Logfile of HijackThis v1.99.1
Scan saved at 1:20:00 AM, on 5/22/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\init32m.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Bpt\bpt.exe
C:\WINDOWS\sys5348.exe
C:\WINDOWS\System32\lsas.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\aim\aim.exe
C:\WINDOWS\System32\sessmgr.exe
C:\windows\virpsgc.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\System32\win32.exe
C:\Program Files\BigFix\BigFix.exe
C:\WINDOWS\System32\Services\{B85C4DA7-659D-48A5-9AA7-3CFBF0E38056}\SVCHOST.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://w-find.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://w-find.com/index.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.clicksear...ndex.php?aff=19
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapp...rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapp...://my.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://w-find.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://w-find.com/index.htm
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: Shell=Explorer.exe init32m.exe
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_5_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: FlashEnhancer Extender - {0AD937E7-2F37-4873-A05E-548A67EF1D0E} - c:\Program Files\Flen\flen.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: FlashEnhancer Ext - {5EDB03AF-0341-4e96-9E9B-3171522E4BAF} - c:\Program Files\Fla\fla.dll
O2 - BHO: BRedObj Class - {63CF97E8-4133-438a-A831-CC9C6D47D673} - c:\Program Files\Reg2\Reg2.dll (file missing)
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_5_0.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WebSavingsfromEbates] C:\Program Files\WebSavingsfromEbates\WebSavingsfromEbatesrun.exe /cp:p "C:\Program Files\WebSavingsfromEbates\System\Code" Main lp: "C:\Program Files\WebSavingsfromEbates"
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BPT] "C:\Program Files\Bpt\bpt.exe"
O4 - HKLM\..\Run: [DI2] "C:\DOCUME~1\Owner\LOCALS~1\Temp\27.exe\27.exe"
O4 - HKLM\..\Run: [sys5348] C:\WINDOWS\sys5348.exe
O4 - HKLM\..\Run: [BPCV2] C:\Program Files\bpc_search\BPCv2.exe
O4 - HKLM\..\Run: [Shellspl] lsas.exe
O4 - HKLM\..\Run: [Service Host] C:\WINDOWS\System32\Services\{B85C4DA7-659D-48A5-9AA7-3CFBF0E38056}\SVCHOST.EXE
O4 - HKLM\..\Run: [FlaCPY] "C:\Program Files\Common Files\Java\flacpy.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Disk Keeper] C:\WINDOWS\System32\Services\{B85C4DA7-659D-48A5-9AA7-3CFBF0E38056}\SECURITY.EXE
O4 - HKLM\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\aim\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [kwkdxkp] c:\windows\virpsgc.exe
O4 - HKCU\..\Run: [sys5348] C:\WINDOWS\sys5348.exe
O4 - HKCU\..\Run: [ihgjyuh] c:\windows\virpsgc.exe
O4 - HKCU\..\Run: [gxifloa] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [glxkgvp] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [kkgrejn] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [jfyhvru] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [clxsdud] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [reguoht] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [tkrpoti] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [blbhdyj] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [huwopvs] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [twihkxd] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [rdnpdne] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [tkdbssj] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [xmibvdv] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [vbcxgyr] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [prrovyc] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [ptkbbuv] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [dujqjnd] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [ilryhxo] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [enkcyvo] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [jsyhpyh] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [jtyjunr] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [vgyoytn] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [mgcgjll] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [qrpyyuf] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [rcihrxq] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [pxefxpr] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [hpvrmll] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [ejiobnt] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [vdvwyyy] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [ietwfxg] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [fngjqtv] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [urdpkeo] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [mrqowbb] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [pvbwmed] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [tvwtgqg] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [xqrwfhi] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [kfjcnwj] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [ewsyibs] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [slhlxnh] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [nkcbocn] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [rltwqkg] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [thtxgdn] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [fbllrxe] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [hcjvsdc] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [tqkqcoo] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [qbdywcu] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [ygmrgmn] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [brivend] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [wfmtwjj] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [qbdellk] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [ljkoawb] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [sgfnwsn] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [cxiqmuo] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [janynmh] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [bowdmpc] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [olkbmmt] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [lqdewss] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [jmynnki] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [hmrtifm] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [lwymnso] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [fkvhyap] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [htrfvay] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [alpmmxc] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [ytnimsl] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [dimgjcw] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [esjyxtu] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [qhbmnvr] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [qxwwdqp] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [mkfechy] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [owpuqum] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [eirjsql] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [burtoxn] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [krskgon] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [tjsigqf] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [nffvitr] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [ejchpvo] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [wbdbrlh] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [vrkatkm] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [sacbqcq] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [janyusu] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [fenhuaq] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [dumqbox] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [abyvhdd] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [uliwpqr] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [yksyyvj] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [bbmycvr] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [ctsoktb] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [ktketop] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [fxawqwi] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [oakvcii] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [hwxeuhj] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [ekaihfs] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [tlpinle] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [jmkxqjn] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [sdoudgp] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [ivixswq] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [lerktfx] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [tnkwcir] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [ohtgcpo] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [qshtjpy] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [cxuqeaw] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [ifxdmsp] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [ddkiqja] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [hwdmkwd] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [sxqijub] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [rrpvydg] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [dgyiesl] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [mbcxetb] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [cquvbty] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [wbauubj] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [webnqyq] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [fxgnfss] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [jbijcaj] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [pihqqwf] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [kbdlxjm] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [tbyypoc] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [rfobsrx] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [gkvhtwf] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [sygmsdo] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [txuhbmm] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [fkrovuw] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [fybjdas] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [wlribjw] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [jqdpdtq] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [hbmpbiq] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [xlvurbo] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [issefap] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [ndslkba] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [sqcfxxs] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [jvobmjw] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [bndmcso] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [cwpdtyt] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [xqlgeyd] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [vvoryxs] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [pacfhxg] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [xxphkhg] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [aliuwpg] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [lrvsyet] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [otthjqd] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [kvbhfsx] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [dhtupln] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [ebugbdy] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [mtabakr] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [erqosxs] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [pftfptb] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [baynsci] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [ddasciv] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [swvhpkb] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [cceodhh] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [kbotnsn] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [whaveyu] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [idvnonh] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [tjclkbv] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [cwhlecp] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [oubqhgs] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [hkcxtio] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [nevwypb] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [lnarxgq] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [wjpolkg] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [fyyyupi] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [gdmvuqq] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [vbjrqom] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [qogqsyl] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [cbnnbrh] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [ulnonfp] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [mtoibmk] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [rbiyjpi] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [ochguor] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [krqcrkp] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [xwxirku] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [jksddfm] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [bmrxkpm] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [tuiorny] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [asuborw] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [mxmngpa] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [yoycoqp] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [fbqyhvd] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [gkynvsk] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [suqdytx] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [vpskjyx] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [xyueoqk] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [wyogknf] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [pvonhnb] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [sptxqcv] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [dfaqfds] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [dgpktcc] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [vpcpoqo] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [ajouasv] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [hoaupgh] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [htvjlai] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [kdwxksu] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [ameoewn] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [gxtngyg] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [bsfedon] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [vbeecbx] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [watnapw] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [ndjjqsh] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [rxuusof] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [jkqompm] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [wrkjvah] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [hykhrup] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [atjxskm] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [bswhndg] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [qsrkqgc] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [ucwvtag] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [wbybiyt] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [aueyduv] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [fukfaig] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [lxtuasb] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [fyuanlm] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [ssecqkk] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [iyhvsec] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [yrwolue] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [devmkkv] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [ytomubk] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [pprnnnx] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [ohhjdlx] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [gnmmjtf] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [hkxpcid] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [siguqvw] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [hegclii] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [udhqgng] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [xdbeuel] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [pypfuhi] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [bltjfhw] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [yipsjxe] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [fobljrq] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [ombqkow] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [uphhwme] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [ukiacgt] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [qerwifw] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [nxfrwbw] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [wrlotgr] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [qunvpvv] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [dkjfsfb] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [hhthpnc] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [aargewi] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [fafbkyd] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [anngfhj] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [npexjhm] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [pebyrwh] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [ufvfgvr] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [pnpchyb] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [gtfgjwv] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [yeskdrq] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [mqiiply] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [yeopite] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [qkwkmgm] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [jytucoy] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [igjbppd] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [jvobaad] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [oyxmknx] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [jvyiuse] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [mriiivx] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [lotfhak] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [prnbydq] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [wbhpnec] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [liaryhl] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [gtwyrqj] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [ggclblr] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [mtpaqne] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [gdbrdrq] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [pmbvmpu] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [dbwidai] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [lfoeveh] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [roykuhb] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [dbfiwfq] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [dyqddju] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [dkenjdd] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [ionwtwo] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [odfhfhu] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [qhmjwwd] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [yfhoevi] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [wpqnpoc] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [wtdlbgo] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [trgdexm] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [sfpkcir] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [kjanauf] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [odexown] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [lfoouog] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [uqidayg] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [hvrkxiv] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [qoelllh] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [rcfjdrk] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [gmmhens] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [qixgsdb] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [alpyllw] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [rubbwui] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [bcekebh] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [jgujlgm] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [mgvcfqu] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [eaomqdo] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [hlrfith] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [lcxpwyk] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [ekgkqbk] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [iipivhk] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [iwrguew] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [blcvwkc] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [ofobeut] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [hlbmyno] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [yeoissr] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [quwhlur] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [qvuasaj] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [daomvna] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [tjhvkbo] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [krqebft] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [eeurcyp] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [bmdauel] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [aryfqri] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [givxpne] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [wuwgcsr] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [rgxdtwd] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [drrmtdh] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [awxuvmn] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [qdudpkh] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [fjwcneo] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [swepvry] c:\windows\itrgsqo.exe
O4 - HKCU\..\Run: [bowwpcn] c:\windows\umyfooo.exe
O4 - HKCU\..\Run: [wupd] C:\WINDOWS\System32\win32.exe
O4 - HKCU\..\Run: [gdsoerk] c:\windows\umyfooo.exe
O4 - HKCU\..\Run: [yxeuhkt] c:\windows\umyfooo.exe
O4 - HKCU\..\Run: [svipggv] c:\windows\umyfooo.exe
O4 - HKCU\..\Run: [vhboqtn] c:\windows\umyfooo.exe
O4 - HKCU\..\Run: [epexhfb] c:\windows\umyfooo.exe
O4 - HKCU\..\Run: [wnppelj] c:\windows\umyfooo.exe
O4 - HKCU\..\Run: [pvspfhy] c:\windows\umyfooo.exe
O4 - HKCU\..\Run: [yslhlfn] c:\windows\umyfooo.exe
O4 - HKCU\..\Run: [gbklfsq] c:\windows\umyfooo.exe
O4 - HKCU\..\Run: [jptokkw] c:\windows\umyfooo.exe
O4 - HKCU\..\Run: [ogpsxjd] c:\windows\umyfooo.exe
O4 - HKCU\..\Run: [cdfyrsx] c:\windows\umyfooo.exe
O4 - HKCU\..\Run: [jygtcpx] c:\windows\umyfooo.exe
O4 - HKCU\..\Run: [towpswx] c:\windows\umyfooo.exe
O4 - HKCU\..\Run: [xdukleg] c:\windows\umyfooo.exe
O4 - HKCU\..\Run: [xmrxqyx] c:\windows\umyfooo.exe
O4 - HKCU\..\Run: [bqyartr] c:\windows\umyfooo.exe
O4 - HKCU\..\Run: [ytelisb] c:\windows\umyfooo.exe
O4 - HKCU\..\Run: [ncxsrhe] c:\windows\umyfooo.exe
O4 - HKCU\..\Run: [wbyyips] c:\windows\umyfooo.exe
O4 - HKCU\..\Run: [euwagjf] c:\windows\umyfooo.exe
O4 - HKCU\..\Run: [eidbdpa] c:\windows\umyfooo.exe
O4 - HKCU\..\Run: [vgsoexx] c:\windows\eldxnic.exe
O4 - HKCU\..\Run: [sjokpgd] c:\windows\eldxnic.exe
O4 - HKCU\..\Run: [fhjmywf] c:\windows\eldxnic.exe
O4 - HKCU\..\Run: [lctxije] c:\windows\eldxnic.exe
O4 - HKCU\..\Run: [obtynvp] c:\windows\eldxnic.exe
O4 - HKCU\..\Run: [wbjheap] c:\windows\eldxnic.exe
O4 - HKCU\..\Run: [evehgkj] c:\windows\eldxnic.exe
O4 - HKCU\..\Run: [ghvqlsy] c:\windows\eldxnic.exe
O4 - HKCU\..\Run: [wuatnsd] c:\windows\eldxnic.exe
O4 - HKCU\..\Run: [gqqkmux] c:\windows\eldxnic.exe
O4 - HKCU\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Web Savings - file://C:\Program Files\WebSavingsfromEbates\System\Temp\ebateswebsavings_script0.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: Microsoft AntiSpyware helper - {6240D3D4-3DB0-4B83-AF07-62A919B80BF1} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {6240D3D4-3DB0-4B83-AF07-62A919B80BF1} - (no file) (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\flsmngr.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\flsmngr.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\flsmngr.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.c...nst20040510.cab
O16 - DPF: {75D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin.SecureControl) - http://secure2.comne...iveSecurity.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.c.../ymmapi_416.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O21 - SSODL: System - {E936C709-61A6-48A7-9BB4-84361C644D94} - vr_sys.dll (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe