quacker1uk
New member
Hi. I seem to have an issue where spybot S&D deletes the Malware win32.TDSS.rtk but on reboot and rescan the Malware reappears. I have run ERUNT registry backup tool as requested and deactivated the Spybot TeaTimer. The Hijack This log file follows this.
Any help would be appreciated.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:12:06, on 18/08/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\HP Share-to-Web\hpgs2wnd.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\HP\Digital Imaging\Bin\hpqSTE08.exe
C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Nokia\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\Nokia\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sky.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sky.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer Provided By Sky Broadband
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\HP\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Nokia FastStart] "C:\Program Files\Nokia\Nokia Music\NokiaMusic.exe" /command:faststart
O4 - HKLM\..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [CONNECTScheduler] "C:\Program Files\Sony\CONNECTAutoUpdate\CONNECTScheduler.exe" /RUN_SCHEDULER
O4 - HKLM\..\RunOnce: [SpybotDeletingA122] command.com /c del "C:\WINDOWS\system32\drivers\SKYNETtelnqlld.sys_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8876] cmd.exe /c del "C:\WINDOWS\system32\drivers\SKYNETtelnqlld.sys_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4805] command.com /c del "C:\WINDOWS\system32\drivers\SKYNETtelnqlld.sys"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2807] cmd.exe /c del "C:\WINDOWS\system32\drivers\SKYNETtelnqlld.sys"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2797] command.com /c del "C:\WINDOWS\system32\SKYNETwyikmpme.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8706] cmd.exe /c del "C:\WINDOWS\system32\SKYNETwyikmpme.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2268] command.com /c del "C:\WINDOWS\system32\SKYNETwyikmpme.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2571] cmd.exe /c del "C:\WINDOWS\system32\SKYNETwyikmpme.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7843] command.com /c del "C:\WINDOWS\system32\SKYNETydkuooqx.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9221] cmd.exe /c del "C:\WINDOWS\system32\SKYNETydkuooqx.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5062] command.com /c del "C:\WINDOWS\system32\SKYNETydkuooqx.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9387] cmd.exe /c del "C:\WINDOWS\system32\SKYNETydkuooqx.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2815] command.com /c del "C:\WINDOWS\system32\SKYNETeaephbqu.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8138] cmd.exe /c del "C:\WINDOWS\system32\SKYNETeaephbqu.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3505] command.com /c del "C:\WINDOWS\system32\SKYNETeaephbqu.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6779] cmd.exe /c del "C:\WINDOWS\system32\SKYNETeaephbqu.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingA73] command.com /c del "C:\WINDOWS\system32\SKYNETrnmftitu.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7312] cmd.exe /c del "C:\WINDOWS\system32\SKYNETrnmftitu.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4090] command.com /c del "C:\WINDOWS\system32\SKYNETrnmftitu.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5651] cmd.exe /c del "C:\WINDOWS\system32\SKYNETrnmftitu.dat"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TEST GLUE] C:\DOCUME~1\Monty\APPLIC~1\vcdraw01\WAYEXIT.exe
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Valve\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\RunOnce: [SpybotDeletingB7201] command.com /c del "C:\WINDOWS\system32\drivers\SKYNETtelnqlld.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9781] cmd.exe /c del "C:\WINDOWS\system32\drivers\SKYNETtelnqlld.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8374] command.com /c del "C:\WINDOWS\system32\drivers\SKYNETtelnqlld.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3592] cmd.exe /c del "C:\WINDOWS\system32\drivers\SKYNETtelnqlld.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7038] command.com /c del "C:\WINDOWS\system32\SKYNETwyikmpme.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6324] cmd.exe /c del "C:\WINDOWS\system32\SKYNETwyikmpme.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5482] command.com /c del "C:\WINDOWS\system32\SKYNETwyikmpme.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2308] cmd.exe /c del "C:\WINDOWS\system32\SKYNETwyikmpme.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB779] command.com /c del "C:\WINDOWS\system32\SKYNETydkuooqx.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6753] cmd.exe /c del "C:\WINDOWS\system32\SKYNETydkuooqx.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4717] command.com /c del "C:\WINDOWS\system32\SKYNETydkuooqx.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8708] cmd.exe /c del "C:\WINDOWS\system32\SKYNETydkuooqx.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2544] command.com /c del "C:\WINDOWS\system32\SKYNETeaephbqu.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4649] cmd.exe /c del "C:\WINDOWS\system32\SKYNETeaephbqu.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3401] command.com /c del "C:\WINDOWS\system32\SKYNETeaephbqu.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3710] cmd.exe /c del "C:\WINDOWS\system32\SKYNETeaephbqu.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3252] command.com /c del "C:\WINDOWS\system32\SKYNETrnmftitu.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8817] cmd.exe /c del "C:\WINDOWS\system32\SKYNETrnmftitu.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8891] command.com /c del "C:\WINDOWS\system32\SKYNETrnmftitu.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8089] cmd.exe /c del "C:\WINDOWS\system32\SKYNETrnmftitu.dat"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: CONNECTAUTrayApp.lnk = C:\Program Files\Sony\CONNECTAutoUpdate\CONNECTAUTrayApp.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Sky - {08E730A4-FB02-45BD-A900-01E4AD8016F6} - http://www.sky.com (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.celartem.com/en/download/data/djvu_autoinstall/DjVuControl_en_US.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://ebanking.northernbank.co.uk/html/activex/e-Safekey/NB/e-Safekey.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: c:\windows\system32\gebyaxy.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O20 - Winlogon Notify: bithcp - bithcp.dll (file missing)
O20 - Winlogon Notify: fdepusl - fdepusl.dll (file missing)
O20 - Winlogon Notify: lz3252 - lz3252.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 14604 bytes
Any help would be appreciated.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:12:06, on 18/08/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\HP Share-to-Web\hpgs2wnd.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\HP\Digital Imaging\Bin\hpqSTE08.exe
C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Nokia\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\Nokia\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sky.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sky.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer Provided By Sky Broadband
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\HP\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Nokia FastStart] "C:\Program Files\Nokia\Nokia Music\NokiaMusic.exe" /command:faststart
O4 - HKLM\..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [CONNECTScheduler] "C:\Program Files\Sony\CONNECTAutoUpdate\CONNECTScheduler.exe" /RUN_SCHEDULER
O4 - HKLM\..\RunOnce: [SpybotDeletingA122] command.com /c del "C:\WINDOWS\system32\drivers\SKYNETtelnqlld.sys_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8876] cmd.exe /c del "C:\WINDOWS\system32\drivers\SKYNETtelnqlld.sys_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4805] command.com /c del "C:\WINDOWS\system32\drivers\SKYNETtelnqlld.sys"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2807] cmd.exe /c del "C:\WINDOWS\system32\drivers\SKYNETtelnqlld.sys"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2797] command.com /c del "C:\WINDOWS\system32\SKYNETwyikmpme.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8706] cmd.exe /c del "C:\WINDOWS\system32\SKYNETwyikmpme.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2268] command.com /c del "C:\WINDOWS\system32\SKYNETwyikmpme.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2571] cmd.exe /c del "C:\WINDOWS\system32\SKYNETwyikmpme.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7843] command.com /c del "C:\WINDOWS\system32\SKYNETydkuooqx.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9221] cmd.exe /c del "C:\WINDOWS\system32\SKYNETydkuooqx.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5062] command.com /c del "C:\WINDOWS\system32\SKYNETydkuooqx.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9387] cmd.exe /c del "C:\WINDOWS\system32\SKYNETydkuooqx.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2815] command.com /c del "C:\WINDOWS\system32\SKYNETeaephbqu.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8138] cmd.exe /c del "C:\WINDOWS\system32\SKYNETeaephbqu.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3505] command.com /c del "C:\WINDOWS\system32\SKYNETeaephbqu.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6779] cmd.exe /c del "C:\WINDOWS\system32\SKYNETeaephbqu.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingA73] command.com /c del "C:\WINDOWS\system32\SKYNETrnmftitu.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7312] cmd.exe /c del "C:\WINDOWS\system32\SKYNETrnmftitu.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4090] command.com /c del "C:\WINDOWS\system32\SKYNETrnmftitu.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5651] cmd.exe /c del "C:\WINDOWS\system32\SKYNETrnmftitu.dat"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TEST GLUE] C:\DOCUME~1\Monty\APPLIC~1\vcdraw01\WAYEXIT.exe
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Valve\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\RunOnce: [SpybotDeletingB7201] command.com /c del "C:\WINDOWS\system32\drivers\SKYNETtelnqlld.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9781] cmd.exe /c del "C:\WINDOWS\system32\drivers\SKYNETtelnqlld.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8374] command.com /c del "C:\WINDOWS\system32\drivers\SKYNETtelnqlld.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3592] cmd.exe /c del "C:\WINDOWS\system32\drivers\SKYNETtelnqlld.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7038] command.com /c del "C:\WINDOWS\system32\SKYNETwyikmpme.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6324] cmd.exe /c del "C:\WINDOWS\system32\SKYNETwyikmpme.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5482] command.com /c del "C:\WINDOWS\system32\SKYNETwyikmpme.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2308] cmd.exe /c del "C:\WINDOWS\system32\SKYNETwyikmpme.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB779] command.com /c del "C:\WINDOWS\system32\SKYNETydkuooqx.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6753] cmd.exe /c del "C:\WINDOWS\system32\SKYNETydkuooqx.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4717] command.com /c del "C:\WINDOWS\system32\SKYNETydkuooqx.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8708] cmd.exe /c del "C:\WINDOWS\system32\SKYNETydkuooqx.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2544] command.com /c del "C:\WINDOWS\system32\SKYNETeaephbqu.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4649] cmd.exe /c del "C:\WINDOWS\system32\SKYNETeaephbqu.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3401] command.com /c del "C:\WINDOWS\system32\SKYNETeaephbqu.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3710] cmd.exe /c del "C:\WINDOWS\system32\SKYNETeaephbqu.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3252] command.com /c del "C:\WINDOWS\system32\SKYNETrnmftitu.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8817] cmd.exe /c del "C:\WINDOWS\system32\SKYNETrnmftitu.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8891] command.com /c del "C:\WINDOWS\system32\SKYNETrnmftitu.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8089] cmd.exe /c del "C:\WINDOWS\system32\SKYNETrnmftitu.dat"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: CONNECTAUTrayApp.lnk = C:\Program Files\Sony\CONNECTAutoUpdate\CONNECTAUTrayApp.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Sky - {08E730A4-FB02-45BD-A900-01E4AD8016F6} - http://www.sky.com (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.celartem.com/en/download/data/djvu_autoinstall/DjVuControl_en_US.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://ebanking.northernbank.co.uk/html/activex/e-Safekey/NB/e-Safekey.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: c:\windows\system32\gebyaxy.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O20 - Winlogon Notify: bithcp - bithcp.dll (file missing)
O20 - Winlogon Notify: fdepusl - fdepusl.dll (file missing)
O20 - Winlogon Notify: lz3252 - lz3252.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 14604 bytes