[Inactive]help hijackers got me pls

help me pls i feel like my life is ended


Logfile of HijackThis v1.99.1
Scan saved at 12:09:38, on 02/12/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
C:\WINDOWS\Mixer.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIE.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\Sony\CONNECTAutoUpdate\CONNECTScheduler.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
C:\Program Files\Desktop Architect\datray.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\SunProtectionServer.exe
C:\Program Files\Nokia\PC Suite for Nokia 6600\connmngmntbox.exe
C:\PROGRA~1\MSNMES~1\msnmsgr.exe
C:\Program Files\Nokia\PC Suite for Nokia 6600\ectaskscheduler.exe
C:\Program Files\ARTEC ScanEZ\SCANEZ.EXE
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\palstart.exe
C:\PROGRA~1\Nokia\PCSUIT~1\Elogerr.exe
C:\Program Files\Sony\CONNECTAutoUpdate\CONNECTAUTrayApp.exe
C:\Program Files\Intuwave\Shared\mRouterRunTime\mRouterRuntime.exe
C:\PROGRA~1\YAHOO!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunThreatEngine.exe
C:\Program Files\Common Files\Sony Shared\GMR\GMRMan.exe
C:\Program Files\Morpheus\Morpheus.exe
C:\Program Files\Sony\CONNECTAutoUpdate\CONNECTAutoUpdate.exe
C:\PROGRA~1\Nokia\PCSUIT~1\BROADC~1.EXE
C:\PROGRA~1\Nokia\PCSUIT~1\SCRFS.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\SunServAlert.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\SunServAlert.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\SunServAlert.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\SunServAlert.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\SunServAlert.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\SunServAlert.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\CounterSpy.exe
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Documents and Settings\jerrell simeon\Desktop\cwshredder.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\jerrell simeon\Local Settings\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.supanet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = supanet Internet Explorer
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {01459542-C37E-C5EA-05BA-1A515DC8EE34} - (no file)
O2 - BHO: (no name) - {029073B0-66F6-D9B0-C24F-8F8330D53834} - (no file)
O2 - BHO: (no name) - {04D84A7E-AF1A-27B3-7174-33D2BABA7210} - (no file)
O2 - BHO: (no name) - {06174100-CAF8-CE60-F6D9-08763BA72C17} - (no file)
O2 - BHO: (no name) - {068489CE-C742-D99D-0B6E-1D0E454D2566} - (no file)
O2 - BHO: (no name) - {07E66B38-1367-7DC0-FD3C-CA1BFBA6BCC7} - (no file)
O2 - BHO: (no name) - {089905C9-1483-4347-E125-35E7E989E40E} - (no file)
O2 - BHO: (no name) - {09207CE5-BD48-226E-8BA1-3964BEC3C523} - (no file)
O2 - BHO: (no name) - {0B7CF0C1-AE5A-B428-6229-E649815FF71C} - (no file)
O2 - BHO: (no name) - {0E0ABE69-7345-8741-938E-5DCCA13C4284} - (no file)
O2 - BHO: (no name) - {109212EC-3F75-38A1-64AA-DD6F914869B6} - (no file)
O2 - BHO: (no name) - {10AA115E-9874-17AF-147C-C424D9FA21F0} - (no file)
O2 - BHO: (no name) - {10CB9ED8-DE3E-49E2-5735-9F1B7A0CC365} - (no file)
O2 - BHO: (no name) - {160292A8-8482-FF8D-4D84-FBB413F28A39} - (no file)
O2 - BHO: (no name) - {167AE968-C709-3A38-3F1C-C1CBB01B9FF3} - (no file)
O2 - BHO: (no name) - {1706490A-46E4-DD57-A8BB-9E0DE0B66E7B} - (no file)
O2 - BHO: (no name) - {1739822B-FCAD-E0B7-8AE6-A7FA3ADF9CE7} - (no file)
O2 - BHO: (no name) - {18A26320-9939-6C6A-D3C0-22A67A264E36} - (no file)
O2 - BHO: (no name) - {1A764511-7F00-D1BA-FF81-B7869B84230E} - (no file)
O2 - BHO: (no name) - {1B7649CB-3BCF-46D5-F4A7-39AEAE5625AB} - (no file)
O2 - BHO: (no name) - {1CC5EA1C-5AC4-2B40-63AB-A18318F681C3} - (no file)
O2 - BHO: (no name) - {1E883F2F-29E2-AD4B-A546-1CFC8B6CBE28} - (no file)
O2 - BHO: (no name) - {201166BC-FF75-D1B9-E36A-D1964D800CF1} - (no file)
O2 - BHO: (no name) - {20744CC5-FB11-DE1F-FEE2-6EF49E72CB4B} - (no file)
O2 - BHO: (no name) - {209F8E8B-6292-6C42-3CE2-9DCDECC213E7} - (no file)
O2 - BHO: (no name) - {24817430-5142-4C7E-9CFF-0DCF7AC3D4C9} - (no file)
O2 - BHO: (no name) - {248F4AA0-2FBE-AC94-9343-FA3E8832F5B2} - (no file)
O2 - BHO: (no name) - {24BE1459-795A-5BA6-B9B1-DC1A2D1652EF} - (no file)
O2 - BHO: (no name) - {24D87AB5-7115-66D2-F97A-234319B569B2} - (no file)
O2 - BHO: (no name) - {25A009EF-9AD1-F48E-DE09-4FBF9D83EA16} - (no file)
O2 - BHO: (no name) - {295E94EF-17FD-F524-DCBC-A03A2D5699EB} - (no file)
O2 - BHO: (no name) - {2DB3238E-D296-FBA8-594B-64849E0A5C45} - (no file)
O2 - BHO: (no name) - {2DCB300B-8992-BE39-ABB4-00C240619497} - (no file)
O2 - BHO: (no name) - {2E060147-D980-CDD2-64D5-AD18C7E395DE} - (no file)
O2 - BHO: (no name) - {2EE38D01-F026-ABE1-0E63-6C92A5B58AE5} - (no file)
O2 - BHO: (no name) - {2F81B0AE-8954-D01D-E50B-7FCBA7679003} - (no file)
O2 - BHO: (no name) - {301755A0-D9D5-A0CE-DB02-2D3AD027AB6D} - (no file)
O2 - BHO: (no name) - {306F8479-A75A-9D8E-3C63-AD58B0678A6A} - (no file)
O2 - BHO: (no name) - {309D4ABE-913D-3435-6260-9ABB4A8F608C} - (no file)
O2 - BHO: (no name) - {30D69B85-EE43-35E6-D2B5-25DF6A5DEDBF} - (no file)
O2 - BHO: (no name) - {321F7904-194F-9A0F-04B0-2C3F916C8D1D} - (no file)
O2 - BHO: (no name) - {32EDCCFD-DAC9-D83E-5DB1-6CB6E0DCD071} - (no file)
O2 - BHO: (no name) - {33A49432-E399-EC6E-1569-941A0DB59717} - (no file)
O2 - BHO: Class - {367BDA74-112C-A690-28AA-F33ADF8DEDD0} - C:\WINDOWS\system32\javarw32.dll (file missing)
O2 - BHO: (no name) - {369A63AB-22E5-CEAD-69B4-F3234AC621E8} - (no file)
O2 - BHO: (no name) - {36C8BFEE-9131-2E75-B2A0-0B02A6B32FED} - (no file)
O2 - BHO: (no name) - {377FEB56-8C41-2539-026D-47F1BD3C2087} - (no file)
O2 - BHO: (no name) - {38F529FF-1EDC-01E9-83E9-DD82ED68EC0D} - (no file)
O2 - BHO: (no name) - {3966C64B-A81F-E339-FCB7-FADA509397A0} - (no file)
O2 - BHO: (no name) - {3B905E87-A740-AA37-B797-EC359ECDC866} - (no file)
O2 - BHO: (no name) - {3C21F8E7-4262-C50A-B696-091F6BCE92B1} - (no file)
O2 - BHO: (no name) - {3C37FDEC-A395-D261-6C7C-07CDA6E395A0} - (no file)
O2 - BHO: (no name) - {3FF4DC00-DFBF-5AF6-26C7-ADA5FDD1BA63} - (no file)
O2 - BHO: (no name) - {4014B4D5-2904-EAE9-66BC-9F97C5F321F8} - (no file)
O2 - BHO: (no name) - {427792FE-C50B-E431-ABCE-3735EA006792} - (no file)
O2 - BHO: (no name) - {435DCC73-6A82-B382-0379-1897B3483C72} - (no file)
O2 - BHO: (no name) - {442CDA43-CA0D-6E47-3178-B83BA52399E2} - (no file)
O2 - BHO: (no name) - {46197FE1-6233-D248-4E10-4F51A8E96522} - (no file)
O2 - BHO: (no name) - {461A2653-B36A-3762-33AF-CBD520971823} - (no file)
O2 - BHO: (no name) - {47AAFE8A-F547-32BE-9E28-92B0411D0CC3} - (no file)
O2 - BHO: (no name) - {47B53421-0DCB-C3EA-A451-2E8EDBE2B5BD} - (no file)
O2 - BHO: (no name) - {48318C66-81D4-290B-BD6B-DA3DD281424B} - (no file)
O2 - BHO: (no name) - {48785F27-22B3-8233-44D2-64CF0F0060B0} - (no file)
O2 - BHO: (no name) - {4B3E5A14-3E7C-118C-24D5-F3F49D8E89A8} - (no file)
O2 - BHO: (no name) - {4C8EF58C-1E8B-772E-B285-50C063477787} - (no file)
O2 - BHO: (no name) - {4CAA193E-F9F0-5C3A-BE38-36A7FC5DBE10} - (no file)
O2 - BHO: (no name) - {4F8F140F-AC5D-B2A8-88F2-102063F77E8B} - (no file)
O2 - BHO: (no name) - {5644A91B-9F1D-CA30-938F-F211D4062632} - (no file)
O2 - BHO: (no name) - {56A8C663-874D-4D49-A514-C7F1D1B06635} - (no file)
O2 - BHO: (no name) - {59411F8E-CF6C-7B7A-F0C0-DB33873458BD} - (no file)
O2 - BHO: (no name) - {597C394D-7209-3F39-761D-930B4E37CB86} - (no file)
O2 - BHO: (no name) - {5DC8F5E4-E651-4A8F-0C0E-BB293A521172} - (no file)
O2 - BHO: (no name) - {5E5BCC20-3714-13E6-A800-5A0B8A51992C} - (no file)
O2 - BHO: (no name) - {5F4CF23D-5370-7E4F-F006-FB29CBB4A970} - (no file)
O2 - BHO: (no name) - {5FBE1FF5-7AF6-CB56-86BF-3D041D413241} - (no file)
O2 - BHO: (no name) - {5FF7BB31-38C8-9368-5FEE-A72B4BCC8B6A} - (no file)
O2 - BHO: (no name) - {603713DB-4BD5-544A-66D3-C39C456D92CC} - (no file)
O2 - BHO: (no name) - {608BFC8E-0413-A3AF-D9F1-1B80CAF6FA40} - (no file)
O2 - BHO: (no name) - {60CF4492-119D-A24C-4318-B79E3CA3AE85} - (no file)
O2 - BHO: (no name) - {626886F5-0E40-2626-FD2B-6A22AEACA6C6} - (no file)
O2 - BHO: (no name) - {6477E0AE-C44A-D3CD-6823-CC6538DFBFEE} - (no file)
O2 - BHO: (no name) - {6736D543-9459-D61F-8FA7-A53653949C0D} - (no file)
O2 - BHO: (no name) - {6794F65E-B936-8788-DF21-FC72FF82FA53} - (no file)
O2 - BHO: (no name) - {6818C993-D3C4-9CB8-5FF2-04EAC7FEB4D4} - (no file)
O2 - BHO: (no name) - {684D8316-B9C2-464B-BD62-8EF1A6D52F75} - (no file)
O2 - BHO: (no name) - {6BA46265-A7F0-AB90-AD08-51550B1A16B0} - (no file)
O2 - BHO: (no name) - {6CB6FA3E-4E06-6264-2A77-866A236736C8} - (no file)
O2 - BHO: (no name) - {7209F9C3-6DF8-77E8-2A99-C2E455B54257} - (no file)
O2 - BHO: (no name) - {729D4A66-1A5F-6A6D-E8AA-4A3BCF02109E} - (no file)
O2 - BHO: (no name) - {74343E32-9027-9936-7DCF-73D4C7D77C90} - (no file)
O2 - BHO: (no name) - {74FBD308-0C2F-B067-A261-12277E5F3C23} - (no file)
O2 - BHO: (no name) - {763AF3F6-BC0C-14B6-3366-52CE92AA3A6D} - (no file)
O2 - BHO: (no name) - {770CE589-D47C-9567-46F4-E4E08B3366BC} - (no file)
O2 - BHO: (no name) - {772E0CC1-EE6B-2A80-0292-99E434619A9A} - (no file)
O2 - BHO: (no name) - {77E07B4E-9CE6-E087-9155-EC37594EE654} - (no file)
O2 - BHO: (no name) - {77FBBD4D-9D5E-743E-61E0-9905C147C18E} - (no file)
O2 - BHO: (no name) - {795C4F6D-8709-7CDE-2594-4B088D22936D} - (no file)
O2 - BHO: (no name) - {7A7E10DA-FBEB-BEC0-8B9D-91213C74ECF2} - (no file)
O2 - BHO: (no name) - {7ABC8CA3-1C8B-1C2F-D77D-56540FC9BABD} - (no file)
O2 - BHO: (no name) - {7AEAA22C-5AF0-904E-FBFC-87BB64D7C238} - (no file)
O2 - BHO: (no name) - {7C12119B-223D-DFD5-D55D-B7954FBD4E39} - (no file)
O2 - BHO: (no name) - {7E5DA506-8E62-2871-824D-057117148321} - (no file)
O2 - BHO: (no name) - {81C8B002-E341-A0E2-D75A-49D627E588C6} - (no file)
O2 - BHO: (no name) - {86A0C09D-1B74-868D-C89A-093479621C99} - (no file)
O2 - BHO: (no name) - {87399116-4F8B-2283-16A7-16BA2B2E75F0} - (no file)
O2 - BHO: (no name) - {875B4A75-88F5-E7EE-970A-F733BAD255DD} - (no file)
O2 - BHO: (no name) - {88D23398-80FD-CCFF-2845-80C3E94F818D} - (no file)
O2 - BHO: (no name) - {8B001F81-D1AE-44C9-343F-9CF52FD2A7EF} - (no file)
O2 - BHO: (no name) - {8D1DC95E-3145-B4D6-7B78-BD7EBCDB10B3} - (no file)
O2 - BHO: (no name) - {8EDEB261-7C44-2154-53C6-FA3DD5685210} - (no file)
O2 - BHO: (no name) - {8F916F94-C19B-C8D4-2EF3-E8824FCBD83F} - (no file)
O2 - BHO: (no name) - {9077A962-ADEE-5591-6287-7FF61B9A9249} - (no file)
O2 - BHO: (no name) - {932D21BB-436A-AA18-7EFE-9D87C425742E} - (no file)
O2 - BHO: (no name) - {979EE20A-DF52-7D91-E686-6534573A1238} - (no file)
O2 - BHO: (no name) - {9AA00E8E-DF77-92FE-007F-550C36210091} - (no file)
O2 - BHO: (no name) - {9AAF21EC-8C5E-7FEC-A196-DE0DBD9208A5} - (no file)
O2 - BHO: (no name) - {9ADF800E-4A66-7869-6F69-A66D5FC57F3F} - (no file)
O2 - BHO: (no name) - {9E36483D-36A3-2FD6-E6B5-7E47C21A009F} - (no file)
O2 - BHO: (no name) - {9FF6A8D2-CC97-F041-1BB1-98741933AF0D} - (no file)
O2 - BHO: (no name) - {A13AEB93-2FFA-5E39-64E1-E321510B0115} - (no file)
O2 - BHO: (no name) - {A1A5E364-E35E-3207-00BC-5BCD057C00C4} - (no file)
O2 - BHO: (no name) - {A201E9FB-E957-9FD0-D7B8-E7180B6535EB} - (no file)
O2 - BHO: (no name) - {A242E683-72B0-E8A6-630D-7874F7A00AAC} - (no file)
O2 - BHO: (no name) - {A490913E-404C-4851-6AFE-B571204BBED4} - (no file)
O2 - BHO: (no name) - {A8A6D469-369F-3458-9CB6-13F81431144C} - (no file)
O2 - BHO: (no name) - {AA17060B-41AF-88EC-D24D-13F4FB9C2034} - (no file)
O2 - BHO: (no name) - {AE591174-12ED-6C80-F97A-97B75A21E8A5} - (no file)
O2 - BHO: (no name) - {B05BB3F1-E281-9429-9161-2EFA4B24E35B} - (no file)
O2 - BHO: (no name) - {B148E930-3364-EE89-4148-4B7B2877D74C} - (no file)
O2 - BHO: (no name) - {B761EF1B-A8E6-61C8-4DAC-F05E97FF5FAE} - (no file)
O2 - BHO: (no name) - {BBF5E38D-037F-77FE-1BD4-D0175630EF03} - (no file)
O2 - BHO: (no name) - {BD6292E2-CEBD-27AC-7BB6-566F7436B592} - (no file)
O2 - BHO: (no name) - {BFB065A2-4F3C-61BB-4A5B-FA6D452D3EAC} - (no file)
O2 - BHO: (no name) - {BFBFA424-9910-08B0-2FBF-CC5180D847C2} - (no file)
O2 - BHO: (no name) - {C0A99D85-4A67-BD82-BF78-49D851758BE0} - (no file)
O2 - BHO: (no name) - {C660661C-10FD-F21F-3A46-4EAAF0E43199} - (no file)
O2 - BHO: (no name) - {CAB90C3B-89E7-10B2-D3AB-EAA171F175B7} - (no file)
O2 - BHO: (no name) - {CCE4F981-DD69-6A68-6F5D-1A1766D4B271} - (no file)
O2 - BHO: (no name) - {CDF42652-3705-BFD1-B061-1F21BA9B7A66} - (no file)
O2 - BHO: (no name) - {CE8D7B7D-6D87-064D-7E17-E8BCBCAD0D49} - (no file)
O2 - BHO: (no name) - {CE91F604-199F-7882-72AB-B4D8255E7E3A} - (no file)
O2 - BHO: (no name) - {D1B08BEF-61F3-13A0-6BCC-CB7E58770653} - (no file)
O2 - BHO: (no name) - {D1D3F629-D478-30C0-AA11-597B3DEFBC62} - (no file)
O2 - BHO: (no name) - {D407E716-119A-3685-180E-BDCC09FAE72C} - (no file)
O2 - BHO: (no name) - {D515FFD7-038F-6ED7-3964-B55DA46F9601} - (no file)
O2 - BHO: (no name) - {D633C653-180F-ABA8-F319-38C99338A3DC} - (no file)
O2 - BHO: (no name) - {D74D00C3-EB52-A0FF-0E67-45BE41EF3E73} - (no file)
O2 - BHO: (no name) - {D8010B5A-E220-B876-B855-D2861F450A0C} - (no file)
O2 - BHO: (no name) - {D8DEC485-CE65-A3D0-7970-3801569ABBF8} - (no file)
O2 - BHO: (no name) - {D8F3C22A-6CEB-61D4-7123-9B293A2D57FF} - (no file)
O2 - BHO: (no name) - {DD499CA0-63C5-BE6B-7B26-F81AF2321007} - (no file)
O2 - BHO: (no name) - {E0CF4A70-0E96-DF38-A8BC-64D6EF4B33C5} - (no file)
O2 - BHO: (no name) - {E2433A15-FEC3-03A3-3F1B-035F002AB92A} - (no file)
O2 - BHO: (no name) - {E394341A-2ED9-EFE0-6516-4B65343512E4} - (no file)
O2 - BHO: (no name) - {E3BB58FA-9E29-5453-8515-DD85FF9C16C7} - (no file)
O2 - BHO: (no name) - {E3BCCA55-75E7-6990-81F7-0372DB33198A} - (no file)
O2 - BHO: (no name) - {E6A8DF75-9B34-005D-4060-2AB82D18D1F5} - (no file)
O2 - BHO: (no name) - {E6CC0B82-A5E1-6AA6-DF5E-EBC3C207ED6F} - (no file)
O2 - BHO: (no name) - {E868E85F-8A2C-8F90-11C8-C70A8A47961A} - (no file)
O2 - BHO: (no name) - {E8983D00-0142-A0FE-63A0-D9E1F3C04A6B} - (no file)
O2 - BHO: (no name) - {E8CB8F3D-0EF0-B83E-7CE8-95669AA1BCA0} - (no file)
O2 - BHO: (no name) - {EB875E59-D1A2-BEDD-B6E0-01204A789601} - (no file)
O2 - BHO: (no name) - {EFF80E42-AC7D-BE18-E98A-B6EDE16CC5AB} - (no file)
O2 - BHO: (no name) - {F0D6D30E-BA73-7B78-30E2-D479FA6CBF01} - (no file)
O2 - BHO: (no name) - {F27F1D27-3CF0-21F4-CC05-4594BE098CBB} - (no file)
O2 - BHO: (no name) - {F30C5202-B2CD-18C6-86CD-486CBAC73988} - (no file)
O2 - BHO: (no name) - {F4483D2B-2AA0-A1D6-2F5E-8733958DDE93} - (no file)
O2 - BHO: (no name) - {F47A935F-6D84-6D4E-54C7-DA22B3F01D10} - (no file)
O2 - BHO: (no name) - {F52A683D-86BC-5DC9-8231-5370AB157678} - (no file)
O2 - BHO: (no name) - {F61C43C0-8F6A-C654-1213-B906276F3ADF} - (no file)
O2 - BHO: (no name) - {F7C42564-EA95-5F04-2382-4C97CB847F28} - (no file)
O2 - BHO: (no name) - {F9538E86-36EE-4A7E-6596-B6F8EAA229D9} - (no file)
O2 - BHO: (no name) - {FB403460-5205-9C0D-68F5-071490BA8A0D} - (no file)
O2 - BHO: (no name) - {FBE52283-28CB-B35F-A52E-EDE0AE934884} - (no file)
O2 - BHO: (no name) - {FC933F3B-F61C-174E-C6CD-8A9A8ECDD4A8} - (no file)
O2 - BHO: (no name) - {FD350929-ABF9-B29E-4912-9CF55B4CB92A} - (no file)
O2 - BHO: (no name) - {FDD2AC6A-B7E4-6D04-F3CF-9A9B7D9CE11A} - (no file)
O2 - BHO: (no name) - {FE937706-6A52-A0DA-6536-E5C2A84CE79C} - (no file)
O2 - BHO: (no name) - {FF7AF231-F460-F958-9E42-30A70C516066} - (no file)
