omiyage
Topic Starter
Hello!
I have never had any virus or malware problems with my PC until Internet Explorer and Firefox started to behave strangely about a week ago with constant pop-ups and rogue spyware program ads and such. I do frequent checks with avast and Spybot. Avast did not find any risks on my PC, even with the latest update. Here are my HJT and Spybot logs. Please advice! I'm getting desperate. Thanks in advance!
The latest HijackThis log:
Logfile of HijackThis v1.99.1
Scan saved at 17:45:17, on 26.02.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programfiler\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Programfiler\Alwil Software\Avast4\aswUpdSv.exe
C:\Programfiler\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Programfiler\Intel\Intel Application Accelerator\iaanotif.exe
C:\Programfiler\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programfiler\Messenger\msmsgs.exe
C:\Programfiler\Microsoft ActiveSync\wcescomm.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Programfiler\Intel\Intel Application Accelerator\iaantmon.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\MICROS~4\rapimgr.exe
C:\Programfiler\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Programfiler\Alwil Software\Avast4\ashMaiSv.exe
C:\Programfiler\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programfiler\Outlook Express\MSIMN.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Programfiler\Mozilla Firefox\firefox.exe
C:\Programfiler\Hijackthis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger
O4 - HKLM\..\Run: [IAAnotif] "C:\Programfiler\Intel\Intel Application Accelerator\iaanotif.exe"
O4 - HKLM\..\Run: [CTSysVol] "C:\Programfiler\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe" /r
O4 - HKLM\..\Run: [ATIPTA] "C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [a4acc9ca] rundll32.exe "C:\WINDOWS\system32\khghgmlp.dll",b
O4 - HKLM\..\Run: [BMa79ffa56] Rundll32.exe "C:\WINDOWS\system32\hdipfgfd.dll",s
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programfiler\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Programfiler\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Programfiler\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Programfiler\EmpirePokerMaster\EmpirePoker\RunEPoker.exe
O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Programfiler\EmpirePokerMaster\EmpirePoker\RunEPoker.exe
O9 - Extra button: Oppslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (Nedlastningsadministratorkontroll) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.1.6.cab
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Programfiler\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programfiler\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programfiler\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programfiler\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Programfiler\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Programfiler\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programfiler\Fellesfiler\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Programfiler\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Norman\Nvc\BIN\nipsvc.exe (file missing)
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Programfiler\Webroot\Spy Sweeper\SpySweeper.exe
The latest Spybot log:
Virtumonde: [SBI $42352499] User settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-3263487750-3685434837-3920864227-1006\Software\Microsoft\rdfa
Virtumonde: [SBI $47E741CD] Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws
Virtumonde: [SBI $7342F9D9] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-3263487750-3685434837-3920864227-1006\Software\Microsoft\aldd
Virtumonde.Dll: [SBI $6E058324] Library (File, nothing done)
C:\WINDOWS\SYSTEM32\sldkjkda.dll
LinkSynergy: [SBI $4CDCC3D5] Tracking cookie (Internet Explorer: Eirik) (Cookie, nothing done)
Statcounter: [SBI $4CDCC3D5] Tracking cookie (Internet Explorer: Eirik) (Cookie, nothing done)
DoubleClick: [SBI $4CDCC3D5] Tracking cookie (Internet Explorer: Eirik) (Cookie, nothing done)
MediaPlex: [SBI $4CDCC3D5] Tracking cookie (Internet Explorer: Eirik) (Cookie, nothing done)
AdRevolver: [SBI $4CDCC3D5] Tracking cookie (Internet Explorer: Eirik) (Cookie, nothing done)
AdRevolver: [SBI $4CDCC3D5] Tracking cookie (Internet Explorer: Eirik) (Cookie, nothing done)
Tradedoubler: [SBI $4CDCC3D5] Tracking cookie (Internet Explorer: Eirik) (Cookie, nothing done)
Zedo: [SBI $4CDCC3D5] Tracking cookie (Internet Explorer: Eirik) (Cookie, nothing done)
AdRevolver: [SBI $4CDCC3D5] Tracking cookie (Internet Explorer: Eirik) (Cookie, nothing done)
MediaPlex: [SBI $4CDCC3D5] Tracking cookie (Firefox: default) (Cookie, nothing done)
Vario.AntiVirus: [SBI $4CDCC3D5] Tracking cookie (Firefox: default) (Cookie, nothing done)
Vario.AntiVirus: [SBI $4CDCC3D5] Tracking cookie (Firefox: default) (Cookie, nothing done)
Vario.AntiVirus: [SBI $4CDCC3D5] Tracking cookie (Firefox: default) (Cookie, nothing done)
Vario.AntiVirus: [SBI $4CDCC3D5] Tracking cookie (Firefox: default) (Cookie, nothing done)
Vario.AntiVirus: [SBI $4CDCC3D5] Tracking cookie (Firefox: default) (Cookie, nothing done)
Vario.AntiVirus: [SBI $4CDCC3D5] Tracking cookie (Firefox: default) (Cookie, nothing done)
Vario.AntiVirus: [SBI $4CDCC3D5] Tracking cookie (Firefox: default) (Cookie, nothing done)
Vario.AntiVirus: [SBI $4CDCC3D5] Tracking cookie (Firefox: default) (Cookie, nothing done)
Vario.AntiVirus: [SBI $4CDCC3D5] Tracking cookie (Firefox: default) (Cookie, nothing done)
Vario.AntiVirus: [SBI $4CDCC3D5] Tracking cookie (Firefox: default) (Cookie, nothing done)
Vario.AntiVirus: [SBI $4CDCC3D5] Tracking cookie (Firefox: default) (Cookie, nothing done)
Vario.AntiVirus: [SBI $4CDCC3D5] Tracking cookie (Firefox: default) (Cookie, nothing done)
Statcounter: [SBI $4CDCC3D5] Tracking cookie (Firefox: default) (Cookie, nothing done)
Statcounter: [SBI $4CDCC3D5] Tracking cookie (Firefox: default) (Cookie, nothing done)
Vario.AntiVirus: [SBI $4CDCC3D5] Tracking cookie (Firefox: default) (Cookie, nothing done)
Vario.AntiVirus: [SBI $4CDCC3D5] Tracking cookie (Firefox: default) (Cookie, nothing done)
Vario.AntiVirus: [SBI $4CDCC3D5] Tracking cookie (Firefox: default) (Cookie, nothing done)
Vario.AntiVirus: [SBI $4CDCC3D5] Tracking cookie (Firefox: default) (Cookie, nothing done)
Vario.AntiVirus: [SBI $4CDCC3D5] Tracking cookie (Firefox: default) (Cookie, nothing done)
I have never had any virus or malware problems with my PC until Internet Explorer and Firefox started to behave strangely about a week ago with constant pop-ups and rogue spyware program ads and such. I do frequent checks with avast and Spybot. Avast did not find any risks on my PC, even with the latest update. Here are my HJT and Spybot logs. Please advice! I'm getting desperate. Thanks in advance!
The latest HijackThis log:
Logfile of HijackThis v1.99.1
Scan saved at 17:45:17, on 26.02.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programfiler\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Programfiler\Alwil Software\Avast4\aswUpdSv.exe
C:\Programfiler\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Programfiler\Intel\Intel Application Accelerator\iaanotif.exe
C:\Programfiler\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programfiler\Messenger\msmsgs.exe
C:\Programfiler\Microsoft ActiveSync\wcescomm.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Programfiler\Intel\Intel Application Accelerator\iaantmon.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\MICROS~4\rapimgr.exe
C:\Programfiler\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Programfiler\Alwil Software\Avast4\ashMaiSv.exe
C:\Programfiler\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programfiler\Outlook Express\MSIMN.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Programfiler\Mozilla Firefox\firefox.exe
C:\Programfiler\Hijackthis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger
O4 - HKLM\..\Run: [IAAnotif] "C:\Programfiler\Intel\Intel Application Accelerator\iaanotif.exe"
O4 - HKLM\..\Run: [CTSysVol] "C:\Programfiler\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe" /r
O4 - HKLM\..\Run: [ATIPTA] "C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [a4acc9ca] rundll32.exe "C:\WINDOWS\system32\khghgmlp.dll",b
O4 - HKLM\..\Run: [BMa79ffa56] Rundll32.exe "C:\WINDOWS\system32\hdipfgfd.dll",s
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programfiler\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Programfiler\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Programfiler\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Programfiler\EmpirePokerMaster\EmpirePoker\RunEPoker.exe
O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Programfiler\EmpirePokerMaster\EmpirePoker\RunEPoker.exe
O9 - Extra button: Oppslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (Nedlastningsadministratorkontroll) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.1.6.cab
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Programfiler\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Programfiler\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Programfiler\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programfiler\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Programfiler\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Programfiler\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programfiler\Fellesfiler\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Programfiler\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Norman\Nvc\BIN\nipsvc.exe (file missing)
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Programfiler\Webroot\Spy Sweeper\SpySweeper.exe
The latest Spybot log:
Virtumonde: [SBI $42352499] User settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-3263487750-3685434837-3920864227-1006\Software\Microsoft\rdfa
Virtumonde: [SBI $47E741CD] Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws
Virtumonde: [SBI $7342F9D9] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-3263487750-3685434837-3920864227-1006\Software\Microsoft\aldd
Virtumonde.Dll: [SBI $6E058324] Library (File, nothing done)
C:\WINDOWS\SYSTEM32\sldkjkda.dll
LinkSynergy: [SBI $4CDCC3D5] Tracking cookie (Internet Explorer: Eirik) (Cookie, nothing done)
Statcounter: [SBI $4CDCC3D5] Tracking cookie (Internet Explorer: Eirik) (Cookie, nothing done)
DoubleClick: [SBI $4CDCC3D5] Tracking cookie (Internet Explorer: Eirik) (Cookie, nothing done)
MediaPlex: [SBI $4CDCC3D5] Tracking cookie (Internet Explorer: Eirik) (Cookie, nothing done)
AdRevolver: [SBI $4CDCC3D5] Tracking cookie (Internet Explorer: Eirik) (Cookie, nothing done)
AdRevolver: [SBI $4CDCC3D5] Tracking cookie (Internet Explorer: Eirik) (Cookie, nothing done)
Tradedoubler: [SBI $4CDCC3D5] Tracking cookie (Internet Explorer: Eirik) (Cookie, nothing done)
Zedo: [SBI $4CDCC3D5] Tracking cookie (Internet Explorer: Eirik) (Cookie, nothing done)
AdRevolver: [SBI $4CDCC3D5] Tracking cookie (Internet Explorer: Eirik) (Cookie, nothing done)
MediaPlex: [SBI $4CDCC3D5] Tracking cookie (Firefox: default) (Cookie, nothing done)
Vario.AntiVirus: [SBI $4CDCC3D5] Tracking cookie (Firefox: default) (Cookie, nothing done)
Vario.AntiVirus: [SBI $4CDCC3D5] Tracking cookie (Firefox: default) (Cookie, nothing done)
Vario.AntiVirus: [SBI $4CDCC3D5] Tracking cookie (Firefox: default) (Cookie, nothing done)
Vario.AntiVirus: [SBI $4CDCC3D5] Tracking cookie (Firefox: default) (Cookie, nothing done)
Vario.AntiVirus: [SBI $4CDCC3D5] Tracking cookie (Firefox: default) (Cookie, nothing done)
Vario.AntiVirus: [SBI $4CDCC3D5] Tracking cookie (Firefox: default) (Cookie, nothing done)
Vario.AntiVirus: [SBI $4CDCC3D5] Tracking cookie (Firefox: default) (Cookie, nothing done)
Vario.AntiVirus: [SBI $4CDCC3D5] Tracking cookie (Firefox: default) (Cookie, nothing done)
Vario.AntiVirus: [SBI $4CDCC3D5] Tracking cookie (Firefox: default) (Cookie, nothing done)
Vario.AntiVirus: [SBI $4CDCC3D5] Tracking cookie (Firefox: default) (Cookie, nothing done)
Vario.AntiVirus: [SBI $4CDCC3D5] Tracking cookie (Firefox: default) (Cookie, nothing done)
Vario.AntiVirus: [SBI $4CDCC3D5] Tracking cookie (Firefox: default) (Cookie, nothing done)
Statcounter: [SBI $4CDCC3D5] Tracking cookie (Firefox: default) (Cookie, nothing done)
Statcounter: [SBI $4CDCC3D5] Tracking cookie (Firefox: default) (Cookie, nothing done)
Vario.AntiVirus: [SBI $4CDCC3D5] Tracking cookie (Firefox: default) (Cookie, nothing done)
Vario.AntiVirus: [SBI $4CDCC3D5] Tracking cookie (Firefox: default) (Cookie, nothing done)
Vario.AntiVirus: [SBI $4CDCC3D5] Tracking cookie (Firefox: default) (Cookie, nothing done)
Vario.AntiVirus: [SBI $4CDCC3D5] Tracking cookie (Firefox: default) (Cookie, nothing done)
Vario.AntiVirus: [SBI $4CDCC3D5] Tracking cookie (Firefox: default) (Cookie, nothing done)