COMBOFIX LOG
ComboFix 08-11-04.02 - Apurva 2008-11-05 20:52:25.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.546 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-10-06 to 2008-11-06 )))))))))))))))))))))))))))))))
.
2008-11-05 12:38 . 2008-11-05 12:38 d——– c:\program files\Trend Micro
2008-11-04 15:42 . 2008-11-04 17:34 d——– c:\program files\Malwarebytes' Anti-Malware
2008-11-04 15:42 . 2008-11-04 15:42 d——– c:\documents and settings\Apurva\Application Data\Malwarebytes
2008-11-04 15:42 . 2008-11-04 15:42 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-04 15:42 . 2008-10-22 16:10 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-04 15:42 . 2008-10-22 16:10 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-11-01 22:10 . 2008-11-01 22:10 d——– c:\windows\system32\IOSUBSYS
2008-11-01 13:16 . 2008-11-01 13:16 d——– c:\documents and settings\All Users\Application Data\Hewlett-Packard
2008-11-01 13:13 . 2008-11-01 13:13 d——– C:\spoolerlogs
2008-10-30 21:52 . 2008-10-30 21:52 d——– c:\windows\Sun
2008-10-30 21:48 . 2008-10-30 21:48 d——– c:\program files\Java
2008-10-30 21:48 . 2008-10-30 21:48 410,976 –a—— c:\windows\system32\deploytk.dll
2008-10-30 21:48 . 2008-10-30 21:48 73,728 –a—— c:\windows\system32\javacpl.cpl
2008-10-28 11:50 . 2008-10-28 11:50 69,632 –a—— c:\windows\system32\TIFmtA.dll
2008-10-28 11:50 . 2008-10-28 11:50 61,440 –a—— c:\windows\system32\TrackID.DLL
2008-10-28 11:50 . 2008-10-28 11:50 59,904 –a—— c:\windows\system32\RIC644X.EXE
2008-10-28 11:50 . 2008-10-28 11:50 49,152 –a—— c:\windows\system32\TIBase64.dll
2008-10-28 11:10 . 2008-10-28 11:11 d——– c:\program files\Common Files\Adobe
2008-10-25 22:49 . 2008-10-25 22:49 d——– c:\windows\system32\E177E04D548C4006A465EEB92D3DE021
2008-10-25 22:49 . 2008-10-25 22:49 d——– c:\documents and settings\All Users\Application Data\InstallShield
2008-10-25 22:49 . 2008-10-25 22:49 64 –a—— c:\windows\minitab.ini
2008-10-25 22:48 . 2008-10-25 22:50 d——– c:\program files\Minitab 15
2008-10-23 19:18 . 2008-10-23 19:18 2,302,017 –a—— c:\windows\system32\GPhotos.scr
2008-10-23 17:16 . 2004-08-03 22:08 26,496 –a–c— c:\windows\system32\dllcache\usbstor.sys
2008-10-23 09:05 . 2008-10-23 09:05 d——– c:\program files\MSXML 4.0
2008-10-22 21:05 . 2008-10-22 21:05 d–h—– C:\$AVG8.VAULT$
2008-10-22 15:18 . 2008-10-22 15:18 d——– c:\documents and settings\Apurva\Application Data\vlc
2008-10-22 14:35 . 2008-11-01 22:23 69 –a—— c:\windows\NeroDigital.ini
2008-10-22 06:17 . 2008-11-05 17:36 d——– c:\windows\system32\drivers\Avg
2008-10-22 06:17 . 2008-10-22 06:17 97,928 –a—— c:\windows\system32\drivers\avgldx86.sys
2008-10-22 06:17 . 2008-10-22 06:17 76,040 –a—— c:\windows\system32\drivers\avgtdix.sys
2008-10-22 06:17 . 2008-10-22 06:17 10,520 –a—— c:\windows\system32\avgrsstx.dll
2008-10-22 00:01 . 2008-10-22 00:01 376 –a—— c:\windows\ODBC.INI
2008-10-22 00:00 . 2007-04-09 12:23 28,040 –a—— c:\windows\system32\mdimon.dll
2008-10-21 23:59 . 2008-10-21 23:59 d——– c:\program files\Microsoft ActiveSync
2008-10-21 23:58 . 2008-10-21 23:59 d——– c:\windows\SHELLNEW
2008-10-21 23:58 . 2008-10-21 23:58 d——– c:\program files\Microsoft.NET
2008-10-21 23:56 . 2008-10-22 06:17 d——– c:\documents and settings\All Users\Application Data\Avg8
2008-10-21 23:52 . 2008-10-21 23:52 dr-h—– C:\MSOCache
2008-10-21 23:33 . 2008-10-22 00:31 d——– c:\windows\system32\CatRoot_bak
2008-10-21 23:31 . 2008-10-21 23:32 d——– c:\documents and settings\Apurva\Application Data\Ahead
2008-10-21 23:31 . 2008-08-14 05:00 2,180,352 —–c— c:\windows\system32\dllcache\ntoskrnl.exe
2008-10-21 23:31 . 2008-08-14 04:58 2,136,064 —–c— c:\windows\system32\dllcache\ntkrnlmp.exe
2008-10-21 23:31 . 2008-08-14 04:22 2,057,728 —–c— c:\windows\system32\dllcache\ntkrnlpa.exe
2008-10-21 23:31 . 2008-08-14 04:22 2,015,744 —–c— c:\windows\system32\dllcache\ntkrpamp.exe
2008-10-21 23:29 . 2008-10-21 23:29 d——– c:\program files\Nero
2008-10-21 23:29 . 2008-10-21 23:30 d——– c:\program files\Common Files\Ahead
2008-10-21 23:29 . 2008-10-21 23:29 d——– c:\documents and settings\All Users\Application Data\Nero
2008-10-21 23:25 . 2008-10-21 23:25 d——– c:\program files\Launchy
2008-10-21 23:25 . 2008-11-05 20:51 d——– c:\documents and settings\Apurva\Application Data\Launchy
2008-10-21 23:24 . 2008-10-25 22:48 d——– c:\windows\Downloaded Installations
2008-10-21 23:24 . 2008-10-21 23:24 d——– c:\program files\D-Tools
2008-10-21 23:24 . 2003-12-27 19:42 137,216 –a—— c:\windows\system32\drivers\d344bus.sys
2008-10-21 23:24 . 2003-12-27 01:38 5,248 –a—— c:\windows\system32\drivers\d344prt.sys
2008-10-21 23:23 . 2008-10-21 23:23 d——– c:\program files\MSECache
2008-10-21 23:21 . 2008-06-13 08:10 272,128 ——— c:\windows\system32\drivers\bthport.sys
2008-10-21 23:21 . 2008-06-13 08:10 272,128 —–c— c:\windows\system32\dllcache\bthport.sys
2008-10-21 23:18 . 2008-10-21 23:20 d——– c:\program files\Winamp
2008-10-21 23:18 . 2008-10-31 23:56 d——– c:\documents and settings\Apurva\Application Data\Winamp
2008-10-21 23:18 . 2007-03-07 18:51 129,784 ——— c:\windows\system32\pxafs.dll
2008-10-21 23:18 . 2007-03-07 18:51 9,464 ——— c:\windows\system32\drivers\cdralw2k.sys
2008-10-21 23:18 . 2007-03-07 18:51 9,336 ——— c:\windows\system32\drivers\cdr4_xp.sys
2008-10-21 23:17 . 2008-10-21 23:17 d——– c:\program files\VideoLAN
2008-10-21 23:14 . 2008-10-21 23:14 d——– c:\program files\AVG
2008-10-21 23:11 . 2008-11-05 19:45 d-a—— c:\documents and settings\All Users\Application Data\TEMP
2008-10-21 23:10 . 2008-10-21 23:12 d——– c:\program files\DAP
2008-10-21 23:10 . 2008-10-21 23:10 d——– c:\documents and settings\All Users\Application Data\SpeedBit
2008-10-21 23:10 . 2008-10-21 23:10 479,298 –a—— c:\windows\system32\wbocx.ocx
2008-10-21 23:10 . 2008-10-21 23:10 172,032 –a—— c:\windows\system32\AniGIF.ocx
2008-10-21 23:10 . 2008-10-21 23:10 50,688 –a—— c:\windows\system32\wbhelp2.dll
2008-10-21 23:09 . 2008-10-21 23:09 d——– c:\program files\uTorrent
2008-10-21 23:09 . 2008-10-24 10:19 d——– c:\documents and settings\Apurva\Application Data\uTorrent
2008-10-21 23:08 . 2008-10-22 20:53 d——– c:\windows\Internet Logs
2008-10-21 23:08 . 2007-01-31 12:45 127,376 –a—— c:\windows\system32\drivers\dne2000.sys
2008-10-21 23:08 . 2007-01-31 12:45 101,904 –a—— c:\windows\system32\dneinobj.dll
2008-10-21 23:07 . 2008-10-21 23:07 d——– c:\program files\Common Files\Deterministic Networks
2008-10-21 23:07 . 2008-10-21 23:07 d——– c:\program files\Cisco Systems
2008-10-21 23:07 . 2008-10-21 23:08 1,595 –a—— c:\windows\VPNInstall.MIF
2008-10-21 23:06 . 2008-11-01 22:10 d——– c:\program files\Google
2008-10-21 22:59 . 2008-10-21 22:59 0 –a—— c:\windows\nsreg.dat
2008-10-21 22:58 . 2008-10-24 02:00 d–h—– c:\windows\$hf_mig$
2008-10-21 22:58 . 2006-09-06 15:43 22,752 –a—— c:\windows\system32\spupdsvc.exe
2008-10-21 22:22 . 2008-10-21 22:22 d——– c:\program files\Vimicro
2008-10-21 22:22 . 2008-10-21 22:22 d——– c:\documents and settings\Apurva\Application Data\InstallShield
2008-10-21 22:22 . 2006-04-25 09:57 428,160 –a—— c:\windows\system32\drivers\vmfilter303.sys
2008-10-21 22:22 . 2006-12-01 13:23 392,122 –a—— c:\windows\system32\drivers\usbVM303.sys
2008-10-21 22:22 . 2006-06-01 16:03 278,589 –a—— c:\windows\system32\VM303Prp.Ax
2008-10-21 22:22 . 2007-01-09 12:33 176,128 –a—— c:\windows\amcap.exe
2008-10-21 22:22 . 2007-01-09 12:33 102,400 –a—— c:\windows\VM303Cap.exe
2008-10-21 22:22 . 2005-04-30 17:46 81,920 –a—— c:\windows\system32\VM303STI.dll
2008-10-21 22:22 . 2007-01-09 12:33 49,152 –a—— c:\windows\recovery.exe
2008-10-21 22:22 . 2007-01-09 12:34 49,152 –a—— c:\windows\Paizhao.exe
2008-10-21 22:22 . 2007-01-09 12:33 40,960 –a—— c:\windows\system32\setupfilter.exe
2008-10-21 22:20 . 2008-11-05 11:44 d——– c:\documents and settings\Apurva\Application Data\skypePM
2008-10-21 22:20 . 2008-11-05 12:37 d——– c:\documents and settings\Apurva\Application Data\Skype
2008-10-21 22:20 . 2008-10-21 22:20 32 –a—— c:\documents and settings\All Users\Application Data\ezsid.dat
2008-10-21 22:19 . 2008-10-21 22:19 d——– c:\program files\Skype
2008-10-21 22:19 . 2008-10-21 22:19 d——– c:\program files\Common Files\Skype
2008-10-21 22:19 . 2008-10-21 22:19 d——– c:\documents and settings\All Users\Application Data\Skype
2008-10-21 22:14 . 2008-10-21 22:14 d——– c:\program files\Synaptics
2008-10-21 22:14 . 2006-03-08 11:35 191,872 –a—— c:\windows\system32\drivers\SynTP.sys
2008-10-21 22:14 . 2006-03-08 11:38 114,688 –a—— c:\windows\system32\SynCtrl.dll
2008-10-21 22:14 . 2006-03-08 11:38 94,299 –a—— c:\windows\system32\SynTPAPI.dll
2008-10-21 22:14 . 2006-03-08 11:37 82,014 –a—— c:\windows\system32\SynCOM.dll
2008-10-21 22:14 . 2006-03-08 11:51 81,920 –a—— c:\windows\system32\SynTPCo2.dll
2008-10-21 22:14 . 2006-03-08 11:49 69,723 –a—— c:\windows\system32\SynTPFcs.dll
2008-10-21 22:13 . 2008-10-21 22:13 d——– c:\program files\CONEXANT
2008-10-21 22:11 . 2008-10-21 22:11 d——– c:\program files\SigmaTel
2008-10-21 22:11 . 2006-07-27 13:24 1,171,464 –a—— c:\windows\system32\drivers\sthda.sys
2008-10-21 22:11 . 2006-07-27 13:20 225,280 –a—— c:\windows\system32\stacapi.dll
2008-10-21 22:05 . 2008-10-21 22:05 d——– c:\program files\AMD
2008-10-21 22:05 . 2006-07-01 21:39 36,864 –a—— c:\windows\system32\drivers\AmdK8.sys
2008-10-21 22:02 . 2008-10-21 22:02 d——– c:\documents and settings\Apurva\Application Data\ATI
2008-10-21 21:59 . 2008-10-21 21:59 d——– c:\windows\system32\URTTemp
2008-10-21 21:59 . 2008-10-21 22:01 d——– c:\program files\ATI Technologies
2008-10-21 21:53 . 2005-12-19 08:08 3,096,576 –a—— c:\windows\system32\BCMWLCPL.CPL
2008-10-21 21:52 . 2008-10-21 21:52 d——– c:\program files\Broadcom
2008-10-21 21:52 . 2006-08-17 07:55 44,544 -ra—— c:\windows\system32\drivers\bcm4sbxp.sys
2008-10-21 21:50 . 2008-10-21 22:22 d—-c— c:\windows\system32\DRVSTORE
2008-10-21 21:50 . 2008-10-21 21:50 d——– c:\program files\DIFX
2008-10-21 21:50 . 2005-07-14 17:58 28,544 –a—— c:\windows\system32\drivers\rimmptsk.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-26 03:48 ——— d—–w c:\program files\Common Files\InstallShield
2008-10-22 03:22 ——— d–h–w c:\program files\InstallShield Installation Information
2008-10-22 02:53 ——— d—–w c:\program files\Dell
2008-10-22 00:35 ——— d—–w c:\program files\microsoft frontpage
2008-09-15 11:57 1,846,016 —-a-w c:\windows\system32\win32k.sys
2008-08-26 07:24 826,368 —-a-w c:\windows\system32\wininet.dll
2008-08-14 09:58 2,136,064 —-a-w c:\windows\system32\ntoskrnl.exe
2008-08-14 09:22 2,015,744 —-a-w c:\windows\system32\ntkrnlpa.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DownloadAccelerator"="c:\program files\DAP\DAP.EXE" [2008-10-21 3061248]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 153136]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2005-12-19 1347584]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 90112]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"VMSnap3"="c:\windows\Paizhao.EXE" [2007-01-09 49152]
"Domino"="c:\windows\Recovery.EXE" [2007-01-09 49152]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 153136]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-10-22 1234712]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-03-20 213936]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-10-30 136600]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-03 36352]
"SigmatelSysTrayApp"="stsystra.exe" [2006-07-27 c:\windows\stsystra.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Launchy.lnk - c:\program files\Launchy\Launchy.exe [2008-10-21 520192]
Purdue University VPN Client.lnk - c:\windows\Installer\{14FCFE7C-AB86-428A-9D2E-BFB6F5A7AA6E}\connected.ico [2008-10-21 77414]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 d344bus;d344bus;c:\windows\system32\DRIVERS\d344bus.sys [2003-12-27 137216]
R0 d344prt;d344prt;c:\windows\system32\Drivers\d344prt.sys [2003-12-27 5248]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-10-22 97928]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-10-22 875288]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-10-22 231704]
R2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-10-22 76040]
R2 JavaQuickStarterService;Java Quick Starter;c:\program files\Java\jre6\bin\jqs.exe [2008-10-30 152984]
S3 vmfilter303;vmfilter303;c:\windows\system32\drivers\vmfilter303.sys [2006-04-25 428160]
*Newly Created Service* - PROCEXP90
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-BigDog303 - c:\windows\VM303_STI.EXE
.
——- Supplementary Scan ——-
.
FireFox -: Profile - c:\documents and settings\Apurva\Application Data\Mozilla\Firefox\Profiles\trtj6ajp.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - about:blank
FF -: plugin - c:\program files\Google\Picasa3\npPicasa3.dll
FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npdeploytk.dll
FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npjp2.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npdeploytk.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-05 20:54:37
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
BigDog303 = c:\windows\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)????????????????0?????????@?Y????????????
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-11-05 20:55:33
ComboFix-quarantined-files.txt 2008-11-06 01:55:31
Pre-Run: 11,477,864,448 bytes free
Post-Run: 11,597,488,128 bytes free
216 — E O F — 2008-10-24 15:25:45
————————————————————————————————————————————————————————————————————————————-
HIJACKTHIS LOG
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:01:20 PM, on 11/5/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\WINDOWS\Paizhao.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\Recovery.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\DAP\DAP.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZipm12.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Launchy\Launchy.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [VMSnap3] C:\WINDOWS\Paizhao.EXE
O4 - HKLM\..\Run: [Domino] C:\WINDOWS\Recovery.EXE
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKCU\..\Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP.EXE" /STARTUP
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Launchy.lnk = C:\Program Files\Launchy\Launchy.exe
O4 - Global Startup: Purdue University VPN Client.lnk = ?
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Purdue University VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZipm12.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
–
End of file - 6991 bytes