Here is the ComboFix Log:
ComboFix 08-11-23.02 - Cygnus X-1 2008-11-24 20:06:34.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1602 [GMT -8:00]
Running from: c:\documents and settings\Cygnus X-1\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\system32\bgyjyaog.dll
c:\windows\system32\hgGAQhFx.dll
c:\windows\system32\istjqfha.ini
c:\windows\system32\jnesutmb.ini
c:\windows\system32\jrmxxu.dll
c:\windows\system32\mcrh.tmp
c:\windows\system32\MnXEKRqr.ini
c:\windows\system32\MnXEKRqr.ini2
c:\windows\system32\uigmntvr.dll
c:\windows\system32\vaokyajd.ini
c:\windows\system32\wawmfn.dll
c:\windows\Tasks\hnsojmiu.job
c:\windows\Temp\tmp3.tmp
E:\Autorun.inf
----- BITS: Possible infected sites -----
hxxp://childhe.com
.
((((((((((((((((((((((((( Files Created from 2008-10-25 to 2008-11-25 )))))))))))))))))))))))))))))))
.
2008-11-23 12:32 . 2008-11-23 12:32 <DIR> d--h----- C:\$AVG8.VAULT$
2008-11-23 12:16 . 2008-11-23 12:40 <DIR> d-------- c:\windows\system32\drivers\Avg
2008-11-23 12:16 . 2008-11-23 12:16 <DIR> d-------- c:\program files\AVG
2008-11-23 12:16 . 2008-11-23 23:06 <DIR> d-------- c:\documents and settings\Cygnus X-1\Application Data\AVGTOOLBAR
2008-11-23 12:16 . 2008-11-23 12:16 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\avg8
2008-11-23 12:16 . 2008-11-23 12:16 97,928 --a------ c:\windows\system32\drivers\avgldx86.sys
2008-11-23 12:16 . 2008-11-23 12:16 76,040 --a------ c:\windows\system32\drivers\avgtdix.sys
2008-11-23 12:16 . 2008-11-23 12:16 10,520 --a------ c:\windows\system32\avgrsstx.dll
2008-11-23 11:39 . 2008-11-23 11:39 72,704 --a------ c:\windows\system32\djaykoav.dll
2008-11-19 20:19 . 2008-11-19 20:19 129,024 --a------ c:\windows\system32\jqlosgjl.dll
2008-11-19 20:19 . 2008-11-19 20:19 129,024 --a------ c:\windows\system32\bbgilx.dll
2008-11-18 20:19 . 2008-11-18 20:19 124,928 --a------ c:\windows\system32\xpujrgrg.dll
2008-11-18 20:19 . 2008-11-18 20:19 124,928 --a------ c:\windows\system32\cmzzfla.dll
2008-11-13 17:38 . 2008-11-13 17:38 124,928 --a------ c:\windows\system32\gldzmr.dll
2008-11-13 05:25 . 2008-11-13 05:25 15,083,520 --a------ C:\spybotsd160.exe
2008-11-13 00:30 . 2008-11-13 00:30 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\Blizzard
2008-11-02 16:35 . 2008-11-02 16:35 98,304 --a------ c:\windows\system32\CmdLineExt.dll
2008-11-02 16:29 . 2008-11-02 16:29 <DIR> d-------- c:\program files\GameSpy Arcade
2008-11-02 16:29 . 2008-11-02 16:29 <DIR> d-------- c:\documents and settings\Cygnus X-1\Application Data\Leadertech
2008-10-30 22:26 . 2008-10-30 22:26 4,096 --a------ c:\windows\d3dx.dat
2008-10-30 22:23 . 2008-10-30 22:23 <DIR> d-------- C:\Dynamix
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-14 01:37 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2008-11-13 13:41 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-11-13 08:56 --------- d-----w c:\program files\Common Files\Blizzard Entertainment
2008-11-03 00:16 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-31 06:35 21,840 ----atw c:\windows\system32\SIntfNT.dll
2008-10-31 06:35 17,212 ----atw c:\windows\system32\SIntf32.dll
2008-10-31 06:35 12,067 ----atw c:\windows\system32\SIntf16.dll
2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-23 01:50 17,801 ----a-w c:\windows\system32\drivers\AegisP.sys
2008-10-23 01:50 --------- d-----w c:\program files\Linksys Wireless-G PCI Network Adapter with SpeedBooster
2008-10-16 15:06 --------- d-----w c:\documents and settings\Cygnus X-1\Application Data\Move Networks
2008-10-16 14:19 --------- d-----w c:\program files\World of Warcraft
2008-10-08 06:05 --------- d-----w c:\program files\Microsoft Games
2008-10-08 03:41 --------- d-----w c:\documents and settings\Cygnus X-1\Application Data\TransRender
2008-10-01 00:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-15 11:57 1,846,016 ----a-w c:\windows\system32\win32k.sys
2008-09-04 16:42 1,106,944 ----a-w c:\windows\system32\msxml3.dll
2008-03-28 03:33 867,785 ----a-w c:\program files\zsnesw151.zip
2008-03-21 16:53 5,037,072 ----a-w c:\program files\spybotsd14.exe
2008-03-21 16:46 45,942,912 ----a-w c:\program files\169.21_forceware_winxp_32bit_english_whql.exe
2008-03-15 06:38 3,258,750 ----a-w c:\program files\reaper214159-install.exe
2008-02-23 01:02 141,909,560 ----a-w c:\documents and settings\Cygnus X-1\WoW-2.3.3.7799-to-0.4.0.7897-enUS-patch.exe
2007-11-02 21:26 220,008,707 ----a-w c:\documents and settings\Cygnus X-1\WoW-2.2.3.7359-to-0.3.0.7441-enUS-patch.exe
2007-08-10 06:07 16,525 ----a-w c:\documents and settings\Interface\rdm-real-dps-meter-1-2.zip
2007-06-11 05:21 46,647 ----a-w c:\documents and settings\Interface\opium-opium-2-7b.zip
2007-06-07 02:01 449,762 ----a-w c:\documents and settings\Interface\IceHUD-r19702.zip
2007-05-17 03:54 3,098 ----a-w c:\documents and settings\Interface\easylanguage-tweaked-easylanguage-1-4.zip
2007-05-03 21:58 13,850 ----a-w c:\documents and settings\Interface\buffwatch-2-0beta5.zip
2007-05-01 00:47 4,029,225 ----a-w c:\documents and settings\Interface\atlas-1-8-6.zip
2007-05-01 00:40 510,849 ----a-w c:\documents and settings\Interface\atlasloot-enhanced-v2-03-04.zip
2007-04-25 10:07 132,431 ----a-w c:\documents and settings\Interface\chatmod-revision-103.zip
2007-04-25 03:36 129,196 ----a-w c:\documents and settings\Interface\damagemeters-5-6-0.zip
2007-04-25 02:47 7,776 ----a-w c:\documents and settings\Interface\es-guildcheck-es-guildcheck-1-53.zip
2007-04-25 02:25 13,595 ----a-w c:\documents and settings\Interface\bigguild-bigguild.zip
2007-04-25 01:36 272,156 ----a-w c:\documents and settings\Interface\vanaskos-3-00-beta5.zip
2007-04-25 01:35 10,488 ----a-w c:\documents and settings\Interface\pvpshuffle-r5.zip
2007-04-17 04:52 1,069 ----a-w c:\documents and settings\Interface\ImprovedCamera-v2.0.1_20070131.zip
2007-04-16 06:04 959,546 ----a-w c:\documents and settings\Interface\natur-enemycastbar-7-2-4.zip
2007-04-16 06:03 22,475 ----a-w c:\documents and settings\Interface\carnival-pvppve-enemy-cast-bar-1-6-final-beta.zip
2007-04-16 05:13 27,689 ----a-w c:\documents and settings\Interface\buffoptions-2-0-0-1.zip
2007-04-16 05:02 1,222 ----a-w c:\documents and settings\Interface\hidebuffs-hidebuffs-1-0-0.zip
2007-04-14 00:39 143,189 ----a-w c:\documents and settings\Interface\ecastingbar-for-wow-2-0-ecastingbar-2-00-07.zip
2007-04-14 00:38 301,230 ----a-w c:\documents and settings\Interface\drathals-hud-1-4-20003.zip
2007-04-08 03:05 84,265 ----a-w c:\documents and settings\Interface\bongos-7-1-15.zip
2007-04-07 19:29 435,810 ----a-w c:\documents and settings\Interface\x-perl-unitframes-2-2-0a.zip
2007-04-07 19:26 938 ----a-w c:\documents and settings\Interface\simplehealthfade-1-0.zip
2007-04-07 19:24 6,152 ----a-w c:\documents and settings\Interface\simple-party-frame-1-2a.zip
2007-04-07 19:23 2,897 ----a-w c:\documents and settings\Interface\showguild-20003-2.zip
2007-04-07 10:59 2,737 ----a-w c:\documents and settings\Interface\ctplayerframe-1-0.zip
2007-04-07 10:51 66,775 ----a-w c:\documents and settings\Interface\moveframes-moveframes-1-0-61.zip
2007-04-07 10:27 488,273 ----a-w c:\documents and settings\Interface\archaeologist-3-7.zip
2007-04-07 10:25 8,893 ----a-w c:\documents and settings\Interface\focusframe-1-2.zip
2007-04-07 10:18 140,128 ----a-w c:\documents and settings\Interface\class-viewer-2-0-3-1-0.zip
2007-04-07 07:09 6,163 ----a-w c:\documents and settings\Interface\omni-cooldown-count-7-1-13.zip
2007-04-07 07:04 16,631 ----a-w c:\documents and settings\Interface\cooldowncount-10900.zip
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Creative Detector"="c:\program files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 102400]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTDVDDET"="c:\program files\Creative\SBAudigy4\DVDAudio\CTDVDDET.EXE" [2003-06-17 45056]
"CTSysVol"="c:\program files\Creative\SBAudigy4\Surround Mixer\CTSysVol.exe" [2005-02-15 57344]
"AudioDrvEmulator"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-06-16 49152]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-10 90112]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-01-31 385024]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-02-04 267048]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-02 13529088]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-02 86016]
"WD Drive Manager"="c:\program files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe" [2008-01-30 438272]
"084532da"="c:\windows\system32\djaykoav.dll" [2008-11-23 72704]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-11-23 1234712]
"CTHelper"="CTHELPER.EXE" [2005-06-17 c:\windows\CTHELPER.EXE]
"nwiz"="nwiz.exe" [2008-05-02 c:\windows\system32\nwiz.exe]
c:\documents and settings\Cygnus X-1\Start Menu\Programs\Startup\
WD Anywhere Backup Launcher.lnk - c:\documents and settings\Cygnus X-1\Application Data\Microsoft\Installer\{B9A81070-616D-4E93-BE02-CEE651343204}\NewShortcut4_3A95A0BFA90C41A28DFACEDE7630C4FB.exe [2008-06-03 17542]
c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Loadout Manager.lnk - c:\program files\Belkin\Nostromo\nost_LM.exe [2003-06-23 442368]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.iv41"= ir41_32.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-1.12.0.5595-to-1.12.1.5875-enUS-downloader.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-1.12.x-to-2.0.1-enUS-patch-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.3-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.5.6320-to-2.0.6.6337-enUS-downloader.exe"=
"c:\\temp\\MultiTES4Server_0.2.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.12.6546-to-2.1.0.6692-enUS-downloader.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"e:\\Diablo II\\Game.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\Irrational Games\\Freedom Force\\fforce.exe"=
"c:\\Dynamix\\Tribes2\\GameData\\Tribes2.exe"=
"e:\\Neverwinter Nights\\NWN\\nwmain.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader
"6881:TCP"= 6881:TCP:Blizzard Downloader: 6881
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-11-23 97928]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-11-23 875288]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-11-23 231704]
R2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-11-23 76040]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\Viewpoint\Common\ViewpointService.exe" [2007-11-06 24652]
R2 WDBtnMgrSvc.exe;WD Drive Manager Service;"c:\program files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe" [2008-01-30 106496]
S3 bcgame;Nostromo HID Device Minidriver;c:\windows\system32\drivers\bcgame.sys [2003-07-23 22821]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);c:\windows\system32\DRIVERS\ss_bus.sys [2007-07-13 58320]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;c:\windows\system32\DRIVERS\ss_mdfl.sys [2007-07-13 8304]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;c:\windows\system32\DRIVERS\ss_mdm.sys [2007-07-13 94000]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1075e218-75c7-11dc-ab0b-00161743c9ec}]
\Shell\AutoRun\command - E:\setupSNK.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{15d8d840-76ec-11dd-ac3f-00161743c9ec}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{50467f15-0997-11dc-aac6-00161743c9ec}]
\Shell\AutoRun\command - e:\jdsecure\Windows\JDSecure31.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8004b74a-e5b5-11dc-ab7a-00161743c9ec}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
*Newly Created Service* - GTNDIS5
.
Contents of the 'Scheduled Tasks' folder
2008-08-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 13:57]
.
- - - - ORPHANS REMOVED - - - -
BHO-{04D45E68-82AB-4186-B792-26292C8BB0F6} - (no file)
BHO-{5E599AFA-6A55-40E1-B29F-688EDF3ED85A} - (no file)
BHO-{6BD938DC-6BB9-43F3-9DB4-73968D70677C} - (no file)
BHO-{7F8FBE43-DE14-46CE-9601-44A4EE2A7A54} - c:\windows\system32\hgGAQhFx.dll
BHO-{879268BA-A14D-43EB-A23D-FB2777AB1003} - (no file)
BHO-{8A5B6A4C-B5BD-4085-9030-428C0BA22B15} - c:\windows\system32\rqRKEXnM.dll
BHO-{b676b863-0982-4af3-ae73-95103d5e9600} - c:\windows\system32\jrmxxu.dll
BHO-{C65E9188-47A5-4477-B8A8-E9AC777839EC} - (no file)
HKCU-Run-SearchAndDestroyMFC - c:\program files\Search And Destroy\Search And Destroy.exe
HKCU-Run-Aim6 - (no file)
HKLM-Run-Adobe Photo Downloader - c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
ShellExecuteHooks-{7F8FBE43-DE14-46CE-9601-44A4EE2A7A54} - c:\windows\system32\hgGAQhFx.dll
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\Cygnus X-1\Application Data\Mozilla\Firefox\Profiles\yp94zojy.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-24 20:09:19
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1048)
c:\windows\system32\rsaenh.dll
c:\windows\system32\WgaLogon.dll
- - - - - - - > 'lsass.exe'(1104)
c:\windows\system32\msprivs.dll
c:\windows\system32\rsaenh.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\system32\CTSVCCDA.EXE
c:\windows\system32\nvsvc32.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WLService.exe
c:\program files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WMP54GSv1_1.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-11-24 20:11:48 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-25 04:11:45
Pre-Run: 880,320,512 bytes free
Post-Run: 1,577,992,192 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
250 --- E O F --- 2008-11-12 08:42:14
And here is the latest Hijack This Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:25:37 PM, on 11/24/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WLService.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WMP54GSv1_1.exe
C:\Documents and Settings\Cygnus X-1\Desktop\HiJackThis\caleb1234.exe.exe
C:\WINDOWS\system32\wuauclt.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\SBAudigy4\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy4\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WD Drive Manager] C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
O4 - HKLM\..\Run: [084532da] rundll32.exe "C:\WINDOWS\system32\djaykoav.dll",b
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WD Drive Manager Service (WDBtnMgrSvc.exe) - WDC - C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
O23 - Service: WMP54GSSVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Network Adapter with SpeedBooster\WLService.exe
--
End of file - 6003 bytes