teeps
Topic Starter
I am cleaning up a fun one this time.
1) Installed and ran Adaware 2007 - found:
- Family Id: 763 Name: Virtumonde Category: Malware TAI:10
- Family Id: 1032 Name: Win32.TrojanDownloader.Small Category: Malware TAI:7
2) Installed Spybot S&D 1.5 - found:
ZenoSearch: [SBI $31BD3E09] Uninstall settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Enhanced Ads by Think-Adz
ZenoSearch: [SBI $676AEA50] Uninstall settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Think-Adz Search Assistant
ZenoSearch: [SBI $C9F43479] Link (File, nothing done)
C:\Documents and Settings\Owner\Start Menu\Programs\Startup\Think-Adz.lnk
ZenoSearch: [SBI $7E6E3149] Text file (File, nothing done)
C:\WINDOWS\system32\msnav32.ax
Smitfraud-C.: [SBI $3D8C0DCC] Program directory (Directory, nothing done)
C:\Program Files\InetGet2\
Wintouch: [SBI $8C435B3D] Uninstall settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-3655754979-698933516-4157319073-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinTouch
Wintouch: [SBI $351DB170] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-3655754979-698933516-4157319073-1003\Software\WinTouch
Wintouch: [SBI $A30B133B] Text file (File, nothing done)
C:\Documents and Settings\Owner\Application Data\WinTouch\wintouch.cfg
Wintouch: [SBI $34B98A05] Executable (File, nothing done)
C:\Documents and Settings\Owner\Application Data\WinTouch\WTUninstaller.exe
Virtumonde: [SBI $7342F9D9] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-3655754979-698933516-4157319073-1003\Software\Microsoft\aldd
3) Since things were acting a little funky, I thought that the Trend Micro AV installed may have been compromised. So I installed BitDefender 8 free and did a scan… Found:
C:\Program Files\CPV\CPV8.dll Infected Trojan.BHO.Agent.U
C:\Program Files\CPV\CPV8.dll Deleted
C:\WINDOWS\b155.exe Infected Trojan.BHO.Agent.U
C:\WINDOWS\b155.exe Deleted
C:\WINDOWS\system32\dwdsrngt.exe Infected Trojan.Agent.AZT
C:\WINDOWS\system32\dwdsrngt.exe Deleted
C:\WINDOWS\system32\f02WtR\f02WtR1065.exe Infected Trojan.Downloader.VB.VGA
C:\WINDOWS\system32\f02WtR\f02WtR1065.exe Disinfection failed
C:\WINDOWS\system32\f02WtR\f02WtR1065.exe Moved
C:\WINDOWS\system32\lldsrngm.exe Infected Trojan.Agent.AZT
C:\WINDOWS\system32\lldsrngm.exe Deleted
C:\WINDOWS\system32\pac.txt Infected Trojan.Downloader.VB.VPG
C:\WINDOWS\system32\pac.txt Deleted
4) I then ran AVG AntiSpyware in safemode and found:
C:\WINDOWS\system32\nwinmmdt.exe -> Adware.ZenoSearch : No action taken
C:\System Volume Information\_restore{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP283\A0035627.exe - > Downloader.Small.buy : No action taken
C:\System Volume Information\_restore{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP284\A0036703.exe -> Downloader.VB.awj : No action taken
C:\System Volume Information\_restore{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP283\A0036671.exe -> Not-A-Virus.Adware.ZenoSearch : No action taken
C:\WINDOWS\system32\nwinmmds.exe -> Not-A-Virus.Adware.ZenoSearch : No action taken
C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\8SKJTK9H\alb[2].htm -> Not-A-Virus.Exploit.HTML.IframeBof :No action taken
C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\NZ14OVHS\altarserver[1].htm -> Not-A-Virus.Exploit.HTML.IframeBof :No action taken
C:\Documents and Settings\ Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\NZ14OVHS\cassock[1].htm -> Not-A-Virus.Exploit.HTML.IframeBof : No action taken
5) Lastly I ran the ATFCleaner and used the select all option.
After the above steps, explorer.exe now will not keep itself running. It will load up for about 10 seconds then crash. It is stuck in an endless loop of loading and crashing. I have to run things now through the task manager run menu item. I first noticed this behavior after I told Spybot S&D to remove smitfraud.
I also tried to run sfc /scannow thinking that some of the win files were corrupt. No luck…
Here is my current hijackthis:
Logfile of HijackThis v1.99.1
Scan saved at 10:42:25 PM, on 4/17/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\taskmgr.exe
G:\CleanupTools_updated_02102008\AntiSpyware\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5,1,1,0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Antivirus\pccguide.exe"
O4 - HKLM\..\Run: [PCClient.exe] "C:\Program Files\Trend Micro\Antivirus\PCClient.exe"
O4 - HKLM\..\Run: [TM Outbreak Agent] "C:\Program Files\Trend Micro\Antivirus\TMOAgent.exe" /run
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [BDMCon] "C:\Program Files\Softwin\BitDefender8\bdmcon.exe"
O4 - HKLM\..\Run: [BDNewsAgent] "C:\Program Files\Softwin\BitDefender8\bdnagent.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Antivirus\Tmntsrv.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Antivirus\tmproxy.exe
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)
just ran VundoFix while I was waiting and it didn't turn anything up.
1) Installed and ran Adaware 2007 - found:
- Family Id: 763 Name: Virtumonde Category: Malware TAI:10
- Family Id: 1032 Name: Win32.TrojanDownloader.Small Category: Malware TAI:7
2) Installed Spybot S&D 1.5 - found:
ZenoSearch: [SBI $31BD3E09] Uninstall settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Enhanced Ads by Think-Adz
ZenoSearch: [SBI $676AEA50] Uninstall settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Think-Adz Search Assistant
ZenoSearch: [SBI $C9F43479] Link (File, nothing done)
C:\Documents and Settings\Owner\Start Menu\Programs\Startup\Think-Adz.lnk
ZenoSearch: [SBI $7E6E3149] Text file (File, nothing done)
C:\WINDOWS\system32\msnav32.ax
Smitfraud-C.: [SBI $3D8C0DCC] Program directory (Directory, nothing done)
C:\Program Files\InetGet2\
Wintouch: [SBI $8C435B3D] Uninstall settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-3655754979-698933516-4157319073-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinTouch
Wintouch: [SBI $351DB170] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-3655754979-698933516-4157319073-1003\Software\WinTouch
Wintouch: [SBI $A30B133B] Text file (File, nothing done)
C:\Documents and Settings\Owner\Application Data\WinTouch\wintouch.cfg
Wintouch: [SBI $34B98A05] Executable (File, nothing done)
C:\Documents and Settings\Owner\Application Data\WinTouch\WTUninstaller.exe
Virtumonde: [SBI $7342F9D9] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-3655754979-698933516-4157319073-1003\Software\Microsoft\aldd
3) Since things were acting a little funky, I thought that the Trend Micro AV installed may have been compromised. So I installed BitDefender 8 free and did a scan… Found:
C:\Program Files\CPV\CPV8.dll Infected Trojan.BHO.Agent.U
C:\Program Files\CPV\CPV8.dll Deleted
C:\WINDOWS\b155.exe Infected Trojan.BHO.Agent.U
C:\WINDOWS\b155.exe Deleted
C:\WINDOWS\system32\dwdsrngt.exe Infected Trojan.Agent.AZT
C:\WINDOWS\system32\dwdsrngt.exe Deleted
C:\WINDOWS\system32\f02WtR\f02WtR1065.exe Infected Trojan.Downloader.VB.VGA
C:\WINDOWS\system32\f02WtR\f02WtR1065.exe Disinfection failed
C:\WINDOWS\system32\f02WtR\f02WtR1065.exe Moved
C:\WINDOWS\system32\lldsrngm.exe Infected Trojan.Agent.AZT
C:\WINDOWS\system32\lldsrngm.exe Deleted
C:\WINDOWS\system32\pac.txt Infected Trojan.Downloader.VB.VPG
C:\WINDOWS\system32\pac.txt Deleted
4) I then ran AVG AntiSpyware in safemode and found:
C:\WINDOWS\system32\nwinmmdt.exe -> Adware.ZenoSearch : No action taken
C:\System Volume Information\_restore{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP283\A0035627.exe - > Downloader.Small.buy : No action taken
C:\System Volume Information\_restore{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP284\A0036703.exe -> Downloader.VB.awj : No action taken
C:\System Volume Information\_restore{88A9728D-068D-4BE5-99BD-49CC3FD4BC94}\RP283\A0036671.exe -> Not-A-Virus.Adware.ZenoSearch : No action taken
C:\WINDOWS\system32\nwinmmds.exe -> Not-A-Virus.Adware.ZenoSearch : No action taken
C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\8SKJTK9H\alb[2].htm -> Not-A-Virus.Exploit.HTML.IframeBof :No action taken
C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\NZ14OVHS\altarserver[1].htm -> Not-A-Virus.Exploit.HTML.IframeBof :No action taken
C:\Documents and Settings\ Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\NZ14OVHS\cassock[1].htm -> Not-A-Virus.Exploit.HTML.IframeBof : No action taken
5) Lastly I ran the ATFCleaner and used the select all option.
After the above steps, explorer.exe now will not keep itself running. It will load up for about 10 seconds then crash. It is stuck in an endless loop of loading and crashing. I have to run things now through the task manager run menu item. I first noticed this behavior after I told Spybot S&D to remove smitfraud.
I also tried to run sfc /scannow thinking that some of the win files were corrupt. No luck…
Here is my current hijackthis:
Logfile of HijackThis v1.99.1
Scan saved at 10:42:25 PM, on 4/17/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\taskmgr.exe
G:\CleanupTools_updated_02102008\AntiSpyware\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5,1,1,0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Antivirus\pccguide.exe"
O4 - HKLM\..\Run: [PCClient.exe] "C:\Program Files\Trend Micro\Antivirus\PCClient.exe"
O4 - HKLM\..\Run: [TM Outbreak Agent] "C:\Program Files\Trend Micro\Antivirus\TMOAgent.exe" /run
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [BDMCon] "C:\Program Files\Softwin\BitDefender8\bdmcon.exe"
O4 - HKLM\..\Run: [BDNewsAgent] "C:\Program Files\Softwin\BitDefender8\bdnagent.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Antivirus\Tmntsrv.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Antivirus\tmproxy.exe
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)
just ran VundoFix while I was waiting and it didn't turn anything up.