Sorry for delay in coming back to you but my computer suddenly refused to send any data. Could not post on here or send emails, or download from internet though could receive mails and surf ok
Working again now after reinstalling modem drivers. Now getting alerts that trojan-dropper.win32.agent.avl is in combofix file and it will not let me download it again. I have a log I made yesterday from it so will include that and a hijack report.
This virus removal business is pretty complex isn't it?!
Anyway:
B - 06-08-31 9:03:50.78
ComboFix 06.08.30BT - Running from: C:\Documents and Settings\B\Desktop
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\components
((((((((((((((((((((((((((((((( Files Created from 2006-07-31 to 2006-08-31 ))))))))))))))))))))))))))))))))))
2006-08-29 09:05 670,704 ---hs---- C:\WINDOWS\system32\fhhkj.bak2
2006-08-28 15:02 53,248 --a------ C:\WINDOWS\system32\Process.exe
2006-08-28 15:02 42,496 --a------ C:\WINDOWS\system32\swreg.exe
2006-08-28 15:02 40,960 --a------ C:\WINDOWS\system32\swsc.exe
2006-08-28 15:02 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2006-08-28 12:48 632,065 ---hs---- C:\WINDOWS\system32\fhhkj.bak1
2006-08-25 20:16 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2006-08-24 22:35 49,152 --a------ C:\WINDOWS\system32\ffdrv1.dll
2006-08-24 22:35 290,816 --a------ C:\WINDOWS\system32\Projoycpl.dll
2006-08-24 22:27 43,520 --a------ C:\WINDOWS\system32\CmdLineExt03.dll
2006-08-24 14:16 737,280 --a------ C:\WINDOWS\iun6002.exe
2006-08-23 13:53 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2006-08-23 13:53 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll
2006-08-22 22:58 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll
2006-08-22 22:58 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll
2006-08-22 22:58 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll
2006-08-22 22:58 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
2006-08-22 22:58 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll
2006-08-22 22:58 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll
2006-08-22 21:45 98,304 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2006-08-18 15:06 86,016 --a------ C:\WINDOWS\system32\SageNatWestBankline.dll
2006-08-18 15:06 86,016 --a------ C:\WINDOWS\system32\SageBankPayments.dll
2006-08-18 15:06 81,920 --a------ C:\WINDOWS\system32\SGUserInfo.dll
2006-08-18 15:06 81,920 --a------ C:\WINDOWS\system32\SageNatWestOnline.dll
2006-08-18 15:06 81,920 --a------ C:\WINDOWS\system32\sageebanking.dll
2006-08-18 15:06 81,920 --a------ C:\WINDOWS\system32\SageBarclaysOnline.dll
2006-08-18 15:06 81,920 --a------ C:\WINDOWS\system32\SageBarclaysBusinessMasterII.dll
2006-08-18 15:06 69,632 --a------ C:\WINDOWS\system32\SageBankBalances.dll
2006-08-18 15:06 61,440 --a------ C:\WINDOWS\system32\BankServiceUtilities.dll
2006-08-18 15:06 37,224 --a------ C:\WINDOWS\system32\SageStorage.dll
2006-08-18 15:06 368,696 --a------ C:\WINDOWS\system32\S10DBC32.dll
2006-08-18 15:06 335,872 --a------ C:\WINDOWS\system32\SGINFMR.dll
2006-08-18 15:06 322,832 --------- C:\WINDOWS\system32\MFC30.DLL
2006-08-18 15:06 192,512 --a------ C:\WINDOWS\system32\SageBankReconciliation.dll
2006-08-18 15:06 167,936 --a------ C:\WINDOWS\system32\SGXMLQry.dll
2006-08-18 15:06 139,264 --a------ C:\WINDOWS\system32\SGISAQry.dll
2006-08-18 15:06 127,352 --a------ C:\WINDOWS\system32\SageSoftwareUpdate.dll
2006-08-18 15:06 126,976 --a------ C:\WINDOWS\system32\SGInfProgressBar.dll
2006-08-18 15:06 119,160 --a------ C:\WINDOWS\system32\SageFolderBrowse.dll
2006-08-18 11:30 16,384 --a------ C:\WINDOWS\system32\FileOps.exe
2006-08-17 22:50 60,416 --a------ C:\WINDOWS\system32\DSETUP.dll
2006-08-17 22:48 92,160 --a------ C:\WINDOWS\system32\evntwin.exe
2006-08-17 22:48 8,704 --a------ C:\WINDOWS\system32\snmptrap.exe
2006-08-17 22:48 6,144 --a------ C:\WINDOWS\system32\snmpmib.dll
2006-08-17 22:48 39,936 --a------ C:\WINDOWS\system32\hostmib.dll
2006-08-17 22:48 33,792 --a------ C:\WINDOWS\system32\lmmib2.dll
2006-08-17 22:48 32,768 --a------ C:\WINDOWS\system32\snmp.exe
2006-08-17 22:48 24,064 --a------ C:\WINDOWS\system32\evntcmd.exe
2006-08-17 22:48 101,888 --a------ C:\WINDOWS\system32\evntagnt.dll
2006-08-17 14:41 7,680 --a------ C:\WINDOWS\system32\CNMVS6y.DLL
2006-08-17 14:41 116,736 --a------ C:\WINDOWS\system32\CNMLM6y.DLL
2006-08-17 14:32 98,304 --a------ C:\WINDOWS\system32\CNCSUT60.DLL
2006-08-17 14:32 90,112 --a------ C:\WINDOWS\system32\CNCI780.DLL
2006-08-17 14:32 81,920 --a------ C:\WINDOWS\system32\CNCSTR60.DLL
2006-08-17 14:32 81,920 --a------ C:\WINDOWS\system32\CNCSIF60.DLL
2006-08-17 14:32 77,824 --a------ C:\WINDOWS\system32\CNCSCM60.DLL
2006-08-17 14:32 69,632 --a------ C:\WINDOWS\system32\CNCL780.DLL
2006-08-17 14:32 561,152 --a------ C:\WINDOWS\system32\CNCC780.DLL
2006-08-17 14:32 49,152 --a------ C:\WINDOWS\system32\cncisco.dll
2006-08-17 14:32 389,180 --a------ C:\WINDOWS\system32\UCS32P.DLL
2006-08-17 14:32 110,592 --a------ C:\WINDOWS\system32\CNCSDO60.DLL
2006-08-17 14:31 20,480 --a------ C:\WINDOWS\system32\CNCFMS60.EXE
2006-08-17 14:31 120,320 --a------ C:\WINDOWS\system32\CNCF2L60.DLL
2006-08-17 13:02 1,650,688 --a------ C:\WINDOWS\system32\cdintf250.dll
2006-08-17 08:39 127,208 --a------ C:\WINDOWS\system32\mucltui.dll
2006-08-16 20:45 53,760 --a------ C:\WINDOWS\system32\vfwwdm32.dll
2006-08-16 20:45 363,520 --a------ C:\WINDOWS\system32\PsisDecd.dll
2006-08-16 20:43 520,192 --------- C:\WINDOWS\system32\ati2sgag.exe
2006-08-16 13:10 4,096 --a------ C:\WINDOWS\system32\ksuser.dll
2006-08-16 13:08 74,240 --a------ C:\WINDOWS\system32\usbui.dll
2006-08-16 13:07 85,020 --a------ C:\WINDOWS\system32\dgsetup.dll
2006-08-16 13:07 8,192 -ra------ C:\WINDOWS\system32\kbdhept.dll
2006-08-16 13:07 7,168 -ra------ C:\WINDOWS\system32\kbdcz.dll
2006-08-16 13:07 6,656 -ra------ C:\WINDOWS\system32\kbdycl.dll
2006-08-16 13:07 6,656 -ra------ C:\WINDOWS\system32\kbdsl1.dll
2006-08-16 13:07 6,656 -ra------ C:\WINDOWS\system32\kbdsl.dll
2006-08-16 13:07 6,656 -ra------ C:\WINDOWS\system32\kbdpl.dll
2006-08-16 13:07 6,656 -ra------ C:\WINDOWS\system32\kbdhu.dll
2006-08-16 13:07 6,656 -ra------ C:\WINDOWS\system32\kbdhela3.dll
2006-08-16 13:07 6,656 -ra------ C:\WINDOWS\system32\kbdcz2.dll
2006-08-16 13:07 6,656 -ra------ C:\WINDOWS\system32\kbdcz1.dll
2006-08-16 13:07 6,656 -ra------ C:\WINDOWS\system32\kbdcr.dll
2006-08-16 13:07 6,656 -ra------ C:\WINDOWS\system32\KBDAL.DLL
2006-08-16 13:07 6,144 -ra------ C:\WINDOWS\system32\kbdtuq.dll
2006-08-16 13:07 6,144 -ra------ C:\WINDOWS\system32\kbdtuf.dll
2006-08-16 13:07 6,144 -ra------ C:\WINDOWS\system32\kbdlv1.dll
2006-08-16 13:07 6,144 -ra------ C:\WINDOWS\system32\kbdlv.dll
2006-08-16 13:07 6,144 -ra------ C:\WINDOWS\system32\kbdhela2.dll
2006-08-16 13:07 6,144 -ra------ C:\WINDOWS\system32\kbdgkl.dll
2006-08-16 13:07 6,144 -ra------ C:\WINDOWS\system32\kbdest.dll
2006-08-16 13:07 5,632 -ra------ C:\WINDOWS\system32\kbdycc.dll
2006-08-16 13:07 5,632 -ra------ C:\WINDOWS\system32\kbduzb.dll
2006-08-16 13:07 5,632 -ra------ C:\WINDOWS\system32\kbdur.dll
2006-08-16 13:07 5,632 -ra------ C:\WINDOWS\system32\kbdtat.dll
2006-08-16 13:07 5,632 -ra------ C:\WINDOWS\system32\kbdru1.dll
2006-08-16 13:07 5,632 -ra------ C:\WINDOWS\system32\kbdru.dll
2006-08-16 13:07 5,632 -ra------ C:\WINDOWS\system32\kbdro.dll
2006-08-16 13:07 5,632 -ra------ C:\WINDOWS\system32\kbdpl1.dll
2006-08-16 13:07 5,632 -ra------ C:\WINDOWS\system32\kbdmon.dll
2006-08-16 13:07 5,632 -ra------ C:\WINDOWS\system32\kbdlt1.dll
2006-08-16 13:07 5,632 -ra------ C:\WINDOWS\system32\kbdlt.dll
2006-08-16 13:07 5,632 -ra------ C:\WINDOWS\system32\kbdkyr.dll
2006-08-16 13:07 5,632 -ra------ C:\WINDOWS\system32\kbdkaz.dll
2006-08-16 13:07 5,632 -ra------ C:\WINDOWS\system32\kbdhu1.dll
2006-08-16 13:07 5,632 -ra------ C:\WINDOWS\system32\kbdhe319.dll
2006-08-16 13:07 5,632 -ra------ C:\WINDOWS\system32\kbdhe220.dll
2006-08-16 13:07 5,632 -ra------ C:\WINDOWS\system32\kbdhe.dll
2006-08-16 13:07 5,632 -ra------ C:\WINDOWS\system32\kbdbu.dll
2006-08-16 13:07 5,632 -ra------ C:\WINDOWS\system32\kbdblr.dll
2006-08-16 13:07 5,632 -ra------ C:\WINDOWS\system32\kbdazel.dll
2006-08-16 13:07 5,632 -ra------ C:\WINDOWS\system32\kbdaze.dll
2006-08-16 13:07 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll
2006-08-16 13:07 176,157 --a------ C:\WINDOWS\system32\dgrpsetu.dll
2006-08-16 13:07 13,312 --a------ C:\WINDOWS\system32\irclass.dll
2006-08-16 13:06 8,704 --a------ C:\WINDOWS\system32\batt.dll
2006-08-16 13:06 74,752 --a------ C:\WINDOWS\system32\storprop.dll
2006-08-16 13:06 69,120 --a------ C:\WINDOWS\NOTEPAD.EXE
2006-08-16 13:06 15,360 --a------ C:\WINDOWS\TASKMAN.EXE
2006-08-16 13:06 103,424 --a------ C:\WINDOWS\system32\EqnClass.Dll
2006-08-16 12:34 5,606 --a------ C:\WINDOWS\system32\stci.dll
2006-08-16 12:29 9,709,568 -r------- C:\WINDOWS\RTLCPL.exe
2006-08-16 12:29 86,016 -r------- C:\WINDOWS\SoundMan.exe
2006-08-16 12:29 69,632 -r------- C:\WINDOWS\Alcmtr.exe
2006-08-16 12:29 40,960 -r------- C:\WINDOWS\system32\ChCfg.exe
2006-08-16 12:29 385,024 -r------- C:\WINDOWS\system32\JMRaidTool.exe
2006-08-16 12:29 364,544 -r------- C:\WINDOWS\RtlUpd.exe
2006-08-16 12:29 306,688 --a------ C:\WINDOWS\IsUninst.exe
2006-08-16 12:29 2,879,488 -r------- C:\WINDOWS\SkyTel.exe
2006-08-16 12:29 2,808,832 -r------- C:\WINDOWS\alcwzrd.exe
2006-08-16 12:29 2,158,592 -r------- C:\WINDOWS\MicCal.exe
2006-08-16 12:29 16,208,384 -r------- C:\WINDOWS\RTHDCPL.exe
2006-08-16 12:29 135,168 -r------- C:\WINDOWS\system32\RtlCPAPI.dll
2006-08-16 12:28 487,424 -r------- C:\WINDOWS\RtlExUpd.dll
2006-08-16 12:28 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2006-08-16 12:16 112,128 --a------ C:\WINDOWS\system32\mapi32.dll
2006-08-16 12:16 0 -rahs---- C:\MSDOS.SYS
2006-08-16 12:16 0 -rahs---- C:\IO.SYS
2006-08-16 12:16 0 --a------ C:\CONFIG.SYS
2006-08-16 12:16 0 --a------ C:\AUTOEXEC.BAT
2006-08-16 12:14 64,512 --a------ C:\WINDOWS\system32\acctres.dll
2006-08-16 12:14 6,656 --a------ C:\WINDOWS\system32\wuauserv.dll
2006-08-16 12:14 194,328 --a------ C:\WINDOWS\system32\wuaueng1.dll
2006-08-16 12:14 173,536 --a------ C:\WINDOWS\system32\wuweb.dll
2006-08-16 12:14 16,384 --a------ C:\WINDOWS\system32\icfgnt5.dll
2006-08-16 12:14 127,256 --a------ C:\WINDOWS\system32\wucltui.dll
2006-08-16 12:14 12,288 --a------ C:\WINDOWS\system32\nmevtmsg.dll
2006-08-16 12:14 11,264 --a------ C:\WINDOWS\system32\atrace.dll
2006-08-16 12:13 81,920 --a------ C:\WINDOWS\system32\isign32.dll
2006-08-16 12:13 81,920 --a------ C:\WINDOWS\system32\ils.dll
2006-08-16 12:13 8,192 --a------ C:\WINDOWS\system32\bitsprx2.dll
2006-08-16 12:13 73,728 --a------ C:\WINDOWS\system32\icwdial.dll
2006-08-16 12:13 7,168 --a------ C:\WINDOWS\system32\bitsprx3.dll
2006-08-16 12:13 69,632 --a------ C:\WINDOWS\system32\msconf.dll
2006-08-16 12:13 679,424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-08-16 12:13 67,584 --a------ C:\WINDOWS\system32\srclient.dll
2006-08-16 12:13 65,536 --a------ C:\WINDOWS\system32\icwphbk.dll
2006-08-16 12:13 48,128 --a------ C:\WINDOWS\system32\inetres.dll
2006-08-16 12:13 465,176 --a------ C:\WINDOWS\system32\wuapi.dll
2006-08-16 12:13 45,568 --a------ C:\WINDOWS\system32\safrslv.dll
2006-08-16 12:13 43,520 --a------ C:\WINDOWS\system32\safrcdlg.dll
2006-08-16 12:13 43,520 --a------ C:\WINDOWS\system32\racpldlg.dll
2006-08-16 12:13 41,240 --a------ C:\WINDOWS\system32\wups.dll
2006-08-16 12:13 382,464 --a------ C:\WINDOWS\system32\qmgr.dll
2006-08-16 12:13 34,560 --a------ C:\WINDOWS\system32\mnmdd.dll
2006-08-16 12:13 32,768 --a------ C:\WINDOWS\system32\mnmsrvc.exe
2006-08-16 12:13 32,768 --a------ C:\WINDOWS\system32\isrdbg32.dll
2006-08-16 12:13 29,696 --a------ C:\WINDOWS\system32\safrdm.dll
2006-08-16 12:13 28,672 --a------ C:\WINDOWS\system32\nmmkcert.dll
2006-08-16 12:13 274,944 --a------ C:\WINDOWS\system32\mstask.dll
2006-08-16 12:13 274,432 --a------ C:\WINDOWS\system32\inetcfg.dll
2006-08-16 12:13 252,928 --a------ C:\WINDOWS\system32\msoeacct.dll
2006-08-16 12:13 239,104 --a------ C:\WINDOWS\system32\srrstr.dll
2006-08-16 12:13 22,528 --a------ C:\WINDOWS\system32\fltMc.exe
2006-08-16 12:13 190,976 --a------ C:\WINDOWS\system32\schedsvc.dll
2006-08-16 12:13 18,944 --a------ C:\WINDOWS\system32\qmgrprxy.dll
2006-08-16 12:13 172,312 --a------ C:\WINDOWS\system32\wuauclt1.exe
2006-08-16 12:13 170,496 --a------ C:\WINDOWS\system32\srsvc.dll
2006-08-16 12:13 16,896 --a------ C:\WINDOWS\system32\fltlib.dll
2006-08-16 12:13 124,184 --a------ C:\WINDOWS\system32\wuauclt.exe
2006-08-16 12:13 12,288 --a------ C:\WINDOWS\system32\mstinit.exe
2006-08-16 12:13 105,984 --a------ C:\WINDOWS\system32\msoert2.dll
2006-08-16 12:13 1,343,768 --a------ C:\WINDOWS\system32\wuaueng.dll
2006-08-16 12:12 97,792 --a------ C:\WINDOWS\system32\comrepl.dll
2006-08-16 12:12 9,728 --a------ C:\WINDOWS\system32\reset.exe
2006-08-16 12:12 80,384 --a------ C:\WINDOWS\system32\charmap.exe
2006-08-16 12:12 73,216 --a------ C:\WINDOWS\system32\avwav.dll
2006-08-16 12:12 605,696 --a------ C:\WINDOWS\system32\getuname.dll
2006-08-16 12:12 56,832 --a------ C:\WINDOWS\system32\sol.exe
2006-08-16 12:12 55,296 --a------ C:\WINDOWS\system32\freecell.exe
2006-08-16 12:12 54,272 --a------ C:\WINDOWS\system32\stclient.dll
2006-08-16 12:12 5,632 --a------ C:\WINDOWS\system32\write.exe
2006-08-16 12:12 5,120 --a------ C:\WINDOWS\system32\dcomcnfg.exe
2006-08-16 12:12 44,544 --a------ C:\WINDOWS\system32\hticons.dll
2006-08-16 12:12 4,096 --a------ C:\WINDOWS\system32\rdpcfgex.dll
2006-08-16 12:12 4,096 --a------ C:\WINDOWS\system32\mtxex.dll
2006-08-16 12:12 35,328 --a------ C:\WINDOWS\system32\winchat.exe
2006-08-16 12:12 33,792 --a------ C:\WINDOWS\system32\regini.exe
2006-08-16 12:12 25,600 --a------ C:\WINDOWS\system32\comaddin.dll
2006-08-16 12:12 25,088 --a------ C:\WINDOWS\system32\mtxlegih.dll
2006-08-16 12:12 227,840 --a------ C:\WINDOWS\system32\avtapi.dll
2006-08-16 12:12 22,016 --a------ C:\WINDOWS\system32\qwinsta.exe
2006-08-16 12:12 20,992 --a------ C:\WINDOWS\system32\msg.exe
2006-08-16 12:12 20,480 --a------ C:\WINDOWS\system32\mtxdm.dll
2006-08-16 12:12 16,896 --a------ C:\WINDOWS\system32\tsshutdn.exe
2006-08-16 12:12 16,896 --a------ C:\WINDOWS\system32\qappsrv.exe
2006-08-16 12:12 16,384 --a------ C:\WINDOWS\system32\tskill.exe
2006-08-16 12:12 16,384 --a------ C:\WINDOWS\system32\avmeter.dll
2006-08-16 12:12 15,872 --a------ C:\WINDOWS\system32\rwinsta.exe
2006-08-16 12:12 15,872 --a------ C:\WINDOWS\system32\cdmodem.dll
2006-08-16 12:12 15,360 --a------ C:\WINDOWS\system32\logoff.exe
2006-08-16 12:12 147,456 --a------ C:\WINDOWS\system32\comsnap.dll
2006-08-16 12:12 14,848 --a------ C:\WINDOWS\system32\tsdiscon.exe
2006-08-16 12:12 14,848 --a------ C:\WINDOWS\system32\tscon.exe
2006-08-16 12:12 14,848 --a------ C:\WINDOWS\system32\shadow.exe
2006-08-16 12:12 138,752 --a------ C:\WINDOWS\system32\sndvol32.exe
2006-08-16 12:12 126,976 --a------ C:\WINDOWS\system32\mshearts.exe
2006-08-16 12:12 119,808 --a------ C:\WINDOWS\system32\winmine.exe
2006-08-16 12:12 114,688 --a------ C:\WINDOWS\system32\calc.exe
2006-08-16 12:12 1,161 --a------ C:\WINDOWS\system32\usrlogon.cmd
2006-08-16 12:11 956,416 --a------ C:\WINDOWS\system32\msdtctm.dll
2006-08-16 12:11 93,696 --a------ C:\WINDOWS\system32\tscfgwmi.dll
2006-08-16 12:11 91,136 --a------ C:\WINDOWS\system32\mtxoci.dll
2006-08-16 12:11 87,176 --a------ C:\WINDOWS\system32\rdpwsx.dll
2006-08-16 12:11 85,504 --a------ C:\WINDOWS\system32\catsrvps.dll
2006-08-16 12:11 67,072 --a------ C:\WINDOWS\system32\rdshost.exe
2006-08-16 12:11 655,360 --a------ C:\WINDOWS\system32\mstscax.dll
2006-08-16 12:11 625,152 --a------ C:\WINDOWS\system32\catsrvut.dll
2006-08-16 12:11 62,464 --a------ C:\WINDOWS\system32\rdpclip.exe
2006-08-16 12:11 60,416 --a------ C:\WINDOWS\system32\remotepg.dll
2006-08-16 12:11 60,416 --a------ C:\WINDOWS\system32\colbact.dll
2006-08-16 12:11 6,144 --a------ C:\WINDOWS\system32\msdtc.exe
2006-08-16 12:11 58,880 --a------ C:\WINDOWS\system32\msdtclog.dll
2006-08-16 12:11 58,880 --a------ C:\WINDOWS\system32\licwmi.dll
2006-08-16 12:11 56,320 --a------ C:\WINDOWS\system32\servdeps.dll
2006-08-16 12:11 540,160 --a------ C:\WINDOWS\system32\comuid.dll
2006-08-16 12:11 538,624 --a------ C:\WINDOWS\system32\spider.exe
2006-08-16 12:11 498,688 --a------ C:\WINDOWS\system32\clbcatq.dll
2006-08-16 12:11 44,544 --a------ C:\WINDOWS\system32\tscupgrd.exe
2006-08-16 12:11 426,496 --a------ C:\WINDOWS\system32\msdtcprx.dll
2006-08-16 12:11 407,552 --a------ C:\WINDOWS\system32\mstsc.exe
2006-08-16 12:11 38,912 --a------ C:\WINDOWS\system32\cfgbkend.dll
2006-08-16 12:11 347,136 --a------ C:\WINDOWS\system32\hypertrm.dll
2006-08-16 12:11 343,040 --a------ C:\WINDOWS\system32\mspaint.exe
2006-08-16 12:11 295,424 --a------ C:\WINDOWS\system32\termsrv.dll
2006-08-16 12:11 225,792 --a------ C:\WINDOWS\system32\catsrv.dll
2006-08-16 12:11 20,480 --a------ C:\WINDOWS\system32\qprocess.exe
2006-08-16 12:11 19,968 --a------ C:\WINDOWS\system32\rdpsnd.dll
2006-08-16 12:11 185,344 --a------ C:\WINDOWS\system32\cmprops.dll
2006-08-16 12:11 183,808 --a------ C:\WINDOWS\system32\accwiz.exe
2006-08-16 12:11 17,408 --a------ C:\WINDOWS\system32\mmfutil.dll
2006-08-16 12:11 161,280 --a------ C:\WINDOWS\system32\msdtcuiu.dll
2006-08-16 12:11 147,968 --a------ C:\WINDOWS\system32\rdchost.dll
2006-08-16 12:11 140,800 --a------ C:\WINDOWS\system32\sessmgr.exe
2006-08-16 12:11 131,584 --a------ C:\WINDOWS\system32\sndrec32.exe
2006-08-16 12:11 13,824 --a------ C:\WINDOWS\system32\rdsaddin.exe
2006-08-16 12:11 123,392 --a------ C:\WINDOWS\system32\mplay32.exe
2006-08-16 12:11 110,080 --a------ C:\WINDOWS\system32\clbcatex.dll
2006-08-16 12:11 11,776 --a------ C:\WINDOWS\system32\xolehlp.dll
2006-08-16 12:11 11,264 --a------ C:\WINDOWS\system32\icaapi.dll
2006-08-16 12:11 102,912 --a------ C:\WINDOWS\system32\clipbrd.exe
2006-08-16 12:11 1,267,200 --a------ C:\WINDOWS\system32\comsvcs.dll
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-08-31 00:47 -------- d-------- C:\Program Files\GetRight
2006-08-30 23:12 -------- d-------- C:\Documents and Settings\B\Application Data\Skype
2006-08-29 23:15 -------- d-------- C:\Documents and Settings\B\Application Data\GetRightToGo
2006-08-29 21:39 -------- d-------- C:\Program Files\ewido anti-spyware 4.0
2006-08-29 20:25 -------- d-------- C:\Program Files\Kaspersky Lab
2006-08-29 20:18 -------- d-------- C:\Program Files\Trustix
2006-08-29 19:20 -------- d-------- C:\Documents and Settings\B\Application Data\Comodo
2006-08-29 19:15 -------- d-------- C:\Program Files\Comodo
2006-08-29 16:02 -------- d-------- C:\Program Files\CleanUp!
2006-08-28 12:51 -------- d-------- C:\Program Files\Lavasoft
2006-08-28 12:51 -------- d-------- C:\Documents and Settings\B\Application Data\Lavasoft
2006-08-28 12:37 -------- d-------- C:\Documents and Settings\B\Application Data\Google
2006-08-28 12:36 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-08-28 12:36 -------- d-------- C:\Program Files\Google
2006-08-27 21:38 -------- d-------- C:\Program Files\GameSpy Arcade
2006-08-27 20:13 -------- d-------- C:\Program Files\EA GAMES
2006-08-27 16:13 -------- d-------- C:\Program Files\The All-Seeing Eye
2006-08-27 14:55 -------- d-------- C:\Program Files\Common Files\EasyInfo
2006-08-27 14:55 -------- d-------- C:\Program Files\Common Files
2006-08-25 22:07 -------- d-------- C:\Program Files\OfficeUpdate11
2006-08-24 22:35 -------- d-------- C:\Program Files\Superjoy Box Pro
2006-08-24 22:25 -------- d-------- C:\Program Files\Pro Evolution Soccer 5
2006-08-24 14:15 -------- d-------- C:\Program Files\PES5
2006-08-24 10:07 -------- d---s---- C:\Documents and Settings\B\Application Data\Microsoft
2006-08-23 15:41 -------- d-------- C:\Documents and Settings\B\Application Data\Real
2006-08-23 15:40 -------- d-------- C:\Program Files\Real
2006-08-23 15:40 -------- d-------- C:\Program Files\Common Files\xing shared
2006-08-23 15:40 -------- d-------- C:\Program Files\Common Files\Real
2006-08-23 13:49 -------- d-------- C:\Documents and Settings\B\Application Data\Samsung
2006-08-23 10:33 -------- d-------- C:\Program Files\Karndean International
2006-08-22 22:58 -------- d-------- C:\Program Files\Common Files\Ahead
2006-08-22 22:58 -------- d-------- C:\Program Files\Ahead
2006-08-22 21:44 -------- d-------- C:\Program Files\Sierra
2006-08-22 07:55 -------- d-------- C:\Program Files\Microsoft IntelliPoint
2006-08-19 23:29 -------- d-------- C:\Program Files\ATITool
2006-08-19 19:36 -------- d-------- C:\Documents and Settings\B\Application Data\My Battle for Middle-earth(tm) II Files
2006-08-19 18:16 -------- d-------- C:\Program Files\Common Files\WhenU
2006-08-19 18:12 -------- d-------- C:\Program Files\Electronic Arts
2006-08-19 16:49 -------- d-------- C:\Program Files\Common Files\Wise Installation Wizard
2006-08-19 16:44 -------- d-------- C:\Documents and Settings\B\Application Data\Adobe
2006-08-19 16:42 -------- d-------- C:\Program Files\TechSmith
2006-08-19 15:38 -------- d-------- C:\Program Files\Windows Media Player
2006-08-18 20:11 41888 --a------ C:\WINDOWS\system32\drivers\Oreans.sys
2006-08-18 19:57 -------- d-------- C:\Program Files\Samsung
2006-08-18 16:14 -------- d-------- C:\Program Files\Inland Revenue
2006-08-18 15:17 -------- d-------- C:\Program Files\Common Files\Microsoft Shared
2006-08-18 15:06 -------- d-------- C:\Program Files\Sage EBanking
2006-08-18 15:06 -------- d-------- C:\Program Files\Informer50
2006-08-18 15:05 -------- d-------- C:\Program Files\Sage
2006-08-18 15:05 -------- d-------- C:\Program Files\Common Files\Sage Line50
2006-08-18 11:35 -------- d-------- C:\Program Files\Common Files\Adobe
2006-08-18 11:35 -------- d-------- C:\Program Files\Adobe
2006-08-18 09:26 -------- d-------- C:\Program Files\Microsoft IntelliType Pro 5.5
2006-08-18 09:26 -------- d-------- C:\Program Files\Microsoft IntelliType Pro
2006-08-17 23:06 -------- d-------- C:\Program Files\GIGABYTE
2006-08-17 22:06 -------- d-------- C:\Program Files\Valve
2006-08-17 18:17 163644 --a------ C:\WINDOWS\system32\drivers\secdrv.sys
2006-08-17 18:01 -------- d-------- C:\Program Files\Activision
2006-08-17 14:56 -------- d-------- C:\Program Files\Bethesda Softworks
2006-08-17 14:32 -------- d-------- C:\Program Files\Canon
2006-08-17 13:36 -------- d-------- C:\Program Files\Common Files\Intuit
2006-08-17 13:36 -------- d-------- C:\Program Files\Common Files\AnswerWorks 4.0
2006-08-17 13:35 -------- d-------- C:\Program Files\Intuit
2006-08-17 13:28 -------- d-------- C:\Documents and Settings\B\Application Data\AdobeUM
2006-08-17 12:58 -------- d-------- C:\Program Files\Common Files\SWF Studio
2006-08-17 12:58 -------- d-------- C:\Documents and Settings\B\Application Data\Macromedia
2006-08-17 12:11 -------- d-------- C:\Program Files\Common Files\Adobe Systems Shared
2006-08-17 11:28 -------- d-------- C:\Program Files\Microsoft IntelliPoint 5.2
2006-08-17 09:24 -------- d-------- C:\Program Files\Trend Micro
2006-08-17 08:41 -------- d-------- C:\Program Files\Smart Projects
2006-08-17 00:50 -------- d-------- C:\Program Files\Skype
2006-08-16 23:52 223128 --a------ C:\WINDOWS\system32\drivers\dtscsi.sys
2006-08-16 23:52 -------- d-------- C:\Program Files\DAEMON Tools
2006-08-16 23:48 -------- d-------- C:\Program Files\MSN
2006-08-16 23:40 -------- d-------- C:\Program Files\Messenger
2006-08-16 23:30 -------- d-------- C:\Documents and Settings\B\Application Data\MSNInstaller
2006-08-16 23:19 96256 --a------ C:\WINDOWS\system32\drivers\sptd0941.sys
2006-08-16 23:19 643072 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2006-08-16 23:18 -------- d-------- C:\Program Files\BitComet
2006-08-16 23:08 -------- d-------- C:\Program Files\Internet Explorer
2006-08-16 22:07 -------- d-------- C:\Program Files\TuneUp Utilities 2006
2006-08-16 22:07 -------- d-------- C:\Documents and Settings\B\Application Data\TuneUp Software
2006-08-16 22:06 -------- d-------- C:\Program Files\WinRAR
2006-08-16 21:40 -------- d-------- C:\Program Files\Futuremark
2006-08-16 21:15 -------- d-------- C:\Program Files\Outlook Express
2006-08-16 21:15 -------- d-------- C:\Program Files\Common Files\System
2006-08-16 20:48 -------- d-------- C:\Documents and Settings\B\Application Data\ATI
2006-08-16 20:45 -------- d-------- C:\Program Files\Common Files\InstallShield
2006-08-16 20:45 -------- d-------- C:\Program Files\ATI Technologies
2006-08-16 20:40 -------- d-------- C:\Program Files\Microsoft Office
2006-08-16 20:40 -------- d-------- C:\Program Files\Microsoft ActiveSync
2006-08-16 20:40 -------- d-------- C:\Program Files\Common Files\Designer
2006-08-16 13:07 -------- d-------- C:\Program Files\Common Files\SpeechEngines
2006-08-16 13:07 -------- d-------- C:\Program Files\Common Files\ODBC
2006-08-16 13:06 62 --ahs---- C:\Documents and Settings\B\Application Data\desktop.ini
2006-08-16 12:34 -------- d-------- C:\Program Files\Thomson
2006-08-16 12:29 -------- d-------- C:\Program Files\Realtek
2006-08-16 12:26 -------- d-------- C:\Program Files\Intel
2006-08-16 12:22 -------- d--h----- C:\Program Files\Uninstall Information
2006-08-16 12:22 -------- d-------- C:\Documents and Settings\B\Application Data\Identities
2006-08-16 12:16 -------- d-------- C:\Program Files\xerox
2006-08-16 12:16 -------- d-------- C:\Program Files\microsoft frontpage
2006-08-16 12:15 -------- d--h----- C:\Program Files\WindowsUpdate
2006-08-16 12:14 -------- d-------- C:\Program Files\NetMeeting
2006-08-16 12:14 -------- d-------- C:\Program Files\Common Files\Services
2006-08-16 12:14 -------- d-------- C:\Program Files\Common Files\MSSoap
2006-08-16 12:13 -------- d-------- C:\Program Files\Movie Maker
2006-08-16 12:12 -------- d-------- C:\Program Files\Windows NT
2006-08-16 12:12 -------- d-------- C:\Program Files\Online Services
2006-08-16 12:12 -------- d-------- C:\Program Files\MSN Gaming Zone
2006-08-16 12:12 -------- d-------- C:\Program Files\ComPlus Applications
2006-07-21 09:24 72704 --a------ C:\WINDOWS\system32\hlink.dll
2006-07-19 03:58 258048 --a------ C:\WINDOWS\system32\ati2dvag.dll
2006-07-19 03:58 1621504 --a------ C:\WINDOWS\system32\drivers\ati2mtag.sys
2006-07-19 03:53 77824 --a------ C:\WINDOWS\system32\Oemdspif.dll
2006-07-19 03:53 26112 --a------ C:\WINDOWS\system32\Ati2mdxx.exe
2006-07-19 03:53 114688 --a------ C:\WINDOWS\system32\atipdlxx.dll
2006-07-19 03:52 86016 --a------ C:\WINDOWS\system32\ati2evxx.dll
2006-07-19 03:52 41984 --a------ C:\WINDOWS\system32\ati2edxx.dll
2006-07-19 03:51 53248 --a------ C:\WINDOWS\system32\ATIDDC.DLL
2006-07-19 03:51 401408 --a------ C:\WINDOWS\system32\ati2evxx.exe
2006-07-19 03:44 2732608 --a------ C:\WINDOWS\system32\ati3duag.dll
2006-07-19 03:39 1744416 --a------ C:\WINDOWS\system32\ativvaxx.dll
2006-07-19 03:27 204800 --a------ C:\WINDOWS\system32\atikvmag.dll
2006-07-19 03:26 17408 --a------ C:\WINDOWS\system32\atitvo32.dll
2006-07-19 03:23 307200 --a------ C:\WINDOWS\system32\atiiiexx.dll
2006-07-19 03:22 6684672 --a------ C:\WINDOWS\system32\atioglx1.dll
2006-07-19 03:22 286720 --a------ C:\WINDOWS\system32\ati2cqag.dll
2006-07-19 03:21 290816 --a------ C:\WINDOWS\system32\ATIDEMGR.dll
2006-07-19 03:13 5136384 --a------ C:\WINDOWS\system32\atioglxx.dll
2006-06-18 14:54 36864 --a------ C:\WINDOWS\system32\frapsvid.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GBB36X Configure"="C:\\WINDOWS\\system32\\JMRaidTool.exe boot"
"IntelliPoint"="\"C:\\Program Files\\Microsoft IntelliPoint\\point32.exe\""
@=""
"itype"="\"C:\\Program Files\\Microsoft IntelliType Pro\\itype.exe\""
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"Comodo Personal Firewall"="C:\\Program Files\\Comodo\\Personal Firewall\\CPF.exe sysrestart"
"Comodo Launch Pad Tray"="C:\\Program Files\\Comodo\\LaunchPad\\CLPTray.exe"
"kav"="\"C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 6.0\\avp.exe\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"Skype"="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"
"Steam"="C:\\Program Files\\Valve\\Steam\\Steam.exe -silent"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000004
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-]
"Alcmtr"="ALCMTR.EXE"
"RTHDCPL"="RTHDCPL.EXE"
"SkyTel"="SkyTel.EXE"
"SpeedTouch USB Diagnostics"="\"C:\\Program Files\\Thomson\\SpeedTouch USB\\Dragdiag.exe\" /icon"
"DAEMON Tools"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
"Acrobat Assistant 7.0"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Distillr\\Acrotray.exe\""
"ATICCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\CLIStart.exe\""
"EasyTuneV"="C:\\Program Files\\Gigabyte\\ET5\\GUI.exe"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\1-Click Maintenance.job
Completion time: 31/08/2006 9:04:30.81
ComboFix.txt
Logfile of HijackThis v1.99.1
Scan saved at 20:50:16, on 01/09/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\B\Desktop\analyze.exe.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [GBB36X Configure] C:\WINDOWS\system32\JMRaidTool.exe boot
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [kav] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: ATITool.lnk = C:\Program Files\ATITool\ATITool.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky.com/kos/eng/partner/d...can_unicode.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdat...b?1155766136796O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{F9E39900-48F2-4505-996B-A69666BF7069}: NameServer = 194.168.4.100 194.168.8.100
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r (file missing)
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe