Thanks again for all of your help with this! Here are the reports for Fixwareout, ComboFix, and HijackThis:
Fixwareout Report
Username "Jonathan" - 11/08/2007 22:21:15 [Fixwareout edited 9/01/2007]
~~~~~ Prerun check
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{C74B4B20-22BB-47D8-BFE7-F07800DB5C78}
"DhcpNameServer"="85.255.116.104,85.255.112.222" <Value cleared.
Successfully flushed the DNS Resolver Cache.
System was rebooted successfully.
~~~~~ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "system"=""
....
....
~~~~~ Misc files.
....
~~~~~ Checking for older varients.
....
~~~~~ Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
"ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"Display Settings"="C:\\Program Files\\HPQ\\Notebook Utilities\\hptasks.exe /s"
"QT4HPOT"="C:\\Program Files\\HPQ\\One-Touch\\OneTouch.EXE"
"SynTPLpr"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"CARPService"="carpserv.exe"
"HPDJ Taskbar Utility"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\hpztsb05.exe"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"Cpqset"="C:\\Program Files\\HPQ\\Default Settings\\cpqset.exe"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_02\\bin\\jusched.exe\""
"HP Software Update"="C:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWuSchd2.exe"
"mcagent_exe"="C:\\Program Files\\McAfee.com\\Agent\\mcagent.exe /runkey"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\QTTask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PhotoShow Deluxe Media Manager"="C:\\PROGRA~1\\Ahead\\NEROPH~1\\data\\Xtras\\mssysmgr.exe"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"Aim6"=""
"Yahoo! Pager"="\"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe\" -quiet"
"WMPNSCFG"="C:\\Program Files\\Windows Media Player\\WMPNSCFG.exe"
....
Hosts file was reset, If you use a custom hosts file please replace it...
~~~~~ End report ~~~~~
----------------------------------------------------------------------------------------------------------------------
ComboFix Log
ComboFix 07-11-08.1 - Jonathan 2007-11-08 23:29:20.2 - NTFSx86
Running from: C:\Documents and Settings\Jonathan\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2007-10-09 to 2007-11-09 )))))))))))))))))))))))))))))))
.
2007-11-08 11:45 3,242 --a------ C:\WINDOWS\system32\tmp.reg
2007-11-08 11:17 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-06 20:49 <DIR> d-------- C:\Program Files\iTunes
2007-11-06 20:40 <DIR> d-------- C:\Program Files\QuickTime
2007-11-05 10:37 <DIR> d-------- C:\Program Files\Trend Micro
2007-10-22 13:39 <DIR> d-------- C:\Program Files\Hp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-07 18:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2007-11-07 01:50 --------- d-----w C:\Program Files\iPod
2007-11-04 04:10 --------- d-----w C:\Documents and Settings\Jonathan\Application Data\uTorrent
2007-11-02 14:19 --------- d-----w C:\Program Files\McAfee
2007-11-02 02:47 --------- d-----w C:\Program Files\Common Files\McAfee
2007-09-26 23:16 --------- d-----w C:\Program Files\DivX
2007-09-17 18:23 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-09-17 18:23 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2007-09-17 18:22 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2007-09-17 18:22 739,840 ----a-w C:\WINDOWS\system32\DivX.dll
2007-09-17 15:13 --------- d-----w C:\Program Files\Apple Software Update
2007-09-12 05:28 --------- d-----w C:\Program Files\Java
2007-09-12 05:06 --------- d-----w C:\Program Files\Sun
2007-09-11 23:14 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-21 06:15 683,520 ------w C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-08-21 00:26 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-08-21 00:26 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2007-08-20 10:04 824,832 ----a-w C:\WINDOWS\system32\dllcache\wininet.dll
2007-08-20 10:04 671,232 ----a-w C:\WINDOWS\system32\dllcache\mstime.dll
2007-08-20 10:04 63,488 ------w C:\WINDOWS\system32\dllcache\icardie.dll
2007-08-20 10:04 6,058,496 ------w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-08-20 10:04 52,224 ------w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-08-20 10:04 477,696 ----a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-08-20 10:04 459,264 ------w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-08-20 10:04 44,544 ------w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-08-20 10:04 384,512 ------w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-08-20 10:04 383,488 ------w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-08-20 10:04 3,584,512 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-08-20 10:04 27,648 ----a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-08-20 10:04 267,776 ------w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-08-20 10:04 232,960 ----a-w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-08-20 10:04 230,400 ------w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-08-20 10:04 214,528 ----a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-08-20 10:04 193,024 ----a-w C:\WINDOWS\system32\dllcache\msrating.dll
2007-08-20 10:04 153,088 ------w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-08-20 10:04 132,608 ----a-w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-08-20 10:04 124,928 ----a-w C:\WINDOWS\system32\dllcache\advpack.dll
2007-08-20 10:04 105,984 ----a-w C:\WINDOWS\system32\dllcache\url.dll
2007-08-20 10:04 102,400 ------w C:\WINDOWS\system32\dllcache\occache.dll
