Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Help! Spyware/Malware on my computer  (Read 21027 times)

0 Members and 1 Guest are viewing this topic.

xSmootx

    Topic Starter


    Rookie

    Help! Spyware/Malware on my computer
    « on: September 14, 2008, 10:12:34 AM »
    Hello, I'm having a lot of trouble removing some kind of spyware/malware....something that's causing my computer to not work right.
    There's something that keeps spawning shortcuts on the desktop called "casino" which leads to some casino2400 site. Also, I can't view some sites on the internet like symantec's home page. Also, whenever I search for something online through yahoo, the search links redirects me to something else. I've ran avast, trend micro anti-spyware, spybot, windows defender, and AVG. They all found something, but nothing that remedies the problem. Avast doesn't have any the onaccess scanner, and it's getting hard to startup the computer each time. Please, I'm close to having another panic attack and I need help.
    « Last Edit: September 14, 2008, 11:35:45 AM by xSmootx »

    kpac

    • Web moderator


    • Hacker

    • kpac®
    • Thanked: 184
      • Yes
      • Yes
      • Yes
    • Certifications: List
    • Computer: Specs
    • Experience: Expert
    • OS: Windows 7
    Re: Help! Spyware on my computer
    « Reply #1 on: September 14, 2008, 10:15:26 AM »
    Okay calm down. We'll get it sorted. ;)

    Read this: http://www.computerhope.com/forum/index.php/topic,46313.0.html
    And post the three logs.

    xSmootx

      Topic Starter


      Rookie

      Re: Help! Spyware on my computer
      « Reply #2 on: September 14, 2008, 10:33:22 AM »
      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 12:27:43 PM, on 9/14/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Windows Defender\MsMpEng.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Viewpoint\Common\ViewpointService.exe
      C:\WINDOWS\system32\wwSecure.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
      C:\WINDOWS\sm56hlpr.exe
      C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :
      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
      O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
      O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [Performance Center] C:\Program Files\Ascentive\Performance Center\APCMain.exe -m
      O4 - HKCU\..\RunServices: [Microsoft Update Machine] Setup.exe
      O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
      O4 - Global Startup: SpyCatcher.lnk = C:\Program Files\Tenebril\SpyCatcher\SpyCatcher.exe
      O8 - Extra context menu item: Add To Compaq Organize... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
      O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {32305793-C19A-48E7-AD2F-D87FF7B264A4} (TenebrilSpywareScanner Control) - http://download.tenebril.com/pub/bin/scanner2008/TenebrilSpywareScanner.ocx
      O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game02.zylom.com/activex/zylomgamesplayer.cab
      O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.popcap.com/games/popcaploader_v6.cab
      O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
      O20 - AppInit_DLLs: secuload.dll,avgrsstx.dll
      O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
      O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
      O23 - Service: Washer AutoComplete (wwSecSvc) - Webroot Software, Inc. - C:\WINDOWS\system32\wwSecure.exe
      O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\TURTLE~1\AUDIOS~1\x10nets.exe (file missing)
      O24 - Desktop Component 1: (no name) - C:\Documents and Settings\Jeven\Desktop\News folder\News and such.html

      --
      End of file - 8448 bytes

      ^From Hijack this

      A couple of other things, Svchost.exe was acting up so I terminated it and then the network service of svchost.exe was acting up and terminated that, which caused the emergency shutdown.

      I don't know or not sure if the logs from the other searches were saved or where they're located right now. Off the top of my head, spybot only caught some CoolWWW stuff, avast only caught some stuff in the system volume information, trend micro only nailed some stuff in the hosts area, and AVG got some registry stuff.

      xSmootx

        Topic Starter


        Rookie

        Re: Help! Spyware on my computer
        « Reply #3 on: September 14, 2008, 11:21:31 AM »
        A little more info, I just got a dialog window just now about how svchost.exe at 0x7c952c91 referenced memory at 0x00000010. The memory couldn't be "read" just now

        This whole ordeal started Thursday when I listened to the advice on technibble.com 's instructions on how to fix svchost.exe because it was using a lot of resources. After using there patch instructions, I had to reregister a couple of dll's to get some things like system restore and windows media player working again. Friday night from clipnabber.com I got this from the S&D teatimer program:

         9/13/2008 1:30:42 AM Allowed (based on user decision) value "SVCHOST.EXE" (new data: "C:\WINDOWS\system32\drivers\svchost.exe") added in System Startup user entry!
        9/13/2008 1:33:56 AM Denied (based on user decision) value "xrt_Shell" (new data: "C:\Documents and Settings\Jeven\xrt_opye.exe") added in System Startup user entry!

        I also got a dialog window from windows firewall about svchost.exe and I allowed it through the firewall.  After this I started to get the Casino shortcut on the desktop.

        I also recently downloaded spycatcher a little while ago (like a few hours ago) and it can't seem to work.

        Please help, I don't know what to do and I'm having a hard time keeping it together right now  :-\. I'll try to be online all day today to provide input for you folks.

        PS: Just had another emergency shutdown from the memory error caused by svchost.exe. During the countdown, the display problem with some pages went away.
        « Last Edit: September 14, 2008, 11:34:29 AM by xSmootx »

        evilfantasy

        • Malware Removal Specialist
        • Moderator


        • Genius
        • Calm like a bomb
        • Thanked: 493
        • Experience: Experienced
        • OS: Windows 11
        Re: Help! Spyware/Malware on my computer
        « Reply #4 on: September 14, 2008, 11:43:09 AM »

        Read this: http://www.computerhope.com/forum/index.php/topic,46313.0.html
        And post the three logs.

        HijackThis should be the LAST scanner and log to be created and posted.

        xSmootx

          Topic Starter


          Rookie

          Re: Help! Spyware/Malware on my computer
          « Reply #5 on: September 14, 2008, 12:01:55 PM »
          I cannot access and download the other two scanners.

          evilfantasy

          • Malware Removal Specialist
          • Moderator


          • Genius
          • Calm like a bomb
          • Thanked: 493
          • Experience: Experienced
          • OS: Windows 11
          Re: Help! Spyware/Malware on my computer
          « Reply #6 on: September 14, 2008, 12:05:35 PM »
          Download SDFix by AndyManchesta and save it to your desktop.

          When using this tool, you must use the Administrator's account or an account with Administrative rights

          • Double click SDFix.exe and it will extract the files to %systemdrive%
          • (this is the drive that contains the Windows Directory, typically C:\SDFix).
          • DO NOT use it just yet.
          Reboot your computer in Safe Mode using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

          Open the SDFix folder and double click RunThis.bat to start the script.
          • Type Y to begin the cleanup process.
          • It will remove any Trojan Services or Registry Entries found then prompt you to press any key to Reboot.
          • Press any Key and it will restart the PC.
          • When the PC restarts, the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
          • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt.
          • Copy and paste the contents of the results file Report.txt in your next reply along with a new HijackThis log.

          xSmootx

            Topic Starter


            Rookie

            Re: Help! Spyware/Malware on my computer
            « Reply #7 on: September 14, 2008, 12:34:52 PM »

            SDFix: Version 1.224
            Run by Administrator on Sun 09/14/2008 at 02:18 PM

            Microsoft Windows XP [Version 5.1.2600]
            Running From: C:\SDFix\SDFix

            Checking Services :

            Rootkit Found :
            C:\WINDOWS\system32\drivers\tdssserv.sys - Rootkit.Win32.Agent.cku

            Name :
            tdssserv

            Path :
            \systemroot\system32\drivers\TDSSserv.sys

            tdssserv - Deleted



            Restoring Default Security Values
            Restoring Default Hosts File


            from hijackthis
            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 2:30:23 PM, on 9/14/2008
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
            Boot mode: Safe mode with network support

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Windows Defender\MsMpEng.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\NOTEPAD.EXE
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
            O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
            O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
            O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
            O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
            O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
            O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [SDFix] C:\SDFix\SDFix\RunThis.bat /second
            O4 - HKLM\..\RunOnce: [SDFix] C:\SDFix\SDFix\RunThis.bat /second
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
            O4 - HKCU\..\RunOnce: [SpySweeperUninstallSurvey] http://products.webroot.com/disp0201.php?pc=64021&rc=5025&ps=T&oc=33&mjv=5&mnv=0&bld=1608&cd=&dcc=&drc=&mo=&sid=&lang=en&loc=USA&opi=2&omj=5&omn=1&rsc=
            O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
            O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
            O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
            O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
            O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
            O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll
            O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
            O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
            O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
            O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O16 - DPF: {32305793-C19A-48E7-AD2F-D87FF7B264A4} (TenebrilSpywareScanner Control) - http://download.tenebril.com/pub/bin/scanner2008/TenebrilSpywareScanner.ocx
            O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game02.zylom.com/activex/zylomgamesplayer.cab
            O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.popcap.com/games/popcaploader_v6.cab
            O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
            O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
            O20 - AppInit_DLLs: secuload.dll,avgrsstx.dll
            O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
            O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
            O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
            O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
            O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
            O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
            O23 - Service: Washer AutoComplete (wwSecSvc) - Webroot Software, Inc. - C:\WINDOWS\system32\wwSecure.exe
            O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\TURTLE~1\AUDIOS~1\x10nets.exe (file missing)

            --
            End of file - 7839 bytes


            I can visit symantec.com again, search sites aren't redirecting me, and the display looks like it's back to normal. I'm still in safe mode going to reboot in normal mode now to see if it's ok.

            evilfantasy

            • Malware Removal Specialist
            • Moderator


            • Genius
            • Calm like a bomb
            • Thanked: 493
            • Experience: Experienced
            • OS: Windows 11
            Re: Help! Spyware/Malware on my computer
            « Reply #8 on: September 14, 2008, 12:40:32 PM »
            Post a HijackThis log from normal mode please.

            xSmootx

              Topic Starter


              Rookie

              Re: Help! Spyware/Malware on my computer
              « Reply #9 on: September 14, 2008, 01:16:47 PM »
              Normal mode had the dos program doing the final scan touchups, it did get rid of some files and possibly fixed the situation. Here's the hijackthis log after that final dos scan in normal mode.

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 3:10:51 PM, on 9/14/2008
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Windows Defender\MsMpEng.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              C:\Program Files\Alwil Software\Avast4\ashServ.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\Common Files\LightScribe\LSSrvc.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Viewpoint\Common\ViewpointService.exe
              C:\WINDOWS\system32\wwSecure.exe
              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
              C:\WINDOWS\system32\notepad.exe
              C:\WINDOWS\sm56hlpr.exe
              C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Windows Defender\MSASCui.exe
              C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\AIM\aim.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
              R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :
              R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
              O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
              O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
              O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
              O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
              O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
              O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
              O8 - Extra context menu item: Add To Compaq Organize... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html
              O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
              O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
              O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O16 - DPF: {32305793-C19A-48E7-AD2F-D87FF7B264A4} (TenebrilSpywareScanner Control) - http://download.tenebril.com/pub/bin/scanner2008/TenebrilSpywareScanner.ocx
              O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game02.zylom.com/activex/zylomgamesplayer.cab
              O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.popcap.com/games/popcaploader_v6.cab
              O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
              O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
              O20 - AppInit_DLLs: secuload.dll,avgrsstx.dll
              O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
              O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
              O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
              O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
              O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
              O23 - Service: Washer AutoComplete (wwSecSvc) - Webroot Software, Inc. - C:\WINDOWS\system32\wwSecure.exe
              O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\TURTLE~1\AUDIOS~1\x10nets.exe (file missing)
              O24 - Desktop Component 1: (no name) - C:\Documents and Settings\Jeven\Desktop\News folder\News and such.html

              --
              End of file - 8310 bytes

              evilfantasy

              • Malware Removal Specialist
              • Moderator


              • Genius
              • Calm like a bomb
              • Thanked: 493
              • Experience: Experienced
              • OS: Windows 11
              Re: Help! Spyware/Malware on my computer
              « Reply #10 on: September 14, 2008, 01:21:45 PM »
              Open HijackThis and select Do a system scan only.

              Place a check mark next to the following entries: (if there)

              O20 - AppInit_DLLs: secuload.dll,avgrsstx.dll

              Important: Close all windows except for HijackThis and then click Fix checked.

              Exit HijackThis.

              ----------

              Your Java is out of date.

              Older versions have vulnerabilities that malicious sites can use to infect your system.

              First install the new Sun Java Runtime Environment

              Be sure to close all browser windows before beginning the install.

              Remove the old version(s)

              • Download JavaRa and unzip the file to your Desktop.
              • Open JavaRA.exe and choose Remove Older Versions
              • Once complete exit JavaRA and delete the program.
              • Run CCleaner.
              .
              ----------

              Download Malwarebytes' Anti-Malware (MBAM)

              • Double-click mbam-setup.exe and follow the prompts to install the program.
              • At the end, be sure a checkmark is placed next to the following:
                • Update Malwarebytes' Anti-Malware
                • Launch Malwarebytes' Anti-Malware
                • Then click Finish.
                • If an update is found, it will download and install the latest version.
                • Once the program has loaded, select Perform quick scan, then click Scan.
                • When the scan is complete, click OK, then Show Results to view the results.
                • Be sure that everything is checked, and click Remove Selected.
                • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
                • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
                • Copy and Paste the entire report in your next reply.
                Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.

                xSmootx

                  Topic Starter


                  Rookie

                  Re: Help! Spyware/Malware on my computer
                  « Reply #11 on: September 14, 2008, 01:36:17 PM »
                  alright, I performed the hijackthis operation but the other two I can't download cause IE is having an error

                  I'm gonna restart and see if that will help.

                  EDIT: It appears now that after I download anything, IE has some error and closes out
                  « Last Edit: September 14, 2008, 01:53:29 PM by xSmootx »

                  evilfantasy

                  • Malware Removal Specialist
                  • Moderator


                  • Genius
                  • Calm like a bomb
                  • Thanked: 493
                  • Experience: Experienced
                  • OS: Windows 11
                  Re: Help! Spyware/Malware on my computer
                  « Reply #12 on: September 14, 2008, 02:02:41 PM »
                  Download ComboFix by sUBs. Be sure top save it to the Desktop.

                  **Note:  It is important that it is saved directly to your Desktop

                  Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

                  Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

                  Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.
                   
                  Double click combofix.exe & follow the prompts.
                  When finished ComboFix will produce a log for you.
                  Post the ComboFix log and a new HijackThis log in your next reply.

                  Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

                  xSmootx

                    Topic Starter


                    Rookie

                    Re: Help! Spyware/Malware on my computer
                    « Reply #13 on: September 14, 2008, 02:55:18 PM »
                    ComboFix 08-09-14.01 - Jeven 2008-09-14 16:22:17.1 - NTFSx86
                    Running from: C:\Documents and Settings\Jeven\Desktop\ComboFix.exe
                     * Created a new restore point
                    .

                    (((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
                    .

                    C:\Documents and Settings\Jeven\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
                    C:\WINDOWS\system32\actskn43.ocx

                    .
                    (((((((((((((((((((((((((   Files Created from 2008-08-14 to 2008-09-14  )))))))))))))))))))))))))))))))
                    .

                    2008-09-14 15:59 . 2008-09-14 15:59   <DIR>   d--------   C:\Documents and Settings\Jeven\Application Data\Malwarebytes
                    2008-09-14 15:58 . 2008-09-14 15:59   <DIR>   d--------   C:\Program Files\Malwarebytes' Anti-Malware
                    2008-09-14 15:58 . 2008-09-14 15:58   <DIR>   d--------   C:\Documents and Settings\All Users\Application Data\Malwarebytes
                    2008-09-14 15:58 . 2008-09-10 00:04   38,528   --a------   C:\WINDOWS\system32\drivers\mbamswissarmy.sys
                    2008-09-14 15:58 . 2008-09-10 00:03   17,200   --a------   C:\WINDOWS\system32\drivers\mbam.sys
                    2008-09-14 15:49 . 2008-06-10 02:32   73,728   --a------   C:\WINDOWS\system32\javacpl.cpl
                    2008-09-14 14:14 . 2008-09-14 14:14   <DIR>   d--------   C:\WINDOWS\ERUNT
                    2008-09-14 14:09 . 2008-09-14 14:09   <DIR>   d--------   C:\SDFix
                    2008-09-14 14:04 . 2008-09-14 14:04   <DIR>   d--------   C:\Documents and Settings\Administrator\Application Data\Aim
                    2008-09-14 11:52 . 2008-09-14 11:52   <DIR>   d--hs----   C:\Documents and Settings\LocalService.NT AUTHORITY
                    2008-09-14 11:47 . 2008-09-14 11:47   <DIR>   d--------   C:\WINDOWS\system32\SpycatcherAgentSetupTemp
                    2008-09-14 05:45 . 2008-09-14 11:35   <DIR>   d--h-----   C:\$AVG8.VAULT$
                    2008-09-14 04:46 . 2008-09-14 04:50   <DIR>   d--------   C:\WINDOWS\system32\drivers\Avg
                    2008-09-14 04:46 . 2008-09-14 04:46   <DIR>   d--------   C:\Program Files\AVG
                    2008-09-14 04:46 . 2008-09-14 04:46   97,928   --a------   C:\WINDOWS\system32\drivers\avgldx86.sys
                    2008-09-14 04:46 . 2008-09-14 04:46   76,040   --a------   C:\WINDOWS\system32\drivers\avgtdix.sys
                    2008-09-14 04:46 . 2008-09-14 04:46   10,520   --a------   C:\WINDOWS\system32\avgrsstx.dll
                    2008-09-14 04:45 . 2008-09-14 04:54   <DIR>   d--------   C:\Documents and Settings\All Users\Application Data\avg8
                    2008-09-13 01:31 . 2008-09-13 01:31   39,424   --a------   C:\Documents and Settings\Jeven\xrt_opye.exe
                    2008-09-12 17:49 . 2008-09-12 17:49   <DIR>   d--------   C:\Documents and Settings\Administrator\Application Data\HPQ
                    2008-09-06 17:27 . 2008-09-12 17:42   <DIR>   d--------   C:\WINDOWS\system32\CatRoot_bak
                    2008-09-05 15:14 . 2007-12-24 17:37   138,384   --a------   C:\WINDOWS\system32\drivers\tmcomm.sys
                    2008-08-31 02:43 . 2008-08-31 02:46   <DIR>   d--------   C:\Program Files\Windows Live Safety Center
                    2008-08-30 23:15 . 2008-08-30 23:15   <DIR>   d--------   C:\Program Files\Microsoft CAPICOM 2.1.0.2
                    2008-08-30 22:52 . 2008-06-13 09:10   272,128   ---------   C:\WINDOWS\system32\drivers\bthport.sys
                    2008-08-30 22:52 . 2008-06-13 09:10   272,128   ---------   C:\WINDOWS\system32\dllcache\bthport.sys
                    2008-08-30 02:54 . 2008-07-18 22:07   270,880   --a------   C:\WINDOWS\system32\mucltui.dll
                    2008-08-30 02:54 . 2008-07-18 22:07   210,976   --a------   C:\WINDOWS\system32\muweb.dll
                    2008-08-30 02:54 . 2008-07-18 22:07   29,728   --a------   C:\WINDOWS\system32\mucltui.dll.mui
                    2008-08-21 15:17 . 2008-08-21 15:17   <DIR>   d--------   C:\Documents and Settings\All Users\Application Data\Reflexive
                    2008-08-21 15:16 . 2008-08-21 15:48   <DIR>   d--------   C:\Program Files\Music Catch
                    2008-08-17 01:54 . 2008-09-10 11:40   54,156   --ah-----   C:\WINDOWS\QTFont.qfn
                    2008-08-17 01:54 . 2008-08-17 01:54   1,409   --a------   C:\WINDOWS\QTFont.for

                    .
                    ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
                    .
                    2008-09-14 19:55   ---------   d-----w   C:\Program Files\Java
                    2008-09-14 03:21   ---------   d-----w   C:\Program Files\Spybot - Search & Destroy
                    2008-09-12 21:43   ---------   d-----w   C:\Program Files\Windows Media Connect 2
                    2008-09-09 02:23   ---------   d-----w   C:\Documents and Settings\Jeven\Application Data\uTorrent
                    2008-09-08 22:04   ---------   d-----w   C:\Program Files\Magic Workstation
                    2008-09-08 21:43   ---------   d---a-w   C:\Documents and Settings\All Users\Application Data\TEMP
                    2008-09-06 14:18   ---------   d-----w   C:\Documents and Settings\Jeven\Application Data\Move Networks
                    2008-09-05 19:54   ---------   d-----w   C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
                    2008-09-05 19:14   ---------   d-----w   C:\Program Files\Trend Micro
                    2008-08-31 19:23   10   ----a-w   C:\Documents and Settings\All Users\Application Data\mmrpplic.dat
                    2008-08-20 03:18   ---------   d-----w   C:\Documents and Settings\Jeven\Application Data\Publish Providers
                    2008-08-12 09:43   ---------   d-----w   C:\Program Files\Puzzle Quest
                    2008-08-12 01:32   ---------   d-----w   C:\Program Files\Lavasoft
                    2008-08-12 01:31   ---------   d-----w   C:\Program Files\Common Files\Wise Installation Wizard
                    2008-08-12 01:28   ---------   d-----w   C:\Documents and Settings\All Users\Application Data\Lavasoft
                    2008-08-07 21:11   ---------   d-----w   C:\Program Files\Jewel Quest Solitaire II
                    2008-08-01 23:50   ---------   d-----w   C:\Program Files\OpenAL
                    2008-07-29 19:07   ---------   d-----w   C:\Program Files\AIM
                    2008-07-26 19:20   ---------   d-----w   C:\Program Files\Gold Rush Treasure Hunt
                    2008-07-26 18:08   ---------   d-----w   C:\Documents and Settings\All Users\Application Data\GameHouse
                    2008-07-22 03:59   ---------   d-----w   C:\Program Files\Advanced GIF Optimizer
                    2008-07-20 21:07   ---------   d-----w   C:\Program Files\Astro Avenger 2
                    2008-07-20 06:38   ---------   d-----w   C:\Documents and Settings\Jeven\Application Data\Skype
                    2008-07-20 04:44   ---------   d-----w   C:\Program Files\Drop Em Deluxe
                    2008-07-19 17:08   ---------   d-----w   C:\Program Files\Jewel Quest III
                    2008-07-19 16:04   ---------   d-----w   C:\Program Files\Diablo II
                    2008-07-17 05:27   ---------   d-----w   C:\Documents and Settings\Jeven\Application Data\iWin
                    2008-03-26 21:29   0   -c--a-w   C:\Program Files\temp01
                    2008-03-03 07:40   774,144   -c--a-w   C:\Program Files\RngInterstitial.dll
                    2007-07-15 17:48   1,158   ----a-w   C:\Documents and Settings\Jeven\Application Data\wklnhst.dat
                    2007-05-09 19:43   32   ----a-r   C:\Documents and Settings\All Users\hash.dat
                    2007-02-28 01:35   356,352   ----a-w   C:\Documents and Settings\Jeven\cwshredder.dll
                    2006-06-09 08:41   0   -c--a-w   C:\Documents and Settings\Compaq_Owner\Application Data\wklnhst.dat
                    2006-05-03 09:06   163,328   --sh--r   C:\WINDOWS\system32\flvDX.dll
                    2007-02-21 10:47   31,232   --sh--r   C:\WINDOWS\system32\msfDX.dll
                    2007-12-17 12:43   27,648   --sh--w   C:\WINDOWS\system32\Smab0.dll
                    .

                    ------- Sigcheck -------

                    2004-08-04 08:00  502272  01c3346c241652f43aed8e2149881bfe   C:\WINDOWS\SoftwareDistribution\Download\0d3b5d19cc06db007bbe6584808bfa9e\backup\winlogon.exe
                    2008-09-13 01:32  502272  9b1bd82bd0761b5ba986af66d2809c30   C:\WINDOWS\system32\winlogon.exe
                    2004-08-04 08:00  502272  01c3346c241652f43aed8e2149881bfe   C:\WINDOWS\system32\dllcache\winlogon.exe
                    .
                    (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
                    .
                    .
                    *Note* empty entries & legit default entries are not shown
                    REGEDIT4

                    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    "LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2005-05-10 253952]
                    "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 79224]
                    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
                    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 282624]
                    "SMSERIAL"="sm56hlpr.exe" [2005-01-24 C:\WINDOWS\sm56hlpr.exe]

                    C:\Documents and Settings\Jeven\Start Menu\Programs\Startup\
                    Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]

                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
                    "AllowLegacyWebView"= 1 (0x1)
                    "AllowUnhashedWebView"= 1 (0x1)
                    "RevertWebViewSecurity"= 1 (0x1)
                    "NoResolveSearch"= 1 (0x1)

                    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
                    "NoBandCustomize"= 0 (0x0)
                    "NoMovingBands"= 0 (0x0)
                    "NoCloseDragDropBands"= 0 (0x0)

                    [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
                    Source= C:\Documents and Settings\Jeven\Desktop\News folder\News and such.html
                    FriendlyName=

                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                    "VIDC.I420"= i420vfw.dll
                    "vidc.yv12"= yv12vfw.dll
                    "vidc.MJPG"= m3jpeg32.dll
                    "vidc.dmb1"= m3jpeg32.dll

                    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
                    "DisableMonitoring"=dword:00000001

                    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                    "%windir%\\system32\\sessmgr.exe"=
                    "C:\\Program Files\\iTunes\\iTunes.exe"=
                    "C:\\Program Files\\Compaq Connections\\5577497\\Program\\Compaq Connections.exe"=
                    "C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
                    "C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
                    "C:\\Program Files\\AIM\\aim.exe"=
                    "C:\\Program Files\\utorrent\\utorrent.exe"=
                    "C:\\WINDOWS\\system32\\dplaysvr.exe"=
                    "C:\\Program Files\\HydraIRC\\HydraIRC.exe"=
                    "C:\\Program Files\\GameHouse\\Wheel of Fortune\\Wheel of Fortune.exe"=
                    "C:\\Program Files\\MSN Games\\JEOPARDY! Deluxe\\JEOPARDY! Deluxe.exe"=
                    "C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
                    "C:\\Program Files\\Risk II\\RiskII.RWG"=
                    "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                    "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
                    "C:\\Program Files\\Skype\\Phone\\Skype.exe"=

                    R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
                    S3 ASPI;Advanced SCSI Programming Interface Driver;C:\WINDOWS\System32\DRIVERS\ASPI32.sys [2002-07-17 16512]

                    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\K]
                    \Shell\AutoRun\command - K:\SETUP.EXE

                    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d435b36-e506-11d9-9b78-e6b009352ae7}]
                    \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480

                    *Newly Created Service* - PROCEXP90
                    .
                    Contents of the 'Scheduled Tasks' folder
                    .
                    .
                    ------- Supplementary Scan -------
                    .
                    R0 -: HKCU-Main,Start Page = hxxp://www.yahoo.com/
                    R0 -: HKCU-Main,Default_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
                    R0 -: HKLM-Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
                    R0 -: HKLM-Main,Search Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
                    R1 -: HKCU-SearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
                    O8 -: Add To Compaq Organize... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html
                    O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000

                    O16 -: {32305793-C19A-48E7-AD2F-D87FF7B264A4} - hxxp://download.tenebril.com/pub/bin/scanner2008/TenebrilSpywareScanner.ocx
                    C:\WINDOWS\Downloaded Program Files\TenebrilSpywareScanner.ocx

                    O16 -: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game02.zylom.com/activex/zylomgamesplayer.cab
                    C:\WINDOWS\Downloaded Program Files\ZylomGamesPlayer.inf
                    C:\WINDOWS\Downloaded Program Files\zylomgamesplayer.dll
                    .

                    **************************************************************************

                    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                    Rootkit scan 2008-09-14 16:35:46
                    Windows 5.1.2600 Service Pack 2 NTFS

                    scanning hidden processes ...

                    scanning hidden autostart entries ...

                    scanning hidden files ...

                    scan completed successfully
                    hidden files: 0

                    **************************************************************************
                    .
                    Completion time: 2008-09-14 16:47:14
                    ComboFix-quarantined-files.txt  2008-09-14 20:46:24

                    Pre-Run: 16,301,805,568 bytes free
                    Post-Run: 17,817,219,072 bytes free

                    181   --- E O F ---   2008-09-14 03:50:07

                    xSmootx

                      Topic Starter


                      Rookie

                      Re: Help! Spyware/Malware on my computer
                      « Reply #14 on: September 14, 2008, 02:55:58 PM »
                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 4:54:08 PM, on 9/14/2008
                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                      Boot mode: Normal

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\Ati2evxx.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\Program Files\Windows Defender\MsMpEng.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\WINDOWS\system32\Ati2evxx.exe
                      C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\Program Files\Viewpoint\Common\ViewpointService.exe
                      C:\WINDOWS\system32\wwSecure.exe
                      C:\WINDOWS\sm56hlpr.exe
                      C:\Program Files\Windows Defender\MSASCui.exe
                      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                      C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\explorer.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
                      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
                      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :
                      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                      O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
                      O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
                      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                      O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
                      O8 - Extra context menu item: Add To Compaq Organize... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html
                      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
                      O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
                      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                      O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
                      O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O16 - DPF: {32305793-C19A-48E7-AD2F-D87FF7B264A4} (TenebrilSpywareScanner Control) - http://download.tenebril.com/pub/bin/scanner2008/TenebrilSpywareScanner.ocx
                      O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game02.zylom.com/activex/zylomgamesplayer.cab
                      O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                      O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                      O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
                      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                      O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                      O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                      O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
                      O23 - Service: Washer AutoComplete (wwSecSvc) - Webroot Software, Inc. - C:\WINDOWS\system32\wwSecure.exe
                      O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\TURTLE~1\AUDIOS~1\x10nets.exe (file missing)
                      O24 - Desktop Component 1: (no name) - C:\Documents and Settings\Jeven\Desktop\News folder\News and such.html

                      --
                      End of file - 7589 bytes