View Single Post
Old 02-12-2007, 10:52 PM   #3 (permalink)
cul8rman
Registered User
 
cul8rman's Avatar
 
Join Date: Aug 2006
Location: Arizona
Posts: 134
OS: XP


Results from step 1 download -

Diagnostic Report (1.7.0012.0):
-----------------------------------------
WGA Data-->
Validation Status: Genuine
Detailed Status: N/A
Windows Product Key: *****-*****-J8BM6-MXPH6-3R2BW
Windows Product Key Hash: YMRVitCEjlJfwDQfjDvm97FbWA4=
Windows Product ID: 55277-OEM-2111907-00103
Windows Product ID Type: 2
Windows License Type: OEM SLP
Windows OS version: 5.1.2600.2.00010300.1.0.hom
ID: 7aa11489-6a6b-4d60-b670-1b07893a27f0
Is Admin: Yes
AutoDial: No
Registry: 0x0
WGA Version: Registered, 1.5.530.0
Signed By: Microsoft
Product Name: N/A
Architecture: N/A
Build lab: N/A
TTS Error: N/A
Validation Diagnostic:
Resolution Status: N/A

Notifications Data-->
Cached Result: N/A
File Exists: No
Version: N/A
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002

OGA Data-->
Office Status: 109 N/A
OGA Version: Failed to retrieve file version. - 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: FCEE394C-3178-80070002_77F760FE-150-80070002_7E90FEE8-175-80070002_77F760FE-150-80070002_7E90FEE8-175-80070002

Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Win32)
Default Browser: C:\PROGRA~1\MOZILL~1\FIREFOX.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed

File Scan Data-->

Other data-->
Office Details: <GenuineResults><MachineData><UGUID>7aa11489-6a6b-4d60-b670-1b07893a27f0</UGUID><Version>1.7.0012.0</Version><OS>5.1.2600.2.00010300.1.0.hom</OS><PKey>*****-*****-*****-*****-3R2BW</PKey><PID>55277-OEM-2111907-00103</PID><PIDType>2</PIDType><SID>S-1-5-21-1784762916-2740901186-3389046013</SID><SYSTEM><Manufacturer>eMachines, Inc.</Manufacturer><Model>Imperial</Model></SYSTEM><BIOS><Manufacturer>Phoenix</Manufacturer><Version>6.00</Version><SMBIOSVersion major="2" minor="31"/><Date>20031002******.******+***</Date><SLPBIOS>EMACHINES</SLPBIOS></BIOS><HWID>11153F4F01842062</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>US Mountain Standard Time(GMT-07:00)</TimeZone><iJoin>0</iJoin><SBID><stat>2</stat><msppid></msppid><name>eMachines</name><model>T2692</model></SBID><OEM/></MachineData> <Software><Office><Result>109</Result><Products/></Office></Software></GenuineResults>

Results of Vundofix.text


VundoFix V6.3.6

Checking Java version...

Sun Java not detected
Scan started at 10:05:48 PM 2/12/2007

Listing files found while scanning....

C:\WINDOWS\system32\bcyqquco.exe
C:\WINDOWS\System32\jjkmp.bak1
C:\WINDOWS\System32\jjkmp.bak2
C:\WINDOWS\System32\jjkmp.ini
C:\WINDOWS\System32\jjkmp.ini2
C:\WINDOWS\System32\jjkmp.tmp
C:\WINDOWS\system32\kbfjmtiu.exe
C:\WINDOWS\System32\pmkjj.dll
C:\WINDOWS\system32\wokdkkfn.exe
C:\WINDOWS\system32\xxywuss.dll
C:\WINDOWS\system32\yaywwvv.dll
C:\WINDOWS\system32\yayywvu.dll

VundoFix V6.3.6

Checking Java version...

Sun Java not detected
Scan started at 10:18:51 PM 2/12/2007

Listing files found while scanning....

C:\WINDOWS\system32\awttqpm.dll
C:\WINDOWS\system32\bcyqquco.exe
C:\WINDOWS\system32\byxwttt.dll
C:\WINDOWS\system32\cbxxwxy.dll
C:\WINDOWS\system32\ddccdde.dll
C:\WINDOWS\system32\dgtorbmn.ini
C:\WINDOWS\system32\efcawvw.dll
C:\WINDOWS\system32\iifdabb.dll
C:\WINDOWS\system32\jkkhfda.dll
C:\WINDOWS\system32\jkkifgh.dll
C:\WINDOWS\system32\kbfjmtiu.exe
C:\WINDOWS\system32\khfgfcd.dll
C:\WINDOWS\System32\lfkekvsk.dll
C:\WINDOWS\system32\mljghgg.dll
C:\WINDOWS\system32\nmbrotgd.dll
C:\WINDOWS\system32\nnnlmjj.dll
C:\WINDOWS\system32\nnnlmjk.dll
C:\WINDOWS\system32\nnnoomm.dll
C:\WINDOWS\system32\nnnoopn.dll
C:\WINDOWS\system32\opnmlkl.dll
C:\WINDOWS\system32\opnnkii.dll
C:\WINDOWS\system32\opnopop.dll
C:\WINDOWS\System32\pmkjj.dll
C:\WINDOWS\system32\qomlmlj.dll
C:\WINDOWS\system32\qommnnk.dll
C:\WINDOWS\system32\qomnnnk.dll
C:\WINDOWS\system32\rqropop.dll
C:\WINDOWS\system32\rqrppol.dll
C:\WINDOWS\system32\rqrsrsq.dll
C:\WINDOWS\system32\urqrqrs.dll
C:\WINDOWS\system32\vturppo.dll
C:\WINDOWS\system32\vtusqnl.dll
C:\WINDOWS\system32\vtutsqr.dll
C:\WINDOWS\system32\wokdkkfn.exe
C:\WINDOWS\system32\xxywuss.dll
C:\WINDOWS\system32\yaywwvv.dll
C:\WINDOWS\system32\yayywvu.dll

Beginning removal...

Beginning removal...

Attempting to delete C:\WINDOWS\system32\awttqpm.dll
C:\WINDOWS\system32\awttqpm.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\bcyqquco.exe
C:\WINDOWS\system32\bcyqquco.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\byxwttt.dll
C:\WINDOWS\system32\byxwttt.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\cbxxwxy.dll
C:\WINDOWS\system32\cbxxwxy.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ddccdde.dll
C:\WINDOWS\system32\ddccdde.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\dgtorbmn.ini
C:\WINDOWS\system32\dgtorbmn.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\efcawvw.dll
C:\WINDOWS\system32\efcawvw.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\iifdabb.dll
C:\WINDOWS\system32\iifdabb.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\jkkhfda.dll
C:\WINDOWS\system32\jkkhfda.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\jkkifgh.dll
C:\WINDOWS\system32\jkkifgh.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\kbfjmtiu.exe
C:\WINDOWS\system32\kbfjmtiu.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\khfgfcd.dll
C:\WINDOWS\system32\khfgfcd.dll Has been deleted!

Attempting to delete C:\WINDOWS\System32\lfkekvsk.dll
C:\WINDOWS\System32\lfkekvsk.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\mljghgg.dll
C:\WINDOWS\system32\mljghgg.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\nmbrotgd.dll
C:\WINDOWS\system32\nmbrotgd.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\nnnlmjj.dll
C:\WINDOWS\system32\nnnlmjj.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\nnnlmjk.dll
C:\WINDOWS\system32\nnnlmjk.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\nnnoomm.dll
C:\WINDOWS\system32\nnnoomm.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\nnnoopn.dll
C:\WINDOWS\system32\nnnoopn.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\opnmlkl.dll
C:\WINDOWS\system32\opnmlkl.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\opnnkii.dll
C:\WINDOWS\system32\opnnkii.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\opnopop.dll
C:\WINDOWS\system32\opnopop.dll Has been deleted!

Attempting to delete C:\WINDOWS\System32\pmkjj.dll
C:\WINDOWS\System32\pmkjj.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\qomlmlj.dll
C:\WINDOWS\system32\qomlmlj.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\qommnnk.dll
C:\WINDOWS\system32\qommnnk.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\qomnnnk.dll
C:\WINDOWS\system32\qomnnnk.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\rqropop.dll
C:\WINDOWS\system32\rqropop.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\rqrppol.dll
C:\WINDOWS\system32\rqrppol.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\rqrsrsq.dll
C:\WINDOWS\system32\rqrsrsq.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\urqrqrs.dll
C:\WINDOWS\system32\urqrqrs.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vturppo.dll
C:\WINDOWS\system32\vturppo.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vtusqnl.dll
C:\WINDOWS\system32\vtusqnl.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vtutsqr.dll
C:\WINDOWS\system32\vtutsqr.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\wokdkkfn.exe
C:\WINDOWS\system32\wokdkkfn.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\xxywuss.dll
C:\WINDOWS\system32\xxywuss.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\yaywwvv.dll
C:\WINDOWS\system32\yaywwvv.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\yayywvu.dll
C:\WINDOWS\system32\yayywvu.dll Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal...


Results of HJT

Logfile of HijackThis v1.99.1
Scan saved at 10:46:52 PM, on 2/12/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\qwinpoeb.exe
C:\Program Files\Micro Innovations\Keyboard\kbdap32a.EXE
C:\Program Files\Micro Innovations\Mouse\mouse32a.exe
C:\WINDOWS\System32\fxsugwhh.exe
C:\WINDOWS\System32\cstatvmq.exe
C:\WINDOWS\System32\sdmmlmn.exe
C:\WINDOWS\System32\scmdcon.exe
C:\WINDOWS\System32\ctlmems.exe
C:\WINDOWS\System32\gmonstml.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\Duane\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///c:/secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_3_16_0.dll
O3 - Toolbar: WeatherBug Browser Bar - powered by MyWebSearch - {8EAB99C9-F9EC-4b64-A4BA-D9BCAE8779C2} - C:\Program Files\MyWebSearchWB\bar\1.bin\W6BAR.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Error Nuker] C:\Program Files\Error Nuker\bin\ErrorNuker.exe autostart
O4 - HKLM\..\Run: [Ulead AutoDetector] C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~2\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\Run: [DSS] C:\WINDOWS\BBSTORE\DSS\DSSAGENT.EXE
O4 - HKLM\..\Run: [ijciiqc.dll] C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\ijciiqc.dll,okbblr
O4 - HKLM\..\Run: [AutoSys] C:\WINDOWS\System32\autosys.exe
O4 - HKLM\..\Run: [{7B-BE-E8-8B-ZN}] C:\windows\system32\nodsregj.exe SKY001
O4 - HKLM\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\System32\qwinpoeb.exe SKY001
O4 - HKLM\..\Run: [OFFICEKB] C:\Program Files\Micro Innovations\Keyboard\kbdap32a.EXE
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Micro Innovations\Mouse\mouse32a.exe
O4 - HKLM\..\Run: [PC Pitstop Optimize Scheduler] C:\Program Files\PCPitstop\Optimize\PCPOptimize.exe -boot
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [lmjvservc] fxsugwhh.exe
O4 - HKLM\..\Run: [nvcdllx] C:\WINDOWS\System32\cstatvmq.exe
O4 - HKLM\..\Run: [csmhtop] C:\WINDOWS\System32\sdmmlmn.exe
O4 - HKLM\..\Run: [ddsysmns] C:\WINDOWS\System32\scmdcon.exe
O4 - HKLM\..\Run: [ncsmmlg] C:\WINDOWS\System32\ctlmems.exe
O4 - HKLM\..\Run: [kdmmcvs] C:\WINDOWS\System32\gmonstml.exe
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\System32\iiydacla.dll",setvm
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKCU\..\Run: [cwingllib] C:\WINDOWS\system32\atllsimm.exe
O4 - HKCU\..\Run: [jmlcv4m] C:\WINDOWS\System32\mgcplwin.exe
O4 - HKCU\..\Run: [WinInit] "C:\DOCUME~1\Duane\LOCALS~1\Temp\162015.exe "
O4 - HKCU\..\Run: [ymmsddlop] C:\WINDOWS\system32\vssmnptc.exe
O4 - HKCU\..\Run: [mdwinllm3] C:\WINDOWS\System32\sscmsslv.exe
O4 - HKCU\..\Run: [lvcdmsys] C:\WINDOWS\System32\dbbsrcc.exe
O4 - HKCU\..\Run: [winksddm] C:\WINDOWS\System32\jvmmods.exe
O4 - HKCU\..\Run: [lsmdwinr] C:\WINDOWS\System32\vstldmem.exe
O4 - HKCU\..\Run: [gdxapimn] C:\WINDOWS\System32\jgdepgc.exe
O4 - HKCU\..\Run: [nvcdllx] C:\WINDOWS\System32\cstatvmq.exe
O4 - HKCU\..\Run: [csmhtop] C:\WINDOWS\System32\sdmmlmn.exe
O4 - HKCU\..\Run: [ddsysmns] C:\WINDOWS\System32\scmdcon.exe
O4 - HKCU\..\Run: [ncsmmlg] C:\WINDOWS\System32\ctlmems.exe
O4 - HKCU\..\Run: [kdmmcvs] C:\WINDOWS\System32\gmonstml.exe
O4 - Startup: .protected
O4 - Global Startup: .protected
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbar...p=ZUxdm080YYUS
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: Video Poker - http://download.games.yahoo.com/game...s/y/vpt0_x.cab
O16 - DPF: Yahoo! Backgammon - http://download.games.yahoo.com/game...ts/y/at1_x.cab
O16 - DPF: Yahoo! Bingo - http://download.games.yahoo.com/game...ts/y/xt0_x.cab
O16 - DPF: Yahoo! Blackjack - http://download.games.yahoo.com/game...ts/y/jt0_x.cab
O16 - DPF: Yahoo! Checkers - http://download.games.yahoo.com/game...ts/y/kt4_x.cab
O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/game...ts/y/ct2_x.cab
O16 - DPF: Yahoo! Cribbage - http://download.games.yahoo.com/game...ts/y/it1_x.cab
O16 - DPF: Yahoo! Dice - http://download.games.yahoo.com/game...s/y/dct4_x.cab
O16 - DPF: Yahoo! Go Fish - http://download.games.yahoo.com/game...ts/y/zt3_x.cab
O16 - DPF: Yahoo! Klondike Solitaire - http://presence.games.yahoo.com/yog/y/ks12_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/game...ts/y/pt3_x.cab
O16 - DPF: Yahoo! Pyramids - http://download.games.yahoo.com/game...s/y/pyt1_x.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://support.cox.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {15589FA1-C456-11CE-BF01-000000000000} - http://www.errornuker.com/products/e...rInstaller.exe
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/mini...ansporter.cab?
O16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} (SurferNETWORK Plugin) - http://rd1.surfernetwork.com/surferplugin.ocx
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/14939218...p/RdxIE601.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://maricopa.gov/assessor/gis/plugin/mgaxctrl.cab
O16 - DPF: {7FE26BE2-B923-4B41-9834-E84DA1CC1F96} (Maid Control) - http://vsp.closetmaid.com/vsp/cmaidc...downloader.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://download.games.yahoo.com/game.../gpcontrol.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/game...ploader_v6.cab
O20 - AppInit_DLLs: dxclib303562752.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Windows Host Services (DLLHOST32) - Unknown owner - C:\WINDOWS\system\dllhost.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ICF - Unknown owner - C:\WINDOWS\System32\svchost.exe:exe.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Microsoft authenticate service (MsaSvc) - Unknown owner - C:\WINDOWS\System32\msasvc.exe (file missing)
O23 - Service: WINS Client (RpcPatch) - Unknown owner - C:\WINDOWS\System32\wins\DLLHOST.EXE (file missing)
O23 - Service: Network Connections Sharing (RpcTftpd) - Unknown owner - C:\WINDOWS\System32\wins\svchost.exe (file missing)
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TCP and UDP Supp0rt - Unknown owner - C:\WINDOWS\System32\tccpip.exe (file missing)
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: Microsoft Apache for Windows (Windows Apache Service) - Unknown owner - C:\WINDOWS\wpablin.exe (file missing)
cul8rman is offline