I ran everything as instructed. I ran into a couple of problems along the way:
- When I typed in Prefetch into the Run Dialogue in Windows, Windows did not recognize that command. Therefore, that part had to be skipped.
- When I ran HiJackThis to Fix the entries you listed above, the following entries did not show up:
O18 - Filter: text/html - {8293D547-38DD-4325-B35A-F1817EDFA5FC} - C:\Program Files\Cas\Client\casmf.dll
O20 - Winlogon Notify: ThemeManager - C:\WINDOWS\system32\mrcbase.dll
O20 - Winlogon Notify: Uninstall - C:\WINDOWS\system32\mrcbase.dll
However, this DID show up:
O20 - Winlogon Notify: WebCheck - C:\WINDOWS\system32\mrcbase.dll
So I checked that entry off for HJT to fix.
- When I was using KillBox, and I clicked "Yes" to Reboot after entering all 4 file paths, it told me "PendingFileRename Operations Registry data has been removed by External Process!" After some playing around, I found that the files
C:\Program Files\Cas\Client\casclient.exe
C:\Program Files\Cas\Client\casmf.dll
did not exist any more (or so I think).
However, I'm afraid the other two files:
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\nppk.exe
C:\WINDOWS\system32\mrcbase.dll
may still be on my system. I tried to delete them without choosing the Restart option in KillBox, and that didn't work.
- Even after finishing all of these steps, my McAfee Security Center and ewido detected and attempted to stop trojans. One of them was the Downloader -LG.dll trojan.
---
Finally, here are the log files:
Panda:
Incident Status Location
Adware:Adware/AdBehavior No disinfected C:\WINDOWS\system32\roopkpu.dll
Adware:Adware/AdBehavior No disinfected C:\WINDOWS\system32\rnnjaj.exe
Adware:Adware/AdBehavior No disinfected C:\Documents and Settings\All Users\Start Menu\Programs\Startup\nppk.exe
Adware:Adware/WinTools No disinfected Windows Registry
Adware:Adware/Novo No disinfected C:\WINDOWS\system32\CdmFiles
------------------------------------
Ewido:
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 1:54:07 AM, 6/29/2005
+ Report-Checksum: FF647A45
+ Date of database: 6/29/2005
+ Version of scan engine: v3.0
+ Duration: 94 min
+ Scanned Files: 148305
+ Speed: 26.05 Files/Second
+ Infected files: 87
+ Removed files: 87
+ Files put in quarantine: 87
+ Files that could not be opened: 0
+ Files that could not be cleaned: 0
+ Binder: Yes
+ Crypter: Yes
+ Archives: Yes
+ Scanned items:
C:\
X:\
Y:\
+ Scan result:
C:\Documents and Settings\Guest\Cookies\guest@atdmt[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@doubleclick[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Cookies\maxx hyeok
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Cookies\maxx hyeok
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Cookies\maxx hyeok
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Cookies\maxx hyeok
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Cookies\maxx hyeok
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Cookies\maxx hyeok
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Cookies\maxx hyeok
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Cookies\maxx hyeok
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Cookies\maxx hyeok
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Cookies\maxx hyeok
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Cookies\maxx hyeok
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Cookies\maxx hyeok
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Cookies\maxx hyeok
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Cookies\maxx hyeok cho@a[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Cookies\maxx hyeok
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Cookies\maxx hyeok
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Cookies\maxx hyeok
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Cookies\maxx hyeok
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Cookies\maxx hyeok
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Cookies\maxx hyeok
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Cookies\maxx hyeok cho@geocities[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Cookies\maxx hyeok
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Cookies\maxx hyeok
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Cookies\maxx hyeok cho@indiads[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Cookies\maxx hyeok
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Cookies\maxx hyeok cho@link[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Cookies\maxx hyeok cho@list[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Cookies\maxx hyeok cho@myway[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Cookies\maxx hyeok
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Cookies\maxx hyeok cho@outster[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Cookies\maxx hyeok
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Cookies\maxx hyeok
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Cookies\maxx hyeok cho@real[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Cookies\maxx hyeok
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Cookies\maxx hyeok
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Cookies\maxx hyeok
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Cookies\maxx hyeok
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Cookies\maxx hyeok
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Cookies\maxx hyeok
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Cookies\maxx hyeok
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Local Settings\Temp\Cookies\maxx hyeok cho@58154541[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Local Settings\Temp\Cookies\maxx hyeok cho@adknowledge[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Local Settings\Temp\Cookies\maxx hyeok
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Local Settings\Temp\Cookies\maxx hyeok
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Local Settings\Temp\Cookies\maxx hyeok cho@bluestreak[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Local Settings\Temp\Cookies\maxx hyeok cho@bravenet[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Local Settings\Temp\Cookies\maxx hyeok cho@cgi-bin[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Local Settings\Temp\Cookies\maxx hyeok
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Local Settings\Temp\Cookies\maxx hyeok cho@com[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Local Settings\Temp\Cookies\maxx hyeok cho@exitexchange[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Local Settings\Temp\Cookies\maxx hyeok
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Local Settings\Temp\Cookies\maxx hyeok
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Local Settings\Temp\Cookies\maxx hyeok
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Local Settings\Temp\Cookies\maxx hyeok cho@overture[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Local Settings\Temp\Cookies\maxx hyeok
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Local Settings\Temp\Cookies\maxx hyeok cho@realmedia[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Local Settings\Temp\Cookies\maxx hyeok
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Local Settings\Temp\Cookies\maxx hyeok
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Local Settings\Temp\Cookies\maxx hyeok cho@targetnetworks[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Local Settings\Temp\Cookies\maxx hyeok cho@tribalfusion[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Local Settings\Temp\Cookies\maxx hyeok cho@valueclick[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Local Settings\Temp\Cookies\maxx hyeok
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Local Settings\Temp\Cookies\maxx hyeok cho@zedo[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Local Settings\Temp\Del33.tmp -> TrojanDownloader.Small.asf -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Local Settings\Temp\Del3C.tmp -> TrojanDownloader.Small.asf -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Local Settings\Temp\f640160.exe -> TrojanDownloader.Qoologic.n -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Local Settings\Temp\MediaAccessInstPack.exe -> Spyware.WinAD -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Local Settings\Temp\SSK3_B5 Seedcorn 4.exe -> TrojanDropper.Small.qn -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Local Settings\Temp\Temporary Internet Files\Content.IE5\0DUNS9U7\abiuninst[1].exe -> Spyware.BetterInternet -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Local Settings\Temporary Internet Files\Content.IE5\2D2HCL4R\AppWrap[1].exe -> TrojanDownloader.Adload.a -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Local Settings\Temporary Internet Files\Content.IE5\2D2HCL4R\AppWrap[2].exe -> TrojanDownloader.Adload.a -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Local Settings\Temporary Internet Files\Content.IE5\4LAJ8HQN\AppWrap[2].exe -> TrojanDownloader.Agent.qg -> Cleaned with backup
C:\Documents and Settings\Maxx Hyeok Cho\Local Settings\Temporary Internet Files\Content.IE5\OP2J0927\AppWrap[3].exe -> TrojanDownloader.Wintool.e -> Cleaned with backup
C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Spyware.Wheaterbug.a -> Cleaned with backup
C:\Program Files\CasStub\casstub.exe -> TrojanDownloader.Agent.qg -> Cleaned with backup
C:\WINDOWS\system32\dist001.exe -> TrojanDownloader.Agent.qg -> Cleaned with backup
C:\WINDOWS\system32\exclean.exe -> Spyware.BargainBuddy -> Cleaned with backup
C:\WINDOWS\system32\mqexdlm.srg -> Spyware.BargainBuddy.q -> Cleaned with backup
C:\WINDOWS\system32\mscb.dll -> Spyware.BargainBuddy.i -> Cleaned with backup
C:\WINDOWS\system32\nsw7C.dll -> Spyware.HotSearchBar -> Cleaned with backup
C:\WINDOWS\system32\nvms.dll -> Spyware.Bargainbuddy -> Cleaned with backup
C:\WINDOWS\system32\pppkm.dll -> TrojanDownloader.Qoologic.q -> Cleaned with backup
C:\WINDOWS\system32\supdate.dll -> TrojanDownloader.Qoologic.p -> Cleaned with backup
C:\WINDOWS\system32\zhhixig.dll -> TrojanDownloader.Qoologic.q -> Cleaned with backup
C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\QJD1061C\abiuninst[1].exe -> Spyware.BetterInternet -> Cleaned with backup
::Report End
------------------------------------
HJT:
Logfile of HijackThis v1.99.1
Scan saved at 4:00:54 AM, on 6/29/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Small Programs\ewido security suite\ewidoctrl.exe
C:\Small Programs\ewido security suite\ewidoguard.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
c:\progra~1\mcafee\MCAFEE~1\MssSrv.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\progra~1\mcafee\MCAFEE~1\MssCli.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\iTunes\iTunesHelper.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\system32\rnnjaj.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Small Programs\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://www.geekstogo...o_Here-f37.htmlR0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1
\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32
\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"
-osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RegKillElbyCheck] "C:\Small Programs\DVD Region Killer\ElbyCheck.exe"
/L RegKill
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [_AntiSpyware] c:\progra~1\mcafee\MCAFEE~1\MssCli.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\rnnjaj.exe reg_run
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft
ActiveSync\WCESCOMM.EXE"
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0
\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common
Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10
\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} -
C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program
Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-
00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program
Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} -
C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program
Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O13 - DefaultPrefix:
O13 - WWW Prefix:
O13 - Home Prefix:
O13 - Mosaic Prefix:
O13 - FTP Prefix:
O13 - Gopher Prefix:
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoft.../as5/asinst.cabO16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) -
http://chat.yahoo.com/cab/yvwrctl.cabO20 - Winlogon Notify: SharedDLLs - C:\WINDOWS\system32\mrcbase.dll
O23 - Service: ewido security suite control - ewido networks - C:\Small Programs\ewido
security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Small Programs\ewido
security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program
Files\iPod\bin\iPodService.exe
O23 - Service: McAfee AntiSpyware Real-Time Scanner (McAfeeAntiSpyware) - McAfee, Inc. -
c:\progra~1\mcafee\MCAFEE~1\MssSrv.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1
\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc -
C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc -
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -
C:\WINDOWS\System32\nvsvc32.exe
---------------------
Thank you so much for your time and effort! I really really really am grateful.