ComboFix Log
ComboFix 09-03-19.02 - dijones 2009-03-21 10:51:51.3 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.576.334 [GMT -4:00]
Running from: c:\documents and settings\dijones\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\dijones\Desktop\CFScript.txt
* Created a new restore point
FILE ::
c:\windows\Downloaded Program Files\SbCIe01f.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Downloaded Program Files\SbCIe01f.dll
.
((((((((((((((((((((((((( Files Created from 2009-02-21 to 2009-03-21 )))))))))))))))))))))))))))))))
.
2009-03-20 12:46 . 2009-03-20 12:46 <DIR> d-------- c:\program files\EsetOnlineScanner
2009-03-18 19:08 . 2009-03-18 19:08 525,928 --a------ c:\temp\ZCP9EA07.exe
2009-03-17 20:10 . 2009-03-17 20:10 <DIR> d-------- C:\dell
2009-03-16 14:57 . 2009-03-16 14:57 <DIR> d-------- c:\program files\Common Files\ScanSoft Shared
2009-03-15 02:40 . 2009-03-15 02:40 <DIR> d-------- c:\documents and settings\LocalService.NT AUTHORITY\Application Data\AdobeUM
2009-03-14 20:15 . 2009-03-14 20:15 <DIR> d-------- c:\windows\SYSTEM32\CatRoot_bak
2009-03-13 23:00 . 2009-03-13 23:00 <DIR> d--h----- C:\$AVG8.VAULT$
2009-03-13 22:50 . 2009-03-13 22:50 <DIR> d-------- c:\documents and settings\All Users\Application Data\avg8
2009-03-13 11:31 . 2008-06-13 09:10 272,128 --------- c:\windows\SYSTEM32\DRIVERS\bthport.sys
2009-03-13 11:31 . 2008-06-13 09:10 272,128 --------- c:\windows\SYSTEM32\dllcache\bthport.sys
2009-03-13 11:27 . 2008-05-01 10:30 331,776 --------- c:\windows\SYSTEM32\dllcache\msadce.dll
2009-03-13 05:31 . 2009-03-13 05:31 <DIR> d-------- c:\documents and settings\dijones\Application Data\Malwarebytes
2009-03-13 05:31 . 2009-02-11 10:19 15,504 --a------ c:\windows\SYSTEM32\DRIVERS\mbam.sys
2009-03-13 05:30 . 2009-03-13 05:30 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-13 05:30 . 2009-02-11 10:19 38,496 --a------ c:\windows\SYSTEM32\DRIVERS\mbamswissarmy.sys
2009-03-13 01:15 . 2009-03-13 01:15 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-03-13 00:50 . 2009-03-13 00:49 410,984 --a------ c:\windows\SYSTEM32\deploytk.dll
2009-03-13 00:50 . 2009-03-13 00:49 73,728 --a------ c:\windows\SYSTEM32\javacpl.cpl
2009-03-09 00:12 . 2009-03-09 00:12 <DIR> d---s---- c:\documents and settings\LocalService.NT AUTHORITY\UserData
2009-03-08 15:16 . 2009-03-08 15:16 <DIR> d-------- c:\program files\Remote
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-11 16:29 4,224 ----a-w c:\windows\system32\drivers\beep.sys
2009-02-09 10:19 1,846,272 ----a-w c:\windows\SYSTEM32\win32k.sys
2009-02-09 10:19 1,846,272 ------w c:\windows\SYSTEM32\dllcache\win32k.sys
2007-07-01 17:51 121,392 ----a-w c:\documents and settings\dijones\Application Data\GDIPFONTCACHEV1.DAT
2005-04-27 18:47 266 --sh--w c:\program files\desktop.ini
2005-04-27 18:47 11,079 ---h--w c:\program files\folder.htt
1997-04-21 01:51 33,539 ----a-w c:\program files\readme.txt
1997-01-16 16:45 186 ----a-w c:\program files\File_id.diz
1997-01-16 16:45 10,460 ----a-w c:\program files\VENDINFO.DIZ
1996-12-31 01:11 26,624 ----a-w c:\program files\Gold.doc
.
((((((((((((((((((((((((((((( SnapShot@2009-03-16_16.08.00.14 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-03-16 19:50:48 16,384 ----a-w c:\windows\Application Data\Earthlink\6.0\dijones@infionline.net\Cookies\index.dat
+ 2009-03-20 22:41:14 32,768 ----a-w c:\windows\Application Data\Earthlink\6.0\dijones@infionline.net\Cookies\index.dat
- 2009-03-01 05:43:28 32,768 ----a-w c:\windows\Application Data\Earthlink\6.0\dijones@infionline.net\UserData\index.dat
+ 2009-03-18 22:19:16 32,768 ----a-w c:\windows\Application Data\Earthlink\6.0\dijones@infionline.net\UserData\index.dat
- 2009-03-16 03:34:12 16,384 ----a-w c:\windows\SYSTEM32\config\systemprofile\Cookies\index.dat
+ 2009-03-17 20:27:48 16,384 ----a-w c:\windows\SYSTEM32\config\systemprofile\Cookies\index.dat
- 2009-03-16 03:34:12 32,768 ----a-w c:\windows\SYSTEM32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-03-17 20:27:48 32,768 ----a-w c:\windows\SYSTEM32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-03-16 03:34:12 32,768 ----a-w c:\windows\SYSTEM32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-03-17 20:27:48 32,768 ----a-w c:\windows\SYSTEM32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2009-03-13 04:50:42 1,636 ----a-w c:\windows\SYSTEM32\d3d9caps.dat
+ 2009-03-21 05:35:36 1,636 ----a-w c:\windows\SYSTEM32\d3d9caps.dat
+ 2007-07-27 18:49:02 196,683 ----a-w c:\windows\SYSTEM32\lnod32apiA.dll
+ 2007-07-27 18:49:02 225,355 ----a-w c:\windows\SYSTEM32\lnod32apiW.dll
+ 2005-12-05 23:25:22 139,264 ----a-w c:\windows\SYSTEM32\lnod32umc.dll
+ 2005-12-05 16:37:10 106,496 ----a-w c:\windows\SYSTEM32\lnod32upd.dll
+ 2008-02-11 13:39:26 253,952 ----a-w c:\windows\SYSTEM32\OnlineScannerDLLA.dll
+ 2008-02-11 13:39:18 237,568 ----a-w c:\windows\SYSTEM32\OnlineScannerDLLW.dll
+ 2008-02-08 17:53:46 110,592 ----a-w c:\windows\SYSTEM32\OnlineScannerLang.dll
+ 2008-02-05 12:48:04 77,824 ----a-w c:\windows\SYSTEM32\OnlineScannerUninstaller.exe
+ 2004-12-07 14:11:34 258,352 ----a-w c:\windows\SYSTEM32\unicows.dll
+ 2009-03-20 21:32:56 16,384 ----a-w c:\windows\TEMP\Perflib_Perfdata_52c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SlowFile Icon Overlay]
@="{7D688A77-C613-11D0-999B-00C04FD655E1}"
[HKEY_CLASSES_ROOT\CLSID\{7D688A77-C613-11D0-999B-00C04FD655E1}]
2008-07-03 09:16 8454656 --a------ c:\windows\SYSTEM32\SHELL32.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\windows\SYSTEM32\qttask.exe" [2004-10-03 98304]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"EditLevel"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"EditLevel"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.yvu9"= ATIYVU9.DLL
"MSACM.MSNAUDIO"= msnaudio.acm
"VIDC.VDOM"= vdowave.drv
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PrintKey-Pro.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\PrintKey-Pro.lnk
backup=c:\windows\pss\PrintKey-Pro.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EReminderdiamond]
--a------ 1998-08-17 13:03 167424 c:\program files\Encompass\Diamond\EReminder.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
--a------ 2006-01-13 20:36 196608 c:\windows\SYSTEM32\spool\drivers\w32x86\3\hpztsb04.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelliPoint]
--a------ 2004-06-03 01:50 204800 c:\program files\Microsoft IntelliPoint\point32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
--a------ 2001-07-09 06:50 155648 c:\windows\SYSTEM32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2004-10-03 00:18 98304 c:\windows\SYSTEM32\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoboForm]
--a------ 2008-11-01 13:56 160592 d:\program files\Siber Systems\Ai RoboForm\robotaskbaricon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2009-03-05 16:07 2260480 d:\steve's help speed this computer folder\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2009-03-13 00:49 148888 d:\java\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"avg8wd"=2 (0x2)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpySweeper"=
"Attune Download"=c:\progra~1\AVEO\ATTUNE\UPDATER1\ATTUNEL.EXE
"E6TaskPanel"=d:\program files\EARTHLINK TOTALACCESS\TASKPANL.EXE -winstart
"HXIUL.EXE"=c:\program files\Micro Warehouse\HelpExpress\dijones\HXIUL.EXE -uninstall
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"WinampAgent"="c:\program files\Winamp3\winampa.exe"
"QuickTime Task"="c:\windows\SYSTEM32\qttask.exe" -atboottime
"InCD"=c:\program files\Ahead\InCD\InCD.exe
"POINTER"=point32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"Disknag"=c:\dell\DISKNAG.EXE
"AtiCwd32"=Aticwd32.exe
"StillImageMonitor"=c:\windows\SYSTEM32\STIMON.EXE
"Ati2cwxx"=Ati2cwxx.exe
"AccessRampMonitor"="c:\program files\EarthLink\FastLane\ARMon32.exe"
"HPDJ Taskbar Utility"=c:\windows\SYSTEM32\hpztsb04.exe
"mdac_runonce"=c:\windows\SYSTEM32\RUNONCE.EXE
"AtiPTA"=Atiptaxx.exe
"QuickTime Task"="c:\windows\SYSTEM32\qttask.exe" -atboottime
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
"POINTER"=point32.exe
"ICSDCLT"=c:\windows\SYSTEM32\RUNDLL32.EXE c:\windows\SYSTEM32\ICSDCLT.DLL,ICSClient
"ScreenPrint32"=c:\program files\SCREENPRINT32 V3\SCREENPRINT32.exe -startup
"COMSMDEXE"=comsmd.exe -off
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"d:\\Java\\bin\\java.exe"=
R3 cwbmidi_device;Crystal WDM MPU-401 UART Driver;c:\windows\SYSTEM32\DRIVERS\cwbmidi.sys [2006-07-12 3072]
R3 cwbwdm_device;Crystal WDM Audio Codec Driver;c:\windows\SYSTEM32\DRIVERS\cwbwdm.sys [2006-07-12 72832]
S3 NtApm;NT Apm/Legacy Interface Driver;c:\windows\SYSTEM32\DRIVERS\NtApm.sys [2006-07-12 9344]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
"c:\program files\Outlook Express\setup50.exe" /APP:OE /CALLER:IE50 /user /install
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
"c:\program files\Outlook Express\setup50.exe" /APP:OE /CALLER:IE50 /user /install
"c:\program files\Outlook Express\setup50.exe" /APP:OE /CALLER:IE50 /user /install
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
"c:\program files\Outlook Express\setup50.exe" /APP:WAB /CALLER:IE50 /user /install
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
"c:\program files\Outlook Express\setup50.exe" /APP:WAB /CALLER:IE50 /user /install
"c:\program files\Outlook Express\setup50.exe" /APP:WAB /CALLER:IE50 /user /install
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}]
c:\windows\SYSTEM32\updcrl.exe -e -u c:\windows\SYSTEM\verisignpub1.crl
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://middlegeorgia.cox.net/cci/home
mLocal Page = c:\windows\SYSTEM\blank.htm
mSearch Bar = hxxp://home.netscape.com/home/winsearch200.html
uInternet Settings,ProxyOverride = 127.0.0.1
uSearchURL,(Default) = hxxp://keyword.netscape.com/keyword/%s
IE: Add to filterlist (WebWasher) - http://-Web.Washer-/ie_add
IE: Customize Menu - file://d:\program files\Siber Systems\Ai RoboForm\RoboFormComCustomizeIEMenu.html
IE: RoboForm Toolbar - file://d:\program files\Siber Systems\Ai RoboForm\RoboFormComShowToolbar.html
Trusted Zone: turbotax.com
DPF: DirectAnimation Java Classes - file://c:\windows\SYSTEM\dajava.cab
DPF: Internet Explorer Classes for Java - file://c:\windows\SYSTEM\iejava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso4.cab
FF - ProfilePath - c:\documents and settings\dijones\Application Data\Mozilla\Firefox\Profiles\j1ovf96g.default\
FF - plugin: d:\java\bin\new_plugin\npdeploytk.dll
FF - plugin: d:\java\bin\new_plugin\npjp2.dll
FF - plugin: d:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-21 10:56:07
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-03-21 11:02:05
ComboFix-quarantined-files.txt 2009-03-21 15:02:02
ComboFix3.txt 2009-03-16 20:33:26
ComboFix2.txt 2009-03-17 20:49:22
Pre-Run: 140,591,104 bytes free
Post-Run: 198,619,136 bytes free
214 --- E O F --- 2009-03-14 07:26:06
_____________________________________________
HJT Log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:08:46 AM, on 3/21/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
D:\Java\bin\jqs.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
D:\Steve's help speed this computer folder\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
D:\Steve's help speed this computer folder\Firefox\firefox.exe
D:\Steve's help speed this computer folder\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://216.65.101.250/sbms/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://middlegeorgia.cox.net/cci/home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.netscape.com/home/winsearch200.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://keyword.netscape.com/keyword/%s
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\STEVE'~1\SPYBOT~1\SDHelper.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - D:\Program Files\Siber Systems\Ai RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Java\bin\ssv.dll
O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Java\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Java\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - D:\Program Files\Siber Systems\Ai RoboForm\roboform.dll
O3 - Toolbar: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM32\qttask.exe" -atboottime
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Add to filterlist (WebWasher) - http://-Web.Washer-/ie_add
O8 - Extra context menu item: Customize Menu - file://D:\Program Files\Siber Systems\Ai RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: RoboForm Toolbar - file://D:\Program Files\Siber Systems\Ai RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Java\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Java\bin\jp2iexp.dll
O9 - Extra button: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - http://www.net2phone.com/ (file missing)
O9 - Extra 'Tools' menuitem: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - http://www.net2phone.com/ (file missing)
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://D:\Program Files\Siber Systems\Ai RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://D:\Program Files\Siber Systems\Ai RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\STEVE'~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\STEVE'~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O13 - WWW. Prefix: http://
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52...ple.com/drakken/us/win/QuickTimeInstaller.exe
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {65E7DB1D-0101-4100-BD66-C5C78C917F93} -
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} (Java Plug-in 1.5.0_09) -
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Java\bin\jqs.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O24 - Desktop Component 0: (no name) - http://www3.shopsmartbargains.com/images/product/105838/1058382609_LG.jpg
--
End of file - 5508 bytes
ComboFix 09-03-19.02 - dijones 2009-03-21 10:51:51.3 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.576.334 [GMT -4:00]
Running from: c:\documents and settings\dijones\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\dijones\Desktop\CFScript.txt
* Created a new restore point
FILE ::
c:\windows\Downloaded Program Files\SbCIe01f.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Downloaded Program Files\SbCIe01f.dll
.
((((((((((((((((((((((((( Files Created from 2009-02-21 to 2009-03-21 )))))))))))))))))))))))))))))))
.
2009-03-20 12:46 . 2009-03-20 12:46 <DIR> d-------- c:\program files\EsetOnlineScanner
2009-03-18 19:08 . 2009-03-18 19:08 525,928 --a------ c:\temp\ZCP9EA07.exe
2009-03-17 20:10 . 2009-03-17 20:10 <DIR> d-------- C:\dell
2009-03-16 14:57 . 2009-03-16 14:57 <DIR> d-------- c:\program files\Common Files\ScanSoft Shared
2009-03-15 02:40 . 2009-03-15 02:40 <DIR> d-------- c:\documents and settings\LocalService.NT AUTHORITY\Application Data\AdobeUM
2009-03-14 20:15 . 2009-03-14 20:15 <DIR> d-------- c:\windows\SYSTEM32\CatRoot_bak
2009-03-13 23:00 . 2009-03-13 23:00 <DIR> d--h----- C:\$AVG8.VAULT$
2009-03-13 22:50 . 2009-03-13 22:50 <DIR> d-------- c:\documents and settings\All Users\Application Data\avg8
2009-03-13 11:31 . 2008-06-13 09:10 272,128 --------- c:\windows\SYSTEM32\DRIVERS\bthport.sys
2009-03-13 11:31 . 2008-06-13 09:10 272,128 --------- c:\windows\SYSTEM32\dllcache\bthport.sys
2009-03-13 11:27 . 2008-05-01 10:30 331,776 --------- c:\windows\SYSTEM32\dllcache\msadce.dll
2009-03-13 05:31 . 2009-03-13 05:31 <DIR> d-------- c:\documents and settings\dijones\Application Data\Malwarebytes
2009-03-13 05:31 . 2009-02-11 10:19 15,504 --a------ c:\windows\SYSTEM32\DRIVERS\mbam.sys
2009-03-13 05:30 . 2009-03-13 05:30 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-13 05:30 . 2009-02-11 10:19 38,496 --a------ c:\windows\SYSTEM32\DRIVERS\mbamswissarmy.sys
2009-03-13 01:15 . 2009-03-13 01:15 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-03-13 00:50 . 2009-03-13 00:49 410,984 --a------ c:\windows\SYSTEM32\deploytk.dll
2009-03-13 00:50 . 2009-03-13 00:49 73,728 --a------ c:\windows\SYSTEM32\javacpl.cpl
2009-03-09 00:12 . 2009-03-09 00:12 <DIR> d---s---- c:\documents and settings\LocalService.NT AUTHORITY\UserData
2009-03-08 15:16 . 2009-03-08 15:16 <DIR> d-------- c:\program files\Remote
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-11 16:29 4,224 ----a-w c:\windows\system32\drivers\beep.sys
2009-02-09 10:19 1,846,272 ----a-w c:\windows\SYSTEM32\win32k.sys
2009-02-09 10:19 1,846,272 ------w c:\windows\SYSTEM32\dllcache\win32k.sys
2007-07-01 17:51 121,392 ----a-w c:\documents and settings\dijones\Application Data\GDIPFONTCACHEV1.DAT
2005-04-27 18:47 266 --sh--w c:\program files\desktop.ini
2005-04-27 18:47 11,079 ---h--w c:\program files\folder.htt
1997-04-21 01:51 33,539 ----a-w c:\program files\readme.txt
1997-01-16 16:45 186 ----a-w c:\program files\File_id.diz
1997-01-16 16:45 10,460 ----a-w c:\program files\VENDINFO.DIZ
1996-12-31 01:11 26,624 ----a-w c:\program files\Gold.doc
.
((((((((((((((((((((((((((((( SnapShot@2009-03-16_16.08.00.14 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-03-16 19:50:48 16,384 ----a-w c:\windows\Application Data\Earthlink\6.0\dijones@infionline.net\Cookies\index.dat
+ 2009-03-20 22:41:14 32,768 ----a-w c:\windows\Application Data\Earthlink\6.0\dijones@infionline.net\Cookies\index.dat
- 2009-03-01 05:43:28 32,768 ----a-w c:\windows\Application Data\Earthlink\6.0\dijones@infionline.net\UserData\index.dat
+ 2009-03-18 22:19:16 32,768 ----a-w c:\windows\Application Data\Earthlink\6.0\dijones@infionline.net\UserData\index.dat
- 2009-03-16 03:34:12 16,384 ----a-w c:\windows\SYSTEM32\config\systemprofile\Cookies\index.dat
+ 2009-03-17 20:27:48 16,384 ----a-w c:\windows\SYSTEM32\config\systemprofile\Cookies\index.dat
- 2009-03-16 03:34:12 32,768 ----a-w c:\windows\SYSTEM32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-03-17 20:27:48 32,768 ----a-w c:\windows\SYSTEM32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-03-16 03:34:12 32,768 ----a-w c:\windows\SYSTEM32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-03-17 20:27:48 32,768 ----a-w c:\windows\SYSTEM32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2009-03-13 04:50:42 1,636 ----a-w c:\windows\SYSTEM32\d3d9caps.dat
+ 2009-03-21 05:35:36 1,636 ----a-w c:\windows\SYSTEM32\d3d9caps.dat
+ 2007-07-27 18:49:02 196,683 ----a-w c:\windows\SYSTEM32\lnod32apiA.dll
+ 2007-07-27 18:49:02 225,355 ----a-w c:\windows\SYSTEM32\lnod32apiW.dll
+ 2005-12-05 23:25:22 139,264 ----a-w c:\windows\SYSTEM32\lnod32umc.dll
+ 2005-12-05 16:37:10 106,496 ----a-w c:\windows\SYSTEM32\lnod32upd.dll
+ 2008-02-11 13:39:26 253,952 ----a-w c:\windows\SYSTEM32\OnlineScannerDLLA.dll
+ 2008-02-11 13:39:18 237,568 ----a-w c:\windows\SYSTEM32\OnlineScannerDLLW.dll
+ 2008-02-08 17:53:46 110,592 ----a-w c:\windows\SYSTEM32\OnlineScannerLang.dll
+ 2008-02-05 12:48:04 77,824 ----a-w c:\windows\SYSTEM32\OnlineScannerUninstaller.exe
+ 2004-12-07 14:11:34 258,352 ----a-w c:\windows\SYSTEM32\unicows.dll
+ 2009-03-20 21:32:56 16,384 ----a-w c:\windows\TEMP\Perflib_Perfdata_52c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SlowFile Icon Overlay]
@="{7D688A77-C613-11D0-999B-00C04FD655E1}"
[HKEY_CLASSES_ROOT\CLSID\{7D688A77-C613-11D0-999B-00C04FD655E1}]
2008-07-03 09:16 8454656 --a------ c:\windows\SYSTEM32\SHELL32.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\windows\SYSTEM32\qttask.exe" [2004-10-03 98304]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"EditLevel"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"EditLevel"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.yvu9"= ATIYVU9.DLL
"MSACM.MSNAUDIO"= msnaudio.acm
"VIDC.VDOM"= vdowave.drv
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PrintKey-Pro.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\PrintKey-Pro.lnk
backup=c:\windows\pss\PrintKey-Pro.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EReminderdiamond]
--a------ 1998-08-17 13:03 167424 c:\program files\Encompass\Diamond\EReminder.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
--a------ 2006-01-13 20:36 196608 c:\windows\SYSTEM32\spool\drivers\w32x86\3\hpztsb04.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelliPoint]
--a------ 2004-06-03 01:50 204800 c:\program files\Microsoft IntelliPoint\point32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
--a------ 2001-07-09 06:50 155648 c:\windows\SYSTEM32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2004-10-03 00:18 98304 c:\windows\SYSTEM32\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoboForm]
--a------ 2008-11-01 13:56 160592 d:\program files\Siber Systems\Ai RoboForm\robotaskbaricon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2009-03-05 16:07 2260480 d:\steve's help speed this computer folder\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2009-03-13 00:49 148888 d:\java\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"avg8wd"=2 (0x2)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpySweeper"=
"Attune Download"=c:\progra~1\AVEO\ATTUNE\UPDATER1\ATTUNEL.EXE
"E6TaskPanel"=d:\program files\EARTHLINK TOTALACCESS\TASKPANL.EXE -winstart
"HXIUL.EXE"=c:\program files\Micro Warehouse\HelpExpress\dijones\HXIUL.EXE -uninstall
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"WinampAgent"="c:\program files\Winamp3\winampa.exe"
"QuickTime Task"="c:\windows\SYSTEM32\qttask.exe" -atboottime
"InCD"=c:\program files\Ahead\InCD\InCD.exe
"POINTER"=point32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"Disknag"=c:\dell\DISKNAG.EXE
"AtiCwd32"=Aticwd32.exe
"StillImageMonitor"=c:\windows\SYSTEM32\STIMON.EXE
"Ati2cwxx"=Ati2cwxx.exe
"AccessRampMonitor"="c:\program files\EarthLink\FastLane\ARMon32.exe"
"HPDJ Taskbar Utility"=c:\windows\SYSTEM32\hpztsb04.exe
"mdac_runonce"=c:\windows\SYSTEM32\RUNONCE.EXE
"AtiPTA"=Atiptaxx.exe
"QuickTime Task"="c:\windows\SYSTEM32\qttask.exe" -atboottime
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
"POINTER"=point32.exe
"ICSDCLT"=c:\windows\SYSTEM32\RUNDLL32.EXE c:\windows\SYSTEM32\ICSDCLT.DLL,ICSClient
"ScreenPrint32"=c:\program files\SCREENPRINT32 V3\SCREENPRINT32.exe -startup
"COMSMDEXE"=comsmd.exe -off
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"d:\\Java\\bin\\java.exe"=
R3 cwbmidi_device;Crystal WDM MPU-401 UART Driver;c:\windows\SYSTEM32\DRIVERS\cwbmidi.sys [2006-07-12 3072]
R3 cwbwdm_device;Crystal WDM Audio Codec Driver;c:\windows\SYSTEM32\DRIVERS\cwbwdm.sys [2006-07-12 72832]
S3 NtApm;NT Apm/Legacy Interface Driver;c:\windows\SYSTEM32\DRIVERS\NtApm.sys [2006-07-12 9344]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
"c:\program files\Outlook Express\setup50.exe" /APP:OE /CALLER:IE50 /user /install
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
"c:\program files\Outlook Express\setup50.exe" /APP:OE /CALLER:IE50 /user /install
"c:\program files\Outlook Express\setup50.exe" /APP:OE /CALLER:IE50 /user /install
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
"c:\program files\Outlook Express\setup50.exe" /APP:WAB /CALLER:IE50 /user /install
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
"c:\program files\Outlook Express\setup50.exe" /APP:WAB /CALLER:IE50 /user /install
"c:\program files\Outlook Express\setup50.exe" /APP:WAB /CALLER:IE50 /user /install
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}]
c:\windows\SYSTEM32\updcrl.exe -e -u c:\windows\SYSTEM\verisignpub1.crl
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://middlegeorgia.cox.net/cci/home
mLocal Page = c:\windows\SYSTEM\blank.htm
mSearch Bar = hxxp://home.netscape.com/home/winsearch200.html
uInternet Settings,ProxyOverride = 127.0.0.1
uSearchURL,(Default) = hxxp://keyword.netscape.com/keyword/%s
IE: Add to filterlist (WebWasher) - http://-Web.Washer-/ie_add
IE: Customize Menu - file://d:\program files\Siber Systems\Ai RoboForm\RoboFormComCustomizeIEMenu.html
IE: RoboForm Toolbar - file://d:\program files\Siber Systems\Ai RoboForm\RoboFormComShowToolbar.html
Trusted Zone: turbotax.com
DPF: DirectAnimation Java Classes - file://c:\windows\SYSTEM\dajava.cab
DPF: Internet Explorer Classes for Java - file://c:\windows\SYSTEM\iejava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso4.cab
FF - ProfilePath - c:\documents and settings\dijones\Application Data\Mozilla\Firefox\Profiles\j1ovf96g.default\
FF - plugin: d:\java\bin\new_plugin\npdeploytk.dll
FF - plugin: d:\java\bin\new_plugin\npjp2.dll
FF - plugin: d:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-21 10:56:07
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-03-21 11:02:05
ComboFix-quarantined-files.txt 2009-03-21 15:02:02
ComboFix3.txt 2009-03-16 20:33:26
ComboFix2.txt 2009-03-17 20:49:22
Pre-Run: 140,591,104 bytes free
Post-Run: 198,619,136 bytes free
214 --- E O F --- 2009-03-14 07:26:06
_____________________________________________
HJT Log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:08:46 AM, on 3/21/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
D:\Java\bin\jqs.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
D:\Steve's help speed this computer folder\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
D:\Steve's help speed this computer folder\Firefox\firefox.exe
D:\Steve's help speed this computer folder\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://216.65.101.250/sbms/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://middlegeorgia.cox.net/cci/home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.netscape.com/home/winsearch200.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://keyword.netscape.com/keyword/%s
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\STEVE'~1\SPYBOT~1\SDHelper.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - D:\Program Files\Siber Systems\Ai RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Java\bin\ssv.dll
O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Java\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Java\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - D:\Program Files\Siber Systems\Ai RoboForm\roboform.dll
O3 - Toolbar: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM32\qttask.exe" -atboottime
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Add to filterlist (WebWasher) - http://-Web.Washer-/ie_add
O8 - Extra context menu item: Customize Menu - file://D:\Program Files\Siber Systems\Ai RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: RoboForm Toolbar - file://D:\Program Files\Siber Systems\Ai RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Java\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Java\bin\jp2iexp.dll
O9 - Extra button: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - http://www.net2phone.com/ (file missing)
O9 - Extra 'Tools' menuitem: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - http://www.net2phone.com/ (file missing)
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://D:\Program Files\Siber Systems\Ai RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://D:\Program Files\Siber Systems\Ai RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\STEVE'~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\STEVE'~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O13 - WWW. Prefix: http://
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52...ple.com/drakken/us/win/QuickTimeInstaller.exe
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {65E7DB1D-0101-4100-BD66-C5C78C917F93} -
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} (Java Plug-in 1.5.0_09) -
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Java\bin\jqs.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O24 - Desktop Component 0: (no name) - http://www3.shopsmartbargains.com/images/product/105838/1058382609_LG.jpg
--
End of file - 5508 bytes