Hi again,
This is my new Hijackthis log and ComboFix log (I had my McAfee antivirus turn off while scanning through my system) :
ComboFix 08-08-24.03 - Owner 2008-08-26 5:31:51.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1501 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Owner.MinhHoangNguyen\Desktop\Error Cleaner.url
C:\Documents and Settings\Owner.MinhHoangNguyen\Desktop\Privacy Protector.url
C:\Documents and Settings\Owner.MinhHoangNguyen\Desktop\Spyware&Malware Protection.url
C:\Documents and Settings\Owner.MinhHoangNguyen\Favorites\Error Cleaner.url
C:\Documents and Settings\Owner.MinhHoangNguyen\Favorites\Privacy Protector.url
C:\Documents and Settings\Owner.MinhHoangNguyen\Favorites\Spyware&Malware Protection.url
.
—- Previous Run ——-
.
C:\_uninsep.bat
C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\macromedia\Flash Player\#SharedObjects\FUR8V3SE\iforex.com
C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\macromedia\Flash Player\#SharedObjects\FUR8V3SE\iforex.com\Emerp\Events\flash_object.swf\user_data.sol
C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\macromedia\Flash Player\#SharedObjects\FUR8V3SE\interclick.com
C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\macromedia\Flash Player\#SharedObjects\FUR8V3SE\interclick.com\ud.sol
C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\macromedia\Flash Player\#SharedObjects\FUR8V3SE\static.youku.com
C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\macromedia\Flash Player\#SharedObjects\FUR8V3SE\static.youku.com\v1.0.0272\v\swf\qplayer.swf\qplayer.sol
C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com
C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com\settings.sol
C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#static.youku.com
C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#static.youku.com\settings.sol
C:\Documents and Settings\Owner.MinhHoangNguyen\Desktop\Error Cleaner.url
C:\Documents and Settings\Owner.MinhHoangNguyen\Desktop\Privacy Protector.url
C:\Documents and Settings\Owner.MinhHoangNguyen\Desktop\Spyware&Malware Protection.url
C:\Documents and Settings\Owner.MinhHoangNguyen\Favorites\Error Cleaner.url
C:\Documents and Settings\Owner.MinhHoangNguyen\Favorites\Privacy Protector.url
C:\Documents and Settings\Owner.MinhHoangNguyen\Favorites\Spyware&Malware Protection.url
C:\Program Files\autorun.inf
C:\Program Files\Common Files\sogou pxp
C:\WINDOWS\system32\anshslgx.dll
C:\WINDOWS\system32\BKSCLkkj.ini
C:\WINDOWS\system32\BKSCLkkj.ini2
C:\WINDOWS\system32\dao350.dll
C:\WINDOWS\system32\ddcYsrRH.dll
C:\WINDOWS\system32\efndyonn.ini
C:\WINDOWS\system32\evlelweq.ini
C:\WINDOWS\system32\geBUMefG.dll
C:\WINDOWS\system32\ghboeqef.ini
C:\WINDOWS\system32\HPoorXbc.ini
C:\WINDOWS\system32\HPoorXbc.ini2
C:\WINDOWS\system32\Iklmmnnn.ini
C:\WINDOWS\system32\Iklmmnnn.ini2
C:\WINDOWS\system32\lcfgbsni.dll
C:\WINDOWS\system32\lqgcnjdc.ini
C:\WINDOWS\system32\mlJDvSJD.dll
C:\WINDOWS\system32\nadhexnr.dll
C:\WINDOWS\system32\RuEdJkkj.ini
C:\WINDOWS\system32\RuEdJkkj.ini2
C:\WINDOWS\system32\smtbrtbt.ini
C:\WINDOWS\system32\viwklask.dll
C:\WINDOWS\system32\WDcdLnpo.ini
C:\WINDOWS\system32\WDcdLnpo.ini2
C:\WINDOWS\system32\wjsidojk.dll
C:\WINDOWS\system32\xeejejsp.ini
C:\WINDOWS\system32\xyaGffii.ini
C:\WINDOWS\system32\xyaGffii.ini2
C:\WINDOWS\system32\ycsmkqhp.dll
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_P4P_SERVICE
——-\Service_P4P Service
((((((((((((((((((((((((( Files Created from 2008-07-26 to 2008-08-26 )))))))))))))))))))))))))))))))
.
2008-08-25 20:22 . 2008-08-25 20:22 578,560 –a–c— C:\WINDOWS\system32\dllcache\user32.dll
2008-08-25 20:20 . 2008-08-25 20:20 d——– C:\WINDOWS\ERUNT
2008-08-25 20:12 . 2008-08-25 20:35 d——– C:\SDFix
2008-08-25 15:44 . 2008-08-25 15:44 d——– C:\Program Files\Trend Micro
2008-08-25 13:44 . 2008-02-28 13:26 1,414,440 –a—— C:\WINDOWS\system32\ShellManager310E2D762.dll
2008-08-25 13:44 . 2008-02-28 13:01 774,144 –a—— C:\WINDOWS\system32\NEROINSTAEC43759.DB
2008-08-25 11:51 . 2008-08-25 11:52 d——– C:\Program Files\Common Files\Symantec Shared
2008-08-25 11:21 . 2008-08-26 05:26 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-25 11:21 . 2007-12-10 14:53 81,288 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2008-08-25 11:21 . 2007-12-10 14:53 66,952 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2008-08-25 11:21 . 2008-02-01 12:55 42,376 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-08-25 11:21 . 2007-12-10 14:53 29,576 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2008-08-25 11:20 . 2008-08-26 04:41 d——– C:\Program Files\Spyware Doctor
2008-08-25 11:20 . 2008-08-25 11:50 d——– C:\Program Files\Norton Security Scan
2008-08-25 11:20 . 2008-08-25 11:20 d——– C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\PC Tools
2008-08-25 11:19 . 2008-08-25 12:20 d——– C:\Documents and Settings\All Users\Application Data\Google Updater
2008-08-25 11:13 . 2008-08-25 11:13 d——– C:\Program Files\NeroInstall.bak
2008-08-25 03:02 . 2008-08-22 17:22 3,262 –a—— C:\WINDOWS\system32\2.ico
2008-08-25 02:55 . 2008-08-22 15:38 165,888 –a—— C:\WINDOWS\system32\MSA.cpl
2008-08-25 02:54 . 2008-08-25 11:12 d——– C:\Program Files\MSA
2008-08-25 02:54 . 2008-08-24 03:45 380,928 –a—— C:\WINDOWS\rodqgpvlkoa.dll
2008-08-25 02:54 . 2008-08-24 03:45 233,472 –a—— C:\WINDOWS\pdoskegl.dll
2008-08-25 02:54 . 2008-08-24 03:45 188,416 –a—— C:\WINDOWS\rqbmvpso.dll
2008-08-25 02:54 . 2008-08-24 03:45 155,648 –a—— C:\WINDOWS\qalkfxor.dll
2008-08-25 02:54 . 2008-08-24 03:45 86,016 –a—— C:\WINDOWS\rvoelbxt.exe
2008-08-25 02:54 . 2008-08-22 17:22 3,262 –a—— C:\WINDOWS\system32\1.ico
2008-08-22 23:40 . 2005-03-31 01:06 36,864 ——— C:\WINDOWS\system32\CTCamMgr.dll
2008-08-22 22:50 . 2008-08-22 22:50 d——– C:\WINDOWS\system32\scripting
2008-08-22 22:50 . 2008-08-22 22:50 d——– C:\WINDOWS\system32\en
2008-08-22 22:50 . 2008-08-22 22:50 d——– C:\WINDOWS\system32\bits
2008-08-22 22:50 . 2008-08-22 22:50 d——– C:\WINDOWS\l2schemas
2008-08-22 22:48 . 2008-08-22 22:48 d——– C:\WINDOWS\ServicePackFiles
2008-08-18 20:30 . 2008-04-13 17:11 136,192 ——— C:\WINDOWS\system32\aaclient.dll
2008-08-18 20:30 . 2008-04-13 17:11 4,255 ——— C:\WINDOWS\system32\drivers\adv01nt5.dll
2008-08-18 20:30 . 2008-04-13 17:11 3,967 ——— C:\WINDOWS\system32\drivers\adv02nt5.dll
2008-08-18 20:30 . 2008-04-13 17:11 3,775 ——— C:\WINDOWS\system32\drivers\adv11nt5.dll
2008-08-18 20:30 . 2008-04-13 17:11 3,711 ——— C:\WINDOWS\system32\drivers\adv09nt5.dll
2008-08-18 20:30 . 2008-04-13 17:11 3,647 ——— C:\WINDOWS\system32\drivers\adv07nt5.dll
2008-08-18 20:30 . 2008-04-13 17:11 3,615 ——— C:\WINDOWS\system32\drivers\adv05nt5.dll
2008-08-18 20:30 . 2008-04-13 17:11 3,135 ——— C:\WINDOWS\system32\drivers\adv08nt5.dll
2008-08-15 09:59 . 2008-08-15 09:59 d——– C:\Program Files\Sun
2008-08-14 19:04 . 2008-05-01 07:33 331,776 —–c— C:\WINDOWS\system32\dllcache\msadce.dll
2008-08-14 19:03 . 2008-04-11 12:04 691,712 —–c— C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-08-04 16:45 . 2008-08-22 23:27 d——– C:\Program Files\CamStudio
2008-08-01 23:45 . 2008-08-01 23:45 d——– C:\Nexon
2008-08-01 23:45 . 2008-08-01 23:49 d——– C:\Documents and Settings\All Users\Application Data\NexonUS
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-26 02:57 ——— d—–w C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\SiteAdvisor
2008-08-25 20:44 ——— d—–w C:\Program Files\Nero
2008-08-25 20:44 ——— d—–w C:\Program Files\Common Files\Nero
2008-08-25 20:44 ——— d—–w C:\Documents and Settings\All Users\Application Data\Nero
2008-08-25 18:19 ——— d—–w C:\Program Files\Google
2008-08-25 18:12 ——— d—–w C:\Program Files\soft
2008-08-25 07:16 737,280 -c–a-w C:\WINDOWS\iun6002.exe
2008-08-24 09:11 ——— d—–w C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\skypePM
2008-08-24 09:11 ——— d—–w C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\Skype
2008-08-24 09:07 ——— d—–w C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\uTorrent
2008-08-23 06:33 ——— d—–w C:\Program Files\Java
2008-08-20 21:36 ——— d—–w C:\Program Files\9Dragons
2008-08-12 21:05 ——— d—–w C:\Program Files\FlashGet
2008-07-19 05:10 94,920 —-a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 05:10 53,448 —-a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 05:10 45,768 —-a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 05:10 36,552 —-a-w C:\WINDOWS\system32\wups.dll
2008-07-19 05:09 563,912 —-a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 05:09 325,832 —-a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 05:09 205,000 —-a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 05:09 1,811,656 —-a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-19 05:07 270,880 —-a-w C:\WINDOWS\system32\mucltui.dll
2008-07-19 05:07 210,976 —-a-w C:\WINDOWS\system32\muweb.dll
2008-07-18 01:38 ——— d—–w C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\Nuotex
2008-07-07 20:26 253,952 —-a-w C:\WINDOWS\system32\es.dll
2008-07-01 19:25 ——— d—–w C:\Program Files\YahooFriend
2008-06-30 09:53 ——— d—–w C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\fltk.org
2008-06-28 10:29 ——— d—–w C:\Program Files\Advanced JPEG Compressor
2008-06-27 20:18 ——— d—–w C:\Program Files\Skype
2008-06-27 20:18 ——— d—–w C:\Program Files\Common Files\Skype
2008-06-27 20:18 ——— d—–w C:\Documents and Settings\All Users\Application Data\Skype
2008-06-24 16:43 74,240 —-a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 16:57 826,368 —-a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:46 245,248 —-a-w C:\WINDOWS\system32\mswsock.dll
2008-05-27 04:30 36,864 —-a-w C:\WINDOWS\system32\VisualTaskTips.exe
2007-06-17 21:24 0 -c–a-w C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\wklnhst.dat
2007-02-08 20:18 1,067,256 -c–a-w C:\Program Files\check.md
2006-12-21 23:31 21,526 -c–a-w C:\Program Files\CopyRight.txt
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E350B1C6-A8DC-4EEF-90DB-61DCAE9D1B67}]
2008-08-24 03:45 380928 –a—— C:\WINDOWS\rodqgpvlkoa.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{18C388BB-5014-4906-AE38-E62BA5AA7387}"= "C:\WINDOWS\qalkfxor.dll" [2008-08-24 03:45 155648]
[HKEY_CLASSES_ROOT\clsid\{18c388bb-5014-4906-ae38-e62ba5aa7387}]
[HKEY_CLASSES_ROOT\qalkfxor.1]
[HKEY_CLASSES_ROOT\TypeLib\{2E94E090-6554-4076-97A0-BC0EBE5CD9B2}]
[HKEY_CLASSES_ROOT\qalkfxor]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="C:\Program Files\RocketDock\RocketDock.exe" [2007-03-18 12:35 630784]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 17:12 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 20:56 64512]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-05 07:47 98394]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-05 07:47 688218]
"SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-05-23 19:22 573440]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-03-23 12:17 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-03-23 12:13 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-03-23 12:17 118784]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-28 11:55 667718]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-12-28 11:56 602182]
"MskAgentexe"="C:\Program Files\McAfee\MSK\MskAgent.exe" [2007-01-17 17:30 152144]
"VX3000"="C:\WINDOWS\vVX3000.exe" [2006-10-13 16:04 707376]
"LifeCam"="C:\Program Files\Microsoft LifeCam\LifeExp.exe" [2006-10-13 16:01 277296]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6261\SiteAdv.exe" [2007-01-17 12:24 36904]
"RocketDock"="C:\Program Files\RocketDock\RocketDock.exe" [2007-03-18 12:35 630784]
"AOL Spyware Protection"="C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" [2004-10-18 17:42 79448]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-03 22:33 582992]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2008-02-01 12:55 1103240]
"SigmatelSysTrayApp"="stsystra.exe" [2005-12-27 10:20 413696 C:\WINDOWS\stsystra.exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-07-22 23:25 28160 C:\WINDOWS\KHALMNPR.Exe]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"pdoskegl"= {D9889943-6B58-4631-A57D-7801CDADEF72} - C:\WINDOWS\pdoskegl.dll [2008-08-24 03:45 233472]
"rqbmvpso"= {ED710DA2-0DB9-4574-8DD7-6F8C516CB162} - C:\WINDOWS\rqbmvpso.dll [2008-08-24 03:45 188416]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="logonuiX.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtUnOEUm]
vtUnOEUm.dll [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.clmp3enc"= C:\PROGRA~1\CYBERL~1\Power2Go\CLMP3Enc.ACM
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\ff_vfw.dll
"vidc.wmv3"= C:\PROGRA~1\COMBIN~1\Filters\wmv9vcm.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\MSN Messenger\msnmsgr.exe [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"FlashGet"="C:\Program Files\FlashGet\FlashGet.exe" /min
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" -atboottime
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"podXP"=C:\Program Files\podXP\podXP.exe
"Anti-Blaxx Manager"=C:\Program Files\Anti-Blaxx\Anti-Blaxx.exe
"HostManager"=C:\Program Files\Common Files\AOL\1161306523\EE\AOLHostManager.exe
"SecurDisc"=C:\Program Files\Nero\Nero\Nero8\InCD\NBHGui.exe
"InCD"=C:\Program Files\Nero\Nero\Nero8\InCD\InCD.exe
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
"\VIE318.exe"=C:\Windows\System32\VIE318.exe
"\VIE319.exe"=C:\Windows\System32\VIE319.exe
"\VIE31A.exe"=C:\Windows\System32\VIE31A.exe
"\VIE31D.exe"=C:\Windows\System32\VIE31D.exe
"\SUE31E.exe"=C:\Windows\SUE31E.exe
"\VIE3.exe"=C:\Windows\System32\VIE3.exe
"\VIE4.exe"=C:\Windows\System32\VIE4.exe
"\VIE5.exe"=C:\Windows\System32\VIE5.exe
"\VIE6.exe"=C:\Windows\System32\VIE6.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"C:\\Program Files\\America Online 9.0\\waol.exe"=
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"C:\\Program Files\\Common Files\\AOL\\1161306523\\EE\\AOLServiceHost.exe"=
"C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\AOLSP Scheduler.exe"=
"C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\asp.exe"=
"C:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\SDP Multimedia\\SDP Downloader\\SDP.exe"=
"C:\\Program Files\\FlashGet\\flashget.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"C:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Sierra\\Half-life\\hl.exe"=
"C:\\Program Files\\Special Force\\specialforce.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R2 MSCamSvc;MSCamSvc;C:\Program Files\Microsoft LifeCam\MSCamS32.exe [2006-10-13 16:01]
R3 kbdcap;kbdcap;C:\WINDOWS\system32\drivers\kbdcap.sys [2007-06-09 15:46]
S3 DeepFree Update;DeepFree Update;C:\WINDOWS\system32\drivers\pcihdd2.sys []
S3 Revolution1;Revolution1;C:\Documents and Settings\Owner.MinhHoangNguyen\Desktop\Revolution_Engine_8.3_ShaK3\SHAK3.sys []
S3 tap0801;TAP-Win32 Adapter V8;C:\WINDOWS\system32\DRIVERS\tap0801.sys [2007-02-15 10:48]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d6f23399-3c73-11dc-8dca-806d6172696f}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ed5f27f3-3d2d-11dc-9703-806d6172696f}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f3b09c99-8c8a-11db-af2b-806d6172696f}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ff6d408b-76ba-11db-afa6-806d6172696f}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
.
Contents of the 'Scheduled Tasks' folder
2008-08-23 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 16:57]
2008-08-15 C:\WINDOWS\Tasks\McDefragTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
2008-08-01 C:\WINDOWS\Tasks\McQcTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
2008-08-25 C:\WINDOWS\Tasks\Norton Security Scan.job
- C:\Program Files\Norton Security Scan\Nss.exe [2007-09-18 23:42]
2008-08-26 C:\WINDOWS\Tasks\User_Feed_Synchronization-{6FE1F0EA-AD86-4209-A2CB-7B9242E62E24}.job
- C:\WINDOWS\system32\msfeedssync.exe [2006-10-17 11:58]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Vistadrv - C:\WINDOWS\system32\drive\vsdrv.exe
HKLM-Run-Zing Chat - (no file)
.
——- Supplementary Scan ——-
.
FireFox -: Profile - C:\Documents and Settings\Owner.MinhHoangNguyen\Application Data\Mozilla\Firefox\Profiles\mwru2jmp.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.com.vn/
FF -: plugin - C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF -: plugin - C:\PROGRA~1\Yahoo!\Common\npyaxmpb.dll
FF -: plugin - C:\Program Files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - C:\Program Files\DivX\DivX Content Uploader\npUpload.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npdrmv2.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npdsplay.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npitunes.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\NPMGWRAP.DLL
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npmozax.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npwmsdrm.dll
FF -: plugin - C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF -: plugin - C:\Program Files\Yahoo!\Shared\npYState.dll
FF -: plugin - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-08-26 05:33:32
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-08-26 5:35:04
ComboFix-quarantined-files.txt 2008-08-26 12:34:27
Pre-Run: 7,780,044,800 bytes free
Post-Run: 7,762,255,872 bytes free
333 — E O F — 2008-08-24 09:06:49
Hijackthis's log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 05:37: VIRUS ALERT!, on 8/26/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\SiteAdvisor\6261\SAService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\McAfee\MSK\MskAgent.exe
C:\Program Files\SiteAdvisor\6261\SiteAdv.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=…6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://127.0.0.1:4664/first_usage&s=Ty…fl1zpkUBc-UGu3g
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.509.6972\swg.dll
O2 - BHO: CPub Object - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - c:\program files\mcafee\mps\mcpopup.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll
O2 - BHO: QXK Olive - {E350B1C6-A8DC-4EEF-90DB-61DCAE9D1B67} - C:\WINDOWS\rodqgpvlkoa.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O3 - Toolbar: FlashGet - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\Program Files\FlashGet\fgiebar.dll
O3 - Toolbar: qalkfxor - {18C388BB-5014-4906-AE38-E62BA5AA7387} - C:\WINDOWS\qalkfxor.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [VX3000] C:\WINDOWS\vVX3000.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6261\SiteAdv.exe"
O4 - HKLM\..\Run: [RocketDock] C:\Program Files\RocketDock\RocketDock.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open using &Advanced JPEG Compressor - C:\Program Files\Advanced JPEG Compressor\ajcieex.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: vtUnOEUm - vtUnOEUm.dll (file missing)
O21 - SSODL: pdoskegl - {D9889943-6B58-4631-A57D-7801CDADEF72} - C:\WINDOWS\pdoskegl.dll
O21 - SSODL: rqbmvpso - {ED710DA2-0DB9-4574-8DD7-6F8C516CB162} - C:\WINDOWS\rqbmvpso.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6261\SAService.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O24 - Desktop Component 0: My Current Home Page - About:Home
–
End of file - 12352 bytes
Looking forward your reply and thank you so much for your help.
Leo