I've been dealing with an malware assault of which I may be the winner; the only item left is a recurring redirect in IE 6 that is pointing to
http://jl.chura.pl/rc/ and giving me an
HTTP 404 - File not found
Internet Explorer
I have not been able to find whatever is calling up the site.
My question is how do I locate the cause of the redirect and delete it?
Background:
While deleting other malware I ran HijackThis - and the redirect (as a url) is not present.
EDIT: i have included a HJT Report at the end of the background.
Searching around I found that .pl is not listed as a mainstream domain, nor can you buy a url with the domain .pl. Looking further I found this site:
http://www.robtex.com/dns/zief.pl.htmlI do not understand exactly what the purpose of the site is it does have notices of blacklisted domains and appears to host questionable web sites of many domains perhaps it has something to do with dns, however, they have this to say about themselves:
"zief.pl is a domain controlled by two nameservers at zief.pl themselves. They are on different IP networks. Incoming mail for zief.pl is handled by one mailserver also at zief.pl. zief.pl has one IP record. irc.zief.pl, ns2.zief.pl, ns1.zief.pl,
www.zief.pl, dns2.zief.pl and at least five other hosts are subdomains to this hostname. pl is a domain controlled by eight nameservers at pl themselves. All of them are on different IP networks."
I thought the part "at least five other hosts are subdomains to this hostname. pl is a domain controlled by eight nameservers at pl themselves. All of them are on different IP networks" indicated the domain could be a sub-domain, so I attempted to go directly to
http://www.zief.pl and AVG Gave me this:
__________________________
__________
__________
__________
__________
____
Danger: AVG Search-Shield has detected active threats on this page and has blocked access for your protection.
The page you are trying to access has been identified as a known exploit, phishing, or social engineering web site and therefore has been blocked for your safety. Without protection, such as that in the AVG Security Toolbar and AVG, your computer is at risk of being compromised, corrupted or having your identity stolen. Please follow one of the suggestions below to continue.
IP Address: 61.235.117.75
For additional information click here.
Suggestions:
§ Click the Back button on your browser to return to the previous page and choose another link (recommended).
§ If you would like to ignore the warning and continue to the page, click here (not recommended)
__________________________
__________
__________
__________
__________
___
Certainly would appear that someone from this site is connected with the redirect that IE continues trying to open. (
http://jl.chura.pl/rc/)
The site lists the whois info but, I really don't want to go down that rabbit hole . .
I just want to get it off the computer.
My question is how do I locate the cause of the redirect and delete it?
__________________________
__________
__________
__________
__________
_________
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:12:40 PM, on 3/14/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spools
v.exe
C:\Program Files\Common Files\Acronis\Schedule2\sc
hedul2.exe
C:\PROGRA~1\AVG\AVG8\avgwd
svc.exe
C:\WINDOWS\system32\CTSVCC
DA.EXE
C:\Program Files\Citrix\GoToMyPC\g2sv
c.exe
C:\Program Files\Google\Common\Google
Updater\GoogleUpdaterServi
ce.exe
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\Citrix\GoToMyPC\g2co
mm.exe
C:\Program Files\Java\jre6\bin\jqs.ex
e
C:\Program Files\Citrix\GoToMyPC\g2pr
e.exe
C:\Program Files\Citrix\GoToMyPC\g2tr
ay.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\AVG\AVG8\avgam
.exe
C:\PROGRA~1\AVG\AVG8\avgrs
x.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\PROGRA~1\AVG\AVG8\avgns
x.exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\system32\nvsvc3
2.exe
C:\Program Files\Photodex\ProShowGold
\ScsiAcces
s.exe
C:\PROGRA~1\NORTON~1\SPEED
D~1\nopdb.
