ComboFix 08-06-08.8 - Des 2008-06-12 18:25:21.3 - NTFSx86
Running from: C:\Documents and Settings\Des\Desktop\Combo-Fix.exe
Command switches used :: C:\Documents and Settings\Des\Desktop\CFScript.txt
FILE ::
C:\Documents and Settings\All Users\setupneoaudio-cnet.exe
C:\Documents and Settings\Des\csetup_neonapster.exe
C:\Documents and Settings\Des\My Documents\parkend121\backups\backup-20070613-004426-229.dll
C:\Documents and Settings\Yvonne\Local Settings\Application DataKiweeToolbar1.2.116.msi
C:\Downloads\TorrentSoftware-4.2.0.0-setup-0270.exe
C:\WINDOWS\Downloaded Program Files\flash.inf
C:\WINDOWS\system32\drivers\etc\hosts.20080225-011914.backup
C:\WINDOWS\system32\drivers\etc\hosts.20080310-093619.backup
C:\WINDOWS\system32\drivers\etc\hosts.20080419-162908.backup
C:\WINDOWS\system32\drivers\etc\hosts.20080524-152036.backup
C:\WINDOWS\system32\drivers\etc\hosts.20080530-230348.backup
C:\WINDOWS\system32\drivers\etc\hosts.20080606-202500.backup
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\ADMIN HOLE REF RULE
C:\Documents and Settings\All Users\Application Data\ADMIN HOLE REF RULE\32 Bike Sixth
C:\Documents and Settings\All Users\Application Data\ADMIN HOLE REF RULE\Antiaxissoft
C:\Documents and Settings\All Users\Application Data\ADMIN HOLE REF RULE\Boltdumb.exe
C:\Documents and Settings\All Users\setupneoaudio-cnet.exe
C:\Documents and Settings\Des\csetup_neonapster.exe
C:\Documents and Settings\Des\My Documents\parkend121\backups\backup-20070613-004426-229.dll
C:\Documents and Settings\Yvonne\Local Settings\Application DataKiweeToolbar1.2.116.msi
C:\Downloads\TorrentSoftware-4.2.0.0-setup-0270.exe
C:\WINDOWS\Downloaded Program Files\flash.inf
C:\WINDOWS\system32\drivers\etc\hosts.20080225-011914.backup
C:\WINDOWS\system32\drivers\etc\hosts.20080310-093619.backup
C:\WINDOWS\system32\drivers\etc\hosts.20080419-162908.backup
C:\WINDOWS\system32\drivers\etc\hosts.20080524-152036.backup
C:\WINDOWS\system32\drivers\etc\hosts.20080530-230348.backup
C:\WINDOWS\system32\drivers\etc\hosts.20080606-202500.backup
.
((((((((((((((((((((((((( Files Created from 2008-05-12 to 2008-06-12 )))))))))))))))))))))))))))))))
.
2008-06-12 18:15 . 2008-06-12 18:15 <DIR> d--hs---- C:\Documents and Settings\TEMP
2008-06-11 01:10 . 2008-06-11 01:52 <DIR> d-------- C:\Documents and Settings\Des\Application Data\Symantec
2008-06-11 01:07 . 2008-06-11 01:07 <DIR> d-------- C:\Program Files\Windows Sidebar
2008-06-11 01:06 . 2008-06-11 01:14 <DIR> d-------- C:\Program Files\Norton 360 Online
2008-06-09 22:08 . 2008-06-09 22:08 <DIR> d-------- C:\WINDOWS\Sun
2008-06-09 21:53 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-06-09 21:52 . 2008-06-09 21:53 <DIR> d-------- C:\Program Files\Java
2008-06-09 21:51 . 2008-06-09 21:51 <DIR> d-------- C:\Program Files\Common Files\Java
2008-06-09 18:38 . 2008-06-09 18:38 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-08 04:20 . 2008-06-08 04:20 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Yahoo!
2008-06-07 17:38 . 2008-06-10 18:27 <DIR> d-------- C:\Kontiki
2008-06-05 00:34 . 2008-06-05 00:34 0 --a------ C:\WINDOWS\vpc32.INI
2008-06-03 22:33 . 2008-06-03 22:33 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-06-03 22:33 . 2008-06-03 22:33 1,409 --a------ C:\WINDOWS\QTFont.for
2008-06-03 02:20 . 2008-06-03 02:20 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-05-31 21:24 . 2008-05-31 21:24 154 --a------ C:\WINDOWS\adidsl.ini
2008-05-31 21:24 . 2008-05-31 21:24 21 --a------ C:\WINDOWS\Fast800.ini
2008-05-31 21:23 . 2008-05-31 21:23 <DIR> d-------- C:\Program Files\SAGEM
2008-05-26 19:30 . 2004-02-05 11:52 53,248 --a------ C:\WINDOWS\setFireWall.exe
2008-05-26 19:30 . 2003-12-05 15:09 2,238 --a------ C:\WINDOWS\tiscali04.ico
2008-05-26 18:50 . 2003-01-30 13:46 28,672 -ra------ C:\WINDOWS\system32\adinst32.dll
2008-05-26 18:45 . 2008-05-31 21:24 184 --a------ C:\setuplog.exe
2008-05-26 16:44 . 2008-05-26 18:44 <DIR> d-------- C:\Program Files\Tiscali Broadband
2008-05-26 16:44 . 2004-01-23 12:51 2,238 --a------ C:\WINDOWS\TiscaliHelp04.ico
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-12 17:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kontiki
2008-06-12 17:32 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-06-11 00:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-06-11 00:23 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-06-11 00:23 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2008-06-11 00:23 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-06-11 00:23 10,671 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-06-11 00:23 --------- d-----w C:\Program Files\Symantec
2008-06-10 22:59 --------- d-----w C:\Documents and Settings\Des\Application Data\Free Download Manager
2008-06-04 19:33 --------- d-----w C:\Program Files\Oberon Media
2008-06-04 19:31 --------- d-----w C:\Program Files\Yahoo!
2008-06-01 13:26 --------- d-----w C:\Program Files\Norton Security Scan
2008-05-31 20:24 23 ----a-w C:\WINDOWS\system32\drivers\adidsl.cfg
2008-05-31 20:23 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-31 11:49 --------- d-----w C:\Program Files\Replay Media Catcher
2008-05-26 19:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-25 13:07 --------- d-----w C:\Program Files\McDonaldsDragons
2008-05-25 13:06 --------- d-----w C:\Program Files\McDonaldsFairies
2008-05-20 19:30 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-05-12 18:02 --------- d-----w C:\Documents and Settings\Yvonne\Application Data\Free Download Manager
2008-05-03 10:32 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-30 17:21 --------- d-----w C:\Program Files\BitTorrent
2008-04-26 19:40 --------- d-----w C:\Documents and Settings\Yvonne\Application Data\BitTorrent
2008-04-19 16:45 --------- d-----w C:\Program Files\Kiwee Toolbar2
2008-04-19 16:44 --------- d-----w C:\Program Files\MSN Messenger
2008-04-19 10:55 --------- d-----w C:\Documents and Settings\Yvonne\Application Data\PlayFirst
2008-04-19 10:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\PlayFirst
2008-04-19 10:54 --------- d-----w C:\Program Files\Common Files\Oberon Media
2008-04-15 19:49 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-13 08:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-27 08:12 151,583 ------w C:\WINDOWS\system32\dllcache\msjint40.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-19 09:47 1,845,248 ------w C:\WINDOWS\system32\dllcache\win32k.sys
2008-02-17 11:29 3,955,352 ----a-w C:\Program Files\FLV PlayerRCATSetup.exe
2008-02-17 11:26 411,248 ----a-w C:\Program Files\FLV PlayerRCSetup.exe
2006-10-29 18:05 3,638 ----a-w C:\Program Files\favicon.ico
2005-02-25 21:41 116,312 ----a-w C:\Documents and Settings\Yvonne\Application Data\GDIPFONTCACHEV1.DAT
2004-11-17 22:26 116,312 ----a-w C:\Documents and Settings\Des\Application Data\GDIPFONTCACHEV1.DAT
2004-10-23 19:21 284 ----a-w C:\Documents and Settings\Des\Application Data\ViewerApp.dat
2004-10-04 18:23 35,969,278 ----a-w C:\Program Files\NIS71000IN.exe
2003-11-05 00:02 217,329 ----a-w C:\Documents and Settings\Des\gspot221.exe
2003-10-16 19:51 390,312 ----a-w C:\Documents and Settings\Des\setupscreenhunterfree.exe
2003-10-12 21:17 2,835,552 ----a-w C:\Documents and Settings\Des\PlusPAD.exe
2003-10-02 20:15 1,044,168 ----a-w C:\Documents and Settings\Des\VBRun60sp5.exe
2003-09-26 20:28 5,787,083 ----a-w C:\Documents and Settings\Des\klickwizard_v2.exe
2003-09-18 19:12 3,326,820 ----a-w C:\Documents and Settings\Des\klitekpp242e.exe
2003-08-21 20:32 143,040 ----a-w C:\Documents and Settings\Des\FixBlast.exe
2003-07-07 22:32 628,746 ----a-w C:\Documents and Settings\Des\cubebuster.exe
2003-06-16 00:09 1,540,293 ----a-w C:\Documents and Settings\All Users\aaw6.exe
2003-06-13 23:18 4,808,199 ----a-w C:\Documents and Settings\All Users\DjVuWebBrowserPlugin.exe
2003-06-09 21:10 3,563,166 ----a-w C:\Documents and Settings\All Users\klcodec203b.exe
2003-06-09 21:03 3,005,176 ----a-w C:\Documents and Settings\All Users\klitekpp210b3e.exe
2003-05-30 22:38 1,722,883 ----a-w C:\Documents and Settings\All Users\nopopupin.exe
2003-05-28 23:39 1,736,232 ----a-w C:\Documents and Settings\All Users\PDivXNG311.exe
2003-05-28 22:22 7,168 ----a-w C:\Program Files\vdremote.dll
2003-05-28 22:22 6,656 ----a-w C:\Program Files\vdicmdrv.dll
2003-05-28 22:22 16,384 ----a-w C:\Program Files\auxsetup.exe
2003-05-28 22:21 74,195 ----a-w C:\Program Files\VirtualDub.vdhelp
2003-05-28 22:21 69,370 ----a-w C:\Program Files\VirtualDub.vdi
2003-05-28 22:21 507,904 ----a-w C:\Program Files\VirtualDub.exe
2003-05-28 22:21 5,120 ----a-w C:\Program Files\vdsvrlnk.dll
2003-05-27 22:19 616,631 ----a-w C:\Documents and Settings\All Users\Popup_Blocker.exe
2003-05-26 23:05 11,047,248 ----a-w C:\Documents and Settings\All Users\QuickTimeInstaller.zip
2003-05-25 15:20 792,506 ----a-w C:\Documents and Settings\All Users\regcln41.exe
2003-05-18 19:50 2,955,952 ----a-w C:\Documents and Settings\All Users\ymsgruk.exe
2003-05-17 13:05 2,438,895 ----a-w C:\Documents and Settings\Des\efc_pc_screensaver_1052866890.exe
2003-05-17 13:02 1,427,620 ----a-w C:\Documents and Settings\Des\davey_install_1.0.exe
2003-05-09 18:37 770,048 ----a-w C:\Documents and Settings\Des\winmx331.exe
2003-05-09 00:51 6,285,328 ----a-w C:\Documents and Settings\Des\Update_OMG2210.exe
2003-05-09 00:46 9,892,744 ----a-w C:\Documents and Settings\Des\OpenMGSetup31.exe
2003-02-22 00:09 18,321 ----a-w C:\Program Files\copying
2003-03-12 04:16 307,200 ----a-w C:\Program Files\internet explorer\plugins\djvu0407.dll
2003-03-12 04:16 303,104 ----a-w C:\Program Files\internet explorer\plugins\djvu0409.dll
2003-03-12 04:16 311,296 ----a-w C:\Program Files\internet explorer\plugins\djvu040c.dll
2003-03-12 04:16 299,008 ----a-w C:\Program Files\internet explorer\plugins\djvu0411.dll
2003-03-12 04:16 303,104 ----a-w C:\Program Files\internet explorer\plugins\djvu0412.dll
2003-03-12 04:16 290,816 ----a-w C:\Program Files\internet explorer\plugins\djvu0804.dll
2003-03-12 04:15 122,880 ----a-w C:\Program Files\internet explorer\plugins\DjVuCntl.dll
2003-01-13 10:20 278,528 ------w C:\Program Files\internet explorer\plugins\PanoViewer.dll
1999-04-30 15:00 98,304 ------w C:\Program Files\internet explorer\plugins\UPjpeg.dll
2007-03-09 08:12 27,648 --sha-w C:\WINDOWS\system32\AVSredirect.dll
.
((((((((((((((((((((((((((((( snapshot@2008-06-09_20.41.05.56 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-09 19:13:15 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-12 17:15:18 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2008-05-14 23:36:12 38,240 ----a-r C:\WINDOWS\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
+ 2008-06-10 01:13:22 38,240 ----a-r C:\WINDOWS\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
+ 2008-06-11 00:05:08 7,406 ----a-r C:\WINDOWS\Installer\{E80F62FF-5D3C-4A19-8409-9721F2928206}\IconE80F62FF.exe
+ 2007-08-09 00:39:56 36,056 ----a-w C:\WINDOWS\system32\drivers\CO_Mon.sys
- 2008-03-06 21:32:09 23,904 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
+ 2008-03-06 20:32:09 23,904 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
+ 2008-01-29 11:01:28 16,168 ----a-w C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
+ 2008-02-01 01:51:16 279,088 ----a-w C:\WINDOWS\system32\drivers\srtsp.sys
+ 2008-02-01 01:51:16 317,616 ----a-w C:\WINDOWS\system32\drivers\srtspl.sys
+ 2008-02-01 01:51:16 43,696 ----a-w C:\WINDOWS\system32\drivers\srtspx.sys
- 2006-08-07 15:01:56 12,992 ----a-w C:\WINDOWS\system32\drivers\symdns.sys
+ 2008-02-05 19:34:43 13,616 ----a-w C:\WINDOWS\system32\drivers\symdns.sys
- 2006-08-07 15:02:02 110,784 ----a-w C:\WINDOWS\system32\drivers\symfw.sys
+ 2008-02-05 19:34:43 96,432 ----a-w C:\WINDOWS\system32\drivers\symfw.sys
- 2006-08-07 15:02:18 31,936 ----a-w C:\WINDOWS\system32\drivers\symids.sys
+ 2008-02-05 19:34:43 38,576 ----a-w C:\WINDOWS\system32\drivers\symids.sys
+ 2008-02-06 21:43:53 31,408 ----a-w C:\WINDOWS\system32\drivers\SymIM.sys
- 2006-08-07 15:02:14 28,352 ----a-w C:\WINDOWS\system32\drivers\symndis.sys
+ 2008-02-05 19:34:43 37,424 ----a-w C:\WINDOWS\system32\drivers\symndis.sys
+ 2008-02-05 19:34:43 41,008 ----a-w C:\WINDOWS\system32\drivers\symndisv.sys
- 2006-08-07 15:02:22 24,768 ----a-w C:\WINDOWS\system32\drivers\symredrv.sys
+ 2008-02-05 19:34:43 22,320 ----a-w C:\WINDOWS\system32\drivers\symredrv.sys
- 2006-08-07 15:02:26 195,776 ----a-w C:\WINDOWS\system32\drivers\symtdi.sys
+ 2008-02-05 19:34:43 188,464 ----a-w C:\WINDOWS\system32\drivers\symtdi.sys
+ 2008-01-29 11:02:30 107,368 ----a-w C:\WINDOWS\system32\GEARAspi.dll
+ 2008-03-25 00:28:39 135,168 ----a-w C:\WINDOWS\system32\java.exe
+ 2008-03-25 00:28:43 135,168 ----a-w C:\WINDOWS\system32\javaw.exe
+ 2008-03-25 01:37:01 139,264 ----a-w C:\WINDOWS\system32\javaws.exe
- 2006-08-07 15:02:32 534,208 ----a-w C:\WINDOWS\system32\SymNeti.dll
+ 2008-02-20 01:06:11 579,464 ----a-w C:\WINDOWS\system32\SymNeti.dll
- 2006-08-07 15:02:30 161,472 ----a-w C:\WINDOWS\system32\SymRedir.dll
+ 2008-02-20 01:06:11 207,240 ----a-w C:\WINDOWS\system32\SymRedir.dll
+ 2008-06-12 17:15:39 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_5b0.dat
+ 2008-06-12 17:15:46 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_f0.dat
+ 2006-12-01 21:56:00 96,256 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_cbb27474\ATL80.dll
+ 2006-12-01 21:54:32 479,232 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcm80.dll
+ 2006-12-01 21:54:34 548,864 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcp80.dll
+ 2006-12-01 21:54:32 626,688 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcr80.dll
+ 2006-12-01 23:25:52 1,101,824 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80.dll
+ 2006-12-01 23:25:56 1,093,120 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80u.dll
+ 2006-12-01 23:25:58 69,632 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80.dll
+ 2006-12-01 23:26:00 57,856 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80u.dll
+ 2006-12-01 23:08:00 40,960 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHS.dll
+ 2006-12-01 23:08:00 45,056 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHT.dll
+ 2006-12-01 23:08:00 65,536 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80DEU.dll
+ 2006-12-01 23:08:00 57,344 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ENU.dll
+ 2006-12-01 23:08:00 61,440 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ESP.dll
+ 2006-12-01 23:08:00 61,440 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80FRA.dll
+ 2006-12-01 23:08:00 61,440 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ITA.dll
+ 2006-12-01 23:08:00 49,152 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80JPN.dll
+ 2006-12-01 23:08:00 49,152 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80KOR.dll
+ 2006-12-01 23:46:44 65,536 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6c18549a\vcomp.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
2008-02-24 03:08 349552 --a------ C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2008-06-11 01:08 116088 --a------ C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= "C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll" [2008-02-24 03:08 349552]
[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll [2008-02-24 03:08 349552]
[HKEY_CLASSES_ROOT\clsid\{7febefe3-6b19-4349-98d2-ffb09d4b49ca}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayExcluded]
@={4433A54A-1AC8-432F-90FC-85F045CF383C}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayPending]
@={F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayProtected]
@={476D0EA3-80F9-48B5-B70B-05E677C9C148}
[HKEY_CLASSES_ROOT\CLSID\{4433A54A-1AC8-432F-90FC-85F045CF383C}]
2008-02-26 09:34 576352 --a------ C:\Program Files\Common Files\Symantec Shared\Backup\buShell.dll
[HKEY_CLASSES_ROOT\CLSID\{F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225}]
2008-02-26 09:34 576352 --a------ C:\Program Files\Common Files\Symantec Shared\Backup\buShell.dll
[HKEY_CLASSES_ROOT\CLSID\{476D0EA3-80F9-48B5-B70B-05E677C9C148}]
2008-02-26 09:34 576352 --a------ C:\Program Files\Common Files\Symantec Shared\Backup\buShell.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:56 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-08 19:21 68856]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 21:05 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VCSPlayer"="C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe" [2003-05-05 13:47 299008]
"HPDJ Taskbar Utility"="C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe" [2002-12-24 03:33 188416]
"ATIPTA"="C:\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-02-22 21:05 339968]
"ezShieldProtector for Px"="C:\WINDOWS\system32\ezSP_Px.exe" [2002-08-20 10:29 40960]
"ShowIcon_Justrams_USB Product Driver v2.12r012"="C:\Program Files\USB Product Driver v2.12r012\shwicon.exe" [2003-12-11 19:54 73728]
"ATIModeChange"="Ati2mdxx.exe" [2002-08-15 23:19 28672 C:\WINDOWS\system32\Ati2mdxx.exe]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 15:57 153136]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-12-21 20:35 77824]
"LVCOMS"="C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE" [2002-12-10 17:54 127022]
"LogitechImageStudioTray"="C:\Program Files\Logitech\ImageStudio\LogiTray.exe" [2002-12-10 18:31 61440]
"LogitechGalleryRepair"="C:\Program Files\Logitech\ImageStudio\ISStart.exe" [2002-12-10 18:32 155648]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 11:09 63712]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"adiras"="adiras.exe" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-02-18 20:37 51048]
"osCheck"="C:\Program Files\Norton 360 Online\osCheck.exe" [2008-02-26 15:50 988512]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 08:56 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-04 08:56 53760 C:\WINDOWS\system32\narrator.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2008-05-31 21:23:44 962663]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.iac2"= C:\PROGRA~1\REPLAY~1\iac25_32.ax
"msacm.dvacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\Vio\dvacm.acm
"msacm.msnaudio"= msnaudio.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Kontiki\\KService.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\WINDOWS\\PCHEALTH\\HELPCTR\\Binaries\\helpctr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8070:TCP"= 8070:TCP:BitComet 8070 TCP
"8070:UDP"= 8070:UDP:BitComet 8070 UDP
"60002:TCP"= 60002:TCP:BitComet 60002 TCP
"60002:UDP"= 60002:UDP:BitComet 60002 UDP
"8826:TCP"= 8826:TCP:BitComet 8826 TCP
"8826:UDP"= 8826:UDP:BitComet 8826 UDP
R0 hpt3xx;hpt3xx;C:\WINDOWS\system32\DRIVERS\hpt3xx.sys [2001-08-17 13:52]
R1 vcsmpdrv;vcsmpdrv;C:\WINDOWS\system32\DRIVERS\vcsmpdrv.sys [2003-06-16 16:07]
R2 VCSSecS;Virtual CD v4 Security service (SDK - Version);C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe [2002-05-16 12:17]
R3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-03-06 21:32]
R3 STAC97NA;SigmaTel 3D Environmental Audio;C:\WINDOWS\system32\drivers\stac97na.sys [2002-09-20 18:42]
R3 STAC97NH;STAC97NH;C:\WINDOWS\system32\drivers\stac97nh.sys [2002-09-20 18:43]
S3 MXBULK;DualCam Still, MXBulk3.Sys;C:\WINDOWS\system32\Drivers\MXBulk3.sys [2002-01-22 15:01]
S3 MXCap;DSC-06 Video Camera;C:\WINDOWS\system32\DRIVERS\MXCap3.sys [2002-04-17 18:35]
S3 sonypvs1;Sony Digital Imaging Video2;C:\WINDOWS\system32\DRIVERS\sonypvs1.sys [2006-10-30 13:46]
S3 V90drv;v90drv;C:\WINDOWS\system32\DRIVERS\v90drv.sys [2001-11-29 16:09]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6254de80-cdb7-11db-9d3f-4d6564696130}]
\Shell\AutoRun\command - E:\setupSNK.exe
*Newly Created Service* - CATCHME
*Newly Created Service* - COMHOST
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-12 18:33:11
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\Program Files\Common Files\Symantec Shared\SymcData\nco1.0defs\20080611.004\WebAuth_BrandDomains.ccs.bin 1598632 bytes
C:\Program Files\Common Files\Symantec Shared\SymcData\nco1.0defs\20080611.004\WebAuth_DataProperties.ccs.bin 230 bytes
C:\Program Files\Common Files\Symantec Shared\SymcData\nco1.0defs\20080611.004\WebAuth_Trusted_RootCerts_SHA1.ccs.bin 47112 bytes
C:\Program Files\Common Files\Symantec Shared\SymcData\nco1.0defs\20080611.005\WebAuth_BrandDomains.ccs.bin 1598632 bytes
C:\Program Files\Common Files\Symantec Shared\SymcData\nco1.0defs\20080611.005\WebAuth_DataProperties.ccs.bin 230 bytes
C:\Program Files\Common Files\Symantec Shared\SymcData\nco1.0defs\20080611.005\WebAuth_Trusted_RootCerts_SHA1.ccs.bin 47112 bytes
C:\Program Files\Common Files\Symantec Shared\SymcData\nco1.0defs\BinHub\Identifiers.xml.bin 1025039 bytes
C:\Program Files\Common Files\Symantec Shared\SymcData\nco1.0defs\BinHub\Indicators.xml.bin 74555 bytes
C:\Program Files\Common Files\Symantec Shared\SymcData\nco1.0defs\BinHub\PopularSites.xml.bin 8324 bytes
C:\Program Files\Common Files\Symantec Shared\SymcData\nco1.0defs\BinHub\Redirectors.xml.bin 47431 bytes
C:\Program Files\Common Files\Symantec Shared\SymcData\nco1.0defs\BinHub\Resources.xml.bin 556 bytes
C:\Program Files\Common Files\Symantec Shared\SymcData\nco1.0defs\BinHub\SafeList.xml.bin 593079 bytes
C:\Program Files\Common Files\Symantec Shared\SymcData\nco1.0defs\BinHub\SearchServices.xml.bin 20719 bytes
C:\Program Files\Common Files\Symantec Shared\SymcData\nco1.0defs\BinHub\Throttle.xml.bin 454 bytes
C:\Program Files\Common Files\Symantec Shared\SymcData\nco1.0defs\BinHub\TrustedDomains.xml.bin 262717 bytes
C:\Program Files\Common Files\Symantec Shared\SymcData\nco1.0defs\BinHub\URLAnalysis.xml.bin 568756 bytes
C:\Program Files\Common Files\Symantec Shared\SymcData\nco1.0defs\BinHub\WebAuth_BrandDomains.ccs.bin 1570830 bytes
C:\Program Files\Common Files\Symantec Shared\SymcData\nco1.0defs\BinHub\WebAuth_DataProperties.ccs.bin 230 bytes
C:\Program Files\Common Files\Symantec Shared\SymcData\nco1.0defs\BinHub\WebAuth_Trusted_RootCerts_SHA1.ccs.bin 46248 bytes
C:\Program Files\Common Files\Symantec Shared\SymcData\nco1.0defs\BinHub\WebHostingSites.xml.bin 29070 bytes
C:\Program Files\Common Files\Symantec Shared\SymcData\nco1.0defs\tmp7e19.tmp\cur.enc 10574 bytes
scan completed successfully
hidden files: 21
**************************************************************************
.
Completion time: 2008-06-12 18:45:33
ComboFix-quarantined-files.txt 2008-06-12 17:45:16
ComboFix2.txt 2008-06-09 20:38:48
ComboFix3.txt 2008-06-09 19:42:07
Pre-Run: 26,201,239,552 bytes free
Post-Run: 26,182,840,320 bytes free
348 --- E O F --- 2008-06-10 01:13:24
HiJack report
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:52:18, on 12/06/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\Program Files\USB Product Driver v2.12r012\shwicon.exe
C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
C:\Program Files\Logitech\ImageStudio\LogiTray.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.tiscali.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll
O4 - HKLM\..\Run: [VCSPlayer] "C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe
O4 - HKLM\..\Run: [ShowIcon_Justrams_USB Product Driver v2.12r012] "C:\Program Files\USB Product Driver v2.12r012\shwicon.exe" -t"Justrams\USB Product Driver v2.12r012"
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [adiras] adiras.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton 360 Online\osCheck.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-20\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [NeroHomeFirstStart] C:\Program Files\Common Files\Ahead\Lib\NMFirstStart.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: Tiscali Broadband.lnk = ?
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for .UVR: C:\Program Files\Internet Explorer\Plugins\NPUPano.dll
O16 - DPF: Yahoo! Chat -
http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
O16 - DPF: Yahoo! Pool 2 -
http://download.games.yahoo.com/games/clients/y/potc_x.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
http://messenger.zone.msn.com/binary/msgrchkr.cab28578.cab
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} -
http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} -
http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) -
http://www.creative.com/su/ocx/15015/CTSUEng.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) -
http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
O16 - DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} (Bebo Uploader Control) -
http://www.bebo.com/files/BeboUploader.5.1.4.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) -
https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) -
http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {245637BB-3A58-49A2-A7AB-F4A63B67652E} (PrinterDetector40.PrinterDetector) -
http://www.mymemory.co.uk/detector/PrinterDetector40.ocx
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) -
http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} -
http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) -
http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) -
https://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) -
http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) -
http://www.snapfish.co.uk/SnapfishUKActivia.cab
O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) -
https://www-secure.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) -
https://www-secure.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) -
http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-9.cab
O16 - DPF: {4CCA4E6B-9259-11D9-AC6E-444553544200} (FixController Control) -
http://h30155.www3.hp.com/ediags/dd/install/HPInstallMgr_v01.cab
O16 - DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} (AccountTracking Profile Manager Class) -
https://moneymanager.egg.com/Pinsafe/accounttracking.cab
O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} (Microsoft.WinRep) -
https://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) -
http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) -
http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) -
http://216.249.24.141/code/PWActiveXImgCtl.CAB
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1121902082609
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) -
http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) -
http://sdlc-esd.sun.com/ESD42/JSCDL...-jc.cab&File=jinstall-6u6-windows-i586-jc.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) -
http://212.248.234.26/activex/AxisCamControl.cab
O16 - DPF: {924C1588-90C3-4910-B6CA-D57A1C0418FE} (YbUploadFavsCtl Class) -
http://uk.bookmarks.yahoo.com/YbConvFav.CAB
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://messenger.zone.msn.com/binary/ZIntro.cab53083.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) -
http://game03.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {C45B1500-7B63-47C2-AB25-C28CB46AFDEE} (Tiscali Music Downloads) -
http://sib1.od2.com/common/musicmanager/installation/MusicManagerPlugin.CAB
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) -
http://a532.g.akamai.net/f/532/6712/4h/player.virtools.com/downloads/player/Install3.0/Installer.exe
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} -
https://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} -
http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) -
http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab
O16 - DPF: {E862C832-3A5F-4CEB-BFAA-167B22010A71} (InfosFinder2.InfosFinder) -
http://support.packardbell.com/files/activex/InfosFinder2.CAB
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Toolbar) -
http://us.dl1.yimg.com/download.companion.yahoo.com/dl/toolbar/yiebio5_1_6_0.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) -
http://www.creative.com/su/ocx/15014/CTPID.cab
O16 - DPF: {FEE1002D-90A5-4A5D-AABE-01803FFBCF7A} -
http://ps.itv.mop.com/dn/files/pCastCtl_1.0.0.89_20060727.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{F021C4DE-F77C-4857-ABFA-AE72EFE53D3B}: NameServer = 212.139.132.24 212.139.132.25
O18 - Protocol: AutorunsDisabled - (no CLSID) - (no file)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: KService - Unknown owner - C:\Program Files\Kontiki\KService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
--
End of file - 17038 bytes