Wastegate
2006-03-14, 19:06
I think I have everything else cleaned out, but for the life of me, I cannot get these registry keys gone. Any help will be appreciated.
Spybot Report
--- Search result list ---
Command Service: Settings (Registry key, fixing failed)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmdService
Command Service: Settings (Registry key, fixing failed)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cmdService
Command Service: Settings (Registry key, fixed)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\cmdService
Hijack This Report
Logfile of HijackThis v1.99.1
Scan saved at 11:57:34 AM, on 3/14/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\HJT\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=56626&homepage=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=56626&homepage=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O1 - Hosts: .elwisp.com
O1 - Hosts: www.internetpeace.com #[eTrust.Free Popup Killer]
O1 - Hosts: .elwisp.com
O1 - Hosts: .com
O1 - Hosts: 1 www.albiondrugs.com
O1 - Hosts: www.internetpeace.com #[eTrust.Free Popup Killer]
O1 - Hosts: .elwisp.com
O1 - Hosts: cgi.sexswap.com
O1 - Hosts: he.sidefind.com #[McAfee.Adware-ISTbar.dldr]
O1 - Hosts: .com
O1 - Hosts: 1 www.albiondrugs.com
O1 - Hosts: www.internetpeace.com #[eTrust.Free Popup Killer]
O1 - Hosts: .wegcash.com #[SunBelt.WegCash.com]
O1 - Hosts: .1 clickcash.webpower.com #[IE-SpyAd]
O1 - Hosts: .elwisp.com
O1 - Hosts: cgi.sexswap.com
O1 - Hosts: he.sidefind.com #[McAfee.Adware-ISTbar.dldr]
O1 - Hosts: .com
O1 - Hosts: 1 www.albiondrugs.com
O1 - Hosts: ire.online-more.com #[Dialer.Win32.PlayGames.a]
O1 - Hosts: www.internetpeace.com #[eTrust.Free Popup Killer]
O1 - Hosts: .wegcash.com #[SunBelt.WegCash.com]
O1 - Hosts: .1 clickcash.webpower.com #[IE-SpyAd]
O1 - Hosts: .elwisp.com
O1 - Hosts: cgi.sexswap.com
O1 - Hosts: he.sidefind.com #[McAfee.Adware-ISTbar.dldr]
O1 - Hosts: 127.0.0.
O1 - Hosts: .com
O1 - Hosts: 1 www.albiondrugs.com
O1 - Hosts: ire.online-more.com #[Dialer.Win32.PlayGames.a]
O1 - Hosts: www.internetpeace.com #[eTrust.Free Popup Killer]
O1 - Hosts: .wegcash.com #[SunBelt.WegCash.com]
O1 - Hosts: .1 clickcash.webpower.com #[IE-SpyAd]
O1 - Hosts: .elwisp.com
O1 - Hosts: cgi.sexswap.com
O1 - Hosts: he.sidefind.com #[McAfee.Adware-ISTbar.dldr]
O1 - Hosts: om]
O1 - Hosts: .com]
O1 - Hosts: 127.0.0.
O1 - Hosts: .com
O1 - Hosts: 1 www.albiondrugs.com
O1 - Hosts: ire.online-more.com #[Dialer.Win32.PlayGames.a]
O1 - Hosts: www.internetpeace.com #[eTrust.Free Popup Killer]
O1 - Hosts: .wegcash.com #[SunBelt.WegCash.com]
O1 - Hosts: .1 clickcash.webpower.com #[IE-SpyAd]
O1 - Hosts: .elwisp.com
O1 - Hosts: cgi.sexswap.com
O1 - Hosts: he.sidefind.com #[McAfee.Adware-ISTbar.dldr]
O1 - Hosts: 127
O1 - Hosts: m
O1 - Hosts: 127
O1 - Hosts: 0.1 www.tbcode.com #[HJTH.Win32.IstBar.hg]
O1 - Hosts: om]
O1 - Hosts: .com]
O1 - Hosts: 127.0.0.
O1 - Hosts: .com
O1 - Hosts: 1 www.albiondrugs.com
O1 - Hosts: ire.online-more.com #[Dialer.Win32.PlayGames.a]
O1 - Hosts: www.internetpeace.com #[eTrust.Free Popup Killer]
O1 - Hosts: .wegcash.com #[SunBelt.WegCash.com]
O1 - Hosts: .1 clickcash.webpower.com #[IE-SpyAd]
O1 - Hosts: .elwisp.com
O1 - Hosts: cgi.sexswap.com
O1 - Hosts: cgi.sexswap.com
O1 - Hosts: sexswap2.com
O1 - Hosts: he.sidefind.com #[McAfee.Adware-ISTbar.dldr]
O1 - Hosts: 127
O1 - Hosts: m
O1 - Hosts: 127
O1 - Hosts: 0.1 www.tbcode.com #[HJTH.Win32.IstBar.hg]
O1 - Hosts: om]
O1 - Hosts: .com]
O1 - Hosts: 127.0.0.
O1 - Hosts: .com
O1 - Hosts: 1 www.albiondrugs.com
O1 - Hosts: ire.online-more.com #[Dialer.Win32.PlayGames.a]
O1 - Hosts: www.internetpeace.com #[eTrust.Free Popup Killer]
O1 - Hosts: .wegcash.com #[SunBelt.WegCash.com]
O1 - Hosts: .1 clickcash.webpower.com #[IE-SpyAd]
O1 - Hosts: .elwisp.com
O1 - Hosts: sing.gammae.com
O1 - Hosts: om #[AVG.Dialer.JT]
O1 - Hosts: cgi.sexswap.com
O1 - Hosts: cgi.sexswap.com
O1 - Hosts: sexswap2.com
O1 - Hosts: he.sidefind.com #[McAfee.Adware-ISTbar.dldr]
O1 - Hosts: 127
O1 - Hosts: m
O1 - Hosts: 127
O1 - Hosts: 0.1 www.tbcode.com #[HJTH.Win32.IstBar.hg]
O1 - Hosts: om]
O1 - Hosts: .com]
O1 - Hosts: 127.0.0.
O1 - Hosts: .com
O1 - Hosts: 1 www.albiondrugs.com
O1 - Hosts: ire.online-more.com #[Dialer.Win32.PlayGames.a]
O1 - Hosts: www.internetpeace.com #[eTrust.Free Popup Killer]
O1 - Hosts: .wegcash.com #[SunBelt.WegCash.com]
O1 - Hosts: .1 clickcash.webpower.com #[IE-SpyAd]
O1 - Hosts: .elwisp.com
O1 - Hosts: iz #[WMF-exploit]
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Verizon Online Dialer.lnk = C:\Program Files\Common Files\Verizon Online\ConnMgr\Verizon Online.exe
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\SupportCenter\bin\matcli.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - H+BEDV Datentechnik GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Local Security Authority Subsystem Service (lsass) - Unknown owner - C:\WINDOWS\scvhost.exe (file missing)
Spybot Report
--- Search result list ---
Command Service: Settings (Registry key, fixing failed)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmdService
Command Service: Settings (Registry key, fixing failed)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cmdService
Command Service: Settings (Registry key, fixed)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\cmdService
Hijack This Report
Logfile of HijackThis v1.99.1
Scan saved at 11:57:34 AM, on 3/14/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\HJT\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=56626&homepage=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=56626&homepage=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O1 - Hosts: .elwisp.com
O1 - Hosts: www.internetpeace.com #[eTrust.Free Popup Killer]
O1 - Hosts: .elwisp.com
O1 - Hosts: .com
O1 - Hosts: 1 www.albiondrugs.com
O1 - Hosts: www.internetpeace.com #[eTrust.Free Popup Killer]
O1 - Hosts: .elwisp.com
O1 - Hosts: cgi.sexswap.com
O1 - Hosts: he.sidefind.com #[McAfee.Adware-ISTbar.dldr]
O1 - Hosts: .com
O1 - Hosts: 1 www.albiondrugs.com
O1 - Hosts: www.internetpeace.com #[eTrust.Free Popup Killer]
O1 - Hosts: .wegcash.com #[SunBelt.WegCash.com]
O1 - Hosts: .1 clickcash.webpower.com #[IE-SpyAd]
O1 - Hosts: .elwisp.com
O1 - Hosts: cgi.sexswap.com
O1 - Hosts: he.sidefind.com #[McAfee.Adware-ISTbar.dldr]
O1 - Hosts: .com
O1 - Hosts: 1 www.albiondrugs.com
O1 - Hosts: ire.online-more.com #[Dialer.Win32.PlayGames.a]
O1 - Hosts: www.internetpeace.com #[eTrust.Free Popup Killer]
O1 - Hosts: .wegcash.com #[SunBelt.WegCash.com]
O1 - Hosts: .1 clickcash.webpower.com #[IE-SpyAd]
O1 - Hosts: .elwisp.com
O1 - Hosts: cgi.sexswap.com
O1 - Hosts: he.sidefind.com #[McAfee.Adware-ISTbar.dldr]
O1 - Hosts: 127.0.0.
O1 - Hosts: .com
O1 - Hosts: 1 www.albiondrugs.com
O1 - Hosts: ire.online-more.com #[Dialer.Win32.PlayGames.a]
O1 - Hosts: www.internetpeace.com #[eTrust.Free Popup Killer]
O1 - Hosts: .wegcash.com #[SunBelt.WegCash.com]
O1 - Hosts: .1 clickcash.webpower.com #[IE-SpyAd]
O1 - Hosts: .elwisp.com
O1 - Hosts: cgi.sexswap.com
O1 - Hosts: he.sidefind.com #[McAfee.Adware-ISTbar.dldr]
O1 - Hosts: om]
O1 - Hosts: .com]
O1 - Hosts: 127.0.0.
O1 - Hosts: .com
O1 - Hosts: 1 www.albiondrugs.com
O1 - Hosts: ire.online-more.com #[Dialer.Win32.PlayGames.a]
O1 - Hosts: www.internetpeace.com #[eTrust.Free Popup Killer]
O1 - Hosts: .wegcash.com #[SunBelt.WegCash.com]
O1 - Hosts: .1 clickcash.webpower.com #[IE-SpyAd]
O1 - Hosts: .elwisp.com
O1 - Hosts: cgi.sexswap.com
O1 - Hosts: he.sidefind.com #[McAfee.Adware-ISTbar.dldr]
O1 - Hosts: 127
O1 - Hosts: m
O1 - Hosts: 127
O1 - Hosts: 0.1 www.tbcode.com #[HJTH.Win32.IstBar.hg]
O1 - Hosts: om]
O1 - Hosts: .com]
O1 - Hosts: 127.0.0.
O1 - Hosts: .com
O1 - Hosts: 1 www.albiondrugs.com
O1 - Hosts: ire.online-more.com #[Dialer.Win32.PlayGames.a]
O1 - Hosts: www.internetpeace.com #[eTrust.Free Popup Killer]
O1 - Hosts: .wegcash.com #[SunBelt.WegCash.com]
O1 - Hosts: .1 clickcash.webpower.com #[IE-SpyAd]
O1 - Hosts: .elwisp.com
O1 - Hosts: cgi.sexswap.com
O1 - Hosts: cgi.sexswap.com
O1 - Hosts: sexswap2.com
O1 - Hosts: he.sidefind.com #[McAfee.Adware-ISTbar.dldr]
O1 - Hosts: 127
O1 - Hosts: m
O1 - Hosts: 127
O1 - Hosts: 0.1 www.tbcode.com #[HJTH.Win32.IstBar.hg]
O1 - Hosts: om]
O1 - Hosts: .com]
O1 - Hosts: 127.0.0.
O1 - Hosts: .com
O1 - Hosts: 1 www.albiondrugs.com
O1 - Hosts: ire.online-more.com #[Dialer.Win32.PlayGames.a]
O1 - Hosts: www.internetpeace.com #[eTrust.Free Popup Killer]
O1 - Hosts: .wegcash.com #[SunBelt.WegCash.com]
O1 - Hosts: .1 clickcash.webpower.com #[IE-SpyAd]
O1 - Hosts: .elwisp.com
O1 - Hosts: sing.gammae.com
O1 - Hosts: om #[AVG.Dialer.JT]
O1 - Hosts: cgi.sexswap.com
O1 - Hosts: cgi.sexswap.com
O1 - Hosts: sexswap2.com
O1 - Hosts: he.sidefind.com #[McAfee.Adware-ISTbar.dldr]
O1 - Hosts: 127
O1 - Hosts: m
O1 - Hosts: 127
O1 - Hosts: 0.1 www.tbcode.com #[HJTH.Win32.IstBar.hg]
O1 - Hosts: om]
O1 - Hosts: .com]
O1 - Hosts: 127.0.0.
O1 - Hosts: .com
O1 - Hosts: 1 www.albiondrugs.com
O1 - Hosts: ire.online-more.com #[Dialer.Win32.PlayGames.a]
O1 - Hosts: www.internetpeace.com #[eTrust.Free Popup Killer]
O1 - Hosts: .wegcash.com #[SunBelt.WegCash.com]
O1 - Hosts: .1 clickcash.webpower.com #[IE-SpyAd]
O1 - Hosts: .elwisp.com
O1 - Hosts: iz #[WMF-exploit]
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Verizon Online Dialer.lnk = C:\Program Files\Common Files\Verizon Online\ConnMgr\Verizon Online.exe
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\SupportCenter\bin\matcli.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - H+BEDV Datentechnik GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Local Security Authority Subsystem Service (lsass) - Unknown owner - C:\WINDOWS\scvhost.exe (file missing)