First of all, thank you for taking the time to help out people like myself. I'm a first time poster so if I make any mistakes, please bare with me and point them out so that I won't make them again.
First of all, I'm running on Windows XP Pro SP2. I'm unable to connect to the internet and this virus has disabled my firewall and antiviruses. I believe I got the virus when I visited a website that suddenly grinded my computer to a slow snail and it suddenly installed d1.exe, d2.exe, d3.exe, d4.exe to my desktop. I then proceeded to reset my computer before it do anymore damage.
I've done some analysis myself and I believe I have the nuwar.N!sys Virus. My computer restarts every single time I try to run any antivirus software where or visit any site that has any scanning. I was lucky one time and I sent an error report to Microsoft and it said I had the nuwar.N!sys virus.
A couple of times when I restarted, it gave me the blue screen of death with the following info:
Driver_IRQL_not_less_or_equal
STOP 0x000.....
NDIS.sys error
I then preceeded to run in safe mode with networking but upon loading the networking "d347.bus", my computer would restart as well. So I ran in safe mode without networking and skipped the loading of d347.bus and it ran fine. I downloaded the AVG Anti spyware program from another computer and ran the scanner. Here is the log it produced :
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 6:57:42 PM 4/14/2007
+ Scan result:
C:\Program Files\Overnet\Plugins\httpprotocol.dll -> Downloader.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\wincom32.sys -> Dropper.Agent.bbv : Cleaned with backup (quarantined).
C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\8FTF2G3Z\d5[1].exe -> Dropper.Agent.bdy : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT 000061.EXE -> Dropper.Agent.bdy : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-484763869-706699826-682003330-1003\Dc1.exe -> Dropper.Agent.bdy : Cleaned with backup (quarantined).
C:\Program Files\eDonkey2000\URL2FILE.exe -> Not-A-Virus.Downloader.Win32.Url2File.a : Cleaned with backup (quarantined).
C:\Program Files\eDonkey2000\server.met_autoupdater_by_maurice_-_version_3.0_-_core.zip/URL2FILE.exe -> Not-A-Virus.Downloader.Win32.Url2File.a : Cleaned with backup (quarantined).
C:\Documents and Settings\user\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-3da4390a-13539c24.zip/Dummy.class -> Not-A-Virus.Exploit.ByteVerify : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\windev-1a33-45b0.sys -> Not-A-Virus.SpamTool.Win32.Agent.af : Cleaned with backup (quarantined).
C:\WINDOWS\comdlg64.dll -> Proxy.Agent.jk : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WinOpts -> Proxy.Small : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT 000062.sys -> Rootkit.Agent.dn : Cleaned with backup (quarantined).
C:\Documents and Settings\user\Cookies\user@247realmedia[2].txt -> TrackingCookie.247realmedia : Cleaned.
C:\Documents and Settings\user\Cookies\user@oasc06006.247realmedia[2].txt -> TrackingCookie.247realmedia : Cleaned.
C:\Documents and Settings\user\Cookies\user@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\user\Cookies\user@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\user\Cookies\user@axa.addcontrol[1].txt -> TrackingCookie.Addcontrol : Cleaned.
C:\Documents and Settings\user\Cookies\user@ads.addynamix[2].txt -> TrackingCookie.Addynamix : Cleaned.
C:\Documents and Settings\user\Cookies\user@ad.adition[2].txt -> TrackingCookie.Adition : Cleaned.
C:\Documents and Settings\user\Cookies\user@rotator.its.adjuggler[2].txt -> TrackingCookie.Adjuggler : Cleaned.
C:\Documents and Settings\user\Cookies\user@ad.admarketplace[1].txt -> TrackingCookie.Admarketplace : Cleaned.
C:\Documents and Settings\user\Cookies\user@admarketplace[1].txt -> TrackingCookie.Admarketplace : Cleaned.
C:\Documents and Settings\user\Cookies\user@admarketplace[3].txt -> TrackingCookie.Admarketplace : Cleaned.
C:\Documents and Settings\user\Local Settings\Temp\Cookies\user@admarketplace[2].txt -> TrackingCookie.Admarketplace : Cleaned.
C:\Documents and Settings\user\Cookies\user@www.adobe[2].txt -> TrackingCookie.Adobe : Cleaned.
C:\Documents and Settings\user\Cookies\user@adrevolver[2].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\user\Cookies\user@media.adrevolver[2].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\user\Cookies\user@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\user\Cookies\user@citi.bridgetrack[2].txt -> TrackingCookie.Bridgetrack : Cleaned.
C:\Documents and Settings\user\Cookies\user@text.burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\user\Cookies\user@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\user\Cookies\user@ad1.clickhype[1].txt -> TrackingCookie.Clickhype : Cleaned.
C:\Documents and Settings\user\Cookies\user@ad1.clickhype[2].txt -> TrackingCookie.Clickhype : Cleaned.
C:\Documents and Settings\user\Cookies\user@cz6.clickzs[2].txt -> TrackingCookie.Clickzs : Cleaned.
C:\Documents and Settings\user\Cookies\user@ads.cnn[1].txt -> TrackingCookie.Cnn : Cleaned.
C:\Documents and Settings\user\Cookies\user@ads.cnn[3].txt -> TrackingCookie.Cnn : Cleaned.
C:\Documents and Settings\user\Cookies\user@ads.com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\user\Cookies\user@com[2].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\user\Cookies\user@com[3].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\user\Cookies\user@com[4].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\user\Cookies\user@news.com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\user\Local Settings\Temp\Cookies\user@com[2].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\user\Cookies\user@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\user\Cookies\user@dealtime[1].txt -> TrackingCookie.Dealtime : Cleaned.
C:\Documents and Settings\user\Cookies\user@c.enhance[2].txt -> TrackingCookie.Enhance : Cleaned.
C:\Documents and Settings\user\Cookies\user@estat[1].txt -> TrackingCookie.Estat : Cleaned.
C:\Documents and Settings\user\Cookies\user@www.etracker[1].txt -> TrackingCookie.Etracker : Cleaned.
C:\Documents and Settings\user\Cookies\user@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\user\Cookies\user@as-eu.falkag[2].txt -> TrackingCookie.Falkag : Cleaned.
C:\Documents and Settings\user\Cookies\user@as-us.falkag[2].txt -> TrackingCookie.Falkag : Cleaned.
C:\Documents and Settings\user\Cookies\user@as1.falkag[2].txt -> TrackingCookie.Falkag : Cleaned.
C:\Documents and Settings\user\Cookies\user@fortunecity[1].txt -> TrackingCookie.Fortunecity : Cleaned.
C:\Documents and Settings\user\Cookies\user@ads.gamershell[1].txt -> TrackingCookie.Gamershell : Cleaned.
C:\Documents and Settings\user\Cookies\user@gamershell[2].txt -> TrackingCookie.Gamershell : Cleaned.
C:\Documents and Settings\user\Cookies\user@www.gamershell[1].txt -> TrackingCookie.Gamershell : Cleaned.
C:\Documents and Settings\user\Cookies\user@hit.gemius[1].txt -> TrackingCookie.Gemius : Cleaned.
C:\Documents and Settings\user\Cookies\user@hit.gemius[2].txt -> TrackingCookie.Gemius : Cleaned.
C:\Documents and Settings\user\Cookies\user@hotlog[1].txt -> TrackingCookie.Hotlog : Cleaned.
C:\Documents and Settings\user\Cookies\user@hypertracker[1].txt -> TrackingCookie.Hypertracker : Cleaned.
C:\Documents and Settings\user\Cookies\user@ads.infinite-ads[2].txt -> TrackingCookie.Infinite-ads : Cleaned.
C:\Documents and Settings\user\Cookies\user@searchportal.information[2].txt -> TrackingCookie.Information : Cleaned.
C:\Documents and Settings\user\Cookies\user@intelli-direct[1].txt -> TrackingCookie.Intelli-direct : Cleaned.
C:\Documents and Settings\user\Cookies\user@intelli-direct[2].txt -> TrackingCookie.Intelli-direct : Cleaned.
C:\Documents and Settings\user\Cookies\user@intelli-direct[3].txt -> TrackingCookie.Intelli-direct : Cleaned.
C:\Documents and Settings\user\Cookies\user@ilead.itrack[2].txt -> TrackingCookie.Itrack : Cleaned.
C:\Documents and Settings\user\Cookies\user@komtrack[2].txt -> TrackingCookie.Komtrack : Cleaned.
C:\Documents and Settings\user\Cookies\user@search.live[2].txt -> TrackingCookie.Live : Cleaned.
C:\Documents and Settings\user\Cookies\user@sales.liveperson[1].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\user\Cookies\user@image.masterstats[1].txt -> TrackingCookie.Masterstats : Cleaned.
C:\Documents and Settings\user\Cookies\user@image.masterstats[2].txt -> TrackingCookie.Masterstats : Cleaned.
C:\Documents and Settings\user\Local Settings\Temp\Cookies\user@image.masterstats[1].txt -> TrackingCookie.Masterstats : Cleaned.
C:\Documents and Settings\user\Cookies\user@search.msn[1].txt -> TrackingCookie.Msn : Cleaned.
C:\Documents and Settings\user\Cookies\user@search.msn[2].txt -> TrackingCookie.Msn : Cleaned.
C:\Documents and Settings\user\Cookies\user@search.msn[3].txt -> TrackingCookie.Msn : Cleaned.
C:\Documents and Settings\user\Cookies\user@search.msn[4].txt -> TrackingCookie.Msn : Cleaned.
C:\Documents and Settings\user\Local Settings\Temp\Cookies\user@search.msn[2].txt -> TrackingCookie.Msn : Cleaned.
C:\Documents and Settings\user\Cookies\user@www.myaffiliateprogram[1].txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
C:\Documents and Settings\user\Cookies\user@www.myaffiliateprogram[3].txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
C:\Documents and Settings\user\Cookies\user@ssl-hints.netflame[1].txt -> TrackingCookie.Netflame : Cleaned.
C:\Documents and Settings\user\Cookies\user@ssl-hints.netflame[2].txt -> TrackingCookie.Netflame : Cleaned.
C:\Documents and Settings\user\Cookies\user@ssl-hints.netflame[4].txt -> TrackingCookie.Netflame : Cleaned.
C:\Documents and Settings\user\Cookies\user@diepress.oewabox[1].txt -> TrackingCookie.Oewabox : Cleaned.
C:\Documents and Settings\user\Cookies\user@data2.perf.overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\user\Cookies\user@data3.perf.overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\user\Cookies\user@data4.perf.overture[2].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\user\Cookies\user@perf.overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\user\Local Settings\Temp\Cookies\user@data2.perf.overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\user\Cookies\user@www.paypal[1].txt -> TrackingCookie.Paypal : Cleaned.
C:\Documents and Settings\user\Cookies\user@ads.planetactive[1].txt -> TrackingCookie.Planetactive : Cleaned.
C:\Documents and Settings\user\Cookies\user@ads.pointroll[1].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\user\Cookies\user@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\user\Cookies\user@ads.realcastmedia[2].txt -> TrackingCookie.Realcastmedia : Cleaned.
C:\Documents and Settings\user\Cookies\user@revenue[2].txt -> TrackingCookie.Revenue : Cleaned.
C:\Documents and Settings\user\Cookies\user@revsci[2].txt -> TrackingCookie.Revsci : Cleaned.
C:\Documents and Settings\user\Cookies\user@bs.serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\user\Cookies\user@serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\user\Cookies\user@adopt.specificclick[1].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\user\Cookies\user@adopt.specificclick[2].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\user\Cookies\user@adopt.specificclick[3].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\user\Cookies\user@adopt.specificclick[4].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\user\Cookies\user@specificclick[2].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\user\Cookies\user@spylog[2].txt -> TrackingCookie.Spylog : Cleaned.
C:\Documents and Settings\user\Cookies\user@h.starware[1].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\user\Cookies\user@starware[2].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\user\Cookies\user@statcounter[2].txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\user\Cookies\user@anad.tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\user\Cookies\user@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\user\Cookies\user@ad.text.tbn[1].txt -> TrackingCookie.Texttbnru : Cleaned.
C:\Documents and Settings\user\Cookies\user@toplist[2].txt -> TrackingCookie.Toplist : Cleaned.
C:\Documents and Settings\user\Cookies\user@toplist[3].txt -> TrackingCookie.Toplist : Cleaned.
C:\Documents and Settings\user\Cookies\user@login.tracking101[2].txt -> TrackingCookie.Tracking101 : Cleaned.
C:\Documents and Settings\user\Cookies\user@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : Cleaned.
C:\Documents and Settings\user\Cookies\user@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\user\Cookies\user@reduxads.valuead[2].txt -> TrackingCookie.Valuead : Cleaned.
C:\Documents and Settings\user\Cookies\user@ezzs.valueclick[1].txt -> TrackingCookie.Valueclick : Cleaned.
C:\Documents and Settings\user\Cookies\user@valueclick[1].txt -> TrackingCookie.Valueclick : Cleaned.
C:\Documents and Settings\user\Local Settings\Temp\Cookies\user@www.web-stat[1].txt -> TrackingCookie.Web-stat : Cleaned.
C:\Documents and Settings\user\Cookies\user@yadro[1].txt -> TrackingCookie.Yadro : Cleaned.
C:\Documents and Settings\user\Cookies\user@yadro[2].txt -> TrackingCookie.Yadro : Cleaned.
C:\Documents and Settings\user\Cookies\user@yadro[3].txt -> TrackingCookie.Yadro : Cleaned.
C:\Documents and Settings\user\Cookies\user@yadro[4].txt -> TrackingCookie.Yadro : Cleaned.
C:\Documents and Settings\user\Cookies\user@yadro[5].txt -> TrackingCookie.Yadro : Cleaned.
C:\Documents and Settings\user\Cookies\user@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\user\Cookies\user@yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\user\Cookies\user@yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\user\Local Settings\Temp\Cookies\user@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\user\Cookies\user@zedo[2].txt -> TrackingCookie.Zedo : Cleaned.
C:\Cracks\rpftpv90.zip/aaocg_ftpvoyager_crk.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\sblwjsnte.dll -> Trojan.Vqten : Cleaned with backup (quarantined).
C:\Program Files\AIM95\icbmft.ocm -> Worm.AimVen : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\rsvp32_2.dll -> Worm.Zhelatin.al : Cleaned with backup (quarantined).
[476] C:\WINDOWS\system32\rsvp32_2.dll -> Worm.Zhelatin.al : Cleaned with backup (quarantined).
[664] C:\WINDOWS\system32\rsvp32_2.dll -> Worm.Zhelatin.al : Cleaned with backup (quarantined).
C:\Documents and Settings\user\Local Settings\Temp\d3.exe -> Worm.Zhelatin.cs : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\spoolsvv.exe -> Worm.Zhelatin.cs : Cleaned with backup (quarantined).
::Report end
Unfortunately, I forgot to disable system restore before running it. I proceeded to go back in Windows XP normally and my internet would not work at all. I restarted my computer again and I found myself at the blue screen of death again, with the same error message and I got back the exact same symtoms of restarting everytime i tried to run scan in non-safe mode. I then ran HijackThis in safe mode again with the following log:
Logfile of HijackThis v1.99.1
Scan saved at 10:52:45 AM, on 4/15/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Windows\Explorer.exe
C:\HijackThis\HijackThis.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRAM FILES\FLASHGET\JCCATCH.DLL
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [PopUpKiller] C:\Program Files\PopUp Killer\PopUpKiller.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\System32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Start GetRight.lnk = C:\Program Files\GetRight\GETRIGHT.EXE
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Download with GetRight - C:\PROGRA~1\GETRIGHT\GRdownload.htm
O8 - Extra context menu item: Open with GetRight Browser - C:\PROGRA~1\GETRIGHT\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES12031.DLL
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES12031.DLL
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM95\AIM.EXE
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRAM FILES\FLASHGET\JETCAR.EXE
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRAM FILES\FLASHGET\JETCAR.EXE
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'rsvp32_2.dll' missing
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .csm: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .csml: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .cub: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .cube: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .dx: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .emb: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .embl: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .gau: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .jdx: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .mol: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .mop: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .pdb: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .rxn: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .scr: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .skc: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .spt: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .tgf: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .xyz: C:\Program Files\Internet Explorer\Plugins\npchime.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros....?1120209053671
O16 - DPF: {68253470-5D4F-4CDF-8D9C-353C14A2F013} (SVPorsche Control) - http://seevideo.co.k...3/svporsche.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros....?1160072345984
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn....o.cab34246.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://zone.msn.com/....ploader_v6.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: mszsrn32 - C:\WINDOWS\system32\mszsrn32.dll
O20 - Winlogon Notify: rpcc - C:\WINDOWS\system32\rpcc.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~4\GHOSTS~2.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~2\NPROTECT.EXE
O23 - Service: RadClock - Unknown owner - C:\WINDOWS\system32\RadClock.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~2\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Sorry for the long post. I'm afraid to do anything else right now and I hope I can leave it to you professionals for help. Thanks a lot for the help and hopefully we'll be able to resolve this soon.