Hi,
Panda Active Scan will not work.
ComboFix Log:ComboFix 08-02-16.2 - Rick 2008-02-16 17:44:01.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.150 [GMT 11:00]
Running from: C:\Documents and Settings\Rick\My Documents\Downloads\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Rick\Application Data\Install.dat
C:\RECYCLER\desktopA.sys
C:\WINDOWS\system32\dbxDgrevCheck.dll
C:\WINDOWS\system32\dllgh8jkd1q8.exe
.
((((((((((((((((((((((((( Files Created from 2008-01-16 to 2008-02-16 )))))))))))))))))))))))))))))))
.
2008-02-16 17:44 . 2008-02-16 17:44 0 --a------ C:\WINDOWS\system32\regsvr32.DbgLog
2008-02-16 15:49 . 2008-02-16 17:42 <DIR> d-------- C:\Program Files\SpywareGuard
2008-02-16 15:02 . 2008-02-16 15:02 <DIR> d-------- C:\WINDOWS\LastGood
2008-02-14 22:31 . 2008-02-14 22:31 <DIR> d-------- C:\Program Files\Apple Software Update
2008-02-14 22:31 . 2008-02-14 22:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-02-14 21:32 . 2008-02-14 21:38 <DIR> d-------- C:\I386
2008-02-14 16:10 . 2001-08-17 13:52 26,496 --a--c--- C:\WINDOWS\system32\dllcache\asc.sys
2008-02-14 16:10 . 2001-08-17 13:52 22,400 --a--c--- C:\WINDOWS\system32\dllcache\asc3350p.sys
2008-02-14 16:08 . 2001-08-17 14:07 56,960 --a--c--- C:\WINDOWS\system32\dllcache\aic78xx.sys
2008-02-14 16:08 . 2001-08-17 14:07 55,168 --a--c--- C:\WINDOWS\system32\dllcache\aic78u2.sys
2008-02-14 16:08 . 2004-08-03 22:31 36,224 --a--c--- C:\WINDOWS\system32\dllcache\an983.sys
2008-02-14 16:08 . 2001-08-17 12:11 27,678 --a--c--- C:\WINDOWS\system32\dllcache\ali5261.sys
2008-02-14 16:08 . 2001-08-17 13:49 26,624 --a--c--- C:\WINDOWS\system32\dllcache\alifir.sys
2008-02-14 16:08 . 2001-08-17 12:11 16,969 --a--c--- C:\WINDOWS\system32\dllcache\amb8002.sys
2008-02-14 16:08 . 2001-08-17 13:52 12,800 --a--c--- C:\WINDOWS\system32\dllcache\aha154x.sys
2008-02-14 16:08 . 2001-08-17 13:52 12,032 --a--c--- C:\WINDOWS\system32\dllcache\amsint.sys
2008-02-14 16:08 . 2001-08-17 13:47 6,272 --a--c--- C:\WINDOWS\system32\dllcache\apmbatt.sys
2008-02-14 16:08 . 2001-08-17 13:51 5,248 --a--c--- C:\WINDOWS\system32\dllcache\aliide.sys
2008-02-14 00:25 . 2004-08-04 23:00 119,808 --a------ C:\WINDOWS\system32\winmine.exe
2008-02-14 00:25 . 2004-08-04 23:00 119,808 --a--c--- C:\WINDOWS\system32\dllcache\winmine.exe
2008-02-14 00:21 . 2001-08-17 22:37 24,576 --a--c--- C:\WINDOWS\system32\dllcache\agcgauge.ax
2008-02-14 00:18 . 2001-08-17 14:56 66,048 --a--c--- C:\WINDOWS\system32\dllcache\s3legacy.dll
2008-02-14 00:17 . 2004-08-03 23:18 2,148,352 --a--c--- C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-02-13 23:14 . 2008-02-13 23:17 <DIR> d-------- C:\Program Files\MSECACHE
2008-02-13 18:43 . 2008-02-13 18:49 <DIR> d-------- C:\Documents and Settings\Rick\Application Data\AVG7
2008-02-13 18:43 . 2008-02-13 18:43 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-02-13 18:42 . 2008-02-13 18:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-13 18:42 . 2008-02-15 19:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-02-13 02:30 . 2004-08-04 23:00 2,178,131 --a--c--- C:\WINDOWS\system32\dllcache\shvlres.dll
2008-02-13 02:29 . 2004-08-04 23:00 1,875,968 --a--c--- C:\WINDOWS\system32\dllcache\msir3jp.lex
2008-02-13 02:28 . 2004-08-04 23:00 13,463,552 --a--c--- C:\WINDOWS\system32\dllcache\hwxjpn.dll
2008-02-13 02:27 . 2004-08-04 23:00 1,677,824 --a--c--- C:\WINDOWS\system32\dllcache\chsbrkr.dll
2008-02-13 02:26 . 2004-08-04 23:00 1,817,687 --a--c--- C:\WINDOWS\system32\dllcache\bckgres.dll
2008-02-13 02:24 . 2008-02-13 02:24 488 -rah----- C:\WINDOWS\system32\logonui.exe.manifest
2008-02-13 02:23 . 2008-02-13 02:23 749 -rah----- C:\WINDOWS\WindowsShell.Manifest
2008-02-13 02:23 . 2008-02-13 02:23 749 -rah----- C:\WINDOWS\system32\wuaucpl.cpl.manifest
2008-02-13 02:23 . 2008-02-13 02:23 749 -rah----- C:\WINDOWS\system32\sapi.cpl.manifest
2008-02-13 02:23 . 2008-02-13 02:23 749 -rah----- C:\WINDOWS\system32\ncpa.cpl.manifest
2008-02-13 01:59 . 2004-08-04 23:00 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll
2008-02-13 01:59 . 2004-08-04 23:00 24,661 --a--c--- C:\WINDOWS\system32\dllcache\spxcoins.dll
2008-02-13 01:59 . 2004-08-04 23:00 13,312 --a------ C:\WINDOWS\system32\irclass.dll
2008-02-13 01:59 . 2004-08-04 23:00 13,312 --a--c--- C:\WINDOWS\system32\dllcache\irclass.dll
2008-02-12 22:56 . 2008-02-13 15:38 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-02-12 22:56 . 2008-02-12 22:56 <DIR> d-------- C:\WINDOWS\system32\bits
2008-02-12 22:55 . 2007-03-29 23:56 7,168 --a------ C:\WINDOWS\system32\bitsprx4.dll
2008-02-12 14:57 . 2008-02-13 17:59 <DIR> d-------- C:\Documents and Settings\Rick\Application Data\SUPERAntiSpyware.com
2008-02-12 11:42 . 2008-02-12 11:42 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-02-12 11:42 . 2008-02-12 11:42 1,406 --a------ C:\WINDOWS\system32\Help.ico
2008-02-12 11:15 . 1995-07-31 13:44 212,480 --a------ C:\WINDOWS\pcdlib32.dll
2008-02-12 11:15 . 1997-08-19 21:54 54,272 --a------ C:\WINDOWS\EasyPhoto Slide Show.scr
2008-02-12 11:15 . 1997-06-17 04:00 4,064 --a------ C:\WINDOWS\system32\drivers\ATMHELPR.SYS
2008-02-12 11:15 . 2008-02-12 21:57 810 --a------ C:\WINDOWS\EZPHOTO.INI
2008-02-12 11:14 . 2008-02-12 11:15 <DIR> d-------- C:\Program Files\PhotoDeluxe 2.0
2008-02-11 23:42 . 2008-02-15 18:35 1,440,054 --a------ C:\WINDOWS\ACD Wallpaper.bmp
2008-02-11 21:44 . 2006-04-27 18:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-02-11 21:44 . 2003-06-05 22:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-02-11 20:10 . 2008-02-11 20:11 366 --a------ C:\WINDOWS\wininit.ini
2008-02-11 15:35 . 2008-02-11 15:38 <DIR> d-------- C:\Program Files\Maxtor
2008-02-11 04:00 . 2008-02-11 23:36 502,874,112 --a------ C:\WINDOWS\MEMORY.DMP
2008-02-10 22:46 . 2008-02-10 22:46 88 --a------ C:\WINDOWS\Ejigman2.ini
2008-02-10 22:45 . 2008-02-10 22:45 <DIR> d-------- C:\Program Files\Nodtronics
2008-02-10 17:13 . 2004-08-04 23:00 1,086,058 -ra------ C:\WINDOWS\SET45.tmp
2008-02-10 17:13 . 2004-08-04 23:00 1,042,903 -ra------ C:\WINDOWS\SET42.tmp
2008-02-10 17:13 . 2004-08-04 23:00 13,753 -ra------ C:\WINDOWS\SET51.tmp
2008-02-10 17:12 . 2008-02-12 23:29 371,762 --a------ C:\WINDOWS\setupapi.old
2008-02-07 17:54 . 2008-02-12 23:05 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-01-31 23:13 . 2008-01-31 23:13 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-01-31 23:13 . 2008-01-31 23:13 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
2008-01-27 01:42 . 2004-08-04 23:00 65,978 --a------ C:\WINDOWS\Soap Bubbles.bmp
2008-01-27 01:42 . 2004-08-04 23:00 65,954 --a------ C:\WINDOWS\Prairie Wind.bmp
2008-01-27 01:42 . 2004-08-04 23:00 65,832 --a------ C:\WINDOWS\Santa Fe Stucco.bmp
2008-01-27 01:42 . 2004-08-04 23:00 26,680 --a------ C:\WINDOWS\River Sumida.bmp
2008-01-27 01:42 . 2004-08-04 23:00 26,582 --a------ C:\WINDOWS\Greenstone.bmp
2008-01-27 01:42 . 2004-08-04 23:00 17,362 --a------ C:\WINDOWS\Rhododendron.bmp
2008-01-27 01:42 . 2004-08-04 23:00 17,336 --a------ C:\WINDOWS\Gone Fishing.bmp
2008-01-27 01:42 . 2004-08-04 23:00 17,062 --a------ C:\WINDOWS\Coffee Bean.bmp
2008-01-27 01:42 . 2004-08-04 23:00 16,730 --a------ C:\WINDOWS\FeatherTexture.bmp
2008-01-27 01:42 . 2004-08-04 23:00 9,522 --a------ C:\WINDOWS\Zapotec.bmp
2008-01-27 01:32 . 2004-08-04 23:00 1,086,058 -ra------ C:\WINDOWS\SETB7.tmp
2008-01-27 01:32 . 2004-08-04 23:00 1,042,903 -ra------ C:\WINDOWS\SETB4.tmp
2008-01-27 01:32 . 2004-08-04 23:00 13,753 -ra------ C:\WINDOWS\SETC3.tmp
2008-01-27 01:32 . 2004-08-04 23:00 7,334 --a--c--- C:\WINDOWS\system32\dllcache\wmerrenu.cat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-14 11:50 5,632 --sha-w C:\Program Files\Thumbs.db
2008-02-14 11:34 --------- d-----w C:\Program Files\QuickTime Alternative
2008-02-14 11:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-02-12 00:15 --------- d-----w C:\Program Files\Adobe Type Manager
2008-02-11 10:47 --------- d-----w C:\Documents and Settings\Rick\Application Data\Canon
2008-02-10 11:45 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-09 06:39 --------- d-----w C:\Documents and Settings\Rick\Application Data\IEPro
2008-01-03 03:59 44,544 ----a-w C:\WINDOWS\AWuninstall.exe
2007-12-19 06:44 --------- d-----w C:\Program Files\Lavasoft
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 23:00 15360]
"zTrashReg"="c:\trashkeys\trashreg.exe" [2006-12-11 20:16 211705]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Smapp"="C:\Program Files\Analog Devices\SoundMAX\SMTray.exe" [2003-05-05 08:57 143360]
"SiSPower"="SiSPower.dll" [2004-09-02 13:47 49152 C:\WINDOWS\system32\SiSPower.dll]
"SiSUSBRG"="C:\WINDOWS\SiSUSBrg.exe" [2002-07-12 18:15 106496]
"EPSON Stylus Photo R310 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3F2.exe" [2003-09-11 14:00 99840]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" [2006-12-15 03:23 75520]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 17:40 155648]
"InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [2005-07-25 13:01 1397760]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-02-13 18:44 579072]
"QuickTime Task"="C:\Program Files\QuickTime Alternative\QTTask.exe" [2008-01-31 23:13 385024]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 23:00 15360]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 01:01 437160]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-13 18:42 219136]
C:\Documents and Settings\Rick\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-03-06 21:45:14 113664]
SpywareGuard.lnk - C:\Program Files\SpywareGuard\sgmain.exe [2003-08-29 19:05:35 360448]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
hueyTray.lnk - C:\Program Files\Pantone\huey\hueyTray.exe [2007-06-06 16:27:35 913408]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-03-22 12:00:00 65588]
Utility Tray.lnk - C:\WINDOWS\system32\sistray.exe [2007-03-05 16:01:04 331776]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\
0]
Source= file:///C:\WINDOWS\privacy_danger\index.htm
FriendlyName= Privacy Protection
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Scanner Finder.lnk]
backup=C:\WINDOWS\pss\Scanner Finder.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MaxtorOneTouch]
--a------ 2006-08-11 08:45 712704 C:\Program Files\Maxtor\ManagerApp\Onetouch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mxomssmenu]
--a------ 2006-08-11 11:15 81920 C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
R1 ATMhelpr;ATMhelpr;C:\WINDOWS\system32\drivers\ATMhelpr.sys [1997-06-17 04:00]
R2 DriverX;DriverX;C:\WINDOWS\system32\drivers\DriverX.sys [1997-03-12 23:57]
S2 BulkUsb;USB Film Scanner;C:\WINDOWS\system32\Drivers\usbscan.sys [2004-08-03 23:58]
S3 AshAVMon;AshAVMon;C:\Program Files\Ashampoo\Ashampoo AntiVirus\ASHAVMON.SYS []
S3 SISNICXP;SiS PCI Fast Ethernet Adapter Driver for NDIS51;C:\WINDOWS\system32\DRIVERS\sisnicxp.sys [2006-02-14 17:02]
.
Contents of the 'Scheduled Tasks' folder
"2008-02-14 11:32:08 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-02-16 17:46:00
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-02-16 17:46:54
ComboFix-quarantined-files.txt 2008-02-16 06:46:21
2008-02-15 13:24:40 --- E O F ---
ComboFix-quarantined-files Log:2007-06-08 17:36 1024 --a------ C:\Qoobox\Quarantine\C\RECYCLER\desktopA.sys.vir
2007-09-07 16:18 254000 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\dbxDgrevCheck.dll.vir
2008-02-11 18:32 17 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\dllgh8jkd1q8.exe.vir
2008-02-11 18:33 1175372 --a------ C:\Qoobox\Quarantine\C\Documents and Settings\Rick\Application Data\Install.dat.vir
hijackthis Log:Logfile of HijackThis v1.99.1
Scan saved at 6:05:13 PM, on 16/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe
C:\Program Files\Maxtor\Utils\SyncServices.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3F2.EXE
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Pantone\huey\hueyTray.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.tsninternet.com.au/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O1 - Hosts: 124.217.252.77 www.bravesentry.com
O1 - Hosts: 124.217.252.77 bravesentry.com
O1 - Hosts: 124.217.252.78 secure.isoftpay.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {206E52E0-D52E-11D4-AD54-0000E86C26F6} - C:\PROGRA~1\FRESHD~1\FRESHD~1\FDCatch.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O3 - Toolbar: FreshDownload Bar - {ED0E8CA5-42FB-4B18-997B-769E0408E79D} - C:\PROGRA~1\FRESHD~1\FRESHD~1\fdiebar.dll
O3 - Toolbar: (no name) - {D6F180CB-E683-41a3-8CD2-C53DBAA0530D} - (no file)
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo R310 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3F2.EXE /P30 "EPSON Stylus Photo R310 Series" /O6 "USB001" /M "Stylus Photo R310"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime Alternative\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [zTrashReg] c:\trashkeys\trashreg.exe /AUTO
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: hueyTray.lnk = C:\Program Files\Pantone\huey\hueyTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O9 - Extra button: FreshDownload - {CE5E0488-E808-4DB5-A2E1-02F2727C3542} - C:\Program Files\FreshDevices\FreshDownload\fd.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) -
http://utilities.pcp...a/PCPitStop.CABO16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.syma...n/bin/cabsa.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.micros...b?1179467858265O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.m...ash/swflash.cabO20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: MaxBackServiceInt - Unknown owner - C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: MaxSyncService (NTService1) - - C:\Program Files\Maxtor\Utils\SyncServices.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
Regards