QUOTE (__RiP_ChAiN_ @ Aug 17 2008, 02:02 AM)

Hello marian,
Please uninstall your old version of HijackThis, it is outdated.
Click here to download
HJTInstall.exe- Save HJTInstall.exe to your desktop.
- Doubleclick on the HJTInstall.exe icon on your desktop.
- By default it will install to C:\Program Files\Trend Micro\HijackThis .
- Click on Install.
- It will create a HijackThis icon on the desktop.
- Once installed, it will launch Hijackthis.
- DO NOT have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.
----------------------------------------------- Step 2Download
Combofix from any of the links below. You
must rename it before saving it. Save it to your desktop.
Link 1Link 2Link 3 

--------------------------------------------------------------------
Double click on
Combo-Fix.exe & follow the prompts.
When finished, it will produce a report for you. - Please post the C:\ComboFix.txt along with a HijackThis log so we can continue cleaning the system.
Hereunder are the reports from Combofix , and hijack this which you required me to run.
ComboFix 08-08-29.02 - Zaievol 2008-08-30 15:50:05.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1473 [GMT 8:00]
Running from: C:\Documents and Settings\Zaievol\Desktop\Combo-Fix.exe
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Start Menu\Programs\XPSecurityCenter
C:\Documents and Settings\All Users\Start Menu\Programs\XPSecurityCenter\Uninstall.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\XPSecurityCenter\XPSecurityCenter.lnk
C:\Documents and Settings\Zaievol\Application Data\FunWebProducts
C:\Documents and Settings\Zaievol\Application Data\macromedia\Flash Player\#SharedObjects\JDF4R7G4\bin.clearspring.com
C:\Documents and Settings\Zaievol\Application Data\macromedia\Flash Player\#SharedObjects\JDF4R7G4\bin.clearspring.com\clearspring.sol
C:\Documents and Settings\Zaievol\Application Data\macromedia\Flash Player\#SharedObjects\JDF4R7G4\bin.clearspring.com\ws\wan\wanLib.swf\463a656a1ea70875.sol
C:\Documents and Settings\Zaievol\Application Data\macromedia\Flash Player\#SharedObjects\JDF4R7G4\interclick.com
C:\Documents and Settings\Zaievol\Application Data\macromedia\Flash Player\#SharedObjects\JDF4R7G4\interclick.com\ud.sol
C:\Documents and Settings\Zaievol\Application Data\macromedia\Flash Player\#SharedObjects\JDF4R7G4\static.youku.com
C:\Documents and Settings\Zaievol\Application Data\macromedia\Flash Player\#SharedObjects\JDF4R7G4\static.youku.com\v\swf\qplayer.swf\qplayer.sol
C:\Documents and Settings\Zaievol\Application Data\macromedia\Flash Player\#SharedObjects\JDF4R7G4\static.youku.com\v1.0.0261\v\swf\qplayer.swf\qplayer.sol
C:\Documents and Settings\Zaievol\Application Data\macromedia\Flash Player\#SharedObjects\JDF4R7G4\static.youku.com\v1.0.0267\v\swf\qplayer.swf\qplayer.sol
C:\Documents and Settings\Zaievol\Application Data\macromedia\Flash Player\#SharedObjects\JDF4R7G4\static.youku.com\v1.0.0268\v\swf\qplayer.swf\qplayer.sol
C:\Documents and Settings\Zaievol\Application Data\macromedia\Flash Player\#SharedObjects\JDF4R7G4\static.youku.com\v1.0.0270\v\swf\qplayer.swf\qplayer.sol
C:\Documents and Settings\Zaievol\Application Data\macromedia\Flash Player\#SharedObjects\JDF4R7G4\static.youku.com\v1.0.0272\v\swf\qplayer.swf\qplayer.sol
C:\Documents and Settings\Zaievol\Application Data\macromedia\Flash Player\#SharedObjects\JDF4R7G4\static.youku.com\v1.0.0275\v\swf\qplayer.swf\qplayer.sol
C:\Documents and Settings\Zaievol\Application Data\macromedia\Flash Player\#SharedObjects\JDF4R7G4\static.youku.com\v1.0.0288\v\swf\qplayer.swf\qplayer.sol
C:\Documents and Settings\Zaievol\Application Data\macromedia\Flash Player\#SharedObjects\JDF4R7G4\static.youku.com\v1.0.0290\v\swf\qplayer.swf\qplayer.sol
C:\Documents and Settings\Zaievol\Application Data\macromedia\Flash Player\#SharedObjects\JDF4R7G4\static.youku.com\v1.0.0293\v\swf\qplayer.swf\qplayer.sol
C:\Documents and Settings\Zaievol\Application Data\macromedia\Flash Player\#SharedObjects\JDF4R7G4\static.youku.com\v1.0.0307\v\swf\qplayer.swf\qplayer.sol
C:\Documents and Settings\Zaievol\Application Data\macromedia\Flash Player\#SharedObjects\JDF4R7G4\static.youku.com\v1.0.0312\v\swf\qplayer.swf\qplayer.sol
C:\Documents and Settings\Zaievol\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com
C:\Documents and Settings\Zaievol\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com\settings.sol
C:\Documents and Settings\Zaievol\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Zaievol\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\Zaievol\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#static.youku.com
C:\Documents and Settings\Zaievol\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#static.youku.com\settings.sol
C:\Documents and Settings\Zaievol\Cookies\adilan.vbs
C:\Documents and Settings\Zaievol\Cookies\akysyraso.ban
C:\Documents and Settings\Zaievol\Cookies\dovub.inf
C:\Documents and Settings\Zaievol\Cookies\ebixa.sys
C:\Documents and Settings\Zaievol\Cookies\hasas.exe
C:\Documents and Settings\Zaievol\Cookies\mulehumo.scr
C:\Documents and Settings\Zaievol\Cookies\mytedehery.db
C:\Documents and Settings\Zaievol\Cookies\ujagum.vbs
C:\Documents and Settings\Zaievol\Cookies\xyjo.exe
C:\Documents and Settings\Zaievol\Local Settings\Temporary Internet Files\agisen.db
C:\Documents and Settings\Zaievol\Local Settings\Temporary Internet Files\fovikevan._dl
C:\Documents and Settings\Zaievol\Local Settings\Temporary Internet Files\gacewyseta.com
C:\Documents and Settings\Zaievol\Local Settings\Temporary Internet Files\jomo.lib
C:\Documents and Settings\Zaievol\Local Settings\Temporary Internet Files\jygow.ban
C:\Documents and Settings\Zaievol\Local Settings\Temporary Internet Files\paticop.exe
C:\Documents and Settings\Zaievol\Local Settings\Temporary Internet Files\qikywymy._sy
C:\Documents and Settings\Zaievol\Local Settings\Temporary Internet Files\ywib.ban
C:\Program Files\FunWebProducts
C:\Program Files\FunWebProducts\ScreenSaver\Images\
019503D6.urr
C:\Program Files\FunWebProducts\Shared\Cache\CursorManiaBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html
C:\Program Files\XPSecurityCenter
C:\Program Files\XPSecurityCenter\comp.dat
C:\Program Files\XPSecurityCenter\data\daily.cvd
C:\Program Files\XPSecurityCenter\htmlayout.dll
C:\Program Files\XPSecurityCenter\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest
C:\Program Files\XPSecurityCenter\Microsoft.VC80.CRT\msvcm80.dll
C:\Program Files\XPSecurityCenter\Microsoft.VC80.CRT\msvcp80.dll
C:\Program Files\XPSecurityCenter\Microsoft.VC80.CRT\msvcr80.dll
C:\Program Files\XPSecurityCenter\pthreadVC2.dll
C:\Program Files\XPSecurityCenter\un.ico
C:\Program Files\XPSecurityCenter\unzip32.dll
C:\Program Files\XPSecurityCenter\wscui.cpl
C:\Program Files\XPSecurityCenter\XP_SecurityCenter.cfg
C:\Program Files\XPSecurityCenter\XPSecurityCenter.exe
C:\WINDOWS\system32\braviax.exe
C:\WINDOWS\system32\vsdatant.sys
H:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MYWEBSEARCHSERVICE
-------\Legacy_VSDATANT
-------\Service_MyWebSearchService
-------\Service_vsdatant
((((((((((((((((((((((((( Files Created from 2008-07-28 to 2008-08-30 )))))))))))))))))))))))))))))))
.
2008-08-30 15:39 . 2008-08-30 15:39 <DIR> d-------- C:\Program Files\Trend Micro
2008-08-27 16:51 . 2008-08-27 16:51 <DIR> dr------- C:\Documents and Settings\Zaievol\Application Data\Brother
2008-08-19 00:25 . 2008-08-19 20:43 <DIR> d-------- C:\Documents and Settings\zaiganda28
2008-08-19 00:25 . 2006-01-13 09:24 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-08-17 21:49 . 2008-08-17 21:50 400 --ah----- C:\IPH.PH
2008-08-17 15:07 . 2008-08-17 15:07 419 --a------ C:\WINDOWS\BRWMARK.INI
2008-08-17 15:07 . 2008-08-17 15:07 27 --a------ C:\WINDOWS\BRPP2KA.INI
2008-08-17 15:06 . 2006-01-06 15:53 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-08-17 14:55 . 2008-08-17 14:55 50 --a------ C:\WINDOWS\system32\bridf07a.dat
2008-08-17 14:54 . 2007-02-01 13:19 1,520,640 --a------ C:\WINDOWS\system32\BrWia07a.dll
2008-08-17 14:54 . 2007-01-26 16:13 54,784 --a------ C:\WINDOWS\system32\brinsstr.dll
2008-08-17 14:54 . 2007-01-26 14:06 45,568 --a------ C:\WINDOWS\system32\BrUsi07a.dll
2008-08-17 14:54 . 2004-10-15 12:50 15,295 --a------ C:\WINDOWS\system32\drivers\BrScnUsb.sys
2008-08-17 14:53 . 2008-08-17 14:55 <DIR> d-------- C:\Program Files\Brother
2008-08-17 14:53 . 2006-12-28 13:39 176,128 --------- C:\WINDOWS\system32\BroSNMP.dll
2008-08-17 14:53 . 2007-01-18 13:51 163,840 --------- C:\WINDOWS\system32\NSSearch.dll
2008-08-17 14:53 . 2007-02-15 13:54 131,072 --------- C:\WINDOWS\brunin03.dll
2008-08-17 14:53 . 2007-01-25 17:16 94,208 -r------- C:\WINDOWS\system32\BrDctF2.dll
2008-08-17 14:53 . 2007-01-15 21:54 12,288 -r------- C:\WINDOWS\system32\BrDctF2S.dll
2008-08-17 14:53 . 2007-01-15 16:09 12,288 -r------- C:\WINDOWS\system32\BrDctF2L.dll
2008-08-17 14:53 . 2001-11-15 01:00 6,224 --------- C:\WINDOWS\CVRPAGE.BMP
2008-08-17 14:52 . 2008-08-17 14:52 <DIR> d-------- C:\Program Files\Nuance
2008-08-17 14:49 . 2008-08-17 14:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Brother
2008-08-17 14:29 . 2008-08-17 14:29 <DIR> d-------- C:\Documents and Settings\Guest\Application Data\Grisoft
2008-08-16 20:02 . 2008-08-28 13:32 <DIR> d-------- C:\Program Files\The Lost Crown
2008-08-16 18:09 . 2008-08-30 15:56 61,724,704 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-08-16 18:09 . 2008-08-30 15:53 727,520 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-08-16 18:05 . 2008-08-16 18:05 <DIR> d-------- C:\Program Files\ZoneAlarmSB
2008-08-16 18:02 . 2008-08-16 18:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-08-16 18:02 . 2008-07-09 09:05 75,248 --a------ C:\WINDOWS\zllsputility.exe
2008-08-16 18:02 . 2008-08-16 18:10 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2008-08-16 18:01 . 2008-08-16 18:01 <DIR> d-------- C:\Program Files\Zone Labs
2008-08-16 17:29 . 2008-08-16 17:29 18,301 --a------ C:\Documents and Settings\All Users\Application Data\ducuq.reg
2008-08-16 17:29 . 2008-08-16 17:29 16,709 --a------ C:\Documents and Settings\All Users\Application Data\lywahinow.bin
2008-08-16 17:29 . 2008-08-16 17:29 16,012 --a------ C:\Program Files\Common Files\oroq.bat
2008-08-16 17:29 . 2008-08-16 17:29 15,480 --a------ C:\WINDOWS\owokarel.sys
2008-08-16 17:29 . 2008-08-16 17:29 14,764 --a------ C:\WINDOWS\koryxej._sy
2008-08-16 17:29 . 2008-08-16 17:29 12,955 --a------ C:\WINDOWS\system32\qocit.inf
2008-08-16 17:13 . 2008-08-16 17:13 <DIR> d-------- C:\Documents and Settings\Zaievol\Application Data\Grisoft
2008-08-16 17:13 . 2008-08-16 17:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-08-16 17:13 . 2007-05-30 20:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-08-16 00:51 . 2008-05-18 17:51 <DIR> d-------- C:\Documents and Settings\Guest\ff_temp
2008-08-16 00:51 . 2008-08-16 00:51 <DIR> d-------- C:\Documents and Settings\Guest\Application Data\PC Suite
2008-08-16 00:51 . 2008-05-18 17:51 <DIR> d-------- C:\Documents and Settings\Guest\7zS182C.tmp
2008-08-16 00:51 . 2008-08-19 18:54 <DIR> d-------- C:\Documents and Settings\Guest
2008-08-15 20:31 . 2006-01-06 15:53 78,464 --a------ C:\WINDOWS\system32\drivers\usbvideo.sys
2008-08-15 20:31 . 2006-01-06 15:53 20,992 --a------ C:\WINDOWS\system32\dshowext.ax
2008-08-13 20:16 . 2008-08-13 20:16 19,652 --a------ C:\WINDOWS\icetygowi.db
2008-08-13 20:16 . 2008-08-13 20:16 19,608 --a------ C:\WINDOWS\efecehed.scr
2008-08-13 20:16 . 2008-08-13 20:16 18,767 --a------ C:\WINDOWS\system32\yrawutukef._dl
2008-08-13 20:16 . 2008-08-13 20:16 18,650 --a------ C:\Documents and Settings\Zaievol\Application Data\ukocuki.com
2008-08-13 20:16 . 2008-08-13 20:16 17,807 --a------ C:\WINDOWS\xefatuqa.vbs
2008-08-13 20:16 . 2008-08-13 20:16 17,019 --a------ C:\WINDOWS\gicijuwahe.dll
2008-08-13 20:16 . 2008-08-13 20:16 15,772 --a------ C:\Documents and Settings\Zaievol\Application Data\zesyvad.dat
2008-08-13 20:16 . 2008-08-13 20:16 15,684 --a------ C:\WINDOWS\tukypyvug.vbs
2008-08-13 20:16 . 2008-08-13 20:16 15,421 --a------ C:\Documents and Settings\All Users\Application Data\ligypa.exe
2008-08-13 20:16 . 2008-08-13 20:16 14,695 --a------ C:\Program Files\Common Files\luha.scr
2008-08-13 20:16 . 2008-08-13 20:16 14,178 --a------ C:\WINDOWS\pucocynuti.exe
2008-08-13 20:16 . 2008-08-13 20:16 14,089 --a------ C:\Documents and Settings\Zaievol\Application Data\zyxapelono.reg
2008-08-13 20:16 . 2008-08-13 20:16 13,976 --a------ C:\WINDOWS\rocicikop.inf
2008-08-13 20:16 . 2008-08-13 20:16 13,283 --a------ C:\WINDOWS\system32\okivamy.reg
2008-08-13 20:16 . 2008-08-13 20:16 10,965 --a------ C:\WINDOWS\faqitybow.dat
2008-08-13 20:16 . 2008-08-13 20:16 10,257 --a------ C:\Documents and Settings\Zaievol\Application Data\luvydet.dat
2008-08-13 18:19 . 2008-08-13 18:19 <DIR> d-------- C:\Program Files\Vimicro
2008-08-13 18:19 . 2008-08-13 18:19 <DIR> d-------- C:\Documents and Settings\Zaievol\Application Data\InstallShield
2008-08-13 18:19 . 2007-08-08 10:59 1,472,896 --a------ C:\WINDOWS\system32\drivers\usbVM302.sys
2008-08-13 18:19 . 2007-03-18 18:06 475,136 --a------ C:\WINDOWS\system32\drivers\vvftav302.sys
2008-08-13 18:19 . 2006-11-08 14:25 122,880 --a------ C:\WINDOWS\rm302.exe
2008-08-13 18:19 . 2007-04-03 15:50 77,824 --a------ C:\WINDOWS\ZC0302Cap.exe
2008-08-13 18:19 . 2004-12-10 14:30 61,440 --a------ C:\WINDOWS\system32\VM302STI.dll
2008-08-13 18:19 . 2007-10-25 14:09 57,344 --a------ C:\WINDOWS\VM302Snap.exe
2008-08-13 18:19 . 2006-07-04 14:16 49,152 --a------ C:\WINDOWS\Domino.exe
2008-08-13 18:19 . 2002-10-16 09:29 49,152 --a------ C:\WINDOWS\amcap.exe
2008-08-13 18:09 . 2008-08-13 18:09 <DIR> d-------- C:\Program Files\Vimicro Corporation
2008-08-13 18:09 . 2008-08-13 18:09 <DIR> d-------- C:\Program Files\Common Files\Vimicro Corporation
2008-08-13 18:09 . 2007-04-30 15:31 32,768 --a------ C:\WINDOWS\merit.exe
2008-08-11 21:02 . 2008-08-26 15:52 151 --a------ C:\WINDOWS\PhotoSnapViewer.INI
2008-08-06 14:38 . 2008-08-06 14:38 <DIR> d-------- C:\Program Files\Common Files\muvee Technologies
2008-08-06 13:51 . 2008-08-06 13:51 16,202 --a------ C:\WINDOWS\goli.bat
2008-08-02 00:32 . 2008-08-02 00:32 16,770 --a------ C:\WINDOWS\system32\lavig.dat
2008-07-29 11:21 . 2008-07-29 11:21 19,837 --a------ C:\WINDOWS\system32\aturecila._dl
2008-07-29 11:21 . 2008-07-29 11:21 18,598 --a------ C:\Documents and Settings\All Users\Application Data\icyjudeb.exe
2008-07-29 11:21 . 2008-07-29 11:21 18,229 --a------ C:\Program Files\Common Files\yhuv.sys
2008-07-29 11:21 . 2008-07-29 11:21 14,945 --a------ C:\WINDOWS\ubyfus._dl
2008-07-29 11:21 . 2008-07-29 11:21 14,017 --a------ C:\Program Files\Common Files\elesifyrak.sys
2008-07-29 11:21 . 2008-07-29 11:21 13,991 --a------ C:\Documents and Settings\Zaievol\Application Data\voluw.bat
2008-07-29 11:21 . 2008-07-29 11:21 13,909 --a------ C:\WINDOWS\jofifalig.inf
2008-07-29 11:21 . 2008-07-29 11:21 13,636 --a------ C:\WINDOWS\taxapibode._sy
2008-07-29 11:21 . 2008-07-29 11:21 13,419 --a------ C:\WINDOWS\oreg.scr
2008-07-29 11:21 . 2008-07-29 11:21 13,226 --a------ C:\Documents and Settings\All Users\Application Data\ojujiqux.sys
2008-07-29 11:21 . 2008-07-29 11:21 12,426 --a------ C:\Documents and Settings\Zaievol\Application Data\digikexo.com
2008-07-29 11:21 . 2008-07-29 11:21 11,471 --a------ C:\WINDOWS\bawocuxur._sy
2008-07-29 11:21 . 2008-07-29 11:21 11,291 --a------ C:\WINDOWS\system32\ylyx.scr
2008-07-29 11:21 . 2008-07-29 11:21 10,828 --a------ C:\WINDOWS\qowifesyru.vbs
2008-07-29 11:21 . 2008-07-29 11:21 10,310 --a------ C:\WINDOWS\yfyvowen.lib
2008-07-28 17:13 . 2008-07-28 17:13 <DIR> d-------- C:\Program Files\Common Files\Adobe AIR
2008-07-25 22:47 . 2008-07-25 22:47 <DIR> d-------- C:\Documents and Settings\Zaievol\Application Data\acccore
2008-07-21 05:54 . 2008-07-21 05:54 <DIR> d-------- C:\Logs
2008-07-20 18:58 . 2008-07-20 19:20 <DIR> d-------- C:\Program Files\Common Files\Blizzard Entertainment
2008-07-10 07:35 . 2008-07-10 07:35 <DIR> d-------- C:\Program Files\DivX
2008-07-09 23:44 . 2008-07-09 23:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\POP3Profiles
2008-07-09 22:05 . 2008-07-09 23:26 <DIR> d-------- C:\Program Files\Buka
2008-07-09 21:59 . 2008-07-09 21:59 165,376 --a------ C:\WINDOWS\system32\drivers\atksgt.sys
2008-07-09 21:59 . 2008-07-09 21:59 18,048 --a------ C:\WINDOWS\system32\drivers\lirsgt.sys
2008-07-09 21:58 . 2008-07-09 21:58 <DIR> d-------- C:\WINDOWS\system32\Adobe
2008-07-09 21:58 . 2008-07-09 21:58 <DIR> d-------- C:\WINDOWS\Profiles
2008-07-09 21:58 . 2008-07-09 21:58 <DIR> d-------- C:\Documents and Settings\Zaievol\Application Data\InterTrust
2008-07-09 21:58 . 1998-10-29 14:45 306,688 --a------ C:\WINDOWS\IsUninst.exe
2008-07-09 19:05 . 2008-07-09 19:05 <DIR> d-------- C:\Program Files\LimeWire
2008-07-09 19:05 . 2008-08-30 13:00 <DIR> d-------- C:\Documents and Settings\Zaievol\Application Data\LimeWire
2008-07-09 18:55 . 2008-07-09 18:55 <DIR> d-------- C:\Program Files\SEGA
2008-07-09 18:49 . 2008-07-09 18:49 <DIR> dr-h----- C:\Documents and Settings\Zaievol\Application Data\SecuROM
2008-07-09 18:49 . 2008-07-09 18:49 108,144 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2008-07-09 18:46 . 2008-07-09 22:28 205 --a------ C:\WINDOWS\disneysy.ini
2008-07-09 18:46 . 2008-07-09 22:40 121 --a------ C:\WINDOWS\disney.ini
2008-07-09 18:40 . 2008-07-09 18:40 <DIR> d--hs---- C:\WINDOWS\ftpcache
2008-07-09 08:16 . 2008-07-09 08:16 126,976 --a------ C:\WINDOWS\War3Unin.exe
2008-07-09 08:16 . 2008-07-09 08:17 14,949 --a------ C:\WINDOWS\War3Unin.dat
2008-07-09 08:16 . 2008-07-09 08:16 2,829 --a------ C:\WINDOWS\War3Unin.pif
2008-07-08 21:05 . 2008-07-08 21:04 286,720 --a------ C:\WINDOWS\iun506.exe
2008-07-08 21:04 . 2008-07-08 21:04 <DIR> d-------- C:\WINDOWS\Prefs
2008-07-08 21:04 . 2008-08-16 01:05 <DIR> d-------- C:\Program Files\Las Vegas Casino
2008-07-05 13:50 . 2008-07-22 18:33 <DIR> d-------- C:\Documents and Settings\Zaievol\Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-29 03:56 1,909,248 ----a-w C:\WINDOWS\Internet Logs\xDB10.tmp
2008-08-29 03:56 1,440,768 ----a-w C:\WINDOWS\Internet Logs\xDB11.tmp
2008-08-29 03:22 --------- d-----w C:\Program Files\MSN Messenger
2008-08-25 05:35 863,232 ----a-w C:\WINDOWS\Internet Logs\xDBE.tmp
2008-08-25 05:35 1,426,944 ----a-w C:\WINDOWS\Internet Logs\xDBF.tmp
2008-08-22 16:26 574,464 ----a-w C:\WINDOWS\Internet Logs\xDBC.tmp
2008-08-22 16:26 1,419,776 ----a-w C:\WINDOWS\Internet Logs\xDBD.tmp
2008-08-21 03:20 1,418,240 ----a-w C:\WINDOWS\Internet Logs\xDBB.tmp
2008-08-21 03:19 1,415,680 ----a-w C:\WINDOWS\Internet Logs\xDBA.tmp
2008-08-20 15:29 --------- d-----w C:\Documents and Settings\Zaievol\Application Data\Skype
2008-08-19 12:39 2,932,736 ----a-w C:\WINDOWS\Internet Logs\xDB9.tmp
2008-08-19 04:24 1,400,832 ----a-w C:\WINDOWS\Internet Logs\xDB8.tmp
2008-08-19 04:24 1,037,312 ----a-w C:\WINDOWS\Internet Logs\xDB7.tmp
2008-08-18 08:54 --------- d-----w C:\Documents and Settings\Zaievol\Application Data\Nokia Multimedia Player
2008-08-17 07:13 3,022,848 ----a-w C:\WINDOWS\Internet Logs\xDB5.tmp
2008-08-17 07:13 1,377,280 ----a-w C:\WINDOWS\Internet Logs\xDB6.tmp
2008-08-17 06:53 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-16 17:47 586,240 ----a-w C:\WINDOWS\Internet Logs\xDB3.tmp
2008-08-16 17:47 1,369,600 ----a-w C:\WINDOWS\Internet Logs\xDB4.tmp
2008-08-16 17:42 1,369,088 ----a-w C:\WINDOWS\Internet Logs\xDB2.tmp
2008-08-16 17:41 2,998,784 ----a-w C:\WINDOWS\Internet Logs\xDB1.tmp
2008-08-16 16:01 --------- d-----w C:\Documents and Settings\Zaievol\Application Data\skypePM
2008-08-16 09:44 --------- d-----w C:\Program Files\ESET
2008-08-16 09:29 10,139 ----a-w C:\Program Files\Common Files\oguxafowev._sy
2008-08-06 07:25 560 ----a-w C:\Documents and Settings\Zaievol\Application Data\ViewerApp.dat
2008-08-06 06:38 --------- d-----w C:\Program Files\Sony Corporation
2008-07-29 03:21 19,820 ----a-w C:\Program Files\Common Files\axyxe.dl
2008-07-29 03:21 16,848 ----a-w C:\Program Files\Common Files\adytytabu.ban
2008-07-25 15:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL
2008-07-13 12:25 --------- d-----w C:\Documents and Settings\Zaievol\Application Data\Ahead
2008-07-09 14:47 --------- d-----w C:\Program Files\EA SPORTS
2008-07-09 13:58 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-09 01:05 1,086,952 ----a-w C:\WINDOWS\system32\zpeng24.dll
2008-07-06 09:13 --------- d-----w C:\Program Files\FrostWire
2008-07-06 06:29 --------- d-----w C:\Documents and Settings\Zaievol\Application Data\FrostWire
2008-06-29 10:05 512,096 ----a-w C:\WINDOWS\system32\drivers\amon.sys
2008-06-29 10:05 298,104 ----a-w C:\WINDOWS\system32\imon.dll
2008-06-29 10:05 15,424 ----a-w C:\WINDOWS\system32\drivers\nod32drv.sys
2008-06-11 00:04 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-06-11 00:04 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-05-18 09:51 107,132 ----a-w C:\WINDOWS\UninstallFirefox.exe
2008-05-18 03:11 315,392 ----a-w C:\WINDOWS\HideWin.exe
.
------- Sigcheck -------
2006-01-13 10:03 360448 2a4818aea80acd2c95d7d92d2f3155f8 C:\WINDOWS\system32\drivers\tcpip.sys
2006-01-13 09:46 1075200 2deaca71a7fd77205f59d48d76b2f565 C:\WINDOWS\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2}"= "C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL" [2008-05-18 13:34 66912]
[HKEY_CLASSES_ROOT\clsid\{0579b4b6-0293-4d73-b02d-5ebb0ba0f0a2}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-07-04 14:01 148776]
"LightScribe Control Panel"="C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-06-20 12:49 451872]
"PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-06-27 16:21 1449984]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-26 22:14 68856]
"Messenger (Yahoo!)"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2008-05-27 21:58 4269296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-01-09 01:53 8523776]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-01-09 01:53 81920]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2008-06-29 18:05 949376]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-07-04 14:20 161064]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2006-06-15 12:36 229376]
"BigDogPath"="C:\WINDOWS\VM302Snap.exe" [2007-10-25 14:09 57344]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"Domino"="C:\WINDOWS\Domino.exe" [2006-07-04 14:16 49152]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 17:25 6731312]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 09:05 919016]
"BrMfcWnd"="C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe" [2007-03-12 14:51 663552]
"ControlCenter3"="C:\Program Files\Brother\ControlCenter3\brctrcen.exe" [2007-01-26 15:58 65536]
"nwiz"="nwiz.exe" [2008-01-09 01:53 1626112 C:\WINDOWS\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnsc"="C:\WINDOWS\system32\msnsc.exe" [2006-01-13 09:36 62054]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nlsf"="move" [X]
"tscuninstall"="C:\WINDOWS\system32\tscupgrd.exe" [2006-01-13 09:25 44544]
C:\Documents and Settings\Zaievol\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2008-03-27 01:19:43 147456]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Picture Package Menu.lnk - C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe [2008-08-06 14:38:29 151552]
Picture Package VCD Maker.lnk - C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe [2008-08-06 14:38:27 106496]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.imc"= imc32.acm
"msacm.l3codecp"= l3codecp.acm
"VIDC.i263"= i263_32.drv
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2005-12-14 19:13 7095344 C:\Program Files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TBPanel]
--a------ 2008-01-29 11:19 2157096 C:\Program Files\VDOTool\TBPANEL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
-r------- 2005-05-03 18:43 69632 C:\WINDOWS\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
-r------- 2007-08-20 15:38 16384512 C:\WINDOWS\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
-r------- 2007-08-03 13:22 1826816 C:\WINDOWS\SkyTel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\FrostWire\\FrostWire.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
S3 vvftav302;vvftav302;C:\WINDOWS\system32\drivers\vvftav302.sys [2007-03-18 18:06]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7644f23c-2bcf-11dd-bfe5-001e8c078927}]
\Shell\AutoRun\command - H:\
\Shell\explore\Command - WScript.exe .\azkaban.vbs
\Shell\open\Command - WScript.exe .\azkaban.vbs
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-XP SecurityCenter - C:\Program Files\XPSecurityCenter\xpsecuritycenter.exe
HKLM-Run-MyWebSearch Plugin - C:\PROGRA~1\MYWEBS~1\bar\3.bin\M3PLUGIN.DLL
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Zaievol\Application Data\Mozilla\Firefox\Profiles\rekggvdq.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.yahoo.com/
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\NPAskSBr.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\NPMyWebS.dll
FF -: plugin - C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF -: plugin - C:\Program Files\Yahoo!\Shared\npYState.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-08-30 15:56:19
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\ESET\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Brother\ControlCenter3\BrccMCtl.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Brother\Brmfcmon\BrMfcMon.exe
C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-08-30 15:59:28 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-30 07:59:24
Pre-Run: 10,787,393,536 bytes free
Post-Run: 12,714,205,184 bytes free
379
Hijack this scanned report
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:03:45 PM, on 8/30/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\WINDOWS\VM302Snap.exe
C:\WINDOWS\Domino.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.com/customize/ie/defaul...rch/search.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
R3 - URLSearchHook: Yahoo! 工具列 - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: Yahoo! 工具列 - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM302Snap.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Domino] C:\WINDOWS\Domino.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKUS\S-1-5-19\..\Run: [msnsc] C:\WINDOWS\system32\msnsc.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [msnsc] C:\WINDOWS\system32\msnsc.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [msnsc] C:\WINDOWS\system32\msnsc.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnsc] C:\WINDOWS\system32\msnsc.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'Default user')
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: Registration Prince of Persia The Two Thrones.LNK = F:\Support\Register\RegistrationReminder.exe
O4 - Global Startup: Picture Package Menu.lnk = ?
O4 - Global Startup: Picture Package VCD Maker.lnk = ?
O8 - Extra context menu item: &Search -
http://edits.mywebsearch.com/toolbaredits/...html?p=ZKfox000O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) -
http://javadl.sun.com/webapps/download/AutoDL?BundleId=21871O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 8748 bytes