boarder04
2009-04-29, 05:03
I got a virus/malware a little bit ago, i was able to take care of it with malwarebyte's anti-malware. Now whenever i put in a removable usb drive it comes up with "the maximum number of secrets that may be stored in a single system has been exceeded."
Spybot comes up clean, except for windows security center being disabled, which it re-disables as soon as I fix it.
Logfile of HijackThis v1.99.1
Scan saved at 7:00:16 PM, on 4/28/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
c:\program files\pinnacle\shared files\programs\mediaserver\pmshost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Documents and Settings\Neil and Laurie\Desktop\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9150] command.com /c del "C:\WINDOWS\system32\UACkolwbuht.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4926] cmd.exe /c del "C:\WINDOWS\system32\UACkolwbuht.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6131] command.com /c del "C:\WINDOWS\system32\UACkolwbuht.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1773] cmd.exe /c del "C:\WINDOWS\system32\UACkolwbuht.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7596] command.com /c del "C:\WINDOWS\system32\UACmhossrsn.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2728] cmd.exe /c del "C:\WINDOWS\system32\UACmhossrsn.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8191] command.com /c del "C:\WINDOWS\system32\UACmhossrsn.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6830] cmd.exe /c del "C:\WINDOWS\system32\UACmhossrsn.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6518] command.com /c del "C:\WINDOWS\system32\UACwygktexy.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8779] cmd.exe /c del "C:\WINDOWS\system32\UACwygktexy.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2448] command.com /c del "C:\WINDOWS\system32\UACwygktexy.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC942] cmd.exe /c del "C:\WINDOWS\system32\UACwygktexy.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8930] command.com /c del "C:\WINDOWS\system32\drivers\UACiyqvpxgw.sys_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7749] cmd.exe /c del "C:\WINDOWS\system32\drivers\UACiyqvpxgw.sys_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2606] command.com /c del "C:\WINDOWS\system32\drivers\UACiyqvpxgw.sys"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6816] cmd.exe /c del "C:\WINDOWS\system32\drivers\UACiyqvpxgw.sys"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9639] command.com /c del "C:\WINDOWS\system32\UACtobiqgkl.log_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1675] cmd.exe /c del "C:\WINDOWS\system32\UACtobiqgkl.log_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6408] command.com /c del "C:\WINDOWS\system32\UACtobiqgkl.log"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4596] cmd.exe /c del "C:\WINDOWS\system32\UACtobiqgkl.log"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8954] command.com /c del "C:\WINDOWS\system32\UACmeqmplvo.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3566] cmd.exe /c del "C:\WINDOWS\system32\UACmeqmplvo.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8835] command.com /c del "C:\WINDOWS\system32\UACmeqmplvo.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4782] cmd.exe /c del "C:\WINDOWS\system32\UACmeqmplvo.dat"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [EPSON Stylus CX6000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBIA.EXE /FU "C:\WINDOWS\TEMP\E_S187.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB3483] command.com /c del "C:\WINDOWS\system32\UACkolwbuht.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2824] cmd.exe /c del "C:\WINDOWS\system32\UACkolwbuht.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7012] command.com /c del "C:\WINDOWS\system32\UACkolwbuht.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1047] cmd.exe /c del "C:\WINDOWS\system32\UACkolwbuht.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9048] command.com /c del "C:\WINDOWS\system32\UACmhossrsn.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5727] cmd.exe /c del "C:\WINDOWS\system32\UACmhossrsn.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1631] command.com /c del "C:\WINDOWS\system32\UACmhossrsn.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7949] cmd.exe /c del "C:\WINDOWS\system32\UACmhossrsn.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8547] command.com /c del "C:\WINDOWS\system32\UACwygktexy.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1874] cmd.exe /c del "C:\WINDOWS\system32\UACwygktexy.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2174] command.com /c del "C:\WINDOWS\system32\UACwygktexy.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6054] cmd.exe /c del "C:\WINDOWS\system32\UACwygktexy.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5352] command.com /c del "C:\WINDOWS\system32\drivers\UACiyqvpxgw.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4995] cmd.exe /c del "C:\WINDOWS\system32\drivers\UACiyqvpxgw.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8670] command.com /c del "C:\WINDOWS\system32\drivers\UACiyqvpxgw.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6648] cmd.exe /c del "C:\WINDOWS\system32\drivers\UACiyqvpxgw.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7976] command.com /c del "C:\WINDOWS\system32\UACtobiqgkl.log_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3247] cmd.exe /c del "C:\WINDOWS\system32\UACtobiqgkl.log_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9850] command.com /c del "C:\WINDOWS\system32\UACtobiqgkl.log"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5151] cmd.exe /c del "C:\WINDOWS\system32\UACtobiqgkl.log"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9996] command.com /c del "C:\WINDOWS\system32\UACmeqmplvo.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4562] cmd.exe /c del "C:\WINDOWS\system32\UACmeqmplvo.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB813] command.com /c del "C:\WINDOWS\system32\UACmeqmplvo.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6586] cmd.exe /c del "C:\WINDOWS\system32\UACmeqmplvo.dat"
O4 - Startup: Microsoft Find Fast.lnk.disabled
O4 - Startup: Office Startup.lnk.disabled
O4 - Global Startup: Adobe Reader Speed Launch.lnk.disabled
O4 - Global Startup: Microsoft Office.lnk.disabled
O4 - Global Startup: Service Manager.lnk.disabled
O4 - Global Startup: Windows Desktop Search.lnk.disabled
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International
O16 - DPF: {594ECDD4-A991-4208-A7B7-00DDAD9BE328} (Photosynth Class) - http://media.labs.live.com/all/ps/_code_/Photosynth.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5483.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pinnacle Systems Media Service (PinnacleSys.MediaServer) - Pinnacle Systems - c:\program files\pinnacle\shared files\programs\mediaserver\pmshost.exe
Spybot comes up clean, except for windows security center being disabled, which it re-disables as soon as I fix it.
Logfile of HijackThis v1.99.1
Scan saved at 7:00:16 PM, on 4/28/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
c:\program files\pinnacle\shared files\programs\mediaserver\pmshost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Documents and Settings\Neil and Laurie\Desktop\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9150] command.com /c del "C:\WINDOWS\system32\UACkolwbuht.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4926] cmd.exe /c del "C:\WINDOWS\system32\UACkolwbuht.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6131] command.com /c del "C:\WINDOWS\system32\UACkolwbuht.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1773] cmd.exe /c del "C:\WINDOWS\system32\UACkolwbuht.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7596] command.com /c del "C:\WINDOWS\system32\UACmhossrsn.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2728] cmd.exe /c del "C:\WINDOWS\system32\UACmhossrsn.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8191] command.com /c del "C:\WINDOWS\system32\UACmhossrsn.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6830] cmd.exe /c del "C:\WINDOWS\system32\UACmhossrsn.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6518] command.com /c del "C:\WINDOWS\system32\UACwygktexy.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8779] cmd.exe /c del "C:\WINDOWS\system32\UACwygktexy.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2448] command.com /c del "C:\WINDOWS\system32\UACwygktexy.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC942] cmd.exe /c del "C:\WINDOWS\system32\UACwygktexy.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8930] command.com /c del "C:\WINDOWS\system32\drivers\UACiyqvpxgw.sys_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7749] cmd.exe /c del "C:\WINDOWS\system32\drivers\UACiyqvpxgw.sys_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2606] command.com /c del "C:\WINDOWS\system32\drivers\UACiyqvpxgw.sys"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6816] cmd.exe /c del "C:\WINDOWS\system32\drivers\UACiyqvpxgw.sys"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9639] command.com /c del "C:\WINDOWS\system32\UACtobiqgkl.log_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1675] cmd.exe /c del "C:\WINDOWS\system32\UACtobiqgkl.log_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6408] command.com /c del "C:\WINDOWS\system32\UACtobiqgkl.log"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4596] cmd.exe /c del "C:\WINDOWS\system32\UACtobiqgkl.log"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8954] command.com /c del "C:\WINDOWS\system32\UACmeqmplvo.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3566] cmd.exe /c del "C:\WINDOWS\system32\UACmeqmplvo.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8835] command.com /c del "C:\WINDOWS\system32\UACmeqmplvo.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4782] cmd.exe /c del "C:\WINDOWS\system32\UACmeqmplvo.dat"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [EPSON Stylus CX6000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBIA.EXE /FU "C:\WINDOWS\TEMP\E_S187.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB3483] command.com /c del "C:\WINDOWS\system32\UACkolwbuht.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2824] cmd.exe /c del "C:\WINDOWS\system32\UACkolwbuht.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7012] command.com /c del "C:\WINDOWS\system32\UACkolwbuht.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1047] cmd.exe /c del "C:\WINDOWS\system32\UACkolwbuht.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9048] command.com /c del "C:\WINDOWS\system32\UACmhossrsn.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5727] cmd.exe /c del "C:\WINDOWS\system32\UACmhossrsn.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1631] command.com /c del "C:\WINDOWS\system32\UACmhossrsn.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7949] cmd.exe /c del "C:\WINDOWS\system32\UACmhossrsn.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8547] command.com /c del "C:\WINDOWS\system32\UACwygktexy.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1874] cmd.exe /c del "C:\WINDOWS\system32\UACwygktexy.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2174] command.com /c del "C:\WINDOWS\system32\UACwygktexy.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6054] cmd.exe /c del "C:\WINDOWS\system32\UACwygktexy.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5352] command.com /c del "C:\WINDOWS\system32\drivers\UACiyqvpxgw.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4995] cmd.exe /c del "C:\WINDOWS\system32\drivers\UACiyqvpxgw.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8670] command.com /c del "C:\WINDOWS\system32\drivers\UACiyqvpxgw.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6648] cmd.exe /c del "C:\WINDOWS\system32\drivers\UACiyqvpxgw.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7976] command.com /c del "C:\WINDOWS\system32\UACtobiqgkl.log_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3247] cmd.exe /c del "C:\WINDOWS\system32\UACtobiqgkl.log_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9850] command.com /c del "C:\WINDOWS\system32\UACtobiqgkl.log"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5151] cmd.exe /c del "C:\WINDOWS\system32\UACtobiqgkl.log"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9996] command.com /c del "C:\WINDOWS\system32\UACmeqmplvo.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4562] cmd.exe /c del "C:\WINDOWS\system32\UACmeqmplvo.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB813] command.com /c del "C:\WINDOWS\system32\UACmeqmplvo.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6586] cmd.exe /c del "C:\WINDOWS\system32\UACmeqmplvo.dat"
O4 - Startup: Microsoft Find Fast.lnk.disabled
O4 - Startup: Office Startup.lnk.disabled
O4 - Global Startup: Adobe Reader Speed Launch.lnk.disabled
O4 - Global Startup: Microsoft Office.lnk.disabled
O4 - Global Startup: Service Manager.lnk.disabled
O4 - Global Startup: Windows Desktop Search.lnk.disabled
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International
O16 - DPF: {594ECDD4-A991-4208-A7B7-00DDAD9BE328} (Photosynth Class) - http://media.labs.live.com/all/ps/_code_/Photosynth.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5483.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S30RP1.EXE
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pinnacle Systems Media Service (PinnacleSys.MediaServer) - Pinnacle Systems - c:\program files\pinnacle\shared files\programs\mediaserver\pmshost.exe