Simon V. -
Thanks for the advice. I never even used utorrent, so I removed it.
Lately I've started getting a new problem. First my active desktop switches off and the taskbar at the bottom disappears. Eventually I get it back, but after a few minutes it goes again. This repeats and then it goes out all together, no taskbar, no desktop icons, no start button, etc. I have to switch off the computer and restart it everytime now.
Anyway, here's the logs:
ComboFix 07-11-08.1 - Dr. Becker 2007-11-15 14:07:26.3 - NTFSx86
Running from: C:\Documents and Settings\Dr. Becker\Desktop\ComboFix.exe
.
Unable to gain System Privileges
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\Dr. Becker\Desktop\Live Safety Center.lnk
C:\Documents and Settings\Dr. Becker\Desktop\Online Security Guide.lnk
C:\Documents and Settings\Dr. Becker\Favorites\Online Security Guide.lnk
C:\Program Files\MSN Gaming Zone\qulac.dll
C:\Program Files\MSN Gaming Zone\qulac260.dll
C:\Program Files\MSN Gaming Zone\qulac561.dll
C:\Program Files\MSN Gaming Zone\qulac905.dll
C:\Program Files\MSN Gaming Zone\qulac99.dll
C:\Program Files\MSN Gaming Zone\rterteq.html
C:\WINDOWS\system32\fsrmddmb.dllbox
C:\WINDOWS\system32\kjkmp.ini
C:\WINDOWS\system32\kjkmp.ini2
C:\WINDOWS\system32\pmkjk.dll
C:\WINDOWS\tk58.exe
C:\WINDOWS\TTC-4444.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
-------\DomainService
((((((((((((((((((((((((( Files Created from 2007-10-15 to 2007-11-15 )))))))))))))))))))))))))))))))
.
2007-11-15 12:47 79,936 --a------ C:\WINDOWS\system32\yusqhtfk.dll
2007-11-15 12:45 85,056 --a------ C:\WINDOWS\system32\ygfqwwwq.dll
2007-11-15 12:38 71,232 --a------ C:\WINDOWS\system32\pnruhefb.exe
2007-11-14 13:45 <DIR> d-------- C:\Program Files\CCleaner
2007-11-12 17:10 3,446 --a------ C:\WINDOWS\system32\tmp.reg
2007-11-12 16:15 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-12 14:27 89,664 --a------ C:\WINDOWS\system32\ovlatrso.dll
2007-11-12 14:26 81,472 --a------ C:\WINDOWS\system32\rideayao.dll
2007-11-12 14:22 71,232 --a------ C:\WINDOWS\system32\lderhtgi.exe
2007-11-12 10:27 81,472 --a------ C:\WINDOWS\system32\ssmjbbtw.dll
2007-11-12 10:23 71,232 --a------ C:\WINDOWS\system32\gswhdehk.exe
2007-11-10 15:02 71,232 --a------ C:\WINDOWS\system32\klabving.exe
2007-11-09 18:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-09 18:20 <DIR> d-------- C:\VundoFix Backups
2007-11-09 13:42 77,888 --a------ C:\WINDOWS\system32\decpntbb.dll
2007-11-09 13:39 145,984 --a------ C:\WINDOWS\system32\fsrmddmb.dll
2007-11-09 13:38 145,984 --a------ C:\WINDOWS\system32\qjmjuqhu.dll
2007-11-09 13:36 71,232 --a------ C:\WINDOWS\system32\rqtdidvs.exe
2007-11-08 12:50 35,840 -ra------ C:\WINDOWS\mrofinu572.exe
2007-11-08 00:48 35,328 --a------ C:\WINDOWS\system32\gebxvvt.dll
2007-11-08 00:41 35,840 --a------ C:\WINDOWS\mrofinu1000106.exe
2007-11-08 00:40 <DIR> d-------- C:\WINDOWS\system32\Mz02r
2007-11-08 00:40 <DIR> d-------- C:\Temp\mZOr
2007-11-08 00:40 <DIR> d-------- C:\Temp
2007-11-08 00:40 35,328 --a------ C:\WINDOWS\system32\ddcayax.dll
2007-10-31 15:31 <DIR> d-------- C:\Documents and Settings\All Users\SonicStage
2007-10-31 15:24 90,112 --------- C:\WINDOWS\snymsico.dll
2007-10-31 15:24 38,951 --a------ C:\WINDOWS\system32\drivers\NETMDUSB.sys
2007-10-31 15:24 36,679 --a------ C:\WINDOWS\system32\drivers\NETMD052.sys
2007-10-31 15:24 36,232 --a------ C:\WINDOWS\system32\drivers\NETMD033.sys
2007-10-31 15:24 35,319 --a------ C:\WINDOWS\system32\drivers\NETMD031.sys
2007-10-31 15:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Sony Corporation
2007-10-31 15:19 <DIR> d-------- C:\Program Files\Sony
2007-10-31 15:17 <DIR> d-------- C:\Program Files\Common Files\Sony Shared
2007-10-31 15:17 <DIR> d-------- C:\Documents and Settings\Dr. Becker\Application Data\Sony Corporation
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-31 23:24 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-26 03:36 8,454,656 ------w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-11 00:14 --------- d-----w C:\Documents and Settings\Dr. Becker\Application Data\Corel
2007-10-03 22:16 --------- d-----w C:\Documents and Settings\Dr. Becker\Application Data\uTorrent
2007-10-01 18:45 --------- d-----w C:\Program Files\uTorrent
2007-09-23 04:41 --------- d-----w C:\Program Files\Audacity
2007-09-15 17:44 --------- d-----w C:\Program Files\Google
2007-08-22 13:12 96,256 ------w C:\WINDOWS\system32\dllcache\inseng.dll
2007-08-22 13:12 658,944 ------w C:\WINDOWS\system32\dllcache\wininet.dll
2007-08-22 13:12 615,424 ------w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-08-22 13:12 55,808 ------w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-08-22 13:12 532,480 ------w C:\WINDOWS\system32\dllcache\mstime.dll
2007-08-22 13:12 474,112 ------w C:\WINDOWS\system32\dllcache\shlwapi.dll
2007-08-22 13:12 449,024 ------w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-08-22 13:12 39,424 ------w C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-08-22 13:12 357,888 ------w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-08-22 13:12 3,058,176 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-08-22 13:12 251,392 ------w C:\WINDOWS\system32\dllcache\iepeers.dll
2007-08-22 13:12 205,312 ------w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-08-22 13:12 16,384 ------w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-08-22 13:12 151,040 ------w C:\WINDOWS\system32\dllcache\cdfview.dll
2007-08-22 13:12 146,432 ------w C:\WINDOWS\system32\dllcache\msrating.dll
2007-08-22 13:12 1,494,528 ------w C:\WINDOWS\system32\dllcache\shdocvw.dll
2007-08-22 13:12 1,054,208 ------w C:\WINDOWS\system32\dllcache\danim.dll
2007-08-22 13:12 1,022,976 ------w C:\WINDOWS\system32\dllcache\browseui.dll
2007-08-21 10:30 18,432 ------w C:\WINDOWS\system32\dllcache\iedw.exe
2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-21 06:15 683,520 ------w C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-01-23 19:10 43,072 ----a-w C:\Documents and Settings\Dr. Becker\Application Data\GDIPFONTCACHEV1.DAT
2006-12-05 18:42 192,768 ----a-w C:\WINDOWS\inf\MA521_patch\MA521nd5.sys
2006-04-26 01:30 35,232 ----a-w C:\WINDOWS\inf\MA521_patch\ME_INST.EXE
2006-04-26 01:30 212,992 ----a-w C:\WINDOWS\inf\MA521_patch\CopyWHQLDriver.exe
2006-04-26 01:30 14,848 ----a-w C:\WINDOWS\inf\MA521_patch\INST2000.DLL
2005-06-15 22:48 43,072 ----a-w C:\Documents and Settings\Owner\Application Data\GDIPFONTCACHEV1.DAT
2001-08-18 12:00:00 94,784 --sha-w C:\WINDOWS\twain.dll
2004-08-04 08:56:48 50,688 --sha-w C:\WINDOWS\twain_32.dll
2004-08-04 08:56:44 1,028,096 --sha-w C:\WINDOWS\system32\mfc42.dll
2004-08-04 08:56:44 54,784 --sha-w C:\WINDOWS\system32\msvcirt.dll
2004-08-04 08:56:44 413,696 --sha-w C:\WINDOWS\system32\msvcp60.dll
2004-08-04 08:56:44 343,040 --sha-w C:\WINDOWS\system32\msvcrt.dll
2007-05-17 11:28:05 549,376 --sha-w C:\WINDOWS\system32\oleaut32.dll
2004-08-04 08:56:46 83,456 --sha-w C:\WINDOWS\system32\olepro32.dll
2004-08-04 08:56:56 11,776 --sha-w C:\WINDOWS\system32\regsvr32.exe
.
((((((((((((((((((((((((((((( snapshot@2007-11-12_16.58.35.75 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-09-28 05:19:39 18,089,592 ----a-w C:\WINDOWS\system32\MRT.exe
+ 2007-11-02 07:12:57 18,238,072 ----a-w C:\WINDOWS\system32\MRT.exe
- 2006-12-19 21:52:18 8,453,632 ----a-w C:\WINDOWS\system32\shell32.dll
+ 2007-10-26 03:36:51 8,454,656 ----a-w C:\WINDOWS\system32\shell32.dll
- 2007-08-21 10:20:02 115,712 ----a-w C:\WINDOWS\system32\xpsp3res.dll
+ 2007-10-29 10:26:53 115,712 ----a-w C:\WINDOWS\system32\xpsp3res.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{05D02035-9EB4-453C-87BB-013C3F785C18}]
2007-11-15 14:37 313952 --a------ C:\WINDOWS\system32\awtss.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1C1DD717-53B2-485E-A17B-C9977C205E10}]
2007-11-08 00:40 35328 --a------ C:\WINDOWS\system32\ddcayax.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{92065620-a8c4-4dfe-a1aa-ea405709d4f7}]
2007-11-15 12:47 79936 --a------ C:\WINDOWS\system32\yusqhtfk.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
2007-11-09 13:39 145984 --a------ C:\WINDOWS\system32\fsrmddmb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\fsrmddmb.dll [2007-11-09 13:39 145984]
[HKEY_CLASSES_ROOT\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\fsrmddmb.dll [2007-11-09 13:39 145984]
[HKEY_CLASSES_ROOT\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CARPService"="carpserv.exe" [2003-05-21 15:35 C:\WINDOWS\system32\carpserv.exe]
"ATIModeChange"="Ati2mdxx.exe" [2002-06-11 20:14 C:\WINDOWS\system32\Ati2mdxx.exe]
"AtiPTA"="atiptaxx.exe" [2002-06-11 20:56 C:\WINDOWS\system32\atiptaxx.exe]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2002-05-02 13:48]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2002-05-02 13:47]
"HP TV Now"="C:\Program Files\Hewlett-Packard\HP TV Now\HpTvNow.exe" [2002-07-29 12:50]
"HP Display Settings"="C:\Program Files\Hewlett-Packard\HP Notebook Utilities\hptasks.exe" [2002-07-16 12:23]
"PreloadApp"="c:\hp\drivers\printers\photosmart\hphprld.exe" [2001-12-12 06:05]
"QT4HPOT"="C:\PROGRA~1\HEWLET~1\ONE-TO~1\OneTouch.EXE" [2002-04-20 12:56]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [2001-07-19 13:50]
"NAV Agent"="C:\PROGRA~1\NORTON~1\navapw32.exe" [2002-02-27 10:27]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2002-03-14 03:25]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2005-03-31 10:16]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2004-12-20 10:41]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2005-10-06 17:03]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 09:54]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 02:06]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 08:24]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" []
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{1C1DD717-53B2-485E-A17B-C9977C205E10}"= C:\WINDOWS\system32\ddcayax.dll [2007-11-08 00:40 35328]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddcayax]
ddcayax.dll 2007-11-08 00:40 35328 C:\WINDOWS\system32\ddcayax.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fsrmddmb]
fsrmddmb.dll 2007-11-09 13:39 145984 C:\WINDOWS\system32\fsrmddmb.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\awtss.dll
.
Contents of the 'Scheduled Tasks' folder
"2007-11-03 03:00:00 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job"
- C:\PROGRA~1\NORTON~1\NAVW32.exe
"2005-03-31 18:20:23 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-15 14:34:41
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\WINDOWS\system32\sstwa.ini 317 bytes
C:\WINDOWS\system32\sstwa.ini2 317 bytes
scan completed successfully
hidden files: 2
**************************************************************************
.
Completion time: 2007-11-15 14:42:50 - machine was rebooted
C:\ComboFix2.txt ... 2007-11-12 17:02
.
--- E O F ---
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Friday, November 16, 2007 12:12:39 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 16/11/2007
Kaspersky Anti-Virus database records: 460072
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
Scan Statistics:
Total number of scanned objects: 45736
Number of viruses found: 18
Number of infected objects: 108
Number of suspicious objects: 0
Duration of the scan process: 02:00:59
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\Dr. Becker\Application Data\Mozilla\Firefox\Profiles\vadkad0z.default\cert8.db Object is locked skipped
C:\Documents and Settings\Dr. Becker\Application Data\Mozilla\Firefox\Profiles\vadkad0z.default\history.dat Object is locked skipped
C:\Documents and Settings\Dr. Becker\Application Data\Mozilla\Firefox\Profiles\vadkad0z.default\key3.db Object is locked skipped
C:\Documents and Settings\Dr. Becker\Application Data\Mozilla\Firefox\Profiles\vadkad0z.default\parent.lock Object is locked skipped
C:\Documents and Settings\Dr. Becker\Application Data\Mozilla\Firefox\Profiles\vadkad0z.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Dr. Becker\Application Data\Mozilla\Firefox\Profiles\vadkad0z.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Dr. Becker\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Dr. Becker\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Dr. Becker\Desktop\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Dr. Becker\Desktop\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Dr. Becker\Desktop\SmitfraudFix.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\Dr. Becker\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Dr. Becker\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Dr. Becker\Local Settings\Application Data\Mozilla\Firefox\Profiles\vadkad0z.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Dr. Becker\Local Settings\Application Data\Mozilla\Firefox\Profiles\vadkad0z.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Dr. Becker\Local Settings\Application Data\Mozilla\Firefox\Profiles\vadkad0z.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Dr. Becker\Local Settings\Application Data\Mozilla\Firefox\Profiles\vadkad0z.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Dr. Becker\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Dr. Becker\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Dr. Becker\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Dr. Becker\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Messenger\mezojelis4444.dll Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\Program Files\Messenger\mezojelis83122.dll Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\qoobox\Quarantine\C\Program Files\MSN Gaming Zone\qulac.dll.vir Infected: Trojan.Win32.BHO.ab skipped
C:\qoobox\Quarantine\C\Program Files\MSN Gaming Zone\qulac260.dll.vir Infected: Trojan.Win32.BHO.ab skipped
C:\qoobox\Quarantine\C\Program Files\MSN Gaming Zone\qulac561.dll.vir Infected: Trojan.Win32.BHO.ab skipped
C:\qoobox\Quarantine\C\Program Files\MSN Gaming Zone\qulac62.dll.vir Infected: Trojan.Win32.BHO.ab skipped
C:\qoobox\Quarantine\C\Program Files\MSN Gaming Zone\qulac724.dll.vir Infected: Trojan.Win32.BHO.ab skipped
C:\qoobox\Quarantine\C\Program Files\MSN Gaming Zone\qulac872.dll.vir Infected: Trojan.Win32.BHO.ab skipped
C:\qoobox\Quarantine\C\Program Files\MSN Gaming Zone\qulac905.dll.vir Infected: Trojan.Win32.BHO.ab skipped
C:\qoobox\Quarantine\C\Program Files\MSN Gaming Zone\qulac93.dll.vir Infected: Trojan.Win32.BHO.ab skipped
C:\qoobox\Quarantine\C\Program Files\MSN Gaming Zone\qulac99.dll.vir Infected: Trojan.Win32.BHO.ab skipped
C:\qoobox\Quarantine\C\Program Files\MSN Gaming Zone\rterteq.html.vir Infected: Trojan-Clicker.HTML.IFrame.dn skipped
C:\qoobox\Quarantine\C\Program Files\Network Monitor\netmon.exe.vir Infected: not-a-virus:Monitor.Win32.NetMon.a skipped
C:\qoobox\Quarantine\C\WINDOWS\IA\asappsrv.dll.vir Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\qoobox\Quarantine\C\WINDOWS\IA\command.exe.vir Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\a1\rarndrll2.exe.vir Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\g2\caws83122.exe.vir/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\g2\caws83122.exe.vir NSIS: infected - 1 skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\r2\wr31drs.exe.vir Infected: Trojan-Downloader.Win32.Small.gll skipped
C:\qoobox\Quarantine\C\WINDOWS\tk58.exe.vir Infected: Trojan.Win32.BHO.ab skipped
C:\qoobox\Quarantine\C\WINDOWS\TTC-4444.exe.vir/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\qoobox\Quarantine\C\WINDOWS\TTC-4444.exe.vir NSIS: infected - 1 skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP384\A0269982.exe Infected: Trojan-Downloader.Win32.Agent.emo skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP385\A0269984.exe/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP385\A0269984.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP385\A0269985.exe Infected: Trojan.Win32.BHO.ab skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP385\A0269987.exe Infected: not-a-virus:AdWare.Win32.Agent.co skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP385\A0269988.dll Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP385\A0270002.exe Infected: Trojan-Downloader.Win32.Agent.emo skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP385\A0270999.exe/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP385\A0270999.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP385\A0271000.exe Infected: Trojan.Win32.BHO.ab skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP385\A0271004.exe Infected: not-a-virus:AdWare.Win32.Agent.tb skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP385\A0271987.dll Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP385\A0271988.dll Infected: not-a-virus:AdWare.Win32.Agent.ta skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP385\A0272000.exe Infected: Trojan-Downloader.Win32.Agent.emo skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP385\A0272002.exe/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP385\A0272002.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP385\A0272003.exe Infected: Trojan.Win32.BHO.ab skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP385\A0272987.dll Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP385\A0273000.exe/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP385\A0273000.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP385\A0273001.exe Infected: Trojan.Win32.BHO.ab skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP385\A0273010.exe Infected: not-a-virus:AdWare.Win32.Agent.tb skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP385\A0273011.exe Infected: not-a-virus:AdWare.Win32.Agent.ta skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP385\A0273017.dll Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP385\A0273031.exe/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP385\A0273031.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP385\A0273032.exe Infected: Trojan.Win32.BHO.ab skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP385\A0273033.dll Infected: Trojan.Win32.BHO.ab skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP386\A0273043.dll Infected: Trojan.Win32.BHO.ab skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP386\A0273044.dll Infected: Trojan.Win32.BHO.ab skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP386\A0273045.dll Infected: Trojan.Win32.BHO.ab skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP386\A0273046.dll Infected: Trojan.Win32.BHO.ab skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP386\A0273047.dll Infected: Trojan.Win32.BHO.ab skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP386\A0273048.exe Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP386\A0273049.dll Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP386\A0273051.exe Infected: not-a-virus:Monitor.Win32.NetMon.a skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP386\A0273052.exe Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP386\A0273053.exe/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP386\A0273053.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP386\A0273054.exe Infected: Trojan-Downloader.Win32.Small.gll skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP386\A0273056.exe Infected: Trojan.Win32.BHO.ab skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP386\A0273057.exe/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP386\A0273057.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP386\A0273064.dll Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP387\A0274064.dll Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP388\A0274073.exe/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP388\A0274073.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP388\A0274074.exe Infected: Trojan.Win32.BHO.ab skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP388\A0275064.dll Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP388\A0275076.exe/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP388\A0275076.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP388\A0275077.exe Infected: Trojan.Win32.BHO.ab skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP388\A0276064.dll Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP388\A0278075.exe/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP388\A0278075.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP388\A0278076.exe Infected: Trojan.Win32.BHO.ab skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP391\A0278104.dll Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP391\A0278121.exe/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP391\A0278121.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP391\A0278122.exe Infected: Trojan.Win32.BHO.ab skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP392\A0278159.dll Infected: Trojan.Win32.BHO.ab skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP392\A0278160.dll Infected: Trojan.Win32.BHO.ab skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP392\A0278161.dll Infected: Trojan.Win32.BHO.ab skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP392\A0278162.dll Infected: Trojan.Win32.BHO.ab skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP392\A0278163.dll Infected: Trojan.Win32.BHO.ab skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP392\A0278164.exe Infected: Trojan.Win32.BHO.ab skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP392\A0278165.exe/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP392\A0278165.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP392\A0278175.dll Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\System Volume Information\_restore{83BE25CE-CF1F-4EE7-A83E-5EE431814AD3}\RP394\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\mrofinu1000106.exe Infected: Trojan-Downloader.Win32.Agent.emo skipped
C:\WINDOWS\mrofinu572.exe Infected: Trojan-Downloader.Win32.Agent.fak skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\ddcayax.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ahr skipped
C:\WINDOWS\system32\fsrmddmb.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\WINDOWS\system32\gebxvvt.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ahr skipped
C:\WINDOWS\system32\gswhdehk.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\klabving.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\WINDOWS\system32\lderhtgi.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\WINDOWS\system32\Mz02r\Mz02r1065.exe Infected: Trojan-Downloader.Win32.VB.bqc skipped
C:\WINDOWS\system32\pnruhefb.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\WINDOWS\system32\qjmjuqhu.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\WINDOWS\system32\rqtdidvs.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\ygfqwwwq.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
Logfile of HijackThis v1.99.1
Scan saved at 12:38:58 AM, on 11/16/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\Hewlett-Packard\HP Notebook Utilities\HPWirelessMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\carpserv.exe
C:\WINDOWS\system32\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Hewlett-Packard\HP Notebook Utilities\hptasks.exe
C:\PROGRA~1\HEWLET~1\ONE-TO~1\OneTouch.EXE
C:\windows\system\hpsysdrv.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://srch-us4nb.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.gmail.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.hp.com/info/e-center-p
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://srch-us4nb.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://srch-us4nb.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://srch-us4nb.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://www.hp.com/info/e-center-p
F1 - win.ini: run= C:\WESTWOOD\REDALERT\INSTICON.EXE
O3 - Toolbar: &hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\fsrmddmb.dll
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HP TV Now] C:\Program Files\Hewlett-Packard\HP TV Now\HpTvNow.exe /RK
O4 - HKLM\..\Run: [HP Display Settings] C:\Program Files\Hewlett-Packard\HP Notebook Utilities\hptasks.exe /s
O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
O4 - HKLM\..\Run: [QT4HPOT] C:\PROGRA~1\HEWLET~1\ONE-TO~1\OneTouch.EXE
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com/info/e-center-p
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...can_unicode.cab
O16 - DPF: {22D4879A-92DB-470D-8A83-E158797D8176} (Liquid.LiquidHelper) - file://D:\components\Liquid.ocx
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\Hewlett-Packard\HP Notebook Utilities\HPWirelessMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe