compstill slow, there are still 51 processes, but i havent had a popup yet. so we re improving; here is combo fix log
User - 06-08-31 22:37:41.50
ComboFix 06.08.30BT - Running from: C:\
((((((((((((((((((((((((((((((((((((((((((((( Look2Me's Log ))))))))))))))))))))))))))))))))))))))))))))))))))
REGISTRY ENTRIES REMOVED:
[HKEY_CLASSES_ROOT\CLSID\{31E0A4B0-C33D-48AA-A0A8-62BAF4BA898F}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{31E0A4B0-C33D-48AA-A0A8-62BAF4BA898F}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{31E0A4B0-C33D-48AA-A0A8-62BAF4BA898F}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{31E0A4B0-C33D-48AA-A0A8-62BAF4BA898F}\InprocServer32]
@="C:\\WINDOWS\\system32\\iuetmib1.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{E18E0473-9079-4D37-9126-454A01A58A3C}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{E18E0473-9079-4D37-9126-454A01A58A3C}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{E18E0473-9079-4D37-9126-454A01A58A3C}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{E18E0473-9079-4D37-9126-454A01A58A3C}\InprocServer32]
@="C:\\WINDOWS\\system32\\uwat.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{3747B12D-3CF3-4704-B191-0536B8CE56AC}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{3747B12D-3CF3-4704-B191-0536B8CE56AC}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{3747B12D-3CF3-4704-B191-0536B8CE56AC}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{3747B12D-3CF3-4704-B191-0536B8CE56AC}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{0C2A5340-4A04-44AE-B270-BEC2E781B212}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{0C2A5340-4A04-44AE-B270-BEC2E781B212}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{0C2A5340-4A04-44AE-B270-BEC2E781B212}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{0C2A5340-4A04-44AE-B270-BEC2E781B212}\InprocServer32]
@="C:\\WINDOWS\\system32\\marepl40.dll"
"ThreadingModel"="Apartment"
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
Granting sedebugprivilege to Administrators ... successful
((((((((((((((((((((((((((((((((((((((((((((( Qoologic's Log )))))))))))))))))))))))))))))))))))))))))))))))))))
* * * PRE-RUN - Filepaths extracted from the Registry * * * * * * * * * * * * * * * * * * * * * *
O4 - HKEY_CURRENT_USER\...\Run C:\WINDOWS\system32\orruho.exe
O4 - HKEY_LOCAL_MACHINE\...\Run C:\WINDOWS\system32\orruho.exe
F2 -REG:system.ini: Shell C:\WINDOWS\system32\fbiyg.exe
F2 -REG:system.ini: UserInit C:\WINDOWS\system32\qwpdrtp.exe
* * * PRE-RUN - Filepaths from Locate * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
2006-08-31 13:32 236261 -r--s---- C:\WINDOWS\system32\phbase.dll
2006-08-31 05:56 235204 -r--s---- C:\WINDOWS\system32\nbcfg.dll
2006-08-31 05:36 51712 --a------ C:\WINDOWS\system32\uyruxwb.dll
2006-08-31 05:36 127488 --a------ C:\WINDOWS\system32\upgxs.dat
2006-08-29 02:54 28672 --a------ C:\WINDOWS\system32\ra8pv.exe
2006-08-29 02:51 53 --a------ C:\WINDOWS\vwvwvv.dat
2006-08-29 02:51 28672 --a------ C:\WINDOWS\system32\fbiyg.exe
2006-08-29 02:51 127488 --a------ C:\WINDOWS\system32\orruho.exe
2006-08-29 02:51 127488 --a------ C:\Documents and Settings\All Users\Start Menu\Programs\Startup\haevn.exe
2006-08-21 08:36 78848 --a------ C:\WINDOWS\system32\nsj221.dll
2006-08-07 16:02 534208 --a------ C:\WINDOWS\system32\SymNeti.dll
2006-07-21 01:24 72704 --a------ C:\WINDOWS\system32\hlink.dll
* * * PRE-RUN - Filepaths extracted by Memory Dump * * * * * * * * * * * * * * * * * * * * * *
2006-08-29 02:51 127488 C:\WINDOWS\system32\orruho.exe
2006-08-31 05:36 51712 C:\WINDOWS\system32\uyruxwb.dll
2006-08-29 02:51 23552 C:\WINDOWS\system32\qwpdrtp.exe
2006-08-29 02:51 127488 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\haevn.exe
2006-08-31 13:50 481 C:\WINDOWS\nnxcx.dll
2006-08-31 05:36 127488 C:\WINDOWS\system32\upgxs.dat
2006-08-29 02:51 28672 C:\WINDOWS\system32\fbiyg.exe
* * * POST-RUN - Files in the Quarantine folder * * * * * * * * * * * * * * * * * * * * * * * * *
06-08-29 02:51 53 vwvwvv.dat.qoo
DO NOT DELETE ANY FILES FROM THIS DIRECTORY UNLESS INSTRUCTED TO
((((((((((((((((((((((((((((((((((((((((((( E-Give / Ssk's Log )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Documents and Settings\User\Application Data\Sskdmns.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\aaa00000.dll
C:\WINDOWS\system32\aaa00000.sys
((((((((((((((((((((((((((((((( Files Created from 2006-07-31 to 2006-08-31 ))))))))))))))))))))))))))))))))))
2006-08-31 22:35 298,542 --a------ C:\combofix.exe
2006-08-31 22:19 235,752 -r--s---- C:\WINDOWS\system32\kt22l7fo1.dll
2006-08-31 22:19 234,525 -r--s---- C:\WINDOWS\system32\marepl40.dll
2006-08-31 22:12 234,525 -r--s---- C:\WINDOWS\system32\dn2601fse.dll
2006-08-31 13:32 236,261 -r--s---- C:\WINDOWS\system32\phbase.dll
2006-08-31 05:56 235,204 -r--s---- C:\WINDOWS\system32\nbcfg.dll
2006-08-31 05:36 51,712 --------- C:\WINDOWS\system32\uyruxwb.dll
2006-08-30 23:31 87,808 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2006-08-29 02:56 28,672 --a------ C:\WINDOWS\system32ra8pv.exe
2006-08-29 02:54 28,672 --a------ C:\WINDOWS\system32\ra8pv.exe
2006-08-29 02:52 186,223 --a------ C:\WINDOWS\srvuleexmw.exe
2006-08-29 02:51 481 --a------ C:\WINDOWS\nnxcx.dll
2006-08-29 02:51 28,672 --------- C:\WINDOWS\system32\fbiyg.exe
2006-08-29 02:51 23,552 --a------ C:\WINDOWS\system32\qwpdrtp.exe
2006-08-29 02:51 127,488 --------- C:\WINDOWS\system32\orruho.exe
2006-08-29 02:50 215,308 --a------ C:\WINDOWS\srvthaitgd.exe
2006-08-29 01:48 61,952 --a------ C:\WINDOWS\system32\ztvb3ef2.dll
2006-08-29 01:48 215,308 --a------ C:\WINDOWS\Setup90.exe
2006-08-29 01:48 1,233 --a------ C:\WINDOWS\system32\ztvb3ef2.sys
2006-08-21 08:36 78,848 --a------ C:\WINDOWS\system32\nsj221.dll
2006-08-07 16:02 534,208 --a------ C:\WINDOWS\system32\SymNeti.dll
2006-08-07 16:02 161,472 --a------ C:\WINDOWS\system32\SymRedir.dll
2006-08-03 00:05 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll
2006-08-03 00:05 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll
2006-08-03 00:05 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll
2006-08-03 00:05 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
2006-08-03 00:05 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll
2006-08-03 00:05 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll
2006-08-02 03:37 229,450 --a------ C:\WINDOWS\system32\ocpTools.dll
2006-07-31 09:25 24,576 --a------ C:\WINDOWS\system32\ewxcksr.exe
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-08-31 05:16 -------- d-------- C:\Program Files\ewido anti-malware
2006-08-31 04:10 -------- d-------- C:\Documents and Settings\User\Application Data\Azureus
2006-08-31 00:40 -------- d-------- C:\Program Files\Norton AntiVirus
2006-08-31 00:40 -------- d-------- C:\Program Files\Common Files\Symantec Shared
2006-08-31 00:00 -------- d-------- C:\Program Files\Symantec
2006-08-30 23:59 -------- d-------- C:\Program Files\Common Files
2006-08-30 23:38 -------- d-------- C:\Documents and Settings\User\Application Data\Symantec
2006-08-30 23:31 10344 --a------ C:\WINDOWS\system32\drivers\symlcbrd.sys
2006-08-30 05:17 -------- d-------- C:\Program Files\msn gaming zone
2006-08-30 05:13 -------- d-------- C:\Program Files\MSN
2006-08-30 05:13 -------- d-------- C:\Program Files\Common Files\ooim
2006-08-30 01:31 -------- d-------- C:\Program Files\Azureus
2006-08-30 01:26 -------- d-------- C:\Program Files\PowerISO
2006-08-29 04:20 -------- d-------- C:\Program Files\Yahoo!
2006-08-29 04:17 -------- d-------- C:\Program Files\Microsoft ActiveSync
2006-08-29 04:06 -------- d-------- C:\Program Files\Matroska Pack
2006-08-29 04:03 -------- d-------- C:\Program Files\Common Files\Adobe
2006-08-29 03:14 -------- d-------- C:\Program Files\Online Services
2006-08-29 02:34 -------- d-------- C:\Documents and Settings\User\Application Data\Lavasoft
2006-08-29 02:33 -------- d-------- C:\Program Files\Lavasoft
2006-08-25 18:10 -------- d-------- C:\Program Files\LimeWire
2006-08-24 05:59 -------- d-------- C:\Documents and Settings\User\Application Data\Skype
2006-08-22 20:31 -------- d-------- C:\Documents and Settings\User\Application Data\LimeWire
2006-08-16 05:06 -------- d-------- C:\Documents and Settings\User\Application Data\Apple Computer
2006-08-16 04:19 -------- d-------- C:\Program Files\Kazaa Lite K++
2006-08-16 04:19 -------- d-------- C:\Documents and Settings\User\Application Data\Kazaa Lite
2006-08-14 23:54 -------- d-------- C:\Program Files\Internet Explorer
2006-08-07 16:02 31936 --a------ C:\WINDOWS\system32\drivers\symids.sys
2006-08-07 16:02 28352 --a------ C:\WINDOWS\system32\drivers\symndis.sys
2006-08-07 16:02 24768 --a------ C:\WINDOWS\system32\drivers\symredrv.sys
2006-08-07 16:02 195776 --a------ C:\WINDOWS\system32\drivers\symtdi.sys
2006-08-07 16:02 110784 --a------ C:\WINDOWS\system32\drivers\symfw.sys
2006-08-07 16:01 12992 --a------ C:\WINDOWS\system32\drivers\symdns.sys
2006-08-03 00:05 -------- d-------- C:\Program Files\Common Files\Ahead
2006-08-03 00:05 -------- d-------- C:\Program Files\Ahead
2006-08-02 03:37 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-08-02 03:37 -------- d-------- C:\Program Files\OCP Software
2006-08-02 03:37 -------- d-------- C:\Program Files\Common Files\OCP Software
2006-08-01 19:39 -------- d-------- C:\Program Files\SmartArchiver
2006-07-29 04:11 30601 --a------ C:\WINDOWS\system32\drivers\scdemu.sys
2006-07-27 06:24 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-07-21 01:24 72704 --a------ C:\WINDOWS\system32\hlink.dll
2006-07-11 01:18 -------- d-------- C:\Documents and Settings\User\Application Data\Sprite Software
2006-07-11 01:18 -------- d-------- C:\Documents and Settings\User\Application Data\Sprite Setup Wizard
2006-07-11 01:18 -------- d-------- C:\Documents and Settings\User\Application Data\Sprite PC Agent
2006-07-07 21:51 -------- d---s---- C:\Documents and Settings\User\Application Data\Microsoft
2006-06-22 01:35 3082 --a------ C:\WINDOWS\system32\affv11300p4now.sys
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe"
@=""
"IntelWireless"="C:\\Program Files\\Intel\\Wireless\\Bin\\ifrmewrk.exe /tf Intel PROSet/Wireless"
"EOUApp"="C:\\Program Files\\Intel\\Wireless\\Bin\\EOUWiz.exe"
"\\\\KAYLEE\\EPSON Stylus Photo R300 Series"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_S4I2F1.EXE /P39 \"\\\\KAYLEE\\EPSON Stylus Photo R300 Series\" /O6 \"USB003\" /M \"Stylus Photo R300\""
"Auto EPSON Stylus C86 Series on loren"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_S4I2R1.EXE /P37 \"Auto EPSON Stylus C86 Series on loren\" /O20 \"\\\\LOREN\\EPSONStylusC\" /M \"Stylus C86\""
"PWRISOVM.EXE"="C:\\Program Files\\PowerISO\\PWRISOVM.EXE"
"CHotkey"="mHotkey.exe"
"ojvmgm"="C:\\WINDOWS\\system32\\orruho.exe reg_run"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="\"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe\""
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"kgdni"="C:\\WINDOWS\\system32\\orruho.exe reg_run"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"Skype"="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,\
00,00,04,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,\
00,00,01,00,00,00
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{54D9498B-CF93-414F-8984-8CE7FDE0D391}"="ewido shell guard"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Aim6]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="AOLLaunch"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Common Files\\AOL\\Launch\\AOLLaunch.exe\" /d locale=en-US
ee://aol/imApp"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\HostManager]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="AOLSoftware"
"hkey"="HKLM"
"command"="C:\\Program Files\\Common Files\\AOL\\1139386937\\ee\\AOLSoftware.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run-]
"HotKeysCmds"="C:\\WINDOWS\\system32\\hkcmd.exe"
"ms041133971818"="C:\\WINDOWS\\ms041133971818.exe"
"RTHDCPL"="RTHDCPL.EXE"
"SMSERIAL"="sm56hlpr.exe"
"win32073971818113"="C:\\WINDOWS\\win32073971818113.exe"
"win32089718181133"="C:\\WINDOWS\\win32089718181133.exe"
"ztvb3ef2"="RUNDLL32.EXE w18dcfa0.dll,n 003b3eef0000000218dcfa0"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"NAV CfgWiz"="\"C:\\Program Files\\Norton AntiVirus\\CfgWiz.exe\" /GUID {0D7956A2-5A08-4ec2-A72C-DF8495A66016} /MODE CfgWiz /CMDLINE \"REBOOT\""
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime Alternative\\qttask.exe\" -atboottime"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"Alcmtr"="ALCMTR.EXE"
"IgfxTray"="C:\\WINDOWS\\system32\\igfxtray.exe"
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Norton AntiVirus - Run Full System Scan - User.job
C:\WINDOWS\tasks\Symantec NetDetect.job
Completion time: Thu 08/31/2006 22:44:23.25
ComboFix.txt
hjt log
Logfile of HijackThis v1.99.1
Scan saved at 11:07:04 PM, on 8/31/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\orruho.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\fbiyg.exe
C:\WINDOWS\system32\fbiyg.exe
C:\WINDOWS\system32\fbiyg.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2R1.EXE
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\mHotkey.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.myspace.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://www.mrfindalot.com/search.asp?si=
R3 - URLSearchHook: (no name) - _{A8B28872-3324-4CD2-8AA3-7D555C872D96} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\fbiyg.exe
F2 - REG:system.ini: UserInit=c:\windows\system32\userinit.exe,qwpdrtp.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [EOUApp] C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
O4 - HKLM\..\Run: [\\KAYLEE\EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE /P39 "\\KAYLEE\EPSON Stylus Photo R300 Series" /O6 "USB003" /M "Stylus Photo R300"
O4 - HKLM\..\Run: [Auto EPSON Stylus C86 Series on loren] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2R1.EXE /P37 "Auto EPSON Stylus C86 Series on loren" /O20 "\\LOREN\EPSONStylusC" /M "Stylus C86"
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [ojvmgm] C:\WINDOWS\system32\orruho.exe reg_run
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [kgdni] C:\WINDOWS\system32\orruho.exe reg_run
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: haevn.exe
O8 - Extra context menu item: &Google Search -
res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word -
res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links -
res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page -
res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Similar Pages -
res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English -
res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -
http://download.mcafee.com/molbin/share ... insctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupda ... 8657749394
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan ... asinst.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} -
http://download.mcafee.com/molbin/share ... cgdmgr.cab
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) -
http://www.auctiva.com/hostedimages/act ... Upload.ocx
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: OwnershipProtocol - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
its wierd, most of my rescorces 60%+ are gojng to system, and like 15% to IE and the rest are scattered with all the other processes.