Ooookay.
I updated my Vundofix and it scanned with no infected files found. I then added the two files, removed and restarted as you said.
VundoFix V6.2.1
Checking Java version...
Java version is 1.5.0.6
Scan started at 6:35:41 PM 09/10/2006
Listing files found while scanning....
No infected files were found.
Beginning removal...
Performing Repairs to the registry.
Done!
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 8:22:58 PM 09/10/2006
+ Scan result:
C:\System Volume Information\_restore{42382A6D-A202-4D10-8672-F706D2544C0B}\RP89\A0030597.dll -> Logger.VBStat.e : No action taken.
C:\Documents and Settings\Kate\Cookies\kate@2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Kate\Cookies\
[email protected][1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Kate\Cookies\kate@advertising[1].txt -> TrackingCookie.Advertising : No action taken.
:mozilla.32:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\vifjwio4.default\cookies.txt -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\Kate\Cookies\kate@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken.
:mozilla.24:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\vifjwio4.default\cookies.txt -> TrackingCookie.Bridgetrack : No action taken.
:mozilla.25:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\vifjwio4.default\cookies.txt -> TrackingCookie.Bridgetrack : No action taken.
:mozilla.26:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\vifjwio4.default\cookies.txt -> TrackingCookie.Bridgetrack : No action taken.
:mozilla.27:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\vifjwio4.default\cookies.txt -> TrackingCookie.Burstnet : No action taken.
C:\Documents and Settings\Kate\Cookies\kate@doubleclick[2].txt -> TrackingCookie.Doubleclick : No action taken.
C:\Documents and Settings\Kate\Cookies\kate@tacoda[1].txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.16:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\vifjwio4.default\cookies.txt -> TrackingCookie.Trafic : No action taken.
:mozilla.28:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\vifjwio4.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
:mozilla.29:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\vifjwio4.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
:mozilla.30:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\vifjwio4.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
C:\Documents and Settings\Kate\Cookies\kate@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : No action taken.
:mozilla.17:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\vifjwio4.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.18:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\vifjwio4.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.19:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\vifjwio4.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.20:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\vifjwio4.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.22:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\vifjwio4.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.23:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\vifjwio4.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.47:C:\Documents and Settings\Kate\Application Data\Mozilla\Firefox\Profiles\vifjwio4.default\cookies.txt -> TrackingCookie.Webtrendslive : No action taken.
::Report end
Kate - 06-10-09 20:25:53.04 Service Pack 2
ComboFix 06.09.28 - Running from: "C:\Documents and Settings\Kate\Desktop"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files\Common Files\{320D180E-069F-1033-0227-060331200002}
((((((((((((((((((((((((((((((( Files Created from 2006-09-09 to 2006-10-09 ))))))))))))))))))))))))))))))))))
2006-10-09 18:42 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2006-10-09 18:08 53,248 --a------ C:\WINDOWS\system32\Process.exe
2006-10-09 18:08 40,960 --a------ C:\WINDOWS\system32\swsc.exe
2006-10-09 18:08 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2006-10-09 18:08 135,168 --a------ C:\WINDOWS\system32\swreg.exe
2006-10-09 12:55 76,560 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2006-10-08 09:05 1,000,213 ---hs---- C:\WINDOWS\system32\xycdd.bak2
2006-10-07 09:05 992,274 ---hs---- C:\WINDOWS\system32\xycdd.bak1
2006-09-30 23:16 8,704 --a------ C:\WINDOWS\system32\SpOrder.dll
2006-09-20 14:51 29,968 --a------ C:\WINDOWS\system32\mdimon.dll
2006-09-14 20:05 69,632 --a------ C:\WINDOWS\system32\lfgif13n.dll
2006-09-14 20:05 57,344 --a------ C:\WINDOWS\system32\lfbmp13n.dll
2006-09-14 20:05 462,848 --a------ C:\WINDOWS\system32\ltkrn13n.dll
2006-09-14 20:05 450,560 --a------ C:\WINDOWS\system32\ltimg13n.dll
2006-09-14 20:05 401,408 --a------ C:\WINDOWS\system32\lfcmp13n.dll
2006-09-14 20:05 299,008 --a------ C:\WINDOWS\system32\ltdis13n.dll
2006-09-14 20:05 206,336 --a------ C:\WINDOWS\system32\ltefx13n.dll
2006-09-14 20:05 163,840 --a------ C:\WINDOWS\system32\ltfil13n.dll
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-10-09 15:39 -------- d-------- C:\Program Files\Mozilla Firefox
2006-10-09 15:39 -------- d-------- C:\Documents and Settings\Kate\Application Data\Mozilla
2006-10-09 14:05 -------- d-------- C:\Documents and Settings\Kate\Application Data\TrojanHunter
2006-10-09 12:58 -------- d-------- C:\Program Files\TrojanHunter 4.6
2006-10-04 20:35 -------- d-------- C:\Program Files\Grisoft
2006-10-02 15:08 -------- d-------- C:\Program Files\HnHSoft
2006-09-25 23:35 -------- d-------- C:\Program Files\Pardon 3
2006-09-20 14:47 -------- d-------- C:\Program Files\Microsoft Visual Studio
2006-09-20 14:47 -------- d-------- C:\Program Files\Common Files\DESIGNER
2006-09-20 14:46 -------- d-------- C:\Program Files\Microsoft.NET
2006-09-20 14:44 -------- d-------- C:\Program Files\Microsoft Office
2006-09-11 17:55 -------- d-------- C:\Program Files\Thomson
2006-09-07 23:07 223128 --a------ C:\WINDOWS\system32\drivers\dtscsi.sys
2006-08-25 02:55 -------- d-------- C:\Program Files\Common Files\xing shared
2006-08-25 02:53 -------- d-------- C:\Program Files\Real
2006-08-25 02:53 -------- d-------- C:\Program Files\Common Files\Real
2006-08-25 02:52 -------- d-------- C:\Documents and Settings\Kate\Application Data\Real
2006-08-24 01:26 -------- d-------- C:\Program Files\Messenger Plus! Live
2006-08-24 01:08 -------- d-------- C:\Program Files\MSN Messenger
2006-08-22 23:47 -------- d-------- C:\Program Files\USB(CIF) Camera
2006-08-22 23:47 -------- d-------- C:\Program Files\Common Files\USBCIF
2006-08-22 02:59 -------- d-------- C:\Program Files\Windows Journal Viewer
2006-08-22 02:49 -------- d-------- C:\Program Files\Lavasoft
2006-08-22 02:49 -------- d-------- C:\Documents and Settings\Kate\Application Data\Lavasoft
2006-08-22 02:48 -------- d-------- C:\Program Files\Google
2006-08-21 09:21 16896 --a------ C:\WINDOWS\system32\fltlib.dll
2006-08-21 06:14 23040 --a------ C:\WINDOWS\system32\fltMc.exe
2006-08-21 06:14 128896 --a------ C:\WINDOWS\system32\drivers\fltMgr.sys
2006-08-18 19:14 -------- d-------- C:\Documents and Settings\Kate\Application Data\Ahead
2006-08-18 19:11 -------- d-------- C:\Program Files\Nero
2006-08-18 19:11 -------- d-------- C:\Program Files\Common Files\Ahead
2006-08-18 16:22 -------- d-------- C:\Program Files\Ubisoft
2006-08-18 16:14 -------- d-------- C:\Program Files\HHD Software
2006-08-17 15:37 -------- d-------- C:\Program Files\Cucusoft
2006-08-17 15:31 -------- d-------- C:\Program Files\Winamp
2006-08-17 04:38 -------- d-------- C:\Documents and Settings\Kate\Application Data\Sun
2006-08-17 04:02 -------- d-------- C:\Documents and Settings\Kate\Application Data\Cakewalk
2006-08-17 04:00 118784 --a------ C:\WINDOWS\dsdxirmv.exe
2006-08-17 04:00 -------- d-------- C:\Program Files\Cakewalk
2006-08-15 11:03 -------- d-------- C:\Documents and Settings\Kate\Application Data\AdobeUM
2006-08-12 11:14 -------- d-------- C:\Program Files\VstPlugins
2006-08-12 11:13 -------- d-------- C:\Program Files\Image-Line
2006-08-12 09:06 -------- d-------- C:\Program Files\Common Files\Adobe Systems Shared
2006-08-12 01:09 -------- d-------- C:\Program Files\Java
2006-08-12 01:05 14848 --a------ C:\WINDOWS\system32\BASSMOD.dll
2006-08-12 00:19 96256 --a------ C:\WINDOWS\system32\drivers\sptd5629.sys
2006-08-12 00:19 643072 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2006-08-11 04:27 -------- d-------- C:\Documents and Settings\Kate\Application Data\Macromedia
2006-08-10 16:08 -------- d-------- C:\Documents and Settings\Kate\Application Data\CyberLink
2006-08-10 16:04 -------- d-------- C:\Program Files\Norton AntiVirus
2006-08-10 16:03 -------- d-------- C:\Program Files\Symantec
2006-08-10 16:03 -------- d-------- C:\Documents and Settings\Kate\Application Data\Symantec
2006-08-10 16:03 -------- d-------- C:\Documents and Settings\Kate\Application Data\Acer
2006-08-10 15:57 21275 --a------ C:\WINDOWS\system32\drivers\AegisP.sys
2006-08-10 14:06 -------- d-------- C:\Program Files\Registry Mechanic
2006-08-10 13:50 279122 ---hs---- C:\WINDOWS\system32\ilkkj.bak1
2006-08-10 13:19 -------- d-------- C:\Documents and Settings\Kate\Application Data\PC Tools
2006-08-10 13:16 -------- d-------- C:\Program Files\WinRAR
2006-08-10 12:53 -------- d-------- C:\Program Files\BitLord
2006-07-29 19:32 48936 --a------ C:\WINDOWS\system32\sirenacm.dll
2006-07-27 06:24 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-07-21 01:24 72704 --a------ C:\WINDOWS\system32\hlink.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="\"C:\\Program Files\\Common Files\\Ahead\\Lib\\NMBgMonitor.exe\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\\WINDOWS\\system32\\igfxtray.exe"
"HotKeysCmds"="C:\\WINDOWS\\system32\\hkcmd.exe"
"LaunchApp"="Alaunch"
"SoundMan"="SOUNDMAN.EXE"
"KTPWare"="C:\\Program Files\\Elantech\\ktp.exe"
"BluetoothAuthenticationAgent"="rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent"
"IMJPMIG8.1"="\"C:\\WINDOWS\\IME\\imjp8_1\\IMJPMIG.EXE\" /Spoil /RemAdvDef /Migration32"
"MSPY2002"="C:\\WINDOWS\\system32\\IME\\PINTLGNT\\ImScInst.exe /SYNC"
"PHIME2002ASync"="C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /SYNC"
"PHIME2002A"="C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /IMEName"
"eDataSecurity Loader"="C:\\Acer\\Empowering Technology\\eDataSecurity\\eDSloader.exe"
"EPM-DM"="c:\\acer\\Empowering Technology\\ePower\\epm-dm.exe"
"Acer ePower Management"="C:\\Acer\\Empowering Technology\\ePower\\Acer ePower Management.exe boot"
"LManager"="C:\\PROGRA~1\\LAUNCH~1\\LManager.exe"
"eRecoveryService"="C:\\Acer\\Empowering Technology\\eRecovery\\Monitor.exe"
"ADMTray.exe"="\"C:\\Acer\\Empowering Technology\\admtray.exe\""
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"RegistryMechanic"=""
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"NeroFilterCheck"="C:\\Program Files\\Common Files\\Ahead\\Lib\\NeroCheck.exe"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"Symantec NetDriver Monitor"="C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe /Consumer"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
@=""
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
@=""
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
@=""
"Installed"="1"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,a0,00,00,00,00,00,00,00,80,02,00,00,3a,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,12,03,00,00,23,00,00,00,dc,00,00,00,d2,00,\
00,00,01,00,00,00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddcyx
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer - Kate.job
C:\WINDOWS\tasks\Low Battery Alarm Program.job
Completion time: 09/10/2006 20:28:04.62
ComboFix.txt
ANNDDD my fresh Hijackthis from normal mode.
Logfile of HijackThis v1.99.1
Scan saved at 8:43:45 PM, on 09/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Elantech\ktp.exe
C:\Acer\Empowering Technology\eRecovery\Monitor.exe
C:\WINDOWS\system32\rundll32.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\acer\Empowering Technology\ePower\epm-dm.exe
C:\PROGRA~1\LAUNCH~1\LManager.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Acer\Empowering Technology\admtray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Acer\Empowering Technology\admServ.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\igfxext.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Kate\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://smuport.smu.ca/R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [KTPWare] C:\Program Files\Elantech\ktp.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [EPM-DM] c:\acer\Empowering Technology\ePower\epm-dm.exe
O4 - HKLM\..\Run: [Acer ePower Management] C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe boot
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
O4 - HKLM\..\Run: [ADMTray.exe] "C:\Acer\Empowering Technology\admtray.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab31267.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) -
http://messenger.zon...er.cab31267.cabO16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://by106fd.bay10...es/MsnPUpld.cabO16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab31267.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://messenger.zon...ro.cab47946.cabO18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AdminWorks Agent X6 (AWService) - Avocent Inc. - C:\Acer\Empowering Technology\admServ.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe