MicroWorld Scan:
Object "AltNet Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "myway Spyware/Adware" found in File System! Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\HDPlugin1018.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\WinAdToolsX.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\System32\iuctl.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\iuctl.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\HDPlugin1018.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Oberon Media\Diamond Mine\Uninstall.exe". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0B6DC6EE-C4FD-11d1-819A-00C04FB69B4D}" refers to invalid object "C:\Program Files\Common Files\Adobe\Shell\psicon.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{5B7C6F6B-5A3B-3284-AF84-BC054D93579C}" refers to invalid object "C:\DOCUME~1\Jesse\APPLIC~1\WAVEIN~1\Second Bold.exe". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{700B1221-CAFF-11d1-B9DE-000000001B1B}" refers to invalid object "C:\Program Files\ATI Technologies\ATI Control Panel\atippaxx.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{83D4679F-B6D7-11D2-BF36-00C04FB90A03}" refers to invalid object "C:\PROGRA~1\MESSEN~1\rtcimsp.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{88E729D6-BDC1-11D1-BD2A-00C04FB9603F}" refers to invalid object "fde.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{E62DCD80-C262-11d1-A419-006097923041}" refers to invalid object "C:\Program Files\ATI Technologies\ATI Control Panel\atipdsxx.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F2B8E361-D2E2-11D1-A41F-00609729B902}" refers to invalid object "C:\Program Files\ATI Technologies\ATI Control Panel\atipuixx.dll". Action Taken: No Action Taken.
Entry "HKCR\Alg.AlgSetup" refers to invalid object "{27D0BCCC-344D-4287-AF37-0C72C161C14C}". Action Taken: No Action Taken.
Entry "HKCR\Alg.AlgSetup.1" refers to invalid object "{27D0BCCC-344D-4287-AF37-0C72C161C14C}". Action Taken: No Action Taken.
Entry "HKCR\ComPlusMetaData.MsCorHost" refers to invalid object "{727CDF4F-3BA0-11D3-8738-00C04F79ED0D}". Action Taken: No Action Taken.
Entry "HKCR\ComPlusMetaData.MsCorHost.2" refers to invalid object "{727CDF4F-3BA0-11D3-8738-00C04F79ED0D}". Action Taken: No Action Taken.
Entry "HKCR\MailFileAtt" refers to invalid object "{00020D05-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\mapifvbx.object" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken.
Entry "HKCR\mapifvbx.object.1" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken.
Entry "HKCR\Microsoft.Diagnostics.2" refers to invalid object "{D8484424-9F04-44B4-3F11-2BDAEC85729B}". Action Taken: No Action Taken.
Entry "HKCR\Plenoptic.Plenoptic" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken.
Entry "HKCR\Plenoptic.Plenoptic.1" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken.
Entry "HKCR\RTCCore.RTCClient" refers to invalid object "{7a42ea29-a2b7-40c4-b091-f6f024aa89be}". Action Taken: No Action Taken.
Entry "HKCR\RTCCore.RTCClient.1" refers to invalid object "{7a42ea29-a2b7-40c4-b091-f6f024aa89be}". Action Taken: No Action Taken.
Entry "HKCR\SymWriter.pdb" refers to invalid object "{520DC67A-752E-11D3-8D56-00C04F680B2B}". Action Taken: No Action Taken.
Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken.
Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr.1" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken.
File C:\DOCUME~1\Jesse\LOCALS~1\Temp\4c6f8262.exe infected by "Trojan-Downloader.Win32.Swizzor.ca" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Jesse\LOCALS~1\Temp\4d4ba727.exe infected by "Trojan-Downloader.Win32.Swizzor.ca" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Jesse\LOCALS~1\Temp\agcnzjfa.exe tagged as "not-a-virus:AdWare.Lop.m". Action Taken: No Action Taken.
File C:\DOCUME~1\Jesse\LOCALS~1\Temp\drltecze.exe tagged as "not-a-virus:AdWare.Lop.m". Action Taken: No Action Taken.
File C:\DOCUME~1\Jesse\LOCALS~1\Temp\ghvzlblw.exe tagged as "not-a-virus:AdWare.Lop.m". Action Taken: No Action Taken.
File C:\DOCUME~1\Jesse\LOCALS~1\Temp\gqargjja.exe tagged as "not-a-virus:AdWare.Lop.m". Action Taken: No Action Taken.
File C:\DOCUME~1\Jesse\LOCALS~1\Temp\hhunauio.exe tagged as "not-a-virus:AdWare.Lop.m". Action Taken: No Action Taken.
