sgent67
Topic Starter
My son recently downloaded a virus on my PC. The virus was disguised as free anti-virus software, and I now get constant pop-ups asking me to download anti-virus programs. My web explorer home page has been hijacked, and I have located the virus on my C drive, but am unable to delete it. The following file appears to have a non-deletable virus in it: C:\WINDOWS\system32\768890\768890.dll
I downloaded HijackThis as a last attempt to rid my PC of this problem, but do not know where to go from here. This is causing numerous problems with work I do from home, and for my daughters when they are doing their schoolwork. Help would be greatly appreciated! Below is the start-up log I ran from HijackThis:
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Logitech\Bluetooth\LBTSERV.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\arservice.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\PCSecurityShield\The Shield Deluxe 2008\avp.exe
C:\Program Files\Common Files\AOL\1144372511\ee\AOLSoftware.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\Pure Networks\Network Magic\nmapp.exe
C:\Program Files\Logitech\Easy Synchronization\LogitechEasySync.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\Logitech\SetPoint\LBTWiz.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\PCSecurityShield\The Shield Deluxe 2008\avp.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre1.5.0_05\bin\jucheck.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\algg.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\America Online 9.0\waol.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Logitech\Easy Synchronization\servicestub.exe
C:\Program Files\Logitech\Easy Synchronization\LogitechEasySync.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Pure Networks\Router Service\pnroutsv.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\WINDOWS\ehome\RMSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\America Online 9.0\shellmon.exe
C:\Program Files\Hijackthis\HijackThis.exe
————————————————–
Listing of startup folders:
Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
————————————————–
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,
————————————————–
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
ehTray = C:\WINDOWS\ehome\ehtray.exe
AlwaysReady Power Message APP = ARPWRMSG.EXE
NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
nwiz = nwiz.exe /install
RTHDCPL = RTHDCPL.EXE
Recguard = C:\WINDOWS\SMINST\RECGUARD.EXE
PCDrProfiler =
HP Software Update = C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
HostManager = C:\Program Files\Common Files\AOL\1144372511\ee\AOLSoftware.exe
AOLDialer = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
nmapp = "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun
Kernel and Hardware Abstraction Layer = KHALMNPR.EXE
Easy Synchronization = C:\Program Files\Logitech\Easy Synchronization\LogitechEasySync.exe
Logitech Hardware Abstraction Layer = KHALMNPR.EXE
SunJavaUpdateSched = C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
Bluetooth Connection Assistant = LBTWIZ.EXE -silent
ALCMTR = ALCMTR.EXE
hpsysdrv = c:\windows\system\hpsysdrv.exe
RealTray = C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
QuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottime
ANTIVIRUS = C:\Program Files\MSX\MSx.exe
AVP = "C:\Program Files\PCSecurityShield\The Shield Deluxe 2008\avp.exe"
4389d48a = rundll32.exe "C:\WINDOWS\system32\jimuxbtr.dll",b
BM40bae716 = Rundll32.exe "C:\WINDOWS\system32\jrmwmrdj.dll",s
————————————————–
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
Easy Synchronization = C:\Program Files\Logitech\Easy Synchronization\LogitechEasySync.exe –ports
————————————————–
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
LDM = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
ANTIVIRUS = C:\Program Files\MSX\MSx.exe
wblogon = C:\WINDOWS\system32\algg.exe
AOL Fast Start = "C:\Program Files\America Online 9.0\AOL.EXE" -b
AdobeUpdater = C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
————————————————–
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
[AutorunsDisabled]
*No values found*
[OptionalComponents]
=
————————————————–
Load/Run keys from C:\WINDOWS\WIN.INI:
load=*INI section not found*
run=*INI section not found*
Load/Run keys from Registry:
HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows: load=
HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=auwaak.dll
————————————————–
Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*
————————————————–
Enumerating Task Scheduler jobs:
AppleSoftwareUpdate.job
————————————————–
Enumerating Download Program Files:
[ScrabbleCubes Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\SCRABB~1.OCX
CODEBASE = http://www.worldwinner.com/games/v46/scrab…rabblecubes.cab
[SpinTop DRM Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\stg_drm.ocx
CODEBASE = file:///C:/Program%20Files/Chessmaster%20Challenge/Images/stg_drm.ocx
[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\system32\Adobe\Director\SwDir.dll
CODEBASE = http://download.macromedia.com/pub/shockwa…director/sw.cab
[{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}]
CODEBASE = http://ak.exe.imgfarm.com/images/nocache/f…etup1.0.1.0.cab
[{26FCCDF9-A7E1-452A-A73D-7BF7B4D0BA6C}]
CODEBASE = http://pictures.aol.com/ap/Resources/2.0.3…ns.10.4.0.3.cab
[Snapfish Activia]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\SnapfishActivia1000.ocx
CODEBASE = http://www2.snapfish.com/SnapfishActivia.cab
[PowerLoader Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\PowerLoader.dll
CODEBASE = http://powerchallenge.com/applet/PowerLoader.cab
[EPUImageControl Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\EPUWALcontrol.dll
CODEBASE = http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-3-48.cab
[MUWebControl Class]
InProcServer32 = C:\WINDOWS\system32\muweb.dll
CODEBASE = http://www.update.microsoft.com/microsoftu…b?1186660668937
[SecureLogin class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\securelogin.ocx
CODEBASE = http://secure2.comned.com/signuptemplates/…login-devel.cab
[Yahoo! Webcam Upload Wrapper]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\yuplapp.dll
CODEBASE = http://chat.yahoo.com/cab/yuplapp.cab
[Wwlaunch Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\wwlaunch.ocx
CODEBASE = http://www.worldwinner.com/games/shared/wwlaunch.cab
[NeffyLauncherCtl Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\NeffyLauncher.dll
CODEBASE = http://disteng.nefficient.com/disteng/neff…ffyLauncher.cab
[ArmHelper Control]
InProcServer32 = ./Images/armhelper.ocx
CODEBASE = file:///C:/Program%20Files/Chessmaster%20Challenge/Images/armhelper.ocx
[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash9e.ocx
CODEBASE = http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
[InstantAction Game Launcher]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\iaplayer.dll
CODEBASE = http://www.instantaction.com/download/iaplayer.cab
————————————————–
Enumerating ShellServiceObjectDelayLoad items:
PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\system32\stobject.dll
————————————————–
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
smile = C:\Program Files\Applications\wcs.exe
————————————————–
End of report, 11,534 bytes
Report generated in 0.078 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
I downloaded HijackThis as a last attempt to rid my PC of this problem, but do not know where to go from here. This is causing numerous problems with work I do from home, and for my daughters when they are doing their schoolwork. Help would be greatly appreciated! Below is the start-up log I ran from HijackThis:
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Logitech\Bluetooth\LBTSERV.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\arservice.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\PCSecurityShield\The Shield Deluxe 2008\avp.exe
C:\Program Files\Common Files\AOL\1144372511\ee\AOLSoftware.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\Pure Networks\Network Magic\nmapp.exe
C:\Program Files\Logitech\Easy Synchronization\LogitechEasySync.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\Logitech\SetPoint\LBTWiz.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\PCSecurityShield\The Shield Deluxe 2008\avp.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre1.5.0_05\bin\jucheck.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\algg.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\America Online 9.0\waol.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Logitech\Easy Synchronization\servicestub.exe
C:\Program Files\Logitech\Easy Synchronization\LogitechEasySync.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Pure Networks\Router Service\pnroutsv.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\WINDOWS\ehome\RMSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\America Online 9.0\shellmon.exe
C:\Program Files\Hijackthis\HijackThis.exe
————————————————–
Listing of startup folders:
Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
————————————————–
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,
————————————————–
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
ehTray = C:\WINDOWS\ehome\ehtray.exe
AlwaysReady Power Message APP = ARPWRMSG.EXE
NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
nwiz = nwiz.exe /install
RTHDCPL = RTHDCPL.EXE
Recguard = C:\WINDOWS\SMINST\RECGUARD.EXE
PCDrProfiler =
HP Software Update = C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
HostManager = C:\Program Files\Common Files\AOL\1144372511\ee\AOLSoftware.exe
AOLDialer = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
nmapp = "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun
Kernel and Hardware Abstraction Layer = KHALMNPR.EXE
Easy Synchronization = C:\Program Files\Logitech\Easy Synchronization\LogitechEasySync.exe
Logitech Hardware Abstraction Layer = KHALMNPR.EXE
SunJavaUpdateSched = C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
Bluetooth Connection Assistant = LBTWIZ.EXE -silent
ALCMTR = ALCMTR.EXE
hpsysdrv = c:\windows\system\hpsysdrv.exe
RealTray = C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
QuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottime
ANTIVIRUS = C:\Program Files\MSX\MSx.exe
AVP = "C:\Program Files\PCSecurityShield\The Shield Deluxe 2008\avp.exe"
4389d48a = rundll32.exe "C:\WINDOWS\system32\jimuxbtr.dll",b
BM40bae716 = Rundll32.exe "C:\WINDOWS\system32\jrmwmrdj.dll",s
————————————————–
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
Easy Synchronization = C:\Program Files\Logitech\Easy Synchronization\LogitechEasySync.exe –ports
————————————————–
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
LDM = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
ANTIVIRUS = C:\Program Files\MSX\MSx.exe
wblogon = C:\WINDOWS\system32\algg.exe
AOL Fast Start = "C:\Program Files\America Online 9.0\AOL.EXE" -b
AdobeUpdater = C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
————————————————–
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
[AutorunsDisabled]
*No values found*
[OptionalComponents]
=
————————————————–
Load/Run keys from C:\WINDOWS\WIN.INI:
load=*INI section not found*
run=*INI section not found*
Load/Run keys from Registry:
HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows: load=
HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=auwaak.dll
————————————————–
Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*
————————————————–
Enumerating Task Scheduler jobs:
AppleSoftwareUpdate.job
————————————————–
Enumerating Download Program Files:
[ScrabbleCubes Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\SCRABB~1.OCX
CODEBASE = http://www.worldwinner.com/games/v46/scrab…rabblecubes.cab
[SpinTop DRM Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\stg_drm.ocx
CODEBASE = file:///C:/Program%20Files/Chessmaster%20Challenge/Images/stg_drm.ocx
[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\system32\Adobe\Director\SwDir.dll
CODEBASE = http://download.macromedia.com/pub/shockwa…director/sw.cab
[{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}]
CODEBASE = http://ak.exe.imgfarm.com/images/nocache/f…etup1.0.1.0.cab
[{26FCCDF9-A7E1-452A-A73D-7BF7B4D0BA6C}]
CODEBASE = http://pictures.aol.com/ap/Resources/2.0.3…ns.10.4.0.3.cab
[Snapfish Activia]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\SnapfishActivia1000.ocx
CODEBASE = http://www2.snapfish.com/SnapfishActivia.cab
[PowerLoader Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\PowerLoader.dll
CODEBASE = http://powerchallenge.com/applet/PowerLoader.cab
[EPUImageControl Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\EPUWALcontrol.dll
CODEBASE = http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-3-48.cab
[MUWebControl Class]
InProcServer32 = C:\WINDOWS\system32\muweb.dll
CODEBASE = http://www.update.microsoft.com/microsoftu…b?1186660668937
[SecureLogin class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\securelogin.ocx
CODEBASE = http://secure2.comned.com/signuptemplates/…login-devel.cab
[Yahoo! Webcam Upload Wrapper]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\yuplapp.dll
CODEBASE = http://chat.yahoo.com/cab/yuplapp.cab
[Wwlaunch Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\wwlaunch.ocx
CODEBASE = http://www.worldwinner.com/games/shared/wwlaunch.cab
[NeffyLauncherCtl Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\NeffyLauncher.dll
CODEBASE = http://disteng.nefficient.com/disteng/neff…ffyLauncher.cab
[ArmHelper Control]
InProcServer32 = ./Images/armhelper.ocx
CODEBASE = file:///C:/Program%20Files/Chessmaster%20Challenge/Images/armhelper.ocx
[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash9e.ocx
CODEBASE = http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
[InstantAction Game Launcher]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\iaplayer.dll
CODEBASE = http://www.instantaction.com/download/iaplayer.cab
————————————————–
Enumerating ShellServiceObjectDelayLoad items:
PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\system32\stobject.dll
————————————————–
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
smile = C:\Program Files\Applications\wcs.exe
————————————————–
End of report, 11,534 bytes
Report generated in 0.078 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only