It worked....
First of all ... thank you very much for your help.
Here's the logs:
xeHelper by Raktor - 09
Build 20090925
Run at 13:27:12 on 10/07/09
Now searching...
Checking for numerical processes...
Checking for bad processes...
Checking for bad files...
Deleting file C:\WINDOWS\system32\logon.exe
Checking for bad registry entries...
Resetting filetype association for .exe
Resetting filetype association for .com
Resetting userinit and shell values...
Resetting policies...
--Finished--
ComboFix 09-10-06.04 - Computer User 10/07/2009 13:36.1.2 - NTFSx86
Running from: c:\documents and settings\Computer User\Desktop\PepperCasks.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\COMPUT~1\LOCALS~1\Temp\HCBackup\hcpackage.exe
c:\docume~1\COMPUT~1\LOCALS~1\Temp\HouseCall\bspatch.exe
c:\docume~1\COMPUT~1\LOCALS~1\Temp\HouseCall\bzip2.exe
c:\docume~1\COMPUT~1\LOCALS~1\Temp\HouseCall\hc_core.dll
c:\docume~1\COMPUT~1\LOCALS~1\Temp\HouseCall\ICRCHdler.dll
c:\docume~1\COMPUT~1\LOCALS~1\Temp\HouseCall\libcurl.dll
c:\docume~1\COMPUT~1\LOCALS~1\Temp\HouseCall\libeay32.dll
c:\docume~1\COMPUT~1\LOCALS~1\Temp\HouseCall\libexpatw.dll
c:\docume~1\COMPUT~1\LOCALS~1\Temp\HouseCall\perfiCrcPerfMonMgr.dll
c:\docume~1\COMPUT~1\LOCALS~1\Temp\HouseCall\ssleay32.dll
c:\docume~1\COMPUT~1\LOCALS~1\Temp\HouseCall\tmcomm.sys
c:\docume~1\COMPUT~1\LOCALS~1\Temp\HouseCall\TmEngDrv.dll
c:\docume~1\COMPUT~1\LOCALS~1\Temp\HouseCall\tmfbeng.dll
c:\docume~1\COMPUT~1\LOCALS~1\Temp\HouseCall\TSC.exe
c:\docume~1\COMPUT~1\LOCALS~1\Temp\HouseCall\vsapi32.dll
c:\docume~1\COMPUT~1\LOCALS~1\Temp\setup.exe
c:\docume~1\COMPUT~1\LOCALS~1\Temp\TFR16.exe
c:\documents and settings\All Users\Microsoft Private Data
c:\documents and settings\All Users\Microsoft Private Data\Microsoft\t.id
c:\documents and settings\Computer User\Local Settings\Temp\HCBackup\hcpackage.exe
c:\documents and settings\Computer User\Local Settings\Temp\HouseCall\bspatch.exe
c:\documents and settings\Computer User\Local Settings\Temp\HouseCall\bzip2.exe
c:\documents and settings\Computer User\Local Settings\Temp\HouseCall\hc_core.dll
c:\documents and settings\Computer User\Local Settings\Temp\HouseCall\ICRCHdler.dll
c:\documents and settings\Computer User\Local Settings\Temp\HouseCall\libcurl.dll
c:\documents and settings\Computer User\Local Settings\Temp\HouseCall\libeay32.dll
c:\documents and settings\Computer User\Local Settings\Temp\HouseCall\libexpatw.dll
c:\documents and settings\Computer User\Local Settings\Temp\HouseCall\perfiCrcPerfMonMgr.dll
c:\documents and settings\Computer User\Local Settings\Temp\HouseCall\ssleay32.dll
c:\documents and settings\Computer User\Local Settings\Temp\HouseCall\tmcomm.sys
c:\documents and settings\Computer User\Local Settings\Temp\HouseCall\TmEngDrv.dll
c:\documents and settings\Computer User\Local Settings\Temp\HouseCall\tmfbeng.dll
c:\documents and settings\Computer User\Local Settings\Temp\HouseCall\TSC.exe
c:\documents and settings\Computer User\Local Settings\Temp\HouseCall\vsapi32.dll
c:\documents and settings\Computer User\Local Settings\Temp\setup.exe
c:\documents and settings\Computer User\Local Settings\Temp\TFR16.exe
c:\windows\bf23567.dat
c:\windows\Downloaded Program Files\bdcore.dll
c:\windows\Downloaded Program Files\libfn.dll
c:\windows\jmmark2.dat
c:\windows\kb913800.exe
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\lowsec
c:\windows\system32\nosazene.dll
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
c:\windows\zaponce52597.dat
c:\windows\zaponce52621.dat
c:\windows\zaponce52689.dat
Infected copy of c:\windows\system32\eventlog.dll was found and disinfected
Restored copy from - c:\windows\system32\dllcache\eventlog.dll
c:\windows\system32\proquota.exe was missing
Restored copy from - c:\windows\system32\dllcache\proquota.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
((((((((((((((((((((((((( Files Created from 2009-09-07 to 2009-10-07 )))))))))))))))))))))))))))))))
.
2009-10-07 17:41 . 2008-04-14 00:12 50176 ----a-w- c:\windows\system32\proquota.exe
2009-10-07 15:13 . 2009-10-07 15:13 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-10-05 22:05 . 2008-07-08 18:54 148496 ----a-w- c:\windows\system32\drivers\93265621.sys
2009-10-05 21:49 . 2008-07-08 18:54 148496 ----a-w- c:\windows\system32\drivers\61875401.sys
2009-10-05 21:45 . 2008-07-08 18:54 148496 ----a-w- c:\windows\system32\drivers\52037295.sys
2009-10-05 21:34 . 2009-10-05 21:34 -------- d-----w- c:\documents and settings\Computer User\Application Data\MSNInstaller
2009-10-05 21:30 . 2009-10-05 21:30 -------- d-----w- c:\program files\CCleaner
2009-10-03 20:00 . 2009-10-03 20:00 -------- d-----w- c:\documents and settings\Computer User\Local Settings\Application Data\Identities
2009-10-03 16:45 . 2009-10-03 16:53 -------- d-----w- c:\documents and settings\Computer User\.housecall6.6
2009-10-03 14:15 . 2009-10-03 14:15 -------- d-----w- c:\program files\Trend Micro
2009-10-03 14:13 . 2009-10-03 14:13 -------- d-----w- c:\documents and settings\Computer User\Application Data\LockHunter
2009-10-03 12:54 . 2009-10-03 12:54 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-10-03 12:54 . 2009-10-03 12:54 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-10-03 12:54 . 2009-10-03 12:54 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-10-03 12:54 . 2009-10-03 12:54 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-10-03 12:54 . 2009-10-05 21:30 -------- d-----w- c:\windows\system32\drivers\Avg
2009-10-03 12:54 . 2009-10-07 15:11 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-10-03 12:54 . 2009-10-03 12:54 -------- d-----w- c:\program files\AVG
2009-10-02 23:43 . 2008-07-08 18:54 148496 ----a-w- c:\windows\system32\drivers\97179918.sys
2009-10-02 23:39 . 2008-07-08 18:54 148496 ----a-w- c:\windows\system32\drivers\17051351.sys
2009-10-02 23:33 . 2008-07-08 18:54 148496 ----a-w- c:\windows\system32\drivers\01159109.sys
2009-10-02 17:52 . 2004-08-04 02:29 33599 -c--a-w- c:\windows\system32\dllcache\watv04nt.sys
2009-10-02 17:51 . 2001-08-18 02:36 99328 -c--a-w- c:\windows\system32\dllcache\srusd.dll
2009-10-02 17:51 . 2001-08-17 16:11 48736 -c--a-w- c:\windows\system32\dllcache\srwlnd5.sys
2009-10-02 17:51 . 2001-08-18 02:36 24660 -c--a-w- c:\windows\system32\dllcache\spxupchk.dll
2009-10-02 17:51 . 2001-08-18 02:36 106584 -c--a-w- c:\windows\system32\dllcache\spdports.dll
2009-10-02 17:51 . 2001-08-17 17:51 61824 -c--a-w- c:\windows\system32\dllcache\speed.sys
2009-10-02 17:51 . 2001-08-17 18:07 19072 -c--a-w- c:\windows\system32\dllcache\sparrow.sys
2009-10-02 17:51 . 2001-08-17 17:56 7552 -c--a-w- c:\windows\system32\dllcache\sonypvu1.sys
2009-10-02 17:51 . 2001-08-18 02:36 114688 -c--a-w- c:\windows\system32\dllcache\sonypi.dll
2009-10-02 17:51 . 2001-08-17 16:51 37040 -c--a-w- c:\windows\system32\dllcache\sonypi.sys
2009-10-02 17:51 . 2001-08-17 17:53 9600 -c--a-w- c:\windows\system32\dllcache\sonymc.sys
2009-10-02 17:51 . 2001-08-17 16:51 20752 -c--a-w- c:\windows\system32\dllcache\sonync.sys
2009-10-02 17:51 . 2008-04-13 18:40 7552 -c--a-w- c:\windows\system32\dllcache\sonyait.sys
2009-10-02 17:51 . 2001-08-17 17:53 7040 -c--a-w- c:\windows\system32\dllcache\snyaitmc.sys
2009-10-02 17:30 . 2001-08-17 17:51 17280 -c--a-w- c:\windows\system32\dllcache\scr111.sys
2009-10-02 17:21 . 2001-08-17 17:51 19584 -c--a-w- c:\windows\system32\dllcache\rasirda.sys
2009-10-02 17:20 . 2004-08-04 02:06 169984 -c--a-w- c:\windows\system32\dllcache\pcx500.sys
2009-10-02 17:16 . 2001-08-17 17:47 9344 -c--a-w- c:\windows\system32\dllcache\ntapm.sys
2009-10-02 17:15 . 2001-08-17 17:52 7424 -c--a-w- c:\windows\system32\dllcache\mammoth.sys
2009-10-02 16:59 . 2008-04-14 00:09 6144 -c--a-w- c:\windows\system32\dllcache\kbd106.dll
2009-10-02 16:58 . 2001-08-17 17:28 50751 -c--a-w- c:\windows\system32\dllcache\hsf_tone.sys
2009-10-02 16:55 . 2001-08-17 16:12 24618 -c--a-w- c:\windows\system32\dllcache\fa410nd5.sys
2009-10-02 16:54 . 2001-08-17 17:52 14720 -c--a-w- c:\windows\system32\dllcache\dac960nt.sys
2009-10-02 16:53 . 2001-08-17 17:51 13824 -c--a-w- c:\windows\system32\dllcache\bulltlp3.sys
2009-10-02 16:52 . 2004-08-04 02:31 36224 -c--a-w- c:\windows\system32\dllcache\an983.sys
2009-10-02 16:52 . 2001-08-17 17:47 6272 -c--a-w- c:\windows\system32\dllcache\apmbatt.sys
2009-10-02 16:52 . 2001-08-17 17:52 12032 -c--a-w- c:\windows\system32\dllcache\amsint.sys
2009-10-02 16:52 . 2001-08-17 16:11 16969 -c--a-w- c:\windows\system32\dllcache\amb8002.sys
2009-10-02 16:52 . 2001-08-17 17:51 5248 -c--a-w- c:\windows\system32\dllcache\aliide.sys
2009-10-02 16:52 . 2001-08-17 17:49 26624 -c--a-w- c:\windows\system32\dllcache\alifir.sys
2009-10-02 16:52 . 2001-08-17 18:07 56960 -c--a-w- c:\windows\system32\dllcache\aic78xx.sys
2009-10-02 16:52 . 2001-08-17 16:11 27678 -c--a-w- c:\windows\system32\dllcache\ali5261.sys
2009-10-02 16:52 . 2001-08-17 18:07 55168 -c--a-w- c:\windows\system32\dllcache\aic78u2.sys
2009-10-02 16:52 . 2001-08-17 17:52 12800 -c--a-w- c:\windows\system32\dllcache\aha154x.sys
2009-10-02 14:37 . 2008-07-08 18:54 148496 ----a-w- c:\windows\system32\drivers\22798165.sys
2009-10-02 03:57 . 2009-10-07 17:43 32243744 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-09-30 23:04 . 2009-10-02 22:15 -------- d-----w- c:\program files\Spybot - Search & Destroy4
2009-09-30 22:38 . 2009-09-30 23:04 -------- d-----w- c:\program files\Spybot - Search & Destroy3
2009-09-30 22:26 . 2009-10-02 22:14 -------- d-----w- c:\program files\Spybot - Search & Destroy2
2009-09-30 22:05 . 2009-10-07 14:31 -------- d--h--w- c:\windows\PIF
2009-09-30 20:55 . 2009-09-30 20:55 -------- d-----w- C:\Patch files
2009-09-30 18:21 . 2009-10-07 17:22 0 ----a-r- c:\windows\win32k.sys
2009-09-30 18:21 . 2009-09-30 18:21 79360 ----a-w- C:\mqhimp.exe
2009-09-22 04:55 . 2009-09-30 22:11 -------- d-----w- c:\windows\BDOSCAN8
2009-09-22 04:43 . 2009-09-22 04:43 10752 ----a-w- c:\windows\DCEBoot.exe
2009-09-22 04:39 . 2009-05-07 07:04 157712 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2009-09-21 19:22 . 2008-04-14 00:12 82432 ---h-tw- c:\windows\system32\6abc18c.dll
2009-09-21 19:22 . 2008-04-14 00:12 82432 ---h-tw- c:\windows\system32\1e9dbd56.dll
2009-09-21 19:04 . 2009-09-21 19:04 -------- d-----w- c:\program files\Common Files\iS3
2009-09-20 14:21 . 2008-04-14 00:12 82432 ---h-tw- c:\windows\system32\3142fe00.dll
2009-09-20 14:21 . 2008-04-14 00:12 82432 ---h-tw- c:\windows\system32\2e2d380.dll
2009-09-19 19:04 . 2008-04-14 00:12 82432 ---h-tw- c:\windows\system32\2a3ce04.dll
2009-09-19 19:04 . 2008-04-14 00:12 82432 ---h-tw- c:\windows\system32\15a0962.dll
2009-09-19 18:42 . 2008-04-14 00:12 82432 ---h-tw- c:\windows\system32\f14e6b4.dll
2009-09-19 18:42 . 2008-04-14 00:12 82432 ---h-tw- c:\windows\system32\1afda2c.dll
2009-09-19 18:04 . 2009-09-30 22:49 -------- dc-h--w- c:\windows\ie8
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-07 17:41 . 2009-10-02 03:57 378116 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-10-07 01:23 . 2008-05-21 17:25 -------- d-----w- c:\program files\Java
2009-10-07 01:23 . 2009-10-07 01:23 0 ----a-w- c:\windows\system32\REND.tmp
2009-10-05 21:48 . 2009-06-25 02:14 -------- d-----w- c:\program files\DivX
2009-10-04 17:47 . 2009-10-04 16:57 3808 ----a-w- c:\windows\system32\drivers\kgpcpy.cfg
2009-10-04 16:59 . 2009-10-04 16:58 688 ----a-w- c:\windows\system32\drivers\kgpfr2.cfg
2009-10-03 17:37 . 2008-08-29 08:44 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2009-10-02 23:53 . 2008-08-13 16:59 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-10-02 02:37 . 2008-07-09 01:27 -------- d-----w- c:\program files\VideoLAN
2009-09-30 23:01 . 2008-05-21 15:46 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-30 22:45 . 2008-07-07 22:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-09-28 18:54 . 2008-07-09 00:59 -------- d-----w- c:\program files\Gpotato
2009-08-29 21:33 . 2008-07-09 01:15 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-08-29 21:32 . 2009-08-29 21:12 -------- d-----w- c:\program files\AGEIA Technologies
2009-08-29 21:25 . 2008-09-25 01:45 -------- d-----w- c:\program files\SystemRequirementsLab
2009-08-23 04:22 . 2008-09-11 00:28 -------- d-----w- c:\program files\NVIDIA Corporation
2009-08-23 04:22 . 2009-08-23 04:22 -------- d-----w- c:\documents and settings\All Users\Application Data\NVIDIA Corporation
2009-08-23 04:05 . 2009-08-23 04:05 -------- d-----w- c:\program files\THQICE
2009-08-17 07:04 . 2009-08-17 07:04 2173472 ----a-w- c:\windows\system32\nvcplui.exe
2009-08-17 07:04 . 2009-08-17 07:04 81920 ----a-w- c:\windows\system32\nvwddi.dll
2009-08-17 07:03 . 2009-08-17 07:03 3170304 ----a-w- c:\windows\system32\nvwss.dll
2009-08-17 07:03 . 2009-08-17 07:03 4026368 ----a-w- c:\windows\system32\nvvitvs.dll
2009-08-17 07:03 . 2009-08-17 07:03 188416 ----a-w- c:\windows\system32\nvmccss.dll
2009-08-17 07:03 . 2009-08-17 07:03 1286144 ----a-w- c:\windows\system32\nvmobls.dll
2009-08-17 07:03 . 2009-08-17 07:03 3547136 ----a-w- c:\windows\system32\nvgames.dll
2009-08-17 07:03 . 2009-08-17 07:03 4923392 ----a-w- c:\windows\system32\nvdisps.dll
2009-08-17 07:03 . 2009-08-17 07:03 86016 ----a-w- c:\windows\system32\nvmctray.dll
2009-08-17 07:03 . 2009-08-17 07:03 168004 ----a-w- c:\windows\system32\nvsvc32.exe
2009-08-17 07:03 . 2009-08-17 07:03 143360 ----a-w- c:\windows\system32\nvcolor.exe
2009-08-17 07:03 . 2009-08-17 07:03 13877248 ----a-w- c:\windows\system32\nvcpl.dll
2009-08-17 07:02 . 2009-08-17 07:02 229376 ----a-w- c:\windows\system32\nvmccs.dll
2009-08-17 04:57 . 2009-08-29 21:10 485920 ----a-w- c:\windows\system32\nvudisp.exe
2009-08-17 04:57 . 2009-08-17 04:57 1706528 ----a-w- c:\windows\system32\nvcuvenc.dll
2009-08-17 04:57 . 2009-08-17 04:57 1597690 ----a-w- c:\windows\system32\nvdata.bin
2009-08-17 04:57 . 2009-02-18 18:44 868352 ----a-w- c:\windows\system32\nvapi.dll
2009-08-17 04:57 . 2009-02-18 18:44 2189856 ----a-w- c:\windows\system32\nvcuvid.dll
2009-08-17 04:57 . 2009-02-18 18:44 2002944 ----a-w- c:\windows\system32\nvcuda.dll
2009-08-17 04:57 . 2009-02-18 18:44 155648 ----a-w- c:\windows\system32\nvcodins.dll
2009-08-17 04:57 . 2009-02-18 18:44 155648 ----a-w- c:\windows\system32\nvcod.dll
2009-08-17 04:57 . 2009-02-18 18:44 10457088 ----a-w- c:\windows\system32\nvoglnt.dll
2009-08-17 04:57 . 2008-05-21 16:00 7729568 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2009-08-17 04:57 . 2008-05-21 16:00 5845760 ----a-w- c:\windows\system32\nv4_disp.dll
2009-08-14 17:36 . 2009-08-14 17:36 70936 ----a-w- c:\windows\system32\PhysXLoader.dll
2009-08-11 16:35 . 2009-08-29 21:10 485920 ----a-w- c:\windows\system32\NVUNINST.EXE
2009-08-05 09:01 . 2004-08-03 22:56 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-03 04:21 . 2009-08-03 04:21 23320 ----a-w- c:\windows\system32\PhysXDevice.dll
2009-07-29 04:37 . 2006-09-26 20:08 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-07-29 04:37 . 2006-09-26 20:07 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-07-17 19:01 . 2004-08-03 22:56 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 14:08 . 2006-09-26 20:09 286720 ----a-w- c:\windows\system32\wmpdxm.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-09-02 15:58 1107200 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 1107200]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2009-08-13 1657376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-08-17 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-08-17 13877248]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-03-24 94208]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-03-24 118784]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-03-24 77824]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-10-03 2023704]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Belkin F5D8053 N Wireless USB Adapter Utility.lnk - c:\program files\Belkin\F5D8053\Belkinwcui.exe [2007-9-17 1732608]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-10-03 12:54 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rootrepeal.sys]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^Computer User^Start Menu^Programs^Startup^is-F04P4.lnk]
path=c:\documents and settings\Computer User\Start Menu\Programs\Startup\is-F04P4.lnk
backup=c:\windows\pss\is-F04P4.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Computer User^Start Menu^Programs^Startup^is-HMN82.lnk]
path=c:\documents and settings\Computer User\Start Menu\Programs\Startup\is-HMN82.lnk
backup=c:\windows\pss\is-HMN82.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Computer User^Start Menu^Programs^Startup^is-SI9JV.lnk]
path=c:\documents and settings\Computer User\Start Menu\Programs\Startup\is-SI9JV.lnk
backup=c:\windows\pss\is-SI9JV.lnkStartup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\monitor.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\manager.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\server.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\THQICE\\Dragonica Online - Open Beta Test\\Release\\DRAGONICA.EXE"=
"c:\\Program Files\\AVG\\AVG8\\avgrsx.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
R1 is-SI9JVdrv;is-SI9JVdrv;c:\windows\system32\DRIVERS\52037295.sys [2008-07-08 148496]
R1 SABKUTIL;SABKUTIL;c:\program files\SuperAdBlocker.com\Super Ad Blocker\SABKUTIL.sys [x]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [x]
R3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter;c:\windows\system32\DRIVERS\ADM8511.SYS [2001-08-17 20160]
R3 digiclsb;digiclsb;c:\windows\system32\DRIVERS\digiclsb.sys [2007-07-25 122254]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [x]
R3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver;c:\windows\system32\DRIVERS\rt2870.sys [2007-07-28 517632]
R3 UFB;UFB;c:\docume~1\COMPUT~1\LOCALS~1\Temp\UFB.exe [x]
R3 XDva202;XDva202;c:\windows\system32\XDva202.sys [x]
R4 EBRHT;EBRHT;c:\docume~1\COMPUT~1\LOCALS~1\Temp\EBRHT.exe [x]
R4 JMDNNI;JMDNNI;c:\docume~1\COMPUT~1\LOCALS~1\Temp\JMDNNI.exe [2005-12-07 97280]
R4 UNXJABY;UNXJABY;c:\docume~1\COMPUT~1\LOCALS~1\Temp\UNXJABY.exe [x]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-10-03 335240]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-10-03 108552]
S1 is-C02J6drv;is-C02J6drv;c:\windows\system32\DRIVERS\01159109.sys [2008-07-08 148496]
S1 is-F04P4drv;is-F04P4drv;c:\windows\system32\DRIVERS\61875401.sys [2008-07-08 148496]
S1 is-HMN82drv;is-HMN82drv;c:\windows\system32\DRIVERS\93265621.sys [2008-07-08 148496]
S1 is-IJUH8drv;is-IJUH8drv;c:\windows\system32\DRIVERS\97179918.sys [2008-07-08 148496]
S1 is-O1NVRdrv;is-O1NVRdrv;c:\windows\system32\DRIVERS\17051351.sys [2008-07-08 148496]
S1 is-PLQIVdrv;is-PLQIVdrv;c:\windows\system32\DRIVERS\22798165.sys [2008-07-08 148496]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-10-03 297752]
.
Contents of the 'Scheduled Tasks' folder
2009-09-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
FF - ProfilePath - c:\documents and settings\Computer User\Application Data\Mozilla\Firefox\Profiles\cwlj312a.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\documents and settings\Computer User\Application Data\Mozilla\Firefox\Profiles\cwlj312a.default\extensions\CSLauncher@getamped.com\plugins\npCsLauncher.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
Toolbar-SITEguard - (no file)
Notify-NavLogon - (no file)
SafeBoot-AVG Anti-Spyware Driver
SafeBoot-AVG Anti-Spyware Guard
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-10-07 13:43
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-2052111302-920026266-1801674531-1003\Software\SecuROM\License information*]
"datasecu"=hex:6b,42,0a,b8,e6,92,bd,09,a3,d9,23,bf,c1,a0,f1,d1,ba,3d,06,07,32,
3b,c6,5d,84,dc,e2,60,f3,c8,1d,14,a7,58,a0,18,39,e2,b3,8f,cf,75,c1,a2,26,4b,\
"rkeysecu"=hex:e2,26,6d,94,9c,ba,ad,1d,64,79,70,1b,d8,19,de,23
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2552)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-10-07 13:47 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-07 17:47
Pre-Run: 32,375,246,848 bytes free
Post-Run: 32,351,657,984 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
[spybotsd]
timeout.old=30
Current=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4
393
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:11:47, on 10/7/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Belkin\F5D8053\Belkinwcui.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Computer User\My Documents\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-2052111302-920026266-1801674531-1003\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User '?')
O4 - HKUS\S-1-5-21-2052111302-920026266-1801674531-1003\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - Global Startup: Belkin F5D8053 N Wireless USB Adapter Utility.lnk = C:\Program Files\Belkin\F5D8053\Belkinwcui.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) -
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) -
http://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) -
http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) -
http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) -
http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.3.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) -
http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) -
http://messenger.zone.msn.com/PT-BR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1196436445734
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1196436378265
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) -
http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
O16 - DPF: {80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA} -
http://zone.msn.com/bingame/zpagames/GAME_UNO1.cab60096.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) -
http://cdn2.zone.msn.com/binFramework/v10/ZPAFramework.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} -
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) -
http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Unknown owner - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: UFB - Unknown owner - C:\DOCUME~1\COMPUT~1\LOCALS~1\Temp\UFB.exe (file missing)
--
End of file - 9308 bytes