exe
C:\WINDOWS\system32\Tablet
.exe
C:\PROGRA~1\AVG\AVG8\avgem
c.exe
C:\WINDOWS\system32\WTable
t\TabUserW
.exe
C:\WINDOWS\system32\Tablet
.exe
C:\Program Files\AVG\AVG8\avgcsrvx.ex
e
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\WINDOWS\MXOALDR.EXE
C:\Program Files\Common Files\Logitech\QCDriver\LV
COMS.EXE
C:\PROGRA~1\Logitech\MOUSE
W~1\SYSTEM
\EM_EXEC.E
XE
C:\WINDOWS\system32\RUNDLL
32.EXE
C:\Program Files\Creative\SBAudigy\Su
rround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll
32.exe
C:\WINDOWS\system32\BacsTr
ay.exe
C:\Program Files\DU Meter\DUMeter.exe
C:\WINDOWS\system32\CTHELP
ER.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\TWEAKM~1\TMTra
y.exe
C:\Program Files\Acronis\TrueImageHom
e\TrueImag
eMonitor.e
xe
C:\Program Files\Spamihilator\spamihi
lator.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch
Tray.exe
C:\Program Files\Roxio\Easy Media Creator 8\Drag to Disc\DrgToDsc.exe
C:\Program Files\iTunes\iTunesHelper.
exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Acronis\TrueImageHom
e\Timounte
rMonitor.e
xe
C:\Program Files\Common Files\Acronis\Schedule2\sc
hedhlp.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch
.exe
C:\WINDOWS\system32\ctfmon
.exe
C:\PROGRA~1\AVG\AVG8\avgtr
ay.exe
C:\Program Files\iPod\bin\iPodService
.exe
C:\Program Files\Java\jre6\bin\jusche
d.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\CPSHelpR
unner.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Skype\Phone\Skype.ex
e
C:\Program Files\Citrix\GoToMeeting\3
20\g2mstar
t.exe
C:\Program Files\Citrix\GoToAssist Express Expert\86\g2ax_start.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Citrix\GoToMeeting\3
20\g2mcomm
.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Citrix\GoToMeeting\3
20\g2mlaun
cher.exe
C:\Program Files\Citrix\GoToAssist Express Expert\86\g2ax_comm.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Citrix\GoToAssist Express Expert\86\g2ax_launcherexp
ert.exe
C:\Program Files\Citrix\GoToAssist Express Expert\86\g2ax_uiexpert.ex
e
C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
C:\Program Files\TechSmith\Snagit 9\Snagit32.exe
C:\Program Files\VCOM\PowerDesk\pddlg
hlp.exe
C:\Program Files\TDK\TDKLauncher\TDKL
auncher.ex
e
C:\Program Files\TechSmith\Snagit 9\TSCHelp.exe
C:\Program Files\TechSmith\Snagit 9\SnagPriv.exe
C:\Program Files\TechSmith\Snagit 9\snagiteditor.exe
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\Citrix\GoToMyPC\g2ma
inh.exe
C:\Program Files\Citrix\GoToMyPC\g2ho
st.exe
C:\Program Files\Citrix\GoToMyPC\g2pr
inth.exe
C:\Program Files\Citrix\GoToMyPC\g2au
dioh.exe
C:\Program Files\AVG\AVG8\avgui.exe
C:\Program Files\AVG\AVG8\avgscanx.ex
e
C:\Program Files\AVG\AVG8\avgcsrvx.ex
e
C:\Program Files\Trend Micro\HijackThis\HijackThi
s.exe
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-F
CE54AD9C20
8} - C:\Program Files\TechSmith\Snagit 9\SnagitBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Common Files\Adobe\Acrobat\Active
X\AcroIEHe
lper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-F
A578C2EBDC
3} - C:\Program Files\Common Files\Adobe\Acrobat\Active
X\AcroIEHe
lperShim.d
ll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4
E65E497C8C
0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-2
06D7942484
F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Desktop Search Capture - {7c1ce531-09e9-4fc5-9803-1
c295661578
6} - C:\Program Files\Google\Google Desktop Search\GoogleDesktopIE.dll
O2 - BHO: TweakMASTER PRO Component - {7DAAC7DE-9EF0-4FF0-BFA5-A
FF3E899054
C} - C:\PROGRA~1\TWEAKM~1\Tweak
BHO.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0
445EE16191
0} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClien
t.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9
C25C1C588A
9} - C:\Program Files\Java\jre6\bin\jp2ssv
.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-E
ABFE594F69
C} - C:\Program Files\Java\jre6\lib\deploy
\jqs\ie\jq
s_plugin.d
ll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0
819E2EAAC9
3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClien
t.dll
O3 - Toolbar: Snagit - {8FF5E183-ABDE-46EB-B09E-D
2AAB95CABE
3} - C:\Program Files\TechSmith\Snagit 9\SnagitIEAddin.dll
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [MXO Auto Loader] C:\WINDOWS\MXOALDR.EXE
O4 - HKLM\..\Run: [LVCOMS] "C:\Program Files\Common Files\Logitech\QCDriver\LV
COMS.EXE"
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSE
W~1\SYSTEM
\EM_EXEC.E
XE
O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe
O4 - HKLM\..\Run: [ccApp] "c:\Documents and Settings\John\Local Settings\Temp\NAV\Support\
ccCommon\c
cCommon\cc
App.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IM
JPMIG.EXE"
/Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IME
KRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] "C:\WINDOWS\System32\IME\P
INTLGNT\Im
ScInst.exe
" /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] "C:\WINDOWS\System32\IME\T
INTLGNT\TI
NTSETP.EXE
" /SYNC
O4 - HKLM\..\Run: [PHIME2002A] "C:\WINDOWS\System32\IME\T
INTLGNT\TI
NTSETP.EXE
" /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.
dll,NvStar
tup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTr
ay.dll,NvT
askbarInit
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROG
RAM\ADGJDe
t.exe"
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Su
rround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [bacstray] BacsTray.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\Update
Service\is
sch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\Update
Service\is
uspm.exe" -startup
O4 - HKLM\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [TweakMASTER] C:\PROGRA~1\TWEAKM~1\TMTra
y.exe
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHom
e\TrueImag
eMonitor.e
xe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgd
update.exe
" -Embedding -boot
O4 - HKLM\..\Run: [Spamihilator] "C:\Program Files\Spamihilator\spamihi
lator.exe"
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch
Tray.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 8\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.
exe"
O4 - HKLM\..\Run: [GoToMyPC] "C:\Program Files\Citrix\GoToMyPC\g2sv
c.exe" -logon
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHom
e\Timounte
rMonitor.e
xe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\sc
hedhlp.exe
"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtr
ay.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusche
d.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.ex
e" /nosplash /minimized
O4 - HKCU\..\Run: [GoToMeeting] C:\Program Files\Citrix\GoToMeeting\3
20\g2mstar
t.exe "/Trigger RunAtLogon"
O4 - HKCU\..\Run: [GoToAssist Express Expert] "C:\Program Files\Citrix\GoToAssist Express Expert\86\g2ax_start.exe" "/Trigger RunAtLogon"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe
O4 - HKCU\..\Run: [cdloader] "C:\Documents and Settings\John\Application Data\mjusbsp\cdloader2.exe
" MAGICJACK
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICR
OS~1\DW\dw
trig20.exe
" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICR
OS~1\DW\dw
trig20.exe
" -t (User 'Default user')
O4 - Startup: Dialog Helper.lnk = C:\Program Files\VCOM\PowerDesk\pddlg
hlp.exe
O4 - Startup: TDK Launcher.lnk = C:\Program Files\TDK\TDKLauncher\TDKL
auncher.ex
e
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Ad
obe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: High Impact eMail 4.0 Professional.lnk = C:\Program Files\High Impact eMail 4.0\SendBatchMails.exe
O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe
O4 - Global Startup: Image Transfer.lnk = ?
O4 - Global Startup: Snagit 9.lnk = C:\Program Files\TechSmith\Snagit 9\Snagit32.exe
O6 - HKCU\Software\Policies\Mic
rosoft\Int
ernet Explorer\Restrictions present
O8 - Extra context menu item: Add to &LinkFox - res://C:\PROGRA~1\TWEAKM~1
\TweakBHO.
dll/IESCRI
PT
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - C:\PROGRA~1\MICROS~2\OFFIC
E11\REFIEB
AR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-5
8CAB36FD2A
2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-5
8CAB36FD2A
2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f
2ba3849658
3} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f
2ba3849658
3} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0
050045C3C9
6} - C:\PROGRA~1\Yahoo!\MESSEN~
1\YPager.e
xe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0
050045C3C9
6} - C:\PROGRA~1\Yahoo!\MESSEN~
1\YPager.e
xe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprov
au.dll
O15 - Trusted Zone:
http://www.dmiteamtraining.comO15 - Trusted Zone:
http://www.glycosystem.comO15 - Trusted Zone:
http://www.myisagenixteam.comO16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0
E3A5CAA8CD
8} (Office Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=58813O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9
952547D571
5} (Creative Software AutoUpdate) -
http://www.creative.com/su/ocx/15031/CTSUEng.cabO16 - DPF: {17492023-C23A-453E-A040-C
7C580BBF70
0} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {230C3D02-DA27-11D2-8612-0
0A0C93EEA3
C} (SAXFile FileUpload ActiveX Control) -
https://backup.filesanywhere.com/References/FilesanywhereUploader.cabO16 - DPF: {5C86F808-EDD2-4E5D-9C4F-E
0D1ADA859A
F} (Web Conferencing) -
http://208.49.241.193/join_a.cabO16 - DPF: {6414512B-B978-451D-A0D8-F
CFDF33E833
C} (WUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1166590027122O16 - DPF: {6E32070A-766D-4EE6-879C-D
C1FA91D2FC
3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1166590002957O16 - DPF: {9B8D3E79-A732-4EC0-AEEE-8
AF8CDF10D8
A} -
http://installer.palmsource.com/PSIWebStub.dllO16 - DPF: {ED28050F-D713-43BA-A376-D
CC5C35407D
5} (MsnMusicAx Class) -
http://entimg.msn.com/client/msnmusax2822.cabO16 - DPF: {F6ACF75C-C32C-447B-9BEF-4
6B766368D2
9} (Creative Software AutoUpdate Support Package) -
http://www.creative.com/su2/CTL_V02002/ocx/15033/CTPID.cabO16 - DPF: {FE5B9F54-7764-4C01-89F0-4
862601EE95
4} (DigWebHelper Class) -
http://photos.msn.com/resources/neutral/controls/DigWebX2.cab?10,0,910,0O17 - HKLM\System\CCS\Services\T
cpip\..\{3
9F64795-BC
AB-4D85-96
21-CBD2B18
68C36}: NameServer = 208.67.222.222,208.67.222.
220
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-F
BDDE494F8D
1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1
830C7DD7F5
D} - C:\PROGRA~1\COMMON~1\Skype
\SKYPE4~1.
DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrss
tx.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\sc
hedul2.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgem
c.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwd
svc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTSVCC
DA.EXE
O23 - Service: GoToMyPC - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToMyPC\g2sv
c.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google
Updater\GoogleUpdaterServi
ce.exe
O23 - Service: Sony SPTI Service for DVE (ICDSPTSV) - Sony Corporation - C:\WINDOWS\system32\IcdSpt
Sv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver
\1050\Inte
l 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService
.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.ex
e
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.e
xe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc3
2.exe
O23 - Service: LiveShare P2P Server (RoxLiveShare) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxLiveS
hare.exe
O23 - Service: RoxMediaDB - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMedia
DB.exe
O23 - Service: RoxUpnpRenderer (RoxUPnPRenderer) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCom\RoxUpnpRe
nderer.exe
O23 - Service: RoxUpnpServer - Sonic Solutions - C:\Program Files\Roxio\Easy Media Creator 8\Digital Home\RoxUpnpServer.exe
O23 - Service: Roxio Hard Drive Watcher (RoxWatch) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch
.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowGold
\ScsiAcces
s.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEED
D~1\nopdb.
exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet
.exe
--
End of file - 17168 bytes