File C:\DOCUME~1\Jesse\LOCALS~1\Temp\ixpthrhi.exe tagged as "not-a-virus:AdWare.Lop.m". Action Taken: No Action Taken.
File C:\DOCUME~1\Jesse\LOCALS~1\Temp\qarntcvs.exe tagged as "not-a-virus:AdWare.Lop.m". Action Taken: No Action Taken.
File C:\DOCUME~1\Jesse\LOCALS~1\Temp\qrujtnte.exe tagged as "not-a-virus:AdWare.Lop.m". Action Taken: No Action Taken.
File C:\DOCUME~1\Jesse\LOCALS~1\TEMPOR~1\Content.IE5\8DAFOP63\1[1].htm infected by "Exploit.HTML.Mht" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Jesse\LOCALS~1\TEMPOR~1\Content.IE5\A303163U\install[1].htm infected by "Exploit.HTML.CodeBaseExec" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Jesse\LOCALS~1\TEMPOR~1\Content.IE5\U8IHFP4W\prompt[1].htm infected by "Trojan-Downloader.JS.IstBar.j" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Jesse\LOCALS~1\TEMPOR~1\Content.IE5\UVI14HWH\prompt[1].htm infected by "Trojan-Downloader.JS.IstBar.s" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Jesse\LOCALS~1\TEMPOR~1\Content.IE5\UVI14HWH\prompt[2].htm infected by "Trojan-Downloader.JS.IstBar.j" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Jesse\LOCALS~1\TEMPOR~1\Content.IE5\WRU9YJCR\prompt[1].htm infected by "Trojan-Downloader.JS.IstBar.f" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Eachtestdeadbrowse\01 software.exe tagged as "not-a-virus:AdWare.Lop.p". Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Eachtestdeadbrowse\Axisatom.exe tagged as "not-a-virus:AdWare.Lop.j". Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Eachtestdeadbrowse\Blehtwo.exe infected by "Trojan-Downloader.Win32.Swizzor.cn" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Eachtestdeadbrowse\bows amok.exe infected by "Trojan-Downloader.Win32.Swizzor.cn" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Eachtestdeadbrowse\dart 1.exe tagged as "not-a-virus:AdWare.Lop.p". Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Eachtestdeadbrowse\flaw amok.exe infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Eachtestdeadbrowse\locksinternet.exe infected by "Trojan-Downloader.Win32.Swizzor.cn" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Eachtestdeadbrowse\Media Love.exe infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Eachtestdeadbrowse\meta platform.exe tagged as "not-a-virus:AdWare.Lop.p". Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Eachtestdeadbrowse\name upload.exe infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Eachtestdeadbrowse\objname.exe tagged as "not-a-virus:AdWare.Lop.p". Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Eachtestdeadbrowse\Setup poke.exe infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Eachtestdeadbrowse\Slow regs.exe tagged as "not-a-virus:AdWare.Lop.j". Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Eachtestdeadbrowse\tick fork.exe infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Eachtestdeadbrowse\vga32.exe infected by "Trojan.Win32.Krepper.ab" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\01740000.VBN infected by "Exploit.Java.ByteVerify" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\01740001.VBN infected by "Trojan.Java.ClassLoader.c" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\01740002.VBN infected by "Trojan.Java.ClassLoader.Dummy.d" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\01780000.VBN infected by "Exploit.Java.Bytverify" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0C880000.VBN infected by "Trojan-Downloader.Java.OpenStream.c" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Jesse\Local Settings\Temp\4c6f8262.exe infected by "Trojan-Downloader.Win32.Swizzor.ca" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Jesse\Local Settings\Temp\4d4ba727.exe infected by "Trojan-Downloader.Win32.Swizzor.ca" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Jesse\Local Settings\Temp\agcnzjfa.exe tagged as "not-a-virus:AdWare.Lop.m". Action Taken: No Action Taken.
File C:\Documents and Settings\Jesse\Local Settings\Temp\drltecze.exe tagged as "not-a-virus:AdWare.Lop.m". Action Taken: No Action Taken.
File C:\Documents and Settings\Jesse\Local Settings\Temp\ghvzlblw.exe tagged as "not-a-virus:AdWare.Lop.m". Action Taken: No Action Taken.
File C:\Documents and Settings\Jesse\Local Settings\Temp\gqargjja.exe tagged as "not-a-virus:AdWare.Lop.m". Action Taken: No Action Taken.
File C:\Documents and Settings\Jesse\Local Settings\Temp\hhunauio.exe tagged as "not-a-virus:AdWare.Lop.m". Action Taken: No Action Taken.
File C:\Documents and Settings\Jesse\Local Settings\Temp\ixpthrhi.exe tagged as "not-a-virus:AdWare.Lop.m". Action Taken: No Action Taken.
File C:\Documents and Settings\Jesse\Local Settings\Temp\qarntcvs.exe tagged as "not-a-virus:AdWare.Lop.m". Action Taken: No Action Taken.
File C:\Documents and Settings\Jesse\Local Settings\Temp\qrujtnte.exe tagged as "not-a-virus:AdWare.Lop.m". Action Taken: No Action Taken.
File C:\Documents and Settings\Jesse\Local Settings\Temporary Internet Files\Content.IE5\8DAFOP63\1[1].htm infected by "Exploit.HTML.Mht" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Jesse\Local Settings\Temporary Internet Files\Content.IE5\A303163U\install[1].htm infected by "Exploit.HTML.CodeBaseExec" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Jesse\Local Settings\Temporary Internet Files\Content.IE5\U8IHFP4W\prompt[1].htm infected by "Trojan-Downloader.JS.IstBar.j" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Jesse\Local Settings\Temporary Internet Files\Content.IE5\UVI14HWH\prompt[1].htm infected by "Trojan-Downloader.JS.IstBar.s" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Jesse\Local Settings\Temporary Internet Files\Content.IE5\UVI14HWH\prompt[2].htm infected by "Trojan-Downloader.JS.IstBar.j" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Jesse\Local Settings\Temporary Internet Files\Content.IE5\WRU9YJCR\prompt[1].htm infected by "Trojan-Downloader.JS.IstBar.f" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Jesse\My Documents\progs\mirc616.exe tagged as not-a-virus:Client-IRC.Win32.mIRC.16. No Action Taken.
File C:\Documents and Settings\Jesse\My Documents\progs\mirc616.rar tagged as not-a-virus:Client-IRC.Win32.mIRC.16. No Action Taken.
File C:\Documents and Settings\Jesse\My Documents\progs\setup_ares.exe tagged as "not-a-virus:AdWare.NavExcel.d". Action Taken: No Action Taken.
HIJACKTHIS LOGFILE:
Logfile of HijackThis v1.99.1
Scan saved at 8:17:13 PM, on 14/06/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\essspk.exe
C:\Program Files\OptusNet DSL Internet\DSC.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Jesse\My Documents\progs\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://rljwbzjrovivf...xS558bvTQQ.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://dsl.optusnet.com.au/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak =
http://dsl.optusnet.com.au/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by OptusNet
R3 - Default URLSearchHook is missing
O1 - Hosts: com
O1 - Hosts: timizer.com
O1 - Hosts: optimizer.com
O1 - Hosts: 127.0.0.
O1 - Hosts: eroptimizer.com
O1 - Hosts: fferoptimizer.com
O1 - Hosts: 127.0.0.
O1 - Hosts: .offeroptimizer.com
O1 - Hosts: so.offeroptimizer.com
O1 - Hosts: 127.0.0.
O1 - Hosts: adso.offeroptimizer.com
O1 - Hosts: .whenu.com
O1 - Hosts: .whenu.com
O1 - Hosts: 1
O1 - Hosts: 1
O1 - Hosts: inc.whenu.com
O1 - Hosts: inc.whenu.com
O1 - Hosts: m
O1 - Hosts: om
O1 - Hosts: com
O1 - Hosts: r.com
O1 - Hosts: zer.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5B7C6F6B-5A3B-3284-AF84-BC054D93579C} - C:\DOCUME~1\Jesse\APPLIC~1\WAVEIN~1\Second Bold.exe (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [EssSpkPhone] essspk.exe
O4 - HKLM\..\Run: [svckernell] c:\windows\svckernell.com
O4 - HKLM\..\Run: [Desktop Service Centre] C:\Program Files\OptusNet DSL Internet\DSC.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://dsl.optusnet.com.au/
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
http://messenger.zon...ry/msgrchkr.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....467&clcid=0x409O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) -
http://messenger.zon...MineSweeper.cabO16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zon...StatsClient.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn...pDownloader.cabO23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: CWShredder Service - Unknown owner - C:\Documents and Settings\Jesse\My Documents\progs\CWShredder.exe (file missing)
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe