Thank you for your swift reply. Here is the logfile from combofix and hijackthis.
ComboFix 07-09-09.5 - "sharon" 2007-09-09 21:51:27.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.44.1033.18.461 [GMT 1:00]
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\autorun.inf
C:\WINDOWS\system32\_000005_.tmp.dll
C:\WINDOWS\system32\_000006_.tmp.dll
C:\WINDOWS\system32\_000007_.tmp.dll
C:\WINDOWS\system32\_000008_.tmp.dll
C:\WINDOWS\system32\_000009_.tmp.dll
C:\WINDOWS\system32\_000010_.tmp.dll
C:\WINDOWS\system32\_000019_.tmp.dll
C:\WINDOWS\system32\drivers\asc3550.sys
D:\DOCUME~1\khari\APPLIC~1\Starware347
D:\DOCUME~1\khari\APPLIC~1\Starware347\BrowserSearch\BrowserSearch.xml
D:\DOCUME~1\khari\APPLIC~1\Starware347\BrowserSearch\BrowserSearch.xml.backup
D:\DOCUME~1\khari\APPLIC~1\Starware347\Configurator\Configurator.xml
D:\DOCUME~1\khari\APPLIC~1\Starware347\Configurator\Configurator.xml.backup
D:\DOCUME~1\khari\APPLIC~1\Starware347\EntertainmentMarketingSP\EntertainmentMarketingSPOptions.xml
D:\DOCUME~1\khari\APPLIC~1\Starware347\EntertainmentMarketingSP\EntertainmentMarketingSPOptions.xml.backup
D:\DOCUME~1\khari\APPLIC~1\Starware347\ErrorSearch\ErrorSearchOptions.xml
D:\DOCUME~1\khari\APPLIC~1\Starware347\ErrorSearch\ErrorSearchOptions.xml.backup
D:\DOCUME~1\khari\APPLIC~1\Starware347\Games\GamesOptions.xml
D:\DOCUME~1\khari\APPLIC~1\Starware347\Games\GamesOptions.xml.backup
D:\DOCUME~1\khari\APPLIC~1\Starware347\JokeSearch\JokeSearchOptions.xml
D:\DOCUME~1\khari\APPLIC~1\Starware347\JokeSearch\JokeSearchOptions.xml.backup
D:\DOCUME~1\khari\APPLIC~1\Starware347\Layouts\PitchLayout.xml
D:\DOCUME~1\khari\APPLIC~1\Starware347\Layouts\PitchLayout.xml.backup
D:\DOCUME~1\khari\APPLIC~1\Starware347\Layouts\ToolbarLayout.xml
D:\DOCUME~1\khari\APPLIC~1\Starware347\Layouts\ToolbarLayout.xml.backup
D:\DOCUME~1\khari\APPLIC~1\Starware347\Manager\ManagerOptions.xml
D:\DOCUME~1\khari\APPLIC~1\Starware347\Manager\ManagerOptions.xml.backup
D:\DOCUME~1\khari\APPLIC~1\Starware347\Movies\MoviesOptions.xml
D:\DOCUME~1\khari\APPLIC~1\Starware347\Movies\MoviesOptions.xml.backup
D:\DOCUME~1\khari\APPLIC~1\Starware347\Pranks\PranksOptions.xml
D:\DOCUME~1\khari\APPLIC~1\Starware347\Pranks\PranksOptions.xml.backup
D:\DOCUME~1\khari\APPLIC~1\Starware347\RelatedSearch\RelatedSearchOptions.xml
D:\DOCUME~1\khari\APPLIC~1\Starware347\RelatedSearch\RelatedSearchOptions.xml.backup
D:\DOCUME~1\khari\APPLIC~1\Starware347\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml
D:\DOCUME~1\khari\APPLIC~1\Starware347\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml.backup
D:\DOCUME~1\khari\APPLIC~1\Starware347\SearchAssistPlus\SearchAssistPlusOptions.xml
D:\DOCUME~1\khari\APPLIC~1\Starware347\SearchAssistPlus\SearchAssistPlusOptions.xml.backup
D:\DOCUME~1\khari\APPLIC~1\Starware347\SearchMatch\SearchMatchOptions.xml
D:\DOCUME~1\khari\APPLIC~1\Starware347\SearchMatch\SearchMatchOptions.xml.backup
D:\DOCUME~1\khari\APPLIC~1\Starware347\Toolbar\TBProductsOptions.xml
D:\DOCUME~1\khari\APPLIC~1\Starware347\Toolbar\TBProductsOptions.xml.backup
D:\DOCUME~1\khari\APPLIC~1\Starware347\ToolbarLogo\ToolbarLogoOptions.xml
D:\DOCUME~1\khari\APPLIC~1\Starware347\ToolbarLogo\ToolbarLogoOptions.xml.backup
D:\DOCUME~1\khari\APPLIC~1\Starware347\ToolbarSearch\ToolbarSearchOptions.xml
D:\DOCUME~1\khari\APPLIC~1\Starware347\ToolbarSearch\ToolbarSearchOptions.xml.backup
D:\DOCUME~1\khari\APPLIC~1\Starware347\TravelSearch\TravelSearchOptions.xml
D:\DOCUME~1\khari\APPLIC~1\Starware347\TravelSearch\TravelSearchOptions.xml.backup
((((((((((((((((((((((((( Files Created from 2007-08-09 to 2007-09-09 )))))))))))))))))))))))))))))))
.
2007-09-09 21:50 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-09-09 21:49 1,484,800 --a------ C:\Program Files\ComboFix.exe
2007-09-08 23:36 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-09-08 23:34 12,413,440 --a------ C:\Program Files\avgas-setup-7.5.1.43.exe
2007-09-08 23:27 50,688 --a------ C:\Program Files\ATF-Cleaner.exe
2007-09-07 13:16 <DIR> d-------- C:\Program Files\Trend Micro
2007-09-05 16:39 <DIR> d-------- D:\DOCUME~1\ASHIA~1.CHE\APPLIC~1\OD2
2007-08-27 20:45 <DIR> d-------- D:\DOCUME~1\UZOAMA~1.CHE\APPLIC~1\OD2
2007-08-19 15:46 71,168 --a------ C:\WINDOWS\system32\E_FLBBEE.DLL
2007-08-19 15:46 62,976 --a------ C:\WINDOWS\system32\E_FD4BBEE.DLL
2007-08-19 15:32 29,696 --a------ C:\WINDOWS\system32\escwiad.dll
2007-08-19 10:21 <DIR> d-------- D:\DOCUME~1\KHARI~1.CHE\APPLIC~1\OD2
2007-08-15 22:50 <DIR> d-------- C:\Program Files\MSECache
2007-08-14 19:10 <DIR> d-------- D:\DOCUME~1\KHARI~1.CHE\APPLIC~1\Zango
2007-08-14 19:10 <DIR> d-------- D:\DOCUME~1\ALLUSE~1\APPLIC~1\ZangoSA
2007-08-14 19:10 <DIR> d-------- D:\DOCUME~1\ALLUSE~1\APPLIC~1\2ACA5CC3-0F83-453D-A079-1076FE1A8B65
2007-08-13 11:13 <DIR> d-------- D:\DOCUME~1\KHARI~1.CHE\APPLIC~1\CyberLink
2007-08-11 23:34 <DIR> d-------- D:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-08-11 23:05 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-08-11 22:47 <DIR> d-------- C:\Program Files\NoAdware5.0
2007-08-11 22:36 159,744 --a------ C:\WINDOWS\system32\hasher.dll
2007-08-11 22:36 <DIR> d-------- C:\Program Files\Trisnap Technologies
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-09 21:58 --------- d-------- C:\Program Files\Incomplete
2007-09-09 21:57 --------- d-------- D:\DOCUME~1\ALLUSE~1\APPLIC~1\Kontiki
2007-09-09 21:57 --------- d-------- C:\Program Files\LimeWire
2007-09-09 21:09 --------- d-------- C:\Program Files\McAfee
2007-09-07 22:16 --------- d-------- D:\DOCUME~1\SHARON~1.CHE\APPLIC~1\LimeWire
2007-08-19 16:02 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-08-19 16:01 --------- d-------- C:\Program Files\Common Files\InstallShield
2007-08-19 16:00 --------- d-------- D:\DOCUME~1\ALLUSE~1\APPLIC~1\UDL
2007-08-19 16:00 --------- d-------- C:\Program Files\EPSON
2007-08-13 18:21 --------- d-------- D:\DOCUME~1\KHARI~1.CHE\APPLIC~1\Ulead Systems
2007-08-10 19:19 --------- d-------- D:\DOCUME~1\ALLUSE~1\APPLIC~1\QuickTime
2007-08-04 00:38 --------- d-------- C:\Program Files\Microsoft ActiveSync
2007-08-04 00:36 --------- d-------- C:\Program Files\Microsoft.NET
2007-08-03 20:46 --------- d-------- D:\DOCUME~1\SHARON~1.CHE\APPLIC~1\Sonic
2007-08-03 20:46 --------- d-------- D:\DOCUME~1\SHARON~1.CHE\APPLIC~1\Leadertech
2007-08-02 10:52 --------- d-------- D:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft Help
2007-07-22 14:28 --------- d-a------ D:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-07-22 14:23 --------- d-------- C:\Program Files\MSN Games
2007-06-13 11:23 1033216 --a------ C:\WINDOWS\explorer.exe
2007-05-04 13:54 3098056 --a------ C:\Program Files\LimeWireWin.exe
2007-05-03 23:06 25755448 --a------ C:\Program Files\wmp11-windowsxp-x86-enu.exe
2007-05-03 20:48 18040176 --a------ C:\Program Files\Install_Messenger_nous.exe
2004-01-15 02:34 259539966 --a------ C:\Program Files\Microsoft Office XP Publisher 2003.zip
2001-04-04 18:11 1499904 -ra------ C:\Program Files\INSTMSIW.EXE
2001-04-04 18:11 1489152 -ra------ C:\Program Files\INSTMSI.EXE
2001-04-02 20:50 29 -ra------ C:\Program Files\cd-key.txt
2001-03-02 00:38 3485184 -ra------ C:\Program Files\PROPLUS.MSI
2001-03-02 00:35 306688 -ra------ C:\Program Files\OWC10.MSI
2001-03-01 15:35 224771818 -rah----- C:\Program Files\OFFICE1.CAB
2001-02-28 13:14 476576 -ra------ C:\Program Files\SETUP.EXE
2001-02-21 13:18 7929 -ra------ C:\Program Files\README.HTM
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-10 15:00]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-10 15:00]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 14:56]
"SoundMan"="SOUNDMAN.EXE" [2005-01-20 21:04 C:\WINDOWS\SOUNDMAN.EXE]
"ATIPTA"="C:\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-03-22 22:05]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"Ulead AutoDetector v2"="C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe" [2004-11-26 12:43]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-10 15:00]
"MskAgentexe"="C:\Program Files\McAfee\MSK\MskAgent.exe" [2007-01-17 16:30]
"EPSON Stylus Photo RX420 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.exe" [2004-04-09 04:00]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-11-25 22:19]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-11-25 22:24]
"4oD"="C:\Program Files\Kontiki\KHost.exe" [2006-11-08 17:32]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"ZangoOE"="C:\Program Files\Zango\bin\10.0.341.0\OEAddOn.exe" []
"ZangoSA"="C:\Program Files\Zango\bin\10.0.341.0\ZangoSA.exe" []
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 15:00]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" []
"kdx"="C:\Program Files\Kontiki\KHost.exe" [2006-11-08 17:32]
D:\DOCUME~1\SHARON~1.CHE\STARTM~1\Programs\Startup\
LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2007-01-29 22:33:41]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
R3 3xHybrid;3xHybrid service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys
S0 SiSRaid;SiSRaid;C:\WINDOWS\system32\DRIVERS\SiSRaid.sys
.
Contents of the 'Scheduled Tasks' folder
"2007-05-03 19:27:11 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2007-07-01 00:00:14 C:\WINDOWS\Tasks\McQcTask.job"
.
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-09-09 21:57:34
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-09-09 21:59:02 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-09-09 21:59
.
--- E O F ---
ogfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:04:13, on 09/09/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
C:\Program Files\McAfee\MSK\MskAgent.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Kontiki\KHost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32"
O4 - HKLM\..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [4oD] "C:\Program Files\Kontiki\KHost.exe" -all
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ZangoOE] C:\Program Files\Zango\bin\10.0.341.0\OEAddOn.exe
O4 - HKLM\..\Run: [ZangoSA] "C:\Program Files\Zango\bin\10.0.341.0\ZangoSA.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Sky - {08E730A4-FB02-45BD-A900-01E4AD8016F6} -
http://www.skybroadband.com (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\uk.htm
O16 - DPF: {40272BF7-4FF5-4D6F-9BAD-3C1D3CB32982} (Live365PlayerVIP Class) -
http://www.live365.c...ers/p365vip.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://gfx1.mail.liv...es/MSNPUpld.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) -
http://www.adobe.com...obat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.m...ash/swflash.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: KService - Unknown owner - C:\Program Files\Kontiki\KService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: SysEnforce - Unknown owner - C:\PROGRA~1\TRISNA~1\SSI\SYSENF~1.EXE (file missing)
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
--
End of file - 9909 bytes