Combofix file:ComboFix 08-04-22.5 - Acer 2008-04-25 1:36:49.7 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.131 [GMT 8:00]
Running from: C:\Documents and Settings\Acer\Desktop\ComboFix.exe
* Created a new restore point
[color=\"red\"]
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/color]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\kmd.exe
C:\WINDOWS\system32\kavo.exe
.
((((((((((((((((((((((((( Files Created from 2008-03-24 to 2008-04-24 )))))))))))))))))))))))))))))))
.
2008-04-23 12:11 . 2004-08-04 06:56 88,064 --a------ C:\WINDOWS\system32\comctl3.dll
2008-04-23 03:21 . 2008-04-23 11:57 <DIR> d-------- C:\Downloads
2008-04-23 03:17 . 2008-04-23 22:16 <DIR> d-------- C:\Program Files\FlashGet
2008-04-16 19:12 . 2008-04-16 19:27 <DIR> d-------- C:\Program Files\MyRosso
2008-04-16 19:12 . 2008-04-16 19:12 <DIR> d-------- C:\Documents and Settings\Acer\Application Data\InstallShield
2008-04-16 19:12 . 2007-03-30 19:49 266,240 --a------ C:\WINDOWS\system32\MyRossoPlugin.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-24 17:35 --------- d-----w C:\Program Files\Symantec AntiVirus
2008-04-24 17:25 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-22 20:53 0 ----a-w C:\Program Files\temp01
2008-04-22 20:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\PlayFirst
2008-04-22 20:39 --------- d-----w C:\Documents and Settings\Acer\Application Data\PlayFirst
2008-04-16 11:27 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-07 01:04 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-03-16 08:30 720,896 ----a-w C:\WINDOWS\iun6002.exe
2008-03-09 11:39 --------- d-----w C:\Program Files\EA GAMES
2008-03-05 12:36 --------- d-----w C:\Program Files\Burger Shop
2007-09-16 05:51 20,464 ----a-w C:\Documents and Settings\Acer\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((( snapshot@2008-01-23_10.21.22.85 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-04-24 17:23:40 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2007-11-20 08:04:32 1,523,536 ----a-w C:\WINDOWS\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe
- 2000-08-31 00:00:00 163,328 ----a-w C:\WINDOWS\erdnt\Hiv-backup\ERDNT.EXE
+ 2005-10-20 12:02:28 163,328 ----a-w C:\WINDOWS\erdnt\Hiv-backup\ERDNT.EXE
+ 2000-08-31 00:00:00 73,728 ----a-w C:\WINDOWS\fdsv.exe
+ 2000-08-31 00:00:00 80,412 ----a-w C:\WINDOWS\grep.exe
+ 2007-07-17 08:16:38 2,560 ----a-r C:\WINDOWS\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\cagicon.exe
+ 2007-09-11 06:49:11 2,494 ----a-r C:\WINDOWS\Installer\{EE48D800-A3B5-43E3-B846-1CC556B8170D}\NewShortcut1_DB8CEC4230B14F49BD069393EB81CCF7.exe
+ 2008-02-24 10:51:26 472,576 ----a-w C:\WINDOWS\Jane's Hotel\uninstall.exe
- 2000-08-31 00:00:00 51,200 ----a-w C:\WINDOWS\Nircmd.exe
+ 2000-08-31 00:00:00 28,160 ----a-w C:\WINDOWS\Nircmd.exe
+ 2007-07-17 08:03:18 2,112 ----a-w C:\WINDOWS\pchealth\helpctr\PackageStore\SkuStore.bin
+ 2000-08-31 00:00:00 98,816 ----a-w C:\WINDOWS\sed.exe
+ 2000-08-31 00:00:00 161,792 ----a-w C:\WINDOWS\swreg.exe
+ 2000-08-31 00:00:00 136,704 ----a-w C:\WINDOWS\swsc.exe
+ 2000-08-31 00:00:00 212,480 ----a-w C:\WINDOWS\swxcacls.exe
+ 2001-08-23 11:00:00 2,000 ----a-w C:\WINDOWS\system\KEYBOARD.DRV
+ 2001-08-23 11:00:00 73,376 ----a-w C:\WINDOWS\system\MCIAVI.DRV
+ 2001-08-23 11:00:00 25,264 ----a-w C:\WINDOWS\system\MCISEQ.DRV
+ 2001-08-23 11:00:00 28,160 ----a-w C:\WINDOWS\system\MCIWAVE.DRV
+ 2001-08-23 11:00:00 2,032 ----a-w C:\WINDOWS\system\MOUSE.DRV
+ 2001-08-23 11:00:00 1,744 ----a-w C:\WINDOWS\system\SOUND.DRV
+ 2001-08-23 11:00:00 3,360 ----a-w C:\WINDOWS\system\SYSTEM.DRV
+ 2001-08-23 11:00:00 4,048 ----a-w C:\WINDOWS\system\TIMER.DRV
+ 2001-08-23 11:00:00 2,176 ----a-w C:\WINDOWS\system\VGA.DRV
+ 2001-08-23 11:00:00 13,600 ----a-w C:\WINDOWS\system\WFWNET.DRV
+ 2004-08-03 22:56:58 146,432 ----a-w C:\WINDOWS\system\WINSPOOL.DRV
+ 2008-03-19 11:23:20 114,688 ----a-w C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
+ 2008-03-19 11:36:22 202,168 ----a-w C:\WINDOWS\system32\Adobe\Director\swdir.dll
+ 2008-03-19 11:36:40 67,000 ----a-w C:\WINDOWS\system32\Adobe\Director\SwDnld.exe
+ 2008-03-19 11:24:02 487,424 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\Control.dll
+ 2008-03-19 10:46:26 1,798,144 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\dirapi.dll
+ 2008-03-19 11:24:04 9,216 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\DynaPlayer.dll
+ 2008-03-19 10:36:14 754,688 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\gi.dll
+ 2008-03-19 10:36:16 1,145,896 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\gt.exe
+ 2008-03-19 10:36:14 52,288 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\gtapi.dll
+ 2008-03-19 10:42:42 892,928 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\iml32.dll
+ 2008-03-19 11:22:34 249,856 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\Plugin.dll
+ 2008-03-19 11:25:36 442,368 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\Proj.dll
+ 2008-03-19 11:36:06 439,736 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\SwHelper_1100429.exe
+ 2008-03-19 11:26:20 110,592 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\SwInit.exe
+ 2008-03-19 11:22:22 94,208 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\SwMenu.dll
+ 2008-03-19 10:36:14 50,808 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\SYMCCHECKER.DLL
+ 1999-06-25 02:55:30 149,504 ----a-w C:\WINDOWS\system32\Adobe\Shockwave 11\UNWISE.EXE
+ 2001-08-23 11:00:00 10,544 ----a-w C:\WINDOWS\system32\comm.drv
+ 2004-08-03 23:07:22 1,788 ----a-w C:\WINDOWS\system32\Dcache.bin
+ 2004-08-03 17:37:58 2,944 -c--a-w C:\WINDOWS\system32\dllcache\drmkaud.sys
+ 2001-08-23 11:00:00 2,000 -c--a-w C:\WINDOWS\system32\dllcache\keyboard.drv
+ 2001-08-23 11:00:00 2,560 -c--a-w C:\WINDOWS\system32\dllcache\lz32.dll
+ 2001-08-23 11:00:00 73,376 -c--a-w C:\WINDOWS\system32\dllcache\mciavi.drv
+ 2001-08-23 11:00:00 25,264 -c--a-w C:\WINDOWS\system32\dllcache\mciseq.drv
+ 2001-08-23 11:00:00 28,160 -c--a-w C:\WINDOWS\system32\dllcache\mciwave.drv
+ 2001-08-23 11:00:00 2,032 -c--a-w C:\WINDOWS\system32\dllcache\mouse.drv
+ 2001-08-23 11:00:00 2,944 -c--a-w C:\WINDOWS\system32\dllcache\null.sys
+ 2001-08-23 11:00:00 1,744 -c--a-w C:\WINDOWS\system32\dllcache\sound.drv
+ 2001-08-23 11:00:00 3,360 -c--a-w C:\WINDOWS\system32\dllcache\system.drv
+ 2001-08-23 11:00:00 4,048 -c--a-w C:\WINDOWS\system32\dllcache\timer.drv
+ 2001-08-23 11:00:00 2,176 -c--a-w C:\WINDOWS\system32\dllcache\vga.drv
+ 2004-08-03 19:26:58 23,552 -c--a-w C:\WINDOWS\system32\dllcache\wdmaud.drv
+ 2001-08-23 11:00:00 13,600 -c--a-w C:\WINDOWS\system32\dllcache\wfwnet.drv
+ 2001-08-23 11:00:00 2,864 -c--a-w C:\WINDOWS\system32\dllcache\winsock.dll
+ 2004-08-03 22:56:58 146,432 -c--a-w C:\WINDOWS\system32\dllcache\winspool.drv
+ 2001-08-23 11:00:00 2,112 -c--a-w C:\WINDOWS\system32\dllcache\winspool.exe
+ 2001-08-23 11:00:00 2,736 -c--a-w C:\WINDOWS\system32\dllcache\wowdeb.exe
+ 2004-08-03 17:37:58 2,944 ----a-w C:\WINDOWS\system32\drivers\drmkaud.sys
+ 2001-08-23 11:00:00 2,944 ----a-w C:\WINDOWS\system32\drivers\null.sys
+ 2001-08-23 11:00:00 2,000 ----a-w C:\WINDOWS\system32\keyboard.drv
+ 2001-08-23 11:00:00 221,600 ----a-w C:\WINDOWS\system32\lanman.drv
+ 2001-08-23 11:00:00 2,560 ----a-w C:\WINDOWS\system32\lz32.dll
+ 2008-01-03 10:22:04 53,248 ------w C:\WINDOWS\system32\Macromed\Common\SwSupport.dll
- 2008-01-22 07:47:30 74,137 ----a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
+ 2008-03-28 13:33:21 74,649 ----a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
+ 2001-08-23 11:00:00 73,376 ----a-w C:\WINDOWS\system32\mciavi.drv
+ 2001-08-23 11:00:00 25,264 ----a-w C:\WINDOWS\system32\mciseq.drv
+ 2001-08-23 11:00:00 28,160 ----a-w C:\WINDOWS\system32\mciwave.drv
+ 2001-08-23 11:00:00 2,032 ----a-w C:\WINDOWS\system32\mouse.drv
+ 2001-08-23 11:00:00 20,480 ----a-w C:\WINDOWS\system32\msacm32.drv
+ 2004-08-03 22:56:58 188,416 ----a-w C:\WINDOWS\system32\msh261.drv
+ 2004-08-03 23:05:44 294,912 ----a-w C:\WINDOWS\system32\msh263.drv
+ 2001-08-23 11:00:00 2,656 ----a-w C:\WINDOWS\system32\netware.drv
+ 2001-08-23 11:00:00 1,744 ----a-w C:\WINDOWS\system32\sound.drv
+ 2001-08-23 11:00:00 3,360 ----a-w C:\WINDOWS\system32\system.drv
+ 2001-08-23 11:00:00 4,048 ----a-w C:\WINDOWS\system32\timer.drv
+ 2001-08-23 11:00:00 2,176 ----a-w C:\WINDOWS\system32\vga.drv
+ 2004-08-03 19:26:58 23,552 ----a-w C:\WINDOWS\system32\wdmaud.drv
+ 2001-08-23 11:00:00 13,600 ----a-w C:\WINDOWS\system32\wfwnet.drv
+ 2001-08-23 11:00:00 2,864 ----a-w C:\WINDOWS\system32\winsock.dll
+ 2004-08-03 22:56:58 146,432 ----a-w C:\WINDOWS\system32\winspool.drv
+ 2001-08-23 11:00:00 2,112 ----a-w C:\WINDOWS\system32\winspool.exe
+ 2001-08-23 11:00:00 2,736 ----a-w C:\WINDOWS\system32\wowdeb.exe
+ 2000-08-31 00:00:00 49,152 ----a-w C:\WINDOWS\VFind.exe
+ 2000-08-31 00:00:00 68,096 ----a-w C:\WINDOWS\zip.exe
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CAC3D8A5-F0E4-49FF-A731-ED4356CE0446}]
2004-08-04 06:56 88064 --a------ C:\WINDOWS\system32\comctl3.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 15:24 5674352]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-03-01 18:11 4670968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 14:20 155648]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-12-08 20:05 32768]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-03-22 16:27 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-03-22 16:23 126976]
"SoundMan"="SOUNDMAN.EXE" [2005-03-24 23:50 77824 C:\WINDOWS\SOUNDMAN.EXE]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-06-02 11:51 48752]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2005-06-23 21:57 85696]
"AdslTaskBar"="stmctrl.dll" [2004-07-27 15:58 155648 C:\WINDOWS\system32\stmctrl.dll]
"DownloadAccelerator"="C:\Program Files\DAP\DAP.exe" [2007-08-16 13:15 4376328]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-09-08 15:11 98304]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\DAP\\DAP.exe"=
"D:\\torrant\\utorrent.exe"=
R3 Stmatm;ATM/ADSL miniport;C:\WINDOWS\system32\DRIVERS\stmatm.sys [2003-08-12 12:51]
R3 TaurusUsb;Prolink ADSL Modem USB Service;C:\WINDOWS\system32\DRIVERS\torususb.sys [2004-05-12 17:16]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ecbd50f8-4101-11dc-9318-000fb0f39c4b}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe kernel32.dll.vbs
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-04-25 01:39:11
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-04-25 1:42:02
ComboFix-quarantined-files.txt 2008-04-24 17:41:48
ComboFix2.txt 2008-02-11 05:17:53
ComboFix3.txt 2008-01-29 08:47:26
ComboFix4.txt 2008-01-27 08:40:48
ComboFix5.txt 2008-01-27 07:42:48
Pre-Run: 13,870,833,664 bytes free
Post-Run: 14,059,266,048 bytes free
189
HJT log file:Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:45:52 AM, on 4/25/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\DAP\DAP.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.com/customize/ie/defaul...rch/search.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.comR3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {4246C120-7F3C-4E96-86C7-E0E13EFDA75B} - C:\WINDOWS\system32\comctl3.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {CAC3D8A5-F0E4-49FF-A731-ED4356CE0446} - C:\WINDOWS\system32\comctl3.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
O4 - HKLM\..\Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP.EXE" /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{9B9C9EAC-17F0-4D34-B01C-053A9AF6F861}: NameServer = 203.115.0.46 203.115.0.47
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
--
End of file - 5924 bytes