jasevr4
Topic Starter
Hi,
I recently (and stupidly may I add) ran an exe file that apparently had a virus/trojans/etc within it.
I have tried to get rid of it all, but I still can't boot my PC into normal mode, just safe mode. If I boot into normal mode I will see everything load, the cursor will load, and about a second later the PC will reset.
Operating System: Windows XP Pro SP2
ewido log:
———————————————————
ewido anti-spyware - Scan Report
———————————————————
+ Created at: 8:10:21 PM 10/09/2006
+ Scan result:
C:\Documents and Settings\Jase\My Documents\My Received Files\Messenger Plus! - Setup.exe/70000011.exe -> Downloader.Swizzor.g : No action taken.
:mozilla.10:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.11:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.12:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.13:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.14:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Adjuggler : No action taken.
:mozilla.147:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Com : No action taken.
:mozilla.148:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Com : No action taken.
C:\Documents and Settings\Jase\Cookies\jase@com[1].txt -> TrackingCookie.Com : No action taken.
:mozilla.181:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.182:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.183:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.184:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.185:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.186:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.496:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.497:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.498:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.499:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.516:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.517:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.518:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.575:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Web-stat : No action taken.
:mozilla.646:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.647:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
::Report end
HijackThis log:
Logfile of HijackThis v1.99.1
Scan saved at 8:11:25 PM, on 10/09/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DU Meter\DUMeter.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\mIRC\mirc.exe
C:\DOCUME~1\Jase\LOCALS~1\Temp\Temporary Directory 1 for startuplist.zip\StartupList.exe
D:\Downloads\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.jsrdesign.net/start/start.pl
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Idea2 SidebarBrowserMonitor Class - {45AD732C-2CE2-4666-B366-B2214AD57A49} - C:\Program Files\Desktop Sidebar\sbhelp.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SIDEBAR] "C:\Program Files\Desktop Sidebar\dsidebar.exe"
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\WidgetEngine\YahooWidgetEngine.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Program Files\Desktop Sidebar\sbhelp.dll
O9 - Extra 'Tools' menuitem: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Program Files\Desktop Sidebar\sbhelp.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2357B3CF-7F8D-4451-8D81-FD6097610AEE} (CamfrogWEB Advanced Unicode Control) - http://activex.camfrogweb.com/advanced/cfw…_instmodule.exe
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: MpService - Canon Inc. - C:\Program Files\Canon\MultiPASS4\MPSERVIC.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
I did run HijackThis in safe mode; not sure if that makes any difference?
Thanks a lot for reading.
EDIT: On closer inspection, I have found the virus "Win32:Joiner-H" to be what was installed. I am able to login with "Last Known Good Configuration" but by the sounds of it, this is a password capturer, so obviously I want to get rid of it ASAP!
I recently (and stupidly may I add) ran an exe file that apparently had a virus/trojans/etc within it.
I have tried to get rid of it all, but I still can't boot my PC into normal mode, just safe mode. If I boot into normal mode I will see everything load, the cursor will load, and about a second later the PC will reset.
Operating System: Windows XP Pro SP2
ewido log:
———————————————————
ewido anti-spyware - Scan Report
———————————————————
+ Created at: 8:10:21 PM 10/09/2006
+ Scan result:
C:\Documents and Settings\Jase\My Documents\My Received Files\Messenger Plus! - Setup.exe/70000011.exe -> Downloader.Swizzor.g : No action taken.
:mozilla.10:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.11:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.12:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.13:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.14:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Adjuggler : No action taken.
:mozilla.147:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Com : No action taken.
:mozilla.148:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Com : No action taken.
C:\Documents and Settings\Jase\Cookies\jase@com[1].txt -> TrackingCookie.Com : No action taken.
:mozilla.181:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.182:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.183:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.184:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.185:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.186:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.496:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.497:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.498:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.499:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.516:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.517:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.518:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.575:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Web-stat : No action taken.
:mozilla.646:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.647:C:\Documents and Settings\Jase\Application Data\Mozilla\Firefox\Profiles\yfmva7hm.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
::Report end
HijackThis log:
Logfile of HijackThis v1.99.1
Scan saved at 8:11:25 PM, on 10/09/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DU Meter\DUMeter.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\mIRC\mirc.exe
C:\DOCUME~1\Jase\LOCALS~1\Temp\Temporary Directory 1 for startuplist.zip\StartupList.exe
D:\Downloads\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.jsrdesign.net/start/start.pl
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Idea2 SidebarBrowserMonitor Class - {45AD732C-2CE2-4666-B366-B2214AD57A49} - C:\Program Files\Desktop Sidebar\sbhelp.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SIDEBAR] "C:\Program Files\Desktop Sidebar\dsidebar.exe"
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\WidgetEngine\YahooWidgetEngine.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Program Files\Desktop Sidebar\sbhelp.dll
O9 - Extra 'Tools' menuitem: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Program Files\Desktop Sidebar\sbhelp.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2357B3CF-7F8D-4451-8D81-FD6097610AEE} (CamfrogWEB Advanced Unicode Control) - http://activex.camfrogweb.com/advanced/cfw…_instmodule.exe
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: MpService - Canon Inc. - C:\Program Files\Canon\MultiPASS4\MPSERVIC.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
I did run HijackThis in safe mode; not sure if that makes any difference?
Thanks a lot for reading.
EDIT: On closer inspection, I have found the virus "Win32:Joiner-H" to be what was installed. I am able to login with "Last Known Good Configuration" but by the sounds of it, this is a password capturer, so obviously I want to get rid of it ASAP!