combofix log:
ComboFix 08-02-25.3 - Jenny 2008-02-29 14:13:53.3 - NTFSx86
Running from: C:\Documents and Settings\Jenny\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Jenny\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\DOCUME~1\Jenny\LOCALS~1\Temp\asbp2poa.sys
C:\Documents and Settings\Jenny\Application Data\DownloadPlus.exe
C:\WINDOWS\svcproc.exe
C:\WINDOWS\System32\Msvrl.dll
c:\windows\system32\sluixbb.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Jenny\Application Data\DownloadPlus.exe
.
((((((((((((((((((((((((( Files Created from 2008-01-28 to 2008-02-29 )))))))))))))))))))))))))))))))
.
2008-02-27 14:19 . 2008-02-27 14:19 d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-02-27 14:19 . 2008-02-29 13:31 d-------- C:\Documents and Settings\Jenny\Application Data\AVG7
2008-02-27 14:18 . 2008-02-27 14:18 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-27 14:18 . 2008-02-28 11:28 d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-02-26 17:46 . 2008-02-26 17:46 d-------- C:\Program Files\Common Files\xing shared
2008-02-25 16:42 . 2008-02-25 16:42 d-------- C:\Program Files\AsmwSoft
2008-02-25 16:42 . 1998-01-31 13:25 133,120 --a------ C:\WINDOWS\system32\zip32.dll
2008-02-25 16:42 . 2004-03-09 00:00 124,688 --a------ C:\WINDOWS\system32\Mswinsck.ocx
2008-02-25 16:42 . 2004-05-27 01:32 102,400 --a------ C:\WINDOWS\system32\Unzip32.dll
2008-02-25 16:42 . 1999-04-25 09:37 77,824 --a------ C:\WINDOWS\system32\Alafile.ocx
2008-02-25 12:01 . 2002-08-29 12:00 1,688 --a------ C:\WINDOWS\system32\autoexec.nt
2008-02-14 22:51 . 2008-02-14 22:51 d-------- C:\Park
2008-02-14 21:03 . 2008-02-15 21:16 d-------- C:\Program Files\DOSBox-0.65
2008-02-14 20:21 . 2008-02-14 20:40 d-------- C:\Program Files\BitLord
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-26 17:46 --------- d-----w C:\Program Files\Real
2008-02-26 17:45 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-02-26 17:45 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-02-26 17:45 --------- d-----w C:\Program Files\Common Files\Real
2008-02-26 16:58 --------- d-----w C:\Program Files\Google
2008-02-26 11:32 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-02-14 22:29 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-13 16:50 28,218 ----a-w C:\Documents and Settings\adam\Application Data\wklnhst.dat
2008-01-17 14:08 --------- d-----w C:\Documents and Settings\Guest\Application Data\Teleca
2008-01-17 14:07 --------- d-----w C:\Program Files\Xerox One Touch
2008-01-15 00:09 38,656 ----a-w C:\Documents and Settings\Jenny\Application Data\wklnhst.dat
2007-12-07 02:21 824,832 ----a-w C:\WINDOWS\system32\wininet.dll
2007-12-04 18:38 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
2006-07-26 11:32 74,192 ----a-w C:\Documents and Settings\adam\Application Data\GDIPFONTCACHEV1.DAT
2006-05-22 11:43 74,192 ----a-w C:\Documents and Settings\Jenny\Application Data\GDIPFONTCACHEV1.DAT
2003-07-15 15:33 225,280 ----a-w C:\WINDOWS\inf\i386\rtscan.dll
2002-10-09 10:11 61,440 ----a-w C:\WINDOWS\inf\i386\onetUSD.dll
2002-08-23 15:06 13,824 ----a-w C:\WINDOWS\inf\i386\Usbscan.sys
2002-07-09 09:23 36,864 ----a-w C:\WINDOWS\inf\i386\Vizmicro.dll
2002-05-20 09:20 172,032 ----a-w C:\WINDOWS\inf\i386\viceo.dll
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of C:\Park ----
2008-02-15 21:54 304668 --a------ C:\Park\SAVE\CRAIG.G0
2008-02-15 21:51 304668 --a------ C:\Park\SAVE\CRAIG.GY
2008-02-15 13:52 141 --a------ C:\Park\SAVE\CRAIG.GD
2006-07-25 21:05 304668 --a------ C:\Park\SAVE\JAREK.GY
2006-07-25 21:04 141 --a------ C:\Park\SAVE\JAREK.GD
2006-07-24 18:33 304668 --a------ C:\Park\SAVE\BLEEE.GY
2006-07-24 18:31 141 --a------ C:\Park\SAVE\BLEEE.GD
2004-08-14 04:04 50 --a------ C:\Park\SNDSETUP.INF
1994-06-17 14:34 30912 --a------ C:\Park\DATA\LANG0-0.DAT
1994-06-14 09:58 841223 --a------ C:\Park\TP.EXE
1994-06-14 08:02 90758 --a------ C:\Park\SETUP.EXE
1994-06-14 05:54 33895 --a------ C:\Park\DATA\LANG3-0.DAT
1994-06-13 12:08 35245 --a------ C:\Park\DATA\LANG4-0.DAT
1994-06-13 12:08 30531 --a------ C:\Park\DATA\LANG2-0.DAT
1994-06-13 12:07 36592 --a------ C:\Park\DATA\LANG1-0.DAT
1994-06-11 14:38 64000 --a------ C:\Park\DATA\MSTATE-0.DAT
1994-06-11 09:43 987204 --a------ C:\Park\DATA\RIDEANI.026
1994-06-11 09:16 6994068 --a------ C:\Park\DATA\RIDEANI.009
1994-06-10 15:47 5836494 --a------ C:\Park\DATA\RIDEANI.012
1994-06-10 15:21 7429352 --a------ C:\Park\DATA\RIDEANI.002
1994-06-10 14:47 2512644 --a------ C:\Park\DATA\RIDEANI.003
1994-06-10 14:33 6782968 --a------ C:\Park\DATA\RIDEANI.000
1994-06-10 13:23 2771272 --a------ C:\Park\DATA\RIDEANI.013
1994-06-10 11:31 736 --a------ C:\Park\DATA\MUSIC0-1.TAB
1994-06-10 11:31 736 --a------ C:\Park\DATA\MUSIC0-0.TAB
1994-06-10 11:31 107424 --a------ C:\Park\DATA\MUSIC0-0.DAT
1994-06-10 11:31 103888 --a------ C:\Park\DATA\MUSIC0-1.DAT
1994-06-10 10:49 736 --a------ C:\Park\DATA\MUSIC0-2.TAB
1994-06-10 10:49 108976 --a------ C:\Park\DATA\MUSIC0-2.DAT
1994-06-10 10:11 2225274 --a------ C:\Park\DATA\WINGAME.DAT
1994-06-06 14:29 304668 --a------ C:\Park\SAVE\DEMO.GY
1994-06-03 16:23 989499 --a------ C:\Park\DATA\MSPR-0.DAT
1994-06-03 16:23 19806 --a------ C:\Park\DATA\MSPR-0.TAB
1994-06-03 16:22 74120 --a------ C:\Park\DATA\MELE-0.ANI
1994-06-03 16:22 45640 --a------ C:\Park\DATA\MFRA-0.ANI
1994-06-03 16:22 246187 --a------ C:\Park\DATA\MEDIT-0.ANI
1994-06-03 16:22 1388 --a------ C:\Park\DATA\MSTA-0.ANI
1994-06-03 15:25 96988 --a------ C:\Park\DATA\HPANEL-0.DAT
1994-06-03 15:25 8 --a------ C:\Park\DATA\MREQ-0.INF
1994-06-03 15:25 768 --a------ C:\Park\DATA\MPALETTE.DAT
1994-06-03 15:25 504 --a------ C:\Park\DATA\MPANEL-0.TAB
1994-06-03 15:25 504 --a------ C:\Park\DATA\HPANEL-0.TAB
1994-06-03 15:25 3421 --a------ C:\Park\DATA\MPOINTER.DAT
1994-06-03 15:25 27149 --a------ C:\Park\DATA\MREQ-0.DAT
1994-06-03 15:25 26522 --a------ C:\Park\DATA\MPANEL-0.DAT
1994-06-03 15:25 1554 --a------ C:\Park\DATA\MREQ-0.TAB
1994-06-03 15:25 1464 --a------ C:\Park\DATA\MBLK-0.TAB
1994-06-03 15:25 126 --a------ C:\Park\DATA\MPOINTER.TAB
1994-06-03 15:25 112 --a------ C:\Park\DATA\MSPR-0.INF
1994-06-03 15:25 104623 --a------ C:\Park\DATA\MBLK-0.DAT
1994-06-03 15:24 8441 --a------ C:\Park\DATA\MRSSPR-0.DAT
1994-06-03 15:24 768 --a------ C:\Park\DATA\MSTPAL-0.DAT
1994-06-03 15:24 768 --a------ C:\Park\DATA\MSTAP-0.DAT
1994-06-03 15:24 768 --a------ C:\Park\DATA\MRSPAL-0.DAT
1994-06-03 15:24 768 --a------ C:\Park\DATA\MNGPAL-0.DAT
1994-06-03 15:24 768 --a------ C:\Park\DATA\MGLPAL-0.DAT
1994-06-03 15:24 768 --a------ C:\Park\DATA\MAWPAL-0.DAT
1994-06-03 15:24 7411 --a------ C:\Park\DATA\MSTSPR-0.DAT
1994-06-03 15:24 66 --a------ C:\Park\DATA\MPLAY-0.TAB
1994-06-03 15:24 64000 --a------ C:\Park\DATA\MSTOCK-0.DAT
1994-06-03 15:24 64000 --a------ C:\Park\DATA\MSHARE-0.DAT
1994-06-03 15:24 64000 --a------ C:\Park\DATA\MRES-0.DAT
1994-06-03 15:24 64000 --a------ C:\Park\DATA\MNEG-0.DAT
1994-06-03 15:24 64000 --a------ C:\Park\DATA\MMENU-1.DAT
1994-06-03 15:24 64000 --a------ C:\Park\DATA\MMENU-0.DAT
1994-06-03 15:24 64000 --a------ C:\Park\DATA\MMAP-0.DAT
1994-06-03 15:24 64000 --a------ C:\Park\DATA\MGLOBE-0.DAT
1994-06-03 15:24 64000 --a------ C:\Park\DATA\MAWAR1-0.DAT
1994-06-03 15:24 64000 --a------ C:\Park\DATA\MAWAR0-0.DAT
1994-06-03 15:24 64000 --a------ C:\Park\DATA\MAUCT-0.DAT
1994-06-03 15:24 4999 --a------ C:\Park\DATA\MPLAY-0.DAT
1994-06-03 15:24 360 --a------ C:\Park\DATA\MHAND-0.TAB
1994-06-03 15:24 23781 --a------ C:\Park\DATA\MCUP-0.DAT
1994-06-03 15:24 21842 --a------ C:\Park\DATA\MAUSPR-0.DAT
1994-06-03 15:24 180 --a------ C:\Park\DATA\MSTSPR-0.TAB
1994-06-03 15:24 168 --a------ C:\Park\DATA\MCUP-0.TAB
1994-06-03 15:24 156 --a------ C:\Park\DATA\MRSSPR-0.TAB
1994-06-03 15:24 119573 --a------ C:\Park\DATA\MHAND-0.DAT
1994-06-03 15:24 102 --a------ C:\Park\DATA\MAUSPR-0.TAB
1994-06-03 10:57 131920 --a------ C:\Park\DATA\MSTAPAL-.DAT
1994-06-02 15:02 630 --a------ C:\Park\DATA\MFONT-0.TAB
1994-06-02 15:02 12472 --a------ C:\Park\DATA\MFONT-0.DAT
1994-06-02 09:21 2617 --a------ C:\Park\HMIMDRV.386
1994-06-02 05:48 74120 --a------ C:\Park\DATA\MSELE-0.ANI
1994-06-01 07:27 42061 --a------ C:\Park\HMIDET.386
1994-06-01 07:18 186165 --a------ C:\Park\HMIDRV.386
1994-05-31 17:00 265396 --a------ C:\Park\DOS4GW.EXE
1994-05-23 07:17 625472 --a------ C:\Park\DATA\SNDS0-0.DAT
1994-05-23 07:17 622624 --a------ C:\Park\DATA\SNDS1-0.DAT
1994-05-23 07:17 1568 --a------ C:\Park\DATA\SNDS0-0.TAB
1994-05-23 07:17 1312 --a------ C:\Park\DATA\SNDS1-1.TAB
1994-05-23 07:17 1312 --a------ C:\Park\DATA\SNDS1-0.TAB
1994-05-23 07:17 1276560 --a------ C:\Park\DATA\SNDS1-1.DAT
1994-05-23 07:16 5056960 --a------ C:\Park\DATA\SNDS0-2.DAT
1994-05-23 07:16 5031488 --a------ C:\Park\DATA\SNDS1-2.DAT
1994-05-23 07:16 1568 --a------ C:\Park\DATA\SNDS0-2.TAB
1994-05-23 07:16 1568 --a------ C:\Park\DATA\SNDS0-1.TAB
1994-05-23 07:16 1312 --a------ C:\Park\DATA\SNDS1-2.TAB
1994-05-23 07:16 1282560 --a------ C:\Park\DATA\SNDS0-1.DAT
1994-05-16 13:43 9584 --a------ C:\Park\DATA\INTIT.DAT
1994-05-14 14:03 768 --a------ C:\Park\DATA\TAKPAL.DAT
1994-05-14 14:03 768 --a------ C:\Park\DATA\BUSPAL.DAT
1994-05-14 14:03 64034 --a------ C:\Park\DATA\TAKOVER.DAT
1994-05-14 14:03 64033 --a------ C:\Park\DATA\BUSTED.DAT
1994-05-14 14:03 200996 --a------ C:\Park\DATA\TAKOVER.ANM
1994-05-14 14:03 112582 --a------ C:\Park\DATA\BUSTED.ANM
1994-04-20 07:12 5404 --a------ C:\Park\DATA\INST.BNK
1994-04-20 07:12 5404 --a------ C:\Park\DATA\DRUM.BNK
1994-04-18 09:05 25536 --a------ C:\Park\DATA\MUSIC1-2.DAT
1994-04-18 09:05 192 --a------ C:\Park\DATA\MUSIC1-2.TAB
1994-04-18 08:24 45640 --a------ C:\Park\DATA\MDFRA-0.ANI
1994-04-18 08:24 246187 --a------ C:\Park\DATA\MDEDIT-0.ANI
1994-04-18 08:24 19580 --a------ C:\Park\DATA\MDELE-0.ANI
1994-04-18 08:24 1372 --a------ C:\Park\DATA\MDSTA-0.ANI
1994-04-15 08:41 26128 --a------ C:\Park\DATA\MUSIC1-0.DAT
1994-04-15 08:41 192 --a------ C:\Park\DATA\MUSIC1-0.TAB
1994-04-11 07:57 25760 --a------ C:\Park\DATA\MUSIC1-1.DAT
1994-04-11 07:57 192 --a------ C:\Park\DATA\MUSIC1-1.TAB
1994-03-30 05:56 722 --a------ C:\Park\DATA\INPAL.DAT
1994-03-30 05:56 334 --a------ C:\Park\DATA\MUSFRA.ANI
1994-03-30 05:56 2800 --a------ C:\Park\DATA\MUS.DAT
1994-03-30 05:56 262 --a------ C:\Park\DATA\MUS.TAB
1994-03-30 05:56 169 --a------ C:\Park\DATA\MUSELE.ANI
1994-03-04 07:09 64000 --a------ C:\Park\DATA\MIDLAND.DAT
1994-01-20 11:19 10 --a------ C:\Park\DATA\MUSSTA.ANI
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-02-26 17:44 185896]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-02-27 14:18 579072]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-27 14:18 219136]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"nousernameinstartmenu"= 0 (0x0)
"nosimplestartmenu"= 0 (0x0)
"nostartmenumfuprogramslist"= 0 (0x0)
"nostartmenumoreprograms"= 0 (0x0)
"norecentdochistory"= 0 (0x0)
"maxrecentdocs"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\system32\\LEXPPS.EXE"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\BitLord\\BitLord.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"45920:TCP"= 45920:TCP:TCP
"48623:UDP"= 48623:UDP:out
"4662:TCP"= 4662:TCP:a
"4672:UDP"= 4672:UDP:4672
"46403:TCP"= 46403:TCP:46403
"46403:UDP"= 46403:UDP:46403
"47058:TCP"= 47058:TCP:limewire in
"47058:UDP"= 47058:UDP:limewire out
R3 EL910;3Com 3CSOHO100B-TX PCI;C:\WINDOWS\system32\DRIVERS\EL910N51.sys [2003-07-11 01:54]
S2 SvcProc;System Startup Service ;C:\WINDOWS\svcproc.exe []
S3 asbp2poa;asbp2poa;C:\DOCUME~1\Jenny\LOCALS~1\Temp\asbp2poa.sys []
S3 MA8630C;MA8630C;C:\WINDOWS\system32\DRIVERS\MA8630C.sys [2004-09-14 03:12]
S3 MA8630M;MA8630M;C:\WINDOWS\system32\DRIVERS\MA8630M.sys [2005-01-25 00:31]
S3 MA8630U;MA8630U;C:\WINDOWS\system32\DRIVERS\MA8630U.sys [2005-03-14 20:10]
S3 MaRdPnp;MaRdPnp;C:\WINDOWS\system32\DRIVERS\MaRdP2K.sys [2004-09-12 20:11]
.
Contents of the 'Scheduled Tasks' folder
"2005-04-05 09:26:39 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - Jenny.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\NAVW32.EXEh/task:
"2007-12-07 20:34:40 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exeh/task:
"2008-02-25 16:45:00 C:\WINDOWS\Tasks\PcbugDoctorJenny.job"
- C:\Program Files\PCBugDoctor\PCBugDoctor.exe
"2008-02-26 17:27:40 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-29 14:21:35
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-02-29 14:24:23
ComboFix-quarantined-files.txt 2008-02-29 14:23:51
ComboFix2.txt 2008-02-27 12:50:06
.
2008-02-13 16:58:02 --- E O F ---
HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:40:34, on 29/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Grisoft\AVG7\avgw.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Jenny\My Documents\HiJackThis.exe
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O8 - Extra context menu item: &Search - http://kl.bar.need2find.com/KL/menusearch.html?p=KL
O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_07\bin\npjpi142_07.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_07\bin\npjpi142_07.dll
O9 - Extra button: DownloadMP3 - {76DD9E77-F06C-4471-AB6C-CF03C5C6B5B0} - C:\WINDOWS\System32\DownloadMP3 (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{5BAD6B91-41F1-46A8-BD9F-F2966EA21CFB}: NameServer = 194.168.4.100,194.168.8.100
O17 - HKLM\System\CS1\Services\Tcpip\..\{5BAD6B91-41F1-46A8-BD9F-F2966EA21CFB}: NameServer = 194.168.4.100,194.168.8.100
O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34545} - (no file)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing)
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
--
End of file - 6264 bytes