spybot powers off computer...
"Owner" - 07-01-12 19:12:18 Service Pack 2
ComboFix 07-01-12 - Running from: "C:\Documents and Settings\Owner\Desktop"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\dlh9jkd1q8.exe
c:\command.com
C:\WINDOWS\s32.txt
C:\WINDOWS\ws386.ini
C:\WINDOWS\Downloaded Program Files\WebEx
C:\Program Files\Common Files\{34401~1
C:\Documents and Settings\All Users\Documents\Settings
C:\Program Files\psdream
C:\WINDOWS\system32\components
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\DOCUME~1
C:\qoobox\purity\DOCUME~1\Owner
C:\qoobox\purity\DOCUME~1\Owner\My Documents
C:\qoobox\purity\DOCUME~1\Owner\My Documents\from.txt
C:\qoobox\purity\DOCUME~1\Owner\My Documents\CROSOF~1.NET
((((((((((((((((((((((((((((((( Files Created from 2006-12-12 to 2007-01-12 ))))))))))))))))))))))))))))))))))
2007-01-11 19:04 <DIR> d-------- C:\Rustbfix
2007-01-10 18:06 <DIR> d--hs---- C:\FOUND.000
2007-01-09 16:37 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-01-07 18:42 3,176 --a------ C:\WINDOWS\system32\tmp.reg
2007-01-07 18:41 79,360 --a------ C:\WINDOWS\system32\swxcacls.exe
2007-01-07 18:41 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-01-07 18:41 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-01-07 18:41 40,960 --a------ C:\WINDOWS\system32\swsc.exe
2007-01-07 18:41 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-01-07 18:41 135,168 --a------ C:\WINDOWS\system32\swreg.exe
2006-12-20 18:35 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2006-12-20 18:29 <DIR> d-------- C:\DOCUME~1\Owner\Application Data\Active Disk
2006-12-20 18:25 86,016 --a------ C:\WINDOWS\unvise32.exe
2006-12-20 18:24 <DIR> d-------- C:\Program Files\Iomega
2006-12-20 18:23 <DIR> d-------- C:\DOCUME~1\Owner\Application Data\Leadertech
2006-12-20 17:16 <DIR> d-------- C:\DOCUME~1\Owner\Application Data\TrojanHunter
2006-12-20 17:15 <DIR> d-------- C:\Program Files\TrojanHunter 4.6
2006-12-20 17:01 <DIR> d-------- C:\WINDOWS\system32\ZoneLabs
2006-12-20 17:00 <DIR> d-------- C:\WINDOWS\Internet Logs
2006-12-19 18:32 <DIR> d-------- C:\VundoFix Backups
2006-12-19 18:26 81,684 --a------ C:\WINDOWS\system32\ofopxbgk.dll
2006-12-18 23:04 <DIR> d-------- C:\Program Files\eFax Messenger 4.2
2006-12-18 23:04 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\eFax Messenger 4.2 Setup
2006-12-18 19:11 <DIR> d-------- C:\hijackthis
2006-12-18 14:18 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2006-12-17 22:21 <DIR> d--hs---- C:\FOUND.023
2006-12-17 19:38 <DIR> d--hs---- C:\FOUND.022
2006-12-17 16:03 <DIR> d--hs---- C:\FOUND.021
2006-12-17 15:42 <DIR> d--hs---- C:\FOUND.020
2006-12-16 13:29 <DIR> d--hs---- C:\FOUND.019
2006-12-14 10:26 118,804 --a------ C:\WINDOWS\system32\ysrnkfcd.dll
2006-12-13 10:17 <DIR> d--hs---- C:\FOUND.018
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-01-08 13:24 69670 --a------ C:\WINDOWS\system32\lzx32.sys
2006-12-10 19:21 -------- d-------- C:\Program Files\address book recovery
2006-12-10 13:24 -------- d-------- C:\DOCUME~1\Owner\Application Data\uniblue
2006-12-10 01:57 -------- d-------- C:\Program Files\copy of outlook express
2006-12-09 17:09 -------- d-------- C:\Program Files\uphclean
2006-12-06 23:40 90164 ---hs---- C:\WINDOWS\system32\ddccd.dll
2006-12-06 15:02 -------- d-------- C:\Program Files\eprintv4
2006-12-06 15:01 -------- d-------- C:\Program Files\agentx
2006-12-06 15:00 -------- d-------- C:\Program Files\agentlink
2006-11-24 08:14 816672 --a------ C:\WINDOWS\system32\drivers\avg7core.sys
2006-11-21 13:14 692276 --a------ C:\WINDOWS\system32\gebcc.dll
2006-11-21 12:11 692276 --a------ C:\WINDOWS\system32\mllmn.dll
2006-11-21 00:25 734369 ---hs---- C:\WINDOWS\system32\mpqss.ini2
2006-11-21 00:24 4960 --a------ C:\WINDOWS\system32\drivers\avgtdi.sys
2006-11-21 00:24 4224 --a------ C:\WINDOWS\system32\drivers\avg7rsw.sys
2006-11-21 00:24 3968 --a------ C:\WINDOWS\system32\drivers\avgclean.sys
2006-11-21 00:24 28416 --a------ C:\WINDOWS\system32\drivers\avg7rsxp.sys
2006-11-20 23:55 728154 ---hs---- C:\WINDOWS\system32\mpqss.bak2
2006-11-20 00:01 -------- d-------- C:\Program Files\symantec
2006-11-19 23:24 10 --a------ C:\WINDOWS\smdat32m.sys
2006-11-19 16:23 732227 ---hs---- C:\WINDOWS\system32\mpqss.bak1
2006-11-19 15:15 7408 --a------ C:\WINDOWS\system32\start2.exe
2006-11-19 15:13 24 --a------ C:\WINDOWS\koxks.dll
2006-11-15 16:57 0 --a------ C:\WINDOWS\dmffo4kd.exe
2006-11-15 00:14 35328 --a------ C:\ohsrdx.exe
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.0.720.3640\\GoogleToolbarNotifier.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"IgfxTray"="C:\\WINDOWS\\System32\\igfxtray.exe"
"HotKeysCmds"="C:\\WINDOWS\\System32\\hkcmd.exe"
"IPPDetect"="IPP4Detect.exe"
"WorksFUD"="C:\\Program Files\\Microsoft Works\\wkfud.exe"
"Microsoft Works Portfolio"="C:\\Program Files\\Microsoft Works\\WksSb.exe /AllUsers"
"Microsoft Works Update Detection"="C:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\WkUFind.exe"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"eFax 4.2"="\"C:\\Program Files\\eFax Messenger 4.2\\J2GDllCmd.exe\" /R"
"Zone Labs Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
"THGuard"="\"C:\\Program Files\\TrojanHunter 4.6\\THGuard.exe\""
"ADUserMon"="C:\\Program Files\\Iomega\\AutoDisk\\ADUserMon.exe"
"Iomega Drive Icons"="C:\\Program Files\\Iomega\\DriveIcons\\ImgIcon.exe"
"Deskup"="C:\\Program Files\\Iomega\\DriveIcons\\deskup.exe /IMGSTART"
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
"KernelFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,\
65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b,00
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Reader Speed Launch.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Adobe\\ACROBA~1.0\\Reader\\READER~1.EXE "
"item"="Adobe Reader Speed Launch"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\America Online 9.0 Tray Icon.lnk"
"backup"="C:\\WINDOWS\\pss\\America Online 9.0 Tray Icon.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\AMERIC~1.0\\aoltray.exe -check"
"item"="America Online 9.0 Tray Icon"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AOL Companion.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\AOL Companion.lnk"
"backup"="C:\\WINDOWS\\pss\\AOL Companion.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\AOLCOM~1\\COMPAN~1.EXE /s"
"item"="AOL Companion"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^eFax 4.2.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\eFax 4.2.lnk"
"backup"="C:\\WINDOWS\\pss\\eFax 4.2.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\EFAXME~1.2\\J2GTray.exe "
"item"="eFax 4.2"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^eFax DllCmd 3.5.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\eFax DllCmd 3.5.lnk"
"backup"="C:\\WINDOWS\\pss\\eFax DllCmd 3.5.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\EFAXME~1.5\\J2GDLL~1.EXE /R"
"item"="eFax DllCmd 3.5"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^eFax Tray Menu 3.5.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\eFax Tray Menu 3.5.lnk"
"backup"="C:\\WINDOWS\\pss\\eFax Tray Menu 3.5.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\EFAXME~1.5\\J2GTray.exe "
"item"="eFax Tray Menu 3.5"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SmartUI.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\SmartUI.lnk"
"backup"="C:\\WINDOWS\\pss\\SmartUI.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Scansoft\\PAPERP~1\\SmartUI\\SmartUI.exe "
"item"="SmartUI"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\WinZip Quick Pick.lnk"
"backup"="C:\\WINDOWS\\pss\\WinZip Quick Pick.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\WinZip\\WZQKPICK.EXE "
"item"="WinZip Quick Pick"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^PaperMaster Live Menu 7.0.lnk]
"path"="C:\\Documents and Settings\\Owner\\Start Menu\\Programs\\Startup\\PaperMaster Live Menu 7.0.lnk"
"backup"="C:\\WINDOWS\\pss\\PaperMaster Live Menu 7.0.lnkStartup"
"location"="Startup"
"command"="C:\\PROGRA~1\\PAPERM~1.0\\J2GDLL~1.EXE /R /K \"C:\\Program Files\\PaperMaster Pro 7.0\\J2GPfcW.dll\",JSPFCWSetHooking,1,0,0,0"
"item"="PaperMaster Live Menu 7.0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^PaperMaster Tray Menu 7.0.lnk]
"path"="C:\\Documents and Settings\\Owner\\Start Menu\\Programs\\Startup\\PaperMaster Tray Menu 7.0.lnk"
"backup"="C:\\WINDOWS\\pss\\PaperMaster Tray Menu 7.0.lnkStartup"
"location"="Startup"
"command"="C:\\PROGRA~1\\PAPERM~1.0\\J2GTray.exe "
"item"="PaperMaster Tray Menu 7.0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="aim"
"hkey"="HKCU"
"command"="C:\\Program Files\\AIM\\aim.exe -cnetwait.odl"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eFax 4.1]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="J2GDllCmd"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\eFax Messenger 4.1\\J2GDllCmd.exe\" /R"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eFax 4.2]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="J2GDllCmd"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\eFax Messenger 4.2\\J2GDllCmd.exe\" /R"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndexSearch]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="IndexSearch"
"hkey"="HKLM"
"command"="C:\\Program Files\\Scansoft\\PaperPort\\IndexSearch.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msmsgs"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msnmsgr"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaperPort 8.0 SE Registration Reminder]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="navLoad"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Scansoft\\PaperPort\\WebEreg\\NAVBrowser.exe\" -r \"C:\\Program Files\\Scansoft\\PaperPort\\WebEreg\\navLoad.ini\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaperPort PTD]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="pptd40nt"
"hkey"="HKLM"
"command"="C:\\Program Files\\Scansoft\\PaperPort\\pptd40nt.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PlaxoUpdate]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PlaxoHelper"
"hkey"="HKCU"
"command"="C:\\Program Files\\Plaxo\\2.11.1.5\\PlaxoHelper.exe -a"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="RealPlay"
"hkey"="HKLM"
"command"="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe SYSTEMBOOTHIDEPLAYER"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SemanticInsight]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SemanticInsight"
"hkey"="HKLM"
"command"="C:\\Program Files\\RXToolBar\\Semantic Insight\\SemanticInsight.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Smart Start UP]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PnPDetect"
"hkey"="HKLM"
"command"="C:\\Program Files\\NewSoft\\Smart Start UP\\PnPDetect.exe /Automation "
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="winampa"
"hkey"="HKLM"
"command"="C:\\Program Files\\Winamp\\winampa.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ypager"
"hkey"="HKCU"
"command"="C:\\Program Files\\Yahoo!\\Messenger\\ypager.exe -quiet"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\control panel\load]
"forwas"=hex:15,26,db,fb,69
"cryptpa"=hex:21,df,db,f4,20
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"system"="C:\\WINDOWS\\csrss.exe"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoActiveDesktop"=dword:00000000
"ForceActiveDesktopOn"=dword:00000000
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoActiveDesktop"=dword:00000000
"ForceActiveDesktopOn"=dword:00000000
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
backup-20061220-134953-230
O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - (no file)
backup-20061220-134953-284
O2 - BHO: (no name) - {08B0A51B-0C50-4B9A-99B5-89AC1E56E533} - C:\WINDOWS\System32\ddcyw.dll (file missing)
backup-20061220-134953-450
O2 - BHO: (no name) - {380739FB-EB33-8E37-C659-02260E8D29C4} - (no file)
backup-20061219-185747-172
O20 - Winlogon Notify: winxtx32 - winxtx32.dll (file missing)
backup-20061219-185746-141
O20 - Winlogon Notify: ssqpm - C:\WINDOWS\System32\ssqpm.dll (file missing)
backup-20061219-185644-800
O4 - HKLM\..\Run: [mxwpic.dll] C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\mxwpic.dll,wealicb
backup-20061219-185644-334
O2 - BHO: (no name) - {755bbd1a-aa59-456c-afeb-b4c42c4dcb6f} - (no file)
backup-20061219-185644-462
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\system32\ysrnkfcd.dll",setvm
backup-20061219-185644-216
O8 - Extra context menu item: &Search -
http://km.bar.need2find.com/KM/menusearch.html?p=KM
backup-20061219-185644-953
O18 - Filter: text/html - (no CLSID) - (no file)
backup-20061219-185644-228
O2 - BHO: (no name) - {3FD6B99C-A275-46ea-8FD1-3D63986E51E4} - C:\WINDOWS\system32\kxjuwbvm.dll
backup-20061219-185644-601
O2 - BHO: (no name) - {8d83b16e-0de1-452b-ac52-96ec0b34aa4b} - (no file)
backup-20061219-185644-511
O2 - BHO: (no name) - {45B70304-6774-6631-26BC-0B328E8CE570} - (no file)
backup-20061219-185644-833
O2 - BHO: (no name) - {11F0EE13-5947-2942-F631-09BEB2706006} - (no file)
backup-20061219-185644-468
O4 - HKLM\..\Run: [IpWins] C:\Program Files\ipwins\ipwins.exe
backup-20061219-185644-542
O2 - BHO: (no name) - {0FC1C4CA-3F9D-4548-AF67-50E10FE9685F} - (no file)
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Symantec NetDetect.job
Completion time: 07-01-12 19:15:37