Many thanks for your response LTDate!!!!
I followed your instructions and see below results…hope its not too loooong
Thanks again for your time!
ComboFix 07-12-09.1 - co.endeavour 2007-12-09 7:51:29.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.48.1033.18.71 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data.\sdcpeher.dll
C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\co.endeavour\Favorites\Online Security Guide.lnk
C:\Program Files\dkjalubc
C:\Program Files\dkjalubc\bcfsjmhq.dll
C:\Program Files\Ffkrklwa
C:\Program Files\Ffkrklwa\ewwvbgii.dll
C:\Program Files\Fspehrdu
C:\Program Files\Fspehrdu\xtkiagsp.dll
C:\Program Files\Iyxgkyox
C:\Program Files\Iyxgkyox\igacewpc.dll
C:\Program Files\Kvuuwfxc
C:\Program Files\Kvuuwfxc\spdizeuv.dll
C:\Program Files\Ojwwuuto
C:\Program Files\Ojwwuuto\klsxgyom.dll
C:\Program Files\SecCenter
C:\Program Files\SecCenter\bbb.ejpg
C:\Program Files\Zuonauue
C:\Program Files\Zuonauue\uiqaqgum.dll
C:\WINDOWS\system32\aupaeqlf.dll
C:\WINDOWS\system32\awtuvuv.dll
C:\WINDOWS\system32\bccdd.ini
C:\WINDOWS\system32\bccdd.ini2
C:\WINDOWS\system32\blpnluxo.dll
C:\WINDOWS\system32\cjbratxi.dll
C:\WINDOWS\system32\cqujphff.dll
C:\WINDOWS\system32\ddccb.dll
C:\WINDOWS\system32\dixjujth.dll
C:\WINDOWS\system32\flqeapua.ini
C:\WINDOWS\system32\gcgrcwiu.ini
C:\WINDOWS\system32\gxqkekmv.dll
C:\WINDOWS\system32\htjujxid.ini
C:\WINDOWS\system32\jglpkmvh.dll
C:\WINDOWS\system32\nuinopsd
C:\WINDOWS\system32\nuinopsd\bg1.gif
C:\WINDOWS\system32\nuinopsd\bgtop.gif
C:\WINDOWS\system32\nuinopsd\bottom1.gif
C:\WINDOWS\system32\nuinopsd\essentials.gif
C:\WINDOWS\system32\nuinopsd\icon1.ico
C:\WINDOWS\system32\nuinopsd\install1.gif
C:\WINDOWS\system32\nuinopsd\left1.gif
C:\WINDOWS\system32\nuinopsd\li.gif
C:\WINDOWS\system32\nuinopsd\logo.gif
C:\WINDOWS\system32\nuinopsd\main.htm
C:\WINDOWS\system32\nuinopsd\mainframe.htm
C:\WINDOWS\system32\nuinopsd\nuinopsd1.exe
C:\WINDOWS\system32\nuinopsd\nuinopsd2.exe
C:\WINDOWS\system32\nuinopsd\nuinopsd3.exe
C:\WINDOWS\system32\nuinopsd\reinstall1.gif
C:\WINDOWS\system32\nuinopsd\right1.gif
C:\WINDOWS\system32\nuinopsd\s1.htm
C:\WINDOWS\system32\nuinopsd\s2.htm
C:\WINDOWS\system32\nuinopsd\s3.htm
C:\WINDOWS\system32\nuinopsd\SMTop1.gif
C:\WINDOWS\system32\nuinopsd\SMTop2.gif
C:\WINDOWS\system32\nuinopsd\SMTop3.gif
C:\WINDOWS\system32\nuinopsd\SMTop4.gif
C:\WINDOWS\system32\nuinopsd\soft1_off.gif
C:\WINDOWS\system32\nuinopsd\soft1_off_ext.gif
C:\WINDOWS\system32\nuinopsd\soft1_on.gif
C:\WINDOWS\system32\nuinopsd\soft1_on_ext.gif
C:\WINDOWS\system32\nuinopsd\soft2_off.gif
C:\WINDOWS\system32\nuinopsd\soft2_off_ext.gif
C:\WINDOWS\system32\nuinopsd\soft2_on.gif
C:\WINDOWS\system32\nuinopsd\soft2_on_ext.gif
C:\WINDOWS\system32\nuinopsd\soft3_off.gif
C:\WINDOWS\system32\nuinopsd\soft3_off_ext.gif
C:\WINDOWS\system32\nuinopsd\soft3_on.gif
C:\WINDOWS\system32\nuinopsd\soft3_on_ext.gif
C:\WINDOWS\system32\nuinopsd\softbottom_off.gif
C:\WINDOWS\system32\nuinopsd\softbottom_on.gif
C:\WINDOWS\system32\nuinopsd\softleft_off.gif
C:\WINDOWS\system32\nuinopsd\softleft_on.gif
C:\WINDOWS\system32\nuinopsd\top1.gif
C:\WINDOWS\system32\nuinopsd\top2.gif
C:\WINDOWS\system32\nuinopsd\turnoff1.gif
C:\WINDOWS\system32\nuinopsd\turnon1.gif
C:\WINDOWS\system32\packet.dll
C:\WINDOWS\system32\swmjvggy.ini
C:\WINDOWS\system32\tmbrdfng.dll
C:\WINDOWS\system32\tmesxnau.ini
C:\WINDOWS\system32\uanxsemt.dll
C:\WINDOWS\system32\uiwcrgcg.dll
C:\WINDOWS\system32\uroevdmw.dll
C:\WINDOWS\system32\vcnwwita.dll
C:\WINDOWS\system32\veogrpxw.dll
C:\WINDOWS\system32\wbekmtij.dll
C:\WINDOWS\system32\wincjf32.dll
C:\WINDOWS\system32\wlqxtmdu.dll
C:\WINDOWS\system32\wmdveoru.ini
C:\WINDOWS\system32\wpcap.dll
C:\WINDOWS\system32\wxprgoev.ini
C:\WINDOWS\system32\yggvjmws.dll
C:\WINDOWS\system32\yxwydxdu.dll
F:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\LEGACY_DOMAINSERVICE
——-\LEGACY_NPF
——-\DomainService
——-\nm
——-\NPF
((((((((((((((((((((((((( Files Created from 2007-11-09 to 2007-12-09 )))))))))))))))))))))))))))))))
.
2007-12-03 03:09 . 2006-08-21 03:14 128,896 —–c— C:\WINDOWS\system32\dllcache\fltmgr.sys
2007-12-03 03:09 . 2006-08-21 03:14 23,040 —–c— C:\WINDOWS\system32\dllcache\fltmc.exe
2007-12-03 03:09 . 2006-08-21 06:21 16,896 —–c— C:\WINDOWS\system32\dllcache\fltlib.dll
2007-12-02 11:26 . 2007-07-09 07:09 584,192 —–c— C:\WINDOWS\system32\dllcache\rpcrt4.dll
2007-12-02 09:20 . 2007-12-02 11:36 d——– C:\Program Files\EsetOnlineScanner
2007-12-02 08:50 . 2007-07-30 19:18 34,136 –a—— C:\WINDOWS\system32\wucltui.dll.mui
2007-12-02 08:50 . 2007-07-30 19:19 25,944 –a—— C:\WINDOWS\system32\wuaucpl.cpl.mui
2007-12-02 08:50 . 2007-07-30 19:19 25,944 –a—— C:\WINDOWS\system32\wuapi.dll.mui
2007-12-02 08:50 . 2007-07-30 19:18 20,312 –a—— C:\WINDOWS\system32\wuaueng.dll.mui
2007-12-02 05:03 . 2007-12-02 05:03 793,664 –ahs—- C:\WINDOWS\system32\bbqeqpeb.ini
2007-12-01 18:00 . 2007-12-01 19:01 d——– C:\Program Files\Enigma Software Group
2007-12-01 04:57 . 2007-12-01 04:57 793,664 –ahs—- C:\WINDOWS\system32\cmvtdoiq.ini
2007-11-30 15:46 . 2007-12-04 18:40 107,832 –a—— C:\WINDOWS\system32\PnkBstrB.exe
2007-11-30 15:46 . 2007-12-04 18:40 22,328 –a—— C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-11-30 15:45 . 2007-11-30 15:45 66,872 –a—— C:\WINDOWS\system32\PnkBstrA.exe
2007-11-30 14:08 . 2007-11-30 14:08 d——– C:\Program Files\Trend Micro
2007-11-30 14:03 . 2007-12-06 18:08 4,698 –a—— C:\WINDOWS\system32\tmp.reg
2007-11-30 05:01 . 2007-11-30 05:54 792,853 –ahs—- C:\WINDOWS\system32\qyplopjr.ini
2007-11-29 18:44 . 2007-11-30 12:11 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-29 15:44 . 2007-11-30 04:53 789,779 –ahs—- C:\WINDOWS\system32\tllbxfkb.ini
2007-11-28 15:36 . 2007-11-28 15:36 102,912 –a—— C:\WINDOWS\system32\drvcan.dll
2007-11-24 12:46 . 2007-11-30 22:49 d——– C:\Program Files\Wolfenstein - Enemy Territory
2007-11-12 13:19 . 2007-11-12 13:19 d——– C:\Documents and Settings\co.endeavour\Application Data\Arcsoft
2007-11-12 13:19 . 2007-11-12 13:19 0 –a—— C:\WINDOWS\QuickInstall.INI
2007-11-12 13:05 . 2007-11-12 13:13 d——– C:\Program Files\palmOne
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-09 14:14 ——— d—–w C:\Program Files\Symantec AntiVirus
2007-12-09 14:00 ——— d—–w C:\Documents and Settings\co.endeavour\Application Data\Skype
2007-12-09 13:45 2,401 —-a-w C:\WINDOWS\system32\drivers\AlKernel.sys
2007-12-07 17:12 ——— d—–w C:\Program Files\Duraprint_30
2007-12-06 04:46 ——— d—–w C:\Program Files\Call of Duty Game of the Year Edition
2007-12-02 01:04 ——— d—–w C:\Documents and Settings\co.endeavour\Application Data\U3
2007-12-01 17:21 ——— d—–w C:\Program Files\DYMO Label
2007-10-30 13:19 ——— d—–w C:\Program Files\Skype
2007-10-30 13:19 ——— d—–w C:\Documents and Settings\All Users\Application Data\Skype
2007-10-30 13:18 ——— d—–w C:\Program Files\Common Files\Skype
2007-10-23 14:45 ——— d—–w C:\Program Files\ItCan.Net Monitor
2007-10-18 20:16 ——— d—–w C:\Documents and Settings\Ruairidh\Application Data\Skype
2005-11-15 21:32 3,638 —-a-r C:\Program Files\Common Files\Altiris_Icon.ico
2005-08-06 21:30 164 -c-ha-w C:\Documents and Settings\All Users\hpothb07.dat
2005-08-04 18:21 0 -c-ha-w C:\Documents and Settings\administrator\hpothb07.dat
2005-05-25 17:10 784,896 —-a-w C:\Program Files\DoubleKiller.exe
1998-02-16 01:02 463,872 —-a-w C:\Program Files\Convert.exe
1999-09-28 22:42 1,050,896 –sha-w C:\WINDOWS\system32\msjet35.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06CE41E7-B782-4FAF-B131-DD1978956444}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1C8637D8-25F7-4883-B845-83997A720730}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2B7BBAC2-2089-4A3F-98A3-8BB5BC67A5B2}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30BAA4DF-E0AB-4AFD-B6D8-FFAA032D0468}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3FFE159E-1D39-4F6F-A08B-10E6910F019D}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7BD0D837-3ABA-4CC8-ABE7-98330A2C7959}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9AEBAF79-EF2E-427F-AE7D-D5F031F68135}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CEA1FF0D-9F98-4340-81F5-129B1D1E3543}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DECCA76E-40E0-48F0-B22C-FDE46949F8F7}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FA61EE4D-C9EB-4D16-A235-5A2F1165832A}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AutoCAD Digital Signatures Icon Overlay Handler]
@={36A21736-36C2-4C11-8ACB-D4136F2B57BD}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Offline Files]
[HKEY_CLASSES_ROOT\CLSID\{36A21736-36C2-4C11-8ACB-D4136F2B57BD}]
2005-03-05 07:30 136312 –a—— C:\WINDOWS\system32\AcSignIcon.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"pamela.exe"="C:\Program Files\Pamela\Pamela.exe" [2007-04-14 16:44]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-03 23:56 C:\WINDOWS\system32\rundll32.exe]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-04 17:40]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-04 17:38]
"MW1HelperStartUp"="C:\PROGRA~1\MAGICW~1\MW1HEL~1.exe" []
"VC6Player"="C:\Program Files\HHVcdV6Sys\VC6Play.exe" [2004-06-25 11:44]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-10-20 23:50]
"mmtask"="C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [2004-09-22 18:20]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" []
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-03-07 13:02]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2006-03-17 06:34]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2005-10-20 11:00]
"AeXAgentLogon"="C:\Program Files\Altiris\Altiris Agent\AeXAgentActivate.exe" [2006-09-14 00:42]
"AClntUsr"="C:\Altiris\AClient\AClntUsr.EXE" [2007-12-09 08:18]
"MaxtorOneTouch"="C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe" [2005-11-09 15:19]
"mxomssmenu"="C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe" [2005-10-17 15:24]
"Synchronization Manager"="C:\WINDOWS\system32\mobsync.exe" [2004-08-03 23:56]
"SpyHunter Security Suite"="C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe" []
"dkjalubc"="C:\Program Files\dkjalubc\bcfsjmhq.dll" []
"combofix"="C:\WINDOWS\system32\cmd.exe" [2004-08-03 23:56]
"jovsxizm"="regsvr32 /u C:\Documents and Settings\All Users\Application Data\jovsxizm.dll" []
"b0cbf53b"="C:\WINDOWS\system32\aupaeqlf.dll" []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"combofix"="C:\WINDOWS\system32\cmd.exe" [2004-08-03 23:56]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 10:24]
C:\Documents and Settings\Ruairidh\Start Menu\Programs\Startup\
Skype.lnk - C:\Program Files\Skype\Phone\Skype.exe [2007-09-13 13:31:38]
C:\Documents and Settings\co.endeavour\Start Menu\Programs\Startup\
HotSync Manager.lnk - C:\Program Files\palmOne\HOTSYNC.EXE [2004-04-13 17:03:10]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
AutoCAD LT Startup Accelerator.lnk - C:\Program Files\Common Files\Autodesk Shared\acstart16.exe [2005-03-05 07:18:22]
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [2007-01-15 15:03:07]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtuvuv]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"= AMINIT.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoCAD LT Startup Accelerator.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoCAD LT Startup Accelerator.lnk
backup=C:\WINDOWS\pss\AutoCAD LT Startup Accelerator.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Cisco Systems VPN Client.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Cisco Systems VPN Client.lnk
backup=C:\WINDOWS\pss\Cisco Systems VPN Client.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
2004-09-22 18:20 131072 –a—— C:\Program Files\MusicMatch\MusicMatch Jukebox\mm_tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /installquiet
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
R1 CCDevice;CCDevice;C:\WINDOWS\system32\drivers\CCDevice.sys
R1 SLEE_13_DRIVER;Steganos Live Encryption Engine 13 [Driver];\??\C:\WINDOWS\system32\drivers\SLEE13.sys
R3 EMCR;EMCR;C:\WINDOWS\system32\DRIVERS\EMCR7SK.sys
S3 AlKernel;Altiris Kernel Driver;C:\WINDOWS\system32\Drivers\AlKernel.sys
S3 RimSerPort;RIM Virtual Serial Port;C:\WINDOWS\system32\DRIVERS\RimSerial.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - G:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5d4c3217-1915-11dc-9aaf-00c09f37438b}]
\Shell\AutoRun\command - G:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b9fc2d39-e48e-11db-9aa2-00c09f37438b}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bd67d93e-4d12-11dc-9ab9-00c09f37438b}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dcd1411b-a069-11dc-9aca-00c09f37438b}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe killVBS.vbs
.
Contents of the 'Scheduled Tasks' folder
"2007-12-09 09:00:29 C:\WINDOWS\Tasks\SyncBack Backup of server files.job"
- C:\Program Files\2BrightSparks\SyncBack\SyncBack.exe
"2007-12-03 16:08:44 C:\WINDOWS\Tasks\SyncBack backup to external drive.job"
- C:\Program Files\2BrightSparks\SyncBack\SyncBack.exe
.
**************************************************************************
catchme 0.3.1331 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-09 08:19:27
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-09 8:25:49 - machine was rebooted
.
— E O F —
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:34, on 2007-12-09
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Altiris\AClient\AClient.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Altiris\Altiris Agent\AeXNSAgent.exe
C:\WINDOWS\system32\ccsrvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Altiris\Carbon Copy\shellker.exe
C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe
C:\Program Files\Maxtor\OneTouch\Utils\SyncServices.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\PROGRA~1\Altiris\CARBON~1\client.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\HHVcdV6Sys\VC6SecS.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HHVcdV6Sys\VC6Play.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Altiris\AClient\AClntUsr.EXE
C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\Program Files\Pamela\Pamela.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\palmOne\HOTSYNC.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1C8637D8-25F7-4883-B845-83997A720730} - (no file)
O2 - BHO: (no name) - {2B7BBAC2-2089-4A3F-98A3-8BB5BC67A5B2} - (no file)
O2 - BHO: (no name) - {3FFE159E-1D39-4F6F-A08B-10E6910F019D} - (no file)
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7BD0D837-3ABA-4CC8-ABE7-98330A2C7959} - (no file)
O2 - BHO: (no name) - {9AEBAF79-EF2E-427F-AE7D-D5F031F68135} - (no file)
O2 - BHO: (no name) - {CEA1FF0D-9F98-4340-81F5-129B1D1E3543} - (no file)
O2 - BHO: (no name) - {DECCA76E-40E0-48F0-B22C-FDE46949F8F7} - (no file)
O2 - BHO: (no name) - {FA61EE4D-C9EB-4D16-A235-5A2F1165832A} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [MW1HelperStartUp] C:\PROGRA~1\MAGICW~1\MW1HEL~1.EXE /partner MW1
O4 - HKLM\..\Run: [VC6Player] C:\Program Files\HHVcdV6Sys\VC6Play.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [AeXAgentLogon] C:\Program Files\Altiris\Altiris Agent\AeXAgentActivate.exe /logon
O4 - HKLM\..\Run: [AClntUsr] C:\Altiris\AClient\AClntUsr.EXE
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [SpyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
O4 - HKCU\..\Run: [pamela.exe] "C:\Program Files\Pamela\Pamela.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'Default user')
O4 - Startup: HotSync Manager.lnk = C:\Program Files\palmOne\HOTSYNC.EXE
O4 - Global Startup: AutoCAD LT Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O8 - Extra context menu item: &Search; - ?p=zuzeb004YYUS_undefined
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://help.cableone.net
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupdate.microsoft.com/v5co…b?1115335185812
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = sd.local
O17 - HKLM\Software\..\Telephony: DomainName = sd.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = sd.local
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = sd.local
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: AMINIT.dll
O23 - Service: Altiris Client Service (AClient) - Altiris, Inc. - C:\Altiris\AClient\AClient.exe
O23 - Service: Altiris Agent (AeXNSClient) - Altiris, Inc. - C:\Program Files\Altiris\Altiris Agent\AeXNSAgent.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Altiris Carbon Copy (CarbonCopy32) - Altiris - C:\WINDOWS\system32\ccsrvc.exe
O23 - Service: Carbon Copy Scheduler (CarbonCopyScheduler) - Altiris - C:\WINDOWS\system32\schdsrvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: MaxBackServiceInt - Unknown owner - C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe
O23 - Service: MaxSyncService (NTService1) - - C:\Program Files\Maxtor\OneTouch\Utils\SyncServices.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Roger Wilco Base Station - Unknown owner - C:\Program Files\Roger Wilco\rwbs\rwbs.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Virtual CD v6 Management Service (VC6SecS) - H+H Software GmbH - C:\Program Files\HHVcdV6Sys\VC6SecS.exe
–
End of file - 9532 bytes