Judging from the previous threads, I guess this is a popular problem. Spybot tends to detect Virtumonde.dll, and it successfully removes it, but it always comes back. Whatever combination of malware I have, it makes my explorer use up way more resources than it should, and doesn't allow me to go to most websites. Can't log onto facebook, can't search on google. So, here is my kasper log, which was my computer before I ran spybot (again) in safe mode. The HJT log is a log of my computer after I rebooted from safe mode.
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Sunday, June 08, 2008 11:07:16 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 8/06/2008
Kaspersky Anti-Virus database records: 840603
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
Scan Statistics:
Total number of scanned objects: 184471
Number of viruses found: 11
Number of infected objects: 46
Number of suspicious objects: 0
Duration of the scan process: 02:34:03
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Signus\Application Data\Aim\impyggep\Numenor37\cert8.db Object is locked skipped
C:\Documents and Settings\Signus\Application Data\Aim\impyggep\Numenor37\key3.db Object is locked skipped
C:\Documents and Settings\Signus\Application Data\Mozilla\Firefox\Profiles\7b3s6n2o.default\cert8.db Object is locked skipped
C:\Documents and Settings\Signus\Application Data\Mozilla\Firefox\Profiles\7b3s6n2o.default\history.dat Object is locked skipped
C:\Documents and Settings\Signus\Application Data\Mozilla\Firefox\Profiles\7b3s6n2o.default\key3.db Object is locked skipped
C:\Documents and Settings\Signus\Application Data\Mozilla\Firefox\Profiles\7b3s6n2o.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Signus\Application Data\Mozilla\Firefox\Profiles\7b3s6n2o.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Signus\Application Data\Mozilla\Firefox\Profiles\7b3s6n2o.default\webappsstore.sqlite Object is locked skipped
C:\Documents and Settings\Signus\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Signus\Desktop\Zone of Silence\Antivirus\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Signus\Desktop\Zone of Silence\Antivirus\SmitfraudFix.exe/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Signus\Desktop\Zone of Silence\Antivirus\SmitfraudFix.exe RAR: infected - 1 skipped
C:\Documents and Settings\Signus\Local Settings\Application Data\Ahead\Nero Home\bl.db Object is locked skipped
C:\Documents and Settings\Signus\Local Settings\Application Data\Ahead\Nero Home\is2.db Object is locked skipped
C:\Documents and Settings\Signus\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Signus\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Signus\Local Settings\Application Data\Mozilla\Firefox\Profiles\7b3s6n2o.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Signus\Local Settings\Application Data\Mozilla\Firefox\Profiles\7b3s6n2o.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Signus\Local Settings\Application Data\Mozilla\Firefox\Profiles\7b3s6n2o.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Signus\Local Settings\Application Data\Mozilla\Firefox\Profiles\7b3s6n2o.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Signus\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Signus\Local Settings\History\History.IE5\MSHist012008060820080609\index.dat Object is locked skipped
C:\Documents and Settings\Signus\Local Settings\Temp\Free Download Manager\tic253.tmp Object is locked skipped
C:\Documents and Settings\Signus\Local Settings\Temp\sqlite_emgsIfzIwtuHETM Object is locked skipped
C:\Documents and Settings\Signus\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Signus\Local Settings\Temporary Internet Files\Content.IE5\WHYZWL6Z\kb516107[1] Infected: Trojan.Win32.Agent.reo skipped
C:\Documents and Settings\Signus\Local Settings\Temporary Internet Files\Content.IE5\ZKUOT7PQ\kb516107[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.yhx skipped
C:\Documents and Settings\Signus\My Documents\My Music\iTunes\iTunes Music\Adobe Premiere CS3 Pro Keygenerator.rar/Setup+Patch.exe Infected: P2P-Worm.Win32.Agent.bm skipped
C:\Documents and Settings\Signus\My Documents\My Music\iTunes\iTunes Music\Adobe Premiere CS3 Pro Keygenerator.rar CAB: infected - 1 skipped
C:\Documents and Settings\Signus\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Signus\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Tobias\Local Settings\Temporary Internet Files\Content.IE5\5HUS6U5X\hctp[1] Infected: Trojan.Win32.Monder.eb skipped
C:\Documents and Settings\Tobias\Local Settings\Temporary Internet Files\Content.IE5\7I9YWGTS\CAIF6FUL Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\Tobias\Local Settings\Temporary Internet Files\Content.IE5\7I9YWGTS\query[1] Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\Tobias\Local Settings\Temporary Internet Files\Content.IE5\F2V31YJ6\iddqd[1] Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\Tobias\Local Settings\Temporary Internet Files\Content.IE5\UMDR6VAE\CAMFMBYL Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\Tobias\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Tobias\NTUSER.DAT.LOG Object is locked skipped
C:\Program Files\Teamspeak2_RC2\server.dbs Object is locked skipped
C:\Program Files\Teamspeak2_RC2\server.log Object is locked skipped
C:\Program Files\Teamspeak2_RC2\TSClient.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP69\A0005079.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP69\A0005080.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP69\A0005081.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP69\A0005085.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP69\A0005086.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP69\A0005087.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.rkn skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP69\A0005109.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP71\A0005196.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP71\A0005198.dll Infected: Trojan.Win32.Monder.eb skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP71\A0005199.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP76\A0006444.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP76\A0006445.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP76\A0006446.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP76\A0006447.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.vjr skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP76\A0006448.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.vnb skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP76\A0006449.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP76\A0006450.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP76\A0006451.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP76\A0006452.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP76\A0006453.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP76\A0006454.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP76\A0006455.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP76\A0006456.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP76\A0006457.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP76\A0006458.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.vjr skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP76\A0006459.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP76\A0006462.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP76\A0006464.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP76\A0006485.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP86\A0009762.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP87\A0009769.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.yff skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP88\A0009837.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.yff skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP91\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT.LOG Object is locked skipped
C:\WINDOWS\system32\config\sam Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\security Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM.LOG Object is locked skipped
C:\WINDOWS\system32\LogFiles\HTTPERR\httperr1.log Object is locked skipped
C:\WINDOWS\system32\vxjtgkem.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.yhx skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\WinUpdating.exe Infected: Trojan.Win32.Agent.giv skipped
C:\WINDOWS\Temp\Perflib_Perfdata_724.dat Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
D:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP91\change.log Object is locked skipped
Scan process completed.
After a trip to safe mode and running spybot, HJT reads
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:16:20 AM, on 6/9/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAJA.EXE
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {0A139928-ED72-4C8D-A14D-9490614AD0FD} - (no file)
O2 - BHO: (no name) - {2710B599-3262-4C03-87E9-7ABC72076486} - C:\WINDOWS\system32\qoMffEUk.dll (file missing)
O2 - BHO: (no name) - {39339088-C297-497B-AFE8-A64EE2B27858} - C:\WINDOWS\system32\hgGVpPfF.dll (file missing)
O2 - BHO: (no name) - {4F017E29-DE18-43CC-9FEF-8E7BCC487538} - C:\WINDOWS\system32\iifeCvSm.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7F1314F2-F379-4BA8-B4CB-B31D17B9C8E0} - C:\WINDOWS\system32\ddcYrqPI.dll (file missing)
O2 - BHO: (no name) - {BDB2A289-3605-4A8F-B3F3-F328207AF7E9} - (no file)
O2 - BHO: {48e95029-82ba-f68a-8904-3bc46c95173c} - {c37159c6-4cb3-4098-a86f-ab2892059e84} - C:\WINDOWS\system32\uwhyride.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\SMax4.exe" /tray
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [EPSON Stylus Photo R340 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAJA.EXE /P30 "EPSON Stylus Photo R340 Series" /O6 "USB001" /M "Stylus Photo R340"
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [BM6fd35c23] Rundll32.exe "C:\WINDOWS\system32\vxjtgkem.dll",s
O4 - HKLM\..\Run: [6ce06fbf] rundll32.exe "C:\WINDOWS\system32\ctvjfjsd.dll",b
O4 - HKCU\..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe -autorun
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Policies\Explorer\Run: [WinUpdating] WinUpdating.exe
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase9563.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A1C80F3C-D189-4D63-9814-1179BD40C410}: NameServer = 68.87.71.226,68.87.73.242
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 6628 bytes
This is my first time posting something like this, so I apologize if I did it wrong. If any other information is needed just let me know, and thanks in advance!
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Sunday, June 08, 2008 11:07:16 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 8/06/2008
Kaspersky Anti-Virus database records: 840603
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
Scan Statistics:
Total number of scanned objects: 184471
Number of viruses found: 11
Number of infected objects: 46
Number of suspicious objects: 0
Duration of the scan process: 02:34:03
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Signus\Application Data\Aim\impyggep\Numenor37\cert8.db Object is locked skipped
C:\Documents and Settings\Signus\Application Data\Aim\impyggep\Numenor37\key3.db Object is locked skipped
C:\Documents and Settings\Signus\Application Data\Mozilla\Firefox\Profiles\7b3s6n2o.default\cert8.db Object is locked skipped
C:\Documents and Settings\Signus\Application Data\Mozilla\Firefox\Profiles\7b3s6n2o.default\history.dat Object is locked skipped
C:\Documents and Settings\Signus\Application Data\Mozilla\Firefox\Profiles\7b3s6n2o.default\key3.db Object is locked skipped
C:\Documents and Settings\Signus\Application Data\Mozilla\Firefox\Profiles\7b3s6n2o.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Signus\Application Data\Mozilla\Firefox\Profiles\7b3s6n2o.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Signus\Application Data\Mozilla\Firefox\Profiles\7b3s6n2o.default\webappsstore.sqlite Object is locked skipped
C:\Documents and Settings\Signus\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Signus\Desktop\Zone of Silence\Antivirus\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Signus\Desktop\Zone of Silence\Antivirus\SmitfraudFix.exe/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Signus\Desktop\Zone of Silence\Antivirus\SmitfraudFix.exe RAR: infected - 1 skipped
C:\Documents and Settings\Signus\Local Settings\Application Data\Ahead\Nero Home\bl.db Object is locked skipped
C:\Documents and Settings\Signus\Local Settings\Application Data\Ahead\Nero Home\is2.db Object is locked skipped
C:\Documents and Settings\Signus\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Signus\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Signus\Local Settings\Application Data\Mozilla\Firefox\Profiles\7b3s6n2o.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Signus\Local Settings\Application Data\Mozilla\Firefox\Profiles\7b3s6n2o.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Signus\Local Settings\Application Data\Mozilla\Firefox\Profiles\7b3s6n2o.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Signus\Local Settings\Application Data\Mozilla\Firefox\Profiles\7b3s6n2o.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Signus\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Signus\Local Settings\History\History.IE5\MSHist012008060820080609\index.dat Object is locked skipped
C:\Documents and Settings\Signus\Local Settings\Temp\Free Download Manager\tic253.tmp Object is locked skipped
C:\Documents and Settings\Signus\Local Settings\Temp\sqlite_emgsIfzIwtuHETM Object is locked skipped
C:\Documents and Settings\Signus\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Signus\Local Settings\Temporary Internet Files\Content.IE5\WHYZWL6Z\kb516107[1] Infected: Trojan.Win32.Agent.reo skipped
C:\Documents and Settings\Signus\Local Settings\Temporary Internet Files\Content.IE5\ZKUOT7PQ\kb516107[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.yhx skipped
C:\Documents and Settings\Signus\My Documents\My Music\iTunes\iTunes Music\Adobe Premiere CS3 Pro Keygenerator.rar/Setup+Patch.exe Infected: P2P-Worm.Win32.Agent.bm skipped
C:\Documents and Settings\Signus\My Documents\My Music\iTunes\iTunes Music\Adobe Premiere CS3 Pro Keygenerator.rar CAB: infected - 1 skipped
C:\Documents and Settings\Signus\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Signus\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Tobias\Local Settings\Temporary Internet Files\Content.IE5\5HUS6U5X\hctp[1] Infected: Trojan.Win32.Monder.eb skipped
C:\Documents and Settings\Tobias\Local Settings\Temporary Internet Files\Content.IE5\7I9YWGTS\CAIF6FUL Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\Tobias\Local Settings\Temporary Internet Files\Content.IE5\7I9YWGTS\query[1] Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\Tobias\Local Settings\Temporary Internet Files\Content.IE5\F2V31YJ6\iddqd[1] Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\Tobias\Local Settings\Temporary Internet Files\Content.IE5\UMDR6VAE\CAMFMBYL Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\Tobias\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Tobias\NTUSER.DAT.LOG Object is locked skipped
C:\Program Files\Teamspeak2_RC2\server.dbs Object is locked skipped
C:\Program Files\Teamspeak2_RC2\server.log Object is locked skipped
C:\Program Files\Teamspeak2_RC2\TSClient.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP69\A0005079.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP69\A0005080.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP69\A0005081.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP69\A0005085.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP69\A0005086.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP69\A0005087.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.rkn skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP69\A0005109.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP71\A0005196.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP71\A0005198.dll Infected: Trojan.Win32.Monder.eb skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP71\A0005199.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP76\A0006444.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP76\A0006445.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP76\A0006446.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP76\A0006447.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.vjr skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP76\A0006448.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.vnb skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP76\A0006449.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP76\A0006450.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP76\A0006451.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP76\A0006452.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP76\A0006453.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP76\A0006454.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP76\A0006455.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP76\A0006456.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP76\A0006457.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP76\A0006458.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.vjr skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP76\A0006459.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP76\A0006462.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP76\A0006464.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP76\A0006485.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP86\A0009762.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP87\A0009769.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.yff skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP88\A0009837.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.yff skipped
C:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP91\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT.LOG Object is locked skipped
C:\WINDOWS\system32\config\sam Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\security Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM.LOG Object is locked skipped
C:\WINDOWS\system32\LogFiles\HTTPERR\httperr1.log Object is locked skipped
C:\WINDOWS\system32\vxjtgkem.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.yhx skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\WinUpdating.exe Infected: Trojan.Win32.Agent.giv skipped
C:\WINDOWS\Temp\Perflib_Perfdata_724.dat Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
D:\System Volume Information\_restore{6D8271DE-3058-4F00-9755-4B1477455823}\RP91\change.log Object is locked skipped
Scan process completed.
After a trip to safe mode and running spybot, HJT reads
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:16:20 AM, on 6/9/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAJA.EXE
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {0A139928-ED72-4C8D-A14D-9490614AD0FD} - (no file)
O2 - BHO: (no name) - {2710B599-3262-4C03-87E9-7ABC72076486} - C:\WINDOWS\system32\qoMffEUk.dll (file missing)
O2 - BHO: (no name) - {39339088-C297-497B-AFE8-A64EE2B27858} - C:\WINDOWS\system32\hgGVpPfF.dll (file missing)
O2 - BHO: (no name) - {4F017E29-DE18-43CC-9FEF-8E7BCC487538} - C:\WINDOWS\system32\iifeCvSm.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7F1314F2-F379-4BA8-B4CB-B31D17B9C8E0} - C:\WINDOWS\system32\ddcYrqPI.dll (file missing)
O2 - BHO: (no name) - {BDB2A289-3605-4A8F-B3F3-F328207AF7E9} - (no file)
O2 - BHO: {48e95029-82ba-f68a-8904-3bc46c95173c} - {c37159c6-4cb3-4098-a86f-ab2892059e84} - C:\WINDOWS\system32\uwhyride.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\SMax4.exe" /tray
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [EPSON Stylus Photo R340 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAJA.EXE /P30 "EPSON Stylus Photo R340 Series" /O6 "USB001" /M "Stylus Photo R340"
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [BM6fd35c23] Rundll32.exe "C:\WINDOWS\system32\vxjtgkem.dll",s
O4 - HKLM\..\Run: [6ce06fbf] rundll32.exe "C:\WINDOWS\system32\ctvjfjsd.dll",b
O4 - HKCU\..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe -autorun
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Policies\Explorer\Run: [WinUpdating] WinUpdating.exe
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase9563.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A1C80F3C-D189-4D63-9814-1179BD40C410}: NameServer = 68.87.71.226,68.87.73.242
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 6628 bytes
This is my first time posting something like this, so I apologize if I did it wrong. If any other information is needed just let me know, and thanks in advance!