1
Tech Clinic / complete folder omg
« on: November 04, 2006, 06:52:46 AM »
The file that always spiking my cpu is whatever im using (mozillaFF, linerider, cs, photoshop everything really) but its weird cuz its in periods, sometimes the cpu works normal for a while, then the high pitch sound comes bringing slowness, for long. i observed another weird fact is that in the task manager the PF value is always below 50% and the avalable memory seems to be on 50% whenever i look at it..
and the auto updates is on "..When i choose to install.."
Syko - 06-11-01 1:19:47.46 Service Pack 2
ComboFix 06.10.19 - Running from: "C:\Program Files\Mozilla Firefox"
((((((((((((((((((((((((((((((( Files Created from 2006-10-01 to 2006-11-01 ))))))))))))))))))))))))))))))))))
2006-10-30 16:08 76,800 --a------ C:\WINDOWS\system32\mcilma32.dll
2006-10-30 16:08 71,168 --a------ C:\WINDOWS\system32\lmactl32.dll
2006-10-30 16:08 69,632 --a------ C:\WINDOWS\system32\SX83P32.DLL
2006-10-30 16:08 67,936 --a------ C:\WINDOWS\system32\isprsht.dll
2006-10-30 16:08 563,712 --a------ C:\WINDOWS\system32\VDK32116.DLL
2006-10-30 16:08 37,856 --a------ C:\WINDOWS\system32\mcilma.dll
2006-10-30 16:08 264,192 --a------ C:\WINDOWS\system32\npacrx.dll
2006-10-30 16:08 22,528 --a------ C:\WINDOWS\system32\NSMLAW32.DLL
2006-10-30 16:08 131,584 --a------ C:\WINDOWS\system32\mcilau32.dll
2006-10-30 16:07 652,289 --a------ C:\WINDOWS\cd32402.exe
2006-10-18 17:46 4,682 --a------ C:\WINDOWS\system32\npptNT2.sys
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-11-01 01:17 -------- d-------- C:\Program Files\Mozilla Firefox
2006-10-30 16:07 -------- d-------- C:\Program Files\Netscape
2006-10-24 12:23 -------- d-------- C:\Program Files\Daikatana
2006-10-23 05:38 -------- d-------- C:\Program Files\The All-Seeing Eye
2006-10-18 16:22 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-10-18 16:22 -------- d-------- C:\Program Files\Wizet
2006-10-17 19:01 -------- d-------- C:\Documents and Settings\Syko\Application Data\Adobe
2006-10-15 13:40 -------- d-------- C:\Program Files\windows media player
2006-10-15 13:40 -------- d-------- C:\Program Files\Spybot
2006-10-15 13:40 -------- d-------- C:\Program Files\QuickTime
2006-10-15 13:39 -------- d-------- C:\Program Files\GameSpy Arcade
2006-10-15 13:39 -------- d-------- C:\Program Files\Common Files\aolshare
2006-10-15 13:39 -------- d-------- C:\Program Files\Common Files\AOL
2006-10-15 13:39 -------- d-------- C:\Program Files\AOL 9.0a
2006-10-15 13:39 -------- d-------- C:\Program Files\AOL 9.0
2006-10-15 13:35 -------- d-------- C:\Program Files\WON
2006-10-15 13:34 -------- d-------- C:\Documents and Settings\Syko\Application Data\Avant Browser
2006-10-15 12:20 -------- d-------- C:\Program Files\Fox
2006-10-15 02:26 -------- d-------- C:\Program Files\Common Files\Adobe
2006-10-15 02:26 -------- d-------- C:\Program Files\Adobe
2006-09-28 20:40 -------- d-------- C:\Program Files\Red Orb Entertainment
2006-09-28 08:51 778656 --a------ C:\WINDOWS\system32\drivers\avg7core.sys
2006-09-26 16:24 -------- d-------- C:\Program Files\StarportGE
2006-09-24 20:45 -------- d-------- C:\Documents and Settings\Syko\Application Data\AVG7
2006-09-24 20:44 4992 --a------ C:\WINDOWS\system32\drivers\avgtdi.sys
2006-09-24 20:44 4288 --a------ C:\WINDOWS\system32\drivers\avg7rsw.sys
2006-09-24 20:44 27904 --a------ C:\WINDOWS\system32\drivers\avg7rsxp.sys
2006-09-24 20:44 23424 --a------ C:\WINDOWS\system32\drivers\avgmfrs.sys
2006-09-24 20:44 -------- d---s---- C:\Documents and Settings\Syko\Application Data\Microsoft
2006-09-24 20:44 -------- d-------- C:\Program Files\Grisoft
2006-09-24 20:20 -------- d-------- C:\Program Files\SpywareBlaster
2006-09-24 09:54 -------- d-------- C:\Program Files\ewido anti-spyware 4.0
2006-09-23 23:10 -------- d-------- C:\Program Files\DAEMON Tools
2006-09-21 09:06 -------- d-------- C:\Program Files\Lavasoft
2006-09-21 09:06 -------- d-------- C:\Documents and Settings\Syko\Application Data\Lavasoft
2006-09-13 05:01 1084416 --a------ C:\WINDOWS\system32\msxml3.dll
2006-09-07 18:50 -------- d-------- C:\Program Files\Synaptics
2006-09-01 22:34 -------- d-------- C:\Program Files\Java
2006-09-01 20:46 -------- d-------- C:\Program Files\Common Files\Java
2006-09-01 20:46 -------- d-------- C:\Program Files\Common Files
2006-08-25 15:45 617472 --a------ C:\WINDOWS\system32\comctl32.dll
2006-08-21 12:21 16896 --a------ C:\WINDOWS\system32\fltlib.dll
2006-08-21 09:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe
2006-08-16 11:58 100352 --a------ C:\WINDOWS\system32\6to4svc.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"updateMgr"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\AdobeUpdateManager.exe\" AcRdB7_0_7 -reboot 1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SoundMan"="SOUNDMAN.EXE"
"HTpatch"="C:\\WINDOWS\\htpatch.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"HostManager"="C:\\Program Files\\Common Files\\AOL\\1152633414\\ee\\AOLSoftware.exe"
"AOLDialer"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"
"AOL Spyware Protection"="\"C:\\PROGRA~1\\COMMON~1\\AOL\\AOLSPY~1\\AOLSP Scheduler.exe\""
"%FP%Friendly fts.exe"="\"C:\\Program Files\\VoyagerTest\\fts.exe\""
"DSLSTATEXE"="C:\\Program Files\\BT Voyager 105 ADSL Modem\\dslstat.exe icon"
"DSLAGENTEXE"="C:\\Program Files\\BT Voyager 105 ADSL Modem\\dslagent.exe"
"SynTPLpr"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_08\\bin\\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e4,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=dword:40000004
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"="Narrator.exe"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\runonce]
"RunNarrator"="Narrator.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AOL 9.0 Tray Icon.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\AOL 9.0 Tray Icon.lnk"
"backup"="C:\\WINDOWS\\pss\\AOL 9.0 Tray Icon.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\AOL9~1.0A\\aoltray.exe -check"
"item"="AOL 9.0 Tray Icon"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="CloneCDTray"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\SlySoft\\CloneCD\\CloneCDTray.exe\" /s"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Skype"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll"
Completion time: 06-11-01 1:21:00.01
C:\ComboFix.txt ... 06-11-01 01:21
C:\ComboFix2.txt ... 06-09-22 10:53
and the auto updates is on "..When i choose to install.."
Syko - 06-11-01 1:19:47.46 Service Pack 2
ComboFix 06.10.19 - Running from: "C:\Program Files\Mozilla Firefox"
((((((((((((((((((((((((((((((( Files Created from 2006-10-01 to 2006-11-01 ))))))))))))))))))))))))))))))))))
2006-10-30 16:08 76,800 --a------ C:\WINDOWS\system32\mcilma32.dll
2006-10-30 16:08 71,168 --a------ C:\WINDOWS\system32\lmactl32.dll
2006-10-30 16:08 69,632 --a------ C:\WINDOWS\system32\SX83P32.DLL
2006-10-30 16:08 67,936 --a------ C:\WINDOWS\system32\isprsht.dll
2006-10-30 16:08 563,712 --a------ C:\WINDOWS\system32\VDK32116.DLL
2006-10-30 16:08 37,856 --a------ C:\WINDOWS\system32\mcilma.dll
2006-10-30 16:08 264,192 --a------ C:\WINDOWS\system32\npacrx.dll
2006-10-30 16:08 22,528 --a------ C:\WINDOWS\system32\NSMLAW32.DLL
2006-10-30 16:08 131,584 --a------ C:\WINDOWS\system32\mcilau32.dll
2006-10-30 16:07 652,289 --a------ C:\WINDOWS\cd32402.exe
2006-10-18 17:46 4,682 --a------ C:\WINDOWS\system32\npptNT2.sys
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-11-01 01:17 -------- d-------- C:\Program Files\Mozilla Firefox
2006-10-30 16:07 -------- d-------- C:\Program Files\Netscape
2006-10-24 12:23 -------- d-------- C:\Program Files\Daikatana
2006-10-23 05:38 -------- d-------- C:\Program Files\The All-Seeing Eye
2006-10-18 16:22 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-10-18 16:22 -------- d-------- C:\Program Files\Wizet
2006-10-17 19:01 -------- d-------- C:\Documents and Settings\Syko\Application Data\Adobe
2006-10-15 13:40 -------- d-------- C:\Program Files\windows media player
2006-10-15 13:40 -------- d-------- C:\Program Files\Spybot
2006-10-15 13:40 -------- d-------- C:\Program Files\QuickTime
2006-10-15 13:39 -------- d-------- C:\Program Files\GameSpy Arcade
2006-10-15 13:39 -------- d-------- C:\Program Files\Common Files\aolshare
2006-10-15 13:39 -------- d-------- C:\Program Files\Common Files\AOL
2006-10-15 13:39 -------- d-------- C:\Program Files\AOL 9.0a
2006-10-15 13:39 -------- d-------- C:\Program Files\AOL 9.0
2006-10-15 13:35 -------- d-------- C:\Program Files\WON
2006-10-15 13:34 -------- d-------- C:\Documents and Settings\Syko\Application Data\Avant Browser
2006-10-15 12:20 -------- d-------- C:\Program Files\Fox
2006-10-15 02:26 -------- d-------- C:\Program Files\Common Files\Adobe
2006-10-15 02:26 -------- d-------- C:\Program Files\Adobe
2006-09-28 20:40 -------- d-------- C:\Program Files\Red Orb Entertainment
2006-09-28 08:51 778656 --a------ C:\WINDOWS\system32\drivers\avg7core.sys
2006-09-26 16:24 -------- d-------- C:\Program Files\StarportGE
2006-09-24 20:45 -------- d-------- C:\Documents and Settings\Syko\Application Data\AVG7
2006-09-24 20:44 4992 --a------ C:\WINDOWS\system32\drivers\avgtdi.sys
2006-09-24 20:44 4288 --a------ C:\WINDOWS\system32\drivers\avg7rsw.sys
2006-09-24 20:44 27904 --a------ C:\WINDOWS\system32\drivers\avg7rsxp.sys
2006-09-24 20:44 23424 --a------ C:\WINDOWS\system32\drivers\avgmfrs.sys
2006-09-24 20:44 -------- d---s---- C:\Documents and Settings\Syko\Application Data\Microsoft
2006-09-24 20:44 -------- d-------- C:\Program Files\Grisoft
2006-09-24 20:20 -------- d-------- C:\Program Files\SpywareBlaster
2006-09-24 09:54 -------- d-------- C:\Program Files\ewido anti-spyware 4.0
2006-09-23 23:10 -------- d-------- C:\Program Files\DAEMON Tools
2006-09-21 09:06 -------- d-------- C:\Program Files\Lavasoft
2006-09-21 09:06 -------- d-------- C:\Documents and Settings\Syko\Application Data\Lavasoft
2006-09-13 05:01 1084416 --a------ C:\WINDOWS\system32\msxml3.dll
2006-09-07 18:50 -------- d-------- C:\Program Files\Synaptics
2006-09-01 22:34 -------- d-------- C:\Program Files\Java
2006-09-01 20:46 -------- d-------- C:\Program Files\Common Files\Java
2006-09-01 20:46 -------- d-------- C:\Program Files\Common Files
2006-08-25 15:45 617472 --a------ C:\WINDOWS\system32\comctl32.dll
2006-08-21 12:21 16896 --a------ C:\WINDOWS\system32\fltlib.dll
2006-08-21 09:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe
2006-08-16 11:58 100352 --a------ C:\WINDOWS\system32\6to4svc.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"updateMgr"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\AdobeUpdateManager.exe\" AcRdB7_0_7 -reboot 1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SoundMan"="SOUNDMAN.EXE"
"HTpatch"="C:\\WINDOWS\\htpatch.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"HostManager"="C:\\Program Files\\Common Files\\AOL\\1152633414\\ee\\AOLSoftware.exe"
"AOLDialer"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"
"AOL Spyware Protection"="\"C:\\PROGRA~1\\COMMON~1\\AOL\\AOLSPY~1\\AOLSP Scheduler.exe\""
"%FP%Friendly fts.exe"="\"C:\\Program Files\\VoyagerTest\\fts.exe\""
"DSLSTATEXE"="C:\\Program Files\\BT Voyager 105 ADSL Modem\\dslstat.exe icon"
"DSLAGENTEXE"="C:\\Program Files\\BT Voyager 105 ADSL Modem\\dslagent.exe"
"SynTPLpr"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_08\\bin\\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e4,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=dword:40000004
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"="Narrator.exe"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\runonce]
"RunNarrator"="Narrator.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AOL 9.0 Tray Icon.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\AOL 9.0 Tray Icon.lnk"
"backup"="C:\\WINDOWS\\pss\\AOL 9.0 Tray Icon.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\AOL9~1.0A\\aoltray.exe -check"
"item"="AOL 9.0 Tray Icon"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="CloneCDTray"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\SlySoft\\CloneCD\\CloneCDTray.exe\" /s"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Skype"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll"
Completion time: 06-11-01 1:21:00.01
C:\ComboFix.txt ... 06-11-01 01:21
C:\ComboFix2.txt ... 06-09-22 10:53
\' />
\' />