Here are the 3 test results
ComboFix 08-09-15.02 - Administrator 2008-09-16 22:01:20.1 - NTFSx86 MINIMAL
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.830 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\edvk.exe
.
((((((((((((((((((((((((( Files Created from 2008-08-17 to 2008-09-17 )))))))))))))))))))))))))))))))
.
2008-09-16 21:17 . 2008-09-16 21:17 d——– C:\Program Files\Trend Micro
2008-09-16 18:47 . 2008-09-16 19:40 5,236 –a—— C:\WINDOWS\system32\tmp.reg
2008-09-16 17:41 . 2008-09-16 17:41 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-09-16 17:41 . 2008-09-16 17:41 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-16 17:41 . 2008-09-16 17:41 d——– C:\Documents and Settings\Administrator.HOMEOFFICE\Application Data\Malwarebytes
2008-09-16 17:41 . 2008-09-08 00:11 38,528 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-16 17:41 . 2008-09-08 00:11 17,200 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-09-16 17:19 . 2008-09-16 18:43 d——– C:\Documents and Settings\Administrator.HOMEOFFICE
2008-09-16 17:07 . 2008-09-16 17:07 136,832 –a—— C:\WINDOWS\system32\suwhiycj.dll
2008-09-16 16:27 . 2008-09-16 17:01 d—s—- C:\Documents and Settings\Administrator
2008-09-16 14:45 . 2008-09-16 17:01 d——– C:\Program Files\Spyware Doctor
2008-09-16 14:32 . 2008-09-16 17:01 d——– C:\WINDOWS\privacy_danger(2)
2008-09-10 12:35 . 2008-09-10 12:35 9,662 –a—— C:\WINDOWS\EPISME00.SWB
2008-09-09 11:03 . 2008-09-09 11:03 d——– C:\CWONDERS
2008-09-09 11:03 . 1994-09-21 00:00 92,208 –a—— C:\WINDOWS\system\WING.DLL
2008-09-09 11:03 . 1994-09-21 00:00 12,800 –a—— C:\WINDOWS\system\WING32.DLL
2008-09-08 21:06 . 2008-09-08 21:13 d——– C:\Program Files\Celestia
2008-09-08 20:59 . 2008-09-08 21:00 d——– C:\Program Files\Stellarium
2008-08-28 11:11 . 2008-08-28 11:11 29 –a—— C:\WINDOWS\DEBUGSM.INI
2008-08-28 11:08 . 2008-08-28 11:08 d——– C:\Program Files\ABBYY FineReader 5.0 Sprint
2008-08-28 11:07 . 2008-08-28 11:07 d——– C:\Program Files\Common Files\Python
2008-08-28 11:07 . 2001-10-19 12:18 708,696 –a—— C:\WINDOWS\system32\python21.dll
2008-08-28 11:07 . 2001-10-19 12:18 290,919 –a—— C:\WINDOWS\system32\pythoncom21.dll
2008-08-28 11:07 . 2001-10-19 12:19 57,344 –a—— C:\WINDOWS\system32\PyWinTypes21.dll
2008-08-28 11:05 . 1999-06-15 11:31 96,768 –a—— C:\WINDOWS\SlantAdj.dll
2008-08-28 11:05 . 1999-12-07 02:03 73,216 –a—— C:\WINDOWS\ADE.DLL
2008-08-28 11:05 . 1999-04-27 00:17 3,136 –a—— C:\WINDOWS\Ade001.bin
2008-08-28 11:05 . 2000-09-08 13:31 72 ——— C:\WINDOWS\system32\epDPE.ini
2008-08-28 11:04 . 2008-08-28 11:07 d——– C:\Program Files\Smart Panel
2008-08-28 11:02 . 2008-08-28 11:08 d——– C:\Program Files\EPSON
2008-08-28 11:02 . 2003-04-02 00:00 217,088 –a—— C:\WINDOWS\system32\ESDTR.dll
2008-08-28 11:02 . 2003-05-28 19:01 91,648 –a—— C:\WINDOWS\system32\E_SAGSET.DLL
2008-08-28 11:02 . 2003-05-22 19:06 73,869 –a—— C:\WINDOWS\system32\EBPMON24.DLL
2008-08-28 11:02 . 2003-05-20 20:27 64,000 –a—— C:\WINDOWS\system32\ECBTEG.DLL
2008-08-28 11:02 . 2001-11-15 00:00 47,104 –a—— C:\WINDOWS\system32\escimgd.dll
2008-08-28 11:02 . 2000-06-06 19:01 34,304 –a—— C:\WINDOWS\system32\EBPCHP.DLL
2008-08-28 11:02 . 2002-06-20 00:00 32,256 –a—— C:\WINDOWS\system32\escwiad.dll
2008-08-28 11:02 . 2002-06-20 00:00 22,528 –a—— C:\WINDOWS\system32\esccmd.dll
2008-08-28 11:02 . 2008-08-28 11:03 19,308 –a—— C:\WINDOWS\EPSTPLOG.BAK
2008-08-28 11:02 . 2001-09-03 20:04 182 –a—— C:\WINDOWS\system32\EBPPORT4.DAT
2008-08-28 11:01 . 2008-08-28 11:02 162 –a—— C:\WINDOWS\EPSON Stylus CX5400.ini
2008-08-27 20:55 . 2008-08-27 20:55 d——– C:\TimezAttack
2008-08-27 19:46 . 2008-08-27 19:46 d——– C:\WINDOWS\system32\scripting
2008-08-27 19:46 . 2008-08-27 19:46 d——– C:\WINDOWS\system32\en
2008-08-27 19:46 . 2008-08-27 19:46 d——– C:\WINDOWS\system32\bits
2008-08-27 19:46 . 2008-08-27 19:46 d——– C:\WINDOWS\l2schemas
2008-08-27 19:43 . 2008-08-27 19:43 d——– C:\WINDOWS\ServicePackFiles
2008-08-27 19:36 . 2008-08-27 19:36 d——– C:\WINDOWS\EHome
2008-08-27 12:34 . 2008-09-11 13:46 d——– C:\tlcwin
2008-08-27 12:34 . 1994-08-23 22:00 188,960 ——— C:\WINDOWS\system32\Wingde.dll
2008-08-27 12:34 . 1994-09-20 22:00 92,208 ——— C:\WINDOWS\system32\Wing.dll
2008-08-27 12:34 . 1994-09-20 22:00 12,800 ——— C:\WINDOWS\system32\Wing32.dll
2008-08-27 12:34 . 1994-09-20 22:00 6,736 ——— C:\WINDOWS\system32\Wingdib.drv
2008-08-27 12:34 . 1994-09-20 22:00 5,024 ——— C:\WINDOWS\system32\Wingpal.wnd
2008-08-27 12:34 . 2008-09-11 13:47 237 –a—— C:\WINDOWS\TLCAPPS.INI
2008-08-27 12:34 . 2008-08-27 12:41 105 –a—— C:\WINDOWS\E-REGTLC.INI
2008-08-26 08:56 . 2008-04-13 18:11 1,888,992 ——— C:\WINDOWS\system32\ati3duag.dll
2008-08-25 16:20 . 2008-08-25 16:20 d——– C:\Program Files\Transparent
2008-08-25 16:20 . 2008-08-25 16:20 d——– C:\Documents and Settings\All Users\Application Data\Transparent
2008-08-25 09:26 . 2008-08-25 09:26 d——– C:\Program Files\Seterra
2008-08-24 18:57 . 2008-08-24 18:57 280 –a—— C:\WINDOWS\EReg196.dat
2008-08-24 18:56 . 2008-08-24 18:56 d——– C:\Program Files\TLI
2008-08-24 15:02 . 2008-08-24 15:02 d——– C:\Program Files\Quickstart Immersion
2008-08-21 14:25 . 2008-08-21 14:25 d——– C:\Program Files\directx
2008-08-21 14:25 . 2008-08-21 14:25 0 –a—— C:\WINDOWS\PowerReg.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-13 21:54 ——— d—–w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-08-28 17:07 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-08-25 00:54 ——— d—–w C:\Program Files\Quicken
2008-08-25 00:54 ——— d—–w C:\Program Files\Common Files\Intuit
2008-08-25 00:42 ——— d—–w C:\Program Files\ComcastToolbar
2008-08-20 02:20 ——— d—–w C:\Program Files\Java
2008-08-15 21:41 ——— d—–w C:\Documents and Settings\All Users\Application Data\Comcast
2008-08-11 14:41 ——— d—–w C:\Program Files\Google
2008-08-05 22:16 ——— d—–w C:\Documents and Settings\All Users\Application Data\McAfee
2008-08-05 22:14 ——— d—–w C:\Program Files\Common Files\McAfee
2008-08-05 22:13 ——— d—–w C:\Program Files\McAfee.com
2008-08-05 18:30 ——— d—–w C:\Program Files\Common Files\Scanner
2008-08-05 16:51 ——— d—–w C:\Program Files\Comcast
2008-08-05 16:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\SupportSoft
2008-08-05 16:41 ——— d—–w C:\Program Files\Support.com
2006-06-07 17:00 56 –sh–r C:\WINDOWS\system32\C627C717F1.sys
2007-12-01 01:53 88 –sh–r C:\WINDOWS\system32\F117C727C6.sys
2007-12-01 01:53 4,184 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-04 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-14 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-14 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-10-14 114688]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2006-04-18 26112]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 282624]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe" [2005-09-08 8192]
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2005-09-08 110592]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 172032]
"OpwareSE2"="C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 49152]
"WireLessKeyboard"="C:\Program Files\Visikey Hotkey Manager\PS2USBKbdDrv.exe" [2005-10-23 729088]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"DNS7reminder"="C:\Program Files\Nuance\NaturallySpeaking9\Ereg\Ereg.exe" [2006-11-27 255528]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"ddoctorv2"="C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2008-04-24 202560]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"EPSON Stylus CX5400"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE" [2003-05-26 99840]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 C:\WINDOWS\stsystra.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-04-18 24576]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-12-31 67128]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\
0]
Source= file:///C:\WINDOWS\privacy_danger\index.htm
FriendlyName= Privacy Protection
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=txqcxa.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\NetMeeting\\conf.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
R3 PowerManagerFilter;PowerManagerFilter;C:\WINDOWS\system32\Drivers\PowerManager.sys [2005-10-23 60607]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3437dbb0-7f9a-11dd-9604-001372c4f08f}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a6bef156-2cbf-11db-91b1-001372c4f08f}]
\Shell\AutoRun\command - E:\Installer.exe
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-MSKDetectorExe - C:\Program Files\McAfee\SpamKiller\MSKDetct.exe
HKLM-Run-tgcmd - C:\Program Files\Support.com\bin\tgcmd.exe
.
——- Supplementary Scan ——-
.
R0 -: HKCU-Main,Start Page = hxxp://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2
R0 -: HKLM-Main,Window Title = Windows Internet Explorer provided by Comcast
R1 -: HKCU-Internet Connection Wizard,ShellNext = iexplore
O18 -: Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-09-16 22:05:45
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\PROGRA~1\COMMON~1\McAfee\MNA\McNASvc.exe
C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\ComboFix\pv.cfexe
.
**************************************************************************
.
Completion time: 2008-09-16 22:11:54 - machine was rebooted [Rolf Magnusson]
ComboFix-quarantined-files.txt 2008-09-17 04:11:51
Pre-Run: 136,013,119,488 bytes free
Post-Run: 134,518,530,048 bytes free
203 — E O F — 2008-09-09 21:31:31
——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Wednesday, September 17, 2008
Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Wednesday, September 17, 2008 19:12:25
Records in database: 1246182
——————————————————————————–
Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes
Scan area - My Computer:
C:\
D:\
E:\
Scan statistics:
Files scanned: 80960
Threat name: 2
Infected objects: 5
Suspicious objects: 0
Duration of the scan: 01:19:01
File name / Threat name / Threats count
C:\Documents and Settings\Administrator.HOMEOFFICE\Desktop\Fix backups\SmitfraudFix\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f 1
C:\Documents and Settings\Administrator.HOMEOFFICE\Desktop\Fix backups\SmitfraudFix.zip Infected: not-a-virus:RiskTool.Win32.Reboot.f 1
C:\Program Files\MUSICMATCH\Common\ComponentMgr\HoldingArea\WebSys2\WebSys.mmz Infected: not-a-virus:RiskTool.Win32.Deleter.f 1
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\WebSys\offline.mmz Infected: not-a-virus:RiskTool.Win32.Deleter.f 1
E:\SmitfraudFix.zip Infected: not-a-virus:RiskTool.Win32.Reboot.f 1
The selected area was scanned.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:47, on 2008-09-17
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\Program Files\Visikey Hotkey Manager\PS2USBKbdDrv.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=…6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.509.6972\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [WireLessKeyboard] C:\Program Files\Visikey Hotkey Manager\PS2USBKbdDrv.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [DNS7reminder] "C:\Program Files\Nuance\NaturallySpeaking9\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\Nuance\NaturallySpeaking9\Ereg.ini
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [EPSON Stylus CX5400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE /P19 "EPSON Stylus CX5400" /O6 "USB002" /M "Stylus CX5400"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {230C3D02-DA27-11D2-8612-00A0C93EEA3C} (SAXFile FileUpload ActiveX Control) -
http://www.winkflash.com/photo/loaders/SAXFile.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/microsoftu…b?1218425010500
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.0 Control) -
http://www.winkflash.com/photo/loaders/ImageUploader3.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) -
http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.1.2.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: McAfee Services (mcmscsvc) - Unknown owner - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe (file missing)
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe (file missing)
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - Unknown owner - C:\Program Files\McAfee\VirusScan\McShield.exe (file missing)
O23 - Service: McAfee SystemGuards (McSysmon) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe (file missing)
O23 - Service: McAfee Personal Firewall Service (MpfService) - Unknown owner - C:\Program Files\McAfee\MPF\MPFSrv.exe (file missing)
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
–
End of file - 8859 bytes