ComboFix 07-11-19.3 - Administrator 2007-11-23 19:21:29.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1254.1.1033.18.1596 [GMT 2:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix-1.exe
Command switches used :: C:\Documents and Settings\Administrator\Desktop\CFScript.txt
* Created a new restore point
FILE
C:\Documents and Settings\Administrator\5012.bat
C:\Documents and Settings\Administrator\8553.bat
C:\Documents and Settings\Administrator\8941.bat
C:\Documents and Settings\Administrator\winlogo.exe
C:\WINDOWS\system32\bhxvmyld.exe
C:\WINDOWS\system32\derrymtt.dll
C:\WINDOWS\system32\diaosdrx.ini
C:\WINDOWS\system32\ersvsvfx.exe
C:\WINDOWS\system32\fbeixnns.ini
C:\WINDOWS\system32\guticybl.ini
C:\WINDOWS\system32\hivqofgr.exe
C:\WINDOWS\system32\kcdeaxul.ini
C:\WINDOWS\system32\lcenqiat.ini
C:\WINDOWS\system32\mbxpbokk.ini
C:\WINDOWS\system32\mbxpbokk.tmp
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mfdbccoa.ini
C:\WINDOWS\system32\msykklfy.exe
C:\WINDOWS\system32\nhvodbjp.ini
C:\WINDOWS\system32\outdordx.ini
C:\WINDOWS\system32\qokshgsw.ini
C:\WINDOWS\system32\qrdvcsoc.ini
C:\WINDOWS\system32\rewgomud.ini
C:\WINDOWS\system32\sqhuueou.ini
C:\WINDOWS\system32\suquuljk.ini
C:\WINDOWS\system32\syvqjqxt.dll
C:\WINDOWS\system32\tlcstxrc.exe
C:\WINDOWS\system32\uramwlyt.ini
C:\WINDOWS\system32\vndekxsv.ini
C:\WINDOWS\system32\vuusclby.dll
C:\WINDOWS\system32\xdrodtuo.dll
C:\WINDOWS\system32\xfjchfla.ini
C:\WINDOWS\system32\yblcsuuv.ini
C:\WINDOWS\tsitra1000137.exe
C:\WINDOWS\tsitra1000140.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Administrator\5012.bat
C:\Documents and Settings\Administrator\8553.bat
C:\Documents and Settings\Administrator\8941.bat
C:\Documents and Settings\Administrator\winlogo.exe
C:\VundoFix Backups
C:\VundoFix Backups\addmorefiles.txt
C:\VundoFix Backups\bmvmgdds.dll.bad
C:\VundoFix Backups\cspxtvmn.dll.bad
C:\VundoFix Backups\cspxtvmn.dllbox.bad
C:\VundoFix Backups\urqommm.dll.bad
C:\WINDOWS\system32\bhxvmyld.exe
C:\WINDOWS\system32\derrymtt.dll
C:\WINDOWS\system32\diaosdrx.ini
C:\WINDOWS\system32\ersvsvfx.exe
C:\WINDOWS\system32\fbeixnns.ini
C:\WINDOWS\system32\guticybl.ini
C:\WINDOWS\system32\hivqofgr.exe
C:\WINDOWS\system32\kcdeaxul.ini
C:\WINDOWS\system32\lcenqiat.ini
C:\WINDOWS\system32\mbxpbokk.ini
C:\WINDOWS\system32\mbxpbokk.tmp
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mfdbccoa.ini
C:\WINDOWS\system32\msykklfy.exe
C:\WINDOWS\system32\nhvodbjp.ini
C:\WINDOWS\system32\outdordx.ini
C:\WINDOWS\system32\qokshgsw.ini
C:\WINDOWS\system32\qrdvcsoc.ini
C:\WINDOWS\system32\rewgomud.ini
C:\WINDOWS\system32\sqhuueou.ini
C:\WINDOWS\system32\suquuljk.ini
C:\WINDOWS\system32\syvqjqxt.dll
C:\WINDOWS\system32\tlcstxrc.exe
C:\WINDOWS\system32\uramwlyt.ini
C:\WINDOWS\system32\vndekxsv.ini
C:\WINDOWS\system32\vuusclby.dll
C:\WINDOWS\system32\xdrodtuo.dll
C:\WINDOWS\system32\xfjchfla.ini
C:\WINDOWS\system32\yblcsuuv.ini
C:\WINDOWS\tsitra1000137.exe
C:\WINDOWS\tsitra1000140.exe
.
((((((((((((((((((((((((( Files Created from 2007-10-23 to 2007-11-23 )))))))))))))))))))))))))))))))
.
2007-11-13 20:44 <DIR> d-------- C:\Documents and Settings\Administrator\DoctorWeb
2007-11-13 11:03 218,112 --a------ C:\Program Files\scanner.exe
2007-11-06 00:37 52 --a------ C:\WINDOWS\system\ACD2.CMD
2007-11-06 00:37 52 --a------ C:\WINDOWS\system\ACD.CMD
2007-10-26 19:50 <DIR> d--hs---- C:\Documents and Settings\Administrator\Complete
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-22 13:15 --------- d-----w C:\Program Files\MSN Messenger
2007-11-14 20:55 7,709 ----a-w C:\Program Files\hijackthis.log
2007-11-13 09:11 --------- d-----w C:\Program Files\Java
2007-11-13 09:00 17 ----a-w C:\Program Files\s_t_i_n_g_e_r.opt
2007-11-09 10:36 --------- d-----w C:\Program Files\Ad-Aware SE Personal
2007-11-04 00:04 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Creative
2007-11-03 23:52 --------- d-----w C:\Program Files\GetRight
2007-10-28 18:29 --------- d-----w C:\Program Files\PokerStars
2007-10-27 17:23 --------- d-----w C:\Program Files\LimeWire
2007-10-14 11:50 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Bioshock
2007-10-14 11:02 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-10 16:18 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Skype
2007-10-06 14:48 --------- d-----w C:\Documents and Settings\Administrator\Application Data\funkitron
2007-10-06 14:44 --------- d-----w C:\Program Files\ReflexiveArcade
2007-10-06 14:44 --------- d-----w C:\Program Files\Poker Superstars II
2007-09-24 19:56 48,928 ----a-w C:\WINDOWS\system32\drivers\Tetris.sys
2007-09-24 19:47 162,432 ----a-w C:\WINDOWS\system32\drivers\ithsgt.sys
2007-09-24 19:47 12,032 ----a-w C:\WINDOWS\system32\drivers\lilsgt.sys
2007-09-23 13:41 --------- d-----w C:\Program Files\Google
2006-09-25 10:45 24,192 ----a-w C:\Documents and Settings\Administrator\usbsermptxp.sys
2006-09-25 10:45 22,768 ----a-w C:\Documents and Settings\Administrator\usbsermpt.sys
2005-11-06 01:03 1,232,903 ----a-w C:\Program Files\s_t_i_n_g_e_r.exe
2002-10-26 14:21 245,248 ----a-w C:\Program Files\AutostartExplorer.exe
.
((((((((((((((((((((((((((((( snapshot@2007-11-13_20.38.32.67 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-10-29 16:56:19 136,192 ----a-w C:\WINDOWS\catchme.exe
+ 2007-11-08 14:59:01 136,704 ----a-w C:\WINDOWS\catchme.exe
- 2006-12-19 21:52:18 8,453,632 -c--a-w C:\WINDOWS\system32\dllcache\shell32.dll
+ 2007-10-26 03:36:51 8,454,656 -c--a-w C:\WINDOWS\system32\dllcache\shell32.dll
- 2007-09-28 05:19:39 18,089,592 ----a-w C:\WINDOWS\system32\MRT.exe
+ 2007-11-02 07:12:57 18,238,072 ----a-w C:\WINDOWS\system32\MRT.exe
- 2006-12-19 21:52:18 8,453,632 ----a-w C:\WINDOWS\system32\shell32.dll
+ 2007-10-26 03:36:51 8,454,656 ----a-w C:\WINDOWS\system32\shell32.dll
- 2007-08-21 10:20:02 115,712 ----a-w C:\WINDOWS\system32\xpsp3res.dll
+ 2007-10-29 10:26:53 115,712 ----a-w C:\WINDOWS\system32\xpsp3res.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" [2005-01-19 14:49]
"Start WingMan Profiler"="" []
"Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 17:23]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-11 11:50 C:\WINDOWS\LOGI_MWX.EXE]
"DAEMON Tools-1033"="C:\Program Files\Daemon\daemon.exe" [2004-08-22 16:05]
"CTHelper"="CTHELPER.EXE" [2003-08-28 10:45 C:\WINDOWS\system32\CTHELPER.EXE]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 00:00]
"Jet Detection"="C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe" [2001-11-29 00:00]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-03 23:56 C:\WINDOWS\system32\rundll32.exe]
"nwiz"="nwiz.exe" [2007-09-17 00:07 C:\WINDOWS\system32\nwiz.exe]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-06-16 05:03]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-06-16 05:03]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47]
"nod32kui"="C:\Program Files\NOD32\nod32kui.exe" [2007-05-20 13:42]
"nod32upd"="C:\Program Files\NOD32\fc_upd.dll" [2007-05-26 20:52]
"NvMediaCenter"="RUNDLL32.exe" [2004-08-03 23:56 C:\WINDOWS\system32\rundll32.exe]
"cc7b536c"="C:\WINDOWS\system32\vuusclby.dll" []
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-03 23:56]
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 20:24:54]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
AirTies ADSL Hizmet Program.lnk - C:\Program Files\AirTies\ADSL Hizmet Program\AirTies_util3.exe [2006-05-03 19:44:20]
Lexibase Express.lnk - C:\Program Files\Collins\exe\L-Express.exe [2007-03-06 20:10:47]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWindowsUpdate"= 0 (0x0)
"NoRecentDocsMenu"= 0 (0x0)
"NoFavoritesMenu"= 0 (0x0)
"NoSMMyPictures"= 1 (0x1)
"NoStartMenuMyMusic"= 1 (0x1)
"NoRecentDocsHistory"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"NoInstrumentation"= 1 (0x1)
"NoSimpleStartMenu"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsMenu"= 0 (0x0)
"NoFavoritesMenu"= 0 (0x0)
"NoSMMyPictures"= 1 (0x1)
"NoStartMenuMyMusic"= 1 (0x1)
"NoRecentDocsHistory]"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"NoUserNameInStartMenu"= 0 (0x0)
"NoInstrumentation"= 1 (0x1)
"NoStartMenuPinnedList"= 0 (0x0)
"ForceStartMenuLogoff"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
C:\Program Files\Ares\Ares.exe -h
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KAVPersonal50]
C:\Program Files\Kaspersky Anti-Virus Personal\kav.exe /minimize
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);C:\WINDOWS\system32\drivers\sfdrv01a.sys
R2 ithsgt;ithsgt;C:\WINDOWS\system32\DRIVERS\ithsgt.sys
R2 lilsgt;lilsgt;C:\WINDOWS\system32\DRIVERS\lilsgt.sys
R3 Tetris;Tetris driver;C:\WINDOWS\system32\Drivers\Tetris.sys
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver;C:\WINDOWS\system32\drivers\WmBEnum.sys
R3 WmFilter;Logitech WingMan HID Filter Driver;C:\WINDOWS\system32\drivers\WmFilter.sys
R3 WmXlCore;Logitech WingMan Translation Layer Driver;C:\WINDOWS\system32\drivers\WmXlCore.sys
S3 WmHidLo;Logitech WingMan USB Filter Driver;C:\WINDOWS\system32\drivers\WmHidLo.sys
S3 WmVirHid;Logitech Virtual Hid Device Driver;C:\WINDOWS\system32\drivers\WmVirHid.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b070a350-d5aa-11d9-b6f4-806d6172696f}]
\Shell\AutoRun\command - G:\ASUSACPI.exe
.
**************************************************************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-23 19:24:23
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-23 19:25:08 - machine was rebooted
C:\ComboFix ... 2007-11-23 19:25
C:\ComboFix2.txt ... 2007-11-23 00:10
.
--- E O F ---
-------------------------------------------------------------------------------------------
-------------------------------------------------------------------------------------------
-------------------------------------------------------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 19:25:48, on 23.11.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ctsvccda.exe
C:\Program Files\NOD32\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\tlntsvr.exe
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Daemon\daemon.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\NOD32\nod32kui.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\AirTies\ADSL Hizmet Programı\AirTies_util3.exe
C:\Program Files\Collins\exe\L-Express.exe
C:\Program Files\Collins\exe\lexibase.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\HijackThis\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\program files\Acrobat Reader\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\Daemon\daemon.exe" -lang 1033 -lock
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\NOD32\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [nod32upd] rundll32 "C:\Program Files\NOD32\fc_upd.dll",NOD32Ioctl
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [cc7b536c] rundll32.exe "C:\WINDOWS\system32\vuusclby.dll",b
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: AirTies ADSL Hizmet Programı.lnk = ?
O4 - Global Startup: Lexibase Express.lnk = ?
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Mobil Sık Kullanılanı Oluştur - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Mobil Sık Kullanılanı Oluştur... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) -
https://www.gamespyid.com/alaunch.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\Ctsvccda.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\NOD32\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\system32\UAService7.exe