Katana,
Here is the log from ComboFix:
ComboFix 09-06-26.02 - Papa 06/26/2009 22:00.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2688 [GMT -4:00]
Running from: c:\documents and settings\Papa\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Papa\Desktop\CFScript.txt
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
FILE ::
"c:\windows\sessmgr.exe"
"e:\20090429_000000_maintom\E\Documents\Papa\LimeWire\downloads\glamorous indie rock and roll.mp3"
"f:\documents\Papa\LimeWire\downloads\glamorous indie rock and roll.mp3"
"h:\backup\Documents\Papa\LimeWire\downloads\glamorous indie rock and roll.mp3"
file zipped: c:\windows\Suspect_sessmgr.exe.vir
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Rachel\Application Data\Microsoft\cmstp.exe
c:\windows\sessmgr.exe
e:\20090429_000000_maintom\E\Documents\Papa\LimeWire\downloads\glamorous indie rock and roll.mp3
f:\documents\Papa\LimeWire\downloads\glamorous indie rock and roll.mp3
h:\backup\Documents\Papa\LimeWire\downloads\glamorous indie rock and roll.mp3
.
((((((((((((((((((((((((( Files Created from 2009-05-27 to 2009-06-27 )))))))))))))))))))))))))))))))
.
2009-06-26 00:09 . 2009-06-26 00:09 -------- d-----w- c:\windows\Sun
2009-06-26 00:09 . 2009-06-26 00:08 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-06-26 00:08 . 2009-06-26 00:08 152576 ----a-w- c:\documents and settings\Papa\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-25 10:28 . 2009-06-25 10:28 -------- dc----w- c:\windows\system32\dllcache\cache
2009-06-24 02:35 . 2009-06-24 02:35 -------- d-----w- c:\documents and settings\Papa\Application Data\Malwarebytes
2009-06-24 02:35 . 2009-06-17 15:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-24 02:35 . 2009-06-24 02:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-24 02:35 . 2009-06-17 15:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-23 02:04 . 2009-06-23 02:04 -------- d-----w- C:\rsit
2009-06-21 15:54 . 2009-06-21 15:54 -------- d-----w- c:\documents and settings\Rachel\Local Settings\Application Data\Microsoft Help
2009-06-13 19:29 . 2009-06-13 19:29 -------- d-----w- c:\documents and settings\Papa\Application Data\Nero
2009-06-12 02:32 . 2009-06-12 02:32 -------- d-----w- c:\documents and settings\Papa\Application Data\Apple Computer
2009-06-12 02:30 . 2009-06-12 02:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-06-12 02:30 . 2009-06-12 02:30 -------- d-----w- c:\documents and settings\Papa\Local Settings\Application Data\Apple
2009-06-12 02:30 . 2009-06-12 02:30 -------- d-----w- c:\program files\Apple Software Update
2009-06-12 02:30 . 2009-06-12 02:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-06-12 02:29 . 2009-06-12 02:29 -------- d-----w- c:\documents and settings\Papa\Local Settings\Application Data\Apple Computer
2009-06-12 02:04 . 2001-08-18 02:36 5632 ----a-w- c:\windows\system32\ptpusb.dll
2009-06-12 02:04 . 2008-04-14 00:12 159232 ----a-w- c:\windows\system32\ptpusd.dll
2009-06-06 02:55 . 2009-06-06 02:55 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-06-03 10:19 . 2009-06-03 10:19 2904064 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\18154-181625.dll
2009-06-02 22:29 . 2009-06-02 22:29 -------- d-----r- c:\documents and settings\Rachel\Application Data\Brother
2009-05-31 21:29 . 2009-05-31 22:28 -------- d-----w- c:\documents and settings\Anna\Local Settings\Application Data\Microsoft Help
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-26 11:08 . 2009-05-02 15:27 -------- d-----w- c:\program files\Common Files\Adobe
2009-06-25 02:43 . 2009-05-15 18:06 -------- d-----w- c:\program files\GE Security Supra
2009-06-15 10:20 . 2009-05-02 14:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-06-12 02:23 . 2009-05-02 14:27 -------- d-----w- c:\documents and settings\Papa\Application Data\IEPro
2009-06-03 10:19 . 2009-05-12 02:34 242976 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\QWPATCH.EXE
2009-05-15 18:07 . 2009-05-15 18:07 159744 ----a-w- c:\windows\system32\libssl32.dll
2009-05-15 18:07 . 2009-05-15 18:07 -------- d-----w- c:\program files\SiLabs
2009-05-15 11:51 . 2009-05-15 11:51 -------- d-----w- c:\documents and settings\Papa\Application Data\ICAClient
2009-05-15 11:50 . 2009-05-15 11:50 -------- d-----w- c:\program files\Citrix
2009-05-15 11:39 . 2009-05-15 11:39 -------- d-----w- c:\program files\CheckPoint
2009-05-15 11:32 . 2009-05-15 11:32 -------- d-----w- c:\program files\Windows Media Connect 2
2009-05-15 02:16 . 2009-05-03 16:55 71192 ----a-w- c:\documents and settings\Leah\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-13 01:12 . 2009-05-02 22:25 71192 ----a-w- c:\documents and settings\Anna\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-13 00:43 . 2009-05-02 19:03 71192 ----a-w- c:\documents and settings\Rachel\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-12 02:34 . 2009-05-12 02:34 3616768 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\181311-181414.dll
2009-05-12 02:34 . 2009-05-12 02:34 1536000 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\181414-18154.dll
2009-05-12 02:34 . 2009-05-12 02:34 1007616 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\181129-181212.dll
2009-05-12 02:34 . 2009-05-12 02:34 811008 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\181212-181311.dll
2009-05-12 02:34 . 2009-05-12 02:34 223584 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\patchw32.dll
2009-05-12 02:34 . 2009-05-12 02:34 997 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\rebase.cmd
2009-05-12 02:34 . 2009-05-02 13:20 71192 ----a-w- c:\documents and settings\Papa\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-12 02:33 . 2009-05-12 02:33 -------- d-----w- c:\program files\Common Files\AnswerWorks 5.0
2009-05-12 02:33 . 2009-05-04 01:42 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-12 02:32 . 2009-05-12 02:32 -------- d-----w- c:\documents and settings\Papa\Application Data\Intuit
2009-05-12 02:32 . 2009-05-12 02:32 -------- d-----w- c:\program files\Common Files\Intuit
2009-05-12 02:30 . 2009-05-12 02:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Intuit
2009-05-10 23:26 . 2009-05-10 23:26 -------- d-----w- c:\documents and settings\Rachel\Application Data\MiniDm
2009-05-07 23:22 . 2009-05-02 15:53 57 ----a-w- c:\documents and settings\All Users\Application Data\Brother\BrLog\BrCollectDir\BR_cat.bat
2009-05-07 23:17 . 2009-05-02 15:54 65 ----a-w- c:\windows\system32\BD7820N.dat
2009-05-07 23:16 . 2009-05-07 23:16 -------- d-----w- c:\program files\Brother
2009-05-07 23:16 . 2009-05-04 01:41 -------- d-----w- c:\program files\Common Files\InstallShield
2009-05-07 15:32 . 2004-08-04 12:00 345600 ----a-w- c:\windows\system32\localspl.dll
2009-05-07 12:17 . 2009-05-03 11:11 -------- d-----w- c:\program files\Microsoft Silverlight
2009-05-07 02:12 . 2009-05-07 02:12 -------- d-----w- c:\program files\MSXML 4.0
2009-05-04 02:10 . 2009-05-04 02:10 -------- d-----w- c:\program files\Qimage
2009-05-04 02:02 . 2009-05-04 02:02 -------- d-----w- c:\documents and settings\Papa\Application Data\ACD Systems
2009-05-04 02:02 . 2009-05-04 02:01 -------- d-----w- c:\program files\Common Files\ACD Systems
2009-05-04 02:02 . 2009-05-04 02:02 -------- d-----w- c:\documents and settings\All Users\Application Data\ACD Systems
2009-05-04 01:42 . 2009-05-04 01:42 -------- d-----w- c:\program files\Realtek AC97
2009-05-03 18:11 . 2009-05-03 17:35 -------- d-----w- c:\documents and settings\Leah\Application Data\MiniDm
2009-05-03 16:59 . 2009-05-03 16:59 -------- d-----w- c:\documents and settings\Leah\Application Data\IEPro
2009-05-03 13:31 . 2009-05-03 13:31 10134 ----a-r- c:\documents and settings\Papa\Application Data\Microsoft\Installer\{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}\ARPPRODUCTICON.exe
2009-05-03 13:31 . 2009-05-03 13:31 -------- d-----w- c:\program files\HP
2009-05-03 11:15 . 2009-05-02 22:26 -------- d-----w- c:\documents and settings\Anna\Application Data\IEPro
2009-05-03 11:12 . 2009-05-02 22:27 -------- d-----w- c:\documents and settings\Anna\Application Data\MiniDm
2009-05-03 11:11 . 2009-05-03 11:11 -------- d-----w- c:\program files\Microsoft
2009-05-03 11:11 . 2009-05-03 11:10 -------- d-----w- c:\program files\Windows Live
2009-05-03 11:10 . 2009-05-03 11:10 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-05-03 11:08 . 2009-05-03 11:08 -------- d-----w- c:\program files\Common Files\Windows Live
2009-05-03 10:19 . 2009-05-03 10:19 0 ----a-w- c:\windows\nsreg.dat
2009-05-02 19:14 . 2009-05-02 19:14 -------- d-----w- c:\documents and settings\Rachel\Application Data\IEPro
2009-05-02 17:47 . 2009-05-02 17:47 -------- d-----w- c:\program files\Common Files\Nero
2009-05-02 17:47 . 2009-05-02 17:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Nero
2009-05-02 17:05 . 2009-05-02 17:05 -------- d-----w- c:\documents and settings\Papa\Application Data\InstallShield
2009-05-02 17:01 . 2009-05-02 17:01 -------- d-----w- c:\documents and settings\All Users\Application Data\EPSON
2009-05-02 17:00 . 2009-05-02 17:00 -------- d-----w- c:\program files\EPSON
2009-05-02 16:49 . 2009-05-02 16:49 -------- d-----w- c:\documents and settings\All Users\Application Data\DVD Shrink
2009-05-02 16:48 . 2009-05-02 16:48 1915520 ----a-w- c:\documents and settings\Papa\Application Data\Macromedia\Flash Player\
www.macromedia.com\bin\fpupdateax\fpupdateax.exe
2009-05-02 16:35 . 2009-05-02 16:36 9464 ------w- c:\windows\system32\drivers\cdralw2k.sys
2009-05-02 16:35 . 2009-05-02 16:36 9336 ------w- c:\windows\system32\drivers\cdr4_xp.sys
2009-05-02 16:35 . 2009-05-02 16:36 43528 ------w- c:\windows\system32\drivers\PxHelp20.sys
2009-05-02 16:35 . 2009-05-02 16:36 129784 ------w- c:\windows\system32\pxafs.dll
2009-05-02 16:35 . 2009-05-02 16:36 118520 ------w- c:\windows\system32\pxinsi64.exe
2009-05-02 16:35 . 2009-05-02 16:36 116472 ------w- c:\windows\system32\pxcpyi64.exe
2009-05-02 15:53 . 2009-05-02 15:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Brother
2009-05-02 15:51 . 2009-05-02 15:51 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet
2009-05-02 15:43 . 2009-05-02 15:43 -------- d-----w- c:\program files\Adobe Media Player
2009-05-02 15:41 . 2009-05-02 15:41 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-05-02 15:38 . 2009-05-02 15:38 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2009-05-02 15:33 . 2009-05-02 15:33 -------- d-----w- c:\program files\Microsoft IntelliPoint
2009-05-02 15:22 . 2009-05-02 15:22 454688 ----a-w- c:\windows\system32\drivers\timntr.sys
2009-05-02 15:22 . 2009-05-02 15:22 43008 ----a-w- c:\windows\system32\drivers\tifsfilt.sys
2009-05-02 15:22 . 2009-05-02 15:22 132352 ----a-w- c:\windows\system32\drivers\snapman.sys
2009-05-02 14:56 . 2009-05-02 14:45 -------- d-----w- c:\program files\Microsoft Works
2009-05-02 14:35 . 2009-05-02 14:33 -------- d-----w- c:\documents and settings\Papa\Application Data\MiniDm
2009-05-02 14:31 . 2009-05-02 14:30 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-05-02 14:30 . 2009-05-02 14:30 -------- d-----w- c:\program files\Symantec
2009-05-02 14:30 . 2009-05-02 14:30 60800 ----a-w- c:\windows\system32\S32EVNT1.DLL
2009-05-02 14:30 . 2009-05-02 14:30 805 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
2009-05-02 14:30 . 2009-05-02 14:30 123952 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2009-05-02 14:30 . 2009-05-02 14:30 10671 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2009-05-02 14:30 . 2009-05-02 14:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-05-02 13:58 . 2009-05-02 12:40 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-05-02 12:41 . 2009-05-02 12:41 -------- d-----w- c:\program files\microsoft frontpage
2009-05-02 12:38 . 2009-05-02 12:38 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2009-04-29 04:56 . 2004-08-04 12:00 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2004-08-04 12:00 78336 ------w- c:\windows\system32\ieencode.dll
2009-04-17 12:26 . 2004-08-04 12:00 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-08-04 12:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-06-25_10.28.00 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-25 10:28 . 2008-10-16 18:09 51224 c:\windows\system32\dllcache\cache\wuauclt.exe
+ 2009-06-25 10:28 . 2008-04-14 00:12 82432 c:\windows\system32\dllcache\cache\ws2_32.dll
+ 2009-06-25 10:28 . 2008-04-14 00:12 26112 c:\windows\system32\dllcache\cache\userinit.exe
+ 2009-06-25 10:28 . 2008-04-14 00:12 14336 c:\windows\system32\dllcache\cache\svchost.exe
+ 2009-06-25 10:28 . 2008-04-14 00:12 57856 c:\windows\system32\dllcache\cache\spoolsv.exe
+ 2009-06-25 10:28 . 2008-04-14 00:12 17408 c:\windows\system32\dllcache\cache\powrprof.dll
+ 2009-06-25 10:28 . 2008-04-14 00:12 13312 c:\windows\system32\dllcache\cache\lsass.exe
+ 2009-06-25 10:28 . 2008-04-13 18:39 24576 c:\windows\system32\dllcache\cache\kbdclass.sys
+ 2009-06-25 10:28 . 2008-04-13 18:53 36608 c:\windows\system32\dllcache\cache\ip6fw.sys
+ 2009-06-25 10:28 . 2008-04-14 00:12 15360 c:\windows\system32\dllcache\cache\ctfmon.exe
+ 2009-06-26 00:09 . 2009-06-26 00:08 148888 c:\windows\system32\javaws.exe
+ 2009-06-26 00:09 . 2009-06-26 00:08 144792 c:\windows\system32\javaw.exe
+ 2009-06-26 00:09 . 2009-06-26 00:08 144792 c:\windows\system32\java.exe
+ 2009-06-25 10:28 . 2008-04-14 00:12 507904 c:\windows\system32\dllcache\cache\winlogon.exe
+ 2009-06-25 10:28 . 2009-04-29 04:56 827392 c:\windows\system32\dllcache\cache\wininet.dll
+ 2009-06-25 10:28 . 2008-04-14 00:12 578560 c:\windows\system32\dllcache\cache\user32.dll
+ 2009-06-25 10:28 . 2008-04-14 00:12 295424 c:\windows\system32\dllcache\cache\termsrv.dll
+ 2009-06-25 10:28 . 2008-06-20 11:51 361600 c:\windows\system32\dllcache\cache\tcpip.sys
+ 2009-06-25 10:28 . 2009-02-06 11:11 110592 c:\windows\system32\dllcache\cache\services.exe
+ 2009-06-25 10:28 . 2008-04-13 19:20 182656 c:\windows\system32\dllcache\cache\ndis.sys
+ 2009-06-25 10:28 . 2009-03-21 14:06 989696 c:\windows\system32\dllcache\cache\kernel32.dll
+ 2009-06-25 10:28 . 2008-04-14 00:11 110080 c:\windows\system32\dllcache\cache\imm32.dll
+ 2009-06-25 10:28 . 2008-04-14 00:11 167936 c:\windows\system32\dllcache\cache\appmgmts.dll
+ 2009-06-25 10:28 . 2008-04-14 00:12 1614848 c:\windows\system32\dllcache\cache\sfcfiles.dll
+ 2009-06-25 10:28 . 2009-02-06 11:08 2189056 c:\windows\system32\dllcache\cache\ntoskrnl.exe
+ 2009-06-25 10:28 . 2009-02-07 23:02 2066048 c:\windows\system32\dllcache\cache\ntkrnlpa.exe
+ 2009-06-25 10:28 . 2008-04-14 00:12 1033728 c:\windows\system32\dllcache\cache\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe" [2007-08-03 202024]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-27 13684736]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-27 86016]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-06-24 53096]
"vptray"="d:\progra~1\SYMANT~1\VPTray.exe" [2008-09-30 125368]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2009-01-07 1468296]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"SetDefPrt"="d:\program files\Brother\Brmfl04g\BrStDvPt.exe" [2004-11-11 49152]
"ControlCenter2.0"="c:\program files\Brother\ControlCenter2\brctrcen.exe" [2005-01-07 864256]
"SunJavaUpdateSched"="d:\program files\Java\jre6\bin\jusched.exe" [2009-06-26 148888]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-03-27 1657376]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2006-11-17 577536]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-F400-7760-000000000003}\_SC_Acrobat.exe [2009-5-11 295606]
Adobe Acrobat Synchronizer.lnk - d:\program files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe [2006-10-23 734872]
DisplayKEY eSYNC Info.lnk - c:\program files\GE Security Supra\SyncInfoApp.exe [2009-5-15 102400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ckpNotify]
2007-05-24 14:13 24665 ----a-w- c:\windows\system32\ckpNotify.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Program Files\\IEPro\\MiniDM.exe"=
"d:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"d:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_Service.exe"=
"d:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_GUI.exe"=
"d:\\Program Files\\CheckPoint\\SecuRemote\\bin\\scc.exe"=
"d:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_SDS.exe"=
"d:\\Program Files\\CheckPoint\\SecuRemote\\bin\\SR_Diagnostics.exe"=
R1 FW1;SecuRemote Miniport;c:\windows\system32\drivers\fw.sys [5/24/2007 10:13 AM 2234800]
R2 CP_OMDRV;Check Point Office Mode Module;c:\windows\system32\drivers\omdrv.sys [5/24/2007 10:13 AM 36368]
R2 VNASC;Check Point Virtual Network Adapter - SecureClient;c:\windows\system32\drivers\vnasc.sys [5/24/2007 10:13 AM 110032]
R2 VPN-1;VPN-1 Module;c:\windows\system32\drivers\vpn.sys [5/24/2007 10:13 AM 673456]
R2 WinDefend;Windows Defender;d:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [5/8/2009 8:03 PM 101936]
S3 SavRoam;SAVRoam;d:\program files\Symantec AntiVirus\SavRoam.exe [9/30/2008 5:41 PM 116664]
.
Contents of the 'Scheduled Tasks' folder
2009-06-26 c:\windows\Tasks\MP Scheduled Scan.job
- d:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]
2009-06-26 c:\windows\Tasks\SyncToy 2.job
- d:\program files\SyncToy 2.0\SyncToyCmd.exe [2008-08-12 18:07]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
IE: Append to existing PDF - d:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - d:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - d:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - d:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - d:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - d:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - d:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - d:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - d:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Papa\Application Data\Mozilla\Firefox\Profiles\w1zusv1v.default\
FF - plugin: d:\program files\Adobe\Acrobat 8.0\Acrobat\browser\nppdf32.dll
FF - plugin: d:\program files\Mozilla Firefox\plugins\npicaN.dll
FF - plugin: d:\program files\QuickTime\Plugins\npqtplugin.dll
FF - plugin: d:\program files\QuickTime\Plugins\npqtplugin2.dll
FF - plugin: d:\program files\QuickTime\Plugins\npqtplugin3.dll
FF - plugin: d:\program files\QuickTime\Plugins\npqtplugin4.dll
FF - plugin: d:\program files\QuickTime\Plugins\npqtplugin5.dll
FF - plugin: d:\program files\QuickTime\Plugins\npqtplugin6.dll
FF - plugin: d:\program files\QuickTime\Plugins\npqtplugin7.dll
FF - HiddenExtension: Java Console: No Registry Reference - d:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-06-26 22:02
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-06-27 22:03
ComboFix-quarantined-files.txt 2009-06-27 02:03
ComboFix2.txt 2009-06-25 10:28
Pre-Run: 30,509,608,960 bytes free
Post-Run: 30,650,208,256 bytes free
265 --- E O F --- 2009-06-15 10:20
Upload was successful
*************************************************************
This is where Symantec is finding the issues:
C:\Documents and Settings\Anna\Local Settings\temp\~temp\mlp28\
C:\Documents and Settings\Rachel\Local Settings\temp\~temp\mlp28\
C:\Documents and Settings\Anna\Local Settings\temp\~temp\mlp28\
C:\Documents and Settings\Anna\Local Settings\temp\~temp\mlp28\
C:\Documents and Settings\Anna\Local Settings\temp\~temp\mlp28\
C:\Documents and Settings\Anna\Local Settings\temp\~temp\mlp28\
C:\Documents and Settings\Anna\Local Settings\temp\~temp\mlp28\
C:\Documents and Settings\Anna\Local Settings\temp\~temp\mlp28\
C:\Documents and Settings\Anna\Local Settings\temp\~temp\mlp28\
C:\Documents and Settings\Rachel\Local Settings\Temp\~temp\hmunmlcn98\
C:\Documents and Settings\Rachel\Local Settings\Temp\~temp\hmunmlcn96\
C:\Documents and Settings\Rachel\Local Settings\Temp\~temp\hmunmlcn95\
C:\Documents and Settings\Rachel\Local Settings\Temp\~temp\hmunmlcln11\
C:\Documents and Settings\Rachel\Local Settings\Temp\~temp\hmunmlcln06\
C:\Documents and Settings\Rachel\Local Settings\Temp\~temp\hmunmlcln02\
C:\Documents and Settings\Rachel\Local Settings\Temp\~temp\hmrg13\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\hmunmlcn98\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\hmunmlcn95\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\hmunmlcln11\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\hmunmlcln07\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\hmunmlcln06\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\hmrg13\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\hmrg12\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\hmunmlcn96\
C:\Documents and Settings\Leah\Local Settings\Temp\~temp\hmunmlcn95\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\hmunmlcn98\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\hmunmlcn95\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\hmunmlcln11\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\hmunmlcln07\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\hmunmlcln04\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\hmrg13\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\hmrg12\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\hmunmlcn96\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Rachel\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Rachel\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Rachel\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Rachel\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Rachel\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Rachel\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Rachel\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Rachel\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Rachel\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Rachel\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Rachel\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Rachel\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Rachel\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Rachel\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Rachel\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Rachel\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Rachel\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Rachel\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Rachel\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Rachel\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Rachel\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp27\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp26\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp26\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp26\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp26\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp26\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp26\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp26\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp26\
C:\Documents and Settings\Rachel\Local Settings\Temp\~temp\mlp26\
C:\Documents and Settings\Rachel\Local Settings\Temp\~temp\mlp25\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp25\
C:\Documents and Settings\Rachel\Local Settings\Temp\~temp\mlp25\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp25\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp25\
C:\Documents and Settings\Rachel\Local Settings\Temp\~temp\mlp25\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp25\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp25\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp25\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp25\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp25\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp25\
C:\Documents and Settings\Rachel\Local Settings\Temp\~temp\mlp25\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp25\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp25\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp25\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp25\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp25\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp25\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp25\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp25\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp25\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp25\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp25\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp25\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp25\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp25\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp25\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp25\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp25\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp25\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp25\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp25\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp25\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp25\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp25\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp24\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp24\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp24\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp24\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp24\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp24\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp24\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp24\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp24\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp24\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp24\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp24\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp24\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp23\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp23\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp23\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp23\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp23\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp23\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp23\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp23\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp23\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp23\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Rachel\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Rachel\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Rachel\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Rachel\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Rachel\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Rachel\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Anna\Local Settings\Temp\~temp\mlp22\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp21\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp21\
C:\Documents and Settings\Papa\Local Settings\Temp\~temp\mlp21\
***************************************************************
Fresh HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:45:21 PM, on 6/26/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16850)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
D:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
D:\Program Files\CheckPoint\SecuRemote\bin\SR_Watchdog.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Symantec AntiVirus\DefWatch.exe
c:\program files\ge security supra\syncservice.exe
C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\GE Security Supra\ProxyDaemon.exe
C:\SSL\stunnel-4.10.exe
D:\Program Files\CheckPoint\SecuRemote\bin\SR_GUI.Exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
D:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Brother\ControlCenter2\brctrcen.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\GE Security Supra\SyncInfoApp.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Microsoft Office\Office12\EXCEL.EXE
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\wuauclt.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - d:\Program Files\IEPro\iepro.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] D:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SetDefPrt] d:\Program Files\Brother\Brmfl04g\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-21-1220945662-1532298954-839522115-1004\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Anna')
O4 - HKUS\S-1-5-21-1220945662-1532298954-839522115-1004\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe" (User 'Anna')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe
O4 - Global Startup: DisplayKEY eSYNC Info.lnk = C:\Program Files\GE Security Supra\SyncInfoApp.exe
O8 - Extra context menu item: Append to existing PDF - res://D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - d:\Program Files\IEPro\iepro.dll
O9 - Extra 'Tools' menuitem: IE7Pro Grab and Drag - {000002a3-84fe-43f1-b958-f2c3ca804f1a} - d:\Program Files\IEPro\iepro.dll
O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - d:\Program Files\IEPro\iepro.dll
O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - d:\Program Files\IEPro\iepro.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) -
http://h20270.www2.hp.com/ediags/gmn...Detection2.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - D:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: DkeySync - GE Security Supra - c:\program files\ge security supra\syncservice.exe
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - D:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Check Point VPN-1 Securemote service (SR_Service) - Check Point Software Technologies - D:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
O23 - Service: Check Point VPN-1 Securemote watchdog (SR_Watchdog) - Check Point Software Technologies - D:\Program Files\CheckPoint\SecuRemote\bin\SR_Watchdog.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - D:\Program Files\Symantec AntiVirus\Rtvscan.exe
--
End of file - 9848 bytes
*************************************************************
Thanks!