Hey RatHat,
Unfortunately the PC is barely usable now, the CPU quickly gets pegged at 100%. The cleaning seems to have awoken some latent viruses. I'm including the results of the OTM.txt file, the Panda scan (took me a few tries to complete) and the latest HijackThis log file. There are about 20 iexplore.exe processes in my windows processes list but they are not visible IE browsers.
OTM.txt:
C:\Documents and Settings\All Users\Application Data\CyberLink\PowerDVD\HTML\help\[X]l0v3ly.x moved successfully.
C:\hex.exe moved successfully.
C:\WINDOWS\expacc.exe moved successfully.
File/Folder C:\WINDOWS\pss\autorun.exe not found.
DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\LogCrypt.dll
C:\WINDOWS\SYSTEM32\LogCrypt.dll NOT unregistered.
C:\WINDOWS\SYSTEM32\LogCrypt.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\WLCtrl32.dll
C:\WINDOWS\SYSTEM32\WLCtrl32.dll NOT unregistered.
C:\WINDOWS\SYSTEM32\WLCtrl32.dll moved successfully.
C:\xz.bat moved successfully.
OTMoveIt2 v1.0.20 log created on 02182008_173915
Panda scan:
;*******************************************************************************
*********************************************************************************
*******************
ANALYSIS: 2008-02-19 13:30:48
PROTECTIONS: 1
MALWARE: 62
SUSPECTS: 0
;*******************************************************************************
*********************************************************************************
*******************
PROTECTIONS
Description Version Active Updated
;===============================================================================
=================================================================================
===================
avast! antivirus 4.7.1098 [VPS 080218-0] 4.7.1098 No Yes
;===============================================================================
=================================================================================
===================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===============================================================================
=================================================================================
===================
00000431 adware/ist.istbar Adware No 1 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7C559105-9ECF-42b8-B3F7-832E75EDD959}
00000431 adware/ist.istbar Adware No 1 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{386A771C-E96A-421F-8BA7-32F1B706892F}
00020942 adware/exact.bargainbuddy Adware No 0 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0878B424-1F95-4e26-B5AB-F0D349D89650}
00029434 spyware/virtumonde Spyware No 1 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{79A576C4-B7A9-47EC-B57C-2CE5CA6ECC6A}
00029434 spyware/virtumonde Spyware No 1 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
00034463 adware/wupd Adware No 0 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6}
00034463 adware/wupd Adware No 0 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6}
00040415 adware/wintools Adware No 0 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{87067F04-DE4C-4688-BC3C-4FCF39D609E7}
00047863 adware/ieplugin Adware No 0 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{886DDE35-E955-11D0-A707-000000521958}
00047863 adware/ieplugin Adware No 0 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{886DDE35-E585-11D0-A707-000000521958}
00055986 adware/consumeralertsystem Adware No 0 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4208FB4D-4E53-4F5A-BF7A-3E047DDB5281}
00091942 adware/favoriteman Adware No 0 Yes No c:\windows\downloaded program files\atpartners.inf
00122828 Bck/IRC.Mirc.Based Virus/Trojan No 0 Yes No C:\Documents and Settings\All Users\Application Data\CyberLink\PowerDVD\HTML\help\v1rg1n.dll
00139059 Cookie/Traffic Marketplace TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.trafficmp.com/]
00139059 Cookie/Traffic Marketplace TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.trafficmp.com/]
00139059 Cookie/Traffic Marketplace TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.trafficmp.com/]
00139059 Cookie/Traffic Marketplace TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.trafficmp.com/]
00139059 Cookie/Traffic Marketplace TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.trafficmp.com/]
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.casalemedia.com/]
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.casalemedia.com/]
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.casalemedia.com/]
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.casalemedia.com/]
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.casalemedia.com/]
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.casalemedia.com/]
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.casalemedia.com/]
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.casalemedia.com/]
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.casalemedia.com/]
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.casalemedia.com/]
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Cookies\dad@doubleclick[1].txt
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.doubleclick.net/]
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.doubleclick.net/]
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Cookies\dad@atdmt[2].txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.atdmt.com/]
00139535 Application/Processor HackTools No 0 Yes No C:\smitfraudfix\SmitfraudFix\Process.exe
00139535 Application/Processor HackTools No 0 Yes No C:\Documents and Settings\Dad\Desktop\SmitfraudFix\Process.exe
00139535 Application/Processor HackTools No 0 No No C:\temp\VirtumundoBeGone.exe[²₧Ç]
00139535 Application/Processor HackTools No 0 Yes No C:\WINDOWS\SYSTEM32\Process.exe
00145439 Cookie/Santa Monica networks inc TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\anyuser@smni[1].txt
00145439 Cookie/Santa Monica networks inc TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\anyuser@smni[2].txt
00145439 Cookie/Santa Monica networks inc TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\jayallen@smni[1].txt
00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.fastclick.net/]
00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.fastclick.net/]
00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.fastclick.net/]
00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.fastclick.net/]
00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.fastclick.net/]
00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.fastclick.net/]
00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.tribalfusion.com/]
00145738 Cookie/Mediaplex TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.mediaplex.com/]
00145738 Cookie/Mediaplex TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.mediaplex.com/]
00145786 Cookie/LinkExchange TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\anyuser@linkexchange[2].txt
00145786 Cookie/LinkExchange TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\jayallen@linkexchange[1].txt
00145786 Cookie/LinkExchange TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\jayallen@linkexchange[4].txt
00145807 Cookie/Linksynergy TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.linksynergy.com/]
00145807 Cookie/Linksynergy TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.linksynergy.com/]
00145881 Cookie/NewMedia TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.anm.co.uk/]
00148925 Cookie/Preferences TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\jayallen@preferences[3].txt
00148925 Cookie/Preferences TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\
[email protected]00148925 Cookie/Preferences TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\anyuser@preferences[1].txt
00148925 Cookie/Preferences TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\jayallen@preferences[2].txt
00148925 Cookie/Preferences TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\anyuser@preferences[2].txt
00148925 Cookie/Preferences TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\jayallen@preferences[5].txt
00148925 Cookie/Preferences TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\jayallen@preferences[1].txt
00167430 Cookie/myaffiliateprogram TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\
[email protected][1].txt
00167642 Cookie/Com.com TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\anyuser@com[2].txt
00167642 Cookie/Com.com TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.com.com/]
00167642 Cookie/Com.com TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\jayallen@com[2].txt
00167744 Cookie/GoStats TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\jayallen@gostats[1].txt
00167774 Cookie/web-stat TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\
[email protected][1].txt
00167774 Cookie/web-stat TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\
[email protected][1].txt
00168048 Cookie/Overture TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.perf.overture.com/]
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[ad.yieldmanager.com/]
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[ad.yieldmanager.com/]
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[ad.yieldmanager.com/]
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[ad.yieldmanager.com/]
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[ad.yieldmanager.com/]
00168061 Cookie/Apmebf TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.apmebf.com/]
00168061 Cookie/Apmebf TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.apmebf.com/]
00168076 Cookie/BurstNet TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.burstnet.com/]
00168076 Cookie/BurstNet TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.burstnet.com/]
00168076 Cookie/BurstNet TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.burstnet.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.serving-sys.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.serving-sys.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.serving-sys.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.serving-sys.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.serving-sys.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.serving-sys.com/]
00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.bs.serving-sys.com/]
00168097 Cookie/BurstBeacon TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[www.burstbeacon.com/]
00168114 Cookie/onestat.com TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[stat.onestat.com/]
00168114 Cookie/onestat.com TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[stat.onestat.com/]
00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.advertising.com/]
00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Cookies\dad@advertising[2].txt
00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.advertising.com/]
00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.advertising.com/]
00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.advertising.com/]
00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.advertising.com/]
00170304 Cookie/WebtrendsLive TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[statse.webtrendslive.com/]
00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.ads.pointroll.com/]
00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.ads.pointroll.com/]
00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.ads.pointroll.com/]
00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.ads.pointroll.com/]
00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.ads.pointroll.com/]
00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.ads.pointroll.com/]
00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.ads.pointroll.com/]
00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.ads.pointroll.com/]
00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.ads.pointroll.com/]
00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.ads.pointroll.com/]
00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.ads.pointroll.com/]
00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.ads.pointroll.com/]
00170554 Cookie/Overture TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.overture.com/]
00170554 Cookie/Overture TrackingCookie No 0 Yes No C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Cookies\system@overture[1].txt
00170554 Cookie/Overture TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.overture.com/]
00170556 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.realmedia.com/]
00170556 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.realmedia.com/]
00170556 Cookie/RealMedia TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\jayallen@realmedia[2].txt
00170556 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.realmedia.com/]
00170556 Cookie/RealMedia TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\jayallen@realmedia[1].txt
00170556 Cookie/RealMedia TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\anyuser@realmedia[1].txt
00170556 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.realmedia.com/]
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\jayallen@questionmarket[1].txt
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\anyuser@questionmarket[3].txt
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\anyuser@questionmarket[2].txt
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.questionmarket.com/]
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\anyuser@questionmarket[1].txt
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\anyuser@questionmarket[4].txt
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\jayallen@questionmarket[3].txt
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.questionmarket.com/]
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.questionmarket.com/]
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\jayallen@questionmarket[5].txt
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\jayallen@questionmarket[2].txt
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\jayallen@questionmarket[4].txt
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\anyuser@questionmarket[5].txt
00172221 Cookie/Zedo TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.zedo.com/]
00172221 Cookie/Zedo TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.zedo.com/]
00172221 Cookie/Zedo TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.zedo.com/]
00172221 Cookie/Zedo TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.zedo.com/]
00172221 Cookie/Zedo TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.zedo.com/]
00172221 Cookie/Zedo TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.zedo.com/]
00172825 Joke/Stress Jokes No 0 Yes No E:\test\stressre.exe
00173520 Cookie/Bluestreak TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.bluestreak.com/]
00182104 Cookie/Hitbox TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.phg.hitbox.com/]
00184846 Cookie/Adrevolver TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.adrevolver.com/]
00184846 Cookie/Adrevolver TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.adrevolver.com/]
00184846 Cookie/Adrevolver TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.adrevolver.com/]
00186189 Cookie/LinkExchange TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\jayallen@linkexchange[2].txt
00194327 Cookie/Go TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.go.com/]
00194327 Cookie/Go TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\anyuser@go[4].txt
00194327 Cookie/Go TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.go.com/]
00194327 Cookie/Go TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.go.com/]
00194327 Cookie/Go TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.go.com/]
00194327 Cookie/Go TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\jayallen@go[8].txt
00194327 Cookie/Go TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\jayallen@go[7].txt
00194327 Cookie/Go TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\anyuser@go[3].txt
00194327 Cookie/Go TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.go.com/]
00194327 Cookie/Go TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\anyuser@go[1].txt
00194327 Cookie/Go TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.go.com/]
00194327 Cookie/Go TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.go.com/]
00194327 Cookie/Go TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.go.com/]
00194327 Cookie/Go TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\jayallen@go(1).txt
00194327 Cookie/Go TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\jayallen@go[5].txt
00194327 Cookie/Go TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\jayallen@go[1].txt
00194327 Cookie/Go TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.go.com/]
00194327 Cookie/Go TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\jayallen@go[3].txt
00194327 Cookie/Go TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.go.com/]
00194327 Cookie/Go TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\anyuser@go[2].txt
00194327 Cookie/Go TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.go.com/]
00194327 Cookie/Go TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\jayallen@go[6].txt
00194327 Cookie/Go TrackingCookie No 0 Yes No E:\WINDOWS\Cookies\jayallen@go[4].txt
00220869 Trj/ProcKill.K Virus/Trojan No 0 Yes No C:\_OTMoveIt\MovedFiles\02182008_173915\xz.bat
00262020 Cookie/Atwola TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.atwola.com/]
00262020 Cookie/Atwola TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Cookies\dad@atwola[1].txt
00286739 Cookie/Hitbox TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.ehg-dig.hitbox.com/]
00286739 Cookie/Hitbox TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.ehg-dig.hitbox.com/]
00286739 Cookie/Hitbox TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.ehg-dig.hitbox.com/]
00286739 Cookie/Hitbox TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.ehg-dig.hitbox.com/]
00286739 Cookie/Hitbox TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.ehg-dig.hitbox.com/]
00286739 Cookie/Hitbox TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.ehg-dig.hitbox.com/]
00286739 Cookie/Hitbox TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.ehg-dig.hitbox.com/]
00286739 Cookie/Hitbox TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.ehg-dig.hitbox.com/]
00286739 Cookie/Hitbox TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.ehg-dig.hitbox.com/]
00286739 Cookie/Hitbox TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.ehg-dig.hitbox.com/]
00293517 Cookie/AdDynamix TrackingCookie No 0 Yes No C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v674gy2g.default\cookies-1.txt[.ads.addynamix.com/]
00517584 Application/SuperFast HackTools No 0 Yes No C:\Documents and Settings\Dad\Desktop\SmitfraudFix\restart.exe
00517584 Application/SuperFast HackTools No 0 Yes No C:\smitfraudfix\SmitfraudFix\restart.exe
00816208 Adware/eZula Adware No 0 Yes No E:\WINDOWS\SYSTEM\MACROMED\Shockwave 8\Xtras\download\TheGrooveAlliance\3DGrooveXtrav18\Groove.x32
01260840 Trj/Downloader.PME Virus/Trojan No 1 Yes No C:\Documents and Settings\Dad\Local Settings\Application Data\Wildtangent\Cdacache\00\02\36.dat
01262593 Application/NirCmd.A HackTools No 0 No No C:\Documents and Settings\Dad\Desktop\ComboFix.exe[327882R2FWJFW\nircmd.com]
01262593 Application/NirCmd.A HackTools No 0 Yes No C:\WINDOWS\Nircmd.exe
01262593 Application/NirCmd.A HackTools No 0 No No C:\Documents and Settings\Dad\Desktop\ComboFix.exe[327882R2FWJFW\nircmd.cfexe]
02056589 Spyware/Conducent-Timesink Spyware No 1 Yes No E:\TEMP\pk263wsp.exe[TSADBOT.EXE]
02197130 Trj/Rebooter.J Virus/Trojan No 1 Yes No C:\smitfraudfix\SmitfraudFix\Reboot.exe
02197130 Trj/Rebooter.J Virus/Trojan No 1 Yes No C:\Documents and Settings\Dad\Desktop\SmitfraudFix\Reboot.exe
02657327 Adware/WinAntiVirus2007 Adware No 0 Yes No C:\WINDOWS\pss\autorun.exeCommon Startup
02895262 W32/PatchLog.P Virus No 0 Yes No C:\WINDOWS\UPDREG.EXE
02895262 W32/PatchLog.P Virus Yes 0 Yes No C:\PROGRAM FILES\COMMON FILES\DELL\EUSW\SUPPORT.EXE
02895262 W32/PatchLog.P Virus No 0 Yes No C:\PROGRAM FILES\QUICKTIME\QTTASK.EXE
02895262 W32/PatchLog.P Virus Yes 0 Yes No C:\AIM95\AIM.EXE
02895262 W32/PatchLog.P Virus Yes 0 Yes No C:\PROGRAM FILES\ITUNES\ITUNESHELPER.EXE
02895262 W32/PatchLog.P Virus Yes 0 Yes No C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBARNOTIFIER\GOOGLETOOLBARNOTIFIER.EXE
02895262 W32/PatchLog.P Virus No 0 Yes No C:\PROGRAM FILES\LEXMARK X74-X75\LXBBBMGR.EXE
02895534 Bck/Lanman.CA Virus/Trojan Yes 1 Yes No C:\WINDOWS\SYSTEM32\LANMANWRK.EXE
02895536 Rootkit/Lanman.CB HackTools No 0 Yes No C:\WINDOWS\SYSTEM32\lanmandrv.sys
02900272 Trj/Agent.IAB Virus/Trojan No 0 Yes No C:\_OTMoveIt\MovedFiles\02182008_173915\WINDOWS\SYSTEM32\LogCrypt.dll
;===============================================================================
=================================================================================
===================
SUSPECTS
Location
;===============================================================================
=================================================================================
===================
;===============================================================================
=================================================================================
===================
HijackThis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:28:46 PM, on 2/19/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Documents and Settings\Dad\Local Settings\Application Data\Google\Update\1.0.103.3\GoogleUpdate.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Documents and Settings\Dad\Local Settings\Application Data\YouTube\Uploader\youtubeuploader.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.msnbc.msn.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\windows\googletoolbar4.dll
O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [EarthLink Installer] " /C
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [lanmanwrk.exe] C:\WINDOWS\System32\lanmanwrk.exe
O4 - HKCU\..\Run: [AIM] C:\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [pcdlib32] C:\WINDOWS\System32\pcdlib32.exe
O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Dad\Local Settings\Application Data\Google\Update\1.0.103.3\GoogleUpdate.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: YouTube Uploader.lnk = C:\Documents and Settings\Dad\Local Settings\Application Data\YouTube\Uploader\youtubeuploader.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...can_unicode.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
http://a1540.g.akama...meInstaller.exeO16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) -
http://www.nanoscan....s/ascstubie.cabO16 - DPF: {65E7DB1D-0101-4100-BD66-C5C78C917F93} (WTDMMPVersion Class) -
http://install.wildt...lim/install.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.mi...b?1185736413671O16 - DPF: {8436FE12-31DB-48BF-83BF-FE682F9160B4} (NanoInstaller Class) -
http://www.nanoscan....bs/nanoinst.cabO16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} -
http://toolbar.googl...gleActivate.cabO20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: LogCrypt - LogCrypt.dll (file missing)
O20 - Winlogon Notify: WLCtrl32 - C:\WINDOWS\SYSTEM32\WLCtrl32.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing)
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: OracleCSService - Unknown owner - C:\oracle\product\10.1.0\Db_1\bin\ocssd.exe
O23 - Service: OracleOraDb10g_home1SNMPPeerEncapsulator - Unknown owner - C:\oracle\product\10.1.0\Db_1\BIN\ENCSVC.EXE
O23 - Service: OracleOraDb10g_home1SNMPPeerMasterAgent - Unknown owner - C:\oracle\product\10.1.0\Db_1\BIN\AGNTSVC.EXE
O23 - Service: OracleOraDb10g_home1TNSListener - Unknown owner - C:\oracle\product\10.1.0\Db_1\BIN\TNSLSNR.exe
O23 - Service: Viewpoint Manager Service - Viewpoint