Page 1 of 2 12 LastLast
Results 1 to 10 of 14

Thread: handfull of virtuemonde and other trojans

  1. #1
    Junior Member
    Join Date
    Feb 2009
    Posts
    7

    Default handfull of virtuemonde and other trojans

    yea, i noticed that there was another person who posted a similar issue but im not sure i should follow the same advice. heres my HJT logfile

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 5:54:32 PM, on 2/1/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16762)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKLM\..\Run: [18e2e033] rundll32.exe "C:\WINDOWS\system32\wsvgptdt.dll",b
    O4 - HKLM\..\RunOnce: [SpybotDeletingA5422] command /c del "C:\WINDOWS\system32\wsvgptdt.dll_old"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC4876] cmd /c del "C:\WINDOWS\system32\wsvgptdt.dll_old"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\RunOnce: [SpybotDeletingB4186] command /c del "C:\WINDOWS\system32\wsvgptdt.dll_old"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD5970] cmd /c del "C:\WINDOWS\system32\wsvgptdt.dll_old"
    O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
    O18 - Filter hijack: text/html - {0818f66b-5dc6-4308-820c-958ee09e18e0} - C:\WINDOWS\system32\mst122.dll
    O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\ccPwdSvc.exe
    O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Norton Internet Security\comHost.exe
    O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

    --
    End of file - 6805 bytes

    i could really use the help, ive been using advice from some friends that are computer engineers such as avira and nothing is seeming to work

  2. #2
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi slambert

    Rename hijackthis.exe to slambert.exe and post back a fresh HijackThis log, please
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  3. #3
    Junior Member
    Join Date
    Feb 2009
    Posts
    7

    Default nvm

    yea yesterday the viruses stacked up so much so that i couldnt do anything with the computer anymore so i had to do a destructive system restore. i havent been able to get back connected until this afternoon. thanks for trying though.

  4. #4
    Junior Member
    Join Date
    Feb 2009
    Posts
    7

    Default wait no!

    nvm again... its STILL on my computer somehow... crap, ok ill re post a hijack this log just give me a minute

  5. #5
    Junior Member
    Join Date
    Feb 2009
    Posts
    7

    Default

    sorry i dont quite understand where you wanted me to rename the hijack this file,

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 6:06:05 PM, on 2/4/2009
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\ehome\ehtray.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\DISC\DISCover.exe
    C:\Program Files\DISC\DiscUpdateMgr.exe
    C:\Program Files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\DISC\DiscGui.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
    C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\Program Files\DISC\DiscStreamHub.exe
    c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\HP\KBD\KBD.EXE
    c:\windows\system\hpsysdrv.exe
    C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
    O4 - HKLM\..\Run: [DISCover] C:\Program Files\DISC\DISCover.exe
    O4 - HKLM\..\Run: [DiscUpdateManager] C:\Program Files\DISC\DiscUpdateMgr.exe
    O4 - HKLM\..\Run: [DMAScheduler] c:\Program Files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [PCDrProfiler] "C:\Program Files\PC-Doctor 5 for Windows\RunProfiler.exe" -r
    O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [IS CfgWiz] c:\Program Files\Norton Internet Security\cfgwiz.exe /GUID {F073BDC9-0D67-4ff0-879E-27241C843828} /MODE CfgWiz /CMDLINE "REBOOT"
    O4 - HKLM\..\Run: [SSC_UserPrompt] "c:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe"
    O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
    O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\RunOnce: [AddRAID] c:\windows\regedit.exe /s c:\hp\bin\Add_RAID\AddRAID1.reg
    O4 - HKLM\..\RunOnce: [SpybotDeletingC2542] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\actorobject.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA4554] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\dx5drv.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC9628] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\dx5drv.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA1453] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\dx7drv.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC6873] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\dx7drv.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA3494] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\objectbundle.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC2747] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\objectbundle.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA6027] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\sound.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC48] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\sound.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA2021] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wdcaps.ded"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC8838] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wdcaps.ded"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA7819] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wdengine.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC3658] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wdengine.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA1791] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\webdriver.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC6756] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\webdriver.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA545] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wthost.exe"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC1165] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wthost.exe"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA4476] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wthostctl.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC6170] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wthostctl.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA5832] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtmulti.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC4092] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\data.wts"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA665] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtmulti.jar"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC4335] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtmulti.jar"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA3541] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtwmplug.ax"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC7692] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtwmplug.ax"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA3901] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtwmplug.ini"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC8601] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtwmplug.ini"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA4455] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\DRM0302.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC4665] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\DRM0302.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA3258] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\DRM0302Java.jar"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC6572] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\DRM0302Java.jar"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA38] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\jDRM0302.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC740] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\jDRM0302.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA4885] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\rDRM0302.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC1859] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\rDRM0302.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA5754] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\controlpanel\index.html"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC8697] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\controlpanel\index.html"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA432] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\install\DRM0302.cdanfo"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC8165] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\install\DRM0302.cdanfo"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA2759] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\install\DRM0302_Uninstall.cdas"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC7662] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\install\DRM0302_Uninstall.cdas"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA6005] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\actorobject.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC2852] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\actorobject.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA5548] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\dx5drv.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC4734] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\dx5drv.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA7253] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\dx7drv.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC5617] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\dx7drv.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA5597] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\jdriver.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC3047] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\jdriver.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA9737] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\npWTHost.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC5839] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\npWTHost.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA7648] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\nsIWTHostPlugin.xpt"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC9354] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\nsIWTHostPlugin.xpt"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA9173] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\ObjectBundle.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC3038] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\ObjectBundle.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA7527] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\rdriver.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC4485] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\rdriver.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA3274] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Sound.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC3487] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Sound.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA2212] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wdcaps.ded"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC8763] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wdcaps.ded"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA8545] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wdengine.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC138] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wdengine.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA833] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331.cdanfo"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC4063] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331.cdanfo"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA3984] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331_fileList.cdas"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC3069] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331_fileList.cdas"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA4513] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331_Uninstall.cdas"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC1674] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331_Uninstall.cdas"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA9193] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\webdriver.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC155] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\webdriver.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA1129] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wildtangent.jar"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC9065] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wildtangent.jar"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA1643] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wt3d.ini"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC1578] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wt3d.ini"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA5628] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\WTHost.exe"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC8741] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\WTHost.exe"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA6407] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\WTHostCtl.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC1045] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\WTHostCtl.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA4198] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtmulti.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC5015] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtmulti.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA7075] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtmulti.jar"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC7272] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtmulti.jar"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA2207] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtvh.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC6508] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtvh.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA7435] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtwmplug.ax"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC5547] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtwmplug.ax"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA6769] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtwmplug.ini"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC5708] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtwmplug.ini"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA9171] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\controlpanel\index.html"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC6455] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\controlpanel\index.html"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA9160] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\data.wts"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA1856] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\webdriver.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC9710] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\webdriver.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA1464] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\wt3d.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC2083] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\wt3d.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA2703] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\update_info\data.wts"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC4774] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\update_info\data.wts"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA8797] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\install\Webd4_1_1.cdanfo"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC8446] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\install\Webd4_1_1.cdanfo"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA6150] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\install\Webd4_1_1_Uninstall.cdas"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC8624] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\install\Webd4_1_1_Uninstall.cdas"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA5657] command.com /c del "C:\WINDOWS\wt\wtupdates\wtwebdriver\update_info\data.wts"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC8666] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\wtwebdriver\update_info\data.wts"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\RunOnce: [SpybotDeletingB1600] command.com /c del "C:\WINDOWS\wt\data.wts"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD7142] cmd.exe /c del "C:\WINDOWS\wt\data.wts"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB571] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\actorobject.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD9737] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\actorobject.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB1705] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\dx5drv.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD2240] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\dx5drv.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB3165] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\dx7drv.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD6292] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\dx7drv.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB752] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\objectbundle.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD5459] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\objectbundle.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB5414] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\sound.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD1952] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\sound.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9496] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wdcaps.ded"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD6936] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wdcaps.ded"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9192] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wdengine.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD1735] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wdengine.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB3811] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\webdriver.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD755] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\webdriver.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB7473] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wthost.exe"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD4036] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wthost.exe"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB6637] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wthostctl.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD686] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wthostctl.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB6956] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtmulti.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD2687] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtmulti.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB2075] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtmulti.jar"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3982] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtmulti.jar"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB1798] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtwmplug.ax"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD9539] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtwmplug.ax"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB2901] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtwmplug.ini"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD407] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtwmplug.ini"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB7025] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\DRM0302.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD1377] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\DRM0302.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB3205] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\DRM0302Java.jar"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD6919] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\DRM0302Java.jar"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB8275] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\jDRM0302.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD6691] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\jDRM0302.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB8299] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\rDRM0302.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD4963] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\rDRM0302.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9410] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\controlpanel\index.html"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD369] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\controlpanel\index.html"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB160] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\install\DRM0302.cdanfo"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3437] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\install\DRM0302.cdanfo"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB3199] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\install\DRM0302_Uninstall.cdas"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD8818] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\install\DRM0302_Uninstall.cdas"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB1715] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\actorobject.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD6226] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\actorobject.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB8166] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\dx5drv.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD5972] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\dx5drv.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB2556] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\dx7drv.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3047] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\dx7drv.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB5798] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\jdriver.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD4366] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\jdriver.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB7452] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\npWTHost.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD4738] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\npWTHost.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB8029] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\nsIWTHostPlugin.xpt"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD8082] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\nsIWTHostPlugin.xpt"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB595] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\ObjectBundle.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD6467] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\ObjectBundle.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9887] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\rdriver.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD622] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\rdriver.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB1628] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Sound.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3329] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Sound.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB4941] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wdcaps.ded"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3799] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wdcaps.ded"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB4479] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wdengine.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD734] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wdengine.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9878] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331.cdanfo"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD713] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331.cdanfo"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB4724] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331_fileList.cdas"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3680] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331_fileList.cdas"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB825] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331_Uninstall.cdas"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3786] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331_Uninstall.cdas"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB889] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\webdriver.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD6233] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\webdriver.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9939] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wildtangent.jar"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD5634] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wildtangent.jar"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB7949] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wt3d.ini"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD4314] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wt3d.ini"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB8774] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\WTHost.exe"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD8041] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\WTHost.exe"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB2242] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\WTHostCtl.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD2305] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\WTHostCtl.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB4419] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtmulti.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD9956] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtmulti.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB4287] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtmulti.jar"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD5851] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtmulti.jar"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9223] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtvh.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD633] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtvh.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB5501] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtwmplug.ax"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD6485] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtwmplug.ax"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB4947] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtwmplug.ini"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD9631] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtwmplug.ini"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB2078] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\controlpanel\index.html"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD1251] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\controlpanel\index.html"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB7296] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\data.wts"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD5572] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\data.wts"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB284] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\webdriver.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD196] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\webdriver.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB5724] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\wt3d.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3943] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\wt3d.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9193] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\update_info\data.wts"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD6426] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\update_info\data.wts"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9416] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\install\Webd4_1_1.cdanfo"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD8978] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\install\Webd4_1_1.cdanfo"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB6874] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\install\Webd4_1_1_Uninstall.cdas"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD1477] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\install\Webd4_1_1_Uninstall.cdas"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB2800] command.com /c del "C:\WINDOWS\wt\wtupdates\wtwebdriver\update_info\data.wts"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3580] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\wtwebdriver\update_info\data.wts"
    O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
    O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
    O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O15 - Trusted Zone: http://*.trymedia.com (HKLM)
    O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/Driver...sysreqlab3.cab
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\ccPwdSvc.exe
    O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Norton Internet Security\comHost.exe
    O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

    --
    End of file - 36423 bytes

  6. #6
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Does spybot find virtumonde?

    If so, please post next spybot report.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  7. #7
    Junior Member
    Join Date
    Feb 2009
    Posts
    7

    Default

    spybot didnt find virtuemonde this time but for some reason spybot keeps pooping up like 50 windows 1 at a time about things i should allow or block and most of them are spybotdeletions i guess involving command exe and cmd exe, do you know why spot bot is doing this?

  8. #8
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    That is due to TeaTimer.

    Let's do this:

    1. Run Spybot-S&D in Advanced Mode.
    2. If it is not already set to do this go to the "Mode" menu and select "Advanced Mode".
    3. On the left hand side, click on "Tools".
    4. Then click on the Resident Icon in the List.
    5. Uncheck "Resident TeaTimer" and OK any prompts.
    6. Restart your computer

    Open HijackThis, click do a system scan only and checkmark these:

    O4 - HKLM\..\RunOnce: [SpybotDeletingC2542] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\actorobject.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA4554] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\dx5drv.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC9628] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\dx5drv.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA1453] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\dx7drv.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC6873] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\dx7drv.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA3494] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\objectbundle.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC2747] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\objectbundle.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA6027] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\sound.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC48] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\sound.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA2021] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wdcaps.ded"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC8838] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wdcaps.ded"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA7819] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wdengine.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC3658] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wdengine.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA1791] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\webdriver.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC6756] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\webdriver.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA545] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wthost.exe"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC1165] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wthost.exe"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA4476] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wthostctl.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC6170] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wthostctl.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA5832] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtmulti.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC4092] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\data.wts"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA665] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtmulti.jar"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC4335] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtmulti.jar"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA3541] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtwmplug.ax"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC7692] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtwmplug.ax"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA3901] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtwmplug.ini"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC8601] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtwmplug.ini"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA4455] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\DRM0302.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC4665] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\DRM0302.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA3258] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\DRM0302Java.jar"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC6572] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\DRM0302Java.jar"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA38] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\jDRM0302.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC740] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\jDRM0302.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA4885] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\rDRM0302.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC1859] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\rDRM0302.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA5754] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\controlpanel\index.html"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC8697] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\controlpanel\index.html"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA432] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\install\DRM0302.cdanfo"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC8165] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\install\DRM0302.cdanfo"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA2759] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\install\DRM0302_Uninstall.cdas"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC7662] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\install\DRM0302_Uninstall.cdas"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA6005] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\actorobject.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC2852] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\actorobject.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA5548] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\dx5drv.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC4734] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\dx5drv.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA7253] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\dx7drv.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC5617] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\dx7drv.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA5597] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\jdriver.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC3047] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\jdriver.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA9737] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\npWTHost.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC5839] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\npWTHost.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA7648] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\nsIWTHostPlugin.xpt"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC9354] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\nsIWTHostPlugin.xpt"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA9173] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\ObjectBundle.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC3038] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\ObjectBundle.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA7527] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\rdriver.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC4485] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\rdriver.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA3274] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Sound.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC3487] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Sound.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA2212] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wdcaps.ded"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC8763] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wdcaps.ded"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA8545] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wdengine.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC138] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wdengine.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA833] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331.cdanfo"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC4063] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331.cdanfo"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA3984] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331_fileList.cdas"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC3069] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331_fileList.cdas"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA4513] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331_Uninstall.cdas"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC1674] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331_Uninstall.cdas"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA9193] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\webdriver.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC155] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\webdriver.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA1129] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wildtangent.jar"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC9065] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wildtangent.jar"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA1643] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wt3d.ini"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC1578] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wt3d.ini"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA5628] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\WTHost.exe"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC8741] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\WTHost.exe"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA6407] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\WTHostCtl.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC1045] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\WTHostCtl.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA4198] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtmulti.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC5015] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtmulti.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA7075] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtmulti.jar"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC7272] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtmulti.jar"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA2207] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtvh.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC6508] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtvh.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA7435] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtwmplug.ax"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC5547] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtwmplug.ax"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA6769] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtwmplug.ini"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC5708] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtwmplug.ini"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA9171] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\controlpanel\index.html"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC6455] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\controlpanel\index.html"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA9160] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\data.wts"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA1856] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\webdriver.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC9710] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\webdriver.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA1464] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\wt3d.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC2083] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\wt3d.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA2703] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\update_info\data.wts"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC4774] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\update_info\data.wts"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA8797] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\install\Webd4_1_1.cdanfo"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC8446] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\install\Webd4_1_1.cdanfo"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA6150] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\install\Webd4_1_1_Uninstall.cdas"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC8624] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\install\Webd4_1_1_Uninstall.cdas"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA5657] command.com /c del "C:\WINDOWS\wt\wtupdates\wtwebdriver\update_info\data.wts"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC8666] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\wtwebdriver\update_info\data.wts"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB1600] command.com /c del "C:\WINDOWS\wt\data.wts"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD7142] cmd.exe /c del "C:\WINDOWS\wt\data.wts"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB571] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\actorobject.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD9737] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\actorobject.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB1705] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\dx5drv.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD2240] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\dx5drv.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB3165] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\dx7drv.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD6292] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\dx7drv.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB752] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\objectbundle.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD5459] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\objectbundle.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB5414] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\sound.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD1952] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\sound.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9496] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wdcaps.ded"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD6936] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wdcaps.ded"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9192] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wdengine.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD1735] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wdengine.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB3811] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\webdriver.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD755] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\webdriver.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB7473] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wthost.exe"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD4036] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wthost.exe"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB6637] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wthostctl.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD686] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wthostctl.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB6956] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtmulti.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD2687] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtmulti.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB2075] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtmulti.jar"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3982] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtmulti.jar"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB1798] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtwmplug.ax"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD9539] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtwmplug.ax"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB2901] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtwmplug.ini"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD407] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtwmplug.ini"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB7025] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\DRM0302.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD1377] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\DRM0302.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB3205] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\DRM0302Java.jar"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD6919] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\DRM0302Java.jar"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB8275] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\jDRM0302.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD6691] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\jDRM0302.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB8299] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\rDRM0302.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD4963] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\rDRM0302.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9410] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\controlpanel\index.html"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD369] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\controlpanel\index.html"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB160] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\install\DRM0302.cdanfo"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3437] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\install\DRM0302.cdanfo"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB3199] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\install\DRM0302_Uninstall.cdas"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD8818] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\install\DRM0302_Uninstall.cdas"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB1715] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\actorobject.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD6226] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\actorobject.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB8166] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\dx5drv.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD5972] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\dx5drv.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB2556] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\dx7drv.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3047] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\dx7drv.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB5798] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\jdriver.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD4366] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\jdriver.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB7452] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\npWTHost.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD4738] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\npWTHost.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB8029] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\nsIWTHostPlugin.xpt"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD8082] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\nsIWTHostPlugin.xpt"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB595] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\ObjectBundle.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD6467] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\ObjectBundle.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9887] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\rdriver.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD622] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\rdriver.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB1628] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Sound.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3329] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Sound.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB4941] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wdcaps.ded"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3799] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wdcaps.ded"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB4479] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wdengine.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD734] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wdengine.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9878] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331.cdanfo"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD713] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331.cdanfo"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB4724] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331_fileList.cdas"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3680] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331_fileList.cdas"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB825] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331_Uninstall.cdas"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3786] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\Webd331_Uninstall.cdas"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB889] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\webdriver.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD6233] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\webdriver.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9939] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wildtangent.jar"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD5634] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wildtangent.jar"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB7949] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wt3d.ini"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD4314] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wt3d.ini"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB8774] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\WTHost.exe"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD8041] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\WTHost.exe"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB2242] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\WTHostCtl.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD2305] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\WTHostCtl.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB4419] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtmulti.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD9956] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtmulti.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB4287] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtmulti.jar"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD5851] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtmulti.jar"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9223] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtvh.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD633] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtvh.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB5501] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtwmplug.ax"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD6485] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtwmplug.ax"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB4947] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtwmplug.ini"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD9631] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtwmplug.ini"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB2078] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\controlpanel\index.html"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD1251] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\controlpanel\index.html"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB7296] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\data.wts"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD5572] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\data.wts"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB284] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\webdriver.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD196] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\webdriver.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB5724] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\wt3d.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3943] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy\wt3d.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9193] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\update_info\data.wts"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD6426] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\update_info\data.wts"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9416] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\install\Webd4_1_1.cdanfo"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD8978] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\install\Webd4_1_1.cdanfo"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB6874] command.com /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\install\Webd4_1_1_Uninstall.cdas"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD1477] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\webd\4.1.1\install\Webd4_1_1_Uninstall.cdas"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB2800] command.com /c del "C:\WINDOWS\wt\wtupdates\wtwebdriver\update_info\data.wts"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3580] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\wtwebdriver\update_info\data.wts"


    Close all windows including browser and press fix checked.

    Reboot.

    Re-enable TeaTimer.

    Post back a fresh HijackThis log, please.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  9. #9
    Junior Member
    Join Date
    Feb 2009
    Posts
    7

    Default

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 4:28:23 PM, on 2/6/2009
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16762)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\DISC\DISCover.exe
    C:\Program Files\DISC\DiscUpdateMgr.exe
    C:\Program Files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
    C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe
    C:\Program Files\DISC\DiscGui.exe
    C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
    c:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\system32\HPZipm12.exe
    c:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\DISC\DiscStreamHub.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\HP\KBD\KBD.EXE
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
    O4 - HKLM\..\Run: [DISCover] C:\Program Files\DISC\DISCover.exe
    O4 - HKLM\..\Run: [DiscUpdateManager] C:\Program Files\DISC\DiscUpdateMgr.exe
    O4 - HKLM\..\Run: [DMAScheduler] c:\Program Files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [PCDrProfiler] "C:\Program Files\PC-Doctor 5 for Windows\RunProfiler.exe" -r
    O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [IS CfgWiz] c:\Program Files\Norton Internet Security\cfgwiz.exe /GUID {F073BDC9-0D67-4ff0-879E-27241C843828} /MODE CfgWiz /CMDLINE "REBOOT"
    O4 - HKLM\..\Run: [SSC_UserPrompt] "c:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe"
    O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
    O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\RunOnce: [SpybotDeletingD686] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wthostctl.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB6956] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtmulti.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD2687] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtmulti.dll"
    O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
    O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
    O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O15 - Trusted Zone: http://*.trymedia.com (HKLM)
    O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/Driver...sysreqlab3.cab
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\ccPwdSvc.exe
    O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Norton Internet Security\comHost.exe
    O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

    --
    End of file - 12259 bytes

    every thing seems mostly fine now i think, thanks for the help

  10. #10
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    There are still some:


    1. Run Spybot-S&D in Advanced Mode.
    2. If it is not already set to do this go to the "Mode" menu and select "Advanced Mode".
    3. On the left hand side, click on "Tools".
    4. Then click on the Resident Icon in the List.
    5. Uncheck "Resident TeaTimer" and OK any prompts.
    6. Restart your computer

    Open HijackThis, click do a system scan only and checkmark these:

    O4 - HKCU\..\RunOnce: [SpybotDeletingD686] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wthostctl.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB6956] command.com /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtmulti.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD2687] cmd.exe /c del "C:\WINDOWS\wt\webdriver\4.1.1\wtmulti.dll"



    Close all windows including browser and press fix checked.

    Reboot.

    Re-enable TeaTimer.

    Post back a fresh HijackThis log, please.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •