﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Tweaks.com Forum  / Windows &amp; System Security / HiJack This Logs  / Numerous infections, numous scans .... still have some work to do / Latest Posts</title><generator>InstantForum.NET v4.1.4</generator><description>Tweaks.com Forum </description><link>http://forum.tweaks.com/forum/</link><webMaster>forum@tweaks.com</webMaster><lastBuildDate>Sun, 07 Sep 2008 13:35:26 GMT</lastBuildDate><ttl>20</ttl><item><title>RE: Numerous infections, numous scans .... still have some work to do</title><link>http://forum.tweaks.com/forum/Topic239571-29-1.aspx</link><description>You're welcome.</description><pubDate>Sat, 17 May 2008 18:52:36 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: Numerous infections, numous scans .... still have some work to do</title><link>http://forum.tweaks.com/forum/Topic239571-29-1.aspx</link><description>Thanks so much~ Once again!</description><pubDate>Sat, 17 May 2008 17:50:57 GMT</pubDate><dc:creator>fairlite</dc:creator></item><item><title>RE: Numerous infections, numous scans .... still have some work to do</title><link>http://forum.tweaks.com/forum/Topic239571-29-1.aspx</link><description>Your log is clean:),please do the following:&lt;br&gt;&lt;br&gt;Click on Start/Run,copy and paste [b]ComboFix /u[/b] into the 'Open:' space,then press Ok.&lt;br&gt;This will uninstall Combofix,delete its related folders and files,reset your clock settings,hide file extensions,hide the system/hidden files and resets System Restore.&lt;br&gt;&lt;br&gt;[IMG]http://img.photobucket.com/albums/v624/29wood/comu.gif[/IMG]&lt;br&gt;&lt;br&gt;&lt;br&gt;Please double-click [b]OTMoveIt.exe[/b] again to run it.&lt;br&gt;Click on the 'Cleanup' button [IMG]http://img.photobucket.com/albums/v624/29wood/Clipboard01cleanup.gif[/IMG]&lt;br&gt;When you do this a text file named cleanup.txt will be downloaded from the internet. &lt;br&gt;If you get a warning from your firewall or other security programs regarding OTMoveIt attempting to contact the internet you should allow it to do so. &lt;br&gt;When the 'Confirm' box appears click 'Yes'.&lt;br&gt;[b]Restart your pc when prompted.[/b]&lt;br&gt;&lt;br&gt;&lt;br&gt;You should now take the time to read and follow the information found in the links below,to help you prevent any possible future infections and stay safe and secure while online:&lt;br&gt;&lt;br&gt;[b][color="blue"]Simple and easy ways to keep your computer safe and secure on the Internet[/color][/b]:&lt;br&gt;[url]http://www.bleepingcomputer.com/tutorials/tutorial82.html[/url]&lt;br&gt;&lt;br&gt;[b][color="blue"]How to prevent Malware[/color][/b]:&lt;br&gt;[url]http://users.telenet.be/bluepatchy/miekiemoes/prevention.html[/url]&lt;br&gt;&lt;br&gt;[B][color="blue"]So how did I get infected in the first place[/color][/B]:&lt;br&gt;[URL]http://forums.spybot.info/showthread.php?t=279[/URL]&lt;br&gt;&lt;br&gt;[B][color="blue"]Malware Cleanup Programs and Preventative Procedures[/color][/B]: &lt;br&gt;[URL]http://russelltexas.com/malware/allclear.htm[/URL]&lt;br&gt;&lt;br&gt;[b][color="blue"]Hardening Windows Security - Part 1[/color][/b]:&lt;br&gt;[url]http://www.malwarehelp.org/Malware-Prevention-Hardening-Windows-Security1.html[/url]&lt;br&gt;&lt;br&gt;[b][color="blue"]Hardening Windows Security - Part 2[/color][/b]:&lt;br&gt;[url]http://www.malwarehelp.org/malware-prevention-hardening-windows-security2.html[/url]</description><pubDate>Sat, 17 May 2008 17:09:08 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: Numerous infections, numous scans .... still have some work to do</title><link>http://forum.tweaks.com/forum/Topic239571-29-1.aspx</link><description>C:\WINDOWS\BMc303b894.xml moved successfully.&lt;BR&gt; &lt;BR&gt;OTMoveIt2 by OldTimer - Version 1.0.4.2 log created on 05172008_110652&lt;/P&gt;&lt;P&gt;______________________________________________________________________&lt;/P&gt;&lt;P&gt;Malwarebytes' Anti-Malware 1.12&lt;BR&gt;Database version: 758&lt;/P&gt;&lt;P&gt;Scan type: Quick Scan&lt;BR&gt;Objects scanned: 50370&lt;BR&gt;Time elapsed: 13 minute(s), 37 second(s)&lt;/P&gt;&lt;P&gt;Memory Processes Infected: 0&lt;BR&gt;Memory Modules Infected: 0&lt;BR&gt;Registry Keys Infected: 3&lt;BR&gt;Registry Values Infected: 0&lt;BR&gt;Registry Data Items Infected: 0&lt;BR&gt;Folders Infected: 0&lt;BR&gt;Files Infected: 0&lt;/P&gt;&lt;P&gt;Memory Processes Infected:&lt;BR&gt;(No malicious items detected)&lt;/P&gt;&lt;P&gt;Memory Modules Infected:&lt;BR&gt;(No malicious items detected)&lt;/P&gt;&lt;P&gt;Registry Keys Infected:&lt;BR&gt;HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -&amp;gt; Quarantined and deleted successfully.&lt;BR&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -&amp;gt; Quarantined and deleted successfully.&lt;BR&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -&amp;gt; Quarantined and deleted successfully.&lt;/P&gt;&lt;P&gt;Registry Values Infected:&lt;BR&gt;(No malicious items detected)&lt;/P&gt;&lt;P&gt;Registry Data Items Infected:&lt;BR&gt;(No malicious items detected)&lt;/P&gt;&lt;P&gt;Folders Infected:&lt;BR&gt;(No malicious items detected)&lt;/P&gt;&lt;P&gt;Files Infected:&lt;BR&gt;(No malicious items detected)&lt;BR&gt;_____________________________________________________________________&lt;/P&gt;&lt;P&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 11:28:52 AM, on 5/17/2008&lt;BR&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;BR&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16640)&lt;BR&gt;Boot mode: Normal&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\WINDOWS\System32\smss.exe&lt;BR&gt;C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;C:\WINDOWS\system32\services.exe&lt;BR&gt;C:\WINDOWS\system32\lsass.exe&lt;BR&gt;C:\WINDOWS\system32\ibmpmsvc.exe&lt;BR&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\Program Files\Windows Defender\MsMpEng.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\S24EvMon.exe&lt;BR&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;BR&gt;C:\WINDOWS\system32\spoolsv.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe&lt;BR&gt;C:\WINDOWS\system32\acs.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe&lt;BR&gt;C:\Program Files\Common Files\Motive\McciCMService.exe&lt;BR&gt;C:\WINDOWS\System32\RegSrvc.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\Program Files\Sierra Wireless\AirCard 580\Generic\Components\swiwificomm.exe&lt;BR&gt;C:\Program Files\Windows Defender\MSASCui.exe&lt;BR&gt;C:\Program Files\Total Recorder Professional 6\TotRecSched.exe&lt;BR&gt;C:\Program Files\Synaptics\SynTP\SynTPLpr.exe&lt;BR&gt;C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&lt;BR&gt;C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe&lt;BR&gt;C:\Program Files\CounterSpy\SBCSTray.exe&lt;BR&gt;C:\Program Files\Microsoft IntelliPoint\point32.exe&lt;BR&gt;C:\WINDOWS\CTHELPER.EXE&lt;BR&gt;C:\WINDOWS\system32\RunDll32.exe&lt;BR&gt;C:\WINDOWS\system32\rundll32.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe&lt;BR&gt;C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;C:\Program Files\AnyDVD\AnyDVDtray.exe&lt;BR&gt;C:\WINDOWS\explorer.exe&lt;BR&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;BR&gt;C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe&lt;BR&gt;C:\Documents and Settings\Chris\Desktop\OldTimerMoveIt2.exe&lt;BR&gt;C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe&lt;BR&gt;C:\WINDOWS\system32\NOTEPAD.EXE&lt;BR&gt;C:\Program Files\HijackThis\HijackThis.exe&lt;/P&gt;&lt;P&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://www.ebay.com"&gt;http://www.ebay.com&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://www.ebay.com"&gt;http://www.ebay.com&lt;/A&gt;&lt;BR&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = &lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = &lt;BR&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = &lt;BR&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;BR&gt;O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll&lt;BR&gt;O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide&lt;BR&gt;O4 - HKLM\..\Run: [TotalRecorderScheduler] "C:\Program Files\Total Recorder Professional 6\TotRecSched.exe"&lt;BR&gt;O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe&lt;BR&gt;O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&lt;BR&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"&lt;BR&gt;O4 - HKLM\..\Run: [SBCSTray] C:\Program Files\CounterSpy\SBCSTray.exe&lt;BR&gt;O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe&lt;BR&gt;O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"&lt;BR&gt;O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"&lt;BR&gt;O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE&lt;BR&gt;O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE&lt;BR&gt;O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor&lt;BR&gt;O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent&lt;BR&gt;O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min&lt;BR&gt;O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe&lt;BR&gt;O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020&lt;BR&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\AnyDVD\AnyDVDtray.exe&lt;BR&gt;O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')&lt;BR&gt;O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')&lt;BR&gt;O8 - Extra context menu item: &amp;amp;Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm&lt;BR&gt;O8 - Extra context menu item: &amp;amp;Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm&lt;BR&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000&lt;BR&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;BR&gt;O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - &lt;A href="http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab"&gt;http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {22E5D91F-89E6-4405-AD9C-0AF27BA6F06B} (HidInputMonitorX Control) - &lt;A href="file:///D:/components/hidinputmonitorx.ocx"&gt;file:///D:/components/hidinputmonitorx.ocx&lt;/A&gt;&lt;BR&gt;O16 - DPF: {2DAD3559-2923-4935-AD49-B673D2539944} (IASRunner Class) - &lt;A href="https://www-307.ibm.com/pc/support/access/aslibmain/content/AcpIR.cab"&gt;https://www-307.ibm.com/pc/support/access/aslibmain/content/AcpIR.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - &lt;A href="http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab"&gt;http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {4F63D44B-6274-4D60-8AB1-CAA7116B8AF3} (A9Helper.A9) - &lt;A href="file:///D:/components/A9.ocx"&gt;file:///D:/components/A9.ocx&lt;/A&gt;&lt;BR&gt;O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - &lt;A href="http://upload.facebook.com/controls/FacebookPhotoUploader.cab"&gt;http://upload.facebook.com/controls/FacebookPhotoUploader.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &lt;A href="http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1107394181500"&gt;http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1107394181500&lt;/A&gt;&lt;BR&gt;O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - &lt;A href="http://download.divx.com/player/DivXBrowserPlugin.cab"&gt;http://download.divx.com/player/DivXBrowserPlugin.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {7030CC6C-1A88-4591-BB5A-651B9F7F0C30} (WMVHDRatingCtrl Class) - &lt;A href="file:///D:/components/wmvhdrating.ocx"&gt;file:///D:/components/wmvhdrating.ocx&lt;/A&gt;&lt;BR&gt;O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - &lt;A href="http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab"&gt;http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - &lt;A href="http://support.f-secure.com/ols/fscax.cab"&gt;http://support.f-secure.com/ols/fscax.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &lt;A href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab"&gt;http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab&lt;/A&gt;&lt;BR&gt;O17 - HKLM\System\CCS\Services\Tcpip\..\{62EC955C-255C-405C-A396-1967C4580BEB}: NameServer = 204.174.120.45 204.174.120.46&lt;BR&gt;O18 - Protocol: intu-qt2007 - {026BF40D-BA05-467B-9F1F-AD0D7A3F5F11} - C:\Program Files\QuickTax 2007\ic2007pp.dll&lt;BR&gt;O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll&lt;BR&gt;O23 - Service: Atheros Configuration Service (acs) - Atheros - C:\WINDOWS\system32\acs.exe&lt;BR&gt;O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe&lt;BR&gt;O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe&lt;BR&gt;O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe&lt;BR&gt;O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe&lt;BR&gt;O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)&lt;BR&gt;O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe&lt;BR&gt;O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe&lt;BR&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe&lt;BR&gt;O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe&lt;BR&gt;O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe&lt;BR&gt;O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe&lt;BR&gt;O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe&lt;BR&gt;O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\WINDOWS\System32\S24EvMon.exe&lt;BR&gt;O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - C:\Program Files\CounterSpy\SBCSSvc.exe&lt;BR&gt;O23 - Service: SwiWiFiComm - Unknown owner - C:\Program Files\Sierra Wireless\AirCard 580\Generic\Components\swiwificomm.exe&lt;/P&gt;&lt;P&gt;--&lt;BR&gt;End of file - 9278 bytes&lt;BR&gt;</description><pubDate>Sat, 17 May 2008 12:29:29 GMT</pubDate><dc:creator>fairlite</dc:creator></item><item><title>RE: Numerous infections, numous scans .... still have some work to do</title><link>http://forum.tweaks.com/forum/Topic239571-29-1.aspx</link><description>Please download [b]OTMoveIt[/b] by [b]OldTimer[/b],save it to your desktop:&lt;br&gt;[url]http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe[/url]&lt;br&gt;Please double-click OTMoveIt.exe to run it.&lt;br&gt;Copy ALL the text inside the code box below to the clipboard by highlighting [b]ALL[/b] of it and pressing CTRL + C (or, after highlighting, right-click and choose 'Copy'):&lt;br&gt;&lt;br&gt;[quote]C:\WINDOWS\BMc303b894.xml[/quote]&lt;br&gt;Return to OTMoveIt, right click on the "[b]Paste List of Files/Folders to Move[/b]" window under the [b]"yellow"[/b] bar,and choose [b]Paste[/b],see image below:&lt;br&gt;&lt;br&gt;[IMG]http://img.photobucket.com/albums/v624/29wood/Clipboard01-3.png[/IMG]&lt;br&gt;&lt;br&gt;Click on the Moveit! button [IMG]http://img.photobucket.com/albums/v624/29wood/Clipboard01moveit.gif[/IMG]&lt;br&gt;[b]Copy everything on the 'Results' window to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose 'Copy'), and paste it into your next reply.[/b]&lt;br&gt;Close OTMoveIt by clicking on the "Exit" button.&lt;br&gt;If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. &lt;br&gt;If you are asked to reboot the machine choose [b]Yes[/b].&lt;br&gt;&lt;br&gt;&lt;br&gt;Please download [b][color="red"]Malwarebytes Anti-Malware[/color][/b]:&lt;br&gt;[url]http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html[/url]&lt;br&gt;[url]http://www.besttechie.net/tools/mbam-setup.exe[/url]&lt;br&gt;&lt;br&gt;Double Click mbam-setup.exe to install the application.&lt;br&gt;(If using Windows Vista,be sure to [b][url=http://windowshelp.microsoft.com/Windows/en-US/Help/fb464905-31d5-4427-89a2-ed5322327fc21033.mspx][color="blue"]"Run As Administrator"[/color][/url][/b]).&lt;br&gt;&lt;br&gt;* Make sure a checkmark is placed next to [b]Update Malwarebytes' Anti-Malware[/b] and [b]Launch Malwarebytes' Anti-Malware[/b], then click Finish.&lt;br&gt;* If an update is found, it will download and install the latest version.&lt;br&gt;* Once the program has loaded, select "Perform Quick Scan", then click Scan.&lt;br&gt;* The scan may take some time to finish,so please be patient.&lt;br&gt;* When the scan is complete, click OK, then Show Results to view the results.&lt;br&gt;* Make sure that everything is checked, and click Remove Selected.&lt;br&gt;* When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)&lt;br&gt;* The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.&lt;br&gt;* [b]Copy and paste the entire report into your next reply[/b].&lt;br&gt;&lt;br&gt;Extra Note:&lt;br&gt;[b][color="green"]If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.[/color][/b]&lt;br&gt;&lt;br&gt;[b]Also post a new Hijackthis log please.[/b]</description><pubDate>Sat, 17 May 2008 03:31:27 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: Numerous infections, numous scans .... still have some work to do</title><link>http://forum.tweaks.com/forum/Topic239571-29-1.aspx</link><description>My PC seems to be running &lt;STRONG&gt;'excellent'&lt;/STRONG&gt; once again Richie. &lt;STRONG&gt;THANKS. &lt;/STRONG&gt;I'd like to add, I do not use p2p programs other than soulseek which is strictly mp3 so no viruses/malware. I did have my browser security and cookies set to low, actually cookies were set to 'accept all cookies!' I would assume this is not good! I can't believe I found my browser settings in this state. I use bit torrents sometimes as carefully as i can and i know this poses a risk as well. What would you recommend I run for AV and spyware guard? It seems very tough to find 1 program to protect from and remove all infections. SpyNoMore seems to find the most but I realize this is a case-by-case type of thing. Anyway, it just seems to be happening all-too-often lately! I'm sure there's a guide somewhere on here. I'll search for one in the meantime. Thanks again.&lt;/P&gt;&lt;P&gt;Chris</description><pubDate>Fri, 16 May 2008 22:05:51 GMT</pubDate><dc:creator>fairlite</dc:creator></item><item><title>RE: Numerous infections, numous scans .... still have some work to do</title><link>http://forum.tweaks.com/forum/Topic239571-29-1.aspx</link><description>ComboFix 08-05-15.3 - Chris 2008-05-16 17:19:29.3 - NTFSx86&lt;BR&gt;Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.370 [GMT -6:00]&lt;BR&gt;Running from: C:\Documents and Settings\Chris\Desktop\ComboFix.exe&lt;BR&gt;Command switches used :: C:\Documents and Settings\Chris\Desktop\CFScript.txt&lt;BR&gt; * Created a new restore point&lt;/P&gt;&lt;P&gt;[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]&lt;/P&gt;&lt;P&gt;FILE ::&lt;BR&gt;C:\WINDOWS\system32\hdouopdd.dll&lt;BR&gt;C:\WINDOWS\system32\xgddunxf.dll&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;C:\WINDOWS\pskt.ini&lt;BR&gt;C:\WINDOWS\system32\hdouopdd.dll&lt;BR&gt;C:\WINDOWS\system32\xgddunxf.dll&lt;/P&gt;&lt;P&gt;.&lt;BR&gt;(((((((((((((((((((((((((   Files Created from 2008-04-16 to 2008-05-16  )))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;2008-05-16 13:57 . 2008-05-16 13:57 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\Christopher\Accessories&lt;BR&gt;2008-05-16 13:24 . 2008-05-16 13:24 0 --a------ C:\WINDOWS\BMc303b894.xml&lt;BR&gt;2008-05-16 10:47 . 2008-05-16 10:47 &amp;lt;DIR&amp;gt; d-------- C:\WINDOWS\system32\Kaspersky Lab&lt;BR&gt;2008-05-16 09:08 . 2008-05-16 09:30 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\SpyNoMore&lt;BR&gt;2008-05-15 23:52 . 2008-05-15 23:52 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Avira&lt;BR&gt;2008-05-15 23:22 . 2008-05-15 23:22 15,544 --a------ C:\WINDOWS\system32\drivers\sbhr.sys&lt;BR&gt;2008-05-15 23:21 . 2008-05-15 23:21 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\All Users\Application Data\Sunbelt Software&lt;BR&gt;2008-05-15 23:20 . 2008-05-16 00:06 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\CounterSpy&lt;BR&gt;2008-05-15 18:14 . 2008-05-16 13:07 4,566 --a------ C:\WINDOWS\imsins.BAK&lt;BR&gt;2008-05-15 10:32 . 2008-05-15 10:59 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Cucusoft AVI To DVD Pro&lt;BR&gt;2008-05-15 09:32 . 2008-05-15 09:33 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Cucusoft Ultimate Video Converter&lt;BR&gt;2008-05-15 09:32 . 2006-09-11 04:13 409,600 --a------ C:\WINDOWS\system32\vampd.ax&lt;BR&gt;2008-05-15 09:32 . 2003-03-30 20:08 372,736 --a------ C:\WINDOWS\system32\xvid.ax&lt;BR&gt;2008-05-15 09:32 . 2008-01-25 21:06 364,544 --a------ C:\WINDOWS\system32\cdg.dll&lt;BR&gt;2008-05-15 09:32 . 2006-09-27 17:46 348,160 --a------ C:\WINDOWS\system32\cdga.dll&lt;BR&gt;2008-05-15 09:32 . 2006-07-08 04:07 114,688 --a------ C:\WINDOWS\system32\PropListCtrl.ocx&lt;BR&gt;2008-05-15 09:32 . 2006-07-17 21:42 14,909 --a------ C:\WINDOWS\system32\A_reg.reg&lt;BR&gt;2008-05-09 12:41 . 2008-05-09 12:41 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Synaptics&lt;BR&gt;2008-05-09 12:41 . 2007-12-05 16:11 177,664 --a------ C:\WINDOWS\system32\drivers\SynTP.sys&lt;BR&gt;2008-05-09 12:41 . 2007-12-05 16:12 110,592 --a------ C:\WINDOWS\system32\SynTPAPI.dll&lt;BR&gt;2008-05-09 12:41 . 2007-12-05 16:12 110,592 --a------ C:\WINDOWS\system32\SynCtrl.dll&lt;BR&gt;2008-05-09 12:41 . 2007-12-05 17:10 77,824 --a------ C:\WINDOWS\system32\SynTPCoI.dll&lt;BR&gt;2008-05-09 12:41 . 2007-12-05 16:12 73,728 --a------ C:\WINDOWS\system32\SynCOM.dll&lt;BR&gt;2008-05-09 12:41 . 2007-12-05 16:14 65,536 --a------ C:\WINDOWS\system32\SynTPFcs.dll&lt;BR&gt;2008-05-09 12:13 . 2007-03-21 13:33 1,257,566 -ra------ C:\WINDOWS\system32\dsa.dll&lt;BR&gt;2008-05-09 12:13 . 2007-03-21 13:46 254,023 --a------ C:\WINDOWS\system32\wsfwDS.dll&lt;BR&gt;2008-05-09 12:13 . 2007-03-21 13:46 249,925 --a------ C:\WINDOWS\system32\wsimd.dll&lt;BR&gt;2008-05-09 12:13 . 2007-03-21 13:33 82,017 -ra------ C:\WINDOWS\system32\dsaNac.dll&lt;BR&gt;2008-05-09 12:12 . 2008-05-09 12:12 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\ThinkPad R51&lt;BR&gt;2008-05-09 12:12 . 2007-10-26 01:20 549,184 --a------ C:\WINDOWS\system32\ar5211.sys&lt;BR&gt;2008-05-09 12:12 . 2006-08-07 14:17 118,784 --a------ C:\WINDOWS\system32\ATHCFG10.DLL&lt;BR&gt;2008-05-09 12:12 . 2007-10-26 01:20 100,996 --a------ C:\WINDOWS\system32\net5211.inf&lt;BR&gt;2008-05-09 12:12 . 2007-07-03 18:46 57,344 --a------ C:\WINDOWS\system32\wsimd.sys&lt;BR&gt;2008-05-09 12:12 . 2007-07-03 18:46 57,344 --------- C:\WINDOWS\system32\drivers\wsimd.sys&lt;BR&gt;2008-05-09 12:12 . 2007-10-29 12:47 23,501 --a------ C:\WINDOWS\system32\net5211.cat&lt;BR&gt;2008-05-09 12:12 . 2007-07-28 17:07 12,552 --a------ C:\WINDOWS\system32\wsimdp.cat&lt;BR&gt;2008-05-09 12:12 . 2007-07-28 17:07 12,129 --a------ C:\WINDOWS\system32\wsimd.cat&lt;BR&gt;2008-05-09 12:12 . 2007-07-03 18:46 5,361 --a------ C:\WINDOWS\system32\wsimdp.inf&lt;BR&gt;2008-05-09 12:12 . 2007-07-03 18:46 2,179 --a------ C:\WINDOWS\system32\wsimd.inf&lt;BR&gt;2008-05-09 11:56 . 2008-05-09 11:56 99,264 --a------ C:\WINDOWS\system32\drivers\AnyDVD.sys&lt;BR&gt;2008-05-09 09:54 . 2008-05-09 09:57 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Common Files\Ahead&lt;BR&gt;2008-05-09 09:53 . 2008-05-09 09:54 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Nero 7.8.5.0 Premium&lt;BR&gt;2008-05-04 18:48 . 2008-05-06 10:24 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Spybot S&amp;amp;D&lt;BR&gt;2008-05-04 18:48 . 2008-05-06 00:03 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search &amp;amp; Destroy&lt;BR&gt;2008-05-04 17:56 . 2008-05-04 17:56 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\KillBox&lt;BR&gt;2008-05-02 12:14 . 2008-05-02 12:17 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Kaspersky Antivirus 7&lt;BR&gt;2008-05-01 18:12 . 2008-05-01 18:12 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\ACW&lt;BR&gt;2008-05-01 14:01 . 2008-05-01 14:01 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\LocalService\Application Data\AdobeUM&lt;BR&gt;2008-05-01 12:31 . 2008-05-01 12:31 0 --a------ C:\WINDOWS\system32\SBRC.dat&lt;BR&gt;2008-05-01 12:31 . 2008-05-01 12:31 0 --a------ C:\WINDOWS\system32\SBFC.dat&lt;BR&gt;2008-05-01 12:22 . 2008-05-01 12:22 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\Chris\Application Data\Sunbelt Software&lt;BR&gt;2008-05-01 11:54 . 2006-08-24 15:56 40,832 --a------ C:\WINDOWS\system32\drivers\apusbsnt.sys&lt;BR&gt;2008-05-01 11:54 . 2005-03-15 11:11 17,920 --a------ C:\WINDOWS\system32\apintfnt.dll&lt;BR&gt;2008-05-01 11:54 . 2006-08-24 15:57 11,776 --a------ C:\WINDOWS\system32\apusbdco.dll&lt;BR&gt;2008-05-01 00:05 . 2008-02-28 13:26 1,414,440 --a------ C:\WINDOWS\system32\ShellManager310E2D762.dll&lt;BR&gt;2008-04-30 22:03 . 2008-04-30 22:17 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\SpyZooka&lt;BR&gt;2008-04-30 21:48 . 2008-04-30 21:50 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\Chris\Application Data\Mp3tag&lt;BR&gt;2008-04-30 21:47 . 2008-04-30 21:47 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Mp3tag&lt;BR&gt;2008-04-30 20:27 . 2008-05-03 08:28 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Virtual DJ Pro 5&lt;BR&gt;2008-04-30 17:50 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl&lt;BR&gt;2008-04-30 17:49 . 2008-04-30 17:50 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Java&lt;BR&gt;2008-04-30 17:46 . 2008-04-30 17:46 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Common Files\Java&lt;BR&gt;2008-04-30 13:49 . 2008-04-30 13:49 1,152 --a------ C:\WINDOWS\system32\windrv.sys&lt;BR&gt;2008-04-30 13:14 . 2008-04-30 13:14 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Common Files\Wise Installation Wizard&lt;BR&gt;2008-04-30 01:49 . 2008-05-15 23:52 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\All Users\Application Data\Avira&lt;BR&gt;2008-04-29 19:26 . 2008-04-29 19:26 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\NeroInstall.bak&lt;BR&gt;2008-04-29 19:18 . 2008-05-09 09:43 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Nero&lt;BR&gt;2008-04-29 19:18 . 2008-05-02 03:31 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Common Files\Nero&lt;BR&gt;2008-04-29 19:18 . 2008-05-09 09:54 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\All Users\Application Data\Nero&lt;BR&gt;2008-04-29 19:03 . 2008-04-29 19:03 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\MagicISO&lt;BR&gt;2008-04-28 19:29 . 2008-04-28 19:29 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\CCleaner&lt;BR&gt;2008-04-27 22:44 . 2008-04-30 21:02 &amp;lt;DIR&amp;gt; d-------- C:\WINDOWS\RegCure&lt;BR&gt;2008-04-27 22:44 . 2008-04-30 21:02 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\RegCure&lt;BR&gt;2008-04-26 17:18 . 2008-04-26 17:18 0 --a------ C:\WINDOWS\nsreg.dat&lt;BR&gt;2008-04-24 12:05 . 2008-04-24 12:28 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\QuickTax 2007&lt;BR&gt;2008-04-24 12:05 . 2008-04-24 12:05 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Common Files\Intuit&lt;BR&gt;2008-04-24 12:05 . 2008-04-24 12:05 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Common Files\AnswerWorks 4.0&lt;BR&gt;2008-04-24 12:05 . 2008-04-24 12:05 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\Chris\Application Data\Intuit Canada&lt;BR&gt;2008-04-24 12:03 . 2008-04-24 12:03 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\All Users\Application Data\Intuit Canada&lt;BR&gt;2008-04-22 23:13 . 2008-04-22 23:13 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\Chris\Application Data\GTek&lt;BR&gt;2008-04-22 23:13 . 2008-04-22 23:13 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\All Users\Application Data\Gtek&lt;BR&gt;2008-04-22 23:13 . 2008-04-22 23:13 5,248 --a------ C:\WINDOWS\system32\OEMINFO.PNF&lt;/P&gt;&lt;P&gt;.&lt;BR&gt;((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;BR&gt;2008-07-12 20:12 --------- d-----w C:\Program Files\Azureus&lt;BR&gt;2008-05-16 16:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab&lt;BR&gt;2008-05-16 04:32 --------- d-----w C:\Program Files\XoftSpy SE&lt;BR&gt;2008-05-16 00:12 --------- d-----w C:\Program Files\Windows Media Connect 2&lt;BR&gt;2008-05-15 16:34 --------- d-----w C:\Documents and Settings\Chris\Application Data\Azureus&lt;BR&gt;2008-05-15 04:21 --------- d-----w C:\Program Files\AnyDVD&lt;BR&gt;2008-05-09 18:12 --------- d--h--w C:\Program Files\InstallShield Installation Information&lt;BR&gt;2008-05-09 18:01 --------- d-----w C:\Program Files\ThinkPad&lt;BR&gt;2008-05-05 20:07 --------- d-----w C:\Program Files\Soulseek&lt;BR&gt;2008-05-02 18:38 96,256 ----a-w C:\WINDOWS\system32\drivers\sptd6637.sys&lt;BR&gt;2008-05-01 22:02 --------- d-----w C:\Program Files\Power ISO&lt;BR&gt;2008-04-30 19:17 --------- d-----w C:\Program Files\SUPERAntiSpyware&lt;BR&gt;2008-04-30 19:16 --------- d-----w C:\Documents and Settings\Chris\Application Data\SUPERAntiSpyware.com&lt;BR&gt;2008-04-29 22:34 --------- d-----w C:\Program Files\Common Files\Macrovision Shared&lt;BR&gt;2008-04-25 05:02 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP&lt;BR&gt;2008-04-15 22:15 --------- d-----w C:\Program Files\Native Instruments&lt;BR&gt;2008-04-15 22:13 --------- d-----w C:\Program Files\Syncrosoft&lt;BR&gt;2008-04-15 21:52 --------- d-----w C:\Program Files\Games&lt;BR&gt;2008-04-14 18:02 --------- d-----w C:\Program Files\DivX&lt;BR&gt;2008-04-09 05:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help&lt;BR&gt;2008-04-06 11:27 --------- d-----w C:\Program Files\Microsoft IntelliPoint&lt;BR&gt;2008-04-04 04:39 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2&lt;BR&gt;2008-04-03 05:41 3,532 ----a-w C:\drmHeader.bin&lt;BR&gt;2008-04-03 04:18 --------- d-----w C:\Program Files\Windows Live&lt;BR&gt;2008-04-03 04:16 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller&lt;BR&gt;2008-04-03 04:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller&lt;BR&gt;2008-03-31 21:25 831,488 ----a-w C:\WINDOWS\system32\divx_xx0a.dll&lt;BR&gt;2008-03-31 21:25 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll&lt;BR&gt;2008-03-31 21:25 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll&lt;BR&gt;2008-03-31 21:25 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll&lt;BR&gt;2008-03-31 21:25 682,496 ----a-w C:\WINDOWS\system32\DivX.dll&lt;BR&gt;2008-03-31 21:25 161,096 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe&lt;BR&gt;2008-03-21 20:30 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe&lt;BR&gt;2008-03-21 20:30 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll&lt;BR&gt;2008-03-21 20:30 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll&lt;BR&gt;2008-03-21 20:30 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll&lt;BR&gt;2008-03-21 20:28 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll&lt;BR&gt;2008-03-21 20:28 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll&lt;BR&gt;2008-03-21 20:28 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll&lt;BR&gt;2008-03-21 20:28 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll&lt;BR&gt;2008-03-21 20:28 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll&lt;BR&gt;2008-03-21 20:28 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll&lt;BR&gt;2008-03-21 20:28 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll&lt;BR&gt;2008-03-21 20:28 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll&lt;BR&gt;2008-03-21 20:28 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll&lt;BR&gt;2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys&lt;BR&gt;2008-03-19 09:47 1,845,248 ------w C:\WINDOWS\system32\dllcache\win32k.sys&lt;BR&gt;2008-03-14 22:24 93,128 ----a-w C:\WINDOWS\system32\ElbyCDIO.dll&lt;BR&gt;2008-03-02 00:36 3,591,680 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll&lt;BR&gt;2008-02-29 08:55 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe&lt;BR&gt;2008-02-29 08:55 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe&lt;BR&gt;2008-02-22 10:00 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe&lt;BR&gt;2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll&lt;BR&gt;2008-02-20 06:51 282,624 ------w C:\WINDOWS\system32\dllcache\gdi32.dll&lt;BR&gt;2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll&lt;BR&gt;2008-02-20 05:32 45,568 ------w C:\WINDOWS\system32\dllcache\dnsrslvr.dll&lt;BR&gt;2008-02-20 05:32 148,992 ------w C:\WINDOWS\system32\dllcache\dnsapi.dll&lt;BR&gt;2007-07-23 18:50 39,832 ----a-w C:\Documents and Settings\Chris\Application Data\GDIPFONTCACHEV1.DAT&lt;BR&gt;2007-02-06 00:11 87,608 ----a-w C:\Documents and Settings\Chris\Application Data\ezpinst.exe&lt;BR&gt;2007-02-06 00:11 47,360 ----a-w C:\Documents and Settings\Chris\Application Data\pcouffin.sys&lt;BR&gt;2006-10-10 13:25 14 ----a-w C:\Documents and Settings\Chris\getfile.dat&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;BR&gt;.&lt;BR&gt;*Note* empty entries &amp;amp; legit default entries are not shown &lt;BR&gt;REGEDIT4&lt;/P&gt;&lt;P&gt;[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;BR&gt;"P2kAutostart"="" []&lt;BR&gt;"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [ ]&lt;BR&gt;"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]&lt;BR&gt;"AnyDVD"="C:\Program Files\AnyDVD\AnyDVDtray.exe" [2008-05-13 12:41 2091968]&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;BR&gt;"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20 866584]&lt;BR&gt;"TotalRecorderScheduler"="C:\Program Files\Total Recorder Professional 6\TotRecSched.exe" [2006-05-12 02:32 86016]&lt;BR&gt;"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2007-12-05 16:14 122880]&lt;BR&gt;"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-05 16:14 524288]&lt;BR&gt;"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]&lt;BR&gt;"SBCSTray"="C:\Program Files\CounterSpy\SBCSTray.exe" [2007-12-21 15:30 698864]&lt;BR&gt;"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 18:53 153136]&lt;BR&gt;"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [ ]&lt;BR&gt;"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2004-06-03 02:50 204800]&lt;BR&gt;"CTxfiHlp"="CTXFIHLP.EXE" [2006-08-11 15:56 18944 C:\WINDOWS\system32\CTXFIHLP.EXE]&lt;BR&gt;"CTHelper"="CTHELPER.EXE" [2006-08-11 15:56 17920 C:\WINDOWS\CTHELPER.EXE]&lt;BR&gt;"BMMGAG"="C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll" [2005-04-20 02:38 110592]&lt;BR&gt;"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 01:56 110592 C:\WINDOWS\system32\bthprops.cpl]&lt;BR&gt;"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-05-16 01:37 262401]&lt;BR&gt;"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2007-02-06 21:00 344064]&lt;/P&gt;&lt;P&gt;[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]&lt;BR&gt;"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2006-10-26 19:48 434528]&lt;/P&gt;&lt;P&gt;[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]&lt;BR&gt;"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]&lt;BR&gt;C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]&lt;BR&gt;tphklock.dll 2005-06-16 23:23 24576 C:\WINDOWS\system32\tphklock.dll&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]&lt;BR&gt;"mixer"= DrvTrNTm.dll&lt;BR&gt;"wave"= DrvTrNTm.dll&lt;BR&gt;"VIDC.ZMBV"= zmbv.dll&lt;/P&gt;&lt;P&gt;[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]&lt;BR&gt;"%windir%\\system32\\sessmgr.exe"=&lt;BR&gt;"C:\\StubInstaller.exe"=&lt;BR&gt;"C:\\Program Files\\Azureus\\Azureus.exe"=&lt;BR&gt;"C:\\Program Files\\Soulseek\\slsk.exe"=&lt;BR&gt;"C:\\Program Files\\Games\\Kyodai Mahjongg 2006\\kmj.exe"=&lt;BR&gt;"C:\\Program Files\\Motorola\\Software Update\\msu.exe"=&lt;BR&gt;"C:\\Program Files\\Motorola Phone Tools\\mPhonetools.exe"=&lt;BR&gt;"C:\\Program Files\\Internet Explorer\\iexplore.exe"=&lt;BR&gt;"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=&lt;BR&gt;"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=&lt;/P&gt;&lt;P&gt;[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]&lt;BR&gt;"6346:TCP"= 6346:TCP:LimeWire UDP&lt;BR&gt;"6881:TCP"= 6881:TCP:Azureus TCP&lt;BR&gt;"6881:UDP"= 6881:UDP:Azureus UDP&lt;BR&gt;"1700:TCP"= 1700:TCP:MioNet Remote Drive Access 0&lt;BR&gt;"1701:TCP"= 1701:TCP:MioNet Remote Drive Access 1&lt;BR&gt;"1702:TCP"= 1702:TCP:MioNet Remote Drive Access 2&lt;BR&gt;"1703:TCP"= 1703:TCP:MioNet Remote Drive Access 3&lt;BR&gt;"1704:TCP"= 1704:TCP:MioNet Remote Drive Access 4&lt;BR&gt;"1705:TCP"= 1705:TCP:MioNet Remote Drive Access 5&lt;BR&gt;"1706:TCP"= 1706:TCP:MioNet Remote Drive Access 6&lt;BR&gt;"1707:TCP"= 1707:TCP:MioNet Remote Drive Access 7&lt;BR&gt;"1708:TCP"= 1708:TCP:MioNet Remote Drive Access 8&lt;BR&gt;"1709:TCP"= 1709:TCP:MioNet Remote Drive Access 9&lt;BR&gt;"1641:TCP"= 1641:TCP:MioNet Remote Drive Verification&lt;BR&gt;"1647:TCP"= 1647:TCP:MioNet Storage Device Configuration&lt;BR&gt;"5432:UDP"= 5432:UDP:MioNet Storage Device Discovery&lt;/P&gt;&lt;P&gt;R0 SBHR;SBHR;C:\WINDOWS\system32\drivers\sbhr.sys [2008-05-15 23:22]&lt;BR&gt;R1 TPPWR;TPPWR;C:\WINDOWS\system32\drivers\Tppwr.sys [2005-04-20 02:38]&lt;BR&gt;R2 McciCMService;McciCMService;"C:\Program Files\Common Files\Motive\McciCMService.exe" [2007-09-26 11:43]&lt;BR&gt;R2 SwiWiFiComm;SwiWiFiComm;C:\Program Files\Sierra Wireless\AirCard 580\Generic\Components\swiwificomm.exe [2007-03-16 15:50]&lt;BR&gt;R3 apusbsnt;Sierra Wireless USB Modem Device Driver;C:\WINDOWS\system32\DRIVERS\apusbsnt.sys [2006-08-24 15:56]&lt;BR&gt;R3 WSIMD;wsimd Service;C:\WINDOWS\system32\DRIVERS\wsimd.sys [2007-07-03 18:46]&lt;BR&gt;S3 atinysxx;ATI USB 2.0 TV Audio Crossbar;C:\WINDOWS\system32\DRIVERS\atinysxx.sys [2005-01-25 20:36]&lt;BR&gt;S3 atinyvxx;ATI TV WONDER USB2.0 Video &amp;amp; Audio;C:\WINDOWS\system32\DRIVERS\atinyvxx.sys [2005-01-25 20:36]&lt;BR&gt;S3 ATITUNEP2;ATI TV WONDER USB2.0 TV Tuner;C:\WINDOWS\system32\DRIVERS\atinyuxx.sys [2005-01-25 20:37]&lt;BR&gt;S3 ATIUTD;ATI TV WONDER USB2.0 Device Driver;C:\WINDOWS\system32\Drivers\ATIUTD.sys [2005-01-25 20:37]&lt;BR&gt;S3 MotDev;Motorola Inc. USB Device;C:\WINDOWS\system32\DRIVERS\motodrv.sys [2007-10-10 17:41]&lt;BR&gt;S3 MREMP50;MREMP50 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS [2007-09-26 11:43]&lt;BR&gt;S3 MREMP50a64;MREMP50a64 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS []&lt;BR&gt;S3 MRESP50;MRESP50 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS [2007-09-26 11:43]&lt;BR&gt;S3 MRESP50a64;MRESP50a64 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS []&lt;BR&gt;S3 SBAPIFS;SBAPIFS;C:\WINDOWS\system32\drivers\sbapifs.sys []&lt;BR&gt;S3 TTDec;ATI TV WONDER USB2.0 Teletext Decoder;C:\WINDOWS\system32\DRIVERS\atinyttx.sys [2005-01-25 20:33]&lt;/P&gt;&lt;P&gt;.&lt;BR&gt;Contents of the 'Scheduled Tasks' folder&lt;BR&gt;"2006-03-11 10:42:52 C:\WINDOWS\Tasks\BMMTask.job"&lt;BR&gt;- C:\PROGRA~1\ThinkPad\UTILIT~1\BMMTASK.EXE&lt;BR&gt;"2008-05-16 23:30:16 C:\WINDOWS\Tasks\MP Scheduled Scan.job"&lt;BR&gt;- C:\Program Files\Windows Defender\MpCmdRun.exe&lt;BR&gt;"2008-05-16 23:26:08 C:\WINDOWS\Tasks\RegCure Program Check.job"&lt;BR&gt;- C:\Program Files\RegCure\RegCure.exe&lt;BR&gt;"2008-05-15 09:00:00 C:\WINDOWS\Tasks\RegCure.job"&lt;BR&gt;- C:\Program Files\RegCure\RegCure.exe&lt;BR&gt;"2005-06-06 04:59:37 C:\WINDOWS\Tasks\XoftSpy.job"&lt;BR&gt;- C:\Program Files\XoftSpy 4\XoftSpy.exe&lt;BR&gt;"2008-05-16 23:26:08 C:\WINDOWS\Tasks\XoftSpySE 2.job"&lt;BR&gt;- C:\Program Files\XoftSpy SE\XoftSpy.exe&lt;BR&gt;"2008-05-10 10:00:00 C:\WINDOWS\Tasks\XoftSpySE.job"&lt;BR&gt;- C:\Program Files\XoftSpy SE\XoftSpy.exe&lt;BR&gt;.&lt;BR&gt;**************************************************************************&lt;/P&gt;&lt;P&gt;catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &lt;A href="http://www.gmer.net"&gt;http://www.gmer.net&lt;/A&gt;&lt;BR&gt;Rootkit scan 2008-05-16 17:27:07&lt;BR&gt;Windows 5.1.2600 Service Pack 2 NTFS&lt;/P&gt;&lt;P&gt;scanning hidden processes ... &lt;/P&gt;&lt;P&gt;scanning hidden autostart entries ...&lt;/P&gt;&lt;P&gt;scanning hidden files ... &lt;/P&gt;&lt;P&gt;scan completed successfully&lt;BR&gt;hidden files: 0&lt;/P&gt;&lt;P&gt;**************************************************************************&lt;BR&gt;.&lt;BR&gt;--------------------- DLLs Loaded Under Running Processes ---------------------&lt;/P&gt;&lt;P&gt;PROCESS: C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;-&amp;gt; C:\WINDOWS\system32\tphklock.dll&lt;BR&gt;.&lt;BR&gt;------------------------ Other Running Processes ------------------------&lt;BR&gt;.&lt;BR&gt;C:\WINDOWS\system32\ibmpmsvc.exe&lt;BR&gt;C:\WINDOWS\system32\ati2evxx.exe&lt;BR&gt;C:\Program Files\Windows Defender\MsMpEng.exe&lt;BR&gt;C:\WINDOWS\system32\S24EvMon.exe&lt;BR&gt;C:\WINDOWS\system32\ati2evxx.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe&lt;BR&gt;C:\WINDOWS\system32\acs.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe&lt;BR&gt;C:\WINDOWS\system32\RegSrvc.exe&lt;BR&gt;C:\WINDOWS\system32\rundll32.exe&lt;BR&gt;C:\WINDOWS\system32\rundll32.exe&lt;BR&gt;.&lt;BR&gt;**************************************************************************&lt;BR&gt;.&lt;BR&gt;Completion time: 2008-05-16 17:35:56 - machine was rebooted&lt;BR&gt;ComboFix-quarantined-files.txt  2008-05-16 23:35:39&lt;BR&gt;ComboFix2.txt  2008-05-16 19:30:11&lt;BR&gt;ComboFix3.txt  2008-05-16 17:58:59&lt;BR&gt;ComboFix4.txt  2008-05-01 00:15:51&lt;/P&gt;&lt;P&gt;Pre-Run: 5,696,503,808 bytes free&lt;BR&gt;Post-Run: 5,672,001,536 bytes free&lt;/P&gt;&lt;P&gt;303 --- E O F --- 2008-05-16 18:11:05&lt;BR&gt;___________________________________________________________________&lt;/P&gt;&lt;P&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 5:37:50 PM, on 5/16/2008&lt;BR&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;BR&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16640)&lt;BR&gt;Boot mode: Normal&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\WINDOWS\System32\smss.exe&lt;BR&gt;C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;C:\WINDOWS\system32\services.exe&lt;BR&gt;C:\WINDOWS\system32\lsass.exe&lt;BR&gt;C:\WINDOWS\system32\ibmpmsvc.exe&lt;BR&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\Program Files\Windows Defender\MsMpEng.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\S24EvMon.exe&lt;BR&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;BR&gt;C:\WINDOWS\system32\spoolsv.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe&lt;BR&gt;C:\WINDOWS\system32\acs.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe&lt;BR&gt;C:\Program Files\Common Files\Motive\McciCMService.exe&lt;BR&gt;C:\WINDOWS\System32\RegSrvc.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\Program Files\Sierra Wireless\AirCard 580\Generic\Components\swiwificomm.exe&lt;BR&gt;C:\WINDOWS\system32\wuauclt.exe&lt;BR&gt;C:\Program Files\Windows Defender\MSASCui.exe&lt;BR&gt;C:\Program Files\Total Recorder Professional 6\TotRecSched.exe&lt;BR&gt;C:\Program Files\Synaptics\SynTP\SynTPLpr.exe&lt;BR&gt;C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&lt;BR&gt;C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe&lt;BR&gt;C:\Program Files\CounterSpy\SBCSTray.exe&lt;BR&gt;C:\Program Files\Microsoft IntelliPoint\point32.exe&lt;BR&gt;C:\WINDOWS\CTHELPER.EXE&lt;BR&gt;C:\WINDOWS\system32\RunDll32.exe&lt;BR&gt;C:\WINDOWS\system32\rundll32.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe&lt;BR&gt;C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;C:\Program Files\AnyDVD\AnyDVDtray.exe&lt;BR&gt;C:\WINDOWS\explorer.exe&lt;BR&gt;C:\WINDOWS\system32\notepad.exe&lt;BR&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;BR&gt;C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe&lt;BR&gt;C:\Program Files\Outlook Express\msimn.exe&lt;BR&gt;C:\Program Files\HijackThis\HijackThis.exe&lt;/P&gt;&lt;P&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://www.ebay.com"&gt;http://www.ebay.com&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://www.ebay.com"&gt;http://www.ebay.com&lt;/A&gt;&lt;BR&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = &lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = &lt;BR&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = &lt;BR&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;BR&gt;O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll&lt;BR&gt;O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide&lt;BR&gt;O4 - HKLM\..\Run: [TotalRecorderScheduler] "C:\Program Files\Total Recorder Professional 6\TotRecSched.exe"&lt;BR&gt;O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe&lt;BR&gt;O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&lt;BR&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"&lt;BR&gt;O4 - HKLM\..\Run: [SBCSTray] C:\Program Files\CounterSpy\SBCSTray.exe&lt;BR&gt;O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe&lt;BR&gt;O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"&lt;BR&gt;O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"&lt;BR&gt;O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE&lt;BR&gt;O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE&lt;BR&gt;O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor&lt;BR&gt;O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent&lt;BR&gt;O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min&lt;BR&gt;O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe&lt;BR&gt;O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020&lt;BR&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\AnyDVD\AnyDVDtray.exe&lt;BR&gt;O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')&lt;BR&gt;O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')&lt;BR&gt;O8 - Extra context menu item: &amp;amp;Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm&lt;BR&gt;O8 - Extra context menu item: &amp;amp;Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm&lt;BR&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000&lt;BR&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;BR&gt;O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - &lt;A href="http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab"&gt;http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {22E5D91F-89E6-4405-AD9C-0AF27BA6F06B} (HidInputMonitorX Control) - &lt;A href="file:///D:/components/hidinputmonitorx.ocx"&gt;file:///D:/components/hidinputmonitorx.ocx&lt;/A&gt;&lt;BR&gt;O16 - DPF: {2DAD3559-2923-4935-AD49-B673D2539944} (IASRunner Class) - &lt;A href="https://www-307.ibm.com/pc/support/access/aslibmain/content/AcpIR.cab"&gt;https://www-307.ibm.com/pc/support/access/aslibmain/content/AcpIR.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - &lt;A href="http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab"&gt;http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {4F63D44B-6274-4D60-8AB1-CAA7116B8AF3} (A9Helper.A9) - &lt;A href="file:///D:/components/A9.ocx"&gt;file:///D:/components/A9.ocx&lt;/A&gt;&lt;BR&gt;O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - &lt;A href="http://upload.facebook.com/controls/FacebookPhotoUploader.cab"&gt;http://upload.facebook.com/controls/FacebookPhotoUploader.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &lt;A href="http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1107394181500"&gt;http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1107394181500&lt;/A&gt;&lt;BR&gt;O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - &lt;A href="http://download.divx.com/player/DivXBrowserPlugin.cab"&gt;http://download.divx.com/player/DivXBrowserPlugin.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {7030CC6C-1A88-4591-BB5A-651B9F7F0C30} (WMVHDRatingCtrl Class) - &lt;A href="file:///D:/components/wmvhdrating.ocx"&gt;file:///D:/components/wmvhdrating.ocx&lt;/A&gt;&lt;BR&gt;O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - &lt;A href="http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab"&gt;http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - &lt;A href="http://support.f-secure.com/ols/fscax.cab"&gt;http://support.f-secure.com/ols/fscax.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &lt;A href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab"&gt;http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab&lt;/A&gt;&lt;BR&gt;O17 - HKLM\System\CCS\Services\Tcpip\..\{62EC955C-255C-405C-A396-1967C4580BEB}: NameServer = 204.174.120.45 204.174.120.46&lt;BR&gt;O18 - Protocol: intu-qt2007 - {026BF40D-BA05-467B-9F1F-AD0D7A3F5F11} - C:\Program Files\QuickTax 2007\ic2007pp.dll&lt;BR&gt;O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll&lt;BR&gt;O23 - Service: Atheros Configuration Service (acs) - Atheros - C:\WINDOWS\system32\acs.exe&lt;BR&gt;O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe&lt;BR&gt;O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe&lt;BR&gt;O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe&lt;BR&gt;O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe&lt;BR&gt;O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)&lt;BR&gt;O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe&lt;BR&gt;O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe&lt;BR&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe&lt;BR&gt;O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe&lt;BR&gt;O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe&lt;BR&gt;O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe&lt;BR&gt;O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe&lt;BR&gt;O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\WINDOWS\System32\S24EvMon.exe&lt;BR&gt;O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - C:\Program Files\CounterSpy\SBCSSvc.exe&lt;BR&gt;O23 - Service: SwiWiFiComm - Unknown owner - C:\Program Files\Sierra Wireless\AirCard 580\Generic\Components\swiwificomm.exe&lt;/P&gt;&lt;P&gt;--&lt;BR&gt;End of file - 9239 bytes&lt;BR&gt;</description><pubDate>Fri, 16 May 2008 18:38:08 GMT</pubDate><dc:creator>fairlite</dc:creator></item><item><title>RE: Numerous infections, numous scans .... still have some work to do</title><link>http://forum.tweaks.com/forum/Topic239571-29-1.aspx</link><description>Copy and paste ALL the following text in the code box below into [b]Notepad[/b].&lt;br&gt;Click on File(in the menu at the top)&gt;Save as../Save as Type: 'All Files' /File name: [b]CFScript[/b] to your desktop.&lt;br&gt;[quote]File::&lt;br&gt;C:\WINDOWS\system32\xgddunxf.dll&lt;br&gt;C:\WINDOWS\system32\hdouopdd.dll&lt;br&gt;Registry::&lt;br&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;br&gt;"BMc303b894"=-&lt;br&gt;[/quote]&lt;br&gt;Now drag then drop the [b]CFScript[/b] file onto [b]ComboFix.exe[/b] as seen in the image below.&lt;br&gt;&lt;br&gt;[img]http://img.photobucket.com/albums/v624/29wood/CFScript.gif[/img]&lt;br&gt;&lt;br&gt;This will start ComboFix again. &lt;br&gt;After reboot, (in case it asks to reboot), [b]post the contents of Combofix.txt in your next reply along with a new HijackThis log.[/b]</description><pubDate>Fri, 16 May 2008 16:39:07 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: Numerous infections, numous scans .... still have some work to do</title><link>http://forum.tweaks.com/forum/Topic239571-29-1.aspx</link><description>ComboFix 08-05-15.3 - Chris 2008-05-16 13:14:02.2 - NTFSx86&lt;BR&gt;Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.348 [GMT -6:00]&lt;BR&gt;Running from: C:\Documents and Settings\Chris\Desktop\ComboFix.exe&lt;BR&gt;Command switches used :: C:\Documents and Settings\Chris\Desktop\CFScript.txt&lt;BR&gt; * Created a new restore point&lt;/P&gt;&lt;P&gt;[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]&lt;/P&gt;&lt;P&gt;FILE ::&lt;BR&gt;C:\WINDOWS\BMc303b894.xml&lt;BR&gt;C:\WINDOWS\system32\feqbfrob.dll&lt;BR&gt;C:\WINDOWS\system32\yayaYsSJ.dll&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;C:\WINDOWS\BMc303b894.xml&lt;BR&gt;C:\WINDOWS\pskt.ini&lt;BR&gt;C:\WINDOWS\system32\feqbfrob.dll&lt;BR&gt;C:\WINDOWS\system32\JSsYayay.ini&lt;BR&gt;C:\WINDOWS\system32\JSsYayay.ini2&lt;BR&gt;C:\WINDOWS\system32\mcrh.tmp&lt;BR&gt;C:\WINDOWS\system32\yayaYsSJ.dll&lt;/P&gt;&lt;P&gt;.&lt;BR&gt;(((((((((((((((((((((((((   Files Created from 2008-04-16 to 2008-05-16  )))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;2008-05-16 13:02 . 2008-05-16 13:02 125,952 --a------ C:\WINDOWS\system32\xgddunxf.dll&lt;BR&gt;2008-05-16 13:02 . 2008-05-16 13:02 125,952 --a------ C:\WINDOWS\system32\hdouopdd.dll&lt;BR&gt;2008-05-16 10:47 . 2008-05-16 10:47 &amp;lt;DIR&amp;gt; d-------- C:\WINDOWS\system32\Kaspersky Lab&lt;BR&gt;2008-05-16 09:08 . 2008-05-16 09:30 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\SpyNoMore&lt;BR&gt;2008-05-15 23:52 . 2008-05-15 23:52 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Avira&lt;BR&gt;2008-05-15 23:22 . 2008-05-15 23:22 15,544 --a------ C:\WINDOWS\system32\drivers\sbhr.sys&lt;BR&gt;2008-05-15 23:21 . 2008-05-15 23:21 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\All Users\Application Data\Sunbelt Software&lt;BR&gt;2008-05-15 23:20 . 2008-05-16 00:06 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\CounterSpy&lt;BR&gt;2008-05-15 18:14 . 2008-05-16 13:07 4,566 --a------ C:\WINDOWS\imsins.BAK&lt;BR&gt;2008-05-15 10:32 . 2008-05-15 10:59 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Cucusoft AVI To DVD Pro&lt;BR&gt;2008-05-15 09:32 . 2008-05-15 09:33 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Cucusoft Ultimate Video Converter&lt;BR&gt;2008-05-15 09:32 . 2006-09-11 04:13 409,600 --a------ C:\WINDOWS\system32\vampd.ax&lt;BR&gt;2008-05-15 09:32 . 2003-03-30 20:08 372,736 --a------ C:\WINDOWS\system32\xvid.ax&lt;BR&gt;2008-05-15 09:32 . 2008-01-25 21:06 364,544 --a------ C:\WINDOWS\system32\cdg.dll&lt;BR&gt;2008-05-15 09:32 . 2006-09-27 17:46 348,160 --a------ C:\WINDOWS\system32\cdga.dll&lt;BR&gt;2008-05-15 09:32 . 2006-07-08 04:07 114,688 --a------ C:\WINDOWS\system32\PropListCtrl.ocx&lt;BR&gt;2008-05-15 09:32 . 2006-07-17 21:42 14,909 --a------ C:\WINDOWS\system32\A_reg.reg&lt;BR&gt;2008-05-09 12:41 . 2008-05-09 12:41 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Synaptics&lt;BR&gt;2008-05-09 12:41 . 2007-12-05 16:11 177,664 --a------ C:\WINDOWS\system32\drivers\SynTP.sys&lt;BR&gt;2008-05-09 12:41 . 2007-12-05 16:12 110,592 --a------ C:\WINDOWS\system32\SynTPAPI.dll&lt;BR&gt;2008-05-09 12:41 . 2007-12-05 16:12 110,592 --a------ C:\WINDOWS\system32\SynCtrl.dll&lt;BR&gt;2008-05-09 12:41 . 2007-12-05 17:10 77,824 --a------ C:\WINDOWS\system32\SynTPCoI.dll&lt;BR&gt;2008-05-09 12:41 . 2007-12-05 16:12 73,728 --a------ C:\WINDOWS\system32\SynCOM.dll&lt;BR&gt;2008-05-09 12:41 . 2007-12-05 16:14 65,536 --a------ C:\WINDOWS\system32\SynTPFcs.dll&lt;BR&gt;2008-05-09 12:13 . 2007-03-21 13:33 1,257,566 -ra------ C:\WINDOWS\system32\dsa.dll&lt;BR&gt;2008-05-09 12:13 . 2007-03-21 13:46 254,023 --a------ C:\WINDOWS\system32\wsfwDS.dll&lt;BR&gt;2008-05-09 12:13 . 2007-03-21 13:46 249,925 --a------ C:\WINDOWS\system32\wsimd.dll&lt;BR&gt;2008-05-09 12:13 . 2007-03-21 13:33 82,017 -ra------ C:\WINDOWS\system32\dsaNac.dll&lt;BR&gt;2008-05-09 12:12 . 2008-05-09 12:12 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\ThinkPad R51&lt;BR&gt;2008-05-09 12:12 . 2007-10-26 01:20 549,184 --a------ C:\WINDOWS\system32\ar5211.sys&lt;BR&gt;2008-05-09 12:12 . 2006-08-07 14:17 118,784 --a------ C:\WINDOWS\system32\ATHCFG10.DLL&lt;BR&gt;2008-05-09 12:12 . 2007-10-26 01:20 100,996 --a------ C:\WINDOWS\system32\net5211.inf&lt;BR&gt;2008-05-09 12:12 . 2007-07-03 18:46 57,344 --a------ C:\WINDOWS\system32\wsimd.sys&lt;BR&gt;2008-05-09 12:12 . 2007-07-03 18:46 57,344 --------- C:\WINDOWS\system32\drivers\wsimd.sys&lt;BR&gt;2008-05-09 12:12 . 2007-10-29 12:47 23,501 --a------ C:\WINDOWS\system32\net5211.cat&lt;BR&gt;2008-05-09 12:12 . 2007-07-28 17:07 12,552 --a------ C:\WINDOWS\system32\wsimdp.cat&lt;BR&gt;2008-05-09 12:12 . 2007-07-28 17:07 12,129 --a------ C:\WINDOWS\system32\wsimd.cat&lt;BR&gt;2008-05-09 12:12 . 2007-07-03 18:46 5,361 --a------ C:\WINDOWS\system32\wsimdp.inf&lt;BR&gt;2008-05-09 12:12 . 2007-07-03 18:46 2,179 --a------ C:\WINDOWS\system32\wsimd.inf&lt;BR&gt;2008-05-09 11:56 . 2008-05-09 11:56 99,264 --a------ C:\WINDOWS\system32\drivers\AnyDVD.sys&lt;BR&gt;2008-05-09 09:54 . 2008-05-09 09:57 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Common Files\Ahead&lt;BR&gt;2008-05-09 09:53 . 2008-05-09 09:54 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Nero 7.8.5.0 Premium&lt;BR&gt;2008-05-04 18:48 . 2008-05-06 10:24 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Spybot S&amp;amp;D&lt;BR&gt;2008-05-04 18:48 . 2008-05-06 00:03 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search &amp;amp; Destroy&lt;BR&gt;2008-05-04 17:56 . 2008-05-04 17:56 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\KillBox&lt;BR&gt;2008-05-02 12:14 . 2008-05-02 12:17 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Kaspersky Antivirus 7&lt;BR&gt;2008-05-01 18:12 . 2008-05-01 18:12 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\ACW&lt;BR&gt;2008-05-01 14:01 . 2008-05-01 14:01 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\LocalService\Application Data\AdobeUM&lt;BR&gt;2008-05-01 12:31 . 2008-05-01 12:31 0 --a------ C:\WINDOWS\system32\SBRC.dat&lt;BR&gt;2008-05-01 12:31 . 2008-05-01 12:31 0 --a------ C:\WINDOWS\system32\SBFC.dat&lt;BR&gt;2008-05-01 12:22 . 2008-05-01 12:22 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\Chris\Application Data\Sunbelt Software&lt;BR&gt;2008-05-01 11:54 . 2006-08-24 15:56 40,832 --a------ C:\WINDOWS\system32\drivers\apusbsnt.sys&lt;BR&gt;2008-05-01 11:54 . 2005-03-15 11:11 17,920 --a------ C:\WINDOWS\system32\apintfnt.dll&lt;BR&gt;2008-05-01 11:54 . 2006-08-24 15:57 11,776 --a------ C:\WINDOWS\system32\apusbdco.dll&lt;BR&gt;2008-05-01 00:05 . 2008-02-28 13:26 1,414,440 --a------ C:\WINDOWS\system32\ShellManager310E2D762.dll&lt;BR&gt;2008-04-30 22:03 . 2008-04-30 22:17 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\SpyZooka&lt;BR&gt;2008-04-30 21:48 . 2008-04-30 21:50 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\Chris\Application Data\Mp3tag&lt;BR&gt;2008-04-30 21:47 . 2008-04-30 21:47 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Mp3tag&lt;BR&gt;2008-04-30 20:27 . 2008-05-03 08:28 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Virtual DJ Pro 5&lt;BR&gt;2008-04-30 17:50 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl&lt;BR&gt;2008-04-30 17:49 . 2008-04-30 17:50 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Java&lt;BR&gt;2008-04-30 17:46 . 2008-04-30 17:46 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Common Files\Java&lt;BR&gt;2008-04-30 13:49 . 2008-04-30 13:49 1,152 --a------ C:\WINDOWS\system32\windrv.sys&lt;BR&gt;2008-04-30 13:14 . 2008-04-30 13:14 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Common Files\Wise Installation Wizard&lt;BR&gt;2008-04-30 01:49 . 2008-05-15 23:52 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\All Users\Application Data\Avira&lt;BR&gt;2008-04-29 19:26 . 2008-04-29 19:26 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\NeroInstall.bak&lt;BR&gt;2008-04-29 19:18 . 2008-05-09 09:43 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Nero&lt;BR&gt;2008-04-29 19:18 . 2008-05-02 03:31 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Common Files\Nero&lt;BR&gt;2008-04-29 19:18 . 2008-05-09 09:54 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\All Users\Application Data\Nero&lt;BR&gt;2008-04-29 19:03 . 2008-04-29 19:03 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\MagicISO&lt;BR&gt;2008-04-28 19:29 . 2008-04-28 19:29 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\CCleaner&lt;BR&gt;2008-04-27 22:44 . 2008-04-30 21:02 &amp;lt;DIR&amp;gt; d-------- C:\WINDOWS\RegCure&lt;BR&gt;2008-04-27 22:44 . 2008-04-30 21:02 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\RegCure&lt;BR&gt;2008-04-26 17:18 . 2008-04-26 17:18 0 --a------ C:\WINDOWS\nsreg.dat&lt;BR&gt;2008-04-24 12:05 . 2008-04-24 12:28 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\QuickTax 2007&lt;BR&gt;2008-04-24 12:05 . 2008-04-24 12:05 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Common Files\Intuit&lt;BR&gt;2008-04-24 12:05 . 2008-04-24 12:05 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Common Files\AnswerWorks 4.0&lt;BR&gt;2008-04-24 12:05 . 2008-04-24 12:05 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\Chris\Application Data\Intuit Canada&lt;BR&gt;2008-04-24 12:03 . 2008-04-24 12:03 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\All Users\Application Data\Intuit Canada&lt;BR&gt;2008-04-22 23:13 . 2008-04-22 23:13 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\Chris\Application Data\GTek&lt;BR&gt;2008-04-22 23:13 . 2008-04-22 23:13 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\All Users\Application Data\Gtek&lt;BR&gt;2008-04-22 23:13 . 2008-04-22 23:13 5,248 --a------ C:\WINDOWS\system32\OEMINFO.PNF&lt;/P&gt;&lt;P&gt;.&lt;BR&gt;((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;BR&gt;2008-07-12 20:12 --------- d-----w C:\Program Files\Azureus&lt;BR&gt;2008-05-16 16:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab&lt;BR&gt;2008-05-16 04:32 --------- d-----w C:\Program Files\XoftSpy SE&lt;BR&gt;2008-05-16 00:12 --------- d-----w C:\Program Files\Windows Media Connect 2&lt;BR&gt;2008-05-15 16:34 --------- d-----w C:\Documents and Settings\Chris\Application Data\Azureus&lt;BR&gt;2008-05-15 04:21 --------- d-----w C:\Program Files\AnyDVD&lt;BR&gt;2008-05-09 18:12 --------- d--h--w C:\Program Files\InstallShield Installation Information&lt;BR&gt;2008-05-09 18:01 --------- d-----w C:\Program Files\ThinkPad&lt;BR&gt;2008-05-05 20:07 --------- d-----w C:\Program Files\Soulseek&lt;BR&gt;2008-05-02 18:38 96,256 ----a-w C:\WINDOWS\system32\drivers\sptd6637.sys&lt;BR&gt;2008-05-01 22:02 --------- d-----w C:\Program Files\Power ISO&lt;BR&gt;2008-04-30 19:17 --------- d-----w C:\Program Files\SUPERAntiSpyware&lt;BR&gt;2008-04-30 19:16 --------- d-----w C:\Documents and Settings\Chris\Application Data\SUPERAntiSpyware.com&lt;BR&gt;2008-04-29 22:34 --------- d-----w C:\Program Files\Common Files\Macrovision Shared&lt;BR&gt;2008-04-25 05:02 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP&lt;BR&gt;2008-04-15 22:15 --------- d-----w C:\Program Files\Native Instruments&lt;BR&gt;2008-04-15 22:13 --------- d-----w C:\Program Files\Syncrosoft&lt;BR&gt;2008-04-15 21:52 --------- d-----w C:\Program Files\Games&lt;BR&gt;2008-04-14 18:02 --------- d-----w C:\Program Files\DivX&lt;BR&gt;2008-04-09 05:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help&lt;BR&gt;2008-04-06 11:27 --------- d-----w C:\Program Files\Microsoft IntelliPoint&lt;BR&gt;2008-04-04 04:39 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2&lt;BR&gt;2008-04-03 05:41 3,532 ----a-w C:\drmHeader.bin&lt;BR&gt;2008-04-03 04:18 --------- d-----w C:\Program Files\Windows Live&lt;BR&gt;2008-04-03 04:16 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller&lt;BR&gt;2008-04-03 04:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller&lt;BR&gt;2008-03-31 21:25 831,488 ----a-w C:\WINDOWS\system32\divx_xx0a.dll&lt;BR&gt;2008-03-31 21:25 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll&lt;BR&gt;2008-03-31 21:25 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll&lt;BR&gt;2008-03-31 21:25 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll&lt;BR&gt;2008-03-31 21:25 682,496 ----a-w C:\WINDOWS\system32\DivX.dll&lt;BR&gt;2008-03-31 21:25 161,096 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe&lt;BR&gt;2008-03-21 20:30 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe&lt;BR&gt;2008-03-21 20:30 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll&lt;BR&gt;2008-03-21 20:30 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll&lt;BR&gt;2008-03-21 20:30 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll&lt;BR&gt;2008-03-21 20:28 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll&lt;BR&gt;2008-03-21 20:28 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll&lt;BR&gt;2008-03-21 20:28 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll&lt;BR&gt;2008-03-21 20:28 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll&lt;BR&gt;2008-03-21 20:28 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll&lt;BR&gt;2008-03-21 20:28 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll&lt;BR&gt;2008-03-21 20:28 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll&lt;BR&gt;2008-03-21 20:28 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll&lt;BR&gt;2008-03-21 20:28 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll&lt;BR&gt;2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys&lt;BR&gt;2008-03-19 09:47 1,845,248 ------w C:\WINDOWS\system32\dllcache\win32k.sys&lt;BR&gt;2008-03-14 22:24 93,128 ----a-w C:\WINDOWS\system32\ElbyCDIO.dll&lt;BR&gt;2008-03-02 00:36 3,591,680 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll&lt;BR&gt;2008-02-29 08:55 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe&lt;BR&gt;2008-02-29 08:55 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe&lt;BR&gt;2008-02-22 10:00 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe&lt;BR&gt;2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll&lt;BR&gt;2008-02-20 06:51 282,624 ------w C:\WINDOWS\system32\dllcache\gdi32.dll&lt;BR&gt;2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll&lt;BR&gt;2008-02-20 05:32 45,568 ------w C:\WINDOWS\system32\dllcache\dnsrslvr.dll&lt;BR&gt;2008-02-20 05:32 148,992 ------w C:\WINDOWS\system32\dllcache\dnsapi.dll&lt;BR&gt;2007-07-23 18:50 39,832 ----a-w C:\Documents and Settings\Chris\Application Data\GDIPFONTCACHEV1.DAT&lt;BR&gt;2007-02-06 00:11 87,608 ----a-w C:\Documents and Settings\Chris\Application Data\ezpinst.exe&lt;BR&gt;2007-02-06 00:11 47,360 ----a-w C:\Documents and Settings\Chris\Application Data\pcouffin.sys&lt;BR&gt;2006-10-10 13:25 14 ----a-w C:\Documents and Settings\Chris\getfile.dat&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;BR&gt;.&lt;BR&gt;*Note* empty entries &amp;amp; legit default entries are not shown &lt;BR&gt;REGEDIT4&lt;/P&gt;&lt;P&gt;[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;BR&gt;"P2kAutostart"="" []&lt;BR&gt;"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [ ]&lt;BR&gt;"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]&lt;BR&gt;"AnyDVD"="C:\Program Files\AnyDVD\AnyDVDtray.exe" [2008-05-13 12:41 2091968]&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;BR&gt;"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20 866584]&lt;BR&gt;"TotalRecorderScheduler"="C:\Program Files\Total Recorder Professional 6\TotRecSched.exe" [2006-05-12 02:32 86016]&lt;BR&gt;"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2007-12-05 16:14 122880]&lt;BR&gt;"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-05 16:14 524288]&lt;BR&gt;"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]&lt;BR&gt;"SBCSTray"="C:\Program Files\CounterSpy\SBCSTray.exe" [2007-12-21 15:30 698864]&lt;BR&gt;"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 18:53 153136]&lt;BR&gt;"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [ ]&lt;BR&gt;"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2004-06-03 02:50 204800]&lt;BR&gt;"CTxfiHlp"="CTXFIHLP.EXE" [2006-08-11 15:56 18944 C:\WINDOWS\system32\CTXFIHLP.EXE]&lt;BR&gt;"CTHelper"="CTHELPER.EXE" [2006-08-11 15:56 17920 C:\WINDOWS\CTHELPER.EXE]&lt;BR&gt;"BMMGAG"="C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll" [2005-04-20 02:38 110592]&lt;BR&gt;"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 01:56 110592 C:\WINDOWS\system32\bthprops.cpl]&lt;BR&gt;"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-05-16 01:37 262401]&lt;BR&gt;"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2007-02-06 21:00 344064]&lt;BR&gt;"BMc303b894"="C:\WINDOWS\system32\hdouopdd.dll" [2008-05-16 13:02 125952]&lt;/P&gt;&lt;P&gt;[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]&lt;BR&gt;"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2006-10-26 19:48 434528]&lt;/P&gt;&lt;P&gt;[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]&lt;BR&gt;"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]&lt;BR&gt;C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]&lt;BR&gt;tphklock.dll 2005-06-16 23:23 24576 C:\WINDOWS\system32\tphklock.dll&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]&lt;BR&gt;"mixer"= DrvTrNTm.dll&lt;BR&gt;"wave"= DrvTrNTm.dll&lt;BR&gt;"VIDC.ZMBV"= zmbv.dll&lt;/P&gt;&lt;P&gt;[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]&lt;BR&gt;"%windir%\\system32\\sessmgr.exe"=&lt;BR&gt;"C:\\StubInstaller.exe"=&lt;BR&gt;"C:\\Program Files\\Azureus\\Azureus.exe"=&lt;BR&gt;"C:\\Program Files\\Soulseek\\slsk.exe"=&lt;BR&gt;"C:\\Program Files\\Games\\Kyodai Mahjongg 2006\\kmj.exe"=&lt;BR&gt;"C:\\Program Files\\Motorola\\Software Update\\msu.exe"=&lt;BR&gt;"C:\\Program Files\\Motorola Phone Tools\\mPhonetools.exe"=&lt;BR&gt;"C:\\Program Files\\Internet Explorer\\iexplore.exe"=&lt;BR&gt;"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=&lt;BR&gt;"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=&lt;/P&gt;&lt;P&gt;[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]&lt;BR&gt;"6346:TCP"= 6346:TCP:LimeWire UDP&lt;BR&gt;"6881:TCP"= 6881:TCP:Azureus TCP&lt;BR&gt;"6881:UDP"= 6881:UDP:Azureus UDP&lt;BR&gt;"1700:TCP"= 1700:TCP:MioNet Remote Drive Access 0&lt;BR&gt;"1701:TCP"= 1701:TCP:MioNet Remote Drive Access 1&lt;BR&gt;"1702:TCP"= 1702:TCP:MioNet Remote Drive Access 2&lt;BR&gt;"1703:TCP"= 1703:TCP:MioNet Remote Drive Access 3&lt;BR&gt;"1704:TCP"= 1704:TCP:MioNet Remote Drive Access 4&lt;BR&gt;"1705:TCP"= 1705:TCP:MioNet Remote Drive Access 5&lt;BR&gt;"1706:TCP"= 1706:TCP:MioNet Remote Drive Access 6&lt;BR&gt;"1707:TCP"= 1707:TCP:MioNet Remote Drive Access 7&lt;BR&gt;"1708:TCP"= 1708:TCP:MioNet Remote Drive Access 8&lt;BR&gt;"1709:TCP"= 1709:TCP:MioNet Remote Drive Access 9&lt;BR&gt;"1641:TCP"= 1641:TCP:MioNet Remote Drive Verification&lt;BR&gt;"1647:TCP"= 1647:TCP:MioNet Storage Device Configuration&lt;BR&gt;"5432:UDP"= 5432:UDP:MioNet Storage Device Discovery&lt;/P&gt;&lt;P&gt;R0 SBHR;SBHR;C:\WINDOWS\system32\drivers\sbhr.sys [2008-05-15 23:22]&lt;BR&gt;R1 TPPWR;TPPWR;C:\WINDOWS\system32\drivers\Tppwr.sys [2005-04-20 02:38]&lt;BR&gt;R2 McciCMService;McciCMService;"C:\Program Files\Common Files\Motive\McciCMService.exe" [2007-09-26 11:43]&lt;BR&gt;R2 SwiWiFiComm;SwiWiFiComm;C:\Program Files\Sierra Wireless\AirCard 580\Generic\Components\swiwificomm.exe [2007-03-16 15:50]&lt;BR&gt;R3 apusbsnt;Sierra Wireless USB Modem Device Driver;C:\WINDOWS\system32\DRIVERS\apusbsnt.sys [2006-08-24 15:56]&lt;BR&gt;R3 WSIMD;wsimd Service;C:\WINDOWS\system32\DRIVERS\wsimd.sys [2007-07-03 18:46]&lt;BR&gt;S3 atinysxx;ATI USB 2.0 TV Audio Crossbar;C:\WINDOWS\system32\DRIVERS\atinysxx.sys [2005-01-25 20:36]&lt;BR&gt;S3 atinyvxx;ATI TV WONDER USB2.0 Video &amp;amp; Audio;C:\WINDOWS\system32\DRIVERS\atinyvxx.sys [2005-01-25 20:36]&lt;BR&gt;S3 ATITUNEP2;ATI TV WONDER USB2.0 TV Tuner;C:\WINDOWS\system32\DRIVERS\atinyuxx.sys [2005-01-25 20:37]&lt;BR&gt;S3 ATIUTD;ATI TV WONDER USB2.0 Device Driver;C:\WINDOWS\system32\Drivers\ATIUTD.sys [2005-01-25 20:37]&lt;BR&gt;S3 MotDev;Motorola Inc. USB Device;C:\WINDOWS\system32\DRIVERS\motodrv.sys [2007-10-10 17:41]&lt;BR&gt;S3 MREMP50;MREMP50 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS [2007-09-26 11:43]&lt;BR&gt;S3 MREMP50a64;MREMP50a64 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS []&lt;BR&gt;S3 MRESP50;MRESP50 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS [2007-09-26 11:43]&lt;BR&gt;S3 MRESP50a64;MRESP50a64 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS []&lt;BR&gt;S3 SBAPIFS;SBAPIFS;C:\WINDOWS\system32\drivers\sbapifs.sys []&lt;BR&gt;S3 TTDec;ATI TV WONDER USB2.0 Teletext Decoder;C:\WINDOWS\system32\DRIVERS\atinyttx.sys [2005-01-25 20:33]&lt;/P&gt;&lt;P&gt;.&lt;BR&gt;Contents of the 'Scheduled Tasks' folder&lt;BR&gt;"2006-03-11 10:42:52 C:\WINDOWS\Tasks\BMMTask.job"&lt;BR&gt;- C:\PROGRA~1\ThinkPad\UTILIT~1\BMMTASK.EXE&lt;BR&gt;"2008-05-16 19:24:58 C:\WINDOWS\Tasks\MP Scheduled Scan.job"&lt;BR&gt;- C:\Program Files\Windows Defender\MpCmdRun.exe&lt;BR&gt;"2008-05-16 19:21:18 C:\WINDOWS\Tasks\RegCure Program Check.job"&lt;BR&gt;- C:\Program Files\RegCure\RegCure.exe&lt;BR&gt;"2008-05-15 09:00:00 C:\WINDOWS\Tasks\RegCure.job"&lt;BR&gt;- C:\Program Files\RegCure\RegCure.exe&lt;BR&gt;"2005-06-06 04:59:37 C:\WINDOWS\Tasks\XoftSpy.job"&lt;BR&gt;- C:\Program Files\XoftSpy 4\XoftSpy.exe&lt;BR&gt;"2008-05-16 19:21:18 C:\WINDOWS\Tasks\XoftSpySE 2.job"&lt;BR&gt;- C:\Program Files\XoftSpy SE\XoftSpy.exe&lt;BR&gt;"2008-05-10 10:00:00 C:\WINDOWS\Tasks\XoftSpySE.job"&lt;BR&gt;- C:\Program Files\XoftSpy SE\XoftSpy.exe&lt;BR&gt;.&lt;BR&gt;**************************************************************************&lt;/P&gt;&lt;P&gt;catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &lt;A href="http://www.gmer.net"&gt;http://www.gmer.net&lt;/A&gt;&lt;BR&gt;Rootkit scan 2008-05-16 13:22:18&lt;BR&gt;Windows 5.1.2600 Service Pack 2 NTFS&lt;/P&gt;&lt;P&gt;scanning hidden processes ... &lt;/P&gt;&lt;P&gt;scanning hidden autostart entries ...&lt;/P&gt;&lt;P&gt;scanning hidden files ... &lt;/P&gt;&lt;P&gt;scan completed successfully&lt;BR&gt;hidden files: 0&lt;/P&gt;&lt;P&gt;**************************************************************************&lt;BR&gt;.&lt;BR&gt;--------------------- DLLs Loaded Under Running Processes ---------------------&lt;/P&gt;&lt;P&gt;PROCESS: C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;-&amp;gt; C:\WINDOWS\system32\tphklock.dll&lt;/P&gt;&lt;P&gt;PROCESS: C:\WINDOWS\explorer.exe&lt;BR&gt;-&amp;gt; C:\WINDOWS\system32\hdouopdd.dll&lt;BR&gt;-&amp;gt; ?:\WINDOWS\System32\CSCDLL.dll&lt;BR&gt;.&lt;BR&gt;------------------------ Other Running Processes ------------------------&lt;BR&gt;.&lt;BR&gt;C:\WINDOWS\system32\ibmpmsvc.exe&lt;BR&gt;C:\WINDOWS\system32\ati2evxx.exe&lt;BR&gt;C:\Program Files\Windows Defender\MsMpEng.exe&lt;BR&gt;C:\WINDOWS\system32\S24EvMon.exe&lt;BR&gt;C:\WINDOWS\system32\ati2evxx.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe&lt;BR&gt;C:\WINDOWS\system32\acs.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe&lt;BR&gt;C:\WINDOWS\system32\RegSrvc.exe&lt;BR&gt;C:\WINDOWS\system32\rundll32.exe&lt;BR&gt;C:\WINDOWS\system32\rundll32.exe&lt;BR&gt;C:\WINDOWS\system32\rundll32.exe&lt;BR&gt;.&lt;BR&gt;**************************************************************************&lt;BR&gt;.&lt;BR&gt;Completion time: 2008-05-16 13:30:10 - machine was rebooted&lt;BR&gt;ComboFix-quarantined-files.txt  2008-05-16 19:29:42&lt;BR&gt;ComboFix2.txt  2008-05-16 17:58:59&lt;BR&gt;ComboFix3.txt  2008-05-01 00:15:51&lt;/P&gt;&lt;P&gt;Pre-Run: 5,610,016,768 bytes free&lt;BR&gt;Post-Run: 5,600,915,456 bytes free&lt;/P&gt;&lt;P&gt;312 --- E O F --- 2008-05-16 18:11:05&lt;BR&gt;&lt;/P&gt;&lt;P&gt;__________________________________________________________________&lt;/P&gt;&lt;P&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 1:34:42 PM, on 5/16/2008&lt;BR&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;BR&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16640)&lt;BR&gt;Boot mode: Normal&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\WINDOWS\System32\smss.exe&lt;BR&gt;C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;C:\WINDOWS\system32\services.exe&lt;BR&gt;C:\WINDOWS\system32\lsass.exe&lt;BR&gt;C:\WINDOWS\system32\ibmpmsvc.exe&lt;BR&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\Program Files\Windows Defender\MsMpEng.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\S24EvMon.exe&lt;BR&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;BR&gt;C:\WINDOWS\system32\spoolsv.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe&lt;BR&gt;C:\WINDOWS\system32\acs.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe&lt;BR&gt;C:\Program Files\Common Files\Motive\McciCMService.exe&lt;BR&gt;C:\WINDOWS\System32\RegSrvc.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\Program Files\Sierra Wireless\AirCard 580\Generic\Components\swiwificomm.exe&lt;BR&gt;C:\Program Files\Windows Defender\MSASCui.exe&lt;BR&gt;C:\Program Files\Total Recorder Professional 6\TotRecSched.exe&lt;BR&gt;C:\Program Files\Synaptics\SynTP\SynTPLpr.exe&lt;BR&gt;C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&lt;BR&gt;C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe&lt;BR&gt;C:\Program Files\CounterSpy\SBCSTray.exe&lt;BR&gt;C:\Program Files\Microsoft IntelliPoint\point32.exe&lt;BR&gt;C:\WINDOWS\CTHELPER.EXE&lt;BR&gt;C:\WINDOWS\system32\RunDll32.exe&lt;BR&gt;C:\WINDOWS\system32\rundll32.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe&lt;BR&gt;C:\WINDOWS\system32\Rundll32.exe&lt;BR&gt;C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;C:\Program Files\AnyDVD\AnyDVDtray.exe&lt;BR&gt;C:\WINDOWS\explorer.exe&lt;BR&gt;C:\WINDOWS\system32\notepad.exe&lt;BR&gt;C:\WINDOWS\system32\wuauclt.exe&lt;BR&gt;C:\Program Files\Outlook Express\msimn.exe&lt;BR&gt;C:\Program Files\Internet Explorer\IEXPLORE.EXE&lt;BR&gt;C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe&lt;BR&gt;C:\Program Files\HijackThis\HijackThis.exe&lt;/P&gt;&lt;P&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://www.ebay.com"&gt;http://www.ebay.com&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://www.ebay.com"&gt;http://www.ebay.com&lt;/A&gt;&lt;BR&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = &lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = &lt;BR&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = &lt;BR&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;BR&gt;O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll&lt;BR&gt;O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide&lt;BR&gt;O4 - HKLM\..\Run: [TotalRecorderScheduler] "C:\Program Files\Total Recorder Professional 6\TotRecSched.exe"&lt;BR&gt;O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe&lt;BR&gt;O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&lt;BR&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"&lt;BR&gt;O4 - HKLM\..\Run: [SBCSTray] C:\Program Files\CounterSpy\SBCSTray.exe&lt;BR&gt;O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe&lt;BR&gt;O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"&lt;BR&gt;O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"&lt;BR&gt;O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE&lt;BR&gt;O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE&lt;BR&gt;O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor&lt;BR&gt;O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent&lt;BR&gt;O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min&lt;BR&gt;O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe&lt;BR&gt;O4 - HKLM\..\Run: [BMc303b894] Rundll32.exe "C:\WINDOWS\system32\hdouopdd.dll",s&lt;BR&gt;O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020&lt;BR&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\AnyDVD\AnyDVDtray.exe&lt;BR&gt;O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')&lt;BR&gt;O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')&lt;BR&gt;O8 - Extra context menu item: &amp;amp;Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm&lt;BR&gt;O8 - Extra context menu item: &amp;amp;Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm&lt;BR&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000&lt;BR&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;BR&gt;O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - &lt;A href="http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab"&gt;http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {22E5D91F-89E6-4405-AD9C-0AF27BA6F06B} (HidInputMonitorX Control) - &lt;A href="file:///D:/components/hidinputmonitorx.ocx"&gt;file:///D:/components/hidinputmonitorx.ocx&lt;/A&gt;&lt;BR&gt;O16 - DPF: {2DAD3559-2923-4935-AD49-B673D2539944} (IASRunner Class) - &lt;A href="https://www-307.ibm.com/pc/support/access/aslibmain/content/AcpIR.cab"&gt;https://www-307.ibm.com/pc/support/access/aslibmain/content/AcpIR.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - &lt;A href="http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab"&gt;http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {4F63D44B-6274-4D60-8AB1-CAA7116B8AF3} (A9Helper.A9) - &lt;A href="file:///D:/components/A9.ocx"&gt;file:///D:/components/A9.ocx&lt;/A&gt;&lt;BR&gt;O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - &lt;A href="http://upload.facebook.com/controls/FacebookPhotoUploader.cab"&gt;http://upload.facebook.com/controls/FacebookPhotoUploader.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &lt;A href="http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1107394181500"&gt;http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1107394181500&lt;/A&gt;&lt;BR&gt;O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - &lt;A href="http://download.divx.com/player/DivXBrowserPlugin.cab"&gt;http://download.divx.com/player/DivXBrowserPlugin.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {7030CC6C-1A88-4591-BB5A-651B9F7F0C30} (WMVHDRatingCtrl Class) - &lt;A href="file:///D:/components/wmvhdrating.ocx"&gt;file:///D:/components/wmvhdrating.ocx&lt;/A&gt;&lt;BR&gt;O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - &lt;A href="http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab"&gt;http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - &lt;A href="http://support.f-secure.com/ols/fscax.cab"&gt;http://support.f-secure.com/ols/fscax.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &lt;A href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab"&gt;http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab&lt;/A&gt;&lt;BR&gt;O17 - HKLM\System\CCS\Services\Tcpip\..\{62EC955C-255C-405C-A396-1967C4580BEB}: NameServer = 204.174.120.45 204.174.120.46&lt;BR&gt;O18 - Protocol: intu-qt2007 - {026BF40D-BA05-467B-9F1F-AD0D7A3F5F11} - C:\Program Files\QuickTax 2007\ic2007pp.dll&lt;BR&gt;O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll&lt;BR&gt;O23 - Service: Atheros Configuration Service (acs) - Atheros - C:\WINDOWS\system32\acs.exe&lt;BR&gt;O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe&lt;BR&gt;O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe&lt;BR&gt;O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe&lt;BR&gt;O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe&lt;BR&gt;O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)&lt;BR&gt;O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe&lt;BR&gt;O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe&lt;BR&gt;O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe&lt;BR&gt;O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe&lt;BR&gt;O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe&lt;BR&gt;O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe&lt;BR&gt;O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe&lt;BR&gt;O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\WINDOWS\System32\S24EvMon.exe&lt;BR&gt;O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - C:\Program Files\CounterSpy\SBCSSvc.exe&lt;BR&gt;O23 - Service: SwiWiFiComm - Unknown owner - C:\Program Files\Sierra Wireless\AirCard 580\Generic\Components\swiwificomm.exe&lt;/P&gt;&lt;P&gt;--&lt;BR&gt;End of file - 9355 bytes&lt;BR&gt;</description><pubDate>Fri, 16 May 2008 14:35:05 GMT</pubDate><dc:creator>fairlite</dc:creator></item><item><title>RE: Numerous infections, numous scans .... still have some work to do</title><link>http://forum.tweaks.com/forum/Topic239571-29-1.aspx</link><description>Copy and paste ALL the following text in the code box below into [b]Notepad[/b].&lt;br&gt;Click on File(in the menu at the top)&gt;Save as../Save as Type: 'All Files' /File name: [b]CFScript[/b] to your desktop.&lt;br&gt;[quote]File::&lt;br&gt;C:\WINDOWS\system32\feqbfrob.dll&lt;br&gt;C:\WINDOWS\BMc303b894.xml&lt;br&gt;C:\WINDOWS\system32\yayaYsSJ.dll&lt;br&gt;Registry::&lt;br&gt;[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{14370F76-7676-44A2-AD11-93A31C5FC9FC}]&lt;br&gt;[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AA07D05F-5465-41ED-A457-3516E108D6BC}]&lt;br&gt;[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{f591201f-dc78-4126-8875-ce6b8b2117cd}]&lt;br&gt;[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]&lt;br&gt;"{14370F76-7676-44A2-AD11-93A31C5FC9FC}"=-&lt;br&gt;[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ljJARkKA]&lt;br&gt;[/quote]&lt;br&gt;Now drag then drop the [b]CFScript[/b] file onto [b]ComboFix.exe[/b] as seen in the image below.&lt;br&gt;&lt;br&gt;[img]http://img.photobucket.com/albums/v624/29wood/CFScript.gif[/img]&lt;br&gt;&lt;br&gt;This will start ComboFix again. &lt;br&gt;After reboot, (in case it asks to reboot), [b]post the contents of Combofix.txt in your next reply along with a new HijackThis log.[/b]</description><pubDate>Fri, 16 May 2008 13:23:10 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: Numerous infections, numous scans .... still have some work to do</title><link>http://forum.tweaks.com/forum/Topic239571-29-1.aspx</link><description>ComboFix 08-05-15.3 - Chris 2008-05-16 11:38:03.1 - NTFSx86&lt;BR&gt;Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.357 [GMT -6:00]&lt;BR&gt;Running from: C:\Documents and Settings\Chris\Desktop\ComboFix.exe&lt;BR&gt; * Created a new restore point&lt;/P&gt;&lt;P&gt;[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;C:\WINDOWS\cookies.ini&lt;BR&gt;C:\WINDOWS\pskt.ini&lt;BR&gt;C:\WINDOWS\system32\dvuqsrxy.ini&lt;BR&gt;C:\WINDOWS\system32\JSsYayay.ini&lt;BR&gt;C:\WINDOWS\system32\JSsYayay.ini2&lt;BR&gt;C:\WINDOWS\system32\mcrh.tmp&lt;BR&gt;C:\WINDOWS\system32\pkjkejta.ini&lt;/P&gt;&lt;P&gt;.&lt;BR&gt;(((((((((((((((((((((((((   Files Created from 2008-04-16 to 2008-05-16  )))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;2008-05-16 10:47 . 2008-05-16 10:47 &amp;lt;DIR&amp;gt; d-------- C:\WINDOWS\system32\Kaspersky Lab&lt;BR&gt;2008-05-16 09:08 . 2008-05-16 09:30 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\SpyNoMore&lt;BR&gt;2008-05-15 23:52 . 2008-05-15 23:52 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Avira&lt;BR&gt;2008-05-15 23:22 . 2008-05-15 23:22 15,544 --a------ C:\WINDOWS\system32\drivers\sbhr.sys&lt;BR&gt;2008-05-15 23:21 . 2008-05-15 23:21 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\All Users\Application Data\Sunbelt Software&lt;BR&gt;2008-05-15 23:20 . 2008-05-16 00:06 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\CounterSpy&lt;BR&gt;2008-05-15 21:41 . 2008-05-15 21:42 133,120 --a------ C:\WINDOWS\system32\feqbfrob.dll&lt;BR&gt;2008-05-15 21:40 . 2008-05-15 21:40 0 --a------ C:\WINDOWS\BMc303b894.xml&lt;BR&gt;2008-05-15 10:32 . 2008-05-15 10:59 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Cucusoft AVI To DVD Pro&lt;BR&gt;2008-05-15 09:37 . 2008-05-15 09:37 370,176 --a------ C:\WINDOWS\system32\yayaYsSJ.dll&lt;BR&gt;2008-05-15 09:32 . 2008-05-15 09:33 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Cucusoft Ultimate Video Converter&lt;BR&gt;2008-05-15 09:32 . 2006-09-11 04:13 409,600 --a------ C:\WINDOWS\system32\vampd.ax&lt;BR&gt;2008-05-15 09:32 . 2003-03-30 20:08 372,736 --a------ C:\WINDOWS\system32\xvid.ax&lt;BR&gt;2008-05-15 09:32 . 2008-01-25 21:06 364,544 --a------ C:\WINDOWS\system32\cdg.dll&lt;BR&gt;2008-05-15 09:32 . 2006-09-27 17:46 348,160 --a------ C:\WINDOWS\system32\cdga.dll&lt;BR&gt;2008-05-15 09:32 . 2006-07-08 04:07 114,688 --a------ C:\WINDOWS\system32\PropListCtrl.ocx&lt;BR&gt;2008-05-15 09:32 . 2006-07-17 21:42 14,909 --a------ C:\WINDOWS\system32\A_reg.reg&lt;BR&gt;2008-05-09 12:41 . 2008-05-09 12:41 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Synaptics&lt;BR&gt;2008-05-09 12:41 . 2007-12-05 16:11 177,664 --a------ C:\WINDOWS\system32\drivers\SynTP.sys&lt;BR&gt;2008-05-09 12:41 . 2007-12-05 16:12 110,592 --a------ C:\WINDOWS\system32\SynTPAPI.dll&lt;BR&gt;2008-05-09 12:41 . 2007-12-05 16:12 110,592 --a------ C:\WINDOWS\system32\SynCtrl.dll&lt;BR&gt;2008-05-09 12:41 . 2007-12-05 17:10 77,824 --a------ C:\WINDOWS\system32\SynTPCoI.dll&lt;BR&gt;2008-05-09 12:41 . 2007-12-05 16:12 73,728 --a------ C:\WINDOWS\system32\SynCOM.dll&lt;BR&gt;2008-05-09 12:41 . 2007-12-05 16:14 65,536 --a------ C:\WINDOWS\system32\SynTPFcs.dll&lt;BR&gt;2008-05-09 12:13 . 2007-03-21 13:33 1,257,566 -ra------ C:\WINDOWS\system32\dsa.dll&lt;BR&gt;2008-05-09 12:13 . 2007-03-21 13:46 254,023 --a------ C:\WINDOWS\system32\wsfwDS.dll&lt;BR&gt;2008-05-09 12:13 . 2007-03-21 13:46 249,925 --a------ C:\WINDOWS\system32\wsimd.dll&lt;BR&gt;2008-05-09 12:13 . 2007-03-21 13:33 82,017 -ra------ C:\WINDOWS\system32\dsaNac.dll&lt;BR&gt;2008-05-09 12:12 . 2008-05-09 12:12 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\ThinkPad R51&lt;BR&gt;2008-05-09 12:12 . 2007-10-26 01:20 549,184 --a------ C:\WINDOWS\system32\ar5211.sys&lt;BR&gt;2008-05-09 12:12 . 2006-08-07 14:17 118,784 --a------ C:\WINDOWS\system32\ATHCFG10.DLL&lt;BR&gt;2008-05-09 12:12 . 2007-10-26 01:20 100,996 --a------ C:\WINDOWS\system32\net5211.inf&lt;BR&gt;2008-05-09 12:12 . 2007-07-03 18:46 57,344 --a------ C:\WINDOWS\system32\wsimd.sys&lt;BR&gt;2008-05-09 12:12 . 2007-07-03 18:46 57,344 --------- C:\WINDOWS\system32\drivers\wsimd.sys&lt;BR&gt;2008-05-09 12:12 . 2007-10-29 12:47 23,501 --a------ C:\WINDOWS\system32\net5211.cat&lt;BR&gt;2008-05-09 12:12 . 2007-07-28 17:07 12,552 --a------ C:\WINDOWS\system32\wsimdp.cat&lt;BR&gt;2008-05-09 12:12 . 2007-07-28 17:07 12,129 --a------ C:\WINDOWS\system32\wsimd.cat&lt;BR&gt;2008-05-09 12:12 . 2007-07-03 18:46 5,361 --a------ C:\WINDOWS\system32\wsimdp.inf&lt;BR&gt;2008-05-09 12:12 . 2007-07-03 18:46 2,179 --a------ C:\WINDOWS\system32\wsimd.inf&lt;BR&gt;2008-05-09 11:56 . 2008-05-09 11:56 99,264 --a------ C:\WINDOWS\system32\drivers\AnyDVD.sys&lt;BR&gt;2008-05-09 09:54 . 2008-05-09 09:57 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Common Files\Ahead&lt;BR&gt;2008-05-09 09:53 . 2008-05-09 09:54 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Nero 7.8.5.0 Premium&lt;BR&gt;2008-05-04 18:48 . 2008-05-06 10:24 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Spybot S&amp;amp;D&lt;BR&gt;2008-05-04 18:48 . 2008-05-06 00:03 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search &amp;amp; Destroy&lt;BR&gt;2008-05-04 17:56 . 2008-05-04 17:56 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\KillBox&lt;BR&gt;2008-05-02 12:14 . 2008-05-02 12:17 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Kaspersky Antivirus 7&lt;BR&gt;2008-05-01 18:12 . 2008-05-01 18:12 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\ACW&lt;BR&gt;2008-05-01 14:01 . 2008-05-01 14:01 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\LocalService\Application Data\AdobeUM&lt;BR&gt;2008-05-01 12:31 . 2008-05-01 12:31 0 --a------ C:\WINDOWS\system32\SBRC.dat&lt;BR&gt;2008-05-01 12:31 . 2008-05-01 12:31 0 --a------ C:\WINDOWS\system32\SBFC.dat&lt;BR&gt;2008-05-01 12:22 . 2008-05-01 12:22 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\Chris\Application Data\Sunbelt Software&lt;BR&gt;2008-05-01 11:54 . 2006-08-24 15:56 40,832 --a------ C:\WINDOWS\system32\drivers\apusbsnt.sys&lt;BR&gt;2008-05-01 11:54 . 2005-03-15 11:11 17,920 --a------ C:\WINDOWS\system32\apintfnt.dll&lt;BR&gt;2008-05-01 11:54 . 2006-08-24 15:57 11,776 --a------ C:\WINDOWS\system32\apusbdco.dll&lt;BR&gt;2008-05-01 00:05 . 2008-02-28 13:26 1,414,440 --a------ C:\WINDOWS\system32\ShellManager310E2D762.dll&lt;BR&gt;2008-04-30 22:03 . 2008-04-30 22:17 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\SpyZooka&lt;BR&gt;2008-04-30 21:48 . 2008-04-30 21:50 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\Chris\Application Data\Mp3tag&lt;BR&gt;2008-04-30 21:47 . 2008-04-30 21:47 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Mp3tag&lt;BR&gt;2008-04-30 20:27 . 2008-05-03 08:28 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Virtual DJ Pro 5&lt;BR&gt;2008-04-30 17:50 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl&lt;BR&gt;2008-04-30 17:49 . 2008-04-30 17:50 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Java&lt;BR&gt;2008-04-30 17:46 . 2008-04-30 17:46 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Common Files\Java&lt;BR&gt;2008-04-30 13:49 . 2008-04-30 13:49 1,152 --a------ C:\WINDOWS\system32\windrv.sys&lt;BR&gt;2008-04-30 13:14 . 2008-04-30 13:14 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Common Files\Wise Installation Wizard&lt;BR&gt;2008-04-30 01:49 . 2008-05-15 23:52 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\All Users\Application Data\Avira&lt;BR&gt;2008-04-29 19:26 . 2008-04-29 19:26 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\NeroInstall.bak&lt;BR&gt;2008-04-29 19:18 . 2008-05-09 09:43 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Nero&lt;BR&gt;2008-04-29 19:18 . 2008-05-02 03:31 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Common Files\Nero&lt;BR&gt;2008-04-29 19:18 . 2008-05-09 09:54 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\All Users\Application Data\Nero&lt;BR&gt;2008-04-29 19:03 . 2008-04-29 19:03 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\MagicISO&lt;BR&gt;2008-04-28 19:29 . 2008-04-28 19:29 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\CCleaner&lt;BR&gt;2008-04-27 22:44 . 2008-04-30 21:02 &amp;lt;DIR&amp;gt; d-------- C:\WINDOWS\RegCure&lt;BR&gt;2008-04-27 22:44 . 2008-04-30 21:02 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\RegCure&lt;BR&gt;2008-04-26 17:18 . 2008-04-26 17:18 0 --a------ C:\WINDOWS\nsreg.dat&lt;BR&gt;2008-04-24 12:05 . 2008-04-24 12:28 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\QuickTax 2007&lt;BR&gt;2008-04-24 12:05 . 2008-04-24 12:05 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Common Files\Intuit&lt;BR&gt;2008-04-24 12:05 . 2008-04-24 12:05 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Common Files\AnswerWorks 4.0&lt;BR&gt;2008-04-24 12:05 . 2008-04-24 12:05 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\Chris\Application Data\Intuit Canada&lt;BR&gt;2008-04-24 12:03 . 2008-04-24 12:03 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\All Users\Application Data\Intuit Canada&lt;BR&gt;2008-04-22 23:13 . 2008-04-22 23:13 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\Chris\Application Data\GTek&lt;BR&gt;2008-04-22 23:13 . 2008-04-22 23:13 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\All Users\Application Data\Gtek&lt;BR&gt;2008-04-22 23:13 . 2008-04-22 23:13 5,248 --a------ C:\WINDOWS\system32\OEMINFO.PNF&lt;/P&gt;&lt;P&gt;.&lt;BR&gt;((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;BR&gt;2008-07-12 20:12 --------- d-----w C:\Program Files\Azureus&lt;BR&gt;2008-05-16 16:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab&lt;BR&gt;2008-05-16 04:32 --------- d-----w C:\Program Files\XoftSpy SE&lt;BR&gt;2008-05-16 00:12 --------- d-----w C:\Program Files\Windows Media Connect 2&lt;BR&gt;2008-05-15 16:34 --------- d-----w C:\Documents and Settings\Chris\Application Data\Azureus&lt;BR&gt;2008-05-15 04:21 --------- d-----w C:\Program Files\AnyDVD&lt;BR&gt;2008-05-09 18:12 --------- d--h--w C:\Program Files\InstallShield Installation Information&lt;BR&gt;2008-05-09 18:01 --------- d-----w C:\Program Files\ThinkPad&lt;BR&gt;2008-05-05 20:07 --------- d-----w C:\Program Files\Soulseek&lt;BR&gt;2008-05-02 18:38 96,256 ----a-w C:\WINDOWS\system32\drivers\sptd6637.sys&lt;BR&gt;2008-05-01 22:02 --------- d-----w C:\Program Files\Power ISO&lt;BR&gt;2008-04-30 19:17 --------- d-----w C:\Program Files\SUPERAntiSpyware&lt;BR&gt;2008-04-30 19:16 --------- d-----w C:\Documents and Settings\Chris\Application Data\SUPERAntiSpyware.com&lt;BR&gt;2008-04-29 22:34 --------- d-----w C:\Program Files\Common Files\Macrovision Shared&lt;BR&gt;2008-04-25 05:02 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP&lt;BR&gt;2008-04-15 22:15 --------- d-----w C:\Program Files\Native Instruments&lt;BR&gt;2008-04-15 22:13 --------- d-----w C:\Program Files\Syncrosoft&lt;BR&gt;2008-04-15 21:52 --------- d-----w C:\Program Files\Games&lt;BR&gt;2008-04-14 18:02 --------- d-----w C:\Program Files\DivX&lt;BR&gt;2008-04-09 05:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help&lt;BR&gt;2008-04-06 11:27 --------- d-----w C:\Program Files\Microsoft IntelliPoint&lt;BR&gt;2008-04-04 04:39 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2&lt;BR&gt;2008-04-03 05:41 3,532 ----a-w C:\drmHeader.bin&lt;BR&gt;2008-04-03 04:18 --------- d-----w C:\Program Files\Windows Live&lt;BR&gt;2008-04-03 04:16 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller&lt;BR&gt;2008-04-03 04:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller&lt;BR&gt;2007-07-23 18:50 39,832 ----a-w C:\Documents and Settings\Chris\Application Data\GDIPFONTCACHEV1.DAT&lt;BR&gt;2007-02-06 00:11 87,608 ----a-w C:\Documents and Settings\Chris\Application Data\ezpinst.exe&lt;BR&gt;2007-02-06 00:11 47,360 ----a-w C:\Documents and Settings\Chris\Application Data\pcouffin.sys&lt;BR&gt;2006-10-10 13:25 14 ----a-w C:\Documents and Settings\Chris\getfile.dat&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;BR&gt;.&lt;BR&gt;*Note* empty entries &amp;amp; legit default entries are not shown &lt;BR&gt;REGEDIT4&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{14370F76-7676-44A2-AD11-93A31C5FC9FC}]&lt;BR&gt;   C:\WINDOWS\system32\ljJARkKA.dll&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AA07D05F-5465-41ED-A457-3516E108D6BC}]&lt;BR&gt;2008-05-15 09:37 370176 --a------ C:\WINDOWS\system32\yayaYsSJ.dll&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{f591201f-dc78-4126-8875-ce6b8b2117cd}]&lt;BR&gt;2008-05-15 21:42 133120 --a------ C:\WINDOWS\system32\feqbfrob.dll&lt;/P&gt;&lt;P&gt;[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;BR&gt;"P2kAutostart"="" []&lt;BR&gt;"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [ ]&lt;BR&gt;"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]&lt;BR&gt;"AnyDVD"="C:\Program Files\AnyDVD\AnyDVDtray.exe" [2008-05-13 12:41 2091968]&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;BR&gt;"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20 866584]&lt;BR&gt;"TotalRecorderScheduler"="C:\Program Files\Total Recorder Professional 6\TotRecSched.exe" [2006-05-12 02:32 86016]&lt;BR&gt;"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2007-12-05 16:14 122880]&lt;BR&gt;"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-05 16:14 524288]&lt;BR&gt;"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]&lt;BR&gt;"SBCSTray"="C:\Program Files\CounterSpy\SBCSTray.exe" [2007-12-21 15:30 698864]&lt;BR&gt;"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 18:53 153136]&lt;BR&gt;"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [ ]&lt;BR&gt;"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2004-06-03 02:50 204800]&lt;BR&gt;"CTxfiHlp"="CTXFIHLP.EXE" [2006-08-11 15:56 18944 C:\WINDOWS\system32\CTXFIHLP.EXE]&lt;BR&gt;"CTHelper"="CTHELPER.EXE" [2006-08-11 15:56 17920 C:\WINDOWS\CTHELPER.EXE]&lt;BR&gt;"BMMGAG"="C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll" [2005-04-20 02:38 110592]&lt;BR&gt;"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 01:56 110592 C:\WINDOWS\system32\bthprops.cpl]&lt;BR&gt;"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-05-16 01:37 262401]&lt;BR&gt;"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2007-02-06 21:00 344064]&lt;/P&gt;&lt;P&gt;[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]&lt;BR&gt;"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2006-10-26 19:48 434528]&lt;/P&gt;&lt;P&gt;[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]&lt;BR&gt;"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]&lt;BR&gt;"{14370F76-7676-44A2-AD11-93A31C5FC9FC}"= C:\WINDOWS\system32\ljJARkKA.dll [ ]&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]&lt;BR&gt;C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ljJARkKA]&lt;BR&gt;ljJARkKA.dll&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]&lt;BR&gt;tphklock.dll 2005-06-16 23:23 24576 C:\WINDOWS\system32\tphklock.dll&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]&lt;BR&gt;"mixer"= DrvTrNTm.dll&lt;BR&gt;"wave"= DrvTrNTm.dll&lt;BR&gt;"VIDC.ZMBV"= zmbv.dll&lt;/P&gt;&lt;P&gt;[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]&lt;BR&gt;"%windir%\\system32\\sessmgr.exe"=&lt;BR&gt;"C:\\StubInstaller.exe"=&lt;BR&gt;"C:\\Program Files\\Azureus\\Azureus.exe"=&lt;BR&gt;"C:\\Program Files\\Soulseek\\slsk.exe"=&lt;BR&gt;"C:\\Program Files\\Games\\Kyodai Mahjongg 2006\\kmj.exe"=&lt;BR&gt;"C:\\Program Files\\Motorola\\Software Update\\msu.exe"=&lt;BR&gt;"C:\\Program Files\\Motorola Phone Tools\\mPhonetools.exe"=&lt;BR&gt;"C:\\Program Files\\Internet Explorer\\iexplore.exe"=&lt;BR&gt;"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=&lt;BR&gt;"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=&lt;/P&gt;&lt;P&gt;[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]&lt;BR&gt;"6346:TCP"= 6346:TCP:LimeWire UDP&lt;BR&gt;"6881:TCP"= 6881:TCP:Azureus TCP&lt;BR&gt;"6881:UDP"= 6881:UDP:Azureus UDP&lt;BR&gt;"1700:TCP"= 1700:TCP:MioNet Remote Drive Access 0&lt;BR&gt;"1701:TCP"= 1701:TCP:MioNet Remote Drive Access 1&lt;BR&gt;"1702:TCP"= 1702:TCP:MioNet Remote Drive Access 2&lt;BR&gt;"1703:TCP"= 1703:TCP:MioNet Remote Drive Access 3&lt;BR&gt;"1704:TCP"= 1704:TCP:MioNet Remote Drive Access 4&lt;BR&gt;"1705:TCP"= 1705:TCP:MioNet Remote Drive Access 5&lt;BR&gt;"1706:TCP"= 1706:TCP:MioNet Remote Drive Access 6&lt;BR&gt;"1707:TCP"= 1707:TCP:MioNet Remote Drive Access 7&lt;BR&gt;"1708:TCP"= 1708:TCP:MioNet Remote Drive Access 8&lt;BR&gt;"1709:TCP"= 1709:TCP:MioNet Remote Drive Access 9&lt;BR&gt;"1641:TCP"= 1641:TCP:MioNet Remote Drive Verification&lt;BR&gt;"1647:TCP"= 1647:TCP:MioNet Storage Device Configuration&lt;BR&gt;"5432:UDP"= 5432:UDP:MioNet Storage Device Discovery&lt;/P&gt;&lt;P&gt;R0 SBHR;SBHR;C:\WINDOWS\system32\drivers\sbhr.sys [2008-05-15 23:22]&lt;BR&gt;R1 TPPWR;TPPWR;C:\WINDOWS\system32\drivers\Tppwr.sys [2005-04-20 02:38]&lt;BR&gt;R2 McciCMService;McciCMService;"C:\Program Files\Common Files\Motive\McciCMService.exe" [2007-09-26 11:43]&lt;BR&gt;R2 SwiWiFiComm;SwiWiFiComm;C:\Program Files\Sierra Wireless\AirCard 580\Generic\Components\swiwificomm.exe [2007-03-16 15:50]&lt;BR&gt;R3 apusbsnt;Sierra Wireless USB Modem Device Driver;C:\WINDOWS\system32\DRIVERS\apusbsnt.sys [2006-08-24 15:56]&lt;BR&gt;R3 WSIMD;wsimd Service;C:\WINDOWS\system32\DRIVERS\wsimd.sys [2007-07-03 18:46]&lt;BR&gt;S3 atinysxx;ATI USB 2.0 TV Audio Crossbar;C:\WINDOWS\system32\DRIVERS\atinysxx.sys [2005-01-25 20:36]&lt;BR&gt;S3 atinyvxx;ATI TV WONDER USB2.0 Video &amp;amp; Audio;C:\WINDOWS\system32\DRIVERS\atinyvxx.sys [2005-01-25 20:36]&lt;BR&gt;S3 ATITUNEP2;ATI TV WONDER USB2.0 TV Tuner;C:\WINDOWS\system32\DRIVERS\atinyuxx.sys [2005-01-25 20:37]&lt;BR&gt;S3 ATIUTD;ATI TV WONDER USB2.0 Device Driver;C:\WINDOWS\system32\Drivers\ATIUTD.sys [2005-01-25 20:37]&lt;BR&gt;S3 MotDev;Motorola Inc. USB Device;C:\WINDOWS\system32\DRIVERS\motodrv.sys [2007-10-10 17:41]&lt;BR&gt;S3 MREMP50;MREMP50 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS [2007-09-26 11:43]&lt;BR&gt;S3 MREMP50a64;MREMP50a64 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS []&lt;BR&gt;S3 MRESP50;MRESP50 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS [2007-09-26 11:43]&lt;BR&gt;S3 MRESP50a64;MRESP50a64 NDIS Protocol Driver;C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS []&lt;BR&gt;S3 SBAPIFS;SBAPIFS;C:\WINDOWS\system32\drivers\sbapifs.sys []&lt;BR&gt;S3 TTDec;ATI TV WONDER USB2.0 Teletext Decoder;C:\WINDOWS\system32\DRIVERS\atinyttx.sys [2005-01-25 20:33]&lt;/P&gt;&lt;P&gt;.&lt;BR&gt;Contents of the 'Scheduled Tasks' folder&lt;BR&gt;"2006-03-11 10:42:52 C:\WINDOWS\Tasks\BMMTask.job"&lt;BR&gt;- C:\PROGRA~1\ThinkPad\UTILIT~1\BMMTASK.EXE&lt;BR&gt;"2008-05-16 17:54:44 C:\WINDOWS\Tasks\MP Scheduled Scan.job"&lt;BR&gt;- C:\Program Files\Windows Defender\MpCmdRun.exe&lt;BR&gt;"2008-05-16 17:51:33 C:\WINDOWS\Tasks\RegCure Program Check.job"&lt;BR&gt;- C:\Program Files\RegCure\RegCure.exe&lt;BR&gt;"2008-05-15 09:00:00 C:\WINDOWS\Tasks\RegCure.job"&lt;BR&gt;- C:\Program Files\RegCure\RegCure.exe&lt;BR&gt;"2005-06-06 04:59:37 C:\WINDOWS\Tasks\XoftSpy.job"&lt;BR&gt;- C:\Program Files\XoftSpy 4\XoftSpy.exe&lt;BR&gt;"2008-05-16 17:51:33 C:\WINDOWS\Tasks\XoftSpySE 2.job"&lt;BR&gt;- C:\Program Files\XoftSpy SE\XoftSpy.exe&lt;BR&gt;"2008-05-10 10:00:00 C:\WINDOWS\Tasks\XoftSpySE.job"&lt;BR&gt;- C:\Program Files\XoftSpy SE\XoftSpy.exe&lt;BR&gt;.&lt;BR&gt;**************************************************************************&lt;BR&gt;scanning hidden processes ... &lt;/P&gt;&lt;P&gt;scanning hidden autostart entries ...&lt;/P&gt;&lt;P&gt;scanning hidden files ... &lt;/P&gt;&lt;P&gt;scan completed successfully&lt;BR&gt;hidden files: &lt;/P&gt;&lt;P&gt;**************************************************************************&lt;BR&gt;.&lt;BR&gt;--------------------- DLLs Loaded Under Running Processes ---------------------&lt;/P&gt;&lt;P&gt;PROCESS: C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;-&amp;gt; C:\WINDOWS\system32\tphklock.dll&lt;BR&gt;.&lt;BR&gt;------------------------ Other Running Processes ------------------------&lt;BR&gt;.&lt;BR&gt;C:\WINDOWS\system32\ibmpmsvc.exe&lt;BR&gt;C:\WINDOWS\system32\ati2evxx.exe&lt;BR&gt;C:\Program Files\Windows Defender\MsMpEng.exe&lt;BR&gt;C:\WINDOWS\system32\S24EvMon.exe&lt;BR&gt;C:\WINDOWS\system32\ati2evxx.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe&lt;BR&gt;C:\WINDOWS\system32\acs.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe&lt;BR&gt;C:\WINDOWS\system32\RegSrvc.exe&lt;BR&gt;C:\WINDOWS\system32\rundll32.exe&lt;BR&gt;C:\WINDOWS\system32\rundll32.exe&lt;BR&gt;.&lt;BR&gt;**************************************************************************&lt;BR&gt;.&lt;BR&gt;Completion time: 2008-05-16 11:58:58 - machine was rebooted&lt;BR&gt;ComboFix-quarantined-files.txt  2008-05-16 17:58:52&lt;BR&gt;ComboFix2.txt  2008-05-01 00:15:51&lt;/P&gt;&lt;P&gt;Pre-Run: 5,194,858,496 bytes free&lt;BR&gt;Post-Run: 5,618,933,760 bytes free&lt;/P&gt;&lt;P&gt;276 --- E O F --- 2008-05-12 16:11:25&lt;BR&gt;&lt;/P&gt;&lt;P&gt;__________________________________________________________________&lt;/P&gt;&lt;P&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 12:02:06 PM, on 5/16/2008&lt;BR&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;BR&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16640)&lt;BR&gt;Boot mode: Normal&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\WINDOWS\System32\smss.exe&lt;BR&gt;C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;C:\WINDOWS\system32\services.exe&lt;BR&gt;C:\WINDOWS\system32\lsass.exe&lt;BR&gt;C:\WINDOWS\system32\ibmpmsvc.exe&lt;BR&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\Program Files\Windows Defender\MsMpEng.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\S24EvMon.exe&lt;BR&gt;C:\WINDOWS\system32\Ati2evxx.exe&lt;BR&gt;C:\WINDOWS\system32\spoolsv.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe&lt;BR&gt;C:\WINDOWS\system32\acs.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe&lt;BR&gt;C:\Program Files\Common Files\Motive\McciCMService.exe&lt;BR&gt;C:\WINDOWS\System32\RegSrvc.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\Program Files\Sierra Wireless\AirCard 580\Generic\Components\swiwificomm.exe&lt;BR&gt;C:\Program Files\Windows Defender\MSASCui.exe&lt;BR&gt;C:\Program Files\Total Recorder Professional 6\TotRecSched.exe&lt;BR&gt;C:\Program Files\Synaptics\SynTP\SynTPLpr.exe&lt;BR&gt;C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&lt;BR&gt;C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe&lt;BR&gt;C:\Program Files\CounterSpy\SBCSTray.exe&lt;BR&gt;C:\Program Files\Microsoft IntelliPoint\point32.exe&lt;BR&gt;C:\WINDOWS\CTHELPER.EXE&lt;BR&gt;C:\WINDOWS\system32\RunDll32.exe&lt;BR&gt;C:\WINDOWS\system32\rundll32.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe&lt;BR&gt;C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;C:\Program Files\AnyDVD\AnyDVDtray.exe&lt;BR&gt;C:\WINDOWS\system32\wuauclt.exe&lt;BR&gt;C:\WINDOWS\explorer.exe&lt;BR&gt;C:\WINDOWS\system32\notepad.exe&lt;BR&gt;C:\Program Files\Outlook Express\msimn.exe&lt;BR&gt;C:\Program Files\Internet Explorer\IEXPLORE.EXE&lt;BR&gt;C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe&lt;BR&gt;C:\WINDOWS\system32\wuauclt.exe&lt;BR&gt;C:\Program Files\HijackThis\HijackThis.exe&lt;/P&gt;&lt;P&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://www.ebay.com"&gt;http://www.ebay.com&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://www.ebay.com"&gt;http://www.ebay.com&lt;/A&gt;&lt;BR&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = &lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = &lt;BR&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = &lt;BR&gt;O2 - BHO: (no name) - {14370F76-7676-44A2-AD11-93A31C5FC9FC} - C:\WINDOWS\system32\ljJARkKA.dll (file missing)&lt;BR&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;BR&gt;O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll&lt;BR&gt;O2 - BHO: (no name) - {AA07D05F-5465-41ED-A457-3516E108D6BC} - C:\WINDOWS\system32\yayaYsSJ.dll&lt;BR&gt;O2 - BHO: {dc7112b8-b6ec-5788-6214-87cdf102195f} - {f591201f-dc78-4126-8875-ce6b8b2117cd} - C:\WINDOWS\system32\feqbfrob.dll&lt;BR&gt;O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide&lt;BR&gt;O4 - HKLM\..\Run: [TotalRecorderScheduler] "C:\Program Files\Total Recorder Professional 6\TotRecSched.exe"&lt;BR&gt;O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe&lt;BR&gt;O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe&lt;BR&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"&lt;BR&gt;O4 - HKLM\..\Run: [SBCSTray] C:\Program Files\CounterSpy\SBCSTray.exe&lt;BR&gt;O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe&lt;BR&gt;O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"&lt;BR&gt;O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"&lt;BR&gt;O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE&lt;BR&gt;O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE&lt;BR&gt;O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor&lt;BR&gt;O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent&lt;BR&gt;O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min&lt;BR&gt;O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe&lt;BR&gt;O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020&lt;BR&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\AnyDVD\AnyDVDtray.exe&lt;BR&gt;O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')&lt;BR&gt;O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')&lt;BR&gt;O8 - Extra context menu item: &amp;amp;Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm&lt;BR&gt;O8 - Extra context menu item: &amp;amp;Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm&lt;BR&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000&lt;BR&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;BR&gt;O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - &lt;A href="http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab"&gt;http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {22E5D91F-89E6-4405-AD9C-0AF27BA6F06B} (HidInputMonitorX Control) - &lt;A href="file:///D:/components/hidinputmonitorx.ocx"&gt;file:///D:/components/hidinputmonitorx.ocx&lt;/A&gt;&lt;BR&gt;O16 - DPF: {2DAD3559-2923-4935-AD49-B673D2539944} (IASRunner Class) - &lt;A href="https://www-307.ibm.com/pc/support/access/aslibmain/content/AcpIR.cab"&gt;https://www-307.ibm.com/pc/support/access/aslibmain/content/AcpIR.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - &lt;A href="http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab"&gt;http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {4F63D44B-6274-4D60-8AB1-CAA7116B8AF3} (A9Helper.A9) - &lt;A href="file:///D:/components/A9.ocx"&gt;file:///D:/components/A9.ocx&lt;/A&gt;&lt;BR&gt;O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - &lt;A href="http://upload.facebook.com/controls/FacebookPhotoUploader.cab"&gt;http://upload.facebook.com/controls/FacebookPhotoUploader.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &lt;A href="http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1107394181500"&gt;http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1107394181500&lt;/A&gt;&lt;BR&gt;O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - &lt;A href="http://download.divx.com/player/DivXBrowserPlugin.cab"&gt;http://download.divx.com/player/DivXBrowserPlugin.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {7030CC6C-1A88-4591-BB5A-651B9F7F0C30} (WMVHDRatingCtrl Class) - &lt;A href="file:///D:/components/wmvhdrating.ocx"&gt;file:///D:/components/wmvhdrating.ocx&lt;/A&gt;&lt;BR&gt;O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - &lt;A href="http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab"&gt;http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - &lt;A href="http://support.f-secure.com/ols/fscax.cab"&gt;http://support.f-secure.com/ols/fscax.cab&lt;/A&gt;&lt;BR&gt;O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - &lt;A href="http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab"&gt;http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab&lt;/A&gt;&lt;BR&gt;O17 - HKLM\System\CCS\Services\Tcpip\..\{62EC955C-255C-405C-A396-1967C4580BEB}: NameServer = 204.174.120.45 204.174.120.46&lt;BR&gt;O18 - Protocol: intu-qt2007 - {026BF40D-BA05-467B-9F1F-AD0D7A3F5F11} - C:\Program Files\QuickTax 2007\ic2007pp.dll&lt;BR&gt;O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll&lt;BR&gt;O20 - Winlogon Notify: ljJARkKA - ljJARkKA.dll (file missing)&lt;BR&gt;O23 - Service: Atheros Configuration Service (acs) - Atheros - C:\WINDOWS\system32\acs.exe&lt;BR&gt;O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe&lt;BR&gt;O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe&lt;BR&gt;O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe&lt;BR&gt;O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe&lt;BR&gt;O23 - Service: ##I