"phil" - 2007-07-11 23:14:39 - ComboFix 07-07-12.3 - Service Pack 2
/wow section - STAGE #8
(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\jidnihee.dll
C:\WINDOWS\system32\mfoixehh.dll
C:\WINDOWS\system32\lsctfhfk.exe
C:\WINDOWS\system32\winjks32.dll
C:\WINDOWS\system32\eehindij.ini
C:\WINDOWS\system32\ggjlm.bak1
C:\WINDOWS\system32\ggjlm.bak2
C:\WINDOWS\system32\ggjlm.ini
C:\WINDOWS\system32\ggjlm.bak1
C:\WINDOWS\system32\ggjlm.bak2
C:\WINDOWS\system32\ggjlm.ini
C:\WINDOWS\system32\mljgg.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
((((((((((((((((((((((((( Files Created from 2007-06-12 to 2007-07-12 )))))))))))))))))))))))))))))))
2007-07-11 23:13 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-11 18:10 <DIR> d-------- C:\Program Files\Trend Micro
2007-07-11 16:22 66,112 --a------ C:\WINDOWS\system32\awdqrkrb.exe
2007-07-11 06:10 43,528 --------- C:\WINDOWS\system32\drivers\PxHelp20.sys
2007-07-11 06:09 <DIR> d-------- C:\DOCUME~1\phil\APPLIC~1\Winamp
2007-07-11 04:26 <DIR> d-------- C:\WINDOWS\system32\msmq
2007-07-11 03:02 22,080 --a------ C:\WINDOWS\system32\drivers\sshrmd.sys
2007-07-11 03:02 21,056 --a------ C:\WINDOWS\system32\drivers\sskbfd.sys
2007-07-11 03:02 20,544 --a------ C:\WINDOWS\system32\drivers\SSFS0509.sys
2007-07-11 03:02 144,448 --a------ C:\WINDOWS\system32\drivers\ssidrv.sys
2007-07-11 03:02 <DIR> d-------- C:\Program Files\Webroot
2007-07-11 03:02 <DIR> d-------- C:\DOCUME~1\LOCALS~1\APPLIC~1\Webroot
2007-07-11 03:02 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Webroot
2007-07-11 02:59 <DIR> d-------- C:\DOCUME~1\phil\APPLIC~1\Webroot
2007-07-11 01:36 31,254 --a------ C:\WINDOWS\system32\rqrrpnk.dll
2007-07-09 19:56 <DIR> d-------- C:\ATARI
2007-07-09 19:55 <DIR> d-------- C:\MAME
2007-07-08 20:27 <DIR> d-------- C:\N64
2007-07-08 20:26 <DIR> d-------- C:\snes9x
2007-07-08 20:23 <DIR> d-------- C:\Sega Genesis
2007-07-08 20:23 <DIR> d-------- C:\PJ64
2007-07-08 20:21 <DIR> d-------- C:\zSNES
2007-07-08 19:19 31,254 --a------ C:\WINDOWS\system32\byxwvsq.dll
2007-07-04 02:51 <DIR> d-------- C:\LEMMINGS
2007-07-02 15:13 81,984 --a------ C:\WINDOWS\system32\bdod.bin
2007-07-01 20:09 <DIR> d-------- C:\Program Files\Symantec AntiVirus
2007-06-30 22:05 <DIR> d-------- C:\Program Files\Aquarius Soft
2007-06-30 22:05 <DIR> d-------- C:\DOCUME~1\phil\APPLIC~1\Aquarius Soft
2007-06-30 22:05 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Aquarius Soft
2007-06-29 22:58 110,592 --a------ C:\WINDOWS\system32\ccrpbds6.dll
2007-06-29 22:58 <DIR> d-------- C:\Program Files\PIXresizer
2007-06-29 16:53 12,288 --a------ C:\WINDOWS\mgrs.exe
2007-06-29 15:18 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\MSN Messenger 6.1.0207
2007-06-29 15:17 <DIR> d-------- C:\Program Files\MSN Messenger
2007-06-27 22:05 <DIR> d-------- C:\Program Files\DosBox
2007-06-27 22:04 <DIR> d-------- C:\Program Files\Tyrian
2007-06-23 19:17 <DIR> d-------- C:\Program Files\Lavasoft
2007-06-23 19:16 <DIR> d-------- C:\WINDOWS\Video to iPod MP4 PSP 3GP Converter
2007-06-23 19:16 <DIR> d-------- C:\Program Files\Video to iPod MP4 PSP 3GP Converter
2007-06-23 00:07 <DIR> d-------- C:\WINDOWS\Replay Media Catcher
2007-06-23 00:07 <DIR> d-------- C:\Program Files\Replay Media Catcher
2007-06-22 14:04 <DIR> d-------- C:\Program Files\FLVPlayer
2007-06-22 02:27 <DIR> d-------- C:\DOCUME~1\phil\APPLIC~1\SWF.max
2007-06-22 02:26 <DIR> d-------- C:\Program Files\SWF.max
2007-06-22 00:08 <DIR> d-------- C:\Program Files\Sony
2007-06-21 19:07 <DIR> d-------- C:\Program Files\iPod
2007-06-20 01:14 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2007-06-20 00:52 <DIR> d-------- C:\Program Files\Publisher XP
2007-06-20 00:12 476,576 -ra------ C:\Program Files\SETUP.EXE
2007-06-19 23:59 1,499,904 -ra------ C:\Program Files\INSTMSIW.EXE
2007-06-19 23:59 1,489,152 -ra------ C:\Program Files\INSTMSI.EXE
2007-06-19 23:54 <DIR> d-------- C:\Program Files\FILES
2007-06-19 23:53 <DIR> d-------- C:\Program Files\SHAREPT
2007-06-19 23:51 <DIR> d-------- C:\Program Files\ORK
2007-06-19 23:51 <DIR> d-------- C:\Program Files\MSDE2000
2007-06-18 17:36 <DIR> d-------- C:\Program Files\BitTorrent
2007-06-18 17:36 <DIR> d-------- C:\DOCUME~1\phil\APPLIC~1\BitTorrent
2007-06-17 22:16 <DIR> d-------- C:\Downloads
2007-06-17 22:15 <DIR> d-------- C:\Program Files\BitComet
2007-06-16 09:33 <DIR> d-------- C:\Program Files\System
2007-06-16 09:24 <DIR> d-------- C:\Program Files\iTunes
2007-06-16 09:21 <DIR> d-------- C:\Program Files\Library
2007-06-16 09:21 <DIR> d-------- C:\Program Files\Developer
2007-06-16 05:19 7,852 --a------ C:\WINDOWS\system32\mcdmsg7.dll
2007-06-16 04:38 <DIR> d-------- C:\Program Files\TGTSoft
2007-06-15 17:16 <DIR> d-------- C:\Program Files\Common Files\Stardock
2007-06-13 17:55 <DIR> d-------- C:\DOCUME~1\phil\APPLIC~1\uTorrent
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-11 10:13:50 -------- d-----w C:\Program Files\Winamp
2007-07-11 08:57:48 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-07-11 08:51:35 -------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-07-11 08:51:30 -------- d-----w C:\Program Files\Symantec
2007-07-11 08:46:21 -------- d-----w C:\Program Files\LimeWire
2007-07-11 08:42:45 -------- d-----w C:\Program Files\Common Files\Corel
2007-07-11 08:26:45 -------- d-----w C:\Program Files\Windows NT
2007-07-11 03:37:17 -------- d-----w C:\Program Files\Common Files\Intuit
2007-07-11 03:29:26 -------- d-----w C:\Program Files\Stardock
2007-07-11 02:41:28 -------- d-----w C:\Program Files\DivX
2007-07-08 22:50:24 -------- d-----w C:\DOCUME~1\phil\APPLIC~1\OpenOffice.org2
2007-07-02 00:43:20 -------- d-----w C:\Program Files\Symantec_Client_Security
2007-06-23 23:11:47 -------- d-----w C:\Program Files\Common Files\AOL
2007-06-19 06:15:09 -------- d-----w C:\Program Files\Google
2007-06-16 08:13:50 3,350 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2007-06-16 08:13:30 56 --sh--r C:\WINDOWS\system32\01003E142A.sys
2007-06-01 01:32:03 -------- d-----w C:\Program Files\Mozilla Firefox 2 Beta 2
2007-05-29 01:15:52 -------- d-----w C:\DOCUME~1\phil\APPLIC~1\AdobeUM
2007-05-20 04:32:27 -------- d-----w C:\DOCUME~1\phil\APPLIC~1\Ambient Design
2007-05-20 04:07:02 -------- d-----w C:\Program Files\Ambient Design
2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-04-30 20:02:15 664 ----a-w C:\WINDOWS\system32\d3d9caps.dat
2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-17 02:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-17 02:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 02:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 02:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 02:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 02:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 02:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 02:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-04-13 07:21:14 271,360 ----a-w C:\WINDOWS\system32\mscoree.dll
2006-02-17 03:15:26 774,144 -c--a-w C:\Program Files\RngInterstitial.dll
2004-01-15 06:34:18 259,539,966 ----a-w C:\Program Files\Microsoft Office XP Publisher 2003.zip
2001-04-04 22:11:28 184 ---ha-r C:\Program Files\AUTORUN.INF
2001-04-03 00:50:14 29 ----a-r C:\Program Files\cd-key.txt
2001-03-02 04:38:12 3,485,184 ----a-r C:\Program Files\PROPLUS.MSI
2001-03-02 04:35:58 306,688 ----a-r C:\Program Files\OWC10.MSI
2001-03-01 19:35:26 224,771,818 ---ha-r C:\Program Files\OFFICE1.CAB
2001-02-21 17:18:24 7,929 ----a-r C:\Program Files\README.HTM
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2004-12-14 01:56 63136 --a------ C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4D25F921-B9FE-4682-BF72-8AB8210D6D75}]
2005-06-14 15:56 86016 --a------ C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5CA3D70E-1895-11CF-8E15-001234567890}]
2004-12-06 03:05 118842 --a------ C:\WINDOWS\system32\dla\tfswshx.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2006-12-15 03:23 440056 --a------ C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FB40D31A-B1F8-47EA-BC54-D27DDB475978}]
C:\WINDOWS\system32\oppnljh.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD2A7D3A-3DA1-4CA5-AD39-B4C3A72B567F}]
2007-07-08 19:19 31254 --a------ C:\WINDOWS\system32\byxwvsq.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-23 02:20 C:\WINDOWS\stsystra.exe]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 18:19]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 12:44]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 12:44]
"@"="" []
"Zone Labs Client"="C:\Program Files\Zone Labs\Integrity Client\iclient.exe" [2004-06-28 05:34]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [2005-07-12 21:05]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-02-26 17:54]
"HostManager"="C:\Program Files\Common Files\AOL\1160275593\ee\AOLSoftware.exe" [2006-05-24 07:15]
"IPHSend"="C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-06-01 16:51]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-06-19 02:15]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" [2006-12-15 03:23]
"MsmqIntCert"="regsvr32 /s mqrt.dll" []
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-05-14 18:22]
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2007-01-25 21:58]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 07:00]
"@"="" []
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{FB40D31A-B1F8-47EA-BC54-D27DDB475978}"="C:\WINDOWS\system32\oppnljh.dll" []
"{FD2A7D3A-3DA1-4CA5-AD39-B4C3A72B567F}"="C:\WINDOWS\system32\byxwvsq.dll" [2007-07-08 19:19]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\byxwvsq]
byxwvsq.dll --a------ 2007-07-08 19:19 31254 C:\WINDOWS\system32\byxwvsq.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\oppnljh]
oppnljh.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll --a------ 2005-11-28 15:52 176128 C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\WbSrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\WebrootSpySweeperService]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
AutoRun\command- E:\setup.exe
Contents of the 'Scheduled Tasks' folder
2007-07-05 14:51:02 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-07-11 23:22:00
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-11 23:27:34 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-07-11 23:27
--- E O F ---
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:31:11 PM, on 7/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Zone Labs\Integrity Client\iclient.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\AOL\1160275593\ee\AOLSoftware.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Aquarius Soft\PC Keyboard Hotkey Pro\khotkeys.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox 2 Beta 2\firefox.exe
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\agent.exe
C:\WINDOWS\system32\MsiExec.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\Integrity Client\iclient.exe"
O4 - HKLM\..\Run: [MSKDetectorExe] "C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" /uninstall
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HostManager] "C:\Program Files\Common Files\AOL\1160275593\ee\AOLSoftware.exe"
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Aquarius Soft PC Keyboard Hotkey Pro.lnk = C:\Program Files\Aquarius Soft\PC Keyboard Hotkey Pro\khotkeys.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\phil\Start Menu\Programs\>IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
--
End of file - 6661 bytes