Logfile of HijackThis v1.99.1
Scan saved at 9:59:27 PM, on 7/10/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\WINDOWS\vsnpstd2.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\YAHOO!\browser\ycommon.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\system32\apiik32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SEC\Natural Color\NaturalColorLoad.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wisptis.exe
C:\MSOffice\Office10\WINWORD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\dhcah.dll/sp.html#52409
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\dhcah.dll/sp.html#52409
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\dhcah.dll/sp.html#52409
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\dhcah.dll/sp.html#52409
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\dhcah.dll/sp.html#52409
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\dhcah.dll/sp.html#52409
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\dhcah.dll/sp.html#52409
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {045AE71F-801F-4A71-C593-6529CE594056} - C:\WINDOWS\nttk32.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Class - {07DA44E0-3BFC-A455-CD97-F7B7B8790347} - C:\WINDOWS\mfcdx.dll
O2 - BHO: Class - {150DD6A2-741C-3AC1-86EF-B9F0211447BA} - C:\WINDOWS\mscx32.dll
O2 - BHO: Class - {176407B4-E211-4E16-BFFA-63C50AA24B06} - C:\WINDOWS\iegq32.dll
O2 - BHO: Class - {19F352CA-1BB9-DD56-81EF-9595DD355FD0} - C:\WINDOWS\system32\crcu.dll
O2 - BHO: Class - {1E5865E5-FF6F-A5FA-646C-038A3C2F5165} - C:\WINDOWS\system32\winkh32.dll
O2 - BHO: Class - {2CB91DCB-A5E9-DD47-0B46-E2380FC72EF2} - C:\WINDOWS\mfcpi32.dll
O2 - BHO: Class - {2FC735CE-855B-F1B2-A6ED-CAEA0E1EA230} - C:\WINDOWS\nthz.dll
O2 - BHO: Class - {30463195-A68F-5D9B-95C6-6E9E1788E6F2} - C:\WINDOWS\system32\iesb.dll
O2 - BHO: Class - {3EAF3A17-CC8D-5DC9-285D-C38B83233D28} - C:\WINDOWS\ieqs32.dll
O2 - BHO: Class - {40959590-5A08-A012-E5CC-72E14627D513} - C:\WINDOWS\mfcrs32.dll
O2 - BHO: Class - {5A23A6D7-97E3-2631-C5AA-E8733BB4E5DB} - C:\WINDOWS\crev32.dll
O2 - BHO: Class - {62883FE9-57A7-4A38-F908-7FA3F3C59429} - C:\WINDOWS\system32\javanz.dll
O2 - BHO: Class - {6518F4B3-A15F-E14C-71F3-61A49FC2A684} - C:\WINDOWS\system32\mfcnz.dll
O2 - BHO: Class - {66A15FEE-5E94-86FB-0CE6-EC4939529CDA} - C:\WINDOWS\mswj.dll
O2 - BHO: Class - {72763199-C2D7-3547-5C10-D62AF7ADE07C} - C:\WINDOWS\system32\apifm32.dll
O2 - BHO: Class - {7339C21E-5D1D-F6EF-29FC-8E7E97E8C4F9} - C:\WINDOWS\sdkxv32.dll
O2 - BHO: Class - {7C5F07FA-EE61-E2CA-7AC9-845516B1F196} - C:\WINDOWS\netjx.dll
O2 - BHO: Class - {8002B6F0-0D81-F712-A8F6-D0072EF4DAA2} - C:\WINDOWS\apivd32.dll
O2 - BHO: Class - {88260434-8547-32F0-C3AF-72B7C69C143F} - C:\WINDOWS\system32\syswm.dll
O2 - BHO: Class - {88CA47DE-D491-40E1-D009-5594D634627D} - C:\WINDOWS\sysix.dll
O2 - BHO: Class - {9414B585-09CB-B343-09D8-5DC5D2B786EF} - C:\WINDOWS\system32\atlao.dll
O2 - BHO: Class - {94FA607F-D21C-7B55-1D1B-1A9DE22BEE8D} - C:\WINDOWS\system32\appuu32.dll
O2 - BHO: Class - {9AB0AEAF-5C00-97B4-67EB-26FA674D4DA9} - C:\WINDOWS\system32\netlz.dll
O2 - BHO: Class - {A8955C5E-7D09-18F5-1D0E-99FB9B61BC16} - C:\WINDOWS\system32\addqb32.dll
O2 - BHO: Class - {A8F51229-8EF3-4D90-8BE3-E843327D6F95} - C:\WINDOWS\iere.dll
O2 - BHO: Class - {A96C5AC5-3757-499C-81C5-9CE344BBEFEC} - C:\WINDOWS\ipbd32.dll
O2 - BHO: Class - {A989B009-49B7-5A55-1A34-1D32EE1EA30B} - C:\WINDOWS\ntfq.dll
O2 - BHO: Class - {ABA388C5-AC45-44CB-9816-6536A674986F} - C:\WINDOWS\system32\sdkvu32.dll
O2 - BHO: Class - {AF3FF52D-6CB5-60E4-3DF7-76172788BE5E} - C:\WINDOWS\atlyf.dll
O2 - BHO: Class - {B012290B-F6CB-AE54-0C3F-C8D408BBF992} - C:\WINDOWS\system32\ieeh32.dll
O2 - BHO: Class - {B11BCDC9-1DD6-8BB6-933F-3824A67B8492} - C:\WINDOWS\appks32.dll
O2 - BHO: Class - {B849DA45-86A4-E0DA-DD53-02A7363DFCC4} - C:\WINDOWS\winmq32.dll
O2 - BHO: Class - {C10E70B6-0A9C-EFB9-C902-4055C2D7F322} - C:\WINDOWS\addst.dll
O2 - BHO: Class - {C211B80E-58BE-0087-621D-A487AE79FA25} - C:\WINDOWS\atlwd.dll
O2 - BHO: Class - {C2FA80DA-98A5-92AA-61BD-3EDED8569F27} - C:\WINDOWS\sysyw.dll
O2 - BHO: Class - {C8E09CC6-5143-0AEA-9C0D-D61F50C10ABA} - C:\WINDOWS\javalq.dll
O2 - BHO: Class - {CBE5F226-BD90-1454-83F4-2686C681720C} - C:\WINDOWS\system32\sdkgh.dll
O2 - BHO: Class - {CDF9636C-D75A-2630-DA17-CE41F76F5491} - C:\WINDOWS\sysud.dll
O2 - BHO: Class - {D8F86D1C-DCB4-B7F0-F514-1EC3928A742B} - C:\WINDOWS\addal.dll
O2 - BHO: Class - {E4406573-EB81-A46C-2815-B4F90C430E29} - C:\WINDOWS\system32\apprg.dll
O2 - BHO: Class - {EE5E8D85-5C41-AEAB-016D-094F74F518E8} - C:\WINDOWS\system32\ntrb.dll
O2 - BHO: Class - {F0E095A0-3EA9-8479-E393-7CB483F3BC0D} - C:\WINDOWS\system32\apiho.dll
O2 - BHO: Class - {F24066EC-902B-5FD0-38BE-FCBA8F762791} - C:\WINDOWS\winpy32.dll
O2 - BHO: Class - {F54252AB-AF1A-DA2D-3827-1F172DB2A621} - C:\WINDOWS\system32\crgf32.dll
O2 - BHO: Class - {F5E4007D-5064-4A70-D8DC-AF529CC13F3F} - C:\WINDOWS\system32\winos32.dll
O2 - BHO: Class - {F61C43C0-8F6A-C654-1213-B906276F3ADF} - C:\WINDOWS\msli32.dll
O2 - BHO: Class - {F9B1B847-EF94-1E89-A740-CBCBD8346C87} - C:\WINDOWS\system32\msaw32.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dll
O4 - HKLM\..\Run: [GWMDMpi] C:\WINDOWS\GWMDMpi.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp3\winampa.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [SNPSTD2] C:\WINDOWS\vsnpstd2.exe
O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [apiik32.exe] C:\WINDOWS\system32\apiik32.exe
O4 - HKLM\..\RunOnce: [winyn32.exe] C:\WINDOWS\winyn32.exe
O4 - HKLM\..\RunOnce: [mfcmq.exe] C:\WINDOWS\system32\mfcmq.exe
O4 - HKLM\..\RunOnce: [appcl.exe] C:\WINDOWS\system32\appcl.exe
O4 - HKLM\..\RunOnce: [netgp32.exe] C:\WINDOWS\netgp32.exe
O4 - HKLM\..\RunOnce: [adddv32.exe] C:\WINDOWS\system32\adddv32.exe
O4 - HKLM\..\RunOnce: [netce.exe] C:\WINDOWS\system32\netce.exe
O4 - HKLM\..\RunOnce: [syskc32.exe] C:\WINDOWS\syskc32.exe
O4 - HKLM\..\RunOnce: [sdkqe.exe] C:\WINDOWS\sdkqe.exe
O4 - HKLM\..\RunOnce: [netft.exe] C:\WINDOWS\netft.exe
O4 - HKLM\..\RunOnce: [addko32.exe] C:\WINDOWS\system32\addko32.exe
O4 - HKLM\..\RunOnce: [addnf.exe] C:\WINDOWS\addnf.exe
O4 - HKLM\..\RunOnce: [msyw.exe] C:\WINDOWS\system32\msyw.exe
O4 - HKLM\..\RunOnce: [sysxd.exe] C:\WINDOWS\sysxd.exe
O4 - HKLM\..\RunOnce: [mfcqa.exe] C:\WINDOWS\system32\mfcqa.exe
O4 - HKLM\..\RunOnce: [sdklo.exe] C:\WINDOWS\system32\sdklo.exe
O4 - HKLM\..\RunOnce: [ieid32.exe] C:\WINDOWS\ieid32.exe
O4 - HKLM\..\RunOnce: [appzs32.exe] C:\WINDOWS\appzs32.exe
O4 - HKLM\..\RunOnce: [javatm32.exe] C:\WINDOWS\javatm32.exe
O4 - HKLM\..\RunOnce: [mfcmd.exe] C:\WINDOWS\mfcmd.exe
O4 - HKLM\..\RunOnce: [sdkqh.exe] C:\WINDOWS\sdkqh.exe
O4 - HKLM\..\RunOnce: [d3bi32.exe] C:\WINDOWS\d3bi32.exe
O4 - HKLM\..\RunOnce: [winzp.exe] C:\WINDOWS\winzp.exe
O4 - HKLM\..\RunOnce: [mfcvt32.exe] C:\WINDOWS\system32\mfcvt32.exe
O4 - HKLM\..\RunOnce: [addfu.exe] C:\WINDOWS\addfu.exe
O4 - HKLM\..\RunOnce: [ielh.exe] C:\WINDOWS\ielh.exe
O4 - HKLM\..\RunOnce: [sdkqj32.exe] C:\WINDOWS\system32\sdkqj32.exe
O4 - HKLM\..\RunOnce: [appnw.exe] C:\WINDOWS\appnw.exe
O4 - HKLM\..\RunOnce: [ipgt.exe] C:\WINDOWS\system32\ipgt.exe
O4 - HKLM\..\RunOnce: [ipam32.exe] C:\WINDOWS\system32\ipam32.exe
O4 - HKLM\..\RunOnce: [appfg.exe] C:\WINDOWS\system32\appfg.exe
O4 - HKLM\..\RunOnce: [apied.exe] C:\WINDOWS\apied.exe
O4 - HKLM\..\RunOnce: [sysjf32.exe] C:\WINDOWS\sysjf32.exe
O4 - HKLM\..\RunOnce: [winjn32.exe] C:\WINDOWS\winjn32.exe
O4 - HKLM\..\RunOnce: [sysgi.exe] C:\WINDOWS\system32\sysgi.exe
O4 - HKLM\..\RunOnce: [iehi32.exe] C:\WINDOWS\iehi32.exe
O4 - HKLM\..\RunOnce: [sdkmk.exe] C:\WINDOWS\sdkmk.exe
O4 - HKLM\..\RunOnce: [syseo32.exe] C:\WINDOWS\system32\syseo32.exe
O4 - HKLM\..\RunOnce: [javasw.exe] C:\WINDOWS\system32\javasw.exe
O4 - HKLM\..\RunOnce: [apifr32.exe] C:\WINDOWS\apifr32.exe
O4 - HKLM\..\RunOnce: [winzw.exe] C:\WINDOWS\system32\winzw.exe
O4 - HKLM\..\RunOnce: [ieiw32.exe] C:\WINDOWS\ieiw32.exe
O4 - HKLM\..\RunOnce: [ntcv.exe] C:\WINDOWS\system32\ntcv.exe
O4 - HKLM\..\RunOnce: [winwg.exe] C:\WINDOWS\winwg.exe
O4 - HKLM\..\RunOnce: [msmn32.exe] C:\WINDOWS\msmn32.exe
O4 - HKLM\..\RunOnce: [atlbd32.exe] C:\WINDOWS\system32\atlbd32.exe
O4 - HKLM\..\RunOnce: [winll.exe] C:\WINDOWS\system32\winll.exe
O4 - HKLM\..\RunOnce: [addqa32.exe] C:\WINDOWS\system32\addqa32.exe
O4 - HKLM\..\RunOnce: [winfx32.exe] C:\WINDOWS\winfx32.exe
O4 - HKLM\..\RunOnce: [addnn32.exe] C:\WINDOWS\addnn32.exe
O4 - HKLM\..\RunOnce: [mfcrr.exe] C:\WINDOWS\system32\mfcrr.exe
O4 - HKLM\..\RunOnce: [atlsr32.exe] C:\WINDOWS\atlsr32.exe
O4 - HKLM\..\RunOnce: [mslk.exe] C:\WINDOWS\mslk.exe
O4 - HKLM\..\RunOnce: [sdkpo.exe] C:\WINDOWS\system32\sdkpo.exe
O4 - HKLM\..\RunOnce: [winyv32.exe] C:\WINDOWS\system32\winyv32.exe
O4 - HKLM\..\RunOnce: [d3pk.exe] C:\WINDOWS\d3pk.exe
O4 - HKLM\..\RunOnce: [ipoa32.exe] C:\WINDOWS\ipoa32.exe
O4 - HKLM\..\RunOnce: [atlmp32.exe] C:\WINDOWS\system32\atlmp32.exe
O4 - HKLM\..\RunOnce: [mfcmx.exe] C:\WINDOWS\system32\mfcmx.exe
O4 - HKLM\..\RunOnce: [appux.exe] C:\WINDOWS\system32\appux.exe
O4 - HKLM\..\RunOnce: [ntkv32.exe] C:\WINDOWS\ntkv32.exe
O4 - HKLM\..\RunOnce: [d3ac32.exe] C:\WINDOWS\system32\d3ac32.exe
O4 - HKLM\..\RunOnce: [sdkvg.exe] C:\WINDOWS\system32\sdkvg.exe
O4 - HKLM\..\RunOnce: [mfccv32.exe] C:\WINDOWS\system32\mfccv32.exe
O4 - HKLM\..\RunOnce: [winsl32.exe] C:\WINDOWS\winsl32.exe
O4 - HKLM\..\RunOnce: [mfcor32.exe] C:\WINDOWS\mfcor32.exe
O4 - HKLM\..\RunOnce: [crgv32.exe] C:\WINDOWS\crgv32.exe
O4 - HKLM\..\RunOnce: [ipwd.exe] C:\WINDOWS\system32\ipwd.exe
O4 - HKLM\..\RunOnce: [d3au.exe] C:\WINDOWS\system32\d3au.exe
O4 - HKLM\..\RunOnce: [netor.exe] C:\WINDOWS\system32\netor.exe
O4 - HKLM\..\RunOnce: [msic.exe] C:\WINDOWS\system32\msic.exe
O4 - HKLM\..\RunOnce: [crxs.exe] C:\WINDOWS\system32\crxs.exe
O4 - HKLM\..\RunOnce: [netik32.exe] C:\WINDOWS\netik32.exe
O4 - HKLM\..\RunOnce: [appgy32.exe] C:\WINDOWS\system32\appgy32.exe
O4 - HKLM\..\RunOnce: [atlsj.exe] C:\WINDOWS\atlsj.exe
O4 - HKLM\..\RunOnce: [ipwn.exe] C:\WINDOWS\ipwn.exe
O4 - HKLM\..\RunOnce: [crgo32.exe] C:\WINDOWS\crgo32.exe
O4 - HKLM\..\RunOnce: [iefv.exe] C:\WINDOWS\iefv.exe
O4 - HKLM\..\RunOnce: [atlaz32.exe] C:\WINDOWS\atlaz32.exe
O4 - HKLM\..\RunOnce: [winka.exe] C:\WINDOWS\winka.exe
O4 - HKLM\..\RunOnce: [ipti32.exe] C:\WINDOWS\ipti32.exe
O4 - HKLM\..\RunOnce: [ipid32.exe] C:\WINDOWS\system32\ipid32.exe
O4 - HKLM\..\RunOnce: [javavf32.exe] C:\WINDOWS\javavf32.exe
O4 - HKLM\..\RunOnce: [atloy32.exe] C:\WINDOWS\atloy32.exe
O4 - HKLM\..\RunOnce: [mfcog32.exe] C:\WINDOWS\mfcog32.exe
O4 - HKLM\..\RunOnce: [sdkyh32.exe] C:\WINDOWS\sdkyh32.exe
O4 - HKLM\..\RunOnce: [appyp.exe] C:\WINDOWS\system32\appyp.exe
O4 - HKLM\..\RunOnce: [iect.exe] C:\WINDOWS\system32\iect.exe
O4 - HKLM\..\RunOnce: [mfcrq32.exe] C:\WINDOWS\mfcrq32.exe
O4 - HKLM\..\RunOnce: [iphx.exe] C:\WINDOWS\iphx.exe
O4 - HKLM\..\RunOnce: [d3lt32.exe] C:\WINDOWS\d3lt32.exe
O4 - HKLM\..\RunOnce: [addpl32.exe] C:\WINDOWS\system32\addpl32.exe
O4 - HKLM\..\RunOnce: [msob.exe] C:\WINDOWS\msob.exe
O4 - HKLM\..\RunOnce: [ipni32.exe] C:\WINDOWS\system32\ipni32.exe
O4 - HKLM\..\RunOnce: [atldy32.exe] C:\WINDOWS\atldy32.exe
O4 - HKLM\..\RunOnce: [mfclo.exe] C:\WINDOWS\mfclo.exe
O4 - HKLM\..\RunOnce: [msri32.exe] C:\WINDOWS\system32\msri32.exe
O4 - HKLM\..\RunOnce: [winvn.exe] C:\WINDOWS\system32\winvn.exe
O4 - HKLM\..\RunOnce: [sysen32.exe] C:\WINDOWS\sysen32.exe
O4 - HKLM\..\RunOnce: [ietk32.exe] C:\WINDOWS\system32\ietk32.exe
O4 - HKLM\..\RunOnce: [sdkyg32.exe] C:\WINDOWS\system32\sdkyg32.exe
O4 - HKLM\..\RunOnce: [systa32.exe] C:\WINDOWS\systa32.exe
O4 - HKLM\..\RunOnce: [ipqs32.exe] C:\WINDOWS\system32\ipqs32.exe
O4 - HKLM\..\RunOnce: [javavx.exe] C:\WINDOWS\javavx.exe
O4 - HKLM\..\RunOnce: [atljz.exe] C:\WINDOWS\system32\atljz.exe
O4 - HKLM\..\RunOnce: [winnd.exe] C:\WINDOWS\winnd.exe
O4 - HKLM\..\RunOnce: [apica32.exe] C:\WINDOWS\apica32.exe
O4 - HKLM\..\RunOnce: [sdksi.exe] C:\WINDOWS\sdksi.exe
O4 - HKLM\..\RunOnce: [mswm32.exe] C:\WINDOWS\system32\mswm32.exe
O4 - HKLM\..\RunOnce: [appbw32.exe] C:\WINDOWS\appbw32.exe
O4 - HKLM\..\RunOnce: [ierl32.exe] C:\WINDOWS\system32\ierl32.exe
O4 - HKLM\..\RunOnce: [javaev32.exe] C:\WINDOWS\javaev32.exe
O4 - HKLM\..\RunOnce: [netcd32.exe] C:\WINDOWS\system32\netcd32.exe
O4 - HKLM\..\RunOnce: [netct.exe] C:\WINDOWS\netct.exe
O4 - HKLM\..\RunOnce: [ntjd32.exe] C:\WINDOWS\system32\ntjd32.exe
O4 - HKLM\..\RunOnce: [atlof.exe] C:\WINDOWS\atlof.exe
O4 - HKLM\..\RunOnce: [ntzl.exe] C:\WINDOWS\system32\ntzl.exe
O4 - HKLM\..\RunOnce: [appeg32.exe] C:\WINDOWS\appeg32.exe
O4 - HKLM\..\RunOnce: [atljy.exe] C:\WINDOWS\atljy.exe
O4 - HKLM\..\RunOnce: [nttv.exe] C:\WINDOWS\system32\nttv.exe
O4 - HKLM\..\RunOnce: [addei.exe] C:\WINDOWS\addei.exe
O4 - HKLM\..\RunOnce: [netxe32.exe] C:\WINDOWS\system32\netxe32.exe
O4 - HKLM\..\RunOnce: [appws32.exe] C:\WINDOWS\appws32.exe
O4 - HKLM\..\RunOnce: [ntta32.exe] C:\WINDOWS\ntta32.exe
O4 - HKLM\..\RunOnce: [ntjr.exe] C:\WINDOWS\system32\ntjr.exe
O4 - HKLM\..\RunOnce: [mfcbm.exe] C:\WINDOWS\system32\mfcbm.exe
O4 - HKLM\..\RunOnce: [sysog.exe] C:\WINDOWS\system32\sysog.exe
O4 - HKLM\..\RunOnce: [ntfo.exe] C:\WINDOWS\system32\ntfo.exe
O4 - HKLM\..\RunOnce: [ipom.exe] C:\WINDOWS\ipom.exe
O4 - HKLM\..\RunOnce: [appuo.exe] C:\WINDOWS\system32\appuo.exe
O4 - HKLM\..\RunOnce: [d3te32.exe] C:\WINDOWS\d3te32.exe
O4 - HKLM\..\RunOnce: [ipgy.exe] C:\WINDOWS\system32\ipgy.exe
O4 - HKLM\..\RunOnce: [addbb.exe] C:\WINDOWS\system32\addbb.exe
O4 - HKLM\..\RunOnce: [javahv.exe] C:\WINDOWS\javahv.exe
O4 - HKLM\..\RunOnce: [mfcdf.exe] C:\WINDOWS\system32\mfcdf.exe
O4 - HKLM\..\RunOnce: [sysji32.exe] C:\WINDOWS\sysji32.exe
O4 - HKLM\..\RunOnce: [apimr32.exe] C:\WINDOWS\system32\apimr32.exe
O4 - HKLM\..\RunOnce: [sdkdz.exe] C:\WINDOWS\system32\sdkdz.exe
O4 - HKLM\..\RunOnce: [atlib32.exe] C:\WINDOWS\atlib32.exe
O4 - HKLM\..\RunOnce: [apibm.exe] C:\WINDOWS\apibm.exe
O4 - HKLM\..\RunOnce: [sysho32.exe] C:\WINDOWS\system32\sysho32.exe
O4 - HKLM\..\RunOnce: [addaz.exe] C:\WINDOWS\system32\addaz.exe
O4 - HKLM\..\RunOnce: [crfu32.exe] C:\WINDOWS\crfu32.exe
O4 - HKLM\..\RunOnce: [apitw32.exe] C:\WINDOWS\system32\apitw32.exe
O4 - HKLM\..\RunOnce: [d3dc.exe] C:\WINDOWS\system32\d3dc.exe
O4 - HKLM\..\RunOnce: [sdknb.exe] C:\WINDOWS\system32\sdknb.exe
O4 - HKLM\..\RunOnce: [mfcsd32.exe] C:\WINDOWS\system32\mfcsd32.exe
O4 - HKLM\..\RunOnce: [syszq.exe] C:\WINDOWS\system32\syszq.exe
O4 - HKLM\..\RunOnce: [sdkfl32.exe] C:\WINDOWS\system32\sdkfl32.exe
O4 - HKLM\..\RunOnce: [javafb32.exe] C:\WINDOWS\system32\javafb32.exe
O4 - HKLM\..\RunOnce: [apisv32.exe] C:\WINDOWS\system32\apisv32.exe
O4 - HKLM\..\RunOnce: [javabv32.exe] C:\WINDOWS\javabv32.exe
O4 - HKLM\..\RunOnce: [mfchp.exe] C:\WINDOWS\system32\mfchp.exe
O4 - HKLM\..\RunOnce: [javawn32.exe] C:\WINDOWS\javawn32.exe
O4 - HKLM\..\RunOnce: [msmu.exe] C:\WINDOWS\msmu.exe
O4 - HKLM\..\RunOnce: [addqy32.exe] C:\WINDOWS\addqy32.exe
O4 - HKLM\..\RunOnce: [sysaz.exe] C:\WINDOWS\sysaz.exe
O4 - HKLM\..\RunOnce: [netjh.exe] C:\WINDOWS\netjh.exe
O4 - HKLM\..\RunOnce: [ieds32.exe] C:\WINDOWS\ieds32.exe
O4 - HKLM\..\RunOnce: [addta32.exe] C:\WINDOWS\addta32.exe
O4 - HKLM\..\RunOnce: [sdksj.exe] C:\WINDOWS\sdksj.exe
O4 - HKLM\..\RunOnce: [atlyd.exe] C:\WINDOWS\atlyd.exe
O4 - HKLM\..\RunOnce: [d3zr.exe] C:\WINDOWS\d3zr.exe
O4 - HKLM\..\RunOnce: [netel.exe] C:\WINDOWS\netel.exe
O4 - HKLM\..\RunOnce: [sysmr.exe] C:\WINDOWS\system32\sysmr.exe
O4 - HKLM\..\RunOnce: [javast.exe] C:\WINDOWS\javast.exe
O4 - HKLM\..\RunOnce: [addnd32.exe] C:\WINDOWS\addnd32.exe
O4 - HKLM\..\RunOnce: [d3sx.exe] C:\WINDOWS\system32\d3sx.exe
O4 - HKLM\..\RunOnce: [apppu32.exe] C:\WINDOWS\apppu32.exe
O4 - HKLM\..\RunOnce: [d3uo.exe] C:\WINDOWS\d3uo.exe
O4 - HKLM\..\RunOnce: [msal.exe] C:\WINDOWS\system32\msal.exe
O4 - HKLM\..\RunOnce: [ipff32.exe] C:\WINDOWS\system32\ipff32.exe
O4 - HKLM\..\RunOnce: [netda32.exe] C:\WINDOWS\system32\netda32.exe
O4 - HKLM\..\RunOnce: [winjc.exe] C:\WINDOWS\system32\winjc.exe
O4 - HKLM\..\RunOnce: [ntdo.exe] C:\WINDOWS\ntdo.exe
O4 - HKLM\..\RunOnce: [atlii32.exe] C:\WINDOWS\atlii32.exe
O4 - HKLM\..\RunOnce: [netgp.exe] C:\WINDOWS\netgp.exe
O4 - HKLM\..\RunOnce: [d3wk32.exe] C:\WINDOWS\d3wk32.exe
O4 - HKLM\..\RunOnce: [netbe.exe] C:\WINDOWS\netbe.exe
O4 - HKLM\..\RunOnce: [apikf32.exe] C:\WINDOWS\system32\apikf32.exe
O4 - HKLM\..\RunOnce: [winqh.exe] C:\WINDOWS\system32\winqh.exe
O4 - HKLM\..\RunOnce: [mfcoc32.exe] C:\WINDOWS\system32\mfcoc32.exe
O4 - HKLM\..\RunOnce: [syscw.exe] C:\WINDOWS\syscw.exe
O4 - HKLM\..\RunOnce: [atlgy.exe] C:\WINDOWS\atlgy.exe
O4 - HKLM\..\RunOnce: [apphw.exe] C:\WINDOWS\system32\apphw.exe
O4 - HKLM\..\RunOnce: [ipuo.exe] C:\WINDOWS\system32\ipuo.exe
O4 - HKLM\..\RunOnce: [apptc32.exe] C:\WINDOWS\system32\apptc32.exe
O4 - HKLM\..\RunOnce: [d3yw.exe] C:\WINDOWS\system32\d3yw.exe
O4 - HKLM\..\RunOnce: [iemy32.exe] C:\WINDOWS\iemy32.exe
O4 - HKLM\..\RunOnce: [crri.exe] C:\WINDOWS\system32\crri.exe
O4 - HKLM\..\RunOnce: [apiel32.exe] C:\WINDOWS\system32\apiel32.exe
O4 - HKLM\..\RunOnce: [netet.exe] C:\WINDOWS\system32\netet.exe
O4 - HKLM\..\RunOnce: [d3hc32.exe] C:\WINDOWS\system32\d3hc32.exe
O4 - HKLM\..\RunOnce: [ipne32.exe] C:\WINDOWS\system32\ipne32.exe
O4 - HKLM\..\RunOnce: [mslp.exe] C:\WINDOWS\mslp.exe
O4 - HKLM\..\RunOnce: [sdkpb.exe] C:\WINDOWS\system32\sdkpb.exe
O4 - HKLM\..\RunOnce: [mfcuv32.exe] C:\WINDOWS\mfcuv32.exe
O4 - HKLM\..\RunOnce: [appec.exe] C:\WINDOWS\appec.exe
O4 - HKLM\..\RunOnce: [ipcr32.exe] C:\WINDOWS\system32\ipcr32.exe
O4 - HKLM\..\RunOnce: [apphl.exe] C:\WINDOWS\system32\apphl.exe
O4 - HKLM\..\RunOnce: [apivt.exe] C:\WINDOWS\apivt.exe
O4 - HKLM\..\RunOnce: [appka.exe] C:\WINDOWS\system32\appka.exe
O4 - HKLM\..\RunOnce: [mspd32.exe] C:\WINDOWS\system32\mspd32.exe
O4 - HKLM\..\RunOnce: [winvf.exe] C:\WINDOWS\winvf.exe
O4 - HKLM\..\RunOnce: [javaiz32.exe] C:\WINDOWS\system32\javaiz32.exe
O4 - HKLM\..\RunOnce: [netnj32.exe] C:\WINDOWS\system32\netnj32.exe
O4 - HKLM\..\RunOnce: [applz32.exe] C:\WINDOWS\applz32.exe
O4 - HKLM\..\RunOnce: [d3rt.exe] C:\WINDOWS\d3rt.exe
O4 - HKLM\..\RunOnce: [netqa32.exe] C:\WINDOWS\netqa32.exe
O4 - HKLM\..\RunOnce: [winvv.exe] C:\WINDOWS\system32\winvv.exe
O4 - HKLM\..\RunOnce: [netlq32.exe] C:\WINDOWS\netlq32.exe
O4 - HKLM\..\RunOnce: [addyk.exe] C:\WINDOWS\addyk.exe
O4 - HKLM\..\RunOnce: [syszk32.exe] C:\WINDOWS\system32\syszk32.exe
O4 - HKLM\..\RunOnce: [javaem.exe] C:\WINDOWS\system32\javaem.exe
O4 - HKLM\..\RunOnce: [ipiq.exe] C:\WINDOWS\system32\ipiq.exe
O4 - HKLM\..\RunOnce: [addns32.exe] C:\WINDOWS\system32\addns32.exe
O4 - HKLM\..\RunOnce: [mfcax.exe] C:\WINDOWS\system32\mfcax.exe
O4 - HKLM\..\RunOnce: [sysgr32.exe] C:\WINDOWS\system32\sysgr32.exe
O4 - HKLM\..\RunOnce: [crwg.exe] C:\WINDOWS\crwg.exe
O4 - HKLM\..\RunOnce: [apijj32.exe] C:\WINDOWS\apijj32.exe
O4 - HKLM\..\RunOnce: [winuz.exe] C:\WINDOWS\system32\winuz.exe
O4 - HKLM\..\RunOnce: [crzt32.exe] C:\WINDOWS\system32\crzt32.exe
O4 - HKLM\..\RunOnce: [addcf32.exe] C:\WINDOWS\system32\addcf32.exe
O4 - HKLM\..\RunOnce: [d3ih.exe] C:\WINDOWS\system32\d3ih.exe
O4 - HKLM\..\RunOnce: [iphv32.exe] C:\WINDOWS\system32\iphv32.exe
O4 - HKLM\..\RunOnce: [ippd32.exe] C:\WINDOWS\system32\ippd32.exe
O4 - HKLM\..\RunOnce: [appuf.exe] C:\WINDOWS\system32\appuf.exe
O4 - HKLM\..\RunOnce: [mfctn.exe] C:\WINDOWS\mfctn.exe
O4 - HKLM\..\RunOnce: [syszh.exe] C:\WINDOWS\system32\syszh.exe
O4 - HKLM\..\RunOnce: [mscr.exe] C:\WINDOWS\system32\mscr.exe
O4 - HKLM\..\RunOnce: [ipil32.exe] C:\WINDOWS\ipil32.exe
O4 - HKLM\..\RunOnce: [winit32.exe] C:\WINDOWS\system32\winit32.exe
O4 - HKLM\..\RunOnce: [javavn.exe] C:\WINDOWS\system32\javavn.exe
O4 - HKLM\..\RunOnce: [mfcgo.exe] C:\WINDOWS\mfcgo.exe
O4 - HKLM\..\RunOnce: [systi32.exe] C:\WINDOWS\system32\systi32.exe
O4 - HKLM\..\RunOnce: [wintq32.exe] C:\WINDOWS\system32\wintq32.exe
O4 - HKLM\..\RunOnce: [apien.exe] C:\WINDOWS\system32\apien.exe
O4 - HKLM\..\RunOnce: [iesr.exe] C:\WINDOWS\system32\iesr.exe
O4 - HKLM\..\RunOnce: [sdkxl32.exe] C:\WINDOWS\system32\sdkxl32.exe
O4 - HKLM\..\RunOnce: [winla.exe] C:\WINDOWS\system32\winla.exe
O4 - HKLM\..\RunOnce: [javarc32.exe] C:\WINDOWS\javarc32.exe
O4 - HKLM\..\RunOnce: [winuo.exe] C:\WINDOWS\system32\winuo.exe
O4 - HKLM\..\RunOnce: [crzi32.exe] C:\WINDOWS\crzi32.exe
O4 - HKLM\..\RunOnce: [ieen.exe] C:\WINDOWS\system32\ieen.exe
O4 - HKLM\..\RunOnce: [sdkjp32.exe] C:\WINDOWS\system32\sdkjp32.exe
O4 - HKLM\..\RunOnce: [mfche.exe] C:\WINDOWS\mfche.exe
O4 - HKLM\..\RunOnce: [sysgm32.exe] C:\WINDOWS\sysgm32.exe
O4 - HKLM\..\RunOnce: [apike32.exe] C:\WINDOWS\apike32.exe
O4 - HKLM\..\RunOnce: [sdkal.exe] C:\WINDOWS\sdkal.exe
O4 - HKLM\..\RunOnce: [mswp32.exe] C:\WINDOWS\mswp32.exe
O4 - HKLM\..\RunOnce: [croq.exe] C:\WINDOWS\croq.exe
O4 - HKLM\..\RunOnce: [crtm32.exe] C:\WINDOWS\crtm32.exe
O4 - HKLM\..\RunOnce: [crib32.exe] C:\WINDOWS\system32\crib32.exe
O4 - HKLM\..\RunOnce: [apinf32.exe] C:\WINDOWS\apinf32.exe
O4 - HKLM\..\RunOnce: [crir32.exe] C:\WINDOWS\system32\crir32.exe
O4 - HKLM\..\RunOnce: [iemv.exe] C:\WINDOWS\iemv.exe
O4 - HKLM\..\RunOnce: [msvw32.exe] C:\WINDOWS\system32\msvw32.exe
O4 - HKLM\..\RunOnce: [d3cs32.exe] C:\WINDOWS\d3cs32.exe
O4 - HKLM\..\RunOnce: [ipgp.exe] C:\WINDOWS\system32\ipgp.exe
O4 - HKLM\..\RunOnce: [mfckb.exe] C:\WINDOWS\mfckb.exe
O4 - HKLM\..\RunOnce: [mfcnk32.exe] C:\WINDOWS\mfcnk32.exe
O4 - HKLM\..\RunOnce: [ieso32.exe] C:\WINDOWS\ieso32.exe
O4 - HKLM\..\RunOnce: [apina32.exe] C:\WINDOWS\system32\apina32.exe
O4 - HKLM\..\RunOnce: [ipse.exe] C:\WINDOWS\system32\ipse.exe
O4 - HKLM\..\RunOnce: [netaf32.exe] C:\WINDOWS\system32\netaf32.exe
O4 - HKLM\..\RunOnce: [nethc.exe] C:\WINDOWS\system32\nethc.exe
O4 - HKLM\..\RunOnce: [netvq.exe] C:\WINDOWS\system32\netvq.exe
O4 - HKLM\..\RunOnce: [sysav.exe] C:\WINDOWS\sysav.exe
O4 - HKLM\..\RunOnce: [ipug.exe] C:\WINDOWS\system32\ipug.exe
O4 - HKLM\..\RunOnce: [mfckn.exe] C:\WINDOWS\system32\mfckn.exe
O4 - HKLM\..\RunOnce: [winug32.exe] C:\WINDOWS\winug32.exe
O4 - HKLM\..\RunOnce: [addoz.exe] C:\WINDOWS\addoz.exe
O4 - HKLM\..\RunOnce: [msmn.exe] C:\WINDOWS\system32\msmn.exe
O4 - HKLM\..\RunOnce: [addir.exe] C:\WINDOWS\addir.exe
O4 - HKLM\..\RunOnce: [apibj32.exe] C:\WINDOWS\system32\apibj32.exe
O4 - HKLM\..\RunOnce: [ntrr.exe] C:\WINDOWS\system32\ntrr.exe
O4 - HKLM\..\RunOnce: [d3vv32.exe] C:\WINDOWS\d3vv32.exe
O4 - HKLM\..\RunOnce: [javafd.exe] C:\WINDOWS\javafd.exe
O4 - HKLM\..\RunOnce: [crks32.exe] C:\WINDOWS\crks32.exe
O4 - HKLM\..\RunOnce: [javazp32.exe] C:\WINDOWS\system32\javazp32.exe
O4 - HKLM\..\RunOnce: [mfcel32.exe] C:\WINDOWS\system32\mfcel32.exe
O4 - HKLM\..\RunOnce: [crzf32.exe] C:\WINDOWS\system32\crzf32.exe
O4 - HKLM\..\RunOnce: [iedj.exe] C:\WINDOWS\iedj.exe
O4 - HKLM\..\RunOnce: [d3mj32.exe] C:\WINDOWS\system32\d3mj32.exe
O4 - HKLM\..\RunOnce: [netgb.exe] C:\WINDOWS\netgb.exe
O4 - HKLM\..\RunOnce: [ieam.exe] C:\WINDOWS\system32\ieam.exe
O4 - HKLM\..\RunOnce: [crqb.exe] C:\WINDOWS\system32\crqb.exe
O4 - HKLM\..\RunOnce: [netau32.exe] C:\WINDOWS\netau32.exe
O4 - HKLM\..\RunOnce: [nttf32.exe] C:\WINDOWS\system32\nttf32.exe
O4 - HKLM\..\RunOnce: [appyb32.exe] C:\WINDOWS\system32\appyb32.exe
O4 - HKLM\..\RunOnce: [sdktn.exe] C:\WINDOWS\sdktn.exe
O4 - HKLM\..\RunOnce: [apixz.exe] C:\WINDOWS\apixz.exe
O4 - HKLM\..\RunOnce: [crmo32.exe] C:\WINDOWS\system32\crmo32.exe
O4 - HKLM\..\RunOnce: [iedw.exe] C:\WINDOWS\system32\iedw.exe
O4 - HKLM\..\RunOnce: [atlha32.exe] C:\WINDOWS\system32\atlha32.exe
O4 - HKLM\..\RunOnce: [winqa.exe] C:\WINDOWS\system32\winqa.exe
O4 - HKLM\..\RunOnce: [addwx32.exe] C:\WINDOWS\system32\addwx32.exe
O4 - HKLM\..\RunOnce: [ntfd.exe] C:\WINDOWS\system32\ntfd.exe
O4 - HKLM\..\RunOnce: [ievs32.exe] C:\WINDOWS\ievs32.exe
O4 - HKLM\..\RunOnce: [addti.exe] C:\WINDOWS\addti.exe
O4 - HKLM\..\RunOnce: [apipe32.exe] C:\WINDOWS\system32\apipe32.exe
O4 - HKLM\..\RunOnce: [atlym.exe] C:\WINDOWS\atlym.exe
O4 - HKLM\..\RunOnce: [atlmb32.exe] C:\WINDOWS\system32\atlmb32.exe
O4 - HKLM\..\RunOnce: [atlsy32.exe] C:\WINDOWS\atlsy32.exe
O4 - HKLM\..\RunOnce: [msxc32.exe] C:\WINDOWS\msxc32.exe
O4 - HKLM\..\RunOnce: [mfcao.exe] C:\WINDOWS\mfcao.exe
O4 - HKLM\..\RunOnce: [wines32.exe] C:\WINDOWS\system32\wines32.exe
O4 - HKLM\..\RunOnce: [d3uh.exe] C:\WINDOWS\d3uh.exe
O4 - HKLM\..\RunOnce: [iptx32.exe] C:\WINDOWS\iptx32.exe
O4 - HKLM\..\RunOnce: [msxg32.exe] C:\WINDOWS\system32\msxg32.exe
O4 - HKLM\..\RunOnce: [addno.exe] C:\WINDOWS\system32\addno.exe
O4 - HKLM\..\RunOnce: [apirs.exe] C:\WINDOWS\apirs.exe
O4 - HKLM\..\RunOnce: [sdkct32.exe] C:\WINDOWS\system32\sdkct32.exe
O4 - HKLM\..\RunOnce: [d3aa.exe] C:\WINDOWS\d3aa.exe
O4 - HKLM\..\RunOnce: [winwe32.exe] C:\WINDOWS\winwe32.exe
O4 - HKLM\..\RunOnce: [ieff.exe] C:\WINDOWS\ieff.exe
O4 - HKLM\..\RunOnce: [apion.exe] C:\WINDOWS\system32\apion.exe
O4 - HKLM\..\RunOnce: [d3iy32.exe] C:\WINDOWS\d3iy32.exe
O4 - HKLM\..\RunOnce: [winzg32.exe] C:\WINDOWS\winzg32.exe
O4 - HKLM\..\RunOnce: [ieuk.exe] C:\WINDOWS\system32\ieuk.exe
O4 - HKLM\..\RunOnce: [d3xt32.exe] C:\WINDOWS\system32\d3xt32.exe
O4 - HKLM\..\RunOnce: [javasx.exe] C:\WINDOWS\javasx.exe
O4 - HKLM\..\RunOnce: [mfcrn32.exe] C:\WINDOWS\mfcrn32.exe
O4 - HKLM\..\RunOnce: [winqc32.exe] C:\WINDOWS\system32\winqc32.exe
O4 - HKLM\..\RunOnce: [addpk.exe] C:\WINDOWS\addpk.exe
O4 - HKLM\..\RunOnce: [winyk.exe] C:\WINDOWS\system32\winyk.exe
O4 - HKLM\..\RunOnce: [apioa32.exe] C:\WINDOWS\apioa32.exe
O4 - HKLM\..\RunOnce: [sdkep32.exe] C:\WINDOWS\sdkep32.exe
O4 - HKLM\..\RunOnce: [ipzt.exe] C:\WINDOWS\system32\ipzt.exe
O4 - HKLM\..\RunOnce: [addyi32.exe] C:\WINDOWS\system32\addyi32.exe
O4 - HKLM\..\RunOnce: [ntbs32.exe] C:\WINDOWS\ntbs32.exe
O4 - HKLM\..\RunOnce: [craz.exe] C:\WINDOWS\craz.exe
O4 - HKLM\..\RunOnce: [winwd32.exe] C:\WINDOWS\system32\winwd32.exe
O4 - HKLM\..\RunOnce: [msfe.exe] C:\WINDOWS\msfe.exe
O4 - HKLM\..\RunOnce: [ietb32.exe] C:\WINDOWS\system32\ietb32.exe
O4 - HKLM\..\RunOnce: [mszx32.exe] C:\WINDOWS\mszx32.exe
O4 - HKLM\..\RunOnce: [nteu32.exe] C:\WINDOWS\nteu32.exe
O4 - HKLM\..\RunOnce: [iehf32.exe] C:\WINDOWS\iehf32.exe
O4 - HKLM\..\RunOnce: [addmk.exe] C:\WINDOWS\system32\addmk.exe
O4 - HKLM\..\RunOnce: [winnk32.exe] C:\WINDOWS\winnk32.exe
O4 - HKLM\..\RunOnce: [sysbh32.exe] C:\WINDOWS\system32\sysbh32.exe
O4 - HKLM\..\RunOnce: [sdkgl.exe] C:\WINDOWS\system32\sdkgl.exe
O4 - HKLM\..\RunOnce: [addpj32.exe] C:\WINDOWS\system32\addpj32.exe
O4 - HKLM\..\RunOnce: [atluo32.exe] C:\WINDOWS\atluo32.exe
O4 - HKLM\..\RunOnce: [d3uw.exe] C:\WINDOWS\system32\d3uw.exe
O4 - HKLM\..\RunOnce: [sdkyi.exe] C:\WINDOWS\system32\sdkyi.exe
O4 - HKLM\..\RunOnce: [ienx32.exe] C:\WINDOWS\ienx32.exe
O4 - HKLM\..\RunOnce: [apple.exe] C:\WINDOWS\apple.exe
O4 - HKLM\..\RunOnce: [nethi32.exe] C:\WINDOWS\nethi32.exe
O4 - HKLM\..\RunOnce: [atlrj.exe] C:\WINDOWS\atlrj.exe
O4 - HKLM\..\RunOnce: [mfcff32.exe] C:\WINDOWS\mfcff32.exe
O4 - HKLM\..\RunOnce: [atltc32.exe] C:\WINDOWS\system32\atltc32.exe
O4 - HKLM\..\RunOnce: [ieqz32.exe] C:\WINDOWS\ieqz32.exe
O4 - HKLM\..\RunOnce: [mfctk32.exe] C:\WINDOWS\system32\mfctk32.exe
O4 - HKLM\..\RunOnce: [appdr32.exe] C:\WINDOWS\system32\appdr32.exe
O4 - HKLM\..\RunOnce: [ieby.exe] C:\WINDOWS\ieby.exe
O4 - HKLM\..\RunOnce: [ntao32.exe] C:\WINDOWS\ntao32.exe
O4 - HKLM\..\RunOnce: [mfcqd32.exe] C:\WINDOWS\system32\mfcqd32.exe
O4 - HKLM\..\RunOnce: [apiyl.exe] C:\WINDOWS\system32\apiyl.exe
O4 - HKLM\..\RunOnce: [mfczm.exe] C:\WINDOWS\system32\mfczm.exe
O4 - HKLM\..\RunOnce: [cris32.exe] C:\WINDOWS\system32\cris32.exe
O4 - HKLM\..\RunOnce: [ipgh.exe] C:\WINDOWS\ipgh.exe
O4 - HKLM\..\RunOnce: [addfx32.exe] C:\WINDOWS\addfx32.exe
O4 - HKLM\..\RunOnce: [iedu.exe] C:\WINDOWS\system32\iedu.exe
O4 - HKLM\..\RunOnce: [msev.exe] C:\WINDOWS\msev.exe
O4 - HKLM\..\RunOnce: [appus32.exe] C:\WINDOWS\system32\appus32.exe
O4 - HKLM\..\RunOnce: [netsz32.exe] C:\WINDOWS\system32\netsz32.exe
O4 - HKLM\..\RunOnce: [mfcnd.exe] C:\WINDOWS\system32\mfcnd.exe
O4 - HKLM\..\RunOnce: [iemt32.exe] C:\WINDOWS\system32\iemt32.exe
O4 - HKLM\..\RunOnce: [javaki.exe] C:\WINDOWS\javaki.exe
O4 - HKLM\..\RunOnce: [sysos.exe] C:\WINDOWS\system32\sysos.exe
O4 - HKLM\..\RunOnce: [sdkux.exe] C:\WINDOWS\sdkux.exe
O4 - HKLM\..\RunOnce: [winoi.exe] C:\WINDOWS\winoi.exe
O4 - HKLM\..\RunOnce: [msep.exe] C:\WINDOWS\msep.exe
O4 - HKLM\..\RunOnce: [sdkoi32.exe] C:\WINDOWS\system32\sdkoi32.exe
O4 - HKLM\..\RunOnce: [javaib.exe] C:\WINDOWS\javaib.exe
O4 - HKLM\..\RunOnce: [iemf.exe] C:\WINDOWS\iemf.exe
O4 - HKLM\..\RunOnce: [appwy32.exe] C:\WINDOWS\appwy32.exe
O4 - HKLM\..\RunOnce: [mspp32.exe] C:\WINDOWS\system32\mspp32.exe
O4 - HKLM\..\RunOnce: [msvm32.exe] C:\WINDOWS\msvm32.exe
O4 - HKLM\..\RunOnce: [msdc.exe] C:\WINDOWS\msdc.exe
O4 - HKLM\..\RunOnce: [d3ec.exe] C:\WINDOWS\d3ec.exe
O4 - HKLM\..\RunOnce: [apptr32.exe] C:\WINDOWS\system32\apptr32.exe
O4 - HKLM\..\RunOnce: [apisz32.exe] C:\WINDOWS\apisz32.exe
O4 - HKLM\..\RunOnce: [atlnk.exe] C:\WINDOWS\atlnk.exe
O4 - HKLM\..\RunOnce: [iems32.exe] C:\WINDOWS\iems32.exe
O4 - HKLM\..\RunOnce: [javakh32.exe] C:\WINDOWS\system32\javakh32.exe
O4 - HKLM\..\RunOnce: [javakx.exe] C:\WINDOWS\system32\javakx.exe
O4 - HKLM\..\RunOnce: [addnh32.exe] C:\WINDOWS\addnh32.exe
O4 - HKLM\..\RunOnce: [appnp.exe] C:\WINDOWS\appnp.exe
O4 - HKLM\..\RunOnce: [winwp.exe] C:\WINDOWS\system32\winwp.exe
O4 - HKLM\..\RunOnce: [netln32.exe] C:\WINDOWS\netln32.exe
O4 - HKLM\..\RunOnce: [javacu32.exe] C:\WINDOWS\javacu32.exe
O4 - HKLM\..\RunOnce: [ntxy.exe] C:\WINDOWS\system32\ntxy.exe
O4 - HKLM\..\RunOnce: [appwn32.exe] C:\WINDOWS\appwn32.exe
O4 - HKLM\..\RunOnce: [ieud.exe] C:\WINDOWS\system32\ieud.exe
O4 - HKLM\..\RunOnce: [sdktt32.exe] C:\WINDOWS\system32\sdktt32.exe
O4 - HKLM\..\RunOnce: [apija32.exe] C:\WINDOWS\apija32.exe
O4 - HKLM\..\RunOnce: [apirq32.exe] C:\WINDOWS\apirq32.exe
O4 - HKLM\..\RunOnce: [javabj32.exe] C:\WINDOWS\system32\javabj32.exe
O4 - HKLM\..\RunOnce: [atlar.exe] C:\WINDOWS\atlar.exe
O4 - HKLM\..\RunOnce: [sysed.exe] C:\WINDOWS\system32\sysed.exe
O4 - HKLM\..\RunOnce: [winzm32.exe] C:\WINDOWS\system32\winzm32.exe
O4 - HKLM\..\RunOnce: [javaeq32.exe] C:\WINDOWS\system32\javaeq32.exe
O4 - HKLM\..\RunOnce: [winzc32.exe] C:\WINDOWS\winzc32.exe
O4 - HKLM\..\RunOnce: [atlmg.exe] C:\WINDOWS\atlmg.exe
O4 - HKLM\..\RunOnce: [appmg32.exe] C:\WINDOWS\appmg32.exe
O4 - HKLM\..\RunOnce: [addbd.exe] C:\WINDOWS\addbd.exe
O4 - HKLM\..\RunOnce: [appgs.exe] C:\WINDOWS\appgs.exe
O4 - HKLM\..\RunOnce: [cruw.exe] C:\WINDOWS\system32\cruw.exe
O4 - HKLM\..\RunOnce: [atloi.exe] C:\WINDOWS\atloi.exe
O4 - HKLM\..\RunOnce: [winep.exe] C:\WINDOWS\winep.exe
O4 - HKLM\..\RunOnce: [croi32.exe] C:\WINDOWS\system32\croi32.exe
O4 - HKLM\..\RunOnce: [msab.exe] C:\WINDOWS\system32\msab.exe
O4 - HKLM\..\RunOnce: [addef.exe] C:\WINDOWS\addef.exe
O4 - HKLM\..\RunOnce: [apioy32.exe] C:\WINDOWS\system32\apioy32.exe
O4 - HKLM\..\RunOnce: [ntmn.exe] C:\WINDOWS\system32\ntmn.exe
O4 - HKLM\..\RunOnce: [d3ij32.exe] C:\WINDOWS\d3ij32.exe
O4 - HKLM\..\RunOnce: [addvb32.exe] C:\WINDOWS\addvb32.exe
O4 - HKLM\..\RunOnce: [mslr.exe] C:\WINDOWS\system32\mslr.exe
O4 - HKLM\..\RunOnce: [ntky32.exe] C:\WINDOWS\system32\ntky32.exe
O4 - HKLM\..\RunOnce: [mfcio32.exe] C:\WINDOWS\mfcio32.exe
O4 - HKLM\..\RunOnce: [apiie32.exe] C:\WINDOWS\apiie32.exe
O4 - HKLM\..\RunOnce: [javarw32.exe] C:\WINDOWS\system32\javarw32.exe
O4 - HKLM\..\RunOnce: [appre.exe] C:\WINDOWS\system32\appre.exe
O4 - HKLM\..\RunOnce: [sysvi.exe] C:\WINDOWS\system32\sysvi.exe
O4 - HKLM\..\RunOnce: [mfclg32.exe] C:\WINDOWS\mfclg32.exe
O4 - HKLM\..\RunOnce: [ntbn32.exe] C:\WINDOWS\ntbn32.exe
O4 - HKLM\..\RunOnce: [neter.exe] C:\WINDOWS\system32\neter.exe
O4 - HKLM\..\RunOnce: [windg32.exe] C:\WINDOWS\windg32.exe
O4 - HKLM\..\RunOnce: [ipyq32.exe] C:\WINDOWS\ipyq32.exe
O4 - HKLM\..\RunOnce: [javaxy.exe] C:\WINDOWS\javaxy.exe
O4 - HKLM\..\RunOnce: [systc32.exe] C:\WINDOWS\systc32.exe
O4 - HKLM\..\RunOnce: [d3cc.exe] C:\WINDOWS\d3cc.exe
O4 - HKLM\..\RunOnce: [msqz32.exe] C:\WINDOWS\msqz32.exe
O4 - HKLM\..\RunOnce: [d3ww32.exe] C:\WINDOWS\d3ww32.exe
O4 - HKLM\..\RunOnce: [netbs32.exe] C:\WINDOWS\netbs32.exe
O4 - HKLM\..\RunOnce: [msee32.exe] C:\WINDOWS\system32\msee32.exe
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] C:\Program Files\Valve\Steam\Steam.exe -silent
O4 - Global Startup: NaturalColorLoad.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\MSOffice\Office10\OSA.EXE
O8 - Extra context menu item: Download all by Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download by Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: Download selected by Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download web site by Free Download Manager - file://C:\Program Files\Free Download Manager\dlpage.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\MSOffice\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\common\ylogin.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: ICQ 4.0 - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg...t/c381/chat.cab
O16 - DPF: Yahoo! Graffiti - http://download.game...ts/y/grt5_x.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} - http://www.spywarest...es2/Install.cab
O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg...l_v1-0-3-24.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcaf...83/mcinsctl.cab
O16 - DPF: {53B8B406-42E4-4DD3-96E7-9DEC8CEB3DD8} (ICQVideoControl Class) - http://xtraz.icq.com...ideoControl.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.r...ip/RdxIE601.cab
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - https://www.gamespyid.com/alaunch.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {8FA9D107-547B-4DBC-9D88-FABD891EDB0A} (shizmoo Class) - http://playroom.icq....dyssey_web8.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zon...ro.cab32846.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcaf...,20/mcgdmgr.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zon...oF.cab31267.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zon...ss.cab31267.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg...ntrol_v1-32.cab
O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\winyn32.exe" /s (file missing)
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE