[email protected] and PSW.x-Vir.trogan

Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

Nylink

Thread Starter
Joined
Nov 1, 2007
Messages
1
Well, this is an annoying one. That's what I get for letting my cousin use this computer.

I get popup balloons, saying stuff like PSW.x-Vir.trogan and [email protected] are on my computer. Also get IE opening up with sites (won't list it here in case it could infect something else). The popups are contant, and the computer has slowed down significantly.

Specs: XP SP2 (updated) on a C2D E6600. 2 GB ram. No anti-virus (didn't need it before because I did minimal internet work on here - no downloading - until my family used it). A program called stjjwibf.exe is running, never seen it before. I googled it and got no results. THe popups have something to do with System Defender.

Any help would be appreciated.

Hyjack and anti-virus log:

AV report:

AntiVir PersonalEdition Classic
Report file date: November 2, 2007 10:19

Scanning for 913334 virus strains and unwanted programs.

Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Username: SYSTEM
Computer name: HOME

Version information:
BUILD.DAT : 270 15603 Bytes 9/19/2007 13:32:00
AVSCAN.EXE : 7.0.6.1 290856 Bytes 8/23/2007 18:16:29
AVSCAN.DLL : 7.0.6.0 49192 Bytes 8/16/2007 17:23:51
LUKE.DLL : 7.0.5.3 147496 Bytes 8/14/2007 20:32:47
LUKERES.DLL : 7.0.6.1 10280 Bytes 8/21/2007 17:35:20
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 7/18/2007 19:27:15
ANTIVIR1.VDF : 7.0.0.0 1640448 Bytes 9/13/2007 19:26:55
ANTIVIR2.VDF : 7.0.0.140 940544 Bytes 10/26/2007 14:18:36
ANTIVIR3.VDF : 7.0.0.164 127488 Bytes 11/2/2007 14:18:36
AVEWIN32.DLL : 7.6.0.30 3056128 Bytes 11/2/2007 14:18:36
AVWINLL.DLL : 1.0.0.7 14376 Bytes 2/26/2007 15:36:26
AVPREF.DLL : 7.0.2.2 25640 Bytes 7/18/2007 12:39:17
AVREP.DLL : 7.0.0.1 155688 Bytes 4/16/2007 18:16:24
AVPACK32.DLL : 7.3.0.15 360488 Bytes 8/3/2007 13:46:00
AVREG.DLL : 7.0.1.6 30760 Bytes 7/18/2007 12:17:06
AVARKT.DLL : 1.0.0.20 278568 Bytes 8/28/2007 17:26:33
AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 7/18/2007 12:10:18
NETNT.DLL : 7.0.0.0 7720 Bytes 3/8/2007 16:09:42
RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 8/7/2007 17:38:13
RCTEXT.DLL : 7.0.62.0 86056 Bytes 8/21/2007 17:50:37
SQLITE3.DLL : 3.3.17.1 339968 Bytes 7/23/2007 14:37:21

Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: d:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Boot sectors.....................: F:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium

Start of the scan: November 2, 2007 10:19

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'WLLoginProxy.exe' - '1' Module(s) have been scanned
Scan process 'iexplore.exe' - '1' Module(s) have been scanned
Scan process 'Opera.exe' - '1' Module(s) have been scanned
Scan process 'CCC.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'wscntfy.exe' - '1' Module(s) have been scanned
Scan process 'YzShadow.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'Styler.exe' - '1' Module(s) have been scanned
Scan process 'OSD.exe' - '1' Module(s) have been scanned
Scan process 'Magickey.exe' - '1' Module(s) have been scanned
Scan process 'CapabilityManager.exe' - '1' Module(s) have been scanned
Scan process 'AVEDESK.EXE' - '1' Module(s) have been scanned
Scan process 'atitray.exe' - '1' Module(s) have been scanned
Scan process 'uTorrent.exe' - '1' Module(s) have been scanned
Scan process 'Newzie.exe' - '1' Module(s) have been scanned
Scan process 'MSASCui.exe' - '1' Module(s) have been scanned
Scan process 'MOM.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Module is infected -> 'D:\WINDOWS\system\explorer.exe'
Scan process 'GrooveMonitor.exe' - '1' Module(s) have been scanned
Scan process 'jusched.exe' - '1' Module(s) have been scanned
Scan process 'SkyTel.exe' - '1' Module(s) have been scanned
Scan process 'RTHDCPL.exe' - '1' Module(s) have been scanned
Scan process 'CTHELPER.EXE' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'MediaServer.exe' - '1' Module(s) have been scanned
Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'MsMpEng.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
Process 'explorer.exe' has been terminated
D:\WINDOWS\system\explorer.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] A backup was created as '479b3281.qua' ( QUARANTINE )
[WARNING] The file could not be deleted!

46 processes with 45 modules were scanned

Start scanning boot sectors:
Boot sector 'C:\'
[NOTE] No virus was found!
Boot sector 'D:\'
[NOTE] No virus was found!
Boot sector 'F:\'
[NOTE] No virus was found!

Starting to scan the registry.
D:\WINDOWS\system\explorer.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] The file was moved to '479b329f.qua'!
D:\WINDOWS\system\explorer.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
D:\WINDOWS\system32\efccyab.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[INFO] A backup was created as '478e32a3.qua' ( QUARANTINE )
[WARNING] The file could not be deleted!
D:\WINDOWS\system32\efccyab.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
D:\WINDOWS\system32\opnooli.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[INFO] A backup was created as '479932bc.qua' ( QUARANTINE )
[INFO] The file was deleted!
D:\WINDOWS\system32\opnooli.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen

The registry was scanned ( '47' files ).


Starting the file scan:

Begin scan in 'C:\' <Dual Audio Anime>
Begin scan in 'D:\' <System>
D:\pagefile.sys
[WARNING] The file could not be opened!
D:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Quarantine\{00004517-0000-0000-1D9A-AF19CC32B644}\DATA.CAB
[0] Archive type: CAB (Microsoft)
--> RESOURCE11
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[INFO] A backup was created as '477f32aa.qua' ( QUARANTINE )
[INFO] The file was deleted!
D:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Quarantine\{00004517-0000-0000-4551-4DCD83EB033A}\DATA.CAB
[0] Archive type: CAB (Microsoft)
--> RESOURCE11
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[INFO] A backup was created as '477f32ab.qua' ( QUARANTINE )
[INFO] The file was deleted!
D:\Documents and Settings\Kevin\Local Settings\Temp\dlwixoql.exe
[DETECTION] Is the Trojan horse TR/Dldr.WinFixer.AU
[INFO] A backup was created as '47a23337.qua' ( QUARANTINE )
[INFO] The file was deleted!
D:\Documents and Settings\Kevin\Local Settings\Temp\dswtmhmj.exe
[DETECTION] Is the Trojan horse TR/Dldr.WinFixer.AU
[INFO] A backup was created as '47a2333e.qua' ( QUARANTINE )
[INFO] The file was deleted!
D:\Documents and Settings\Kevin\Local Settings\Temp\mofugclq.exe
[DETECTION] Is the Trojan horse TR/Dldr.WinFixer.AU
[INFO] A backup was created as '4791333b.qua' ( QUARANTINE )
[INFO] The file was deleted!
D:\Documents and Settings\Kevin\Local Settings\Temp\ngproxvf.exe
[DETECTION] Is the Trojan horse TR/Dldr.WinFixer.AU
[INFO] A backup was created as '479b3333.qua' ( QUARANTINE )
[INFO] The file was deleted!
D:\Documents and Settings\Kevin\Local Settings\Temp\qrjatydi.exe
[DETECTION] Is the Trojan horse TR/Dldr.WinFixer.AU
[INFO] A backup was created as '4795333f.qua' ( QUARANTINE )
[INFO] The file was deleted!
D:\Documents and Settings\Kevin\Local Settings\Temp\rhvqsuwb.exe
[DETECTION] Is the Trojan horse TR/Dldr.WinFixer.AU
[INFO] A backup was created as '47a13335.qua' ( QUARANTINE )
[INFO] The file was deleted!
D:\Documents and Settings\Kevin\Local Settings\Temp\urclqecd.exe
[DETECTION] Is the Trojan horse TR/Dldr.WinFixer.AU
[INFO] A backup was created as '478e3340.qua' ( QUARANTINE )
[INFO] The file was deleted!
D:\Documents and Settings\Kevin\Local Settings\Temp\vntmrykt.exe
[DETECTION] Is the Trojan horse TR/Dldr.WinFixer.AU
[INFO] A backup was created as '479f333c.qua' ( QUARANTINE )
[INFO] The file was deleted!
D:\Documents and Settings\Kevin\Local Settings\Temp\xqedqkpr.exe
[DETECTION] Is the Trojan horse TR/Dldr.WinFixer.AU
[INFO] A backup was created as '4790333f.qua' ( QUARANTINE )
[INFO] The file was deleted!
D:\Documents and Settings\Kevin\My Documents\My Received Files\IMG-6950.zip
[0] Archive type: ZIP
--> img0794-www.photoupload.com
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] A backup was created as '47723355.qua' ( QUARANTINE )
[INFO] The file was deleted!
D:\System Volume Information\_restore{AAD95EB0-8722-41AD-8FCE-01D3EFC0E9CF}\RP204\A0084781.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[INFO] A backup was created as '475b35fd.qua' ( QUARANTINE )
[INFO] The file was deleted!
D:\System Volume Information\_restore{AAD95EB0-8722-41AD-8FCE-01D3EFC0E9CF}\RP206\A0084826.exe
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] A backup was created as '475b35ff.qua' ( QUARANTINE )
[INFO] The file was deleted!
D:\System Volume Information\_restore{AAD95EB0-8722-41AD-8FCE-01D3EFC0E9CF}\RP206\A0084827.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[INFO] A backup was created as '46f9a0f0.qua' ( QUARANTINE )
[INFO] The file was deleted!
D:\System Volume Information\_restore{AAD95EB0-8722-41AD-8FCE-01D3EFC0E9CF}\RP206\A0084830.dll
[DETECTION] Contains detection pattern of the Phish-File/Email PHISH/FraudTool.SpyNoMore.A
[INFO] A backup was created as '475b3601.qua' ( QUARANTINE )
[INFO] The file was deleted!
D:\System Volume Information\_restore{AAD95EB0-8722-41AD-8FCE-01D3EFC0E9CF}\RP206\A0084831.exe
[DETECTION] Contains detection pattern of the Phish-File/Email PHISH/FraudTool.SpyNoMore.A.1
[INFO] A backup was created as '475b3600.qua' ( QUARANTINE )
[INFO] The file was deleted!
D:\WINDOWS\IMG-0741.zip
[0] Archive type: ZIP
--> img0794-www.photoupload.com
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] A backup was created as '4772361e.qua' ( QUARANTINE )
[INFO] The file was deleted!
D:\WINDOWS\IMG-3794.zip
[0] Archive type: ZIP
--> img0794-www.photoupload.com
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] A backup was created as '4772361f.qua' ( QUARANTINE )
[INFO] The file was deleted!
D:\WINDOWS\IMG-4377.zip
[0] Archive type: ZIP
--> img0794-www.photoupload.com
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] A backup was created as '46d2bdc0.qua' ( QUARANTINE )
[INFO] The file was deleted!
D:\WINDOWS\IMG-9101.zip
[0] Archive type: ZIP
--> img0794-www.photoupload.com
[DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
[INFO] A backup was created as '47723621.qua' ( QUARANTINE )
[INFO] The file was deleted!
D:\WINDOWS\system32\efccyab.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[INFO] A backup was created as '478e37da.qua' ( QUARANTINE )
[WARNING] The file could not be deleted!
D:\WINDOWS\system32\ssqnonl.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[INFO] A backup was created as '479c37f9.qua' ( QUARANTINE )
[INFO] The file was deleted!
D:\WINDOWS\system32\stjjwibf.exe
[DETECTION] Is the Trojan horse TR/Fotomoto.E
[INFO] A backup was created as '479537fa.qua' ( QUARANTINE )
[INFO] The file was deleted!
D:\WINDOWS\system32\drivers\sptd.sys
[WARNING] The file could not be opened!
Begin scan in 'F:\' <Personal Files>


End of the scan: November 2, 2007 10:53
Used time: 34:37 min

The scan has been done completely.

11174 Scanning directories
308571 Files were scanned
31 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
25 files were deleted
0 files were repaired
29 files were moved to quarantine
0 files were renamed
2 Files cannot be scanned
308540 Files not concerned
2725 Archives were scanned
5 Warnings
0 Notes

Hijack Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:07:32 AM, on 02/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Windows Defender\MsMpEng.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
D:\Program Files\TVersity\Media Server\MediaServer.exe
D:\WINDOWS\system32\ctfmon.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\CTHELPER.EXE
D:\WINDOWS\RTHDCPL.EXE
D:\WINDOWS\SkyTel.EXE
D:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
D:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
D:\Program Files\Windows Defender\MSASCui.exe
D:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
D:\Program Files\Newzie\Newzie.exe
D:\WINDOWS\system32\wuauclt.exe
D:\Program Files\uTorrent\uTorrent.exe
D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
D:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe
F:\Applications\AveDesk\AVEDESK.EXE
D:\Program Files\Wireless Device\Wireless Keyboard\Magickey.exe
D:\Program Files\Wireless Device\Wireless Keyboard\osd.exe
F:\Applications\Styler\Styler.exe
F:\Applications\Yz Shadow\YzShadow.exe
D:\Program Files\Avira\AntiVir PersonalEdition Classic\avcenter.exe
D:\WINDOWS\system32\notepad.exe
D:\Program Files\Opera\Opera.exe
D:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
D:\Program Files\Opera\profile\cache4\temporary_download\HiJackThis (1).exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: {cd926161-5a1d-f30b-09c4-f5b3d06bd004} - {400db60d-3b5f-4c90-b03f-d1a5161629dc} - D:\WINDOWS\system32\qyrycbkl.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {806E1CA8-2B65-45B5-B1D4-C42EF388E119} - D:\WINDOWS\system32\efccyab.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Mouse Gestures - {A6A49249-57AE-4295-8D4D-18A9502C7D8E} - D:\Program Files\Internet Explorer\Plugins\Drowse\MouseGestures.dll
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - D:\WINDOWS\system32\hmydwykd.dll
O2 - BHO: Loader Class - {F880A4A8-C436-4AC4-AFD1-AA0BDC9552DD} - D:\Program Files\FindeXer\FindeXer.dll
O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - F:\Applications\Styler\TB\StylerTB.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - D:\WINDOWS\system32\hmydwykd.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] D:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] D:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] D:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [JMB36X IDE Setup] D:\WINDOWS\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [36X Raid Configurer] D:\WINDOWS\System32\xRaidSetup.exe boot
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "D:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [NeroFilterCheck] D:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [StartCCC] "D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [d4f147ca] rundll32.exe "D:\WINDOWS\system32\jyxornys.dll",b
O4 - HKLM\..\Run: [Windows Defender] "D:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SNM] D:\Program Files\SpyNoMore\SNM.exe /startup
O4 - HKLM\..\Run: [avgnt] "D:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [Newzie Start-Up] D:\Program Files\Newzie\Newzie.exe /background
O4 - HKCU\..\Run: [uTorrent] "D:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AtiTrayTools] "D:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe"
O4 - HKCU\..\Run: [AVEDESK] "F:\Applications\AveDesk\AVEDESK.EXE"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = D:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Styler.lnk = ?
O4 - Startup: YzShadow.lnk = F:\Applications\Yz Shadow\YzShadow.exe
O4 - Global Startup: Enable Wireless Keyboard Driver.lnk = D:\Program Files\Wireless Device\Wireless Keyboard\Magickey.exe
O4 - Global Startup: Super Turbo Tango Patcher Reloader.lnk = D:\WINDOWS\Super Turbo Tango Patcher\Reloader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {4E660F19-E91E-41e1-88EF-D1DFAB118F67} - D:\Program Files\Internet Explorer\Plugins\Drowse\MouseGestures.dll
O9 - Extra 'Tools' menuitem: Mouse Gestures... - {4E660F19-E91E-41e1-88EF-D1DFAB118F67} - D:\Program Files\Internet Explorer\Plugins\Drowse\MouseGestures.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - D:\Documents and Settings\Kevin\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1181104418655
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1181128269592
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{46D388D2-3FDA-4749-9895-C0E9C055D999}: NameServer = 4.2.2.2,4.2.2.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{46D388D2-3FDA-4749-9895-C0E9C055D999}: NameServer = 4.2.2.2,4.2.2.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{46D388D2-3FDA-4749-9895-C0E9C055D999}: NameServer = 4.2.2.2,4.2.2.1
O17 - HKLM\System\CS3\Services\Tcpip\..\{46D388D2-3FDA-4749-9895-C0E9C055D999}: NameServer = 4.2.2.2,4.2.2.1
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: efccyab - D:\WINDOWS\SYSTEM32\efccyab.dll
O20 - Winlogon Notify: hmydwykd - D:\WINDOWS\SYSTEM32\hmydwykd.dll
O20 - Winlogon Notify: opnooli - D:\WINDOWS\
O23 - Service: Adobe LM Service - Adobe Systems - D:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - D:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - D:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe
O23 - Service: NMIndexingService - Nero AG - D:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: TVersityMediaServer - Unknown owner - D:\Program Files\TVersity\Media Server\MediaServer.exe

--
End of file - 10936 bytes
 
Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

Users Who Are Viewing This Thread (Users: 0, Guests: 1)

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 807,865 other people just like you!

Latest posts

Staff online

Top