Hi Trev,
Thanks again for the help. Just some quick notes. I couldn't run the Trend Microsystems online scan. When I originally tried to open IE it just gave me the error reporting screen. Eventually it came up with the Microsoft Help page telling me how to do a basic trouble shoot of IE.
I tried the scan twice, only ever reaching the stage where I was asked to install the ActiveX control for the site. I clicked run and IE crashed. I tried once more, but wanted to limit my net activity. Anyway, here is the HijackThis log file. Thanks again.
Logfile of HijackThis v1.99.1
Scan saved at 5:11:12 PM, on 15/07/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\mskl.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\winsu.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\hphmon05.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Symantec AntiVirus\DoScan.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dell.comR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\ugfdq.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\ugfdq.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\ugfdq.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\ugfdq.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\ugfdq.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\ugfdq.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\ugfdq.dll/sp.html#37049
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Class - {10093460-6F53-E394-D35F-77E61A43FF4C} - C:\WINDOWS\system32\appdi.dll
O2 - BHO: Class - {4600A8E2-F7BC-32D2-2B42-0CAB9CAC3C8D} - C:\WINDOWS\mskl.dll
O2 - BHO: Class - {797CF3F6-DFA4-7C09-D2A7-116A21249ABF} - C:\WINDOWS\system32\ippn32.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Class - {E5F0C91D-B125-C770-69FE-FB3428702538} - C:\WINDOWS\system32\sysmn.dll
O2 - BHO: Class - {FA368488-8008-3889-4E2F-86BBFD486BD2} - C:\WINDOWS\system32\d3ga32.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\hphupd05.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [atlnh.exe] C:\WINDOWS\system32\atlnh.exe
O4 - HKLM\..\Run: [sysmn.exe] C:\WINDOWS\system32\sysmn.exe
O4 - HKLM\..\Run: [mskl.exe] C:\WINDOWS\mskl.exe
O4 - HKLM\..\RunOnce: [javaxi.exe] C:\WINDOWS\system32\javaxi.exe
O4 - HKLM\..\RunOnce: [apick.exe] C:\WINDOWS\apick.exe
O4 - HKLM\..\RunOnce: [ntar32.exe] C:\WINDOWS\ntar32.exe
O4 - HKLM\..\RunOnce: [atlgl.exe] C:\WINDOWS\atlgl.exe
O4 - HKLM\..\RunOnce: [syszo.exe] C:\WINDOWS\system32\syszo.exe
O4 - HKLM\..\RunOnce: [atlop32.exe] C:\WINDOWS\atlop32.exe
O4 - HKLM\..\RunOnce: [mfcza32.exe] C:\WINDOWS\system32\mfcza32.exe
O4 - HKLM\..\RunOnce: [sysew32.exe] C:\WINDOWS\system32\sysew32.exe
O4 - HKLM\..\RunOnce: [apizi.exe] C:\WINDOWS\system32\apizi.exe
O4 - HKLM\..\RunOnce: [atlcu32.exe] C:\WINDOWS\system32\atlcu32.exe
O4 - HKLM\..\RunOnce: [netqu32.exe] C:\WINDOWS\system32\netqu32.exe
O4 - HKLM\..\RunOnce: [mfcay.exe] C:\WINDOWS\mfcay.exe
O4 - HKLM\..\RunOnce: [iebk.exe] C:\WINDOWS\system32\iebk.exe
O4 - HKLM\..\RunOnce: [ieim32.exe] C:\WINDOWS\ieim32.exe
O4 - HKLM\..\RunOnce: [mfcqh32.exe] C:\WINDOWS\mfcqh32.exe
O4 - HKLM\..\RunOnce: [apiyx.exe] C:\WINDOWS\apiyx.exe
O4 - HKLM\..\RunOnce: [mfczx.exe] C:\WINDOWS\system32\mfczx.exe
O4 - HKLM\..\RunOnce: [sdkom32.exe] C:\WINDOWS\sdkom32.exe
O4 - HKLM\..\RunOnce: [msmu32.exe] C:\WINDOWS\msmu32.exe
O4 - HKLM\..\RunOnce: [crif.exe] C:\WINDOWS\crif.exe
O4 - HKLM\..\RunOnce: [apigv32.exe] C:\WINDOWS\apigv32.exe
O4 - HKLM\..\RunOnce: [appft.exe] C:\WINDOWS\system32\appft.exe
O4 - HKLM\..\RunOnce: [addft.exe] C:\WINDOWS\addft.exe
O4 - HKLM\..\RunOnce: [apiys.exe] C:\WINDOWS\system32\apiys.exe
O4 - HKLM\..\RunOnce: [apiga.exe] C:\WINDOWS\system32\apiga.exe
O4 - HKLM\..\RunOnce: [sdkra32.exe] C:\WINDOWS\system32\sdkra32.exe
O4 - HKLM\..\RunOnce: [d3hi.exe] C:\WINDOWS\system32\d3hi.exe
O4 - HKLM\..\RunOnce: [addlm32.exe] C:\WINDOWS\system32\addlm32.exe
O4 - HKLM\..\RunOnce: [sdktc32.exe] C:\WINDOWS\system32\sdktc32.exe
O4 - HKLM\..\RunOnce: [addct32.exe] C:\WINDOWS\addct32.exe
O4 - HKLM\..\RunOnce: [javavm32.exe] C:\WINDOWS\javavm32.exe
O4 - HKLM\..\RunOnce: [addqx32.exe] C:\WINDOWS\system32\addqx32.exe
O4 - HKLM\..\RunOnce: [crek.exe] C:\WINDOWS\crek.exe
O4 - HKLM\..\RunOnce: [wintz32.exe] C:\WINDOWS\wintz32.exe
O4 - HKLM\..\RunOnce: [mfcrh.exe] C:\WINDOWS\mfcrh.exe
O4 - HKLM\..\RunOnce: [cran32.exe] C:\WINDOWS\system32\cran32.exe
O4 - HKLM\..\RunOnce: [d3ad.exe] C:\WINDOWS\system32\d3ad.exe
O4 - HKLM\..\RunOnce: [sdkeh32.exe] C:\WINDOWS\system32\sdkeh32.exe
O4 - HKLM\..\RunOnce: [mfcuw.exe] C:\WINDOWS\mfcuw.exe
O4 - HKLM\..\RunOnce: [crsb32.exe] C:\WINDOWS\crsb32.exe
O4 - HKLM\..\RunOnce: [d3rj.exe] C:\WINDOWS\d3rj.exe
O4 - HKLM\..\RunOnce: [javaak.exe] C:\WINDOWS\system32\javaak.exe
O4 - HKLM\..\RunOnce: [winqz.exe] C:\WINDOWS\winqz.exe
O4 - HKLM\..\RunOnce: [winem.exe] C:\WINDOWS\system32\winem.exe
O4 - HKLM\..\RunOnce: [addka32.exe] C:\WINDOWS\system32\addka32.exe
O4 - HKLM\..\RunOnce: [winyx32.exe] C:\WINDOWS\system32\winyx32.exe
O4 - HKLM\..\RunOnce: [crdb32.exe] C:\WINDOWS\system32\crdb32.exe
O4 - HKLM\..\RunOnce: [atlls32.exe] C:\WINDOWS\atlls32.exe
O4 - HKLM\..\RunOnce: [javavy.exe] C:\WINDOWS\javavy.exe
O4 - HKLM\..\RunOnce: [atliu.exe] C:\WINDOWS\system32\atliu.exe
O4 - HKLM\..\RunOnce: [ipey32.exe] C:\WINDOWS\ipey32.exe
O4 - HKLM\..\RunOnce: [apioz.exe] C:\WINDOWS\system32\apioz.exe
O4 - HKLM\..\RunOnce: [sysnp32.exe] C:\WINDOWS\system32\sysnp32.exe
O4 - HKLM\..\RunOnce: [netqa32.exe] C:\WINDOWS\system32\netqa32.exe
O4 - HKLM\..\RunOnce: [sdkuf.exe] C:\WINDOWS\sdkuf.exe
O4 - HKLM\..\RunOnce: [ipdf32.exe] C:\WINDOWS\system32\ipdf32.exe
O4 - HKLM\..\RunOnce: [ipkc32.exe] C:\WINDOWS\ipkc32.exe
O4 - HKLM\..\RunOnce: [addpy32.exe] C:\WINDOWS\addpy32.exe
O4 - HKLM\..\RunOnce: [ipss32.exe] C:\WINDOWS\ipss32.exe
O4 - HKLM\..\RunOnce: [atlqq32.exe] C:\WINDOWS\system32\atlqq32.exe
O4 - HKLM\..\RunOnce: [sdktb32.exe] C:\WINDOWS\system32\sdktb32.exe
O4 - HKLM\..\RunOnce: [d3yg.exe] C:\WINDOWS\d3yg.exe
O4 - HKLM\..\RunOnce: [ntgb32.exe] C:\WINDOWS\ntgb32.exe
O4 - HKLM\..\RunOnce: [msbn.exe] C:\WINDOWS\msbn.exe
O4 - HKLM\..\RunOnce: [mspk32.exe] C:\WINDOWS\mspk32.exe
O4 - HKLM\..\RunOnce: [msdh32.exe] C:\WINDOWS\system32\msdh32.exe
O4 - HKLM\..\RunOnce: [iedp32.exe] C:\WINDOWS\system32\iedp32.exe
O4 - HKLM\..\RunOnce: [sysfg32.exe] C:\WINDOWS\sysfg32.exe
O4 - HKLM\..\RunOnce: [addll32.exe] C:\WINDOWS\addll32.exe
O4 - HKLM\..\RunOnce: [winzi.exe] C:\WINDOWS\winzi.exe
O4 - HKLM\..\RunOnce: [javasb.exe] C:\WINDOWS\system32\javasb.exe
O4 - HKLM\..\RunOnce: [javahw32.exe] C:\WINDOWS\javahw32.exe
O4 - HKLM\..\RunOnce: [mfcms32.exe] C:\WINDOWS\system32\mfcms32.exe
O4 - HKLM\..\RunOnce: [crpe.exe] C:\WINDOWS\crpe.exe
O4 - HKLM\..\RunOnce: [iplq32.exe] C:\WINDOWS\system32\iplq32.exe
O4 - HKLM\..\RunOnce: [atljx.exe] C:\WINDOWS\atljx.exe
O4 - HKLM\..\RunOnce: [iein32.exe] C:\WINDOWS\iein32.exe
O4 - HKLM\..\RunOnce: [javazc32.exe] C:\WINDOWS\system32\javazc32.exe
O4 - HKLM\..\RunOnce: [sdkhs.exe] C:\WINDOWS\sdkhs.exe
O4 - HKLM\..\RunOnce: [d3mx32.exe] C:\WINDOWS\system32\d3mx32.exe
O4 - HKLM\..\RunOnce: [msfi.exe] C:\WINDOWS\msfi.exe
O4 - HKLM\..\RunOnce: [winzj32.exe] C:\WINDOWS\winzj32.exe
O4 - HKLM\..\RunOnce: [javasc32.exe] C:\WINDOWS\javasc32.exe
O4 - HKLM\..\RunOnce: [atlss.exe] C:\WINDOWS\atlss.exe
O4 - HKLM\..\RunOnce: [appat32.exe] C:\WINDOWS\system32\appat32.exe
O4 - HKLM\..\RunOnce: [iezw32.exe] C:\WINDOWS\iezw32.exe
O4 - HKLM\..\RunOnce: [apppd.exe] C:\WINDOWS\apppd.exe
O4 - HKLM\..\RunOnce: [nettz32.exe] C:\WINDOWS\system32\nettz32.exe
O4 - HKLM\..\RunOnce: [atldi.exe] C:\WINDOWS\atldi.exe
O4 - HKLM\..\RunOnce: [mfcxt32.exe] C:\WINDOWS\mfcxt32.exe
O4 - HKLM\..\RunOnce: [iecy32.exe] C:\WINDOWS\iecy32.exe
O4 - HKLM\..\RunOnce: [apizl32.exe] C:\WINDOWS\system32\apizl32.exe
O4 - HKLM\..\RunOnce: [netzt32.exe] C:\WINDOWS\system32\netzt32.exe
O4 - HKLM\..\RunOnce: [sdkdx.exe] C:\WINDOWS\sdkdx.exe
O4 - HKLM\..\RunOnce: [appfq32.exe] C:\WINDOWS\appfq32.exe
O4 - HKLM\..\RunOnce: [javaoh32.exe] C:\WINDOWS\javaoh32.exe
O4 - HKLM\..\RunOnce: [addxn.exe] C:\WINDOWS\addxn.exe
O4 - HKLM\..\RunOnce: [netmk32.exe] C:\WINDOWS\system32\netmk32.exe
O4 - HKLM\..\RunOnce: [crqw.exe] C:\WINDOWS\system32\crqw.exe
O4 - HKLM\..\RunOnce: [d3wt32.exe] C:\WINDOWS\system32\d3wt32.exe
O4 - HKLM\..\RunOnce: [d3ki32.exe] C:\WINDOWS\d3ki32.exe
O4 - HKLM\..\RunOnce: [ieyc32.exe] C:\WINDOWS\ieyc32.exe
O4 - HKLM\..\RunOnce: [msmz32.exe] C:\WINDOWS\system32\msmz32.exe
O4 - HKLM\..\RunOnce: [winam32.exe] C:\WINDOWS\system32\winam32.exe
O4 - HKLM\..\RunOnce: [winuf.exe] C:\WINDOWS\system32\winuf.exe
O4 - HKLM\..\RunOnce: [sdkhc.exe] C:\WINDOWS\sdkhc.exe
O4 - HKLM\..\RunOnce: [ierc.exe] C:\WINDOWS\system32\ierc.exe
O4 - HKLM\..\RunOnce: [ieaq.exe] C:\WINDOWS\system32\ieaq.exe
O4 - HKLM\..\RunOnce: [atlqg32.exe] C:\WINDOWS\system32\atlqg32.exe
O4 - HKLM\..\RunOnce: [apibr.exe] C:\WINDOWS\system32\apibr.exe
O4 - HKLM\..\RunOnce: [sysig32.exe] C:\WINDOWS\system32\sysig32.exe
O4 - HKLM\..\RunOnce: [ieda32.exe] C:\WINDOWS\system32\ieda32.exe
O4 - HKLM\..\RunOnce: [atlhm.exe] C:\WINDOWS\atlhm.exe
O4 - HKLM\..\RunOnce: [sdkwb32.exe] C:\WINDOWS\system32\sdkwb32.exe
O4 - HKLM\..\RunOnce: [d3ur.exe] C:\WINDOWS\system32\d3ur.exe
O4 - HKLM\..\RunOnce: [winqn32.exe] C:\WINDOWS\system32\winqn32.exe
O4 - HKLM\..\RunOnce: [ieav.exe] C:\WINDOWS\system32\ieav.exe
O4 - HKLM\..\RunOnce: [ienk32.exe] C:\WINDOWS\system32\ienk32.exe
O4 - HKLM\..\RunOnce: [ieuh32.exe] C:\WINDOWS\ieuh32.exe
O4 - HKLM\..\RunOnce: [ntzl32.exe] C:\WINDOWS\system32\ntzl32.exe
O4 - HKLM\..\RunOnce: [apphb.exe] C:\WINDOWS\system32\apphb.exe
O4 - HKLM\..\RunOnce: [winhb32.exe] C:\WINDOWS\winhb32.exe
O4 - HKLM\..\RunOnce: [msox32.exe] C:\WINDOWS\system32\msox32.exe
O4 - HKLM\..\RunOnce: [apiii32.exe] C:\WINDOWS\apiii32.exe
O4 - HKLM\..\RunOnce: [appsj.exe] C:\WINDOWS\system32\appsj.exe
O4 - HKLM\..\RunOnce: [appmc32.exe] C:\WINDOWS\system32\appmc32.exe
O4 - HKLM\..\RunOnce: [atlmk32.exe] C:\WINDOWS\system32\atlmk32.exe
O4 - HKLM\..\RunOnce: [netqo.exe] C:\WINDOWS\netqo.exe
O4 - HKLM\..\RunOnce: [sysli32.exe] C:\WINDOWS\sysli32.exe
O4 - HKLM\..\RunOnce: [apiou32.exe] C:\WINDOWS\apiou32.exe
O4 - HKLM\..\RunOnce: [ntsy.exe] C:\WINDOWS\system32\ntsy.exe
O4 - HKLM\..\RunOnce: [netbg32.exe] C:\WINDOWS\netbg32.exe
O4 - HKLM\..\RunOnce: [ippl32.exe] C:\WINDOWS\system32\ippl32.exe
O4 - HKLM\..\RunOnce: [crxp32.exe] C:\WINDOWS\system32\crxp32.exe
O4 - HKLM\..\RunOnce: [ipvm.exe] C:\WINDOWS\ipvm.exe
O4 - HKLM\..\RunOnce: [netvm.exe] C:\WINDOWS\system32\netvm.exe
O4 - HKLM\..\RunOnce: [sysjr32.exe] C:\WINDOWS\sysjr32.exe
O4 - HKLM\..\RunOnce: [msev.exe] C:\WINDOWS\system32\msev.exe
O4 - HKLM\..\RunOnce: [ntdk32.exe] C:\WINDOWS\ntdk32.exe
O4 - HKLM\..\RunOnce: [mfcta32.exe] C:\WINDOWS\system32\mfcta32.exe
O4 - HKLM\..\RunOnce: [mfcbi.exe] C:\WINDOWS\system32\mfcbi.exe
O4 - HKLM\..\RunOnce: [atlci.exe] C:\WINDOWS\atlci.exe
O4 - HKLM\..\RunOnce: [javalq.exe] C:\WINDOWS\javalq.exe
O4 - HKLM\..\RunOnce: [addiw.exe] C:\WINDOWS\system32\addiw.exe
O4 - HKLM\..\RunOnce: [crhd32.exe] C:\WINDOWS\system32\crhd32.exe
O4 - HKLM\..\RunOnce: [ipmn.exe] C:\WINDOWS\system32\ipmn.exe
O4 - HKLM\..\RunOnce: [apptt.exe] C:\WINDOWS\apptt.exe
O4 - HKLM\..\RunOnce: [appnf32.exe] C:\WINDOWS\appnf32.exe
O4 - HKLM\..\RunOnce: [atlnn32.exe] C:\WINDOWS\atlnn32.exe
O4 - HKLM\..\RunOnce: [apiaz32.exe] C:\WINDOWS\apiaz32.exe
O4 - HKLM\..\RunOnce: [apivl.exe] C:\WINDOWS\system32\apivl.exe
O4 - HKLM\..\RunOnce: [addyx32.exe] C:\WINDOWS\system32\addyx32.exe
O4 - HKLM\..\RunOnce: [d3dt32.exe] C:\WINDOWS\system32\d3dt32.exe
O4 - HKLM\..\RunOnce: [appyf.exe] C:\WINDOWS\appyf.exe
O4 - HKLM\..\RunOnce: [syscr.exe] C:\WINDOWS\syscr.exe
O4 - HKLM\..\RunOnce: [mfcrg32.exe] C:\WINDOWS\system32\mfcrg32.exe
O4 - HKLM\..\RunOnce: [sysrt32.exe] C:\WINDOWS\system32\sysrt32.exe
O4 - HKLM\..\RunOnce: [winzb32.exe] C:\WINDOWS\winzb32.exe
O4 - HKLM\..\RunOnce: [nths.exe] C:\WINDOWS\nths.exe
O4 - HKLM\..\RunOnce: [mfcdc32.exe] C:\WINDOWS\mfcdc32.exe
O4 - HKLM\..\RunOnce: [nethh.exe] C:\WINDOWS\nethh.exe
O4 - HKLM\..\RunOnce: [apixe32.exe] C:\WINDOWS\apixe32.exe
O4 - HKLM\..\RunOnce: [sysba.exe] C:\WINDOWS\sysba.exe
O4 - HKLM\..\RunOnce: [d3av32.exe] C:\WINDOWS\system32\d3av32.exe
O4 - HKLM\..\RunOnce: [netfa32.exe] C:\WINDOWS\system32\netfa32.exe
O4 - HKLM\..\RunOnce: [msil32.exe] C:\WINDOWS\system32\msil32.exe
O4 - HKLM\..\RunOnce: [ienq32.exe] C:\WINDOWS\system32\ienq32.exe
O4 - HKLM\..\RunOnce: [iecn.exe] C:\WINDOWS\iecn.exe
O4 - HKLM\..\RunOnce: [iehj.exe] C:\WINDOWS\iehj.exe
O4 - HKLM\..\RunOnce: [ntvg.exe] C:\WINDOWS\ntvg.exe
O4 - HKLM\..\RunOnce: [mfcnx.exe] C:\WINDOWS\mfcnx.exe
O4 - HKLM\..\RunOnce: [sdkjb32.exe] C:\WINDOWS\sdkjb32.exe
O4 - HKLM\..\RunOnce: [nettc.exe] C:\WINDOWS\nettc.exe
O4 - HKLM\..\RunOnce: [netvn32.exe] C:\WINDOWS\system32\netvn32.exe
O4 - HKLM\..\RunOnce: [addsr32.exe] C:\WINDOWS\addsr32.exe
O4 - HKLM\..\RunOnce: [crtq.exe] C:\WINDOWS\system32\crtq.exe
O4 - HKLM\..\RunOnce: [appcz.exe] C:\WINDOWS\system32\appcz.exe
O4 - HKLM\..\RunOnce: [ipmz.exe] C:\WINDOWS\ipmz.exe
O4 - HKLM\..\RunOnce: [mfcid.exe] C:\WINDOWS\system32\mfcid.exe
O4 - HKLM\..\RunOnce: [d3wi32.exe] C:\WINDOWS\system32\d3wi32.exe
O4 - HKLM\..\RunOnce: [sysup.exe] C:\WINDOWS\system32\sysup.exe
O4 - HKLM\..\RunOnce: [atlqt.exe] C:\WINDOWS\atlqt.exe
O4 - HKLM\..\RunOnce: [ipjm32.exe] C:\WINDOWS\system32\ipjm32.exe
O4 - HKLM\..\RunOnce: [sysdy32.exe] C:\WINDOWS\sysdy32.exe
O4 - HKLM\..\RunOnce: [d3mg.exe] C:\WINDOWS\system32\d3mg.exe
O4 - HKLM\..\RunOnce: [mssv32.exe] C:\WINDOWS\mssv32.exe
O4 - HKLM\..\RunOnce: [d3hs32.exe] C:\WINDOWS\system32\d3hs32.exe
O4 - HKLM\..\RunOnce: [msgi32.exe] C:\WINDOWS\system32\msgi32.exe
O4 - HKLM\..\RunOnce: [winlm.exe] C:\WINDOWS\winlm.exe
O4 - HKLM\..\RunOnce: [iejj32.exe] C:\WINDOWS\iejj32.exe
O4 - HKLM\..\RunOnce: [winip.exe] C:\WINDOWS\system32\winip.exe
O4 - HKLM\..\RunOnce: [iexe.exe] C:\WINDOWS\system32\iexe.exe
O4 - HKLM\..\RunOnce: [sdkix32.exe] C:\WINDOWS\sdkix32.exe
O4 - HKLM\..\RunOnce: [javati.exe] C:\WINDOWS\javati.exe
O4 - HKLM\..\RunOnce: [iexm.exe] C:\WINDOWS\system32\iexm.exe
O4 - HKLM\..\RunOnce: [appin32.exe] C:\WINDOWS\appin32.exe
O4 - HKLM\..\RunOnce: [winfk32.exe] C:\WINDOWS\winfk32.exe
O4 - HKLM\..\RunOnce: [msdh.exe] C:\WINDOWS\system32\msdh.exe
O4 - HKLM\..\RunOnce: [crei.exe] C:\WINDOWS\crei.exe
O4 - HKLM\..\RunOnce: [addtx32.exe] C:\WINDOWS\system32\addtx32.exe
O4 - HKLM\..\RunOnce: [atlnq.exe] C:\WINDOWS\atlnq.exe
O4 - HKLM\..\RunOnce: [mfcjd32.exe] C:\WINDOWS\system32\mfcjd32.exe
O4 - HKLM\..\RunOnce: [winzs32.exe] C:\WINDOWS\winzs32.exe
O4 - HKLM\..\RunOnce: [winqp.exe] C:\WINDOWS\winqp.exe
O4 - HKLM\..\RunOnce: [sdkvl.exe] C:\WINDOWS\system32\sdkvl.exe
O4 - HKLM\..\RunOnce: [addqx.exe] C:\WINDOWS\addqx.exe
O4 - HKLM\..\RunOnce: [iefm.exe] C:\WINDOWS\iefm.exe
O4 - HKLM\..\RunOnce: [sdkqf32.exe] C:\WINDOWS\system32\sdkqf32.exe
O4 - HKLM\..\RunOnce: [atlxv32.exe] C:\WINDOWS\system32\atlxv32.exe
O4 - HKLM\..\RunOnce: [ntva32.exe] C:\WINDOWS\system32\ntva32.exe
O4 - HKLM\..\RunOnce: [appaw32.exe] C:\WINDOWS\system32\appaw32.exe
O4 - HKLM\..\RunOnce: [sdkvi32.exe] C:\WINDOWS\system32\sdkvi32.exe
O4 - HKLM\..\RunOnce: [javajn32.exe] C:\WINDOWS\system32\javajn32.exe
O4 - HKLM\..\RunOnce: [addys.exe] C:\WINDOWS\addys.exe
O4 - HKLM\..\RunOnce: [crff32.exe] C:\WINDOWS\crff32.exe
O4 - HKLM\..\RunOnce: [appar32.exe] C:\WINDOWS\system32\appar32.exe
O4 - HKLM\..\RunOnce: [mfcfv.exe] C:\WINDOWS\mfcfv.exe
O4 - HKLM\..\RunOnce: [addxm.exe] C:\WINDOWS\system32\addxm.exe
O4 - HKLM\..\RunOnce: [msqf32.exe] C:\WINDOWS\system32\msqf32.exe
O4 - HKLM\..\RunOnce: [iebq.exe] C:\WINDOWS\iebq.exe
O4 - HKLM\..\RunOnce: [appfu.exe] C:\WINDOWS\appfu.exe
O4 - HKLM\..\RunOnce: [crob32.exe] C:\WINDOWS\crob32.exe
O4 - HKLM\..\RunOnce: [msng.exe] C:\WINDOWS\system32\msng.exe
O4 - HKLM\..\RunOnce: [javadv.exe] C:\WINDOWS\system32\javadv.exe
O4 - HKLM\..\RunOnce: [netvo32.exe] C:\WINDOWS\netvo32.exe
O4 - HKLM\..\RunOnce: [crkd.exe] C:\WINDOWS\system32\crkd.exe
O4 - HKLM\..\RunOnce: [sysve32.exe] C:\WINDOWS\sysve32.exe
O4 - HKLM\..\RunOnce: [ippq32.exe] C:\WINDOWS\system32\ippq32.exe
O4 - HKLM\..\RunOnce: [mfczq.exe] C:\WINDOWS\system32\mfczq.exe
O4 - HKLM\..\RunOnce: [apien32.exe] C:\WINDOWS\system32\apien32.exe
O4 - HKLM\..\RunOnce: [mfctk32.exe] C:\WINDOWS\mfctk32.exe
O4 - HKLM\..\RunOnce: [ntfw.exe] C:\WINDOWS\system32\ntfw.exe
O4 - HKLM\..\RunOnce: [netvt32.exe] C:\WINDOWS\system32\netvt32.exe
O4 - HKLM\..\RunOnce: [winap32.exe] C:\WINDOWS\system32\winap32.exe
O4 - HKLM\..\RunOnce: [ipdb32.exe] C:\WINDOWS\system32\ipdb32.exe
O4 - HKLM\..\RunOnce: [javahf.exe] C:\WINDOWS\javahf.exe
O4 - HKLM\..\RunOnce: [d3be.exe] C:\WINDOWS\system32\d3be.exe
O4 - HKLM\..\RunOnce: [sdkqu.exe] C:\WINDOWS\system32\sdkqu.exe
O4 - HKLM\..\RunOnce: [addfq32.exe] C:\WINDOWS\system32\addfq32.exe
O4 - HKLM\..\RunOnce: [crkv32.exe] C:\WINDOWS\system32\crkv32.exe
O4 - HKLM\..\RunOnce: [appfh.exe] C:\WINDOWS\system32\appfh.exe
O4 - HKLM\..\RunOnce: [javaha.exe] C:\WINDOWS\system32\javaha.exe
O4 - HKLM\..\RunOnce: [addwf32.exe] C:\WINDOWS\addwf32.exe
O4 - HKLM\..\RunOnce: [winfn.exe] C:\WINDOWS\winfn.exe
O4 - HKLM\..\RunOnce: [javaks32.exe] C:\WINDOWS\javaks32.exe
O4 - HKLM\..\RunOnce: [ipnw.exe] C:\WINDOWS\ipnw.exe
O4 - HKLM\..\RunOnce: [iecb.exe] C:\WINDOWS\system32\iecb.exe
O4 - HKLM\..\RunOnce: [d3gc.exe] C:\WINDOWS\d3gc.exe
O4 - HKLM\..\RunOnce: [ieze32.exe] C:\WINDOWS\ieze32.exe
O4 - HKLM\..\RunOnce: [ieoa32.exe] C:\WINDOWS\system32\ieoa32.exe
O4 - HKLM\..\RunOnce: [nttx32.exe] C:\WINDOWS\nttx32.exe
O4 - HKLM\..\RunOnce: [javamo32.exe] C:\WINDOWS\system32\javamo32.exe
O4 - HKLM\..\RunOnce: [winpa32.exe] C:\WINDOWS\winpa32.exe
O4 - HKLM\..\RunOnce: [appdf32.exe] C:\WINDOWS\appdf32.exe
O4 - HKLM\..\RunOnce: [addjb.exe] C:\WINDOWS\system32\addjb.exe
O4 - HKLM\..\RunOnce: [crdv.exe] C:\WINDOWS\system32\crdv.exe
O4 - HKLM\..\RunOnce: [winmn.exe] C:\WINDOWS\winmn.exe
O4 - HKLM\..\RunOnce: [atlsp32.exe] C:\WINDOWS\system32\atlsp32.exe
O4 - HKLM\..\RunOnce: [sdkvj32.exe] C:\WINDOWS\sdkvj32.exe
O4 - HKLM\..\RunOnce: [d3zf.exe] C:\WINDOWS\d3zf.exe
O4 - HKLM\..\RunOnce: [javapc.exe] C:\WINDOWS\javapc.exe
O4 - HKLM\..\RunOnce: [crcz.exe] C:\WINDOWS\crcz.exe
O4 - HKLM\..\RunOnce: [mfcie.exe] C:\WINDOWS\system32\mfcie.exe
O4 - HKLM\..\RunOnce: [d3cp.exe] C:\WINDOWS\d3cp.exe
O4 - HKLM\..\RunOnce: [sdksw.exe] C:\WINDOWS\sdksw.exe
O4 - HKLM\..\RunOnce: [netvi.exe] C:\WINDOWS\system32\netvi.exe
O4 - HKLM\..\RunOnce: [javarm.exe] C:\WINDOWS\javarm.exe
O4 - HKLM\..\RunOnce: [addam.exe] C:\WINDOWS\system32\addam.exe
O4 - HKLM\..\RunOnce: [atlor.exe] C:\WINDOWS\system32\atlor.exe
O4 - HKLM\..\RunOnce: [atlto32.exe] C:\WINDOWS\atlto32.exe
O4 - HKLM\..\RunOnce: [atlil32.exe] C:\WINDOWS\system32\atlil32.exe
O4 - HKLM\..\RunOnce: [msnh32.exe] C:\WINDOWS\system32\msnh32.exe
O4 - HKLM\..\RunOnce: [mfcit32.exe] C:\WINDOWS\system32\mfcit32.exe
O4 - HKLM\..\RunOnce: [netmx.exe] C:\WINDOWS\netmx.exe
O4 - HKLM\..\RunOnce: [d3ed.exe] C:\WINDOWS\system32\d3ed.exe
O4 - HKLM\..\RunOnce: [netki.exe] C:\WINDOWS\netki.exe
O4 - HKLM\..\RunOnce: [ipym.exe] C:\WINDOWS\ipym.exe
O4 - HKLM\..\RunOnce: [ipsg32.exe] C:\WINDOWS\system32\ipsg32.exe
O4 - HKLM\..\RunOnce: [appxc32.exe] C:\WINDOWS\appxc32.exe
O4 - HKLM\..\RunOnce: [cres32.exe] C:\WINDOWS\cres32.exe
O4 - HKLM\..\RunOnce: [appbf.exe] C:\WINDOWS\system32\appbf.exe
O4 - HKLM\..\RunOnce: [crhc32.exe] C:\WINDOWS\crhc32.exe
O4 - HKLM\..\RunOnce: [msav32.exe] C:\WINDOWS\system32\msav32.exe
O4 - HKLM\..\RunOnce: [ipfr32.exe] C:\WINDOWS\system32\ipfr32.exe
O4 - HKLM\..\RunOnce: [iead.exe] C:\WINDOWS\system32\iead.exe
O4 - HKLM\..\RunOnce: [javaep.exe] C:\WINDOWS\javaep.exe
O4 - HKLM\..\RunOnce: [atlkm.exe] C:\WINDOWS\system32\atlkm.exe
O4 - HKLM\..\RunOnce: [sysiz.exe] C:\WINDOWS\sysiz.exe
O4 - HKLM\..\RunOnce: [mfcmd.exe] C:\WINDOWS\system32\mfcmd.exe
O4 - HKLM\..\RunOnce: [crnl.exe] C:\WINDOWS\system32\crnl.exe
O4 - HKLM\..\RunOnce: [d3vb32.exe] C:\WINDOWS\d3vb32.exe
O4 - HKLM\..\RunOnce: [winhw.exe] C:\WINDOWS\system32\winhw.exe
O4 - HKLM\..\RunOnce: [iext32.exe] C:\WINDOWS\system32\iext32.exe
O4 - HKLM\..\RunOnce: [appjf.exe] C:\WINDOWS\appjf.exe
O4 - HKLM\..\RunOnce: [addkf32.exe] C:\WINDOWS\system32\addkf32.exe
O4 - HKLM\..\RunOnce: [addez.exe] C:\WINDOWS\addez.exe
O4 - HKLM\..\RunOnce: [javasv.exe] C:\WINDOWS\javasv.exe
O4 - HKLM\..\RunOnce: [apphy32.exe] C:\WINDOWS\apphy32.exe
O4 - HKLM\..\RunOnce: [ntck32.exe] C:\WINDOWS\system32\ntck32.exe
O4 - HKLM\..\RunOnce: [croo.exe] C:\WINDOWS\croo.exe
O4 - HKLM\..\RunOnce: [javapo32.exe] C:\WINDOWS\system32\javapo32.exe
O4 - HKLM\..\RunOnce: [sdkel.exe] C:\WINDOWS\sdkel.exe
O4 - HKLM\..\RunOnce: [javaji.exe] C:\WINDOWS\system32\javaji.exe
O4 - HKLM\..\RunOnce: [crrq.exe] C:\WINDOWS\system32\crrq.exe
O4 - HKLM\..\RunOnce: [nthf.exe] C:\WINDOWS\system32\nthf.exe
O4 - HKLM\..\RunOnce: [sdkgn.exe] C:\WINDOWS\system32\sdkgn.exe
O4 - HKLM\..\RunOnce: [winpv.exe] C:\WINDOWS\winpv.exe
O4 - HKLM\..\RunOnce: [mfclz32.exe] C:\WINDOWS\system32\mfclz32.exe
O4 - HKLM\..\RunOnce: [appiw32.exe] C:\WINDOWS\system32\appiw32.exe
O4 - HKLM\..\RunOnce: [addpt32.exe] C:\WINDOWS\addpt32.exe
O4 - HKLM\..\RunOnce: [d3uq32.exe] C:\WINDOWS\d3uq32.exe
O4 - HKLM\..\RunOnce: [javarl.exe] C:\WINDOWS\javarl.exe
O4 - HKLM\..\RunOnce: [mfcqs32.exe] C:\WINDOWS\mfcqs32.exe
O4 - HKLM\..\RunOnce: [crxh.exe] C:\WINDOWS\system32\crxh.exe
O4 - HKLM\..\RunOnce: [mswp32.exe] C:\WINDOWS\system32\mswp32.exe
O4 - HKLM\..\RunOnce: [winev32.exe] C:\WINDOWS\system32\winev32.exe
O4 - HKLM\..\RunOnce: [mfcwe32.exe] C:\WINDOWS\mfcwe32.exe
O4 - HKLM\..\RunOnce: [atlfu.exe] C:\WINDOWS\system32\atlfu.exe
O4 - HKLM\..\RunOnce: [apimk32.exe] C:\WINDOWS\apimk32.exe
O4 - HKLM\..\RunOnce: [addca32.exe] C:\WINDOWS\system32\addca32.exe
O4 - HKLM\..\RunOnce: [appki.exe] C:\WINDOWS\system32\appki.exe
O4 - HKLM\..\RunOnce: [javalo.exe] C:\WINDOWS\javalo.exe
O4 - HKLM\..\RunOnce: [apikd32.exe] C:\WINDOWS\apikd32.exe
O4 - HKLM\..\RunOnce: [addit.exe] C:\WINDOWS\system32\addit.exe
O4 - HKLM\..\RunOnce: [ipgg.exe] C:\WINDOWS\system32\ipgg.exe
O4 - HKLM\..\RunOnce: [msvv32.exe] C:\WINDOWS\msvv32.exe
O4 - HKLM\..\RunOnce: [wintd32.exe] C:\WINDOWS\wintd32.exe
O4 - HKLM\..\RunOnce: [ieoo.exe] C:\WINDOWS\ieoo.exe
O4 - HKLM\..\RunOnce: [sdkne32.exe] C:\WINDOWS\sdkne32.exe
O4 - HKLM\..\RunOnce: [apilc.exe] C:\WINDOWS\system32\apilc.exe
O4 - HKLM\..\RunOnce: [appsh.exe] C:\WINDOWS\appsh.exe
O4 - HKLM\..\RunOnce: [d3rx32.exe] C:\WINDOWS\d3rx32.exe
O4 - HKLM\..\RunOnce: [nthm32.exe] C:\WINDOWS\system32\nthm32.exe
O4 - HKLM\..\RunOnce: [atlad.exe] C:\WINDOWS\atlad.exe
O4 - HKLM\..\RunOnce: [syslm32.exe] C:\WINDOWS\syslm32.exe
O4 - HKLM\..\RunOnce: [winsu.exe] C:\WINDOWS\winsu.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: AOL 9.0 Tray Icon.lnk = C:\Program Files\AOL 9.0\aoltray.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} -
http://wwws.musicmat...enWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.syma...bin/AvSniff.cabO16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.syma...n/bin/cabsa.cabO16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai...all/xscan53.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoft.../as5/asinst.cabO23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\javaxi.exe" /s (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: CWShredder Service - InterMute, Inc. - C:\Documents and Settings\Roger Stewart\Desktop\Dean's Malware Removal\CWShredder.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Here is the about:Buster log file:
AboutBuster 5.0 reference file 30
Scan started on [13/07/2005] at [10:30:42 AM]
------------------------------------------------
Removed Stream! C:\WINDOWS\Blue Lace 16.bmp:siwuip
Removed Stream! C:\WINDOWS\brtvv.dat:uzohe
Removed Stream! C:\WINDOWS\CBCDIJKN.ini:lihzcr
Removed Stream! C:\WINDOWS\CMSETACL.LOG:fbeaz
Removed Stream! C:\WINDOWS\COMSETUP.LOG:gmuywb
Removed Stream! C:\WINDOWS\DESKTOP.INI:qnmdql
Removed Stream! C:\WINDOWS\EventSystem.log:joxrsw
Removed Stream! C:\WINDOWS\gbniz.txt:kshqfn
Removed Stream! C:\WINDOWS\Greenstone.bmp:rgxjm
Removed Stream! C:\WINDOWS\hmkmr.dat:tywtx
Removed Stream! C:\WINDOWS\hpothb07.tif:itpys
Removed Stream! C:\WINDOWS\igfvg.dat:wbuiu
Removed Stream! C:\WINDOWS\itpys.txt:obmnw
Removed Stream! C:\WINDOWS\KB873333.log:ehmvck
Removed Stream! C:\WINDOWS\KB886185.log:vysalz
Removed Stream! C:\WINDOWS\KB888302.log:rwith
Removed Stream! C:\WINDOWS\KB893086.log:qsdsc
Removed Stream! C:\WINDOWS\lablw.dat:qslfz
Removed Stream! C:\WINDOWS\mp10oem.txt:upesxj
Removed Stream! C:\WINDOWS\MSDFMAP.INI:brwjc
Removed Stream! C:\WINDOWS\nsw.log:nhwfrt
Removed Stream! C:\WINDOWS\River Sumida.bmp:bjrnmo
Removed Stream! C:\WINDOWS\setuperr.log:vikbxq
Removed Stream! C:\WINDOWS\SIERRA.INI:lwxmz
Removed Stream! C:\WINDOWS\Sti_Trace.log:hnfhsf
Removed Stream! C:\WINDOWS\SYSTEM.INI:zfcrln
Removed Stream! C:\WINDOWS\T30DebugLogFile.txt:znqnup
Removed Stream! C:\WINDOWS\wmsetup10.log:irohc
Removed Stream! C:\WINDOWS\xhbmd.log:flsoz
Removed Stream! C:\WINDOWS\yeaec.dat:iwttdb
Removed Stream! C:\WINDOWS\_DEFAULT.PIF:awlyxm
Removed Stream! C:\WINDOWS\_DEFAULT.PIF:axipi
------------------------------------------------
Removed File! : C:\Windows\ddlis.dll
Removed File! : C:\Windows\dkble.dat
Removed File! : C:\Windows\fdmao.dat
Removed File! : C:\Windows\fdoxj.dll
Removed File! : C:\Windows\lablw.dat
Removed File! : C:\Windows\xfkad.dat
Removed File! : C:\Windows\zrbvk.dat
Removed File! : C:\Windows\System32\acazu.dat
Removed File! : C:\Windows\System32\agrjt.dat
Removed File! : C:\Windows\System32\eggyg.dll
------------------------------------------------
Scan was COMPLETED SUCCESSFULLY at 10:31:00 AM
AboutBuster 5.0 reference file 30
Scan started on [13/07/2005] at [5:46:14 PM]
------------------------------------------------
Removed Stream! C:\WINDOWS\brtvv.dat:kpoxgz
Removed Stream! C:\WINDOWS\hpothb07.tif:itpysa
Removed Stream! C:\WINDOWS\xhbmd.log:pxhrx
Removed Stream! C:\WINDOWS\_DEFAULT.PIF:acwdnk
------------------------------------------------
Removed File! : C:\Windows\sumzh.dat
Removed File! : C:\Windows\System32\fypps.dat
Removed File! : C:\Windows\System32\jgucl.dat
------------------------------------------------
Scan was COMPLETED SUCCESSFULLY at 5:46:33 PM
AboutBuster 5.0 reference file 30
Scan started on [15/07/2005] at [4:57:11 PM]
------------------------------------------------
Removed Stream! C:\WINDOWS\_DEFAULT.PIF:bclgoq
Removed Stream! C:\WINDOWS\_DEFAULT.PIF:bkwxkz
------------------------------------------------
Removed File! : C:\Windows\itejb.dll
Removed File! : C:\Windows\jwvwp.dll
Removed File! : C:\Windows\System32\hkpil.dat
Removed File! : C:\Windows\System32\uaott.dll
------------------------------------------------
Scan was COMPLETED SUCCESSFULLY at 4:57:45 PM
Thank you again.
Dean