Here is the combofix log:
-----
ComboFix 09-11-04.02 - David 11/04/2009 23:03.2.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.958.526 [GMT -5:00]
Running from: h:\documents and settings\David\Desktop\ComboFix.exe
Command switches used :: h:\documents and settings\David\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((( Files Created from 2009-10-05 to 2009-11-05 )))))))))))))))))))))))))))))))
.
2009-11-04 05:34 . 2004-08-04 07:56 50176 -c--a-w- h:\windows\system32\dllcache\proquota.exe
2009-11-04 05:34 . 2004-08-04 07:56 50176 ----a-w- h:\windows\system32\proquota.exe
2009-11-04 04:44 . 2009-11-04 04:44 -------- d-----w- h:\program files\Trend Micro
2009-11-04 01:57 . 2009-11-04 01:57 -------- d-----w- H:\VundoFix Backups
2009-11-03 06:02 . 2009-11-03 05:52 15880 ----a-w- h:\windows\system32\lsdelete.exe
2009-11-03 05:51 . 2009-11-03 05:51 5908024 ----a-w- h:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2009-11-03 05:51 . 2009-11-03 05:51 327000 ----a-w- h:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-11-03 05:51 . 2009-11-03 05:51 87496 ----a-w- h:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-11-03 05:51 . 2009-11-03 05:51 933120 ----a-w- h:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-11-03 05:51 . 2009-11-03 05:51 640608 ----a-w- h:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AutoLaunch.exe
2009-11-03 05:50 . 2009-11-03 05:50 815760 ----a-w- h:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-11-03 05:50 . 2009-11-03 05:50 822904 ----a-w- h:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-11-03 05:50 . 2009-11-03 05:50 1638104 ----a-w- h:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-11-03 05:50 . 2009-11-03 05:50 788368 ----a-w- h:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-11-03 05:50 . 2009-11-03 05:50 1179232 ----a-w- h:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-11-03 05:49 . 2009-11-03 05:49 -------- dc-h--w- h:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
2009-11-03 05:49 . 2009-10-03 08:15 2924848 -c--a-w- h:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}\Ad-AwareInstallation.exe
2009-11-03 05:49 . 2009-11-03 05:52 -------- d-----w- h:\documents and settings\All Users\Application Data\Lavasoft
2009-11-03 05:49 . 2009-11-03 05:49 -------- d-----w- h:\program files\Lavasoft
2009-10-17 12:36 . 2009-10-17 12:36 2025752 ----a-w- h:\documents and settings\All Users\Application Data\avg8\update\backup\avgtray.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-05 04:01 . 2008-09-08 23:40 -------- d-----w- h:\documents and settings\David\Application Data\DNA
2009-11-04 05:49 . 2008-09-08 23:40 -------- d-----w- h:\program files\DNA
2009-11-04 05:08 . 2009-07-24 01:04 -------- d-----w- h:\program files\Malwarebytes' Anti-Malware
2009-11-03 03:41 . 2009-06-13 21:54 -------- d-----w- h:\documents and settings\All Users\Application Data\avg8
2009-10-19 18:33 . 2006-04-19 01:36 -------- d-----w- h:\documents and settings\David\Application Data\AdobeUM
2009-10-09 23:15 . 2006-04-25 03:10 -------- d-----w- h:\program files\Java
2009-10-09 23:13 . 2009-08-29 21:41 152576 ----a-w- h:\documents and settings\David\Application Data\Sun\Java\jre1.6.0_15\lzma.dll
2009-09-23 12:55 . 2009-11-03 05:52 64288 ----a-w- h:\windows\system32\drivers\Lbd.sys
2009-09-15 21:28 . 2006-04-19 01:45 32 ----a-w- h:\windows\msocreg32.dat
2009-09-10 19:54 . 2009-07-24 01:04 38224 ----a-w- h:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 19:53 . 2009-07-24 01:04 19160 ----a-w- h:\windows\system32\drivers\mbam.sys
2009-08-29 21:38 . 2009-06-13 21:54 335240 ----a-w- h:\windows\system32\drivers\avgldx86.sys
2009-08-29 21:38 . 2009-06-13 21:54 11952 ----a-w- h:\windows\system32\avgrsstx.dll
2009-08-29 21:38 . 2007-12-19 05:01 27784 ----a-w- h:\windows\system32\drivers\avgmfx86.sys
2009-07-24 00:00 . 2009-07-24 00:00 19292 ----a-w- h:\program files\Common Files\zisyluwy.com
2009-07-24 00:00 . 2009-07-24 00:00 12309 ----a-w- h:\program files\Common Files\emucyvixep._dl
2009-07-25 14:39 . 2009-07-25 14:39 3 --sha-w- h:\windows\system32\vodesome.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-11-04_05.37.29 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-11-04 05:49 . 2009-11-04 05:49 16384 h:\windows\temp\Perflib_Perfdata_7dc.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EasyLinkAdvisor"="h:\program files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-15 454784]
"BitTorrent DNA"="h:\program files\DNA\btdna.exe" [2008-12-19 342848]
"H/PC Connection Agent"="h:\program files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 1289000]
"swg"="h:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-06-30 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HP Component Manager"="h:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 241664]
"M-Audio Delta Taskbar Icon"="h:\windows\System32\DeltTray.exe" [2004-08-27 56320]
"H2O"="h:\program files\SyncroSoft\Pos\H2O\cledx.exe" [2005-10-23 385024]
"QuickTime Task"="h:\program files\QuickTime\qttask.exe" [2008-02-01 385024]
"AVG8_TRAY"="h:\progra~1\AVG\AVG8\avgtray.exe" [2009-11-03 2028312]
"SunJavaUpdateSched"="h:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"Malwarebytes Anti-Malware (reboot)"="h:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"DeltTray"="DeltTray.exe" - h:\windows\system32\DeltTray.exe [2004-08-27 56320]
"VTTimer"="VTTimer.exe" - h:\windows\system32\VTTimer.exe [2005-03-08 53248]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - h:\windows\system32\narrator.exe [2004-08-04 53760]
h:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - h:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-29 21:38 11952 ----a-w- h:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\startupfolder\H:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
path=h:\documents and settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
backup=h:\windows\pss\Acrobat Assistant.lnkCommon Startup
[HKLM\~\startupfolder\H:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=h:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=h:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Apple Mobile Device"=2 (0x2)
"Bonjour Service"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"h:\\StubInstaller.exe"=
"h:\\Program Files\\LimeWire\\LimeWire.exe"=
"h:\\Program Files\\Messenger\\msmsgs.exe"=
"h:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"h:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"h:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"h:\\Program Files\\BitTorrent\\bittorrent.exe"=
"h:\\Program Files\\DNA\\btdna.exe"=
"h:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"h:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"h:\program files\Microsoft ActiveSync\rapimgr.exe"= h:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"h:\program files\Microsoft ActiveSync\wcescomm.exe"= h:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"h:\program files\Microsoft ActiveSync\WCESMgr.exe"= h:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"h:\\Program Files\\Mozilla Firefox\\firefox.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R0 Lbd;Lbd;h:\windows\system32\drivers\Lbd.sys [11/3/2009 12:52 AM 64288]
R0 xfilt;VIA SATA IDE Hot-plug Driver;h:\windows\system32\drivers\xfilt.sys [2/19/2007 10:31 PM 11264]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;h:\windows\system32\drivers\avgldx86.sys [6/13/2009 4:54 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;h:\windows\system32\drivers\avgtdix.sys [6/13/2009 4:54 PM 108552]
R1 BIOS;BIOS;h:\windows\system32\drivers\BIOS.sys [2/19/2007 10:25 PM 13696]
R2 avg8wd;AVG Free8 WatchDog;h:\progra~1\AVG\AVG8\avgwdsvc.exe [6/13/2009 4:54 PM 297752]
R2 Viewpoint Manager Service;Viewpoint Manager Service;h:\program files\Viewpoint\Common\ViewpointService.exe [4/27/2009 9:40 AM 24652]
R3 CLEDX;Team H2O CLEDX service;h:\windows\system32\drivers\cledx.sys [4/18/2006 7:18 PM 33792]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;h:\program files\Lavasoft\Ad-Aware\AAWService.exe [9/24/2009 6:17 AM 1179232]
S3 ICDUSB2;Sony IC Recorder (ST);h:\windows\system32\drivers\ICDUSB2.sys [11/28/2002 8:23 PM 39048]
--- Other Services/Drivers In Memory ---
*Deregistered* - mbr
*Deregistered* - PROCEXP113
.
Contents of the 'Scheduled Tasks' folder
2009-11-04 h:\windows\Tasks\Ad-Aware Update (Weekly).job
- h:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 05:50]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mStart Page = hxxp://www.google.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - h:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - h:\documents and settings\David\Application Data\Mozilla\Firefox\Profiles\cvuhjv3z.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - nytimes.com
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrab&query=
FF - component: h:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: h:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: h:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: h:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - plugin: h:\program files\Virtual Earth 3D\npVE3D.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-11-04 23:09
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3356)
h:\windows\System32\shdoclc.dll
h:\windows\system32\WPDShServiceObj.dll
h:\windows\system32\PortableDeviceTypes.dll
h:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-11-05 23:12
ComboFix-quarantined-files.txt 2009-11-05 04:11
ComboFix2.txt 2009-11-04 05:41
Pre-Run: 16,994,398,208 bytes free
Post-Run: 16,958,144,512 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
h:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
-----
And the hijackthis log:
---
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:17:42 PM, on 11/4/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
H:\WINDOWS\System32\smss.exe
H:\WINDOWS\system32\winlogon.exe
H:\WINDOWS\system32\services.exe
H:\WINDOWS\system32\lsass.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\system32\spoolsv.exe
H:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
H:\Program Files\Java\jre6\bin\jqs.exe
H:\WINDOWS\System32\svchost.exe
H:\Program Files\HP\hpcoretech\hpcmpmgr.exe
H:\WINDOWS\System32\DeltTray.exe
H:\WINDOWS\system32\VTTimer.exe
H:\Program Files\Viewpoint\Common\ViewpointService.exe
H:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
H:\PROGRA~1\AVG\AVG8\avgrsx.exe
H:\Program Files\Java\jre6\bin\jusched.exe
H:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
H:\Program Files\DNA\btdna.exe
H:\Program Files\Microsoft ActiveSync\Wcescomm.exe
H:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
H:\PROGRA~1\MICROS~3\rapimgr.exe
H:\WINDOWS\System32\svchost.exe
H:\PROGRA~1\AVG\AVG8\avgnsx.exe
H:\WINDOWS\system32\notepad.exe
H:\WINDOWS\explorer.exe
H:\Program Files\Mozilla Firefox\firefox.exe
H:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.com/customize/ie/defaul...rch/search.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - H:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - H:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - H:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - H:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - H:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - H:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - H:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - H:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [HP Component Manager] "H:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [M-Audio Delta Taskbar Icon] H:\WINDOWS\System32\DeltTray.exe
O4 - HKLM\..\Run: [DeltTray] DeltTray.exe
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [H2O] H:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
O4 - HKLM\..\Run: [QuickTime Task] "H:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG8_TRAY] H:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "H:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "H:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [EasyLinkAdvisor] "H:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
O4 - HKCU\..\Run: [BitTorrent DNA] "H:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "H:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [swg] "H:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = H:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://H:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - H:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - H:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - H:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - H:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/...b?1145389590374O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) -
http://nadzmumper.spaces.live.com/PhotoUpload/MsnPUpld.cabO18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - H:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - H:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - H:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Google Software Updater (gusvc) - Google - H:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - H:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - H:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - H:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - H:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - H:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 6677 bytes