CG:
ComboFix report
Dennis S - 07-01-11 17:54:59.28 Service Pack 2
ComboFix 06.11.27 - Running from: "C:\08_jan_2007"
((((((((((((((((((((((((((((((( Files Created from 2006-12-11 to 2007-01-11 ))))))))))))))))))))))))))))))))))
2007-01-09 17:05 d-------- C:\WINDOWS\ie7updates
2007-01-08 14:58 684,032 --a------ C:\WINDOWS\system32\libeay32.dll
2007-01-08 14:58 155,648 --a------ C:\WINDOWS\system32\ssleay32.dll
2007-01-08 13:18 d-------- C:\Program Files\Grisoft
2007-01-08 13:16 27,510 --a------ C:\WINDOWS\system32\tmp.reg
2007-01-08 10:00 d-------- C:\WINDOWS\system32\ActiveScan
2007-01-08 09:56 d-------- C:\08_jan_2007
2007-01-06 08:52 d-------- C:\Documents and Settings\Dennis S\Application Data\Walgreens
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-12-17 08:45 1080 --a------ C:\WINDOWS\AUTOLNCH.REG
2006-12-06 23:40 2362184 --a------ C:\WINDOWS\system32\wmvcore.dll
2006-11-07 22:06 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-11-04 14:14 1245696 --a------ C:\WINDOWS\system32\msxml4.dll
2006-10-27 15:09 6049280 --------- C:\WINDOWS\system32\ieframe.dll
2006-10-27 15:09 50688 --------- C:\WINDOWS\system32\msfeedsbs.dll
2006-10-27 15:09 458752 --------- C:\WINDOWS\system32\msfeeds.dll
2006-10-27 15:09 413696 --a------ C:\WINDOWS\system32\vbscript.dll
2006-10-27 15:09 231424 --a------ C:\WINDOWS\system32\webcheck.dll
2006-10-27 15:09 180736 --------- C:\WINDOWS\system32\ieui.dll
2006-10-27 15:09 156160 --a------ C:\WINDOWS\system32\msls31.dll
2006-10-27 02:44 71680 --a------ C:\WINDOWS\system32\admparse.dll
2006-10-27 02:44 55296 --a------ C:\WINDOWS\system32\iesetup.dll
2006-10-27 02:44 54784 --a------ C:\WINDOWS\system32\ie4uinit.exe
2006-10-27 02:44 43008 --a------ C:\WINDOWS\system32\iernonce.dll
2006-10-27 02:44 382976 --a------ C:\WINDOWS\system32\iedkcs32.dll
2006-10-27 02:44 229376 --a------ C:\WINDOWS\system32\ieaksie.dll
2006-10-27 02:44 152064 --a------ C:\WINDOWS\system32\ieakeng.dll
2006-10-27 02:44 13312 --a------ C:\WINDOWS\system32\ieudinit.exe
2006-10-27 02:44 123904 --a------ C:\WINDOWS\system32\advpack.dll
2006-10-27 02:42 161792 --a------ C:\WINDOWS\system32\ieakui.dll
2006-10-19 06:56 713216 --a------ C:\WINDOWS\system32\sxs.dll
2006-10-17 13:06 78336 --a------ C:\WINDOWS\system32\ieencode.dll
2006-10-17 13:05 40960 --a------ C:\WINDOWS\system32\licmgr10.dll
2006-10-17 13:05 206336 --------- C:\WINDOWS\system32\WinFXDocObj.exe
2006-10-17 13:05 105984 --a------ C:\WINDOWS\system32\url.dll
2006-10-17 13:04 101376 --a------ C:\WINDOWS\system32\occache.dll
2006-10-17 13:03 17408 --a------ C:\WINDOWS\system32\corpol.dll
2006-10-17 12:58 61952 --------- C:\WINDOWS\system32\icardie.dll
2006-10-17 12:58 12288 --------- C:\WINDOWS\system32\msfeedssync.exe
2006-10-17 12:57 36352 --a------ C:\WINDOWS\system32\imgutil.dll
2006-10-17 12:57 266752 --------- C:\WINDOWS\system32\iertutil.dll
2006-10-17 12:56 45568 --a------ C:\WINDOWS\system32\mshta.exe
2006-10-17 12:28 48128 --a------ C:\WINDOWS\system32\mshtmler.dll
2006-10-17 12:27 380928 --------- C:\WINDOWS\system32\ieapfltr.dll
2006-10-13 11:30 668976 --a------ C:\WINDOWS\system32\OGACheckControl.DLL
2006-10-13 05:35 142336 --a------ C:\WINDOWS\system32\nwprovau.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"Microsoft Location Finder"="\"C:\\Program Files\\Microsoft Location Finder\\LocationFinder.exe\""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NvCplDaemon"="\"RUNDLL32.EXE\" C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"Microsoft Works Update Detection"="\"C:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\WkUFind.exe\""
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"HPDJ Taskbar Utility"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb04.exe"
"avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"
"Adobe Photo Downloader"="\"C:\\Program Files\\Adobe\\Photoshop Elements 4.0\\apdproxy.exe\""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\cmesys]
"NAV Agent"="C:\\PROGRA~1\\NORTON~1\\navapw32.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"CMESys"="\"C:\\Program Files\\Common Files\\CMEII\\CMESys.exe\""
"wininetd"="C:\\WINDOWS\\System32\\wininetd.exe"
"OAKSTART"="C:\\PROGRA~1\\OAKTEC~1\\OAKSIM~1\\OAKSTART.EXE"
"OAKTASK"="C:\\PROGRA~1\\OAKTEC~1\\OAKSIM~1\\OAKTASK.EXE"
"HPDJ Taskbar Utility"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb07.exe"
"IEDriver"="C:\\WINDOWS\\System32\\IEDriver\\IEDriver.exe"
"Pcsv"="C:\\WINDOWS\\system32\\pcs\\pcsvc.exe"
"Dpi"="C:\\Program Files\\Common Files\\Dpi\\dpi.exe"
"updater"="C:\\Program Files\\Common files\\updater\\wupdater.exe"
"SAHAgent"="C:\\WINDOWS\\System32\\SahAgent.exe"
"AutoUpdater"="\"C:\\Program Files\\AutoUpdate\\AutoUpdate.exe\""
"msbb"="C:\\WINDOWS\\System32\\msbb.exe"
"ALYGQ"="C:\\WINDOWS\\ALYGQ.exe"
"SpyHunter"=""
"EnigmaPopupStop"="C:\\Program Files\\SpyHunter\\PopupBlocker\\EnigmaPopupStop.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\cmesys\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\cmesys\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\cmesys\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\cmesys\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\Pcsv]
"NAV Agent"="C:\\PROGRA~1\\NORTON~1\\navapw32.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"wininetd"="C:\\WINDOWS\\System32\\wininetd.exe"
"OAKSTART"="C:\\PROGRA~1\\OAKTEC~1\\OAKSIM~1\\OAKSTART.EXE"
"OAKTASK"="C:\\PROGRA~1\\OAKTEC~1\\OAKSIM~1\\OAKTASK.EXE"
"HPDJ Taskbar Utility"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb07.exe"
"IEDriver"="C:\\WINDOWS\\System32\\IEDriver\\IEDriver.exe"
"Pcsv"="C:\\WINDOWS\\system32\\pcs\\pcsvc.exe"
"Dpi"="C:\\Program Files\\Common Files\\Dpi\\dpi.exe"
"SAHAgent"="C:\\WINDOWS\\System32\\SahAgent.exe"
"AutoUpdater"="\"C:\\Program Files\\AutoUpdate\\AutoUpdate.exe\""
"msbb"="C:\\WINDOWS\\System32\\msbb.exe"
"ALYGQ"="C:\\WINDOWS\\ALYGQ.exe"
"SpyHunter"=""
"EnigmaPopupStop"="C:\\Program Files\\SpyHunter\\PopupBlocker\\EnigmaPopupStop.exe"
"CMESys"="\"C:\\Program Files\\Common Files\\CMEII\\CMESys.exe\""
"Belt"="C:\\WINDOWS\\Belt.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\Pcsv\cmesys]
"NAV Agent"="C:\\PROGRA~1\\NORTON~1\\navapw32.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"CMESys"="\"C:\\Program Files\\Common Files\\CMEII\\CMESys.exe\""
"wininetd"="C:\\WINDOWS\\System32\\wininetd.exe"
"OAKSTART"="C:\\PROGRA~1\\OAKTEC~1\\OAKSIM~1\\OAKSTART.EXE"
"OAKTASK"="C:\\PROGRA~1\\OAKTEC~1\\OAKSIM~1\\OAKTASK.EXE"
"HPDJ Taskbar Utility"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb07.exe"
"IEDriver"="C:\\WINDOWS\\System32\\IEDriver\\IEDriver.exe"
"Pcsv"="C:\\WINDOWS\\system32\\pcs\\pcsvc.exe"
"Dpi"="C:\\Program Files\\Common Files\\Dpi\\dpi.exe"
"updater"="C:\\Program Files\\Common files\\updater\\wupdater.exe"
"SAHAgent"="C:\\WINDOWS\\System32\\SahAgent.exe"
"AutoUpdater"="\"C:\\Program Files\\AutoUpdate\\AutoUpdate.exe\""
"msbb"="C:\\WINDOWS\\System32\\msbb.exe"
"ALYGQ"="C:\\WINDOWS\\ALYGQ.exe"
"SpyHunter"=""
"EnigmaPopupStop"="C:\\Program Files\\SpyHunter\\PopupBlocker\\EnigmaPopupStop.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\Pcsv\cmesys\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\Pcsv\cmesys\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\Pcsv\cmesys\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\Pcsv\cmesys\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\Pcsv\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\Pcsv\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\Pcsv\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\Pcsv\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\Pcsv\Updater]
"NAV Agent"="C:\\PROGRA~1\\NORTON~1\\navapw32.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"wininetd"="C:\\WINDOWS\\System32\\wininetd.exe"
"OAKSTART"="C:\\PROGRA~1\\OAKTEC~1\\OAKSIM~1\\OAKSTART.EXE"
"OAKTASK"="C:\\PROGRA~1\\OAKTEC~1\\OAKSIM~1\\OAKTASK.EXE"
"HPDJ Taskbar Utility"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb07.exe"
"IEDriver"="C:\\WINDOWS\\System32\\IEDriver\\IEDriver.exe"
"Pcsv"="C:\\WINDOWS\\system32\\pcs\\pcsvc.exe"
"Dpi"="C:\\Program Files\\Common Files\\Dpi\\dpi.exe"
"updater"="C:\\Program Files\\Common files\\updater\\wupdater.exe"
"SAHAgent"="C:\\WINDOWS\\System32\\SahAgent.exe"
"AutoUpdater"="\"C:\\Program Files\\AutoUpdate\\AutoUpdate.exe\""
"msbb"="C:\\WINDOWS\\System32\\msbb.exe"
"ALYGQ"="C:\\WINDOWS\\ALYGQ.exe"
"SpyHunter"=""
"EnigmaPopupStop"="C:\\Program Files\\SpyHunter\\PopupBlocker\\EnigmaPopupStop.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\Pcsv\Updater\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\Pcsv\Updater\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\Pcsv\Updater\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\Pcsv\Updater\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\Pcsv\UpdateStats]
"NAV Agent"="C:\\PROGRA~1\\NORTON~1\\navapw32.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"CMESys"="\"C:\\Program Files\\Common Files\\CMEII\\CMESys.exe\""
"wininetd"="C:\\WINDOWS\\System32\\wininetd.exe"
"OAKSTART"="C:\\PROGRA~1\\OAKTEC~1\\OAKSIM~1\\OAKSTART.EXE"
"OAKTASK"="C:\\PROGRA~1\\OAKTEC~1\\OAKSIM~1\\OAKTASK.EXE"
"HPDJ Taskbar Utility"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb07.exe"
"UpdateStats"="C:\\Program Files\\Media\\Media\\UpdateStats.exe"
"IEDriver"="C:\\WINDOWS\\System32\\IEDriver\\IEDriver.exe"
"Pcsv"="C:\\WINDOWS\\system32\\pcs\\pcsvc.exe"
"Dpi"="C:\\Program Files\\Common Files\\Dpi\\dpi.exe"
"updater"="C:\\Program Files\\Common files\\updater\\wupdater.exe"
"SAHAgent"="C:\\WINDOWS\\System32\\SahAgent.exe"
"AutoUpdater"="\"C:\\Program Files\\AutoUpdate\\AutoUpdate.exe\""
"msbb"="C:\\WINDOWS\\System32\\msbb.exe"
"ALYGQ"="C:\\WINDOWS\\ALYGQ.exe"
"SpyHunter"=""
"EnigmaPopupStop"="C:\\Program Files\\SpyHunter\\PopupBlocker\\EnigmaPopupStop.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\Pcsv\UpdateStats\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\Pcsv\UpdateStats\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\Pcsv\UpdateStats\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\Pcsv\UpdateStats\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\Updater]
"NAV Agent"="C:\\PROGRA~1\\NORTON~1\\navapw32.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"wininetd"="C:\\WINDOWS\\System32\\wininetd.exe"
"OAKSTART"="C:\\PROGRA~1\\OAKTEC~1\\OAKSIM~1\\OAKSTART.EXE"
"OAKTASK"="C:\\PROGRA~1\\OAKTEC~1\\OAKSIM~1\\OAKTASK.EXE"
"HPDJ Taskbar Utility"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb07.exe"
"IEDriver"="C:\\WINDOWS\\System32\\IEDriver\\IEDriver.exe"
"Pcsv"="C:\\WINDOWS\\system32\\pcs\\pcsvc.exe"
"Dpi"="C:\\Program Files\\Common Files\\Dpi\\dpi.exe"
"updater"="C:\\Program Files\\Common files\\updater\\wupdater.exe"
"SAHAgent"="C:\\WINDOWS\\System32\\SahAgent.exe"
"AutoUpdater"="\"C:\\Program Files\\AutoUpdate\\AutoUpdate.exe\""
"msbb"="C:\\WINDOWS\\System32\\msbb.exe"
"ALYGQ"="C:\\WINDOWS\\ALYGQ.exe"
"SpyHunter"=""
"EnigmaPopupStop"="C:\\Program Files\\SpyHunter\\PopupBlocker\\EnigmaPopupStop.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\Updater\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\Updater\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\Updater\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\Updater\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\UpdateStats]
"NAV Agent"="C:\\PROGRA~1\\NORTON~1\\navapw32.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"CMESys"="\"C:\\Program Files\\Common Files\\CMEII\\CMESys.exe\""
"wininetd"="C:\\WINDOWS\\System32\\wininetd.exe"
"OAKSTART"="C:\\PROGRA~1\\OAKTEC~1\\OAKSIM~1\\OAKSTART.EXE"
"OAKTASK"="C:\\PROGRA~1\\OAKTEC~1\\OAKSIM~1\\OAKTASK.EXE"
"HPDJ Taskbar Utility"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb07.exe"
"UpdateStats"="C:\\Program Files\\Media\\Media\\UpdateStats.exe"
"IEDriver"="C:\\WINDOWS\\System32\\IEDriver\\IEDriver.exe"
"Pcsv"="C:\\WINDOWS\\system32\\pcs\\pcsvc.exe"
"Dpi"="C:\\Program Files\\Common Files\\Dpi\\dpi.exe"
"updater"="C:\\Program Files\\Common files\\updater\\wupdater.exe"
"SAHAgent"="C:\\WINDOWS\\System32\\SahAgent.exe"
"AutoUpdater"="\"C:\\Program Files\\AutoUpdate\\AutoUpdate.exe\""
"msbb"="C:\\WINDOWS\\System32\\msbb.exe"
"ALYGQ"="C:\\WINDOWS\\ALYGQ.exe"
"SpyHunter"=""
"EnigmaPopupStop"="C:\\Program Files\\SpyHunter\\PopupBlocker\\EnigmaPopupStop.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\UpdateStats\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\UpdateStats\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\UpdateStats\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\UpdateStats\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000005
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,80,00,00,00,00,00,00,00,00,02,00,00,c2,01,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,e2,03,\
00,00,04,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,e2,03,\
00,00,01,00,00,00
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"CDRAutoRun"=dword:00000000
"NoDriveAutoRun"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"CDRAutoRun"=dword:00000000
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"CDRAutoRun"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Billminder.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Billminder.lnk"
"backup"="C:\\WINDOWS\\pss\\Billminder.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\QUICKEN\\BILLMIND.EXE "
"item"="Billminder"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Event Reminder.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Event Reminder.lnk"
"backup"="C:\\WINDOWS\\pss\\Event Reminder.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\Program Files\\Broderbund\\PrintMaster\\PMremind.exe "
"item"="Event Reminder"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Microsoft Office.lnk"
"backup"="C:\\WINDOWS\\pss\\Microsoft Office.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\Program Files\\Microsoft Office\\Office\\OSA9.EXE -b -l"
"item"="Microsoft Office"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Quicken Scheduled Updates.lnk"
"backup"="C:\\WINDOWS\\pss\\Quicken Scheduled Updates.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\QUICKEN\\bagent.exe "
"item"="Quicken Scheduled Updates"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Startup.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Quicken Startup.lnk"
"backup"="C:\\WINDOWS\\pss\\Quicken Startup.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\QUICKEN\\QWDLLS.EXE "
"item"="Quicken Startup"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Desktop Search.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Windows Desktop Search.lnk"
"backup"="C:\\WINDOWS\\pss\\Windows Desktop Search.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\Program Files\\MSN Toolbar Suite\\DS\\02.05.0000.1082\\en-us\\bin\\WindowsSearch.exe /startup"
"item"="Windows Desktop Search"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Dennis S^Start Menu^Programs^Startup^PowerReg Scheduler.exe]
"path"="C:\\Documents and Settings\\Dennis S\\Start Menu\\Programs\\Startup\\PowerReg Scheduler.exe"
"backup"="C:\\WINDOWS\\pss\\PowerReg Scheduler.exeStartup"
"location"="Startup"
"command"="C:\\Documents and Settings\\Dennis S\\Start Menu\\Programs\\Startup\\PowerReg Scheduler.exe"
"item"="PowerReg Scheduler"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Dennis S^Start Menu^Programs^Startup^Webshots.lnk]
"path"="C:\\Documents and Settings\\Dennis S\\Start Menu\\Programs\\Startup\\Webshots.lnk"
"backup"="C:\\WINDOWS\\pss\\Webshots.lnkStartup"
"location"="Startup"
"command"="C:\\PROGRA~1\\Webshots\\WEBSHO~1.EXE "
"item"="Webshots"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CXMon]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Hpi_Monitor"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Hewlett-Packard\\PhotoSmart\\Photo Imaging\\Hpi_Monitor.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellTouch]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="MMKeybd"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\MMKeybd.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E6TaskPanel]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="TaskPanl"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe\" -winstart"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHmon03]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="hphmon03"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\System32\\hphmon03.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpppta]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="hpppta"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Hewlett-Packard\\HP PrecisionScan\\PrecisionScan Pro\\hpppta.exe\" /ICON"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMOL]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="IMOLApp"
"hkey"="HKCU"
"command"="IMOLApp.exe /c"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KPPS-Control-Centre]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PicCent"
"hkey"="HKCU"
"command"="C:\\Program Files\\Kodak\\PicturePageSoftware\\PicCent.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="\"nwiz"
"hkey"="HKLM"
"command"="\"nwiz.exe\" /install"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OAKSTART]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="OAKSTART"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\OAKTEC~1\\OAKSIM~1\\OAKSTART.EXE"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OAKTASK]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="OAKTASK"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\OAKTEC~1\\OAKSIM~1\\OAKTASK.EXE"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PicasaMediaDetector"
"hkey"="HKLM"
"command"="\"e:\\Program Files\\Picasa2\\PicasaMediaDetector.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PinnacleDriverCheck]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PSDrvCheck"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\PSDrvCheck.exe -CheckReg"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\POINTER]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="point32"
"hkey"="HKLM"
"command"="point32.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QAGENT]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="QAGENT"
"hkey"="HKLM"
"command"="C:\\Program Files\\Intuit\\QAgent\\QAGENT.EXE"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Share-to-Web Namespace Daemon]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="hpgs2wnd"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Hewlett-Packard\\PhotoSmart\\HP Share-to-Web\\hpgs2wnd.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
backup-20070108-170258-164
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (file missing)
backup-20070108-170054-761
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) -
http://www2.incredimail.com/contents/setup/downloader/imloader.cab
backup-20070108-170058-690
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (file missing)
backup-20070108-170052-919
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
backup-20070108-170046-867
O9 - Extra 'Tools' menuitem: Internet SEXplorer - {47055D63-DFCD-11d3-8406-00500445A7D1} - C:\WINDOWS\System32\windialup\1714\windialup.exe (file missing)
backup-20070108-170050-128
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
backup-20070108-170043-220
O9 - Extra button: Internet SEXplorer - {47055D63-DFCD-11d3-8406-00500445A7D1} - C:\WINDOWS\System32\windialup\1714\windialup.exe (file missing)
backup-20070108-170042-282
O4 - HKLM\..\Run: [IncrediMail] C:\PROGRA~1\INCRED~1\bin\IncMail.exe /c
backup-20070108-170042-813
O4 - HKLM\..\Run: [ALYGQ] C:\WINDOWS\ALYGQ.exe
backup-20070108-170043-662
O4 - Global Startup: Date Manager.lnk = C:\Program Files\Date Manager\DateManager.exe
backup-20070108-170042-446
O4 - HKLM\..\Run: [ConMgr.exe] "C:\Program Files\EarthLink 5.0\ConMgr.exe"
backup-20070108-170042-270
O4 - HKLM\..\Run: [KAZAA] C:\Program Files\KaZaA\Kazaa.exe /SYSTRAY
backup-20070108-170042-437
O4 - HKLM\..\Run: [t69k36Q] unigehlp.exe
backup-20070108-170042-639
O4 - HKLM\..\Run: [Corel® Custom Photo] "D:\setup32.exe" /rspfile="C:\WINDOWS\Corel\Corel® Custom Photo\5\RECOVERY.CSW" /g+ /close
backup-20070108-170042-492
O4 - HKLM\..\Run: [Prein] C:\DOCUME~1\DENNIS~1\LOCALS~1\Temp\app580.tmp
backup-20070108-170042-793
O4 - HKLM\..\Run: [zazzunc] C:\WINDOWS\System32\rnnuhn.exe
backup-20070108-170042-889
O4 - HKLM\..\Run: [AutoLoadert1q21INjLNOO] "C:\WINDOWS\System32\ltvund3d.exe" /PC="AM.WILD" /HideUninstall
backup-20070108-170042-283
F3 - REG:win.ini: run=C:\EPPRT\WSWPD.EXE
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp officejet 6100 series#1073527009.job
Completion time: 07-01-11 17:56:58.32
Sincerely,
RF123