HighJackThis Log:
Logfile of HijackThis v1.99.1
Scan saved at 8:05:08 AM, on 7/14/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\xl.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\javakf32.exe
C:\Program Files\Sunbelt Software\CounterSpy Client\sunasDtServ.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\MSN\MSNCoreFiles\msn6.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HighJackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\ytrgd.dll/sp.html#12047
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ytrgd.dll/sp.html#12047
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about
:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\ytrgd.dll/sp.html#12047
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\ytrgd.dll/sp.html#12047
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ytrgd.dll/sp.html#12047
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\ytrgd.dll/sp.html#12047
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\ytrgd.dll/sp.html#12047
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {1C72FEB7-4D6C-FAF3-195A-D51516EDCC77} - C:\WINDOWS\apihw32.dll
O2 - BHO: Class - {52CA0E68-18D4-4EE7-27A9-12262907D778} - C:\WINDOWS\system32\addcm32.dll
O2 - BHO: Class - {8C4F8213-4CBA-4C70-31C9-B2D727A270F1} - C:\WINDOWS\ipoh.dll
O2 - BHO: Class - {9A65FF84-5F62-35FE-18D6-0C43F27B7AEB} - C:\WINDOWS\system32\netxj.dll
O2 - BHO: Class - {B784881A-C236-6F52-D86B-285DC0FC4011} - C:\WINDOWS\syskb32.dll
O2 - BHO: Class - {B7C25C68-FA17-FA9D-AF0F-BB29B5B9B64C} - C:\WINDOWS\apicj.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [LTWinModem1] ltmsg.exe 9
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [Dell|Alert] C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [CamMonitor] C:\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Microsoft Tray] C:\Documents and Settings\JDG\Desktop\Josh\My Shared Folder\Video Strip Poker 2002.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [IEXPLORE.EXE] c:\Program Files\Internet Explorer\IEXPLORE.EXE
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\Program Files\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [javakf32.exe] C:\WINDOWS\system32\javakf32.exe
O4 - HKLM\..\Run: [sunasDTServ] C:\Program Files\Sunbelt Software\CounterSpy Client\sunasDtServ.exe
O4 - HKLM\..\Run: [sunasServ] C:\Program Files\Sunbelt Software\CounterSpy Client\sunasServ.exe
O4 - HKLM\..\RunOnce: [iect.exe] C:\WINDOWS\iect.exe
O4 - HKLM\..\RunOnce: [atlsj32.exe] C:\WINDOWS\system32\atlsj32.exe
O4 - HKLM\..\RunOnce: [appim32.exe] C:\WINDOWS\system32\appim32.exe
O4 - HKLM\..\RunOnce: [atlat32.exe] C:\WINDOWS\system32\atlat32.exe
O4 - HKLM\..\RunOnce: [ipzm32.exe] C:\WINDOWS\system32\ipzm32.exe
O4 - HKLM\..\RunOnce: [appsw.exe] C:\WINDOWS\appsw.exe
O4 - HKLM\..\RunOnce: [crse32.exe] C:\WINDOWS\system32\crse32.exe
O4 - HKLM\..\RunOnce: [d3mp.exe] C:\WINDOWS\d3mp.exe
O4 - HKLM\..\RunOnce: [d3gh.exe] C:\WINDOWS\system32\d3gh.exe
O4 - HKLM\..\RunOnce: [sdkns32.exe] C:\WINDOWS\system32\sdkns32.exe
O4 - HKLM\..\RunOnce: [ipru.exe] C:\WINDOWS\system32\ipru.exe
O4 - HKLM\..\RunOnce: [sdknu.exe] C:\WINDOWS\system32\sdknu.exe
O4 - HKLM\..\RunOnce: [apiry.exe] C:\WINDOWS\apiry.exe
O4 - HKLM\..\RunOnce: [sdknc.exe] C:\WINDOWS\sdknc.exe
O4 - HKLM\..\RunOnce: [msfd32.exe] C:\WINDOWS\msfd32.exe
O4 - HKLM\..\RunOnce: [winvl.exe] C:\WINDOWS\winvl.exe
O4 - HKLM\..\RunOnce: [d3uy.exe] C:\WINDOWS\system32\d3uy.exe
O4 - HKLM\..\RunOnce: [addyc.exe] C:\WINDOWS\addyc.exe
O4 - HKLM\..\RunOnce: [mfcjv32.exe] C:\WINDOWS\system32\mfcjv32.exe
O4 - HKLM\..\RunOnce: [sdkgn32.exe] C:\WINDOWS\sdkgn32.exe
O4 - HKLM\..\RunOnce: [javaob32.exe] C:\WINDOWS\system32\javaob32.exe
O4 - HKLM\..\RunOnce: [ntwx32.exe] C:\WINDOWS\system32\ntwx32.exe
O4 - HKLM\..\RunOnce: [apipo32.exe] C:\WINDOWS\apipo32.exe
O4 - HKLM\..\RunOnce: [msem.exe] C:\WINDOWS\system32\msem.exe
O4 - HKLM\..\RunOnce: [appie32.exe] C:\WINDOWS\system32\appie32.exe
O4 - HKLM\..\RunOnce: [mswy.exe] C:\WINDOWS\system32\mswy.exe
O4 - HKLM\..\RunOnce: [netzt.exe] C:\WINDOWS\netzt.exe
O4 - HKLM\..\RunOnce: [sdklp32.exe] C:\WINDOWS\sdklp32.exe
O4 - HKLM\..\RunOnce: [sysqd.exe] C:\WINDOWS\system32\sysqd.exe
O4 - HKLM\..\RunOnce: [netle.exe] C:\WINDOWS\netle.exe
O4 - HKLM\..\RunOnce: [d3im32.exe] C:\WINDOWS\d3im32.exe
O4 - HKLM\..\RunOnce: [wingl.exe] C:\WINDOWS\system32\wingl.exe
O4 - HKLM\..\RunOnce: [appeq32.exe] C:\WINDOWS\system32\appeq32.exe
O4 - HKLM\..\RunOnce: [winpc32.exe] C:\WINDOWS\winpc32.exe
O4 - HKLM\..\RunOnce: [apich.exe] C:\WINDOWS\apich.exe
O4 - HKLM\..\RunOnce: [mfchl.exe] C:\WINDOWS\system32\mfchl.exe
O4 - HKLM\..\RunOnce: [sysae32.exe] C:\WINDOWS\sysae32.exe
O4 - HKLM\..\RunOnce: [mfcuw.exe] C:\WINDOWS\mfcuw.exe
O4 - HKLM\..\RunOnce: [crnw32.exe] C:\WINDOWS\crnw32.exe
O4 - HKLM\..\RunOnce: [apieo32.exe] C:\WINDOWS\system32\apieo32.exe
O4 - HKLM\..\RunOnce: [sdkvj.exe] C:\WINDOWS\system32\sdkvj.exe
O4 - HKLM\..\RunOnce: [sdkpc32.exe] C:\WINDOWS\system32\sdkpc32.exe
O4 - HKLM\..\RunOnce: [sysiz.exe] C:\WINDOWS\system32\sysiz.exe
O4 - HKLM\..\RunOnce: [sdkbg32.exe] C:\WINDOWS\system32\sdkbg32.exe
O4 - HKLM\..\RunOnce: [addvl.exe] C:\WINDOWS\system32\addvl.exe
O4 - HKLM\..\RunOnce: [apian.exe] C:\WINDOWS\apian.exe
O4 - HKLM\..\RunOnce: [sdkah.exe] C:\WINDOWS\system32\sdkah.exe
O4 - HKLM\..\RunOnce: [mfcfb32.exe] C:\WINDOWS\mfcfb32.exe
O4 - HKLM\..\RunOnce: [netdl.exe] C:\WINDOWS\netdl.exe
O4 - HKLM\..\RunOnce: [javarb.exe] C:\WINDOWS\javarb.exe
O4 - HKLM\..\RunOnce: [javanw32.exe] C:\WINDOWS\javanw32.exe
O4 - HKLM\..\RunOnce: [sysgs.exe] C:\WINDOWS\system32\sysgs.exe
O4 - HKLM\..\RunOnce: [apivj32.exe] C:\WINDOWS\apivj32.exe
O4 - HKLM\..\RunOnce: [sysgc32.exe] C:\WINDOWS\system32\sysgc32.exe
O4 - HKLM\..\RunOnce: [mfczz.exe] C:\WINDOWS\mfczz.exe
O4 - HKLM\..\RunOnce: [ieyg.exe] C:\WINDOWS\ieyg.exe
O4 - HKLM\..\RunOnce: [sdkdr.exe] C:\WINDOWS\sdkdr.exe
O4 - HKLM\..\RunOnce: [msvk.exe] C:\WINDOWS\msvk.exe
O4 - HKLM\..\RunOnce: [d3yv.exe] C:\WINDOWS\system32\d3yv.exe
O4 - HKLM\..\RunOnce: [winho.exe] C:\WINDOWS\winho.exe
O4 - HKLM\..\RunOnce: [crnq32.exe] C:\WINDOWS\system32\crnq32.exe
O4 - HKLM\..\RunOnce: [d3sh32.exe] C:\WINDOWS\system32\d3sh32.exe
O4 - HKLM\..\RunOnce: [netxj.exe] C:\WINDOWS\system32\netxj.exe
O4 - HKLM\..\RunOnce: [atlqi.exe] C:\WINDOWS\atlqi.exe
O4 - HKLM\..\RunOnce: [ievc32.exe] C:\WINDOWS\system32\ievc32.exe
O4 - HKLM\..\RunOnce: [mskx32.exe] C:\WINDOWS\mskx32.exe
O4 - HKLM\..\RunOnce: [apptz32.exe] C:\WINDOWS\system32\apptz32.exe
O4 - HKLM\..\RunOnce: [d3zu.exe] C:\WINDOWS\system32\d3zu.exe
O4 - HKLM\..\RunOnce: [apikh.exe] C:\WINDOWS\system32\apikh.exe
O4 - HKLM\..\RunOnce: [crud32.exe] C:\WINDOWS\crud32.exe
O4 - HKLM\..\RunOnce: [crzu32.exe] C:\WINDOWS\crzu32.exe
O4 - HKLM\..\RunOnce: [mstn32.exe] C:\WINDOWS\system32\mstn32.exe
O4 - HKLM\..\RunOnce: [ipyj32.exe] C:\WINDOWS\system32\ipyj32.exe
O4 - HKLM\..\RunOnce: [mstv.exe] C:\WINDOWS\mstv.exe
O4 - HKLM\..\RunOnce: [apprq32.exe] C:\WINDOWS\apprq32.exe
O4 - HKLM\..\RunOnce: [msaa.exe] C:\WINDOWS\msaa.exe
O4 - HKLM\..\RunOnce: [addee.exe] C:\WINDOWS\system32\addee.exe
O4 - HKLM\..\RunOnce: [addtw32.exe] C:\WINDOWS\addtw32.exe
O4 - HKLM\..\RunOnce: [sysrr32.exe] C:\WINDOWS\sysrr32.exe
O4 - HKLM\..\RunOnce: [winrh32.exe] C:\WINDOWS\winrh32.exe
O4 - HKLM\..\RunOnce: [apiaa32.exe] C:\WINDOWS\apiaa32.exe
O4 - HKLM\..\RunOnce: [apidr32.exe] C:\WINDOWS\apidr32.exe
O4 - HKLM\..\RunOnce: [nttz32.exe] C:\WINDOWS\nttz32.exe
O4 - HKLM\..\RunOnce: [netoc.exe] C:\WINDOWS\system32\netoc.exe
O4 - HKLM\..\RunOnce: [addns32.exe] C:\WINDOWS\addns32.exe
O4 - HKLM\..\RunOnce: [iprk32.exe] C:\WINDOWS\iprk32.exe
O4 - HKLM\..\RunOnce: [crhr.exe] C:\WINDOWS\crhr.exe
O4 - HKLM\..\RunOnce: [ipge.exe] C:\WINDOWS\system32\ipge.exe
O4 - HKLM\..\RunOnce: [mfcwt.exe] C:\WINDOWS\mfcwt.exe
O4 - HKLM\..\RunOnce: [javarl.exe] C:\WINDOWS\system32\javarl.exe
O4 - HKLM\..\RunOnce: [apiqb32.exe] C:\WINDOWS\system32\apiqb32.exe
O4 - HKLM\..\RunOnce: [addpi32.exe] C:\WINDOWS\addpi32.exe
O4 - HKLM\..\RunOnce: [appoy32.exe] C:\WINDOWS\appoy32.exe
O4 - HKLM\..\RunOnce: [ipyr32.exe] C:\WINDOWS\system32\ipyr32.exe
O4 - HKLM\..\RunOnce: [sysyz32.exe] C:\WINDOWS\sysyz32.exe
O4 - HKLM\..\RunOnce: [apibl32.exe] C:\WINDOWS\system32\apibl32.exe
O4 - HKLM\..\RunOnce: [winby32.exe] C:\WINDOWS\system32\winby32.exe
O4 - HKLM\..\RunOnce: [javaur32.exe] C:\WINDOWS\javaur32.exe
O4 - HKLM\..\RunOnce: [cruh32.exe] C:\WINDOWS\cruh32.exe
O4 - HKLM\..\RunOnce: [winda32.exe] C:\WINDOWS\system32\winda32.exe
O4 - HKLM\..\RunOnce: [atlrc.exe] C:\WINDOWS\atlrc.exe
O4 - HKLM\..\RunOnce: [netbd.exe] C:\WINDOWS\netbd.exe
O4 - HKLM\..\RunOnce: [winal32.exe] C:\WINDOWS\winal32.exe
O4 - HKLM\..\RunOnce: [iphz32.exe] C:\WINDOWS\iphz32.exe
O4 - HKLM\..\RunOnce: [winhz32.exe] C:\WINDOWS\system32\winhz32.exe
O4 - HKLM\..\RunOnce: [netkl32.exe] C:\WINDOWS\system32\netkl32.exe
O4 - HKLM\..\RunOnce: [crtm32.exe] C:\WINDOWS\system32\crtm32.exe
O4 - HKLM\..\RunOnce: [atltu.exe] C:\WINDOWS\atltu.exe
O4 - HKLM\..\RunOnce: [msis32.exe] C:\WINDOWS\system32\msis32.exe
O4 - HKLM\..\RunOnce: [mfcxh32.exe] C:\WINDOWS\mfcxh32.exe
O4 - HKLM\..\RunOnce: [ipdr.exe] C:\WINDOWS\ipdr.exe
O4 - HKLM\..\RunOnce: [ipxk32.exe] C:\WINDOWS\system32\ipxk32.exe
O4 - HKLM\..\RunOnce: [addqd32.exe] C:\WINDOWS\system32\addqd32.exe
O4 - HKLM\..\RunOnce: [addql32.exe] C:\WINDOWS\system32\addql32.exe
O4 - HKLM\..\RunOnce: [netam32.exe] C:\WINDOWS\system32\netam32.exe
O4 - HKLM\..\RunOnce: [sysam.exe] C:\WINDOWS\sysam.exe
O4 - HKLM\..\RunOnce: [crdy.exe] C:\WINDOWS\crdy.exe
O4 - HKLM\..\RunOnce: [sdknx.exe] C:\WINDOWS\system32\sdknx.exe
O4 - HKLM\..\RunOnce: [addlx.exe] C:\WINDOWS\system32\addlx.exe
O4 - HKLM\..\RunOnce: [msbn.exe] C:\WINDOWS\msbn.exe
O4 - HKLM\..\RunOnce: [wintn32.exe] C:\WINDOWS\wintn32.exe
O4 - HKLM\..\RunOnce: [mfckv.exe] C:\WINDOWS\mfckv.exe
O4 - HKLM\..\RunOnce: [winii.exe] C:\WINDOWS\system32\winii.exe
O4 - HKLM\..\RunOnce: [mfcem.exe] C:\WINDOWS\mfcem.exe
O4 - HKLM\..\RunOnce: [ntxf32.exe] C:\WINDOWS\system32\ntxf32.exe
O4 - HKLM\..\RunOnce: [crnn.exe] C:\WINDOWS\system32\crnn.exe
O4 - HKLM\..\RunOnce: [msbz.exe] C:\WINDOWS\system32\msbz.exe
O4 - HKLM\..\RunOnce: [iego32.exe] C:\WINDOWS\iego32.exe
O4 - HKLM\..\RunOnce: [ipan.exe] C:\WINDOWS\system32\ipan.exe
O4 - HKLM\..\RunOnce: [sysuy.exe] C:\WINDOWS\sysuy.exe
O4 - HKLM\..\RunOnce: [ipfi.exe] C:\WINDOWS\ipfi.exe
O4 - HKLM\..\RunOnce: [ntco.exe] C:\WINDOWS\ntco.exe
O4 - HKLM\..\RunOnce: [mfchq32.exe] C:\WINDOWS\system32\mfchq32.exe
O4 - HKLM\..\RunOnce: [sdkrr32.exe] C:\WINDOWS\system32\sdkrr32.exe
O4 - HKLM\..\RunOnce: [addrz.exe] C:\WINDOWS\addrz.exe
O4 - HKLM\..\RunOnce: [ievd.exe] C:\WINDOWS\ievd.exe
O4 - HKLM\..\RunOnce: [atlks32.exe] C:\WINDOWS\system32\atlks32.exe
O4 - HKLM\..\RunOnce: [ipih.exe] C:\WINDOWS\system32\ipih.exe
O4 - HKLM\..\RunOnce: [cred32.exe] C:\WINDOWS\system32\cred32.exe
O4 - HKLM\..\RunOnce: [sdkom.exe] C:\WINDOWS\system32\sdkom.exe
O4 - HKLM\..\RunOnce: [addwk32.exe] C:\WINDOWS\addwk32.exe
O4 - HKLM\..\RunOnce: [ntou.exe] C:\WINDOWS\ntou.exe
O4 - HKLM\..\RunOnce: [neteb.exe] C:\WINDOWS\neteb.exe
O4 - HKLM\..\RunOnce: [appil32.exe] C:\WINDOWS\system32\appil32.exe
O4 - HKLM\..\RunOnce: [d3ue32.exe] C:\WINDOWS\system32\d3ue32.exe
O4 - HKLM\..\RunOnce: [msbu.exe] C:\WINDOWS\system32\msbu.exe
O4 - HKLM\..\RunOnce: [d3cu.exe] C:\WINDOWS\system32\d3cu.exe
O4 - HKLM\..\RunOnce: [addrk32.exe] C:\WINDOWS\system32\addrk32.exe
O4 - HKLM\..\RunOnce: [mska.exe] C:\WINDOWS\system32\mska.exe
O4 - HKLM\..\RunOnce: [netyf.exe] C:\WINDOWS\netyf.exe
O4 - HKLM\..\RunOnce: [iekq.exe] C:\WINDOWS\system32\iekq.exe
O4 - HKLM\..\RunOnce: [crax.exe] C:\WINDOWS\system32\crax.exe
O4 - HKLM\..\RunOnce: [netsq32.exe] C:\WINDOWS\netsq32.exe
O4 - HKLM\..\RunOnce: [sdkys.exe] C:\WINDOWS\system32\sdkys.exe
O4 - HKLM\..\RunOnce: [appvr.exe] C:\WINDOWS\appvr.exe
O4 - HKLM\..\RunOnce: [wincg.exe] C:\WINDOWS\system32\wincg.exe
O4 - HKLM\..\RunOnce: [crvz32.exe] C:\WINDOWS\system32\crvz32.exe
O4 - HKLM\..\RunOnce: [ipmu32.exe] C:\WINDOWS\system32\ipmu32.exe
O4 - HKLM\..\RunOnce: [apihy32.exe] C:\WINDOWS\apihy32.exe
O4 - HKLM\..\RunOnce: [sdkfv.exe] C:\WINDOWS\sdkfv.exe
O4 - HKLM\..\RunOnce: [appls32.exe] C:\WINDOWS\system32\appls32.exe
O4 - HKLM\..\RunOnce: [mfcel32.exe] C:\WINDOWS\system32\mfcel32.exe
O4 - HKLM\..\RunOnce: [iebp32.exe] C:\WINDOWS\system32\iebp32.exe
O4 - HKLM\..\RunOnce: [atlak.exe] C:\WINDOWS\atlak.exe
O4 - HKLM\..\RunOnce: [apidd32.exe] C:\WINDOWS\system32\apidd32.exe
O4 - HKLM\..\RunOnce: [apisa32.exe] C:\WINDOWS\apisa32.exe
