here is teh combofix log
ComboFix 09-03-06.02 - Owner 2009-03-08 11:10:15.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.511.76 [GMT -7:00]
Running from: c:\documents and settings\Owner.ANTHONE\Desktop\ComboFix.exe
AV: AVG Anti-Virus *On-access scanning enabled* (Updated)
AV: Windows OneCare Antivirus *On-access scanning enabled* (Outdated)
FW: Norton Internet Worm Protection *disabled*
FW: Windows OneCare Firewall *enabled*
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Owner.ANTHONE\Application Data\Adobe\Player.exe.bak
c:\windows\cdmxtras
c:\windows\cdmxtras\uninst.exe
c:\windows\IE4 Error Log.txt
c:\windows\patch.exe
c:\windows\system32\au3305adc.dll
c:\windows\system32\cache329
c:\windows\system32\cache329\B_329_0_0_106800.htm
c:\windows\system32\cache329\B_329_0_0_107400.htm
c:\windows\system32\cache329\B_329_1_0_449200.htm
c:\windows\system32\cache329\B_329_1_0_454300.htm
c:\windows\system32\cache329\B_329_2_0_106800.htm
c:\windows\system32\cache329\B_329_2_0_107400.htm
c:\windows\system32\cache329\B_329_3_0_106800.htm
c:\windows\system32\cache329\B_329_3_0_107400.htm
c:\windows\system32\cache329\t_B_329_0_0_106800.htm
c:\windows\system32\cache329\t_B_329_0_0_107400.htm
c:\windows\system32\cache329\t_B_329_1_0_449200.htm
c:\windows\system32\cache329\t_B_329_1_0_454300.htm
c:\windows\system32\cache329\t_B_329_2_0_106800.htm
c:\windows\system32\cache329\t_B_329_2_0_107400.htm
c:\windows\system32\cache329\t_B_329_3_0_106800.htm
c:\windows\system32\cache329\t_B_329_3_0_107400.htm
c:\windows\system32\drivers\npf.sys
c:\windows\system32\packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\WayJmUvw.ini2
c:\windows\system32\WGOqAcdd.ini2
c:\windows\system32\wpcap.dll
c:\windows\wiaserviv.log
D:\Autorun.inf
E:\Autorun.inf
[color=\"RED\"] c:\windows\system32\userinit.exe . . . is infected!![/color]
[color=\"RED\"] c:\windows\system32\svchost.exe . . . is infected!![/color]
[color=\"RED\"] c:\windows\system32\spoolsv.exe . . . is infected!![/color]
[color=\"RED\"] c:\windows\explorer.exe . . . is infected!![/color]
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
-------\Service_NPF
((((((((((((((((((((((((( Files Created from 2009-02-08 to 2009-03-08 )))))))))))))))))))))))))))))))
.
2009-03-06 14:30 . 2009-03-06 14:30 <DIR> d-------- c:\program files\Trend Micro
2009-03-06 12:22 . 2009-03-06 12:22 <DIR> d-------- c:\documents and settings\Owner.ANTHONE\Application Data\Malwarebytes
2009-03-06 12:21 . 2009-02-11 11:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-06 12:21 . 2009-02-11 11:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-03-06 12:20 . 2009-03-06 12:21 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-03-06 12:20 . 2009-03-06 12:20 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-03 12:26 . 2009-03-03 12:29 162,816 --a------ c:\windows\system32\302.tmp
2009-03-03 12:26 . 2009-03-03 12:26 88 --a------ c:\windows\system32\300.tmp
2009-03-03 12:26 . 2009-03-03 12:26 0 --a------ c:\windows\system32\301.tmp
2009-03-03 02:47 . 2009-03-07 20:41 <DIR> d--h----- C:\$AVG8.VAULT$
2009-03-03 02:39 . 2009-03-03 12:33 <DIR> d-------- c:\windows\system32\drivers\Avg
2009-03-03 02:39 . 2009-03-03 02:39 <DIR> d-------- c:\program files\AVG
2009-03-03 02:39 . 2009-03-03 02:39 <DIR> d-------- c:\documents and settings\All Users\Application Data\avg8
2009-03-03 02:39 . 2009-03-03 02:39 325,128 --a------ c:\windows\system32\drivers\avgldx86.sys
2009-03-03 02:39 . 2009-03-03 02:39 107,272 --a------ c:\windows\system32\drivers\avgtdix.sys
2009-03-03 02:39 . 2009-03-03 02:39 12,552 --a------ c:\windows\system32\drivers\avgrkx86.sys
2009-03-03 02:39 . 2009-03-03 02:39 10,520 --a------ c:\windows\system32\avgrsstx.dll
2009-03-03 01:16 . 2009-03-03 01:16 <DIR> d-------- c:\program files\threedegrees
2009-03-03 01:16 . 2009-03-03 01:16 <DIR> d-------- c:\program files\Skyhook Wireless
2009-03-03 01:16 . 2009-03-03 01:16 <DIR> d-------- c:\program files\SEGA
2009-03-03 01:16 . 2009-03-03 01:16 <DIR> d-------- c:\program files\Safari
2009-03-03 01:16 . 2009-03-03 01:16 <DIR> d-------- c:\program files\Pure Networks
2009-03-03 01:16 . 2009-03-03 01:16 <DIR> d-------- c:\program files\MSXML 4.0
2009-03-03 01:16 . 2009-03-03 01:16 <DIR> d-------- c:\program files\MSN Screen Saver
2009-03-03 01:16 . 2009-03-03 01:16 <DIR> d-------- c:\program files\Microsoft Xbox Music Mixer PC Tool
2009-03-03 01:16 . 2009-03-03 01:16 <DIR> d-------- c:\program files\illiminable
2009-03-03 01:16 . 2009-03-03 01:16 <DIR> d-------- c:\program files\FoxyTunes
2009-03-03 01:16 . 2009-03-03 01:16 <DIR> d-------- c:\program files\FolderAccess
2009-03-03 01:16 . 2009-03-03 01:16 <DIR> d-------- c:\program files\Dearborn
2009-03-03 01:16 . 2009-03-03 01:16 <DIR> d-------- c:\program files\Common Files\NSV
2009-03-03 01:04 . 2009-03-03 01:16 <DIR> d-------- c:\program files\LochJournal
2009-03-03 01:03 . 2009-03-03 01:03 <DIR> d-------- c:\program files\Microsoft SQL Server Compact Edition
2009-03-03 01:02 . 2009-03-03 01:16 <DIR> d-------- c:\program files\Messenger Plus! Live
2009-03-02 19:17 . 2009-03-02 19:17 30,208 --a------ c:\windows\system32\308.tmp
2009-03-02 19:14 . 2009-03-02 19:17 161,792 --a------ c:\windows\system32\304.tmp
2009-03-02 19:14 . 2009-03-02 19:14 124 --a------ c:\windows\system32\303.tmp
2009-03-02 10:18 . 2009-03-03 01:00 <DIR> d-------- c:\documents and settings\Owner.ANTHONE\.housecall6.6
2009-03-02 10:05 . 2009-03-02 10:05 0 --a------ c:\windows\_id.dat
2009-03-02 10:04 . 2009-03-02 10:04 30,208 --a------ c:\windows\system32\2FA.tmp
2009-03-01 22:52 . 2009-03-01 22:52 0 --a------ c:\windows\system32\2FB.tmp
2009-03-01 14:31 . 2009-03-03 01:17 <DIR> d-------- c:\documents and settings\Owner.ANTHONE\AdobeLicensingFilesBackup
2009-02-08 00:47 . 2009-02-08 00:47 32 --a------ c:\windows\basefx.INI
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-08 20:06 114 ----a-w C:\sccfg.sys
2009-03-08 08:31 --------- d-----w c:\program files\Microsoft Windows OneCare Live
2009-03-08 08:08 --------- d-----w c:\program files\LogMeIn
2009-03-08 03:42 --------- d-----w c:\documents and settings\All Users\Application Data\WFP
2009-03-03 15:04 --------- d-----w c:\program files\WinPcap
2009-03-03 14:18 --------- d-----w c:\program files\magicISO
2009-03-03 14:15 --------- d-----w c:\program files\Kazaa Lite K++
2009-03-03 14:02 --------- d-----w c:\program files\iIChatLogger
2009-03-03 08:21 --------- d-----w c:\program files\Common Files\Adobe
2009-03-03 08:17 --------- d-----w c:\program files\Trojan Remover
2009-03-03 08:17 --------- d-----w c:\program files\AIMTunes
2009-03-03 08:04 --------- d-----w c:\program files\MSN Messenger
2009-03-03 07:56 --------- d-----w c:\program files\UDPixel
2009-03-02 03:29 --------- d-----w c:\program files\Windows Live
2009-03-01 21:32 --------- d-----w c:\documents and settings\All Users\Application Data\FLEXnet
2009-02-26 01:57 --------- d-----w c:\program files\Steam
2008-12-12 19:18 87,336 ----a-w c:\windows\system32\dns-sd.exe
2008-12-12 19:11 61,440 ----a-w c:\windows\system32\dnssd.dll
2008-03-07 20:58 32 ----a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2004-12-07 20:30 92,536 ----a-w c:\documents and settings\Owner.ANTHONE\Application Data\GDIPFONTCACHEV1.DAT
2003-09-24 14:30 94,784 -csh--w c:\windows\twain.dll
2004-08-04 10:56 50,688 --sh--w c:\windows\twain_32.dll
2006-02-23 21:54 80 --sh--r c:\windows\system32\9E6F8F5001.dll
2004-09-06 03:33 10,022 -csha-w c:\windows\system32\KGyGaAvL.sys
2004-08-04 10:56 1,028,096 --sha-w c:\windows\system32\mfc42.dll
2004-08-04 10:56 54,784 --sha-w c:\windows\system32\msvcirt.dll
2004-08-04 10:56 413,696 --sha-w c:\windows\system32\msvcp60.dll
2007-12-04 18:38 550,912 --sha-w c:\windows\system32\oleaut32.dll
2004-08-04 10:56 83,456 --sha-w c:\windows\system32\olepro32.dll
2004-08-04 10:56 29,184 --sha-w c:\windows\system32\regsvr32.exe
.
------- Sigcheck -------
2003-09-23 21:40 30208 0e30185391664a93adea467fb30d112d c:\windows\$NtServicePackUninstall$\svchost.exe
2004-08-04 03:56 31744 507d4280883b3b2f86cf419409f7c752 c:\windows\ServicePackFiles\i386\svchost.exe
2008-04-13 17:12 31744 80e8884636e2f24878225ec7e6212371 c:\windows\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\svchost.exe
2004-08-04 03:56 31744 a91cf50336aff204e52c96739fe587be c:\windows\system32\svchost.exe
2007-06-13 03:23 1050624 064764874e384ce81c976a2b23101287 c:\windows\explorer.exe
2007-06-13 04:26 1050624 7c9855e139757c4ff9b0aea726e45063 c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
2003-09-23 13:32 1021440 f3bd0a5fbe5ac1102068af36f1de5dea c:\windows\$NtServicePackUninstall$\explorer.exe
2003-09-23 13:32 1021440 4beb38ca693bcc872f01060ce4aeb560 c:\windows\$NtUninstallKB820291$\explorer.exe
2004-08-04 03:56 1049600 b6ead87cff7cd1beab8d15bae4a0344d c:\windows\$NtUninstallKB938828$\explorer.exe
2004-08-04 03:56 1049088 a120c5a41edde16e888bc1c12d3923d4 c:\windows\ServicePackFiles\i386\explorer.exe
2008-04-13 17:12 1050624 61c4df4d6b876a7ed811c69977781ffe c:\windows\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\explorer.exe
2007-06-13 03:23 1050624 ce5d36031342ded2f3556889d100f6ba c:\windows\system32\dllcache\explorer.exe
2003-09-23 13:54 30720 651996b9e028a6cb9300f751851635fd c:\windows\$NtServicePackUninstall$\ctfmon.exe
2004-08-04 03:56 32768 46cd882e4a9513fa4493f69bd8ce5a48 c:\windows\ServicePackFiles\i386\ctfmon.exe
2008-04-13 17:12 32768 fda80b85f613580c9775e1cae6981e2e c:\windows\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\ctfmon.exe
2004-08-04 03:56 32768 7217d1f15893498e12426adc35464080 c:\windows\system32\ctfmon.exe
2004-08-04 03:56 32768 03c80a6a1a561bffe132465fcde7032f c:\windows\system32\dllcache\ctfmon.exe
2005-06-10 17:17 75264 e62e147599af3f9f0bb818b9d425051a c:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2003-09-24 05:19 68608 d5bf1bd8ebe36342e1231548b16bcd23 c:\windows\$NtServicePackUninstall$\spoolsv.exe
2004-08-04 03:56 75264 6358865e9c84bcbecb67b8bf5d792994 c:\windows\$NtUninstallKB896423$\spoolsv.exe
2004-08-04 03:56 75264 044bec1aeabbb690fb2cf3cc35079aa5 c:\windows\ServicePackFiles\i386\spoolsv.exe
2008-04-13 17:12 75264 4adca18e0b6ad9daa5af45ab194ad1de c:\windows\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\spoolsv.exe
2005-06-10 16:53 75264 e31e3d84663d285c15d5925a43607679 c:\windows\system32\spoolsv.exe
2003-09-23 21:45 39424 ff8b53ed5cad216a3156e76b81e74b40 c:\windows\$NtServicePackUninstall$\userinit.exe
2004-08-04 03:56 41984 e93743a26b7dcac4bf4f059b80c421e2 c:\windows\ServicePackFiles\i386\userinit.exe
2008-04-13 17:12 43520 16a4911aeba83a43beb52fe8daf4678f c:\windows\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\userinit.exe
2004-08-04 03:56 41984 8f831b54d54841b645f59ca5c2783ede c:\windows\system32\userinit.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 32768]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 221696]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2005-11-15 1220608]
"Google Update"="c:\documents and settings\Owner.ANTHONE\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-03 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 70144]
"HPHUPD05"="c:\program files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [2003-08-21 69632]
"HPHmon05"="c:\windows\System32\hphmon05.exe" [2003-08-21 503808]
"KBD"="c:\hp\KBD\KBD.EXE" [2003-02-11 81920]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 262144]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2003-12-05 3022848]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-25 360448]
"OneCareUI"="c:\program files\Microsoft Windows OneCare Live\winssnotify.exe" [2006-01-05 262104]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2006-01-12 217088]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2005-12-04 461584]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_10\bin\jusched.exe" [2006-11-09 49263]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2007-04-17 63048]
"UVS10 Preload"="c:\program files\Ulead Systems\Ulead VideoStudio 10\uvPL.exe" [2006-03-07 57344]
"WindowsTelemetry"="c:\program files\Microsoft Windows Feedback Panel\\WFPUser.exe" [2008-12-12 177016]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-10-01 111936]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-05-24 180269]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 434176]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-03-03 1601304]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 c:\windows\ALCXMNTR.EXE]
c:\documents and settings\Owner.ANTHONE\Start Menu\Programs\Startup\
Rainlendar.lnk - c:\program files\Rainlendar\Rainlendar.exe [2006-01-21 139264]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
WFPUser.lnk - c:\program files\Microsoft Windows Feedback Panel\wfpuser.exe [2008-12-12 177016]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\explorer.exe,"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MCPClient]
2003-08-25 13:25 139264 c:\progra~1\COMMON~1\stardock\MCPStub.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
2005-12-06 22:16 176128 c:\progra~1\Stardock\OBJECT~1\WINDOW~1\WbSrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-03-03 02:39 10520 c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2008-10-17 08:03 87352 c:\windows\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wbsys.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= c:\progra~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm
"msacm.MPEGacm"= c:\progra~1\COMMON~1\ULEADS~1\MPEG\MPEGacm.acm
"msacm.ulmp3acm"= c:\progra~1\COMMON~1\ULEADS~1\MPEG\ulmp3acm.acm
"msacm.ac3filter"= ac3filter.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=c:\windows\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Compaq Connections.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Compaq Connections.lnk
backup=c:\windows\pss\Compaq Connections.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^MSN Desktop Search.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\MSN Desktop Search.lnk
backup=c:\windows\pss\MSN Desktop Search.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NaturalColorLoad.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\NaturalColorLoad.lnk
backup=c:\windows\pss\NaturalColorLoad.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
backup=c:\windows\pss\Quicken Scheduled Updates.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Winter Fun Wallpaper Changer.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Winter Fun Wallpaper Changer.lnk
backup=c:\windows\pss\Winter Fun Wallpaper Changer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner.ANTHONE^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\Owner.ANTHONE\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner.ANTHONE^Start Menu^Programs^Startup^AquariumDesktop2006.lnk]
path=c:\documents and settings\Owner.ANTHONE\Start Menu\Programs\Startup\AquariumDesktop2006.lnk
backup=c:\windows\pss\AquariumDesktop2006.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner.ANTHONE^Start Menu^Programs^Startup^spamsubtract.lnk]
path=c:\documents and settings\Owner.ANTHONE\Start Menu\Programs\Startup\spamsubtract.lnk
backup=c:\windows\pss\spamsubtract.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Bart Station]
c:\program files\ISP50\BIN\PPCOLink -STATION [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
c:\windows\system32\dumprep 0 -u [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\3Degrees]
--a------ 2003-07-14 12:57 245824 c:\program files\threedegrees\threedegrees.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
--a------ 2001-07-20 06:10 73728 c:\program files\AIM\aim.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CW]
--a--c--- 2006-01-17 18:00 231936 c:\program files\windowsys\cw4.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeadAIM]
--a--c--- 2003-03-03 22:59 144896 c:\program files\AIM\DeadAIM.ocm
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DesktopX]
--a------ 2004-02-10 01:16 556544 c:\program files\Stardock\Object Desktop\DesktopX\DesktopX.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
--a----t- 2008-09-03 08:02 133104 c:\documents and settings\Owner.ANTHONE\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
--a------ 2005-11-15 20:44 1220608 c:\program files\Microsoft ActiveSync\wcescomm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-11-20 14:20 290088 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
--a------ 2003-06-18 20:00 221184 c:\program files\Microsoft Money\System\mnyexpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 09:24 1711616 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a--c--- 2001-07-09 13:50 176128 c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2003-12-05 20:50 3022848 c:\windows\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PS2]
--a------ 2003-09-12 20:13 118784 c:\windows\system32\ps2.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
--a--c--- 2006-01-31 05:20 200704 c:\program files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-11-04 11:30 434176 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
--a--c--- 2003-11-03 17:50 241664 c:\windows\SMINST\Recguard.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder]
--a--c--- 2003-12-18 00:31 139264 c:\windows\CREATOR\Remind_XP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 2008-02-01 18:22 21898024 c:\program files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2008-10-09 15:21 1410296 c:\program files\Steam\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a--c--- 2004-01-27 05:53 32881 c:\program files\Java\j2re1.4.2_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sunkist2k]
--a------ 2003-10-29 14:17 155648 c:\program files\Multimedia Card Reader\shwicon2k.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2006-05-24 08:57 180269 c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrojanScanner]
--a--c--- 2004-11-28 20:48 281232 c:\program files\Trojan Remover\Trjscan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
--a------ 2003-08-19 09:01 131072 c:\program files\Common Files\Sonic\Update Manager\sgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
-ra------ 2006-03-30 16:45 313472 c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Media Connect 2]
--------- 2006-10-18 22:58 26112 c:\program files\Windows Media Connect 2\WMCCFG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-08-30 17:43 4670704 c:\program files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
--a------ 2004-09-07 16:47 77824 c:\windows\ALCXMNTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LTMSG]
--a--c--- 2003-07-14 18:52 61440 c:\windows\ltmsg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a--c--- 2003-12-05 20:50 774144 c:\windows\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"mW[íµˆÖ¾`=µú¾˜v%S8’ÿÙêé>grl>Ý\†Ð=ŸàÛ±Þ"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\kdx\\khost.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Excursion9.5\\mIRC.ExCurSioN.exe"=
"c:\\Program Files\\threedegrees\\threedegrees.exe"=
"c:\\Program Files\\Compaq Connections\\1940576\\Program\\BackWeb-1940576.exe"=
"c:\\Program Files\\threedegrees\\musicmix.exe"=
"c:\\Program Files\\Sierra On-Line\\SIGSPat.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Steam\\SteamApps\\anthone\\counter-strike\\hl.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\XBConnect4\\XBC4.exe"=
"c:\\Program Files\\Steam\\SteamApps\\anthone\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Railroad Tycoon 3\\RT3.exe"=
"c:\\Program Files\\Shareaza\\Shareaza.exe"=
"c:\\Program Files\\K-litePro\\k-litepro.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\Kazaa Lite K++\\KazaaLite.kpp"=
"c:\\Program Files\\Bit Lord 1.1\\BitLord.exe"=
"c:\\Program Files\\LeechFTP\\Leechftp.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"=
"c:\\StubInstaller.exe"=
"c:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\helpctr.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\PPLive\\PPLive.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:@xpsp2res.dll,-22010
"3540:UDP"= 3540:UDP:*:Disabled:@xpsp2res.dll,-22011
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\RaInfo.sys [2008-02-28 12856]
R2 mrtRate;mrtRate;
R3 Ipinprospw;Ipinprospw;c:\windows\system32\drivers\nwlnkflt.sys [2003-09-24 12416]
R3 ldiskl;ldiskl;
R3 Mssauisk;Mssauisk;
R3 xusb20;Xbox 360 Wireless Receiver for Windows Driver Service;c:\windows\system32\DRIVERS\xusb20.sys [2006-10-13 50048]
R4 LMIRfsClientNP;LMIRfsClientNP;
S0 AvgRkx86;avgrkx86.sys;c:\windows\System32\Drivers\avgrkx86.sys [2009-03-03 12552]
S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-03-03 325128]
S1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-03-03 107272]
S1 MPSHLPR;MPSHLPR;c:\windows\system32\DRIVERS\mpshlpr.sys [2005-10-26 106752]
S2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-03-03 298264]
S2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2008-10-17 47640]
S2 MPSDrv;MPSDrv;c:\windows\system32\DRIVERS\mpsdrv.sys [2005-10-26 82560]
S2 mpssvc;Microsoft Protection Service;c:\program files\Microsoft Windows OneCare Live\Firewall\mpssvc.exe [2005-10-27 836328]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S2 wfpservice;Windows Feedback Panel Background Service;c:\program files\Microsoft Windows Feedback Panel\WFPService.EXE [2008-12-12 250744]
--- Other Services/Drivers In Memory ---
*Deregistered* - 6to4
*Deregistered* - ALG
*Deregistered* - Apple Mobile Device
*Deregistered* - Ati HotKey Poller
*Deregistered* - AudioSrv
*Deregistered* - avg8wd
*Deregistered* - BITS
*Deregistered* - Bonjour Service
*Deregistered* - Browser
*Deregistered* - CryptSvc
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - Dnscache
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - FltMgr
*Deregistered* - Ftdisk
*Deregistered* - Gpc
*Deregistered* - helpsvc
*Deregistered* - HidServ
*Deregistered* - HTTP
*Deregistered* - HTTPFilter
*Deregistered* - ImapiService
*Deregistered* - IpFilterDriver
*Deregistered* - IpN