I did everything. Here's the AVG report:
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 23:14:21 2007-01-21
+ Scan result:
HKU\S-1-5-21-583907252-602162358-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1A1DDC19-5893-43AB-A73F-F41A0F34D115} -> Adware.Generic : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP76\A0023209.exe -> Adware.MediaTickets : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP69\A0020051.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP70\A0020466.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP70\A0020539.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP73\A0020870.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP73\A0020871.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP73\A0022023.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP73\A0022172.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP75\A0022858.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP76\A0023189.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP76\A0023191.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP76\A0023207.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP82\A0028708.dll -> Adware.SpyMarshal : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP82\A0028709.dll -> Adware.SpyMarshal : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP82\A0028710.dll -> Adware.SpyMarshal : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP82\A0028711.dll -> Adware.SpyMarshal : Cleaned with backup (quarantined).
F:\Gry\Tradewinds\tradewindsam-dm.exe -> Adware.Trymedia : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00007258.exe -> Dialer.GBDialer.i : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP73\A0022173.exe -> Downloader.Purit.co : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP75\A0022751.exe -> Downloader.Purit.co : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP75\A0022786.exe -> Downloader.Purit.co : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP75\A0022896.exe -> Downloader.Purit.co : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP82\A0028442.exe -> Downloader.Small.dgk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP84\A0029946.exe -> Downloader.Small.dgk : Cleaned with backup (quarantined).
D:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP82\A0028436.exe -> Downloader.Small.edb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP76\A0023062.dll -> Downloader.Zlob.aeg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP75\A0022981.exe -> Downloader.Zlob.aqh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP75\A0023012.exe -> Downloader.Zlob.aqh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP76\A0023033.exe -> Downloader.Zlob.aqh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP76\A0023065.exe -> Downloader.Zlob.aqh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP76\A0023067.exe -> Downloader.Zlob.aqh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP76\A0023068.exe -> Downloader.Zlob.aqh : Cleaned with backup (quarantined).
D:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP75\A0022999.exe -> Downloader.Zlob.axr : Cleaned with backup (quarantined).
D:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP75\A0023002.exe -> Downloader.Zlob.axr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP75\A0022980.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP75\A0023011.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP76\A0023032.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP76\A0023070.dll -> Downloader.Zlob.bbv : Cleaned with backup (quarantined).
D:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP75\A0022995.exe -> Downloader.Zlob.bbx : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP76\A0023069.exe -> Downloader.Zlob.bcb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP76\A0023066.exe -> Downloader.Zlob.bcz : Cleaned with backup (quarantined).
D:\_inst\1\Adobe_Photoshop_v7[1].0_Keygen.zip/keygen.exe -> Logger.Delf.ncs : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP82\A0028443.exe -> Not-A-Virus.Hoax.Win32.Renos.fl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP82\A0028440.exe -> Not-A-Virus.Hoax.Win32.Renos.gc : Cleaned with backup (quarantined).
C:\WINDOWS\system32\protector.exe -> Proxy.Wopla.ac : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ntio256.sys -> Rootkit.Agent.cf : Cleaned with backup (quarantined).
C:\Documents and Settings\Grot\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
E:\Documents and Settings\Ja\Cookies\ja@admarketplace[2].txt -> TrackingCookie.Admarketplace : Cleaned.
C:\Documents and Settings\Grot\Cookies\[email protected][2].txt -> TrackingCookie.Adocean : Cleaned.
C:\Documents and Settings\Grot\Cookies\[email protected][2].txt -> TrackingCookie.Adocean : Cleaned.
C:\Documents and Settings\Grot\Cookies\[email protected][2].txt -> TrackingCookie.Adocean : Cleaned.
E:\Documents and Settings\Ja\Cookies\[email protected][2].txt -> TrackingCookie.Adocean : Cleaned.
E:\Documents and Settings\Ja\Cookies\[email protected][2].txt -> TrackingCookie.Adocean : Cleaned.
E:\Documents and Settings\Ja\Cookies\[email protected][1].txt -> TrackingCookie.Adocean : Cleaned.
E:\Documents and Settings\Ja\Cookies\[email protected][1].txt -> TrackingCookie.Adocean : Cleaned.
E:\Documents and Settings\Ja\Ustawienia lokalne\Temp\Cookies\[email protected][1].txt -> TrackingCookie.Adocean : Cleaned.
C:\Documents and Settings\Grot\Cookies\grot@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
E:\Documents and Settings\Ja\Cookies\[email protected][1].txt -> TrackingCookie.Burstbeacon : Cleaned.
E:\Documents and Settings\Ja\Cookies\ja@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
E:\Documents and Settings\Ja\Cookies\ja@com[1].txt -> TrackingCookie.Com : Cleaned.
E:\Documents and Settings\Ja\Cookies\[email protected][1].txt -> TrackingCookie.Enhance : Cleaned.
E:\Documents and Settings\Ja\Cookies\[email protected][2].txt -> TrackingCookie.Hitbox : Cleaned.
E:\Documents and Settings\Ja\Cookies\[email protected][1].txt -> TrackingCookie.Masterstats : Cleaned.
C:\Documents and Settings\Grot\Cookies\grot@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned.
E:\Documents and Settings\Ja\Cookies\ja@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Grot\Cookies\grot@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : Cleaned.
C:\Documents and Settings\Grot\Cookies\grot@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned.
E:\Documents and Settings\Ja\Cookies\[email protected][2].txt -> TrackingCookie.Web-stat : Cleaned.
E:\Documents and Settings\Ja\Cookies\ja@yadro[1].txt -> TrackingCookie.Yadro : Cleaned.
E:\Documents and Settings\Ja\Cookies\[email protected][2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\RECYCLER\NPROTECT\00007256.dll -> Trojan.Sinowal.bh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP84\A0029945.exe -> Trojan.Sinowal.bh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP69\A0018889.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP69\A0018922.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP69\A0018975.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP69\A0019007.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP69\A0020052.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP69\A0020085.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP70\A0020157.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP70\A0020208.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP70\A0020260.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP70\A0020325.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP70\A0020503.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP70\A0020540.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP71\A0020715.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP73\A0020872.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP73\A0020887.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP73\A0022025.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP73\A0022149.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP73\A0022174.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP73\A0022314.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP75\A0022752.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP75\A0022787.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP75\A0022859.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP75\A0022897.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6B791278-1EE7-4637-86A6-5C4E1B5416A8}\RP84\A0029944.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\system32\wintsvtr.exe -> Trojan.Small : Cleaned with backup (quarantined).
::Report end
And the HJT log:
Logfile of HijackThis v1.99.1
Scan saved at 23:16:59, on 2007-01-21
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\MSI\Live Update 3\LMonitor.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Gadu-Gadu\gg.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wscntfy.exe
C:\HJT\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LiveMonitor] C:\Program Files\MSI\Live Update 3\LMonitor.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MailScanner] C:\Program Files\MKS_VIR_2006\Mks_mail.exe
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O16 - DPF: {4E330863-6A11-11D0-BFD8-006097237877} (InstallFromTheWeb ActiveX Control) - http://tw.msi.com.tw...nt/iftwclix.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1135426657640
O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} (MainControl Class) - http://www.mks.com.p...kanerOnline.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: BOINC - Unknown owner - C:\Program Files\BOINC\boinc.exe" -daemon (file missing)
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Microsoft authenticate service (MsaSvc) - Unknown owner - C:\WINDOWS\system32\msasvc.exe (file missing)
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
I saw that the entry you told me to fix with HJT didn't disappear from there, but I checked the box and clicked Fix Checked. Also, in normal mode my computer showed a warning that it is endangered, because the MS authenticate service is turned off.