hello, thank for helping
I could not find "Domain Service" so i couldnt do anything. here are my other logs.
VundoFix V6.2.13
Checking Java version...
Java version is 1.5.0.3
Java version is 1.5.0.6
Scan started at 11:30:46 AM 9/12/2006
Listing files found while scanning....
C:\WINDOWS\system32\geebx.dll
C:\WINDOWS\system32\xbeeg.ini
C:\WINDOWS\system32\xbeeg.bak1
C:\WINDOWS\system32\xbeeg.bak2
Beginning removal...
Attempting to delete C:\WINDOWS\system32\geebx.dll
C:\WINDOWS\system32\geebx.dll Could not be deleted.
Attempting to delete C:\WINDOWS\system32\xbeeg.ini
C:\WINDOWS\system32\xbeeg.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\xbeeg.bak1
C:\WINDOWS\system32\xbeeg.bak1 Has been deleted!
Attempting to delete C:\WINDOWS\system32\xbeeg.bak2
C:\WINDOWS\system32\xbeeg.bak2 Has been deleted!
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\WINDOWS\system32\geebx.dll
C:\WINDOWS\system32\geebx.dll Has been deleted!
Performing Repairs to the registry.
Done!
VundoFix V6.6.1
Checking Java version...
Java version is 1.5.0.10
Java version is 1.5.0.11
Scan started at 6:30:02 PM 15/11/2007
Listing files found while scanning....
C:\windows\system32\keftxyly.dll
C:\WINDOWS\system32\kjjlm.bak1
C:\WINDOWS\system32\kjjlm.ini
C:\WINDOWS\system32\mljjk.dll
C:\WINDOWS\system32\qeonajmx.dll
C:\windows\system32\umhndysy.dll
Beginning removal...
Attempting to delete C:\windows\system32\keftxyly.dll
C:\windows\system32\keftxyly.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\kjjlm.bak1
C:\WINDOWS\system32\kjjlm.bak1 Has been deleted!
Attempting to delete C:\WINDOWS\system32\kjjlm.ini
C:\WINDOWS\system32\kjjlm.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\mljjk.dll
C:\WINDOWS\system32\mljjk.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\qeonajmx.dll
C:\WINDOWS\system32\qeonajmx.dll Has been deleted!
Attempting to delete C:\windows\system32\umhndysy.dll
C:\windows\system32\umhndysy.dll Has been deleted!
Performing Repairs to the registry.
Done!
VundoFix V6.6.1
Checking Java version...
Java version is 1.5.0.10
Java version is 1.5.0.11
Scan started at 7:13:53 PM 16/11/2007
Listing files found while scanning....
ComboFix 07-11-08.3 - k-sparky-k 2007-11-16 19:23:36.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.167 [GMT 11:00]
Running from: C:\Documents and Settings\k-sparky-k\Desktop\ComboFix.exe
* Created a new restore point
.
Unable to gain System Privileges
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\k-sparky-k\Desktop\Live Safety Center.lnk
C:\Documents and Settings\k-sparky-k\Desktop\Online Security Guide.lnk
C:\Documents and Settings\k-sparky-k\Favorites\Online Security Guide.lnk
C:\Documents and Settings\k-sparky-k\Start Menu\Programs\Outerinfo
C:\Documents and Settings\Owner\Application Data\searchtoolbarcorp
C:\Documents and Settings\Owner\Application Data\searchtoolbarcorp\Toolbar Vision\PageHistory.txt
C:\Documents and Settings\Owner\Application Data\searchtoolbarcorp\Toolbar Vision\WebHistory.txt
C:\Documents and Settings\Owner\Favorites\Online Security Guide.lnk
C:\Program Files\Common Files\sstem3~1
C:\Program Files\Common Files\sstem3~1\s?stem32\
C:\Program Files\Common Files\Yazzle1162OinUninstaller.exe
C:\Program Files\outerinfo
C:\Program Files\outerinfo\Terms.rtf
C:\Program Files\SecCenter
C:\Program Files\SecCenter\scprot4.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\racle~1
C:\WINDOWS\racle~1\?ervices.exe
C:\WINDOWS\system32\fibagbia
C:\WINDOWS\system32\fibagbia\bg1.gif
C:\WINDOWS\system32\fibagbia\bgtop.gif
C:\WINDOWS\system32\fibagbia\bottom1.gif
C:\WINDOWS\system32\fibagbia\essentials.gif
C:\WINDOWS\system32\fibagbia\fibagbia1.exe
C:\WINDOWS\system32\fibagbia\fibagbia2.exe
C:\WINDOWS\system32\fibagbia\fibagbia3.exe
C:\WINDOWS\system32\fibagbia\icon1.ico
C:\WINDOWS\system32\fibagbia\install1.gif
C:\WINDOWS\system32\fibagbia\left1.gif
C:\WINDOWS\system32\fibagbia\li.gif
C:\WINDOWS\system32\fibagbia\logo.gif
C:\WINDOWS\system32\fibagbia\main.htm
C:\WINDOWS\system32\fibagbia\mainframe.htm
C:\WINDOWS\system32\fibagbia\reinstall1.gif
C:\WINDOWS\system32\fibagbia\right1.gif
C:\WINDOWS\system32\fibagbia\s1.htm
C:\WINDOWS\system32\fibagbia\s2.htm
C:\WINDOWS\system32\fibagbia\s3.htm
C:\WINDOWS\system32\fibagbia\SMTop1.gif
C:\WINDOWS\system32\fibagbia\SMTop2.gif
C:\WINDOWS\system32\fibagbia\SMTop3.gif
C:\WINDOWS\system32\fibagbia\SMTop4.gif
C:\WINDOWS\system32\fibagbia\soft1_off.gif
C:\WINDOWS\system32\fibagbia\soft1_off_ext.gif
C:\WINDOWS\system32\fibagbia\soft1_on.gif
C:\WINDOWS\system32\fibagbia\soft1_on_ext.gif
C:\WINDOWS\system32\fibagbia\soft2_off.gif
C:\WINDOWS\system32\fibagbia\soft2_off_ext.gif
C:\WINDOWS\system32\fibagbia\soft2_on.gif
C:\WINDOWS\system32\fibagbia\soft2_on_ext.gif
C:\WINDOWS\system32\fibagbia\soft3_off.gif
C:\WINDOWS\system32\fibagbia\soft3_off_ext.gif
C:\WINDOWS\system32\fibagbia\soft3_on.gif
C:\WINDOWS\system32\fibagbia\soft3_on_ext.gif
C:\WINDOWS\system32\fibagbia\softbottom_off.gif
C:\WINDOWS\system32\fibagbia\softbottom_on.gif
C:\WINDOWS\system32\fibagbia\softleft_off.gif
C:\WINDOWS\system32\fibagbia\softleft_on.gif
C:\WINDOWS\system32\fibagbia\top1.gif
C:\WINDOWS\system32\fibagbia\top2.gif
C:\WINDOWS\system32\fibagbia\turnoff1.gif
C:\WINDOWS\system32\fibagbia\turnon1.gif
C:\WINDOWS\system32\gjllm.ini
C:\WINDOWS\system32\gjllm.ini2
C:\WINDOWS\system32\kjwsy.dll
C:\WINDOWS\system32\mlljg.dll
C:\WINDOWS\system32\prltvtjz.dllbox
C:\WINDOWS\system32\qeonajmx.dllbox
C:\WINDOWS\system32\ssembl~1
C:\WINDOWS\system32\ssembl~1\?ssembly\
C:\WINDOWS\system32\winwly32.dll
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
-------\LEGACY_WCVS
-------\nm
-------\wcvs
((((((((((((((((((((((((( Files Created from 2007-10-16 to 2007-11-16 )))))))))))))))))))))))))))))))
.
2007-11-16 19:18 145,984 --a------ C:\WINDOWS\system32\prltvtjz.dll
2007-11-16 19:17 145,984 --a------ C:\WINDOWS\system32\nhlcpbgv.dll
2007-11-16 19:06 81,984 --a------ C:\WINDOWS\system32\wabplqdx.dll
2007-11-16 11:02 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\AVG7
2007-11-15 21:23 <DIR> d-------- C:\Documents and Settings\k-sparky-k\Application Data\AVG7
2007-11-15 21:22 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2007-11-15 21:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2007-11-15 17:03 <DIR> d-------- C:\Program Files\Vpyjcxev
2007-11-15 14:37 24,064 --a------ C:\WINDOWS\system32\msxml3a.dll
2007-11-15 13:17 236,824 --a------ C:\WINDOWS\system32\xactengine2_3.dll
2007-11-15 13:17 62,744 --a------ C:\WINDOWS\system32\xinput1_2.dll
2007-11-15 13:10 <DIR> d---s---- C:\Program Files\Xfire
2007-11-15 13:10 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Xfire
2007-11-15 12:08 <DIR> d-------- C:\Program Files\THQ
2007-11-15 12:06 <DIR> d-------- C:\Program Files\Xlodkizo
2007-11-15 12:06 <DIR> d-------- C:\Program Files\utcbmzcr
2007-11-15 12:06 36,352 --a------ C:\WINDOWS\system32\vtuspno.dll
2007-11-15 12:05 36,352 --a------ C:\WINDOWS\system32\opnoonn.dll
2007-11-15 12:05 36,352 --a------ C:\WINDOWS\system32\nnnnlml.dll
2007-11-15 12:05 36,352 --a------ C:\WINDOWS\system32\iifedde.dll
2007-11-15 12:04 36,352 --a------ C:\WINDOWS\system32\xxyyyxv.dll
2007-11-15 12:04 36,352 --a------ C:\WINDOWS\system32\wvuspop.dll
2007-11-15 12:04 36,352 --a------ C:\WINDOWS\system32\qomligd.dll.vir
2007-11-04 14:32 10,741,112 --a------ C:\GhostzillaCD-1.0.1-free-v1.zip
2007-10-21 14:20 35,840 --a------ C:\WINDOWS\system32\drivers\AFS2K.SYS
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2007-11-15 10:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-15 08:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-15 06:06 --------- d-----w C:\Program Files\GetRight
2007-11-15 03:37 0 ----a-w C:\WINDOWS\system32\drivers\is-M0LAB.tmp
2007-11-15 02:21 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll
2007-11-15 01:57 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-14 08:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-11-14 06:50 --------- d-----w C:\Program Files\MSN Messenger
2007-11-10 11:48 --------- d-----w C:\Program Files\Warcraft III
2007-11-01 08:19 --------- d-----w C:\Documents and Settings\k-sparky-k\Application Data\TransRender
2007-10-22 09:33 --------- d-----w C:\Documents and Settings\k-sparky-k\Application Data\MSN6
2007-10-21 06:15 --------- d-----w C:\Documents and Settings\k-sparky-k\Application Data\Skype
2007-10-21 03:53 --------- d-----w C:\Program Files\Google
2007-10-21 03:18 --------- d-----w C:\Program Files\Silkroad
2007-10-21 03:13 --------- d-----w C:\Program Files\Hewlett-Packard
2007-10-21 03:07 --------- d-----w C:\Program Files\Easy Internet signup
2007-10-21 03:05 --------- d-----w C:\Program Files\Common Files\Scanner
2007-10-21 03:05 --------- d-----w C:\Program Files\Apple Software Update
2007-10-16 10:21 --------- d-----w C:\Program Files\NJStar Communicator
2007-10-13 05:49 --------- d-----w C:\Program Files\Ocean Technology
2007-10-13 05:48 --------- d-----w C:\Documents and Settings\k-sparky-k\Application Data\InstallShield
2007-10-04 02:36 --------- d-----w C:\Documents and Settings\k-sparky-k\Application Data\Move Networks
2007-10-01 07:02 --------- d-----w C:\Program Files\OptusNet Cable
2007-09-29 05:41 --------- d-----w C:\Documents and Settings\Owner\Application Data\EPSON
2007-09-24 07:29 --------- d-----w C:\Documents and Settings\k-sparky-k\Application Data\ConvertTemp
2007-09-17 10:17 --------- d-----w C:\Documents and Settings\k-sparky-k\Application Data\Temporary
2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2006-06-20 05:19 0 ----a-w C:\Program Files\eicmcnb.exe
2006-06-20 05:17 1,687 ----a-w C:\Documents and Settings\k-sparky-k\orderopt6.bin
2006-03-11 13:26 0 ----a-w C:\Documents and Settings\Owner\order_tempopt.bin
2006-03-11 13:24 196 ----a-w C:\Documents and Settings\Owner\order_opt3.bin
2006-03-11 12:20 196 ----a-w C:\Documents and Settings\k-sparky-k\order_opt3.bin
2003-12-18 01:33 20,102 ----a-w C:\Program Files\Readme.txt
2003-09-02 21:46 10,960 ----a-w C:\Program Files\EULA.txt
2002-10-04 04:09 204,800 ----a-w C:\WINDOWS\inf\FXPlugin.dll
2005-02-12 06:26:29 9 --sha-w C:\WINDOWS\system32\bob\modscn\2005-02-12_17-21-28\index.dat
2005-02-12 06:52:34 9 --sha-w C:\WINDOWS\system32\bob\modscn\2005-02-12_17-47-33\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{200D0AAD-71B1-51C9-DDB0-092BA4662A54}]
2007-11-15 17:03 114688 --a------ C:\Program Files\Vpyjcxev\dbyhcfjo.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4cf45c8e-fe92-404d-871b-758d08a4d93c}]
2007-11-16 19:06 81984 --a------ C:\WINDOWS\system32\wabplqdx.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D08BC42-79A8-4F89-909E-3BE12D5877AA}]
C:\WINDOWS\system32\mljjk.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
2007-11-16 19:18 145984 --a------ C:\WINDOWS\system32\prltvtjz.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\prltvtjz.dll [2007-11-16 19:18 145984]
[HKEY_CLASSES_ROOT\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 17:04]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-03-11 18:11]
"CamMonitor"="c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe" [2002-06-22 08:27]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 21:02]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2002-09-13 22:42]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 01:01]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2002-10-16 17:57]
"PPHIDPAD"="C:\WINPENJR\Win32\pphidpad.exe" [2004-09-16 15:49]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.e xe" [2004-08-04 16:31]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScI nst.exe" [2002-09-23 07:34]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT \TINTSETP.exe" [2002-09-23 05:49]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TIN TSETP.exe" [2002-09-23 05:49]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 05:00]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 04:06]
"Network Translation Service"="C:\WINDOWS\nts.exe" []
"Windows Certificate Verification Service"="C:\WINDOWS\wcvs.exe" []
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 14:20]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-11-15 21:22]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2006-11-12 21:48]
"MessengerPlus3"="C:\Program Files\MessengerPlus! 3\MsgPlus.exe" [2007-02-03 20:24]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 18:56]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-14 03:24]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 13:54]
"Gpole"="C:\WINDOWS\?racle\?ervices.exe" []
[HKEY_USERS\.default\software\microsoft\windows\cur rentversion\runonce]
"RunNarrator"=Narrator.exe
[HKEY_USERS\.default\software\microsoft\windows\cur rentversion\run]
"Network Translation Service"="C:\WINDOWS\nts.exe" *
"Nokia.PCSync"=C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-07-31 13

39]
Xfire.lnk - C:\Program Files\Xfire\Xfire.exe [2006-08-30 11

11]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
GetRight - Tray Icon.lnk - C:\Program Files\GetRight\getright.exe [2007-10-29 18:51:27]
PenPower PenKeyboard.lnk - C:\WINPENJR\win32\penkeybd.exe [2005-07-27 19:20:36]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\prltvtjz]
prltvtjz.dll 2007-11-16 19:18 145984 C:\WINDOWS\system32\prltvtjz.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\contro l\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\mlljg.dll
R0 SSI;SSI;C:\WINDOWS\system32\Drivers\SSI.SYS
R1 oreans32;oreans32;\??\C:\WINDOWS\system32\drivers\ oreans32.sys
R1 ppmoucls;ppmoucls;C:\WINDOWS\system32\DRIVERS\ppmo ucls.sys
R1 pptchpad;PenPower Touchpad;C:\WINDOWS\system32\DRIVERS\pptchpd5.sys
R2 DVDAccss;DVDAccss;C:\WINDOWS\system32\drivers\DVDA ccss.sys
R2 PRTGService;PRTG Service - Paessler Router Traffic Grapher;C:\Program Files\PRTG Traffic Grapher\PRTG Traffic Grapher.exe
R3 NPF;WinPcap Packet Driver (NPF);C:\WINDOWS\system32\drivers\NPF.sys
S1 gdim2k;GDI kernel srvc;\??\C:\WINDOWS\system32\gdim2k.sys
S2 NTS;Network Translation Service;C:\WINDOWS\nts.exe
S3 Camdrv30;Philips ToUcam XS;C:\WINDOWS\system32\Drivers\camdrv30.sys
S3 iMSPQMn;iMSPQMn;\??\C:\DOCUME~1\Owner\LOCALS~1\Tem p\iMSPQMn.sys
S3 NTProcDrv;Process creation detector for NT.;\??\C:\Documents and Settings\Owner\Desktop\NtProcDrv.sys
S3 PCDRDRV;Pcdr Helper Driver;\??\C:\PROGRA~1\PC-DOC~1\DIAGNO~1\PCDRDRV.sys
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\Info.exe folder.htt 480 480
.
************************************************** ************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-16 19:50:19
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
Completion time: 2007-11-16 19:53:50 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-09-13 11:46
C:\ComboFix2.txt ... 2007-09-13 19:12
C:\ComboFix3.txt ... 2006-12-11 16:19
.
--- E O F ---
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:02:01 PM, on 16/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5450.0004)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\PRTG Traffic Grapher\PRTG Traffic Grapher.exe
C:\Program Files\PRTG Traffic Grapher\PRTG Traffic Grapher.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\WINPENJR\Win32\pphidpad.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\GetRight\getright.exe
C:\Program Files\GetRight\getright.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\hijackthis\hijackthis.exe\follyou.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about
:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {200D0AAD-71B1-51C9-DDB0-092BA4662A54} - C:\Program Files\Vpyjcxev\dbyhcfjo.dll
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: {c39d4a80-d857-b178-d404-29efe8c54fc4} - {4cf45c8e-fe92-404d-871b-758d08a4d93c} - C:\WINDOWS\system32\wabplqdx.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {6D08BC42-79A8-4F89-909E-3BE12D5877AA} - C:\WINDOWS\system32\mljjk.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\prltvtjz.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-au\msntb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: ninemsn - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-au\msntb.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\prltvtjz.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [PPHIDPAD] C:\WINPENJR\Win32\pphidpad.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Network Translation Service] "C:\WINDOWS\nts.exe" *
O4 - HKLM\..\Run: [Windows Certificate Verification Service] "C:\WINDOWS\wcvs.exe" *
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Gpole] C:\WINDOWS\?racle\?ervices.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Network Translation Service] "C:\WINDOWS\nts.exe" * (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Network Translation Service] "C:\WINDOWS\nts.exe" * (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: GetRight - Tray Icon.lnk = C:\Program Files\GetRight\getright.exe
O4 - Global Startup: PenPower PenKeyboard.lnk = C:\WINPENJR\win32\penkeybd.exe
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?link...67&clcid=0x409
O16 - DPF: {2B36F775-8CF5-4489-B454-2D1B80984CF2} (FXPluginCtl Object) -
http://www.powerflasher.de/plugin/powerres.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
http://appldnld.m7z.net/content.info...TunesSetup.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://gfx2.hotmail.com/mail/w2/pr02...s/MSNPUpld.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) -
http://static.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) -
http://messenger.zone.msn.com/EN-AU/.../GAME_UNO1.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
http://download.bitdefender.com/reso...an8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} -
http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://beta.update.microsoft.com/mic...?1154591029609
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary...t.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) -
http://messenger.zone.msn.com/binary...r.cab56986.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: prltvtjz - C:\WINDOWS\SYSTEM32\prltvtjz.dll
O22 - SharedTaskScheduler: IE Component Categories cache daemon - {553858A7-4922-4e7e-B1C1-97140C1C16EF} - C:\WINDOWS\system32\ieframe.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Network Translation Service (NTS) - Unknown owner - C:\WINDOWS\nts.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PRTG Service - Paessler Router Traffic Grapher (PRTGService) - Paessler GmbH - C:\Program Files\PRTG Traffic Grapher\PRTG Traffic Grapher.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
--
End of file - 11015 bytes