I have performed the mcafee removal successfully. However, note that I could not go to the site (I had to go through mcafee support to get the mcpr.exe file)...could be virus related, not sure. When i got the file, i could not run it. I had to rename it to something abstract before it would run, but with that it worked.
When I shutdown, i get a viewmgr error. And when i start mozilla, it always asks if i want it to be the default internet browser....so it is reverting back to IE. also, randomly, i get an audible error tone and other random things.
I ran the bitdefender and new hijack this..i will now proceed with the ccleaner and malewarebytes, but here were the logs before i do those:
BitDefender QuickScan Beta 32-bit v0.9.9.0
------------------------------------------
Scan date: Tue Feb 09 17:54:06 2010
Machine ID: 7D97E0CC
Process svchost.exe (900) is affected by Gen:Trojan.Heur.TP.bu4@b4Cv1Ie
Found 1 infected file!
------------------------
C:\WINDOWS\system32\_VOIDlirfuyuedb.dll - Gen:Trojan.Heur.TP.bu4@b4Cv1Ie
Processes
---------
<unsigned> QuickTime 1324 C:\Program Files\QuickTime\QTTask.exe
<verified> CommandService Application 1856 C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe
<verified> Firefox 3080 C:\Program Files\Mozilla Firefox\firefox.exe
<verified> Intel(R) Common User Interface 1932 C:\WINDOWS\system32\hkcmd.exe
<verified> Intel(R) Common User Interface 1152 C:\WINDOWS\system32\igfxtray.exe
<verified> Intuit Update Service 1692 C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
<verified> Java(TM) Platform SE 6 U17 1792 C:\Program Files\Java\jre6\bin\jqs.exe
<verified> Java(TM) Platform SE 6 U17 1228 C:\Program Files\Java\jre6\bin\jusched.exe
<verified> LightScribe 1896 C:\Program Files\Common Files\LightScribe\LSSrvc.exe
<verified> MarkVision for Windows (32 bit) 1472 C:\WINDOWS\system32\LEXBCES.EXE
<verified> MarkVision for Windows (32 bit) 1504 C:\WINDOWS\system32\LEXPPS.EXE
<verified> Microsoft® Windows® Operating System 3992 C:\Program Files\Internet Explorer\iexplore.exe
<verified> Microsoft® Windows® Operating System 1808 C:\WINDOWS\Explorer.EXE
<verified> Microsoft® Windows® Operating System 2288 C:\WINDOWS\System32\alg.exe
<verified> Microsoft® Windows® Operating System 676 C:\WINDOWS\system32\csrss.exe
<verified> Microsoft® Windows® Operating System 1312 C:\WINDOWS\system32\ctfmon.exe
<verified> Microsoft® Windows® Operating System 756 C:\WINDOWS\system32\lsass.exe
<verified> Microsoft® Windows® Operating System 744 C:\WINDOWS\system32\services.exe
<verified> Microsoft® Windows® Operating System 608 C:\WINDOWS\System32\smss.exe
<verified> Microsoft® Windows® Operating System 1488 C:\WINDOWS\system32\spoolsv.exe
<verified> Microsoft® Windows® Operating System 120 C:\WINDOWS\system32\svchost.exe
<verified> Microsoft® Windows® Operating System 900 C:\WINDOWS\system32\svchost.exe
<verified> Microsoft® Windows® Operating System 992 C:\WINDOWS\system32\svchost.exe
<verified> Microsoft® Windows® Operating System 1028 C:\WINDOWS\System32\svchost.exe
<verified> Microsoft® Windows® Operating System 1072 C:\WINDOWS\system32\svchost.exe
<verified> Microsoft® Windows® Operating System 1156 C:\WINDOWS\system32\svchost.exe
<verified> Microsoft® Windows® Operating System 700 C:\WINDOWS\system32\winlogon.exe
<verified> Microsoft® Windows® Operating System 1404 C:\WINDOWS\system32\wuauclt.exe
<verified> Synaptics Pointing Device Driver 848 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
<verified> Synaptics Pointing Device Driver 1408 C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
Network activity
----------------
Process firefox.exe (3080) connected on port 80 (HTTP) - 173.194.8.100
Process firefox.exe (3080) connected on port 80 (HTTP) - 209.85.225.105
Process firefox.exe (3080) connected on port 80 (HTTP) - 96.17.197.115
Process firefox.exe (3080) connected on port 80 (HTTP) - 74.125.95.101
Process firefox.exe (3080) connected on port 80 (HTTP) - 209.85.225.105
Process firefox.exe (3080) connected on port 80 (HTTP) - 209.85.225.104
Process firefox.exe (3080) connected on port 80 (HTTP) - 209.85.225.138
Process firefox.exe (3080) connected on port 80 (HTTP) - 66.235.143.54
Process firefox.exe (3080) connected on port 80 (HTTP) - 96.17.204.20
Process iexplore.exe (3992) connected on port 80 (HTTP) - 209.212.147.208
Process svchost.exe (992) listens on ports: 135 (RPC)
Process LEXPPS.EXE (1504) listens on ports: 1025 (RPC)
Autoruns and critical files
---------------------------
<unsigned> cpqset.exe C:\Program Files\HPQ\Default Settings\cpqset.exe
<unsigned> QuickTime C:\Program Files\QuickTime\QTTask.exe
<verified> Apple Software Update C:\Program Files\Apple Software Update\SoftwareUpdate.exe
<verified> Google Update C:\Program Files\Google\Update\GoogleUpdate.exe
<verified> ImScInst.exe C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe
<verified> Intel(R) Common User Interface C:\WINDOWS\system32\hkcmd.exe
<verified> Intel(R) Common User Interface C:\WINDOWS\system32\igfxsrvc.dll
<verified> Intel(R) Common User Interface C:\WINDOWS\system32\igfxtray.exe
<verified> Java(TM) Platform SE 6 U17 C:\Program Files\Java\jre6\bin\jusched.exe
<verified> Microsoft IME 2002 C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE
<verified> Microsoft Korean IME 2002 C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
<verified> Microsoft(R) Windows(R) Operating System C:\WINDOWS\system32\hplampc.exe
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\browseui.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\crypt32.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\cryptnet.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\cscdll.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\ctfmon.exe
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\dimsntfy.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\logonui.exe
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\rundll32.exe
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\sclgntfy.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\shell32.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\stobject.dll
<verified> Microsoft® Windows® Operating System c:\windows\system32\userinit.exe
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\webcheck.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\wlnotify.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\WPDShServiceObj.dll
<verified> Synaptics Pointing Device Driver C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
<verified> Synaptics Pointing Device Driver C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
<verified> Windows Genuine Advantage C:\WINDOWS\system32\WgaLogon.dll
<verified> 新注音 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE
Browser plugins
---------------
<unsigned> Google Earth Plugin C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
<unsigned> IE Tab Plug-in C:\Documents and Settings\Jason Coryell\Application Data\Mozilla\Firefox\Profiles/74w51qij.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}\plugins\npietab.dll
<unsigned> Java(TM) Platform SE 6 U17 c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
<unsigned> McAfee Virtual Technician C:\WINDOWS\Downloaded Program Files\Uploader.exe
<unsigned> QuickTime Plug-in 7.6.4 C:\Program Files\Internet Explorer\plugins\npqtplugin.dll
<unsigned> QuickTime Plug-in 7.6.4 C:\Program Files\Internet Explorer\plugins\npqtplugin2.dll
<unsigned> QuickTime Plug-in 7.6.4 C:\Program Files\Internet Explorer\plugins\npqtplugin3.dll
<unsigned> QuickTime Plug-in 7.6.4 C:\Program Files\Internet Explorer\plugins\npqtplugin4.dll
<unsigned> QuickTime Plug-in 7.6.4 C:\Program Files\Internet Explorer\plugins\npqtplugin5.dll
<unsigned> QuickTime Plug-in 7.6.4 C:\Program Files\Internet Explorer\plugins\npqtplugin6.dll
<unsigned> QuickTime Plug-in 7.6.4 C:\Program Files\Internet Explorer\plugins\npqtplugin7.dll
<unsigned> QuickTime Plug-in 7.6.4 C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
<unsigned> QuickTime Plug-in 7.6.4 C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
<unsigned> QuickTime Plug-in 7.6.4 C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
<unsigned> QuickTime Plug-in 7.6.4 C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
<unsigned> QuickTime Plug-in 7.6.4 C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
<unsigned> QuickTime Plug-in 7.6.4 C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
<unsigned> QuickTime Plug-in 7.6.4 C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
<unsigned> RealJukebox NS Plugin C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
<unsigned> RealJukebox NS Plugin C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll
<unsigned> RealPlayer Version Plugin C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
<unsigned> RealPlayer Version Plugin C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll
<unsigned> Turner Media Plugin 1.0.0.7 C:\Program Files\Mozilla Firefox\plugins\NPTURNMED.dll
<verified> AcroIEHelper Library c:\program files\adobe\acrobat 7.0\activex\acroiehelper.dll
<verified> ActiveTouch General Plugin Container C:\Program Files\Mozilla Firefox\plugins\npatgpc.dll
<verified> Adobe Acrobat C:\Program Files\Internet Explorer\plugins\nppdf32.dll
<verified> Adobe Acrobat C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll
<verified> AOL Instant Messenger C:\Program Files\AIM\aim.exe
<verified> atcliun C:\Program Files\Mozilla Firefox\plugins\atcliun.exe
<verified> AtMcCli Module C:\Program Files\Mozilla Firefox\plugins\atmccli.dll
<verified> AtMgr Module C:\Program Files\Mozilla Firefox\plugins\atmgr.exe
<verified> BitDefender QuickScan C:\Documents and Settings\Jason Coryell\Application Data\Mozilla\Firefox\Profiles/74w51qij.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\bdqscan.dll
<verified> BitDefender QuickScan C:\Documents and Settings\Jason Coryell\Application Data\Mozilla\Firefox\Profiles/74w51qij.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
<verified> Bonjour C:\Program Files\Bonjour\mdnsNSP.dll
<verified> Domino Web Access C:\WINDOWS\Downloaded Program Files\inotes6W.dll
<verified> Google Update C:\Program Files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
<verified> InstallShield Update Service C:\WINDOWS\Downloaded Program Files\dwusplay.dll
<verified> InstallShield Update Service C:\WINDOWS\Downloaded Program Files\dwusplay.exe
<verified> InstallShield Update Service C:\WINDOWS\Downloaded Program Files\isusweb.dll
<verified> Internet Pictures Corp. iPIX Plugin v6.2 C:\Program Files\Mozilla Firefox\plugins\AppSub32.dll
<verified> Internet Pictures Corp. iPIX Plugin v6.2 C:\Program Files\Mozilla Firefox\plugins\NpIpx32.dll
<verified> Java Deployment Toolkit 6.0.170.4 C:\Program Files\Mozilla Firefox\plugins\npdeploytk.dll
<verified> Java(TM) Platform SE 6 U17 C:\Program Files\Java\jre6\bin\jp2ssv.dll
<verified> McAfee Clinic C:\Program Files\Mozilla Firefox\plugins\NPMGWRAP.DLL
<verified> McAfee Virtual Technician C:\WINDOWS\Downloaded Program Files\McContentMgr.dll
<verified> McAfee Virtual Technician C:\WINDOWS\Downloaded Program Files\McHealthCheck.dll
<verified> McAfee Virtual Technician C:\WINDOWS\Downloaded Program Files\McLogMgr.dll
<verified> McAfee Virtual Technician C:\WINDOWS\Downloaded Program Files\McPlugins.dll
<verified> McAfee Virtual Technician C:\WINDOWS\Downloaded Program Files\McProdMgr.dll
<verified> McAfee Virtual Technician C:\WINDOWS\Downloaded Program Files\MVT.dll
<verified> Messenger C:\Program Files\Messenger\msmsgs.exe
<verified> Microsoft® Windows® Operating System C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\mswsock.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\rsvpsp.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\shdocvw.dll
<verified> Microsoft® Windows® Operating System C:\WINDOWS\system32\winrnr.dll
<verified> Move Streaming Media Player C:\Documents and Settings\Jason Coryell\Application Data\Move Networks\plugins\npqmp071701000002.dll
<verified> Mozilla ActiveX control and plugin support C:\Program Files\Mozilla Firefox\plugins\npmozax.dll
<verified> Mozilla Default Plug-in C:\Program Files\Mozilla Firefox\plugins\npnul32.dll
<verified> npitunes.dll C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
<verified> NPSWF32.dll C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
<verified> PokerStars C:\Program Files\PokerStars\PokerStarsUpdate.exe
<verified> RealNetworks Rhapsody Player Engine C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll
<verified> RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32- C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
<verified> RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32- C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll
<verified> Snapfish Plugin for Firefox C:\Program Files\Mozilla Firefox\plugins\npsnapfish.dll
<verified> ViewBarBHO Module c:\program files\viewpoint\viewpoint toolbar\3.8.0\viewbarbho.dll
<verified> WebEx Download Module C:\Program Files\Mozilla Firefox\plugins\atgpcdec.dll
<verified> WebEx Download Module C:\Program Files\Mozilla Firefox\plugins\atgpcext.dll
<verified> WebEx Download Module C:\Program Files\Mozilla Firefox\plugins\ieatgpc.dll
<verified> Windows Presentation Foundation c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
<verified> Yahoo Application State Plugin C:\Program Files\Yahoo!\Shared\npYState.dll
Missing files
-------------
File not found: C:\Program Files\McAfee\Supportability\MVT\NPMVTPlugin.dll
referenced in: HLKM\Software\MozillaPlugins\@mcafee.com/MVT\"Path"
File not found: C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
referenced in: HLKM\Software\MozillaPlugins\@viewpoint.com/VMP\"Path"
File not found: C:\WINDOWS\System32\appmgmts.dll
referenced in: HKLM\System\CurrentControlSet\Services\AppMgmt\Parameters\"ServiceDll"
File not found: C:\WINDOWS\System32\hidserv.dll
referenced in: HKLM\System\CurrentControlSet\Services\HidServ\Parameters\"ServiceDll"
File not found: c:\windows\system32\papororo.dll
referenced in: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\"AppInit_DLLs"
File not found: fubatuzo.dll
referenced in: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\"AppInit_DLLs"
File not found: system32\DRIVERS\rasirda.sys
referenced in: HKLM\System\CurrentControlSet\Services\Rasirda\"ImagePath"
Scan
----
No file uploaded.
Scan finished - communication took 2 sec
Total traffic - 0.01 MB sent, 0.38 KB recvd
Scanned 673 files and modules - 40 seconds
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:55:59 PM, on 2/9/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Jason Coryell\Desktop\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://search.yahoo.com/search?fr=mcafee&p=%sR1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
https://register.hp.com/servlet/WebReg.servlets.ProdReg1Servlet?appID=java_wreg_wreg_genpg&modelID=EC144UA&product_full_name=HP%20Pavilion%20dv1000&PROD_SERIAL_ID=CNF52838HL&PURCH_DT_MONTH=08&PURCH_DT_DAY=23&PURCH_DT_YEAR=2005&gwCountry=US&language=EN&prodOS=011R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\3.8.0\ViewBarBHO.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [hplampc] C:\WINDOWS\system32\hplampc.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [ddexpshare.exe] C:\WINDOWS\TEMP\ddexpshare.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ddexpshare.exe] C:\WINDOWS\TEMP\ddexpshare.exe (User 'Default user')
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mcafee.com
O15 - Trusted Zone: http://*.buy-internetsecurity10.com (HKLM)
O15 - Trusted Zone: http://*.buy-is2010.com (HKLM)
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) -
http://www.ipix.com/viewers/ipixx.cabO16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabO16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) -
http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5886/mcfscan.cabO20 - AppInit_DLLs: c:\windows\system32\papororo.dll fubatuzo.dll
O21 - SSODL: zunagisuj - {996b2dcd-5337-4d9b-abad-779b9cab57ad} - (no file)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LeapFrog Connect Device Service - LeapFrog Enterprises, Inc. - C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 6688 bytes