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SupaStatus] C:\Program Files\Internet Explorer\Connection Wizard\Status.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe
O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [EPSON Stylus Photo R220 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIE.EXE /P30 "EPSON Stylus Photo R220 Series" /O6 "USB002" /M "Stylus Photo R220"
O4 - HKLM\..\Run: [msag] xwiz.exe
O4 - HKLM\..\Run: [sbin] SAPSTR.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [apipg32.exe] C:\WINDOWS\system32\apipg32.exe
O4 - HKLM\..\Run: [syslr.exe] C:\WINDOWS\system32\syslr.exe
O4 - HKLM\..\Run: [dmvdp.exe] C:\WINDOWS\System32\dmvdp.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [!!!_Sexy_gb] C:\Program Files\SCom\Dialers\!!!_Sexy_gb\!!!_Sexy_gb.exe /dontdial
O4 - HKLM\..\Run: [CONNECTScheduler] "C:\Program Files\Sony\CONNECTAutoUpdate\CONNECTScheduler.exe" /RUN_SCHEDULER
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SunServer] C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [Desktop Architect] "C:\Program Files\Desktop Architect\datray.exe" -S
O4 - HKCU\..\Run: [init32] iehelper.exe
O4 - HKCU\..\Run: [bhoserv] ssweeper.exe
O4 - HKCU\..\Run: [Dest068] WhatsNewBot.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe" -quiet
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRA~1\MSNMES~1\msnmsgr.exe" /background
O4 - Startup: Morpheus.lnk = C:\Program Files\Morpheus\Morpheus.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: PCSuiteForNokia6600 Detect.lnk = ?
O4 - Global Startup: PCSuiteForNokia6600 TS.lnk = ?
O4 - Global Startup: ARTEC ScanEZ.lnk = C:\Program Files\ARTEC ScanEZ\SCANEZ.EXE
O4 - Global Startup: palstart.exe
O4 - Global Startup: CONNECTAUTrayApp.lnk = C:\Program Files\Sony\CONNECTAutoUpdate\CONNECTAUTrayApp.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\npjpi150_09.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\npjpi150_09.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.supanet.com/
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/yinst/yinst_current.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup162.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0DD2FB75-B291-4728-82C4-2C23C17468EB}: NameServer = 85.255.115.43,85.255.112.124
O17 - HKLM\System\CCS\Services\Tcpip\..\{9476A14A-CC70-48F9-BA66-DC9F6890C639}: NameServer = 85.255.115.43,85.255.112.124
O17 - HKLM\System\CCS\Services\Tcpip\..\{9B1A1A18-2000-4382-A658-A5CB4C4ACFFB}: NameServer = 85.255.115.43,85.255.112.124
O17 - HKLM\System\CCS\Services\Tcpip\..\{AF82490E-C6BE-4C96-B52D-77EAD4CBAB07}: NameServer = 85.255.115.43,85.255.112.124
O17 - HKLM\System\CCS\Services\Tcpip\..\{E91C5A47-4C50-475E-A3AC-AC96E7384CD0}: NameServer = 85.255.115.43,85.255.112.124
O17 - HKLM\System\CS1\Services\Tcpip\..\{0DD2FB75-B291-4728-82C4-2C23C17468EB}: NameServer = 85.255.115.43,85.255.112.124
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Windows Remote Procedure Call Monitoring Service (rpcsvc) - Unknown owner - C:\WINDOWS\System32\rpcsvc.exe (file missing)
O23 - Service: Sony SCSI Helper Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

Comments

  • TroganTrogan London, UK
    edited December 2006
    Hi cheekyboi, welcome to Short-Media Forums!

    Please download the Suspicious file Packer from Safer-Networking.Org and unzip it to your desktop.

    Run SFP.exe.

    Please copy the following line into the Step 1: Paste Text window:

    C:\WINDOWS\System32\rpcsvc.exe

    Click "Continue" and close SFP.

    This will create a .cab file on your desktop named requested-files[Date/Time].cab

    Next please visit SpyKillers forum here

    http://www.thespykiller.co.uk/forum/index.php?board=1.0

    Read the instructions for uploading files which is the first topic on the forum and then start a new Topic named 'SDBot file for AndyManchesta'. Next, post a link to this thread and upload the requested files.cab archive from your desktop

    Let me know when this is done or if you need further help with this.

    ==================================

    I have some bad news.

    Amongst other infections, the computer is infected by an SDBot Trojan which has backdoor functionality. This gives intruders complete control of your computer, logging key strokes, stealing information, etc. :(

    You are strongly advised to do the following immediately!:
    • Disconnect infected computer from the internet and from any networked computers until the computer can be cleaned.
    • Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.
    • From a clean computer, change *all* of your online passwords -- for ISP login, email, banks, financial accounts, PayPal, eBay, online companies, and any online forums or groups you belong to.
        Do NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passwords and transaction information.
      Because of its backdoor functionality, your PC is very likely compromised and there is no way to be sure it can ever again be trusted. Many experts in the security community believe that once infected with this type of Trojan, the best course of action would be a reformat and reinstall of the OS. However, if you do not have the resources to reinstall your OS and would like me to attempt to clean your machine, I will be happy to do so.

      To help you make a more informed decision, please read the following articles: Should you have any questions, please feel free to ask

      Please let me know your decision and we'll get started with clean up if that's what you choose.[/quote]
    • TroganTrogan London, UK
      edited December 2006
      Whilst we appreciate that you may be busy, it has been 7 days or more since we heard from you.

      Infections can change and fresh instructions will now need to be given. This topic is now closed, if you still require assistance then please start a new topic in the Spyware & Virus Removal Forum

      If you wish this topic reopened, please send a Private Message (PM) to one of the Spyware Mods with a link to your thread.

      Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required.
      If you are not the user who started this thread, you must start a new Thread instead :)
    This discussion has been closed.