SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 07/22/2007 at 11:43 PM
Application Version : 3.9.1008
Core Rules Database Version : 3272
Trace Rules Database Version: 1283
Scan type : Complete Scan
Total Scan Time : 01:27:50
Memory items scanned : 445
Memory threats detected : 1
Registry items scanned : 5676
Registry threats detected : 18
File items scanned : 89058
File threats detected : 147
Trojan.REGSCAN
C:\WINDOWS\SYSTEM32\REGSCAN.EXE
C:\WINDOWS\SYSTEM32\REGSCAN.EXE
[Regscan] C:\WINDOWS\SYSTEM32\REGSCAN.EXE
Unclassified.Unknown Origin
HKLM\Software\Classes\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}
HKCR\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}
HKCR\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}
HKCR\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}\InprocServer32
HKCR\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\PCSEYGZT.DLL
HKLM\Software\Microsoft\Internet Explorer\Toolbar#{11A69AE4-FBED-4832-A2BF-45AF82825583}
HKU\S-1-5-21-596918897-4040977404-3606967878-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser#{11A69AE4-FBED-4832-A2BF-45AF82825583}
C:\DOCUMENTS AND SETTINGS\DEFAULT USER\DESKTOP\AIMFIX_QUARANTINE\9205_GAH95ON6.EXE.BAK
C:\DOCUMENTS AND SETTINGS\OWNER\DESKTOP\AIMFIX_QUARANTINE\9205_GAH95ON6.EXE.BAK
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\HAMMER.DLL.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\WINDOWS MEDIA PLAYER\QUSOXYCO83122.DLL.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\IA\COMMAND.EXE.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\PCSEYGZT.DLL.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019881.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019907.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019925.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0021015.DLL
C:\_OTMOVEIT\MOVEDFILES\WINDOWS\SYSTEM32\PCSEYGZT.DLL
Adware.Vundo Variant
HKLM\Software\Classes\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}
HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}
HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}\InprocServer32
HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}\InprocServer32#ThreadingModel
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}
HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}
Adware.Tracking Cookie
C:\Documents and Settings\Owner\Cookies\owner@revsci[2].txt
C:\Documents and Settings\Owner\Cookies\owner@html[1].txt
C:\Documents and Settings\Owner\Cookies\owner@atwola[1].txt
C:\Documents and Settings\Owner\Cookies\owner@doubleclick[1].txt
Trojan.Windows Overlay Components/SysMon
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OvMon
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OvMon#DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OvMon#UninstallStr ing
Adware.MediaMotor
C:\WINDOWS\Downloaded Program Files\amm06.inf
C:\WINDOWS\mm06y.ini
C:\WINDOWS\AMM06.OCX
C:\WINDOWS\LASTGOOD\AMM06.OCX
C:\WINDOWS\UNSTALL.EXE
Trojan.Malware
C:\asdf.txt
Trojan.PestTrap
HKU\S-1-5-21-596918897-4040977404-3606967878-1003\Software\SNO2
Adware.IEPlugin
C:\WINDOWS\lu.dat
Adware.Media Access
C:\Program Files\Media Access\Info.txt
C:\Program Files\Media Access\MediaAccC.dll
C:\Program Files\Media Access\MediaAccess.exe
C:\Program Files\Media Access\MediaAccK.exe
C:\Program Files\Media Access
Adware.ConsumerAlertSystem
C:\DIST13.EXE
C:\DOCUMENTS AND SETTINGS\DEFAULT USER\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\Y03SUEJZ\DIST13[1].EXE
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\CAS2STUB\CAS2STUB.EXE.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\SYSTEM FILES\PLUGIN.DLL.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\SYSTEM FILES\SYSTEM.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019883.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019886.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019887.EXE
Adware.SurfSideKick
C:\DOCUMENTS AND SETTINGS\DEFAULT USER\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\X3HRT28M\SS1001[1].EXE
C:\SS1001NEWER.EXE
Trojan.Downloader-Gen/Doh
C:\DOCUMENTS AND SETTINGS\DEFAULT USER\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\Y8U1ZP4S\DOHINST-103[1].0000
Trojan.Unknown Origin
C:\DOCUMENTS AND SETTINGS\OWNER\LOCAL SETTINGS\TEMP\ICO14.TMP
C:\DOCUMENTS AND SETTINGS\OWNER\LOCAL SETTINGS\TEMP\ICO15.TMP
C:\DOCUMENTS AND SETTINGS\OWNER\LOCAL SETTINGS\TEMP\ICO16.TMP
C:\DOCUMENTS AND SETTINGS\OWNER\LOCAL SETTINGS\TEMP\ICO17.TMP
C:\DOCUMENTS AND SETTINGS\OWNER\LOCAL SETTINGS\TEMP\ICO19.TMP
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\COMMON FILES\{18A19~1\SERVICES.DLL.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\IA\KE.VBS.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\PF78.EXE.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\TELLER2.CHK.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\UNINSTALL_NMON.VBS.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0013350.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019860.VBS
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019882.VBS
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019892.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019900.EXE
C:\WINDOWS\TEMPF.TXT
BearShare File Sharing Client
C:\PROGRAM FILES\BEARSHARE\BEARSHARE.EXE
Trojan.WinAntiSpyware/WinAntiVirus 2006
C:\QOOBOX\QUARANTINE\C\DOCUME~1\OWNER\APPLIC~1\WINANTISPYWARE2007FREEINSTAL L[1].EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0013381.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019905.EXE
Trojan.WinSysBan
C:\QOOBOX\QUARANTINE\C\KYBRDFG_7.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019856.EXE
Trojan.CmdService
C:\QOOBOX\QUARANTINE\C\MTE3NDI6ODOXNG.EXE.VIR
C:\QOOBOX\QUARANTINE\C\MTE3NDI6ODOXNGNEW.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019857.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019858.EXE
Adware.Director
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\COMMON FILES\{18A19~1\UPDATE.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019893.EXE
Trojan.ZQuest
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\MSN GAMING ZONE\TEFA.DLL.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\MSN GAMING ZONE\TEFA120.DLL.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\MSN GAMING ZONE\TEFA196.DLL.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\MSN GAMING ZONE\TEFA249.DLL.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\MSN GAMING ZONE\TEFA3.DLL.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\MSN GAMING ZONE\TEFA313.DLL.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\MSN GAMING ZONE\TEFA327.DLL.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\MSN GAMING ZONE\TEFA649.DLL.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\MSN GAMING ZONE\TEFA774.DLL.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\MSN GAMING ZONE\TEFA855.DLL.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\MSN GAMING ZONE\TEFA970.DLL.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019867.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019868.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019869.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019870.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019871.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019872.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019873.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019874.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019875.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019876.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019877.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019878.DLL
Adware.k8l
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\MSN GAMING ZONE\XUNE.HTML.VIR
Trojan.NetMon/DNSChange
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\NETWORK MONITOR\NETMON.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019884.EXE
Trojan.Downloader-Gen/BasicMath
C:\QOOBOX\QUARANTINE\C\WINDOWS\DLS0523PMW.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019898.EXE
Adware.Adservs
C:\QOOBOX\QUARANTINE\C\WINDOWS\IA\ASAPPSRV.DLL.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019880.DLL
Trojan.Downloader-VisFX
C:\QOOBOX\QUARANTINE\C\WINDOWS\OFFUN.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019899.EXE
Adware.Vundo/Traff-2
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\AFJBKNTS.EXE.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\MBTSNRFD.EXE.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\PNWGMIXN.EXE.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\QWBGYJEE.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019913.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019914.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019916.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019917.EXE
Adware.SysMon
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\B5\Z53.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019897.EXE
Trojan.Downloader-Gen/TStamp
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\FIQEVANV.EXE.VIR
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\OHKGHPLR.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019915.EXE
Adware.SearchAssistant
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32BEZ6N4R21.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019902.EXE
Unclassified.Unknown Origin/System
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32GHYNF.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019903.EXE
Adware.ZenoSearch
C:\QOOBOX\QUARANTINE\C\WINDOWS\TISKY009.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019909.EXE
Trojan.ZQuest-Installer
C:\QOOBOX\QUARANTINE\C\WINDOWS\TK58.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0013257.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0013346.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0013380.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0014412.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0014428.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0014446.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0014460.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019908.EXE
Adware.WebBuying Assistant-Installer
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0013233.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0013241.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0013242.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0013334.EXE
Adware.ClickSpring-Variant
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0013328.EXE
Adware.ClickSpring/Resident
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0013348.DLL
Adware.ClickSpring
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0013349.EXE
Adware.ClickSpring/Outer Info Network
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0013385.EXE
Trojan.Downloader-Gen/RetAd
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0014465.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019611.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019630.EXE
Trojan.Rootkit-TnCore
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019615.SYS
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019624.SYS
Trojan.Freeprod
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019627.EXE
Malware.SystemDoctor
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019634.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019635.EXE
Trojan.Rootkit-TnCore/Installer
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019896.EXE
Trojan.Downloader-Gen/HitItQuitIt
C:\SYSTEM VOLUME INFORMATION\_RESTORE{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP302\A0019924.DLL
Adware.Mirar/NetNucleus
C:\WINDOWS\MIRAR.EXE
-------------------------------------------------------------------------------------
here is the hijack this log:
Logfile of HijackThis v1.99.1
Scan saved at 10:47:52 PM, on 7/23/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\LTMSG.exe
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\WinZip110\WZQKPICK.EXE
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\msiexec.exe
C:\Program Files\Hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://srch-qus10.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.osu.edu/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://qus10.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://srch-qus10.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://srch-qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip110\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) -
http://upload.facebook.com/controls/...toUploader.cab
O20 - AppInit_DLLs:
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: pcseygzt - pcseygzt.dll (file missing)
O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - C:\Program Files\Network Associates\VirusScan\avsynmgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files\McAfee\Common Framework\FrameworkService.exe" /ServiceStart (file missing)
O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\mcshield.exe (file missing)
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe