ComboFix 08-02.01.5 - Todd Baker 2008-02-01 14:14:19.6 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.433 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Todd Baker\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-01-01 to 2008-02-01 )))))))))))))))))))))))))))))))
.
2008-02-01 08:00 . 2008-02-01 08:00 5,209 –a—— C:\WirelessDiagLog.csv
2008-01-31 12:51 . 2008-01-31 13:49 d——– C:\Program Files\EsetOnlineScanner
2008-01-30 22:10 . 2008-01-30 22:10 d——– C:\Program Files\Sun
2008-01-30 22:10 . 2007-12-14 01:59 69,632 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-01-30 22:07 . 2008-01-30 22:10 d——– C:\Program Files\Java
2008-01-30 22:05 . 2008-01-30 22:05 d——– C:\Program Files\Common Files\Java
2008-01-29 14:10 . 2008-01-29 14:10 d——– C:\Program Files\Trend Micro
2008-01-28 22:27 . 2008-01-28 22:27 d——– C:\Program Files\Lavasoft
2008-01-27 12:05 . 2008-01-31 12:21 321 –a—— C:\BOOT.INI
2008-01-27 07:42 . 2008-01-27 07:42 d——– C:\Program Files\Microsoft Silverlight
2008-01-26 19:06 . 2008-01-29 11:46 d——– C:\VundoFix Backups
2008-01-23 04:15 . 2008-01-23 04:15 67 –a—— C:\WINDOWS\URPC.INI
2008-01-19 00:04 . 2008-01-19 00:04 d——– C:\Program Files\DVDFab Platinum 4
2008-01-18 17:02 . 2008-01-18 17:02 d——– C:\Program Files\LG Software Innovations
2008-01-18 17:02 . 2008-01-27 08:54 d——– C:\Documents and Settings\Todd Baker\Application Data\Vso
2008-01-18 17:02 . 2008-01-18 17:02 47,360 –a—— C:\WINDOWS\system32\drivers\pcouffin.sys
2008-01-18 17:02 . 2008-01-27 06:58 47,360 –a—— C:\Documents and Settings\Todd Baker\Application Data\pcouffin.sys
2008-01-18 16:25 . 2008-01-18 16:26 d——– C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-01-18 15:34 . 2008-01-18 15:34 d——– C:\Program Files\XviD
2008-01-18 15:34 . 2008-01-18 15:36 67 –a—— C:\WINDOWS\#1 DVD Ripper.INI
2008-01-07 13:36 . 2008-01-07 13:37 d——– C:\Documents and Settings\Todd Baker\Application Data\PCTV4Me
2008-01-07 13:36 . 2008-01-07 13:37 d——– C:\Documents and Settings\All Users\Application Data\PCTV4Me
2008-01-07 13:23 . 2008-01-07 13:23 d——– C:\Program Files\Common Files\Synacast
2008-01-07 13:23 . 2008-01-07 13:23 d——– C:\Documents and Settings\Todd Baker\Application Data\PPMate
2008-01-07 12:42 . 2008-01-07 12:42 359,808 –a—— C:\WINDOWS\system32\drivers\TCPIP.SYS.ORIGINAL
2008-01-05 10:35 . 2008-01-05 10:35 0 –a—— C:\WINDOWS\iplayer.INI
2008-01-05 10:33 . 2008-01-05 10:34 d——– C:\Program Files\InterActual
2008-01-04 13:50 . 2008-01-27 13:09 0 –a—— C:\WINDOWS\system32\tdlsoui.flag
2008-01-04 13:48 . 2008-01-05 07:08 d——– C:\Documents and Settings\Todd Baker\Application Data\dvdcss
2008-01-02 11:39 . 2008-01-02 11:39 d——– C:\Documents and Settings\Todd Baker\Application Data\Simple Star
2008-01-02 11:38 . 2008-01-02 11:38 d——– C:\Program Files\Common Files\Simple Star Shared
2008-01-02 11:36 . 2008-01-02 11:45 d——– C:\Documents and Settings\Todd Baker\Application Data\Walgreens
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-01 19:55 ——— d—–w C:\Documents and Settings\Todd Baker\Application Data\Skype
2008-02-01 19:53 ——— d—–w C:\Documents and Settings\Todd Baker\Application Data\skypePM
2008-02-01 19:49 ——— d—–w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-02-01 12:31 ——— d—–w C:\Program Files\Symantec AntiVirus
2008-02-01 12:31 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-02-01 12:31 ——— d—–w C:\Program Files\Apoint
2008-01-31 04:00 ——— d—–w C:\Program Files\Microsoft ActiveSync
2008-01-30 16:42 ——— d—–w C:\Documents and Settings\Todd Baker\Application Data\U3
2008-01-30 14:31 ——— d—–w C:\Program Files\Eraser
2008-01-29 04:27 ——— d—–w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-29 04:18 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-01-27 19:01 ——— d—–w C:\Documents and Settings\Todd Baker\Application Data\Hamachi
2008-01-27 15:06 ——— d—–w C:\Program Files\Password Safe
2008-01-27 12:59 ——— d—–w C:\Program Files\MagicDVDRipper
2008-01-23 05:04 ——— d—–w C:\Documents and Settings\Todd Baker\Application Data\Azureus
2008-01-22 18:42 80 ——w C:\Documents and Settings\Todd Baker\Application Data\TIF.DAT
2008-01-07 21:03 ——— d—–w C:\Program Files\Azureus
2007-12-13 04:55 ——— d—–w C:\Program Files\SlySoft
2007-12-09 18:43 ——— d—–w C:\Documents and Settings\Todd Baker\Application Data\SlySoft
2007-12-09 18:40 ——— d—–w C:\Documents and Settings\All Users\Application Data\SlySoft
2007-12-09 18:37 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-09 13:15 ——— d—–w C:\Documents and Settings\Todd Baker\Application Data\CyberLink
2007-12-08 22:25 ——— d—–w C:\Program Files\GE Industrial Systems
2007-12-05 07:37 ——— d—–w C:\Documents and Settings\Todd Baker\Application Data\GoodSync
2007-12-01 20:27 ——— d—–w C:\Documents and Settings\All Users\Application Data\SongbirdVLC
2007-12-01 20:22 ——— d—–w C:\Documents and Settings\Todd Baker\Application Data\Songbird1
2007-12-01 19:31 ——— d—–w C:\Program Files\PCPitstop
2007-11-25 21:29 32 —-a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2007-11-25 21:08 21,361 —-a-w C:\WINDOWS\AegisP.sys
2003-08-27 19:19 36,963 —-a-r C:\Program Files\Common Files\SM1updtr.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-27 12:59 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-04-28 18:05 8429568]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 04:00 110592 C:\WINDOWS\system32\bthprops.cpl]
"NvMediaCenter"="NvMCTray.dll" [2007-04-28 18:05 81920 C:\WINDOWS\system32\nvmctray.dll]
"AT&T Communication Manager"="C:\Program Files\AT&T\Communication Manager\ATTCM.exe" [2008-01-27 12:59 33280]
C:\Documents and Settings\TPS\Start Menu\Programs\Startup\
hamachi.lnk - C:\Program Files\Hamachi\hamachi.exe [2007-05-24 11:23:56 624416]
C:\Documents and Settings\Todd Baker\Start Menu\Programs\Startup\
Hamachi.lnk - C:\Program Files\Hamachi\hamachi.exe [2007-05-24 11:23:56 624416]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2005-11-18 16:46:00 1724416]
SEL Update Manager.lnk - C:\Program Files\SEL\AcSELerator\SELUpdate Manager\SELUpdateManager.exe [2007-04-09 14:29:44 303104]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 01000000
R1 tcpipBM;Bytemobile Kernel Network Provider;C:\WINDOWS\system32\drivers\tcpipBM.sys [2007-09-08 20:17]
R2 CBN;CBN;C:\WINDOWS\System32\Drivers\CBN.SYS [2007-11-08 20:09]
R3 guardian2;guardian2;C:\WINDOWS\system32\Drivers\oz776.sys [2007-02-23 14:47]
S3 CSRBC;CSRBC.Sys CSR test driver;C:\WINDOWS\system32\Drivers\csrbcxp.sys [2007-01-16 10:22]
S3 DN2AKNET;Dualnet IM Driver;C:\Program Files\Common Files\Deterministic Networks\Dnet2\bin\DN2AKNET.sys [2006-02-20 11:18]
S3 DniVad;Kongsberg Maritime virtual Network Adapter;C:\WINDOWS\system32\DRIVERS\dnvad.sys [2006-02-20 11:18]
S3 motmodem;Motorola USB CDC ACM Driver;C:\WINDOWS\system32\DRIVERS\motmodem.sys [2007-05-04 15:54]
S3 PCTINDIS5;PCTINDIS5 NDIS Protocol Driver;C:\WINDOWS\system32\PCTINDIS5.SYS [2007-09-08 20:13]
S3 SE2Cbus;Sony Ericsson Device 044 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\SE2Cbus.sys [2006-11-10 08:54]
S3 SE2Cmdfl;Sony Ericsson Device 044 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\SE2Cmdfl.sys [2006-11-10 08:54]
S3 SE2Cmdm;Sony Ericsson Device 044 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\SE2Cmdm.sys [2006-11-10 08:54]
S3 SE2Cmgmt;Sony Ericsson Device 044 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\SE2Cmgmt.sys [2006-11-10 08:54]
S3 se2Cnd5;Sony Ericsson Device 044 USB Ethernet Emulation SEMC44 (NDIS);C:\WINDOWS\system32\DRIVERS\se2Cnd5.sys [2006-11-10 08:54]
S3 SE2Cobex;Sony Ericsson Device 044 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\SE2Cobex.sys [2006-11-10 08:54]
S3 se2Cunic;Sony Ericsson Device 044 USB Ethernet Emulation SEMC44 (WDM);C:\WINDOWS\system32\DRIVERS\se2Cunic.sys [2006-11-10 08:54]
S3 SEL-5860 Time Service;SEL-5860 Time Service;"C:\Program Files\SEL\SEL5860\SEL-5860 Time Service.exe" [2006-06-30 07:50]
S3 SWNC8U20;Sierra Wireless MUX NDIS Driver (UMTS20);C:\WINDOWS\system32\DRIVERS\swnc8u20.sys [2007-09-05 15:56]
S3 SWUMX20;Sierra Wireless USB MUX Driver (UMTS20);C:\WINDOWS\system32\DRIVERS\swumx20.sys [2007-09-05 15:56]
S3 SWUMX51;Sierra Wireless USB MUX Driver (UMTS51);C:\WINDOWS\system32\DRIVERS\swumx51.sys []
S3 USBDongle;USBDongle;C:\WINDOWS\system32\DRIVERS\USBKey.sys [2002-12-27 01:09]
S3 V0070VID;Creative WebCam Notebook Ultra;C:\WINDOWS\system32\DRIVERS\V0070Vid.sys [2005-02-18 00:24]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{286a2e99-0a18-11dc-b0f5-cb21c15f200b}]
\Shell\AutoRun\command - E:\PortableApps\PortableAppsMenu\PortableAppsMenu.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{87cd5e04-1306-11dc-b108-0019b9694767}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bdaf34f0-5737-11dc-b65f-00164148b3dc}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f90b679c-84c6-11dc-b6b6-00a0d5ffff85}]
\Shell\AutoRun\command - E:\PortableApps\PortableAppsMenu\PortableAppsMenu.exe
.
**************************************************************************
disk not found C:\
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
disk not found C:\
**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\WINDOWS\system32\bmwebcfg.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Dell\OpenManage\Client\Iap.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\SEL\AcSELerator\SELUpdate Manager\SELUpdateManager.exe
C:\Program Files\Hamachi\hamachi.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
.
**************************************************************************
.
Completion time: 2008-02-01 14:23:50 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-01 20:22:58
ComboFix2.txt 2008-02-01 19:23:07
ComboFix3.txt 2008-02-01 12:33:57
ComboFix4.txt 2008-02-01 04:04:53
ComboFix5.txt 2008-01-31 18:39:07
.
2008-01-08 20:38:25 — E O F —
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:24, on 2008-02-01
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\bmwebcfg.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Dell\OpenManage\Client\Iap.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\SEL\AcSELerator\SELUpdate Manager\SELUpdateManager.exe
C:\Program Files\Hamachi\hamachi.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\scanner.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.47.6.3:8887
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AT&T Communication Manager] "C:\Program Files\AT&T\Communication Manager\ATTCM.exe" -a
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: Hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe
O4 - Global Startup: Bluetooth Manager.lnk = C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
O4 - Global Startup: SEL Update Manager.lnk = C:\Program Files\SEL\AcSELerator\SELUpdate Manager\SELUpdateManager.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdat…b?1180326421187
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = TPS
O17 - HKLM\Software\..\Telephony: DomainName = TPS
O17 - HKLM\System\CCS\Services\Tcpip\..\{06DED577-FDB1-4CD0-9491-D956C6614714}: NameServer = 5.35.153.15
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Bytemobile Web Configurator (bmwebcfg) - Bytemobile, Inc. - C:\WINDOWS\system32\bmwebcfg.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Iap - Dell Inc. - C:\Program Files\Dell\OpenManage\Client\Iap.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OpcEnum - OPC Foundation - C:\WINDOWS\system32\OpcEnum.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: SEL-5860 Time Service - Schweitzer Engineering Laboratories, Inc. - C:\Program Files\SEL\SEL5860\SEL-5860 Time Service.exe
O23 - Service: Sentinel Protection Server (SentinelProtectionServer) - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
–
End of file - 11499 bytes