heh.. can't help but notice Virtumonde is the title of 80% of the posts of the last while.. guess it must be a fun one.. heres my buddies machines logs that Im workin on.. any help appreciated:
HJT:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:35:39 PM, on 28/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Safe mode
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Owner\Desktop\HiJackThis.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: (no name) - {910A1D50-5CAB-4E14-8DFA-3BDA15FCADF9} - C:\WINDOWS\system32\wvwus.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [FolderView] rundll32.exe "C:\WINDOWS\system32\icmtnmvp.dll",sitypnow
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\RunOnce: [SpybotDeletingA8823] command /c del "C:\WINDOWS\system32\ddcca.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4917] cmd /c del "C:\WINDOWS\system32\ddcca.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9083] command /c del "C:\WINDOWS\system32\awtrs.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7908] cmd /c del "C:\WINDOWS\system32\awtrs.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9187] command /c del "C:\WINDOWS\system32\byvsp.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7075] cmd /c del "C:\WINDOWS\system32\byvsp.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9506] command /c del "C:\WINDOWS\system32\ddcyx.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2080] cmd /c del "C:\WINDOWS\system32\ddcyx.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1453] command /c del "C:\WINDOWS\system32\efcba.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3520] cmd /c del "C:\WINDOWS\system32\efcba.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9398] command /c del "C:\WINDOWS\system32\geecb.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8920] cmd /c del "C:\WINDOWS\system32\geecb.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8120] command /c del "C:\WINDOWS\system32\geefg.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7275] cmd /c del "C:\WINDOWS\system32\geefg.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9551] command /c del "C:\WINDOWS\system32\hgdaa.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7274] cmd /c del "C:\WINDOWS\system32\hgdaa.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2646] command /c del "C:\WINDOWS\system32\hgdcc.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3047] cmd /c del "C:\WINDOWS\system32\hgdcc.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8314] command /c del "C:\WINDOWS\system32\hgdec.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8401] cmd /c del "C:\WINDOWS\system32\hgdec.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4223] command /c del "C:\WINDOWS\system32\iiigh.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC900] cmd /c del "C:\WINDOWS\system32\iiigh.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4014] command /c del "C:\WINDOWS\system32\khhhh.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1324] cmd /c del "C:\WINDOWS\system32\khhhh.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7281] command /c del "C:\WINDOWS\system32\ljjkl.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1979] cmd /c del "C:\WINDOWS\system32\ljjkl.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8207] command /c del "C:\WINDOWS\system32\opnmm.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3375] cmd /c del "C:\WINDOWS\system32\opnmm.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2338] command /c del "C:\WINDOWS\system32\pmklj.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8438] cmd /c del "C:\WINDOWS\system32\pmklj.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1122] command /c del "C:\WINDOWS\system32\qommn.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5532] cmd /c del "C:\WINDOWS\system32\qommn.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6748] command /c del "C:\WINDOWS\system32\sstst.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8567] cmd /c del "C:\WINDOWS\system32\sstst.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4081] command /c del "C:\WINDOWS\system32\tusrq.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8332] cmd /c del "C:\WINDOWS\system32\tusrq.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9514] command /c del "C:\WINDOWS\system32\vtust.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7315] cmd /c del "C:\WINDOWS\system32\vtust.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6023] command /c del "C:\WINDOWS\system32\vtuuv.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC520] cmd /c del "C:\WINDOWS\system32\vtuuv.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1328] command /c del "C:\WINDOWS\system32\xxywx.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5187] cmd /c del "C:\WINDOWS\system32\xxywx.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4518] command /c del "C:\WINDOWS\system32\xxyxx.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9464] cmd /c del "C:\WINDOWS\system32\xxyxx.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4532] command /c del "C:\WINDOWS\system32\yabab.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4289] cmd /c del "C:\WINDOWS\system32\yabab.dll_old"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\RunOnce: [SpybotDeletingB4648] command /c del "C:\WINDOWS\system32\ddcca.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1954] cmd /c del "C:\WINDOWS\system32\ddcca.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1138] command /c del "C:\WINDOWS\system32\awtrs.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7526] cmd /c del "C:\WINDOWS\system32\awtrs.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7727] command /c del "C:\WINDOWS\system32\byvsp.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3919] cmd /c del "C:\WINDOWS\system32\byvsp.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6522] command /c del "C:\WINDOWS\system32\ddcyx.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9178] cmd /c del "C:\WINDOWS\system32\ddcyx.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3585] command /c del "C:\WINDOWS\system32\efcba.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4514] cmd /c del "C:\WINDOWS\system32\efcba.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5729] command /c del "C:\WINDOWS\system32\geecb.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5294] cmd /c del "C:\WINDOWS\system32\geecb.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB469] command /c del "C:\WINDOWS\system32\geefg.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5413] cmd /c del "C:\WINDOWS\system32\geefg.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2193] command /c del "C:\WINDOWS\system32\hgdaa.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4941] cmd /c del "C:\WINDOWS\system32\hgdaa.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1803] command /c del "C:\WINDOWS\system32\hgdcc.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD174] cmd /c del "C:\WINDOWS\system32\hgdcc.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7412] command /c del "C:\WINDOWS\system32\hgdec.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD748] cmd /c del "C:\WINDOWS\system32\hgdec.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4401] command /c del "C:\WINDOWS\system32\iiigh.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7694] cmd /c del "C:\WINDOWS\system32\iiigh.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6935] command /c del "C:\WINDOWS\system32\khhhh.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2983] cmd /c del "C:\WINDOWS\system32\khhhh.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB259] command /c del "C:\WINDOWS\system32\ljjkl.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1842] cmd /c del "C:\WINDOWS\system32\ljjkl.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8239] command /c del "C:\WINDOWS\system32\opnmm.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9913] cmd /c del "C:\WINDOWS\system32\opnmm.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8] command /c del "C:\WINDOWS\system32\pmklj.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7135] cmd /c del "C:\WINDOWS\system32\pmklj.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3349] command /c del "C:\WINDOWS\system32\qommn.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6046] cmd /c del "C:\WINDOWS\system32\qommn.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB31] command /c del "C:\WINDOWS\system32\sstst.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6133] cmd /c del "C:\WINDOWS\system32\sstst.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9977] command /c del "C:\WINDOWS\system32\tusrq.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD733] cmd /c del "C:\WINDOWS\system32\tusrq.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4125] command /c del "C:\WINDOWS\system32\vtust.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6075] cmd /c del "C:\WINDOWS\system32\vtust.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2699] command /c del "C:\WINDOWS\system32\vtuuv.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2229] cmd /c del "C:\WINDOWS\system32\vtuuv.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3265] command /c del "C:\WINDOWS\system32\xxywx.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2841] cmd /c del "C:\WINDOWS\system32\xxywx.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2944] command /c del "C:\WINDOWS\system32\xxyxx.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7317] cmd /c del "C:\WINDOWS\system32\xxyxx.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3641] command /c del "C:\WINDOWS\system32\yabab.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4130] cmd /c del "C:\WINDOWS\system32\yabab.dll_old"
O8 - Extra context menu item: &Search - ?p=zuzed004YYCA_ZZzer000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O18 - Protocol: intu-qt2007 - {026BF40D-BA05-467B-9F1F-AD0D7A3F5F11} - C:\Program Files\QuickTax 2007\ic2007pp.dll
O20 - Winlogon Notify: winqje32 - winqje32.dll (file missing)
O20 - Winlogon Notify: wvwus - C:\WINDOWS\system32\wvwus.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
--
End of file - 13799 bytes
HJT:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:35:39 PM, on 28/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Safe mode
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Owner\Desktop\HiJackThis.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: (no name) - {910A1D50-5CAB-4E14-8DFA-3BDA15FCADF9} - C:\WINDOWS\system32\wvwus.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [FolderView] rundll32.exe "C:\WINDOWS\system32\icmtnmvp.dll",sitypnow
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\RunOnce: [SpybotDeletingA8823] command /c del "C:\WINDOWS\system32\ddcca.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4917] cmd /c del "C:\WINDOWS\system32\ddcca.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9083] command /c del "C:\WINDOWS\system32\awtrs.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7908] cmd /c del "C:\WINDOWS\system32\awtrs.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9187] command /c del "C:\WINDOWS\system32\byvsp.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7075] cmd /c del "C:\WINDOWS\system32\byvsp.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9506] command /c del "C:\WINDOWS\system32\ddcyx.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2080] cmd /c del "C:\WINDOWS\system32\ddcyx.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1453] command /c del "C:\WINDOWS\system32\efcba.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3520] cmd /c del "C:\WINDOWS\system32\efcba.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9398] command /c del "C:\WINDOWS\system32\geecb.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8920] cmd /c del "C:\WINDOWS\system32\geecb.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8120] command /c del "C:\WINDOWS\system32\geefg.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7275] cmd /c del "C:\WINDOWS\system32\geefg.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9551] command /c del "C:\WINDOWS\system32\hgdaa.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7274] cmd /c del "C:\WINDOWS\system32\hgdaa.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2646] command /c del "C:\WINDOWS\system32\hgdcc.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3047] cmd /c del "C:\WINDOWS\system32\hgdcc.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8314] command /c del "C:\WINDOWS\system32\hgdec.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8401] cmd /c del "C:\WINDOWS\system32\hgdec.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4223] command /c del "C:\WINDOWS\system32\iiigh.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC900] cmd /c del "C:\WINDOWS\system32\iiigh.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4014] command /c del "C:\WINDOWS\system32\khhhh.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1324] cmd /c del "C:\WINDOWS\system32\khhhh.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7281] command /c del "C:\WINDOWS\system32\ljjkl.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1979] cmd /c del "C:\WINDOWS\system32\ljjkl.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8207] command /c del "C:\WINDOWS\system32\opnmm.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3375] cmd /c del "C:\WINDOWS\system32\opnmm.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2338] command /c del "C:\WINDOWS\system32\pmklj.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8438] cmd /c del "C:\WINDOWS\system32\pmklj.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1122] command /c del "C:\WINDOWS\system32\qommn.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5532] cmd /c del "C:\WINDOWS\system32\qommn.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6748] command /c del "C:\WINDOWS\system32\sstst.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8567] cmd /c del "C:\WINDOWS\system32\sstst.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4081] command /c del "C:\WINDOWS\system32\tusrq.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8332] cmd /c del "C:\WINDOWS\system32\tusrq.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9514] command /c del "C:\WINDOWS\system32\vtust.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7315] cmd /c del "C:\WINDOWS\system32\vtust.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6023] command /c del "C:\WINDOWS\system32\vtuuv.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC520] cmd /c del "C:\WINDOWS\system32\vtuuv.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1328] command /c del "C:\WINDOWS\system32\xxywx.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5187] cmd /c del "C:\WINDOWS\system32\xxywx.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4518] command /c del "C:\WINDOWS\system32\xxyxx.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9464] cmd /c del "C:\WINDOWS\system32\xxyxx.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4532] command /c del "C:\WINDOWS\system32\yabab.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4289] cmd /c del "C:\WINDOWS\system32\yabab.dll_old"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\RunOnce: [SpybotDeletingB4648] command /c del "C:\WINDOWS\system32\ddcca.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1954] cmd /c del "C:\WINDOWS\system32\ddcca.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1138] command /c del "C:\WINDOWS\system32\awtrs.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7526] cmd /c del "C:\WINDOWS\system32\awtrs.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7727] command /c del "C:\WINDOWS\system32\byvsp.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3919] cmd /c del "C:\WINDOWS\system32\byvsp.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6522] command /c del "C:\WINDOWS\system32\ddcyx.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9178] cmd /c del "C:\WINDOWS\system32\ddcyx.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3585] command /c del "C:\WINDOWS\system32\efcba.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4514] cmd /c del "C:\WINDOWS\system32\efcba.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5729] command /c del "C:\WINDOWS\system32\geecb.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5294] cmd /c del "C:\WINDOWS\system32\geecb.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB469] command /c del "C:\WINDOWS\system32\geefg.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5413] cmd /c del "C:\WINDOWS\system32\geefg.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2193] command /c del "C:\WINDOWS\system32\hgdaa.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4941] cmd /c del "C:\WINDOWS\system32\hgdaa.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1803] command /c del "C:\WINDOWS\system32\hgdcc.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD174] cmd /c del "C:\WINDOWS\system32\hgdcc.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7412] command /c del "C:\WINDOWS\system32\hgdec.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD748] cmd /c del "C:\WINDOWS\system32\hgdec.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4401] command /c del "C:\WINDOWS\system32\iiigh.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7694] cmd /c del "C:\WINDOWS\system32\iiigh.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6935] command /c del "C:\WINDOWS\system32\khhhh.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2983] cmd /c del "C:\WINDOWS\system32\khhhh.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB259] command /c del "C:\WINDOWS\system32\ljjkl.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1842] cmd /c del "C:\WINDOWS\system32\ljjkl.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8239] command /c del "C:\WINDOWS\system32\opnmm.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9913] cmd /c del "C:\WINDOWS\system32\opnmm.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8] command /c del "C:\WINDOWS\system32\pmklj.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7135] cmd /c del "C:\WINDOWS\system32\pmklj.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3349] command /c del "C:\WINDOWS\system32\qommn.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6046] cmd /c del "C:\WINDOWS\system32\qommn.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB31] command /c del "C:\WINDOWS\system32\sstst.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6133] cmd /c del "C:\WINDOWS\system32\sstst.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9977] command /c del "C:\WINDOWS\system32\tusrq.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD733] cmd /c del "C:\WINDOWS\system32\tusrq.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4125] command /c del "C:\WINDOWS\system32\vtust.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6075] cmd /c del "C:\WINDOWS\system32\vtust.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2699] command /c del "C:\WINDOWS\system32\vtuuv.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2229] cmd /c del "C:\WINDOWS\system32\vtuuv.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3265] command /c del "C:\WINDOWS\system32\xxywx.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2841] cmd /c del "C:\WINDOWS\system32\xxywx.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2944] command /c del "C:\WINDOWS\system32\xxyxx.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7317] cmd /c del "C:\WINDOWS\system32\xxyxx.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3641] command /c del "C:\WINDOWS\system32\yabab.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4130] cmd /c del "C:\WINDOWS\system32\yabab.dll_old"
O8 - Extra context menu item: &Search - ?p=zuzed004YYCA_ZZzer000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O18 - Protocol: intu-qt2007 - {026BF40D-BA05-467B-9F1F-AD0D7A3F5F11} - C:\Program Files\QuickTax 2007\ic2007pp.dll
O20 - Winlogon Notify: winqje32 - winqje32.dll (file missing)
O20 - Winlogon Notify: wvwus - C:\WINDOWS\system32\wvwus.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
--
End of file - 13799 bytes