I ran Combo, ATF Cleaner, and Spybot.
Combo log
"Owner" - 2007-05-14 23:44:46 Service Pack 2
ComboFix 07-05.11.5V - Running from: "C:\Documents and Settings\Owner\Desktop\INSTALLS\kingston add ons\"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\C\DOCUME~1
C:\qoobox\purity\C\DOCUME~1\Owner
C:\qoobox\purity\C\DOCUME~1\Owner\APPLIC~1
C:\qoobox\purity\C\DOCUME~1\Owner\MYDOCU~1
C:\qoobox\purity\C\DOCUME~1\Owner\APPLIC~1\SCURIT~1
C:\qoobox\purity\C\DOCUME~1\Owner\MYDOCU~1\SCURIT~1
C:\qoobox\purity\C\DOCUME~1\Owner\MYDOCU~1\YMBOLS~1
C:\qoobox\purity\C\Program Files\SSTEM3~1
C:\qoobox\purity\C\Program Files\Common Files\SEMBLY~1
C:\qoobox\purity\C\Program Files\Common Files\SKS~1
C:\qoobox\purity\C\Program Files\Common Files\YMANTE~1
C:\qoobox\purity\C\WINDOWS\SEMBLY~1
C:\qoobox\purity\C\WINDOWS\system32\DOBE~1
C:\qoobox\purity\C\WINDOWS\system32\MCROSO~1
C:\qoobox\purity\C\WINDOWS\system32\MCROSO~1.NET
C:\qoobox\purity\C\WINDOWS\system32\SEMBLY~1
C:\qoobox\purity\C\WINDOWS\system32\SSTEM3~1
C:\qoobox\purity\C\WINDOWS\system32\YMANTE~1
((((((((((((((((((((((((((((((( Files Created from 2007-04-05 to 2007-05-14 ))))))))))))))))))))))))))))))))))
2007-05-14 23:18 <DIR> d-------- C:\Program Files\Elprime Media Recovery
2007-05-13 21:19 <DIR> d-------- C:\Program Files\Hasbro Interactive
2007-05-11 18:08 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-05-11 17:45 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-05-11 16:51 <DIR> d-------- C:\Program Files\Hijack
2007-05-11 11:34 <DIR> d-------- C:\Program Files\New Folder
2007-05-11 01:23 77,824 --a------ C:\WINDOWS\system32\CDVPreviewEx.dll
2007-05-11 01:23 237,568 --a------ C:\WINDOWS\CDLaunch.exe
2007-05-11 01:23 <DIR> d-------- C:\DOCUME~1\Owner\APPLIC~1\CSOdessa
2007-05-11 01:22 <DIR> d-------- C:\Program Files\CS Odessa
2007-05-11 01:18 <DIR> d-------- C:\Program Files\SlimBrowser
2007-05-11 01:18 <DIR> d-------- C:\DOCUME~1\Owner\APPLIC~1\SlimBrowser
2007-05-11 00:19 <DIR> d-------- C:\DOCUME~1\Owner\APPLIC~1\iView
2007-05-10 23:58 <DIR> d-------- C:\Program Files\Pradis
2007-05-10 23:56 <DIR> d-------- C:\Program Files\iView Catalog Reader
2007-05-10 13:46 0 --a------ C:\WINDOWS\system32\sys_dll.dll
2007-05-10 00:14 <DIR> d-------- C:\DOCUME~1\Owner\APPLIC~1\GlarySoft
2007-05-10 00:12 <DIR> d-------- C:\Program Files\Glary Utilities
2007-05-09 23:43 <DIR> d-------- C:\Program Files\Easy RSS Content Generator
2007-05-09 18:35 <DIR> d-------- C:\DOCUME~1\LOCALS~1\APPLIC~1\elefundesktops
2007-05-09 16:23 <DIR> d-------- C:\Temp
2007-05-09 16:21 <DIR> d-------- C:\Program Files\Super Blocks
2007-05-08 00:55 <DIR> d-------- C:\Program Files\DoyleSoft
2007-05-07 14:34 <DIR> d-------- C:\Program Files\CDBurnerXP Pro 3
2007-05-07 14:21 <DIR> d-------- C:\Program Files\MesNews
2007-05-07 14:16 <DIR> d-------- C:\Program Files\InControl
2007-05-07 14:13 <DIR> d-------- C:\Program Files\Ronin Solitaire
2007-05-07 14:10 <DIR> d-------- C:\Program Files\EleFun Desktops
2007-05-07 14:07 <DIR> d-------- C:\DOCUME~1\Owner\APPLIC~1\elefundesktops
2007-05-06 17:25 <DIR> d-------- C:\Program Files\Alive Games
2007-05-06 17:25 <DIR> d-------- C:\DOCUME~1\Owner\APPLIC~1\Alive Games
2007-05-06 17:18 <DIR> d-------- C:\Program Files\Identity Knight
2007-05-06 16:00 3,840 --a------ C:\WINDOWS\system32\drivers\BANTExt.sys
2007-05-06 16:00 <DIR> d-------- C:\Program Files\Belarc
2007-05-05 18:02 4,027,840 -ra------ C:\WINDOWS\system32\drivers\ALCXWDM.SYS
2007-05-05 18:02 315,392 --a------ C:\WINDOWS\alcupd.exe
2007-05-05 18:02 217,088 --a------ C:\WINDOWS\Alcrmv.exe
2007-05-05 18:02 147,456 --a------ C:\WINDOWS\system32\RTLCPAPI.dll
2007-05-05 18:02 10,528,768 --a------ C:\WINDOWS\system32\RTLCPL.EXE
2007-05-05 18:02 <DIR> d-------- C:\Program Files\Realtek AC97
2007-05-05 17:54 69,632 --a------ C:\WINDOWS\Alcmtr.exe
2007-05-05 17:54 577,536 --a------ C:\WINDOWS\SOUNDMAN.EXE
2007-05-05 17:54 2,879,488 --a------ C:\WINDOWS\SkyTel.exe
2007-05-05 17:54 2,808,832 --a------ C:\WINDOWS\alcwzrd.exe
2007-05-05 17:54 2,157,568 --a------ C:\WINDOWS\MicCal.exe
2007-05-05 17:54 16,125,440 --a------ C:\WINDOWS\RTHDCPL.exe
2007-05-05 17:53 9,709,568 --a------ C:\WINDOWS\RTLCPL.exe
2007-05-05 17:53 49,152 --a------ C:\WINDOWS\system32\ChCfg.exe
2007-05-05 17:53 4,484,608 --a------ C:\WINDOWS\system32\drivers\RtkHDAud.sys
2007-05-05 17:53 1,191,936 --a------ C:\WINDOWS\RtlUpd.exe
2007-05-05 17:53 <DIR> d-------- C:\WINDOWS\system32\RTCOM
2007-05-05 17:53 <DIR> d-------- C:\Program Files\Realtek
2007-05-05 17:52 520,192 --a------ C:\WINDOWS\RtlExUpd.dll
2007-05-05 17:52 315,392 --a------ C:\WINDOWS\HideWin.exe
2007-05-05 17:29 <DIR> d-------- C:\swsetup
2007-05-05 16:23 75,932 --a------ C:\WINDOWS\system32\drivers\klick.dat
2007-05-05 16:23 74,396 --a------ C:\WINDOWS\system32\drivers\klin.dat
2007-05-05 16:23 5,438,752 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-05-05 16:23 115,744 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2007-05-05 16:23 <DIR> d-------- C:\Program Files\Kaspersky Lab
2007-05-05 16:23 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-05-05 16:19 <DIR> d-------- C:\KAV
2007-05-04 22:25 <DIR> d-------- C:\DOCUME~1\Owner\APPLIC~1\Leadertech
2007-05-04 22:21 <DIR> d-------- C:\Program Files\GRETECH
2007-05-04 22:14 <DIR> d-------- C:\DOCUME~1\Owner\APPLIC~1\vlc
2007-05-04 22:13 <DIR> d-------- C:\Program Files\VideoLAN
2007-05-04 21:10 75,512 --a------ C:\WINDOWS\zllsputility.exe
2007-05-04 21:10 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll
2007-05-04 21:09 1,087,216 --a------ C:\WINDOWS\system32\zpeng24.dll
2007-05-04 20:59 <DIR> d-------- C:\Program Files\IMBT
2007-05-04 20:59 <DIR> d-------- C:\DOCUME~1\Owner\APPLIC~1\IMBT
2007-05-04 20:53 <DIR> d-------- C:\Program Files\7-Zip
2007-05-04 20:47 2,301 --a------ C:\WINDOWS\mozver.dat
2007-05-04 20:47 0 --a------ C:\WINDOWS\nsreg.dat
2007-05-04 20:41 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2007-05-04 14:26 <DIR> d-------- C:\WINDOWS\system32\ZoneLabs
2007-05-04 14:25 <DIR> d-------- C:\WINDOWS\Internet Logs
2007-05-04 13:31 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-05-04 13:23 <DIR> d-------- C:\Program Files\Yahoo!
2007-05-04 13:23 <DIR> d-------- C:\Program Files\CCleaner
2007-05-04 09:45 12,288,463 --------- C:\AVG7QT.DAT
2007-05-04 09:17 636,502 -ra------ C:\WINDOWS\system32\drivers\PRISMUSB.sys
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-05-14 15:48:16 -------- d-----w C:\Program Files\Common Files\InstallShield
2007-05-11 18:53:11 -------- d-----w C:\Program Files\AIM
2007-05-11 08:22:41 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-05-10 02:24:15 25,968 ----a-w C:\DOCUME~1\Owner\APPLIC~1\GDIPFONTCACHEV1.DAT
2007-05-04 21:06:27 -------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-05-04 21:06:26 -------- d-----w C:\Program Files\Symantec
2007-05-04 20:53:45 -------- d-----w C:\Program Files\Google
2007-05-04 20:42:14 -------- d-----w C:\Program Files\The Weather Channel FW
2007-05-04 18:10:39 -------- d-----w C:\DOCUME~1\Owner\APPLIC~1\Google
2007-05-04 17:33:33 -------- d-----w C:\Program Files\Common Files\?ppPatch
2007-05-04 17:30:42 -------- d-----w C:\DOCUME~1\Owner\APPLIC~1\Lavasoft
2007-05-04 17:30:18 -------- d-----w C:\Program Files\Lavasoft
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{53707962-6F74-2D53-2644-206D7942484F}=C:\PROGRA~1\SPYBOT~1\SDHelper.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ZoneAlarm Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
"AVP"="\"C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 6.0\\avp.exe\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-09 01:02]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" [2007-01-29 23:02]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages msv1_0\
Security Packages kerberosmsv1_0schannelwdigest\
Notification Packages scecli\
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^start menu^programs^startup^adobe reader speed launch.lnk
C:\PROGRA~1\Adobe\READER~1.0\Reader\READER~1.EXE
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^start menu^programs^startup^adobe reader synchronizer.lnk
C:\PROGRA~1\Adobe\READER~1.0\Reader\ADOBEC~1.EXE
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^start menu^programs^startup^trojan guarder gold version.lnk
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^owner^start menu^programs^startup^think-adz.lnk
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^owner^start menu^programs^startup^z_start.lnk
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!avg anti-spyware
"C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\amazing3daquariumwallpaper
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt
"C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe
C:\WINDOWS\system32\ctfmon.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dropspam lifestyle
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dw4
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\elefunanimatedwallpaper
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\exploreupdsched
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hotkeyscmds
C:\WINDOWS\system32\hkcmd.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray
C:\WINDOWS\system32\igfxtray.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\imjpmig8.1
"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ituneshelper
"C:\Program Files\iTunes\iTunesHelper.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\kqqi
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxsupmon
C:\WINDOWS\system32\LXSUPMON.EXE RUN
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mspy2002
C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nerofiltercheck
C:\WINDOWS\system32\NeroCheck.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\oe_drop_spam
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\phime2002a
C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\phime2002async
C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\qdvfzp
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\quicktime task
"C:\Program Files\QuickTime\qttask.exe" -atboottime
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ruoo
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\spamblocker
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sunjavaupdatesched
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\viewmgr
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\webhancer agent
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\webhancer survey companion
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService AlerterWebClientLmHostsRemoteRegistryupnphostSSDPSRV\
NetworkService DnsCache\
rpcss RpcSs\
imgsvc StiSvc\
termsvcs TermService\
HTTPFilter HTTPFilter\
DcomLaunch DcomLaunchTermService\
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost
~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
backup-20070505-165654-118
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
backup-20070505-165653-537
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
backup-20070505-165654-389
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
backup-20070505-165653-903
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
backup-20070505-165653-999
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
backup-20070505-165652-802
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) -
http://gamedownload....GPlugin9USA.cab
backup-20070505-165652-128
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) -
http://a.download.to...0.19/ttinst.cab
backup-20070505-165651-148
O16 - DPF: {A2E05F45-F127-4092-B9F7-9A02C3E04C77} (HGPlugin7USA Class) -
http://gamedownload....GPlugin7USA.cab
backup-20070505-165651-794
O16 - DPF: {9BED3AC7-E6D4-43E7-B8A1-1FA502F639E1} (XTools Control) -
http://player.bugs.c...l/mv/XTools.cab
backup-20070505-165650-162
O16 - DPF: {85AF9A98-3423-45E4-8BAD-85645F16AC31} (P3 Bugs VoD Loader Class) -
http://player.bugs.c.../mv/p3bvset.cab
backup-20070505-165649-289
O16 - DPF: {2931566C-B8A6-46C5-BF4D-E6AB9251E953} (Nexon Package Manager Control) -
http://file.nx.com/a...ic_new/nxpm.cab
backup-20070505-165647-503
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) -
http://activation.rr...oad/tgctlcm.cab
backup-20070505-165647-476
O3 - Toolbar: (no name) - {2DEA8791-C2B7-48E1-8992-8E8E6A6FE789} - (no file)
backup-20070505-165647-288
O2 - BHO: (no name) - {A6DA9DA6-0714-7ACC-4503-57F07FCD6C9E} - C:\WINDOWS\system32\zte.dll (file missing)
backup-20070505-165647-955
R3 - URLSearchHook: (no name) - {A6DA9DA6-0714-7ACC-4503-57F07FCD6C9E} - C:\WINDOWS\system32\zte.dll (file missing)
backup-20070505-165647-175
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local.,
backup-20070505-165647-128
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Spybot - Search & Destroy - Scheduled Task.job
********************************************************************
catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-05-14 23:48:22
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 2007-05-14 23:48:34
C:\ComboFix-quarantined-files.txt ... 2007-05-14 23:48
*******************************************************************
Logfile of HijackThis v1.99.1
Scan saved at 11:51:38 PM, on 5/14/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://losangeles.craigslist.org/
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
I'm sorry about posting twice. I couldn't find my previous post. Thank you for your help.
New HJT Log