1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

[email protected] and PSW.x-Vir.trogan

Discussion in 'Virus & Other Malware Removal' started by Nylink, Nov 1, 2007.

Thread Status:
Not open for further replies.
  1. Nylink

    Nylink Thread Starter

    Joined:
    Nov 1, 2007
    Messages:
    1
    Well, this is an annoying one. That's what I get for letting my cousin use this computer.

    I get popup balloons, saying stuff like PSW.x-Vir.trogan and [email protected] are on my computer. Also get IE opening up with sites (won't list it here in case it could infect something else). The popups are contant, and the computer has slowed down significantly.

    Specs: XP SP2 (updated) on a C2D E6600. 2 GB ram. No anti-virus (didn't need it before because I did minimal internet work on here - no downloading - until my family used it). A program called stjjwibf.exe is running, never seen it before. I googled it and got no results. THe popups have something to do with System Defender.

    Any help would be appreciated.

    Hyjack and anti-virus log:

    AV report:

    AntiVir PersonalEdition Classic
    Report file date: November 2, 2007 10:19

    Scanning for 913334 virus strains and unwanted programs.

    Licensed to: Avira AntiVir PersonalEdition Classic
    Serial number: 0000149996-ADJIE-0001
    Platform: Windows XP
    Windows version: (Service Pack 2) [5.1.2600]
    Username: SYSTEM
    Computer name: HOME

    Version information:
    BUILD.DAT : 270 15603 Bytes 9/19/2007 13:32:00
    AVSCAN.EXE : 7.0.6.1 290856 Bytes 8/23/2007 18:16:29
    AVSCAN.DLL : 7.0.6.0 49192 Bytes 8/16/2007 17:23:51
    LUKE.DLL : 7.0.5.3 147496 Bytes 8/14/2007 20:32:47
    LUKERES.DLL : 7.0.6.1 10280 Bytes 8/21/2007 17:35:20
    ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 7/18/2007 19:27:15
    ANTIVIR1.VDF : 7.0.0.0 1640448 Bytes 9/13/2007 19:26:55
    ANTIVIR2.VDF : 7.0.0.140 940544 Bytes 10/26/2007 14:18:36
    ANTIVIR3.VDF : 7.0.0.164 127488 Bytes 11/2/2007 14:18:36
    AVEWIN32.DLL : 7.6.0.30 3056128 Bytes 11/2/2007 14:18:36
    AVWINLL.DLL : 1.0.0.7 14376 Bytes 2/26/2007 15:36:26
    AVPREF.DLL : 7.0.2.2 25640 Bytes 7/18/2007 12:39:17
    AVREP.DLL : 7.0.0.1 155688 Bytes 4/16/2007 18:16:24
    AVPACK32.DLL : 7.3.0.15 360488 Bytes 8/3/2007 13:46:00
    AVREG.DLL : 7.0.1.6 30760 Bytes 7/18/2007 12:17:06
    AVARKT.DLL : 1.0.0.20 278568 Bytes 8/28/2007 17:26:33
    AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 7/18/2007 12:10:18
    NETNT.DLL : 7.0.0.0 7720 Bytes 3/8/2007 16:09:42
    RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 8/7/2007 17:38:13
    RCTEXT.DLL : 7.0.62.0 86056 Bytes 8/21/2007 17:50:37
    SQLITE3.DLL : 3.3.17.1 339968 Bytes 7/23/2007 14:37:21

    Configuration settings for the scan:
    Jobname..........................: Complete system scan
    Configuration file...............: d:\program files\avira\antivir personaledition classic\sysscan.avp
    Logging..........................: low
    Primary action...................: interactive
    Secondary action.................: ignore
    Scan master boot sector..........: off
    Scan boot sector.................: on
    Boot sectors.....................: F:,
    Scan memory......................: on
    Process scan.....................: on
    Scan registry....................: on
    Search for rootkits..............: off
    Scan all files...................: Intelligent file selection
    Scan archives....................: on
    Recursion depth..................: 20
    Smart extensions.................: on
    Macro heuristic..................: on
    File heuristic...................: medium

    Start of the scan: November 2, 2007 10:19

    The scan of running processes will be started
    Scan process 'avscan.exe' - '1' Module(s) have been scanned
    Scan process 'avcenter.exe' - '1' Module(s) have been scanned
    Scan process 'sched.exe' - '1' Module(s) have been scanned
    Scan process 'avgnt.exe' - '1' Module(s) have been scanned
    Scan process 'avguard.exe' - '1' Module(s) have been scanned
    Scan process 'WLLoginProxy.exe' - '1' Module(s) have been scanned
    Scan process 'iexplore.exe' - '1' Module(s) have been scanned
    Scan process 'Opera.exe' - '1' Module(s) have been scanned
    Scan process 'CCC.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'wscntfy.exe' - '1' Module(s) have been scanned
    Scan process 'YzShadow.exe' - '1' Module(s) have been scanned
    Scan process 'alg.exe' - '1' Module(s) have been scanned
    Scan process 'Styler.exe' - '1' Module(s) have been scanned
    Scan process 'OSD.exe' - '1' Module(s) have been scanned
    Scan process 'Magickey.exe' - '1' Module(s) have been scanned
    Scan process 'CapabilityManager.exe' - '1' Module(s) have been scanned
    Scan process 'AVEDESK.EXE' - '1' Module(s) have been scanned
    Scan process 'atitray.exe' - '1' Module(s) have been scanned
    Scan process 'uTorrent.exe' - '1' Module(s) have been scanned
    Scan process 'Newzie.exe' - '1' Module(s) have been scanned
    Scan process 'MSASCui.exe' - '1' Module(s) have been scanned
    Scan process 'MOM.exe' - '1' Module(s) have been scanned
    Scan process 'explorer.exe' - '1' Module(s) have been scanned
    Module is infected -> 'D:\WINDOWS\system\explorer.exe'
    Scan process 'GrooveMonitor.exe' - '1' Module(s) have been scanned
    Scan process 'jusched.exe' - '1' Module(s) have been scanned
    Scan process 'SkyTel.exe' - '1' Module(s) have been scanned
    Scan process 'RTHDCPL.exe' - '1' Module(s) have been scanned
    Scan process 'CTHELPER.EXE' - '1' Module(s) have been scanned
    Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
    Scan process 'MediaServer.exe' - '1' Module(s) have been scanned
    Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned
    Scan process 'explorer.exe' - '1' Module(s) have been scanned
    Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'MsMpEng.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'lsass.exe' - '1' Module(s) have been scanned
    Scan process 'services.exe' - '1' Module(s) have been scanned
    Scan process 'winlogon.exe' - '1' Module(s) have been scanned
    Scan process 'csrss.exe' - '1' Module(s) have been scanned
    Scan process 'smss.exe' - '1' Module(s) have been scanned
    Process 'explorer.exe' has been terminated
    D:\WINDOWS\system\explorer.exe
    [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
    [INFO] A backup was created as '479b3281.qua' ( QUARANTINE )
    [WARNING] The file could not be deleted!

    46 processes with 45 modules were scanned

    Start scanning boot sectors:
    Boot sector 'C:\'
    [NOTE] No virus was found!
    Boot sector 'D:\'
    [NOTE] No virus was found!
    Boot sector 'F:\'
    [NOTE] No virus was found!

    Starting to scan the registry.
    D:\WINDOWS\system\explorer.exe
    [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
    [INFO] The file was moved to '479b329f.qua'!
    D:\WINDOWS\system\explorer.exe
    [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
    D:\WINDOWS\system32\efccyab.dll
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] A backup was created as '478e32a3.qua' ( QUARANTINE )
    [WARNING] The file could not be deleted!
    D:\WINDOWS\system32\efccyab.dll
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    D:\WINDOWS\system32\opnooli.dll
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] A backup was created as '479932bc.qua' ( QUARANTINE )
    [INFO] The file was deleted!
    D:\WINDOWS\system32\opnooli.dll
    [DETECTION] Is the Trojan horse TR/Vundo.Gen

    The registry was scanned ( '47' files ).


    Starting the file scan:

    Begin scan in 'C:\' <Dual Audio Anime>
    Begin scan in 'D:\' <System>
    D:\pagefile.sys
    [WARNING] The file could not be opened!
    D:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Quarantine\{00004517-0000-0000-1D9A-AF19CC32B644}\DATA.CAB
    [0] Archive type: CAB (Microsoft)
    --> RESOURCE11
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] A backup was created as '477f32aa.qua' ( QUARANTINE )
    [INFO] The file was deleted!
    D:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Quarantine\{00004517-0000-0000-4551-4DCD83EB033A}\DATA.CAB
    [0] Archive type: CAB (Microsoft)
    --> RESOURCE11
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] A backup was created as '477f32ab.qua' ( QUARANTINE )
    [INFO] The file was deleted!
    D:\Documents and Settings\Kevin\Local Settings\Temp\dlwixoql.exe
    [DETECTION] Is the Trojan horse TR/Dldr.WinFixer.AU
    [INFO] A backup was created as '47a23337.qua' ( QUARANTINE )
    [INFO] The file was deleted!
    D:\Documents and Settings\Kevin\Local Settings\Temp\dswtmhmj.exe
    [DETECTION] Is the Trojan horse TR/Dldr.WinFixer.AU
    [INFO] A backup was created as '47a2333e.qua' ( QUARANTINE )
    [INFO] The file was deleted!
    D:\Documents and Settings\Kevin\Local Settings\Temp\mofugclq.exe
    [DETECTION] Is the Trojan horse TR/Dldr.WinFixer.AU
    [INFO] A backup was created as '4791333b.qua' ( QUARANTINE )
    [INFO] The file was deleted!
    D:\Documents and Settings\Kevin\Local Settings\Temp\ngproxvf.exe
    [DETECTION] Is the Trojan horse TR/Dldr.WinFixer.AU
    [INFO] A backup was created as '479b3333.qua' ( QUARANTINE )
    [INFO] The file was deleted!
    D:\Documents and Settings\Kevin\Local Settings\Temp\qrjatydi.exe
    [DETECTION] Is the Trojan horse TR/Dldr.WinFixer.AU
    [INFO] A backup was created as '4795333f.qua' ( QUARANTINE )
    [INFO] The file was deleted!
    D:\Documents and Settings\Kevin\Local Settings\Temp\rhvqsuwb.exe
    [DETECTION] Is the Trojan horse TR/Dldr.WinFixer.AU
    [INFO] A backup was created as '47a13335.qua' ( QUARANTINE )
    [INFO] The file was deleted!
    D:\Documents and Settings\Kevin\Local Settings\Temp\urclqecd.exe
    [DETECTION] Is the Trojan horse TR/Dldr.WinFixer.AU
    [INFO] A backup was created as '478e3340.qua' ( QUARANTINE )
    [INFO] The file was deleted!
    D:\Documents and Settings\Kevin\Local Settings\Temp\vntmrykt.exe
    [DETECTION] Is the Trojan horse TR/Dldr.WinFixer.AU
    [INFO] A backup was created as '479f333c.qua' ( QUARANTINE )
    [INFO] The file was deleted!
    D:\Documents and Settings\Kevin\Local Settings\Temp\xqedqkpr.exe
    [DETECTION] Is the Trojan horse TR/Dldr.WinFixer.AU
    [INFO] A backup was created as '4790333f.qua' ( QUARANTINE )
    [INFO] The file was deleted!
    D:\Documents and Settings\Kevin\My Documents\My Received Files\IMG-6950.zip
    [0] Archive type: ZIP
    --> img0794-www.photoupload.com
    [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
    [INFO] A backup was created as '47723355.qua' ( QUARANTINE )
    [INFO] The file was deleted!
    D:\System Volume Information\_restore{AAD95EB0-8722-41AD-8FCE-01D3EFC0E9CF}\RP204\A0084781.dll
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] A backup was created as '475b35fd.qua' ( QUARANTINE )
    [INFO] The file was deleted!
    D:\System Volume Information\_restore{AAD95EB0-8722-41AD-8FCE-01D3EFC0E9CF}\RP206\A0084826.exe
    [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
    [INFO] A backup was created as '475b35ff.qua' ( QUARANTINE )
    [INFO] The file was deleted!
    D:\System Volume Information\_restore{AAD95EB0-8722-41AD-8FCE-01D3EFC0E9CF}\RP206\A0084827.dll
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] A backup was created as '46f9a0f0.qua' ( QUARANTINE )
    [INFO] The file was deleted!
    D:\System Volume Information\_restore{AAD95EB0-8722-41AD-8FCE-01D3EFC0E9CF}\RP206\A0084830.dll
    [DETECTION] Contains detection pattern of the Phish-File/Email PHISH/FraudTool.SpyNoMore.A
    [INFO] A backup was created as '475b3601.qua' ( QUARANTINE )
    [INFO] The file was deleted!
    D:\System Volume Information\_restore{AAD95EB0-8722-41AD-8FCE-01D3EFC0E9CF}\RP206\A0084831.exe
    [DETECTION] Contains detection pattern of the Phish-File/Email PHISH/FraudTool.SpyNoMore.A.1
    [INFO] A backup was created as '475b3600.qua' ( QUARANTINE )
    [INFO] The file was deleted!
    D:\WINDOWS\IMG-0741.zip
    [0] Archive type: ZIP
    --> img0794-www.photoupload.com
    [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
    [INFO] A backup was created as '4772361e.qua' ( QUARANTINE )
    [INFO] The file was deleted!
    D:\WINDOWS\IMG-3794.zip
    [0] Archive type: ZIP
    --> img0794-www.photoupload.com
    [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
    [INFO] A backup was created as '4772361f.qua' ( QUARANTINE )
    [INFO] The file was deleted!
    D:\WINDOWS\IMG-4377.zip
    [0] Archive type: ZIP
    --> img0794-www.photoupload.com
    [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
    [INFO] A backup was created as '46d2bdc0.qua' ( QUARANTINE )
    [INFO] The file was deleted!
    D:\WINDOWS\IMG-9101.zip
    [0] Archive type: ZIP
    --> img0794-www.photoupload.com
    [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
    [INFO] A backup was created as '47723621.qua' ( QUARANTINE )
    [INFO] The file was deleted!
    D:\WINDOWS\system32\efccyab.dll
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] A backup was created as '478e37da.qua' ( QUARANTINE )
    [WARNING] The file could not be deleted!
    D:\WINDOWS\system32\ssqnonl.dll
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] A backup was created as '479c37f9.qua' ( QUARANTINE )
    [INFO] The file was deleted!
    D:\WINDOWS\system32\stjjwibf.exe
    [DETECTION] Is the Trojan horse TR/Fotomoto.E
    [INFO] A backup was created as '479537fa.qua' ( QUARANTINE )
    [INFO] The file was deleted!
    D:\WINDOWS\system32\drivers\sptd.sys
    [WARNING] The file could not be opened!
    Begin scan in 'F:\' <Personal Files>


    End of the scan: November 2, 2007 10:53
    Used time: 34:37 min

    The scan has been done completely.

    11174 Scanning directories
    308571 Files were scanned
    31 viruses and/or unwanted programs were found
    0 Files were classified as suspicious:
    25 files were deleted
    0 files were repaired
    29 files were moved to quarantine
    0 files were renamed
    2 Files cannot be scanned
    308540 Files not concerned
    2725 Archives were scanned
    5 Warnings
    0 Notes

    Hijack Log:
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:07:32 AM, on 02/11/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16544)
    Boot mode: Normal

    Running processes:
    D:\WINDOWS\System32\smss.exe
    D:\WINDOWS\system32\winlogon.exe
    D:\WINDOWS\system32\services.exe
    D:\WINDOWS\system32\lsass.exe
    D:\WINDOWS\system32\svchost.exe
    D:\Program Files\Windows Defender\MsMpEng.exe
    D:\WINDOWS\System32\svchost.exe
    D:\WINDOWS\system32\spoolsv.exe
    D:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    D:\WINDOWS\Explorer.EXE
    D:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    D:\Program Files\TVersity\Media Server\MediaServer.exe
    D:\WINDOWS\system32\ctfmon.exe
    D:\WINDOWS\System32\svchost.exe
    D:\WINDOWS\CTHELPER.EXE
    D:\WINDOWS\RTHDCPL.EXE
    D:\WINDOWS\SkyTel.EXE
    D:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
    D:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
    D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
    D:\Program Files\Windows Defender\MSASCui.exe
    D:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    D:\Program Files\Newzie\Newzie.exe
    D:\WINDOWS\system32\wuauclt.exe
    D:\Program Files\uTorrent\uTorrent.exe
    D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
    D:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe
    F:\Applications\AveDesk\AVEDESK.EXE
    D:\Program Files\Wireless Device\Wireless Keyboard\Magickey.exe
    D:\Program Files\Wireless Device\Wireless Keyboard\osd.exe
    F:\Applications\Styler\Styler.exe
    F:\Applications\Yz Shadow\YzShadow.exe
    D:\Program Files\Avira\AntiVir PersonalEdition Classic\avcenter.exe
    D:\WINDOWS\system32\notepad.exe
    D:\Program Files\Opera\Opera.exe
    D:\Program Files\Internet Explorer\IEXPLORE.EXE
    D:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
    D:\Program Files\Opera\profile\cache4\temporary_download\HiJackThis (1).exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: {cd926161-5a1d-f30b-09c4-f5b3d06bd004} - {400db60d-3b5f-4c90-b03f-d1a5161629dc} - D:\WINDOWS\system32\qyrycbkl.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: (no name) - {806E1CA8-2B65-45B5-B1D4-C42EF388E119} - D:\WINDOWS\system32\efccyab.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Mouse Gestures - {A6A49249-57AE-4295-8D4D-18A9502C7D8E} - D:\Program Files\Internet Explorer\Plugins\Drowse\MouseGestures.dll
    O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - D:\WINDOWS\system32\hmydwykd.dll
    O2 - BHO: Loader Class - {F880A4A8-C436-4AC4-AFD1-AA0BDC9552DD} - D:\Program Files\FindeXer\FindeXer.dll
    O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - F:\Applications\Styler\TB\StylerTB.dll
    O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - D:\WINDOWS\system32\hmydwykd.dll
    O4 - HKLM\..\Run: [IMJPMIG8.1] D:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [PHIME2002ASync] D:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] D:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [JMB36X IDE Setup] D:\WINDOWS\RaidTool\xInsIDE.exe
    O4 - HKLM\..\Run: [36X Raid Configurer] D:\WINDOWS\System32\xRaidSetup.exe boot
    O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
    O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [GrooveMonitor] "D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
    O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "D:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
    O4 - HKLM\..\Run: [NeroFilterCheck] D:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [StartCCC] "D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
    O4 - HKLM\..\Run: [d4f147ca] rundll32.exe "D:\WINDOWS\system32\jyxornys.dll",b
    O4 - HKLM\..\Run: [Windows Defender] "D:\Program Files\Windows Defender\MSASCui.exe" -hide
    O4 - HKLM\..\Run: [SNM] D:\Program Files\SpyNoMore\SNM.exe /startup
    O4 - HKLM\..\Run: [avgnt] "D:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKCU\..\Run: [Newzie Start-Up] D:\Program Files\Newzie\Newzie.exe /background
    O4 - HKCU\..\Run: [uTorrent] "D:\Program Files\uTorrent\uTorrent.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [AtiTrayTools] "D:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe"
    O4 - HKCU\..\Run: [AVEDESK] "F:\Applications\AveDesk\AVEDESK.EXE"
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Startup: Adobe Gamma.lnk = D:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Startup: Styler.lnk = ?
    O4 - Startup: YzShadow.lnk = F:\Applications\Yz Shadow\YzShadow.exe
    O4 - Global Startup: Enable Wireless Keyboard Driver.lnk = D:\Program Files\Wireless Device\Wireless Keyboard\Magickey.exe
    O4 - Global Startup: Super Turbo Tango Patcher Reloader.lnk = D:\WINDOWS\Super Turbo Tango Patcher\Reloader.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: (no name) - {4E660F19-E91E-41e1-88EF-D1DFAB118F67} - D:\Program Files\Internet Explorer\Plugins\Drowse\MouseGestures.dll
    O9 - Extra 'Tools' menuitem: Mouse Gestures... - {4E660F19-E91E-41e1-88EF-D1DFAB118F67} - D:\Program Files\Internet Explorer\Plugins\Drowse\MouseGestures.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - D:\Documents and Settings\Kevin\Start Menu\Programs\IMVU\Run IMVU.lnk
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1181104418655
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1181128269592
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{46D388D2-3FDA-4749-9895-C0E9C055D999}: NameServer = 4.2.2.2,4.2.2.1
    O17 - HKLM\System\CS1\Services\Tcpip\..\{46D388D2-3FDA-4749-9895-C0E9C055D999}: NameServer = 4.2.2.2,4.2.2.1
    O17 - HKLM\System\CS2\Services\Tcpip\..\{46D388D2-3FDA-4749-9895-C0E9C055D999}: NameServer = 4.2.2.2,4.2.2.1
    O17 - HKLM\System\CS3\Services\Tcpip\..\{46D388D2-3FDA-4749-9895-C0E9C055D999}: NameServer = 4.2.2.2,4.2.2.1
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
    O20 - Winlogon Notify: efccyab - D:\WINDOWS\SYSTEM32\efccyab.dll
    O20 - Winlogon Notify: hmydwykd - D:\WINDOWS\SYSTEM32\hmydwykd.dll
    O20 - Winlogon Notify: opnooli - D:\WINDOWS\
    O23 - Service: Adobe LM Service - Adobe Systems - D:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - D:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - D:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: NMIndexingService - Nero AG - D:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
    O23 - Service: TVersityMediaServer - Unknown owner - D:\Program Files\TVersity\Media Server\MediaServer.exe

    --
    End of file - 10936 bytes
     
As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/646584

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice