Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Trojan won't allow Safe Mode


  • Please log in to reply

#1
Kindel

Kindel

    New Member

  • Member
  • Pip
  • 2 posts
I need help.. I've been trying to fix a virus for over 48 hours now. My husband misses me
I've tried system restore, Disk Cleanup, Defragmented a few times, Adaware, Sbybot, Spywareblaster, ewido, AVG Anti-Spyware, ClamWin_Portable, Killbox, Zappit, PC security test, a few windows programs, a few others that are supposed to be good but of course, once I got through the hour and a half plus long scan it wanted me to buy it. I've tried manually deleteing the files but it says they're running so they can't be deleted.. None of the other programs could delete them either and the ones that could be deleted came right back. Since programs were running, I figured it made sense to reboot in Safe Mode which turned out to be impossible. I tried every single combination and option to reboot in safe mode but all I got was a list of the infected files.. or some other files, mostly in System32.. where my biggest Trojans are.. and then restarted itself. It will not let me reboot in Safe Mode. I tried again and again with no luck. So then I tried ending processes in Task Manager and running Adaware again with no luck.. and then I tried the System Configuration Utility and tried the Diagnostic Startup and then ran the programs again. I am all out of options and my entire career is on my comp.. I do not want to reinstall Windows. I'm broke and my external hard drive is totally full. Can anybody help me at all?

Here is my latest Scan results:

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 7:58:47 PM 10/29/2006

+ Scan result:



C:\WINDOWS\system32\docoochb.dll -> Adware.Agent : Ignored.
C:\WINDOWS\thiselt.exe -> Adware.Agent : Ignored.
C:\System Volume Information\_restore{42837194-4F39-4538-B3E2-942950C80DC4}\RP5\A0000072.exe -> Adware.Bagon : Ignored.
C:\WINDOWS\offun.exe -> Adware.Bagon : Ignored.
C:\WINDOWS\stub_mm1.exe -> Adware.BookedSpace : Ignored.
C:\Program Files\Batty2\Batty2.dll -> Adware.CASClient : Ignored.
C:\System Volume Information\_restore{42837194-4F39-4538-B3E2-942950C80DC4}\RP5\A0000073.dll -> Adware.CASClient : Ignored.
C:\WINDOWS\system32\__delete_on_reboot__B_a_t_t_y_R_u_n_2_._d_l_l_ -> Adware.CASClient : Ignored.
HKLM\SOFTWARE\DeluxeCommunications -> Adware.DeluxeCommunications : Ignored.
HKLM\SOFTWARE\DeluxeCommunications\Internet Explorer -> Adware.DeluxeCommunications : Ignored.
HKU\S-1-5-21-1078081533-839522115-725345543-1003\Software\DeluxeCommunications -> Adware.DeluxeCommunications : Ignored.
HKU\S-1-5-21-1078081533-839522115-725345543-1003\Software\DeluxeCommunications\Internet Explorer -> Adware.DeluxeCommunications : Ignored.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ISTbarISTbar -> Adware.HotBar : Ignored.
C:\System Volume Information\_restore{42837194-4F39-4538-B3E2-942950C80DC4}\RP1\A0000002.dll -> Adware.Look2Me : Ignored.
C:\System Volume Information\_restore{42837194-4F39-4538-B3E2-942950C80DC4}\RP3\A0000009.dll -> Adware.Look2Me : Ignored.
C:\System Volume Information\_restore{42837194-4F39-4538-B3E2-942950C80DC4}\RP3\A0000013.dll -> Adware.Look2Me : Ignored.
C:\System Volume Information\_restore{42837194-4F39-4538-B3E2-942950C80DC4}\RP5\A0000078.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\RQ3214_4.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\__delete_on_reboot__a_s_i_f_i_l_3_2_._d_l_l_ -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\adidvag.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\atifil32.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\dhmv2clt.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\dmsetup.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\enp6l17s1.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\gpjml3111.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\hr0405dqe.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\hrj0051me.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\hrls0537e.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\hrnm0551e.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\irnul5591.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\it41_qcx.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\itsutil.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\j00slad71d0.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\kt84l7lq1.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\kudtuf.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\l0j80a1ued.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\l4n40e5qeh.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\lciff12n.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\llcmp80n.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\lrkrn80n.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\mKpistub.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\mlimsg.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\mv64l9jq1.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\mynetobj.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\n6n6lg5s16.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\nfmkcert.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\nlsdexts.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\nptrap.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\nxtevent.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\o4lule391h.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\p88qlil518q.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\pcisdecd.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\q6ps0g77e6.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\slsvcs.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\sqclient.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\sxfolder.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\wdsdmoe.dll -> Adware.Look2Me : Ignored.
[1392] C:\WINDOWS\system32\asifil32.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\mtuninst.exe -> Adware.MediaTickets : Ignored.
C:\WINDOWS\system32\WinNB58.dll -> Adware.Mirar : Ignored.
C:\WINDOWS\system32\msconfig.dll -> Adware.PurityScan : Ignored.
C:\WINDOWS\MirarSetup_876075.exe -> Adware.SaveNow : Ignored.
HKLM\SOFTWARE\SearchRelevancy -> Adware.SearchRelevancy : Ignored.
HKLM\SOFTWARE\SearchRelevancy\Update -> Adware.SearchRelevancy : Ignored.
C:\WINDOWS\System32n9nyb.exe -> Adware.Suggestor : Ignored.
C:\WINDOWS\system32\iqqr.exe -> Adware.Suggestor : Ignored.
C:\WINDOWS\system32\n9nyb.exe -> Adware.Suggestor : Ignored.
C:\WINDOWS\system32\vp1i4.exe -> Adware.Suggestor : Ignored.
C:\DXC9.exe -> Adware.SurfSide : Ignored.
C:\nwnmff_7.exe -> Downloader.Adload.dj : Ignored.
C:\mc44a41.exe -> Downloader.Adload.fu : Ignored.
C:\WINDOWS\system32\w02bd550.dll -> Downloader.Agent.ahv : Ignored.
C:\WINDOWS\ddhb.exe -> Downloader.Agent.ala : Ignored.
C:\WINDOWS\system32\ddabayx.dll -> Downloader.Agent.anm : Ignored.
C:\WINDOWS\system32\jkklmji.dll -> Downloader.Agent.anm : Ignored.
C:\WINDOWS\system32\mljjiih.dll -> Downloader.Agent.anm : Ignored.
C:\WINDOWS\system32\pmnnkji.dll -> Downloader.Agent.anm : Ignored.
C:\WINDOWS\system32\bootoxy.dll -> Downloader.ConHook.aa : Ignored.
C:\WINDOWS\system32\oins.exe -> Downloader.PurityScan.bl : Ignored.
C:\System Volume Information\_restore{42837194-4F39-4538-B3E2-942950C80DC4}\RP5\A0000079.dll -> Downloader.Qoologic.bj : Ignored.
C:\System Volume Information\_restore{42837194-4F39-4538-B3E2-942950C80DC4}\RP5\A0000080.exe -> Downloader.Qoologic.bj : Ignored.
C:\System Volume Information\_restore{42837194-4F39-4538-B3E2-942950C80DC4}\RP5\A0000081.exe -> Downloader.Qoologic.bj : Ignored.
C:\WINDOWS\system32\__delete_on_reboot__f_t_h_a_o_t_p_._d_l_l_ -> Downloader.Qoologic.bj : Ignored.
C:\WINDOWS\system32\__delete_on_reboot__p_v_y_e_w_._e_x_e_ -> Downloader.Qoologic.bj : Ignored.
C:\WINDOWS\system32\__delete_on_reboot__y_m_i_a_x_l_._e_x_e_ -> Downloader.Qoologic.bj : Ignored.
[1820] C:\WINDOWS\System32\fthaotp.dll -> Downloader.Qoologic.bj : Ignored.
[1828] C:\WINDOWS\System32\fthaotp.dll -> Downloader.Qoologic.bj : Ignored.
[1844] C:\WINDOWS\System32\fthaotp.dll -> Downloader.Qoologic.bj : Ignored.
[1852] C:\WINDOWS\System32\fthaotp.dll -> Downloader.Qoologic.bj : Ignored.
[1904] C:\WINDOWS\System32\fthaotp.dll -> Downloader.Qoologic.bj : Ignored.
[1920] C:\WINDOWS\System32\fthaotp.dll -> Downloader.Qoologic.bj : Ignored.
[1936] C:\WINDOWS\System32\fthaotp.dll -> Downloader.Qoologic.bj : Ignored.
[1944] C:\WINDOWS\System32\fthaotp.dll -> Downloader.Qoologic.bj : Ignored.
[1960] C:\WINDOWS\System32\fthaotp.dll -> Downloader.Qoologic.bj : Ignored.
[1968] C:\WINDOWS\System32\fthaotp.dll -> Downloader.Qoologic.bj : Ignored.
[1992] C:\WINDOWS\System32\fthaotp.dll -> Downloader.Qoologic.bj : Ignored.
[2000] C:\WINDOWS\System32\fthaotp.dll -> Downloader.Qoologic.bj : Ignored.
[2144] C:\WINDOWS\System32\fthaotp.dll -> Downloader.Qoologic.bj : Ignored.
[272] C:\WINDOWS\System32\fthaotp.dll -> Downloader.Qoologic.bj : Ignored.
[2732] C:\WINDOWS\System32\fthaotp.dll -> Downloader.Qoologic.bj : Ignored.
[2772] C:\WINDOWS\System32\fthaotp.dll -> Downloader.Qoologic.bj : Ignored.
[3208] C:\WINDOWS\System32\fthaotp.dll -> Downloader.Qoologic.bj : Ignored.
[372] C:\WINDOWS\System32\fthaotp.dll -> Downloader.Qoologic.bj : Ignored.
[484] C:\WINDOWS\System32\fthaotp.dll -> Downloader.Qoologic.bj : Ignored.
[500] C:\WINDOWS\System32\fthaotp.dll -> Downloader.Qoologic.bj : Ignored.
C:\WINDOWS\kiuj0v.exe -> Downloader.Small.afi : Ignored.
C:\WINDOWS\lt.exe -> Downloader.Small.ajc : Ignored.
C:\WINDOWS\idlemg.exe -> Downloader.Small.buy : Ignored.
C:\ac3_0003.exe -> Downloader.Small.cyh : Ignored.
C:\Program Files\Common Files\uuzk\uuzkd\vocabulary -> Downloader.TSUpdate.j : Ignored.
C:\WINDOWS\uahtdwkA.exe -> Downloader.VB.ang : Ignored.
C:\WINDOWS\dqywqlsA.exe -> Downloader.VB.nw : Ignored.
C:\WINDOWS\system32\jkkji.exe -> Dropper.Agent.amr : Ignored.
C:\WINDOWS\uahtdwk.exe -> Dropper.Agent.mu : Ignored.
C:\Program Files\BHO Plugin\plugin.dll -> Hijacker.Small.ja : Ignored.
C:\Program Files\BHO Plugin\~uninstall.exe -> Hijacker.Small.ja : Ignored.
C:\WINDOWS\srvdxwinpx.exe -> Hijacker.Small.ja : Ignored.
C:\Program Files\Creative\mege.html -> Hijacker.Small.jf : Ignored.
C:\Program Files\CyberLink\pojohabe.html -> Hijacker.Small.jf : Ignored.
C:\Program Files\Spybot - Search & Destroy\mege.html -> Hijacker.Small.jf : Ignored.
C:\Program Files\Spybot - Search & Destroy\pojohabe.html -> Hijacker.Small.jf : Ignored.
C:\WINDOWS\dqywqls.exe -> Hijacker.VB.ij : Ignored.
C:\WINDOWS\hcoqeza.exe -> Hijacker.VB.ij : Ignored.
C:\Documents and Settings\Guest\Cookies\guest@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\LocalService\Cookies\system@c.goclick[2].txt -> TrackingCookie.Goclick : Ignored.
C:\Documents and Settings\Guest\Cookies\guest@sales.liveperson[2].txt -> TrackingCookie.Liveperson : Ignored.
C:\Documents and Settings\LocalService\Cookies\system@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Ignored.
C:\WINDOWS\unwn.exe -> Trojan.Qoologic : Ignored.
C:\WINDOWS\uninst108.exe -> Trojan.VB.tg : Ignored.


::Report end
  • 0

Advertisements


#2
Kindel

Kindel

    New Member

  • Topic Starter
  • Member
  • Pip
  • 2 posts
I forgot.. Here is my HJT Scan log, as well:

Logfile of HijackThis v1.99.1
Scan saved at 12:15:48 PM, on 10/29/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\RunDll32.exe
C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\kybrdff_e41.exe
C:\Program Files\ipwins\ipwins.exe
C:\WINDOWS\xload.exe
C:\WINDOWS\hcoqezaA.exe
C:\nwnmff_e41.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\thiselt.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\dqywqlsA.exe
C:\WINDOWS\uahtdwkA.exe
C:\windows\system32\omdsregk.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\PSCastor\PSCastor.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
C:\Program Files\D-Link AirPlus G\AirPlus.exe
C:\Program Files\Infinite Mind LC\eyeQ\ARLaunch.exe
C:\Program Files\Namo\WebBoard\Bin\APMTool.exe
C:\Program Files\Namo\WebBoard\Server\mysql\bin\mysqld.exe
C:\Program Files\Namo\WebBoard\Server\apache\apache.exe
C:\PROGRA~1\MUSICM~1\MUSICM~2\MMDiag.exe
C:\Program Files\Namo\WebBoard\Server\apache\apache.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\HJT\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.my.yahoo.com/
R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\System32\pvyew.exe
F2 - REG:system.ini: UserInit=userinit.exe,argiiqe.exe
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
O4 - HKLM\..\Run: [henwn] C:\WINDOWS\henwn.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe
O4 - HKLM\..\Run: [PicasaNet] "C:\Program Files\Hello\Hello.exe" -b
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_e41.exe
O4 - HKLM\..\Run: [IpWins] C:\Program Files\ipwins\ipwins.exe
O4 - HKLM\..\Run: [xload] "C:\WINDOWS\xload.exe"
O4 - HKLM\..\Run: [hcoqezaA] C:\WINDOWS\hcoqezaA.exe
O4 - HKLM\..\Run: [newname] C:\\nwnmff_e41.exe
O4 - HKLM\..\Run: [w02bd550.dll] RUNDLL32.EXE w02bd550.dll,I2 00266531002bd550
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKLM\..\Run: [SystemDoctor 2006 Free] C:\Program Files\SystemDoctor 2006 Free\sd2006.exe -scan
O4 - HKLM\..\Run: [pop06apelt] C:\WINDOWS\thiselt.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [dqywqlsA] C:\WINDOWS\dqywqlsA.exe
O4 - HKLM\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKLM\..\Run: [uahtdwkA] C:\WINDOWS\uahtdwkA.exe
O4 - HKLM\..\Run: [{5F-F9-9D-DD-ZN}] C:\windows\system32\omdsregk.exe GEN001
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5 -reboot 1
O4 - HKCU\..\Run: [CAS2] "C:\Program Files\System Files\System.exe"
O4 - HKCU\..\Run: [Sanl] C:\DOCUME~1\Kindel\MYDOCU~1\YSTEM3~1\MHTA~1.EXE
O4 - HKCU\..\Run: [PSCastor] "C:\Program Files\PSCastor\PSCastor.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKCU\..\Run: [PSDream] "C:\Program Files\PSDream\PSDream.exe"
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\dwdsregt.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: D-Link AirPlus G Configuration Utility.lnk = ?
O4 - Global Startup: MiniEYE-MiniREAD Launch.lnk = C:\Program Files\Infinite Mind LC\eyeQ\ARLaunch.exe
O4 - Global Startup: Namo APM Manager.lnk = C:\Program Files\Namo\WebBoard\Bin\APMTool.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\System32\dmonwv.dll
O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\System32\dmonwv.dll
O15 - Trusted Zone: *.adgate.info
O15 - Trusted Zone: *.dollarrevenue.com
O15 - Trusted Zone: *.elitemediagroup.net
O15 - Trusted Zone: *.imagesrvr.com
O15 - Trusted Zone: *.matcash.com
O15 - Trusted Zone: *.media-motor.com
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.mediatickets.net
O15 - Trusted Zone: *.mmohsix.com
O15 - Trusted Zone: *.snipernet.biz
O15 - Trusted Zone: *.sxload.com
O15 - Trusted Zone: *.systemdoctor.com
O15 - Trusted Zone: *.winantivirus.com
O15 - Trusted Zone: *.adgate.info (HKLM)
O15 - Trusted Zone: *.dollarrevenue.com (HKLM)
O15 - Trusted Zone: *.elitemediagroup.net (HKLM)
O15 - Trusted Zone: *.imagesrvr.com (HKLM)
O15 - Trusted Zone: *.matcash.com (HKLM)
O15 - Trusted Zone: *.media-motor.com (HKLM)
O15 - Trusted Zone: *.mediatickets.net (HKLM)
O15 - Trusted Zone: *.snipernet.biz (HKLM)
O15 - Trusted Zone: *.systemdoctor.com (HKLM)
O15 - Trusted Zone: *.winantivirus.com (HKLM)
O16 - DPF: {084F552D-19EB-4668-9788-984CBC781A8F} - http://survey.otxres...m/Preloader.dll
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://www.driveclea...leanerstart.cab
O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} - http://promo.dollarr...138302D2D2D.exe
O16 - DPF: {4C226336-4032-489F-9674-67E74225979B} - http://www.otxresear...ia/OTXMedia.dll
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg...l_v1-0-3-24.cab
O16 - DPF: {5526B4C6-63D6-41A1-9783-0FABF529859A} - http://cabs.elitemed...s/mediaview.cab
O16 - DPF: {6632A7E9-FE1F-43D2-A04A-A15951ED63E0} - http://mediaplayer.w...ler/install.cab
O16 - DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} (Install Class) - http://updates.lifes...ll/pinstall.cab
O16 - DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} - http://awbeta.net-nu.../FIX/WinATS.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1....loadManager.ocx
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://download.cdn....FreeInstall.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://download.game...inematycoon.cab
O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - mk:@MSITStore:C:\DOCUME~1\Kindel\LOCALS~1\Temp\winfix.chm::/SystemDoctor2006FreeInstall.cab
O18 - Protocol: advert - {7DC356B2-7366-4F19-BF7A-4875F6AABEA0} - C:\WINDOWS\System32\nodeipproc.dll (file missing)
O20 - AppInit_DLLs: dxclib303562752.dll
O20 - Winlogon Notify: Fonts - C:\WINDOWS\system32\hrlu0539e.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\S2luZGVs\command.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\uahtdwk.exe
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP