Sorry about the delay in getting back...I had some issues with Kaspersky last night. But Here's the update....
I removed the ABC - (I didn't even think about it being a P2P issue since I rarely leave it running and only use it to trade live recordings on a specific member community) Anyway... it's gone ...
I updated Adobe by uninstalling the old version then reinstalling the new -
I also tried to empty the recycled bin but was told there was nothing in there...
Ran the CFscript on combofix
Cleaned up with ATF -
Now the Kaspersky.....I had to reinstall Java and change some of the ActiveX controls to get it to work right... then the first scan took almost two hours (Which I figure is normal) ... the second was running for 13 hours and only got to 45% so I aborted it.
The new combofix log...
ComboFix 08-11-23.02 - Jeff 2008-11-24 17:28:50.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.214 [GMT -5:00]
Running from: c:\documents and settings\Jeff.JEFF-8523F79F03\Desktop\ComboFxx.exe
Command switches used :: c:\documents and settings\Jeff.JEFF-8523F79F03\Desktop\CFScript.txt
* Created a new restore point
FILE ::
c:\documents and settings\All Users.WINDOWS\Application Data\ejyhyza.reg
c:\documents and settings\All Users.WINDOWS\Application Data\fekuqibap.reg
c:\documents and settings\Jeff.JEFF-8523F79F03\delself.bat
c:\program files\Common Files\oxejirizu.lib
c:\program files\Common Files\qicugev._dl
c:\program files\Common Files\razeho._sy
c:\windows\caxakoh.com
c:\windows\ijidi.pif
c:\windows\ijyw.pif
c:\windows\magix.reg
c:\windows\onajuko.dll
c:\windows\system32\drivers\TDSSmaxt.sys
c:\windows\SYSTEM32\fapakat.sys
c:\windows\SYSTEM32\kecefaduqu.exe
.
((((((((((((((((((((((((( Files Created from 2008-10-24 to 2008-11-24 )))))))))))))))))))))))))))))))
.
2019-01-20 15:57 . 2008-02-10 17:49 <DIR> d-------- c:\program files\GoldWave
2019-01-20 15:56 . 2019-01-20 15:56 <DIR> d-------- c:\program files\Lame
2019-01-20 14:58 . 2019-01-20 14:58 <DIR> d--hs---- C:\Recycled
2019-01-20 12:39 . 2019-01-20 12:39 <DIR> d---s---- c:\windows\SYSTEM32\Microsoft
2019-01-20 12:32 . 2019-01-20 12:32 <DIR> d-------- c:\windows\SYSTEM32\xircom
2019-01-20 12:32 . 2008-11-12 08:14 <DIR> d--h----- c:\windows\$hf_mig$
2019-01-20 12:32 . 2019-01-20 12:32 <DIR> d-------- c:\program files\microsoft frontpage
2019-01-20 12:29 . 2008-09-11 21:44 <DIR> d-------- c:\windows\SYSTEM32\Restore
2019-01-20 12:29 . 2008-08-23 00:56 635,848 -----c--- c:\windows\SYSTEM32\dllcache\iexplore.exe
2019-01-20 12:29 . 2008-03-24 23:50 554,008 --a--c--- c:\windows\SYSTEM32\dllcache\dao360.dll
2019-01-20 12:29 . 2008-05-01 09:33 331,776 --a--c--- c:\windows\SYSTEM32\dllcache\msadce.dll
2019-01-20 12:29 . 2007-08-13 17:44 69,120 --a--c--- c:\windows\SYSTEM32\dllcache\iedw.exe
2019-01-20 12:29 . 2007-08-13 17:18 60,416 --a--c--- c:\windows\SYSTEM32\dllcache\hmmapi.dll
2019-01-20 12:23 . 2008-11-22 19:19 <DIR> d-------- c:\windows\SYSTEM32\CatRoot2
2019-01-20 12:23 . 2008-09-11 21:53 <DIR> d-------- c:\windows\SYSTEM32\CatRoot
2019-01-20 12:23 . 2008-11-24 17:12 <DIR> d--hs---- c:\windows\Installer
2019-01-20 12:23 . 2008-11-18 08:02 <DIR> d-------- C:\Documents and Settings
2019-01-20 12:23 . 2006-02-28 07:00 1,685,606 --a--c--- c:\windows\SYSTEM32\dllcache\sam.spd
2019-01-20 12:23 . 2006-02-28 07:00 774,144 --a--c--- c:\windows\SYSTEM32\dllcache\spttseng.dll
2019-01-20 12:23 . 2006-02-28 07:00 643,717 --a--c--- c:\windows\SYSTEM32\dllcache\ltts1033.lxa
2019-01-20 12:23 . 2006-02-28 07:00 605,050 --a--c--- c:\windows\SYSTEM32\dllcache\r1033tts.lxa
2019-01-20 12:23 . 2006-02-28 07:00 77,824 --a--c--- c:\windows\SYSTEM32\dllcache\spcommon.dll
2019-01-20 12:23 . 2006-02-28 07:00 61,440 --a--c--- c:\windows\SYSTEM32\dllcache\spcplui.dll
2019-01-20 12:23 . 2006-02-28 07:00 36,864 --a--c--- c:\windows\SYSTEM32\dllcache\sapisvr.exe
2019-01-20 12:23 . 2006-02-28 07:00 888 --a--c--- c:\windows\SYSTEM32\dllcache\sam.sdf
2019-01-20 12:15 . 2019-01-20 12:15 <DIR> d--hs---- C:\undo
2019-01-20 12:14 . 2019-01-20 12:14 512 ---hs---- C:\BOOTSECT.DOS
2019-01-20 12:04 . 2019-01-20 12:04 <DIR> d-------- c:\windows\MDMUPGLG
2019-01-20 11:12 . 2008-09-12 22:21 <DIR> d---s---- c:\windows\Downloaded Program Files
2019-01-20 11:12 . 2019-01-20 11:13 <DIR> d-------- c:\program files\DirectX
2019-01-20 11:11 . 2019-01-20 11:11 <DIR> d-------- c:\windows\All Users
2008-11-24 17:12 . 2008-11-24 17:12 <DIR> d-------- c:\program files\Common Files\Adobe AIR
2008-11-24 13:32 . 2008-11-24 13:32 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2008-11-24 13:32 . 2008-11-24 17:22 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2008-11-22 08:18 . 2008-11-22 08:18 <DIR> d-------- c:\program files\Trend Micro
2008-11-21 20:07 . 2008-11-21 20:07 <DIR> d-------- c:\documents and settings\Jeff.JEFF-8523F79F03\Application Data\Sunbelt
2008-11-21 20:06 . 2008-11-21 20:06 <DIR> d-------- c:\program files\Sunbelt Software
2008-11-21 20:06 . 2008-11-21 20:06 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\Sunbelt
2008-11-21 12:22 . 2008-11-21 13:48 <DIR> d--h----- C:\$AVG8.VAULT$
2008-11-20 16:13 . 2008-11-20 16:13 <DIR> d-------- c:\program files\Alwil Software
2008-11-20 14:34 . 2008-11-20 14:34 <DIR> d-------- c:\program files\AVG
2008-11-20 14:34 . 2008-11-24 08:41 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\avg8
2008-11-20 13:19 . 2008-11-21 07:23 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft
2008-11-20 12:49 . 2008-11-20 12:49 18,921 --a------ c:\windows\kipomaw.db
2008-11-20 12:49 . 2008-11-20 12:49 18,661 --a------ c:\windows\ylerivu.db
2008-11-20 12:49 . 2008-11-20 12:49 14,811 --a------ c:\windows\lofuzehu.dl
2008-11-20 12:49 . 2008-11-20 12:49 13,804 --a------ c:\windows\okypasa.db
2008-11-20 12:49 . 2008-11-20 12:49 13,189 --a------ c:\windows\SYSTEM32\kaqojokuv._dl
2008-11-20 12:49 . 2008-11-20 12:49 10,542 --a------ c:\windows\ralybu.lib
2008-11-18 21:37 . 2008-11-19 19:59 682 --a------ c:\windows\WININIT.INI
2008-11-12 06:55 . 2008-09-04 12:15 1,106,944 -----c--- c:\windows\SYSTEM32\dllcache\msxml3.dll
2008-11-12 06:55 . 2008-10-24 06:21 455,296 -----c--- c:\windows\SYSTEM32\dllcache\mrxsmb.sys
2008-10-25 15:04 . 2008-10-25 15:04 <DIR> d-------- c:\documents and settings\Jeff.JEFF-8523F79F03\Application Data\Didiom
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2019-01-20 16:12 266 --sh--w c:\program files\desktop.ini
2019-01-20 16:12 11,079 ---ha-w c:\program files\folder.htt
2008-11-24 22:10 --------- d-----w c:\program files\Common Files\Adobe
2008-11-22 13:07 --------- d-----w c:\program files\Java
2008-11-22 13:05 --------- d-----w c:\program files\Common Files\Research In Motion
2008-11-22 13:04 --------- d-----w c:\program files\Common Files\Roxio Shared
2008-11-22 13:04 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Roxio
2008-11-21 12:36 --------- d-----w c:\documents and settings\Jeff.JEFF-8523F79F03\Application Data\Uniblue
2008-11-21 12:36 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\DriverScanner
2008-11-21 12:25 --------- d-----w c:\program files\BlueVoda Website Builder
2008-11-21 12:23 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-11-11 12:49 --------- d-----w c:\documents and settings\Jeff.JEFF-8523F79F03\Application Data\OpenOffice.org2
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-23 23:35 --------- d-----w c:\program files\Napster
2008-10-21 17:34 --------- d-----w c:\program files\Microsoft Silverlight
2008-10-19 13:25 --------- d-----w c:\program files\WMR11
2008-10-16 19:13 202,776 ----a-w c:\windows\SYSTEM32\wuweb.dll
2008-10-16 19:13 1,809,944 ----a-w c:\windows\SYSTEM32\wuaueng.dll
2008-10-16 19:12 561,688 ----a-w c:\windows\SYSTEM32\wuapi.dll
2008-10-16 19:12 323,608 ----a-w c:\windows\SYSTEM32\wucltui.dll
2008-10-16 19:09 92,696 ----a-w c:\windows\SYSTEM32\cdm.dll
2008-10-16 19:09 51,224 ----a-w c:\windows\SYSTEM32\wuauclt.exe
2008-10-16 19:09 43,544 ----a-w c:\windows\SYSTEM32\wups2.dll
2008-10-16 19:08 34,328 ----a-w c:\windows\SYSTEM32\wups.dll
2008-10-16 19:06 268,648 ----a-w c:\windows\SYSTEM32\mucltui.dll
2008-10-16 19:06 208,744 ----a-w c:\windows\SYSTEM32\muweb.dll
2008-10-10 00:10 --------- d-----w c:\program files\MSECache
2008-09-30 21:43 1,286,152 ----a-w c:\windows\SYSTEM32\msxml4.dll
2008-09-25 21:27 --------- d-----w c:\documents and settings\Jeff.JEFF-8523F79F03\Application Data\.ABC
2008-09-25 17:48 --------- d-----w c:\documents and settings\Jeff.JEFF-8523F79F03\Application Data\U3
2008-09-15 12:12 1,846,400 ----a-w c:\windows\SYSTEM32\win32k.sys
2008-09-10 01:14 1,307,648 ----a-w c:\windows\SYSTEM32\msxml6.dll
2008-09-04 17:15 1,106,944 ----a-w c:\windows\SYSTEM32\msxml3.dll
2008-08-26 07:24 826,368 ----a-w c:\windows\SYSTEM32\wininet.dll
2006-03-15 18:19 212,992 ----a-w c:\windows\inf\WG311v3\CopyWHQLDriver.exe
2006-01-26 21:55 280,576 ----a-w c:\windows\inf\WG311v3\WG311v3.sys
2005-10-06 19:17 280,576 ----a-w c:\windows\inf\WG311v3\WG311v3XP.sys
2003-03-21 17:45 250,544 ----a-w c:\program files\Common Files\keyhelp.ocx
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of C:\Recycled ----
2019-01-20 14:58 65 --ahs---- c:\recycled\desktop.ini
2008-02-09 19:00 53620 --ah----- c:\recycled\INFO2
2008-01-23 16:24 278 --a------ c:\recycled\Dc64.lnk
2008-01-23 16:21 278 --a------ c:\recycled\Dc63.lnk
2008-01-09 09:48 4389760 --a------ c:\recycled\Dc24.EXE
2007-07-18 16:53 3932214 --a------ c:\recycled\Dc40.bmp
2007-05-12 13:08 31400 --a------ c:\recycled\Dc65.jpg
2007-05-12 13:08 21359 --a------ c:\recycled\Dc67.jpg
2007-05-12 13:08 20973 --a------ c:\recycled\Dc66.jpg
2007-04-01 09:16 10954 --a------ c:\recycled\Dc38.jpg
2007-04-01 09:12 12951 --a------ c:\recycled\Dc37.jpg
2007-04-01 09:09 13364 --a------ c:\recycled\Dc36.jpg
2007-04-01 09:04 11053 --a------ c:\recycled\Dc32.jpg
2007-04-01 09:02 13193 --a------ c:\recycled\Dc31.jpg
2007-04-01 09:00 12814 --a------ c:\recycled\Dc30.jpg
2007-04-01 08:57 13016 --a------ c:\recycled\Dc26.jpg
2007-04-01 08:52 11985 --a------ c:\recycled\Dc29.jpg
2007-04-01 08:51 11242 --a------ c:\recycled\Dc28.jpg
2007-04-01 08:49 11309 --a------ c:\recycled\Dc27.jpg
2007-04-01 08:47 11248 --a------ c:\recycled\Dc62.jpg
2007-04-01 08:45 12295 --a------ c:\recycled\Dc61.jpg
2007-03-17 02:51 795718 --a------ c:\recycled\Dc35.bmp
2006-12-02 06:06 795718 --a------ c:\recycled\Dc41.bmp
2006-07-08 01:53 795718 --a------ c:\recycled\Dc43.bmp
2006-06-10 12:14 1284534 --a------ c:\recycled\Dc53.bmp
2006-06-10 11:53 596354 --a------ c:\recycled\Dc47.bmp
2006-06-10 11:52 1284534 --a------ c:\recycled\Dc50.bmp
2006-06-10 11:51 200438 --a------ c:\recycled\Dc48.bmp
2006-06-10 11:21 2764854 --a------ c:\recycled\Dc51.bmp
2006-06-10 11:18 1284534 --a------ c:\recycled\Dc52.bmp
2006-06-10 11:14 795718 --a------ c:\recycled\Dc46.bmp
2006-06-10 11:09 2764854 --a------ c:\recycled\Dc49.bmp
2006-06-10 09:25 795718 --a------ c:\recycled\Dc45.bmp
2005-11-16 07:33 3785943 --a------ c:\recycled\Dc1.mp3
2005-11-13 07:38 9660 --a------ c:\recycled\Dc57.jpg
2005-09-03 03:48 58677812 --a------ c:\recycled\Dc9.wav
2005-08-17 16:48 521958 --a------ c:\recycled\Dc54.bmp
2005-08-17 16:46 1233786 --a------ c:\recycled\Dc55.bmp
2005-07-03 10:23 157639375 --a------ c:\recycled\Dc4.zip
2005-06-22 14:36 2764854 --a------ c:\recycled\Dc58.bmp
2005-06-22 14:30 2764854 --a------ c:\recycled\Dc59.bmp
2005-06-22 13:57 795718 --a------ c:\recycled\Dc33.bmp
2005-06-18 02:05 795718 --a------ c:\recycled\Dc34.bmp
2005-05-29 05:01 304266 --a------ c:\recycled\Dc42.bmp
2005-05-27 17:54 2824336 --a------ c:\recycled\Dc16.exe
2005-05-27 17:54 2824336 --a------ c:\recycled\Dc11.exe
2005-05-15 05:19 3469249 --a------ c:\recycled\Dc8.exe
2005-04-25 14:49 20976 --a------ c:\recycled\Dc60.jpg
2005-03-16 15:58 355463 --a------ c:\recycled\Dc10.exe
2005-03-09 12:52 3894 --a------ c:\recycled\Dc44.art
2005-02-28 15:14 2257283 --a------ c:\recycled\Dc19.zip
2005-02-20 17:34 137730 --a------ c:\recycled\Dc39.bmp
2005-02-20 17:31 1105974 --a------ c:\recycled\Dc56.bmp
2005-02-20 06:02 543269 --a------ c:\recycled\Dc2.exe
2005-02-17 15:28 1721856 --a------ c:\recycled\Dc14.exe
2005-02-17 15:28 1721856 --a------ c:\recycled\Dc12.exe
2005-02-16 02:31 951103 --a------ c:\recycled\Dc20.zip
2005-02-15 19:07 1094021 --a------ c:\recycled\Dc3.zip
2005-02-13 08:53 42303 --a------ c:\recycled\Dc23.exe
2005-01-29 17:54 3144 --a------ c:\recycled\Dc21.zip
2005-01-29 17:05 2102985 --a------ c:\recycled\Dc6.exe
2004-11-28 09:46 700120 --a------ c:\recycled\Dc15.exe
2004-11-28 09:46 700120 --a------ c:\recycled\Dc13.exe
2004-07-31 16:31 1648792 --a------ c:\recycled\Dc22.exe
2004-07-09 10:09 6811656 --a------ c:\recycled\Dc5.exe
2004-06-20 09:58 3025075 --a------ c:\recycled\Dc18.exe
2004-06-20 09:56 3266535 --a------ c:\recycled\Dc17.exe
2004-06-11 11:02 2086400 --a------ c:\recycled\Dc7.exe
---- Directory of C:\undo ----
2019-01-20 12:32 5105141 --a------ c:\undo\boot.cab
2019-01-20 12:16 4 --a------ c:\undo\backup.$$$
2019-01-20 12:16 167181795 --a------ c:\undo\backup.cab
((((((((((((((((((((((((((((( snapshot@2008-11-24_13.13.38.71 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-12-12 20:06:42 295,606 ----a-r c:\windows\Installer\{AC76BA86-7AD7-1033-7B44-A90000000001}\SC_Reader.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 2156368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"EPSON Stylus Photo R200 Series (Copy 1)"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE" [2003-07-08 99840]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-01-31 385024]
"NapsterShell"="c:\program files\Napster\napster.exe" [2008-05-29 323216]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SoundMan"="SOUNDMAN.EXE" [2003-10-08 c:\windows\SOUNDMAN.EXE]
c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\
NETGEAR WG311v3 Smart Wizard.lnk - c:\program files\NETGEAR\WG311v3\wlancfg5.exe [2006-01-26 1486848]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= ctwdm32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2008-04-13 19:12 1695232 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
R2 BT848;AVerMedia AVerTV WDM Video Capture (878);c:\windows\system32\drivers\Bt848.sys [2008-02-10 152064]
S3 SBRE;SBRE;\??\c:\windows\system32\drivers\SBREdrv.sys []
S3 SetupNTGLM7X;SetupNTGLM7X;\??\D:\NTGLM7X.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4ca7339a-18b5-11dd-81b6-001b2fd0abe1}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
2008-10-09 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-24 17:31:38
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(608)
c:\windows\system32\MrvGINA.dll
.
Completion time: 2008-11-24 17:33:03
ComboFix-quarantined-files.txt 2008-11-24 22:32:33
ComboFix2.txt 2008-11-24 22:18:05
ComboFix3.txt 2008-11-24 18:15:04
Pre-Run: 192,926,615,552 bytes free
Post-Run: 192,913,542,656 bytes free
264 --- E O F --- 2008-11-12 13:16:32
The new HJT log ...
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:10:28 AM, on 11/25/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\NETGEAR\WG311v3\wlancfg5.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo R200 Series (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE /P39 "EPSON Stylus Photo R200 Series (Copy 1)" /O5 "LPT1:" /M "Stylus Photo R200"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: NETGEAR WG311v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG311v3\wlancfg5.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1205192849750
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) -
http://dl8-cdn-03.sun.com/s/ESD5/JS...d/&filename=jinstall-6u10-windows-i586-jc.cab
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (file missing)
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
--
End of file - 5534 bytes
Thanks again!