ComboFix 08-10-24.02 - LaDonna 2008-10-25 12:13:11.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.582 [GMT -5:00]
Running from: C:\Documents and Settings\LaDonna\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\LaDonna\Desktop\cfscript.txt
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\LaDonna\Application Data\LimeWire
C:\Documents and Settings\LaDonna\Application Data\LimeWire\.AppSpecialShare\Black.Rogue.Cops.XXX.DVDRip.XviD-NYMPHO [2008].torrent
C:\Documents and Settings\LaDonna\Application Data\LimeWire\certificate\limewire.keystore
C:\Documents and Settings\LaDonna\Application Data\LimeWire\createtimes.cache
C:\Documents and Settings\LaDonna\Application Data\LimeWire\downloads.dat
C:\Documents and Settings\LaDonna\Application Data\LimeWire\fileurns.bak
C:\Documents and Settings\LaDonna\Application Data\LimeWire\fileurns.cache
C:\Documents and Settings\LaDonna\Application Data\LimeWire\filters.props
C:\Documents and Settings\LaDonna\Application Data\LimeWire\installation.props
C:\Documents and Settings\LaDonna\Application Data\LimeWire\library.dat
C:\Documents and Settings\LaDonna\Application Data\LimeWire\limewire.props
C:\Documents and Settings\LaDonna\Application Data\LimeWire\mojito.props
C:\Documents and Settings\LaDonna\Application Data\LimeWire\promotion\promodb.backup
C:\Documents and Settings\LaDonna\Application Data\LimeWire\promotion\promodb.data
C:\Documents and Settings\LaDonna\Application Data\LimeWire\promotion\promodb.lck
C:\Documents and Settings\LaDonna\Application Data\LimeWire\promotion\promodb.log
C:\Documents and Settings\LaDonna\Application Data\LimeWire\promotion\promodb.properties
C:\Documents and Settings\LaDonna\Application Data\LimeWire\promotion\promodb.script
C:\Documents and Settings\LaDonna\Application Data\LimeWire\questions.props
C:\Documents and Settings\LaDonna\Application Data\LimeWire\simpp.xml
C:\Documents and Settings\LaDonna\Application Data\LimeWire\spam.dat
C:\Documents and Settings\LaDonna\Application Data\LimeWire\tables.props
C:\Documents and Settings\LaDonna\Application Data\LimeWire\themes\windows_theme.lwtp
C:\Documents and Settings\LaDonna\Application Data\LimeWire\themes\windows_theme\
01_star.gif
C:\Documents and Settings\LaDonna\Application Data\LimeWire\themes\windows_theme\
02_star.gif
C:\Documents and Settings\LaDonna\Application Data\LimeWire\themes\windows_theme\
03_star.gif
C:\Documents and Settings\LaDonna\Application Data\LimeWire\themes\windows_theme\
04_star.gif
C:\Documents and Settings\LaDonna\Application Data\LimeWire\themes\windows_theme\
05_star.gif
C:\Documents and Settings\LaDonna\Application Data\LimeWire\themes\windows_theme\chat.gif
C:\Documents and Settings\LaDonna\Application Data\LimeWire\themes\windows_theme\forward_dn.gif
C:\Documents and Settings\LaDonna\Application Data\LimeWire\themes\windows_theme\forward_up.gif
C:\Documents and Settings\LaDonna\Application Data\LimeWire\themes\windows_theme\kill.gif
C:\Documents and Settings\LaDonna\Application Data\LimeWire\themes\windows_theme\kill_on.gif
C:\Documents and Settings\LaDonna\Application Data\LimeWire\themes\windows_theme\pause_dn.gif
C:\Documents and Settings\LaDonna\Application Data\LimeWire\themes\windows_theme\pause_up.gif
C:\Documents and Settings\LaDonna\Application Data\LimeWire\themes\windows_theme\play_dn.gif
C:\Documents and Settings\LaDonna\Application Data\LimeWire\themes\windows_theme\play_up.gif
C:\Documents and Settings\LaDonna\Application Data\LimeWire\themes\windows_theme\question.gif
C:\Documents and Settings\LaDonna\Application Data\LimeWire\themes\windows_theme\rewind_dn.gif
C:\Documents and Settings\LaDonna\Application Data\LimeWire\themes\windows_theme\rewind_up.gif
C:\Documents and Settings\LaDonna\Application Data\LimeWire\themes\windows_theme\stop_dn.gif
C:\Documents and Settings\LaDonna\Application Data\LimeWire\themes\windows_theme\stop_up.gif
C:\Documents and Settings\LaDonna\Application Data\LimeWire\themes\windows_theme\theme.txt
C:\Documents and Settings\LaDonna\Application Data\LimeWire\themes\windows_theme\version.txt
C:\Documents and Settings\LaDonna\Application Data\LimeWire\themes\windows_theme\warning.gif
C:\Documents and Settings\LaDonna\Application Data\LimeWire\version.xml
C:\Documents and Settings\LaDonna\Application Data\LimeWire\versions.props
C:\Documents and Settings\LaDonna\Application Data\LimeWire\xml\data\audio.sxml2
C:\Documents and Settings\LaDonna\Application Data\LimeWire\xml\data\video.sxml2
C:\Program Files\LimeWire
C:\Program Files\LimeWire\aopalliance.jar.tmp
C:\Program Files\LimeWire\clink.jar.tmp
C:\Program Files\LimeWire\commons-codec-1.3.jar.tmp
C:\Program Files\LimeWire\commons-logging.jar.tmp
C:\Program Files\LimeWire\commons-net.jar.tmp
C:\Program Files\LimeWire\daap.jar.tmp
C:\Program Files\LimeWire\dnsjava.jar.tmp
C:\Program Files\LimeWire\forms.jar.tmp
C:\Program Files\LimeWire\foxtrot.jar.tmp
C:\Program Files\LimeWire\gettext-commons.jar.tmp
C:\Program Files\LimeWire\guice-1.0.jar.tmp
C:\Program Files\LimeWire\hsqldb.jar.tmp
C:\Program Files\LimeWire\httpclient-4.0-alpha5-20080522.192134-5.jar.tmp
C:\Program Files\LimeWire\httpcore-4.0-beta2-20080510.140437-10.jar.tmp
C:\Program Files\LimeWire\httpcore-nio-4.0-beta2-20080510.140437-10.jar.tmp
C:\Program Files\LimeWire\icu4j.jar.tmp
C:\Program Files\LimeWire\jaudiotagger.jar.tmp
C:\Program Files\LimeWire\jcraft.jar.tmp
C:\Program Files\LimeWire\jdic.jar.tmp
C:\Program Files\LimeWire\jdic_stub.jar.tmp
C:\Program Files\LimeWire\jflac.jar.tmp
C:\Program Files\LimeWire\jl.jar.tmp
C:\Program Files\LimeWire\jmdns.jar.tmp
C:\Program Files\LimeWire\jogg.jar.tmp
C:\Program Files\LimeWire\jorbis.jar.tmp
C:\Program Files\LimeWire\LimeWire.jar.tmp
C:\Program Files\LimeWire\log4j.jar.tmp
C:\Program Files\LimeWire\looks.jar.tmp
C:\Program Files\LimeWire\messages.jar.tmp
C:\Program Files\LimeWire\mp3spi.jar.tmp
C:\Program Files\LimeWire\onion-common.jar.tmp
C:\Program Files\LimeWire\onion-fec.jar.tmp
C:\Program Files\LimeWire\ProgressTabs.jar.tmp
C:\Program Files\LimeWire\swt.jar.tmp
C:\Program Files\LimeWire\themes.jar.tmp
C:\Program Files\LimeWire\tritonus.jar.tmp
C:\Program Files\LimeWire\vorbisspi.jar.tmp
C:\Program Files\Morpheus Ultra
.
((((((((((((((((((((((((( Files Created from 2008-09-25 to 2008-10-25 )))))))))))))))))))))))))))))))
.
2008-10-24 21:45 . 2008-10-25 11:03 <DIR> d-------- C:\WINDOWS\system32\CatRoot2
2008-10-24 21:33 . 2006-03-15 15:00 33,792 --a------ C:\WINDOWS\system32\lmmib2.dll
2008-10-24 21:33 . 2006-03-15 15:00 33,792 --a------ C:\WINDOWS\system32\dllcache\lmmib2.dll
2008-10-24 09:46 . 2008-10-24 09:48 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-10-24 09:46 . 2008-10-24 11:31 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2008-10-23 13:48 . 2008-10-23 13:48 <DIR> d-------- C:\Program Files\Common Files\Scanner
2008-10-23 12:53 . 2008-10-23 12:55 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2008-10-23 11:27 . 2008-10-23 11:27 410,976 --a------ C:\WINDOWS\system32\deploytk.dll
2008-10-23 11:27 . 2008-10-23 11:27 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-10-23 11:09 . 2008-10-23 11:09 <DIR> d-------- C:\Program Files\Windows Defender
2008-10-23 10:53 . 2008-10-23 10:53 <DIR> d-------- C:\Program Files\Panda Security
2008-10-23 10:53 . 2008-06-19 17:24 28,544 --a------ C:\WINDOWS\system32\drivers\pavboot.sys
2008-10-23 10:13 . 2008-10-23 10:13 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2008-10-22 12:22 . 2008-10-22 12:22 262,144 --a------ C:\ntuser.dat
2008-10-21 23:18 . 2008-10-21 23:32 4,812 --a------ C:\WINDOWS\system32\tmp.reg
2008-10-21 23:17 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-10-21 23:17 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-10-21 23:17 . 2008-09-08 23:38 88,576 --a------ C:\WINDOWS\system32\AntiXPVSTFix.exe
2008-10-21 23:17 . 2008-10-01 15:51 87,552 --a------ C:\WINDOWS\system32\VACFix.exe
2008-10-21 23:17 . 2008-10-10 08:58 82,944 --a------ C:\WINDOWS\system32\o4Patch.exe
2008-10-21 23:17 . 2008-05-18 21:40 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-10-21 23:17 . 2008-10-10 08:58 82,944 --a------ C:\WINDOWS\system32\IEDFix.C.exe
2008-10-21 23:17 . 2008-08-18 12:19 82,432 --a------ C:\WINDOWS\system32\404Fix.exe
2008-10-21 23:17 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-10-21 23:17 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-10-21 23:17 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-10-21 23:10 . 2008-10-21 23:10 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-10-21 21:59 . 2008-10-21 21:59 <DIR> d---s---- C:\WINDOWS\system32\config\systemprofile\Temporary Internet Files
2008-10-21 21:59 . 2008-10-21 21:59 <DIR> d---s---- C:\WINDOWS\system32\config\systemprofile\History
2008-10-21 11:31 . 2008-10-21 11:31 <DIR> d-------- C:\Documents and Settings\LaDonna\Application Data\Reallusion
2008-10-21 10:32 . 2008-10-21 10:32 0 --ah----- C:\WINDOWS\SwSys2.bmp
2008-10-21 10:32 . 2008-10-21 10:32 0 --ah----- C:\WINDOWS\SwSys1.bmp
2008-10-17 14:43 . 2008-10-17 14:44 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-10-17 14:39 . 2008-10-17 14:39 <DIR> d-------- C:\Program Files\Common Files\Adobe AIR
2008-10-17 14:36 . 2008-10-17 14:36 <DIR> d-------- C:\Program Files\NOS
2008-10-17 14:36 . 2008-10-17 14:36 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\NOS
2008-10-17 12:41 . 2008-10-17 12:41 <DIR> d-------- C:\Documents and Settings\LaDonna\Application Data\AdobeUM
2008-10-16 19:24 . 2006-10-04 09:06 1,197,294 --------- C:\WINDOWS\system32\dllcache\sysmain.sdb
2008-10-16 19:24 . 2006-10-04 09:06 764,868 --------- C:\WINDOWS\system32\dllcache\apph_sp.sdb
2008-10-16 19:24 . 2006-10-04 09:06 217,118 --------- C:\WINDOWS\system32\dllcache\apphelp.sdb
2008-10-16 19:22 . 2008-10-16 19:22 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-10-16 19:22 . 2008-10-18 21:41 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-10-16 19:22 . 2008-10-16 19:23 <DIR> d-------- C:\9b0a2e797fbc78aded50d431
2008-10-15 02:36 . 2008-09-15 06:57 1,846,016 --------- C:\WINDOWS\system32\dllcache\win32k.sys
2008-10-15 02:36 . 2008-08-28 05:04 333,056 --------- C:\WINDOWS\system32\dllcache\srv.sys
2008-10-15 02:34 . 2008-08-14 04:57 2,185,984 --------- C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-15 02:34 . 2008-08-14 04:55 2,142,720 --------- C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-15 02:34 . 2008-08-14 04:18 2,062,976 --------- C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-15 02:34 . 2008-08-14 04:18 2,020,864 --------- C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-14 07:45 . 2004-08-03 23:10 38,016 --a------ C:\WINDOWS\system32\drivers\bthmodem.sys
2008-10-14 07:45 . 2004-08-03 23:10 38,016 --a------ C:\WINDOWS\system32\dllcache\bthmodem.sys
2008-10-14 06:28 . 2008-10-14 06:28 <DIR> d-------- C:\Program Files\Creative
2008-10-14 06:28 . 2005-08-16 12:23 38,422 --a------ C:\WINDOWS\system32\drivers\StMp3Rec.sys
2008-10-11 13:03 . 2004-08-03 23:08 26,496 --a------ C:\WINDOWS\system32\dllcache\usbstor.sys
2008-10-11 12:21 . 2008-10-25 01:10 <DIR> d-------- C:\Documents and Settings\LaDonna\Application Data\uTorrent
2008-10-05 16:34 . 2004-08-04 00:56 152,576 --a------ C:\WINDOWS\system32\irftp.exe
2008-10-05 16:34 . 2004-08-04 00:56 152,576 --a------ C:\WINDOWS\system32\dllcache\irftp.exe
2008-10-05 16:34 . 2004-08-03 22:58 100,992 --a------ C:\WINDOWS\system32\drivers\bthpan.sys
2008-10-05 16:34 . 2004-08-03 22:58 100,992 --a------ C:\WINDOWS\system32\dllcache\bthpan.sys
2008-10-05 16:34 . 2004-08-03 23:10 59,648 --a------ C:\WINDOWS\system32\drivers\rfcomm.sys
2008-10-05 16:34 . 2004-08-03 23:10 59,648 --a------ C:\WINDOWS\system32\dllcache\rfcomm.sys
2008-10-05 16:34 . 2004-08-03 23:10 17,024 --a------ C:\WINDOWS\system32\drivers\BthEnum.sys
2008-10-05 16:34 . 2004-08-03 23:10 17,024 --a------ C:\WINDOWS\system32\dllcache\bthenum.sys
2008-10-05 16:34 . 2004-08-04 00:56 8,192 --a------ C:\WINDOWS\system32\wshirda.dll
2008-10-05 16:34 . 2004-08-04 00:56 8,192 --a------ C:\WINDOWS\system32\dllcache\wshirda.dll
2008-10-05 16:24 . 2004-08-03 23:10 18,944 --a------ C:\WINDOWS\system32\drivers\BTHUSB.SYS
2008-10-05 16:24 . 2004-08-03 23:10 18,944 --a------ C:\WINDOWS\system32\dllcache\bthusb.sys
2008-10-04 17:35 . 2008-10-04 17:35 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\FunGames
2008-10-03 09:50 . 2008-10-03 09:50 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-10-02 09:21 . 2008-10-02 09:34 <DIR> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-10-02 09:20 . 2008-06-13 08:10 272,128 --a------ C:\WINDOWS\system32\drivers\bthport.sys
2008-10-02 09:20 . 2008-06-13 08:10 272,128 --a------ C:\WINDOWS\system32\dllcache\bthport.sys
2008-10-02 09:19 . 2006-03-20 22:23 23,040 --------- C:\WINDOWS\kb913800.exe
2008-10-02 09:18 . 2006-10-18 21:47 2,450,944 --------- C:\WINDOWS\system32\dllcache\wmvcore.dll
2008-10-02 09:18 . 2008-04-11 13:50 683,520 --------- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-10-02 09:18 . 2008-05-01 09:30 331,776 --------- C:\WINDOWS\system32\dllcache\msadce.dll
2008-10-02 09:18 . 2008-05-08 07:28 202,752 --------- C:\WINDOWS\system32\dllcache\rmcast.sys
2008-10-01 22:51 . 2008-10-01 22:51 <DIR> d-------- C:\WINDOWS\Sun
2008-10-01 22:46 . 2008-10-01 22:46 <DIR> d-------- C:\Documents and Settings\LaDonna\Application Data\MSNInstaller
2008-10-01 13:02 . 2008-10-01 13:02 <DIR> d-------- C:\Program Files\Alwil Software
2008-10-01 11:05 . 2008-10-01 11:05 32,549 --a------ C:\WINDOWS\king-uninstall.exe
2008-10-01 11:01 . 2001-08-17 13:48 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2008-10-01 11:01 . 2001-08-17 13:48 12,160 --a------ C:\WINDOWS\system32\dllcache\mouhid.sys
2008-10-01 11:01 . 2001-08-17 14:02 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2008-10-01 11:01 . 2001-08-17 14:02 9,600 --a------ C:\WINDOWS\system32\dllcache\hidusb.sys
2008-10-01 10:54 . 2008-10-01 10:54 <DIR> d-------- C:\Program Files\Common Files\SWF Studio
2008-10-01 10:41 . 2008-10-01 10:41 <DIR> d-------- C:\Program Files\HP Pavilion Webcam Demo
2008-10-01 10:41 . 2006-06-27 18:31 102,400 --a------ C:\WINDOWS\HPWebcam.exe
2008-10-01 10:41 . 2005-11-23 13:55 53,248 --a------ C:\WINDOWS\csnp2uvc.dll
2008-10-01 10:36 . 2008-10-25 11:03 <DIR> d---s---- C:\Documents and Settings\LaDonna\Temporary Internet Files
2008-10-01 10:36 . 2008-10-01 10:36 <DIR> d---s---- C:\Documents and Settings\LaDonna\History
2008-10-01 10:36 . 2008-10-01 10:36 1,783 -rahs---- C:\WINDOWS\system32\drivers\103C_HP_NTBK_HP Pavilion dv6000 (RG360UA#ABA)_YN_0Pavi_QCNF64411RY_E419857002_46_I30BB_SQuanta_V66.21_BF.06_T061026_WXP2_L409_M1015_J250_7Intel_8T2250_91.73_#060911_N80861092_(RG360UA#ABA)_XMOBILE_CN10_Z_2Rev 1.MRK
2008-10-01 10:35 . 2008-10-01 03:28 <DIR> d-------- C:\Documents and Settings\LaDonna\Application Data\Intuit
2008-10-01 10:35 . 2008-10-17 14:44 <DIR> d-------- C:\Documents and Settings\LaDonna
2008-10-01 10:29 . 2006-03-15 15:00 185,344 --a------ C:\WINDOWS\system32\Thawbrkr.dll
2008-10-01 10:29 . 2006-03-15 15:00 66,594 --a------ C:\WINDOWS\system32\c_864.nls
2008-10-01 10:29 . 2006-03-15 15:00 66,594 --a------ C:\WINDOWS\system32\c_862.nls
2008-10-01 10:29 . 2006-03-15 15:00 66,594 --a------ C:\WINDOWS\system32\c_720.nls
2008-10-01 10:29 . 2006-03-15 15:00 66,082 --a------ C:\WINDOWS\system32\c_708.nls
2008-10-01 10:29 . 2006-03-15 15:00 66,082 --a------ C:\WINDOWS\system32\C_28596.NLS
2008-10-01 10:29 . 2006-03-15 15:00 66,082 --a------ C:\WINDOWS\system32\c_10021.nls
2008-10-01 10:29 . 2006-03-15 15:00 66,082 --a------ C:\WINDOWS\system32\c_10005.nls
2008-10-01 10:29 . 2006-03-15 15:00 66,082 --a------ C:\WINDOWS\system32\c_10004.nls
2008-10-01 10:29 . 2006-03-15 15:00 10,752 --a------ C:\WINDOWS\system32\c_iscii.dll
2008-10-01 10:29 . 2006-03-15 15:00 6,144 --a------ C:\WINDOWS\system32\ftlx041e.dll
2008-10-01 10:29 . 2006-03-15 15:00 5,632 --a------ C:\WINDOWS\system32\kbdusa.dll
2008-10-01 09:50 . 2008-10-22 12:22 <DIR> d-------- C:\Documents and Settings\LaDonna\Application Data\Yahoo!
2008-10-01 09:24 . 2008-10-01 09:25 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo!
2008-10-01 09:17 . 2008-10-01 09:17 <DIR> d---s---- C:\Documents and Settings\LaDonna\UserData
2008-10-01 09:09 . 2006-03-15 15:00 22,528 --a------ C:\WINDOWS\system32\lpdsvc.dll
2008-10-01 09:09 . 2006-03-15 15:00 22,528 --a------ C:\WINDOWS\system32\dllcache\lpdsvc.dll
2008-10-01 09:09 . 2006-03-15 15:00 18,944 --a------ C:\WINDOWS\system32\lprmon.dll
2008-10-01 09:09 . 2006-03-15 15:00 18,944 --a------ C:\WINDOWS\system32\dllcache\lprmon.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-25 00:30 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-23 18:48 --------- d-----w C:\Program Files\Yahoo!
2008-10-23 18:41 --------- d-----w C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion
2008-10-23 16:27 --------- d-----w C:\Program Files\Java
2008-10-17 00:24 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-10-01 18:03 --------- d-----w C:\Program Files\Symantec
2008-10-01 18:03 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-10-01 18:03 --------- d-----w C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
2008-10-01 15:41 --------- d-----w C:\Program Files\Hewlett-Packard
2008-10-01 15:28 --------- d-----w C:\Program Files\HPQ
2008-10-01 14:02 --------- d-----w C:\DOCUME~1\ALLUSE~1\APPLIC~1\WildTangent
2008-10-01 08:41 --------- d-----w C:\Program Files\Windows Plus
2008-10-01 08:41 --------- d-----w C:\Program Files\WildTangent
2008-10-01 08:41 --------- d-----w C:\Program Files\Synaptics
2008-10-01 08:41 --------- d-----w C:\Program Files\Sonic
2008-10-01 08:41 --------- d-----w C:\Program Files\RGB
2008-10-01 08:41 --------- d-----w C:\Program Files\Quickensetup
2008-10-01 08:41 --------- d-----w C:\Program Files\Quicken
2008-10-01 08:40 --------- d-----w C:\Program Files\NetWaiting
2008-10-01 08:39 --------- d-----w C:\Program Files\Netscape
2008-10-01 08:39 --------- d-----w C:\Program Files\muvee Technologies
2008-10-01 08:39 --------- d-----w C:\Program Files\music_now
2008-10-01 08:39 --------- d-----w C:\Program Files\Microsoft.NET
2008-10-01 08:39 --------- d-----w C:\Program Files\Microsoft Works
2008-10-01 08:39 --------- d-----w C:\Program Files\Microsoft Office Trial Wizard
2008-10-01 08:39 --------- d-----w C:\Program Files\Microsoft Money 2006
2008-10-01 08:38 --------- d-----w C:\Program Files\microsoft frontpage
2008-10-01 08:38 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-10-01 08:35 --------- d-----w C:\Program Files\HP
2008-10-01 08:34 --------- d-----w C:\Program Files\GemMaster
2008-10-01 08:34 --------- d-----w C:\Program Files\EnglishOtto
2008-10-01 08:34 --------- d-----w C:\Program Files\Encarta Online
2008-10-01 08:34 --------- d-----w C:\Program Files\DivX
2008-10-01 08:34 --------- d-----w C:\Program Files\CONEXANT
2008-10-01 08:34 --------- d-----w C:\Program Files\Common Files\TiVo Shared
2008-10-01 08:33 --------- d-----w C:\Program Files\Common Files\SureThing Shared
2008-10-01 08:33 --------- d-----w C:\Program Files\Common Files\Sonic Shared
2008-10-01 08:33 --------- d-----w C:\Program Files\Common Files\Palo Alto Software
2008-10-01 08:33 --------- d-----w C:\Program Files\Common Files\muvee Technologies
2008-10-01 08:33 --------- d-----w C:\Program Files\Common Files\LightScribe
2008-10-01 08:33 --------- d-----w C:\Program Files\Common Files\Java
2008-10-01 08:33 --------- d-----w C:\Program Files\Common Files\Intuit
2008-10-01 08:33 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-10-01 08:33 --------- d-----w C:\Program Files\Common Files\HP
2008-10-01 08:28 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Intuit
2008-10-01 08:28 --------- d-----w C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sonic
2008-10-01 08:28 --------- d-----w C:\DOCUME~1\ALLUSE~1\APPLIC~1\SBSI
2008-10-01 08:28 --------- d-----w C:\DOCUME~1\ALLUSE~1\APPLIC~1\Intuit
2008-10-01 08:28 --------- d-----w C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
2008-10-01 08:28 --------- d-----w C:\DOCUME~1\ALLUSE~1\APPLIC~1\HP
2008-10-01 08:28 --------- d-----w C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
2008-09-15 11:57 1,846,016 ----a-w C:\WINDOWS\system32\win32k.sys
2008-08-28 10:04 333,056 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-08-19 09:38 18,432 ------w C:\WINDOWS\system32\dllcache\iedw.exe
2008-08-14 09:55 2,142,720 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 09:51 138,368 ------w C:\WINDOWS\system32\dllcache\afd.sys
2008-08-14 09:18 2,020,864 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
.
((((((((((((((((((((((((((((( snapshot@2008-10-25_11.06.43.65 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-10-25 16:04:29 16,384 ----atw C:\WINDOWS\temp\Perflib_Perfdata_c70.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
2008-07-28 05:46 160496 --a------ C:\Program Files\Yahoo!\Companion\Installs\cpn2\YTSingleInstance.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2008-09-19 4347120]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]
"Search Protection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 64512]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-05-04 458752]
"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2008-10-23 136600]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-03-22 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-03-22 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-03-22 118784]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-06-17 794713]
"QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [2006-07-19 102400]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-06-19 163840]
"Cpqset"="C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe" [2006-06-19 40960]
"RecGuard"="C:\Windows\SMINST\RecGuard.exe" [2005-10-11 1187840]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"MsmqIntCert"="mqrt.dll" [2006-03-15 C:\WINDOWS\system32\mqrt.dll]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-06-02 C:\WINDOWS\system32\CHDAudPropShortcut.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 C:\WINDOWS\system32\bthprops.cpl]
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
HP Pavilion Webcam Tray Icon.lnk - C:\Program Files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe [2008-10-01 102400]
HP Photosmart Premier Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2005-09-24 73728]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\mqsvc.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
R0 pavboot;pavboot;C:\WINDOWS\system32\drivers\pavboot.sys [2008-06-19 28544]
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 JavaQuickStarterService;Java Quick Starter;C:\Program Files\Java\jre6\bin\jqs.exe [2008-10-23 152984]
S3 5U870CAP_VID_1262&PID_25FD;HP Pavilion Webcam ;C:\WINDOWS\system32\Drivers\5U870CAP.sys [2006-06-06 61952]
S3 getPlus(R) Helper;getPlus(R) Helper;C:\Program Files\NOS\bin\getPlus_HelperSvc.exe [2008-08-29 33752]
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-10-25 12:14:13
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe????????????L?@? ???0W??????`?@?????L?@
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-10-25 12:14:50
ComboFix-quarantined-files.txt 2008-10-25 17:14:46
ComboFix2.txt 2008-10-25 16:07:06
Pre-Run: 210,540,855,296 bytes free
Post-Run: 210,530,619,392 bytes free
346 --- E O F --- 2008-10-18 14:19:56
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:18:08, on 10/25/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\LaDonna\Desktop\jlo9955.exe.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://www.snapfish.com/hp_spring2006_iconnotebook
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: (no name) - {3BA5EAAE-060C-4E99-B6B0-7298054E6977} - (no file)
O2 - BHO: (no name) - {42AE1DA1-FF60-4435-A81F-9B6538F865A6} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5A99169A-45CB-495A-8A3F-2FD4AE221AC3} - (no file)
O2 - BHO: (no name) - {682B58B6-2D18-445A-8326-ECBDD5EE100B} - (no file)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {9744BD40-B4EA-4FD7-8017-DB333C992300} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - S-1-5-18 Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - Global Startup: HP Pavilion Webcam Tray Icon.lnk = C:\Program Files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=pavilion&pf=laptop
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) -
https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) -
http://www.worldwinner.com/games/v47/shared/FunGamesLoader.cab
O16 - DPF: {1D082E71-DF20-4AAF-863B-596428C49874} (TPIR Control) -
http://www.worldwinner.com/games/v50/tpir/tpir.cab
O16 - DPF: {2C153C75-8476-434B-B3C3-57B63A3D1939} (Brickout Control) -
http://www.worldwinner.com/games/v48/brickout/brickout.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) -
http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {42FDC231-A411-45F8-B8B6-3B5026111DA8} (SolitaireRush Control) -
http://www.worldwinner.com/games/v47/solitairerush/solitairerush.cab
O16 - DPF: {61900274-3323-4446-BDCD-91548D32AF1B} (SpiderSolitaire Control) -
http://www.worldwinner.com/games/v56/spidersolitaire/spidersolitaire.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1224906381421
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) -
http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) -
http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {E12EB891-D000-421B-A8ED-EDE1BDCA14A0} (GolfSol Control) -
http://www.worldwinner.com/games/v44/golfsol/golfsol.cab
O20 - Winlogon Notify: qoMcdCTk - C:\WINDOWS\
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
--
End of file - 10749 bytes