steds
2009-09-18, 19:21
Hi there
Started having problems more than a week ago.
Spybot S&D detected Win32.TDSS.ntf, Trojans removed them, but they keep cominig back. There're there every time I run S&D.
Also MBAM detected a Trojan downloader and Spyware Ambler (?) and seemed to remove them.
I started having problems with my connection. FF and IE didn't work and couldn't download updates for any of my antivirus/antispyware.
I turned the router off.
I then found System Restore had been turned off and there were no restore points.
Also other things affected like Nero backup not working properly.
(Most stuff backedup except recent stuff)
I changed passwords on another pc and backed up what i could. Preparing for the worst, but if anyone can help I would greatly appreciate it.
I ran HJT. Here's the log.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:47:53, on 18/09/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe" "C:\Documents and Settings\Stephen\Local Settings\Application Data\Identities\{B9BC5F44-DBAE-48EF-AF57-1DA90594DE66}\Microsoft\Outlook Express\Sent Items.dbx"
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Freecorder Toolbar - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\tbFre1.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Freecorder Toolbar - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\tbFre1.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3942] command.com /c del "C:\WINDOWS\system32\drivers\kbiwkmbaqjgepp.sys_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7064] cmd.exe /c del "C:\WINDOWS\system32\drivers\kbiwkmbaqjgepp.sys_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6506] command.com /c del "C:\WINDOWS\system32\drivers\kbiwkmbaqjgepp.sys"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1249] cmd.exe /c del "C:\WINDOWS\system32\drivers\kbiwkmbaqjgepp.sys"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5702] command.com /c del "C:\WINDOWS\system32\kbiwkmjefbobow.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2438] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmjefbobow.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA297] command.com /c del "C:\WINDOWS\system32\kbiwkmjefbobow.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3368] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmjefbobow.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA70] command.com /c del "C:\WINDOWS\system32\kbiwkmtkaybajt.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2001] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmtkaybajt.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4756] command.com /c del "C:\WINDOWS\system32\kbiwkmtkaybajt.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6461] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmtkaybajt.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5160] command.com /c del "C:\WINDOWS\system32\kbiwkmtvefyrcw.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2933] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmtvefyrcw.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1577] command.com /c del "C:\WINDOWS\system32\kbiwkmtvefyrcw.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4157] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmtvefyrcw.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8620] command.com /c del "C:\WINDOWS\system32\kbiwkmmkjsakcn.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5273] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmmkjsakcn.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7724] command.com /c del "C:\WINDOWS\system32\kbiwkmmkjsakcn.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4968] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmmkjsakcn.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5429] command.com /c del "C:\WINDOWS\system32\kbiwkmvxoyibqt.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9892] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmvxoyibqt.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2515] command.com /c del "C:\WINDOWS\system32\kbiwkmvxoyibqt.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7237] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmvxoyibqt.dat"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1440] command.com /c del "C:\WINDOWS\system32\drivers\kbiwkmbaqjgepp.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9035] cmd.exe /c del "C:\WINDOWS\system32\drivers\kbiwkmbaqjgepp.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB246] command.com /c del "C:\WINDOWS\system32\drivers\kbiwkmbaqjgepp.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1926] cmd.exe /c del "C:\WINDOWS\system32\drivers\kbiwkmbaqjgepp.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7616] command.com /c del "C:\WINDOWS\system32\kbiwkmjefbobow.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8290] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmjefbobow.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB833] command.com /c del "C:\WINDOWS\system32\kbiwkmjefbobow.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8736] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmjefbobow.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB817] command.com /c del "C:\WINDOWS\system32\kbiwkmtkaybajt.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5983] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmtkaybajt.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6380] command.com /c del "C:\WINDOWS\system32\kbiwkmtkaybajt.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3161] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmtkaybajt.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8692] command.com /c del "C:\WINDOWS\system32\kbiwkmtvefyrcw.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1987] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmtvefyrcw.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8199] command.com /c del "C:\WINDOWS\system32\kbiwkmtvefyrcw.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5275] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmtvefyrcw.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6815] command.com /c del "C:\WINDOWS\system32\kbiwkmmkjsakcn.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7941] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmmkjsakcn.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB737] command.com /c del "C:\WINDOWS\system32\kbiwkmmkjsakcn.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6724] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmmkjsakcn.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7230] command.com /c del "C:\WINDOWS\system32\kbiwkmvxoyibqt.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD997] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmvxoyibqt.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9888] command.com /c del "C:\WINDOWS\system32\kbiwkmvxoyibqt.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2043] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmvxoyibqt.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9654] command.com /c del "C:\WINDOWS\system32\drivers\kbiwkmbaqjgepp.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1654] cmd.exe /c del "C:\WINDOWS\system32\drivers\kbiwkmbaqjgepp.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3698] command.com /c del "C:\WINDOWS\system32\drivers\kbiwkmbaqjgepp.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingD260] cmd.exe /c del "C:\WINDOWS\system32\drivers\kbiwkmbaqjgepp.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9885] command.com /c del "C:\WINDOWS\system32\kbiwkmjefbobow.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4373] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmjefbobow.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1555] command.com /c del "C:\WINDOWS\system32\kbiwkmjefbobow.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD401] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmjefbobow.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7840] command.com /c del "C:\WINDOWS\system32\kbiwkmtkaybajt.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7203] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmtkaybajt.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6810] command.com /c del "C:\WINDOWS\system32\kbiwkmtkaybajt.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2975] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmtkaybajt.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4270] command.com /c del "C:\WINDOWS\system32\kbiwkmtvefyrcw.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4230] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmtvefyrcw.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9180] command.com /c del "C:\WINDOWS\system32\kbiwkmtvefyrcw.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8031] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmtvefyrcw.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5603] command.com /c del "C:\WINDOWS\system32\kbiwkmmkjsakcn.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4366] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmmkjsakcn.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1055] command.com /c del "C:\WINDOWS\system32\kbiwkmmkjsakcn.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7664] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmmkjsakcn.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4154] command.com /c del "C:\WINDOWS\system32\kbiwkmvxoyibqt.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3185] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmvxoyibqt.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1516] command.com /c del "C:\WINDOWS\system32\kbiwkmvxoyibqt.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3637] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmvxoyibqt.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2018] command.com /c del "C:\WINDOWS\system32\drivers\kbiwkmbaqjgepp.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD107] cmd.exe /c del "C:\WINDOWS\system32\drivers\kbiwkmbaqjgepp.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5301] command.com /c del "C:\WINDOWS\system32\drivers\kbiwkmbaqjgepp.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8430] cmd.exe /c del "C:\WINDOWS\system32\drivers\kbiwkmbaqjgepp.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingB730] command.com /c del "C:\WINDOWS\system32\kbiwkmjefbobow.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2130] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmjefbobow.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6799] command.com /c del "C:\WINDOWS\system32\kbiwkmjefbobow.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7019] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmjefbobow.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4778] command.com /c del "C:\WINDOWS\system32\kbiwkmtkaybajt.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD58] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmtkaybajt.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2011] command.com /c del "C:\WINDOWS\system32\kbiwkmtkaybajt.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6727] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmtkaybajt.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1976] command.com /c del "C:\WINDOWS\system32\kbiwkmtvefyrcw.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2475] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmtvefyrcw.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1887] command.com /c del "C:\WINDOWS\system32\kbiwkmtvefyrcw.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5536] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmtvefyrcw.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3332] command.com /c del "C:\WINDOWS\system32\kbiwkmmkjsakcn.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2435] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmmkjsakcn.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4084] command.com /c del "C:\WINDOWS\system32\kbiwkmmkjsakcn.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1577] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmmkjsakcn.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9874] command.com /c del "C:\WINDOWS\system32\kbiwkmvxoyibqt.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3148] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmvxoyibqt.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8023] command.com /c del "C:\WINDOWS\system32\kbiwkmvxoyibqt.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7992] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmvxoyibqt.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7145] command.com /c del "C:\WINDOWS\system32\drivers\kbiwkmbaqjgepp.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1756] cmd.exe /c del "C:\WINDOWS\system32\drivers\kbiwkmbaqjgepp.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9412] command.com /c del "C:\WINDOWS\system32\drivers\kbiwkmbaqjgepp.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7490] cmd.exe /c del "C:\WINDOWS\system32\drivers\kbiwkmbaqjgepp.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2793] command.com /c del "C:\WINDOWS\system32\kbiwkmjefbobow.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1236] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmjefbobow.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1162] command.com /c del "C:\WINDOWS\system32\kbiwkmjefbobow.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1858] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmjefbobow.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9427] command.com /c del "C:\WINDOWS\system32\kbiwkmtkaybajt.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD677] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmtkaybajt.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7153] command.com /c del "C:\WINDOWS\system32\kbiwkmtkaybajt.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3864] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmtkaybajt.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB927] command.com /c del "C:\WINDOWS\system32\kbiwkmtvefyrcw.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8363] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmtvefyrcw.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7928] command.com /c del "C:\WINDOWS\system32\kbiwkmtvefyrcw.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1330] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmtvefyrcw.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2375] command.com /c del "C:\WINDOWS\system32\kbiwkmmkjsakcn.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7436] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmmkjsakcn.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9204] command.com /c del "C:\WINDOWS\system32\kbiwkmmkjsakcn.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8685] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmmkjsakcn.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2210] command.com /c del "C:\WINDOWS\system32\kbiwkmvxoyibqt.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7601] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmvxoyibqt.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1298] command.com /c del "C:\WINDOWS\system32\kbiwkmvxoyibqt.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4483] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmvxoyibqt.dat"
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MotoConnect Service - Unknown owner - C:\Program Files\Motorola\MotoConnectService\MotoConnectService.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 19349 bytes
Started having problems more than a week ago.
Spybot S&D detected Win32.TDSS.ntf, Trojans removed them, but they keep cominig back. There're there every time I run S&D.
Also MBAM detected a Trojan downloader and Spyware Ambler (?) and seemed to remove them.
I started having problems with my connection. FF and IE didn't work and couldn't download updates for any of my antivirus/antispyware.
I turned the router off.
I then found System Restore had been turned off and there were no restore points.
Also other things affected like Nero backup not working properly.
(Most stuff backedup except recent stuff)
I changed passwords on another pc and backed up what i could. Preparing for the worst, but if anyone can help I would greatly appreciate it.
I ran HJT. Here's the log.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:47:53, on 18/09/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe" "C:\Documents and Settings\Stephen\Local Settings\Application Data\Identities\{B9BC5F44-DBAE-48EF-AF57-1DA90594DE66}\Microsoft\Outlook Express\Sent Items.dbx"
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Freecorder Toolbar - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\tbFre1.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Freecorder Toolbar - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\tbFre1.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3942] command.com /c del "C:\WINDOWS\system32\drivers\kbiwkmbaqjgepp.sys_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7064] cmd.exe /c del "C:\WINDOWS\system32\drivers\kbiwkmbaqjgepp.sys_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6506] command.com /c del "C:\WINDOWS\system32\drivers\kbiwkmbaqjgepp.sys"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1249] cmd.exe /c del "C:\WINDOWS\system32\drivers\kbiwkmbaqjgepp.sys"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5702] command.com /c del "C:\WINDOWS\system32\kbiwkmjefbobow.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2438] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmjefbobow.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA297] command.com /c del "C:\WINDOWS\system32\kbiwkmjefbobow.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3368] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmjefbobow.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA70] command.com /c del "C:\WINDOWS\system32\kbiwkmtkaybajt.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2001] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmtkaybajt.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4756] command.com /c del "C:\WINDOWS\system32\kbiwkmtkaybajt.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6461] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmtkaybajt.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5160] command.com /c del "C:\WINDOWS\system32\kbiwkmtvefyrcw.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2933] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmtvefyrcw.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1577] command.com /c del "C:\WINDOWS\system32\kbiwkmtvefyrcw.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4157] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmtvefyrcw.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8620] command.com /c del "C:\WINDOWS\system32\kbiwkmmkjsakcn.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5273] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmmkjsakcn.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7724] command.com /c del "C:\WINDOWS\system32\kbiwkmmkjsakcn.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4968] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmmkjsakcn.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5429] command.com /c del "C:\WINDOWS\system32\kbiwkmvxoyibqt.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9892] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmvxoyibqt.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2515] command.com /c del "C:\WINDOWS\system32\kbiwkmvxoyibqt.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7237] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmvxoyibqt.dat"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1440] command.com /c del "C:\WINDOWS\system32\drivers\kbiwkmbaqjgepp.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9035] cmd.exe /c del "C:\WINDOWS\system32\drivers\kbiwkmbaqjgepp.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB246] command.com /c del "C:\WINDOWS\system32\drivers\kbiwkmbaqjgepp.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1926] cmd.exe /c del "C:\WINDOWS\system32\drivers\kbiwkmbaqjgepp.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7616] command.com /c del "C:\WINDOWS\system32\kbiwkmjefbobow.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8290] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmjefbobow.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB833] command.com /c del "C:\WINDOWS\system32\kbiwkmjefbobow.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8736] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmjefbobow.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB817] command.com /c del "C:\WINDOWS\system32\kbiwkmtkaybajt.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5983] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmtkaybajt.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6380] command.com /c del "C:\WINDOWS\system32\kbiwkmtkaybajt.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3161] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmtkaybajt.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8692] command.com /c del "C:\WINDOWS\system32\kbiwkmtvefyrcw.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1987] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmtvefyrcw.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8199] command.com /c del "C:\WINDOWS\system32\kbiwkmtvefyrcw.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5275] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmtvefyrcw.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6815] command.com /c del "C:\WINDOWS\system32\kbiwkmmkjsakcn.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7941] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmmkjsakcn.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB737] command.com /c del "C:\WINDOWS\system32\kbiwkmmkjsakcn.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6724] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmmkjsakcn.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7230] command.com /c del "C:\WINDOWS\system32\kbiwkmvxoyibqt.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD997] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmvxoyibqt.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9888] command.com /c del "C:\WINDOWS\system32\kbiwkmvxoyibqt.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2043] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmvxoyibqt.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9654] command.com /c del "C:\WINDOWS\system32\drivers\kbiwkmbaqjgepp.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1654] cmd.exe /c del "C:\WINDOWS\system32\drivers\kbiwkmbaqjgepp.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3698] command.com /c del "C:\WINDOWS\system32\drivers\kbiwkmbaqjgepp.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingD260] cmd.exe /c del "C:\WINDOWS\system32\drivers\kbiwkmbaqjgepp.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9885] command.com /c del "C:\WINDOWS\system32\kbiwkmjefbobow.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4373] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmjefbobow.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1555] command.com /c del "C:\WINDOWS\system32\kbiwkmjefbobow.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD401] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmjefbobow.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7840] command.com /c del "C:\WINDOWS\system32\kbiwkmtkaybajt.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7203] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmtkaybajt.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6810] command.com /c del "C:\WINDOWS\system32\kbiwkmtkaybajt.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2975] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmtkaybajt.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4270] command.com /c del "C:\WINDOWS\system32\kbiwkmtvefyrcw.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4230] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmtvefyrcw.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9180] command.com /c del "C:\WINDOWS\system32\kbiwkmtvefyrcw.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8031] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmtvefyrcw.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5603] command.com /c del "C:\WINDOWS\system32\kbiwkmmkjsakcn.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4366] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmmkjsakcn.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1055] command.com /c del "C:\WINDOWS\system32\kbiwkmmkjsakcn.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7664] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmmkjsakcn.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4154] command.com /c del "C:\WINDOWS\system32\kbiwkmvxoyibqt.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3185] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmvxoyibqt.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1516] command.com /c del "C:\WINDOWS\system32\kbiwkmvxoyibqt.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3637] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmvxoyibqt.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2018] command.com /c del "C:\WINDOWS\system32\drivers\kbiwkmbaqjgepp.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD107] cmd.exe /c del "C:\WINDOWS\system32\drivers\kbiwkmbaqjgepp.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5301] command.com /c del "C:\WINDOWS\system32\drivers\kbiwkmbaqjgepp.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8430] cmd.exe /c del "C:\WINDOWS\system32\drivers\kbiwkmbaqjgepp.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingB730] command.com /c del "C:\WINDOWS\system32\kbiwkmjefbobow.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2130] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmjefbobow.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6799] command.com /c del "C:\WINDOWS\system32\kbiwkmjefbobow.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7019] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmjefbobow.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4778] command.com /c del "C:\WINDOWS\system32\kbiwkmtkaybajt.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD58] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmtkaybajt.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2011] command.com /c del "C:\WINDOWS\system32\kbiwkmtkaybajt.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6727] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmtkaybajt.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1976] command.com /c del "C:\WINDOWS\system32\kbiwkmtvefyrcw.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2475] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmtvefyrcw.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1887] command.com /c del "C:\WINDOWS\system32\kbiwkmtvefyrcw.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5536] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmtvefyrcw.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3332] command.com /c del "C:\WINDOWS\system32\kbiwkmmkjsakcn.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2435] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmmkjsakcn.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4084] command.com /c del "C:\WINDOWS\system32\kbiwkmmkjsakcn.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1577] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmmkjsakcn.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9874] command.com /c del "C:\WINDOWS\system32\kbiwkmvxoyibqt.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3148] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmvxoyibqt.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8023] command.com /c del "C:\WINDOWS\system32\kbiwkmvxoyibqt.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7992] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmvxoyibqt.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7145] command.com /c del "C:\WINDOWS\system32\drivers\kbiwkmbaqjgepp.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1756] cmd.exe /c del "C:\WINDOWS\system32\drivers\kbiwkmbaqjgepp.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9412] command.com /c del "C:\WINDOWS\system32\drivers\kbiwkmbaqjgepp.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7490] cmd.exe /c del "C:\WINDOWS\system32\drivers\kbiwkmbaqjgepp.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2793] command.com /c del "C:\WINDOWS\system32\kbiwkmjefbobow.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1236] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmjefbobow.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1162] command.com /c del "C:\WINDOWS\system32\kbiwkmjefbobow.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1858] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmjefbobow.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9427] command.com /c del "C:\WINDOWS\system32\kbiwkmtkaybajt.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD677] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmtkaybajt.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7153] command.com /c del "C:\WINDOWS\system32\kbiwkmtkaybajt.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3864] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmtkaybajt.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB927] command.com /c del "C:\WINDOWS\system32\kbiwkmtvefyrcw.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8363] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmtvefyrcw.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7928] command.com /c del "C:\WINDOWS\system32\kbiwkmtvefyrcw.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1330] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmtvefyrcw.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2375] command.com /c del "C:\WINDOWS\system32\kbiwkmmkjsakcn.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7436] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmmkjsakcn.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9204] command.com /c del "C:\WINDOWS\system32\kbiwkmmkjsakcn.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8685] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmmkjsakcn.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2210] command.com /c del "C:\WINDOWS\system32\kbiwkmvxoyibqt.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7601] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmvxoyibqt.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1298] command.com /c del "C:\WINDOWS\system32\kbiwkmvxoyibqt.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4483] cmd.exe /c del "C:\WINDOWS\system32\kbiwkmvxoyibqt.dat"
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MotoConnect Service - Unknown owner - C:\Program Files\Motorola\MotoConnectService\MotoConnectService.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 19349 bytes