when I boot up my box, it just sits there...I have to manually run a task from task manager to run explorer.exe (So now none of my malware software is running...I'm being infected as we speak)
Known Issues:
ki1) When I boot up my box, it just sits there (because of "d5" below)
ki2) I continue to get a popup from "s5" that says "Found problem: Virtumonde" (it says it removes it though)
ki3) I contiue to get a popup from AVG "s1" that says "Klone Virus found" and I always move it to the vault, but it's always called comething different.
Virus/Malware Software that I have been using:
s1) AVG
s2) SpywareBlaster
s3) SBS&D
s4) Ad-Aware SE
s5) Spyware Doctor (On a 30 day trial)
s6) Registry Mechanic
Here's what I have done so far:
d1) Ran ATF Cleaner
d2) Made a restore point and cleared out old ones
d3) Ran Ad-Aware SE
d4) Booted to SAFE mode and ran AVG Anti-Spyware (You call it "ewido" I assume) (Logs Below)
d5) Booted back to Normal (This is when "ki1" happened)
d6) Ran the "Online - Panda Activescan" (Logs Below)
d7) Ran Hijack-This (Logs Below)
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 3:24:21 AM 10/28/2006
+ Scan result:
E:\Documents and Settings\ndarby\Local Settings\Temp\10498.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\10904.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\11064.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\11482.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\11504.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\11649.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\12333.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\12594.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\12608.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\12787.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\13671.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\13712.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\13985.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\14352.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\14383.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\14521.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\14836.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\15130.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\15535.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\15709.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\16201.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\16706.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\1736.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\17983.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\1827.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\19861.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\20046.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\22277.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\23324.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\23379.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\23446.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\23886.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\24270.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\2432.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\24392.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\25247.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\25748.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\25940.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\26430.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\26432.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\26562.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\26584.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\27428.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\28584.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\28741.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\29600.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\29933.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\30034.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\30277.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\30381.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\30467.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\30567.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\30935.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\31087.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\31890.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\31969.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\32019.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\3548.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\3947.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\4005.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\5565.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\5928.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\6058.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\6258.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\66.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\6813.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\7683.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\8161.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\8603.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\9130.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\9231.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\9463.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\9626.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Local Settings\Temp\9854.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{8E9D16E5-8858-41AF-B0A2-A9129A39D122}\RP379\A0013615.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{8E9D16E5-8858-41AF-B0A2-A9129A39D122}\RP393\A0013785.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{8E9D16E5-8858-41AF-B0A2-A9129A39D122}\RP395\A0013840.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\WINDOWS\system32\pdr.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{8E9D16E5-8858-41AF-B0A2-A9129A39D122}\RP394\A0013827.exe -> Downloader.PurityScan.an : Cleaned with backup (quarantined).
C:\Documents and Settings\ndarby\Local Settings\Temp\cpylvygk.dll -> Logger.VBStat.e : Cleaned with backup (quarantined).
C:\Documents and Settings\ndarby\Local Settings\Temp\jgnskwai.dll -> Logger.VBStat.e : Cleaned with backup (quarantined).
C:\Documents and Settings\ndarby\Local Settings\Temp\kxdjqicq.dll -> Logger.VBStat.e : Cleaned with backup (quarantined).
C:\Documents and Settings\ndarby\Local Settings\Temp\mpdnifjy.dll -> Logger.VBStat.e : Cleaned with backup (quarantined).
C:\Documents and Settings\ndarby\Local Settings\Temp\oatbncle.dll -> Logger.VBStat.e : Cleaned with backup (quarantined).
C:\Documents and Settings\ndarby\Local Settings\Temp\oeseluru.dll -> Logger.VBStat.e : Cleaned with backup (quarantined).
C:\Documents and Settings\ndarby\Local Settings\Temp\wteddqid.dll -> Logger.VBStat.e : Cleaned with backup (quarantined).
C:\Program Files\RealVNC\VNC4\vncconfig.exe -> Not-A-Virus.RemoteAdmin.Win32.WinVNC.4 : Cleaned with backup (quarantined).
C:\Program Files\RealVNC\VNC4\vncviewer.exe -> Not-A-Virus.RemoteAdmin.Win32.WinVNC.4 : Cleaned with backup (quarantined).
C:\Program Files\RealVNC\VNC4\wm_hooks.dll -> Not-A-Virus.RemoteAdmin.Win32.WinVNC.4 : Cleaned with backup (quarantined).
E:\Documents and Settings\ndarby\Cookies\ndarby@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
E:\Documents and Settings\ndarby\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
E:\Documents and Settings\ndarby\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
E:\Documents and Settings\ndarby\Cookies\[email protected][2].txt -> TrackingCookie.Admarketplace : Cleaned.
E:\Documents and Settings\ndarby\Cookies\[email protected][1].txt -> TrackingCookie.Burstbeacon : Cleaned.
E:\Documents and Settings\ndarby\Cookies\ndarby@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
E:\Documents and Settings\ndarby\Local Settings\Temp\Cookies\ndarby@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
E:\Documents and Settings\ndarby\Cookies\ndarby@com[2].txt -> TrackingCookie.Com : Cleaned.
E:\Documents and Settings\ndarby\Cookies\ndarby@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned.
E:\Documents and Settings\ndarby\Cookies\[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned.
E:\Documents and Settings\ndarby\Cookies\[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned.
E:\Documents and Settings\ndarby\Cookies\[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned.
E:\Documents and Settings\ndarby\Local Settings\Temp\Cookies\[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned.
E:\Documents and Settings\ndarby\Local Settings\Temp\Cookies\[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned.
E:\Documents and Settings\ndarby\Local Settings\Temp\Cookies\[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned.
E:\Documents and Settings\ndarby\Local Settings\Temp\Cookies\[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned.
E:\Documents and Settings\ndarby\Local Settings\Temp\Cookies\[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned.
E:\Documents and Settings\ndarby\Local Settings\Temp\Cookies\[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned.
E:\Documents and Settings\ndarby\Local Settings\Temp\Cookies\[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned.
E:\Documents and Settings\ndarby\Local Settings\Temp\Cookies\[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned.
E:\Documents and Settings\ndarby\Local Settings\Temp\Cookies\[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned.
E:\Documents and Settings\ndarby\Local Settings\Temp\Cookies\[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned.
E:\Documents and Settings\ndarby\Local Settings\Temp\Cookies\[email protected][1].txt -> TrackingCookie.Esomniture : Cleaned.
E:\Documents and Settings\ndarby\Local Settings\Temp\Cookies\[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned.
E:\Documents and Settings\ndarby\Local Settings\Temp\Cookies\[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned.
E:\Documents and Settings\ndarby\Local Settings\Temp\Cookies\[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned.
E:\Documents and Settings\ndarby\Local Settings\Temp\Cookies\[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned.
E:\Documents and Settings\ndarby\Local Settings\Temp\Cookies\[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned.
E:\Documents and Settings\ndarby\Local Settings\Temp\Cookies\[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned.
E:\WINDOWS\Temp\Cookies\[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned.
E:\WINDOWS\Temp\Cookies\[email protected][1].txt -> TrackingCookie.Esomniture : Cleaned.
E:\WINDOWS\Temp\Cookies\[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned.
E:\Documents and Settings\ndarby\Cookies\[email protected][1].txt -> TrackingCookie.Liveperson : Cleaned.
E:\Documents and Settings\ndarby\Cookies\[email protected][2].txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
E:\Documents and Settings\ndarby\Cookies\[email protected][1].txt -> TrackingCookie.Realcastmedia : Cleaned.
E:\Documents and Settings\ndarby\Cookies\[email protected][2].txt -> TrackingCookie.Reliablestats : Cleaned.
E:\Documents and Settings\ndarby\Cookies\[email protected][2].txt -> TrackingCookie.Specificclick : Cleaned.
E:\Documents and Settings\ndarby\Cookies\[email protected][2].txt -> TrackingCookie.Starware : Cleaned.
E:\Documents and Settings\ndarby\Cookies\ndarby@starware[2].txt -> TrackingCookie.Starware : Cleaned.
E:\Documents and Settings\ndarby\Cookies\ndarby@trafficmp[1].txt -> TrackingCookie.Trafficmp : Cleaned.
E:\Documents and Settings\ndarby\Cookies\ndarby@webstat[2].txt -> TrackingCookie.Web-stat : Cleaned.
E:\Documents and Settings\ndarby\Cookies\[email protected][1].txt -> TrackingCookie.Yieldmanager : Cleaned.
E:\Documents and Settings\ndarby\Cookies\ndarby@yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.
::Report end
---------------------------------------------------------
Online - Panda Activescan
---------------------------------------------------------
Incident Status Location
Possible Virus. Not disinfected C:\Documents and Settings\ndarby\Desktop\AnyDVD\Anydvd4.5.7 (w-crack).zip[b-any21.zip][anydvd.exe]
Possible Virus. Not disinfected C:\Documents and Settings\ndarby\Desktop\AnyDVD\b-any21.zip[anydvd.exe]
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\system32\fojpjubj.exe
Adware:Adware/WebSearch Not disinfected C:\WINDOWS\system32\kkneexxd.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\system32\ouvnxwgt.exe
Spyware:Cookie/Hbmediapro Not disinfected E:\Documents and Settings\ndarby\Cookies\[email protected][2].txt
Spyware:Cookie/Belnk Not disinfected E:\Documents and Settings\ndarby\Cookies\[email protected][1].txt
Spyware:Cookie/Atwola Not disinfected E:\Documents and Settings\ndarby\Cookies\ndarby@atwola[1].txt
Spyware:Cookie/Azjmp Not disinfected E:\Documents and Settings\ndarby\Cookies\ndarby@azjmp[1].txt
Spyware:Cookie/Banner Not disinfected E:\Documents and Settings\ndarby\Cookies\ndarby@banner[2].txt
Spyware:Cookie/Belnk Not disinfected E:\Documents and Settings\ndarby\Cookies\ndarby@belnk[2].txt
Spyware:Cookie/Cassava Not disinfected E:\Documents and Settings\ndarby\Cookies\ndarby@cassava[1].txt
Spyware:Cookie/Belnk Not disinfected E:\Documents and Settings\ndarby\Cookies\[email protected][2].txt
Spyware:Cookie/ErrorSafe Not disinfected E:\Documents and Settings\ndarby\Cookies\ndarby@errorsafe[1].txt
Spyware:Cookie/Go Not disinfected E:\Documents and Settings\ndarby\Cookies\ndarby@go[1].txt
Spyware:Cookie/Screensavers Not disinfected E:\Documents and Settings\ndarby\Cookies\[email protected][1].txt
Spyware:Cookie/OfferOptimizer Not disinfected E:\Documents and Settings\ndarby\Cookies\ndarby@offeroptimizer[1].txt
Spyware:Cookie/Rn11 Not disinfected E:\Documents and Settings\ndarby\Cookies\ndarby@rn11[1].txt
Spyware:Cookie/Target Not disinfected E:\Documents and Settings\ndarby\Cookies\ndarby@target[2].txt
Spyware:Cookie/seeqA Not disinfected E:\Documents and Settings\ndarby\Cookies\[email protected][1].txt
Spyware:Cookie/Seeq Not disinfected E:\Documents and Settings\ndarby\Cookies\[email protected][1].txt
Spyware:Cookie/Banner Not disinfected E:\Documents and Settings\ndarby\Local Settings\Temp\Cookies\ndarby@banner[1].txt
Spyware:Cookie/360i Not disinfected E:\Documents and Settings\ndarby\Local Settings\Temp\Cookies\[email protected][1].txt
Spyware:Cookie/Belnk Not disinfected E:\Documents and Settings\ndarby\Local Settings\Temp\Cookies\[email protected][1].txt
Spyware:Cookie/Target Not disinfected E:\Documents and Settings\ndarby\Local Settings\Temp\Cookies\ndarby@target[2].txt
Adware:Adware/PurityScan Not disinfected E:\WINDOWS\system32\?ti2evxx.exe
---------------------------------------------------------
Hijack This
---------------------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 12:39:09 PM, on 10/28/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Tanagra\Memeo\MemeoService.exe
D:\Bluetooth\bin\btwdins.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\ndarby\Desktop\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://verizon.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapp.../search/ie.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://verizon.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = N8
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [iTunesHelper] "D:\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [MediaManager] D:\Verizon\Media Manager\MediaManager.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [updateMgr] "D:\Acrobat\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Startup: BHODemon 2.0.lnk = C:\Program Files\BHODemon 2\BHODemon.exe
O4 - Startup: Memeo Launcher.lnk = C:\Program Files\Tanagra\Memeo\MemeoLauncher.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Acrobat\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - D:\Bluetooth\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Bluetooth\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Bluetooth\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemyfi...oad/tgctlcm.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop...p/PCPitStop.CAB
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1133389204727
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://rtc3.webresp...p/TLIEFlash.CAB
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1....loadManager.ocx
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zon...ro.cab32846.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.c...driveragent.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.h.../qdiagh.cab?326
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zon...wn.cab31267.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Memeo (BMUService) - Memeo - C:\Program Files\Tanagra\Memeo\MemeoService.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - D:\Bluetooth\bin\btwdins.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service (file missing)