appears to be fixed
I ran all the steps listed. I needed to hook up the internet to get updates for mbam, and then I forgot to unhook it. After all the scan got done, I noticed that Windows had found an update, so apparently that problem is solved. (I didn't install the update yet) Below are the scan logs requested. Please let me know if you find anything. Otherwise I will assume things are running well, and I will install the windows updates and the regular Messenger. Please let me know if there are other steps I should take first.
Both us of thank you greatly for your assistance!
Here is the combofix log:
ComboFix 08-09-13.05 - Owner 2008-09-14 15:48:31.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.533 [GMT -5:00]
Running from: C:\Documents and Settings\Owner.Upstairs07\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner.Upstairs07\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\412splashfree.png
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\414splashfree.png
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\certificate\limewire.keystore
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\createtimes.cache
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\data.ser
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\downloads.dat
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\fileurns.bak
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\fileurns.cache
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\filters.props
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\gnutella.net
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\installation.props
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\library.dat
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\limewire.props
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\mojito.props
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\promotion\promodb.backup
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\promotion\promodb.data
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\promotion\promodb.lck
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\promotion\promodb.log
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\promotion\promodb.properties
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\promotion\promodb.script
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\pub1.key
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\public.key
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\questions.props
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\responses.cache
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\secureMessage.key
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\simpp.xml
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\spam.dat
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\tables.props
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\black_theme.lwtp
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\black_theme\
01_star.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\black_theme\
02_star.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\black_theme\
03_star.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\black_theme\
04_star.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\black_theme\
05_star.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\black_theme\chat.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\black_theme\dir_closed.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\black_theme\dir_open.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\black_theme\forward_dn.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\black_theme\forward_up.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\black_theme\kill.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\black_theme\kill_on.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\black_theme\lime.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\black_theme\logo.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\black_theme\notsearching.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\black_theme\pause_dn.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\black_theme\pause_up.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\black_theme\play_dn.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\black_theme\play_up.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\black_theme\question.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\black_theme\rewind_dn.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\black_theme\rewind_up.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\black_theme\searching.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\black_theme\splash.png
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\black_theme\splashpro.png
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\black_theme\stop_dn.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\black_theme\stop_up.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\black_theme\theme.txt
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\black_theme\version.txt
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\black_theme\warning.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\classic_theme.lwtp
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\classic_theme\
01_star.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\classic_theme\
02_star.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\classic_theme\
03_star.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\classic_theme\
04_star.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\classic_theme\
05_star.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\classic_theme\chat.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\classic_theme\dir_closed.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\classic_theme\dir_open.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\classic_theme\forward_dn.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\classic_theme\forward_up.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\classic_theme\kill.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\classic_theme\logo.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\classic_theme\notsearching.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\classic_theme\pause_dn.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\classic_theme\pause_up.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\classic_theme\play_dn.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\classic_theme\play_up.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\classic_theme\question.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\classic_theme\rewind_dn.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\classic_theme\rewind_up.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\classic_theme\search.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\classic_theme\searching.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\classic_theme\splash.png
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\classic_theme\splashpro.png
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\classic_theme\stop_dn.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\classic_theme\stop_up.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\classic_theme\theme.txt
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\classic_theme\warning.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\limewire_theme.lwtp
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\limewire_theme\
01_star.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\limewire_theme\
02_star.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\limewire_theme\
03_star.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\limewire_theme\
04_star.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\limewire_theme\
05_star.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\limewire_theme\chat.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\limewire_theme\dir_closed.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\limewire_theme\dir_open.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\limewire_theme\forward_dn.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\limewire_theme\forward_up.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\limewire_theme\kill.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\limewire_theme\kill_on.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\limewire_theme\lime.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\limewire_theme\logo.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\limewire_theme\notsearching.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\limewire_theme\pause_dn.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\limewire_theme\pause_up.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\limewire_theme\play_dn.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\limewire_theme\play_up.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\limewire_theme\question.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\limewire_theme\rewind_dn.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\limewire_theme\rewind_up.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\limewire_theme\searching.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\limewire_theme\splash.png
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\limewire_theme\splashpro.png
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\limewire_theme\stop_dn.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\limewire_theme\stop_up.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\limewire_theme\theme.txt
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\limewire_theme\warning.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\other_theme.lwtp
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\other_theme\
01_star.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\other_theme\
02_star.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\other_theme\
03_star.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\other_theme\
04_star.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\other_theme\
05_star.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\other_theme\chat.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\other_theme\forward_dn.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\other_theme\forward_up.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\other_theme\kill.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\other_theme\kill_on.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\other_theme\logo.png
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\other_theme\name.txt
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\other_theme\notsearching.png
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\other_theme\pause_dn.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\other_theme\pause_up.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\other_theme\play_dn.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\other_theme\play_up.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\other_theme\question.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\other_theme\rewind_dn.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\other_theme\rewind_up.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\other_theme\searching.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\other_theme\splash.png
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\other_theme\splashpro.png
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\other_theme\stop_dn.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\other_theme\stop_up.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\other_theme\theme.txt
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\other_theme\warning.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme.lwtp
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\
01_star.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\
02_star.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\
03_star.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\
04_star.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\
05_star.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\author.txt
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\button1.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\button1_press.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\button2.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\button2_press.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\button3.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\button3_press.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\button4.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\button4_press.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\button5.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\button5_press.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\chat.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\connections.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\dir_closed.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\dir_open.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\forward_dn.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\forward_up.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\kill.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\kill_on.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\library.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\logo.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\monitor.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\notsearching.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\pause_dn.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\pause_up.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\play_dn.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\play_up.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\plug.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\question.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\rewind_dn.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\rewind_up.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\search.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\searching.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\shopping.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\splash.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\stop_dn.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\stop_up.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\theme.txt
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\version.txt
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\pink_and_black_theme\warning.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\windows_theme.lwtp
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\windows_theme\
01_star.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\windows_theme\
02_star.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\windows_theme\
03_star.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\windows_theme\
04_star.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\windows_theme\
05_star.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\windows_theme\chat.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\windows_theme\forward_dn.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\windows_theme\forward_up.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\windows_theme\kill.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\windows_theme\kill_on.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\windows_theme\logo.png
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\windows_theme\notsearching.png
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\windows_theme\pause_dn.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\windows_theme\pause_up.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\windows_theme\play_dn.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\windows_theme\play_up.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\windows_theme\question.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\windows_theme\rewind_dn.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\windows_theme\rewind_up.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\windows_theme\searching.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\windows_theme\splash.png
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\windows_theme\splashpro.png
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\windows_theme\stop_dn.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\windows_theme\stop_up.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\windows_theme\theme.txt
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\windows_theme\version.txt
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\themes\windows_theme\warning.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\ttree.cache
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\ttrees.cache
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\ttroot.cache
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\update.xml
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\version.key
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\version.xml
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\versions.props
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\xml\data\audio.sxml2
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\xml\data\delete_me
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\xml\data\video.sxml2
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\xml\misc\application.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\xml\misc\audio.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\xml\misc\document.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\xml\misc\image.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\xml\misc\video.gif
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\xml\schemas\application.xsd
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\xml\schemas\audio.xsd
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\xml\schemas\document.xsd
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\xml\schemas\image.xsd
C:\Documents and Settings\Owner.Upstairs07\Application Data\LimeWire\xml\schemas\video.xsd
C:\Program Files\LimeWire
C:\Program Files\LimeWire\donotremove.htm
C:\Program Files\LimeWire\GenericWindowsUtils.dll
C:\Program Files\LimeWire\hashes
C:\Program Files\LimeWire\i18n.jar
C:\Program Files\LimeWire\LimeWire20.dll
C:\Program Files\LimeWire\log4j.properties
C:\Program Files\LimeWire\MessagesBundle.properties
C:\Program Files\LimeWire\update.ver
C:\Program Files\LimeWire\WindowsFirewall.dll
C:\Program Files\LimeWire\WindowsV5PlusUtils.dll
C:\Program Files\LimeWire\xerces.jar
C:\Program Files\LimeWire\xml-apis.jar
.
((((((((((((((((((((((((( Files Created from 2008-08-14 to 2008-09-14 )))))))))))))))))))))))))))))))
.
2008-09-08 22:46 . 2008-09-08 22:46 <DIR> d-------- C:\Program Files\Trend Micro
2008-09-08 21:41 . 2008-09-08 21:42 <DIR> d-------- C:\Program Files\Spyware Doctor
2008-09-08 21:41 . 2008-09-08 21:41 <DIR> d-------- C:\Documents and Settings\Owner.Upstairs07\Application Data\PC Tools
2008-09-08 21:41 . 2008-08-25 11:36 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-09-08 21:41 . 2008-08-25 11:36 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-09-08 21:41 . 2008-08-25 11:36 40,840 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-09-08 21:41 . 2008-06-02 15:19 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-09-07 23:26 . 2008-09-08 07:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Hazard Shield
2008-09-07 23:25 . 2008-09-07 23:26 <DIR> d-------- C:\Program Files\Hazard Shield
2008-09-07 13:38 . 2008-09-07 19:07 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2008-09-06 10:43 . 2008-09-06 10:43 <DIR> d-------- C:\Program Files\Safari
2008-09-06 10:43 . 2008-09-06 10:44 <DIR> d-------- C:\Program Files\RegCure
2008-09-04 07:17 . 2008-07-18 22:09 25,800 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-09-02 20:58 . 2008-09-02 20:58 <DIR> d-------- C:\WINDOWS\system32\wTR02
2008-09-02 20:58 . 2008-09-02 20:58 <DIR> d-------- C:\Temp\dax41
2008-09-02 20:58 . 2008-09-02 20:58 <DIR> d-------- C:\Temp
2008-09-02 20:56 . 2008-09-02 20:56 <DIR> d-------- C:\Documents and Settings\Owner.Upstairs07\Application Data\Screenshot Sender
2008-08-15 14:27 . 2008-08-15 14:46 <DIR> d-------- C:\Program Files\ManyCam 2.3
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-14 20:41 --------- d-----w C:\Program Files\Common Files\Nullsoft
2008-09-14 20:41 --------- d-----w C:\Program Files\Common Files\AOL
2008-09-13 19:25 --------- d-----w C:\Program Files\McAfee
2008-09-09 03:10 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-08 01:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-08 00:22 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-09-06 14:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-08-22 19:12 --------- d-----w C:\Documents and Settings\Owner.Upstairs07\Application Data\Apple Computer
2008-08-15 19:46 --------- d-----w C:\Program Files\ManyCam 2.2
2008-08-10 17:28 --------- d-----w C:\Program Files\Oberon Media
2008-08-10 04:35 --------- d-----w C:\Program Files\Apple Software Update
2008-08-05 13:15 --------- d-----w C:\Program Files\Java
2008-08-05 02:29 --------- d-----w C:\Documents and Settings\Owner.Upstairs07\Application Data\SiteAdvisor
2008-08-03 23:45 --------- d-----w C:\Program Files\iTunes
2008-08-03 23:45 --------- d-----w C:\Program Files\iPod
2008-07-07 20:26 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-06-24 16:43 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 16:57 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:46 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="NA" [X]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"PMCRemote"="C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe" [2007-02-12 253000]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 64512]
"readericon"="C:\Program Files\Digital Media Reader\readericon45G.exe" [2005-12-09 139264]
"Reminder"="C:\WINDOWS\Creator\Remind_XP.exe" [2005-02-25 966656]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-11-30 7311360]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6261\SiteAdv.exe" [2007-03-30 36904]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-05-17 505368]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" [2007-05-17 780312]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-11-30 86016]
"PhiBtn"="C:\WINDOWS\System32\drivers\PhiBtn.exe" [2005-08-25 155648]
"Traymin900"="C:\WINDOWS\System32\drivers\Tray900.exe" [2005-08-25 266240]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-04 582992]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 413696]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 116040]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-02 C:\WINDOWS\arpwrmsg.exe]
"CHotkey"="zHotkey.exe" [2004-12-08 C:\WINDOWS\zHotkey.exe]
"RTHDCPL"="RTHDCPL.EXE" [2005-11-09 C:\WINDOWS\RTHDCPL.exe]
"nwiz"="nwiz.exe" [2005-11-30 C:\WINDOWS\system32\nwiz.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
BigFix.lnk - C:\Program Files\BigFix\bigfix.exe [2007-02-07 2348584]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.clmp3enc"= C:\PROGRA~1\CYBERL~1\Power2Go\CLMP3Enc.ACM
"aux1"= ctwdm32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\StubInstaller.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\WINDOWS\\system32\\rtcshare.exe"=
"C:\\Program Files\\utorrent\\utorrent.exe"=
"C:\\Program Files\\Hasbro Interactive\\Classic Games\\ClassicBoard.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;C:\WINDOWS\system32\DRIVERS\ManyCam.sys [2008-01-14 21632]
S3 camvid40;Philips SPC 900NC PC Camera;C:\WINDOWS\system32\DRIVERS\camdrv41.sys [2005-08-25 1240576]
S3 USB28xxBGA;PCTV 330e/800e Device;C:\WINDOWS\system32\DRIVERS\emBDA.sys [2007-01-29 361728]
S3 USB28xxOEM;USB 28xx OEM Filter;C:\WINDOWS\system32\DRIVERS\emOEM.sys [2007-01-29 39680]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{12aa1c33-b6e3-11db-af3e-806d6172696f}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
.
Contents of the 'Scheduled Tasks' folder
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-09-14 15:51:48
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-09-14 15:53:39
ComboFix-quarantined-files.txt 2008-09-14 20:53:31
ComboFix2.txt 2008-09-14 16:45:13
ComboFix3.txt 2008-09-14 16:36:10
Pre-Run: 185,133,006,848 bytes free
Post-Run: 185,110,835,200 bytes free
395 --- E O F --- 2008-08-15 20:17:36
HERE IS THE MBAM LOG:
Malwarebytes' Anti-Malware 1.28
Database version: 1152
Windows 5.1.2600 Service Pack 3
9/14/2008 5:03:08 PM
mbam-log-2008-09-14 (17-03-08).txt
Scan type: Full Scan (C:\|D:\|)
Objects scanned: 175293
Time elapsed: 54 minute(s), 44 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 26
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\WINDOWS\system32\wTR02 (Trojan.Agent) -> Quarantined and deleted successfully.
Files Infected:
C:\regxpcom.exe (Trojan.FBrowsingAdvisor) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\aeghdhkt.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\bslgchpe.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\mlhkcd.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\rflrxhrv.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\vijqdj.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4E015214-6BB0-4181-B365-456CF1DEC069}\RP434\A0091472.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4E015214-6BB0-4181-B365-456CF1DEC069}\RP434\A0091475.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4E015214-6BB0-4181-B365-456CF1DEC069}\RP434\A0091481.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4E015214-6BB0-4181-B365-456CF1DEC069}\RP434\A0091482.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4E015214-6BB0-4181-B365-456CF1DEC069}\RP434\A0091509.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4E015214-6BB0-4181-B365-456CF1DEC069}\RP434\A0091538.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4E015214-6BB0-4181-B365-456CF1DEC069}\RP434\A0091539.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4E015214-6BB0-4181-B365-456CF1DEC069}\RP434\A0091540.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4E015214-6BB0-4181-B365-456CF1DEC069}\RP435\A0091976.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4E015214-6BB0-4181-B365-456CF1DEC069}\RP435\A0091980.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4E015214-6BB0-4181-B365-456CF1DEC069}\RP435\A0092071.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4E015214-6BB0-4181-B365-456CF1DEC069}\RP436\A0094292.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4E015214-6BB0-4181-B365-456CF1DEC069}\RP437\A0094362.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4E015214-6BB0-4181-B365-456CF1DEC069}\RP438\A0094523.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4E015214-6BB0-4181-B365-456CF1DEC069}\RP440\A0094584.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4E015214-6BB0-4181-B365-456CF1DEC069}\RP440\A0094585.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4E015214-6BB0-4181-B365-456CF1DEC069}\RP440\A0094588.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4E015214-6BB0-4181-B365-456CF1DEC069}\RP440\A0094592.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4E015214-6BB0-4181-B365-456CF1DEC069}\RP440\A0094593.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{4E015214-6BB0-4181-B365-456CF1DEC069}\RP382\A0071765.dll (Trojan.FBrowsingAdvisor) -> Quarantined and deleted successfully.
HERE IS THE HJT LOG:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:04:31 PM, on 9/14/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Digital Media Reader\readericon45G.exe
C:\WINDOWS\zHotkey.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\SiteAdvisor\6261\SiteAdv.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\WINDOWS\System32\drivers\PhiBtn.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe
C:\Program Files\BigFix\bigfix.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\arservice.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\SiteAdvisor\6261\SAService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\wscntfy.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://runonce.msn.com/?v=msgrv75
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6261\SiteAdv.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [PhiBtn] %SystemRoot%\System32\drivers\PhiBtn.exe
O4 - HKLM\..\Run: [Traymin900] %SystemRoot%\System32\drivers\Tray900.exe
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Power2GoExpress] NA
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PMCRemote] C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe
O8 - Extra context menu item: &Search - ?p=ZJxdm028YYUS
O8 - Extra context menu item: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) -
http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5036.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1181600828421
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) -
http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) -
http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6261\SAService.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 9938 bytes