Trojan.vundo.dvs Help?

Well , I got this virus : Trojan.Vundo.DVS . I scanned my computer , Bitdefender sayd that it Deleted the files because it was unable to disinfect the files , BUT Virus alert still comes up all the time and says it blocked the virus (the one that should be deleted ) . Can you please help me :) ???

Comments

  • Hello,


    The detection Trojan.Vundo.DVS by itself is not a threat. The files detected with this name are configuration files used by the Vundo trojan. However, if the files reappear this means that you are infected with Vundo. A startup list/hijack-this log would be helpfull!


    Cheers,


    Marius Botis

  • Well , the virus alerts haven't occured anymore -_- so i guess the threat is gone now :) . But does bitdefender work as a registry cleaner too ?

  • Hello,


    I'm not sure whether BitDefender will clean the registry entry in this case. Anyway, you shouldn't worry, only one registry key is used to start the malware, so it's not such a big registry waste :)


    Marius Botis

  • I got exact problem as TotalErik!


    Anyone can help me out of virus: Trojan.vundo.dvs ?


    Thanks

  • Chesda
    edited February 2008

    Please go here and download Silent Runners.vbs (use IE to download it) to a new folder on your drive and run it.


    It takes a minute or two and it will notify you with a popup when your log is ready (it will be in the new folder you created). Please post the information back in this thread.

  • Please go here and download Silent Runners.vbs (use IE to download it) to a new folder on your drive and run it.


    It takes a minute or two and it will notify you with a popup when your log is ready (it will be in the new folder you created). Please post the information back in this thread.


    Hey


    Sorry to hijack this thread but i have same problem and have done as u instructed please help


    Hope this is what u wanted ...


    "Silent Runners.vbs", revision 56, http://www.silentrunners.org/


    Operating System: Windows XP SP2


    Output limited to non-default values, except where indicated by "{++}"


    Startup items buried in registry:


    ---------------------------------


    HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}


    "igndlm.exe" = "C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork" ["IGN Entertainment"]


    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}


    "BDAgent" = ""C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"" ["BitDefender S.R.L."]


    "BitDefender Antiphishing Helper" = ""C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"" ["BitDefender"]


    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\


    {01B4EAAC-2534-435D-975F-32C9F953EC36}\(Default) = (no title provided)


    -> {HKLM...CLSID} = (no title provided)


    \InProcServer32\(Default) = "C:\WINDOWS\system32\awtqr.dll" [null data]


    {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)


    -> {HKLM...CLSID} = "AcroIEHlprObj Class"


    \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]


    {3FECA576-7AD2-4E11-A6AD-6B59D4FB5DB9}\(Default) = (no title provided)


    -> {HKLM...CLSID} = (no title provided)


    \InProcServer32\(Default) = "C:\WINDOWS\system32\iifggdb.dll" [null data]


    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\


    "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Display Panning CPL Extension"


    -> {HKLM...CLSID} = "Display Panning CPL Extension"


    \InProcServer32\(Default) = "deskpan.dll" [file not found]


    "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext"


    -> {HKLM...CLSID} = "HyperTerminal Icon Ext"


    \InProcServer32\(Default) = "C:\WINDOWS\system32\hticons.dll" ["Hilgraeve, Inc."]


    "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"


    -> {HKLM...CLSID} = "WinRAR"


    \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


    "{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D}" = "Messenger Sharing Folders"


    -> {HKLM...CLSID} = "My Sharing Folders"


    \InProcServer32\(Default) = "C:\Program Files\MSN Messenger\fsshext.8.1.0178.00.dll" [MS]


    "{5E2121EE-0300-11D4-8D3B-444553540000}" = "Catalyst Context Menu extension"


    -> {HKLM...CLSID} = "SimpleShlExt Class"


    \InProcServer32\(Default) = "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll" [empty string]


    "{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}" = "iTunes"


    -> {HKLM...CLSID} = "iTunes"


    \InProcServer32\(Default) = "C:\Program Files\iTunes\iTunesMiniPlayer.dll" ["Apple Inc."]


    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\


    <<!>> "{3FECA576-7AD2-4E11-A6AD-6B59D4FB5DB9}" = "*i" (unwritable string)


    -> {HKLM...CLSID} = (no title provided)


    \InProcServer32\(Default) = "C:\WINDOWS\system32\iifggdb.dll" [null data]


    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\


    "WPDShServiceObj" = "{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"


    -> {HKLM...CLSID} = "WPDShServiceObj Class"


    \InProcServer32\(Default) = "C:\WINDOWS\system32\WPDShServiceObj.dll" [MS]


    HKLM\SYSTEM\CurrentControlSet\Control\Lsa\


    <<!>> "Authentication Packages" = "msv1_0"|"C:\WINDOWS\system32\awtqr"


    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\


    <<!>> AtiExtEvent\DLLName = "Ati2evxx.dll" ["ATI Technologies Inc."]


    <<!>> iifggdb\DLLName = "iifggdb.dll" [null data]


    HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\


    {F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info"


    -> {HKLM...CLSID} = "PDF Shell Extension"


    \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."]


    HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\


    MakeFile_VDGD Class\(Default) = "{79599E1F-ED90-4633-8C1B-079B62F97BE1}"


    -> {HKLM...CLSID} = "MakeFile Class"


    \InProcServer32\(Default) = "C:\WINDOWS\system32\vgdshell.dll" ["FarStone Technology Inc."]


    WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"


    -> {HKLM...CLSID} = "WinRAR"


    \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


    HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\


    WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"


    -> {HKLM...CLSID} = "WinRAR"


    \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


    HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\


    FolderShell_VDGD Class\(Default) = "{645128F7-2636-4108-84CD-67D95E5C3817}"


    -> {HKLM...CLSID} = "FolderShell Class"


    \InProcServer32\(Default) = "C:\WINDOWS\system32\vgdshell.dll" ["FarStone Technology Inc."]


    WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"


    -> {HKLM...CLSID} = "WinRAR"


    \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


    Group Policies {GPedit.msc branch and setting}:


    -----------------------------------------------


    Note: detected settings may not have any effect.


    HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Associations\


    "LowRiskFileTypes" = (REG_SZ) .zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi


    .mpg;.mpeg;.mov;.mp3;.m3u;.wav;


    {unrecognized setting}


    HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments\


    "SaveZoneInformation" = (REG_DWORD) dword:0x00000001


    {unrecognized setting}


    HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\


    "NoLowDiskSpaceChecks" = (REG_DWORD) dword:0x00000001


    {unrecognized setting}


    "NoRecentDocsMenu" = (REG_DWORD) dword:0x00000001


    {unrecognized setting}


    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\


    "NoCDBurning" = (REG_DWORD) dword:0x00000000


    {unrecognized setting}


    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\


    "shutdownwithoutlogon" = (REG_DWORD) dword:0x00000001


    {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|


    Shutdown: Allow system to be shut down without having to log on}


    "undockwithoutlogon" = (REG_DWORD) dword:0x00000001


    {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|


    Devices: Allow undock without having to log on}


    Active Desktop and Wallpaper:


    -----------------------------


    Active Desktop may be disabled at this entry:


    HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState


    Displayed if Active Desktop enabled and wallpaper not set by Group Policy:


    HKCU\Software\Microsoft\Internet Explorer\Desktop\General\


    "Wallpaper" = "C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"


    Displayed if Active Desktop disabled and wallpaper not set by Group Policy:


    HKCU\Control Panel\Desktop\


    "Wallpaper" = "C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp"


    Enabled Scheduled Tasks:


    ------------------------


    "AppleSoftwareUpdate" -> launches: "C:\Program Files\Apple Software Update\SoftwareUpdate.exe -task" ["Apple Inc."]


    Winsock2 Service Provider DLLs:


    -------------------------------


    Namespace Service Providers


    HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}


    000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]


    000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]


    000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]


    000000000004\LibraryPath = "C:\Program Files\Bonjour\mdnsNSP.dll" ["Apple Inc."]


    000000000005\LibraryPath = "%SystemRoot%\system32\wshbth.dll" [MS]


    Transport Service Providers


    HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}


    0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:


    %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 24


    %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05


    Toolbars, Explorer Bars, Extensions:


    ------------------------------------


    Toolbars


    HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\


    "{381FFDE8-2394-4F90-B10D-FC6124A40F8C}" = "IEToolbar"


    -> {HKLM...CLSID} = "BitDefender Toolbar"


    \InProcServer32\(Default) = "C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll" ["Bitdefender"]


    Extensions (Tools menu items, main toolbar menu buttons)


    HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\


    {08B0E5C0-4FCB-11CF-AAA5-00401C608501}\


    "MenuText" = "Sun Java Console"


    "CLSIDExtension" = "{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBC}"


    -> {HKLM...CLSID} = "Java Plug-in 1.5.0_04"


    \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll" ["Sun Microsystems, Inc."]


    HOSTS file


    ----------


    C:\WINDOWS\System32\drivers\etc\HOSTS


    maps: 3 domain names to IP addresses,


    2 of the IP addresses are *not* localhost!


    Running Services (Display Name, Service Name, Path {Service DLL}):


    ------------------------------------------------------------------


    BitDefender Communicator, XCOMM, ""C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe" /service" ["BitDefender"]


    BitDefender Desktop Update Service, LIVESRV, ""C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe" /service" ["BitDefender SRL"]


    BitDefender Threat Scanner, scan, "C:\WINDOWS\System32\svchost.exe -kbdx" {"C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\scan.dll" ["S.C. BitDefender S.R.L"]}


    BitDefender Virus Shield, VSSERV, ""C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe" /service" ["BitDefender S.R.L."]


    Bluetooth Support Service, BthServ, "C:\WINDOWS\system32\svchost.exe -k bthsvcs" {"C:\WINDOWS\System32\bthserv.dll" [MS]}


    Windows Driver Foundation - User-mode Driver Framework, WudfSvc, "C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup" {"C:\WINDOWS\System32\WUDFSvc.dll" [MS]}


    WMDM PMSP Service, WMDM PMSP Service, "C:\WINDOWS\system32\MsPMSPSv.exe" [MS]


    ---------- (launch time: 2008-04-01 20:56:28)


    <<!>>: Suspicious data at a malware launch point.


    + This report excludes default entries except where indicated.


    + To see *everywhere* the ****** checks and *everything* it finds,


    launch it from a command prompt or a shortcut with the -all parameter.


    + To search all directories of local fixed drives for DESKTOP.INI


    DLL launch points, use the -supp parameter or answer "No" at the


    first message box and "Yes" at the second message box.


    ---------- (total run time: 98 seconds, including 17 seconds for message boxes)

  • Please go here and download Silent Runners.vbs (use IE to download it) to a new folder on your drive and run it.


    It takes a minute or two and it will notify you with a popup when your log is ready (it will be in the new folder you created). Please post the information back in this thread.


    I picked up Trojan Vundo.dvs The computer was blinking badly when I got it. I restored the computer to the day before and it is working fine. It can not be this easy, the virus most still be in my computer.

  • Please go here and download Silent Runners.vbs (use IE to download it) to a new folder on your drive and run it.


    It takes a minute or two and it will notify you with a popup when your log is ready (it will be in the new folder you created). Please post the information back in this thread.

  • "Silent Runners.vbs", revision 56, http://www.silentrunners.org/


    Operating System: Windows Vista


    Output limited to non-default values, except where indicated by "{++}"


    Startup items buried in registry:


    ---------------------------------


    HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}


    "(Default)" = (empty string) [file not found]


    "SpybotSD TeaTimer" = "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" ["Safer Networking Limited"]


    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}


    "BitDefender Antiphishing Helper" = ""C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"" ["BitDefender"]


    "BDAgent" = ""C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"" ["BitDefender S.R.L."]


    "ISTray" = ""C:\Program Files\Spyware Doctor\pctsTray.exe"" ["PC Tools"]


    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\


    {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)


    -> {HKLM...CLSID} = "Adobe PDF Reader Link Helper"


    \InProcServer32\(Default) = "C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]


    {1827766B-9F49-4854-8034-F6EE26FCB1EC}\(Default) = "SITEguard BHO"


    -> {HKLM...CLSID} = "ZILLAbar Browser Helper Object"


    \InProcServer32\(Default) = "C:\Program Files\STOPzilla!\SZSG.dll" ["iS3, Inc"]


    {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}\(Default) = "BitComet ClickCapture"


    -> {HKLM...CLSID} = "BitComet Helper"


    \InProcServer32\(Default) = "C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll" ["BitComet"]


    {53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)


    -> {HKLM...CLSID} = "Spybot-S&D IE Protection"


    \InProcServer32\(Default) = "C:\PROGRA~1\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"]


    {72853161-30C5-4D22-B7F9-0BBC1D38A37E}\(Default) = (no title provided)


    -> {HKLM...CLSID} = "Groove GFS Browser Helper"


    \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll" [MS]


    {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided)


    -> {HKLM...CLSID} = "SSVHelper Class"


    \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_15\bin\ssv.dll" ["Sun Microsystems, Inc."]


    {E3215F20-3212-11D6-9F8B-00D0B743919D}\(Default) = (no title provided)


    -> {HKLM...CLSID} = "STOPzilla Browser Helper Object"


    \InProcServer32\(Default) = "C:\Program Files\STOPzilla!\SZIEBHO.dll" ["iS3, Inc."]


    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\


    "{5E2121EE-0300-11D4-8D3B-444553540000}" = "Catalyst Context Menu extension"


    -> {HKLM...CLSID} = "SimpleShlExt Class"


    \InProcServer32\(Default) = "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll" [empty string]


    "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"


    -> {HKLM...CLSID} = "WinRAR"


    \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


    "{B327765E-D724-4347-8B16-78AE18552FC3}" = "NeroDigitalIconHandler"


    -> {HKLM...CLSID} = "NeroDigitalIconHandler Class"


    \InProcServer32\(Default) = "C:\Program Files\Common Files\Nero\Lib\NeroDigitalExt.dll" ["Nero AG"]


    "{7F1CF152-04F8-453A-B34C-E609530A9DC8}" = "NeroDigitalPropSheetHandler"


    -> {HKLM...CLSID} = "NeroDigitalPropSheetHandler Class"


    \InProcServer32\(Default) = "C:\Program Files\Common Files\Nero\Lib\NeroDigitalExt.dll" ["Nero AG"]


    "{03FF3962-D823-11D4-97F0-009027769C61}" = "Data Caching Shell Extension"


    -> {HKLM...CLSID} = "Data Caching Shell Extension"


    \InProcServer32\(Default) = "C:\PROGRA~1\DATACA~1\FlashShl.dll" [" "]


    "{C1B2C38F-3DCA-4E3D-BC34-D5B87B636543}" = "FileMenuTools"


    -> {HKLM...CLSID} = "FileMenuTools"


    \InProcServer32\(Default) = "C:\Program Files\LopeSoft\FileMenu Tools\FileMenuTools.dll" ["LopeSoft - Software desarrollado por Rubén López Hernández"]


    "{72853161-30C5-4D22-B7F9-0BBC1D38A37E}" = "Groove GFS Browser Helper"


    -> {HKLM...CLSID} = "Groove GFS Browser Helper"


    \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll" [MS]


    "{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}" = "Groove GFS Explorer Bar"


    -> {HKLM...CLSID} = "Groove Folder Synchronization"


    \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll" [MS]


    "{A449600E-1DC6-4232-B948-9BD794D62056}" = "Groove GFS Stub Icon Handler"


    -> {HKLM...CLSID} = "Groove GFS Stub Icon Handler"


    \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll" [MS]


    "{B5A7F190-DDA6-4420-B3BA-52453494E6CD}" = "Groove GFS Stub Execution Hook"


    -> {HKLM...CLSID} = "Groove GFS Stub Execution Hook"


    \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll" [MS]


    "{6C467336-8281-4E60-8204-430CED96822D}" = "Groove GFS Context Menu Handler"


    -> {HKLM...CLSID} = "Groove GFS Context Menu Handler"


    \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll" [MS]


    "{387E725D-DC16-4D76-B310-2C93ED4752A0}" = "Groove XML Icon Handler"


    -> {HKLM...CLSID} = "Groove XML Icon Handler"


    \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll" [MS]


    "{16F3DD56-1AF5-4347-846D-7C10C4192619}" = "Groove Explorer Icon Overlay 3 (GFS Folder)"


    -> {HKLM...CLSID} = "Groove Explorer Icon Overlay 3 (GFS Folder)"


    \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll" [MS]


    "{AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}" = "Groove Explorer Icon Overlay 2 (GFS Stub)"


    -> {HKLM...CLSID} = "Groove Explorer Icon Overlay 2 (GFS Stub)"


    \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll" [MS]


    "{2916C86E-86A6-43FE-8112-43ABE6BF8DCC}" = "Groove Explorer Icon Overlay 4 (GFS Unread Mark)"


    -> {HKLM...CLSID} = "Groove Explorer Icon Overlay 4 (GFS Unread Mark)"


    \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll" [MS]


    "{99FD978C-D287-4F50-827F-B2C658EDA8E7}" = "Groove Explorer Icon Overlay 1 (GFS Unread Stub)"


    -> {HKLM...CLSID} = "Groove Explorer Icon Overlay 1 (GFS Unread Stub)"


    \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll" [MS]


    "{920E6DB1-9907-4370-B3A0-BAFC03D81399}" = "Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)"


    -> {HKLM...CLSID} = "Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)"


    \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll" [MS]


    "{0006F045-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Custom Icon Handler"


    -> {HKLM...CLSID} = "Outlook File Icon Extension"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~3\Office12\OLKFSTUB.DLL" [MS]


    "{00020D75-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Desktop Icon Handler"


    -> {HKLM...CLSID} = "Microsoft Office Outlook"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~3\Office12\MLSHEXT.DLL" [MS]


    "{5858A72C-C2B4-4dd7-B2BF-B76DB1BD9F6C}" = "Microsoft Office OneNote Namespace Extension for Windows Desktop Search"


    -> {HKLM...CLSID} = "Microsoft Office OneNote Namespace Extension for Windows Desktop Search"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~3\Office12\ONFILTER.DLL" [MS]


    "{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"


    -> {HKLM...CLSID} = (no title provided)


    \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office12\msohevi.dll" [MS]


    "{993BE281-6695-4BA5-8A2A-7AACBFAAB69E}" = "Microsoft Office Metadata Handler"


    -> {HKLM...CLSID} = "Microsoft Office Metadata Handler"


    \InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll" [MS]


    "{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97}" = "Microsoft Office Thumbnail Handler"


    -> {HKLM...CLSID} = "Microsoft Office Thumbnail Handler"


    \InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll" [MS]


    "{97F68CE3-7146-45FF-BE24-D9A7DD7CB8A2}" = "NeroCoverEd Live Icons"


    -> {HKLM...CLSID} = "NeroCoverEdLiveIcons Class"


    \InProcServer32\(Default) = "C:\Program Files\Nero\Nero8\Nero CoverDesigner\CoverEdExtension.dll" ["Nero AG"]


    "{BD88A479-9623-4897-8546-BC62B9628F44}" = "SPTHandler"


    -> {HKLM...CLSID} = "SPTHandler"


    \InProcServer32\(Default) = "C:\Program Files\Spyware Terminator\sptcontmenu.dll" ["Crawler.com"]


    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\


    <<!>> "{B5A7F190-DDA6-4420-B3BA-52453494E6CD}" = "Groove GFS Stub Execution Hook"


    -> {HKLM...CLSID} = "Groove GFS Stub Execution Hook"


    \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll" [MS]


    HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\


    <<!>> "BootExecute" = "autocheck autochk *"|"lsdelete" [null data]| [file not found]


    HKLM\SOFTWARE\Classes\PROTOCOLS\Filter\


    <<!>> text/xml\CLSID = "{807563E5-5146-11D5-A672-00B0D022E945}"


    -> {HKLM...CLSID} = "Microsoft Office InfoPath XML Mime Filter"


    \InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL" [MS]


    HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\


    {7D4D6379-F301-4311-BEBA-E26EB0561882}\(Default) = "NeroDigitalExt.NeroDigitalColumnHandler"


    -> {HKLM...CLSID} = "NeroDigitalColumnHandler Class"


    \InProcServer32\(Default) = "C:\Program Files\Common Files\Nero\Lib\NeroDigitalExt.dll" ["Nero AG"]


    {F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info"


    -> {HKLM...CLSID} = "PDF Shell Extension"


    \InProcServer32\(Default) = "C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."]


    HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\


    Cover Designer\(Default) = "{73FCA462-9BD5-4065-A73F-A8E5F6904EF7}"


    -> {HKLM...CLSID} = "NeroCoverEdContextMenu Class"


    \InProcServer32\(Default) = "C:\Program Files\Nero\Nero8\Nero CoverDesigner\CoverEdExtension.dll" ["Nero AG"]


    FileMenuTools\(Default) = "{C1B2C38F-3DCA-4E3D-BC34-D5B87B636543}"


    -> {HKLM...CLSID} = "FileMenuTools"


    \InProcServer32\(Default) = "C:\Program Files\LopeSoft\FileMenu Tools\FileMenuTools.dll" ["LopeSoft - Software desarrollado por Rubén López Hernández"]


    SPTContMenu\(Default) = "{BD88A479-9623-4897-8546-BC62B9628F44}"


    -> {HKLM...CLSID} = "SPTHandler"


    \InProcServer32\(Default) = "C:\Program Files\Spyware Terminator\sptcontmenu.dll" ["Crawler.com"]


    WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"


    -> {HKLM...CLSID} = "WinRAR"


    \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


    ****** Groove GFS Context Menu Handler ******\(Default) = "{6C467336-8281-4E60-8204-430CED96822D}"


    -> {HKLM...CLSID} = "Groove GFS Context Menu Handler"


    \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll" [MS]


    HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\


    FileMenuTools\(Default) = "{C1B2C38F-3DCA-4E3D-BC34-D5B87B636543}"


    -> {HKLM...CLSID} = "FileMenuTools"


    \InProcServer32\(Default) = "C:\Program Files\LopeSoft\FileMenu Tools\FileMenuTools.dll" ["LopeSoft - Software desarrollado por Rubén López Hernández"]


    WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"


    -> {HKLM...CLSID} = "WinRAR"


    \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


    ****** Groove GFS Context Menu Handler ******\(Default) = "{6C467336-8281-4E60-8204-430CED96822D}"


    -> {HKLM...CLSID} = "Groove GFS Context Menu Handler"


    \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll" [MS]


    HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\


    FileMenuTools\(Default) = "{C1B2C38F-3DCA-4E3D-BC34-D5B87B636543}"


    -> {HKLM...CLSID} = "FileMenuTools"


    \InProcServer32\(Default) = "C:\Program Files\LopeSoft\FileMenu Tools\FileMenuTools.dll" ["LopeSoft - Software desarrollado por Rubén López Hernández"]


    SPTContMenu\(Default) = "{BD88A479-9623-4897-8546-BC62B9628F44}"


    -> {HKLM...CLSID} = "SPTHandler"


    \InProcServer32\(Default) = "C:\Program Files\Spyware Terminator\sptcontmenu.dll" ["Crawler.com"]


    WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"


    -> {HKLM...CLSID} = "WinRAR"


    \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


    ****** Groove GFS Context Menu Handler ******\(Default) = "{6C467336-8281-4E60-8204-430CED96822D}"


    -> {HKLM...CLSID} = "Groove GFS Context Menu Handler"


    \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll" [MS]


    HKLM\SOFTWARE\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers\


    SPTContMenu\(Default) = "{BD88A479-9623-4897-8546-BC62B9628F44}"


    -> {HKLM...CLSID} = "SPTHandler"


    \InProcServer32\(Default) = "C:\Program Files\Spyware Terminator\sptcontmenu.dll" ["Crawler.com"]


    ****** Groove GFS Context Menu Handler ******\(Default) = "{6C467336-8281-4E60-8204-430CED96822D}"


    -> {HKLM...CLSID} = "Groove GFS Context Menu Handler"


    \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll" [MS]


    Group Policies {GPedit.msc branch and setting}:


    -----------------------------------------------


    Note: detected settings may not have any effect.


    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\


    "ConsentPromptBehaviorAdmin" = (REG_DWORD) dword:0x00000002


    {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|


    User Account Control: Behavior Of The Elevation Prompt For Administrators In Admin Approval Mode}


    "ConsentPromptBehaviorUser" = (REG_DWORD) dword:0x00000001


    {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|


    User Account Control: Behavior Of The Elevation Prompt For Standard Users}


    "EnableInstallerDetection" = (REG_DWORD) dword:0x00000001


    {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|


    User Account Control: Detect Application Installations And Prompt For Elevation}


    "EnableLUA" = (REG_DWORD) dword:0x00000001


    {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|


    User Account Control: Run All Administrators In Admin Approval Mode}


    "EnableSecureUIAPaths" = (REG_DWORD) dword:0x00000001


    {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|


    User Account Control: Only elevate UIAccess applications that are installed in secure locations}


    "EnableVirtualization" = (REG_DWORD) dword:0x00000001


    {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|


    User Account Control: Virtualize file and registry write failures to per-user locations}


    "PromptOnSecureDesktop" = (REG_DWORD) dword:0x00000001


    {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|


    User Account Control: Switch to the secure desktop when prompting for elevation}


    "shutdownwithoutlogon" = (REG_DWORD) dword:0x00000001


    {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|


    Shutdown: Allow system to be shut down without having to log on}


    "undockwithoutlogon" = (REG_DWORD) dword:0x00000001


    {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|


    Devices: Allow undock without having to log on}


    "FilterAdministratorToken" = (REG_DWORD) dword:0x00000000


    {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|


    User Account Control: Admin Approval Mode for the Built-in Administrator Account}


    Active Desktop and Wallpaper:


    -----------------------------


    Active Desktop may be disabled at this entry:


    HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState


    Displayed if Active Desktop enabled and wallpaper not set by Group Policy:


    HKCU\Software\Microsoft\Internet Explorer\Desktop\General\


    "Wallpaper" = "C:\Windows\system32\config\systemprofile\AppData\Roaming\Mozilla\Firefox\Desktop Background.bmp"


    Displayed if Active Desktop disabled and wallpaper not set by Group Policy:


    HKCU\Control Panel\Desktop\


    "Wallpaper" = "C:\Users\Nick\AppData\Roaming\Mozilla\Firefox\Desktop Background.bmp"


    Enabled Screen Saver:


    ---------------------


    HKCU\Control Panel\Desktop\


    "SCRNSAVE.EXE" = "C:\Windows\system32\logon.scr" [MS]


    Startup items in "Nick" & "All Users" startup folders:


    ------------------------------------------------------


    C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup


    "OneNote 2007 Screen Clipper and Launcher" -> shortcut to: "C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE /tsr" [MS]


    Winsock2 Service Provider DLLs:


    -------------------------------


    Namespace Service Providers


    HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}


    000000000001\LibraryPath = "%SystemRoot%\system32\NLAapi.dll" [MS]


    000000000002\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]


    000000000003\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]


    000000000004\LibraryPath = "%SystemRoot%\system32\napinsp.dll" [MS]


    000000000005\LibraryPath = "%SystemRoot%\system32\pnrpnsp.dll" [MS]


    000000000006\LibraryPath = "%SystemRoot%\system32\pnrpnsp.dll" [MS]


    Transport Service Providers


    HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}


    0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:


    C:\Program Files\Common Files\iS3\Anti-Spyware\iS3lsp.dll ["iS3 & Exploit Prevention Labs, Inc."], 01 - 10, 29


    %SystemRoot%\system32\mswsock.dll [MS], 11 - 28


    Toolbars, Explorer Bars, Extensions:


    ------------------------------------


    Toolbars


    HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\


    "{F2CF5485-4E02-4F68-819C-B92DE9277049}"


    -> {HKLM...CLSID} = "&Links"


    \InProcServer32\(Default) = "C:\Windows\system32\ieframe.dll" [MS]


    HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\


    "{381FFDE8-2394-4F90-B10D-FC6124A40F8C}" = "IEToolbar"


    -> {HKLM...CLSID} = "BitDefender Toolbar"


    \InProcServer32\(Default) = "C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll" ["Bitdefender"]


    "{98828DED-A591-462F-83BA-D2F62A68B8B8}" = (no title provided)


    -> {HKLM...CLSID} = "STOPzilla"


    \InProcServer32\(Default) = "C:\Program Files\STOPzilla!\SZSG.dll" ["iS3, Inc"]


    Explorer Bars


    HKLM\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\


    HKLM\SOFTWARE\Classes\CLSID\{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}\(Default) = "Groove Folder Synchronization"


    Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]


    InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll" [MS]


    HKLM\SOFTWARE\Classes\CLSID\{FF059E31-CC5A-4E2E-BF3B-96E929D65503}\(Default) = "&Research"


    Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]


    InProcServer32\(Default) = "C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL" [MS]


    Extensions (Tools menu items, main toolbar menu buttons)


    HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\


    {08B0E5C0-4FCB-11CF-AAA5-00401C608501}\


    "MenuText" = "Sun Java Console"


    "CLSIDExtension" = "{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBC}"


    -> {HKLM...CLSID} = "Java Plug-in 1.5.0_15"


    \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_15\bin\ssv.dll" ["Sun Microsystems, Inc."]


    {2670000A-7350-4F3C-8081-5663EE0C6C49}\


    "ButtonText" = "Send to OneNote"


    "MenuText" = "S&end to OneNote"


    "CLSIDExtension" = "{48E73304-E1D6-4330-914C-F5F514E3486C}"


    -> {HKLM...CLSID} = "Send to OneNote from Internet Explorer button"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll" [MS]


    {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F}\


    "ButtonText" = "@C:\Windows\WindowsMobile\INetRepl.dll,-222"


    "CLSIDExtension" = "{2EAF5BB0-070F-11D3-9307-00C04FAE2D4F}"


    -> {HKLM...CLSID} = "Create Mobile Favorite"


    \InProcServer32\(Default) = "C:\Windows\WindowsMobile\INetRepl.dll" [MS]


    {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F}\


    "MenuText" = "@C:\Windows\WindowsMobile\INetRepl.dll,-223"


    "CLSIDExtension" = "{2EAF5BB0-070F-11D3-9307-00C04FAE2D4F}"


    -> {HKLM...CLSID} = "Create Mobile Favorite"


    \InProcServer32\(Default) = "C:\Windows\WindowsMobile\INetRepl.dll" [MS]


    {92780B25-18CC-41C8-B9BE-3C9C571A8263}\


    "ButtonText" = "Research"


    {D18A0B52-D63C-4ED0-AFC6-C1E3DC1AF43A}\


    "ButtonText" = "BitComet"


    "******" = "res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206" ["BitComet"]


    {DFB852A3-47F8-48C4-A200-58CAB36FD2A2}\


    "MenuText" = "Spybot - Search & Destroy Configuration"


    "CLSIDExtension" = "{53707962-6F74-2D53-2644-206D7942484F}"


    -> {HKLM...CLSID} = "Spybot-S&D IE Protection"


    \InProcServer32\(Default) = "C:\PROGRA~1\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"]


    Running Services (Display Name, Service Name, Path {Service DLL}):


    ------------------------------------------------------------------


    Ad-Aware 2007 Service, aawservice, ""C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe"" ["Lavasoft"]


    Andrea RT Filters Service, AERTFilters, "C:\Windows\system32\AERTSrv.exe" ["Andrea Electronics Corporation"]


    Ati External Event Utility, Ati External Event Utility, "C:\Windows\system32\Ati2evxx.exe" ["ATI Technologies Inc."]


    BitDefender Communicator, XCOMM, ""C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe" /service" ["BitDefender"]


    BitDefender Desktop Update Service, LIVESRV, ""C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe" /service" ["BitDefender SRL"]


    BitDefender Threat Scanner, scan, "C:\Windows\System32\svchost.exe -kbdx" {"C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\scan.dll" ["S.C. BitDefender S.R.L"]}


    BitDefender Virus Shield, VSSERV, ""C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe" /service" ["BitDefender S.R.L."]


    Bluetooth Support Service, BthServ, "C:\Windows\system32\svchost.exe -k bthsvcs" {"C:\Windows\System32\bthserv.dll" [MS]}


    Nero BackItUp Scheduler 3, Nero BackItUp Scheduler 3, "C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe" ["Nero AG"]


    PC Tools Auxiliary Service, sdAuxService, "C:\Program Files\Spyware Doctor\pctsAuxs.exe" ["PC Tools"]


    PC Tools Security Service, sdCoreService, "C:\Program Files\Spyware Doctor\pctsSvc.exe" ["PC Tools"]


    SBSD Security Center Service, SBSDWSCService, "C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe" ["Safer Networking Ltd."]


    Spyware Terminator Realtime Shield Service, sp_rssrv, ""C:\Program Files\Spyware Terminator\sp_rsser.exe"" ["Crawler.com"]


    STOPzilla Service, szserver, ""C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe"" ["iS3, Inc."]


    Windows Driver Foundation - User-mode Driver Framework, wudfsvc, "C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted" {"C:\Windows\System32\WUDFSvc.dll" [MS]}


    Windows Image Acquisition (WIA), stisvc, "C:\Windows\system32\svchost.exe -k imgsvc" {"C:\Windows\System32\wiaservc.dll" [MS]}


    Windows Mobile 2003-based device connectivity, WcesComm, "C:\Windows\system32\svchost.exe -k WindowsMobile" {"C:\Windows\WindowsMobile\wcescomm.dll" [MS]}


    Windows Mobile-based device connectivity, RapiMgr, "C:\Windows\system32\svchost.exe -k WindowsMobile" {"C:\Windows\WindowsMobile\rapimgr.dll" [MS]}


    Print Monitors:


    ---------------


    HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\


    PrimoMon\Driver = "Primomonnt.dll" [null data]


    Send To Microsoft OneNote Monitor\Driver = "msonpmon.dll" [MS]


    ---------- (launch time: 2008-04-13 09:10:24)


    <<!>>: Suspicious data at a malware launch point.


    + This report excludes default entries except where indicated.


    + To see *everywhere* the ****** checks and *everything* it finds,


    launch it from a command prompt or a shortcut with the -all parameter.


    + The search for DESKTOP.INI DLL launch points on all local fixed drives


    took 38 seconds.


    ---------- (total run time: 90 seconds)

    /applications/core/interface/file/attachment.php?id=1864" data-fileid="1864" rel="">Startup_Programs__NICK_PC__2008_04_13_09.10.24.txt

  • Please go here and download Silent Runners.vbs (use IE to download it) to a new folder on your drive and run it.


    It takes a minute or two and it will notify you with a popup when your log is ready (it will be in the new folder you created). Please post the information back in this thread.


    "Silent Runners.vbs", revision 56, http://www.silentrunners.org/


    Operating System: Windows Vista


    Output limited to non-default values, except where indicated by "{++}"


    Startup items buried in registry:


    ---------------------------------


    HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}


    "ehTray.exe" = "C:\Windows\ehome\ehTray.exe" [MS]


    "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}" = ""C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"" ["Nero AG"]


    "DellSupportCenter" = ""C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter" ["SupportSoft, Inc."]


    "Free Ram Optimizer" = "C:\Program Files\AceLogix\Free Ram Optimizer\fro.exe" [null data]


    "WMPNSCFG" = "C:\Program Files\Windows Media Player\WMPNSCFG.exe" [MS]


    "PcSync" = "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog" ["Time Information Services Ltd."]


    "MSServer" = "rundll32.exe C:\Users\oziC-\AppData\Local\Temp\opnnlJBU.dll,#1" [MS]


    "cmds" = "rundll32.exe C:\Users\oziC-\AppData\Local\Temp\wvUoPIBq.dll,c" [MS]


    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}


    "Windows Defender" = "C:\Program Files\Windows Defender\MSASCui.exe -hide"


    "SynTPEnh" = "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" ["Synaptics, Inc."]


    "ISUSScheduler" = ""C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start" ["Macrovision Corporation"]


    "dscactivate" = ""C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"" [null data]


    "SigmatelSysTrayApp" = "sttray.exe" ["SigmaTel, Inc."]


    "NSLauncher" = "C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe /startup" [null data]


    "NvSvc" = "RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart" [MS]


    "NvCplDaemon" = "RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup" [MS]


    "NvMediaCenter" = "RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit" [MS]


    "NVHotkey" = "rundll32.exe C:\Windows\system32\nvHotkey.dll,Start" [MS]


    "QuickTime Task" = ""C:\Program Files\VistaCodecPack\QT\QTTask.exe" -atboottime" ["Apple Inc."]


    "iTunesHelper" = ""C:\Program Files\iTunes\iTunesHelper.exe"" ["Apple Inc."]


    "BitDefender Antiphishing Helper" = ""C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"" ["BitDefender"]


    "BDAgent" = ""C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"" ["BitDefender S.R.L."]


    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\


    {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)


    -> {HKLM...CLSID} = "Adobe PDF Reader Link Helper"


    \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]


    {22BF413B-C6D2-4d91-82A9-A0F997BA588C}\(Default) = "Skype add-on (mastermind)"


    -> {HKLM...CLSID} = "Skype add-on (mastermind)"


    \InProcServer32\(Default) = "C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll" ["Skype Technologies S.A."]


    {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided)


    -> {HKLM...CLSID} = "SSVHelper Class"


    \InProcServer32\(Default) = "c:\Program Files\Java\jre1.6.0\bin\ssv.dll" ["Sun Microsystems, Inc."]


    {8126A4A5-BFD3-46FE-BBDF-BFB5CF78E489}\(Default) = (no title provided)


    -> {HKLM...CLSID} = "Alcohol Toolbar Helper"


    \InProcServer32\(Default) = "C:\Program Files\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll" [null data]


    {9030D464-4C02-4ABF-8ECC-5164760863C6}\(Default) = (no title provided)


    -> {HKLM...CLSID} = "Windows Live Sign-in Helper"


    \InProcServer32\(Default) = "C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll" [MS]


    {9CB65201-89C4-402c-BA80-02D8C59F9B1D}\(Default) = "Ask Search Assistant BHO"


    -> {HKLM...CLSID} = "Ask Search Assistant BHO"


    \InProcServer32\(Default) = "C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL" ["Ask.com"]


    {CA6319C0-31B7-401E-A518-A07C3DB8F777}\(Default) = "Browser Address Error Redirector"


    -> {HKLM...CLSID} = "CBrowserHelperObject Object"


    \InProcServer32\(Default) = "C:\Program Files\BAE\BAE.dll" ["Dell Inc."]


    {FE063DB1-4EC0-403e-8DD8-394C54984B2C}\(Default) = "Ask Toolbar BHO"


    -> {HKLM...CLSID} = "Ask Toolbar BHO"


    \InProcServer32\(Default) = "C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL" [file not found]


    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\


    "{2F603045-309F-11CF-9774-0020AFD0CFF6}" = "Synaptics Control Panel"


    -> {HKLM...CLSID} = (no title provided)


    \InProcServer32\(Default) = "C:\Program Files\Synaptics\SynTP\SynTPCpl.dll" ["Synaptics, Inc."]


    "{A70C977A-BF00-412C-90B7-034C51DA2439}" = "NvCpl DesktopContext Class"


    -> {HKLM...CLSID} = "DesktopContext Class"


    \InProcServer32\(Default) = "C:\Windows\system32\nvcpl.dll" ["NVIDIA Corporation"]


    "{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D}" = "Messenger Sharing Folders"


    -> {HKLM...CLSID} = "Mina delade mappar"


    \InProcServer32\(Default) = "C:\Program Files\MSN Messenger\fsshext.8.1.0178.00.dll" [MS]


    "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"


    -> {HKLM...CLSID} = "WinRAR"


    \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


    "{967B2D40-8B7D-4127-9049-61EA0C2C6DCE}" = "PowerISO"


    -> {HKLM...CLSID} = "PowerISO"


    \InProcServer32\(Default) = "C:\Program Files\PowerISO\PWRISOSH.DLL" ["PowerISO Computing, Inc."]


    "{327669A0-59A7-4be9-B99E-1C9F3A57611A}" = "Haali Matroska Thumbnail Exctractor"


    -> {HKLM...CLSID} = "Haali Matroska Thumbnail Extractor"


    \InProcServer32\(Default) = "C:\Program Files\VistaCodecPack\filters\mmfinfo.dll" [null data]


    "{5574006C-28F5-4a65-A28C-74DE6BFBE0BB}" = "Haali Matroska Shell Property Page"


    -> {HKLM...CLSID} = "Haali Matroska Shell Property Page"


    \InProcServer32\(Default) = "C:\Program Files\VistaCodecPack\filters\mmfinfo.dll" [null data]


    "{0561EC90-CE54-4f0c-9C55-E226110A740C}" = "Haali Column Provider"


    -> {HKLM...CLSID} = "Haali Column Provider"


    \InProcServer32\(Default) = "C:\Program Files\VistaCodecPack\filters\mmfinfo.dll" [null data]


    "{97F68CE3-7146-45FF-BE24-D9A7DD7CB8A2}" = "NeroCoverEd Live Icons"


    -> {HKLM...CLSID} = "NeroCoverEdLiveIcons Class"


    \InProcServer32\(Default) = "C:\Program Files\Nero\Nero 7\Nero CoverDesigner\CoverEdExtension.dll" ["Nero AG"]


    "{B327765E-D724-4347-8B16-78AE18552FC3}" = "NeroDigitalIconHandler"


    -> {HKLM...CLSID} = "NeroDigitalIconHandler Class"


    \InProcServer32\(Default) = "C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll" ["Nero AG"]


    "{7F1CF152-04F8-453A-B34C-E609530A9DC8}" = "NeroDigitalPropSheetHandler"


    -> {HKLM...CLSID} = "NeroDigitalPropSheetHandler Class"


    \InProcServer32\(Default) = "C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll" ["Nero AG"]


    "{5E44E225-A408-11CF-B581-008029601108}" = "Roxio DragToDisc Shell Extension"


    -> {HKLM...CLSID} = "Roxio DragToDisc Shell Extension"


    \InProcServer32\(Default) = "C:\Program Files\Roxio\Drag-to-Disc\Shellex.dll" ["Roxio"]


    "{416651E4-9C3C-11D9-8BDE-F66BAD1E3F3A}" = "PhoneBrowser"


    -> {HKLM...CLSID} = "Nokia Phone Browser"


    \InProcServer32\(Default) = "C:\Program Files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll" ["Nokia"]


    "{FFB699E0-306A-11d3-8BD1-00104B6F7516}" = "Play on my TV helper"


    -> {HKLM...CLSID} = "NVIDIA CPL Extension"


    \InProcServer32\(Default) = "C:\Windows\system32\nvcpl.dll" ["NVIDIA Corporation"]


    "{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}" = "iTunes"


    -> {HKLM...CLSID} = "iTunes"


    \InProcServer32\(Default) = "C:\Program Files\iTunes\iTunesMiniPlayer.dll" ["Apple Inc."]


    HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\


    {0561EC90-CE54-4f0c-9C55-E226110A740C}\(Default) = "Haali Column Provider"


    -> {HKLM...CLSID} = "Haali Column Provider"


    \InProcServer32\(Default) = "C:\Program Files\VistaCodecPack\filters\mmfinfo.dll" [null data]


    {7D4D6379-F301-4311-BEBA-E26EB0561882}\(Default) = "NeroDigitalExt.NeroDigitalColumnHandler"


    -> {HKLM...CLSID} = "NeroDigitalColumnHandler Class"


    \InProcServer32\(Default) = "C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll" ["Nero AG"]


    {F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info"


    -> {HKLM...CLSID} = "PDF Shell Extension"


    \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."]


    HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\


    Cover Designer\(Default) = "{73FCA462-9BD5-4065-A73F-A8E5F6904EF7}"


    -> {HKLM...CLSID} = "NeroCoverEdContextMenu Class"


    \InProcServer32\(Default) = "C:\Program Files\Nero\Nero 7\Nero CoverDesigner\CoverEdExtension.dll" ["Nero AG"]


    PowerISO\(Default) = "{967B2D40-8B7D-4127-9049-61EA0C2C6DCE}"


    -> {HKLM...CLSID} = "PowerISO"


    \InProcServer32\(Default) = "C:\Program Files\PowerISO\PWRISOSH.DLL" ["PowerISO Computing, Inc."]


    WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"


    -> {HKLM...CLSID} = "WinRAR"


    \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


    HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\


    PowerISO\(Default) = "{967B2D40-8B7D-4127-9049-61EA0C2C6DCE}"


    -> {HKLM...CLSID} = "PowerISO"


    \InProcServer32\(Default) = "C:\Program Files\PowerISO\PWRISOSH.DLL" ["PowerISO Computing, Inc."]


    WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"


    -> {HKLM...CLSID} = "WinRAR"


    \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


    HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\


    PowerISO\(Default) = "{967B2D40-8B7D-4127-9049-61EA0C2C6DCE}"


    -> {HKLM...CLSID} = "PowerISO"


    \InProcServer32\(Default) = "C:\Program Files\PowerISO\PWRISOSH.DLL" ["PowerISO Computing, Inc."]


    WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"


    -> {HKLM...CLSID} = "WinRAR"


    \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


    Group Policies {GPedit.msc branch and setting}:


    -----------------------------------------------


    Note: detected settings may not have any effect.


    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\


    "ConsentPromptBehaviorAdmin" = (REG_DWORD) dword:0x00000002


    {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|


    User Account Control: Behavior Of The Elevation Prompt For Administrators In Admin Approval Mode}


    "ConsentPromptBehaviorUser" = (REG_DWORD) dword:0x00000001


    {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|


    User Account Control: Behavior Of The Elevation Prompt For Standard Users}


    "EnableInstallerDetection" = (REG_DWORD) dword:0x00000001


    {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|


    User Account Control: Detect Application Installations And Prompt For Elevation}


    "EnableLUA" = (REG_DWORD) dword:0x00000001


    {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|


    User Account Control: Run All Administrators In Admin Approval Mode}


    "EnableSecureUIAPaths" = (REG_DWORD) dword:0x00000001


    {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|


    User Account Control: Only elevate UIAccess applications that are installed in secure locations}


    "EnableVirtualization" = (REG_DWORD) dword:0x00000001


    {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|


    User Account Control: Virtualize file and registry write failures to per-user locations}


    "PromptOnSecureDesktop" = (REG_DWORD) dword:0x00000001


    {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|


    User Account Control: Switch to the secure desktop when prompting for elevation}


    "shutdownwithoutlogon" = (REG_DWORD) dword:0x00000001


    {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|


    Shutdown: Allow system to be shut down without having to log on}


    "undockwithoutlogon" = (REG_DWORD) dword:0x00000001


    {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|


    Devices: Allow undock without having to log on}


    "FilterAdministratorToken" = (REG_DWORD) dword:0x00000000


    {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|


    User Account Control: Admin Approval Mode for the Built-in Administrator Account}


    Active Desktop and Wallpaper:


    -----------------------------


    Active Desktop may be disabled at this entry:


    HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState


    Displayed if Active Desktop enabled and wallpaper not set by Group Policy:


    HKCU\Software\Microsoft\Internet Explorer\Desktop\General\


    "Wallpaper" = ""


    Displayed if Active Desktop disabled and wallpaper not set by Group Policy:


    HKCU\Control Panel\Desktop\


    "Wallpaper" = "C:\Users\oziC-\Pictures\xp wallpapers\Thunder.jpg"


    Startup items in "oziC-" & "All Users" startup folders:


    -------------------------------------------------------


    C:\Users\oziC-\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup


    "Adobe Gamma" -> shortcut to: "C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe" ["Adobe Systems, Inc."]


    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup


    "Adobe Reader Speed Launch" -> shortcut to: "C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe" ["Adobe Systems Incorporated"]


    "Digital Line Detect" -> shortcut to: "C:\Program Files\Digital Line Detect\DLG.exe" ["Avanquest Software "]


    "Logitech Desktop Messenger" -> shortcut to: "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe -startup" ["Logitech Inc."]


    "QuickSet" -> shortcut to: "C:\Windows\Installer\{53A01CC6-14B0-4512-A2E7-10D39BF83DC4}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe" ["InstallShield Software Corp."]


    Winsock2 Service Provider DLLs:


    -------------------------------


    Namespace Service Providers


    HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}


    000000000001\LibraryPath = "%SystemRoot%\system32\NLAapi.dll" [MS]


    000000000002\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]


    000000000003\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]


    000000000004\LibraryPath = "%SystemRoot%\system32\napinsp.dll" [MS]


    000000000005\LibraryPath = "%SystemRoot%\system32\pnrpnsp.dll" [MS]


    000000000006\LibraryPath = "%SystemRoot%\system32\pnrpnsp.dll" [MS]


    Transport Service Providers


    HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}


    0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:


    %SystemRoot%\system32\mswsock.dll [MS], 01 - 18


    Toolbars, Explorer Bars, Extensions:


    ------------------------------------


    Toolbars


    HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\


    "{F2CF5485-4E02-4F68-819C-B92DE9277049}"


    -> {HKLM...CLSID} = "&Links"


    \InProcServer32\(Default) = "C:\Windows\system32\ieframe.dll" [MS]


    "{ED4BD629-C1B6-4399-8A34-02CCAA921DC9}"


    -> {HKLM...CLSID} = "Alcohol Toolbar"


    \InProcServer32\(Default) = "C:\Program Files\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll" [null data]


    "{FE063DB9-4EC0-403E-8DD8-394C54984B2C}"


    -> {HKLM...CLSID} = "Ask Toolbar"


    \InProcServer32\(Default) = "C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL" [file not found]


    HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\


    "{FE063DB9-4EC0-403E-8DD8-394C54984B2C}" = (no title provided)


    -> {HKLM...CLSID} = "Ask Toolbar"


    \InProcServer32\(Default) = "C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL" [file not found]


    "{ED4BD629-C1B6-4399-8A34-02CCAA921DC9}" = "Alcohol Toolbar"


    -> {HKLM...CLSID} = "Alcohol Toolbar"


    \InProcServer32\(Default) = "C:\Program Files\Alcohol Toolbar\v3.2.0.0\Alcohol_Toolbar.dll" [null data]


    "{381FFDE8-2394-4F90-B10D-FC6124A40F8C}" = "IEToolbar"


    -> {HKLM...CLSID} = "BitDefender Toolbar"


    \InProcServer32\(Default) = "C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll" ["Bitdefender"]


    Explorer Bars


    HKLM\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\


    HKLM\SOFTWARE\Classes\CLSID\{72FE8681-0BFA-471B-9B2A-B37ED68DD09E}\(Default) = "Ask PopSwatter"


    Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]


    InProcServer32\(Default) = "C:\Windows\system32\shdocvw.dll" [MS]


    Extensions (Tools menu items, main toolbar menu buttons)


    HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\


    {08B0E5C0-4FCB-11CF-AAA5-00401C608501}\


    "MenuText" = "Sun Java Console"


    "CLSIDExtension" = "{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC}"


    -> {HKLM...CLSID} = "Java Plug-in 1.6.0"


    \InProcServer32\(Default) = "c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll" ["Sun Microsystems, Inc."]


    {77BF5300-1474-4EC7-9980-D32B190E9B07}\


    "ButtonText" = "Skype"


    "CLSIDExtension" = "{77BF5300-1474-4EC7-9980-D32B190E9B07}"


    -> {HKLM...CLSID} = "Skype add-on (button)"


    \InProcServer32\(Default) = "C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll" ["Skype Technologies S.A."]


    {85D1F590-48F4-11D9-9669-0800200C9A66}\


    "MenuText" = "Uninstall BitDefender Online Scanner v8"


    "Exec" = "%windir%\bdoscandel.exe" [null data]


    Miscellaneous IE Hijack Points


    ------------------------------


    HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\


    <<H>> "{9CB65206-89C4-402c-BA80-02D8C59F9B1D}" = (no title provided)


    -> {HKLM...CLSID} = (no title provided)


    \InProcServer32\(Default) = "C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL" ["Ask.com"]


    Running Services (Display Name, Service Name, Path {Service DLL}):


    ------------------------------------------------------------------


    Apple Mobile Device, Apple Mobile Device, ""C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe"" ["Apple, Inc."]


    BitDefender Communicator, XCOMM, ""C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe" /service" ["BitDefender"]


    BitDefender Desktop Update Service, LIVESRV, ""C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe" /service" ["BitDefender SRL"]


    BitDefender Threat Scanner, scan, "C:\Windows\System32\svchost.exe -kbdx" {"C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\scan.dll" ["S.C. BitDefender S.R.L"]}


    BitDefender Virus Shield, VSSERV, ""C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe" /service" ["BitDefender S.R.L."]


    CNG Key Isolation, KeyIso, "C:\Windows\system32\lsass.exe" [MS]


    Computer Browser, Browser, "C:\Windows\System32\svchost.exe -k netsvcs" {"C:\Windows\System32\browser.dll" [MS]}


    Dell Internal Network Card Power Management, nicconfigsvc, ""C:\Program Files\Dell\QuickSet\NicConfigSvc.exe"" ["Dell Inc."]


    Extensible Authentication Protocol, EapHost, "C:\Windows\System32\svchost.exe -k netsvcs" {"C:\Windows\System32\eapsvc.dll" [MS]}


    Intel® PROSet/Wireless Event Log, EvtEng, "C:\Program Files\Intel\Wireless\Bin\EvtEng.exe" ["Intel Corporation"]


    Intel® PROSet/Wireless Registry Service, RegSrvc, "C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe" ["Intel Corporation"]


    iPod Service, iPod Service, ""C:\Program Files\iPod\bin\iPodService.exe"" ["Apple Inc."]


    NMIndexingService, NMIndexingService, ""C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe"" ["Nero AG"]


    PnkBstrA, PnkBstrA, "C:\Windows\system32\PnkBstrA.exe" [null data]


    ServiceLayer, ServiceLayer, ""C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe"" ["Nokia."]


    SigmaTel Audio Service, STacSV, "C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe" ["SigmaTel, Inc."]


    Smart Card, SCardSvr, "C:\Windows\system32\svchost.exe -k LocalService" {"C:\Windows\System32\SCardSvr.dll" [MS]}


    StarWind AE Service, StarWindServiceAE, "C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe" ["Rocket Division Software"]


    SupportSoft Sprocket Service (dellsupportcenter), sprtsvc_dellsupportcenter, "C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service /p dellsupportcenter" ["SupportSoft, Inc."]


    Windows Driver Foundation - User-mode Driver Framework, wudfsvc, "C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted" {"C:\Windows\System32\WUDFSvc.dll" [MS]}


    Windows Image Acquisition (WIA), stisvc, "C:\Windows\system32\svchost.exe -k imgsvc" {"C:\Windows\System32\wiaservc.dll" [MS]}


    Windows Media Player Network Sharing Service, WMPNetworkSvc, ""C:\Program Files\Windows Media Player\wmpnetwk.exe"" [MS]


    WLAN AutoConfig, Wlansvc, "C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted" {"C:\Windows\System32\wlansvc.dll" [MS]}


    XAudioService, XAudioService, "C:\Windows\system32\DRIVERS\xaudio.exe" ["Conexant Systems, Inc."]


    ---------- (launch time: 2008-04-20 15:40:55)


    <<H>>: Suspicious data at a browser hijack point.


    + This report excludes default entries except where indicated.


    + To see *everywhere* the ****** checks and *everything* it finds,


    launch it from a command prompt or a shortcut with the -all parameter.


    + To search all directories of local fixed drives for DESKTOP.INI


    DLL launch points, use the -supp parameter or answer "No" at the


    first message box and "Yes" at the second message box.


    ---------- (total run time: 81 seconds, including 6 seconds for message boxes)

  • Have this problem also, keep getting alerts that bitdefender has blocked this virus and put in quarentine. Popping up ever min now.

  • Hi, guys. I also got the trojan.vundo.dvs so I am pasting the ****** results:


    Thanx for any help possible :unsure:


    "Silent Runners.vbs", revision 56, http://www.silentrunners.org/


    Operating System: Windows XP SP2


    Output limited to non-default values, except where indicated by "{++}"


    Startup items buried in registry:


    ---------------------------------


    HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}


    "DAEMON Tools" = ""C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033" ["DT Soft Ltd."]


    "Uniblue RegistryBooster 2" = "C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S" ["Uniblue Software"]


    "Uniblue SpeedUpMyPC" = "C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe -s" ["Uniblue Software"]


    "Uniblue SpyEraser" = ""C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe" -m" ["Uniblue Software"]


    "ctfmon.exe" = "C:\WINDOWS\system32\ctfmon.exe" [MS]


    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}


    "C-Media Mixer" = "Mixer.exe /startup" ["C-Media Electronic Inc. (www.cmedia.com.tw)"]


    "StartCCC" = ""C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"" [null data]


    "DeathAdder" = "C:\Program Files\Razer\DeathAdder\razerhid.exe" [empty string]


    "BitDefender Antiphishing Helper" = ""C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"" ["BitDefender"]


    "BDAgent" = ""C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"" ["BitDefender S.R.L."]


    "ATIPTA" = "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" ["ATI Technologies, Inc."]


    "KernelFaultCheck" = "C:\WINDOWS\system32\dumprep 0 -k"


    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\


    {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)


    -> {HKLM...CLSID} = "Adobe PDF Reader Link Helper"


    \InProcServer32\(Default) = "C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]


    {0BB6EF78-FFC8-4F7A-BD2C-09DA1169A4B5}\(Default) = (no title provided)


    -> {HKLM...CLSID} = (no title provided)


    \InProcServer32\(Default) = "C:\WINDOWS\system32\tuvWqpQk.dll" [null data]


    {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}\(Default) = "BitComet ClickCapture"


    -> {HKLM...CLSID} = "BitComet Helper"


    \InProcServer32\(Default) = "C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll" ["BitComet"]


    {68F9551E-0411-48E4-9AAF-4BC42A6A46BE}\(Default) = "Canon Easy Web Print Helper"


    -> {HKLM...CLSID} = "EWPBrowseObject Class"


    \InProcServer32\(Default) = "C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll" [null data]


    {72853161-30C5-4D22-B7F9-0BBC1D38A37E}\(Default) = (no title provided)


    -> {HKLM...CLSID} = "Groove GFS Browser Helper"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL" [MS]


    {A8DC284C-E184-417C-B501-568DC4510663}\(Default) = (no title provided)


    -> {HKLM...CLSID} = (no title provided)


    \InProcServer32\(Default) = "C:\WINDOWS\system32\vtUlLBSk.dll" [null data]


    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\


    "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Display Panning CPL Extension"


    -> {HKLM...CLSID} = "Display Panning CPL Extension"


    \InProcServer32\(Default) = "deskpan.dll" [file not found]


    "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext"


    -> {HKLM...CLSID} = "HyperTerminal Icon Ext"


    \InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]


    "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"


    -> {HKLM...CLSID} = "WinRAR"


    \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


    "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"


    -> {HKLM...CLSID} = "RealOne Player Context Menu Class"


    \InProcServer32\(Default) = "C:\Program Files\ACE Mega CoDecS Pack\SystemS\RealMedia\rpshell.dll" ["RealNetworks, Inc."]


    "{72853161-30C5-4D22-B7F9-0BBC1D38A37E}" = "Groove GFS Browser Helper"


    -> {HKLM...CLSID} = "Groove GFS Browser Helper"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL" [MS]


    "{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}" = "Groove GFS Explorer Bar"


    -> {HKLM...CLSID} = "Groove Folder Synchronization"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL" [MS]


    "{A449600E-1DC6-4232-B948-9BD794D62056}" = "Groove GFS Stub Icon Handler"


    -> {HKLM...CLSID} = "Groove GFS Stub Icon Handler"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL" [MS]


    "{B5A7F190-DDA6-4420-B3BA-52453494E6CD}" = "Groove GFS Stub Execution Hook"


    -> {HKLM...CLSID} = "Groove GFS Stub Execution Hook"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL" [MS]


    "{6C467336-8281-4E60-8204-430CED96822D}" = "Groove GFS Context Menu Handler"


    -> {HKLM...CLSID} = "Groove GFS Context Menu Handler"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL" [MS]


    "{387E725D-DC16-4D76-B310-2C93ED4752A0}" = "Groove XML Icon Handler"


    -> {HKLM...CLSID} = "Groove XML Icon Handler"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL" [MS]


    "{16F3DD56-1AF5-4347-846D-7C10C4192619}" = "Groove Explorer Icon Overlay 3 (GFS Folder)"


    -> {HKLM...CLSID} = "Groove Explorer Icon Overlay 3 (GFS Folder)"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL" [MS]


    "{AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}" = "Groove Explorer Icon Overlay 2 (GFS Stub)"


    -> {HKLM...CLSID} = "Groove Explorer Icon Overlay 2 (GFS Stub)"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL" [MS]


    "{2916C86E-86A6-43FE-8112-43ABE6BF8DCC}" = "Groove Explorer Icon Overlay 4 (GFS Unread Mark)"


    -> {HKLM...CLSID} = "Groove Explorer Icon Overlay 4 (GFS Unread Mark)"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL" [MS]


    "{99FD978C-D287-4F50-827F-B2C658EDA8E7}" = "Groove Explorer Icon Overlay 1 (GFS Unread Stub)"


    -> {HKLM...CLSID} = "Groove Explorer Icon Overlay 1 (GFS Unread Stub)"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL" [MS]


    "{920E6DB1-9907-4370-B3A0-BAFC03D81399}" = "Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)"


    -> {HKLM...CLSID} = "Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL" [MS]


    "{0006F045-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Custom Icon Handler"


    -> {HKLM...CLSID} = "Outlook File Icon Extension"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\OLKFSTUB.DLL" [MS]


    "{00020D75-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Desktop Icon Handler"


    -> {HKLM...CLSID} = "Microsoft Office Outlook"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\MLSHEXT.DLL" [MS]


    "{5858A72C-C2B4-4dd7-B2BF-B76DB1BD9F6C}" = "Microsoft Office OneNote Namespace Extension for Windows Desktop Search"


    -> {HKLM...CLSID} = "Microsoft Office OneNote Namespace Extension for Windows Desktop Search"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\ONFILTER.DLL" [MS]


    "{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"


    -> {HKLM...CLSID} = (no title provided)


    \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office12\msohevi.dll" [MS]


    "{993BE281-6695-4BA5-8A2A-7AACBFAAB69E}" = "Microsoft Office Metadata Handler"


    -> {HKLM...CLSID} = "Microsoft Office Metadata Handler"


    \InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll" [MS]


    "{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97}" = "Microsoft Office Thumbnail Handler"


    -> {HKLM...CLSID} = "Microsoft Office Thumbnail Handler"


    \InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll" [MS]


    "{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu"


    -> {HKLM...CLSID} = "Portable Media Devices Menu"


    \InProcServer32\(Default) = "C:\WINDOWS\system32\Audiodev.dll" [MS]


    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\


    <<!>> "{B5A7F190-DDA6-4420-B3BA-52453494E6CD}" = "Groove GFS Stub Execution Hook"


    -> {HKLM...CLSID} = "Groove GFS Stub Execution Hook"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL" [MS]


    <<!>> "{0BB6EF78-FFC8-4F7A-BD2C-09DA1169A4B5}" = "*g" (unwritable string)


    -> {HKLM...CLSID} = (no title provided)


    \InProcServer32\(Default) = "C:\WINDOWS\system32\tuvWqpQk.dll" [null data]


    HKLM\SYSTEM\CurrentControlSet\Control\Lsa\


    <<!>> "Authentication Packages" = "msv1_0"|"C:\WINDOWS\system32\vtUlLBSk"


    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\


    <<!>> AtiExtEvent\DLLName = "Ati2evxx.dll" ["ATI Technologies Inc."]


    <<!>> tuvWqpQk\DLLName = "tuvWqpQk.dll" [null data]


    HKLM\SOFTWARE\Classes\PROTOCOLS\Filter\


    <<!>> text/xml\CLSID = "{807563E5-5146-11D5-A672-00B0D022E945}"


    -> {HKLM...CLSID} = "Microsoft Office InfoPath XML Mime Filter"


    \InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL" [MS]


    HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\


    {F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info"


    -> {HKLM...CLSID} = "PDF Shell Extension"


    \InProcServer32\(Default) = "C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."]


    HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\


    MagicISO\(Default) = "{DB85C504-C730-49DD-BEC1-7B39C6103B7A}"


    -> {HKLM...CLSID} = "MShellExtMenu Class"


    \InProcServer32\(Default) = "C:\Program Files\MagicISO\misosh.dll" ["MagicISO, Inc."]


    WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"


    -> {HKLM...CLSID} = "WinRAR"


    \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


    ****** Groove GFS Context Menu Handler ******\(Default) = "{6C467336-8281-4E60-8204-430CED96822D}"


    -> {HKLM...CLSID} = "Groove GFS Context Menu Handler"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL" [MS]


    HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\


    MagicISO\(Default) = "{DB85C504-C730-49DD-BEC1-7B39C6103B7A}"


    -> {HKLM...CLSID} = "MShellExtMenu Class"


    \InProcServer32\(Default) = "C:\Program Files\MagicISO\misosh.dll" ["MagicISO, Inc."]


    WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"


    -> {HKLM...CLSID} = "WinRAR"


    \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


    ****** Groove GFS Context Menu Handler ******\(Default) = "{6C467336-8281-4E60-8204-430CED96822D}"


    -> {HKLM...CLSID} = "Groove GFS Context Menu Handler"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL" [MS]


    HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\


    MagicISO\(Default) = "{DB85C504-C730-49DD-BEC1-7B39C6103B7A}"


    -> {HKLM...CLSID} = "MShellExtMenu Class"


    \InProcServer32\(Default) = "C:\Program Files\MagicISO\misosh.dll" ["MagicISO, Inc."]


    WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"


    -> {HKLM...CLSID} = "WinRAR"


    \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


    ****** Groove GFS Context Menu Handler ******\(Default) = "{6C467336-8281-4E60-8204-430CED96822D}"


    -> {HKLM...CLSID} = "Groove GFS Context Menu Handler"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL" [MS]


    HKLM\SOFTWARE\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers\


    ****** Groove GFS Context Menu Handler ******\(Default) = "{6C467336-8281-4E60-8204-430CED96822D}"


    -> {HKLM...CLSID} = "Groove GFS Context Menu Handler"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL" [MS]


    Group Policies {GPedit.msc branch and setting}:


    -----------------------------------------------


    Note: detected settings may not have any effect.


    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\


    "shutdownwithoutlogon" = (REG_DWORD) dword:0x00000001


    {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|


    Shutdown: Allow system to be shut down without having to log on}


    "undockwithoutlogon" = (REG_DWORD) dword:0x00000001


    {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|


    Devices: Allow undock without having to log on}


    Active Desktop and Wallpaper:


    -----------------------------


    Active Desktop may be disabled at this entry:


    HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState


    Displayed if Active Desktop enabled and wallpaper not set by Group Policy:


    HKCU\Software\Microsoft\Internet Explorer\Desktop\General\


    "Wallpaper" = "C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"


    Displayed if Active Desktop disabled and wallpaper not set by Group Policy:


    HKCU\Control Panel\Desktop\


    "Wallpaper" = "C:\Documents and Settings\Smotkoti\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"


    Startup items in "Smotkoti" & "All Users" startup folders:


    ----------------------------------------------------------


    C:\Documents and Settings\All Users\Start Menu\Programs\Startup


    "BlueSoleil" -> shortcut to: "C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe" ["IVT Corporation"]


    Enabled Scheduled Tasks:


    ------------------------


    "AppleSoftwareUpdate" -> launches: "C:\Program Files\Apple Software Update\SoftwareUpdate.exe -task" ["Apple Inc."]


    "Uniblue SpeedUpMyPC Nag" -> launches: "C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe -s" ["Uniblue Software"]


    "Uniblue SpeedUpMyPC" -> launches: "C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe -s" ["Uniblue Software"]


    "Uniblue SpyEraser" -> launches: "C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe -s" ["Uniblue Software"]


    Winsock2 Service Provider DLLs:


    -------------------------------


    Namespace Service Providers


    HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}


    000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]


    000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]


    000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]


    Transport Service Providers


    HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}


    0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:


    %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 21


    %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05


    Toolbars, Explorer Bars, Extensions:


    ------------------------------------


    Toolbars


    HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\


    "{381FFDE8-2394-4F90-B10D-FC6124A40F8C}" = "IEToolbar"


    -> {HKLM...CLSID} = "BitDefender Toolbar"


    \InProcServer32\(Default) = "C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll" ["Bitdefender"]


    "{327C2873-E90D-4C37-AA9D-10AC9BABA46C}" = "Easy-WebPrint"


    -> {HKLM...CLSID} = "Easy-WebPrint"


    \InProcServer32\(Default) = "C:\Program Files\Canon\Easy-WebPrint\Toolband.dll" [null data]


    Explorer Bars


    HKCU\Software\Microsoft\Internet Explorer\Explorer Bars\


    {FF059E31-CC5A-4E2E-BF3B-96E929D65503}\(Default) = (no title provided)


    -> {HKLM...CLSID} = "&Research"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL" [MS]


    HKLM\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\


    HKLM\SOFTWARE\Classes\CLSID\{03C1C47F-0538-4645-8372-D3109B9FC636}\(Default) = "Easy-WebPrint"


    Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]


    InProcServer32\(Default) = "C:\Program Files\Canon\Easy-WebPrint\Toolband.dll" [null data]


    HKLM\SOFTWARE\Classes\CLSID\{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}\(Default) = "Groove Folder Synchronization"


    Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]


    InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL" [MS]


    Extensions (Tools menu items, main toolbar menu buttons)


    HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\


    {2670000A-7350-4F3C-8081-5663EE0C6C49}\


    "ButtonText" = "Send to OneNote"


    "MenuText" = "S&end to OneNote"


    "CLSIDExtension" = "{48E73304-E1D6-4330-914C-F5F514E3486C}"


    -> {HKLM...CLSID} = "Send to OneNote from Internet Explorer button"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll" [MS]


    {92780B25-18CC-41C8-B9BE-3C9C571A8263}\


    "ButtonText" = "Research"


    {D18A0B52-D63C-4ED0-AFC6-C1E3DC1AF43A}\


    "ButtonText" = "BitComet"


    "******" = "res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206" ["BitComet"]


    {FB5F1910-F110-11D2-BB9E-00C04F795683}\


    "ButtonText" = "Messenger"


    "MenuText" = "Windows Messenger"


    "Exec" = "C:\Program Files\Messenger\msmsgs.exe" [MS]


    Running Services (Display Name, Service Name, Path {Service DLL}):


    ------------------------------------------------------------------


    Apple Mobile Device, Apple Mobile Device, ""C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe"" ["Apple, Inc."]


    Ati HotKey Poller, Ati HotKey Poller, "C:\WINDOWS\system32\Ati2evxx.exe" ["ATI Technologies Inc."]


    BitDefender Communicator, XCOMM, ""C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe" /service" ["BitDefender"]


    BitDefender Desktop Update Service, LIVESRV, ""C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe" /service" ["BitDefender S.R.L."]


    BitDefender Threat Scanner, scan, "C:\WINDOWS\System32\svchost.exe -kbdx" {"C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\scan.dll" ["S.C. BitDefender S.R.L"]}


    BitDefender Virus Shield, VSSERV, ""C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe" /service" ["BitDefender S.R.L."]


    BlueSoleil Hid Service, BlueSoleil Hid Service, "C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe" [null data]


    Ulead Burning Helper, UleadBurningHelper, "C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe" ["Ulead Systems, Inc."]


    Windows User Mode Driver Framework, UMWdf, "C:\WINDOWS\system32\wdfmgr.exe" [MS]


    Print Monitors:


    ---------------


    HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\


    Canon BJ Language Monitor iP4300\Driver = "CNMLM86.DLL" ["CANON INC."]


    Send To Microsoft OneNote Monitor\Driver = "msonpmon.dll" [MS]


    ---------- (launch time: 2008-04-28 00:39:30)


    <<!>>: Suspicious data at a malware launch point.


    + This report excludes default entries except where indicated.


    + To see *everywhere* the ****** checks and *everything* it finds,


    launch it from a command prompt or a shortcut with the -all parameter.


    + The search for DESKTOP.INI DLL launch points on all local fixed drives


    took 115 seconds.


    ---------- (total run time: 231 seconds)

  • Please go here and download Silent Runners.vbs (use IE to download it) to a new folder on your drive and run it.


    It takes a minute or two and it will notify you with a popup when your log is ready (it will be in the new folder you created). Please post the information back in this thread.


    Jumping on the thread not sure if this is the done thing??


    Need help with the same issue.


    Downloaded silent runner and it has given me this log....


    Not sure what to do with the information.


    The trogan vundo.dvs is continuing to duplicate its self with bit defender keeping up with the quarantine..


    Any help much appreciated....


    "Silent Runners.vbs", revision 56, http://www.silentrunners.org/


    Operating System: Windows XP SP2


    Output limited to non-default values, except where indicated by "{++}"


    Startup items buried in registry:


    ---------------------------------


    HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}


    "MSMSGS" = ""C:\Program Files\Messenger\msmsgs.exe" /background" [MS]


    "ctfmon.exe" = "C:\WINDOWS\system32\ctfmon.exe" [MS]


    "DAEMON Tools Lite" = ""C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun" ["DT Soft Ltd"]


    "AlcoholAutomount" = ""C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount" ["Alcohol Soft Development Team"]


    "kdx" = "C:\Program Files\Kontiki\KHost.exe -all" ["Kontiki Inc."]


    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}


    "SoundMAXPnP" = "C:\Program Files\Analog Devices\Core\smax4pnp.exe" ["Analog Devices, Inc."]


    "SoundMAX" = ""C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray" ["Analog Devices, Inc."]


    "SunJavaUpdateSched" = ""C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"" ["Sun Microsystems, Inc."]


    "QuickTime Task" = ""C:\Program Files\QuickTime\QTTask.exe" -atboottime" ["Apple Inc."]


    "Gainward" = "C:\WINDOWS\TBPanel.exe /A" ["Gainward Co."]


    "NvCplDaemon" = "RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup" [MS]


    "nwiz" = "nwiz.exe /install" ["NVIDIA Corporation"]


    "NvMediaCenter" = "RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit" [MS]


    "BitDefender Antiphishing Helper" = ""C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"" ["BitDefender"]


    "BDAgent" = ""C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"" ["BitDefender S.R.L."]


    "Adobe Photo Downloader" = ""C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"" ["Adobe Systems Incorporated"]


    "4oD" = ""C:\Program Files\Kontiki\KHost.exe" -all" ["Kontiki Inc."]


    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\


    {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)


    -> {HKLM...CLSID} = "Adobe PDF Reader Link Helper"


    \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]


    {72853161-30C5-4D22-B7F9-0BBC1D38A37E}\(Default) = (no title provided)


    -> {HKLM...CLSID} = "Groove GFS Browser Helper"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL" [MS]


    {74ED7DBE-EAB6-452B-9CCC-08AC295E51FC}\(Default) = (no title provided)


    -> {HKLM...CLSID} = (no title provided)


    \InProcServer32\(Default) = "C:\WINDOWS\system32\xxywwULf.dll" [null data]


    {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided)


    -> {HKLM...CLSID} = "SSVHelper Class"


    \InProcServer32\(Default) = "C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll" ["Sun Microsystems, Inc."]


    {AA58ED58-01DD-4d91-8333-CF10577473F7}\(Default) = (no title provided)


    -> {HKLM...CLSID} = "Google Toolbar Helper"


    \InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]


    {AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\(Default) = (no title provided)


    -> {HKLM...CLSID} = "Google Toolbar Notifier BHO"


    \InProcServer32\(Default) = "C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll" ["Google Inc."]


    {ecdee021-0d17-467f-a1ff-c7a115230949}\(Default) = (no title provided)


    -> {HKLM...CLSID} = "free-downloads.net Toolbar"


    \InProcServer32\(Default) = "C:\Program Files\free-downloads.net\tbfree.dll" ["Conduit Ltd."]


    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\


    "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Display Panning CPL Extension"


    -> {HKLM...CLSID} = "Display Panning CPL Extension"


    \InProcServer32\(Default) = "deskpan.dll" [file not found]


    "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext"


    -> {HKLM...CLSID} = "HyperTerminal Icon Ext"


    \InProcServer32\(Default) = "C:\WINDOWS\system32\hticons.dll" ["Hilgraeve, Inc."]


    "{EFA24E62-B078-11d0-89E4-00C04FC9E26E}" = "History Band"


    -> {HKLM...CLSID} = "History Band"


    \InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]


    "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"


    -> {HKLM...CLSID} = "WinRAR"


    \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


    "{721A1B24-EC8B-4eda-9CCE-39720B9FA747}" = "WipeExt"


    -> {HKLM...CLSID} = "WipeExt"


    \InProcServer32\(Default) = "C:\Program Files\Ace Utilities\wipext.dll" [null data]


    "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" = "OpenOffice.org Column Handler"


    -> {HKLM...CLSID} = (no title provided)


    \InProcServer32\(Default) = ""C:\Program Files\OpenOffice.org 2.3\program\shlxthdl.dll"" ["Sun Microsystems, Inc."]


    "{087B3AE3-E237-4467-B8DB-5A38AB959AC9}" = "OpenOffice.org Infotip Handler"


    -> {HKLM...CLSID} = (no title provided)


    \InProcServer32\(Default) = ""C:\Program Files\OpenOffice.org 2.3\program\shlxthdl.dll"" ["Sun Microsystems, Inc."]


    "{63542C48-9552-494A-84F7-73AA6A7C99C1}" = "OpenOffice.org Property Sheet Handler"


    -> {HKLM...CLSID} = (no title provided)


    \InProcServer32\(Default) = ""C:\Program Files\OpenOffice.org 2.3\program\shlxthdl.dll"" ["Sun Microsystems, Inc."]


    "{3B092F0C-7696-40E3-A80F-68D74DA84210}" = "OpenOffice.org Thumbnail Viewer"


    -> {HKLM...CLSID} = (no title provided)


    \InProcServer32\(Default) = ""C:\Program Files\OpenOffice.org 2.3\program\shlxthdl.dll"" ["Sun Microsystems, Inc."]


    "{993BE281-6695-4BA5-8A2A-7AACBFAAB69E}" = "Microsoft Office Metadata Handler"


    -> {HKLM...CLSID} = "Microsoft Office Metadata Handler"


    \InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll" [MS]


    "{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97}" = "Microsoft Office Thumbnail Handler"


    -> {HKLM...CLSID} = "Microsoft Office Thumbnail Handler"


    \InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll" [MS]


    "{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"


    -> {HKLM...CLSID} = (no title provided)


    \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office12\msohevi.dll" [MS]


    "{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}" = "iTunes"


    -> {HKLM...CLSID} = "iTunes"


    \InProcServer32\(Default) = "C:\Program Files\iTunes\iTunesMiniPlayer.dll" ["Apple Inc."]


    "{A70C977A-BF00-412C-90B7-034C51DA2439}" = "NvCpl DesktopContext Class"


    -> {HKLM...CLSID} = "DesktopContext Class"


    \InProcServer32\(Default) = "C:\WINDOWS\system32\nvcpl.dll" ["NVIDIA Corporation"]


    "{FFB699E0-306A-11d3-8BD1-00104B6F7516}" = "Play on my TV helper"


    -> {HKLM...CLSID} = "NVIDIA CPL Extension"


    \InProcServer32\(Default) = "C:\WINDOWS\system32\nvcpl.dll" ["NVIDIA Corporation"]


    "{1CDB2949-8F65-4355-8456-263E7C208A5D}" = "Desktop Explorer"


    -> {HKLM...CLSID} = "Desktop Explorer"


    \InProcServer32\(Default) = "C:\WINDOWS\system32\nvshell.dll" ["NVIDIA Corporation"]


    "{1E9B04FB-F9E5-4718-997B-B8DA88302A47}" = "Desktop Explorer Menu"


    -> {HKLM...CLSID} = (no title provided)


    \InProcServer32\(Default) = "C:\WINDOWS\system32\nvshell.dll" ["NVIDIA Corporation"]


    "{1E9B04FB-F9E5-4718-997B-B8DA88302A48}" = "nView Desktop Context Menu"


    -> {HKLM...CLSID} = "nView Desktop Context Menu"


    \InProcServer32\(Default) = "C:\WINDOWS\system32\nvshell.dll" ["NVIDIA Corporation"]


    "{416651E4-9C3C-11D9-8BDE-F66BAD1E3F3A}" = "PhoneBrowser"


    -> {HKLM...CLSID} = "Nokia Phone Browser"


    \InProcServer32\(Default) = "C:\Program Files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll" ["Nokia"]


    "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"


    -> {HKLM...CLSID} = "RealOne Player Context Menu Class"


    \InProcServer32\(Default) = "C:\Program Files\Real\RealPlayer\rpshell.dll" ["RealNetworks, Inc."]


    "{72853161-30C5-4D22-B7F9-0BBC1D38A37E}" = "Groove GFS Browser Helper"


    -> {HKLM...CLSID} = "Groove GFS Browser Helper"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL" [MS]


    "{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}" = "Groove GFS Explorer Bar"


    -> {HKLM...CLSID} = "Groove Folder Synchronization"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL" [MS]


    "{A449600E-1DC6-4232-B948-9BD794D62056}" = "Groove GFS Stub Icon Handler"


    -> {HKLM...CLSID} = "Groove GFS Stub Icon Handler"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL" [MS]


    "{B5A7F190-DDA6-4420-B3BA-52453494E6CD}" = "Groove GFS Stub Execution Hook"


    -> {HKLM...CLSID} = "Groove GFS Stub Execution Hook"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL" [MS]


    "{6C467336-8281-4E60-8204-430CED96822D}" = "Groove GFS Context Menu Handler"


    -> {HKLM...CLSID} = "Groove GFS Context Menu Handler"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL" [MS]


    "{387E725D-DC16-4D76-B310-2C93ED4752A0}" = "Groove XML Icon Handler"


    -> {HKLM...CLSID} = "Groove XML Icon Handler"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL" [MS]


    "{16F3DD56-1AF5-4347-846D-7C10C4192619}" = "Groove Explorer Icon Overlay 3 (GFS Folder)"


    -> {HKLM...CLSID} = "Groove Explorer Icon Overlay 3 (GFS Folder)"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL" [MS]


    "{AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}" = "Groove Explorer Icon Overlay 2 (GFS Stub)"


    -> {HKLM...CLSID} = "Groove Explorer Icon Overlay 2 (GFS Stub)"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL" [MS]


    "{2916C86E-86A6-43FE-8112-43ABE6BF8DCC}" = "Groove Explorer Icon Overlay 4 (GFS Unread Mark)"


    -> {HKLM...CLSID} = "Groove Explorer Icon Overlay 4 (GFS Unread Mark)"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL" [MS]


    "{99FD978C-D287-4F50-827F-B2C658EDA8E7}" = "Groove Explorer Icon Overlay 1 (GFS Unread Stub)"


    -> {HKLM...CLSID} = "Groove Explorer Icon Overlay 1 (GFS Unread Stub)"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL" [MS]


    "{920E6DB1-9907-4370-B3A0-BAFC03D81399}" = "Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)"


    -> {HKLM...CLSID} = "Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL" [MS]


    "{0006F045-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Custom Icon Handler"


    -> {HKLM...CLSID} = "Outlook File Icon Extension"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\OLKFSTUB.DLL" [MS]


    "{00020D75-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Desktop Icon Handler"


    -> {HKLM...CLSID} = "Microsoft Office Outlook"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\MLSHEXT.DLL" [MS]


    "{5858A72C-C2B4-4dd7-B2BF-B76DB1BD9F6C}" = "Microsoft Office OneNote Namespace Extension for Windows Desktop Search"


    -> {HKLM...CLSID} = "Microsoft Office OneNote Namespace Extension for Windows Desktop Search"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\ONFILTER.DLL" [MS]


    "{5800AD5B-72C1-477B-9A08-CA112DF06D97}" = "AutoCAD DWG InfoTip Handler"


    -> {HKLM...CLSID} = "AcInfoTipHandler"


    \InProcServer32\(Default) = "C:\Program Files\Common Files\Autodesk Shared\AcShellEx\AcShellExtension.dll" ["Autodesk"]


    "{8A0BC933-7552-42E2-A228-3BE055777227}" = "AutoCAD DWG Column Handler"


    -> {HKLM...CLSID} = "AcColumnHandler"


    \InProcServer32\(Default) = "C:\Program Files\Common Files\Autodesk Shared\AcShellEx\AcShellExtension.dll" ["Autodesk"]


    "{ADC46291-D8A1-4486-A24C-86FFB392AEFA}" = "Autodesk Dgn File Preview"


    -> {HKLM...CLSID} = "AcDgnImageExtractor"


    \InProcServer32\(Default) = "C:\Program Files\Common Files\Autodesk Shared\AcDgnCOM17.dll" ["Autodesk"]


    "{36A21736-36C2-4C11-8ACB-D4136F2B57BD}" = "AutoCAD Digital Signatures Icon Overlay Handler"


    -> {HKLM...CLSID} = "AcSignIcon"


    \InProcServer32\(Default) = "C:\WINDOWS\system32\AcSignIcon.dll" ["Autodesk, Inc."]


    "{AC1DB655-4F9A-4c39-8AD2-A65324A4C446}" = "Autodesk Drawing Preview"


    -> {HKLM...CLSID} = "ACTHUMBNAIL"


    \InProcServer32\(Default) = "C:\Program Files\Common Files\Autodesk Shared\Thumbnail\AcThumbnail16.dll" ["Autodesk, Inc."]


    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\


    <<!>> "{B5A7F190-DDA6-4420-B3BA-52453494E6CD}" = "Groove GFS Stub Execution Hook"


    -> {HKLM...CLSID} = "Groove GFS Stub Execution Hook"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL" [MS]


    <<!>> "{1C218BC1-B339-40DF-8346-792D2DBAFFB5}" = "*b" (unwritable string)


    -> {HKLM...CLSID} = (no title provided)


    \InProcServer32\(Default) = "C:\WINDOWS\system32\fccdcARl.dll" [null data]


    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\


    "WPDShServiceObj" = "{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"


    -> {HKLM...CLSID} = "WPDShServiceObj Class"


    \InProcServer32\(Default) = "C:\WINDOWS\system32\WPDShServiceObj.dll" [MS]


    HKLM\SYSTEM\CurrentControlSet\Control\Lsa\


    <<!>> "Authentication Packages" = "msv1_0"|"C:\WINDOWS\system32\xxywwULf"


    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\


    <<!>> fccdcARl\DLLName = "fccdcARl.dll" [null data]


    HKLM\SOFTWARE\Classes\PROTOCOLS\Filter\


    <<!>> text/xml\CLSID = "{807563E5-5146-11D5-A672-00B0D022E945}"


    -> {HKLM...CLSID} = "Microsoft Office InfoPath XML Mime Filter"


    \InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL" [MS]


    HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\


    {8A0BC933-7552-42E2-A228-3BE055777227}\(Default) = "AutoCAD DWG column info"


    -> {HKLM...CLSID} = "AcColumnHandler"


    \InProcServer32\(Default) = "C:\Program Files\Common Files\Autodesk Shared\AcShellEx\AcShellExtension.dll" ["Autodesk"]


    {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}\(Default) = "OpenOffice.org Column Handler"


    -> {HKLM...CLSID} = (no title provided)


    \InProcServer32\(Default) = ""C:\Program Files\OpenOffice.org 2.3\program\shlxthdl.dll"" ["Sun Microsystems, Inc."]


    {F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info"


    -> {HKLM...CLSID} = "PDF Shell Extension"


    \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."]


    HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\


    Autodesk.DWF.ContextMenu\(Default) = "{6C18531F-CA85-45F7-8278-FF33CF0A5964}"


    -> {HKLM...CLSID} = "DWFShellExt Class"


    \InProcServer32\(Default) = "C:\Program Files\Common Files\Autodesk Shared\dwf Common\DWFShellExtension.dll" ["Autodesk, Inc."]


    WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"


    -> {HKLM...CLSID} = "WinRAR"


    \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


    WipeExt\(Default) = "{721A1B24-EC8B-4eda-9CCE-39720B9FA747}"


    -> {HKLM...CLSID} = "WipeExt"


    \InProcServer32\(Default) = "C:\Program Files\Ace Utilities\wipext.dll" [null data]


    ****** Groove GFS Context Menu Handler ******\(Default) = "{6C467336-8281-4E60-8204-430CED96822D}"


    -> {HKLM...CLSID} = "Groove GFS Context Menu Handler"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL" [MS]


    HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\


    WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"


    -> {HKLM...CLSID} = "WinRAR"


    \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


    ****** Groove GFS Context Menu Handler ******\(Default) = "{6C467336-8281-4E60-8204-430CED96822D}"


    -> {HKLM...CLSID} = "Groove GFS Context Menu Handler"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL" [MS]


    HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\


    WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"


    -> {HKLM...CLSID} = "WinRAR"


    \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


    WipeExt\(Default) = "{721A1B24-EC8B-4eda-9CCE-39720B9FA747}"


    -> {HKLM...CLSID} = "WipeExt"


    \InProcServer32\(Default) = "C:\Program Files\Ace Utilities\wipext.dll" [null data]


    ****** Groove GFS Context Menu Handler ******\(Default) = "{6C467336-8281-4E60-8204-430CED96822D}"


    -> {HKLM...CLSID} = "Groove GFS Context Menu Handler"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL" [MS]


    HKLM\SOFTWARE\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers\


    ****** Groove GFS Context Menu Handler ******\(Default) = "{6C467336-8281-4E60-8204-430CED96822D}"


    -> {HKLM...CLSID} = "Groove GFS Context Menu Handler"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL" [MS]


    Group Policies {policy setting}:


    --------------------------------


    Note: detected settings may not have any effect.


    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\


    "shutdownwithoutlogon" = (REG_DWORD) dword:0x00000001


    {Shutdown: Allow system to be shut down without having to log on}


    "undockwithoutlogon" = (REG_DWORD) dword:0x00000001


    {Devices: Allow undock without having to log on}


    Active Desktop and Wallpaper:


    -----------------------------


    Active Desktop may be disabled at this entry:


    HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState


    Displayed if Active Desktop enabled and wallpaper not set by Group Policy:


    HKCU\Software\Microsoft\Internet Explorer\Desktop\General\


    "Wallpaper" = "C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"


    Displayed if Active Desktop disabled and wallpaper not set by Group Policy:


    HKCU\Control Panel\Desktop\


    "Wallpaper" = "C:\Documents and Settings\Daveo\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"


    Enabled Screen Saver:


    ---------------------


    HKCU\Control Panel\Desktop\


    "SCRNSAVE.EXE" = "C:\WINDOWS\System32\logon.scr" [MS]


    Startup items in "Daveo" & "All Users" startup folders:


    -------------------------------------------------------


    C:\Documents and Settings\All Users\Start Menu\Programs\Startup


    "Adobe Reader Speed Launch" -> shortcut to: "C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe" ["Adobe Systems Incorporated"]


    "ASUS WiFi-AP Solo" -> shortcut to: "C:\Program Files\ASUS WiFi-AP Solo\RtWLan.exe /H" ["ASUSTek Computer Inc."]


    "Google Updater" -> shortcut to: "C:\Program Files\Google\Google Updater\GoogleUpdater.exe -systray -startup" ["Google"]


    Enabled Scheduled Tasks:


    ------------------------


    "AppleSoftwareUpdate" -> launches: "C:\Program Files\Apple Software Update\SoftwareUpdate.exe -task" ["Apple Inc."]


    Winsock2 Service Provider DLLs:


    -------------------------------


    Namespace Service Providers


    HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}


    000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]


    000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]


    000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]


    Transport Service Providers


    HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}


    0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:


    %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 17


    %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05


    Toolbars, Explorer Bars, Extensions:


    ------------------------------------


    Toolbars


    HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\


    "{ECDEE021-0D17-467F-A1FF-C7A115230949}"


    -> {HKLM...CLSID} = "free-downloads.net Toolbar"


    \InProcServer32\(Default) = "C:\Program Files\free-downloads.net\tbfree.dll" ["Conduit Ltd."]


    "{2318C2B1-4965-11D4-9B18-009027A5CD4F}"


    -> {HKLM...CLSID} = "&Google"


    \InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]


    HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\


    "{ECDEE021-0D17-467F-A1FF-C7A115230949}" = "free-downloads.net Toolbar"


    -> {HKLM...CLSID} = "free-downloads.net Toolbar"


    \InProcServer32\(Default) = "C:\Program Files\free-downloads.net\tbfree.dll" ["Conduit Ltd."]


    "{327C2873-E90D-4C37-AA9D-10AC9BABA46C}" = "Easy-WebPrint"


    -> {HKLM...CLSID} = "Easy-WebPrint"


    \InProcServer32\(Default) = "C:\Program Files\Canon\Easy-WebPrint\Toolband.dll" [null data]


    "{381FFDE8-2394-4F90-B10D-FC6124A40F8C}" = "IEToolbar"


    -> {HKLM...CLSID} = "BitDefender Toolbar"


    \InProcServer32\(Default) = "C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll" ["Bitdefender"]


    "{2318C2B1-4965-11D4-9B18-009027A5CD4F}" = (no title provided)


    -> {HKLM...CLSID} = "&Google"


    \InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]


    Explorer Bars


    HKLM\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\


    HKLM\SOFTWARE\Classes\CLSID\{03C1C47F-0538-4645-8372-D3109B9FC636}\(Default) = "Easy-WebPrint"


    Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]


    InProcServer32\(Default) = "C:\Program Files\Canon\Easy-WebPrint\Toolband.dll" [null data]


    HKLM\SOFTWARE\Classes\CLSID\{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}\(Default) = "Groove Folder Synchronization"


    Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]


    InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL" [MS]


    HKLM\SOFTWARE\Classes\CLSID\{FF059E31-CC5A-4E2E-BF3B-96E929D65503}\(Default) = "&Research"


    Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]


    InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL" [MS]


    Extensions (Tools menu items, main toolbar menu buttons)


    HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\


    {08B0E5C0-4FCB-11CF-AAA5-00401C608501}\


    "MenuText" = "Sun Java Console"


    "CLSIDExtension" = "{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC}"


    -> {HKCU...CLSID} = "Java Plug-in 1.6.0_03"


    \InProcServer32\(Default) = "C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll" ["Sun Microsystems, Inc."]


    -> {HKLM...CLSID} = "Java Plug-in 1.6.0_03"


    \InProcServer32\(Default) = "C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll" ["Sun Microsystems, Inc."]


    {2670000A-7350-4F3C-8081-5663EE0C6C49}\


    "ButtonText" = "Send to OneNote"


    "MenuText" = "S&end to OneNote"


    "CLSIDExtension" = "{48E73304-E1D6-4330-914C-F5F514E3486C}"


    -> {HKLM...CLSID} = "Send to OneNote from Internet Explorer button"


    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll" [MS]


    {92780B25-18CC-41C8-B9BE-3C9C571A8263}\


    "ButtonText" = "Research"


    {94EDF7B4-4272-4AF3-8F8B-4E2F68E225B7}\


    "ButtonText" = "PacificPoker4"


    "Exec" = "C:\PROGRA~1\PACIFI~1\pacificpoker.exe" ["Cassava Ent."]


    {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}\


    "ButtonText" = "PartyPoker.com"


    "MenuText" = "PartyPoker.com"


    "Exec" = "C:\Program Files\PartyGaming\PartyPoker\RunApp.exe" [empty string]


    {E2E2DD38-D088-4134-82B7-F2BA38496583}\


    "MenuText" = "@xpsp3res.dll,-20001"


    "Exec" = "%windir%\Network Diagnostic\xpnetdiag.exe" [MS]


    {FB5F1910-F110-11D2-BB9E-00C04F795683}\


    "ButtonText" = "Messenger"


    "MenuText" = "Windows Messenger"


    "Exec" = "C:\Program Files\Messenger\msmsgs.exe" [MS]


    Miscellaneous IE Hijack Points


    ------------------------------


    HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\


    <<H>> "{ecdee021-0d17-467f-a1ff-c7a115230949}" = (no title provided)


    -> {HKLM...CLSID} = "free-downloads.net Toolbar"


    \InProcServer32\(Default) = "C:\Program Files\free-downloads.net\tbfree.dll" ["Conduit Ltd."]


    Running Services (Display Name, Service Name, Path {Service DLL}):


    ------------------------------------------------------------------


    Apple Mobile Device, Apple Mobile Device, ""C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe"" ["Apple, Inc."]


    BitDefender Communicator, XCOMM, ""C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe" /service" ["BitDefender"]


    BitDefender Desktop Update Service, LIVESRV, ""C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe" /service" ["BitDefender SRL"]


    BitDefender Threat Scanner, scan, "C:\WINDOWS\System32\svchost.exe -kbdx" {"C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\scan.dll" ["S.C. BitDefender S.R.L"]}


    BitDefender Virus Shield, VSSERV, ""C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe" /service" ["BitDefender S.R.L."]


    Google Updater Service, gusvc, ""C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"" ["Google"]


    KService, KService, ""C:\Program Files\Kontiki\KService.exe"" ["Kontiki Inc."]


    NVIDIA Display Driver Service, NVSvc, "C:\WINDOWS\system32\nvsvc32.exe" ["NVIDIA Corporation"]


    PnkBstrA, PnkBstrA, "C:\WINDOWS\system32\PnkBstrA.exe" [null data]


    ServiceLayer, ServiceLayer, ""C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe"" ["Nokia."]


    StarWind AE Service, StarWindServiceAE, "C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe" ["Rocket Division Software"]


    Windows Driver Foundation - User-mode Driver Framework, WudfSvc, "C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup" {"C:\WINDOWS\System32\WUDFSvc.dll" [MS]}


    Print Monitors:


    ---------------


    HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\


    Canon BJ Language Monitor iP6600D\Driver = "CNMLM7D.DLL" ["CANON INC."]


    Send To Microsoft OneNote Monitor\Driver = "msonpmon.dll" [MS]


    ---------- (launch time: 2008-05-04 10:50:42)


    <<!>>: Suspicious data at a malware launch point.


    <<H>>: Suspicious data at a browser hijack point.


    + This report excludes default entries except where indicated.


    + To see *everywhere* the ****** checks and *everything* it finds,


    launch it from a command prompt or a shortcut with the -all parameter.


    + To search all directories of local fixed drives for DESKTOP.INI


    DLL launch points, use the -supp parameter or answer "No" at the


    first message box and "Yes" at the second message box.


    ---------- (total run time: 62 seconds, including 18 seconds for message boxes)

  • Realy not sure the correct way to post all of this. also ran hijackthis and got these results....


    Again any help would be nice..


    Logfile of Trend Micro HijackThis v2.0.2


    Scan saved at 17:38:21, on 04/05/2008


    Platform: Windows XP SP2 (WinNT 5.01.2600)


    MSIE: Internet Explorer v7.00 (7.00.6000.16640)


    Boot mode: Normal


    Running processes:


    C:\WINDOWS\System32\smss.exe


    C:\WINDOWS\system32\winlogon.exe


    C:\WINDOWS\system32\services.exe


    C:\WINDOWS\system32\lsass.exe


    C:\WINDOWS\system32\svchost.exe


    C:\WINDOWS\System32\svchost.exe


    C:\WINDOWS\system32\svchost.exe


    C:\WINDOWS\system32\spoolsv.exe


    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe


    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe


    C:\Program Files\Kontiki\KService.exe


    C:\WINDOWS\system32\nvsvc32.exe


    C:\WINDOWS\system32\PnkBstrA.exe


    C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe


    C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe


    C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe


    C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe


    C:\WINDOWS\System32\svchost.exe


    C:\WINDOWS\System32\svchost.exe


    C:\WINDOWS\Explorer.EXE


    C:\Program Files\Analog Devices\Core\smax4pnp.exe


    C:\Program Files\Analog Devices\SoundMAX\Smax4.exe


    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe


    C:\WINDOWS\TBPanel.exe


    C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe


    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe


    C:\Program Files\Messenger\msmsgs.exe


    C:\WINDOWS\system32\ctfmon.exe


    C:\Program Files\DAEMON Tools Lite\daemon.exe


    C:\Program Files\Kontiki\KHost.exe


    C:\WINDOWS\system32\rundll32.exe


    C:\Program Files\ASUS WiFi-AP Solo\RtWLan.exe


    C:\Program Files\Google\Google Updater\GoogleUpdater.exe


    C:\WINDOWS\system32\svchost.exe


    C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe


    C:\Program Files\uTorrent\uTorrent.exe


    C:\Program Files\Internet Explorer\iexplore.exe


    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe


    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/


    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157


    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896


    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896


    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157


    R3 - URLSearchHook: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll


    O3 - Toolbar: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll


    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll


    O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll


    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll


    O4 - HKLM\..\Run: [soundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe


    O4 - HKLM\..\Run: [soundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray


    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"


    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime


    O4 - HKLM\..\Run: [Gainward] C:\WINDOWS\TBPanel.exe /A


    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup


    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install


    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit


    O4 - HKLM\..\Run: [bitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"


    O4 - HKLM\..\Run: [bDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"


    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"


    O4 - HKLM\..\Run: [4oD] "C:\Program Files\Kontiki\KHost.exe" -all


    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background


    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe


    O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun


    O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount


    O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all


    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')


    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')


    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')


    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')


    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe


    O4 - Global Startup: ASUS WiFi-AP Solo.lnk = ?


    O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe


    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000


    O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html


    O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html


    O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html


    O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html


    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll


    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll


    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll


    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll


    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL


    O9 - Extra button: PacificPoker4 - {94EDF7B4-4272-4af3-8F8B-4E2F68E225B7} - C:\PROGRA~1\PACIFI~1\pacificpoker.exe


    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe


    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe


    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe


    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe


    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe


    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe


    O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo.../sysreqlab2.cab


    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab


    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL


    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe


    O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe


    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe


    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe


    O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe


    O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe


    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe


    O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe


    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe


    O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe


    O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe


    O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe


    --


    End of file - 9256 bytes

  • rootkit
    rootkit ✭✭✭
    edited May 2008

    @ Jagandub


    The log is clean, but not all vundo version are visible to HijackThis !


    Use Malwarebytes' Anti-Malware and do a complete scan !


    And if it's somethig on your computer, please pack the files into an archive with the password infected and attach them here or upload them on a server and leave here the link ( http://forum.bitdefender.com/index.php?showtopic=84 )


    http://www.malwarebytes.org/

  • rootkit
    rootkit ✭✭✭

    Topic moved !


    @ Jagandub


    You can post here the Malwarebytes' Anti-Malware log !

  • Hi have bitdefender2008 total security and have the vundo.dvs virus. Have run scan and removed what i can however still get the pop up box here's a hijackthis and a silentrunners log


    hijack this:


    Logfile of Trend Micro HijackThis v2.0.2


    Scan saved at 18:38:17, on 27/05/2008


    Platform: Windows XP SP2 (WinNT 5.01.2600)


    MSIE: Internet Explorer v7.00 (7.00.6000.16640)


    Boot mode: Normal


    Running processes:


    C:\WINDOWS\System32\smss.exe


    C:\WINDOWS\system32\winlogon.exe


    C:\WINDOWS\system32\services.exe


    C:\WINDOWS\system32\lsass.exe


    C:\WINDOWS\system32\svchost.exe


    C:\WINDOWS\System32\svchost.exe


    C:\Program Files\Virgin Broadband\PCguard\Fws.exe


    C:\WINDOWS\system32\spoolsv.exe


    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe


    C:\Program Files\Bonjour\mDNSResponder.exe


    C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe


    C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe


    C:\Program Files\Raxco\PerfectDisk\PDAgent.exe


    C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe


    C:\Program Files\Raxco\PerfectDisk\PDEngine.exe


    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe


    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe


    C:\WINDOWS\system32\bcmwltry.exe


    C:\Program Files\Virgin Broadband\advisor\Broadbandadvisor.exe


    C:\Program Files\Common Files\Real\Update_OB\realsched.exe


    C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe


    C:\Program Files\iTunes\iTunesHelper.exe


    C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe


    C:\WINDOWS\system32\ctfmon.exe


    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe


    C:\Program Files\BigFix\BigFix.exe


    C:\Program Files\Shrink Pic\shrink_pic.exe


    C:\Program Files\iPod\bin\iPodService.exe


    C:\Program Files\Internet Explorer\iexplore.exe


    C:\Program Files\BitDefender\BitDefender 2008\seccenter.exe


    C:\WINDOWS\system32\DllHost.exe


    C:\Program Files\Internet Explorer\iexplore.exe


    C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe


    C:\WINDOWS\System32\svchost.exe


    C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe


    C:\WINDOWS\explorer.exe


    C:\WINDOWS\system32\rundll32.exe


    C:\Program Files\Virgin Broadband\PCguard\NetCnMnR.exe


    C:\WINDOWS\system32\wuauclt.exe


    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe


    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com/


    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157


    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896


    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896


    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157


    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/


    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local


    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll


    O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll


    O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\System32\igfxtray.exe


    O4 - HKLM\..\Run: [synTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe


    O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe


    O4 - HKLM\..\Run: [Removecpl] removecpl.exe


    O4 - HKLM\..\Run: [bcmwltry] bcmwltry.exe


    O4 - HKLM\..\Run: [broadbandadvisor.exe] "C:\Program Files\Virgin Broadband\advisor\Broadbandadvisor.exe" /AUTORUN


    O4 - HKLM\..\Run: [PCguard] "C:\Program Files\Virgin Broadband\PCguard\Rps.exe"


    O4 - HKLM\..\Run: [-FreedomNeedsReboot] "C:\Program Files\Virgin Broadband\PCguard\ZkRunOnceR.exe"


    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot


    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"


    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime


    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"


    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k


    O4 - HKLM\..\Run: [bitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"


    O4 - HKLM\..\Run: [bDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"


    O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"


    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe


    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe


    O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe


    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')


    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')


    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')


    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')


    O4 - Startup: Shrink Pic.lnk = C:\Program Files\Shrink Pic\shrink_pic.exe


    O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe


    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll


    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll


    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll


    O9 - Extra button: Money Viewer - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll


    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe


    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe


    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe


    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe


    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll


    O14 - IERESET.INF: START_PAGE_URL=http://www.freeserve.co.uk


    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD40/JSCDL/jre/6u...ows-i586-jc.cab


    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe


    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe


    O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe


    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe


    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe


    O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe


    O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe


    O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe


    O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe


    O23 - Service: Virgin Broadband PCguard Update Service (RPSUpdaterR) - Virgin Media - C:\Program Files\Virgin Broadband\PCguard\rpsupdaterR.exe


    O23 - Service: PCguard Firewall (RP_FWS) - Virgin Media - C:\Program Files\Virgin Broadband\PCguard\Fws.exe


    O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe


    O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe


    --


    End of file - 8297 bytes


    silent runner:


    "Silent Runners.vbs", revision 58, http://www.silentrunners.org/


    Operating System: Windows XP SP2


    Output limited to non-default values, except where indicated by "{++}"


    Startup items buried in registry:


    ---------------------------------


    HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}


    "MoneyAgent" = ""C:\Program Files\Microsoft Money\System\mnyexpr.exe"" [MS]


    "ctfmon.exe" = "C:\WINDOWS\system32\ctfmon.exe" [MS]


    "swg" = "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" ["Google Inc."]


    "Microsoft Works Update Detection" = "C:\Program Files\Microsoft Works\WkDetect.exe" ["Microsoft® Corporation"]


    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}


    "IgfxTray" = "C:\WINDOWS\System32\igfxtray.exe" ["Intel Corporation"]


    "SynTPLpr" = "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" ["Synaptics, Inc."]


    "SynTPEnh" = "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" ["Synaptics, Inc."]


    "Removecpl" = "removecpl.exe" [null data]


    "bcmwltry" = "bcmwltry.exe" ["Broadcom Corporation"]


    "Broadbandadvisor.exe" = ""C:\Program Files\Virgin Broadband\advisor\Broadbandadvisor.exe" /AUTORUN" ["Virgin Broadband"]


    "PCguard" = ""C:\Program Files\Virgin Broadband\PCguard\Rps.exe"" ["Virgin Media"]


    "-FreedomNeedsReboot" = ""C:\Program Files\Virgin Broadband\PCguard\ZkRunOnceR.exe"" ["Virgin Media"]


    "TkBellExe" = ""C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot" ["RealNetworks, Inc."]


    "SunJavaUpdateSched" = ""C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"" ["Sun Microsystems, Inc."]


    "QuickTime Task" = ""C:\Program Files\QuickTime\qttask.exe" -atboottime" ["Apple Inc."]


    "iTunesHelper" = ""C:\Program Files\iTunes\iTunesHelper.exe"" ["Apple Inc."]


    "KernelFaultCheck" = "C:\WINDOWS\system32\dumprep 0 -k"


    "BitDefender Antiphishing Helper" = ""C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"" ["BitDefender"]


    "BDAgent" = ""C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"" ["BitDefender S.R.L."]


    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\


    {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)


    -> {HKLM...CLSID} = "AcroIEHlprObj Class"


    \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx" [empty string]


    {243B17DE-77C7-46BF-B94B-0B5F309A0E64}\(Default) = (no title provided)


    -> {HKLM...CLSID} = (no title provided)


    \InProcServer32\(Default) = "C:\Program Files\Microsoft Money\System\mnyside.dll" [MS]


    {3049C3E9-B461-4BC5-8870-4C09146192CA}\(Default) = (no title provided)


    -> {HKLM...CLSID} = "RealPlayer Download and Record Plugin for Internet Explorer"


    \InProcServer32\(Default) = "C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll" ["RealPlayer"]


    {3C060EA2-E6A9-4E49-A530-D4657B8C449A}\(Default) = "Pop-Up Blocker BHO"


    -> {HKLM...CLSID} = "PopKill Class"


    \InProcServer32\(Default) = "C:\Program Files\Virgin Broadband\PCguard\pkR.dll" ["Radialpoint Inc."]


    {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided)


    -> {HKLM...CLSID} = "SSVHelper Class"


    \InProcServer32\(Default) = "C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll" ["Sun Microsystems, Inc."]


    {AA58ED58-01DD-4d91-8333-CF10577473F7}\(Default) = (no title provided)


    -> {HKLM...CLSID} = "Google Toolbar Helper"


    \InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]


    {AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\(Default) = (no title provided)


    -> {HKLM...CLSID} = "Google Toolbar Notifier BHO"


    \InProcServer32\(Default) = "C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll" ["Google Inc."]


    {BA6C6CB6-676C-4DEA-9BDA-3BC4AB075F7C}\(Default) = (no title provided)


    -> {HKLM...CLSID} = (no title provided)


    \InProcServer32\(Default) = "C:\WINDOWS\system32\rqrpnmj.dll" [file not found]


    {D23FE291-FEF4-4EB9-BF4A-E7405440DF6A}\(Default) = (no title provided)


    -> {HKLM...CLSID} = (no title provided)


    \InProcServer32\(Default) = "C:\WINDOWS\system32\vtsqq.dll" [null data]


    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\


    "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Display Panning CPL Extension"


    -> {HKLM...CLSID} = "Display Panning CPL Extension"


    \InProcServer32\(Default) = "deskpan.dll" [file not found]


    "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext"


    -> {HKLM...CLSID} = "HyperTerminal Icon Ext"


    \InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]


    "{FBE1DB69-5026-42cf-BE97-D52DDB70DB87}" = "AOL"


    -> {HKLM...CLSID} = "AOL"


    \InProcServer32\(Default) = "C:\Program Files\Common Files\aolshare\shell\uk\shellext.dll" [file not found]


    "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"


    -> {HKLM...CLSID} = "RealOne Player Context Menu Class"


    \InProcServer32\(Default) = "C:\Program Files\Real\RealPlayer\rpshell.dll" ["RealNetworks, Inc."]


    "{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}" = "iTunes"


    -> {HKLM...CLSID} = "iTunes"


    \InProcServer32\(Default) = "C:\Program Files\iTunes\iTunesMiniPlayer.dll" ["Apple Inc."]


    "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"


    -> {HKLM...CLSID} = "WinRAR"


    \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\


    <<!>> "{BA6C6CB6-676C-4DEA-9BDA-3BC4AB075F7C}" = "*i" (unwritable string)


    -> {HKLM...CLSID} = (no title provided)


    \InProcServer32\(Default) = "C:\WINDOWS\system32\rqrpnmj.dll" [file not found]


    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\


    "WPDShServiceObj" = "{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"


    -> {HKLM...CLSID} = "WPDShServiceObj Class"


    \InProcServer32\(Default) = "C:\WINDOWS\system32\WPDShServiceObj.dll" [MS]


    HKLM\SYSTEM\CurrentControlSet\Control\Lsa\


    <<!>> "Authentication Packages" = "msv1_0"|"C:\WINDOWS\system32\vtsqq"


    HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\


    <<!>> "BootExecute" = "PDBoot.exe" ["Raxco Software, Inc."]|"autocheck autochk *"


    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\


    <<!>> igfxcui\DLLName = "igfxsrvc.dll" ["Intel Corporation"]


    <<!>> rqrpnmj\DLLName = "rqrpnmj.dll" [file not found]


    HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\


    WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"


    -> {HKLM...CLSID} = "WinRAR"


    \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


    HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\


    WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"


    -> {HKLM...CLSID} = "WinRAR"


    \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


    HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\


    WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"


    -> {HKLM...CLSID} = "WinRAR"


    \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


    Group Policies {policy setting}:


    --------------------------------


    Note: detected settings may not have any effect.


    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\


    "shutdownwithoutlogon" = (REG_DWORD) dword:0x00000001


    {Shutdown: Allow system to be shut down without having to log on}


    "undockwithoutlogon" = (REG_DWORD) dword:0x00000001


    {Devices: Allow undock without having to log on}


    Active Desktop and Wallpaper:


    -----------------------------


    Active Desktop may be disabled at this entry:


    HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState


    Displayed if Active Desktop enabled and wallpaper not set by Group Policy:


    HKCU\Software\Microsoft\Internet Explorer\Desktop\General\


    "Wallpaper" = "%APPDATA%\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp"


    Displayed if Active Desktop disabled and wallpaper not set by Group Policy:


    HKCU\Control Panel\Desktop\


    "Wallpaper" = "C:\Documents and Settings\Judith Laib\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp"


    Enabled Screen Saver:


    ---------------------


    HKCU\Control Panel\Desktop\


    "SCRNSAVE.EXE" = "C:\WINDOWS\system32\logon.scr" [MS]


    Windows Portable Device AutoPlay Handlers


    -----------------------------------------


    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\


    iTunesBurnCDOnArrival\


    "Provider" = "iTunes"


    "InvokeProgID" = "iTunes.BurnCD"


    "InvokeVerb" = "burn"


    HKLM\SOFTWARE\Classes\iTunes.BurnCD\shell\burn\command\(Default) = ""C:\Program Files\iTunes\iTunes.exe" /AutoPlayBurn "%L"" ["Apple Inc."]


    iTunesImportSongsOnArrival\


    "Provider" = "iTunes"


    "InvokeProgID" = "iTunes.ImportSongsOnCD"


    "InvokeVerb" = "import"


    HKLM\SOFTWARE\Classes\iTunes.ImportSongsOnCD\shell\import\command\(Default) = ""C:\Program Files\iTunes\iTunes.exe" /AutoPlayImportSongs "%L"" ["Apple Inc."]


    iTunesPlaySongsOnArrival\


    "Provider" = "iTunes"


    "InvokeProgID" = "iTunes.PlaySongsOnCD"


    "InvokeVerb" = "play"


    HKLM\SOFTWARE\Classes\iTunes.PlaySongsOnCD\shell\play\command\(Default) = ""C:\Program Files\iTunes\iTunes.exe" /playCD "%L"" ["Apple Inc."]


    iTunesShowSongsOnArrival\


    "Provider" = "iTunes"


    "InvokeProgID" = "iTunes.ShowSongsOnCD"


    "InvokeVerb" = "showsongs"


    HKLM\SOFTWARE\Classes\iTunes.ShowSongsOnCD\shell\showsongs\command\(Default) = ""C:\Program Files\iTunes\iTunes.exe" /AutoPlayShowSongs "%L"" ["Apple Inc."]


    MSWPDShellNamespaceHandler\


    "Provider" = "@%SystemRoot%\System32\WPDShextRes.dll,-501"


    "CLSID" = "{A55803CC-4D53-404c-8557-FD63DBA95D24}"


    "InitCmdLine" = " "


    -> {HKLM...CLSID} = "WPDShextAutoplay"


    \LocalServer32\(Default) = "C:\WINDOWS\system32\WPDShextAutoplay.exe" [MS]


    PDVDPlayDVDMovieOnArrival\


    "Provider" = "PowerDVD"


    "InvokeProgID" = "DVD"


    "InvokeVerb" = "PlayWithPowerDVD"


    HKLM\SOFTWARE\Classes\DVD\shell\PlayWithPowerDVD\Command\(Default) = "C:\Program Files\PowerDVD\PowerDVD.exe %1" ["CyberLink Corp."]


    RPCDBurningOnArrival\


    "Provider" = "RealPlayer"


    "InvokeProgID" = "RealPlayer.CDBurn.6"


    "InvokeVerb" = "open"


    HKCU\Software\Classes\RealPlayer.CDBurn.6\shell\open\command\(Default) = ""C:\Program Files\Real\RealPlayer\RealPlay.exe" /burn "%1"" ["RealNetworks, Inc."]


    RPDeviceOnArrival\


    "Provider" = "RealPlayer"


    "ProgID" = "RealPlayer.HWEventHandler"


    HKLM\SOFTWARE\Classes\RealPlayer.HWEventHandler\CLSID\(Default) = "{67E76F1D-BDE2-4052-913C-2752366192D2}"


    -> {HKLM...CLSID} = "RealNetworks Scheduler"


    \LocalServer32\(Default) = ""C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -autoplay" ["RealNetworks, Inc."]


    RPPlayCDAudioOnArrival\


    "Provider" = "RealPlayer"


    "InvokeProgID" = "RealPlayer.AudioCD.6"


    "InvokeVerb" = "play"


    HKCU\Software\Classes\RealPlayer.AudioCD.6\shell\play\command\(Default) = ""C:\Program Files\Real\RealPlayer\RealPlay.exe" /play %1 " ["RealNetworks, Inc."]


    RPPlayDVDMovieOnArrival\


    "Provider" = "RealPlayer"


    "InvokeProgID" = "RealPlayer.DVD.6"


    "InvokeVerb" = "play"


    HKCU\Software\Classes\RealPlayer.DVD.6\shell\play\command\(Default) = ""C:\Program Files\Real\RealPlayer\RealPlay.exe" /dvd %1 " ["RealNetworks, Inc."]


    RPPlayMediaOnArrival\


    "Provider" = "RealPlayer"


    "InvokeProgID" = "RealPlayer.AutoPlay.6"


    "InvokeVerb" = "open"


    HKCU\Software\Classes\RealPlayer.AutoPlay.6\shell\open\command\(Default) = ""C:\Program Files\Real\RealPlayer\RealPlay.exe" /autoplay "%1"" ["RealNetworks, Inc."]


    Startup items in "Judith Laib" & "All Users" startup folders:


    -------------------------------------------------------------


    C:\Documents and Settings\Judith Laib\Start Menu\Programs\Startup


    "Shrink Pic" -> shortcut to: "C:\Program Files\Shrink Pic\shrink_pic.exe -s" [null data]


    C:\Documents and Settings\All Users\Start Menu\Programs\Startup


    "BigFix" -> shortcut to: "C:\Program Files\BigFix\BigFix.exe /atstartup" ["BigFix Inc."]


    Enabled Scheduled Tasks:


    ------------------------


    "AppleSoftwareUpdate" -> launches: "C:\Program Files\Apple Software Update\SoftwareUpdate.exe -task" ["Apple Inc."]


    Winsock2 Service Provider DLLs:


    -------------------------------


    Namespace Service Providers


    HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}


    000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]


    000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]


    000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]


    000000000004\LibraryPath = "C:\Program Files\Bonjour\mdnsNSP.dll" ["Apple Inc."]


    Transport Service Providers


    HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}


    0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:


    %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 15


    %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05


    Toolbars, Explorer Bars, Extensions:


    ------------------------------------


    Toolbars


    HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\


    "{2318C2B1-4965-11D4-9B18-009027A5CD4F}"


    -> {HKLM...CLSID} = "&Google"


    \InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]


    HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\


    "{2318C2B1-4965-11D4-9B18-009027A5CD4F}" = (no title provided)


    -> {HKLM...CLSID} = "&Google"


    \InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]


    "{381FFDE8-2394-4F90-B10D-FC6124A40F8C}" = "IEToolbar"


    -> {HKLM...CLSID} = "BitDefender Toolbar"


    \InProcServer32\(Default) = "C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll" ["Bitdefender"]


    Explorer Bars


    HKLM\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\


    {FE54FA40-D68C-11D2-98FA-00C0F0318AFE}\(Default) = (no title provided)


    -> {HKLM...CLSID} = "Real.com"


    \InProcServer32\(Default) = "C:\WINDOWS\System32\Shdocvw.dll" [MS]


    HKLM\SOFTWARE\Classes\CLSID\{D6A116E7-5906-42E4-87F6-E7E15936415E}\(Default) = "Money Viewer"


    Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]


    InProcServer32\(Default) = "C:\Program Files\Microsoft Money\System\mnyside.dll" [MS]


    Extensions (Tools menu items, main toolbar menu buttons)


    HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\


    {08B0E5C0-4FCB-11CF-AAA5-00401C608501}\


    "MenuText" = "Sun Java Console"


    "CLSIDExtension" = "{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC}"


    -> {HKCU...CLSID} = "Java Plug-in 1.6.0_05"


    \InProcServer32\(Default) = "C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll" ["Sun Microsystems, Inc."]


    -> {HKLM...CLSID} = "Java Plug-in 1.6.0_05"


    \InProcServer32\(Default) = "C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll" ["Sun Microsystems, Inc."]


    {CD67F990-D8E9-11D2-98FE-00C0F0318AFE}\


    "ButtonText" = "Real.com"


    {E023F504-0C5A-4750-A1E7-A9046DEA8A21}\


    "ButtonText" = "Money Viewer"


    "CLSIDExtension" = "{DD6687B5-CB43-4211-BFC9-2942CCBDCB3E}"


    -> {HKLM...CLSID} = (no title provided)


    \InProcServer32\(Default) = "C:\Program Files\Microsoft Money\System\mnyside.dll" [MS]


    {E2E2DD38-D088-4134-82B7-F2BA38496583}\


    "MenuText" = "@xpsp3res.dll,-20001"


    "Exec" = "%windir%\Network Diagnostic\xpnetdiag.exe" [MS]


    {FB5F1910-F110-11D2-BB9E-00C04F795683}\


    "ButtonText" = "Messenger"


    "MenuText" = "Windows Messenger"


    "Exec" = "C:\Program Files\Messenger\msmsgs.exe" [MS]


    Running Services (Display Name, Service Name, Path {Service DLL}):


    ------------------------------------------------------------------


    Apple Mobile Device, Apple Mobile Device, ""C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe"" ["Apple, Inc."]


    BitDefender Communicator, XCOMM, ""C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe" /service" ["BitDefender"]


    BitDefender Desktop Update Service, LIVESRV, ""C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe" /service" ["BitDefender SRL"]


    BitDefender Threat Scanner, scan, "C:\WINDOWS\System32\svchost.exe -kbdx" {"C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\scan.dll" ["S.C. BitDefender S.R.L"]}


    BitDefender Virus Shield, VSSERV, ""C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe" /service" ["BitDefender S.R.L."]


    Bonjour Service, Bonjour Service, ""C:\Program Files\Bonjour\mDNSResponder.exe"" ["Apple Inc."]


    CA Pest Patrol Realtime Protection Service, ITMRTSVC, ""C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe"" ["CA, Inc."]


    DvpApi, dvpapi, ""C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe"" ["Authentium, Inc."]


    iPod Service, iPod Service, ""C:\Program Files\iPod\bin\iPodService.exe"" ["Apple Inc."]


    PCguard Firewall, RP_FWS, "C:\Program Files\Virgin Broadband\PCguard\Fws.exe" ["Virgin Media"]


    PDAgent, PDAgent, ""C:\Program Files\Raxco\PerfectDisk\PDAgent.exe"" ["Raxco Software, Inc."]


    PDEngine, PDEngine, ""C:\Program Files\Raxco\PerfectDisk\PDEngine.exe"" ["Raxco Software, Inc."]


    Windows CardSpace, idsvc, ""C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe"" [MS]


    ---------- (launch time: 2008-05-27 19:05:39)


    <<!>>: Suspicious data at a malware launch point.


    + This report excludes default entries except where indicated.


    + To see *everywhere* the ****** checks and *everything* it finds,


    launch it from a command prompt or a shortcut with the -all parameter.


    + To search all directories of local fixed drives for DESKTOP.INI


    DLL launch points, use the -supp parameter or answer "No" at the


    first message box and "Yes" at the second message box.


    ---------- (total run time: 99 seconds, including 6 seconds for message boxes)


    Any help would be much appreciated

  • p.s the file infected seems to be called c:\windows\system32\qqstv.ini


    cheers :)

  • rootkit
    rootkit ✭✭✭

    Run a complete scan with Malwarebytes' Anti-Malware !