Ok everything went fine. We have a wireless router that feeds our DSL throughout the house so I just took out my wireless card for the duration of ComboFixes scan. Here are both of the logs.
ComboFix 08-08-06.02 - Daniel 2008-08-07 10:00:02.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.644 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Daniel\Application Data\macromedia\Flash Player\#SharedObjects\M52VALAW\interclick.com
C:\Documents and Settings\Daniel\Application Data\macromedia\Flash Player\#SharedObjects\M52VALAW\interclick.com\ud.sol
C:\Documents and Settings\Daniel\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Daniel\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\system32\mdm.exe
.
((((((((((((((((((((((((( Files Created from 2008-07-07 to 2008-08-07 )))))))))))))))))))))))))))))))
.
2008-08-05 20:13 . 2008-07-30 20:07 38,472 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-05 20:13 . 2008-07-30 20:07 17,144 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-08-03 13:20 . 2008-08-06 12:00 d——– C:\Documents and Settings\Daniel\Application Data\dvdcss
2008-08-03 09:48 . 2008-08-04 12:22 d——– C:\Program Files\EOF - Song Maker
2008-08-01 17:54 . 2008-08-01 17:58 d——– C:\Program Files\FretsOnFire - Rock Band
2008-07-29 22:50 . 2008-07-29 22:51 d——– C:\Documents and Settings\Daniel\Application Data\fretsonfire
2008-07-29 22:49 . 2008-08-03 15:41 d——– C:\Program Files\FretsOnFire
2008-07-27 17:11 . 2008-07-27 17:12 d——– C:\Program Files\iTunes
2008-07-17 23:13 . 2008-07-17 23:13 d——– C:\Documents and Settings\Daniel\Application Data\vlc
2008-07-17 22:12 . 2008-07-17 22:12 d——– C:\Program Files\WinRAR 3.71
2008-07-15 21:05 . 2008-07-15 21:05 d——– C:\Program Files\VideoLAN
2008-07-15 19:09 . 2008-07-15 19:09 42,320 –a—— C:\WINDOWS\system32\xfcodec.dll
2008-07-15 14:59 . 2008-07-17 21:39 d——– C:\Documents and Settings\Daniel\Application Data\gtk-2.0
2008-07-15 14:58 . 2008-07-15 14:59 d——– C:\Documents and Settings\Daniel\Application Data\avidemux
2008-07-12 11:07 . 2008-07-17 22:16 d——– C:\Documents and Settings\Daniel\temp
2008-07-12 11:07 . 2008-07-12 11:50 d——– C:\Documents and Settings\Daniel\Application Data\TeamViewer
2008-07-11 23:36 . 2008-07-11 23:36 0 –ah—– C:\WINDOWS\SwSys2.bmp
2008-07-11 23:36 . 2008-07-11 23:36 0 –ah—– C:\WINDOWS\SwSys1.bmp
2008-07-11 23:35 . 2008-07-11 23:35 d——– C:\Program Files\Game Maker 7.0
2008-07-09 15:15 . 2008-07-09 15:15 d——– C:\Program Files\Common Files\Download Manager
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-07 12:22 ——— d—–w C:\Program Files\WarRock
2008-08-07 02:56 ——— d—–w C:\Program Files\Microsoft Games
2008-08-06 21:45 22,328 —-a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-08-06 21:44 107,832 —-a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-08-06 12:33 23 —-a-w C:\Documents and Settings\Daniel\jagex_runescape_preferences.dat
2008-08-06 12:15 ——— d—–w C:\Documents and Settings\All Users\Application Data\Avg7
2008-08-06 00:44 ——— d—–w C:\Program Files\Anti-Malware
2008-08-05 17:37 ——— d—–w C:\Documents and Settings\Daniel\Application Data\LimeWire
2008-08-05 00:34 ——— d—–w C:\Documents and Settings\Daniel\Application Data\Xfire
2008-08-04 23:57 ——— d—–w C:\Program Files\Bonjour
2008-08-01 17:58 ——— d—–w C:\Program Files\Knight Online
2008-08-01 16:22 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-01 13:27 ——— d—–w C:\Documents and Settings\Daniel\Application Data\DMCache
2008-08-01 11:14 ——— d—–w C:\Program Files\Xfire
2008-07-27 21:11 ——— d—–w C:\Program Files\iPod
2008-07-27 21:09 ——— d—–w C:\Program Files\QuickTime
2008-07-11 14:26 ——— d—–w C:\Program Files\Java
2008-07-09 19:13 ——— d—–w C:\Documents and Settings\Daniel\Application Data\AVG7
2008-06-28 23:10 ——— d—–w C:\Program Files\LimeWire
2008-06-28 17:36 ——— d—–w C:\Program Files\Activision
2008-06-20 17:41 245,248 —-a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 10:45 360,320 —-a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 —-a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 —-a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-20 03:09 ——— d—–w C:\Program Files\MetaStream
2008-06-13 13:10 272,128 ——w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-07 15:24 ——— d—–w C:\Program Files\DivX
2008-05-30 23:22 823,296 —-a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-05-30 23:22 823,296 —-a-w C:\WINDOWS\system32\divx_xx07.dll
2008-05-30 23:22 815,104 —-a-w C:\WINDOWS\system32\divx_xx0a.dll
2008-05-30 23:22 802,816 —-a-w C:\WINDOWS\system32\divx_xx11.dll
2008-05-30 23:22 683,520 —-a-w C:\WINDOWS\system32\DivX.dll
2008-05-30 23:22 593,920 —-a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-05-30 23:22 57,344 —-a-w C:\WINDOWS\system32\dpv11.dll
2008-05-30 23:22 53,248 —-a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-05-30 23:22 344,064 —-a-w C:\WINDOWS\system32\dpus11.dll
2008-05-30 23:22 294,912 —-a-w C:\WINDOWS\system32\dpu11.dll
2008-05-30 23:22 294,912 —-a-w C:\WINDOWS\system32\dpu10.dll
2008-05-22 22:22 524,288 —-a-w C:\WINDOWS\system32\DivXsm.exe
2008-05-22 22:22 3,596,288 —-a-w C:\WINDOWS\system32\qt-dx331.dll
2008-05-22 22:20 200,704 —-a-w C:\WINDOWS\system32\ssldivx.dll
2008-05-22 22:20 1,044,480 —-a-w C:\WINDOWS\system32\libdivx.dll
2008-05-22 22:19 81,920 —-a-w C:\WINDOWS\system32\dpl100.dll
2008-05-22 22:19 196,608 —-a-w C:\WINDOWS\system32\dtu100.dll
2008-05-22 22:19 161,096 —-a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-05-22 22:18 12,288 —-a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-05-07 05:18 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2008-04-03 20:12 124,760 —-a-w C:\Documents and Settings\Daniel\Application Data\GDIPFONTCACHEV1.DAT
2007-06-12 19:59 114,152 —-a-w C:\Documents and Settings\David Dara\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-12-12 11:31 335872]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2003-04-24 12:51 110592]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2003-04-24 12:44 610304]
"CTDVDDet"="C:\Program Files\Creative\USB SBAudigy2 NX\DVDAudio\CTDVDDet.EXE" [2003-06-18 01:00 45056]
"CTSysVol"="C:\Program Files\Creative\USB SBAudigy2 NX\Surround Mixer\CTSysVol.exe" [2003-07-09 14:36 57344]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2005-01-12 03:01 32768]
"FLMOFFICE4DMOUSE"="C:\Program Files\GE\98059 Keyboard and Mouse\mouse32a.exe" [2007-08-21 18:52 360448]
"OFFICEKB"="C:\Program Files\GE\98059 Keyboard and Mouse\kbdap32a.exe" [2007-08-21 18:52 381440]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-01-25 08:14 579072]
"VBTUCopy"="C:\Program Files\VBTUCopy\VBTUCopy.exe" [2005-01-27 06:14 131072]
"Profiler"="C:\Program Files\Saitek\Software\Profiler.exe" [2005-06-14 15:23 159744]
"SaiMfd"="C:\Program Files\Saitek\Software\SaiMfd.exe" [2005-06-17 19:02 126976]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 09:47 116040]
"SoundMan"="SOUNDMAN.EXE" [2003-05-14 09:20 55296 C:\WINDOWS\SOUNDMAN.EXE]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 16:24 28672 C:\WINDOWS\system32\Ati2mdxx.exe]
"SbUsb AudCtrl"="sbusbdll.dll" [2003-08-06 01:33 68608 C:\WINDOWS\system32\sbusbdll.dll]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-03-10 13:01 28160 C:\WINDOWS\KHALMNPR.Exe]
"atwtusb"="atwtusb.exe" [2005-03-09 18:29 290816 C:\WINDOWS\system32\atwtusb.exe]
"emMON"="HCWemMON.exe" [2006-05-31 12:24 61440 C:\WINDOWS\HCWemMON.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-01-25 08:14 219136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"AllowLegacyWebView"= 1 (0x1)
"AllowUnhashedWebView"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.SP54"= SP5X_32.DLL
"VIDC.SP55"= SP5X_32.DLL
"VIDC.SP56"= SP5X_32.DLL
"VIDC.SP57"= SP5X_32.DLL
"VIDC.SP58"= SP5X_32.DLL
"VIDC.JPGL"= jpgl.dll
"vidc.ixvp"= videoplus.dll
"VIDC.XFR1"= xfcodec.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-07-10 10:51 289064 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\MPSMC__U.EXE"=
"C:\\Program Files\\backburner 2\\monitor.exe"=
"C:\\Program Files\\Serif\\WebPlus\\10.0\\Program\\WebPlus.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Autodesk\\backburner\\monitor.exe"=
"C:\\Program Files\\Autodesk\\backburner\\manager.exe"=
"C:\\Program Files\\Autodesk\\backburner\\server.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Autodesk\\3dsMax8\\3dsmax.exe"=
"C:\\WINDOWS\\system32\\notepad.exe"=
"C:\\Program Files\\Xfire\\xfire.exe"=
"C:\\Program Files\\Microsoft Games\\Halo\\halo.exe"=
"C:\\Program Files\\WarRock\\WRLauncher.exe"=
"C:\\Program Files\\LucasArts\\Star Wars Battlefront\\GameData\\Battlefront.exe"=
"C:\\Program Files\\Electronic Arts\\Battlefield 2142\\BF2142.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\Activision\\THPS 4\\THPS4 (2)\\Game\\Skate4.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
S1 aiptektp;HyperPen;C:\WINDOWS\system32\DRIVERS\aiptektp.sys [2004-07-07 17:02]
S2 Ca536av;DV 4500(Video);C:\WINDOWS\system32\Drivers\Ca536av.sys []
S3 A4UsbScanner;600 USB Still Image Device Service;C:\WINDOWS\system32\drivers\usbscan.sys [2004-08-04 01:58]
S3 DCamUSBCompany;P35U Camera Capture;C:\WINDOWS\system32\DRIVERS\p35u.sys []
S3 gAGP440p;gAGP440p;C:\DOCUME~1\Daniel\LOCALS~1\Temp\gAGP440p.sys []
S3 KMW_KBD;Kensington Input Devices Class filter driver;C:\WINDOWS\system32\DRIVERS\KMW_KBD.sys []
S3 KMW_USB;Kensington MouseWorks USB filter driver;C:\WINDOWS\system32\DRIVERS\KMW_USB.sys [2004-01-19 15:07]
S3 MR97310_VGA_DUAL_CAMERA;VGA Dual Camera;C:\WINDOWS\system32\DRIVERS\mr97310v.sys [2004-03-17 02:54]
S3 Nalmsys;Nalmsys;C:\WINDOWS\System32\drivers\aec.sys [2006-02-14 20:22]
S3 SaiH040C;SaiH040C;C:\WINDOWS\system32\DRIVERS\SaiH040C.sys [2005-07-07 08:10]
S3 SaiU040C;SaiU040C;C:\WINDOWS\system32\DRIVERS\SaiU040C.sys [2005-07-07 08:10]
S3 Sbuotsiui;Sbuotsiui;C:\WINDOWS\system32\drivers\mf.sys [2004-08-04 02:07]
S3 sbusb;Sound Blaster USB Audio Driver;C:\WINDOWS\system32\DRIVERS\sbusb.sys [2003-08-25 03:12]
S3 USB28xxBGA;WinTV HVR-900;C:\WINDOWS\system32\DRIVERS\emBDA.sys [2006-09-13 12:21]
S3 USB28xxOEM;WinTV OEM Filter;C:\WINDOWS\system32\DRIVERS\emOEM.sys [2006-09-13 12:21]
S3 USBCamera;DV 4500(Still);C:\WINDOWS\system32\Drivers\Bulk536.sys []
S3 WLAN(WLAN);XPC 802.11b/g Wireless Kit Driver(WLAN);C:\WINDOWS\system32\DRIVERS\zd1211u.sys [2005-08-16 14:50]
S3 XDva020;XDva020;C:\WINDOWS\system32\XDva020.sys []
S3 XDva022;XDva022;C:\WINDOWS\system32\XDva022.sys []
S3 XDva114;XDva114;C:\WINDOWS\system32\XDva114.sys []
S3 ZD1211U(Hawking Technologies);Hawking Technologies HWU54D Hi-Gain Wireless-G USB Adapter(Hawking Technologies);C:\WINDOWS\system32\DRIVERS\zd1211u.sys [2005-08-16 14:50]
S3 ZDBRGSYS;ZDBRGSYS NDIS Protocol Driver;C:\WINDOWS\system32\ZDBRGSYS.SYS []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
2008-07-27 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]
2008-08-07 C:\WINDOWS\Tasks\RegCure Program Check.job
- C:\Program Files\RegCure\RegCure.exe [2007-08-02 12:20]
2008-03-15 C:\WINDOWS\Tasks\RegCure.job
- C:\Program Files\RegCure\RegCure.exe [2007-08-02 12:20]
.
- - - - ORPHANS REMOVED - - - -
ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file)
.
——- Supplementary Scan ——-
.
FireFox -: Profile - C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\prsjrkq6.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - www.google.com
FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npvirtools.dll
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-08-07 10:07:24
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-08-07 10:14:19
ComboFix-quarantined-files.txt 2008-08-07 14:14:15
Pre-Run: 22,758,100,992 bytes free
Post-Run: 22,790,983,680 bytes free
224 — E O F — 2008-07-09 14:25:24
Logfile of HijackThis v1.99.1
Scan saved at 10:16:52 AM, on 8/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Creative\USB SBAudigy2 NX\Surround Mixer\CTSysVol.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\GE\98059 Keyboard and Mouse\mouse32a.exe
C:\Program Files\GE\98059 Keyboard and Mouse\kbdap32a.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\HCWemMON.exe
C:\Program Files\VBTUCopy\VBTUCopy.exe
C:\Program Files\Saitek\Software\SaiMfd.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\System32\bgsvcgen.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Daniel\My Documents\Setup Files\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SbUsb AudCtrl] RunDll32 sbusbdll.dll,RCMonitor
O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\USB SBAudigy2 NX\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\USB SBAudigy2 NX\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\GE\98059 Keyboard and Mouse\mouse32a.exe
O4 - HKLM\..\Run: [OFFICEKB] C:\Program Files\GE\98059 Keyboard and Mouse\kbdap32a.exe
O4 - HKLM\..\Run: [atwtusb] atwtusb.exe beta
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [emMON] HCWemMON.exe
O4 - HKLM\..\Run: [VBTUCopy] C:\Program Files\VBTUCopy\VBTUCopy.exe /a /f
O4 - HKLM\..\Run: [Profiler] C:\Program Files\Saitek\Software\Profiler.exe
O4 - HKLM\..\Run: [SaiMfd] C:\Program Files\Saitek\Software\SaiMfd.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15012/CTSUEng.cab
O16 - DPF: {22D4879A-92DB-470D-8A83-E158797D8176} (Liquid.LiquidHelper) - file://D:\components\Liquid.ocx
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-3-48.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdat…b?1136763884000
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15012/CTPID.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\System32\bgsvcgen.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: RaySat_3dsmax8 Server (mi-raysat_3dsmax8) - Unknown owner - C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe