Systmesy
Topic Starter
this is my second time coming here for help… ive been carefull since the first time last year when i was infected and got help here. obviously something still got me.
I use spyware guard, spywareblaster, spybot s&d, adaware se, etc.
i have configured my IE settings the best i can using this site:
https://netfiles.uiuc.edu/ehowes/www/btw/ie/ie-opts.htm
still somehow i got infected by a trojan which has been downloading tons of carp**, altered my IE security settings, and added unwanted sites to my trusted zone. Some of the items listed i know are bad and i have removed repeatedly but the trojan keeps reinstalling them. I appreciate any help and thank you in advance for your assistance.
here is my hjt log:
Logfile of HijackThis v1.99.1
Scan saved at 7:54:40 PM, on 5/19/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
C:\Program Files\Verizon Online\WinPoET\WrOS.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\WINDOWS\System32\paytime.exe
C:\WINDOWS\System32\paytime.exe
C:\Program Files\Verizon Online\SupportCenter\bin\mpbtn.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\ISTsvc\istsvc.exe
C:\WINDOWS\dffuhf.exe
C:\Program Files\Internet Optimizer\optimize.exe
c:\program files\180solutions\sais.exe
C:\WINDOWS\System32\cmd.exe
C:\WINDOWS\System32\cmd.exe
C:\WINDOWS\System32\cmd.exe
C:\Documents and Settings\Scotts\My Documents\hjt and backup fiels\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://81.222.131.49/index.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://cgi.verizon.net/bookmarks/bmredir.a….0&bm=ho_search
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://81.222.131.49/index.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://81.222.131.49/index.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://81.222.131.49/index.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://81.222.131.49/index.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://81.222.131.49/index.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer customized for Verizon Online
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [MediaFace Integration] C:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [ifanqb] C:\WINDOWS\ifanqb.exe
O4 - HKLM\..\Run: [PayTime] C:\WINDOWS\System32\paytime.exe
O4 - HKLM\..\Run: [annaT3f] C:\WINDOWS\dffuhf.exe
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [sais] c:\program files\180solutions\sais.exe
O4 - HKLM\..\Run: [jubgvyp] C:\WINDOWS\jubgvyp.exe
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [DeleteISTbar] rundll32.exe advpack.dll,DelNodeRunDLL32 "C:\Program Files\ISTbar\istbarcm.dll"
O4 - HKCU\..\Run: [PayTime] C:\WINDOWS\System32\paytime.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\SupportCenter\bin\matcli.exe
O9 - Extra button: Control Pad - {28D44DAC-D1FC-4d4f-BB1B-ADF037C8DDBC} - C:\Program Files\Verizon Online\ControlPad\Misc\a_menu.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O15 - Trusted Zone: http://www.angelfire.com
O15 - Trusted Zone: *.cattco.org
O15 - Trusted Zone: *.dell.com
O15 - Trusted Zone: *.ea.com
O15 - Trusted Zone: *.ebaumsworld.com
O15 - Trusted Zone: *.ebgames.com
O15 - Trusted Zone: http://www.erie.gov
O15 - Trusted Zone: *.erie.gov
O15 - Trusted Zone: *.fandango.com
O15 - Trusted Zone: http://www.sims2shoppe.freewebsitehosting.com
O15 - Trusted Zone: http://www.geico.com
O15 - Trusted Zone: *.co.genesee.ny.us
O15 - Trusted Zone: *.healthcaresource.com
O15 - Trusted Zone: *.hotmail.com
O15 - Trusted Zone: *.forums.jedi-tech.com
O15 - Trusted Zone: http://www.limewire.com
O15 - Trusted Zone: *.Logfile of HijackThis v1.98.2
O15 - Trusted Zone: http://www.lucasarts.com
O15 - Trusted Zone: *.lucasarts.com
O15 - Trusted Zone: http://www.mediaplay.com
O15 - Trusted Zone: *.mediaplay.com
O15 - Trusted Zone: *.hotmail.msn.com
O15 - Trusted Zone: http://by103fd.bay103.hotmail.msn.com
O15 - Trusted Zone: http://www.mtv.com
O15 - Trusted Zone: *.netflix.com
O15 - Trusted Zone: *.niagaracounty.com
O15 - Trusted Zone: *.nvidia.com
O15 - Trusted Zone: *.orleansny.com
O15 - Trusted Zone: http://www.pandasoftware.com
O15 - Trusted Zone: *.pandasoftware.com
O15 - Trusted Zone: *.passport.com
O15 - Trusted Zone: *.login.passport.net
O15 - Trusted Zone: http://login.passport.net
O15 - Trusted Zone: *.www.psheddy.com
O15 - Trusted Zone: http://www.rochesternypolice.com
O15 - Trusted Zone: *.rochesternypolice.com
O15 - Trusted Zone: *.rottentomatoes.com
O15 - Trusted Zone: *.salliemae.com
O15 - Trusted Zone: http://www.secretservice.gov
O15 - Trusted Zone: *.secretservice.gov
O15 - Trusted Zone: *..station.sony.com
O15 - Trusted Zone: *.starwarsgalaxies.station.sony.com
O15 - Trusted Zone: http://starwarsgalaxies.station.sony.com
O15 - Trusted Zone: *.state.ny.us
O15 - Trusted Zone: *.station.com
O15 - Trusted Zone: *.thesims2.com
O15 - Trusted Zone: http://www.thesimsresource.com
O15 - Trusted Zone: *.tomcoyote.org
O15 - Trusted Zone: *.housecall.trendmicro.com
O15 - Trusted Zone: http://housecall.trendmicro.com
O15 - Trusted Zone: *.verizon.com
O15 - Trusted Zone: http://cgi.verizon.net
O15 - Trusted Zone: *.verizon.net
O15 - Trusted Zone: *.wyomingco.net
O15 - Trusted Zone: http://ny.contentmatch.net (HKLM)
O15 - Trusted Zone: *.skoobidoo.com (HKLM)
O15 - Trusted Zone: *.slotchbar.com (HKLM)
O15 - Trusted Zone: *.windupdates.com (HKLM)
O15 - Trusted IP range: 81.222.131.59 (HKLM)
O16 - DPF: {10ABC6DB-E091-4EAE-98DD-21B5A2460714} (DetInstaller Class) - http://www.pandasoftware.es/avchecker/cont…s/AvDetInst.cab
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/MediaAcc…bridge-c293.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by103fd.bay103.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {7C559105-9ECF-42B8-B3F7-832E75EDD959} (Installer Class) - http://www.xxxtoolbar.com/ist/softwares/v4…006_regular.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0B714D75-9E59-4E12-83FE-BF0E4FF447C8}: NameServer = 151.202.0.84 151.203.0.84
O17 - HKLM\System\CS1\Services\Tcpip\..\{0B714D75-9E59-4E12-83FE-BF0E4FF447C8}: NameServer = 151.202.0.84 151.203.0.84
O23 - Service: iTunes Music Service (iTunesMusic) - Unknown owner - C:\WINDOWS\iTunesMusic.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: sdktemp - Unknown owner - C:\WINDOWS\sdktemp.exe
O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
O23 - Service: WinPPPoverEthernet - iVasion, a Routerware Company - C:\Program Files\Verizon Online\WinPoET\WrOS.EXE
I use spyware guard, spywareblaster, spybot s&d, adaware se, etc.
i have configured my IE settings the best i can using this site:
https://netfiles.uiuc.edu/ehowes/www/btw/ie/ie-opts.htm
still somehow i got infected by a trojan which has been downloading tons of carp**, altered my IE security settings, and added unwanted sites to my trusted zone. Some of the items listed i know are bad and i have removed repeatedly but the trojan keeps reinstalling them. I appreciate any help and thank you in advance for your assistance.
here is my hjt log:
Logfile of HijackThis v1.99.1
Scan saved at 7:54:40 PM, on 5/19/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
C:\Program Files\Verizon Online\WinPoET\WrOS.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\WINDOWS\System32\paytime.exe
C:\WINDOWS\System32\paytime.exe
C:\Program Files\Verizon Online\SupportCenter\bin\mpbtn.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\ISTsvc\istsvc.exe
C:\WINDOWS\dffuhf.exe
C:\Program Files\Internet Optimizer\optimize.exe
c:\program files\180solutions\sais.exe
C:\WINDOWS\System32\cmd.exe
C:\WINDOWS\System32\cmd.exe
C:\WINDOWS\System32\cmd.exe
C:\Documents and Settings\Scotts\My Documents\hjt and backup fiels\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://81.222.131.49/index.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://cgi.verizon.net/bookmarks/bmredir.a….0&bm=ho_search
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://81.222.131.49/index.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://81.222.131.49/index.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://81.222.131.49/index.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://81.222.131.49/index.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://81.222.131.49/index.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer customized for Verizon Online
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [MediaFace Integration] C:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [ifanqb] C:\WINDOWS\ifanqb.exe
O4 - HKLM\..\Run: [PayTime] C:\WINDOWS\System32\paytime.exe
O4 - HKLM\..\Run: [annaT3f] C:\WINDOWS\dffuhf.exe
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [sais] c:\program files\180solutions\sais.exe
O4 - HKLM\..\Run: [jubgvyp] C:\WINDOWS\jubgvyp.exe
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [DeleteISTbar] rundll32.exe advpack.dll,DelNodeRunDLL32 "C:\Program Files\ISTbar\istbarcm.dll"
O4 - HKCU\..\Run: [PayTime] C:\WINDOWS\System32\paytime.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\SupportCenter\bin\matcli.exe
O9 - Extra button: Control Pad - {28D44DAC-D1FC-4d4f-BB1B-ADF037C8DDBC} - C:\Program Files\Verizon Online\ControlPad\Misc\a_menu.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O15 - Trusted Zone: http://www.angelfire.com
O15 - Trusted Zone: *.cattco.org
O15 - Trusted Zone: *.dell.com
O15 - Trusted Zone: *.ea.com
O15 - Trusted Zone: *.ebaumsworld.com
O15 - Trusted Zone: *.ebgames.com
O15 - Trusted Zone: http://www.erie.gov
O15 - Trusted Zone: *.erie.gov
O15 - Trusted Zone: *.fandango.com
O15 - Trusted Zone: http://www.sims2shoppe.freewebsitehosting.com
O15 - Trusted Zone: http://www.geico.com
O15 - Trusted Zone: *.co.genesee.ny.us
O15 - Trusted Zone: *.healthcaresource.com
O15 - Trusted Zone: *.hotmail.com
O15 - Trusted Zone: *.forums.jedi-tech.com
O15 - Trusted Zone: http://www.limewire.com
O15 - Trusted Zone: *.Logfile of HijackThis v1.98.2
O15 - Trusted Zone: http://www.lucasarts.com
O15 - Trusted Zone: *.lucasarts.com
O15 - Trusted Zone: http://www.mediaplay.com
O15 - Trusted Zone: *.mediaplay.com
O15 - Trusted Zone: *.hotmail.msn.com
O15 - Trusted Zone: http://by103fd.bay103.hotmail.msn.com
O15 - Trusted Zone: http://www.mtv.com
O15 - Trusted Zone: *.netflix.com
O15 - Trusted Zone: *.niagaracounty.com
O15 - Trusted Zone: *.nvidia.com
O15 - Trusted Zone: *.orleansny.com
O15 - Trusted Zone: http://www.pandasoftware.com
O15 - Trusted Zone: *.pandasoftware.com
O15 - Trusted Zone: *.passport.com
O15 - Trusted Zone: *.login.passport.net
O15 - Trusted Zone: http://login.passport.net
O15 - Trusted Zone: *.www.psheddy.com
O15 - Trusted Zone: http://www.rochesternypolice.com
O15 - Trusted Zone: *.rochesternypolice.com
O15 - Trusted Zone: *.rottentomatoes.com
O15 - Trusted Zone: *.salliemae.com
O15 - Trusted Zone: http://www.secretservice.gov
O15 - Trusted Zone: *.secretservice.gov
O15 - Trusted Zone: *..station.sony.com
O15 - Trusted Zone: *.starwarsgalaxies.station.sony.com
O15 - Trusted Zone: http://starwarsgalaxies.station.sony.com
O15 - Trusted Zone: *.state.ny.us
O15 - Trusted Zone: *.station.com
O15 - Trusted Zone: *.thesims2.com
O15 - Trusted Zone: http://www.thesimsresource.com
O15 - Trusted Zone: *.tomcoyote.org
O15 - Trusted Zone: *.housecall.trendmicro.com
O15 - Trusted Zone: http://housecall.trendmicro.com
O15 - Trusted Zone: *.verizon.com
O15 - Trusted Zone: http://cgi.verizon.net
O15 - Trusted Zone: *.verizon.net
O15 - Trusted Zone: *.wyomingco.net
O15 - Trusted Zone: http://ny.contentmatch.net (HKLM)
O15 - Trusted Zone: *.skoobidoo.com (HKLM)
O15 - Trusted Zone: *.slotchbar.com (HKLM)
O15 - Trusted Zone: *.windupdates.com (HKLM)
O15 - Trusted IP range: 81.222.131.59 (HKLM)
O16 - DPF: {10ABC6DB-E091-4EAE-98DD-21B5A2460714} (DetInstaller Class) - http://www.pandasoftware.es/avchecker/cont…s/AvDetInst.cab
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/MediaAcc…bridge-c293.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by103fd.bay103.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {7C559105-9ECF-42B8-B3F7-832E75EDD959} (Installer Class) - http://www.xxxtoolbar.com/ist/softwares/v4…006_regular.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0B714D75-9E59-4E12-83FE-BF0E4FF447C8}: NameServer = 151.202.0.84 151.203.0.84
O17 - HKLM\System\CS1\Services\Tcpip\..\{0B714D75-9E59-4E12-83FE-BF0E4FF447C8}: NameServer = 151.202.0.84 151.203.0.84
O23 - Service: iTunes Music Service (iTunesMusic) - Unknown owner - C:\WINDOWS\iTunesMusic.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: sdktemp - Unknown owner - C:\WINDOWS\sdktemp.exe
O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
O23 - Service: WinPPPoverEthernet - iVasion, a Routerware Company - C:\Program Files\Verizon Online\WinPoET\WrOS.EXE