View Single Post
Old 02-19-2007, 03:06 PM   #5 (permalink)
Musquie
Registered User
 
Join Date: Feb 2007
Posts: 6
OS: XP


More files...

I have completed your instructions and am posting the requested files below. Just a note to say that my computer is behaving much better, with no pop-ups apparent (yet anyway). I am surprised that scans are still coming up with infections. It makes me wonder how many types of virus software I need to catch it all.
-----------

AVG A/S:

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 11:17:22 PM 2007-02-18

+ Scan result:



HKLM\SOFTWARE\iGlobalMedia -> Adware.AceClubCasino : Cleaned with backup (quarantined).
HKLM\SOFTWARE\iGlobalMedia\Installer -> Adware.AceClubCasino : Cleaned with backup (quarantined).
HKLM\SOFTWARE\iGlobalMedia\partybingo -> Adware.AceClubCasino : Cleaned with backup (quarantined).
HKLM\SOFTWARE\iGlobalMedia\partybingo\casino -> Adware.AceClubCasino : Cleaned with backup (quarantined).
HKLM\SOFTWARE\iGlobalMedia\partybingo\casino\upgrades -> Adware.AceClubCasino : Cleaned with backup (quarantined).
HKLM\SOFTWARE\iGlobalMedia\partybingo\casino\version -> Adware.AceClubCasino : Cleaned with backup (quarantined).
HKLM\SOFTWARE\iGlobalMedia\partybingo\casino\version\boardbabe -> Adware.AceClubCasino : Cleaned with backup (quarantined).
HKLM\SOFTWARE\iGlobalMedia\partybingo\casino\version\coolbananas -> Adware.AceClubCasino : Cleaned with backup (quarantined).
HKLM\SOFTWARE\iGlobalMedia\partybingo\casino\version\flamingo -> Adware.AceClubCasino : Cleaned with backup (quarantined).
HKLM\SOFTWARE\iGlobalMedia\partybingo\casino\version\funkychicken -> Adware.AceClubCasino : Cleaned with backup (quarantined).
HKLM\SOFTWARE\iGlobalMedia\partybingo\casino\version\games -> Adware.AceClubCasino : Cleaned with backup (quarantined).
HKLM\SOFTWARE\iGlobalMedia\partybingo\casino\version\goannagold -> Adware.AceClubCasino : Cleaned with backup (quarantined).
HKLM\SOFTWARE\iGlobalMedia\partybingo\casino\version\goldeneagle -> Adware.AceClubCasino : Cleaned with backup (quarantined).
HKLM\SOFTWARE\iGlobalMedia\partybingo\casino\version\goldengopher -> Adware.AceClubCasino : Cleaned with backup (quarantined).
HKLM\SOFTWARE\iGlobalMedia\partybingo\casino\version\hotroller -> Adware.AceClubCasino : Cleaned with backup (quarantined).
HKLM\SOFTWARE\iGlobalMedia\partybingo\casino\version\junglerumble -> Adware.AceClubCasino : Cleaned with backup (quarantined).
HKLM\SOFTWARE\iGlobalMedia\partybingo\casino\version\kangacash -> Adware.AceClubCasino : Cleaned with backup (quarantined).
HKLM\SOFTWARE\iGlobalMedia\partybingo\casino\version\kenodll -> Adware.AceClubCasino : Cleaned with backup (quarantined).
HKLM\SOFTWARE\iGlobalMedia\partybingo\casino\version\kookakeno -> Adware.AceClubCasino : Cleaned with backup (quarantined).
HKLM\SOFTWARE\iGlobalMedia\partybingo\casino\version\magicmanslot -> Adware.AceClubCasino : Cleaned with backup (quarantined).
HKLM\SOFTWARE\iGlobalMedia\partybingo\casino\version\metropolis -> Adware.AceClubCasino : Cleaned with backup (quarantined).
HKLM\SOFTWARE\iGlobalMedia\partybingo\casino\version\nextgenvpdll -> Adware.AceClubCasino : Cleaned with backup (quarantined).
HKLM\SOFTWARE\iGlobalMedia\partybingo\casino\version\piggypayback -> Adware.AceClubCasino : Cleaned with backup (quarantined).
HKLM\SOFTWARE\iGlobalMedia\partybingo\casino\version\predatorslot -> Adware.AceClubCasino : Cleaned with backup (quarantined).
HKLM\SOFTWARE\iGlobalMedia\partybingo\casino\version\safecrackerkeno -> Adware.AceClubCasino : Cleaned with backup (quarantined).
HKLM\SOFTWARE\iGlobalMedia\partybingo\casino\version\silvercity -> Adware.AceClubCasino : Cleaned with backup (quarantined).
HKLM\SOFTWARE\iGlobalMedia\partybingo\casino\version\slotsdll -> Adware.AceClubCasino : Cleaned with backup (quarantined).
HKLM\SOFTWARE\iGlobalMedia\partybingo\casino\version\tod -> Adware.AceClubCasino : Cleaned with backup (quarantined).
HKLM\SOFTWARE\iGlobalMedia\partybingo\casino\version\vegasclub -> Adware.AceClubCasino : Cleaned with backup (quarantined).
HKLM\SOFTWARE\iGlobalMedia\starluckitalia -> Adware.AceClubCasino : Cleaned with backup (quarantined).
HKLM\SOFTWARE\iGlobalMedia\starluckitalia\casino -> Adware.AceClubCasino : Cleaned with backup (quarantined).
C:\WINDOWS\system32\GroupPolicy.UserCache\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf -> Backdoor.SdBot.ry : Cleaned with backup (quarantined).


::Report end

--------------------------

Kaspersky Scan:

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Monday, February 19, 2007 5:27:26 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 19/02/2007
Kaspersky Anti-Virus database records: 269294
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: false

Scan Target - My Computer:
C:\
D:\
O:\
P:\

Scan Statistics:
Total number of scanned objects: 149282
Number of viruses found: 11
Number of infected objects: 49 / 0
Number of suspicious objects: 0
Duration of the scan process: 09:14:32

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0CC80000.VBN Infected: Backdoor.Win32.Rbot.aeu skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0CC80001.VBN Infected: Backdoor.Win32.Rbot.aeu skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\MYERSWS\.housecall6.6\Quarantine\Microsoft.Office.2007.Enterprise.Keygen.Only-MiCROSOFT.rar.bac_a05952/Microsoft.Office.2007.Enterprise.Keygen.Only-MiCROSOFT/KeyGen.exe Infected: Backdoor.Win32.Rbot.aeu skipped
C:\Documents and Settings\MYERSWS\.housecall6.6\Quarantine\Microsoft.Office.2007.Enterprise.Keygen.Only-MiCROSOFT.rar.bac_a05952 RAR: infected - 1 skipped
C:\Documents and Settings\MYERSWS\.housecall6.6\Quarantine\Microsoft.Office.2007.Enterprise.Keygen.Only-MiCROSOFT.rar.bac_a05952 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\MYERSWS\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\MYERSWS\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\MYERSWS\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\MYERSWS\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\MYERSWS\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\MYERSWS\ntuser.dat Object is locked skipped
C:\Documents and Settings\MYERSWS\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\mirc\mIRC v6.16 [Keygen Included]\mIRC 6.16 Setup.exe/data0001.bin Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
C:\mirc\mIRC v6.16 [Keygen Included]\mIRC 6.16 Setup.exe mIRC: infected - 1 skipped
C:\Nsgov\My Downloads\3in1 combo\Macro Buddy\macrob14_full.exe/data0006 Infected: not-a-virus:Monitor.Win32.KeyLogger.o skipped
C:\Nsgov\My Downloads\3in1 combo\Macro Buddy\macrob14_full.exe/data0007 Infected: not-a-virus:Monitor.Win32.KeyLogger.o skipped
C:\Nsgov\My Downloads\3in1 combo\Macro Buddy\macrob14_full.exe Inno: infected - 2 skipped
C:\Nsgov\My Downloads\mIRC v6.16 [Keygen Included]\mIRC 6.16 Setup.exe/data0001.bin Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
C:\Nsgov\My Downloads\mIRC v6.16 [Keygen Included]\mIRC 6.16 Setup.exe mIRC: infected - 1 skipped
C:\Nsgov\My Received Files\mIRC v6.16 [Keygen Included].rar/mIRC v6.16 [Keygen Included]/mIRC 6.16 Setup.exe/data0001.bin Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
C:\Nsgov\My Received Files\mIRC v6.16 [Keygen Included].rar/mIRC v6.16 [Keygen Included]/mIRC 6.16 Setup.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
C:\Nsgov\My Received Files\mIRC v6.16 [Keygen Included].rar RAR: infected - 2 skipped
C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\mifdb\errors.log Object is locked skipped
C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
C:\Program Files\WinFax\Data\Status.WFD Object is locked skipped
C:\Program Files\WinFax\Data\Status.WFF Object is locked skipped
C:\Program Files\WinFax\Data\Status.WFG Object is locked skipped
C:\Program Files\WinFax\Data\Status.WFR Object is locked skipped
C:\Program Files\WinFax\Data\Status.WFX Object is locked skipped
C:\Program Files\WinFax\Data\Status2.WFD Object is locked skipped
C:\Program Files\WinFax\Data\Status2.WFG Object is locked skipped
C:\Program Files\WinFax\Data\Status2.WFX Object is locked skipped
C:\Program Files\WinFax\Data\Status3.WFD Object is locked skipped
C:\Program Files\WinFax\Data\Status3.WFG Object is locked skipped
C:\Program Files\WinFax\Data\Status3.WFX Object is locked skipped
C:\Program Files\WinFax\Data\StatusS.WFD Object is locked skipped
C:\Program Files\WinFax\Data\StatusS.WFG Object is locked skipped
C:\Program Files\WinFax\Data\StatusS.WFX Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{A0CEF90F-B7B6-42AD-BC36-BA0615F10CEE}\RP543\A0048677.exe Infected: not-a-virus:AdWare.Win32.Casino.i skipped
C:\System Volume Information\_restore{A0CEF90F-B7B6-42AD-BC36-BA0615F10CEE}\RP548\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Noble Poker setup.exe Infected: not-a-virus:AdWare.Win32.Casino.w skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\novell\nici\Administrator\XMGRCFG.KS2 Object is locked skipped
C:\WINDOWS\system32\novell\nici\Administrator\XMGRCFG.KS3 Object is locked skipped
C:\WINDOWS\system32\novell\nici\SuperNT\XMGRCFG.KS2 Object is locked skipped
C:\WINDOWS\system32\novell\nici\SuperNT\XMGRCFG.KS3 Object is locked skipped
C:\WINDOWS\system32\novell\nici\SYSTEM\XMGRCFG.KS2 Object is locked skipped
C:\WINDOWS\system32\novell\nici\SYSTEM\XMGRCFG.KS3 Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\~DF5466.tmp Object is locked skipped
C:\WINDOWS\Temp\~DF8DE9.tmp Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
O:\Data\Blackberry\AutoBackup-(2006-03-11).ipd Object is locked skipped
O:\Data\Blackberry\AutoBackup-(2006-03-13).ipd Object is locked skipped
O:\Data\Blackberry\Backup-(2006-02-05)-1.ipd Object is locked skipped
O:\Data\Blackberry\Backup-(2006-02-05)-2.ipd Object is locked skipped
O:\Data\Blackberry\Backup-(2006-02-05).ipd Object is locked skipped
O:\Data\Blackberry\Backup-(2006-03-11).ipd Object is locked skipped
O:\Folder Lock\3in1 combo\macrob14_full.exe/data0006 Infected: not-a-virus:Monitor.Win32.KeyLogger.o skipped
O:\Folder Lock\3in1 combo\macrob14_full.exe/data0007 Infected: not-a-virus:Monitor.Win32.KeyLogger.o skipped
O:\Folder Lock\3in1 combo\macrob14_full.exe Inno: infected - 2 skipped
O:\Folder Lock\3in1 combo.zip/macrob14_full.exe/data0006 Infected: not-a-virus:Monitor.Win32.KeyLogger.o skipped
O:\Folder Lock\3in1 combo.zip/macrob14_full.exe/data0007 Infected: not-a-virus:Monitor.Win32.KeyLogger.o skipped
O:\Folder Lock\3in1 combo.zip/macrob14_full.exe Infected: not-a-virus:Monitor.Win32.KeyLogger.o skipped
O:\Folder Lock\3in1 combo.zip ZIP: infected - 3 skipped
O:\LoaderBackup-(2006-03-11).ipd Object is locked skipped
O:\My Downloads\3in1 combo.zip/macrob14_full.exe/data0006 Infected: not-a-virus:Monitor.Win32.KeyLogger.o skipped
O:\My Downloads\3in1 combo.zip/macrob14_full.exe/data0007 Infected: not-a-virus:Monitor.Win32.KeyLogger.o skipped
O:\My Downloads\3in1 combo.zip/macrob14_full.exe Infected: not-a-virus:Monitor.Win32.KeyLogger.o skipped
O:\My Downloads\3in1 combo.zip ZIP: infected - 3 skipped
O:\My Downloads\Backup Files\CrackSearcher\cracksearcher.exe Infected: HackTool.Win32.CrackSearch.a skipped
O:\My Downloads\Bit Torrent\DVDFab Platinum 2.9.7.7.rar/DVDFab Platinum 2.9.7.7/setup.exe Infected: not-a-virus:AdWare.Win32.WinAD.bt skipped
O:\My Downloads\Bit Torrent\DVDFab Platinum 2.9.7.7.rar RAR: infected - 1 skipped
O:\My Downloads\Bit Torrent\Poker.Tracker.v2.06.02.WinALL.Incl.Keymaker-CORE\pt2su.exe/data0000.cab/INSTAL~1.EXE Infected: Backdoor.Win32.Bifrose.mq skipped
O:\My Downloads\Bit Torrent\Poker.Tracker.v2.06.02.WinALL.Incl.Keymaker-CORE\pt2su.exe/data0000.cab Infected: Backdoor.Win32.Bifrose.mq skipped
O:\My Downloads\Bit Torrent\Poker.Tracker.v2.06.02.WinALL.Incl.Keymaker-CORE\pt2su.exe DotFix NiceProtect: infected - 2 skipped
O:\My Downloads\DVD-Backup-10\Winamp.Pro.v5.1.Full + Plug-In.with.keygen.rar/Winamp.Pro.v5.1.Full + Plug-In.with.keygen/winamp51_full.exe/data0000.cab/iexplorer.exe Infected: Trojan-Clicker.Win32.VB.in skipped
O:\My Downloads\DVD-Backup-10\Winamp.Pro.v5.1.Full + Plug-In.with.keygen.rar/Winamp.Pro.v5.1.Full + Plug-In.with.keygen/winamp51_full.exe/data0000.cab Infected: Trojan-Clicker.Win32.VB.in skipped
O:\My Downloads\DVD-Backup-10\Winamp.Pro.v5.1.Full + Plug-In.with.keygen.rar/Winamp.Pro.v5.1.Full + Plug-In.with.keygen/winamp51_full.exe Infected: Trojan-Clicker.Win32.VB.in skipped
O:\My Downloads\DVD-Backup-10\Winamp.Pro.v5.1.Full + Plug-In.with.keygen.rar RAR: infected - 3 skipped
O:\My Downloads\mirc\mIRC v6.16 [Keygen Included]\mIRC 6.16 Setup.exe/data0001.bin Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
O:\My Downloads\mirc\mIRC v6.16 [Keygen Included]\mIRC 6.16 Setup.exe mIRC: infected - 1 skipped
O:\My Videos\0-31764 (Mar 26).mpg Object is locked skipped
O:\My Videos\0-31764 (Mar 31).mpg Object is locked skipped
P:\Downloads\mirc\mIRC v6.16 [Keygen Included]\mIRC 6.16 Setup.exe/data0001.bin Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
P:\Downloads\mirc\mIRC v6.16 [Keygen Included]\mIRC 6.16 Setup.exe mIRC: infected - 1 skipped
P:\Old Comp Files\Downloads\Bit Torrent\CrackSearcher.exe/CrackSearcher/cracksearcher.exe Infected: HackTool.Win32.CrackSearch.a skipped
P:\Old Comp Files\Downloads\Bit Torrent\CrackSearcher.exe ZIP: infected - 1 skipped
P:\Old Comp Files\Downloads\gdivx\GDiVX1.9.5.exe/data0007/SaveNow.exe Infected: not-a-virus:AdWare.Win32.SaveNow.ar skipped
P:\Old Comp Files\Downloads\gdivx\GDiVX1.9.5.exe/data0007 Infected: not-a-virus:AdWare.Win32.SaveNow.ar skipped
P:\Old Comp Files\Downloads\gdivx\GDiVX1.9.5.exe/data0008 Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
P:\Old Comp Files\Downloads\gdivx\GDiVX1.9.5.exe NSIS: infected - 3 skipped

Scan process completed.

----------------------------

New HJT:

Logfile of HijackThis v1.99.1
Scan saved at 5:28:50 PM, on 2007-02-19
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Compaq\Compaq Management Agents\cpqalert.exe
C:\PROGRA~1\Compaq\COMPAQ~1\CPQWEB~1\WebDmi.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\Cpqdiag\Cpqdfwag.exe
C:\WINDOWS\System32\NALNTSRV.EXE
C:\WINDOWS\System32\RegSrvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\WFXSVC.EXE
C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe
C:\Program Files\WinFax\WFXMOD32.EXE
C:\WINDOWS\System32\wm.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\NOVELL\ZENRC\WUOLService.exe
C:\PROGRA~1\Compaq\COMPAQ~1\cpqdmi.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\System32\1XConfig.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\PROGRA~1\Compaq\COMPAQ~1\CHKADMIN.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\EXSHOW95.EXE
C:\WINDOWS\System32\dpmw32.exe
C:\WINDOWS\system32\NWTRAY.EXE
C:\WINDOWS\VM_STI.EXE
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\PROGRA~1\WinFax\WFXSWTCH.exe
C:\WINDOWS\system32\wfxsnt40.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Hewlett-Packard\HP Mobile Printing\HPBMOBIL.EXE
C:\PROGRA~1\Nero\data\Xtras\mssysmgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/ig?hl=en
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [ChkAdmin] C:\PROGRA~1\Compaq\COMPAQ~1\CHKADMIN.EXE
O4 - HKLM\..\Run: [PRONoMgr.exe] c:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [EXSHOW95.EXE] EXSHOW95.EXE
O4 - HKLM\..\Run: [NDPS] C:\WINDOWS\System32\dpmw32.exe
O4 - HKLM\..\Run: [ZENRC Tray Icon] zentray.exe
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE USB(VGA) Camera
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [WFXSwtch] C:\PROGRA~1\WinFax\WFXSWTCH.exe
O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [\\WELDON-HP\EPSON Stylus Photo R200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE /P42 "\\WELDON-HP\EPSON Stylus Photo R200 Series" /O6 "USB002" /M "Stylus Photo R200"
O4 - HKLM\..\Run: [Auto EPSON Stylus Photo R200 Series on WELDON-HP] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE /P48 "Auto EPSON Stylus Photo R200 Series on WELDON-HP" /O20 "\\WELDON-HP\Printer5" /M "Stylus Photo R200"
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [Flap coal sign less] C:\Documents and Settings\All Users\Application Data\Proxy Support Flap Coal\Hearteggs.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\RunServices: [CPQDFWAG] C:\WINDOWS\Cpqdiag\CpqDfwAg.exe
O4 - HKCU\..\Run: [HP Mobile Printing] C:\Program Files\Hewlett-Packard\HP Mobile Printing\HPBMOBIL.EXE
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Nero\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: AbsolutePoker.com - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: AbsolutePoker.com - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
O15 - Trusted Zone: http://usa.kaspersky.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english...an_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/ho...vex/hcImpl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1111516712270
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1140128956597
O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} (Microsoft RDP Client Control (redist)) - http://www.gov.ns.ca/fina/rescsu/tsweb/msrdp.cab
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - file://C:\WINDOWS\msxml4.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://a.download.toontown.com/sv1.0.24.24/ttinst.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\System32\btxppanel.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O20 - Winlogon Notify: Sebring - c:\WINDOWS\System32\LgNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Insight Local Alerter (CPQALERT) - Hewlett-Packard Company - C:\Program Files\Compaq\Compaq Management Agents\cpqalert.exe
O23 - Service: cpqdmi - Compaq Computer Corporation - C:\PROGRA~1\Compaq\COMPAQ~1\cpqdmi.exe
O23 - Service: Insight Web Agent (cpqWebDmi) - Hewlett-Packard Company - C:\PROGRA~1\Compaq\COMPAQ~1\CPQWEB~1\WebDmi.exe
O23 - Service: Client Update Service for Novell (cusrvc) - Novell, Inc. - C:\WINDOWS\System32\cusrvc.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Remote Diagnostics Enabling Agent (DfwWebAgent) - Hewlett-Packard - C:\WINDOWS\Cpqdiag\Cpqdfwag.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Novell Application Launcher (NALNTSERVICE) - Novell, Inc. - C:\WINDOWS\System32\NALNTSRV.EXE
O23 - Service: Remote management (Novell WUser Agent) - Novell, Inc. - C:\NOVELL\ZENRC\wuser32.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: WinFax PRO (wfxsvc) - Symantec Corporation - C:\WINDOWS\system32\WFXSVC.EXE
O23 - Service: Win32Sl (WIN32SL) - Intel - C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe
O23 - Service: Novell Workstation Manager (WM) - Novell, Inc. - C:\WINDOWS\System32\wm.exe
O23 - Service: WUOLservice (WUOLService) - Novell, Inc. - C:\NOVELL\ZENRC\WUOLService.exe

------------------------------------

Thanks again for all the help,
musquie
Musquie is offline