PeterVerelst
2007-11-02, 15:40
The computer they gave me at work was full of spyware, so I tried to clean it up a bit. Spybot and AdAware help a lot but I can't get rid of a small banner on top of the screen when I visit www.google.com (or my local www.google.be version).
It says "Google Money: Do you need money? Fill this form!" and links to a site called "http://goatszeqheep.com", don't know what it is but a little googling told me it's fishy.
Doing the necessary test to post here, I realized there is probably a lot more wrong then I thought.
The Kaspersky log:
Scan Statistics:
Total number of scanned objects: 80378
Number of viruses found: 7
Number of infected objects: 28
Number of suspicious objects: 0
Duration of the scan process: 01:01:23
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-01252007-221112.log Object is locked skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\ATAPI.EXE.bac_a03152 Infected: Virus.Win32.Sality.s skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\ExtZip.Exe.bac_a03152 Infected: Virus.Win32.Sality.s skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\ibm00002.dll.bac_a03152 Infected: Trojan-PSW.Win32.Sinowal.cl skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\iljlon.sys.bac_a03060 Infected: Virus.Win32.Sality.s skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\PXHPINST.EXE.bac_a03152 Infected: Virus.Win32.Sality.s skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\wmdrtc32.dll.bac_a03152 Infected: Email-Worm.Win32.Warezov.et skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\wmdrtc32.dl_.bac_a03060/ Infected: Email-Worm.Win32.Warezov.et skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\wmdrtc32.dl_.bac_a03060 MS Expand: infected - 1 skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\wmdrtc32.dl_.bac_a03060 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\wmdrtc32.dl_.bac_a03152/ Infected: Email-Worm.Win32.Warezov.et skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\wmdrtc32.dl_.bac_a03152 MS Expand: infected - 1 skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\wmdrtc32.dl_.bac_a03152 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\z1376.exe.bac_a03152 Infected: not-virus:Hoax.Win32.Renos.fk skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\z194.exe.bac_a03152 Infected: not-virus:Hoax.Win32.Renos.fk skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\z2783.exe.bac_a03060 Infected: Trojan.Win32.Agent.aws skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\z2783.exe.bac_a03152 Infected: Virus.Win32.Sality.s skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\z329.dll.bac_a03152 Infected: not-virus:Hoax.Win32.Renos.fk skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\z3547.dll.bac_a03152 Infected: not-virus:Hoax.Win32.Renos.fk skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\z3569.dll.bac_a03152 Infected: not-virus:Hoax.Win32.Renos.fk skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\z357.dll.bac_a03152 Infected: not-virus:Hoax.Win32.Renos.fk skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\z3599.dll.bac_a03152 Infected: not-virus:Hoax.Win32.Renos.fk skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\z3723.dll.bac_a03152 Infected: not-virus:Hoax.Win32.Renos.fk skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\z3815.dll.bac_a03152 Infected: not-virus:Hoax.Win32.Renos.fk skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\z3866.dll.bac_a03152 Infected: not-virus:Hoax.Win32.Renos.fk skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\z3925.dll.bac_a03152 Infected: not-virus:Hoax.Win32.Renos.fk skipped
C:\Documents and Settings\dirk\Application Data\Microsoft\Outlook\outitems.log Object is locked skipped
C:\Documents and Settings\dirk\Application Data\Microsoft\Outlook\Outlook.NK2 Object is locked skipped
C:\Documents and Settings\dirk\Application Data\Microsoft\Outlook\Outlook.srs Object is locked skipped
C:\Documents and Settings\dirk\Application Data\Microsoft\Sjablonen\Normal.dot Object is locked skipped
C:\Documents and Settings\dirk\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Application Data\Microsoft\Outlook\archive.pst Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{28DAADC0-DB10-4B24-9451-1341B668470F} Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Geschiedenis\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Temp\ClamWin1.log Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Temp\FMTEMPFM472aec020c1e.tmp Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Temp\FMTEMPFM472aec145076.tmp Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Temp\FMTEMPFM472aefc02278.tmp Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Temp\~DF1380.tmp Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Temp\~DF2CC.tmp Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Temp\~DF3E1B.tmp Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Temp\~DF41B3.tmp Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Temp\~DF5D89.tmp Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Temp\~DF789B.tmp Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Temp\~DF78A6.tmp Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Temp\~DFB305.tmp Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Temporary Internet Files\Content.Word\~WRS0000.tmp Object is locked skipped
C:\Documents and Settings\dirk\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\dirk\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Geschiedenis\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Microsoft Office\OFFICE11\Biblio\EUROTOOL.XLA Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{20FACB27-B213-45DF-B711-A07B77057628}\RP637\A0117520.dll Infected: Trojan-Proxy.Win32.Dlena.ch skipped
C:\System Volume Information\_restore{20FACB27-B213-45DF-B711-A07B77057628}\RP638\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\ie7\iexplore.exe Infected: Trojan.Win32.Patched.j skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\1396092ld.exe Infected: Trojan-Proxy.Win32.Dlena.ch skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\cqhtset.dll Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\{32345679-1234-1234-1122-334455667788} Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_568.dat Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Then I tried running Spybot S&D in safemode, but this doens't seem to be possible. Starting up in safe mode always leads to a bluescreencrash immediatly after choosing safe mode.
Running it in normal mode gives a clean sheet.
HijackThis Logfile
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 14:36:32, on 2/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\ClamWin\bin\ClamTray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\FileMaker\FileMaker Pro 7\FileMaker Pro.exe
C:\Documents and Settings\dirk\Bureaublad\HiJackThis_v2.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http://pac.pandora.be:8080
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [7v3j] C:\WINDOWS\system32\z1376.exe gdtgh
O4 - HKLM\..\Run: [WINDOWS] C:\egnt.exe
O4 - HKLM\..\Run: [SvcManager] kernelex1.exe
O4 - HKLM\..\Run: [ClamWin] "C:\Program Files\ClamWin\bin\ClamTray.exe" --logon
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_0
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://eu-housecall.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {5DDCC37F-7C6B-48B8-9664-97C537920CA0} (aecviz Class) - http://lsmlssge24.leroysomer.com/ACE/config_sp/ACE/Resources/npaecviz.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1169923146406
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1180026888421
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O21 - SSODL: wHYRlEPYQrigmO - {74F66A67-DE5C-C0CD-9652-167E84113805} - C:\WINDOWS\system32\vijao.dll (file missing)
O22 - SharedTaskScheduler: Preloader van browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Cache-daemon voor onderdeelcategorieën - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: OpenGL additional - {8A5849C4-93F3-429D-FF34-660A2068897C} - (no file)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Microsoft ASPI Manager (aspi113210) - Unknown owner - C:\WINDOWS\system32\aspi1492112.exe (file missing)
O23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Microsoft authenticate service (MsaSvc) - Unknown owner - C:\WINDOWS\system32\msasvc.exe (file missing)
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
--
End of file - 7878 bytes
Anyone who can help me with deleting "Google Money" (and other malicious things that I'm not aware of).
It says "Google Money: Do you need money? Fill this form!" and links to a site called "http://goatszeqheep.com", don't know what it is but a little googling told me it's fishy.
Doing the necessary test to post here, I realized there is probably a lot more wrong then I thought.
The Kaspersky log:
Scan Statistics:
Total number of scanned objects: 80378
Number of viruses found: 7
Number of infected objects: 28
Number of suspicious objects: 0
Duration of the scan process: 01:01:23
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-01252007-221112.log Object is locked skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\ATAPI.EXE.bac_a03152 Infected: Virus.Win32.Sality.s skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\ExtZip.Exe.bac_a03152 Infected: Virus.Win32.Sality.s skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\ibm00002.dll.bac_a03152 Infected: Trojan-PSW.Win32.Sinowal.cl skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\iljlon.sys.bac_a03060 Infected: Virus.Win32.Sality.s skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\PXHPINST.EXE.bac_a03152 Infected: Virus.Win32.Sality.s skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\wmdrtc32.dll.bac_a03152 Infected: Email-Worm.Win32.Warezov.et skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\wmdrtc32.dl_.bac_a03060/ Infected: Email-Worm.Win32.Warezov.et skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\wmdrtc32.dl_.bac_a03060 MS Expand: infected - 1 skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\wmdrtc32.dl_.bac_a03060 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\wmdrtc32.dl_.bac_a03152/ Infected: Email-Worm.Win32.Warezov.et skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\wmdrtc32.dl_.bac_a03152 MS Expand: infected - 1 skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\wmdrtc32.dl_.bac_a03152 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\z1376.exe.bac_a03152 Infected: not-virus:Hoax.Win32.Renos.fk skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\z194.exe.bac_a03152 Infected: not-virus:Hoax.Win32.Renos.fk skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\z2783.exe.bac_a03060 Infected: Trojan.Win32.Agent.aws skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\z2783.exe.bac_a03152 Infected: Virus.Win32.Sality.s skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\z329.dll.bac_a03152 Infected: not-virus:Hoax.Win32.Renos.fk skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\z3547.dll.bac_a03152 Infected: not-virus:Hoax.Win32.Renos.fk skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\z3569.dll.bac_a03152 Infected: not-virus:Hoax.Win32.Renos.fk skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\z357.dll.bac_a03152 Infected: not-virus:Hoax.Win32.Renos.fk skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\z3599.dll.bac_a03152 Infected: not-virus:Hoax.Win32.Renos.fk skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\z3723.dll.bac_a03152 Infected: not-virus:Hoax.Win32.Renos.fk skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\z3815.dll.bac_a03152 Infected: not-virus:Hoax.Win32.Renos.fk skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\z3866.dll.bac_a03152 Infected: not-virus:Hoax.Win32.Renos.fk skipped
C:\Documents and Settings\dirk\.housecall6.6\Quarantine\z3925.dll.bac_a03152 Infected: not-virus:Hoax.Win32.Renos.fk skipped
C:\Documents and Settings\dirk\Application Data\Microsoft\Outlook\outitems.log Object is locked skipped
C:\Documents and Settings\dirk\Application Data\Microsoft\Outlook\Outlook.NK2 Object is locked skipped
C:\Documents and Settings\dirk\Application Data\Microsoft\Outlook\Outlook.srs Object is locked skipped
C:\Documents and Settings\dirk\Application Data\Microsoft\Sjablonen\Normal.dot Object is locked skipped
C:\Documents and Settings\dirk\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Application Data\Microsoft\Outlook\archive.pst Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{28DAADC0-DB10-4B24-9451-1341B668470F} Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Geschiedenis\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Temp\ClamWin1.log Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Temp\FMTEMPFM472aec020c1e.tmp Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Temp\FMTEMPFM472aec145076.tmp Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Temp\FMTEMPFM472aefc02278.tmp Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Temp\~DF1380.tmp Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Temp\~DF2CC.tmp Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Temp\~DF3E1B.tmp Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Temp\~DF41B3.tmp Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Temp\~DF5D89.tmp Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Temp\~DF789B.tmp Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Temp\~DF78A6.tmp Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Temp\~DFB305.tmp Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\dirk\Local Settings\Temporary Internet Files\Content.Word\~WRS0000.tmp Object is locked skipped
C:\Documents and Settings\dirk\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\dirk\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Geschiedenis\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Microsoft Office\OFFICE11\Biblio\EUROTOOL.XLA Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{20FACB27-B213-45DF-B711-A07B77057628}\RP637\A0117520.dll Infected: Trojan-Proxy.Win32.Dlena.ch skipped
C:\System Volume Information\_restore{20FACB27-B213-45DF-B711-A07B77057628}\RP638\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\ie7\iexplore.exe Infected: Trojan.Win32.Patched.j skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\1396092ld.exe Infected: Trojan-Proxy.Win32.Dlena.ch skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\cqhtset.dll Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\{32345679-1234-1234-1122-334455667788} Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_568.dat Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Then I tried running Spybot S&D in safemode, but this doens't seem to be possible. Starting up in safe mode always leads to a bluescreencrash immediatly after choosing safe mode.
Running it in normal mode gives a clean sheet.
HijackThis Logfile
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 14:36:32, on 2/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\ClamWin\bin\ClamTray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\FileMaker\FileMaker Pro 7\FileMaker Pro.exe
C:\Documents and Settings\dirk\Bureaublad\HiJackThis_v2.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http://pac.pandora.be:8080
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [7v3j] C:\WINDOWS\system32\z1376.exe gdtgh
O4 - HKLM\..\Run: [WINDOWS] C:\egnt.exe
O4 - HKLM\..\Run: [SvcManager] kernelex1.exe
O4 - HKLM\..\Run: [ClamWin] "C:\Program Files\ClamWin\bin\ClamTray.exe" --logon
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_0
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://eu-housecall.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {5DDCC37F-7C6B-48B8-9664-97C537920CA0} (aecviz Class) - http://lsmlssge24.leroysomer.com/ACE/config_sp/ACE/Resources/npaecviz.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1169923146406
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1180026888421
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O21 - SSODL: wHYRlEPYQrigmO - {74F66A67-DE5C-C0CD-9652-167E84113805} - C:\WINDOWS\system32\vijao.dll (file missing)
O22 - SharedTaskScheduler: Preloader van browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Cache-daemon voor onderdeelcategorieën - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: OpenGL additional - {8A5849C4-93F3-429D-FF34-660A2068897C} - (no file)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Microsoft ASPI Manager (aspi113210) - Unknown owner - C:\WINDOWS\system32\aspi1492112.exe (file missing)
O23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Microsoft authenticate service (MsaSvc) - Unknown owner - C:\WINDOWS\system32\msasvc.exe (file missing)
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
--
End of file - 7878 bytes
Anyone who can help me with deleting "Google Money" (and other malicious things that I'm not aware of).