Hello again,
AVG scan:
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
A V G A n t i - S p y w a r e - S c a n R e p o r t
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
+ C r e a t e d a t : 1 2 : 5 8 : 0 9 P M 2 8 / 1 0 / 2 0 0 6
+ S c a n r e s u l t :
C : \ W I N N T \ s y s t e m 3 2 \ b y x y w x y . d l l - > A d w a r e . V i r t u m o n d e : C l e a n e d w i t h b a c k u p ( q u a r a n t i n e d ) .
C : \ W I N N T \ s y s t e m 3 2 \ g e b x v s r . d l l - > A d w a r e . V i r t u m o n d e : C l e a n e d w i t h b a c k u p ( q u a r a n t i n e d ) .
C : \ W I N N T \ s y s t e m 3 2 \ g e b y x x u . d l l - > A d w a r e . V i r t u m o n d e : C l e a n e d w i t h b a c k u p ( q u a r a n t i n e d ) .
C : \ W I N N T \ s y s t e m 3 2 \ i i f d a b x . d l l - > A d w a r e . V i r t u m o n d e : C l e a n e d w i t h b a c k u p ( q u a r a n t i n e d ) .
C : \ W I N N T \ s y s t e m 3 2 \ i i f e c a x . d l l - > A d w a r e . V i r t u m o n d e : C l e a n e d w i t h b a c k u p ( q u a r a n t i n e d ) .
C : \ W I N N T \ s y s t e m 3 2 \ l j j j j g f . d l l - > A d w a r e . V i r t u m o n d e : C l e a n e d w i t h b a c k u p ( q u a r a n t i n e d ) .
C : \ W I N N T \ s y s t e m 3 2 \ l j j k i h f . d l l - > A d w a r e . V i r t u m o n d e : C l e a n e d w i t h b a c k u p ( q u a r a n t i n e d ) .
C : \ W I N N T \ s y s t e m 3 2 \ m l j j j i f . d l l - > A d w a r e . V i r t u m o n d e : C l e a n e d w i t h b a c k u p ( q u a r a n t i n e d ) .
C : \ W I N N T \ s y s t e m 3 2 \ m l j j k h e . d l l - > A d w a r e . V i r t u m o n d e : C l e a n e d w i t h b a c k u p ( q u a r a n t i n e d ) .
C : \ W I N N T \ s y s t e m 3 2 \ m l j j k k h . d l l - > A d w a r e . V i r t u m o n d e : C l e a n e d w i t h b a c k u p ( q u a r a n t i n e d ) .
C : \ W I N N T \ s y s t e m 3 2 \ n n n o l m l . d l l - > A d w a r e . V i r t u m o n d e : C l e a n e d w i t h b a c k u p ( q u a r a n t i n e d ) .
C : \ W I N N T \ s y s t e m 3 2 \ o p n l j h e . d l l - > A d w a r e . V i r t u m o n d e : C l e a n e d w i t h b a c k u p ( q u a r a n t i n e d ) .
C : \ W I N N T \ s y s t e m 3 2 \ q o m j k j h . d l l - > A d w a r e . V i r t u m o n d e : C l e a n e d w i t h b a c k u p ( q u a r a n t i n e d ) .
C : \ W I N N T \ s y s t e m 3 2 \ t u v t r o o . d l l - > A d w a r e . V i r t u m o n d e : C l e a n e d w i t h b a c k u p ( q u a r a n t i n e d ) .
C : \ W I N N T \ s y s t e m 3 2 \ t u v u r q q . d l l - > A d w a r e . V i r t u m o n d e : C l e a n e d w i t h b a c k u p ( q u a r a n t i n e d ) .
C : \ W I N N T \ s y s t e m 3 2 \ u r q q r r p . d l l - > A d w a r e . V i r t u m o n d e : C l e a n e d w i t h b a c k u p ( q u a r a n t i n e d ) .
C : \ W I N N T \ s y s t e m 3 2 \ v t u u s s p . d l l - > A d w a r e . V i r t u m o n d e : C l e a n e d w i t h b a c k u p ( q u a r a n t i n e d ) .
C : \ W I N N T \ s y s t e m 3 2 \ w v u s p q p . d l l - > A d w a r e . V i r t u m o n d e : C l e a n e d w i t h b a c k u p ( q u a r a n t i n e d ) .
C : \ W I N N T \ s y s t e m 3 2 \ w v u t t s q . d l l - > A d w a r e . V i r t u m o n d e : C l e a n e d w i t h b a c k u p ( q u a r a n t i n e d ) .
C : \ W I N N T \ s y s t e m 3 2 \ y a y v u v t . d l l - > A d w a r e . V i r t u m o n d e : C l e a n e d w i t h b a c k u p ( q u a r a n t i n e d ) .
C : \ W I N N T \ s y s t e m 3 2 \ y a y y v w w . d l l - > A d w a r e . V i r t u m o n d e : C l e a n e d w i t h b a c k u p ( q u a r a n t i n e d ) .
C : \ W I N N T \ s y s t e m 3 2 \ C o m \ d r e v e . e x e - > D o w n l o a d e r . A d l o a d . f u : C l e a n e d w i t h b a c k u p ( q u a r a n t i n e d ) .
: : R e p o r t e n d
HijackThis log:
Logfile of HijackThis v1.99.1
Scan saved at 1:08:37 PM, on 28/10/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINNT\system32\cisvc.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\UAService7.exe
C:\WINNT\winmgr.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\WINNT\system32\carpserv.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\OptusNet DSL Internet\DSC.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINNT\system32\internat.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Microsoft Office\Office\MSOFFICE.EXE
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\WINNT\system32\cidaemon.exe
C:\Program Files\HijackTHis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://search.optusnet.com.au/?brand=ODSL&panel=1
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://dsl.optusnet.com.au/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://dsl.optusnet.com.au/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by OptusNet
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINNT\system32\byxywxy.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (file missing)
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing)
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [Desktop Service Centre] C:\Program Files\OptusNet DSL Internet\DSC.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [defender] C:\\defender25.exe
O4 - HKLM\..\Run: [newname] c:\\newname25.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: Microsoft Office Shortcut Bar.lnk = C:\Program Files\Microsoft Office\Office\MSOFFICE.EXE
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://dsl.optusnet.com.au/
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -
http://software-dl.real.com/082c26ed...p/RdxIE601.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsof...?1123577020750
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
https://download.macromedia.com/pub/...sh/swflash.cab
O20 - Winlogon Notify: byxywxy - byxywxy.dll (file missing)
O20 - Winlogon Notify: gebyxxu - gebyxxu.dll (file missing)
O20 - Winlogon Notify: ljjkihf - ljjkihf.dll (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINNT\system32\UAService7.exe
O23 - Service: Microsoft Windows Man Service (Windows Man Service) - Unknown owner - C:\WINNT\winmgr.exe
O23 - Service: Microsoft Windows Spooler Service (Windows Spooler Service) - Unknown owner - C:\WINNT\services.exe (file missing)
I still can't get into safe mode.
Thanks again,
Velvet.