ok, Kapersky comes back clean.. but i keep getting One Care Reporting a Trojan:Win32/Boaxxe.F which it says it has quarantined. so i guess it's doing it's job.
here are the logs. and thanks for the assitance my pc is already running better.
ComboFix 08-10-07.01 - user 2008-10-07 16:20:39.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.580 [GMT -4:00]
Running from: C:\Documents and Settings\user\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\user\Desktop\CFScript.txt
* Created a new restore point
FILE ::
C:\WINDOWS\system32\drivers\gxjfvznx.sys
c:\windows\system32\wklhbml.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\NetworkService\Application Data\hoqemcwt
C:\Documents and Settings\NetworkService\Application Data\hoqemcwt\profiles.ini
C:\Documents and Settings\NetworkService\Application Data\hoqemcwt\Profiles\qcawaiw7.default\cert8.db
C:\Documents and Settings\NetworkService\Application Data\hoqemcwt\Profiles\qcawaiw7.default\compatibility.ini
C:\Documents and Settings\NetworkService\Application Data\hoqemcwt\Profiles\qcawaiw7.default\cookies.sqlite
C:\Documents and Settings\NetworkService\Application Data\hoqemcwt\Profiles\qcawaiw7.default\formhistory.sqlite
C:\Documents and Settings\NetworkService\Application Data\hoqemcwt\Profiles\qcawaiw7.default\key3.db
C:\Documents and Settings\NetworkService\Application Data\hoqemcwt\Profiles\qcawaiw7.default\localstore.rdf
C:\Documents and Settings\NetworkService\Application Data\hoqemcwt\Profiles\qcawaiw7.default\permissions.sqlite
C:\Documents and Settings\NetworkService\Application Data\hoqemcwt\Profiles\qcawaiw7.default\places.sqlite-journal
C:\Documents and Settings\NetworkService\Application Data\hoqemcwt\Profiles\qcawaiw7.default\places.sqlite
C:\Documents and Settings\NetworkService\Application Data\hoqemcwt\Profiles\qcawaiw7.default\pluginreg.dat
C:\Documents and Settings\NetworkService\Application Data\hoqemcwt\Profiles\qcawaiw7.default\prefs.js
C:\Documents and Settings\NetworkService\Application Data\hoqemcwt\Profiles\qcawaiw7.default\secmod.db
C:\Documents and Settings\NetworkService\Application Data\hoqemcwt\Profiles\qcawaiw7.default\xpti.dat
C:\Documents and Settings\user\Application Data\hoqemcwt
C:\Documents and Settings\user\Application Data\hoqemcwt\profiles.ini
C:\Documents and Settings\user\Application Data\hoqemcwt\Profiles\iy3waybg.default\cert8.db
C:\Documents and Settings\user\Application Data\hoqemcwt\Profiles\iy3waybg.default\compatibility.ini
C:\Documents and Settings\user\Application Data\hoqemcwt\Profiles\iy3waybg.default\cookies.sqlite
C:\Documents and Settings\user\Application Data\hoqemcwt\Profiles\iy3waybg.default\formhistory.sqlite
C:\Documents and Settings\user\Application Data\hoqemcwt\Profiles\iy3waybg.default\key3.db
C:\Documents and Settings\user\Application Data\hoqemcwt\Profiles\iy3waybg.default\localstore.rdf
C:\Documents and Settings\user\Application Data\hoqemcwt\Profiles\iy3waybg.default\permissions.sqlite
C:\Documents and Settings\user\Application Data\hoqemcwt\Profiles\iy3waybg.default\places.sqlite-journal
C:\Documents and Settings\user\Application Data\hoqemcwt\Profiles\iy3waybg.default\places.sqlite
C:\Documents and Settings\user\Application Data\hoqemcwt\Profiles\iy3waybg.default\pluginreg.dat
C:\Documents and Settings\user\Application Data\hoqemcwt\Profiles\iy3waybg.default\prefs.js
C:\Documents and Settings\user\Application Data\hoqemcwt\Profiles\iy3waybg.default\secmod.db
C:\Documents and Settings\user\Application Data\hoqemcwt\Profiles\iy3waybg.default\xpti.dat
C:\VundoFix Backups
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_GXJFVZNX
-------\Service_gxjfvznx
((((((((((((((((((((((((( Files Created from 2008-09-07 to 2008-10-07 )))))))))))))))))))))))))))))))
.
2008-10-06 03:47 . 2008-10-06 03:50 <DIR> d-------- C:\Program Files\EsetOnlineScanner
2008-10-06 03:37 . 2004-08-04 15:00 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-10-06 02:16 . 2008-10-06 02:16 <DIR> d-------- C:\WINDOWS\Sun
2008-10-06 02:15 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-10-06 02:14 . 2008-10-06 02:15 <DIR> d-------- C:\Program Files\Java
2008-10-06 02:09 . 2008-10-06 02:09 <DIR> d-------- C:\Program Files\Common Files\Java
2008-10-01 02:23 . 2008-10-01 02:25 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-10-01 02:23 . 2008-10-02 01:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-01 02:10 . 2008-10-01 02:10 <DIR> d-------- C:\Program Files\Trend Micro
2008-10-01 01:53 . 2008-05-15 16:15 53,168 --a------ C:\WINDOWS\system32\drivers\MpFilter.sys
2008-09-28 06:26 . 2008-06-13 09:10 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-09-28 06:26 . 2008-06-13 09:10 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-09-25 06:39 . 2008-09-25 06:53 <DIR> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-09-25 06:31 . 2008-07-18 22:07 270,880 --a------ C:\WINDOWS\system32\mucltui.dll
2008-09-25 06:31 . 2008-07-18 22:07 210,976 --a------ C:\WINDOWS\system32\muweb.dll
2008-09-25 06:31 . 2008-07-18 22:07 29,728 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-09-24 22:38 . 2008-09-24 22:38 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-09-24 22:38 . 2008-09-24 22:38 <DIR> d-------- C:\WINDOWS\system32\en
2008-09-24 22:38 . 2008-09-24 23:18 <DIR> d-------- C:\WINDOWS\l2schemas
2008-09-24 22:26 . 2004-08-04 15:00 4,190,352 --a------ C:\WINDOWS\system32\dllcache\luna.mst
2008-09-24 22:25 . 2004-08-04 15:00 8,384,000 --a------ C:\WINDOWS\system32\dllcache\shell32.dll
2008-09-24 22:23 . 2008-09-24 22:23 <DIR> d-------- C:\WINDOWS\EHome
2008-09-24 14:33 . 2008-09-24 14:53 <DIR> d-------- C:\849d1e27f66e491376849f9f07
2008-09-24 14:23 . 2008-09-24 14:23 2,888 --a------ C:\WINDOWS\system32\OEMINFO.PNF
2008-09-24 13:52 . 2004-08-27 12:54 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS
2008-09-24 13:52 . 2008-10-04 04:00 <DIR> d-------- C:\Documents and Settings\Administrator
2008-09-24 11:45 . 2007-08-13 18:45 78,336 --a------ C:\WINDOWS\system32\ieencode.dll
2008-09-24 11:28 . 2007-11-27 22:56 116,416 --a------ C:\WINDOWS\system32\drivers\msfwhlpr.sys
2008-09-24 11:28 . 2007-11-27 22:56 91,328 --a------ C:\WINDOWS\system32\drivers\msfwdrv.sys
2008-09-24 11:27 . 2008-10-01 01:53 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-09-24 11:27 . 2008-09-24 23:20 <DIR> d-------- C:\WINDOWS\system32\bits
2008-09-24 11:27 . 2007-03-29 08:56 7,168 --a------ C:\WINDOWS\system32\bitsprx4.dll
2008-09-24 11:26 . 2008-10-04 03:01 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-09-24 11:16 . 2008-10-06 23:40 <DIR> d-------- C:\Program Files\Microsoft Windows OneCare Live
2008-09-19 05:47 . 2008-09-19 05:47 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-09-19 05:46 . 2008-09-24 11:40 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-09-19 05:46 . 2008-09-19 05:46 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-09-19 05:43 . 2008-09-19 05:43 <DIR> d-------- C:\Program Files\Netflix
2008-09-11 12:46 . 2008-09-11 12:46 376 --a------ C:\WINDOWS\ODBC.INI
2008-09-11 12:32 . 2008-09-11 12:32 <DIR> d-------- C:\WINDOWS\ShellNew
2008-09-11 12:30 . 2008-09-11 12:30 <DIR> d-------- C:\Documents and Settings\user\Application Data\Microsoft Web Folders
2008-09-11 12:28 . 2004-11-11 07:50 2,433,024 --------- C:\WINDOWS\UNNMP.exe
2008-09-11 12:28 . 2004-12-13 11:20 52,521 --------- C:\WINDOWS\UNNMP.cfg
2008-09-11 12:26 . 2008-09-11 12:28 <DIR> d-------- C:\Program Files\Common Files\Ahead
2008-09-11 12:26 . 2008-09-11 12:28 <DIR> d-------- C:\Program Files\Ahead
2008-09-11 12:26 . 2004-07-20 16:24 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll
2008-09-11 12:26 . 2004-07-20 16:24 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll
2008-09-11 12:26 . 2004-07-20 16:24 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll
2008-09-11 12:26 . 2004-07-09 08:43 364,544 --------- C:\WINDOWS\system32\TwnLib4.dll
2008-09-11 12:26 . 2004-07-20 16:24 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll
2008-09-11 12:26 . 2001-07-09 10:50 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
2008-09-11 12:26 . 2000-06-26 10:45 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll
2008-09-11 12:26 . 2001-06-26 07:15 38,912 --------- C:\WINDOWS\system32\picn20.dll
2008-09-11 12:18 . 2008-09-11 12:18 <DIR> d-------- C:\Program Files\CyberLink
2008-09-11 12:18 . 2008-09-11 12:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\CyberLink
2008-09-11 12:09 . 2008-09-11 12:09 <DIR> d-------- C:\WINDOWS\tiinst
2008-09-10 18:20 . 2008-09-10 18:20 <DIR> d-------- C:\Program Files\VIA
2008-09-10 18:20 . 2005-04-13 16:54 331,184 --------- C:\WINDOWS\system32\difxapi.dll
2008-09-10 18:20 . 2006-10-09 12:58 203,648 -ra------ C:\WINDOWS\system32\drivers\vinyl97.sys
2008-09-10 18:09 . 2008-09-10 18:09 <DIR> d-------- C:\Documents and Settings\user\Application Data\AdobeUM
2008-09-10 18:08 . 2008-09-10 18:08 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-09-10 12:58 . 2003-05-01 13:22 259,977 --a------ C:\WINDOWS\system32\drivers\em202f.cty
2008-09-10 12:58 . 2003-05-01 14:40 165,504 --a------ C:\WINDOWS\system32\drivers\HSFHWICH.sys
2008-09-10 12:58 . 2003-05-01 14:42 30,592 --a------ C:\WINDOWS\system32\drivers\strmdisp.sys
2008-09-10 12:58 . 2003-04-14 18:53 27,765 --a------ C:\WINDOWS\system32\HSFCI006.dll
2008-09-10 12:54 . 2008-06-12 11:27 26,144 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-09-10 12:51 . 2003-05-01 14:37 1,107,200 --a------ C:\WINDOWS\system32\drivers\HSF_DP.sys
2008-09-10 12:51 . 2003-05-01 14:38 622,848 --a------ C:\WINDOWS\system32\drivers\HSF_CNXT.sys
2008-09-10 12:51 . 2002-12-11 07:49 69,632 --a------ C:\WINDOWS\system32\mdmxsdk.dll
2008-09-10 12:51 . 2002-12-11 09:22 11,044 --a------ C:\WINDOWS\system32\drivers\mdmxsdk.sys
2008-09-10 12:46 . 2008-09-10 12:46 <DIR> d-------- C:\Program Files\CONEXANT
2008-09-10 12:46 . 2001-08-17 12:20 96,256 --a------ C:\WINDOWS\system32\drivers\ac97intc.sys
2008-09-10 12:46 . 2001-08-17 12:20 96,256 --a--c--- C:\WINDOWS\system32\dllcache\ac97intc.sys
2008-09-10 12:45 . 2004-08-04 00:56 130,048 --a------ C:\WINDOWS\system32\ksproxy.ax
2008-09-10 12:45 . 2004-08-04 00:56 4,096 --a------ C:\WINDOWS\system32\ksuser.dll
2008-09-10 12:44 . 2001-08-17 13:28 802,683 --a------ C:\WINDOWS\system32\drivers\LTSM.sys
2008-09-10 12:44 . 2001-08-17 13:28 802,683 --a--c--- C:\WINDOWS\system32\dllcache\ltsm.sys
2008-09-10 11:03 . 2008-09-10 11:03 <DIR> d-------- C:\BCM_REL_4_100_15_5_WHQL
2008-09-10 10:44 . 2008-09-10 10:44 <DIR> d-------- C:\Program Files\Synaptics
2008-09-10 10:44 . 2004-10-08 14:33 185,824 --a------ C:\WINDOWS\system32\drivers\SynTP.sys
2008-09-10 10:44 . 2004-10-08 14:36 114,688 --a------ C:\WINDOWS\system32\SynCtrl.dll
2008-09-10 10:44 . 2004-10-08 14:36 90,202 --a------ C:\WINDOWS\system32\SynTPAPI.dll
2008-09-10 10:44 . 2004-10-08 14:46 81,920 --a------ C:\WINDOWS\system32\SynTPCo2.dll
2008-09-10 10:44 . 2004-10-08 14:35 77,917 --a------ C:\WINDOWS\system32\SynCOM.dll
2008-09-10 10:44 . 2004-10-08 14:44 69,722 --a------ C:\WINDOWS\system32\SynTPFcs.dll
2008-09-10 10:42 . 2008-09-10 10:42 <DIR> d-------- C:\Program Files\Intel
2008-09-10 10:42 . 2008-09-11 12:18 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-09-10 10:41 . 2008-09-10 18:20 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2008-09-10 10:39 . 2004-08-20 15:50 159,744 --a------ C:\WINDOWS\system32\igfxres.dll
2008-09-10 10:32 . 2008-09-11 11:49 <DIR> d-------- C:\cabs
2008-09-10 10:05 . 2008-09-10 10:07 <DIR> d-------- C:\Drivers
2008-09-09 14:09 . 2001-08-17 12:11 20,160 --a------ C:\WINDOWS\system32\drivers\ADM8511.SYS
2008-09-09 14:09 . 2001-08-17 12:11 20,160 --a--c--- C:\WINDOWS\system32\dllcache\adm8511.sys
2008-09-09 14:00 . 2004-08-27 12:54 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\WINDOWS
2008-09-09 14:00 . 2008-09-09 14:00 <DIR> d-------- C:\SYSPREP
2008-09-09 14:00 . 2004-08-27 12:54 <DIR> d-------- C:\Documents and Settings\user\WINDOWS
2008-09-09 14:00 . 2008-10-06 03:22 <DIR> d-------- C:\Documents and Settings\user
2008-09-09 14:00 . 2004-08-27 12:54 <DIR> d-------- C:\Documents and Settings\Default User\WINDOWS
2008-09-09 13:56 . 2008-09-09 13:56 8,192 --a------ C:\WINDOWS\REGLOCS.OLD
2008-09-09 13:54 . 2008-09-09 13:54 333 --a------ C:\WINDOWS\system32\$ncsp$.inf
2008-09-09 13:53 . 2001-08-17 16:48 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2008-09-09 13:52 . 2004-08-04 03:56 7,168 --a------ C:\WINDOWS\system32\hccoin.dll
2008-09-09 13:52 . 2001-08-17 16:46 6,400 --a------ C:\WINDOWS\system32\drivers\enum1394.sys
2008-09-09 13:28 . 2004-08-03 20:56 359,936 --a------ C:\WINDOWS\system32\wzcsvc.dll
2008-09-09 13:28 . 2004-08-03 20:56 51,712 --a------ C:\WINDOWS\system32\wzcsapi.dll
2008-09-09 13:28 . 2004-08-04 00:56 23,552 --a------ C:\WINDOWS\system32\wdmaud.drv
2008-09-09 13:28 . 2001-08-17 18:36 13,824 --a------ C:\WINDOWS\system32\wowfaxui.dll
2008-09-09 13:28 . 2001-08-17 18:36 3,200 --a------ C:\WINDOWS\system32\wowfax.dll
2008-09-09 13:28 . 2008-09-09 13:28 60 --a------ C:\WINDOWS\system32\SYSDRV.DAT
2008-09-09 13:26 . 2004-08-03 20:56 4,274,816 --a------ C:\WINDOWS\system32\nv4_disp.dll
2008-09-09 13:25 . 2004-08-03 18:29 1,897,408 --a------ C:\WINDOWS\system32\drivers\nv4_mini.sys
2008-09-09 13:24 . 2001-08-17 10:02 262,528 --a------ C:\WINDOWS\system32\drivers\cinemst2.sys
2008-09-09 13:24 . 2004-08-03 20:56 52,224 --a------ C:\WINDOWS\system32\dmutil.dll
2008-09-09 13:24 . 2001-08-17 09:49 19,968 --a------ C:\WINDOWS\system32\drivers\mxnic.sys
2008-09-09 13:24 . 2001-08-17 09:52 18,688 --a------ C:\WINDOWS\system32\drivers\cdaudio.sys
2008-09-09 13:24 . 2001-08-17 09:57 12,160 --a------ C:\WINDOWS\system32\drivers\fsvga.sys
2008-09-09 13:24 . 2001-08-17 09:24 12,032 --a------ C:\WINDOWS\system32\drivers\nikedrv.sys
2008-09-09 13:24 . 2001-08-17 09:24 11,776 --a------ C:\WINDOWS\system32\drivers\cpqdap01.sys
2008-09-09 13:24 . 2001-08-17 09:59 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys
2008-09-09 13:23 . 2008-09-09 13:23 <DIR> d-------- C:\WINDOWS\SMINST
2008-09-09 13:23 . 2004-08-03 20:56 47,104 --a------ C:\WINDOWS\system32\cnbjmon.dll
2008-09-09 13:22 . 2004-08-04 15:00 <DIR> d-------- C:\Program Files\Common Files\Mozilla Shared
2008-09-09 13:21 . 2004-08-04 15:00 4,399,505 --a--c--- C:\WINDOWS\system32\dllcache\nls302en.lex
2008-09-09 13:20 . 2004-08-04 15:00 3,440,660 --a------ C:\WINDOWS\system32\drivers\gm.dls
2008-09-09 13:19 . 2008-09-09 13:54 <DIR> d-------- C:\WINDOWS\I386
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-11 16:30 --------- d-----w C:\Program Files\microsoft frontpage
2008-09-10 14:46 17,801 ----a-w C:\WINDOWS\system32\drivers\AegisP.sys
.
((((((((((((((((((((((((((((( snapshot@2008-10-07_ 1.45.15.50 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-10-07 20:25:49 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_d0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY" [X]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\OneCareMP]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R2 OcHealthMon;Windows Live OneCare Health Monitor;C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe [2008-08-08 28200]
S3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter;C:\WINDOWS\system32\DRIVERS\ADM8511.SYS [2001-08-17 20160]
S3 LucentSoftModem;Lucent Technologies Soft Modem;C:\WINDOWS\system32\DRIVERS\LTSM.sys [2001-08-17 802683]
*Newly Created Service* - GXJFVZNX
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-10-07 16:25:10
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\WINDOWS\system32\WLTRYSVC.EXE
C:\WINDOWS\system32\BCMWLTRY.EXE
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\WINDOWS\system32\WLTRAY.EXE
.
**************************************************************************
.
Completion time: 2008-10-07 16:29:12 - machine was rebooted [user]
ComboFix-quarantined-files.txt 2008-10-07 20:29:06
ComboFix2.txt 2008-10-07 13:11:52
ComboFix3.txt 2008-10-07 05:46:03
Pre-Run: 112,711,618,560 bytes free
Post-Run: 112,735,563,776 bytes free
233 --- E O F --- 2008-10-06 22:04:19
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:48:52 PM, on 10/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) -
http://www.eset.eu/OnlineScanner.cab
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
--
End of file - 2588 bytes