Thanks for the help. Here are the logs, as requested:
ComboFix 09-09-02.02 - Administrator 03/09/2009 3:49.4.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2014.1549 [GMT -4:00]
Running from: c:\documents and settings\Administrator\Desktop\Combo-Fix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrator\Application Data\inst.exe
c:\windows\system\SysMFS.dll
.
((((((((((((((((((((((((( Files Created from 2009-08-03 to 2009-09-03 )))))))))))))))))))))))))))))))
.
2009-09-03 07:40 . 2009-09-03 07:40 -------- d-----w- c:\windows\LastGood
2009-08-30 06:35 . 2009-08-30 06:40 -------- d-----w- c:\program files\Save Flash
2009-08-30 06:02 . 2009-08-30 17:39 -------- d-----w- c:\program files\NOS
2009-08-30 03:30 . 2009-08-30 03:30 -------- d-----w- C:\My Videos
2009-08-30 03:30 . 2009-08-30 03:30 -------- d-----w- c:\documents and settings\Administrator\Application Data\aHisoft
2009-08-30 02:56 . 2009-08-30 02:56 -------- d-----w- c:\program files\Belarc
2009-08-30 02:56 . 2008-03-06 15:51 3840 ----a-w- c:\windows\system32\drivers\BANTExt.sys
2009-08-22 04:43 . 2009-09-03 07:40 -------- d-----w- c:\program files\Windows Live Safety Center
2009-08-13 14:43 . 2006-06-19 17:01 69632 ----a-w- c:\windows\system32\ztvcabinet.dll
2009-08-13 14:43 . 2006-05-25 19:52 162304 ----a-w- c:\windows\system32\ztvunrar36.dll
2009-08-13 14:43 . 2005-08-26 05:50 77312 ----a-w- c:\windows\system32\ztvunace26.dll
2009-08-13 14:43 . 2003-02-03 00:06 153088 ----a-w- c:\windows\system32\unrar3.dll
2009-08-13 14:43 . 2002-03-06 05:00 75264 ----a-w- c:\windows\system32\unacev2.dll
2009-08-12 22:38 . 2009-03-30 14:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-08-12 22:38 . 2009-02-13 16:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-08-12 22:38 . 2009-02-13 16:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-08-12 22:38 . 2009-08-12 22:38 -------- d-----w- c:\program files\Avira
2009-08-12 22:38 . 2009-08-12 22:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-08-12 04:10 . 2009-08-12 04:10 -------- d-----w- c:\program files\Alwil Software
2009-08-12 04:09 . 2009-08-12 04:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-12 04:09 . 2009-08-12 04:11 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-12 03:54 . 2009-08-13 01:28 -------- d-----w- c:\program files\Panda Security
2009-08-12 01:27 . 2006-11-10 19:05 18688 ----a-w- c:\windows\system32\drivers\afc.sys
2009-08-12 01:27 . 2005-04-27 20:36 245408 ----a-w- c:\windows\system32\unicows.dll
2009-08-12 01:26 . 2009-08-12 01:27 -------- d-----w- c:\program files\Common Files\ArcSoft
2009-08-12 01:26 . 2009-08-12 01:26 -------- d-----w- c:\program files\ArcSoft
2009-08-12 01:26 . 2009-08-12 01:28 -------- d-----w- c:\documents and settings\Administrator\Application Data\ArcSoft
2009-08-11 21:44 . 2009-08-11 21:44 -------- d-----w- c:\program files\AVG
2009-08-11 19:50 . 2008-05-19 16:26 102664 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2009-08-11 06:05 . 2009-08-11 06:05 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-08-11 01:24 . 2009-08-13 01:28 -------- d-----w- c:\windows\system32\The Legend of Zelda Phantom Hourglass dir
2009-08-11 01:07 . 2009-08-11 01:09 606848 ----a-w- c:\windows\flashax.exe
2009-08-11 01:07 . 2009-08-11 01:09 12288 ----a-w- c:\windows\impborl.dll
2009-08-10 16:36 . 2009-08-10 16:37 -------- d-----w- c:\program files\Autoplay Repair
2009-08-09 19:09 . 2009-08-09 19:09 -------- d-----w- c:\program files\FreeTime
2009-08-09 18:06 . 2009-08-09 18:06 -------- d-----w- c:\windows\system32\wbem\Repository
2009-08-09 18:06 . 2009-08-09 18:13 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-08 00:47 . 2009-08-09 18:06 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware(2)
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-03 06:54 . 2008-03-13 07:56 -------- d-----w- c:\program files\Mozilla Thunderbird
2009-09-01 07:03 . 2007-11-18 02:56 -------- d-----w- c:\documents and settings\Administrator\Application Data\BitTorrent
2009-08-31 19:40 . 2008-11-25 17:46 -------- d-----w- c:\documents and settings\Administrator\Application Data\vlc
2009-08-30 17:39 . 2008-09-29 07:05 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-08-30 06:49 . 2007-11-15 08:11 -------- d-----w- c:\documents and settings\Administrator\Application Data\U3
2009-08-30 03:21 . 2009-06-17 01:41 -------- d-----w- c:\program files\Common Files\Real
2009-08-23 16:16 . 2009-06-25 02:21 -------- d-----w- c:\program files\Last.fm
2009-08-13 23:52 . 2007-11-06 21:24 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-08-13 14:46 . 2008-10-18 21:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-08-13 04:55 . 2009-07-30 20:25 -------- d-----w- c:\program files\DVDFab 6
2009-08-13 04:55 . 2007-11-19 18:57 -------- d-----w- c:\documents and settings\Administrator\Application Data\Vso
2009-08-13 04:55 . 2007-12-30 04:18 47360 ----a-w- c:\documents and settings\Administrator\Application Data\pcouffin.sys
2009-08-13 04:55 . 2007-11-01 00:01 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2009-08-12 22:40 . 2009-05-01 09:28 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-08-12 01:28 . 2007-10-27 04:34 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-12 01:28 . 2009-08-12 01:28 -------- d-----w- c:\documents and settings\All Users\Application Data\ArcSoft
2009-08-12 01:07 . 2009-05-29 12:52 -------- d-----w- c:\program files\Lavasoft
2009-08-12 01:07 . 2007-10-28 14:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-08-12 01:07 . 2008-06-24 17:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Avg8
2009-08-09 18:13 . 2008-07-20 07:49 -------- d-----w- c:\program files\Java
2009-08-05 09:01 . 2004-08-04 01:56 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-03 17:36 . 2008-07-19 20:00 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 17:36 . 2008-06-24 08:20 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-01 03:56 . 2007-12-11 22:01 -------- d-----w- c:\documents and settings\Administrator\Application Data\Image Zone Express
2009-07-25 09:23 . 2008-11-22 05:25 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-24 16:03 . 2009-07-24 16:03 -------- d-----w- c:\program files\Microsoft
2009-07-24 16:03 . 2009-07-24 16:02 -------- d-----w- c:\program files\Windows Live
2009-07-24 16:03 . 2009-07-24 16:03 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-07-17 19:01 . 2004-08-04 01:56 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 03:43 . 2007-07-22 13:19 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-08 09:18 . 2009-07-06 04:57 -------- d-----w- c:\program files\Common Files\DVDRect
2009-07-08 05:09 . 2009-03-20 23:11 -------- d-----w- c:\documents and settings\Administrator\Application Data\Winamp
2009-07-08 04:14 . 2009-07-08 04:14 -------- d-----w- c:\program files\Common Files\Windows Live
2009-07-03 17:09 . 2007-07-22 13:17 915456 ----a-w- c:\windows\system32\wininet.dll
2009-06-16 14:36 . 2007-07-22 13:31 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2007-07-22 13:16 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-12 12:31 . 2004-08-04 01:56 80896 ----a-w- c:\windows\system32\tlntsess.exe
2009-06-12 12:31 . 2005-05-11 01:51 76288 ----a-w- c:\windows\system32\telnet.exe
2009-06-10 14:13 . 2004-08-04 01:56 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 13:19 . 2007-10-26 19:59 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:14 . 2007-07-22 13:17 132096 ----a-w- c:\windows\system32\wkssvc.dll
2007-02-01 22:02 . 2009-05-07 08:03 313344 ----a-w- c:\program files\hjsplit.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-01-24 7311360]
"zBrowser Launcher"="c:\program files\Logitech\iTouch\iTouch.exe" [2004-03-18 892928]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"WinampAgent"="d:\winamp\winampa.exe" [2009-07-01 37888]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2009-07-10 195072]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"Tweak UI"="TWEAKUI.CPL" - c:\windows\system32\TWEAKUI.CPL [2000-06-18 106544]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-01-24 1519616]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-12-15 282624]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0aswBoot.exe /A:* /L:English /KBD:2
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Orb Networks\\Orb\\bin\\Orb.exe"=
"c:\\Program Files\\Orb Networks\\Orb\\bin\\OrbTray.exe"=
"c:\\Program Files\\Orb Networks\\Orb\\bin\\OrbStreamerClient.exe"=
"c:\\Program Files\\Orb Networks\\Orb\\bin\\xmltv.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Realtime Converter\\R7C.exe"=
"c:\\Program Files\\Mozilla Thunderbird\\thunderbird.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [12/08/2009 06:38 PM 108289]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-08-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3bomyhzo.default\
FF - prefs.js: browser.startup.homepage - www.yahoo.com
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\OpenOffice.org 3\program\npsoplugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-09-03 03:55
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1708537768-1303643608-725345543-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,a8,1a,7a,1c,71,b3,0b,41,ac,ae,d4,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,a8,1a,7a,1c,71,b3,0b,41,ac,ae,d4,\
.
Completion time: 2009-09-03 3:57
ComboFix-quarantined-files.txt 2009-09-03 07:56
Pre-Run: 48,058,871,808 bytes free
Post-Run: 47,947,558,912 bytes free
194 --- E O F --- 2009-09-01 08:59
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 03:59:29 AM, on 03/09/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
D:\Winamp\winampa.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
D:\Winamp\winamp.exe
C:\Program Files\Last.fm\LastFM.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Downloaded Program Files\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://go.microsoft.com/fwlink/?LinkId=74005R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [WinampAgent] D:\Winamp\winampa.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) -
http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cabO16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) -
http://tools.ebayimg.com/eps/wl/activex/eB...l_v1-0-3-48.cabO16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cabO16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} -
http://download.eset.com/special/eos/OnlineScanner.cabO16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) -
http://download.mcafee.com/molbin/iss-loc/...323/mcfscan.cabO23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
--
End of file - 7391 bytes