Joined
·
14 Posts
Need to get rid of "Live Safety Center" and "Online Security Guide"
My son uses his computer on the net a lot and of course there is a virus out there waiting to serve its twisted master.
He got the wellknown "Live Safety Center" and "Online Security Guide" and it keeps comming back and hijacks his internet browser to redirect to the same page that promises peace and wellbeing for money ... of course.
Here is the DDS log:
"
Deckard's System Scanner v20071014.68
Run by Emil on 2007-11-10 20:43:53
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- HijackThis (run as Emil.exe) ------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:44:39, on 10-11-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmer\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\agsdyely.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Programmer\Logitech\Video\LogiTray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe
C:\Programmer\iTunes\iTunesHelper.exe
C:\WINDOWS\Fonts\svchost.exe
C:\WINDOWS\mrofinu1188.exe
C:\WINDOWS\Fonts\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\MSN Messenger\MsnMsgr.Exe
C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programmer\Logitech\Video\FxSvr2.exe
C:\Programmer\iPod\bin\iPodService.exe
C:\Programmer\limewire\limewire.exe
C:\HBA\Virus\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Emil.exe
C:\WINDOWS\system32\mspaint.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.dk/0SEDADK/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Media Holding Enterprises, LLC - {0D39A900-0F3A-4C29-A254-3E65244FDC34} - C:\Programmer\ContextTool\ContextTool-2.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Programmer\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {64F7A424-5613-4885-A1B2-4A3CC56D5F08} - C:\WINDOWS\system32\mljge.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {86A2673A-1B5F-4E5A-B8D8-099D446F4616} - C:\Programmer\Windows NT\hosecuC:\WINDOWS\system32\e1\caws83122.exe.dll (file missing)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\zpsfvoli.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmer\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmer\Windows Live Toolbar\msntb.dll
O2 - BHO: {4569e5e9-4e67-bfe9-f914-4fd129c98feb} - {bef89c92-1df4-419f-9efb-76e49e5e9654} - C:\WINDOWS\system32\ntwsbkjy.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmer\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar2.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\zpsfvoli.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programmer\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Programmer\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmer\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Host Process] C:\WINDOWS\Fonts\svchost.exe
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu1188.exe 61A847B5BBF72813339330466188719AB689201522886B092CBD44BD8689220221DD325762EA4EBF968951185EFC412806867680AEDE604D64C2661373F819EBDCD66A47
O4 - HKLM\..\Run: [cc429608] rundll32.exe "C:\WINDOWS\system32\jmpenofk.dll",b
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] C:\Programmer\Logitech\Video\ManifestEngine.exe boot
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WinAble] C:\Programmer\WinAble\winable.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: IMVU.lnk = C:\Programmer\IMVU\IMVUClient.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Programmer\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Åbn på ny baggrundsfane - res://C:\Programmer\Windows Live Toolbar\Components\da-dk\msntabres.dll.mui/229?ad0ecc5bcbe84099a7ef653c4a4aa47a
O8 - Extra context menu item: Åbn på ny forgrundsfane - res://C:\Programmer\Windows Live Toolbar\Components\da-dk\msntabres.dll.mui/230?ad0ecc5bcbe84099a7ef653c4a4aa47a
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Programmer\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Emil\Menuen Start\Programmer\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programmer\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1169665996593
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\__c004A02A.dat
O20 - Winlogon Notify: zpsfvoli - C:\WINDOWS\SYSTEM32\zpsfvoli.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: DomainService - - C:\WINDOWS\system32\agsdyely.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
--
End of file - 9746 bytes
-- Files created between 2007-10-10 and 2007-11-10 -----------------------------
2007-11-10 19:44:43 0 d-------- C:\Programmer\Trend Micro
2007-11-10 19:05:35 0 d-------- C:\Programmer\SpywareBlaster
2007-11-10 17:33:11 41724 ---hs---- C:\Programmer\Fælles filer\Yazzle1560OinUninstaller.exe
2007-11-10 17:25:00 0 d-------- C:\Programmer\Insider
2007-11-10 17:24:58 0 d-------- C:\Programmer\InetGet2
2007-11-10 16:40:12 85056 --a------ C:\WINDOWS\system32\jmpenofk.dll
2007-11-10 16:37:12 81472 --a------ C:\WINDOWS\system32\ntwsbkjy.dll
2007-11-10 16:35:16 0 d-------- C:\Documents and Settings\Henrik\Application Data\LimeWire
2007-11-10 16:34:12 71232 --a------ C:\WINDOWS\system32\emkmtixx.exe <Not Verified; ; DDC>
2007-11-10 16:31:13 10816 --a------ C:\WINDOWS\system32\__c004A02A.dat
2007-11-10 16:31:12 10816 --a------ C:\WINDOWS\system32\pwyhayjy.dll
2007-11-10 16:30:08 36352 --a------ C:\WINDOWS\system32\rqrqppo.dll
2007-11-10 16:29:54 7713 --a------ C:\WINDOWS\system32\ldcore.dll
2007-11-10 16:28:48 10816 --a------ C:\WINDOWS\system32\mbhjrblp.dll
2007-11-09 16:20:37 0 d-------- C:\Documents and Settings\Miki\Application Data\LimeWire
2007-11-09 13:04:35 77888 --a------ C:\WINDOWS\system32\nckvbyeb.dll
2007-11-09 13:04:31 88128 --a------ C:\WINDOWS\system32\mjickogw.dll
2007-11-09 13:01:33 10816 --a------ C:\WINDOWS\system32\__c00F6D1B.dat
2007-11-09 13:01:32 10816 --a------ C:\WINDOWS\system32\tdxbarra.dll
2007-11-09 13:01:31 71232 --a------ C:\WINDOWS\system32\agsdyely.exe <Not Verified; ; DDC>
2007-11-09 13:00:51 134 --a------ C:\n.bat
2007-11-09 13:00:32 35328 --a------ C:\WINDOWS\system32\pmnnnop.dll
2007-11-09 13:00:31 0 --a------ C:\x.dat
2007-11-09 13:00:29 0 --a------ C:\Documents and Settings\Emil\x.dat
2007-11-09 13:00:16 0 --a------ C:\z.dat
2007-11-09 13:00:13 264 --a------ C:\Documents and Settings\Emil\z.dat
2007-11-09 13:00:09 172032 --a------ C:\winlogon.exe
2007-11-09 12:59:34 145984 --a------ C:\WINDOWS\system32\zpsfvoli.dll
2007-11-09 12:59:13 145984 --a------ C:\WINDOWS\system32\xuxpjeuh.dll
2007-11-09 12:59:11 101726 ---hs---- C:\WINDOWS\system32\egjlm.bak2
2007-11-08 16:51:38 6465 ---hs---- C:\WINDOWS\system32\egjlm.bak1
2007-11-08 16:51:00 316000 --a------ C:\WINDOWS\system32\mljge.dll
2007-11-08 16:49:29 147456 --a------ C:\WINDOWS\system32\vbzip10.dll <Not Verified; Info-ZIP; Info-ZIP's WiZ>
2007-11-08 16:49:09 0 d-------- C:\Programmer\WinAble
2007-11-08 16:49:08 0 d-------- C:\Programmer\Temporary
2007-11-08 16:46:01 35840 --a------ C:\WINDOWS\mrofinu1000106.exe
2007-11-08 16:46:00 35840 -ra------ C:\WINDOWS\mrofinu1188.exe
2007-11-08 16:45:57 35328 --a------ C:\WINDOWS\system32\gebcdbc.dll
2007-11-08 16:45:48 0 d-------- C:\WINDOWS\system32\u4
2007-11-08 16:45:48 0 d-------- C:\WINDOWS\system32\e1
2007-11-08 16:45:39 0 d-------- C:\WINDOWS\system32\b3
2007-11-08 16:45:37 0 d-------- C:\WINDOWS\system32\Mz18r
2007-11-08 16:45:35 111727 --a------ C:\a.exe
2007-11-08 16:29:59 0 dr-h----- C:\Documents and Settings\Emil\Application Data\SecuROM
2007-11-06 18:45:25 0 d-------- C:\Programmer\iPod
2007-11-01 12:24:00 229376 --a------ C:\WINDOWS\b128.exe
2007-10-30 19:53:32 97280 --a------ C:\WINDOWS\b147.exe
2007-10-29 21:21:52 145920 ---hs---- C:\Programmer\Fælles filer\Yazzle1560OinAdmin.exe
2007-10-29 17:12:21 0 d-------- C:\Documents and Settings\Iku\Application Data\Apple Computer
2007-10-27 21:14:36 0 d-------- C:\Documents and Settings\Henrik\cbt
2007-10-26 22:10:59 0 d-------- C:\Documents and Settings\Iku\Application Data\Google
2007-10-25 16:24:20 53760 --a------ C:\WINDOWS\b122.exe
-- Find3M Report ---------------------------------------------------------------
2007-11-10 20:01:00 0 d-------- C:\Documents and Settings\Emil\Application Data\LimeWire
2007-11-10 18:44:26 0 d-------- C:\Programmer\Windows Live Toolbar
2007-11-10 18:40:57 0 d-------- C:\Programmer\LimeWire
2007-11-10 18:40:43 0 d-------- C:\Programmer\iTunes
2007-11-10 18:40:15 0 d-------- C:\Programmer\Google
2007-11-10 18:37:26 0 d-------- C:\Programmer\ContextTool
2007-11-10 17:33:11 0 d-------- C:\Programmer\Fælles filer
2007-11-06 18:43:14 0 d-------- C:\Programmer\QuickTime
2007-10-31 16:52:14 0 d--h----- C:\Programmer\InstallShield Installation Information
2007-10-28 11:34:47 410000 --a------ C:\WINDOWS\system32\perfh006.dat
2007-10-28 11:34:47 69974 --a------ C:\WINDOWS\system32\perfc006.dat
2007-10-23 23:21:44 0 d-------- C:\Programmer\MSN Messenger
2007-10-12 18:28:35 0 d-------- C:\Programmer\Bethesda Softworks
2007-10-10 16:33:10 43520 --a------ C:\WINDOWS\system32\CmdLineExt03.dll
2007-10-03 19:34:44 0 d-------- C:\Programmer\Ground Control II
2007-10-03 15:50:50 0 d-------- C:\Programmer\Illusion Softworks
2007-09-18 18:10:57 0 d-------- C:\Programmer\Rockstar Games
2007-09-18 16:22:17 0 d-------- C:\Programmer\Apple Software Update
2007-09-18 15:38:54 0 d-------- C:\Programmer\Sierra
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0D39A900-0F3A-4C29-A254-3E65244FDC34}]
27-06-2007 21:27 1044480 --a------ C:\Programmer\ContextTool\ContextTool-2.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{64F7A424-5613-4885-A1B2-4A3CC56D5F08}]
08-11-2007 16:51 316000 --a------ C:\WINDOWS\system32\mljge.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{86A2673A-1B5F-4E5A-B8D8-099D446F4616}]
C:\Programmer\Windows NT\hosecuC:\WINDOWS\system32\e1\caws83122.exe.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
09-11-2007 12:59 145984 --a------ C:\WINDOWS\system32\zpsfvoli.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{bef89c92-1df4-419f-9efb-76e49e5e9654}]
10-11-2007 16:37 81472 --a------ C:\WINDOWS\system32\ntwsbkjy.dll
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\zpsfvoli.dll [09-11-2007 12:59 145984]
[-HKEY_CLASSES_ROOT\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [04-08-2004 06:31]
"PHIME2002ASync"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [04-08-2004 06:32]
"PHIME2002A"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [04-08-2004 06:32]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [22-10-2006 12:22]
"nwiz"="nwiz.exe" [22-10-2006 12:22 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [22-10-2006 12:22]
"SoundMan"="SOUNDMAN.EXE" [21-06-2006 05:42 C:\WINDOWS\soundman.exe]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [19-07-2005 17:32]
"LogitechVideoRepair"="C:\Programmer\Logitech\Video\ISStart.exe" [08-06-2005 15:24]
"LogitechVideoTray"="C:\Programmer\Logitech\Video\LogiTray.exe" [08-06-2005 15:14]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [27-07-2007 23:03]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe" [12-07-2007 03:00]
"Adobe Reader Speed Launcher"="C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe" [11-05-2007 02:06]
"QuickTime Task"="C:\Programmer\QuickTime\qttask.exe" [19-10-2007 20:16]
"iTunesHelper"="C:\Programmer\iTunes\iTunesHelper.exe" [02-11-2007 18:36]
"Host Process"="C:\WINDOWS\Fonts\svchost.exe" [01-10-2007 12:15]
"runner1"="C:\WINDOWS\mrofinu1188.exe" [08-11-2007 21:50]
"cc429608"="C:\WINDOWS\system32\jmpenofk.dll" [10-11-2007 16:40]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [27-08-2004 01:53]
"LogitechSoftwareUpdate"="C:\Programmer\Logitech\Video\ManifestEngine.exe" [08-06-2005 14:44]
"MsnMsgr"="C:\Programmer\MSN Messenger\MsnMsgr.exe" [19-01-2007 11:55]
"swg"="C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [13-08-2007 15:01]
"WinAble"="C:\Programmer\WinAble\winable.exe" []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\zpsfvoli]
zpsfvoli.dll 09-11-2007 12:59 145984 C:\WINDOWS\system32\zpsfvoli.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\WINDOWS\system32\__c004A02A.dat
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\mljge.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
-- End of Deckard's System Scanner: finished at 2007-11-10 20:45:17 ------------
"
If by any chance you should have a a neuclear bomb, a missile to carry it and the GPS-coordinates to that server that send out all this virus crap.....
My son uses his computer on the net a lot and of course there is a virus out there waiting to serve its twisted master.
He got the wellknown "Live Safety Center" and "Online Security Guide" and it keeps comming back and hijacks his internet browser to redirect to the same page that promises peace and wellbeing for money ... of course.
Here is the DDS log:
"
Deckard's System Scanner v20071014.68
Run by Emil on 2007-11-10 20:43:53
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- HijackThis (run as Emil.exe) ------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:44:39, on 10-11-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmer\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\agsdyely.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Programmer\Logitech\Video\LogiTray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe
C:\Programmer\iTunes\iTunesHelper.exe
C:\WINDOWS\Fonts\svchost.exe
C:\WINDOWS\mrofinu1188.exe
C:\WINDOWS\Fonts\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\MSN Messenger\MsnMsgr.Exe
C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programmer\Logitech\Video\FxSvr2.exe
C:\Programmer\iPod\bin\iPodService.exe
C:\Programmer\limewire\limewire.exe
C:\HBA\Virus\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Emil.exe
C:\WINDOWS\system32\mspaint.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.dk/0SEDADK/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Media Holding Enterprises, LLC - {0D39A900-0F3A-4C29-A254-3E65244FDC34} - C:\Programmer\ContextTool\ContextTool-2.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Programmer\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {64F7A424-5613-4885-A1B2-4A3CC56D5F08} - C:\WINDOWS\system32\mljge.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {86A2673A-1B5F-4E5A-B8D8-099D446F4616} - C:\Programmer\Windows NT\hosecuC:\WINDOWS\system32\e1\caws83122.exe.dll (file missing)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmer\Fælles filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\zpsfvoli.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmer\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmer\Windows Live Toolbar\msntb.dll
O2 - BHO: {4569e5e9-4e67-bfe9-f914-4fd129c98feb} - {bef89c92-1df4-419f-9efb-76e49e5e9654} - C:\WINDOWS\system32\ntwsbkjy.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmer\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmer\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmer\google\googletoolbar2.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\zpsfvoli.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programmer\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Programmer\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmer\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Host Process] C:\WINDOWS\Fonts\svchost.exe
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu1188.exe 61A847B5BBF72813339330466188719AB689201522886B092CBD44BD8689220221DD325762EA4EBF968951185EFC412806867680AEDE604D64C2661373F819EBDCD66A47
O4 - HKLM\..\Run: [cc429608] rundll32.exe "C:\WINDOWS\system32\jmpenofk.dll",b
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] C:\Programmer\Logitech\Video\ManifestEngine.exe boot
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WinAble] C:\Programmer\WinAble\winable.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: IMVU.lnk = C:\Programmer\IMVU\IMVUClient.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Programmer\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Åbn på ny baggrundsfane - res://C:\Programmer\Windows Live Toolbar\Components\da-dk\msntabres.dll.mui/229?ad0ecc5bcbe84099a7ef653c4a4aa47a
O8 - Extra context menu item: Åbn på ny forgrundsfane - res://C:\Programmer\Windows Live Toolbar\Components\da-dk\msntabres.dll.mui/230?ad0ecc5bcbe84099a7ef653c4a4aa47a
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Programmer\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Emil\Menuen Start\Programmer\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programmer\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1169665996593
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\__c004A02A.dat
O20 - Winlogon Notify: zpsfvoli - C:\WINDOWS\SYSTEM32\zpsfvoli.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Programmer\Fælles filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programmer\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Programmer\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: DomainService - - C:\WINDOWS\system32\agsdyely.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Programmer\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
--
End of file - 9746 bytes
-- Files created between 2007-10-10 and 2007-11-10 -----------------------------
2007-11-10 19:44:43 0 d-------- C:\Programmer\Trend Micro
2007-11-10 19:05:35 0 d-------- C:\Programmer\SpywareBlaster
2007-11-10 17:33:11 41724 ---hs---- C:\Programmer\Fælles filer\Yazzle1560OinUninstaller.exe
2007-11-10 17:25:00 0 d-------- C:\Programmer\Insider
2007-11-10 17:24:58 0 d-------- C:\Programmer\InetGet2
2007-11-10 16:40:12 85056 --a------ C:\WINDOWS\system32\jmpenofk.dll
2007-11-10 16:37:12 81472 --a------ C:\WINDOWS\system32\ntwsbkjy.dll
2007-11-10 16:35:16 0 d-------- C:\Documents and Settings\Henrik\Application Data\LimeWire
2007-11-10 16:34:12 71232 --a------ C:\WINDOWS\system32\emkmtixx.exe <Not Verified; ; DDC>
2007-11-10 16:31:13 10816 --a------ C:\WINDOWS\system32\__c004A02A.dat
2007-11-10 16:31:12 10816 --a------ C:\WINDOWS\system32\pwyhayjy.dll
2007-11-10 16:30:08 36352 --a------ C:\WINDOWS\system32\rqrqppo.dll
2007-11-10 16:29:54 7713 --a------ C:\WINDOWS\system32\ldcore.dll
2007-11-10 16:28:48 10816 --a------ C:\WINDOWS\system32\mbhjrblp.dll
2007-11-09 16:20:37 0 d-------- C:\Documents and Settings\Miki\Application Data\LimeWire
2007-11-09 13:04:35 77888 --a------ C:\WINDOWS\system32\nckvbyeb.dll
2007-11-09 13:04:31 88128 --a------ C:\WINDOWS\system32\mjickogw.dll
2007-11-09 13:01:33 10816 --a------ C:\WINDOWS\system32\__c00F6D1B.dat
2007-11-09 13:01:32 10816 --a------ C:\WINDOWS\system32\tdxbarra.dll
2007-11-09 13:01:31 71232 --a------ C:\WINDOWS\system32\agsdyely.exe <Not Verified; ; DDC>
2007-11-09 13:00:51 134 --a------ C:\n.bat
2007-11-09 13:00:32 35328 --a------ C:\WINDOWS\system32\pmnnnop.dll
2007-11-09 13:00:31 0 --a------ C:\x.dat
2007-11-09 13:00:29 0 --a------ C:\Documents and Settings\Emil\x.dat
2007-11-09 13:00:16 0 --a------ C:\z.dat
2007-11-09 13:00:13 264 --a------ C:\Documents and Settings\Emil\z.dat
2007-11-09 13:00:09 172032 --a------ C:\winlogon.exe
2007-11-09 12:59:34 145984 --a------ C:\WINDOWS\system32\zpsfvoli.dll
2007-11-09 12:59:13 145984 --a------ C:\WINDOWS\system32\xuxpjeuh.dll
2007-11-09 12:59:11 101726 ---hs---- C:\WINDOWS\system32\egjlm.bak2
2007-11-08 16:51:38 6465 ---hs---- C:\WINDOWS\system32\egjlm.bak1
2007-11-08 16:51:00 316000 --a------ C:\WINDOWS\system32\mljge.dll
2007-11-08 16:49:29 147456 --a------ C:\WINDOWS\system32\vbzip10.dll <Not Verified; Info-ZIP; Info-ZIP's WiZ>
2007-11-08 16:49:09 0 d-------- C:\Programmer\WinAble
2007-11-08 16:49:08 0 d-------- C:\Programmer\Temporary
2007-11-08 16:46:01 35840 --a------ C:\WINDOWS\mrofinu1000106.exe
2007-11-08 16:46:00 35840 -ra------ C:\WINDOWS\mrofinu1188.exe
2007-11-08 16:45:57 35328 --a------ C:\WINDOWS\system32\gebcdbc.dll
2007-11-08 16:45:48 0 d-------- C:\WINDOWS\system32\u4
2007-11-08 16:45:48 0 d-------- C:\WINDOWS\system32\e1
2007-11-08 16:45:39 0 d-------- C:\WINDOWS\system32\b3
2007-11-08 16:45:37 0 d-------- C:\WINDOWS\system32\Mz18r
2007-11-08 16:45:35 111727 --a------ C:\a.exe
2007-11-08 16:29:59 0 dr-h----- C:\Documents and Settings\Emil\Application Data\SecuROM
2007-11-06 18:45:25 0 d-------- C:\Programmer\iPod
2007-11-01 12:24:00 229376 --a------ C:\WINDOWS\b128.exe
2007-10-30 19:53:32 97280 --a------ C:\WINDOWS\b147.exe
2007-10-29 21:21:52 145920 ---hs---- C:\Programmer\Fælles filer\Yazzle1560OinAdmin.exe
2007-10-29 17:12:21 0 d-------- C:\Documents and Settings\Iku\Application Data\Apple Computer
2007-10-27 21:14:36 0 d-------- C:\Documents and Settings\Henrik\cbt
2007-10-26 22:10:59 0 d-------- C:\Documents and Settings\Iku\Application Data\Google
2007-10-25 16:24:20 53760 --a------ C:\WINDOWS\b122.exe
-- Find3M Report ---------------------------------------------------------------
2007-11-10 20:01:00 0 d-------- C:\Documents and Settings\Emil\Application Data\LimeWire
2007-11-10 18:44:26 0 d-------- C:\Programmer\Windows Live Toolbar
2007-11-10 18:40:57 0 d-------- C:\Programmer\LimeWire
2007-11-10 18:40:43 0 d-------- C:\Programmer\iTunes
2007-11-10 18:40:15 0 d-------- C:\Programmer\Google
2007-11-10 18:37:26 0 d-------- C:\Programmer\ContextTool
2007-11-10 17:33:11 0 d-------- C:\Programmer\Fælles filer
2007-11-06 18:43:14 0 d-------- C:\Programmer\QuickTime
2007-10-31 16:52:14 0 d--h----- C:\Programmer\InstallShield Installation Information
2007-10-28 11:34:47 410000 --a------ C:\WINDOWS\system32\perfh006.dat
2007-10-28 11:34:47 69974 --a------ C:\WINDOWS\system32\perfc006.dat
2007-10-23 23:21:44 0 d-------- C:\Programmer\MSN Messenger
2007-10-12 18:28:35 0 d-------- C:\Programmer\Bethesda Softworks
2007-10-10 16:33:10 43520 --a------ C:\WINDOWS\system32\CmdLineExt03.dll
2007-10-03 19:34:44 0 d-------- C:\Programmer\Ground Control II
2007-10-03 15:50:50 0 d-------- C:\Programmer\Illusion Softworks
2007-09-18 18:10:57 0 d-------- C:\Programmer\Rockstar Games
2007-09-18 16:22:17 0 d-------- C:\Programmer\Apple Software Update
2007-09-18 15:38:54 0 d-------- C:\Programmer\Sierra
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0D39A900-0F3A-4C29-A254-3E65244FDC34}]
27-06-2007 21:27 1044480 --a------ C:\Programmer\ContextTool\ContextTool-2.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{64F7A424-5613-4885-A1B2-4A3CC56D5F08}]
08-11-2007 16:51 316000 --a------ C:\WINDOWS\system32\mljge.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{86A2673A-1B5F-4E5A-B8D8-099D446F4616}]
C:\Programmer\Windows NT\hosecuC:\WINDOWS\system32\e1\caws83122.exe.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
09-11-2007 12:59 145984 --a------ C:\WINDOWS\system32\zpsfvoli.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{bef89c92-1df4-419f-9efb-76e49e5e9654}]
10-11-2007 16:37 81472 --a------ C:\WINDOWS\system32\ntwsbkjy.dll
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\zpsfvoli.dll [09-11-2007 12:59 145984]
[-HKEY_CLASSES_ROOT\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [04-08-2004 06:31]
"PHIME2002ASync"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [04-08-2004 06:32]
"PHIME2002A"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [04-08-2004 06:32]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [22-10-2006 12:22]
"nwiz"="nwiz.exe" [22-10-2006 12:22 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [22-10-2006 12:22]
"SoundMan"="SOUNDMAN.EXE" [21-06-2006 05:42 C:\WINDOWS\soundman.exe]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [19-07-2005 17:32]
"LogitechVideoRepair"="C:\Programmer\Logitech\Video\ISStart.exe" [08-06-2005 15:24]
"LogitechVideoTray"="C:\Programmer\Logitech\Video\LogiTray.exe" [08-06-2005 15:14]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [27-07-2007 23:03]
"SunJavaUpdateSched"="C:\Programmer\Java\jre1.6.0_02\bin\jusched.exe" [12-07-2007 03:00]
"Adobe Reader Speed Launcher"="C:\Programmer\Adobe\Reader 8.0\Reader\Reader_sl.exe" [11-05-2007 02:06]
"QuickTime Task"="C:\Programmer\QuickTime\qttask.exe" [19-10-2007 20:16]
"iTunesHelper"="C:\Programmer\iTunes\iTunesHelper.exe" [02-11-2007 18:36]
"Host Process"="C:\WINDOWS\Fonts\svchost.exe" [01-10-2007 12:15]
"runner1"="C:\WINDOWS\mrofinu1188.exe" [08-11-2007 21:50]
"cc429608"="C:\WINDOWS\system32\jmpenofk.dll" [10-11-2007 16:40]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [27-08-2004 01:53]
"LogitechSoftwareUpdate"="C:\Programmer\Logitech\Video\ManifestEngine.exe" [08-06-2005 14:44]
"MsnMsgr"="C:\Programmer\MSN Messenger\MsnMsgr.exe" [19-01-2007 11:55]
"swg"="C:\Programmer\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [13-08-2007 15:01]
"WinAble"="C:\Programmer\WinAble\winable.exe" []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\zpsfvoli]
zpsfvoli.dll 09-11-2007 12:59 145984 C:\WINDOWS\system32\zpsfvoli.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\WINDOWS\system32\__c004A02A.dat
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\mljge.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
-- End of Deckard's System Scanner: finished at 2007-11-10 20:45:17 ------------
"
If by any chance you should have a a neuclear bomb, a missile to carry it and the GPS-coordinates to that server that send out all this virus crap.....
Attachments
-
4.8 KB Views: 147