report :
SDFix: Version 1.117
Run by Jarrod on Wed 12/05/2007 at 08:05 AM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Trojan Files Found:
C:\Documents and Settings\Jarrod\Desktop\Unused Desktop Shortcuts\Error Cleaner.url - Deleted
C:\Documents and Settings\Jarrod\Desktop\Unused Desktop Shortcuts\Privacy Protector.url - Deleted
C:\WINDOWS\system32\CatRoot\TMP91.tmp - Deleted
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
catchme 0.3.1262.1 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-05 08:14:57
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Reinstall\\24\xe1\21]
"DisplayName"="\x3688\x34c\x3688\x34c\1"
"DeviceDesc"="\x3688\x34c\x3688\x34c\1"
"ProviderName"="\xfed4\21\xee18\x7c90\xff44\21\b"
"MFG"="\x574"
"ReinstallString"="C:\WINDOWS\System32\ReinstallBackups\\xe114\21\x80\xc010\DriverFiles\.INF"
"DeviceInstanceIds"=str(7):"c:\chipset and display.temp\sbdrv\smbus\smbusati.inf"
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
Remaining Files:
---------------
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes:
Mon 7 Aug 2006 30,720 ...HR --- "C:\WINDOWS\CdaC13BA.EXE"
Mon 7 Aug 2006 112,128 ...HR --- "C:\WINDOWS\CdaC14BA.DLL"
Sun 24 Dec 2006 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Finished!
cfscript:
ComboFix 07-12-02.5 - Jarrod 2007-12-04 22:14:28.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.79 [GMT -8:00]
Running from: C:\Documents and Settings\Jarrod\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Jarrod\Desktop\CFScript.txt
* Created a new restore point
FILE
C:\WINDOWS\312-zKVVez.jpg
C:\WINDOWS\316-u7s--yn.jpg
C:\WINDOWS\318-AzTK.jpg
C:\WINDOWS\320-en8nT.jpg
C:\WINDOWS\321-TXA8.jpg
C:\WINDOWS\322-BB64c.jpg
C:\WINDOWS\323-zcVs.jpg
C:\WINDOWS\324-sJJs7r.jpg
C:\WINDOWS\325-edH88.jpg
C:\WINDOWS\326-6HBr2y.jpg
C:\WINDOWS\327-5A77u.jpg
C:\WINDOWS\328-Lz7--sd.jpg
C:\WINDOWS\329-2srr.jpg
C:\WINDOWS\330-VKc6.jpg
C:\WINDOWS\331-5Bw8J.jpg
C:\WINDOWS\332-44srB6.jpg
C:\WINDOWS\333-nn7K2r.jpg
C:\WINDOWS\334-4py3Xy.jpg
C:\WINDOWS\335-45w8ds.jpg
C:\WINDOWS\336-we52.jpg
C:\WINDOWS\337-eTurnF.jpg
C:\WINDOWS\338-dBHH.jpg
C:\WINDOWS\339-uTc4.jpg
C:\WINDOWS\340-drs3K.jpg
C:\WINDOWS\341-pB4MB.jpg
C:\WINDOWS\342-wM4K.jpg
C:\WINDOWS\343-dp5--7Tw.jpg
C:\WINDOWS\344-84Hy7.jpg
C:\WINDOWS\345-5z73wL.jpg
C:\WINDOWS\346-FL36ny.jpg
C:\WINDOWS\347-nT2r6.jpg
C:\WINDOWS\348-5Xedd.jpg
C:\WINDOWS\349-Gw67B-G.jpg
C:\WINDOWS\350-dBw-d.jpg
C:\WINDOWS\351-BV2yw.jpg
C:\WINDOWS\352-ep4V7.jpg
C:\WINDOWS\353-Gec4.jpg
C:\WINDOWS\354-wd37.jpg
C:\WINDOWS\355-d7M.jpg
C:\WINDOWS\356-zrA.jpg
C:\WINDOWS\357-32Bc.jpg
C:\WINDOWS\358-uJ4rre7.jpg
C:\WINDOWS\359-3uA6w.jpg
C:\WINDOWS\360-uuFr.jpg
C:\WINDOWS\361-Hu4B4.jpg
C:\WINDOWS\362-pM3r6n.jpg
C:\WINDOWS\363-GepMr.jpg
C:\WINDOWS\364-F75Gu.jpg
C:\WINDOWS\365-V3GJes.jpg
C:\WINDOWS\366-cw----uA.jpg
C:\WINDOWS\367-cpB7p7.jpg
C:\WINDOWS\380-dLyBrp6.jpg
C:\WINDOWS\381-7drd.jpg
C:\WINDOWS\382-3pT7.jpg
C:\WINDOWS\383-s-75zw.jpg
C:\WINDOWS\384-4737.jpg
C:\WINDOWS\385-cBcM.jpg
C:\WINDOWS\386-VrT8BL.jpg
C:\WINDOWS\387-7MuwHs.jpg
C:\WINDOWS\388-88rrsz.jpg
C:\WINDOWS\389-4MV3d5.jpg
C:\WINDOWS\390-64F2.jpg
C:\WINDOWS\391-p4cz4.jpg
C:\WINDOWS\392-cVrwKG.jpg
C:\WINDOWS\393-TwAw8G.jpg
C:\WINDOWS\394-d6sd-p.jpg
C:\WINDOWS\395-BBc-yX.jpg
C:\WINDOWS\396-n4dyK.jpg
C:\WINDOWS\397-XJsA2.jpg
C:\WINDOWS\398-HT3r7d.jpg
C:\WINDOWS\399-GH7LpK.jpg
C:\WINDOWS\400-3yw7.jpg
C:\WINDOWS\401-T7r7AF.jpg
C:\WINDOWS\402-F7dz.jpg
C:\WINDOWS\403-nrepnu6.jpg
C:\WINDOWS\404-Xc7.jpg
C:\WINDOWS\405-3rzcG.jpg
C:\WINDOWS\406-y-7cV.jpg
C:\WINDOWS\407-3eGwc.jpg
C:\WINDOWS\408-JJLuJ7.jpg
C:\WINDOWS\409-Xn-c4cX.jpg
C:\WINDOWS\410-8e6u4.jpg
C:\WINDOWS\411-X64H.jpg
C:\WINDOWS\412-yLnzc.jpg
C:\WINDOWS\413-K3F7-GwA.jpg
C:\WINDOWS\414-sdzMy2.jpg
C:\WINDOWS\415-68MHw.jpg
C:\WINDOWS\416-dXdw4n.jpg
C:\WINDOWS\417-6FwF88.jpg
C:\WINDOWS\418-2pz7.jpg
C:\WINDOWS\419-B-pV68A.jpg
C:\WINDOWS\420-u4VT3p.jpg
C:\WINDOWS\421-4pLsL.jpg
C:\WINDOWS\422-rTyK8.jpg
C:\WINDOWS\423-wKH8.jpg
C:\WINDOWS\424-nre4rc.jpg
C:\WINDOWS\425-2pVc6.jpg
C:\WINDOWS\426-BuL.jpg
C:\WINDOWS\427-Jpwzsz.jpg
C:\WINDOWS\428-3-645TX.jpg
C:\WINDOWS\CdaC14BA.exe
C:\WINDOWS\mmall.exe
C:\WINDOWS\system32\ctfmona.exe
C:\WINDOWS\system32\mzf.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Viewpoint
C:\Program Files\SelectRebates
C:\Program Files\SelectRebates\FFToolbar\chrome.manifest
C:\Program Files\SelectRebates\FFToolbar\chrome\content\options.js
C:\Program Files\SelectRebates\FFToolbar\chrome\content\options.xul
C:\Program Files\SelectRebates\FFToolbar\chrome\content\sahtoolbar.js
C:\Program Files\SelectRebates\FFToolbar\chrome\content\sahtoolbar.xul
C:\Program Files\SelectRebates\FFToolbar\chrome\locale\en-US\contents.rdf
C:\Program Files\SelectRebates\FFToolbar\chrome\locale\en-US\sahtoolbar.dtd
C:\Program Files\SelectRebates\FFToolbar\chrome\locale\en-US\sahtoolbar.properties
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\3rdParty.png
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\add-folderplus.png
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\add-plussign.png
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\alert-blue.png
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\alert-red.png
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\bluebar.png
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\dollarsign.png
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\FindWords.png
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\gripper.png
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\icon-magnifying.png
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\invite.png
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\invite2.png
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\my-blue.png
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\my-gray.png
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\my-green.png
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\my-red.png
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\Options.png
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\S.png
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\SAH-logotext.png
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\SAH-mainlogo-v1.png
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\SAH-mainlogo-v2.png
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\sahtoolbar.css
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\Search.png
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\shoppingcart.png
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\singleperson.png
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\star.png
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\thumb2.png
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\Thumbs.db
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\toolbar-images-ALL.png
C:\Program Files\SelectRebates\FFToolbar\chrome\skin\Toolbar_HelpAndFeedback.png
C:\Program Files\SelectRebates\FFToolbar\defaults\preferences\sahtoolbar.js
C:\Program Files\SelectRebates\FFToolbar\fftoolbar.reg
C:\Program Files\SelectRebates\FFToolbar\install.rdf
C:\Program Files\SelectRebates\SahImages\bg-gradient.gif
C:\Program Files\SelectRebates\SahImages\button-close.gif
C:\Program Files\SelectRebates\SahImages\sah-logopop.gif
C:\Program Files\SelectRebates\SelectAlerts.dat
C:\Program Files\SelectRebates\SelectRebates.ini
C:\Program Files\SelectRebates\SelectRebatesA.dat
C:\Program Files\SelectRebates\SelectRebatesApi.exe
C:\Program Files\SelectRebates\SelectRebatesApi.ini
C:\Program Files\SelectRebates\SelectRebatesB.dat
C:\Program Files\SelectRebates\SelectRebatesBT.dat
C:\Program Files\SelectRebates\SelectRebatesUninstall.ini
C:\Program Files\SelectRebates\Toolbar\Add.bmp
C:\Program Files\SelectRebates\Toolbar\AdvancedOptions.html
C:\Program Files\SelectRebates\Toolbar\basis.xml
C:\Program Files\SelectRebates\Toolbar\Blank.bmp
C:\Program Files\SelectRebates\Toolbar\button-CloseWindow.gif
C:\Program Files\SelectRebates\Toolbar\i_clipboard.bmp
C:\Program Files\SelectRebates\Toolbar\i_help.bmp
C:\Program Files\SelectRebates\Toolbar\i_magnifying.bmp
C:\Program Files\SelectRebates\Toolbar\icons.bmp
C:\Program Files\SelectRebates\Toolbar\ImageCache\alert-red.bmp
C:\Program Files\SelectRebates\Toolbar\Invite.bmp
C:\Program Files\SelectRebates\Toolbar\logo.bmp
C:\Program Files\SelectRebates\Toolbar\logo_24.bmp
C:\Program Files\SelectRebates\Toolbar\MyNew.bmp
C:\Program Files\SelectRebates\Toolbar\MyNone.bmp
C:\Program Files\SelectRebates\Toolbar\MyPage.bmp
C:\Program Files\SelectRebates\Toolbar\Rate.bmp
C:\Program Files\SelectRebates\Toolbar\RightControls.dym
C:\Program Files\SelectRebates\Toolbar\sah_logo_bars.gif
C:\Program Files\SelectRebates\Toolbar\Scissors.bmp
C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar.dll
C:\WINDOWS\312-zKVVez.jpg
C:\WINDOWS\316-u7s--yn.jpg
C:\WINDOWS\318-AzTK.jpg
C:\WINDOWS\320-en8nT.jpg
C:\WINDOWS\321-TXA8.jpg
C:\WINDOWS\322-BB64c.jpg
C:\WINDOWS\323-zcVs.jpg
C:\WINDOWS\324-sJJs7r.jpg
C:\WINDOWS\325-edH88.jpg
C:\WINDOWS\326-6HBr2y.jpg
C:\WINDOWS\327-5A77u.jpg
C:\WINDOWS\328-Lz7--sd.jpg
C:\WINDOWS\329-2srr.jpg
C:\WINDOWS\330-VKc6.jpg
C:\WINDOWS\331-5Bw8J.jpg
C:\WINDOWS\332-44srB6.jpg
C:\WINDOWS\333-nn7K2r.jpg
C:\WINDOWS\334-4py3Xy.jpg
C:\WINDOWS\335-45w8ds.jpg
C:\WINDOWS\336-we52.jpg
C:\WINDOWS\337-eTurnF.jpg
C:\WINDOWS\338-dBHH.jpg
C:\WINDOWS\339-uTc4.jpg
C:\WINDOWS\340-drs3K.jpg
C:\WINDOWS\341-pB4MB.jpg
C:\WINDOWS\342-wM4K.jpg
C:\WINDOWS\343-dp5--7Tw.jpg
C:\WINDOWS\344-84Hy7.jpg
C:\WINDOWS\345-5z73wL.jpg
C:\WINDOWS\346-FL36ny.jpg
C:\WINDOWS\347-nT2r6.jpg
C:\WINDOWS\348-5Xedd.jpg
C:\WINDOWS\349-Gw67B-G.jpg
C:\WINDOWS\350-dBw-d.jpg
C:\WINDOWS\351-BV2yw.jpg
C:\WINDOWS\352-ep4V7.jpg
C:\WINDOWS\353-Gec4.jpg
C:\WINDOWS\354-wd37.jpg
C:\WINDOWS\355-d7M.jpg
C:\WINDOWS\356-zrA.jpg
C:\WINDOWS\357-32Bc.jpg
C:\WINDOWS\358-uJ4rre7.jpg
C:\WINDOWS\359-3uA6w.jpg
C:\WINDOWS\360-uuFr.jpg
C:\WINDOWS\361-Hu4B4.jpg
C:\WINDOWS\362-pM3r6n.jpg
C:\WINDOWS\363-GepMr.jpg
C:\WINDOWS\364-F75Gu.jpg
C:\WINDOWS\365-V3GJes.jpg
C:\WINDOWS\366-cw----uA.jpg
C:\WINDOWS\367-cpB7p7.jpg
C:\WINDOWS\380-dLyBrp6.jpg
C:\WINDOWS\381-7drd.jpg
C:\WINDOWS\382-3pT7.jpg
C:\WINDOWS\383-s-75zw.jpg
C:\WINDOWS\384-4737.jpg
C:\WINDOWS\385-cBcM.jpg
C:\WINDOWS\386-VrT8BL.jpg
C:\WINDOWS\387-7MuwHs.jpg
C:\WINDOWS\388-88rrsz.jpg
C:\WINDOWS\389-4MV3d5.jpg
C:\WINDOWS\390-64F2.jpg
C:\WINDOWS\391-p4cz4.jpg
C:\WINDOWS\392-cVrwKG.jpg
C:\WINDOWS\393-TwAw8G.jpg
C:\WINDOWS\394-d6sd-p.jpg
C:\WINDOWS\395-BBc-yX.jpg
C:\WINDOWS\396-n4dyK.jpg
C:\WINDOWS\397-XJsA2.jpg
C:\WINDOWS\398-HT3r7d.jpg
C:\WINDOWS\399-GH7LpK.jpg
C:\WINDOWS\400-3yw7.jpg
C:\WINDOWS\401-T7r7AF.jpg
C:\WINDOWS\402-F7dz.jpg
C:\WINDOWS\403-nrepnu6.jpg
C:\WINDOWS\404-Xc7.jpg
C:\WINDOWS\405-3rzcG.jpg
C:\WINDOWS\406-y-7cV.jpg
C:\WINDOWS\407-3eGwc.jpg
C:\WINDOWS\408-JJLuJ7.jpg
C:\WINDOWS\409-Xn-c4cX.jpg
C:\WINDOWS\410-8e6u4.jpg
C:\WINDOWS\411-X64H.jpg
C:\WINDOWS\412-yLnzc.jpg
C:\WINDOWS\413-K3F7-GwA.jpg
C:\WINDOWS\414-sdzMy2.jpg
C:\WINDOWS\415-68MHw.jpg
C:\WINDOWS\416-dXdw4n.jpg
C:\WINDOWS\417-6FwF88.jpg
C:\WINDOWS\418-2pz7.jpg
C:\WINDOWS\419-B-pV68A.jpg
C:\WINDOWS\420-u4VT3p.jpg
C:\WINDOWS\421-4pLsL.jpg
C:\WINDOWS\422-rTyK8.jpg
C:\WINDOWS\423-wKH8.jpg
C:\WINDOWS\424-nre4rc.jpg
C:\WINDOWS\425-2pVc6.jpg
C:\WINDOWS\426-BuL.jpg
C:\WINDOWS\427-Jpwzsz.jpg
C:\WINDOWS\428-3-645TX.jpg
C:\WINDOWS\CdaC14BA.exe
C:\WINDOWS\mmall.exe
C:\WINDOWS\SmFycm9k
C:\WINDOWS\SmFycm9k\asappsrv.dll
C:\WINDOWS\SmFycm9k\command.exe
C:\WINDOWS\SmFycm9k\mAIVwA64.vbs
C:\WINDOWS\system32\mzf.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_TDLSERV
((((((((((((((((((((((((( Files Created from 2007-11-05 to 2007-12-05 )))))))))))))))))))))))))))))))
.
2007-12-04 09:19 . 2007-12-04 09:19 533,504 --a------ C:\WINDOWS\mmoc.bin
2007-12-04 09:19 . 2007-12-04 09:19 533,504 --a------ C:\WINDOWS\mm_tmpoc.bin
2007-12-04 09:18 . 2007-12-04 21:51 40,960 --a------ C:\WINDOWS\mm_tmphr.exe
2007-12-03 23:41 . 2007-12-03 23:41 2,309 --a------ C:\WINDOWS\46-zV7w.jpg
2007-12-03 23:41 . 2007-12-03 23:41 1,932 --a------ C:\WINDOWS\45-s7z8.jpg
2007-12-03 23:40 . 2007-12-03 23:40 3,840 --a------ C:\WINDOWS\39-2dnGpJ.jpg
2007-12-03 23:40 . 2007-12-03 23:40 3,325 --a------ C:\WINDOWS\38-44GBsw.jpg
2007-12-03 23:40 . 2007-12-03 23:40 2,932 --a------ C:\WINDOWS\37-yTu7sG.jpg
2007-12-03 23:40 . 2007-12-03 23:40 2,873 --a------ C:\WINDOWS\43-Bdr8HV.jpg
2007-12-03 23:40 . 2007-12-03 23:40 2,765 --a------ C:\WINDOWS\40-dKcKc.jpg
2007-12-03 23:40 . 2007-12-03 23:40 2,739 --a------ C:\WINDOWS\41-85AFK.jpg
2007-12-03 23:40 . 2007-12-03 23:40 2,556 --a------ C:\WINDOWS\44-s5sAd.jpg
2007-12-03 23:40 . 2007-12-03 23:40 1,940 --a------ C:\WINDOWS\42-T7Fu.jpg
2007-12-03 23:39 . 2007-12-03 23:39 3,288 --a------ C:\WINDOWS\34-2GpA4.jpg
2007-12-03 23:39 . 2007-12-03 23:39 3,273 --a------ C:\WINDOWS\31-AcprVpw.jpg
2007-12-03 23:39 . 2007-12-03 23:39 3,146 --a------ C:\WINDOWS\32-36TBd.jpg
2007-12-03 23:39 . 2007-12-03 23:39 3,050 --a------ C:\WINDOWS\35-MJ5er.jpg
2007-12-03 23:39 . 2007-12-03 23:39 2,760 --a------ C:\WINDOWS\30-7K7sr4.jpg
2007-12-03 23:39 . 2007-12-03 23:39 2,703 --a------ C:\WINDOWS\36-42H.jpg
2007-12-03 23:39 . 2007-12-03 23:39 2,060 --a------ C:\WINDOWS\33-ArLn.jpg
2007-12-03 23:38 . 2007-12-03 23:38 3,735 --a------ C:\WINDOWS\27-BpsrBu.jpg
2007-12-03 23:38 . 2007-12-03 23:38 3,446 --a------ C:\WINDOWS\24-24FrGwc.jpg
2007-12-03 23:38 . 2007-12-03 23:38 3,409 --a------ C:\WINDOWS\22-Bn8n4ry.jpg
2007-12-03 23:38 . 2007-12-03 23:38 3,151 --a------ C:\WINDOWS\25-8TKFy.jpg
2007-12-03 23:38 . 2007-12-03 23:38 2,922 --a------ C:\WINDOWS\21-u--VJenK.jpg
2007-12-03 23:38 . 2007-12-03 23:38 2,696 --a------ C:\WINDOWS\28-6Vedr.jpg
2007-12-03 23:38 . 2007-12-03 23:38 2,518 --a------ C:\WINDOWS\26-T7-r.jpg
2007-12-03 23:38 . 2007-12-03 23:38 2,489 --a------ C:\WINDOWS\29-F7Jdp.jpg
2007-12-03 23:38 . 2007-12-03 23:38 2,401 --a------ C:\WINDOWS\23-psGG.jpg
2007-12-03 23:37 . 2007-12-03 23:37 3,450 --a------ C:\WINDOWS\16-wnsM8c.jpg
2007-12-03 23:37 . 2007-12-03 23:37 3,311 --a------ C:\WINDOWS\14-B6cr7w.jpg
2007-12-03 23:37 . 2007-12-03 23:37 3,303 --a------ C:\WINDOWS\18-MG463V.jpg
2007-12-03 23:37 . 2007-12-03 23:37 3,013 --a------ C:\WINDOWS\19-rHrsu.jpg
2007-12-03 23:37 . 2007-12-03 23:37 2,794 --a------ C:\WINDOWS\15-THVK.jpg
2007-12-03 23:37 . 2007-12-03 23:37 2,640 --a------ C:\WINDOWS\17-F8sdG.jpg
2007-12-03 23:37 . 2007-12-03 23:37 2,329 --a------ C:\WINDOWS\20--ApK.jpg
2007-12-03 23:36 . 2007-12-03 23:36 3,332 --a------ C:\WINDOWS\6-JnpB2.jpg
2007-12-03 23:36 . 2007-12-03 23:36 3,072 --a------ C:\WINDOWS\9-urJ7r4.jpg
2007-12-03 23:36 . 2007-12-03 23:36 2,900 --a------ C:\WINDOWS\12-H3nJ7w.jpg
2007-12-03 23:36 . 2007-12-03 23:36 2,883 --a------ C:\WINDOWS\8-cMH8r.jpg
2007-12-03 23:36 . 2007-12-03 23:36 2,681 --a------ C:\WINDOWS\11-82Jr27.jpg
2007-12-03 23:36 . 2007-12-03 23:36 2,417 --a------ C:\WINDOWS\10-uJHr7.jpg
2007-12-03 23:36 . 2007-12-03 23:36 2,188 --a------ C:\WINDOWS\13-M8r-.jpg
2007-12-03 23:36 . 2007-12-03 23:36 1,862 --a------ C:\WINDOWS\7-43L3.jpg
2007-12-03 23:35 . 2007-12-03 23:35 3,399 --a------ C:\WINDOWS\2-cTMGVu.jpg
2007-12-03 23:35 . 2007-12-03 23:35 3,296 --a------ C:\WINDOWS\3-HTyF36.jpg
2007-12-03 23:35 . 2007-12-03 23:35 3,214 --a------ C:\WINDOWS\5-wr8-JyJ.jpg
2007-12-03 23:35 . 2007-12-03 23:35 3,027 --a------ C:\WINDOWS\1-u64w6.jpg
2007-12-03 23:35 . 2007-12-03 23:35 2,750 --a------ C:\WINDOWS\4-6rsuBy.jpg
2007-12-03 23:33 . 2007-12-03 23:33 3,393 --a------ C:\WINDOWS\379-rMVBcL.jpg
2007-12-03 23:33 . 2007-12-03 23:33 2,214 --a------ C:\WINDOWS\382-78V-.jpg
2007-12-03 23:33 . 2007-12-03 23:33 2,152 --a------ C:\WINDOWS\380-JM6X.jpg
2007-12-03 23:33 . 2007-12-03 23:33 1,904 --a------ C:\WINDOWS\381-uBcr.jpg
2007-12-03 23:33 . 2007-12-03 23:33 1,895 --a------ C:\WINDOWS\383-yrJX.jpg
2007-12-03 23:32 . 2007-12-03 23:32 3,427 --a------ C:\WINDOWS\374-567H2.jpg
2007-12-03 23:32 . 2007-12-03 23:32 2,902 --a------ C:\WINDOWS\377-XMd7B.jpg
2007-12-03 23:32 . 2007-12-03 23:32 2,656 --a------ C:\WINDOWS\372-d7dpX.jpg
2007-12-03 23:32 . 2007-12-03 23:32 2,644 --a------ C:\WINDOWS\373-7cVysL.jpg
2007-12-03 23:32 . 2007-12-03 23:32 2,592 --a------ C:\WINDOWS\378-86dJe.jpg
2007-12-03 23:32 . 2007-12-03 23:32 2,523 --a------ C:\WINDOWS\371-JB4L.jpg
2007-12-03 23:32 . 2007-12-03 23:32 2,188 --a------ C:\WINDOWS\375-84ue.jpg
2007-12-03 23:32 . 2007-12-03 23:32 2,141 --a------ C:\WINDOWS\376-pLp.jpg
2007-12-03 23:31 . 2007-12-03 23:31 3,540 --a------ C:\WINDOWS\370-yMH-r86.jpg
2007-12-03 23:31 . 2007-12-03 23:31 2,435 --a------ C:\WINDOWS\368-6LVMy.jpg
2007-12-03 23:31 . 2007-12-03 23:31 2,085 --a------ C:\WINDOWS\366-Be83.jpg
2007-12-03 23:31 . 2007-12-03 23:31 2,047 --a------ C:\WINDOWS\367-25V.jpg
2007-12-03 23:31 . 2007-12-03 23:31 1,893 --a------ C:\WINDOWS\369-KAe7.jpg
2007-12-03 23:29 . 2007-12-03 23:29 3,758 --a------ C:\WINDOWS\351-3rH56B.jpg
2007-12-03 23:29 . 2007-12-03 23:29 3,145 --a------ C:\WINDOWS\354-r5Jsez.jpg
2007-12-03 23:29 . 2007-12-03 23:29 3,076 --a------ C:\WINDOWS\353-4A-By7.jpg
2007-12-03 23:29 . 2007-12-03 23:29 3,020 --a------ C:\WINDOWS\352-JTVzL5.jpg
2007-12-03 23:29 . 2007-12-03 23:29 2,299 --a------ C:\WINDOWS\350-8X45.jpg
2007-12-03 23:28 . 2007-12-03 23:28 3,293 --a------ C:\WINDOWS\344-AH-dTyH.jpg
2007-12-03 23:28 . 2007-12-03 23:28 3,273 --a------ C:\WINDOWS\347-BV5pFA.jpg
2007-12-03 23:28 . 2007-12-03 23:28 2,688 --a------ C:\WINDOWS\349-5VyM.jpg
2007-12-03 23:28 . 2007-12-03 23:28 2,541 --a------ C:\WINDOWS\343-2uuVF.jpg
2007-12-03 23:28 . 2007-12-03 23:28 2,455 --a------ C:\WINDOWS\342-rX-r8.jpg
2007-12-03 23:28 . 2007-12-03 23:28 2,394 --a------ C:\WINDOWS\346-nK3cG.jpg
2007-12-03 23:28 . 2007-12-03 23:28 2,292 --a------ C:\WINDOWS\348-L5rT.jpg
2007-12-03 23:28 . 2007-12-03 23:28 1,789 --a------ C:\WINDOWS\345-L4en.jpg
2007-12-03 23:27 . 2007-12-03 23:27 3,654 --a------ C:\WINDOWS\336-JH7VnB.jpg
2007-12-03 23:27 . 2007-12-03 23:27 3,289 --a------ C:\WINDOWS\334-XBpAps.jpg
2007-12-03 23:27 . 2007-12-03 23:27 3,206 --a------ C:\WINDOWS\335-ceHFy4.jpg
2007-12-03 23:27 . 2007-12-03 23:27 2,503 --a------ C:\WINDOWS\338-B8uVrc.jpg
2007-12-03 23:27 . 2007-12-03 23:27 2,360 --a------ C:\WINDOWS\333-TBn3J.jpg
2007-12-03 23:27 . 2007-12-03 23:27 2,337 --a------ C:\WINDOWS\341-dydJF.jpg
2007-12-03 23:27 . 2007-12-03 23:27 2,271 --a------ C:\WINDOWS\339-p-u-43.jpg
2007-12-03 23:27 . 2007-12-03 23:27 2,226 --a------ C:\WINDOWS\340-wnee.jpg
2007-12-03 23:27 . 2007-12-03 23:27 2,139 --a------ C:\WINDOWS\337-587M.jpg
2007-12-03 23:26 . 2007-12-03 23:26 3,249 --a------ C:\WINDOWS\330-6JrwG.jpg
2007-12-03 23:26 . 2007-12-03 23:26 3,132 --a------ C:\WINDOWS\332-328MK.jpg
2007-12-03 23:26 . 2007-12-03 23:26 2,553 --a------ C:\WINDOWS\327-5drs7.jpg
2007-12-03 23:26 . 2007-12-03 23:26 2,516 --a------ C:\WINDOWS\328-w-s43.jpg
2007-12-03 23:26 . 2007-12-03 23:26 2,439 --a------ C:\WINDOWS\329-cVL-r.jpg
2007-12-03 23:26 . 2007-12-03 23:26 2,344 --a------ C:\WINDOWS\326-J-4-L4n.jpg
2007-12-03 23:26 . 2007-12-03 23:26 1,954 --a------ C:\WINDOWS\331-H-Ju.jpg
2007-12-03 23:24 . 2007-12-03 23:24 2,944 --a------ C:\WINDOWS\321-4d68K.jpg
2007-12-03 23:24 . 2007-12-03 23:24 2,928 --a------ C:\WINDOWS\320-XJ8rH2.jpg
2007-12-03 23:24 . 2007-12-03 23:24 2,734 --a------ C:\WINDOWS\324-eA46d.jpg
2007-12-03 23:24 . 2007-12-03 23:24 2,275 --a------ C:\WINDOWS\316-82TK.jpg
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-02 10:42 --------- d-----w C:\Program Files\Common Files\AOL
2007-12-02 10:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL
2007-12-01 09:17 --------- d-----w C:\Program Files\RegSweep
2007-12-01 09:12 --------- d-----w C:\Program Files\Java
2007-12-01 09:06 --------- d-----w C:\Program Files\MySpace
2007-12-01 09:01 --------- d-----w C:\Program Files\The Weather Channel FW
2007-11-27 21:04 --------- d-----w C:\Program Files\LimeWire
2007-11-16 08:29 3,638 ----a-w C:\info.exe
2007-09-06 09:14 2,416 ----a-w C:\Documents and Settings\Administrator\GetPaths.vbs
2007-03-31 08:16 1,708 ----a-w C:\Documents and Settings\Jarrod\Application Data\wklnhst.dat
2006-07-12 19:40 162 ----a-w C:\Documents and Settings\Jerry\Application Data\wklnhst.dat
.
((((((((((((((((((((((((((((( snapshot@2007-12-02_ 2.44.57.06 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-12-01 10:20:48 36,352 ----a-w C:\WINDOWS\mm_tmpgr.exe
+ 2007-12-04 20:59:33 36,352 ----a-w C:\WINDOWS\mm_tmpgr.exe
- 2007-12-01 10:21:19 41,472 ----a-w C:\WINDOWS\mm_tmpregalka.exe
+ 2007-12-04 07:32:56 41,472 ----a-w C:\WINDOWS\mm_tmpregalka.exe
- 2007-12-01 10:21:18 36,352 ----a-w C:\WINDOWS\mmgr.exe
+ 2007-12-04 21:00:04 36,352 ----a-w C:\WINDOWS\mmgr.exe
+ 2007-12-05 04:51:09 40,960 ----a-w C:\WINDOWS\mmhr.exe
- 2007-12-01 10:21:51 41,472 ----a-w C:\WINDOWS\mmregalka.exe
+ 2007-12-04 07:33:26 41,472 ----a-w C:\WINDOWS\mmregalka.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:00]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2004-12-30 00:32]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 08:24]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-24 00:40]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-01-19 12:49]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\McUpdate.exe" [2006-01-11 11:05]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2005-09-22 17:29]
"RTHDCPL"="RTHDCPL.EXE" [2005-11-10 11:14 C:\WINDOWS\RTHDCPL.exe]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 21:05]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-14 15:28]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-14 15:26]
"THotkey"="C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe" [2005-11-25 13:07]
"Tvs"="C:\Program Files\Toshiba\Tvs\TvsTray.exe" [2005-11-10 10:24]
"LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [2005-05-19 07:57]
"AGRSMMSG"="AGRSMMSG.exe" [2005-10-15 06:29 C:\WINDOWS\agrsmmsg.exe]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-08-01 05:10]
"TPSMain"="TPSMain.exe" [2005-05-31 21:00 C:\WINDOWS\system32\TPSMain.exe]
"PadTouch"="C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" [2005-07-15 10:52]
"SmoothView"="C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2005-04-26 16:13]
"VSOCheckTask"="C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" [2005-07-08 17:18]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2005-03-17 17:37]
"VirusScan Online"="C:\Program Files\McAfee.com\VSO\mcvsshld.exe" [2005-08-10 12:49]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2005-11-04 20:10]
"OASClnt"="C:\Program Files\McAfee.com\VSO\oasclnt.exe" [2005-08-11 21:02]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-11-04 20:10]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
C:\Documents and Settings\Jarrod\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2006-02-16 13:55:37]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
RAMASST.lnk - C:\WINDOWS\system32\RAMASST.exe [2005-11-04 19:20:51]
R0 KR10N;KR10N;C:\WINDOWS\system32\drivers\KR10N.sys
*Newly Created Service* - TDLSERV
.
Contents of the 'Scheduled Tasks' folder
"2007-12-01 08:31:23 C:\WINDOWS\Tasks\RegistrySmart Scheduled Scan.job"
- C:\Program Files\RegistrySmart\RegistrySmart.ex
- C:\Program Files\RegistrySmart.Jarrod.Runs RegistrySmart to optimize your registry.
"2007-12-01 08:31:02 C:\WINDOWS\Tasks\RegSweep Scheduled Scan.job"
- C:\Program Files\RegSweep\RegSweep.ex
.
**************************************************************************
catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-04 22:18:42
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwOpenFile
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2007-12-04 22:21:04 - machine was rebooted
C:\ComboFix2.txt ... 2007-12-02 02:46
.
--- E O F ---
hijackthis:
Logfile of HijackThis v1.99.1
Scan saved at 8:31:02 AM, on 12/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\Program Files\Toshiba\Tvs\TvsTray.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\toshiba\ivp\ism\pinger.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.jdmuniver...rums/usercp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page =
http://go.microsoft....k/?LinkId=54843
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) -
http://lads.myspace....ploader1005.cab
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe