XucoKurosaki
New member
Hello!
I am having a big spyware problem. First of all let me say that I am posting from a different computer as the infected computer is unable to access the internet. When I run spybot there is always something it is unable to remove: AdBreak. I tried to do a system restore but it has been disabled and I cannot reenable it. The taskmanager has also been disabled (it says by admin but no one actually did this) and I cannot access the user accounts setting in the control panel. The taskbar is also acting funny, as none of the running programs or windows show up on it. Well, here is the HJT log. I thank you for your help in advance
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:19:14 PM, on 3/15/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5346.0005)
Boot mode: Safe mode
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\rxjddnvj.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp_adbe/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp_adbe/defaults/sp/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\rxjddnvj.exe,
O1 - Hosts: 194.54.90.226 www.google.com
O1 - Hosts: 194.54.90.226 www.google.ca
O1 - Hosts: 194.54.90.226 www.google.com.ag
O1 - Hosts: 194.54.90.226 www.google.com.ar
O1 - Hosts: 194.54.90.226 www.google.com.au
O1 - Hosts: 194.54.90.226 www.google.at
O1 - Hosts: 194.54.90.226 www.google.az
O1 - Hosts: 194.54.90.226 www.google.be
O1 - Hosts: 194.54.90.226 www.google.com.br
O1 - Hosts: 194.54.90.226 www.google.vg
O1 - Hosts: 194.54.90.226 www.google.bi
O1 - Hosts: 194.54.90.226 www.google.ca
O1 - Hosts: 194.54.90.226 www.google.td
O1 - Hosts: 194.54.90.226 www.google.cl
O1 - Hosts: 194.54.90.226 www.google.com.co
O1 - Hosts: 194.54.90.226 www.google.co.cr
O1 - Hosts: 194.54.90.226 www.google.dk
O1 - Hosts: 194.54.90.226 www.google.com.do
O1 - Hosts: 194.54.90.226 www.google.fm
O1 - Hosts: 194.54.90.226 www.google.fi
O1 - Hosts: 194.54.90.226 www.google.fr
O1 - Hosts: 194.54.90.226 www.google.gm
O1 - Hosts: 194.54.90.226 www.google.ge
O1 - Hosts: 194.54.90.226 www.google.de
O1 - Hosts: 194.54.90.226 www.google.com.gi
O1 - Hosts: 194.54.90.226 www.google.com.gr
O1 - Hosts: 194.54.90.226 www.google.gl
O1 - Hosts: 194.54.90.226 www.google.gg
O1 - Hosts: 194.54.90.226 www.google.co.il
O1 - Hosts: 194.54.90.226 www.google.it
O1 - Hosts: 194.54.90.226 www.google.co.kr
O1 - Hosts: 194.54.90.226 www.google.lu
O1 - Hosts: 194.54.90.226 www.google.mw
O1 - Hosts: 194.54.90.226 www.google.ro
O1 - Hosts: 194.54.90.226 www.google.se
O1 - Hosts: 194.54.90.226 www.google.co.uk
O1 - Hosts: 194.54.90.226 www.google.uz
O1 - Hosts: 194.54.90.226 google.com
O1 - Hosts: 194.54.90.226 google.ca
O1 - Hosts: 194.54.90.226 google.com.ag
O1 - Hosts: 194.54.90.226 google.com.ar
O1 - Hosts: 194.54.90.226 google.com.au
O1 - Hosts: 194.54.90.226 google.at
O1 - Hosts: 194.54.90.226 google.az
O1 - Hosts: 194.54.90.226 google.be
O1 - Hosts: 194.54.90.226 google.com.br
O1 - Hosts: 194.54.90.226 google.vg
O1 - Hosts: 194.54.90.226 google.bi
O1 - Hosts: 194.54.90.226 google.ca
O1 - Hosts: 194.54.90.226 google.td
O1 - Hosts: 194.54.90.226 google.cl
O1 - Hosts: 194.54.90.226 google.com.co
O1 - Hosts: 194.54.90.226 google.co.cr
O1 - Hosts: 194.54.90.226 google.dk
O1 - Hosts: 194.54.90.226 google.com.do
O1 - Hosts: 194.54.90.226 google.fm
O1 - Hosts: 194.54.90.226 google.fi
O1 - Hosts: 194.54.90.226 google.fr
O1 - Hosts: 194.54.90.226 google.gm
O1 - Hosts: 194.54.90.226 google.ge
O1 - Hosts: 194.54.90.226 google.de
O1 - Hosts: 194.54.90.226 google.com.gi
O1 - Hosts: 194.54.90.226 google.com.gr
O1 - Hosts: 194.54.90.226 google.gl
O1 - Hosts: 194.54.90.226 google.gg
O1 - Hosts: 194.54.90.226 google.co.il
O1 - Hosts: 194.54.90.226 google.it
O1 - Hosts: 194.54.90.226 google.co.kr
O1 - Hosts: 194.54.90.226 google.lu
O1 - Hosts: 194.54.90.226 google.mw
O1 - Hosts: 194.54.90.226 google.ro
O1 - Hosts: 194.54.90.226 google.se
O1 - Hosts: 194.54.90.226 google.co.uk
O1 - Hosts: 194.54.90.226 google.uz
O1 - Hosts: 194.54.90.226 search.yahoo.com
O1 - Hosts: 194.54.90.226 de.search.yahoo.com
O1 - Hosts: 194.54.90.226 search.msn.com
O1 - Hosts: 194.54.90.226 search.msn.de
O1 - Hosts: 194.54.90.226 search.live.com
O1 - Hosts: ÿÿÿñœ(›ñ¶ˆEñxñl=›xñoYExñxñl=›live.com
O1 - Hosts: @«ìð«7‘
O2 - BHO: (no name) - {00000000-d9e3-4bc6-a0bd-3d0ca4be5271} - (no file)
O2 - BHO: (no name) - {00000012-890e-4aac-afd9-eff6954a34dd} - (no file)
O2 - BHO: (no name) - {029e02f0-a0e5-4b19-b958-7bf2db29fb13} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {06dfedaa-6196-11d5-bfc8-00508b4a487d} - (no file)
O2 - BHO: (no name) - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - (no file)
O2 - BHO: (no name) - {1adbcce8-cf84-441e-9b38-afc7a19c06a4} - (no file)
O2 - BHO: (no name) - {2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71} - (no file)
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: (no name) - {51641ef3-8a7a-4d84-8659-b0911e947cc8} - (no file)
O2 - BHO: (no name) - {53C330D6-A4AB-419B-B45D-FD4411C1FEF4} - (no file)
O2 - BHO: (no name) - {54645654-2225-4455-44A1-9F4543D34546} - (no file)
O2 - BHO: (no name) - {548E1154-FA99-4B77-9FC5-02C9D8C9D24D} - (no file)
O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file)
O2 - BHO: (no name) - {6abc861a-31e7-4d91-b43b-d3c98f22a5c0} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: BndBlock4 BHO Class - {8F9E2BE3-766D-4831-BB0E-766D5B819995} - C:\Program Files\QdrDrive\QdrDrive9.dll (file missing)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {944864a5-3916-46e2-96a9-a2e84f3f1208} - (no file)
O2 - BHO: (no name) - {a4a435cf-3583-11d4-91bd-0048546a1450} - (no file)
O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file)
O2 - BHO: (no name) - {bb936323-19fa-4521-ba29-eca6a121bc78} - (no file)
O2 - BHO: (no name) - {c2680e10-1655-4a0e-87f8-4259325a84b7} - (no file)
O2 - BHO: (no name) - {c4ca6559-2cf1-48b6-96b2-8340a06fd129} - (no file)
O2 - BHO: (no name) - {c5af2622-8c75-4dfb-9693-23ab7686a456} - (no file)
O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file)
O2 - BHO: (no name) - {d8eaf51a-1dd1-11b2-a60c-f58b1c66741b} - C:\WINDOWS\fyxevybo.dll
O2 - BHO: (no name) - {d8efadf1-9009-11d6-8c73-608c5dc19089} - (no file)
O2 - BHO: (no name) - {e9147a0a-a866-4214-b47c-da821891240f} - (no file)
O2 - BHO: (no name) - {e9306072-417e-43e3-81d5-369490beef7c} - (no file)
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-3384558774-311419948-3184442665-1005\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User '?')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2DFF31F9-7893-4922-AF66-C9A1EB4EBB31} (Rhapsody Player Engine) - http://forms.real.com/real/player/d.../mrkt/rhapx/RhapsodyPlayerEngine_Inst_Win.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1146513545890
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin9USA.cab
O16 - DPF: {E856B973-45FD-4559-8F82-EAB539144667} (Dell PC Checkup Installer Control) - http://pccheckup.dellfix.com/rel/41/install/gtdownde.cab
O18 - Filter hijack: text/html - {07851C6A-1C43-41d9-8319-BC89154A8C00} - C:\Program Files\RcvSystem\httpdchk.dll
O20 - Winlogon Notify: mljjg - C:\WINDOWS\system32\mljjg.dll (file missing)
O22 - SharedTaskScheduler: IE Component Categories cache daemon - {553858A7-4922-4e7e-B1C1-97140C1C16EF} - C:\WINDOWS\system32\ieframe.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: dlbu_device - Dell - C:\WINDOWS\system32\dlbucoms.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LibUsb-Win32 - Daemon, Version 0.1.10.1 (libusbd) - http://libusb-win32.sourceforge.net - C:\WINDOWS\system32\libusbd-nt.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: mental ray 3.5 Satellite (32-bit) (mi-raysat_3dsmax9_32) - Unknown owner - C:\Program Files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe (file missing)
--
End of file - 11858 bytes
I am having a big spyware problem. First of all let me say that I am posting from a different computer as the infected computer is unable to access the internet. When I run spybot there is always something it is unable to remove: AdBreak. I tried to do a system restore but it has been disabled and I cannot reenable it. The taskmanager has also been disabled (it says by admin but no one actually did this) and I cannot access the user accounts setting in the control panel. The taskbar is also acting funny, as none of the running programs or windows show up on it. Well, here is the HJT log. I thank you for your help in advance

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:19:14 PM, on 3/15/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5346.0005)
Boot mode: Safe mode
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\rxjddnvj.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp_adbe/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp_adbe/defaults/sp/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\rxjddnvj.exe,
O1 - Hosts: 194.54.90.226 www.google.com
O1 - Hosts: 194.54.90.226 www.google.ca
O1 - Hosts: 194.54.90.226 www.google.com.ag
O1 - Hosts: 194.54.90.226 www.google.com.ar
O1 - Hosts: 194.54.90.226 www.google.com.au
O1 - Hosts: 194.54.90.226 www.google.at
O1 - Hosts: 194.54.90.226 www.google.az
O1 - Hosts: 194.54.90.226 www.google.be
O1 - Hosts: 194.54.90.226 www.google.com.br
O1 - Hosts: 194.54.90.226 www.google.vg
O1 - Hosts: 194.54.90.226 www.google.bi
O1 - Hosts: 194.54.90.226 www.google.ca
O1 - Hosts: 194.54.90.226 www.google.td
O1 - Hosts: 194.54.90.226 www.google.cl
O1 - Hosts: 194.54.90.226 www.google.com.co
O1 - Hosts: 194.54.90.226 www.google.co.cr
O1 - Hosts: 194.54.90.226 www.google.dk
O1 - Hosts: 194.54.90.226 www.google.com.do
O1 - Hosts: 194.54.90.226 www.google.fm
O1 - Hosts: 194.54.90.226 www.google.fi
O1 - Hosts: 194.54.90.226 www.google.fr
O1 - Hosts: 194.54.90.226 www.google.gm
O1 - Hosts: 194.54.90.226 www.google.ge
O1 - Hosts: 194.54.90.226 www.google.de
O1 - Hosts: 194.54.90.226 www.google.com.gi
O1 - Hosts: 194.54.90.226 www.google.com.gr
O1 - Hosts: 194.54.90.226 www.google.gl
O1 - Hosts: 194.54.90.226 www.google.gg
O1 - Hosts: 194.54.90.226 www.google.co.il
O1 - Hosts: 194.54.90.226 www.google.it
O1 - Hosts: 194.54.90.226 www.google.co.kr
O1 - Hosts: 194.54.90.226 www.google.lu
O1 - Hosts: 194.54.90.226 www.google.mw
O1 - Hosts: 194.54.90.226 www.google.ro
O1 - Hosts: 194.54.90.226 www.google.se
O1 - Hosts: 194.54.90.226 www.google.co.uk
O1 - Hosts: 194.54.90.226 www.google.uz
O1 - Hosts: 194.54.90.226 google.com
O1 - Hosts: 194.54.90.226 google.ca
O1 - Hosts: 194.54.90.226 google.com.ag
O1 - Hosts: 194.54.90.226 google.com.ar
O1 - Hosts: 194.54.90.226 google.com.au
O1 - Hosts: 194.54.90.226 google.at
O1 - Hosts: 194.54.90.226 google.az
O1 - Hosts: 194.54.90.226 google.be
O1 - Hosts: 194.54.90.226 google.com.br
O1 - Hosts: 194.54.90.226 google.vg
O1 - Hosts: 194.54.90.226 google.bi
O1 - Hosts: 194.54.90.226 google.ca
O1 - Hosts: 194.54.90.226 google.td
O1 - Hosts: 194.54.90.226 google.cl
O1 - Hosts: 194.54.90.226 google.com.co
O1 - Hosts: 194.54.90.226 google.co.cr
O1 - Hosts: 194.54.90.226 google.dk
O1 - Hosts: 194.54.90.226 google.com.do
O1 - Hosts: 194.54.90.226 google.fm
O1 - Hosts: 194.54.90.226 google.fi
O1 - Hosts: 194.54.90.226 google.fr
O1 - Hosts: 194.54.90.226 google.gm
O1 - Hosts: 194.54.90.226 google.ge
O1 - Hosts: 194.54.90.226 google.de
O1 - Hosts: 194.54.90.226 google.com.gi
O1 - Hosts: 194.54.90.226 google.com.gr
O1 - Hosts: 194.54.90.226 google.gl
O1 - Hosts: 194.54.90.226 google.gg
O1 - Hosts: 194.54.90.226 google.co.il
O1 - Hosts: 194.54.90.226 google.it
O1 - Hosts: 194.54.90.226 google.co.kr
O1 - Hosts: 194.54.90.226 google.lu
O1 - Hosts: 194.54.90.226 google.mw
O1 - Hosts: 194.54.90.226 google.ro
O1 - Hosts: 194.54.90.226 google.se
O1 - Hosts: 194.54.90.226 google.co.uk
O1 - Hosts: 194.54.90.226 google.uz
O1 - Hosts: 194.54.90.226 search.yahoo.com
O1 - Hosts: 194.54.90.226 de.search.yahoo.com
O1 - Hosts: 194.54.90.226 search.msn.com
O1 - Hosts: 194.54.90.226 search.msn.de
O1 - Hosts: 194.54.90.226 search.live.com
O1 - Hosts: ÿÿÿñœ(›ñ¶ˆEñxñl=›xñoYExñxñl=›live.com
O1 - Hosts: @«ìð«7‘
O2 - BHO: (no name) - {00000000-d9e3-4bc6-a0bd-3d0ca4be5271} - (no file)
O2 - BHO: (no name) - {00000012-890e-4aac-afd9-eff6954a34dd} - (no file)
O2 - BHO: (no name) - {029e02f0-a0e5-4b19-b958-7bf2db29fb13} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {06dfedaa-6196-11d5-bfc8-00508b4a487d} - (no file)
O2 - BHO: (no name) - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - (no file)
O2 - BHO: (no name) - {1adbcce8-cf84-441e-9b38-afc7a19c06a4} - (no file)
O2 - BHO: (no name) - {2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71} - (no file)
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: (no name) - {51641ef3-8a7a-4d84-8659-b0911e947cc8} - (no file)
O2 - BHO: (no name) - {53C330D6-A4AB-419B-B45D-FD4411C1FEF4} - (no file)
O2 - BHO: (no name) - {54645654-2225-4455-44A1-9F4543D34546} - (no file)
O2 - BHO: (no name) - {548E1154-FA99-4B77-9FC5-02C9D8C9D24D} - (no file)
O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file)
O2 - BHO: (no name) - {6abc861a-31e7-4d91-b43b-d3c98f22a5c0} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: BndBlock4 BHO Class - {8F9E2BE3-766D-4831-BB0E-766D5B819995} - C:\Program Files\QdrDrive\QdrDrive9.dll (file missing)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {944864a5-3916-46e2-96a9-a2e84f3f1208} - (no file)
O2 - BHO: (no name) - {a4a435cf-3583-11d4-91bd-0048546a1450} - (no file)
O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file)
O2 - BHO: (no name) - {bb936323-19fa-4521-ba29-eca6a121bc78} - (no file)
O2 - BHO: (no name) - {c2680e10-1655-4a0e-87f8-4259325a84b7} - (no file)
O2 - BHO: (no name) - {c4ca6559-2cf1-48b6-96b2-8340a06fd129} - (no file)
O2 - BHO: (no name) - {c5af2622-8c75-4dfb-9693-23ab7686a456} - (no file)
O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file)
O2 - BHO: (no name) - {d8eaf51a-1dd1-11b2-a60c-f58b1c66741b} - C:\WINDOWS\fyxevybo.dll
O2 - BHO: (no name) - {d8efadf1-9009-11d6-8c73-608c5dc19089} - (no file)
O2 - BHO: (no name) - {e9147a0a-a866-4214-b47c-da821891240f} - (no file)
O2 - BHO: (no name) - {e9306072-417e-43e3-81d5-369490beef7c} - (no file)
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-3384558774-311419948-3184442665-1005\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User '?')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2DFF31F9-7893-4922-AF66-C9A1EB4EBB31} (Rhapsody Player Engine) - http://forms.real.com/real/player/d.../mrkt/rhapx/RhapsodyPlayerEngine_Inst_Win.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1146513545890
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin9USA.cab
O16 - DPF: {E856B973-45FD-4559-8F82-EAB539144667} (Dell PC Checkup Installer Control) - http://pccheckup.dellfix.com/rel/41/install/gtdownde.cab
O18 - Filter hijack: text/html - {07851C6A-1C43-41d9-8319-BC89154A8C00} - C:\Program Files\RcvSystem\httpdchk.dll
O20 - Winlogon Notify: mljjg - C:\WINDOWS\system32\mljjg.dll (file missing)
O22 - SharedTaskScheduler: IE Component Categories cache daemon - {553858A7-4922-4e7e-B1C1-97140C1C16EF} - C:\WINDOWS\system32\ieframe.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: dlbu_device - Dell - C:\WINDOWS\system32\dlbucoms.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LibUsb-Win32 - Daemon, Version 0.1.10.1 (libusbd) - http://libusb-win32.sourceforge.net - C:\WINDOWS\system32\libusbd-nt.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: mental ray 3.5 Satellite (32-bit) (mi-raysat_3dsmax9_32) - Unknown owner - C:\Program Files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe (file missing)
--
End of file - 11858 bytes