Beadza
Topic Starter
Hihi
Its my girlfriend's computer that has the troubles. It's been slow for ages, especially with internet related stuff.
I've ran VundoFix and ComboFix, and they've removed stuff (I'll paste in the logs) but I'm still getting the occasional pop-up (for WinAntiVirusPro mostly)
VundoFix log:
ComboFix log:
ComboFix quarantined files log:
And a current HijackThis log:
This one strikes me as suspicious, but HijackThis can't remove it:
O20 - Winlogon Notify: kbdbnt - C:\WINDOWS\SYSTEM32\kbdbnt.dll
TIA for any help proceeding
Peet
EDIT: Preview broke my post =(
Its my girlfriend's computer that has the troubles. It's been slow for ages, especially with internet related stuff.
I've ran VundoFix and ComboFix, and they've removed stuff (I'll paste in the logs) but I'm still getting the occasional pop-up (for WinAntiVirusPro mostly)
VundoFix log:
VundoFix V6.5.7 Checking Java version… Java version is 1.5.0.5 Old versions of java are exploitable and should be removed. Scan started at 19:22:37 29/08/2007 Listing files found while scanning…. C:\WINDOWS\gfgggh.ini C:\WINDOWS\hgggfg.dll C:\windows\system32\mlljigg.dll C:\WINDOWS\system32\tmp8.tmp.dll Beginning removal… Attempting to delete C:\WINDOWS\gfgggh.ini C:\WINDOWS\gfgggh.ini Has been deleted! Attempting to delete C:\WINDOWS\hgggfg.dll C:\WINDOWS\hgggfg.dll Has been deleted! Attempting to delete C:\windows\system32\mlljigg.dll C:\windows\system32\mlljigg.dll Could not be deleted. Attempting to delete C:\WINDOWS\system32\tmp8.tmp.dll C:\WINDOWS\system32\tmp8.tmp.dll Has been deleted! Performing Repairs to the registry. Done! VundoFix V6.5.7 Checking Java version… Java version is 1.5.0.5 Old versions of java are exploitable and should be removed. Scan started at 19:46:13 29/08/2007 Listing files found while scanning…. C:\windows\system32\mlljigg.dll Beginning removal… Attempting to delete C:\windows\system32\mlljigg.dll C:\windows\system32\mlljigg.dll Could not be deleted. Performing Repairs to the registry. Done! Beginning removal… Attempting to delete C:\windows\system32\mlljigg.dll C:\windows\system32\mlljigg.dll Could not be deleted. Performing Repairs to the registry. Done! VundoFix V6.5.7 Checking Java version… Java version is 1.5.0.5 Old versions of java are exploitable and should be removed. Scan started at 20:09:44 29/08/2007 Listing files found while scanning…. C:\WINDOWS\effcyy.dll C:\WINDOWS\system32\tmp3.tmp.dll C:\WINDOWS\yycffe.ini Beginning removal… Attempting to delete C:\WINDOWS\effcyy.dll C:\WINDOWS\effcyy.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\tmp3.tmp.dll C:\WINDOWS\system32\tmp3.tmp.dll Has been deleted! Attempting to delete C:\WINDOWS\yycffe.ini C:\WINDOWS\yycffe.ini Has been deleted! Performing Repairs to the registry. Done! VundoFix V6.5.7 Checking Java version… Java version is 1.5.0.5 Old versions of java are exploitable and should be removed. Scan started at 20:22:26 2007-08-29 Listing files found while scanning…. No infected files were found.
ComboFix log:
ComboFix 07-08-29.3 - "Christine" 2007-08-29 20:30:49.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.348 [GMT 1:00]
* Created a new restore point
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\CHRIST~1\APPLIC~1\tmp1.tmp.exe
C:\DOCUME~1\CHRIST~1\APPLIC~1\tmp12.tmp.exe
C:\DOCUME~1\CHRIST~1\APPLIC~1\tmp2.tmp.exe
C:\DOCUME~1\CHRIST~1\APPLIC~1\tmp3.tmp.exe
C:\DOCUME~1\CHRIST~1\APPLIC~1\tmp6.tmp.exe
C:\DOCUME~1\CHRIST~1\APPLIC~1\tmp6B.tmp.exe
C:\DOCUME~1\CHRIST~1\APPLIC~1\tmp6C.tmp.exe
C:\DOCUME~1\CHRIST~1\APPLIC~1\tmp6D.tmp.exe
C:\DOCUME~1\CHRIST~1\APPLIC~1\tmp6E.tmp.exe
C:\DOCUME~1\CHRIST~1\APPLIC~1\tmp7.tmp.exe
C:\DOCUME~1\CHRIST~1\APPLIC~1\tmp8.tmp.exe
C:\DOCUME~1\CHRIST~1\APPLIC~1\tmp9.tmp.exe
C:\DOCUME~1\CHRIST~1\APPLIC~1\tmp99.tmp.exe
C:\DOCUME~1\CHRIST~1\APPLIC~1\tmp9A.tmp.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\dmcm32.dll
C:\WINDOWS\system32\gebxv.exe
C:\WINDOWS\system32\qwerty12.exe
C:\WINDOWS\system32\tmp6D.tmp.dll
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
——-\LEGACY_DOMAINSERVICE
——-\DomainService
((((((((((((((((((((((((( Files Created from 2007-07-28 to 2007-08-29 )))))))))))))))))))))))))))))))
2007-08-29 20:25 d——– C:\Program Files\Trend Micro
2007-08-29 20:09 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-29 19:22 d——– C:\VundoFix Backups
2007-08-27 17:12 d——– C:\DOCUME~1\CHRIST~1\.housecall6.6
2007-08-27 17:01 613,469 –a—— C:\WINDOWS\system32\dn0c20b90c.dat
2007-08-26 13:53 94,713 –a—— C:\WINDOWS\system32\kbdbnt.dll
2007-08-20 19:31 d——– C:\Program Files\OpenOffice.org 2.2
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-27 21:48 ——— d——– C:\DOCUME~1\CHRIST~1\APPLIC~1\OpenOffice.org2
2007-08-24 19:03 ——— d——– C:\Program Files\EPSON
2007-07-17 20:24 ——— d——– C:\DOCUME~1\NETWOR~1\APPLIC~1\Juniper Networks
2007-07-13 23:20 ——— d——– C:\DOCUME~1\LOCALS~1\APPLIC~1\Juniper Networks
2007-07-13 23:13 ——— d——– C:\DOCUME~1\CHRIST~1\APPLIC~1\Juniper Networks
2007-07-13 23:04 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Juniper Networks
2007-07-13 22:45 ——— d——– C:\Program Files\Neoteris
2007-07-13 22:44 ——— d——– C:\Program Files\Juniper Networks
2007-07-12 18:47 ——— d——– C:\Program Files\Dofus
2005-03-24 18:13 28672 –a—— C:\Program Files\shutdown.exe
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Disc Detector"="C:\Program Files\Creative\ShareDLL\CtNotify.exe" [2001-12-26 02:00]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 01:00]
"CTSysVol"="C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe" [2003-09-17 10:43]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2005-08-02 16:35]
"nwiz"="nwiz.exe" [2005-08-02 16:35 C:\WINDOWS\system32\nwiz.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 00:56 C:\WINDOWS\system32\bthprops.cpl]
"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2005-08-02 16:35]
"Control Center"="C:\Program Files\ASUS\WLAN Card Utilities\Center.exe" [2004-02-24 13:17]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2005-03-24 00:26]
"itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [2005-12-04 17:38]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\Program Files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 22:48]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0\bin\jusched.exe" [2007-08-20 19:30]
"\\azure\EPSON Stylus Photo 900"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0XIC1.exe" [2002-12-10 03:00]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoUserNameInStartMenu"=1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\kbdbnt]
kbdbnt.dll 2007-08-26 13:53 94713 C:\WINDOWS\system32\kbdbnt.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Christine^Start Menu^Programs^Startup^OpenOffice.org 2.0.lnk]
path=C:\Documents and Settings\Christine\Start Menu\Programs\Startup\OpenOffice.org 2.0.lnk
backup=C:\WINDOWS\pss\OpenOffice.org 2.0.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BandwidthMonitor]
C:\Program Files\BandwidthMonitor\BWMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files\Steam\Steam.exe -silent
R1 NEOFLTR_550_11711;Juniper Networks TDI Filter Driver (NEOFLTR_550_11711);\??\C:\WINDOWS\system32\Drivers\NEOFLTR_550_11711.SYS
R1 SSHDRV65;SSHDRV65;\??\C:\WINDOWS\system32\drivers\SSHDRV65.sys
R1 vcdrom;Virtual CD-ROM Device Driver;\??\C:\WINDOWS\system32\drivers\VCdRom.sys
R2 SVKP;SVKP;\??\C:\WINDOWS\system32\SVKP.sys
R3 P17;Sound Blaster Live! 24-bit;C:\WINDOWS\system32\drivers\P17.sys
R3 Point32;Microsoft IntelliPoint Filter Driver;C:\WINDOWS\system32\DRIVERS\point32.sys
R3 W8100PCI;ASUS 802.11b/g Driver for Windows XP;C:\WINDOWS\system32\DRIVERS\mrv8k51.sys
S3 ASNDIS5;ASNDIS5 Protocol Driver;\??\C:\WINDOWS\system32\ASNDIS5.SYS
S3 AWINDIS5;AWINDIS5 Protocol Driver;\??\C:\WINDOWS\System32\AWINDIS5.SYS
S3 ne2000;Novell/Eagle NE2000 Adapter Driver;C:\WINDOWS\system32\DRIVERS\ne2000.sys
S3 NETGEAR_WG311T_SERVICE;NETGEAR WG311T Wireless Adapter Service;C:\WINDOWS\system32\DRIVERS\wg311tn5.sys
S3 oUltraf;oUltraf;\??\C:\DOCUME~1\CHRIST~1\LOCALS~1\Temp\oUltraf.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\Y]
AutoRun\command- Y:\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\Z]
AutoRun\command- Z:\Autorun.exe
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-29 20:39:47
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"\\\\azure\\EPSON Stylus Photo 900"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_S0XIC1.EXE /P30 \"\\\\azure\\EPSON Stylus Photo 900\" /O6 \"USB002\" /M \"Stylus Photo 900\""
Completion time: 2007-08-29 20:41:09 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-08-29 20:41
— E O F —
ComboFix quarantined files log:
2007-08-26 13:54 124685 –a—— C:\Qoobox\Quarantine\C\DOCUME~1\CHRIST~1\APPLIC~1\tmp6B.tmp.exe.vir 2007-08-26 13:54 55235 –a—— C:\Qoobox\Quarantine\C\WINDOWS\system32\qwerty12.exe.vir 2007-08-26 13:54 55330 –a—— C:\Qoobox\Quarantine\C\DOCUME~1\CHRIST~1\APPLIC~1\tmp6C.tmp.exe.vir 2007-08-26 13:54 58798 –a—— C:\Qoobox\Quarantine\C\DOCUME~1\CHRIST~1\APPLIC~1\tmp6E.tmp.exe.vir 2007-08-26 13:54 64652 –a—— C:\Qoobox\Quarantine\C\WINDOWS\system32\tmp6D.tmp.dll.vir 2007-08-26 13:54 79635 –a—— C:\Qoobox\Quarantine\C\DOCUME~1\CHRIST~1\APPLIC~1\tmp6D.tmp.exe.vir 2007-08-27 17:01 55330 –a—— C:\Qoobox\Quarantine\C\DOCUME~1\CHRIST~1\APPLIC~1\tmp99.tmp.exe.vir 2007-08-27 17:01 58798 –a—— C:\Qoobox\Quarantine\C\DOCUME~1\CHRIST~1\APPLIC~1\tmp9A.tmp.exe.vir 2007-08-27 21:50 124609 –a—— C:\Qoobox\Quarantine\C\DOCUME~1\CHRIST~1\APPLIC~1\tmp6.tmp.exe.vir 2007-08-27 21:50 55330 –a—— C:\Qoobox\Quarantine\C\DOCUME~1\CHRIST~1\APPLIC~1\tmp9.tmp.exe.vir 2007-08-27 21:50 58798 –a—— C:\Qoobox\Quarantine\C\DOCUME~1\CHRIST~1\APPLIC~1\tmp7.tmp.exe.vir 2007-08-27 21:50 79578 –a—— C:\Qoobox\Quarantine\C\DOCUME~1\CHRIST~1\APPLIC~1\tmp8.tmp.exe.vir 2007-08-29 19:08 55333 –a—— C:\Qoobox\Quarantine\C\DOCUME~1\CHRIST~1\APPLIC~1\tmp12.tmp.exe.vir 2007-08-29 20:05 105476 –a—— C:\Qoobox\Quarantine\C\WINDOWS\system32\gebxv.exe.vir 2007-08-29 20:05 92778 –a—— C:\Qoobox\Quarantine\C\WINDOWS\system32\dmcm32.dll.vir 2007-08-29 20:08 124760 –a—— C:\Qoobox\Quarantine\C\DOCUME~1\CHRIST~1\APPLIC~1\tmp1.tmp.exe.vir 2007-08-29 20:08 55333 –a—— C:\Qoobox\Quarantine\C\DOCUME~1\CHRIST~1\APPLIC~1\tmp2.tmp.exe.vir 2007-08-29 20:10 131 –a—— C:\Qoobox\Quarantine\C\WINDOWS\cookies.ini.vir 2007-08-29 20:10 79552 –a—— C:\Qoobox\Quarantine\C\DOCUME~1\CHRIST~1\APPLIC~1\tmp3.tmp.exe.vir 2007-08-29 20:34 154 –a—— C:\Qoobox\Quarantine\catchme.log 2007-08-29 20:34 2956 –a—— C:\Qoobox\Quarantine\Registry_backups\services_DomainService.reg.cf 2007-08-29 20:34 846 –a—— C:\Qoobox\Quarantine\Registry_backups\LEGACY_DOMAINSERVICE.reg.cf 2007-08-29 20:34 90656 –a—— C:\Qoobox\Quarantine\catchme2007-08-29_203946.06.zip 2007-08-29 20:40 717602 –a—— C:\Qoobox\snapshot_2007-08-29_204029.65.cf Folder PATH listing Volume serial number is 0C20-B90C C:\QOOBOX | snapshot_2007-08-29_204029.65.cf | \—Quarantine | catchme.log | catchme2007-08-29_203946.06.zip | +—C | +—ComboFix | +—DOCUME~1 | | \—CHRIST~1 | | \—APPLIC~1 | | tmp1.tmp.exe.vir | | tmp12.tmp.exe.vir | | tmp2.tmp.exe.vir | | tmp3.tmp.exe.vir | | tmp6.tmp.exe.vir | | tmp6B.tmp.exe.vir | | tmp6C.tmp.exe.vir | | tmp6D.tmp.exe.vir | | tmp6E.tmp.exe.vir | | tmp7.tmp.exe.vir | | tmp8.tmp.exe.vir | | tmp9.tmp.exe.vir | | tmp99.tmp.exe.vir | | tmp9A.tmp.exe.vir | | | \—WINDOWS | | cookies.ini.vir | | | \—system32 | dmcm32.dll.vir | gebxv.exe.vir | qwerty12.exe.vir | tmp6D.tmp.dll.vir | \—Registry_backups LEGACY_DOMAINSERVICE.reg.cf services_DomainService.reg.cf
And a current HijackThis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:16:03, on 29/08/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Documents and Settings\Christine\Desktop\Peet\procexp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Control Center] C:\Program Files\ASUS\WLAN Card Utilities\Center.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [\\azure\EPSON Stylus Photo 900] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0XIC1.EXE /P30 "\\azure\EPSON Stylus Photo 900" /O6 "USB002" /M "Stylus Photo 900"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Office Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{377076CA-CDC2-41ED-97E8-C5BF78C7D476}: NameServer = 10.0.0.138
O17 - HKLM\System\CCS\Services\Tcpip\..\{E4A027E8-D7CB-41D3-A889-A9A5B4320977}: NameServer = 10.0.0.138
O17 - HKLM\System\CS1\Services\Tcpip\..\{377076CA-CDC2-41ED-97E8-C5BF78C7D476}: NameServer = 10.0.0.138
O20 - Winlogon Notify: kbdbnt - C:\WINDOWS\SYSTEM32\kbdbnt.dll
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
–
End of file - 4111 bytes
This one strikes me as suspicious, but HijackThis can't remove it:
O20 - Winlogon Notify: kbdbnt - C:\WINDOWS\SYSTEM32\kbdbnt.dll
TIA for any help proceeding
Peet
EDIT: Preview broke my post =(