Scan saved at 6:29:20 PM, on 5/22/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\combo.exe
C:\WINDOWS\System32\avznkp.exe
C:\WINDOWS\System32\taskmgr.exe
C:\WINDOWS\lt.exe
C:\Program Files\Compaq\Compaq Advisor\bin\compaq-rba.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\vwa32.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\mozilla.org\Mozilla\mozilla.exe
c:\windows\system32\iutpro.exe
C:\WINDOWS\svcproc.exe
C:\Program Files\Adobe\Acrobat 6.0\Reader\AcroRd32.exe
C:\WINDOWS\System32\wisptis.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZSTC10.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZSTW10.exe
C:\Documents and Settings\DHERE\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\DHERE\LOCALS~1\Temp\se.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\DHERE\LOCALS~1\Temp\se.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.mail.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Compaq
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: Band Class - {0007522A-2297-43C1-8EB1-C90B0FF20DA5} - C:\WINDOWS\enhtb.dll (file missing)
O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\cfgmgr52.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0AD937E7-2F37-4873-A05E-548A67EF1D0E} - (no file)
O2 - BHO: RsyncHlpr Class - {16B238D5-80DE-47CE-8F17-B3ECE2C2248D} - C:\WINDOWS\System32\rsyncmon.dll
O2 - BHO: FlashEnhancer Ext - {5EDB03AF-0341-4e96-9E9B-3171522E4BAF} - c:\Program Files\Fla\fla.dll
O2 - BHO: (no name) - {8DA5457F-A8AA-4CCF-A842-70E6FD274094} - C:\PROGRA~1\COMMON~1\WinTools\WToolsT.dll (file missing)
O2 - BHO: ohb - {999A06FF-10EF-4A29-8640-69E99882C26B} - C:\WINDOWS\System32\nsf69D.dll
O2 - BHO: FlashEnhancer Extnder - {A749B4BC-7621-4a80-9220-D0A283367DD5} - c:\Program Files\Fln\fln.dll (file missing)
O2 - BHO: CIEExtension Object - {B51DC573-E998-4834-9B45-BAB7C2AE0A75} - C:\Program Files\Ad-Protect\ADPIEmonitor.dll (file missing)
O2 - BHO: (no name) - {ED103D9F-3070-4580-AB1E-E5C179C1AE41} - (no file)
O2 - BHO: (no name) - {F867A896-5966-4071-852C-54DF65E36ADB} - C:\WINDOWS\System32\nneheha.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [Smapp] Smtray.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\Compaq\Easy Access Button Support\StartEAK.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [Vio Pes] vwa32.exe
O4 - HKLM\..\Run: [sountskmanager] sountaskmgr
O4 - HKLM\..\Run: [scvhost.exe] scvhost.exe
O4 - HKLM\..\Run: [Microsoft Update] msawindows.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [4U4Rfn] C:\documents and settings\dhere\local settings\temp\4U4Rfn.exe
O4 - HKLM\..\Run: [pQpJE8y] C:\documents and settings\dhere\local settings\temp\pQpJE8y.exe
O4 - HKLM\..\Run: [SStb.exe] SStb.exe
O4 - HKLM\..\Run: [ssqb.exe] ssqb.exe
O4 - HKLM\..\Run: [CKBcC5c] C:\documents and settings\dhere\local settings\temp\CKBcC5c.exe
O4 - HKLM\..\Run: [yhqY3d7] C:\documents and settings\dhere\local settings\temp\yhqY3d7.exe
O4 - HKLM\..\Run: [xVCVpv] C:\documents and settings\dhere\local settings\temp\xVCVpv.exe
O4 - HKLM\..\Run: [DI2] "C:\DOCUME~1\DHERE\LOCALS~1\Temp\27.exe\27.exe"
O4 - HKLM\..\Run: [vcmxin] C:\WINDOWS\system32\BW_ActiveX.Stub.exe
O4 - HKLM\..\Run: [Dvx] C:\WINDOWS\System32\wsxsvc\wsxsvc.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [csuptfn] c:\windows\system32\csuptfn.exe
O4 - HKLM\..\Run: [msw] C:\Documents and Settings\All Users\Application Data\msw\MSW.exe
O4 - HKLM\..\Run: [Breg] "C:\Program Files\Common Files\Java\bptre.exe"
O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
O4 - HKLM\..\Run: [nsvcin] C:\WINDOWS\system32\n20050308.exe
O4 - HKLM\..\Run: [BMan] C:\Documents and Settings\All Users\Application Data\msw\BMan1.exe
O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\System32\exp.exe
O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\System32\wintask.exe
O4 - HKLM\..\Run: [win3207618104677] C:\WINDOWS\win3207618104677.exe
O4 - HKLM\..\Run: [tguofjwmndhxdjcbihzvz] C:\WINDOWS\loloqmft.exe
O4 - HKLM\..\Run: [A70F6A1D-0195-42a2-934C-D8AC0F7C08EB] rundll32.exe E6F1873B.DLL,D9EBC318C
O4 - HKLM\..\Run: [98D0CE0C16B1] rundll32.exe D0CE0C16B1,D0CE0C16B1
O4 - HKLM\..\Run: [ms06761810467] C:\WINDOWS\ms06761810467.exe
O4 - HKLM\..\Run: [AutoLoaderq0t61YKfMKPJ] "C:\WINDOWS\System32\ulrrenv.exe" /HideDir /HideUninstall /PC="CP.FHB" /ShowLegalNote="nonbranded"
O4 - HKLM\..\Run: [q72g3sX] ulrrenv.exe
O4 - HKLM\..\Run: [abasa5jrp] C:\WINDOWS\System32\abasa5jrp.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [sealmon] C:\Program Files\SealedMedia\sealmon.exe
O4 - HKLM\..\Run: [ Messenger] C:\WINDOWS\System32\p0n8ting.exe
O4 - HKLM\..\Run: [combop.exe] combop.exe
O4 - HKLM\..\Run: [combo.exe] combo.exe
O4 - HKLM\..\Run: [FlnCPY] "C:\Program Files\Common Files\Java\flncpy.exe"
O4 - HKLM\..\Run: [FlaCPY] "C:\Program Files\Common Files\Java\flacpy.exe"
O4 - HKLM\..\Run: [RSync] C:\WINDOWS\System32\netsync.exe
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\System32\avznkp.exe reg_run
O4 - HKLM\..\Run: [Service Host] C:\WINDOWS\System32\Services\{0F30DB53-0F59-49D5-9A2D-C1517C1EDD9B}\SVCHOST.EXE
O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\DHERE\LOCALS~1\Temp\se.dll,DllInstall
O4 - HKLM\..\Run: [wnfida] c:\windows\system32\iutpro.exe
O4 - HKLM\..\RunServices: [Vio Pes] vwa32.exe
O4 - HKLM\..\RunServices: [sountskmanager] sountaskmgr
O4 - HKLM\..\RunServices: [scvhost.exe] scvhost.exe
O4 - HKLM\..\RunServices: [Microsoft Update] msawindows.exe
O4 - HKLM\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe
O4 - HKLM\..\RunOnce: [Compaq_RBA] C:\Program Files\Compaq\Compaq Advisor\bin\compaq-rba.exe -z
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [sysmonnt] C:\WINDOWS\System32\sysmonnt
O4 - HKCU\..\Run: [Ajr] C:\WINDOWS\System32\??anregw.exe
O4 - HKCU\..\Run: [xjyfrrf] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [oapdtoi] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [mimfimp] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [viiqxhr] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [bxtsjtm] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [oaeosns] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [cvilixc] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [dxtfnah] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [xhtyvxh] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [ykhenxg] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [bntcsvf] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [yeeturm] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [yycfhae] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [apjpdsl] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [ryphkdi] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [hgepfsi] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [xrnsdev] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [ctrereq] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [kmhasdl] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [ictxgin] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [jkhfmhx] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [gammcdp] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [ciqlyxv] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [fuhsvxi] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [hrcrrya] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [mprgjcu] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [usyytli] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [gqjitfm] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [ipayptn] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [jfbvdlc] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [ygurpra] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [nkucbif] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [hfmqeks] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [gyacbsr] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [xyeehyg] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [dmqdmfd] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [qodltbq] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [wuoudri] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [indedyr] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [ucwacne] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [waufsgx] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [wnhrkpx] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [okbctba] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [hjqlkcl] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [ygnhrjv] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [xbhwfhp] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [ificgic] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [stywcvk] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [uqjobsh] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [lncqmls] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [vojisat] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [ecujgim] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [qkjwnpp] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [yqncquq] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [nqqyskv] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [wqyaxoi] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [opotjro] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [otuvnjx] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [fensrhb] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [cnywnjm] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [vovgach] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [faivdjx] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [rpdmixy] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [audpfqn] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [layliog] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [ipsuyuc] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [fkmgejw] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [oribmju] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [lejfiuc] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [eascnho] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [vdinvrv] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [spdxkyq] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [mahygls] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [ibciqmj] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [vsafrxo] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [yonreiy] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [dllfgie] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [aepeaff] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [hpmeboh] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [shacofm] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [lliktuk] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [sqaupnn] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [hwiauou] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [tintjeo] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [iktlytn] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [kpuwadh] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [oqnrunl] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [sihfsxc] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [yccnfwm] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [elkadib] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [xalhebu] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [letcqnl] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [gabsivd] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [mxxnfkt] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [ojxpwqx] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [lfrinlm] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [ilruilc] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [ugeetqy] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [ooywhfb] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [lkymjwm] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [vwisovs] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [xjotoqj] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [idwofbq] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [qmonkxy] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [qxkmktd] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [igcyknb] c:\windows\ddlkwrq.exe
O4 - HKCU\..\Run: [wnbgssm] c:\windows\ryxqtkn.exe
O4 - HKCU\..\Run: [ppviocc] c:\windows\nexqgiq.exe
O4 - HKCU\..\Run: [jmontux] c:\windows\ikgerqa.exe
O4 - HKCU\..\Run: [qwveiap] c:\windows\khkoyvr.exe
O4 - HKCU\..\Run: [linofsx] c:\windows\rmwxwgm.exe
O4 - HKCU\..\Run: [mwdjklp] c:\windows\rmwxwgm.exe
O4 - HKCU\..\Run: [ksjpent] c:\windows\kqcpmms.exe
O4 - HKCU\..\Run: [vqcxadn] c:\windows\tfudewl.exe
O4 - HKCU\..\Run: [alkvyes] c:\windows\avbenjt.exe
O4 - HKCU\..\Run: [lofioik] c:\windows\sltvdji.exe
O4 - HKCU\..\Run: [eawnsom] c:\windows\ksaauyu.exe
O4 - HKCU\..\Run: [fvwjkyl] c:\windows\hxfwwxc.exe
O4 - HKCU\..\Run: [inaifkb] c:\windows\hxfwwxc.exe
O4 - HKCU\..\Run: [ekhhnqv] c:\windows\epjujcu.exe
O4 - HKCU\..\Run: [wbplrwr] c:\windows\lsujyff.exe
O4 - HKCU\..\Run: [lhcpmxk] c:\windows\xexlxxv.exe
O4 - HKCU\..\Run: [siiemkh] c:\windows\lsujyff.exe
O4 - HKCU\..\Run: [cikegjn] c:\windows\xexlxxv.exe
O4 - HKCU\..\Run: [mtupqnq] c:\windows\lsujyff.exe
O4 - HKCU\..\Run: [tjrpvvu] c:\windows\xexlxxv.exe
O4 - HKCU\..\Run: [icgdwdy] c:\windows\lsujyff.exe
O4 - HKCU\..\Run: [bsxjgpl] c:\windows\xexlxxv.exe
O4 - HKCU\..\Run: [jcmoeut] c:\windows\lsujyff.exe
O4 - HKCU\..\Run: [mqabuws] c:\windows\xexlxxv.exe
O4 - HKCU\..\Run: [qltlcum] c:\windows\lsujyff.exe
O4 - HKCU\..\Run: [kanuhys] c:\windows\xexlxxv.exe
O4 - HKCU\..\Run: [chaxanb] c:\windows\lsujyff.exe
O4 - HKCU\..\Run: [fqdkcdw] c:\windows\xexlxxv.exe
O4 - HKCU\..\Run: [qckvsjj] c:\windows\lsujyff.exe
O4 - HKCU\..\Run: [nehtpvm] c:\windows\xexlxxv.exe
O4 - HKCU\..\Run: [rfgqjri] c:\windows\lsujyff.exe
O4 - HKCU\..\Run: [whtvbfk] c:\windows\xexlxxv.exe
O4 - HKCU\..\Run: [srrysqc] c:\windows\khppcsy.exe
O4 - HKCU\..\Run: [qvysnej] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [nibtxul] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [cooqksr] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [wrxvwge] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [kxcifou] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [kismube] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [foljhtx] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [aqntdqq] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [tyvydkw] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [eytbklx] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [tweaccg] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [uoiontn] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [cgsibri] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [chcdxmw] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [WindowsFY] c:\wp.exe
O4 - HKCU\..\Run: [yitsdkl] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [lkfjxon] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [qiiohga] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [qpqvslt] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [uaulmob] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [uqtgexc] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [kavlhkk] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [oyvwxha] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [dajqckd] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [kawncaq] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [guiqvuc] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [qgerpgn] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [lywwoel] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [gfeveeh] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [qrivywg] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [sjjpoiu] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [yyjvemb] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [aogktmy] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [txfxpuu] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [rkdgkls] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [nywksvp] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [tpiexpd] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [hnogauj] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [gxhnhop] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [ltadrjx] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [yaragga] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [kcuqfhc] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [daotcwx] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [olfbvnk] c:\windows\myxwddb.exe
O4 - HKCU\..\Run: [xonsflb] c:\windows\tmmqvqx.exe
O4 - HKCU\..\Run: [sqdnwoa] c:\windows\ppjtmry.exe
O4 - HKCU\..\Run: [whjntop] c:\windows\dvuwwbl.exe
O4 - HKCU\..\Run: [svkkfcg] c:\windows\ppjtmry.exe
O4 - HKCU\..\Run: [hmjqank] c:\windows\ppjtmry.exe
O4 - HKCU\..\Run: [gkdweco] c:\windows\ppjtmry.exe
O4 - HKCU\..\Run: [fifvwcb] c:\windows\ppjtmry.exe
O4 - HKCU\..\Run: [oljsuuw] c:\windows\ppjtmry.exe
O4 - HKCU\..\Run: [asmcvtw] c:\windows\ciyfktd.exe
O4 - HKCU\..\Run: [nsgbjic] c:\windows\mtfxuql.exe
O4 - HKCU\..\Run: [vajhafd] c:\windows\einhnfd.exe
O4 - HKCU\..\Run: [khlbgxd] c:\windows\kpvssxf.exe
O4 - HKCU\..\Run: [nemlyrv] c:\windows\kqjltfy.exe
O4 - HKCU\..\Run: [slwkjiw] c:\windows\kjpakwn.exe
O4 - HKCU\..\Run: [oguvtua] c:\windows\crjoubx.exe
O4 - HKCU\..\Run: [cgblfay] c:\windows\cpwnhlh.exe
O4 - HKCU\..\Run: [kauntvu] c:\windows\tkdjwum.exe
O4 - HKCU\..\Run: [lcjabyb] c:\windows\tkdjwum.exe
O4 - HKCU\..\Run: [hhbyahf] c:\windows\tkdjwum.exe
O4 - HKCU\..\Run: [vtliypb] c:\windows\tkdjwum.exe
O4 - HKCU\..\Run: [nrvxfyb] c:\windows\tkdjwum.exe
O4 - HKCU\..\Run: [jfppkvq] c:\windows\tkdjwum.exe
O4 - HKCU\..\Run: [jjkwpxq] c:\windows\tkdjwum.exe
O4 - HKCU\..\Run: [gmtoklb] c:\windows\tkdjwum.exe
O4 - HKCU\..\Run: [geaxxgg] c:\windows\isrolbo.exe
O4 - HKCU\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe
O4 - Global Startup: America Online 7.0 Tray Icon.lnk = C:\Program Files\America Online 7.0\aoltray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Microsoft AntiSpyware helper - {210B16CB-F9F8-4C36-B11E-E865DF76354B} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {210B16CB-F9F8-4C36-B11E-E865DF76354B} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {2AEF4EE1-07B6-46FD-9379-2C8C7B4F62DD} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {2AEF4EE1-07B6-46FD-9379-2C8C7B4F62DD} - (no file) (HKCU)
O9 - Extra button: (no name) - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O9 - Extra button: Support - {95540188-895D-49E0-BF8B-37D28ED3F799} - C:\Program Files\Internet Explorer\SIGNUP\Presario.htm (file missing) (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\flsmngr.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\flsmngr.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\flsmngr.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\flsmngr.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\flsmngr.dll
O12 - Plugin for .IE5: C:\PROGRA~1\INTERN~1\PLUGINS\NPQTPL~1.DLL
O14 - IERESET.INF: START_PAGE_URL=http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=3c01&lc=0409
O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} (CInstall Class) - http://www.errorguar...ion/Install.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.c...nst20040510.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.r...ip/RdxIE601.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{205893FB-CABD-4E12-82F2-6D1E9BA6E5FF}: NameServer = 206.141.192.60 206.141.193.55
O17 - HKLM\System\CS1\Services\Tcpip\..\{205893FB-CABD-4E12-82F2-6D1E9BA6E5FF}: NameServer = 206.141.192.60 206.141.193.55
O18 - Filter: text/html - {34B2155F-82AC-4853-8ED0-3CA1ACD5432C} - C:\WINDOWS\System32\nneheha.dll
O18 - Filter: text/plain - {34B2155F-82AC-4853-8ED0-3CA1ACD5432C} - C:\WINDOWS\System32\nneheha.dll
O20 - Winlogon Notify: Explorer - C:\WINDOWS\system32\guard.tmp (file missing)
O20 - Winlogon Notify: WebCheck - C:\WINDOWS\system32\n0r20a9oed.dll (file missing)
O21 - SSODL: Shedule Protocol - {07A58DD3-BC91-4982-9550-D69F8866AE12} - C:\WINDOWS\System32\iasantld.dll
O23 - Service: Compaq Advisor (Compaq_RBA) - NeoPlanet - C:\Program Files\Compaq\Compaq Advisor\bin\compaq-rba.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: Vio Pes (Vie Pes) - Unknown owner - C:\WINDOWS\System32\vwa32.exe" -service (file missing)
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE