Hello again,
Did as instructed. This page is now loading correctly again, computer seems to be running fine - still no error or dialog boxes upon reboot. Checked the background/desktop tab in display properties. It is back. Most of the icons in the drop down menu are visable. Some have a mark (looks like a small white & maroon box with a dot in it) on them but will work when selected.
Here is a log of the combo fix/notepad experience:
ComboFix 08-01-20.1 - FLASHIRL 2008-01-20 17:17:09.2 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\FLASHIRL\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE
C:\20C.tmp
C:\WINDOWS\iun6002ev.exe
C:\WINDOWS\system32\drivers\obnecekrlidi.sys
.
The following files were disabled during the run:
C:\Program Files\Axaware\Spam Bully 3 for OE\hookoecreation.dll
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\20C.tmp
C:\Documents and Settings\All Users\Application Data\Viewpoint
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\MetaStreamConfig.ini
C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Experience Technology\MetaStreamID.ini
C:\Program Files\Viewpoint
C:\Program Files\Viewpoint\Viewpoint Experience Technology\AxMetaStream.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\ClassIDs.ini
C:\Program Files\Viewpoint\Viewpoint Experience Technology\ComponentMgr.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\MetaStreamID.ini
C:\Program Files\Viewpoint\Viewpoint Experience Technology\MtsAxInstaller.exe
C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\AOLArt.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\AOLShell.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\AOLUserShell.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\Cursors.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\DataTracking.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\GifReader.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\JpegReader.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\LensFlares.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\Mts3Reader.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\ObjectMovie.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\SceneComponent.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\ServiceComponent.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\SreeDMMX.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\SWFView.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\VectorView.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\VMPAudio.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\VMPExtras.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\VMPSpeech.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\VMPVideo.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\WaveletReader.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\ZoomView.dll
C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
C:\WINDOWS\iun6002ev.exe
C:\WINDOWS\NV18041468.TMP
C:\WINDOWS\NV18041468.TMP\default.tvp
C:\WINDOWS\system32\drivers\obnecekrlidi.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\LEGACY_OBNECEKRLIDI
——-\obnecekrlidi
((((((((((((((((((((((((( Files Created from 2007-12-20 to 2008-01-20 )))))))))))))))))))))))))))))))
.
2008-01-20 15:15 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-20 14:14 . 2007-06-08 09:44 8,576 –a—— C:\WINDOWS\system32\drivers\RkPavProc.sys
2008-01-20 13:30 . 2007-06-05 10:56 44,928 –a—— C:\WINDOWS\system32\drivers\SDTHOOK.SYS
2008-01-20 13:17 . 2008-01-20 14:46 921,120 –ahs—- C:\WINDOWS\system32\drivers\fidbox.dat
2008-01-20 13:17 . 2008-01-20 14:46 58,144 –ahs—- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-01-20 13:17 . 2008-01-20 14:46 19,676 –ahs—- C:\WINDOWS\system32\drivers\fidbox.idx
2008-01-20 13:17 . 2008-01-20 14:46 6,524 –ahs—- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-01-20 13:07 . 2008-01-20 14:42 d——– C:\WINDOWS\system32\ActiveScan
2008-01-20 13:07 . 2008-01-20 13:07 d——– C:\KAV
2008-01-20 13:07 . 2008-01-20 14:12 2,550 –a—— C:\WINDOWS\system32\Uninstall.ico
2008-01-20 13:07 . 2008-01-20 14:12 1,406 –a—— C:\WINDOWS\system32\Help.ico
2008-01-20 11:17 . 2008-01-20 11:18 d——– C:\WINDOWS\BDOSCAN8
2008-01-20 10:45 . 2008-01-20 10:44 102,664 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2008-01-20 10:44 . 2008-01-20 13:35 d——– C:\Documents and Settings\FLASHIRL\.housecall6.6
2008-01-20 10:38 . 2008-01-20 17:13 3,284 –a—— C:\WINDOWS\system32\ANIWZCS{CD9320BD-B3A7-4150-8D20-3E6B48FC39D6}
2008-01-20 10:30 . 2008-01-20 10:30 d——– C:\Program Files\D-Link
2008-01-20 10:30 . 2008-01-20 10:30 d——– C:\Program Files\ANI
2008-01-16 13:09 . 2006-10-22 15:06 208,896 –a—— C:\WINDOWS\system32\NVUNINST.EXE
2008-01-16 13:04 . 2008-01-16 13:12 d——– C:\WINDOWS\nview
2008-01-16 13:04 . 2006-10-22 15:06 208,896 –a—— C:\WINDOWS\system32\nvudisp.exe
2008-01-16 13:04 . 2006-10-22 12:22 17,056 –a—— C:\WINDOWS\system32\nvdisp.nvu
2008-01-16 12:45 . 2008-01-16 12:45 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-16 12:08 . 2008-01-16 12:08 d–h—– C:\WINDOWS\system32\GroupPolicy
2008-01-16 11:52 . 2002-08-29 01:27 86,912 –a—— C:\WINDOWS\system32\drivers\atapi.sys
2008-01-16 11:52 . 2002-08-29 01:27 86,912 –a–c— C:\WINDOWS\system32\dllcache\atapi.sys
2008-01-16 11:52 . 2001-08-17 22:36 67,072 –a—— C:\WINDOWS\system32\usbui.dll
2008-01-16 11:52 . 2001-08-17 22:36 67,072 –a–c— C:\WINDOWS\system32\dllcache\usbui.dll
2008-01-16 11:52 . 2001-08-17 13:58 25,472 –a—— C:\WINDOWS\system32\drivers\AGP440.SYS
2008-01-16 11:52 . 2001-08-17 13:58 25,472 –a–c— C:\WINDOWS\system32\dllcache\agp440.sys
2008-01-16 11:52 . 2002-08-29 01:27 23,680 –a—— C:\WINDOWS\system32\drivers\pciidex.sys
2008-01-16 11:52 . 2002-08-29 01:27 23,680 –a–c— C:\WINDOWS\system32\dllcache\pciidex.sys
2008-01-16 11:52 . 2001-08-17 13:51 3,328 –a—— C:\WINDOWS\system32\drivers\pciide.sys
2008-01-16 11:52 . 2001-08-17 13:51 3,328 –a–c— C:\WINDOWS\system32\dllcache\pciide.sys
2008-01-16 11:51 . 2002-08-29 01:09 62,976 –a—— C:\WINDOWS\system32\drivers\pci.sys
2008-01-16 11:51 . 2002-08-29 01:09 62,976 –a–c— C:\WINDOWS\system32\dllcache\pci.sys
2008-01-16 11:51 . 2001-08-17 13:58 35,840 –a—— C:\WINDOWS\system32\drivers\isapnp.sys
2008-01-16 11:51 . 2001-08-17 13:58 35,840 –a–c— C:\WINDOWS\system32\dllcache\isapnp.sys
2008-01-14 00:20 . 2008-01-14 00:20 d——– C:\Program Files\NewTech Infosystems
2008-01-14 00:20 . 2002-04-26 11:39 226,816 ——— C:\WINDOWS\system32\htvcdsvcd.ax
2008-01-14 00:20 . 2002-11-13 10:20 9,728 ——— C:\WINDOWS\system\regsvr32.exe
2008-01-14 00:19 . 2008-01-14 00:19 6,016 –a—— C:\WINDOWS\system32\drivers\NTIDrvr.sys
2008-01-04 07:30 . 2008-01-05 08:14 d——– C:\WINDOWS\SxsCaPendDel
2008-01-04 07:23 . 2008-01-04 07:23 2,048 ——— C:\WINDOWS\system32\drivers\kgpfr.cfg
2008-01-04 07:22 . 2008-01-04 07:22 d——– C:\Program Files\Common Files\iS3
2008-01-04 07:22 . 2008-01-04 07:30 d——– C:\Documents and Settings\All Users\Application Data\STOPzilla!
2008-01-04 07:22 . 2008-01-04 07:22 d——– C:\Documents and Settings\All Users\Application Data\SITEguard
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-20 19:15 ——— d—–w C:\Program Files\TrueLaunchBar
2008-01-20 18:48 ——— d—–w C:\Program Files\Common Files\Webroot Shared
2008-01-20 15:37 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-16 17:52 ——— d—–w C:\Program Files\Sygate
2008-01-16 17:51 ——— d—–w C:\Documents and Settings\FLASHIRL\Application Data\AVG7
2008-01-16 17:44 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg7
2008-01-16 15:01 ——— d—–w C:\Program Files\iPod
2007-12-18 17:49 ——— d—–w C:\Program Files\Realtek Sound Manager
2007-12-18 17:49 ——— d—–w C:\Program Files\Realtek AC97
2007-12-18 17:49 ——— d—–w C:\Program Files\MagicISO
2007-12-18 17:49 ——— d—–w C:\Program Files\AvRack
2007-12-17 19:57 ——— d—–w C:\Program Files\RegCure
2007-12-12 15:18 ——— d—–w C:\Program Files\iTunes
2007-12-05 14:22 49,152 —-a-w C:\WINDOWS\system32\Holiday Lights.scr
2007-11-27 13:29 ——— d—–w C:\Documents and Settings\FLASHIRL\Application Data\Image Zone Express
2007-11-26 18:40 ——— d—–w C:\Documents and Settings\FLASHIRL\Application Data\Snapfish
2007-10-25 15:26 53,248 —-a-w C:\WINDOWS\bdoscandel.exe
.
((((((((((((((((((((((((((((( snapshot@2008-01-20_15.16.46.59 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-20 20:15:34 229,376 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
+ 2008-01-20 22:17:05 229,376 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
- 2008-01-20 20:15:34 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
+ 2008-01-20 22:17:05 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
- 2008-01-20 20:15:34 225,280 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\ntuser.dat
+ 2008-01-20 22:17:05 225,280 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\ntuser.dat
+ 2008-01-20 22:17:06 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
+ 2008-01-20 22:17:06 4,526,080 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000005\ntuser.dat
- 2008-01-20 20:15:35 110,592 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000006\UsrClass.dat
+ 2008-01-20 22:17:06 110,592 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000006\UsrClass.dat
+ 2000-08-31 13:00:00 163,328 —-a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
- 2008-01-20 19:51:53 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-01-20 22:12:56 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-01-20 19:51:53 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-01-20 22:12:56 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-01-20 19:51:53 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-01-20 22:12:56 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpamBully 3 for Outlook Express"="C:\Program Files\Axaware\Spam Bully 3 for OE\sb3oe.exe" [2005-09-01 04:56 665088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-01-16 12:45 579072]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2006-10-22 12:22 7700480]
"nwiz"="nwiz.exe" [2006-10-22 12:22 1622016 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2006-10-22 12:22 86016]
"D-Link Wireless G WUA-1340"="C:\Program Files\D-Link\Wireless G WUA-1340\AirGCFG.exe" [2005-12-15 12:19 2715648]
"ANIWZCS2Service"="C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2005-11-30 10:35 49152]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-01-16 12:45 219136]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 03:21:22 288472]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoStartMenuMFUprogramsList"= 0 (0x0)
[HKLM\~\startupfolder\C:^Documents and Settings^FLASHIRL^Start Menu^Programs^Startup^Holiday Lights.lnk]
path=C:\Documents and Settings\FLASHIRL\Start Menu\Programs\Startup\Holiday Lights.lnk
backup=C:\WINDOWS\pss\Holiday Lights.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EasyLinkAdvisor]
–a—— 2006-04-02 20:07 389120 C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-01-13 01:59:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-20 22:19:21 C:\WINDOWS\Tasks\RegCure Program Check.job"
- C:\Program Files\RegCure\RegCure.exe
"2007-01-17 00:49:12 C:\WINDOWS\Tasks\RegCure.job"
- C:\Program Files\RegCure\RegCure.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-20 17:19:36
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2800.1106]
-> C:\Program Files\TrueLaunchBar\tlbhook.dll
.
Completion time: 2008-01-20 17:20:42 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-20 22:20:40
ComboFix2.txt 2008-01-20 20:17:04
Here is my newest HJT log:
Logfile of HijackThis v1.99.1
Scan saved at 5:28:02 PM, on 1/20/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\D-Link\Wireless G WUA-1340\AirGCFG.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\WINDOWS\system32\HPZipm12.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O3 - Toolbar: PopUpCop - {DB43E4E6-FF8A-4018-8C8E-F68587A44A73} - C:\Program Files\PopUpCop\PopUpCop.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [D-Link Wireless G WUA-1340] C:\Program Files\D-Link\Wireless G WUA-1340\AirGCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKCU\..\Run: [SpamBully 3 for Outlook Express] "C:\Program Files\Axaware\Spam Bully 3 for OE\sb3oe.exe" install
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &Search -
http://edits.mywebsearch.com/toolbaredits/…arch.jhtml?p=ZU
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload.adobe.com/pub/shockwave/…ash/swflash.cab
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
By the way, will get SP2 on here this week!!!!!