FilthyAssistant
New member
Background time: About a week ago I started getting odd redirects from the firefox start google page. Clicking anything other than the first link, or a site I'd never been to before, would redirect to one of many sites, with an image of a green globe-type thing near the address bar. I found that the regular google.com wouldn't do that. I scanned with Malwarebytes and it found a trojan.dropper. I removed it, restarted, and things seemed fine. Then, the next day, when I woke up (the computer was on when I was asleep, which I'm obviously not going to do anymore) there was a rogue anti-spyware program running. It restricted access to pretty much everything, but I was able to find its root process (svchAst.exe) and stop it, disable it from startup, etc. I restarted, scanned with MWB again, and it removed it all. After this I scanned with spybot, it found a few things and made some spybotdeleting registry keys.
Since then, I don't SEEM to have any problems but scanning with spybot keeps returning a few files under win32.tdss.rtk. Though it says "problem fixed" it comes up every time I re-scan. Anyway, that was long-winded. Here's the HijackThis log.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:05:00 AM, on 8/22/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\SYSTEM32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\Explorer.EXE
C:\WINNT\CTHELPER.EXE
C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb12.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINNT\system32\RUNDLL32.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\WINNT\system32\ctfmon.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINNT\System32\CTSvcCDA.EXE
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\System32\HPZipm12.exe
C:\WINNT\system32\PSIService.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINNT\wanmpsvc.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.yahoo.com/search?p=%s
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb12.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINNT\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\RunOnce: [SpybotDeletingA1918] command.com /c del "C:\WINNT\system32\drivers\SKYNETctrknukn.sys_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3205] cmd.exe /c del "C:\WINNT\system32\drivers\SKYNETctrknukn.sys_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1290] command.com /c del "C:\WINNT\system32\drivers\SKYNETctrknukn.sys"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8787] cmd.exe /c del "C:\WINNT\system32\drivers\SKYNETctrknukn.sys"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6521] command.com /c del "C:\WINNT\system32\SKYNETuegjrukl.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7517] cmd.exe /c del "C:\WINNT\system32\SKYNETuegjrukl.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9044] command.com /c del "C:\WINNT\system32\SKYNETuegjrukl.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9969] cmd.exe /c del "C:\WINNT\system32\SKYNETuegjrukl.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA167] command.com /c del "C:\WINNT\system32\SKYNETvudoxwmn.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5866] cmd.exe /c del "C:\WINNT\system32\SKYNETvudoxwmn.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6433] command.com /c del "C:\WINNT\system32\SKYNETvudoxwmn.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4681] cmd.exe /c del "C:\WINNT\system32\SKYNETvudoxwmn.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1805] command.com /c del "C:\WINNT\system32\SKYNETawvcaenc.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4891] cmd.exe /c del "C:\WINNT\system32\SKYNETawvcaenc.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6724] command.com /c del "C:\WINNT\system32\SKYNETawvcaenc.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1246] cmd.exe /c del "C:\WINNT\system32\SKYNETawvcaenc.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7406] command.com /c del "C:\WINNT\system32\SKYNETinltxyut.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7434] cmd.exe /c del "C:\WINNT\system32\SKYNETinltxyut.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7072] command.com /c del "C:\WINNT\system32\SKYNETinltxyut.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3843] cmd.exe /c del "C:\WINNT\system32\SKYNETinltxyut.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3058] command.com /c del "C:\WINNT\system32\drivers\SKYNETctrknukn.sys_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5195] cmd.exe /c del "C:\WINNT\system32\drivers\SKYNETctrknukn.sys_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7597] command.com /c del "C:\WINNT\system32\drivers\SKYNETctrknukn.sys"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2333] cmd.exe /c del "C:\WINNT\system32\drivers\SKYNETctrknukn.sys"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9465] command.com /c del "C:\WINNT\system32\SKYNETuegjrukl.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4710] cmd.exe /c del "C:\WINNT\system32\SKYNETuegjrukl.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9323] command.com /c del "C:\WINNT\system32\SKYNETuegjrukl.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC960] cmd.exe /c del "C:\WINNT\system32\SKYNETuegjrukl.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5619] command.com /c del "C:\WINNT\system32\SKYNETvudoxwmn.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1975] cmd.exe /c del "C:\WINNT\system32\SKYNETvudoxwmn.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8965] command.com /c del "C:\WINNT\system32\SKYNETvudoxwmn.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2401] cmd.exe /c del "C:\WINNT\system32\SKYNETvudoxwmn.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8505] command.com /c del "C:\WINNT\system32\SKYNETawvcaenc.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC525] cmd.exe /c del "C:\WINNT\system32\SKYNETawvcaenc.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA182] command.com /c del "C:\WINNT\system32\SKYNETawvcaenc.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6172] cmd.exe /c del "C:\WINNT\system32\SKYNETawvcaenc.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6007] command.com /c del "C:\WINNT\system32\SKYNETinltxyut.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC285] cmd.exe /c del "C:\WINNT\system32\SKYNETinltxyut.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7329] command.com /c del "C:\WINNT\system32\SKYNETinltxyut.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6276] cmd.exe /c del "C:\WINNT\system32\SKYNETinltxyut.dat"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB8278] command.com /c del "C:\WINNT\system32\drivers\SKYNETctrknukn.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3359] cmd.exe /c del "C:\WINNT\system32\drivers\SKYNETctrknukn.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2492] command.com /c del "C:\WINNT\system32\drivers\SKYNETctrknukn.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5009] cmd.exe /c del "C:\WINNT\system32\drivers\SKYNETctrknukn.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7839] command.com /c del "C:\WINNT\system32\SKYNETuegjrukl.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3890] cmd.exe /c del "C:\WINNT\system32\SKYNETuegjrukl.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8543] command.com /c del "C:\WINNT\system32\SKYNETuegjrukl.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD838] cmd.exe /c del "C:\WINNT\system32\SKYNETuegjrukl.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2703] command.com /c del "C:\WINNT\system32\SKYNETvudoxwmn.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5156] cmd.exe /c del "C:\WINNT\system32\SKYNETvudoxwmn.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8635] command.com /c del "C:\WINNT\system32\SKYNETvudoxwmn.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3206] cmd.exe /c del "C:\WINNT\system32\SKYNETvudoxwmn.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7268] command.com /c del "C:\WINNT\system32\SKYNETawvcaenc.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7883] cmd.exe /c del "C:\WINNT\system32\SKYNETawvcaenc.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3137] command.com /c del "C:\WINNT\system32\SKYNETawvcaenc.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2801] cmd.exe /c del "C:\WINNT\system32\SKYNETawvcaenc.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5430] command.com /c del "C:\WINNT\system32\SKYNETinltxyut.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6454] cmd.exe /c del "C:\WINNT\system32\SKYNETinltxyut.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5850] command.com /c del "C:\WINNT\system32\SKYNETinltxyut.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1794] cmd.exe /c del "C:\WINNT\system32\SKYNETinltxyut.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8270] command.com /c del "C:\WINNT\system32\drivers\SKYNETctrknukn.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6390] cmd.exe /c del "C:\WINNT\system32\drivers\SKYNETctrknukn.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2100] command.com /c del "C:\WINNT\system32\drivers\SKYNETctrknukn.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1071] cmd.exe /c del "C:\WINNT\system32\drivers\SKYNETctrknukn.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3462] command.com /c del "C:\WINNT\system32\SKYNETuegjrukl.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5639] cmd.exe /c del "C:\WINNT\system32\SKYNETuegjrukl.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1517] command.com /c del "C:\WINNT\system32\SKYNETuegjrukl.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9852] cmd.exe /c del "C:\WINNT\system32\SKYNETuegjrukl.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6736] command.com /c del "C:\WINNT\system32\SKYNETvudoxwmn.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8292] cmd.exe /c del "C:\WINNT\system32\SKYNETvudoxwmn.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4681] command.com /c del "C:\WINNT\system32\SKYNETvudoxwmn.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6962] cmd.exe /c del "C:\WINNT\system32\SKYNETvudoxwmn.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3065] command.com /c del "C:\WINNT\system32\SKYNETawvcaenc.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5022] cmd.exe /c del "C:\WINNT\system32\SKYNETawvcaenc.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2022] command.com /c del "C:\WINNT\system32\SKYNETawvcaenc.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2649] cmd.exe /c del "C:\WINNT\system32\SKYNETawvcaenc.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9731] command.com /c del "C:\WINNT\system32\SKYNETinltxyut.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9243] cmd.exe /c del "C:\WINNT\system32\SKYNETinltxyut.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8781] command.com /c del "C:\WINNT\system32\SKYNETinltxyut.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3130] cmd.exe /c del "C:\WINNT\system32\SKYNETinltxyut.dat"
O8 - Extra context menu item: Blocking access to the document address by AliveProxy - C:\Program Files\AiS AliveProxy Server\aisBlockDocument.html
O8 - Extra context menu item: Blocking access to the image address by AliveProxy - C:\Program Files\AiS AliveProxy Server\aisBlockImage.html
O8 - Extra context menu item: Blocking access to the link address by AliveProxy - C:\Program Files\AiS AliveProxy Server\aisBlockLink.html
O8 - Extra context menu item: Cut proxy addresses from selected text by AliveProxy - C:\Program Files\AiS AliveProxy Server\aisCutProxyFromSelectedTåxt.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Owner\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5483.cab
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin11USA.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
O16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} (System Requirements Lab) - http://www.srtest.com/sysreqlab.cab
O16 - DPF: {E991BDE0-9816-4094-853E-6BDB60F0342D} (Get_ActiveX Control) - http://apps.corel.com/nos_dl_manager/plugin/IENetOpPlugin.ocx
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: ddccdab - ddccdab.dll (file missing)
O20 - Winlogon Notify: jkkljhi - jkkljhi.dll (file missing)
O20 - Winlogon Notify: rastask - c:\winnt\repair\rastask.dll (file missing)
O20 - Winlogon Notify: tuvvtqn - tuvvtqn.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTSvcCDA.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Net Agent - Unknown owner - C:\WINNT\dls0523pmw.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\System32\HPZipm12.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINNT\wanmpsvc.exe
O24 - Desktop Component 0: (no name) - http://www.thebestpageintheuniverse.net/images/razor2.gif
--
End of file - 15723 bytes
Since then, I don't SEEM to have any problems but scanning with spybot keeps returning a few files under win32.tdss.rtk. Though it says "problem fixed" it comes up every time I re-scan. Anyway, that was long-winded. Here's the HijackThis log.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:05:00 AM, on 8/22/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\SYSTEM32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\Explorer.EXE
C:\WINNT\CTHELPER.EXE
C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb12.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINNT\system32\RUNDLL32.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\WINNT\system32\ctfmon.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINNT\System32\CTSvcCDA.EXE
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\System32\HPZipm12.exe
C:\WINNT\system32\PSIService.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINNT\wanmpsvc.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.yahoo.com/search?p=%s
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb12.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINNT\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\RunOnce: [SpybotDeletingA1918] command.com /c del "C:\WINNT\system32\drivers\SKYNETctrknukn.sys_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3205] cmd.exe /c del "C:\WINNT\system32\drivers\SKYNETctrknukn.sys_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1290] command.com /c del "C:\WINNT\system32\drivers\SKYNETctrknukn.sys"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8787] cmd.exe /c del "C:\WINNT\system32\drivers\SKYNETctrknukn.sys"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6521] command.com /c del "C:\WINNT\system32\SKYNETuegjrukl.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7517] cmd.exe /c del "C:\WINNT\system32\SKYNETuegjrukl.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9044] command.com /c del "C:\WINNT\system32\SKYNETuegjrukl.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9969] cmd.exe /c del "C:\WINNT\system32\SKYNETuegjrukl.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA167] command.com /c del "C:\WINNT\system32\SKYNETvudoxwmn.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5866] cmd.exe /c del "C:\WINNT\system32\SKYNETvudoxwmn.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6433] command.com /c del "C:\WINNT\system32\SKYNETvudoxwmn.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4681] cmd.exe /c del "C:\WINNT\system32\SKYNETvudoxwmn.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1805] command.com /c del "C:\WINNT\system32\SKYNETawvcaenc.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4891] cmd.exe /c del "C:\WINNT\system32\SKYNETawvcaenc.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6724] command.com /c del "C:\WINNT\system32\SKYNETawvcaenc.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1246] cmd.exe /c del "C:\WINNT\system32\SKYNETawvcaenc.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7406] command.com /c del "C:\WINNT\system32\SKYNETinltxyut.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7434] cmd.exe /c del "C:\WINNT\system32\SKYNETinltxyut.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7072] command.com /c del "C:\WINNT\system32\SKYNETinltxyut.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3843] cmd.exe /c del "C:\WINNT\system32\SKYNETinltxyut.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3058] command.com /c del "C:\WINNT\system32\drivers\SKYNETctrknukn.sys_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5195] cmd.exe /c del "C:\WINNT\system32\drivers\SKYNETctrknukn.sys_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7597] command.com /c del "C:\WINNT\system32\drivers\SKYNETctrknukn.sys"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2333] cmd.exe /c del "C:\WINNT\system32\drivers\SKYNETctrknukn.sys"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9465] command.com /c del "C:\WINNT\system32\SKYNETuegjrukl.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4710] cmd.exe /c del "C:\WINNT\system32\SKYNETuegjrukl.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9323] command.com /c del "C:\WINNT\system32\SKYNETuegjrukl.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC960] cmd.exe /c del "C:\WINNT\system32\SKYNETuegjrukl.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5619] command.com /c del "C:\WINNT\system32\SKYNETvudoxwmn.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1975] cmd.exe /c del "C:\WINNT\system32\SKYNETvudoxwmn.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8965] command.com /c del "C:\WINNT\system32\SKYNETvudoxwmn.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2401] cmd.exe /c del "C:\WINNT\system32\SKYNETvudoxwmn.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8505] command.com /c del "C:\WINNT\system32\SKYNETawvcaenc.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC525] cmd.exe /c del "C:\WINNT\system32\SKYNETawvcaenc.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA182] command.com /c del "C:\WINNT\system32\SKYNETawvcaenc.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6172] cmd.exe /c del "C:\WINNT\system32\SKYNETawvcaenc.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6007] command.com /c del "C:\WINNT\system32\SKYNETinltxyut.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC285] cmd.exe /c del "C:\WINNT\system32\SKYNETinltxyut.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7329] command.com /c del "C:\WINNT\system32\SKYNETinltxyut.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6276] cmd.exe /c del "C:\WINNT\system32\SKYNETinltxyut.dat"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB8278] command.com /c del "C:\WINNT\system32\drivers\SKYNETctrknukn.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3359] cmd.exe /c del "C:\WINNT\system32\drivers\SKYNETctrknukn.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2492] command.com /c del "C:\WINNT\system32\drivers\SKYNETctrknukn.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5009] cmd.exe /c del "C:\WINNT\system32\drivers\SKYNETctrknukn.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7839] command.com /c del "C:\WINNT\system32\SKYNETuegjrukl.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3890] cmd.exe /c del "C:\WINNT\system32\SKYNETuegjrukl.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8543] command.com /c del "C:\WINNT\system32\SKYNETuegjrukl.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD838] cmd.exe /c del "C:\WINNT\system32\SKYNETuegjrukl.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2703] command.com /c del "C:\WINNT\system32\SKYNETvudoxwmn.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5156] cmd.exe /c del "C:\WINNT\system32\SKYNETvudoxwmn.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8635] command.com /c del "C:\WINNT\system32\SKYNETvudoxwmn.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3206] cmd.exe /c del "C:\WINNT\system32\SKYNETvudoxwmn.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7268] command.com /c del "C:\WINNT\system32\SKYNETawvcaenc.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7883] cmd.exe /c del "C:\WINNT\system32\SKYNETawvcaenc.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3137] command.com /c del "C:\WINNT\system32\SKYNETawvcaenc.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2801] cmd.exe /c del "C:\WINNT\system32\SKYNETawvcaenc.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5430] command.com /c del "C:\WINNT\system32\SKYNETinltxyut.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6454] cmd.exe /c del "C:\WINNT\system32\SKYNETinltxyut.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5850] command.com /c del "C:\WINNT\system32\SKYNETinltxyut.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1794] cmd.exe /c del "C:\WINNT\system32\SKYNETinltxyut.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8270] command.com /c del "C:\WINNT\system32\drivers\SKYNETctrknukn.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6390] cmd.exe /c del "C:\WINNT\system32\drivers\SKYNETctrknukn.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2100] command.com /c del "C:\WINNT\system32\drivers\SKYNETctrknukn.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1071] cmd.exe /c del "C:\WINNT\system32\drivers\SKYNETctrknukn.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3462] command.com /c del "C:\WINNT\system32\SKYNETuegjrukl.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5639] cmd.exe /c del "C:\WINNT\system32\SKYNETuegjrukl.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1517] command.com /c del "C:\WINNT\system32\SKYNETuegjrukl.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9852] cmd.exe /c del "C:\WINNT\system32\SKYNETuegjrukl.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6736] command.com /c del "C:\WINNT\system32\SKYNETvudoxwmn.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8292] cmd.exe /c del "C:\WINNT\system32\SKYNETvudoxwmn.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4681] command.com /c del "C:\WINNT\system32\SKYNETvudoxwmn.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6962] cmd.exe /c del "C:\WINNT\system32\SKYNETvudoxwmn.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3065] command.com /c del "C:\WINNT\system32\SKYNETawvcaenc.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5022] cmd.exe /c del "C:\WINNT\system32\SKYNETawvcaenc.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2022] command.com /c del "C:\WINNT\system32\SKYNETawvcaenc.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2649] cmd.exe /c del "C:\WINNT\system32\SKYNETawvcaenc.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9731] command.com /c del "C:\WINNT\system32\SKYNETinltxyut.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9243] cmd.exe /c del "C:\WINNT\system32\SKYNETinltxyut.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8781] command.com /c del "C:\WINNT\system32\SKYNETinltxyut.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3130] cmd.exe /c del "C:\WINNT\system32\SKYNETinltxyut.dat"
O8 - Extra context menu item: Blocking access to the document address by AliveProxy - C:\Program Files\AiS AliveProxy Server\aisBlockDocument.html
O8 - Extra context menu item: Blocking access to the image address by AliveProxy - C:\Program Files\AiS AliveProxy Server\aisBlockImage.html
O8 - Extra context menu item: Blocking access to the link address by AliveProxy - C:\Program Files\AiS AliveProxy Server\aisBlockLink.html
O8 - Extra context menu item: Cut proxy addresses from selected text by AliveProxy - C:\Program Files\AiS AliveProxy Server\aisCutProxyFromSelectedTåxt.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Owner\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5483.cab
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin11USA.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
O16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} (System Requirements Lab) - http://www.srtest.com/sysreqlab.cab
O16 - DPF: {E991BDE0-9816-4094-853E-6BDB60F0342D} (Get_ActiveX Control) - http://apps.corel.com/nos_dl_manager/plugin/IENetOpPlugin.ocx
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: ddccdab - ddccdab.dll (file missing)
O20 - Winlogon Notify: jkkljhi - jkkljhi.dll (file missing)
O20 - Winlogon Notify: rastask - c:\winnt\repair\rastask.dll (file missing)
O20 - Winlogon Notify: tuvvtqn - tuvvtqn.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTSvcCDA.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Net Agent - Unknown owner - C:\WINNT\dls0523pmw.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\System32\HPZipm12.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINNT\wanmpsvc.exe
O24 - Desktop Component 0: (no name) - http://www.thebestpageintheuniverse.net/images/razor2.gif
--
End of file - 15723 bytes