Here we go Mr Gecko. Internet Explorer is still not working at this stage.
ComboFix 08-04-22.5 - Owner 2008-04-29 23:46:44.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.493 [GMT 10:00]Running from: C:\Documents and Settings\Owner\Desktop\Other\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!FILE ::
C:\Documents and Settings\Owner\Local Settings\Temp\gAGP440p.sys
.
((((((((((((((((((((((((( Files Created from 2008-03-28 to 2008-04-29 )))))))))))))))))))))))))))))))
.
2008-04-24 18:38 . 2008-04-25 10:18 <DIR> d-------- C:\Program Files\Xfire
2008-04-24 18:38 . 2008-04-24 18:41 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Xfire
2008-04-24 18:37 . 2006-12-08 12:02 251,672 --a------ C:\WINDOWS\system32\xactengine2_5.dll
2008-04-21 11:55 . 2008-04-21 11:56 <DIR> d-------- C:\Documents and Settings\Owner\grooveshark
2008-04-21 11:52 . 2008-04-22 08:41 <DIR> d-------- C:\Program Files\Grooveshark
2008-04-17 18:15 . 2008-04-17 18:15 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Move Networks
2008-04-16 21:54 . 2008-04-16 21:54 <DIR> d-------- C:\Program Files\PIXresizer
2008-04-16 21:54 . 1996-01-12 00:00 200,704 --a------ C:\WINDOWS\system32\threed32.ocx
2008-04-16 21:54 . 1999-09-16 09:04 151,552 --a------ C:\WINDOWS\system32\ccrpfd6.ocx
2008-04-16 21:54 . 2000-05-01 23:02 110,592 --a------ C:\WINDOWS\system32\ccrpbds6.dll
2008-04-16 21:54 . 2000-07-09 18:15 106,496 --a------ C:\WINDOWS\system32\mbprgbar.ocx
2008-04-16 21:54 . 2004-01-12 11:05 69,632 --a------ C:\WINDOWS\system32\imageviewer2.ocx
2008-04-16 21:45 . 2008-04-16 22:44 <DIR> d-------- C:\Program Files\BlueVoda Website Builder
2008-04-13 13:30 . 2008-04-13 13:30 <DIR> d-------- C:\Program Files\Hotspot_Shield
2008-04-13 13:30 . 2008-04-13 13:30 <DIR> d-------- C:\Program Files\Conduit
2008-04-12 16:21 . 2008-04-12 16:21 <DIR> d-------- C:\Program Files\Flock
2008-04-12 12:52 . 2006-03-30 17:39 368,640 --a------ C:\WINDOWS\system32\ReWire.dll
2008-04-12 12:51 . 2008-04-12 12:53 <DIR> d-------- C:\Program Files\u-he
2008-04-12 12:51 . 2008-04-12 12:51 <DIR> d-------- C:\Program Files\Common Files\Digidesign
2008-04-12 12:51 . 2008-04-12 12:51 <DIR> d-------- C:\Program Files\Celemony
2008-04-11 15:56 . 2008-04-29 07:59 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-04-11 15:56 . 2008-04-11 15:56 1,409 --a------ C:\WINDOWS\QTFont.for
2008-04-11 08:12 . 2008-04-11 08:12 23,392 --a------ C:\WINDOWS\system32\nscompat.tlb
2008-04-11 08:12 . 2008-04-11 08:12 16,832 --a------ C:\WINDOWS\system32\amcompat.tlb
2008-04-10 20:20 . 2008-04-10 20:20 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2008-04-10 20:20 . 2007-09-04 17:56 164,352 --a------ C:\WINDOWS\system32\unrar.dll
2008-04-10 20:17 . 2008-04-10 20:17 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\vlc
2008-04-10 14:57 . 2008-04-10 14:57 <DIR> d-------- C:\Program Files\Adobe Media Player
2008-04-08 17:03 . 2008-04-08 17:03 <DIR> d-------- C:\Program Files\ecto 2
2008-04-08 17:03 . 2008-04-08 17:03 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Yik-Fai Hung
2008-04-05 11:22 . 2008-04-05 11:22 <DIR> d-------- C:\Program Files\GiPo@Utilities
2008-04-05 11:22 . 2008-04-05 11:22 <DIR> d-------- C:\Program Files\Common Files\Gibinsoft Shared
2008-04-05 10:51 . 2008-04-05 10:51 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Songbird1
2008-04-05 10:51 . 2008-04-05 10:52 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\SongbirdVLC
