jake - 06-11-13 16:04:14.85 Service Pack 2
ComboFix 06.11.9 - Running from: "C:\Documents and Settings\jake"
((((((((((((((((((((((((((((((((((((((((((( E-Give / Ssk's Log )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Documents and Settings\jake\Application Data\Dxcknwrd.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\cfg32.exe
C:\WINDOWS\cfg32a.exe
C:\WINDOWS\Duce6.exe
C:\dfndrff_e54.exe
C:\kybrdff_e54.exe
C:\nwnmff_e54.exe
C:\Documents and Settings\jake\setup9X.exe
C:\RDFX4.exe
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\cmd.com
C:\WINDOWS\system32\netstat.com
C:\WINDOWS\system32\ping.com
C:\WINDOWS\system32\regedit.com
C:\WINDOWS\system32\taskkill.com
C:\WINDOWS\system32\tasklist.com
C:\WINDOWS\system32\tracert.com
C:\Program Files\batty2
C:\Program Files\winupdates
C:\WINDOWS\Y2hyaXM
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\QooBox\Purity\WINDOWS\MCROSO~1
C:\QooBox\Purity\WINDOWS\MCROSO~1\M?crosoft
C:\QooBox\Purity\WINDOWS\system32\APPATC~1
C:\QooBox\Purity\WINDOWS\system32\YMANTE~1
C:\QooBox\Purity\WINDOWS\system32\YMANTE~1\n?tepad.exe
((((((((((((((((((((((((((((((( Files Created from 2006-10-13 to 2006-11-13 ))))))))))))))))))))))))))))))))))
2006-11-17 18:13 102,400 --a------ C:\WINDOWS\cfg32r.dll
2006-11-17 11:48 397,312 --a------ C:\WINDOWS\cfg32p.dll
2006-11-16 20:30 213,072 --a------ C:\Qoofix.dll
2006-11-16 20:30 102,400 --a------ C:\Qoofix.exe
2006-11-16 19:08 45,056 --a------ C:\WINDOWS\cfg32s.dll
2006-11-16 19:08 110,592 --a------ C:\WINDOWS\cfg32o.dll
2006-11-16 14:11 218 --a------ C:\WINDOWS\tptyp.dll
2006-11-16 13:46 32,768 --a------ C:\WINDOWS\vvlckofa.exe
2006-11-16 13:46 204 --a------ C:\Documents and Settings\jake\jdkfjdskfjkdsjf.bat
2006-11-16 13:45 32,768 --a------ C:\Documents and Settings\jake\install.exe
2006-11-16 13:45 1,284 --a------ C:\WINDOWS\system32\nrqec335.sys
2006-11-16 13:43 8,464 --a------ C:\WINDOWS\system32\sporder.dll
2006-11-16 13:42 537,376 -r-hs---- C:\WINDOWS\suocgnhA.exe
2006-11-16 13:42 430,080 --a------ C:\windows_e54.exe
2006-11-16 13:42 204 --a------ C:\WINDOWS\system32\jdkfjdskfjkdsjf.bat
2006-11-16 13:42 2 --a------ C:\WINDOWS\system32\wtssvit.exe
2006-11-16 13:42 178,306 --a------ C:\WINDOWS\ac3_0008.exe
2006-11-16 13:42 167,936 --a------ C:\WINDOWS\sys011259916461-.exe
2006-11-11 13:42 217,276 --a------ C:\WINDOWS\srviyibw.exe
2006-11-11 13:41 45,056 --a------ C:\WINDOWS\system32nrnqetwbz.exe
2006-11-11 13:41 323,072 --a------ C:\165.exe
2006-11-11 13:41 32,768 --a------ C:\WINDOWS\system32\setup9X.exe
2006-11-11 13:41 32,768 --a------ C:\WINDOWS\system32\install.exe
2006-11-11 13:41 28,672 --a------ C:\WINDOWS\system32\pfbo0yj.exe
2006-11-11 13:41 147,456 --a------ C:\WINDOWS\system32\vbzip10.dll
2006-11-11 13:41 1,122,304 --a------ C:\WINDOWS\system32\rnnypbw.exe
2006-11-11 13:41 0 --a------ C:\WINDOWS\system32ysjaevwx.exe
2006-11-05 11:56 129,784 --------- C:\WINDOWS\system32\pxafs.dll
2006-10-29 03:13 299,008 --a------ C:\WINDOWS\uninst.exe
2006-10-24 20:02 4,682 --a------ C:\WINDOWS\system32\npptNT2.sys
2006-10-23 17:02 24 --a------ C:\WINDOWS\system32\sysogg.dll
2006-10-23 17:01 233,472 --a------ C:\WINDOWS\system32\lame_enc.dll
2006-10-23 17:01 1,703,936 --a------ C:\WINDOWS\system32\NCTAudioFile.dll
2006-10-21 23:49 68,888 --a------ C:\WINDOWS\system32\xinput1_3.dll
2006-10-21 23:49 62,744 --a------ C:\WINDOWS\system32\xinput1_2.dll
2006-10-21 23:49 237,848 --a------ C:\WINDOWS\system32\xactengine2_4.dll
2006-10-21 23:49 236,824 --a------ C:\WINDOWS\system32\xactengine2_3.dll
2006-10-21 23:49 2,414,360 --a------ C:\WINDOWS\system32\d3dx9_31.dll
2006-10-21 23:49 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll
2006-10-21 23:49 15,128 --a------ C:\WINDOWS\system32\x3daudio1_1.dll
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-11-17 18:47 -------- d-------- C:\Documents and Settings\jake\Application Data\teamspeak2
2006-11-17 18:17 -------- d-------- C:\Program Files\Hijackthis
2006-11-17 02:58 -------- d-------- C:\Documents and Settings\jake\Application Data\Xfire
2006-11-17 02:01 -------- d-------- C:\Program Files\Java
2006-11-17 02:00 -------- d-------- C:\Program Files\Common Files\Java
2006-11-17 02:00 -------- d-------- C:\Program Files\Common Files
2006-11-16 19:17 -------- d-------- C:\Program Files\PSCastor
2006-11-16 19:13 -------- d-------- C:\Program Files\Security Task Manager
2006-11-16 17:57 -------- d-------- C:\Program Files\ewido anti-spyware 4.0
2006-11-16 14:09 -------- d-------- C:\Program Files\Common Files\Microsoft Shared
2006-11-16 13:50 -------- d-------- C:\Program Files\Online Services
2006-11-16 13:46 -------- d-------- C:\Program Files\Windows NT
2006-11-16 13:46 -------- d-------- C:\Program Files\Outlook Express
2006-11-13 16:00 -------- d-------- C:\Program Files\Mozilla Firefox
2006-11-13 15:58 -------- d-------- C:\Program Files\Steam
2006-11-09 17:14 -------- d---s---- C:\Program Files\Xfire
2006-11-06 19:17 -------- d-------- C:\Program Files\Teamspeak2_RC2
2006-11-05 18:18 -------- d-------- C:\Program Files\mIRC
2006-11-05 12:20 -------- d-------- C:\Program Files\Winamp
2006-10-30 00:24 -------- d-------- C:\Program Files\World of Warcraft
2006-10-29 23:55 -------- d-------- C:\Program Files\Atari
2006-10-29 22:32 -------- d-------- C:\Program Files\Common Files\Blizzard Entertainment
2006-10-29 22:31 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-10-29 11:54 -------- d-------- C:\Program Files\GameSpy Arcade
2006-10-29 03:29 -------- d-------- C:\Program Files\DOSBox-0.65
2006-10-23 17:01 -------- d-------- C:\Program Files\MP3 Converter Simple
2006-10-22 20:15 -------- d-------- C:\Program Files\Rockstar Games
2006-10-22 11:18 -------- d-------- C:\Documents and Settings\jake\Application Data\Leadertech
2006-10-22 02:37 -------- d-------- C:\Documents and Settings\jake\Application Data\IGN_DLM
2006-10-22 01:23 -------- d-------- C:\Program Files\Codemasters
2006-10-22 01:12 -------- d-------- C:\Program Files\IGN
2006-10-21 19:53 -------- d-------- C:\Program Files\Common Files\SWF Studio
2006-10-18 14:48 -------- d-------- C:\Program Files\Google
2006-10-14 23:06 -------- d-------- C:\Documents and Settings\jake\Application Data\ZangoToolbar
2006-10-11 17:43 -------- d-------- C:\Program Files\Game Cam
2006-10-11 17:38 -------- d-------- C:\Program Files\TechSmith
2006-10-11 17:38 -------- d-------- C:\Program Files\Common Files\Wise Installation Wizard
2006-10-11 16:09 21840 --a----t- C:\WINDOWS\system32\SIntfNT.dll
2006-10-11 16:09 17212 --a----t- C:\WINDOWS\system32\SIntf32.dll
2006-10-11 16:09 12067 --a----t- C:\WINDOWS\system32\SIntf16.dll
2006-10-10 22:22 -------- d-------- C:\Program Files\Toribash-2.1
2006-10-09 12:36 -------- d-------- C:\Program Files\Toribash
2006-10-08 13:23 -------- d-------- C:\Program Files\SecondLife
2006-10-08 13:23 -------- d-------- C:\Documents and Settings\jake\Application Data\SecondLife
2006-10-08 12:55 14848 --a------ C:\WINDOWS\system32\BASSMOD.dll
2006-10-08 12:55 -------- d-------- C:\Program Files\MagicISO
2006-10-08 12:33 223128 --a------ C:\WINDOWS\system32\drivers\vaxscsi.sys
2006-10-08 12:30 611064 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2006-10-07 21:58 -------- d-------- C:\Program Files\FrostWire
2006-09-30 13:25 98304 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2006-09-30 12:32 -------- d-------- C:\Program Files\Diablo II
2006-09-22 22:47 -------- d-------- C:\Program Files\Eidos
2006-09-22 21:22 -------- d-------- C:\Program Files\Microsoft Games
2006-09-21 22:24 -------- d-------- C:\Program Files\MTA San Andreas
2006-09-19 19:11 -------- d-------- C:\Program Files\SnadBoy's Revelation v2
2006-09-19 19:08 -------- d-------- C:\Program Files\PartyGaming
2006-09-19 19:06 -------- d-------- C:\Program Files\zbattle.net
2006-09-18 23:36 -------- d-------- C:\Program Files\Blender Foundation
2006-09-18 17:06 -------- d-------- C:\Documents and Settings\jake\Application Data\Google
2006-09-17 00:29 -------- d-------- C:\Documents and Settings\jake\Application Data\FrostWire
2006-09-15 15:16 53248 --a------ C:\WINDOWS\uni_e6h.exe
2006-09-12 23:01 1084416 --a------ C:\WINDOWS\system32\msxml3.dll
2006-09-09 12:51 2829 --a------ C:\WINDOWS\DiabUnin.pif
2006-09-09 12:51 118784 --a------ C:\WINDOWS\DiabUnin.exe
2006-09-07 20:52 28672 --a------ C:\WINDOWS\system32\syscmd.dll
2006-08-25 09:45 617472 --a------ C:\WINDOWS\system32\comctl32.dll
2006-08-24 21:47 115880 --------- C:\WINDOWS\system32\pxinsi64.exe
2006-08-21 06:21 16896 --a------ C:\WINDOWS\system32\fltlib.dll
2006-08-21 03:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe
2006-08-16 05:58 100352 --a------ C:\WINDOWS\system32\6to4svc.dll
2006-08-13 14:08 86528 --a------ C:\WINDOWS\bnetunin.exe
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"Steam"="\"C:\\Program Files\\Steam\\Steam.exe\" -silent"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.908.5008\\GoogleToolbarNotifier.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"GhostStartTrayApp"="C:\\Program Files\\Symantec\\Norton Ghost 2003\\GhostStartTrayApp.exe"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"D-Link Wireless G WDA-1320"="C:\\Program Files\\D-Link\\Wireless G WDA-1320\\AirGCFG.exe"
"ANIWZCS2Service"="C:\\Program Files\\ANI\\ANIWZCS2 Service\\WZCSLDR2.exe"
"ATICCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe\" runtime -Delay"
"DAEMON Tools"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="C:\\Program Files\\Windows NT\\kyzeqel.html"
"SubscribedURL"=""
"FriendlyName"=""
"Flags"=dword:00002000
"Position"=hex:2c,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,00,00,e8,\
03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,00,14,00,00,00
"CurrentState"=hex:01,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,\
00,00,01,00,00,00
"RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
"Source"="C:\\Program Files\\Outlook Express\\howynyjaj.html"
"SubscribedURL"=""
"FriendlyName"=""
"Flags"=dword:00002000
"Position"=hex:2c,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,00,00,ea,\
03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,00,14,00,00,00
"CurrentState"=hex:01,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,\
00,00,01,00,00,00
"RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{03A80B1D-5C6A-42c2-9DFB-81B6005D8023}"="Trend Micro Anti-Spyware Shell Extension"
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
Completion time: 06-11-13 16:07:49.42
C:\ComboFix.txt ... 06-11-13 16:07
Logfile of HijackThis v1.99.1
Scan saved at 4:11:30 PM, on 11/13/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
C:\Program Files\D-Link\Wireless G WDA-1320\AirGCFG.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Silicon Image\SiISATARaid\SATARaid.exe
C:\Program Files\TechSmith\SnagIt 8\SnagIt32.exe
C:\Program Files\TechSmith\SnagIt 8\TSCHelp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://myspace.com/R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://farm.thinktar...ams/r...&o=0&q=O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\cfg32p.dll
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: CFG32S - {7564B020-44E8-4c9b-A887-C6EC41AC67DA} - C:\WINDOWS\cfg32r.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Scaggy Insert - {C68AE9C0-0909-4DDC-B661-C1AFB9F59898} - C:\WINDOWS\cfg32o.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Search - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\WINDOWS\cfg32s.dll
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [D-Link Wireless G WDA-1320] C:\Program Files\D-Link\Wireless G WDA-1320\AirGCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: SATARaid.lnk = ?
O4 - Global Startup: SnagIt 8.lnk = C:\Program Files\TechSmith\SnagIt 8\SnagIt32.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab31267.cabO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) -
http://www.fileplane...C_2.3.2.100.cabO16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -
http://download.mcaf...01/mcinsctl.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoft...free/asinst.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://messenger.zon...ro.cab32846.cabO16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} -
http://download.mcaf...,26/mcgdmgr.cabO16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) -
http://gamedownload....GPlugin9USA.cabO23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe