Smitfraud-C.Toolbar888
This is looking better, yeah?
ComboFix 07-06-18.2 - C:\Documents and Settings\m.somers\Desktop\ComboFix.exe
"m.somers" - 2007-06-21 13:04:40 - Service Pack 2 NTFS
(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\opomli.dll
C:\WINDOWS\system32\pmnmn.exe
C:\WINDOWS\ilmopo.ini
C:\WINDOWS\system32\ie4ery.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\M7A3D~1.SOM\APPLIC~1\tmp211.tmp.exe
C:\DOCUME~1\M7A3D~1.SOM\APPLIC~1\tmp327.tmp.exe
C:\DOCUME~1\M7A3D~1.SOM\APPLIC~1\tmp32D.tmp.exe
C:\DOCUME~1\M7A3D~1.SOM\APPLIC~1\tmp344.tmp.exe
C:\DOCUME~1\M7A3D~1.SOM\APPLIC~1\tmp347.tmp.exe
C:\DOCUME~1\M7A3D~1.SOM\APPLIC~1\tmp3B3.tmp.exe
C:\DOCUME~1\M7A3D~1.SOM\APPLIC~1\tmp576.tmp.exe
C:\DOCUME~1\M7A3D~1.SOM\APPLIC~1\tmp66.tmp.exe
C:\DOCUME~1\M7A3D~1.SOM\APPLIC~1\tmp9899.tmp.exe
C:\DOCUME~1\M7A3D~1.SOM\APPLIC~1\tmp9904.tmp.exe
C:\DOCUME~1\M7A3D~1.SOM\APPLIC~1\tmpB6.tmp.exe
((((((((((((((((((((((((( Files Created from 2007-05-21 to 2007-06-21 )))))))))))))))))))))))))))))))
2007-06-21 12:58 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-06-20 19:42 <DIR> d-------- C:\VundoFix Backups
2007-06-17 10:15 <DIR> d-------- C:\Program Files\ahead
2007-06-17 09:46 5,248 --a------ C:\WINDOWS\system32\drivers\a347scsi.sys
2007-06-17 09:46 160,640 --a------ C:\WINDOWS\system32\drivers\a347bus.sys
2007-06-17 09:45 <DIR> d-------- C:\Program Files\Alcohol Soft
2007-06-16 14:14 <DIR> d-------- C:\Program Files\ieSpell
2007-06-11 14:29 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-06-11 07:54 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2007-06-10 07:33 <DIR> d-------- C:\Program Files\EA SPORTS
2007-06-05 19:27 512,096 --a------ C:\WINDOWS\system32\drivers\amon.sys
2007-06-05 19:27 298,104 --a------ C:\WINDOWS\system32\imon.dll
2007-06-05 19:27 15,424 --a------ C:\WINDOWS\system32\drivers\nod32drv.sys
2007-06-04 00:04 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-06-02 18:54 <DIR> d-------- C:\Program Files\CCleaner
2007-06-02 18:49 <DIR> d-------- C:\Program Files\AusLogics Registry Defrag
2007-06-02 18:23 <DIR> d-------- C:\Program Files\Yahoo!
2007-06-02 08:59 82,432 --a------ C:\WINDOWS\system32\msxml4r.dll
2007-06-02 08:58 516,784 -ra------ C:\WINDOWS\system32\XceedCry.dll
2007-06-02 08:58 44,544 --a------ C:\WINDOWS\system32\Gif89.dll
2007-06-02 08:58 118,784 --a------ C:\WINDOWS\system32\DartWeb.dll
2007-06-01 11:53 89,360 --a------ C:\WINDOWS\system32\VB5DB.DLL
2007-05-31 12:16 696,320 --a------ C:\WINDOWS\system32\libeay32.dll
2007-05-31 12:16 155,648 --a------ C:\WINDOWS\system32\ssleay32.dll
2007-05-31 12:15 73,915 --a------ C:\WINDOWS\system32\mfc45.dll
2007-05-31 12:11 <DIR> d-------- C:\DOCUME~1\M7A3D~1.SOM\APPLIC~1\iolo
2007-05-31 12:11 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\iolo
2007-05-30 13:30 <DIR> d-------- C:\LimeWire
2007-05-27 09:26 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Seagate
2007-05-27 09:25 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\MSN6
2007-05-27 07:45 <DIR> d-------- C:\DOCUME~1\M7A3D~1.SOM\APPLIC~1\MSN6
2007-05-25 22:52 215,144 -ra------ C:\WINDOWS\patchw32.A445.dll
2007-05-25 22:48 215,144 -ra------ C:\WINDOWS\pw32a0.dll
2007-05-25 19:49 10,344 --a------ C:\WINDOWS\system32\drivers\symlcbrd.sys
2007-05-21 22:17 392,320 --a------ C:\WINDOWS\system32\drivers\timntr.sys
2007-05-21 22:17 32,768 --a------ C:\WINDOWS\system32\drivers\tifsfilt.sys
2007-05-21 22:17 120,992 --a------ C:\WINDOWS\system32\drivers\snapman.sys
2007-05-21 22:13 <DIR> d-------- C:\Program Files\Seagate
2007-05-21 22:13 <DIR> d-------- C:\Program Files\Common Files\Seagate
2007-05-21 22:04 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-05-21 19:59 <DIR> d-------- C:\Program Files\DIY DataRecovery CHK-Mate
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-06-21 11:09:07 -------- d-----w C:\Program Files\SpywareBlaster
2007-06-11 08:04:18 -------- d-----w C:\Program Files\Windows Live Toolbar
2007-06-11 08:01:52 -------- d-----w C:\Program Files\MSN Messenger
2007-06-11 08:01:06 -------- d-----w C:\Program Files\Messenger
2007-06-11 07:55:10 -------- d-----w C:\Program Files\iTunes
2007-06-09 18:52:05 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-06-07 17:48:06 92,672 ----a-w C:\WINDOWS\system32\wlnotify.dll
2007-06-05 18:07:26 -------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-06-03 00:57:23 -------- d-----w C:\DOCUME~1\M7A3D~1.SOM\APPLIC~1\LimeWire
2007-06-02 07:54:42 -------- d-----w C:\Program Files\Common Files\InstallShield
2007-05-28 10:22:14 -------- d-----w C:\DOCUME~1\M7A3D~1.SOM\APPLIC~1\AdobeUM
2007-05-26 13:36:50 -------- d-----w C:\Program Files\Common Files\Ahead
2007-05-18 11:38:39 -------- d-----w C:\Program Files\PowerQuest
2007-05-17 16:36:55 -------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-19 20:30:10 14,368 ----a-w C:\WINDOWS\system32\relog_ap.dll
2007-04-19 19:07:20 17,440 ----a-w C:\WINDOWS\system32\acrotls.dll
2007-04-19 17:49:14 210,464 ----a-w C:\WINDOWS\system32\snapapi.dll
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-03-26 13:41:20 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2007-03-26 13:41:20 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{53707962-6F74-2D53-2644-206D7942484F}=C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2005-05-31 09:04]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43]
{9030D464-4C02-4ABF-8ECC-5164760863C6}=C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2006-07-07 12:29]
{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}=C:\Program Files\Windows Live Toolbar\msntb.dll [2007-02-12 15:56]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsmqIntCert"="regsvr32 /s mqrt.dll" []
"QuickTime Task"="C:\Program Files\K-Lite Codec Pack\QuickTime\qttask.exe" [2006-07-01 15:24]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 23:46]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-06-14 16:24]
"DiscWizardMonitor.exe"="C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe" [2007-04-19 21:24]
"AcronisTimounterMonitor"="C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe" [2007-04-19 21:38]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe" [2007-04-19 21:29]
"NWEReboot"="" []
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-06-05 19:25]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-15 15:51]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 17:24]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:56]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2007-05-30 13:29]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=c:\windows\system32\pmnnnnn.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages msv1_0 relog_ap
Notification Packages scecli scecli scecli
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b8e48664-0d13-11db-8b55-8648012f51fc}]
AutoRun\command- H:\setuppro.EXE /AUTORUN
configure\command- H:\setuppro.EXE
install\command- H:\setuppro.EXE
Contents of the 'Scheduled Tasks' folder
2007-06-21 12:00:04 C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
**************************************************************************
catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-06-21 13:29:49
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
Completion time: 2007-06-21 13:34:41 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-06-21 13:34
--- E O F ---
Logfile of HijackThis v1.99.1
Scan saved at 1:44:51 PM, on 6/21/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\K-Lite Codec Pack\QuickTime\qttask.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe
C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.skybroadband.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page =
http://www.skybroadband.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\K-Lite Codec Pack\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DiscWizardMonitor.exe] C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://H:\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-gb\msntabres.dll.mui/229?602a5a17c8444bebb5ee23f1749d40f6
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-gb\msntabres.dll.mui/230?602a5a17c8444bebb5ee23f1749d40f6
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Sky - {08E730A4-FB02-45BD-A900-01E4AD8016F6} -
http://www.skybroadband.com (file missing)
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1150058547516
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1150396229950
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) -
http://www.ca.com/us/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E2EDBB82-9450-4AE3-9354-F46650F75425}: NameServer = 192.168.0.1
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: c:\windows\system32\pmnnnnn.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
Not had a popup since being on line

: