Here are the 2 logs required, thx very much for taking the time to help me
COMBOFIX LOG:
ComboFix 08-06-12.2 - Administrator 2008-06-15 12:17:55.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.950.1.1028.18.1662 [GMT 8:00]
Running From: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Administrator\Desktop\CFScript.txt
* New Reset point created
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!FILE ::
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\cusbohcn.sys
C:\kdy.cmd
C:\WINDOWS\system32\jvvo0.dll
C:\WINDOWS\system32\jvvo1.dll
C:\WINDOWS\system32\kxvo0.dll
C:\WINDOWS\system32\kxvo1.dll
.
(((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\kdy.cmd
C:\WINDOWS\system32\jvvo0.dll
C:\WINDOWS\system32\jvvo1.dll
C:\WINDOWS\system32\kxvo0.dll
C:\WINDOWS\system32\kxvo1.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CUSBOHCN
-------\Service_cusbohcn
(((((((((((((((((((((((((((( Files Created from 2008-05-15 to 2008-06-15 )))))))))))))))))))))))))))))))))
.
2008-06-15 12:14 . 2008-06-15 12:14 268 --ah----- C:\sqmdata16.sqm
2008-06-15 12:14 . 2008-06-15 12:14 244 --ah----- C:\sqmnoopt16.sqm
2008-06-15 12:12 . 2008-06-15 12:12 268 --ah----- C:\sqmdata15.sqm
2008-06-15 12:12 . 2008-06-15 12:12 244 --ah----- C:\sqmnoopt15.sqm
2008-06-14 17:58 . 2008-06-14 17:58 268 --ah----- C:\sqmdata14.sqm
2008-06-14 17:58 . 2008-06-14 17:58 244 --ah----- C:\sqmnoopt14.sqm
2008-06-14 13:14 . 2008-06-14 13:14 268 --ah----- C:\sqmdata13.sqm
2008-06-14 13:14 . 2008-06-14 13:14 244 --ah----- C:\sqmnoopt13.sqm
2008-06-14 13:13 . 2008-06-14 13:13 <DIR> d-------- C:\WINDOWS\system32\xircom
2008-06-14 13:13 . 2008-06-14 13:13 <DIR> d-------- C:\WINDOWS\system32\oobe
2008-06-14 13:13 . 2008-06-14 13:13 <DIR> d-------- C:\WINDOWS\srchasst
2008-06-14 13:13 . 2008-06-14 13:13 <DIR> d-------- C:\Program Files\microsoft frontpage
2008-06-14 11:14 . 2008-06-14 11:14 <DIR> d-------- C:\_OTMoveIt
2008-06-14 11:01 . 2008-06-14 11:01 268 --ah----- C:\sqmdata12.sqm
2008-06-14 11:01 . 2008-06-14 11:01 244 --ah----- C:\sqmnoopt12.sqm
2008-06-14 00:13 . 2008-06-14 00:13 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-14 00:08 . 2008-06-14 00:09 <DIR> d-------- C:\Program Files\Panda Security
2008-06-14 00:03 . 2008-06-14 00:03 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-14 00:03 . 2008-06-14 00:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-14 00:03 . 2008-06-14 00:03 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2008-06-14 00:03 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-14 00:03 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-14 00:02 . 2008-06-14 00:02 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-06-13 12:59 . 2008-06-13 12:59 268 --ah----- C:\sqmdata11.sqm
2008-06-13 12:59 . 2008-06-13 12:59 244 --ah----- C:\sqmnoopt11.sqm
2008-06-12 13:32 . 2008-06-12 13:32 268 --ah----- C:\sqmdata10.sqm
2008-06-12 13:32 . 2008-06-12 13:32 244 --ah----- C:\sqmnoopt10.sqm
2008-06-12 13:28 . 2007-08-13 18:54 33,792 --a------ C:\WINDOWS\system32\dllcache\custsat.dll
2008-06-12 11:13 . 2008-06-12 11:19 763 --a------ C:\WINDOWS\wininit.ini
2008-06-12 10:55 . 2008-06-13 17:58 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-12 10:55 . 2005-04-15 20:58 1,071,088 --a------ C:\WINDOWS\system32\MSCOMCTL.OCX
2008-06-12 10:55 . 2005-08-25 19:18 118,784 --a------ C:\WINDOWS\system32\MSSTDFMT.DLL
2008-06-12 10:52 . 2008-06-12 10:52 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-06-12 10:52 . 2008-06-12 11:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-12 01:52 . 2008-06-12 01:52 118 --a------ C:\WINDOWS\system32\MRT.INI
2008-06-12 01:51 . 2008-06-12 01:51 268 --ah----- C:\sqmdata09.sqm
2008-06-12 01:51 . 2008-06-12 01:51 244 --ah----- C:\sqmnoopt09.sqm
2008-06-11 14:56 . 2008-05-08 20:28 202,752 --------- C:\WINDOWS\system32\dllcache\rmcast.sys
2008-06-11 14:55 . 2008-04-14 23:51 269,568 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 14:55 . 2008-04-14 23:51 269,568 --------- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-10 01:53 . 2008-06-10 04:25 732,985,344 --a------ C:\Kung.Fu.Panda.TS.XViD-mvs [BTarena.org].avi
2008-06-09 13:20 . 2008-06-09 13:20 268 --ah----- C:\sqmdata08.sqm
2008-06-09 13:20 . 2008-06-09 13:20 244 --ah----- C:\sqmnoopt08.sqm
2008-06-08 12:10 . 2008-06-08 12:10 268 --ah----- C:\sqmdata07.sqm
2008-06-08 12:10 . 2008-06-08 12:10 244 --ah----- C:\sqmnoopt07.sqm
2008-06-05 21:20 . 2008-06-05 21:20 268 --ah----- C:\sqmdata06.sqm
2008-06-05 21:20 . 2008-06-05 21:20 244 --ah----- C:\sqmnoopt06.sqm
2008-05-31 13:41 . 2008-05-31 13:41 268 --ah----- C:\sqmdata05.sqm
2008-05-31 13:41 . 2008-05-31 13:41 244 --ah----- C:\sqmnoopt05.sqm
2008-05-30 18:07 . 2008-05-30 18:07 268 --ah----- C:\sqmdata04.sqm
2008-05-30 18:07 . 2008-05-30 18:07 244 --ah----- C:\sqmnoopt04.sqm
2008-05-27 23:26 . 2008-05-27 23:26 268 --ah----- C:\sqmdata03.sqm
2008-05-27 23:26 . 2008-05-27 23:26 244 --ah----- C:\sqmnoopt03.sqm
2008-05-24 23:53 . 2008-05-24 23:53 268 --ah----- C:\sqmdata02.sqm
2008-05-24 23:53 . 2008-05-24 23:53 244 --ah----- C:\sqmnoopt02.sqm
2008-05-23 10:07 . 2008-05-23 10:07 268 --ah----- C:\sqmdata01.sqm
2008-05-23 10:07 . 2008-05-23 10:07 244 --ah----- C:\sqmnoopt01.sqm
.
(((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-15 04:03 --------- d-----w C:\Documents and Settings\Administrator\Application Data\AVG7
2008-06-14 02:51 20,992 ----a-w C:\WINDOWS\system32\drivers\vga.sys
2008-06-10 02:20 --------- d-----w C:\Documents and Settings\Administrator\Application Data\uTorrent
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:14 1,269,248 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-07 05:14 1,269,248 ------w C:\WINDOWS\system32\dllcache\quartz.dll
2008-05-02 10:50 --------- d-----w C:\Program Files\Windows Live
2008-04-23 14:16 3,591,680 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-04-22 07:39 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-04-22 07:38 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-04-22 07:38 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-04-21 07:01 473,088 ------w C:\WINDOWS\system32\dllcache\shlwapi.dll
2008-04-21 07:01 150,016 ------w C:\WINDOWS\system32\dllcache\cdfview.dll
2008-04-21 07:01 1,494,016 ------w C:\WINDOWS\system32\dllcache\shdocvw.dll
2008-04-21 07:01 1,049,088 ------w C:\WINDOWS\system32\dllcache\danim.dll
2008-04-21 07:01 1,023,488 ------w C:\WINDOWS\system32\dllcache\browseui.dll
2008-04-20 05:07 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2008-03-25 04:49 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:49 621,344 ------w C:\WINDOWS\system32\dllcache\mswstr10.dll
2008-03-25 04:49 158,496 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-25 04:49 158,496 ------w C:\WINDOWS\system32\dllcache\msjint40.dll
2008-03-20 08:03 1,844,864 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-20 08:03 1,844,864 ------w C:\WINDOWS\system32\dllcache\win32k.sys
2006-06-23 06:48 32,768 ----a-r C:\WINDOWS\inf\UpdateUSB.exe
.
------- Sigcheck -------
2007-05-20 10:33 573440 fdef087c4231d694376835423612a3ad C:\WINDOWS\system32\user32.dll
2007-05-20 10:33 2017280 fdd3edac0deb70b0353f683bda6913c4 C:\WINDOWS\system32\ntkrnlpa.exe
2007-05-20 10:33 2137600 e95edb1b0167492b734fcea7b95f36e8 C:\WINDOWS\system32\ntoskrnl.exe
.
((((((((((((((((((((((((((((( snapshot@2008-06-14_11.23.27.40 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-14 02:49:49 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-15 04:19:52 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2005-10-20 12:02:28 163,328 ----a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
.
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2007-05-20 10:33 15360]
"AlcoholAutomount"="E:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" [2007-12-22 15:23 221568]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-11-07 15:34 3739672]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2007-05-20 10:33 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2007-05-20 10:33 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2007-05-20 10:33 455168]
"RTHDCPL"="RTHDCPL.EXE" [2007-03-21 14:49 16126464 C:\WINDOWS\RTHDCPL.exe]
"WinampAgent"="E:\Winamp\winampa.exe" [ ]
"!AVG Anti-Spyware"="D:\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 17:25 6731312]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-17 09:02 579584]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 01:41 8523776]
"nwiz"="nwiz.exe" [2007-12-05 01:41 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 01:41 81920]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="ctfmon.exe" [2007-05-20 10:33 15360 C:\WINDOWS\system32\ctfmon.exe]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-25 21:30 219136]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2008-04-23 12:16 124928 C:\WINDOWS\system32\advpack.dll]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoDesktopCleanupWizard"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"D:\\Electronic Arts\\game.dat"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"D:\\Program Files\\Unreal Tournament 3\\Binaries\\UT3.exe"=
"D:\\Program Files\\Microsoft Games\\Age of Empires III\\age3x.exe"=
"E:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"F:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"F:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Warlords\\Civ4Warlords.exe"=
"F:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Warlords\\Civ4Warlords_PitBoss.exe"=
"F:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword.exe"=
"F:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword_PitBoss.exe"=
"F:\\Program Files\\Sierra Entertainment\\Empire Earth III\\EE3.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R0 mv61xx;mv61xx;C:\WINDOWS\system32\DRIVERS\mv61xx.sys [2007-02-09 20:24]
R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;C:\WINDOWS\system32\DRIVERS\atl01_xp.sys [2007-03-15 14:12]
S3 asusgsb;ASUS Virtual Video Capture Device Driver;C:\WINDOWS\system32\drivers\asusgsb.sys [2007-07-12 10:03]
S3 MBAMCatchMe;MBAMCatchMe;C:\WINDOWS\system32\drivers\mbamcatchme.sys [2008-06-10 19:02]
S3 Video3D;ASUS Video3D Service;C:\WINDOWS\system32\Drivers\Video3D32.sys []
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-06-15 12:20:20
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\conime.exe
D:\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\nvsvc32.exe
E:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2008-06-15 12:22:16 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-15 04:22:14
ComboFix2.txt 2008-06-14 03:23:34
Pre-run: 27,357,171,712 bytes free
Post-run: 27,309,068,288 bytes free
210 --- E O F --- 2008-06-12 14:14:41
NEW HIJACKTHIS LOG:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 下午 12:29:47, on 2008/6/15
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\conime.exe
D:\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\nvsvc32.exe
E:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\RTHDCPL.EXE
D:\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [WinampAgent] E:\Winamp\winampa.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "D:\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AlcoholAutomount] "E:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] ctfmon.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [ctfmon.exe] ctfmon.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] ctfmon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] ctfmon.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O15 - ESC Trusted Zone:
http://*.update.microsoft.comO23 - Service: ATK Keyboard Service (ATKKeyboardService) - Unknown owner - C:\WINDOWS\ATKKBService.exe (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - D:\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Indexing Service (CiSvc) - Unknown owner - C:\WINDOWS\system32\cisvc.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - E:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
--
End of file - 5155 bytes