Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

infected by worm


  • Please log in to reply

#1
jabr

jabr

    New Member

  • Member
  • Pip
  • 3 posts
Hi,

Last week my computer was running real slow and I could barely connect to the internet.

So, I came here in desperate need of help. I already did all the steps you recommend and I list bellow all the logs.

I don't now if my computer is already clean or not. Could you please help me?

Thank you very much,
Jaime Ramos

===================

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 13:42:37 12-12-2006

+ Scan result:



C:\WINDOWS\ydqxrlh.exe -> Adware.BetterInternet : Cleaned.
C:\Documents and Settings\jabr\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-334f0d06-5f03aa3f.zip/Dummy.class -> Not-A-Virus.Exploit.ByteVerify : Cleaned.
:mozilla.10:C:\RECYCLER\NPROTECT\01129230.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.10:C:\RECYCLER\NPROTECT\01129235.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.10:C:\RECYCLER\NPROTECT\01129237.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.10:C:\RECYCLER\NPROTECT\01129420.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.11:C:\RECYCLER\NPROTECT\01129230.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.11:C:\RECYCLER\NPROTECT\01129235.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.11:C:\RECYCLER\NPROTECT\01129237.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.11:C:\RECYCLER\NPROTECT\01129420.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.12:C:\RECYCLER\NPROTECT\01129233.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.12:C:\RECYCLER\NPROTECT\01129235.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.12:C:\RECYCLER\NPROTECT\01129237.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.12:C:\RECYCLER\NPROTECT\01129420.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.13:C:\RECYCLER\NPROTECT\01129233.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.13:C:\RECYCLER\NPROTECT\01129235.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.13:C:\RECYCLER\NPROTECT\01129237.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.13:C:\RECYCLER\NPROTECT\01129420.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.13:C:\RECYCLER\NPROTECT\01129447.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.14:C:\RECYCLER\NPROTECT\01129447.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.15:C:\RECYCLER\NPROTECT\01129447.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.16:C:\RECYCLER\NPROTECT\01129447.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.17:C:\Documents and Settings\jabr\Application Data\Mozilla\Firefox\Profiles\zvmybib1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.17:C:\RECYCLER\NPROTECT\01129447.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.17:C:\RECYCLER\NPROTECT\01129448.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.17:C:\RECYCLER\NPROTECT\01129449.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.17:C:\RECYCLER\NPROTECT\01129450.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.17:C:\RECYCLER\NPROTECT\01129453.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.17:C:\RECYCLER\NPROTECT\01129506.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.18:C:\Documents and Settings\jabr\Application Data\Mozilla\Firefox\Profiles\zvmybib1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.18:C:\RECYCLER\NPROTECT\01129447.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.18:C:\RECYCLER\NPROTECT\01129448.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.18:C:\RECYCLER\NPROTECT\01129449.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.18:C:\RECYCLER\NPROTECT\01129450.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.18:C:\RECYCLER\NPROTECT\01129453.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.18:C:\RECYCLER\NPROTECT\01129506.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.19:C:\Documents and Settings\jabr\Application Data\Mozilla\Firefox\Profiles\zvmybib1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.19:C:\RECYCLER\NPROTECT\01129448.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.19:C:\RECYCLER\NPROTECT\01129449.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.19:C:\RECYCLER\NPROTECT\01129450.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.19:C:\RECYCLER\NPROTECT\01129453.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.19:C:\RECYCLER\NPROTECT\01129506.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.20:C:\Documents and Settings\jabr\Application Data\Mozilla\Firefox\Profiles\zvmybib1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.20:C:\RECYCLER\NPROTECT\01129448.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.20:C:\RECYCLER\NPROTECT\01129449.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.20:C:\RECYCLER\NPROTECT\01129450.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.20:C:\RECYCLER\NPROTECT\01129453.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.20:C:\RECYCLER\NPROTECT\01129506.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.21:C:\Documents and Settings\jabr\Application Data\Mozilla\Firefox\Profiles\zvmybib1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.21:C:\RECYCLER\NPROTECT\01129448.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.21:C:\RECYCLER\NPROTECT\01129449.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.21:C:\RECYCLER\NPROTECT\01129450.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.21:C:\RECYCLER\NPROTECT\01129453.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.21:C:\RECYCLER\NPROTECT\01129506.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.22:C:\Documents and Settings\jabr\Application Data\Mozilla\Firefox\Profiles\zvmybib1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.22:C:\RECYCLER\NPROTECT\01129448.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.22:C:\RECYCLER\NPROTECT\01129449.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.22:C:\RECYCLER\NPROTECT\01129450.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.22:C:\RECYCLER\NPROTECT\01129453.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.22:C:\RECYCLER\NPROTECT\01129506.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.6:C:\RECYCLER\NPROTECT\01129229.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.6:C:\RECYCLER\NPROTECT\01129233.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.6:C:\RECYCLER\NPROTECT\01129237.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.7:C:\RECYCLER\NPROTECT\01129228.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.7:C:\RECYCLER\NPROTECT\01129229.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.7:C:\RECYCLER\NPROTECT\01129233.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.8:C:\RECYCLER\NPROTECT\01129228.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.8:C:\RECYCLER\NPROTECT\01129229.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.8:C:\RECYCLER\NPROTECT\01129230.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.8:C:\RECYCLER\NPROTECT\01129233.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.8:C:\RECYCLER\NPROTECT\01129235.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.8:C:\RECYCLER\NPROTECT\01129420.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.9:C:\RECYCLER\NPROTECT\01129229.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.9:C:\RECYCLER\NPROTECT\01129230.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.9:C:\RECYCLER\NPROTECT\01129233.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.9:C:\RECYCLER\NPROTECT\01129235.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.9:C:\RECYCLER\NPROTECT\01129237.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.9:C:\RECYCLER\NPROTECT\01129420.MOZ -> TrackingCookie.2o7 : Cleaned.
:mozilla.15:C:\RECYCLER\NPROTECT\01128813.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.16:C:\RECYCLER\NPROTECT\01128814.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.16:C:\RECYCLER\NPROTECT\01128816.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.16:C:\RECYCLER\NPROTECT\01128818.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.16:C:\RECYCLER\NPROTECT\01128819.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.16:C:\RECYCLER\NPROTECT\01128820.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.16:C:\RECYCLER\NPROTECT\01128822.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.16:C:\RECYCLER\NPROTECT\01128823.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.16:C:\RECYCLER\NPROTECT\01128824.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.16:C:\RECYCLER\NPROTECT\01128825.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.16:C:\RECYCLER\NPROTECT\01128826.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.16:C:\RECYCLER\NPROTECT\01128827.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.16:C:\RECYCLER\NPROTECT\01128829.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.16:C:\RECYCLER\NPROTECT\01129227.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.18:C:\RECYCLER\NPROTECT\01129228.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.21:C:\RECYCLER\NPROTECT\01129229.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.22:C:\RECYCLER\NPROTECT\01129230.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.24:C:\RECYCLER\NPROTECT\01129233.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.24:C:\RECYCLER\NPROTECT\01129235.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.24:C:\RECYCLER\NPROTECT\01129237.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.24:C:\RECYCLER\NPROTECT\01129420.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.25:C:\RECYCLER\NPROTECT\01129447.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.29:C:\Documents and Settings\jabr\Application Data\Mozilla\Firefox\Profiles\zvmybib1.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.29:C:\RECYCLER\NPROTECT\01129448.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.29:C:\RECYCLER\NPROTECT\01129449.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.29:C:\RECYCLER\NPROTECT\01129450.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.29:C:\RECYCLER\NPROTECT\01129453.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.29:C:\RECYCLER\NPROTECT\01129506.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.6:C:\RECYCLER\NPROTECT\01128812.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.7:C:\RECYCLER\NPROTECT\01128765.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.8:C:\RECYCLER\NPROTECT\01128766.MOZ -> TrackingCookie.Atdmt : Cleaned.
:mozilla.9:C:\RECYCLER\NPROTECT\01128751.MOZ -> TrackingCookie.Atdmt : Cleaned.


::Report end



===============


Incident Status Location

Spyware:spyware/betterinet Not disinfected c:\windows\inf\satmat.inf
Adware:adware/twain-tech Not disinfected c:\windows\satmat.ini
Adware:adware/ncase Not disinfected c:\temp\FLEOK
Adware:adware/wupd Not disinfected c:\program files\Windows SyncroAd
Adware:adware/localnrd Not disinfected Windows Registry
Adware:adware/blazefind Not disinfected Windows Registry
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\jabr\Application Data\Mozilla\Firefox\Profiles\zvmybib1.default\cookies.txt[.xiti.com/]
Virus:W32/Sober.V.worm!CME-456 Disinfected C:\Documents and Settings\jabr\Application Data\Thunderbird\Profiles\default.ov2\ImapMail\mailcentrl.math.ist.utl.pt\INBOX[mail_info.zip][Winzipped-Text_Data.txt .pif]
Virus:W32/Sober.V.worm!CME-456 Disinfected C:\Documents and Settings\jabr\Application Data\Thunderbird\Profiles\default.ov2\ImapMail\mailcentrl.math.ist.utl.pt\INBOX[account_info.zip][Winzipped-Text_Data.txt .pif]
Virus:W32/Eyeveg.D.worm Disinfected C:\Documents and Settings\jabr\Application Data\Thunderbird\Profiles\default.ov2\ImapMail\mailcentrl.math.ist.utl.pt\INBOX[image.zip][image.jpg .scr]


=====

Logfile of HijackThis v1.99.1
Scan saved at 16:34:11, on 12-12-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\PROGRA~1\NORTON~1\NORTON~2\GHOSTS~2.EXE
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://wslc.math.ist.utl.pt/
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RegEasy.exe] C:\Program Files\RegistryEasy\RegEasy.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: APC UPS Status.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\GHOSTS~2.EXE
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe


====================
uninstal list
=====================

µBook 0.9g
3D Windows XP Screen Saver
Ad-Aware SE Personal
Adobe Reader 6.0.1
AFPL Ghostscript 8.00
AFPL Ghostscript Fonts
Agere Systems PCI Soft Modem
APC PowerChute Personal Edition
AVG Anti-Spyware 7.5
AVG Free Edition
CCleaner (remove only)
CDisplay 1.8
CoreVorbis Audio Decoder (remove only)
DivX
DivX Player
DVD Shrink 3.2
DVD-lab Studio 1.25
ewido anti-malware
Google Earth
GSpot Codec Information Appliance
GSview 4.4
HighMAT Extension to Microsoft Windows XP CD Writing Wizard
HijackThis 1.99.1
iTunes
J2SE Runtime Environment 5.0 Update 4
J2SE Runtime Environment 5.0 Update 6
Java 2 Runtime Environment, SE v1.4.2_05
Java 2 Runtime Environment, SE v1.4.2_06
Lavasoft VX2 Cleaner
LINGO 9.0
LiveReg (Symantec Corporation)
LiveUpdate 2.7 (Symantec Corporation)
Lizardtech DjVu Control
Macromedia Flash Player 8
Mathematica 5
MATLAB 6.1
McAfee VirusScan Enterprise
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB886903)
Microsoft Office FrontPage 2003
Microsoft Office Professional Edition 2003
MiKTeX
Mozilla Firefox (1.5.0.8)
Mozilla Sunbird 0.3a1
Mozilla Thunderbird (0.7.3)
Mozilla Thunderbird (1.0.7)
MP3 Creation Pack for WinXP
MSN Messenger 7.5
MSN Music Assistant
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 Parser and SDK
Nero 6
Norton Utilities 2003 for Windows
NVIDIA Drivers
Panda ActiveScan
PowerDVD
QuickTime
RealPlayer
Realtek AC'97 Audio
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB925486)
SiSoftware Sandra Standard 2004.SP2b (Win32 x86)
Skype™ 1.0
Spybot - Search & Destroy 1.3
SSH Secure Shell
SUPERAntiSpyware Free Edition
SWI-Prolog (remove only)
TeXnicCenter Version 1 Beta 6.31 (Firenze)
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Windows Defender
Windows Installer 3.1 (KB893803)
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB834707
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
WinRAR archiver
WinSCP 3.7.4
Yahoo! Toolbar
  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP