I'm sorry it has been so long since your reply. I have followed your steps. Thank you. When I reset my computer in Safe Mode I was unable to locate
MessengerPlus3
C:\Documents and Settings\All Users\Application Data\Amok Gram Vga Slow
C:\Documents and Settings\YOUR USERNAME\Start Menu\Programs\Startup\csrss.lnk
C:\WINDOWS\system32\jvyolx
Here are my logs:
NoLop! Log by Skate_Punk_21
Fix running from: C:\Documents and Settings\Administrator\Desktop
[29/01/2007]
[3:03:01 PM]
---Infection Files Found/Removed---
C:\WINDOWS\tasks\A6DD4BBD912AC629.job
Beginning Removal...
Rebooting...
Removing Lop's Leftover Files/Folders...
Editing Registry...
**Fix Complete!**
---Listing AppData sub directories---
C:\Documents and Settings\Default User\Application Data\Microsoft
C:\Documents and Settings\All Users\Application Data\Microsoft
C:\Documents and Settings\All Users\Application Data\Objtwowindowfast
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
C:\Documents and Settings\All Users\Application Data\Apple Computer
C:\Documents and Settings\All Users\Application Data\Quicktime
C:\Documents and Settings\All Users\Application Data\Macrovision
C:\Documents and Settings\All Users\Application Data\Symantec
C:\Documents and Settings\All Users\Application Data\Adobe
C:\Documents and Settings\All Users\Application Data\Avg7
C:\Documents and Settings\All Users\Application Data\Skype
C:\Documents and Settings\All Users\Application Data\Pixelstorm
C:\Documents and Settings\All Users\Application Data\Adobe Systems
C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
C:\Documents and Settings\All Users\Application Data\Nvidia Corporation
C:\Documents and Settings\All Users\Application Data\Grisoft
C:\Documents and Settings\All Users\Application Data\Move Networks
C:\Documents and Settings\All Users\Application Data\Teleca
C:\Documents and Settings\All Users\Application Data\Sony Ericsson
C:\Documents and Settings\All Users\Application Data\Temp -- EMPTY Directory
C:\Documents and Settings\Networkservice\Application Data\Microsoft
C:\Documents and Settings\Localservice\Application Data\Microsoft
C:\Documents and Settings\Localservice\Application Data\Avg7 -- EMPTY Directory
C:\Documents and Settings\Administrator\Application Data\Microsoft
C:\Documents and Settings\Administrator\Application Data\Identities
C:\Documents and Settings\Administrator\Application Data\Mozilla
C:\Documents and Settings\Administrator\Application Data\Help -- EMPTY Directory
C:\Documents and Settings\Administrator\Application Data\Mail Bike Safe -- EMPTY Directory
C:\Documents and Settings\Administrator\Application Data\Sun
C:\Documents and Settings\Administrator\Application Data\Lavasoft
C:\Documents and Settings\Administrator\Application Data\Macromedia
C:\Documents and Settings\Administrator\Application Data\Apple Computer
C:\Documents and Settings\Administrator\Application Data\Adobe
C:\Documents and Settings\Administrator\Application Data\Adobeum
C:\Documents and Settings\Administrator\Application Data\Symantec
C:\Documents and Settings\Administrator\Application Data\Thunderbird
C:\Documents and Settings\Administrator\Application Data\Teamspeak2
C:\Documents and Settings\Administrator\Application Data\Avg7
C:\Documents and Settings\Administrator\Application Data\Real
C:\Documents and Settings\Administrator\Application Data\Skype
C:\Documents and Settings\Administrator\Application Data\Vlc
C:\Documents and Settings\Administrator\Application Data\Atari
C:\Documents and Settings\Administrator\Application Data\Securom
C:\Documents and Settings\Administrator\Application Data\Leadertech
C:\Documents and Settings\Administrator\Application Data\Revolution
C:\Documents and Settings\Administrator\Application Data\Musicmatch
C:\Documents and Settings\Administrator\Application Data\Installshield Installation Information
C:\Documents and Settings\Administrator\Application Data\Talkback
C:\Documents and Settings\Administrator\Application Data\1clickdvdcopy
C:\Documents and Settings\Administrator\Application Data\Copytodvd -- EMPTY Directory
C:\Documents and Settings\Administrator\Application Data\?dobe
C:\Documents and Settings\Administrator\Application Data\Slysoft
C:\Documents and Settings\Administrator\Application Data\Teleca
C:\Documents and Settings\Administrator\Application Data\Smith Micro
C:\Documents and Settings\Administrator\Application Data\Ign_dlm
--------------------------------------------------------------------------
"Administrator" - 07-01-29 14:53:07 Service Pack 2
ComboFix 07-01-25 - Running from: "C:\Documents and Settings\Administrator\desktop"
Command switches used :: /v winrbt32 tncf
(((((((((((((((((((((((((((((((((((((((((((((((( Vundo Log )))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\tncf.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\drivers\npf.sys
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\DOCUME~1
C:\qoobox\purity\WINDOWS\CROSOF~1.NET
C:\qoobox\purity\WINDOWS\MCROSO~1.NET
C:\qoobox\purity\WINDOWS\SKS~1
C:\qoobox\purity\WINDOWS\çSKS~1
C:\qoobox\purity\WINDOWS\FNTS~1
C:\qoobox\purity\WINDOWS\ASEMBL~1
C:\qoobox\purity\WINDOWS\SEMBLY~1
C:\qoobox\purity\WINDOWS\system32\YMANTE~1
C:\qoobox\purity\WINDOWS\system32\DOBE~1
C:\qoobox\purity\WINDOWS\system32\ICROSO~1
C:\qoobox\purity\WINDOWS\system32\MCROSO~1.NET
C:\qoobox\purity\WINDOWS\system32\YSTEM3~1
C:\qoobox\purity\WINDOWS\system32\CURITY~1
C:\qoobox\purity\WINDOWS\system32\FNTS~1
C:\qoobox\purity\WINDOWS\system32\PPPATC~1
C:\qoobox\purity\Program Files\SMANTE~1
C:\qoobox\purity\Program Files\çSKS~1
C:\qoobox\purity\Program Files\YSTEM~1
C:\qoobox\purity\Program Files\MBOLS~1
C:\qoobox\purity\Program Files\Common Files\SMANTE~1
C:\qoobox\purity\Program Files\Common Files\YMANTE~1
C:\qoobox\purity\Program Files\Common Files\ICROSO~1
C:\qoobox\purity\Program Files\Common Files\CROSOF~1.NET
C:\qoobox\purity\Program Files\Common Files\ICROSO~1.NET
C:\qoobox\purity\Program Files\Common Files\WNSXS~1
C:\qoobox\purity\Program Files\Common Files\TSKS~1
C:\qoobox\purity\Program Files\Common Files\YSTEM3~1
C:\qoobox\purity\Program Files\Common Files\ECURIT~1
C:\qoobox\purity\Program Files\Common Files\SSEMBL~1
C:\qoobox\purity\DOCUME~1\ADMINI~1
C:\qoobox\purity\DOCUME~1\ADMINI~1\Application Data
C:\qoobox\purity\DOCUME~1\ADMINI~1\My Documents
C:\qoobox\purity\DOCUME~1\ADMINI~1\Application Data\from.txt
C:\qoobox\purity\DOCUME~1\ADMINI~1\Application Data\MCROSO~1
C:\qoobox\purity\DOCUME~1\ADMINI~1\Application Data\çSKS~1
C:\qoobox\purity\DOCUME~1\ADMINI~1\Application Data\TSKS~1
C:\qoobox\purity\DOCUME~1\ADMINI~1\Application Data\STEM~1
C:\qoobox\purity\DOCUME~1\ADMINI~1\Application Data\SSEMBL~1
C:\qoobox\purity\DOCUME~1\ADMINI~1\My Documents\from.txt
C:\qoobox\purity\DOCUME~1\ADMINI~1\My Documents\RACLE~1
C:\qoobox\purity\DOCUME~1\ADMINI~1\My Documents\SMANTE~1
C:\qoobox\purity\DOCUME~1\ADMINI~1\My Documents\DOBE~1
C:\qoobox\purity\DOCUME~1\ADMINI~1\My Documents\ICROSO~1
C:\qoobox\purity\DOCUME~1\ADMINI~1\My Documents\CROSOF~1.NET
C:\qoobox\purity\DOCUME~1\ADMINI~1\My Documents\WNSXS~1
C:\qoobox\purity\DOCUME~1\ADMINI~1\My Documents\ASKS~1
C:\qoobox\purity\DOCUME~1\ADMINI~1\My Documents\YSTEM3~1
C:\qoobox\purity\DOCUME~1\ADMINI~1\My Documents\SMBOLS~1
C:\qoobox\purity\DOCUME~1\ADMINI~1\My Documents\FNTS~1
C:\qoobox\purity\DOCUME~1\ADMINI~1\My Documents\àPPATC~1
C:\qoobox\purity\DOCUME~1\ADMINI~1\My Documents\ASKS~1\ASKS~1
C:\qoobox\purity\DOCUME~1\ADMINI~1\My Documents\ASKS~1\wowexec.exe
((((((((((((((((((((((((((((((( Files Created from 2006-12-29 to 2007-01-29 ))))))))))))))))))))))))))))))))))
2007-01-29 14:55 <DIR> d-------- C:\WINDOWS\erdnt
2007-01-27 15:31 <DIR> d--hs---- C:\FOUND.003
2007-01-25 16:31 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll
2007-01-14 11:22 <DIR> d-------- C:\Program Files\iPod
2007-01-14 11:19 <DIR> d-------- C:\Program Files\Apple Software Update
2007-01-11 03:00 <DIR> d-------- C:\WINDOWS\ie7updates
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-01-29 08:01 40 ---hs---- C:\Documents and Settings\Administrator\Application Data\.zreglib
2006-12-12 16:25 2 --a------ C:\WINDOWS\system32\wnsapisv.exe
2006-12-11 05:41 190976 -r-hs---- C:\?hkdsk.exe
2006-12-10 12:50 -------- d-------- C:\Documents and Settings\Administrator\Application Data\ign_dlm
2006-12-06 21:29 2374472 --a------ C:\WINDOWS\system32\wmvcore.dll
2006-12-03 23:15 737280 --a------ C:\WINDOWS\iun6002.exe
2006-11-22 18:36 3082 --a------ C:\WINDOWS\system32\affv11300p2now.sys
2006-11-11 06:57 356352 --a------ C:\WINDOWS\esellerateengine.dll
2006-11-07 21:06 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-11-07 21:03 6049280 --------- C:\WINDOWS\system32\ieframe.dll
2006-11-07 21:03 50688 --------- C:\WINDOWS\system32\msfeedsbs.dll
2006-11-07 21:03 458752 --------- C:\WINDOWS\system32\msfeeds.dll
2006-11-07 21:03 413696 --a------ C:\WINDOWS\system32\vbscript.dll
2006-11-07 21:03 231424 --a------ C:\WINDOWS\system32\webcheck.dll
2006-11-07 21:03 180736 --------- C:\WINDOWS\system32\ieui.dll
2006-11-07 21:03 156160 --a------ C:\WINDOWS\system32\msls31.dll
2006-11-07 03:27 382976 --a------ C:\WINDOWS\system32\iedkcs32.dll
2006-11-07 03:27 229376 --a------ C:\WINDOWS\system32\ieaksie.dll
2006-11-07 03:26 71680 --a------ C:\WINDOWS\system32\admparse.dll
2006-11-07 03:26 55296 --a------ C:\WINDOWS\system32\iesetup.dll
2006-11-07 03:26 54784 --a------ C:\WINDOWS\system32\ie4uinit.exe
2006-11-07 03:26 43008 --a------ C:\WINDOWS\system32\iernonce.dll
2006-11-07 03:26 152064 --a------ C:\WINDOWS\system32\ieakeng.dll
2006-11-07 03:26 13312 --a------ C:\WINDOWS\system32\ieudinit.exe
2006-11-07 03:26 123904 --a------ C:\WINDOWS\system32\advpack.dll
2006-11-07 03:25 161792 --a------ C:\WINDOWS\system32\ieakui.dll
2006-11-04 14:14 1245696 --a------ C:\WINDOWS\system32\msxml4.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"Steam"=""
"Kyieqrhj"="\\?hkdsk.exe"
"Oohs"="\"C:\\DOCUME~1\\ADMINI~1\\MYDOCU~1\\ASKS~1\\wowexec.exe\" -vt ndrv"
"AnyDVD"="E:\\Program Files\\SlySoft\\AnyDVD\\AnyDVD.exe"
"svchost"="C:\\WINDOWS\\system32\\jvyolx\\svchost.exe"
"igndlm.exe"="E:\\Program Files\\FilePlanet\\Download Manager\\DLM.exe /windowsstart /startifwork"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"vga slow proxy math"="C:\\Documents and Settings\\All Users\\Application Data\\Amok Gram Vga Slow\\AXIS FLAW.exe"
"UStorag"="c:\\program files\\u-storage tool2.91\\ustorage.exe sys_auto_run C:\\Program Files\\U-Storage Tool2.91"
"Wise-FTP Scheduler"=""
"URLLSTCK.exe"="E:\\Treadstone Setups\\UrlLstCk.exe"
"MessengerPlus3"="\"E:\\Treadstone Setups\\MsgPlus.exe\""
"DAEMON Tools-1033"="\"E:\\Program Files\\TorrentSpy stuff\\daemon.exe\" -lang 1033"
"AudioDeck"="C:\\Program Files\\VIA Technologies, Inc\\Audio Deck\\ADeck.exe"
"MimBoot"="C:\\PROGRA~1\\MUSICM~1\\MUSICM~2\\mimboot.exe"
"SunJavaUpdateSched"="E:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"AVG7_CC"="E:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"LVCOMS"="C:\\WINDOWS\\system32\\LVComS.exe"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"KernelFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,\
65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b,00
@=""
"Sony Ericsson PC Suite"="\"E:\\Program Files\\Sony Ericsson\\Mobile2\\Application Launcher\\Application Launcher.exe\" /startoptions"
"QuickTime Task"="\"E:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"E:\\Program Files\\iTunes\\iTunesHelper.exe\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"appinit_dlls"="mshta.dll "
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{81559C35-8464-49F7-BB0E-07A383BEF910}"=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"0aMCPClient"="{F5DF91F9-15E9-416B-A7C3-7519B11ECBFC}"
"UPnPMonitor"="{e57ce738-33e8-4c51-8354-bb4de9d215d1}"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="E:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"AVG7_Run"="E:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{34c43c65-1d79-11da-a858-000fea1c652e}]
Shell\AutoRun\command I:\setupSNK.exe
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\A6DD4BBD912AC629.job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
Completion time: 07-01-29 15:00:02
-----------------------------------------------------------------------
Volume in drive C has no label.
Volume Serial Number is 1F68-17DE
Directory of C:\Documents and Settings\All Users\Application Data
29/12/2004 04:31 PM <DIR> .
29/12/2004 04:31 PM <DIR> ..
30/12/2004 11:31 AM <DIR> ObjTwoWindowFast
31/12/2004 03:40 PM <DIR> Spybot - Search & Destroy
07/01/2005 05:59 PM <DIR> Apple Computer
07/01/2005 05:59 PM <DIR> QuickTime
09/01/2005 03:12 PM <DIR> Macrovision
15/01/2005 03:49 PM <DIR> Symantec
23/01/2005 03:04 PM <DIR> Adobe
25/03/2005 09:12 PM <DIR> AVG7
29/05/2005 08:03 PM <DIR> Skype
21/08/2005 02:10 AM <DIR> pixelStorm
02/10/2005 02:43 PM <DIR> Adobe Systems
09/10/2005 10:14 AM <DIR> Windows Genuine Advantage
27/01/2007 10:20 PM 3,341 QTSBandwidthCache
25/01/2006 06:04 PM <DIR> NVIDIA Corporation
31/03/2006 11:39 PM <DIR> Grisoft
11/11/2006 12:16 AM <DIR> Teleca
11/11/2006 12:16 AM <DIR> Sony Ericsson
11/11/2006 01:36 PM <DIR> TEMP
1 File(s) 3,341 bytes
19 Dir(s) 3,277,111,296 bytes free
Volume in drive C has no label.
Volume Serial Number is 1F68-17DE
Directory of C:\Documents and Settings\Administrator\Application Data
29/12/2004 04:05 PM <DIR> .
29/12/2004 04:05 PM <DIR> ..
29/12/2004 04:05 PM <DIR> Identities
29/12/2004 04:13 PM <DIR> Mozilla
29/12/2004 07:45 PM <DIR> Help
29/12/2004 11:00 PM <DIR> mail bike safe
30/12/2004 12:07 PM <DIR> Sun
31/12/2004 03:47 PM <DIR> Lavasoft
01/01/2005 07:46 PM <DIR> Macromedia
07/01/2005 05:59 PM <DIR> Apple Computer
12/01/2005 06:53 PM <DIR> Adobe
12/01/2005 06:54 PM <DIR> AdobeUM
15/01/2005 03:50 PM <DIR> Symantec
19/01/2005 11:04 PM <DIR> Thunderbird
25/01/2005 10:45 PM 0 dm.ini
25/01/2005 10:45 PM 881 AdobeDLM.log
15/02/2005 07:12 PM <DIR> teamspeak2
25/03/2005 09:12 PM <DIR> AVG7
10/04/2005 02:32 PM <DIR> Real
29/05/2005 08:03 PM <DIR> Skype
21/06/2005 05:42 PM <DIR> vlc
29/06/2005 10:26 AM <DIR> Atari
14/08/2005 09:36 PM <DIR> Leadertech
27/11/2005 04:37 PM <DIR> Revolution
03/12/2005 02:31 PM <DIR> Musicmatch
19/03/2006 10:46 PM <DIR> InstallShield Installation Information
25/03/2006 12:55 PM <DIR> Talkback
15/04/2006 11:01 AM <DIR> 1ClickDVDCopy
15/04/2006 11:43 AM <DIR> CopyToDvd
22/08/2006 02:55 PM <DIR> àdobe
11/09/2006 04:07 PM <DIR> SlySoft
11/11/2006 12:17 AM <DIR> Teleca
03/12/2006 06:10 PM <DIR> Smith Micro
10/12/2006 12:50 PM <DIR> IGN_DLM
2 File(s) 881 bytes
32 Dir(s) 3,277,111,296 bytes free
Volume in drive C has no label.
Volume Serial Number is 1F68-17DE
Directory of C:\Documents and Settings\Default User\Application Data
29/12/2004 04:31 PM 62 desktop.ini
1 File(s) 62 bytes
0 Dir(s) 3,277,111,296 bytes free
Volume in drive C has no label.
Volume Serial Number is 1F68-17DE
Directory of C:\Documents and Settings\NetworkService\Application Data
Volume in drive C has no label.
Volume Serial Number is 1F68-17DE
Directory of C:\Documents and Settings\LocalService\Application Data
[TRACE] Enumerating jobs and queues
[TRACE] Activating job 'AppleSoftwareUpdate.job'
[TRACE] Printing all job properties
ApplicationName: 'C:\Program Files\Apple Software Update\SoftwareUpdate.exe'
Parameters: '-Task'
WorkingDirectory: ''
Comment: ''
Creator: 'SYSTEM'
Priority: NORMAL
MaxRunTime: 259200000 (3d 0:00:00)
IdleWait: 10
IdleDeadline: 60
MostRecentRun: 00/00/0000 0:00:00
NextRun: 02/02/2007 17:27:00
StartError: 0x80090016
ExitCode: 0
Status: SCHED_S_TASK_HAS_NOT_RUN
ScheduledWorkItem Flags:
DeleteWhenDone = 0
Suspend = 0
StartOnlyIfIdle = 0
KillOnIdleEnd = 0
RestartOnIdleResume = 0
DontStartIfOnBatteries = 0
KillIfGoingOnBatteries = 0
RunOnlyIfLoggedOn = 0
SystemRequired = 0
Hidden = 0
TaskFlags: 0
1 Trigger
Trigger 0:
Type: Weekly
WeeksInterval: 1
DaysOfTheWeek: .....F.
StartDate: 10/01/2006
EndDate: 00/00/0000
StartTime: 17:27
MinutesDuration: 0
MinutesInterval: 0
Flags:
HasEndDate = 0
KillAtDuration = 0
Disabled = 0
--------------------------------------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 3:55:21 PM, on 29/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
E:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\program files\u-storage tool2.91\ustorage.exe
E:\Program Files\TorrentSpy stuff\daemon.exe
C:\Program Files\VIA Technologies, Inc\Audio Deck\ADeck.exe
E:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\MUSICM~1\MUSICM~2\MMDiag.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\LVComS.exe
E:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
E:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
E:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
E:\Program Files\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - E:\Program Files\SpywareGuard\dlprotect.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [UStorag] c:\program files\u-storage tool2.91\ustorage.exe sys_auto_run C:\Program Files\U-Storage Tool2.91
O4 - HKLM\..\Run: [URLLSTCK.exe] E:\Treadstone Setups\UrlLstCk.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "E:\Program Files\TorrentSpy stuff\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIA Technologies, Inc\Audio Deck\ADeck.exe
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] E:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [AVG7_CC] E:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [LVCOMS] C:\WINDOWS\system32\LVComS.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "E:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "E:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AnyDVD] E:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKCU\..\Run: [igndlm.exe] E:\Program Files\FilePlanet\Download Manager\DLM.exe /windowsstart /startifwork
O4 - Startup: SMPMEnvSetup.lnk = E:\Treadstone Setups\SMPMEnvSetup.exe
O4 - Startup: SpywareGuard.lnk = E:\Program Files\SpywareGuard\sgmain.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: csrss.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = E:\Program Files\Reader\reader_sl.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = E:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1BAD0830-AC09-44FA-8A44-5365AEB45D11} - http://www.mtv.com/overdrive/bin/setup.exe
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.3.102.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://famousplayers.zictor.com/Exent/ExentCtl.ocx
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} - http://launch.gamespyarcade.com/software/launch/alaunch.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - E:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
------------------------------------------------------------------------
Thank you very much :smile: