avprox777

Members
  • Content Count

    14
  • Joined

  • Last visited

Posts posted by avprox777

  1. well, i was running OTScanIt2 and it got an error halfway through. it finished and asked if i wanted to reboot, i said yes, and it wouldnt reboot. so i manually restarted (held down the power button) and when i turned my computer back on, it got to the login screen and there were no users to log onto. the screen was just blank. so i went into safe mode, and it was the same. i ended up just formatting my computer, so i guess you can close this thread, because the issue is resolved. thanks again for all the help, i really appreciate it.

  2. SDFix: Version 1.240

    Run by Owner on Sun 11/09/2008 at 01:10 PM

    Microsoft Windows XP [Version 5.1.2600]

    Running From: C:\SDFix

    Checking Services :

    Restoring Default Security Values

    Restoring Default Hosts File

    Rebooting

    Checking Files :

    Trojan Files Found:

    C:\WINDOWS\system32\comsa32.sys - Deleted

    Removing Temp Files

    ADS Check :

    Final Check :

    catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

    Rootkit scan 2008-11-09 14:36:30

    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    C:\WINDOWS\system32\afisicx.exe [1884] 0x85F37020

    C:\WINDOWS\system32\noytcyr.exe [1236] 0x85CC3C18

    C:\WINDOWS\system32\roytctm.exe [1312] 0x85CBB638

    C:\WINDOWS\system32\tdydowkc.exe [1776] 0x84B4DDA0

    C:\WINDOWS\system32\wsldoekd.exe [1968] 0x84B41C80

    scanning hidden services & system hive ...

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40]

    "khjeh"=hex:20,02,00,00,a6,d3,71,e9,1b,3a,37,c4,62,55,97,4c,9d,bd,dd,fb,66,..

    "hj34z0"=hex:d1,8e,77,fc,dd,09,81,38,8d,e1,ca,8f,f2,95,de,02,f2,a4,99,c6,77,..

    scanning hidden registry entries ...

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.\x2558\x2524ä\OpenWithProgids]

    "X%$%ä?_?a?u?t?o?_?f?i?l?e?"=hex(0):

    scanning hidden files ...

    scan completed successfully

    hidden processes: 5

    hidden services: 0

    hidden files: 0

    Remaining Services :

    Authorized Application Key Export:

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

    "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

    "C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"

    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"

    "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

    "C:\\Program Files\\Xfire\\xfire.exe"="C:\\Program Files\\Xfire\\xfire.exe:*:Enabled:Xfire"

    "C:\\Program Files\\Azureus\\Azureus.exe"="C:\\Program Files\\Azureus\\Azureus.exe:*:Enabled:Azureus"

    "C:\\Program Files\\FrostWire\\FrostWire.exe"="C:\\Program Files\\FrostWire\\FrostWire.exe:*:Enabled:LimeWire"

    "C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"

    "C:\\Program Files\\Orbitdownloader\\orbitdm.exe"="C:\\Program Files\\Orbitdownloader\\orbitdm.exe:*:Enabled:Orbit"

    "C:\\Program Files\\Orbitdownloader\\orbitnet.exe"="C:\\Program Files\\Orbitdownloader\\orbitnet.exe:*:Enabled:Orbit"

    "C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"="C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe:*:Enabled:MySpaceIM"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

    "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"

    "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

    Remaining Files :

    File Backups: - C:\SDFix\backups\backups.zip

    Files with Hidden Attributes :

    Thu 8 Mar 2007 258,560 A..H. --- "C:\Program Files\Adobe\upx.exe"

    Sun 26 Jun 2005 616,448 A.SHR --- "C:\Program Files\Replay Converter\cygwin1.dll"

    Tue 21 Jun 2005 45,568 A.SHR --- "C:\Program Files\Replay Converter\cygz.dll"

    Mon 9 Dec 2002 102,437 A..HR --- "C:\Program Files\Replay Converter\drv13260.dll"

    Mon 9 Dec 2002 176,165 A..HR --- "C:\Program Files\Replay Converter\drv23260.dll"

    Mon 9 Dec 2002 208,935 A..HR --- "C:\Program Files\Replay Converter\drv33260.dll"

    Mon 9 Dec 2002 217,127 A..HR --- "C:\Program Files\Replay Converter\drv43260.dll"

    Sun 9 Jun 2002 40,448 A..HR --- "C:\Program Files\Replay Converter\dspr3260.dll"

    Sat 3 Nov 2001 225,280 A..HR --- "C:\Program Files\Replay Converter\ivvideo.dll"

    Tue 10 Apr 2001 225,280 A..HR --- "C:\Program Files\Replay Converter\qtmlClient.dll"

    Fri 20 Feb 2004 232,960 A..HR --- "C:\Program Files\Replay Converter\raac.dll"

    Sun 9 Jun 2002 525,824 A..HR --- "C:\Program Files\Replay Converter\rnco3260.dll"

    Mon 9 Dec 2002 245,805 A..HR --- "C:\Program Files\Replay Converter\rnlt3260.dll"

    Mon 9 Dec 2002 45,093 A..HR --- "C:\Program Files\Replay Converter\rv103260.dll"

    Mon 9 Dec 2002 98,341 A..HR --- "C:\Program Files\Replay Converter\rv203260.dll"

    Mon 9 Dec 2002 94,247 A..HR --- "C:\Program Files\Replay Converter\rv303260.dll"

    Mon 9 Dec 2002 90,151 A..HR --- "C:\Program Files\Replay Converter\rv403260.dll"

    Sun 9 Jun 2002 49,152 A..HR --- "C:\Program Files\Replay Converter\tokr3260.dll"

    Wed 30 Jul 2008 1,429,840 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"

    Wed 30 Jul 2008 4,891,984 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"

    Wed 30 Jul 2008 1,829,712 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"

    Thu 8 Mar 2007 27,648 A.SH. --- "C:\WINDOWS\system32\AVSredirect.dll"

    Thu 3 Apr 2008 80 ..SHR --- "C:\WINDOWS\system32\B007C43AE0.dll"

    Tue 11 Apr 2006 2,461,696 A..H. --- "C:\Documents and Settings\Owner\Application Data\U3\temp\Launchpad Removal.exe"

    Tue 11 Apr 2006 2,461,696 A..H. --- "C:\Documents and Settings\Robbie\Application Data\U3\temp\Launchpad Removal.exe"

    Thu 7 Jun 2001 339,968 A..H. --- "C:\Documents and Settings\Owner\Desktop\Downloads\M64K_079\Mupen64K 0.7.9\MSVCR70.dll"

    Thu 7 Jun 2001 339,968 A..H. --- "C:\_OTMoveIt\MovedFiles\11092008_110058\Documents and Settings\Owner\Desktop\emu shit\M64K_079\Mupen64K 0.7.9\MSVCR70.dll"

    Finished!

  3. Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 11:17:50 AM, on 11/9/2008

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v7.00 (7.00.6000.16441)

    Boot mode: Normal

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\Ati2evxx.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

    C:\WINDOWS\system32\Ati2evxx.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\VistaDrive\VistaDrive.exe

    C:\WINDOWS\ALCXMNTR.EXE

    C:\WINDOWS\AGRSMMSG.exe

    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe

    C:\Program Files\Eset\nod32kui.exe

    C:\Program Files\Unlocker\UnlockerAssistant.exe

    C:\Program Files\Winamp\winampa.exe

    C:\Program Files\iTunes\iTunesHelper.exe

    C:\Program Files\Xfire\xfiremusic.exe

    C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe

    C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe

    C:\Program Files\Creative\Software Update 3\SoftAuto.exe

    C:\Program Files\Orbitdownloader\orbitdm.exe

    C:\Program Files\Last.fm\LastFM.exe

    C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe

    C:\Program Files\SpeedFan\speedfan.exe

    C:\Program Files\Orbitdownloader\orbitnet.exe

    C:\Program Files\Steam\steam.exe

    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    C:\WINDOWS\system32\CTsvcCDA.exe

    C:\Program Files\Creative\Shared Files\CTDevSrv.exe

    C:\Program Files\Eset\nod32krn.exe

    C:\WINDOWS\system32\PnkBstrA.exe

    C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\wscntfy.exe

    C:\Program Files\iPod\bin\iPodService.exe

    C:\Program Files\Mozilla Firefox\firefox.exe

    C:\Program Files\Xfire\xfire.exe

    C:\WINDOWS\system32\msnioed.exe

    C:\WINDOWS\system32\mabidwe.exe

    C:\WINDOWS\system32\soxpeca.exe

    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/

    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :

    O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll

    O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 9\SnagItBHO.dll

    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

    O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL

    O2 - BHO: Yahoo! IE Suggest - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - (no file)

    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

    O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll

    O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL

    O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 9\SnagItIEAddin.dll

    O4 - HKLM\..\Run: [VistaDrive] C:\WINDOWS\VistaDrive\VistaDrive.exe

    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE

    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe

    O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe

    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe

    O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033

    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"

    O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe

    O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE

    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

    O4 - HKLM\..\Run: [unlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"

    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

    O4 - HKLM\..\Run: [Xfire Music] "C:\Program Files\Xfire\xfiremusic.exe"

    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

    O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

    O4 - HKLM\..\Run: [iMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE

    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC

    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC

    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName

    O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"

    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: [CTZDetec.exe] "C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe"

    O4 - HKCU\..\Run: [softAuto.exe] "C:\Program Files\Creative\Software Update 3\SoftAuto.exe"

    O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')

    O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')

    O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')

    O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')

    O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')

    O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')

    O4 - S-1-5-18 Startup: Last.fm.lnk = C:\Program Files\Last.fm\LastFM.exe (User 'SYSTEM')

    O4 - S-1-5-18 Startup: SpeedFan.lnk = C:\Program Files\SpeedFan\speedfan.exe (User 'SYSTEM')

    O4 - S-1-5-18 Startup: Steam.lnk = ? (User 'SYSTEM')

    O4 - .DEFAULT Startup: Last.fm.lnk = C:\Program Files\Last.fm\LastFM.exe (User 'Default user')

    O4 - .DEFAULT Startup: SpeedFan.lnk = C:\Program Files\SpeedFan\speedfan.exe (User 'Default user')

    O4 - .DEFAULT Startup: Steam.lnk = ? (User 'Default user')

    O4 - Startup: Last.fm.lnk = C:\Program Files\Last.fm\LastFM.exe

    O4 - Startup: SpeedFan.lnk = C:\Program Files\SpeedFan\speedfan.exe

    O4 - Startup: Steam.lnk = ?

    O4 - Global Startup: Orbit.lnk = C:\Program Files\Orbitdownloader\orbitdm.exe

    O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201

    O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204

    O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203

    O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202

    O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

    O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm

    O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm

    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

    O23 - Service: afisicx - Unknown owner - C:\WINDOWS\system32\afisicx.exe

    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe

    O23 - Service: CT Device Query service (CTDevice_Srv) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTDevSrv.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe

    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: mabidwe Service (mabidwe) - Unknown owner - C:\WINDOWS\system32\mabidwe.exe

    O23 - Service: Windows File Manager Services (mscbcosd) - Unknown owner - C:\WINDOWS\system32\mscbco.exe

    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

    O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe

    O23 - Service: noytcyr - Unknown owner - C:\WINDOWS\system32\noytcyr.exe

    O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

    O23 - Service: root - Unknown owner - C:\Program.exe (file missing)

    O23 - Service: roytctm - Unknown owner - C:\WINDOWS\system32\roytctm.exe

    O23 - Service: soxpeca Service (soxpeca) - Unknown owner - C:\WINDOWS\system32\soxpeca.exe

    O23 - Service: tdydowkc - Unknown owner - C:\WINDOWS\system32\tdydowkc.exe

    O23 - Service: wsldoekd - Unknown owner - C:\WINDOWS\system32\wsldoekd.exe

    --

    End of file - 10626 bytes

  4. yeah, i havent reformatted my HDD for a good 3 years, so im definately due for it.

    ========== PROCESSES ==========

    Process explorer.exe killed successfully.

    ========== SERVICES/DRIVERS ==========

    ========== REGISTRY ==========

    ========== FILES ==========

    DllUnregisterServer procedure not found in C:\Documents and Settings\Owner\Desktop\Downloads\M64K_079\Mupen64K 0.7.9\kailleraclient.dll

    C:\Documents and Settings\Owner\Desktop\Downloads\M64K_079\Mupen64K 0.7.9\kailleraclient.dll NOT unregistered.

    C:\Documents and Settings\Owner\Desktop\Downloads\M64K_079\Mupen64K 0.7.9\kailleraclient.dll moved successfully.

    C:\Documents and Settings\Owner\Desktop\emu shit\emu shit.rar moved successfully.

    C:\Documents and Settings\Owner\Desktop\emu shit\M64K_079\Mupen64K 0.7.9\ScreenShots moved successfully.

    C:\Documents and Settings\Owner\Desktop\emu shit\M64K_079\Mupen64K 0.7.9\save moved successfully.

    C:\Documents and Settings\Owner\Desktop\emu shit\M64K_079\Mupen64K 0.7.9\plugin moved successfully.

    C:\Documents and Settings\Owner\Desktop\emu shit\M64K_079\Mupen64K 0.7.9\Lang moved successfully.

    C:\Documents and Settings\Owner\Desktop\emu shit\M64K_079\Mupen64K 0.7.9 moved successfully.

    C:\Documents and Settings\Owner\Desktop\emu shit\M64K_079 moved successfully.

    C:\Documents and Settings\Owner\Desktop\Rarely Used Shortcuts\CBS Refresh.exe moved successfully.

    C:\Documents and Settings\Robbie\Desktop\ZwinkySetup2.2.60.11-2.ZJfox000.exe moved successfully.

    C:\WINDOWS\system32\msnioed.exe moved successfully.

    C:\WINDOWS\system32\noytcyr.exe moved successfully.

    C:\WINDOWS\system32\roytctm.exe moved successfully.

    C:\WINDOWS\system32\tdydowkc.exe moved successfully.

    C:\WINDOWS\system32\wsldoekd.exe moved successfully.

    C:\WINDOWS\system32\zzzzz.zzz moved successfully.

    C:\Documents and Settings\Owner\Desktop\Modified_WPE___Filter\WPE Pro moved successfully.

    C:\Documents and Settings\Owner\Desktop\Modified_WPE___Filter moved successfully.

    ========== COMMANDS ==========

    File delete failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\etilqs_5RSHXQmaI50Uwpp scheduled to be deleted on reboot.

    File delete failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\Perflib_Perfdata_a40.dat scheduled to be deleted on reboot.

    User's Temp folder emptied.

    User's Temporary Internet Files folder emptied.

    User's Internet Explorer cache folder emptied.

    Local Service Temp folder emptied.

    File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.

    Local Service Temporary Internet Files folder emptied.

    File delete failed. C:\WINDOWS\temp\mta115464.dll scheduled to be deleted on reboot.

    File delete failed. C:\WINDOWS\temp\mta40322.dll scheduled to be deleted on reboot.

    File delete failed. C:\WINDOWS\temp\mta70383.dll scheduled to be deleted on reboot.

    File delete failed. C:\WINDOWS\temp\mta95314.dll scheduled to be deleted on reboot.

    File delete failed. C:\WINDOWS\temp\mta99655.dll scheduled to be deleted on reboot.

    Windows Temp folder emptied.

    Java cache emptied.

    File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\3szpobj6.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.

    File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\3szpobj6.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.

    File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\3szpobj6.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.

    File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\3szpobj6.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.

    File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\3szpobj6.default\urlclassifier3.sqlite scheduled to be deleted on reboot.

    File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\3szpobj6.default\XUL.mfl scheduled to be deleted on reboot.

    FireFox cache emptied.

    Opera cache emptied.

    Temp folders emptied.

    Explorer started successfully

    OTMoveIt3 by OldTimer - Version 1.0.7.0 log created on 11092008_110058

    Files moved on Reboot...

    File C:\DOCUME~1\Owner\LOCALS~1\Temp\etilqs_5RSHXQmaI50Uwpp not found!

    File C:\DOCUME~1\Owner\LOCALS~1\Temp\Perflib_Perfdata_a40.dat not found!

    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat moved successfully.

    C:\WINDOWS\temp\mta115464.dll unregistered successfully.

    C:\WINDOWS\temp\mta115464.dll moved successfully.

    C:\WINDOWS\temp\mta40322.dll unregistered successfully.

    C:\WINDOWS\temp\mta40322.dll moved successfully.

    C:\WINDOWS\temp\mta70383.dll unregistered successfully.

    C:\WINDOWS\temp\mta70383.dll moved successfully.

    C:\WINDOWS\temp\mta95314.dll unregistered successfully.

    C:\WINDOWS\temp\mta95314.dll moved successfully.

    C:\WINDOWS\temp\mta99655.dll unregistered successfully.

    C:\WINDOWS\temp\mta99655.dll moved successfully.

    C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\3szpobj6.default\Cache\_CACHE_001_ moved successfully.

    C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\3szpobj6.default\Cache\_CACHE_002_ moved successfully.

    C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\3szpobj6.default\Cache\_CACHE_003_ moved successfully.

    C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\3szpobj6.default\Cache\_CACHE_MAP_ moved successfully.

    C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\3szpobj6.default\urlclassifier3.sqlite moved successfully.

    C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\3szpobj6.default\XUL.mfl moved successfully.

  5. Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 10:07:38 PM, on 11/8/2008

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v7.00 (7.00.6000.16441)

    Boot mode: Normal

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\Ati2evxx.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

    C:\WINDOWS\system32\Ati2evxx.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\VistaDrive\VistaDrive.exe

    C:\WINDOWS\ALCXMNTR.EXE

    C:\WINDOWS\AGRSMMSG.exe

    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe

    C:\Program Files\Eset\nod32kui.exe

    C:\Program Files\Unlocker\UnlockerAssistant.exe

    C:\Program Files\Winamp\winampa.exe

    C:\Program Files\iTunes\iTunesHelper.exe

    C:\Program Files\Xfire\xfiremusic.exe

    C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe

    C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe

    C:\Program Files\Creative\Software Update 3\SoftAuto.exe

    C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe

    C:\Program Files\Orbitdownloader\orbitnet.exe

    C:\Program Files\SpeedFan\speedfan.exe

    C:\Program Files\Steam\steam.exe

    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    C:\WINDOWS\system32\CTsvcCDA.exe

    C:\Program Files\Creative\Shared Files\CTDevSrv.exe

    C:\Program Files\Eset\nod32krn.exe

    C:\WINDOWS\system32\PnkBstrA.exe

    C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\iPod\bin\iPodService.exe

    C:\WINDOWS\system32\wscntfy.exe

    C:\WINDOWS\system32\soxpeca.exe

    C:\Program Files\Mozilla Firefox\firefox.exe

    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/

    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :

    O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll

    O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 9\SnagItBHO.dll

    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

    O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL

    O2 - BHO: Yahoo! IE Suggest - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - (no file)

    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

    O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll

    O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL

    O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 9\SnagItIEAddin.dll

    O4 - HKLM\..\Run: [VistaDrive] C:\WINDOWS\VistaDrive\VistaDrive.exe

    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE

    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe

    O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe

    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe

    O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033

    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"

    O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe

    O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE

    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

    O4 - HKLM\..\Run: [unlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"

    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

    O4 - HKLM\..\Run: [Xfire Music] "C:\Program Files\Xfire\xfiremusic.exe"

    O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"

    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: [CTZDetec.exe] "C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe"

    O4 - HKCU\..\Run: [softAuto.exe] "C:\Program Files\Creative\Software Update 3\SoftAuto.exe"

    O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')

    O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')

    O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')

    O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')

    O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')

    O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')

    O4 - S-1-5-18 Startup: Last.fm.lnk = C:\Program Files\Last.fm\LastFM.exe (User 'SYSTEM')

    O4 - S-1-5-18 Startup: SpeedFan.lnk = C:\Program Files\SpeedFan\speedfan.exe (User 'SYSTEM')

    O4 - S-1-5-18 Startup: Steam.lnk = ? (User 'SYSTEM')

    O4 - .DEFAULT Startup: Last.fm.lnk = C:\Program Files\Last.fm\LastFM.exe (User 'Default user')

    O4 - .DEFAULT Startup: SpeedFan.lnk = C:\Program Files\SpeedFan\speedfan.exe (User 'Default user')

    O4 - .DEFAULT Startup: Steam.lnk = ? (User 'Default user')

    O4 - Startup: Last.fm.lnk = C:\Program Files\Last.fm\LastFM.exe

    O4 - Startup: SpeedFan.lnk = C:\Program Files\SpeedFan\speedfan.exe

    O4 - Startup: Steam.lnk = ?

    O4 - Global Startup: Orbit.lnk = C:\Program Files\Orbitdownloader\orbitdm.exe

    O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201

    O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204

    O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203

    O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202

    O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

    O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm

    O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm

    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

    O23 - Service: afisicx - Unknown owner - C:\WINDOWS\system32\afisicx.exe

    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe

    O23 - Service: CT Device Query service (CTDevice_Srv) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTDevSrv.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe

    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: mabidwe Service (mabidwe) - Unknown owner - C:\WINDOWS\system32\mabidwe.exe (file missing)

    O23 - Service: Windows File Manager Services (mscbcosd) - Unknown owner - C:\WINDOWS\system32\mscbco.exe

    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

    O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe

    O23 - Service: noytcyr - Unknown owner - C:\WINDOWS\system32\noytcyr.exe

    O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

    O23 - Service: root - Unknown owner - C:\Program.exe (file missing)

    O23 - Service: roytctm - Unknown owner - C:\WINDOWS\system32\roytctm.exe

    O23 - Service: soxpeca Service (soxpeca) - Unknown owner - C:\WINDOWS\system32\soxpeca.exe

    O23 - Service: tdydowkc - Unknown owner - C:\WINDOWS\system32\tdydowkc.exe

    O23 - Service: wsldoekd - Unknown owner - C:\WINDOWS\system32\wsldoekd.exe

    --

    End of file - 10032 bytes

  6. --------------------------------------------------------------------------------

    KASPERSKY ONLINE SCANNER 7 REPORT

    Saturday, November 8, 2008

    Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)

    Kaspersky Online Scanner 7 version: 7.0.25.0

    Program database last update: Saturday, November 08, 2008 17:23:19

    Records in database: 1374606

    --------------------------------------------------------------------------------

    Scan settings:

    Scan using the following database: extended

    Scan archives: yes

    Scan mail databases: yes

    Scan area - My Computer:

    C:\

    E:\

    F:\

    G:\

    H:\

    J:\

    K:\

    Scan statistics:

    Files scanned: 199610

    Threat name: 19

    Infected objects: 42

    Suspicious objects: 0

    Duration of the scan: 08:45:26

    File name / Threat name / Threats count

    C:\Documents and Settings\Owner\Desktop\Downloads\M64K_079\Mupen64K 0.7.9\kailleraclient.dll Infected: Trojan-Downloader.Win32.Agent.ahtr 1

    C:\Documents and Settings\Owner\Desktop\emu shit\emu shit.rar Infected: Trojan-Downloader.Win32.Agent.ahtr 1

    C:\Documents and Settings\Owner\Desktop\emu shit\M64K_079\Mupen64K 0.7.9\kailleraclient.dll Infected: Trojan-Downloader.Win32.Agent.ahtr 1

    C:\Documents and Settings\Owner\Desktop\Modified_WPE___Filter\WPE Pro\WPE PRO - modified.exe Infected: HackTool.Win32.Sniffer.WpePro.v 1

    C:\Documents and Settings\Owner\Desktop\Modified_WPE___Filter\WPE Pro\WpeSpy.dll Infected: HackTool.Win32.Sniffer.WpePro.w 1

    C:\Documents and Settings\Owner\Desktop\Modified_WPE___Filter\WPE PRO - modified.exe Infected: HackTool.Win32.Sniffer.WpePro.v 1

    C:\Documents and Settings\Owner\Desktop\Modified_WPE___Filter\WPE Pro.rar Infected: HackTool.Win32.Sniffer.WpePro.v 1

    C:\Documents and Settings\Owner\Desktop\Modified_WPE___Filter\WPE Pro.rar Infected: HackTool.Win32.Sniffer.WpePro.w 1

    C:\Documents and Settings\Owner\Desktop\Modified_WPE___Filter\WpeSpy.dll Infected: HackTool.Win32.Sniffer.WpePro.w 1

    C:\Documents and Settings\Owner\Desktop\Modified_WPE___Filter.rar Infected: HackTool.Win32.Sniffer.WpePro.v 1

    C:\Documents and Settings\Owner\Desktop\Modified_WPE___Filter.rar Infected: HackTool.Win32.Sniffer.WpePro.w 1

    C:\Documents and Settings\Owner\Desktop\Rarely Used Shortcuts\CBS Refresh.exe Infected: Trojan-Spy.Win32.Pophot.cpc 1

    C:\Documents and Settings\Robbie\Desktop\ZwinkySetup2.2.60.11-2.ZJfox000.exe Infected: not-a-virus:WebToolbar.Win32.MyWebSearch.bc 1

    C:\Program Files\ESET\infected\DFCJCFBA.NQF Infected: not-a-virus:Monitor.Win32.WinSpy.bq 1

    C:\Program Files\ESET\infected\DFCJCFBA.NQF Infected: not-a-virus:Monitor.Win32.WinSpy.a 4

    C:\Program Files\ESET\infected\DFCJCFBA.NQF Infected: Trojan-Spy.Win32.SpyWin.a 2

    C:\Program Files\ESET\infected\JRLWLZDA.NQF Infected: not-a-virus:Monitor.Win32.ActualSpy.252 1

    C:\Program Files\ESET\infected\S1RYSHCA.NQF Infected: Hoax.Win32.Renos.he 1

    C:\Program Files\ESET\infected\T3KYZ5BA.NQF Infected: HackTool.Win32.Sniffer.WpePro.w 1

    C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.621 1

    C:\WINDOWS\system32\afisicx.exe Infected: Trojan.Win32.Agent.amej 1

    C:\WINDOWS\system32\cmdow.exe Infected: not-a-virus:RiskTool.Win32.HideWindows 1

    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\48WD6HP8\af[1].bin Infected: Trojan.Win32.Agent.amej 1

    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\S16YRF8K\af[1].bin Infected: Trojan.Win32.Agent.amej 1

    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\S16YRF8K\msusp[1].bin Infected: Trojan.Win32.Agent.ambw 1

    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\S16YRF8K\no[1].bin Infected: Trojan.Win32.Agent.gpa 1

    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\S16YRF8K\td[1].bin Infected: Trojan.Win32.Agent.gpd 1

    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\S16YRF8K\td[2].bin Infected: Trojan.Win32.Agent.gpd 1

    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\S16YRF8K\ws[2].bin Infected: Trojan.Win32.Agent.gpe 1

    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\S1QTPL3I\no[1].bin Infected: Trojan.Win32.Agent.gpa 1

    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\S1QTPL3I\ro[1].bin Infected: Trojan.Win32.Agent.gpc 1

    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\S1QTPL3I\ro[2].bin Infected: Trojan.Win32.Agent.gpc 1

    C:\WINDOWS\system32\msnioed.exe Infected: Trojan.Win32.Agent.ambw 1

    C:\WINDOWS\system32\noytcyr.exe Infected: Trojan.Win32.Agent.gpa 1

    C:\WINDOWS\system32\roytctm.exe Infected: Trojan.Win32.Agent.gpc 1

    C:\WINDOWS\system32\tdydowkc.exe Infected: Trojan.Win32.Agent.gpd 1

    C:\WINDOWS\system32\wsldoekd.exe Infected: Trojan.Win32.Agent.gpe 1

    C:\WINDOWS\system32\zzzzz.zzz Infected: Trojan.Win32.Agent.amaz 1

    The selected area was scanned.

  7. Malwarebytes' Anti-Malware 1.30

    Database version: 1368

    Windows 5.1.2600 Service Pack 2

    11/6/2008 6:49:42 PM

    mbam-log-2008-11-06 (18-49-42).txt

    Scan type: Quick Scan

    Objects scanned: 52578

    Time elapsed: 3 minute(s), 2 second(s)

    Memory Processes Infected: 2

    Memory Modules Infected: 0

    Registry Keys Infected: 21

    Registry Values Infected: 0

    Registry Data Items Infected: 0

    Folders Infected: 0

    Files Infected: 9

    Memory Processes Infected:

    C:\WINDOWS\system32\mabidwe.exe (Trojan.Agent) -> Unloaded process successfully.

    C:\WINDOWS\system32\soxpeca.exe (Trojan.Agent) -> Unloaded process successfully.

    Memory Modules Infected:

    (No malicious items detected)

    Registry Keys Infected:

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\afisicx (Trojan.Agent) -> Quarantined and deleted successfully.

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mabidwe (Trojan.Agent) -> Quarantined and deleted successfully.

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\noytcyr (Trojan.Agent) -> Quarantined and deleted successfully.

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\roytctm (Trojan.Agent) -> Quarantined and deleted successfully.

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\soxpeca (Trojan.Agent) -> Quarantined and deleted successfully.

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tdydowkc (Trojan.Agent) -> Quarantined and deleted successfully.

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wsldoekd (Trojan.Agent) -> Quarantined and deleted successfully.

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\afisicx (Trojan.Agent) -> Quarantined and deleted successfully.

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\mabidwe (Trojan.Agent) -> Quarantined and deleted successfully.

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\noytcyr (Trojan.Agent) -> Quarantined and deleted successfully.

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\roytctm (Trojan.Agent) -> Quarantined and deleted successfully.

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\soxpeca (Trojan.Agent) -> Quarantined and deleted successfully.

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\tdydowkc (Trojan.Agent) -> Quarantined and deleted successfully.

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\wsldoekd (Trojan.Agent) -> Quarantined and deleted successfully.

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\afisicx (Trojan.Agent) -> Quarantined and deleted successfully.

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mabidwe (Trojan.Agent) -> Quarantined and deleted successfully.

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\noytcyr (Trojan.Agent) -> Quarantined and deleted successfully.

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\roytctm (Trojan.Agent) -> Quarantined and deleted successfully.

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\soxpeca (Trojan.Agent) -> Quarantined and deleted successfully.

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tdydowkc (Trojan.Agent) -> Quarantined and deleted successfully.

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wsldoekd (Trojan.Agent) -> Quarantined and deleted successfully.

    Registry Values Infected:

    (No malicious items detected)

    Registry Data Items Infected:

    (No malicious items detected)

    Folders Infected:

    (No malicious items detected)

    Files Infected:

    C:\WINDOWS\system32\afisicx.exe (Trojan.Agent) -> Delete on reboot.

    C:\WINDOWS\system32\comsa32.sys (Trojan.Agent) -> Quarantined and deleted successfully.

    C:\WINDOWS\system32\mabidwe.exe (Trojan.Agent) -> Quarantined and deleted successfully.

    C:\WINDOWS\system32\msnioed.exe (Trojan.Agent) -> Quarantined and deleted successfully.

    C:\WINDOWS\system32\noytcyr.exe (Trojan.Agent) -> Delete on reboot.

    C:\WINDOWS\system32\roytctm.exe (Trojan.Agent) -> Delete on reboot.

    C:\WINDOWS\system32\soxpeca.exe (Trojan.Agent) -> Quarantined and deleted successfully.

    C:\WINDOWS\system32\tdydowkc.exe (Trojan.Agent) -> Delete on reboot.

    C:\WINDOWS\system32\wsldoekd.exe (Trojan.Agent) -> Delete on reboot.

  8. ========== PROCESSES ==========

    Process explorer.exe killed successfully.

    ========== SERVICES/DRIVERS ==========

    ========== REGISTRY ==========

    Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ada19060-796b-11dd-854e-000fdb1ba9ca}\\ deleted successfully.

    Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ada19061-796b-11dd-854e-000fdb1ba9ca}\\ deleted successfully.

    ========== FILES ==========

    c:\windows\SwSys2.bmp moved successfully.

    c:\windows\SwSys1.bmp moved successfully.

    ========== COMMANDS ==========

    File delete failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\etilqs_CBXGJZs2Jd1khXZQCauD scheduled to be deleted on reboot.

    File delete failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\Perflib_Perfdata_894.dat scheduled to be deleted on reboot.

    User's Temp folder emptied.

    User's Temporary Internet Files folder emptied.

    User's Internet Explorer cache folder emptied.

    Local Service Temp folder emptied.

    File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.

    Local Service Temporary Internet Files folder emptied.

    Windows Temp folder emptied.

    Java cache emptied.

    File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\3szpobj6.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.

    File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\3szpobj6.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.

    File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\3szpobj6.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.

    File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\3szpobj6.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.

    File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\3szpobj6.default\urlclassifier3.sqlite scheduled to be deleted on reboot.

    File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\3szpobj6.default\XUL.mfl scheduled to be deleted on reboot.

    FireFox cache emptied.

    Opera cache emptied.

    Temp folders emptied.

    Explorer started successfully

    OTMoveIt3 by OldTimer - Version 1.0.7.0 log created on 11062008_183837

    Files moved on Reboot...

    File C:\DOCUME~1\Owner\LOCALS~1\Temp\etilqs_CBXGJZs2Jd1khXZQCauD not found!

    File C:\DOCUME~1\Owner\LOCALS~1\Temp\Perflib_Perfdata_894.dat not found!

    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat moved successfully.

    C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\3szpobj6.default\Cache\_CACHE_001_ moved successfully.

    C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\3szpobj6.default\Cache\_CACHE_002_ moved successfully.

    C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\3szpobj6.default\Cache\_CACHE_003_ moved successfully.

    C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\3szpobj6.default\Cache\_CACHE_MAP_ moved successfully.

    C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\3szpobj6.default\urlclassifier3.sqlite moved successfully.

    C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\3szpobj6.default\XUL.mfl moved successfully.

  9. ComboFix 08-11-05.02 - Owner 2008-11-06 10:10:12.1 - NTFSx86

    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.740 [GMT -8:00]

    Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe

    * Created a new restore point

    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

    .

    c:\windows\Install.txt

    c:\windows\system32\afisicx.exe

    c:\windows\system32\Install.txt

    c:\windows\system32\Memman.vxd

    c:\windows\system32\noytcyr.exe

    c:\windows\system32\roytctm.exe

    c:\windows\system32\skinboxer43.dll

    c:\windows\system32\tdydowkc.exe

    c:\windows\system32\tpszxyd.sys

    c:\windows\system32\wsldoekd.exe

    .

    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

    .

    -------\Legacy_AFISICX

    -------\Legacy_MABIDWE

    -------\Legacy_NOYTCYR

    -------\Legacy_ROYTCTM

    -------\Legacy_SOXPECA

    -------\Legacy_TDYDOWKC

    -------\Legacy_WSLDOEKD

    -------\Service_afisicx

    -------\Service_noytcyr

    -------\Service_roytctm

    -------\Service_tdydowkc

    -------\Service_wsldoekd

    ((((((((((((((((((((((((( Files Created from 2008-10-06 to 2008-11-06 )))))))))))))))))))))))))))))))

    .

    2008-11-06 10:12 . 2008-11-06 10:12 <DIR> d-------- c:\windows\system32\xircom

    2008-11-06 10:12 . 2008-11-06 10:12 <DIR> d-------- c:\windows\system32\npp

    2008-11-06 10:12 . 2008-11-06 10:12 <DIR> d-------- c:\windows\srchasst

    2008-11-06 10:12 . 2008-11-06 10:12 <DIR> d-------- c:\program files\microsoft frontpage

    2008-11-06 00:27 . 2008-11-06 00:27 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware

    2008-11-06 00:27 . 2008-11-06 00:27 <DIR> d-------- c:\documents and settings\Owner\Application Data\Malwarebytes

    2008-11-06 00:27 . 2008-11-06 00:27 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes

    2008-11-06 00:27 . 2008-10-26 21:53 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys

    2008-11-06 00:27 . 2008-10-26 21:53 15,504 --a------ c:\windows\system32\drivers\mbam.sys

    2008-11-06 00:22 . 2008-11-06 00:22 <DIR> d-------- c:\program files\ERUNT

    2008-11-05 22:03 . 1998-01-14 22:06 304,128 --a------ c:\windows\IsUn0411.exe

    2008-11-05 17:28 . 2008-11-05 17:28 <DIR> d-------- c:\program files\Trend Micro

    2008-11-05 14:13 . 2008-11-05 14:13 <DIR> d-------- c:\documents and settings\Robbie\Application Data\Viewpoint

    2008-11-05 03:25 . 2008-11-05 03:25 <DIR> d-------- c:\documents and settings\Administrator

    2008-10-29 17:24 . 2008-10-29 17:24 42,320 --a------ c:\windows\system32\xfcodec.dll

    2008-10-27 15:45 . 2008-10-27 15:45 <DIR> d-------- c:\program files\Sarm Software

    2008-10-27 00:35 . 2008-10-27 00:35 <DIR> d-------- c:\documents and settings\Owner\Application Data\Xfire Plus

    2008-10-23 22:25 . 2008-10-23 22:25 0 --ah----- c:\windows\SwSys2.bmp

    2008-10-23 22:25 . 2008-10-23 22:25 0 --ah----- c:\windows\SwSys1.bmp

    2008-10-23 22:14 . 2008-10-23 22:14 <DIR> d-------- c:\program files\SystemRequirementsLab

    2008-10-23 22:14 . 2008-10-23 22:14 <DIR> d-------- c:\documents and settings\Owner\Application Data\SystemRequirementsLab

    2008-10-23 22:09 . 2008-10-23 22:32 <DIR> d-------- c:\program files\The Suffering

    2008-10-20 04:05 . 2008-10-20 04:26 <DIR> d-------- c:\documents and settings\All Users\Application Data\YoYoGames

    2008-10-20 00:59 . 2008-10-20 00:59 <DIR> d-------- c:\documents and settings\Robbie\Application Data\Xfire Plus

    2008-10-16 14:56 . 2008-10-16 14:56 <DIR> d-------- c:\documents and settings\All Users\Application Data\Last.fm

    2008-10-16 14:55 . 2008-10-16 14:55 <DIR> d-------- c:\program files\Last.fm

    2008-10-10 13:43 . 2008-10-10 13:43 <DIR> d-------- c:\program files\7-Zip

    2008-10-10 13:35 . 2008-10-10 13:35 <DIR> d-------- c:\program files\Xfire Plus

    .

    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    2008-11-06 18:13 --------- d-----w c:\program files\Steam

    2008-11-06 18:13 --------- d-----w c:\program files\SpeedFan

    2008-11-06 18:13 --------- d-----w c:\documents and settings\Owner\Application Data\Orbit

    2008-11-06 18:04 --------- d-----w c:\documents and settings\Owner\Application Data\Xfire

    2008-11-06 08:39 --------- d-----w c:\documents and settings\Robbie\Application Data\Orbit

    2008-11-06 04:42 --------- d-----w c:\program files\mIRC

    2008-11-06 04:28 --------- d-s---w c:\program files\Xfire

    2008-11-05 11:30 --------- d-----w c:\program files\HP Optical 4 Button USB Mouse

    2008-10-31 02:52 --------- d-----w c:\program files\Orbitdownloader

    2008-10-27 23:45 --------- d--h--w c:\program files\InstallShield Installation Information

    2008-10-27 09:59 --------- d-----w c:\documents and settings\Owner\Application Data\Azureus

    2008-10-20 09:04 --------- d-----w c:\documents and settings\Robbie\Application Data\Xfire

    2008-10-17 11:22 --------- d-----w c:\program files\Cheat Engine

    2008-10-07 03:47 --------- d-----w c:\program files\LucasArts

    2008-10-05 19:26 --------- d-----w c:\program files\TuneUp Utilities 2007

    2008-10-05 19:25 --------- d-----w c:\program files\Westwood

    2008-10-05 19:23 --------- d-----w c:\documents and settings\Owner\Application Data\InstallShield Installation Information

    2008-10-05 18:57 --------- d--h--r c:\documents and settings\Owner\Application Data\yahoo!

    2008-10-05 18:57 --------- d-----w c:\program files\Yahoo!

    2008-10-05 18:57 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo!

    2008-10-01 18:57 --------- d-----w c:\program files\Common Files\Adobe

    2008-09-25 08:40 --------- d-----w c:\documents and settings\Owner\Application Data\U3

    2008-09-23 05:47 --------- d-----w c:\documents and settings\Robbie\Application Data\U3

    2008-09-22 15:53 --------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft

    2008-09-22 15:51 --------- d-----w c:\program files\Lavasoft

    2008-09-22 15:51 --------- d-----w c:\program files\Common Files\Wise Installation Wizard

    2008-09-21 14:01 --------- d-----w c:\program files\Spybot - Search & Destroy

    2008-09-17 01:13 --------- d-----w c:\program files\World of Warcraft

    2008-09-15 15:52 --------- d--h--r c:\documents and settings\Robbie\Application Data\yahoo!

    2008-09-14 03:14 --------- d-----w c:\documents and settings\Robbie\Application Data\Notepad++

    2007-03-09 07:12 27,648 --sha-w c:\windows\system32\AVSredirect.dll

    2008-04-03 21:37 80 --sh--r c:\windows\system32\B007C43AE0.dll

    2007-05-21 15:30 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012007052120070522\index.dat

    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    *Note* empty entries & legit default entries are not shown

    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-11-16 139264]

    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-11 15360]

    "CTZDetec.exe"="c:\program files\Creative\Creative Media Lite\CTZDetec.exe" [2008-04-24 368640]

    "SoftAuto.exe"="c:\program files\Creative\Software Update 3\SoftAuto.exe" [2008-05-27 401408]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "VistaDrive"="c:\windows\VistaDrive\VistaDrive.exe" [2006-10-05 280779]

    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-08-20 155648]

    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-08-20 118784]

    "DAEMON Tools-1033"="c:\program files\D-Tools\daemon.exe" [2004-08-22 81920]

    "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]

    "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]

    "nod32kui"="c:\program files\Eset\nod32kui.exe" [2007-06-05 949376]

    "NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]

    "UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2006-09-07 15872]

    "WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-01-15 37376]

    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-01-31 385024]

    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-02-19 267048]

    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]

    "Xfire Music"="c:\program files\Xfire\xfiremusic.exe" [2006-11-20 253650]

    "AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 c:\windows\ALCXMNTR.EXE]

    "AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 c:\windows\AGRSMMSG.exe]

    "AtiPTA"="atiptaxx.exe" [2006-02-21 c:\windows\system32\atiptaxx.exe]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

    "MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-04-17 9117696]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]

    "nltide_3"="advpack.dll" [2007-03-07 c:\windows\system32\advpack.dll]

    c:\documents and settings\Owner\Start Menu\Programs\Startup\

    Last.fm.lnk - c:\program files\Last.fm\LastFM.exe [2008-10-16 1138688]

    SpeedFan.lnk - c:\program files\SpeedFan\speedfan.exe [2007-09-17 2902528]

    Steam.lnk - c:\windows\Installer\{048298C9-A4D3-490B-9FF9-AB023A9238F3}\Icon048298C91.exe [2007-05-21 27648]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\

    Orbit.lnk - c:\program files\Orbitdownloader\orbitdm.exe [2008-04-14 1707208]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

    "ForceClassicControlPanel"= 1 (0x1)

    "NoSMConfigurePrograms"= 1 (0x1)

    [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]

    "ForceClassicControlPanel"= 1 (0x1)

    "NoSMConfigurePrograms"= 1 (0x1)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

    "msacm.l3acm"= l3codecp.acm

    "msacm.ac3filter"= ac3filter.acm

    "msacm.l3codec"= l3codecp.acm

    "VIDC.XFR1"= xfcodec.dll

    [HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Camio Viewer.lnk]

    path=c:\documents and settings\Owner\Start Menu\Programs\Startup\Camio Viewer.lnk

    backup=c:\windows\pss\Camio Viewer.lnkStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]

    --a------ 2007-04-27 13:17 50736 c:\program files\AIM6\aim6.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BtcMaestro]

    --------- 2007-10-22 22:48 344064 c:\program files\HP USB Multimedia Keyboard\Kmaestro.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]

    --a------ 2007-01-19 09:54 5674352 c:\program files\MSN Messenger\msnmsgr.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]

    --a------ 2008-04-17 15:27 9117696 c:\program files\MySpace\IM\MySpaceIM.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PSwitch]

    --a------ 2007-07-28 22:42 1129472 c:\program files\Proxy Switcher Standard\ProxySwitcher.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

    --a------ 2008-01-31 23:13 385024 c:\program files\QuickTime\QTTask.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]

    --a------ 2008-10-08 18:52 1410296 c:\program files\Steam\steam.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant]

    --a------ 2006-09-07 09:19 15872 c:\program files\Unlocker\UnlockerAssistant.exe

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=

    "%windir%\\system32\\sessmgr.exe"=

    "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=

    "c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=

    "c:\\Program Files\\MSN Messenger\\livecall.exe"=

    "c:\\Program Files\\Xfire\\xfire.exe"=

    "c:\\Program Files\\Azureus\\Azureus.exe"=

    "c:\\Program Files\\FrostWire\\FrostWire.exe"=

    "c:\\Program Files\\iTunes\\iTunes.exe"=

    "c:\\Program Files\\Orbitdownloader\\orbitdm.exe"=

    "c:\\Program Files\\Orbitdownloader\\orbitnet.exe"=

    "c:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=

    R1 atitray;atitray;c:\program files\Radeon Omega Drivers\v3.8.252\ATI Tray Tools\atitray.sys [2006-02-28 12032]

    R2 root;root;c:\program files\MySQL\MySQL Server 5.0\bin\mysqld-nt --defaults-file=c:\program files\MySQL\MySQL Server 5.0\my.ini root [ ]

    R2 UxTuneUp;TuneUp Theme Extension;c:\windows\System32\svchost.exe [2004-08-11 14336]

    R3 RMSPPPOE;WAN Miniport (PPP over Ethernet Protocol);c:\windows\system32\DRIVERS\RMSPPPOE.SYS [2002-10-02 31424]

    R3 USB_RNDIS_XP;Westell WireSpeed Dual Connect Modem;c:\windows\system32\DRIVERS\usb8023.sys [2004-08-11 12672]

    S3 gttap1;GoTrusted TAP Adapter;c:\windows\system32\DRIVERS\gttap1.sys [ ]

    S3 SCR3XX2K;SCR3xx USB SmartCardReader;c:\windows\system32\DRIVERS\SCR3XX2K.sys [2007-10-17 56448]

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

    UxTuneUp

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ada19060-796b-11dd-854e-000fdb1ba9ca}]

    \Shell\AutoRun\command - D:\LaunchU3.exe -a

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ada19061-796b-11dd-854e-000fdb1ba9ca}]

    \Shell\AutoRun\command - pdemvwpm.exe

    \Shell\explore\Command - pdemvwpm.exe

    \Shell\open\Command - pdemvwpm.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E0837E00-F502-AF00-E8CB-A02CC30C5E5B}]

    c:\windows\system32\svchost.exe

    .

    Contents of the 'Scheduled Tasks' folder

    2008-11-01 c:\windows\Tasks\1-Click Maintenance.job

    - c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2007-04-26 18:51]

    .

    - - - - ORPHANS REMOVED - - - -

    WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)

    MSConfigStartUp-Yahoo! Pager - c:\program files\Yahoo!\Messenger\YahooMessenger.exe

    .

    ------- Supplementary Scan -------

    .

    FireFox -: Profile - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\3szpobj6.default\

    FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.com/

    FF -: plugin - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\3szpobj6.default\extensions\[email protected]\plugins\NPYYGInstantPlay.dll

    FF -: plugin - c:\program files\iTunes\Mozilla Plugins\npitunes.dll

    FF -: plugin - c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll

    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

    Rootkit scan 2008-11-06 10:13:15

    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully

    hidden files: 0

    **************************************************************************

    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\root]

    "ImagePath"="\"c:\program files\MySQL\MySQL Server 5.0\bin\mysqld-nt\" --defaults-file=\"c:\program files\MySQL\MySQL Server 5.0\my.ini\" root"

    .

    ------------------------ Other Running Processes ------------------------

    .

    c:\windows\system32\ati2evxx.exe

    c:\program files\Lavasoft\Ad-Aware\aawservice.exe

    c:\windows\system32\scardsvr.exe

    c:\windows\system32\ati2evxx.exe

    c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    c:\windows\system32\CTSVCCDA.EXE

    c:\program files\Creative\Shared Files\CTDevSrv.exe

    c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe

    c:\program files\Orbitdownloader\orbitnet.exe

    c:\program files\ESET\nod32krn.exe

    c:\windows\system32\PnkBstrA.exe

    c:\program files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe

    c:\program files\iPod\bin\iPodService.exe

    c:\windows\system32\wscntfy.exe

    c:\windows\system32\verclsid.exe

    .

    **************************************************************************

    .

    Completion time: 2008-11-06 10:21:44 - machine was rebooted

    ComboFix-quarantined-files.txt 2008-11-06 18:21:39

    Pre-Run: 109,634,826,240 bytes free

    Post-Run: 109,635,780,608 bytes free

    WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe

    [boot loader]

    timeout=2

    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

    [operating systems]

    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

    260

  10. Hi, i just want to say thank you before-hand to everyone thats here for having a website to help people out. I honestly cant remember anything suspicious ive downloaded recently that would have added this malware. The first malware i noticed was one that kept making a clicking noise and would play sound clips randomly. I renamed it as a short fix and fell asleep, and now it has started back up and i have multiple processes that i dont recognize and im SURE are malware. here is my hijackthis log:

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 5:29:40 PM, on 11/5/2008

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v7.00 (7.00.6000.16441)

    Boot mode: Normal

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\Ati2evxx.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\system32\Ati2evxx.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\VistaDrive\VistaDrive.exe

    C:\WINDOWS\ALCXMNTR.EXE

    C:\WINDOWS\AGRSMMSG.exe

    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe

    C:\Program Files\Eset\nod32kui.exe

    C:\Program Files\Unlocker\UnlockerAssistant.exe

    C:\Program Files\Winamp\winampa.exe

    C:\Program Files\iTunes\iTunesHelper.exe

    C:\Program Files\Xfire\xfiremusic.exe

    C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe

    C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe

    C:\Program Files\Creative\Software Update 3\SoftAuto.exe

    C:\Program Files\Orbitdownloader\orbitdm.exe

    C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe

    C:\Program Files\Last.fm\LastFM.exe

    C:\Program Files\SpeedFan\speedfan.exe

    C:\Program Files\Orbitdownloader\orbitnet.exe

    C:\Program Files\Steam\steam.exe

    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    C:\WINDOWS\system32\CTsvcCDA.exe

    C:\Program Files\Creative\Shared Files\CTDevSrv.exe

    C:\Program Files\Eset\nod32krn.exe

    C:\WINDOWS\system32\PnkBstrA.exe

    C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\iPod\bin\iPodService.exe

    C:\WINDOWS\system32\wscntfy.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\Ati2evxx.exe

    C:\WINDOWS\system32\mabidwe.exe

    C:\WINDOWS\system32\soxpeca.exe

    C:\Program Files\Xfire\xfire.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\Mozilla Firefox\firefox.exe

    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/

    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :

    O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll

    O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 9\SnagItBHO.dll

    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

    O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL

    O2 - BHO: Yahoo! IE Suggest - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - (no file)

    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

    O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll

    O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL

    O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 9\SnagItIEAddin.dll

    O4 - HKLM\..\Run: [VistaDrive] C:\WINDOWS\VistaDrive\VistaDrive.exe

    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE

    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe

    O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe

    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe

    O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033

    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"

    O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe

    O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE

    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

    O4 - HKLM\..\Run: [unlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"

    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

    O4 - HKLM\..\Run: [Xfire Music] "C:\Program Files\Xfire\xfiremusic.exe"

    O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"

    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: [CTZDetec.exe] "C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe"

    O4 - HKCU\..\Run: [softAuto.exe] "C:\Program Files\Creative\Software Update 3\SoftAuto.exe"

    O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')

    O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')

    O4 - HKUS\S-1-5-21-1659004503-152049171-725345543-1004\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (User 'Robbie')

    O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')

    O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')

    O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')

    O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')

    O4 - S-1-5-18 Startup: Last.fm.lnk = C:\Program Files\Last.fm\LastFM.exe (User 'SYSTEM')

    O4 - S-1-5-18 Startup: SpeedFan.lnk = C:\Program Files\SpeedFan\speedfan.exe (User 'SYSTEM')

    O4 - S-1-5-18 Startup: Steam.lnk = ? (User 'SYSTEM')

    O4 - .DEFAULT Startup: Last.fm.lnk = C:\Program Files\Last.fm\LastFM.exe (User 'Default user')

    O4 - .DEFAULT Startup: SpeedFan.lnk = C:\Program Files\SpeedFan\speedfan.exe (User 'Default user')

    O4 - .DEFAULT Startup: Steam.lnk = ? (User 'Default user')

    O4 - Startup: Last.fm.lnk = C:\Program Files\Last.fm\LastFM.exe

    O4 - Startup: SpeedFan.lnk = C:\Program Files\SpeedFan\speedfan.exe

    O4 - Startup: Steam.lnk = ?

    O4 - Global Startup: Orbit.lnk = C:\Program Files\Orbitdownloader\orbitdm.exe

    O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201

    O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204

    O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203

    O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202

    O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

    O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm

    O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

    O23 - Service: afisicx Service (afisicx) - Unknown owner - C:\WINDOWS\system32\afisicx.exe

    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe

    O23 - Service: CT Device Query service (CTDevice_Srv) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTDevSrv.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe

    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: mabidwe Service (mabidwe) - Unknown owner - C:\WINDOWS\system32\mabidwe.exe

    O23 - Service: Windows File Manager Services (mscbcosd) - Unknown owner - C:\WINDOWS\system32\mscbco.exe

    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

    O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe

    O23 - Service: noytcyr Service (noytcyr) - Unknown owner - C:\WINDOWS\system32\noytcyr.exe

    O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

    O23 - Service: root - Unknown owner - C:\Program.exe (file missing)

    O23 - Service: roytctm Service (roytctm) - Unknown owner - C:\WINDOWS\system32\roytctm.exe

    O23 - Service: soxpeca Service (soxpeca) - Unknown owner - C:\WINDOWS\system32\soxpeca.exe

    O23 - Service: tdydowkc Service (tdydowkc) - Unknown owner - C:\WINDOWS\system32\tdydowkc.exe

    O23 - Service: wsldoekd Service (wsldoekd) - Unknown owner - C:\WINDOWS\system32\wsldoekd.exe

    --

    End of file - 11114 bytes