Couple of things i noticed after combofix finished. My clock still reads with military time, combofix did not change it back like it said it would. My desktop background is now solid blue but without the stupid "Spyware found...." message on it. A non-shortcut IE desktop icon is now on my desktop (along with my original shortcut icon)...not sure what that's doing there now.
Here are my logs:
ComboFix 08-06-30.2 - Jeff 2008-07-01 19:56:57.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.92 [GMT -7:00]
Running from: C:\Documents and Settings\Jeff\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Jeff\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Administrator\Application Data\rhc75sj0en59
C:\Documents and Settings\Administrator\Application Data\shc55sj0en59
C:\Documents and Settings\All Users\Start Menu\Programs\Malware Protector 2008
C:\Documents and Settings\All Users\Start Menu\Programs\Malware Protector 2008\How to Register Malware Protector 2008.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Malware Protector 2008\License Agreement.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Malware Protector 2008\Malware Protector 2008.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Malware Protector 2008\Register Malware Protector 2008.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Malware Protector 2008\Uninstall.lnk
C:\Documents and Settings\Jeff\Application Data\rhc75sj0en59
C:\Program Files\Common Files\wnsxs~1
C:\Program Files\outerinfo
C:\Program Files\outerinfo\FF\chrome.manifest
C:\Program Files\outerinfo\FF\components\FF.dll
C:\Program Files\outerinfo\FF\components\OuterinfoAds.xpt
C:\Program Files\outerinfo\FF\install.rdf
C:\Program Files\outerinfo\OiUninstaller.exe
C:\Program Files\outerinfo\outerinfo.ico
C:\Program Files\rhc75sj0en59
C:\Program Files\shc55sj0en59
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\temp\tn3
C:\WINDOWS\pskt.ini
C:\WINDOWS\sembly~1
C:\WINDOWS\sembly~1\??sembly\
C:\WINDOWS\sembly~1\nslookup.exe
C:\WINDOWS\stem~1
C:\WINDOWS\stem~1\j?vaw.exe
C:\WINDOWS\system32\4.tmp
C:\WINDOWS\system32\5.tmp
C:\WINDOWS\system32\6.tmp
C:\WINDOWS\system32\7.tmp
C:\WINDOWS\system32\aamhyxrw.dll
C:\WINDOWS\system32\blphc35sj0en59.scr
C:\WINDOWS\system32\coevgycy.ini
C:\WINDOWS\system32\cssrss.exe
C:\WINDOWS\system32\dwstxxjx.ini
C:\WINDOWS\system32\eaxlmrvp.ini
C:\WINDOWS\system32\EKmVyyay.ini
C:\WINDOWS\system32\EKmVyyay.ini2
C:\WINDOWS\system32\evrdbikd.dll
C:\WINDOWS\system32\f10
C:\WINDOWS\system32\fajhxjhw.dll
C:\WINDOWS\system32\folhcmei.dll
C:\WINDOWS\system32\fxhinrsv.dll
C:\WINDOWS\system32\gdphmtrf.dll
C:\WINDOWS\system32\gfvcewss.ini
C:\WINDOWS\system32\gtxnuepy.dll
C:\WINDOWS\system32\hljwugsf.bin
C:\WINDOWS\system32\hpnwtegq.dll
C:\WINDOWS\system32\iemchlof.ini
C:\WINDOWS\system32\lelavtto.dll
C:\WINDOWS\system32\lfbmusby.dll
C:\WINDOWS\system32\ljJBqqNg.dll
C:\WINDOWS\system32\lkhwvpmn.dll
C:\WINDOWS\system32\lphc35sj0en59.exe
C:\WINDOWS\system32\mliyobhr.ini
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\mtfheqcw.dll
C:\WINDOWS\system32\mvghdawp.dll
C:\WINDOWS\system32\nmpvwhkl.ini
C:\WINDOWS\system32\nmxynuxw.dll
C:\WINDOWS\system32\nnnnLfGA.dll
C:\WINDOWS\system32\nnnnNDsp.dll
C:\WINDOWS\system32\omewjeas.dll
C:\WINDOWS\system32\phc35sj0en59.bmp
C:\WINDOWS\system32\phmipyws.dll
C:\WINDOWS\system32\pphc35sj0en59.exe
C:\WINDOWS\system32\psDNnnnn.ini
C:\WINDOWS\system32\psDNnnnn.ini2
C:\WINDOWS\system32\pvrmlxae.dll
C:\WINDOWS\system32\PzaLav.syz
C:\WINDOWS\system32\qgetwnph.ini
C:\WINDOWS\system32\rgmnpsyc.dll
C:\WINDOWS\system32\rhboyilm.dll
C:\WINDOWS\system32\sibakhky.dll
C:\WINDOWS\system32\uypalhmt.dll
C:\WINDOWS\system32\vsrnihxf.ini
C:\WINDOWS\system32\wgcvyryq.dll
C:\WINDOWS\system32\whjxhjaf.ini
C:\WINDOWS\system32\whruihpe.dll
C:\WINDOWS\system32\xjxxtswd.dll
C:\WINDOWS\system32\XzD1sa.syz
C:\WINDOWS\system32\yayyVmKE.dll
C:\WINDOWS\system32\ybsumbfl.ini
C:\WINDOWS\system32\ycygveoc.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SYSREST.SYS
-------\Service_sysrest.sys
((((((((((((((((((((((((( Files Created from 2008-06-02 to 2008-07-02 )))))))))))))))))))))))))))))))
.
2008-07-01 19:43 . 2008-07-01 19:43 106,240 --a------ C:\WINDOWS\system32\qrupsk.dll
2008-07-01 19:43 . 2008-07-01 19:43 106,240 --a------ C:\WINDOWS\system32\jhfaabcc.dll
2008-07-01 17:28 . 2008-07-01 17:28 106,240 --a------ C:\WINDOWS\system32\wvrywrsi.dll
2008-07-01 17:28 . 2008-07-01 17:28 106,240 --a------ C:\WINDOWS\system32\qvvhcl.dll
2008-07-01 15:50 . 2008-07-01 15:50 106,240 --a------ C:\WINDOWS\system32\osfihbjf.dll
2008-07-01 15:50 . 2008-07-01 15:50 106,240 --a------ C:\WINDOWS\system32\dhwmdu.dll
2008-07-01 01:39 . 2008-07-01 01:39 105,904 --a------ C:\WINDOWS\system32\whxjza.dll
2008-07-01 01:39 . 2008-07-01 01:39 105,904 --a------ C:\WINDOWS\system32\ckxseaka.dll
2008-06-30 17:25 . 2008-06-30 17:25 105,872 --a------ C:\WINDOWS\system32\kwffehmh.dll
2008-06-30 17:25 . 2008-06-30 17:25 105,872 --a------ C:\WINDOWS\system32\jdnuuw.dll
2008-06-30 01:34 . 2008-06-30 01:34 105,856 --a------ C:\WINDOWS\system32\uheigqnc.dll
2008-06-30 01:34 . 2008-06-30 01:34 105,856 --a------ C:\WINDOWS\system32\ftbplk.dll
2008-06-29 20:07 . 2008-06-29 20:07 105,856 --a------ C:\WINDOWS\system32\nwjdtxdd.dll
2008-06-29 20:07 . 2008-06-29 20:07 105,856 --a------ C:\WINDOWS\system32\kytrqt.dll
2008-06-29 18:43 . 2008-06-29 18:43 <DIR> d-------- C:\Program Files\AXPFixer
2008-06-29 18:43 . 2008-06-29 18:43 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AXPFixer
2008-06-29 17:28 . 2008-06-29 17:28 105,856 --a------ C:\WINDOWS\system32\xzxhzs.dll
2008-06-29 17:28 . 2008-06-29 17:28 105,856 --a------ C:\WINDOWS\system32\ddthqqqp.dll
2008-06-29 05:39 . 2008-06-29 05:38 23,040 --a------ C:\WINDOWS\system32\sysrest32.exe
2008-06-29 05:39 . 2008-06-29 05:39 15,328 --a------ C:\WINDOWS\system32\sysrest.sys
2008-06-28 21:08 . 2008-06-28 21:08 4,286 --a------ C:\WINDOWS\system32\Jamster.ico
2008-06-28 20:07 . 2008-06-28 20:07 105,968 --a------ C:\WINDOWS\system32\suelqyyg.dll
2008-06-28 20:07 . 2008-06-28 20:07 105,968 --a------ C:\WINDOWS\system32\dyaywf.dll
2008-06-28 18:04 . 2008-06-28 18:04 105,968 --a------ C:\WINDOWS\system32\wzajyn.dll
2008-06-28 18:04 . 2008-06-28 18:04 105,968 --a------ C:\WINDOWS\system32\tldltalj.dll
2008-06-28 17:26 . 2008-06-28 17:26 105,968 --a------ C:\WINDOWS\system32\ohsksgwe.dll
2008-06-28 17:26 . 2008-06-28 17:26 105,968 --a------ C:\WINDOWS\system32\kuiksb.dll
2008-06-26 22:36 . 2008-06-26 22:36 25,520 --a------ C:\WINDOWS\system32\cbXPjIcy.dll
2008-06-26 15:45 . 2008-06-26 15:45 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2008-06-26 15:38 . 2008-06-26 15:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-06-26 15:37 . 2008-06-26 15:37 <DIR> d-------- C:\Documents and Settings\Jeff\Application Data\SUPERAntiSpyware.com
2008-06-26 15:22 . 2008-06-26 15:22 <DIR> d-------- C:\Documents and Settings\Jeff\Application Data\Malwarebytes
2008-06-26 15:22 . 2008-06-26 15:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-26 15:22 . 2008-06-19 17:48 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-26 15:22 . 2008-06-19 17:47 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-26 00:31 . 2008-06-26 00:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-25 23:53 . 2008-06-25 23:53 122,272 --a------ C:\WINDOWS\BM13784573.xml
2008-06-25 16:27 . 2008-06-25 16:27 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2008-06-25 14:38 . 2008-06-26 17:51 9,662 --a------ C:\WINDOWS\system32\ZoneAlarmIconUS.ico
2008-06-25 14:31 . 2008-06-26 07:54 <DIR> d-------- C:\WINDOWS\system32\vec3
2008-06-25 14:31 . 2008-06-26 07:54 <DIR> d-------- C:\WINDOWS\system32\bam
2008-06-25 14:31 . 2008-06-26 07:54 <DIR> d--hs---- C:\WINDOWS\SmVmZiBNZWxsaW5nZXI
2008-06-25 14:27 . 2008-06-25 14:27 <DIR> d-------- C:\WINDOWS\system32\modtrux01
2008-06-10 23:15 . 2008-06-13 06:10 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-10 23:15 . 2008-06-13 06:10 272,128 --a------ C:\WINDOWS\system32\DllCache\bthport.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-02 03:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\DIGStream
2008-06-26 22:37 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-06-26 07:32 --------- d-----w C:\Documents and Settings\Jeff\Application Data\Lavasoft
2008-06-26 07:30 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-26 07:30 --------- d-----w C:\Program Files\Ulead Systems
2008-06-26 07:30 --------- d-----w C:\Program Files\Common Files\Ulead Systems
2008-06-26 07:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ulead Systems
2008-06-26 07:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2008-05-19 08:15 --------- d-----w C:\Documents and Settings\Jeff\Application Data\LimeWire
2008-05-16 18:58 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\DllCache\rmcast.sys
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\DllCache\quartz.dll
2008-04-17 10:46 18,432 ----a-w C:\WINDOWS\system32\DllCache\iedw.exe
2007-03-02 07:10 88,576 ---ha-w C:\Documents and Settings\Jeff\Application Data\rbap550.dll
2007-03-02 07:10 73,728 ---ha-w C:\Documents and Settings\Jeff\Application Data\RBRegEx550.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3EE86D91-2F18-4027-9157-A16110AC59BE}]
2008-06-26 22:36 25520 --a------ C:\WINDOWS\system32\cbXPjIcy.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{40bf4675-4359-468c-80f1-3c1475fff222}]
2008-07-01 19:43 106240 --a------ C:\WINDOWS\system32\qrupsk.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HostManager"="C:\Program Files\Common Files\AOL\1136771408\ee\AOLSoftware.exe" [2006-05-09 17:24 50760]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 00:46 57344]
"DIGStream"="C:\Program Files\DIGStream\digstream.exe" [2005-10-31 12:05 278528]
"DIGServices"="C:\Program Files\ESPNRunTime\DIGServices.exe" [2005-10-31 12:18 101888]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 02:11 132496]
"NeroCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-08 21:50 155648]
"QuickTime Task"="D:\Program Files\QuickTime\qttask.exe" [2006-03-30 14:58 155648]
"Write DVD-R!"="C:\Program Files\Write DVD!\saimon.exe" [2003-07-18 11:34 114688]
"WinampAgent"="F:\Program Files\Winamp\winampa.exe" [2006-05-25 10:35 35328]
"IPHSend"="C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 09:59 124520]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-01-08 17:21 185896]
"AXPFixer"="C:\Program Files\AXPFixer\AXPFixer.exe" [2008-05-19 11:03 1564672]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-01-11 18:45 4898816]
C:\Documents and Settings\Jeff\Start Menu\Programs\Startup\
PowerReg Scheduler.exe [2006-02-09 17:38:05 189952]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 23:05:26 29696]
Microsoft Office.lnk - F:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 13:05:56 65588]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "D:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824]
"{3EE86D91-2F18-4027-9157-A16110AC59BE}"= "C:\WINDOWS\system32\cbXPjIcy.dll" [2008-06-26 22:36 25520]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 13:41 294912 D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cbXPjIcy]
2008-06-26 22:36 25520 C:\WINDOWS\system32\cbXPjIcy.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Common Files\\AOL\\1136771408\\ee\\aolsoftware.exe"=
"C:\\Program Files\\Common Files\\AOL\\1136771408\\ee\\aim6.exe"=
"F:\\StubInstaller.exe"=
"F:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"D:\\Program Files\\Azureus\\Azureus.exe"=
"F:\\Program Files\\eMule\\emule.exe"=
"D:\\Program Files\\Swim TEAM MANAGER Lite 4.0\\TM4.exe"=
"D:\\hy-sport\\SwMM2\\SwimMM2.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
R1 saicdr;saicdr;C:\WINDOWS\system32\drivers\saicdr.sys [2003-07-16 13:20]
R1 saicdrwup;saicdrwup;C:\WINDOWS\system32\drivers\saicdrwup.sys [2003-05-16 14:32]
R1 saiudf;saiudf;C:\WINDOWS\system32\drivers\saiudf.sys [2003-07-09 09:42]
S1 srvv;srvv;C:\WINDOWS\system32\drivers\srvv.sys []
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-lphc35sj0en59 - C:\WINDOWS\system32\lphc35sj0en59.exe
HKLM-Run-SMrhc75sj0en59 - C:\Program Files\rhc75sj0en59\rhc75sj0en59.exe
HKLM-Run-SMshc55sj0en59 - C:\Program Files\shc55sj0en59\shc55sj0en59.exe
HKLM-Run-104b76ef - C:\WINDOWS\system32\lkhwvpmn.dll
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-07-01 20:10:39
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\cbXPjIcy.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
F:\Program Files\Lavasoft\aawservice.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\WgaTray.exe
.
**************************************************************************
.
Completion time: 2008-07-01 20:14:31 - machine was rebooted [Administrator]
ComboFix-quarantined-files.txt 2008-07-02 03:14:21
Pre-Run: 126,005,248 bytes free
Post-Run: 88,514,560 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
F:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
263 --- E O F --- 2008-06-22 10:00:38
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:17, on 2008-07-01
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
F:\Program Files\Lavasoft\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\AOL\1136771408\ee\AOLSoftware.exe
C:\Program Files\DIGStream\digstream.exe
C:\Program Files\ESPNRunTime\DIGServices.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
D:\Program Files\QuickTime\qttask.exe
C:\Program Files\Write DVD!\saimon.exe
F:\Program Files\Winamp\winampa.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\AXPFixer\AXPFixer.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\msiexec.exe
F:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.espn.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896N3 - Netscape 7: user_pref("browser.startup.homepage", "www.google.com"); (C:\Documents and Settings\JEFF\Application Data\Mozilla\Profiles\default\3gg5fsiq.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\JEFF\Application Data\Mozilla\Profiles\default\3gg5fsiq.slt\prefs.js)
O2 - BHO: (no name) - {3EE86D91-2F18-4027-9157-A16110AC59BE} - C:\WINDOWS\system32\cbXPjIcy.dll
O2 - BHO: {222fff57-41c3-1f08-c864-95345764fb04} - {40bf4675-4359-468c-80f1-3c1475fff222} - C:\WINDOWS\system32\qrupsk.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1136771408\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [DIGServices] C:\Program Files\ESPNRunTime\DIGServices.exe /brand=ESPN /priority=0 /poll=24
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Write DVD-R!] C:\Program Files\Write DVD!\saimon.exe
O4 - HKLM\..\Run: [WinampAgent] F:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AXPFixer] C:\Program Files\AXPFixer\AXPFixer.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [Wjqq] C:\WINDOWS\??stem\j?vaw.exe
O4 - HKCU\..\Run: [Eaos] "C:\WINDOWS\SEMBLY~1\nslookup.exe" -vt ndrv
O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlhr] RunDll32.exe %SystemRoot%\System32\AdvPack.Dll,LaunchINFSection %SystemRoot%\inf\nlite.inf,C (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'Default user')
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = F:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {C68F9105-04FD-4B48-B6CC-2A076F711C35} (HpodPCFileCtrl2 Class) - file://H:\MEMDISC\ALBUM_A\VIEW\PLUGIN\HPODPCFC.CAB
O20 - Winlogon Notify: !SASWinLogon - D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: cbXPjIcy - C:\WINDOWS\SYSTEM32\cbXPjIcy.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - F:\Program Files\Lavasoft\aawservice.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
--
End of file - 6487 bytes