I have major malware issues on a Windows 2000 machine. My hijackthis log is below. I have a feeling all of the R1 categories can be erased and alot of the .dll files in the O2 categories need to be erased. I just don't know much about Win2k and don't want to delete anything critical. Thanks in advance for the help.
Logfile of HijackThis v1.99.1
Scan saved at 2:36:15 PM, on 11/30/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\winnt\System32\smss.exe
C:\winnt\system32\winlogon.exe
C:\winnt\system32\services.exe
C:\winnt\system32\lsass.exe
C:\winnt\system32\svchost.exe
C:\winnt\system32\spoolsv.exe
C:\winnt\system32\ntof32.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\winnt\system32\mgabg.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\winnt\system32\regsvc.exe
C:\winnt\system32\MSTask.exe
C:\winnt\system32\stisvc.exe
C:\winnt\System32\WBEM\WinMgmt.exe
C:\winnt\system32\svchost.exe
C:\winnt\Explorer.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINNT\system32\PDesk\PDesk.exe
C:\Program Files\QuickTime\qttask.exe
C:\winnt\system32\iegp32.exe
C:\Program Files\AIM\aim.exe
C:\winnt\system32\ctfmon.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Cisco\Call Manager Attendant Console\bin\ACClient.exe
C:\PROGRA~1\MICROS~2\Office10\OUTLOOK.EXE
C:\Documents and Settings\reception\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\winnt\uzwhr.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\winnt\uzwhr.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\winnt\uzwhr.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\winnt\uzwhr.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\winnt\uzwhr.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\winnt\uzwhr.dll/sp.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\winnt\uzwhr.dll/sp.html#28129
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {0151F02E-FCEA-C108-C5C6-699029066F22} - C:\winnt\system32\d3xm32.dll
O2 - BHO: Class - {05EC6A69-684D-8BE0-FDEE-2B01F30E35CF} - C:\winnt\system32\d3zx32.dll
O2 - BHO: Class - {061F4600-7622-35F3-F6BE-7313A603238F} - C:\winnt\system32\creq32.dll
O2 - BHO: Class - {06247722-C17F-E0E6-9078-6F4CF007B78A} - C:\winnt\system32\sdkot.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Class - {06EA0125-4480-6233-6740-1197ADDF5152} - C:\winnt\system32\ieju.dll
O2 - BHO: Class - {091A0144-B62A-57FF-3D1E-E05A16CC50B9} - C:\winnt\system32\d3jg.dll
O2 - BHO: Class - {0D6035B9-99FF-7CC5-D27E-52A6827CD9AA} - C:\winnt\syslu32.dll
O2 - BHO: Class - {11A38C5E-4FF9-B6BE-7B32-10FCBAC74EE3} - C:\winnt\ipfv.dll
O2 - BHO: Class - {13D33DA3-6A3B-5C51-A2E2-7685449EFCA2} - C:\winnt\system32\appty32.dll
O2 - BHO: Class - {1491454F-5064-E19C-58F7-204E07DB4C97} - C:\winnt\msmv32.dll
O2 - BHO: (no name) - {149C875D-61DC-6453-2883-DD1C7FC427B1} - C:\winnt\mfcnz.dll
O2 - BHO: Class - {149CF3EA-AF53-4656-DF77-321F18DF8C5A} - C:\winnt\sdkfi32.dll
O2 - BHO: Class - {1BA65E69-881B-8800-58BF-210B32EDB04F} - C:\winnt\system32\mfcnj32.dll
O2 - BHO: Class - {1DEDD482-EBB7-4CC6-3673-6BD821E65751} - C:\winnt\apptt.dll
O2 - BHO: Class - {1EB9B628-5CFC-F3C2-044F-3B45FC995C80} - C:\winnt\system32\sysiy.dll
O2 - BHO: Class - {22CD8DF6-43B9-AA2F-B5A0-55C130D6EB64} - C:\winnt\system32\ipzd.dll
O2 - BHO: Class - {2366C71F-D625-50AB-41C3-B6ECE563B80E} - C:\winnt\crcv.dll
O2 - BHO: Class - {241E7EFE-1EE9-818D-B49E-DA5F26391034} - C:\winnt\system32\javafk32.dll
O2 - BHO: Class - {24FD92CB-568C-0CF4-6D27-5CE42601B9E3} - C:\winnt\sdkey.dll
O2 - BHO: (no name) - {25937398-4EB7-0591-56C9-A5E60E3D0D4B} - C:\winnt\system32\mfcmy32.dll
O2 - BHO: Class - {25A230CD-675B-C47F-FF73-DFD6F3935B55} - C:\winnt\winlr.dll
O2 - BHO: Class - {2C7D9206-EDAA-D789-CF05-F765683F27E6} - C:\winnt\atlsc.dll
O2 - BHO: Class - {2CB7E8D2-8A51-29D3-4936-BDA74E112CBA} - C:\winnt\system32\msae.dll
O2 - BHO: Class - {2CF4A72C-8292-5365-15FE-14567DCA1A35} - C:\winnt\sysgx32.dll
O2 - BHO: Class - {2D5FEA89-1F56-91C7-3865-6AA3C7397AA0} - C:\winnt\system32\atlhy.dll
O2 - BHO: Class - {2FA3BFDF-DF5F-8BD2-D8F5-CDCEB8480F0F} - C:\winnt\system32\iegp32.dll (file missing)
O2 - BHO: Class - {2FEB92FD-BAD2-394E-34AC-A46E88F0D846} - C:\winnt\netai32.dll
O2 - BHO: Class - {312D51F0-4BE1-0339-5E41-2089AB9EFDD2} - C:\winnt\ieux.dll
O2 - BHO: Class - {317116EF-853C-9261-FA5B-DC8BBEB4EFE2} - C:\winnt\javael.dll
O2 - BHO: Class - {335C75D0-9CD2-4992-B77F-CC150B7E5C6A} - C:\winnt\system32\netug32.dll
O2 - BHO: Class - {347626D3-A5F3-9AB0-A4A7-C36A8E595766} - C:\winnt\system32\netue.dll
O2 - BHO: Class - {353D04C8-A19B-A4F5-EF26-4ECE686C737F} - C:\winnt\mfcvm.dll
O2 - BHO: (no name) - {359277C5-1C2D-19B3-0C3F-12480FD7B869} - C:\winnt\ntyy32.dll (file missing)
O2 - BHO: Class - {39877125-B379-33C8-470D-6BD25A1804FA} - C:\winnt\netdr.dll
O2 - BHO: Class - {3BB026D2-8759-F801-285B-E44EF1C5F193} - C:\winnt\system32\mfcqg32.dll
O2 - BHO: Class - {3BE38BB0-E911-E13A-19E7-233C1515C1B1} - C:\winnt\system32\ntif.dll
O2 - BHO: Class - {3D1EBDDB-BC87-FB1D-7B9C-FFA47B7B74EF} - C:\winnt\system32\msao32.dll
O2 - BHO: Class - {3DEDD351-B2DC-C873-8BBB-3EDFAFEAB6D7} - C:\winnt\msbf32.dll
O2 - BHO: Class - {3E6827E7-C740-B029-DEE7-D251DD884B34} - C:\winnt\crkz32.dll
O2 - BHO: Class - {3EAAF6BD-588A-9715-5175-79D5FECCFDF5} - C:\winnt\system32\ipdb.dll
O2 - BHO: CATLEvents Object - {3EC8E271-FAB9-418a-8A8E-65AEB4029E64} - C:\DOCUME~1\TSAUCE~1\LOCALS~1\Temp\drahcm.dat (file missing)
O2 - BHO: Class - {40F71E8F-EDFA-FBFC-EE8C-05CE369D541D} - C:\winnt\atlen32.dll
O2 - BHO: Class - {41A21EE5-BFB9-5EAD-DA47-66EFF22AC6CB} - C:\winnt\mshg32.dll
O2 - BHO: Class - {41B7661D-BFFA-D3F3-4CC5-B90AF46A2FA8} - C:\winnt\system32\javahy32.dll
O2 - BHO: Class - {44521543-3C6B-A3DD-6852-0B5741963C24} - C:\winnt\system32\apiys.dll
O2 - BHO: Class - {44C0E523-5AC2-5B62-7CF1-D4088D32F80A} - C:\winnt\system32\netsv32.dll
O2 - BHO: Class - {4906F763-2030-B9BE-58D5-F80B7CC0AF48} - C:\winnt\system32\iprr.dll
O2 - BHO: Class - {4EE94F9A-AD17-CC96-69B3-E92E69E04D64} - C:\winnt\apiad.dll
O2 - BHO: Class - {4F96F696-50BA-E211-9CC1-95DD27AB7866} - C:\winnt\msbl32.dll
O2 - BHO: Class - {51A8F4CD-2343-18E1-ABD2-F00B481A116E} - C:\winnt\atlkj32.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Class - {541F1706-238F-9438-7FDD-624B31735E89} - C:\winnt\system32\iedf32.dll
O2 - BHO: (no name) - {55E43758-CF06-07C4-A21B-9E2CBB550F35} - C:\winnt\system32\mfcmy32.dll
O2 - BHO: Class - {572C939A-DAA3-83C5-9A5C-ED789C2FD487} - C:\winnt\system32\apimo.dll
O2 - BHO: Class - {5A15DDB6-655D-F522-E714-789A91C4560A} - C:\winnt\sdkqq32.dll
O2 - BHO: Class - {5ADBC662-7902-CAC4-D18A-CD699FB2A6CD} - C:\winnt\sysaj.dll
O2 - BHO: Class - {60F1B77A-C063-6009-D43A-9B05BA99FEAB} - C:\winnt\system32\sdkll32.dll
O2 - BHO: Class - {6452F9BA-199C-1DEF-E436-AC4EF1767869} - C:\winnt\atlkt32.dll
O2 - BHO: Class - {646EB617-19AA-E630-342A-9E1728181A17} - C:\winnt\apiae32.dll
O2 - BHO: Class - {64BBCA47-3F6A-4E9E-2A9A-60E143C38669} - C:\winnt\system32\javazt.dll
O2 - BHO: Class - {65D9A653-FEE7-1F32-CC4D-FA547CDA683C} - C:\winnt\addtk32.dll
O2 - BHO: Class - {66EF1A30-20AF-0B46-BD7E-CC8DE178BE2C} - C:\winnt\ield.dll
O2 - BHO: Class - {67B91E64-8EAD-2DAA-53EE-25131BEF4984} - C:\winnt\appyb.dll
O2 - BHO: Class - {6846D4B3-2846-1D3C-B92E-04404EE8991E} - C:\winnt\ipzs.dll
O2 - BHO: Class - {6A205A54-22B3-CB83-0909-47DA46EC5C08} - C:\winnt\system32\iepx.dll
O2 - BHO: Class - {6BD31BFC-D7C3-7B7E-D4A5-19B7CC0B5A31} - C:\winnt\system32\mfcmm32.dll
O2 - BHO: Class - {6E3BDCC0-A228-DCB8-7E88-ECF18F0D9B1C} - C:\winnt\system32\apigc32.dll
O2 - BHO: Class - {6F703FE9-7706-6A52-A0DA-65365E5C2A84} - C:\winnt\system32\sdklq32.dll
O2 - BHO: Class - {6F818A3E-99E0-A43B-D407-342292A76765} - C:\winnt\apijo.dll
O2 - BHO: Class - {70B77B00-7B9F-F6BD-D603-BB4B1C70AD11} - C:\winnt\system32\mfcmt.dll
O2 - BHO: (no name) - {710089CF-87C3-763F-C8F6-5A0DBFD3AEC3} - C:\winnt\mfcnz.dll
O2 - BHO: Class - {710CDC80-83EB-3168-A0CF-68EBB618A230} - C:\winnt\ntfh.dll
O2 - BHO: Class - {73BC70E6-B13D-6F72-9B7B-B4BFCC37738B} - C:\winnt\system32\ipie.dll
O2 - BHO: Class - {750A6761-6392-8539-908D-4036A50DE210} - C:\winnt\crrx.dll
O2 - BHO: Class - {766E7ABE-AB9F-7B27-4A8F-05B567E7F318} - C:\winnt\netgw.dll
O2 - BHO: Class - {76809D44-6064-3F47-3EE9-37308394C91E} - C:\winnt\d3kb32.dll
O2 - BHO: Class - {7A8D2792-764B-44F0-9F01-9B04408707F3} - C:\winnt\system32\addlp32.dll
O2 - BHO: Class - {7E1264CD-9067-6BFB-3F2A-43CE3650846E} - C:\winnt\crvk.dll
O2 - BHO: Class - {818958EB-27DC-138B-73BD-F81BDF2118D3} - C:\winnt\addfr.dll
O2 - BHO: Class - {85398450-1DF7-A898-FA64-D21BDAA43E7A} - C:\winnt\apigv.dll
O2 - BHO: Class - {853AEA0D-29B4-E70C-E805-D306EC149F9C} - C:\winnt\system32\apidg.dll
O2 - BHO: Class - {862855C2-032B-290B-772E-ED9ACA262343} - C:\winnt\javahk32.dll
O2 - BHO: Class - {869DCA1B-02CB-8C74-277D-109B01FF4795} - C:\winnt\system32\msme.dll
O2 - BHO: Class - {88BD9C13-39AD-5989-6759-E7433A121E97} - C:\winnt\ntyy32.dll (file missing)
O2 - BHO: Class - {8A085509-89CE-7DCE-68D2-341C6B333674} - C:\winnt\system32\msmx32.dll
O2 - BHO: Class - {8BC98744-A18A-A2E3-17A4-F26601005660} - C:\winnt\winqn.dll
O2 - BHO: Class - {8BCAF24C-CE04-143E-430E-2261D4A6BD83} - C:\winnt\ntjp.dll
O2 - BHO: Class - {8ECB4C30-94D8-37D6-8485-B8391D0066D1} - C:\winnt\system32\atlpj.dll
O2 - BHO: Class - {8F4A8A22-CB82-9DA4-CF49-EB8786CC5CF1} - C:\winnt\d3sv32.dll
O2 - BHO: Class - {8F7DECB4-A94C-8822-1C7E-CBFD18AF4DA7} - C:\winnt\system32\javaqh32.dll
O2 - BHO: Class - {9072FB00-1A6A-A22A-089C-CEBA99407062} - C:\winnt\winxo.dll
O2 - BHO: Class - {91C2D9FA-46EC-535B-6B07-73A15FF99DA8} - C:\winnt\system32\d3db32.dll
O2 - BHO: Class - {91E63E36-E139-91C8-2FC2-0FBE16831798} - C:\winnt\javakg32.dll
O2 - BHO: Class - {92CEDEB5-DB01-03A1-485E-3E2A9654F66C} - C:\winnt\system32\wincf.dll
O2 - BHO: Class - {931176F0-9786-B2C0-054E-1F2629032038} - C:\winnt\system32\mfcmy32.dll
O2 - BHO: (no name) - {94D7C423-35CE-7F01-EFF6-720628B10FB2} - C:\winnt\mfcnz.dll
O2 - BHO: Class - {977A72CC-2C3D-1ED8-AC44-BB18BD9FD478} - C:\winnt\system32\sdkab32.dll
O2 - BHO: Class - {97D76449-375E-30C4-8898-1DD2480E2787} - C:\winnt\system32\syscp32.dll
O2 - BHO: (no name) - {98A669B7-50D7-027A-5B9D-E7FD022FD1CC} - C:\winnt\mfcnz.dll
O2 - BHO: Class - {9970AE63-B9CA-E64F-25BA-7EFE0D9BF431} - C:\winnt\system32\crti32.dll
O2 - BHO: Class - {9F05C234-0389-D85F-86BB-5FFD52FD6347} - C:\winnt\system32\mfcbb.dll
O2 - BHO: Class - {A0E44ED7-32D2-CD28-07AF-0C0FEDBD5E1F} - C:\winnt\ntlx.dll
O2 - BHO: Class - {A180E716-27E5-5741-4CE6-FC961DFBD33E} - C:\winnt\ipgn32.dll
O2 - BHO: Class - {A287067A-D984-E929-3B81-6572CE5C53D0} - C:\winnt\system32\d3tw32.dll
O2 - BHO: Class - {A6B1C53B-8CDF-5675-61DE-9E153AF22939} - C:\winnt\sysrp32.dll
O2 - BHO: Class - {AE5AC69B-D006-C2FF-5BB2-A3C43062AD4E} - C:\winnt\addna.dll
O2 - BHO: (no name) - {AEA1D4D6-95A3-1DF6-9B5D-68EF21F917A1} - C:\winnt\system32\mfcmy32.dll
O2 - BHO: Class - {AF550F29-E32E-3172-0F1E-0B3FE9407D86} - C:\winnt\system32\ntda32.dll
O2 - BHO: Class - {AF55C00E-7B47-7EBB-6FA6-4D4DA9A8D3C1} - C:\winnt\system32\sdkqa.dll
O2 - BHO: Class - {B026F818-3C77-1847-EF05-91F2713B094A} - C:\winnt\system32\atled.dll
O2 - BHO: Class - {B294118E-713C-0FD4-2CF8-EDCDBD7BA705} - C:\winnt\system32\appvy32.dll
O2 - BHO: Class - {B2B353BD-D22A-EBC2-DD1A-8C4374D79C93} - C:\winnt\system32\mshx.dll
O2 - BHO: Class - {B2B9FA69-DEDC-E13F-FF4D-686C8A2F5D80} - C:\winnt\netue32.dll
O2 - BHO: Class - {B3C2380F-1747-2626-6C59-0CC299CB5465} - C:\winnt\appep32.dll
O2 - BHO: Class - {B6100874-25B8-6289-A9B7-4149DA46FE08} - C:\winnt\system32\appny32.dll
O2 - BHO: Class - {B7B62511-01AC-2123-8F7B-E8D5619C0DBD} - C:\winnt\mfcjz32.dll
O2 - BHO: Class - {B83F0E40-DA8D-FFCB-BF98-93E374EC3B9D} - C:\winnt\atlmb.dll
O2 - BHO: Class - {B8831CBD-C391-2AC8-5713-D46101548A9D} - C:\winnt\addiz32.dll
O2 - BHO: Class - {C13BC0F1-BF1D-F3B8-4E2F-E0AEA646BD51} - C:\winnt\ntfa.dll
O2 - BHO: Class - {C3366D3F-8396-2965-AE95-EC2D538A1389} - C:\winnt\system32\addrk32.dll
O2 - BHO: Class - {C7D92E15-46A4-79E2-5D03-07DEE2849F0E} - C:\winnt\d3pu.dll
O2 - BHO: Class - {C7FEB52A-8FCB-3586-286B-07E44B09039B} - C:\winnt\system32\winxi32.dll
O2 - BHO: Class - {C8004CAD-44C4-1A1C-61ED-29087744B433} - C:\winnt\system32\apine32.dll
O2 - BHO: Class - {CC5BAD4C-8CA3-C206-BB64-001B9FC8A31C} - C:\winnt\d3gj.dll
O2 - BHO: Class - {D014DAA5-070B-83B6-0F69-285FEB823E5A} - C:\winnt\system32\javanx32.dll (file missing)
O2 - BHO: Class - {D02C092A-9AC3-41F7-BEFB-399E09371F50} - C:\winnt\syson32.dll
O2 - BHO: Class - {D2574341-D32E-50AA-37CE-B88EAD351767} - C:\winnt\system32\apisd32.dll
O2 - BHO: Class - {D2850FF8-7735-B943-3C32-9CC34F5DA81A} - C:\winnt\system32\sdkwk.dll
O2 - BHO: Class - {D2B62795-4240-10AA-4CDE-55B8F49D4A68} - C:\winnt\system32\winil32.dll
O2 - BHO: (no name) - {D763BB4D-7342-740E-CA30-194CC520280A} - C:\winnt\mfcnz.dll
O2 - BHO: Class - {DD53705B-C3B6-C10B-7C01-05650628A5B7} - C:\winnt\system32\atlcc32.dll
O2 - BHO: Class - {DFCC53AC-E350-5C69-6831-FF99D6EC366D} - C:\winnt\system32\mfcbn.dll
O2 - BHO: Class - {E22D513B-9033-2058-6CC5-98B0336603AE} - C:\winnt\system32\sysii.dll
O2 - BHO: Class - {E242AD05-F49E-8697-B586-6E43C236C954} - C:\winnt\msyo.dll
O2 - BHO: Class - {E686D89D-B07F-32F6-6B66-2E2FCB929D81} - C:\winnt\system32\crqv32.dll
O2 - BHO: (no name) - {E71DE0DD-A511-6A3A-D0FC-2A41EE33709D} - C:\winnt\ntyy32.dll (file missing)
O2 - BHO: Class - {E8BF7FA6-085D-F6F9-EF0A-151303BD7892} - C:\winnt\system32\sysgu.dll
O2 - BHO: Class - {E91F4483-DFFA-A25A-1C69-08818BB0410F} - C:\winnt\ntgo.dll
O2 - BHO: Class - {EC3B6EE5-1810-270D-7BAA-CB06DEF3DA3C} - C:\winnt\d3bm.dll
O2 - BHO: Class - {ED6C97F0-3BCB-05C4-EC15-86AB059880B0} - C:\winnt\winch32.dll
O2 - BHO: Class - {F141BD80-6EDB-B9C1-84A8-483C374007BA} - C:\winnt\system32\atlvt32.dll
O2 - BHO: Class - {F1D6E61C-4831-A1A5-DC65-A4011A25B7BB} - C:\winnt\system32\mfcmy32.dll
O2 - BHO: Class - {F84A75A9-2E69-E130-2CE8-0A1BE2E41960} - C:\winnt\winfm32.dll
O2 - BHO: Class - {F9B474FF-51A3-FFA5-56B2-0AC0914CE88D} - C:\winnt\javako32.dll
O2 - BHO: Class - {F9B9FC73-14A5-58D3-388C-F56982280DA5} - C:\winnt\system32\winuy32.dll
O2 - BHO: Class - {FBBD5339-410E-458C-646F-58C1E4FBE458} - C:\winnt\mfcnz.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [Matrox Powerdesk] C:\WINNT\system32\PDesk\PDesk.exe /Autolaunch
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iegp32.exe] C:\winnt\system32\iegp32.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\RunOnce: [MS Setup] C:\Program Files\Windows Media Player\wmplayer.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: Yahoo! MahJong Solitaire - http://download.game...s/y/mjst4_x.cab
O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) - http://www.712fiftha...sses/CFJava.cab
O16 - DPF: {084F552D-19EB-4668-9788-984CBC781A8F} (AsyncDownloader Class) - http://survey.otxres...m/Preloader.dll
O16 - DPF: {1D9EFA3B-4E85-41A8-9092-14012CD447C9} (NetCamPlayerWeb Control) - http://aspnbrat.ourl...amPlayerWeb.ocx
O16 - DPF: {4A026B12-94F3-4D2F-A468-96AA55DE20A5} (NetCamPlayerWeb11g Control) - http://aspnbrat.ourl...layerWeb11g.ocx
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ********.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = ********.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = ********.com
O20 - Winlogon Notify: NavLogon - C:\WINNT\system32\NavLogon.dll
O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\winnt\system32\ntof32.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\winnt\System32\dmadmin.exe
O23 - Service: iPod Service (iPodService) - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: MGABGEXE - Matrox Graphics Inc. - C:\winnt\system32\mgabg.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe