Combofix & HJT
"Mona Lynam" - 07-04-17 14:53:53 Service Pack 2
ComboFix 07-04-05.Rev3 - Running from: "C:\Documents and Settings\Mona Lynam\desktop"
Command switches used :: /v iifeb
(((((((((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\befii.bak1
C:\WINDOWS\system32\befii.ini
C:\WINDOWS\system32\befii.tmp
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
((((((((((((((((((((((((((((((( Files Created from 2007-03-17 to 2007-04-17 ))))))))))))))))))))))))))))))))))
2007-04-16 21:03 <DIR> d-------- C:\DOCUME~1\MONALY~1\APPLIC~1\Prevx
2007-04-16 21:00 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Prevx
2007-04-16 20:58 77,312 --a------ C:\WINDOWS\ua2.dll
2007-04-16 19:56 <DIR> d-------- C:\Program Files\InCode Solutions
2007-04-15 13:11 <DIR> d-------- C:\WINDOWS\Prefetch
2007-04-15 12:49 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2007-04-15 12:38 20,992 --a------ C:\WINDOWS\system32\drivers\RTL8139.sys
2007-04-15 12:33 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll
2007-04-15 12:33 13,312 --a------ C:\WINDOWS\system32\irclass.dll
2007-04-12 19:41 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-04-12 15:10 <DIR> d-------- C:\VundoFix Backups
2007-04-12 14:00 <DIR> d-------- C:\DOCUME~1\MONALY~1\APPLIC~1\RecordNow MAX Wizard
2007-04-11 22:33 131,072 --a------ C:\WINDOWS\system32\datestamp.dll
2007-04-11 21:31 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SecTaskMan
2007-04-11 21:30 <DIR> d-------- C:\Program Files\Security Task Manager
2007-04-10 18:51 <DIR> d-------- C:\QUARANTINE
2007-04-10 18:39 1,495,552 --a------ C:\WINDOWS\system32\epoPGPsdk.dll
2007-04-10 18:39 <DIR> d-------- C:\Program Files\Common Files\Cisco Systems
2007-04-10 18:39 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee
2007-04-10 18:38 72,264 --a------ C:\WINDOWS\system32\drivers\mfeavfk.sys
2007-04-10 18:38 64,360 --a------ C:\WINDOWS\system32\drivers\mfeapfk.sys
2007-04-10 18:38 52,136 --a------ C:\WINDOWS\system32\drivers\mfetdik.sys
2007-04-10 18:38 34,152 --a------ C:\WINDOWS\system32\drivers\mfebopk.sys
2007-04-10 18:38 170,408 --a------ C:\WINDOWS\system32\drivers\mfehidk.sys
2007-04-10 18:35 <DIR> d-------- C:\Program Files\McAfee
2007-04-10 18:35 <DIR> d-------- C:\Program Files\Common Files\McAfee
2007-04-10 15:28 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2007-04-09 21:29 <DIR> d-------- C:\WINDOWS\uninstall
2007-04-09 20:51 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-04-08 23:38 <DIR> d-------- C:\{8001807E-0000-0000-9BBA-104992C36D50}
2007-04-08 20:43 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2007-04-07 15:59 76,560 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2007-04-06 08:14 <DIR> d-------- C:\Program Files\DVD Shrink
2007-04-06 08:14 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\DVD Shrink
2007-04-05 23:32 2,560 --a------ C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-04-05 23:32 2,432 --a------ C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-04-05 23:32 129,784 --a------ C:\WINDOWS\system32\pxafs.dll
2007-04-05 23:32 118,520 --a------ C:\WINDOWS\system32\pxinsi64.exe
2007-04-05 23:32 116,472 --a------ C:\WINDOWS\system32\pxcpyi64.exe
2007-04-05 23:18 <DIR> d-------- C:\Program Files\Common Files\xing shared
2007-04-05 23:10 <DIR> d-------- C:\DOCUME~1\MONALY~1\APPLIC~1\Real
2007-04-05 23:06 <DIR> d-------- C:\My Downloads
2007-04-05 21:59 <DIR> d-------- C:\Program Files\Lavasoft
2007-04-05 21:44 <DIR> d-------- C:\Program Files\Lavasoft Ad-Aware
2007-04-05 21:23 5,600 --a------ C:\WINDOWS\system\WINASPI.DLL
2007-04-05 21:23 45,056 --a------ C:\WINDOWS\system32\WNASPI32.DLL
2007-04-05 21:23 4,672 --a------ C:\WINDOWS\system\WOWPOST.EXE
2007-04-05 21:23 16,877 --a------ C:\WINDOWS\system32\drivers\ASPI32.SYS
2007-04-05 21:20 522,682 --a------ C:\WINDOWS\system\aspi_471a2.exe
2007-04-05 21:20 <DIR> d-------- C:\adaptec
2007-04-05 20:06 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SlySoft
2007-04-05 19:59 3,932,160 --a------ C:\DOCUME~1\MONALY~1\ntuser.dat
2007-04-05 19:45 <DIR> d-------- C:\DOCUME~1\MONALY~1\APPLIC~1\SlySoft
2007-04-05 19:27 <DIR> d-------- C:\Program Files\LiveUpdate
2007-04-05 19:26 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2007-04-05 17:40 <DIR> d-------- C:\WINDOWS\Sun
2007-04-05 17:40 <DIR> d-------- C:\DOCUME~1\MONALY~1\APPLIC~1\Sun
2007-04-05 14:48 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Elaborate Bytes
2007-04-05 13:55 <DIR> d-------- C:\CloneDVDTemp
2007-04-05 13:44 <DIR> d-------- C:\Program Files\Elaborate Bytes
2007-04-05 13:32 <DIR> d-------- C:\Program Files\SlySoft
2007-04-04 22:59 <DIR> d-------- C:\DOCUME~1\MONALY~1\Incomplete
2007-04-04 22:46 <DIR> d-------- C:\DOCUME~1\MONALY~1\.limewire
2007-04-04 21:03 <DIR> d-------- C:\Program Files\WinAVIVideoConverter
2007-04-04 18:56 <DIR> d-------- C:\Program Files\Total Video Converter
2007-04-04 13:41 <DIR> d-------- C:\divx
2007-04-04 13:40 <DIR> d-------- C:\DOCUME~1\MONALY~1\APPLIC~1\DivX
2007-04-04 12:39 56 -rahs---- C:\WINDOWS\system32\819E506783.sys
2007-04-04 12:39 3,350 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
2007-04-04 12:39 <DIR> d-------- C:\Program Files\DivX
2007-04-03 21:02 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\55-85-oq-1r-48-n2
2007-04-01 15:27 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2007-03-29 10:14 59,904 --a------ C:\WINDOWS\system32\Mscc2fr.dll
2007-03-29 10:14 32,768 --a------ C:\WINDOWS\system32\CMDLGFR.DLL
2007-03-29 10:14 21,504 --a------ C:\WINDOWS\system32\TABCTFR.DLL
2007-03-29 10:14 15,360 --a------ C:\WINDOWS\system32\inetfr.DLL
2007-03-29 10:14 141,312 --a------ C:\WINDOWS\system32\MSCMCFR.DLL
2007-03-29 10:14 119,568 --a------ C:\WINDOWS\system32\VB6FR.DLL
2007-03-29 10:14 101,888 --a------ C:\WINDOWS\system32\VB6STKIT.DLL
2007-03-29 10:14 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2007-03-27 00:55 524,288 --a------ C:\WINDOWS\system32\DivXsm.exe
2007-03-27 00:55 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2007-03-27 00:55 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll
2007-03-27 00:55 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll
2007-03-27 00:49 73,728 --a------ C:\WINDOWS\system32\dpl100.dll
2007-03-27 00:49 593,920 --a------ C:\WINDOWS\system32\dpuGUI11.dll
2007-03-27 00:49 57,344 --a------ C:\WINDOWS\system32\dpv11.dll
2007-03-27 00:49 53,248 --a------ C:\WINDOWS\system32\dpuGUI10.dll
2007-03-27 00:49 344,064 --a------ C:\WINDOWS\system32\dpus11.dll
2007-03-27 00:49 294,912 --a------ C:\WINDOWS\system32\dpu11.dll
2007-03-27 00:49 294,912 --a------ C:\WINDOWS\system32\dpu10.dll
2007-03-27 00:49 196,608 --a------ C:\WINDOWS\system32\dtu100.dll
2007-03-27 00:48 823,296 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2007-03-27 00:48 823,296 --a------ C:\WINDOWS\system32\divx_xx07.dll
2007-03-27 00:48 802,816 --a------ C:\WINDOWS\system32\divx_xx11.dll
2007-03-27 00:48 639,066 --a------ C:\WINDOWS\system32\DivX.dll
2007-03-26 23:58 <DIR> d-------- C:\Program Files\DaisyWords
2007-03-26 21:22 <DIR> d-------- C:\DOCUME~1\MONALY~1\APPLIC~1\Beep Industries
2007-03-26 21:20 <DIR> d-------- C:\Program Files\GameHouse
2007-03-25 19:16 <DIR> d-------- C:\DOCUME~1\MONALY~1\APPLIC~1\WNR
2007-03-22 19:27 <DIR> d-------- C:\Program Files\_ArcadeDownloadFolder
2007-03-21 22:54 <DIR> d--h----- C:\WINDOWS\PIF
2007-03-21 22:42 <DIR> d-------- C:\DOCUME~1\MONALY~1\APPLIC~1\vlc
2007-03-21 22:38 <DIR> d-------- C:\Program Files\VideoLAN
2007-03-21 17:01 4 --ah----- C:\WINDOWS\uccspecb.sys
2007-03-20 16:56 <DIR> d-------- C:\WINDOWS\Dora's Carnival Adventure
2007-03-19 22:16 <DIR> d-------- C:\WINDOWS\system32\appmgmt
2007-03-19 20:51 <DIR> d-------- C:\Program Files\eBrainyGames
2007-03-18 21:49 <DIR> d-------- C:\DOCUME~1\MONALY~1\APPLIC~1\Nology
2007-03-18 20:20 <DIR> d-------- C:\Program Files\Oberon Media
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-04-17 15:01 -------- d-------- C:\Program Files\avpersonal
2007-04-15 12:43 22720 --a------ C:\WINDOWS\system32\emptyregdb.dat
2007-04-15 11:48 -------- d-------- C:\Program Files\online services
2007-04-10 22:20 -------- d-------- C:\Program Files\_arcadedownloadfolder
2007-04-10 22:19 -------- d-------- C:\Program Files\wingowspoker98
2007-04-10 22:12 -------- d-------- C:\Program Files\wingowspoker
2007-04-10 22:12 -------- d-------- C:\Program Files\windows media connect 2
2007-04-10 21:53 -------- d-------- C:\Program Files\stomp
2007-04-10 21:47 -------- d-------- C:\Program Files\reflexivearcade
2007-04-10 20:07 -------- d-------- C:\Program Files\real
2007-04-10 20:06 -------- d-------- C:\Program Files\microsoft carioca rummy
2007-04-10 20:06 -------- d-------- C:\Program Files\lexmark x74-x75
2007-04-10 19:40 -------- d-------- C:\Program Files\java
2007-04-10 19:39 -------- d-------- C:\Program Files\google
2007-04-10 19:34 -------- d-------- C:\Program Files\bfg
2007-04-10 18:51 700416 --a------ C:\StubInstaller.exe
2007-04-05 23:17 -------- d-------- C:\Program Files\Common Files\real
2007-04-05 22:17 -------- d-------- C:\DOCUME~1\MONALY~1\APPLIC~1\lavasoft
2007-03-27 00:55 36624 --a------ C:\WINDOWS\system32\drivers\pxhelp20.sys
2007-03-15 15:42 77000 --a------ C:\WINDOWS\system32\drivers\AnyDVD.sys
2007-03-15 12:23 497496 --a------ C:\WINDOWS\system32\xceedzip.dll
2007-03-15 12:19 526184 --a------ C:\WINDOWS\system32\xceedcry.dll
2007-03-04 19:31 3084 --a------ C:\WINDOWS\system32\x.dat
2007-02-28 21:55 -------- d-------- C:\Program Files\Common Files\java
2007-02-28 21:26 -------- d-------- C:\DOCUME~1\MONALY~1\APPLIC~1\kazaa lite
2007-02-28 16:05 86016 --a------ C:\WINDOWS\system32\elbycdio.dll
2007-02-28 13:56 15440 --a------ C:\WINDOWS\system32\drivers\ElbyCDIO.sys
2007-02-15 18:40 124472 --a------ C:\WINDOWS\system32\divxcodecupdatechecker.exe
2007-02-06 23:14 80 -rahs---- C:\WINDOWS\system32\819e506783.dll
2007-01-29 22:33 1632 --a------ C:\WINDOWS\system32\d3d8caps.dat
2007-01-27 23:04 592 --a------ C:\WINDOWS\chgkey.vbs
2007-01-27 21:54 774144 --a------ C:\Program Files\rnginterstitial.dll
2007-01-26 23:57 0 -rahs---- C:\MSDOS.SYS
2007-01-26 23:57 0 -rahs---- C:\IO.SYS
2007-01-26 23:57 0 --a------ C:\CONFIG.SYS
2007-01-26 23:57 0 --a------ C:\AUTOEXEC.BAT
2007-01-26 15:33 62 --ahs---- C:\DOCUME~1\MONALY~1\APPLIC~1\desktop.ini
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"updateMgr"="C:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\AdobeUpdateManager.exe AcRdB7_0_9"
@=""
"BTCLiveUpdate"="\"C:\\Program Files\\LiveUpdate\\LiveUpdate.exe\" /autostart"
"AnyDVD"="C:\\Program Files\\SlySoft\\AnyDVD\\AnyDVD.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"AVGCtrl"="\"C:\\Program Files\\AVPersonal\\AVGNT.EXE\" /min"
"Lexmark X74-X75"="\"C:\\Program Files\\Lexmark X74-X75\\lxbbbmgr.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_11\\bin\\jusched.exe\""
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"ShStatEXE"="\"C:\\Program Files\\McAfee\\VirusScan Enterprise\\SHSTAT.EXE\" /STANDALONE"
"McAfeeUpdaterUI"="\"C:\\Program Files\\McAfee\\Common Framework\\UdaterUI.exe\" /StartedFromRunKey"
"PrevxOne"="\"C:\\Program Files\\Prevx1\\PXConsole.exe\""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iifeb
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\0\0
Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages REG_MULTI_SZ scecli\0\0
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
p2psvc REG_MULTI_SZ p2psvc\0p2pimsvc\0p2pgasvc\0PNRPSvc\0\0
********************************************************************
catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-04-17 15:09:40
C:\ComboFix-quarantined-files.txt ... 07-04-17 15:09
_________________________________________________________________
HJT
_______
Logfile of HijackThis v1.99.1
Scan saved at 3:15:19 PM, on 4/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\Prevx1\PXAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\Prevx1\PXConsole.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\LiveUpdate\LiveUpdate.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\Program Files\HijackThis\Scanner.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
https://wc.floridacitizensbank.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\Scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {E43495CB-C08D-42C6-B8A5-68E0F9FC1E1A} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - HKLM\..\Run: [AVGCtrl] "C:\Program Files\AVPersonal\AVGNT.EXE" /min
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [PrevxOne] "C:\Program Files\Prevx1\PXConsole.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [BTCLiveUpdate] "C:\Program Files\LiveUpdate\LiveUpdate.exe" /autostart
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) -
http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8300.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) -
http://a19.g.akamai.net/7/19/7125/4058/ftp.coupons.com/r3302/UnileverAll/Coupons.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: iifeb - C:\WINDOWS\
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files\McAfee\Common Framework\FrameworkService.exe" /ServiceStart (file missing)
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx1\PXAgent.exe" -f (file missing)