Here are the resulting logs:
ComboFix 09-02-06.04 - Mike 2009-02-07 14:22:33.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3070.2522 [GMT -5:00]
Running from: c:\documents and settings\Mike\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\IE4 Error Log.txt
c:\windows\system32\bguwsxgi.dll
c:\windows\system32\bxrlcjwq.dll
c:\windows\system32\dkwkehdm.dll
c:\windows\system32\fdchgqmy.dll
c:\windows\system32\fiydtoyf.dll
c:\windows\system32\iurfwrmd.dll
c:\windows\system32\lmgvpqdf.dll
c:\windows\system32\mrsvbduh.dll
c:\windows\system32\qoMffGxV.dll
c:\windows\system32\qoMgdbBU.dll.vir
c:\windows\system32\rlxaapjj.dll
c:\windows\system32\vuedwhfu.dll
c:\windows\system32\VxGffMoq.ini
c:\windows\system32\VxGffMoq.ini2
c:\windows\system32\wpv931233435211.cpx
c:\windows\system32\yewbfn.dll
c:\windows\wiaserviv.log
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
((((((((((((((((((((((((( Files Created from 2009-01-07 to 2009-02-07 )))))))))))))))))))))))))))))))
.
2009-02-05 18:39 . 2009-02-05 18:39 54,156 --ah----- c:\windows\QTFont.qfn
2009-02-05 18:39 . 2009-02-05 18:39 1,409 --a------ c:\windows\QTFont.for
2009-02-02 20:22 . 2009-02-02 20:22 <DIR> d-------- c:\program files\Trend Micro
2009-02-02 20:20 . 2009-02-02 20:20 <DIR> d-------- c:\program files\ERUNT
2009-02-01 23:08 . 2009-02-02 01:24 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2009-02-01 23:08 . 2009-02-02 09:18 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-01 22:32 . 2009-02-01 22:32 <DIR> d-------- C:\VundoFix Backups
2009-02-01 19:56 . 2009-02-07 14:00 <DIR> d-------- C:\quarantine
2009-01-23 15:58 . 2009-01-23 16:01 <DIR> d-------- c:\windows\NV27803580.TMP
2009-01-15 08:19 . 2009-01-15 08:19 1,253,376 --a------ c:\windows\system32\NvPVEnc.ax
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-04 02:12 --------- d-----w c:\documents and settings\Mike\Application Data\OpenOffice.org2
2009-02-02 14:58 --------- d-----w c:\program files\Java
2009-02-02 02:09 --------- d-----w c:\program files\533soft Icon Changer
2009-01-30 08:50 --------- d-----w c:\program files\GStudio7
2009-01-25 16:20 --------- d-----w c:\program files\Google
2009-01-24 21:57 --------- d-----w c:\program files\Microsoft Visual Studio 8
2009-01-24 21:56 --------- d-----w c:\documents and settings\All Users\Application Data\PreEmptive Solutions
2009-01-24 21:50 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-01-23 21:00 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-01-23 20:59 --------- d-----w c:\program files\AGEIA Technologies
2009-01-23 00:43 --------- d-----w c:\documents and settings\Mike\Application Data\IGN_DLM
2009-01-22 06:20 --------- d-----w c:\program files\Steam
2009-01-22 06:13 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-22 06:12 --------- d-----w c:\program files\Soulseek-Test
2009-01-22 06:12 --------- d-----w c:\program files\Soulseek
2009-01-19 23:32 --------- d-----w c:\program files\Texture Maker
2009-01-15 13:19 6,301,248 ----a-w c:\windows\system32\drivers\nv4_mini.sys
2009-01-10 19:38 --------- d-----w c:\documents and settings\Mike\Application Data\Xfire
2009-01-07 23:53 --------- d-s---w c:\program files\Xfire
2009-01-01 22:57 --------- d-----w c:\program files\Electronic Arts
2008-12-17 00:43 --------- d-----w c:\documents and settings\Mike\Application Data\.purple
2008-12-14 02:23 --------- d-----w c:\program files\MySQL
2008-12-14 02:23 --------- d-----w c:\documents and settings\All Users\Application Data\MySQL
2008-12-11 10:57 333,952 ----a-w c:\windows\system32\drivers\srv.sys
2008-12-11 03:40 --------- d-----w c:\documents and settings\Mike\Application Data\Move Networks
2007-11-09 16:52 22,328 ----a-w c:\documents and settings\Mike\Application Data\PnkBstrK.sys
2003-07-16 20:48 94,784 --sh--w c:\windows\twain.dll
2008-04-14 00:12 50,688 --sh--w c:\windows\twain_32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SB Audigy 2 Startup Menu"="/L:ENG" [X]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-17 68856]
"igndlm.exe"="c:\program files\IGN\Download Manager\DLM.exe" [2008-08-01 1103216]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-05-28 335872]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"CTSysVol"="c:\program files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe" [2002-10-29 49152]
"CTDVDDet"="c:\program files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE" [2002-09-30 45056]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-11 53248]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2006-06-21 35328]
"ShStatEXE"="c:\program files\Network Associates\VirusScan\SHSTAT.EXE" [2004-09-22 94208]
"McAfeeUpdaterUI"="c:\program files\Network Associates\Common Framework\UpdaterUI.exe" [2005-12-07 131072]
"Network Associates Error Reporting Service"="c:\program files\Common Files\Network Associates\TalkBack\TBMon.exe" [2003-10-07 147514]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-01-15 13680640]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-12-11 286720]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-01-15 86016]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"CTHelper"="CTHELPER.EXE" [2003-02-20 c:\windows\system32\CTHELPER.EXE]
"AsioReg"="CTASIO.DLL" [2003-02-20 c:\windows\system32\CTASIO.DLL]
"nwiz"="nwiz.exe" [2009-01-15 c:\windows\system32\nwiz.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Device Detector 3.lnk - c:\program files\Olympus\DeviceDetector\DevDtct2.exe [2007-07-31 118784]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=yewbfn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Cisco Systems Gatorlink VPN Client.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Cisco Systems Gatorlink VPN Client.lnk
backup=c:\windows\pss\Cisco Systems Gatorlink VPN Client.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Mike^Start Menu^Programs^Startup^Psi.lnk]
path=c:\documents and settings\Mike\Start Menu\Programs\Startup\Psi.lnk
backup=c:\windows\pss\Psi.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Mike^Start Menu^Programs^Startup^Xfire.lnk]
path=c:\documents and settings\Mike\Start Menu\Programs\Startup\Xfire.lnk
backup=c:\windows\pss\Xfire.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CXMon]
--a------ 2002-03-08 11:00 45056 c:\program files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_monitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
--a------ 2001-11-02 11:25 196608 c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igndlm.exe]
--a------ 2008-08-01 12:36 1103216 c:\program files\IGN\Download Manager\DLM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ImpulseFastStart]
--a------ 2008-12-15 15:20 1779056 c:\program files\Stardock\Impulse\Impulse.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2007-11-15 13:11 267048 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
--a------ 2006-01-17 12:03 53248 c:\program files\Musicmatch\Musicmatch Jukebox\mmtask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2008-04-13 19:12 1695232 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\openvpn-gui]
--a------ 2007-05-10 16:49 98816 c:\program files\OpenVPN\bin\openvpn-gui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-12-11 10:56 286720 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2008-11-12 00:41 1410296 c:\program files\Steam\steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-06-17 18:29 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\Program Files\\Starcraft\\starcraft.exe"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\Network Associates\\Common Framework\\FrameworkService.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Psi\\psi.exe"=
"c:\\Savage\\savage.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Program Files\\Abacast\\Abaclient.exe"=
"c:\\Documents and Settings\\Mike\\Desktop\\gamestudio stuff\\multiplayer tutorial 2\\LocoweedsMPTut\\BiosphereIV.cd\\multiplayer.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\GStudio6\\acknex.exe"=
"c:\\Program Files\\GStudio6\\MultiplayerLearning\\multiplayer.cd\\multiplayer.exe"=
"c:\\Program Files\\GStudio6\\Tanx\\Tanx.cd\\Tanx.exe"=
"c:\\Program Files\\Microsoft Games\\Freelancer\\EXE\\Freelancer.exe"=
"c:\\Program Files\\Microsoft Games\\Freelancer\\EXE\\flserver.exe"=
"c:\\Documents and Settings\\Mike\\Desktop\\EclipseForC\\eclipse\\eclipse.exe"=
"c:\\Documents and Settings\\Mike\\Desktop\\EclipseForJava\\eclipse\\eclipse.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Sony\\Station\\LaunchPad\\LaunchPad.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Steam\\steamapps\\tfuzelek\\team fortress 2\\hl2.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Documents and Settings\\Mike\\Desktop\\ZSNES NET\\zsnesw.exe"=
"c:\\Program Files\\GStudio7\\acknex.exe"=
"c:\\Program Files\\GStudio6\\Kingdoms\\KingdomsCD\\Kingdoms.exe"=
"c:\\Program Files\\Steam\\steam.exe"=
"c:\\Program Files\\SecondLife\\SLVoice.exe"=
"c:\\Program Files\\ICQ6\\ICQ.exe"=
"c:\\Documents and Settings\\Mike\\Desktop\\ZSNES NET\\zsnesw142n\\zsnesw.exe"=
"c:\\Program Files\\Kingdoms\\Kingdoms.cd\\Kingdoms.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\EditPlus 3\\editplus.exe"=
"c:\\Program Files\\GStudio7\\PowerGridExec\\PowerGridExec.cd\\PowerGrid.cd\\POWERGRID.exe"=
"c:\\Program Files\\EA Games\\Red Alert 3 Beta\\RetailExe\\1.2\\ra3game.dat"=
"c:\\Program Files\\PowerGrid\\PowerGrid.cd\\POWERGRID.exe"=
"c:\\Program Files\\EA Games\\Red Alert 3 Beta\\RetailExe\\1.3\\ra3game.dat"=
"c:\\Program Files\\GStudio7\\PowerPlayExec\\PowerPlay.cd\\PowerPlay.exe"=
"c:\\Program Files\\Stardock Games\\Sins of a Solar Empire\\Sins of a Solar Empire.exe"=
"c:\\Savage\\silverback.exe"=
R1 hwinterface;hwinterface;c:\windows\system32\drivers\hwinterface.sys [2007-01-02 3026]
R1 NaiAvTdi1;NaiAvTdi1;c:\windows\system32\drivers\mvstdi5x.sys [2006-09-04 58464]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-10-27 24652]
R3 tap0801;TAP-Win32 Adapter V8;c:\windows\system32\drivers\tap0801.sys [2007-05-10 23552]
S3 m4301a;Linksys Wireless-B USB Network Adapter v4.0 Driver;c:\windows\system32\drivers\m4301A.sys [2006-12-23 116192]
S3 MA763010;M-Audio Fast Track;c:\windows\system32\drivers\MA763010.sys [2006-08-13 30848]
S3 PciCon;PciCon;\??\e:\pcicon.sys --> e:\PciCon.sys [?]
S3 XDva037;XDva037;\??\c:\windows\system32\XDva037.sys --> c:\windows\system32\XDva037.sys [?]
.
- - - - ORPHANS REMOVED - - - -
BHO-{454543FE-3F53-470B-89A9-47031D8E6E3D} - c:\windows\system32\qoMffGxV.dll
BHO-{4A17504D-1604-4A1C-A68C-6BDDE4B07F00} - (no file)
BHO-{ca4780e6-49df-4c43-ae2c-cd872de969f4} - c:\windows\system32\yewbfn.dll
MSConfigStartUp-80b381e9 - c:\windows\system32\hlrebjki.dll
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
FF - ProfilePath - c:\documents and settings\Mike\Application Data\Mozilla\Firefox\Profiles\2nztjuep.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\documents and settings\Mike\Application Data\Mozilla\Firefox\Profiles\2nztjuep.default\extensions\{3b56bcc7-54e5-44a2-9b44-66c3ef58c13e}\components\nstidy.dll
FF - plugin: c:\documents and settings\Mike\Application Data\Mozilla\Firefox\Profiles\2nztjuep.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll
FF - plugin: c:\program files\IGN\Download Manager\npfpdlm.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmusicn.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-02-07 14:33:36
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1606980848-287218729-725345543-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:9f,32,66,3b,02,ec,b3,c6,64,94,0a,9b,c5,15,1d,a0,33,c5,b9,d9,c9,c7,58,
1f,08,b1,20,b5,48,2f,97,f3,35,47,9b,46,eb,99,1c,e9,bd,1b,0f,5e,66,2e,76,66,\
"??"=hex:85,0f,20,92,37,87,4a,97,e0,a8,d6,6e,34,66,b4,d1
[HKEY_USERS\S-1-5-21-1606980848-287218729-725345543-1004\Software\SecuROM\License information*]
"datasecu"=hex:40,58,d2,74,97,df,5b,00,35,fd,48,32,c9,c9,5e,c0,97,98,bd,71,4f,
24,c9,af,04,df,ad,06,60,6e,77,ea,8a,cf,91,37,75,f3,09,be,36,35,18,4a,74,7b,\
"rkeysecu"=hex:fc,58,68,c1,4c,58,de,40,6c,5f,d2,84,7c,e0,7f,31
[HKEY_USERS\S-1-5-21-1606980848-287218729-725345543-1004_Classes\CLSID\{F98D1881-94B3-4204-9E1B-7CE01A6DFD33}\InprocServer32]
@Denied: (A 4) (Everyone)
[HKEY_USERS\S-1-5-21-1606980848-287218729-725345543-1004_Classes\CLSID\{F98D1881-94B3-4204-9E1B-7CE01A6DFD33}\InprocServer32\Misc]
"0"=hex:ed,d0,7a,d5,81,3e,6f,44,b3,e3,a8,52,ed,b9,89,64,5f,68,28,15,67,ea,00,
df,5b,42,18,36,40,a5,67,ef,c6,b5,fb,9e,15,b4,69,2b,f6,c6,e0,16,c0,59,95,b8,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(1416)
c:\windows\system32\EntApi.dll
c:\windows\system32\WININET.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\system32\CTSVCCDA.EXE
c:\program files\Cisco Systems\VPN Client\cvpnd.exe
c:\program files\M-Audio Fast Track\GBInst.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Network Associates\Common Framework\FrameworkService.exe
c:\program files\Network Associates\VirusScan\Mcshield.exe
c:\program files\Network Associates\Common Framework\naPrdMgr.exe
c:\program files\Network Associates\VirusScan\VsTskMgr.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\nexon\Mabinogi\npkcmsvc.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Analog Devices\SoundMAX\spkrmon.exe
c:\windows\system32\MsPMSPSv.exe
c:\windows\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2009-02-07 14:43:53 - machine was rebooted [Mike]
ComboFix-quarantined-files.txt 2009-02-07 19:42:33
Pre-Run: 26,048,888,832 bytes free
Post-Run: 30,503,120,896 bytes free
269 --- E O F --- 2009-01-15 05:38:03
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:45:12 PM, on 2/7/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\M-Audio Fast Track\GBInst.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Nexon\Mabinogi\npkcmsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\Program Files\QuickTime\QTTask.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SB Audigy 2 Startup Menu] /L:ENG
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\IGN\Download Manager\DLM.exe /windowsstart /startifwork
O4 - Global Startup: Device Detector 3.lnk = C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) -
http://www.creative.com/su/ocx/15015/CTSUEng.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) -
http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) -
http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} -
http://download.abacast.com/download/files/abasetup163.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) -
http://www.creative.com/su/ocx/15023/CTPID.cab
O20 - AppInit_DLLs: yewbfn.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Fast Track Installer (FastTrackInstallerService) - Nemesis - C:\Program Files\M-Audio Fast Track\GBInst.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Nexon\Mabinogi\npkcmsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:\Program Files\OpenVPN\bin\openvpnserv.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 9287 bytes
Abacast Client
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Flash Player 9 ActiveX
Adobe Reader 7.0.8
AIM 6
Amazing Slow Downer (remove only)
Amazon MP3 Downloader 1.0.3
AnalogX Vocal Remover (WinAmp)
AOL Instant Messenger (SM)
Apple Mobile Device Support
Apple Software Update
Aspell English Dictionary-0.50-2
ATI - Software Uninstall Utility
ATI Control Panel
ATI Display Driver
Audacity 1.3.0
BattleForge™
Broadcom Advanced Control Suite 2
Broadcom Gigabit Integrated Controller
Brother HL-2070N
Clip2Speech
Creative MediaSource
Crystal Reports Basic for Visual Studio 2008
Dell ResourceCD
DivX Codec
DivX Content Uploader
DivX Converter
DivX Player
DivX Web Player
DSound GT Player Express
easy Particle 3
EditPlus 3
ERUNT 1.1j
Fast Track
FileZilla Client 3.0.8.1
FontCreator 5.6
FontGenerator Version 1.10
Fraps (remove only)
Freelancer
Galactic Civilizations II
GameStudio / A6
Gamestudio A7
GanttProject
Garmin c320 City Navigator North America NT v8
Garmin MapSource
Gleim's EA Test Prep 2008 2008
GNU Aspell 0.50-3
Google Toolbar for Internet Explorer
GTK+ Runtime 2.12.8 rev a (remove only)
Guitar Pro 5.2
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
hp deskjet 825c series
hp deskjet 825c series (Remove only)
HP Photo Imaging Software
IcoFX 1.5.01
ICQ6
IGN Download Manager 2.2.1
ImageMagick 6.4.3-10 Q16 (2008-10-01)
Impulse
Impulse
Install Creator
iTunes
Jasc Paint Shop Pro 8
Java 2 Runtime Environment, SE v1.4.2_15
Java 2 SDK, SE v1.4.2_15
Java DB 10.2.2.0
Java(TM) 6 Update 11
Java(TM) 6 Update 2
Java(TM) 6 Update 3
Java(TM) 6 Update 5
Java(TM) 6 Update 7
Java(TM) SE Development Kit 6 Update 3
Java(TM) SE Runtime Environment 6 Update 1
LADSPA_plugins-win-0.4.15
libsecondlife 0.5.0
Lite-C
MATLAB Student 7.0
McAfee VirusScan Enterprise
Memorex Solid State Digital Audio Player
Merchants Guide to the Universe v1.50
Mercurial snapshot
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft .NET Framework 3.0 Service Pack 1
Microsoft .NET Framework 3.5
Microsoft .NET Framework 3.5
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Device Emulator version 3.0 - ENU
Microsoft DirectX SDK (November 2007)
Microsoft Document Explorer 2005
Microsoft Document Explorer 2005
Microsoft Document Explorer 2008
Microsoft Document Explorer 2008
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office PowerPoint Viewer 2003
Microsoft Office Project Professional 2003
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Visual Web Developer 2007
Microsoft Office Visual Web Developer MUI (English) 2007
Microsoft Office Word Viewer 2003
Microsoft Platform SDK (3790.1830)
Microsoft SQL Server 2005
Microsoft SQL Server 2005 Express Edition (SQLEXPRESS)
Microsoft SQL Server 2005 Mobile [ENU] Developer Tools
Microsoft SQL Server 2005 Tools Express Edition
Microsoft SQL Server Compact 3.5 Design Tools ENU
Microsoft SQL Server Compact 3.5 ENU
Microsoft SQL Server Compact 3.5 for Devices ENU
Microsoft SQL Server Database Publishing Wizard 1.2
Microsoft SQL Server Native Client
Microsoft SQL Server Setup Support Files (English)
Microsoft SQL Server VSS Writer
Microsoft Text-to-Speech Engine 4.0 (English)
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Express Edition - ENU
Microsoft Visual C++ 2005 Express Edition - ENU
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual J# 2.0 Redistributable Package
Microsoft Visual Studio 2005 Tools for Office Runtime
Microsoft Visual Studio 2008 Professional Edition - ENU
Microsoft Visual Studio Web Authoring Component
Microsoft Windows SDK for Visual Studio 2008 .NET Framework Tools
Microsoft Windows SDK for Visual Studio 2008 Headers and Libraries
Microsoft Windows SDK for Visual Studio 2008 SDK Reference Assemblies and IntelliSense
Microsoft Windows SDK for Visual Studio 2008 Tools
Microsoft Windows SDK for Visual Studio 2008 Win32 Tools
MilkShape 3D 1.7.9
mIRC
MoleBox 2 (2981)
Mozilla Firefox (3.0.6)
Mozilla Thunderbird (2.0.0.17)
MSDN Library for Visual Studio 2008 - ENU
MSDN Library for Visual Studio 2008 - ENU
MSM2MSI_gstudio
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB954430)
MSXML 6 Service Pack 2 (KB954459)
Musicmatch® Jukebox
Musicnotes Player V1.23.1
MySQL Server 5.1
NASA World Wind 1.4
NVIDIA Cg Toolkit 2.0 December 2007
NVIDIA Drivers
NVIDIA PhysX
OGRE Command Line Tools
OGRE Demos 1.2.0
OGRE Milkshape Exporter
OgreOde_Source
ogreProject
ogreProjectv2
Olympus Digital Wave Player
OpenAL
OpenOffice.org 2.0
OpenVPN 2.0_rc18-gui-1.0-rc5
Pidgin
PlayNC Launcher
Power Tab Editor 1.7
PowerDVD 5.1
Psi (remove only)
PunkBuster Services
QuickTime
ReadPlease 2003/ReadPlease PLUS 2003
RealPlayer
RGSS-RTP Standard
RPGToolkit, Version 3.1.0
RPGXP
Savage 2.00e
SecondLife (remove only)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Sibelius Scorch Plugin
Sins of a Solar Empire
Sins of a Solar Empire
Sound Blaster Audigy 2
SoundMAX
Spybot - Search & Destroy
Standard ML of New Jersey 110.0.7
Starcraft
Stardock Central
Steam
TBS WMP Plug-in
Team Fortress 2
TeamSpeak 2 RC2
Texture Maker
Thumbplug TGA
ThumbView_Lite 1.0
Ultimate Unwrap3D 2.28
Ultimate Unwrap3D 2.29
Ultimate Unwrap3D 2.32
Ultimate Unwrap3D 2.40
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Ventrilo Client
version 2.2.7
Viewpoint Media Player
Visual Studio 2005 Tools for Office Second Edition Runtime
Visual Studio Tools for the Office system 3.0 Runtime
Visual Studio Tools for the Office system 3.0 Runtime
VPN Client
VST Bridge 1.1
Winamp (remove only)
Windows Imaging Component
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows Mobile 5.0 SDK R2 for Pocket PC
Windows Mobile 5.0 SDK R2 for Smartphone
Windows XP Service Pack 3
WinRAR archiver
WinSCP 3.8.2
Xfire (remove only)