georgevk
2008-04-29, 16:35
Hello everyone,
God bless each of you for volunteering your expertise and time to help those of us in trouble. I need your help, please. I have been working on this for the past 4 days or so, I read your Stickys, and I have done the following:
1) Ran Spybot S&D SEVERAL times until finally there were no more red items (I had to do it in regular mode, and each scan took forever, since I can't boot into safe mode for some reason).
2) I ran Kaspersky, which appears below,
3) I ran HijackThis, which also appears below.
Any help you can give would be greatly appreciated, believe me!
Thank you in advance.
***********************************
KASPERSKY ONLINE SCANNER REPORT
Tuesday, April 29, 2008 6:22:27 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 29/04/2008
Kaspersky Anti-Virus database records: 729986
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
C:\
E:\
F:\
Scan Statistics
Total number of scanned objects 72064
Number of viruses found 8
Number of infected objects 33
Number of suspicious objects 0
Duration of the scan process 04:54:10
Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\McConfig.dat Object is locked skipped
C:\Program Files\INITIO\Button Manager v1.874\inihid.exe Infected: not-a-virus:AdWare.Win32.Look2Me.e skipped
C:\Program Files\RealVNC\VNC4\vncconfig.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\Program Files\RealVNC\VNC4\vncviewer.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\Program Files\RealVNC\VNC4\winvnc4.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\Program Files\RealVNC\VNC4\wm_hooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
F:\Documents and Settings\All Users\Application Data\McAfee\MNA\NAData Object is locked skipped
F:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\Events.dat Object is locked skipped
F:\Documents and Settings\All Users\Application Data\McAfee\MSC\McUsers.dat Object is locked skipped
F:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Data\TFR8.tmp Object is locked skipped
F:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Logs\OAS.Log Object is locked skipped
F:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
F:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
F:\Documents and Settings\All Users\Application Data\QSLLPSVCShare Object is locked skipped
F:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
F:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
F:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
F:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
F:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
F:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
F:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
F:\Documents and Settings\Owner\Cookies\index.dat Object is locked skipped
F:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
F:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
F:\Documents and Settings\Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped
F:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
F:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
F:\Documents and Settings\Owner\NTUSER.DAT Object is locked skipped
F:\Documents and Settings\Owner\ntuser.dat.LOG Object is locked skipped
F:\Documents and Settings\TEMP\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
F:\Documents and Settings\TEMP\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
F:\Documents and Settings\TEMP\NTUSER.DAT Object is locked skipped
F:\Documents and Settings\TEMP\ntuser.dat.LOG Object is locked skipped
F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP332\A0098143.exe Object is locked skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP333\A0100246.dll Infected: Packed.Win32.Monder.gen skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP333\A0101273.dll Infected: Packed.Win32.Monder.gen skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP334\A0102670.exe Infected: not-a-virus:AdWare.Win32.Vapsup.rr skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP334\A0102671.dll Infected: Packed.Win32.Monder.gen skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP334\A0102672.dll Infected: Packed.Win32.Monder.gen skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP334\A0102673.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qrh skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP334\A0102674.dll Infected: Packed.Win32.Monder.gen skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP334\A0102675.dll Infected: Packed.Win32.Monder.gen skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP334\A0102676.dll Infected: Packed.Win32.Monder.gen skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP334\A0102677.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qrg skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP334\A0105875.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qre skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP334\A0109069.dll Infected: Packed.Win32.Monder.gen skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP335\A0110098.dll Infected: Packed.Win32.Monder.gen skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP335\A0110100.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qre skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP335\A0110101.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qre skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP335\A0110102.dll Infected: Packed.Win32.Monder.gen skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP335\A0110103.dll Infected: Packed.Win32.Monder.gen skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP335\A0110104.dll Infected: Packed.Win32.Monder.gen skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP335\A0110105.dll Infected: Packed.Win32.Monder.gen skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP335\A0110106.dll Infected: Packed.Win32.Monder.gen skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP335\A0110107.dll Infected: Packed.Win32.Monder.gen skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP335\A0110108.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qre skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP335\A0110109.dll Infected: Packed.Win32.Monder.gen skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP335\A0110110.dll Infected: Packed.Win32.Monder.gen skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP335\A0110111.dll Infected: Packed.Win32.Monder.gen skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP335\A0110112.dll Infected: Packed.Win32.Monder.gen skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP335\A0110113.dll Infected: Packed.Win32.Monder.gen skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP335\A0113126.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qni skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP336\change.log Object is locked skipped
F:\WINDOWS\CSC\00000001 Object is locked skipped
F:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
F:\WINDOWS\SchedLgU.Txt Object is locked skipped
F:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
F:\WINDOWS\Sti_Trace.log Object is locked skipped
F:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
F:\WINDOWS\system32\config\default Object is locked skipped
F:\WINDOWS\system32\config\default.LOG Object is locked skipped
F:\WINDOWS\system32\config\Internet.evt Object is locked skipped
F:\WINDOWS\system32\config\SAM Object is locked skipped
F:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
F:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
F:\WINDOWS\system32\config\SECURITY Object is locked skipped
F:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
F:\WINDOWS\system32\config\software Object is locked skipped
F:\WINDOWS\system32\config\software.LOG Object is locked skipped
F:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
F:\WINDOWS\system32\config\system Object is locked skipped
F:\WINDOWS\system32\config\system.LOG Object is locked skipped
F:\WINDOWS\system32\h323log.txt Object is locked skipped
F:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
F:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
F:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
F:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
F:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
F:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
F:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
F:\WINDOWS\Temp\mcmsc_5dAfemtzLGP9oaS Object is locked skipped
F:\WINDOWS\Temp\mcmsc_zBPglMQrrPcoPx0 Object is locked skipped
F:\WINDOWS\wiadebug.log Object is locked skipped
F:\WINDOWS\wiaservc.log Object is locked skipped
F:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
***********************************
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:28:07 PM, on 4/29/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20733)
Boot mode: Normal
Running processes:
F:\Windows\System32\smss.exe
F:\Windows\system32\winlogon.exe
F:\Windows\system32\services.exe
F:\Windows\system32\lsass.exe
F:\Windows\system32\svchost.exe
F:\Windows\System32\svchost.exe
F:\Windows\system32\svchost.exe
F:\Windows\system32\spoolsv.exe
F:\Windows\Explorer.EXE
F:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
F:\Windows\system32\hkcmd.exe
F:\Program Files\Dell\QuickSet\quickset.exe
F:\Program Files\Saitek\SD6\Software\SaiMfd.exe
F:\Program Files\Dell\AccessDirect\dadapp.exe
F:\Program Files\Saitek\SD6\Software\ProfilerU.exe
F:\Windows\system32\ctfmon.exe
F:\Windows\system32\drivers\CDAC11BA.EXE
F:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
F:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
f:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
F:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
F:\PROGRA~1\McAfee\MSC\mcpromgr.exe
f:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
f:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
F:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
F:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
F:\PROGRA~1\McAfee\MPS\mps.exe
F:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
F:\Program Files\Saitek\DirectOutput\DirectOutputService.exe
F:\Windows\system32\svchost.exe
F:\Windows\system32\svchost.exe
f:\PROGRA~1\mcafee.com\agent\mcagent.exe
F:\Program Files\McAfee\MPS\mpsevh.exe
F:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 200.66.20.20:8000
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Catcher Class - {ADECBED6-0366-4377-A739-E69DFBA04663} - F:\Program Files\Moyea\FLV Downloader\MoyeaCth.dll
O2 - BHO: (no name) - {AE80D3FE-5FB5-45C7-B977-D52DCC55A6A0} - F:\Windows\system32\qomkh.dll (file missing)
O2 - BHO: (no name) - {AE8409D2-6A55-47EE-A972-6CEBCCB82A93} - (no file)
O2 - BHO: (no name) - {E9383002-FC55-4330-B9C9-67E03BC5C840} - (no file)
O3 - Toolbar: Alive Text to Speech - {954F618B-0DEC-4D1A-9317-E0FC96F87865} - D:\PROGRA~1\STUDIO~1\APPLIC~1\ORIONP~1\VSTPLU~1\TEXTTO~1\IETOOL~1.DLL (file missing)
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O4 - HKLM\..\Run: [H2O] F:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
O4 - HKLM\..\Run: [IgfxTray] F:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] F:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Dell QuickSet] F:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [SaiMfd] F:\Program Files\Saitek\SD6\Software\SaiMfd.exe
O4 - HKLM\..\Run: [DadApp] F:\Program Files\Dell\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [ProfilerU] F:\Program Files\Saitek\SD6\Software\ProfilerU.exe
O4 - HKLM\..\Run: [BMcea96586] Rundll32.exe "F:\Windows\system32\bsybfabi.dll",s
O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE F:\Windows\system32\sti_ci.dll,WiaCreateWizardMenu
O4 - HKCU\..\Run: [ctfmon.exe] F:\Windows\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] F:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] F:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Rip YouTube File - {38E51477-DDB4-4aed-9D61-D0C193E10749} - D:\Program Files\AllMusicConverter\YouTubeRipper.dll (file missing)
O9 - Extra 'Tools' menuitem: Rip YouTube file embedded in this page - {38E51477-DDB4-4aed-9D61-D0C193E10749} - D:\Program Files\AllMusicConverter\YouTubeRipper.dll (file missing)
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - F:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\Windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\Windows\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - http://www.vzwpix.com/activex/VerizonWirelessUploadControl.cab
O16 - DPF: {F09BFD07-20B5-46D8-A6D5-BE4EF22F1F4D} (DGTx.uc1) - http://67.19.2.10/DGTx.CAB
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/optimize2/pcpitstop2.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - F:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: khhfd - F:\Windows\
O20 - Winlogon Notify: pmnmjhg - pmnmjhg.dll (file missing)
O23 - Service: C-DillaCdaC11BA - Macrovision - F:\Windows\system32\drivers\CDAC11BA.EXE
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - F:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - F:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - F:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - F:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - f:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - F:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - F:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - f:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - f:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - F:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - F:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - F:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - F:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Saitek DirectOutput (SaiDOutput) - Saitek - F:\Program Files\Saitek\DirectOutput\DirectOutputService.exe
O23 - Service: SoundMovieServer - SoundMovieServer - F:\Windows\system32\snmvtsvc.exe
--
End of file - 9166 bytes
***********************************
Thanks again for your help. As you can see, I need it desperately!
God bless each of you for volunteering your expertise and time to help those of us in trouble. I need your help, please. I have been working on this for the past 4 days or so, I read your Stickys, and I have done the following:
1) Ran Spybot S&D SEVERAL times until finally there were no more red items (I had to do it in regular mode, and each scan took forever, since I can't boot into safe mode for some reason).
2) I ran Kaspersky, which appears below,
3) I ran HijackThis, which also appears below.
Any help you can give would be greatly appreciated, believe me!
Thank you in advance.
***********************************
KASPERSKY ONLINE SCANNER REPORT
Tuesday, April 29, 2008 6:22:27 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 29/04/2008
Kaspersky Anti-Virus database records: 729986
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
C:\
E:\
F:\
Scan Statistics
Total number of scanned objects 72064
Number of viruses found 8
Number of infected objects 33
Number of suspicious objects 0
Duration of the scan process 04:54:10
Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\McConfig.dat Object is locked skipped
C:\Program Files\INITIO\Button Manager v1.874\inihid.exe Infected: not-a-virus:AdWare.Win32.Look2Me.e skipped
C:\Program Files\RealVNC\VNC4\vncconfig.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\Program Files\RealVNC\VNC4\vncviewer.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\Program Files\RealVNC\VNC4\winvnc4.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\Program Files\RealVNC\VNC4\wm_hooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
F:\Documents and Settings\All Users\Application Data\McAfee\MNA\NAData Object is locked skipped
F:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\Events.dat Object is locked skipped
F:\Documents and Settings\All Users\Application Data\McAfee\MSC\McUsers.dat Object is locked skipped
F:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Data\TFR8.tmp Object is locked skipped
F:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Logs\OAS.Log Object is locked skipped
F:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
F:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
F:\Documents and Settings\All Users\Application Data\QSLLPSVCShare Object is locked skipped
F:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
F:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
F:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
F:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
F:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
F:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
F:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
F:\Documents and Settings\Owner\Cookies\index.dat Object is locked skipped
F:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
F:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
F:\Documents and Settings\Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped
F:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
F:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
F:\Documents and Settings\Owner\NTUSER.DAT Object is locked skipped
F:\Documents and Settings\Owner\ntuser.dat.LOG Object is locked skipped
F:\Documents and Settings\TEMP\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
F:\Documents and Settings\TEMP\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
F:\Documents and Settings\TEMP\NTUSER.DAT Object is locked skipped
F:\Documents and Settings\TEMP\ntuser.dat.LOG Object is locked skipped
F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP332\A0098143.exe Object is locked skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP333\A0100246.dll Infected: Packed.Win32.Monder.gen skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP333\A0101273.dll Infected: Packed.Win32.Monder.gen skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP334\A0102670.exe Infected: not-a-virus:AdWare.Win32.Vapsup.rr skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP334\A0102671.dll Infected: Packed.Win32.Monder.gen skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP334\A0102672.dll Infected: Packed.Win32.Monder.gen skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP334\A0102673.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qrh skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP334\A0102674.dll Infected: Packed.Win32.Monder.gen skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP334\A0102675.dll Infected: Packed.Win32.Monder.gen skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP334\A0102676.dll Infected: Packed.Win32.Monder.gen skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP334\A0102677.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qrg skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP334\A0105875.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qre skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP334\A0109069.dll Infected: Packed.Win32.Monder.gen skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP335\A0110098.dll Infected: Packed.Win32.Monder.gen skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP335\A0110100.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qre skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP335\A0110101.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qre skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP335\A0110102.dll Infected: Packed.Win32.Monder.gen skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP335\A0110103.dll Infected: Packed.Win32.Monder.gen skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP335\A0110104.dll Infected: Packed.Win32.Monder.gen skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP335\A0110105.dll Infected: Packed.Win32.Monder.gen skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP335\A0110106.dll Infected: Packed.Win32.Monder.gen skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP335\A0110107.dll Infected: Packed.Win32.Monder.gen skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP335\A0110108.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qre skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP335\A0110109.dll Infected: Packed.Win32.Monder.gen skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP335\A0110110.dll Infected: Packed.Win32.Monder.gen skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP335\A0110111.dll Infected: Packed.Win32.Monder.gen skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP335\A0110112.dll Infected: Packed.Win32.Monder.gen skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP335\A0110113.dll Infected: Packed.Win32.Monder.gen skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP335\A0113126.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qni skipped
F:\System Volume Information\_restore{DC5FE94F-C247-48BB-8757-6743C8CBD62D}\RP336\change.log Object is locked skipped
F:\WINDOWS\CSC\00000001 Object is locked skipped
F:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
F:\WINDOWS\SchedLgU.Txt Object is locked skipped
F:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
F:\WINDOWS\Sti_Trace.log Object is locked skipped
F:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
F:\WINDOWS\system32\config\default Object is locked skipped
F:\WINDOWS\system32\config\default.LOG Object is locked skipped
F:\WINDOWS\system32\config\Internet.evt Object is locked skipped
F:\WINDOWS\system32\config\SAM Object is locked skipped
F:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
F:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
F:\WINDOWS\system32\config\SECURITY Object is locked skipped
F:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
F:\WINDOWS\system32\config\software Object is locked skipped
F:\WINDOWS\system32\config\software.LOG Object is locked skipped
F:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
F:\WINDOWS\system32\config\system Object is locked skipped
F:\WINDOWS\system32\config\system.LOG Object is locked skipped
F:\WINDOWS\system32\h323log.txt Object is locked skipped
F:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
F:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
F:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
F:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
F:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
F:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
F:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
F:\WINDOWS\Temp\mcmsc_5dAfemtzLGP9oaS Object is locked skipped
F:\WINDOWS\Temp\mcmsc_zBPglMQrrPcoPx0 Object is locked skipped
F:\WINDOWS\wiadebug.log Object is locked skipped
F:\WINDOWS\wiaservc.log Object is locked skipped
F:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
***********************************
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:28:07 PM, on 4/29/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20733)
Boot mode: Normal
Running processes:
F:\Windows\System32\smss.exe
F:\Windows\system32\winlogon.exe
F:\Windows\system32\services.exe
F:\Windows\system32\lsass.exe
F:\Windows\system32\svchost.exe
F:\Windows\System32\svchost.exe
F:\Windows\system32\svchost.exe
F:\Windows\system32\spoolsv.exe
F:\Windows\Explorer.EXE
F:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
F:\Windows\system32\hkcmd.exe
F:\Program Files\Dell\QuickSet\quickset.exe
F:\Program Files\Saitek\SD6\Software\SaiMfd.exe
F:\Program Files\Dell\AccessDirect\dadapp.exe
F:\Program Files\Saitek\SD6\Software\ProfilerU.exe
F:\Windows\system32\ctfmon.exe
F:\Windows\system32\drivers\CDAC11BA.EXE
F:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
F:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
f:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
F:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
F:\PROGRA~1\McAfee\MSC\mcpromgr.exe
f:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
f:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
F:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
F:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
F:\PROGRA~1\McAfee\MPS\mps.exe
F:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
F:\Program Files\Saitek\DirectOutput\DirectOutputService.exe
F:\Windows\system32\svchost.exe
F:\Windows\system32\svchost.exe
f:\PROGRA~1\mcafee.com\agent\mcagent.exe
F:\Program Files\McAfee\MPS\mpsevh.exe
F:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 200.66.20.20:8000
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Catcher Class - {ADECBED6-0366-4377-A739-E69DFBA04663} - F:\Program Files\Moyea\FLV Downloader\MoyeaCth.dll
O2 - BHO: (no name) - {AE80D3FE-5FB5-45C7-B977-D52DCC55A6A0} - F:\Windows\system32\qomkh.dll (file missing)
O2 - BHO: (no name) - {AE8409D2-6A55-47EE-A972-6CEBCCB82A93} - (no file)
O2 - BHO: (no name) - {E9383002-FC55-4330-B9C9-67E03BC5C840} - (no file)
O3 - Toolbar: Alive Text to Speech - {954F618B-0DEC-4D1A-9317-E0FC96F87865} - D:\PROGRA~1\STUDIO~1\APPLIC~1\ORIONP~1\VSTPLU~1\TEXTTO~1\IETOOL~1.DLL (file missing)
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O4 - HKLM\..\Run: [H2O] F:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
O4 - HKLM\..\Run: [IgfxTray] F:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] F:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Dell QuickSet] F:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [SaiMfd] F:\Program Files\Saitek\SD6\Software\SaiMfd.exe
O4 - HKLM\..\Run: [DadApp] F:\Program Files\Dell\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [ProfilerU] F:\Program Files\Saitek\SD6\Software\ProfilerU.exe
O4 - HKLM\..\Run: [BMcea96586] Rundll32.exe "F:\Windows\system32\bsybfabi.dll",s
O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE F:\Windows\system32\sti_ci.dll,WiaCreateWizardMenu
O4 - HKCU\..\Run: [ctfmon.exe] F:\Windows\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] F:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] F:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Rip YouTube File - {38E51477-DDB4-4aed-9D61-D0C193E10749} - D:\Program Files\AllMusicConverter\YouTubeRipper.dll (file missing)
O9 - Extra 'Tools' menuitem: Rip YouTube file embedded in this page - {38E51477-DDB4-4aed-9D61-D0C193E10749} - D:\Program Files\AllMusicConverter\YouTubeRipper.dll (file missing)
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - F:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\Windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\Windows\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - http://www.vzwpix.com/activex/VerizonWirelessUploadControl.cab
O16 - DPF: {F09BFD07-20B5-46D8-A6D5-BE4EF22F1F4D} (DGTx.uc1) - http://67.19.2.10/DGTx.CAB
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/optimize2/pcpitstop2.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - F:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: khhfd - F:\Windows\
O20 - Winlogon Notify: pmnmjhg - pmnmjhg.dll (file missing)
O23 - Service: C-DillaCdaC11BA - Macrovision - F:\Windows\system32\drivers\CDAC11BA.EXE
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - F:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - F:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - F:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - F:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - f:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - F:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - F:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - f:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - f:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - F:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - F:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - F:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - F:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Saitek DirectOutput (SaiDOutput) - Saitek - F:\Program Files\Saitek\DirectOutput\DirectOutputService.exe
O23 - Service: SoundMovieServer - SoundMovieServer - F:\Windows\system32\snmvtsvc.exe
--
End of file - 9166 bytes
***********************************
Thanks again for your help. As you can see, I need it desperately!