Error "__"disabled by administrator [RESOLVED], Hijack this Log |
![]() ![]() |
Error "__"disabled by administrator [RESOLVED], Hijack this Log |
Sep 19 2006, 01:30 PM
Post
#1
|
|
|
Member ![]() ![]() Posts: 20 OS: Windows xp |
Logfile of HijackThis v1.99.1 Scan saved at 12:22:11 PM, on 9/19/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe C:\windows\system\hpsysdrv.exe C:\WINDOWS\system32\hkcmd.exe C:\HP\KBD\KBD.EXE C:\WINDOWS\AGRSMMSG.exe C:\Program Files\HP\HP Software Update\HPWuSchd.exe C:\Program Files\HP\hpcoretech\hpcmpmgr.exe C:\PROGRA~1\TELUSE~1\SMARTB~1\MotiveSB.exe C:\WINDOWS\ALCXMNTR.EXE C:\WINDOWS\system32\igfxtray.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\ewido anti-spyware 4.0\guard.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\ewido anti-spyware 4.0\ewido.exe C:\Program Files\TrojanHunter 4.6\THGuard.exe C:\Program Files\Messenger\MSMSGS.EXE C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\TELUS eCare\bin\mpbtn.exe C:\WINDOWS\System32\HPZipm12.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\HP\hpcoretech\comp\hpdarc.exe C:\Documents and Settings\Owner\Desktop\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.ca/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe" O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [VTTimer] VTTimer.exe O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe" O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\TELUSE~1\SMARTB~1\MotiveSB.exe O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.6\THGuard.exe" O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe" O4 - HKCU\..\Run: [WMP Plugin] C:\Program Files\Windows Media Player Plugin\wmplugin.exe O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealOne Player\realplay.exe" /RunUPGToolCommandReBoot O4 - Startup: IMStart.lnk = C:\Program Files\InterMute\IMStart.exe O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O4 - Global Startup: Quicken Scheduled Updates.lnk = ? O4 - Global Startup: TELUS eCare.lnk = C:\Program Files\TELUS eCare\bin\matcli.exe O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1 O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesca.dll O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesca.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe O23 - Service: Windows Firewall/Internet Connection Sharing (ICS) (SharedAccess) - Unknown owner - C:\WINDOWS\C:\WINDOWS\System32\svchost.exe (file missing) O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe |
|
|
Sep 24 2006, 06:33 AM
Post
#2
|
|
|
Member 2k Posts: 2,744 OS: Windows XP SP2 |
Hi pandora13,
Go to Start > Run and copy paste the following lines one by one into the Run box and click OK after pasting each line. sc stop SharedAccess sc delete SharedAccess Running the following program should restore the defaults. Even if doesn't find any infections let it run till the end. Download SDFix and save it to your desktop. Please then reboot your computer in Safe Mode by doing the following :
|
|
|
Sep 24 2006, 10:57 AM
Post
#3
|
|
|
Member ![]() ![]() Posts: 20 OS: Windows xp |
SDFix: Version 1.26
------------------- Scan run on: Sun 09/24/2006 At: 09:49 AM Microsoft Windows XP [Version 5.1.2600] Running from: C:\Documents and Settings\Owner\Desktop\SDFix\SDFix Stage One... Checking Services... Name: ----- Path: ---- Repairing Registry... Restoring Default Hosts File... Stage One Complete Rebooting! Stage Two... Registry Cleaning Finished... Checking For Malware Files: -------------------------- Backing Up and Removing any Files Found... Final Check: Remaining Services: ------------------ Remaining Files: -------------- *Any removed Files are saved in the SDFix\backups Folder* *FINISHED* |
|
|
Sep 24 2006, 11:00 AM
Post
#4
|
|
|
Member ![]() ![]() Posts: 20 OS: Windows xp |
Sorry, forgot to add that my system restore tab is still missing and cant access firewall settings, not sure what else yet
Thank you |
|
|
Sep 24 2006, 11:51 AM
Post
#5
|
|
|
Member ![]() ![]() Posts: 20 OS: Windows xp |
sorry, what a dummy....forgot the hijackthis report
Logfile of HijackThis v1.99.1 Scan saved at 10:49:51 AM, on 9/24/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\ewido anti-spyware 4.0\guard.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe C:\windows\system\hpsysdrv.exe C:\WINDOWS\system32\hkcmd.exe C:\HP\KBD\KBD.EXE C:\WINDOWS\AGRSMMSG.exe C:\Program Files\HP\HP Software Update\HPWuSchd.exe C:\Program Files\HP\hpcoretech\hpcmpmgr.exe C:\PROGRA~1\TELUSE~1\SMARTB~1\MotiveSB.exe C:\WINDOWS\ALCXMNTR.EXE C:\WINDOWS\system32\igfxtray.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\ewido anti-spyware 4.0\ewido.exe C:\Program Files\TrojanHunter 4.6\THGuard.exe C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe C:\WINDOWS\System32\HPZipm12.exe C:\Documents and Settings\Owner\Desktop\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.ca/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe" O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [VTTimer] VTTimer.exe O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe" O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\TELUSE~1\SMARTB~1\MotiveSB.exe O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.6\THGuard.exe" O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe" O4 - HKCU\..\Run: [WMP Plugin] C:\Program Files\Windows Media Player Plugin\wmplugin.exe O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealOne Player\realplay.exe" /RunUPGToolCommandReBoot O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe O4 - Startup: IMStart.lnk = C:\Program Files\InterMute\IMStart.exe O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O4 - Global Startup: Quicken Scheduled Updates.lnk = ? O4 - Global Startup: TELUS eCare.lnk = C:\Program Files\TELUS eCare\bin\matcli.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesca.dll O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesca.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe |
|
|
Sep 25 2006, 05:52 AM
Post
#6
|
|
|
Member 2k Posts: 2,744 OS: Windows XP SP2 |
Ok, let's take a look at the registry.
Download WinPFind2.zip and unzip it to your Desktop. It will create a folder named WinPFind2. Do NOT run the program directly from the zip file.
|
|
|
Sep 25 2006, 09:51 AM
Post
#7
|
|
|
Member ![]() ![]() Posts: 20 OS: Windows xp |
Well, here it is. And thank you by the way for responding so fast....that's awesome Logfile created on: 09/25/2006 08:49 WinPFind2 by OldTimer - Version 1.0.10 Folder = C:\Documents and Settings\Owner\Desktop\WinPFind2\ Microsoft Windows XP Service Pack 2 (Version = 5.1.2600) Internet Explorer (Version = 6.0.2900.2180) < All Processes > \systemroot\system32\smss.exe - (Microsoft Corporation ) \??\c:\windows\system32\csrss.exe - (Microsoft Corporation ) \??\c:\windows\system32\winlogon.exe - (Microsoft Corporation ) c:\windows\system32\services.exe - (Microsoft Corporation ) c:\windows\system32\lsass.exe - (Microsoft Corporation ) c:\windows\system32\svchost.exe [C:\WINDOWS\SYSTEM32\SVCHOST -K DCOMLAUNCH] - (Microsoft Corporation ) (DcomLaunch) C:\WINDOWS\system32\rpcss.dll - (Microsoft Corporation ) (TermService) C:\WINDOWS\System32\termsrv.dll - (Microsoft Corporation ) (TermService) C:\WINDOWS\System32\termsrv.dll - (Microsoft Corporation ) (TermService) C:\WINDOWS\System32\termsrv.dll - (Microsoft Corporation ) (SharedAccess) - (File not found)) (Wmi) - (File not found)) c:\windows\system32\svchost.exe [C:\WINDOWS\SYSTEM32\SVCHOST -K RPCSS] - (Microsoft Corporation ) (RpcSs) C:\WINDOWS\system32\rpcss.dll - (Microsoft Corporation ) (SharedAccess) - (File not found)) (Wmi) - (File not found)) c:\windows\system32\svchost.exe [C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETSVCS] - (Microsoft Corporation ) (AppMgmt) C:\WINDOWS\System32\appmgmts.dll - (File not found)) (AudioSrv) C:\WINDOWS\System32\audiosrv.dll - (Microsoft Corporation ) (BITS) C:\WINDOWS\System32\qmgr.dll - (Microsoft Corporation ) (Browser) C:\WINDOWS\System32\browser.dll - (Microsoft Corporation ) (CryptSvc) C:\WINDOWS\System32\cryptsvc.dll - (Microsoft Corporation ) (Dhcp) C:\WINDOWS\System32\dhcpcsvc.dll - (Microsoft Corporation ) (dmserver) C:\WINDOWS\System32\dmserver.dll - (Microsoft Corp. ) (ERSvc) C:\WINDOWS\System32\ersvc.dll - (Microsoft Corporation ) (EventSystem) C:\WINDOWS\System32\es.dll - (Microsoft Corporation ) (FastUserSwitchingCompatibility) C:\WINDOWS\System32\shsvcs.dll - (Microsoft Corporation ) (helpsvc) %WINDIR%\PCHealth\HelpCtr\Binaries\pchsvc.dll - (File not found)) (HidServ) C:\WINDOWS\System32\hidserv.dll - (Microsoft Corporation ) (lanmanserver) C:\WINDOWS\System32\srvsvc.dll - (Microsoft Corporation ) (lanmanworkstation) C:\WINDOWS\System32\wkssvc.dll - (Microsoft Corporation ) (Messenger) C:\WINDOWS\System32\msgsvc.dll - (Microsoft Corporation ) (Netman) C:\WINDOWS\System32\netman.dll - (Microsoft Corporation ) (Nla) C:\WINDOWS\System32\mswsock.dll - (Microsoft Corporation ) (NtmsSvc) C:\WINDOWS\system32\ntmssvc.dll - (Microsoft Corporation ) (RasAuto) C:\WINDOWS\System32\rasauto.dll - (Microsoft Corporation ) (RasMan) C:\WINDOWS\System32\rasmans.dll - (Microsoft Corporation ) (RemoteAccess) C:\WINDOWS\System32\mprdim.dll - (Microsoft Corporation ) (Schedule) C:\WINDOWS\system32\schedsvc.dll - (Microsoft Corporation ) (seclogon) C:\WINDOWS\System32\seclogon.dll - (Microsoft Corporation ) (SENS) C:\WINDOWS\system32\sens.dll - (Microsoft Corporation ) (ShellHWDetection) C:\WINDOWS\System32\shsvcs.dll - (Microsoft Corporation ) (srservice) C:\WINDOWS\System32\srsvc.dll - (Microsoft Corporation ) (TapiSrv) C:\WINDOWS\System32\tapisrv.dll - (Microsoft Corporation ) (Themes) C:\WINDOWS\System32\shsvcs.dll - (Microsoft Corporation ) (TrkWks) C:\WINDOWS\system32\trkwks.dll - (Microsoft Corporation ) (W32Time) C:\WINDOWS\System32\w32time.dll - (Microsoft Corporation ) (winmgmt) C:\WINDOWS\system32\wbem\WMIsvc.dll - (Microsoft Corporation ) (WmdmPmSN) C:\WINDOWS\system32\MsPMSNSv.dll - (Microsoft Corporation ) (wscsvc) C:\WINDOWS\system32\wscsvc.dll - (Microsoft Corporation ) (wuauserv) C:\WINDOWS\System32\wuauserv.dll - (Microsoft Corporation ) (WZCSVC) C:\WINDOWS\System32\wzcsvc.dll - (Microsoft Corporation ) (xmlprov) C:\WINDOWS\System32\xmlprov.dll - (Microsoft Corporation ) (SharedAccess) - (File not found)) (Wmi) - (File not found)) c:\windows\system32\svchost.exe [C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K NETWORKSERVICE] - (Microsoft Corporation ) (Dnscache) C:\WINDOWS\System32\dnsrslvr.dll - (Microsoft Corporation ) (SharedAccess) - (File not found)) (Wmi) - (File not found)) c:\windows\system32\svchost.exe [C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K LOCALSERVICE] - (Microsoft Corporation ) (Alerter) C:\WINDOWS\system32\alrsvc.dll - (Microsoft Corporation ) (LmHosts) C:\WINDOWS\System32\lmhsvc.dll - (Microsoft Corporation ) (SSDPSRV) C:\WINDOWS\System32\ssdpsrv.dll - (Microsoft Corporation ) (upnphost) C:\WINDOWS\System32\upnphost.dll - (Microsoft Corporation ) (WebClient) C:\WINDOWS\System32\webclnt.dll - (Microsoft Corporation ) (SharedAccess) - (File not found)) (Wmi) - (File not found)) c:\windows\explorer.exe - (Microsoft Corporation ) c:\windows\system32\spoolsv.exe - (Microsoft Corporation ) c:\program files\ewido anti-spyware 4.0\guard.exe - (Anti-Malware Development a.s. ) c:\windows\system32\svchost.exe [C:\WINDOWS\SYSTEM32\SVCHOST.EXE -K IMGSVC] - (Microsoft Corporation ) (stisvc) C:\WINDOWS\system32\wiaservc.dll - (Microsoft Corporation ) (SharedAccess) - (File not found)) (Wmi) - (File not found)) c:\windows\system32\wdfmgr.exe - (Microsoft Corporation ) c:\windows\system32\wscntfy.exe - (Microsoft Corporation ) c:\program files\java\jre1.5.0_08\bin\jusched.exe - (Sun Microsystems, Inc. ) c:\windows\system\hpsysdrv.exe - (Hewlett-Packard Company ) c:\windows\system32\hkcmd.exe - (Intel Corporation ) c:\hp\kbd\kbd.exe - (Hewlett-Packard Company ) c:\windows\agrsmmsg.exe - (Agere Systems ) c:\program files\hp\hp software update\hpwuschd.exe - (Hewlett-Packard ) c:\program files\hp\hpcoretech\hpcmpmgr.exe - (Hewlett-Packard Company ) c:\progra~1\teluse~1\smartb~1\motivesb.exe - (TELUS ) c:\windows\alcxmntr.exe - (Realtek Semiconductor Corp. ) c:\windows\system32\igfxtray.exe - (Intel Corporation ) c:\program files\quicktime\qttask.exe - (Apple Computer, Inc. ) c:\program files\ewido anti-spyware 4.0\ewido.exe - (Anti-Malware Development a.s. ) c:\program files\trojanhunter 4.6\thguard.exe - (Mischel Internet Security ) c:\program files\google\googletoolbarnotifier\1.0.720.3640\googletoolbarnotifier.exe - (Google Inc. ) c:\program files\compaq connections\1940576\program\backweb-1940576.exe - ( ) c:\windows\system32\hpzipm12.exe - (HP ) c:\documents and settings\owner\desktop\winpfind2\winpfind2.exe - (OldTimer Tools ) < Registry Entries > [>> Internet Explorer Settings <<] HKLM->Main\\Start Page - http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop HKLM->Main\\Search Bar - http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop HKLM->Main\\Search Page - http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop HKLM->Main\\Default_Page_URL - http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop HKLM->Main\\Default_Search_URL - http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop HKLM->Main\\Local Page - %SystemRoot%\system32\blank.htm HKCU->Main\\Start Page - http://www.yahoo.ca/ HKCU->Main\\Search Bar - http://www.google.com/ie HKCU->Main\\Search Page - http://www.google.com HKCU->Main\\Default_Page_URL - http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop HKCU->Main\\Default_Search_URL - http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop HKCU->Main\\Local Page - C:\WINDOWS\system32\blank.htm HKLM->Search\\CustomizeSearch - http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm HKLM->Search\\SearchAssistant - http://www.google.com/ie HKCU->URLSearchHooks\\{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Microsoft Url Search Hook = %SystemRoot%\System32\shdocvw.dll (Microsoft Corporation ) HKCU->URLSearchHooks\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar = C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc. ) HKCU->Internet Settings\\ProxyEnable - 0 HKCU->Internet Settings\\ProxyOverride - 127.0.0.1;localhost [>> BHO's <<] {02478D38-C3F9-4EFB-9B51-7695ECA05670} - Yahoo! Toolbar Helper = C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc. ) {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class = C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated ) {53707962-6F74-2D53-2644-206D7942484F} - = C:\PROGRA~1\SPYBOT~1\SDHelper.dll (Safer Networking Limited ) {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - SSVHelper Class = C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll (Sun Microsystems, Inc. ) {AA58ED58-01DD-4d91-8333-CF10577473F7} - Google Toolbar Helper = c:\program files\google\googletoolbar1.dll (Google Inc. ) [>> Internet Explorer Bars, Toolbars and Extensions <<] [HKLM-> Internet Explorer Bars] {4528BBE0-4E08-11D5-AD55-00010333D0AD} - &Yahoo! Messenger = C:\PROGRA~1\Yahoo!\Common\yhexbmesca.dll (Yahoo! Inc. ) {4D5C8C25-D075-11d0-B416-00C04FB90376} - &Tip of the Day = %SystemRoot%\System32\shdocvw.dll (Microsoft Corporation ) [HKCU-> Internet Explorer Bars] {32683183-48a0-441b-a342-7c2a440a9478} - Reg Data missing or invalid = Reg Data missing or invalid (File not found)) {4528BBE0-4E08-11D5-AD55-00010333D0AD} - &Yahoo! Messenger = C:\PROGRA~1\Yahoo!\Common\yhexbmesca.dll (Yahoo! Inc. ) [HKLM-> Internet Explorer ToolBars] {2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google = c:\program files\google\googletoolbar1.dll (Google Inc. ) {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar = C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc. ) [HKCU-> Internet Explorer ToolBars] ShellBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} - &Google = c:\program files\google\googletoolbar1.dll (Google Inc. ) WebBrowser\\{01E04581-4EEE-11D0-BFE9-00AA005B4383} - &Address = %SystemRoot%\System32\browseui.dll (Microsoft Corporation ) WebBrowser\\{0E5CBF21-D15F-11D0-8301-00AA005B4383} - &Links = %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation ) WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} - &Google = c:\program files\google\googletoolbar1.dll (Google Inc. ) WebBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Data missing or invalid = Reg Data missing or invalid (File not found)) WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar = C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc. ) [HKCU-> Internet Explorer CmdMapping] {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - 8192 - Sun Java Console {4528BBE0-4E08-11D5-AD55-00010333D0AD} - 8193 - Yahoo! Messenger {92780B25-18CC-41C8-B9BE-3C9C571A8263} - 8194 - Reg Data missing or invalid {FB5F1910-F110-11d2-BB9E-00C04F795683} - 8195 - Windows Messenger NextId - 8196 [HKLM-> Internet Explorer Extensions] {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - MenuText: Sun Java Console = C:\Program Files\Java\jre1.5.0_08\bin\npjpi150_08.dll (Sun Microsystems, Inc. ) {08B0E5C0-4FCB-11CF-AAA5-00401C608501} (HKCU CLSID) - MenuText: Sun Java Console = C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll (Sun Microsystems, Inc. ) {4528BBE0-4E08-11D5-AD55-00010333D0AD} - ButtonText: Messenger = Reg Data missing or invalid (File not found)) {92780B25-18CC-41C8-B9BE-3C9C571A8263} - ButtonText: Research = Reg Data missing or invalid (File not found)) {FB5F1910-F110-11d2-BB9E-00C04F795683} - ButtonText: Messenger = C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation ) [HKCU-> Internet Explorer Menu Extensions] E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000 (Microsoft Corporation ) [>> Approved Shell Extensions (Non-Microsoft only) <<] [HKLM-> Approved Shell Extensions] {0DF44EAA-FF21-4412-828E-260A8728E7F1} - Taskbar and Start Menu = Reg Data missing or invalid (File not found)) {32683183-48a0-441b-a342-7c2a440a9478} - Media Band = Reg Data missing or invalid (File not found)) {42071714-76d4-11d1-8b24-00a0c9068ff3} - Display Panning CPL Extension = deskpan.dll (File not found)) {5464D816-CF16-4784-B9F3-75C0DB52B499} - Yahoo! Mail = C:\PROGRA~1\Yahoo!\Common\ymmapi.dll (Yahoo! Inc. ) {764BF0E1-F219-11ce-972D-00AA00A14F56} - Shell extensions for file compression = Reg Data missing or invalid (File not found)) {7A9D77BD-5403-11d2-8785-2E0420524153} - User Accounts = Reg Data missing or invalid (File not found)) {7F67036B-66F1-411A-AD85-759FB9C5B0DB} - SampleView = C:\WINDOWS\System32\ShellvRTF.dll (XSS ) {853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} - Encryption Context Menu = Reg Data missing or invalid (File not found)) {88895560-9AA2-1069-930E-00AA0030EBC8} - HyperTerminal Icon Ext = C:\WINDOWS\System32\hticons.dll (Hilgraeve, Inc. ) {B41DB860-8EE4-11D2-9906-E49FADC173CA} - WinRAR shell extension = C:\Program Files\WinRAR\rarext.dll ( ) {EBDF1F20-C829-11D1-8233-FF20AF3E97A9} - TrojanHunter Menu Shell Extension = C:\PROGRA~1\TROJAN~1.6\contmenu.dll ( ) {F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} - Shell Extensions for RealOne Player = C:\Program Files\Real\RealOne Player\rpshellext.dll (RealNetworks ) [>> ContextMenuHandlers (Non-Microsoft only) <<] [HKLM-> ContextMenuHandlers] * - ewido anti-spyware - {8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Program Files\ewido anti-spyware 4.0\context.dll (Anti-Malware Development a.s. ) * - TrojanHunter - {EBDF1F20-C829-11D1-8233-FF20AF3E97A9} = C:\PROGRA~1\TROJAN~1.6\contmenu.dll ( ) * - WinRAR - {B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll ( ) * - Yahoo! Mail - {5464D816-CF16-4784-B9F3-75C0DB52B499} = C:\PROGRA~1\Yahoo!\Common\ymmapi.dll (Yahoo! Inc. ) Directory - ewido anti-spyware - {8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Program Files\ewido anti-spyware 4.0\context.dll (Anti-Malware Development a.s. ) Directory - TrojanHunter - {EBDF1F20-C829-11D1-8233-FF20AF3E97A9} = C:\PROGRA~1\TROJAN~1.6\contmenu.dll ( ) Directory - WinRAR - {B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll ( ) Directory\Background - igfxcui - {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} = C:\WINDOWS\system32\igfxpph.dll (Intel Corporation ) Folder - TrojanHunter - {EBDF1F20-C829-11D1-8233-FF20AF3E97A9} = C:\PROGRA~1\TROJAN~1.6\contmenu.dll ( ) Folder - WinRAR - {B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll ( ) [>> ColumnHandlers (Non-Microsoft only) <<] [HKLM-> ColumnHandlers] [>> File Associations Keys <<] HKLM->SOFTWARE\Classes\.bat\\'' - batfile HKLM->SOFTWARE\Classes\batfile\shell\open\command\\'' - "%1" %* HKLM->SOFTWARE\Classes\.cmd\\'' - cmdfile HKLM->SOFTWARE\Classes\cmdfile\shell\open\command\\'' - "%1" %* HKLM->SOFTWARE\Classes\.com\\'' - comfile HKLM->SOFTWARE\Classes\comfile\shell\open\command\\'' - "%1" %* HKLM->SOFTWARE\Classes\.exe\\'' - exefile HKLM->SOFTWARE\Classes\exefile\shell\open\command\\'' - "%1" %* HKLM->SOFTWARE\Classes\.hta\\'' - htafile HKLM->SOFTWARE\Classes\htafile\shell\open\command\\'' - C:\WINDOWS\System32\mshta.exe "%1" %* HKLM->SOFTWARE\Classes\.js\\'' - JSFile HKLM->SOFTWARE\Classes\jsfile\shell\open\command\\'' - %SystemRoot%\System32\WScript.exe "%1" %* HKLM->SOFTWARE\Classes\.jse\\'' - JSEFile HKLM->SOFTWARE\Classes\jsefile\shell\open\command\\'' - %SystemRoot%\System32\WScript.exe "%1" %* HKLM->SOFTWARE\Classes\.scr\\'' - scrfile HKLM->SOFTWARE\Classes\scrfile\shell\open\command\\'' - "%1" /S HKLM->SOFTWARE\Classes\.vbe\\'' - VBEFile HKLM->SOFTWARE\Classes\vbefile\shell\open\command\\'' - %SystemRoot%\System32\WScript.exe "%1" %* HKLM->SOFTWARE\Classes\.vbs\\'' - VBSFile HKLM->SOFTWARE\Classes\vbsfile\shell\open\command\\'' - %SystemRoot%\System32\WScript.exe "%1" %* HKLM->SOFTWARE\Classes\.wsf\\'' - WSFFile HKLM->SOFTWARE\Classes\wsffile\shell\open\command\\'' - %SystemRoot%\System32\WScript.exe "%1" %* HKLM->SOFTWARE\Classes\.wsh\\'' - WSHFile HKLM->SOFTWARE\Classes\wshfile\shell\open\command\\'' - %SystemRoot%\System32\WScript.exe "%1" %* HKLM->SOFTWARE\Classes\.txt\\'' - txtfile HKLM->SOFTWARE\Classes\txtfile\shell\open\command\\'' - %SystemRoot%\system32\NOTEPAD.EXE %1 [>> Registry Run Keys <<] HKLM->Run\\AGRSMMSG - AGRSMMSG.exe (Agere Systems ) HKLM->Run\\AlcxMonitor - ALCXMNTR.EXE (Realtek Semiconductor Corp. ) HKLM->Run\\HotKeysCmds - C:\WINDOWS\system32\hkcmd.exe (Intel Corporation ) HKLM->Run\\HP Component Manager - "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" (Hewlett-Packard Company ) HKLM->Run\\HP Software Update - "C:\Program Files\HP\HP Software Update\HPWuSchd.exe" (Hewlett-Packard ) HKLM->Run\\hpsysdrv - c:\windows\system\hpsysdrv.exe (Hewlett-Packard Company ) HKLM->Run\\IgfxTray - C:\WINDOWS\system32\igfxtray.exe (Intel Corporation ) HKLM->Run\\KBD - C:\HP\KBD\KBD.EXE (Hewlett-Packard Company ) HKLM->Run\\Motive SmartBridge - C:\PROGRA~1\TELUSE~1\SMARTB~1\MotiveSB.exe (TELUS ) HKLM->Run\\PS2 - C:\WINDOWS\system32\ps2.exe (Hewlett-Packard Company ) HKLM->Run\\QuickTime Task - "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Computer, Inc. ) HKLM->Run\\Recguard - C:\WINDOWS\SMINST\RECGUARD.EXE ( ) HKLM->Run\\REGSHAVE - C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN (FUJI PHOTO FILM CO., LTD. ) HKLM->Run\\SunJavaUpdateSched - "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe" (Sun Microsystems, Inc. ) HKLM->Run\\THGuard - "C:\Program Files\TrojanHunter 4.6\THGuard.exe" (Mischel Internet Security ) HKLM->Run\\TkBellExe - C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot (RealNetworks, Inc. ) HKLM->Run\\VTTimer - VTTimer.exe (File not found)) HKLM->Run\OptionalComponents\IMAIL - Installed = 1 HKLM->Run\OptionalComponents\MAPI - Installed = 1 HKLM->Run\OptionalComponents\MSFS - Installed = 1 HKCU->Run\\MoneyAgent - "C:\Program Files\Microsoft Money\System\mnyexpr.exe" (File not found)) HKCU->Run\\MSMSGS - "C:\Program Files\Messenger\MSMSGS.EXE" /background (Microsoft Corporation ) HKCU->Run\\RealPlayer - "C:\Program Files\Real\RealOne Player\realplay.exe" /RunUPGToolCommandReBoot (RealNetworks, Inc. ) HKCU->Run\\swg - C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe (Google Inc. ) HKCU->Run\\WMP Plugin - C:\Program Files\Windows Media Player Plugin\wmplugin.exe (Created by Yuri ) HKCU->Run\\Yahoo! Pager - "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet (Yahoo! Inc. ) [>> Miscellaneous Startup Keys <<] [AppInit DLLs] AppInit_DLL - (File not found)) [Image File Execution Options] Your Image File Name Here without a path - Debugger = ntsd -d [Shell Service Object Delay Load] CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} = %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation ) PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} = %SystemRoot%\system32\SHELL32.dll (Microsoft Corporation ) SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} = C:\WINDOWS\System32\stobject.dll (Microsoft Corporation ) WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\System32\webcheck.dll (Microsoft Corporation ) [Shell Execute Hooks] {57B86673-276A-48B2-BAE7-C6DBB3020EB8} - CShellExecuteHookImpl Object = C:\Program Files\ewido anti-spyware 4.0\shellexecutehook.dll (Anti-Malware Development a.s. ) {AEB6717E-7E19-11d0-97EE-00C04FD91972} - URL Exec Hook = shell32.dll (Microsoft Corporation ) [Shared Task Scheduler] {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader = %SystemRoot%\System32\browseui.dll (Microsoft Corporation ) {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon = %SystemRoot%\System32\browseui.dll (Microsoft Corporation ) [SafeBoot Option] [HKLM Command Processor AutoRun] HKLM->Command Processor\\AutoRun - [HKCU Command Processor AutoRun] [Security Providers] SecurityProviders\\SecurityProviders - msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll [BootExecute] Session Manager\\BootExecute - autocheck autochk *; [PendingFileRenameOperations] [FileRenameOperations] [ExcludeFromKnownDlls] Session Manager\\ExcludeFromKnownDlls - [>> Disabled MSConfig Items <<] [>> User Agent Post Platform <<] SV1 - [>> Winlogon <<] HMLM->UserInit - C:\WINDOWS\system32\userinit.exe, (Microsoft Corporation ) HKLM->Shell - Explorer.exe (Microsoft Corporation ) HKLM->System - (File not found)) HKLM->VMApplet - rundll32 shell32,Control_RunDLL "sysdm.cpl" Notify\crypt32chain - crypt32.dll (Microsoft Corporation ) Notify\cryptnet - cryptnet.dll (Microsoft Corporation ) Notify\cscdll - cscdll.dll (Microsoft Corporation ) Notify\igfxcui - igfxsrvc.dll (Intel Corporation ) Notify\ScCertProp - wlnotify.dll (Microsoft Corporation ) Notify\Schedule - wlnotify.dll (Microsoft Corporation ) Notify\sclgntfy - sclgntfy.dll (Microsoft Corporation ) Notify\SensLogn - WlNotify.dll (Microsoft Corporation ) Notify\termsrv - wlnotify.dll (Microsoft Corporation ) Notify\WgaLogon - WgaLogon.dll (Microsoft Corporation ) Notify\wlballoon - wlnotify.dll (Microsoft Corporation ) [>> DNS Name Servers <<] {CAEDE487-F354-4B7B-811C-0BD8095913E8} - (Realtek RTL8139/810x Family Fast Ethernet NIC) {ECDF52E4-7185-4052-BFB5-696DA0C5CE4E} - (1394 Net Adapter) [>> All Winsock2 Catalogs <<] NameSpace_Catalog5\Catalog_Entries\000000000001 - %SystemRoot%\System32\mswsock.dll (Microsoft Corporation ) NameSpace_Catalog5\Catalog_Entries\000000000002 - %SystemRoot%\System32\winrnr.dll (Microsoft Corporation ) NameSpace_Catalog5\Catalog_Entries\000000000003 - %SystemRoot%\System32\mswsock.dll (Microsoft Corporation ) Protocol_Catalog9\Catalog_Entries\000000000001 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation ) Protocol_Catalog9\Catalog_Entries\000000000002 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation ) Protocol_Catalog9\Catalog_Entries\000000000003 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation ) Protocol_Catalog9\Catalog_Entries\000000000004 - %SystemRoot%\system32\rsvpsp.dll (Microsoft Corporation ) Protocol_Catalog9\Catalog_Entries\000000000005 - %SystemRoot%\system32\rsvpsp.dll (Microsoft Corporation ) Protocol_Catalog9\Catalog_Entries\000000000006 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation ) Protocol_Catalog9\Catalog_Entries\000000000007 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation ) Protocol_Catalog9\Catalog_Entries\000000000008 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation ) Protocol_Catalog9\Catalog_Entries\000000000009 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation ) Protocol_Catalog9\Catalog_Entries\000000000010 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation ) Protocol_Catalog9\Catalog_Entries\000000000011 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation ) Protocol_Catalog9\Catalog_Entries\000000000012 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation ) Protocol_Catalog9\Catalog_Entries\000000000013 - %SystemRoot%\system32\mswsock.dll (Microsoft Corporation ) [>> Protocol Handlers (Non-Microsoft only) <<] cetihpz - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company ) ipp - (File not found)) msdaipp - (File not found)) [>> Protocol Filters (Non-Microsoft only) <<] < All Services > Abiosdsk (Abiosdsk) - (File not found)) [Disabled - Stopped - Kernel driver] abp480n5 (abp480n5) - (File not found)) [Disabled - Stopped - Kernel driver] Microsoft ACPI Driver (ACPI) - \SystemRoot\System32\DRIVERS\ACPI.sys (Microsoft Corporation ) [ - Running - Kernel driver] ACPIEC (ACPIEC) - (File not found)) [Disabled - Stopped - Kernel driver] adpu160m (adpu160m) - (File not found)) [Disabled - Stopped - Kernel driver] Microsoft Kernel Acoustic Echo Canceller (aec) - system32\drivers\aec.sys (Microsoft Corporation ) [On Demand - Stopped - Kernel driver] AFD Networking Support Environment (AFD) - \SystemRoot\System32\drivers\afd.sys (Microsoft Corporation ) [ - Running - Kernel driver] AFS2k (AFS2K) - (File not found)) [ - Running - Kernel driver] Agere Systems Soft Modem (AgereSoftModem) - System32\DRIVERS\AGRSM.sys (Agere Systems ) [On Demand - Running - Kernel driver] Aha154x (Aha154x) - (File not found)) [Disabled - Stopped - Kernel driver] aic78u2 (aic78u2) - (File not found)) [Disabled - Stopped - Kernel driver] aic78xx (aic78xx) - (File not found)) [Disabled - Stopped - Kernel driver] Service for WDM 3D Audio Driver (ALCXSENS) - system32\drivers\ALCXSENS.SYS (Sensaura Ltd ) [On Demand - Stopped - Kernel driver] Service for Realtek AC97 Audio (WDM) (ALCXWDM) - system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp. ) [On Demand - Running - Kernel driver] Alerter (Alerter) - C:\WINDOWS\System32\svchost.exe -k LocalService (Microsoft Corporation ) [Disabled - Stopped - Win32, running in a shared process] Application Layer Gateway Service (ALG) - C:\WINDOWS\System32\alg.exe (Microsoft Corporation ) [On Demand - Stopped - Win32, running in it's own process] AliIde (AliIde) - (File not found)) [Disabled - Stopped - Kernel driver] amsint (amsint) - (File not found)) [Disabled - Stopped - Kernel driver] Application Management (AppMgmt) - C:\WINDOWS\system32\svchost.exe -k netsvcs (Microsoft Corporation ) [On Demand - Stopped - Win32, running in a shared process] 1394 ARP Client Protocol (Arp1394) - System32\DRIVERS\arp1394.sys (Microsoft Corporation ) [On Demand - Running - Kernel driver] asc (asc) - (File not found)) [Disabled - Stopped - Kernel driver] asc3350p (asc3350p) - (File not found)) [Disabled - Stopped - Kernel driver] asc3550 (asc3550) - (File not found)) [Disabled - Stopped - Kernel driver] ASP.NET State Service (aspnet_state) - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation ) [On Demand - Stopped - Win32, running in it's own process] RAS Asynchronous Media Driver (AsyncMac) - System32\DRIVERS\asyncmac.sys (Microsoft Corporation ) [On Demand - Stopped - Kernel driver] Standard IDE/ESDI Hard Disk Controller (atapi) - \SystemRoot\System32\DRIVERS\atapi.sys (Microsoft Corporation ) [ - Running - Kernel driver] Atdisk (Atdisk) - (File not found)) [Disabled - Stopped - Kernel driver] ATM ARP Client Protocol (Atmarpc) - System32\DRIVERS\atmarpc.sys (Microsoft Corporation ) [On Demand - Stopped - Kernel driver] Windows Audio (AudioSrv) - C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process] Audio Stub Driver (audstub) - System32\DRIVERS\audstub.sys (Microsoft Corporation ) [On Demand - Running - Kernel driver] Beep (Beep) - (File not found)) [ - Running - Kernel driver] Background Intelligent Transfer Service (BITS) - C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation ) [On Demand - Stopped - Win32, running in a shared process] Computer Browser (Browser) - C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation ) [Automatic - Stopped - Win32, running in a shared process] cbidf2k (cbidf2k) - (File not found)) [Disabled - Stopped - Kernel driver] cd20xrnt (cd20xrnt) - (File not found)) [Disabled - Stopped - Kernel driver] Cdaudio (Cdaudio) - (File not found)) [ - Stopped - Kernel driver] Cdfs (Cdfs) - (File not found)) [Disabled - Running - Filesystem driver] CD-ROM Driver (Cdrom) - System32\DRIVERS\cdrom.sys (Microsoft Corporation ) [ - Running - Kernel driver] Changer (Changer) - (File not found)) [ - Stopped - Kernel driver] Indexing Service (CiSvc) - C:\WINDOWS\system32\cisvc.exe (Microsoft Corporation ) [On Demand - Stopped - Win32, running in a shared process] ClipBook (ClipSrv) - C:\WINDOWS\system32\clipsrv.exe (Microsoft Corporation ) [Disabled - Stopped - Win32, running in it's own process] .NET Runtime Optimization Service v2.0.50727_X86 (clr_optimization_v2.0.50727_32) - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation ) [On Demand - Stopped - Win32, running in it's own process] CmdIde (CmdIde) - (File not found)) [Disabled - Stopped - Kernel driver] COM+ System Application (COMSysApp) - C:\WINDOWS\System32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} (Microsoft Corporation ) [On Demand - Stopped - Win32, running in it's own process] Cpqarray (Cpqarray) - (File not found)) [Disabled - Stopped - Kernel driver] Cryptographic Services (CryptSvc) - C:\WINDOWS\system32\svchost.exe -k netsvcs (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process] dac960nt (dac960nt) - (File not found)) [Disabled - Stopped - Kernel driver] DCOM Server Process Launcher (DcomLaunch) - C:\WINDOWS\system32\svchost -k DcomLaunch (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process] DHCP Client (Dhcp) - C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process] Disk Driver (Disk) - \SystemRoot\System32\DRIVERS\disk.sys (Microsoft Corporation ) [ - Running - Kernel driver] Logical Disk Manager Administrative Service (dmadmin) - C:\WINDOWS\System32\dmadmin.exe /com (Microsoft Corp., Veritas Software ) [On Demand - Stopped - Win32, running in a shared process] dmboot (dmboot) - System32\drivers\dmboot.sys (Microsoft Corp., Veritas Software ) [Disabled - Stopped - Kernel driver] dmio (dmio) - System32\drivers\dmio.sys (Microsoft Corp., Veritas Software ) [Disabled - Stopped - Kernel driver] dmload (dmload) - System32\drivers\dmload.sys (Microsoft Corp., Veritas Software. ) [Disabled - Stopped - Kernel driver] Logical Disk Manager (dmserver) - C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation ) [On Demand - Stopped - Win32, running in a shared process] Microsoft Kernel DLS Syntheiszer (DMusic) - system32\drivers\DMusic.sys (Microsoft Corporation ) [On Demand - Stopped - Kernel driver] DNS Client (Dnscache) - C:\WINDOWS\System32\svchost.exe -k NetworkService (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process] dpti2o (dpti2o) - (File not found)) [Disabled - Stopped - Kernel driver] Microsoft Kernel DRM Audio Descrambler (drmkaud) - system32\drivers\drmkaud.sys (Microsoft Corporation ) [On Demand - Stopped - Kernel driver] Error Reporting Service (ERSvc) - C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process] Event Log (Eventlog) - C:\WINDOWS\system32\services.exe (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process] COM+ Event System (EventSystem) - C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation ) [On Demand - Running - Win32, running in a shared process] ewido anti-spyware 4.0 driver (ewido anti-spyware 4.0 driver) - \??\C:\Program Files\ewido anti-spyware 4.0\guard.sys ( ) [ - Running - Kernel driver] ewido anti-spyware 4.0 guard (ewido anti-spyware 4.0 guard) - C:\Program Files\ewido anti-spyware 4.0\guard.exe (Anti-Malware Development a.s. ) [Automatic - Running - Win32, running in it's own process] Fastfat (Fastfat) - (File not found)) [Disabled - Running - Filesystem driver] fasttx2k (fasttx2k) - \SystemRoot\System32\DRIVERS\fasttx2k.sys (Promise Technology, Inc. ) [ - Running - Kernel driver] Fast User Switching Compatibility (FastUserSwitchingCompatibility) - C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation ) [On Demand - Running - Win32, running in a shared process] Fax (Fax) - C:\WINDOWS\system32\fxssvc.exe (Microsoft Corporation ) [On Demand - Stopped - Win32, running in it's own process] Floppy Disk Controller Driver (Fdc) - System32\DRIVERS\fdc.sys (Microsoft Corporation ) [On Demand - Running - Kernel driver] Fips (Fips) - (File not found)) [ - Running - Kernel driver] Floppy Disk Driver (Flpydisk) - System32\DRIVERS\flpydisk.sys (Microsoft Corporation ) [On Demand - Running - Kernel driver] FltMgr (FltMgr) - \SystemRoot\system32\drivers\fltmgr.sys (Microsoft Corporation ) [ - Running - Filesystem driver] Volume Manager Driver (Ftdisk) - \SystemRoot\System32\DRIVERS\ftdisk.sys (Microsoft Corporation ) [ - Running - Kernel driver] Generic Packet Classifier (Gpc) - System32\DRIVERS\msgpc.sys (Microsoft Corporation ) [On Demand - Running - Kernel driver] Help and Support (helpsvc) - C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process] HID Input Service (HidServ) - C:\WINDOWS\System32\svchost.exe -k netsvcs (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process] Microsoft HID Class Driver (HidUsb) - system32\DRIVERS\hidusb.sys (Microsoft Corporation ) [On Demand - Running - Kernel driver] hpn (hpn) - (File not found)) [Disabled - Stopped - Kernel driver] IEEE-1284.4 Driver HPZid412 (HPZid412) - System32\DRIVERS\HPZid412.sys (HP ) [On Demand - Running - Kernel driver] Print Class Driver for IEEE-1284.4 HPZipr12 (HPZipr12) - System32\DRIVERS\HPZipr12.sys (HP ) [On Demand - Running - Kernel driver] USB to IEEE-1284.4 Translation Driver HPZius12 (HPZius12) - System32\DRIVERS\HPZius12.sys (HP ) [On Demand - Running - Kernel driver] HTTP (HTTP) - System32\Drivers\HTTP.sys (Microsoft Corporation ) [On Demand - Running - Kernel driver] HTTP SSL (HTTPFilter) - C:\WINDOWS\System32\svchost.exe -k HTTPFilter (Microsoft Corporation ) [On Demand - Stopped - Win32, running in a shared process] i2omgmt (i2omgmt) - (File not found)) [ - Stopped - Kernel driver] i2omp (i2omp) - (File not found)) [Disabled - Stopped - Kernel driver] i8042 Keyboard and PS/2 Mouse Port Driver (i8042prt) - System32\DRIVERS\i8042prt.sys (Microsoft Corporation ) [ - Running - Kernel driver] ialm (ialm) - System32\DRIVERS\ialmnt5.sys (Intel Corporation ) [On Demand - Running - Kernel driver] InstallDriver Table Manager (IDriverT) - "C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe" (Macrovision Corporation ) [On Demand - Stopped - Win32, running in it's own process] CD-Burning Filter Driver (Imapi) - System32\DRIVERS\imapi.sys (Microsoft Corporation ) [ - Running - Kernel driver] IMAPI CD-Burning COM Service (ImapiService) - C:\WINDOWS\System32\imapi.exe (Microsoft Corporation ) [On Demand - Stopped - Win32, running in it's own process] ini910u (ini910u) - (File not found)) [Disabled - Stopped - Kernel driver] IntelIde (IntelIde) - \SystemRoot\System32\DRIVERS\intelide.sys (Microsoft Corporation ) [ - Running - Kernel driver] Intel Processor Driver (intelppm) - System32\DRIVERS\intelppm.sys (Microsoft Corporation ) [ - Running - Kernel driver] IPv6 Windows Firewall Driver (ip6fw) - system32\drivers\ip6fw.sys (Microsoft Corporation ) [On Demand - Stopped - Kernel driver] IP Traffic Filter Driver (IpFilterDriver) - System32\DRIVERS\ipfltdrv.sys (Microsoft Corporation ) [On Demand - Stopped - Kernel driver] IP in IP Tunnel Driver (IpI |