logs
ComboFix 08-04-09.8 - yfulmer 2008-04-10 0:43:25.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.555 [GMT -5:00]
Running from: C:\Documents and Settings\yfulmer\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BMcfaf4406.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\aGQprBeg.ini
C:\WINDOWS\system32\aGQprBeg.ini2
C:\WINDOWS\system32\ayglpoek.ini
C:\WINDOWS\system32\keoplgya.dll
C:\WINDOWS\system32\PAdMnnmp.ini
C:\WINDOWS\system32\PAdMnnmp.ini2
C:\WINDOWS\system32\ssqOFWnL.dll
C:\WINDOWS\system32\taopjcfr.dll
C:\WINDOWS\system32\tuvSMFxU.dll
C:\WINDOWS\system32\UxFMSvut.ini
C:\WINDOWS\system32\UxFMSvut.ini2
C:\WINDOWS\system32\VuuENXbc.ini
C:\WINDOWS\system32\VuuENXbc.ini2
C:\WINDOWS\system32\WvDegMoq.ini
C:\WINDOWS\system32\WvDegMoq.ini2
C:\winlogon.exe
.
((((((((((((((((((((((((( Files Created from 2008-03-10 to 2008-04-10 )))))))))))))))))))))))))))))))
.
2008-04-09 16:41 . 2008-04-09 16:41 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-09 16:28 . 2008-04-09 16:28 3,648 --a------ C:\WINDOWS\system32\ceiqyxhq.dll
2008-04-09 14:51 . 2008-04-09 14:51 3,648 --a------ C:\WINDOWS\system32\wkrdyfcn.dll
2008-04-08 19:48 . 2008-04-09 16:12 442 --a------ C:\WINDOWS\wininit.ini
2008-04-08 18:17 . 2008-04-08 18:18 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-08 18:17 . 2008-04-08 18:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-08 14:07 . 2008-04-08 14:07 7,680 --ahs---- C:\WINDOWS\Thumbs.db
2008-04-08 13:57 . 2008-04-08 13:58 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2008-04-08 12:51 . 2008-04-08 12:56 <DIR> d--hs---- C:\Documents and Settings\yfulmer\!
2008-04-08 12:51 . 2008-04-08 18:44 60,301 --------- C:\Documents and Settings\yfulmer\zz.dat
2008-04-08 00:12 . 2008-04-08 20:22 <DIR> d-------- C:\Program Files\LimeWire
2008-04-08 00:12 . 2008-04-08 20:16 <DIR> d-------- C:\Documents and Settings\yfulmer\Application Data\LimeWire
2008-04-08 00:04 . 2008-04-08 00:07 <DIR> d-------- C:\Program Files\BitTorrent
2008-04-08 00:04 . 2008-04-08 00:04 <DIR> d-------- C:\Documents and Settings\yfulmer\Application Data\BitTorrent
2008-04-07 16:47 . 2008-04-07 16:47 0 --a------ C:\WINDOWS\nsreg.dat
2008-04-07 14:49 . 2008-04-07 14:49 <DIR> d-------- C:\Program Files\Zappit
2008-04-06 20:33 . 2008-04-06 20:33 <DIR> d-------- C:\Program Files\WOT
2008-04-04 19:26 . 2008-04-04 19:26 <DIR> d-------- C:\Program Files\Disney
2008-04-04 18:45 . 2008-04-04 18:45 <DIR> d-------- C:\WINDOWS\system32\Lang
2008-04-04 18:45 . 2008-04-04 18:45 940,794 --a------ C:\WINDOWS\system32\LoopyMusic.wav
2008-04-04 18:45 . 2008-04-04 18:45 146,650 --a------ C:\WINDOWS\system32\BuzzingBee.wav
2008-04-04 18:40 . 2008-04-04 18:40 <DIR> d-------- C:\Documents and Settings\yfulmer\Application Data\StarOffice8
2008-04-04 14:17 . 2008-04-04 14:17 <DIR> d-------- C:\Documents and Settings\yfulmer\Application Data\Intel
2008-04-01 14:21 . 2008-04-01 14:21 <DIR> d-------- C:\Documents and Settings\jclement\Application Data\ICAClient
2008-04-01 14:17 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-04-01 14:17 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-04-01 14:07 . 2008-04-01 14:07 <DIR> d-------- C:\Program Files\SeaCOM
2008-04-01 14:07 . 2001-02-27 17:24 456,192 --a------ C:\WINDOWS\system32\ftdiun2k.exe
2008-04-01 14:07 . 2002-05-02 14:58 136,075 --a------ C:\WINDOWS\system32\drivers\SeaCOM2k.sys
2008-04-01 14:07 . 2002-03-07 11:17 49,105 --a------ C:\WINDOWS\system32\drivers\Ftser2k.sys
2008-04-01 14:07 . 2001-12-03 16:56 32,768 --a------ C:\WINDOWS\system32\SeaCOM2kCoInstaller.dll
2008-04-01 14:07 . 2002-03-07 11:17 18,102 --a------ C:\WINDOWS\system32\drivers\Ftdibus.sys
2008-04-01 14:07 . 2001-09-19 08:16 92 --a------ C:\WINDOWS\system32\ftdiun2k.ini
2008-04-01 13:59 . 2008-04-01 13:59 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2008-04-01 13:54 . 2008-04-01 13:54 <DIR> d-------- C:\Program Files\MSXML 6.0
2008-04-01 13:54 . 2008-04-01 13:54 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-04-01 13:54 . 2004-08-04 07:00 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-04-01 13:53 . 2008-04-01 13:53 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-04-01 12:14 . 2008-04-01 12:14 0 --a------ C:\WINDOWS\vpc32.INI
2008-04-01 12:04 . 2008-04-01 12:04 <DIR> d-------- C:\Program Files\Launch Manager
2008-04-01 12:04 . 2008-04-01 12:04 83 --a------ C:\WINDOWS\QtZgAcer.UNI
2008-04-01 12:02 . 2006-02-22 11:19 69,632 --a------ C:\WINDOWS\system32\eRecUtil.dll
2008-04-01 12:02 . 2006-04-18 19:54 49,152 --a------ C:\WINDOWS\system32\SysMonitor.exe
2008-04-01 11:55 . 2008-04-01 11:55 <DIR> d-------- C:\Program Files\Windows Defender
2008-04-01 11:49 . 2008-04-01 12:06 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-04-01 11:47 . 2008-04-01 11:47 <DIR> d-------- C:\Program Files\Sun
2008-04-01 11:47 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-04-01 11:46 . 2008-04-05 17:48 <DIR> d-------- C:\Program Files\Java
2008-04-01 11:46 . 2008-04-01 11:46 <DIR> d-------- C:\Program Files\Common Files\Java
2008-04-01 11:32 . 2008-04-01 11:32 <DIR> d-------- C:\Program Files\Google
2008-04-01 11:32 . 2008-04-09 22:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Google Updater
2008-04-01 10:55 . 2008-04-01 10:55 <DIR> d-------- C:\Program Files\Synaptics
2008-04-01 10:55 . 2006-04-29 05:54 193,056 --a------ C:\WINDOWS\system32\drivers\SynTP.sys
2008-04-01 10:55 . 2006-04-29 06:00 114,688 --a------ C:\WINDOWS\system32\SynCtrl.dll
2008-04-01 10:55 . 2006-04-29 06:00 94,297 --a------ C:\WINDOWS\system32\SynTPAPI.dll
2008-04-01 10:55 . 2006-04-29 05:59 82,012 --a------ C:\WINDOWS\system32\SynCOM.dll
2008-04-01 10:55 . 2006-04-29 06:17 81,920 --a------ C:\WINDOWS\system32\SynTPCo2.dll
2008-04-01 10:55 . 2006-04-29 06:14 69,721 --a------ C:\WINDOWS\system32\SynTPFcs.dll
2008-04-01 10:32 . 2008-04-01 10:32 <DIR> d-------- C:\Documents and Settings\jclement\Application Data\Intel
2008-04-01 10:31 . 2008-04-01 10:31 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\Intel
2008-04-01 10:31 . 2008-04-01 10:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Intel
2008-04-01 10:31 . 2008-04-01 10:31 21,275 --a------ C:\WINDOWS\system32\drivers\AegisP.sys
2008-04-01 10:28 . 2008-04-01 10:31 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-03-31 16:37 . 2008-03-31 16:37 <DIR> d-------- C:\Program Files\Atheros
2008-03-31 16:37 . 2006-01-25 10:44 488,448 --a------ C:\WINDOWS\system32\drivers\ar5211.sys
2008-03-31 16:37 . 2005-06-21 13:32 28,544 --a------ C:\WINDOWS\system32\drivers\callistx.sys
2008-03-31 16:18 . 2008-04-01 10:31 <DIR> d-------- C:\Program Files\Intel
2008-03-31 16:05 . 2008-03-31 16:05 <DIR> d-------- C:\Program Files\Realtek
2008-03-31 15:59 . 2008-03-31 15:59 <DIR> d-------- C:\WINDOWS\Options
2008-03-31 15:59 . 2006-03-16 17:24 68,096 --a------ C:\WINDOWS\system32\agrsmdel.exe
2008-03-31 15:55 . 2006-06-13 09:57 139,264 --a------ C:\WINDOWS\system32\igfxres.dll
2008-03-31 15:44 . 2008-04-01 14:07 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-03-31 15:43 . 2008-03-31 15:43 <DIR> d-------- C:\WINDOWS\tiinst
2008-03-31 15:43 . 2008-03-31 16:36 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2008-03-31 14:45 . 2008-03-31 14:45 <DIR> d-------- C:\Program Files\MSBuild
2008-03-31 14:42 . 2008-04-01 13:58 <DIR> d-------- C:\WINDOWS\system32\XPSViewer
2008-03-31 14:42 . 2008-03-31 14:42 <DIR> d-------- C:\Program Files\Reference Assemblies
2008-03-31 14:41 . 2006-06-29 13:07 14,048 --a------ C:\WINDOWS\system32\spmsg2.dll
2008-03-31 14:38 . 2008-03-31 14:38 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-03-31 14:38 . 2008-03-31 14:38 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-03-31 14:38 . 2008-03-31 14:38 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-03-31 14:29 . 2008-03-31 14:29 <DIR> d-------- C:\Program Files\HP Wireless Keyboard
2008-03-31 14:28 . 2008-03-31 14:28 <DIR> d-------- C:\WINDOWS\system32\URTTemp
2008-03-31 14:12 . 2006-11-13 01:02 288,768 --a------ C:\WINDOWS\system32\rhttpaa.dll
2008-03-31 14:12 . 2006-11-13 01:02 116,736 --a------ C:\WINDOWS\system32\aaclient.dll
2008-03-31 14:12 . 2006-11-13 01:02 36,352 --a------ C:\WINDOWS\system32\tsgqec.dll
2008-03-31 13:45 . 2008-04-08 12:52 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-03-31 13:45 . 2007-10-05 15:42 23,856 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-03-31 13:42 . 2007-07-30 20:19 43,352 --a------ C:\WINDOWS\system32\wups2.dll
2008-03-31 13:42 . 2007-07-30 20:18 34,136 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2008-03-31 13:42 . 2007-07-30 20:19 25,944 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-03-31 13:42 . 2007-07-30 20:19 25,944 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-03-31 13:42 . 2007-07-30 20:18 20,312 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2008-03-31 13:38 . 2008-03-31 13:38 <DIR> d--hs---- C:\Documents and Settings\jclement\UserData
2008-03-31 13:10 . 2006-04-07 01:55 25,165 -ra------ C:\WINDOWS\system32\drivers\MN110-50.SYS
2008-03-12 13:10 . 2008-03-12 13:10 633,344 --a------ C:\WINDOWS\system32\gpprefcl.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-10 05:46 --------- d-----w C:\Program Files\Symantec AntiVirus
2008-04-01 17:15 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-04-01 16:49 --------- d-----w C:\Program Files\Common Files\Adobe
2008-03-31 17:54 --------- d-----w C:\Program Files\Symantec
2008-03-31 17:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-03-31 17:53 --------- d-----w C:\Program Files\Executive Software
2008-03-31 17:53 --------- d-----w C:\Program Files\Citrix
2008-03-31 17:47 --------- d-----w C:\Program Files\microsoft frontpage
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{40B3DF45-3A57-4615-86A0-12D94AA886B2}]
C:\WINDOWS\system32\cbXNEuuV.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{80E872E7-FA9A-4092-9AE8-F3560DF4EE73}]
C:\WINDOWS\system32\pmnnMdAP.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C920E44A-7F78-4E64-BDD7-A57026E7FEB7}]
2008-02-13 12:53 1096864 --a------ C:\Program Files\WOT\WOT.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DFBC7F95-E7E0-4DAC-8498-7510B838709E}]
C:\WINDOWS\system32\geBrpQGa.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{71576546-354D-41C9-AAE8-31F2EC22BF0D}"= "C:\Program Files\WOT\WOT.dll" [2008-02-13 12:53 1096864]
[HKEY_CLASSES_ROOT\clsid\{71576546-354d-41c9-aae8-31f2ec22bf0d}]
[HKEY_CLASSES_ROOT\WOT.WOTBar.1]
[HKEY_CLASSES_ROOT\WOT.WOTBar]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{71576546-354D-41C9-AAE8-31F2EC22BF0D}"= C:\Program Files\WOT\WOT.dll [2008-02-13 12:53 1096864]
[HKEY_CLASSES_ROOT\clsid\{71576546-354d-41c9-aae8-31f2ec22bf0d}]
[HKEY_CLASSES_ROOT\WOT.WOTBar.1]
[HKEY_CLASSES_ROOT\WOT.WOTBar]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00 15360]
"BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-06-02 10:21 48752]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2005-06-23 20:27 85696]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-06-13 09:57 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-06-13 09:57 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-06-13 09:57 118784]
"AzMixerSel"="C:\Program Files\Realtek\InstallShield\AzMixerSel.exe" [2006-07-19 09:41 53248]
"INPROCOMMWireless"="C:\Program Files\Atheros\Wireless\Utility\WlanUtil.exe" [ ]
"SkyTel"="SkyTel.EXE" [2006-07-19 09:42 2879488 C:\WINDOWS\SkyTel.exe]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-04-14 11:51 667718]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-04-14 11:52 602182]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-04-29 06:13 766041]
"AGRSMMSG"="AGRSMMSG.exe" [2005-12-13 21:50 88204 C:\WINDOWS\AGRSMMSG.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20 866584]
"LManager"="C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE" [2006-07-14 12:13 471040]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2008-04-01 11:32:30 124400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqOFWnL]
ssqOFWnL.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
--a------ 2006-07-19 09:42 16248320 C:\WINDOWS\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
R3 EraserUtilDrv10741;EraserUtilDrv10741;C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10741.sys [2008-03-18 14:13]
S1 seacom2k;Sealevel Systems Win2K Serial Driver;C:\WINDOWS\system32\DRIVERS\seacom2k.sys [2002-05-02 14:58]
S3 MN110-50;Microsoft(R) USB Adapter MN-110;C:\WINDOWS\system32\DRIVERS\MN110-50.SYS [2006-04-07 01:55]
.
Contents of the 'Scheduled Tasks' folder
"2008-04-10 05:51:07 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-04-10 00:48:31
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\igfxext.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
.
**************************************************************************
.
Completion time: 2008-04-10 0:51:55 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-10 05:51:49
Pre-Run: 64,552,615,936 bytes free
Post-Run: 65,062,641,664 bytes free
.
2008-04-06 15:06:12 --- E O F ---
hijack log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:54:27 AM, on 4/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\WINDOWS\system32\igfxext.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://go.microsoft.com/fwlink/?LinkId=74005
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {40B3DF45-3A57-4615-86A0-12D94AA886B2} - C:\WINDOWS\system32\cbXNEuuV.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {80E872E7-FA9A-4092-9AE8-F3560DF4EE73} - C:\WINDOWS\system32\pmnnMdAP.dll (file missing)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll
O2 - BHO: (no name) - {DFBC7F95-E7E0-4DAC-8498-7510B838709E} - C:\WINDOWS\system32\geBrpQGa.dll (file missing)
O3 - Toolbar: WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [INPROCOMMWireless] C:\Program Files\Atheros\Wireless\Utility\WlanUtil.exe
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) -
http://disney.go.com/pirates/online/testActiveX/built/signed/DisneyOnlineGames.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1206988801881
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1207075277375
O18 - Protocol: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll
O20 - Winlogon Notify: ssqOFWnL - ssqOFWnL.dll (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
--
End of file - 8559 bytes