ComboFix log:
ComboFix 08-05-11.1 - bat 2008-05-11 15:39:18.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1044 [GMT -5:00]
Running from: C:\Documents and Settings\bat\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\pskt.ini
.
((((((((((((((((((((((((( Files Created from 2008-04-11 to 2008-05-11 )))))))))))))))))))))))))))))))
.
2008-05-11 14:57 . 2008-05-11 14:57 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-11 14:50 . 2008-05-11 14:50 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-11 14:50 . 2008-05-11 14:50 <DIR> d-------- C:\WINDOWS\LastGood
2008-05-11 14:50 . 2008-05-11 14:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-11 14:29 . 2008-05-11 14:29 <DIR> d-------- C:\Documents and Settings\Administrator
2008-05-11 14:29 . 2008-05-11 15:39 1,024 --ah----- C:\Documents and Settings\Administrator\NtUser.dat.LOG
2008-05-11 14:11 . 2008-05-11 14:11 <DIR> d-------- C:\!KillBox
2008-05-11 14:06 . 2008-05-11 14:07 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-05-11 14:06 . 2008-05-11 14:09 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-11 00:24 . 2008-05-11 00:24 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-11 00:24 . 2008-05-11 00:24 <DIR> d-------- C:\Documents and Settings\bat\Application Data\Malwarebytes
2008-05-11 00:24 . 2008-05-11 00:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-11 00:24 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-11 00:24 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-05-11 00:19 . 2008-05-11 00:19 <DIR> d-------- C:\VundoFix Backups
2008-05-10 23:48 . 2008-05-10 23:48 116,736 --a------ C:\WINDOWS\system32\ebuktfsm.dll
2008-05-10 23:45 . 2008-05-10 23:45 2,048 --a------ C:\WINDOWS\system32\kuebwjra.exe
2008-05-10 23:13 . 2008-05-10 23:13 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-05-10 22:00 . 2008-05-10 22:00 116,736 --a------ C:\WINDOWS\system32\sutunykq.dll
2008-05-10 21:57 . 2008-05-10 21:57 94,720 --a------ C:\WINDOWS\system32\ldyojsfm.dll
2008-05-10 21:54 . 2008-05-10 21:54 2,048 --a------ C:\WINDOWS\system32\llcnxbcs.exe
2008-05-10 21:52 . 2008-05-10 21:52 110,080 --a------ C:\WINDOWS\system32\vqihkfwj.dll
2008-05-10 20:56 . 2008-05-10 20:56 5,760,054 --a------ C:\WINDOWS\OfotoWP.bmp
2008-05-10 20:49 . 2008-05-10 20:49 94,720 --a------ C:\WINDOWS\system32\rmcgkfou.dll
2008-05-10 20:46 . 2008-05-10 20:46 2,048 --a------ C:\WINDOWS\system32\xoxbsfxq.exe
2008-05-10 20:43 . 2008-05-10 20:43 110,080 --a------ C:\WINDOWS\system32\axrogpwf.dll
2008-05-10 15:52 . 2008-05-10 15:52 94,720 --a------ C:\WINDOWS\system32\vwqnqkaj.dll
2008-05-10 15:49 . 2008-05-10 15:49 2,048 --a------ C:\WINDOWS\system32\wimcoixf.exe
2008-05-10 15:46 . 2008-05-10 15:46 116,736 --a------ C:\WINDOWS\system32\iqrdrepa.dll
2008-05-10 15:43 . 2008-05-10 15:43 110,080 --a------ C:\WINDOWS\system32\toldbmul.dll
2008-05-10 15:43 . 2008-05-10 23:58 109,807 --a------ C:\WINDOWS\BM03aed4f7.xml
2008-05-10 11:42 . 2008-05-10 11:42 38 --a------ C:\WINDOWS\AviSplitter.INI
2008-05-09 15:34 . 2008-05-11 00:37 <DIR> d-------- C:\WINDOWS\system32\vdTMP
2008-05-09 15:34 . 2008-05-11 00:37 <DIR> d-------- C:\WINDOWS\system32\hNF
2008-05-09 15:34 . 2008-05-11 00:37 <DIR> d-------- C:\WINDOWS\system32\2033b
2008-05-09 15:34 . 2008-05-09 15:34 <DIR> d-------- C:\Temp\maxsv15
2008-05-09 15:34 . 2008-05-10 23:54 <DIR> d-------- C:\Temp
2008-04-29 18:31 . 2008-04-29 18:31 <DIR> d-------- C:\Program Files\MSECache
2008-04-22 15:57 . 2008-04-22 15:58 151 --a------ C:\WINDOWS\PhotoSnapViewer.INI
2008-04-13 09:15 . 2008-04-13 09:15 <DIR> d-------- C:\Documents and Settings\bat\Application Data\Snapfish
2008-04-12 20:46 . 2008-04-13 20:23 10,152 --a------ C:\logfile
2008-04-12 20:42 . 2008-04-12 20:44 <DIR> d-------- C:\Program Files\Kodak
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-11 03:07 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-08 23:39 --------- d-----w C:\Documents and Settings\bat\Application Data\uTorrent
2008-05-07 01:43 --------- d-----w C:\Documents and Settings\bat\Application Data\LimeWire
2008-04-20 01:55 --------- d-----w C:\Program Files\World of Warcraft
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-03 06:28 691,545 ----a-w C:\WINDOWS\unins000.exe
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-16 09:32 666,112 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-10 19:43 141,909,560 ----a-w C:\Documents and Settings\bat\WoW-2.3.3.7799-to-0.4.0.7897-enUS-patch.exe
.
------- Sigcheck -------
2006-04-20 07:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
2007-10-30 11:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2006-04-20 06:51 359808 1dbf125862891817f374f407626967f4 C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
2006-02-28 07:00 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\$NtUninstallKB917953_0$\tcpip.sys
2007-09-25 16:46 360576 542e27b73c1c7ad3e40511d564d3da09 C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
2008-02-24 00:15 360064 482ab7f9cd41702e8f856c11cfefb02d C:\WINDOWS\system32\dllcache\TCPIP.SYS
2008-02-24 00:15 360064 482ab7f9cd41702e8f856c11cfefb02d C:\WINDOWS\system32\drivers\TCPIP.SYS
.
((((((((((((((((((((((((((((( snapshot@2008-05-10_23.58.05.54 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-11 04:55:55 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-11 19:45:19 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2005-05-24 17:27:16 213,048 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 20:47:20 94,208 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 20:49:54 950,272 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2947EA3B-B2F0-4E14-B9B6-CE5C7BB3971D}]
C:\WINDOWS\system32\qoMGWoLD.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BFA1A01C-CD74-4DA4-A75E-4031842A8FFF}]
C:\WINDOWS\system32\byXOfcDW.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fb5df11d-7a21-4d01-b38d-3b90e0a12fac}]
2008-05-10 23:48 116736 --a------ C:\WINDOWS\system32\ebuktfsm.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FE6D8B77-4CF2-45A7-A3E0-426BAC79DF2D}]
C:\WINDOWS\system32\hgGabBRi.dll
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2007-02-05 16:39 294400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= ffdshow.ax
"vidc.hfyu"= huffyuv.dll
"msacm.divxa32"= DivXa32.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=C:\WINDOWS\pss\Logitech SetPoint.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Desktop Search.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Desktop Search.lnk
backup=C:\WINDOWS\pss\Windows Desktop Search.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^bat^Start Menu^Programs^Startup^DW_Start.lnk]
path=C:\Documents and Settings\bat\Start Menu\Programs\Startup\DW_Start.lnk
backup=C:\WINDOWS\pss\DW_Start.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\
009de76b]
--a------ 2008-05-10 21:57 94720 C:\WINDOWS\system32\ldyojsfm.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
--a------ 2007-03-09 11:09 63712 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2007-05-11 03:06 40048 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
-ra------ 2007-03-01 10:37 2321600 C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
--a------ 2005-05-03 18:43 69632 C:\WINDOWS\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM03aed4f7]
--a------ 2008-05-10 21:52 110080 C:\WINDOWS\system32\vqihkfwj.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2006-02-28 07:00 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
--------- 2005-10-31 11:51 57344 C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dbar_starter]
C:\Documents and Settings\bat\Application Data\Deskbar_{E8066457-5AC5-41f6-BBC3-45A9F23FE2D9}\starter.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Fast anti]
C:\DOCUME~1\bat\APPLIC~1\16Dash\Wipe Sign Four.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Hardware Abstraction Layer]
--a------ 2007-04-11 15:32 56080 C:\WINDOWS\KHALMNPR.Exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nTrayFw]
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2007-06-29 00:43 8466432 C:\WINDOWS\system32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2007-06-29 00:43 81920 C:\WINDOWS\system32\NvMcTray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2007-06-29 00:43 1626112 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OfotoNow USB Detection]
C:\PROGRA~1\Ofoto\OfotoNow\OFUSBS.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\P17Helper]
--a------ 2005-05-03 20:38 64512 C:\WINDOWS\system32\P17.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-08-28 20:29 286720 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
--a------ 2007-08-10 15:21 16384000 C:\WINDOWS\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
C:\WINDOWS\mrofinu1188.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2008-01-28 12:43 2097488 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
--a------ 2006-11-10 12:35 90112 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2007-10-20 23:33 1271032 C:\Program Files\Steam\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-07-12 04:00 132496 C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec PIF AlertEng]
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UltraMon]
C:\Program Files\UltraMon\UltraMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
--------- 2000-05-11 02:00 90112 C:\WINDOWS\UpdReg.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\warn default inter for]
C:\Documents and Settings\All Users\Application Data\Time Dead Warn Default\Way Jump.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebSUpdater]
C:\Program Files\winvi\wupda.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinUpdater]
C:\Program Files\winvi\update.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{DE-E7-7C-C4-DW}]
C:\WINDOWS\system32\vdTMP\bvre32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"ose"=3 (0x3)
"NVSvc"=2 (0x2)
"nSvcLog"=2 (0x2)
"KodakCCS"=3 (0x3)
"idsvc"=3 (0x3)
"ForcewareWebInterface"=2 (0x2)
"ATI Smart"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\WINDOWS\\system32\\rundll32.exe"=
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
S3 UltraMonMirror;UltraMonMirror;C:\WINDOWS\system32\DRIVERS\UltraMonMirror.sys []
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-05-01 23:22:13 C:\WINDOWS\Tasks\EasyShare Registration Task.job"
- C:\WINDOWS\system32\rundll32.exelC:\DOCUME~1\ALLUSE~1\APPLIC~1\Kodak\EasyShareSetup\$REGIS~1\Registration_7.5.30.2.sxt _RegistrationOffer@16
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-11 15:40:33
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-05-11 15:41:11
ComboFix-quarantined-files.txt 2008-05-11 20:41:07
ComboFix2.txt 2008-05-11 04:58:16
Pre-Run: 141,010,558,976 bytes free
Post-Run: 141,003,694,080 bytes free
229 --- E O F --- 2008-05-11 08:17:06
HIJACK THIS! log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:44:52 PM, on 5/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.whynotsearchhere.com/start.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {2947EA3B-B2F0-4E14-B9B6-CE5C7BB3971D} - C:\WINDOWS\system32\qoMGWoLD.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {BFA1A01C-CD74-4DA4-A75E-4031842A8FFF} - C:\WINDOWS\system32\byXOfcDW.dll (file missing)
O2 - BHO: {caf21a0e-09b3-d83b-10d4-12a7d11fd5bf} - {fb5df11d-7a21-4d01-b38d-3b90e0a12fac} - C:\WINDOWS\system32\ebuktfsm.dll
O2 - BHO: (no name) - {FE6D8B77-4CF2-45A7-A3E0-426BAC79DF2D} - C:\WINDOWS\system32\hgGabBRi.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) -
http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1188108173671
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) -
http://driveragent.com/files/driveragent.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) -
http://www.creative.com/su2/CTL_V02002/ocx/15033/CTPID.cab
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
--
End of file - 3518 bytes