My laptop lost power

at the end of running combo fix, but it seemed to pickup where it left off when I turned it back in. Let me know if I need to repeat anything because of that.
Combofix Log:
ComboFix 08-10-29.07 - Lisa Yiu 2008-10-30 9:02:16.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.600 [GMT -7:00]
Running from: C:\Documents and Settings\Lisa Yiu\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Lisa Yiu\Desktop\CFScript.txt
* Created a new restore point
FILE ::
C:\avremove.csv
C:\WINDOWS\system32\g38.exe
C:\WINDOWS\system32\hikjlmupwmdpxdhyq.exe
C:\WINDOWS\system32\Jamster.ico
C:\WINDOWS\system32\rcntptdl.exe
C:\WINDOWS\system32\vprfbtmwxabgda.dll
C:\WINDOWS\system32\vwytzykprnnesd.dll
C:\WINDOWS\system32\vwytzykprnnesd.dll-uninst.exe
C:\WINDOWS\system32\ZoneAlarmIconUS.ico
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\avremove.csv
C:\Documents and Settings\Lisa Yiu\Application Data\Gool
C:\Documents and Settings\Lisa Yiu\Application Data\Gool\Gool.exe
C:\Documents and Settings\Lisa Yiu\Temporary Internet Files\bestwiner.stt
C:\ESXPXML
C:\ESXPXML\cac.pem
C:\ESXPXML\cidsync.upd
C:\ESXPXML\instmsiw.exe
C:\ESXPXML\master.upd
C:\ESXPXML\mrinit.conf
C:\ESXPXML\product.spi
C:\ESXPXML\root.upd
C:\ESXPXML\sau\1028.mst
C:\ESXPXML\sau\1031.mst
C:\ESXPXML\sau\1033.mst
C:\ESXPXML\sau\1034.mst
C:\ESXPXML\sau\1036.mst
C:\ESXPXML\sau\1040.mst
C:\ESXPXML\sau\1041.mst
C:\ESXPXML\sau\2052.mst
C:\ESXPXML\sau\3076.mst
C:\ESXPXML\sau\cidsync.upd
C:\ESXPXML\sau\commonappdata\sophos\autoupdate\defaultconfig\iconn.cfg
C:\ESXPXML\sau\commonappdata\sophos\autoupdate\defaultconfig\idata.cfg
C:\ESXPXML\sau\commonappdata\sophos\autoupdate\defaultconfig\ilog.cfg
C:\ESXPXML\sau\commonappdata\sophos\autoupdate\defaultconfig\imon.cfg
C:\ESXPXML\sau\commonappdata\sophos\autoupdate\defaultconfig\isched.cfg
C:\ESXPXML\sau\commonappdata\sophos\autoupdate\defaultconfig\iupd.cfg
C:\ESXPXML\sau\manifest.dat
C:\ESXPXML\sau\program files\sophos\autoupdate\almon.exe
C:\ESXPXML\sau\program files\sophos\autoupdate\almon.exe.manifest
C:\ESXPXML\sau\program files\sophos\autoupdate\alsvc.exe
C:\ESXPXML\sau\program files\sophos\autoupdate\alupdate.exe
C:\ESXPXML\sau\program files\sophos\autoupdate\auadapter.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\boost_date_time-vc71-mt-1_32.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\channelupdater.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\cidsync.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\config.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\crypto.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\de\alhelp.chm
C:\ESXPXML\sau\program files\sophos\autoupdate\de\almonres.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\de\iconfres.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\de\ilogres.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\de\ischdres.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\de\sharedres.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\eecustomactions.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\en\alhelp.chm
C:\ESXPXML\sau\program files\sophos\autoupdate\en\almonres.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\en\iconfres.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\en\ilogres.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\en\ischdres.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\en\sharedres.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\es\alhelp.chm
C:\ESXPXML\sau\program files\sophos\autoupdate\es\almonres.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\es\iconfres.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\es\ilogres.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\es\ischdres.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\es\sharedres.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\fr\alhelp.chm
C:\ESXPXML\sau\program files\sophos\autoupdate\fr\almonres.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\fr\iconfres.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\fr\ilogres.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\fr\ischdres.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\fr\sharedres.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\iconfig.ppi
C:\ESXPXML\sau\program files\sophos\autoupdate\ilog.ppi
C:\ESXPXML\sau\program files\sophos\autoupdate\inetconn.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\instlmgr.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\isched.ppi
C:\ESXPXML\sau\program files\sophos\autoupdate\ispsheet.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\it\alhelp.chm
C:\ESXPXML\sau\program files\sophos\autoupdate\it\almonres.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\it\iconfres.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\it\ilogres.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\it\ischdres.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\it\sharedres.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\ja\alhelp.chm
C:\ESXPXML\sau\program files\sophos\autoupdate\ja\almonres.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\ja\iconfres.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\ja\ilogres.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\ja\ischdres.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\ja\sharedres.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\libcurl.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\libeay32.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\license_agreements.txt
C:\ESXPXML\sau\program files\sophos\autoupdate\logger.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\mfc71.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\msvcp71.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\msvcr71.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\ps.crl
C:\ESXPXML\sau\program files\sophos\autoupdate\ps_rootca.crt
C:\ESXPXML\sau\program files\sophos\autoupdate\retailer.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\sauconfigdll.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\scf.dat
C:\ESXPXML\sau\program files\sophos\autoupdate\swlocale.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\xmlcpp.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\xmlparse.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\xmltok.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\zh_cn\alhelp.chm
C:\ESXPXML\sau\program files\sophos\autoupdate\zh_cn\almonres.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\zh_cn\iconfres.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\zh_cn\ilogres.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\zh_cn\ischdres.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\zh_cn\sharedres.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\zh_tw\alhelp.chm
C:\ESXPXML\sau\program files\sophos\autoupdate\zh_tw\almonres.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\zh_tw\iconfres.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\zh_tw\ilogres.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\zh_tw\ischdres.dll
C:\ESXPXML\sau\program files\sophos\autoupdate\zh_tw\sharedres.dll
C:\ESXPXML\sau\sauconf.xml
C:\ESXPXML\sau\setup.dll
C:\ESXPXML\sau\sophos autoupdate.msi
C:\ESXPXML\sau\toplevelcatalogue.dat
C:\ESXPXML\savxp\access-a.ide
C:\ESXPXML\savxp\agen-fam.ide
C:\ESXPXML\savxp\agen-ghf.ide
C:\ESXPXML\savxp\agen-ghm.ide
C:\ESXPXML\savxp\agen-ghn.ide
C:\ESXPXML\savxp\agen-ght.ide
C:\ESXPXML\savxp\agen-gia.ide
C:\ESXPXML\savxp\agen-gil.ide
C:\ESXPXML\savxp\agen-giq.ide
C:\ESXPXML\savxp\agen-gis.ide
C:\ESXPXML\savxp\agen-giu.ide
C:\ESXPXML\savxp\agen-giv.ide
C:\ESXPXML\savxp\agen-giy.ide
C:\ESXPXML\savxp\agen-gjg.ide
C:\ESXPXML\savxp\agen-gjl.ide
C:\ESXPXML\savxp\agen-gjq.ide
C:\ESXPXML\savxp\agen-gjr.ide
C:\ESXPXML\savxp\agen-gju.ide
C:\ESXPXML\savxp\agen-gkh.ide
C:\ESXPXML\savxp\agen-gki.ide
C:\ESXPXML\savxp\agen-gkk.ide
C:\ESXPXML\savxp\agen-gkl.ide
C:\ESXPXML\savxp\agen-glf.ide
C:\ESXPXML\savxp\ambler-a.ide
C:\ESXPXML\savxp\appc01.vdb
C:\ESXPXML\savxp\atax-a.ide
C:\ESXPXML\savxp\autor-ad.ide
C:\ESXPXML\savxp\autor-ae.ide
C:\ESXPXML\savxp\autor-ag.ide
C:\ESXPXML\savxp\autoru-s.ide
C:\ESXPXML\savxp\autoru-t.ide
C:\ESXPXML\savxp\autoru-x.ide
C:\ESXPXML\savxp\autoru-y.ide
C:\ESXPXML\savxp\bagle-ti.ide
C:\ESXPXML\savxp\bancb-qr.ide
C:\ESXPXML\savxp\banco-ak.ide
C:\ESXPXML\savxp\bank-ejw.ide
C:\ESXPXML\savxp\bank-ekh.ide
C:\ESXPXML\savxp\bankd-dc.ide
C:\ESXPXML\savxp\banlo-et.ide
C:\ESXPXML\savxp\banlo-eu.ide
C:\ESXPXML\savxp\bbdos-a.ide
C:\ESXPXML\savxp\bckd-qkk.ide
C:\ESXPXML\savxp\bckd-qku.ide
C:\ESXPXML\savxp\bdoo-aiy.ide
C:\ESXPXML\savxp\bdoo-ajb.ide
C:\ESXPXML\savxp\binder-a.ide
C:\ESXPXML\savxp\blehs-a.ide
C:\ESXPXML\savxp\buzzit-b.ide
C:\ESXPXML\savxp\cargar-a.ide
C:\ESXPXML\savxp\cashgr-t.ide
C:\ESXPXML\savxp\cekar-e.ide
C:\ESXPXML\savxp\cidsync.upd
C:\ESXPXML\savxp\cimuz-cs.ide
C:\ESXPXML\savxp\common\cisco systems\ciscotrustagent\plugins\install\savpostureplugin.dll
C:\ESXPXML\savxp\common\cisco systems\ciscotrustagent\plugins\install\savpostureplugin.inf
C:\ESXPXML\savxp\commonappdata\sophos\sophos anti-virus\config\bootstrap.xml
C:\ESXPXML\savxp\commonappdata\sophos\sophos anti-virus\config\factory.xml
C:\ESXPXML\savxp\commonappdata\sophos\sophos anti-virus\config\machine.xml
C:\ESXPXML\savxp\commonappdata\sophos\sophos anti-virus\config\quarantine.xml
C:\ESXPXML\savxp\commonappdata\sophos\sophos anti-virus\config\saviconfigfile.xml
C:\ESXPXML\savxp\commonappdata\sophos\sophos anti-virus\config\storebootstrap.xml
C:\ESXPXML\savxp\configuresav.exe
C:\ESXPXML\savxp\conho-al.ide
C:\ESXPXML\savxp\delf-ezc.ide
C:\ESXPXML\savxp\delf-ezi.ide
C:\ESXPXML\savxp\dloa-bfz.ide
C:\ESXPXML\savxp\dloa-bgi.ide
C:\ESXPXML\savxp\dloa-bgo.ide
C:\ESXPXML\savxp\dloa-bgr.ide
C:\ESXPXML\savxp\dloa-bgs.ide
C:\ESXPXML\savxp\dload-ab.ide
C:\ESXPXML\savxp\dload-ae.ide
C:\ESXPXML\savxp\dload-af.ide
C:\ESXPXML\savxp\dload-ag.ide
C:\ESXPXML\savxp\dload-ai.ide
C:\ESXPXML\savxp\dload-am.ide
C:\ESXPXML\savxp\dorf-aj.ide
C:\ESXPXML\savxp\dorf-ak.ide
C:\ESXPXML\savxp\dorf-am.ide
C:\ESXPXML\savxp\dorf-an.ide
C:\ESXPXML\savxp\dorf-ao.ide
C:\ESXPXML\savxp\droopy-a.ide
C:\ESXPXML\savxp\drop-d.ide
C:\ESXPXML\savxp\drop-e.ide
C:\ESXPXML\savxp\dropp-sr.ide
C:\ESXPXML\savxp\dropp-sz.ide
C:\ESXPXML\savxp\drpr-gen.ide
C:\ESXPXML\savxp\dwnl-gzh.ide
C:\ESXPXML\savxp\dwnl-gzs.ide
C:\ESXPXML\savxp\etap-a.ide
C:\ESXPXML\savxp\feebs-bz.ide
C:\ESXPXML\savxp\feebs-ca.ide
C:\ESXPXML\savxp\flux-eg.ide
C:\ESXPXML\savxp\framer-b.ide
C:\ESXPXML\savxp\goopo-a.ide
C:\ESXPXML\savxp\hipsconfig-1-0-4.dat
C:\ESXPXML\savxp\hipsrules-1-0-4.bdl
C:\ESXPXML\savxp\hookbi-a.ide
C:\ESXPXML\savxp\hoxi-b.ide
C:\ESXPXML\savxp\hoxi-d.ide
C:\ESXPXML\savxp\hupig-sv.ide
C:\ESXPXML\savxp\hupig-sx.ide
C:\ESXPXML\savxp\idas-a.ide
C:\ESXPXML\savxp\ircbo-zm.ide
C:\ESXPXML\savxp\jalous-a.ide
C:\ESXPXML\savxp\jetdro-a.ide
C:\ESXPXML\savxp\kenfa-a.ide
C:\ESXPXML\savxp\killa-ed.ide
C:\ESXPXML\savxp\killdi-l.ide
C:\ESXPXML\savxp\killfi-i.ide
C:\ESXPXML\savxp\ldpin-rg.ide
C:\ESXPXML\savxp\linea-cu.ide
C:\ESXPXML\savxp\linea-cv.ide
C:\ESXPXML\savxp\linea-cw.ide
C:\ESXPXML\savxp\looke-eb.ide
C:\ESXPXML\savxp\mabeza-b.ide
C:\ESXPXML\savxp\mailb-ci.ide
C:\ESXPXML\savxp\manifest.dat
C:\ESXPXML\savxp\mutrk-a.ide
C:\ESXPXML\savxp\mypi-fam.ide
C:\ESXPXML\savxp\nmism-a.ide
C:\ESXPXML\savxp\ntrtdr-a.ide
C:\ESXPXML\savxp\nugach-i.ide
C:\ESXPXML\savxp\nutpea-a.ide
C:\ESXPXML\savxp\onlin-ag.ide
C:\ESXPXML\savxp\osdp.dll
C:\ESXPXML\savxp\patch-c.ide
C:\ESXPXML\savxp\phish-b.ide
C:\ESXPXML\savxp\poison-n.ide
C:\ESXPXML\savxp\ppntdr-a.ide
C:\ESXPXML\savxp\proage-a.ide
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\categories.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\module retargetable folder\authorisedlists.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\module retargetable folder\backgroundscanclient.exe
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\module retargetable folder\backgroundscanning.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\module retargetable folder\bhomanagement.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\module retargetable folder\componentmanager.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\module retargetable folder\configuration.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\module retargetable folder\desktopmessaging.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\module retargetable folder\driveprocessor.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\module retargetable folder\eeconsumer.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\module retargetable folder\filterprocessors.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\module retargetable folder\fsdecomposer.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\module retargetable folder\icadapter.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\module retargetable folder\icmanagement.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\module retargetable folder\icprocessors.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\module retargetable folder\legacyconsumers.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\module retargetable folder\localisation.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\module retargetable folder\logging.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\module retargetable folder\persistance.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\module retargetable folder\savadapter.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\module retargetable folder\savmain.exe
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\module retargetable folder\savprogress.exe
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\module retargetable folder\savshellext.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\module retargetable folder\scaneditexports.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\module retargetable folder\scaneditfacade.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\module retargetable folder\scanmanagement.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\module retargetable folder\security.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\module retargetable folder\sipsmanagement.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\module retargetable folder\sophtaineradapter.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\module retargetable folder\systeminformation.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\module retargetable folder\threatdetection.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\module retargetable folder\threatmanagement.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\module retargetable folder\translators.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\module retargetable folder\virusdetection.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\msvcp71.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\msvcr71.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\sav32cli.exe
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\savadminservice.exe
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\savcleanupservice.exe
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\savhelpchs.chm
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\savhelpcht.chm
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\savhelpdeu.chm
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\savhelpeng.chm
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\savhelpesp.chm
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\savhelpfra.chm
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\savhelpit.chm
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\savhelpjap.chm
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\savmscm.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\savneutralres.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\savres.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\savreschs.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\savrescht.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\savresdeu.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\savreseng.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\savresesp.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\savresfra.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\savresit.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\savresjap.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\savservice.exe
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\savshellextia64.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\savshellextx64.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\scf.dat
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\sophos anti-virus (de).url
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\sophos anti-virus (es).url
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\sophos anti-virus (fr).url
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\sophos anti-virus (it).url
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\sophos anti-virus (ja).url
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\sophos anti-virus (zh_cn).url
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\sophos anti-virus (zh_tw).url
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\sophos anti-virus.url
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\sophosbho.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\sophosbhoia64.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\sophosbhores.dll
C:\ESXPXML\savxp\program files\sophos\sophos anti-virus\sophosbhox64.dll
C:\ESXPXML\savxp\proxy-ib.ide
C:\ESXPXML\savxp\psyme-fx.ide
C:\ESXPXML\savxp\psyme-gb.ide
C:\ESXPXML\savxp\psyme-gc.ide
C:\ESXPXML\savxp\psyme-gm.ide
C:\ESXPXML\savxp\pushu-e.ide
C:\ESXPXML\savxp\pushu-f.ide
C:\ESXPXML\savxp\pws-apl.ide
C:\ESXPXML\savxp\pws-apw.ide
C:\ESXPXML\savxp\ranck-fs.ide
C:\ESXPXML\savxp\rbot-gvk.ide
C:\ESXPXML\savxp\rbot-gvl.ide
C:\ESXPXML\savxp\rbot-gvm.ide
C:\ESXPXML\savxp\rbot-gvo.ide
C:\ESXPXML\savxp\rbot-gvr.ide
C:\ESXPXML\savxp\remmah-b.ide
C:\ESXPXML\savxp\revkey-a.ide
C:\ESXPXML\savxp\savi.dll
C:\ESXPXML\savxp\savsync.upd
C:\ESXPXML\savxp\sdbo-djc.ide
C:\ESXPXML\savxp\sdbo-dje.ide
C:\ESXPXML\savxp\setup.dll
C:\ESXPXML\savxp\silly-bp.ide
C:\ESXPXML\savxp\silly-bq.ide
C:\ESXPXML\savxp\silly-tl.ide
C:\ESXPXML\savxp\silly-tt.ide
C:\ESXPXML\savxp\sillyp-a.ide
C:\ESXPXML\savxp\smit-a.ide
C:\ESXPXML\savxp\sohan-ap.ide
C:\ESXPXML\savxp\sophos anti-virus.msi
C:\ESXPXML\savxp\sophos_detoured.dll
C:\ESXPXML\savxp\spy-ad.ide
C:\ESXPXML\savxp\spybo-of.ide
C:\ESXPXML\savxp\startp-w.ide
C:\ESXPXML\savxp\strat-tl.ide
C:\ESXPXML\savxp\sus01.vdb
C:\ESXPXML\savxp\svf.xml
C:\ESXPXML\savxp\sxs\msxml4.cat
C:\ESXPXML\savxp\sxs\msxml4.dll
C:\ESXPXML\savxp\sxs\msxml4.manifest
C:\ESXPXML\savxp\sxs\msxml4r.cat
C:\ESXPXML\savxp\sxs\msxml4r.dll
C:\ESXPXML\savxp\sxs\msxml4r.manifest
C:\ESXPXML\savxp\system\msxml4.dll
C:\ESXPXML\savxp\system\msxml4a.dll
C:\ESXPXML\savxp\system\msxml4r.dll
C:\ESXPXML\savxp\tagbot-a.ide
C:\ESXPXML\savxp\tanto-g.ide
C:\ESXPXML\savxp\tibs-tv.ide
C:\ESXPXML\savxp\tibspk-b.ide
C:\ESXPXML\savxp\tileb-kr.ide
C:\ESXPXML\savxp\torpi-by.ide
C:\ESXPXML\savxp\trats-a.ide
C:\ESXPXML\savxp\trinit-c.ide
C:\ESXPXML\savxp\vb-dyd.ide
C:\ESXPXML\savxp\vb-dye.ide
C:\ESXPXML\savxp\vb-dyf.ide
C:\ESXPXML\savxp\vbdrop-e.ide
C:\ESXPXML\savxp\vdl.dat
C:\ESXPXML\savxp\vdl01.vdb
C:\ESXPXML\savxp\vdl02.vdb
C:\ESXPXML\savxp\vdl03.vdb
C:\ESXPXML\savxp\vdl04.vdb
C:\ESXPXML\savxp\vdl05.vdb
C:\ESXPXML\savxp\vdl06.vdb
C:\ESXPXML\savxp\vdl07.vdb
C:\ESXPXML\savxp\vdl08.vdb
C:\ESXPXML\savxp\vdl09.vdb
C:\ESXPXML\savxp\vdl10.vdb
C:\ESXPXML\savxp\vdl11.vdb
C:\ESXPXML\savxp\vdl12.vdb
C:\ESXPXML\savxp\vdl13.vdb
C:\ESXPXML\savxp\vdl14.vdb
C:\ESXPXML\savxp\vdl15.vdb
C:\ESXPXML\savxp\vdl16.vdb
C:\ESXPXML\savxp\vdl17.vdb
C:\ESXPXML\savxp\vdl18.vdb
C:\ESXPXML\savxp\vdl19.vdb
C:\ESXPXML\savxp\vdl20.vdb
C:\ESXPXML\savxp\vdl21.vdb
C:\ESXPXML\savxp\vdl22.vdb
C:\ESXPXML\savxp\vdl23.vdb
C:\ESXPXML\savxp\vdl24.vdb
C:\ESXPXML\savxp\vdl25.vdb
C:\ESXPXML\savxp\vdl26.vdb
C:\ESXPXML\savxp\vdl27.vdb
C:\ESXPXML\savxp\vdl28.vdb
C:\ESXPXML\savxp\vdl29.vdb
C:\ESXPXML\savxp\vdl30.vdb
C:\ESXPXML\savxp\vdl31.vdb
C:\ESXPXML\savxp\vdl32.vdb
C:\ESXPXML\savxp\vdl33.vdb
C:\ESXPXML\savxp\vdl34.vdb
C:\ESXPXML\savxp\vdl35.vdb
C:\ESXPXML\savxp\vdl36.vdb
C:\ESXPXML\savxp\vdl37.vdb
C:\ESXPXML\savxp\veex.dll
C:\ESXPXML\savxp\virtin-a.ide
C:\ESXPXML\savxp\virtin-b.ide
C:\ESXPXML\savxp\votera-a.ide
C:\ESXPXML\savxp\vvf.xml
C:\ESXPXML\savxp\weird-l.ide
C:\ESXPXML\savxp\wiepaz-a.ide
C:\ESXPXML\savxp\win2k\savonaccesscontrol.sys
C:\ESXPXML\savxp\win2k\savonaccessdriv.inf
C:\ESXPXML\savxp\win2k\savonaccessfilter.sys
C:\ESXPXML\savxp\win2k\sophosboottasks.exe
C:\ESXPXML\savxp\winlh_amd64\native.exe
C:\ESXPXML\savxp\winlh_amd64\sav.cat
C:\ESXPXML\savxp\winlh_amd64\savonaccess.sys
C:\ESXPXML\savxp\winlh_amd64\savonaccessdriv.inf
C:\ESXPXML\savxp\winlh_amd64\sophosboottasks.exe
C:\ESXPXML\savxp\winlh_i386\sav.cat
C:\ESXPXML\savxp\winlh_i386\savonaccess.sys
C:\ESXPXML\savxp\winlh_i386\savonaccessdriv.inf
C:\ESXPXML\savxp\winlh_i386\sophosboottasks.exe
C:\ESXPXML\savxp\winlh_ia64\native.exe
C:\ESXPXML\savxp\winlh_ia64\sav.cat
C:\ESXPXML\savxp\winlh_ia64\savonaccess.sys
C:\ESXPXML\savxp\winlh_ia64\savonaccessdriv.inf
C:\ESXPXML\savxp\winlh_ia64\sophosboottasks.exe
C:\ESXPXML\savxp\winxp_amd64\native.exe
C:\ESXPXML\savxp\winxp_amd64\savonaccesscontrol.sys
C:\ESXPXML\savxp\winxp_amd64\savonaccessdriv.inf
C:\ESXPXML\savxp\winxp_amd64\savonaccessfilter.sys
C:\ESXPXML\savxp\winxp_amd64\sophosboottasks.exe
C:\ESXPXML\savxp\winxp_i386\sav.cat
C:\ESXPXML\savxp\winxp_i386\savonaccesscontrol.sys
C:\ESXPXML\savxp\winxp_i386\savonaccessdriv.inf
C:\ESXPXML\savxp\winxp_i386\savonaccessfilter.sys
C:\ESXPXML\savxp\winxp_i386\sophosboottasks.exe
C:\ESXPXML\savxp\winxp_ia64\native.exe
C:\ESXPXML\savxp\winxp_ia64\savonaccesscontrol.sys
C:\ESXPXML\savxp\winxp_ia64\savonaccessdriv.inf
C:\ESXPXML\savxp\winxp_ia64\savonaccessfilter.sys
C:\ESXPXML\savxp\winxp_ia64\sophosboottasks.exe
C:\ESXPXML\savxp\xorer-a.ide
C:\ESXPXML\savxp\ymworm-a.ide
C:\ESXPXML\savxp\zbot-b.ide
C:\ESXPXML\savxp\zlob-agj.ide
C:\ESXPXML\savxp\zlob-ago.ide
C:\ESXPXML\savxp\zlob-fam.ide
C:\ESXPXML\sdf.xml
C:\ESXPXML\setup.exe
C:\ESXPXML\setupchs.dll
C:\ESXPXML\setupcht.dll
C:\ESXPXML\setupdeu.dll
C:\ESXPXML\setupenu.dll
C:\ESXPXML\setupesp.dll
C:\ESXPXML\setupfra.dll
C:\ESXPXML\setupita.dll
C:\ESXPXML\setupjpn.dll
C:\ESXPXML\svf.xml
C:\ESXPXML\vvf.xml
C:\Program Files\Common Files\ufur
C:\Program Files\Common Files\ufur\ufura.lck
C:\Program Files\Common Files\ufur\ufurd\class-barrel
C:\Program Files\Common Files\ufur\ufurd\vocabulary
C:\Program Files\Common Files\ufur\ufurl.lck
C:\Program Files\Common Files\ufur\ufurm.lck
C:\Program Files\Mjcore
C:\Program Files\Mjcore\Mjcore.dll
C:\Program Files\PasswordDirector
C:\Program Files\PasswordDirector\clvlk2.dll
C:\Program Files\PasswordDirector\lartl.dll
C:\Program Files\PasswordDirector\PasswordDirector.exe
C:\Program Files\PasswordDirector\pwdir.dll
C:\Program Files\PasswordDirector\scrkbd.dll
C:\Program Files\PasswordDirector\sf.dll
C:\Program Files\PasswordDirector\vdicapi.dll
C:\Program Files\Webtools
C:\Program Files\Webtools\webtools.dll
C:\WINDOWS\system32\ec2
C:\WINDOWS\system32\EV02
C:\WINDOWS\system32\EV02\EV022328.exe
C:\WINDOWS\system32\fs3
C:\WINDOWS\system32\fs3\CL65CON2.exe
C:\WINDOWS\system32\g38.exe
C:\WINDOWS\system32\hikjlmupwmdpxdhyq.exe
C:\WINDOWS\system32\Jamster.ico
C:\WINDOWS\system32\m3v
C:\WINDOWS\system32\PX
C:\WINDOWS\system32\PX\TP6567IV.exe
C:\WINDOWS\system32\rcntptdl.exe
C:\WINDOWS\system32\vprfbtmwxabgda.dll
C:\WINDOWS\system32\vwytzykprnnesd.dll-uninst.exe
C:\WINDOWS\system32\vwytzykprnnesd.dll
C:\WINDOWS\system32\wi
C:\WINDOWS\system32\ZoneAlarmIconUS.ico
C:\WINDOWS\TGlzYSBZaXU
C:\WINDOWS\ufur
C:\WINDOWS\ufur\ufur.dat
C:\WINDOWS\ufur\wu
.
((((((((((((((((((((((((( Files Created from 2008-09-28 to 2008-10-30 )))))))))))))))))))))))))))))))
.
2008-10-30 08:55 . <DIR> C:\WINDOWS\LastGood.Tmp
2008-10-29 11:41 . 2008-10-29 11:49 <DIR> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-10-29 08:07 . 2008-10-29 11:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-10-28 20:54 . 2008-10-28 20:55 <DIR> d-------- C:\Program Files\CCleaner
2008-10-28 20:49 . 2008-10-28 20:49 <DIR> d-------- C:\Program Files\Common Files\Cisco Systems
2008-10-28 20:49 . 2008-10-28 20:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Sophos
2008-10-28 20:49 . 2008-10-29 14:25 17,920 --a------ C:\WINDOWS\system32\sophosboottasks.exe
2008-10-28 20:03 . 2008-10-28 20:03 <DIR> d-------- C:\Program Files\Trend Micro
2008-10-28 19:04 . 2008-10-29 14:25 <DIR> d-------- C:\Program Files\Sophos
2008-10-28 19:04 . 2008-10-29 14:26 101,120 --a------ C:\WINDOWS\system32\drivers\savonaccesscontrol.sys
2008-10-28 19:04 . 2008-10-29 14:26 33,408 --a------ C:\WINDOWS\system32\drivers\savonaccessfilter.sys
2008-10-28 15:40 . 2008-10-28 16:32 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-10-28 15:40 . 2008-10-28 17:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-28 13:25 . 2008-10-28 13:25 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\Yahoo!
2008-10-27 03:48 . 2008-10-27 03:48 <DIR> d-------- C:\Program Files\Sun
2008-10-26 02:52 . 2008-10-26 02:52 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Yahoo!
2008-10-26 02:13 . 2008-10-26 02:13 <DIR> d-------- C:\Documents and Settings\Lisa Yiu\Application Data\Sonic
2008-10-07 11:39 . 2008-10-07 11:39 0 --a------ C:\.autoreg
2008-10-07 10:57 . 2008-10-07 11:13 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2008-10-07 10:53 . 2008-10-30 08:57 <DIR> d--hs---- C:\WINDOWS\Installer
2008-09-11 12:34 . 2008-05-01 07:30 331,776 --------- C:\WINDOWS\system32\dllcache\msadce.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-27 12:04 --------- d-----w C:\Program Files\Common Files\Adobe
2008-10-27 11:59 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-10-27 11:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-10-27 11:43 --------- d-----w C:\Program Files\Citrix
2008-10-27 11:42 --------- d-----w C:\Program Files\WildTangent
2008-10-27 11:37 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-27 10:48 --------- d-----w C:\Program Files\Java
2008-10-26 11:29 --------- d-----w C:\Program Files\SmartDraw 2008
2008-10-15 16:57 332,800 ----a-w C:\WINDOWS\system32\dllcache\netapi32.dll
2008-10-07 18:45 --------- d-----w C:\Program Files\Google
2008-10-07 18:42 --------- d-----w C:\Program Files\eBay
2008-10-07 18:42 --------- d-----w C:\Documents and Settings\Lisa Yiu\Application Data\eBay
2008-10-07 18:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\eBay
2008-10-07 18:33 --------- d-----w C:\Program Files\Webroot
2008-10-07 18:32 --------- d-----w C:\Documents and Settings\Lisa Yiu\Application Data\Webroot
2008-10-07 18:05 --------- d-----w C:\Program Files\Disney Interactive
2008-10-03 17:41 6,066,176 ----a-w C:\WINDOWS\system32\dllcache\ieframe.dll
2008-09-15 11:57 1,846,016 ----a-w C:\WINDOWS\system32\win32k.sys
2008-09-15 11:57 1,846,016 ----a-w C:\WINDOWS\system32\dllcache\win32k.sys
2008-09-11 19:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\WholeSecurity
2008-09-06 06:30 241,704 ----a-w C:\WINDOWS\system32\dllcache\wgaLogon.dll
2008-09-06 06:29 917,032 ----a-w C:\WINDOWS\system32\dllcache\WgaTray.exe
2008-08-28 10:04 333,056 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-08-28 10:04 333,056 ----a-w C:\WINDOWS\system32\dllcache\srv.sys
2008-08-27 08:24 3,593,216 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-08-25 08:38 13,824 ----a-w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-08-25 08:37 70,656 ----a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-08-23 05:56 635,848 ----a-w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-08-23 05:54 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll
2008-08-14 09:57 2,185,984 ----a-w C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-08-14 09:55 2,142,720 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 09:55 2,142,720 ----a-w C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-08-14 09:51 138,368 ------w C:\WINDOWS\system32\dllcache\afd.sys
2008-08-14 09:18 2,062,976 ----a-w C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-08-14 09:18 2,020,864 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-08-14 09:18 2,020,864 ----a-w C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-07 20:32 253,952 ------w C:\WINDOWS\system32\dllcache\es.dll
2008-06-01 15:53 166 ----a-w C:\Documents and Settings\Lisa Yiu\Application Data\wklnhst.dat
2007-05-08 20:10 56,912 ----a-w C:\Documents and Settings\Lisa Yiu\g2mdlhlpx.exe
2007-04-17 23:30 630,784 ----a-w C:\Documents and Settings\Lisa Yiu\GoToAssist_chat2way__317_en.exe
.
((((((((((((((((((((((((((((( snapshot@2008-10-29_11.40.39.68 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-10-29 02:04:40 65,536 ----a-r C:\WINDOWS\Installer\{15C418EB-7675-42be-B2B3-281952DA014D}\ARPPRODUCTICON.exe
+ 2008-10-29 21:25:55 65,536 ----a-r C:\WINDOWS\Installer\{15C418EB-7675-42be-B2B3-281952DA014D}\ARPPRODUCTICON.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-03-07 131072]
"RecGuard"="C:\Windows\SMINST\RecGuard.exe" [2005-10-11 1187840]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-05-16 213936]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 224248]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 267048]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-04-26 7561216]
"MsmqIntCert"="mqrt.dll" [2007-07-06 C:\WINDOWS\system32\mqrt.dll]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
AutoUpdate Monitor.lnk - C:\Program Files\Sophos\AutoUpdate\ALMon.exe [2007-08-02 245760]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SAVService]
@="service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SophosAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\mqsvc.exe"=
"C:\\Program Files\\SmartFTP Client 2.0\\SmartFTP.exe"=
"C:\\WINDOWS\\system32\\dpnsvr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
R1 SAVOnAccessControl;SAVOnAccessControl;C:\WINDOWS\system32\DRIVERS\savonaccesscontrol.sys [2008-10-29 101120]
R1 SAVOnAccessFilter;SAVOnAccessFilter;C:\WINDOWS\system32\DRIVERS\savonaccessfilter.sys [2008-10-29 33408]
S3 w600bus;Sony Ericsson W600 driver (WDM);C:\WINDOWS\system32\DRIVERS\w600bus.sys [ ]
S3 w600mdfl;Sony Ericsson W600 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w600mdfl.sys [ ]
S3 w600mdm;Sony Ericsson W600 USB WMC Modem Drivers;C:\WINDOWS\system32\DRIVERS\w600mdm.sys [ ]
.
Contents of the 'Scheduled Tasks' folder
2008-09-11 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-mapkbdzwxbbo - C:\WINDOWS\system32\vprfbtmwxabgda.dll
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-10-30 09:09:40
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\msdtc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\WINDOWS\system32\wwSecure.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-10-30 9:13:10 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-30 16:13:07
ComboFix2.txt 2008-10-29 18:41:05
Pre-Run: 37,099,253,760 bytes free
Post-Run: 37,113,417,728 bytes free
692 --- E O F --- 2008-10-27 10:50:00
Here is the Malware log:
Malwarebytes' Anti-Malware 1.30
Database version: 1340
Windows 5.1.2600 Service Pack 2
10/30/2008 10:38:34 AM
mbam-log-2008-10-30 (10-38-34).txt
Scan type: Full Scan (C:\|D:\|)
Objects scanned: 142135
Time elapsed: 50 minute(s), 54 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 7
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 58
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\Interface\{17e44256-51e0-4d46-a0c8-44e80ab4ba5b} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{87255c51-cd7d-4506-b9ad-97606daf53f3} (Adware.Coupons) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{e0f01490-dcf3-4357-95aa-169a8c2b2190} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{80ef304a-b1c4-425c-8535-95ab6f1eefb8} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\BHO_MyJavaCore.DLL (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\bho_myjavacore.mjcore (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\bho_myjavacore.mjcore.1 (Trojan.BHO) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\StartMenuLogOff (Hijack.StartMenu) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Qoobox\Quarantine\C\Documents and Settings\Lisa Yiu\Application Data\Facegame\Facegame.exe.vir (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\Documents and Settings\Lisa Yiu\Application Data\Gool\Gool.exe.vir (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\Documents and Settings\Lisa Yiu\Application Data\ICROSO~1\winlogon.exe.vir (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\Program Files\Webtools\webtools.dll.vir (Trojan.BHO) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\bjsnge.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\bjwjbp.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\ddo.dll.vir (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\ekgoewks.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\hwqlhwcs.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\nkdfimsu.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\vlizww.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\wxilikqs.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\yayyXOHw.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\ysmiicyq.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\asyncmacc.sys.vir (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\EV02\EV022328.exe.vir (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\fs3\CL65CON2.exe.vir (Adware.Webhancer) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\PX\TP6567IV.exe.vir (Adware.ZenoSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{02AB5DEF-1097-4711-A644-97E93C8F5D09}\RP624\A0078047.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{02AB5DEF-1097-4711-A644-97E93C8F5D09}\RP625\A0078172.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{02AB5DEF-1097-4711-A644-97E93C8F5D09}\RP625\A0078175.exe (Trojan.DNSChanger) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{02AB5DEF-1097-4711-A644-97E93C8F5D09}\RP625\A0078176.ocx (Adware.Coupons) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{02AB5DEF-1097-4711-A644-97E93C8F5D09}\RP625\A0078185.exe (Adware.Webhancer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{02AB5DEF-1097-4711-A644-97E93C8F5D09}\RP625\A0078188.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{02AB5DEF-1097-4711-A644-97E93C8F5D09}\RP625\A0078203.dll (Adware.Webhancer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{02AB5DEF-1097-4711-A644-97E93C8F5D09}\RP625\A0078204.dll (Adware.Webhancer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{02AB5DEF-1097-4711-A644-97E93C8F5D09}\RP625\A0078184.exe (Adware.Webhancer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{02AB5DEF-1097-4711-A644-97E93C8F5D09}\RP625\A0078267.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{02AB5DEF-1097-4711-A644-97E93C8F5D09}\RP627\A0080023.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{02AB5DEF-1097-4711-A644-97E93C8F5D09}\RP627\A0080024.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{02AB5DEF-1097-4711-A644-97E93C8F5D09}\RP627\A0080025.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{02AB5DEF-1097-4711-A644-97E93C8F5D09}\RP627\A0080026.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{02AB5DEF-1097-4711-A644-97E93C8F5D09}\RP627\A0080027.dll (Adware.TargetServer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{02AB5DEF-1097-4711-A644-97E93C8F5D09}\RP627\A0080028.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{02AB5DEF-1097-4711-A644-97E93C8F5D09}\RP627\A0080029.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{02AB5DEF-1097-4711-A644-97E93C8F5D09}\RP627\A0080030.dll (Adware.CommAd) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{02AB5DEF-1097-4711-A644-97E93C8F5D09}\RP627\A0080031.exe (Adware.CommAd) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{02AB5DEF-1097-4711-A644-97E93C8F5D09}\RP627\A0080035.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{02AB5DEF-1097-4711-A644-97E93C8F5D09}\RP630\A0080204.exe (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{02AB5DEF-1097-4711-A644-97E93C8F5D09}\RP630\A0080208.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{02AB5DEF-1097-4711-A644-97E93C8F5D09}\RP630\A0080209.exe (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{02AB5DEF-1097-4711-A644-97E93C8F5D09}\RP630\A0080222.dll (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{02AB5DEF-1097-4711-A644-97E93C8F5D09}\RP630\A0080223.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{02AB5DEF-1097-4711-A644-97E93C8F5D09}\RP630\A0080225.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{02AB5DEF-1097-4711-A644-97E93C8F5D09}\RP630\A0080226.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{02AB5DEF-1097-4711-A644-97E93C8F5D09}\RP630\A0080228.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{02AB5DEF-1097-4711-A644-97E93C8F5D09}\RP630\A0080229.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{02AB5DEF-1097-4711-A644-97E93C8F5D09}\RP630\A0080232.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{02AB5DEF-1097-4711-A644-97E93C8F5D09}\RP630\A0080234.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{02AB5DEF-1097-4711-A644-97E93C8F5D09}\RP630\A0080236.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{02AB5DEF-1097-4711-A644-97E93C8F5D09}\RP630\A0080237.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{02AB5DEF-1097-4711-A644-97E93C8F5D09}\RP630\A0080238.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{02AB5DEF-1097-4711-A644-97E93C8F5D09}\RP631\A0081037.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{02AB5DEF-1097-4711-A644-97E93C8F5D09}\RP631\A0081290.dll (Trojan.BHO) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{02AB5DEF-1097-4711-A644-97E93C8F5D09}\RP631\A0081291.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{02AB5DEF-1097-4711-A644-97E93C8F5D09}\RP631\A0081292.exe (Adware.Webhancer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{02AB5DEF-1097-4711-A644-97E93C8F5D09}\RP631\A0081296.exe (Adware.ZenoSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\Lisa Yiu\Desktop\Internet Security Suite.url (Rogue.Link) -> Quarantined and deleted successfully.
Here is the HTJ log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:41:33 AM, on 10/30/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wwSecure.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\Fixmeplease.exe.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - S-1-5-18 Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0612502E-29F8-11D6-BC3C-00C0F0167E34} (CRS Inc. Data Object) -
http://tarmls.crsdata.com/CRSDataObject/CRSNInfo.cab
O16 - DPF: {10E0E75E-6701-4134-9D95-C0942ED1F1C8} (Snapfish Outlook Import ActiveX Control) -
http://photo.walgreens.com/WalgreensOutlookImport.cab
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) -
http://a516.g.akamai.net/f/516/25175/7d/runaware.download.akamai.com/25175/citrix/wficat-no-eula.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) -
http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {4FAE30E1-EE9C-477D-8D06-BF8D3429B60F} (WebIQ Technology Client) -
https://www.webiqonline.com/WebIQ/bin/WebIQ.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) -
http://tarmls.crsdata.com/realestate/maps/downloads/mgaxctrlv65.cab
O16 - DPF: {62BC5DB2-0044-4040-B366-D628F3CFD551} (PowerTeam HTML Printing Behavior) - file:///C:/DOCUME~1/LISAYI~1/LOCALS~1/Temp/IXP000.TMP/setup.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) -
https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {DB1B4C3B-8690-43B2-9045-91EDA7A12580} (eWebEditProLibCtl4.eWEPLoader) -
http://v25.salesaspects.com/ewebeditpro4/ewebeditpro4.cab
O16 - DPF: {F375116A-793C-11D2-BFE1-444553540001} (First American Res MapActiveX Control) -
http://realist2.firstamres.com/mapviewer/mapviewer.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Sophos AutoUpdate Service - Sophos Plc - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: Washer Security Access (wwSecSvc) - Webroot Software, Inc. - C:\WINDOWS\system32\wwSecure.exe
--
End of file - 8205 bytes