This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Trojan and Possible Rootkit Removal Help

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

The last few times I've run Malware's Anti-malware I've gotten quite a few trojans that I've removed multiple times but they keep coming back as soon as I restart my PC, the name that comes up for me on it is just called Trojan but when I run a Spybot Search and Destroy scan I get Win32.Delf.rtk and Refpron. Every time I run a scan with Spybot I get those trojans. Any help would be appreciated.








Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:10:02 PM, on 12/14/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\msnmoed.exe
C:\WINDOWS\system32\tpszxyd.sys
C:\WINDOWS\system32\noytcyr.exe
C:\WINDOWS\system32\wsldoekd.exe
C:\WINDOWS\system32\afisicx.exe
C:\WINDOWS\system32\roytctm.exe
C:\WINDOWS\system32\tdydowkc.exe
C:\WINDOWS\system32\mabidwe.exe
C:\WINDOWS\system32\soxpeca.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\udxfytw.sys
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: desktopComic.exe
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {10093E98-C073-4C75-8D0E-FB5CD3A71D33} (ZoneUpwords Object) - http://messenger.zone.msn.com/binary/Upwords.cab57176.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} (get_atlcom Class) - http://apps.corel.com/nos_dl_manager_dev/p…IEGetPlugin.ocx
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1227657889875
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab57176.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O16 - DPF: {FF3C5A9F-5A91-4930-80E8-4709194C2AD3} (CheckersZPA Object) - http://zone.msn.com/bingame/zpagames/Check…PA.cab55579.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O23 - Service: McAfee Application Installer Cleanup (0148681227668442) (0148681227668442mcinstcleanup) - Unknown owner - C:\DOCUME~1\Owner\LOCALS~1\Temp\014868~1.EXE (file missing)
O23 - Service: afisicx Service (afisicx) - Unknown owner - C:\WINDOWS\system32\afisicx.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: mabidwe Service (mabidwe) - Unknown owner - C:\WINDOWS\system32\mabidwe.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Ms DataBases Management Service (mscmcosd) - Unknown owner - C:\WINDOWS\system32\mscmco.exe
O23 - Service: noytcyr Service (noytcyr) - Unknown owner - C:\WINDOWS\system32\noytcyr.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: roytctm Service (roytctm) - Unknown owner - C:\WINDOWS\system32\roytctm.exe
O23 - Service: soxpeca Service (soxpeca) - Unknown owner - C:\WINDOWS\system32\soxpeca.exe
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: tdydowkc Service (tdydowkc) - Unknown owner - C:\WINDOWS\system32\tdydowkc.exe
O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
O23 - Service: wsldoekd Service (wsldoekd) - Unknown owner - C:\WINDOWS\system32\wsldoekd.exe

–
End of file - 11547 bytes
Hi and welcome back to the forums here at WTT.

:welcome:

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply. Please also post an updated HijackThis log and let me know how it's running.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
ComboFix 08-12-14.04 - Owner 2008-12-14 22:48:39.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1183 [GMT -8:00]
Running from: c:\documents and settings\[removed]\My Documents\ComboFix.exe
* Created a new restore point
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Install.txt
c:\windows\system32\afisicx.exe
c:\windows\system32\comsa32.sys
c:\windows\system32\e1000msg.dll
c:\windows\system32\hpowiax2.dll
c:\windows\system32\mabidwe.exe
c:\windows\system32\noytcyr.exe
c:\windows\system32\roytctm.exe
c:\windows\system32\soxpeca.exe
c:\windows\system32\tdydowkc.exe
c:\windows\system32\tpszxyd.sys
c:\windows\system32\udxfytw.sys
c:\windows\system32\wsldoekd.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_AFISICX
——-\Legacy_MABIDWE
——-\Legacy_NOYTCYR
——-\Legacy_ROYTCTM
——-\Legacy_SOXPECA
——-\Legacy_TDYDOWKC
——-\Legacy_WSLDOEKD
——-\Service_afisicx
——-\Service_mabidwe
——-\Service_noytcyr
——-\Service_roytctm
——-\Service_soxpeca
——-\Service_tdydowkc
——-\Service_wsldoekd


((((((((((((((((((((((((( Files Created from 2008-11-15 to 2008-12-15 )))))))))))))))))))))))))))))))
.

2008-12-14 22:07 . 2008-12-14 22:34 d——– c:\documents and settings\Owner\Application Data\IMVUClient
2008-12-14 22:07 . 2008-12-14 22:50 d——– c:\documents and settings\Owner\Application Data\IMVU
2008-12-14 19:05 . 2008-12-14 19:05 d——– c:\documents and settings\Owner\Application Data\ieSpell
2008-12-14 18:59 . 2008-12-14 18:59 d——– c:\program files\Trend Micro
2008-12-14 18:53 . 2008-12-14 22:14 59,392 –a—— c:\windows\system32\msnmoed.exe
2008-12-12 15:30 . 2008-12-12 15:40 d——– c:\program files\Will
2008-12-12 02:01 . 2008-12-12 02:01 d——– c:\documents and settings\All Users\Application Data\pixelStorm
2008-12-12 01:15 . 2008-12-12 01:15 d——– c:\documents and settings\All Users\Application Data\MumboJumbo
2008-12-12 01:15 . 2008-12-12 01:15 22 –a—— c:\windows\msnmsgr.exe.ini
2008-12-10 21:52 . 2008-12-10 21:52 d——– c:\windows\system32\DRM
2008-12-10 15:29 . 2008-04-13 10:46 17,024 –a—— c:\windows\system32\drivers\CCDECODE.sys
2008-12-10 15:29 . 2008-04-13 10:46 17,024 –a–c— c:\windows\system32\dllcache\ccdecode.sys
2008-12-10 15:28 . 2008-04-13 16:12 91,136 –a—— c:\windows\system32\kswdmcap.ax
2008-12-10 15:28 . 2008-04-13 16:12 91,136 –a–c— c:\windows\system32\dllcache\kswdmcap.ax
2008-12-10 15:28 . 2008-04-13 16:12 61,952 –a—— c:\windows\system32\kstvtune.ax
2008-12-10 15:28 . 2008-04-13 16:12 61,952 –a–c— c:\windows\system32\dllcache\kstvtune.ax
2008-12-10 15:28 . 2008-04-13 16:12 53,760 –a—— c:\windows\system32\vfwwdm32.dll
2008-12-10 15:28 . 2008-04-13 16:12 53,760 –a–c— c:\windows\system32\dllcache\vfwwdm32.dll
2008-12-10 15:28 . 2008-04-13 16:12 43,008 –a—— c:\windows\system32\ksxbar.ax
2008-12-10 15:28 . 2008-04-13 16:12 43,008 –a–c— c:\windows\system32\dllcache\ksxbar.ax
2008-12-10 15:28 . 2008-04-13 16:12 20,992 –a—— c:\windows\system32\dshowext.ax
2008-12-10 15:28 . 2008-04-13 16:12 20,992 –a–c— c:\windows\system32\dllcache\dshowext.ax
2008-12-10 15:20 . 2008-12-10 15:20 d——– c:\program files\Yahoo!
2008-12-10 15:20 . 2008-12-10 15:21 d——– c:\documents and settings\All Users\Application Data\Yahoo!
2008-12-10 15:04 . 2008-11-10 03:39 73,728 –a—— c:\windows\system32\javacpl.cpl
2008-12-04 17:03 . 2008-12-04 17:03 d——– c:\windows\system32\xlive
2008-12-04 17:03 . 2008-12-04 17:03 d——– c:\program files\Microsoft Games for Windows - LIVE
2008-12-04 17:03 . 2008-03-05 15:56 3,786,760 –a—— c:\windows\system32\D3DX9_37.dll
2008-12-04 17:03 . 2008-03-05 15:56 1,420,824 –a—— c:\windows\system32\D3DCompiler_37.dll
2008-12-04 17:03 . 2008-02-05 23:07 462,864 –a—— c:\windows\system32\d3dx10_37.dll
2008-12-04 16:58 . 2008-12-04 16:58 d——– c:\documents and settings\Owner\Application Data\Microsoft Games
2008-12-04 16:49 . 2008-12-04 16:49 d——– c:\documents and settings\Owner\Application Data\InstallShield Installation Information
2008-12-04 16:26 . 2008-12-04 16:26 d——– c:\program files\Microsoft Games
2008-12-03 21:18 . 2008-12-14 19:33 d——– c:\program files\City of Heroes
2008-12-02 13:37 . 2008-12-02 13:37 d——– c:\program files\DivX
2008-12-02 13:23 . 2008-12-02 13:23 d——– c:\documents and settings\Owner\Application Data\Apple Computer
2008-11-30 21:27 . 2008-11-30 21:27 d——– c:\program files\Common Files\Motive
2008-11-30 21:27 . 2003-10-22 08:54 81,920 –a—— c:\windows\system32\W32n50.dll
2008-11-30 21:27 . 2003-10-22 08:54 17,162 –a—— c:\windows\system32\Pcandis5.sys
2008-11-30 21:27 . 2003-10-22 08:54 16,848 –a—— c:\windows\system32\Pcandis4.sys
2008-11-30 21:27 . 2003-10-22 08:54 16,073 –a—— c:\windows\system32\Pcandis3.vxd
2008-11-30 01:58 . 2008-11-10 05:43 410,984 –a—— c:\windows\system32\deploytk.dll
2008-11-30 01:48 . 2008-11-30 01:48 d——– c:\windows\Sun
2008-11-30 01:33 . 2004-08-04 02:00 10,129,408 –a–c— c:\windows\system32\dllcache\hwxkor.dll
2008-11-30 01:32 . 2001-08-17 22:36 8,704 –a—— c:\windows\system32\kbdjpn.dll
2008-11-30 01:32 . 2001-08-17 22:36 8,704 –a–c— c:\windows\system32\dllcache\kbdjpn.dll
2008-11-30 01:32 . 2001-08-17 22:36 8,192 –a—— c:\windows\system32\kbdkor.dll
2008-11-30 01:32 . 2001-08-17 22:36 8,192 –a–c— c:\windows\system32\dllcache\kbdkor.dll
2008-11-30 01:32 . 2008-04-13 16:09 6,144 –a—— c:\windows\system32\kbd106.dll
2008-11-30 01:32 . 2001-08-17 14:55 6,144 –a—— c:\windows\system32\kbd101c.dll
2008-11-30 01:32 . 2001-08-17 14:55 6,144 –a—— c:\windows\system32\kbd101b.dll
2008-11-30 01:32 . 2008-04-13 16:09 6,144 –a–c— c:\windows\system32\dllcache\kbd106.dll
2008-11-30 01:32 . 2001-08-17 14:55 6,144 –a–c— c:\windows\system32\dllcache\kbd101c.dll
2008-11-30 01:32 . 2001-08-17 14:55 6,144 –a–c— c:\windows\system32\dllcache\kbd101b.dll
2008-11-30 01:32 . 2001-08-17 14:55 5,632 –a—— c:\windows\system32\kbd103.dll
2008-11-30 01:32 . 2001-08-17 14:55 5,632 –a–c— c:\windows\system32\dllcache\kbd103.dll
2008-11-29 21:23 . 2008-11-29 21:23 d——– c:\documents and settings\Owner\Application Data\Roxio
2008-11-29 13:05 . 2008-11-29 13:06 d——– c:\documents and settings\Owner\Application Data\Move Networks
2008-11-28 20:33 . 2008-11-28 20:37 d–h—– c:\windows\msdownld.tmp
2008-11-28 20:33 . 2008-11-28 20:33 d——– c:\windows\Logs
2008-11-28 19:53 . 2008-11-28 19:53 d——– c:\program files\Common Files\Adobe AIR
2008-11-28 19:52 . 2008-11-28 19:53 d——– c:\program files\Common Files\Adobe
2008-11-28 19:48 . 2008-11-29 00:02 d——– c:\program files\NOS
2008-11-28 19:48 . 2008-11-29 00:02 d——– c:\documents and settings\All Users\Application Data\NOS
2008-11-27 20:04 . 2008-11-27 20:04 203,776 –a—— c:\windows\system32\clrviddc.dll
2008-11-27 20:04 . 1999-09-10 04:06 45,056 –a—— c:\windows\system32\wnaspi32.dll
2008-11-27 20:04 . 1999-09-10 04:06 25,244 –a—— c:\windows\system32\drivers\aspi32.sys
2008-11-27 20:04 . 1999-09-10 04:06 5,600 –a—— c:\windows\system\winaspi.dll
2008-11-27 20:04 . 1999-09-10 04:06 4,672 –a—— c:\windows\system\wowpost.exe
2008-11-27 20:02 . 2008-11-27 20:02 d——– c:\program files\Common Files\xing shared
2008-11-27 19:59 . 2008-11-27 19:59 25 –a—— c:\windows\cdplayer.ini
2008-11-27 19:26 . 2008-11-27 19:26 40 –ah—– c:\windows\system32\ivireg.ivr
2008-11-27 17:45 . 2008-11-27 17:45 d——– c:\program files\Real
2008-11-27 17:45 . 2008-11-27 20:02 d——– c:\program files\Common Files\Real
2008-11-27 17:45 . 2005-09-20 17:27 10,368 –a—— c:\windows\system32\drivers\iviaspi.sys
2008-11-27 17:43 . 2008-11-27 17:43 d——– c:\program files\InterVideo
2008-11-27 17:43 . 2008-11-27 17:43 d——– c:\program files\Corel
2008-11-27 17:43 . 2008-11-27 17:43 d——– c:\program files\Common Files\Protexis
2008-11-27 17:43 . 2008-11-27 17:43 d——– c:\program files\Common Files\InterVideo
2008-11-27 17:43 . 2008-11-27 17:43 d——– c:\documents and settings\All Users\Application Data\Corel
2008-11-27 17:09 . 2008-11-27 17:09 d——– c:\documents and settings\Owner\Application Data\MSNInstaller
2008-11-27 16:37 . 2006-11-29 13:06 3,426,072 –a—— c:\windows\system32\d3dx9_32.dll
2008-11-27 16:37 . 2006-09-28 16:05 2,414,360 –a—— c:\windows\system32\d3dx9_31.dll
2008-11-27 16:37 . 2007-01-24 15:27 255,848 –a—— c:\windows\system32\xactengine2_6.dll
2008-11-27 16:37 . 2006-12-08 12:02 251,672 –a—— c:\windows\system32\xactengine2_5.dll
2008-11-27 16:37 . 2006-09-28 16:05 237,848 –a—— c:\windows\system32\xactengine2_4.dll
2008-11-27 16:37 . 2006-07-28 09:30 236,824 –a—— c:\windows\system32\xactengine2_3.dll
2008-11-27 16:37 . 2007-04-04 18:53 81,768 –a—— c:\windows\system32\xinput1_3.dll
2008-11-27 16:37 . 2006-07-28 09:30 62,744 –a—— c:\windows\system32\xinput1_2.dll
2008-11-27 16:37 . 2007-03-05 12:42 15,128 –a—— c:\windows\system32\x3daudio1_1.dll
2008-11-27 16:36 . 2005-05-26 15:34 2,297,552 –a—— c:\windows\system32\d3dx9_26.dll
2008-11-27 15:52 . 2008-11-27 15:52 d——– c:\program files\ieSpell
2008-11-27 15:50 . 2008-11-27 15:50 d——– C:\DECCHECK
2008-11-27 15:45 . 2008-11-27 15:52 d——– c:\documents and settings\All Users\Application Data\CyberLink
2008-11-27 14:04 . 2008-11-27 14:04 d——– c:\documents and settings\All Users\Application Data\SupportSoft
2008-11-27 14:04 . 2008-11-27 14:04 d——– c:\documents and settings\All Users\Application Data\PCDr
2008-11-27 14:04 . 2008-11-27 14:04 d——– c:\documents and settings\All Users\Application Data\PC-Doctor
2008-11-27 14:03 . 2008-11-27 14:04 d——– c:\program files\Dell Support Center
2008-11-27 14:03 . 2008-11-27 14:03 d——– c:\program files\Common Files\supportsoft
2008-11-27 13:44 . 2008-11-27 13:44 d——– c:\program files\MSXML 4.0
2008-11-27 13:39 . 2008-11-27 13:39 d——– c:\program files\Apple Software Update
2008-11-27 13:39 . 2008-12-02 13:34 d——– c:\documents and settings\All Users\Application Data\Apple Computer
2008-11-27 13:39 . 2008-11-27 13:39 d——– c:\documents and settings\All Users\Application Data\Apple
2008-11-26 23:47 . 2008-11-26 23:47 d——– c:\documents and settings\All Users\Application Data\HP Product Assistant
2008-11-26 23:44 . 2008-11-26 23:44 d——– c:\documents and settings\Owner\Application Data\HP
2008-11-26 23:43 . 2008-11-26 23:43 d——– c:\documents and settings\All Users\Application Data\HP
2008-11-26 23:42 . 2008-11-26 23:42 d——– C:\bin
2008-11-26 23:38 . 2008-11-26 23:40 d——– c:\program files\Common Files\HP
2008-11-26 23:35 . 2008-11-26 23:36 d——– c:\program files\Hewlett-Packard
2008-11-26 23:35 . 2008-11-26 23:35 d——– c:\program files\Common Files\Hewlett-Packard
2008-11-26 23:34 . 2006-01-04 01:12 77,824 -ra—— c:\windows\system32\HPZIDS01.dll
2008-11-26 23:34 . 2006-04-12 16:04 49,664 -ra—— c:\windows\system32\drivers\HPZid412.sys
2008-11-26 23:34 . 2006-04-10 14:03 38,400 –a—— c:\windows\system32\hpz3l054.dll
2008-11-26 23:34 . 2006-04-12 16:04 16,496 -ra—— c:\windows\system32\drivers\HPZipr12.sys
2008-11-26 23:32 . 2008-04-13 10:45 15,104 –a—— c:\windows\system32\drivers\usbscan.sys
2008-11-26 23:32 . 2008-04-13 10:45 15,104 –a–c— c:\windows\system32\dllcache\usbscan.sys
2008-11-26 23:29 . 2008-11-26 18:24 116,908 ——— c:\windows\hpoins11.dat.temp
2008-11-26 23:29 . 2006-05-05 13:18 11,634 ——— c:\windows\hpomdl11.dat.temp
2008-11-26 18:24 . 2008-11-26 23:48 d——– c:\program files\HP
2008-11-26 18:24 . 2008-04-13 10:45 32,128 –a—— c:\windows\system32\drivers\usbccgp.sys
2008-11-26 18:24 . 2008-04-13 10:45 32,128 –a–c— c:\windows\system32\dllcache\usbccgp.sys
2008-11-26 18:24 . 2008-04-13 10:47 25,856 –a—— c:\windows\system32\drivers\usbprint.sys
2008-11-26 18:24 . 2008-04-13 10:47 25,856 –a–c— c:\windows\system32\dllcache\usbprint.sys
2008-11-26 18:22 . 2008-11-26 23:44 117,091 –a—— c:\windows\hpoins11.dat
2008-11-26 18:21 . 2006-04-12 16:04 21,568 –a—— c:\windows\system32\drivers\HPZius12.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-30 05:08 ——— d—–w c:\documents and settings\All Users\Application Data\Dell
2008-11-27 23:52 ——— d—–w c:\program files\CyberLink
2008-11-27 07:41 ——— d—–w c:\documents and settings\All Users\Application Data\Sonic
2008-11-25 21:50 ——— d–h–w c:\program files\InstallShield Installation Information
2008-11-25 20:23 ——— d—–w c:\program files\ATI Technologies
2008-11-25 20:23 ——— d—–w c:\program files\ATI
2008-11-25 20:22 ——— d—–w c:\program files\SigmaTel
2008-11-25 20:20 ——— d—–w c:\program files\Roxio
2008-11-25 20:20 ——— d—–w c:\program files\Common Files\SureThing Shared
2008-11-25 20:20 ——— d—–w c:\program files\Common Files\Sonic Shared
2008-11-25 20:20 ——— d—–w c:\program files\Common Files\Roxio Shared
2008-11-25 20:20 ——— d—–w c:\documents and settings\All Users\Application Data\Uninstall
2008-11-25 20:19 ——— d—–w c:\program files\Common Files\InstallShield
2008-11-25 20:19 ——— d—–w c:\documents and settings\All Users\Application Data\InstallShield
2008-11-25 20:16 ——— d—–w c:\documents and settings\Owner\Application Data\CyberLink
2008-11-25 20:08 ——— d—–w c:\program files\microsoft frontpage
2008-10-29 03:10 3,341,824 —-a-w c:\windows\system32\drivers\ati2mtag.sys
2008-10-29 01:18 53,248 —-a-w c:\windows\system32\drivers\ati2erec.dll
2008-10-24 11:21 455,296 —-a-w c:\windows\system32\drivers\mrxsmb.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2008-07-11 641208]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-26 206064]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 c:\windows\stsystra.exe]

c:\documents and settings\Owner\Start Menu\Programs\Startup\
desktopComic.exe [2008-10-04 604877]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Fast Start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk
backup=c:\windows\pss\HP Photosmart Premier Fast Start.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-06-12 02:38 34672 c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICustomerCare]
–a—— 2007-10-04 18:38 307200 c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dellsupportcenter]
–a—— 2008-08-26 15:58 206064 c:\program files\Dell Support Center\bin\sprtcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
–a—— 2007-05-08 16:24 54840 c:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
——— 2008-04-13 16:12 1695232 c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Pitstop Optimize Scheduler]
–a—— 2008-03-26 17:40 2577120 c:\program files\PCPitstop\Optimize\PCPOptimize.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVDDXSrv]
——— 2008-05-12 14:47 128296 c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs—- 2008-09-16 12:16 1833296 c:\program files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
–a—— 2008-08-29 16:11 61440 c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2007-09-25 01:11 132496 c:\program files\Java\jre1.6.0_03\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Microsoft Games\\Viva Pinata\\Viva Pinata.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=

R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;"c:\program files\McAfee\SiteAdvisor\McSACore.exe" [2008-11-25 203280]
R2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-04-17 11032]
R3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [2007-07-20 84992]
S2 0148681227668442mcinstcleanup;McAfee Application Installer Cleanup (0148681227668442);c:\docume~1\Owner\LOCALS~1\Temp\014868~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service []

*Newly Created Service* - GTNDIS5
.
Contents of the 'Scheduled Tasks' folder

2008-11-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2008-11-25 c:\windows\Tasks\McDefragTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2008-07-09 18:10]

2008-12-01 c:\windows\Tasks\McQcTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2008-07-09 18:10]
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-LELA - c:\program files\Linksys\Linksys EasyLink Advisor\Linksys EasyLink Advisor.exe
MSConfigStartUp-QuickTime Task - c:\program files\QuickTime\QTTask.exe


.
——- Supplementary Scan ——-
.
IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Lookup on Merriam Webster - file://c:\program files\ieSpell\Merriam Webster.HTM
IE: Lookup on Wikipedia - file://c:\program files\ieSpell\wikipedia.HTM
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\Owner\Start Menu\Programs\IMVU\Run IMVU.lnk
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\Owner\Start Menu\Programs\IMVU\Run IMVU.lnk -
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\fjwomjtn.default\
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeploytk.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npjp2.dll
FF - plugin: c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeploytk.dll
FF - plugin: c:\program files\Yahoo!\Shared\npYState.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-14 22:54:19
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(728)
c:\windows\system32\Ati2evxx.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\program files\Common Files\McAfee\MNA\McNASvc.exe
c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
c:\program files\McAfee\MPF\MpfSrv.exe
c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\program files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
c:\program files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
c:\progra~1\McAfee\VIRUSS~1\mcsysmon.exe
.
**************************************************************************
.
Completion time: 2008-12-14 22:57:32 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-15 06:57:27

Pre-Run: 118,223,872,000 bytes free
Post-Run: 118,262,214,656 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

340 — E O F — 2008-12-11 01:43:31








Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:00:38 PM, on 12/14/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Documents and Settings\Owner\Application Data\IMVUClient\IMVUClient.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Documents and Settings\Owner\Application Data\IMVUClient\IMVUQualityAgent.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: desktopComic.exe
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Owner\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {10093E98-C073-4C75-8D0E-FB5CD3A71D33} (ZoneUpwords Object) - http://messenger.zone.msn.com/binary/Upwords.cab57176.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} (get_atlcom Class) - http://apps.corel.com/nos_dl_manager_dev/p…IEGetPlugin.ocx
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1227657889875
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab57176.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O16 - DPF: {FF3C5A9F-5A91-4930-80E8-4709194C2AD3} (CheckersZPA Object) - http://zone.msn.com/bingame/zpagames/Check…PA.cab55579.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O23 - Service: McAfee Application Installer Cleanup (0148681227668442) (0148681227668442mcinstcleanup) - Unknown owner - C:\DOCUME~1\Owner\LOCALS~1\Temp\014868~1.EXE (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Ms DataBases Management Service (mscmcosd) - Unknown owner - C:\WINDOWS\system32\mscmco.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe

–
End of file - 10887 bytes
Please go to http://virusscan.jotti.org, click on Browse, and upload the following file for analysis:

C:\WINDOWS\system32\mscmco.exe

Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.

If Jotti is too busy you can try these.

http://www.kaspersky.com/scanforvirus.html
http://www.virustotal.com/en/indexf.html

~~~~~~~~~~~~~~~~~~~~~~~~~~

Also, have you tried running MalwareBytes' again? If so is it still finding any Malware. Please post the log.

~~~~~~~~~~~~~~~~~~~~~~~~~~

Use ATF Cleaner to remove temp files,
cookies, cache, ect…

Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

~~~~~~~~~~~~~~~~~~~~~~~~~~

I'd like for you to run this next online scan to check for remnants or anything that might be hidden.
The below scan can take up to an hour or longer, please be patient.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so no conflicts and to speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once scan is finished remember to re-enable resident antivirus protection along with whatever antispyware app you use.


Please do a scan with Kaspersky Online Scanner or from here
http://www.kaspersky.com/virusscanner

Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

  • The program will install and then begin downloading the latest definition
    files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run. (At times it may appear to stall)
    * Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
    * Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
    * Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Once the scan is complete, click on View scan report To obtain the report:
Click on: Save Report As
Next, in the Save as prompt, Save in area, select: Desktop
In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select:
Text file [*.txt]
Then, click: Save
Please post the Kaspersky Online Scanner Report in
your reply.

Animated tutorial
http://i275.photobucket.com/albums/jj285/B…ng/KAS/KAS9.gif

(Note.. for Internet Explorer 7 users:
If at any time you have trouble with the "Accept" button of the license, click on the "Zoom" tool located at the bottom right of the IE window and set the zoom to 75 %. Once the license has been accepted, reset to 100%
.)
Or use Firefox with IE-Tab plugin
https://addons.mozilla.org/en-US/firefox/addon/1419

In your next reply post:
Kaspersky log
New HJT log taken after the above scan has run
I tried to upload the file you told me to upload, but all 3 of the sites said that the file was 0 bytes due possibly to my firewall but I tried all 3 sties with my firewall turned off but still didn't work. I also ran the ATF cleaner with no problem.

Yes, Maleware is still finding those trojans when I run a scan. Here is the log for Ant-Malware

Malwarebytes' Anti-Malware 1.31
Database version: 1504
Windows 5.1.2600 Service Pack 3

12/15/2008 5:39:02 PM
mbam-log-2008-12-15 (17-39-02).txt

Scan type: Quick Scan
Objects scanned: 41996
Time elapsed: 5 minute(s), 0 second(s)

Memory Processes Infected: 7
Memory Modules Infected: 0
Registry Keys Infected: 21
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 9

Memory Processes Infected:
C:\WINDOWS\system32\afisicx.exe (Trojan.Agent) -> Unloaded process successfully.
C:\WINDOWS\system32\mabidwe.exe (Trojan.Agent) -> Unloaded process successfully.
C:\WINDOWS\system32\noytcyr.exe (Trojan.Agent) -> Unloaded process successfully.
C:\WINDOWS\system32\roytctm.exe (Trojan.Agent) -> Unloaded process successfully.
C:\WINDOWS\system32\soxpeca.exe (Trojan.Agent) -> Unloaded process successfully.
C:\WINDOWS\system32\tdydowkc.exe (Trojan.Agent) -> Unloaded process successfully.
C:\WINDOWS\system32\wsldoekd.exe (Trojan.Agent) -> Unloaded process successfully.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\afisicx (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\afisicx (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\afisicx (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mabidwe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\mabidwe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mabidwe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\noytcyr (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\noytcyr (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\noytcyr (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\roytctm (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\roytctm (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\roytctm (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\soxpeca (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\soxpeca (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\soxpeca (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tdydowkc (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\tdydowkc (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tdydowkc (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wsldoekd (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\wsldoekd (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wsldoekd (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\msnmoed.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\afisicx.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mabidwe.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\noytcyr.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\roytctm.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\soxpeca.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tdydowkc.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wsldoekd.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\comsa32.sys (Trojan.Agent) -> Quarantined and deleted successfully.







Here is my Kaspersky log



——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Monday, December 15, 2008
Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Monday, December 15, 2008 22:01:27
Records in database: 1463985
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\

Scan statistics:
Files scanned: 53630
Threat name: 3
Infected objects: 19
Suspicious objects: 0
Duration of the scan: 00:48:58


File name / Threat name / Threats count
C:\Qoobox\Quarantine\C\WINDOWS\system32\afisicx.exe.vir Infected: Trojan.Win32.Agent.astn 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\mabidwe.exe.vir Infected: Trojan.Win32.Agent.astn 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\noytcyr.exe.vir Infected: Trojan.Win32.Agent.astn 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\roytctm.exe.vir Infected: Trojan.Win32.Agent.astn 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\soxpeca.exe.vir Infected: Trojan.Win32.Agent.astn 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\tdydowkc.exe.vir Infected: Trojan.Win32.Agent.astn 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\udxfytw.sys.vir Infected: Trojan-Clicker.Win32.VBScobb.en 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\wsldoekd.exe.vir Infected: Trojan.Win32.Agent.astn 1
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\PKXDOKLN\msuse[1].bin Infected: Trojan-Downloader.Win32.Murlo.uk 1
C:\WINDOWS\system32\tmpxr_329333453645.bk Infected: Trojan.Win32.Agent.astn 1
C:\WINDOWS\system32\tmpxr_615510540871.bk Infected: Trojan.Win32.Agent.astn 1
C:\WINDOWS\system32\tmpxr_641705116048.bk Infected: Trojan.Win32.Agent.astn 1
C:\WINDOWS\system32\tmpxr_643411360581.bk Infected: Trojan.Win32.Agent.astn 1
C:\WINDOWS\system32\tmpxr_648810867608.bk Infected: Trojan.Win32.Agent.astn 1
C:\WINDOWS\system32\tmpxr_735088537824.bk Infected: Trojan.Win32.Agent.astn 1
C:\WINDOWS\system32\tmpxr_818142896721.bk Infected: Trojan.Win32.Agent.astn 1
C:\WINDOWS\system32\tmpxr_8429441681.bk Infected: Trojan.Win32.Agent.astn 1
C:\WINDOWS\system32\tmpxr_95479355738.bk Infected: Trojan.Win32.Agent.astn 1
C:\WINDOWS\system32\udxfytw.sys Infected: Trojan-Clicker.Win32.VBScobb.en 1

The selected area was scanned.





And finally here's my new HJT Log



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:57:06 PM, on 12/15/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: desktopComic.exe
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Owner\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {10093E98-C073-4C75-8D0E-FB5CD3A71D33} (ZoneUpwords Object) - http://messenger.zone.msn.com/binary/Upwords.cab57176.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} (get_atlcom Class) - http://apps.corel.com/nos_dl_manager_dev/p…IEGetPlugin.ocx
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1227657889875
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab57176.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O16 - DPF: {FF3C5A9F-5A91-4930-80E8-4709194C2AD3} (CheckersZPA Object) - http://zone.msn.com/bingame/zpagames/Check…PA.cab55579.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O23 - Service: McAfee Application Installer Cleanup (0148681227668442) (0148681227668442mcinstcleanup) - Unknown owner - C:\DOCUME~1\Owner\LOCALS~1\Temp\014868~1.EXE (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Ms DataBases Management Service (mscmcosd) - Unknown owner - C:\WINDOWS\system32\mscmco.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe

–
End of file - 11049 bytes
1. Open Notepad

2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\WINDOWS\system32\udxfytw.sys
C:\WINDOWS\system32\tmpxr_329333453645.bk 
C:\WINDOWS\system32\tmpxr_615510540871.bk 
C:\WINDOWS\system32\tmpxr_641705116048.bk 
C:\WINDOWS\system32\tmpxr_643411360581.bk 
C:\WINDOWS\system32\tmpxr_648810867608.bk 
C:\WINDOWS\system32\tmpxr_735088537824.bk 
C:\WINDOWS\system32\tmpxr_818142896721.bk 
C:\WINDOWS\system32\tmpxr_8429441681.bk 
C:\WINDOWS\system32\tmpxr_95479355738.bk
C:\WINDOWS\system32\mscmco.exe

Driver::
mscmcosd


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.
Here's the combofix log


ComboFix 08-12-14.04 - Owner 2008-12-15 20:10:39.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1509 [GMT -8:00]
Running from: c:\documents and settings\[removed]\My Documents\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\My Documents\CFScript.txt
* Created a new restore point
* Resident AV is active


FILE ::
c:\windows\system32\mscmco.exe
c:\windows\system32\tmpxr_329333453645.bk
c:\windows\system32\tmpxr_615510540871.bk
c:\windows\system32\tmpxr_641705116048.bk
c:\windows\system32\tmpxr_643411360581.bk
c:\windows\system32\tmpxr_648810867608.bk
c:\windows\system32\tmpxr_735088537824.bk
c:\windows\system32\tmpxr_818142896721.bk
c:\windows\system32\tmpxr_8429441681.bk
c:\windows\system32\tmpxr_95479355738.bk
c:\windows\system32\udxfytw.sys
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Install.txt
c:\windows\system32\afisicx.exe
c:\windows\system32\comsa32.sys
c:\windows\system32\mabidwe.exe
c:\windows\system32\mscmco.exe
c:\windows\system32\noytcyr.exe
c:\windows\system32\roytctm.exe
c:\windows\system32\soxpeca.exe
c:\windows\system32\tdydowkc.exe
c:\windows\system32\tmpxr_329333453645.bk
c:\windows\system32\tmpxr_615510540871.bk
c:\windows\system32\tmpxr_641705116048.bk
c:\windows\system32\tmpxr_643411360581.bk
c:\windows\system32\tmpxr_648810867608.bk
c:\windows\system32\tmpxr_735088537824.bk
c:\windows\system32\tmpxr_818142896721.bk
c:\windows\system32\tmpxr_8429441681.bk
c:\windows\system32\tmpxr_95479355738.bk
c:\windows\system32\tpszxyd.sys
c:\windows\system32\udxfytw.sys
c:\windows\system32\wsldoekd.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_AFISICX
——-\Legacy_MABIDWE
——-\Legacy_MSCMCOSD
——-\Legacy_NOYTCYR
——-\Legacy_ROYTCTM
——-\Legacy_SOXPECA
——-\Legacy_TDYDOWKC
——-\Legacy_WSLDOEKD
——-\Service_afisicx
——-\Service_mabidwe
——-\Service_mscmcosd
——-\Service_noytcyr
——-\Service_roytctm
——-\Service_soxpeca
——-\Service_tdydowkc
——-\Service_wsldoekd


((((((((((((((((((((((((( Files Created from 2008-11-16 to 2008-12-16 )))))))))))))))))))))))))))))))
.

2008-12-15 13:28 . 2008-12-15 13:28 d——– c:\program files\QuickTime
2008-12-14 22:07 . 2008-12-14 22:34 d——– c:\documents and settings\Owner\Application Data\IMVUClient
2008-12-14 22:07 . 2008-12-15 02:01 d——– c:\documents and settings\Owner\Application Data\IMVU
2008-12-14 19:05 . 2008-12-14 19:05 d——– c:\documents and settings\Owner\Application Data\ieSpell
2008-12-14 18:59 . 2008-12-14 18:59 d——– c:\program files\Trend Micro
2008-12-12 15:30 . 2008-12-12 15:40 d——– c:\program files\Will
2008-12-12 02:01 . 2008-12-12 02:01 d——– c:\documents and settings\All Users\Application Data\pixelStorm
2008-12-12 01:15 . 2008-12-12 01:15 d——– c:\documents and settings\All Users\Application Data\MumboJumbo
2008-12-12 01:15 . 2008-12-12 01:15 22 –a—— c:\windows\msnmsgr.exe.ini
2008-12-10 21:52 . 2008-12-10 21:52 d——– c:\windows\system32\DRM
2008-12-10 15:29 . 2008-04-13 10:46 17,024 –a—— c:\windows\system32\drivers\CCDECODE.sys
2008-12-10 15:29 . 2008-04-13 10:46 17,024 –a–c— c:\windows\system32\dllcache\ccdecode.sys
2008-12-10 15:28 . 2008-04-13 16:12 91,136 –a—— c:\windows\system32\kswdmcap.ax
2008-12-10 15:28 . 2008-04-13 16:12 91,136 –a–c— c:\windows\system32\dllcache\kswdmcap.ax
2008-12-10 15:28 . 2008-04-13 16:12 61,952 –a—— c:\windows\system32\kstvtune.ax
2008-12-10 15:28 . 2008-04-13 16:12 61,952 –a–c— c:\windows\system32\dllcache\kstvtune.ax
2008-12-10 15:28 . 2008-04-13 16:12 53,760 –a—— c:\windows\system32\vfwwdm32.dll
2008-12-10 15:28 . 2008-04-13 16:12 53,760 –a–c— c:\windows\system32\dllcache\vfwwdm32.dll
2008-12-10 15:28 . 2008-04-13 16:12 43,008 –a—— c:\windows\system32\ksxbar.ax
2008-12-10 15:28 . 2008-04-13 16:12 43,008 –a–c— c:\windows\system32\dllcache\ksxbar.ax
2008-12-10 15:28 . 2008-04-13 16:12 20,992 –a—— c:\windows\system32\dshowext.ax
2008-12-10 15:28 . 2008-04-13 16:12 20,992 –a–c— c:\windows\system32\dllcache\dshowext.ax
2008-12-10 15:20 . 2008-12-10 15:20 d——– c:\program files\Yahoo!
2008-12-10 15:20 . 2008-12-10 15:21 d——– c:\documents and settings\All Users\Application Data\Yahoo!
2008-12-10 15:04 . 2008-11-10 03:39 73,728 –a—— c:\windows\system32\javacpl.cpl
2008-12-04 17:03 . 2008-12-04 17:03 d——– c:\windows\system32\xlive
2008-12-04 17:03 . 2008-12-04 17:03 d——– c:\program files\Microsoft Games for Windows - LIVE
2008-12-04 17:03 . 2008-03-05 15:56 3,786,760 –a—— c:\windows\system32\D3DX9_37.dll
2008-12-04 17:03 . 2008-03-05 15:56 1,420,824 –a—— c:\windows\system32\D3DCompiler_37.dll
2008-12-04 17:03 . 2008-02-05 23:07 462,864 –a—— c:\windows\system32\d3dx10_37.dll
2008-12-04 16:58 . 2008-12-04 16:58 d——– c:\documents and settings\Owner\Application Data\Microsoft Games
2008-12-04 16:49 . 2008-12-04 16:49 d——– c:\documents and settings\Owner\Application Data\InstallShield Installation Information
2008-12-04 16:26 . 2008-12-04 16:26 d——– c:\program files\Microsoft Games
2008-12-03 21:18 . 2008-12-15 14:25 d——– c:\program files\City of Heroes
2008-12-02 13:37 . 2008-12-02 13:37 d——– c:\program files\DivX
2008-12-02 13:23 . 2008-12-02 13:23 d——– c:\documents and settings\Owner\Application Data\Apple Computer
2008-11-30 21:27 . 2008-11-30 21:27 d——– c:\program files\Common Files\Motive
2008-11-30 21:27 . 2003-10-22 08:54 81,920 –a—— c:\windows\system32\W32n50.dll
2008-11-30 21:27 . 2003-10-22 08:54 17,162 –a—— c:\windows\system32\Pcandis5.sys
2008-11-30 21:27 . 2003-10-22 08:54 16,848 –a—— c:\windows\system32\Pcandis4.sys
2008-11-30 21:27 . 2003-10-22 08:54 16,073 –a—— c:\windows\system32\Pcandis3.vxd
2008-11-30 01:58 . 2008-11-10 05:43 410,984 –a—— c:\windows\system32\deploytk.dll
2008-11-30 01:48 . 2008-11-30 01:48 d——– c:\windows\Sun
2008-11-30 01:33 . 2004-08-04 02:00 10,129,408 –a–c— c:\windows\system32\dllcache\hwxkor.dll
2008-11-30 01:32 . 2001-08-17 22:36 8,704 –a—— c:\windows\system32\kbdjpn.dll
2008-11-30 01:32 . 2001-08-17 22:36 8,704 –a–c— c:\windows\system32\dllcache\kbdjpn.dll
2008-11-30 01:32 . 2001-08-17 22:36 8,192 –a—— c:\windows\system32\kbdkor.dll
2008-11-30 01:32 . 2001-08-17 22:36 8,192 –a–c— c:\windows\system32\dllcache\kbdkor.dll
2008-11-30 01:32 . 2008-04-13 16:09 6,144 –a—— c:\windows\system32\kbd106.dll
2008-11-30 01:32 . 2001-08-17 14:55 6,144 –a—— c:\windows\system32\kbd101c.dll
2008-11-30 01:32 . 2001-08-17 14:55 6,144 –a—— c:\windows\system32\kbd101b.dll
2008-11-30 01:32 . 2008-04-13 16:09 6,144 –a–c— c:\windows\system32\dllcache\kbd106.dll
2008-11-30 01:32 . 2001-08-17 14:55 6,144 –a–c— c:\windows\system32\dllcache\kbd101c.dll
2008-11-30 01:32 . 2001-08-17 14:55 6,144 –a–c— c:\windows\system32\dllcache\kbd101b.dll
2008-11-30 01:32 . 2001-08-17 14:55 5,632 –a—— c:\windows\system32\kbd103.dll
2008-11-30 01:32 . 2001-08-17 14:55 5,632 –a–c— c:\windows\system32\dllcache\kbd103.dll
2008-11-29 21:23 . 2008-11-29 21:23 d——– c:\documents and settings\Owner\Application Data\Roxio
2008-11-29 13:05 . 2008-11-29 13:06 d——– c:\documents and settings\Owner\Application Data\Move Networks
2008-11-28 20:33 . 2008-11-28 20:37 d–h—– c:\windows\msdownld.tmp
2008-11-28 20:33 . 2008-11-28 20:33 d——– c:\windows\Logs
2008-11-28 19:53 . 2008-11-28 19:53 d——– c:\program files\Common Files\Adobe AIR
2008-11-28 19:52 . 2008-11-28 19:53 d——– c:\program files\Common Files\Adobe
2008-11-28 19:48 . 2008-11-29 00:02 d——– c:\program files\NOS
2008-11-28 19:48 . 2008-11-29 00:02 d——– c:\documents and settings\All Users\Application Data\NOS
2008-11-27 20:04 . 2008-11-27 20:04 203,776 –a—— c:\windows\system32\clrviddc.dll
2008-11-27 20:04 . 1999-09-10 04:06 45,056 –a—— c:\windows\system32\wnaspi32.dll
2008-11-27 20:04 . 1999-09-10 04:06 25,244 –a—— c:\windows\system32\drivers\aspi32.sys
2008-11-27 20:04 . 1999-09-10 04:06 5,600 –a—— c:\windows\system\winaspi.dll
2008-11-27 20:04 . 1999-09-10 04:06 4,672 –a—— c:\windows\system\wowpost.exe
2008-11-27 20:02 . 2008-11-27 20:02 d——– c:\program files\Common Files\xing shared
2008-11-27 19:59 . 2008-11-27 19:59 25 –a—— c:\windows\cdplayer.ini
2008-11-27 19:26 . 2008-11-27 19:26 40 –ah—– c:\windows\system32\ivireg.ivr
2008-11-27 17:45 . 2008-11-27 17:45 d——– c:\program files\Real
2008-11-27 17:45 . 2008-11-27 20:02 d——– c:\program files\Common Files\Real
2008-11-27 17:45 . 2005-09-20 17:27 10,368 –a—— c:\windows\system32\drivers\iviaspi.sys
2008-11-27 17:43 . 2008-11-27 17:43 d——– c:\program files\InterVideo
2008-11-27 17:43 . 2008-11-27 17:43 d——– c:\program files\Corel
2008-11-27 17:43 . 2008-11-27 17:43 d——– c:\program files\Common Files\Protexis
2008-11-27 17:43 . 2008-11-27 17:43 d——– c:\program files\Common Files\InterVideo
2008-11-27 17:43 . 2008-11-27 17:43 d——– c:\documents and settings\All Users\Application Data\Corel
2008-11-27 17:09 . 2008-11-27 17:09 d——– c:\documents and settings\Owner\Application Data\MSNInstaller
2008-11-27 16:37 . 2006-11-29 13:06 3,426,072 –a—— c:\windows\system32\d3dx9_32.dll
2008-11-27 16:37 . 2006-09-28 16:05 2,414,360 –a—— c:\windows\system32\d3dx9_31.dll
2008-11-27 16:37 . 2007-01-24 15:27 255,848 –a—— c:\windows\system32\xactengine2_6.dll
2008-11-27 16:37 . 2006-12-08 12:02 251,672 –a—— c:\windows\system32\xactengine2_5.dll
2008-11-27 16:37 . 2006-09-28 16:05 237,848 –a—— c:\windows\system32\xactengine2_4.dll
2008-11-27 16:37 . 2006-07-28 09:30 236,824 –a—— c:\windows\system32\xactengine2_3.dll
2008-11-27 16:37 . 2007-04-04 18:53 81,768 –a—— c:\windows\system32\xinput1_3.dll
2008-11-27 16:37 . 2006-07-28 09:30 62,744 –a—— c:\windows\system32\xinput1_2.dll
2008-11-27 16:37 . 2007-03-05 12:42 15,128 –a—— c:\windows\system32\x3daudio1_1.dll
2008-11-27 16:36 . 2005-05-26 15:34 2,297,552 –a—— c:\windows\system32\d3dx9_26.dll
2008-11-27 15:52 . 2008-11-27 15:52 d——– c:\program files\ieSpell
2008-11-27 15:50 . 2008-11-27 15:50 d——– C:\DECCHECK
2008-11-27 15:45 . 2008-11-27 15:52 d——– c:\documents and settings\All Users\Application Data\CyberLink
2008-11-27 14:04 . 2008-11-27 14:04 d——– c:\documents and settings\All Users\Application Data\SupportSoft
2008-11-27 14:04 . 2008-11-27 14:04 d——– c:\documents and settings\All Users\Application Data\PCDr
2008-11-27 14:04 . 2008-11-27 14:04 d——– c:\documents and settings\All Users\Application Data\PC-Doctor
2008-11-27 14:03 . 2008-11-27 14:04 d——– c:\program files\Dell Support Center
2008-11-27 14:03 . 2008-11-27 14:03 d——– c:\program files\Common Files\supportsoft
2008-11-27 13:44 . 2008-11-27 13:44 d——– c:\program files\MSXML 4.0
2008-11-27 13:39 . 2008-11-27 13:39 d——– c:\program files\Apple Software Update
2008-11-27 13:39 . 2008-12-02 13:34 d——– c:\documents and settings\All Users\Application Data\Apple Computer
2008-11-27 13:39 . 2008-11-27 13:39 d——– c:\documents and settings\All Users\Application Data\Apple
2008-11-26 23:47 . 2008-11-26 23:47 d——– c:\documents and settings\All Users\Application Data\HP Product Assistant
2008-11-26 23:44 . 2008-11-26 23:44 d——– c:\documents and settings\Owner\Application Data\HP
2008-11-26 23:43 . 2008-11-26 23:43 d——– c:\documents and settings\All Users\Application Data\HP
2008-11-26 23:42 . 2008-11-26 23:42 d——– C:\bin
2008-11-26 23:38 . 2008-11-26 23:40 d——– c:\program files\Common Files\HP
2008-11-26 23:35 . 2008-11-26 23:36 d——– c:\program files\Hewlett-Packard
2008-11-26 23:35 . 2008-11-26 23:35 d——– c:\program files\Common Files\Hewlett-Packard
2008-11-26 23:34 . 2006-01-04 01:12 77,824 -ra—— c:\windows\system32\HPZIDS01.dll
2008-11-26 23:34 . 2006-04-12 16:04 49,664 -ra—— c:\windows\system32\drivers\HPZid412.sys
2008-11-26 23:34 . 2006-04-10 14:03 38,400 –a—— c:\windows\system32\hpz3l054.dll
2008-11-26 23:34 . 2006-04-12 16:04 16,496 -ra—— c:\windows\system32\drivers\HPZipr12.sys
2008-11-26 23:32 . 2008-04-13 10:45 15,104 –a—— c:\windows\system32\drivers\usbscan.sys
2008-11-26 23:32 . 2008-04-13 10:45 15,104 –a–c— c:\windows\system32\dllcache\usbscan.sys
2008-11-26 23:29 . 2008-11-26 18:24 116,908 ——— c:\windows\hpoins11.dat.temp
2008-11-26 23:29 . 2006-05-05 13:18 11,634 ——— c:\windows\hpomdl11.dat.temp
2008-11-26 18:24 . 2008-11-26 23:48 d——– c:\program files\HP
2008-11-26 18:24 . 2008-04-13 10:45 32,128 –a—— c:\windows\system32\drivers\usbccgp.sys
2008-11-26 18:24 . 2008-04-13 10:45 32,128 –a–c— c:\windows\system32\dllcache\usbccgp.sys
2008-11-26 18:24 . 2008-04-13 10:47 25,856 –a—— c:\windows\system32\drivers\usbprint.sys
2008-11-26 18:24 . 2008-04-13 10:47 25,856 –a–c— c:\windows\system32\dllcache\usbprint.sys
2008-11-26 18:22 . 2008-11-26 23:44 117,091 –a—— c:\windows\hpoins11.dat
2008-11-26 18:21 . 2006-04-12 16:04 21,568 –a—— c:\windows\system32\drivers\HPZius12.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-30 05:08 ——— d—–w c:\documents and settings\All Users\Application Data\Dell
2008-11-27 23:52 ——— d—–w c:\program files\CyberLink
2008-11-27 07:41 ——— d—–w c:\documents and settings\All Users\Application Data\Sonic
2008-11-25 21:50 ——— d–h–w c:\program files\InstallShield Installation Information
2008-11-25 20:23 ——— d—–w c:\program files\ATI Technologies
2008-11-25 20:23 ——— d—–w c:\program files\ATI
2008-11-25 20:22 ——— d—–w c:\program files\SigmaTel
2008-11-25 20:20 ——— d—–w c:\program files\Roxio
2008-11-25 20:20 ——— d—–w c:\program files\Common Files\SureThing Shared
2008-11-25 20:20 ——— d—–w c:\program files\Common Files\Sonic Shared
2008-11-25 20:20 ——— d—–w c:\program files\Common Files\Roxio Shared
2008-11-25 20:20 ——— d—–w c:\documents and settings\All Users\Application Data\Uninstall
2008-11-25 20:19 ——— d—–w c:\program files\Common Files\InstallShield
2008-11-25 20:19 ——— d—–w c:\documents and settings\All Users\Application Data\InstallShield
2008-11-25 20:16 ——— d—–w c:\documents and settings\Owner\Application Data\CyberLink
2008-11-25 20:08 ——— d—–w c:\program files\microsoft frontpage
2008-10-29 03:10 3,341,824 —-a-w c:\windows\system32\drivers\ati2mtag.sys
2008-10-29 01:18 53,248 —-a-w c:\windows\system32\drivers\ati2erec.dll
2008-10-24 11:21 455,296 —-a-w c:\windows\system32\drivers\mrxsmb.sys
.

((((((((((((((((((((((((((((( snapshot@2008-12-14_22.56.49.03 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-12-15 06:03:47 32,768 –sha-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-12-16 04:09:11 32,768 –sha-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2008-12-15 06:03:47 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-12-16 04:09:11 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-12-16 03:22:48 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008120820081215\index.dat
+ 2008-12-16 03:22:48 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008121520081216\index.dat
- 2008-12-15 06:03:47 294,912 –sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-12-16 04:09:11 262,144 –sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-12-16 04:16:10 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_6c0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2008-07-11 641208]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-26 206064]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-12-15 413696]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 c:\windows\stsystra.exe]

c:\documents and settings\Owner\Start Menu\Programs\Startup\
desktopComic.exe [2008-10-04 604877]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Fast Start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk
backup=c:\windows\pss\HP Photosmart Premier Fast Start.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-06-12 02:38 34672 c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICustomerCare]
–a—— 2007-10-04 18:38 307200 c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dellsupportcenter]
–a—— 2008-08-26 15:58 206064 c:\program files\Dell Support Center\bin\sprtcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
–a—— 2007-05-08 16:24 54840 c:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
——— 2008-04-13 16:12 1695232 c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Pitstop Optimize Scheduler]
–a—— 2008-03-26 17:40 2577120 c:\program files\PCPitstop\Optimize\PCPOptimize.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVDDXSrv]
——— 2008-05-12 14:47 128296 c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs—- 2008-09-16 12:16 1833296 c:\program files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
–a—— 2008-08-29 16:11 61440 c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2007-09-25 01:11 132496 c:\program files\Java\jre1.6.0_03\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Microsoft Games\\Viva Pinata\\Viva Pinata.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=

R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;"c:\program files\McAfee\SiteAdvisor\McSACore.exe" [2008-11-25 203280]
R2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-04-17 11032]
R3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [2007-07-20 84992]
S2 0148681227668442mcinstcleanup;McAfee Application Installer Cleanup (0148681227668442);c:\docume~1\Owner\LOCALS~1\Temp\014868~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service []
.
Contents of the 'Scheduled Tasks' folder

2008-11-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2008-12-15 c:\windows\Tasks\McDefragTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2008-07-09 18:10]

2008-12-01 c:\windows\Tasks\McQcTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2008-07-09 18:10]
.
.
——- Supplementary Scan ——-
.
IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Lookup on Merriam Webster - file://c:\program files\ieSpell\Merriam Webster.HTM
IE: Lookup on Wikipedia - file://c:\program files\ieSpell\wikipedia.HTM
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\Owner\Start Menu\Programs\IMVU\Run IMVU.lnk
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\Owner\Start Menu\Programs\IMVU\Run IMVU.lnk -
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\fjwomjtn.default\
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeploytk.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npjp2.dll
FF - plugin: c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeploytk.dll
FF - plugin: c:\program files\Yahoo!\Shared\npYState.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-15 20:16:24
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(728)
c:\windows\system32\Ati2evxx.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\program files\Common Files\McAfee\MNA\McNASvc.exe
c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
c:\program files\McAfee\MPF\MpfSrv.exe
c:\program files\Common Files\Protexis\License Service\PsiService_2.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\program files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
c:\program files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
c:\progra~1\McAfee.com\Agent\mcagent.exe
c:\documents and settings\Owner\Start Menu\Programs\Startup\desktopComic.exe
c:\progra~1\McAfee\VIRUSS~1\mcsysmon.exe
.
**************************************************************************
.
Completion time: 2008-12-15 20:19:36 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-16 04:19:32
ComboFix2.txt 2008-12-15 06:57:33

Pre-Run: 118,114,078,720 bytes free
Post-Run: 118,180,216,832 bytes free

368 — E O F — 2008-12-11 01:43:31




And my HJT Log


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:22:39 PM, on 12/15/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Owner\Start Menu\Programs\Startup\desktopComic.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: desktopComic.exe
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Owner\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {10093E98-C073-4C75-8D0E-FB5CD3A71D33} (ZoneUpwords Object) - http://messenger.zone.msn.com/binary/Upwords.cab57176.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} (get_atlcom Class) - http://apps.corel.com/nos_dl_manager_dev/p…IEGetPlugin.ocx
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1227657889875
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab57176.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O16 - DPF: {FF3C5A9F-5A91-4930-80E8-4709194C2AD3} (CheckersZPA Object) - http://zone.msn.com/bingame/zpagames/Check…PA.cab55579.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O23 - Service: McAfee Application Installer Cleanup (0148681227668442) (0148681227668442mcinstcleanup) - Unknown owner - C:\DOCUME~1\Owner\LOCALS~1\Temp\014868~1.EXE (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe

–
End of file - 10786 bytes
OK can you run back through the MalwareBytes' and Kasperksy scans again? I won't be able to check in until a little later today, but hopefully that last run got it. Post the logs from MBAM, Kaspersky, and a new HJT log. Let me know how it's running also. Thanks, Dave
MBAM is still finding trojans, not as much as before though. Here are the reports. For the most part my PC is fine, only main problems is that web pages take long to load and shutting down takes a while too.

Malwarebytes' Anti-Malware 1.31
Database version: 1508
Windows 5.1.2600 Service Pack 3

12/16/2008 1:48:05 PM
mbam-log-2008-12-16 (13-48-05).txt

Scan type: Full Scan (C:\|)
Objects scanned: 101226
Time elapsed: 32 minute(s), 16 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 7

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\System Volume Information\_restore{5C85473E-0870-4E59-97A0-8A5060C75863}\RP49\A0012143.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5C85473E-0870-4E59-97A0-8A5060C75863}\RP49\A0012187.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5C85473E-0870-4E59-97A0-8A5060C75863}\RP50\A0012270.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5C85473E-0870-4E59-97A0-8A5060C75863}\RP50\A0012293.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5C85473E-0870-4E59-97A0-8A5060C75863}\RP50\A0012315.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5C85473E-0870-4E59-97A0-8A5060C75863}\RP50\A0012345.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5C85473E-0870-4E59-97A0-8A5060C75863}\RP51\A0012364.exe (Trojan.Agent) -> Quarantined and deleted successfully.




——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Tuesday, December 16, 2008
Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Tuesday, December 16, 2008 17:52:49
Records in database: 1466314
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\

Scan statistics:
Files scanned: 57546
Threat name: 2
Infected objects: 17
Suspicious objects: 0
Duration of the scan: 00:51:13


File name / Threat name / Threats count
C:\Qoobox\Quarantine\C\WINDOWS\system32\afisicx.exe.vir Infected: Trojan.Win32.Agent.astn 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\mabidwe.exe.vir Infected: Trojan.Win32.Agent.astn 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\noytcyr.exe.vir Infected: Trojan.Win32.Agent.astn 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\roytctm.exe.vir Infected: Trojan.Win32.Agent.astn 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\soxpeca.exe.vir Infected: Trojan.Win32.Agent.astn 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\tdydowkc.exe.vir Infected: Trojan.Win32.Agent.astn 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\tmpxr_329333453645.bk.vir Infected: Trojan.Win32.Agent.astn 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\tmpxr_615510540871.bk.vir Infected: Trojan.Win32.Agent.astn 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\tmpxr_641705116048.bk.vir Infected: Trojan.Win32.Agent.astn 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\tmpxr_643411360581.bk.vir Infected: Trojan.Win32.Agent.astn 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\tmpxr_648810867608.bk.vir Infected: Trojan.Win32.Agent.astn 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\tmpxr_735088537824.bk.vir Infected: Trojan.Win32.Agent.astn 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\tmpxr_818142896721.bk.vir Infected: Trojan.Win32.Agent.astn 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\tmpxr_8429441681.bk.vir Infected: Trojan.Win32.Agent.astn 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\tmpxr_95479355738.bk.vir Infected: Trojan.Win32.Agent.astn 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\udxfytw.sys.vir Infected: Trojan-Clicker.Win32.VBScobb.en 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\wsldoekd.exe.vir Infected: Trojan.Win32.Agent.astn 1

The selected area was scanned.






Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:20:54 PM, on 12/16/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: desktopComic.exe
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Owner\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {10093E98-C073-4C75-8D0E-FB5CD3A71D33} (ZoneUpwords Object) - http://messenger.zone.msn.com/binary/Upwords.cab57176.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} (get_atlcom Class) - http://apps.corel.com/nos_dl_manager_dev/p…IEGetPlugin.ocx
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1227657889875
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab57176.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O16 - DPF: {FF3C5A9F-5A91-4930-80E8-4709194C2AD3} (CheckersZPA Object) - http://zone.msn.com/bingame/zpagames/Check…PA.cab55579.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O23 - Service: McAfee Application Installer Cleanup (0148681227668442) (0148681227668442mcinstcleanup) - Unknown owner - C:\DOCUME~1\Owner\LOCALS~1\Temp\014868~1.EXE (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe

–
End of file - 10754 bytes
OK the only thing MBAM found is in restore points, and Kaspersky found items in combofix quarantine. We'll clear both of those out now.

Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.


  • [external image: Posted Image]
The above procedure will:
  • Delete the following:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Reset System Restore.

~~~~~~~~~~~~~~~~~~~~~

  • Download random's system information tool (RSIT) by random/random from here.
  • It is important that is saved to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<info.txt (<
Ok here are the two reports



Logfile of random's system information tool 1.04 (written by random/random)
Run by [removed] at 2008-12-16 16:43:34
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 113 GB (76%) free of 149 GB
Total RAM: 2046 MB (65% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:43:53 PM, on 12/16/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Documents and Settings\Owner\My Documents\My Stuff\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Owner.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: desktopComic.exe
O8 - Extra context menu item: &ieSpell; Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling; - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Owner\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {10093E98-C073-4C75-8D0E-FB5CD3A71D33} (ZoneUpwords Object) - http://messenger.zone.msn.com/binary/Upwords.cab57176.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} (get_atlcom Class) - http://apps.corel.com/nos_dl_manager_dev/p…IEGetPlugin.ocx
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1227657889875
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab57176.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O16 - DPF: {FF3C5A9F-5A91-4930-80E8-4709194C2AD3} (CheckersZPA Object) - http://zone.msn.com/bingame/zpagames/Check…PA.cab55579.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O23 - Service: McAfee Application Installer Cleanup (0148681227668442) (0148681227668442mcinstcleanup) - Unknown owner - C:\DOCUME~1\Owner\LOCALS~1\Temp\014868~1.EXE (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe

–
End of file - 10646 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\McDefragTask.job
C:\WINDOWS\tasks\McQcTask.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{089FD14D-132B-48FC-8861-0048AE113215}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2008-11-27 304736]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D; IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2008-09-15 1562960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java™ Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2008-11-10 320920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}]
scriptproxy - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll [2008-06-20 58688]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2007-09-20 328752]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}]
McAfee SiteAdvisor BHO - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll [2008-09-30 145424]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-11-10 34816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-11-10 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - McAfee SiteAdvisor Toolbar - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll [2008-09-30 145424]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"=C:\WINDOWS\stsystra.exe [2005-03-22 339968]
"mcagent_exe"=C:\Program Files\McAfee.com\Agent\mcagent.exe [2008-07-11 641208]
"dellsupportcenter"=C:\Program Files\Dell Support Center\bin\sprtcmd.exe [2008-08-26 206064]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-11-10 136600]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICustomerCare]
C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe [2007-10-04 307200]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dellsupportcenter]
C:\Program Files\Dell Support Center\bin\sprtcmd.exe [2008-08-26 206064]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-05-08 54840]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Pitstop Optimize Scheduler]
C:\Program Files\PCPitstop\Optimize\PCPOptimize.exe [2008-03-26 2577120]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVDDXSrv]
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe [2008-05-12 128296]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2008-09-16 1833296]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2008-08-29 61440]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe [2007-09-25 132496]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2006-02-19 288472]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Fast Start.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqthb08.exe [2006-02-10 73728]

C:\Documents and Settings\Owner\Start Menu\Programs\Startup
desktopComic.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2008-10-28 143360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDrives"=0
"NoDriveAutoRun"=67108863

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\CyberLink\PowerDVD DX\PowerDVD.exe"="C:\Program Files\CyberLink\PowerDVD DX\PowerDVD.exe:*:Enabled:CyberLink PowerDVD DX"
"C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"="C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe:*:Enabled:CyberLink PowerDVD DX Resident Program"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe"="C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"
"C:\Program Files\Microsoft Games\Viva Pinata\Viva Pinata.exe"="C:\Program Files\Microsoft Games\Viva Pinata\Viva Pinata.exe:*:Enabled:Viva Piñata"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\CyberLink\PowerDVD DX\PowerDVD.exe"="C:\Program Files\CyberLink\PowerDVD DX\PowerDVD.exe:*:Enabled:CyberLink PowerDVD DX"
"C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"="C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe:*:Enabled:CyberLink PowerDVD DX Resident Program"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

======List of files/folders created in the last 1 months======

2008-12-16 16:43:34 —-D—- C:\rsit
2008-12-16 16:42:44 —-D—- C:\ComboFix
2008-12-16 15:26:08 —-SHD—- C:\RECYCLER
2008-12-15 20:19:38 —-A—- C:\ComboFix.txt
2008-12-15 13:28:57 —-D—- C:\Program Files\QuickTime
2008-12-14 22:48:11 —-A—- C:\Boot.bak
2008-12-14 22:48:06 —-RASHD—- C:\cmdcons
2008-12-14 22:46:51 —-D—- C:\WINDOWS\ERDNT
2008-12-14 22:07:32 —-D—- C:\Documents and Settings\Owner\Application Data\IMVU
2008-12-14 22:07:27 —-D—- C:\Documents and Settings\Owner\Application Data\IMVUClient
2008-12-14 19:05:54 —-D—- C:\Documents and Settings\Owner\Application Data\ieSpell
2008-12-14 18:59:42 —-D—- C:\Program Files\Trend Micro
2008-12-12 15:30:52 —-D—- C:\Program Files\Will
2008-12-12 02:01:23 —-D—- C:\Documents and Settings\All Users\Application Data\pixelStorm
2008-12-12 01:15:45 —-A—- C:\WINDOWS\msnmsgr.exe.ini
2008-12-12 01:15:43 —-D—- C:\Documents and Settings\All Users\Application Data\MumboJumbo
2008-12-10 21:52:40 —-D—- C:\WINDOWS\system32\DRM
2008-12-10 15:39:28 —-HDC—- C:\WINDOWS\$NtUninstallKB955839$
2008-12-10 15:39:00 —-HDC—- C:\WINDOWS\$NtUninstallKB956802$
2008-12-10 15:38:55 —-HDC—- C:\WINDOWS\$NtUninstallKB954600$
2008-12-10 15:37:04 —-HDC—- C:\WINDOWS\$NtUninstallKB952069_WM9$
2008-12-10 15:28:39 —-A—- C:\WINDOWS\system32\vfwwdm32.dll
2008-12-10 15:20:16 —-D—- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-12-10 15:20:14 —-D—- C:\Program Files\Yahoo!
2008-12-10 15:04:28 —-A—- C:\WINDOWS\system32\javaws.exe
2008-12-10 15:04:28 —-A—- C:\WINDOWS\system32\javaw.exe
2008-12-10 15:04:28 —-A—- C:\WINDOWS\system32\java.exe
2008-12-04 17:03:50 —-A—- C:\WINDOWS\system32\D3DX9_37.dll
2008-12-04 17:03:50 —-A—- C:\WINDOWS\system32\d3dx10_37.dll
2008-12-04 17:03:50 —-A—- C:\WINDOWS\system32\D3DCompiler_37.dll
2008-12-04 17:03:41 —-D—- C:\WINDOWS\system32\xlive
2008-12-04 17:03:39 —-D—- C:\Program Files\Microsoft Games for Windows - LIVE
2008-12-04 16:58:27 —-D—- C:\Documents and Settings\Owner\Application Data\Microsoft Games
2008-12-04 16:57:35 —-A—- C:\WINDOWS\system32\xactengine2_9.dll
2008-12-04 16:57:35 —-A—- C:\WINDOWS\system32\d3dx10_35.dll
2008-12-04 16:57:34 —-A—- C:\WINDOWS\system32\xactengine2_8.dll
2008-12-04 16:57:34 —-A—- C:\WINDOWS\system32\x3daudio1_2.dll
2008-12-04 16:57:34 —-A—- C:\WINDOWS\system32\d3dx9_35.dll
2008-12-04 16:57:34 —-A—- C:\WINDOWS\system32\d3dx10_34.dll
2008-12-04 16:57:34 —-A—- C:\WINDOWS\system32\D3DCompiler_35.dll
2008-12-04 16:57:34 —-A—- C:\WINDOWS\system32\D3DCompiler_34.dll
2008-12-04 16:57:33 —-A—- C:\WINDOWS\system32\d3dx9_34.dll
2008-12-04 16:57:32 —-A—- C:\WINDOWS\system32\xactengine2_7.dll
2008-12-04 16:57:31 —-A—- C:\WINDOWS\system32\d3dx10_33.dll
2008-12-04 16:57:31 —-A—- C:\WINDOWS\system32\D3DCompiler_33.dll
2008-12-04 16:57:29 —-A—- C:\WINDOWS\system32\d3dx9_33.dll
2008-12-04 16:49:32 —-D—- C:\Documents and Settings\Owner\Application Data\InstallShield Installation Information
2008-12-04 16:26:54 —-D—- C:\Program Files\Microsoft Games
2008-12-03 21:18:52 —-D—- C:\Program Files\City of Heroes
2008-12-02 13:37:22 —-D—- C:\Program Files\DivX
2008-12-02 13:23:46 —-D—- C:\Documents and Settings\Owner\Application Data\Apple Computer
2008-11-30 21:27:39 —-A—- C:\WINDOWS\system32\W32n50.dll
2008-11-30 21:27:38 —-D—- C:\Program Files\Common Files\Motive
2008-11-30 01:58:36 —-A—- C:\WINDOWS\system32\deploytk.dll
2008-11-30 01:48:41 —-D—- C:\WINDOWS\Sun
2008-11-30 01:34:07 —-A—- C:\WINDOWS\system32\chsbrkr.dll
2008-11-30 01:34:06 —-A—- C:\WINDOWS\system32\korwbrkr.dll
2008-11-30 01:34:06 —-A—- C:\WINDOWS\system32\chtbrkr.dll
2008-11-30 01:34:05 —-A—- C:\WINDOWS\system32\msir3jp.dll
2008-11-30 01:33:54 —-A—- C:\WINDOWS\system32\kbd101a.dll
2008-11-30 01:33:47 —-A—- C:\WINDOWS\system32\kbdnecNT.dll
2008-11-30 01:33:47 —-A—- C:\WINDOWS\system32\kbdnecAT.dll
2008-11-30 01:33:47 —-A—- C:\WINDOWS\system32\kbdnec95.dll
2008-11-30 01:33:32 —-A—- C:\WINDOWS\system32\c_is2022.dll
2008-11-30 01:32:07 —-A—- C:\WINDOWS\system32\kbdkor.dll
2008-11-30 01:32:07 —-A—- C:\WINDOWS\system32\kbdjpn.dll
2008-11-30 01:32:07 —-A—- C:\WINDOWS\system32\kbd103.dll
2008-11-30 01:32:07 —-A—- C:\WINDOWS\system32\kbd101c.dll
2008-11-30 01:32:04 —-A—- C:\WINDOWS\system32\kbd101b.dll
2008-11-30 01:32:03 —-A—- C:\WINDOWS\system32\kbd106.dll
2008-11-29 21:23:16 —-D—- C:\Documents and Settings\Owner\Application Data\Roxio
2008-11-29 13:05:58 —-D—- C:\Documents and Settings\Owner\Application Data\Move Networks
2008-11-28 20:33:16 —-HD—- C:\WINDOWS\msdownld.tmp
2008-11-28 20:33:10 —-D—- C:\WINDOWS\Logs
2008-11-28 19:53:40 —-D—- C:\Program Files\Common Files\Adobe AIR
2008-11-28 19:53:08 —-D—- C:\Documents and Settings\All Users\Application Data\Adobe
2008-11-28 19:52:59 —-D—- C:\Program Files\Common Files\Adobe
2008-11-28 19:52:59 —-D—- C:\Program Files\Adobe
2008-11-28 19:48:22 —-D—- C:\Documents and Settings\All Users\Application Data\NOS
2008-11-28 19:48:19 —-D—- C:\Program Files\NOS
2008-11-27 20:04:13 —-A—- C:\WINDOWS\system32\wnaspi32.dll
2008-11-27 20:04:11 —-A—- C:\WINDOWS\system32\clrviddc.dll
2008-11-27 20:02:49 —-D—- C:\Program Files\Common Files\xing shared
2008-11-27 19:59:19 —-A—- C:\WINDOWS\cdplayer.ini
2008-11-27 17:45:38 —-A—- C:\WINDOWS\system32\rmoc3260.dll
2008-11-27 17:45:34 —-A—- C:\WINDOWS\system32\pndx5032.dll
2008-11-27 17:45:34 —-A—- C:\WINDOWS\system32\pndx5016.dll
2008-11-27 17:45:33 —-D—- C:\Program Files\Real
2008-11-27 17:45:33 —-A—- C:\WINDOWS\system32\pncrt.dll
2008-11-27 17:45:31 —-D—- C:\Program Files\Common Files\Real
2008-11-27 17:45:31 —-D—- C:\Documents and Settings\Owner\Application Data\Real
2008-11-27 17:43:58 —-D—- C:\Documents and Settings\All Users\Application Data\Corel
2008-11-27 17:43:24 —-D—- C:\Program Files\InterVideo
2008-11-27 17:43:23 —-D—- C:\Program Files\Common Files\Protexis
2008-11-27 17:43:23 —-D—- C:\Program Files\Common Files\InterVideo
2008-11-27 17:43:08 —-D—- C:\Program Files\Corel
2008-11-27 17:09:28 —-D—- C:\Documents and Settings\Owner\Application Data\MSNInstaller
2008-11-27 16:37:03 —-A—- C:\WINDOWS\system32\xactengine2_6.dll
2008-11-27 16:37:03 —-A—- C:\WINDOWS\system32\xactengine2_5.dll
2008-11-27 16:37:02 —-A—- C:\WINDOWS\system32\xinput1_3.dll
2008-11-27 16:37:02 —-A—- C:\WINDOWS\system32\xactengine2_4.dll
2008-11-27 16:37:02 —-A—- C:\WINDOWS\system32\x3daudio1_1.dll
2008-11-27 16:37:02 —-A—- C:\WINDOWS\system32\d3dx9_32.dll
2008-11-27 16:37:02 —-A—- C:\WINDOWS\system32\d3dx9_31.dll
2008-11-27 16:37:01 —-A—- C:\WINDOWS\system32\xinput1_2.dll
2008-11-27 16:37:01 —-A—- C:\WINDOWS\system32\xactengine2_3.dll
2008-11-27 16:37:01 —-A—- C:\WINDOWS\system32\xactengine2_2.dll
2008-11-27 16:37:00 —-A—- C:\WINDOWS\system32\xinput1_1.dll
2008-11-27 16:37:00 —-A—- C:\WINDOWS\system32\xactengine2_1.dll
2008-11-27 16:36:55 —-A—- C:\WINDOWS\system32\xactengine2_0.dll
2008-11-27 16:36:55 —-A—- C:\WINDOWS\system32\x3daudio1_0.dll
2008-11-27 16:36:55 —-A—- C:\WINDOWS\system32\d3dx9_30.dll
2008-11-27 16:36:55 —-A—- C:\WINDOWS\system32\d3dx9_29.dll
2008-11-27 16:36:54 —-A—- C:\WINDOWS\system32\xinput9_1_0.dll
2008-11-27 16:36:54 —-A—- C:\WINDOWS\system32\d3dx9_28.dll
2008-11-27 16:36:54 —-A—- C:\WINDOWS\system32\d3dx9_27.dll
2008-11-27 16:36:53 —-A—- C:\WINDOWS\system32\d3dx9_26.dll
2008-11-27 16:36:53 —-A—- C:\WINDOWS\system32\d3dx9_25.dll
2008-11-27 16:36:52 —-A—- C:\WINDOWS\system32\d3dx9_24.dll
2008-11-27 15:52:03 —-D—- C:\Program Files\ieSpell
2008-11-27 15:50:35 —-D—- C:\DECCHECK
2008-11-27 15:45:13 —-D—- C:\Documents and Settings\All Users\Application Data\CyberLink
2008-11-27 14:04:32 —-D—- C:\Documents and Settings\All Users\Application Data\SupportSoft
2008-11-27 14:04:28 —-D—- C:\Documents and Settings\All Users\Application Data\PCDr
2008-11-27 14:04:28 —-D—- C:\Documents and Settings\All Users\Application Data\PC-Doctor
2008-11-27 14:03:36 —-D—- C:\Program Files\Dell Support Center
2008-11-27 14:03:35 —-D—- C:\Program Files\Common Files\supportsoft
2008-11-27 13:44:25 —-D—- C:\Program Files\MSXML 4.0
2008-11-27 13:39:16 —-D—- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-11-27 13:39:01 —-D—- C:\Program Files\Apple Software Update
2008-11-27 13:39:01 —-D—- C:\Documents and Settings\All Users\Application Data\Apple
2008-11-26 23:47:54 —-D—- C:\Documents and Settings\All Users\Application Data\HP Product Assistant
2008-11-26 23:44:33 —-D—- C:\Documents and Settings\Owner\Application Data\HP
2008-11-26 23:43:19 —-D—- C:\Documents and Settings\All Users\Application Data\HP
2008-11-26 23:42:13 —-D—- C:\bin
2008-11-26 23:38:47 —-D—- C:\Program Files\Common Files\HP
2008-11-26 23:35:52 —-D—- C:\Program Files\Hewlett-Packard
2008-11-26 23:35:21 —-D—- C:\Program Files\Common Files\Hewlett-Packard
2008-11-26 23:34:08 —-RA—- C:\WINDOWS\system32\HPZIDS01.dll
2008-11-26 23:34:05 —-A—- C:\WINDOWS\system32\hpz3l054.dll
2008-11-26 18:24:51 —-D—- C:\Program Files\HP
2008-11-26 18:23:55 —-HD—- C:\Config.Msi
2008-11-26 18:20:34 —-A—- C:\WINDOWS\system32\hpotiop2.dll
2008-11-26 18:20:33 —-A—- C:\WINDOWS\system32\hpzjsn01.dll
2008-11-26 18:20:33 —-A—- C:\WINDOWS\system32\HPZc3212.dll
2008-11-26 18:20:33 —-A—- C:\WINDOWS\system32\hpovst09.dll
2008-11-26 17:38:11 —-D—- C:\Documents and Settings\Owner\Application Data\Mozilla
2008-11-26 17:38:05 —-D—- C:\Program Files\Mozilla Firefox
2008-11-26 17:15:54 —-A—- C:\WINDOWS\ODBC.INI
2008-11-26 17:15:46 —-A—- C:\WINDOWS\system32\mdimon.dll
2008-11-26 17:14:50 —-D—- C:\Program Files\Microsoft ActiveSync
2008-11-26 17:14:25 —-D—- C:\Program Files\Common Files\DESIGNER
2008-11-26 17:14:07 —-D—- C:\WINDOWS\SHELLNEW
2008-11-26 17:13:31 —-D—- C:\Program Files\Microsoft.NET
2008-11-26 17:13:31 —-D—- C:\Program Files\Microsoft Office
2008-11-26 17:11:50 —-RHD—- C:\MSOCache
2008-11-26 11:10:01 —-A—- C:\WINDOWS\wininit.ini
2008-11-26 10:04:38 —-A—- C:\WINDOWS\system32\mucltui.dll.mui
2008-11-26 10:04:38 —-A—- C:\WINDOWS\system32\mucltui.dll
2008-11-25 23:30:57 —-D—- C:\Documents and Settings\Owner\Application Data\Malwarebytes
2008-11-25 23:30:46 —-D—- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-11-25 23:30:45 —-D—- C:\Program Files\Malwarebytes' Anti-Malware
2008-11-25 23:30:25 —-D—- C:\Program Files\Common Files\Download Manager
2008-11-25 23:01:17 —-D—- C:\Documents and Settings\All Users\Application Data\Blizzard
2008-11-25 21:14:31 —-D—- C:\WINDOWS\system32\Garfield 9 Lives dir
2008-11-25 21:13:28 —-D—- C:\WINDOWS\system32\Garfield Midnight Snack dir
2008-11-25 19:43:00 —-D—- C:\Logs
2008-11-25 19:33:12 —-D—- C:\Program Files\PCPitstop
2008-11-25 18:50:10 —-D—- C:\Documents and Settings\Owner\Application Data\Macromedia
2008-11-25 18:50:09 —-D—- C:\Documents and Settings\Owner\Application Data\Adobe
2008-11-25 17:52:22 —-SHDC—- C:\Program Files\Common Files\WindowsLiveInstaller
2008-11-25 17:52:18 —-D—- C:\Program Files\Windows Live
2008-11-25 17:52:10 —-D—- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-11-25 16:23:11 —-HDC—- C:\WINDOWS\$NtUninstallKB954459$
2008-11-25 16:18:25 —-HDC—- C:\WINDOWS\$NtUninstallKB954154_WM11$
2008-11-25 16:18:21 —-HDC—- C:\WINDOWS\$NtUninstallKB929399$
2008-11-25 16:18:04 —-HDC—- C:\WINDOWS\$NtUninstallKB936782_WMP11$
2008-11-25 16:17:52 —-HDC—- C:\WINDOWS\$NtUninstallKB939683$
2008-11-25 16:17:25 —-D—- C:\WINDOWS\ie7updates
2008-11-25 16:17:07 —-HDC—- C:\WINDOWS\$NtUninstallKB951978$
2008-11-25 16:06:35 —-D—- C:\Program Files\World of Warcraft
2008-11-25 16:06:35 —-D—- C:\Program Files\Common Files\Blizzard Entertainment
2008-11-25 15:20:04 —-D—- C:\Program Files\Spybot - Search & Destroy
2008-11-25 15:20:04 —-D—- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-25 15:16:12 —-AD—- C:\Documents and Settings\All Users\Application Data\TEMP
2008-11-25 15:16:09 —-A—- C:\WINDOWS\system32\MSSTDFMT.DLL
2008-11-25 15:16:08 —-D—- C:\Program Files\SpywareBlaster
2008-11-25 14:51:41 —-A—- C:\WINDOWS\system32\wmpns.dll
2008-11-25 14:49:19 —-D—- C:\WINDOWS\Prefetch
2008-11-25 14:47:15 —-HDC—- C:\WINDOWS\$NtUninstallKB958644$
2008-11-25 14:47:09 —-HDC—- C:\WINDOWS\$NtUninstallKB957097$
2008-11-25 14:47:02 —-HDC—- C:\WINDOWS\$NtUninstallKB957095$
2008-11-25 14:46:55 —-HDC—- C:\WINDOWS\$NtUninstallKB956841$
2008-11-25 14:46:48 —-HDC—- C:\WINDOWS\$NtUninstallKB956803$
2008-11-25 14:46:39 —-HDC—- C:\WINDOWS\$NtUninstallKB955069$
2008-11-25 14:46:32 —-HDC—- C:\WINDOWS\$NtUninstallKB954211$
2008-11-25 14:46:26 —-HDC—- C:\WINDOWS\$NtUninstallKB952954$
2008-11-25 14:46:20 —-HDC—- C:\WINDOWS\$NtUninstallKB952287$
2008-11-25 14:46:12 —-HDC—- C:\WINDOWS\$NtUninstallKB951748$
2008-11-25 14:46:05 —-HDC—- C:\WINDOWS\$NtUninstallKB951698$
2008-11-25 14:45:59 —-HDC—- C:\WINDOWS\$NtUninstallKB951376-v2$
2008-11-25 14:45:51 —-HDC—- C:\WINDOWS\$NtUninstallKB951066$
2008-11-25 14:45:44 —-HDC—- C:\WINDOWS\$NtUninstallKB950974$
2008-11-25 14:45:38 —-HDC—- C:\WINDOWS\$NtUninstallKB950762$
2008-11-25 14:45:31 —-HDC—- C:\WINDOWS\$NtUninstallKB946648$
2008-11-25 14:45:25 —-HDC—- C:\WINDOWS\$NtUninstallKB938464$
2008-11-25 14:45:19 —-HDC—- C:\WINDOWS\$NtUninstallKB915800-v4$
2008-11-25 14:42:51 —-D—- C:\WINDOWS\system32\scripting
2008-11-25 14:42:50 —-D—- C:\WINDOWS\system32\en
2008-11-25 14:42:50 —-D—- C:\WINDOWS\system32\bits
2008-11-25 14:42:50 —-D—- C:\WINDOWS\l2schemas
2008-11-25 14:40:52 —-D—- C:\WINDOWS\ServicePackFiles
2008-11-25 14:39:26 —-D—- C:\WINDOWS\network diagnostic
2008-11-25 14:34:55 —-HDC—- C:\WINDOWS\$NtServicePackUninstall$
2008-11-25 14:34:53 —-D—- C:\WINDOWS\EHome
2008-11-25 14:09:51 —-D—- C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-11-25 14:08:43 —-D—- C:\Program Files\McAfee.com
2008-11-25 14:08:40 —-D—- C:\Program Files\Common Files\McAfee
2008-11-25 14:08:31 —-D—- C:\Program Files\McAfee
2008-11-25 14:06:00 —-D—- C:\Documents and Settings\All Users\Application Data\McAfee
2008-11-25 13:58:15 —-D—- C:\WINDOWS\SxsCaPendDel
2008-11-25 13:52:59 —-D—- C:\WINDOWS\pss
2008-11-25 13:50:11 —-D—- C:\WINDOWS\system32\ReinstallBackups
2008-11-25 13:50:09 —-A—- C:\WINDOWS\system32\results.txt
2008-11-25 13:50:06 —-A—- C:\WINDOWS\system32\GTW32N50.dll
2008-11-25 13:49:59 —-D—- C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor
2008-11-25 13:49:54 —-A—- C:\WINDOWS\system32\WLAN.INI
2008-11-25 13:46:14 —-D—- C:\Program Files\WebEx
2008-11-25 13:46:07 —-D—- C:\Documents and Settings\All Users\Application Data\Linksys
2008-11-25 13:45:53 —-D—- C:\Program Files\Java
2008-11-25 13:45:52 —-D—- C:\Program Files\Common Files\Java
2008-11-25 13:45:46 —-D—- C:\Documents and Settings\Owner\Application Data\Sun
2008-11-25 13:45:35 —-DC—- C:\WINDOWS\system32\DRVSTORE
2008-11-25 13:37:16 —-D—- C:\Documents and Settings\Owner\Application Data\Windows Search
2008-11-25 13:37:13 —-D—- C:\Documents and Settings\Owner\Application Data\ATI
2008-11-25 13:37:13 —-D—- C:\Documents and Settings\All Users\Application Data\ATI
2008-11-25 13:35:40 —-HDC—- C:\WINDOWS\$NtUninstallKB957097_0$
2008-11-25 13:35:04 —-A—- C:\WINDOWS\system32\MRT.exe
2008-11-25 13:35:00 —-HDC—- C:\WINDOWS\$NtUninstallKB955069_0$
2008-11-25 13:34:54 —-HDC—- C:\WINDOWS\$NtUninstallKB958644_0$
2008-11-25 13:34:51 —-D—- C:\Program Files\Microsoft Silverlight
2008-11-25 13:34:43 —-HDC—- C:\WINDOWS\$NtUninstallKB956390$
2008-11-25 13:34:36 —-HDC—- C:\WINDOWS\$NtUninstallKB957095_0$
2008-11-25 13:34:29 —-HDC—- C:\WINDOWS\$NtUninstallKB956841_0$
2008-11-25 13:34:23 —-HDC—- C:\WINDOWS\$NtUninstallKB956803_0$
2008-11-25 13:34:18 —-HDC—- C:\WINDOWS\$NtUninstallKB956391$
2008-11-25 13:34:13 —-HDC—- C:\WINDOWS\$NtUninstallKB954211_0$
2008-11-25 13:33:46 —-D—- C:\Program Files\MSBuild
2008-11-25 13:30:42 —-D—- C:\WINDOWS\system32\XPSViewer
2008-11-25 13:30:26 —-D—- C:\Program Files\Reference Assemblies
2008-11-25 13:30:04 —-N—- C:\WINDOWS\system32\spmsg2.dll
2008-11-25 13:29:57 —-HDC—- C:\WINDOWS\$NtUninstallWIC$
2008-11-25 13:29:52 —-D—- C:\063d86031033552844923f63d011ae
2008-11-25 13:29:49 —-HDC—- C:\WINDOWS\$NtUninstallKB938464_0$
2008-11-25 13:29:44 —-HDC—- C:\WINDOWS\$NtUninstallKB952287_0$
2008-11-25 13:29:39 —-HDC—- C:\WINDOWS\$NtUninstallKB951072-v2$
2008-11-25 13:29:34 —-HDC—- C:\WINDOWS\$NtUninstallKB950974_0$
2008-11-25 13:29:29 —-HDC—- C:\WINDOWS\$NtUninstallKB952954_0$
2008-11-25 13:29:24 —-HDC—- C:\WINDOWS\$NtUninstallKB946648_0$
2008-11-25 13:29:19 —-HDC—- C:\WINDOWS\$NtUninstallKB951066_0$
2008-11-25 13:29:15 —-HDC—- C:\WINDOWS\$NtUninstallKB944338-v2$
2008-11-25 13:29:08 —-HDC—- C:\WINDOWS\$NtUninstallKB951748_0$
2008-11-25 13:28:42 —-D—- C:\WINDOWS\system32\GroupPolicy
2008-11-25 13:28:42 —-D—- C:\Program Files\Windows Desktop Search
2008-11-25 13:28:30 —-HDC—- C:\WINDOWS\$NtUninstallKB915800-v4_0$
2008-11-25 13:28:14 —-HDC—- C:\WINDOWS\$NtUninstallKB951698_0$
2008-11-25 13:28:11 —-HDC—- C:\WINDOWS\$NtUninstallKB951376-v2_0$
2008-11-25 13:28:06 —-HDC—- C:\WINDOWS\$NtUninstallKB950762_0$
2008-11-25 13:27:59 —-HDC—- C:\WINDOWS\$NtUninstallKB941569$
2008-11-25 13:27:39 —-HDC—- C:\WINDOWS\$NtUninstallKB950749$
2008-11-25 13:27:25 —-D—- C:\WINDOWS\WBEM
2008-11-25 13:27:11 —-HDC—- C:\WINDOWS\ie7
2008-11-25 13:27:03 —-HDC—- C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$
2008-11-25 13:26:50 —-HDC—- C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$
2008-11-25 13:26:36 —-HDC—- C:\WINDOWS\$NtUninstallKB915865$
2008-11-25 13:26:32 —-N—- C:\WINDOWS\system32\xmllite.dll
2008-11-25 13:24:01 —-HDC—- C:\WINDOWS\$NtUninstallKB926239$
2008-11-25 13:23:56 —-N—- C:\WINDOWS\system32\spmsg.dll
2008-11-25 13:23:55 —-HDC—- C:\WINDOWS\$NtUninstallMSCompPackV1$
2008-11-25 13:23:46 —-D—- C:\Program Files\Windows Media Connect 2
2008-11-25 13:23:41 —-HDC—- C:\WINDOWS\$NtUninstallwmp11$
2008-11-25 13:23:15 —-HDC—- C:\WINDOWS\$NtUninstallWMFDist11$
2008-11-25 13:23:01 —-D—- C:\WINDOWS\system32\LogFiles
2008-11-25 13:22:59 —-HDC—- C:\WINDOWS\$NtUninstallWudf01000$
2008-11-25 13:22:44 —-HDC—- C:\WINDOWS\$NtUninstallKB948590$
2008-11-25 13:22:39 —-HDC—- C:\WINDOWS\$NtUninstallKB945553$
2008-11-25 13:22:34 —-HDC—- C:\WINDOWS\$NtUninstallKB943055$
2008-11-25 13:22:29 —-HDC—- C:\WINDOWS\$NtUninstallKB946026$
2008-11-25 13:22:24 —-HDC—- C:\WINDOWS\$NtUninstallKB943485$
2008-11-25 13:22:20 —-HDC—- C:\WINDOWS\$NtUninstallKB944653$
2008-11-25 13:22:15 —-HDC—- C:\WINDOWS\$NtUninstallKB936357$
2008-11-25 13:22:09 —-HDC—- C:\WINDOWS\$NtUninstallKB943460$
2008-11-25 13:22:02 —-HDC—- C:\WINDOWS\$NtUninstallKB933729$
2008-11-25 13:21:56 —-HDC—- C:\WINDOWS\$NtUninstallKB938127$
2008-11-25 13:21:52 —-HDC—- C:\WINDOWS\$NtUninstallKB936782_WMP9$
2008-11-25 13:21:39 —-HDC—- C:\WINDOWS\$NtUninstallKB938828$
2008-11-25 13:21:34 —-HDC—- C:\WINDOWS\$NtUninstallKB925398_WMP64$
2008-11-25 13:21:22 —-HDC—- C:\WINDOWS\$NtUninstallKB935839$
2008-11-25 13:21:17 —-HDC—- C:\WINDOWS\$NtUninstallKB935840$
2008-11-25 13:21:11 —-HDC—- C:\WINDOWS\$NtUninstallKB929123$
2008-11-25 13:21:05 —-HDC—- C:\WINDOWS\$NtUninstallKB927891$
2008-11-25 13:21:00 —-HDC—- C:\WINDOWS\$NtUninstallKB930916$
2008-11-25 13:20:55 —-HDC—- C:\WINDOWS\$NtUninstallKB920213$
2008-11-25 13:20:50 —-HDC—- C:\WINDOWS\$NtUninstallKB890046$
2008-11-25 13:20:45 —-HDC—- C:\WINDOWS\$NtUninstallKB932168$
2008-11-25 13:20:39 —-HDC—- C:\WINDOWS\$NtUninstallKB931261$
2008-11-25 13:20:33 —-HDC—- C:\WINDOWS\$NtUninstallKB930178$
2008-11-25 13:20:27 —-HDC—- C:\WINDOWS\$NtUninstallKB925902$
2008-11-25 13:20:21 —-D—- C:\WINDOWS\system32\en-us
2008-11-25 13:20:19 —-HDC—- C:\WINDOWS\$NtUninstallKB925876$
2008-11-25 13:20:14 —-HDC—- C:\WINDOWS\$NtUninstallKB926436$
2008-11-25 13:20:08 —-HDC—- C:\WINDOWS\$NtUninstallKB918118$
2008-11-25 13:20:03 —-HDC—- C:\WINDOWS\$NtUninstallKB927779$
2008-11-25 13:19:58 —-HDC—- C:\WINDOWS\$NtUninstallKB924667$
2008-11-25 13:19:53 —-HDC—- C:\WINDOWS\$NtUninstallKB927802$
2008-11-25 13:19:48 —-HDC—- C:\WINDOWS\$NtUninstallKB928843$
2008-11-25 13:19:41 —-HDC—- C:\WINDOWS\$NtUninstallKB928255$
2008-11-25 13:19:35 —-HDC—- C:\WINDOWS\$NtUninstallKB926255$
2008-11-25 13:19:30 —-HDC—- C:\WINDOWS\$NtUninstallKB923980$
2008-11-25 13:19:25 —-HDC—- C:\WINDOWS\$NtUninstallKB924270$
2008-11-25 13:19:20 —-HDC—- C:\WINDOWS\$NtUninstallKB923191$
2008-11-25 13:19:14 —-HDC—- C:\WINDOWS\$NtUninstallKB924496$
2008-11-25 13:19:06 —-HDC—- C:\WINDOWS\$NtUninstallKB920872$
2008-11-25 13:18:58 —-HDC—- C:\WINDOWS\$NtUninstallKB920685$
2008-11-25 13:18:53 —-HDC—- C:\WINDOWS\$NtUninstallKB916595$
2008-11-25 13:18:46 —-HDC—- C:\WINDOWS\$NtUninstallKB922582$
2008-11-25 13:18:40 —-HDC—- C:\WINDOWS\$NtUninstallKB920683$
2008-11-25 13:18:35 —-HDC—- C:\WINDOWS\$NtUninstallKB920670$
2008-11-25 13:18:29 —-HDC—- C:\WINDOWS\$NtUninstallKB914388$
2008-11-25 13:18:24 —-HDC—- C:\WINDOWS\$NtUninstallKB904942$
2008-11-25 13:18:19 —-HDC—- C:\WINDOWS\$NtUninstallKB911280$
2008-11-25 13:18:13 —-HDC—- C:\WINDOWS\$NtUninstallKB913580$
2008-11-25 13:18:08 —-HDC—- C:\WINDOWS\$NtUninstallKB918439$
2008-11-25 13:18:03 —-HDC—- C:\WINDOWS\$NtUninstallKB914389$
2008-11-25 13:17:57 —-HDC—- C:\WINDOWS\$NtUninstallKB908531$
2008-11-25 13:17:51 —-HDC—- C:\WINDOWS\$NtUninstallKB900485$
2008-11-25 13:17:44 —-HDC—- C:\WINDOWS\$NtUninstallKB911562$
2008-11-25 13:17:40 —-HDC—- C:\WINDOWS\$NtUninstallKB911564$
2008-11-25 13:17:29 —-HDC—- C:\WINDOWS\$NtUninstallKB911927$
2008-11-25 13:15:23 —-HDC—- C:\WINDOWS\$NtUninstallKB908519$
2008-11-25 13:15:18 —-HDC—- C:\WINDOWS\$NtUninstallKB910437$
2008-11-25 13:15:13 —-HDC—- C:\WINDOWS\$NtUninstallbasecsp$
2008-11-25 13:15:11 —-HDC—- C:\WINDOWS\$NtUninstallKB891122$
2008-11-25 13:15:00 —-D—- C:\WINDOWS\RegisteredPackages
2008-11-25 13:14:42 —-HDC—- C:\WINDOWS\$NtUninstallKB900725$
2008-11-25 13:14:37 —-HDC—- C:\WINDOWS\$NtUninstallKB905749$
2008-11-25 13:14:33 —-HDC—- C:\WINDOWS\$NtUninstallKB905414$
2008-11-25 13:14:28 —-HDC—- C:\WINDOWS\$NtUninstallKB901017$
2008-11-25 13:14:19 —-HDC—- C:\WINDOWS\$NtUninstallKB902400$
2008-11-25 13:14:13 —-HDC—- C:\WINDOWS\$NtUninstallKB894391$
2008-11-25 13:14:08 —-HDC—- C:\WINDOWS\$NtUninstallKB896423$
2008-11-25 13:14:04 —-HDC—- C:\WINDOWS\$NtUninstallKB899587$
2008-11-25 13:13:59 —-HDC—- C:\WINDOWS\$NtUninstallKB899591$
2008-11-25 13:13:55 —-HDC—- C:\WINDOWS\$NtUninstallKB893756$
2008-11-25 13:13:50 —-HDC—- C:\WINDOWS\$NtUninstallKB896358$
2008-11-25 13:13:44 —-HDC—- C:\WINDOWS\$NtUninstallKB890859$
2008-11-25 13:13:39 —-HDC—- C:\WINDOWS\$NtUninstallKB901214$
2008-11-25 13:13:32 —-HDC—- C:\WINDOWS\$NtUninstallKB912812$
2008-11-25 13:13:27 —-HDC—- C:\WINDOWS\$NtUninstallKB896344$
2008-11-25 13:13:22 —-HDC—- C:\WINDOWS\$NtUninstallKB896428$
2008-11-25 13:13:17 —-HDC—- C:\WINDOWS\$NtUninstallKB885835$
2008-11-25 13:13:12 —-HDC—- C:\WINDOWS\$NtUninstallKB891781$
2008-11-25 13:13:07 —-HDC—- C:\WINDOWS\$NtUninstallKB887472$
2008-11-25 13:13:02 —-HDC—- C:\WINDOWS\$NtUninstallKB888302$
2008-11-25 13:12:58 —-HDC—- C:\WINDOWS\$NtUninstallKB885836$
2008-11-25 13:12:53 —-HDC—- C:\WINDOWS\$NtUninstallKB886185$
2008-11-25 13:12:47 —-HDC—- C:\WINDOWS\$NtUninstallKB873339$
2008-11-25 13:12:03 —-RSD—- C:\WINDOWS\assembly
2008-11-25 13:12:03 —-D—- C:\WINDOWS\Microsoft.NET
2008-11-25 13:12:02 —-D—- C:\WINDOWS\system32\URTTemp
2008-11-25 13:01:50 —-N—- C:\WINDOWS\system32\tsgqec.dll
2008-11-25 13:01:50 —-N—- C:\WINDOWS\system32\rhttpaa.dll
2008-11-25 13:01:50 —-N—- C:\WINDOWS\system32\aaclient.dll
2008-11-25 12:40:09 —-HDC—- C:\WINDOWS\$MSI31Uninstall_KB893803v2$
2008-11-25 12:39:19 —-D—- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-11-25 12:39:12 —-D—- C:\WINDOWS\system32\PreInstall
2008-11-25 12:39:12 —-A—- C:\WINDOWS\system32\spupdsvc.exe
2008-11-25 12:39:11 —-HDC—- C:\WINDOWS\$NtUninstallKB898461$
2008-11-25 12:35:00 —-D—- C:\WINDOWS\system32\SoftwareDistribution
2008-11-25 12:32:32 —-D—- C:\drvrtmp
2008-11-25 12:32:32 —-A—- C:\WINDOWS\system32\Prounstl.exe
2008-11-25 12:32:32 —-A—- C:\WINDOWS\system32\IntelNic.dll
2008-11-25 12:32:32 —-A—- C:\WINDOWS\system32\EtCoInst.dll
2008-11-25 12:23:53 —-D—- C:\Program Files\ATI
2008-11-25 12:23:22 —-N—- C:\WINDOWS\system32\ati2sgag.exe
2008-11-25 12:23:08 —-D—- C:\Program Files\ATI Technologies
2008-11-25 12:22:45 —-D—- C:\ATI
2008-11-25 12:22:12 —-A—- C:\WINDOWS\stsystra.exe
2008-11-25 12:22:11 —-A—- C:\WINDOWS\system32\ksuser.dll
2008-11-25 12:22:10 —-A—- C:\WINDOWS\system32\staco.dll
2008-11-25 12:22:01 —-HDC—- C:\WINDOWS\$NtUninstallKB835221WXP$
2008-11-25 12:22:00 —-D—- C:\Program Files\SigmaTel
2008-11-25 12:22:00 —-A—- C:\WINDOWS\system32\stacapi.dll
2008-11-25 12:20:58 —-D—- C:\Documents and Settings\All Users\Application Data\Uninstall
2008-11-25 12:20:57 —-D—- C:\Program Files\Common Files\SureThing Shared
2008-11-25 12:20:14 —-D—- C:\Documents and Settings\All Users\Application Data\Sonic
2008-11-25 12:20:10 —-D—- C:\Program Files\Common Files\Sonic Shared
2008-11-25 12:19:18 —-D—- C:\Program Files\Common Files\Roxio Shared
2008-11-25 12:19:15 —-D—- C:\Program Files\Roxio
2008-11-25 12:19:15 —-D—- C:\Documents and Settings\All Users\Application Data\InstallShield
2008-11-25 12:16:37 —-RA—- C:\WINDOWS\system32\hhactivex.dll
2008-11-25 12:16:37 —-A—- C:\WINDOWS\system32\RcdScan.dll
2008-11-25 12:16:35 —-A—- C:\WINDOWS\system32\VB5DB.DLL
2008-11-25 12:16:13 —-D—- C:\Documents and Settings\Owner\Application Data\CyberLink
2008-11-25 12:15:31 —-D—- C:\Documents and Settings\All Users\Application Data\Dell
2008-11-25 12:15:06 —-HD—- C:\Program Files\InstallShield Installation Information
2008-11-25 12:15:06 —-D—- C:\Program Files\CyberLink
2008-11-25 12:15:06 —-A—- C:\WINDOWS\system32\msvcr71.dll
2008-11-25 12:15:06 —-A—- C:\WINDOWS\system32\msvcp71.dll
2008-11-25 12:15:06 —-A—- C:\WINDOWS\system32\MFC71u.dll
2008-11-25 12:15:06 —-A—- C:\WINDOWS\system32\MFC71.dll
2008-11-25 12:15:06 —-A—- C:\WINDOWS\system32\atl71.dll
2008-11-25 12:14:45 —-D—- C:\Program Files\Common Files\InstallShield
2008-11-25 12:12:01 —-D—- C:\Documents and Settings\Owner\Application Data\Identities
2008-11-25 12:11:59 —-HD—- C:\Program Files\Uninstall Information
2008-11-25 12:11:54 —-SD—- C:\Documents and Settings\Owner\Application Data\Microsoft
2008-11-25 12:11:54 —-ASH—- C:\Documents and Settings\Owner\Application Data\desktop.ini
2008-11-25 12:11:50 —-D—- C:\WINDOWS\SoftwareDistribution
2008-11-25 12:11:48 —-SD—- C:\WINDOWS\system32\Microsoft
2008-11-25 12:11:48 —-A—- C:\WINDOWS\SchedLgU.Txt
2008-11-25 12:08:57 —-D—- C:\WINDOWS\system32\xircom
2008-11-25 12:08:57 —-D—- C:\Program Files\xerox
2008-11-25 12:08:57 —-D—- C:\Program Files\microsoft frontpage
2008-11-25 12:08:55 —-D—- C:\DELL
2008-11-25 12:08:47 —-HD—- C:\WINDOWS\$hf_mig$
2008-11-25 12:08:45 —-A—- C:\WINDOWS\system32\xpsp3res.dll
2008-11-25 12:08:40 —-A—- C:\WINDOWS\control.ini
2008-11-25 12:08:40 —-A—- C:\AUTOEXEC.BAT
2008-11-25 12:08:32 —-A—- C:\WINDOWS\system32\mapi32.dll
2008-11-25 12:07:54 —-SD—- C:\WINDOWS\Downloaded Program Files
2008-11-25 12:07:54 —-RD—- C:\WINDOWS\Offline Web Pages
2008-11-25 12:07:54 —-RAH—- C:\WINDOWS\system32\logonui.exe.manifest
2008-11-25 12:07:49 —-RAH—- C:\WINDOWS\system32\cdplayer.exe.manifest
2008-11-25 12:07:46 —-HD—- C:\Program Files\WindowsUpdate
2008-11-25 12:07:34 —-D—- C:\WINDOWS\system32\DirectX
2008-11-25 12:07:18 —-A—- C:\WINDOWS\system32\atrace.dll
2008-11-25 12:07:15 —-A—- C:\WINDOWS\system32\desktop.ini
2008-11-25 12:07:15 —-A—- C:\WINDOWS\desktop.ini
2008-11-25 12:07:10 —-A—- C:\WINDOWS\system32\nmevtmsg.dll
2008-11-25 12:07:09 —-A—- C:\WINDOWS\system32\acctres.dll
2008-11-25 12:07:08 —-D—- C:\Program Files\Common Files\Services
2008-11-25 12:07:06 —-SD—- C:\WINDOWS\Tasks
2008-11-25 12:07:06 —-D—- C:\Program Files\Common Files\MSSoap
2008-11-25 12:07:06 —-A—- C:\WINDOWS\system32\icfgnt5.dll
2008-11-25 12:07:02 —-D—- C:\WINDOWS\system32\Macromed
2008-11-25 12:07:02 —-D—- C:\WINDOWS\srchasst
2008-11-25 12:06:59 —-A—- C:\WINDOWS\system32\wuweb.dll
2008-11-25 12:06:59 —-A—- C:\WINDOWS\system32\wups.dll
2008-11-25 12:06:59 —-A—- C:\WINDOWS\system32\wucltui.dll
2008-11-25 12:06:59 —-A—- C:\WINDOWS\system32\wuauserv.dll
2008-11-25 12:06:59 —-A—- C:\WINDOWS\system32\wuaueng1.dll
2008-11-25 12:06:59 —-A—- C:\WINDOWS\system32\wuaueng.dll
2008-11-25 12:06:59 —-A—- C:\WINDOWS\system32\wuauclt1.exe
2008-11-25 12:06:59 —-A—- C:\WINDOWS\system32\wuauclt.exe
2008-11-25 12:06:59 —-A—- C:\WINDOWS\system32\wuapi.dll
2008-11-25 12:06:59 —-A—- C:\WINDOWS\system32\bitsprx3.dll
2008-11-25 12:06:58 —-A—- C:\WINDOWS\system32\qmgrprxy.dll
2008-11-25 12:06:58 —-A—- C:\WINDOWS\system32\qmgr.dll
2008-11-25 12:06:58 —-A—- C:\WINDOWS\system32\bitsprx2.dll
2008-11-25 12:06:55 —-D—- C:\Program Files\Movie Maker
2008-11-25 12:06:52 —-A—- C:\WINDOWS\system32\safrslv.dll
2008-11-25 12:06:52 —-A—- C:\WINDOWS\system32\safrdm.dll
2008-11-25 12:06:52 —-A—- C:\WINDOWS\system32\safrcdlg.dll
2008-11-25 12:06:52 —-A—- C:\WINDOWS\system32\racpldlg.dll
2008-11-25 12:06:49 —-D—- C:\WINDOWS\system32\Restore
2008-11-25 12:06:49 —-A—- C:\WINDOWS\system32\srsvc.dll
2008-11-25 12:06:49 —-A—- C:\WINDOWS\system32\srrstr.dll
2008-11-25 12:06:49 —-A—- C:\WINDOWS\system32\srclient.dll
2008-11-25 12:06:49 —-A—- C:\WINDOWS\system32\fltmc.exe
2008-11-25 12:06:49 —-A—- C:\WINDOWS\system32\fltlib.dll
2008-11-25 12:06:48 —-A—- C:\WINDOWS\system32\nmmkcert.dll
2008-11-25 12:06:48 —-A—- C:\WINDOWS\system32\msconf.dll
2008-11-25 12:06:48 —-A—- C:\WINDOWS\system32\mnmsrvc.exe
2008-11-25 12:06:48 —-A—- C:\WINDOWS\system32\mnmdd.dll
2008-11-25 12:06:48 —-A—- C:\WINDOWS\system32\isrdbg32.dll
2008-11-25 12:06:48 —-A—- C:\WINDOWS\system32\ils.dll
2008-11-25 12:06:45 —-D—- C:\Program Files\NetMeeting
2008-11-25 12:06:45 —-A—- C:\WINDOWS\system32\msoert2.dll
2008-11-25 12:06:45 —-A—- C:\WINDOWS\system32\msoeacct.dll
2008-11-25 12:06:44 —-A—- C:\WINDOWS\system32\inetres.dll
2008-11-25 12:06:44 —-A—- C:\WINDOWS\system32\inetcomm.dll
2008-11-25 12:06:43 —-D—- C:\Program Files\Outlook Express
2008-11-25 12:06:43 —-A—- C:\WINDOWS\system32\schedsvc.dll
2008-11-25 12:06:43 —-A—- C:\WINDOWS\system32\mstinit.exe
2008-11-25 12:06:42 —-A—- C:\WINDOWS\system32\mstask.dll
2008-11-25 12:06:42 —-A—- C:\WINDOWS\system32\isign32.dll
2008-11-25 12:06:42 —-A—- C:\WINDOWS\system32\inetcfg.dll
2008-11-25 12:06:42 —-A—- C:\WINDOWS\system32\icwphbk.dll
2008-11-25 12:06:42 —-A—- C:\WINDOWS\system32\icwdial.dll
2008-11-25 12:06:37 —-D—- C:\Program Files\Common Files\System
2008-11-25 12:06:36 —-D—- C:\Program Files\Internet Explorer
2008-11-25 12:06:33 —-D—- C:\Program Files\ComPlus Applications
2008-11-25 12:06:33 —-A—- C:\WINDOWS\vbaddin.ini
2008-11-25 12:06:33 —-A—- C:\WINDOWS\vb.ini
2008-11-25 12:06:32 —-D—- C:\WINDOWS\Registration
2008-11-25 12:06:15 —-D—- C:\Program Files\Windows Media Player
2008-11-25 12:06:15 —-D—- C:\Program Files\Online Services
2008-11-25 12:06:13 —-D—- C:\Program Files\Messenger
2008-11-25 12:06:09 —-D—- C:\Program Files\MSN Gaming Zone
2008-11-25 12:06:09 —-A—- C:\WINDOWS\system32\write.exe
2008-11-25 12:06:02 —-A—- C:\WINDOWS\system32\winchat.exe
2008-11-25 12:06:02 —-A—- C:\WINDOWS\system32\sndvol32.exe
2008-11-25 12:06:02 —-A—- C:\WINDOWS\system32\hticons.dll
2008-11-25 12:06:02 —-A—- C:\WINDOWS\system32\avwav.dll
2008-11-25 12:06:02 —-A—- C:\WINDOWS\system32\avtapi.dll
2008-11-25 12:06:02 —-A—- C:\WINDOWS\system32\avmeter.dll
2008-11-25 12:05:56 —-A—- C:\WINDOWS\system32\winmine.exe
2008-11-25 12:05:56 —-A—- C:\WINDOWS\system32\sol.exe
2008-11-25 12:05:56 —-A—- C:\WINDOWS\system32\getuname.dll
2008-11-25 12:05:56 —-A—- C:\WINDOWS\system32\charmap.exe
2008-11-25 12:05:56 —-A—- C:\WINDOWS\system32\calc.exe
2008-11-25 12:05:55 —-A—- C:\WINDOWS\system32\usrlogon.cmd
2008-11-25 12:05:55 —-A—- C:\WINDOWS\system32\tsshutdn.exe
2008-11-25 12:05:55 —-A—- C:\WINDOWS\system32\tslabels.ini
2008-11-25 12:05:55 —-A—- C:\WINDOWS\system32\tskill.exe
2008-11-25 12:05:55 —-A—- C:\WINDOWS\system32\tsdiscon.exe
2008-11-25 12:05:55 —-A—- C:\WINDOWS\system32\tscon.exe
2008-11-25 12:05:55 —-A—- C:\WINDOWS\system32\shadow.exe
2008-11-25 12:05:55 —-A—- C:\WINDOWS\system32\rwinsta.exe
2008-11-25 12:05:55 —-A—- C:\WINDOWS\system32\reset.exe
2008-11-25 12:05:55 —-A—- C:\WINDOWS\system32\regini.exe
2008-11-25 12:05:55 —-A—- C:\WINDOWS\system32\rdpcfgex.dll
2008-11-25 12:05:55 —-A—- C:\WINDOWS\system32\mshearts.exe
2008-11-25 12:05:55 —-A—- C:\WINDOWS\system32\freecell.exe
2008-11-25 12:05:54 —-A—- C:\WINDOWS\system32\qwinsta.exe
2008-11-25 12:05:54 —-A—- C:\WINDOWS\system32\qappsrv.exe
2008-11-25 12:05:54 —-A—- C:\WINDOWS\system32\msg.exe
2008-11-25 12:05:54 —-A—- C:\WINDOWS\system32\msdtcprf.ini
2008-11-25 12:05:54 —-A—- C:\WINDOWS\system32\logoff.exe
2008-11-25 12:05:54 —-A—- C:\WINDOWS\system32\cdmodem.dll
2008-11-25 12:05:53 —-A—- C:\WINDOWS\system32\stclient.dll
2008-11-25 12:05:53 —-A—- C:\WINDOWS\system32\mtxlegih.dll
2008-11-25 12:05:53 —-A—- C:\WINDOWS\system32\mtxex.dll
2008-11-25 12:05:53 —-A—- C:\WINDOWS\system32\mtxdm.dll
2008-11-25 12:05:53 —-A—- C:\WINDOWS\system32\dcomcnfg.exe
2008-11-25 12:05:53 —-A—- C:\WINDOWS\system32\comsnap.dll
2008-11-25 12:05:53 —-A—- C:\WINDOWS\system32\comrepl.dll
2008-11-25 12:05:53 —-A—- C:\WINDOWS\system32\comaddin.dll
2008-11-25 12:05:49 —-A—- C:\WINDOWS\system32\wmimgmt.msc
2008-11-25 12:05:39 —-D—- C:\Program Files\MSN
2008-11-25 12:05:39 —-A—- C:\WINDOWS\system32\accwiz.exe
2008-11-25 12:05:38 —-D—- C:\Program Files\Windows NT
2008-11-25 12:05:38 —-A—- C:\WINDOWS\system32\sndrec32.exe
2008-11-25 12:05:38 —-A—- C:\WINDOWS\system32\mspaint.exe
2008-11-25 12:05:38 —-A—- C:\WINDOWS\system32\mplay32.exe
2008-11-25 12:05:38 —-A—- C:\WINDOWS\system32\hypertrm.dll
2008-11-25 12:05:38 —-A—- C:\WINDOWS\system32\clipbrd.exe
2008-11-25 12:05:37 —-A—- C:\WINDOWS\system32\tscfgwmi.dll
2008-11-25 12:05:37 —-A—- C:\WINDOWS\system32\spider.exe
2008-11-25 12:05:36 —-A—- C:\WINDOWS\system32\tscupgrd.exe
2008-11-25 12:05:36 —-A—- C:\WINDOWS\system32\termsrv.dll
2008-11-25 12:05:36 —-A—- C:\WINDOWS\system32\sessmgr.exe
2008-11-25 12:05:36 —-A—- C:\WINDOWS\system32\remotepg.dll
2008-11-25 12:05:36 —-A—- C:\WINDOWS\system32\rdshost.exe
2008-11-25 12:05:36 —-A—- C:\WINDOWS\system32\rdsaddin.exe
2008-11-25 12:05:36 —-A—- C:\WINDOWS\system32\rdpwsx.dll
2008-11-25 12:05:36 —-A—- C:\WINDOWS\system32\rdpsnd.dll
2008-11-25 12:05:36 —-A—- C:\WINDOWS\system32\rdpclip.exe
2008-11-25 12:05:36 —-A—- C:\WINDOWS\system32\rdchost.dll
2008-11-25 12:05:36 —-A—- C:\WINDOWS\system32\mstscax.dll
2008-11-25 12:05:36 —-A—- C:\WINDOWS\system32\mstsc.exe
2008-11-25 12:05:35 —-D—- C:\WINDOWS\system32\MsDtc
2008-11-25 12:05:35 —-A—- C:\WINDOWS\system32\qprocess.exe
2008-11-25 12:05:35 —-A—- C:\WINDOWS\system32\mtxoci.dll
2008-11-25 12:05:35 —-A—- C:\WINDOWS\system32\msdtcuiu.dll
2008-11-25 12:05:35 —-A—- C:\WINDOWS\system32\msdtctm.dll
2008-11-25 12:05:35 —-A—- C:\WINDOWS\system32\msdtcprx.dll
2008-11-25 12:05:35 —-A—- C:\WINDOWS\system32\icaapi.dll
2008-11-25 12:05:35 —-A—- C:\WINDOWS\system32\cfgbkend.dll
2008-11-25 12:05:34 —-D—- C:\WINDOWS\system32\Com
2008-11-25 12:05:34 —-A—- C:\WINDOWS\system32\xolehlp.dll
2008-11-25 12:05:34 —-A—- C:\WINDOWS\system32\msdtclog.dll
2008-11-25 12:05:34 —-A—- C:\WINDOWS\system32\msdtc.exe
2008-11-25 12:05:34 —-A—- C:\WINDOWS\system32\colbact.dll
2008-11-25 12:05:34 —-A—- C:\WINDOWS\system32\catsrvps.dll
2008-11-25 12:05:33 —-A—- C:\WINDOWS\system32\comuid.dll
2008-11-25 12:05:33 —-A—- C:\WINDOWS\system32\comsvcs.dll
2008-11-25 12:05:33 —-A—- C:\WINDOWS\system32\clbcatex.dll
2008-11-25 12:05:33 —-A—- C:\WINDOWS\system32\catsrvut.dll
2008-11-25 12:05:33 —-A—- C:\WINDOWS\system32\catsrv.dll
2008-11-25 12:05:32 —-A—- C:\WINDOWS\system32\clbcatq.dll
2008-11-25 12:05:28 —-A—- C:\WINDOWS\system32\servdeps.dll
2008-11-25 12:05:28 —-A—- C:\WINDOWS\system32\mmfutil.dll
2008-11-25 12:05:28 —-A—- C:\WINDOWS\system32\licwmi.dll
2008-11-25 12:05:28 —-A—- C:\WINDOWS\system32\cmprops.dll
2008-11-25 04:05:08 —-A—- C:\WINDOWS\system32\h323log.txt
2008-11-25 04:02:49 —-A—- C:\WINDOWS\system32\usbui.dll
2008-11-25 04:02:10 —-A—- C:\WINDOWS\imsins.BAK
2008-11-25 04:02:08 —-SHD—- C:\WINDOWS\Installer
2008-11-25 04:02:08 —-A—- C:\WINDOWS\system32\PerfStringBackup.INI
2008-11-25 04:02:07 —-D—- C:\Program Files\Common Files\ODBC
2008-11-25 04:02:07 —-A—- C:\WINDOWS\ODBCINST.INI
2008-11-25 04:02:05 —-D—- C:\Program Files\Common Files\SpeechEngines
2008-11-25 04:02:04 —-RD—- C:\Program Files
2008-11-25 04:02:04 —-D—- C:\Program Files\Common Files\Microsoft Shared
2008-11-25 04:02:04 —-D—- C:\Program Files\Common Files
2008-11-25 04:02:02 —-RA—- C:\WINDOWS\system32\kbdtuq.dll
2008-11-25 04:02:02 —-RA—- C:\WINDOWS\system32\kbdtuf.dll
2008-11-25 04:02:02 —-RA—- C:\WINDOWS\system32\kbdazel.dll
2008-11-25 04:02:01 —-RA—- C:\WINDOWS\system32\kbdycc.dll
2008-11-25 04:02:01 —-RA—- C:\WINDOWS\system32\kbduzb.dll
2008-11-25 04:02:01 —-RA—- C:\WINDOWS\system32\kbdur.dll
2008-11-25 04:02:01 —-RA—- C:\WINDOWS\system32\kbdtat.dll
2008-11-25 04:02:01 —-RA—- C:\WINDOWS\system32\kbdru1.dll
2008-11-25 04:02:01 —-RA—- C:\WINDOWS\system32\kbdru.dll
2008-11-25 04:02:01 —-RA—- C:\WINDOWS\system32\kbdmon.dll
2008-11-25 04:02:01 —-RA—- C:\WINDOWS\system32\kbdkyr.dll
2008-11-25 04:02:01 —-RA—- C:\WINDOWS\system32\kbdkaz.dll
2008-11-25 04:02:01 —-RA—- C:\WINDOWS\system32\kbdbu.dll
2008-11-25 04:02:01 —-RA—- C:\WINDOWS\system32\kbdblr.dll
2008-11-25 04:02:01 —-RA—- C:\WINDOWS\system32\kbdaze.dll
2008-11-25 04:01:59 —-RA—- C:\WINDOWS\system32\kbdhept.dll
2008-11-25 04:01:59 —-RA—- C:\WINDOWS\system32\kbdhela3.dll
2008-11-25 04:01:59 —-RA—- C:\WINDOWS\system32\kbdhela2.dll
2008-11-25 04:01:59 —-RA—- C:\WINDOWS\system32\kbdhe319.dll
2008-11-25 04:01:59 —-RA—- C:\WINDOWS\system32\kbdhe220.dll
2008-11-25 04:01:59 —-RA—- C:\WINDOWS\system32\kbdhe.dll
2008-11-25 04:01:59 —-RA—- C:\WINDOWS\system32\kbdgkl.dll
2008-11-25 04:01:58 —-RA—- C:\WINDOWS\system32\kbdlv1.dll
2008-11-25 04:01:58 —-RA—- C:\WINDOWS\system32\kbdlv.dll
2008-11-25 04:01:58 —-RA—- C:\WINDOWS\system32\kbdlt1.dll
2008-11-25 04:01:58 —-RA—- C:\WINDOWS\system32\kbdlt.dll
2008-11-25 04:01:58 —-RA—- C:\WINDOWS\system32\kbdest.dll
2008-11-25 04:01:57 —-RA—- C:\WINDOWS\system32\kbdsl1.dll
2008-11-25 04:01:57 —-RA—- C:\WINDOWS\system32\kbdsl.dll
2008-11-25 04:01:57 —-RA—- C:\WINDOWS\system32\kbdro.dll
2008-11-25 04:01:56 —-RA—- C:\WINDOWS\system32\kbdycl.dll
2008-11-25 04:01:56 —-RA—- C:\WINDOWS\system32\kbdpl1.dll
2008-11-25 04:01:56 —-RA—- C:\WINDOWS\system32\kbdpl.dll
2008-11-25 04:01:56 —-RA—- C:\WINDOWS\system32\kbdhu1.dll
2008-11-25 04:01:56 —-RA—- C:\WINDOWS\system32\kbdhu.dll
2008-11-25 04:01:56 —-RA—- C:\WINDOWS\system32\kbdcz2.dll
2008-11-25 04:01:56 —-RA—- C:\WINDOWS\system32\kbdcz1.dll
2008-11-25 04:01:56 —-RA—- C:\WINDOWS\system32\kbdcz.dll
2008-11-25 04:01:56 —-RA—- C:\WINDOWS\system32\kbdcr.dll
2008-11-25 04:01:56 —-RA—- C:\WINDOWS\system32\KBDAL.DLL
2008-11-25 04:01:54 —-A—- C:\WINDOWS\system32\spxcoins.dll
2008-11-25 04:01:54 —-A—- C:\WINDOWS\system32\irclass.dll
2008-11-25 04:01:54 —-A—- C:\WINDOWS\system32\EqnClass.Dll
2008-11-25 04:01:54 —-A—- C:\WINDOWS\system32\dgsetup.dll
2008-11-25 04:01:54 —-A—- C:\WINDOWS\system32\dgrpsetu.dll
2008-11-25 04:01:52 —-N—- C:\WINDOWS\system32\CONFIG.TMP
2008-11-25 04:01:52 —-A—- C:\WINDOWS\TASKMAN.EXE
2008-11-25 04:01:52 —-A—- C:\WINDOWS\system32\batt.dll
2008-11-25 04:01:51 —-A—- C:\WINDOWS\notepad.exe
2008-11-25 04:01:50 —-A—- C:\WINDOWS\system32\storprop.dll
2008-11-25 04:01:47 —-RA—- C:\WINDOWS\SET26.tmp
2008-11-25 04:01:47 —-RA—- C:\WINDOWS\SET25.tmp
2008-11-25 04:01:47 —-ASH—- C:\Documents and Settings\All Users\Application Data\desktop.ini
2008-11-25 04:01:44 —-RA—- C:\WINDOWS\SET8.tmp
2008-11-25 04:01:42 —-RA—- C:\WINDOWS\SET4.tmp
2008-11-25 04:01:41 —-RA—- C:\WINDOWS\SET3.tmp
2008-11-25 04:01:38 —-D—- C:\WINDOWS\system32\CatRoot2
2008-11-25 04:01:38 —-D—- C:\WINDOWS\system32\CatRoot
2008-11-25 04:01:32 —-SD—- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-11-25 04:01:14 —-SHD—- C:\System Volume Information
2008-11-25 04:01:14 —-D—- C:\Documents and Settings
2008-11-25 04:00:33 —-RASH—- C:\boot.ini
2008-11-25 03:55:18 —-RSHDC—- C:\WINDOWS\system32\dllcache
2008-11-25 03:55:18 —-RSD—- C:\WINDOWS\Fonts
2008-11-25 03:55:18 —-RD—- C:\WINDOWS\Web
2008-11-25 03:55:18 —-HD—- C:\WINDOWS\inf
2008-11-25 03:55:18 —-D—- C:\WINDOWS\WinSxS
2008-11-25 03:55:18 —-D—- C:\WINDOWS\twain_32
2008-11-25 03:55:18 —-D—- C:\WINDOWS\Temp
2008-11-25 03:55:18 —-D—- C:\WINDOWS\system32\wins
2008-11-25 03:55:18 —-D—- C:\WINDOWS\system32\wbem
2008-11-25 03:55:18 —-D—- C:\WINDOWS\system32\usmt
2008-11-25 03:55:18 —-D—- C:\WINDOWS\system32\spool
2008-11-25 03:55:18 —-D—- C:\WINDOWS\system32\ShellExt
2008-11-25 03:55:18 —-D—- C:\WINDOWS\system32\Setup
2008-11-25 03:55:18 —-D—- C:\WINDOWS\system32\ras
2008-11-25 03:55:18 —-D—- C:\WINDOWS\system32\oobe
2008-11-25 03:55:18 —-D—- C:\WINDOWS\system32\npp
2008-11-25 03:55:18 —-D—- C:\WINDOWS\system32\mui
2008-11-25 03:55:18 —-D—- C:\WINDOWS\system32\inetsrv
2008-11-25 03:55:18 —-D—- C:\WINDOWS\system32\IME
2008-11-25 03:55:18 —-D—- C:\WINDOWS\system32\icsxml
2008-11-25 03:55:18 —-D—- C:\WINDOWS\system32\ias
2008-11-25 03:55:18 —-D—- C:\WINDOWS\system32\export
2008-11-25 03:55:18 —-D—- C:\WINDOWS\system32\drivers
2008-11-25 03:55:18 —-D—- C:\WINDOWS\system32\dhcp
2008-11-25 03:55:18 —-D—- C:\WINDOWS\system32\config
2008-11-25 03:55:18 —-D—- C:\WINDOWS\system32\3com_dmi
2008-11-25 03:55:18 —-D—- C:\WINDOWS\system32\3076
2008-11-25 03:55:18 —-D—- C:\WINDOWS\system32\2052
2008-11-25 03:55:18 —-D—- C:\WINDOWS\system32\1054
2008-11-25 03:55:18 —-D—- C:\WINDOWS\system32\1042
2008-11-25 03:55:18 —-D—- C:\WINDOWS\system32\1041
2008-11-25 03:55:18 —-D—- C:\WINDOWS\system32\1037
2008-11-25 03:55:18 —-D—- C:\WINDOWS\system32\1033
2008-11-25 03:55:18 —-D—- C:\WINDOWS\system32\1031
2008-11-25 03:55:18 —-D—- C:\WINDOWS\system32\1028
2008-11-25 03:55:18 —-D—- C:\WINDOWS\system32\1025
2008-11-25 03:55:18 —-D—- C:\WINDOWS\system32
2008-11-25 03:55:18 —-D—- C:\WINDOWS\system
2008-11-25 03:55:18 —-D—- C:\WINDOWS\security
2008-11-25 03:55:18 —-D—- C:\WINDOWS\Resources
2008-11-25 03:55:18 —-D—- C:\WINDOWS\repair
2008-11-25 03:55:18 —-D—- C:\WINDOWS\Provisioning
2008-11-25 03:55:18 —-D—- C:\WINDOWS\PeerNet
2008-11-25 03:55:18 —-D—- C:\WINDOWS\pchealth
2008-11-25 03:55:18 —-D—- C:\WINDOWS\mui
2008-11-25 03:55:18 —-D—- C:\WINDOWS\msapps
2008-11-25 03:55:18 —-D—- C:\WINDOWS\msagent
2008-11-25 03:55:18 —-D—- C:\WINDOWS\Media
2008-11-25 03:55:18 —-D—- C:\WINDOWS\java
2008-11-25 03:55:18 —-D—- C:\WINDOWS\ime
2008-11-25 03:55:18 —-D—- C:\WINDOWS\Help
2008-11-25 03:55:18 —-D—- C:\WINDOWS\Driver Cache
2008-11-25 03:55:18 —-D—- C:\WINDOWS\dell
2008-11-25 03:55:18 —-D—- C:\WINDOWS\Debug
2008-11-25 03:55:18 —-D—- C:\WINDOWS\Cursors
2008-11-25 03:55:18 —-D—- C:\WINDOWS\Connection Wizard
2008-11-25 03:55:18 —-D—- C:\WINDOWS\Config
2008-11-25 03:55:18 —-D—- C:\WINDOWS\AppPatch
2008-11-25 03:55:18 —-D—- C:\WINDOWS\addins
2008-11-25 03:55:18 —-D—- C:\WINDOWS

======List of files/folders modified in the last 1 months======

2008-12-15 20:16:39 —-A—- C:\WINDOWS\system.ini
2008-12-10 15:38:01 —-A—- C:\WINDOWS\win.ini

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
R1 mfehidk;McAfee Inc. mfehidk; C:\WINDOWS\system32\drivers\mfehidk.sys [2008-06-27 207656]
R1 MPFP;MPFP; C:\WINDOWS\System32\Drivers\Mpfp.sys [2008-06-02 120136]
R1 OMCI;OMCI; C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS [2001-08-22 13632]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.3.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2008-11-25 20747]
R2 Aspi32;Aspi32; C:\WINDOWS\system32\drivers\Aspi32.sys [1999-09-10 25244]
R2 regi;regi; C:\WINDOWS\system32\drivers\regi.sys [2007-04-17 11032]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2008-10-28 3341824]
R3 AtiHdmiService;ATI Function Driver for HDMI Service; C:\WINDOWS\system32\drivers\AtiHdmi.sys [2007-07-20 84992]
R3 e1express;Intel® PRO/1000 PCI Express Network Connection Driver; C:\WINDOWS\system32\DRIVERS\e1e5132.sys [2005-03-31 180736]
R3 GTNDIS5;GTNDIS5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\GTNDIS5.SYS []
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 Iviaspi;IVI ASPI Shell; C:\WINDOWS\system32\drivers\iviaspi.sys [2005-09-20 10368]
R3 mfeavfk;McAfee Inc. mfeavfk; C:\WINDOWS\system32\drivers\mfeavfk.sys [2008-06-27 79240]
R3 mfebopk;McAfee Inc. mfebopk; C:\WINDOWS\system32\drivers\mfebopk.sys [2008-06-27 35240]
R3 mfesmfk;McAfee Inc. mfesmfk; C:\WINDOWS\system32\drivers\mfesmfk.sys [2008-06-27 40488]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-04 12160]
R3 RT61;Linksys Wireless-G PCI Adapter Driver(RT61); C:\WINDOWS\system32\DRIVERS\RT61.sys [2005-10-27 356096]
R3 STHDA;SigmaTel High Definition Audio CODEC; C:\WINDOWS\system32\drivers\sthda.sys [2005-11-16 1047816]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 BCM42RLY;BCM42RLY; \??\C:\WINDOWS\System32\BCM42RLY.SYS []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2006-04-12 49664]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2006-04-12 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2006-04-12 21568]
S3 mferkdk;McAfee Inc. mferkdk; C:\WINDOWS\system32\drivers\mferkdk.sys [2008-06-20 34152]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 usbvideo;USB Video Device (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-13 121984]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2008-10-28 585728]
R2 IviRegMgr;IviRegMgr; C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe [2007-01-04 112152]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2008-11-10 152984]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service; C:\Program Files\McAfee\SiteAdvisor\McSACore.exe [2008-10-08 203280]
R2 mcmscsvc;McAfee Services; C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe [2008-10-10 792696]
R2 McNASvc;McAfee Network Agent; c:\program files\common files\mcafee\mna\mcnasvc.exe [2008-07-18 2482848]
R2 McProxy;McAfee Proxy Service; c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe [2008-07-09 358736]
R2 McShield;McAfee Real-time Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe [2008-06-20 144704]
R2 MpfService;McAfee Personal Firewall Service; C:\Program Files\McAfee\MPF\MPFSrv.exe [2008-07-09 884360]
R2 PSI_SVC_2;Protexis Licensing V2; C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2007-07-24 185632]
R2 sprtsvc_DellSupportCenter;SupportSoft Sprocket Service (DellSupportCenter); C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2008-08-26 201968]
R3 McSysmon;McAfee SystemGuards; C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe [2008-09-16 605512]
R3 usnjsvc;Messenger Sharing Folders USN Journal Reader service; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S2 0148681227668442mcinstcleanup;McAfee Application Installer Cleanup (0148681227668442); C:\DOCUME~1\Owner\LOCALS~1\Temp\014868~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service []
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2008-10-28 593920]
S2 WMP54Gv4SVC;WMP54Gv4SVC; C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe [2004-02-06 41025]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2007-10-09 36864]
S3 HP Port Resolver;HP Port Resolver; C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE [2005-05-20 81920]
S3 HP Status Server;HP Status Server; C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE [2004-10-16 73728]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2007-10-11 864256]
S3 McODS;McAfee Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe [2008-06-20 361800]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 stllssvr;stllssvr; C:\Program Files\Common Files\SureThing Shared\stllssvr.exe [2007-12-02 74384]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2007-10-11 122880]

—————–EOF—————–









info.txt logfile of random's system information tool 1.04 2008-12-16 16:44:28

======Uninstall list======

–>C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
–>rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Acrobat.com–>C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe -uninstall com.adobe.mauby 4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
Acrobat.com–>MsiExec.exe /I{77DCDCE3-2DED-62F3-8154-05E745472D07}
Adobe AIR–>C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR–>MsiExec.exe /I{00203668-8170-44A0-BE44-B632FA4D780F}
Adobe Flash Player 10 ActiveX–>C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin–>C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 9–>MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A90000000001}
Apple Software Update–>MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
AT&T; Yahoo! Messenger–>C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG
ATI - Software Uninstall Utility–>C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
ATI Catalyst Control Center–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{055EE59D-217B-43A7-ABFF-507B966405D8}\setup.exe" -l0x0
ATI Catalyst Registration–>MsiExec.exe /X{72736F5F-520D-472A-88CC-7B02872FD34E}
ATI Display Driver–>rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
Catalyst Control Center - Branding–>MsiExec.exe /I{D3B1C799-CB73-42DE-BA0F-2344793A095C}
City of Villains/City of Heroes (remove only)–>"C:\Program Files\City of Heroes\uninstall.exe"
Corel WinDVD 9–>C:\Program Files\InstallShield Installation Information\{E3993D46-AE3F-402E-9F9D-EEBDFBEC3564}\setup.exe -runfromtemp -l0x0409
Dell ResourceCD–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D78653C3-A8FF-415F-92E6-D774E634FF2D}\setup.exe"
Dell Support Center (Support Software)–>MsiExec.exe /X{E3BFEE55-39E2-4BE0-B966-89FE583822C1}
DivX Codec–>C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
Garfield 9 Lives Screen Saver–>C:\WINDOWS\system32\Garfield 9 Lives.scr /u
Garfield Desktop Comic–>MsiExec.exe /I{AE3D9733-1D64-45AF-AC44-05331D82FC41}
Garfield Midnight Snack Screen Saver–>C:\WINDOWS\system32\Garfield Midnight Snack.scr /u
High Definition Audio Driver Package - KB835221–>C:\WINDOWS\$NtUninstallKB835221WXP$\spuninst\spuninst.exe
HijackThis 2.0.2–>"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows Media Format 11 SDK (KB929399)–>"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 11 (KB939683)–>"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB915800-v4)–>"C:\WINDOWS\$NtUninstallKB915800-v4$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)–>"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
HP Document Viewer 7.0–>C:\Program Files\HP\Digital Imaging\DocumentViewer\hpzscr01.exe -datfile hpqbud04.dat
HP Imaging Device Functions 7.0–>C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
HP Photosmart Essential–>MsiExec.exe /X{6994491D-D491-48F1-AE1F-E179C1FFFC2F}
HP Photosmart Premier Software 6.5–>C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat
HP Photosmart, Officejet and Deskjet 7.0.A–>C:\Program Files\HP\Digital Imaging\{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}\setup\hpzscr01.exe -datfile hposcr11.dat
HP Product Assistant–>MsiExec.exe /I{36FDBE6E-6684-462B-AE98-9A39A1B200CC}
HP Solution Center 7.0–>C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
HP Update–>MsiExec.exe /X{FE57DE70-95DE-4B64-9266-84DA811053DB}
ieSpell–>"C:\Program Files\ieSpell\uninst.exe"
Intel® PRO Network Connections Drivers–>Prounstl.exe
Java™ 6 Update 11–>MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216010FF}
Java™ 6 Update 3–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java™ 6 Update 7–>MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Linksys Wireless-G PCI Adapter–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4DDC3BED-CC68-44AA-B435-D727B620CA5B}\setup.exe" -l0x9
Malwarebytes' Anti-Malware–>"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
McAfee SecurityCenter–>C:\Program Files\McAfee\MSC\mcuninst.exe
Microsoft .NET Framework 1.1 Hotfix (KB928366)–>"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1–>msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1–>MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 1–>MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
Microsoft .NET Framework 3.0 Service Pack 1–>MsiExec.exe /I{2BA00471-0328-3743-93BD-FA813353A783}
Microsoft Base Smart Card Cryptographic Service Provider Package–>"C:\WINDOWS\$NtUninstallbasecsp$\spuninst\spuninst.exe"
Microsoft Compression Client Pack 1.0 for Windows XP–>"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Games for Windows - LIVE Redistributable–>MsiExec.exe /X{FD052FB9-FE90-4438-B355-15EDC89D8FB1}
Microsoft Internationalized Domain Names Mitigation APIs–>"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft National Language Support Downlevel APIs–>"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office Professional Edition 2003–>MsiExec.exe /I{91110409-6000-11D3-8CFE-0150048383C9}
Microsoft Silverlight–>MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft User-Mode Driver Framework Feature Pack 1.0–>"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable–>MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Windows XP Video Decoder Checkup Utility–>RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\DECCHECK.inf,Uninstall
Mozilla Firefox (3.0.4)–>C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB954430)–>MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 6.0 Parser (KB927977)–>MsiExec.exe /I{5A710547-B58E-488B-828D-CA9A25A0533C}
PC Pitstop Optimize 1.5–>"C:\Program Files\PCPitstop\Optimize\unins000.exe"
PowerDVD–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\Setup.exe" -l0x9 -cluninstall
RealPlayer–>C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Roxio Creator Audio–>MsiExec.exe /I{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}
Roxio Creator Copy–>MsiExec.exe /I{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}
Roxio Creator Data–>MsiExec.exe /I{08E81ABD-79F7-49C2-881F-FD6CB0975693}
Roxio Creator DE–>C:\Documents and Settings\All Users\Application Data\Uninstall\{09760D42-E223-42AD-8C3E-55B47D0DDAC3}\setup.exe /x {09760D42-E223-42AD-8C3E-55B47D0DDAC3}
Roxio Creator DE–>MsiExec.exe /I{ED439A64-F018-4DD4-8BA5-328D85AB09AB}
Roxio Creator Tools–>MsiExec.exe /I{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}
Roxio Express Labeler 3–>MsiExec.exe /I{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
Roxio Update Manager–>MsiExec.exe /I{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
Security Update for Windows Internet Explorer 7 (KB938127-v2)–>"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)–>"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB958215)–>"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB952069)–>"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB936782)–>"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB954154)–>"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923789)–>C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Security Update for Windows XP (KB938464)–>"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)–>"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)–>"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)–>"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)–>"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)–>"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)–>"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)–>"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)–>"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)–>"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)–>"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954459)–>"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954600)–>"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)–>"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956390)–>"C:\WINDOWS\$NtUninstallKB956390$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)–>"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)–>"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)–>"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)–>"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)–>"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)–>"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)–>"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
SigmaTel Audio–>RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}\setup.exe" -l0x9 -remove -removeonly
Spelling Dictionaries Support For Adobe Reader 9–>MsiExec.exe /I{AC76BA86-7AD7-5464-3428-900000000004}
Spybot - Search & Destroy–>"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
SpywareBlaster 4.1–>"C:\Program Files\SpywareBlaster\unins000.exe"
Update for Windows XP (KB951072-v2)–>"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)–>"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Update for Windows XP (KB955839)–>"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Viva Pinata–>MsiExec.exe /X{343EFA17-5BC5-44DA-924F-539ECBEFF68C}
WebEx Support Manager for Internet Explorer–>MsiExec.exe /I{C34FAEF3-4241-4C4E-9CFF-7BBD8BCEABE7}
Windows Imaging Component–>"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Live installer–>MsiExec.exe /X{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}
Windows Live Mail–>MsiExec.exe /I{184E7118-0295-43C4-B72C-1D54AA75AAF7}
Windows Live Messenger–>MsiExec.exe /X{508CE775-4BA4-4748-82DF-FE28DA9F03B0}
Windows Live Sign-in Assistant–>MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
Windows Media Format 11 runtime–>"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime–>"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Format SDK Hotfix - KB891122–>"C:\WINDOWS\$NtUninstallKB891122$\spuninst\spuninst.exe"
Windows Media Player 11–>"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11–>"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows Presentation Foundation–>MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
Windows Rights Management Client Backwards Compatibility SP2–>MsiExec.exe /X{EC905264-BCFE-423B-9C42-C3A106266790}
Windows Rights Management Client with Service Pack 2–>MsiExec.exe /X{BDCF27CA-BFC4-4F49-8D24-A925C9505AB8}
Windows XP Service Pack 3–>"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
World of Warcraft FREE Trial–>MsiExec.exe /X{02EBDBB9-4600-41D3-B566-40CB861511D2}
World of Warcraft–>C:\Program Files\Common Files\Blizzard Entertainment\World of Warcraft\Uninstall.exe

======Security center information======

AV: McAfee VirusScan
FW: McAfee Personal Firewall

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\Common Files\Roxio Shared\DLLShared;C:\Program Files\Common Files\Roxio Shared\10.0\DLLShared;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 7, GenuineIntel
"PROCESSOR_REVISION"=0407
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"RoxioCentral"=C:\Program Files\Common Files\Roxio Shared\10.0\Roxio Central36\

—————–EOF—————–
Not seeing anything else malicious. You do have the latest version of Java, but there are a couple of older versions that should be uninstalled. Using Add or Remove Programs in Control Panel remove the 2 older versions. Java™ 6 Update 3 Java™ 6 Update 7 Let me know how it's running now.
Ok I deleted the older versions of Java, didnt know I could delete the older versions like that. Everything seems so be running good. Thanks so much for all your help, as always very invaluable :)
OK great. You have pretty good security in place, just make sure to keep it updated. You may also want to consider the following….

Install Winpatrol -
Use Winpatrol to take control of your PC and provide another layer of security.
Help file and tutorial can be found Here

Use IE-SPYAD with Zoned Out -
Zoned Out with IE-SPYAD will block access to malicious websites so you cannot be redirected to them from an infected site or email. Instructions for set up and use can be found at the websites.
NOTE: Works with IE only.

Block unwanted parasites with a custom hosts file -
http://www.mvps.org/winhelp2002/hosts.htm

Update all of your Anti-Malware programs regularly - Make sure you update all the programs I have listed and the ones you are currently running regularly. Without regular updates you Will Not be protected when new malicious programs are released.

I'll leave the thread open a few days in case you have questions or issues.

Regards,
Dave
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI