Panda
Incident Status Location
Adware:adware/dollarrevenue Not disinfected C:\drsmartload.exe
Spyware:spyware/altnet Not disinfected Windows Registry
Adware:Adware/DollarRevenue Not disinfected C:\drsmartload.exe
Adware:Adware/IWon Not disinfected C:\WINDOWS\Downloaded Program Files\iwonslot1,0,2,5_9.inf
Virus:Bck/Agent.AWF Not disinfected C:\WINDOWS\SYSTEM32\wintcpmod.exe
ewido
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 12:07:16 PM, 11/30/2005
+ Report-Checksum: 71A8210
+ Scan result:
:mozilla.21:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.85:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.86:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.87:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.89:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.90:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.91:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.92:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.93:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.97:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.100:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.102:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.103:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.104:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.105:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.106:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.107:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.108:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.109:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.110:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.111:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
:mozilla.112:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.113:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.114:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.115:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.116:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.117:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.118:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.119:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.120:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.121:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.122:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.123:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.124:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.125:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.126:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.127:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.128:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
:mozilla.133:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.134:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.135:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.136:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.137:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.138:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.139:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.140:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.141:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.142:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.143:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.144:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.161:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.162:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.163:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.164:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.165:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Addynamix : Cleaned with backup
:mozilla.178:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.179:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.180:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.181:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.182:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.183:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.184:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.185:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.188:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.189:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.205:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.265:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup
:mozilla.266:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup
:mozilla.267:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup
:mozilla.268:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup
:mozilla.269:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Valuead : Cleaned with backup
:mozilla.270:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.298:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.299:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.300:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.301:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.305:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.306:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.307:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.308:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.309:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.310:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.311:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.343:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup
:mozilla.344:C:\Documents and Settings\Larissa\Application Data\Mozilla\Firefox\Profiles\hegn26ih.default\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup
::Report End
HJT
Logfile of HijackThis v1.99.1
Scan saved at 12:57:58 PM, on 11/30/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Comcast\COMCAS~1\data\Xtras\mssysmgr.exe
C:\PROGRA~1\DELLSU~1\DSAgnt.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Larissa\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.livejourn...hnyflwr/friends
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Comcast\COMCAS~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [DellSupport] "C:\PROGRA~1\DELLSU~1\DSAgnt.exe" /startup
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar3.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar3.dll/cmwordtrans.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar3.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar3.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar3.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O16 - DPF: {09C6CAC0-936E-40A0-BC26-707480103DC3} - http://www.uproar.co...pside_web18.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.s...sa/LSSupCtl.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg...ol_v1-0-3-9.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://bin.mcafee.co...76/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by3fd.bay3.ho...es/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1125627094578
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - http://www.vzwpix.co...loadControl.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installen...gine/isetup.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.c...utocomplete.cab
O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real...ArcadeRdxIE.cab
O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) - http://photos8.msn.c...d.cab?9,0,917,0
O16 - DPF: {CC32D4D8-2A0B-4CEB-B105-C9B968379105} (CGameManagerCtrl Object) - http://www.disney.go...GameManager.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.s...sa/SymAData.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://www.sonypictu...outLauncher.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.app.../ITDetector.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.sonypictu...aploader_v6.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Thank You!!