Hello pskelley, thanks a lot for repply, also helpful information.
i did everything what you said, here are three logs:
SDFix LOGS
SDFix: Version 1.99
Run by Administrator on Thu 08/23/2007 at 08:48 AM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Name:
DomainService
ImagePath:
C:\WINDOWS\System32\qwerty12.exe /service
DomainService - Deleted
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Trojan Files Found:
C:\WINDOWS\SYSTEM32\EFCDB.EXE - Deleted
C:\WINDOWS\system32\tmp25.tmp.dll - Deleted
C:\WINDOWS\system32\tmp42.tmp.dll - Deleted
C:\WINDOWS\system32\tmp62.tmp.dll - Deleted
C:\WINDOWS\system32\system\klog.dat - Deleted
C:\WINDOWS\system32\qwerty12.exe - Deleted
Folder C:\WINDOWS\system32\system - Removed
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
Remaining Services:
------------------
Authorized Application Key Export:
Remaining Files:
---------------
File Backups: - C:\SDFix\backups\backups.zip
Registry Backups: - C:\SDFix\backups\backupreg.zip
Full Registry Backup: - C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
Files with Hidden Attributes:
C:\WINDOWS\system32\9A3D4FBA8E.sys
C:\WINDOWS\LastGood.Tmp\INF\oem10.inf
C:\WINDOWS\LastGood.Tmp\INF\oem10.PNF
C:\WINDOWS\LastGood.Tmp\INF\oem11.inf
C:\WINDOWS\LastGood.Tmp\INF\oem11.PNF
C:\WINDOWS\LastGood.Tmp\INF\oem9.inf
C:\WINDOWS\LastGood.Tmp\INF\oem9.PNF
Finished
ComboFIX LOGS
ComboFix 07-08-17.2 - "Albano" 2007-08-23 9:05:42.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.1.1252.1.1033.18.26 [GMT 2:00]
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\Albano\APPLIC~1\addon.dat
C:\DOCUME~1\Albano\APPLIC~1\tmp1.tmp.exe
C:\DOCUME~1\Albano\APPLIC~1\tmp10.tmp.exe
C:\DOCUME~1\Albano\APPLIC~1\tmp2.tmp.exe
C:\DOCUME~1\Albano\APPLIC~1\tmp3F.tmp.exe
C:\DOCUME~1\Albano\APPLIC~1\tmp40.tmp.exe
C:\DOCUME~1\Albano\APPLIC~1\tmp42.tmp.exe
C:\DOCUME~1\Albano\APPLIC~1\tmpF.tmp.exe
C:\WINDOWS\qpprtv.ini
C:\WINDOWS\system32\dn985ca620.dat
C:\WINDOWS\system32\memut8.dll
C:\WINDOWS\system32\mljgh.exe
C:\WINDOWS\system32\rqrss.exe
C:\WINDOWS\vtrppq.dll
((((((((((((((((((((((((( Files Created from 2007-07-23 to 2007-08-23 )))))))))))))))))))))))))))))))
2007-08-23 09:03 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-23 08:46 <DIR> d-------- C:\WINDOWS\ERUNT
2007-08-22 08:42 <DIR> d-------- C:\Program Files\Trend Micro
2007-08-20 13:20 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
2007-08-20 12:34 <DIR> d-------- C:\Program Files\MSN Messenger
2007-08-20 12:04 <DIR> d-------- C:\DOCUME~1\Albano\Contacts
2007-08-20 12:03 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-08-19 18:37 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-08-18 14:33 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-08-18 01:26 272,896 --a------ C:\WINDOWS\system32\kerberos.dll
2007-08-18 01:20 1,129,472 --a------ C:\WINDOWS\system32\msxml3.dll
2007-08-18 01:14 95,232 --a------ C:\WINDOWS\system32\6to4svc.dll
2007-08-18 01:14 83,456 --a------ C:\WINDOWS\system32\netsh.exe
2007-08-18 01:14 70,656 --a------ C:\WINDOWS\system32\ws2_32.dll
2007-08-18 01:14 54,272 --a------ C:\WINDOWS\system32\ipv6mon.dll
2007-08-18 01:14 48,640 --a------ C:\WINDOWS\system32\ipv6.exe
2007-08-18 01:14 31,232 --a------ C:\WINDOWS\system32\inetmib1.dll
2007-08-18 01:14 203,008 --a------ C:\WINDOWS\system32\drivers\tcpip6.sys
2007-08-18 01:14 159,232 --a------ C:\WINDOWS\system32\xpob2res.dll
2007-08-18 01:14 13,312 --a------ C:\WINDOWS\system32\wship6.dll
2007-08-18 01:14 11,776 --a------ C:\WINDOWS\system32\drivers\tunmp.sys
2007-08-18 01:08 322,048 --a------ C:\WINDOWS\system32\drivers\srv.sys
2007-08-18 00:56 61,952 --a------ C:\WINDOWS\system32\webclnt.dll
2007-08-18 00:56 172,672 --a------ C:\WINDOWS\system32\drivers\mrxdav.sys
2007-08-18 00:39 115,976 --a------ C:\WINDOWS\system32\drivers\rdpwd.sys
2007-08-18 00:28 1,797,120 --a------ C:\WINDOWS\system32\win32k.sys
2007-08-18 00:23 233,984 --a------ C:\WINDOWS\system32\tapisrv.dll
2007-08-18 00:16 87,552 --a------ C:\WINDOWS\system32\polstore.dll
2007-08-18 00:16 57,984 --a------ C:\WINDOWS\system32\drivers\ipsec.sys
2007-08-18 00:16 364,032 --a------ C:\WINDOWS\system32\ipsmsnap.dll
2007-08-18 00:16 332,800 --a------ C:\WINDOWS\system32\ipsecsnp.dll
2007-08-18 00:16 328,704 --a------ C:\WINDOWS\system32\oakley.dll
2007-08-18 00:16 25,600 --a------ C:\WINDOWS\system32\winipsec.dll
2007-08-18 00:16 155,648 --a------ C:\WINDOWS\system32\ipsecsvc.dll
2007-08-18 00:05 99,328 --a------ C:\WINDOWS\system32\win32spl.dll
2007-08-18 00:05 51,200 --a------ C:\WINDOWS\system32\spoolsv.exe
2007-08-17 23:31 1,018,368 --a------ C:\WINDOWS\system32\esent.dll
2007-08-17 23:15 68,608 --a------ C:\WINDOWS\system32\olecli32.dll
2007-08-17 23:15 64,512 --a------ C:\WINDOWS\system32\colbact.dll
2007-08-17 23:15 594,944 --a------ C:\WINDOWS\system32\catsrvut.dll
2007-08-17 23:15 499,712 --a------ C:\WINDOWS\system32\clbcatq.dll
2007-08-17 23:15 35,328 --a------ C:\WINDOWS\system32\olecnv32.dll
2007-08-17 23:15 284,672 --a------ C:\WINDOWS\system32\rpcss.dll
2007-08-17 23:15 226,816 --a------ C:\WINDOWS\system32\es.dll
2007-08-17 23:15 225,280 --a------ C:\WINDOWS\system32\catsrv.dll
2007-08-17 23:15 1,258,496 --a------ C:\WINDOWS\system32\ole32.dll
2007-08-17 23:15 1,194,496 --a------ C:\WINDOWS\system32\comsvcs.dll
2007-08-17 22:57 200,064 --a------ C:\WINDOWS\system32\drivers\rmcast.sys
2007-08-17 22:39 154,112 --a------ C:\WINDOWS\system32\netman.dll
2007-08-17 22:35 332,928 --a------ C:\WINDOWS\system32\drivers\tcpip.sys
2007-08-17 22:28 68,096 --a------ C:\WINDOWS\system32\mscms.dll
2007-08-17 22:15 557,056 --a------ C:\WINDOWS\system32\comctl32.dll
2007-08-17 21:48 277,504 --a------ C:\WINDOWS\system32\winsrv.dll
2007-08-17 21:48 15,872 --a------ C:\WINDOWS\system32\linkinfo.dll
2007-08-17 21:39 257,536 --a------ C:\WINDOWS\system32\gdi32.dll
2007-08-17 21:11 594,432 --a------ C:\WINDOWS\system32\xpsp2res.dll
2007-08-17 20:59 107,008 --a------ C:\WINDOWS\system32\umpnpmgr.dll
2007-08-17 20:46 64,512 --a------ C:\WINDOWS\system32\mtxclu.dll
2007-08-17 10:35 <DIR> d-------- C:\Program Files\Symantec
2007-08-17 10:34 <DIR> d-------- C:\Program Files\Symantec AntiVirus
2007-08-17 10:34 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2007-08-16 19:06 440,064 --a------ C:\WINDOWS\system32\drivers\mrxsmb.sys
2007-08-16 19:06 170,112 --a------ C:\WINDOWS\system32\drivers\rdbss.sys
2007-08-16 13:20 884,736 --a------ C:\WINDOWS\system32\msimsg.dll
2007-08-16 13:20 77,312 --a------ C:\WINDOWS\system32\msiexec.exe
2007-08-16 13:20 44,032 --a------ C:\WINDOWS\system32\msisip.dll
2007-08-16 13:20 331,264 --a------ C:\WINDOWS\system32\msihnd.dll
2007-08-16 13:20 2,797,056 --a------ C:\WINDOWS\system32\msi.dll
2007-08-16 13:16 <DIR> d-------- C:\WINDOWS\system32\PreInstall
2007-08-16 11:56 <DIR> d-------- C:\WINDOWS\system32\SoftwareDistribution
2007-08-16 11:21 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee
2007-08-16 11:20 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com
2007-08-16 10:34 524,288 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-08-16 09:43 76,560 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2007-08-15 09:23 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Prevx
2007-08-15 09:22 77,312 --a------ C:\WINDOWS\ua2.dll
2007-08-14 13:30 28,672 --a------ C:\WINDOWS\system32\drivers\CO_Mon.sys
2007-08-12 14:54 <DIR> d-------- C:\Program Files\Cyberlink
2007-08-04 20:13 8,704 --a------ C:\WINDOWS\system32\kbdjpn.dll
2007-08-04 20:13 8,192 --a------ C:\WINDOWS\system32\kbdkor.dll
2007-08-04 20:13 6,144 --a------ C:\WINDOWS\system32\kbd106.dll
2007-08-04 20:13 6,144 --a------ C:\WINDOWS\system32\kbd101c.dll
2007-08-04 20:13 6,144 --a------ C:\WINDOWS\system32\kbd101b.dll
2007-08-04 20:13 5,632 --a------ C:\WINDOWS\system32\kbd103.dll
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-22 10:28 --------- d-------- C:\Program Files\Google
2007-08-21 08:37 --------- d-------- C:\DOCUME~1\Albano\APPLIC~1\Google
2007-08-12 14:55 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-07-25 15:55 --------- d-------- C:\DOCUME~1\Albano\APPLIC~1\Real
2007-07-19 09:13 --------- d-------- C:\Program Files\Chopper XP
2004-11-27 16:43:20 152 -csh--r C:\WINDOWS\system32\9A3D4FBA8E.sys
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{85589B5D-D53D-4237-A677-46B82EA275F3}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-20 13:18]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"=Narrator.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"EditLevel"=0 (0x0)
"NoClose"=0 (0x0)
"NoFileMenu"=0 (0x0)
"NoCommonGroups"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\acctop]
acctop.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=C:\WINDOWS\pss\Google Updater.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^LG SyncManager.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\LG SyncManager.lnk
backup=C:\WINDOWS\pss\LG SyncManager.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eMuleAutoStart]
D:\Program Files\eMule\emule.exe -AutoStart
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
C:\PowerDVD\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MOD]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PrevxOne]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RavTimeXP]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
C:\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\STYLEXP]
C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Synchronization Manager]
%SystemRoot%\system32\mobsync.exe /logon
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemOptimizer]
rundll32.exe "C:\WINDOWS\vtrppq.dll",forkonce
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WatchDog]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
R0 ppa;Iomega Parallel Port Filter Driver;C:\WINDOWS\System32\DRIVERS\ppa.sys
R3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver;C:\WINDOWS\System32\DRIVERS\fetnd5.sys
R3 G200;G200;C:\WINDOWS\System32\DRIVERS\G200m.sys
S3 iteio;iteio;\??\C:\WINDOWS\System32\drivers\iteio.sys
S3 U81xbus;LGE U8XXX driver (WDM);C:\WINDOWS\System32\DRIVERS\U81xbus.sys
S3 U81xmdfl;LGE U8XXX USB WMC Modem Filter;C:\WINDOWS\System32\DRIVERS\U81xmdfl.sys
S3 U81xmdm;LGE U8XXX USB WMC Modem Driver;C:\WINDOWS\System32\DRIVERS\U81xmdm.sys
S3 U81xmgmt;LGE U8XXX USB WMC Device Management Drivers (WDM);C:\WINDOWS\System32\DRIVERS\U81xmgmt.sys
S3 U81xobex;LGE U8XXX USB WMC OBEX Interface;C:\WINDOWS\System32\DRIVERS\U81xobex.sys
Contents of the 'Scheduled Tasks' folder
2007-08-22 22:00:00 C:\WINDOWS\Tasks\At1.job - C:\WINDOWS\System32\H06s36DU.exe
2007-08-23 07:00:01 C:\WINDOWS\Tasks\At10.job - C:\WINDOWS\System32\H06s36DU.exe
2007-08-22 08:00:03 C:\WINDOWS\Tasks\At11.job
2007-08-22 09:00:01 C:\WINDOWS\Tasks\At12.job - C:\WINDOWS\System32\H06s36DU.exe
2007-08-22 10:00:04 C:\WINDOWS\Tasks\At13.job - C:\WINDOWS\System32\H06s36DU.exe
2007-08-22 11:00:01 C:\WINDOWS\Tasks\At14.job - C:\WINDOWS\System32\H06s36DU.exe
2007-08-21 12:00:02 C:\WINDOWS\Tasks\At15.job - C:\WINDOWS\System32\H06s36DU.exe
2007-08-18 13:00:05 C:\WINDOWS\Tasks\At16.job
2007-08-18 14:00:04 C:\WINDOWS\Tasks\At17.job - C:\WINDOWS\System32\H06s36DU.exe
2007-08-18 15:00:03 C:\WINDOWS\Tasks\At18.job - C:\WINDOWS\System32\H06s36DU.exe
2007-08-21 16:00:00 C:\WINDOWS\Tasks\At19.job
2007-08-22 23:00:00 C:\WINDOWS\Tasks\At2.job - C:\WINDOWS\System32\H06s36DU.exe
2007-08-21 17:00:01 C:\WINDOWS\Tasks\At20.job - C:\WINDOWS\System32\H06s36DU.exe
2007-08-22 18:00:00 C:\WINDOWS\Tasks\At21.job - C:\WINDOWS\System32\H06s36DU.exe
2007-08-22 19:00:00 C:\WINDOWS\Tasks\At22.job - C:\WINDOWS\System32\H06s36DU.exe
2007-08-22 20:00:00 C:\WINDOWS\Tasks\At23.job - C:\WINDOWS\System32\H06s36DU.exe
2007-08-22 21:00:00 C:\WINDOWS\Tasks\At24.job - C:\WINDOWS\System32\H06s36DU.exe
2007-08-23 00:00:00 C:\WINDOWS\Tasks\At3.job
2007-08-23 01:00:00 C:\WINDOWS\Tasks\At4.job - C:\WINDOWS\System32\H06s36DU.exe
2007-08-23 02:00:00 C:\WINDOWS\Tasks\At5.job - C:\WINDOWS\System32\H06s36DU.exe
2007-08-23 03:00:00 C:\WINDOWS\Tasks\At6.job - C:\WINDOWS\System32\H06s36DU.exe
2007-08-23 04:00:00 C:\WINDOWS\Tasks\At7.job
2007-08-23 05:00:00 C:\WINDOWS\Tasks\At8.job - C:\WINDOWS\System32\H06s36DU.exe
2007-08-23 06:00:00 C:\WINDOWS\Tasks\At9.job
2006-03-26 10:12:21 C:\WINDOWS\Tasks\UPS System Shutdown Program.job
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-08-23 09:12:46
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-08-23 9:16:04 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-08-23 09:15
--- E O F ---
Hijackthis LOGS
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:19:17 AM, on 8/23/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Cyberlink\Shared files\RichVideo.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Hijackthis\HiJackThis.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: WebAssist - {85589B5D-D53D-4237-A677-46B82EA275F3} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O20 - Winlogon Notify: acctop - acctop.dll (file missing)
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx2\PXAgent.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\Cyberlink\Shared files\RichVideo.exe
--
End of file - 2828 bytes