Logfile of HijackThis v1.99.1
Scan saved at 4:24:34 PM, on 8/7/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\avpcc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\d3ri.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\DOCUME~1\MIKEYT~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
C:\DOCUME~1\MIKEYT~1\LOCALS~1\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\vrfwt.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\vrfwt.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\vrfwt.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\vrfwt.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\vrfwt.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\vrfwt.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\vrfwt.dll/sp.html#37049
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {2BAB9DCF-AB6E-FD19-25BB-4FA3012F78E1} - C:\WINDOWS\system32\apptq.dll
O2 - BHO: Class - {4F96C427-A2E2-F522-0ABA-0CDBB14A7153} - C:\WINDOWS\system32\apiez32.dll
O2 - BHO: Class - {FEB759AF-0344-33C1-9B59-C5DB1E7E371F} - C:\WINDOWS\system32\appoo.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_3_12_0.dll
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [C-Media Speaker Configuration] C:\DOCUME~1\MIKEYT~1\LOCALS~1\Temp\Temporary Directory 1 for cmi8738_w2k_xp_me-630.zip\CMI8738 for XP-W2K-ME\Setup.exe /SPEAKER
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [iexplore.exe] C:\Program Files\Internet Explorer\iexplore.exe
O4 - HKLM\..\Run: [sdkif32.exe] C:\WINDOWS\sdkif32.exe
O4 - HKLM\..\Run: [sysqm32.exe] C:\WINDOWS\system32\sysqm32.exe
O4 - HKLM\..\Run: [iegc.exe] C:\WINDOWS\system32\iegc.exe
O4 - HKLM\..\Run: [appal32.exe] C:\WINDOWS\system32\appal32.exe
O4 - HKLM\..\Run: [javaeg.exe] C:\WINDOWS\javaeg.exe
O4 - HKLM\..\Run: [apiyf32.exe] C:\WINDOWS\apiyf32.exe
O4 - HKLM\..\Run: [d3fi32.exe] C:\WINDOWS\system32\d3fi32.exe
O4 - HKLM\..\Run: [ielt.exe] C:\WINDOWS\system32\ielt.exe
O4 - HKLM\..\Run: [javayd32.exe] C:\WINDOWS\system32\javayd32.exe
O4 - HKLM\..\Run: [winmr.exe] C:\WINDOWS\system32\winmr.exe
O4 - HKLM\..\Run: [addyn32.exe] C:\WINDOWS\addyn32.exe
O4 - HKLM\..\Run: [mfctl32.exe] C:\WINDOWS\system32\mfctl32.exe
O4 - HKLM\..\Run: [apppp32.exe] C:\WINDOWS\system32\apppp32.exe
O4 - HKLM\..\Run: [crid32.exe] C:\WINDOWS\system32\crid32.exe
O4 - HKLM\..\Run: [mfcjb32.exe] C:\WINDOWS\system32\mfcjb32.exe
O4 - HKLM\..\Run: [winaf.exe] C:\WINDOWS\winaf.exe
O4 - HKLM\..\Run: [ipfe.exe] C:\WINDOWS\ipfe.exe
O4 - HKLM\..\Run: [ielx.exe] C:\WINDOWS\ielx.exe
O4 - HKLM\..\Run: [atljt.exe] C:\WINDOWS\atljt.exe
O4 - HKLM\..\Run: [d3kf.exe] C:\WINDOWS\system32\d3kf.exe
O4 - HKLM\..\Run: [mfczy.exe] C:\WINDOWS\system32\mfczy.exe
O4 - HKLM\..\Run: [winal.exe] C:\WINDOWS\system32\winal.exe
O4 - HKLM\..\Run: [d3os32.exe] C:\WINDOWS\system32\d3os32.exe
O4 - HKLM\..\Run: [addbg32.exe] C:\WINDOWS\system32\addbg32.exe
O4 - HKLM\..\Run: [apivz32.exe] C:\WINDOWS\system32\apivz32.exe
O4 - HKLM\..\Run: [iphd32.exe] C:\WINDOWS\iphd32.exe
O4 - HKLM\..\Run: [winrs32.exe] C:\WINDOWS\winrs32.exe
O4 - HKLM\..\Run: [ipqa32.exe] C:\WINDOWS\system32\ipqa32.exe
O4 - HKLM\..\Run: [apisf32.exe] C:\WINDOWS\system32\apisf32.exe
O4 - HKLM\..\Run: [winua.exe] C:\WINDOWS\system32\winua.exe
O4 - HKLM\..\Run: [javaiq.exe] C:\WINDOWS\javaiq.exe
O4 - HKLM\..\Run: [sdkpj32.exe] C:\WINDOWS\sdkpj32.exe
O4 - HKLM\..\Run: [atlud.exe] C:\WINDOWS\system32\atlud.exe
O4 - HKLM\..\Run: [d3hl32.exe] C:\WINDOWS\system32\d3hl32.exe
O4 - HKLM\..\Run: [mfcav.exe] C:\WINDOWS\mfcav.exe
O4 - HKLM\..\Run: [sdksr.exe] C:\WINDOWS\sdksr.exe
O4 - HKLM\..\Run: [apivh.exe] C:\WINDOWS\apivh.exe
O4 - HKLM\..\Run: [sdkia.exe] C:\WINDOWS\system32\sdkia.exe
O4 - HKLM\..\Run: [d3ri.exe] C:\WINDOWS\d3ri.exe
O4 - HKLM\..\RunOnce: [adduu.exe] C:\WINDOWS\adduu.exe
O4 - HKLM\..\RunOnce: [wingz32.exe] C:\WINDOWS\system32\wingz32.exe
O4 - HKLM\..\RunOnce: [syspd32.exe] C:\WINDOWS\syspd32.exe
O4 - HKLM\..\RunOnce: [crqs32.exe] C:\WINDOWS\crqs32.exe
O4 - HKLM\..\RunOnce: [iedc32.exe] C:\WINDOWS\system32\iedc32.exe
O4 - HKLM\..\RunOnce: [atlcq.exe] C:\WINDOWS\system32\atlcq.exe
O4 - HKLM\..\RunOnce: [crbs.exe] C:\WINDOWS\system32\crbs.exe
O4 - HKLM\..\RunOnce: [ielf.exe] C:\WINDOWS\system32\ielf.exe
O4 - HKLM\..\RunOnce: [ntoy32.exe] C:\WINDOWS\system32\ntoy32.exe
O4 - HKLM\..\RunOnce: [netsz.exe] C:\WINDOWS\system32\netsz.exe
O4 - HKLM\..\RunOnce: [winti32.exe] C:\WINDOWS\winti32.exe
O4 - HKLM\..\RunOnce: [mswn.exe] C:\WINDOWS\system32\mswn.exe
O4 - HKLM\..\RunOnce: [sdkvy.exe] C:\WINDOWS\sdkvy.exe
O4 - HKLM\..\RunOnce: [winid.exe] C:\WINDOWS\system32\winid.exe
O4 - HKLM\..\RunOnce: [iesh32.exe] C:\WINDOWS\iesh32.exe
O4 - HKLM\..\RunOnce: [appkq32.exe] C:\WINDOWS\system32\appkq32.exe
O4 - HKLM\..\RunOnce: [netmt32.exe] C:\WINDOWS\system32\netmt32.exe
O4 - HKLM\..\RunOnce: [addrn.exe] C:\WINDOWS\system32\addrn.exe
O4 - HKLM\..\RunOnce: [netkj32.exe] C:\WINDOWS\netkj32.exe
O4 - HKLM\..\RunOnce: [crwj.exe] C:\WINDOWS\crwj.exe
O4 - HKLM\..\RunOnce: [winbl.exe] C:\WINDOWS\winbl.exe
O4 - HKLM\..\RunOnce: [mfchw.exe] C:\WINDOWS\system32\mfchw.exe
O4 - HKLM\..\RunOnce: [netdp.exe] C:\WINDOWS\system32\netdp.exe
O4 - HKLM\..\RunOnce: [iewx32.exe] C:\WINDOWS\system32\iewx32.exe
O4 - HKLM\..\RunOnce: [d3ft32.exe] C:\WINDOWS\system32\d3ft32.exe
O4 - HKLM\..\RunOnce: [ntyk32.exe] C:\WINDOWS\ntyk32.exe
O4 - HKLM\..\RunOnce: [crrb32.exe] C:\WINDOWS\system32\crrb32.exe
O4 - HKLM\..\RunOnce: [iebn32.exe] C:\WINDOWS\system32\iebn32.exe
O4 - HKLM\..\RunOnce: [javavq32.exe] C:\WINDOWS\javavq32.exe
O4 - HKLM\..\RunOnce: [addoy.exe] C:\WINDOWS\addoy.exe
O4 - HKLM\..\RunOnce: [sysmj32.exe] C:\WINDOWS\system32\sysmj32.exe
O4 - HKLM\..\RunOnce: [winzx.exe] C:\WINDOWS\winzx.exe
O4 - HKLM\..\RunOnce: [apiku.exe] C:\WINDOWS\system32\apiku.exe
O4 - HKLM\..\RunOnce: [javaow.exe] C:\WINDOWS\system32\javaow.exe
O4 - HKLM\..\RunOnce: [javasj32.exe] C:\WINDOWS\system32\javasj32.exe
O4 - HKLM\..\RunOnce: [netps.exe] C:\WINDOWS\system32\netps.exe
O4 - HKLM\..\RunOnce: [addwy32.exe] C:\WINDOWS\addwy32.exe
O4 - HKLM\..\RunOnce: [mfcug.exe] C:\WINDOWS\mfcug.exe
O4 - HKLM\..\RunOnce: [ieyy32.exe] C:\WINDOWS\ieyy32.exe
O4 - HKLM\..\RunOnce: [ntzh.exe] C:\WINDOWS\system32\ntzh.exe
O4 - HKLM\..\RunOnce: [mshu.exe] C:\WINDOWS\system32\mshu.exe
O4 - HKLM\..\RunOnce: [crzt.exe] C:\WINDOWS\crzt.exe
O4 - HKLM\..\RunOnce: [mshw32.exe] C:\WINDOWS\system32\mshw32.exe
O4 - HKLM\..\RunOnce: [ipwv32.exe] C:\WINDOWS\ipwv32.exe
O4 - HKLM\..\RunOnce: [cryn32.exe] C:\WINDOWS\cryn32.exe
O4 - HKLM\..\RunOnce: [winhi32.exe] C:\WINDOWS\winhi32.exe
O4 - HKLM\..\RunOnce: [javakt.exe] C:\WINDOWS\system32\javakt.exe
O4 - HKLM\..\RunOnce: [mfcnl32.exe] C:\WINDOWS\system32\mfcnl32.exe
O4 - HKLM\..\RunOnce: [ielj.exe] C:\WINDOWS\ielj.exe
O4 - HKLM\..\RunOnce: [apprv.exe] C:\WINDOWS\system32\apprv.exe
O4 - HKLM\..\RunOnce: [iecm32.exe] C:\WINDOWS\iecm32.exe
O4 - HKLM\..\RunOnce: [ipth.exe] C:\WINDOWS\ipth.exe
O4 - HKLM\..\RunOnce: [winge.exe] C:\WINDOWS\system32\winge.exe
O4 - HKLM\..\RunOnce: [ipnd32.exe] C:\WINDOWS\ipnd32.exe
O4 - HKLM\..\RunOnce: [crqv.exe] C:\WINDOWS\system32\crqv.exe
O4 - HKLM\..\RunOnce: [addra32.exe] C:\WINDOWS\system32\addra32.exe
O4 - HKLM\..\RunOnce: [javasl32.exe] C:\WINDOWS\javasl32.exe
O4 - HKLM\..\RunOnce: [mfcln.exe] C:\WINDOWS\system32\mfcln.exe
O4 - HKLM\..\RunOnce: [iprn.exe] C:\WINDOWS\system32\iprn.exe
O4 - HKLM\..\RunOnce: [javavt.exe] C:\WINDOWS\javavt.exe
O4 - HKLM\..\RunOnce: [sysck.exe] C:\WINDOWS\sysck.exe
O4 - HKLM\..\RunOnce: [ntzv.exe] C:\WINDOWS\ntzv.exe
O4 - HKLM\..\RunOnce: [netav32.exe] C:\WINDOWS\system32\netav32.exe
O4 - HKLM\..\RunOnce: [winuz32.exe] C:\WINDOWS\system32\winuz32.exe
O4 - HKLM\..\RunOnce: [sysrx.exe] C:\WINDOWS\sysrx.exe
O4 - HKLM\..\RunOnce: [syspo.exe] C:\WINDOWS\system32\syspo.exe
O4 - HKLM\..\RunOnce: [ieoj32.exe] C:\WINDOWS\system32\ieoj32.exe
O4 - HKLM\..\RunOnce: [mfczs32.exe] C:\WINDOWS\system32\mfczs32.exe
O4 - HKLM\..\RunOnce: [mfczv.exe] C:\WINDOWS\system32\mfczv.exe
O4 - HKLM\..\RunOnce: [addya.exe] C:\WINDOWS\system32\addya.exe
O4 - HKLM\..\RunOnce: [javand32.exe] C:\WINDOWS\system32\javand32.exe
O4 - HKLM\..\RunOnce: [sysgb.exe] C:\WINDOWS\sysgb.exe
O4 - HKLM\..\RunOnce: [syswb.exe] C:\WINDOWS\syswb.exe
O4 - HKLM\..\RunOnce: [javaur32.exe] C:\WINDOWS\system32\javaur32.exe
O4 - HKLM\..\RunOnce: [ntqa.exe] C:\WINDOWS\ntqa.exe
O4 - HKLM\..\RunOnce: [msue.exe] C:\WINDOWS\msue.exe
O4 - HKLM\..\RunOnce: [appyo.exe] C:\WINDOWS\appyo.exe
O4 - HKLM\..\RunOnce: [netrn.exe] C:\WINDOWS\netrn.exe
O4 - HKLM\..\RunOnce: [ipcy32.exe] C:\WINDOWS\system32\ipcy32.exe
O4 - HKLM\..\RunOnce: [atlbl32.exe] C:\WINDOWS\atlbl32.exe
O4 - HKLM\..\RunOnce: [msav.exe] C:\WINDOWS\msav.exe
O4 - HKLM\..\RunOnce: [apizp32.exe] C:\WINDOWS\apizp32.exe
O4 - HKLM\..\RunOnce: [sdkzg32.exe] C:\WINDOWS\system32\sdkzg32.exe
O4 - HKLM\..\RunOnce: [d3ne.exe] C:\WINDOWS\d3ne.exe
O4 - HKLM\..\RunOnce: [mstb32.exe] C:\WINDOWS\mstb32.exe
O4 - HKLM\..\RunOnce: [sdkqd.exe] C:\WINDOWS\system32\sdkqd.exe
O4 - HKLM\..\RunOnce: [sdkwz.exe] C:\WINDOWS\system32\sdkwz.exe
O4 - HKLM\..\RunOnce: [iplo.exe] C:\WINDOWS\system32\iplo.exe
O4 - HKLM\..\RunOnce: [crcb.exe] C:\WINDOWS\system32\crcb.exe
O4 - HKLM\..\RunOnce: [winko.exe] C:\WINDOWS\system32\winko.exe
O4 - HKLM\..\RunOnce: [apipq.exe] C:\WINDOWS\apipq.exe
O4 - HKLM\..\RunOnce: [ntfx32.exe] C:\WINDOWS\ntfx32.exe
O4 - HKLM\..\RunOnce: [ipzl32.exe] C:\WINDOWS\system32\ipzl32.exe
O4 - HKLM\..\RunOnce: [netjh.exe] C:\WINDOWS\netjh.exe
O4 - HKLM\..\RunOnce: [crru.exe] C:\WINDOWS\crru.exe
O4 - HKLM\..\RunOnce: [javanj.exe] C:\WINDOWS\system32\javanj.exe
O4 - HKLM\..\RunOnce: [appgr32.exe] C:\WINDOWS\system32\appgr32.exe
O4 - HKLM\..\RunOnce: [winlc.exe] C:\WINDOWS\winlc.exe
O4 - HKLM\..\RunOnce: [mfccj32.exe] C:\WINDOWS\mfccj32.exe
O4 - HKLM\..\RunOnce: [crkc32.exe] C:\WINDOWS\system32\crkc32.exe
O4 - HKLM\..\RunOnce: [netxe.exe] C:\WINDOWS\system32\netxe.exe
O4 - HKLM\..\RunOnce: [apipg32.exe] C:\WINDOWS\system32\apipg32.exe
O4 - HKLM\..\RunOnce: [crhk32.exe] C:\WINDOWS\crhk32.exe
O4 - HKLM\..\RunOnce: [winrl32.exe] C:\WINDOWS\system32\winrl32.exe
O4 - HKLM\..\RunOnce: [crwf32.exe] C:\WINDOWS\system32\crwf32.exe
O4 - HKLM\..\RunOnce: [syskn.exe] C:\WINDOWS\syskn.exe
O4 - HKLM\..\RunOnce: [nettt32.exe] C:\WINDOWS\system32\nettt32.exe
O4 - HKLM\..\RunOnce: [msph.exe] C:\WINDOWS\msph.exe
O4 - HKLM\..\RunOnce: [apiiq.exe] C:\WINDOWS\system32\apiiq.exe
O4 - HKLM\..\RunOnce: [ipjb.exe] C:\WINDOWS\system32\ipjb.exe
O4 - HKLM\..\RunOnce: [apicc32.exe] C:\WINDOWS\system32\apicc32.exe
O4 - HKLM\..\RunOnce: [apprt32.exe] C:\WINDOWS\system32\apprt32.exe
O4 - HKLM\..\RunOnce: [winpm.exe] C:\WINDOWS\system32\winpm.exe
O4 - HKLM\..\RunOnce: [msuw32.exe] C:\WINDOWS\msuw32.exe
O4 - HKLM\..\RunOnce: [nthg32.exe] C:\WINDOWS\system32\nthg32.exe
O4 - HKLM\..\RunOnce: [sdknu.exe] C:\WINDOWS\system32\sdknu.exe
O4 - HKLM\..\RunOnce: [winwb32.exe] C:\WINDOWS\system32\winwb32.exe
O4 - HKLM\..\RunOnce: [netgp32.exe] C:\WINDOWS\system32\netgp32.exe
O4 - HKLM\..\RunOnce: [javaec.exe] C:\WINDOWS\system32\javaec.exe
O4 - HKLM\..\RunOnce: [crsf32.exe] C:\WINDOWS\system32\crsf32.exe
O4 - HKLM\..\RunOnce: [winlp32.exe] C:\WINDOWS\system32\winlp32.exe
O4 - HKLM\..\RunOnce: [ntss32.exe] C:\WINDOWS\ntss32.exe
O4 - HKLM\..\RunOnce: [mfcwl32.exe] C:\WINDOWS\mfcwl32.exe
O4 - HKLM\..\RunOnce: [iekn.exe] C:\WINDOWS\system32\iekn.exe
O4 - HKLM\..\RunOnce: [apiqe.exe] C:\WINDOWS\system32\apiqe.exe
O4 - HKLM\..\RunOnce: [winvy32.exe] C:\WINDOWS\system32\winvy32.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Microsoft.hta
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Read By Natural Voice Reader - C:\Program Files\NaturalReaders\Natural Voice Reader Free\read.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: Natural Reader - {0DF757C4-9999-463C-A4EB-B6BF1D8D8D3D} - C:\Program Files\NaturalReaders\Natural Voice Reader Free\read.html
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\cdlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cdlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cdlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\inetadpt.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\inetadpt.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\inetadpt.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\inetadpt.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cdlsp.dll
O16 - DPF: Yahoo! Blackjack - http://download.game...nts/y/jt0_x.cab
O16 - DPF: Yahoo! Checkers - http://download.game...nts/y/kt3_x.cab
O16 - DPF: Yahoo! Chess - http://download.game...nts/y/ct2_x.cab
O16 - DPF: Yahoo! Chinese Checkers - http://download.game...ts/y/cct0_x.cab
O16 - DPF: Yahoo! Freecell Solitaire - http://yog55.games.s...og/y/fs10_x.cab
O16 - DPF: Yahoo! Literati - http://download.game...nts/y/tt3_x.cab
O16 - DPF: Yahoo! MahJong - http://download.game...nts/y/ot0_x.cab
O16 - DPF: Yahoo! MahJong Solitaire - http://download.game...s/y/mjst4_x.cab
O16 - DPF: Yahoo! Poker - http://download.game...nts/y/pt1_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.game...ts/y/potd_x.cab
O16 - DPF: Yahoo! Pyramids - http://download.game...ts/y/pyt1_x.cab
O16 - DPF: Yahoo! Reversi - http://download.game...nts/y/rt0_x.cab
O16 - DPF: Yahoo! Spelldown - http://download.game...ts/y/sdt1_x.cab
O16 - DPF: Yahoo! Towers 2.0 - http://download.game...ts/y/ywt0_x.cab
O16 - DPF: Yahoo! Word Racer - http://download.game...nts/y/wt1_x.cab
O16 - DPF: {1471EAED-278A-4777-8803-CFFEE82A00A8} - http://micronetclub....3dx/3daplyr.CAB
O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} (CoGSManager Class) - http://gamingzone.ub...s/GSManager.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by17fd.bay17....es/MsnPUpld.cab
O18 - Protocol: relatedlinks - {CD8D1CAA-FE4A-45DF-A06C-028AAF1821DE} - (no file)
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\appwl32.exe
O23 - Service: AVP Control Centre Service (AVPCC) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\avpcc.exe" /Service (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: KAV Monitor Service (KAVMonitorService) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\avpm.exe" /Service (file missing)
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe