Well - I still suffered from something so I ran Spybot, Ad-Aware, AVG-Antivirus, ATF-Cleaner and my AV: Avast once again (with on boot virust scan and spybot on logon) and most of it in safe mode. and I still get a program called "Project1" running visible in Task Manager and am expecting problems with a search bar again.
Here's the Ad-Aware Log, AVG-Antivirus Log and HJT Logs again
Ad-Aware Log
==================================================================
Ad-Aware SE Build 1.06r1
Logfile Created on:14 October 2006 23:38:14
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R126 12.10.2006
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Adware.DollarRevenue(TAC index:10):18 total references
MRU List(TAC index:0):13 total references
Other(TAC index:5):1 total references
Possible Browser Hijack attempt(TAC index:3):6 total references
Softomate Toolbar(TAC index:9):2 total references
Tracking Cookie(TAC index:3):1 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Ad-Aware SE Settings
===========================
Set : Search for negligible risk entries
Set : Search for low-risk threats
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan my Hosts file
Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects
14-10-2006 23:38:14 - Scan started. (Full System Scan)
MRU List Object Recognized!
Location: : C:\Documents and Settings\David\Application Data\microsoft\office\recent
Description : list of recently opened documents using microsoft office
MRU List Object Recognized!
Location: : C:\Documents and Settings\David\recent
Description : list of recently opened documents
MRU List Object Recognized!
Location: : software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct3d
MRU List Object Recognized!
Location: : software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct X
MRU List Object Recognized!
Location: : software\microsoft\directdraw\mostrecentapplication
Description : most recent application to use microsoft directdraw
MRU List Object Recognized!
Location: : S-1-5-21-839522115-484763869-2147053123-1003\software\microsoft\mediaplayer\preferences
Description : last playlist index loaded in microsoft windows media player
MRU List Object Recognized!
Location: : S-1-5-21-839522115-484763869-2147053123-1003\software\microsoft\mediaplayer\preferences
Description : last playlist loaded in microsoft windows media player
MRU List Object Recognized!
Location: : S-1-5-21-839522115-484763869-2147053123-1003\software\microsoft\office\10.0\common\open find\microsoft word\settings\save as\file name mru
Description : list of recent documents saved by microsoft word
MRU List Object Recognized!
Location: : S-1-5-21-839522115-484763869-2147053123-1003\software\microsoft\office\10.0\excel\recent files
Description : list of recent files used by microsoft excel
MRU List Object Recognized!
Location: : S-1-5-21-839522115-484763869-2147053123-1003\software\microsoft\office\10.0\powerpoint\recent file list
Description : list of recent files used by microsoft powerpoint
MRU List Object Recognized!
Location: : S-1-5-21-839522115-484763869-2147053123-1003\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru
Description : list of recent programs opened
MRU List Object Recognized!
Location: : S-1-5-21-839522115-484763869-2147053123-1003\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru
Description : list of recently saved files, stored according to file extension
MRU List Object Recognized!
Location: : S-1-5-21-839522115-484763869-2147053123-1003\software\microsoft\windows\currentversion\explorer\recentdocs
Description : list of recent documents opened
Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ProcessID : 608
ThreadCreationTime : 14-10-2006 11:17:54
BasePriority : Normal
#:2 [csrss.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 672
ThreadCreationTime : 14-10-2006 11:17:56
BasePriority : Normal
#:3 [winlogon.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 696
ThreadCreationTime : 14-10-2006 11:17:56
BasePriority : High
#:4 [services.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 740
ThreadCreationTime : 14-10-2006 11:17:57
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : services.exe
#:5 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 752
ThreadCreationTime : 14-10-2006 11:17:57
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : lsass.exe
#:6 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 904
ThreadCreationTime : 14-10-2006 11:17:57
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:7 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 988
ThreadCreationTime : 14-10-2006 11:17:57
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:8 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1080
ThreadCreationTime : 14-10-2006 11:17:57
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:9 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1136
ThreadCreationTime : 14-10-2006 11:17:57
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:10 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1348
ThreadCreationTime : 14-10-2006 11:17:58
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:11 [spoolsv.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1548
ThreadCreationTime : 14-10-2006 11:17:59
BasePriority : Normal
FileVersion : 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)
ProductVersion : 5.1.2600.2696
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : spoolsv.exe
#:12 [aswupdsv.exe]
FilePath : C:\Program Files\Alwil Software\Avast4\
ProcessID : 1700
ThreadCreationTime : 14-10-2006 11:18:06
BasePriority : Normal
#:13 [ashserv.exe]
FilePath : C:\Program Files\Alwil Software\Avast4\
ProcessID : 1712
ThreadCreationTime : 14-10-2006 11:18:06
BasePriority : High
FileVersion : 4, 7, 889, 0
ProductVersion : 4, 7, 0, 0
ProductName : avast! Antivirus
FileDescription : avast! antivirus service
InternalName : aswServ
LegalCopyright : Copyright © 2006 ALWIL Software
OriginalFilename : aswServ.exe
#:14 [guard.exe]
FilePath : C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\
ProcessID : 1736
ThreadCreationTime : 14-10-2006 11:18:06
BasePriority : Normal
FileVersion : 7, 5, 0, 47
ProductVersion : 7, 5, 0, 47
ProductName : AVG Anti-Spyware
CompanyName : Anti-Malware Development a.s.
FileDescription : AVG Anti-Spyware guard
InternalName : AVG Anti-Spyware guard
LegalCopyright : Copyright © 2006 Anti-Malware Development a.s.
OriginalFilename : guard.exe
#:15 [mdm.exe]
FilePath : C:\Program Files\Common Files\Microsoft Shared\VS7Debug\
ProcessID : 1872
ThreadCreationTime : 14-10-2006 11:18:07
BasePriority : Normal
FileVersion : 7.00.9064.9150
ProductVersion : 7.00.9064.9150
ProductName : Microsoft Development Environment
CompanyName : Microsoft Corporation
FileDescription : Machine Debug Manager
InternalName : mdm.exe
LegalCopyright : Copyright © Microsoft Corp. 1997-2000
OriginalFilename : mdm.exe
#:16 [nvsvc32.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1912
ThreadCreationTime : 14-10-2006 11:18:07
BasePriority : Normal
FileVersion : 6.14.10.7181
ProductVersion : 6.14.10.7181
ProductName : NVIDIA Driver Helper Service, Version 71.81
CompanyName : NVIDIA Corporation
FileDescription : NVIDIA Driver Helper Service, Version 71.81
InternalName : NVSVC
LegalCopyright : © NVIDIA Corporation. All rights reserved.
OriginalFilename : nvsvc32.exe
#:17 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 240
ThreadCreationTime : 14-10-2006 11:18:11
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:18 [wdfmgr.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 260
ThreadCreationTime : 14-10-2006 11:18:11
BasePriority : Normal
FileVersion : 5.2.3790.1230 built by: dnsrv(bld4act)
ProductVersion : 5.2.3790.1230
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows User Mode Driver Manager
InternalName : WdfMgr
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : WdfMgr.exe
#:19 [ashmaisv.exe]
FilePath : C:\Program Files\Alwil Software\Avast4\
ProcessID : 380
ThreadCreationTime : 14-10-2006 11:18:13
BasePriority : Normal
#:20 [ashwebsv.exe]
FilePath : C:\Program Files\Alwil Software\Avast4\
ProcessID : 660
ThreadCreationTime : 14-10-2006 11:18:14
BasePriority : Normal
#:21 [alg.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1116
ThreadCreationTime : 14-10-2006 11:18:14
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Application Layer Gateway Service
InternalName : ALG.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : ALG.exe
#:22 [explorer.exe]
FilePath : C:\WINDOWS\
ProcessID : 548
ThreadCreationTime : 14-10-2006 22:06:39
BasePriority : Normal
FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 6.00.2900.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : EXPLORER.EXE
Adware.DollarRevenue Object Recognized!
Type : Process
Data : deskbar.dll
TAC Rating : 10
Category : Adware
Comment : deskbar.dll.dmp
Object : C:\Program Files\Deskbar\
Warning! Adware.DollarRevenue Object found in memory(C:\Program Files\Deskbar\deskbar.dll)
#:23 [type32.exe]
FilePath : C:\Program Files\Microsoft IntelliType Pro\
ProcessID : 2272
ThreadCreationTime : 14-10-2006 22:06:46
BasePriority : Normal
#:24 [point32.exe]
FilePath : C:\Program Files\Microsoft IntelliPoint\
ProcessID : 2336
ThreadCreationTime : 14-10-2006 22:06:57
BasePriority : Normal
#:25 [realsched.exe]
FilePath : C:\Program Files\Common Files\Real\Update_OB\
ProcessID : 2472
ThreadCreationTime : 14-10-2006 22:06:58
BasePriority : Normal
FileVersion : 0.1.0.3275
ProductVersion : 0.1.0.3275
ProductName : RealPlayer (32-bit)
CompanyName : RealNetworks, Inc.
FileDescription : RealNetworks Scheduler
InternalName : schedapp
LegalCopyright : Copyright © RealNetworks, Inc. 1995-2004
LegalTrademarks : RealAudio™ is a trademark of RealNetworks, Inc.
OriginalFilename : realsched.exe
#:26 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 2628
ThreadCreationTime : 14-10-2006 22:06:59
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:27 [hpztsb10.exe]
FilePath : C:\WINDOWS\system32\spool\drivers\w32x86\3\
ProcessID : 2800
ThreadCreationTime : 14-10-2006 22:07:01
BasePriority : Normal
FileVersion : 2.323.0.0
ProductVersion : 2.323.0.0
ProductName : HP DeskJet
CompanyName : HP
LegalCopyright : Copyright © Hewlett-Packard Company 1999-2004
#:28 [qttask.exe]
FilePath : C:\Program Files\QuickTime\
ProcessID : 2840
ThreadCreationTime : 14-10-2006 22:07:02
BasePriority : Normal
FileVersion : 7.0.4
ProductVersion : QuickTime 7.0.4
ProductName : QuickTime
CompanyName : Apple Computer, Inc.
FileDescription : QuickTime Task
InternalName : QuickTime Task
LegalCopyright : Copyright Apple Computer, Inc. 1989-2006
OriginalFilename : QTTask.exe
#:29 [hpcmpmgr.exe]
FilePath : C:\Program Files\HP\hpcoretech\
ProcessID : 2880
ThreadCreationTime : 14-10-2006 22:07:04
BasePriority : Normal
FileVersion : 2.1.1.0
ProductVersion : 2.1.4
ProductName : hp coretech (COmponent REuse TECHnology)
CompanyName : Hewlett-Packard Company
FileDescription : HP Framework Component Manager Service
InternalName : HPComponentManagerService module
LegalCopyright : Copyright © Hewlett-Packard. 2002-2003
OriginalFilename : HpCmpMgr.exe
#:30 [ashdisp.exe]
FilePath : C:\PROGRA~1\ALWILS~1\Avast4\
ProcessID : 2764
ThreadCreationTime : 14-10-2006 22:07:08
BasePriority : Normal
FileVersion : 5, 0, 0, 0
ProductVersion : 5, 0, 0, 0
ProductName : avast! Antivirus
FileDescription : avast! service GUI component
InternalName : aswDisp
LegalCopyright : Copyright © 2006 ALWIL Software
OriginalFilename : aswDisp.exe
#:31 [ctfmon.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 3204
ThreadCreationTime : 14-10-2006 22:07:17
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : CTF Loader
InternalName : CTFMON
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : CTFMON.EXE
#:32 [avgas.exe]
FilePath : C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\
ProcessID : 3232
ThreadCreationTime : 14-10-2006 22:07:22
BasePriority : Normal
FileVersion : 7, 5, 0, 50
ProductVersion : 7, 5, 0, 50
ProductName : AVG Anti-Spyware
CompanyName : Anti-Malware Development a.s.
FileDescription : AVG Anti-Spyware
InternalName : AVG Anti-Spyware
LegalCopyright : Copyright © 2006 Anti-Malware Development a.s.
OriginalFilename : avgas.exe
#:33 [msmsgs.exe]
FilePath : C:\Program Files\Messenger\
ProcessID : 3344
ThreadCreationTime : 14-10-2006 22:07:34
BasePriority : Normal
FileVersion : 4.7.3001
ProductVersion : Version 4.7.3001
ProductName : Messenger
CompanyName : Microsoft Corporation
FileDescription : Windows Messenger
InternalName : msmsgs
LegalCopyright : Copyright © Microsoft Corporation 2004
LegalTrademarks : Microsoft® is a registered trademark of Microsoft Corporation in the U.S. and/or other countries.
OriginalFilename : msmsgs.exe
#:34 [kybrdff_e29.exe]
FilePath : c:\
ProcessID : 3380
ThreadCreationTime : 14-10-2006 22:07:42
BasePriority : Normal
FileVersion : 1.00.0183
ProductVersion : 1.00.0183
ProductName : Project1
CompanyName : fdslj reditf8eru8turdtreduj54tr8u548
InternalName : kybrdff_18_a
OriginalFilename : kybrdff_18_a.exe
#:35 [msnmsgr.exe]
FilePath : C:\Program Files\MSN Messenger\
ProcessID : 2064
ThreadCreationTime : 14-10-2006 22:07:45
BasePriority : Normal
FileVersion : 7.5.0324
ProductVersion : 7.5.0324
ProductName : MSN Messenger
CompanyName : Microsoft Corporation
FileDescription : MSN Messenger
InternalName : msnmsgr
LegalCopyright : Copyright © Microsoft Corporation 1997-2004
LegalTrademarks : Microsoft® is a registered trademark of Microsoft Corporation in the U.S. and/or other countries.
OriginalFilename : msnmsgr.exe
#:36 [wcescomm.exe]
FilePath : C:\Program Files\Microsoft ActiveSync\
ProcessID : 3492
ThreadCreationTime : 14-10-2006 22:07:48
BasePriority : Normal
FileVersion : 4.2.4876.0
ProductVersion : 4.2.4876
ProductName : Microsoft ActiveSync
CompanyName : Microsoft Corporation
FileDescription : ActiveSync Connection Manager
InternalName : wcescomm
LegalCopyright : Copyright © 1995-2006 Microsoft Corp. All rights reserved.
LegalTrademarks : Microsoft® and Windows® are registered trademarks of Microsoft Corporation.
OriginalFilename : WCESCOMM.EXE
#:37 [dfndrff_e29.exe]
FilePath : c:\
ProcessID : 3608
ThreadCreationTime : 14-10-2006 22:07:49
BasePriority : Normal
FileVersion : 1.00.0254
ProductVersion : 1.00.0254
ProductName : Project1
CompanyName : ;ew;weew;e;wr;43;;5;
InternalName : Project1
OriginalFilename : Project1.exe
#:38 [rapimgr.exe]
FilePath : C:\PROGRA~1\MI3AA1~1\
ProcessID : 3620
ThreadCreationTime : 14-10-2006 22:07:49
BasePriority : Normal
FileVersion : 4.2.4876.0
ProductVersion : 4.2.4876
ProductName : Microsoft ActiveSync
CompanyName : Microsoft Corporation
FileDescription : ActiveSync RAPI Manager
InternalName : rapimgr
LegalCopyright : Copyright © 1995-2006 Microsoft Corp. All rights reserved.
LegalTrademarks : Microsoft® and Windows® are registered trademarks of Microsoft Corporation.
OriginalFilename : rapimgr.exe
#:39 [pageant.exe]
FilePath : C:\Program Files\PuTTY\
ProcessID : 1188
ThreadCreationTime : 14-10-2006 22:07:57
BasePriority : Normal
#:40 [tosbtmng.exe]
FilePath : C:\Program Files\Toshiba\Bluetooth Toshiba Stack\
ProcessID : 3904
ThreadCreationTime : 14-10-2006 22:07:58
BasePriority : Normal
#:41 [tosa2dp.exe]
FilePath : C:\Program Files\Toshiba\Bluetooth Toshiba Stack\
ProcessID : 212
ThreadCreationTime : 14-10-2006 22:08:01
BasePriority : Normal
#:42 [tosbthsp.exe]
FilePath : C:\Program Files\Toshiba\Bluetooth Toshiba Stack\
ProcessID : 1200
ThreadCreationTime : 14-10-2006 22:08:01
BasePriority : Normal
#:43 [wuauclt.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1776
ThreadCreationTime : 14-10-2006 22:09:38
BasePriority : Normal
FileVersion : 5.8.0.2469 built by: lab01_n(wmbla)
ProductVersion : 5.8.0.2469
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Automatic Updates
InternalName : wuauclt.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : wuauclt.exe
#:44 [spybotsd.exe]
FilePath : C:\Program Files\Spybot - Search & Destroy\
ProcessID : 3312
ThreadCreationTime : 14-10-2006 22:34:38
BasePriority : Normal
FileVersion : 1.4.0.3
ProductVersion : 1, 4, 0, 3
ProductName : SpyBot-S&D;
CompanyName : Safer Networking Limited
FileDescription : Spybot - Search & Destroy
InternalName : SpybotSD
LegalCopyright : © 2000-2005 Patrick M. Kolla / Safer Networking Limited. Alle Rechte vorbehalten.
LegalTrademarks : "Spybot" und "Spybot - Search & Destroy" sind registrierte Warenzeichen.
OriginalFilename : SpyBotSD.exe
Comments : Software zum Entfernen von Spyware und ähnlichen Bedrohungen.
#:45 [ashsimpl.exe]
FilePath : C:\Program Files\Alwil Software\Avast4\
ProcessID : 3884
ThreadCreationTime : 14-10-2006 22:37:33
BasePriority : Normal
FileVersion : 4, 7, 889, 0
ProductVersion : 4, 7, 0, 0
ProductName : avast! Antivirus
CompanyName : ALWIL Software
FileDescription : Virus scanner
InternalName : aswSimpl.exe
LegalCopyright : Copyright © 2006 ALWIL Software
OriginalFilename : aswSimpl.exe
#:46 [ad-aware.exe]
FilePath : C:\Program Files\Lavasoft\Ad-Aware SE Personal\
ProcessID : 3128
ThreadCreationTime : 14-10-2006 22:37:35
BasePriority : Normal
FileVersion : 6.2.0.236
ProductVersion : SE 106
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft AB Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved
Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 14
Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Adware.DollarRevenue Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Adware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{a8b28872-3324-4cd2-8aa3-7d555c872d96}
Adware.DollarRevenue Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Adware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{d7cc80d4-376c-4586-b023-4f35c2ceb28e}
Adware.DollarRevenue Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Adware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{d8c2d4b4-eeaf-4ec4-b1f8-9b6ed15d5a38}
Adware.DollarRevenue Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Adware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{8f15b157-40d9-4b20-8d3b-b1f8b475b58d}
Adware.DollarRevenue Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Adware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{a0881aa1-68be-41ac-9c0d-4c8a69c6c72c}
Adware.DollarRevenue Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Adware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{e827ffd9-95d1-4b49-beb3-5d49e688c108}
Adware.DollarRevenue Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Adware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : typelib\{a4c8f181-6cdb-4dcc-9fc9-bb9933c81e1f}
Adware.DollarRevenue Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Adware
Comment :
Rootkey : HKEY_USERS
Object : S-1-5-21-839522115-484763869-2147053123-1003\software\microsoft\windows\currentversion\ext\stats\{a8b28872-3324-4cd2-8aa3-7d555c872d96}
Adware.DollarRevenue Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Adware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\explorer\browser helper objects\{a8b28872-3324-4cd2-8aa3-7d555c872d96}
Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 9
Objects found so far: 23
Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Possible Browser Hijack attempt : Software\Microsoft\Internet Explorer\MainSearch Page.findthewebsiteyouneed.com
Possible Browser Hijack attempt Object Recognized!
Type : RegData
Data : "http://searchbar.findthewebsiteyouneed.com"
TAC Rating : 10
Category : Adware
Comment : Possible Browser Hijack attempt
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Internet Explorer\Main
Value : Search Page
Data : "http://searchbar.findthewebsiteyouneed.com"
Possible Browser Hijack attempt : Software\Microsoft\Internet Explorer\SearchSearchAssistant.findthewebsiteyouneed.com
Possible Browser Hijack attempt Object Recognized!
Type : RegData
Data : "http://searchbar.findthewebsiteyouneed.com"
TAC Rating : 10
Category : Adware
Comment : Possible Browser Hijack attempt
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Internet Explorer\Search
Value : SearchAssistant
Data : "http://searchbar.findthewebsiteyouneed.com"
Possible Browser Hijack attempt : S-1-5-21-839522115-484763869-2147053123-1003\Software\Microsoft\Internet Explorer\MainSearch Page.findthewebsiteyouneed.com
Possible Browser Hijack attempt Object Recognized!
Type : RegData
Data : "http://searchbar.findthewebsiteyouneed.com"
TAC Rating : 10
Category : Adware
Comment : Possible Browser Hijack attempt
Rootkey : HKEY_USERS
Object : S-1-5-21-839522115-484763869-2147053123-1003\Software\Microsoft\Internet Explorer\Main
Value : Search Page
Data : "http://searchbar.findthewebsiteyouneed.com"
Possible Browser Hijack attempt : S-1-5-21-839522115-484763869-2147053123-1003\Software\Microsoft\Internet Explorer\MainStart Page.findthewebsiteyouneed.com
Possible Browser Hijack attempt Object Recognized!
Type : RegData
Data : "
http://www.findthewebsiteyouneed.com"
TAC Rating : 10
Category : Adware
Comment : Possible Browser Hijack attempt
Rootkey : HKEY_USERS
Object : S-1-5-21-839522115-484763869-2147053123-1003\Software\Microsoft\Internet Explorer\Main
Value : Start Page
Data : "
http://www.findthewebsiteyouneed.com"
Possible Browser Hijack attempt : S-1-5-21-839522115-484763869-2147053123-1003\Software\Microsoft\Internet Explorer\MainSearch Bar.findthewebsiteyouneed.com
Possible Browser Hijack attempt Object Recognized!
Type : RegData
Data : "http://searchbar.findthewebsiteyouneed.com"
TAC Rating : 10
Category : Adware
Comment : Possible Browser Hijack attempt
Rootkey : HKEY_USERS
Object : S-1-5-21-839522115-484763869-2147053123-1003\Software\Microsoft\Internet Explorer\Main
Value : Search Bar
Data : "http://searchbar.findthewebsiteyouneed.com"
Possible Browser Hijack attempt : S-1-5-21-839522115-484763869-2147053123-1003\Software\Microsoft\Internet Explorer\MainDefault_Search_URL.findthewebsiteyouneed.com
Possible Browser Hijack attempt Object Recognized!
Type : RegData
Data : "http://searchbar.findthewebsiteyouneed.com"
TAC Rating : 10
Category : Adware
Comment : Possible Browser Hijack attempt
Rootkey : HKEY_USERS
Object : S-1-5-21-839522115-484763869-2147053123-1003\Software\Microsoft\Internet Explorer\Main
Value : Default_Search_URL
Data : "http://searchbar.findthewebsiteyouneed.com"
Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 6
Objects found so far: 29
Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : [removed][2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:14
Value : Cookie:[removed]/
Expires : 28-10-2006 00:07:04
LastSync : Hits:14
UseCount : 0
Hits : 14
Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 1
Objects found so far: 30
Deep scanning and examining files (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Adware.DollarRevenue Object Recognized!
Type : File
Data : deskbar.exe
TAC Rating : 10
Category : Adware
Comment :
Object : C:\
Softomate Toolbar Object Recognized!
Type : File
Data : nsProcess.dll
TAC Rating : 9
Category : Data Miner
Comment :
Object : C:\Documents and Settings\David\Local Settings\Temp\nsj33.tmp\
Adware.DollarRevenue Object Recognized!
Type : File
Data : deskbar.exe
TAC Rating : 10
Category : Adware
Comment :
Object : C:\Odd\
Adware.DollarRevenue Object Recognized!
Type : File
Data : __delete_on_reboot__d_e_s_k_b_a_r_._d_l_l_
TAC Rating : 10
Category : Adware
Comment :
Object : C:\Program Files\Deskbar\
FileVersion : 1, 0, 0, 272
ProductVersion : 1, 0, 0, 1
ProductName : Deskbar
CompanyName : Deskbar
FileDescription : Deskbar
InternalName : Deskbar
LegalCopyright : Copyright 2001-2003. All rights reserved.
OriginalFilename : deskbar.dll
Adware.DollarRevenue Object Recognized!
Type : File
Data : A0116020.exe
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP233\
Adware.DollarRevenue Object Recognized!
Type : File
Data : A0116544.exe
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP234\
Adware.DollarRevenue Object Recognized!
Type : File
Data : A0116568.exe
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP235\
Adware.DollarRevenue Object Recognized!
Type : File
Data : A0116572.dll
TAC Rating : 10
Category : Adware
Comment :
Object : C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP236\
FileVersion : 1, 0, 0, 272
ProductVersion : 1, 0, 0, 1
ProductName : Deskbar
CompanyName : Deskbar
FileDescription : Deskbar
InternalName : Deskbar
LegalCopyright : Copyright 2001-2003. All rights reserved.
OriginalFilename : deskbar.dll
Disk Scan Result for C:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 38
Deep scanning and examining files (E:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Disk Scan Result for E:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 38
Scanning Hosts file……
Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts".
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Hosts file scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
6728 entries scanned.
New critical objects:0
Objects found so far: 38
Performing conditional scans…
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Adware.DollarRevenue Object Recognized!
Type : RegValue
Data :
TAC Rating : 10
Category : Adware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\run
Value : defender
Softomate Toolbar Object Recognized!
Type : RegData
Data : 0
TAC Rating : 9
Category : Data Miner
Comment :
Rootkey : HKEY_CURRENT_USER
Object : software\microsoft\internet explorer\main\featurecontrol\feature_localmachine_lockdown
Value : iexplore.exe
Data : 0
Other Object Recognized!
Type : File
Data : DESKBAR.EXE-38CDF805.pf
TAC Rating : 7
Category : Malware
Comment :
Object : C:\WINDOWS\prefetch\
Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 3
Objects found so far: 41
00:00:04 Scan Complete
Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:21:50.78
Objects scanned:215272
Objects identified:29
Objects ignored:0
New critical objects:29
AVG-Antivirus Log:
==================================================================
———————————————————
AVG Anti-Spyware - Scan Report
———————————————————
+ Created at: 14:40:15 15/10/2006
+ Scan result:
C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP234\A0116512.exe -> Adware.Look2Me : Cleaned.
C:\Program Files\Common Files\{84173296-095F-2057-1125-04100504002c}\services.dll -> Adware.Softomate : Cleaned.
C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP234\A0116513.dll -> Adware.Softomate : Cleaned.
C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP234\A0116514.exe -> Adware.Softomate : Cleaned.
C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP234\A0116515.dll -> Adware.Softomate : Cleaned.
C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP234\A0116511.exe -> Adware.SurfSide : Cleaned.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\GPUNOLQ7\1[1].exe -> Backdoor.Small.ml : Cleaned.
C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP234\A0116505.exe -> Backdoor.Small.ml : Cleaned.
C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP234\A0116506.exe -> Backdoor.Small.ml : Cleaned.
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\ST6ZWXEV\drsmartload815a[1].exe -> Downloader.Adload.fu : Cleaned.
C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP234\A0116504.exe -> Downloader.Adload.fu : Cleaned.
C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP234\A0116509.exe -> Downloader.Adload.gk : Cleaned.
C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP234\A0116510.exe -> Downloader.Adload.gk : Cleaned.
C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP236\A0116595.exe -> Downloader.Adload.gp : Cleaned.
C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP236\A0116594.exe -> Downloader.Adload.gr : Cleaned.
C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP234\A0116507.exe -> Downloader.Banload.bni : Cleaned.
C:\System Volume Information\_restore{1731FC50-3080-4F77-9B65-1CEA108E2A46}\RP234\A0116508.exe -> Downloader.Banload.bni : Cleaned.
:mozilla.40:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.41:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.42:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.15:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.16:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.17:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.18:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.19:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.21:C:\Documents and Settings\David\Application Data\Mozilla\Firefox\Profiles\6e35vhh5.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
::Report end
HijackThis Log
==================================================================
Logfile of HijackThis v1.99.1
Scan saved at 16:59:40, on 15/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\kybrdff_e29.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\PuTTY\pageant.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
E:\Sources\_PC Security\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://messenger.msn.com/flash/?mkt=en-gb&…ersion=7,0,19,0
R3 - URLSearchHook: (no name) - {A8B28872-3324-4CD2-8AA3-7D555C872D96} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Program Files\Common Files\{34173296-095F-2057-1125-04100504002c}\MyToolBar.dll (file missing)
O2 - BHO: Burn4Free Toolbar Helper - {F8E5CA21-C27B-43e7-B2BE-4CA93C9F9A1F} - C:\Program Files\Burn4Free Toolbar\v2.0.0.4\Burn4Free_Toolbar.dll
O3 - Toolbar: Burn4Free Toolbar - {70DE7956-479D-4eb7-8641-2B45774C350E} - C:\Program Files\Burn4Free Toolbar\v2.0.0.4\Burn4Free_Toolbar.dll
O3 - Toolbar: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Program Files\Common Files\{34173296-095F-2057-1125-04100504002c}\MyToolBar.dll (file missing)
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_e29.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [strmfilt] C:\WINDOWS\system32\strmfilt.exe
O4 - HKCU\..\Run: [kbdest] C:\WINDOWS\system32\kbdest.exe
O4 - HKCU\..\Run: [wmpasf] C:\WINDOWS\system32\wmpasf.exe
O4 - HKCU\..\Run: [FIREFOX] C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
O4 - HKCU\..\Run: [wshirda] C:\WINDOWS\system32\wshirda.exe
O4 - HKCU\..\Run: [ddrawex] C:\WINDOWS\system32\ddrawex.exe
O4 - HKCU\..\Run: [prflbmsg] C:\WINDOWS\system32\prflbmsg.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Pageant.lnk = C:\Program Files\PuTTY\pageant.exe
O4 - Global User Startup: Bluetooth Manager.lnk = ?
O4 - Global User Startup: Pageant.lnk = C:\Program Files\PuTTY\pageant.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apache - Unknown owner - C:\Program Files\IBserver\apache\Apache.exe" –ntservice (file missing)
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: batt.exe - Unknown owner - C:\WINDOWS\system32\batt.exe
O23 - Service: dxmasf.exe - Unknown owner - C:\WINDOWS\system32\dxmasf.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: mqutil.exe - Unknown owner - C:\WINDOWS\system32\mqutil.exe (file missing)
O23 - Service: MySql - Unknown owner - C:\Program Files\IBserver\mysql\bin\mysqld-opt.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: nvwimg.exe - Unknown owner - C:\WINDOWS\system32\nvwimg.exe (file missing)
O23 - Service: unzip32.exe - Unknown owner - C:\WINDOWS\system32\unzip32.exe (file missing)
Many Thanks, Any help greatly appreciated.
David