Here are the logs, as requested.
_____________________________________
ComboFix 08-04-01.2 - Jeauseoff 2008-04-03 6:50:09.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2301 [GMT -4:00]
Running from: C:\Documents and Settings\Jeauseoff\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Jeauseoff\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\WINDOWS\BMd3838e5d.xml
C:\WINDOWS\msn.com
C:\WINDOWS\system32\awtsRJAs.dll
C:\WINDOWS\system32\cbXOfeFw.dll
C:\WINDOWS\system32\crugfqwg.ini
C:\WINDOWS\system32\dveocrid.ini
C:\WINDOWS\system32\efcCuRjj.dll
C:\WINDOWS\system32\fegamxny.ini
C:\WINDOWS\system32\fkjctfrw.dll
C:\WINDOWS\system32\hgGXqppo.dll
C:\WINDOWS\system32\HQWFOqru.ini
C:\WINDOWS\system32\HQWFOqru.ini2
C:\WINDOWS\system32\iifGYpnn.dll
C:\WINDOWS\system32\jkkLEXQi.dll
C:\WINDOWS\system32\khfGvwtT.dll
C:\WINDOWS\system32\KjQXaccf.ini
C:\WINDOWS\system32\KjQXaccf.ini2
C:\WINDOWS\system32\KnXyHRqr.ini
C:\WINDOWS\system32\KnXyHRqr.ini2
C:\WINDOWS\system32\ljJbCron.dll
C:\WINDOWS\system32\lnhirlpj.ini
C:\WINDOWS\system32\PonXIkkj.ini
C:\WINDOWS\system32\PonXIkkj.ini2
C:\WINDOWS\system32\qoMCuUOF.dll
C:\WINDOWS\system32\qoMfgHaW.dll
C:\WINDOWS\system32\qoMgdeEW.dll
C:\WINDOWS\system32\qoMGvsTm.dll
C:\WINDOWS\system32\rqRJcyWM.dll
C:\WINDOWS\system32\rvbrtkgj.ini
C:\WINDOWS\system32\sjoefskk.ini
C:\WINDOWS\system32\spool.exe
C:\WINDOWS\system32\tqebhdxk.ini
C:\WINDOWS\system32\tuvtRkih.dll
C:\WINDOWS\system32\tydyrwek.dll
C:\WINDOWS\system32\urqOFVoO.dll
C:\WINDOWS\system32\vtUlMdbY.dll
C:\WINDOWS\system32\vtUoomkl.dll
C:\WINDOWS\system32\wFefOXbc.ini
C:\WINDOWS\system32\wFefOXbc.ini2
C:\WINDOWS\system32\yayaAtrQ.dll
C:\WINDOWS\system32\yuvdbmyt.ini
D:\Autorun.exe
F:\AutorunArcanum.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BMd3838e5d.xml
C:\WINDOWS\msn.com
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\awtsRJAs.dll
C:\WINDOWS\system32\byXNhHxx.dll
C:\WINDOWS\system32\cbXOfeFw.dll
C:\WINDOWS\system32\crugfqwg.ini
C:\WINDOWS\system32\dveocrid.ini
C:\WINDOWS\system32\efcCuRjj.dll
C:\WINDOWS\system32\efcYRIbX.dll
C:\WINDOWS\system32\fegamxny.ini
C:\WINDOWS\system32\hgGXqppo.dll
C:\WINDOWS\system32\HQWFOqru.ini
C:\WINDOWS\system32\HQWFOqru.ini2
C:\WINDOWS\system32\iifGYpnn.dll
C:\WINDOWS\system32\ipxndjwf.dll
C:\WINDOWS\system32\jkkLEXQi.dll
C:\WINDOWS\system32\khfGvwtT.dll
C:\WINDOWS\system32\KjQXaccf.ini
C:\WINDOWS\system32\KjQXaccf.ini2
C:\WINDOWS\system32\KnXyHRqr.ini
C:\WINDOWS\system32\KnXyHRqr.ini2
C:\WINDOWS\system32\ljJbCron.dll
C:\WINDOWS\system32\lnhirlpj.ini
C:\WINDOWS\system32\lvcdqfkm.ini
C:\WINDOWS\system32\mkfqdcvl.dll
C:\WINDOWS\system32\mlJApOeE.dll
C:\WINDOWS\system32\nygtxfif.dll
C:\WINDOWS\system32\PonXIkkj.ini
C:\WINDOWS\system32\PonXIkkj.ini2
C:\WINDOWS\system32\qoMCuUOF.dll
C:\WINDOWS\system32\qoMdETMF.dll
C:\WINDOWS\system32\qoMdEuUK.dll
C:\WINDOWS\system32\qoMfcYQJ.dll
C:\WINDOWS\system32\qoMfgHaW.dll
C:\WINDOWS\system32\qoMgdeEW.dll
C:\WINDOWS\system32\qoMGvsTm.dll
C:\WINDOWS\system32\rqRJcyWM.dll
C:\WINDOWS\system32\rvbrtkgj.ini
C:\WINDOWS\system32\sjoefskk.ini
C:\WINDOWS\system32\spool.exe
C:\WINDOWS\system32\ssqqooPG.dll
C:\WINDOWS\system32\tqebhdxk.ini
C:\WINDOWS\system32\tuvtRkih.dll
C:\WINDOWS\system32\urqOFVoO.dll
C:\WINDOWS\system32\vtUlMdbY.dll
C:\WINDOWS\system32\vtUoomkl.dll
C:\WINDOWS\system32\wFefOXbc.ini
C:\WINDOWS\system32\wFefOXbc.ini2
C:\WINDOWS\system32\yayaAtrQ.dll
C:\WINDOWS\system32\yuvdbmyt.ini
.
((((((((((((((((((((((((( Files Created from 2008-03-03 to 2008-04-03 )))))))))))))))))))))))))))))))
.
2008-04-01 21:13 . 2008-04-01 21:13 1,600,027 ---hs---- C:\WINDOWS\system32\lcbhpjpx.ini
2008-04-01 21:01 . 2008-04-01 21:01 1,600,027 ---hs---- C:\WINDOWS\system32\nxqishvn.ini
2008-04-01 20:43 . 2008-04-01 20:43 <DIR> d-------- C:\Logs
2008-03-30 21:36 . 2008-03-30 21:36 <DIR> d-------- C:\Program Files\Java
2008-03-30 21:36 . 2080-03-31 14:32 <DIR> d-------- C:\Program Files\Common Files\Java
2008-03-30 21:36 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-03-28 14:28 . 2008-03-28 14:28 244 --ah----- C:\sqmnoopt06.sqm
2008-03-28 14:28 . 2008-03-28 14:28 232 --ah----- C:\sqmdata06.sqm
2008-03-28 14:27 . 2008-03-28 14:27 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-03-10 20:52 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-03-10 20:52 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-03-10 20:52 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-03-10 04:35 . 2008-03-10 04:37 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-10 04:35 . 2008-03-10 04:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2080-03-31 18:33 --------- d-----w C:\Program Files\CCleaner
2008-04-03 10:53 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-02 01:25 --------- d-----w C:\Program Files\World of Warcraft
2008-04-02 01:14 --------- d-----w C:\Program Files\Common Files\Seagate
2008-04-02 00:54 --------- d-----w C:\Program Files\Spyware Doctor
2008-03-29 22:31 --------- d-----w C:\Program Files\Steam
2008-02-27 14:46 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Talkback
2008-02-25 17:55 --------- d-----w C:\Program Files\iTunes
2008-02-25 17:55 --------- d-----w C:\Program Files\iPod
2008-02-25 17:54 --------- d-----w C:\Program Files\QuickTime
2008-02-11 16:17 --------- d-----w C:\Documents and Settings\Jeauseoff\Application Data\InfraRecorder
2008-02-11 16:13 --------- d-----w C:\Program Files\InfraRecorder
2008-02-07 13:16 --------- d-----w C:\Documents and Settings\Jeauseoff\Application Data\InstallShield
2008-02-07 12:27 --------- d-----w C:\Program Files\OpenOffice.org 2.3
2008-02-07 12:23 --------- d-----w C:\Documents and Settings\Jeauseoff\Application Data\OpenOffice.org2
2008-02-05 05:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-02-05 02:44 --------- d-----w C:\Program Files\Sword of The New World
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{58EA3606-4ADF-4454-AEF1-98F6B4F683C3}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-10-04 18:14 8491008]
"nwiz"="nwiz.exe" [2007-10-04 18:14 1626112 C:\WINDOWS\system32\nwiz.exe]
"RegistryMechanic"="" []
"CTHelper"="CTHELPER.EXE" [2006-08-11 15:56 17920 C:\WINDOWS\CTHELPER.EXE]
"CTxfiHlp"="CTXFIHLP.EXE" [2006-08-11 15:56 18944 C:\WINDOWS\system32\CTXFIHLP.EXE]
"P17Helper"="P17.dll" [2005-05-02 23:38 64512 C:\WINDOWS\system32\P17.dll]
"RTHDCPL"="RTHDCPL.EXE" [2006-04-17 03:34 16143872 C:\WINDOWS\RTHDCPL.EXE]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-02-01 00:13 385024]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-10-04 18:14 81920]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-11-02 18:24 1065800]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe" [2007-08-08 18:51 148760]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 14:10 267048]
"Windows live Messenger"="msn.com" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [ ]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{060BB0AB-4B09-4C51-9ECB-9580A6D08D7F}"= blank [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtustUL]
awtustUL.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtUoomkl]
vtUoomkl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wvUkKaxW]
wvUkKaxW.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wvUljHBs]
wvUljHBs.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli scecli scecli
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Steam\\steamapps\\jeauseoff@hotmail.com\\day of defeat source\\hl2.exe"=
"C:\\Program Files\\Autodesk\\3dsMax8\\3dsmax.exe"=
"C:\\Torque\\SDK\\example\\torqueDemo.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"C:\\Program Files\\Sony\\Station\\LaunchPad\\LaunchPad.exe"=
"C:\\Program Files\\Steam\\steamapps\\jeauseoff@hotmail.com\\counter-strike source\\hl2.exe"=
"C:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56594:TCP"= 56594:TCP:Pando P2P TCP Listening Port
"56594:UDP"= 56594:UDP:Pando P2P UDP Listening Port
R0 ppa;Iomega Parallel Port Filter Driver;C:\WINDOWS\system32\DRIVERS\ppa.sys [2001-08-17 09:53]
R0 UGURU;UGURU;C:\WINDOWS\system32\drivers\uGuru.sys [2006-05-03 14:46]
S2 Ray3_4_6_18Server;Ray3_4_6_18 Server;X:\XSI_5.11\Application\bin\ray3_4_6_18server.exe []
S3 ctgame;Game Port;C:\WINDOWS\system32\DRIVERS\ctgame.sys [2002-12-30 11:53]
S3 XDva011;XDva011;C:\WINDOWS\system32\XDva011.sys []
S3 XDva020;XDva020;C:\WINDOWS\system32\XDva020.sys []
.
Contents of the 'Scheduled Tasks' folder
"2008-03-31 16:12:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-04-03 06:55:22
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwClose
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-04-03 6:57:10 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-03 10:57:07
ComboFix2.txt 2008-04-02 00:13:03
Pre-Run: 190,662,279,168 bytes free
Post-Run: 190,543,265,792 bytes free
.
2008-03-12 15:51:12 --- E O F ---
____________________________________________________________
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:59:36 AM, on 4/3/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\Moogles.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.hotmail.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {58EA3606-4ADF-4454-AEF1-98F6B4F683C3} - blank (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Windows live Messenger] msn.com
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) -
http://www.creative....026/CTSUEng.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) -
http://messenger.zon...1/GAME_UNO1.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) -
http://www.acclaim.c.../acclaim_v4.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) -
http://messenger.zon...ro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) -
http://messenger.zon...er.cab56986.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) -
http://www.creative....15027/CTPID.cab
O20 - Winlogon Notify: awtustUL - awtustUL.dll (file missing)
O20 - Winlogon Notify: vtUoomkl - vtUoomkl.dll (file missing)
O20 - Winlogon Notify: wvUkKaxW - wvUkKaxW.dll (file missing)
O20 - Winlogon Notify: wvUljHBs - wvUljHBs.dll (file missing)
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Unknown owner - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (file missing)
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: RaySat_3dsmax8 Server (mi-raysat_3dsmax8) - Unknown owner - C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Ray3_4_6_18 Server (Ray3_4_6_18Server) - Unknown owner - X:\XSI_5.11\Application\bin\ray3_4_6_18server.exe (file missing)
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe (file missing)
--
End of file - 8791 bytes