Combofix cont...
2007-01-06 11:16 4,096 --a------ D:\WINDOWS\system32\ksuser.dll
2007-01-06 11:16 145,792 --a------ D:\WINDOWS\system32\drivers\portcls.sys
2007-01-06 11:15 8,192 -ra------ D:\WINDOWS\system32\kbdhept.dll
2007-01-06 11:15 7,168 -ra------ D:\WINDOWS\system32\kbdcz.dll
2007-01-06 11:15 6,656 -ra------ D:\WINDOWS\system32\kbdycl.dll
2007-01-06 11:15 6,656 -ra------ D:\WINDOWS\system32\kbdsl1.dll
2007-01-06 11:15 6,656 -ra------ D:\WINDOWS\system32\kbdsl.dll
2007-01-06 11:15 6,656 -ra------ D:\WINDOWS\system32\kbdpl.dll
2007-01-06 11:15 6,656 -ra------ D:\WINDOWS\system32\kbdhu.dll
2007-01-06 11:15 6,656 -ra------ D:\WINDOWS\system32\kbdhela3.dll
2007-01-06 11:15 6,656 -ra------ D:\WINDOWS\system32\kbdcz2.dll
2007-01-06 11:15 6,656 -ra------ D:\WINDOWS\system32\kbdcz1.dll
2007-01-06 11:15 6,656 -ra------ D:\WINDOWS\system32\kbdcr.dll
2007-01-06 11:15 6,656 -ra------ D:\WINDOWS\system32\KBDAL.DLL
2007-01-06 11:15 6,144 -ra------ D:\WINDOWS\system32\kbdtuq.dll
2007-01-06 11:15 6,144 -ra------ D:\WINDOWS\system32\kbdtuf.dll
2007-01-06 11:15 6,144 -ra------ D:\WINDOWS\system32\kbdlv1.dll
2007-01-06 11:15 6,144 -ra------ D:\WINDOWS\system32\kbdlv.dll
2007-01-06 11:15 6,144 -ra------ D:\WINDOWS\system32\kbdhela2.dll
2007-01-06 11:15 6,144 -ra------ D:\WINDOWS\system32\kbdgkl.dll
2007-01-06 11:15 6,144 -ra------ D:\WINDOWS\system32\kbdest.dll
2007-01-06 11:15 5,632 -ra------ D:\WINDOWS\system32\kbdro.dll
2007-01-06 11:15 5,632 -ra------ D:\WINDOWS\system32\kbdpl1.dll
2007-01-06 11:15 5,632 -ra------ D:\WINDOWS\system32\kbdmon.dll
2007-01-06 11:15 5,632 -ra------ D:\WINDOWS\system32\kbdlt1.dll
2007-01-06 11:15 5,632 -ra------ D:\WINDOWS\system32\kbdlt.dll
2007-01-06 11:15 5,632 -ra------ D:\WINDOWS\system32\kbdkyr.dll
2007-01-06 11:15 5,632 -ra------ D:\WINDOWS\system32\kbdhu1.dll
2007-01-06 11:15 5,632 -ra------ D:\WINDOWS\system32\kbdhe319.dll
2007-01-06 11:15 5,632 -ra------ D:\WINDOWS\system32\kbdhe220.dll
2007-01-06 11:15 5,632 -ra------ D:\WINDOWS\system32\kbdhe.dll
2007-01-06 11:15 5,632 -ra------ D:\WINDOWS\system32\kbdazel.dll
2007-01-06 11:15 176,157 --a------ D:\WINDOWS\system32\dgrpsetu.dll
2007-01-06 11:15 13,312 --a------ D:\WINDOWS\system32\irclass.dll
2007-01-06 11:14 9,936 --a------ D:\WINDOWS\system\LZEXPAND.DLL
2007-01-06 11:14 9,008 --a------ D:\WINDOWS\system\VER.DLL
2007-01-06 11:14 85,020 --a------ D:\WINDOWS\system32\dgsetup.dll
2007-01-06 11:14 82,944 --a------ D:\WINDOWS\system\OLECLI.DLL
2007-01-06 11:14 8,704 --a------ D:\WINDOWS\system32\batt.dll
2007-01-06 11:14 74,752 --a------ D:\WINDOWS\system32\storprop.dll
2007-01-06 11:14 69,584 --a------ D:\WINDOWS\system\AVICAP.DLL
2007-01-06 11:14 69,120 --a------ D:\WINDOWS\NOTEPAD.EXE
2007-01-06 11:14 68,768 --a------ D:\WINDOWS\system\MMSYSTEM.DLL
2007-01-06 11:14 5,120 --a------ D:\WINDOWS\system\SHELL.DLL
2007-01-06 11:14 32,816 --a------ D:\WINDOWS\system\COMMDLG.DLL
2007-01-06 11:14 24,661 --a------ D:\WINDOWS\system32\spxcoins.dll
2007-01-06 11:14 24,064 --a------ D:\WINDOWS\system\OLESVR.DLL
2007-01-06 11:14 19,200 --a------ D:\WINDOWS\system\TAPI.DLL
2007-01-06 11:14 15,360 --a------ D:\WINDOWS\TASKMAN.EXE
2007-01-06 11:14 126,912 --a------ D:\WINDOWS\system\MSVIDEO.DLL
2007-01-06 11:14 11,264 --a------ D:\WINDOWS\system32\drivers\irenum.sys
2007-01-06 11:14 109,456 --a------ D:\WINDOWS\system\AVIFILE.DLL
2007-01-06 11:14 103,424 --a------ D:\WINDOWS\system32\EqnClass.Dll
2007-01-06 11:14 dr------- D:\DOCUME~1\ALLUSE~1.WIN\Documents
2007-01-06 11:04 d-------- D:\WINDOWS\Provisioning
2007-01-06 11:04 d-------- D:\WINDOWS\PeerNet
2007-01-06 11:00 d-------- D:\WINDOWS\setup.pss
2007-01-06 10:27 d--h----- D:\WINDOWS\$xpsp1hfm$
2007-01-06 06:23 d-------- D:\DOCUME~1\ALLUSE~1\Application Data\Windows Genuine Advantage
2007-01-06 06:19 d-------- D:\WINDOWS\system32\bits
2007-01-06 06:17 d-------- D:\WINDOWS\SoftwareDistribution
2007-01-06 06:16 d---s---- D:\DOCUME~1\Andy\UserData
2007-01-06 06:10 d-------- D:\WINDOWS\Motive
2007-01-06 06:09 d-------- D:\Program Files\ntl
2007-01-06 06:09 d-------- D:\Program Files\Motive
2007-01-06 04:31 d-------- D:\Program Files\Xvid
2007-01-06 04:08 d--hs---- D:\RECYCLED
2007-01-06 03:14 d-------- D:\Games
2007-01-06 02:19 d-------- D:\WINDOWS\pss
2007-01-06 02:14 d-------- D:\Program Files\Common Files\Motive
2007-01-06 02:11 d-------- D:\WINDOWS\RegisteredPackages
2007-01-06 02:11 d-------- D:\Program Files\BroadJump
2007-01-06 02:07 d--hs---- D:\WINDOWS\Installer
2007-01-06 02:03 d--hs---- D:\System Volume Information
2007-01-06 02:03 d-------- D:\WINDOWS\Prefetch
2007-01-06 01:59 d-------- D:\WINDOWS\system32\xircom
2007-01-06 01:59 d-------- D:\Program Files\microsoft frontpage
2007-01-06 01:58 dr------- D:\WINDOWS\Offline Web Pages
2007-01-06 01:58 d--hs---- D:\DOCUME~1\ALLUSE~1\DRM
2007-01-06 01:58 d---s---- D:\WINDOWS\Downloaded Program Files
2007-01-06 01:57 d---s---- D:\WINDOWS\Tasks
2007-01-06 01:57 d-------- D:\WINDOWS\system32\Restore
2007-01-06 01:57 d-------- D:\WINDOWS\system32\Macromed
2007-01-06 01:57 d-------- D:\WINDOWS\system32\DirectX
2007-01-06 01:57 d-------- D:\WINDOWS\srchasst
2007-01-06 01:57 d-------- D:\WINDOWS\PCHEALTH
2007-01-06 01:57 d-------- D:\Program Files\Movie Maker
2007-01-06 01:57 d-------- D:\Program Files\Common Files\MSSoap
2007-01-06 01:56 d--h----- D:\Program Files\WindowsUpdate
2007-01-06 01:56 d-------- D:\WINDOWS\system32\MsDtc
2007-01-06 01:56 d-------- D:\WINDOWS\system32\Com
2007-01-06 01:56 d-------- D:\WINDOWS\Registration
2007-01-06 01:56 d-------- D:\Program Files\Windows NT
2007-01-06 01:56 d-------- D:\Program Files\Online Services
2007-01-06 01:56 d-------- D:\Program Files\MSN Gaming Zone
2007-01-06 01:56 d-------- D:\Program Files\Messenger
2007-01-06 01:51 d-------- D:\Program Files\Common Files\SpeechEngines
2007-01-06 01:51 d-------- D:\Program Files\Common Files\ODBC
2007-01-06 01:50 dr------- D:\DOCUME~1\ALLUSE~1\Documents
2007-01-06 01:50 d-------- D:\WINDOWS\system32\CatRoot2
2007-01-06 01:50 d-------- D:\WINDOWS\system32\CatRoot
2007-01-06 01:50 d-------- D:\Documents and Settings
2007-01-06 01:47 dr-hs---- D:\WINDOWS\system32\dllcache
2007-01-06 01:47 dr--s---- D:\WINDOWS\Fonts
2007-01-06 01:47 dr------- D:\WINDOWS\Web
2007-01-06 01:47 d--h----- D:\WINDOWS\inf
2007-01-06 01:47 d-------- D:\WINDOWS\WinSxS
2007-01-06 01:47 d-------- D:\WINDOWS\twain_32
2007-01-06 01:47 d-------- D:\WINDOWS\system32\wins
2007-01-06 01:47 d-------- D:\WINDOWS\system32\wbem
2007-01-06 01:47 d-------- D:\WINDOWS\system32\usmt
2007-01-06 01:47 d-------- D:\WINDOWS\system32\spool
2007-01-06 01:47 d-------- D:\WINDOWS\system32\ShellExt
2007-01-06 01:47 d-------- D:\WINDOWS\system32\Setup
2007-01-06 01:47 d-------- D:\WINDOWS\system32\ras
2007-01-06 01:47 d-------- D:\WINDOWS\system32\oobe
2007-01-06 01:47 d-------- D:\WINDOWS\system32\npp
2007-01-06 01:47 d-------- D:\WINDOWS\system32\mui
2007-01-06 01:47 d-------- D:\WINDOWS\system32\inetsrv
2007-01-06 01:47 d-------- D:\WINDOWS\system32\IME
2007-01-06 01:47 d-------- D:\WINDOWS\system32\icsxml
2007-01-06 01:47 d-------- D:\WINDOWS\system32\ias
2007-01-06 01:47 d-------- D:\WINDOWS\system32\export
2007-01-06 01:47 d-------- D:\WINDOWS\system32\drivers\etc
2007-01-06 01:47 d-------- D:\WINDOWS\system32\drivers\disdn
2007-01-06 01:47 d-------- D:\WINDOWS\system32\drivers
2007-01-06 01:47 d-------- D:\WINDOWS\system32\dhcp
2007-01-06 01:47 d-------- D:\WINDOWS\system32\config
2007-01-06 01:47 d-------- D:\WINDOWS\system32\3com_dmi
2007-01-06 01:47 d-------- D:\WINDOWS\system32\3076
2007-01-06 01:47 d-------- D:\WINDOWS\system32\2052
2007-01-06 01:47 d-------- D:\WINDOWS\system32\1054
2007-01-06 01:47 d-------- D:\WINDOWS\system32\1042
2007-01-06 01:47 d-------- D:\WINDOWS\system32\1041
2007-01-06 01:47 d-------- D:\WINDOWS\system32\1037
2007-01-06 01:47 d-------- D:\WINDOWS\system32\1033
2007-01-06 01:47 d-------- D:\WINDOWS\system32\1031
2007-01-06 01:47 d-------- D:\WINDOWS\system32\1028
2007-01-06 01:47 d-------- D:\WINDOWS\system32\1025
2007-01-06 01:47 d-------- D:\WINDOWS\system32
2007-01-06 01:47 d-------- D:\WINDOWS\system
2007-01-06 01:47 d-------- D:\WINDOWS\security
2007-01-06 01:47 d-------- D:\WINDOWS\Resources
2007-01-06 01:47 d-------- D:\WINDOWS\repair
2007-01-06 01:47 d-------- D:\WINDOWS\mui
2007-01-06 01:47 d-------- D:\WINDOWS\msapps
2007-01-06 01:47 d-------- D:\WINDOWS\msagent
2007-01-06 01:47 d-------- D:\WINDOWS\Media
2007-01-06 01:47 d-------- D:\WINDOWS\java
2007-01-06 01:47 d-------- D:\WINDOWS\ime
2007-01-06 01:47 d-------- D:\WINDOWS\Help
2007-01-06 01:47 d-------- D:\WINDOWS\Driver Cache
2007-01-06 01:47 d-------- D:\WINDOWS\Debug
2007-01-06 01:47 d-------- D:\WINDOWS\Cursors
2007-01-06 01:47 d-------- D:\WINDOWS\Connection Wizard
2007-01-06 01:47 d-------- D:\WINDOWS\Config
2007-01-06 01:47 d-------- D:\WINDOWS\AppPatch
2007-01-06 01:47 d-------- D:\WINDOWS\addins
2007-01-06 01:47 d-------- D:\WINDOWS
2007-01-06 01:18 d-a------ D:\Program Files
2007-01-06 01:18 d-------- D:\My Downloads
2006-12-25 11:00 218,112 --a------ D:\Program Files\HijackThis.exe
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-01-11 01:59 -------- d-------- D:\DOCUME~1\ANDY~1.HOM\Application Data\mozilla
2007-01-10 22:44 5208 --a------ D:\Program Files\hijackthis.log
2007-01-07 14:28 -------- d-------- D:\DOCUME~1\ANDY~1.HOM\Application Data\macromedia
2007-01-06 11:36 -------- d-------- D:\DOCUME~1\ANDY~1.HOM\Application Data\identities
2007-01-06 11:14 62 --ahs---- D:\DOCUME~1\ANDY~1.HOM\Application Data\desktop.ini
2007-01-06 11:14 -------- d---s---- D:\DOCUME~1\ANDY~1.HOM\Application Data\microsoft
2006-12-12 16:30 520192 --a------ D:\WINDOWS\system32\divxsm.exe
2006-12-12 16:30 3596288 --a------ D:\WINDOWS\system32\qt-dx331.dll
2006-12-12 16:30 200704 --a------ D:\WINDOWS\system32\ssldivx.dll
2006-12-12 16:30 1044480 --a------ D:\WINDOWS\system32\libdivx.dll
2006-12-12 16:25 806912 --a------ D:\WINDOWS\system32\divx_xx0c.dll
2006-12-12 16:25 806912 --a------ D:\WINDOWS\system32\divx_xx07.dll
2006-12-12 16:25 790528 --a------ D:\WINDOWS\system32\divx_xx11.dll
2006-12-12 16:25 73728 --a------ D:\WINDOWS\system32\dpl100.dll
2006-12-12 16:25 635486 --a------ D:\WINDOWS\system32\divx.dll
2006-12-12 16:25 593920 --a------ D:\WINDOWS\system32\dpugui11.dll
2006-12-12 16:25 57344 --a------ D:\WINDOWS\system32\dpv11.dll
2006-12-12 16:25 53248 --a------ D:\WINDOWS\system32\dpugui10.dll
2006-12-12 16:25 344064 --a------ D:\WINDOWS\system32\dpus11.dll
2006-12-12 16:25 294912 --a------ D:\WINDOWS\system32\dpu11.dll
2006-12-12 16:25 294912 --a------ D:\WINDOWS\system32\dpu10.dll
2006-12-12 16:25 196608 --a------ D:\WINDOWS\system32\dtu100.dll
2006-12-12 16:24 12288 --a------ D:\WINDOWS\system32\divxwmpexttype.dll
2006-12-12 16:24 118784 --a------ D:\WINDOWS\system32\divxcodecupdatechecker.exe
2006-11-16 19:47 524288 --a------ D:\WINDOWS\opuc.dll
2006-11-07 03:26 13312 --a------ D:\WINDOWS\system32\ieudinit.exe
2006-11-04 14:14 1245696 --a------ D:\WINDOWS\system32\msxml4.dll
2006-10-19 13:56 713216 --a------ D:\WINDOWS\system32\sxs.dll
2006-10-18 21:58 8704 --------- D:\WINDOWS\system32\wdfmgr.exe
2006-10-18 21:58 8704 --------- D:\WINDOWS\system32\uwdf.exe
2006-10-18 21:47 99840 --a------ D:\WINDOWS\system32\wmpshell.dll
2006-10-18 21:47 991744 --a------ D:\WINDOWS\system32\drmv2clt.dll
2006-10-18 21:47 937984 --a------ D:\WINDOWS\system32\wmnetmgr.dll
2006-10-18 21:47 8231936 --a------ D:\WINDOWS\system32\wmploc.dll
2006-10-18 21:47 767488 --------- D:\WINDOWS\system32\wmvsencd.dll
2006-10-18 21:47 757248 --a------ D:\WINDOWS\system32\wmadmod.dll
2006-10-18 21:47 7168 --a------ D:\WINDOWS\system32\asferror.dll
2006-10-18 21:47 656896 --------- D:\WINDOWS\system32\wmvxencd.dll
2006-10-18 21:47 63488 --------- D:\WINDOWS\system32\wpdmtpus.dll
2006-10-18 21:47 629760 --------- D:\WINDOWS\system32\wpd_ci.dll
2006-10-18 21:47 613376 --------- D:\WINDOWS\system32\wmpmde.dll
2006-10-18 21:47 603648 --a------ D:\WINDOWS\system32\wmspdmod.dll
2006-10-18 21:47 542720 --a------ D:\WINDOWS\system32\blackbox.dll
2006-10-18 21:47 535040 --------- D:\WINDOWS\system32\wmdrmsdk.dll
2006-10-18 21:47 429056 --------- D:\WINDOWS\system32\wmdrmdev.dll
2006-10-18 21:47 414208 --a------ D:\WINDOWS\system32\msscp.dll
2006-10-18 21:47 4096 --a------ D:\WINDOWS\system32\wmvdmoe2.dll
2006-10-18 21:47 4096 --a------ D:\WINDOWS\system32\wmvdmod.dll
2006-10-18 21:47 4096 --a------ D:\WINDOWS\system32\wmsdmoe2.dll
2006-10-18 21:47 4096 --a------ D:\WINDOWS\system32\wmsdmod.dll
2006-10-18 21:47 4096 --a------ D:\WINDOWS\system32\mpg4dmod.dll
2006-10-18 21:47 4096 --a------ D:\WINDOWS\system32\mp4sdmod.dll
2006-10-18 21:47 4096 --a------ D:\WINDOWS\system32\mp43dmod.dll
2006-10-18 21:47 4096 --------- D:\WINDOWS\system32\wmvadve.dll
2006-10-18 21:47 4096 --------- D:\WINDOWS\system32\wmvadvd.dll
2006-10-18 21:47 4096 --------- D:\WINDOWS\system32\wdfapi.dll
2006-10-18 21:47 38400 --------- D:\WINDOWS\system32\wpdshextres.dll
2006-10-18 21:47 37376 --a------ D:\WINDOWS\system32\wmdmps.dll
2006-10-18 21:47 35840 --------- D:\WINDOWS\system32\wpdconns.dll
2006-10-18 21:47 356352 --------- D:\WINDOWS\system32\wpdsp.dll
2006-10-18 21:47 348672 --------- D:\WINDOWS\system32\wmdrmnet.dll
2006-10-18 21:47 33792 --a------ D:\WINDOWS\system32\wmdmlog.dll
2006-10-18 21:47 321536 --a------ D:\WINDOWS\system32\mswmdm.dll
2006-10-18 21:47 317440 --------- D:\WINDOWS\system32\mp4sdecd.dll
2006-10-18 21:47 314880 --a------ D:\WINDOWS\system32\wmpdxm.dll
2006-10-18 21:47 295936 --------- D:\WINDOWS\system32\wmpeffects.dll
2006-10-18 21:47 284160 --------- D:\WINDOWS\system32\portabledeviceapi.dll
2006-10-18 21:47 276992 --------- D:\WINDOWS\system32\audiodev.dll
2006-10-18 21:47 27136 --a------ D:\WINDOWS\system32\mspmsnsv.dll
2006-10-18 21:47 2603008 --------- D:\WINDOWS\system32\wpdshext.dll
2006-10-18 21:47 259072 --------- D:\WINDOWS\system32\mpg4decd.dll
2006-10-18 21:47 259072 --------- D:\WINDOWS\system32\mp43decd.dll
2006-10-18 21:47 2450944 --a------ D:\WINDOWS\system32\wmvcore.dll
2006-10-18 21:47 242688 --a------ D:\WINDOWS\system32\wmpasf.dll
2006-10-18 21:47 229376 --a------ D:\WINDOWS\system32\cewmdm.dll
2006-10-18 21:47 227328 --a------ D:\WINDOWS\system32\wmerror.dll
2006-10-18 21:47 222208 --a------ D:\WINDOWS\system32\wmasf.dll
2006-10-18 21:47 212992 --------- D:\WINDOWS\system32\mfplat.dll
2006-10-18 21:47 211456 --a------ D:\WINDOWS\system32\qasf.dll
2006-10-18 21:47 204288 --------- D:\WINDOWS\system32\wmpsrcwp.dll
2006-10-18 21:47 199168 --------- D:\WINDOWS\system32\portabledevicewmdrm.dll
2006-10-18 21:47 179712 --a------ D:\WINDOWS\system32\msnetobj.dll
2006-10-18 21:47 175616 --a------ D:\WINDOWS\system32\mspmsp.dll
2006-10-18 21:47 166912 --------- D:\WINDOWS\system32\portabledevicetypes.dll
2006-10-18 21:47 1661440 --------- D:\WINDOWS\system32\wmpencen.dll
2006-10-18 21:47 1574912 --------- D:\WINDOWS\system32\wmvencod.dll
2006-10-18 21:47 157184 --a------ D:\WINDOWS\system32\wmidx.dll
2006-10-18 21:47 154624 --------- D:\WINDOWS\system32\wpdmtp.dll
2006-10-18 21:47 1543680 --------- D:\WINDOWS\system32\wmvdecod.dll
2006-10-18 21:47 1382912 --------- D:\WINDOWS\system32\wmvsdecd.dll
2006-10-18 21:47 133632 --------- D:\WINDOWS\system32\wpdshserviceobj.dll
2006-10-18 21:47 1329152 --a------ D:\WINDOWS\system32\wmspdmoe.dll
2006-10-18 21:47 132096 --------- D:\WINDOWS\system32\portabledevicewiacompat.dll
2006-10-18 21:47 130048 --------- D:\WINDOWS\system32\wmpps.dll
2006-10-18 21:47 11264 --a------ D:\WINDOWS\system32\laprxy.dll
2006-10-18 21:47 1117696 --a------ D:\WINDOWS\system32\wmadmoe.dll
2006-10-18 21:47 101888 --------- D:\WINDOWS\system32\portabledeviceclassextension.dll
2006-10-18 20:03 100864 --a------ D:\WINDOWS\system32\logagent.exe
2006-10-18 20:00 249856 --------- D:\WINDOWS\system32\drmupgds.exe
2006-10-18 20:00 17408 --------- D:\WINDOWS\system32\wpdshextautoplay.exe
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MsnMsgr"="\"D:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"ctfmon.exe"="D:\\WINDOWS\\system32\\ctfmon.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"BJCFD"="D:\\Program Files\\BroadJump\\Client Foundation\\CFD.exe"
"Motive SmartBridge"="C:\\PROGRA~1\\ntl\\BROADB~1\\SMARTB~1\\MotiveSB.exe"
"!AVG Anti-Spyware"="\"D:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ctfmon"
"hkey"="HKCU"
"command"="D:\\WINDOWS\\system32\\ctfmon.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Easy-PrintToolBox]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="BJPSMAIN"
"hkey"="HKLM"
"command"="D:\\Program Files\\Canon\\Easy-PrintToolBox\\BJPSMAIN.EXE /logon"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="dumprep 0 -k"
"hkey"="HKLM"
"command"="%systemroot%\\system32\\dumprep 0 -k"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Matrox Powerdesk]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PDesk"
"hkey"="HKLM"
"command"="D:\\WINDOWS\\system32\\PDesk\\PDesk.exe /Autolaunch"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msmsgs"
"hkey"="HKCU"
"command"="\"D:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NeroCheck"
"hkey"="HKLM"
"command"="D:\\WINDOWS\\system32\\NeroCheck.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ntl Netguard]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Rps"
"hkey"="HKLM"
"command"="D:\\Program Files\\ntl\\ntl Netguard\\Rps.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDUiP6220DMon]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PDUiP6220DMon"
"hkey"="HKLM"
"command"="D:\\Program Files\\Canon\\Memory Card Utility\\iP6220D\\PDUiP6220DMon.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PhotoShow Deluxe Media Manager]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="mssysmgr"
"hkey"="HKCU"
"command"="D:\\PROGRA~1\\Nero\\data\\Xtras\\mssysmgr.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"D:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\shareaza]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Shareaza"
"hkey"="HKCU"
"command"="\"D:\\Program Files\\Shareaza\\Shareaza.exe\" -tray"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="jusched"
"hkey"="HKLM"
"command"="\"D:\\Program Files\\Java\\jre1.5.0_10\\bin\\jusched.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\team remote]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="BOLD JOY BOLT"
"hkey"="HKCU"
"command"="D:\\DOCUME~1\\ANDY~1.HOM\\APPLIC~1\\OPTION~1\\BOLD JOY BOLT.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="MSASCui"
"hkey"="HKLM"
"command"="\"D:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
Contents of the 'Scheduled Tasks' folder
D:\WINDOWS\tasks\AAC9AD1590DE5D5D.job
D:\WINDOWS\tasks\1-Click Maintenance.job
D:\WINDOWS\tasks\MP Scheduled Scan.job
Completion time: 07-01-14 0:52:30
HJT log:
Logfile of HijackThis v1.99.1
Scan saved at 01:05:43, on 14/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Windows Defender\MsMpEng.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\ntl\ntl Netguard\fws.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
D:\Program Files\Common Files\Command Software\dvpapi.exe
D:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
D:\Program Files\MSN Messenger\MsnMsgr.Exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
D:\WINDOWS\system32\mgabg.exe
D:\WINDOWS\system32\svchost.exe
C:\Program Files\ntl\broadband medic\bin\mpbtn.exe
D:\Program Files\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - D:\Program Files\ntl\ntl Netguard\pkR.dll
O2 - BHO: Form Filler BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - D:\Program Files\ntl\ntl Netguard\FBHR.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - D:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [BJCFD] D:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MsnMsgr] "D:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: broadband medic.lnk = C:\Program Files\ntl\broadband medic\bin\matcli.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://D:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://D:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://D:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://D:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CFA086E-6336-4D95-B6AA-90F564E99631} (TNSClicker.Clicker) -
http://www.shopandscan.com/TNSClicker.CAB
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) -
http://launch.gamespyarcade.com/software/launch/alaunch.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - D:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - D:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: Radialpoint Service (FWS) - Radialpoint Inc. - D:\Program Files\ntl\ntl Netguard\fws.exe
O23 - Service: MGABGEXE - Matrox Graphics Inc. - D:\WINDOWS\system32\mgabg.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - D:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe