by Get Real! » Mon Jan 31, 2011 10:15 am
I’ve directly marked problem entries in your list as follows…
Entries marked in BLUE need not load and stay resident wasting precious Windows load time and memory resources so you can just delete all entries coloured blue from within HijackThis.
Just click/tick the box of all blue entries and then select “Fix checked”.
Entries marked in RED are very suspicious:
1. Explorer.EXE is the windows file manager but it should not load automatically at startup unless you specifically set it up to, and it should not have a capitalized file extension! Research points to a “vundo/monder infection”.
Start with a Malwarebytes scan and if it doesn’t go away proceed to an online virus scan for that.
2. IncrediMail is a nifty Mail program but also a Trojan! Go to add/remove programs in control panel and uninstall it.
And finally when you've done all the above, rerstart your PC and post a new log again.
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ASG USB Phone\ASG_USB_Phone.exe
C:\WINDOWS\VM305_STI.EXE
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\VoipStunt.com\VoipStunt\VoipStunt.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
F:\Program Files\SkypeMate\SkypeMate.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\IncrediMail\Bin\ImApp.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files\AVG\AVG10\avgnsx.exe
C:\WINDOWS\system32\svchost.exe