View Single Post
Old 11-04-2008, 09:45 PM   #6 (permalink)
kru1992
Registered User
 
Join Date: Nov 2008
Posts: 8
OS: Windows XP


Re: computer running very slow

Thank you tetonbob here is the Avira report and the HijackThis logfile.


Avira AntiVir Personal
Report file date: Tuesday, November 04, 2008 22:03

Scanning for 1007891 virus strains and unwanted programs.

Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 3) [5.1.2600]
Boot mode: Normally booted
Username: SYSTEM
Computer name: FABIOLA-NH5CX1A

Version information:
BUILD.DAT : 8.2.0.334 16933 Bytes 10/16/2008 14:55:00
AVSCAN.EXE : 8.1.4.7 315649 Bytes 6/26/2008 16:57:53
AVSCAN.DLL : 8.1.4.0 40705 Bytes 5/26/2008 15:56:40
LUKE.DLL : 8.1.4.5 164097 Bytes 6/12/2008 20:44:19
LUKERES.DLL : 8.1.4.0 12033 Bytes 5/26/2008 15:58:52
ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 10/27/2008 04:01:08
ANTIVIR1.VDF : 7.1.0.21 130560 Bytes 10/31/2008 04:01:09
ANTIVIR2.VDF : 7.1.0.22 2048 Bytes 10/31/2008 04:01:10
ANTIVIR3.VDF : 7.1.0.36 106496 Bytes 11/4/2008 04:01:11
Engineversion : 8.2.0.10
AEVDF.DLL : 8.1.0.6 102772 Bytes 10/14/2008 18:05:56
AESCRIPT.DLL : 8.1.1.9 319867 Bytes 11/5/2008 04:01:21
AESCN.DLL : 8.1.1.3 123252 Bytes 10/14/2008 18:05:56
AERDL.DLL : 8.1.1.2 438644 Bytes 9/12/2008 1402
AEPACK.DLL : 8.1.2.4 369014 Bytes 10/14/2008 18:05:56
AEOFFICE.DLL : 8.1.0.29 196988 Bytes 11/5/2008 04:01:20
AEHEUR.DLL : 8.1.0.63 1479032 Bytes 11/5/2008 04:01:19
AEHELP.DLL : 8.1.1.2 115062 Bytes 10/14/2008 18:05:56
AEGEN.DLL : 8.1.0.42 319861 Bytes 11/5/2008 04:01:15
AEEMU.DLL : 8.1.0.9 393588 Bytes 10/14/2008 18:05:56
AECORE.DLL : 8.1.2.9 172407 Bytes 11/5/2008 04:01:13
AEBB.DLL : 8.1.0.3 53618 Bytes 10/14/2008 18:05:56
AVWINLL.DLL : 1.0.0.12 15105 Bytes 7/9/2008 16:40:05
AVPREF.DLL : 8.0.2.0 38657 Bytes 5/16/2008 17:28:01
AVREP.DLL : 8.0.0.2 98344 Bytes 11/5/2008 04:01:12
AVREG.DLL : 8.0.0.1 33537 Bytes 5/9/2008 19:26:40
AVARKT.DLL : 1.0.0.23 307457 Bytes 2/12/2008 16:29:23
AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 6/12/2008 20:27:49
SQLITE3.DLL : 3.3.17.1 339968 Bytes 1/23/2008 01:28:02
SMTPLIB.DLL : 1.2.0.23 28929 Bytes 6/12/2008 20:49:40
NETNT.DLL : 8.0.0.1 7937 Bytes 1/25/2008 20:05:10
RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 6/12/2008 21:48:07
RCTEXT.DLL : 8.0.52.0 86273 Bytes 6/27/2008 21:34:37

Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:,
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium

Start of the scan: Tuesday, November 04, 2008 22:03

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'setup.exe' - '1' Module(s) have been scanned
Scan process 'antivir_workstation_winu_en_h[1].exe' - '1' Module(s) have been scanned
Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
Scan process 'iexplore.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'CTSVCCDA.EXE' - '1' Module(s) have been scanned
Scan process 'mDNSResponder.exe' - '1' Module(s) have been scanned
Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned
Scan process 'cpkbinst.exe' - '1' Module(s) have been scanned
Scan process 'cpCCtrl.exe' - '1' Module(s) have been scanned
Scan process 'dpupdchk.exe' - '1' Module(s) have been scanned
Scan process 'cpACtrl.exe' - '1' Module(s) have been scanned
Scan process 'CTSyncU.exe' - '1' Module(s) have been scanned
Scan process 'ISUSPM.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'msmsgs.exe' - '1' Module(s) have been scanned
Scan process 'CTCheck.exe' - '1' Module(s) have been scanned
Scan process 'jusched.exe' - '1' Module(s) have been scanned
Scan process 'cpserver.exe' - '1' Module(s) have been scanned
Scan process 'realsched.exe' - '1' Module(s) have been scanned
Scan process 'OpWareSE4.exe' - '1' Module(s) have been scanned
Scan process 'itype.exe' - '1' Module(s) have been scanned
Scan process 'ipoint.exe' - '1' Module(s) have been scanned
Scan process 'ALCXMNTR.EXE' - '1' Module(s) have been scanned
Scan process 'KPDRV4XP.EXE' - '1' Module(s) have been scanned
Scan process 'KEMailKb.EXE' - '1' Module(s) have been scanned
Scan process 'CPHQ.exe' - '1' Module(s) have been scanned
Scan process 'apdproxy.exe' - '1' Module(s) have been scanned
Scan process 'hkcmd.exe' - '1' Module(s) have been scanned
Scan process 'igfxtray.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
49 processes with 49 modules were scanned

Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!

Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!

Starting to scan the registry.
The registry was scanned ( '55' files ).


Starting the file scan:

Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\Documents and Settings\Fabiola Kelly\.housecall6.6\Quarantine\iesbunst.exe.bac_a02100
[0] Archive type: HIDDEN
--> FIL\\\?\C:\Documents and Settings\Fabiola Kelly\.housecall6.6\Quarantine\iesbunst.exe.bac_a02100
[DETECTION] Is the TR/Dldr.Zlob.bgs.7 Trojan
[NOTE] The file was moved to '49841bc6.qua'!
C:\Documents and Settings\Fabiola Kelly\.housecall6.6\Quarantine\iesmin.exe.bac_a02100
[DETECTION] Is the TR/Dldr.Zlob.Gen Trojan
[NOTE] The file was moved to '49841bc9.qua'!
C:\Documents and Settings\Fabiola Kelly\.housecall6.6\Quarantine\iesmn.exe.bac_a02100
[0] Archive type: HIDDEN
--> FIL\\\?\C:\Documents and Settings\Fabiola Kelly\.housecall6.6\Quarantine\iesmn.exe.bac_a02100
[1] Archive type: RSRC
--> Object
[DETECTION] Is the TR/Dldr.Zlob.YT.60 Trojan
[DETECTION] Is the TR/Dldr.Zlob.Gen Trojan
[NOTE] The file was moved to '49841bcc.qua'!
C:\Documents and Settings\Fabiola Kelly\.housecall6.6\Quarantine\iesplg.dll.bac_a02100
[0] Archive type: HIDDEN
--> FIL\\\?\C:\Documents and Settings\Fabiola Kelly\.housecall6.6\Quarantine\iesplg.dll.bac_a02100
[DETECTION] Is the TR/Dldr.Zlob.YT.60 Trojan
[NOTE] The file was moved to '49841bd2.qua'!
C:\Documents and Settings\Fabiola Kelly\.housecall6.6\Quarantine\iesunst.exe.bac_a02100
[0] Archive type: HIDDEN
--> FIL\\\?\C:\Documents and Settings\Fabiola Kelly\.housecall6.6\Quarantine\iesunst.exe.bac_a02100
[DETECTION] Is the TR/Dldr.Zlob.awv.13 Trojan
[NOTE] The file was moved to '49841bd4.qua'!
C:\Documents and Settings\Fabiola Kelly\.housecall6.6\Quarantine\imsmain.exe.bac_a02100
[DETECTION] Is the TR/Dldr.Zlob.Gen Trojan
[NOTE] The file was moved to '49841bde.qua'!
C:\Documents and Settings\Fabiola Kelly\.housecall6.6\Quarantine\imsmn.exe.bac_a02100
[DETECTION] Is the TR/Dldr.Zlob.Gen Trojan
[NOTE] The file was moved to '49841be0.qua'!
C:\Documents and Settings\Fabiola Kelly\.housecall6.6\Quarantine\imsunst.exe.bac_a02100
[0] Archive type: HIDDEN
--> FIL\\\?\C:\Documents and Settings\Fabiola Kelly\.housecall6.6\Quarantine\imsunst.exe.bac_a02100
[DETECTION] Is the TR/Dldr.Zlob.Gen Trojan
[NOTE] The file was moved to '49841be5.qua'!
C:\Documents and Settings\Fabiola Kelly\Local Settings\Application Data\CyberDefender\Scam Alert\host.html
[DETECTION] Contains HEUR/HTML.Malware suspicious code
[NOTE] The detection was classified as suspicious.
[NOTE] The file was moved to '49841ce7.qua'!
C:\Documents and Settings\Fabiola Kelly\Local Settings\Application Data\CyberDefender\Scam Alert\referrer.html
[DETECTION] Contains HEUR/HTML.Malware suspicious code
[NOTE] The detection was classified as suspicious.
[NOTE] The file was moved to '49771ce0.qua'!
C:\Documents and Settings\Fabiola Kelly\Local Settings\Application Data\CyberDefender\Scam Alert\script.html
[DETECTION] Contains HEUR/HTML.Malware suspicious code
[NOTE] The detection was classified as suspicious.
[NOTE] The file was moved to '49831ce1.qua'!
C:\Qoobox\Quarantine\C\Program Files\XP_Antispyware\AVEngn.dll.vir
[DETECTION] Is the TR/Fake.AntivirusPro.J.2 Trojan
[NOTE] The file was moved to '49561edb.qua'!
C:\Qoobox\Quarantine\C\Program Files\XP_Antispyware\Uninstall.exe.vir
[DETECTION] Is the TR/Fakealert.ald.6 Trojan
[NOTE] The file was moved to '497a1ef6.qua'!
C:\Qoobox\Quarantine\C\Program Files\XP_Antispyware\wscui.cpl.vir
[DETECTION] Is the TR/Fake.AntivirusPro.J.1 Trojan
[NOTE] The file was moved to '49741efd.qua'!
C:\Qoobox\Quarantine\C\WINDOWS\system32\wini10455.exe.vir
[DETECTION] Is the TR/Fakealert.ald.6 Trojan
[NOTE] The file was moved to '497f1f25.qua'!
C:\Qoobox\Quarantine\C\WINDOWS\system32\_scui.cpl.vir
[DETECTION] Is the TR/Fake.AntivirusPro.J.1 Trojan
[NOTE] The file was moved to '49741f31.qua'!
C:\System Volume Information\_restore{D514B8B6-E545-4D68-9F9A-CA34DCD6A0A3}\RP909\A0082723.sys
[DETECTION] Is the TR/Rootkit.Gen Trojan
[NOTE] The file was moved to '4941202c.qua'!
C:\System Volume Information\_restore{D514B8B6-E545-4D68-9F9A-CA34DCD6A0A3}\RP909\A0082788.exe
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to '49412030.qua'!
C:\System Volume Information\_restore{D514B8B6-E545-4D68-9F9A-CA34DCD6A0A3}\RP910\A0083376.dll
[DETECTION] Is the TR/Fake.AntivirusPro.J.2 Trojan
[NOTE] The file was moved to '49412080.qua'!
C:\System Volume Information\_restore{D514B8B6-E545-4D68-9F9A-CA34DCD6A0A3}\RP910\A0083383.exe
[DETECTION] Is the TR/Fakealert.ald.6 Trojan
[NOTE] The file was moved to '49412084.qua'!
C:\System Volume Information\_restore{D514B8B6-E545-4D68-9F9A-CA34DCD6A0A3}\RP910\A0083384.cpl
[DETECTION] Is the TR/Fake.AntivirusPro.J.1 Trojan
[NOTE] The file was moved to '49412088.qua'!
C:\System Volume Information\_restore{D514B8B6-E545-4D68-9F9A-CA34DCD6A0A3}\RP910\A0083386.cpl
[DETECTION] Is the TR/Fake.AntivirusPro.J.1 Trojan
[NOTE] The file was moved to '4941208b.qua'!
C:\System Volume Information\_restore{D514B8B6-E545-4D68-9F9A-CA34DCD6A0A3}\RP910\A0083392.exe
[DETECTION] Is the TR/Fakealert.ald.6 Trojan
[NOTE] The file was moved to '4941208e.qua'!


End of the scan: Tuesday, November 04, 2008 22:36
Used time: 33:06 Minute(s)

The scan has been done completely.

8697 Scanning directories
199660 Files were scanned
21 viruses and/or unwanted programs were found
3 Files were classified as suspicious:
0 files were deleted
0 files were repaired
23 files were moved to quarantine
0 files were renamed
1 Files cannot be scanned
199635 Files not concerned
1675 Archives were scanned
1 Warnings
23 Notes


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:44:34 PM, on 11/4/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\SurfControl\CyberPatrol\cphq.exe
C:\PROGRA~1\MICROI~1\INTERN~1\KEMailKb.EXE
C:\PROGRA~1\MICROI~1\INTERN~1\KPDrv4XP.EXE
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\SurfControl\CyberPatrol\cpserver.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\Program Files\SurfControl\CyberPatrol\cpACtrl.exe
C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe
C:\Program Files\SurfControl\CyberPatrol\cpCCtrl.exe
C:\Program Files\SurfControl\CyberPatrol\cpkbinst.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\trend micro\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://safesearch.cyberdefender.com/smallsearch.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - ~EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: MyIdentityDefender - {A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6} - C:\Documents and Settings\Fabiola Kelly\Local Settings\Application Data\CyberDefender\cdmyidd.dll
O2 - BHO: MyIdentityDefender - {A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6} - C:\Documents and Settings\Fabiola Kelly\Local Settings\Application Data\CyberDefender\cdmyidd.dll
O3 - Toolbar: MyIdentityDefender - {A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6} - C:\Documents and Settings\Fabiola Kelly\Local Settings\Application Data\CyberDefender\cdmyidd.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [CyberPatrolNew] "C:\Program Files\SurfControl\CyberPatrol\cphq.exe" /m
O4 - HKLM\..\Run: [KEMailKb] C:\PROGRA~1\MICROI~1\INTERN~1\KEMailKb.EXE
O4 - HKLM\..\Run: [KPDrv4XP] C:\PROGRA~1\MICROI~1\INTERN~1\KPDrv4XP.EXE
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [CTCheck] C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbar...tml?p=ZCfox000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll
O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.dragongamez.com
O15 - Trusted Zone: http://*.maplestory.com
O15 - Trusted Zone: http://*.tenderfoot.com
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://download.shockwave.com/pub/otoy/OTOYAX.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramewor...o.cab34246.cab
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Services Client v.3.12) - http://gameadvisor.futuremark.com/global/msc3121.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...nt/swflash.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://zone.msn.com/bingame/feed/def...utLauncher.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by121fd.bay121.hotmail.msn.co...x/HMAtchmt.ocx
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--
End of file - 8385 bytes
kru1992 is offline