Uploaded the file inetexp.dat and reported no problems.
The results from ComboFix log
ComboFix 08-04-18.3 - Steve 2008-04-20 1:34:27.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.61.1033.18.574 [GMT 10:00]
Running from: C:\Documents and Settings\Steve.STEVESPC\My Documents\ComboFix.exe
Command switches used :: C:\Documents and Settings\Steve.STEVESPC\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\1.dat
C:\WINDOWS\BM5f6ac17e.xml
C:\WINDOWS\SYSTEM32\ddcYqNfc.dll.vir
C:\WINDOWS\SYSTEM32\hgGyYRJc.dll.vir
C:\WINDOWS\SYSTEM32\kbbytwbx.dll.vir
C:\WINDOWS\SYSTEM32\pxenvokp.ini
C:\WINDOWS\SYSTEM32\temp_0000_85-19.aok
C:\WINDOWS\SYSTEM32\test.aok
C:\WINDOWS\SYSTEM32\wcthqfbu.ini
C:\WINDOWS\SYSTEM32\xgouapmy.ini
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\1.dat
C:\Documents and Settings\All Users.WINDOWS\Application Data\IDLE LOGO 32 HOLE
C:\Documents and Settings\Steve.STEVESPC\Application Data\inst.exe
C:\VundoFix Backups
C:\VundoFix Backups\blingen.dll.bad
C:\VundoFix Backups\hgGyYRJc.dll.bad
C:\VundoFix Backups\iifedaYs.dll.bad
C:\WINDOWS\BM5f6ac17e.xml
C:\WINDOWS\SYSTEM32\ddcYqNfc.dll.vir
C:\WINDOWS\SYSTEM32\hgGyYRJc.dll.vir
C:\WINDOWS\SYSTEM32\kbbytwbx.dll.vir
C:\WINDOWS\system32\msvcsv60.dll
C:\WINDOWS\SYSTEM32\pxenvokp.ini
C:\WINDOWS\SYSTEM32\temp_0000_85-19.aok
C:\WINDOWS\SYSTEM32\test.aok
C:\WINDOWS\SYSTEM32\wcthqfbu.ini
C:\WINDOWS\SYSTEM32\xgouapmy.ini
.
((((((((((((((((((((((((( Files Created from 2008-03-19 to 2008-04-19 )))))))))))))))))))))))))))))))
.
2008-04-19 15:24 . 2008-04-19 18:00 4,705 --a------ C:\WINDOWS\SYSTEM32\inetexp.dat
2008-04-19 14:03 . 2006-05-25 15:52 162,304 --a------ C:\WINDOWS\SYSTEM32\ztvunrar36.dll
2008-04-19 14:03 . 2003-02-02 20:06 153,088 --a------ C:\WINDOWS\SYSTEM32\UNRAR3.dll
2008-04-19 14:03 . 2005-08-26 01:50 77,312 --a------ C:\WINDOWS\SYSTEM32\ztvunace26.dll
2008-04-19 14:03 . 2002-03-06 01:00 75,264 --a------ C:\WINDOWS\SYSTEM32\unacev2.dll
2008-04-19 14:03 . 2006-06-19 13:01 69,632 --a------ C:\WINDOWS\SYSTEM32\ztvcabinet.dll
2008-04-16 20:04 . 2008-04-16 20:04 <DIR> d-------- C:\WINDOWS\SYSTEM32\Kaspersky Lab
2008-04-16 20:04 . 2008-04-16 20:04 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Kaspersky Lab
2008-04-16 18:19 . 2008-04-16 18:23 <DIR> d-------- C:\Documents and Settings\Steve.STEVESPC\.housecall6.6
2008-04-16 18:19 . 2008-04-16 18:19 102,664 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\tmcomm.sys
2008-04-13 13:00 . 2008-04-13 13:01 <DIR> d-------- C:\Program Files\CCleaner
2008-04-13 12:50 . 2008-04-13 12:50 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-13 11:55 . 2008-04-14 17:22 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-04-13 09:55 . 2008-04-19 09:37 <DIR> d-------- C:\Program Files\Panda Security
2008-04-13 09:20 . 2008-04-19 09:37 <DIR> d-------- C:\Program Files\VS Revo Group
2008-04-13 00:01 . 2008-04-13 12:07 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-13 00:01 . 2008-04-13 12:08 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2008-04-11 18:53 . 2008-04-11 18:53 <DIR> d-------- C:\Program Files\Outsim
2008-04-09 21:43 . 2008-04-09 21:43 <DIR> d-------- C:\Program Files\MP4Converter
2008-04-09 21:07 . 2008-04-09 21:17 <DIR> d-------- C:\Program Files\Realmedia RM RMVB Converter
2008-04-09 18:28 . 2008-04-09 18:28 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-04-09 18:28 . 2008-04-09 18:28 1,409 --a------ C:\WINDOWS\QTFont.for
2008-04-09 16:28 . 2008-04-09 16:28 <DIR> d-------- C:\Documents and Settings\Steve.STEVESPC\Application Data\Ulead Systems
2008-04-09 16:26 . 2008-04-09 16:26 <DIR> d-------- C:\Program Files\Ulead Systems
2008-04-09 16:26 . 2008-04-09 16:43 <DIR> d-------- C:\Program Files\Common Files\Ulead Systems
2008-04-09 16:26 . 2008-04-09 16:43 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Ulead Systems
2008-04-08 19:07 . 2008-04-08 19:07 <DIR> d-------- C:\Program Files\WinAVI MP4 Converter
2008-04-08 17:05 . 2008-04-09 21:53 <DIR> d-------- C:\Temp
2008-04-05 18:49 . 2008-04-09 20:29 <DIR> d-------- C:\Documents and Settings\Steve.STEVESPC\Application Data\Nokia Multimedia Player
2008-04-05 18:46 . 2008-04-07 20:55 2,841,973 --------- C:\Documents and Settings\Steve.STEVESPC\Application Data\NMM-MetaData.db
2008-04-05 18:29 . 2008-04-05 18:29 <DIR> d-------- C:\Program Files\DIFX
2008-04-05 18:29 . 2008-04-05 18:31 <DIR> d-------- C:\Documents and Settings\Steve.STEVESPC\Application Data\Nokia
2008-04-05 18:28 . 2008-04-05 18:28 <DIR> d-------- C:\Program Files\PC Connectivity Solution
2008-04-05 18:28 . 2007-02-22 09:15 12,288 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\nmwcdcm.sys
2008-04-05 18:28 . 2007-02-22 09:15 12,288 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\nmwcdcj.sys
2008-04-05 18:28 . 2007-02-22 09:15 8,320 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\nmwcdc.sys
2008-04-05 18:27 . 2008-04-05 18:28 <DIR> d-------- C:\Program Files\Nokia
2008-04-05 18:27 . 2007-02-22 09:15 137,216 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\nmwcd.sys
2008-04-05 18:27 . 2007-02-22 09:15 90,624 --a------ C:\WINDOWS\SYSTEM32\nmwcdcls.dll
2008-04-05 18:27 . 2007-02-22 09:15 65,536 --a------ C:\WINDOWS\SYSTEM32\nmwcdcocls.dll
2008-04-05 18:13 . 2008-04-05 18:21 <DIR> d-------- C:\Program Files\PC Connectivity Solution(2)
2008-04-05 17:56 . 2008-04-05 17:56 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Installations
2008-04-05 17:24 . 2008-04-05 18:31 <DIR> d-------- C:\Documents and Settings\Steve.STEVESPC\Application Data\PC Suite
2008-04-05 17:24 . 2008-04-05 18:31 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\PC Suite
2008-04-03 19:24 . 2008-04-08 21:16 <DIR> d-------- C:\Program Files\PeerGuardian2
2008-04-02 16:52 . 2008-04-02 17:09 <DIR> d-------- C:\Documents and Settings\Steve.STEVESPC\Application Data\StoneLoops
2008-04-02 16:50 . 2008-04-02 16:50 <DIR> d-------- C:\Program Files\StoneLoops
2008-04-02 16:50 . 2008-04-02 16:52 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\StoneLoops!
2008-03-24 10:47 . 2008-03-24 11:03 <DIR> d-------- C:\Documents and Settings\Steve.STEVESPC\Application Data\BitTyrant
2008-03-22 22:15 . 2008-03-22 22:15 158,456 --a------ C:\WINDOWS\SYSTEM32\pxwma.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-19 04:04 --------- d-----w C:\Program Files\Trojan Remover
2008-04-19 03:58 --------- d-----w C:\Documents and Settings\Steve.STEVESPC\Application Data\uTorrent
2008-04-19 03:38 --------- d---a-w C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
2008-04-18 23:35 --------- d-----w C:\Program Files\Common Files\Scanner
2008-04-14 10:09 35,296 ----a-w C:\WINDOWS\system32\drivers\Dvd43.sys
2008-04-13 08:45 --------- d-----w C:\Program Files\Yahoo!
2008-04-12 11:42 --------- d-----w C:\Documents and Settings\Steve.STEVESPC\Application Data\Vso
2008-04-11 08:54 --------- d-----w C:\Program Files\VstPlugins
2008-04-11 08:54 --------- d-----w C:\Program Files\Image-Line
2008-04-09 09:23 --------- d-----w C:\Program Files\WinAVI Video Converter
2008-04-09 08:53 --------- d-----w C:\Program Files\Xilisoft
2008-04-09 06:43 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-29 09:16 --------- d-----w C:\Program Files\MSN Messenger
2008-03-20 05:51 360,064 ----a-w C:\WINDOWS\system32\drivers\TCPIP.SYS
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\SYSTEM32\win32k.sys
2008-03-18 07:14 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\PlayPond
2008-03-13 06:35 --------- d-----w C:\Program Files\Common Files\xing shared
2008-03-13 06:35 --------- d-----w C:\Program Files\Common Files\Real
2008-03-13 06:34 499,712 ----a-w C:\WINDOWS\SYSTEM32\msvcp71.dll
2008-03-13 06:34 348,160 ----a-w C:\WINDOWS\SYSTEM32\msvcr71.dll
2008-03-13 06:34 --------- d-----w C:\Program Files\Real
2008-03-10 00:07 --------- d-----w C:\Documents and Settings\Steve.STEVESPC\Application Data\Simply Super Software
2008-03-10 00:07 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Simply Super Software
2008-03-08 23:53 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Avg7
2008-03-08 23:52 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Grisoft
2008-03-08 23:46 99,904 ----a-w C:\WINDOWS\SYSTEM32\isafeif.dll
2008-03-08 23:46 79,424 ----a-w C:\WINDOWS\SYSTEM32\vetredir.dll
2008-03-08 23:46 75,280 ----a-w C:\WINDOWS\SYSTEM32\isafprod.dll
2008-03-08 23:46 32,528 ----a-w C:\WINDOWS\system32\drivers\vetmonnt.sys
2008-03-08 23:46 26,640 ----a-w C:\WINDOWS\system32\drivers\vet-filt.sys
2008-03-08 23:46 21,648 ----a-w C:\WINDOWS\system32\drivers\vetfddnt.sys
2008-03-08 23:46 21,392 ----a-w C:\WINDOWS\system32\drivers\vet-rec.sys
2008-03-08 23:41 879,832 ----a-w C:\WINDOWS\system32\drivers\vetefile.sys
2008-03-08 23:41 108,360 ----a-w C:\WINDOWS\system32\drivers\veteboot.sys
2008-03-08 23:40 --------- d-----w C:\Program Files\CA
2008-03-08 23:40 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\CA
2008-03-04 08:07 --------- d-----w C:\Program Files\Star Blaze
2008-03-01 20:32 --------- d-----w C:\Documents and Settings\Steve.STEVESPC\Application Data\LEAPS
2008-03-01 20:17 --------- d-----w C:\Documents and Settings\Steve.STEVESPC\Application Data\Pegasys Inc
2008-03-01 20:15 59,488 ----a-w C:\WINDOWS\SYSTEM32\GenSvcInst.exe
2008-03-01 20:15 33,408 ----a-w C:\WINDOWS\system32\drivers\CDRBSDRV.SYS
2008-03-01 20:15 145,504 ----a-w C:\WINDOWS\SYSTEM32\bgsvcgen.exe
2008-03-01 20:15 --------- d-----w C:\Program Files\Pegasys Inc
2008-03-01 19:44 --------- d-----w C:\Documents and Settings\Steve.STEVESPC\Application Data\Sony
2008-03-01 19:39 --------- d-----w C:\Program Files\Sony
2008-03-01 19:39 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Sony
2008-03-01 19:38 --------- d-----w C:\Program Files\MSBuild
2008-03-01 19:34 --------- d-----w C:\Program Files\Reference Assemblies
2008-03-01 19:21 --------- d-----w C:\Program Files\Sony Setup
2008-03-01 19:21 --------- d-----w C:\Documents and Settings\Steve.STEVESPC\Application Data\Sony Setup
2008-03-01 18:25 360,064 ----a-w C:\WINDOWS\system32\drivers\TCPIP.SYS.ORIGINAL
2008-03-01 17:55 --------- d-----w C:\Program Files\DVD Region+CSS Free
2008-03-01 17:35 47,360 ----a-w C:\WINDOWS\system32\drivers\pcouffin.sys
2008-03-01 17:35 47,360 ------w C:\Documents and Settings\Steve.STEVESPC\Application Data\pcouffin.sys
2008-03-01 17:35 --------- d-----w C:\Program Files\vso
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\SYSTEM32\wininet.dll
2008-03-01 11:49 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-03-01 07:03 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-01 07:03 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\WLInstaller
2008-02-27 05:25 --------- d-----w C:\Program Files\Windows Live
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\SYSTEM32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\SYSTEM32\dnsrslvr.dll
2007-06-10 07:04 284 ------w C:\Documents and Settings\Steve.STEVESPC\Application Data\ViewerApp.dat
2002-07-01 14:13 243 --sha-w C:\Documents and Settings\All Users.WINDOWS\Application Data\system16driver.dat
2002-04-03 05:01 286,720 -c--a-w C:\Program Files\internet explorer\plugins\PanoViewer.dll
1999-04-30 06:00 98,304 -c--a-w C:\Program Files\internet explorer\plugins\UPjpeg.dll
2007-07-07 06:29 80 --sh--r C:\WINDOWS\SYSTEM32\B5D296F3CC.dll
.
------- Sigcheck -------
2006-04-20 22:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
2007-10-31 02:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2004-08-12 23:30 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
2007-01-06 14:00 359808 8d8949936913b041c6a0e184fbf1030b C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
2008-03-20 15:51 360064 482ab7f9cd41702e8f856c11cfefb02d C:\WINDOWS\SYSTEM32\DLLCACHE\TCPIP.SYS
2008-03-20 15:51 360064 482ab7f9cd41702e8f856c11cfefb02d C:\WINDOWS\SYSTEM32\DRIVERS\TCPIP.SYS
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 10:34 5724184]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-12 23:18 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"P17Helper"="P17.dll" [2005-05-03 11:38 64512 C:\WINDOWS\SYSTEM32\P17.dll]
"DVD43"="C:\PROGRA~1\DVDREG~1\DVDRegionFree.exe" [2006-08-03 17:38 259072]
"CAVRID"="C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2008-03-09 09:46 230928]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-03-20 17:40 213936]
"cctray"="C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe" [2008-03-09 09:46 177416]
"EPSON Stylus Photo RX530 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAGP.exe" [2005-04-07 14:00 98304]
"TrojanScanner"="C:\Program Files\Trojan Remover\Trjscan.exe" [2008-04-07 19:51 873040]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{93994DE8-8239-4655-B1D1-5F4E91300429}"= C:\PROGRA~1\DVDREG~1\DVDShell.dll [2004-10-09 15:18 49152]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
path=C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
backup=C:\WINDOWS\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2004-08-12 23:18 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
--a------ 2003-09-17 10:43 57344 C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVD43]
--a------ 2006-08-03 17:38 259072 C:\PROGRA~1\DVDREG~1\DVDRegionFree.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eTrustPPAP]
C:\Program Files\CA\eTrust PestPatrol\PPActiveDetection.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H2O]
--a------ 2005-10-23 00:00 385024 C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
C:\Program Files\Nero\Nero 7\InCD\InCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iPlusAgent2]
C:\Program Files\iriver\iriver plus 2\iAgent2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM]
--a------ 2006-03-20 17:40 213936 C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Media Codec Update Service]
C:\Program Files\Essentials Codec Pack\update.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
--a------ 2007-05-30 11:34 5419008 C:\Program Files\MySpace\IM\MySpaceIM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
--a------ 2003-07-13 01:49 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2003-07-13 01:49 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NWEReboot]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-04-27 09:41 282624 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
--a------ 2006-11-10 12:35 90112 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files\Steam\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-09-25 00:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
-ra--c--- 2005-08-19 04:49 307200 C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
-----c--- 2000-05-11 01:00 90112 C:\WINDOWS\UpdReg.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"GEARSecurity"=2 (0x2)
"usnjsvc"=3 (0x3)
"StarWindService"=2 (0x2)
"LxrSII1s"=2 (0x2)
"IviRegMgr"=2 (0x2)
"CaCCProvSP"=3 (0x3)
"ATI Smart"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
"gusvc"=3 (0x3)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe
"PC Suite Tray"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
"C:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\Winamp\\winamp.exe"=
"C:\\Documents and Settings\\Steve.STEVESPC\\My Documents\\EXE FILES\\utorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\SYSTEM32\\dplaysvr.exe"=
"C:\\Documents and Settings\\Steve.STEVESPC\\My Documents\\GP4\\GP4.exe"=
"C:\\Program Files\\InterVideo\\DVD8\\WinDVD.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Documents and Settings\\Steve.STEVESPC\\My Documents\\Blazing Angels Squadrons of WWII\\bin\\MainR.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
R2 LxrSII1d;Secure II Driver;C:\WINDOWS\system32\Drivers\LxrSII1d.sys [2005-05-19 15:48]
R3 CLEDX;Team H2O CLEDX service;C:\WINDOWS\system32\DRIVERS\cledx.sys [2005-05-09 20:08]
R3 Dvd43;Dvd43;C:\WINDOWS\system32\DRIVERS\Dvd43.sys [2008-04-14 20:09]
S3 ICAM3NT5;Intel USB Video Camera III;C:\WINDOWS\system32\Drivers\Icam3.sys [2001-08-17 13:05]
S3 MA_CMIDI;M-Audio USB Driver;C:\WINDOWS\system32\drivers\ma_cmidi.sys [2007-11-14 15:20]
S3 sonypvs1;Sony Digital Imaging Video2;C:\WINDOWS\system32\DRIVERS\sonypvs1.sys [2002-10-15 22:41]
*Newly Created Service* - CATCHME
*Newly Created Service* - SWPRV
*Newly Created Service* - VSS
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-04-20 01:38:48
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 160
**************************************************************************
.
Completion time: 2008-04-20 1:40:25
ComboFix-quarantined-files.txt 2008-04-19 15:40:07
ComboFix2.txt 2008-04-19 14:15:16
Pre-Run: 17,302,884,352 bytes free
Post-Run: 17,291,849,728 bytes free
294 --- E O F --- 2008-04-12 14:45:25
the results from Kaspersky
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Sunday, April 20, 2008 3:35:31 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 19/04/2008
Kaspersky Anti-Virus database records: 715414
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 168428
Number of viruses found: 4
Number of infected objects: 11
Number of suspicious objects: 0
Duration of the scan process: 01:48:40
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\DSS\MachineKeys\08dc74d04d0c814cb3db0258ea52253f_50e417e0-e461-474b-96e2-077b80325612 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Steve.STEVESPC\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Steve.STEVESPC\Local Settings\Application Data\Microsoft\CardSpace\CardSpace.db Object is locked skipped
C:\Documents and Settings\Steve.STEVESPC\Local Settings\Application Data\Microsoft\CardSpace\CardSpace.db.shadow Object is locked skipped
C:\Documents and Settings\Steve.STEVESPC\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\Steve.STEVESPC\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Steve.STEVESPC\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Steve.STEVESPC\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Steve.STEVESPC\Local Settings\History\History.IE5\MSHist012008042020080421\index.dat Object is locked skipped
C:\Documents and Settings\Steve.STEVESPC\Local Settings\Temp\~DF2C65.tmp Object is locked skipped
C:\Documents and Settings\Steve.STEVESPC\Local Settings\Temp\~DFAF6F.tmp Object is locked skipped
C:\Documents and Settings\Steve.STEVESPC\Local Settings\Temp\~DFE7BD.tmp Object is locked skipped
C:\Documents and Settings\Steve.STEVESPC\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Steve.STEVESPC\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Steve.STEVESPC\ntuser.dat Object is locked skipped
C:\Documents and Settings\Steve.STEVESPC\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Outlook Express\svchost.exe Infected: Trojan-Downloader.Win32.Delf.ghp skipped
C:\QooBox\Quarantine\C\VundoFix Backups\hgGyYRJc.dll.bad.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.oax skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\hgGyYRJc.dll.vir.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.oax skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\kbbytwbx.dll.vir.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.pjx skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{9FCE5156-1BED-4CFF-AE68-BC30B8633F8F}\RP803\A0122511.exe/data0000.cab/is152510.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.oax skipped
C:\System Volume Information\_restore{9FCE5156-1BED-4CFF-AE68-BC30B8633F8F}\RP803\A0122511.exe/data0000.cab Infected: not-a-virus:AdWare.Win32.Virtumonde.oax skipped
C:\System Volume Information\_restore{9FCE5156-1BED-4CFF-AE68-BC30B8633F8F}\RP803\A0122511.exe Rsrc-Package: infected - 2 skipped
C:\System Volume Information\_restore{9FCE5156-1BED-4CFF-AE68-BC30B8633F8F}\RP803\A0122527.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.pke skipped
C:\System Volume Information\_restore{9FCE5156-1BED-4CFF-AE68-BC30B8633F8F}\RP804\A0122564.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.pke skipped
C:\System Volume Information\_restore{9FCE5156-1BED-4CFF-AE68-BC30B8633F8F}\RP806\A0122865.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.oax skipped
C:\System Volume Information\_restore{9FCE5156-1BED-4CFF-AE68-BC30B8633F8F}\RP806\A0122911.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.pjx skipped
C:\System Volume Information\_restore{9FCE5156-1BED-4CFF-AE68-BC30B8633F8F}\RP807\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\SYSTEM32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\SYSTEM32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\ACEEvent.evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\default Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\default.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\Internet.evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\software Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\software.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\system Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\system.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\DRIVERS\sptd.sys Object is locked skipped
C:\WINDOWS\SYSTEM32\DRIVERS\sptd1581.sys Object is locked skipped
C:\WINDOWS\SYSTEM32\h323log.txt Object is locked skipped
C:\WINDOWS\SYSTEM32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\SYSTEM32\MsDtc\MSDTC.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\MsDtc\Trace\dtctrace.log Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
Results from HiJackThis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:36:33 AM, on 4/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HJT.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 192.168.1.1
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [DVD43] C:\PROGRA~1\DVDREG~1\DVDRegionFree.exe /hidden
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [EPSON Stylus Photo RX530 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAGP.EXE /P31 "EPSON Stylus Photo RX530 Series" /O6 "USB001" /M "Stylus Photo RX530"
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0000000A-0000-0010-8000-00AA00389B71} -
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) -
http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} -
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) -
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) -
http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7B2E7556-1EA5-4D8C-B26F-2B659F83C3A6}: NameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{A0D347F8-0A6B-4BB3-A78A-1DDE445B522A}: NameServer = 192.168.1.1
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
--
End of file - 6391 bytes