Here are the new logs. It's a bit soon to tell if anything is still going on as I just did the tests, but will keep an eye open.
ComboFix 08-11-13.01 - Administrator 2008-11-15 13:47:31.25 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1354 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript.txt
* Created a new restore point
* Resident AV is active
FILE ::
C:\bkM.exe
c:\windows\system32\3tWBhKcG.exe
c:\windows\system32\7MeM5Doa.exe
c:\windows\system32\drivers\f75f25db.sys
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\bkM.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_f75f25db
((((((((((((((((((((((((( Files Created from 2008-10-15 to 2008-11-15 )))))))))))))))))))))))))))))))
.
2008-11-15 18:50 . 2004-10-28 18:39 122,880 –a—— c:\windows\system32\BtCoreIf.dll
2008-11-15 18:50 . 2004-11-05 16:34 71,756 –a—— c:\windows\system32\drivers\LMouKE.Sys
2008-11-15 18:50 . 2004-11-05 16:34 55,008 ——— c:\windows\system32\drivers\L8042MOU.SYS
2008-11-15 18:50 . 2004-12-02 09:34 37,888 –a—— c:\windows\KHALMNPR.Exe
2008-11-15 18:50 . 2004-04-13 12:44 22,497 –a—— c:\windows\system32\drivers\LHidPPKE.Sys
2008-11-15 18:49 . 2008-11-15 18:49 d——– c:\program files\Logitech
2008-11-15 18:49 . 2004-11-05 16:34 24,764 –a—— c:\windows\system32\drivers\LHidKE.Sys
2008-11-15 12:22 . 2008-11-15 12:22 d——– c:\documents and settings\Administrator\Bluetooth Software
2008-11-15 12:16 . 2008-11-15 12:16 d——– c:\program files\WIDCOMM
2008-11-10 20:23 . 2008-11-10 21:02 d——– c:\program files\ggpo
2008-11-08 17:03 . 2008-11-08 17:03 d——– c:\documents and settings\Administrator\Application Data\com.doubleperfect.ggpo.0753AD3679DBFCA1E7F470171B7D0DB8B404A7EA.1
2008-10-31 01:07 . 2008-10-31 01:07 18,944 –a—— C:\MHr.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-15 17:49 ——— d—–w c:\program files\Common Files\Logitech
2008-11-15 11:48 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-15 11:44 ——— d—–w c:\documents and settings\Administrator\Application Data\Azureus
2008-11-15 10:41 ——— d—–w c:\program files\PartyGaming
2008-11-11 18:31 ——— d—–w c:\documents and settings\Administrator\Application Data\bibble
2008-11-02 12:53 ——— d—–w c:\program files\Spybot - Search & Destroy
2008-11-01 14:38 ——— d—–w c:\documents and settings\All Users\Application Data\Lavasoft
2008-10-22 15:10 38,496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2008-10-22 15:10 15,504 —-a-w c:\windows\system32\drivers\mbam.sys
2008-09-21 14:50 ——— d—–w c:\documents and settings\Administrator\Application Data\Logitech
2008-04-15 06:40 68,088 —-a-w c:\documents and settings\Administrator\Application Data\GDIPFONTCACHEV1.DAT
.
——- Sigcheck ——-
2007-11-24 15:23 14336 8f078ae4ed187aaabc0a305146de6716 c:\windows\system32\svchost.exe
2002-12-31 13:00 577024 1800f293bccc8ede8a70e12b88d80036 c:\windows\system32\user32.dll
2002-12-31 13:00 82944 2ed0b7f12a60f90092081c50fa0ec2b2 c:\windows\system32\ws2_32.dll
2002-12-31 13:00 359936 63fdfea54eb53de2d863ee454937ce1e c:\windows\system32\drivers\tcpip.sys
2002-12-31 13:00 502784 b66dbc40d428fe1293041d621d836ac8 c:\windows\system32\winlogon.exe
2002-12-31 13:00 182912 558635d3af1c7546d26067d5d9b6959e c:\windows\system32\drivers\ndis.sys
2002-12-31 13:00 2056832 d8aba3eab509627e707a3b14f00fbb6b c:\windows\system32\ntkrnlpa.exe
2002-12-31 13:00 2179456 28187802b7c368c0d3aef7d4c382aabb c:\windows\system32\ntoskrnl.exe
2002-12-31 13:00 1032192 98d45efddd1a67f90353be8d28ed72db c:\windows\explorer.exe
2002-12-31 13:00 108032 c6ce6eec82f187615d1002bb3bb50ed4 c:\windows\system32\services.exe
2002-12-31 13:00 13312 84885f9b82f4d55c6146ebf6065d75d2 c:\windows\system32\lsass.exe
2002-12-31 13:00 15360 24232996a38c0b0cf151c2140ae29fc8 c:\windows\system32\ctfmon.exe
2005-06-11 01:17 57856 ad3d9d191aea7b5445fe1d82ffbb4788 c:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2002-12-31 13:00 57856 7435b108b935e42ea92ca94f59c8e717 c:\windows\$NtUninstallKB896423$\spoolsv.exe
2005-06-11 00:53 57856 da81ec57acd4cdc3d4c51cf3d409af9f c:\windows\system32\spoolsv.exe
2002-12-31 13:00 24576 39b1ffb03c2296323832acbae50d2aff c:\windows\system32\userinit.exe
2002-12-31 13:00 295424 972063211cb1ce503e7cb0ae48955145 c:\windows\system32\termsrv.dll
.
((((((((((((((((((((((((((((( snapshot@2008-11-15_12.48.12.48 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-20 19:02:28 163,328 —-a-w c:\windows\erdnt\subs\ERDNT.EXE
- 2008-11-10 11:27:12 16,384 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-11-15 12:49:26 16,384 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2008-11-10 11:27:12 16,384 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-11-15 12:49:26 16,384 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-11-10 11:27:12 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-11-15 12:49:26 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2007-11-24 949376]
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTServ]
2004-12-02 09:34 1404928 c:\program files\Common Files\Logitech\Bluetooth\LBTServ.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.i263"= i263_32.drv
"msacm.imc"= imc32.acm
"vidc.hfyu"= huffyuv.dll
"msacm.divxa32"= DivXa32.acm
"msacm.l3codec"= l3codecp.acm
[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^HDD temperature.lnk]
path=c:\documents and settings\Administrator\Start Menu\Programs\Startup\HDD temperature.lnk
backup=c:\windows\pss\HDD temperature.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=c:\windows\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Synchronizer.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Synchronizer.lnk
backup=c:\windows\pss\Adobe Acrobat Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoCAD Startup Accelerator.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\AutoCAD Startup Accelerator.lnk
backup=c:\windows\pss\AutoCAD Startup Accelerator.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BTTray.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BTTray.lnk
backup=c:\windows\pss\BTTray.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^m-trip Launcher.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\m-trip Launcher.lnk
backup=c:\windows\pss\m-trip Launcher.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^msn_0802_upd181826.exe]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\msn_0802_upd181826.exe
backup=c:\windows\pss\msn_0802_upd181826.exeCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Suitcase 11.0.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Suitcase 11.0.lnk
backup=c:\windows\pss\Suitcase 11.0.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2002-12-31 13:00 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
–a—— 2005-12-10 15:57 133016 d:\program files\DAEMON Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2001-07-09 10:50 155648 c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RaidTool]
–a—— 2005-06-20 18:53 1056768 c:\program files\VIA\RAID\raid_tool.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs—- 2008-09-16 12:16 1833296 c:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2007-07-12 03:00 132496 c:\program files\Java\jre1.6.0_02\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JulaPan]
–a—— 2005-07-05 16:27 425984 c:\windows\system32\JulaPan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer]
–a—— 2004-12-02 09:34 37888 c:\windows\KHALMNPR.Exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Hardware Abstraction Layer]
–a—— 2004-12-02 09:34 37888 c:\windows\KHALMNPR.Exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
–a—— 2005-01-10 03:36 77824 c:\windows\SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"PDSched"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"d:\\Program Files\\Next Limit\\Maxwell\\mxcl.exe"=
R3 ipgd;IC Plus IP1000 Family Gigabit Ethernet Adapter Driver;c:\windows\system32\DRIVERS\ipgdnd51.sys [2005-01-11 33792]
R3 LHidPPKE;Logitech SetPoint HID Function Driver;c:\windows\system32\DRIVERS\LHidPPKE.Sys [2004-04-13 22497]
S3 JULA_01;Service for Juli@ 1;c:\windows\system32\drivers\JulaWdm.sys [2005-07-05 22880]
S3 JULA_AA;Service for Juli@ Audio Driver (EWDM);c:\windows\system32\drivers\Jula.sys [2005-07-05 29472]
S3 MA_CMIDI;%EVOL_USB.SvcDesc%;c:\windows\system32\drivers\ma_cmidi.sys [ ]
.
Contents of the 'Scheduled Tasks' folder
2008-11-14 c:\windows\Tasks\At1.job
- c:\windows\system32\3tWBhKcG.exe []
2008-11-15 c:\windows\Tasks\At10.job
- c:\windows\system32\3tWBhKcG.exe []
2008-11-15 c:\windows\Tasks\At11.job
- c:\windows\system32\3tWBhKcG.exe []
2008-11-15 c:\windows\Tasks\At12.job
- c:\windows\system32\3tWBhKcG.exe []
2008-11-15 c:\windows\Tasks\At13.job
- c:\windows\system32\3tWBhKcG.exe []
2008-11-15 c:\windows\Tasks\At14.job
- c:\windows\system32\3tWBhKcG.exe []
2008-11-14 c:\windows\Tasks\At15.job
- c:\windows\system32\3tWBhKcG.exe []
2008-11-14 c:\windows\Tasks\At16.job
- c:\windows\system32\3tWBhKcG.exe []
2008-11-14 c:\windows\Tasks\At17.job
- c:\windows\system32\3tWBhKcG.exe []
2008-11-14 c:\windows\Tasks\At18.job
- c:\windows\system32\3tWBhKcG.exe []
2008-11-14 c:\windows\Tasks\At19.job
- c:\windows\system32\3tWBhKcG.exe []
2008-11-15 c:\windows\Tasks\At2.job
- c:\windows\system32\3tWBhKcG.exe []
2008-11-14 c:\windows\Tasks\At20.job
- c:\windows\system32\3tWBhKcG.exe []
2008-11-14 c:\windows\Tasks\At21.job
- c:\windows\system32\3tWBhKcG.exe []
2008-11-14 c:\windows\Tasks\At22.job
- c:\windows\system32\3tWBhKcG.exe []
2008-11-14 c:\windows\Tasks\At23.job
- c:\windows\system32\3tWBhKcG.exe []
2008-11-14 c:\windows\Tasks\At24.job
- c:\windows\system32\3tWBhKcG.exe []
2008-11-14 c:\windows\Tasks\At25.job
- c:\windows\system32\7MeM5Doa.exe []
2008-11-15 c:\windows\Tasks\At26.job
- c:\windows\system32\7MeM5Doa.exe []
2008-11-15 c:\windows\Tasks\At27.job
- c:\windows\system32\7MeM5Doa.exe []
2008-11-15 c:\windows\Tasks\At28.job
- c:\windows\system32\7MeM5Doa.exe []
2008-11-15 c:\windows\Tasks\At29.job
- c:\windows\system32\7MeM5Doa.exe []
2008-11-15 c:\windows\Tasks\At3.job
- c:\windows\system32\3tWBhKcG.exe []
2008-11-15 c:\windows\Tasks\At30.job
- c:\windows\system32\7MeM5Doa.exe []
2008-11-15 c:\windows\Tasks\At31.job
- c:\windows\system32\7MeM5Doa.exe []
2008-11-15 c:\windows\Tasks\At32.job
- c:\windows\system32\7MeM5Doa.exe []
2008-11-15 c:\windows\Tasks\At33.job
- c:\windows\system32\7MeM5Doa.exe []
2008-11-15 c:\windows\Tasks\At34.job
- c:\windows\system32\7MeM5Doa.exe []
2008-11-15 c:\windows\Tasks\At35.job
- c:\windows\system32\7MeM5Doa.exe []
2008-11-15 c:\windows\Tasks\At36.job
- c:\windows\system32\7MeM5Doa.exe []
2008-11-15 c:\windows\Tasks\At37.job
- c:\windows\system32\7MeM5Doa.exe []
2008-11-15 c:\windows\Tasks\At38.job
- c:\windows\system32\7MeM5Doa.exe []
2008-11-14 c:\windows\Tasks\At39.job
- c:\windows\system32\7MeM5Doa.exe []
2008-11-15 c:\windows\Tasks\At4.job
- c:\windows\system32\3tWBhKcG.exe []
2008-11-14 c:\windows\Tasks\At40.job
- c:\windows\system32\7MeM5Doa.exe []
2008-11-14 c:\windows\Tasks\At41.job
- c:\windows\system32\7MeM5Doa.exe []
2008-11-14 c:\windows\Tasks\At42.job
- c:\windows\system32\7MeM5Doa.exe []
2008-11-14 c:\windows\Tasks\At43.job
- c:\windows\system32\7MeM5Doa.exe []
2008-11-14 c:\windows\Tasks\At44.job
- c:\windows\system32\7MeM5Doa.exe []
2008-11-14 c:\windows\Tasks\At45.job
- c:\windows\system32\7MeM5Doa.exe []
2008-11-14 c:\windows\Tasks\At46.job
- c:\windows\system32\7MeM5Doa.exe []
2008-11-14 c:\windows\Tasks\At47.job
- c:\windows\system32\7MeM5Doa.exe []
2008-11-14 c:\windows\Tasks\At48.job
- c:\windows\system32\7MeM5Doa.exe []
2008-11-15 c:\windows\Tasks\At5.job
- c:\windows\system32\3tWBhKcG.exe []
2008-11-15 c:\windows\Tasks\At6.job
- c:\windows\system32\3tWBhKcG.exe []
2008-11-15 c:\windows\Tasks\At7.job
- c:\windows\system32\3tWBhKcG.exe []
2008-11-15 c:\windows\Tasks\At8.job
- c:\windows\system32\3tWBhKcG.exe []
2008-11-15 c:\windows\Tasks\At9.job
- c:\windows\system32\3tWBhKcG.exe []
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-15 13:50:27
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
d:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
c:\program files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\ESET\nod32krn.exe
c:\program files\Canon\CAL\CALMAIN.exe
.
**************************************************************************
.
Completion time: 2008-11-15 13:58:02 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-15 12:57:52
ComboFix2.txt 2008-11-15 11:48:39
ComboFix3.txt 2008-08-04 08:42:58
Pre-Run: 9,372,254,208 bytes free
Post-Run: 9,677,594,624 bytes free
291
———
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:00:22 PM, on 11/15/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\explorer.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\Administrator\Desktop\spyware\HijackThis.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) -
http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) -
http://www.eset.eu/OnlineScanner.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4A27027D-9371-47B2-A07A-1B5CC3A6F3B3}: NameServer = 192.168.1.1
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
–
End of file - 3738 bytes
Also got this error from HJT:
Please help us improve HijackThis by reporting this error
Click 'Yes' to submit
Error Details:
An unexpected error has occurred at procedure: modRegistry_IniGetString(sFile=system.ini, sSection=boot, sValue=Shell)
Error #5 - Invalid procedure call or argument
Windows version: Windows NT 5.01.2600
MSIE version: 6.0.2900.2180
HijackThis version: 2.0.2