Start Time= Sun 07/16/2006 11:06:23.62
Running from: C:\Documents and Settings\[removed]\Desktop
QuickScan did not find any signs of infected files
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-07-15 10:00:06 18432 ( A…. ) "C:\WINDOWS\system32\ixt5.dll"
2006-07-14 14:16:04 18432 ( A…. ) "C:\WINDOWS\system32\ixt4.dll"
2006-07-14 14:15:56 18432 ( A…. ) "C:\WINDOWS\system32\ixt3.dll"
2006-07-14 13:39:30 18432 ( A…. ) "C:\WINDOWS\system32\ixt2.dll"
2006-07-14 13:39:26 29184 ( A…. ) "C:\WINDOWS\system32\issearch.exe"
2006-07-14 13:13:16 573492 ( ..SH. ) "C:\WINDOWS\system32\gebca.dll"
2006-07-13 22:25:44 ( .D… ) "C:\Program Files\??curity"
2006-07-13 20:27:02 16384 ( A…. ) "C:\WINDOWS\system32\ixt1.dll"
2006-07-13 20:05:54 ( .D… ) "C:\Program Files\Webroot"
2006-07-13 20:05:54 ( .D… ) "C:\Documents and Settings\Owner\Application Data\Webroot"
2006-07-13 19:17:34 16384 ( A…. ) "C:\WINDOWS\system32\ixt0.dll"
2006-07-11 23:01:38 56832 ( A…. ) "C:\WINDOWS\g438044343.dll"
2006-07-11 22:39:38 56832 ( A…. ) "C:\WINDOWS\g436724312.dll"
2006-07-11 19:43:34 56832 ( A…. ) "C:\WINDOWS\g426162546.dll"
2006-07-11 18:39:34 56832 ( A…. ) "C:\WINDOWS\g422322390.dll"
2006-07-11 18:17:34 56832 ( A…. ) "C:\WINDOWS\g421002234.dll"
2006-07-11 17:55:34 56832 ( A…. ) "C:\WINDOWS\g419681484.dll"
2006-07-11 16:49:32 56832 ( A…. ) "C:\WINDOWS\g415720546.dll"
2006-07-11 16:27:32 56832 ( A…. ) "C:\WINDOWS\g414400140.dll"
2006-07-11 16:05:32 56832 ( A…. ) "C:\WINDOWS\g413080031.dll"
2006-07-11 14:09:32 56832 ( A…. ) "C:\WINDOWS\g406119578.dll"
2006-07-11 13:47:30 56832 ( A…. ) "C:\WINDOWS\g404799343.dll"
2006-07-11 11:57:26 56832 ( A…. ) "C:\WINDOWS\g398195265.dll"
2006-07-11 11:35:26 56832 ( A…. ) "C:\WINDOWS\g396875171.dll"
2006-07-11 11:13:26 56832 ( A…. ) "C:\WINDOWS\g395554890.dll"
2006-07-11 02:27:22 56832 ( A…. ) "C:\WINDOWS\g363989984.dll"
2006-07-11 02:05:22 56832 ( A…. ) "C:\WINDOWS\g362669750.dll"
2006-07-11 01:43:22 56832 ( A…. ) "C:\WINDOWS\g361348875.dll"
2006-07-10 20:45:18 56832 ( A…. ) "C:\WINDOWS\g343465640.dll"
2006-07-10 20:23:18 56832 ( A…. ) "C:\WINDOWS\g342145359.dll"
2006-07-10 19:21:14 56832 ( A…. ) "C:\WINDOWS\g338421781.dll"
2006-07-10 18:59:14 56832 ( A…. ) "C:\WINDOWS\g337101656.dll"
2006-07-10 18:37:12 56832 ( A…. ) "C:\WINDOWS\g335781187.dll"
2006-07-10 17:31:12 56832 ( A…. ) "C:\WINDOWS\g331820906.dll"
2006-07-10 16:19:12 56832 ( A…. ) "C:\WINDOWS\g327500500.dll"
2006-07-10 15:57:12 56832 ( A…. ) "C:\WINDOWS\g326180593.dll"
2006-07-10 10:57:10 56832 ( A…. ) "C:\WINDOWS\g308177750.dll"
2006-07-09 21:28:58 56832 ( A…. ) "C:\WINDOWS\g259686437.dll"
2006-07-09 21:06:58 56832 ( A…. ) "C:\WINDOWS\g258365937.dll"
2006-07-09 19:34:58 56832 ( A…. ) "C:\WINDOWS\g252845515.dll"
2006-07-09 06:06:36 56832 ( A…. ) "C:\WINDOWS\g204354953.dll"
2006-07-08 21:16:24 56832 ( A…. ) "C:\WINDOWS\g172542609.dll"
2006-07-08 20:56:22 56832 ( A…. ) "C:\WINDOWS\g171341687.dll"
2006-07-08 20:34:22 56832 ( A…. ) "C:\WINDOWS\g170020656.dll"
2006-07-08 06:18:08 56832 ( A…. ) "C:\WINDOWS\g118647109.dll"
2006-07-08 05:58:08 56832 ( A…. ) "C:\WINDOWS\g117447015.dll"
2006-07-07 22:47:56 56832 ( A…. ) "C:\WINDOWS\g91634203.dll"
2006-07-07 22:25:56 56832 ( A…. ) "C:\WINDOWS\g90314109.dll"
2006-07-07 22:03:54 56832 ( A…. ) "C:\WINDOWS\g88993968.dll"
2006-07-07 16:54:10 252928 ( A…. ) "C:\WINDOWS\WRUninstall.dll"
2006-07-07 16:53:54 208896 ( A…. ) "C:\WINDOWS\system32\WRLogonNtf.dll"
2006-07-07 16:53:52 8704 ( A…. ) "C:\WINDOWS\system32\ssiefr.EXE"
2006-07-07 16:53:50 20992 ( A…. ) "C:\WINDOWS\system32\wrlzma.dll"
2006-07-07 06:09:34 56832 ( A…. ) "C:\WINDOWS\g31732625.dll"
2006-07-06 22:05:26 56832 ( A…. ) "C:\WINDOWS\g2683609.dll"
2006-07-06 21:45:24 56832 ( A…. ) "C:\WINDOWS\g1483062.dll"
2006-07-06 14:08:48 ( .D… ) "C:\Documents and Settings\Owner\Application Data\Yahoo!"
2006-07-06 13:14:26 ( .D… ) "C:\Program Files\ePrompter"
2006-07-05 20:59:46 ( .D… ) "C:\Program Files\ewido anti-spyware 4.0"
2006-07-05 17:06:00 ( .D… ) "C:\Documents and Settings\Owner\Application Data\Registry Booster"
2006-07-03 21:40:08 ( .D… ) "C:\Documents and Settings\Owner\Application Data\PlayFirst"
2006-07-02 16:34:36 2 ( A…. ) "C:\WINDOWS\system32\wintsvcc.exe"
2006-07-02 16:34:34 ( .D… ) "C:\Program Files\Common Files\??stem"
2006-07-02 16:34:06 ( .D… ) "C:\Program Files\Cowabanga"
2006-07-02 16:29:36 ( .D… ) "C:\Documents and Settings\Owner\Application Data\Mobile Media Master"
2006-06-30 10:32:02 ( .D… ) "C:\Documents and Settings\Owner\Application Data\Digital Asphyxia"
2006-06-30 03:59:32 407080 ( A…. ) "C:\msgr8us.exe"
2006-06-16 22:48:46 ( .D… ) "C:\Documents and Settings\Owner\Application Data\MySpace"
2006-06-16 14:34:44 48936 ( A…. ) "C:\WINDOWS\system32\sirenacm.dll"
2006-06-14 20:27:46 ( .D… ) "C:\Program Files\ewido anti-malware"
2006-05-19 07:59:42 148480 ( A…. ) "C:\WINDOWS\system32\dnsapi.dll"
2006-05-19 07:59:42 111616 ( A…. ) "C:\WINDOWS\system32\dhcpcsvc.dll"
2006-05-19 07:59:42 94720 ( A…. ) "C:\WINDOWS\system32\iphlpapi.dll"
2006-04-25 17:45:06 123 ( A…. ) "C:\tsrvweb.exe"
(((((((((((((((((((((((((((((((((((((( Files Created - Last 30days )))))))))))))))))))))))))))))))))))))))))))
2006-07-14 18:21 18,432 C:\WINDOWS\system32\ixt5.dll
2006-07-14 14:16 18,432 C:\WINDOWS\system32\ixt4.dll
2006-07-14 14:15 18,432 C:\WINDOWS\system32\ixt3.dll
2006-07-14 13:39 29,184 C:\WINDOWS\system32\issearch.exe
2006-07-14 13:13 573,492 C:\WINDOWS\system32\gebca.dll
2006-07-13 20:27 18,432 C:\WINDOWS\system32\ixt2.dll
2006-07-13 20:27 16,384 C:\WINDOWS\system32\ixt1.dll
2006-07-13 20:06 208,896 C:\WINDOWS\system32\WRLogonNtf.dll
2006-07-13 20:05 8,704 C:\WINDOWS\system32\ssiefr.EXE
2006-07-13 20:05 684,032 C:\WINDOWS\libeay32.dll
2006-07-13 20:05 252,928 C:\WINDOWS\WRUninstall.dll
2006-07-13 20:05 20,992 C:\WINDOWS\system32\wrlzma.dll
2006-07-13 20:05 155,648 C:\WINDOWS\ssleay32.dll
2006-07-13 19:17 16,384 C:\WINDOWS\system32\ixt0.dll
2006-07-11 23:01 56,832 C:\WINDOWS\g438044343.dll
2006-07-11 22:39 56,832 C:\WINDOWS\g436724312.dll
2006-07-11 19:43 56,832 C:\WINDOWS\g426162546.dll
2006-07-11 18:39 56,832 C:\WINDOWS\g422322390.dll
2006-07-11 18:17 56,832 C:\WINDOWS\g421002234.dll
2006-07-11 17:55 56,832 C:\WINDOWS\g419681484.dll
2006-07-11 16:49 56,832 C:\WINDOWS\g415720546.dll
2006-07-11 16:27 56,832 C:\WINDOWS\g414400140.dll
2006-07-11 16:05 56,832 C:\WINDOWS\g413080031.dll
2006-07-11 14:09 56,832 C:\WINDOWS\g406119578.dll
2006-07-11 13:47 56,832 C:\WINDOWS\g404799343.dll
2006-07-11 11:57 56,832 C:\WINDOWS\g398195265.dll
2006-07-11 11:35 56,832 C:\WINDOWS\g396875171.dll
2006-07-11 11:13 56,832 C:\WINDOWS\g395554890.dll
2006-07-11 02:27 56,832 C:\WINDOWS\g363989984.dll
2006-07-11 02:05 56,832 C:\WINDOWS\g362669750.dll
2006-07-11 01:43 56,832 C:\WINDOWS\g361348875.dll
2006-07-10 20:45 56,832 C:\WINDOWS\g343465640.dll
2006-07-10 20:23 56,832 C:\WINDOWS\g342145359.dll
2006-07-10 19:21 56,832 C:\WINDOWS\g338421781.dll
2006-07-10 18:59 56,832 C:\WINDOWS\g337101656.dll
2006-07-10 18:37 56,832 C:\WINDOWS\g335781187.dll
2006-07-10 17:31 56,832 C:\WINDOWS\g331820906.dll
2006-07-10 16:19 56,832 C:\WINDOWS\g327500500.dll
2006-07-10 15:57 56,832 C:\WINDOWS\g326180593.dll
2006-07-10 10:57 56,832 C:\WINDOWS\g308177750.dll
2006-07-09 21:28 56,832 C:\WINDOWS\g259686437.dll
2006-07-09 21:06 56,832 C:\WINDOWS\g258365937.dll
2006-07-09 19:34 56,832 C:\WINDOWS\g252845515.dll
2006-07-09 06:06 56,832 C:\WINDOWS\g204354953.dll
2006-07-08 21:16 56,832 C:\WINDOWS\g172542609.dll
2006-07-08 20:56 56,832 C:\WINDOWS\g171341687.dll
2006-07-08 20:34 56,832 C:\WINDOWS\g170020656.dll
2006-07-08 06:18 56,832 C:\WINDOWS\g118647109.dll
2006-07-08 05:58 56,832 C:\WINDOWS\g117447015.dll
2006-07-07 22:47 56,832 C:\WINDOWS\g91634203.dll
2006-07-07 22:25 56,832 C:\WINDOWS\g90314109.dll
2006-07-07 22:03 56,832 C:\WINDOWS\g88993968.dll
2006-07-07 06:09 56,832 C:\WINDOWS\g31732625.dll
2006-07-06 22:05 56,832 C:\WINDOWS\g2683609.dll
2006-07-06 21:45 56,832 C:\WINDOWS\g1483062.dll
2006-07-06 12:48 1,038,602,240 C:\hiberfil.sys
2006-07-06 10:53 407,080 C:\msgr8us.exe
2006-07-02 16:34 2 C:\WINDOWS\system32\wintsvcc.exe
2006-06-16 14:34 48,936 C:\WINDOWS\system32\sirenacm.dll
2006-06-06 22:03 28,672 C:\WINDOWS\system32\verclsid.exe
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"Recguard"="C:\\WINDOWS\\SMINST\\RECGUARD.EXE"
"IgfxTray"="C:\\WINDOWS\\system32\\igfxtray.exe"
"HotKeysCmds"="C:\\WINDOWS\\system32\\hkcmd.exe"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"SynTPLpr"="\"C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe\""
"SynTPEnh"="\"C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe\""
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="\"C:\\Program Files\\Google\\Gmail Notifier\\G001-1.0.25.0\\gnotify.exe\""
"WD Button Manager"="WDBtnMgr.exe"
"LVCOMS"="\"C:\\Program Files\\Common Files\\Logitech\\QCDriver\\LVCOMS.EXE\""
"Pure Networks Port Magic"="\"C:\\PROGRA~1\\PURENE~1\\PORTMA~1\\PortAOL.exe\" -Run"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe\""
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"HP Software Update"="\"C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe\""
"WinampAgent"="\"C:\\Program Files\\Winamp\\winampa.exe\""
"Adobe Photo Downloader"="\"C:\\Program Files\\Adobe\\Photoshop Album Starter Edition\\3.0\\Apps\\apdproxy.exe\""
"!ewido"="\"C:\\Program Files\\ewido anti-spyware 4.0\\ewido.exe\" /minimized"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"AIM"="C:\\Program Files\\AIM\\aim.exe -cnetwait.odl"
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"Y!TunnelPro"="C:\\Program Files\\Digital Asphyxia\\Y!TunnelPro 2.5\\YTPro.exe"
"updateMgr"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\AdobeUpdateManager.exe\" AcRdB7_0_7 -reboot 1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"kernel32.dll"="C:\\WINDOWS\\system32\\isnotify.exe"
"ishost.exe"="ishost.exe"
"issearch.exe"="issearch.exe"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000005
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
"cinnamomum"="{93ac7c30-3878-4eaa-9420-7977285df5b1}"
"{259BA022-2005-45E9-A965-10EDB9C00605}"="Windows Updater"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\WebrootSpySweeperService
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Disk Cleanup.job
Completion time: Sun 07/16/2006 11:07:17.37
ComboFix ver 06.07.15 - This logfile is located at C:\ComboFix.txt
Logfile of HijackThis v1.99.1
Scan saved at 11:09:06 AM, on 7/16/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe
C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\issearch.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
C:\WINDOWS\system32\WDBtnMgr.exe
C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Digital Asphyxia\Y!TunnelPro 2.5\YTPro.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Owner\Desktop\HijackThis_v1.99.1.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.yahoo.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {873eb32d-ae1a-4183-89bd-45a77f761be4} - C:\WINDOWS\system32\ixt5.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll
O2 - BHO: (no name) - {E428190D-E490-44E3-9A49-E4240BDA9ABC} - C:\WINDOWS\system32\gebca.dll
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] "C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe"
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [LVCOMS] "C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE"
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Y!TunnelPro] C:\Program Files\Digital Asphyxia\Y!TunnelPro 2.5\YTPro.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1
O4 - Startup: ePrompter.lnk = C:\Program Files\ePrompter\ePrompter.exe
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\WidgetEngine\YahooWidgetEngine.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O8 - Extra context menu item: Download all by Net Transport - C:\Program Files\Xi\NetTransport 2\NTAddList.html
O8 - Extra context menu item: Download by Net Transport - C:\Program Files\Xi\NetTransport 2\NTAddLink.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) -
https://rtc4.webresponse.one.microsoft.com/…p/TLIEFlash.CAB
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} (CPlayFirstDinerDashControl Object) -
http://games.pogo.com/online2/pogop/diner_…sh.1.0.0.80.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} -
http://games.pogo.com/online2/pogo/chuzzle…aploader_v6.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: gebca - C:\WINDOWS\system32\gebca.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe
O23 - Service: Retrospect Helper - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\rthlpsvc.exe
O23 - Service: Retrospect WD Service (RetroWDSvc) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe