this is combofix report
ComboFix 08-05-27.4 - craig 29/05/2008 17:40:04.1 - NTFSx86
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.38 [GMT 1:00]
Running from: C:\Documents and Settings\craig\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINNT\BMffa5aec3.xml
C:\WINNT\cookies.ini
C:\WINNT\pskt.ini
C:\WINNT\system32\aenkuwtw.exe
C:\WINNT\system32\apqxjnif.ini
C:\WINNT\system32\awponvfj.dll
C:\WINNT\system32\bfybterg.dll
C:\WINNT\system32\BKUDNXbc.ini
C:\WINNT\system32\BKUDNXbc.ini2
C:\WINNT\system32\cfleajel.dll
C:\WINNT\system32\components
C:\WINNT\system32\depqxuon.dll
C:\WINNT\system32\dpdkybqt.ini
C:\WINNT\system32\ejpgwdvg.dll
C:\WINNT\system32\ekmkbndp.dll
C:\WINNT\system32\fadsrpyc.ini
C:\WINNT\system32\finjxqpa.dll
C:\WINNT\system32\gmlcowxy.ini
C:\WINNT\system32\idtfdbfl.ini
C:\WINNT\system32\jbktqypi.ini
C:\WINNT\system32\jkuejbnn.exe
C:\WINNT\system32\mcrh.tmp
C:\WINNT\system32\nnxchwmq.ini
C:\WINNT\system32\nouxqped.ini
C:\WINNT\system32\ojjbhkiw.dll
C:\WINNT\system32\qevljlhy.dll
C:\WINNT\system32\qgatrlwk.exe
C:\WINNT\system32\rtewxdue.dll
C:\WINNT\system32\ruiwrnxx.dll
C:\WINNT\system32\rwxtvjvo.exe
C:\WINNT\system32\sohpjgrh.ini
C:\WINNT\system32\tqbykdpd.dll
C:\WINNT\system32\tvklnxgm.dll
C:\WINNT\system32\urjrevbs.dll
C:\WINNT\system32\usdteuec.ini
C:\WINNT\system32\waatgqcq.exe
C:\WINNT\system32\wikhbjjo.ini
C:\WINNT\system32\wikhbjjo.tmp
C:\WINNT\system32\wlixchdp.exe
C:\WINNT\system32\xiywpodl.dll
C:\WINNT\system32\ysfxjmgl.dll
C:\WINNT\system32\yxadd.bak1
C:\WINNT\system32\yxadd.bak2
C:\WINNT\system32\yxadd.ini
C:\WINNT\Web\default.htt
.
((((((((((((((((((((((((( Files Created from 2008-04-28 to 2008-05-29 )))))))))))))))))))))))))))))))
.
2008-05-28 22:16 . 08-05-29 17:32 640,904 ---h----- C:\WINNT\ShellIconCache
2008-05-28 22:14 . 08-05-28 22:14 <DIR> d-------- C:\WINNT\system32\Kaspersky Lab
2008-05-28 22:14 . 08-05-28 22:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-27 22:16 . 08-05-27 22:16 <DIR> d-------- C:\Program Files\ParetoLogic
2008-05-27 22:16 . 08-05-27 22:16 <DIR> d-------- C:\Program Files\Common Files\ParetoLogic
2008-05-27 22:16 . 08-05-27 22:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ParetoLogic Anti-Spyware
2008-05-26 17:21 . 08-05-26 17:21 <DIR> d-------- C:\Documents and Settings\Amy\Application Data\Grisoft
2008-05-25 11:48 . 08-05-25 11:48 92,160 --a------ C:\WINNT\system32\cymiemjr.dll
2008-05-25 10:45 . 08-05-25 10:45 92,160 --a------ C:\WINNT\system32\matxkltd.dll
2008-05-24 10:58 . 08-05-24 10:58 <DIR> d-------- C:\Documents and Settings\craig\Application Data\Grisoft
2008-05-24 10:58 . 08-05-24 10:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-05-24 10:58 . 07-05-30 13:10 10,872 --a------ C:\WINNT\system32\drivers\AvgAsCln.sys
2008-05-24 10:39 . 08-05-24 10:39 92,160 --a------ C:\WINNT\system32\svfrtbdm.dll
2008-05-22 20:29 . 08-05-22 20:29 92,160 --a------ C:\WINNT\system32\agkijuvm.dll
2008-05-22 08:49 . 08-05-22 08:49 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-05-21 13:29 . 08-05-21 13:29 0 --a------ C:\WINNT\system32\SBRC.dat
2008-05-21 13:29 . 08-05-21 13:29 0 --a------ C:\WINNT\system32\SBFC.dat
2008-05-21 10:53 . 08-05-21 10:53 <DIR> d-------- C:\Documents and Settings\craig\Application Data\Sunbelt Software
2008-05-21 10:50 . 08-05-21 10:50 92,160 --a------ C:\WINNT\system32\akmnifpj.dll
2008-05-21 10:47 . 08-05-21 10:47 92,160 --a------ C:\WINNT\system32\drclgvfr.dll
2008-05-21 10:42 . 08-05-21 10:42 56,320 --a------ C:\WINNT\system32\qoMfebbx.dll
2008-05-21 10:38 . 08-05-21 10:38 56,320 --a------ C:\WINNT\system32\ssqRJdDS.dll.bak
2008-05-18 20:42 . 08-05-18 20:42 <DIR> d-------- C:\34a94e8906bad48dca611f25f5
2008-05-13 19:14 . 08-05-13 19:14 54,156 --ah----- C:\WINNT\QTFont.qfn
2008-05-13 19:14 . 08-05-13 19:14 1,409 --a------ C:\WINNT\QTFont.for
2008-04-29 11:20 . 08-04-29 11:20 15,648 --a------ C:\WINNT\system32\drivers\NSDriver.sys
2008-04-29 11:20 . 08-04-29 11:20 14,624 --a------ C:\WINNT\system32\drivers\AWRTRD.sys
2008-04-29 11:20 . 08-04-29 11:20 12,192 --a------ C:\WINNT\system32\drivers\AWRTPD.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-29 16:48 5,969,652 ----a-w C:\WINNT\Internet Logs\tvDebug.zip
2008-05-29 16:47 2,444 --sha-w C:\WINNT\system32\drivers\fidbox.idx
2008-05-29 16:47 13,172 --sha-w C:\WINNT\system32\drivers\fidbox2.idx
2008-05-29 16:47 129,056 --sha-w C:\WINNT\system32\drivers\fidbox2.dat
2008-05-29 16:47 116,768 --sha-w C:\WINNT\system32\drivers\fidbox.dat
2008-05-29 15:22 8,400 ----a-w C:\Program Files\hijackthis.log
2008-05-28 15:16 --------- d-----w C:\Documents and Settings\craig\Application Data\BitTorrent
2008-05-27 07:18 --------- d---a-w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-21 19:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-21 18:59 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-05-21 09:39 --------- d-----w C:\Program Files\Lavasoft
2008-05-20 17:21 --------- d-----w C:\Program Files\IKEA HomePlanner
2008-05-20 08:12 --------- d-----w C:\Program Files\TClock
2008-05-12 07:52 --------- d-----w C:\Program Files\HP
2008-04-21 14:08 13,144 ----a-w C:\WINNT\system32\lsdelete.exe
2008-04-16 07:45 13,944 ----a-w C:\Documents and Settings\craig\Application Data\GDIPFONTCACHEV1.DAT
2008-04-06 15:55 --------- d-----w C:\Documents and Settings\Amy\Application Data\Ahead
2008-03-27 07:13 151,583 ----a-w C:\WINNT\system32\msjint40.dll
2008-03-27 07:06 355,104 ----a-w C:\WINNT\system32\msxbde40.dll
2008-03-27 07:05 838,432 ----a-w C:\WINNT\system32\mswdat10.dll
2008-03-27 07:05 621,344 ----a-w C:\WINNT\system32\mswstr10.dll
2008-03-27 07:05 264,992 ----a-w C:\WINNT\system32\mstext40.dll
2008-03-27 07:04 559,904 ----a-w C:\WINNT\system32\msrepl40.dll
2008-03-27 07:04 432,928 ----a-w C:\WINNT\system32\msrd2x40.dll
2008-03-27 07:04 322,336 ----a-w C:\WINNT\system32\msrd3x40.dll
2008-03-27 07:03 355,104 ----a-w C:\WINNT\system32\mspbde40.dll
2008-03-27 07:03 248,608 ----a-w C:\WINNT\system32\msjtes40.dll
2008-03-27 07:03 219,936 ----a-w C:\WINNT\system32\msltus40.dll
2008-03-27 07:02 60,192 ----a-w C:\WINNT\system32\msjter40.dll
2008-03-27 07:02 355,112 ----a-w C:\WINNT\system32\msjetoledb40.dll
2008-03-27 07:01 1,516,568 ----a-w C:\WINNT\system32\msjet40.dll
2008-03-27 07:00 518,944 ----a-w C:\WINNT\system32\msexch40.dll
2008-03-27 07:00 326,432 ----a-w C:\WINNT\system32\msexcl40.dll
2008-03-23 20:42 904,192 ----a-w C:\WINNT\Internet Logs\xDBC.tmp
2008-03-19 09:26 1,644,080 ----a-w C:\WINNT\system32\WIN32K.SYS
2008-03-17 22:41 311,808 ----a-w C:\WINNT\Internet Logs\xDBB.tmp
2008-03-13 09:03 2,651,136 ----a-w C:\WINNT\Internet Logs\xDBA.tmp
2008-03-04 19:24 719,360 ----a-w C:\WINNT\Internet Logs\xDB9.tmp
2008-01-01 22:13 13,944 ----a-w C:\Documents and Settings\Amy\Application Data\GDIPFONTCACHEV1.DAT
2005-04-20 07:21 271 ---ha-w C:\Program Files\desktop.ini
2005-04-20 07:21 21,952 ---ha-w C:\Program Files\folder.htt
2005-02-16 10:06 218,112 ----a-w C:\Program Files\HijackThis.exe
1999-12-07 12:00 32,528 ----a-w C:\WINNT\inf\wbfirdma.sys
2006-07-19 20:24 8 --sha-r C:\WINNT\system32\34D5FCDEC2.sys
2006-07-19 20:24 3,350 --sha-w C:\WINNT\system32\KGyGaAvL.sys
.
------- Sigcheck -------
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MtdAcq"="C:\Program Files\Creative\Shared Files\Media Sniffer\MtdAcq.exe" [04-07-02 11:26 122956]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [04-09-22 20:00 94208]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [04-08-06 03:50 139320]
"Network Associates Error Reporting Service"="C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe" [03-10-07 09:48 147514]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [05-06-06 23:46 57344]
"Synchronization Manager"="mobsync.exe" [03-06-19 12:05 111376 C:\WINNT\system32\mobsync.exe]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [07-05-08 16:24 54840]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [08-01-11 23:16 39792]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [07-04-27 10:41 282624]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"internat.exe"="internat.exe" [99-12-07 13:00 20752 C:\WINNT\system32\internat.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 05:21:22 288472]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{51C55F9E-C308-4c95-89AB-8858D8AFD819}"= C:\Program Files\ParetoLogic\Anti-Spyware\PASShlExt.dll [08-05-21 17:43 98304]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddaxy]
C:\WINNT\system32\ddaxy.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljjkhg]
mljjkhg.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqRJdDS]
ssqRJdDS.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= mmdrv.dll
R0 amd751;AMD AGP Bus Filter;C:\WINNT\system32\DRIVERS\amd751.sys [99-09-28 16:37 ]
R3 EntDrv50;EntDrv50;C:\WINNT\system32\drivers\EntDrv50.sys [05-01-14 20:00 ]
R3 openhci;Microsoft USB Open Host Controller Driver;C:\WINNT\system32\DRIVERS\openhci.sys [03-06-19 12:05 ]
S3 se46bus;Sony Ericsson Device 070 driver (WDM);C:\WINNT\system32\DRIVERS\se46bus.sys [06-11-30 15:11 ]
S3 se46mdfl;Sony Ericsson Device 070 USB WMC Modem Filter;C:\WINNT\system32\DRIVERS\se46mdfl.sys [06-11-30 15:11 ]
S3 se46mdm;Sony Ericsson Device 070 USB WMC Modem Driver;C:\WINNT\system32\DRIVERS\se46mdm.sys [06-11-30 15:11 ]
S3 se46mgmt;Sony Ericsson Device 070 USB WMC Device Management Drivers (WDM);C:\WINNT\system32\DRIVERS\se46mgmt.sys [06-11-30 15:11 ]
S3 se46nd5;Sony Ericsson Device 070 USB Ethernet Emulation SEMC46 (NDIS);C:\WINNT\system32\DRIVERS\se46nd5.sys [06-11-30 15:11 ]
S3 se46obex;Sony Ericsson Device 070 USB WMC OBEX Interface;C:\WINNT\system32\DRIVERS\se46obex.sys [06-11-30 15:11 ]
S3 se46unic;Sony Ericsson Device 070 USB Ethernet Emulation SEMC46 (WDM);C:\WINNT\system32\DRIVERS\se46unic.sys [06-11-30 15:11 ]
S3 usb_rndisy;USB RNDIS Adapter;C:\WINNT\system32\DRIVERS\usb8023y.sys [05-10-25 09:02 ]
.
Contents of the 'Scheduled Tasks' folder
"2008-05-27 16:37:28 C:\WINNT\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-05-27 21:16:57 C:\WINNT\Tasks\Pareto UNS.job"
- C:\Program Files\Common Files\ParetoLogic\UUS\UUS.dll\Pareto_Update.exe
"2008-05-27 21:16:49 C:\WINNT\Tasks\ParetoLogic Anti-Spyware.job"
- C:\Program Files\ParetoLogic\Anti-Spyware\Pareto_AS.exe
"2008-05-27 21:16:33 C:\WINNT\Tasks\ParetoLogic Update.job"
- C:\Program Files\Common Files\ParetoLogic\UUS\Pareto_Update.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-29 17:51:55
Windows 5.0.2195 Service Pack 4 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-05-29 17:59:53 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-29 16:59:37
Pre-Run: 93,969,608,704 bytes free
Post-Run: 93,929,099,264 bytes free
201 --- E O F --- 2008-05-17 12:48:07
this is HJT report
Logfile of HijackThis v1.99.1
Scan saved at 18:03:49, on 29/05/2008
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINNT\system32\CTsvcCDA.EXE
C:\WINNT\System32\svchost.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINNT\system32\mgabg.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\MsPMSPSv.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Creative\Shared Files\Media Sniffer\MtdAcq.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINNT\explorer.exe
C:\WINNT\system32\notepad.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;127.0.0.;<local>
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MtdAcq] C:\Program Files\Creative\Shared Files\Media Sniffer\MtdAcq.exe /s
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINNT\system32\shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.orange.co.uk
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) -
http://www.creative.com/softwareupdate/su/ocx/15031/CTSUEng.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3B5E9B23-7537-4601-A9E8-FA0D956DEA16} (csauie1 Control) -
http://www.couponreport.net/ftp/v3123/csauie1.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) -
http://www1.snapfish.com/SnapfishActivia.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://by109fd.bay109.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) -
http://test.catalog.update.microsof.../en/x86/MuCatalogWebControl.cab?1185902118154
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) -
http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} -
http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1143719898375
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) -
http://www.creative.com/softwareupdate/su/ocx/15034/CTPID.cab
O16 - DPF: {FF3F0F03-0F01-131A-A3F9-08F02B23E0CC} -
http://207.226.177.98/dba2339.exe
O20 - Winlogon Notify: ddaxy - C:\WINNT\system32\ddaxy.dll (file missing)
O20 - Winlogon Notify: mljjkhg - mljjkhg.dll (file missing)
O20 - Winlogon Notify: ssqRJdDS - ssqRJdDS.dll (file missing)
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\system32\CTsvcCDA.EXE
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: MGABGEXE - Matrox Graphics Inc. - C:\WINNT\system32\mgabg.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe