Let me know when you want to quit for the night , we can continue tomorrow , I will be at the computer all day .
Here are the logs :
ComboFix 08-11-04.02 - vp^ 2008-11-05 21:39:41.10 -
FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.402 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\vp^\Desktop\CFScript.txt
* Created a new restore point
FILE ::
c:\windows\system32\CF11848.exe.vir
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\CF11848.exe.vir
.
((((((((((((((((((((((((( Files Created from 2008-10-06 to 2008-11-06 )))))))))))))))))))))))))))))))
.
2008-11-05 09:07 . 2008-11-05 09:07 d——– c:\windows\LastGood
2008-11-05 08:48 . 2006-11-07 21:01 66,048 –a—— c:\windows\ieResetIcons.exe
2008-11-05 08:48 . 2008-11-05 08:48 230 –a—— c:\windows\system32\spupdsvc.inf
2008-11-01 15:38 . 2008-11-01 15:38 d——– c:\program files\ERUNT
2008-11-01 15:30 . 2008-11-01 15:30 d——– c:\program files\Trend Micro
2008-11-01 13:31 . 2008-11-03 01:30 1,374 –a—— c:\windows\imsins.BAK
2008-10-16 10:36 . 2008-10-31 18:53 54,156 –ah—– c:\windows\QTFont.qfn
2008-10-16 10:36 . 2008-10-16 10:36 1,409 –a—— c:\windows\QTFont.for
2008-10-11 19:35 . 2008-10-11 19:35 d——– c:\documents and settings\vp^\Application Data\Ulead Systems
2008-10-11 19:33 . 2008-10-11 19:33 d——– c:\program files\Ulead Systems
2008-10-11 19:33 . 2008-10-11 19:33 d——– c:\documents and settings\All Users\Application Data\Ulead Systems
2008-10-11 19:32 . 2008-10-11 19:32 d——– c:\windows\Noslip
2008-10-11 19:29 . 2008-10-11 19:29 11,014,144 –a—— c:\program files\UGA5TBYB_E_USG.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-02 01:49 5,527 —-a-w c:\program files\hijackthis11-1.log
2008-11-02 01:48 5,527 —-a-w c:\program files\hijackthis.log
2008-10-30 02:54 27,991 —-a-w c:\program files\
081029_2140.caf.txt
2008-10-15 17:57 332,800 —-a-w c:\windows\system32\dllcache\netapi32.dll
2008-10-03 18:41 6,066,176 ——w c:\windows\system32\dllcache\ieframe.dll
2008-09-15 12:57 1,846,016 —-a-w c:\windows\system32\win32k.sys
2008-09-15 12:57 1,846,016 —-a-w c:\windows\system32\dllcache\win32k.sys
2008-08-29 20:58 3,297,268 —-a-w c:\windows\system32\via_chipset_AC_97_sound_driver.ZIP
2008-08-28 11:04 333,056 —-a-w c:\windows\system32\dllcache\srv.sys
2008-08-26 08:24 63,488 ——w c:\windows\system32\dllcache\icardie.dll
2008-08-26 08:24 52,224 ——w c:\windows\system32\dllcache\msfeedsbs.dll
2008-08-26 08:24 459,264 ——w c:\windows\system32\dllcache\msfeeds.dll
2008-08-26 08:24 383,488 ——w c:\windows\system32\dllcache\ieapfltr.dll
2008-08-26 08:24 267,776 ——w c:\windows\system32\dllcache\iertutil.dll
2008-08-25 09:38 13,824 ——w c:\windows\system32\dllcache\ieudinit.exe
2008-08-14 11:00 2,180,352 —-a-w c:\windows\system32\ntoskrnl.exe
2008-08-14 11:00 2,180,352 —-a-w c:\windows\system32\dllcache\ntoskrnl.exe
2008-08-14 10:58 2,136,064 —-a-w c:\windows\system32\dllcache\ntkrnlmp.exe
2008-08-14 10:51 138,368 —-a-w c:\windows\system32\dllcache\afd.sys
2008-08-14 10:22 2,057,728 —-a-w c:\windows\system32\ntkrnlpa.exe
2008-08-14 10:22 2,057,728 —-a-w c:\windows\system32\dllcache\ntkrnlpa.exe
2008-08-14 10:22 2,015,744 —-a-w c:\windows\system32\dllcache\ntkrpamp.exe
2008-06-23 03:32 2,703 —-a-w c:\program files\
080622_2214.caf
2008-06-22 04:25 21,853 —-a-w c:\program files\
080621_2313.caf
2008-06-21 14:58 2,370 —-a-w c:\program files\
080621_0947.caf
2008-06-19 10:12 6,922 —-a-w c:\program files\
080618_2322.caf
2008-06-18 14:59 4,128 —-a-w c:\program files\
080618_0941.caf
2008-06-16 02:49 6,988 —-a-w c:\program files\
080615_2136.caf
2008-06-14 16:50 63,189 —-a-w c:\program files\
080614_1134.caf
2008-06-14 13:52 11,984 —-a-w c:\program files\
080614_0838.caf
2008-06-13 05:04 12,918 —-a-w c:\program files\
080612_2324.caf
2008-06-12 14:28 9,446 —-a-w c:\program files\
080612_0906.caf
2008-06-12 03:20 2,451 —-a-w c:\program files\
080611_2159.caf
2008-06-11 21:03 4,137 —-a-w c:\program files\
080611_1502.caf
2008-06-10 18:05 146,371 —-a-w c:\program files\
080610_1246.caf
2008-06-10 02:01 246,692 —-a-w c:\program files\
080609_2041.caf
2008-06-08 22:37 83,908 —-a-w c:\program files\
080608_1718.caf
2008-06-08 21:38 14,359 —-a-w c:\program files\
080608_1618.caf
2008-06-08 16:00 16,728 —-a-w c:\program files\
080608_1032.caf
2008-06-07 10:49 58,616 —-a-w c:\program files\
080603_1143.caf
2008-06-05 03:02 2,762 —-a-w c:\program files\
080604_2136.caf
2008-06-01 03:54 38,227 —-a-w c:\program files\
080531_2238.caf
2008-05-31 18:49 4,420 —-a-w c:\program files\
080531_1135.caf
2008-05-29 17:55 9,909 —-a-w c:\program files\
080529_1238.caf
2008-05-29 01:43 50,096 —-a-w c:\program files\
080528_2027.caf
2008-05-27 03:10 18,081 —-a-w c:\program files\
080526_2159.caf
2008-05-26 21:58 6,012 —-a-w c:\program files\
080523_2230.caf
2008-05-25 14:29 2,542 —-a-w c:\program files\
080525_0908.caf
2008-05-24 18:18 28,705 —-a-w c:\program files\
080524_0704.caf
2008-05-23 00:28 1,466 —-a-w c:\program files\
080522_0027.caf
2008-05-21 23:50 1,621 —-a-w c:\program files\
080521_1839.caf
2008-05-20 02:47 7,332 —-a-w c:\program files\
080519_2120.caf
2008-05-18 00:08 7,055 —-a-w c:\program files\
080517_1849.caf
2008-05-17 00:46 5,301 —-a-w c:\program files\
080516_1931.caf
2008-05-16 19:56 8,950 —-a-w c:\program files\
080516_1444.caf
2008-05-16 04:06 15,902 —-a-w c:\program files\
080515_2246.caf
2008-05-15 13:44 18,879 —-a-w c:\program files\
080515_0821.caf
2008-05-15 04:31 109,935 —-a-w c:\program files\
080514_2312.caf
2008-05-15 03:23 1,506 —-a-w c:\program files\
080514_2206.caf
2008-05-14 19:17 1,908 —-a-w c:\program files\
080514_1403.caf
2008-05-12 23:05 84,946 —-a-w c:\program files\
080512_1732.caf
2008-05-11 05:52 4,402 —-a-w c:\program files\
080511_0040.caf
2008-05-10 05:17 100,894 —-a-w c:\program files\
080509_2357.caf
2008-05-10 02:07 26,592 —-a-w c:\program files\
080509_14061.caf
2008-05-08 03:15 53,533 —-a-w c:\program files\
080507_2155.caf
2008-05-06 14:33 65,496 —-a-w c:\program files\
080506_0910.caf
2008-05-05 19:27 2,059 —-a-w c:\program files\
080505_1409.caf
2008-05-04 13:06 9,118 —-a-w c:\program files\
080504_0747.caf
2008-05-03 00:21 991 —-a-w c:\program files\
080502_1852.caf
2008-05-02 13:33 515 —-a-w c:\program files\
080502_0811.caf
2008-05-01 18:42 1,703 —-a-w c:\program files\
080501_1328.caf
2008-05-01 15:03 93,623 —-a-w c:\program files\
080430_2221.caf
2008-04-29 19:57 1,062 —-a-w c:\program files\
080429_1340.caf
2008-04-29 19:32 4,710 —-a-w c:\program files\
080428_0914.caf
2008-04-29 05:12 41,995 —-a-w c:\program files\
080428_2355.caf
2008-04-27 17:29 2,741 —-a-w c:\program files\
080427_1214.caf
2008-04-27 17:06 3,113 —-a-w c:\program files\My-Disc32.caf
2008-04-27 17:01 3,117 —-a-w c:\program files\
080427_0729.caf
2008-04-26 20:58 960 —-a-w c:\program files\
080426_1528.caf
2008-04-26 14:27 359 —-a-w c:\program files\
080426_0910.caf
2008-04-25 22:28 1,177 —-a-w c:\program files\
080425_1712.caf
2008-04-25 14:18 3,834 —-a-w c:\program files\
080425_0855.caf
2008-04-24 21:36 5,702 —-a-w c:\program files\
080424_1614.caf
2008-04-24 16:29 2,080 —-a-w c:\program files\
080424_1114.caf
2008-04-22 16:34 83,652 —-a-w c:\program files\
080422_1115.caf
2008-04-22 12:42 1,631 —-a-w c:\program files\
080422_0720.caf
2008-04-20 20:12 16,869 —-a-w c:\program files\
080420_1500.caf
2008-04-19 17:45 53,404 —-a-w c:\program files\
080419_1234.caf
2008-04-19 15:05 60,632 —-a-w c:\program files\
080418_2136.caf
2008-04-17 20:17 2,854 —-a-w c:\program files\
080417_1503.caf
2008-04-16 21:08 5,840 —-a-w c:\program files\
080416_1551.caf
2008-04-16 16:38 7,058 —-a-w c:\program files\
080415_0809.caf
2008-04-13 04:37 115,642 —-a-w c:\program files\
080412_2313.caf
2008-04-12 23:52 2,704 —-a-w c:\program files\
080412_1728.caf
2008-04-11 21:09 14,853 —-a-w c:\program files\
080411_1543.caf
2008-04-11 18:59 3,318 —-a-w c:\program files\
080411_1326.caf
2008-04-11 13:35 3,022 —-a-w c:\program files\
080410_0842.caf
2008-04-10 02:36 3,400 —-a-w c:\program files\
080409_2121.caf
2008-04-08 13:28 1,056 —-a-w c:\program files\
080408_0812.caf
2008-04-07 05:10 1,349 —-a-w c:\program files\
080406_2358.caf
.
((((((((((((((((((((((((((((( snapshot@2008-11-05_12.41.57.64 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-11-06 00:12:46 16,384 —-a-w c:\windows\Temp\Perflib_Perfdata_144.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"eRecoveryService"="c:\program files\Acer\eRecovery\Monitor.exe" [2005-06-20 352256]
"!AVG Anti-Spyware"="c:\program files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 6731312]
"cctray"="c:\program files\CA\CA Internet Security Suite\cctray\cctray.exe" [2007-09-28 177416]
"CAVRID"="c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2007-04-30 230928]
"SoundMan"="SOUNDMAN.EXE" [2005-06-08 c:\windows\SOUNDMAN.EXE]
"VTTimer"="VTTimer.exe" [2005-05-13 c:\windows\system32\VTTimer.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.avis"= ff_acm.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Easy Video Joiner Help.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Easy Video Joiner Help.lnk
backup=c:\windows\pss\Easy Video Joiner Help.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Easy Video Joiner on the Web.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Easy Video Joiner on the Web.lnk
backup=c:\windows\pss\Easy Video Joiner on the Web.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Easy Video Joiner.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Easy Video Joiner.lnk
backup=c:\windows\pss\Easy Video Joiner.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Uninstall Easy Video Joiner.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Uninstall Easy Video Joiner.lnk
backup=c:\windows\pss\Uninstall Easy Video Joiner.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Verizon Online Help & Support.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Verizon Online Help & Support.lnk
backup=c:\windows\pss\Verizon Online Help & Support.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Verizon Support Service.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Verizon Support Service.lnk
backup=c:\windows\pss\Verizon Support Service.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^vp^^Start Menu^Programs^Startup^Kremlin Sentry.lnk]
path=c:\documents and settings\vp^\Start Menu\Programs\Startup\Kremlin Sentry.lnk
backup=c:\windows\pss\Kremlin Sentry.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AspireService]
–a—— 2005-06-04 12:40 110592 c:\program files\acer\Acer eMode Management\AspireService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus CX3800 Series]
–a—— 2005-02-07 15:00 98304 c:\windows\system32\spool\drivers\w32x86\3\E_FATIACA.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MediaSync]
–a—— 2005-06-01 14:25 421888 c:\program files\acer\Acer eConsole\MediaSync.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
——— 2004-10-13 09:24 1694208 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
——— 2005-09-16 16:41 1961984 c:\program files\Ahead\Nero BackItUp\NBJ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
–a—— 2004-07-15 01:07 32768 c:\program files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Free Download Manager\\fdmwi.exe"=
"c:\\Program Files\\Westell\\Diagnostic Icon\\DGNIcon.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
R2 int15.sys;int15.sys;c:\program files\acer\eRecovery\int15.sys [2005-01-13 69632]
.
Contents of the 'Scheduled Tasks' folder
2008-11-05 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-05 21:46:14
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-11-05 21:48:44
ComboFix-quarantined-files.txt 2008-11-06 02:48:28
ComboFix2.txt 2008-11-05 17:44:08
Pre-Run: 3,810,099,200 bytes free
Post-Run: 3,796,828,160 bytes free
221 — E O F — 2008-11-05 14:10:48
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:49, on 2008-11-05
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\acer\Acer eConsole\MediaServerService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\Program Files\Acer\eRecovery\Monitor.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://cgi.verizon.net/bookmarks/bmredir.a…p;bm=bz_welcome
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O4 - HKLM\..\Run: [eRecoveryService] C:\Program Files\Acer\eRecovery\Monitor.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: vzTCPConfig -
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/…b?1158766737609
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdat…b?1163900908375
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) -
http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} -
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Acer Media Server - Acer Inc. - C:\Program Files\acer\Acer eConsole\MediaServerService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
–
End of file - 6102 bytes