Hi Markka,
I had one problem with the advice you gave me: the Fix.bat file you asked me to create. When I launched it, it said 'the specified service does not exist as an installed service.' When I created it using NotePad, the Encoding was set by default to 'ANSI' (whatever that means)...perhaps that could have something to do with it?
By the way, should I now revert the changes I made according to your instructions on how to 'make hidden files visible'?
Thanks again, and here are the things you asked for:
Kaspersky Report:
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Monday, June 18, 2007 6:52:14 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 18/06/2007
Kaspersky Anti-Virus database records: 348009
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
F:\
H:\
Scan Statistics:
Total number of scanned objects: 152942
Number of viruses found: 8
Number of infected objects: 41
Number of suspicious objects: 0
Duration of the scan process: 03:00:44
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-03182007-095249.log Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\sam\Application Data\Mozilla\Firefox\Profiles\e6xjxgtk.default\cert8.db Object is locked skipped
C:\Documents and Settings\sam\Application Data\Mozilla\Firefox\Profiles\e6xjxgtk.default\history.dat Object is locked skipped
C:\Documents and Settings\sam\Application Data\Mozilla\Firefox\Profiles\e6xjxgtk.default\key3.db Object is locked skipped
C:\Documents and Settings\sam\Application Data\Mozilla\Firefox\Profiles\e6xjxgtk.default\parent.lock Object is locked skipped
C:\Documents and Settings\sam\Application Data\Mozilla\Firefox\Profiles\e6xjxgtk.default\search.sqlite Object is locked skipped
C:\Documents and Settings\sam\Application Data\Mozilla\Firefox\Profiles\e6xjxgtk.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\sam\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\sam\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\sam\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\sam\Local Settings\Application Data\Mozilla\Firefox\Profiles\e6xjxgtk.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\sam\Local Settings\Application Data\Mozilla\Firefox\Profiles\e6xjxgtk.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\sam\Local Settings\Application Data\Mozilla\Firefox\Profiles\e6xjxgtk.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\sam\Local Settings\Application Data\Mozilla\Firefox\Profiles\e6xjxgtk.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\sam\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\sam\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\sam\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\sam\ntuser.dat Object is locked skipped
C:\Documents and Settings\sam\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\sam\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{95C8BA23-7DEC-40CD-A7C2-1ABB11423E47}\RP166\A0041479.exe/data.rar/keygen.exe Infected: Trojan-Downloader.Win32.LoadAdv.gen skipped
C:\System Volume Information\_restore{95C8BA23-7DEC-40CD-A7C2-1ABB11423E47}\RP166\A0041479.exe/data.rar/crack.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\System Volume Information\_restore{95C8BA23-7DEC-40CD-A7C2-1ABB11423E47}\RP166\A0041479.exe/data.rar/serial.exe Infected: Trojan.Win32.Dialer.qn skipped
C:\System Volume Information\_restore{95C8BA23-7DEC-40CD-A7C2-1ABB11423E47}\RP166\A0041479.exe/data.rar/install.exe Infected: Trojan-Downloader.Win32.Agent.brf skipped
C:\System Volume Information\_restore{95C8BA23-7DEC-40CD-A7C2-1ABB11423E47}\RP166\A0041479.exe/data.rar Infected: Trojan-Downloader.Win32.Agent.brf skipped
C:\System Volume Information\_restore{95C8BA23-7DEC-40CD-A7C2-1ABB11423E47}\RP166\A0041479.exe RarSFX: infected - 5 skipped
C:\System Volume Information\_restore{95C8BA23-7DEC-40CD-A7C2-1ABB11423E47}\RP166\A0041480.exe Infected: Trojan-Downloader.Win32.LoadAdv.gen skipped
C:\System Volume Information\_restore{95C8BA23-7DEC-40CD-A7C2-1ABB11423E47}\RP166\A0041481.exe Infected: Trojan-Downloader.Win32.Agent.brf skipped
C:\System Volume Information\_restore{95C8BA23-7DEC-40CD-A7C2-1ABB11423E47}\RP166\A0041484.exe Infected: Trojan.Win32.Dialer.qn skipped
C:\System Volume Information\_restore{95C8BA23-7DEC-40CD-A7C2-1ABB11423E47}\RP166\A0041485.exe/data.rar/keygen.exe Infected: Trojan-Downloader.Win32.LoadAdv.gen skipped
C:\System Volume Information\_restore{95C8BA23-7DEC-40CD-A7C2-1ABB11423E47}\RP166\A0041485.exe/data.rar/crack.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\System Volume Information\_restore{95C8BA23-7DEC-40CD-A7C2-1ABB11423E47}\RP166\A0041485.exe/data.rar/serial.exe Infected: Trojan.Win32.Dialer.qn skipped
C:\System Volume Information\_restore{95C8BA23-7DEC-40CD-A7C2-1ABB11423E47}\RP166\A0041485.exe/data.rar/install.exe Infected: Trojan-Downloader.Win32.Agent.brf skipped
C:\System Volume Information\_restore{95C8BA23-7DEC-40CD-A7C2-1ABB11423E47}\RP166\A0041485.exe/data.rar Infected: Trojan-Downloader.Win32.Agent.brf skipped
C:\System Volume Information\_restore{95C8BA23-7DEC-40CD-A7C2-1ABB11423E47}\RP166\A0041485.exe RarSFX: infected - 5 skipped
C:\System Volume Information\_restore{95C8BA23-7DEC-40CD-A7C2-1ABB11423E47}\RP166\A0041486.exe Infected: Trojan-Downloader.Win32.Agent.brf skipped
C:\System Volume Information\_restore{95C8BA23-7DEC-40CD-A7C2-1ABB11423E47}\RP166\A0041487.exe Infected: Trojan-Downloader.Win32.LoadAdv.gen skipped
C:\System Volume Information\_restore{95C8BA23-7DEC-40CD-A7C2-1ABB11423E47}\RP166\A0041489.exe Infected: Trojan.Win32.Dialer.qn skipped
C:\System Volume Information\_restore{95C8BA23-7DEC-40CD-A7C2-1ABB11423E47}\RP166\A0041490.exe Infected: Trojan-Downloader.Win32.Agent.brf skipped
C:\System Volume Information\_restore{95C8BA23-7DEC-40CD-A7C2-1ABB11423E47}\RP166\A0041491.exe/data.rar/keygen.exe Infected: Trojan-Downloader.Win32.LoadAdv.gen skipped
C:\System Volume Information\_restore{95C8BA23-7DEC-40CD-A7C2-1ABB11423E47}\RP166\A0041491.exe/data.rar/crack.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\System Volume Information\_restore{95C8BA23-7DEC-40CD-A7C2-1ABB11423E47}\RP166\A0041491.exe/data.rar/serial.exe Infected: Trojan.Win32.Dialer.qn skipped
C:\System Volume Information\_restore{95C8BA23-7DEC-40CD-A7C2-1ABB11423E47}\RP166\A0041491.exe/data.rar/install.exe Infected: Trojan-Downloader.Win32.Agent.brf skipped
C:\System Volume Information\_restore{95C8BA23-7DEC-40CD-A7C2-1ABB11423E47}\RP166\A0041491.exe/data.rar Infected: Trojan-Downloader.Win32.Agent.brf skipped
C:\System Volume Information\_restore{95C8BA23-7DEC-40CD-A7C2-1ABB11423E47}\RP166\A0041491.exe RarSFX: infected - 5 skipped
C:\System Volume Information\_restore{95C8BA23-7DEC-40CD-A7C2-1ABB11423E47}\RP166\A0041492.exe Infected: Trojan-Downloader.Win32.LoadAdv.gen skipped
C:\System Volume Information\_restore{95C8BA23-7DEC-40CD-A7C2-1ABB11423E47}\RP166\A0041495.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped
C:\System Volume Information\_restore{95C8BA23-7DEC-40CD-A7C2-1ABB11423E47}\RP167\A0045716.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\System Volume Information\_restore{95C8BA23-7DEC-40CD-A7C2-1ABB11423E47}\RP167\A0045717.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped
C:\System Volume Information\_restore{95C8BA23-7DEC-40CD-A7C2-1ABB11423E47}\RP167\A0045718.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\System Volume Information\_restore{95C8BA23-7DEC-40CD-A7C2-1ABB11423E47}\RP167\A0045719.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped
C:\System Volume Information\_restore{95C8BA23-7DEC-40CD-A7C2-1ABB11423E47}\RP167\A0045720.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\System Volume Information\_restore{95C8BA23-7DEC-40CD-A7C2-1ABB11423E47}\RP167\A0045976.exe Infected: Trojan-Spy.Win32.Ardamax.e skipped
C:\System Volume Information\_restore{95C8BA23-7DEC-40CD-A7C2-1ABB11423E47}\RP168\A0046035.dll Infected: Trojan.Win32.Dialer.qn skipped
C:\System Volume Information\_restore{95C8BA23-7DEC-40CD-A7C2-1ABB11423E47}\RP168\change.log Object is locked skipped
C:\VundoFix Backups\fcccawu.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\VundoFix Backups\geeda.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped
C:\VundoFix Backups\hggfefe.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\VundoFix Backups\jkhhi.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped
C:\VundoFix Backups\khfgfef.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\WINDOWS\.file_store_32\runescape\main_file_cache.dat2 Object is locked skipped
C:\WINDOWS\.file_store_32\runescape\main_file_cache.idx0 Object is locked skipped
C:\WINDOWS\.file_store_32\runescape\main_file_cache.idx1 Object is locked skipped
C:\WINDOWS\.file_store_32\runescape\main_file_cache.idx10 Object is locked skipped
C:\WINDOWS\.file_store_32\runescape\main_file_cache.idx11 Object is locked skipped
C:\WINDOWS\.file_store_32\runescape\main_file_cache.idx12 Object is locked skipped
C:\WINDOWS\.file_store_32\runescape\main_file_cache.idx13 Object is locked skipped
C:\WINDOWS\.file_store_32\runescape\main_file_cache.idx14 Object is locked skipped
C:\WINDOWS\.file_store_32\runescape\main_file_cache.idx15 Object is locked skipped
C:\WINDOWS\.file_store_32\runescape\main_file_cache.idx2 Object is locked skipped
C:\WINDOWS\.file_store_32\runescape\main_file_cache.idx255 Object is locked skipped
C:\WINDOWS\.file_store_32\runescape\main_file_cache.idx3 Object is locked skipped
C:\WINDOWS\.file_store_32\runescape\main_file_cache.idx4 Object is locked skipped
C:\WINDOWS\.file_store_32\runescape\main_file_cache.idx5 Object is locked skipped
C:\WINDOWS\.file_store_32\runescape\main_file_cache.idx6 Object is locked skipped
C:\WINDOWS\.file_store_32\runescape\main_file_cache.idx7 Object is locked skipped
C:\WINDOWS\.file_store_32\runescape\main_file_cache.idx8 Object is locked skipped
C:\WINDOWS\.file_store_32\runescape\main_file_cache.idx9 Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\nimnkwfw.exe Infected: Backdoor.Win32.SdBot.bbn skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_33c.dat Object is locked skipped
C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
D:\System Volume Information\_restore{95C8BA23-7DEC-40CD-A7C2-1ABB11423E47}\RP168\change.log Object is locked skipped
Scan process completed.
HJT Log:
Logfile of HijackThis v1.99.1
Scan saved at 18:54:54, on 18/06/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\WINDOWS\system32\RAMASST.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) -
http://housecall60.t...all/xscan60.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) -
http://www.pcpitstop...p/PCPitStop.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204
O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) -
http://www.pcpitstop...cpConnCheck.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.syma...bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) -
http://www.fileplane...DC_2.2.2.89.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://sambis01.spac...ad/MsnPUpld.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) -
http://cdn.scan.safe...wlscbase969.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) -
http://upload.facebo...otoUploader.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.syma...n/bin/cabsa.cab
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) -
http://download.zone...canner37500.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) -
http://www.ravantivi...n/ravonline.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://messenger.zon...ro.cab32846.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) -
http://www.windowsec...scan/axscan.cab
O16 - DPF: {C36661D7-3590-45B1-80B5-520839E94DAD} (MaxisSimCity4PatcherX Control) -
http://simcity.ea.co...ty4PatcherX.cab
O16 - DPF: {CBD8B1CB-2F5F-415F-93E8-A297B33DCBB2} (CentrinoCheck Control) -
http://entriq.vo.lln...eck_1_0_0_5.cab
O16 - DPF: {CE7D2BF2-D173-4CE2-9DAF-15EA153B5B43} -
http://entriq.vo.lln...0_15_Silent.cab
O16 - DPF: {DE0FB644-C59B-46D1-B650-88BA945BC98F} -
http://entriq.vo.lln...sal_1_0_0_3.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) -
http://download.mcaf...603/mcfscan.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A6E29533-7BF0-464F-84EC-318149ABF8CD}: NameServer = 194.158.37.196,194.158.37.211
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: PFW - C:\WINDOWS\SYSTEM32\UmxWnp.Dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (file missing)
O23 - Service: iPodService - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe