sorry for the delay..my pc really is giving me grief and running slow ...hope all the following helps
Deckard's System Scanner v20071014.68
Run by Owner on 2008-06-21 10:23:14
Computer is in Normal Mode.
--------------------------------------------------------------------------------
Total Physical Memory: 504 MiB (512 MiB recommended).-- HijackThis (run as Owner.exe) -----------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:23:51, on 21/06/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AOL 9.0\waol.exe
C:\Program Files\AOL 9.0\shellmon.exe
C:\Program Files\Common Files\AOL\1172789170\ee\aolsoftware.exe
c:\program files\common files\aol\1172789170\ee\services\antiSpywareApp\ver2_0_12\AOLSP Scheduler.exe
c:\program files\common files\aol\1172789170\ee\aolsoftware.exe
C:\Program Files\Common Files\AOL\aoltpspd.exe
C:\Documents and Settings\Owner\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Owner.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant =
http://www.crawler.c...spx?tb_id=60076R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch =
http://dnl.crawler.c...aspx?TbId=60076R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.crawler.c...spx?tb_id=60076R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://dnl.crawler.c...aspx?TbId=60076O2 - BHO: {aab116a5-ccd1-43b9-ebd4-2d0814674d14} - {41d47641-80d2-4dbe-9b34-1dcc5a611baa} - C:\WINDOWS\system32\vdibqtvk.dll
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton 360\osCheck.exe"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{4164E660-8890-4F61-AF65-BA876921C4D4}: NameServer = 205.188.146.145
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
--
End of file - 5961 bytes
-- Files created between 2008-05-21 and 2008-06-21 -----------------------------
2008-06-19 20:12:31 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-06-19 20:11:54 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-06-19 20:11:54 0 d-------- C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
2008-06-19 20:11:24 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-06-19 19:40:48 0 d-------- C:\Documents and Settings\Owner\Application Data\Malwarebytes
2008-06-19 19:40:01 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-19 19:40:00 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-19 19:39:38 0 d-------- C:\Program Files\Common Files\Download Manager
2008-06-19 18:09:23 68821 --a------ C:\WINDOWS\system32\klmvxhpq.dll
2008-06-19 17:49:42 0 d-------- C:\Documents and Settings\All Users\Application Data\SITEguard
2008-06-19 17:47:44 0 d-------- C:\Program Files\STOPzilla!
2008-06-19 17:38:55 0 d-------- C:\Program Files\Common Files\iS3
2008-06-18 18:09:57 98816 --a------ C:\WINDOWS\system32\vdibqtvk.dll
2008-06-18 18:05:40 89600 --a------ C:\WINDOWS\system32\gtgcibra.dll
2008-06-18 18:05:37 87286 --a------ C:\WINDOWS\system32\ggitwmxh.dll
2008-06-16 18:00:51 88561 --a------ C:\WINDOWS\system32\curpwnoh.dll
2008-06-16 17:45:11 0 d-------- C:\VundoFix Backups
2008-06-16 17:40:18 651919 --ahs---- C:\WINDOWS\system32\MUvwDfhk.ini2
2008-06-15 23:08:41 84331 --a------ C:\WINDOWS\system32\soogmnvq.dll
2008-06-15 22:23:51 63181 --a------ C:\WINDOWS\system32\alsyiiao.dll
2008-06-15 21:51:05 0 d-------- C:\WINDOWS\ERUNT
2008-06-15 19:46:59 88696 --a------ C:\WINDOWS\system32\dritvgab.dll
2008-06-15 16:31:10 89971 --a------ C:\WINDOWS\system32\hfllfmhe.dll
2008-06-13 12:57:10 88696 --a------ C:\WINDOWS\system32\kxsnyfsa.dll
2008-06-13 12:56:03 322560 -----n--- C:\WINDOWS\system32\khfDwvUM.dll
2008-06-12 22:00:34 78691 --a------ C:\WINDOWS\system32\prjpcwaw.dll
2008-06-08 20:41:11 0 d-------- C:\Program Files\Trend Micro
2008-06-07 20:21:11 108544 --a------ C:\WINDOWS\system32\mjxmwqtr.dll
2008-06-07 20:09:11 101376 --a------ C:\WINDOWS\system32\muphcldg.dll
2008-06-06 23:43:28 0 d-------- C:\Documents and Settings\All Users\Symantec Temporary Files
2008-06-06 20:08:09 108544 --a------ C:\WINDOWS\system32\tjqyfjsy.dll
2008-06-06 20:07:14 100864 --a------ C:\WINDOWS\system32\gyjkncep.dll
2008-06-06 20:00:40 0 d-------- C:\Vso
2008-06-06 20:00:40 0 d-------- C:\Help
2008-06-06 20:00:39 0 d-------- C:\setup
2008-06-05 09:47:06 132608 --a------ C:\WINDOWS\system32\vaksisan.dll
2008-06-05 09:29:07 126976 --a------ C:\WINDOWS\system32\qqyqhbhk.dll
2008-06-04 21:25:42 8126464 --a------ C:\Documents and Settings\Owner\ntuser.dat
2008-06-04 21:25:36 229376 --a------ C:\Documents and Settings\LocalService\ntuser.dat
2008-06-04 21:22:07 0 d-------- C:\Program Files\Elaborate Bytes
2008-06-04 21:20:36 0 d-------- C:\Program Files\uTorrent
2008-06-04 21:17:57 0 d-------- C:\Program Files\SlySoft
2008-06-04 21:10:11 1492992 --a------ C:\vso_hwe.dll <Not Verified; VSO Software; Vso Headless Writing Engine>
2008-06-04 21:10:11 57344 --a------ C:\lang.dll
2008-06-04 21:10:11 290816 --a------ C:\burn.dll <Not Verified; LG Software Innovations; LG Software Innovations burn>
2008-06-04 21:10:10 65536 --a------ C:\Launch.exe
2008-06-04 21:10:10 356352 --a------ C:\dvd2dvd.dll <Not Verified; LG Software innovation; 1click>
2008-06-04 21:10:10 724480 --a------ C:\access.dll
-- Find3M Report ---------------------------------------------------------------
2008-06-20 16:25:45 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-06-19 20:11:24 0 d-------- C:\Program Files\Common Files
2008-06-08 23:22:22 0 d-------- C:\Program Files\Photodex Presenter
2008-06-06 20:51:36 0 d-------- C:\Program Files\Symantec
2008-06-06 20:00:29 0 d-------- C:\Program Files\vso
2008-06-01 16:36:17 0 d-------- C:\Program Files\Norton 360
2008-05-17 12:42:43 0 d-------- C:\Program Files\NeroInstall.bak
2008-05-17 12:26:28 0 d-------- C:\Documents and Settings\Owner\Application Data\Nero
2008-05-17 12:19:01 0 d-------- C:\Program Files\Common Files\Nero
2008-05-17 12:06:52 0 d-------- C:\Program Files\Nero
2008-05-16 20:55:17 0 d-------- C:\Documents and Settings\Owner\Application Data\Ahead
2008-05-16 20:55:14 0 d-------- C:\Program Files\Common Files\Ahead
2008-05-01 19:36:11 0 d-------- C:\Program Files\DVD Shrink
2008-04-23 21:04:01 0 d-------- C:\Documents and Settings\Owner\Application Data\Symantec
2008-04-23 20:33:25 0 d-------- C:\Program Files\Windows Sidebar
2008-04-23 20:09:57 0 d-------- C:\Program Files\Alwil Software
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{41d47641-80d2-4dbe-9b34-1dcc5a611baa}]
18/06/2008 18:09 98816 --a------ C:\WINDOWS\system32\vdibqtvk.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll [24/02/2008 03:08 349552]
[-HKEY_CLASSES_ROOT\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [11/11/2004 01:58]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [18/02/2008 20:37]
"osCheck"="C:\Program Files\Norton 360\osCheck.exe" [26/02/2008 15:50]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [20/12/2006 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 27/02/2007 11:39 282624 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"DNSQueryTimeouts"= 1 2 2 4 8 0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AOL 9.0 Tray Icon.lnk]
backup=C:\WINDOWS\pss\AOL 9.0 Tray Icon.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=C:\WINDOWS\pss\HP Image Zone Fast Start.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
backup=C:\WINDOWS\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\34201d6c]
rundll32.exe "C:\WINDOWS\system32\yrluilal.dll",b
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM37132ef0]
Rundll32.exe "C:\WINDOWS\system32\ymxeqgdi.dll",s
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneDVDElbyDelay]
"C:\Program Files\Elaborate Bytes\CloneDVD\ElbyCheck.exe" /L ElbyDelay
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dvd43]
C:\Program Files\dvd43\dvd43_tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
C:\Program Files\Common Files\AOL\1172789170\ee\AOLSoftware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
"C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelliPoint]
"C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\itype]
"C:\Program Files\Microsoft IntelliType Pro\itype.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
%systemroot%\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lsass]
c:\WINDOWS\Fonts\lsass.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
"C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NWEReboot]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Openwares LiveUpdate]
C:\Program Files\LiveUpdate\LiveUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE4]
"C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
"C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\STOPzilla]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sysprot]
sysprot.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\webHancer Agent]
C:\Program Files\webHancer\Programs\whagent.exe
*Newly Created Service* - COMHOST
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7DE0E8C7-C508-10A9-B862-0AB789CDCB90}]
C:\Program Files\NetMeeting\netmeet32.exe s
-- End of Deckard's System Scanner: finished at 2008-06-21 10:24:31 ------------
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Saturday, June 21, 2008
Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Friday, June 20, 2008 20:12:50
Records in database: 879811
--------------------------------------------------------------------------------
Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes
Scan area - My Computer:
A:\
C:\
D:\
E:\
F:\
Scan statistics:
Files scanned: 57976
Threat name: 6
Infected objects: 19
Suspicious objects: 0
Duration of the scan: 01:21:58
File name / Threat name / Threats count
C:\WINDOWS\system32\vdibqtvk.dll/C:\WINDOWS\system32\vdibqtvk.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.yop 1
C:\Program Files\Trend Micro\HijackThis\backups\backup-20080616-194738-749.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.vaaa 1
C:\WINDOWS\system32\alsyiiao.dll Infected: Trojan.Win32.Obfuscated.auw 1
C:\WINDOWS\system32\curpwnoh.dll Infected: Trojan.Win32.Obfuscated.auw 1
C:\WINDOWS\system32\dritvgab.dll Infected: Trojan.Win32.Obfuscated.auw 1
C:\WINDOWS\system32\ggitwmxh.dll Infected: Trojan.Win32.Obfuscated.auw 1
C:\WINDOWS\system32\gtgcibra.dll Infected: Trojan.Win32.Monder.xo 1
C:\WINDOWS\system32\gyjkncep.dll Infected: Trojan.Win32.Monder.gen 1
C:\WINDOWS\system32\hfllfmhe.dll Infected: Trojan.Win32.Obfuscated.auw 1
C:\WINDOWS\system32\klmvxhpq.dll Infected: Trojan.Win32.Obfuscated.auw 1
C:\WINDOWS\system32\kxsnyfsa.dll Infected: Trojan.Win32.Obfuscated.auw 1
C:\WINDOWS\system32\mjxmwqtr.dll Infected: Trojan.Win32.Monder.gen 1
C:\WINDOWS\system32\muphcldg.dll Infected: Trojan.Win32.Agent.reo 1
C:\WINDOWS\system32\prjpcwaw.dll Infected: Trojan.Win32.Obfuscated.auw 1
C:\WINDOWS\system32\qqyqhbhk.dll Infected: Trojan.Win32.Monder.gen 1
C:\WINDOWS\system32\soogmnvq.dll Infected: Trojan.Win32.Obfuscated.auw 1
C:\WINDOWS\system32\tjqyfjsy.dll Infected: Trojan.Win32.Monder.gen 1
C:\WINDOWS\system32\vaksisan.dll Infected: Trojan.Win32.Monder.gen 1
C:\WINDOWS\system32\vdibqtvk.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.yop 1
The selected area was scanned.