Hi, done as requested - please see logs. Thanks for your help.
Explorer killed successfully
C:\Downloads\Software\MotoBlaze-Install.exe moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\dgkrolrw.dll
C:\WINDOWS\system32\dgkrolrw.dll NOT unregistered.
C:\WINDOWS\system32\dgkrolrw.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\pvansvph.dll
C:\WINDOWS\system32\pvansvph.dll NOT unregistered.
C:\WINDOWS\system32\pvansvph.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\qfgxawhr.dll
C:\WINDOWS\system32\qfgxawhr.dll NOT unregistered.
C:\WINDOWS\system32\qfgxawhr.dll moved successfully.
C:\Program Files\PDM\PDM.006 moved successfully.
< purity >
Explorer started successfully
OTMoveIt2 by OldTimer - Version 1.0.4.2 log created on 05212008_101012
------------
ComboFix 08-05-20.5 - Michelle 2008-05-21 11:36:35.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.896 [GMT 1:00]
Running from: C:\Documents and Settings\Michelle\Desktop\ComboFix.exe
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BM4bdf398a.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\auwcrsik.ini
C:\WINDOWS\system32\crvtkrnu.ini
C:\WINDOWS\system32\hpvsnavp.ini
C:\WINDOWS\system32\hxyiegne.dll
C:\WINDOWS\system32\hyqliilv.dll
C:\WINDOWS\system32\igtqjfxx.dll
C:\WINDOWS\system32\KkQBdccf.ini
C:\WINDOWS\system32\KkQBdccf.ini2
C:\WINDOWS\system32\ltnuseps.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\qndkgicr.exe
C:\WINDOWS\system32\tuvTkjHW.dll
C:\WINDOWS\system32\vGhQsvut.ini
C:\WINDOWS\system32\vGhQsvut.ini2
C:\WINDOWS\system32\vwvpbfgl.dll
C:\WINDOWS\system32\WHjkTvut.ini
C:\WINDOWS\system32\WHjkTvut.ini2
C:\WINDOWS\system32\xxfjqtgi.ini
.
((((((((((((((((((((((((( Files Created from 2008-04-21 to 2008-05-21 )))))))))))))))))))))))))))))))
.
2008-05-28 19:27 . 2008-05-28 19:27 <DIR> d-------- C:\Program Files\Hide My IP 2008
2008-05-28 19:27 . 2007-07-11 11:11 888,832 --a------ C:\WINDOWS\system32\securenet.dll
2008-05-26 20:31 . 2008-05-26 20:33 <DIR> d-------- C:\Program Files\Virtual Rosary
2008-05-21 10:10 . 2008-05-21 10:10 <DIR> d-------- C:\_OTMoveIt
2008-05-21 09:55 . 2008-05-21 09:55 115,200 --a------ C:\WINDOWS\system32\unrktvrc.dll
2008-05-21 09:52 . 2008-05-21 09:52 134,144 --a------ C:\WINDOWS\system32\utdiwhlw.dll
2008-05-21 09:46 . 2008-05-21 09:46 92,160 --a------ C:\WINDOWS\system32\depytxnb.dll
2008-05-21 09:44 . 2008-05-21 09:44 126,464 --a------ C:\WINDOWS\system32\ukfbklay.dll
2008-05-19 16:44 . 2008-05-19 16:44 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-19 16:44 . 2008-05-19 16:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-19 14:21 . 2008-05-19 14:21 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Webroot
2008-05-19 14:21 . 2007-07-19 22:54 1,521,464 --a------ C:\WINDOWS\WRSetup.dll
2008-05-19 14:21 . 2007-07-19 22:42 163,128 --a------ C:\WINDOWS\system32\drivers\ssidrv.sys
2008-05-19 14:21 . 2007-07-19 22:42 23,864 --a------ C:\WINDOWS\system32\drivers\sskbfd.sys
2008-05-19 14:21 . 2007-07-19 22:42 21,816 --a------ C:\WINDOWS\system32\drivers\sshrmd.sys
2008-05-19 14:21 . 2007-07-19 22:42 20,280 --a------ C:\WINDOWS\system32\drivers\SSFS0BB8.sys
2008-05-18 20:57 . 2008-05-19 11:11 644 --a------ C:\WINDOWS\system32\tmp.reg
2008-05-18 18:59 . 2008-05-18 18:59 <DIR> d-------- C:\Documents and Settings\Michelle\Application Data\TrojanHunter
2008-05-18 18:55 . 2008-05-18 18:56 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-05-18 18:55 . 2008-05-18 20:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-18 18:44 . 2008-05-18 21:38 <DIR> d-------- C:\Program Files\TrojanHunter 5.0
2008-05-18 16:54 . 2008-05-18 16:54 <DIR> d-------- C:\Documents and Settings\Michelle\Application Data\McAfee
2008-05-18 16:32 . 2008-05-18 16:32 <DIR> d-------- C:\Program Files\XP Codec Pack
2008-05-18 16:32 . 2008-05-18 16:32 <DIR> d-------- C:\Program Files\Undisker
2008-05-18 16:27 . 2008-05-18 16:32 <DIR> d-------- C:\Documents and Settings\Michelle\Application Data\Software Informer
2008-05-17 20:21 . 2008-05-18 16:32 <DIR> d-------- C:\Program Files\XP Codec Pack(2)
2008-05-17 09:47 . 2008-05-17 09:47 58,880 --a------ C:\WINDOWS\system32\mlJCVoLD.dll
2008-05-17 09:46 . 2008-05-17 09:46 354,560 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe
2008-05-17 09:46 . 2008-04-04 14:51 28,416 --a------ C:\WINDOWS\system32\uxtuneup.dll
2008-05-17 09:45 . 2008-05-17 09:46 <DIR> d-------- C:\Program Files\TuneUp Utilities 2008
2008-05-17 09:45 . 2008-05-17 09:45 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-17 09:45 . 2008-05-17 09:45 58,880 --a------ C:\WINDOWS\system32\ddcdButS.dll
2008-05-12 11:42 . 2008-05-12 11:43 <DIR> d-------- C:\Program Files\LimeWire
2008-05-11 17:00 . 2008-05-11 17:00 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-05-11 17:00 . 2008-05-11 17:00 <DIR> d-------- C:\WINDOWS\system32\en
2008-05-11 17:00 . 2008-05-11 17:00 <DIR> d-------- C:\WINDOWS\system32\bits
2008-05-11 17:00 . 2008-05-11 17:00 <DIR> d-------- C:\WINDOWS\l2schemas
2008-05-11 16:57 . 2008-05-11 16:57 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-05-11 16:51 . 2008-05-11 17:05 2,675 --a------ C:\WINDOWS\imsins.BAK
2008-05-11 16:47 . 2008-05-11 16:47 <DIR> d-------- C:\WINDOWS\EHome
2008-05-11 16:36 . 2004-08-03 22:29 104,960 --a------ C:\WINDOWS\system32\drivers\atinrvxx.sys
2008-05-11 16:36 . 2004-08-03 22:29 73,216 --a------ C:\WINDOWS\system32\drivers\atintuxx.sys
2008-05-11 16:36 . 2004-07-17 11:36 64,352 --a------ C:\WINDOWS\system32\drivers\ativmc20.cod
2008-05-11 16:36 . 2004-08-03 22:29 63,488 --a------ C:\WINDOWS\system32\drivers\atinxsxx.sys
2008-05-11 16:36 . 2004-08-03 22:29 57,856 --a------ C:\WINDOWS\system32\drivers\atinbtxx.sys
2008-05-11 16:36 . 2004-08-03 22:29 52,224 --a------ C:\WINDOWS\system32\drivers\atinraxx.sys
2008-05-11 16:36 . 2004-08-03 22:29 31,744 --a------ C:\WINDOWS\system32\drivers\atinxbxx.sys
2008-05-11 16:36 . 2004-08-03 22:29 28,672 --a------ C:\WINDOWS\system32\drivers\atinsnxx.sys
2008-05-11 16:36 . 2004-08-03 22:29 14,336 --a------ C:\WINDOWS\system32\drivers\atinpdxx.sys
2008-05-11 16:36 . 2004-08-03 22:29 13,824 --a------ C:\WINDOWS\system32\drivers\atinttxx.sys
2008-05-11 16:36 . 2004-08-03 22:29 13,824 --a------ C:\WINDOWS\system32\drivers\atinmdxx.sys
2008-05-10 09:29 . 2008-05-19 14:21 <DIR> d-------- C:\Program Files\Webroot
2008-05-10 09:29 . 2008-05-10 09:29 <DIR> d-------- C:\Program Files\Common Files\Webroot Shared
2008-05-10 09:29 . 2008-05-19 14:21 <DIR> d-------- C:\Documents and Settings\Michelle\Application Data\Webroot
2008-05-10 09:29 . 2008-05-19 14:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Webroot
2008-05-10 09:29 . 2007-11-26 14:47 194,888 --a------ C:\WINDOWS\Unwash6.exe
2008-05-09 15:55 . 2008-05-09 15:55 <DIR> d-------- C:\Program Files\Google
2008-05-07 12:54 . 2008-05-07 12:54 <DIR> d-------- C:\Documents and Settings\Michelle\Application Data\AdobeUM
2008-05-03 21:33 . 2008-05-11 18:45 <DIR> d-------- C:\Program Files\MSN Messenger
2008-05-01 11:22 . 2008-05-21 11:33 5,293 --a------ C:\WINDOWS\system32\Config.MPF
2008-05-01 11:21 . 2008-05-01 11:24 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\SiteAdvisor
2008-05-01 11:20 . 2008-05-02 00:02 <DIR> d-------- C:\Program Files\SiteAdvisor
2008-05-01 11:20 . 2008-05-19 01:09 <DIR> d-------- C:\Documents and Settings\Michelle\Application Data\SiteAdvisor
2008-05-01 11:20 . 2008-05-02 00:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-05-01 11:19 . 2006-03-03 08:07 143,360 --a------ C:\WINDOWS\system32\dunzip32.dll
2008-05-01 11:18 . 2007-11-22 06:44 201,320 --a------ C:\WINDOWS\system32\drivers\mfehidk.sys
2008-05-01 11:18 . 2007-07-13 06:20 113,952 --a------ C:\WINDOWS\system32\drivers\Mpfp.sys
2008-05-01 11:18 . 2007-11-22 06:44 79,304 --a------ C:\WINDOWS\system32\drivers\mfeavfk.sys
2008-05-01 11:18 . 2007-12-02 12:51 40,488 --a------ C:\WINDOWS\system32\drivers\mfesmfk.sys
2008-05-01 11:18 . 2007-11-22 06:44 35,240 --a------ C:\WINDOWS\system32\drivers\mfebopk.sys
2008-05-01 11:18 . 2007-11-22 06:44 33,832 --a------ C:\WINDOWS\system32\drivers\mferkdk.sys
2008-05-01 11:17 . 2008-05-02 16:34 <DIR> d-------- C:\Program Files\Common Files\McAfee
2008-05-01 11:16 . 2008-05-21 09:44 <DIR> d-------- C:\Program Files\McAfee
2008-04-30 11:24 . 2008-04-30 11:24 <DIR> d-------- C:\Program Files\Toshiba
2008-04-29 18:22 . 2008-05-21 10:10 <DIR> d-------- C:\Program Files\PDM
2008-04-29 14:03 . 2008-04-29 15:34 <DIR> d-------- C:\Program Files\MATCO
2008-04-28 10:25 . 2008-04-28 10:25 <DIR> d-------- C:\Program Files\Apple Software Update
2008-04-26 15:46 . 2001-08-17 14:55 6,144 --a------ C:\WINDOWS\system32\kbd101c.dll
2008-04-26 15:46 . 2001-08-17 14:55 6,144 --a------ C:\WINDOWS\system32\kbd101b.dll
2008-04-26 15:46 . 2001-08-17 14:55 6,144 --a--c--- C:\WINDOWS\system32\dllcache\kbd101c.dll
2008-04-26 15:46 . 2001-08-17 14:55 6,144 --a--c--- C:\WINDOWS\system32\dllcache\kbd101b.dll
2008-04-25 19:21 . 2008-05-05 15:08 <DIR> d-------- C:\Program Files\FaceOnBody
2008-04-25 19:21 . 2008-05-05 15:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FaceOnBody
2008-04-25 18:23 . 2008-04-25 18:23 <DIR> d-------- C:\Program Files\VS Revo Group
2008-04-23 12:44 . 2008-04-28 10:41 <DIR> d-------- C:\Program Files\CPU Eat 'n' Cool
2008-04-22 22:11 . 2008-04-25 11:29 <DIR> d-------- C:\Documents and Settings\Michelle\Shared
2008-04-22 22:11 . 2008-04-25 11:35 <DIR> d-------- C:\Documents and Settings\Michelle\Incomplete
2008-04-22 22:10 . 2008-05-25 12:46 <DIR> d-------- C:\Documents and Settings\Michelle\Application Data\LimeWire
2008-04-22 12:16 . 2008-04-22 12:16 <DIR> d-------- C:\Program Files\I8kfanGUI
2008-04-22 12:16 . 2007-02-16 10:05 14,464 --a------ C:\WINDOWS\system32\drivers\fanio.sys
2008-04-22 11:46 . 2008-04-22 12:12 <DIR> d-------- C:\Program Files\Motherboard Monitor 5
2008-04-21 13:17 . 2008-04-28 10:43 <DIR> d-------- C:\Program Files\Opera
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-27 18:30 --------- d-----w C:\Program Files\XoftSpySE
2008-05-21 10:20 --------- d-----w C:\Documents and Settings\Michelle\Application Data\Free Download Manager
2008-05-19 11:56 --------- d-----w C:\Documents and Settings\Michelle\Application Data\uTorrent
2008-05-18 16:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kontiki
2008-05-18 15:32 --------- d-----w C:\Program Files\Free Download Manager
2008-05-11 11:37 --------- d-----w C:\Program Files\Kontiki
2008-05-03 21:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-05-03 20:32 --------- d-----w C:\Program Files\Windows Live
2008-05-01 10:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-05-01 10:17 --------- d-----w C:\Program Files\McAfee.com
2008-04-28 11:11 --------- d-----w C:\Program Files\Enigma Software Group
2008-04-28 10:13 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-28 09:56 --------- d-----w C:\Program Files\HP
2008-04-28 09:56 --------- d-----w C:\Program Files\Hewlett-Packard
2008-04-28 09:51 --------- d-----w C:\Program Files\Common Files\HP
2008-04-26 10:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\WinZip
2008-04-20 16:25 --------- d-----w C:\Program Files\RegCure
2008-04-20 14:36 28,448 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-04-20 14:36 25,664 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-04-20 14:36 229,152 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-04-20 14:36 1,809,952 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-04-20 14:32 --------- d-----w C:\Program Files\Common Files\ParetoLogic
2008-04-20 14:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\ParetoLogic
2008-04-20 08:51 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-20 08:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Downloaded Installations
2008-04-18 12:32 --------- d-----w C:\Documents and Settings\Michelle\Application Data\HP
2008-04-16 10:46 --------- d-----w C:\Documents and Settings\Michelle\Application Data\Media Player Classic
2008-04-16 10:11 --------- d-----w C:\Program Files\WinAVI Video Converter
2008-04-16 09:51 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-04-15 16:21 --------- d-----w C:\Program Files\AC3Filter
2008-04-15 15:45 --------- d-----w C:\Program Files\iTunes
2008-04-15 15:45 --------- d-----w C:\Program Files\iPod
2008-04-15 15:42 --------- d-----w C:\Program Files\QuickTime
2008-04-15 15:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-04-14 04:42 985,088 ----a-w C:\WINDOWS\system32\setupapi.dll
2008-04-14 04:42 11,264 ----a-w C:\WINDOWS\system32\spnpinst.exe
2008-04-14 04:41 423,936 ----a-w C:\WINDOWS\system32\licdll.dll
2008-04-14 00:25 1,804 ----a-w C:\WINDOWS\system32\dcache.bin
2008-04-14 00:16 329,728 ----a-w C:\WINDOWS\system32\netsetup.exe
2008-04-14 00:13 92,424 ----a-w C:\WINDOWS\system32\rdpdd.dll
2008-04-14 00:13 87,176 ----a-w C:\WINDOWS\system32\rdpwsx.dll
2008-04-14 00:13 40,840 ----a-w C:\WINDOWS\system32\drivers\termdd.sys
2008-04-14 00:13 299,520 ----a-w C:\WINDOWS\system32\drmclien.dll
2008-04-14 00:13 21,896 ----a-w C:\WINDOWS\system32\drivers\tdtcp.sys
2008-04-14 00:13 139,656 ----a-w C:\WINDOWS\system32\drivers\rdpwd.sys
2008-04-14 00:13 12,168 ----a-w C:\WINDOWS\system32\tsddd.dll
2008-04-14 00:13 12,040 ----a-w C:\WINDOWS\system32\drivers\tdpipe.sys
2008-04-14 00:11 997,376 ----a-w C:\WINDOWS\system32\msgina.dll
2008-04-14 00:10 53,279 ----a-w C:\WINDOWS\system32\odbcji32.dll
2008-04-14 00:10 4,126 ----a-w C:\WINDOWS\system32\msdxmlc.dll
2008-04-14 00:10 3,584 ----a-w C:\WINDOWS\system32\msafd.dll
2008-04-13 21:00 103,424 ----a-w C:\WINDOWS\system32\dpcdll.dll
2008-04-13 19:30 1,845,632 ----a-w C:\WINDOWS\system32\win32k.sys
2008-04-13 19:28 175,744 ----a-w C:\WINDOWS\system32\drivers\rdbss.sys
2008-04-13 19:24 2,145,280 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-04-13 19:21 162,816 ----a-w C:\WINDOWS\system32\drivers\netbt.sys
2008-04-13 19:20 91,520 ----a-w C:\WINDOWS\system32\drivers\ndiswan.sys
2008-04-13 19:20 361,344 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-04-13 19:20 182,656 ----a-w C:\WINDOWS\system32\drivers\ndis.sys
2008-04-13 19:19 75,264 ----a-w C:\WINDOWS\system32\drivers\ipsec.sys
2008-04-13 19:19 51,328 ----a-w C:\WINDOWS\system32\drivers\rasl2tp.sys
2008-04-13 19:19 48,384 ----a-w C:\WINDOWS\system32\drivers\raspptp.sys
2008-04-13 19:19 146,048 ----a-w C:\WINDOWS\system32\drivers\portcls.sys
2008-04-13 19:19 138,112 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-04-13 19:18 52,480 ----a-w C:\WINDOWS\system32\drivers\i8042prt.sys
2008-04-13 19:17 83,072 ----a-w C:\WINDOWS\system32\drivers\wdmaud.sys
2008-04-13 19:17 456,576 ----a-w C:\WINDOWS\system32\drivers\mrxsmb.sys
2008-04-13 19:17 105,344 ----a-w C:\WINDOWS\system32\drivers\mup.sys
2008-04-13 19:16 49,536 ----a-w C:\WINDOWS\system32\drivers\classpnp.sys
2008-04-13 19:16 141,056 ----a-w C:\WINDOWS\system32\drivers\ks.sys
2008-04-13 19:15 64,512 ----a-w C:\WINDOWS\system32\drivers\serial.sys
2008-04-13 19:15 60,800 ----a-w C:\WINDOWS\system32\drivers\sysaudio.sys
2008-04-13 19:15 574,976 ----a-w C:\WINDOWS\system32\drivers\ntfs.sys
2008-04-13 19:15 334,848 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-04-13 19:14 63,744 ----a-w C:\WINDOWS\system32\drivers\cdfs.sys
2008-04-13 19:14 143,744 ----a-w C:\WINDOWS\system32\drivers\fastfat.sys
2008-04-13 19:00 30,080 ----a-w C:\WINDOWS\system32\drivers\modem.sys
2008-04-13 19:00 225,664 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-04-13 19:00 19,072 ----a-w C:\WINDOWS\system32\drivers\tdi.sys
2008-04-13 18:57 41,472 ----a-w C:\WINDOWS\system32\drivers\raspppoe.sys
2008-04-13 18:57 40,576 ----a-w C:\WINDOWS\system32\drivers\ndproxy.sys
2008-04-13 18:57 34,560 ----a-w C:\WINDOWS\system32\drivers\wanarp.sys
2008-04-13 18:57 20,864 ----a-w C:\WINDOWS\system32\drivers\ipinip.sys
2008-04-13 18:57 152,832 ----a-w C:\WINDOWS\system32\drivers\ipnat.sys
2008-04-13 18:57 14,336 ----a-w C:\WINDOWS\system32\drivers\asyncmac.sys
2008-04-13 18:57 10,112 ----a-w C:\WINDOWS\system32\drivers\ndistapi.sys
2008-04-13 18:56 88,320 ----a-w C:\WINDOWS\system32\drivers\nwlnkipx.sys
2008-04-13 18:56 69,120 ----a-w C:\WINDOWS\system32\drivers\psched.sys
2008-04-13 18:56 35,072 ----a-w C:\WINDOWS\system32\drivers\msgpc.sys
2008-04-13 18:56 34,688 ----a-w C:\WINDOWS\system32\drivers\netbios.sys
2008-04-13 18:56 30,592 ----a-w C:\WINDOWS\system32\drivers\rndismpx.sys
2008-04-13 18:56 30,592 ----a-w C:\WINDOWS\system32\drivers\rndismp.sys
2008-04-13 18:56 12,800 ----a-w C:\WINDOWS\system32\drivers\usb8023x.sys
2008-04-13 18:56 12,800 ----a-w C:\WINDOWS\system32\drivers\usb8023.sys
2008-04-13 18:56 12,288 ----a-w C:\WINDOWS\system32\drivers\tunmp.sys
2008-04-13 18:55 202,624 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-04-13 18:55 14,592 ----a-w C:\WINDOWS\system32\drivers\ndisuio.sys
2008-04-13 18:54 11,264 ----a-w C:\WINDOWS\system32\drivers\irenum.sys
2008-04-13 18:53 71,552 ----a-w C:\WINDOWS\system32\drivers\bridge.sys
2008-04-13 18:53 40,320 ----a-w C:\WINDOWS\system32\drivers\nmnt.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{514A5C49-0C7D-42c3-A71B-38864A269B7A}]
2008-05-21 09:46 92160 --a------ C:\WINDOWS\system32\depytxnb.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{522E0112-EDD9-413D-A99E-C311A54B6676}]
2008-05-17 09:45 58880 --a------ C:\WINDOWS\system32\ddcdButS.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{cc6cb170-e4ec-410c-8438-7d7e6ff534aa}]
2008-05-21 09:52 134144 --a------ C:\WINDOWS\system32\utdiwhlw.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BM4bdf398a"="C:\WINDOWS\system32\ukfbklay.dll" [2008-05-21 09:44 126464]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"Windows Firewall"="rundll32.exe" [2008-04-14 01:12 33280 C:\WINDOWS\system32\rundll32.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 01:12 15360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{522E0112-EDD9-413D-A99E-C311A54B6676}"= C:\WINDOWS\system32\ddcdButS.dll [2008-05-17 09:45 58880]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddcdButS]
ddcdButS.dll 2008-05-17 09:45 58880 C:\WINDOWS\system32\ddcdButS.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= ffdshow.ax
"msacm.ac3filter"= ac3filter.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth Manager.lnk]
backup=C:\WINDOWS\pss\Bluetooth Manager.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\48ec0a16]
--a------ 2008-05-21 09:55 115200 C:\WINDOWS\system32\unrktvrc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
--a------ 2003-08-29 06:59 122880 C:\WINDOWS\BCMSMMSG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM4bdf398a]
--a------ 2008-05-21 09:44 126464 C:\WINDOWS\system32\ukfbklay.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Broadcom Wireless Manager UI]
--a------ 2005-12-19 10:08 1347584 C:\WINDOWS\system32\WLTRAY.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2008-04-14 01:12 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\i8kfangui]
--a------ 2007-02-16 17:58 856064 C:\Program Files\I8kfanGUI\I8kfanGUI.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-03-30 10:36 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\kdx]
--a------ 2008-02-27 17:56 1032376 C:\Program Files\Kontiki\KHost.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mcagent_exe]
--a------ 2007-11-01 19:12 582992 C:\Program Files\McAfee.com\Agent\mcagent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:54 5674352 C:\Program Files\MSN Messenger\MsnMsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2004-10-26 13:01 4632576 C:\WINDOWS\system32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2004-10-26 13:01 921600 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OASClnt]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ParetoLogic Anti-Virus PLUS]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDM Agent]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-03-28 23:37 413696 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Rosary Reminder]
--a------ 2001-07-11 00:54 46080 C:\Program Files\Virtual Rosary\reminder.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiteAdvisor]
--a------ 2007-02-09 05:37 36904 C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpyHunter Security Suite]
--a------ 2008-01-23 15:47 847872 C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySweeper]
--a------ 2007-07-19 22:54 5361464 C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-02-22 04:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TuneUp MemOptimizer]
--a------ 2008-04-16 09:59 154368 C:\Program Files\TuneUp Utilities 2008\MemOptimizer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Window Washer]
--a------ 2007-11-26 14:47 1206600 C:\Program Files\Webroot\Washer\wwDisp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Firewall]
--a------ 2008-04-14 01:12 33280 C:\WINDOWS\system32\rundll32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XoftSpySE]
--a------ 2007-10-24 19:59 728576 C:\Program Files\XoftSpySE\xoftspy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wwEngineSvc"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"wltrysvc"=2 (0x2)
"WLSetupSvc"=3 (0x3)
"usnjsvc"=3 (0x3)
"Pml Driver HPZ12"=2 (0x2)
"ose"=3 (0x3)
"NVSvc"=2 (0x2)
"LVSrvLauncher"=2 (0x2)
"KService"=2 (0x2)
"iPod Service"=3 (0x3)
"idsvc"=3 (0x3)
"Bonjour Service"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"TuneUp.Defrag"=3 (0x3)
"SiteAdvisor Service"=2 (0x2)
"DirMS_Defragmentation"=3 (0x3)
"Buzzsaw_Defragmentation"=2 (0x2)
"SecureSrv"=3 (0x3)
"WebrootSpySweeperService"=2 (0x2)
"MSK80Service"=2 (0x2)
"MpfService"=2 (0x2)
"McSysmon"=3 (0x3)
"McShield"=2 (0x2)
"McProxy"=2 (0x2)
"McODS"=3 (0x3)
"McNASvc"=2 (0x2)
"mcmscsvc"=2 (0x2)
"0046731211359484mcinstcleanup"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Kontiki\\KService.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
R0 SSFS0BB8;Spy Sweeper File System Filer Driver: 0BB8;C:\WINDOWS\system32\Drivers\SSFS0BB8.SYS [2007-07-19 22:42]
R1 fanio;FanIO driver;C:\WINDOWS\system32\drivers\fanio.sys [2007-02-16 10:05]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2008-04-14 01:12]
S4 0046731211359484mcinstcleanup;McAfee Application Installer Cleanup (0046731211359484);C:\WINDOWS\TEMP\
004673~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini []
S4 Buzzsaw_Defragmentation;Buzzsaw_Defragmentation;C:\Program Files\MATCO\BuzzSawService.exe [2006-11-26 21:43]
S4 SecureSrv;SecureSrv;C:\Program Files\Hide My IP 2008\SecureSrv.exe [2008-03-13 15:36]
S4 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-05-17 09:46]
S4 wwEngineSvc;Window Washer Engine;C:\Program Files\Webroot\Washer\WasherSvc.exe [2007-11-26 14:47]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
"2008-05-21 10:42:02 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2008\OneClickStarter.exe
"2008-05-19 11:12:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-05-01 10:17:27 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe'
"2008-05-01 10:17:26 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2008-05-19 17:00:49 C:\WINDOWS\Tasks\ParetoLogic Registration.job"
- C:\WINDOWS\system32\rundll32.exe@
"2008-05-21 10:42:02 C:\WINDOWS\Tasks\RegCure Program Check.job"
- C:\Program Files\RegCure\RegCure.exe
"2008-05-08 02:02:11 C:\WINDOWS\Tasks\RegCure.job"
- C:\Program Files\RegCure\RegCure.exe
"2008-05-21 10:42:08 C:\WINDOWS\Tasks\XoftSpySE 2.job"
- C:\Program Files\XoftSpySE\XoftSpy.exe
"2008-05-27 05:57:38 C:\WINDOWS\Tasks\XoftSpySE.job"
- C:\Program Files\XoftSpySE\XoftSpy.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-21 11:42:52
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\ddcdButS.dll
PROCESS: C:\WINDOWS\system32\lsass.exe
-> C:\WINDOWS\system32\securenet.dll
PROCESS: C:\WINDOWS\explorer.exe
-> C:\WINDOWS\system32\ukfbklay.dll
-> C:\WINDOWS\system32\securenet.dll
.
------------------------ Other Running Processes ------------------------
.
C:\PROGRA~1\McAfee\VIRUSS~1\Mcshield.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\verclsid.exe
.
**************************************************************************
.
Completion time: 2008-05-21 11:46:26 - machine was rebooted [Michelle]
ComboFix-quarantined-files.txt 2008-05-21 10:46:16
Pre-Run: 135,167,000,576 bytes free
Post-Run: 135,083,905,024 bytes free
420 --- E O F --- 2008-05-17 08:43:06
--------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:53:21, on 21/05/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Michelle\Desktop\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O2 - BHO: (no name) - {514A5C49-0C7D-42c3-A71B-38864A269B7A} - C:\WINDOWS\system32\depytxnb.dll
O2 - BHO: (no name) - {522E0112-EDD9-413D-A99E-C311A54B6676} - C:\WINDOWS\system32\ddcdButS.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O2 - BHO: {aa435ff6-e7d7-8348-c014-ce4e071bc6cc} - {cc6cb170-e4ec-410c-8438-7d7e6ff534aa} - C:\WINDOWS\system32\utdiwhlw.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O4 - HKLM\..\Run: [BM4bdf398a] Rundll32.exe "C:\WINDOWS\system32\ukfbklay.dll",s
O4 - HKLM\..\RunServices: [Windows Firewall] rundll32.exe
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Download FLV by WinAVI... - C:\Program Files\WinAVI FLV Converter\flv_link.htm
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: WinAVI FLV Manager - {DE365254-2F9B-4908-9E3A-7AAA6EC90BCC} - C:\Program Files\WinAVI FLV Converter\FLVTune.dll
O9 - Extra 'Tools' menuitem: WinAVI FLV Manager - {DE365254-2F9B-4908-9E3A-7AAA6EC90BCC} - C:\Program Files\WinAVI FLV Converter\FLVTune.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\securenet.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\securenet.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\securenet.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) -
http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1200686004062
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) -
http://sdlc-esd.sun.com/ESD40/JSCDL...-jc.cab&File=jinstall-6u5-windows-i586-jc.cab
O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} (TSEasyInstallX Control) -
http://www.trendsecure.com/easy_install/_activex/en-US/TSEasyInstallX.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - Winlogon Notify: ddcdButS - C:\WINDOWS\SYSTEM32\ddcdButS.dll
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
--
End of file - 6377 bytes