Thank you so much.
Here is the combofix log
ComboFix 07-12-02.6 - Kryss 2007-12-03 19:04:19.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.583 [GMT -8:00]
Running from: C:\Documents and Settings\Kryss\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\Kryss\Favorites\Online Security Guide.lnk
C:\Documents and Settings\Kryss\ResErrors.log
C:\WINDOWS\system32\buaknojs.dll
C:\WINDOWS\system32\cbxxust.dll
C:\WINDOWS\system32\hggfghf.dll
C:\WINDOWS\system32\nnnolig.dll
C:\WINDOWS\system32\sjonkaub.ini
C:\WINDOWS\system32\tstwa.ini2
.
((((((((((((((((((((((((( Files Created from 2007-11-04 to 2007-12-04 )))))))))))))))))))))))))))))))
.
2007-12-02 15:52 . 2007-12-02 16:23 <DIR> d-------- C:\VundoFix Backups
2007-12-02 12:38 . 2007-12-02 15:37 594 ---hs---- C:\WINDOWS\system32\rrigjkvt.ini
2007-12-02 11:42 . 2007-12-03 17:50 <DIR> d-------- C:\Program Files\Spyware Doctor
2007-12-02 11:42 . 2007-12-02 11:42 <DIR> d-------- C:\Documents and Settings\Kryss\Application Data\PC Tools
2007-12-02 11:42 . 2005-09-23 08:29 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-12-02 11:42 . 2007-10-18 00:16 79,688 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2007-12-02 11:42 . 2007-10-18 00:15 62,280 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2007-12-02 11:42 . 2007-10-18 00:14 41,288 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-12-02 11:42 . 2007-10-18 00:16 29,000 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2007-12-02 11:19 . 2007-12-02 11:19 <DIR> d-------- C:\Program Files\YourPlace
2007-12-02 11:19 . 2007-12-02 11:19 <DIR> d-------- C:\Program Files\The Learning Company
2007-12-02 11:19 . 2007-12-02 11:19 <DIR> d-------- C:\Program Files\Common Files\Jasc Software Inc
2007-12-02 11:19 . 2007-12-02 11:19 <DIR> d-------- C:\Documents and Settings\Kryss\Application Data\Jasc Software Inc
2007-11-30 09:38 . 2007-11-30 09:39 <DIR> d-------- C:\TEMP\ext37558
2007-11-29 16:06 . 2007-10-01 16:24 219,448 --a------ C:\WINDOWS\system32\WRLogonNtf(2)(2).dll
2007-11-28 21:33 . 2007-11-29 10:20 97 --a------ C:\WINDOWS\system32\mcrh.tmp
2007-11-28 19:22 . 2007-12-02 11:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-28 10:25 . 2007-11-28 10:25 0 --a----t- C:\_wdsuef.dmp
2007-11-28 10:12 . 2007-11-28 10:12 <DIR> d-------- C:\WINDOWS\Performance
2007-11-28 10:12 . 2007-11-28 10:12 <DIR> d-------- C:\Program Files\Microsoft Windows Vista Upgrade Advisor
2007-11-28 10:12 . 2007-11-28 10:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Corporation
2007-11-28 10:08 . 2007-11-28 10:26 2,187 --a------ C:\WINDOWS\diagerr.xml
2007-11-28 10:08 . 2007-11-28 10:26 1,887 --a------ C:\WINDOWS\diagwrn.xml
2007-11-26 17:13 . 2007-11-26 17:13 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2007-11-26 17:13 . 2007-11-26 17:13 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_zumbus_01005.Wdf
2007-11-26 17:10 . 2007-11-26 17:14 <DIR> d-------- C:\Program Files\Zune
2007-11-23 16:39 . 2007-11-23 16:39 <DIR> d-------- C:\Program Files\MoRUN.net
2007-11-23 16:07 . 2007-11-23 16:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Games
2007-11-23 15:28 . 2006-03-24 17:32 4,882,432 --a------ C:\WINDOWS\system32\stacgui.cpl
2007-11-23 15:28 . 2006-03-22 17:52 1,052,672 --a------ C:\WINDOWS\system32\stlang.dll
2007-11-23 15:28 . 2006-03-24 17:30 282,624 --a------ C:\WINDOWS\stsystra.exe
2007-11-23 15:27 . 2007-11-23 15:27 <DIR> d-------- C:\Program Files\SigmaTel
2007-11-23 15:27 . 2006-03-24 17:34 1,156,648 --a------ C:\WINDOWS\system32\drivers\sthda.sys
2007-11-23 15:27 . 2006-03-24 17:31 208,896 --a------ C:\WINDOWS\system32\stacapi.dll
2007-11-23 15:27 . 2006-03-24 17:32 112,128 --a------ C:\WINDOWS\system32\staco.dll
2007-11-22 07:35 . 2007-11-22 07:35 <DIR> d-------- C:\Program Files\Innovatools
2007-11-21 13:05 . 2007-11-23 16:08 <DIR> d-------- C:\Documents and Settings\Kryss\Application Data\Microsoft Games
2007-11-21 12:35 . 2007-11-23 15:55 <DIR> d-------- C:\Program Files\Microsoft Games
2007-11-19 13:22 . 2007-11-19 13:23 <DIR> d-------- C:\Program Files\QuickTime
2007-11-18 10:54 . 2007-11-18 11:08 <DIR> d-------- C:\Documents and Settings\Kryss\Application Data\Corel
2007-11-18 10:54 . 2007-11-18 10:54 2,516 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
2007-11-18 10:54 . 2007-11-18 10:54 88 -r-hs---- C:\WINDOWS\system32\F38C0297AF.sys
2007-11-18 10:51 . 2007-11-18 10:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Corel
2007-11-18 10:50 . 2007-11-18 10:51 <DIR> d-------- C:\Program Files\Common Files\Corel
2007-11-18 10:50 . 2007-11-18 10:50 476,752 --a------ C:\Documents and Settings\All Users\Application Data\pswi_preloaded.exe
2007-11-18 10:39 . 2007-11-18 10:50 <DIR> d-------- C:\Program Files\Corel
2007-11-18 10:04 . 2007-11-18 10:25 <DIR> d-------- C:\Documents and Settings\Kryss\Application Data\Download Manager
2007-11-15 21:51 . 2007-11-15 21:51 245,664 --a------ C:\WINDOWS\system32\ZuneWlanCfgSvc.exe
2007-11-15 21:51 . 2007-11-15 21:51 155,552 --a------ C:\WINDOWS\system32\ZuneMTPZ.dll
2007-11-15 21:51 . 2007-11-15 21:51 80,288 --a------ C:\WINDOWS\system32\ZuneIpTransport.dll
2007-11-15 21:51 . 2007-11-15 21:51 72,608 --a------ C:\WINDOWS\system32\ZuneUsbTransport.dll
2007-11-15 21:51 . 2007-11-15 21:51 59,296 --a------ C:\WINDOWS\system32\ZuneBusEnum.exe
2007-11-15 21:51 . 2007-11-15 21:51 45,472 --a------ C:\WINDOWS\system32\ZuneUsbConnection.dll
2007-11-15 21:38 . 2007-11-15 21:38 40,832 --a------ C:\WINDOWS\system32\drivers\zumbus.sys
2007-11-15 16:43 . 2007-11-15 16:43 <DIR> d-------- C:\Documents and Settings\Kryss\Application Data\j2 Messenger
2007-11-15 16:43 . 2007-11-15 16:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\j2 Messenger 4.2 Setup
2007-11-15 16:42 . 2007-11-15 16:44 <DIR> d-------- C:\Program Files\j2 Messenger 4.2
2007-11-14 23:43 . 2007-11-14 23:43 65,536 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2007-11-14 23:43 . 2007-11-14 23:43 49,152 --a------ C:\WINDOWS\system32\QuickTime.qts
2007-11-09 13:42 . 2007-11-09 13:48 <DIR> d-------- C:\WINDOWS\SHELLNEW
2007-11-08 16:25 . 2007-11-08 16:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\InstallShield
2007-11-08 16:22 . 2007-11-28 19:15 <DIR> d-------- C:\Program Files\Jasc Software Inc
2007-11-07 14:58 . 2007-11-07 14:58 <DIR> d-------- C:\Documents and Settings\Kryss\Application Data\Snapfish
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-03 05:50 --------- d-----w C:\Program Files\Windows Live Toolbar
2007-12-02 23:37 --------- d-----w C:\Program Files\Webroot
2007-12-02 22:46 --------- d-----w C:\Documents and Settings\Kryss\Application Data\Webroot
2007-11-30 03:31 --------- d--h--w C:\Documents and Settings\Kryss\Application Data\Move Networks
2007-11-29 05:40 --------- d-----w C:\Program Files\Trend Micro
2007-11-24 18:17 5 ----a-w C:\WINDOWS\system32\drivers\DELL_WOR_M65.MRK
2007-11-24 18:17 5 ----a-w C:\WINDOWS\system32\drivers\1028_DELL_WOR_M65.MRK
2007-11-24 00:08 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-21 22:13 --------- d-----w C:\Program Files\Paltalk Messenger
2007-11-21 22:13 --------- d-----w C:\Documents and Settings\Kryss\Application Data\Paltalk
2007-11-21 22:08 --------- d-----w C:\Program Files\Apple Software Update
2007-11-15 15:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-11-09 21:43 --------- d-----w C:\Documents and Settings\Kryss\Application Data\uTorrent
2007-11-09 00:23 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-10-19 18:23 --------- d-----w C:\Program Files\Cucusoft
2007-10-19 17:22 --------- d-----w C:\Documents and Settings\Kryss\Application Data\HP
2007-10-18 19:56 --------- d-----w C:\Documents and Settings\Mark\Application Data\HP
2007-10-17 17:22 --------- d-----w C:\Program Files\MSBuild
2007-10-17 17:22 --------- d-----w C:\Program Files\Microsoft Visual Studio 8
2007-10-17 04:54 --------- d-----w C:\Program Files\uTorrent
2007-10-16 02:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Magentic"="C:\PROGRA~1\Magentic\bin\Magentic.exe" [2007-05-30 13:03]
"OE"="C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe" [2006-08-18 12:06]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:00]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 08:24]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe" [2006-08-25 10:25]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-04 02:00 C:\WINDOWS\system32\rundll32.exe]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 17:30 C:\WINDOWS\stsystra.exe]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2005-12-19 09:08]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 02:00]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-11-02 17:24]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:54]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-08-13 16:04]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ljjkjhi]
ljjkjhi.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
LMIinit.dll 2006-10-06 19:56 11504 C:\WINDOWS\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=C:\WINDOWS\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Acrobat Synchronizer.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Fast Start.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk
backup=C:\WINDOWS\pss\HP Photosmart Premier Fast Start.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^j2 4.2.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\j2 4.2.lnk
backup=C:\WINDOWS\pss\j2 4.2.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office OneNote 2003 Quick Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office OneNote 2003 Quick Launch.lnk
backup=C:\WINDOWS\pss\Microsoft Office OneNote 2003 Quick Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PalTalk.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\PalTalk.lnk
backup=C:\WINDOWS\pss\PalTalk.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SSH Tectia Connection Broker.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SSH Tectia Connection Broker.lnk
backup=C:\WINDOWS\pss\SSH Tectia Connection Broker.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Kryss^Start Menu^Programs^Startup^IMVU.lnk]
path=C:\Documents and Settings\Kryss\Start Menu\Programs\Startup\IMVU.lnk
backup=C:\WINDOWS\pss\IMVU.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Kryss^Start Menu^Programs^Startup^Shortcut to Order Counter.lnk]
path=C:\Documents and Settings\Kryss\Start Menu\Programs\Startup\Shortcut to Order Counter.lnk
backup=C:\WINDOWS\pss\Shortcut to Order Counter.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\60288e22]
rundll32.exe C:\WINDOWS\system32\buaknojs.dll,b
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
2007-05-10 21:46 624248 --a------ C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2007-10-10 19:51 39792 --a------ C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
2005-10-07 14:13 176128 -ra------ C:\Program Files\Apoint\Apoint.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2006-11-16 19:04 139264 --a------ C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Broadcom Wireless Manager UI]
2005-12-19 09:08 1347584 --a------ C:\WINDOWS\system32\WLTRAY.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-04 02:00 15360 --a------ C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
2005-12-09 20:29 49152 --------- C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gizmo Project]
C:\Program Files\Gizmo Project\Gizmo.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gizmo Project for LJ Talk]
C:\Program Files\Gizmo Project for LJ Talk\Gizmo-LJ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2006-10-27 00:47 31016 --a------ C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2006-02-19 01:41 49152 --a------ C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IncrediMail]
C:\Program Files\IncrediMail\bin\IncMail.exe /c
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\j2 4.2]
C:\Program Files\j2 Messenger 4.2\J2GDllCmd.exe /R
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]
2007-05-17 09:52 505368 --a------ C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
C:\Program Files\Logitech\QuickCam10\QuickCam10.exe /hide
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn GUI]
2006-10-06 19:55 303864 --a------ C:\Program Files\LogMeIn\LogMeInSystray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
C:\Program Files\MSN Messenger\msnmsgr.exe /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
2007-08-13 16:04 5562368 --a------ C:\Program Files\MySpace\IM\MySpaceIM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2006-01-12 15:40 155648 --a------ C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVHotkey]
rundll32.exe nvHotkey.dll,Start
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OE]
2006-08-18 12:06 315392 --a------ C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
stsystra.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe /nosplash /minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2006-11-09 15:07 49263 --a------ C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Window Washer]
2005-08-08 13:49 1110016 --a------ C:\Program Files\Webroot\Washer\wwDisp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zune Launcher]
2007-11-15 21:51 166304 --a------ c:\Program Files\Zune\ZuneLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ZuneNetworkSvc"=3 (0x3)
"wwSecSvc"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"wltrysvc"=2 (0x2)
"usnjsvc"=3 (0x3)
"tmproxy"=2 (0x2)
"TmPfw"=2 (0x2)
"Tmntsrv"=2 (0x2)
"ProtexisLicensing"=2 (0x2)
"Pml Driver HPZ12"=2 (0x2)
"PcScnSrv"=3 (0x3)
"PcCtlCom"=2 (0x2)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"NVSvc"=2 (0x2)
"NBService"=3 (0x3)
"Microsoft Office Groove Audit Service"=3 (0x3)
"LVSrvLauncher"=2 (0x2)
"LVPrcSrv"=2 (0x2)
"LVCOMSer"=2 (0x2)
"idsvc"=3 (0x3)
"IDriverT"=3 (0x3)
"HP Status Server"=3 (0x3)
"HP Port Resolver"=3 (0x3)
"FLEXnet Licensing Service"=3 (0x3)
"Adobe LM Service"=3 (0x3)
"aawservice"=2 (0x2)
R2 LMIInfo;LogMeIn Kernel Information Provider;\??\C:\Program Files\LogMeIn\RaInfo.sys
R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys
R2 ZuneBusEnum;Zune Bus Enumerator;c:\WINDOWS\system32\ZuneBusEnum.exe
R3 guardian2;guardian2;C:\WINDOWS\system32\Drivers\oz776.sys
R3 LMImirr;LMImirr;C:\WINDOWS\system32\DRIVERS\LMImirr.sys
R3 NWADI;NWADI Bus Enumerator;C:\WINDOWS\system32\DRIVERS\NWADIenum.sys
S3 PCASp50;PCASp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\PCASp50.sys
S3 USBCCID;USB Smart Card reader;C:\WINDOWS\system32\DRIVERS\usbccid.sys
S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;c:\WINDOWS\system32\ZuneWlanCfgSvc.exe
.
Contents of the 'Scheduled Tasks' folder
"2007-12-04 02:22:01 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************
catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-03 19:11:53
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-03 19:14:43 - machine was rebooted
.
--- E O F ---