2008-04-05 10:50 . 2008-04-11 23:23 <DIR> d-------- C:\Program Files\Songbird
2008-04-05 07:31 . 2008-04-05 07:31 41,296 --a------ C:\WINDOWS\system32\xfcodec.dll
2008-04-04 13:19 . 2008-04-04 13:44 <DIR> d-------- C:\Program Files\Audacity
2008-04-03 15:34 . 2008-04-04 13:24 <DIR> d-------- C:\Program Files\Super Audio Grabber 3.0
2008-04-02 15:38 . 2004-08-03 22:10 51,328 --a------ C:\WINDOWS\system32\drivers\msdv.sys
2008-04-02 15:38 . 2004-08-03 22:10 51,328 --a--c--- C:\WINDOWS\system32\dllcache\msdv.sys
2008-04-02 15:38 . 2004-08-03 22:10 48,128 --a------ C:\WINDOWS\system32\drivers\61883.sys
2008-04-02 15:38 . 2004-08-03 22:10 48,128 --a--c--- C:\WINDOWS\system32\dllcache\61883.sys
2008-04-02 15:38 . 2004-08-03 22:10 38,912 --a------ C:\WINDOWS\system32\drivers\avc.sys
2008-04-02 15:38 . 2004-08-03 22:10 38,912 --a--c--- C:\WINDOWS\system32\dllcache\avc.sys
2008-04-01 12:02 . 2008-04-01 12:02 <DIR> d-------- C:\Program Files\SmartFTP Client 3.0 Setup Files
2008-04-01 12:02 . 2008-04-01 12:02 <DIR> d-------- C:\Program Files\SmartFTP Client
2008-04-01 12:02 . 2008-04-01 12:02 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\SmartFTP
2008-03-31 16:43 . 2008-04-01 12:06 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\FileZilla
2008-03-31 16:24 . 2008-04-06 00:20 <DIR> d----c--- C:\xampp
2008-03-31 15:52 . 2008-03-31 15:52 <DIR> d-------- C:\Program Files\CoffeeCup Software
2008-03-31 15:52 . 1998-06-17 03:00 18,944 --a------ C:\WINDOWS\system32\BORLNDMM.DLL
2008-03-30 00:56 . 2008-03-30 00:56 <DIR> d----c--- C:\Documents and Settings\All Users\Application Data\vsosdk
2008-03-29 11:58 . 2008-03-29 20:16 <DIR> d-------- C:\Documents and Settings\Owner\.oboesync
2008-03-29 11:57 . 2008-03-29 11:57 <DIR> d-------- C:\Program Files\MP3tunes
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-27 22:12 --------- d-----w C:\Documents and Settings\Owner\Application Data\AVG7
2008-04-24 08:41 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-04-24 08:27 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-24 08:27 --------- d-----w C:\Program Files\THQ
2008-04-23 11:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-23 09:13 --------- d-----w C:\Program Files\DivX
2008-04-21 08:41 --------- d-----w C:\Documents and Settings\Owner\Application Data\Vso
2008-04-20 03:22 --------- d-----w C:\Documents and Settings\Owner\Application Data\uTorrent
2008-04-20 01:26 --------- d-----w C:\Program Files\Join ME
2008-04-16 11:45 737,280 ----a-w C:\WINDOWS\iun6002.exe
2008-04-11 06:14 --------- d-----w C:\Program Files\iTunes
2008-04-11 06:14 --------- d-----w C:\Program Files\iPod
2008-04-11 06:12 --------- d-----w C:\Program Files\QuickTime
2008-04-10 11:40 --------- dc----w C:\Documents and Settings\All Users\Application Data\CyberLink
2008-04-10 11:40 --------- d-----w C:\Documents and Settings\Owner\Application Data\CyberLink
2008-04-10 10:28 --------- d-----w C:\Program Files\CyberLink DVD Solution
2008-04-10 10:28 --------- d-----w C:\Program Files\CyberLink
2008-04-10 10:27 --------- d-----w C:\Documents and Settings\Owner\Application Data\dvdcss
2008-04-10 10:16 --------- d-----w C:\Program Files\VideoLAN
2008-04-10 10:09 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-04-06 21:51 --------- d-----w C:\Program Files\ScanSoft
2008-04-06 21:51 --------- d-----w C:\Program Files\Google
2008-04-05 14:08 --------- d-----w C:\Program Files\Java
2008-04-05 00:26 --------- dc----w C:\Documents and Settings\All Users\Application Data\avg7
2008-04-04 07:19 --------- d-----w C:\Documents and Settings\Owner\Application Data\StumbleUpon
2008-04-04 05:02 --------- d-----w C:\Program Files\Real
2008-04-04 00:44 --------- d-----w C:\Program Files\Xobni Insight
2008-04-01 04:29 --------- d-----w C:\Program Files\FileZilla Client
2008-04-01 04:11 --------- d-----w C:\Program Files\e-Sword
2008-03-28 09:07 --------- d-----w C:\Program Files\Hotspot Shield
2008-03-21 04:59 --------- d-----w C:\Program Files\Photo Story 3 for Windows
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-14 11:52 --------- d-----w C:\Documents and Settings\Owner\Application Data\AVS Video Converter
2008-03-14 08:41 --------- d-----w C:\Program Files\Common Files\AVSMedia
2008-03-14 08:41 --------- d-----w C:\Program Files\AVSMedia
2008-03-14 08:40 --------- d-----w C:\Program Files\LimeWire
2008-03-13 02:38 27,136 ----a-w C:\WINDOWS\system32\drivers\tapvpn.sys
2008-03-09 06:28 --------- dc----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-03-08 03:46 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-03-01 07:25 --------- d-----w C:\Program Files\Windows Live
2008-03-01 07:20 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-01 07:19 --------- dc----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-02-21 02:05 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-02-21 02:05 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-02-21 02:05 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-02-21 02:05 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-02-21 02:04 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-02-21 02:04 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2008-02-21 02:04 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-02-21 02:04 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2008-02-21 02:04 682,496 ----a-w C:\WINDOWS\system32\DivX.dll
2008-02-21 02:04 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-02-21 02:04 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2008-02-21 02:04 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-02-21 02:04 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2008-02-21 02:04 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2008-02-21 02:04 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2008-02-21 02:04 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2008-02-21 02:03 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-02-21 02:03 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-05 14:27 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-02-05 14:27 282,624 ----a-r C:\WINDOWS\Setup1.exe
2008-01-31 13:51 118,784 ----a-w C:\WINDOWS\GREUninstall.exe
2008-01-29 02:02 107,368 ----a-w C:\WINDOWS\system32\GEARAspi.dll
2007-10-30 02:45 47,360 ----a-w C:\Documents and Settings\Owner\Application Data\pcouffin.sys
2006-12-31 11:22 800,272 ----a-w C:\Documents and Settings\Owner\ppctl.dll
2006-04-19 09:00 94,728 -c--a-w C:\Documents and Settings\Owner\Application Data\GDIPFONTCACHEV1.DAT
2004-03-11 02:27 40,960 -c--a-w C:\Program Files\Uninstall_CDS.exe
2004-08-04 12:00 94,784 -csh--w C:\WINDOWS\twain.dll
2004-08-04 12:00 50,688 --sh--w C:\WINDOWS\twain_32.dll
2006-04-27 07:37 56 --sh--r C:\WINDOWS\system32\C8D42D3D14.sys
2004-12-24 14:33 56 -csh--r C:\WINDOWS\system32\FEF6574199.sys
2008-01-03 01:48 2,672 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2004-08-04 12:00 11,776 --sh--w C:\WINDOWS\system32\regsvr32.exe
.
((((((((((((((((((((((((((((( snapshot_2008-04-28_22.58.54.08 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-27 22:10:36 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-28 21:58:05 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2008-04-27 22:16:10 93,884 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-04-28 22:03:28 93,884 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-04-27 22:16:10 480,552 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-04-28 22:03:28 480,552 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-04-28 21:58:56 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_6f0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c95a4e8e-816d-4655-8c79-d736da1adb6d}]
2008-03-13 10:30 1524248 --a------ C:\Program Files\Hotspot_Shield\tbHots.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{C95A4E8E-816D-4655-8C79-D736DA1ADB6D}"= "C:\Program Files\Hotspot_Shield\tbHots.dll" [2008-03-13 10:30 1524248]
[HKEY_CLASSES_ROOT\clsid\{c95a4e8e-816d-4655-8c79-d736da1adb6d}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{C95A4E8E-816D-4655-8C79-D736DA1ADB6D}"= C:\Program Files\Hotspot_Shield\tbHots.dll [2008-03-13 10:30 1524248]
[HKEY_CLASSES_ROOT\clsid\{c95a4e8e-816d-4655-8c79-d736da1adb6d}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" [2004-02-03 15:42 401491]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 22:00 15360]
"Synergy Server"="C:\Program Files\Synergy\synergys.exe" [2006-04-03 06:20 733184]
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [2005-01-04 13:17 1937408]
"LxrAutorun"="C:\Documents and Settings\Owner\Local Settings\Application Data\Lexar Media\LxrAutorun.exe" [2006-11-09 10:00 24576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-11-30 20:10 344064]
"FlashIcon"="C:\Program Files\Generic\USB Card Reader Driver v2.3\FlashIcon.exe" [2004-07-21 20:48 40960]
"PinnacleDriverCheck"="C:\WINDOWS\system32\PSDrvCheck.exe" [2004-03-10 16:26 406016]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 09:50 155648]
"XeroxScannerDaemon"="C:\Program Files\Xerox\NWWia\XrxFTPLt.exe" [2001-08-17 21:37 27648]
"PRONoMgr.exe"="C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe" [2003-03-11 15:24 86016]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-08-20 08:41 1838592]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2007-08-07 10:05 200704]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 18:54 623992]
"CanonSolutionMenu"="C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-04-04 02:00 644696]
"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-04 02:50 1603152]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 14:28 577536 C:\WINDOWS\soundman.exe]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe" [2006-12-22 06:29 67752]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-17 08:51 579584]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 03:25 144784]
"IndexSearch"="C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe" [2003-02-27 02:40 40960]
"BDRegion"="C:\Program Files\Cyberlink\Shared Files\brs.exe" [2007-11-16 19:20 91432]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2007-10-28 09:35 72736]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2007-10-11 12:06 62760]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-14 02:24 1694208]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-01 11:37 219136]
C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-01-02 21:05:02 110592]
Last.fm Helper.lnk - C:\Program Files\Last.fm\LastFMHelper.exe [2008-01-28 23:44:19 106496]
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2004-12-16 21:29:06 45056]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=39.dll C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.alf2cd"= alf2cd.acm
"vidc.dvsd"= mcdvd_32.dll
"VIDC.MJPG"= Pvmjpg21.dll
"VIDC.PIM1"= pclepim1.dll
"MSACM.CEGSM"= mobilev.acm
"msacm.l3acma"= L3codecp.acm
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"msacm.divxa32"= DivXa32.acm
"msacm.scg726"= scg726.acm
"VIDC.XFR1"= xfcodec.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^MailWasherPro.lnk]
path=C:\Documents and Settings\Owner\Start Menu\Programs\Startup\MailWasherPro.lnk
backup=C:\WINDOWS\pss\MailWasherPro.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Act! Preloader]
--a------ 2006-04-05 16:30 1015808 C:\Program Files\ACT\ACT for Windows\Act8.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-03-30 10:36 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
--------- 2005-01-04 13:17 1937408 C:\PROGRA~1\Ahead\NEROBA~1\NBJ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaperPort PTD]
--a------ 2003-02-27 02:12 57393 C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCLEPCI]
--a------ 2004-02-03 15:13 49152 C:\PROGRA~1\Pinnacle\PPE\PPE.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pdfSaver3]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\slide.exe]
c:\program files\slide\slide.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
c:\valve\condition zero\steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Veoh]
--a------ 2007-05-03 17:43 2019328 C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\SmartFTP Client\\SmartFTP.exe"=
"C:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8483:TCP"= 8483:TCP:BitCometBeta 8483 TCP
"8483:UDP"= 8483:UDP:BitCometBeta 8483 UDP
R2 {95808DC4-FA4A-4C74-92FE-5B863F82066B};{95808DC4-FA4A-4C74-92FE-5B863F82066B};C:\Program Files\CyberLink\PowerDVD\
000.fcl [2007-11-03 00:12]
R2 cx88xbar;FusionHDTV 88x, Crossbar;C:\WINDOWS\system32\drivers\zl88xbar.sys [2004-08-27 22:10]
R2 LxrSII1d;Secure II Driver;C:\WINDOWS\system32\Drivers\LxrSII1d.sys [2006-12-14 08:37]
R2 MicroGuard;MicroGuard Copy Protection;C:\WINDOWS\system32\drivers\mgnt.sys [1998-12-28 07:19]
R2 MSSQL$ACT7;MSSQL$ACT7;C:\Program Files\Microsoft SQL Server\MSSQL$ACT7\Binn\sqlservr.exe [2003-05-31 17:02]
R2 XobniService;XobniService;"C:\Program Files\Xobni Insight\XobniService.exe" [2008-02-26 12:54]
R2 Zulu88Ts;FusionHDTV 88x, Transport Stream Capture (DVB-T);C:\WINDOWS\system32\drivers\zl88tcap.sys [2004-08-10 13:01]
R2 Zulu88Tune;FusionHDTV 88x, Thomson7579 DVB-T WDM TvTuner;C:\WINDOWS\system32\drivers\zl88tune.sys [2004-08-27 22:10]
R2 Zulu88Vid;FusionHDTV 88x, Video Capture;C:\WINDOWS\system32\drivers\zl88vcap.sys [2004-08-27 20:10]
R3 BENDER;Pinnacle AV/DV2 Capture;C:\WINDOWS\system32\drivers\bender.sys [2003-07-09 13:35]
R3 tapvpn;TAP VPN Adapter;C:\WINDOWS\system32\DRIVERS\tapvpn.sys [2008-03-13 12:38]
R3 Zulu88BDA;FusionHDTV 88x, BDA DVB Tuner/Demod;C:\WINDOWS\system32\drivers\zl88bda.sys [2004-08-27 20:10]
S3 CXAVSAUD;FusionHDTV 880, Audio Capture;C:\WINDOWS\system32\drivers\zl88aud.sys [2004-08-27 20:10]
S3 gAGP440p;gAGP440p;C:\DOCUME~1\Owner\LOCALS~1\Temp\gAGP440p.sys []
S3 maxidemo;Maxi_Vista_Demo_Driver;C:\WINDOWS\system32\DRIVERS\maxidemo.sys []
S3 qcusbser;ZTE USB Device for Legacy Serial Communication;C:\WINDOWS\system32\DRIVERS\ZTEusbser.sys [2007-05-29 16:52]
S3 SQLAgent$ACT7;SQLAgent$ACT7;C:\Program Files\Microsoft SQL Server\MSSQL$ACT7\Binn\sqlagent.EXE [2002-12-18 09:23]
S3 UltraMonMirror;UltraMonMirror;C:\WINDOWS\system32\DRIVERS\UltraMonMirror.sys []
S3 UMSSSTOR;C-Media Storage;C:\WINDOWS\system32\DRIVERS\UMSS.SYS [2004-07-13 11:40]
.
Contents of the 'Scheduled Tasks' folder
"2008-04-23 10:08:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-04-29 14:00:00 C:\WINDOWS\Tasks\B22606AB93B1B5C3.job"
- c:\docume~1\owner\applic~1\firsts~1\more keep media.exe
"2008-04-29 14:00:00 C:\WINDOWS\Tasks\User_Feed_Synchronization-{1A7E0D37-DEE1-4DD1-B17C-12E64CAC5F7B}.job"
- C:\WINDOWS\system32\msfeedssync.exe
"2008-04-29 06:00:00 C:\WINDOWS\Tasks\{6A9DF849-A6C3-41DB-A1B4-C09FD3139550}_GALLEMAND_Owner.job"
- C:\WINDOWS\system32\mobsync.exeD /Schedule=
"2008-04-28 23:00:00 C:\WINDOWS\Tasks\{AFFF360E-6E67-435E-A0A5-91B5E7EE681C}_GALLEMAND_Owner.job"
- C:\WINDOWS\system32\mobsync.exeD /Schedule=
"2008-04-25 06:00:00 C:\WINDOWS\Tasks\{FF09BE39-B8B9-4D15-A751-D4FEEF8A8799}_GALLEMAND_Owner.job"
- C:\WINDOWS\system32\mobsync.exeD /Schedule=
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-04-29 23:53:51
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\{95808DC4-FA4A-4C74-92FE-5B863F82066B}]
"ImagePath"="\??\C:\Program Files\CyberLink\PowerDVD\
000.fcl"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\Synergy\synrgyhk.dll
.
Completion time: 2008-04-30 0:05:20
ComboFix-quarantined-files.txt 2008-04-29 14:04:30
ComboFix2.txt 2008-04-28 12:59:57
ComboFix3.txt 2008-04-24 07:47:00
ComboFix4.txt 2007-11-03 14:09:32
Pre-Run: 21,280,546,816 bytes free
Post-Run: 21,276,790,784 bytes free
318 --- E O F --- 2008-04-23 12:23:56
Logfile of HijackThis v1.99.1
Scan saved at 12:08:28 AM, on 30/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
c:\xampp\filezillaftp\filezillaserver.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\WINDOWS\system32\LxrSII1s.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$ACT7\Binn\sqlservr.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Xerox\NWWia\XrxFTPLt.exe
C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Xobni Insight\XobniService.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Cyberlink\Shared Files\brs.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Synergy\synergys.exe
C:\Documents and Settings\Owner\Local Settings\Application Data\Lexar Media\LxrAutorun.exe
C:\Program Files\Last.fm\LastFMHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft ActiveSync\WCESMgr.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\LimeWire\LimeWire.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Owner\Desktop\Other\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:9666
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R3 - URLSearchHook: Hotspot Shield Toolbar - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files\Hotspot_Shield\tbHots.dll
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: StumbleUpon Launcher - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: del.icio.us Toolbar Helper - {7AA07AE6-01EF-44EC-93CA-9D7CD41CCDB6} - C:\Program Files\del.icio.us\Internet Explorer Buttons\dlcsIE.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Hotspot Shield Toolbar - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files\Hotspot_Shield\tbHots.dll
O2 - BHO: &Google Notebook - {CCCCCCD3-666F-4F81-8B69-745DE9F6D897} - C:\Program Files\Google\Google Notebook\gnotes1.0.2.19-27546986.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: Google Notebook - {CCCCCCDB-4DDB-4703-95D4-DD2C526397BF} - C:\Program Files\Google\Google Notebook\gnotes1.0.2.19-27546986.dll
O3 - Toolbar: del.icio.us - {981FE6A8-260C-4930-960F-C3BC82746CB0} - C:\Program Files\del.icio.us\Internet Explorer Buttons\dlcsIE.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O3 - Toolbar: Hotspot Shield Toolbar - {c95a4e8e-816d-4655-8c79-d736da1adb6d} - C:\Program Files\Hotspot_Shield\tbHots.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [FlashIcon] C:\Program Files\Generic\USB Card Reader Driver v2.3\FlashIcon.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [XeroxScannerDaemon] C:\Program Files\Xerox\NWWia\XrxFTPLt.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [BDRegion] C:\Program Files\Cyberlink\Shared Files\brs.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Synergy Server] "C:\Program Files\Synergy\synergys.exe" --no-daemon --debug WARNING --name GEOFFPC --address :24800
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [LxrAutorun] C:\Documents and Settings\Owner\Local Settings\Application Data\Lexar Media\LxrAutorun.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O8 - Extra context menu item: &D&ownload &with BitComet -
res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet -
res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet -
res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Append to existing PDF -
res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF -
res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF -
res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF -
res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF -
res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF -
res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF -
res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF -
res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Note this (Google Notebook) -
res://C:\Program Files\Google\Google Notebook\gnotes1.0.2.19-27546986.dll/gn_menu1.html
O8 - Extra context menu item: Note this item (Google Notebook) -
res://C:\Program Files\Google\Google Notebook\gnotes1.0.2.19-27546986.dll/gn_menu2.html
O8 - Extra context menu item: StumbleUpon PhotoBlog It! -
res://StumbleUponIEBar.dll/blogimageO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} -
res://C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll/206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\caslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\caslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\caslsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\caslsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
http://a1540.g.akamai.net/7/1540/52/200 ... plugin.cabO16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky.com/kos/eng/partne ... nicode.cabO16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) -
http://picasaweb.google.com/s/v/23.21/uploader2.cabO16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) -
http://lads.myspace.com/upload/MySpaceUploader1006.cabO16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) -
http://www.linkedin.com/cab/LinkedInCon ... ontrol.cabO16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) -
http://www.slide.com/uploader/SlideImageUploader.cabO16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) -
http://www.ca.com/securityadvisor/pestscan/pestscan.cabO16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} -
http://zone.msn.com/binframework/v10/ZP ... b32846.cabO16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) -
http://upload.facebook.com/controls/Fac ... loader.cabO16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) -
http://www.acclaim.com/cabs/acclaim_v5.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/microso ... 6634359409O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) -
https://www.dotphoto.com/DPImageUploader.cabO16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/Me ... b56907.cabO16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) -
http://www.adobe.com/products/acrobat/nos/gp.cabO16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} -
http://fdl.msn.com/zone/datafiles/heartbeat.cabO16 - DPF: {FF1CD9A3-00CD-45C1-8182-4EEC229A182D} (Plaxo Auto-Import Utility) -
https://www.plaxo.com/activex/plx_upldr-2k-xp.cabO18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: 39.dll C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FileZilla Server FTP server (FileZilla Server) - FileZilla Project - c:\xampp\filezillaftp\filezillaserver.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Lexar Secure II (LxrSII1s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrSII1s.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
O23 - Service: XobniService - Xobni Corporation - C:\Program Files\Xobni Insight\XobniService.exe