"VIRUS ALERT" in the toolbar, Spyware&Malware protector,, Also, loss of most privleges |
![]() ![]() |
"VIRUS ALERT" in the toolbar, Spyware&Malware protector,, Also, loss of most privleges |
Jul 12 2008, 10:44 AM
Post
#1
|
|
|
Member ![]() ![]() Posts: 12 OS: Windows XP |
Now, I've got a fairly confusing problem here. When I first got the virus, the words: "VIRUS ALERT" appeared next to the clock, and the clock switched over to military time. I had "Spyware&Malware Protector" and "Privacy Protector" installed. I downloaded a program called "SmitfraudFix", which was supposed to fix the problem. The only way I was able to download the program to my computer was with a jump drive, with data from my other computer. I followed some instructions I found online. The program didn't work like it was supposed to: When I double-clicked it in safe mode, nothing would happen, when it was supposed to bring up the command prompt. Eventually, I got it to work (mostly), by using winRAR, going inside the program, and clicking one of the things inside to start it up. It seemed a bit glitchy, though. When it was done, it was SUPPOSED to ask me to shut down the computer and then open up a txt file about what was deleted and fixed and stuff. It didn't though, and it just gave me the txt file afterwards. Unfortunently, I don't have the txt file with me anymore... doing that didn't seem to do anything. Then I went back into safe mode, did it again, and I must have done SOMETHING different, because when I went into regular mode, the two programs were gone, and I was no longer getting annoying pop-ups about their product. But I've STILL got problems.
I cannot see my C drive anywhere When I hit "Start", only a few of my programs are avalible, and there is no "other programs" or "run" or anything... I cannot get to task manager, it has been "disabled by my administrator" I cannot go online with firefox. I double-click, nothing happens. There are no programs being shown in "add and remove programs" I may have more problems, but these are all the ones I am aware of. Please help! Hijackthis log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 09:15: VIRUS ALERT!, on 7/12/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Canon\BJCard\Bjmcmng.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\system32\IoctlSvc.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\WINDOWS\System32\PSIService.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\Tablet.exe C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe C:\Program Files\Analog Devices\SoundMAX\Smax4.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Canon\BJCard\BJLaunch.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\Program Files\AIM6\aim6.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe C:\Program Files\DAEMON Tools Lite\daemon.exe C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe C:\Program Files\Steam\Steam.exe C:\WINDOWS\system32\WTablet\TabUserW.exe C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\AIM6\aolsoftware.exe C:\Program Files\Common Files\AOL\Loader\aolload.exe C:\Documents and Settings\Mikael Myggen\Desktop\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=...6Ojg5&lid=2 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" O4 - HKLM\..\Run: [BJLaunchEXE] C:\Program Files\Canon\BJCard\BJLaunch.exe O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\Run: [28bb82fe] rundll32.exe "C:\WINDOWS\system32\ecsjyyrj.dll",b O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp O4 - HKCU\..\Run: [autoload] C:\WINDOWS\System32\drivers\smss.exe O4 - HKCU\..\Run: [autorun] C:\Documents and Settings\Mikael Myggen\smss.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [mschkdsk.exe] C:\WINDOWS\System32\mschkdsk.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020 O4 - HKCU\..\Run: [EA Core] C:\Program Files\Electronic Arts\EADM\Core.exe -silent O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user') O4 - Startup: .lnk = C:\WINDOWS\system32\msmapibx32.exe O4 - Startup: Picture Motion Browser Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe O4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\kodsrngn.exe O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\twinplds.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\system32\WTablet\TabUserW.exe O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1189476189375 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1189967518687 O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O20 - AppInit_DLLs: c:\windows\system32\mllmmmk.dll,avgrsstx.dll O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: Canon BJ Memory Card Manager (Bjmcmng) - CANON INC. - C:\Program Files\Canon\BJCard\Bjmcmng.exe O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: DomainService - Unknown owner - C:\Documents and Settings\Mikael Myggen\Application Data\tmp4B.tmp.exe (file missing) O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\System32\PSIService.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\System32\Tablet.exe O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe -- End of file - 8949 bytes |
|
|
Jul 12 2008, 11:26 AM
Post
#2
|
|
|
Malware Monger Posts: 2,735 OS: XP Professional SP3 |
Hi,
Please go here to install the recovery console and for a guide on using combofix. Please note: Installing the Recovery Console plays a vital part in making this process of cleaning your computer safe, don't overlook this! Now please download combofix from here or here. It is important that you save this file to your desktop. Double click combofix.exe and follow the prompts. Please, never rename Combofix unless instructed. When finished, it shall produce a log for you. Post that log and a Hijack This log in your next reply. A quick heads up, if you click on combofix's window when it's running, you may cause it to stall. |
|
|
Jul 12 2008, 11:35 AM
Post
#3
|
|
|
Member ![]() ![]() Posts: 12 OS: Windows XP |
Hi, Please go here to install the recovery console and for a guide on using combofix. Please note: Installing the Recovery Console plays a vital part in making this process of cleaning your computer safe, don't overlook this! Now please download combofix from here or here. It is important that you save this file to your desktop. Double click combofix.exe and follow the prompts. Please, never rename Combofix unless instructed. When finished, it shall produce a log for you. Post that log and a Hijack This log in your next reply. A quick heads up, if you click on combofix's window when it's running, you may cause it to stall. I don't know if I can download the Recovery Console. In the start menu, there's no option to "run" anything. |
|
|
Jul 12 2008, 11:52 AM
Post
#4
|
|
|
Malware Monger Posts: 2,735 OS: XP Professional SP3 |
Do it this way please.
Download ComboFix as instructed - do not run it yet. Go to Microsoft's website => http://support.microsoft.com/kb/310994 Select the download that's appropriate for your Operating System. ![]() Download the file & save it as it's originally named, next to ComboFix.exe. ![]() Now close all open windows and programs, then drag the setup package onto ComboFix.exe and drop it. Follow the prompts to start ComboFix and when prompted, agree to the End-User License Agreement to install the Microsoft Recovery Console. It will ask you if you want to run ComboFix - Click on yes. |
|
|
Jul 13 2008, 03:01 PM
Post
#5
|
|
|
Member ![]() ![]() Posts: 12 OS: Windows XP |
Do it this way please. Download ComboFix as instructed - do not run it yet. Go to Microsoft's website => http://support.microsoft.com/kb/310994 Select the download that's appropriate for your Operating System. ![]() Download the file & save it as it's originally named, next to ComboFix.exe. ![]() Now close all open windows and programs, then drag the setup package onto ComboFix.exe and drop it. Follow the prompts to start ComboFix and when prompted, agree to the End-User License Agreement to install the Microsoft Recovery Console. It will ask you if you want to run ComboFix - Click on yes. My computer can't go online (won't boot up firefox), so I downloaded the file to a flash drive on my other computer and put it onto the desktop from there. I tried dragging it over, and nothing happened. I tried it with all the types of service packs too, just to make sure. oh, also, not sure if this is impotant, but it shows up on my desktop as "ComboFix", not "ComboFix.exe" This post has been edited by RedTsunami: Jul 13 2008, 03:04 PM |
|
|
Jul 13 2008, 03:05 PM
Post
#6
|
|
|
Malware Monger Posts: 2,735 OS: XP Professional SP3 |
Did you rename the file or something? Move the file from your flash drive to the desktop, then drag it into the combofix icon. Make sure its the SP2 one, if you were to use another service pack you may not be able to boot.
Otherwise, do you have a windows CD handy? If so just run ComboFix without installing the Recovery Console. |
|
|
Jul 13 2008, 03:29 PM
Post
#7
|
|
|
Member ![]() ![]() Posts: 12 OS: Windows XP |
Did you rename the file or something? Move the file from your flash drive to the desktop, then drag it into the combofix icon. Make sure its the SP2 one, if you were to use another service pack you may not be able to boot. Otherwise, do you have a windows CD handy? If so just run ComboFix without installing the Recovery Console. No, I didn't rename the file. It just came on like that. AND I do have the windows xp CD, but my computer can't read it. It's like it doesn't know it's there. |
|
|
Jul 14 2008, 02:17 AM
Post
#8
|
|
|
Malware Monger Posts: 2,735 OS: XP Professional SP3 |
OK,
Do you have access to another PC just in case? Go ahead with running Combofix please. |
|
|
Jul 14 2008, 04:20 PM
Post
#9
|
|
|
Member ![]() ![]() Posts: 12 OS: Windows XP |
OK, Do you have access to another PC just in case? Go ahead with running Combofix please. What? I CAN'T run this on my infected computer, literally. I could use winrar and go into into and try to start it up from there, but I've heard this software is "iffy", and if I open it up wrong I could kill my whole computer... If I double click it, nothing happens. If I try to go under Start and go to Run, I can't because "Run" isn't there. |
|
|
Jul 15 2008, 03:45 AM
Post
#10
|
|
|
Malware Monger Posts: 2,735 OS: XP Professional SP3 |
OK,
You don't need winRAR for combofix - it doesn't come in any zip or rar file... you can download it here. Run it as mentioned above. If that doesn't work do the following please. Download ATF Cleaner to your Desktop.
Now download OTScanIt.exe to your Desktop and double-click on it to extract the files. It will create a folder named OTScanIt on your desktop. Note: You must be logged on to the system with an account that has Administrator privileges to run this program.
Use the Add Reply button and attach the file in your next post (do not try to copy/paste it into the post). To attach a file, do the following:
* Under the reply panel is the Attachments Panel * Browse for the attachment file you want to upload, then click the green Upload button * Once it has uploaded, click the Manage Current Attachments drop down box * Click on to insert the attachment into your postThis post has been edited by Mike: Jul 15 2008, 03:46 AM |
|
|
Jul 15 2008, 05:53 PM
Post
#11
|
|
|
Member ![]() ![]() Posts: 12 OS: Windows XP |
OK, You don't need winRAR for combofix - it doesn't come in any zip or rar file... you can download it here. Run it as mentioned above. If that doesn't work do the following please. Download ATF Cleaner to your Desktop.
Now download OTScanIt.exe to your Desktop and double-click on it to extract the files. It will create a folder named OTScanIt on your desktop. Note: You must be logged on to the system with an account that has Administrator privileges to run this program.
Use the Add Reply button and attach the file in your next post (do not try to copy/paste it into the post). To attach a file, do the following:
* Under the reply panel is the Attachments Panel * Browse for the attachment file you want to upload, then click the green Upload button * Once it has uploaded, click the Manage Current Attachments drop down box * Click on to insert the attachment into your postI can run ATF Cleaner (and I did), but I can't run OTScanit, it won't start when I double click it. |
|
|
Jul 16 2008, 03:22 AM
Post
#12
|
|
|
Malware Monger Posts: 2,735 OS: XP Professional SP3 |
Heh, looks like we are back to square one - we need some information first before I can help so let's try this
Please download Deckard's System Scanner (DSS) and save it to your Desktop.
Note:These logs may be too large to post in one reply, if so, please post extra.txt in a seperate reply. If that doesn't run, Please RIGHT-CLICK HERE and Save As (in IE it's "Save Target As", in FF it's "Save Link As") to download Silent Runners.
This post has been edited by Mike: Jul 16 2008, 03:23 AM |
|
|
Jul 16 2008, 01:53 PM
Post
#13
|
|
|
Member ![]() ![]() Posts: 12 OS: Windows XP |
Okay, here's the silent runners log...but guess what? I had an interesting little discoverey over here. I tried to run The Dacard scanner, and it worked perfectly, and two txt files were created, but I noticed something...if I hit "save as", it took me straight to my C drive, which my computer was hiding from me. I can even explore the folders in there, but if I click the pull-down tab above that, it'll crash the txt file. Unfortunently, I could not figure out how to get the "extra" log again, so I just did it again with silent runners "Silent Runners.vbs", revision 58, http://www.silentrunners.org/ Operating System: Windows XP SP2 Output limited to non-default values, except where indicated by "{++}" Startup items buried in registry: --------------------------------- HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++} "Aim6" = ""C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp" ["AOL LLC"] "autoload" = "C:\WINDOWS\System32\drivers\smss.exe" [file not found] "autorun" = "C:\Documents and Settings\Mikael Myggen\smss.exe" [file not found] "swg" = "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" ["Google Inc."] "mschkdsk.exe" = "C:\WINDOWS\System32\mschkdsk.exe" [file not found] "MsnMsgr" = ""C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background" [file not found] "ctfmon.exe" = "C:\WINDOWS\system32\ctfmon.exe" [MS] "IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}" = ""C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020" ["Nero AG"] "EA Core" = "C:\Program Files\Electronic Arts\EADM\Core.exe -silent" ["Electronic Arts"] "DAEMON Tools Lite" = ""C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun" ["DT Soft Ltd"] "Steam" = ""C:\Program Files\Steam\Steam.exe" -silent" ["Valve Corporation"] "AdobeUpdater" = "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" ["Adobe Systems Incorporated"] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++} "SoundMAXPnP" = "C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" ["Analog Devices, Inc."] "SoundMAX" = ""C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray" ["Analog Devices, Inc."] "NvCplDaemon" = "RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup" [MS] "nwiz" = "nwiz.exe /install" ["NVIDIA Corporation"] "NvMediaCenter" = "RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit" [MS] "SunJavaUpdateSched" = ""C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"" ["Sun Microsystems, Inc."] "ISUSPM" = ""C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler" ["Macrovision Corporation"] "QuickTime Task" = ""C:\Program Files\QuickTime\QTTask.exe" -atboottime" ["Apple Inc."] "iTunesHelper" = ""C:\Program Files\iTunes\iTunesHelper.exe"" ["Apple Inc."] "NeroFilterCheck" = "C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" ["Nero AG"] "NBKeyScan" = ""C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"" ["Nero AG"] "BJLaunchEXE" = "C:\Program Files\Canon\BJCard\BJLaunch.exe" ["CANON INC."] "AVG8_TRAY" = "C:\PROGRA~1\AVG\AVG8\avgtray.exe" ["AVG Technologies CZ, s.r.o."] "28bb82fe" = "rundll32.exe "C:\WINDOWS\system32\ultedxjh.dll",b" [MS] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ {03D0A277-78D0-47C8-9488-00A6BD765F11}\(Default) = (no title provided) -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = "C:\WINDOWS\system32\fccBuVMf.dll" [null data] {43FCD2CF-5569-4208-97D2-52748E0EF6A0}\(Default) = (no title provided) -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = "C:\WINDOWS\system32\byXNdaxu.dll" [null data] {473f0c48-a19f-44d0-924a-84ad895753ef}\(Default) = "{fe357598-da48-a429-0d44-f91a84c0f374}" -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = "C:\WINDOWS\system32\pmkkcn.dll" [null data] {53B5F2B1-94DD-43E5-8187-EB4E31F00701}\(Default) = (no title provided) -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = "C:\WINDOWS\system32\l4acdb2.dll" [file not found] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided) -> {HKLM...CLSID} = "SSVHelper Class" \InProcServer32\(Default) = "C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll" ["Sun Microsystems, Inc."] {AA58ED58-01DD-4d91-8333-CF10577473F7}\(Default) = (no title provided) -> {HKLM...CLSID} = "Google Toolbar Helper" \InProcServer32\(Default) = "c:\program files\google\googletoolbar2.dll" ["Google Inc."] {AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\(Default) = (no title provided) -> {HKLM...CLSID} = "Google Toolbar Notifier BHO" \InProcServer32\(Default) = "C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll" ["Google Inc."] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\ "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Display Panning CPL Extension" -> {HKLM...CLSID} = "Display Panning CPL Extension" \InProcServer32\(Default) = "deskpan.dll" [file not found] "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext" -> {HKLM...CLSID} = "HyperTerminal Icon Ext" \InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."] "{A70C977A-BF00-412C-90B7-034C51DA2439}" = "NvCpl DesktopContext Class" -> {HKLM...CLSID} = "DesktopContext Class" \InProcServer32\(Default) = "C:\WINDOWS\System32\nvcpl.dll" ["NVIDIA Corporation"] "{FFB699E0-306A-11d3-8BD1-00104B6F7516}" = "Play on my TV helper" -> {HKLM...CLSID} = "NVIDIA CPL Extension" \InProcServer32\(Default) = "C:\WINDOWS\System32\nvcpl.dll" ["NVIDIA Corporation"] "{1CDB2949-8F65-4355-8456-263E7C208A5D}" = "Desktop Explorer" -> {HKLM...CLSID} = "Desktop Explorer" \InProcServer32\(Default) = "C:\WINDOWS\System32\nvshell.dll" ["NVIDIA Corporation"] "{1E9B04FB-F9E5-4718-997B-B8DA88302A47}" = "Desktop Explorer Menu" -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = "C:\WINDOWS\System32\nvshell.dll" ["NVIDIA Corporation"] "{1E9B04FB-F9E5-4718-997B-B8DA88302A48}" = "nView Desktop Context Menu" -> {HKLM...CLSID} = "nView Desktop Context Menu" \InProcServer32\(Default) = "C:\WINDOWS\System32\nvshell.dll" ["NVIDIA Corporation"] "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}" = "AVG8 Shell Extension" -> {HKLM...CLSID} = "AVG8 Shell Extension Class" \InProcServer32\(Default) = "C:\Program Files\AVG\AVG8\avgse.dll" ["AVG Technologies CZ, s.r.o."] "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension" -> {HKLM...CLSID} = "WinRAR" \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data] "{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}" = "iTunes" -> {HKLM...CLSID} = "iTunes" \InProcServer32\(Default) = "C:\Program Files\iTunes\iTunesMiniPlayer.dll" ["Apple Inc."] "{0006F045-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Custom Icon Handler" -> {HKLM...CLSID} = "Outlook File Icon Extension" \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\OLKFSTUB.DLL" [MS] "{00020D75-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Desktop Icon Handler" -> {HKLM...CLSID} = "Microsoft Office Outlook" \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\MLSHEXT.DLL" [MS] "{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler" -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office12\msohevi.dll" [MS] "{993BE281-6695-4BA5-8A2A-7AACBFAAB69E}" = "Microsoft Office Metadata Handler" -> {HKLM...CLSID} = "Microsoft Office Metadata Handler" \InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll" [MS] "{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97}" = "Microsoft Office Thumbnail Handler" -> {HKLM...CLSID} = "Microsoft Office Thumbnail Handler" \InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll" [MS] "{97F68CE3-7146-45FF-BE24-D9A7DD7CB8A2}" = "NeroCoverEd Live Icons" -> {HKLM...CLSID} = "NeroCoverEdLiveIcons Class" \InProcServer32\(Default) = "C:\Program Files\Nero\Nero8\Nero CoverDesigner\CoverEdExtension.dll" ["Nero AG"] "{E0D79304-84BE-11CE-9641-444553540000}" = "WinZip" -> {HKLM...CLSID} = "WinZip" \InProcServer32\(Default) = "C:\Program Files\WinZip\wzshlstb.dll" ["WinZip Computing, S.L."] "{E0D79305-84BE-11CE-9641-444553540000}" = "WinZip" -> {HKLM...CLSID} = "WinZip" \InProcServer32\(Default) = "C:\Program Files\WinZip\wzshlstb.dll" ["WinZip Computing, S.L."] "{E0D79306-84B |