I have been at work all day, so I am just now getting to this.
Here are the logs:
ComboFix 08-01-23.1C - Charlie Mitchell 2008-01-28 19:54:38.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.309 [GMT -6:00]
Running from: C:\Documents and Settings\Charlie Mitchell\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Charlie Mitchell\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE
C:\WINDOWS\system32\msxml3a.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\PokerStars
C:\Program Files\PokerStars\_update2def.dat
C:\Program Files\PokerStars\_update2g.dat
C:\Program Files\PokerStars\_update2gcd.dat
C:\Program Files\PokerStars\_update2gf.dat
C:\Program Files\PokerStars\_update2ni.dat
C:\Program Files\PokerStars\_update2rare.dat
C:\Program Files\PokerStars\_update2s.dat
C:\Program Files\PokerStars\_updcache.dat
C:\Program Files\PokerStars\backup\Gx\fonts\ar08.pff
C:\Program Files\PokerStars\backup\Gx\fonts\ar09.pff
C:\Program Files\PokerStars\backup\Gx\fonts\arb08.pff
C:\Program Files\PokerStars\backup\Gx\fonts\arb09.pff
C:\Program Files\PokerStars\backup\Gx\fonts\arb10.pff
C:\Program Files\PokerStars\backup\Gx\fonts\arb11.pff
C:\Program Files\PokerStars\backup\Gx\fonts\arb12.pff
C:\Program Files\PokerStars\backup\Gx\fonts\arb14.pff
C:\Program Files\PokerStars\backup\Gx\fonts\arbu09.pff
C:\Program Files\PokerStars\backup\Gx\fonts\arbu10.pff
C:\Program Files\PokerStars\backup\Gx\fonts\arbu12.pff
C:\Program Files\PokerStars\backup\Gx\fonts\aru08.pff
C:\Program Files\PokerStars\backup\Gx\fonts\gmb075.pff
C:\Program Files\PokerStars\backup\Gx\fonts\gmb08.pff
C:\Program Files\PokerStars\backup\Gx\fonts\gmb09.pff
C:\Program Files\PokerStars\backup\Gx\fonts\gmb10.pff
C:\Program Files\PokerStars\backup\Gx\fonts\gmb11.pff
C:\Program Files\PokerStars\backup\Gx\fonts\gmb12.pff
C:\Program Files\PokerStars\backup\Gx\fonts\gmb14.pff
C:\Program Files\PokerStars\backup\Gx\fonts\gmb16.pff
C:\Program Files\PokerStars\backup\Gx\fonts\gmb18.pff
C:\Program Files\PokerStars\backup\Gx\fonts\gmb20.pff
C:\Program Files\PokerStars\backup\Gx\fonts\sb08.pff
C:\Program Files\PokerStars\backup\Gx\fonts\sb09.pff
C:\Program Files\PokerStars\backup\Gx\fonts\sb10.pff
C:\Program Files\PokerStars\backup\Gx\fonts\sb11.pff
C:\Program Files\PokerStars\backup\Gx\fonts\sb12.pff
C:\Program Files\PokerStars\backup\Gx\fonts\sb14.pff
C:\Program Files\PokerStars\backup\Gx\fonts\sb16.pff
C:\Program Files\PokerStars\backup\Gx\fonts\sbr10.pff
C:\Program Files\PokerStars\backup\Gx\fonts\sf05.pff
C:\Program Files\PokerStars\backup\Gx\fonts\sf06.pff
C:\Program Files\PokerStars\backup\Gx\fonts\sf07.pff
C:\Program Files\PokerStars\backup\Gx\fonts\sfu06.pff
C:\Program Files\PokerStars\backup\Gx\fonts\sfu07.pff
C:\Program Files\PokerStars\backup\Gx\templates\browser.css
C:\Program Files\PokerStars\backup\Gx\templates\dialog.css
C:\Program Files\PokerStars\backup\Gx\templates\dialog.html
C:\Program Files\PokerStars\backup\Gx\templates\help.html
C:\Program Files\PokerStars\backup\Gx\templates\menu.xml
C:\Program Files\PokerStars\backup\i18n.msg_cli.txt
C:\Program Files\PokerStars\backup\PokerStars.exe
C:\Program Files\PokerStars\backup\PokerStars.ini
C:\Program Files\PokerStars\backup\Themes\default\gx.ini
C:\Program Files\PokerStars\Gx\blt.a.bmp
C:\Program Files\PokerStars\Gx\blt.bmp
C:\Program Files\PokerStars\Gx\cashierdepositbtn.jpg
C:\Program Files\PokerStars\Gx\cashierpaysystem.a.bmp
C:\Program Files\PokerStars\Gx\cashierpaysystem.bmp
C:\Program Files\PokerStars\Gx\cashierpaysystem.jpg
C:\Program Files\PokerStars\Gx\close.a.bmp
C:\Program Files\PokerStars\Gx\close.bmp
C:\Program Files\PokerStars\Gx\ctep.bmp
C:\Program Files\PokerStars\Gx\ctrls\cashierb.a.bmp
C:\Program Files\PokerStars\Gx\ctrls\cashierb.bmp
C:\Program Files\PokerStars\Gx\ctrls\cashiergb.a.bmp
C:\Program Files\PokerStars\Gx\ctrls\cashiergb.bmp
C:\Program Files\PokerStars\Gx\ctrls\cashierrb.a.bmp
C:\Program Files\PokerStars\Gx\ctrls\cashierrb.bmp
C:\Program Files\PokerStars\Gx\ctrls\lobbyb.a.bmp
C:\Program Files\PokerStars\Gx\ctrls\lobbyb.bmp
C:\Program Files\PokerStars\Gx\ctrls\lobbybar.a.bmp
C:\Program Files\PokerStars\Gx\ctrls\lobbybar.bmp
C:\Program Files\PokerStars\Gx\ctrls\lobbydd.a.bmp
C:\Program Files\PokerStars\Gx\ctrls\lobbydd.bmp
C:\Program Files\PokerStars\Gx\ctrls\lobbylb.a.bmp
C:\Program Files\PokerStars\Gx\ctrls\lobbylb.bmp
C:\Program Files\PokerStars\Gx\ctrls\mtgb.a.bmp
C:\Program Files\PokerStars\Gx\ctrls\mtgb.bmp
C:\Program Files\PokerStars\Gx\ctrls\mtrb.a.bmp
C:\Program Files\PokerStars\Gx\ctrls\mtrb.bmp
C:\Program Files\PokerStars\Gx\cvn.jpg
C:\Program Files\PokerStars\Gx\dialog.a.bmp
C:\Program Files\PokerStars\Gx\dialog.bmp
C:\Program Files\PokerStars\Gx\epasslogo.bmp
C:\Program Files\PokerStars\Gx\filter.a.bmp
C:\Program Files\PokerStars\Gx\filter.bmp
C:\Program Files\PokerStars\Gx\filter\ot00.bmp
C:\Program Files\PokerStars\Gx\filter\ot00a.bmp
C:\Program Files\PokerStars\Gx\filter\ot01.bmp
C:\Program Files\PokerStars\Gx\filter\ot01a.bmp
C:\Program Files\PokerStars\Gx\filter\ot02.bmp
C:\Program Files\PokerStars\Gx\filter\ot02a.bmp
C:\Program Files\PokerStars\Gx\filter\ot03.bmp
C:\Program Files\PokerStars\Gx\filter\ot03a.bmp
C:\Program Files\PokerStars\Gx\filterb.bmp
C:\Program Files\PokerStars\Gx\fonts\gmb11.bmp
C:\Program Files\PokerStars\Gx\fonts\gmb11.pff
C:\Program Files\PokerStars\Gx\fonts\sb08.bmp
C:\Program Files\PokerStars\Gx\fonts\sb08.pff
C:\Program Files\PokerStars\Gx\fonts\sb08x.bmp
C:\Program Files\PokerStars\Gx\fonts\sb09.bmp
C:\Program Files\PokerStars\Gx\fonts\sb09.pff
C:\Program Files\PokerStars\Gx\fonts\sb09x.bmp
C:\Program Files\PokerStars\Gx\fonts\sb10.bmp
C:\Program Files\PokerStars\Gx\fonts\sb10.pff
C:\Program Files\PokerStars\Gx\fonts\sb10x.bmp
C:\Program Files\PokerStars\Gx\fonts\sb11.bmp
C:\Program Files\PokerStars\Gx\fonts\sb11.pff
C:\Program Files\PokerStars\Gx\fonts\sb11x.bmp
C:\Program Files\PokerStars\Gx\fonts\sb12.bmp
C:\Program Files\PokerStars\Gx\fonts\sb12.pff
C:\Program Files\PokerStars\Gx\fonts\sb12x.bmp
C:\Program Files\PokerStars\Gx\fonts\sb14.bmp
C:\Program Files\PokerStars\Gx\fonts\sb14.pff
C:\Program Files\PokerStars\Gx\fonts\sb14x.bmp
C:\Program Files\PokerStars\Gx\fonts\sb16.bmp
C:\Program Files\PokerStars\Gx\fonts\sb16.pff
C:\Program Files\PokerStars\Gx\fonts\sb16x.bmp
C:\Program Files\PokerStars\Gx\fonts\sbf10.bmp
C:\Program Files\PokerStars\Gx\fonts\sbf10.pff
C:\Program Files\PokerStars\Gx\fonts\sbf10x.bmp
C:\Program Files\PokerStars\Gx\fonts\sbf11.bmp
C:\Program Files\PokerStars\Gx\fonts\sbf11.pff
C:\Program Files\PokerStars\Gx\fonts\sbf11x.bmp
C:\Program Files\PokerStars\Gx\fonts\sbr10.bmp
C:\Program Files\PokerStars\Gx\fonts\sbr10.pff
C:\Program Files\PokerStars\Gx\fonts\sbr11.bmp
C:\Program Files\PokerStars\Gx\fonts\sbr11.pff
C:\Program Files\PokerStars\Gx\fonts\sbr11x.bmp
C:\Program Files\PokerStars\Gx\ico.bmp
C:\Program Files\PokerStars\Gx\ipb.a.bmp
C:\Program Files\PokerStars\Gx\ipb.bmp
C:\Program Files\PokerStars\Gx\ipkt1.a.bmp
C:\Program Files\PokerStars\Gx\ipkt1.bmp
C:\Program Files\PokerStars\Gx\ipkt2.a.bmp
C:\Program Files\PokerStars\Gx\ipkt2.bmp
C:\Program Files\PokerStars\Gx\ipkt3.a.bmp
C:\Program Files\PokerStars\Gx\ipkt3.bmp
C:\Program Files\PokerStars\Gx\ltb1.a.bmp
C:\Program Files\PokerStars\Gx\ltb1.bmp
C:\Program Files\PokerStars\Gx\ltb2.bmp
C:\Program Files\PokerStars\Gx\ltb3.bmp
C:\Program Files\PokerStars\Gx\moneygram_c.bmp
C:\Program Files\PokerStars\Gx\moneygram_r.bmp
C:\Program Files\PokerStars\Gx\moneygramform.jpg
C:\Program Files\PokerStars\Gx\moneygramlogo.jpg
C:\Program Files\PokerStars\Gx\PaySafeLogo.bmp
C:\Program Files\PokerStars\Gx\pb.a.bmp
C:\Program Files\PokerStars\Gx\pb.bmp
C:\Program Files\PokerStars\Gx\pbb.a.bmp
C:\Program Files\PokerStars\Gx\pbb.bmp
C:\Program Files\PokerStars\Gx\pbc.bmp
C:\Program Files\PokerStars\Gx\pblt.a.bmp
C:\Program Files\PokerStars\Gx\pblt.bmp
C:\Program Files\PokerStars\Gx\pci.a.bmp
C:\Program Files\PokerStars\Gx\pci.bmp
C:\Program Files\PokerStars\Gx\pib.bmp
C:\Program Files\PokerStars\Gx\pmsp.bmp
C:\Program Files\PokerStars\Gx\pmt.bmp
C:\Program Files\PokerStars\Gx\ps.a.bmp
C:\Program Files\PokerStars\Gx\ps.bmp
C:\Program Files\PokerStars\Gx\ptb.bmp
C:\Program Files\PokerStars\Gx\reserved.a.bmp
C:\Program Files\PokerStars\Gx\reserved.bmp
C:\Program Files\PokerStars\Gx\templates\browser.css
C:\Program Files\PokerStars\Gx\templates\dialog.css
C:\Program Files\PokerStars\Gx\templates\dialog.html
C:\Program Files\PokerStars\Gx\templates\help.html
C:\Program Files\PokerStars\Gx\templates\memo.css
C:\Program Files\PokerStars\Gx\templates\menu.xml
C:\Program Files\PokerStars\Gx\tmp.jpg
C:\Program Files\PokerStars\i18n.msg_cli.txt
C:\Program Files\PokerStars\ImgCache\
0000345D.psi
C:\Program Files\PokerStars\ImgCache\
000117AB.psi
C:\Program Files\PokerStars\ImgCache\
00013C60.psi
C:\Program Files\PokerStars\ImgCache\
000310CE.psi
C:\Program Files\PokerStars\ImgCache\
0004045E.psi
C:\Program Files\PokerStars\ImgCache\
00048DB0.psi
C:\Program Files\PokerStars\ImgCache\
0006420C.psi
C:\Program Files\PokerStars\ImgCache\
0006D3DC.psi
C:\Program Files\PokerStars\ImgCache\
000705D9.psi
C:\Program Files\PokerStars\ImgCache\
0007D5BF.psi
C:\Program Files\PokerStars\ImgCache\
00097309.psi
C:\Program Files\PokerStars\ImgCache\
0009D69F.psi
C:\Program Files\PokerStars\ImgCache\
000C1ECA.psi
C:\Program Files\PokerStars\ImgCache\
000CBCCF.psi
C:\Program Files\PokerStars\ImgCache\
000D3F97.psi
C:\Program Files\PokerStars\ImgCache\
000D5E06.psi
C:\Program Files\PokerStars\ImgCache\
000DFFFB.psi
C:\Program Files\PokerStars\ImgCache\
000E89AE.psi
C:\Program Files\PokerStars\ImgCache\
000EB23B.psi
C:\Program Files\PokerStars\ImgCache\
000F13B3.psi
C:\Program Files\PokerStars\ImgCache\
00106CF3.psi
C:\Program Files\PokerStars\ImgCache\
0011379A.psi
C:\Program Files\PokerStars\ImgCache\
00118F85.psi
C:\Program Files\PokerStars\ImgCache\
0012405E.psi
C:\Program Files\PokerStars\ImgCache\
00128F2D.psi
C:\Program Files\PokerStars\ImgCache\
00135CA8.psi
C:\Program Files\PokerStars\ImgCache\
0013993E.psi
C:\Program Files\PokerStars\ImgCache\
00143008.psi
C:\Program Files\PokerStars\ImgCache\
0014495D.psi
C:\Program Files\PokerStars\ImgCache\
00144F8C.psi
C:\Program Files\PokerStars\ImgCache\
0014E985.psi
C:\Program Files\PokerStars\ImgCache\
0015211C.psi
C:\Program Files\PokerStars\ImgCache\
00157049.psi
C:\Program Files\PokerStars\ImgCache\
0015BC03.psi
C:\Program Files\PokerStars\ImgCache\
0015F561.psi
C:\Program Files\PokerStars\ImgCache\
00164E26.psi
C:\Program Files\PokerStars\ImgCache\
00166819.psi
C:\Program Files\PokerStars\ImgCache\
0016AE97.psi
C:\Program Files\PokerStars\ImgCache\
0016D319.psi
C:\Program Files\PokerStars\ImgCache\
00175367.psi
C:\Program Files\PokerStars\ImgCache\
001769CF.psi
C:\Program Files\PokerStars\ImgCache\
0017F49B.psi
C:\Program Files\PokerStars\ImgCache\
00193D83.psi
C:\Program Files\PokerStars\ImgCache\
00196395.psi
C:\Program Files\PokerStars\ImgCache\
001989F5.psi
C:\Program Files\PokerStars\ImgCache\
00199EC0.psi
C:\Program Files\PokerStars\ImgCache\
0019FD88.psi
C:\Program Files\PokerStars\ImgCache\
001A7CC0.psi
C:\Program Files\PokerStars\ImgCache\
001AF6F8.psi
C:\Program Files\PokerStars\ImgCache\
001B0DAB.psi
C:\Program Files\PokerStars\ImgCache\
001B6F58.psi
C:\Program Files\PokerStars\ImgCache\
001BBD5E.psi
C:\Program Files\PokerStars\ImgCache\
001C338B.psi
C:\Program Files\PokerStars\ImgCache\
001CC4FA.psi
C:\Program Files\PokerStars\ImgCache\
001CEAF4.psi
C:\Program Files\PokerStars\ImgCache\
001DE656.psi
C:\Program Files\PokerStars\ImgCache\
001E1EE1.psi
C:\Program Files\PokerStars\ImgCache\
001E7AFB.psi
C:\Program Files\PokerStars\ImgCache\
001E8186.psi
C:\Program Files\PokerStars\ImgCache\
001F4600.psi
C:\Program Files\PokerStars\ImgCache\
001F4BE1.psi
C:\Program Files\PokerStars\ImgCache\
001FF99C.psi
C:\Program Files\PokerStars\ImgCache\
00202873.psi
C:\Program Files\PokerStars\ImgCache\
002045DE.psi
C:\Program Files\PokerStars\ImgCache\
00207B21.psi
C:\Program Files\PokerStars\ImgCache\
0020BA2D.psi
C:\Program Files\PokerStars\ImgCache\
0020DC25.psi
C:\Program Files\PokerStars\ImgCache\
00210142.psi
C:\Program Files\PokerStars\ImgCache\
00212EC6.psi
C:\Program Files\PokerStars\ImgCache\
00215E2D.psi
C:\Program Files\PokerStars\ImgCache\
0021B693.psi
C:\Program Files\PokerStars\ImgCache\
0021D974.psi
C:\Program Files\PokerStars\ImgCache\
002259BA.psi
C:\Program Files\PokerStars\ImgCache\
002263F9.psi
C:\Program Files\PokerStars\ImgCache\
002267F7.psi
C:\Program Files\PokerStars\ImgCache\
00227942.psi
C:\Program Files\PokerStars\ImgCache\
0022ADF2.psi
C:\Program Files\PokerStars\ImgCache\
0022F394.psi
C:\Program Files\PokerStars\ImgCache\
00237AE1.psi
C:\Program Files\PokerStars\ImgCache\
0023D63E.psi
C:\Program Files\PokerStars\ImgCache\
0024E339.psi
C:\Program Files\PokerStars\ImgCache\
0025C8ED.psi
C:\Program Files\PokerStars\ImgCache\
00264EC9.psi
C:\Program Files\PokerStars\ImgCache\
0026FC43.psi
C:\Program Files\PokerStars\ImgCache\
00271049.psi
C:\Program Files\PokerStars\ImgCache\
00271CE8.psi
C:\Program Files\PokerStars\ImgCache\
002749C4.psi
C:\Program Files\PokerStars\ImgCache\
002765FC.psi
C:\Program Files\PokerStars\ImgCache\
00279851.psi
C:\Program Files\PokerStars\ImgCache\
0027CE8F.psi
C:\Program Files\PokerStars\ImgCache\
0027D7FB.psi
C:\Program Files\PokerStars\ImgCache\
0027FAFA.psi
C:\Program Files\PokerStars\ImgCache\
00289830.psi
C:\Program Files\PokerStars\ImgCache\
0028B88D.psi
C:\Program Files\PokerStars\ImgCache\
0028FF4E.psi
C:\Program Files\PokerStars\ImgCache\
00295ABB.psi
C:\Program Files\PokerStars\ImgCache\
0029A117.psi
C:\Program Files\PokerStars\ImgCache\
0029B4FB.psi
C:\Program Files\PokerStars\ImgCache\
0029B510.psi
C:\Program Files\PokerStars\ImgCache\
0029D5E7.psi
C:\Program Files\PokerStars\ImgCache\
0029F7D8.psi
C:\Program Files\PokerStars\ImgCache\
002A30DE.psi
C:\Program Files\PokerStars\ImgCache\
002A621C.psi
C:\Program Files\PokerStars\ImgCache\
002AFF4B.psi
C:\Program Files\PokerStars\ImgCache\
002B8366.psi
C:\Program Files\PokerStars\ImgCache\
002BB0CF.psi
C:\Program Files\PokerStars\ImgCache\
002BD164.psi
C:\Program Files\PokerStars\ImgCache\
002C057E.psi
C:\Program Files\PokerStars\ImgCache\
002C0F11.psi
C:\Program Files\PokerStars\ImgCache\
002C57B3.psi
C:\Program Files\PokerStars\ImgCache\
002C9AE0.psi
C:\Program Files\PokerStars\ImgCache\
002C9C7B.psi
C:\Program Files\PokerStars\ImgCache\
002CBA89.psi
C:\Program Files\PokerStars\ImgCache\
002D490A.psi
C:\Program Files\PokerStars\ImgCache\
002D855B.psi
C:\Program Files\PokerStars\ImgCache\
002DDCC2.psi
C:\Program Files\PokerStars\ImgCache\
002DE04E.psi
C:\Program Files\PokerStars\ImgCache\
002DE9A4.psi
C:\Program Files\PokerStars\ImgCache\
002E4724.psi
C:\Program Files\PokerStars\ImgCache\
002E4C5A.psi
C:\Program Files\PokerStars\ImgCache\
002E88E4.psi
C:\Program Files\PokerStars\ImgCache\
002E9A2C.psi
C:\Program Files\PokerStars\ImgCache\
002EB258.psi
C:\Program Files\PokerStars\ImgCache\
002EEB75.psi
C:\Program Files\PokerStars\ImgCache\
002F4E7D.psi
C:\Program Files\PokerStars\ImgCache\
002F66D3.psi
C:\Program Files\PokerStars\ImgCache\
002F6BE7.psi
C:\Program Files\PokerStars\ImgCache\
002F83C7.psi
C:\Program Files\PokerStars\ImgCache\
002F9036.psi
C:\Program Files\PokerStars\ImgCache\
002FBF19.psi
C:\Program Files\PokerStars\ImgCache\
002FBFD7.psi
C:\Program Files\PokerStars\ImgCache\
002FD8B0.psi
C:\Program Files\PokerStars\ImgCache\
002FF4C2.psi
C:\Program Files\PokerStars\ImgCache\
00301D38.psi
C:\Program Files\PokerStars\ImgCache\
0030265D.psi
C:\Program Files\PokerStars\ImgCache\
003036EF.psi
C:\Program Files\PokerStars\ImgCache\
0030A17A.psi
C:\Program Files\PokerStars\ImgCache\
0030CBF3.psi
C:\Program Files\PokerStars\ImgCache\
00313F62.psi
C:\Program Files\PokerStars\ImgCache\
003195FE.psi
C:\Program Files\PokerStars\ImgCache\
0031B27B.psi
C:\Program Files\PokerStars\ImgCache\
0031B65C.psi
C:\Program Files\PokerStars\ImgCache\
0031D629.psi
C:\Program Files\PokerStars\ImgCache\
00321E98.psi
C:\Program Files\PokerStars\ImgCache\
00323517.psi
C:\Program Files\PokerStars\ImgCache\
0032481A.psi
C:\Program Files\PokerStars\ImgCache\
0032543C.psi
C:\Program Files\PokerStars\ImgCache\
003258F2.psi
C:\Program Files\PokerStars\ImgCache\
00327AE2.psi
C:\Program Files\PokerStars\ImgCache\
00328466.psi
C:\Program Files\PokerStars\ImgCache\
0032B8F9.psi
C:\Program Files\PokerStars\ImgCache\
0032EFEB.psi
C:\Program Files\PokerStars\ImgCache\
0032F1A4.psi
C:\Program Files\PokerStars\ImgCache\
00342183.psi
C:\Program Files\PokerStars\ImgCache\
003461DD.psi
C:\Program Files\PokerStars\ImgCache\
00349706.psi
C:\Program Files\PokerStars\ImgCache\
0034BFDB.psi
C:\Program Files\PokerStars\ImgCache\
0034E9B2.psi
C:\Program Files\PokerStars\ImgCache\
00355493.psi
C:\Program Files\PokerStars\ImgCache\
0035CB5A.psi
C:\Program Files\PokerStars\ImgCache\
0035D93E.psi
C:\Program Files\PokerStars\ImgCache\
0035E7FB.psi
C:\Program Files\PokerStars\ImgCache\
00360636.psi
C:\Program Files\PokerStars\ImgCache\
0036213F.psi
C:\Program Files\PokerStars\ImgCache\
00364570.psi
C:\Program Files\PokerStars\ImgCache\
00367B7A.psi
C:\Program Files\PokerStars\ImgCache\
0036B5E3.psi
C:\Program Files\PokerStars\ImgCache\
0036CDB7.psi
C:\Program Files\PokerStars\ImgCache\
0036D533.psi
C:\Program Files\PokerStars\ImgCache\
0036FC27.psi
C:\Program Files\PokerStars\ImgCache\
00374AEC.psi
C:\Program Files\PokerStars\ImgCache\
003764E7.psi
C:\Program Files\PokerStars\ImgCache\
00376CFE.psi
C:\Program Files\PokerStars\ImgCache\
00378200.psi
C:\Program Files\PokerStars\ImgCache\
0037ACF7.psi
C:\Program Files\PokerStars\ImgCache\
0037B2E7.psi
C:\Program Files\PokerStars\ImgCache\
0037ED45.psi
C:\Program Files\PokerStars\ImgCache\
00380D7C.psi
C:\Program Files\PokerStars\ImgCache\
00381979.psi
C:\Program Files\PokerStars\ImgCache\
003848C6.psi
C:\Program Files\PokerStars\ImgCache\
00385809.psi
C:\Program Files\PokerStars\ImgCache\
00385B77.psi
C:\Program Files\PokerStars\ImgCache\
00387C20.psi
C:\Program Files\PokerStars\ImgCache\
00388C90.psi
C:\Program Files\PokerStars\ImgCache\
0038A424.psi
C:\Program Files\PokerStars\ImgCache\
0038EDD3.psi
C:\Program Files\PokerStars\ImgCache\
00390BE2.psi
C:\Program Files\PokerStars\ImgCache\
00391211.psi
C:\Program Files\PokerStars\ImgCache\
00391C3D.psi
C:\Program Files\PokerStars\ImgCache\
0039654B.psi
C:\Program Files\PokerStars\ImgCache\
0039D01E.psi
C:\Program Files\PokerStars\ImgCache\
003A406B.psi
C:\Program Files\PokerStars\ImgCache\
003A767E.psi
C:\Program Files\PokerStars\ImgCache\
003B2800.psi
C:\Program Files\PokerStars\ImgCache\
003B3522.psi
C:\Program Files\PokerStars\ImgCache\
003B5A37.psi
C:\Program Files\PokerStars\ImgCache\
003B5A39.psi
C:\Program Files\PokerStars\ImgCache\
003B5A3A.psi
C:\Program Files\PokerStars\ImgCache\
003B800C.psi
C:\Program Files\PokerStars\ImgCache\
003BB45C.psi
C:\Program Files\PokerStars\ImgCache\
003BC64E.psi
C:\Program Files\PokerStars\ImgCache\
003BEEA0.psi
C:\Program Files\PokerStars\ImgCache\
003C4369.psi
C:\Program Files\PokerStars\ImgCache\
003C680B.psi
C:\Program Files\PokerStars\ImgCache\
003C7ACE.psi
C:\Program Files\PokerStars\ImgCache\
003CA851.psi
C:\Program Files\PokerStars\ImgCache\
003CAE21.psi
C:\Program Files\PokerStars\ImgCache\
003CCB4B.psi
C:\Program Files\PokerStars\ImgCache\
003CF211.psi
C:\Program Files\PokerStars\ImgCache\
003D0E67.psi
C:\Program Files\PokerStars\ImgCache\
003D18CC.psi
C:\Program Files\PokerStars\ImgCache\
003D51CB.psi
C:\Program Files\PokerStars\ImgCache\
003D6228.psi
C:\Program Files\PokerStars\ImgCache\
003D6D90.psi
C:\Program Files\PokerStars\ImgCache\
003D8244.psi
C:\Program Files\PokerStars\ImgCache\
003D892C.psi
C:\Program Files\PokerStars\ImgCache\
003D99D6.psi
C:\Program Files\PokerStars\ImgCache\
003DB5C6.psi
C:\Program Files\PokerStars\ImgCache\
003DB71A.psi
C:\Program Files\PokerStars\ImgCache\
003DD568.psi
C:\Program Files\PokerStars\ImgCache\
003DECEB.psi
C:\Program Files\PokerStars\ImgCache\
003E03A3.psi
C:\Program Files\PokerStars\ImgCache\
003E3A75.psi
C:\Program Files\PokerStars\ImgCache\
003E5BF9.psi
C:\Program Files\PokerStars\ImgCache\
003EA2B0.psi
C:\Program Files\PokerStars\ImgCache\
003EC067.psi
C:\Program Files\PokerStars\ImgCache\
003ED905.psi
C:\Program Files\PokerStars\ImgCache\
003EDA39.psi
C:\Program Files\PokerStars\ImgCache\
003EDE3C.psi
C:\Program Files\PokerStars\ImgCache\
003EF06D.psi
C:\Program Files\PokerStars\ImgCache\
003EF88B.psi
C:\Program Files\PokerStars\ImgCache\
003F0C1A.psi
C:\Program Files\PokerStars\ImgCache\
003F0D1D.psi
C:\Program Files\PokerStars\ImgCache\
003F13FF.psi
C:\Program Files\PokerStars\ImgCache\
003F1F38.psi
C:\Program Files\PokerStars\ImgCache\
003F262D.psi
C:\Program Files\PokerStars\ImgCache\
003F303E.psi
C:\Program Files\PokerStars\ImgCache\
003F3649.psi
C:\Program Files\PokerStars\ImgCache\
003F3C3A.psi
C:\Program Files\PokerStars\ImgCache\
003F4B4B.psi
C:\Program Files\PokerStars\ImgCache\
003F4CE4.psi
C:\Program Files\PokerStars\ImgCache\
003F4D99.psi
C:\Program Files\PokerStars\ImgCache\
003F7827.psi
C:\Program Files\PokerStars\ImgCache\
003FAADD.psi
C:\Program Files\PokerStars\ImgCache\
003FD60B.psi
C:\Program Files\PokerStars\ImgCache\
003FE2F1.psi
C:\Program Files\PokerStars\ImgCache\
003FF0FB.psi
C:\Program Files\PokerStars\ImgCache\
004020B6.psi
C:\Program Files\PokerStars\ImgCache\
00402340.psi
C:\Program Files\PokerStars\ImgCache\
00404B12.psi
C:\Program Files\PokerStars\ImgCache\
00404E97.psi
C:\Program Files\PokerStars\ImgCache\
00407C1A.psi
C:\Program Files\PokerStars\ImgCache\
0040B29B.psi
C:\Program Files\PokerStars\ImgCache\
0040D10F.psi
C:\Program Files\PokerStars\ImgCache\
00411B1C.psi
C:\Program Files\PokerStars\ImgCache\
00413FB9.psi
C:\Program Files\PokerStars\ImgCache\
00419B88.psi
C:\Program Files\PokerStars\ImgCache\
0041BB7D.psi
C:\Program Files\PokerStars\ImgCache\
0041D684.psi
C:\Program Files\PokerStars\ImgCache\
0041DE87.psi
C:\Program Files\PokerStars\ImgCache\
0041F995.psi
C:\Program Files\PokerStars\ImgCache\
00420F99.psi
C:\Program Files\PokerStars\ImgCache\
00421000.psi
C:\Program Files\PokerStars\ImgCache\
00421159.psi
C:\Program Files\PokerStars\ImgCache\
00423F99.psi
C:\Program Files\PokerStars\ImgCache\
00424240.psi
C:\Program Files\PokerStars\ImgCache\
004247D4.psi
C:\Program Files\PokerStars\ImgCache\
00427223.psi
C:\Program Files\PokerStars\ImgCache\
00427F72.psi
C:\Program Files\PokerStars\ImgCache\
00428AFF.psi
C:\Program Files\PokerStars\ImgCache\
00429D88.psi
C:\Program Files\PokerStars\ImgCache\
0042AFA9.psi
C:\Program Files\PokerStars\ImgCache\
0042B77F.psi
C:\Program Files\PokerStars\ImgCache\
0042C464.psi
C:\Program Files\PokerStars\ImgCache\
0042EE7D.psi
C:\Program Files\PokerStars\ImgCache\
00432521.psi
C:\Program Files\PokerStars\ImgCache\
00434539.psi
C:\Program Files\PokerStars\ImgCache\
00434704.psi
C:\Program Files\PokerStars\ImgCache\
004347BB.psi
C:\Program Files\PokerStars\ImgCache\
00434893.psi
C:\Program Files\PokerStars\ImgCache\
0043764C.psi
C:\Program Files\PokerStars\ImgCache\
00438802.psi
C:\Program Files\PokerStars\ImgCache\
00438DA5.psi
C:\Program Files\PokerStars\ImgCache\
0043B288.psi
C:\Program Files\PokerStars\ImgCache\
0043B498.psi
C:\Program Files\PokerStars\ImgCache\
0043EA2A.psi
C:\Program Files\PokerStars\ImgCache\
0043FCFD.psi
C:\Program Files\PokerStars\ImgCache\
00440BAB.psi
C:\Program Files\PokerStars\ImgCache\
0044389E.psi
C:\Program Files\PokerStars\ImgCache\
004440EC.psi
C:\Program Files\PokerStars\ImgCache\
00449436.psi
C:\Program Files\PokerStars\ImgCache\
0044A6F7.psi
C:\Program Files\PokerStars\ImgCache\
0044C565.psi
C:\Program Files\PokerStars\ImgCache\
00455183.psi
C:\Program Files\PokerStars\ImgCache\
00495992.psi
C:\Program Files\PokerStars\ImgCache\
00499E65.psi
C:\Program Files\PokerStars\ImgCache\
0049C467.psi
C:\Program Files\PokerStars\ImgCache\
0049FFDD.psi
C:\Program Files\PokerStars\ImgCache\
004B03E1.psi
C:\Program Files\PokerStars\ImgCache\
004B13E2.psi
C:\Program Files\PokerStars\ImgCache\img.idx
C:\Program Files\PokerStars\Notes.txt
C:\Program Files\PokerStars\PokerStars.log.0
C:\Program Files\PokerStars\PokerStars.log.1
C:\Program Files\PokerStars\PokerStarsUpdate.log.0
C:\Program Files\PokerStars\PokerStarsUpdate.log.1
C:\Program Files\PokerStars\Themes\simple\reserved.a.bmp
C:\Program Files\PokerStars\Themes\simple\reserved.bmp
C:\Program Files\PokerStars\update\_update2.dat
C:\Program Files\PokerStars\update\_update2g.dat
C:\Program Files\PokerStars\update\_update2ni.dat
C:\Program Files\PokerStars\update\_updatehttptmp.gz
C:\Program Files\PokerStars\update\i18n.msg_cli.txt
C:\Program Files\PokerStars\update\Themes\&default\gx.ini
C:\Program Files\PokerStars\update\Themes\preview\azure.jpg
C:\Program Files\PokerStars\update\Themes\preview\techno.jpg
C:\Program Files\PokerStars\update\Themes\themes.ini
C:\Program Files\PokerStars\update\update.ini
C:\Program Files\PokerStars\user.ini
C:\WINDOWS\system32\msxml3a.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\psa64s
-------\psa64u
((((((((((((((((((((((((( Files Created from 2007-12-28 to 2008-01-29 )))))))))))))))))))))))))))))))
.
2008-01-27 20:31 . 2008-01-27 20:31 <DIR> d----c--- C:\Deckard
2008-01-27 15:30 . 2008-01-27 15:31 <DIR> d----c--- C:\WINDOWS\ERUNT
2008-01-25 23:37 . 2000-08-31 08:00 51,200 --a--c--- C:\WINDOWS\Nircmd.exe
2008-01-25 23:28 . 2008-01-26 00:57 229 --a--c--- C:\WINDOWS\wininit.ini
2008-01-25 23:19 . 2008-01-25 23:19 <DIR> d----c--- C:\Program Files\Trend Micro
2008-01-25 01:33 . 2008-01-25 01:31 102,664 --a--c--- C:\WINDOWS\system32\drivers\tmcomm.sys
2008-01-24 23:58 . 2008-01-26 00:57 <DIR> d----c--- C:\Program Files\Acceleration Software
2008-01-24 23:47 . 2008-01-24 23:47 <DIR> d----c--- C:\Program Files\HighMAT CD Writing Wizard
2008-01-24 00:18 . 2008-01-24 00:18 <DIR> d----c--- C:\Program Files\MediaEntertainmentCodec
2008-01-16 22:57 . 2008-01-28 20:01 54,156 --ah-c--- C:\WINDOWS\QTFont.qfn
2008-01-16 22:57 . 2008-01-16 22:57 1,409 --a--c--- C:\WINDOWS\QTFont.for
2008-01-16 22:56 . 2008-01-16 22:56 <DIR> d----c--- C:\Program Files\iTunes
2008-01-16 22:56 . 2008-01-16 22:56 <DIR> d----c--- C:\Program Files\iPod
2008-01-16 22:55 . 2008-01-16 22:55 <DIR> d----c--- C:\Program Files\QuickTime
2008-01-16 22:55 . 2008-01-16 22:55 <DIR> d----c--- C:\Program Files\Bonjour
2008-01-16 22:53 . 2008-01-16 22:53 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-01-16 22:53 . 2008-01-16 22:53 <DIR> d----c--- C:\Program Files\Common Files\Apple
2008-01-16 22:53 . 2008-01-15 02:39 30,464 --a--c--- C:\WINDOWS\system32\drivers\usbaapl.sys
2008-01-10 15:27 . 2008-01-10 15:27 90,112 --a--c--- C:\WINDOWS\system32\QuickTimeVR.qtx
2008-01-10 15:27 . 2008-01-10 15:27 57,344 --a--c--- C:\WINDOWS\system32\QuickTime.qts
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-17 04:53 --------- dc----w C:\Program Files\Apple Software Update
2007-12-16 05:16 --------- dc----w C:\Program Files\Windows Media Connect 2
2007-12-16 05:02 --------- dc----w C:\Program Files\Sony
2007-12-16 05:01 --------- dc----w C:\Program Files\Common Files\InstallShield
2007-12-02 06:57 --------- dc----w C:\Program Files\Google
.
((((((((((((((((((((((((((((( snapshot@2008-01-25_23.48.08.54 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-26 05:41:05 1,421,312 -c--a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
+ 2008-01-29 01:54:18 1,421,312 -c--a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
- 2008-01-26 05:41:05 8,192 -c--a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
+ 2008-01-29 01:54:18 8,192 -c--a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
- 2008-01-26 05:41:07 1,417,216 -c--a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\NTUSER.DAT
+ 2008-01-29 01:54:18 1,417,216 -c--a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\NTUSER.DAT
- 2008-01-26 05:41:07 8,192 -c--a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
+ 2008-01-29 01:54:18 8,192 -c--a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
- 2008-01-26 05:41:12 5,275,648 -c--a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000005\NTUSER.DAT
+ 2008-01-29 01:54:19 5,345,280 -c--a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000005\NTUSER.DAT
- 2008-01-26 05:41:12 159,744 -c--a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000006\UsrClass.dat
+ 2008-01-29 01:54:19 163,840 -c--a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000006\UsrClass.dat
+ 2008-01-24 15:01:35 163,328 -c--a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2008-01-27 21:31:30 5,345,280 -c--a-w C:\WINDOWS\ERUNT\SDFIX\Users\
00000001\NTUSER.DAT
+ 2008-01-27 21:31:30 163,840 -c--a-w C:\WINDOWS\ERUNT\SDFIX\Users\
00000002\UsrClass.dat
+ 2008-01-24 15:01:35 163,328 -c--a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-01-27 21:31:15 5,345,280 -c--a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\
00000001\NTUSER.DAT
+ 2008-01-27 21:31:15 163,840 -c--a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\
00000002\UsrClass.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"webscan"="C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe" [ ]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-01-16 11:07 176173]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"StopSignSsTsMon"="C:\Program Files\Acceleration Software\Anti-Virus\sstsmon.dll" [2007-11-26 11:40 149152]
"SiSUSBRG"="C:\WINDOWS\sisUSBrg.exe" [2002-04-25 18:06 32768]
"RegistryMechanic"="" []
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-10 15:27 385024]
"nwiz"="nwiz.exe" [2003-05-02 01:19 323584 C:\WINDOWS\system32\nwiz.exe]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2003-05-02 01:19 4640768]
"NeroCheck"="C:\WINDOWS\System32\\NeroCheck.exe" [2001-07-09 04:50 155648]
"LiveNote"="livenote.exe" [2002-07-11 07:31 40960 C:\WINDOWS\livenote.exe]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]
"InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [2003-06-26 18:30 1101874]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-09-23 23:08 49152]
"anvshell"="anvshell.exe" [2003-05-29 01:53 348160 C:\WINDOWS\anvshell.exe]
C:\Documents and Settings\Charlie Mitchell\PrintHood\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2007-12-15 23:02:28 344064]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2003-11-12 11:20:14 110592]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-09-23 23:28:44 282624]
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2005-11-04 15:04:48 176128]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-03-21 19:00:00 65588]
R1 ANVIOCTL;ANVIOCTL;C:\WINDOWS\system32\DRIVERS\anvioctl.sys [2003-05-19 02:12]
S3 SiS7012;Service for AC'97 Sample Driver (WDM);C:\WINDOWS\system32\drivers\sis7012.sys [2002-06-17 04:31]
.
Contents of the 'Scheduled Tasks' folder
"2008-01-23 14:20:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-28 20:01:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-28 20:03:48 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-29 02:03:45
ComboFix2.txt 2008-01-28 04:32:56
ComboFix3.txt 2008-01-26 06:12:30
ComboFix4.txt 2008-01-26 05:48:34
.
2008-01-10 05:24:21 --- E O F ---
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:09:29 PM, on 1/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\anvshell.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [webscan] "C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe" -k
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [StopSignSsTsMon] Rundll32.exe "C:\Program Files\Acceleration Software\Anti-Virus\sstsmon.dll",VerifyStatus
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\sisUSBrg.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [LiveNote] livenote.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [anvshell] anvshell.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {352797A0-EFD0-4FA6-B229-145120EA4B8A} (Walt Disney Internet Group Hardware Control) -
https://disneyblast....wareControl.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) -
http://www.nick.com/.../GrooveAX27.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) -
http://a.download.to...31.5/ttinst.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) -
http://a532.g.akamai...l/installer.exe
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -
http://aolsvc.aol.co...ploader_v10.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: InCD File System Service (InCDsrv) - Unknown owner - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: ASUS Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
--
End of file - 7125 bytes
Thanks amigo