Hi
When I start up my PC and periodically whilst using I get following message:
dll c:\windows\system32\xlibgfl254.dll is not a valid windows image
Am trying to track down what problem is and what I need to do.
Have run the HijackThis programme and results are pasted below. ANy assistance appreicated.
Logfile of HijackThis v1.99.1
Scan saved at 21:21:51, on 14/03/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Boots F2CD\Picture Suite\InsDetect.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\CASIO\Photo Loader\Plauto.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\QAPF0ZFM\HijackThis[1].exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=Q304&bd=presario&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_GB&c=Q304&bd=presario&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_GB&c=Q304&bd=presario&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=Q304&bd=presario&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Wanadoo
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Wanadoo - {8B68564D-53FD-4293-B80C-993A9F3988EE} - C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [UpdateManager] "c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [pdfFactory Dispatcher v2] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe" /source=HKLM
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Acme.PCHButton] C:\PROGRA~1\PRESAR~1\Presario\XPHWWRS4\plugin\bin\PCHButton.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Boots Insert Detect] C:\Program Files\Boots F2CD\Picture Suite\InsDetect.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Photo Loader supervisory.lnk = C:\Program Files\CASIO\Photo Loader\Plauto.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Search with Wanadoo - res://C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll/VSearch.htm
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk
O16 - DPF: {01976EE2-7C9F-2CC4-55E4-344B1B1ABE50} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {06F8E4D5-DC28-2F32-8C64-0DBB66F87155} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {088A0511-4897-44B1-E7A8-5BD610C7FC8B} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {0A2F8A7D-BB0C-1886-1685-433952D03A70} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {0A96B27F-CD12-4B3E-4960-14A15E971C86} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {0ACA9BE8-4F17-34E1-2E1F-1CC566D3A329} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {0AFC22D7-4B69-65B2-D2B5-06BB06D16306} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {0D4E55BE-782D-5951-C7A5-47D853B59468} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {0D7F4FA5-E964-1F12-CA07-449660C67489} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {0E66CABC-18F9-3159-68C9-18884D3DCBE2} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {0F06D3E1-A50B-4B40-C190-379654350022} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {1072E697-0ED2-7F5A-47C5-77371ECB147B} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab
O16 - DPF: {112A675F-AEBF-4971-4382-736B0DBED062} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {11CFF714-1102-6421-038D-2120295656B1} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {1495C8BE-7B33-7EB5-693F-0EEE7BEC2C37} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {1BC6BC18-479F-70FB-EC78-705C01E2EEC5} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {1CDD1F72-398C-109C-EBEA-566A2B303B25} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {1D6D0392-2C57-19CF-0098-2C4A6B4591B9} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {20539B0E-D13C-3482-921C-3AC91F7E6D88} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {215B53CE-9C86-4661-54DF-5BE268D4BFC5} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {2276B1B1-76F7-3BD4-04BC-74E80B750481} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {26CB39D3-22FA-4D07-5DD2-6F1B7C81D8F1} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {285F5676-C010-7D53-C022-6F7F3B08CDA3} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {2A054644-BFB4-07C8-7C7C-23060851B76A} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {2A5ED700-2AF9-0B68-5763-01D03F29FAE3} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {2A78840F-8A6C-270C-4518-1B3E0334E463} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {2A8D8E4E-E1C0-6504-23FB-0644661B826E} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {33EEE2D6-0972-0CE5-1D13-32584C8C1EF8} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {3A904190-6AF7-3FE8-6B0E-13797DDD35CC} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {3CD304FB-0408-2959-3051-267027F264EC} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {42ADC740-207F-4C49-5F71-56F040CCD8FC} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {4656BBF9-579A-4EC7-5C2C-38131151283D} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {46861960-D88A-5F01-5A50-35C41FF8B4AB} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {46B96D65-266F-50EF-7D66-4D3D104F9AB9} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {47F936E6-6B6C-78F2-8E2C-1D5D4F52C3B6} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {484EE1C5-7CB1-258F-9014-10415F3E3EC8} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {49109AC7-6069-3008-4DF5-1F130DBCFB9E} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {4CDB7FC6-BCA7-7645-DA95-75326B18CBAC} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {4FEADD0A-06DD-3032-B97D-0AAC026D77C2} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {502AA470-9B77-2CAE-A453-1FF14E7CBBFB} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {51C8BFB9-9048-66E7-4040-4693365B49E3} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {5222F112-2E96-11CD-1E73-16C35232B5D0} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {52B103E5-6754-1657-F6E4-29234BF95679} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {534FEDF9-8D9C-282B-20F4-16B64BAE3A57} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {54071FE3-D806-6055-0EE3-21EA6DC645D1} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {542BD7F3-29DC-620A-D7C3-128755915AB5} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {551A902C-081C-2899-05C8-1DF31B86558C} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/270a23149772fc851119/netzip/RdxIE601.cab
O16 - DPF: {585A32A1-D066-07FC-080C-6AE70A77E0D3} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {5879530B-BDEE-19B2-BE5B-203B4157E519} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {5A49D7EC-1264-675A-F846-0C7F587356EB} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {5BC7B2E8-4AD6-79DF-1078-08E275800B27} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {5F4E41DF-8F3A-5C99-7B9C-5A1F23864202} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {5F6F0560-EECA-5392-1B69-00335BEF0C2C} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {5FD45F8A-E3FB-01C5-CF10-397B7A048242} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {60CB6105-41B4-170A-EACC-313A5A83A4DA} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {62418869-3778-05BF-DFA4-79A5693485B6} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {6304B21E-060F-60BF-7FFA-622B03720432} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {6351FDA7-FA91-6A9F-B286-682109D5B6C0} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6B8DB26E-8E31-04BC-FD1A-279E403A4754} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {6D51DDE9-638D-169F-6537-64A054C69391} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {6EC093F3-DD6D-1F4D-064F-1B0521F6D277} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {7045B8FC-F0D7-5EDA-4A61-6D412C57DDED} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {7150893D-FEA1-5992-F76F-59035C090741} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {721D741A-65CA-5E1F-16EB-772F5597151B} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {7454D969-EDDD-7A0F-A1AE-180522B552B4} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {750503E7-6DAD-5044-CBBC-3977546CBDCE} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {764AB092-DBB7-111C-4117-605021875D72} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {76E9CDB1-B4F0-414E-42E4-462A363F631B} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {79212E19-2EC1-5799-565A-150A0B5A69FE} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {799350A3-5EC1-44F3-9979-7CC843C7A0AB} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {7A23D3B6-D6F4-3180-34D0-23B652BFFD85} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {7AD304EB-61B2-2C69-5C44-745D16F63E7F} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {7CF28E23-11B9-35B5-EA1D-292636147EEE} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {7DB670B4-B7FD-5318-BD6C-748403E418E4} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {7E073613-CA1A-79C5-6098-75A7695693FB} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {7EAC6876-13C4-43EA-92CE-330F6677D7E9} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://help.broadbandassist.com/prequal/MotivePreQual.cab
O16 - DPF: {FF3F0F03-0F01-131A-A3F9-08F02B23E0CC} - http://66.117.37.13/dba1402.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{19DBB19E-EDF7-40BF-87F3-935057CB8702}: NameServer = 195.92.195.95 195.92.195.94
O17 - HKLM\System\CS1\Services\Tcpip\..\{19DBB19E-EDF7-40BF-87F3-935057CB8702}: NameServer = 195.92.195.95 195.92.195.94
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
When I start up my PC and periodically whilst using I get following message:
dll c:\windows\system32\xlibgfl254.dll is not a valid windows image
Am trying to track down what problem is and what I need to do.
Have run the HijackThis programme and results are pasted below. ANy assistance appreicated.
Logfile of HijackThis v1.99.1
Scan saved at 21:21:51, on 14/03/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Boots F2CD\Picture Suite\InsDetect.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\CASIO\Photo Loader\Plauto.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\QAPF0ZFM\HijackThis[1].exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=Q304&bd=presario&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_GB&c=Q304&bd=presario&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_GB&c=Q304&bd=presario&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=Q304&bd=presario&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Wanadoo
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Wanadoo - {8B68564D-53FD-4293-B80C-993A9F3988EE} - C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [UpdateManager] "c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [pdfFactory Dispatcher v2] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe" /source=HKLM
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Acme.PCHButton] C:\PROGRA~1\PRESAR~1\Presario\XPHWWRS4\plugin\bin\PCHButton.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Boots Insert Detect] C:\Program Files\Boots F2CD\Picture Suite\InsDetect.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Photo Loader supervisory.lnk = C:\Program Files\CASIO\Photo Loader\Plauto.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Search with Wanadoo - res://C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll/VSearch.htm
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk
O16 - DPF: {01976EE2-7C9F-2CC4-55E4-344B1B1ABE50} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {06F8E4D5-DC28-2F32-8C64-0DBB66F87155} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {088A0511-4897-44B1-E7A8-5BD610C7FC8B} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {0A2F8A7D-BB0C-1886-1685-433952D03A70} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {0A96B27F-CD12-4B3E-4960-14A15E971C86} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {0ACA9BE8-4F17-34E1-2E1F-1CC566D3A329} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {0AFC22D7-4B69-65B2-D2B5-06BB06D16306} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {0D4E55BE-782D-5951-C7A5-47D853B59468} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {0D7F4FA5-E964-1F12-CA07-449660C67489} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {0E66CABC-18F9-3159-68C9-18884D3DCBE2} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {0F06D3E1-A50B-4B40-C190-379654350022} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {1072E697-0ED2-7F5A-47C5-77371ECB147B} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab
O16 - DPF: {112A675F-AEBF-4971-4382-736B0DBED062} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {11CFF714-1102-6421-038D-2120295656B1} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {1495C8BE-7B33-7EB5-693F-0EEE7BEC2C37} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {1BC6BC18-479F-70FB-EC78-705C01E2EEC5} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {1CDD1F72-398C-109C-EBEA-566A2B303B25} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {1D6D0392-2C57-19CF-0098-2C4A6B4591B9} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {20539B0E-D13C-3482-921C-3AC91F7E6D88} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {215B53CE-9C86-4661-54DF-5BE268D4BFC5} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {2276B1B1-76F7-3BD4-04BC-74E80B750481} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {26CB39D3-22FA-4D07-5DD2-6F1B7C81D8F1} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {285F5676-C010-7D53-C022-6F7F3B08CDA3} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {2A054644-BFB4-07C8-7C7C-23060851B76A} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {2A5ED700-2AF9-0B68-5763-01D03F29FAE3} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {2A78840F-8A6C-270C-4518-1B3E0334E463} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {2A8D8E4E-E1C0-6504-23FB-0644661B826E} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {33EEE2D6-0972-0CE5-1D13-32584C8C1EF8} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {3A904190-6AF7-3FE8-6B0E-13797DDD35CC} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {3CD304FB-0408-2959-3051-267027F264EC} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {42ADC740-207F-4C49-5F71-56F040CCD8FC} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {4656BBF9-579A-4EC7-5C2C-38131151283D} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {46861960-D88A-5F01-5A50-35C41FF8B4AB} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {46B96D65-266F-50EF-7D66-4D3D104F9AB9} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {47F936E6-6B6C-78F2-8E2C-1D5D4F52C3B6} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {484EE1C5-7CB1-258F-9014-10415F3E3EC8} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {49109AC7-6069-3008-4DF5-1F130DBCFB9E} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {4CDB7FC6-BCA7-7645-DA95-75326B18CBAC} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {4FEADD0A-06DD-3032-B97D-0AAC026D77C2} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {502AA470-9B77-2CAE-A453-1FF14E7CBBFB} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {51C8BFB9-9048-66E7-4040-4693365B49E3} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {5222F112-2E96-11CD-1E73-16C35232B5D0} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {52B103E5-6754-1657-F6E4-29234BF95679} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {534FEDF9-8D9C-282B-20F4-16B64BAE3A57} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {54071FE3-D806-6055-0EE3-21EA6DC645D1} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {542BD7F3-29DC-620A-D7C3-128755915AB5} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {551A902C-081C-2899-05C8-1DF31B86558C} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/270a23149772fc851119/netzip/RdxIE601.cab
O16 - DPF: {585A32A1-D066-07FC-080C-6AE70A77E0D3} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {5879530B-BDEE-19B2-BE5B-203B4157E519} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {5A49D7EC-1264-675A-F846-0C7F587356EB} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {5BC7B2E8-4AD6-79DF-1078-08E275800B27} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {5F4E41DF-8F3A-5C99-7B9C-5A1F23864202} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {5F6F0560-EECA-5392-1B69-00335BEF0C2C} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {5FD45F8A-E3FB-01C5-CF10-397B7A048242} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {60CB6105-41B4-170A-EACC-313A5A83A4DA} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {62418869-3778-05BF-DFA4-79A5693485B6} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {6304B21E-060F-60BF-7FFA-622B03720432} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {6351FDA7-FA91-6A9F-B286-682109D5B6C0} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6B8DB26E-8E31-04BC-FD1A-279E403A4754} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {6D51DDE9-638D-169F-6537-64A054C69391} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {6EC093F3-DD6D-1F4D-064F-1B0521F6D277} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {7045B8FC-F0D7-5EDA-4A61-6D412C57DDED} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {7150893D-FEA1-5992-F76F-59035C090741} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {721D741A-65CA-5E1F-16EB-772F5597151B} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {7454D969-EDDD-7A0F-A1AE-180522B552B4} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {750503E7-6DAD-5044-CBBC-3977546CBDCE} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {764AB092-DBB7-111C-4117-605021875D72} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {76E9CDB1-B4F0-414E-42E4-462A363F631B} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {79212E19-2EC1-5799-565A-150A0B5A69FE} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {799350A3-5EC1-44F3-9979-7CC843C7A0AB} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {7A23D3B6-D6F4-3180-34D0-23B652BFFD85} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {7AD304EB-61B2-2C69-5C44-745D16F63E7F} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {7CF28E23-11B9-35B5-EA1D-292636147EEE} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {7DB670B4-B7FD-5318-BD6C-748403E418E4} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {7E073613-CA1A-79C5-6098-75A7695693FB} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {7EAC6876-13C4-43EA-92CE-330F6677D7E9} - http://85.255.115.229/1/gdnFR1402.exe
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://help.broadbandassist.com/prequal/MotivePreQual.cab
O16 - DPF: {FF3F0F03-0F01-131A-A3F9-08F02B23E0CC} - http://66.117.37.13/dba1402.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{19DBB19E-EDF7-40BF-87F3-935057CB8702}: NameServer = 195.92.195.95 195.92.195.94
O17 - HKLM\System\CS1\Services\Tcpip\..\{19DBB19E-EDF7-40BF-87F3-935057CB8702}: NameServer = 195.92.195.95 195.92.195.94
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe