I am struggling with ComboFix.
Even after disabling Norton Antivirus, I kept getting messages of malicious scripts due to ComboFix.
ComboFix did complete a scan and log; however, I was then unable to get back online through my wireless connection.
I also noticed a new file on my DeskTop titled, CatchMe.Zip.
I restored my system, using the ComboFix restore point. I was then able to get back online.
I re-ran ComboFix and again was unable to get back online. I restored my system again and was able to get back online.
I have posted both my ComboFix log and HJT log (renamed Scanner). However, my system has been restored after running ComboFix and HJT.
ComboFix 07-12-12.3 - Scott Lamm 2007-12-11 19:20:04.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.256 [GMT -7:00]
Running from: C:\Documents and Settings\Scott Lamm\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\cookies.ini
C:\WINDOWS\msettings.ini
C:\WINDOWS\system32\acfpukcr.exe
C:\WINDOWS\system32\adivsvtp.exe
C:\WINDOWS\system32\bhgvsiam.dll
C:\WINDOWS\system32\erwpxjpq.exe
C:\WINDOWS\system32\fhhhk.bak2
C:\WINDOWS\system32\fhhhk.ini
C:\WINDOWS\system32\htdpvtbm.ini
C:\WINDOWS\system32\jcxmnuyy.dll
C:\WINDOWS\system32\jjutqjiy.dll
C:\WINDOWS\system32\khhhf.dll
C:\WINDOWS\system32\kknmvyrj.dll
C:\WINDOWS\system32\knxobtas.dll
C:\WINDOWS\system32\lsp.dll
C:\WINDOWS\system32\mbtvpdth.dll
C:\WINDOWS\system32\obkyiocw.ini
C:\WINDOWS\system32\okldwckq.exe
C:\WINDOWS\system32\renykiaj.exe
C:\WINDOWS\system32\sihidaws.dll
C:\WINDOWS\system32\tdhspspb.dll
C:\WINDOWS\system32\ufmikbyg.dll
C:\WINDOWS\system32\wcoiykbo.dll
C:\WINDOWS\system32\xeibrwcw.exe
C:\WINDOWS\system32\yijqtujj.ini
C:\WINDOWS\system32\yyunmxcj.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
-------\DomainService
((((((((((((((((((((((((( Files Created from 2007-11-12 to 2007-12-12 )))))))))))))))))))))))))))))))
.
2007-12-10 23:00 . 2007-12-11 18:57 <DIR> d-------- C:\ComboFix(2)
2007-12-09 22:27 . 2007-12-09 22:27 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-09 22:05 . 2007-12-11 19:01 913,142 --ahs---- C:\WINDOWS\system32\jxmclefn.ini
2007-12-08 20:19 . 2007-12-09 22:00 834,178 --ahs---- C:\WINDOWS\system32\sofsapec.ini
2007-12-07 17:16 . 2007-12-07 17:16 143 --a------ C:\WINDOWS\system32\mcrh.tmp
2007-12-04 19:44 . 2007-12-04 19:25 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2007-12-04 19:24 . 2007-12-04 20:52 <DIR> d-------- C:\Documents and Settings\Scott Lamm\.housecall6.6
2007-12-03 15:50 . 2007-12-04 19:21 794,187 --ahs---- C:\WINDOWS\system32\rinxtict.ini
2007-12-02 21:31 . 2007-12-02 21:31 <DIR> d-------- C:\Documents and Settings\Scott Lamm\Application Data\Grisoft
2007-12-02 21:30 . 2007-12-02 21:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-02 21:30 . 2007-05-30 05:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-12-02 21:09 . 2007-12-02 21:10 <DIR> d-------- C:\Documents and Settings\Scott Lamm\Application Data\AdwareAlert
2007-11-17 19:22 . 2007-11-17 19:22 24,064 --a------ C:\wndauqq.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-12 01:57 --------- d-----w C:\Program Files\Symantec
2007-12-12 01:57 --------- d-----w C:\Program Files\Norton AntiVirus
2007-12-12 01:57 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-12-12 01:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2007-12-03 04:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-10 04:45 24,064 ----a-w C:\wndrbvm.exe
2007-10-29 03:31 7,822 ----a-w C:\sysdbas.exe
2007-10-06 21:50 7,810 ----a-w C:\sysgzby.exe
2007-09-18 02:35 471,216 ----a-w C:\Program Files\msgr8us.exe
2007-03-12 00:15 30,240 -c--a-w C:\Documents and Settings\Scott Lamm\Application Data\GDIPFONTCACHEV1.DAT
2004-09-18 19:09 6,928 ----a-w C:\Program Files\startuplist.txt
2004-09-07 04:53 0 -csha-w C:\WINDOWS\system32\pojut.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpySweeper"="" []
"E6TaskPanel"="C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" [2005-09-01 15:24]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"00THotkey"="C:\WINDOWS\System32\
00THotkey.exe" [2002-04-15 18:35]
"000StTHK"="000StTHK.exe" [2001-06-23 20:28 C:\WINDOWS\system32\
000StTHK.exe]
"NAV Agent"="C:\PROGRA~1\NORTON~1\navapw32.exe" [2002-02-27 11:27]
"TFNF5"="TFNF5.exe" [2002-06-26 14:43 C:\WINDOWS\system32\TFNF5.exe]
"Tpwrtray"="TPWRTRAY.EXE" [2002-03-19 20:38 C:\WINDOWS\system32\TPWRTRAY.EXE]
"TosHKCW.exe"="C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe" [2002-01-22 18:20]
"ezShieldProtector for Px"="C:\WINDOWS\System32\ezSP_Px.exe" [2002-07-03 17:17]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-04 00:56 C:\WINDOWS\system32\rundll32.exe]
"nwiz"="nwiz.exe" [2002-07-24 23:18 C:\WINDOWS\system32\nwiz.exe]
"LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [2002-05-30 17:23]
"TFncKy"="TFncKy.exe" []
"TcmTray"="" []
"TDispVol"="TDispVol.exe" [2002-03-02 12:40 C:\WINDOWS\system32\TDispVol.exe]
"TMESBS.EXE"="C:\Program Files\TOSHIBA\TME3\TMESBS32.exe" [2002-08-02 12:36]
"TouchED"="C:\Program Files\TOSHIBA\TouchED\TouchED.Exe" [2002-07-09 11:13]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2001-11-14 02:37]
"TSysSMon"="c:\toshiba\sysstability\tsyssmon.exe" [2002-04-05 14:44]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2002-08-01 14:43]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2002-08-01 14:43]
"HPDJ Taskbar Utility"="C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe" [2002-05-24 05:46]
"Samsung LBP SM"="C:\WINDOWS\Samsung\LaserSMMgr\ssmmgr.exe" [2003-01-13 23:57]
"Propel Accelerator"="C:\Program Files\EarthLink TotalAccess\Accelerator\PropelAC.exe" []
"StatusClient"="C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe" [2002-12-16 15:51]
"TomcatStartup"="C:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe" [2003-03-31 18:28]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe" [2004-06-03 21:05]
"ELNKProxy"="C:\WINDOWS\surfmonkey\smproxy.exe" [2004-06-18 21:15]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2005-06-10 02:21]
"IVPServiceMgr"="C:\toshiba\ivp\ism\ivpsvmgr.exe" [2002-07-15 14:27]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 02:25]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Spyware Doctor"="" []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)
R0 tosrfec;Bluetooth ACPI from Toshiba;C:\WINDOWS\system32\DRIVERS\tosrfec.sys
R0 TVALDX;Toshiba ACPI-Based Value Added Logical Device Extension Driver;C:\WINDOWS\system32\DRIVERS\TVALDX.SYS
R0 TVALG;Toshiba Value Added Logical and General Purpose Device Driver;C:\WINDOWS\system32\DRIVERS\TVALG.SYS
R2 EarthLinkMonitor;EarthLink Monitor Service;"C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe"
R2 Tmesbs;Tmesbs32;"C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe" /Service
R3 BW2NDIS5;BW2NDIS5;C:\WINDOWS\system32\Drivers\BW2NDIS5.sys
R3 RT2400PCI;802.11b WLAN PCI;C:\WINDOWS\system32\DRIVERS\RT2400.sys
R3 tsdhd;TOSHIBA SD Card Host Controller Driver;C:\WINDOWS\system32\DRIVERS\tsdhd.sys
R3 WDM_YAMAHAAC97;YAMAHA AC-XG Audio Device;C:\WINDOWS\system32\drivers\yacxgc.sys
S3 pciSd;pciSd;C:\WINDOWS\system32\DRIVERS\tossdpci.sys
S3 toslane;Toshiba BT-LANE;C:\WINDOWS\system32\DRIVERS\TOSRFLAN.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{800c8d80-a7da-11da-b74b-0008a15b1244}]
\Shell\AutoRun\command - E:\JDLightning\Windows\JDLightning.exe
.
Contents of the 'Scheduled Tasks' folder
"2007-12-10 10:00:00 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job"
- C:\Program Files\AdwareAlert\AdwareAlert.ex
- C:\Program Files\AdwareAlert
"2007-12-10 07:00:00 C:\WINDOWS\Tasks\At25.job"
- C:\WINDOWS\system32\201lJKKG.exe
"2007-12-10 08:00:00 C:\WINDOWS\Tasks\At26.job"
- C:\WINDOWS\system32\201lJKKG.exe
"2007-12-10 09:00:00 C:\WINDOWS\Tasks\At27.job"
- C:\WINDOWS\system32\201lJKKG.exe
"2007-12-10 10:00:00 C:\WINDOWS\Tasks\At28.job"
- C:\WINDOWS\system32\201lJKKG.exe
"2007-12-10 11:00:00 C:\WINDOWS\Tasks\At29.job"
- C:\WINDOWS\system32\201lJKKG.exe
"2007-12-10 12:00:00 C:\WINDOWS\Tasks\At30.job"
- C:\WINDOWS\system32\201lJKKG.exe
"2007-12-10 13:00:00 C:\WINDOWS\Tasks\At31.job"
- C:\WINDOWS\system32\201lJKKG.exe
"2007-12-10 14:00:00 C:\WINDOWS\Tasks\At32.job"
- C:\WINDOWS\system32\201lJKKG.exe
"2007-12-10 15:00:00 C:\WINDOWS\Tasks\At33.job"
"2007-12-10 16:00:00 C:\WINDOWS\Tasks\At34.job"
- C:\WINDOWS\system32\201lJKKG.exe
"2007-12-10 17:00:00 C:\WINDOWS\Tasks\At35.job"
- C:\WINDOWS\system32\201lJKKG.exe
"2007-12-10 18:00:00 C:\WINDOWS\Tasks\At36.job"
- C:\WINDOWS\system32\201lJKKG.exe
"2007-12-10 19:00:00 C:\WINDOWS\Tasks\At37.job"
- C:\WINDOWS\system32\201lJKKG.exe
"2007-12-10 20:00:00 C:\WINDOWS\Tasks\At38.job"
- C:\WINDOWS\system32\201lJKKG.exe
"2007-12-10 21:00:00 C:\WINDOWS\Tasks\At39.job"
- C:\WINDOWS\system32\201lJKKG.exe
"2007-12-10 22:00:00 C:\WINDOWS\Tasks\At40.job"
- C:\WINDOWS\system32\201lJKKG.exe
"2007-12-10 23:00:00 C:\WINDOWS\Tasks\At41.job"
- C:\WINDOWS\system32\201lJKKG.exe
"2007-12-11 00:00:00 C:\WINDOWS\Tasks\At42.job"
"2007-12-11 01:00:00 C:\WINDOWS\Tasks\At43.job"
- C:\WINDOWS\system32\201lJKKG.exe
"2007-12-12 02:00:01 C:\WINDOWS\Tasks\At44.job"
- C:\WINDOWS\system32\201lJKKG.exe
"2007-12-06 03:00:00 C:\WINDOWS\Tasks\At45.job"
- C:\WINDOWS\system32\201lJKKG.exe
"2007-12-05 04:00:00 C:\WINDOWS\Tasks\At46.job"
- C:\WINDOWS\system32\201lJKKG.exe
"2007-12-11 05:00:00 C:\WINDOWS\Tasks\At47.job"
- C:\WINDOWS\system32\201lJKKG.exe
"2007-12-11 06:00:00 C:\WINDOWS\Tasks\At48.job"
- C:\WINDOWS\system32\201lJKKG.exe
"2003-02-24 03:45:37 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-11 19:28:48
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-11 19:32:33 - machine was rebooted
C:\ComboFix2.txt ... 2007-12-10 22:28
C:\ComboFix3.txt ... 2007-12-10 22:12
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:33:35 PM, on 12/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe
C:\WINDOWS\System32\00THotkey.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\TFNF5.exe
C:\WINDOWS\system32\TPWRTRAY.EXE
C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\Program Files\TOSHIBA\TME3\TMESBS32.EXE
C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
C:\toshiba\ivp\ism\pinger.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\Samsung\LaserSMMgr\ssmmgr.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\WINDOWS\surfmonkey\smproxy.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\toshiba\ivp\ism\ivpsvmgr.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\EarthLink TotalAccess\TaskPanl.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Trend Micro\HijackThis\Scanner.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.yahoo.com
R3 - URLSearchHook: SrchHook Class - {44F9B173-041C-4825-A9B9-D914BD9DCBB3} - C:\Program Files\EarthLink TotalAccess\ElnIE.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: EarthLink ScamBlocker V2 - {15F4D456-5BAA-4076-8486-EECB38CD3E57} - C:\Program Files\EarthLink TotalAccess\Toolbar\EScamBlk.dll
O2 - BHO: EarthLink PopUp Blocker V2 - {512ACF1B-64D9-4928-B382-A80556F28DB4} - C:\Program Files\EarthLink TotalAccess\Toolbar\ElnkPuB.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: IE_PopupBlocker Class - {656EC4B7-072B-4698-B504-2A414C1F0037} - C:\Program Files\EarthLink TotalAccess\Accelerator\prpl_IePopupBlocker.dll
O2 - BHO: Earthlink Protection BHO - {9579D574-D4D8-4335-9560-FE8641A013BD} - C:\Program Files\EarthLink TotalAccess\Toolbar\ProtctIE.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Uninstall Legacy Earthlink Toolbar - {E713904C-DF05-4C79-BBAD-02DB923253BE} - C:\Program Files\EarthLink TotalAccess\Toolbar\uninsttb.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: EarthLink Toolbar - {C7768536-96F8-4001-B1A2-90EE21279187} - C:\Program Files\EarthLink TotalAccess\Toolbar\Toolbar.dll
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE
O4 - HKLM\..\Run: [TosHKCW.exe] "C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe"
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe /Type 03
O4 - HKLM\..\Run: [TDispVol] TDispVol.exe
O4 - HKLM\..\Run: [TMESBS.EXE] C:\Program Files\TOSHIBA\TME3\TMESBS32.EXE /Client
O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [TSysSMon] c:\toshiba\sysstability\tsyssmon.exe /detect
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [Samsung LBP SM] "C:\WINDOWS\Samsung\LaserSMMgr\ssmmgr.exe" /autorun
O4 - HKLM\..\Run: [Propel Accelerator] "C:\Program Files\EarthLink TotalAccess\Accelerator\PropelAC.exe"
O4 - HKLM\..\Run: [StatusClient] C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [TomcatStartup] C:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [ELNKProxy] C:\WINDOWS\surfmonkey\smproxy.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [IVPServiceMgr] C:\toshiba\ivp\ism\ivpsvmgr.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [E6TaskPanel] "C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" -winstart
O4 - HKUS\S-1-5-18\..\Run: [Spyware Doctor] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Spyware Doctor] (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\lsp.dll' missing
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1123354617364
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) -
http://www3.ca.com/s...nfo/webscan.cab
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: EarthLink Monitor Service (EarthLinkMonitor) - Boingo Wireless, Inc. - C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\System32\HPHipm11.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Tmesbs32 (Tmesbs) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TME3\Tmesbs32.exe
--
End of file - 8283 bytes