Thanks again for all this. I did all things as requested although my PC did not like Kaspersky at all as it shutdown regularly and I no other porgrams would run after I installed it. I ended up having to delete it in safe mode as that was the only thing I could do. Here was one of the error message details that showed up after restarting:
C:\DOCUME~1\James\LOCALS~1\Temp\WERff50.dir00\Mini121705-01.dmp
C:\DOCUME~1\James\LOCALS~1\Temp\WERff50.dir00\sysdata.xml
Here are all the logs as requested:
smitRem © log file
version 2.8
by noahdfear
Microsoft Windows XP [Version 5.1.2600]
The current date is: Sat 17/12/2005
The current time is: 10:33:30.65
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
checking for ShudderLTD key
ShudderLTD key not present!
checking for PSGuard.com key
PSGuard.com key not present!
spyaxe uninstaller NOT present
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Existing Pre-run Files
~~~ Program Files ~~~
~~~ Shortcuts ~~~
Online Security Guide.url
~~~ Favorites ~~~
~~~ system32 folder ~~~
ioctrl.dll
~~~ Icons in System32 ~~~
~~~ Windows directory ~~~
~~~ Drive root ~~~
~~~ Miscellaneous Files/folders ~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 Craig.Peaco*k@beyondlogic.org
Killing PID 748 'explorer.exe'
Starting registry repairs
Deleting files
Remaining Post-run Files
~~~ Program Files ~~~
~~~ Shortcuts ~~~
Online Security Guide.url
~~~ Favorites ~~~
~~~ system32 folder ~~~
~~~ Icons in System32 ~~~
~~~ Windows directory ~~~
~~~ Drive root ~~~
~~~ Miscellaneous Files/folders ~~~
~~~ Wininet.dll ~~~
CLEAN! :)
KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)
Checks SDT for Hooked Native APIs
KeServiceDescriptorTable 80559480
KeServiceDescriptorTable.ServiceTable 804E26A8
KeServiceDescriptorTable.ServiceLimit 284
ZwConnectPort 1F \SystemRoot\System32\vsdatant.sys [F5FC3C90]
ZwCreateFile 25 \SystemRoot\System32\vsdatant.sys [F5FC0B70]
ZwCreateKey 29 \SystemRoot\System32\vsdatant.sys [F5FD9944]
ZwCreateProcess 2F \SystemRoot\System32\vsdatant.sys [F5FD8760]
ZwCreateProces-- The nicest hobby on Earth ;) -- 30 \SystemRoot\System32\vsdatant.sys [F5FD8980]
ZwCreateSection 32 \SystemRoot\System32\vsdatant.sys [F5FDB610]
ZwDeleteFile 3E \SystemRoot\System32\vsdatant.sys [F5FC1180]
ZwDeleteKey 3F \SystemRoot\System32\vsdatant.sys [F5FDA330]
ZwDeleteValueKey 41 \SystemRoot\System32\vsdatant.sys [F5FDA100]
ZwDuplicateObject 44 \SystemRoot\System32\vsdatant.sys [F5FD8080]
ZwLoadKey 62 \SystemRoot\System32\vsdatant.sys [F5FDA4F0]
ZwOpenFile 74 \SystemRoot\System32\vsdatant.sys [F5FC0FD0]
ZwOpenProcess 7A \SystemRoot\System32\vsdatant.sys [F5FD7E80]
ZwOpenThread 80 \SystemRoot\System32\vsdatant.sys [F5FD7C40]
ZwReplaceKey C1 \SystemRoot\System32\vsdatant.sys [F5FDA7C0]
ZwRequestWaitReplyPort C8 \SystemRoot\System32\vsdatant.sys [F5FC3960]
ZwRestoreKey CC \SystemRoot\System32\vsdatant.sys [F5FDAA50]
ZwSecureConnectPort D2 \SystemRoot\System32\vsdatant.sys [F5FC3E40]
ZwSetInformationFile E0 \SystemRoot\System32\vsdatant.sys [F5FC12F0]
ZwSetValueKey F7 \SystemRoot\System32\vsdatant.sys [F5FD9EA0]
ZwTerminateProcess 101 \SystemRoot\System32\vsdatant.sys [F5FD8BB0]
Number of Service Table entries hooked = 21
KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)
Checks Shadow SDT for Hooked Native GDI APIs
KeServiceDescriptorTableShadow 80559440
KeServiceDescriptorTableShadow.SDE[1].ServiceTable BF998300
KeServiceDescriptorTableShadow.SDE[1].ServiceLimit 667
Entry 1CC Hooked - \systemroot\system32\vsdatant.sys [F5FC2270]
Entry 1DB Hooked - \systemroot\system32\vsdatant.sys [F5FC2310]
Entry 1F6 Hooked - \systemroot\system32\vsdatant.sys [F5FC24C0]
Number of GDI Service Table entries hooked = 3
KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)
Process list by traversal of ActiveProcessLinks
4 - System
192 - InoRT.exe
220 - InoTask.exe
288 - LogWatNT.exe
324 - nvsvc32.exe
364 - svchost.exe
384 - wdfmgr.exe
488 - vsmon.exe
560 - InoDist.exe
644 - Realmon.exe
652 - KMaestro.exe
704 - zlclient.exe
736 - smss.exe
788 - csrss.exe
812 - winlogon.exe
860 - services.exe
872 - lsass.exe
1012 - mapiicon.exe
1032 - svchost.exe
1116 - svchost.exe
1172 - svchost.exe
1296 - svchost.exe
1332 - svchost.exe
1476 - spoolsv.exe
1584 - avgamsvr.exe
1764 - explorer.exe
1808 - avgupsvc.exe
1836 - cvpnd.exe
1904 - SAgent2.exe
1952 - ewidoctrl.exe
1968 - InoRpc.exe
2224 - wscntfy.exe
2304 - wmiprvse.exe
2348 - alg.exe
2684 - cmd.exe
2872 - KProcCheck.exe
3264 - wuauclt.exe
Total number of processes = 37
KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)
Process list by traversal of KiWaitListHead
4 - System
192 - InoRT.exe
220 - InoTask.exe
288 - LogWatNT.exe
324 - nvsvc32.exe
364 - svchost.exe
384 - wdfmgr.exe
488 - vsmon.exe
560 - InoDist.exe
644 - Realmon.exe
652 - KMaestro.exe
704 - zlclient.exe
736 - smss.exe
788 - csrss.exe
812 - winlogon.exe
860 - services.exe
872 - lsass.exe
1012 - mapiicon.exe
1032 - svchost.exe
1116 - svchost.exe
1172 - svchost.exe
1296 - svchost.exe
1332 - svchost.exe
1476 - spoolsv.exe
1584 - avgamsvr.exe
1764 - explorer.exe
1808 - avgupsvc.exe
1836 - cvpnd.exe
1904 - SAgent2.exe
1952 - ewidoctrl.exe
1968 - InoRpc.exe
2224 - wscntfy.exe
2304 - wmiprvse.exe
2348 - alg.exe
2684 - cmd.exe
3264 - wuauclt.exe
Total number of processes = 36
NOTE: Under WinXP, this will not show all processes.
KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)
Driver/Module list by traversal of PsLoadedModuleList
804D7000 - \WINDOWS\system32\ntoskrnl.exe
806EC000 - \WINDOWS\system32\hal.dll
F7D2F000 - \WINDOWS\system32\KDCOM.DLL
F7C3F000 - \WINDOWS\system32\BOOTVID.dll
F77E0000 - ACPI.sys
F7D31000 - \WINDOWS\System32\DRIVERS\WMILIB.SYS
F77CF000 - pci.sys
F782F000 - isapnp.sys
F7D33000 - viaide.sys
F7AAF000 - \WINDOWS\System32\DRIVERS\PCIIDEX.SYS
F783F000 - MountMgr.sys
F77B0000 - ftdisk.sys
F7D35000 - dmload.sys
F778A000 - dmio.sys
F7AB7000 - PartMgr.sys
F784F000 - VolSnap.sys
F7772000 - atapi.sys
F785F000 - disk.sys
F786F000 - \WINDOWS\System32\DRIVERS\CLASSPNP.SYS
F7753000 - fltmgr.sys
F7ABF000 - ino_flpy.sys
F773C000 - KSecDD.sys
F76AF000 - Ntfs.sys
F7682000 - NDIS.sys
F787F000 - viaagp.sys
F788F000 - sbp2port.sys
F789F000 - ohci1394.sys
F78AF000 - \WINDOWS\System32\DRIVERS\1394BUS.SYS
F7667000 - Mup.sys
F78DF000 - \SystemRoot\System32\DRIVERS\processr.sys
F74B9000 - \SystemRoot\System32\DRIVERS\nv4_mini.sys
F74A5000 - \SystemRoot\System32\DRIVERS\VIDEOPRT.SYS
F78EF000 - \SystemRoot\System32\DRIVERS\nic1394.sys
F743B000 - \SystemRoot\System32\DRIVERS\itexwana.sys
F7ADF000 - \SystemRoot\System32\DRIVERS\DM9PCI5.SYS
F78FF000 - \SystemRoot\System32\DRIVERS\imapi.sys
F7AEF000 - \SystemRoot\system32\drivers\iviaspi.sys
F7CCB000 - \SystemRoot\system32\drivers\pfc.sys
F790F000 - \SystemRoot\System32\DRIVERS\cdrom.sys
F791F000 - \SystemRoot\System32\DRIVERS\redbook.sys
F7418000 - \SystemRoot\System32\DRIVERS\ks.sys
F7B07000 - \SystemRoot\SYSTEM32\DRIVERS\GEARAspiWDM.sys
F7B0F000 - \SystemRoot\System32\DRIVERS\usbuhci.sys
F73F5000 - \SystemRoot\System32\DRIVERS\USBPORT.SYS
F73C3000 - \SystemRoot\system32\drivers\vinyl97.sys
F739F000 - \SystemRoot\system32\drivers\portcls.sys
F792F000 - \SystemRoot\system32\drivers\drmk.sys
F7B27000 - \SystemRoot\System32\DRIVERS\fdc.sys
F793F000 - \SystemRoot\System32\DRIVERS\serial.sys
F7CE7000 - \SystemRoot\System32\DRIVERS\serenum.sys
F738B000 - \SystemRoot\System32\DRIVERS\parport.sys
F794F000 - \SystemRoot\System32\DRIVERS\i8042prt.sys
F7B37000 - \SystemRoot\System32\DRIVERS\mouclass.sys
F7B3F000 - \SystemRoot\System32\DRIVERS\kbdclass.sys
F7EDA000 - \SystemRoot\system32\drivers\msmpu401.sys
F7CF3000 - \SystemRoot\System32\DRIVERS\gameenum.sys
F7373000 - \SystemRoot\System32\DRIVERS\dne2000.sys
F7EDF000 - \SystemRoot\System32\DRIVERS\audstub.sys
F795F000 - \SystemRoot\System32\DRIVERS\rasl2tp.sys
F7CFF000 - \SystemRoot\System32\DRIVERS\ndistapi.sys
F735C000 - \SystemRoot\System32\DRIVERS\ndiswan.sys
F796F000 - \SystemRoot\System32\DRIVERS\raspppoe.sys
F797F000 - \SystemRoot\System32\DRIVERS\raspptp.sys
F7B67000 - \SystemRoot\System32\DRIVERS\TDI.SYS
F72AB000 - \SystemRoot\System32\DRIVERS\psched.sys
F798F000 - \SystemRoot\System32\DRIVERS\msgpc.sys
F7B77000 - \SystemRoot\System32\DRIVERS\ptilink.sys
F7B87000 - \SystemRoot\System32\DRIVERS\raspti.sys
F727A000 - \SystemRoot\System32\DRIVERS\rdpdr.sys
F799F000 - \SystemRoot\System32\DRIVERS\termdd.sys
F7D3D000 - \SystemRoot\System32\DRIVERS\swenum.sys
F721E000 - \SystemRoot\System32\DRIVERS\update.sys
F7D1F000 - \SystemRoot\System32\DRIVERS\mssmbios.sys
F79AF000 - \SystemRoot\System32\Drivers\NDProxy.SYS
F79CF000 - \SystemRoot\System32\DRIVERS\usbhub.sys
F7D47000 - \SystemRoot\System32\DRIVERS\USBD.SYS
F7B97000 - \SystemRoot\System32\DRIVERS\flpydisk.sys
F7D4B000 - \SystemRoot\System32\Drivers\Fs_Rec.SYS
F7E51000 - \SystemRoot\System32\Drivers\Null.SYS
F7D4F000 - \SystemRoot\System32\Drivers\Beep.SYS
F7E54000 - \SystemRoot\System32\Drivers\VIAPFD.SYS
F7BAF000 - \SystemRoot\System32\drivers\vga.sys
F7D53000 - \SystemRoot\System32\Drivers\mnmdd.SYS
F7D57000 - \SystemRoot\System32\DRIVERS\RDPCDD.sys
F7BBF000 - \SystemRoot\System32\Drivers\Msfs.SYS
F7BCF000 - \SystemRoot\System32\Drivers\Npfs.SYS
F7CC7000 - \SystemRoot\System32\DRIVERS\rasacd.sys
F60A3000 - \SystemRoot\System32\DRIVERS\ipsec.sys
F604B000 - \SystemRoot\System32\DRIVERS\tcpip.sys
F6023000 - \SystemRoot\System32\DRIVERS\netbt.sys
F6002000 - \SystemRoot\System32\DRIVERS\ipnat.sys
F5FA8000 - \SystemRoot\System32\vsdatant.sys
F79EF000 - \SystemRoot\System32\DRIVERS\wanarp.sys
F5F5E000 - \SystemRoot\System32\drivers\afd.sys
F79FF000 - \SystemRoot\System32\DRIVERS\arp1394.sys
F7A0F000 - \SystemRoot\System32\DRIVERS\netbios.sys
F5E93000 - \SystemRoot\System32\DRIVERS\rdbss.sys
F5E24000 - \SystemRoot\System32\DRIVERS\mrxsmb.sys
F7BEF000 - \SystemRoot\System32\DRIVERS\usbprint.sys
F7A1F000 - \SystemRoot\System32\Drivers\Fips.SYS
F5D6C000 - \SystemRoot\System32\Drivers\avg7core.sys
F7276000 - \SystemRoot\System32\DRIVERS\usbscan.sys
F7D5D000 - \SystemRoot\System32\Drivers\avg7rsw.sys
F7C27000 - \SystemRoot\System32\Drivers\avg7rsxp.sys
F5D49000 - \SystemRoot\System32\Drivers\Fastfat.SYS
F5D31000 - \SystemRoot\System32\Drivers\dump_atapi.sys
F7D71000 - \SystemRoot\System32\Drivers\dump_WMILIB.SYS
BF800000 - \SystemRoot\System32\win32k.sys
F6112000 - \SystemRoot\System32\drivers\Dxapi.sys
F7AE7000 - \SystemRoot\System32\watchdog.sys
BF9C2000 - \SystemRoot\System32\drivers\dxg.sys
F7F61000 - \SystemRoot\System32\drivers\dxgthk.sys
BF9D4000 - \SystemRoot\System32\nv4_disp.dll
F4D0A000 - \??\C:\WINDOWS\system32\Drivers\ino_fltr.sys
F4D44000 - \SystemRoot\System32\DRIVERS\ndisuio.sys
F42AD000 - \SystemRoot\System32\DRIVERS\mrxdav.sys
F7DD7000 - \SystemRoot\System32\Drivers\ParVdm.SYS
F43D6000 - \SystemRoot\System32\Drivers\Aspi32.SYS
F4270000 - \SystemRoot\system32\drivers\wdmaud.sys
F4E38000 - \SystemRoot\system32\drivers\sysaudio.sys
F3F21000 - \??\C:\WINDOWS\System32\Drivers\CVPNDRV.sys
F3FF3000 - \SystemRoot\System32\Drivers\Cdfs.SYS
F7DAF000 - \??\C:\WINDOWS\System32\PfModNT.sys
F3C4F000 - \SystemRoot\System32\DRIVERS\srv.sys
F3B63000 - \??\C:\WINDOWS\System32\Drivers\Maestro0.sys
F3815000 - \SystemRoot\system32\drivers\kmixer.sys
F7E25000 - \SystemRoot\System32\DRIVERS\KProcCheck.sys
Total number of drivers = 127
KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)
Support driver successfully unloaded.
Logfile of HijackThis v1.99.1
Scan saved at 11:26:33 a.m., on 19/12/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\EDSNZ\VPN Client\cvpnd.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
C:\Program Files\CA\eTrust Antivirus\InoRT.exe
C:\Program Files\CA\eTrust Antivirus\InoTask.exe
C:\WINDOWS\LogWatNT.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\CA\Common\SCANEN~1\InoDist.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\CA\ETRUST~1\realmon.exe
C:\KMaestro\KMaestro.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\mapiicon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\HJT\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.nz/R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
O3 - Toolbar: SpoofStick - {4D46ED77-1429-4CF6-8F63-C84B5D710BAF} - C:\Program Files\CoreStreet\SpoofStick\SpoofStick.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Realtime Monitor] C:\PROGRA~1\CA\ETRUST~1\realmon.exe -s
O4 - HKLM\..\Run: [KeyMaestro] C:\KMaestro\KMaestro.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: ADSL Diagnostic Tools.LNK = C:\WINDOWS\system32\mapiicon.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Maintain Block List... - C:\PROGRA~1\AllStar\AdShield\maintain.htm
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Add to &Block List... - C:\PROGRA~1\AllStar\AdShield\suppress.htm
O8 - Extra context menu item: Add to &Exclude List... - C:\PROGRA~1\AllStar\AdShield\restrict.htm
O8 - Extra context menu item: AdShield Option &Settings... - C:\PROGRA~1\AllStar\AdShield\settings.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: AdShield - {4FB6C25E-7B37-4c93-B592-16ECD8D18361} - C:\WINDOWS\system32\shdocvw.dll (HKCU)
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone:
http://www.merchdirect.netO15 - Trusted Zone:
http://www.ultimatecarpage.comO16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage) -
http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) -
http://messenger.zone.msn.com/binary/MineS...er.cab28578.cabO16 - DPF: {3B0EA9E6-7003-4B38-B398-9B1B6DF439C5} -
http://download.answers.com/pub/AnswersSetup.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdat...b?1126758160141O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/Messe...nt.cab28578.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cabO16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} -
http://download.abacast.com/download/files/abasetup144.cabO16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) -
http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cabO18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\EDSNZ\VPN Client\cvpnd.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRT.exe
O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoTask.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Event Log Watch (LogWatch) - Unknown owner - C:\WINDOWS\LogWatNT.exe
O23 - Service: MQNGFSJLE - Unknown owner - C:\DOCUME~1\James\LOCALS~1\Temp\MQNGFSJLE.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
O23 - Service: TYCNMHJ - Unknown owner - C:\DOCUME~1\James\LOCALS~1\Temp\TYCNMHJ.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe