ComboFix 08-01-05.1 - Van 2008-01-10 12:56:51.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1627 [GMT -8:00]
Running from: C:\Documents and Settings\Van\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Van\Desktop\CFScript.txt
* Created a new restore point
FILE
C:\Program Files\Common Files\System\$sys$explorer.exe
C:\WINDOWS\system32\rhuexpsy.ini
C:\WINDOWS\system32\ssqrr.dll
C:\WINDOWS\system32\ssqrr.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\AIM\aim.exe
C:\Program Files\Common Files\System\$sys$explorer.exe
C:\Program Files\Winamp\winamp .exe
C:\WINDOWS\system32\rhuexpsy.ini
C:\WINDOWS\system32\rrqss.ini
C:\WINDOWS\system32\rrqss.ini2
C:\WINDOWS\system32\ssqrr.dll
C:\WINDOWS\system32\ssqrr.exe
<pre>
"C:\Program Files\Winamp\winamp .exe" moved to QooBox
</pre>
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_EXPLORER
-------\Explorer
((((((((((((((((((((((((( Files Created from 2007-12-10 to 2008-01-10 )))))))))))))))))))))))))))))))
.
2008-01-09 00:03 . 2008-01-09 00:03 <DIR> d-------- C:\My Downloads
2008-01-09 00:02 . 2008-01-09 00:05 <DIR> d-------- C:\Program Files\BearShare
2008-01-08 19:44 . 2008-01-08 19:44 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-08 19:44 . 2008-01-08 19:44 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-05 16:25 . 2008-01-05 16:25 <DIR> d-------- C:\Deckard
2008-01-04 19:37 . 2008-01-04 19:37 <DIR> d-------- C:\Program Files\MemTurbo30
2008-01-04 19:32 . 2008-01-07 00:05 <DIR> d-------- C:\Program Files\DAEMON Tools Lite
2008-01-04 19:12 . 2008-01-04 19:13 391 --a------ C:\WINDOWS\system32\d-delA.dat
2008-01-04 19:12 . 2008-01-04 19:12 0 --a------ C:\WINDOWS\system32\V-FilesB.dat
2008-01-04 17:40 . 2008-01-04 17:40 661,159 --a------ C:\catchme2008-01-04_190812.04.zip
2008-01-04 17:35 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-02 22:10 . 2008-01-04 16:32 <DIR> d-------- C:\Program Files\Power MP3 WMA Converter
2008-01-02 04:17 . 2008-01-04 17:30 403 --a------ C:\WINDOWS\wininit.ini
2008-01-02 01:55 . 2008-01-10 10:26 <DIR> d-------- C:\Temp
2007-12-31 18:29 . 2007-12-31 18:29 1 --a------ C:\WINDOWS\system32\DJ Doboy - Trancequility Megamix Volume 31.cue
2007-12-31 03:37 . 2007-12-31 03:37 <DIR> dr-h----- C:\Documents and Settings\Van\Application Data\SecuROM
2007-12-31 03:37 . 2007-12-31 03:37 107,888 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2007-12-31 03:29 . 2007-12-31 03:29 <DIR> d-------- C:\Program Files\Flagship Studios
2007-12-31 02:42 . 2007-12-31 02:42 <DIR> d-------- C:\Documents and Settings\Van\Application Data\Syntrillium
2007-12-31 02:42 . 2001-10-19 14:40 1,683,792 --a------ C:\WINDOWS\system32\wmvcore2.dll
2007-12-31 02:42 . 2001-10-19 14:40 665,424 --a------ C:\WINDOWS\system32\wmv8dmoe.dll
2007-12-31 02:42 . 2001-10-19 14:39 572,752 --a------ C:\WINDOWS\system32\wmvdmoe.dll
2007-12-31 02:42 . 2001-10-19 14:40 438,608 --a------ C:\WINDOWS\system32\wmv8dmod.dll
2007-12-31 02:42 . 2001-10-19 02:05 285,184 --a------ C:\WINDOWS\system32\wmidx2.ocx
2007-12-31 02:42 . 2007-12-31 02:42 156,910 --a------ C:\WINDOWS\WMSysPr8.prx
2007-12-31 02:41 . 2007-12-31 02:43 <DIR> d-------- C:\Program Files\coolpro2
2007-12-29 00:29 . 2007-12-29 00:29 <DIR> d-------- C:\Program Files\DivX
2007-12-28 01:46 . 2008-01-02 22:31 <DIR> d-------- C:\Documents and Settings\Van\Application Data\BearShare
2007-12-28 01:46 . 2006-11-12 11:39 483,328 --a------ C:\WINDOWS\system32\actskn45.ocx
2007-12-27 22:38 . 2007-12-27 22:38 <DIR> d-------- C:\Program Files\Sega
2007-12-27 22:30 . 2007-05-16 16:45 3,497,832 --a------ C:\WINDOWS\system32\d3dx9_34.dll
2007-12-27 22:30 . 2007-05-16 16:45 1,124,720 --a------ C:\WINDOWS\system32\D3DCompiler_34.dll
2007-12-27 22:30 . 2007-05-16 16:45 443,752 --a------ C:\WINDOWS\system32\d3dx10_34.dll
2007-12-27 22:30 . 2007-06-20 20:46 266,088 --a------ C:\WINDOWS\system32\xactengine2_8.dll
2007-12-27 22:30 . 2007-06-20 20:45 18,280 --a------ C:\WINDOWS\system32\x3daudio1_2.dll
2007-12-27 22:29 . 2007-12-27 22:29 <DIR> d-------- C:\WINDOWS\system32\xlive
2007-12-27 22:29 . 2007-03-12 16:42 3,495,784 --a------ C:\WINDOWS\system32\d3dx9_33.dll
2007-12-27 22:29 . 2007-03-12 16:42 1,123,696 --a------ C:\WINDOWS\system32\D3DCompiler_33.dll
2007-12-27 22:29 . 2007-03-15 16:57 443,752 --a------ C:\WINDOWS\system32\d3dx10_33.dll
2007-12-27 22:29 . 2007-04-04 18:53 81,768 --a------ C:\WINDOWS\system32\xinput1_3.dll
2007-12-27 22:14 . 2008-01-04 19:32 <DIR> d-------- C:\Documents and Settings\Van\Application Data\DAEMON Tools
2007-12-27 22:12 . 2007-12-27 22:12 715,248 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2007-12-26 23:33 . 2007-12-26 23:33 <DIR> d-------- C:\nvram
2007-12-26 15:55 . 2007-12-26 15:55 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-12-26 14:44 . 2007-12-26 15:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-26 14:43 . 2007-12-26 14:43 <DIR> d-------- C:\Program Files\Lavasoft
2007-12-26 14:43 . 2007-12-26 14:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-12-26 14:08 . 2007-12-26 14:08 <DIR> d-------- C:\Program Files\Bonjour
2007-12-26 14:03 . 2007-12-26 14:03 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2007-12-26 11:58 . 2007-12-26 11:58 <DIR> d-------- C:\Program Files\Stardock
2007-12-26 11:46 . 2007-12-26 11:47 81 --------- C:\WINDOWS\WB.ini
2007-12-26 11:25 . 2007-07-11 15:06 42,672 --a------ C:\WINDOWS\system32\wbsys.dll
2007-12-26 11:18 . 2001-08-17 13:56 7,552 --a------ C:\WINDOWS\system32\drivers\SONYPVU1.SYS
2007-12-26 11:18 . 2001-08-17 13:56 7,552 --a--c--- C:\WINDOWS\system32\dllcache\sonypvu1.sys
2007-12-25 18:47 . 2007-12-25 18:47 <DIR> d-------- C:\Documents and Settings\Van\Application Data\Media Player Classic
2007-12-25 18:44 . 2007-12-25 18:44 <DIR> d-------- C:\Program Files\Real Alternative
2007-12-25 18:43 . 2007-12-25 18:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-12-25 18:43 . 2007-12-11 10:57 65,536 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2007-12-25 18:43 . 2007-12-11 10:57 49,152 --a------ C:\WINDOWS\system32\QuickTime.qts
2007-12-25 18:42 . 2007-12-25 18:42 <DIR> d-------- C:\Program Files\Xvid
2007-12-25 18:42 . 2007-12-25 18:43 <DIR> d-------- C:\Program Files\QuickTime Alternative
2007-12-25 18:42 . 2007-06-28 18:55 77,824 --a------ C:\WINDOWS\system32\xvid.ax
2007-12-25 18:39 . 2007-12-25 18:39 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2007-12-25 15:37 . 2007-12-25 15:37 <DIR> d-------- C:\Program Files\Common Files\Blizzard Entertainment
2007-12-25 15:28 . 2008-01-10 10:24 <DIR> d-------- C:\Program Files\World of Warcraft
2007-12-25 15:20 . 2007-12-25 15:21 <DIR> d-------- C:\Documents and Settings\Van\Application Data\Ventrilo
2007-12-25 15:16 . 2007-12-26 16:03 <DIR> d-------- C:\Program Files\Common Files\Adobe
2007-12-25 15:11 . 2007-12-25 15:11 <DIR> d-------- C:\Program Files\BitTornado
2007-12-25 15:11 . 2007-12-25 15:11 <DIR> d-------- C:\Documents and Settings\Van\Application Data\.BitTornado
2007-12-25 13:59 . 2007-12-25 14:00 <DIR> d-------- C:\WINDOWS\system32\MsDtc
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-10 20:58 --------- d-----w C:\Program Files\Winamp
2008-01-10 20:58 --------- d-----w C:\Program Files\AIM
2008-01-10 18:28 1,626,112 ----a-w C:\WINDOWS\system32\nwiz.exe
2008-01-05 03:21 --------- d-----w C:\Program Files\AOD
2007-12-28 06:47 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-26 22:43 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-25 23:11 --------- d-----w C:\Documents and Settings\Van\Application Data\.BitTornado
2007-12-25 23:06 --------- d-----w C:\Documents and Settings\Van\Application Data\Winamp
2007-12-25 22:55 --------- d-----w C:\Program Files\Ventrilo
2007-12-25 22:52 315,392 ----a-w C:\WINDOWS\HideWin.exe
2007-12-25 22:52 --------- d-----w C:\Program Files\Realtek
2007-12-25 22:20 --------- d-----w C:\Program Files\AWS
2007-12-25 22:20 --------- d-----w C:\Documents and Settings\Van\Application Data\Aim
2007-12-25 22:19 --------- d-----w C:\Program Files\Viewpoint
2007-12-25 22:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-12-25 22:15 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-12-25 22:13 --------- d-----w C:\Program Files\Intel
2007-12-25 22:09 --------- d-----w C:\Program Files\Avant Browser
2007-12-25 22:09 --------- d-----w C:\Documents and Settings\Van\Application Data\Avant Profiles
2007-12-25 22:04 --------- d-----w C:\Program Files\microsoft frontpage
2007-12-08 02:28 7,680 ----a-w C:\WINDOWS\system32\ff_vfw.dll
2007-12-05 10:53 356,352 ----a-w C:\WINDOWS\system32\NVUNINST.EXE
2007-12-05 09:41 81,920 ----a-w C:\WINDOWS\system32\nvwddi.dll
2007-12-05 09:41 81,920 ----a-w C:\WINDOWS\system32\nvmctray.dll
2007-12-05 09:41 8,523,776 ----a-w C:\WINDOWS\system32\nvcpl.dll
2007-12-05 09:41 753,664 ----a-w C:\WINDOWS\system32\nvcplui.exe
2007-12-05 09:41 7,435,392 ----a-w C:\WINDOWS\system32\drivers\nv4_mini.sys
2007-12-05 09:41 6,901,760 ----a-w C:\WINDOWS\system32\nvoglnt.dll
2007-12-05 09:41 6,549,504 ----a-w C:\WINDOWS\system32\nvdisps.dll
2007-12-05 09:41 5,773,568 ----a-w C:\WINDOWS\system32\nv4_disp.dll
2007-12-05 09:41 466,944 ----a-w C:\WINDOWS\system32\nvshell.dll
2007-12-05 09:41 45,056 ----a-w C:\WINDOWS\system32\nvmccsrs.dll
2007-12-05 09:41 442,368 ----a-w C:\WINDOWS\system32\nvappbar.exe
2007-12-05 09:41 425,984 ----a-w C:\WINDOWS\system32\keystone.exe
2007-12-05 09:41 385,024 ----a-w C:\WINDOWS\system32\nvapi.dll
2007-12-05 09:41 356,352 ----a-w C:\WINDOWS\system32\nvudisp.exe
2007-12-05 09:41 35,328 ----a-w C:\WINDOWS\system32\nvcodins.dll
2007-12-05 09:41 35,328 ----a-w C:\WINDOWS\system32\nvcod.dll
2007-12-05 09:41 307,200 ----a-w C:\WINDOWS\system32\nvexpbar.dll
2007-12-05 09:41 3,710,976 ----a-w C:\WINDOWS\system32\nvvitvs.dll
2007-12-05 09:41 3,420,160 ----a-w C:\WINDOWS\system32\nvgames.dll
2007-12-05 09:41 286,720 ----a-w C:\WINDOWS\system32\nvnt4cpl.dll
2007-12-05 09:41 229,376 ----a-w C:\WINDOWS\system32\nvmccs.dll
2007-12-05 09:41 2,498,560 ----a-w C:\WINDOWS\system32\nvwss.dll
2007-12-05 09:41 188,416 ----a-w C:\WINDOWS\system32\nvmccss.dll
2007-12-05 09:41 155,716 ----a-w C:\WINDOWS\system32\nvsvc32.exe
2007-12-05 09:41 147,456 ----a-w C:\WINDOWS\system32\nvcolor.exe
2007-12-05 09:41 1,703,936 ----a-w C:\WINDOWS\system32\nvwdmcpl.dll
2007-12-05 09:41 1,474,560 ----a-w C:\WINDOWS\system32\nview.dll
2007-12-05 09:41 1,339,392 ----a-w C:\WINDOWS\system32\nvdspsch.exe
2007-12-05 09:41 1,228,800 ----a-w C:\WINDOWS\system32\nvmobls.dll
2007-12-05 09:41 1,089,536 ----a-w C:\WINDOWS\system32\nvcuda.dll
2007-12-05 09:41 1,019,904 ----a-w C:\WINDOWS\system32\nvwimg.dll
2007-12-04 10:33 682,496 ----a-w C:\WINDOWS\system32\divx.dll
2007-11-30 07:30 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-11-30 07:28 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-11-29 22:30 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2007-11-29 22:30 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-10-13 07:19 13,653,824 ----a-w C:\WINDOWS\system32\xlivefnt.dll
2007-10-13 07:19 10,155,840 ----a-w C:\WINDOWS\system32\xlive.dll
.
((((((((((((((((((((((((((((( snapshot@2008-01-07_ 0.09.14.43 )))))))))))))))))))))))))))))))))))))))))
.
+ 2001-08-17 22:55:56 6,144 -c--a-w C:\WINDOWS\system32\dllcache\kbd101b.dll
+ 2001-08-17 22:55:56 6,144 -c--a-w C:\WINDOWS\system32\dllcache\kbd101c.dll
+ 2001-08-17 22:55:56 5,632 -c--a-w C:\WINDOWS\system32\dllcache\kbd103.dll
+ 2001-08-17 22:55:56 6,144 -c--a-w C:\WINDOWS\system32\dllcache\kbd106.dll
+ 2001-08-18 06:36:18 8,704 -c--a-w C:\WINDOWS\system32\dllcache\kbdjpn.dll
+ 2001-08-18 06:36:18 8,192 -c--a-w C:\WINDOWS\system32\dllcache\kbdkor.dll
+ 2001-08-17 22:55:56 6,144 ----a-w C:\WINDOWS\system32\kbd101b.dll
+ 2001-08-17 22:55:56 6,144 ----a-w C:\WINDOWS\system32\kbd101c.dll
+ 2001-08-17 22:55:56 5,632 ----a-w C:\WINDOWS\system32\kbd103.dll
+ 2001-08-17 22:55:56 6,144 ----a-w C:\WINDOWS\system32\kbd106.dll
+ 2001-08-18 06:36:18 8,704 ----a-w C:\WINDOWS\system32\kbdjpn.dll
+ 2001-08-18 06:36:18 8,192 ----a-w C:\WINDOWS\system32\kbdkor.dll
+ 2004-08-04 12:00:00 708,096 ----a-w C:\WINDOWS\system32\ntdll.dll
+ 2004-08-04 12:00:00 708,096 ----a-w C:\WINDOWS\system32\ntdll.dll.vir
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [ ]
"AIM"="C:\Program Files\AIM\aim.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 01:41 8523776]
"nwiz"="nwiz.exe" [2008-01-10 10:28 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 01:41 81920]
"RTHDCPL"="RTHDCPL.EXE" [2007-02-26 15:03 16125440 C:\WINDOWS\RTHDCPL.exe]
C:\Documents and Settings\Van\Start Menu\Programs\Startup\
MemTurbo.lnk - C:\Program Files\MemTurbo30\MemTurbo.exe [2008-01-04 19:37:30]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll 2007-12-26 12:13 229376 C:\Program Files\Stardock\Object Desktop\WindowBlinds\WbSrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wbsys.dll
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-01-10 13:00:00
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.2180]
-> C:\Program Files\Stardock\Object Desktop\WindowBlinds\tray.dll
.
Completion time: 2008-01-10 13:01:09 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-10 21:01:07
ComboFix2.txt 2008-01-10 18:31:06
ComboFix3.txt 2008-01-07 08:09:40
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:21:07 PM, on 1/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\MemTurbo30\MemTurbo.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Avant Browser\avant.exe
C:\Documents and Settings\Van\Desktop\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.daemon-search.com/startpageR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe"
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Startup: MemTurbo.lnk = C:\Program Files\MemTurbo30\MemTurbo.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.mi...b?1198621337000O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) -
http://download.divx...owserPlugin.cabO23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 3320 bytes