ComboFix 08-09-15.02 - Administrator 2008-09-17 0:25:51.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.81 [GMT -4:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Administrator\Desktop\CFScript.txt
* Created a new restore point
[color=\"red\"]
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/color]
.
((((((((((((((((((((((((( Files Created from 2008-08-17 to 2008-09-17 )))))))))))))))))))))))))))))))
.
2008-09-16 22:43 . 2008-09-16 22:43 <DIR> d-------- C:\rsit
2008-09-16 21:59 . 2008-09-16 21:59 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-16 21:59 . 2008-09-16 21:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-16 21:59 . 2008-09-16 21:59 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2008-09-16 21:59 . 2008-09-08 00:11 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-16 21:59 . 2008-09-08 00:11 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-09-16 21:51 . 2008-09-16 21:51 <DIR> d-------- C:\WINDOWS\system32\xircom
2008-09-16 21:51 . 2008-09-16 21:51 <DIR> d-------- C:\Program Files\microsoft frontpage
2008-09-16 21:47 . 2008-09-16 21:47 578,560 --a------ C:\WINDOWS\system32\dllcache\user32.dll
2008-09-16 21:46 . 2008-09-16 21:47 <DIR> d-------- C:\WINDOWS\ERUNT
2008-09-16 21:41 . 2008-09-16 21:53 <DIR> d-------- C:\SDFix
2008-09-16 15:41 . 2008-09-16 15:41 <DIR> d-------- C:\mGame
2008-09-16 15:41 . 2008-09-16 15:41 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\InstallShield
2008-09-15 22:44 . 2001-08-17 22:36 8,704 --a------ C:\WINDOWS\system32\kbdjpn.dll
2008-09-15 22:44 . 2001-08-17 22:36 8,192 --a------ C:\WINDOWS\system32\kbdkor.dll
2008-09-15 22:44 . 2008-03-21 01:33 6,144 --a------ C:\WINDOWS\system32\kbd106.dll
2008-09-15 22:44 . 2001-08-17 14:55 6,144 --a------ C:\WINDOWS\system32\kbd101c.dll
2008-09-15 22:44 . 2001-08-17 14:55 6,144 --a------ C:\WINDOWS\system32\kbd101b.dll
2008-09-15 22:44 . 2001-08-17 14:55 5,632 --a------ C:\WINDOWS\system32\kbd103.dll
2008-09-15 22:43 . 2008-09-15 22:44 <DIR> d-------- C:\WINDOWS\CAVTemp
2008-09-15 17:12 . 2008-09-15 17:31 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\LimeWire
2008-09-15 15:34 . 2008-09-15 15:34 <DIR> d-------- C:\Program Files\WiFiConnector
2008-09-15 15:31 . 2008-09-15 15:31 <DIR> d-------- C:\Program Files\CA
2008-09-15 15:31 . 2008-09-15 15:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\CA
2008-09-15 15:31 . 2008-09-15 15:32 880,560 --a------ C:\WINDOWS\system32\drivers\vetefile.sys
2008-09-15 15:31 . 2008-09-15 15:32 108,368 --a------ C:\WINDOWS\system32\drivers\veteboot.sys
2008-09-15 15:31 . 2008-01-11 21:30 99,592 --a------ C:\WINDOWS\system32\isafeif.dll
2008-09-15 15:31 . 2008-09-15 15:32 91,376 --a------ C:\WINDOWS\system32\isafprod.dll
2008-09-15 15:31 . 2008-01-11 21:30 83,256 --a------ C:\WINDOWS\system32\vetredir.dll
2008-09-15 15:31 . 2008-09-15 15:32 32,240 --a------ C:\WINDOWS\system32\drivers\vetmonnt.sys
2008-09-15 15:31 . 2008-09-15 15:32 26,352 --a------ C:\WINDOWS\system32\drivers\vet-filt.sys
2008-09-15 15:31 . 2008-09-15 15:32 21,488 --a------ C:\WINDOWS\system32\drivers\vetfddnt.sys
2008-09-15 15:31 . 2008-09-15 15:32 21,104 --a------ C:\WINDOWS\system32\drivers\vet-rec.sys
2008-09-15 15:29 . 2008-09-15 15:29 <DIR> d-------- C:\WINDOWS\Logs
2008-09-15 15:28 . 2008-09-15 15:28 <DIR> d-------- C:\Program Files\Sun
2008-09-15 15:28 . 2008-09-15 15:28 <DIR> d-------- C:\Program Files\Java
2008-09-15 15:28 . 2008-09-15 15:28 <DIR> d-------- C:\Program Files\Common Files\Java
2008-09-15 15:28 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-09-15 15:26 . 2008-09-15 15:27 <DIR> d-------- C:\Program Files\LimeWire
2008-09-15 15:26 . 2008-09-15 15:29 <DIR> d-------- C:\Program Files\Direct X
2008-09-15 10:18 . 2008-09-15 10:18 <DIR> d-------- C:\Program Files\Ventrilo
2008-09-15 10:18 . 2008-09-15 10:18 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-09-15 10:17 . 2008-09-15 10:17 <DIR> d-------- C:\Program Files\mIRC
2008-09-15 10:17 . 2008-09-15 10:17 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\mIRC
2008-09-15 10:13 . 2008-09-15 10:13 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Logitech
2008-09-15 10:13 . 2008-09-15 10:13 127,034 -r------- C:\WINDOWS\bwUnin-8.1.1.50-8876480SL.exe
2008-09-15 10:12 . 2008-09-15 10:13 <DIR> d-------- C:\Program Files\Logitech
2008-09-15 10:12 . 2008-09-15 10:12 <DIR> d-------- C:\Program Files\Common Files\Logitech
2008-09-15 10:12 . 2008-09-15 10:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Logitech
2008-09-15 10:08 . 2008-09-15 15:45 <DIR> d-------- C:\Program Files\middle_man
2008-09-15 10:06 . 2008-09-15 10:06 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Aim
2008-09-15 10:05 . 2008-09-15 15:38 <DIR> d-------- C:\Program Files\Viewpoint
2008-09-15 10:05 . 2008-09-15 10:05 <DIR> d-------- C:\Program Files\AOD
2008-09-15 10:05 . 2008-09-15 10:08 <DIR> d-------- C:\Program Files\AIM
2008-09-15 10:05 . 2004-02-25 08:05 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
2008-09-15 10:01 . 2008-03-20 14:39 32,128 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-09-15 10:01 . 2008-03-20 20:36 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2008-09-15 10:01 . 2008-03-20 14:32 14,592 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2008-09-15 10:01 . 2001-08-17 08:48 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2008-09-15 10:01 . 2008-03-20 14:38 10,368 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-16 19:41 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-16 00:51 507,904 ----a-w C:\WINDOWS\system32\winlogon.exe
2008-09-16 00:51 295,424 ----a-w C:\WINDOWS\system32\termsrv.dll
2008-09-15 14:12 0 ---ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-09-15 14:12 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2008-09-15 14:12 --------- d-----w C:\Program Files\Common Files\Ahead
2008-09-15 14:11 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-09-15 12:54 --------- d---a-w C:\Program Files\(HDTune)
2008-09-15 12:46 --------- d-----w C:\Program Files\Nero
2008-09-15 12:41 --------- d-----w C:\Program Files\Microsoft.NET
2008-09-15 12:41 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-09-15 12:38 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Talkback
2008-09-15 12:34 --------- d-----w C:\Program Files\office 2003 pro
2008-09-15 12:30 --------- d-----w C:\Program Files\Common Files\Adobe
2008-09-15 12:29 --------- d-----w C:\Program Files\Common Files\Adobe Systems Shared
2008-09-15 12:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\Adobe Systems
2008-09-15 12:25 --------- d-----w C:\Program Files\Analog Devices
2008-09-15 12:24 --------- d-----w C:\Documents and Settings\Administrator\Application Data\U3
2008-09-15 11:56 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-09-15 11:53 --------- d-----w C:\Program Files\Opera
2008-07-31 14:41 68,616 ----a-w C:\WINDOWS\system32\XAPOFX1_1.dll
2008-07-31 14:41 238,088 ----a-w C:\WINDOWS\system32\xactengine3_2.dll
2008-07-31 14:40 509,448 ----a-w C:\WINDOWS\system32\XAudio2_2.dll
2008-07-19 02:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
2008-07-19 02:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 02:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 02:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2008-07-19 02:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 02:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-19 02:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
2008-07-19 02:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 02:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
2008-07-19 02:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 02:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
2008-07-19 02:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 02:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
2008-07-19 02:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-19 02:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
2008-07-12 12:18 467,984 ----a-w C:\WINDOWS\system32\d3dx10_39.dll
2008-07-12 12:18 3,851,784 ----a-w C:\WINDOWS\system32\D3DX9_39.dll
2008-07-12 12:18 1,493,528 ----a-w C:\WINDOWS\system32\D3DCompiler_39.dll
.
------- Sigcheck -------
2008-06-20 06:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 C:\WINDOWS\SoftwareDistribution\Download\ad744bdeedce85bf37a096f34577ff3a\SP2GDR\tcpip.sys
2008-06-20 06:44 360960 744e57c99232201ae98c49168b918f48 C:\WINDOWS\SoftwareDistribution\Download\ad744bdeedce85bf37a096f34577ff3a\SP2QFE\tcpip.sys
2008-06-20 07:51 361600 9aefa14bd6b182d61e3119fa5f436d3d C:\WINDOWS\SoftwareDistribution\Download\ad744bdeedce85bf37a096f34577ff3a\SP3GDR\tcpip.sys
2008-06-20 07:59 361600 ad978a1b783b5719720cff204b666c8e C:\WINDOWS\SoftwareDistribution\Download\ad744bdeedce85bf37a096f34577ff3a\SP3QFE\tcpip.sys
2008-05-03 08:00 361344 37d8387cbd4437c55f454209be10ef11 C:\WINDOWS\system32\drivers\tcpip.sys
2008-09-15 20:51 507904 a8f7ab40d4b2478fdcb4adc1291a9d52 C:\WINDOWS\system32\winlogon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AIM"="C:\PROGRA~1\AIM\aim.exe" [2006-08-01 67112]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-05-03 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"cctray"="C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe" [2008-09-15 181488]
"CAVRID"="C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2008-09-15 234736]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-01-23 C:\WINDOWS\KHALMNPR.Exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-01-23 C:\WINDOWS\KHALMNPR.Exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2007-08-13 C:\WINDOWS\system32\advpack.dll]
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2008-09-15 67128]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2008-09-15 688128]
Run Nintendo Wi-Fi USB Connector Registration Tool.lnk - C:\Program Files\WiFiConnector\NintendoWFCReg.exe [2008-09-15 1073152]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableCAD"= 1 (0x1)
"DisableStatusMessages"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"MemCheckBoxInRunDlg"= 1 (0x1)
"StartMenuFavorites"= 0 (0x0)
"Start_ShowMyComputer"= 1 (0x1)
"Start_ShowMyDocs"= 1 (0x1)
"Start_ShowMyMusic"= 0 (0x0)
"Start_ShowRun"= 1 (0x1)
"Start_ShowSearch"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoResolveSearch"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"MemCheckBoxInRunDlg"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoResolveSearch"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"MemCheckBoxInRunDlg"= 1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"C:\\Program Files\\WiFiConnector\\NintendoWFCReg.exe"=
*Newly Created Service* - PROCEXP90
*Newly Created Service* - SR
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-09-17 00:30:04
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\prio.dll
PROCESS: C:\WINDOWS\system32\lsass.exe
-> C:\WINDOWS\system32\prio.dll
.
Completion time: 2008-09-17 0:32:33
ComboFix-quarantined-files.txt 2008-09-17 04:32:09
Pre-Run: 32,414,777,344 bytes free
Post-Run: 32,412,381,184 bytes free
200
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:34:21 AM, on 9/17/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\PROGRA~1\AIM\aim.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\WiFiConnector\NintendoWFCReg.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Administrator\My Documents\HJT\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O4 - Global Startup: Run Nintendo Wi-Fi USB Connector Registration Tool.lnk = C:\Program Files\WiFiConnector\NintendoWFCReg.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {99CAAA27-FA0C-4FA4-B88A-4AB1CC7A17FE} (MGLaunch_USAv1001 Class) -
http://ares.netgame.com/download/mglaunch_USAv1002.cabO18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
--
End of file - 5190 bytes
There they are. Also, my computer tends to just turn off randomly over a period of time. Seems it varies from 10 minutes, to a few hours, a day or two etc. I just got a brand new motherboard so it cant be dead capacitors. Could it be my wireless mouse and keyboard plus the WiFi Connector that could cause this?
And things are running fine.