2007-08-20 10:04 1,152,000 ----a-w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-08-17 10:21 625,152 ----a-w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-08-17 10:20 63,488 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-08-17 10:20 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-08-17 07:34 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-08-15 22:33 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2007-08-15 22:33 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-08-15 22:33 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2007-08-15 22:33 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-08-15 22:31 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-08-15 22:31 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2007-08-15 22:31 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-08-15 22:31 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2007-08-15 22:31 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2007-08-15 22:31 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2007-08-15 22:30 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2006-08-18 03:07 91,256 ----a-w C:\Documents and Settings\Jonathan\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((( snapshot@2007-11-08_11.38.37.93 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-11-08 14:33:12 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2007-11-09 03:40:29 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2007-11-08 14:33:12 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-11-09 03:40:29 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-11-09 03:40:29 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2007-11-08 14:32:53 63,700 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2007-11-09 03:28:46 63,700 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2007-11-08 14:32:53 404,752 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2007-11-09 03:28:46 404,752 ----a-w C:\WINDOWS\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2002-08-14 20:29]
"Display Settings"="C:\Program Files\HPQ\Notebook Utilities\hptasks.exe" [2002-08-15 09:26]
"QT4HPOT"="C:\Program Files\HPQ\One-Touch\OneTouch.EXE" [2003-03-13 10:14]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-04 17:40]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-04 17:38]
"CARPService"="carpserv.exe" [2003-05-21 17:35 C:\WINDOWS\system32\carpserv.exe]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe" [2002-05-24 07:46]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-04-25 08:26]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2005-02-17 14:01]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 03:00]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2007-05-08 15:24]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-03 21:33]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-10-19 20:16]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-02 18:36]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PhotoShow Deluxe Media Manager"="C:\PROGRA~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]
"Aim6"="" []
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 17:43]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 20:05]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce]
"DelayShred"="c:\program files\mcafee\mshr\ShrCL.EXE" /P2 /q C:\DOCUME~1\Jonathan\LOCALS~1\Temp\TEMPOR~1\Content.SH! C:\DOCUME~1\Jonathan\LOCALS~1\Temp\TEMPOR~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\Temp\History\History.IE5\MSHIST~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\Temp\History\History.SH! C:\DOCUME~1\Jonathan\LOCALS~1\Temp\History.SH! C:\DOCUME~1\Jonathan\LOCALS~1\Temp\Cookies.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\6XVCXCJ6\AIM_UA~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\L7RYJO5Y\ADBRIT~3.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\XEF6AZAB\AD411B~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\ASPM5SSA\ADBRIT~4.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\Y0VAXKE6\ADBRIT~2.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\Y0VAXKE6\WEB_AN~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C3C5W67C\WEB_AN~3.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C3C5W67C\ADBRIT~3.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\1V6B0XCQ\WEB_AN~4.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\XEF6AZAB\ADBRIT~4.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\ASPM5SSA\WEB_AN~4.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\ASPM5SSA\AD4D0B~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\7YMPBCM5\ADBRIT~2.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\ZWBPO4LH\ADBRIT~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\TQ0TBO1A\WEB_AN~3.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\L7RYJO5Y\AD451B~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\ODYQ5GN1\WEB_AN~2.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\L89PBDOE\IMG_3_~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\ODYQ5GN1\ADBRIT~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\VMLF6W5Y\STYLES~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\L7RYJO5Y\WEB_AN~3.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\ASPM5SSA\WEF710~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\XPTEYOJ1\CSS_DR~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\XPTEYOJ1\IMG_6_~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\TQ0TBO1A\780X90~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\TQ0TBO1A\WEB_AN~4.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\L89PBDOE\IMG_4_~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\ASPM5SSA\IMG_8_~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\IEE3PYPI\ADBRIT~3.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\L7RYJO5Y\WEF712~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\7YMPBCM5\ADBRIT~3.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\TQ0TBO1A\IMGCAV~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\L7RYJO5Y\WE081C~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\1V6B0XCQ\IMG_10~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\ODYQ5GN1\WEB_AN~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\Y0VAXKE6\ADBRIT~3.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\VMLF6W5Y\WEB_AN~4.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\L89PBDOE\WEB_AN~2.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\TQ0TBO1A\IMGCAM~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\ODYQ5GN1\AD4D0B~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\ASPM5SSA\WE3C5B~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\7YMPBCM5\AD4D1B~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\ODYQ5GN1\IMG_11~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\FQ5UJLIX\HBX_2_~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\269UC60C\WEB_AN~2.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C5EVD6BW\ADBRIT~2.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\2AOAXHCE\ADBRIT~3.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\4X72PDOH\WEF712~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C5EVD6BW\ADBRIT~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\D0GQTWWY\ADBRIT~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\EY8ZIE90\WEB_AN~2.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\HNYG52Z2\IMG_10~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C4JBM551\ADBRIT~2.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\4X72PDOH\AD4D1B~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\D0GQTWWY\ADBRIT~2.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\HNYG52Z2\IMG_9_~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\EY8ZIE90\WEB_AN~3.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C4JBM551\ADBRIT~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C4JBM551\WEB_AN~3.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\FQ5UJLIX\WEB_AN~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C4JBM551\IMG_8_~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\269UC60C\AD491B~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C5EVD6BW\WEB_AN~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\FQ5UJLIX\ADBRIT~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\269UC60C\AD451B~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C4JBM551\WEB_AN~4.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\FQ5UJLIX\LOG_1_~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\2AOAXHCE\ADBRIT~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C4JBM551\IMGCAR~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\4X72PDOH\IMG_9_~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\FQ5UJLIX\WEB_AN~4.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\FQ5UJLIX\AD4D0B~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\FQ5UJLIX\ADBRIT~2.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\4X72PDOH\IMG_5_~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\4X72PDOH\WEB_AN~3.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C4JBM551\IMGCAF~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\IIY0WY41\WEB_AN~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\IIY0WY41\AD4D0B~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C4JBM551\IMGCA3~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\IIY0WY41\AD411B~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\IIY0WY41\WEF710~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\269UC60C\WEF712~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\5W43WW64\ADBRIT~2.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\2AOAXHCE\ADBRIT~2.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\4X72PDOH\ADBRIT~2.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\5W43WW64\IMG_7_~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C4JBM551\WEF710~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\EY8ZIE90\AD4D0B~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C5EVD6BW\ADBRIT~3.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\4X72PDOH\ADBRIT~3.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\269UC60C\AD411B~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C5EVD6BW\WEF710~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\2AOAXHCE\WEB_AN~4.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\EY8ZIE90\ADBRIT~4.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\2AOAXHCE\WEF710~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\HNYG52Z2\WEB_AN~2.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\2AOAXHCE\WEB_AN~2.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\269UC60C\IMG_4_~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\269UC60C\ADBRIT~2.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C5EVD6BW\WEB_AN~4.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\2AOAXHCE\WEF712~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\HNYY12I7\WEB_AN~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\D0GQTWWY\WEB_AN~2.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C4JBM551\WEF712~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\IIY0WY41\IMG_7_~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\IIY0WY41\ADBRIT~4.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\HNYY12I7\ADBRIT~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C4JBM551\IMG_10~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C5EVD6BW\WEB_AN~2.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\EY8ZIE90\WEB_AN~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\D0GQTWWY\WEB_AN~4.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C5EVD6BW\ADBRIT~4.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\IIY0WY41\AD451B~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\4X72PDOH\WE081C~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\4X72PDOH\IMGCAA~2.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\D0GQTWWY\IMG_6_~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\4X72PDOH\IMG_1_~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\EY8ZIE90\IMG_3_~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\IIY0WY41\IMGCAJ~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\5W43WW64\IMGCA7~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\5W43WW64\IMGCAH~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\FQ5UJLIX\ADBRIT~3.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\IIY0WY41\IMG_10~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\IIY0WY41\WEB_AN~4.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\EY8ZIE90\AD411B~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\4X72PDOH\IMG_4_~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\IIY0WY41\IMGCAI~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\4X72PDOH\AD4D0B~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\4X72PDOH\AD99AE~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\5W43WW64\ADBRIT~3.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\269UC60C\ADBRIT~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\D0GQTWWY\WEB_AN~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\D0GQTWWY\WEF712~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C4JBM551\IMGCAH~2.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C4JBM551\IMG_6_~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\4X72PDOH\WEB_AN~2.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C4JBM551\IMGCAS~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\4X72PDOH\AD99A4~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\HNYG52Z2\ADBRIT~3.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\HNYG52Z2\WEB_AN~3.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\5W43WW64\WEB_AN~3.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C4JBM551\WE081A~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\5W43WW64\WEB_AN~4.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\269UC60C\WEB_AN~3.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\269UC60C\ADBRIT~3.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\5W43WW64\IMGCA6~3.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\4X72PDOH\ADBRIT~4.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\4X72PDOH\WEB_AN~4.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\4X72PDOH\AD491B~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\5W43WW64\IMG_11~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C4JBM551\ADBRIT~4.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\D0GQTWWY\WEB_AN~3.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C4JBM551\WEB_AN~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\IIY0WY41\IMG_4_~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\4X72PDOH\IMGCAV~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\HNYG52Z2\ADBRIT~2.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\IIY0WY41\IMGCAU~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C4JBM551\IMGCA2~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C4JBM551\IMG_4_~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\IIY0WY41\WEB_AN~3.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\2AOAXHCE\WEB_AN~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\HNYG52Z2\WEB_AN~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C5EVD6BW\WEF712~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\HNYG52Z2\AD4D0B~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\269UC60C\AD4D1B~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C5EVD6BW\WEF716~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\269UC60C\ADBRIT~4.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\269UC60C\IMG_7_~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\5W43WW64\WEB_AN~2.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C4JBM551\WE1F00~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\EY8ZIE90\PC_1_~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\5W43WW64\ADBRIT~4.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\2AOAXHCE\WEB_AN~3.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\IIY0WY41\ADBRIT~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C4JBM551\WE1B00~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\4X72PDOH\IMGCAO~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\5W43WW64\IMGCAT~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\5W43WW64\IMGCAK~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\5W43WW64\AD411B~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\5W43WW64\IMGCAM~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\5W43WW64\IMGCAX~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\IIY0WY41\AD99AE~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\4X72PDOH\WEB_AN~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\5W43WW64\IMG_6_~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\IIY0WY41\WEF716~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\4X72PDOH\AD9A64~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\4X72PDOH\WEF710~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\4X72PDOH\AD411B~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\5W43WW64\IMGCA2~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\FQ5UJLIX\ADBRIT~4.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\IIY0WY41\AD4D1B~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C4JBM551\AD4D0B~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C4JBM551\IMGCAN~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\IIY0WY41\IMGCAC~2.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\5W43WW64\IMGCA6~2.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\IIY0WY41\AD99A4~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C4JBM551\IMGCAS~3.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\4X72PDOH\BANNER~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\5W43WW64\IMGCA6~4.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\5W43WW64\IMGCAL~2.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\5W43WW64\ADBRIT~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\IIY0WY41\IMGCA3~2.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\5W43WW64\WEF712~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\IIY0WY41\IMGCAY~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\IIY0WY41\WE081C~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C4JBM551\IMGCAE~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\4X72PDOH\AD9D11~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C4JBM551\WEF716~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C4JBM551\WE081C~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\5W43WW64\WEF710~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C4JBM551\IMGCA3~3.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\4X72PDOH\IMGCAZ~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C4JBM551\IMGCAX~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C4JBM551\WEC782~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\5W43WW64\IMGCAB~3.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\5W43WW64\IMGCAP~2.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C4JBM551\IMGCAO~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\IIY0WY41\IMGCA7~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\5W43WW64\WEF716~1.SH!
C:\Documents and Settings\Jonathan\Start Menu\Programs\Startup\
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2004-06-18 00:05:15]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^EZVideo Chat.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\EZVideo Chat.lnk
backup=C:\WINDOWS\pss\EZVideo Chat.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak software updater.lnk
backup=C:\WINDOWS\pss\Kodak software updater.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^MyWebSearch Email Plugin.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MyWebSearch Email Plugin.lnk
backup=C:\WINDOWS\pss\MyWebSearch Email Plugin.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
backup=C:\WINDOWS\pss\Quicken Scheduled Updates.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SnapDetect.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SnapDetect.lnk
backup=C:\WINDOWS\pss\SnapDetect.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Jonathan^Start Menu^Programs^Startup^MyWebSearch Email Plugin.lnk]
path=C:\Documents and Settings\Jonathan\Start Menu\Programs\Startup\MyWebSearch Email Plugin.lnk
backup=C:\WINDOWS\pss\MyWebSearch Email Plugin.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Jonathan^Start Menu^Programs^Startup^Webshots.lnk]
path=C:\Documents and Settings\Jonathan\Start Menu\Programs\Startup\Webshots.lnk
backup=C:\WINDOWS\pss\Webshots.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeviceDiscovery]
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DIGStream]
C:\Program Files\DIGStream\digstream.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
"C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]
C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
"C:\Program Files\Microsoft Money\System\mnyexpr.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickFinder Scheduler]
"C:\Program Files\Corel\WordPerfect Office 2002\Programs\QFSCHD100.EXE"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
"C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TV Now]
C:\Program Files\HPQ\Notebook Utilities\TvNow.exe /RK
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WildTangent CDA]
"C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe" /startup "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0500.dll"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\x3watch]
C:\Program Files\X3watch\x3watch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"iPodService"=3 (0x3)
R3 CALIAUD;Conexant AMC 3D Environmental Audio;C:\WINDOWS\system32\drivers\caliaud.sys
R3 CALIHALA;CALIHALA;C:\WINDOWS\system32\drivers\calihal.sys
R3 DKbFltr;Dritek HotKey Keyboard Filter Driver;C:\WINDOWS\system32\Drivers\DKbFltr.SYS
R3 DP83815;National Semiconductor Corp. DP83815/816 NDIS 5.0 Miniport Driver;C:\WINDOWS\system32\DRIVERS\DP83815.SYS
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver;C:\WINDOWS\system32\drivers\WmBEnum.sys
R3 WmFilter;Logitech WingMan HID Filter Driver;C:\WINDOWS\system32\drivers\WmFilter.sys
R3 WmXlCore;Logitech WingMan Translation Layer Driver;C:\WINDOWS\system32\drivers\WmXlCore.sys
S3 ALiIRDA;ALi Infrared Device Driver;C:\WINDOWS\system32\DRIVERS\aliirda.sys
S3 CE3;Xircom Ethernet Adapter 10/100 Service;C:\WINDOWS\system32\DRIVERS\ce3n5.sys
S3 KMW_KBD;Kensington Input Devices Class filter driver;C:\WINDOWS\system32\DRIVERS\KMW_KBD.sys
S3 KMW_USB;Kensington MouseWorks USB filter driver;C:\WINDOWS\system32\DRIVERS\KMW_USB.sys
S3 WmVirHid;Logitech Virtual Hid Device Driver;C:\WINDOWS\system32\drivers\WmVirHid.sys
.
Contents of the 'Scheduled Tasks' folder
"2007-11-07 00:01:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-07-15 05:01:15 C:\WINDOWS\Tasks\McDefragTask.job"
- C:\WINDOWS\system32\defrag.exe
"2007-10-01 05:02:35 C:\WINDOWS\Tasks\McQcTask.job"
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-08 23:36:35
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe????????4?9?1?5??????? ???B?????????????hLC? ??????
scanning hidden files ...
**************************************************************************
.
Completion time: 2007-11-08 23:38:53
C:\ComboFix2.txt ... 2007-11-08 11:40
.
--- E O F ---
----------------------------------------------------------------------------------------------
HijackThis Report
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:40:50 PM, on 11/8/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\HPQ\One-Touch\OneTouch.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://mail.lycos.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://us.rd.yahoo.c...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.c...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.c...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://us.rd.yahoo.c...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://us8l.hpwis.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Display Settings] C:\Program Files\HPQ\Notebook Utilities\hptasks.exe /s
O4 - HKLM\..\Run: [QT4HPOT] C:\Program Files\HPQ\One-Touch\OneTouch.EXE
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\RunOnce: [DelayShred] "c:\program files\mcafee\mshr\ShrCL.EXE" /P2 /q C:\DOCUME~1\Jonathan\LOCALS~1\Temp\TEMPOR~1\Content.SH! C:\DOCUME~1\Jonathan\LOCALS~1\Temp\TEMPOR~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\Temp\History\History.IE5\MSHIST~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\Temp\History\History.SH! C:\DOCUME~1\Jonathan\LOCALS~1\Temp\History.SH! C:\DOCUME~1\Jonathan\LOCALS~1\Temp\Cookies.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\6XVCXCJ6\AIM_UA~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\L7RYJO5Y\ADBRIT~3.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\XEF6AZAB\AD411B~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\ASPM5SSA\ADBRIT~4.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\Y0VAXKE6\ADBRIT~2.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\Y0VAXKE6\WEB_AN~1.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C3C5W67C\WEB_AN~3.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR~1\Content.IE5\C3C5W67C\ADBRIT~3.SH! C:\DOCUME~1\Jonathan\LOCALS~1\TEMPOR
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Search -
http://ka.bar.need2f...earch.html?p=KA
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://us8l.hpwis.com
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
http://a1540.g.akama...ex/qtplugin.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) -
http://download.mcaf...99/mcinsctl.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) -
http://upload.facebo...otoUploader.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} -
http://a1540.g.akama...meInstaller.exe
O16 - DPF: {C946EF6D-296D-4907-A6E1-ED0E8E5AF024} (LycosMail Upload Control) -
http://mail.lycos.co.../AttachMail.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -
http://games.pogo.co...aploader_v5.cab
O16 - DPF: {FCEAE646-DCF9-4D59-B994-6BD30A315139} -
http://www.mtv.com/o...e/bin/setup.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/Jonathan/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg
--
End of file - 10992 bytes