Hi LDTate, fellow Missourian,
Thanks very much for the reply. Below are the 2 requested logs. BTW, the ComboFix process created a C:\Qoobox folder of several files with secondary extensions of ".vir". I appears this may be a folder of quarantined items.
Thanks again, Mark C.
————————————————————————————-
————————————————————————————-
COMBOFIX.TXT:
Start Time= Sat 07/15/2006 18:07:10.09
Running from: C:\Documents and Settings\[removed]\Desktop
((((((((((((((((((((((((((((((((((((((((((((( Look2Me's Log
))))))))))))))))))))))))))))))))))))))))))))))))))
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wzcnotif
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
* *
REGISTRY ENTRIES REMOVED:
[HKEY_CLASSES_ROOT\clsid\{41974DFD-921B-4796-9D09-7EC4CC5943FE}]
@=""
[HKEY_CLASSES_ROOT\clsid\{41974DFD-921B-4796-9D09-7EC4CC5943FE}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\clsid\{41974DFD-921B-4796-9D09-7EC4CC5943FE}\Implemented
Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\clsid\{41974DFD-921B-4796-9D09-7EC4CC5943FE}\InprocServer32]
@="C:\\WINDOWS\\system32\\lgfpx13n.dll"
"ThreadingModel"="Apartment"
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
* *
FILES REMOVED:
C:\WINDOWS\SYSTEM32\f40oled31h0.dll
C:\WINDOWS\SYSTEM32\guard.tmp
C:\WINDOWS\SYSTEM32\lvavi13n.dll
C:\WINDOWS\SYSTEM32\mvr0l99m1.dll
Granting sedebugprivilege to Administrators … successful
((((((((((((((((((((((((((((((((((((((((((((( Qoologic's Log
)))))))))))))))))))))))))))))))))))))))))))))))))))
18:10:04.14
Not all files found by this method are bad. There may be legitimate files found
This log should be examined by a trained analyst
* * * PRE-RUN - Filepaths extracted from the Registry * * * * * * * * * * * * * * * * * * * * * *
C:\WINDOWS\System32\mmjvpx.exe
C:\WINDOWS\System32\dvaap.exe
C:\WINDOWS\SYSTEM32\oqheadc.exe
* * * PRE-RUN - Filepaths from Locate * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
2006-06-22 14:06:38 127,488 "C:\WINDOWS\SYSTEM32\mmjvpx.exe"
2006-06-22 14:06:38 28,672 "C:\WINDOWS\SYSTEM32\dvaap.exe"
2006-05-19 15:52:28 2,702,848 "C:\WINDOWS\SYSTEM32\MSHTML.DLL"
2006-05-14 04:13:42 257,536 "C:\WINDOWS\SYSTEM32\oakley.dll"
2006-05-08 10:50:58 461,824 "C:\WINDOWS\SYSTEM32\URLMON.DLL"
2006-06-22 14:06:38 23,552 "C:\WINDOWS\SYSTEM32\oqheadc.exe"
2006-06-02 13:39:46 286,000 "C:\WINDOWS\SYSTEM32\WgaTray.exe"
2006-06-22 14:01:54 146,999 "C:\WINDOWS\SYSTEM32\XPAgent.exe"
2006-04-28 10:57:16 351,744 "C:\WINDOWS\SYSTEM32\DXTMSFT.DLL"
2006-05-26 22:19:50 163,840 "C:\WINDOWS\SYSTEM32\JGDW400.DLL"
2006-05-18 00:58:56 458,752 "C:\WINDOWS\SYSTEM32\jscript.dll"
2006-04-28 10:58:48 12,288 "C:\WINDOWS\SYSTEM32\JSPROXY.DLL"
2006-05-14 04:13:42 169,984 "C:\WINDOWS\SYSTEM32\rasmans.dll"
2006-05-26 15:40:58 1,339,904 "C:\WINDOWS\SYSTEM32\SHDOCVW.DLL"
2006-06-22 14:06:32 8,464 "C:\WINDOWS\SYSTEM32\sporder.dll"
2006-06-22 14:06:38 51,712 "C:\WINDOWS\SYSTEM32\stjvggn.dll"
2006-04-28 10:58:58 575,488 "C:\WINDOWS\SYSTEM32\WININET.DLL"
2006-07-09 14:05:48 127,488 "C:\WINDOWS\SYSTEM32\sjxyb.dat"
2006-07-13 20:32:28 326 "C:\WINDOWS\lhpdg.dll"
2006-06-22 14:06:36 52 "C:\WINDOWS\bwnvev.dat"
2006-06-22 14:06:38 127,488 "C:\Documents and Settings\All Users\Start
Menu\Programs\Startup\ftvwv.exe"
* * * POST-RUN - Files in the Quarantine folder * * * * * * * * * * * * * * * * * * * * * * * * *
07/09/2006 02:05 PM 127,488 sjxyb.dat.vir
06/22/2006 02:06 PM 127,488 mmjvpx.exe.vir
06/22/2006 02:06 PM 127,488 ftvwv.exe.vir
06/22/2006 02:06 PM 51,712 stjvggn.dll.vir
06/22/2006 02:06 PM 28,672 dvaap.exe.vir
06/22/2006 02:06 PM 23,552 oqheadc.exe.vir
DO NOT DELETE ANY FILES FROM THIS DIRECTORY UNLESS INSTRUCTED TO
* * * POST-RUN - Filepaths from Locate * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
2006-06-02 13:39:46 286,000 "C:\WINDOWS\SYSTEM32\WgaTray.exe"
2006-06-22 14:01:54 146,999 "C:\WINDOWS\SYSTEM32\XPAgent.exe"
2006-04-28 10:57:16 351,744 "C:\WINDOWS\SYSTEM32\DXTMSFT.DLL"
2006-05-26 22:19:50 163,840 "C:\WINDOWS\SYSTEM32\JGDW400.DLL"
2006-05-18 00:58:56 458,752 "C:\WINDOWS\SYSTEM32\jscript.dll"
2006-04-28 10:58:48 12,288 "C:\WINDOWS\SYSTEM32\JSPROXY.DLL"
2006-05-14 04:13:42 169,984 "C:\WINDOWS\SYSTEM32\rasmans.dll"
2006-05-26 15:40:58 1,339,904 "C:\WINDOWS\SYSTEM32\SHDOCVW.DLL"
2006-06-22 14:06:32 8,464 "C:\WINDOWS\SYSTEM32\sporder.dll"
2006-04-28 10:58:58 575,488 "C:\WINDOWS\SYSTEM32\WININET.DLL"
2006-05-19 15:52:28 2,702,848 "C:\WINDOWS\SYSTEM32\MSHTML.DLL"
2006-05-14 04:13:42 257,536 "C:\WINDOWS\SYSTEM32\oakley.dll"
2006-05-08 10:50:58 461,824 "C:\WINDOWS\SYSTEM32\URLMON.DLL"
2006-07-13 20:32:28 326 "C:\WINDOWS\lhpdg.dll"
2006-06-22 14:06:36 52 "C:\WINDOWS\bwnvev.dat"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions
)))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\keyboard1.dat
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report
)))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-07-15 17:57:54 ( .D… ) "C:\Program Files\Common Files"
2006-07-13 20:32:28 326 ( A…. ) "C:\WINDOWS\lhpdg.dll"
2006-06-22 14:14:38 183296 ( A…. ) "C:\WINDOWS\NDNuninstall7_22.exe"
2006-06-22 14:06:32 8464 ( A…. ) "C:\WINDOWS\SYSTEM32\sporder.dll"
2006-06-22 14:03:56 9728 ( A…. ) "C:\WINDOWS\SYSTEM32\test.exe"
2006-06-22 14:03:52 146999 ( A…. ) "C:\WINDOWS\SYSTEM32\MSAgentXP.exe"
2006-06-22 14:01:54 146999 ( A…. ) "C:\WINDOWS\SYSTEM32\XPAgent.exe"
2006-06-02 13:39:46 402736 ( ….. ) "C:\WINDOWS\SYSTEM32\WgaLogon.dll"
2006-05-14 04:13:42 364544 ( A…. ) "C:\WINDOWS\SYSTEM32\ipsmsnap.dll"
2006-05-14 04:13:42 334848 ( A…. ) "C:\WINDOWS\SYSTEM32\ipsecsnp.dll"
2006-05-14 04:13:42 257536 ( A…. ) "C:\WINDOWS\SYSTEM32\oakley.dll"
2006-05-14 04:13:42 159744 ( A…. ) "C:\WINDOWS\SYSTEM32\ipsecsvc.dll"
2006-05-14 04:13:42 98304 ( A…. ) "C:\WINDOWS\SYSTEM32\polstore.dll"
2006-05-14 04:13:42 29184 ( A…. ) "C:\WINDOWS\SYSTEM32\winipsec.dll"
2005-06-07 19:49:08 1662 ( A…. ) "C:\Program Files\DeIsL1.isu"
(((((((((((((((((((((((((((((((((((((( Files Created - Last 30days
)))))))))))))))))))))))))))))))))))))))))))
2006-06-22 14:14 183,296 C:\WINDOWS\NDNuninstall7_22.exe
2006-06-22 14:06 940,000 C:\WINDOWS\zzroyrb.exe
2006-06-22 14:06 8,464 C:\WINDOWS\system32\sporder.dll
2006-06-22 14:06 326 C:\WINDOWS\lhpdg.dll
2006-06-22 14:03 9,728 C:\WINDOWS\system32\test.exe
2006-06-22 14:03 146,999 C:\WINDOWS\system32\MSAgentXP.exe
2006-06-22 14:01 146,999 C:\WINDOWS\system32\XPAgent.exe
2006-06-02 13:39 402,736 C:\WINDOWS\system32\WgaLogon.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points
))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"BCMSMMSG"="BCMSMMSG.exe"
"ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"CTSysVol"="C:\\Program Files\\Creative\\SBAudigy2\\Surround Mixer\\CTSysVol.exe"
"CTDVDDet"="C:\\Program Files\\Creative\\SBAudigy2\\DVDAudio\\CTDVDDet.EXE"
"CTHelper"="CTHELPER.EXE"
"UpdReg"="C:\\WINDOWS\\UpdReg.EXE"
"DVDSentry"="C:\\WINDOWS\\System32\\DSentry.exe"
"DwlClient"="C:\\Program Files\\Common Files\\Dell\\EUSW\\Support.exe"
"AdaptecDirectCD"="\"C:\\Program Files\\Roxio\\Easy CD Creator 5\\DirectCD\\DirectCD.exe\""
"Tweak UI"="RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp"
"Microsoft Works Update Detection"="C:\\Program Files\\Common Files\\Microsoft Shared\\Works
Shared\\WkUFind.exe"
"sr1exe"="\"C:\\Documents and Settings\\All Users\\Application
Data\\Dell\\Alert\\252\\updtSup3.exe\" "
"MediaFace Integration"="C:\\Program Files\\Fellowes\\MediaFACE 4.0\\SetHook.exe"
"wcmdmgr"="C:\\WINDOWS\\wt\\updater\\wcmdmgrl.exe -launch"
"ViewMgr"="C:\\Program Files\\Viewpoint\\Viewpoint Manager\\ViewMgr.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"SSC_UserPrompt"="C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\UsrPrmpt.exe"
"Symantec NetDriver Monitor"="C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe /Consumer"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"Zone Labs Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
"{12-2A-AA-A6-ZN}"="C:\\windows\\system32\\dwdsregt.exe GID003"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"PopUpStopperFreeEdition"="\"C:\\PROGRA~1\\PANICW~1\\POP-UP~1\\PSFree.exe\""
"Mozilla Quick Launch"="\"C:\\Program Files\\Netscape\\Netscape\\Netscp.exe\" -turbo"
"Yahoo! Pager"="C:\\Program Files\\Yahoo!\\Messenger\\ypager.exe -quiet"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonceex]
"flags"=dword:00000008
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonceex\000]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
@=""
"NoDriveTypeAutoRun"=hex:5f,00,00,00
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000005
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,\
00,00,04,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"CDRAutoRun"=dword:00000000
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"CDRAutoRun"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer - Mark-Lori.job
Completion time: Sat 07/15/2006 18:14:56.39
ComboFix ver 06.07.15 - This logfile is located at C:\ComboFix.txt
————————————————————————————-
————————————————————————————-
HIJACKTHIS.LOG
Logfile of HijackThis v1.99.1
Scan saved at 6:20:08 PM, on 7/15/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\WINDOWS\System32\CTHELPER.EXE
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe
C:\WINDOWS\wt\updater\wcmdmgr.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Program Files\Netscape\Netscape\Netscp.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Temp\Downloads\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_3_12_0.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [sr1exe] "C:\Documents and Settings\All Users\Application Data\Dell\Alert\252\updtSup3.exe"
O4 - HKLM\..\Run: [MediaFace Integration] C:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe
O4 - HKLM\..\Run: [wcmdmgr] C:\WINDOWS\wt\updater\wcmdmgrl.exe -launch
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [{12-2A-AA-A6-ZN}] C:\windows\system32\dwdsregt.exe GID003
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [Mozilla Quick Launch] "C:\Program Files\Netscape\Netscape\Netscp.exe" -turbo
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Global Startup: Digital Line Detect.lnk = ?
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) -
http://zone.msn.com/binFrameWork/v10/StagingUI.cab34120.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (ZoneBuddy Class) -
http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab32846.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) -
http://zone.msn.com/binframework/v10/ZPAChat.cab32846.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/…b?1121301740695
O16 - DPF: {65E7DB1D-0101-4100-BD66-C5C78C917F93} (WTDMMPVersion Class) -
http://install.wildtangent.com/bgn/partner…lim/install.cab
O16 - DPF: {95B5D20C-BD31-4489-8ABF-F8C8BE748463} (ZPA_HRTZ Object) -
http://zone.msn.com/bingame/zpagames/zpa_hrtz.cab37196.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) -
http://us.dl1.yimg.com/download.yahoo.com/…ropper1_6us.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (StadiumProxy Class) -
http://zone.msn.com/binframework/v10/StProxy.cab35645.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
————————————————————————————-
————————————————————————————-