first of all thanks for your quick reply
so these will be the logs of combofix and hijack this :
ComboFix 08-08-18.05 - mcogzell 2008-08-20 13:48:22.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.239 [GMT 2:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Administrator\Application Data\temp.dll
C:\Documents and Settings\Administrator\UserData
C:\Documents and Settings\Administrator\UserData\index.dat
C:\Program Files\altcmd
C:\Program Files\altcmd\altcmd.inf
C:\Program Files\altcmd\altcmd32.dll
C:\Program Files\altcmd\uninstall.bat
C:\WINDOWS\config.ini
C:\WINDOWS\crock+mock.config
C:\WINDOWS\mywallpaper.bmp
C:\WINDOWS\system32\lphc75fj0e1da.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MSDIRECT
-------\Service_msdirect
((((((((((((((((((((((((( Files Created from 2008-07-20 to 2008-08-20 )))))))))))))))))))))))))))))))
.
2008-08-20 08:37 . 2008-08-20 13:41 <DIR> d-------- C:\HiJackThis
2008-08-19 16:08 . 2008-08-20 11:16 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-08-19 16:08 . 2008-08-20 11:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-19 15:25 . 2008-08-19 15:25 137 --a------ C:\WINDOWS\system32\MRT.INI
2008-08-19 15:05 . 2008-08-20 13:41 <DIR> d--h----- C:\$AVG8.VAULT$
2008-08-19 15:00 . 2008-08-20 13:40 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-08-19 15:00 . 2008-08-19 15:00 <DIR> d-------- C:\Program Files\AVG
2008-08-19 15:00 . 2008-08-19 15:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-08-19 15:00 . 2008-08-19 17:02 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AVGTOOLBAR
2008-08-19 15:00 . 2008-08-19 15:00 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-08-19 15:00 . 2008-08-19 15:00 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-08-19 14:44 . 2008-08-20 09:20 <DIR> d-------- C:\google.com
2008-08-19 14:44 . 2008-08-20 08:21 <DIR> d-------- C:\AntivirAsistant
2008-08-19 09:40 . 2008-08-19 09:40 54,307 --a------ C:\WINDOWS\sysgycnafekb.exe
2008-08-19 09:40 . 2008-08-19 09:40 49,699 --a------ C:\WINDOWS\syscdupretnb.exe
2008-08-19 09:40 . 2008-08-19 09:40 44,579 --a------ C:\WINDOWS\sysuxvmschrb.exe
2008-08-19 09:40 . 2008-08-19 09:40 40,995 --a------ C:\WINDOWS\sysragfchqsb.exe
2008-08-19 09:40 . 2008-08-19 09:55 128 --a------ C:\WINDOWS\sysragfchqsb.exe.dat
2008-08-19 09:40 . 2008-08-19 09:55 16 --a------ C:\WINDOWS\sysuxvmschrb.exe.dat
2008-08-19 09:40 . 2008-08-19 09:55 16 --a------ C:\WINDOWS\sysgycnafekb.exe.dat
2008-08-19 09:40 . 2008-08-19 14:50 16 --a------ C:\WINDOWS\syscdupretnb.exe.dat
2008-08-14 09:41 . 2008-08-14 09:46 <DIR> d-------- C:\Documents and Settings\Administrator\Contacts
2008-08-14 09:41 . 2008-08-14 09:41 268 --ah----- C:\sqmdata00.sqm
2008-08-14 09:41 . 2008-08-14 09:41 244 --ah----- C:\sqmnoopt00.sqm
2008-08-14 09:40 . 2008-08-14 09:40 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-08-14 09:31 . 2008-08-14 09:40 <DIR> d-------- C:\Program Files\Windows Live
2008-08-14 09:31 . 2008-08-14 09:39 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-08-14 09:31 . 2008-08-14 09:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-08-13 12:39 . 2008-08-13 12:39 <DIR> d-------- C:\Program Files\Sports Interactive Ltd
2008-08-07 07:47 . 2008-08-07 07:47 <DIR> d-------- C:\Program Files\Common Files\Crystal Decisions
2008-08-07 07:47 . 2008-08-07 07:47 <DIR> d-------- C:\CSH Solutions
2008-08-06 08:11 . 2008-08-07 08:26 <DIR> d-------- C:\Program Files\mIRC
2008-08-06 08:11 . 2008-08-07 09:02 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\mIRC
2008-08-05 14:19 . 2008-08-05 14:19 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\MSNInstaller
2008-08-05 12:32 . 2008-08-05 12:32 <DIR> d-------- C:\Program Files\Dell
2008-08-05 12:32 . 2003-01-01 02:25 167,936 --a------ C:\WINDOWS\system32\LexLog.dll
2008-08-05 12:32 . 2008-08-05 12:32 1,013 --a------ C:\WINDOWS\DKAAE2DD.ini
2008-08-05 12:14 . 2008-08-05 12:14 <DIR> d-------- C:\Program Files\Hewlett-Packard Company
2008-08-05 12:07 . 2008-08-05 12:07 <DIR> d-------- C:\clj8550pcl5cwinnt4
2008-08-05 11:14 . 1998-10-29 16:45 306,688 --a------ C:\WINDOWS\IsUninst.exe
2008-08-05 07:15 . 2008-08-05 07:15 <DIR> d-------- C:\Program Files\Xvid
2008-08-05 07:15 . 2007-06-28 18:52 765,952 --a------ C:\WINDOWS\system32\xvidcore.dll
2008-08-05 07:15 . 2007-06-28 18:54 180,224 --a------ C:\WINDOWS\system32\xvidvfw.dll
2008-08-05 07:15 . 2007-06-28 18:55 77,824 --a------ C:\WINDOWS\system32\xvid.ax
2008-08-04 12:16 . 2008-08-04 12:16 <DIR> d-------- C:\Malta summer 08
2008-08-04 09:00 . 2008-08-04 09:00 <DIR> d-------- C:\Program Files\uTorrent
2008-08-04 09:00 . 2008-08-07 14:56 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\uTorrent
2008-08-01 09:46 . 2008-08-01 09:46 <DIR> d-------- C:\Program Files\DNA
2008-08-01 09:46 . 2008-08-19 14:43 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\DNA
2008-07-29 07:04 . 2008-07-29 07:04 <DIR> d-------- C:\Program Files\Project Cost Control
2008-07-24 15:52 . 2008-08-07 10:04 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AdobeUM
2008-07-24 15:47 . 2008-07-24 15:47 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-07-24 15:47 . 2008-07-24 15:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Adobe Systems
2008-07-23 16:06 . 2004-08-03 23:08 26,496 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2008-07-23 09:46 . 2006-09-06 17:43 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-07-23 09:45 . 2008-08-13 03:02 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-07-23 09:41 . 2007-07-30 19:19 43,352 --a------ C:\WINDOWS\system32\wups2.dll
2008-07-23 09:41 . 2007-07-30 19:18 34,136 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2008-07-23 09:41 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-07-23 09:41 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-07-23 09:41 . 2007-07-30 19:18 20,312 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-07 08:04 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-07 10:11 --------- d-----w C:\Program Files\Common Files\Adobe AIR
2008-07-07 09:10 --------- d-----w C:\Program Files\Microsoft.NET
2008-07-07 09:10 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-07-07 09:03 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-07 09:02 --------- d-----w C:\Program Files\Intel
2008-07-07 09:00 --------- d-----w C:\Program Files\Analog Devices
2008-07-07 08:57 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-07-07 08:48 --------- d-----w C:\Program Files\microsoft frontpage
2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 16:57 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-08-19 15:00 1177368]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=C:\WINDOWS\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
--a------ 2008-04-23 02:08 483328 C:\Program Files\Adobe\Acrobat 7.0\Distillr\acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-06-12 02:38 34672 C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
--a------ 2008-08-01 09:46 341824 C:\Program Files\DNA\btdna.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 14:00 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
--a------ 2003-04-07 00:07 114688 C:\WINDOWS\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
--a------ 2003-04-07 00:19 155648 C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
-ra------ 2006-03-30 16:45 313472 C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{0389E53C-62CF-4CD6-9F4E-955A740E4385}]
--a------ 2008-08-19 09:40 49699 C:\WINDOWS\syscdupretnb.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{09E23F2C-ED1E-43FC-9AA1-1332162A35AE}]
--a------ 2008-08-19 09:40 44579 C:\WINDOWS\sysuxvmschrb.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{3BCF8450-D134-427E-AE9C-2A42CE8215CC}]
--a------ 2008-08-19 09:40 40995 C:\WINDOWS\sysragfchqsb.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{4D4DB474-8435-4FA1-8D91-512C0CE1E931}]
--a------ 2008-08-19 09:40 54307 C:\WINDOWS\sysgycnafekb.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-08-19 15:00]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-19 15:00]
S2 dnlsvc;MS Software Shadow Download Provider;C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\dnlsvc.exe []
.
- - - - ORPHANS REMOVED - - - -
BHO-{B1D3576A-CA42-4D09-83C1-15D563C19D71} - C:\AntivirAsistant\1.dll
HKCU-Run-CDriver - c:\google.com\svchost.exe
HKCU-Run-DDriver - c:\google.com\svchost.exe
HKCU-Run-alpha - c:\google.com\svchost.exe
HKCU-Run-beta - c:\google.com\svchost.exe
HKCU-Run-gamma - c:\google.com\svchost.exe
HKCU-Run-DriverLoad - (no file)
HKCU-Run-DriverCheck - (no file)
HKCU-Run-SystemDriverLoad - (no file)
HKCU-Run-SystemDriver - (no file)
HKCU-Run-FDriver - (no file)
HKCU-Run-ADriver - (no file)
HKU-Default-Run-DriverLoad - (no file)
HKU-Default-Run-DriverCheck - (no file)
HKU-Default-Run-SystemDriverLoad - (no file)
HKU-Default-Run-SystemDriver - (no file)
HKU-Default-Run-FDriver - (no file)
HKU-Default-Run-ADriver - (no file)
MSConfigStartUp-alpha - c:\google.com\svchost.exe
MSConfigStartUp-beta - c:\google.com\svchost.exe
MSConfigStartUp-CDriver - c:\google.com\svchost.exe
MSConfigStartUp-DDriver - c:\google.com\svchost.exe
MSConfigStartUp-gamma - c:\google.com\svchost.exe
MSConfigStartUp-lphc75fj0e1da - C:\WINDOWS\system32\lphc75fj0e1da.exe
MSConfigStartUp-neos - C:\WINDOWS\neos.exe
MSConfigStartUp-PromoReg - C:\WINDOWS\system32\alt.exe.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\1tjydzai.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.com.mt/
FF -: plugin - C:\Program Files\DNA\plugins\npbtdna.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-08-20 13:52:20
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2008-08-20 13:57:02 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-20 11:55:54
Pre-Run: 70,722,506,752 bytes free
Post-Run: 70,745,108,480 bytes free
204 --- E O F --- 2008-08-19 13:26:33
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:59:21, on 8/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\HiJackThis\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) -
http://lads.myspace....ploader1006.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1216798872822O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.m...ash/swflash.cabO17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ESIDOM.local
O17 - HKLM\Software\..\Telephony: DomainName = ESIDOM.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{BEF1CD4F-3DEB-4C60-A6C8-2172E8EB9642}: NameServer = 194.204.96.1,194.204.96.3
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = ESIDOM.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = ESIDOM.local
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: MS Software Shadow Download Provider (dnlsvc) - Unknown owner - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\dnlsvc.exe (file missing)
--
End of file - 5515 bytes
to be entirly honest i tried cleaning with avg and seems to be fine now. only sometimes a blue screen (fatal error type) appears and i dont know if it has something to do with the virus