Whirlwind
Fully Optimized
- Messages
- 2,400
Having some trouble....spyware protect 2009 pops up.. XP SP3.....here is my highjack this log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:45:32 AM, on 4/11/2009
Platform: Windows XP SP3 (WinNT
5.01.2600)
MSIE: Internet Explorer v8.00
(8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\runservice.exe
C:\Program Files\Common Files\Symantec
Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F22
7FCA9A08}\PIFSvc.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.
exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcpr
oxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\Explorer.EXE
C:\Program
Files\ASUS\AASP\1.00.12\aaCenter.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Common Files\Microsoft
Shared\Works Shared\WkUFind.exe
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\Program
Files\Razer\Copperhead\razerhid.exe
C:\Program Files\Common Files\Symantec
Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F22
7FCA9A08}\PIFSvc.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program
Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program
Files\Razer\Copperhead\razerofa.exe
C:\WINDOWS\sysguard.exe
C:\Program Files\Common Files\Microsoft
Shared\Works Shared\wkcalrem.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program
Files\Yahoo!\browser\ybrowser.exe
C:\Program Files\Trend
Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Default_Page_URL =
http://att.net
R0 - HKCU\Software\Microsoft\Internet
Explorer\Main,Start Page =
http://att.net
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Page_URL =
Amazon.com: Online Shopping for Electronics, Apparel, Computers, Books, DVDs & more
9157
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Search_URL =
Search Microsoft.com
4896
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Search Page =
Search Microsoft.com
4896
R0 - HKLM\Software\Microsoft\Internet
Explorer\Main,Start Page =
Amazon.com: Online Shopping for Electronics, Apparel, Computers, Books, DVDs & more
9157
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,First Home Page =
http://downloads.yahoo.com/p/att/ie/welc
ome
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Window Title = Windows
Internet Explorer provided by Yahoo!
R1 -
HKCU\Software\Microsoft\Windows\CurrentV
ersion\Internet Settings,ProxyOverride =
127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar -
{EF99BD32-C1FB-11D2-892F-0090271D4F88} -
C:\Program
Files\Yahoo!\Common\Companion\Installs\c
pn0\yt.dll
F2 - REG:system.ini:
UserInit=userinit.exe,C:\WINDOWS\system3
2\sdra64.exe,
O2 - BHO: Yahoo! Toolbar Helper -
{02478D38-C3F9-4EFB-9B51-7695ECA05670} -
C:\Program
Files\Yahoo!\Common\Companion\Installs\c
pn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper -
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:\Program Files\Adobe\Acrobat
7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button -
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} -
C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O2 - BHO: scriptproxy -
{7DB2D5A0-7241-4E79-B68D-6309F01C5231} -
C:\Program
Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper
- {DBC80044-A445-435b-BC74-9C25C1C588A9}
- C:\Program
Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl -
{E7E6F031-17CE-4C07-BC86-EABFE594F69C} -
C:\Program
Files\Java\jre6\lib\deploy\jqs\ie\jqs_pl
ugin.dll
O2 - BHO: SidebarAutoLaunch Class -
{F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} -
C:\Program
Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Yahoo! Toolbar -
{EF99BD32-C1FB-11D2-892F-0090271D4F88} -
C:\Program
Files\Yahoo!\Common\Companion\Installs\c
pn0\yt.dll
O3 - Toolbar: Easy-WebPrint -
{327C2873-E90D-4c37-AA9D-10AC9BABA46C} -
C:\Program
Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [SoundMAX] "C:\Program
Files\Analog Devices\SoundMAX\Smax4.exe"
/tray
O4 - HKLM\..\Run: [AsusServiceProvider]
C:\Program
Files\ASUS\AASP\1.00.12\aaCenter.exe
O4 - HKLM\..\Run: [AsusStartupHelp]
C:\Program
Files\ASUS\AASP\1.00.12\AsRunHelp.exe
O4 - HKLM\..\Run: [Launch Ai Booster]
"C:\Program Files\ASUS\AI
Booster\OverClk.exe"
O4 - HKLM\..\Run: [YBrowser]
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [IPInSightMonitor 01]
"C:\Program Files\SBC Yahoo!\Connection
Manager\IP InSight\IPMon32.exe"
O4 - HKLM\..\Run: [WorksFUD] C:\Program
Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works
Portfolio] C:\Program Files\Microsoft
Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works
Update Detection] C:\Program
Files\Common Files\Microsoft
Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [CTHelper]
CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp]
CTXFIHLP.EXE
O4 - HKLM\..\Run: [UpdReg]
C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [razer] C:\Program
Files\Razer\Copperhead\razerhid.exe
O4 - HKLM\..\Run: [Symantec PIF
AlertEng] "C:\Program Files\Common
Files\Symantec
Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F22
7FCA9A08}\PIFSvc.exe" /a /m "C:\Program
Files\Common Files\Symantec
Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F22
7FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [mcagent_exe]
C:\Program
Files\McAfee.com\Agent\mcagent.exe
/runkey
O4 - HKLM\..\Run: [NvCplDaemon]
RUNDLL32.EXE
C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe
/install
O4 - HKLM\..\Run: [NvMediaCenter]
RUNDLL32.EXE
C:\WINDOWS\system32\NvMcTray.dll,NvTaskb
arInit
O4 - HKLM\..\Run: [SunJavaUpdateSched]
"C:\Program
Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Opelawajurijaf]
rundll32.exe "C:\WINDOWS\uboyerez.dll",e
O4 - HKCU\..\Run: [ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager]
"C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EX
E" -quiet
O4 - HKCU\..\Run: [DDC]
C:\WINDOWS\system32\apmjwttv.exe
O4 - HKCU\..\Run: [updateMgr]
"C:\Program Files\Adobe\Acrobat
7.0\Reader\AdobeUpdateManager.exe"
AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [system tool]
C:\WINDOWS\sysguard.exe
O4 - Global Startup: Adobe Reader Speed
Launch.lnk = C:\Program
Files\Adobe\Acrobat
7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft
Office.lnk = C:\Program Files\Microsoft
Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Works
Calendar Reminders.lnk = ?
O9 - Extra button: AT&T Yahoo! Services
- {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}
- C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: ICQ Lite -
{B863453A-26C3-4e1f-A54D-A2CD196348E9} -
F:\Program Files\ICQLite\ICQLite.exe
(file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite -
{B863453A-26C3-4e1f-A54D-A2CD196348E9} -
F:\Program Files\ICQLite\ICQLite.exe
(file missing)
O9 - Extra button: (no name) -
{e2e2dd38-d088-4134-82b7-f2ba38496583} -
C:\WINDOWS\Network
Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem:
@xpsp3res.dll,-20001 -
{e2e2dd38-d088-4134-82b7-f2ba38496583} -
C:\WINDOWS\Network
Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 -
{E59EB121-F339-4851-A3BA-FE49C35617C2} -
F:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 -
{E59EB121-F339-4851-A3BA-FE49C35617C2} -
F:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows
Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O16 - DPF:
{30528230-99f7-4bb4-88d8-fa1d4f56a2ab}
(Installation Support) - C:\Program
Files\Yahoo!\Common\Yinsthelper20073151.
dll
O16 - DPF:
{D18F962A-3722-4B59-B08D-28BB9EB2281E}
(PhotosCtrl Class) -
http://photos.yahoo.com/ocx/us/yexplorer
1_9us.cab
O16 - DPF:
{F6ACF75C-C32C-447B-9BEF-46B766368D29}
(Creative Software AutoUpdate Support
Package) -
http://www.creative.com/su2/CTL_V02002/o
cx/15033/CTPID.cab
O23 - Service: Automatic LiveUpdate
Scheduler - Unknown owner - C:\Program
Files\Symantec\LiveUpdate\ALUSchedulerSv
c.exe (file missing)
O23 - Service: InstallDriver Table
Manager (IDriverT) - Macrovision
Corporation - C:\Program Files\Common
Files\InstallShield\Driver\11\Intel
32\IDriverT.exe
O23 - Service: Java Quick Starter
(JavaQuickStarterService) - Sun
Microsystems, Inc. - C:\Program
Files\Java\jre6\bin\jqs.exe
O23 - Service: LicCtrl Service
(LicCtrlService) - Unknown owner -
C:\WINDOWS\runservice.exe
O23 - Service: LiveUpdate - Unknown
owner -
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.E
XE (file missing)
O23 - Service: LiveUpdate Notice Service
Ex (LiveUpdate Notice Ex) - Unknown
owner - C:\Program Files\Common
Files\Symantec Shared\ccSvcHst.exe (file
missing)
O23 - Service: LiveUpdate Notice Service
- Symantec Corporation - C:\Program
Files\Common Files\Symantec
Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F22
7FCA9A08}\PIFSvc.exe
O23 - Service: McAfee Services
(mcmscsvc) - McAfee, Inc. -
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent
(McNASvc) - McAfee, Inc. -
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.
exe
O23 - Service: McAfee Scanner (McODS) -
McAfee, Inc. -
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service
(McProxy) - McAfee, Inc. -
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcpr
oxy.exe
O23 - Service: McAfee Real-time Scanner
(McShield) - McAfee, Inc. -
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards
(McSysmon) - McAfee, Inc. -
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall
Service (MpfService) - McAfee, Inc. -
C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NVIDIA Display Driver
Service (NVSvc) - NVIDIA Corporation -
C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner
- C:\WINDOWS\system32\PnkBstrA.exe
--
End of file - 10191 bytes
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:45:32 AM, on 4/11/2009
Platform: Windows XP SP3 (WinNT
5.01.2600)
MSIE: Internet Explorer v8.00
(8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\runservice.exe
C:\Program Files\Common Files\Symantec
Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F22
7FCA9A08}\PIFSvc.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.
exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcpr
oxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\Explorer.EXE
C:\Program
Files\ASUS\AASP\1.00.12\aaCenter.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Common Files\Microsoft
Shared\Works Shared\WkUFind.exe
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\Program
Files\Razer\Copperhead\razerhid.exe
C:\Program Files\Common Files\Symantec
Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F22
7FCA9A08}\PIFSvc.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program
Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program
Files\Razer\Copperhead\razerofa.exe
C:\WINDOWS\sysguard.exe
C:\Program Files\Common Files\Microsoft
Shared\Works Shared\wkcalrem.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program
Files\Yahoo!\browser\ybrowser.exe
C:\Program Files\Trend
Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Default_Page_URL =
http://att.net
R0 - HKCU\Software\Microsoft\Internet
Explorer\Main,Start Page =
http://att.net
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Page_URL =
Amazon.com: Online Shopping for Electronics, Apparel, Computers, Books, DVDs & more
9157
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Search_URL =
Search Microsoft.com
4896
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Search Page =
Search Microsoft.com
4896
R0 - HKLM\Software\Microsoft\Internet
Explorer\Main,Start Page =
Amazon.com: Online Shopping for Electronics, Apparel, Computers, Books, DVDs & more
9157
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,First Home Page =
http://downloads.yahoo.com/p/att/ie/welc
ome
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Window Title = Windows
Internet Explorer provided by Yahoo!
R1 -
HKCU\Software\Microsoft\Windows\CurrentV
ersion\Internet Settings,ProxyOverride =
127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar -
{EF99BD32-C1FB-11D2-892F-0090271D4F88} -
C:\Program
Files\Yahoo!\Common\Companion\Installs\c
pn0\yt.dll
F2 - REG:system.ini:
UserInit=userinit.exe,C:\WINDOWS\system3
2\sdra64.exe,
O2 - BHO: Yahoo! Toolbar Helper -
{02478D38-C3F9-4EFB-9B51-7695ECA05670} -
C:\Program
Files\Yahoo!\Common\Companion\Installs\c
pn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper -
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:\Program Files\Adobe\Acrobat
7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button -
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} -
C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O2 - BHO: scriptproxy -
{7DB2D5A0-7241-4E79-B68D-6309F01C5231} -
C:\Program
Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper
- {DBC80044-A445-435b-BC74-9C25C1C588A9}
- C:\Program
Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl -
{E7E6F031-17CE-4C07-BC86-EABFE594F69C} -
C:\Program
Files\Java\jre6\lib\deploy\jqs\ie\jqs_pl
ugin.dll
O2 - BHO: SidebarAutoLaunch Class -
{F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} -
C:\Program
Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Yahoo! Toolbar -
{EF99BD32-C1FB-11D2-892F-0090271D4F88} -
C:\Program
Files\Yahoo!\Common\Companion\Installs\c
pn0\yt.dll
O3 - Toolbar: Easy-WebPrint -
{327C2873-E90D-4c37-AA9D-10AC9BABA46C} -
C:\Program
Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [SoundMAX] "C:\Program
Files\Analog Devices\SoundMAX\Smax4.exe"
/tray
O4 - HKLM\..\Run: [AsusServiceProvider]
C:\Program
Files\ASUS\AASP\1.00.12\aaCenter.exe
O4 - HKLM\..\Run: [AsusStartupHelp]
C:\Program
Files\ASUS\AASP\1.00.12\AsRunHelp.exe
O4 - HKLM\..\Run: [Launch Ai Booster]
"C:\Program Files\ASUS\AI
Booster\OverClk.exe"
O4 - HKLM\..\Run: [YBrowser]
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [IPInSightMonitor 01]
"C:\Program Files\SBC Yahoo!\Connection
Manager\IP InSight\IPMon32.exe"
O4 - HKLM\..\Run: [WorksFUD] C:\Program
Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works
Portfolio] C:\Program Files\Microsoft
Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works
Update Detection] C:\Program
Files\Common Files\Microsoft
Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [CTHelper]
CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp]
CTXFIHLP.EXE
O4 - HKLM\..\Run: [UpdReg]
C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [razer] C:\Program
Files\Razer\Copperhead\razerhid.exe
O4 - HKLM\..\Run: [Symantec PIF
AlertEng] "C:\Program Files\Common
Files\Symantec
Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F22
7FCA9A08}\PIFSvc.exe" /a /m "C:\Program
Files\Common Files\Symantec
Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F22
7FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [mcagent_exe]
C:\Program
Files\McAfee.com\Agent\mcagent.exe
/runkey
O4 - HKLM\..\Run: [NvCplDaemon]
RUNDLL32.EXE
C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe
/install
O4 - HKLM\..\Run: [NvMediaCenter]
RUNDLL32.EXE
C:\WINDOWS\system32\NvMcTray.dll,NvTaskb
arInit
O4 - HKLM\..\Run: [SunJavaUpdateSched]
"C:\Program
Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Opelawajurijaf]
rundll32.exe "C:\WINDOWS\uboyerez.dll",e
O4 - HKCU\..\Run: [ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager]
"C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EX
E" -quiet
O4 - HKCU\..\Run: [DDC]
C:\WINDOWS\system32\apmjwttv.exe
O4 - HKCU\..\Run: [updateMgr]
"C:\Program Files\Adobe\Acrobat
7.0\Reader\AdobeUpdateManager.exe"
AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [system tool]
C:\WINDOWS\sysguard.exe
O4 - Global Startup: Adobe Reader Speed
Launch.lnk = C:\Program
Files\Adobe\Acrobat
7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft
Office.lnk = C:\Program Files\Microsoft
Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Works
Calendar Reminders.lnk = ?
O9 - Extra button: AT&T Yahoo! Services
- {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}
- C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: ICQ Lite -
{B863453A-26C3-4e1f-A54D-A2CD196348E9} -
F:\Program Files\ICQLite\ICQLite.exe
(file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite -
{B863453A-26C3-4e1f-A54D-A2CD196348E9} -
F:\Program Files\ICQLite\ICQLite.exe
(file missing)
O9 - Extra button: (no name) -
{e2e2dd38-d088-4134-82b7-f2ba38496583} -
C:\WINDOWS\Network
Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem:
@xpsp3res.dll,-20001 -
{e2e2dd38-d088-4134-82b7-f2ba38496583} -
C:\WINDOWS\Network
Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 -
{E59EB121-F339-4851-A3BA-FE49C35617C2} -
F:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 -
{E59EB121-F339-4851-A3BA-FE49C35617C2} -
F:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows
Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O16 - DPF:
{30528230-99f7-4bb4-88d8-fa1d4f56a2ab}
(Installation Support) - C:\Program
Files\Yahoo!\Common\Yinsthelper20073151.
dll
O16 - DPF:
{D18F962A-3722-4B59-B08D-28BB9EB2281E}
(PhotosCtrl Class) -
http://photos.yahoo.com/ocx/us/yexplorer
1_9us.cab
O16 - DPF:
{F6ACF75C-C32C-447B-9BEF-46B766368D29}
(Creative Software AutoUpdate Support
Package) -
http://www.creative.com/su2/CTL_V02002/o
cx/15033/CTPID.cab
O23 - Service: Automatic LiveUpdate
Scheduler - Unknown owner - C:\Program
Files\Symantec\LiveUpdate\ALUSchedulerSv
c.exe (file missing)
O23 - Service: InstallDriver Table
Manager (IDriverT) - Macrovision
Corporation - C:\Program Files\Common
Files\InstallShield\Driver\11\Intel
32\IDriverT.exe
O23 - Service: Java Quick Starter
(JavaQuickStarterService) - Sun
Microsystems, Inc. - C:\Program
Files\Java\jre6\bin\jqs.exe
O23 - Service: LicCtrl Service
(LicCtrlService) - Unknown owner -
C:\WINDOWS\runservice.exe
O23 - Service: LiveUpdate - Unknown
owner -
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.E
XE (file missing)
O23 - Service: LiveUpdate Notice Service
Ex (LiveUpdate Notice Ex) - Unknown
owner - C:\Program Files\Common
Files\Symantec Shared\ccSvcHst.exe (file
missing)
O23 - Service: LiveUpdate Notice Service
- Symantec Corporation - C:\Program
Files\Common Files\Symantec
Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F22
7FCA9A08}\PIFSvc.exe
O23 - Service: McAfee Services
(mcmscsvc) - McAfee, Inc. -
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent
(McNASvc) - McAfee, Inc. -
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.
exe
O23 - Service: McAfee Scanner (McODS) -
McAfee, Inc. -
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service
(McProxy) - McAfee, Inc. -
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcpr
oxy.exe
O23 - Service: McAfee Real-time Scanner
(McShield) - McAfee, Inc. -
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards
(McSysmon) - McAfee, Inc. -
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall
Service (MpfService) - McAfee, Inc. -
C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NVIDIA Display Driver
Service (NVSvc) - NVIDIA Corporation -
C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner
- C:\WINDOWS\system32\PnkBstrA.exe
--
End of file - 10191 bytes