
Here are the logs that I was earlier instructed to post a big thank you in advance
ComboFix 07-12-30.3 - Kids 2007-12-30 15:13:03.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.681 [GMT -6:00]
Running from: C:\Documents and Settings\Kids\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\check_LSA7.txt
C:\Documents and Settings\Administrator\Application Data\WinAntiVirus Pro 2007
C:\Documents and Settings\All Users\Application Data.\hmjyruny.dll
C:\Documents and Settings\All Users\Application Data.\ihavopkp.dll
C:\Documents and Settings\All Users\Application Data.\jcvavefk.dll
C:\Documents and Settings\All Users\Application Data.\salesmonitor
C:\Documents and Settings\All Users\Application Data.\vmdsvkxs.dll
C:\Documents and Settings\All Users\Application Data.\winantispyware 2007
C:\Documents and Settings\All Users\Application Data.\winantispyware 2007\Data\Abbr
C:\Documents and Settings\All Users\Application Data.\winantispyware 2007\Data\ProductCode
C:\Documents and Settings\All Users\Application Data\WinAntiSpyware 2007\Data\Abbr
C:\Documents and Settings\All Users\Application Data\WinAntiSpyware 2007\Data\ProductCode
C:\Documents and Settings\All Users\Application Data\WinAntiVirus Pro 2007
C:\Documents and Settings\All Users\Application Data\WinAntiVirus Pro 2007\Data\Abbr
C:\Documents and Settings\All Users\Application Data\WinAntiVirus Pro 2007\Data\ActivationCode
C:\Documents and Settings\All Users\Application Data\WinAntiVirus Pro 2007\Data\ProductCode
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\autorun.exe
C:\Documents and Settings\Dad\Application Data\WinAntiSpyware 2007
C:\Documents and Settings\Dad\Application Data\WinAntiSpyware 2007\Logs\update.log
C:\Documents and Settings\Dad\Application Data\WinAntiVirus Pro 2007
C:\Documents and Settings\Dad\Application Data\WinAntiVirus Pro 2007\history.db
C:\Documents and Settings\Dad\Application Data\WinAntiVirus Pro 2007\Logs\wa7Support.log
C:\Documents and Settings\Dad\Application Data\WinAntiVirus Pro 2007\Logs\winav.log
C:\Documents and Settings\Dad\Application Data\WinAntiVirus Pro 2007\PGE.dat
C:\Documents and Settings\Dad\err.log
C:\Documents and Settings\Dad\ResErrors.log
C:\Documents and Settings\Dad\Start Menu\Programs\Startup\system.exe
C:\Documents and Settings\Kids\Application Data\APPATC~1
C:\Documents and Settings\Kids\Application Data\DOBE~1
C:\Documents and Settings\Kids\Application Data\DOBE~2
C:\Documents and Settings\Kids\Application Data\ICROSO~1
C:\Documents and Settings\Kids\Application Data\SpyGuardPro
C:\Documents and Settings\Kids\Application Data\SpyGuardPro\avtasks.dat
C:\Documents and Settings\Kids\Application Data\SpyGuardPro\Logs\av.log
C:\Documents and Settings\Kids\Application Data\SpyGuardPro\Logs\ga6Support.log
C:\Documents and Settings\Kids\Application Data\SpyGuardPro\Logs\update.log
C:\Documents and Settings\Kids\Application Data\SSTEM3~1
C:\Documents and Settings\Kids\err.log
C:\Documents and Settings\Kids\Favorites\.url
C:\Documents and Settings\Kids\My Documents\ASKS~1
C:\Documents and Settings\Kids\My Documents\MCROSO~1
C:\Documents and Settings\Kids\My Documents\SMBOLS~1
C:\Documents and Settings\Kids\My Documents\SMBOLS~1\?pool32.exe
C:\Documents and Settings\Kids\My Documents\STEM~1
C:\Documents and Settings\Kids\My Documents\WNSXS~1
C:\Documents and Settings\Kids\My Documents\WNSXS~1\c?rss.exe
C:\Documents and Settings\Kids\ResErrors.log
C:\Documents and Settings\Kids\Start Menu\Programs\Outerinfo
C:\Documents and Settings\Kids\Start Menu\Programs\Outerinfo\Terms.lnk
C:\Documents and Settings\Kids\Start Menu\Programs\Outerinfo\Uninstall.lnk
C:\Documents and Settings\Kids\Start Menu\Programs\Startup\system.exe
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Documents and Settings\LocalService\Application Data\NetMon\domains.txt
C:\Documents and Settings\LocalService\Application Data\NetMon\log.txt
C:\Documents and Settings\Mom\Start Menu\Programs\Startup\system.exe
C:\Documents and Settings\NetworkService\Application Data\NetMon
C:\Documents and Settings\NetworkService\Application Data\NetMon\domains.txt
C:\Documents and Settings\NetworkService\Application Data\NetMon\log.txt
C:\install.exe
C:\Program Files\Common Files\dobe~1
C:\Program Files\Common Files\fnts~1
C:\Program Files\Common Files\mantec~1
C:\Program Files\Common Files\mcroso~1
C:\Program Files\Common Files\ppatch~1
C:\Program Files\Common Files\prohdyx.html
C:\Program Files\Common Files\scurit~1
C:\Program Files\Common Files\stem~1
C:\Program Files\Common Files\stem32~1
C:\Program Files\Common Files\ystem3~1
C:\Program Files\curity~1
C:\Program Files\curity~1\n?pdb.exe
C:\Program Files\Esqpooli
C:\Program Files\Esqpooli\uyiwwtbe.dll
C:\Program Files\Lnoiwmcn
C:\Program Files\Lnoiwmcn\wfrxvpxf.dll
C:\Program Files\outerinfo
C:\Program Files\outerinfo\FF\chrome.manifest
C:\Program Files\outerinfo\FF\components\FF.dll
C:\Program Files\outerinfo\FF\components\OuterinfoAds.xpt
C:\Program Files\outerinfo\FF\install.rdf
C:\Program Files\outerinfo\OiUninstaller.exe
C:\Program Files\outerinfo\outerinfo.ico
C:\Program Files\outerinfo\Terms.rtf
C:\Program Files\qtyvwneh
C:\Program Files\qtyvwneh\mruvmhwn.dll
C:\Program Files\racle~1
C:\Program Files\sstem~1
C:\Program Files\TBONAS
C:\Program Files\TBONAS\bestoffers_icon_01.ico
C:\Program Files\TBONAS\center_wnd.htm
C:\Program Files\TBONAS\comp.htm
C:\Program Files\TBONAS\grb12.rtk
C:\Program Files\TBONAS\TBONcomp.dll
C:\Program Files\Zbnhrqxd
C:\Program Files\Zbnhrqxd\tbogtksk.dll
C:\temp\0c2
C:\temp\0c2\tmpFF.log
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\abW9
C:\Temp\abW9\tPho.log
C:\temp\brr
C:\temp\brr\tmpZTF.log
C:\Temp\fse
C:\Temp\fse\tmpZTF.log
C:\temp\tn3
C:\UGA6P
C:\WINDOWS\avp.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\df87173.exe
C:\WINDOWS\dobe~1
C:\WINDOWS\Downloaded Program Files\UDC6_0001_D19M1908NetInstaller.exe
C:\WINDOWS\Downloaded Program Files\UWA7P_0001_N91M0809NetInstaller.exe
C:\WINDOWS\Downloaded Program Files\UWA7P_0001_N99M2908NetInstaller.exe
C:\WINDOWS\hg173.exe
C:\WINDOWS\mcroso~1
C:\WINDOWS\racle~1
C:\WINDOWS\S2lkcw\
C:\WINDOWS\S2lkcw\\mZ54wT.vbs
C:\WINDOWS\stem~1
C:\WINDOWS\system32\acnhfkgo.dll
C:\WINDOWS\system32\aeapdyqa.dll
C:\WINDOWS\system32\arsoqvbc.exe
C:\WINDOWS\system32\athshjii.exe
C:\WINDOWS\SYSTEM32\ayadd.bak1
C:\WINDOWS\SYSTEM32\ayadd.bak2
C:\WINDOWS\SYSTEM32\ayadd.ini
C:\WINDOWS\SYSTEM32\ayadd.ini2
C:\WINDOWS\SYSTEM32\ayadd.tmp
C:\WINDOWS\system32\bhvhytsu.exe
C:\WINDOWS\system32\bnvppljm.dll
C:\WINDOWS\system32\bpfmqobg.exe
C:\WINDOWS\system32\brjjlqyi.exe
C:\WINDOWS\system32\bwpgupao.exe
C:\WINDOWS\system32\bwrkirvo.exe
C:\WINDOWS\system32\bwujtyew.dll
C:\WINDOWS\system32\clivqseh.exe
C:\WINDOWS\system32\crosof~1.net
C:\WINDOWS\system32\curity~1
C:\WINDOWS\system32\curity~1\??curity\
C:\WINDOWS\system32\curity~1\chkdsk.exe
C:\WINDOWS\system32\dbreaviw.exe
C:\WINDOWS\system32\ddaya.dll
C:\WINDOWS\system32\dewppmtt.dll
C:\WINDOWS\system32\didaxgoc.exe
C:\WINDOWS\system32\dlwartvm.exe
C:\WINDOWS\system32\dniymatp.dll
C:\WINDOWS\system32\drivers\ip6fw.sys
C:\WINDOWS\system32\dvnnmbuk.exe
C:\WINDOWS\system32\ebmpbmqk.dll
C:\WINDOWS\system32\ebnlvoyj.dll
C:\WINDOWS\SYSTEM32\eiyqjiao.ini
C:\WINDOWS\system32\emjgqtlk.dll
C:\WINDOWS\system32\enomionx.dll
C:\WINDOWS\SYSTEM32\eohjxfqe.ini
C:\WINDOWS\system32\eqeobjre.dll
C:\WINDOWS\system32\eqfxjhoe.dll
C:\WINDOWS\SYSTEM32\erjboeqe.ini
C:\WINDOWS\system32\eyvwdoqu.dll
C:\WINDOWS\system32\f02WtR
C:\WINDOWS\system32\f02WtR\f02WtR1065.exe
C:\WINDOWS\system32\fccbxxw.dll
C:\WINDOWS\system32\fccccyv.dll
C:\WINDOWS\system32\fibagbia
C:\WINDOWS\system32\fibagbia\bg1.gif
C:\WINDOWS\system32\fibagbia\bgtop.gif
C:\WINDOWS\system32\fibagbia\bottom1.gif
C:\WINDOWS\system32\fibagbia\essentials.gif
C:\WINDOWS\system32\fibagbia\fibagbia1.exe
C:\WINDOWS\system32\fibagbia\fibagbia2.exe
C:\WINDOWS\system32\fibagbia\fibagbia3.exe
C:\WINDOWS\system32\fibagbia\icon1.ico
C:\WINDOWS\system32\fibagbia\install1.gif
C:\WINDOWS\system32\fibagbia\left1.gif
C:\WINDOWS\system32\fibagbia\li.gif
C:\WINDOWS\system32\fibagbia\logo.gif
C:\WINDOWS\system32\fibagbia\main.htm
C:\WINDOWS\system32\fibagbia\mainframe.htm
C:\WINDOWS\system32\fibagbia\reinstall1.gif
C:\WINDOWS\system32\fibagbia\right1.gif
C:\WINDOWS\system32\fibagbia\s1.htm
C:\WINDOWS\system32\fibagbia\s2.htm
C:\WINDOWS\system32\fibagbia\s3.htm
C:\WINDOWS\system32\fibagbia\SMTop1.gif
C:\WINDOWS\system32\fibagbia\SMTop2.gif
C:\WINDOWS\system32\fibagbia\SMTop3.gif
C:\WINDOWS\system32\fibagbia\SMTop4.gif
C:\WINDOWS\system32\fibagbia\soft1_off.gif
C:\WINDOWS\system32\fibagbia\soft1_off_ext.gif
C:\WINDOWS\system32\fibagbia\soft1_on.gif
C:\WINDOWS\system32\fibagbia\soft1_on_ext.gif
C:\WINDOWS\system32\fibagbia\soft2_off.gif
C:\WINDOWS\system32\fibagbia\soft2_off_ext.gif
C:\WINDOWS\system32\fibagbia\soft2_on.gif
C:\WINDOWS\system32\fibagbia\soft2_on_ext.gif
C:\WINDOWS\system32\fibagbia\soft3_off.gif
C:\WINDOWS\system32\fibagbia\soft3_off_ext.gif
C:\WINDOWS\system32\fibagbia\soft3_on.gif
C:\WINDOWS\system32\fibagbia\soft3_on_ext.gif
C:\WINDOWS\system32\fibagbia\softbottom_off.gif
C:\WINDOWS\system32\fibagbia\softbottom_on.gif
C:\WINDOWS\system32\fibagbia\softleft_off.gif
C:\WINDOWS\system32\fibagbia\softleft_on.gif
C:\WINDOWS\system32\fibagbia\top1.gif
C:\WINDOWS\system32\fibagbia\top2.gif
C:\WINDOWS\system32\fibagbia\turnoff1.gif
C:\WINDOWS\system32\fibagbia\turnon1.gif
C:\WINDOWS\SYSTEM32\foyxtupn.ini
C:\WINDOWS\system32\ftevcfsf.exe
C:\WINDOWS\SYSTEM32\gjtyeaqm.ini
C:\WINDOWS\system32\gmwskqqm.dll
C:\WINDOWS\system32\gqgqvgiw.dll
C:\WINDOWS\SYSTEM32\harxeedm.ini
C:\WINDOWS\SYSTEM32\hauahnsv.ini
C:\WINDOWS\SYSTEM32\hcmpfwtb.ini
C:\WINDOWS\system32\hmiuvgvo.dll
C:\WINDOWS\system32\hptkyyty.exe
C:\WINDOWS\system32\hudppfxn.dll
C:\WINDOWS\system32\hussncrm.dll
C:\WINDOWS\system32\iifcaxw.dll
C:\WINDOWS\SYSTEM32\ipltthyl.ini
C:\WINDOWS\SYSTEM32\ivbwabia.ini
C:\WINDOWS\system32\jbegntaq.dll
C:\WINDOWS\SYSTEM32\jegxksxp.ini
C:\WINDOWS\system32\jhedlsyw.exe
C:\WINDOWS\system32\jisltdnx.dll
C:\WINDOWS\system32\jqjvwfct.exe
C:\WINDOWS\SYSTEM32\jrrsqwvv.ini
C:\WINDOWS\system32\juiwfkbp.exe
C:\WINDOWS\system32\jujgbjso.dll
C:\WINDOWS\system32\jwydacvf.exe
C:\WINDOWS\system32\kdpdpjju.exe
C:\WINDOWS\system32\kernel32.exe
C:\WINDOWS\system32\kjdcamkv.exe
C:\WINDOWS\SYSTEM32\knkdcony.ini
C:\WINDOWS\system32\kqlglbrt.exe
C:\WINDOWS\system32\krvlodxk.exe
C:\WINDOWS\system32\laggmyqh.dll
C:\WINDOWS\system32\lcqgkhtg.exe
C:\WINDOWS\system32\ldinfo.ldr
C:\WINDOWS\system32\lmowrndt.dll
C:\WINDOWS\system32\lmtoboyl.exe
C:\WINDOWS\system32\lyhttlpi.dll
C:\WINDOWS\system32\makpfkph.dll
C:\WINDOWS\system32\maucxfob.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\SYSTEM32\mdadrpvl.ini
C:\WINDOWS\system32\mdeexrah.dll
C:\WINDOWS\system32\mdhrogvu.dll
C:\WINDOWS\system32\mfdfwroy.exe
C:\WINDOWS\system32\mltkrulc.dll
C:\WINDOWS\system32\moxtccyn.dll
C:\WINDOWS\system32\ndjqwsdy.dll
C:\WINDOWS\system32\ngwgdsyl.dll
C:\WINDOWS\system32\njptlrlw.dll
C:\WINDOWS\system32\nmoeeyoa.exe
C:\WINDOWS\system32\nputxyof.dll
C:\WINDOWS\system32\nrmhcxyq.exe
C:\WINDOWS\system32\nypgavrx.exe
C:\WINDOWS\system32\occcvkvv.dll
C:\WINDOWS\system32\ohwdrgdp.dll
C:\WINDOWS\SYSTEM32\olxlorys.ini
C:\WINDOWS\system32\ooauorag.exe
C:\WINDOWS\system32\oohptgkh.exe
C:\WINDOWS\system32\oyxojfpf.dll
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\pevqxbhk.dll
C:\WINDOWS\system32\pfkaapjg.exe
C:\WINDOWS\SYSTEM32\phfliyoy.ini
C:\WINDOWS\system32\pmnklml.dll
C:\WINDOWS\system32\printer.exe
C:\WINDOWS\system32\ptuymanr.dll
C:\WINDOWS\system32\qfqfycgh.dll
C:\WINDOWS\SYSTEM32\qmkpmqgt.ini
C:\WINDOWS\SYSTEM32\qrgxbmwf.ini
C:\WINDOWS\SYSTEM32\qybwrnjk.ini
C:\WINDOWS\system32\rdlsedxo.dll
C:\WINDOWS\system32\rimxlhbu.exe
C:\WINDOWS\system32\rMa02yy
C:\WINDOWS\system32\rngfwblt.exe
C:\WINDOWS\system32\rqrpnmk.dll
C:\WINDOWS\SYSTEM32\rrbrnrbc.ini
C:\WINDOWS\system32\RunOnce3.t__
C:\WINDOWS\system32\RunOnce3.tmp
C:\WINDOWS\system32\sjltchhx.exe
C:\WINDOWS\system32\smbols~1
C:\WINDOWS\system32\solmxesa.dll
C:\WINDOWS\system32\stera.log
C:\WINDOWS\system32\swxaullc.dll
C:\WINDOWS\system32\tchaixsu.dll
C:\WINDOWS\system32\tcpconn.exe
C:\WINDOWS\SYSTEM32\tdnrwoml.ini
C:\WINDOWS\SYSTEM32\teocpbvq.ini
C:\WINDOWS\system32\tibasrgo.dll
C:\WINDOWS\system32\tjsxvnth.exe
C:\WINDOWS\system32\tjwxwmw.dll
C:\WINDOWS\system32\tmp_03.exe
C:\WINDOWS\SYSTEM32\topfrxqg.ini
C:\WINDOWS\system32\tuvurom.dll
C:\WINDOWS\system32\uaneqdpu.dll
C:\WINDOWS\system32\uffyoelq.exe
C:\WINDOWS\system32\update118.exe
C:\WINDOWS\system32\update125.exe
C:\WINDOWS\SYSTEM32\usxiahct.ini
C:\WINDOWS\SYSTEM32\utstv.bak1
C:\WINDOWS\SYSTEM32\utstv.ini
C:\WINDOWS\SYSTEM32\vliocrta.ini
C:\WINDOWS\system32\vsbmugxo.dll
C:\WINDOWS\system32\vtjuwmoy.dll
C:\WINDOWS\system32\vtr.dll
C:\WINDOWS\system32\vtstu.dll
C:\WINDOWS\system32\vtutrpo.dll
C:\WINDOWS\system32\vytveejf.exe
C:\WINDOWS\system32\wbwavqey.exe
C:\WINDOWS\SYSTEM32\wigvqgqg.ini
C:\WINDOWS\system32\win_6x0.dll
C:\WINDOWS\system32\WinAvXX.exe
C:\WINDOWS\system32\wintsvsu32.exe
C:\WINDOWS\system32\witnpncr.dll
C:\WINDOWS\SYSTEM32\wlrltpjn.ini
C:\WINDOWS\system32\wsxrbhpv.dll
C:\WINDOWS\SYSTEM32\wtwevjoj.ini
C:\WINDOWS\system32\wuebhvsx.dll
C:\WINDOWS\system32\wvkioabg.exe
C:\WINDOWS\system32\wvurpop.dll
C:\WINDOWS\system32\wxiabvyr.exe
C:\WINDOWS\system32\xasxxnoo.exe
C:\WINDOWS\SYSTEM32\xnoimone.ini
C:\WINDOWS\system32\xppuojch.dll
C:\WINDOWS\system32\yayyawt.dll
C:\WINDOWS\SYSTEM32\ybxwnuxy.ini
C:\WINDOWS\system32\yemfvanj.exe
C:\WINDOWS\system32\ylfoykjq.exe
C:\WINDOWS\system32\ymante~1
C:\WINDOWS\system32\ypfgkemn.dll
C:\WINDOWS\system32\yrsixdeo.dll
C:\WINDOWS\system32\zcksjni.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_APIMON
-------\LEGACY_CMDSERVICE
-------\LEGACY_DOMAINSERVICE
-------\LEGACY_FMTR
-------\LEGACY_FOPN
-------\LEGACY_NETWORK_MONITOR
-------\cmdService
-------\DomainService
((((((((((((((((((((((((( Files Created from 2007-11-28 to 2007-12-30 )))))))))))))))))))))))))))))))
.
2007-12-30 14:22 . 2007-12-30 14:22 <DIR> d-------- C:\Documents and Settings\Kids\Application Data\U3
2007-12-30 14:21 . 2007-12-30 14:21 <DIR> d-------- C:\Documents and Settings\Kids\Application Data\Downloaded Installations
2007-12-28 19:07 . 2007-12-30 13:37 1,957,306 --ahs---- C:\WINDOWS\SYSTEM32\hedbvqcf.ini
2007-12-28 12:28 . 2007-12-28 19:01 1,960,903 --ahs---- C:\WINDOWS\SYSTEM32\bfikrole.ini
2007-12-27 16:05 . 2007-12-28 12:25 1,962,496 --ahs---- C:\WINDOWS\SYSTEM32\qdcjecsb.ini
2007-12-20 22:20 . 2007-12-27 16:05 1,965,090 --ahs---- C:\WINDOWS\SYSTEM32\ximgmxuw.ini
2007-12-20 06:43 . 2007-12-20 22:13 1,672,434 --ahs---- C:\WINDOWS\SYSTEM32\ylidfnwh.ini
2007-12-19 06:43 . 2007-12-20 13:53 1,663,902 --ahs---- C:\WINDOWS\SYSTEM32\kvludivx.ini
2007-12-18 06:40 . 2007-12-19 06:40 1,544,929 --ahs---- C:\WINDOWS\SYSTEM32\gjonrfck.ini
2007-12-17 11:13 . 2007-12-18 06:31 1,526,923 --ahs---- C:\WINDOWS\SYSTEM32\aabeynod.ini
2007-12-16 11:10 . 2007-12-17 11:11 1,528,558 --ahs---- C:\WINDOWS\SYSTEM32\chjpvbdb.ini
2007-12-15 11:10 . 2007-12-17 16:34 1,601,831 --ahs---- C:\WINDOWS\SYSTEM32\rgfknelu.ini
2007-12-15 08:47 . 2007-12-15 11:04 1,555,692 --ahs---- C:\WINDOWS\SYSTEM32\iwlxvyep.ini
2007-12-15 07:51 . 2007-12-15 08:41 1,595,819 --ahs---- C:\WINDOWS\SYSTEM32\sawlcetv.ini
2007-12-14 07:54 . 2007-12-14 07:55 1,566,441 --ahs---- C:\WINDOWS\SYSTEM32\mspnqsuu.ini
2007-12-13 18:19 . 2007-12-14 07:46 1,587,419 --ahs---- C:\WINDOWS\SYSTEM32\nxabciyb.ini
2007-11-29 18:10 . 2007-11-29 15:42 834 --ahs---- C:\WINDOWS\SYSTEM32\tjidbhrt.ini
2007-11-29 15:41 . 2007-11-29 15:42 834 --ahs---- C:\WINDOWS\SYSTEM32\tjidbhrt.tmp
2007-11-28 15:47 . 2007-11-29 03:56 1,967,575 --ahs---- C:\WINDOWS\SYSTEM32\xppntnvj.ini
2007-11-27 15:41 . 2007-11-28 15:47 2,001,066 --ahs---- C:\WINDOWS\SYSTEM32\fcntsqec.ini
2007-11-27 15:32 . 2007-11-27 15:32 0 --a------ C:\WINDOWS\SYSTEM32\poobcpdd.tmp
2007-11-26 11:13 . 2007-11-26 11:13 4,286 --a------ C:\WINDOWS\SYSTEM32\everybodybets.32x32.4.ico
2007-11-26 11:02 . 2007-11-27 15:32 2,066,501 --ahs---- C:\WINDOWS\SYSTEM32\poobcpdd.ini
2007-11-24 03:00 . 2007-12-30 14:20 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-11-23 06:34 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\SYSTEM32\mucltui.dll
2007-11-23 06:34 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\SYSTEM32\muweb.dll
2007-11-23 06:34 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\SYSTEM32\mucltui.dll.mui
2007-11-22 18:22 . 2007-12-30 14:20 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2007-11-22 18:21 . 2007-11-22 18:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2007-11-18 23:24 . 2007-11-18 23:24 20,480 --a------ C:\WINDOWS\quit.exe
2007-11-18 21:18 . 2007-11-18 21:18 <DIR> d-------- C:\Program Files\E404DHelper
2007-11-18 21:18 . 2007-11-18 21:21 <DIR> d-------- C:\Program Files\Cool
2007-11-18 21:18 . 2007-11-18 21:18 115 --a------ C:\mit.bat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-30 20:44 --------- d-----w C:\Program Files\Warcraft III
2007-12-30 20:21 --------- d-----w C:\Program Files\Common Files\zuzk
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-14 15:42 246 ----a-w C:\Program Files\Common Files\laxuk
2007-10-05 15:00 16,896 ----a-w C:\Documents and Settings\Kids\wn10077.exe
2007-10-05 15:00 1,577 ----a-w C:\Documents and Settings\Kids\xl10077.exe
2007-10-05 12:21 246 ----a-w C:\Program Files\Common Files\laxuk475
2007-09-20 16:49 246 ----a-w C:\Program Files\Common Files\laxuk437
2007-07-17 18:46 6,365 --sha-w C:\WINDOWS\SYSTEM32\mlnmp.bak1
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\valve\steam\steam.exe" [2007-11-29 18:10 1266936]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [ ]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45 313472]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2006-11-07 09:29 50736]
"Bkrlduz"="C:\Program Files\Common Files\F?nts\j?vaw.exe" [ ]
"Ccc"="C:\Documents and Settings\Kids\My Documents\M?crosoft\?srss.exe" [ ]
"Ljhgo"="C:\Documents and Settings\Kids\My Documents\s?mbols\?pool32.exe" [ ]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 10:24 1694208]
"Ncao"="C:\WINDOWS\system32\CURITY~1\chkdsk.exe" [ ]
"Wxtvbzi"="C:\Documents and Settings\Kids\My Documents\W?nSxS\c?rss.exe" [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"AllowLegacyWebView"= 1 (0x1)
"AllowUnhashedWebView"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkkljki]
jkkljki.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winzzd32]
winzzd32.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, append.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^findfast.exe]
path=C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\findfast.exe
backup=C:\WINDOWS\pss\findfast.exeStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^autorun.exe]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\autorun.exe
backup=C:\WINDOWS\pss\autorun.exeCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2004-05-25 21:35 335872 --a------ C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
C:\Program Files\DellSupport\DSAgnt.exe /startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
2004-03-15 00:04 122933 --a------ C:\WINDOWS\system32\dla\tfswctrl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
2004-04-11 10:43 53248 --------- C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hotyger]
C:\Program Files\Internet Explorer\hotyger22011.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
2004-03-23 11:16 135168 --a------ C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelMeM]
2003-09-03 19:12 221184 --a------ C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2007-07-31 17:44 271672 --a------ C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NI.UWFX5LP_0001_0715]
C:\WINDOWS\Downloaded Program Files\UWFX5LP_0001_0715NetInstaller.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
2004-04-11 19:15 290816 --------- C:\Program Files\Dell\Media Experience\PCMService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Printer]
C:\WINDOWS\system32\printer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
C:\WINDOWS\retadpu1000106.exe 61A847B5BBF72813329B385772FF01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Salestart]
C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spoolsv]
C:\WINDOWS\system32\spoolvs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2003-11-19 16:48 32881 --a------ C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe /r
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinAVX]
C:\WINDOWS\system32\WinAvXX.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\autoplay.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
"2007-12-17 21:00:20 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-12-30 21:24:00 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDetect.exe
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-30 15:21:26
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-30 15:25:51 - machine was rebooted
C:\qoobox\ComboFix-quarantined-files.txt 2007-12-30 21:25:43
.
2007-12-28 09:00:40 --- E O F ---
undoFix V6.7.7
Checking Java version...
Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.
Scan started at 3:29:46 PM 12/30/2007
Listing files found while scanning....
C:\WINDOWS\SYSTEM32\atjakylb.exe
C:\WINDOWS\SYSTEM32\awdkabgl.exe
C:\WINDOWS\SYSTEM32\fmqfwewb.exe
C:\WINDOWS\SYSTEM32\fveefdyl.exe
C:\WINDOWS\SYSTEM32\lvoedplp.exe
C:\WINDOWS\SYSTEM32\pfooglac.exe
C:\WINDOWS\SYSTEM32\pyhxedys.exe
C:\WINDOWS\SYSTEM32\sowcavyc.exe
C:\WINDOWS\SYSTEM32\upecqpoj.exe
C:\WINDOWS\SYSTEM32\wnfgqmpf.exe
Beginning removal...
Attempting to delete C:\WINDOWS\SYSTEM32\atjakylb.exe
C:\WINDOWS\SYSTEM32\atjakylb.exe Has been deleted!
Attempting to delete C:\WINDOWS\SYSTEM32\awdkabgl.exe
C:\WINDOWS\SYSTEM32\awdkabgl.exe Has been deleted!
Attempting to delete C:\WINDOWS\SYSTEM32\fmqfwewb.exe
C:\WINDOWS\SYSTEM32\fmqfwewb.exe Has been deleted!
Attempting to delete C:\WINDOWS\SYSTEM32\fveefdyl.exe
C:\WINDOWS\SYSTEM32\fveefdyl.exe Has been deleted!
Attempting to delete C:\WINDOWS\SYSTEM32\lvoedplp.exe
C:\WINDOWS\SYSTEM32\lvoedplp.exe Has been deleted!
Attempting to delete C:\WINDOWS\SYSTEM32\pfooglac.exe
C:\WINDOWS\SYSTEM32\pfooglac.exe Has been deleted!
Attempting to delete C:\WINDOWS\SYSTEM32\pyhxedys.exe
C:\WINDOWS\SYSTEM32\pyhxedys.exe Has been deleted!
Attempting to delete C:\WINDOWS\SYSTEM32\sowcavyc.exe
C:\WINDOWS\SYSTEM32\sowcavyc.exe Has been deleted!
Attempting to delete C:\WINDOWS\SYSTEM32\upecqpoj.exe
C:\WINDOWS\SYSTEM32\upecqpoj.exe Has been deleted!
Attempting to delete C:\WINDOWS\SYSTEM32\wnfgqmpf.exe
C:\WINDOWS\SYSTEM32\wnfgqmpf.exe Has been deleted!
Performing Repairs to the registry.
Done!
SDFix: Version 1.120
Run by Kids on Sun 12/30/2007 at 04:14 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Trojan Files Found:
C:\2F6.TMP - Deleted
C:\2F7.TMP - Deleted
C:\2F8.TMP - Deleted
C:\2F9.TMP - Deleted
C:\PROGRA~1\COMMON~1\LAXUK - Deleted
C:\PROGRA~1\COMMON~1\LAXUK437 - Deleted
C:\PROGRA~1\COMMON~1\LAXUK475 - Deleted
C:\Program Files\E404DHelper\e404d.v1.dll - Deleted
C:\WINDOWS\tcb.pmw - Deleted
Folder C:\Program Files\E404DHelper - Removed
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
catchme 0.3.1333.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-30 16:20:09
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
Remaining Files:
---------------
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes:
Wed 12 Dec 2007 848 A.SH. --- "C:\WINDOWS\SYSTEM32\KGyGaAvL.sys"
Tue 17 Jul 2007 6,365 A.SH. --- "C:\WINDOWS\SYSTEM32\mlnmp.bak1"
Thu 29 Nov 2007 834 A.SH. --- "C:\WINDOWS\SYSTEM32\tjidbhrt.tmp"
Sat 15 Oct 2005 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Thu 14 Apr 2005 76,056 ..SHR --- "C:\Program Files\Autodesk\Autodesk DWF Viewer\Setup.exe"
Thu 14 Apr 2005 5,632 A.SHR --- "C:\Program Files\Autodesk\Autodesk DWF Viewer\_Setupx.dll"
Sun 15 Jul 2007 40,183 A.SH. --- "C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP816\A0177801.exe"
Fri 29 Jun 2007 146,944 A.SH. --- "C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP816\A0177802.exe"
Tue 17 Jul 2007 40,183 A.SH. --- "C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP819\A0178928.exe"
Fri 29 Jun 2007 146,944 A.SH. --- "C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP819\A0178929.exe"
Wed 20 Jun 2007 229,888 A.SH. --- "C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP822\A0182025.exe"
Tue 17 Jul 2007 72,704 A.SH. --- "C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP822\A0182027.exe"
Tue 12 Dec 1989 246,352 A.SH. --- "C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP822\A0182057.exe"
Tue 17 Jul 2007 32,177 A.SH. --- "C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP822\A0182081.exe"
Sun 5 Aug 2007 40,183 A.SH. --- "C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP840\A0184541.exe"
Fri 29 Jun 2007 146,944 A.SH. --- "C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP840\A0184542.exe"
Fri 29 Jun 2007 146,944 A.SH. --- "C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP873\A0188759.exe"
Sun 9 Sep 2007 40,183 A.SH. --- "C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP873\A0188761.exe"
Mon 10 Sep 2007 40,183 A.SH. --- "C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP881\A0196815.exe"
Fri 29 Jun 2007 146,944 A.SH. --- "C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP881\A0196816.exe"
Tue 28 Aug 2007 32,177 A.SH. --- "C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP882\A0196855.exe"
Sun 18 Nov 2007 41,723 A.SH. --- "C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP913\A0204693.exe"
Fri 21 Sep 2007 146,432 A.SH. --- "C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP913\A0204694.exe"
Tue 22 May 2007 848 A.SH. --- "C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP934\A0209381.sys"
Thu 22 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\6efcd3506d8bb09b521fd2ab4ee258bc\BITAF.tmp"
Thu 22 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\b0bbf9bad2a96231d750c48395570f92\BITAE.tmp"
Thu 22 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\c212d67be1f86f86c36e82bc3c8d87df\BITB0.tmp"
Thu 12 Apr 2007 8 A..H. --- "C:\Documents and Settings\Kids\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Thu 12 Apr 2007 8 A..H. --- "C:\Documents and Settings\Kids\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Thu 12 Apr 2007 8 A..H. --- "C:\Documents and Settings\Kids\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp"
Thu 12 Apr 2007 8 A..H. --- "C:\Documents and Settings\Kids\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u4\lock.tmp"
Thu 19 Apr 2007 8 A..H. --- "C:\Documents and Settings\Mom\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Thu 19 Apr 2007 8 A..H. --- "C:\Documents and Settings\Mom\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Thu 19 Apr 2007 8 A..H. --- "C:\Documents and Settings\Mom\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp"
Thu 19 Apr 2007 8 A..H. --- "C:\Documents and Settings\Mom\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u4\lock.tmp"
Finished!
Logfile of HijackThis v1.99.1
Scan saved at 4:39:48 PM, on 12/30/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Cool\X_cool.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Kids\Desktop\Killer.exe.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.gophersearch.com/
O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Bkrlduz] "C:\Program Files\Common Files\F?nts\j?vaw.exe"
O4 - HKCU\..\Run: [Ccc] "C:\Documents and Settings\Kids\My Documents\M?crosoft\?srss.exe"
O4 - HKCU\..\Run: [Ljhgo] "C:\Documents and Settings\Kids\My Documents\s?mbols\?pool32.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Ncao] "C:\WINDOWS\system32\CURITY~1\chkdsk.exe" -vt ndrv
O4 - HKCU\..\Run: [Wxtvbzi] "C:\Documents and Settings\Kids\My Documents\W?nSxS\c?rss.exe"
O4 - Startup: Cool - Auto Update.lnk = C:\Program Files\Cool\cool.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmat...enWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windup.../bridge-c15.cab
O16 - DPF: {1C960AA3-FAEE-11D0-9262-00A0243D2412} (TegoSoft SmartLoader ActiveX Control) - http://www.hondapowe...eX/TegoLoad.cab
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://drivecleaner....leanerstart.cab
O20 - Winlogon Notify: jkkljki - jkkljki.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winzzd32 - winzzd32.dll (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe (file missing)
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe (file missing)