thanx bricat, here's logs as requested!
ComboFix 09-10-13.01 - W33 K3RR 14/10/2009 12:25.5.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1919.1494 [GMT 1:00]
Running from: c:\documents and settings\W33 K3RR\Desktop\ComboFix.exe
AV: Avira AntiVir PersonalEdition Classic *On-access scanning enabled* (Outdated) {00000000-0000-0000-0000-000000000000}
AV: Avira AntiVir PersonalEdition Classic *On-access scanning enabled* (Updated) {804FD0EC-FFA4-00EB-0D24-347CA8A3377C}
AV: Avira AntiVir PersonalEdition Classic *On-access scanning enabled* (Updated) {804FD2B8-FFA4-00EB-0D24-347CA8A3377C}
AV: Avira AntiVir PersonalEdition Classic *On-access scanning enabled* (Updated) {804FD2B8-FFA4-00FC-0D24-347CA8A3377C}
AV: Freedom *On-access scanning disabled* (Updated) {5B5A3BD7-8573-4672-AEA8-C9BB713B6755}
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\W33 K3RR\Application Data\wujurekop.reg
c:\documents and settings\W33 K3RR\Start Menu\Programs\Startup\runit_32.lnk
c:\program files\Common Files\yqyrycuguv.vbs
c:\windows\Fonts\acrsec.fon
c:\windows\Installer\ce00b3.msp
c:\windows\system32\c2d.dat
c:\windows\system32\drivers\SKYNETuwykmoth.sys
c:\windows\system32\idm.dat
c:\windows\system32\jc.dat
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
c:\windows\system32\migoc.inf
c:\windows\system32\q1.dat
c:\windows\system32\sdra64.exe
c:\windows\system32\SKYNETbgrftjcb.dat
c:\windows\system32\SKYNETecqfpmts.dll
c:\windows\system32\SKYNETetxfqulv.dll
c:\windows\system32\SKYNETiginetjk.dll
c:\windows\system32\SKYNETihyxwbwa.dat
c:\windows\system32\SKYNETqgoeyjuu.dll
c:\windows\system32\SKYNETqhxftewt.dll
c:\windows\system32\SKYNETtkibmkxq.dll
c:\windows\system32\SKYNETxyffjyvk.dll
c:\windows\vvuxq62447.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_SKYNETxrxumepx
-------\Legacy_SKYNETxrxumepx
-------\Legacy_MSDVDR
((((((((((((((((((((((((( Files Created from 2009-09-14 to 2009-10-14 )))))))))))))))))))))))))))))))
.
2009-09-29 21:40 . 2009-09-29 21:40 1 ----a-w- c:\windows\system32\xd.dat
2009-09-29 19:49 . 2009-09-29 19:49 46080 ----a-w- c:\windows\system32\wrten2.dll
2009-09-29 19:47 . 2009-09-29 19:47 46080 ----a-w- c:\windows\system32\wtmet1.dll
2009-09-24 13:33 . 2009-09-24 13:33 44032 ----a-w- c:\windows\system32\kmf0.dll
2009-09-22 09:29 . 2008-06-13 11:05 272128 ------w- c:\windows\system32\dllcache\bthport.sys
2009-09-22 09:27 . 2008-10-15 16:34 337408 ------w- c:\windows\system32\dllcache\netapi32.dll
2009-09-22 09:16 . 2009-09-22 09:16 -------- d-----w- c:\windows\system32\scripting
2009-09-22 09:16 . 2009-09-22 09:16 -------- d-----w- c:\windows\l2schemas
2009-09-22 09:16 . 2009-09-22 09:16 -------- d-----w- c:\windows\system32\en
2009-09-22 09:16 . 2009-09-22 09:16 -------- d-----w- c:\windows\system32\bits
2009-09-22 09:09 . 2009-09-22 09:09 -------- d-----w- c:\windows\EHome
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2009-10-14 11:38 . 2009-01-20 12:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-10-14 11:35 . 2009-01-20 12:33 565280 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-10-14 11:35 . 2009-01-20 12:33 3211296 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-10-14 11:35 . 2009-01-20 12:33 3012 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-10-14 11:35 . 2009-01-20 12:33 26168 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-10-14 11:11 . 2008-04-20 17:16 -------- d-----w- c:\program files\Messenger Plus! Live
2009-10-14 02:00 . 2008-03-02 12:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-10-07 22:16 . 2009-05-14 17:05 -------- d-----w- c:\documents and settings\W33 K3RR\Application Data\LimeWire
2009-09-22 12:05 . 2009-01-20 12:34 95259 ----a-w- c:\windows\system32\drivers\klick.dat
2009-09-22 12:05 . 2009-01-20 12:34 107547 ----a-w- c:\windows\system32\drivers\klin.dat
2009-09-18 20:48 . 2009-07-01 22:36 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-09-12 13:42 . 2009-09-12 13:42 16078 ----a-w- c:\windows\latalak.sys
2009-09-12 13:42 . 2009-09-12 13:42 15926 ----a-w- c:\documents and settings\W33 K3RR\Local Settings\Application Data\qixydaxufu.dat
2009-09-12 13:42 . 2009-09-12 13:42 15115 ----a-w- c:\windows\wenylunoxa.com
2009-09-12 13:42 . 2009-09-12 13:42 13857 ----a-w- c:\documents and settings\W33 K3RR\Local Settings\Application Data\nifykimiv.com
2009-09-12 13:42 . 2009-09-12 13:42 12355 ----a-w- c:\documents and settings\W33 K3RR\Application Data\asenevibi.dll
2009-09-12 13:42 . 2009-09-12 13:42 11881 ----a-w- c:\documents and settings\All Users\Application Data\ytuwopi.dll
2009-09-12 13:42 . 2009-09-12 13:42 11454 ----a-w- c:\program files\Common Files\inurik.dll
2009-09-12 13:42 . 2009-09-12 13:42 11012 ----a-w- c:\documents and settings\W33 K3RR\Application Data\pelyvivary.dat
2009-09-12 13:42 . 2009-09-12 13:42 10399 ----a-w- c:\documents and settings\All Users\Application Data\tyzupu.bin
2009-09-06 22:52 . 2008-06-24 14:31 111968 ----a-w- c:\documents and settings\W33 K3RR\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-06 22:51 . 2009-03-17 17:05 -------- d-----w- c:\documents and settings\W33 K3RR\Application Data\GetRightToGo
2009-09-06 22:46 . 2007-08-31 17:07 -------- d-----w- c:\program files\Microsoft Works
2009-09-06 22:45 . 2009-09-06 22:45 -------- d-----w- c:\program files\Microsoft.NET
2009-09-06 22:17 . 2005-09-14 18:17 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-22 17:21 . 2009-08-22 17:21 -------- d-----w- c:\program files\MSBuild
2009-08-22 17:21 . 2009-08-22 17:21 -------- d-----w- c:\program files\Reference Assemblies
2009-08-22 17:18 . 2009-08-22 17:18 -------- d-----w- c:\program files\MSXML 6.0
2009-08-06 18:24 . 2004-08-10 15:56 327896 ----a-w- c:\windows\system32\wucltui.dll
2009-08-06 18:24 . 2004-08-10 15:56 209632 ----a-w- c:\windows\system32\wuweb.dll
2009-08-06 18:24 . 2005-05-26 03:16 44768 ----a-w- c:\windows\system32\wups2.dll
2009-08-06 18:24 . 2004-08-10 15:56 35552 ----a-w- c:\windows\system32\wups.dll
2009-08-06 18:24 . 2004-08-10 15:56 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-08-06 18:24 . 2004-08-10 15:37 96480 ----a-w- c:\windows\system32\cdm.dll
2009-08-06 18:23 . 2004-08-10 15:56 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-08-06 18:23 . 2007-03-05 15:33 274288 ----a-w- c:\windows\system32\mucltui.dll
2009-08-06 18:23 . 2007-03-05 15:33 215920 ----a-w- c:\windows\system32\muweb.dll
2009-08-06 18:23 . 2004-08-10 15:56 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-08-05 09:01 . 2004-08-10 15:38 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-29 04:37 . 2004-08-10 15:38 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-07-29 04:37 . 2004-08-10 15:37 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-07-17 18:55 . 2004-08-10 15:37 58880 ----a-w- c:\windows\system32\atl.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"ccleaner"="c:\program files\CCleaner\CCleaner.exe" [2009-05-27 1573104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-14 148888]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-02-06 201992]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
"DisableRegistryTools"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\cur rentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\contro l\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=c:\windows\pss\HP Image Zone Fast Start.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%ProgramFiles%\\AOL 9.0\\aol.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IMApp.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\Program Files\\LimeWire Gold\\LimeWireGold.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\APPS\\skype\\phone\\Skype.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 19:29 33808]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [13/03/2008 20:02 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [25/03/2008 21:07 24592]
S2 AlerterALG;Alerter AlerterALG;c:\windows\TEMP\korxwapbwp.exe service --> c:\windows\TEMP\korxwapbwp.exe service [?]
S3 bfastfao;bfastfao;\??\c:\docume~1\FRANKM~1\LOCALS~ 1\Temp\bfastfao.sys --> c:\docume~1\FRANKM~1\LOCALS~1\Temp\bfastfao.sys [?]
S4 Radialpoint Security Services;Virgin Broadband PCguard;c:\windows\system32\dllhost.exe [10/08/2004 16:37 5120]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D07CDF07-B01D-4A9E-BEF4-0A1BA518203B}]
rundll32 wrten2.dll,laspi
.
Contents of the 'Scheduled Tasks' folder
2009-10-14 c:\windows\Tasks\HDReg.job
- c:\apps\HDReg\HDRegRem.exe [2005-09-14 10:14]
2009-10-14 c:\windows\Tasks\User_Feed_Synchronization-{DBB51C1C-E6BF-40D9-BCDE-B8F49ABDF1F5}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 18:36]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.com
mStart Page =
hxxp://www.google.com
IE: Add to Banner Ad Blocker - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
.
- - - - ORPHANS REMOVED - - - -
BHO-{5D63F90D-F193-4277-B27B-FE70C9C55D6F} - (no file)
************************************************** ************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-10-14 12:37
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1244)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\klogon.dll
- - - - - - - > 'explorer.exe'(2928)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\UAService7.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\ati2evxx.exe
c:\windows\system32\rundll32.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\rundll32.exe
.
************************************************** ************************
.
Completion time: 2009-10-14 12:43 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-14 11:43
ComboFix2.txt 2009-01-16 22:03
Pre-Run: 165,338,972,160 bytes free
Post-Run: 165,028,720,640 bytes free
Current=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4
226 --- E O F --- 2009-10-14 02:00
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:15:38, on 14/10/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
c:\APPS\HIDSERVICE\HIDSERVICE.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: (no name) - {5D63F90D-F193-4277-B27B-FE70C9C55D6F} - (no file)
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Pol icies\System, DisableRegedit=1
O8 - Extra context menu item: Add to Banner Ad Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O16 - DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} (Bebo Uploader Control) -
http://www.bebo.com/files/BeboUploader.5.1.4.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) -
http://messenger.zone.msn.com/EN-GB/.../GAME_UNO1.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} -
http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) -
http://dl8-cdn-09.sun.com/s/ESD7/JSCDL/j...ows-i586-jc.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary...t.cab56907.cab
O23 - Service: Alerter AlerterALG (AlerterALG) - Unknown owner - C:\WINDOWS\TEMP\korxwapbwp.exe (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\system32\UAService7.exe
--
End of file - 5807 bytes