dude234543
2007-10-24, 20:12
Ok, so spybot is picking up virtumonde.generic, and it won't go away. Here's a logfile, please help me with it! Thank you!
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:06, on 2007-10-24
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\70bee86dd2b52f0c3f60c71113182f25\update\update.exe
C:\WINDOWS\System32\taskmgr.exe
E:\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {182B90A3-F372-438A-800C-6814B4DE417B} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7C7DA6DD-F154-4F98-84E8-D0C32F9CE1D2} - (no file)
O2 - BHO: (no name) - {FB802D3B-319A-49E3-910C-4FED939E7E2F} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Antispy] C:\Program Files\Defender Pro\AntiSpy\Dpas.exe startup
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE Webbo Digital Camera
O4 - HKLM\..\Run: [jxnbaefd] RUNDLL32.EXE w01c37a1.dll,n 002baefb0000000a01c37a1
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA6116] command /c del "C:\WINDOWS\system32\wlhext.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5599] cmd /c del "C:\WINDOWS\system32\wlhext.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1340] command /c del "C:\WINDOWS\system32\whwfaxui.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC150] cmd /c del "C:\WINDOWS\system32\whwfaxui.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA254] command /c del "C:\WINDOWS\system32\wfnsrv.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC135] cmd /c del "C:\WINDOWS\system32\wfnsrv.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9236] command /c del "C:\WINDOWS\system32\wbhext.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9821] cmd /c del "C:\WINDOWS\system32\wbhext.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8373] command /c del "C:\WINDOWS\system32\tUpi32.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8974] cmd /c del "C:\WINDOWS\system32\tUpi32.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9599] command /c del "C:\WINDOWS\system32\STDisply.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9688] cmd /c del "C:\WINDOWS\system32\STDisply.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1445] command /c del "C:\WINDOWS\system32\sindcmsg.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8695] cmd /c del "C:\WINDOWS\system32\sindcmsg.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8646] command /c del "C:\WINDOWS\system32\sfredir.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8344] cmd /c del "C:\WINDOWS\system32\sfredir.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1509] command /c del "C:\WINDOWS\system32\sdi.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1889] cmd /c del "C:\WINDOWS\system32\sdi.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA877] command /c del "C:\WINDOWS\system32\rvchost.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5165] cmd /c del "C:\WINDOWS\system32\rvchost.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5162] command /c del "C:\WINDOWS\system32\pwwrprof.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9533] cmd /c del "C:\WINDOWS\system32\pwwrprof.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5663] command /c del "C:\WINDOWS\system32\pcapi.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7157] cmd /c del "C:\WINDOWS\system32\pcapi.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1954] command /c del "C:\WINDOWS\system32\p88q0il5e8q.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3728] cmd /c del "C:\WINDOWS\system32\p88q0il5e8q.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8069] command /c del "C:\WINDOWS\system32\oyengl.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2622] cmd /c del "C:\WINDOWS\system32\oyengl.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9454] command /c del "C:\WINDOWS\system32\mvn0l95m1.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3586] cmd /c del "C:\WINDOWS\system32\mvn0l95m1.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6830] command /c del "C:\WINDOWS\system32\muobjs.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9423] cmd /c del "C:\WINDOWS\system32\muobjs.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4514] command /c del "C:\WINDOWS\system32\mord2x40.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7257] cmd /c del "C:\WINDOWS\system32\mord2x40.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2685] command /c del "C:\WINDOWS\system32\MMHTML.DLL_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6376] cmd /c del "C:\WINDOWS\system32\MMHTML.DLL_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA81] command /c del "C:\WINDOWS\system32\mcvideo.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3483] cmd /c del "C:\WINDOWS\system32\mcvideo.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9272] command /c del "C:\WINDOWS\system32\mbmtapi.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4687] cmd /c del "C:\WINDOWS\system32\mbmtapi.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA325] command /c del "C:\WINDOWS\system32\LXCMP11n.DLL_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2777] cmd /c del "C:\WINDOWS\system32\LXCMP11n.DLL_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8399] command /c del "C:\WINDOWS\system32\lv4u09h9e.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9824] cmd /c del "C:\WINDOWS\system32\lv4u09h9e.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9916] command /c del "C:\WINDOWS\system32\LSCMP11n.DLL_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4463] cmd /c del "C:\WINDOWS\system32\LSCMP11n.DLL_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9395] command /c del "C:\WINDOWS\system32\lgtga11n.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3159] cmd /c del "C:\WINDOWS\system32\lgtga11n.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6434] command /c del "C:\WINDOWS\system32\kqymgr.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2067] cmd /c del "C:\WINDOWS\system32\kqymgr.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5858] command /c del "C:\WINDOWS\system32\kodmac.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC611] cmd /c del "C:\WINDOWS\system32\kodmac.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3130] command /c del "C:\WINDOWS\system32\kldda.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3811] cmd /c del "C:\WINDOWS\system32\kldda.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1928] command /c del "C:\WINDOWS\system32\kddir.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4682] cmd /c del "C:\WINDOWS\system32\kddir.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2894] command /c del "C:\WINDOWS\system32\eovfw.dll_old"
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [IpWins] C:\Program Files\Ipwindows\ipwins.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB6712] command /c del "C:\WINDOWS\system32\wlhext.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3947] cmd /c del "C:\WINDOWS\system32\wlhext.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2901] command /c del "C:\WINDOWS\system32\whwfaxui.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3552] cmd /c del "C:\WINDOWS\system32\whwfaxui.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6575] command /c del "C:\WINDOWS\system32\wfnsrv.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4534] cmd /c del "C:\WINDOWS\system32\wfnsrv.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4063] command /c del "C:\WINDOWS\system32\wbhext.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD974] cmd /c del "C:\WINDOWS\system32\wbhext.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1293] command /c del "C:\WINDOWS\system32\tUpi32.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3246] cmd /c del "C:\WINDOWS\system32\tUpi32.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7067] command /c del "C:\WINDOWS\system32\STDisply.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9187] cmd /c del "C:\WINDOWS\system32\STDisply.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9982] command /c del "C:\WINDOWS\system32\sindcmsg.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8878] cmd /c del "C:\WINDOWS\system32\sindcmsg.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7545] command /c del "C:\WINDOWS\system32\sfredir.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1411] cmd /c del "C:\WINDOWS\system32\sfredir.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4841] command /c del "C:\WINDOWS\system32\sdi.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2794] cmd /c del "C:\WINDOWS\system32\sdi.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2481] command /c del "C:\WINDOWS\system32\rvchost.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD35] cmd /c del "C:\WINDOWS\system32\rvchost.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4939] command /c del "C:\WINDOWS\system32\pwwrprof.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4268] cmd /c del "C:\WINDOWS\system32\pwwrprof.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB30] command /c del "C:\WINDOWS\system32\pcapi.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6971] cmd /c del "C:\WINDOWS\system32\pcapi.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9824] command /c del "C:\WINDOWS\system32\p88q0il5e8q.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7268] cmd /c del "C:\WINDOWS\system32\p88q0il5e8q.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3898] command /c del "C:\WINDOWS\system32\oyengl.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4544] cmd /c del "C:\WINDOWS\system32\oyengl.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2281] command /c del "C:\WINDOWS\system32\mvn0l95m1.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD902] cmd /c del "C:\WINDOWS\system32\mvn0l95m1.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8445] command /c del "C:\WINDOWS\system32\muobjs.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3153] cmd /c del "C:\WINDOWS\system32\muobjs.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7108] command /c del "C:\WINDOWS\system32\mord2x40.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3933] cmd /c del "C:\WINDOWS\system32\mord2x40.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4943] command /c del "C:\WINDOWS\system32\MMHTML.DLL_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6909] cmd /c del "C:\WINDOWS\system32\MMHTML.DLL_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5778] command /c del "C:\WINDOWS\system32\mcvideo.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2952] cmd /c del "C:\WINDOWS\system32\mcvideo.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3985] command /c del "C:\WINDOWS\system32\mbmtapi.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9391] cmd /c del "C:\WINDOWS\system32\mbmtapi.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB316] command /c del "C:\WINDOWS\system32\LXCMP11n.DLL_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7504] cmd /c del "C:\WINDOWS\system32\LXCMP11n.DLL_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7181] command /c del "C:\WINDOWS\system32\lv4u09h9e.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5131] cmd /c del "C:\WINDOWS\system32\lv4u09h9e.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8764] command /c del "C:\WINDOWS\system32\LSCMP11n.DLL_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8145] cmd /c del "C:\WINDOWS\system32\LSCMP11n.DLL_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7922] command /c del "C:\WINDOWS\system32\lgtga11n.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6505] cmd /c del "C:\WINDOWS\system32\lgtga11n.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1398] command /c del "C:\WINDOWS\system32\kqymgr.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1894] cmd /c del "C:\WINDOWS\system32\kqymgr.dll_old"
O4 - HKCU\..\Policies\Explorer\Run: [{0816A5B9-0682-1033-0223-041113020001}] "C:\Program Files\Common Files\{0816A5B9-0682-1033-0223-041113020001}\Update.exe" mc-110-12-0000137
O4 - HKCU\..\Policies\Explorer\Run: [{0816A5B9-0683-1033-0223-041113020001}] "C:\Program Files\Common Files\{0816A5B9-0683-1033-0223-041113020001}\Update.exe" mc-110-12-0000137
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [{0816A5B9-0683-1033-0223-041113020001}] "C:\Program Files\Common Files\{0816A5B9-0683-1033-0223-041113020001}\Update.exe" mc-110-12-0000137 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [{0816A5B9-0683-1033-0223-041113020001}] "C:\Program Files\Common Files\{0816A5B9-0683-1033-0223-041113020001}\Update.exe" mc-110-12-0000137 (User 'Default user')
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZUxdm082YYCA
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00000000-0000-0000-0000-000320050660} -
O16 - DPF: {00000000-0000-0000-0000-000330050660} -
O16 - DPF: {00000000-0709-0000-0000-000330050660} -
O16 - DPF: {00001000-0709-0000-0000-000330050660} -
O16 - DPF: {00330010-0000-0000-0000-000020060010} -
O16 - DPF: {00330010-0000-0000-0000-000020160010} -
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://www.drivecleaner.com/.freeware/installdrivecleanerstart.cab
O16 - DPF: {4AD73894-A895-4FC2-B233-299867E08753} -
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} -
O16 - DPF: {8C875948-9C60-4381-9248-0DF180542D53} -
O16 - DPF: {A1426AC5-8CE5-4A00-B71E-011D35709AC6} -
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
O20 - Winlogon Notify: khhhg - C:\WINDOWS\
O20 - Winlogon Notify: Setup - C:\WINDOWS\
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Client IP-IPX - Unknown owner - C:\WINDOWS\
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
--
End of file - 18012 bytes
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:06, on 2007-10-24
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\70bee86dd2b52f0c3f60c71113182f25\update\update.exe
C:\WINDOWS\System32\taskmgr.exe
E:\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {182B90A3-F372-438A-800C-6814B4DE417B} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7C7DA6DD-F154-4F98-84E8-D0C32F9CE1D2} - (no file)
O2 - BHO: (no name) - {FB802D3B-319A-49E3-910C-4FED939E7E2F} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Antispy] C:\Program Files\Defender Pro\AntiSpy\Dpas.exe startup
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE Webbo Digital Camera
O4 - HKLM\..\Run: [jxnbaefd] RUNDLL32.EXE w01c37a1.dll,n 002baefb0000000a01c37a1
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA6116] command /c del "C:\WINDOWS\system32\wlhext.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5599] cmd /c del "C:\WINDOWS\system32\wlhext.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1340] command /c del "C:\WINDOWS\system32\whwfaxui.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC150] cmd /c del "C:\WINDOWS\system32\whwfaxui.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA254] command /c del "C:\WINDOWS\system32\wfnsrv.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC135] cmd /c del "C:\WINDOWS\system32\wfnsrv.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9236] command /c del "C:\WINDOWS\system32\wbhext.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9821] cmd /c del "C:\WINDOWS\system32\wbhext.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8373] command /c del "C:\WINDOWS\system32\tUpi32.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8974] cmd /c del "C:\WINDOWS\system32\tUpi32.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9599] command /c del "C:\WINDOWS\system32\STDisply.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9688] cmd /c del "C:\WINDOWS\system32\STDisply.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1445] command /c del "C:\WINDOWS\system32\sindcmsg.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8695] cmd /c del "C:\WINDOWS\system32\sindcmsg.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8646] command /c del "C:\WINDOWS\system32\sfredir.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8344] cmd /c del "C:\WINDOWS\system32\sfredir.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1509] command /c del "C:\WINDOWS\system32\sdi.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1889] cmd /c del "C:\WINDOWS\system32\sdi.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA877] command /c del "C:\WINDOWS\system32\rvchost.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5165] cmd /c del "C:\WINDOWS\system32\rvchost.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5162] command /c del "C:\WINDOWS\system32\pwwrprof.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9533] cmd /c del "C:\WINDOWS\system32\pwwrprof.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5663] command /c del "C:\WINDOWS\system32\pcapi.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7157] cmd /c del "C:\WINDOWS\system32\pcapi.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1954] command /c del "C:\WINDOWS\system32\p88q0il5e8q.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3728] cmd /c del "C:\WINDOWS\system32\p88q0il5e8q.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8069] command /c del "C:\WINDOWS\system32\oyengl.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2622] cmd /c del "C:\WINDOWS\system32\oyengl.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9454] command /c del "C:\WINDOWS\system32\mvn0l95m1.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3586] cmd /c del "C:\WINDOWS\system32\mvn0l95m1.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6830] command /c del "C:\WINDOWS\system32\muobjs.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9423] cmd /c del "C:\WINDOWS\system32\muobjs.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4514] command /c del "C:\WINDOWS\system32\mord2x40.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7257] cmd /c del "C:\WINDOWS\system32\mord2x40.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2685] command /c del "C:\WINDOWS\system32\MMHTML.DLL_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6376] cmd /c del "C:\WINDOWS\system32\MMHTML.DLL_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA81] command /c del "C:\WINDOWS\system32\mcvideo.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3483] cmd /c del "C:\WINDOWS\system32\mcvideo.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9272] command /c del "C:\WINDOWS\system32\mbmtapi.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4687] cmd /c del "C:\WINDOWS\system32\mbmtapi.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA325] command /c del "C:\WINDOWS\system32\LXCMP11n.DLL_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2777] cmd /c del "C:\WINDOWS\system32\LXCMP11n.DLL_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8399] command /c del "C:\WINDOWS\system32\lv4u09h9e.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9824] cmd /c del "C:\WINDOWS\system32\lv4u09h9e.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9916] command /c del "C:\WINDOWS\system32\LSCMP11n.DLL_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4463] cmd /c del "C:\WINDOWS\system32\LSCMP11n.DLL_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9395] command /c del "C:\WINDOWS\system32\lgtga11n.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3159] cmd /c del "C:\WINDOWS\system32\lgtga11n.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6434] command /c del "C:\WINDOWS\system32\kqymgr.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2067] cmd /c del "C:\WINDOWS\system32\kqymgr.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5858] command /c del "C:\WINDOWS\system32\kodmac.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC611] cmd /c del "C:\WINDOWS\system32\kodmac.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3130] command /c del "C:\WINDOWS\system32\kldda.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3811] cmd /c del "C:\WINDOWS\system32\kldda.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1928] command /c del "C:\WINDOWS\system32\kddir.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4682] cmd /c del "C:\WINDOWS\system32\kddir.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2894] command /c del "C:\WINDOWS\system32\eovfw.dll_old"
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [IpWins] C:\Program Files\Ipwindows\ipwins.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB6712] command /c del "C:\WINDOWS\system32\wlhext.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3947] cmd /c del "C:\WINDOWS\system32\wlhext.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2901] command /c del "C:\WINDOWS\system32\whwfaxui.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3552] cmd /c del "C:\WINDOWS\system32\whwfaxui.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6575] command /c del "C:\WINDOWS\system32\wfnsrv.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4534] cmd /c del "C:\WINDOWS\system32\wfnsrv.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4063] command /c del "C:\WINDOWS\system32\wbhext.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD974] cmd /c del "C:\WINDOWS\system32\wbhext.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1293] command /c del "C:\WINDOWS\system32\tUpi32.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3246] cmd /c del "C:\WINDOWS\system32\tUpi32.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7067] command /c del "C:\WINDOWS\system32\STDisply.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9187] cmd /c del "C:\WINDOWS\system32\STDisply.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9982] command /c del "C:\WINDOWS\system32\sindcmsg.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8878] cmd /c del "C:\WINDOWS\system32\sindcmsg.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7545] command /c del "C:\WINDOWS\system32\sfredir.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1411] cmd /c del "C:\WINDOWS\system32\sfredir.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4841] command /c del "C:\WINDOWS\system32\sdi.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2794] cmd /c del "C:\WINDOWS\system32\sdi.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2481] command /c del "C:\WINDOWS\system32\rvchost.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD35] cmd /c del "C:\WINDOWS\system32\rvchost.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4939] command /c del "C:\WINDOWS\system32\pwwrprof.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4268] cmd /c del "C:\WINDOWS\system32\pwwrprof.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB30] command /c del "C:\WINDOWS\system32\pcapi.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6971] cmd /c del "C:\WINDOWS\system32\pcapi.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9824] command /c del "C:\WINDOWS\system32\p88q0il5e8q.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7268] cmd /c del "C:\WINDOWS\system32\p88q0il5e8q.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3898] command /c del "C:\WINDOWS\system32\oyengl.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4544] cmd /c del "C:\WINDOWS\system32\oyengl.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2281] command /c del "C:\WINDOWS\system32\mvn0l95m1.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD902] cmd /c del "C:\WINDOWS\system32\mvn0l95m1.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8445] command /c del "C:\WINDOWS\system32\muobjs.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3153] cmd /c del "C:\WINDOWS\system32\muobjs.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7108] command /c del "C:\WINDOWS\system32\mord2x40.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3933] cmd /c del "C:\WINDOWS\system32\mord2x40.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4943] command /c del "C:\WINDOWS\system32\MMHTML.DLL_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6909] cmd /c del "C:\WINDOWS\system32\MMHTML.DLL_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5778] command /c del "C:\WINDOWS\system32\mcvideo.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2952] cmd /c del "C:\WINDOWS\system32\mcvideo.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3985] command /c del "C:\WINDOWS\system32\mbmtapi.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9391] cmd /c del "C:\WINDOWS\system32\mbmtapi.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB316] command /c del "C:\WINDOWS\system32\LXCMP11n.DLL_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7504] cmd /c del "C:\WINDOWS\system32\LXCMP11n.DLL_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7181] command /c del "C:\WINDOWS\system32\lv4u09h9e.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5131] cmd /c del "C:\WINDOWS\system32\lv4u09h9e.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8764] command /c del "C:\WINDOWS\system32\LSCMP11n.DLL_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8145] cmd /c del "C:\WINDOWS\system32\LSCMP11n.DLL_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7922] command /c del "C:\WINDOWS\system32\lgtga11n.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6505] cmd /c del "C:\WINDOWS\system32\lgtga11n.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1398] command /c del "C:\WINDOWS\system32\kqymgr.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1894] cmd /c del "C:\WINDOWS\system32\kqymgr.dll_old"
O4 - HKCU\..\Policies\Explorer\Run: [{0816A5B9-0682-1033-0223-041113020001}] "C:\Program Files\Common Files\{0816A5B9-0682-1033-0223-041113020001}\Update.exe" mc-110-12-0000137
O4 - HKCU\..\Policies\Explorer\Run: [{0816A5B9-0683-1033-0223-041113020001}] "C:\Program Files\Common Files\{0816A5B9-0683-1033-0223-041113020001}\Update.exe" mc-110-12-0000137
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [{0816A5B9-0683-1033-0223-041113020001}] "C:\Program Files\Common Files\{0816A5B9-0683-1033-0223-041113020001}\Update.exe" mc-110-12-0000137 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [{0816A5B9-0683-1033-0223-041113020001}] "C:\Program Files\Common Files\{0816A5B9-0683-1033-0223-041113020001}\Update.exe" mc-110-12-0000137 (User 'Default user')
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZUxdm082YYCA
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00000000-0000-0000-0000-000320050660} -
O16 - DPF: {00000000-0000-0000-0000-000330050660} -
O16 - DPF: {00000000-0709-0000-0000-000330050660} -
O16 - DPF: {00001000-0709-0000-0000-000330050660} -
O16 - DPF: {00330010-0000-0000-0000-000020060010} -
O16 - DPF: {00330010-0000-0000-0000-000020160010} -
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://www.drivecleaner.com/.freeware/installdrivecleanerstart.cab
O16 - DPF: {4AD73894-A895-4FC2-B233-299867E08753} -
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} -
O16 - DPF: {8C875948-9C60-4381-9248-0DF180542D53} -
O16 - DPF: {A1426AC5-8CE5-4A00-B71E-011D35709AC6} -
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
O20 - Winlogon Notify: khhhg - C:\WINDOWS\
O20 - Winlogon Notify: Setup - C:\WINDOWS\
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Client IP-IPX - Unknown owner - C:\WINDOWS\
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
--
End of file - 18012 bytes