combofix log:
ComboFix 09-01-17.04 - Jeanette 2009-01-18 11:38:28.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.511.267 [GMT -5:00]
Running from: c:\documents and settings\Jeanette\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1296 [VPS 090115-0] *On-access scanning disabled* (Updated)
AV: Norton 360 *On-access scanning disabled* (Outdated)
FW: Norton 360 *disabled*
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\Jeanette\Application Data\gadcom
c:\documents and settings\Jeanette\Application Data\GetModule
c:\documents and settings\Jeanette\Application Data\GetModule\dicik.gz
c:\documents and settings\Jeanette\Application Data\GetModule\kwdik.gz
c:\documents and settings\Jeanette\Application Data\GetModule\ofadik.gz
c:\documents and settings\Jeanette\Application Data\Microsoft\Internet Explorer\Quick Launch\XP Antivirus 2008.lnk
c:\documents and settings\Jeanette\Application Data\SpeedRunner
c:\documents and settings\Jeanette\Application Data\SpeedRunner\config.cfg
c:\documents and settings\Jeanette\Local Settings\Temporary Internet Files\fbk.sts
c:\documents and settings\Jeanette\Start Menu\XP Antivirus 2008
c:\documents and settings\Wayland Henderson\Local Settings\Temporary Internet Files\CPV.stt
c:\program files\Antivirus 2009
c:\program files\GetModule
c:\program files\GetPack
c:\program files\GetPack\dictame.gz
c:\program files\GetPack\GetPack26.exe
c:\program files\GetPack\trgtame.gz
c:\program files\GrandPack
c:\program files\GrandPack\GrandPack.dll
c:\program files\GrandPack\GrandPack2.dll
c:\program files\GrandPack\qdrloader.exe
c:\program files\GrandPack\Uninstall.exe
c:\program files\iCheck
c:\program files\iCheck\Uninstall.exe
c:\program files\inetget2
c:\program files\Mjcore
c:\program files\Mjcore\Mjcore.dll
c:\program files\XP Antivirus
c:\windows\system32\aqlmitnm.ini
c:\windows\system32\brqbixbp.ini
c:\windows\system32\cknotsfm.ini
c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\CPV.stt
c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\fbk.sts
c:\windows\system32\fgtmbyws.ini
c:\windows\system32\fkvavkgs.dll
c:\windows\system32\hopsao.dll
c:\windows\system32\iubldf.dll
c:\windows\system32\NUCbdccf.ini
c:\windows\system32\NUCbdccf.ini2
c:\windows\system32\pbxibqrb.dll
c:\windows\system32\TDSSosvd.dat
c:\windows\system32\TDSStkdv.log
c:\windows\system32\tiyxheoo.dll
c:\windows\system32\tpulexcb.ini
c:\windows\system32\vhsfujwi.dll
c:\windows\system32\winsrc.dll.tmp
c:\windows\system32\wpv571228549770.cpx
c:\windows\system32\wpv761228550018.cpx
c:\windows\Temp\tmp3.tmp
----- BITS: Possible infected sites -----
hxxp://childhe.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_TDSSSERV.SYS
-------\Service_TDSSserv.sys
((((((((((((((((((((((((( Files Created from 2008-12-18 to 2009-01-18 )))))))))))))))))))))))))))))))
.
2009-01-18 11:51 . 2009-01-18 11:51 <DIR> d-------- c:\windows\LastGood
2009-01-18 11:17 . 2009-01-18 11:17 <DIR> d-------- c:\documents and settings\Jeanette\Application Data\Malwarebytes
2009-01-17 13:18 . 2009-01-17 13:18 <DIR> d-------- c:\program files\AVG
2009-01-17 13:18 . 2009-01-17 14:55 <DIR> d-------- c:\documents and settings\All Users\Application Data\avg8
2009-01-12 21:38 . 2009-01-17 14:55 <DIR> d-------- c:\documents and settings\Administrator
2009-01-12 21:07 . 2009-01-12 21:07 <DIR> d-------- C:\VundoFix Backups
2009-01-12 11:12 . 2009-01-18 11:16 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2009-01-12 10:20 . 2009-01-12 10:20 <DIR> d-------- c:\program files\Alwil Software
2009-01-12 10:14 . 2009-01-18 11:17 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-12 09:59 . 2009-01-12 09:59 0 --a------ c:\windows\nsreg.dat
2009-01-12 09:54 . 2009-01-12 10:10 <DIR> d-------- c:\program files\CCleaner
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-18 04:45 --------- d-----w c:\program files\e-Sword
2009-01-17 20:33 --------- d-----w c:\documents and settings\Jeanette\Application Data\Twain
2009-01-17 19:05 --------- d-----w c:\program files\Webtools
2009-01-12 07:39 --------- d-----w c:\program files\Common Files\Symantec Shared
2009-01-12 07:36 --------- d-----w c:\program files\Symantec
2009-01-12 07:34 --------- d-----w c:\program files\Google
2009-01-12 07:28 --------- d-----w c:\documents and settings\Jeanette\Application Data\Skype
2009-01-12 07:11 --------- d-----w c:\documents and settings\Jeanette\Application Data\skypePM
2008-12-10 03:19 --------- d-----w c:\program files\PCPitstop
2008-12-10 03:05 --------- d-----w c:\documents and settings\All Users\Application Data\McAfee
2008-12-10 02:44 --------- d-----w c:\documents and settings\Wayland Henderson\Application Data\Symantec
2008-12-10 02:26 --------- d-----w c:\documents and settings\Jeanette\Application Data\Symantec
2008-12-10 02:18 --------- d-----w c:\program files\Norton 360
2008-12-09 04:55 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2008-12-09 04:48 805 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2008-12-09 04:48 123,952 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2008-12-09 04:48 10,563 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2008-12-09 04:41 --------- d-----w c:\program files\Windows Sidebar
2008-12-06 22:10 --------- d-----w c:\windows\system32\config\systemprofile\Application Data\gadcom
2008-12-06 22:08 --------- d-----w c:\windows\system32\config\systemprofile\Application Data\GetModule
2008-12-06 22:03 --------- d-----w c:\documents and settings\LocalService\Application Data\SACore
2008-04-10 02:39 32 ----a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2009-01-12 15:19 211,456 ----a-w c:\program files\mozilla firefox\components\srff.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayExcluded]
@="{4433A54A-1AC8-432F-90FC-85F045CF383C}"
[HKEY_CLASSES_ROOT\CLSID\{4433A54A-1AC8-432F-90FC-85F045CF383C}]
2008-02-26 03:34 576352 --a------ c:\program files\Common Files\Symantec Shared\Backup\buShell.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayPending]
@="{F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225}"
[HKEY_CLASSES_ROOT\CLSID\{F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225}]
2008-02-26 03:34 576352 --a------ c:\program files\Common Files\Symantec Shared\Backup\buShell.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayProtected]
@="{476D0EA3-80F9-48B5-B70B-05E677C9C148}"
[HKEY_CLASSES_ROOT\CLSID\{476D0EA3-80F9-48B5-B70B-05E677C9C148}]
2008-02-26 03:34 576352 --a------ c:\program files\Common Files\Symantec Shared\Backup\buShell.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"L06AXLRD_5439771"="c:\program files\Microsoft Student\Microsoft Student 2006 DVD\EDICT.EXE" [2005-06-03 301776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-10-26 4632576]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring]
2004-01-13 18:17 110592 c:\windows\system32\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-12 01:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
--a------ 2008-11-26 12:18 81000 c:\progra~1\ALWILS~1\Avast4\ashDisp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
--a------ 2008-02-18 14:37 51048 c:\program files\Common Files\Symantec Shared\ccApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-02-19 16:10 267048 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\L06AXLRD_1024062]
--a------ 2005-06-03 12:30 301776 c:\program files\Microsoft Student\Microsoft Student 2006 DVD\EDICT.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\L06AXLRD_1480348]
--a------ 2005-06-03 12:30 301776 c:\program files\Microsoft Student\Microsoft Student 2006 DVD\EDICT.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 11:24 1694208 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2004-10-26 15:01 4632576 c:\windows\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\osCheck]
--a------ 2008-02-26 09:50 988512 c:\program files\Norton 360\osCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Pitstop Optimize Scheduler]
--a------ 2006-10-27 16:03 1696768 c:\program files\PCPitstop\Optimize\PCPOptimize.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PRONoMgr.exe]
--a------ 2003-12-19 15:49 86016 c:\program files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-02-01 02:13 385024 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 2008-02-01 19:22 21898024 c:\program files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
--a------ 2003-08-29 08:59 122880 c:\windows\BCMSMMSG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2004-10-26 15:01 921600 c:\windows\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wscsvc"=2 (0x2)
"Symantec Core LC"=3 (0x3)
"LiveUpdate Notice"=2 (0x2)
"CLTNetCnService"=2 (0x2)
"ccSetMgr"=2 (0x2)
"ccEvtMgr"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-01-18 111184]
R4 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-01-18 20560]
S4 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\ccSvcHst.exe [2008-02-18 149352]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
2008-03-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 17:57]
.
- - - - ORPHANS REMOVED - - - -
BHO-{3358215f-9daa-4702-88e0-80630243e391} - c:\windows\system32\iubldf.dll
BHO-{A85ADAA5-63E9-434B-A2EC-6B11746A6A91} - c:\windows\system32\fccdbCUN.dll
MSConfigStartUp-24057398831746543157152611474847 - c:\program files\Antivirus 2009\av2009.exe
MSConfigStartUp-CAVRID - c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
MSConfigStartUp-cctray - c:\program files\CA\CA Internet Security Suite\casc.exe
MSConfigStartUp-e©ùýùæûïÞóÎÇøøñøôÖÊýÆñûÇÞó - c:\program files\XP Antivirus\xpa.exe
MSConfigStartUp-GetModule30 - c:\program files\GetModule\GetModule30.exe
MSConfigStartUp-GetModule31 - c:\program files\GetModule\GetModule31.exe
MSConfigStartUp-GetPack26 - c:\program files\GetPack\GetPack26.exe
MSConfigStartUp-ieupdate - c:\windows\system32\explorer32.exe
MSConfigStartUp-SfKg6wIP - c:\documents and settings\Jeanette\Application Data\Microsoft\Windows\mhphwk.exe
MSConfigStartUp-SpeedRunner - c:\documents and settings\Jeanette\Application Data\SpeedRunner\SpeedRunner.exe
MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
MSConfigStartUp-Twain - c:\documents and settings\Jeanette\Application Data\Twain\Twain.exe
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Jeanette\Application Data\Mozilla\Firefox\Profiles\wng63hxl.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\program files\Mozilla Firefox\components\srff.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-18 11:59:06
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(912)
c:\windows\System32\LgNotify.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\S24EvMon.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\RegSrvc.exe
c:\windows\system32\ZCfgSvc.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\1XConfig.exe
.
**************************************************************************
.
Completion time: 2009-01-18 12:01:38 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-18 17:01:31
Pre-Run: 26,368,684,032 bytes free
Post-Run: 26,410,446,848 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
262 --- E O F --- 2008-11-17 21:16:02
hjt log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:03:16 PM, on 1/18/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\1XConfig.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft Student\Microsoft Student 2006 DVD\EDICT.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\msiexec.exe
C:\Documents and Settings\Jeanette\Desktop\jeff\shrek.exe
C:\WINDOWS\SoftwareDistribution\Download\ab02de9444a68e46b9d94dbc7903bc14\update\update.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O3 - Toolbar: Encarta Web Companion - {147D6308-0614-4112-89B1-31402F9B82C4} - C:\Program Files\Common Files\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [L06AXLRD_5439771] "C:\Program Files\Microsoft Student\Microsoft Student 2006 DVD\EDICT.EXE" -m
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
--
End of file - 4718 bytes