Piloto de Fuga
New Member
Hello,
I use Windows XP and a few days ago, the taskbar and the desktop icons disappeared. Also, the system restarts on the logon screen when I try to reboot in Safe Mode.
This is my post telling about the problem, please read it to see what I've already tried:
http://www.computerforum.com/84278-taskbar-desktop-icons-disapeared.html
They told me to come here since VundoFix has found some infections. But when the program is trying to remove the Vundos, the system crashes on a blue screen.
Here is the ComboFix log:
Pedro - 07-05-09 21:59:21,95 Service Pack 2
ComboFix 06.11.9 - Running from: "D:\Samir\Outros\Progamas de Seguran‡a"
((((((((((((((((((((((((((((((( Files Created from 2007-04-09 to 2007-05-09 ))))))))))))))))))))))))))))))))))
2007-05-09 20:08 616,578 ---hs---- C:\WINDOWS\system32\srutv.bak2
2007-05-09 20:00 3,935 ---hs---- C:\WINDOWS\system32\srutv.ini2
2007-05-09 15:11 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2007-05-07 19:53 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll
2007-05-07 19:53 13,312 --a------ C:\WINDOWS\system32\irclass.dll
2007-05-05 19:20 284,756 --------- C:\WINDOWS\system32\vturs.dll
2007-05-05 19:20 0 --a------ C:\WINDOWS\system32\gebyv.dll
2007-05-05 12:03 284,756 --ahs---- C:\WINDOWS\system32\ddcca.dll
2007-05-04 11:50 545,766 --ahs---- C:\WINDOWS\system32\srqss.bak1
2007-05-04 11:49 284,756 --ahs---- C:\WINDOWS\system32\ssqrs.dll
2007-04-30 18:29 225,483 --a------ C:\WINDOWS\system32\vtsqn.dll
2007-04-23 13:23 507,120 --ahs---- C:\WINDOWS\system32\pqstv.ini2
2007-04-22 19:51 43,584 --a------ C:\WINDOWS\system32\drivers\avipbb.sys
2007-04-22 19:51 28,352 --a------ C:\WINDOWS\system32\drivers\ssmdrv.sys
2007-04-22 12:11 176,235 --a------ C:\WINDOWS\system32\Primomonnt.dll
2007-04-19 21:27 527,381 --ahs---- C:\WINDOWS\system32\pqstv.bak2
2007-04-18 21:54 501,444 --ahs---- C:\WINDOWS\system32\pqstv.bak1
2007-04-18 20:13 26,694 --------- C:\WINDOWS\system32\hggfeca.dll
2007-04-16 20:56 513,152 --a------ C:\WINDOWS\system32\drivers\WmaCDriverV32.sys
2007-04-16 20:48 573,440 --a------ C:\WINDOWS\system32\NCTAudioInformation2.dll
2007-04-16 20:48 491,520 --a------ C:\WINDOWS\system32\NCTAudioFile.dll
2007-04-16 20:48 290,816 --a------ C:\WINDOWS\system32\NCTWMAFile.dll
2007-04-16 20:48 282,624 --a------ C:\WINDOWS\system32\NCTAudioVisualization.dll
2007-04-16 20:48 274,432 --a------ C:\WINDOWS\system32\NCTAudioRecord.dll
2007-04-16 20:48 168,448 --a------ C:\WINDOWS\system32\NCTAudioPlayer.dll
2007-04-16 20:48 120,832 --a------ C:\WINDOWS\system32\lame_enc.dll
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-05-09 21:33 -------- d-------- C:\Arquivos de programas\Mozilla Firefox
2007-05-09 21:09 -------- d-------- C:\Documents and Settings\Pedro\Dados de aplicativos\Free Download Manager
2007-05-09 19:38 -------- d-------- C:\Arquivos de programas\Discador itelefonica
2007-05-08 18:28 -------- d-------- C:\Arquivos de programas\Arquivos comuns\Adobe
2007-05-08 14:05 -------- d-------- C:\Documents and Settings\Pedro\Dados de aplicativos\Babylon
2007-05-07 20:08 -------- d-------- C:\Arquivos de programas\Windows Media Player
2007-05-07 20:05 -------- d-------- C:\Arquivos de programas\Outlook Express
2007-05-07 20:05 -------- d-------- C:\Arquivos de programas\Internet Explorer
2007-05-07 20:05 -------- d-------- C:\Arquivos de programas\Arquivos comuns\System
2007-05-07 20:04 -------- d-------- C:\Arquivos de programas\Messenger
2007-05-06 21:56 -------- d-------- C:\Arquivos de programas\eMule
2007-05-06 20:57 -------- d-------- C:\Arquivos de programas\nLite
2007-05-06 11:15 -------- d-------- C:\Documents and Settings\Pedro\Dados de aplicativos\AVG7
2007-05-06 10:19 -------- d-------- C:\Arquivos de programas\DAEMON Tools
2007-05-05 22:38 -------- d-------- C:\Documents and Settings\Pedro\Dados de aplicativos\Lavasoft
2007-05-05 22:37 -------- d-------- C:\Arquivos de programas\Lavasoft
2007-05-05 20:45 -------- d-------- C:\Arquivos de programas\WMAConvert
2007-05-05 20:45 -------- d-------- C:\Arquivos de programas\SpeedBit Video Accelerator
2007-05-05 20:45 -------- d-------- C:\Arquivos de programas\Nox
2007-05-05 20:45 -------- d-------- C:\Arquivos de programas\Mafia
2007-05-05 20:45 -------- d-------- C:\Arquivos de programas\Driver Magician
2007-05-05 20:45 -------- d-------- C:\Arquivos de programas\Chrome
2007-05-05 20:45 -------- d-------- C:\Arquivos de programas\AntiVir PersonalEdition Classic
2007-05-05 20:30 -------- d-------- C:\Arquivos de programas\TuneUp Utilities 2007
2007-05-04 19:55 -------- d-------- C:\Arquivos de programas\Free Download Manager
2007-05-04 18:15 2560 --a------ C:\WINDOWS\system32\BitCometRes.dll
2007-05-04 18:10 -------- d-------- C:\Arquivos de programas\BitComet Acceleration Patch
2007-05-04 18:09 -------- d-------- C:\Arquivos de programas\BitComet
2007-05-04 18:02 -------- d-------- C:\Arquivos de programas\Dr Windows
2007-04-30 23:57 -------- d-------- C:\Documents and Settings\Pedro\Dados de aplicativos\Bitdefender
2007-04-30 23:32 -------- d-------- C:\Arquivos de programas\Softwin
2007-04-30 23:32 -------- d-------- C:\Arquivos de programas\Arquivos comuns\Softwin
2007-04-30 23:30 -------- d-------- C:\Arquivos de programas\Arquivos comuns
2007-04-28 20:00 -------- d-------- C:\Arquivos de programas\Project64 1.6
2007-04-27 22:34 -------- d-------- C:\Arquivos de programas\Puxa R pido
2007-04-27 20:03 -------- d-------- C:\Documents and Settings\Pedro\Dados de aplicativos\MXPLAY
2007-04-27 19:57 -------- d-------- C:\Arquivos de programas\MXPLAY
2007-04-27 19:56 -------- d--h----- C:\Arquivos de programas\InstallShield Installation Information
2007-04-27 19:55 -------- d-------- C:\Documents and Settings\Pedro\Dados de aplicativos\InstallShield
2007-04-27 14:10 -------- d-------- C:\Arquivos de programas\RenomearTudo
2007-04-27 13:06 777984 --a------ C:\WINDOWS\system32\drivers\avg7core.sys
2007-04-26 21:47 -------- d-------- C:\Arquivos de programas\Last.fm
2007-04-26 20:47 -------- d---s---- C:\Documents and Settings\Pedro\Dados de aplicativos\Microsoft
2007-04-25 22:03 -------- d-------- C:\Documents and Settings\Pedro\Dados de aplicativos\Adobe
2007-04-23 20:54 -------- d-------- C:\Documents and Settings\Pedro\Dados de aplicativos\Opera
2007-04-23 14:07 -------- d-------- C:\Arquivos de programas\Adobe
2007-04-22 12:11 -------- d-------- C:\Arquivos de programas\PrimoPDF
2007-04-21 18:08 -------- d-------- C:\Arquivos de programas\SystemRequirementsLab
2007-04-20 14:22 19840 --a------ C:\WINDOWS\system32\drivers\avgmfx86.sys
2007-04-19 18:27 43520 --a------ C:\WINDOWS\system32\CmdLineExt03.dll
2007-04-18 20:07 -------- d-------- C:\Documents and Settings\Pedro\Dados de aplicativos\Publish Providers
2007-04-18 19:18 -------- d-------- C:\Documents and Settings\Pedro\Dados de aplicativos\Sony
2007-04-18 19:10 -------- d-------- C:\Arquivos de programas\Sound Forge 9.0
2007-04-18 19:10 -------- d-------- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared
2007-04-18 13:53 -------- d-------- C:\Arquivos de programas\Free Video to Mp3 Converter
2007-04-16 21:54 720896 --a------ C:\WINDOWS\iun6002ev.exe
2007-04-16 21:45 -------- d-------- C:\Arquivos de programas\Eidos
2007-04-09 19:51 -------- d-------- C:\Arquivos de programas\LimeWire
2007-04-06 19:24 -------- d-------- C:\Arquivos de programas\Realtek
2007-04-06 19:23 315392 --a------ C:\WINDOWS\HideWin.exe
2007-04-06 18:41 -------- d-------- C:\Arquivos de programas\The KMPlayer
2007-04-06 12:09 34308 --a------ C:\WINDOWS\system32\BASSMOD.dll
2007-03-31 21:23 -------- d-------- C:\Documents and Settings\Pedro\Dados de aplicativos\Screenshot Sender
2007-03-29 19:01 -------- d-------- C:\Arquivos de programas\Microsoft Games
2007-03-25 13:05 -------- d-------- C:\Arquivos de programas\SigmaTel
2007-03-24 14:01 -------- d-------- C:\Arquivos de programas\X-Micro
2007-03-19 13:57 98304 --a------ C:\WINDOWS\system32\CddbLangNL.dll
2007-03-19 13:57 98304 --a------ C:\WINDOWS\system32\CddbLangFR.dll
2007-03-19 13:57 98304 --a------ C:\WINDOWS\system32\CddbLangES.dll
2007-03-19 13:57 98304 --a------ C:\WINDOWS\system32\CddbLangDE.dll
2007-03-19 13:57 77824 --a------ C:\WINDOWS\system32\CddbLangJA.dll
2007-03-19 13:57 765952 --a------ C:\WINDOWS\system32\CDDBUI.dll
2007-03-19 13:57 655360 --a------ C:\WINDOWS\system32\CDDBControl.dll
2007-03-19 13:57 102400 --a------ C:\WINDOWS\system32\CddbLangIT.dll
2007-03-18 10:53 -------- d-------- C:\Documents and Settings\Pedro\Dados de aplicativos\Mp3tag
2007-03-18 10:52 -------- d-------- C:\Arquivos de programas\Mp3tag
2007-03-18 10:22 27776 --a------ C:\WINDOWS\system32\drivers\avg7rsxp.sys
2007-03-11 21:39 -------- d-------- C:\Arquivos de programas\Winamp
2007-03-11 12:53 -------- d-------- C:\Arquivos de programas\WinAVIVideoConverter
2007-03-10 21:26 -------- d-------- C:\Arquivos de programas\MSN Messenger
2007-03-10 21:26 -------- d-------- C:\Arquivos de programas\Messenger Plus! Live
2007-03-08 12:36 578048 --a------ C:\WINDOWS\system32\Backup user32.dll
2007-02-18 23:55 737280 --a------ C:\WINDOWS\iun6002.exe
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"SpybotSD TeaTimer"="C:\\Arquivos de programas\\Spybot - Search & Destroy\\TeaTimer.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"AVG7_CC"="C:\\ARQUIV~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP"
"avgnt"="\"C:\\Arquivos de programas\\AntiVir PersonalEdition Classic\\avgnt.exe\" /min"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Minha página inicial atual"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,a0,00,00,00,00,00,00,00,80,02,00,00,3a,02,\
00,00,04,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,a0,00,00,00,00,00,00,00,80,02,00,00,3a,02,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\ARQUIV~1\\Grisoft\\AVG7\\avgw.exe /RUNONCE"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\ARQUIV~1\\Grisoft\\AVG7\\avgw.exe /RUNONCE"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-carregador Browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Daemon de cache de categorias de componente"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{93994DE8-8239-4655-B1D1-5F4E91300429}"=""
"{6148028B-D532-4417-8C0B-5A4A0B745393}"=""
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoDispAppearancePage"=dword:00000000
"NoColorChoice"=dword:00000000
"NoDispBackgroundPage"=dword:00000000
"NoDispCPL"=dword:00000000
"NoDispSettingsPage"=dword:00000000
"NoDispScrSavPage"=dword:00000000
"NoVisualStyleChoice"=dword:00000000
"NoSizeChoice"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"LockTaskbar"=dword:00000000
"NoBandCustomize"=dword:00000000
"NoMovingBands"=dword:00000000
"NoCloseDragDropBands"=dword:00000000
"NoSetTaskbar"=dword:00000000
"NoToolbarsOnTaskbar"=dword:00000000
"NoActiveDesktop"=dword:00000000
"ClassicShell"=dword:00000000
"NoSMBalloonTip"=dword:00000001
"NoSaveSettings"=dword:00000000
"NoRecentDocsHistory"=dword:00000001
"CDRAutoRun"=dword:00000000
"NoDriveTypeAutoRun"=dword:00000095
"NoLowDiskSpaceChecks"=dword:00000001
"MemCheckBoxInRunDlg"=dword:00000000
"NoClose"=dword:00000000
"NoAutoTrayNotify"=dword:00000000
"NoResolveTrack"=dword:00000000
"NoResolveSearch"=dword:00000001
"LinkResolveIgnoreLinkInfo"=dword:00000001
"NoStartBanner"=hex:01,00,00,00
"NoWelcomeScreen"=dword:00000001
"NoRecentDocsNetHood"=dword:00000001
"NoDesktopCleanupWizard"=dword:00000001
"NoSharedDocuments"=dword:00000001
"NoThemesTab"=dword:00000000
"NoToolbarCustomize"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"NoInternetOpenWith"=dword:00000000
"RunStartupScriptSync"=dword:00000000
"SynchronousMachineGroupPolicy"=dword:00000000
"SynchronousUserGroupPolicy"=dword:00000000
"DisableCAD"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoRemoteRecursiveEvents"=dword:00000001
"NoStrCmpLogical"=dword:00000001
"NoClose"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Reader Speed Launch.lnk]
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\ARQUIV~1\\Adobe\\Reader 8.0\\Reader\\reader_sl.exe "
"item"="Adobe Reader Speed Launch"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Reader Synchronizer.lnk]
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Synchronizer.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\ARQUIV~1\\Adobe\\Reader 8.0\\Reader\\AdobeCollabSync.exe "
"item"="Adobe Reader Synchronizer"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Pedro^Menu Iniciar^Programas^Inicializar^BitComet Acceleration Patch.lnk]
"backup"="C:\\WINDOWS\\pss\\BitComet Acceleration Patch.lnkStartup"
"location"="Startup"
"command"="C:\\ARQUIV~1\\BitComet Acceleration Patch\\BitComet Acceleration Patch.exe "
"item"="BitComet Acceleration Patch"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ALCMTR"
"hkey"="HKLM"
"command"="ALCMTR.EXE"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Atualizador - Puxa Rápido]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Atualiza"
"hkey"="HKLM"
"command"="C:\\Arquivos de programas\\Puxa Rápido\\Atualiza.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ashDisp"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Babylon Client]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Babylon"
"hkey"="HKLM"
"command"="C:\\Arquivos de programas\\Babylon\\Babylon-Pro\\Babylon.exe -AutoStart"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDAgent]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="bdagent"
"hkey"="HKLM"
"command"="\"C:\\Arquivos de programas\\Softwin\\BitDefender10\\bdagent.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDMCon]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="bdmcon"
"hkey"="HKLM"
"command"="C:\\ARQUIV~1\\Softwin\\BitDefender10\\bdmcon.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="CTFMON"
"hkey"="HKCU"
"command"="C:\\WINDOWS\\system32\\CTFMON.EXE"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="daemon"
"hkey"="HKLM"
"command"="\"C:\\Arquivos de programas\\DAEMON Tools\\daemon.exe\" -lang 1033"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DaemonTools_WhenUSave_Installer]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DaemonTools_WhenUSave_Installer"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="dumprep 0 -k"
"hkey"="HKLM"
"command"="%systemroot%\\system32\\dumprep 0 -k"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NeroCheck"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\New.net Startup]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NEWDOT~1"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="RTHDCPL"
"hkey"="HKLM"
"command"="RTHDCPL.EXE"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\S3Trayp]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="S3trayp"
"hkey"="HKLM"
"command"="S3trayp.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SkyTel"
"hkey"="HKLM"
"command"="SkyTel.EXE"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="sm56hlpr"
"hkey"="HKLM"
"command"="sm56hlpr.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="jusched"
"hkey"="HKLM"
"command"="C:\\Arquivos de programas\\Java\\jre1.5.0_07\\bin\\jusched.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="VTTimer"
"hkey"="HKLM"
"command"="VTTimer.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Winampa"
"hkey"="HKLM"
"command"="\"C:\\Arquivos de programas\\Winamp\\Winampa.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"XCOMM"=dword:00000002
"VSSERV"=dword:00000002
"LIVESRV"=dword:00000002
"bdss"=dword:00000002
"VundoFixSvc"=dword:00000003
"usnjsvc"=dword:00000003
"RichVideo"=dword:00000002
"ose"=dword:00000003
"IDriverT"=dword:00000003
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\hggfeca
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtsqp
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vturs
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\1-Click Maintenance.job
Completion time: 07-05-09 22:00:40.51
C:\ComboFix.txt ... 07-05-09 22:00
C:\ComboFix2.txt ... 07-05-09 13:46
C:\ComboFix3.txt ... 07-05-08 19:18
====================================================
VundoFix V6.3.21
Checking Java version...
Sun Java not detected
Scan started at 22:02:02 9/5/2007
Listing files found while scanning....
C:\WINDOWS\system32\hggfeca.dll
C:\WINDOWS\system32\srutv.bak2
C:\WINDOWS\system32\srutv.ini
C:\WINDOWS\system32\srutv.ini2
C:\WINDOWS\system32\srutv.tmp
C:\WINDOWS\system32\vturs.dll
Beginning removal...
As you can see, Vundo didn't finish the removal, because the system crashed.
But it found something, that might have caused the taskbar problem. How do I remove them?
Thanks in advance.
Regards,
Piloto
I use Windows XP and a few days ago, the taskbar and the desktop icons disappeared. Also, the system restarts on the logon screen when I try to reboot in Safe Mode.
This is my post telling about the problem, please read it to see what I've already tried:
http://www.computerforum.com/84278-taskbar-desktop-icons-disapeared.html
They told me to come here since VundoFix has found some infections. But when the program is trying to remove the Vundos, the system crashes on a blue screen.
Here is the ComboFix log:
Pedro - 07-05-09 21:59:21,95 Service Pack 2
ComboFix 06.11.9 - Running from: "D:\Samir\Outros\Progamas de Seguran‡a"
((((((((((((((((((((((((((((((( Files Created from 2007-04-09 to 2007-05-09 ))))))))))))))))))))))))))))))))))
2007-05-09 20:08 616,578 ---hs---- C:\WINDOWS\system32\srutv.bak2
2007-05-09 20:00 3,935 ---hs---- C:\WINDOWS\system32\srutv.ini2
2007-05-09 15:11 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2007-05-07 19:53 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll
2007-05-07 19:53 13,312 --a------ C:\WINDOWS\system32\irclass.dll
2007-05-05 19:20 284,756 --------- C:\WINDOWS\system32\vturs.dll
2007-05-05 19:20 0 --a------ C:\WINDOWS\system32\gebyv.dll
2007-05-05 12:03 284,756 --ahs---- C:\WINDOWS\system32\ddcca.dll
2007-05-04 11:50 545,766 --ahs---- C:\WINDOWS\system32\srqss.bak1
2007-05-04 11:49 284,756 --ahs---- C:\WINDOWS\system32\ssqrs.dll
2007-04-30 18:29 225,483 --a------ C:\WINDOWS\system32\vtsqn.dll
2007-04-23 13:23 507,120 --ahs---- C:\WINDOWS\system32\pqstv.ini2
2007-04-22 19:51 43,584 --a------ C:\WINDOWS\system32\drivers\avipbb.sys
2007-04-22 19:51 28,352 --a------ C:\WINDOWS\system32\drivers\ssmdrv.sys
2007-04-22 12:11 176,235 --a------ C:\WINDOWS\system32\Primomonnt.dll
2007-04-19 21:27 527,381 --ahs---- C:\WINDOWS\system32\pqstv.bak2
2007-04-18 21:54 501,444 --ahs---- C:\WINDOWS\system32\pqstv.bak1
2007-04-18 20:13 26,694 --------- C:\WINDOWS\system32\hggfeca.dll
2007-04-16 20:56 513,152 --a------ C:\WINDOWS\system32\drivers\WmaCDriverV32.sys
2007-04-16 20:48 573,440 --a------ C:\WINDOWS\system32\NCTAudioInformation2.dll
2007-04-16 20:48 491,520 --a------ C:\WINDOWS\system32\NCTAudioFile.dll
2007-04-16 20:48 290,816 --a------ C:\WINDOWS\system32\NCTWMAFile.dll
2007-04-16 20:48 282,624 --a------ C:\WINDOWS\system32\NCTAudioVisualization.dll
2007-04-16 20:48 274,432 --a------ C:\WINDOWS\system32\NCTAudioRecord.dll
2007-04-16 20:48 168,448 --a------ C:\WINDOWS\system32\NCTAudioPlayer.dll
2007-04-16 20:48 120,832 --a------ C:\WINDOWS\system32\lame_enc.dll
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-05-09 21:33 -------- d-------- C:\Arquivos de programas\Mozilla Firefox
2007-05-09 21:09 -------- d-------- C:\Documents and Settings\Pedro\Dados de aplicativos\Free Download Manager
2007-05-09 19:38 -------- d-------- C:\Arquivos de programas\Discador itelefonica
2007-05-08 18:28 -------- d-------- C:\Arquivos de programas\Arquivos comuns\Adobe
2007-05-08 14:05 -------- d-------- C:\Documents and Settings\Pedro\Dados de aplicativos\Babylon
2007-05-07 20:08 -------- d-------- C:\Arquivos de programas\Windows Media Player
2007-05-07 20:05 -------- d-------- C:\Arquivos de programas\Outlook Express
2007-05-07 20:05 -------- d-------- C:\Arquivos de programas\Internet Explorer
2007-05-07 20:05 -------- d-------- C:\Arquivos de programas\Arquivos comuns\System
2007-05-07 20:04 -------- d-------- C:\Arquivos de programas\Messenger
2007-05-06 21:56 -------- d-------- C:\Arquivos de programas\eMule
2007-05-06 20:57 -------- d-------- C:\Arquivos de programas\nLite
2007-05-06 11:15 -------- d-------- C:\Documents and Settings\Pedro\Dados de aplicativos\AVG7
2007-05-06 10:19 -------- d-------- C:\Arquivos de programas\DAEMON Tools
2007-05-05 22:38 -------- d-------- C:\Documents and Settings\Pedro\Dados de aplicativos\Lavasoft
2007-05-05 22:37 -------- d-------- C:\Arquivos de programas\Lavasoft
2007-05-05 20:45 -------- d-------- C:\Arquivos de programas\WMAConvert
2007-05-05 20:45 -------- d-------- C:\Arquivos de programas\SpeedBit Video Accelerator
2007-05-05 20:45 -------- d-------- C:\Arquivos de programas\Nox
2007-05-05 20:45 -------- d-------- C:\Arquivos de programas\Mafia
2007-05-05 20:45 -------- d-------- C:\Arquivos de programas\Driver Magician
2007-05-05 20:45 -------- d-------- C:\Arquivos de programas\Chrome
2007-05-05 20:45 -------- d-------- C:\Arquivos de programas\AntiVir PersonalEdition Classic
2007-05-05 20:30 -------- d-------- C:\Arquivos de programas\TuneUp Utilities 2007
2007-05-04 19:55 -------- d-------- C:\Arquivos de programas\Free Download Manager
2007-05-04 18:15 2560 --a------ C:\WINDOWS\system32\BitCometRes.dll
2007-05-04 18:10 -------- d-------- C:\Arquivos de programas\BitComet Acceleration Patch
2007-05-04 18:09 -------- d-------- C:\Arquivos de programas\BitComet
2007-05-04 18:02 -------- d-------- C:\Arquivos de programas\Dr Windows
2007-04-30 23:57 -------- d-------- C:\Documents and Settings\Pedro\Dados de aplicativos\Bitdefender
2007-04-30 23:32 -------- d-------- C:\Arquivos de programas\Softwin
2007-04-30 23:32 -------- d-------- C:\Arquivos de programas\Arquivos comuns\Softwin
2007-04-30 23:30 -------- d-------- C:\Arquivos de programas\Arquivos comuns
2007-04-28 20:00 -------- d-------- C:\Arquivos de programas\Project64 1.6
2007-04-27 22:34 -------- d-------- C:\Arquivos de programas\Puxa R pido
2007-04-27 20:03 -------- d-------- C:\Documents and Settings\Pedro\Dados de aplicativos\MXPLAY
2007-04-27 19:57 -------- d-------- C:\Arquivos de programas\MXPLAY
2007-04-27 19:56 -------- d--h----- C:\Arquivos de programas\InstallShield Installation Information
2007-04-27 19:55 -------- d-------- C:\Documents and Settings\Pedro\Dados de aplicativos\InstallShield
2007-04-27 14:10 -------- d-------- C:\Arquivos de programas\RenomearTudo
2007-04-27 13:06 777984 --a------ C:\WINDOWS\system32\drivers\avg7core.sys
2007-04-26 21:47 -------- d-------- C:\Arquivos de programas\Last.fm
2007-04-26 20:47 -------- d---s---- C:\Documents and Settings\Pedro\Dados de aplicativos\Microsoft
2007-04-25 22:03 -------- d-------- C:\Documents and Settings\Pedro\Dados de aplicativos\Adobe
2007-04-23 20:54 -------- d-------- C:\Documents and Settings\Pedro\Dados de aplicativos\Opera
2007-04-23 14:07 -------- d-------- C:\Arquivos de programas\Adobe
2007-04-22 12:11 -------- d-------- C:\Arquivos de programas\PrimoPDF
2007-04-21 18:08 -------- d-------- C:\Arquivos de programas\SystemRequirementsLab
2007-04-20 14:22 19840 --a------ C:\WINDOWS\system32\drivers\avgmfx86.sys
2007-04-19 18:27 43520 --a------ C:\WINDOWS\system32\CmdLineExt03.dll
2007-04-18 20:07 -------- d-------- C:\Documents and Settings\Pedro\Dados de aplicativos\Publish Providers
2007-04-18 19:18 -------- d-------- C:\Documents and Settings\Pedro\Dados de aplicativos\Sony
2007-04-18 19:10 -------- d-------- C:\Arquivos de programas\Sound Forge 9.0
2007-04-18 19:10 -------- d-------- C:\Arquivos de programas\Arquivos comuns\Microsoft Shared
2007-04-18 13:53 -------- d-------- C:\Arquivos de programas\Free Video to Mp3 Converter
2007-04-16 21:54 720896 --a------ C:\WINDOWS\iun6002ev.exe
2007-04-16 21:45 -------- d-------- C:\Arquivos de programas\Eidos
2007-04-09 19:51 -------- d-------- C:\Arquivos de programas\LimeWire
2007-04-06 19:24 -------- d-------- C:\Arquivos de programas\Realtek
2007-04-06 19:23 315392 --a------ C:\WINDOWS\HideWin.exe
2007-04-06 18:41 -------- d-------- C:\Arquivos de programas\The KMPlayer
2007-04-06 12:09 34308 --a------ C:\WINDOWS\system32\BASSMOD.dll
2007-03-31 21:23 -------- d-------- C:\Documents and Settings\Pedro\Dados de aplicativos\Screenshot Sender
2007-03-29 19:01 -------- d-------- C:\Arquivos de programas\Microsoft Games
2007-03-25 13:05 -------- d-------- C:\Arquivos de programas\SigmaTel
2007-03-24 14:01 -------- d-------- C:\Arquivos de programas\X-Micro
2007-03-19 13:57 98304 --a------ C:\WINDOWS\system32\CddbLangNL.dll
2007-03-19 13:57 98304 --a------ C:\WINDOWS\system32\CddbLangFR.dll
2007-03-19 13:57 98304 --a------ C:\WINDOWS\system32\CddbLangES.dll
2007-03-19 13:57 98304 --a------ C:\WINDOWS\system32\CddbLangDE.dll
2007-03-19 13:57 77824 --a------ C:\WINDOWS\system32\CddbLangJA.dll
2007-03-19 13:57 765952 --a------ C:\WINDOWS\system32\CDDBUI.dll
2007-03-19 13:57 655360 --a------ C:\WINDOWS\system32\CDDBControl.dll
2007-03-19 13:57 102400 --a------ C:\WINDOWS\system32\CddbLangIT.dll
2007-03-18 10:53 -------- d-------- C:\Documents and Settings\Pedro\Dados de aplicativos\Mp3tag
2007-03-18 10:52 -------- d-------- C:\Arquivos de programas\Mp3tag
2007-03-18 10:22 27776 --a------ C:\WINDOWS\system32\drivers\avg7rsxp.sys
2007-03-11 21:39 -------- d-------- C:\Arquivos de programas\Winamp
2007-03-11 12:53 -------- d-------- C:\Arquivos de programas\WinAVIVideoConverter
2007-03-10 21:26 -------- d-------- C:\Arquivos de programas\MSN Messenger
2007-03-10 21:26 -------- d-------- C:\Arquivos de programas\Messenger Plus! Live
2007-03-08 12:36 578048 --a------ C:\WINDOWS\system32\Backup user32.dll
2007-02-18 23:55 737280 --a------ C:\WINDOWS\iun6002.exe
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"SpybotSD TeaTimer"="C:\\Arquivos de programas\\Spybot - Search & Destroy\\TeaTimer.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"AVG7_CC"="C:\\ARQUIV~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP"
"avgnt"="\"C:\\Arquivos de programas\\AntiVir PersonalEdition Classic\\avgnt.exe\" /min"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Minha página inicial atual"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,a0,00,00,00,00,00,00,00,80,02,00,00,3a,02,\
00,00,04,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,a0,00,00,00,00,00,00,00,80,02,00,00,3a,02,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\ARQUIV~1\\Grisoft\\AVG7\\avgw.exe /RUNONCE"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\ARQUIV~1\\Grisoft\\AVG7\\avgw.exe /RUNONCE"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-carregador Browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Daemon de cache de categorias de componente"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{93994DE8-8239-4655-B1D1-5F4E91300429}"=""
"{6148028B-D532-4417-8C0B-5A4A0B745393}"=""
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoDispAppearancePage"=dword:00000000
"NoColorChoice"=dword:00000000
"NoDispBackgroundPage"=dword:00000000
"NoDispCPL"=dword:00000000
"NoDispSettingsPage"=dword:00000000
"NoDispScrSavPage"=dword:00000000
"NoVisualStyleChoice"=dword:00000000
"NoSizeChoice"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"LockTaskbar"=dword:00000000
"NoBandCustomize"=dword:00000000
"NoMovingBands"=dword:00000000
"NoCloseDragDropBands"=dword:00000000
"NoSetTaskbar"=dword:00000000
"NoToolbarsOnTaskbar"=dword:00000000
"NoActiveDesktop"=dword:00000000
"ClassicShell"=dword:00000000
"NoSMBalloonTip"=dword:00000001
"NoSaveSettings"=dword:00000000
"NoRecentDocsHistory"=dword:00000001
"CDRAutoRun"=dword:00000000
"NoDriveTypeAutoRun"=dword:00000095
"NoLowDiskSpaceChecks"=dword:00000001
"MemCheckBoxInRunDlg"=dword:00000000
"NoClose"=dword:00000000
"NoAutoTrayNotify"=dword:00000000
"NoResolveTrack"=dword:00000000
"NoResolveSearch"=dword:00000001
"LinkResolveIgnoreLinkInfo"=dword:00000001
"NoStartBanner"=hex:01,00,00,00
"NoWelcomeScreen"=dword:00000001
"NoRecentDocsNetHood"=dword:00000001
"NoDesktopCleanupWizard"=dword:00000001
"NoSharedDocuments"=dword:00000001
"NoThemesTab"=dword:00000000
"NoToolbarCustomize"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"NoInternetOpenWith"=dword:00000000
"RunStartupScriptSync"=dword:00000000
"SynchronousMachineGroupPolicy"=dword:00000000
"SynchronousUserGroupPolicy"=dword:00000000
"DisableCAD"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoRemoteRecursiveEvents"=dword:00000001
"NoStrCmpLogical"=dword:00000001
"NoClose"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Reader Speed Launch.lnk]
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\ARQUIV~1\\Adobe\\Reader 8.0\\Reader\\reader_sl.exe "
"item"="Adobe Reader Speed Launch"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Reader Synchronizer.lnk]
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Synchronizer.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\ARQUIV~1\\Adobe\\Reader 8.0\\Reader\\AdobeCollabSync.exe "
"item"="Adobe Reader Synchronizer"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Pedro^Menu Iniciar^Programas^Inicializar^BitComet Acceleration Patch.lnk]
"backup"="C:\\WINDOWS\\pss\\BitComet Acceleration Patch.lnkStartup"
"location"="Startup"
"command"="C:\\ARQUIV~1\\BitComet Acceleration Patch\\BitComet Acceleration Patch.exe "
"item"="BitComet Acceleration Patch"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ALCMTR"
"hkey"="HKLM"
"command"="ALCMTR.EXE"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Atualizador - Puxa Rápido]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Atualiza"
"hkey"="HKLM"
"command"="C:\\Arquivos de programas\\Puxa Rápido\\Atualiza.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ashDisp"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Babylon Client]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Babylon"
"hkey"="HKLM"
"command"="C:\\Arquivos de programas\\Babylon\\Babylon-Pro\\Babylon.exe -AutoStart"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDAgent]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="bdagent"
"hkey"="HKLM"
"command"="\"C:\\Arquivos de programas\\Softwin\\BitDefender10\\bdagent.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDMCon]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="bdmcon"
"hkey"="HKLM"
"command"="C:\\ARQUIV~1\\Softwin\\BitDefender10\\bdmcon.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="CTFMON"
"hkey"="HKCU"
"command"="C:\\WINDOWS\\system32\\CTFMON.EXE"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="daemon"
"hkey"="HKLM"
"command"="\"C:\\Arquivos de programas\\DAEMON Tools\\daemon.exe\" -lang 1033"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DaemonTools_WhenUSave_Installer]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DaemonTools_WhenUSave_Installer"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="dumprep 0 -k"
"hkey"="HKLM"
"command"="%systemroot%\\system32\\dumprep 0 -k"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NeroCheck"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\New.net Startup]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NEWDOT~1"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="RTHDCPL"
"hkey"="HKLM"
"command"="RTHDCPL.EXE"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\S3Trayp]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="S3trayp"
"hkey"="HKLM"
"command"="S3trayp.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SkyTel"
"hkey"="HKLM"
"command"="SkyTel.EXE"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="sm56hlpr"
"hkey"="HKLM"
"command"="sm56hlpr.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="jusched"
"hkey"="HKLM"
"command"="C:\\Arquivos de programas\\Java\\jre1.5.0_07\\bin\\jusched.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="VTTimer"
"hkey"="HKLM"
"command"="VTTimer.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Winampa"
"hkey"="HKLM"
"command"="\"C:\\Arquivos de programas\\Winamp\\Winampa.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"XCOMM"=dword:00000002
"VSSERV"=dword:00000002
"LIVESRV"=dword:00000002
"bdss"=dword:00000002
"VundoFixSvc"=dword:00000003
"usnjsvc"=dword:00000003
"RichVideo"=dword:00000002
"ose"=dword:00000003
"IDriverT"=dword:00000003
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\hggfeca
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtsqp
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vturs
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\1-Click Maintenance.job
Completion time: 07-05-09 22:00:40.51
C:\ComboFix.txt ... 07-05-09 22:00
C:\ComboFix2.txt ... 07-05-09 13:46
C:\ComboFix3.txt ... 07-05-08 19:18
====================================================
VundoFix V6.3.21
Checking Java version...
Sun Java not detected
Scan started at 22:02:02 9/5/2007
Listing files found while scanning....
C:\WINDOWS\system32\hggfeca.dll
C:\WINDOWS\system32\srutv.bak2
C:\WINDOWS\system32\srutv.ini
C:\WINDOWS\system32\srutv.ini2
C:\WINDOWS\system32\srutv.tmp
C:\WINDOWS\system32\vturs.dll
Beginning removal...
As you can see, Vundo didn't finish the removal, because the system crashed.
But it found something, that might have caused the taskbar problem. How do I remove them?
Thanks in advance.
Regards,
Piloto
Last edited: