ComdoFix Log
--------------------------------------------------------------------------
ComboFix 09-04-16.02 - Owner 04/15/2009 22:00.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1918.1404 [GMT -7:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFii.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
FW: McAfee Personal Firewall Plus *enabled*
* Created a new restore point
* Resident AV is active
FILE ::
c:\windows\ltinhetm.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\binif.scr
c:\documents and settings\All Users\Application Data\melogeze.scr
c:\documents and settings\NetworkService\Local Settings\Application Data\ahmpjqhc
c:\documents and settings\NetworkService\Local Settings\Application Data\ahmpjqhc\Profiles\nbmuuooq.default\urlclassifier3.sqlite
c:\documents and settings\NetworkService\Local Settings\Application Data\ahmpjqhc\Profiles\nbmuuooq.default\XPC.mfl
c:\documents and settings\Owner\Application Data\ahmpjqhc
c:\documents and settings\Owner\Application Data\ahmpjqhc\profiles.ini
c:\documents and settings\Owner\Application Data\ahmpjqhc\Profiles\ithndw1s.default\cert8.db
c:\documents and settings\Owner\Application Data\ahmpjqhc\Profiles\ithndw1s.default\compatibility.ini
c:\documents and settings\Owner\Application Data\ahmpjqhc\Profiles\ithndw1s.default\compreg.dat
c:\documents and settings\Owner\Application Data\ahmpjqhc\Profiles\ithndw1s.default\cookies.sqlite
c:\documents and settings\Owner\Application Data\ahmpjqhc\Profiles\ithndw1s.default\formhistory.sqlite
c:\documents and settings\Owner\Application Data\ahmpjqhc\Profiles\ithndw1s.default\key3.db
c:\documents and settings\Owner\Application Data\ahmpjqhc\Profiles\ithndw1s.default\localstore.rdf
c:\documents and settings\Owner\Application Data\ahmpjqhc\Profiles\ithndw1s.default\permissions.sqlite
c:\documents and settings\Owner\Application Data\ahmpjqhc\Profiles\ithndw1s.default\places.sqlite-journal
c:\documents and settings\Owner\Application Data\ahmpjqhc\Profiles\ithndw1s.default\places.sqlite
c:\documents and settings\Owner\Application Data\ahmpjqhc\Profiles\ithndw1s.default\pluginreg.dat
c:\documents and settings\Owner\Application Data\ahmpjqhc\Profiles\ithndw1s.default\prefs.js
c:\documents and settings\Owner\Application Data\ahmpjqhc\Profiles\ithndw1s.default\secmod.db
c:\documents and settings\Owner\Application Data\ahmpjqhc\Profiles\ithndw1s.default\webappsstore.sqlite
c:\documents and settings\Owner\Application Data\ahmpjqhc\Profiles\ithndw1s.default\xpti.dat
c:\documents and settings\Owner\Application Data\nabywu.sys
c:\documents and settings\Owner\Application Data\owowovu.dll
c:\documents and settings\Owner\Local Settings\Application Data\ahmpjqhc
c:\documents and settings\Owner\Local Settings\Application Data\ahmpjqhc\Profiles\ithndw1s.default\urlclassifier3.sqlite
c:\documents and settings\Owner\Local Settings\Application Data\ahmpjqhc\Profiles\ithndw1s.default\XPC.mfl
c:\documents and settings\Owner\Local Settings\Application Data\fahixom.exe
c:\documents and settings\Owner\Local Settings\Application Data\rafixi.dll
c:\program files\Common Files\dupiricyla.lib
c:\program files\Common Files\ifenu.dat
c:\program files\Common Files\ozijaguhyl.db
c:\program files\Common Files\qobejiwupu.lib
c:\program files\Common Files\ykenaki.com
c:\program files\Common\_helper.dll
c:\windows\Afagoxoy.dat
c:\windows\ajuteriwedokez.dll
c:\windows\Bturarohijep.bin
c:\windows\system32\drivers\cmgbfisi.sys
c:\windows\system32\itxmcvh.dll
c:\windows\system32\nvterah.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CMGBFISI
-------\Service_cmgbfisi
((((((((((((((((((((((((( Files Created from 2009-03-16 to 2009-04-16 )))))))))))))))))))))))))))))))
.
2009-04-15 04:35 . 2009-03-06 14:22 284160 -c----w c:\windows\system32\dllcache\pdh.dll
2009-04-15 04:35 . 2009-02-09 12:10 401408 -c----w c:\windows\system32\dllcache\rpcss.dll
2009-04-15 04:35 . 2009-02-06 10:39 35328 -c----w c:\windows\system32\dllcache\sc.exe
2009-04-15 04:35 . 2009-02-06 11:11 110592 -c----w c:\windows\system32\dllcache\services.exe
2009-04-15 04:35 . 2009-02-09 12:10 473600 -c----w c:\windows\system32\dllcache\fastprox.dll
2009-04-15 04:35 . 2009-02-06 10:10 227840 -c----w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-15 04:35 . 2009-02-09 12:10 453120 -c----w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-15 04:35 . 2009-02-09 12:10 729088 -c----w c:\windows\system32\dllcache\lsasrv.dll
2009-04-15 04:35 . 2009-02-09 12:10 617472 -c----w c:\windows\system32\dllcache\advapi32.dll
2009-04-15 04:35 . 2009-02-09 12:10 714752 -c----w c:\windows\system32\dllcache\ntdll.dll
2009-04-15 04:31 . 2008-05-03 11:55 2560 ------w c:\windows\system32\xpsp4res.dll
2009-04-15 04:31 . 2009-03-27 06:58 1203922 -c----w c:\windows\system32\dllcache\sysmain.sdb
2009-04-15 04:31 . 2008-04-21 12:08 215552 -c----w c:\windows\system32\dllcache\wordpad.exe
2009-04-15 02:38 . 2009-04-15 02:39 -------- d-----w C:\Combofxx
2009-04-14 00:35 . 2009-04-14 00:35 -------- d-----w c:\documents and settings\NetworkService\Application Data\ahmpjqhc
2009-04-08 18:46 . 2009-04-08 18:46 -------- d-----w c:\documents and settings\Owner\Local Settings\Application Data\{090E6ADA-3A8C-4515-9575-B7CF01714EF3}
2009-04-04 17:18 . 2009-04-04 17:18 -------- d-----w c:\documents and settings\Owner\Local Settings\Application Data\Intuit
2009-03-21 14:06 . 2009-03-21 14:06 989696 -c----w c:\windows\system32\dllcache\kernel32.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-16 05:00 . 2008-07-31 04:06 -------- d-----w c:\program files\Common
2009-04-16 05:00 . 2005-01-09 23:48 23424 ----a-w c:\windows\system32\drivers\dvdqhzxp.sys
2009-04-15 15:57 . 2008-10-26 18:28 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-04-15 15:23 . 2006-04-25 03:37 -------- d-----w c:\program files\World of Warcraft
2009-04-10 03:57 . 2009-04-10 03:57 -------- d-----w c:\program files\ERUNT
2009-04-10 03:32 . 2008-10-26 18:28 -------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-04-04 17:18 . 2005-01-10 01:26 55400 ----a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-04 17:14 . 2008-03-16 18:22 -------- d-----w c:\program files\Common Files\AnswerWorks 5.0
2009-04-04 17:12 . 2006-04-25 03:32 -------- d-----w c:\documents and settings\All Users\Application Data\Intuit
2009-04-04 17:12 . 2006-04-25 03:32 -------- d-----w c:\program files\Common Files\Intuit
2009-04-04 17:10 . 2007-04-01 17:07 -------- d-----w c:\program files\TurboTax
2009-03-16 06:40 . 2006-08-15 03:30 14968 ----a-w c:\documents and settings\Owner\Application Data\wklnhst.dat
2009-03-06 14:22 . 2005-01-09 23:48 284160 ----a-w c:\windows\system32\pdh.dll
2009-03-04 04:29 . 2006-05-11 13:45 -------- d-----w c:\documents and settings\Owner\Application Data\Canon
2009-03-03 00:18 . 2005-01-09 23:48 826368 ----a-w c:\windows\system32\wininet.dll
2009-02-20 18:09 . 2005-01-09 23:48 78336 ----a-w c:\windows\system32\ieencode.dll
2009-02-09 12:10 . 2005-01-09 23:48 729088 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2005-01-09 23:48 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 12:10 . 2005-01-09 23:48 714752 ----a-w c:\windows\system32\ntdll.dll
2009-02-09 12:10 . 2005-01-09 23:47 617472 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 11:13 . 2005-01-09 23:48 1846784 ----a-w c:\windows\system32\win32k.sys
2009-02-06 11:11 . 2005-01-09 23:48 110592 ----a-w c:\windows\system32\services.exe
2009-02-06 11:06 . 2005-01-09 23:48 2145280 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 10:39 . 2005-01-09 23:48 35328 ----a-w c:\windows\system32\sc.exe
2009-02-06 10:32 . 2004-08-04 05:59 2023936 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-03 19:59 . 2005-01-09 23:48 56832 ----a-w c:\windows\system32\secur32.dll
2008-12-25 16:58 . 2008-12-25 16:58 20 ---h--w c:\documents and settings\All Users\Application Data\PKP_DLdu.DAT
2008-10-09 18:38 . 2008-10-09 18:38 44544 ----a-w c:\documents and settings\All Users\mjvC.exe
2006-04-24 05:22 . 2006-04-24 05:22 128 ----a-w c:\documents and settings\Owner\Local Settings\Application Data\fusioncache.dat
2005-01-10 01:26 . 2008-12-31 13:19 13104 ----a-w c:\documents and settings\Guest\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2005-01-10 01:26 . 2006-04-23 21:05 13104 ----a-w c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\documents and settings\Owner\Local Settings\Application Data\{090E6ADA-3A8C-4515-9575-B7CF01714EF3} ----
2009-04-08 18:46 . 2009-04-08 18:46 9229 ----a-w c:\documents and settings\Owner\Local Settings\Application Data\{090E6ADA-3A8C-4515-9575-B7CF01714EF3}\chrome\content\overlay.xul
2009-04-08 18:46 . 2009-04-08 18:46 3323 ----a-w c:\documents and settings\Owner\Local Settings\Application Data\{090E6ADA-3A8C-4515-9575-B7CF01714EF3}\chrome\content\c.js
2009-04-08 18:46 . 2009-04-08 18:46 2127 ----a-w c:\documents and settings\Owner\Local Settings\Application Data\{090E6ADA-3A8C-4515-9575-B7CF01714EF3}\chrome\content\_cfg.js
2009-04-08 18:46 . 2009-04-08 18:46 770 ----a-w c:\documents and settings\Owner\Local Settings\Application Data\{090E6ADA-3A8C-4515-9575-B7CF01714EF3}\install.rdf
2009-04-08 18:46 . 2009-04-08 18:46 120 ----a-w c:\documents and settings\Owner\Local Settings\Application Data\{090E6ADA-3A8C-4515-9575-B7CF01714EF3}\chrome.manifest
((((((((((((((((((((((((((((( SnapShot@2009-04-15_03.03.32 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-01-29 08:58 . 2008-10-23 10:06 62976 c:\windows\system32\tzchange.exe
+ 2005-01-10 01:27 . 2008-07-09 07:38 26488 c:\windows\system32\spupdsvc.exe
- 2005-01-10 01:27 . 2007-08-11 03:46 26488 c:\windows\system32\spupdsvc.exe
+ 2008-02-16 14:32 . 2007-11-30 12:39 17272 c:\windows\system32\spmsg.dll
- 2008-02-16 14:32 . 2008-07-08 13:02 17272 c:\windows\system32\spmsg.dll
+ 2005-01-09 23:48 . 2009-02-03 19:59 56832 c:\windows\system32\secur32.dll
+ 2005-01-09 23:48 . 2009-02-06 10:39 35328 c:\windows\system32\sc.exe
- 2005-01-09 23:48 . 2008-08-26 07:24 44544 c:\windows\system32\pngfilt.dll
+ 2005-01-09 23:48 . 2009-02-20 18:09 44544 c:\windows\system32\pngfilt.dll
+ 2005-01-09 23:48 . 2009-04-15 10:17 64372 c:\windows\system32\perfc009.dat
- 2005-01-09 23:48 . 2009-03-25 12:41 64372 c:\windows\system32\perfc009.dat
- 2005-01-10 01:05 . 2008-04-14 00:12 91648 c:\windows\system32\mtxoci.dll
+ 2005-01-10 01:05 . 2008-06-12 14:23 91648 c:\windows\system32\mtxoci.dll
+ 2005-01-09 23:48 . 2008-06-12 14:23 66560 c:\windows\system32\mtxclu.dll
- 2005-01-09 23:48 . 2008-04-14 00:12 66560 c:\windows\system32\mtxclu.dll
- 2006-11-08 05:03 . 2008-08-26 07:24 52224 c:\windows\system32\msfeedsbs.dll
+ 2006-11-08 05:03 . 2009-02-20 18:09 52224 c:\windows\system32\msfeedsbs.dll
- 2005-01-10 01:05 . 2008-04-14 00:11 58880 c:\windows\system32\msdtclog.dll
+ 2005-01-10 01:05 . 2008-06-12 14:23 58880 c:\windows\system32\msdtclog.dll
- 2005-01-09 23:48 . 2008-08-26 07:24 27648 c:\windows\system32\jsproxy.dll
+ 2005-01-09 23:48 . 2009-02-20 18:09 27648 c:\windows\system32\jsproxy.dll
- 2006-11-07 11:26 . 2008-08-25 08:38 13824 c:\windows\system32\ieudinit.exe
+ 2006-11-07 11:26 . 2009-02-20 10:20 13824 c:\windows\system32\ieudinit.exe
- 2005-01-09 23:48 . 2008-08-26 07:24 44544 c:\windows\system32\iernonce.dll
+ 2005-01-09 23:48 . 2009-02-20 18:09 44544 c:\windows\system32\iernonce.dll
+ 2005-01-09 23:48 . 2009-02-20 18:09 78336 c:\windows\system32\ieencode.dll
+ 2005-01-09 23:48 . 2009-02-20 10:20 70656 c:\windows\system32\ie4uinit.exe
- 2005-01-09 23:48 . 2008-08-25 08:37 70656 c:\windows\system32\ie4uinit.exe
+ 2006-10-17 19:58 . 2009-02-20 18:09 63488 c:\windows\system32\icardie.dll
- 2006-10-17 19:58 . 2008-08-26 07:24 63488 c:\windows\system32\icardie.dll
- 2005-01-09 23:48 . 2004-08-10 19:00 23424 c:\windows\system32\drivers\dvdqhzxp.sys
+ 2005-01-09 23:48 . 2009-04-16 05:00 23424 c:\windows\system32\drivers\dvdqhzxp.sys
+ 2009-02-03 19:59 . 2009-02-03 19:59 56832 c:\windows\system32\dllcache\secur32.dll
+ 2009-04-15 04:35 . 2009-02-06 10:39 35328 c:\windows\system32\dllcache\sc.exe
- 2006-05-10 05:25 . 2008-08-26 07:24 44544 c:\windows\system32\dllcache\pngfilt.dll
+ 2006-05-10 05:25 . 2009-02-20 18:09 44544 c:\windows\system32\dllcache\pngfilt.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 91648 c:\windows\system32\dllcache\mtxoci.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 66560 c:\windows\system32\dllcache\mtxclu.dll
- 2007-05-09 04:57 . 2008-08-26 07:24 52224 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2007-05-09 04:57 . 2009-02-20 18:09 52224 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 58880 c:\windows\system32\dllcache\msdtclog.dll
- 2006-05-10 05:25 . 2008-08-26 07:24 27648 c:\windows\system32\dllcache\jsproxy.dll
+ 2006-05-10 05:25 . 2009-02-20 18:09 27648 c:\windows\system32\dllcache\jsproxy.dll
+ 2007-05-09 04:57 . 2009-02-20 10:20 13824 c:\windows\system32\dllcache\ieudinit.exe
- 2007-05-09 04:57 . 2008-08-25 08:38 13824 c:\windows\system32\dllcache\ieudinit.exe
+ 2006-11-07 11:26 . 2009-02-20 18:09 44544 c:\windows\system32\dllcache\iernonce.dll
- 2006-11-07 11:26 . 2008-08-26 07:24 44544 c:\windows\system32\dllcache\iernonce.dll
+ 2009-02-20 18:09 . 2009-02-20 18:09 78336 c:\windows\system32\dllcache\ieencode.dll
+ 2006-11-07 11:26 . 2009-02-20 10:20 70656 c:\windows\system32\dllcache\ie4uinit.exe
- 2006-11-07 11:26 . 2008-08-25 08:37 70656 c:\windows\system32\dllcache\ie4uinit.exe
- 2007-08-20 10:04 . 2008-08-26 07:24 63488 c:\windows\system32\dllcache\icardie.dll
+ 2007-08-20 10:04 . 2009-02-20 18:09 63488 c:\windows\system32\dllcache\icardie.dll
+ 2009-04-15 10:05 . 2008-08-26 07:24 44544 c:\windows\ie7updates\KB963027-IE7\pngfilt.dll
+ 2009-04-15 10:05 . 2008-08-26 07:24 52224 c:\windows\ie7updates\KB963027-IE7\msfeedsbs.dll
+ 2009-04-15 10:05 . 2008-08-26 07:24 27648 c:\windows\ie7updates\KB963027-IE7\jsproxy.dll
+ 2009-04-15 10:05 . 2008-08-25 08:38 13824 c:\windows\ie7updates\KB963027-IE7\ieudinit.exe
+ 2009-04-15 10:05 . 2008-08-26 07:24 44544 c:\windows\ie7updates\KB963027-IE7\iernonce.dll
+ 2009-04-15 10:05 . 2008-04-14 00:11 81920 c:\windows\ie7updates\KB963027-IE7\ieencode.dll
+ 2009-04-15 10:05 . 2008-08-25 08:37 70656 c:\windows\ie7updates\KB963027-IE7\ie4uinit.exe
+ 2009-04-15 10:05 . 2008-08-26 07:24 63488 c:\windows\ie7updates\KB963027-IE7\icardie.dll
+ 2009-04-15 04:31 . 2008-05-03 11:55 2560 c:\windows\system32\xpsp4res.dll
+ 2005-01-09 23:49 . 2008-06-18 12:03 938496 c:\windows\system32\WMNetmgr.dll
- 2005-01-09 23:48 . 2008-08-26 07:24 826368 c:\windows\system32\wininet.dll
+ 2005-01-09 23:48 . 2009-03-03 00:18 826368 c:\windows\system32\wininet.dll
- 2005-01-09 23:48 . 2008-04-14 00:12 354304 c:\windows\system32\winhttp.dll
+ 2005-01-09 23:48 . 2008-12-16 12:30 354304 c:\windows\system32\winhttp.dll
- 2005-01-09 23:48 . 2008-08-26 07:24 233472 c:\windows\system32\webcheck.dll
+ 2005-01-09 23:48 . 2009-02-20 18:09 233472 c:\windows\system32\webcheck.dll
+ 2005-01-10 01:05 . 2009-02-06 10:10 227840 c:\windows\system32\wbem\wmiprvse.exe
+ 2005-01-10 01:05 . 2009-02-09 12:10 453120 c:\windows\system32\wbem\wmiprvsd.dll
+ 2005-01-10 01:05 . 2009-02-09 12:10 473600 c:\windows\system32\wbem\fastprox.dll
+ 2005-01-09 23:48 . 2009-02-20 18:09 105984 c:\windows\system32\url.dll
- 2005-01-09 23:48 . 2008-08-26 07:24 105984 c:\windows\system32\url.dll
+ 2005-01-09 23:49 . 2008-10-03 10:02 247326 c:\windows\system32\strmdll.dll
+ 2005-01-09 23:48 . 2009-02-06 11:11 110592 c:\windows\system32\services.exe
+ 2005-01-09 23:48 . 2008-12-05 06:54 144896 c:\windows\system32\schannel.dll
+ 2005-01-09 23:48 . 2009-02-09 12:10 401408 c:\windows\system32\rpcss.dll
+ 2005-01-09 23:48 . 2009-04-15 10:17 409232 c:\windows\system32\perfh009.dat
- 2005-01-09 23:48 . 2009-03-25 12:41 409232 c:\windows\system32\perfh009.dat
+ 2005-01-09 23:48 . 2009-03-06 14:22 284160 c:\windows\system32\pdh.dll
- 2005-01-09 23:48 . 2008-04-14 00:12 284160 c:\windows\system32\pdh.dll
+ 2005-01-09 23:48 . 2009-02-20 18:09 102912 c:\windows\system32\occache.dll
- 2005-01-09 23:48 . 2008-08-26 07:24 102912 c:\windows\system32\occache.dll
+ 2005-01-09 23:48 . 2009-02-09 12:10 714752 c:\windows\system32\ntdll.dll
- 2005-01-09 23:48 . 2008-08-26 07:24 671232 c:\windows\system32\mstime.dll
+ 2005-01-09 23:48 . 2009-02-20 18:09 671232 c:\windows\system32\mstime.dll
+ 2005-01-09 23:48 . 2009-02-20 18:09 193024 c:\windows\system32\msrating.dll
- 2005-01-09 23:48 . 2008-08-26 07:24 193024 c:\windows\system32\msrating.dll
+ 2005-01-09 23:48 . 2009-02-20 18:09 477696 c:\windows\system32\mshtmled.dll
- 2005-01-09 23:48 . 2008-08-26 07:24 477696 c:\windows\system32\mshtmled.dll
- 2006-11-08 05:03 . 2008-08-26 07:24 459264 c:\windows\system32\msfeeds.dll
+ 2006-11-08 05:03 . 2009-02-20 18:09 459264 c:\windows\system32\msfeeds.dll
- 2005-01-10 01:05 . 2008-04-14 00:11 161792 c:\windows\system32\msdtcuiu.dll
+ 2005-01-10 01:05 . 2008-06-12 14:23 161792 c:\windows\system32\msdtcuiu.dll
- 2005-01-10 01:05 . 2008-04-14 00:11 956928 c:\windows\system32\msdtctm.dll
+ 2005-01-10 01:05 . 2008-06-12 14:23 956928 c:\windows\system32\msdtctm.dll
+ 2005-01-10 01:05 . 2008-06-12 14:23 428032 c:\windows\system32\msdtcprx.dll
+ 2005-01-09 23:48 . 2009-02-09 12:10 729088 c:\windows\system32\lsasrv.dll
- 2005-01-09 23:49 . 2006-10-19 04:03 100864 c:\windows\system32\logagent.exe
+ 2005-01-09 23:49 . 2008-06-18 08:09 100864 c:\windows\system32\logagent.exe
- 2005-01-09 23:48 . 2008-04-14 00:11 989696 c:\windows\system32\kernel32.dll
+ 2005-01-09 23:48 . 2009-03-21 14:06 989696 c:\windows\system32\kernel32.dll
+ 2006-10-17 19:57 . 2009-02-20 18:09 268288 c:\windows\system32\iertutil.dll
+ 2005-01-09 23:48 . 2009-02-20 18:09 385024 c:\windows\system32\iedkcs32.dll
- 2006-10-17 19:27 . 2008-08-26 07:24 383488 c:\windows\system32\ieapfltr.dll
+ 2006-10-17 19:27 . 2009-02-20 18:09 383488 c:\windows\system32\ieapfltr.dll
+ 2005-01-09 23:48 . 2009-02-20 05:14 161792 c:\windows\system32\ieakui.dll
- 2005-01-09 23:48 . 2008-08-23 05:54 161792 c:\windows\system32\ieakui.dll
- 2005-01-09 23:48 . 2008-08-26 07:24 230400 c:\windows\system32\ieaksie.dll
+ 2005-01-09 23:48 . 2009-02-20 18:09 230400 c:\windows\system32\ieaksie.dll
+ 2005-01-09 23:48 . 2009-02-20 18:09 153088 c:\windows\system32\ieakeng.dll
- 2005-01-09 23:48 . 2008-08-26 07:24 153088 c:\windows\system32\ieakeng.dll
+ 2005-01-09 23:48 . 2008-10-23 12:36 286720 c:\windows\system32\gdi32.dll
+ 2005-01-09 16:59 . 2009-04-15 10:13 227208 c:\windows\system32\FNTCACHE.DAT
- 2005-01-09 16:59 . 2009-04-04 17:28 227208 c:\windows\system32\FNTCACHE.DAT
+ 2005-01-09 23:48 . 2009-02-20 18:09 133120 c:\windows\system32\extmgr.dll
- 2005-01-09 23:48 . 2008-08-26 07:24 133120 c:\windows\system32\extmgr.dll
- 2005-01-09 23:48 . 2008-08-26 07:24 214528 c:\windows\system32\dxtrans.dll
+ 2005-01-09 23:48 . 2009-02-20 18:09 214528 c:\windows\system32\dxtrans.dll
- 2005-01-09 23:48 . 2008-08-26 07:24 347136 c:\windows\system32\dxtmsft.dll
+ 2005-01-09 23:48 . 2009-02-20 18:09 347136 c:\windows\system32\dxtmsft.dll
+ 2005-01-09 23:48 . 2008-12-11 10:57 333952 c:\windows\system32\drivers\srv.sys
+ 2009-04-15 04:31 . 2008-04-21 12:08 215552 c:\windows\system32\dllcache\wordpad.exe
+ 2008-06-18 12:03 . 2008-06-18 12:03 938496 c:\windows\system32\dllcache\WMNetmgr.dll
+ 2009-04-15 04:35 . 2009-02-06 10:10 227840 c:\windows\system32\dllcache\wmiprvse.exe
+ 2009-04-15 04:35 . 2009-02-09 12:10 453120 c:\windows\system32\dllcache\wmiprvsd.dll
+ 2006-05-10 05:25 . 2009-03-03 00:18 826368 c:\windows\system32\dllcache\wininet.dll
- 2006-05-10 05:25 . 2008-08-26 07:24 826368 c:\windows\system32\dllcache\wininet.dll
+ 2008-12-16 12:30 . 2008-12-16 12:30 354304 c:\windows\system32\dllcache\winhttp.dll
- 2006-11-08 05:03 . 2008-08-26 07:24 233472 c:\windows\system32\dllcache\webcheck.dll
+ 2006-11-08 05:03 . 2009-02-20 18:09 233472 c:\windows\system32\dllcache\webcheck.dll
+ 2006-10-17 20:05 . 2009-02-20 18:09 105984 c:\windows\system32\dllcache\url.dll
- 2006-10-17 20:05 . 2008-08-26 07:24 105984 c:\windows\system32\dllcache\url.dll
+ 2006-08-21 17:52 . 2008-10-03 10:02 247326 c:\windows\system32\dllcache\strmdll.dll
+ 2008-10-15 10:49 . 2008-12-11 10:57 333952 c:\windows\system32\dllcache\srv.sys
+ 2009-04-15 04:35 . 2009-02-06 11:11 110592 c:\windows\system32\dllcache\services.exe
+ 2008-12-05 06:54 . 2008-12-05 06:54 144896 c:\windows\system32\dllcache\schannel.dll
+ 2009-04-15 04:35 . 2009-02-09 12:10 401408 c:\windows\system32\dllcache\rpcss.dll
+ 2009-04-15 04:35 . 2009-03-06 14:22 284160 c:\windows\system32\dllcache\pdh.dll
- 2006-10-17 20:04 . 2008-08-26 07:24 102912 c:\windows\system32\dllcache\occache.dll
+ 2006-10-17 20:04 . 2009-02-20 18:09 102912 c:\windows\system32\dllcache\occache.dll
+ 2009-04-15 04:35 . 2009-02-09 12:10 714752 c:\windows\system32\dllcache\ntdll.dll
+ 2006-05-10 05:25 . 2009-02-20 18:09 671232 c:\windows\system32\dllcache\mstime.dll
- 2006-05-10 05:25 . 2008-08-26 07:24 671232 c:\windows\system32\dllcache\mstime.dll
- 2006-05-10 05:25 . 2008-08-26 07:24 193024 c:\windows\system32\dllcache\msrating.dll
+ 2006-05-10 05:25 . 2009-02-20 18:09 193024 c:\windows\system32\dllcache\msrating.dll
- 2006-05-10 05:25 . 2008-08-26 07:24 477696 c:\windows\system32\dllcache\mshtmled.dll
+ 2006-05-10 05:25 . 2009-02-20 18:09 477696 c:\windows\system32\dllcache\mshtmled.dll
+ 2007-05-09 04:57 . 2009-02-20 18:09 459264 c:\windows\system32\dllcache\msfeeds.dll
- 2007-05-09 04:57 . 2008-08-26 07:24 459264 c:\windows\system32\dllcache\msfeeds.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 161792 c:\windows\system32\dllcache\msdtcuiu.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 956928 c:\windows\system32\dllcache\msdtctm.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 428032 c:\windows\system32\dllcache\msdtcprx.dll
+ 2009-04-15 04:35 . 2009-02-09 12:10 729088 c:\windows\system32\dllcache\lsasrv.dll
+ 2008-06-18 08:09 . 2008-06-18 08:09 100864 c:\windows\system32\dllcache\logagent.exe
+ 2009-03-21 14:06 . 2009-03-21 14:06 989696 c:\windows\system32\dllcache\kernel32.dll
+ 2006-10-17 20:04 . 2009-02-28 04:54 636072 c:\windows\system32\dllcache\iexplore.exe
+ 2007-05-09 04:57 . 2009-02-20 18:09 268288 c:\windows\system32\dllcache\iertutil.dll
+ 2006-11-07 11:27 . 2009-02-20 18:09 385024 c:\windows\system32\dllcache\iedkcs32.dll
- 2007-05-09 04:57 . 2008-08-26 07:24 383488 c:\windows\system32\dllcache\ieapfltr.dll
+ 2007-05-09 04:57 . 2009-02-20 18:09 383488 c:\windows\system32\dllcache\ieapfltr.dll
- 2006-11-07 11:25 . 2008-08-23 05:54 161792 c:\windows\system32\dllcache\ieakui.dll
+ 2006-11-07 11:25 . 2009-02-20 05:14 161792 c:\windows\system32\dllcache\ieakui.dll
+ 2006-11-07 11:27 . 2009-02-20 18:09 230400 c:\windows\system32\dllcache\ieaksie.dll
- 2006-11-07 11:27 . 2008-08-26 07:24 230400 c:\windows\system32\dllcache\ieaksie.dll
+ 2006-11-07 11:26 . 2009-02-20 18:09 153088 c:\windows\system32\dllcache\ieakeng.dll
- 2006-11-07 11:26 . 2008-08-26 07:24 153088 c:\windows\system32\dllcache\ieakeng.dll
+ 2008-10-23 12:36 . 2008-10-23 12:36 286720 c:\windows\system32\dllcache\gdi32.dll
+ 2009-04-15 04:35 . 2009-02-09 12:10 473600 c:\windows\system32\dllcache\fastprox.dll
+ 2006-05-10 05:25 . 2009-02-20 18:09 133120 c:\windows\system32\dllcache\extmgr.dll
- 2006-05-10 05:25 . 2008-08-26 07:24 133120 c:\windows\system32\dllcache\extmgr.dll
- 2006-05-10 05:25 . 2008-08-26 07:24 214528 c:\windows\system32\dllcache\dxtrans.dll
+ 2006-05-10 05:25 . 2009-02-20 18:09 214528 c:\windows\system32\dllcache\dxtrans.dll
+ 2006-05-10 05:25 . 2009-02-20 18:09 347136 c:\windows\system32\dllcache\dxtmsft.dll
- 2006-05-10 05:25 . 2008-08-26 07:24 347136 c:\windows\system32\dllcache\dxtmsft.dll
+ 2006-11-07 11:26 . 2009-02-20 18:09 124928 c:\windows\system32\dllcache\advpack.dll
- 2006-11-07 11:26 . 2008-08-26 07:24 124928 c:\windows\system32\dllcache\advpack.dll
+ 2009-04-15 04:35 . 2009-02-09 12:10 617472 c:\windows\system32\dllcache\advapi32.dll
+ 2005-01-09 23:47 . 2009-02-20 18:09 124928 c:\windows\system32\advpack.dll
- 2005-01-09 23:47 . 2008-08-26 07:24 124928 c:\windows\system32\advpack.dll
+ 2005-01-09 23:47 . 2009-02-09 12:10 617472 c:\windows\system32\advapi32.dll
- 2005-01-09 23:47 . 2008-04-14 00:11 617472 c:\windows\system32\advapi32.dll
+ 2009-04-15 10:05 . 2008-08-26 07:24 826368 c:\windows\ie7updates\KB963027-IE7\wininet.dll
+ 2009-04-15 10:05 . 2008-08-26 07:24 233472 c:\windows\ie7updates\KB963027-IE7\webcheck.dll
+ 2009-04-15 10:05 . 2008-08-26 07:24 105984 c:\windows\ie7updates\KB963027-IE7\url.dll
+ 2009-04-15 10:05 . 2008-07-09 07:38 382840 c:\windows\ie7updates\KB963027-IE7\spuninst\updspapi.dll
+ 2009-04-15 10:05 . 2008-07-08 13:02 231288 c:\windows\ie7updates\KB963027-IE7\spuninst\spuninst.exe
+ 2009-04-15 10:05 . 2008-08-26 07:24 102912 c:\windows\ie7updates\KB963027-IE7\occache.dll
+ 2009-04-15 10:05 . 2008-08-26 07:24 671232 c:\windows\ie7updates\KB963027-IE7\mstime.dll
+ 2009-04-15 10:05 . 2008-08-26 07:24 193024 c:\windows\ie7updates\KB963027-IE7\msrating.dll
+ 2009-04-15 10:05 . 2008-08-26 07:24 477696 c:\windows\ie7updates\KB963027-IE7\mshtmled.dll
+ 2009-04-15 10:05 . 2008-08-26 07:24 459264 c:\windows\ie7updates\KB963027-IE7\msfeeds.dll
+ 2009-04-15 10:05 . 2008-08-23 05:56 635848 c:\windows\ie7updates\KB963027-IE7\iexplore.exe
+ 2009-04-15 10:05 . 2008-08-26 07:24 267776 c:\windows\ie7updates\KB963027-IE7\iertutil.dll
+ 2009-04-15 10:05 . 2008-08-26 07:24 384512 c:\windows\ie7updates\KB963027-IE7\iedkcs32.dll
+ 2009-04-15 10:05 . 2008-08-26 07:24 383488 c:\windows\ie7updates\KB963027-IE7\ieapfltr.dll
+ 2009-04-15 10:05 . 2008-08-23 05:54 161792 c:\windows\ie7updates\KB963027-IE7\ieakui.dll
+ 2009-04-15 10:05 . 2008-08-26 07:24 230400 c:\windows\ie7updates\KB963027-IE7\ieaksie.dll
+ 2009-04-15 10:05 . 2008-08-26 07:24 153088 c:\windows\ie7updates\KB963027-IE7\ieakeng.dll
+ 2009-04-15 10:05 . 2008-08-26 07:24 133120 c:\windows\ie7updates\KB963027-IE7\extmgr.dll
+ 2009-04-15 10:05 . 2008-08-26 07:24 214528 c:\windows\ie7updates\KB963027-IE7\dxtrans.dll
+ 2009-04-15 10:05 . 2008-08-26 07:24 347136 c:\windows\ie7updates\KB963027-IE7\dxtmsft.dll
+ 2009-04-15 10:05 . 2008-08-26 07:24 124928 c:\windows\ie7updates\KB963027-IE7\advpack.dll
- 2009-04-15 03:00 . 2005-10-21 03:02 163328 c:\windows\ERDNT\subs\ERDNT.EXE
+ 2009-04-16 05:02 . 2005-10-21 03:02 163328 c:\windows\ERDNT\subs\ERDNT.EXE
+ 2009-04-15 04:34 . 2008-04-15 17:47 1724416 c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5581_x-ww_dfbc4fc4\GdiPlus.dll
+ 2005-01-09 23:49 . 2008-06-18 12:03 2458112 c:\windows\system32\WMVCore.dll
+ 2005-01-09 23:48 . 2009-02-09 11:13 1846784 c:\windows\system32\win32k.sys
+ 2005-01-09 23:48 . 2009-02-20 18:09 1160192 c:\windows\system32\urlmon.dll
- 2005-01-09 23:48 . 2008-04-14 00:12 8461312 c:\windows\system32\shell32.dll
+ 2005-01-09 23:48 . 2008-06-17 19:02 8461312 c:\windows\system32\shell32.dll
- 2005-01-09 23:48 . 2008-05-07 05:12 1288192 c:\windows\system32\quartz.dll
+ 2005-01-09 23:48 . 2008-12-20 22:14 1288192 c:\windows\system32\quartz.dll
+ 2005-01-09 23:48 . 2009-02-06 11:06 2145280 c:\windows\system32\ntoskrnl.exe
- 2005-01-09 23:48 . 2008-08-14 10:09 2145280 c:\windows\system32\ntoskrnl.exe
- 2004-08-04 05:59 . 2008-08-14 09:33 2023936 c:\windows\system32\ntkrnlpa.exe
+ 2004-08-04 05:59 . 2009-02-06 10:32 2023936 c:\windows\system32\ntkrnlpa.exe
+ 2005-01-09 23:48 . 2009-02-20 18:09 3595264 c:\windows\system32\mshtml.dll
+ 2006-11-08 05:03 . 2009-02-20 18:09 6066176 c:\windows\system32\ieframe.dll
- 2006-11-08 05:03 . 2008-10-03 17:41 6066176 c:\windows\system32\ieframe.dll
- 2006-09-06 07:01 . 2007-04-17 09:28 2455488 c:\windows\system32\ieapfltr.dat
+ 2006-09-06 07:01 . 2008-07-09 14:25 2455488 c:\windows\system32\ieapfltr.dat
+ 2005-01-09 23:49 . 2008-06-18 12:03 2458112 c:\windows\system32\dllcache\WMVCore.dll
+ 2008-10-15 10:48 . 2009-02-09 11:13 1846784 c:\windows\system32\dllcache\win32k.sys
+ 2006-05-10 05:25 . 2009-02-20 18:09 1160192 c:\windows\system32\dllcache\urlmon.dll
+ 2008-06-17 19:02 . 2008-06-17 19:02 8461312 c:\windows\system32\dllcache\shell32.dll
+ 2008-05-07 05:12 . 2008-12-20 22:14 1288192 c:\windows\system32\dllcache\quartz.dll
- 2008-05-07 05:12 . 2008-05-07 05:12 1288192 c:\windows\system32\dllcache\quartz.dll
+ 2008-10-15 10:48 . 2009-02-06 11:08 2189056 c:\windows\system32\dllcache\ntoskrnl.exe
- 2008-10-15 10:48 . 2008-08-14 09:33 2023936 c:\windows\system32\dllcache\ntkrpamp.exe
+ 2008-10-15 10:48 . 2009-02-06 10:32 2023936 c:\windows\system32\dllcache\ntkrpamp.exe
+ 2008-10-15 10:48 . 2009-02-08 02:02 2066048 c:\windows\system32\dllcache\ntkrnlpa.exe
- 2008-10-15 10:48 . 2008-08-14 09:33 2066048 c:\windows\system32\dllcache\ntkrnlpa.exe
- 2008-10-15 10:48 . 2008-08-14 10:09 2145280 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2008-10-15 10:48 . 2009-02-06 11:06 2145280 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2006-05-19 15:06 . 2009-02-20 18:09 3595264 c:\windows\system32\dllcache\mshtml.dll
- 2007-05-09 04:57 . 2008-10-03 17:41 6066176 c:\windows\system32\dllcache\ieframe.dll
+ 2007-05-09 04:57 . 2009-02-20 18:09 6066176 c:\windows\system32\dllcache\ieframe.dll
+ 2007-05-09 04:57 . 2008-07-09 14:25 2455488 c:\windows\system32\dllcache\ieapfltr.dat
- 2007-05-09 04:57 . 2007-04-17 09:28 2455488 c:\windows\system32\dllcache\ieapfltr.dat
+ 2009-04-15 10:05 . 2008-08-26 07:24 1159680 c:\windows\ie7updates\KB963027-IE7\urlmon.dll
+ 2009-04-15 10:05 . 2008-08-27 08:24 3593216 c:\windows\ie7updates\KB963027-IE7\mshtml.dll
+ 2009-04-15 10:05 . 2008-10-03 17:41 6066176 c:\windows\ie7updates\KB963027-IE7\ieframe.dll
+ 2009-04-15 10:05 . 2007-04-17 09:28 2455488 c:\windows\ie7updates\KB963027-IE7\ieapfltr.dat
+ 2008-10-15 10:48 . 2009-02-06 11:08 2189056 c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2008-10-15 10:48 . 2009-02-06 10:32 2023936 c:\windows\Driver Cache\i386\ntkrpamp.exe
- 2008-10-15 10:48 . 2008-08-14 09:33 2023936 c:\windows\Driver Cache\i386\ntkrpamp.exe
- 2008-10-15 10:48 . 2008-08-14 09:33 2066048 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2008-10-15 10:48 . 2009-02-08 02:02 2066048 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2008-10-15 10:48 . 2009-02-06 11:06 2145280 c:\windows\Driver Cache\i386\ntkrnlmp.exe
- 2008-10-15 10:48 . 2008-08-14 10:09 2145280 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2005-01-09 23:49 . 2008-11-12 01:34 10838016 c:\windows\system32\wmp.dll
+ 2006-12-15 03:40 . 2009-04-06 14:57 24921544 c:\windows\system32\MRT.exe
+ 2005-01-09 23:49 . 2008-11-12 01:34 10838016 c:\windows\system32\dllcache\wmp.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-03-25 50528]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-09-18 7204864]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-09-18 86016]
"AOL Spyware Protection"="c:\progra~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" [2004-10-19 79448]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2005-02-26 966656]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-04-17 196608]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-04-13 69632]
"ehTray"="c:\windows\ehome\ehtray.exe" [N/A]
"readericon"="c:\program files\Digital Media Reader\readericon45G.exe" [N/A]
"VSOCheckTask"="c:\progra~1\McAfee.com\VSO\mcmnhdlr.exe" [N/A]
"OASClnt"="c:\program files\McAfee.com\VSO\oasclnt.exe" [N/A]
"MCAgentExe"="c:\progra~1\mcafee.com\agent\mcagent.exe" [N/A]
"MCUpdateExe"="c:\progra~1\McAfee.com\Agent\bak\McUpdate.exe" [2006-01-11 212992]
"MSKAGENTEXE"="c:\progra~1\McAfee\SPAMKI~1\MskAgent.exe" [N/A]
"MSKDetectorExe"="c:\progra~1\McAfee\SPAMKI~1\MSKDetct.exe" [N/A]
"VirusScan Online"="c:\program files\McAfee.com\VSO\mcvsshld.exe" [N/A]
"MPFExe"="c:\progra~1\McAfee.com\PERSON~1\MpfTray.exe" [N/A]
"YBrowser"="c:\progra~1\Yahoo!\browser\ybrwicon.exe" [N/A]
"YOP"="c:\progra~1\Yahoo!\YOP\yop.exe" [N/A]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [N/A]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-03-29 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-03-30 267048]
"HostManager"="c:\program files\Common Files\AOL\1139343492\EE\AOLHostManager.exe" [N/A]
"OpwareSE2"="c:\program files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [N/A]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2005-09-26 90112]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2005-09-18 1519616]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="NA" [X]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
BigFix.lnk - c:\program files\BigFix\bigfix.exe [2006-2-7 2168360]
forteManager.lnk - c:\program files\LG Soft India\forteManager\bin\Monitor.exe [2008-4-5 1064960]
Nikon Monitor.lnk - c:\program files\Common Files\Nikon\Monitor\NkMonitor.exe [2007-10-18 479232]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.clmp3enc"= c:\progra~1\CYBERL~1\Power2Go\CLMP3Enc.ACM
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"c:\\Program Files\\Common Files\\AOL\\1139343492\\EE\\AOLServiceHost.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\AOLSP Scheduler.exe"=
"c:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\asp.exe"=
"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\yserver.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader
"6112:TCP"= 6112:TCP:Blizzard Downloader
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\K]
\Shell\AutoRun\command - K:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7855b9a1-9814-11da-9eba-806d6172696f}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{79c84d47-1deb-11de-8dae-0015581f649b}]
\Shell\AutoRun\command - K:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9128207b-7b98-11dc-8cce-0015581f649b}]
\Shell\AutoRun\command - K:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b3053969-9822-11da-b84e-806d6172696f}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
.
Contents of the 'Scheduled Tasks' folder
2009-04-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 00:57]
2009-04-16 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-07-16 01:15]
.
- - - - ORPHANS REMOVED - - - -
BHO-{AFD4AD01-58C1-47DB-A404-FBE00A6C5486} - (no file)
BHO-{B666A8F9-8800-4EF9-88EF-237EFEBED37A} - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/
mStart Page = hxxp://www.google.com
mSearchMigratedDefaultURL = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*
http://www.yahoo.com
IE: &AIM Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\Owner\Start Menu\Programs\IMVU\Run IMVU.lnk
Trusted Zone: turbotax.com
DPF: ChatSpace Full Java Client 4.0.0.320 - hxxp://69.65.108.158/Java/cfs40320.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-04-15 22:06
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1152)
c:\program files\iTunes\iTunesMiniPlayer.dll
c:\program files\iTunes\iTunesMiniPlayer.Resources\en.lproj\iTunesMiniPlayerLocalized.dll
c:\program files\iTunes\iTunesMiniPlayer.Resources\iTunesMiniPlayer.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Common Files\aolshare\aolshcpy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Common Files\AOL\ACS\AOLacsd.exe
c:\program files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
c:\program files\McAfee.com\Agent\Mcdetect.exe
c:\progra~1\McAfee.com\VSO\McShield.exe
c:\progra~1\McAfee.com\Agent\McTskshd.exe
c:\progra~1\McAfee.com\PERSON~1\MpfService.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\program files\Viewpoint\Common\ViewpointService.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\AIM6\aolsoftware.exe
.
**************************************************************************
.
Completion time: 2009-04-16 22:10 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-16 05:10
ComboFix2.txt 2009-04-15 03:07
Pre-Run: 176,587,575,296 bytes free
Post-Run: 176,608,067,584 bytes free
536 --- E O F --- 2009-04-15 10:06
----------------------------------------------------
Mbam Log
----------------------------------------------------
Malwarebytes' Anti-Malware 1.36
Database version: 1987
Windows 5.1.2600 Service Pack 3
4/15/2009 11:22:12 PM
mbam-log-2009-04-15 (23-22-12).txt
Scan type: Full Scan (C:\|D:\|)
Objects scanned: 184042
Time elapsed: 45 minute(s), 45 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 13
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\main.bho.1 (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{749a5337-6df7-4138-983a-75c5e0012114} (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Documents and Settings\Owner\My Documents\EA Games\ZwinkySetup2.2.60.11-2.exe (Adware.MyWeb) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\Program Files\GrandPack\qdrloader.exe.vir (Trojan.BHO) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\sysguard.exe.vir (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACjbnssjmf.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACmafywbwi.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACpjeneqrp.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACvppwxlkr.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\wpv241229907565.cpx.vir (Adware.Agent) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\UACyodqgdcn.sys.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP1\A0000024.exe (Trojan.BHO) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP1\A0000025.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\rn.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mst122.dll (Trojan.Agent) -> Quarantined and deleted successfully.
--------------------------------------------
HJT Log
--------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:28:30 PM, on 4/15/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\BigFix\bigfix.exe
C:\Program Files\LG Soft India\forteManager\bin\Monitor.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\bak\McUpdate.exe
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1139343492\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [Power2GoExpress] NA (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Power2GoExpress] NA (User 'Default user')
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe
O4 - Global Startup: forteManager.lnk = ?
O4 - Global Startup: Nikon Monitor.lnk = C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
O8 - Extra context menu item: &AIM Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll
O9 - Extra 'Tools' menuitem: &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll
O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Owner\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: ChatSpace Full Java Client 4.0.0.320 -
http://69.65.108.158/Java/cfs40320.cab
O16 - DPF: Yahoo! Backgammon -
http://download2.games.yahoo.com/games/clients/y/at1_x.cab
O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) -
http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) -
http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {6F750202-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) -
http://targetphoto.kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Google Update Service (gupdate1c8cccf4fec6c50) (gupdate1c8cccf4fec6c50) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE
O24 - Desktop Component 0: (no name) -
http://www.nationalgeographic.com/ngm/0101/images/feature2_6.jpg
--
End of file - 10767 bytes