I have tried your suggestions and still have a slow computer a few lingering Spyware and Adware viruses. I was looking through some free layouts from my myspace page on hotfreelayouts.com website when I noticed the next day that my computer was running extremely slow and the Internet was turning on by itself and I was getting outerinfo and internet speed monitor pop ups. I have already uninstalled internet speed monitor and outer info. I have run superantispyware, malaware, panda scan and the highjack scan which you can see the logs below. I would appreciate any help you can provide so my computer can get rid of these viruses soon.
Thanks,
Compz
Superantispyware Log:
SUPERAntiSpyware Scan Log
Generated 02/06/2008 at 02:58 AM
Application Version : 3.6.1000
Core Rules Database Version : 3396
Trace Rules Database Version: 1388
Scan type : Complete Scan
Total Scan Time : 03:57:40
Memory items scanned : 338
Memory threats detected : 8
Registry items scanned : 4233
Registry threats detected : 34
File items scanned : 144506
File threats detected : 117
Trojan.Vundo/Variant-Installer/A
C:\WINDOWS\SYSTEM32\KHHFC.DLL
C:\WINDOWS\SYSTEM32\KHHFC.DLL
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPLPR.EXE
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPLPR.EXE
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPENH.EXE
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPENH.EXE
C:\PROGRAM FILES\ROXIO\EASY CD CREATOR 5\DIRECTCD\DIRECTCD.EXE
C:\PROGRAM FILES\ROXIO\EASY CD CREATOR 5\DIRECTCD\DIRECTCD.EXE
C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
C:\PROGRAM FILES\ADOBE\PHOTOSHOP ALBUM STARTER EDITION\3.2\APPS\APDPROXY.EXE
C:\PROGRAM FILES\ADOBE\PHOTOSHOP ALBUM STARTER EDITION\3.2\APPS\APDPROXY.EXE
C:\PROGRAM FILES\QUICKTIME\QTTASK .EXE
C:\PROGRAM FILES\QUICKTIME\QTTASK .EXE
C:\PROGRAM FILES\ITUNES\ITUNESHELPER.EXE
C:\PROGRAM FILES\ITUNES\ITUNESHELPER.EXE
[ATIPTA] C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE
C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE
[TV Now] C:\PROGRAM FILES\HPQ\NOTEBOOK UTILITIES\TVNOW.EXE
C:\PROGRAM FILES\HPQ\NOTEBOOK UTILITIES\TVNOW.EXE
[Display Settings] C:\PROGRAM FILES\HPQ\NOTEBOOK UTILITIES\HPTASKS.EXE
C:\PROGRAM FILES\HPQ\NOTEBOOK UTILITIES\HPTASKS.EXE
[SynTPLpr] C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPLPR.EXE
[SynTPEnh] C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPENH.EXE
[AdaptecDirectCD] C:\PROGRAM FILES\ROXIO\EASY CD CREATOR 5\DIRECTCD\DIRECTCD.EXE
[RealTray] C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
[Adobe Photo Downloader] C:\PROGRAM FILES\ADOBE\PHOTOSHOP ALBUM STARTER EDITION\3.2\APPS\APDPROXY.EXE
[Adobe Reader Speed Launcher] C:\PROGRAM FILES\ADOBE\READER 8.0\READER\READER_SL.EXE
C:\PROGRAM FILES\ADOBE\READER 8.0\READER\READER_SL.EXE
[QuickTime Task] C:\PROGRAM FILES\QUICKTIME\QTTASK .EXE
[iTunesHelper] C:\PROGRAM FILES\ITUNES\ITUNESHELPER.EXE
[MSMSGS] C:\PROGRAM FILES\MESSENGER\MSMSGS.EXE
C:\PROGRAM FILES\MESSENGER\MSMSGS.EXE
HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\Directcd.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\Directcd.exe#Path
HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\MSMSGS.EXE
HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\MSMSGS.EXE#Path
HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\RealPlay.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\RealPlay.exe#Path
HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\TvNow.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\TvNow.exe#Path
C:\DOCUMENTS AND SETTINGS\MAGDA ZAPATA\LOCAL SETTINGS\TEMP\RCX1C.TMP
C:\DOCUMENTS AND SETTINGS\MAGDA ZAPATA\LOCAL SETTINGS\TEMP\RCX1F.TMP
C:\DOCUMENTS AND SETTINGS\MAGDA ZAPATA\LOCAL SETTINGS\TEMP\RCX22.TMP
C:\DOCUMENTS AND SETTINGS\MAGDA ZAPATA\LOCAL SETTINGS\TEMP\RCX25.TMP
C:\DOCUMENTS AND SETTINGS\MAGDA ZAPATA\LOCAL SETTINGS\TEMP\RCX29.TMP
C:\DOCUMENTS AND SETTINGS\MAGDA ZAPATA\LOCAL SETTINGS\TEMP\RCX2C.TMP
C:\DOCUMENTS AND SETTINGS\MAGDA ZAPATA\LOCAL SETTINGS\TEMP\RCX32.TMP
C:\PROGRAM FILES\QUICKTIME\QTTASK .EXE
C:\PROGRAM FILES\QUICKTIME\QTTASK .EXE
C:\PROGRAM FILES\QUICKTIME\QTTASK .EXE
C:\PROGRAM FILES\QUICKTIME\QTTASK .EXE
C:\PROGRAM FILES\QUICKTIME\QTTASK .EXE
C:\PROGRAM FILES\QUICKTIME\QTTASK .EXE
C:\PROGRAM FILES\QUICKTIME\QTTASK .EXE
C:\PROGRAM FILES\QUICKTIME\QTTASK .EXE
C:\PROGRAM FILES\QUICKTIME\QTTASK.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP89\A0017623.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP89\A0017627.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP89\A0017631.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP89\A0017634.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP89\A0017635.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP89\A0017636.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP89\A0017637.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP89\A0017638.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP89\A0017639.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP89\A0017640.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP89\A0017641.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP89\A0017643.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP89\A0017897.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP89\A0017901.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP89\A0017904.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP89\A0017905.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP89\A0017906.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP89\A0017907.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP89\A0017908.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP89\A0017909.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP89\A0017910.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP89\A0017911.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP89\A0017912.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP89\A0017913.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP89\A0017914.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP89\A0017940.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP89\A0017948.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP91\A0017979.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP91\A0017985.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP91\A0017990.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP91\A0017991.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP91\A0017994.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP91\A0017995.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP91\A0017998.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP91\A0017999.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP91\A0018000.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP91\A0018001.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP91\A0018003.EXE
C:\WINDOWS\MROFINU72.EXE.TMP
C:\WINDOWS\Prefetch\ITUNESHELPER.EXE-15823303.pf
Trojan.Vundo/Variant-Installer
[Cpqset] C:\PROGRAM FILES\HPQ\DEFAULT SETTINGS\CPQSET.EXE
C:\PROGRAM FILES\HPQ\DEFAULT SETTINGS\CPQSET.EXE
[PreloadApp] C:\HP\DRIVERS\PRINTERS\PHOTOSMART\HPHPRLD.EXE
C:\HP\DRIVERS\PRINTERS\PHOTOSMART\HPHPRLD.EXE
[srmclean] C:\CPQS\SCOM\SRMCLEAN.EXE
C:\CPQS\SCOM\SRMCLEAN.EXE
[Aaou] C:\PROGRA~1\COMMON~1\CROSOF~1\WINSPOOL.EXE
C:\PROGRA~1\COMMON~1\CROSOF~1\WINSPOOL.EXE
[load] C:\WINDOWS\SYSTEM32\KHHFC.EXE
C:\WINDOWS\SYSTEM32\KHHFC.EXE
C:\DOCUMENTS AND SETTINGS\MAGDA ZAPATA\APPLICATION DATA\ICROSO~1\REGEDIT.EXE
C:\DOCUMENTS AND SETTINGS\MAGDA ZAPATA\LOCAL SETTINGS\TEMP\TMP3B.TMP
C:\PROGRAM FILES\COMMON FILES\CROSOF~1\WINSPOOL.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP89\A0017628.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP89\A0017629.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP89\A0017632.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP89\A0017633.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP89\A0017645.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP89\A0017899.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP89\A0017900.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP89\A0017902.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP89\A0017903.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP89\A0017935.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP91\A0017982.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP91\A0017984.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP91\A0017987.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP91\A0017988.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP91\A0018004.EXE
C:\WINDOWS\SYSTEM32\RCX34.TMP
C:\WINDOWS\SYSTEM32\RCX37.TMP
C:\WINDOWS\Prefetch\WINSPOOL.EXE-17017B16.pf
Unclassified.Unknown Origin
HKLM\Software\Classes\CLSID\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}
HKCR\CLSID\{6D794CB4-C7CD-4C6F-BFDC-9B77AFBDC02C}
HKCR\CLSID\{6D794CB4-C7CD-4C6F-BFDC-9B77AFBDC02C}\InprocServer32
HKCR\CLSID\{6D794CB4-C7CD-4C6F-BFDC-9B77AFBDC02C}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\RQRSSRS.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}
HKCR\CLSID\{6D794CB4-C7CD-4C6F-BFDC-9B77AFBDC02C}
Adware.Tracking Cookie
C:\Documents and Settings\Magda Zapata\Cookies\magda [email protected][1].txt
C:\Documents and Settings\Magda Zapata\Cookies\magda zapata@doubleclick[1].txt
C:\Documents and Settings\Magda Zapata\Cookies\magda zapata@2o7[1].txt
C:\Documents and Settings\Magda Zapata\Cookies\magda zapata@directtrack[1].txt
C:\Documents and Settings\Magda Zapata\Cookies\magda [email protected][1].txt
C:\Documents and Settings\Magda Zapata\Cookies\magda [email protected][1].txt
Adware.ClickSpring
HKLM\Software\ClickSpring
HKLM\Software\ClickSpring#UBWKR
C:\DOCUMENTS AND SETTINGS\MAGDA ZAPATA\LOCAL SETTINGS\TEMP\!UPDATE.EXE
C:\DOCUMENTS AND SETTINGS\MAGDA ZAPATA\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\WTQBC14B\!UPDATE-4495[1].0000
Adware.ClickSpring-Variant
C:\DOCUMENTS AND SETTINGS\MAGDA ZAPATA\APPLICATION DATA\ICROSO~1\REGEDIT .EXE
C:\DOCUMENTS AND SETTINGS\MAGDA ZAPATA\LOCAL SETTINGS\TEMP\TMP27.TMP
C:\DOCUMENTS AND SETTINGS\MAGDA ZAPATA\LOCAL SETTINGS\TEMP\TMP4.TMP
C:\DOCUMENTS AND SETTINGS\MAGDA ZAPATA\LOCAL SETTINGS\TEMP\TMP5.TMP
C:\PROGRAM FILES\COMMON FILES\CROSOF~1\WINSPOOL .EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP89\A0017567.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP89\A0017661.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP89\A0017930.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP90\A0017954.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP91\A0017964.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP91\A0017997.EXE
Adware.OuterInfo-Installer
C:\SYSTEM VOLUME INFORMATION\_RESTORE{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP90\A0017956.EXE
Adware.Vundo Variant
C:\WINDOWS\SYSTEM32\NUYQEXS.DLL
Panda Scan Log:
Incident Status Location
Adware:Adware/PurityScan Not disinfected c:\progra~1\common~1\crosof~1\winspool.exe
Adware:Adware/Yazzle Not disinfected C:\Documents and Settings\Magda Zapata\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\QUAR1.14930
Adware:Adware/Yazzle Not disinfected C:\Documents and Settings\Magda Zapata\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\QUAR1.29598
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Magda Zapata\Cookies\magda [email protected][2].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Magda Zapata\Cookies\magda zapata@doubleclick[1].txt
Adware:Adware/PurityScan Not disinfected C:\Documents and Settings\Magda Zapata\Local Settings\Temp\!update.exe
Adware:Adware/PurityScan Not disinfected C:\Documents and Settings\Magda Zapata\Local Settings\Temp\TMP34.tmp
Adware:Adware/PurityScan Not disinfected C:\Documents and Settings\Magda Zapata\Local Settings\Temporary Internet Files\Content.IE5\2LMNSB8D\!update-4495[1].0000
Adware:Adware/PurityScan Not disinfected C:\Documents and Settings\Magda Zapata\Local Settings\Temporary Internet Files\Content.IE5\WD87WRCF\!update-4495[1].0000
Adware:Adware/PurityScan Not disinfected C:\Program Files\Common Files\??crosoft\winspool.exe
Possible Virus. Not disinfected C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
Adware:Adware/Yazzle
Hijack This Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:17:38 PM, on 2/6/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\carpserv.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\Synaptics\SynTP\SynTPLpr .exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy .exe
C:\Documents and Settings\Magda Zapata\My Documents\?ymantec\n?tdde.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh .exe
C:\Program Files\iTunes\iTunesHelper .exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware .exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wuauclt.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\PROGRA~1\COMMON~1\CROSOF~1\winspool.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.att.net/i...arch/index.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.optonline.net/Home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.att.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
F3 - REG:win.ini: load=C:\WINDOWS\System32\khhfc.exe
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AutoTBar] C:\hp\bin\autotbar.exe
O4 - HKLM\..\Run: [TV Now] C:\Program Files\HPQ\Notebook Utilities\TvNow.exe /RK
O4 - HKLM\..\Run: [Display Settings] C:\Program Files\HPQ\Notebook Utilities\hptasks.exe /s
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask .exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Scvpt] "C:\Documents and Settings\Magda Zapata\My Documents\?ymantec\n?tdde.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Aaou] "C:\PROGRA~1\COMMON~1\CROSOF~1\winspool.exe" -vt ndrv
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Billminder.lnk = C:\Program Files\Quicken\billmind.exe
O4 - Global Startup: Image Transfer.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\Quicken\QWDLLS.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Search - http://edits.mywebse...?p=ZKxdm021YYUS
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.att.net
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O18 - Filter hijack: text/html - {07851C6A-1C43-41d9-8319-BC89154A8C00} - C:\Program Files\RcvSystem\httpdchk.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
--
End of file - 5981 bytes