Yeah, I was worried about the thumbdrive too, but it scanned fine. I have an external hard drive that is used for backup that I will need to scan too. I tried to just back things up file by file in the past few days and hope it doesn't get an infected one but other backups may have something.
ComboFix 08-10-27.01 - Owner 2008-10-27 15:04:00.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.666 [GMT -5:00]
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point
FILE ::
C:\Documents and Settings\All Users\Application Data\acoho.dat
C:\Documents and Settings\All Users\Application Data\esurebale.pif
C:\Documents and Settings\All Users\Application Data\gosy.reg
C:\Documents and Settings\All Users\Application Data\voweva.vbs
C:\Documents and Settings\Owner\Application Data\aqixikixyd.dll
C:\WINDOWS\ebog.lib
C:\WINDOWS\nyfupa.vbs
C:\WINDOWS\ojeqopom.ban
C:\WINDOWS\rogip.sys
C:\WINDOWS\sopiryxuk.scr
C:\WINDOWS\system32\drivers\TDSSijso.sys
C:\WINDOWS\system32\gukylyw.lib
C:\WINDOWS\system32\koda.bat
C:\WINDOWS\system32\likyluki.bin
C:\WINDOWS\system32\sowapiwoci.bin
C:\WINDOWS\yfywak.reg
C:\WINDOWS\ykupyja.sys
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\acoho.dat
C:\Documents and Settings\All Users\Application Data\esurebale.pif
C:\Documents and Settings\All Users\Application Data\gosy.reg
C:\Documents and Settings\All Users\Application Data\voweva.vbs
C:\Documents and Settings\Owner\Application Data\aqixikixyd.dll
C:\temp\NoNav
C:\temp\NoNav\ESUGUnEn.exe
C:\temp\NoNav\nolu.inf
C:\temp\NoNav\nolu.reg
C:\temp\NoNav\NONAV.BAT
C:\temp\NoNav\nonav.inf
C:\temp\NoNav\nonav.pif
C:\temp\NoNav\nonav.reg
C:\temp\NoNav\nonav.txt
C:\temp\NoNav\noquar.inf
C:\temp\NoNav\noquar.reg
C:\temp\NoNav\RTVSTOP.EXE
C:\temp\NoNav\UnEngVar.BAT
C:\temp\NoNav\UnEngVar.Txt
C:\WINDOWS\ebog.lib
C:\WINDOWS\nyfupa.vbs
C:\WINDOWS\ojeqopom.ban
C:\WINDOWS\rogip.sys
C:\WINDOWS\sopiryxuk.scr
C:\WINDOWS\system32\drivers\TDSSijso.sys
C:\WINDOWS\system32\gukylyw.lib
C:\WINDOWS\system32\koda.bat
C:\WINDOWS\system32\likyluki.bin
C:\WINDOWS\system32\sowapiwoci.bin
C:\WINDOWS\yfywak.reg
C:\WINDOWS\ykupyja.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_TDSSserv
-------\Legacy_TDSSserv
-------\Legacy_TDSSSERV.SYS
((((((((((((((((((((((((( Files Created from 2008-09-27 to 2008-10-27 )))))))))))))))))))))))))))))))
.
2008-10-26 23:50 . 2008-10-26 23:50 <DIR> d-------- C:\Program Files\Avira
2008-10-26 23:50 . 2008-10-26 23:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-10-26 23:25 . 2008-10-27 15:04 <DIR> d-------- C:\temp
2008-10-26 22:31 . 2008-10-26 22:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NortonInstaller
2008-10-26 20:48 . 2008-10-26 20:48 <DIR> d-------- C:\WINDOWS\ERUNT
2008-10-26 20:47 . 2008-10-26 21:20 <DIR> d-------- C:\SDFix
2008-10-26 19:19 . 2008-10-26 19:29 <DIR> d-------- C:\Program Files\Microsoft Money
2008-10-26 15:57 . 2008-10-26 15:57 <DIR> d-------- C:\rsit
2008-10-26 15:31 . 2008-10-26 15:31 <DIR> d-------- C:\Program Files\Trend Micro
2008-10-26 14:13 . 2008-10-26 14:17 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-26 14:13 . 2008-10-26 14:13 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Malwarebytes
2008-10-26 14:13 . 2008-10-26 14:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-26 14:13 . 2008-10-22 16:10 38,496 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-26 14:13 . 2008-10-22 16:10 15,504 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-26 02:18 . 2008-10-26 02:18 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-10-26 01:57 . 2008-10-26 01:51 1,554,567 --a------ C:\SDFix.exe
2008-10-25 14:51 . 2008-10-25 14:51 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\Yahoo!
2008-10-25 14:51 . 2008-10-27 15:02 77,824 --a------ C:\WINDOWS\system32\TDSSeuvq.dll
2008-10-25 14:51 . 2008-10-27 15:02 31,232 --a------ C:\WINDOWS\system32\TDSSckvy.dll
2008-10-25 14:51 . 2008-10-27 15:02 30,720 --a------ C:\WINDOWS\system32\TDSSfhvv.dll
2008-10-25 14:51 . 2008-10-27 15:02 29,696 --a------ C:\WINDOWS\system32\TDSSurta.dll
2008-10-25 14:51 . 2008-10-27 15:02 26,112 --a------ C:\WINDOWS\system32\TDSSesan.dll
2008-10-25 14:51 . 2008-10-27 15:02 2,840 --a------ C:\WINDOWS\system32\TDSSnhvw.dll
2008-10-25 14:51 . 2008-10-27 15:02 164 --a------ C:\WINDOWS\system32\TDSSierd.dat
2008-09-29 14:41 . 2008-10-27 09:13 <DIR> d-------- C:\Program Files\iTunes
2008-09-29 14:41 . 2008-09-29 14:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-09-29 14:39 . 2008-10-25 23:12 <DIR> d-------- C:\Program Files\Bonjour
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-27 14:13 --------- d-----w C:\Program Files\iPod
2008-10-26 04:36 --------- d-----w C:\Program Files\Wal-Mart Music Downloads Store
2008-10-26 04:19 --------- d-----w C:\Program Files\THQ
2008-10-26 04:19 --------- d-----w C:\Program Files\sz8032
2008-10-26 04:19 --------- d-----w C:\Program Files\sz8022
2008-10-26 04:19 --------- d-----w C:\Program Files\Scholastic
2008-10-26 04:19 --------- d-----w C:\Program Files\RecordNow!
2008-10-26 04:19 --------- d-----w C:\Program Files\QuickTime
2008-10-26 04:19 --------- d-----w C:\Program Files\Print Workshop 2004 LE
2008-10-26 04:18 --------- d-----w C:\Program Files\Microsoft Works
2008-10-26 04:18 --------- d-----w C:\Program Files\Microsoft Visual Studio 8
2008-10-26 04:18 --------- d-----w C:\Program Files\Microsoft SQL Server
2008-10-26 04:18 --------- d-----w C:\Program Files\Microsoft Plus! Digital Media Edition
2008-10-26 04:18 --------- d-----w C:\Program Files\Microsoft IntelliPoint
2008-10-26 04:18 --------- d-----w C:\Program Files\Lavasoft
2008-10-26 04:17 --------- d-----w C:\Program Files\Juniper Networks
2008-10-26 04:17 --------- d-----w C:\Program Files\Java
2008-10-26 04:17 --------- d-----w C:\Program Files\ItsDeductibleEX
2008-10-26 04:17 --------- d-----w C:\Program Files\ItsDeductible2006
2008-10-26 04:17 --------- d-----w C:\Program Files\ItsDeductible2005
2008-10-26 04:17 --------- d-----w C:\Program Files\Iomega
2008-10-26 04:17 --------- d-----w C:\Program Files\IntelliMover Data Transfer Demo
2008-10-26 04:17 --------- d-----w C:\Program Files\Infogrames Interactive
2008-10-26 04:17 --------- d-----w C:\Program Files\HP
2008-10-26 04:17 --------- d-----w C:\Program Files\Hewlett-Packard
2008-10-26 04:17 --------- d-----w C:\Program Files\Hasbro Interactive
2008-10-26 04:15 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-10-26 04:15 --------- d-----w C:\Program Files\Common Files\Apple
2008-10-26 04:15 --------- d-----w C:\Program Files\Common Files\Adobe
2008-10-25 13:33 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-10-20 19:25 --------- d-----w C:\Documents and Settings\Owner\Application Data\AirSet Desktop Sync
2008-10-16 01:30 30 ----a-w C:\Documents and Settings\Owner\jagex_runescape_preferences.dat
2008-03-17 17:38 103,536 ----a-w C:\Documents and Settings\Owner\Application Data\GDIPFONTCACHEV1.DAT
2004-11-01 23:37 0 --sha-w C:\WINDOWS\SMINST\HPCD.sys
.
((((((((((((((((((((((((((((( snapshot@2008-10-26_20.01.28.40 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-08-07 20:27:04 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2008-10-27 01:48:35 9,252,864 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\
00000001\NTUSER.DAT
+ 2008-10-27 01:48:35 802,816 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\
00000002\UsrClass.dat
+ 2008-08-07 20:27:04 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-10-27 01:48:21 9,252,864 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\
00000001\NTUSER.DAT
+ 2008-10-27 01:48:22 802,816 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\
00000002\UsrClass.dat
- 2008-09-29 19:42:35 102,400 ----a-r C:\WINDOWS\Installer\{41B9E2CF-0B3F-442A-B5B3-592A4A355634}\iTunesIco.exe
+ 2008-10-27 14:13:43 102,400 ----a-r C:\WINDOWS\Installer\{41B9E2CF-0B3F-442A-B5B3-592A4A355634}\iTunesIco.exe
- 2008-10-27 00:58:28 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-10-27 20:02:04 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-10-27 00:58:28 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-10-27 20:02:04 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-10-27 18:06:06 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008102020081027\index.dat
+ 2008-10-27 18:42:19 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008102720081028\index.dat
- 2008-10-27 00:58:28 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-10-27 20:02:04 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-05-09 18:15:51 45,376 ----a-w C:\WINDOWS\system32\drivers\avgntdd.sys
+ 2008-01-21 23:11:28 22,336 ----a-w C:\WINDOWS\system32\drivers\avgntmgr.sys
+ 2008-06-27 20:03:55 75,072 ----a-w C:\WINDOWS\system32\drivers\avipbb.sys
+ 2007-03-01 15:34:22 28,352 ----a-w C:\WINDOWS\system32\drivers\ssmdrv.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Weather"="C:\Program Files\AWS\WeatherBug\Weather.exe" [2004-05-20 856064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2005-03-23 217088]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"VTTimer"="VTTimer.exe" [2005-03-08 C:\WINDOWS\system32\VTTimer.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 210520]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\Southwest Airlines\\Ding\\Ding.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R3 dsNcAdpt;Juniper Network Connect Adapter;C:\WINDOWS\system32\DRIVERS\dsNcAdpt.sys [2007-04-10 23552]
R3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2006-12-20 45568]
S2 ltmdmntc;ltmdmntc;C:\WINDOWS\System32\drivers\ltmdmntc.sys [ ]
S2 W55U01;WINBOND W55U01 USB;C:\WINDOWS\system32\Drivers\W55U01.sys [2005-08-12 15232]
S2 X4HS32;X4HS32;C:\Program Files\EXEtender\X4HS32.Sys [ ]
S3 BulkUsb;Usbscan.Sys;C:\WINDOWS\system32\Drivers\usbscan.sys [2004-08-04 15104]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2008-10-24 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe []
2004-03-17 C:\WINDOWS\Tasks\Easy Internet Sign-up.job
- C:\Program Files\Easy Internet signup\HPSdpApp.exe []
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-10-27 15:10:37
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Iomega Activity Disk2]
"ImagePath"="\"\""
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TDSSserv.sys]
"imagepath"="\systemroot\system32\drivers\TDSSijso.sys"
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\msiexec.exe
.
**************************************************************************
.
Completion time: 2008-10-27 15:18:56 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-27 20:18:52
ComboFix2.txt 2008-10-27 18:36:11
ComboFix3.txt 2008-10-27 17:38:42
ComboFix4.txt 2008-10-27 01:01:53
Pre-Run: 41,345,298,432 bytes free
Post-Run: 41,392,779,264 bytes free
233
HJT
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:40:46 PM, on 10/27/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\VTTimer.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.com/customize/ie/defaul...rch/search.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll (file missing)
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) -
http://www1.snapfish.com/SnapfishActivia.cabO16 - DPF: {5445BE81-B796-11D2-B931-002018654E2E} (MeadCo Security Manager) -
https://cim.accenture.com/system/web/view/l...g/ie/SecMgr.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/microsoftu...b?1218409226343O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) -
http://h20270.www2.hp.com/ediags/gmn2/inst...ctDetection.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/microsoftu...b?1218409212234O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) -
https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cabO16 - DPF: {B33422AC-C567-4F7D-BB28-6583371EC4EE} (Microsoft CMS HTML Editor) -
https://portal.accenture.com/NAVIGATOR/CMS/...ort/NRDHtml.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) -
http://cdn2.zone.msn.com/binFramework/v10/...ro.cab56649.cabO16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) -
http://a.download.toontown.com/sv1.0.15.44/ttinst.cabO16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) -
https://amr1-extranet.accenture.com/dana-ca...perSetupSP1.cabO16 - DPF: {E99D3E39-5D92-4360-BA86-2C563B3CFFEB} (Microsoft CMS HTML Editor Toolbar) -
https://portal.accenture.com/NAVIGATOR/CMS/...ort/nrdhtml.cabO17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = dir.svc.accenture.com,accenture.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = dir.svc.accenture.com,accenture.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = dir.svc.accenture.com,accenture.com
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (file missing)
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Office Source Engine (ose) - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (file missing)
O23 - Service: Messenger Sharing Folders USN Journal Reader service (usnjsvc) - Unknown owner - C:\Program Files\Windows Live\Messenger\usnsvc.exe (file missing)
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe (file missing)
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe
--
End of file - 8197 bytes
Things seem to running okay, but I'm missing a lot of files/executables so most of my apps no longer work. Also, I still keep getting a Windows Install on report that tries to install TrayApp.
What do you recommend I use for AV and other protection on this computer and my new Vista laptop?
Thanks.