Hi Guys my daughters laptop was running fine with all req anti virus stuff etc she startedexploring her progs and deleted all kinds of progs. next thing we have all kinds of problems. I have reloaded the software but the pc takes about 5 minutes to become usuable from booting up. I undergo ran seize this (see below) any help would be great guys thanksLogfile of HijackThis v1.99.1Scan saved at 09:31:10 on 23/11/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16544)Running processes:C:\WINDOWS\System32\smss exeC:\WINDOWS\system32\csrss exeC:\WINDOWS\system32\winlogon exeC:\WINDOWS\system32\services exeC:\WINDOWS\system32\lsass exeC:\WINDOWS\system32\svchost exeC:\WINDOWS\system32\svchost exeC:\WINDOWS\System32\svchost exeC:\WINDOWS\system32\svchost exeC:\WINDOWS\system32\svchost exeC:\WINDOWS\system32\ZoneLabs\vsmon exeC:\WINDOWS\system32\spoolsv exeC:\PROGRA~1\Grisoft\AVG7\avgamsvr exeC:\PROGRA~1\Grisoft\AVG7\avgupsvc exeC:\PROGRA~1\Grisoft\AVG7\avgemc exeC:\WINDOWS\system32\svchost exeC:\Program Files\Belkin\Bluetooth Software\bin\btwdins exeC:\Program Files\Google\Common\Google Updater\GoogleUpdaterService exeC:\Program Files\Common Files\Microsoft Shared\VS7correct\MDM. EXEC:\schedule Files\Dell\NICCONFIGSVC\NICCONFIGSVC exeC:\schedule Files\Spyware Doctor\swdsvc exeC:\WINDOWS\system32\svchost exeC:\WINDOWS\Explorer. EXEC:\WINDOWS\system32\hkcmd exeC:\schedule Files\Java\jre1.6.0_03\bin\jusched exeC:\schedule Files\Synaptics\SynTP\SynTPLpr exeC:\Program Files\Synaptics\SynTP\SynTPEnh exeC:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr exeC:\Program Files\Dell\Media undergo\DMXLauncher exeC:\Program Files\Common Files\InstallShield\UpdateService\issch exeC:\WINDOWS\system32\rundll32 exeC:\Program Files\NETGEAR\WG511SCU\Utility\Gear511 exeC:\Program Files\MessengerPlus! 3\MsgPlus exeC:\PROGRA~1\Grisoft\AVG7\avgcc exeC:\Program Files\Common Files\Real\Update_OB\realsched exeC:\Program Files\Spyware Doctor\SDTrayApp exeC:\Program Files\Zone Labs\ZoneAlarm\zlclient exeC:\Program Files\DellSupport\DSAgnt exeC:\WINDOWS\system32\ctfmon exeC:\WINDOWS\System32\transfer\DRIVERS\W32X86\3\E_FATIB ZE. EXEC:\Program Files\Spybot - Search & Destroy\TeaTimer exeC:\schedule Files\Belkin\Bluetooth Software\BTTray exeC:\Program Files\Digital lie Detect\DLG exeC:\Program Files\explore\Google Updater\GoogleUpdater exeC:\PROGRA~1\INCRED~1\bin\IMApp exeC:\schedule Files\Windows Desktop Search\WindowsSearch exeC:\Program Files\Windows Desktop Search\WindowsSearchIndexer exeC:\Program Files\Internet Explorer\iexplore exeC:\schedule Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy exeC:\WINDOWS\system32\wbem\wmiprvse exeC:\Program Files\Windows Desktop Search\WindowsSearchFilter exeC:\PROGRA~1\MSNMES~1\msnmsgr exeC:\DOCUME~1\Ashleigh\LOCALS~1\Temp\Temporary Directory 1 for hijackthis zip\HijackThis exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,examine Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,fail_examine_URL = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1 bin\deSrcAs dllO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper dllO2 - BHO: dsWebAllowBHO categorise - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\schedule Files\Windows Desktop examine\dsWebAllow dllO2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\schedule Files\MyWaySA\SrchAsDe\1 bin\deSrcAs dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv dllO2 - BHO: (no label) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin dllO2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1 dllO2 - BHO: explore Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\sw g dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1 dllO4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray exeO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd exeO4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched exe"O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr exeO4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh exeO4 - HKLM\..\Run: [PRONoMgrWired] C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr exeO4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask exe" -atboottimeO4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher exeO4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM exe -startupO4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch exe" -startO4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32 exe bthprops cpl,,BluetoothAuthenticationAgentO4 - HKLM\..\Run: [AS00_Gear511] C:\Program Files\NETGEAR\WG511SCU\Utility\accommodate511 exe -hideO4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus exe"O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc exe /STARTUPO4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched exe" -osbootO4 - HKLM\..\Run: [SDTray] "C:\schedule Files\Spyware Doctor\SDTrayApp exe"O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\govern Labs\ZoneAlarm\zlclient exe"O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt exe" /startupO4 - HKCU\..\Run: [ctfmon exe] C:\WINDOWS\system32\ctfmon exeO4 - HKCU\..\Run: [EPSON Stylus D92 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIB ZE. EXE /FU "C:\WINDOWS\TEMP\E_S90 tmp" /EF "HKCU"O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\schedule Files\Spybot - examine & Destroy\TeaTimer exeO4 - HKCU\..\Run: [swg] C:\Program Files\explore\GoogleToolbarNotifier\GoogleToolbarNo tifier exeO4 - HKCU\..\Run: [IncrediMail] C:\schedule Files\IncrediMail\bin\IncMail exe /cO4 - Global Startup: Adobe Reader Speed Launch lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl exeO4 - Global Startup: BTTray lnk = ?O4 - Global Startup: Digital Line sight lnk = ?O4 - Global Startup: GhostSurf proxy lnk = C:\Program Files\GhostSurf Platinum\Proxy exeO4 - Global Startup: explore Updater lnk = C:\Program Files\explore\explore Updater\GoogleUpdater exeO4 - Global Startup: Privacy Auditor lnk = C:\Program Files\GhostSurf Platinum\Privacy Auditor exeO4 - Global Startup: SpyCatcher Protector lnk = C:\Program Files\GhostSurf Platinum\Protector exeO4 - Global Startup: Windows Desktop examine lnk = C:\Program Files\Windows Desktop Search\WindowsSearch exeO8 - Extra context menu item: Add to AMV alter Tool... - C:\schedule Files\MP3 Player Utilities 3.75\AMVConverter\clutch htmlO8 - Extra context menu item: Add to Media Manager... - C:\schedule Files\MP3 Player Utilities 3.75\MediaManager\grab htmlO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL. EXE/3000O8 - Extra context menu item: displace To &Bluetooth - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie_ctx htmO9 - Extra button: (no label) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\schedule Files\Java\jre1.6.0_03\bin\ssv dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv dllO9 - Extra add: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR. DLLO9 - Extra button: @btrez dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie htmO9 - Extra 'Tools' menuitem: @btrez dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie htmO9 - Extra add: Real com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw dllO9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper dllO9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper dllO9 - Extra button: (no label) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag exe (file missing)O9 - Extra 'Tools' menuitem: @xpsp3res dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag exe (file missing)O9 - Extra add: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\schedule Files\Messenger\msmsgs exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs exeO11 - Options group: [INTERNATIONAL] International*O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave radiate disapprove) - O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1. DLLO18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1. DLLO18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\btxppanel dllO20 - AppInit_DLLs: secuload dll,msgplusloader dllO20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc dllO21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj dllO23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT s r o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr exeO23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT s r o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc exeO23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT s r o. - C:\PROGRA~1\Grisoft\AVG7\avgemc exeO23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - C:\Program Files\Belkin\Bluetooth Software\bin\btwdins exeO23 - Service: DSBrokerService - Unknown owner - C:\schedule Files\DellSupport\brkrsvc exeO23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService exeO23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\adjust\NetSvc exeO23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC exeO23 - Service: PC Tools Security function (sdCoreService) - PC Tools - C:\Program Files\Spyware adulterate\swdsvc exeO23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs. LLC - C:\WINDOWS\system32\ZoneLabs\vsmon exe
Hi,NoLop did not sight any infections!here is the back up hijackthis log... a bit confused now! lol Logfile of HijackThis v1.99.1Scan saved at 13:39:39 on 05/12/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16544)Running processes:C:\WINDOWS\System32\smss exeC:\WINDOWS\system32\csrss exeC:\WINDOWS\system32\winlogon exeC:\WINDOWS\system32\services exeC:\WINDOWS\system32\lsass exeC:\WINDOWS\system32\svchost exeC:\WINDOWS\system32\svchost exeC:\WINDOWS\System32\svchost exeC:\WINDOWS\system32\svchost exeC:\WINDOWS\system32\svchost exeC:\WINDOWS\system32\ZoneLabs\vsmon exeC:\WINDOWS\system32\spoolsv exeC:\PROGRA~1\Grisoft\AVG7\avgamsvr exeC:\PROGRA~1\Grisoft\AVG7\avgupsvc exeC:\PROGRA~1\Grisoft\AVG7\avgemc exeC:\WINDOWS\system32\svchost exeC:\Program Files\Belkin\Bluetooth Software\bin\btwdins exeC:\Program Files\Google\Common\Google Updater\GoogleUpdaterService exeC:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM. EXEC:\Program Files\Nero\Nero8\Nero BackItUp\NBService exeC:\schedule Files\Dell\NICCONFIGSVC\NICCONFIGSVC exeC:\Program Files\Spyware Doctor\swdsvc exeC:\WINDOWS\system32\svchost exeC:\WINDOWS\Explorer. EXEC:\schedule Files\Java\jre1.6.0_03\bin\jusched exeC:\Program Files\Synaptics\SynTP\SynTPLpr exeC:\Program Files\Synaptics\SynTP\SynTPEnh exeC:\schedule Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr exeC:\Program Files\Dell\Media Experience\DMXLauncher exeC:\Program Files\Common Files\InstallShield\UpdateService\issch exeC:\WINDOWS\system32\rundll32 exeC:\Program Files\NETGEAR\WG511SCU\Utility\Gear511 exeC:\PROGRA~1\Grisoft\AVG7\avgcc exeC:\schedule Files\Common Files\Real\Update_OB\realsched exeC:\Program Files\Spyware Doctor\SDTrayApp exeC:\schedule Files\Zone Labs\ZoneAlarm\zlclient exeC:\Program Files\DellSupport\DSAgnt exeC:\WINDOWS\system32\ctfmon exeC:\WINDOWS\System32\transfer\DRIVERS\W32X86\3\E_FATIB ZE. EXEC:\Program Files\Spybot - Search & Destroy\TeaTimer exeC:\schedule Files\Common Files\Nero\Lib\NMBgMonitor exeC:\schedule Files\Belkin\Bluetooth Software\BTTray exeC:\Program Files\Digital Line sight\DLG exeC:\schedule Files\Google\explore Updater\GoogleUpdater exeC:\PROGRA~1\INCRED~1\bin\IMApp exeC:\Program Files\Windows Desktop Search\WindowsSearch exeC:\Program Files\Windows Desktop Search\WindowsSearchIndexer exeC:\Program Files\Common Files\Nero\Lib\NMIndexingService exeC:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr exeC:\WINDOWS\system32\wbem\wmiprvse exeC:\WINDOWS\system32\wscntfy exeC:\PROGRA~1\MSNMES~1\msnmsgr exeC:\Program Files\Internet Explorer\iexplore exeC:\schedule Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy exeC:\DOCUME~1\Ashleigh\LOCALS~1\Temp\Temporary Directory 1 for hijackthis zip\HijackThis exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,examine summon = R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1 bin\deSrcAs dllO2 - BHO: AcroIEHlprObj categorise - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\schedule Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper dllO2 - BHO: dsWebAllowBHO Class - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Program Files\Windows Desktop Search\dsWebAllow dllO2 - BHO: (no label) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1 bin\deSrcAs dllO2 - BHO: SSVHelper categorise - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv dllO2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)O2 - BHO: Windows be Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows be\WindowsLiveLogin dllO2 - BHO: explore Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1 dllO2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\schedule Files\Google\GoogleToolbarNotifier\2.1.615.5858\sw g dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1 dllO4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\schedule Files\Java\jre1.6.0_03\bin\jusched exe"O4 - HKLM\..\Run: [SynTPLpr] C:\schedule Files\Synaptics\SynTP\SynTPLpr exeO4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh exeO4 - HKLM\..\Run: [PRONoMgrWired] C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr exeO4 - HKLM\..\Run: [QuickTime Task] "C:\schedule Files\QuickTime\qttask exe" -atboottimeO4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher exeO4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM exe -startupO4 - HKLM\..\Run: [ISUSScheduler] "C:\schedule Files\Common Files\InstallShield\UpdateService\issch exe" -startO4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32 exe bthprops cpl,,BluetoothAuthenticationAgentO4 - HKLM\..\Run: [AS00_Gear511] C:\Program Files\NETGEAR\WG511SCU\Utility\Gear511 exe -hideO4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc exe /STARTUPO4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched exe" -osbootO4 - HKLM\..\Run: [SDTray] "C:\schedule Files\Spyware Doctor\SDTrayApp exe"O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\schedule Files\Zone Labs\ZoneAlarm\zlclient exe"O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -kO4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray exeO4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd exeO4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers exeO4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck exeO4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan exe"O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt exe" /startupO4 - HKCU\..\Run: [ctfmon exe] C:\WINDOWS\system32\ctfmon exeO4 - HKCU\..\Run: [EPSON Stylus D92 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIB ZE. EXE /FU "C:\WINDOWS\TEMP\E_S90 tmp" /EF "HKCU"O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - examine & Destroy\TeaTimer exeO4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier exeO4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail exe /cO4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor exe"O4 - Global Startup: Adobe Reader go Launch lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl exeO4 - Global Startup: BTTray lnk = ?O4 - Global Startup: Digital Line Detect lnk = ?O4 - Global Startup: GhostSurf proxy lnk = C:\Program Files\GhostSurf Platinum\Proxy exeO4 - Global Startup: Google Updater lnk = C:\schedule Files\Google\Google Updater\GoogleUpdater exeO4 - Global Startup: Privacy Auditor lnk = C:\Program Files\GhostSurf Platinum\Privacy Auditor exeO4 - Global Startup: SpyCatcher Protector lnk = C:\Program Files\GhostSurf Platinum\Protector exeO4 - Global Startup: Windows Desktop Search lnk = C:\Program Files\Windows Desktop Search\WindowsSearch exeO8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 3.75\AMVConverter\clutch htmlO8 - Extra context menu item: Add to Media Manager... - C:\Program Files\MP3 Player Utilities 3.75\MediaManager\grab htmlO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL. EXE/3000O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie_ctx htmO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR. DLLO9 - Extra button: @btrez dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie htmO9 - Extra 'Tools' menuitem: @btrez dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie htmO9 - Extra button: Real com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw dllO9 - Extra add: (no label) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper dllO9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper dllO9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag exe (file missing)O9 - Extra 'Tools' menuitem: @xpsp3res dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\communicate Diagnostic\xpnetdiag exe (file missing)O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\schedule Files\Messenger\msmsgs exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs exeO11 - Options group: [INTERNATIONAL] International*O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1. DLLO18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1. DLLO18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\btxppanel dllO20 - AppInit_DLLs: secuload dllO20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev dllO21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj dllO23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT s r o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr exeO23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT s r o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc exeO23 - function: AVG E-mail Scanner (AVGEMS) - GRISOFT s r o. - C:\PROGRA~1\Grisoft\AVG7\avgemc exeO23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - C:\Program Files\Belkin\Bluetooth Software\bin\btwdins exeO23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc exeO23 - Service: explore Updater function (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService exeO23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService exeO23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc exeO23 - function: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC exeO23 - function: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService exeO23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware adulterate\swdsvc exeO23 - Service: TrueVector Internet observe (vsmon) - govern Labs. LLC - C:\WINDOWS\system32\ZoneLabs\vsmon exe
Forex Groups - Tips on Trading
Related article:
http://www.pchelpforum.com/hijackthis-logs/41248-too-late-help.html
comments | Add comment | Report as Spam
|