Thanks so much for you help.
Combofix Log:
ComboFix 08-06-19.4 - Rushelle Byfield 2008-06-21 5:38:28.1 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Rushelle Byfield\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Rushelle Byfield\Local Settings\Temporary Internet Files\anojyx.com
C:\Documents and Settings\Rushelle Byfield\Local Settings\Temporary Internet Files\nipamikig.bat
C:\Documents and Settings\Rushelle Byfield\Local Settings\Temporary Internet Files\yhybequ.com
C:\WINDOWS\braviax.exe
C:\WINDOWS\g32.txt
C:\WINDOWS\s32.txt
C:\WINDOWS\system32\aspimgr.exe
C:\WINDOWS\system32\braviax.exe
C:\WINDOWS\system32\DelSelf.bat
C:\WINDOWS\system32\drivers\fad.sys
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\packet.dll
C:\WINDOWS\system32\pthreadVC.dll
C:\WINDOWS\system32\winivstr.exe
C:\WINDOWS\system32\wpcap.dll
C:\WINDOWS\ws386.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_ASPIMGR
——-\Legacy_NPF
——-\Service_aspimgr
——-\Service_NPF
((((((((((((((((((((((((( Files Created from 2008-05-20 to 2008-06-20 )))))))))))))))))))))))))))))))
.
2008-06-21 04:32 . 2006-08-21 18:14 128,896 ——— C:\windows\system32\DllCache\fltmgr.sys
2008-06-21 04:32 . 2006-08-21 18:14 23,040 ——— C:\windows\system32\DllCache\fltmc.exe
2008-06-21 04:32 . 2006-08-21 21:21 16,896 ——— C:\windows\system32\DllCache\fltlib.dll
2008-06-21 04:17 . 2008-06-21 04:17 d——– C:\Program Files\MSXML 4.0
2008-06-20 20:28 . 2008-06-13 22:10 272,128 ——— C:\windows\system32\DllCache\bthport.sys
2008-06-20 04:39 . 2008-06-20 04:37 102,664 –a—— C:\windows\system32\drivers\tmcomm.sys
2008-06-20 04:37 . 2008-06-20 06:52 d——– C:\Documents and Settings\Rushelle Byfield\.housecall6.6
2008-06-20 03:12 . 2007-07-09 22:09 584,192 ——— C:\windows\system32\DllCache\rpcrt4.dll
2008-06-20 03:01 . 2008-06-21 04:54 d–h—– C:\windows\$hf_mig$
2008-06-20 01:53 . 2008-06-20 01:53 d——– C:\Program Files\Trend Micro
2008-06-20 01:30 . 2007-07-30 19:19 271,224 –a—— C:\windows\system32\mucltui.dll
2008-06-20 01:30 . 2007-07-30 19:19 30,072 –a—— C:\windows\system32\mucltui.dll.mui
2008-06-19 22:21 . 2008-06-19 22:21 19,448 –a—— C:\Program Files\Common Files\qymywyxa.bat
2008-06-19 22:21 . 2008-06-19 22:21 19,403 –a—— C:\Documents and Settings\Rushelle Byfield\Application Data\fijizojeqy.scr
2008-06-19 22:21 . 2008-06-19 22:21 19,255 –a—— C:\Program Files\Common Files\exehiqudaw.sys
2008-06-19 22:21 . 2008-06-19 22:21 18,221 –a—— C:\windows\miwohej.lib
2008-06-19 22:21 . 2008-06-19 22:21 16,907 –a—— C:\Documents and Settings\All Users\Application Data\ydedotyne.exe
2008-06-19 22:21 . 2008-06-19 22:21 15,290 –a—— C:\windows\nypejuh.dll
2008-06-19 22:21 . 2008-06-19 22:21 13,916 –a—— C:\windows\aqucutuq.inf
2008-06-19 22:21 . 2008-06-19 22:21 13,319 –a—— C:\windows\jadematy._sy
2008-06-19 22:21 . 2008-06-19 22:21 13,228 –a—— C:\windows\ufokypi.exe
2008-06-19 22:21 . 2008-06-19 22:21 13,212 –a—— C:\Documents and Settings\Rushelle Byfield\Application Data\subybalus.vbs
2008-06-19 22:21 . 2008-06-19 22:21 12,438 –a—— C:\windows\hucyl._dl
2008-06-19 22:21 . 2008-06-19 22:21 12,375 –a—— C:\windows\kiqyji.scr
2008-06-19 22:21 . 2008-06-19 22:21 12,076 –a—— C:\windows\ysej.bat
2008-06-19 22:21 . 2008-06-19 22:21 11,946 –a—— C:\windows\system32\kiqeduh.reg
2008-06-19 22:21 . 2008-06-19 22:21 10,127 –a—— C:\Documents and Settings\All Users\Application Data\esabodomy.dat
2008-06-19 15:55 . 2008-06-21 05:51 54,156 –ah—– C:\windows\QTFont.qfn
2008-06-19 15:55 . 2008-06-19 15:55 1,409 –a—— C:\windows\QTFont.for
2008-06-12 21:04 . 2006-11-01 12:48 2,129,920 –a—— C:\windows\system32\WLBCGCBPRO731.DLL
2008-06-12 21:04 . 2006-11-01 12:48 1,392,640 –a—— C:\windows\system32\WLTRAY.EXE
2008-06-12 21:04 . 2006-11-01 12:48 757,760 –a—— C:\windows\system32\bcm1xsup.dll
2008-06-12 21:04 . 2006-11-01 12:48 86,016 –a—— C:\windows\system32\preflib.dll
2008-06-12 21:04 . 2006-11-01 12:48 69,632 –a—— C:\windows\system32\bcmwlpkt.dll
2008-06-12 21:04 . 2006-11-01 12:48 44,032 –a—— C:\windows\system32\wltrynt.dll
2008-06-12 21:04 . 2006-11-01 12:48 33,664 –a—— C:\windows\system32\drivers\BCMWLNPF.SYS
2008-06-12 21:04 . 2006-11-01 12:48 20,480 –a—— C:\windows\system32\WLTRYSVC.EXE
2008-06-11 08:45 . 2008-06-11 08:47 d——– C:\NetZeroInstaller
2008-06-11 08:45 . 2008-06-11 08:45 d——– C:\Documents and Settings\All Users\Application Data\NetZero
2008-06-07 10:59 . 2008-06-11 07:43 d——– C:\Program Files\Windows Media Connect 2
2008-06-07 10:55 . 2008-06-11 07:43 d——– C:\windows\system32\drivers\UMDF
2008-06-04 03:15 . 2008-06-04 03:15 d——– C:\Documents and Settings\Rushelle Byfield\Application Data\OLYMPUS
2008-06-04 03:02 . 2008-06-04 03:02 d——– C:\Binaries
2008-06-04 03:01 . 2008-06-04 03:01 d——– C:\windows\system32\QuickTime
2008-06-04 03:01 . 2008-06-04 03:01 d——– C:\Program Files\OLYMPUS
2008-06-04 03:01 . 2004-06-09 07:41 319,488 ——— C:\windows\system32\Pvmjpg21.dll
2008-06-04 03:00 . 2004-03-09 02:55 13,567 –a—— C:\windows\system32\drivers\CDRBSDRV.SYS
2008-06-04 02:59 . 2008-06-04 02:59 d——– C:\Program Files\PIXELA
2008-05-31 23:43 . 2008-05-31 23:43 d——– C:\Documents and Settings\Rushelle Byfield\Application Data\Qualcomm
2008-05-31 23:42 . 2008-05-31 23:42 d——– C:\Program Files\Qualcomm
2008-05-31 15:24 . 2008-05-31 15:24 d——– C:\Documents and Settings\Default User\Application Data\Apple Computer
2008-05-25 21:18 . 2008-05-25 21:19 d——– C:\Program Files\iTunes
2008-05-25 21:15 . 2008-05-25 21:16 d——– C:\Program Files\QuickTime
2008-05-25 21:12 . 2008-05-25 21:12 d—-c— C:\windows\system32\DRVSTORE
2008-05-25 21:11 . 2008-05-25 21:11 d——– C:\Program Files\Common Files\Apple
2008-05-25 15:21 . 2008-05-25 15:21 d——– C:\windows\peernet
2008-05-25 15:20 . 2008-05-25 15:20 d——– C:\windows\provisioning
2008-05-25 15:16 . 2008-05-25 15:16 d——– C:\windows\ServicePackFiles
2008-05-25 15:09 . 2005-06-28 10:21 22,752 –a—— C:\windows\system32\spupdsvc.exe
2008-05-25 15:04 . 2008-05-25 15:04 d——– C:\windows\EHome
2008-05-25 14:54 . 2002-04-16 11:11 67,866 ——— C:\windows\system32\drivers\netwlan5.img
2008-05-25 14:54 . 2004-08-04 14:56 11,776 ——— C:\windows\system32\spnpinst.exe
2008-05-25 14:54 . 2004-08-03 04:20 7,208 ——— C:\windows\system32\secupd.sig
2008-05-25 14:54 . 2004-08-03 04:20 4,569 ——— C:\windows\system32\secupd.dat
2008-05-25 14:28 . 2008-05-25 14:28 d——– C:\windows\system32\bits
2008-05-25 14:27 . 2004-08-04 16:56 438,784 ——— C:\windows\system32\xpob2res.dll
2008-05-25 14:27 . 2004-08-04 16:56 351,232 –a—— C:\windows\system32\winhttp.dll
2008-05-25 14:27 . 2004-08-04 16:56 18,944 –a—— C:\windows\system32\qmgrprxy.dll
2008-05-25 14:27 . 2004-08-04 16:56 8,192 ——— C:\windows\system32\bitsprx2.dll
2008-05-25 14:27 . 2004-08-04 16:56 7,168 ——— C:\windows\system32\bitsprx3.dll
2008-05-25 14:25 . 2007-07-31 09:19 549,720 –a—— C:\windows\system32\wuapi.dll
2008-05-25 14:25 . 2007-07-31 09:19 325,976 –a—— C:\windows\system32\wucltui.dll
2008-05-25 14:25 . 2007-07-31 09:19 216,408 –a—— C:\windows\system32\wuaucpl.cpl
2008-05-25 14:25 . 2007-07-31 09:19 43,352 –a—— C:\windows\system32\wups2.dll
2008-05-25 14:25 . 2007-07-31 09:18 34,136 –a—— C:\windows\system32\wucltui.dll.mui
2008-05-25 14:25 . 2007-07-31 09:18 33,624 –a—— C:\windows\system32\wups.dll
2008-05-25 14:25 . 2007-07-31 09:19 25,944 –a—— C:\windows\system32\wuaucpl.cpl.mui
2008-05-25 14:25 . 2007-07-31 09:19 25,944 –a—— C:\windows\system32\wuapi.dll.mui
2008-05-25 14:25 . 2007-07-31 09:18 20,312 –a—— C:\windows\system32\wuaueng.dll.mui
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-20 20:53 ——— d—–w C:\Documents and Settings\Rushelle Byfield\Application Data\Skype
2008-06-20 20:45 ——— d—–w C:\Program Files\Symantec AntiVirus
2008-06-20 06:28 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-06-19 19:21 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-06-19 19:21 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-06-19 18:53 ——— d—–w C:\Program Files\Symantec
2008-06-19 13:21 16,038 —-a-w C:\Program Files\Common Files\ziti.db
2008-06-19 13:21 14,741 —-a-w C:\Program Files\Common Files\ebyjodav._dl
2008-06-13 13:10 272,128 ——w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-12 12:04 ——— d—–w C:\Program Files\Dell
2008-06-10 23:47 ——— d—–w C:\Program Files\NetZero
2008-06-08 18:13 ——— d–h–w C:\Documents and Settings\Rushelle Byfield\Application Data\Move Networks
2008-06-03 17:59 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-06-02 12:54 ——— d—–w C:\Program Files\Common Files\Adobe
2008-06-02 12:50 ——— d—–w C:\Documents and Settings\Rushelle Byfield\Application Data\AdobeUM
2008-05-28 06:33 ——— d—–w C:\Program Files\Soulseek
2008-05-25 12:18 ——— d—–w C:\Program Files\iPod
2008-05-08 12:28 202,752 —-a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-04-23 01:25 ——— d—–w C:\Program Files\Apple Software Update
2008-04-23 01:22 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 16:56 15360]
"NetZero_uoltray"="C:\Program Files\NetZero\exec.exe" [2007-03-07 09:51 1629184]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\ypager.exe" [ ]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2006-10-14 07:20 20058152]
"OM_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe" [2005-11-30 09:19 57344]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-02-03 11:32 155648]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-05 11:24 28672 C:\windows\system32\Ati2mdxx.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 18:25 144784]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-07-30 03:30 335872]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2004-03-05 10:59 487424]
"bascstray"="BascsTray.exe" []
"DVDSentry"="C:\WINDOWS\System32\DSentry.exe" [2002-07-18 00:18 28672]
"AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-12-18 02:28 684032]
"LWBMOUSE"="C:\Program Files\COMPAQ\CPQ650TP\Ver. 2.3\LWBWHEEL.exe" [2003-05-19 12:24 438272]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-11-11 08:11 180269]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-17 13:11 49152]
"ClubBox"="" []
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-11-22 06:38 52840]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2007-03-15 08:49 125632]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-10-10 14:28 36352]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-29 13:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-31 00:36 267048]
"OM_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe" [2005-11-30 09:19 40960]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2006-11-01 12:48 1392640]
C:\Documents and Settings\Rushelle Byfield\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2007-11-02 10:29:28 344064]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe [2006-04-12 00:01:07 49254]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 17:38:16 29696]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2004-07-27 01:38:26 24576]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-05 08:28:24 258048]
HP Image Zone Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-05 08:50:52 53248]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-18 05:05:56 65588]
VPN Client.lnk - C:\WINDOWS\Installer\{CCBAA1F7-E5E1-48B2-9ED9-A79C6A37CE78}\Icon3E5562ED7.ico [2007-07-13 10:02:55 6144]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= C:\Program Files\Qualcomm\Eudora\EuShlExt.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPG"= pvmjpg21.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
Contents of the 'Scheduled Tasks' folder
"2008-06-18 08:26:24 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-21 05:50:48
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\Ati2evxx.dll
.
———————— Other Running Processes ————————
.
C:\windows\system32\ati2evxx.exe
C:\windows\system32\WLTRYSVC.EXE
C:\windows\system32\BCMWLTRY.EXE
C:\windows\system32\scardsvr.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\windows\system32\BAsfIpM.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\windows\system32\ati2evxx.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\windows\system32\wdfmgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Apoint\ApntEx.exe
C:\windows\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\NetZero\qsacc\x1exec.exe
C:\Program Files\Symantec AntiVirus\DoScan.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
.
**************************************************************************
.
Completion time: 2008-06-21 6:09:34 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-20 21:08:40
Pre-Run: 5,523,357,696 bytes free
Post-Run: 5,721,866,240 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
246 — E O F — 2008-06-20 19:55:38
HijackThis Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:41:57 AM, on 6/21/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\basfipm.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\COMPAQ\CPQ650TP\Ver. 2.3\LWBWHEEL.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\NetZero\exec.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\NetZero\exec.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\NetZero\qsacc\x1exec.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\junebug.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.netzero.net/s/search?r=minisearch
R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Program Files\NetZero\SearchEnh1.dll
O2 - BHO: Pop-up Blocker - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\NetZero\qsacc\X1IEBHO.dll
O3 - Toolbar: ZeroBar - {F5735C15-1FB2-41FE-BA12-242757E69DDE} - C:\Program Files\NetZero\toolbar.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [bascstray] BascsTray.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\COMPAQ\CPQ650TP\Ver. 2.3\LWBWHEEL.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NetZero_uoltray] C:\Program Files\NetZero\exec.exe regrun
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe -NoStart
O4 - Startup: Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: VPN Client.lnk = ?
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Display All Images with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/228
O8 - Extra context menu item: Display Image with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/227
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540012} -
http://www.funnytaf.com/fun/installer/Install.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/as…abs/tgctlsr.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1211693090298
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1211693062538
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Broadcom ASF IP monitoring service v6.0.3 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\System32\basfipm.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
–
End of file - 10244 bytes