This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

run-time error '70'

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

when i start up my pc and log into my account on xp i get my windows wallpaper but the desktop icons take forever to load. and then i get no less than 50 popups telling me 'run time error 70. not only that but my net connection is either dramatically slow or keeps dropping out, and i'm sure it's because of the run time problem.

i've attached my hijinks this log and i'm hoping someone can tell me how to fix my pc.

Logfile of HijackThis v1.99.1
Scan saved at 11:29:19 PM, on 10/21/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
C:\WINDOWS\System32\msiexec.exe
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\Program Files\Yahoo!\Messenger\YPager.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\MARG~1.FRA\LOCALS~1\Temp\Rar$EX00.563\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.eftel.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.com/search/search_frame.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.icq.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.eftel.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.eftel.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.eftel.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [Antivirus Socket Manager] C:\WINDOWS\system32\WinOCX32.exe
O4 - HKLM\..\Run: [Remote Update Verification] C:\WINDOWS\system32\DBDllServ.exe
O4 - HKLM\..\Run: [Windows Validation Client] C:\WINDOWS\system32\DBDllCom.exe
O4 - HKLM\..\Run: [Antivirus 32 Manager] C:\WINDOWS\system32\WinOCX32.exe
O4 - HKLM\..\Run: [Registry Client Manager] C:\WINDOWS\system32\MSAVCfg.exe
O4 - HKLM\..\Run: [Driver Device Service] C:\WINDOWS\system32\WinExec.exe
O4 - HKLM\..\Run: [Current Service Validation] C:\WINDOWS\system32\SysDllServ.exe
O4 - HKLM\..\Run: [NT Application Server] C:\WINDOWS\system32\OSAVCfg.exe
O4 - HKLM\..\Run: [XP Manager Socket] C:\WINDOWS\system32\OSAVCfg.exe
O4 - HKLM\..\Run: [System Verification Manager] C:\WINDOWS\system32\MSExecCom.exe
O4 - HKLM\..\Run: [Secure Server 32] C:\WINDOWS\system32\OSOCX32.exe
O4 - HKLM\..\Run: [Microsoft 32 Manager] C:\WINDOWS\system32\WinExec.exe
O4 - HKLM\..\Run: [Secure Server Device] C:\WINDOWS\system32\OSOCX32.exe
O4 - HKLM\..\Run: [Win Verification Application] C:\WINDOWS\system32\MSExecCom.exe
O4 - HKLM\..\Run: [System Verification Application] C:\WINDOWS\system32\MSExecCom.exe
O4 - HKLM\..\Run: [Win Validation Client] C:\WINDOWS\system32\DBExecCom.exe
O4 - HKLM\..\Run: [Admin Manager Update] C:\WINDOWS\system32\SysExecServ.exe
O4 - HKLM\..\RunServices: [Driver Device Service] C:\WINDOWS\system32\WinExec.exe
O4 - HKLM\..\RunServices: [NT Application Server] C:\WINDOWS\system32\OSAVCfg.exe
O4 - HKLM\..\RunServices: [Remote Update Verification] C:\WINDOWS\system32\DBDllServ.exe
O4 - HKLM\..\RunServices: [Windows Validation Client] C:\WINDOWS\system32\DBDllCom.exe
O4 - HKLM\..\RunServices: [System Verification Manager] C:\WINDOWS\system32\MSExecCom.exe
O4 - HKLM\..\RunServices: [XP Manager Socket] C:\WINDOWS\system32\OSAVCfg.exe
O4 - HKLM\..\RunServices: [Secure Server 32] C:\WINDOWS\system32\OSOCX32.exe
O4 - HKLM\..\RunServices: [Root Update Verification] C:\WINDOWS\system32\MSDllServ.exe
O4 - HKLM\..\RunServices: [Registry Client Manager] C:\WINDOWS\system32\MSAVCfg.exe
O4 - HKLM\..\RunServices: [MS Manager Socket] C:\WINDOWS\system32\OSAV32.exe
O4 - HKLM\..\RunServices: [Antivirus 32 Manager] C:\WINDOWS\system32\WinOCX32.exe
O4 - HKLM\..\RunServices: [Admin Manager Update] C:\WINDOWS\system32\SysExecServ.exe
O4 - HKLM\..\RunServices: [Remote Update Client] C:\WINDOWS\system32\DBDllCom.exe
O4 - HKLM\..\RunServices: [Microsoft Device Service] C:\WINDOWS\system32\WinExec.exe
O4 - HKLM\..\RunServices: [Antivirus Socket Device] C:\WINDOWS\system32\WinOCX32.exe
O4 - HKLM\..\RunServices: [Microsoft 32 Service] C:\WINDOWS\system32\WinExec.exe
O4 - HKLM\..\RunServices: [Firewall Socket Device] C:\WINDOWS\system32\WinOCX32.exe
O4 - HKLM\..\RunServices: [System Verification Application] C:\WINDOWS\system32\MSExecCom.exe
O4 - HKLM\..\RunServices: [Root Service Validation] C:\WINDOWS\system32\DBDllServ.exe
O4 - HKLM\..\RunServices: [MS Manager 32] C:\WINDOWS\system32\OSAV32.exe
O4 - HKLM\..\RunServices: [MS Server 32] C:\WINDOWS\system32\OSOCX32.exe
O4 - HKLM\..\RunServices: [Current Manager Validation] C:\WINDOWS\system32\SysDllServ.exe
O4 - HKLM\..\RunServices: [Current Manager Update] C:\WINDOWS\system32\SysDllServ.exe
O4 - HKLM\..\RunServices: [Driver Device Update] C:\WINDOWS\system32\SysExec.exe
O4 - HKLM\..\RunServices: [Current Service Validation] C:\WINDOWS\system32\SysDllServ.exe
O4 - HKLM\..\RunServices: [XP Application Socket] C:\WINDOWS\system32\OSAVCfg.exe
O4 - HKLM\..\RunServices: [Antivirus Socket Manager] C:\WINDOWS\system32\WinOCX32.exe
O4 - HKLM\..\RunServices: [Microsoft 32 Manager] C:\WINDOWS\system32\WinExec.exe
O4 - HKLM\..\RunServices: [Secure Server Device] C:\WINDOWS\system32\OSOCX32.exe
O4 - HKLM\..\RunServices: [Win Verification Application] C:\WINDOWS\system32\MSExecCom.exe
O4 - HKLM\..\RunServices: [Win Validation Client] C:\WINDOWS\system32\DBExecCom.exe
