bullethead399
New member
I don't know what to do. When I use spybot, it finds command services and now I keep gettin pop ups of stupid advertisements. PLEASE HELP...
HERE'S THE ONLINE SCAN REPORT.
File Infection Status Path
adfcook[1] Win32/Secdrop.OC infected C:\Documents and Settings\Eric G\Local Settings\Temporary Internet Files\Content.IE5\0P0VS70R\
retadpu[1].exe Win32/Matcash.AP infected C:\Documents and Settings\Eric G\Local Settings\Temporary Internet Files\Content.IE5\0P0VS70R\
masiyxanidi[1] Win32/Abetear.B infected C:\Documents and Settings\Eric G\Local Settings\Temporary Internet Files\Content.IE5\65T6BUTS\
kcehc_eicooc20070702[1] Win32/Secdrop.OF infected C:\Documents and Settings\Eric G\Local Settings\Temporary Internet Files\Content.IE5\EEFV3AKK\
!update-4395[1].0000 Win32/Clspring.GS infected C:\Documents and Settings\Eric G\Local Settings\Temporary Internet Files\Content.IE5\VM0Z3H85\
CAZEWFVL Win32/Vundo!generic infected C:\Documents and Settings\Eric G\Local Settings\Temporary Internet Files\Content.IE5\WJ5NMQ3T\
_affvm[1] Win32/Vundo!generic infected C:\Documents and Settings\Eric G\Local Settings\Temporary Internet Files\Content.IE5\WJ5NMQ3T\
_jnvm[1] Win32/Darksma!generic infected C:\Documents and Settings\Eric G\Local Settings\Temporary Internet Files\Content.IE5\WJ5NMQ3T\
retadpu[1].exe Win32/Matcash.AP infected C:\Documents and Settings\Eric G\Local Settings\Temporary Internet Files\Content.IE5\Y9DA3E1G\
retadpu[2].exe Win32/Matcash.AP infected C:\Documents and Settings\Eric G\Local Settings\Temporary Internet Files\Content.IE5\Y9DA3E1G\
p.zip Win32/Alcan.I!ZIP infected C:\Program Files\outlook\
p.zip>Setup.exe Win32/Alcan.I infected C:\Program Files\outlook\
v.tmp Win32/Alcan.I infected C:\Program Files\outlook\
cpffxqxc.dll Win32/Darksma!generic infected C:\WINDOWS\system32\
fnccwxku.exe Win32/Abetear.B infected C:\WINDOWS\system32\
fonvgmpi.exe Win32/Abetear.B infected C:\WINDOWS\system32\
gprwuatd.exe Win32/Abetear.B infected C:\WINDOWS\system32\
install.exe Win32/Matcash.AQ infected C:\WINDOWS\system32\
jfpaxpmx.exe Win32/Secdrop.OF infected C:\WINDOWS\system32\
jsamlkdc.exe Win32/Abetear.B infected C:\WINDOWS\system32\
ocnjoqbv.exe Win32/Secdrop.OF infected C:\WINDOWS\system32\
omltxmos.exe Win32/Secdrop.OC infected C:\WINDOWS\system32\
peleegug.exe Win32/Abetear.B infected C:\WINDOWS\system32\
ps.exe Win32/Unknown possibly infected C:\WINDOWS\system32\
pylcgicv.exe Win32/Secdrop.OF infected C:\WINDOWS\system32\
qebltbon.dll Win32/Vundo!generic infected C:\WINDOWS\system32\
sstts.dll Win32/Vundo!generic infected C:\WINDOWS\system32\
taqmsqem.exe Win32/Secdrop.OF infected C:\WINDOWS\system32\
vtuttqn.dll Win32/Chisyne!generic infected C:\WINDOWS\system32\
wefwedhn.exe Win32/Abetear.B infected C:\WINDOWS\system32\
wpdcvxko.exe Win32/Secdrop.OF infected C:\WINDOWS\system32\
ycqphyot.exe Win32/Abetear.B infected C:\WINDOWS\system32\
AND HERE'S THE HJT LOG.
Logfile of HijackThis v1.99.1
Scan saved at 9:30:48 PM, on 8/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\AKProg\AKProg.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb06.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\outlook\outlook.exe
C:\WINDOWS\system32\winlog.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\AIM6\aim6.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Documents and Settings\Eric G\My Documents\?ystem32\n?pdb.exe
C:\WINDOWS\System32\svchost.exe
C:\DOCUME~1\ERICG~1\APPLIC~1\ECURIT~1\wuauboot.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Common Files\Palo Alto Software\9.0\PAS9_UD.exe
C:\Program Files\Silicon Image\SiISATARaid\SATARaid.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Eric G\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb06.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [outlook] C:\Program Files\outlook\outlook.exe /auto
O4 - HKLM\..\Run: [winlog] winlog.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\system32\qebltbon.dll",forkonce
O4 - HKLM\..\RunServices: [winlog] winlog.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Tptohtvh] "C:\Documents and Settings\Eric G\My Documents\?ystem32\n?pdb.exe"
O4 - HKCU\..\Run: [Atou] "C:\DOCUME~1\ERICG~1\APPLIC~1\ECURIT~1\wuauboot.exe" -vt ndrv
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Palo Alto Software Update Manager 9.0.lnk = ?
O4 - Global Startup: SATARaid.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O16 - DPF: {50647AB5-18FD-4142-82B0-5852478DD0D5} (Keynote Connector Launcher 2) - http://webeffective.keynote.com/applications/pconnector/download/ConnectorLauncher.cab
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin11USA.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.ca.com/us/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin9USA.cab
O16 - DPF: {DD583921-A9E9-4FBF-9266-8DC2AB5EA0AF} - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin10USA.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Unknown owner - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe (file missing)
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Unknown owner - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe (file missing)
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\RXJpYyBHLg\command.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
PLEASE TELL ME WHAT TO DO PLEASE.!
HERE'S THE ONLINE SCAN REPORT.
File Infection Status Path
adfcook[1] Win32/Secdrop.OC infected C:\Documents and Settings\Eric G\Local Settings\Temporary Internet Files\Content.IE5\0P0VS70R\
retadpu[1].exe Win32/Matcash.AP infected C:\Documents and Settings\Eric G\Local Settings\Temporary Internet Files\Content.IE5\0P0VS70R\
masiyxanidi[1] Win32/Abetear.B infected C:\Documents and Settings\Eric G\Local Settings\Temporary Internet Files\Content.IE5\65T6BUTS\
kcehc_eicooc20070702[1] Win32/Secdrop.OF infected C:\Documents and Settings\Eric G\Local Settings\Temporary Internet Files\Content.IE5\EEFV3AKK\
!update-4395[1].0000 Win32/Clspring.GS infected C:\Documents and Settings\Eric G\Local Settings\Temporary Internet Files\Content.IE5\VM0Z3H85\
CAZEWFVL Win32/Vundo!generic infected C:\Documents and Settings\Eric G\Local Settings\Temporary Internet Files\Content.IE5\WJ5NMQ3T\
_affvm[1] Win32/Vundo!generic infected C:\Documents and Settings\Eric G\Local Settings\Temporary Internet Files\Content.IE5\WJ5NMQ3T\
_jnvm[1] Win32/Darksma!generic infected C:\Documents and Settings\Eric G\Local Settings\Temporary Internet Files\Content.IE5\WJ5NMQ3T\
retadpu[1].exe Win32/Matcash.AP infected C:\Documents and Settings\Eric G\Local Settings\Temporary Internet Files\Content.IE5\Y9DA3E1G\
retadpu[2].exe Win32/Matcash.AP infected C:\Documents and Settings\Eric G\Local Settings\Temporary Internet Files\Content.IE5\Y9DA3E1G\
p.zip Win32/Alcan.I!ZIP infected C:\Program Files\outlook\
p.zip>Setup.exe Win32/Alcan.I infected C:\Program Files\outlook\
v.tmp Win32/Alcan.I infected C:\Program Files\outlook\
cpffxqxc.dll Win32/Darksma!generic infected C:\WINDOWS\system32\
fnccwxku.exe Win32/Abetear.B infected C:\WINDOWS\system32\
fonvgmpi.exe Win32/Abetear.B infected C:\WINDOWS\system32\
gprwuatd.exe Win32/Abetear.B infected C:\WINDOWS\system32\
install.exe Win32/Matcash.AQ infected C:\WINDOWS\system32\
jfpaxpmx.exe Win32/Secdrop.OF infected C:\WINDOWS\system32\
jsamlkdc.exe Win32/Abetear.B infected C:\WINDOWS\system32\
ocnjoqbv.exe Win32/Secdrop.OF infected C:\WINDOWS\system32\
omltxmos.exe Win32/Secdrop.OC infected C:\WINDOWS\system32\
peleegug.exe Win32/Abetear.B infected C:\WINDOWS\system32\
ps.exe Win32/Unknown possibly infected C:\WINDOWS\system32\
pylcgicv.exe Win32/Secdrop.OF infected C:\WINDOWS\system32\
qebltbon.dll Win32/Vundo!generic infected C:\WINDOWS\system32\
sstts.dll Win32/Vundo!generic infected C:\WINDOWS\system32\
taqmsqem.exe Win32/Secdrop.OF infected C:\WINDOWS\system32\
vtuttqn.dll Win32/Chisyne!generic infected C:\WINDOWS\system32\
wefwedhn.exe Win32/Abetear.B infected C:\WINDOWS\system32\
wpdcvxko.exe Win32/Secdrop.OF infected C:\WINDOWS\system32\
ycqphyot.exe Win32/Abetear.B infected C:\WINDOWS\system32\
AND HERE'S THE HJT LOG.
Logfile of HijackThis v1.99.1
Scan saved at 9:30:48 PM, on 8/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\AKProg\AKProg.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb06.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\outlook\outlook.exe
C:\WINDOWS\system32\winlog.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\AIM6\aim6.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Documents and Settings\Eric G\My Documents\?ystem32\n?pdb.exe
C:\WINDOWS\System32\svchost.exe
C:\DOCUME~1\ERICG~1\APPLIC~1\ECURIT~1\wuauboot.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Common Files\Palo Alto Software\9.0\PAS9_UD.exe
C:\Program Files\Silicon Image\SiISATARaid\SATARaid.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Eric G\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb06.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [outlook] C:\Program Files\outlook\outlook.exe /auto
O4 - HKLM\..\Run: [winlog] winlog.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\system32\qebltbon.dll",forkonce
O4 - HKLM\..\RunServices: [winlog] winlog.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Tptohtvh] "C:\Documents and Settings\Eric G\My Documents\?ystem32\n?pdb.exe"
O4 - HKCU\..\Run: [Atou] "C:\DOCUME~1\ERICG~1\APPLIC~1\ECURIT~1\wuauboot.exe" -vt ndrv
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Palo Alto Software Update Manager 9.0.lnk = ?
O4 - Global Startup: SATARaid.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O16 - DPF: {50647AB5-18FD-4142-82B0-5852478DD0D5} (Keynote Connector Launcher 2) - http://webeffective.keynote.com/applications/pconnector/download/ConnectorLauncher.cab
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin11USA.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.ca.com/us/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin9USA.cab
O16 - DPF: {DD583921-A9E9-4FBF-9266-8DC2AB5EA0AF} - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin10USA.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Unknown owner - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe (file missing)
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Unknown owner - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe (file missing)
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\RXJpYyBHLg\command.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
PLEASE TELL ME WHAT TO DO PLEASE.!