AboutBuster 5.0 reference file 31
Scan started on [8/23/2005] at [6:23:02 PM]
------------------------------------------------
Removed Stream! C:\WINDOWS\aixse.txt:hbbsr
Removed Stream! C:\WINDOWS\auigv.log:lsemfl
Removed Stream! C:\WINDOWS\bootstat.dat:hnlagg
Removed Stream! C:\WINDOWS\cmsetacl.log:kqhqwd
Removed Stream! C:\WINDOWS\cnats.dat:vngjz
Removed Stream! C:\WINDOWS\COM+.log:ucitr
Removed Stream! C:\WINDOWS\CTDV10K2.CDF:ghjcv
Removed Stream! C:\WINDOWS\DHCPUPG.LOG:pbtawc
Removed Stream! C:\WINDOWS\DirectX.log:ricjx
Removed Stream! C:\WINDOWS\dvkbp.dat:sybrt
Removed Stream! C:\WINDOWS\exdfp.log:wkjtmu
Removed Stream! C:\WINDOWS\FaxSetup.log:iegfk
Removed Stream! C:\WINDOWS\Finding Nemo.scr:suflto
Removed Stream! C:\WINDOWS\GEARInstall.log:heulao
Removed Stream! C:\WINDOWS\GEARInstall.log:houblk
Removed Stream! C:\WINDOWS\Greenstone.bmp:refqcr
Removed Stream! C:\WINDOWS\hphmdl01.dat:sqxthx
Removed Stream! C:\WINDOWS\hpimdl01.dat:vtjbfw
Removed Stream! C:\WINDOWS\hpimdl01.dat.temp:krpzci
Removed Stream! C:\WINDOWS\hpoins03.dat:ixowvc
Removed Stream! C:\WINDOWS\hpqins01.dat:kosfgn
Removed Stream! C:\WINDOWS\hpqins01.dat:zioxl
Removed Stream! C:\WINDOWS\hpzmdl01.dat:scbiw
Removed Stream! C:\WINDOWS\hydys.dat:hrkmm
Removed Stream! C:\WINDOWS\Iedit.INI:qiwzpd
Removed Stream! C:\WINDOWS\Iedit.INI:sahkoi
Removed Stream! C:\WINDOWS\itvpj.txt:vckvkd
Removed Stream! C:\WINDOWS\jhztx.txt:makuib
Removed Stream! C:\WINDOWS\jtxag.dat:erdoxs
Removed Stream! C:\WINDOWS\jvahy.dat:eachcm
Removed Stream! C:\WINDOWS\jvahy.dat:ndcief
Removed Stream! C:\WINDOWS\KB810217.log:xsnbrc
Removed Stream! C:\WINDOWS\KB821431.log:byhjmg
Removed Stream! C:\WINDOWS\KB823182.log:nqodxl
Removed Stream! C:\WINDOWS\KB823387.log:ptghtn
Removed Stream! C:\WINDOWS\KB824105.log:lcsxgb
Removed Stream! C:\WINDOWS\KB824105.log:pqzaue
Removed Stream! C:\WINDOWS\KB826939.log:almmkj
Removed Stream! C:\WINDOWS\KB826939.log:ddccil
Removed Stream! C:\WINDOWS\KB828028.log:srclqr
Removed Stream! C:\WINDOWS\KB830786.log:ksvykb
Removed Stream! C:\WINDOWS\KB832418.log:cnpfgw
Removed Stream! C:\WINDOWS\KB835221.log:voikih
Removed Stream! C:\WINDOWS\KB885835.log:xwldzq
Removed Stream! C:\WINDOWS\KB885836.log:wtmlw
Removed Stream! C:\WINDOWS\KB887742.log:oeglsa
Removed Stream! C:\WINDOWS\KB888113.log:mgoqw
Removed Stream! C:\WINDOWS\KB891781.log:sgcjjx
Removed Stream! C:\WINDOWS\KB891781.log:zeyvph
Removed Stream! C:\WINDOWS\KB893803.log:khvolh
Removed Stream! C:\WINDOWS\KB894391.log:kfbglu
Removed Stream! C:\WINDOWS\KB896358.log:znxpnb
Removed Stream! C:\WINDOWS\KB896428.log:cgtlff
Removed Stream! C:\WINDOWS\KB898461.log:jpihcn
Removed Stream! C:\WINDOWS\KB899591.log:cisney
Removed Stream! C:\WINDOWS\kusbb.txt:scfpdg
Removed Stream! C:\WINDOWS\kvzrf.txt:xyxngw
Removed Stream! C:\WINDOWS\lnfnm.dat:hzjycj
Removed Stream! C:\WINDOWS\LUINSTALL.LOG:astdet
Removed Stream! C:\WINDOWS\lzsyz.log:wwbftd
Removed Stream! C:\WINDOWS\miqvk.log:yeifk
Removed Stream! C:\WINDOWS\msdfmap.ini:ghmpx
Removed Stream! C:\WINDOWS\msmqinst.log:skiusa
Removed Stream! C:\WINDOWS\npbam.log:gifrga
Removed Stream! C:\WINDOWS\nsw.log:vcheyk
Removed Stream! C:\WINDOWS\ntdtcsetup.log:zjpwal
Removed Stream! C:\WINDOWS\OEWABLog.txt:kkahwy
Removed Stream! C:\WINDOWS\pkbcn.txt:irmwv
Removed Stream! C:\WINDOWS\Q327979.log:zztjn
Removed Stream! C:\WINDOWS\Q329112.log:mzjdcu
Removed Stream! C:\WINDOWS\q329256.log:tuyafu
Removed Stream! C:\WINDOWS\Q331958.log:zsvmg
Removed Stream! C:\WINDOWS\Q811789.log:eojsbh
Removed Stream! C:\WINDOWS\Q814995.log:pcfbbs
Removed Stream! C:\WINDOWS\Q817287.log:xpuyws
Removed Stream! C:\WINDOWS\Q822688.log:icqgvc
Removed Stream! C:\WINDOWS\qlfdx.txt:ionnbg
Removed Stream! C:\WINDOWS\rbfmm.txt:lqqgxs
Removed Stream! C:\WINDOWS\revah.dat:eqjlrd
Removed Stream! C:\WINDOWS\SBWIN.INI:dqlnkq
Removed Stream! C:\WINDOWS\setuperr.log:oswfhd
Removed Stream! C:\WINDOWS\setuplog.txt:llfgl
Removed Stream! C:\WINDOWS\sntgl.txt:bvfrh
Removed Stream! C:\WINDOWS\svcpack.log:ufsimb
Removed Stream! C:\WINDOWS\SYMEVENT.LOG:ajlvll
Removed Stream! C:\WINDOWS\system.ini:uhncxx
Removed Stream! C:\WINDOWS\tniot.txt:fgvajo
Removed Stream! C:\WINDOWS\tniot.txt:rtynxi
Removed Stream! C:\WINDOWS\tsoc.log:fjqvuk
Removed Stream! C:\WINDOWS\tuyaf.dat:xhngdy
Removed Stream! C:\WINDOWS\uciwj.dat:yjjaov
Removed Stream! C:\WINDOWS\updspapi.log:cuqsas
Removed Stream! C:\WINDOWS\UPGRADE.TXT:lloozg
Removed Stream! C:\WINDOWS\vb.ini:jtnrfv
Removed Stream! C:\WINDOWS\vbaddin.ini:unbgud
Removed Stream! C:\WINDOWS\vjgqv.log:lsnkfp
Removed Stream! C:\WINDOWS\vmuninst.log:vbqvk
Removed Stream! C:\WINDOWS\vvqom.log:lgawup
Removed Stream! C:\WINDOWS\wiaservc.log:umzjbi
Removed Stream! C:\WINDOWS\win.ini:kxicld
Removed Stream! C:\WINDOWS\win.ini:ouiiwm
Removed Stream! C:\WINDOWS\WindowsUpdate.log:mlsgw
Removed Stream! C:\WINDOWS\WINNT32.LOG:vqtvhq
Removed Stream! C:\WINDOWS\winsx.inf:xtspp
Removed Stream! C:\WINDOWS\wmsetup10.log:greaba
Removed Stream! C:\WINDOWS\wsdu.log:hmynul
Removed Stream! C:\WINDOWS\xcozo.dat:qwnvwm
Removed Stream! C:\WINDOWS\xwnab.txt:coypqh
Removed Stream! C:\WINDOWS\Zapotec.bmp:snbgqy
------------------------------------------------
Removed File! : C:\Windows\bflsk.dat
Removed File! : C:\Windows\cnats.dat
Removed File! : C:\Windows\drpvo.dat
Removed File! : C:\Windows\hvzgv.dat
Removed File! : C:\Windows\inlxw.dat
Removed File! : C:\Windows\jtxag.dat
Removed File! : C:\Windows\karqr.dat
Removed File! : C:\Windows\nfuxs.dat
Removed File! : C:\Windows\ngkpi.dat
Removed File! : C:\Windows\qqkao.dat
Removed File! : C:\Windows\rnwdy.dat
Removed File! : C:\Windows\sprub.dll
Removed File! : C:\Windows\tuyaf.dat
Removed File! : C:\Windows\tykdn.dat
Removed File! : C:\Windows\udqfa.dat
Removed File! : C:\Windows\zccpw.dat
Removed File! : C:\Windows\zzkuc.dat
Removed File! : C:\Windows\System32\ahzzc.dat
Removed File! : C:\Windows\System32\aofmu.dat
Removed File! : C:\Windows\System32\bcqro.dat
Removed File! : C:\Windows\System32\byhjm.dat
Removed File! : C:\Windows\System32\ddqxq.dat
Removed File! : C:\Windows\System32\djndt.dat
Removed File! : C:\Windows\System32\dyhbq.dat
Removed File! : C:\Windows\System32\dzrem.dat
Removed File! : C:\Windows\System32\fknwp.dat
Removed File! : C:\Windows\System32\jsapw.dat
Removed File! : C:\Windows\System32\lwerk.dat
Removed File! : C:\Windows\System32\mldpm.dat
Removed File! : C:\Windows\System32\myhvz.dat
Removed File! : C:\Windows\System32\pggjd.dat
Removed File! : C:\Windows\System32\poskv.dat
Removed File! : C:\Windows\System32\puuzs.dat
Removed File! : C:\Windows\System32\svpps.dat
Removed File! : C:\Windows\System32\takdg.dat
Removed File! : C:\Windows\System32\uskfo.dat
Removed File! : C:\Windows\System32\vinzp.dat
Removed File! : C:\Windows\System32\yjfqm.dat
Removed File! : C:\Windows\System32\ytvtg.dat
Removed File! : C:\Windows\System32\yxoet.dat
Removed File! : C:\Windows\System32\zlfdb.dat
------------------------------------------------
Scan was COMPLETED SUCCESSFULLY at 6:24:13 PM
AboutBuster 5.0 reference file 31
Scan started on [8/23/2005] at [6:26:43 PM]
------------------------------------------------
Removed Stream! C:\WINDOWS\COM+.log:uqadzo
Removed Stream! C:\WINDOWS\KB885836.log:xvkjh
Removed Stream! C:\WINDOWS\sntgl.txt:htgljn
Removed Stream! C:\WINDOWS\UPGRADE.TXT:tfirrn
------------------------------------------------
No Files Found!
------------------------------------------------
Scan was COMPLETED SUCCESSFULLY at 6:27:44 PM
AboutBuster 5.0 reference file 31
Scan started on [8/27/2005] at [6:16:55 AM]
------------------------------------------------
Removed Stream! C:\WINDOWS\AC3API.INI:xrwhb
Removed Stream! C:\WINDOWS\aixse.txt:bbndp
Removed Stream! C:\WINDOWS\aucfg.ini:xgohi
Removed Stream! C:\WINDOWS\AuHCcup1.ini:yvkro
Removed Stream! C:\WINDOWS\bouvi.txt:eyqgj
Removed Stream! C:\WINDOWS\bxexc.dat:uuenmc
Removed Stream! C:\WINDOWS\cfqnd.log:mknbe
Removed Stream! C:\WINDOWS\drmyg.txt:drkxjp
Removed Stream! C:\WINDOWS\DtcInstall.log:rsgnl
Removed Stream! C:\WINDOWS\dvkbp.dat:ddrka
Removed Stream! C:\WINDOWS\eimve.log:zgkzbu
Removed Stream! C:\WINDOWS\FaxSetup.log:lgwof
Removed Stream! C:\WINDOWS\GEARInstall.log:zzixgv
Removed Stream! C:\WINDOWS\hpdins01.dat:ytvxxh
Removed Stream! C:\WINDOWS\hpimdl01.dat.temp:jkowua
Removed Stream! C:\WINDOWS\hpomdl03.dat:juyhuu
Removed Stream! C:\WINDOWS\hrkuo.log:cnqnoe
Removed Stream! C:\WINDOWS\hteto.log:udsoqv
Removed Stream! C:\WINDOWS\igjaw.txt:nekusx
Removed Stream! C:\WINDOWS\inlxw.dat:laljo
Removed Stream! C:\WINDOWS\iskps.log:fvdse
Removed Stream! C:\WINDOWS\ivwsm.log:hsimeb
Removed Stream! C:\WINDOWS\izzsj.dat:lkdnpm
Removed Stream! C:\WINDOWS\jepqp.log:ztsrhm
Removed Stream! C:\WINDOWS\jhztx.txt:laiaw
Removed Stream! C:\WINDOWS\jpzyy.dat:sllfbo
Removed Stream! C:\WINDOWS\KB828028.log:vnoqww
Removed Stream! C:\WINDOWS\KB832418.log:ghutd
Removed Stream! C:\WINDOWS\KB867282.log:fizkt
Removed Stream! C:\WINDOWS\KB890859.log:srvpn
Removed Stream! C:\WINDOWS\KB896358.log:jyjyfj
Removed Stream! C:\WINDOWS\KB899587.log:wrtpy
Removed Stream! C:\WINDOWS\KB899591.log:xxdyi
Removed Stream! C:\WINDOWS\mozver.dat:ilwwe
Removed Stream! C:\WINDOWS\mzgft.log:iwldog
Removed Stream! C:\WINDOWS\nsw.log:mogop
Removed Stream! C:\WINDOWS\ODBC.INI:jjwfob
Removed Stream! C:\WINDOWS\orun32.ini:ilmag
Removed Stream! C:\WINDOWS\Q327979.log:ltulm
Removed Stream! C:\WINDOWS\Q329112.log:imnar
Removed Stream! C:\WINDOWS\rlxiv.dat:mthvl
Removed Stream! C:\WINDOWS\setuperr.log:joxkho
Removed Stream! C:\WINDOWS\Soap Bubbles.bmp:upaudb
Removed Stream! C:\WINDOWS\Sti_Trace.log:ztjnbu
Removed Stream! C:\WINDOWS\surmd.txt:mqtagm
Removed Stream! C:\WINDOWS\tabletoc.log:hazqkf
Removed Stream! C:\WINDOWS\tkrpz.dat:vlpaop
Removed Stream! C:\WINDOWS\tlvio.txt:ofzfi
Removed Stream! C:\WINDOWS\tniot.txt:ekqglo
Removed Stream! C:\WINDOWS\tpajl.dat:twowm
Removed Stream! C:\WINDOWS\vmuninst.log:tsdtjp
Removed Stream! C:\WINDOWS\vsypw.dat:ltwgms
Removed Stream! C:\WINDOWS\wininit.ini:qnpkv
Removed Stream! C:\WINDOWS\wmsetup.log:nkuui
Removed Stream! C:\WINDOWS\xcozo.dat:bfxio
Removed Stream! C:\WINDOWS\xfowb.txt:bbfzuf
Removed Stream! C:\WINDOWS\zcnpw.txt:dxqnj
------------------------------------------------
Removed File! : C:\Windows\apzcc.dll
Removed File! : C:\Windows\bxexc.dat
Removed File! : C:\Windows\cnssm.dll
Removed File! : C:\Windows\dhntn.dll
Removed File! : C:\Windows\ftghl.dll
Removed File! : C:\Windows\gnhaw.dll
Removed File! : C:\Windows\nitkb.dat
Removed File! : C:\Windows\nvtpv.dat
Removed File! : C:\Windows\qpccx.dll
Removed File! : C:\Windows\rdyeq.dat
Removed File! : C:\Windows\rsyit.dll
Removed File! : C:\Windows\snqmh.dat
Removed File! : C:\Windows\ujyql.dll
Removed File! : C:\Windows\vplkf.dat
Removed File! : C:\Windows\yjmyu.dat
Removed File! : C:\Windows\zjecn.dat
Removed File! : C:\Windows\System32\btmvj.dll
Removed File! : C:\Windows\System32\cxuya.dll
Removed File! : C:\Windows\System32\jqasg.dat
Removed File! : C:\Windows\System32\kpnkg.dll
Removed File! : C:\Windows\System32\ojihg.dll
Removed File! : C:\Windows\System32\oxkho.dll
Removed File! : C:\Windows\System32\qpyvp.dll
Removed File! : C:\Windows\System32\rtzto.dat
Removed File! : C:\Windows\System32\tmsji.dll
Removed File! : C:\Windows\System32\vdeyc.dll
Removed File! : C:\Windows\System32\wjdgr.dat
Removed File! : C:\Windows\System32\ztauq.dll
------------------------------------------------
Scan was COMPLETED SUCCESSFULLY at 6:18:20 AM
AboutBuster 5.0 reference file 31
Scan started on [8/27/2005] at [6:20:38 AM]
------------------------------------------------
Removed Stream! C:\WINDOWS\jhztx.txt:qndrs
Removed Stream! C:\WINDOWS\ODBC.INI:puwfe
Removed Stream! C:\WINDOWS\orun32.ini:nmbim
Removed Stream! C:\WINDOWS\Q327979.log:zinmd
------------------------------------------------
No Files Found!
------------------------------------------------
Scan was COMPLETED SUCCESSFULLY at 6:21:55 AM
-----------------------------------------------------------------------------------------------
--- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- ---
-----------------------------------------------------------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 6:25:30 AM, on 8/27/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\appew.exe
C:\WINDOWS\System32\CTSvcCDA.EXE
C:\WINDOWS\ehome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\System32\hphmon05.exe
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\intell32.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\System32\imapi.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\hjt\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\nmrbp.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\nmrbp.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\nmrbp.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\nmrbp.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\nmrbp.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\nmrbp.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Class - {F831BBBD-4EFD-0AD2-5B57-0067ABE2F1DD} - C:\WINDOWS\system32\mfcao.dll
O2 - BHO: Class - {FEF22621-9874-CE5F-4F45-E119822E35B8} - C:\WINDOWS\javaxi32.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [CTDVDDET] C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\Run: [winct.exe] C:\WINDOWS\system32\winct.exe
O4 - HKLM\..\Run: [mfcpv.exe] C:\WINDOWS\mfcpv.exe
O4 - HKLM\..\Run: [d3np32.exe] C:\WINDOWS\system32\d3np32.exe
O4 - HKLM\..\Run: [sdktu.exe] C:\WINDOWS\sdktu.exe
O4 - HKLM\..\Run: [intell32.exe] C:\WINDOWS\system32\intell32.exe
O4 - HKLM\..\Run: [PSGuard] C:\Program Files\PSGuard\PSGuard.exe
O4 - HKLM\..\Run: [appew.exe] C:\WINDOWS\appew.exe
O4 - HKLM\..\RunOnce: [netqd32.exe] C:\WINDOWS\system32\netqd32.exe
O4 - HKLM\..\RunOnce: [crib32.exe] C:\WINDOWS\crib32.exe
O4 - HKLM\..\RunOnce: [sysho.exe] C:\WINDOWS\sysho.exe
O4 - HKLM\..\RunOnce: [cran32.exe] C:\WINDOWS\cran32.exe
O4 - HKLM\..\RunOnce: [javamb.exe] C:\WINDOWS\system32\javamb.exe
O4 - HKLM\..\RunOnce: [apifr32.exe] C:\WINDOWS\apifr32.exe
O4 - HKLM\..\RunOnce: [addre32.exe] C:\WINDOWS\system32\addre32.exe
O4 - HKLM\..\RunOnce: [ietx32.exe] C:\WINDOWS\system32\ietx32.exe
O4 - HKLM\..\RunOnce: [creb32.exe] C:\WINDOWS\creb32.exe
O4 - HKLM\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe
O4 - HKLM\..\RunOnce: [sysrb.exe] C:\WINDOWS\system32\sysrb.exe
O4 - HKLM\..\RunOnce: [sysps.exe] C:\WINDOWS\sysps.exe
O4 - HKLM\..\RunOnce: [mfcyf.exe] C:\WINDOWS\mfcyf.exe
O4 - HKLM\..\RunOnce: [iexm32.exe] C:\WINDOWS\iexm32.exe
O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe
O4 - HKCU\..\Run: [Acme.PCHButton] C:\PROGRA~1\HPINST~1\Pavilion\XPENABS4EN\plugin\bin\pchbutton.exe
O4 - HKCU\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} -
http://static.windup...bridge-c282.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204O16 - DPF: {22A88341-AFCB-45F0-A856-C2BAE74F878E} (InstallX Class) -
http://www.20x2p.com...5e012/enter.cabO16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) -
http://photo.walgree...eensActivia.cabO16 - DPF: {6C6FE41A-0DA6-42A1-9AD8-792026B2B2A7} (FreeCell Control) -
http://www.worldwinn...ll/freecell.cabO16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai...all/xscan53.cabO16 - DPF: {7C559105-9ECF-42B8-B3F7-832E75EDD959} (Installer Class) -
http://www.xxxtoolba...006_regular.cabO16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) -
http://www.worldwinn...ed/wwlaunch.cabO16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} (WordMojo Control) -
http://www.worldwinn...jo/wordmojo.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn...pDownloader.cabO16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) -
http://www.live365.c...ers/play365.cabO16 - DPF: {D1ACD2D8-7312-4D06-BECD-90EB094D2277} -
http://mediaplayer.w...ler/install.cabO16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -
http://download.game...aploader_v5.cabO16 - DPF: {E93A6FCA-C052-45DF-AC9B-B729066092F8} (Util Class) -
https://isupport4.hp...her/MotUtil.cabO20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\netqd32.exe" /s (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTSvcCDA.EXE
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe