COMBOFIX PART 1:
ComboFix 09-12-11.01 - Owner 11/12/2009 19:01:01.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2038.1125 [GMT 0:00]
Running from: c:\documents and settings\Owner\My Documents\Downloads\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Owner\Application Data\System Defender
c:\documents and settings\Owner\Local Settings\Application Data\{F6D74AC3-C563-4D0E-89F7-8201ED77337F}
c:\documents and settings\Owner\Local Settings\Application Data\{F6D74AC3-C563-4D0E-89F7-8201ED77337F}\chrome.manifest
c:\documents and settings\Owner\Local Settings\Application Data\{F6D74AC3-C563-4D0E-89F7-8201ED77337F}\chrome\content\_cfg.js
c:\documents and settings\Owner\Local Settings\Application Data\{F6D74AC3-C563-4D0E-89F7-8201ED77337F}\chrome\content\overlay.xul
c:\documents and settings\Owner\Local Settings\Application Data\{F6D74AC3-C563-4D0E-89F7-8201ED77337F}\install.rdf
c:\program files\WinPCap
c:\program files\WinPCap\rpcapd.exe
c:\recycler\S-1-5-21-2298946822-3142497278-1171021050-500
c:\windows\run.log
c:\windows\system32\config\systemprofile\Start Menu\Programs\Windows Police Pro
c:\windows\system32\config\systemprofile\Start Menu\Programs\Windows Police Pro\Windows Police Pro.lnk
c:\windows\system32\drivers\npf.sys
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
c:\windows\system32\lowsec\user.ds.lll
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\qtplugin.exe
c:\windows\system32\R-EJ-O-_0tQK.exe
c:\windows\system32\schtml
c:\windows\system32\sdra64.exe
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ANTIPOL
-------\Legacy_NPF
-------\Service_npf
((((((((((((((((((((((((( Files Created from 2009-11-11 to 2009-12-11 )))))))))))))))))))))))))))))))
.
2009-12-11 00:00 . 2009-12-11 00:00 -------- d-sh--w- c:\documents and settings\Owner\Application Data\SystemProc
2009-12-08 17:48 . 2009-12-11 19:17 70688 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-12-08 17:48 . 2009-12-11 19:17 5478176 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-12-08 17:15 . 2009-12-08 17:15 -------- d-----w- c:\program files\Common Files\ParetoLogic
2009-12-08 17:15 . 2009-12-08 17:15 -------- d-----w- c:\documents and settings\All Users\Application Data\ParetoLogic Anti-Virus PLUS
2009-12-08 17:15 . 2009-12-08 17:15 -------- d-----w- c:\program files\ParetoLogic
2009-12-08 17:15 . 2009-12-08 17:15 -------- d-----w- c:\documents and settings\All Users\Application Data\ParetoLogic
2009-12-08 17:14 . 2009-12-08 17:14 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\Downloaded Installations
2009-12-08 01:21 . 2009-12-09 00:49 0 ----a-w- c:\windows\Twupewoqanedev.bin
2009-12-08 01:21 . 2009-12-09 05:17 120 ----a-w- c:\windows\Ifeseyojiyedoh.dat
2009-12-08 01:18 . 2009-12-08 01:18 -------- d-sh--w- c:\documents and settings\All Users\Application Data\WSKJPIQD_APDM
2009-12-08 01:18 . 2009-12-08 01:18 -------- d-----w- c:\documents and settings\Owner\.COMMgr
2009-12-08 01:18 . 2009-12-08 02:36 -------- d-----w- c:\documents and settings\All Users\Application Data\a78badf
2009-12-08 01:16 . 2009-12-08 01:16 -------- d-sh--w- c:\documents and settings\Owner\Application Data\System
2009-12-08 01:16 . 2009-12-08 01:16 -------- d-----w- c:\documents and settings\Owner\Application Data\Mozilla Firefox
2009-12-05 02:04 . 2009-12-05 02:04 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\Easy CD-DA Extractor
2009-12-05 02:04 . 2009-12-07 06:47 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-05 02:03 . 2009-12-05 02:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Easy CD-DA Extractor
2009-12-05 02:03 . 2009-12-05 02:03 -------- d-----w- c:\program files\Easy CD-DA Extractor 12
2009-12-05 02:03 . 2009-12-05 02:03 -------- d-----w- c:\windows\Easy CD-DA Extractor 12.0.4
2009-11-21 13:38 . 2009-11-21 13:38 -------- d-----w- c:\documents and settings\Owner\Tracing
2009-11-21 13:37 . 2009-11-21 13:37 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-11-21 13:35 . 2009-11-21 13:35 -------- d-----w- c:\program files\Microsoft
2009-11-21 13:35 . 2009-11-21 13:35 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-11-21 13:29 . 2009-11-21 13:29 -------- d-----w- c:\program files\Common Files\Windows Live
2009-11-19 11:45 . 2009-11-19 11:45 1183744 ----a-w- c:\windows\system32\z2b4kwnD4.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-11 19:15 . 2009-12-08 17:48 7556 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-12-11 19:15 . 2009-12-08 17:48 74324 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-12-11 00:00 . 2009-12-11 00:00 59392 --sh--w- c:\documents and settings\Owner\Application Data\SystemProc\lsass.exe
2009-12-09 17:13 . 2008-09-08 15:55 -------- d-----w- c:\program files\World of Warcraft
2009-12-08 17:49 . 2009-12-08 17:49 125952 ----a-w- c:\documents and settings\All Users\Application Data\ParetoLogic\UUS2\Temp\Update.exe
2009-12-08 01:16 . 2009-12-08 01:16 59392 --sh--w- c:\documents and settings\Owner\Application Data\System\lsass.exe
2009-11-30 13:44 . 2008-10-06 17:52 -------- d-----w- c:\documents and settings\Owner\Application Data\Skype
2009-11-30 13:43 . 2008-10-06 17:58 -------- d-----w- c:\documents and settings\Owner\Application Data\skypePM
2009-11-26 12:47 . 2009-12-11 17:23 2063640 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-11-26 12:47 . 2009-12-11 17:23 3514648 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgui.exe
2009-11-26 12:47 . 2009-12-11 17:23 2029336 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgtray.exe
2009-11-21 13:37 . 2008-07-26 11:28 43536 ----a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-21 13:37 . 2008-09-10 16:18 -------- d-----w- c:\program files\Windows Live
2009-11-21 13:37 . 2008-07-22 23:44 -------- d-----w- c:\program files\Windows Live Toolbar
2009-11-09 01:00 . 2009-11-09 01:00 -------- d-----w- c:\documents and settings\Owner\Application Data\Octoshape
2009-11-06 13:49 . 2009-12-08 01:18 457688 ----a-w- c:\documents and settings\All Users\Application Data\a78badf\sqlite3.dll
2009-11-06 13:49 . 2009-12-08 01:18 722392 ----a-w- c:\documents and settings\All Users\Application Data\a78badf\mozcrt19.dll
2009-10-26 15:02 . 2008-09-27 11:26 -------- d-----w- c:\documents and settings\Owner\Application Data\Apple Computer
2009-10-26 14:55 . 2009-10-26 14:54 -------- d-----w- c:\program files\iTunes
2009-10-26 14:55 . 2009-10-26 14:54 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-10-26 14:54 . 2009-10-26 14:54 -------- d-----w- c:\program files\iPod
2009-10-26 14:53 . 2009-10-26 14:53 -------- d-----w- c:\program files\Bonjour
2009-10-26 14:52 . 2009-10-26 14:52 -------- d-----w- c:\program files\QuickTime
2009-10-26 14:52 . 2008-09-27 11:25 -------- d-----w- c:\program files\Common Files\Apple
2009-10-18 15:48 . 2009-02-06 14:35 -------- d-----w- c:\documents and settings\Owner\Application Data\Ventrilo
2009-10-16 07:40 . 2008-06-23 20:34 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-16 07:40 . 2009-06-09 02:08 -------- d-----w- c:\program files\THQ
2009-10-16 07:38 . 2009-05-02 18:37 -------- d-----w- c:\documents and settings\Owner\Application Data\My Battle for Middle-earth Files
2009-10-14 16:14 . 2009-10-14 16:14 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes
2009-10-14 16:14 . 2009-10-14 16:14 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-14 16:14 . 2009-10-14 16:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-10-14 16:04 . 2008-10-31 14:44 -------- d-----w- c:\documents and settings\Owner\Application Data\LimeWire
2009-09-21 17:09 . 2009-09-21 17:09 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.1.8\SetupAdmin.exe
2009-11-19 11:45 . 2009-12-08 01:18 1265664 ----a-w- c:\program files\mozilla firefox\components\JCluyp.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{f6e5180e-0c46-e5c9-9406-a1ccd9357ffb}]
2009-11-19 11:45 1183744 ----a-w- c:\windows\system32\z2b4kwnD4.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-28 152872]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FingerPrintSoftware"="c:\program files\Lenovo Fingerprint Software\fpapp.exe \s" [X]
"PMHandler"="c:\progra~1\Lenovo\PMDRIV~1\PMHandler.exe" [2007-03-16 31840]
"snp2uvc"="c:\windows\vsnp2uvc.exe" [2006-12-29 569344]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-05-19 774233]
"TPFNF7"="c:\program files\Lenovo\NPDIRECT\TPFNF7SP.exe" [2007-04-09 58416]
"TPWAUDAP"="c:\program files\Lenovo\HOTKEY\TpWAudAp.exe" [2006-09-06 54824]
"RTHDCPL"="RTHDCPL.EXE" [2007-08-10 16384000]
"AzMixerSel"="c:\program files\Realtek\Audio\InstallShield\AzMixerSel.exe" [2007-08-23 53248]
"AGRSMMSG"="AGRSMMSG.exe" [2006-08-30 89542]
"TVT Scheduler Proxy"="c:\program files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2008-03-04 487424]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"LPManager"="c:\progra~1\Lenovo\LENOVO~2\LPMGR.exe" [2007-04-26 120368]
"AwaySch"="c:\program files\Lenovo\AwayTask\AwaySch.EXE" [2006-11-07 91688]
"AMSG"="c:\program files\ThinkVantage\AMSG\Amsg.exe" [2007-02-01 439856]
"nmapp"="c:\program files\Pure Networks\Network Magic\nmapp.exe" [2007-03-14 321088]
"DiskeeperSystray"="c:\program files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2006-05-18 196696]
"cssauth"="c:\program files\Lenovo\Client Security Solution\cssauth.exe" [2007-08-03 2630968]
"BDRegion"="c:\program files\Cyberlink\Shared Files\brs.exe" [2007-11-16 91432]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-10-28 72736]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-10-11 62760]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"btbb_McciTrayApp"="c:\program files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe" [2007-11-01 1475072]
"btbb_wcm_McciTrayApp"="c:\program files\BT Broadband Desktop Help\btbb_wcm\McciTrayApp.exe" [2007-11-29 1474048]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-12-11 2043160]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-12-18 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-12-18 178712]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-12-18 150040]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
"ParetoLogic Anti-Virus PLUS"="c:\program files\ParetoLogic\Anti-Virus PLUS\Pareto_AV.exe" [2009-02-18 2659664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]
"RTHDBPL"="c:\documents and settings\Owner\Application Data\SystemProc\lsass.exe" [2009-12-11 59392]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
Bluetooth.lnk - c:\program files\Lenovo\Bluetooth Software\BTTray.exe [2006-11-13 561213]
HallsLogon_Old_New_S.exe [2008-7-4 937984]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ATFUS]
2007-05-31 20:57 155648 ----a-w- c:\windows\system32\FpWinlogonNp.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-03 11:51 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2006-12-14 02:06 28672 ------w- c:\program files\Lenovo\HOTKEY\tphklock.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\utorent.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader
"6112:TCP"= 6112:TCP:Blizzard Downloader
"10622:TCP"= 10622:TCP:WaR1
"8040:TCP"= 8040:TCP:WaR2
"8041:TCP"= 8041:TCP:WaR3
"8042:TCP"= 8042:TCP:WaR4
"8043:TCP"= 8043:TCP:WaR4
"8044:TCP"= 8044:TCP:WaR5
"8045:TCP"= 8045:TCP:WaR6
"8046:TCP"= 8046:TCP:WaR7
"8047:TCP"= 8047:TCP:WaR8
"1024:UDP"= 1024:UDP:WaR10
"65535:UDP"= 65535:UDP:WaR11
"6881:TCP"= 6881:TCP:WaR12
"6882:TCP"= 6882:TCP:WaR13
"6883:TCP"= 6883:TCP:WaR13
"6884:TCP"= 6884:TCP:WaR14
"6885:TCP"= 6885:TCP:WaR15
"6886:TCP"= 6886:TCP:WaR16
"6887:TCP"= 6887:TCP:WaR17
"6888:TCP"= 6888:TCP:WaR18
"6889:TCP"= 6889:TCP:WaR19
"6969:TCP"= 6969:TCP:WaR16
"6881:UDP"= 6881:UDP:WaR20
"6882:UDP"= 6882:UDP:WaR21
"6883:UDP"= 6883:UDP:WaR22
"6884:UDP"= 6884:UDP:WaR23
"6885:UDP"= 6885:UDP:WaR24
"6886:UDP"= 6886:UDP:WaR25
"6887:UDP"= 6887:UDP:WaR26
"6888:UDP"= 6888:UDP:WaR27
"6889:UDP"= 6889:UDP:WaR28
"6969:UDP"= 6969:UDP:WaR29
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [03/08/2009 11:51 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [03/08/2009 11:51 108552]
R1 PMHler;PMHler;c:\windows\system32\drivers\PMHler.sys [24/05/2006 18:48 10240]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [03/08/2009 11:50 297752]
R2 FingerprintServer;Fingerprint Server;c:\windows\system32\FpLogonServ.exe [22/06/2007 18:45 106496]
R2 FNF5SVC;Fn+F5 Service;c:\program files\Lenovo\HOTKEY\FnF5svc.exe [11/05/2007 02:22 54832]
R2 TVT Backup Protection Service;TVT Backup Protection Service;c:\program files\Lenovo\Rescue and Recovery\rrpservice.exe [08/02/2007 20:11 569344]
R2 ZeppelinService;plasservice;c:\program files\Common Files\ParetoLogic\PLAS\plasservice.exe [18/02/2009 14:40 587216]
R3 TVTI2C;Lenovo SM bus driver;c:\windows\system32\drivers\tvti2c.sys [22/05/2007 22:59 30336]
S1 egh15de;egh15de;c:\windows\system32\drivers\egh15de.sys --> c:\windows\system32\drivers\egh15de.sys [?]
S1 eklbcbe;eklbcbe;c:\windows\system32\drivers\eklbcbe.sys --> c:\windows\system32\drivers\eklbcbe.sys [?]
S1 ekmbb2e;ekmbb2e;c:\windows\system32\drivers\ekmbb2e.sys --> c:\windows\system32\drivers\ekmbb2e.sys [?]
S1 fgna207;fgna207;c:\windows\system32\drivers\fgna207.sys --> c:\windows\system32\drivers\fgna207.sys [?]
S1 mnp0fe2;mnp0fe2;c:\windows\system32\drivers\mnp0fe2.sys --> c:\windows\system32\drivers\mnp0fe2.sys [?]
S1 mstd742;mstd742;c:\windows\system32\drivers\mstd742.sys --> c:\windows\system32\drivers\mstd742.sys [?]
S1 oacb548;oacb548;c:\windows\system32\drivers\oacb548.sys --> c:\windows\system32\drivers\oacb548.sys [?]
S1 opr3fc8;opr3fc8;c:\windows\system32\drivers\opr3fc8.sys --> c:\windows\system32\drivers\opr3fc8.sys [?]
S1 pqd9b09;pqd9b09;c:\windows\system32\drivers\pqd9b09.sys --> c:\windows\system32\drivers\pqd9b09.sys [?]
S1 prd95b9;prd95b9;c:\windows\system32\drivers\prd95b9.sys --> c:\windows\system32\drivers\prd95b9.sys [?]
S1 sab45a8;sab45a8;c:\windows\system32\drivers\sab45a8.sys --> c:\windows\system32\drivers\sab45a8.sys [?]
S1 tbh8e29;tbh8e29;c:\windows\system32\drivers\tbh8e29.sys --> c:\windows\system32\drivers\tbh8e29.sys [?]
S3 kbeepm;kbeepm;\??\c:\docume~1\Owner\LOCALS~1\Temp\kbeepm.sys --> c:\docume~1\Owner\LOCALS~1\Temp\kbeepm.sys [?]
.
------- Supplementary Scan -------
.
uStart Page = hxxp://scanyourpc-onlinex.com/pr.cgi?id=2847
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm
IE: {{08E730A4-FB02-45BD-A900-01E4AD8016F6} -
Sky.com - your home for the latest news, sport and entertainment
LSP: c:\windows\system32\INetHTTPFilter.dll
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\truj5vq4.default\
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\Mozilla Firefox\components\JCluyp.dll