KevinWingrave
New member
Hi people,
Approximately a week ago my desktop has been behaving strangely.
It was receving 2 types of errors:
1) userinit.exe - the application failed to initialise properly (0xC0000005).....
2) rundll32.exe - the application failed to initialise properly (0xC0000005).....
3) many applications won't work
Now when I bootup and enter the user logon password I get the rundll32.exe error repeatedly and when I close the message box the screen is blank and I can't do anything, no sesssion icons at all. I can only go into TaskMgr and start a "explorer" session and that gets me going but then throughout I keep getting the rundll32.exe errors.
I updated and run Spybot and Adaware to latest levels and my McAfees is up to date. Spybot found problems with:
Virtumonde.dll
Virtumonde
Win32.BHO.df
Could not run HijackThis got the 0xc0000005 error.
Have followed as many of the instructions provided on this forum but am unable to run some of the programs suggested.---------------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Saturday, May 31, 2008 10:38:47 PM
Operating System: Microsoft Windows XP Professional, Service Pack 3 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 31/05/2008
Kaspersky Anti-Virus database records: 818004
---------------------------------------------------------------------------------------
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target Critical Areas
C:\WINDOWS
C:\DOCUME~1\KEVINW~1\LOCALS~1\Temp\
Scan Statistics
Total number of scanned objects 22972
Number of viruses found 2
Number of infected objects 2
Number of suspicious objects 0
Duration of the scan process 00:16:33
Infected Object Name Virus Name Last Action
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\khaivyjx.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.vqh skipped
C:\WINDOWS\system32\loipvlby.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.vqd skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\mcafee_upEstkXhFbKMWQq Object is locked skipped
C:\WINDOWS\Temp\mcmsc_JpvVJFYcCG0csoU Object is locked skipped
C:\WINDOWS\Temp\mcmsc_kU2OEa5n2hvB2WW Object is locked skipped
C:\WINDOWS\Temp\mcmsc_MV3YP3PPMuRmgfN Object is locked skipped
C:\WINDOWS\Temp\mcmsc_oPd4Jec335Sdb8Y Object is locked skipped
C:\WINDOWS\Temp\mcmsc_u7dADNafkXrHrU9 Object is locked skipped
C:\WINDOWS\Temp\sqlite_bGDOAeeZYks8zdw Object is locked skipped
C:\WINDOWS\Temp\sqlite_ek4kotUI4R1ahOI Object is locked skipped
C:\WINDOWS\Temp\sqlite_hvYYNf288vpmfVr Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\{00000005-00000000-00000004-00001102-00000004-20061102}.CDF Object is locked skipped
C:\DOCUME~1\KEVINW~1\LOCALS~1\Temp\sqlite_dhvrKjUMJJhMvJj Object is locked skipped
C:\DOCUME~1\KEVINW~1\LOCALS~1\Temp\~DF2D5A.tmp Object is locked skipped
C:\DOCUME~1\KEVINW~1\LOCALS~1\Temp\~DFCA50.tmp Object is locked skipped
C:\DOCUME~1\KEVINW~1\LOCALS~1\Temp\~DFCA6B.tmp Object is locked skipped
Scan process completed.
---------------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Sunday, June 01, 2008 10:49:05 AM
Operating System: Microsoft Windows XP Professional, Service Pack 3 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 31/05/2008
Kaspersky Anti-Virus database records: 819344
---------------------------------------------------------------------------------------
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target Folders
C:\_OTMoveIt\
C:\327882R2FWJFW\
C:\cmdcons\
C:\Deckard\
C:\DELL\
C:\Dell942\
C:\drvrtmp\
C:\KPCMS\
C:\Program Files\
C:\RECYCLER\
C:\spoolerlogs\
C:\System Volume Information\
C:\Temp\
C:\Webshots\
Scan Statistics
Total number of scanned objects 84588
Number of viruses found 4
Number of infected objects 7
Number of suspicious objects 0
Duration of the scan process 01:05:16
Infected Object Name Virus Name Last Action
C:\_OTMoveIt\MovedFiles\05302008_203653\WINDOWS\system32\awtsSjGa.dll_old Infected: Trojan.Win32.Pakes.cym skipped
C:\_OTMoveIt\MovedFiles\05302008_203653\WINDOWS\system32\byXRhFXP.dll Infected: Trojan-Downloader.Win32.Agent.qsk skipped
C:\_OTMoveIt\MovedFiles\05302008_203653\WINDOWS\system32\urqRLdCT.dll Infected: Trojan-Downloader.Win32.Agent.qsk skipped
C:\Program Files\Nero\Nero8\Nero BackItUp\BIU1.txt Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{EFA8AF3D-9D4F-49AD-91A1-D11B95972509}\RP214\A0031876.dll Infected: Trojan.Win32.Pakes.cym skipped
C:\System Volume Information\_restore{EFA8AF3D-9D4F-49AD-91A1-D11B95972509}\RP216\A0033257.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.tsk skipped
C:\System Volume Information\_restore{EFA8AF3D-9D4F-49AD-91A1-D11B95972509}\RP216\A0033302.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.trp skipped
C:\System Volume Information\_restore{EFA8AF3D-9D4F-49AD-91A1-D11B95972509}\RP217\A0033614.dll Infected: Trojan.Win32.Pakes.cym skipped
C:\System Volume Information\_restore{EFA8AF3D-9D4F-49AD-91A1-D11B95972509}\RP220\change.log Object is locked skipped
Scan process completed.
KASPERSKY ONLINE SCANNER REPORT
Sunday, June 01, 2008 11:43:59 AM
Operating System: Microsoft Windows XP Professional, Service Pack 3 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 31/05/2008
Kaspersky Anti-Virus database records: 819344
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target Folders
D:\
E:\
Scan Statistics
Total number of scanned objects 24422
Number of viruses found 7
Number of infected objects 15
Number of suspicious objects 0
Duration of the scan process 00:53:41
Infected Object Name Virus Name Last Action
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
D:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP841\A0042463.exe/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
D:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP841\A0042463.exe 7-Zip: infected - 1 skipped
D:\System Volume Information\_restore{EFA8AF3D-9D4F-49AD-91A1-D11B95972509}\RP220\change.log Object is locked skipped
E:\Download Patches and updates\Adobe\Adobe PageMaker v7.0.1.zip/crack.exe Infected: Trojan-Downloader.Win32.IstBar.is skipped
E:\Download Patches and updates\Adobe\Adobe PageMaker v7.0.1.zip ZIP: infected - 1 skipped
E:\Download Patches and updates\Hackers Toolkit.rar/HTS_part1/appz/Golden eye 2005/gesetup.exe/file01 Infected: not-a-virus:Monitor.Win32.GoldenEye.401 skipped
E:\Download Patches and updates\Hackers Toolkit.rar/HTS_part1/appz/Golden eye 2005/gesetup.exe/file23 Infected: Trojan.Win32.Hooker.j skipped
E:\Download Patches and updates\Hackers Toolkit.rar/HTS_part1/appz/Golden eye 2005/gesetup.exe/file24 Infected: Trojan-Spy.Win32.SpyAnyTime.a skipped
E:\Download Patches and updates\Hackers Toolkit.rar/HTS_part1/appz/Golden eye 2005/gesetup.exe Infected: Trojan-Spy.Win32.SpyAnyTime.a skipped
E:\Download Patches and updates\Hackers Toolkit.rar RAR: infected - 4 skipped
E:\Download Patches and updates\Nero\Nero-8.2.8.0_eng_update.exe/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
E:\Download Patches and updates\Nero\Nero-8.2.8.0_eng_update.exe 7-Zip: infected - 1 skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
E:\System Volume Information\_restore{EFA8AF3D-9D4F-49AD-91A1-D11B95972509}\RP220\change.log Object is locked skipped
E:\Videos\AVI's\Applications.zip/california.exe Infected: not-virus:BadJoke.Win16.Aloap skipped
E:\Videos\AVI's\Applications.zip/ATT1.EXE Infected: not-virus:BadJoke.Win16.Stupid.a skipped
E:\Videos\AVI's\Applications.zip/SMALL.EXE Infected: not-virus:BadJoke.Win16.Stupid.a skipped
E:\Videos\AVI's\Applications.zip ZIP: infected - 3 skipped
Scan process completed.
----------------------------------------------------------------------------------------------
Had to run multiple times because Internet Explorer likes to crash often.
Could not run HiJackThis directly but could run it from DSS as shown below-----------------------------------------------------------------------------------------------
Deckard's System Scanner v20071014.68
Run by Kevin Wingrave on 2008-06-01 10:56:04
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- HijackThis (run as Kevin Wingrave.exe) --------------------------------------
Unable to find log (file not found); running clone.
-- HijackThis Clone ------------------------------------------------------------
Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-06-01 10:59:33
Platform: Windows XP Service Pack 3 (5.01.2600)
MSIE: Internet Explorer (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTSVCCDA.EXE
C:\WINDOWS\system32\dlbucoms.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Nero\Nero8\InCD\InCDsrv.exe
C:\Program Files\Common Files\logishrd\LVCOMSER\LVComSer.exe
C:\Program Files\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
C:\Program Files\Common Files\McAfee\McProxy\McProxy.exe
C:\Program Files\McAfee\VirusScan\Mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MpfSrv.exe
C:\Program Files\McAfee\MSK\msksrver.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\Nero\Nero8\InCD\NBHRegInCDSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\Program Files\Registry Defragmentation\RegManServ.exe
C:\Program Files\SiteAdvisor\6261\SAService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Common Files\logishrd\LVCOMSER\LVComSer.exe
C:\Program Files\McAfee\VirusScan\mcsysmon.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\logishrd\LComMgr\Communications_Helper.exe
C:\Program Files\Nero\Nero8\InCD\NBHGui.exe
C:\Program Files\Nero\Nero8\InCD\InCD.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Documents and Settings\Kevin Wingrave\Desktop\dss.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ninemsn.com.au/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.ninemsn.com.au/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O2 - BHO: StumbleUpon Launcher - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O2 - BHO: AddTask Class - {24F06550-65E3-4D1C-8CFE-839C296B5530} - C:\Program Files\Real\IEeREAD.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {323DB43C-424C-4309-909E-3BEDE995D91E} - C:\WINDOWS\system32\awtsSjGa.dll (file missing)
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - C:\Program Files\McAfee\MSK\mcapbho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: AddTask Class - {6A19C29D-ED45-4483-8999-9F939C8161F2} - C:\Program Files\Real\WebHook.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\GoogleToolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\GoogleToolbar1.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe /inspect
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Dell Photo AIO Printer 942] "C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe"
O4 - HKLM\..\Run: [DellMCM] "C:\Program Files\Dell Photo AIO Printer 942\memcard.exe"
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero8\InCD\NBHGui.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero8\InCD\InCD.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6261\SiteAdv.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Dell PC Fax\fm3032.exe" /s
O4 - HKLM\..\Run: [DLBUCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBUtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlbumon.exe] "C:\Program Files\Dell Photo AIO Printer 942\dlbumon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 942\memcard.exe"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = ?
O4 - Global Startup: NETGEAR WG311T Wireless Assistant.lnk = C:\Program Files\NETGEAR\WG311T\wlancfg5.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.microsoft.com (HKCU)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://download.microsoft.com/download/e/7/3/e7345c16-80aa-4488-ae10-9ac6be844f99/OGAControl.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase9563.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1209472499999
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc4.cab
O18 - Protocol: bw+0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL
O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL
O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL
O18 - Protocol: offline-8876480 - {08B78CAD-CD39-4558-8665-B5765DC70D0F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\__c004AA10.dat
O23 - Service: McAfee Application Installer Cleanup (0128551212245013) (0128551212245013mcinstcleanup) - McAfee, Inc. - C:\WINDOWS\Temp\0128551212245013mcinst.exe
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTSVCCDA.EXE
O23 - Service: dlbu_device - Unknown owner - C:\WINDOWS\system32\dlbucoms.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero8\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\logishrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\logishrd\SrvLnch\SrvLnch.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McProxy\McProxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\Mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MpfSrv.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\msksrver.exe
O23 - Service: Nero BackItUp Scheduler 3 - Unknown owner - C:\Program Files\Nero\Nero8\Nero
O23 - Service: Nero Registry InCD Service (NeroRegInCDSrv) - Nero AG - C:\Program Files\Nero\Nero8\InCD\NBHRegInCDSrv.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: Registry Management Service (RegManServ) - Unknown owner - C:\Program Files\Registry Defragmentation\RegManServ.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6261\SAService.exe
--
End of file - 30484 bytes
-- Files created between 2008-05-01 and 2008-06-01 -----------------------------
2008-06-01 10:56:25 0 d-------- C:\Program Files\Trend Micro
2008-05-31 22:46:24 0 d-------- C:\Program Files\Windows Live Safety Center
2008-05-31 21:34:16 0 d-------- C:\Program Files\Enigma Software Group
2008-05-30 22:24:06 0 d-------- C:\WINDOWS\LastGood
2008-05-30 20:50:07 245920 -r-hs---- C:\cmldr
2008-05-30 20:49:51 0 dr-hs---- C:\cmdcons
2008-05-30 20:49:46 0 d-------- C:\WINDOWS\setup.pss
2008-05-30 20:48:33 0 d-------- C:\WINDOWS\setupupd
2008-05-29 22:32:14 0 d-------- C:\327882R2FWJFW
2008-05-29 21:58:09 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-29 21:58:05 0 d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-29 20:47:21 51200 --a------ C:\WINDOWS\system32\__c004AA10.dat
2008-05-29 20:47:20 51200 --a------ C:\WINDOWS\system32\yiieftmf.dll
2008-05-29 20:47:19 51200 --a------ C:\WINDOWS\system32\yhnqjrhn.dll
2008-05-29 20:47:18 51200 --a------ C:\WINDOWS\system32\__c001A7BE.dat
2008-05-29 20:47:17 51200 --a------ C:\WINDOWS\system32\peondmqa.dll
2008-05-29 20:47:09 116224 --a------ C:\WINDOWS\system32\loipvlby.dll
2008-05-29 20:44:05 126976 --a------ C:\WINDOWS\system32\khaivyjx.dll
2008-05-28 20:47:15 51200 --a------ C:\WINDOWS\system32\__c00CCA9B.dat
2008-05-28 20:47:14 51200 --a------ C:\WINDOWS\system32\bexsqgvx.dll
2008-05-27 22:50:32 51200 --a------ C:\WINDOWS\system32\__c0027900.dat
2008-05-26 22:45:45 51200 --a------ C:\WINDOWS\system32\__c0077655.dat
2008-05-25 21:44:02 0 d-------- C:\Program Files\Microsoft Reader
2008-05-25 10:39:41 1572864 --a------ C:\Documents and Settings\Administrator\ntuser.dat
2008-05-25 10:39:40 8388608 --a------ C:\Documents and Settings\Kevin Wingrave\ntuser.dat
2008-05-25 10:39:07 487570 --ahs---- C:\WINDOWS\system32\aGjSstwa.ini2
2008-05-15 17:15:41 0 d-------- C:\WINDOWS\Prefetch
2008-05-14 22:32:40 0 d-------- C:\WINDOWS\system32\scripting
2008-05-14 22:32:40 0 d-------- C:\WINDOWS\l2schemas
2008-05-14 22:32:39 0 d-------- C:\WINDOWS\system32\en
2008-05-14 22:32:39 0 d-------- C:\WINDOWS\system32\bits
2008-05-14 22:30:03 0 d-------- C:\WINDOWS\ServicePackFiles
-- Find3M Report ---------------------------------------------------------------
2008-06-01 11:02:31 0 d-------- C:\Documents and Settings\Kevin Wingrave\Application Data\uTorrent
2008-05-30 06:43:09 0 d-------- C:\Program Files\uTorrent
2008-05-29 21:10:50 0 d-------- C:\Documents and Settings\Kevin Wingrave\Application Data\SiteAdvisor
2008-05-28 22:06:16 0 d-------- C:\Program Files\dl_Cats
2008-05-28 20:43:48 0 d-------- C:\Program Files\SiteAdvisor
2008-05-28 17:53:55 0 d-------- C:\Program Files\McAfee
2008-05-25 21:44:02 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-05-14 22:32:57 0 d-------- C:\Program Files\Messenger
2008-05-14 22:32:39 0 d-------- C:\Program Files\Movie Maker
2008-05-14 22:29:44 0 d-------- C:\Program Files\Windows NT
2008-05-13 07:04:50 0 d-------- C:\Documents and Settings\Kevin Wingrave\Application Data\DivX
2008-05-10 07:16:45 0 d-------- C:\Documents and Settings\Kevin Wingrave\Application Data\vlc
2008-05-10 07:13:43 0 d-------- C:\Documents and Settings\Kevin Wingrave\Application Data\Creative
2008-05-07 06:45:31 0 d-------- C:\Program Files\Microsoft Silverlight
2008-05-04 21:08:14 0 d-------- C:\Documents and Settings\Kevin Wingrave\Application Data\StumbleUpon
2008-05-02 06:51:53 0 d-------- C:\Program Files\Real
2008-04-30 06:44:47 0 d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-04-24 15:25:34 0 d-------- C:\Documents and Settings\Kevin Wingrave\Application Data\DellFaxCtr
2008-04-24 15:23:09 0 d-------- C:\Program Files\Creative
2008-04-24 15:22:13 409600 --a------ C:\WINDOWS\system32\wrap_oal.dll <Not Verified; Creative Labs; Creative Labs OpenAL32>
2008-04-24 15:22:13 86016 --a------ C:\WINDOWS\system32\OpenAL32.dll <Not Verified; Portions (C) Creative Labs Inc. and NVIDIA Corp.; Standard OpenAL(TM) Library>
2008-04-23 22:16:53 0 d-------- C:\Program Files\ECIClientV5
2008-04-13 22:50:29 0 d-------- C:\Program Files\Dell Photo AIO Printer 942
2008-04-13 22:34:40 0 d-------- C:\Program Files\Dell PC Fax
2008-04-12 15:45:17 0 d-------- C:\Program Files\DivX
2008-04-12 12:35:46 0 d-------- C:\Documents and Settings\Kevin Wingrave\Application Data\Malwarebytes
2008-04-12 12:35:40 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-12 11:25:00 0 d-------- C:\Documents and Settings\Kevin Wingrave\Application Data\TmpRecentIcons
2008-04-03 21:44:20 0 d-------- C:\Documents and Settings\Kevin Wingrave\Application Data\NeroDigital™
2008-04-01 07:25:48 823296 --a------ C:\WINDOWS\system32\divx_xx0c.dll <Not Verified; DivX, Inc.; DivX®>
2008-04-01 07:25:48 823296 --a------ C:\WINDOWS\system32\divx_xx07.dll <Not Verified; DivX, Inc.; DivX®>
2008-04-01 07:25:46 802816 --a------ C:\WINDOWS\system32\divx_xx11.dll <Not Verified; DivX, Inc.; DivX?>
2008-04-01 07:25:46 831488 --a------ C:\WINDOWS\system32\divx_xx0a.dll
2008-04-01 07:25:46 682496 --a------ C:\WINDOWS\system32\DivX.dll <Not Verified; DivX, Inc.; DivX®>
2008-03-22 06:30:08 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2008-03-22 06:28:54 196608 --a------ C:\WINDOWS\system32\dtu100.dll <Not Verified; DivX, Inc.; DivX, Inc. dtu100>
2008-03-22 06:28:54 81920 --a------ C:\WINDOWS\system32\dpl100.dll <Not Verified; DivX, Inc.; DivX, Inc. dpl100>
2008-03-22 06:28:20 12288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll
2008-03-16 10:11:52 2556 --a------ C:\WINDOWS\unins000.dat
2008-03-16 10:10:12 691545 --a------ C:\WINDOWS\unins000.exe
2008-03-14 20:58:07 335 --a------ C:\WINDOWS\mozregistry.dat
2008-03-14 20:54:16 1158 --a------ C:\WINDOWS\mozver.dat
-- Registry Dump ---------------------------------------------------------------
-- End of Deckard's System Scanner: finished at 2008-06-01 11:02:38 ------------
Have downloaded OTMoveIt and am ready to proceed - it works.
Have downloaded ATF Cleaner - but it wont install - gets the 0xc0000005 error.
Have downloaded Combofix - but it wont install - get the 0xc0000005 error on cmd.exe and rundll32.exe
Have downloaded DSS as mentioned above - that is the output from main.txt, below is extra.txt
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------
-- System Information ----------------------------------------------------------
Microsoft Windows XP Professional (build 2600) SP 3.0
Architecture: X86; Language: English
CPU 0: Intel(R) Pentium(R) D CPU 3.20GHz
Percentage of Memory in Use: 40%
Physical Memory (total/avail): 2046.09 MiB / 1227.36 MiB
Pagefile Memory (total/avail): 3941.56 MiB / 3273.62 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1901.99 MiB
A: is Removable (No Media)
C: is Fixed (NTFS) - 232.78 GiB total, 134.08 GiB free.
D: is Fixed (NTFS) - 232.82 GiB total, 115.36 GiB free.
E: is Fixed (NTFS) - 115.04 GiB total, 27.9 GiB free.
F: is Removable (No Media)
G: is Removable (No Media)
H: is Removable (No Media)
I: is Removable (No Media)
K: is CDROM (No Media)
L: is Removable (No Media)
\\.\PHYSICALDRIVE2 - IC35L120AVV207-0 - 115.04 GiB - 1 partition
\PARTITION0 (bootable) - Installable File System - 115.04 GiB - E:
\\.\PHYSICALDRIVE0 - Maxtor 7L250S0 - 232.83 GiB - 2 partitions
\PARTITION0 - Unknown - 39.19 MiB
\PARTITION1 (bootable) - Installable File System - 232.78 GiB - C:
\\.\PHYSICALDRIVE1 - Maxtor 7L250S0 - 232.83 GiB - 1 partition
\PARTITION0 - Installable File System - 232.82 GiB - D:
\\.\PHYSICALDRIVE7 - Disk drive
\\.\PHYSICALDRIVE3 - Samsung CF Card CF USB Device
\\.\PHYSICALDRIVE4 - Samsung MS Card MS USB Device
\\.\PHYSICALDRIVE5 - Samsung SD Card MMC/SD USB Device
\\.\PHYSICALDRIVE6 - Samsung SM/XD Card SM USB Device
-- Security Center -------------------------------------------------------------
AUOptions is scheduled to auto-install.
-- Environment Variables -------------------------------------------------------
-- User Profiles ---------------------------------------------------------------
Kevin Wingrave (admin)
Administrator (new local, admin)
-- Add/Remove Programs ---------------------------------------------------------
-- Application Event Log -------------------------------------------------------
Event Record #/Type4855 / Error
Event Submitted/Written: 05/31/2008 01:45:01 AM
Event ID/Source: 5000 / MPSampleSubmission
Event Description:
mptelemetry80070422updateservicemanager-_get_servicesfallbackcheck1.1.1593.0mpsigdwn.dll1.1.1593.0windows defenderNILNILNIL
Event Record #/Type4854 / Error
Event Submitted/Written: 05/30/2008 11:30:25 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application wlancfg5.exe, version 4.0.2.303, faulting module ntdll.dll, version 5.1.2600.5512, fault address 0x00010193.
Processing media-specific event for [wlancfg5.exe!ws!]
Event Record #/Type4853 / Error
Event Submitted/Written: 05/30/2008 10:24:32 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application teatimer.exe, version 1.5.2.16, faulting module teatimer.exe, version 1.5.2.16, fault address 0x0009a71c.
Processing media-specific event for [teatimer.exe!ws!]
Event Record #/Type4852 / Error
Event Submitted/Written: 05/30/2008 10:24:31 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application teatimer.exe, version 1.5.2.16, faulting module teatimer.exe, version 1.5.2.16, fault address 0x0009a71c.
Processing media-specific event for [teatimer.exe!ws!]
Event Record #/Type4851 / Error
Event Submitted/Written: 05/30/2008 10:24:30 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application teatimer.exe, version 1.5.2.16, faulting module teatimer.exe, version 1.5.2.16, fault address 0x0009a71c.
Processing media-specific event for [teatimer.exe!ws!]
-- Security Event Log ----------------------------------------------------------
No Errors/Warnings found.
-- System Event Log ------------------------------------------------------------
Event Record #/Type28484 / Warning
Event Submitted/Written: 05/31/2008 00:45:24 PM
Event ID/Source: 4226 / Tcpip
Event Description:
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.
Event Record #/Type28483 / Warning
Event Submitted/Written: 05/31/2008 00:02:21 PM
Event ID/Source: 36 / W32Time
Event Description:
The time service has not been able to synchronize the system time
for 49152 seconds because none of the time providers has been able to
provide a usable time stamp. The system clock is unsynchronized.
Event Record #/Type28476 / Warning
Event Submitted/Written: 05/31/2008 05:28:29 AM
Event ID/Source: 4226 / Tcpip
Event Description:
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.
Event Record #/Type28474 / Warning
Event Submitted/Written: 05/31/2008 01:50:01 AM
Event ID/Source: 4226 / Tcpip
Event Description:
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.
Event Record #/Type28472 / Error
Event Submitted/Written: 05/31/2008 01:45:00 AM
Event ID/Source: 10005 / DCOM
Event Description:
DCOM got error "%%1058" attempting to start the service wuauserv with arguments ""
in order to run the server:
{E60687F7-01A1-40AA-86AC-DB1CBF673334}
-- End of Deckard's System Scanner: finished at 2008-05-31 20:45:18 ------------
-------------------------------------------------------------------------------------------------
Have downloaded OTScanIt but it wont install - 0xc0000005 error
Have Malwarebytes already but it wont run, tried to re download and install but still wont run - oxc0000005 error
Have downloaded gmer but it wont install.
I would very much appreciate your help with repairing this very annoying problem.
Regards
Kevin Wingrave
Approximately a week ago my desktop has been behaving strangely.
It was receving 2 types of errors:
1) userinit.exe - the application failed to initialise properly (0xC0000005).....
2) rundll32.exe - the application failed to initialise properly (0xC0000005).....
3) many applications won't work
Now when I bootup and enter the user logon password I get the rundll32.exe error repeatedly and when I close the message box the screen is blank and I can't do anything, no sesssion icons at all. I can only go into TaskMgr and start a "explorer" session and that gets me going but then throughout I keep getting the rundll32.exe errors.
I updated and run Spybot and Adaware to latest levels and my McAfees is up to date. Spybot found problems with:
Virtumonde.dll
Virtumonde
Win32.BHO.df
Could not run HijackThis got the 0xc0000005 error.
Have followed as many of the instructions provided on this forum but am unable to run some of the programs suggested.---------------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Saturday, May 31, 2008 10:38:47 PM
Operating System: Microsoft Windows XP Professional, Service Pack 3 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 31/05/2008
Kaspersky Anti-Virus database records: 818004
---------------------------------------------------------------------------------------
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target Critical Areas
C:\WINDOWS
C:\DOCUME~1\KEVINW~1\LOCALS~1\Temp\
Scan Statistics
Total number of scanned objects 22972
Number of viruses found 2
Number of infected objects 2
Number of suspicious objects 0
Duration of the scan process 00:16:33
Infected Object Name Virus Name Last Action
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\khaivyjx.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.vqh skipped
C:\WINDOWS\system32\loipvlby.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.vqd skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\mcafee_upEstkXhFbKMWQq Object is locked skipped
C:\WINDOWS\Temp\mcmsc_JpvVJFYcCG0csoU Object is locked skipped
C:\WINDOWS\Temp\mcmsc_kU2OEa5n2hvB2WW Object is locked skipped
C:\WINDOWS\Temp\mcmsc_MV3YP3PPMuRmgfN Object is locked skipped
C:\WINDOWS\Temp\mcmsc_oPd4Jec335Sdb8Y Object is locked skipped
C:\WINDOWS\Temp\mcmsc_u7dADNafkXrHrU9 Object is locked skipped
C:\WINDOWS\Temp\sqlite_bGDOAeeZYks8zdw Object is locked skipped
C:\WINDOWS\Temp\sqlite_ek4kotUI4R1ahOI Object is locked skipped
C:\WINDOWS\Temp\sqlite_hvYYNf288vpmfVr Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\{00000005-00000000-00000004-00001102-00000004-20061102}.CDF Object is locked skipped
C:\DOCUME~1\KEVINW~1\LOCALS~1\Temp\sqlite_dhvrKjUMJJhMvJj Object is locked skipped
C:\DOCUME~1\KEVINW~1\LOCALS~1\Temp\~DF2D5A.tmp Object is locked skipped
C:\DOCUME~1\KEVINW~1\LOCALS~1\Temp\~DFCA50.tmp Object is locked skipped
C:\DOCUME~1\KEVINW~1\LOCALS~1\Temp\~DFCA6B.tmp Object is locked skipped
Scan process completed.
---------------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Sunday, June 01, 2008 10:49:05 AM
Operating System: Microsoft Windows XP Professional, Service Pack 3 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 31/05/2008
Kaspersky Anti-Virus database records: 819344
---------------------------------------------------------------------------------------
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target Folders
C:\_OTMoveIt\
C:\327882R2FWJFW\
C:\cmdcons\
C:\Deckard\
C:\DELL\
C:\Dell942\
C:\drvrtmp\
C:\KPCMS\
C:\Program Files\
C:\RECYCLER\
C:\spoolerlogs\
C:\System Volume Information\
C:\Temp\
C:\Webshots\
Scan Statistics
Total number of scanned objects 84588
Number of viruses found 4
Number of infected objects 7
Number of suspicious objects 0
Duration of the scan process 01:05:16
Infected Object Name Virus Name Last Action
C:\_OTMoveIt\MovedFiles\05302008_203653\WINDOWS\system32\awtsSjGa.dll_old Infected: Trojan.Win32.Pakes.cym skipped
C:\_OTMoveIt\MovedFiles\05302008_203653\WINDOWS\system32\byXRhFXP.dll Infected: Trojan-Downloader.Win32.Agent.qsk skipped
C:\_OTMoveIt\MovedFiles\05302008_203653\WINDOWS\system32\urqRLdCT.dll Infected: Trojan-Downloader.Win32.Agent.qsk skipped
C:\Program Files\Nero\Nero8\Nero BackItUp\BIU1.txt Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{EFA8AF3D-9D4F-49AD-91A1-D11B95972509}\RP214\A0031876.dll Infected: Trojan.Win32.Pakes.cym skipped
C:\System Volume Information\_restore{EFA8AF3D-9D4F-49AD-91A1-D11B95972509}\RP216\A0033257.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.tsk skipped
C:\System Volume Information\_restore{EFA8AF3D-9D4F-49AD-91A1-D11B95972509}\RP216\A0033302.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.trp skipped
C:\System Volume Information\_restore{EFA8AF3D-9D4F-49AD-91A1-D11B95972509}\RP217\A0033614.dll Infected: Trojan.Win32.Pakes.cym skipped
C:\System Volume Information\_restore{EFA8AF3D-9D4F-49AD-91A1-D11B95972509}\RP220\change.log Object is locked skipped
Scan process completed.
KASPERSKY ONLINE SCANNER REPORT
Sunday, June 01, 2008 11:43:59 AM
Operating System: Microsoft Windows XP Professional, Service Pack 3 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 31/05/2008
Kaspersky Anti-Virus database records: 819344
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target Folders
D:\
E:\
Scan Statistics
Total number of scanned objects 24422
Number of viruses found 7
Number of infected objects 15
Number of suspicious objects 0
Duration of the scan process 00:53:41
Infected Object Name Virus Name Last Action
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
D:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP841\A0042463.exe/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
D:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP841\A0042463.exe 7-Zip: infected - 1 skipped
D:\System Volume Information\_restore{EFA8AF3D-9D4F-49AD-91A1-D11B95972509}\RP220\change.log Object is locked skipped
E:\Download Patches and updates\Adobe\Adobe PageMaker v7.0.1.zip/crack.exe Infected: Trojan-Downloader.Win32.IstBar.is skipped
E:\Download Patches and updates\Adobe\Adobe PageMaker v7.0.1.zip ZIP: infected - 1 skipped
E:\Download Patches and updates\Hackers Toolkit.rar/HTS_part1/appz/Golden eye 2005/gesetup.exe/file01 Infected: not-a-virus:Monitor.Win32.GoldenEye.401 skipped
E:\Download Patches and updates\Hackers Toolkit.rar/HTS_part1/appz/Golden eye 2005/gesetup.exe/file23 Infected: Trojan.Win32.Hooker.j skipped
E:\Download Patches and updates\Hackers Toolkit.rar/HTS_part1/appz/Golden eye 2005/gesetup.exe/file24 Infected: Trojan-Spy.Win32.SpyAnyTime.a skipped
E:\Download Patches and updates\Hackers Toolkit.rar/HTS_part1/appz/Golden eye 2005/gesetup.exe Infected: Trojan-Spy.Win32.SpyAnyTime.a skipped
E:\Download Patches and updates\Hackers Toolkit.rar RAR: infected - 4 skipped
E:\Download Patches and updates\Nero\Nero-8.2.8.0_eng_update.exe/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
E:\Download Patches and updates\Nero\Nero-8.2.8.0_eng_update.exe 7-Zip: infected - 1 skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
E:\System Volume Information\_restore{EFA8AF3D-9D4F-49AD-91A1-D11B95972509}\RP220\change.log Object is locked skipped
E:\Videos\AVI's\Applications.zip/california.exe Infected: not-virus:BadJoke.Win16.Aloap skipped
E:\Videos\AVI's\Applications.zip/ATT1.EXE Infected: not-virus:BadJoke.Win16.Stupid.a skipped
E:\Videos\AVI's\Applications.zip/SMALL.EXE Infected: not-virus:BadJoke.Win16.Stupid.a skipped
E:\Videos\AVI's\Applications.zip ZIP: infected - 3 skipped
Scan process completed.
----------------------------------------------------------------------------------------------
Had to run multiple times because Internet Explorer likes to crash often.
Could not run HiJackThis directly but could run it from DSS as shown below-----------------------------------------------------------------------------------------------
Deckard's System Scanner v20071014.68
Run by Kevin Wingrave on 2008-06-01 10:56:04
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- HijackThis (run as Kevin Wingrave.exe) --------------------------------------
Unable to find log (file not found); running clone.
-- HijackThis Clone ------------------------------------------------------------
Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-06-01 10:59:33
Platform: Windows XP Service Pack 3 (5.01.2600)
MSIE: Internet Explorer (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTSVCCDA.EXE
C:\WINDOWS\system32\dlbucoms.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Nero\Nero8\InCD\InCDsrv.exe
C:\Program Files\Common Files\logishrd\LVCOMSER\LVComSer.exe
C:\Program Files\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
C:\Program Files\Common Files\McAfee\McProxy\McProxy.exe
C:\Program Files\McAfee\VirusScan\Mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MpfSrv.exe
C:\Program Files\McAfee\MSK\msksrver.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\Nero\Nero8\InCD\NBHRegInCDSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\Program Files\Registry Defragmentation\RegManServ.exe
C:\Program Files\SiteAdvisor\6261\SAService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Common Files\logishrd\LVCOMSER\LVComSer.exe
C:\Program Files\McAfee\VirusScan\mcsysmon.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\logishrd\LComMgr\Communications_Helper.exe
C:\Program Files\Nero\Nero8\InCD\NBHGui.exe
C:\Program Files\Nero\Nero8\InCD\InCD.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Documents and Settings\Kevin Wingrave\Desktop\dss.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ninemsn.com.au/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.ninemsn.com.au/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O2 - BHO: StumbleUpon Launcher - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O2 - BHO: AddTask Class - {24F06550-65E3-4D1C-8CFE-839C296B5530} - C:\Program Files\Real\IEeREAD.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {323DB43C-424C-4309-909E-3BEDE995D91E} - C:\WINDOWS\system32\awtsSjGa.dll (file missing)
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - C:\Program Files\McAfee\MSK\mcapbho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: AddTask Class - {6A19C29D-ED45-4483-8999-9F939C8161F2} - C:\Program Files\Real\WebHook.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\GoogleToolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\GoogleToolbar1.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe /inspect
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Dell Photo AIO Printer 942] "C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe"
O4 - HKLM\..\Run: [DellMCM] "C:\Program Files\Dell Photo AIO Printer 942\memcard.exe"
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero8\InCD\NBHGui.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero8\InCD\InCD.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6261\SiteAdv.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Dell PC Fax\fm3032.exe" /s
O4 - HKLM\..\Run: [DLBUCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBUtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlbumon.exe] "C:\Program Files\Dell Photo AIO Printer 942\dlbumon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 942\memcard.exe"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = ?
O4 - Global Startup: NETGEAR WG311T Wireless Assistant.lnk = C:\Program Files\NETGEAR\WG311T\wlancfg5.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.microsoft.com (HKCU)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://download.microsoft.com/download/e/7/3/e7345c16-80aa-4488-ae10-9ac6be844f99/OGAControl.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase9563.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1209472499999
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc4.cab
O18 - Protocol: bw+0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {08b78cad-cd39-4558-8665-b5765dc70d0f} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL
O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL
O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL
O18 - Protocol: offline-8876480 - {08B78CAD-CD39-4558-8665-B5765DC70D0F} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\__c004AA10.dat
O23 - Service: McAfee Application Installer Cleanup (0128551212245013) (0128551212245013mcinstcleanup) - McAfee, Inc. - C:\WINDOWS\Temp\0128551212245013mcinst.exe
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTSVCCDA.EXE
O23 - Service: dlbu_device - Unknown owner - C:\WINDOWS\system32\dlbucoms.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero8\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\logishrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\logishrd\SrvLnch\SrvLnch.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McProxy\McProxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\Mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MpfSrv.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\msksrver.exe
O23 - Service: Nero BackItUp Scheduler 3 - Unknown owner - C:\Program Files\Nero\Nero8\Nero
O23 - Service: Nero Registry InCD Service (NeroRegInCDSrv) - Nero AG - C:\Program Files\Nero\Nero8\InCD\NBHRegInCDSrv.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: Registry Management Service (RegManServ) - Unknown owner - C:\Program Files\Registry Defragmentation\RegManServ.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6261\SAService.exe
--
End of file - 30484 bytes
-- Files created between 2008-05-01 and 2008-06-01 -----------------------------
2008-06-01 10:56:25 0 d-------- C:\Program Files\Trend Micro
2008-05-31 22:46:24 0 d-------- C:\Program Files\Windows Live Safety Center
2008-05-31 21:34:16 0 d-------- C:\Program Files\Enigma Software Group
2008-05-30 22:24:06 0 d-------- C:\WINDOWS\LastGood
2008-05-30 20:50:07 245920 -r-hs---- C:\cmldr
2008-05-30 20:49:51 0 dr-hs---- C:\cmdcons
2008-05-30 20:49:46 0 d-------- C:\WINDOWS\setup.pss
2008-05-30 20:48:33 0 d-------- C:\WINDOWS\setupupd
2008-05-29 22:32:14 0 d-------- C:\327882R2FWJFW
2008-05-29 21:58:09 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-29 21:58:05 0 d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-29 20:47:21 51200 --a------ C:\WINDOWS\system32\__c004AA10.dat
2008-05-29 20:47:20 51200 --a------ C:\WINDOWS\system32\yiieftmf.dll
2008-05-29 20:47:19 51200 --a------ C:\WINDOWS\system32\yhnqjrhn.dll
2008-05-29 20:47:18 51200 --a------ C:\WINDOWS\system32\__c001A7BE.dat
2008-05-29 20:47:17 51200 --a------ C:\WINDOWS\system32\peondmqa.dll
2008-05-29 20:47:09 116224 --a------ C:\WINDOWS\system32\loipvlby.dll
2008-05-29 20:44:05 126976 --a------ C:\WINDOWS\system32\khaivyjx.dll
2008-05-28 20:47:15 51200 --a------ C:\WINDOWS\system32\__c00CCA9B.dat
2008-05-28 20:47:14 51200 --a------ C:\WINDOWS\system32\bexsqgvx.dll
2008-05-27 22:50:32 51200 --a------ C:\WINDOWS\system32\__c0027900.dat
2008-05-26 22:45:45 51200 --a------ C:\WINDOWS\system32\__c0077655.dat
2008-05-25 21:44:02 0 d-------- C:\Program Files\Microsoft Reader
2008-05-25 10:39:41 1572864 --a------ C:\Documents and Settings\Administrator\ntuser.dat
2008-05-25 10:39:40 8388608 --a------ C:\Documents and Settings\Kevin Wingrave\ntuser.dat
2008-05-25 10:39:07 487570 --ahs---- C:\WINDOWS\system32\aGjSstwa.ini2
2008-05-15 17:15:41 0 d-------- C:\WINDOWS\Prefetch
2008-05-14 22:32:40 0 d-------- C:\WINDOWS\system32\scripting
2008-05-14 22:32:40 0 d-------- C:\WINDOWS\l2schemas
2008-05-14 22:32:39 0 d-------- C:\WINDOWS\system32\en
2008-05-14 22:32:39 0 d-------- C:\WINDOWS\system32\bits
2008-05-14 22:30:03 0 d-------- C:\WINDOWS\ServicePackFiles
-- Find3M Report ---------------------------------------------------------------
2008-06-01 11:02:31 0 d-------- C:\Documents and Settings\Kevin Wingrave\Application Data\uTorrent
2008-05-30 06:43:09 0 d-------- C:\Program Files\uTorrent
2008-05-29 21:10:50 0 d-------- C:\Documents and Settings\Kevin Wingrave\Application Data\SiteAdvisor
2008-05-28 22:06:16 0 d-------- C:\Program Files\dl_Cats
2008-05-28 20:43:48 0 d-------- C:\Program Files\SiteAdvisor
2008-05-28 17:53:55 0 d-------- C:\Program Files\McAfee
2008-05-25 21:44:02 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-05-14 22:32:57 0 d-------- C:\Program Files\Messenger
2008-05-14 22:32:39 0 d-------- C:\Program Files\Movie Maker
2008-05-14 22:29:44 0 d-------- C:\Program Files\Windows NT
2008-05-13 07:04:50 0 d-------- C:\Documents and Settings\Kevin Wingrave\Application Data\DivX
2008-05-10 07:16:45 0 d-------- C:\Documents and Settings\Kevin Wingrave\Application Data\vlc
2008-05-10 07:13:43 0 d-------- C:\Documents and Settings\Kevin Wingrave\Application Data\Creative
2008-05-07 06:45:31 0 d-------- C:\Program Files\Microsoft Silverlight
2008-05-04 21:08:14 0 d-------- C:\Documents and Settings\Kevin Wingrave\Application Data\StumbleUpon
2008-05-02 06:51:53 0 d-------- C:\Program Files\Real
2008-04-30 06:44:47 0 d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-04-24 15:25:34 0 d-------- C:\Documents and Settings\Kevin Wingrave\Application Data\DellFaxCtr
2008-04-24 15:23:09 0 d-------- C:\Program Files\Creative
2008-04-24 15:22:13 409600 --a------ C:\WINDOWS\system32\wrap_oal.dll <Not Verified; Creative Labs; Creative Labs OpenAL32>
2008-04-24 15:22:13 86016 --a------ C:\WINDOWS\system32\OpenAL32.dll <Not Verified; Portions (C) Creative Labs Inc. and NVIDIA Corp.; Standard OpenAL(TM) Library>
2008-04-23 22:16:53 0 d-------- C:\Program Files\ECIClientV5
2008-04-13 22:50:29 0 d-------- C:\Program Files\Dell Photo AIO Printer 942
2008-04-13 22:34:40 0 d-------- C:\Program Files\Dell PC Fax
2008-04-12 15:45:17 0 d-------- C:\Program Files\DivX
2008-04-12 12:35:46 0 d-------- C:\Documents and Settings\Kevin Wingrave\Application Data\Malwarebytes
2008-04-12 12:35:40 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-12 11:25:00 0 d-------- C:\Documents and Settings\Kevin Wingrave\Application Data\TmpRecentIcons
2008-04-03 21:44:20 0 d-------- C:\Documents and Settings\Kevin Wingrave\Application Data\NeroDigital™
2008-04-01 07:25:48 823296 --a------ C:\WINDOWS\system32\divx_xx0c.dll <Not Verified; DivX, Inc.; DivX®>
2008-04-01 07:25:48 823296 --a------ C:\WINDOWS\system32\divx_xx07.dll <Not Verified; DivX, Inc.; DivX®>
2008-04-01 07:25:46 802816 --a------ C:\WINDOWS\system32\divx_xx11.dll <Not Verified; DivX, Inc.; DivX?>
2008-04-01 07:25:46 831488 --a------ C:\WINDOWS\system32\divx_xx0a.dll
2008-04-01 07:25:46 682496 --a------ C:\WINDOWS\system32\DivX.dll <Not Verified; DivX, Inc.; DivX®>
2008-03-22 06:30:08 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2008-03-22 06:28:54 196608 --a------ C:\WINDOWS\system32\dtu100.dll <Not Verified; DivX, Inc.; DivX, Inc. dtu100>
2008-03-22 06:28:54 81920 --a------ C:\WINDOWS\system32\dpl100.dll <Not Verified; DivX, Inc.; DivX, Inc. dpl100>
2008-03-22 06:28:20 12288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll
2008-03-16 10:11:52 2556 --a------ C:\WINDOWS\unins000.dat
2008-03-16 10:10:12 691545 --a------ C:\WINDOWS\unins000.exe
2008-03-14 20:58:07 335 --a------ C:\WINDOWS\mozregistry.dat
2008-03-14 20:54:16 1158 --a------ C:\WINDOWS\mozver.dat
-- Registry Dump ---------------------------------------------------------------
-- End of Deckard's System Scanner: finished at 2008-06-01 11:02:38 ------------
Have downloaded OTMoveIt and am ready to proceed - it works.
Have downloaded ATF Cleaner - but it wont install - gets the 0xc0000005 error.
Have downloaded Combofix - but it wont install - get the 0xc0000005 error on cmd.exe and rundll32.exe
Have downloaded DSS as mentioned above - that is the output from main.txt, below is extra.txt
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------
-- System Information ----------------------------------------------------------
Microsoft Windows XP Professional (build 2600) SP 3.0
Architecture: X86; Language: English
CPU 0: Intel(R) Pentium(R) D CPU 3.20GHz
Percentage of Memory in Use: 40%
Physical Memory (total/avail): 2046.09 MiB / 1227.36 MiB
Pagefile Memory (total/avail): 3941.56 MiB / 3273.62 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1901.99 MiB
A: is Removable (No Media)
C: is Fixed (NTFS) - 232.78 GiB total, 134.08 GiB free.
D: is Fixed (NTFS) - 232.82 GiB total, 115.36 GiB free.
E: is Fixed (NTFS) - 115.04 GiB total, 27.9 GiB free.
F: is Removable (No Media)
G: is Removable (No Media)
H: is Removable (No Media)
I: is Removable (No Media)
K: is CDROM (No Media)
L: is Removable (No Media)
\\.\PHYSICALDRIVE2 - IC35L120AVV207-0 - 115.04 GiB - 1 partition
\PARTITION0 (bootable) - Installable File System - 115.04 GiB - E:
\\.\PHYSICALDRIVE0 - Maxtor 7L250S0 - 232.83 GiB - 2 partitions
\PARTITION0 - Unknown - 39.19 MiB
\PARTITION1 (bootable) - Installable File System - 232.78 GiB - C:
\\.\PHYSICALDRIVE1 - Maxtor 7L250S0 - 232.83 GiB - 1 partition
\PARTITION0 - Installable File System - 232.82 GiB - D:
\\.\PHYSICALDRIVE7 - Disk drive
\\.\PHYSICALDRIVE3 - Samsung CF Card CF USB Device
\\.\PHYSICALDRIVE4 - Samsung MS Card MS USB Device
\\.\PHYSICALDRIVE5 - Samsung SD Card MMC/SD USB Device
\\.\PHYSICALDRIVE6 - Samsung SM/XD Card SM USB Device
-- Security Center -------------------------------------------------------------
AUOptions is scheduled to auto-install.
-- Environment Variables -------------------------------------------------------
-- User Profiles ---------------------------------------------------------------
Kevin Wingrave (admin)
Administrator (new local, admin)
-- Add/Remove Programs ---------------------------------------------------------
-- Application Event Log -------------------------------------------------------
Event Record #/Type4855 / Error
Event Submitted/Written: 05/31/2008 01:45:01 AM
Event ID/Source: 5000 / MPSampleSubmission
Event Description:
mptelemetry80070422updateservicemanager-_get_servicesfallbackcheck1.1.1593.0mpsigdwn.dll1.1.1593.0windows defenderNILNILNIL
Event Record #/Type4854 / Error
Event Submitted/Written: 05/30/2008 11:30:25 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application wlancfg5.exe, version 4.0.2.303, faulting module ntdll.dll, version 5.1.2600.5512, fault address 0x00010193.
Processing media-specific event for [wlancfg5.exe!ws!]
Event Record #/Type4853 / Error
Event Submitted/Written: 05/30/2008 10:24:32 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application teatimer.exe, version 1.5.2.16, faulting module teatimer.exe, version 1.5.2.16, fault address 0x0009a71c.
Processing media-specific event for [teatimer.exe!ws!]
Event Record #/Type4852 / Error
Event Submitted/Written: 05/30/2008 10:24:31 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application teatimer.exe, version 1.5.2.16, faulting module teatimer.exe, version 1.5.2.16, fault address 0x0009a71c.
Processing media-specific event for [teatimer.exe!ws!]
Event Record #/Type4851 / Error
Event Submitted/Written: 05/30/2008 10:24:30 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application teatimer.exe, version 1.5.2.16, faulting module teatimer.exe, version 1.5.2.16, fault address 0x0009a71c.
Processing media-specific event for [teatimer.exe!ws!]
-- Security Event Log ----------------------------------------------------------
No Errors/Warnings found.
-- System Event Log ------------------------------------------------------------
Event Record #/Type28484 / Warning
Event Submitted/Written: 05/31/2008 00:45:24 PM
Event ID/Source: 4226 / Tcpip
Event Description:
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.
Event Record #/Type28483 / Warning
Event Submitted/Written: 05/31/2008 00:02:21 PM
Event ID/Source: 36 / W32Time
Event Description:
The time service has not been able to synchronize the system time
for 49152 seconds because none of the time providers has been able to
provide a usable time stamp. The system clock is unsynchronized.
Event Record #/Type28476 / Warning
Event Submitted/Written: 05/31/2008 05:28:29 AM
Event ID/Source: 4226 / Tcpip
Event Description:
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.
Event Record #/Type28474 / Warning
Event Submitted/Written: 05/31/2008 01:50:01 AM
Event ID/Source: 4226 / Tcpip
Event Description:
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.
Event Record #/Type28472 / Error
Event Submitted/Written: 05/31/2008 01:45:00 AM
Event ID/Source: 10005 / DCOM
Event Description:
DCOM got error "%%1058" attempting to start the service wuauserv with arguments ""
in order to run the server:
{E60687F7-01A1-40AA-86AC-DB1CBF673334}
-- End of Deckard's System Scanner: finished at 2008-05-31 20:45:18 ------------
-------------------------------------------------------------------------------------------------
Have downloaded OTScanIt but it wont install - 0xc0000005 error
Have Malwarebytes already but it wont run, tried to re download and install but still wont run - oxc0000005 error
Have downloaded gmer but it wont install.
I would very much appreciate your help with repairing this very annoying problem.
Regards
Kevin Wingrave