stevencp77
2008-07-30, 03:44
I have a desktop (running XP) that is connected to a wireless network. All other computers don't have any problems, except this one. I have AVG, which is constantly warning of a trojan, but when I click on Heal, it just keeps coming back. Sometimes the webpages wont load, like its not connected, but a few minutes later, it will come back up. Could you look at this and let me know if you see anything?
Also, when I first boot up and log in, I get this popup...
Error loading C:\WINDOWS\system32\emqblwre.dll
The HJT and Spybot logs:
--- Report generated: 2008-07-27 23:48 ---
Hint of the Day: Click the bar at the right of this to see more information! ()
AdSponsor: [SBI $3113EBD7] Explorer toolbar (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{2BC9C452-BB57-4896-A9A2-64611E06C5AA}
WhenU.DAEMONTools.SearchBar: [SBI $D02FC508] Web page (File, fixed)
C:\Program Files\Mozilla Firefox\extensions\{BEE3E87E-E1C6-4bfe-BE9D-48E84271AB34}\chrome.manifest
WhenU.DAEMONTools.SearchBar: [SBI $CB4796A2] Web page (File, fixed)
C:\Program Files\Mozilla Firefox\extensions\{BEE3E87E-E1C6-4bfe-BE9D-48E84271AB34}\install.js
WhenU.DAEMONTools.SearchBar: [SBI $2BCC81C5] Web page (File, fixed)
C:\Program Files\Mozilla Firefox\extensions\{BEE3E87E-E1C6-4bfe-BE9D-48E84271AB34}\install.rdf
WhenU.DAEMONTools.SearchBar: [SBI $5FF721E8] Program directory (Directory, fixed)
C:\Program Files\Mozilla Firefox\extensions\{BEE3E87E-E1C6-4bfe-BE9D-48E84271AB34}\chrome\
WhenU.DAEMONTools.SearchBar: [SBI $677F2445] Web page (File, fixed)
C:\Program Files\Mozilla Firefox\extensions\{BEE3E87E-E1C6-4bfe-BE9D-48E84271AB34}\chrome\whenu_ff.jar
WhenU.DAEMONTools.SearchBar: [SBI $AC0C2FE5] Program directory (Directory, fixed)
C:\Program Files\Mozilla Firefox\extensions\{BEE3E87E-E1C6-4bfe-BE9D-48E84271AB34}\components\
WhenU.DAEMONTools.SearchBar: [SBI $4FB36046] Web page (File, fixed)
C:\Program Files\Mozilla Firefox\extensions\{BEE3E87E-E1C6-4bfe-BE9D-48E84271AB34}\components\Iwhenu_ff.xpt
WhenU.DAEMONTools.SearchBar: [SBI $642B8E1D] Web page (File, fixed)
C:\Program Files\Mozilla Firefox\extensions\{BEE3E87E-E1C6-4bfe-BE9D-48E84271AB34}\components\whenu_ff.dll
Zango: [SBI $62B12F59] Settings (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\ZangoToolbar
Zango: [SBI $BEB0030D] Application data folder (Directory, fixing failed)
C:\Program Files\ZangoToolbar\
Batty: [SBI $8D3AF552] Type library (Registry key, fixed)
HKEY_CLASSES_ROOT\TypeLib\{1B8B502E-455B-4022-BE27-736D9F808A18}
Batty: [SBI $11824C62] Library (File, fixed)
C:\WINDOWS\system32\BattyRun2.dll
BPSSpywareRemover: [SBI $56D821C1] Type library (Registry key, fixed)
HKEY_CLASSES_ROOT\TypeLib\{602E2CE0-53F7-11D2-A7F4-00A0C91110C3}
Delf.12.an: [SBI $85FB44D5] Library (File, fixed)
C:\WINDOWS\system32\esen.dll
Deskbar: [SBI $B9F21263] Root class (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DBTB00001.DBTB00001.1
Deskbar: [SBI $B9F21263] Class ID (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D7CC80D4-376C-4586-B023-4F35C2CEB28E}
Deskbar: [SBI $E53E52EB] Root class (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DBTB00001.DeskBar.1
Deskbar: [SBI $9466FADA] Settings (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A8B28872-3324-4CD2-8AA3-7D555C872D96}
ZenoSearch: [SBI $1C15885E] Data (File, fixed)
C:\WINDOWS\system32\winpfz32.sys
ZenoSearch: [SBI $5BE77FAA] Executable (File, fixed)
C:\WINDOWS\system32\mrdsregr.exe
Deskbar: [SBI $CE04FEFC] Root class (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DBTB00001.DBTB00001
Deskbar: [SBI $8E85FEB0] Root class (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DBTB00001.DeskBar
Deskbar: [SBI $83FD130E] Root class (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DBTB00001.deskbarBHO
Deskbar: [SBI $83FD130E] Class ID (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A8B28872-3324-4CD2-8AA3-7D555C872D96}
Deskbar: [SBI $41C34260] Root class (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DBTB00001.deskbarBHO.1
Deskbar: [SBI $B6E5E4A2] Root class (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DBTB00001.DeskbarEnabler
Deskbar: [SBI $B6E5E4A2] Class ID (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D8C2D4B4-EEAF-4EC4-B1F8-9B6ED15D5A38}
Deskbar: [SBI $60A8E322] Root class (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DBTB00001.DeskbarEnabler.1
Deskbar: [SBI $F0C8404B] Interface (Registry key, fixed)
HKEY_CLASSES_ROOT\Interface\{8F15B157-40D9-4B20-8D3B-B1F8B475B58D}
Deskbar: [SBI $CFF191EA] Interface (Registry key, fixed)
HKEY_CLASSES_ROOT\Interface\{A0881AA1-68BE-41AC-9C0D-4C8A69C6C72C}
Deskbar: [SBI $9905CAF4] Interface (Registry key, fixed)
HKEY_CLASSES_ROOT\Interface\{E827FFD9-95D1-4B49-BEB3-5D49E688C108}
Deskbar: [SBI $049D752F] Type library (Registry key, fixed)
HKEY_CLASSES_ROOT\TypeLib\{A4C8F181-6CDB-4DCC-9FC9-BB9933C81E1F}
Deskbar: [SBI $4452472C] Uninstall settings (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DBTB00001.DBTB00001Deskbar
Deskbar: [SBI $6C5F0CD8] Web page (File, fixed)
C:\Program Files\Deskbar\about.html
Deskbar: [SBI $AD818246] Web page (File, fixed)
C:\Program Files\Deskbar\basis.xml
Deskbar: [SBI $AB8BB51D] Data (File, fixed)
C:\Program Files\Deskbar\deskbar.crc
Deskbar: [SBI $054302FB] Library (File, fixed)
C:\Program Files\Deskbar\deskbar.dll
Deskbar: [SBI $8499AA6C] Data (File, fixed)
C:\Program Files\Deskbar\deskbar.inf
Deskbar: [SBI $512A8643] Picture (File, fixed)
C:\Program Files\Deskbar\icons.bmp
Deskbar: [SBI $C2EA749D] Picture (File, fixed)
C:\Program Files\Deskbar\inst.bat
Deskbar: [SBI $8B729757] Picture (File, fixed)
C:\Program Files\Deskbar\mbback.bmp
Deskbar: [SBI $B783E243] Picture (File, fixed)
C:\Program Files\Deskbar\mbbigopen.bmp
Deskbar: [SBI $B5F99307] Picture (File, fixed)
C:\Program Files\Deskbar\mbclose.bmp
Deskbar: [SBI $4F1C281E] Picture (File, fixed)
C:\Program Files\Deskbar\mbfwd.bmp
Deskbar: [SBI $290F2054] Picture (File, fixed)
C:\Program Files\Deskbar\mblogo.bmp
Deskbar: [SBI $45C80BE4] Picture (File, fixed)
C:\Program Files\Deskbar\mbsep.bmp
Deskbar: [SBI $0D5EFF2F] Picture (File, fixed)
C:\Program Files\Deskbar\options.html
Deskbar: [SBI $8B17DAF2] Picture (File, fixed)
C:\Program Files\Deskbar\softomate.gif
Deskbar: [SBI $6DB2F639] Picture (File, fixed)
C:\Program Files\Deskbar\version.txt
Deskbar: [SBI $384B0E7F] Program directory (Directory, fixed)
C:\Program Files\Deskbar\Cache\
Deskbar: [SBI $B0C8C7E7] Program directory (Directory, fixed)
C:\Program Files\Deskbar\
Deskbar: [SBI $EB99F0A0] Executable (File, fixed)
c:\deskbar4.exe
Marketscore.RelevantKnowledge: [SBI $4756FE45] Settings (Registry value, fixed)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\C:\WINDOWS\system32\rk.exe
Marketscore.RelevantKnowledge: [SBI $D68A3AB4] Settings (Registry value, fixed)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\C:\WINDOWS\system32\rk.exe
Banker: [SBI $EBFB4022] Browser helper object (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8CA5ED52-F3FB-4414-A105-2E3491156990}
Banker: [SBI $7F6039C1] Class ID (Registry key, fixed)
HKEY_CLASSES_ROOT\CLSID\{8CA5ED52-F3FB-4414-A105-2E3491156990}
SearchClickAds: [SBI $96486C8B] Program directory (Directory, fixed)
C:\WINDOWS\zAbstract\
SearchClickAds: [SBI $B9EFF9BB] Data (File, fixed)
C:\WINDOWS\zAbstract\ASI_SPEC.bsx
SearchClickAds: [SBI $B00807F9] Data (File, fixed)
C:\WINDOWS\zAbstract\ASI5AFF.bsx
SearchClickAds: [SBI $3F3E7A95] Data (File, fixed)
C:\WINDOWS\zAbstract\EECH.bsx
SearchClickAds: [SBI $AE4CED38] Data (File, fixed)
C:\WINDOWS\zAbstract\MYGEEK3.bsx
SearchClickAds: [SBI $F42138AB] Data (File, fixed)
C:\WINDOWS\zAbstract\SPZ5.bsx
TagASaurus: [SBI $0F18797C] Settings (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\System
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\ymhlurfa.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\spwtvkyg.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\ahhrshke.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\xvtnfrvj.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\sxyvimvl.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\sjvvyfew.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\xmtcvibq.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\shmssmfq.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\xaccaqkl.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\bhbrrutu.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\bprlqfhd.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\bvimelbe.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\rqvrnyim.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\wyxffmwf.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\ccbsrixe.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\ccsonlrp.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\cevsjcqv.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\cfvkirum.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\cgnfueoj.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\wxugxdkc.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\rkmrgimt.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\qxysjemg.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\qubtrqyy.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\qpuxcqcg.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\qmxceidd.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\pwgnfmkw.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\ptnjmbge.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\pehgukpq.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\oxgvanjv.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\cqbkllfu.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\tnjldigo.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\olqixcgc.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\ojdyxqfc.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\nvdmtqgf.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\toopnred.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\ngnfvrcn.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\ncrixixy.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\tvdloegp.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\dknmootf.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\ucakqbxh.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\uhtqvxli.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\ukvxftxh.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\mdopfclb.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\wlthxgpi.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\lwsnxrkh.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\urvibjwo.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\leqkdqhg.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\lbthdkjh.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\ebiphapy.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\lbeiakbx.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\eknrihrn.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\emlbwtuh.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\kywsxcuo.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\kcoeaivb.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\kcbkelag.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\jiknenwq.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\jcjutkga.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\ffsrncxr.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\isedsoha.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\vgpojuax.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\vqnqggcx.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\walsnwhq.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\iafaouhi.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\wfemewdp.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\gtsgfpta.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\hmpggvos.exe
Virtumonde.dll: [SBI $E0164A95] Library (File, fixed)
C:\WINDOWS\system32\uhabwskg.dll
Virtumonde.dll: [SBI $59A629A9] Library (File, fixed)
C:\WINDOWS\system32\yhyqrrqu.dll
Virtumonde.dll: [SBI $59A629A9] Library (File, fixed)
C:\WINDOWS\system32\xyvtsogs.dll
Virtumonde.dll: [SBI $59A629A9] Library (File, fixed)
C:\WINDOWS\system32\xyhnnsve.dll
Virtumonde.dll: [SBI $59A629A9] Library (File, fixed)
C:\WINDOWS\system32\qrpewfau.dll
Virtumonde.dll: [SBI $59A629A9] Library (File, fixed)
C:\WINDOWS\system32\oyyjgxad.dll
Virtumonde.dll: [SBI $59A629A9] Library (File, fixed)
C:\WINDOWS\system32\bapmoips.dll
Virtumonde.dll: [SBI $59A629A9] Library (File, fixed)
C:\WINDOWS\system32\kulnstkj.dll
Virtumonde.dll: [SBI $59A629A9] Library (File, fixed)
C:\WINDOWS\system32\kfmirwmg.dll
Virtumonde.dll: [SBI $59A629A9] Library (File, fixed)
C:\WINDOWS\system32\ipurqwur.dll
Right Media: Tracking cookie (Firefox: default) (Cookie, fixed)
Right Media: Tracking cookie (Firefox: default) (Cookie, fixed)
Right Media: Tracking cookie (Firefox: default) (Cookie, fixed)
Right Media: Tracking cookie (Firefox: default) (Cookie, fixed)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, fixed)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, fixed)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, fixed)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, fixed)
MediaPlex: Tracking cookie (Firefox: default) (Cookie, fixed)
BurstMedia: Tracking cookie (Firefox: default) (Cookie, fixed)
BurstMedia: Tracking cookie (Firefox: default) (Cookie, fixed)
CasaleMedia: Tracking cookie (Firefox: default) (Cookie, fixed)
DoubleClick: Tracking cookie (Firefox: default) (Cookie, fixed)
HitBox: Tracking cookie (Firefox: default) (Cookie, fixed)
HitBox: Tracking cookie (Firefox: default) (Cookie, fixed)
HitBox: Tracking cookie (Firefox: default) (Cookie, fixed)
HitBox: Tracking cookie (Firefox: default) (Cookie, fixed)
HitBox: Tracking cookie (Firefox: default) (Cookie, fixed)
HitBox: Tracking cookie (Firefox: default) (Cookie, fixed)
FastClick: Tracking cookie (Firefox: default) (Cookie, fixed)
FastClick: Tracking cookie (Firefox: default) (Cookie, fixed)
FastClick: Tracking cookie (Firefox: default) (Cookie, fixed)
FastClick: Tracking cookie (Firefox: default) (Cookie, fixed)
HitBox: Tracking cookie (Firefox: default) (Cookie, fixed)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, fixed)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, fixed)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, fixed)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, fixed)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, fixed)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, fixed)
MediaPlex: Tracking cookie (Firefox: default) (Cookie, fixed)
MediaPlex: Tracking cookie (Firefox: default) (Cookie, fixed)
Statcounter: Tracking cookie (Firefox: default) (Cookie, fixed)
WebTrends live: Tracking cookie (Firefox: default) (Cookie, fixed)
Zedo: Tracking cookie (Firefox: default) (Cookie, fixed)
Zedo: Tracking cookie (Firefox: default) (Cookie, fixed)
Zedo: Tracking cookie (Firefox: default) (Cookie, fixed)
--- Spybot - Search & Destroy version: 1.6.0 (build: 20080707) ---
2008-07-07 blindman.exe (1.0.0.8)
2008-07-07 SDFiles.exe (1.6.0.4)
2008-07-07 SDMain.exe (1.0.0.6)
2008-07-07 SDShred.exe (1.0.2.3)
2008-07-07 SDUpdate.exe (1.6.0.8)
2008-07-07 SDWinSec.exe (1.0.0.12)
2008-07-07 SpybotSD.exe (1.6.0.30)
2008-07-07 TeaTimer.exe (1.6.0.20)
2008-07-27 unins000.exe (51.49.0.0)
2008-07-07 Update.exe (1.6.0.7)
2008-07-07 advcheck.dll (1.6.1.12)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2008-07-07 SDHelper.dll (1.6.0.12)
2008-06-19 sqlite3.dll
2008-07-07 Tools.dll (2.1.5.7)
2008-07-15 Includes\Adware.sbi (*)
2008-07-15 Includes\AdwareC.sbi (*)
2008-06-03 Includes\Cookies.sbi (*)
2008-06-03 Includes\Dialer.sbi (*)
2008-07-07 Includes\DialerC.sbi (*)
2008-07-23 Includes\HeavyDuty.sbi (*)
2008-07-10 Includes\Hijackers.sbi (*)
2008-07-08 Includes\HijackersC.sbi (*)
2008-07-15 Includes\Keyloggers.sbi (*)
2008-07-15 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2008-07-23 Includes\Malware.sbi (*)
2008-07-23 Includes\MalwareC.sbi (*)
2008-07-15 Includes\PUPS.sbi (*)
2008-07-22 Includes\PUPSC.sbi (*)
2007-11-07 Includes\Revision.sbi (*)
2008-06-18 Includes\Security.sbi (*)
2008-07-08 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2008-07-11 Includes\Spyware.sbi (*)
2008-07-15 Includes\SpywareC.sbi (*)
2008-06-03 Includes\Tracks.uti
2008-07-23 Includes\Trojans.sbi (*)
2008-07-22 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:11:40 AM, on 7/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iWin Games\iWinGamesInstaller.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Documents and Settings\All Users\Application Data\iWin Games\DesktopAlerts\DesktopAlerts.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.emachines.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R3 - URLSearchHook: (no name) - {A8B28872-3324-4CD2-8AA3-7D555C872D96} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\ymlcn.exe
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {F73015A2-3DB9-40BB-8378-B39FF28F604E} - C:\WINDOWS\system32\esen.dll
O4 - HKLM\..\Run: [sys09341701420] C:\WINDOWS\sys09341701420.exe
O4 - HKLM\..\Run: [SearchIndexer] rundll32.exe "C:\WINDOWS\system32\emqblwre.dll",sitypnow
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: iWin Desktop Alerts.lnk = C:\Documents and Settings\All Users\Application Data\iWin Games\DesktopAlerts\DesktopAlerts.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) - http://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O20 - Winlogon Notify: jkkkjih - jkkkjih.dll (file missing)
O20 - Winlogon Notify: RunServices - C:\WINDOWS\system32\r0r60a9sed.dll (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: iWinGamesInstaller - iWin Inc. - C:\Program Files\iWin Games\iWinGamesInstaller.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - c:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
--
End of file - 8362 bytes
Also, when I first boot up and log in, I get this popup...
Error loading C:\WINDOWS\system32\emqblwre.dll
The HJT and Spybot logs:
--- Report generated: 2008-07-27 23:48 ---
Hint of the Day: Click the bar at the right of this to see more information! ()
AdSponsor: [SBI $3113EBD7] Explorer toolbar (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{2BC9C452-BB57-4896-A9A2-64611E06C5AA}
WhenU.DAEMONTools.SearchBar: [SBI $D02FC508] Web page (File, fixed)
C:\Program Files\Mozilla Firefox\extensions\{BEE3E87E-E1C6-4bfe-BE9D-48E84271AB34}\chrome.manifest
WhenU.DAEMONTools.SearchBar: [SBI $CB4796A2] Web page (File, fixed)
C:\Program Files\Mozilla Firefox\extensions\{BEE3E87E-E1C6-4bfe-BE9D-48E84271AB34}\install.js
WhenU.DAEMONTools.SearchBar: [SBI $2BCC81C5] Web page (File, fixed)
C:\Program Files\Mozilla Firefox\extensions\{BEE3E87E-E1C6-4bfe-BE9D-48E84271AB34}\install.rdf
WhenU.DAEMONTools.SearchBar: [SBI $5FF721E8] Program directory (Directory, fixed)
C:\Program Files\Mozilla Firefox\extensions\{BEE3E87E-E1C6-4bfe-BE9D-48E84271AB34}\chrome\
WhenU.DAEMONTools.SearchBar: [SBI $677F2445] Web page (File, fixed)
C:\Program Files\Mozilla Firefox\extensions\{BEE3E87E-E1C6-4bfe-BE9D-48E84271AB34}\chrome\whenu_ff.jar
WhenU.DAEMONTools.SearchBar: [SBI $AC0C2FE5] Program directory (Directory, fixed)
C:\Program Files\Mozilla Firefox\extensions\{BEE3E87E-E1C6-4bfe-BE9D-48E84271AB34}\components\
WhenU.DAEMONTools.SearchBar: [SBI $4FB36046] Web page (File, fixed)
C:\Program Files\Mozilla Firefox\extensions\{BEE3E87E-E1C6-4bfe-BE9D-48E84271AB34}\components\Iwhenu_ff.xpt
WhenU.DAEMONTools.SearchBar: [SBI $642B8E1D] Web page (File, fixed)
C:\Program Files\Mozilla Firefox\extensions\{BEE3E87E-E1C6-4bfe-BE9D-48E84271AB34}\components\whenu_ff.dll
Zango: [SBI $62B12F59] Settings (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\ZangoToolbar
Zango: [SBI $BEB0030D] Application data folder (Directory, fixing failed)
C:\Program Files\ZangoToolbar\
Batty: [SBI $8D3AF552] Type library (Registry key, fixed)
HKEY_CLASSES_ROOT\TypeLib\{1B8B502E-455B-4022-BE27-736D9F808A18}
Batty: [SBI $11824C62] Library (File, fixed)
C:\WINDOWS\system32\BattyRun2.dll
BPSSpywareRemover: [SBI $56D821C1] Type library (Registry key, fixed)
HKEY_CLASSES_ROOT\TypeLib\{602E2CE0-53F7-11D2-A7F4-00A0C91110C3}
Delf.12.an: [SBI $85FB44D5] Library (File, fixed)
C:\WINDOWS\system32\esen.dll
Deskbar: [SBI $B9F21263] Root class (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DBTB00001.DBTB00001.1
Deskbar: [SBI $B9F21263] Class ID (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D7CC80D4-376C-4586-B023-4F35C2CEB28E}
Deskbar: [SBI $E53E52EB] Root class (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DBTB00001.DeskBar.1
Deskbar: [SBI $9466FADA] Settings (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A8B28872-3324-4CD2-8AA3-7D555C872D96}
ZenoSearch: [SBI $1C15885E] Data (File, fixed)
C:\WINDOWS\system32\winpfz32.sys
ZenoSearch: [SBI $5BE77FAA] Executable (File, fixed)
C:\WINDOWS\system32\mrdsregr.exe
Deskbar: [SBI $CE04FEFC] Root class (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DBTB00001.DBTB00001
Deskbar: [SBI $8E85FEB0] Root class (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DBTB00001.DeskBar
Deskbar: [SBI $83FD130E] Root class (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DBTB00001.deskbarBHO
Deskbar: [SBI $83FD130E] Class ID (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A8B28872-3324-4CD2-8AA3-7D555C872D96}
Deskbar: [SBI $41C34260] Root class (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DBTB00001.deskbarBHO.1
Deskbar: [SBI $B6E5E4A2] Root class (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DBTB00001.DeskbarEnabler
Deskbar: [SBI $B6E5E4A2] Class ID (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D8C2D4B4-EEAF-4EC4-B1F8-9B6ED15D5A38}
Deskbar: [SBI $60A8E322] Root class (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DBTB00001.DeskbarEnabler.1
Deskbar: [SBI $F0C8404B] Interface (Registry key, fixed)
HKEY_CLASSES_ROOT\Interface\{8F15B157-40D9-4B20-8D3B-B1F8B475B58D}
Deskbar: [SBI $CFF191EA] Interface (Registry key, fixed)
HKEY_CLASSES_ROOT\Interface\{A0881AA1-68BE-41AC-9C0D-4C8A69C6C72C}
Deskbar: [SBI $9905CAF4] Interface (Registry key, fixed)
HKEY_CLASSES_ROOT\Interface\{E827FFD9-95D1-4B49-BEB3-5D49E688C108}
Deskbar: [SBI $049D752F] Type library (Registry key, fixed)
HKEY_CLASSES_ROOT\TypeLib\{A4C8F181-6CDB-4DCC-9FC9-BB9933C81E1F}
Deskbar: [SBI $4452472C] Uninstall settings (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DBTB00001.DBTB00001Deskbar
Deskbar: [SBI $6C5F0CD8] Web page (File, fixed)
C:\Program Files\Deskbar\about.html
Deskbar: [SBI $AD818246] Web page (File, fixed)
C:\Program Files\Deskbar\basis.xml
Deskbar: [SBI $AB8BB51D] Data (File, fixed)
C:\Program Files\Deskbar\deskbar.crc
Deskbar: [SBI $054302FB] Library (File, fixed)
C:\Program Files\Deskbar\deskbar.dll
Deskbar: [SBI $8499AA6C] Data (File, fixed)
C:\Program Files\Deskbar\deskbar.inf
Deskbar: [SBI $512A8643] Picture (File, fixed)
C:\Program Files\Deskbar\icons.bmp
Deskbar: [SBI $C2EA749D] Picture (File, fixed)
C:\Program Files\Deskbar\inst.bat
Deskbar: [SBI $8B729757] Picture (File, fixed)
C:\Program Files\Deskbar\mbback.bmp
Deskbar: [SBI $B783E243] Picture (File, fixed)
C:\Program Files\Deskbar\mbbigopen.bmp
Deskbar: [SBI $B5F99307] Picture (File, fixed)
C:\Program Files\Deskbar\mbclose.bmp
Deskbar: [SBI $4F1C281E] Picture (File, fixed)
C:\Program Files\Deskbar\mbfwd.bmp
Deskbar: [SBI $290F2054] Picture (File, fixed)
C:\Program Files\Deskbar\mblogo.bmp
Deskbar: [SBI $45C80BE4] Picture (File, fixed)
C:\Program Files\Deskbar\mbsep.bmp
Deskbar: [SBI $0D5EFF2F] Picture (File, fixed)
C:\Program Files\Deskbar\options.html
Deskbar: [SBI $8B17DAF2] Picture (File, fixed)
C:\Program Files\Deskbar\softomate.gif
Deskbar: [SBI $6DB2F639] Picture (File, fixed)
C:\Program Files\Deskbar\version.txt
Deskbar: [SBI $384B0E7F] Program directory (Directory, fixed)
C:\Program Files\Deskbar\Cache\
Deskbar: [SBI $B0C8C7E7] Program directory (Directory, fixed)
C:\Program Files\Deskbar\
Deskbar: [SBI $EB99F0A0] Executable (File, fixed)
c:\deskbar4.exe
Marketscore.RelevantKnowledge: [SBI $4756FE45] Settings (Registry value, fixed)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\C:\WINDOWS\system32\rk.exe
Marketscore.RelevantKnowledge: [SBI $D68A3AB4] Settings (Registry value, fixed)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\C:\WINDOWS\system32\rk.exe
Banker: [SBI $EBFB4022] Browser helper object (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8CA5ED52-F3FB-4414-A105-2E3491156990}
Banker: [SBI $7F6039C1] Class ID (Registry key, fixed)
HKEY_CLASSES_ROOT\CLSID\{8CA5ED52-F3FB-4414-A105-2E3491156990}
SearchClickAds: [SBI $96486C8B] Program directory (Directory, fixed)
C:\WINDOWS\zAbstract\
SearchClickAds: [SBI $B9EFF9BB] Data (File, fixed)
C:\WINDOWS\zAbstract\ASI_SPEC.bsx
SearchClickAds: [SBI $B00807F9] Data (File, fixed)
C:\WINDOWS\zAbstract\ASI5AFF.bsx
SearchClickAds: [SBI $3F3E7A95] Data (File, fixed)
C:\WINDOWS\zAbstract\EECH.bsx
SearchClickAds: [SBI $AE4CED38] Data (File, fixed)
C:\WINDOWS\zAbstract\MYGEEK3.bsx
SearchClickAds: [SBI $F42138AB] Data (File, fixed)
C:\WINDOWS\zAbstract\SPZ5.bsx
TagASaurus: [SBI $0F18797C] Settings (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\System
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\ymhlurfa.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\spwtvkyg.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\ahhrshke.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\xvtnfrvj.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\sxyvimvl.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\sjvvyfew.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\xmtcvibq.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\shmssmfq.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\xaccaqkl.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\bhbrrutu.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\bprlqfhd.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\bvimelbe.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\rqvrnyim.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\wyxffmwf.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\ccbsrixe.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\ccsonlrp.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\cevsjcqv.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\cfvkirum.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\cgnfueoj.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\wxugxdkc.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\rkmrgimt.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\qxysjemg.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\qubtrqyy.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\qpuxcqcg.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\qmxceidd.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\pwgnfmkw.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\ptnjmbge.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\pehgukpq.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\oxgvanjv.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\cqbkllfu.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\tnjldigo.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\olqixcgc.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\ojdyxqfc.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\nvdmtqgf.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\toopnred.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\ngnfvrcn.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\ncrixixy.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\tvdloegp.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\dknmootf.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\ucakqbxh.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\uhtqvxli.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\ukvxftxh.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\mdopfclb.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\wlthxgpi.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\lwsnxrkh.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\urvibjwo.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\leqkdqhg.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\lbthdkjh.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\ebiphapy.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\lbeiakbx.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\eknrihrn.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\emlbwtuh.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\kywsxcuo.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\kcoeaivb.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\kcbkelag.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\jiknenwq.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\jcjutkga.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\ffsrncxr.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\isedsoha.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\vgpojuax.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\vqnqggcx.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\walsnwhq.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\iafaouhi.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\wfemewdp.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\gtsgfpta.exe
Virtumonde.ddc: [SBI $F30C1704] Executable (File, fixed)
C:\WINDOWS\system32\hmpggvos.exe
Virtumonde.dll: [SBI $E0164A95] Library (File, fixed)
C:\WINDOWS\system32\uhabwskg.dll
Virtumonde.dll: [SBI $59A629A9] Library (File, fixed)
C:\WINDOWS\system32\yhyqrrqu.dll
Virtumonde.dll: [SBI $59A629A9] Library (File, fixed)
C:\WINDOWS\system32\xyvtsogs.dll
Virtumonde.dll: [SBI $59A629A9] Library (File, fixed)
C:\WINDOWS\system32\xyhnnsve.dll
Virtumonde.dll: [SBI $59A629A9] Library (File, fixed)
C:\WINDOWS\system32\qrpewfau.dll
Virtumonde.dll: [SBI $59A629A9] Library (File, fixed)
C:\WINDOWS\system32\oyyjgxad.dll
Virtumonde.dll: [SBI $59A629A9] Library (File, fixed)
C:\WINDOWS\system32\bapmoips.dll
Virtumonde.dll: [SBI $59A629A9] Library (File, fixed)
C:\WINDOWS\system32\kulnstkj.dll
Virtumonde.dll: [SBI $59A629A9] Library (File, fixed)
C:\WINDOWS\system32\kfmirwmg.dll
Virtumonde.dll: [SBI $59A629A9] Library (File, fixed)
C:\WINDOWS\system32\ipurqwur.dll
Right Media: Tracking cookie (Firefox: default) (Cookie, fixed)
Right Media: Tracking cookie (Firefox: default) (Cookie, fixed)
Right Media: Tracking cookie (Firefox: default) (Cookie, fixed)
Right Media: Tracking cookie (Firefox: default) (Cookie, fixed)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, fixed)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, fixed)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, fixed)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, fixed)
MediaPlex: Tracking cookie (Firefox: default) (Cookie, fixed)
BurstMedia: Tracking cookie (Firefox: default) (Cookie, fixed)
BurstMedia: Tracking cookie (Firefox: default) (Cookie, fixed)
CasaleMedia: Tracking cookie (Firefox: default) (Cookie, fixed)
DoubleClick: Tracking cookie (Firefox: default) (Cookie, fixed)
HitBox: Tracking cookie (Firefox: default) (Cookie, fixed)
HitBox: Tracking cookie (Firefox: default) (Cookie, fixed)
HitBox: Tracking cookie (Firefox: default) (Cookie, fixed)
HitBox: Tracking cookie (Firefox: default) (Cookie, fixed)
HitBox: Tracking cookie (Firefox: default) (Cookie, fixed)
HitBox: Tracking cookie (Firefox: default) (Cookie, fixed)
FastClick: Tracking cookie (Firefox: default) (Cookie, fixed)
FastClick: Tracking cookie (Firefox: default) (Cookie, fixed)
FastClick: Tracking cookie (Firefox: default) (Cookie, fixed)
FastClick: Tracking cookie (Firefox: default) (Cookie, fixed)
HitBox: Tracking cookie (Firefox: default) (Cookie, fixed)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, fixed)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, fixed)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, fixed)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, fixed)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, fixed)
AdRevolver: Tracking cookie (Firefox: default) (Cookie, fixed)
MediaPlex: Tracking cookie (Firefox: default) (Cookie, fixed)
MediaPlex: Tracking cookie (Firefox: default) (Cookie, fixed)
Statcounter: Tracking cookie (Firefox: default) (Cookie, fixed)
WebTrends live: Tracking cookie (Firefox: default) (Cookie, fixed)
Zedo: Tracking cookie (Firefox: default) (Cookie, fixed)
Zedo: Tracking cookie (Firefox: default) (Cookie, fixed)
Zedo: Tracking cookie (Firefox: default) (Cookie, fixed)
--- Spybot - Search & Destroy version: 1.6.0 (build: 20080707) ---
2008-07-07 blindman.exe (1.0.0.8)
2008-07-07 SDFiles.exe (1.6.0.4)
2008-07-07 SDMain.exe (1.0.0.6)
2008-07-07 SDShred.exe (1.0.2.3)
2008-07-07 SDUpdate.exe (1.6.0.8)
2008-07-07 SDWinSec.exe (1.0.0.12)
2008-07-07 SpybotSD.exe (1.6.0.30)
2008-07-07 TeaTimer.exe (1.6.0.20)
2008-07-27 unins000.exe (51.49.0.0)
2008-07-07 Update.exe (1.6.0.7)
2008-07-07 advcheck.dll (1.6.1.12)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2008-07-07 SDHelper.dll (1.6.0.12)
2008-06-19 sqlite3.dll
2008-07-07 Tools.dll (2.1.5.7)
2008-07-15 Includes\Adware.sbi (*)
2008-07-15 Includes\AdwareC.sbi (*)
2008-06-03 Includes\Cookies.sbi (*)
2008-06-03 Includes\Dialer.sbi (*)
2008-07-07 Includes\DialerC.sbi (*)
2008-07-23 Includes\HeavyDuty.sbi (*)
2008-07-10 Includes\Hijackers.sbi (*)
2008-07-08 Includes\HijackersC.sbi (*)
2008-07-15 Includes\Keyloggers.sbi (*)
2008-07-15 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2008-07-23 Includes\Malware.sbi (*)
2008-07-23 Includes\MalwareC.sbi (*)
2008-07-15 Includes\PUPS.sbi (*)
2008-07-22 Includes\PUPSC.sbi (*)
2007-11-07 Includes\Revision.sbi (*)
2008-06-18 Includes\Security.sbi (*)
2008-07-08 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2008-07-11 Includes\Spyware.sbi (*)
2008-07-15 Includes\SpywareC.sbi (*)
2008-06-03 Includes\Tracks.uti
2008-07-23 Includes\Trojans.sbi (*)
2008-07-22 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:11:40 AM, on 7/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iWin Games\iWinGamesInstaller.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Documents and Settings\All Users\Application Data\iWin Games\DesktopAlerts\DesktopAlerts.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.emachines.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R3 - URLSearchHook: (no name) - {A8B28872-3324-4CD2-8AA3-7D555C872D96} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\ymlcn.exe
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {F73015A2-3DB9-40BB-8378-B39FF28F604E} - C:\WINDOWS\system32\esen.dll
O4 - HKLM\..\Run: [sys09341701420] C:\WINDOWS\sys09341701420.exe
O4 - HKLM\..\Run: [SearchIndexer] rundll32.exe "C:\WINDOWS\system32\emqblwre.dll",sitypnow
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: iWin Desktop Alerts.lnk = C:\Documents and Settings\All Users\Application Data\iWin Games\DesktopAlerts\DesktopAlerts.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) - http://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O20 - Winlogon Notify: jkkkjih - jkkkjih.dll (file missing)
O20 - Winlogon Notify: RunServices - C:\WINDOWS\system32\r0r60a9sed.dll (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: iWinGamesInstaller - iWin Inc. - C:\Program Files\iWin Games\iWinGamesInstaller.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - c:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
--
End of file - 8362 bytes