Hi RichieUK,
Thanks again for the quick response! I went ahead and ran everything as you said. I did notice after running SDFix that my USB keys no longer worked on that computer, which seems odd. For now I'm using a CD-RW that appears to be working fine. I was skimming through the log files and I should probably mention that I did do a couple registry edits myself prior to posting here. The main one I recall was doing a search in the registry for that .exe process i mentioned earlier (think it was vvgeowbv.exe) and found that some Userinit keys had been altered. I ended up erasing the second half of the string entered because it appeared to be altered to run that exe file instead of the normal userinit. I may not be able to respond tomorrow, but I'll check for a reply and post back as soon as I can. Anyway, here are my log files:
SDFIX (Report.txt):
SDFix: Version 1.113
Run by Abe on Tue 11/06/2007 at 11:15 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Name:
noskrnl
ImagePath:
\??\C:\WINDOWS\System32\noskrnl.sys
noskrnl - Deleted
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
No Trojan Files Found
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
catchme 0.3.1253 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-06 23:19:01
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\3\x00ffC\xffH\xffO\xffO\xffL\xffW0\x01920c0u0\x20390\0020]
"SlowInfoCache"=hex:28,02,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,00,00,00,00,..
"Changed"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\3\x00ffC\xffH\xffO\xffO\xffL\xffW0\x01920c0u0\x20390\0020]
"DisplayName"="\xff33\xff43\xff48\xff4f\xff4f\xff4c\x3057\x3083\x3063\x3075\x308b\x3002"
"UninstallString"=""P:\Program Files\\xff33\xff43\xff48\xff4f\xff4fl2\epuninst.exe" /s"
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\\tgI\x201eh0\ta\xeb_j0\xf2N\x201c\x2022_0a0]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\3\x00ffC\xffH\xffO\xffO\xffL\xffW0\x01920c0u0\x20390\0020]
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services:
------------------
Authorized Application Key Export:
Remaining Files:
---------------
Files with Hidden Attributes:
Mon 4 Sep 2006 199 A.SH. --- "C:\BOOT.BAK"
Tue 17 Aug 2004 0 A..H. --- "C:\Program Files\Windows Media Player\npdrmv6.dll"
Tue 17 Aug 2004 0 A..H. --- "C:\Program Files\Windows Media Player\npdrmv7.dll"
Tue 12 Oct 2004 1,056 A.SH. --- "C:\WINDOWS\system32\KGyGaAvL.sys"
Sun 21 Aug 2005 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Sat 6 Dec 2003 24,576 ...H. --- "C:\Documents and Settings\Abe\Application Data\Microsoft\Word\~WRL0004.tmp"
Sat 6 Dec 2003 23,552 ...H. --- "C:\Documents and Settings\Abe\Application Data\Microsoft\Word\~WRL0062.tmp"
Sat 6 Dec 2003 19,456 ...H. --- "C:\Documents and Settings\Abe\Application Data\Microsoft\Word\~WRL0427.tmp"
Sat 6 Dec 2003 19,456 ...H. --- "C:\Documents and Settings\Abe\Application Data\Microsoft\Word\~WRL0475.tmp"
Sat 6 Dec 2003 26,112 ...H. --- "C:\Documents and Settings\Abe\Application Data\Microsoft\Word\~WRL0532.tmp"
Tue 4 Apr 2006 23,040 ...H. --- "C:\Documents and Settings\Abe\Application Data\Microsoft\Word\~WRL0567.tmp"
Sat 6 Dec 2003 24,576 ...H. --- "C:\Documents and Settings\Abe\Application Data\Microsoft\Word\~WRL1068.tmp"
Sat 6 Dec 2003 23,552 ...H. --- "C:\Documents and Settings\Abe\Application Data\Microsoft\Word\~WRL1419.tmp"
Sat 21 May 2005 23,040 ...H. --- "C:\Documents and Settings\Abe\Application Data\Microsoft\Word\~WRL1484.tmp"
Sat 21 May 2005 23,552 ...H. --- "C:\Documents and Settings\Abe\Application Data\Microsoft\Word\~WRL1554.tmp"
Tue 9 May 2006 23,040 ...H. --- "C:\Documents and Settings\Abe\Application Data\Microsoft\Word\~WRL1589.tmp"
Sat 6 Dec 2003 24,576 ...H. --- "C:\Documents and Settings\Abe\Application Data\Microsoft\Word\~WRL1610.tmp"
Sat 21 May 2005 32,768 ...H. --- "C:\Documents and Settings\Abe\Application Data\Microsoft\Word\~WRL1787.tmp"
Tue 9 May 2006 22,528 ...H. --- "C:\Documents and Settings\Abe\Application Data\Microsoft\Word\~WRL1818.tmp"
Sat 6 Dec 2003 26,112 ...H. --- "C:\Documents and Settings\Abe\Application Data\Microsoft\Word\~WRL1842.tmp"
Sat 21 May 2005 30,208 ...H. --- "C:\Documents and Settings\Abe\Application Data\Microsoft\Word\~WRL1974.tmp"
Tue 9 May 2006 22,016 ...H. --- "C:\Documents and Settings\Abe\Application Data\Microsoft\Word\~WRL2202.tmp"
Sat 6 Dec 2003 24,576 ...H. --- "C:\Documents and Settings\Abe\Application Data\Microsoft\Word\~WRL2666.tmp"
Sat 6 Dec 2003 20,992 ...H. --- "C:\Documents and Settings\Abe\Application Data\Microsoft\Word\~WRL2798.tmp"
Thu 16 Mar 2006 22,528 ...H. --- "C:\Documents and Settings\Abe\Application Data\Microsoft\Word\~WRL2881.tmp"
Sat 6 Dec 2003 24,576 ...H. --- "C:\Documents and Settings\Abe\Application Data\Microsoft\Word\~WRL3007.tmp"
Sat 21 May 2005 24,064 ...H. --- "C:\Documents and Settings\Abe\Application Data\Microsoft\Word\~WRL3058.tmp"
Tue 4 Apr 2006 23,040 ...H. --- "C:\Documents and Settings\Abe\Application Data\Microsoft\Word\~WRL3160.tmp"
Sat 6 Dec 2003 20,480 ...H. --- "C:\Documents and Settings\Abe\Application Data\Microsoft\Word\~WRL3609.tmp"
Thu 16 Mar 2006 23,552 ...H. --- "C:\Documents and Settings\Abe\Application Data\Microsoft\Word\~WRL3868.tmp"
Sat 21 May 2005 23,552 ...H. --- "C:\Documents and Settings\Abe\Application Data\Microsoft\Word\~WRL4039.tmp"
Finished!
ComboFix (ComboFix.txt):
ComboFix 07-11-07.3 - Abe 2007-11-06 23:44:28.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.1.1252.1.1033.18.800 [GMT -8:00]
Running from: C:\Documents and Settings\Abe\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\grouppolicy\machine\scripts\scripts.ini
.
((((((((((((((((((((((((( Files Created from 2007-10-07 to 2007-11-07 )))))))))))))))))))))))))))))))
.
2007-11-06 23:43 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-06 23:14 <DIR> d-------- C:\WINDOWS\ERUNT
2007-11-04 20:15 <DIR> d-------- C:\HJT
2007-10-12 14:39 <DIR> d-------- C:\Program Files\Game On
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-07 07:13 --------- d-----w C:\Documents and Settings\Abe\Application Data\U3
2007-11-04 07:27 --------- d-----w C:\Program Files\Symantec
2007-11-04 07:27 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-11-04 07:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2007-11-03 18:43 --------- d-----w C:\Program Files\Microsoft IntelliPoint 5.0
2007-11-03 18:43 --------- d-----w C:\Program Files\ImgBurn
2007-11-03 18:43 --------- d-----w C:\Program Files\hkSFV
2007-11-03 18:43 --------- d-----w C:\Program Files\Google
2007-11-03 18:43 --------- d-----w C:\Program Files\DVDFab HD Decrypter 3
2007-11-03 18:43 --------- d-----w C:\Program Files\DVD Shrink
2007-11-03 18:43 --------- d-----w C:\Program Files\DVD Genie
2007-11-03 18:43 --------- d-----w C:\Program Files\DVD Decrypter
2007-11-03 18:43 --------- d-----w C:\Program Files\DivX_311alpha
2007-11-03 18:43 --------- d-----w C:\Program Files\DivX
2007-11-03 18:43 --------- d-----w C:\Program Files\Common Files\Raxco
2007-11-03 18:43 --------- d-----w C:\Program Files\Combined Community Codec Pack
2007-11-03 18:43 --------- d-----w C:\Program Files\Blighty Design
2007-11-03 18:43 --------- d-----w C:\Program Files\Azureus
2007-11-03 18:43 --------- d-----w C:\Program Files\AviSynth 2.5
2007-11-03 18:34 --------- d-----w C:\Program Files\Avi2Dvd
2007-09-30 09:43 --------- d-----w C:\Documents and Settings\Abe\Application Data\Azureus
2007-09-19 05:24 --------- d-----w C:\Program Files\Real Alternative
2007-08-13 00:49 720,896 ----a-w C:\WINDOWS\iun6002ev.exe
2006-03-13 02:07 24,192 ----a-w C:\Documents and Settings\Abe\usbsermptxp.sys
2006-03-13 02:07 22,768 ----a-w C:\Documents and Settings\Abe\usbsermpt.sys
2005-05-12 21:37 242,176 ----a-w C:\Documents and Settings\Abe\in_cue.dll
2005-03-26 04:47 4,608 ----a-w C:\Documents and Settings\Abe\gen_cue.dll
2004-02-09 17:29 216 ----a-w C:\Program Files\INSTALL.LOG
2004-10-13 06:42:26 1,056 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{029e02f0-a0e5-4b19-b958-7bf2db29fb13}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54645654-2225-4455-44A1-9F4543D34546}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6abc861a-31e7-4d91-b43b-d3c98f22a5c0}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{944864a5-3916-46e2-96a9-a2e84f3f1208}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a4a435cf-3583-11d4-91bd-0048546a1450}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c2680e10-1655-4a0e-87f8-4259325a84b7}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c4ca6559-2cf1-48b6-96b2-8340a06fd129}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d8efadf1-9009-11d6-8c73-608c5dc19089}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9147a0a-a866-4214-b47c-da821891240f}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9306072-417e-43e3-81d5-369490beef7c}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2003-03-31 04:00]
"PHIME2002ASync"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [2003-03-31 04:00]
"PHIME2002A"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [2003-03-31 04:00]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50]
"RegKillElbyCheck"="P:\Program Files\Elaborate Bytes\DVD Region Killer\ElbyCheck.exe" [2002-11-01 22:33]
"NetLimiter"="P:\Program Files\NetLimiter\NetLimiter.exe" [2004-09-10 23:53]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2004-10-29 16:50]
"nwiz"="nwiz.exe" [2004-10-29 16:50 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2004-10-29 16:50]
"razer"="C:\Program Files\Razer\razerhid.exe" [2005-05-17 17:21]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-07-12 01:30]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="" []
"SpySweeper"="P:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" [2004-02-25 11:48]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45]
C:\Documents and Settings\Abe\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 18:16:50]
trillian.lnk - P:\Program Files\Trillian\trillian.exe [2004-06-23 23:00:00]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
DMX 6fire 2496 ControlPanel.lnk - C:\Program Files\TerraTec\DMX 6fire\DMX6Fire.exe [2004-01-30 21:49:05]
Kirby Alarm.lnk - P:\Program Files\Kirby Alarm\kirbyalarm.exe [2004-01-21 04:25:54]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ShowSuperHidden"=1 (0x1)
"AllowLegacyWebView"=1 (0x1)
"AllowUnhashedWebView"=1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Abe^Start Menu^Programs^Startup^Microsoft Find Fast.lnk]
path=C:\Documents and Settings\Abe\Start Menu\Programs\Startup\Microsoft Find Fast.lnk
backup=C:\WINDOWS\pss\Microsoft Find Fast.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Abe^Start Menu^Programs^Startup^Office Startup.lnk]
path=C:\Documents and Settings\Abe\Start Menu\Programs\Startup\Office Startup.lnk
backup=C:\WINDOWS\pss\Office Startup.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^MSWin.exe]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MSWin.exe
backup=C:\WINDOWS\pss\MSWin.exeCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
R0 Defrag32b;Defrag32Boot;C:\WINDOWS\System32\drivers\Defrag32b.sys
R0 Si3112r;Silicon Image SiI 3112 SATARaid Controller;C:\WINDOWS\System32\DRIVERS\si3112r.sys
R0 sojubus;sojubus;C:\WINDOWS\System32\DRIVERS\sojubus.sys
R0 sojuscsi;sojuscsi;C:\WINDOWS\System32\DRIVERS\sojuscsi.sys
R1 Asapi;Asapi;C:\WINDOWS\System32\drivers\Asapi.sys
R1 NPPTNT;NPPTNT;\??\C:\WINDOWS\System32\npptNT.sys
R1 tvtool;tvtool;\??\P:\Program Files\TVTool\tvtool.sys
R2 Defrag32;Defrag32;C:\WINDOWS\System32\drivers\Defrag32.sys
R3 dmxfire;DMX6fire WDM Audio;C:\WINDOWS\System32\drivers\dmx6fire.sys
R3 dmxsens;dmxsens;C:\WINDOWS\System32\drivers\dmxsens.sys
R3 RegKill;RegKill;C:\WINDOWS\System32\Drivers\RegKill.sys
S0 DigiFilter;DigiFilter;C:\WINDOWS\System32\drivers\DigiFilt.sys
S2 DigiNet;Digidesign Ethernet Support;C:\WINDOWS\System32\DRIVERS\diginet.sys
S2 PDSched;PDScheduler;C:\Program Files\Raxco\PerfectDisk\PDSched.exe
S3 Bulk503;Chameleon Mega Digital Camera;C:\WINDOWS\System32\Drivers\Bulk503.sys
S3 Ip6FwHlp;IPv6 Internet Connection Firewall;C:\WINDOWS\System32\svchost.exe -k netsvcs
S3 ISO503;Chameleon Mega Video Camera;C:\WINDOWS\System32\Drivers\ISO503.SYS
S3 ngrpci;NETGEAR FA310TX Fast Ethernet Adapter Driver;C:\WINDOWS\System32\DRIVERS\ngrpci.sys
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\System32\drivers\npf.sys
S3 Razerlow;Razerlow USB Filter Driver;C:\WINDOWS\System32\Drivers\Razerlow.sys
S3 RivaTunerEx;RivaTunerEx;\??\C:\Program Files\RivaTuner\RivaTunerEx.sys
S3 SilverLink;Texas Instruments SilverLink (USB GraphLink) Cable;C:\WINDOWS\System32\Drivers\SilvrLnk.sys
S3 tbhsd;Tunebite High-Speed Dubbing;C:\WINDOWS\System32\drivers\tbhsd.sys
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-06 23:45:28
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\WINDOWS\winhelp.exe 256192 bytes
C:\WINDOWS\winhlp32.exe 266752 bytes executable
C:\WINDOWS\winnt.bmp 48680 bytes
C:\WINDOWS\winnt256.bmp 48680 bytes
C:\WINDOWS\WINNT32.LOG 14813 bytes
C:\WINDOWS\WinSxS
C:\WINDOWS\wmsetup.log 284612 bytes
C:\WINDOWS\WMSysPr9.prx 316640 bytes
C:\WINDOWS\WMSysPrx.prx 299552 bytes
C:\WINDOWS\WORDPAD.INI 754 bytes
C:\WINDOWS\wsdu.log 35143 bytes
C:\WINDOWS\xpsp1hfm.log 7491 bytes
C:\WINDOWS\Zapotec.bmp 9522 bytes
C:\WINDOWS\_default.pif 707 bytes
C:\WINDOWS\_ISTMP1.DIR
C:\WINDOWS\Winamp.ini 192 bytes
C:\WINDOWS\winampa.ini 41 bytes
C:\WINDOWS\Windows Update.log 167320 bytes
C:\WINDOWS\WindowsShell.Manifest 749 bytes
C:\WINDOWS\WindowsUpdate.log 997427 bytes
scan completed successfully
hidden files: 20
**************************************************************************
.
Completion time: 2007-11-06 23:45:55
.
--- E O F ---
Hijackthis Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:52:35 PM, on 11/6/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
P:\Program Files\NetLimiter\NetLimiter.exe
C:\Program Files\Razer\razerhid.exe
C:\Program Files\TerraTec\DMX 6fire\DMX6Fire.exe
P:\Program Files\Kirby Alarm\kirbyalarm.exe
C:\Program Files\Razer\razerofa.exe
C:\WINDOWS\explorer.exe
C:\HJT\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com
O2 - BHO: (no name) - {029e02f0-a0e5-4b19-b958-7bf2db29fb13} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - (no file)
O2 - BHO: (no name) - {2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - P:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {54645654-2225-4455-44A1-9F4543D34546} - (no file)
O2 - BHO: (no name) - {6abc861a-31e7-4d91-b43b-d3c98f22a5c0} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {944864a5-3916-46e2-96a9-a2e84f3f1208} - (no file)
O2 - BHO: (no name) - {a4a435cf-3583-11d4-91bd-0048546a1450} - (no file)
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - P:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O2 - BHO: (no name) - {c2680e10-1655-4a0e-87f8-4259325a84b7} - (no file)
O2 - BHO: (no name) - {c4ca6559-2cf1-48b6-96b2-8340a06fd129} - (no file)
O2 - BHO: (no name) - {d8efadf1-9009-11d6-8c73-608c5dc19089} - (no file)
O2 - BHO: (no name) - {e9147a0a-a866-4214-b47c-da821891240f} - (no file)
O2 - BHO: (no name) - {e9306072-417e-43e3-81d5-369490beef7c} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - P:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RegKillElbyCheck] "P:\Program Files\Elaborate Bytes\DVD Region Killer\ElbyCheck.exe" /L RegKill
O4 - HKLM\..\Run: [NetLimiter] P:\Program Files\NetLimiter\NetLimiter.exe /s
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [razer] C:\Program Files\Razer\razerhid.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [SpySweeper] "P:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: trillian.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: DMX 6fire 2496 ControlPanel.lnk = ?
O4 - Global Startup: Kirby Alarm.lnk = P:\Program Files\Kirby Alarm\kirbyalarm.exe
O8 - Extra context menu item: Download All by FlashGet - P:\PROGRA~1\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - P:\PROGRA~1\FlashGet\jc_link.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - P:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - P:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: PDScheduler (PDSched) - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDSched.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
--
End of file - 5775 bytes