O4 - HKLM\..\RunOnce: [Win Verification Application] C:\WINDOWS\system32\MSExecCom.exe
O4 - HKLM\..\RunOnce: [System Verification Application] C:\WINDOWS\system32\MSExecCom.exe
O4 - HKLM\..\RunOnce: [Remote Update Verification] C:\WINDOWS\system32\DBDllServ.exe
O4 - HKLM\..\RunOnce: [Current Service Validation] C:\WINDOWS\system32\SysDllServ.exe
O4 - HKLM\..\RunOnce: [Windows Validation Client] C:\WINDOWS\system32\DBDllCom.exe
O4 - HKLM\..\RunOnce: [Win Validation Client] C:\WINDOWS\system32\DBExecCom.exe
O4 - HKLM\..\RunOnce: [Secure Server 32] C:\WINDOWS\system32\OSOCX32.exe
O4 - HKLM\..\RunOnce: [Microsoft 32 Manager] C:\WINDOWS\system32\WinExec.exe
O4 - HKLM\..\RunOnce: [XP Manager Socket] C:\WINDOWS\system32\OSAVCfg.exe
O4 - HKLM\..\RunOnce: [Registry Client Manager] C:\WINDOWS\system32\MSAVCfg.exe
O4 - HKLM\..\RunOnce: [Driver Device Service] C:\WINDOWS\system32\WinExec.exe
O4 - HKLM\..\RunOnce: [Admin Manager Update] C:\WINDOWS\system32\SysExecServ.exe
O4 - HKCU\..\Run: [Antivirus Socket Manager] C:\WINDOWS\system32\WinOCX32.exe
O4 - HKCU\..\Run: [Remote Update Verification] C:\WINDOWS\system32\DBDllServ.exe
O4 - HKCU\..\Run: [Windows Validation Client] C:\WINDOWS\system32\DBDllCom.exe
O4 - HKCU\..\Run: [Antivirus 32 Manager] C:\WINDOWS\system32\WinOCX32.exe
O4 - HKCU\..\Run: [Registry Client Manager] C:\WINDOWS\system32\MSAVCfg.exe
O4 - HKCU\..\Run: [Driver Device Service] C:\WINDOWS\system32\WinExec.exe
O4 - HKCU\..\Run: [Current Service Validation] C:\WINDOWS\system32\SysDllServ.exe
O4 - HKCU\..\Run: [NT Application Server] C:\WINDOWS\system32\OSAVCfg.exe
O4 - HKCU\..\Run: [XP Manager Socket] C:\WINDOWS\system32\OSAVCfg.exe
O4 - HKCU\..\Run: [System Verification Manager] C:\WINDOWS\system32\MSExecCom.exe
O4 - HKCU\..\Run: [Secure Server 32] C:\WINDOWS\system32\OSOCX32.exe
O4 - HKCU\..\Run: [Microsoft 32 Manager] C:\WINDOWS\system32\WinExec.exe
O4 - HKCU\..\Run: [Secure Server Device] C:\WINDOWS\system32\OSOCX32.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Win Verification Application] C:\WINDOWS\system32\MSExecCom.exe
O4 - HKCU\..\Run: [System Verification Application] C:\WINDOWS\system32\MSExecCom.exe
O4 - HKCU\..\Run: [Win Validation Client] C:\WINDOWS\system32\DBExecCom.exe
O4 - HKCU\..\Run: [Admin Manager Update] C:\WINDOWS\system32\SysExecServ.exe
O4 - HKCU\..\RunServices: [Driver Device Service] C:\WINDOWS\system32\WinExec.exe
O4 - HKCU\..\RunServices: [NT Application Server] C:\WINDOWS\system32\OSAVCfg.exe
O4 - HKCU\..\RunServices: [Remote Update Verification] C:\WINDOWS\system32\DBDllServ.exe
O4 - HKCU\..\RunServices: [Windows Validation Client] C:\WINDOWS\system32\DBDllCom.exe
O4 - HKCU\..\RunServices: [System Verification Manager] C:\WINDOWS\system32\MSExecCom.exe
O4 - HKCU\..\RunServices: [XP Manager Socket] C:\WINDOWS\system32\OSAVCfg.exe
O4 - HKCU\..\RunServices: [Secure Server 32] C:\WINDOWS\system32\OSOCX32.exe
O4 - HKCU\..\RunServices: [Root Update Verification] C:\WINDOWS\system32\MSDllServ.exe
O4 - HKCU\..\RunServices: [Registry Client Manager] C:\WINDOWS\system32\MSAVCfg.exe
O4 - HKCU\..\RunServices: [MS Manager Socket] C:\WINDOWS\system32\OSAV32.exe
O4 - HKCU\..\RunServices: [Antivirus 32 Manager] C:\WINDOWS\system32\WinOCX32.exe
O4 - HKCU\..\RunServices: [Admin Manager Update] C:\WINDOWS\system32\SysExecServ.exe
O4 - HKCU\..\RunServices: [Remote Update Client] C:\WINDOWS\system32\DBDllCom.exe
O4 - HKCU\..\RunServices: [Microsoft Device Service] C:\WINDOWS\system32\WinExec.exe
O4 - HKCU\..\RunServices: [Antivirus Socket Device] C:\WINDOWS\system32\WinOCX32.exe
O4 - HKCU\..\RunServices: [Microsoft 32 Service] C:\WINDOWS\system32\WinExec.exe
O4 - HKCU\..\RunServices: [Firewall Socket Device] C:\WINDOWS\system32\WinOCX32.exe
O4 - HKCU\..\RunServices: [System Verification Application] C:\WINDOWS\system32\MSExecCom.exe
O4 - HKCU\..\RunServices: [Root Service Validation] C:\WINDOWS\system32\DBDllServ.exe
O4 - HKCU\..\RunServices: [Current Manager Validation] C:\WINDOWS\system32\SysDllServ.exe
O4 - HKCU\..\RunServices: [Current Manager Update] C:\WINDOWS\system32\SysDllServ.exe
O4 - HKCU\..\RunServices: [Driver Device Update] C:\WINDOWS\system32\SysExec.exe
O4 - HKCU\..\RunServices: [Current Service Validation] C:\WINDOWS\system32\SysDllServ.exe
O4 - HKCU\..\RunServices: [MS Manager 32] C:\WINDOWS\system32\OSAV32.exe
O4 - HKCU\..\RunServices: [XP Application Socket] C:\WINDOWS\system32\OSAVCfg.exe
O4 - HKCU\..\RunServices: [Antivirus Socket Manager] C:\WINDOWS\system32\WinOCX32.exe
O4 - HKCU\..\RunServices: [Microsoft 32 Manager] C:\WINDOWS\system32\WinExec.exe
O4 - HKCU\..\RunServices: [Secure Server Device] C:\WINDOWS\system32\OSOCX32.exe
O4 - HKCU\..\RunServices: [Win Verification Application] C:\WINDOWS\system32\MSExecCom.exe
O4 - HKCU\..\RunServices: [Win Validation Client] C:\WINDOWS\system32\DBExecCom.exe
O4 - HKCU\..\RunOnce: [Admin Manager Update] C:\WINDOWS\system32\SysExecServ.exe
O4 - HKCU\..\RunOnce: [Windows Validation Client] C:\WINDOWS\system32\DBDllCom.exe
O4 - Global Startup: BigFix.lnk = D:\Marg's Stuff\marg's programs\BigFix.exe
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesau.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesau.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

can someone please tell me how to fix my pc without having to reformat.

email address is [removed].

thnx

Marg
Greetings and welcome to TomCoyote.org!

I want to check some things before beginning any cleaning operations.

Run Hijack This!.

Click on Open Misc Tools section

To the right of Generate Startuplist log, there are two boxes.

Check them both, then click Generate Startuplist log.

"Copy/paste" the startuplist log into this thread.
Hey Micah.

Thanks for your assistance so far.

Here's the info u wanted.

StartupList report, 10/22/2005, 6:47:02 PM
StartupList version: 1.52.2
Started from : C:\DOCUME~1\MARG~1.FRA\LOCALS~1\Temp\Rar$EX01.437\HijackThis.EXE
Detected: Windows XP (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 (6.00.2600.0000)
* Using default options
* Including empty and uninteresting sections
* Showing rarely important sections
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\System32\lexpps.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\WINDOWS\System32\ctfmon.exe
D:\Marg's Stuff\marg's programs\BigFix.exe
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Yahoo!\Messenger\YPager.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\MARG~1.FRA\LOCALS~1\Temp\Rar$EX01.437\HijackThis.exe

————————————————–

Listing of startup folders:

Shell folders Startup:
[C:\Documents and Settings\Marg.FRANKIES_BEAST\Start Menu\Programs\Startup]
*No files*

Shell folders AltStartup:
*Folder not found*

User shell folders Startup:
*Folder not found*

User shell folders AltStartup:
*Folder not found*

Shell folders Common Startup:
[C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup]
BigFix.lnk = D:\Marg's Stuff\marg's programs\BigFix.exe

Shell folders Common AltStartup:
*Folder not found*

User shell folders Common Startup:
*Folder not found*

User shell folders Alternate Common Startup:
*Folder not found*

————————————————–

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

[HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*

[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
*Registry value not found*

[HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

Lexmark X1100 Series = "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
AVG7_CC = C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
Root Update Verification = C:\WINDOWS\system32\DBDllServ.exe

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce

*No values found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

*No values found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

Remote Update Verification = C:\WINDOWS\system32\DBDllServ.exe
System Verification Manager = C:\WINDOWS\system32\MSExecCom.exe
Secure Server 32 = C:\WINDOWS\system32\OSOCX32.exe
Root Update Verification = C:\WINDOWS\system32\DBDllServ.exe
Registry Client Manager = C:\WINDOWS\system32\MSExecCfg.exe
Antivirus Socket Device = C:\WINDOWS\system32\WinOCX32.exe
Firewall Socket Device = C:\WINDOWS\system32\WinOCX32.exe
MS Manager 32 = C:\WINDOWS\system32\OSOCX32.exe
MS Server 32 = C:\WINDOWS\system32\OSOCX32.exe
Antivirus Socket Manager = C:\WINDOWS\system32\WinOCX32.exe
Secure Server Device = C:\WINDOWS\system32\WinOCX32.exe
Win Verification Application = C:\WINDOWS\system32\MSExecCom.exe
Root Service Verification = C:\WINDOWS\system32\DBDllServ.exe
System Client Manager = C:\WINDOWS\system32\MSExecCom.exe

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

*Registry key not found*

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

ctfmon.exe = C:\WINDOWS\System32\ctfmon.exe
System Verification Manager = C:\WINDOWS\system32\MSExecCom.exe
Win Validation Application = C:\WINDOWS\system32\DBExecCom.exe
Win Verification Application = C:\WINDOWS\system32\MSExecCom.exe
Windows Validation Client = C:\WINDOWS\system32\DBExecCom.exe
Windows Update Client = C:\WINDOWS\system32\DBDllCom.exe
Microsoft 32 Manager = C:\WINDOWS\system32\WinExec.exe
NT Application Server = C:\WINDOWS\system32\MSAVCfg.exe
Root Service Validation = C:\WINDOWS\system32\SysDllServ.exe
Root Update Verification = C:\WINDOWS\system32\DBDllServ.exe
Admin Manager Update = C:\WINDOWS\system32\SysExecServ.exe
Current Service Validation = C:\WINDOWS\system32\SysDllServ.exe
Driver Device Service = C:\WINDOWS\system32\SysExec.exe
MS Manager Socket = C:\WINDOWS\system32\OSAVCfg.exe

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

*No values found*

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

*Registry key not found*

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices

Driver Device Service = C:\WINDOWS\system32\SysExec.exe
NT Application Server = C:\WINDOWS\system32\MSAVCfg.exe
Remote Update Verification = C:\WINDOWS\system32\DBDllServ.exe
Windows Validation Client = C:\WINDOWS\system32\DBExecCom.exe
System Verification Manager = C:\WINDOWS\system32\MSExecCom.exe
XP Manager Socket = C:\WINDOWS\system32\OSAVCfg.exe
Secure Server 32 = C:\WINDOWS\system32\OSOCX32.exe
Root Update Verification = C:\WINDOWS\system32\DBDllServ.exe
Registry Client Manager = C:\WINDOWS\system32\MSExecCfg.exe
MS Manager Socket = C:\WINDOWS\system32\OSAVCfg.exe
Antivirus 32 Manager = C:\WINDOWS\system32\WinExec.exe
Admin Manager Update = C:\WINDOWS\system32\SysExecServ.exe
Remote Update Client = C:\WINDOWS\system32\DBDllCom.exe
Microsoft Device Service = C:\WINDOWS\system32\WinExec.exe
Antivirus Socket Device = C:\WINDOWS\system32\WinOCX32.exe
Microsoft 32 Service = C:\WINDOWS\system32\WinExec.exe
Firewall Socket Device = C:\WINDOWS\system32\WinOCX32.exe
System Verification Application = C:\WINDOWS\system32\MSAVCfg.exe
Root Service Validation = C:\WINDOWS\system32\SysDllServ.exe
Current Manager Validation = C:\WINDOWS\system32\SysDllServ.exe
Current Manager Update = C:\WINDOWS\system32\SysDllServ.exe
Driver Device Update = C:\WINDOWS\system32\SysExec.exe
Current Service Validation = C:\WINDOWS\system32\SysDllServ.exe
MS Manager 32 = C:\WINDOWS\system32\OSOCX32.exe
XP Application Socket = C:\WINDOWS\system32\OSAVCfg.exe
Antivirus Socket Manager = C:\WINDOWS\system32\WinOCX32.exe
Microsoft 32 Manager = C:\WINDOWS\system32\WinExec.exe
Secure Server Device = C:\WINDOWS\system32\WinOCX32.exe
Win Verification Application = C:\WINDOWS\system32\MSExecCom.exe
Win Validation Client = C:\WINDOWS\system32\DBExecCom.exe
Root Service Verification = C:\WINDOWS\system32\DBDllServ.exe
System Client Manager = C:\WINDOWS\system32\MSExecCom.exe
Win Validation Application = C:\WINDOWS\system32\DBExecCom.exe
Registry Client Server = C:\WINDOWS\system32\MSAVCfg.exe
Windows Update Client = C:\WINDOWS\system32\DBDllCom.exe

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

*Registry key not found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run

*Registry key not found*

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run

*Registry key not found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

[AutorunsDisabled]
Antivirus Socket Manager = C:\WINDOWS\system32\WinOCX32.exe
Firewall Socket Device = C:\WINDOWS\system32\WinOCX32.exe
Registry Client Manager = C:\WINDOWS\system32\MSExecCfg.exe
Remote Update Verification = C:\WINDOWS\system32\DBDllServ.exe
Root Service Verification = C:\WINDOWS\system32\DBDllServ.exe
Secure Server 32 = C:\WINDOWS\system32\OSOCX32.exe
Secure Server Device = C:\WINDOWS\system32\WinOCX32.exe
System Client Manager = C:\WINDOWS\system32\MSExecCom.exe
System Verification Manager = C:\WINDOWS\system32\MSExecCom.exe
Win Verification Application = C:\WINDOWS\system32\MSExecCom.exe
NeroFilterCheck = C:\WINDOWS\system32\NeroCheck.exe
MS Manager 32 = C:\WINDOWS\system32\OSOCX32.exe
SunJavaUpdateSched = C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe

[OptionalComponents]
*No values found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

[AutorunsDisabled]
Admin Manager Update = C:\WINDOWS\system32\SysExecServ.exe
Antivirus 32 Manager = C:\WINDOWS\system32\WinExec.exe
Antivirus Socket Manager = C:\WINDOWS\system32\WinOCX32.exe
Current Service Validation = C:\WINDOWS\system32\SysDllServ.exe
Driver Device Service = C:\WINDOWS\system32\SysExec.exe
Firewall Socket Device = C:\WINDOWS\system32\WinOCX32.exe
Microsoft 32 Manager = C:\WINDOWS\system32\WinExec.exe
MS Manager Socket = C:\WINDOWS\system32\OSAVCfg.exe
NT Application Server = C:\WINDOWS\system32\MSAVCfg.exe
Registry Client Manager = C:\WINDOWS\system32\MSExecCfg.exe
Root Service Validation = C:\WINDOWS\system32\SysDllServ.exe
Root Service Verification = C:\WINDOWS\system32\DBDllServ.exe
Secure Server Device = C:\WINDOWS\system32\WinOCX32.exe
System Verification Application = C:\WINDOWS\system32\MSAVCfg.exe
System Client Manager = C:\WINDOWS\system32\MSExecCom.exe
Microsoft Device Service = C:\WINDOWS\system32\WinExec.exe
MS Manager 32 = C:\WINDOWS\system32\OSOCX32.exe
Registry Client Server = C:\WINDOWS\system32\MSAVCfg.exe
Remote Update Verification = C:\WINDOWS\system32\DBDllServ.exe
Secure Server 32 = C:\WINDOWS\system32\OSOCX32.exe

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*Registry key not found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*

————————————————–

File association entry for .EXE:
HKEY_CLASSES_ROOT\exefile\shell\open\command

(Default) = "%1" %*

————————————————–

File association entry for .COM:
HKEY_CLASSES_ROOT\comfile\shell\open\command

(Default) = "%1" %*

————————————————–

File association entry for .BAT:
HKEY_CLASSES_ROOT\batfile\shell\open\command

(Default) = "%1" %*

————————————————–

File association entry for .PIF:
HKEY_CLASSES_ROOT\piffile\shell\open\command

(Default) = "%1" %*

————————————————–

File association entry for .SCR:
HKEY_CLASSES_ROOT\scrfile\shell\open\command

(Default) = "%1" /S

————————————————–

File association entry for .HTA:
HKEY_CLASSES_ROOT\htafile\shell\open\command

(Default) = C:\WINDOWS\System32\mshta.exe "%1" %*

————————————————–

File association entry for .TXT:
HKEY_CLASSES_ROOT\txtfile\shell\open\command

(Default) = %SystemRoot%\system32\NOTEPAD.EXE %1

————————————————–

Enumerating Active Setup stub paths:
HKLM\Software\Microsoft\Active Setup\Installed Components
(* = disabled by HKCU twin)

[>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] *
StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP

[{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\mplayer2.inf,PerUserStub.NT

[{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] *
StubPath = %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll

[{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install

[{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT

[{5945c046-1e7d-11d1-bc44-00c04fd912be}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.Install.PerUser

[{6BF52A52-394A-11d3-B153-00C04F79FAA6}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub

[{7790769C-0471-11d2-AF11-00C04FA35D02}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install

[{89820200-ECBD-11cf-8B85-00AA005B4340}] *
StubPath = regsvr32.exe /s /n /i:U shell32.dll

[{89820200-ECBD-11cf-8B85-00AA005B4383}] *
StubPath = %SystemRoot%\system32\ie4uinit.exe

[{ACC563BC-4266-43f0-B6ED-9D38C4202C7E}] *
StubPath = rundll32 iesetup.dll,IEAccessUserInst

————————————————–

Enumerating ICQ Agent Autostart apps:
HKCU\Software\Mirabilis\ICQ\Agent\Apps

*Registry key not found*

————————————————–

Load/Run keys from C:\WINDOWS\WIN.INI:

load=*INI section not found*
run=*INI section not found*

Load/Run keys from Registry:

HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows: load=
HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=

————————————————–

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\System32\logon.scr
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*

————————————————–

Checking for EXPLORER.EXE instances:

C:\WINDOWS\Explorer.exe: PRESENT!

C:\Explorer.exe: not present
C:\WINDOWS\Explorer\Explorer.exe: not present
C:\WINDOWS\System\Explorer.exe: not present
C:\WINDOWS\System32\Explorer.exe: not present
C:\WINDOWS\Command\Explorer.exe: not present
C:\WINDOWS\Fonts\Explorer.exe: not present

————————————————–

Checking for superhidden extensions:

.lnk: HIDDEN! (arrow overlay: yes)
.pif: HIDDEN! (arrow overlay: yes)
.exe: not hidden
.com: not hidden
.bat: not hidden
.hta: not hidden
.scr: not hidden
.shs: HIDDEN!
.shb: HIDDEN!
.vbs: not hidden
.vbe: not hidden
.wsh: not hidden
.scf: HIDDEN! (arrow overlay: NO!)
.url: HIDDEN! (arrow overlay: yes)
.js: not hidden
.jse: not hidden

————————————————–

Verifying REGEDIT.EXE integrity:

- Regedit.exe found in C:\WINDOWS
- .reg open command is normal (regedit.exe %1)
- Company name OK: 'Microsoft Corporation'
- Original filename OK: 'REGEDIT.EXE'
- File description: 'Registry Editor'

Registry check passed

————————————————–

Enumerating Browser Helper Objects:

*No BHO's found*

————————————————–

Enumerating Task Scheduler jobs:

*No jobs found*

————————————————–

Enumerating Download Program Files:

[HouseCall Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\xscan60.ocx
CODEBASE = http://housecall60.trendmicro.com/housecall/xscan60.cab

[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\system32\Macromed\Director\SwDir.dll
CODEBASE = http://download.macromedia.com/pub/shockwa…director/sw.cab

[YInstStarter Class]
InProcServer32 = C:\Program Files\Yahoo!\Common\yinsthelper.dll
CODEBASE = C:\Program Files\Yahoo!\Common\yinsthelper.dll

[Java Plug-in 1.5.0_04]
InProcServer32 = C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
CODEBASE = http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab

[Java Plug-in 1.5.0_04]
InProcServer32 = C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
CODEBASE = http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\System32\Macromed\Flash\Flash8.ocx
CODEBASE = http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab

————————————————–

Enumerating Winsock LSP files:

NameSpace #1: C:\WINDOWS\System32\mswsock.dll
NameSpace #2: C:\WINDOWS\System32\winrnr.dll
NameSpace #3: C:\WINDOWS\System32\mswsock.dll
Protocol #1: C:\WINDOWS\system32\mswsock.dll
Protocol #2: C:\WINDOWS\system32\mswsock.dll
Protocol #3: C:\WINDOWS\system32\mswsock.dll
Protocol #4: C:\WINDOWS\system32\rsvpsp.dll
Protocol #5: C:\WINDOWS\system32\rsvpsp.dll
Protocol #6: C:\WINDOWS\system32\mswsock.dll
Protocol #7: C:\WINDOWS\system32\mswsock.dll
Protocol #8: C:\WINDOWS\system32\mswsock.dll
Protocol #9: C:\WINDOWS\system32\mswsock.dll
Protocol #10: C:\WINDOWS\system32\mswsock.dll
Protocol #11: C:\WINDOWS\system32\mswsock.dll
Protocol #12: C:\WINDOWS\system32\mswsock.dll
Protocol #13: C:\WINDOWS\system32\mswsock.dll
Protocol #14: C:\WINDOWS\system32\mswsock.dll
Protocol #15: C:\WINDOWS\system32\mswsock.dll

————————————————–

Enumerating Windows NT/2000/XP services

Intel® 82801DB/DBM Audio Driver Service (WDM): system32\drivers\ac97ich4.sys (manual start)
Microsoft ACPI Driver: System32\DRIVERS\ACPI.sys (system)
Microsoft Kernel Acoustic Echo Canceller: system32\drivers\aec.sys (manual start)
AFD Networking Support Environment: \SystemRoot\System32\drivers\afd.sys (autostart)
Intel AGP Bus Filter: System32\DRIVERS\agp440.sys (system)
Alerter: %SystemRoot%\System32\svchost.exe -k LocalService (manual start)
Application Layer Gateway Service: %SystemRoot%\System32\alg.exe (manual start)
AnyDVD: System32\Drivers\AnyDVD.sys (manual start)
Application Management: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
RAS Asynchronous Media Driver: System32\DRIVERS\asyncmac.sys (manual start)
Standard IDE/ESDI Hard Disk Controller: System32\DRIVERS\atapi.sys (system)
ATM ARP Client Protocol: System32\DRIVERS\atmarpc.sys (manual start)
Windows Audio: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Audio Stub Driver: System32\DRIVERS\audstub.sys (manual start)
AVG7 Alert Manager Server: C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe (autostart)
AVG7 Kernel: \SystemRoot\System32\Drivers\avg7core.sys (system)
AVG7 Wrap Driver: \SystemRoot\System32\Drivers\avg7rsw.sys (system)
AVG7 Rezident Driver: \SystemRoot\System32\Drivers\avg7rsxp.sys (system)
AVG7 Update Service: C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe (autostart)
Background Intelligent Transfer Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Computer Browser: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
CD-ROM Driver: System32\DRIVERS\cdrom.sys (system)
Indexing Service: %SystemRoot%\system32\cisvc.exe (manual start)
ClipBook: %SystemRoot%\system32\clipsrv.exe (manual start)
COM+ System Application: C:\WINDOWS\System32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} (manual start)
Cryptographic Services: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
DHCP Client: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Disk Driver: System32\DRIVERS\disk.sys (system)
Logical Disk Manager Administrative Service: %SystemRoot%\System32\dmadmin.exe /com (manual start)
dmboot: System32\drivers\dmboot.sys (disabled)
Logical Disk Manager Driver: System32\DRIVERS\dmio.sys (system)
Logical Disk Manager: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Microsoft Kernel DLS Syntheiszer: system32\drivers\DMusic.sys (manual start)
DNS Client: %SystemRoot%\System32\svchost.exe -k NetworkService (autostart)
Microsoft Kernel DRM Audio Descrambler: system32\drivers\drmkaud.sys (manual start)
ElbyCDIO Driver: System32\Drivers\ElbyCDIO.sys (autostart)
ElbyDelay: System32\Drivers\ElbyDelay.sys (manual start)
Error Reporting Service: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Event Log: %SystemRoot%\system32\services.exe (autostart)
COM+ Event System: C:\WINDOWS\System32\svchost.exe -k netsvcs (manual start)
Fast User Switching Compatibility: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Floppy Disk Controller Driver: System32\DRIVERS\fdc.sys (manual start)
Floppy Disk Driver: System32\DRIVERS\flpydisk.sys (manual start)
Volume Manager Driver: System32\DRIVERS\ftdisk.sys (system)
Game Port Enumerator: System32\DRIVERS\gameenum.sys (manual start)
Generic Packet Classifier: System32\DRIVERS\msgpc.sys (manual start)
Help and Support: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Human Interface Device Access: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
i8042 Keyboard and PS/2 Mouse Port Driver: System32\DRIVERS\i8042prt.sys (system)
IMAPI CD-Burning COM Service: C:\WINDOWS\System32\imapi.exe (manual start)
IP Traffic Filter Driver: System32\DRIVERS\ipfltdrv.sys (manual start)
IP in IP Tunnel Driver: System32\DRIVERS\ipinip.sys (manual start)
IP Network Address Translator: System32\DRIVERS\ipnat.sys (manual start)
IPSEC driver: System32\DRIVERS\ipsec.sys (system)
IR Enumerator Service: System32\DRIVERS\irenum.sys (manual start)
PnP ISA/EISA Bus Driver: System32\DRIVERS\isapnp.sys (system)
Keyboard Class Driver: System32\DRIVERS\kbdclass.sys (system)
Microsoft Kernel Wave Audio Mixer: system32\drivers\kmixer.sys (manual start)
Server: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Workstation: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
LexBce Server: C:\WINDOWS\system32\LEXBCES.EXE (autostart)
TCP/IP NetBIOS Helper: %SystemRoot%\System32\svchost.exe -k LocalService (autostart)
Machine Debug Manager: "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE" (autostart)
Messenger: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
NetMeeting Remote Desktop Sharing: C:\WINDOWS\System32\mnmsrvc.exe (manual start)
Mouse Class Driver: System32\DRIVERS\mouclass.sys (system)
WebDav Client Redirector: System32\DRIVERS\mrxdav.sys (manual start)
MRXSMB: System32\DRIVERS\mrxsmb.sys (system)
Distributed Transaction Coordinator: C:\WINDOWS\System32\msdtc.exe (manual start)
Windows Installer: C:\WINDOWS\System32\msiexec.exe /V (manual start)
Microsoft Streaming Service Proxy: system32\drivers\MSKSSRV.sys (manual start)
Microsoft Streaming Clock Proxy: system32\drivers\MSPCLOCK.sys (manual start)
Microsoft Streaming Quality Manager Proxy: system32\drivers\MSPQM.sys (manual start)
Microsoft MPU-401 MIDI UART Driver: system32\drivers\msmpu401.sys (manual start)
Compaq Ethernet or Fast Ethernet NIC Driver: System32\DRIVERS\n100325.sys (manual start)
Remote Access NDIS TAPI Driver: System32\DRIVERS\ndistapi.sys (manual start)
NDIS Usermode I/O Protocol: System32\DRIVERS\ndisuio.sys (manual start)
Remote Access NDIS WAN Driver: System32\DRIVERS\ndiswan.sys (manual start)
NetBIOS Interface: System32\DRIVERS\netbios.sys (system)
NetBios over Tcpip: System32\DRIVERS\netbt.sys (system)
Network DDE: %SystemRoot%\system32\netdde.exe (manual start)
Network DDE DSDM: %SystemRoot%\system32\netdde.exe (manual start)
Net Logon: %SystemRoot%\System32\lsass.exe (manual start)
Network Connections: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Network Location Awareness (NLA): %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
NT LM Security Support Provider: %SystemRoot%\System32\lsass.exe (manual start)
Removable Storage: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
IPX Traffic Filter Driver: System32\DRIVERS\nwlnkflt.sys (manual start)
IPX Traffic Forwarder Driver: System32\DRIVERS\nwlnkfwd.sys (manual start)
Office Source Engine: C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (manual start)
Parallel port driver: System32\DRIVERS\parport.sys (manual start)
PCI Bus Driver: System32\DRIVERS\pci.sys (system)
PCIIde: System32\DRIVERS\pciide.sys (system)
Plug and Play: %SystemRoot%\system32\services.exe (autostart)
IPSEC Services: %SystemRoot%\System32\lsass.exe (autostart)
WAN Miniport (PPTP): System32\DRIVERS\raspptp.sys (manual start)
Processor Driver: System32\DRIVERS\processr.sys (system)
Protected Storage: %SystemRoot%\system32\lsass.exe (autostart)
QoS Packet Scheduler: System32\DRIVERS\psched.sys (manual start)
Direct Parallel Link Driver: System32\DRIVERS\ptilink.sys (manual start)
Remote Access Auto Connection Driver: System32\DRIVERS\rasacd.sys (system)
Remote Access Auto Connection Manager: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
WAN Miniport (L2TP): System32\DRIVERS\rasl2tp.sys (manual start)
Remote Access Connection Manager: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Remote Access PPPOE Driver: System32\DRIVERS\raspppoe.sys (manual start)
Direct Parallel: System32\DRIVERS\raspti.sys (manual start)
Rdbss: System32\DRIVERS\rdbss.sys (system)
RDPCDD: System32\DRIVERS\RDPCDD.sys (system)
Terminal Server Device Redirector Driver: System32\DRIVERS\rdpdr.sys (manual start)
Remote Desktop Help Session Manager: C:\WINDOWS\system32\sessmgr.exe (manual start)
Digital CD Audio Playback Filter Driver: System32\DRIVERS\redbook.sys (system)
Routing and Remote Access: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
Remote Registry: %SystemRoot%\system32\svchost.exe -k LocalService (autostart)
Remote Procedure Call (RPC) Locator: %SystemRoot%\System32\locator.exe (manual start)
Remote Procedure Call (RPC): %SystemRoot%\system32\svchost -k rpcss (autostart)
QoS RSVP: %SystemRoot%\System32\rsvp.exe (manual start)
Security Accounts Manager: %SystemRoot%\system32\lsass.exe (autostart)
Smart Card Helper: %SystemRoot%\System32\SCardSvr.exe (manual start)
Smart Card: %SystemRoot%\System32\SCardSvr.exe (manual start)
Task Scheduler: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Secdrv: System32\DRIVERS\secdrv.sys (manual start)
Secondary Logon: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
System Event Notification: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Serenum Filter Driver: System32\DRIVERS\serenum.sys (manual start)
Serial port driver: System32\DRIVERS\serial.sys (system)
Internet Connection Firewall (ICF) / Internet Connection Sharing (ICS): %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Shell Hardware Detection: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Microsoft Kernel Audio Splitter: system32\drivers\splitter.sys (manual start)
Print Spooler: %SystemRoot%\system32\spoolsv.exe (autostart)
System Restore Filter Driver: \SystemRoot\System32\DRIVERS\sr.sys (disabled)
System Restore Service: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Srv: System32\DRIVERS\srv.sys (manual start)
SSDP Discovery Service: %SystemRoot%\System32\svchost.exe -k LocalService (manual start)
Windows Image Acquisition (WIA): %SystemRoot%\System32\svchost.exe -k imgsvc (autostart)
Software Bus Driver: System32\DRIVERS\swenum.sys (manual start)
Microsoft Kernel GS Wavetable Synthesizer: system32\drivers\swmidi.sys (manual start)
MS Software Shadow Copy Provider: C:\WINDOWS\System32\dllhost.exe /Processid:{5362E545-7BEF-47CB-B01C-2CA4CD4E6C29} (manual start)
Microsoft Kernel System Audio Device: system32\drivers\sysaudio.sys (manual start)
Performance Logs and Alerts: %SystemRoot%\system32\smlogsvc.exe (manual start)
Telephony: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
TCP/IP Protocol Driver: System32\DRIVERS\tcpip.sys (system)
Terminal Device Driver: System32\DRIVERS\termdd.sys (system)
Terminal Services: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Themes: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Telnet: C:\WINDOWS\System32\tlntsvr.exe (manual start)
Distributed Link Tracking Client: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Microcode Update Driver: System32\DRIVERS\update.sys (manual start)
Universal Plug and Play Device Host: %SystemRoot%\System32\svchost.exe -k LocalService (manual start)
Uninterruptible Power Supply: %SystemRoot%\System32\ups.exe (manual start)
Microsoft USB Standard Hub Driver: System32\DRIVERS\usbhub.sys (manual start)
Microsoft USB PRINTER Class: System32\DRIVERS\usbprint.sys (manual start)
USB Scanner Driver: System32\DRIVERS\usbscan.sys (manual start)
USB Mass Storage Driver: System32\DRIVERS\USBSTOR.SYS (manual start)
Microsoft USB Universal Host Controller Miniport Driver: System32\DRIVERS\usbuhci.sys (manual start)
Texas Instruments AR7D01 DSL Router: System32\DRIVERS\usb8023.sys (manual start)
VgaSave: \SystemRoot\System32\drivers\vga.sys (system)
Volume Shadow Copy: %SystemRoot%\System32\vssvc.exe (manual start)
Windows Time: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Remote Access IP ARP Driver: System32\DRIVERS\wanarp.sys (manual start)
Microsoft WINMM WDM Audio Compatibility Driver: system32\drivers\wdmaud.sys (manual start)
WebClient: %SystemRoot%\System32\svchost.exe -k LocalService (autostart)
Windows Management Instrumentation: %systemroot%\system32\svchost.exe -k netsvcs (autostart)
Portable Media Serial Number: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Windows Management Instrumentation Driver Extensions: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
WMI Performance Adapter: C:\WINDOWS\System32\wbem\wmiapsrv.exe (manual start)
Automatic Updates: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Wireless Zero Configuration: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)


————————————————–

Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*

Windows NT checkdisk command:
BootExecute = autocheck autochk *

Windows NT 'Wininit.ini':
PendingFileRenameOperations: *Registry value not found*

————————————————–

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: *Registry key not found*
SysTray: C:\WINDOWS\System32\stobject.dll

————————————————–
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

*Registry key not found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

*Registry key not found*

————————————————–

End of report, 35,561 bytes
Report generated in 0.719 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only


someone tried to assist me last night and I did something in a similar vein to the above, but the pop-up box advising runtime error 70 continues to come up. I used AVG anti virus and found 5044 virus's. primarily all Worm/VG.DG. I'm using the Heal button as opposed to the 'delete' or 'move to vault' options. Would you suggest that is the right thing to do?

Thanks again

marg
Please make a PERMANANT folder for Hijack This!

Important: Create a folder on the C: drive called C:\HJT.
You can do this by going to My Computer (Windows key+e) then double click on C: then right click and select New then Folder and name it HJT. MOVE (drag-and-drop) HijackThis into this folder.

If required a tutorial is here = Hijackthis Folder Tutorial

Download Killbox from here:

Killbox.zip

Unzip it, but don't run it yet.

Copy the file names in the quote box below to the clipboard by highlighting them and pressing
C (hold the key down, then press C):

c:\windows\system32\dbdllcom.exe
c:\windows\system32\dbdllserv.exe
c:\windows\system32\dbexeccom.exe
c:\windows\system32\msavcfg.exe
c:\windows\system32\msdllserv.exe
c:\windows\system32\msexeccom.exe
c:\windows\system32\osav32.exe
c:\windows\system32\osavcfg.exe
c:\windows\system32\osocx32.exe
c:\windows\system32\sysdllserv.exe
c:\windows\system32\sysexec.exe
c:\windows\system32\sysexecserv.exe
c:\windows\system32\winexec.exe
c:\windows\system32\winocx32.exe


CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

O4 - HKLM\..\Run: [Antivirus Socket Manager] C:\WINDOWS\system32\WinOCX32.exe

O4 - HKLM\..\Run: [Remote Update Verification] C:\WINDOWS\system32\DBDllServ.exe

O4 - HKLM\..\Run: [Windows Validation Client] C:\WINDOWS\system32\DBDllCom.exe

O4 - HKLM\..\Run: [Antivirus 32 Manager] C:\WINDOWS\system32\WinOCX32.exe

O4 - HKLM\..\Run: [Registry Client Manager] C:\WINDOWS\system32\MSAVCfg.exe

O4 - HKLM\..\Run: [Driver Device Service] C:\WINDOWS\system32\WinExec.exe

O4 - HKLM\..\Run: [Current Service Validation] C:\WINDOWS\system32\SysDllServ.exe

O4 - HKLM\..\Run: [NT Application Server] C:\WINDOWS\system32\OSAVCfg.exe

O4 - HKLM\..\Run: [XP Manager Socket] C:\WINDOWS\system32\OSAVCfg.exe

O4 - HKLM\..\Run: [System Verification Manager] C:\WINDOWS\system32\MSExecCom.exe

O4 - HKLM\..\Run: [Secure Server 32] C:\WINDOWS\system32\OSOCX32.exe

O4 - HKLM\..\Run: [Microsoft 32 Manager] C:\WINDOWS\system32\WinExec.exe

O4 - HKLM\..\Run: [Secure Server Device] C:\WINDOWS\system32\OSOCX32.exe

O4 - HKLM\..\Run: [Win Verification Application] C:\WINDOWS\system32\MSExecCom.exe

O4 - HKLM\..\Run: [System Verification Application] C:\WINDOWS\system32\MSExecCom.exe

O4 - HKLM\..\Run: [Win Validation Client] C:\WINDOWS\system32\DBExecCom.exe

O4 - HKLM\..\Run: [Admin Manager Update] C:\WINDOWS\system32\SysExecServ.exe

O4 - HKLM\..\RunServices: [Driver Device Service] C:\WINDOWS\system32\WinExec.exe

O4 - HKLM\..\RunServices: [NT Application Server] C:\WINDOWS\system32\OSAVCfg.exe

O4 - HKLM\..\RunServices: [Remote Update Verification] C:\WINDOWS\system32\DBDllServ.exe

O4 - HKLM\..\RunServices: [Windows Validation Client] C:\WINDOWS\system32\DBDllCom.exe

O4 - HKLM\..\RunServices: [System Verification Manager] C:\WINDOWS\system32\MSExecCom.exe

O4 - HKLM\..\RunServices: [XP Manager Socket] C:\WINDOWS\system32\OSAVCfg.exe

O4 - HKLM\..\RunServices: [Secure Server 32] C:\WINDOWS\system32\OSOCX32.exe

O4 - HKLM\..\RunServices: [Root Update Verification] C:\WINDOWS\system32\MSDllServ.exe

O4 - HKLM\..\RunServices: [Registry Client Manager] C:\WINDOWS\system32\MSAVCfg.exe

O4 - HKLM\..\RunServices: [MS Manager Socket] C:\WINDOWS\system32\OSAV32.exe

O4 - HKLM\..\RunServices: [Antivirus 32 Manager] C:\WINDOWS\system32\WinOCX32.exe

O4 - HKLM\..\RunServices: [Admin Manager Update] C:\WINDOWS\system32\SysExecServ.exe

O4 - HKLM\..\RunServices: [Remote Update Client] C:\WINDOWS\system32\DBDllCom.exe

O4 - HKLM\..\RunServices: [Microsoft Device Service] C:\WINDOWS\system32\WinExec.exe

O4 - HKLM\..\RunServices: [Antivirus Socket Device] C:\WINDOWS\system32\WinOCX32.exe

O4 - HKLM\..\RunServices: [Microsoft 32 Service] C:\WINDOWS\system32\WinExec.exe

O4 - HKLM\..\RunServices: [Firewall Socket Device] C:\WINDOWS\system32\WinOCX32.exe

O4 - HKLM\..\RunServices: [System Verification Application] C:\WINDOWS\system32\MSExecCom.exe

O4 - HKLM\..\RunServices: [Root Service Validation] C:\WINDOWS\system32\DBDllServ.exe

O4 - HKLM\..\RunServices: [MS Manager 32] C:\WINDOWS\system32\OSAV32.exe

O4 - HKLM\..\RunServices: [MS Server 32] C:\WINDOWS\system32\OSOCX32.exe

O4 - HKLM\..\RunServices: [Current Manager Validation] C:\WINDOWS\system32\SysDllServ.exe

O4 - HKLM\..\RunServices: [Current Manager Update] C:\WINDOWS\system32\SysDllServ.exe

O4 - HKLM\..\RunServices: [Driver Device Update] C:\WINDOWS\system32\SysExec.exe

O4 - HKLM\..\RunServices: [Current Service Validation] C:\WINDOWS\system32\SysDllServ.exe

O4 - HKLM\..\RunServices: [XP Application Socket] C:\WINDOWS\system32\OSAVCfg.exe

O4 - HKLM\..\RunServices: [Antivirus Socket Manager] C:\WINDOWS\system32\WinOCX32.exe

O4 - HKLM\..\RunServices: [Microsoft 32 Manager] C:\WINDOWS\system32\WinExec.exe

O4 - HKLM\..\RunServices: [Secure Server Device] C:\WINDOWS\system32\OSOCX32.exe

O4 - HKLM\..\RunServices: [Win Verification Application] C:\WINDOWS\system32\MSExecCom.exe

O4 - HKLM\..\RunServices: [Win Validation Client] C:\WINDOWS\system32\DBExecCom.exe

O4 - HKLM\..\RunOnce: [Win Verification Application] C:\WINDOWS\system32\MSExecCom.exe

O4 - HKLM\..\RunOnce: [System Verification Application] C:\WINDOWS\system32\MSExecCom.exe

O4 - HKLM\..\RunOnce: [Remote Update Verification] C:\WINDOWS\system32\DBDllServ.exe

O4 - HKLM\..\RunOnce: [Current Service Validation] C:\WINDOWS\system32\SysDllServ.exe

O4 - HKLM\..\RunOnce: [Windows Validation Client] C:\WINDOWS\system32\DBDllCom.exe

O4 - HKLM\..\RunOnce: [Win Validation Client] C:\WINDOWS\system32\DBExecCom.exe

O4 - HKLM\..\RunOnce: [Secure Server 32] C:\WINDOWS\system32\OSOCX32.exe

O4 - HKLM\..\RunOnce: [Microsoft 32 Manager] C:\WINDOWS\system32\WinExec.exe

O4 - HKLM\..\RunOnce: [XP Manager Socket] C:\WINDOWS\system32\OSAVCfg.exe

O4 - HKLM\..\RunOnce: [Registry Client Manager] C:\WINDOWS\system32\MSAVCfg.exe

O4 - HKLM\..\RunOnce: [Driver Device Service] C:\WINDOWS\system32\WinExec.exe

O4 - HKLM\..\RunOnce: [Admin Manager Update] C:\WINDOWS\system32\SysExecServ.exe

O4 - HKCU\..\Run: [Antivirus Socket Manager] C:\WINDOWS\system32\WinOCX32.exe

O4 - HKCU\..\Run: [Remote Update Verification] C:\WINDOWS\system32\DBDllServ.exe

O4 - HKCU\..\Run: [Windows Validation Client] C:\WINDOWS\system32\DBDllCom.exe

O4 - HKCU\..\Run: [Antivirus 32 Manager] C:\WINDOWS\system32\WinOCX32.exe

O4 - HKCU\..\Run: [Registry Client Manager] C:\WINDOWS\system32\MSAVCfg.exe

O4 - HKCU\..\Run: [Driver Device Service] C:\WINDOWS\system32\WinExec.exe

O4 - HKCU\..\Run: [Current Service Validation] C:\WINDOWS\system32\SysDllServ.exe

O4 - HKCU\..\Run: [NT Application Server] C:\WINDOWS\system32\OSAVCfg.exe

O4 - HKCU\..\Run: [XP Manager Socket] C:\WINDOWS\system32\OSAVCfg.exe

O4 - HKCU\..\Run: [System Verification Manager] C:\WINDOWS\system32\MSExecCom.exe

O4 - HKCU\..\Run: [Secure Server 32] C:\WINDOWS\system32\OSOCX32.exe

O4 - HKCU\..\Run: [Microsoft 32 Manager] C:\WINDOWS\system32\WinExec.exe

O4 - HKCU\..\Run: [Secure Server Device] C:\WINDOWS\system32\OSOCX32.exe

O4 - HKCU\..\Run: [Win Verification Application] C:\WINDOWS\system32\MSExecCom.exe

O4 - HKCU\..\Run: [System Verification Application] C:\WINDOWS\system32\MSExecCom.exe

O4 - HKCU\..\Run: [Win Validation Client] C:\WINDOWS\system32\DBExecCom.exe

O4 - HKCU\..\Run: [Admin Manager Update] C:\WINDOWS\system32\SysExecServ.exe

O4 - HKCU\..\RunServices: [Driver Device Service] C:\WINDOWS\system32\WinExec.exe

O4 - HKCU\..\RunServices: [NT Application Server] C:\WINDOWS\system32\OSAVCfg.exe

O4 - HKCU\..\RunServices: [Remote Update Verification] C:\WINDOWS\system32\DBDllServ.exe

O4 - HKCU\..\RunServices: [Windows Validation Client] C:\WINDOWS\system32\DBDllCom.exe

O4 - HKCU\..\RunServices: [System Verification Manager] C:\WINDOWS\system32\MSExecCom.exe

O4 - HKCU\..\RunServices: [XP Manager Socket] C:\WINDOWS\system32\OSAVCfg.exe

O4 - HKCU\..\RunServices: [Secure Server 32] C:\WINDOWS\system32\OSOCX32.exe

O4 - HKCU\..\RunServices: [Root Update Verification] C:\WINDOWS\system32\MSDllServ.exe

O4 - HKCU\..\RunServices: [Registry Client Manager] C:\WINDOWS\system32\MSAVCfg.exe

O4 - HKCU\..\RunServices: [MS Manager Socket] C:\WINDOWS\system32\OSAV32.exe

O4 - HKCU\..\RunServices: [Antivirus 32 Manager] C:\WINDOWS\system32\WinOCX32.exe

O4 - HKCU\..\RunServices: [Admin Manager Update] C:\WINDOWS\system32\SysExecServ.exe

O4 - HKCU\..\RunServices: [Remote Update Client] C:\WINDOWS\system32\DBDllCom.exe

O4 - HKCU\..\RunServices: [Microsoft Device Service] C:\WINDOWS\system32\WinExec.exe

O4 - HKCU\..\RunServices: [Antivirus Socket Device] C:\WINDOWS\system32\WinOCX32.exe

O4 - HKCU\..\RunServices: [Microsoft 32 Service] C:\WINDOWS\system32\WinExec.exe

O4 - HKCU\..\RunServices: [Firewall Socket Device] C:\WINDOWS\system32\WinOCX32.exe

O4 - HKCU\..\RunServices: [System Verification Application] C:\WINDOWS\system32\MSExecCom.exe

O4 - HKCU\..\RunServices: [Root Service Validation] C:\WINDOWS\system32\DBDllServ.exe

O4 - HKCU\..\RunServices: [Current Manager Validation] C:\WINDOWS\system32\SysDllServ.exe

O4 - HKCU\..\RunServices: [Current Manager Update] C:\WINDOWS\system32\SysDllServ.exe

O4 - HKCU\..\RunServices: [Driver Device Update] C:\WINDOWS\system32\SysExec.exe

O4 - HKCU\..\RunServices: [Current Service Validation] C:\WINDOWS\system32\SysDllServ.exe

O4 - HKCU\..\RunServices: [MS Manager 32] C:\WINDOWS\system32\OSAV32.exe

O4 - HKCU\..\RunServices: [XP Application Socket] C:\WINDOWS\system32\OSAVCfg.exe

O4 - HKCU\..\RunServices: [Antivirus Socket Manager] C:\WINDOWS\system32\WinOCX32.exe

O4 - HKCU\..\RunServices: [Microsoft 32 Manager] C:\WINDOWS\system32\WinExec.exe

O4 - HKCU\..\RunServices: [Secure Server Device] C:\WINDOWS\system32\OSOCX32.exe

O4 - HKCU\..\RunServices: [Win Verification Application] C:\WINDOWS\system32\MSExecCom.exe

O4 - HKCU\..\RunServices: [Win Validation Client] C:\WINDOWS\system32\DBExecCom.exe

O4 - HKCU\..\RunOnce: [Admin Manager Update] C:\WINDOWS\system32\SysExecServ.exe

O4 - HKCU\..\RunOnce: [Windows Validation Client] C:\WINDOWS\system32\DBDllCom.exe

Then click "Fix checked" and close Hijack This!.

Run Killbox, click File (in the upper left of Killbox), and choose "Paste from Clipboard".

Click the red dot with the white X in it, in the upper right of Killbox, then click "Yes", and "Yes" again.

After the reboot, "copy/paste" a new Hijack This! (normal) log file into this thread. :)
Hey Micah,

I want to thank you again. I rebooted the system and so far so good. It is coming up much MUCH quicker than it has done recently. He's a new copy of hijack this as you requested. Can you have a quick look and let me know if there is anything else i should do. Also I've noticed that i've got lots of Limewire stuff happening on my pc even tho i've uninstalled it with the assistance of registryfix. Can you tell me why that might be happening?

Logfile of HijackThis v1.99.1
Scan saved at 9:05:54 PM, on 10/23/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\System32\ctfmon.exe
D:\Marg's Stuff\marg's programs\BigFix.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\DOCUME~1\MARG~1.FRA\LOCALS~1\Temp\Rar$EX01.375\HijackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.eftel.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.com/search/search_frame.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.icq.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.eftel.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.eftel.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.eftel.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: BigFix.lnk = D:\Marg's Stuff\marg's programs\BigFix.exe
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesau.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesau.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE


Thanks again

Marg
Please make a PERMANANT folder for Hijack This!

Important: Create a folder on the C: drive called C:\HJT.
You can do this by going to My Computer (Windows key+e) then double click on C: then right click and select New then Folder and name it HJT. MOVE (drag-and-drop) HijackThis into this folder.

If required a tutorial is here = Hijackthis Folder Tutorial

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe

Then click "Fix checked" and close Hijack This!.

Reboot in "safe" mode.

Delete all of the following noted (in red) file(s)/FOLDER(s) you can find:

c:\program files\limewire <— FOLDER

Some malware files may be "hidden".
Be sure to show hidden files when looking for these file(s) and/or folder(s).

Reboot in normal mode and "copy/paste" a new log file into this thread. :)

That should stop Limewire.
Micah,

Alls well that ends well… thank you.

here's the final paste… if you see anything else untoward i'm happy to listen to your advice.

Ta

Logfile of HijackThis v1.99.1
Scan saved at 10:45:45 PM, on 10/23/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\System32\ctfmon.exe
D:\Marg's Stuff\marg's programs\BigFix.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\MARG~1.FRA\LOCALS~1\Temp\Rar$EX00.719\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.eftel.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.com/search/search_frame.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.icq.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.eftel.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.eftel.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.eftel.com
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: BigFix.lnk = D:\Marg's Stuff\marg's programs\BigFix.exe
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesau.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesau.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

Marg
Looks good, Marg. :thumbup:

GOD bless you!!!

M68 :)

Items you may wish to consider to harden your defenses against future infections:

Read "How did I get infected in the first place?"

Download/install IE-Spyad

IE-Spyad puts over 4000 known malicious web sites into IE's "restricted zone" to help prevent you from getting infected.

Check your browser settings at Qualsys.com

A series of "tests" (and suggested fixes) to help tweak IE's settings to help prevent infections when surfing the web.

Follow safe Internet practices:

1. Keep your virus definitions up to date, and scan your system regularly.

2. Don't open email, or download attachments from unrecognized email addresses.

3. Be careful when downloading email attachments, EVEN FROM PEOPLE YOU KNOW! Many virii, worms, and trojans infect a persons system then immeadiately spread themselves to the people in the infected persons addressbook via email attachments.

4. Be careful downloading files from the Internet. Scan all downloaded files with a reliable UP-TO-DATE antivirus program. Scan "zip" files BEFORE unzipping, and scan all unzipped files BEFORE USING THEM.

5. Keep your Windows and IE current with all the latest patches and updates.

This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI