Positronic
New member
I was attacked by a particularly vicious virus / trojan and just got around to trying to remedy it. I got rid of the bulk of it through Spybot Search & Destroy, Avast! AV, and Windows Defender, but I am wondering if there is anything left over.
Here is my HijackThis log:
[QUOTE="HiJackThis Logfile]Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:52:46 PM, on 4/27/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Airlink101\AWLH5026\WLService.exe
C:\WINDOWS\winself.exe
C:\Program Files\Airlink101\AWLH5026\AWLH5026.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
D:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\ZuneBusEnum.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\regsvr32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\PC Magazine Utilities\Startup Cop Pro\StartupCopPro.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Mozilla Firefox 3 Beta 3\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://livesecuritycenter.com/?aid=444.0
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,userinit.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: testCPV6 - {15421B84-3488-49A7-AD18-CBF84A3EFAF6} - C:\Program Files\CPV\CPV8.dll (file missing)
O2 - BHO: (no name) - {15651c7c-e812-44a2-a9ac-b467a2233e7d} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {622cc208-b014-4fe0-801b-874a5e5e403a} - (no file)
O2 - BHO: BatBHO - {63F7460B-C831-4142-A4AA-5EC303EC4343} - C:\Program Files\Bat\Bat.dll (file missing)
O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {9c5b2f29-1f46-4639-a6b4-828942301d3e} - (no file)
O2 - BHO: (no name) - {9DFF5598-EA60-4B59-B566-A94F6FF034CE} - C:\WINDOWS\system32\awvts.dll (file missing)
O2 - BHO: (no name) - {CAFE15D2-8215-8CC6-1592-A28F76267D92} - C:\WINDOWS\system32\pflrka.dll (file missing)
O2 - BHO: (no name) - {db41de82-1dd1-11b2-b7fd-fbaf280c36b9} - C:\WINDOWS\kvazyzst.dll
O2 - BHO: (no name) - {E9383002-FC55-4330-B9C9-67E03BC5C840} - C:\WINDOWS\system32\opnnmkj.dll (file missing)
O2 - BHO: (no name) - {ffff0001-0002-101a-a3c9-08002b2f49fb} - (no file)
O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [hwlypana] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\hwlypana.dll"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\RunOnce: [SpybotDeletingA9220] command /c del "C:\Program Files\Outerinfo\FF\install.rdf"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8374] cmd /c del "C:\Program Files\Outerinfo\FF\install.rdf"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1727] command /c del "C:\Program Files\Outerinfo\FF\components\OuterinfoAds.xpt"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5449] cmd /c del "C:\Program Files\Outerinfo\FF\components\OuterinfoAds.xpt"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5554] command /c del "C:\WINDOWS\odsfkhmd.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2595] cmd /c del "C:\WINDOWS\odsfkhmd.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3703] command /c del "C:\WINDOWS\odsfkhmd.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7545] cmd /c del "C:\WINDOWS\odsfkhmd.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1122] command /c del "C:\WINDOWS\b155.exe_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9251] cmd /c del "C:\WINDOWS\b155.exe_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2745] command /c del "C:\WINDOWS\b156.exe_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4418] cmd /c del "C:\WINDOWS\b156.exe_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4441] command /c del "C:\WINDOWS\b157.exe_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4972] cmd /c del "C:\WINDOWS\b157.exe_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7416] command /c del "C:\WINDOWS\odsfkhmd.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4349] cmd /c del "C:\WINDOWS\odsfkhmd.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9376] command /c del "C:\WINDOWS\system32\geedc.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2746] cmd /c del "C:\WINDOWS\system32\geedc.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5785] command /c del "C:\WINDOWS\system32\jkhhg.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3392] cmd /c del "C:\WINDOWS\system32\jkhhg.dll_old"
O4 - HKCU\..\Run: [Startup Cop Pro Startup Launcher] "C:\Program Files\PC Magazine Utilities\Startup Cop Pro\StartupCopPro.exe" /startup
O4 - HKCU\..\Run: [HijackThis startup scan] C:\Program Files\Trend Micro\HijackThis\HijackThis.exe /startupscan
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB280] command /c del "C:\Program Files\Outerinfo\FF\install.rdf"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3577] cmd /c del "C:\Program Files\Outerinfo\FF\install.rdf"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1954] command /c del "C:\Program Files\Outerinfo\FF\components\OuterinfoAds.xpt"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4946] cmd /c del "C:\Program Files\Outerinfo\FF\components\OuterinfoAds.xpt"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2546] command /c del "C:\WINDOWS\odsfkhmd.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6118] cmd /c del "C:\WINDOWS\odsfkhmd.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9382] command /c del "C:\WINDOWS\odsfkhmd.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8870] cmd /c del "C:\WINDOWS\odsfkhmd.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7771] command /c del "C:\WINDOWS\b155.exe_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5160] cmd /c del "C:\WINDOWS\b155.exe_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7057] command /c del "C:\WINDOWS\b156.exe_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9027] cmd /c del "C:\WINDOWS\b156.exe_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9643] command /c del "C:\WINDOWS\b157.exe_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7824] cmd /c del "C:\WINDOWS\b157.exe_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7083] command /c del "C:\WINDOWS\odsfkhmd.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2443] cmd /c del "C:\WINDOWS\odsfkhmd.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8525] command /c del "C:\WINDOWS\system32\geedc.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2739] cmd /c del "C:\WINDOWS\system32\geedc.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9512] command /c del "C:\WINDOWS\system32\jkhhg.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2061] cmd /c del "C:\WINDOWS\system32\jkhhg.dll_old"
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O20 - AppInit_DLLs: WIKI.DLL
O20 - Winlogon Notify: opnnmkj - opnnmkj.dll (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: MIMO XR TM PCI Adapter WLService (MIMO XR TM PCI WLService) - Unknown owner - C:\Program Files\Airlink101\AWLH5026\WLService.exe
O23 - Service: MSSysInterv (MSSysInterv1) - Unknown owner - C:\WINDOWS\winself.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - D:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 10508 bytes
[/QUOTE]
Here is my HijackThis log:
[QUOTE="HiJackThis Logfile]Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:52:46 PM, on 4/27/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Airlink101\AWLH5026\WLService.exe
C:\WINDOWS\winself.exe
C:\Program Files\Airlink101\AWLH5026\AWLH5026.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
D:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\ZuneBusEnum.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\regsvr32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\PC Magazine Utilities\Startup Cop Pro\StartupCopPro.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Mozilla Firefox 3 Beta 3\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://livesecuritycenter.com/?aid=444.0
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,userinit.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: testCPV6 - {15421B84-3488-49A7-AD18-CBF84A3EFAF6} - C:\Program Files\CPV\CPV8.dll (file missing)
O2 - BHO: (no name) - {15651c7c-e812-44a2-a9ac-b467a2233e7d} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {622cc208-b014-4fe0-801b-874a5e5e403a} - (no file)
O2 - BHO: BatBHO - {63F7460B-C831-4142-A4AA-5EC303EC4343} - C:\Program Files\Bat\Bat.dll (file missing)
O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {9c5b2f29-1f46-4639-a6b4-828942301d3e} - (no file)
O2 - BHO: (no name) - {9DFF5598-EA60-4B59-B566-A94F6FF034CE} - C:\WINDOWS\system32\awvts.dll (file missing)
O2 - BHO: (no name) - {CAFE15D2-8215-8CC6-1592-A28F76267D92} - C:\WINDOWS\system32\pflrka.dll (file missing)
O2 - BHO: (no name) - {db41de82-1dd1-11b2-b7fd-fbaf280c36b9} - C:\WINDOWS\kvazyzst.dll
O2 - BHO: (no name) - {E9383002-FC55-4330-B9C9-67E03BC5C840} - C:\WINDOWS\system32\opnnmkj.dll (file missing)
O2 - BHO: (no name) - {ffff0001-0002-101a-a3c9-08002b2f49fb} - (no file)
O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [hwlypana] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\hwlypana.dll"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\RunOnce: [SpybotDeletingA9220] command /c del "C:\Program Files\Outerinfo\FF\install.rdf"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8374] cmd /c del "C:\Program Files\Outerinfo\FF\install.rdf"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1727] command /c del "C:\Program Files\Outerinfo\FF\components\OuterinfoAds.xpt"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5449] cmd /c del "C:\Program Files\Outerinfo\FF\components\OuterinfoAds.xpt"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5554] command /c del "C:\WINDOWS\odsfkhmd.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2595] cmd /c del "C:\WINDOWS\odsfkhmd.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3703] command /c del "C:\WINDOWS\odsfkhmd.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7545] cmd /c del "C:\WINDOWS\odsfkhmd.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1122] command /c del "C:\WINDOWS\b155.exe_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9251] cmd /c del "C:\WINDOWS\b155.exe_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2745] command /c del "C:\WINDOWS\b156.exe_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4418] cmd /c del "C:\WINDOWS\b156.exe_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4441] command /c del "C:\WINDOWS\b157.exe_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4972] cmd /c del "C:\WINDOWS\b157.exe_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7416] command /c del "C:\WINDOWS\odsfkhmd.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4349] cmd /c del "C:\WINDOWS\odsfkhmd.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9376] command /c del "C:\WINDOWS\system32\geedc.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2746] cmd /c del "C:\WINDOWS\system32\geedc.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5785] command /c del "C:\WINDOWS\system32\jkhhg.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3392] cmd /c del "C:\WINDOWS\system32\jkhhg.dll_old"
O4 - HKCU\..\Run: [Startup Cop Pro Startup Launcher] "C:\Program Files\PC Magazine Utilities\Startup Cop Pro\StartupCopPro.exe" /startup
O4 - HKCU\..\Run: [HijackThis startup scan] C:\Program Files\Trend Micro\HijackThis\HijackThis.exe /startupscan
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB280] command /c del "C:\Program Files\Outerinfo\FF\install.rdf"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3577] cmd /c del "C:\Program Files\Outerinfo\FF\install.rdf"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1954] command /c del "C:\Program Files\Outerinfo\FF\components\OuterinfoAds.xpt"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4946] cmd /c del "C:\Program Files\Outerinfo\FF\components\OuterinfoAds.xpt"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2546] command /c del "C:\WINDOWS\odsfkhmd.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6118] cmd /c del "C:\WINDOWS\odsfkhmd.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9382] command /c del "C:\WINDOWS\odsfkhmd.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8870] cmd /c del "C:\WINDOWS\odsfkhmd.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7771] command /c del "C:\WINDOWS\b155.exe_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5160] cmd /c del "C:\WINDOWS\b155.exe_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7057] command /c del "C:\WINDOWS\b156.exe_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9027] cmd /c del "C:\WINDOWS\b156.exe_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9643] command /c del "C:\WINDOWS\b157.exe_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7824] cmd /c del "C:\WINDOWS\b157.exe_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7083] command /c del "C:\WINDOWS\odsfkhmd.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2443] cmd /c del "C:\WINDOWS\odsfkhmd.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8525] command /c del "C:\WINDOWS\system32\geedc.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2739] cmd /c del "C:\WINDOWS\system32\geedc.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9512] command /c del "C:\WINDOWS\system32\jkhhg.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2061] cmd /c del "C:\WINDOWS\system32\jkhhg.dll_old"
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O20 - AppInit_DLLs: WIKI.DLL
O20 - Winlogon Notify: opnnmkj - opnnmkj.dll (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: MIMO XR TM PCI Adapter WLService (MIMO XR TM PCI WLService) - Unknown owner - C:\Program Files\Airlink101\AWLH5026\WLService.exe
O23 - Service: MSSysInterv (MSSysInterv1) - Unknown owner - C:\WINDOWS\winself.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - D:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 10508 bytes
[/QUOTE]