ok... logs galore...
Combofix....
ComboFix 08-06-20.4 - 2008-06-24 17:15:47.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.459 [GMT -5:00]
Running from: C:\Documents and Settings\tressure\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\tressure\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\WINDOWS\system32\cppgkjgo.ini
C:\WINDOWS\system32\ogjkgppc.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\cppgkjgo.ini
C:\WINDOWS\system32\ogjkgppc.dll
.
((((((((((((((((((((((((( Files Created from 2008-05-24 to 2008-06-24 )))))))))))))))))))))))))))))))
.
2346-08-13 07:28 . 2346-08-13 07:28 3,120 --a------ C:\WINDOWS\MF_C421.lfa
2346-08-13 07:28 . 2346-08-13 07:28 3,120 --a------ C:\WINDOWS\MF_C420.lfa
2008-06-21 00:34 . 2008-06-21 00:34 268 --ah----- C:\sqmdata12.sqm
2008-06-21 00:34 . 2008-06-21 00:34 244 --ah----- C:\sqmnoopt12.sqm
2008-06-20 00:35 . 2008-06-20 00:35 268 --ah----- C:\sqmdata11.sqm
2008-06-20 00:35 . 2008-06-20 00:35 244 --ah----- C:\sqmnoopt11.sqm
2008-06-19 23:11 . 2008-06-20 02:09 412 --a------ C:\WINDOWS\wininit.ini
2008-06-19 22:41 . 2008-06-20 00:23 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2008-06-19 21:30 . 2008-06-19 21:30 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-19 00:32 . 2008-06-19 00:32 268 --ah----- C:\sqmdata10.sqm
2008-06-19 00:32 . 2008-06-19 00:32 244 --ah----- C:\sqmnoopt10.sqm
2008-06-18 21:39 . 2008-06-18 21:39 268 --ah----- C:\sqmdata09.sqm
2008-06-18 21:39 . 2008-06-18 21:39 244 --ah----- C:\sqmnoopt09.sqm
2008-06-17 19:25 . 2008-06-17 19:25 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-06-17 19:14 . 2008-06-17 19:14 268 --ah----- C:\sqmdata08.sqm
2008-06-17 19:14 . 2008-06-17 19:14 244 --ah----- C:\sqmnoopt08.sqm
2008-06-17 18:12 . 2008-06-17 18:12 <DIR> d-------- C:\Program Files\Lavasoft
2008-06-17 18:12 . 2008-06-17 19:22 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Lavasoft
2008-06-16 22:29 . 2008-06-16 22:29 268 --ah----- C:\sqmdata07.sqm
2008-06-16 22:29 . 2008-06-16 22:29 244 --ah----- C:\sqmnoopt07.sqm
2008-06-16 19:49 . 2008-06-16 19:49 268 --ah----- C:\sqmdata06.sqm
2008-06-16 19:49 . 2008-06-16 19:49 244 --ah----- C:\sqmnoopt06.sqm
2008-06-16 19:37 . 2008-06-23 15:14 <DIR> d--h----- C:\$AVG8.VAULT$
2008-06-16 19:36 . 2008-06-16 19:36 75,272 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-06-16 19:36 . 2008-06-16 19:36 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-06-16 19:35 . 2008-06-24 16:58 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-06-16 19:35 . 2008-06-16 19:35 <DIR> d-------- C:\Program Files\AVG
2008-06-16 19:35 . 2008-06-17 05:43 <DIR> d-------- C:\Documents and Settings\tressure\Application Data\AVGTOOLBAR
2008-06-16 19:35 . 2008-06-16 19:35 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\avg8
2008-06-16 19:35 . 2008-06-16 19:35 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-06-16 19:24 . 2008-06-18 23:08 <DIR> d-------- C:\Program Files\VAV
2008-06-16 19:24 . 2008-06-19 20:11 <DIR> d-------- C:\Program Files\PCHealthCenter
2008-06-16 18:54 . 2008-06-23 21:06 <DIR> d-------- C:\Documents and Settings\tressure\Application Data\NoNameScript
2008-06-16 13:16 . 2008-06-16 13:16 268 --ah----- C:\sqmdata05.sqm
2008-06-16 13:16 . 2008-06-16 13:16 244 --ah----- C:\sqmnoopt05.sqm
2008-06-15 13:02 . 2008-06-15 13:02 268 --ah----- C:\sqmdata04.sqm
2008-06-15 13:02 . 2008-06-15 13:02 244 --ah----- C:\sqmnoopt04.sqm
2008-05-29 18:06 . 2008-05-29 18:06 244 --ah----- C:\sqmnoopt03.sqm
2008-05-29 18:06 . 2008-05-29 18:06 232 --ah----- C:\sqmdata03.sqm
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-24 22:13 --------- d-----w C:\Program Files\mIRC
2008-06-24 04:20 --------- d-----w C:\Program Files\2 Pic
2008-06-20 03:41 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-06-17 02:21 --------- d-----w C:\Program Files\Common Files\Sandlot Shared
2008-06-17 00:35 --------- d-----w C:\Program Files\PopCap Games
2008-06-04 02:25 --------- d-----w C:\Documents and Settings\tressure\Application Data\U3
2008-05-22 22:23 --------- d-----w C:\Documents and Settings\tressure\Application Data\Yahoo! Messenger
2008-05-13 05:21 --------- d-----w C:\Program Files\Common Files\INCA Shared
2008-04-29 16:20 15,648 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2008-04-29 16:19 15,648 ----a-w C:\WINDOWS\system32\drivers\Awrtrd.sys
2008-04-29 16:19 12,960 ----a-w C:\WINDOWS\system32\drivers\Awrtpd.sys
2007-02-28 03:48 23,552 -c--a-w C:\Program Files\mozilla firefox\plugins\DrvMgt.dll
.
((((((((((((((((((((((((((((( snapshot@2008-06-23_20.58.25.95 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-24 01:42:54 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-24 22:21:00 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
2008-03-19 17:36 1267040 --a------ C:\Program Files\Winamp Toolbar\winamptb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= "C:\Program Files\Winamp Toolbar\winamptb.dll" [2008-03-19 17:36 1267040]
[HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= C:\Program Files\Winamp Toolbar\winamptb.dll [2008-03-19 17:36 1267040]
[HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2005-02-02 07:12 102492]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-06-08 00:47 827392]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-04-11 10:00 339968]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2006-04-18 09:32 405504]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-04-01 15:11 794624]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 23:11 49152]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00 132496]
"EPSON Stylus CX5400"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE" [2003-05-26 15:00 99840]
"WinampAgent"="C:\Program Files\Winamp\wianmpa.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-14 12:41 77824]
"AirPort Base Station Agent"="C:\Program Files\AirPort\APAgent.exe" [2008-03-06 17:40 733184]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 07:00 208952]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 07:00 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 07:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 07:00 455168]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-06-16 19:35 1177368]
C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
BTTray.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2004-12-23 11:07:30 569405]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
NETGEAR Smart Wizard.lnk - C:\WINDOWS\Installer\{B93D24B3-928D-4805-B379-4AA47CB3794E}\NewShortcut1_1.exe [2007-12-27 20:04:26 2238]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\IncrediMail\\bin\\ImApp.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Documents and Settings\\tressure\\Desktop\\WoW-BurningCrusade-Trial-enUS-Installer-downloader.exe"=
"C:\\Program Files\\mIRC\\mirc.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Crux P2P\\Crux P2P.exe"=
"C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\AirPort\\APAgent.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"5353:UDP"= 5353:UDP:Bonjour
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-06-16 19:35]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-06-16 19:35]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-06-16 19:35]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-06-16 19:36]
R2 npkcmsvc;npkcmsvc;C:\Nexon\Mabinogi\npkcmsvc.exe [2007-08-02 12:33]
R3 HSFHWATI;HSFHWATI;C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys [2005-08-22 16:06]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
"2008-06-17 19:07:06 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-06-22 05:23:27 C:\WINDOWS\Tasks\System Restore.job"
- C:\WINDOWS\system32\Restore\rstrui.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-24 17:22:15
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\HPQ\shared\hpqwmi.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\NETGEAR\WG511v2\wlancfg5.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Java\jre1.6.0_02\bin\jucheck.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-06-24 17:32:28 - machine was rebooted [tressure]
ComboFix-quarantined-files.txt 2008-06-24 22:32:23
ComboFix2.txt 2008-06-24 01:59:20
Pre-Run: 21,902,585,856 bytes free
Post-Run: 21,911,924,736 bytes free
196 --- E O F --- 2008-06-24 11:55:56
Kapersky
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, June 24, 2008 20:33
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 24/06/2008
Kaspersky Anti-Virus database records: 881538
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
Scan Statistics:
Total number of scanned objects: 166378
Number of viruses found: 4
Number of infected objects: 11
Number of suspicious objects: 0
Duration of the scan process: 02:40:29
Infected Object Name / Virus Name / Last Action
C:\3f4134c45990343b01562dd2ddaa3d7e\%temp%dd_msxml_retMSI.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\F9F96F5B.TMP Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\avg8\emc\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\avg8\Log\avgcore.log Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\avg8\Log\avglng.log Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\avg8\Log\avgrs.log Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\avg8\Log\avgsched.log Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\avg8\Log\avgui.log Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\avg8\Log\avgwd.log Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\avg8\Log\avgwdsvc.log Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\avg8\Log\commonpriv.log Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\tressure\Application Data\Mozilla\Firefox\Profiles\lorx4qqq.default\cert8.db Object is locked skipped
C:\Documents and Settings\tressure\Application Data\Mozilla\Firefox\Profiles\lorx4qqq.default\foxmarks.log Object is locked skipped
C:\Documents and Settings\tressure\Application Data\Mozilla\Firefox\Profiles\lorx4qqq.default\history.dat Object is locked skipped
C:\Documents and Settings\tressure\Application Data\Mozilla\Firefox\Profiles\lorx4qqq.default\key3.db Object is locked skipped
C:\Documents and Settings\tressure\Application Data\Mozilla\Firefox\Profiles\lorx4qqq.default\parent.lock Object is locked skipped
C:\Documents and Settings\tressure\Application Data\Mozilla\Firefox\Profiles\lorx4qqq.default\search.sqlite Object is locked skipped
C:\Documents and Settings\tressure\Application Data\Mozilla\Firefox\Profiles\lorx4qqq.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\tressure\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\tressure\Local Settings\Application Data\IM\Identities\{0C4A7914-E07A-48B7-88EC-942CC442170C}\Message Store\Attachments\ENTER_SITE_HERE.HTML Infected: Trojan.JS.Redirector.b skipped
C:\Documents and Settings\tressure\Local Settings\Application Data\IM\Identities\{0C4A7914-E07A-48B7-88EC-942CC442170C}\Message Store\Attachments\Pham_Online_RX.HTML Infected: Trojan.JS.Redirector.b skipped
C:\Documents and Settings\tressure\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\tressure\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\tressure\Local Settings\Application Data\Mozilla\Firefox\Profiles\lorx4qqq.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\tressure\Local Settings\Application Data\Mozilla\Firefox\Profiles\lorx4qqq.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\tressure\Local Settings\Application Data\Mozilla\Firefox\Profiles\lorx4qqq.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\tressure\Local Settings\Application Data\Mozilla\Firefox\Profiles\lorx4qqq.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\tressure\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\tressure\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\tressure\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\tressure\ntuser.dat.LOG Object is locked skipped
C:\f12b9487c72e9adfad1e\msxml4-KB927978-enu.log Object is locked skipped
C:\Program Files\mIRC\backups\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.621 skipped
C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.631 skipped
C:\Program Files\Yahoo!\Messenger\logs\billing_tressure.log Object is locked skipped
C:\Program Files\Yahoo!\Messenger\logs\client_tressure.log Object is locked skipped
C:\Program Files\Yahoo!\Messenger\logs\network_tressure.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP50\A0005903.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.621 skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP52\A0005972.exe/stream/data0001/stream/data0014 Infected: not-a-virus:Client-IRC.Win32.mIRC.631 skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP52\A0005972.exe/stream/data0001/stream Infected: not-a-virus:Client-IRC.Win32.mIRC.631 skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP52\A0005972.exe/stream/data0001 Infected: not-a-virus:Client-IRC.Win32.mIRC.631 skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP52\A0005972.exe/stream Infected: not-a-virus:Client-IRC.Win32.mIRC.631 skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP52\A0005972.exe NSIS: infected - 4 skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP52\A0005988.exe Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP52\A0006986.dll Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP52\A0006995.exe Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP52\A0007990.exe Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP52\A0007991.exe Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP52\A0008986.exe Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP52\A0008995.exe Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP52\A0009986.exe Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP52\A0009994.exe Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP54\A0010071.exe Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP54\A0010073.exe Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP54\A0010078.exe Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP54\A0010148.dll Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP54\A0010163.exe Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP54\A0010280.exe Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP54\A0010282.exe Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP54\A0010283.exe Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP54\A0010284.dll Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP54\A0010285.dll Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP54\A0010286.dll Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP55\A0010290.dll Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP55\A0010291.dll Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP55\A0010292.dll Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP55\A0010293.dll Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP55\A0010294.exe Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP55\A0010305.exe Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP55\A0010314.cpl Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP55\A0010315.cpl Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP55\A0010326.exe Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP55\A0010333.exe Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP55\A0010334.exe Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP55\A0010335.exe Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP55\A0010336.exe Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP55\A0010337.exe Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP55\A0010338.exe Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP55\A0010339.exe Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP55\A0010340.exe Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP55\A0010341.exe Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP55\A0010342.exe Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP55\A0010386.exe Infected: not-a-virus:FraudTool.Win32.WinSpywareProtect.ac skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP55\A0010389.dll Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP55\A0010412.dll Object is locked skipped
C:\System Volume Information\_restore{E532FC4A-DFBD-4FAA-BF9A-570EDA51DEA4}\RP61\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{0FB7737B-EADF-4822-8B5D-7CD80113A5DE}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\security Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\TEMP\Perflib_Perfdata_840.dat Object is locked skipped
C:\WINDOWS\TEMP\~DF892F.tmp Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
HJT
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:34, on 6/24/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Nexon\Mabinogi\npkcmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\HPQ\shared\hpqwmi.exe
C:\Program Files\AirPort\APAgent.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\NETGEAR\WG511v2\wlancfg5.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Java\jre1.6.0_02\bin\jucheck.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://windowsupdate.microsoft.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Shareaza Web Download Hook - {0EEDB912-C5FA-486F-8334-57288578C627} - C:\Program Files\Crux P2P\Plugins\RazaWebHook.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [EPSON Stylus CX5400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE /P19 "EPSON Stylus CX5400" /O6 "USB001" /M "Stylus CX5400"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\wianmpa.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AirPort Base Station Agent] "C:\Program Files\AirPort\APAgent.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NETGEAR Smart Wizard.lnk = ?
O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users.WINDOWS\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: Download with &Shareaza - res://C:\Program Files\Crux P2P\Plugins\RazaWebHook.dll/3000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\tressure\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky.nl/scanforvirus-en/kavwebscan_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1190490915734
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\shared\hpqwmi.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Nexon\Mabinogi\npkcmsvc.exe
--
End of file - 9333 bytes