Hi Scotty,
Below I think I have the 3 things you asked me to post: the Kaspersky log, the new Combofix log, and the new Hijackthis log.
KASPERSKY ONLINE SCANNER REPORT
Sunday, October 28, 2007 6:54:31 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 28/10/2007
Kaspersky Anti-Virus database records: 447696
——————————————————————————-
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 61171
Number of viruses found: 39
Number of infected objects: 183
Number of suspicious objects: 0
Duration of the scan process: 01:29:41
Infected Object Name / Virus Name / Last Action
C:\3A4.tmp/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eg skipped
C:\3A4.tmp NSIS: infected - 1 skipped
C:\3A5.tmp/stream/data0002 Infected: not-a-virus:Downloader.Win32.Agent.q skipped
C:\3A5.tmp/stream/data0003 Infected: not-a-virus:AdWare.Win32.Agent.ay skipped
C:\3A5.tmp/stream Infected: not-a-virus:AdWare.Win32.Agent.ay skipped
C:\3A5.tmp NSIS: infected - 3 skipped
C:\3A6.tmp Infected: Trojan-Downloader.Win32.Small.eqn skipped
C:\77D.tmp/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eg skipped
C:\77D.tmp NSIS: infected - 1 skipped
C:\77E.tmp/stream/data0002 Infected: not-a-virus:Downloader.Win32.Agent.q skipped
C:\77E.tmp/stream/data0003 Infected: not-a-virus:AdWare.Win32.Agent.ay skipped
C:\77E.tmp/stream Infected: not-a-virus:AdWare.Win32.Agent.ay skipped
C:\77E.tmp NSIS: infected - 3 skipped
C:\77F.tmp Infected: Trojan-Downloader.Win32.Small.eqn skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\Common Framework\Db\Agent_EMACHINES.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\Common Framework\Db\PrdMgr_EMACHINES.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\VirusScan\UpdateLog.txt Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Owner\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Desktop\SDFix\backups\backups.zip/backups/.exe Infected: Trojan-Dropper.Win32.VB.tg skipped
C:\Documents and Settings\Owner\Desktop\SDFix\backups\backups.zip/backups/3FD.tmp Infected: Trojan-Spy.Win32.Zbot.bk skipped
C:\Documents and Settings\Owner\Desktop\SDFix\backups\backups.zip/backups/retadpu.exe Infected: Trojan-Downloader.Win32.Agent.djj skipped
C:\Documents and Settings\Owner\Desktop\SDFix\backups\backups.zip/backups/retadpu.exe.tmp Infected: Trojan-Downloader.Win32.Agent.djj skipped
C:\Documents and Settings\Owner\Desktop\SDFix\backups\backups.zip/backups/retadpu11.exe Infected: Trojan-Downloader.Win32.Agent.enr skipped
C:\Documents and Settings\Owner\Desktop\SDFix\backups\backups.zip/backups/retadpu11.exe.tmp Infected: Trojan-Downloader.Win32.Agent.enr skipped
C:\Documents and Settings\Owner\Desktop\SDFix\backups\backups.zip/backups/retadpu72.exe Infected: Trojan-Downloader.Win32.Agent.bls skipped
C:\Documents and Settings\Owner\Desktop\SDFix\backups\backups.zip/backups/rt25.exe Infected: Packed.Win32.PolyCrypt.d skipped
C:\Documents and Settings\Owner\Desktop\SDFix\backups\backups.zip/backups/sipov.dll Infected: Trojan-Clicker.Win32.Agent.lu skipped
C:\Documents and Settings\Owner\Desktop\SDFix\backups\backups.zip/backups/startdrv.exe Infected: Trojan-Downloader.Win32.Agent.eoa skipped
C:\Documents and Settings\Owner\Desktop\SDFix\backups\backups.zip/backups/tcprp.dll Infected: Trojan-Clicker.Win32.Agent.lu skipped
C:\Documents and Settings\Owner\Desktop\SDFix\backups\backups.zip ZIP: infected - 11 skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\AOL\UserProfiles\All Users\cls\common.cls Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Owner\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Owner\ntuser.dat.LOG Object is locked skipped
C:\Program Files\HP\hpcoretech\hpcmerr.log Object is locked skipped
C:\qoobox\Quarantine\C\Program Files\AntispyStorm\uninstall.exe.vir/EXE-file Infected: not-a-virus:FraudTool.Win32.AntiSpyStorm.a skipped
C:\qoobox\Quarantine\C\Program Files\AntispyStorm\uninstall.exe.vir Embedded EXE: infected - 1 skipped
C:\qoobox\Quarantine\C\Program Files\AntispyStorm\uninstall.exe.vir UPX: infected - 1 skipped
C:\qoobox\Quarantine\C\Program Files\ISM\BndDrive.dll.vir Infected: not-a-virus:AdWare.Win32.Agent.ay skipped
C:\qoobox\Quarantine\C\Program Files\ISM\BndDrive3.dll.vir Infected: not-a-virus:AdWare.Win32.AdBand.c skipped
C:\qoobox\Quarantine\C\Program Files\ISM\bndloader.exe.vir Infected: not-a-virus:Downloader.Win32.Agent.q skipped
C:\qoobox\Quarantine\C\Program Files\ISM2\cringupd.exe.vir/data0002 Infected: not-a-virus:AdWare.Win32.Agent.qi skipped
C:\qoobox\Quarantine\C\Program Files\ISM2\cringupd.exe.vir NSIS: infected - 1 skipped
C:\qoobox\Quarantine\C\Program Files\ISM2\ISMPack7.exe.vir Infected: not-a-virus:AdWare.Win32.Agent.qi skipped
C:\qoobox\Quarantine\C\WINDOWS\fkwggshm.exe.vir Infected: Trojan.Win32.VB.azo skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\aivskurq.dll.vir Infected: Trojan-Downloader.Win32.VB.bpt skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\bk.exe.vir/InpB/SskBho.dll Infected: not-a-virus:AdWare.Win32.SurfSide.t skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\bk.exe.vir/InpB/SskCore.dll Infected: not-a-virus:AdWare.Win32.SurfSide.aa skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\bk.exe.vir/InpB/Ssk.exe Infected: not-a-virus:AdWare.Win32.SurfSide.aa skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\bk.exe.vir/InpB/Ssk3RepairInstall.exe Infected: not-a-virus:AdWare.Win32.SurfSide.t skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\bk.exe.vir/InpB Infected: not-a-virus:AdWare.Win32.SurfSide.t skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\bk.exe.vir CAB: infected - 5 skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\communicator.dll.vir Infected: not-a-virus:AdWare.Win32.MegaSearch.k skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\nusrmgr.exe.vir Infected: not-virus:Hoax.Win32.Renos.kj skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\oembios32.dll.vir Infected: Trojan-Downloader.Win32.VB.bkb skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\qlink32.dll.vir Infected: not-a-virus:AdWare.Win32.Suggestor.r skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\REPAIR~1.DLL.vir Infected: not-a-virus:AdWare.Win32.SurfSide.t skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\vvgeowbv.exe.vir Infected: not-virus:Hoax.Win32.Renos.kj skipped
C:\qoobox\Quarantine\C\WINDOWS\winh32.exe.vir Infected: Trojan.Win32.VB.azo skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP726\A0080080.exe Infected: Trojan-Downloader.Win32.PurityScan.eg skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP726\A0080083.exe Infected: not-a-virus:Downloader.Win32.Agent.q skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP731\A0080132.dll Infected: not-a-virus:AdWare.Win32.PurityScan.gd skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP731\A0080133.exe Infected: not-a-virus:AdWare.Win32.PurityScan.gc skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP744\A0081371.exe Infected: Trojan-Downloader.Win32.Agent.bls skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP746\A0081402.exe Infected: Trojan-Downloader.Win32.PurityScan.eg skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP746\A0081420.exe Infected: not-a-virus:Downloader.Win32.Agent.q skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP760\A0081503.exe Infected: Trojan-Downloader.Win32.Agent.djj skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP764\A0081524.exe Infected: Trojan-Downloader.Win32.Agent.djj skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP769\A0082292.dll Infected: not-a-virus:AdWare.Win32.PurityScan.ft skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP769\A0082293.exe Infected: not-a-virus:AdWare.Win32.PurityScan.ga skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP769\A0082295.dll Infected: not-a-virus:AdWare.Win32.PurityScan.fs skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP780\A0082442.exe Infected: Trojan.Win32.VB.azo skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP780\A0083472.exe Infected: not-a-virus:FraudTool.Win32.AntiSpyStorm.a skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP780\A0083484.exe Infected: Trojan.Win32.VB.azo skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP780\A0083486.exe/EXE-file Infected: not-a-virus:FraudTool.Win32.AntiSpyStorm.a skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP780\A0083486.exe Embedded EXE: infected - 1 skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP780\A0083486.exe UPX: infected - 1 skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP781\A0083510.exe Infected: Trojan.Win32.VB.azo skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP782\A0083536.exe Infected: Trojan.Win32.VB.azo skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP783\A0083563.exe Infected: Trojan.Win32.VB.azo skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP784\A0084586.exe Infected: not-a-virus:FraudTool.Win32.AntiSpyStorm.a skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP784\A0085586.exe Infected: Trojan.Win32.VB.azo skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP785\A0085650.exe Infected: Trojan.Win32.VB.azo skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP785\A0085687.exe/EXE-file Infected: not-a-virus:FraudTool.Win32.AntiSpyStorm.a skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP785\A0085687.exe Embedded EXE: infected - 1 skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP785\A0085687.exe UPX: infected - 1 skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP785\A0085857.dll Infected: Trojan-Downloader.Win32.VB.bkb skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP785\A0085860.exe Infected: not-virus:Hoax.Win32.Renos.kj skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP785\A0085861.dll Infected: Trojan-Clicker.Win32.Agent.lu skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP785\A0085862.dll Infected: Trojan-Clicker.Win32.Agent.lu skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP785\A0085863.exe Infected: Packed.Win32.PolyCrypt.d skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP785\A0086136.exe Infected: Trojan-Downloader.Win32.Agent.djj skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP785\A0086146.dll Infected: not-a-virus:AdWare.Win32.PurityScan.ft skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP785\A0086147.exe Infected: not-a-virus:AdWare.Win32.PurityScan.ga skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP785\A0086149.dll Infected: not-a-virus:AdWare.Win32.PurityScan.fs skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP786\A0086360.exe Infected: Trojan-Downloader.Win32.Agent.enr skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP792\A0086469.exe Infected: Trojan-Downloader.Win32.Agent.enr skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP792\A0086485.exe Infected: not-a-virus:AdWare.Win32.Agent.jn skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP797\A0086801.exe Infected: Trojan-Downloader.Win32.Agent.enr skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP802\A0086940.exe Infected: Trojan-Downloader.Win32.Agent.enr skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP809\A0087021.exe Infected: Trojan-Downloader.Win32.Agent.enr skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP811\A0087042.exe Infected: Trojan.Win32.Small.rv skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP812\A0087044.exe Infected: Trojan.Win32.VB.azo skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0087193.exe Infected: not-a-virus:AdWare.Win32.Agent.qi skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0087194.exe/stream/data0001 Infected: not-a-virus:AdWare.Win32.Agent.qi skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0087194.exe/stream Infected: not-a-virus:AdWare.Win32.Agent.qi skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0087194.exe NSIS: infected - 2 skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0087208.exe Infected: Trojan.Win32.VB.azo skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0087261.dll Infected: Trojan-Downloader.Win32.VB.bkb skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0087264.exe Infected: not-virus:Hoax.Win32.Renos.kj skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0087266.dll Infected: Trojan-Spy.Win32.Agent.ags skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0087274.exe Infected: not-a-virus:AdWare.Win32.Agent.qi skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0087278.exe Infected: Trojan-Downloader.Win32.Agent.enr skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0087292.exe Infected: Trojan-Downloader.Win32.Agent.enr skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0087452.exe Infected: Trojan-Downloader.Win32.Agent.cbx skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0087458.exe Infected: Trojan-Downloader.Win32.Agent.enr skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0087792.dll Infected: not-a-virus:AdWare.Win32.AdBand.b skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0087793.exe/stream/data0002 Infected: not-a-virus:AdWare.Win32.AdBand.b skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0087793.exe/stream Infected: not-a-virus:AdWare.Win32.AdBand.b skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0087793.exe NSIS: infected - 2 skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0087795.exe Infected: Trojan-Downloader.Win32.Agent.enr skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0088083.exe Infected: Trojan-Downloader.Win32.Agent.enr skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0088084.exe/data0002 Infected: not-a-virus:AdWare.Win32.Agent.jn skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP813\A0088084.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP814\A0088623.exe Infected: not-a-virus:FraudTool.Win32.AntiSpyStorm.a skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP814\A0088644.exe Infected: Trojan.Win32.VB.azo skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP815\A0088688.exe Infected: Trojan.Win32.VB.azo skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP816\A0088690.exe Infected: Trojan.Win32.VB.azo skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP817\A0088776.exe Infected: Trojan.Win32.VB.azo skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP822\A0103526.exe Infected: Trojan.Win32.VB.azo skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP822\A0103527.exe Infected: Trojan-Dropper.Win32.VB.tg skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP822\A0103528.exe Infected: Trojan-Downloader.Win32.Agent.djj skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP822\A0103529.exe Infected: Trojan-Downloader.Win32.Agent.enr skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP822\A0103530.exe Infected: Trojan-Downloader.Win32.Agent.bls skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP822\A0103531.exe Infected: Packed.Win32.PolyCrypt.d skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP822\A0103532.dll Infected: Trojan-Clicker.Win32.Agent.lu skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP822\A0103533.dll Infected: Trojan-Clicker.Win32.Agent.lu skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP822\A0103542.exe Infected: Trojan-Dropper.Win32.VB.tg skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP822\A0103544.exe Infected: Trojan-Downloader.Win32.Agent.djj skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP822\A0103545.exe Infected: Trojan-Downloader.Win32.Agent.enr skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP822\A0103546.exe Infected: Trojan-Downloader.Win32.Agent.bls skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP822\A0103547.exe Infected: Packed.Win32.PolyCrypt.d skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP822\A0103548.dll Infected: Trojan-Clicker.Win32.Agent.lu skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP822\A0103549.dll Infected: Trojan-Clicker.Win32.Agent.lu skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP823\A0103590.sys Infected: Trojan-Downloader.Win32.Agent.acl skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP823\A0103591.exe/data0002 Infected: not-a-virus:AdWare.Win32.Agent.qi skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP823\A0103591.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP823\A0103593.exe Infected: not-a-virus:AdWare.Win32.Agent.qi skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP823\A0103604.dll Infected: not-a-virus:AdWare.Win32.Agent.ay skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP823\A0103607.dll Infected: not-a-virus:AdWare.Win32.AdBand.c skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP823\A0103609.exe Infected: not-a-virus:Downloader.Win32.Agent.q skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP823\A0103618.exe/InpB/SskBho.dll Infected: not-a-virus:AdWare.Win32.SurfSide.t skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP823\A0103618.exe/InpB/SskCore.dll Infected: not-a-virus:AdWare.Win32.SurfSide.aa skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP823\A0103618.exe/InpB/Ssk.exe Infected: not-a-virus:AdWare.Win32.SurfSide.aa skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP823\A0103618.exe/InpB/Ssk3RepairInstall.exe Infected: not-a-virus:AdWare.Win32.SurfSide.t skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP823\A0103618.exe/InpB Infected: not-a-virus:AdWare.Win32.SurfSide.t skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP823\A0103618.exe CAB: infected - 5 skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP823\A0103619.dll Infected: not-a-virus:AdWare.Win32.MegaSearch.k skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP823\A0103622.dll Infected: not-a-virus:AdWare.Win32.Suggestor.r skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP823\A0103623.dll Infected: not-a-virus:AdWare.Win32.SurfSide.t skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP823\A0103669.dll Infected: Trojan-Downloader.Win32.VB.bkb skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP823\A0103670.exe Infected: not-virus:Hoax.Win32.Renos.kj skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP823\A0103671.exe Infected: Trojan.Win32.VB.azo skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP827\A0103911.exe/EXE-file Infected: not-a-virus:FraudTool.Win32.AntiSpyStorm.a skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP827\A0103911.exe Embedded EXE: infected - 1 skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP827\A0103911.exe UPX: infected - 1 skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP827\A0103914.exe Infected: Trojan.Win32.VB.azo skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP827\A0103916.dll Infected: Trojan-Downloader.Win32.VB.bpt skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP827\A0103917.exe Infected: not-virus:Hoax.Win32.Renos.kj skipped
C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP828\change.log Object is locked skipped
C:\UBCD4Win\plugin\Network\ipscan\ipscan.exe Infected: not-a-virus:NetTool.Win32.Portscan.c skipped
C:\UBCD4Win\plugin\Network\ultravnc\files\vnchooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.c skipped
C:\UBCD4Win\plugin\Network\ultravnc\files\vncviewer.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.1102 skipped
C:\UBCD4Win\plugin\Network\ultravnc\files\winvnc.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.c skipped
C:\UBCD4Win\plugin\Network\VNCServer\vncconfig.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\UBCD4Win\plugin\Network\VNCServer\vncviewer.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\UBCD4Win\plugin\Network\VNCServer\winvnc4.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\UBCD4Win\plugin\Network\VNCServer\wm_hooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\UBCD4Win\plugin\System-Info\Information\keyfinderpe\keyfinder.exe/data.rar/officekey.exe Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
C:\UBCD4Win\plugin\System-Info\Information\keyfinderpe\keyfinder.exe/data.rar Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
C:\UBCD4Win\plugin\System-Info\Information\keyfinderpe\keyfinder.exe RarSFX: infected - 2 skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
E:\UBCD4WinV306.exe/file3145 Infected: not-a-virus:NetTool.Win32.Portscan.c skipped
E:\UBCD4WinV306.exe/file3324 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.c skipped
E:\UBCD4WinV306.exe/file3326 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.1102 skipped
E:\UBCD4WinV306.exe/file3329 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.c skipped
E:\UBCD4WinV306.exe/file3382 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
E:\UBCD4WinV306.exe/file3385 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
E:\UBCD4WinV306.exe/file3386 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
E:\UBCD4WinV306.exe/file3387 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
E:\UBCD4WinV306.exe/file3587/data.rar/officekey.exe Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
E:\UBCD4WinV306.exe/file3587/data.rar Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
E:\UBCD4WinV306.exe/file3587 Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
E:\UBCD4WinV306.exe Inno: infected - 11 skipped
Scan process completed.
File::
C:\WINDOWS\fkwggshm.exe
C:\WINDOWS\system32\dpqaqlqx.bin
C:\WINDOWS\system32\vvgeowbv.exe
C:\WINDOWS\system32\aivskurq.dll
C:\WINDOWS\system32\stfv.bin
C:\WINDOWS\system32\ace16win.dll
C:\WINDOWS\System32\stb.exe
Folder::
C:\WINDOWS\system32\acespy
C:\Program Files\AntispyStorm
C:\Program Files\Common Files\?dobe
C:\WINDOWS\F?nts
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000000-d9e3-4bc6-a0bd-3d0ca4be5271}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000012-890e-4aac-afd9-eff6954a34dd}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{029e02f0-a0e5-4b19-b958-7bf2db29fb13}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06dfedaa-6196-11d5-bfc8-00508b4a487d}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1adbcce8-cf84-441e-9b38-afc7a19c06a4}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{51641ef3-8a7a-4d84-8659-b0911e947cc8}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53C330D6-A4AB-419B-B45D-FD4411C1FEF4}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54645654-2225-4455-44A1-9F4543D34546}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{669695bc-a811-4a9d-8cdf-ba8c795f261e}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6abc861a-31e7-4d91-b43b-d3c98f22a5c0}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{944864a5-3916-46e2-96a9-a2e84f3f1208}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a4a435cf-3583-11d4-91bd-0048546a1450}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A6E432B4-D4C2-43B3-BF55-C364F8F7362A}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b8875bfe-b021-11d4-bfa8-00508b8e9bd3}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c2680e10-1655-4a0e-87f8-4259325a84b7}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c4ca6559-2cf1-48b6-96b2-8340a06fd129}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c5af2622-8c75-4dfb-9693-23ab7686a456}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ca1d1b05-9c66-11d5-a009-000103c1e50b}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d8efadf1-9009-11d6-8c73-608c5dc19089}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9147a0a-a866-4214-b47c-da821891240f}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9306072-417e-43e3-81d5-369490beef7c}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"stb"=-
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Soeal"=-
"Jihi"=-
Logfile of HijackThis v1.99.1
Scan saved at 6:57:04 PM, on 10/28/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe
C:\Program Files\Common Files\AOL\1127353525\ee\AOLSoftware.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\aim\aim.exe
C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Network Associates\VirusScan\MCUPDATE.EXE
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\program files\aol\aol toolbar 3.1\aoltbhelper.exe
E:\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-8DBC-A42EB79CB428} - (no file)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1127353525\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [Alogserv] C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
O4 - HKLM\..\Run: [McAfee Guardian] "C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe" /SU
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [AIM] C:\Program Files\aim\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /startmonitor
O4 - HKCU\..\Run: [ISMPack7] "C:\Program Files\ISM2\ISMPack7.exe"
O4 - HKCU\..\Run: [ISMModule8] "C:\Program Files\ISM\ISMModule8.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.1\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) -
http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/…b?1125335325997
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdat…b?1125335881153
O16 - DPF: {E9670165-86FE-4C34-8C4B-D3158DDC5D92} (Installer Class) -
http://downloads.shopathomeselect.com/axin…Install4110.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVSync Manager (AvSynMgr) - Networks Associates Technologies, Inc. - C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Hope I got this right! Thanks very much,
GracesDad