O4 - HKLM\..\RunOnce: [syswe.exe] C:\WINDOWS\system32\syswe.exe
O4 - HKLM\..\RunOnce: [d3ai.exe] C:\WINDOWS\d3ai.exe
O4 - HKLM\..\RunOnce: [sdkkg32.exe] C:\WINDOWS\sdkkg32.exe
O4 - HKLM\..\RunOnce: [appkp.exe] C:\WINDOWS\appkp.exe
O4 - HKLM\..\RunOnce: [ieob.exe] C:\WINDOWS\ieob.exe
O4 - HKLM\..\RunOnce: [netim32.exe] C:\WINDOWS\netim32.exe
O4 - HKLM\..\RunOnce: [sdkzt32.exe] C:\WINDOWS\sdkzt32.exe
O4 - HKLM\..\RunOnce: [ipcx.exe] C:\WINDOWS\system32\ipcx.exe
O4 - HKLM\..\RunOnce: [appbn32.exe] C:\WINDOWS\system32\appbn32.exe
O4 - HKLM\..\RunOnce: [netmm32.exe] C:\WINDOWS\netmm32.exe
O4 - HKLM\..\RunOnce: [ipfx32.exe] C:\WINDOWS\system32\ipfx32.exe
O4 - HKLM\..\RunOnce: [syscq32.exe] C:\WINDOWS\syscq32.exe
O4 - HKLM\..\RunOnce: [msft.exe] C:\WINDOWS\system32\msft.exe
O4 - HKLM\..\RunOnce: [ntej32.exe] C:\WINDOWS\system32\ntej32.exe
O4 - HKLM\..\RunOnce: [ieab32.exe] C:\WINDOWS\ieab32.exe
O4 - HKLM\..\RunOnce: [appyi.exe] C:\WINDOWS\appyi.exe
O4 - HKLM\..\RunOnce: [netum32.exe] C:\WINDOWS\system32\netum32.exe
O4 - HKLM\..\RunOnce: [atldn.exe] C:\WINDOWS\system32\atldn.exe
O4 - HKLM\..\RunOnce: [mfcrj32.exe] C:\WINDOWS\system32\mfcrj32.exe
O4 - HKLM\..\RunOnce: [atlxy32.exe] C:\WINDOWS\atlxy32.exe
O4 - HKLM\..\RunOnce: [iecc32.exe] C:\WINDOWS\iecc32.exe
O4 - HKLM\..\RunOnce: [d3ax.exe] C:\WINDOWS\d3ax.exe
O4 - HKLM\..\RunOnce: [netzx32.exe] C:\WINDOWS\netzx32.exe
O4 - HKLM\..\RunOnce: [msgu.exe] C:\WINDOWS\system32\msgu.exe
O4 - HKLM\..\RunOnce: [sysfc.exe] C:\WINDOWS\sysfc.exe
O4 - HKLM\..\RunOnce: [atlxu.exe] C:\WINDOWS\system32\atlxu.exe
O4 - HKLM\..\RunOnce: [d3oc32.exe] C:\WINDOWS\system32\d3oc32.exe
O4 - HKLM\..\RunOnce: [atldr32.exe] C:\WINDOWS\atldr32.exe
O4 - HKCU\..\Run: [Extreme Messenger for AIM] C:\Program Files\Extreme Messenger\ExtremeMessenger.exe nosplash
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Startup: VirtuaGirl2.lnk = C:\Program Files\vg\VirtuaGirl2.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global User Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global User Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar Search - res://c:\program files\aol\aol toolbar 2.0\aoltbhtml.dll/search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\inetrepl.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: ChatSpace Java Client 2.1.0.91L -
http://207.29.194.123:8000/Java/cs4msl091.cab
O16 - DPF: Yahoo! Chat -
http://us.chat1.yimg.com/us.yimg.com.../c381/chat.cab
O16 - DPF: Yahoo! Chess -
http://download.games.yahoo.com/game...ts/y/ct1_x.cab
O16 - DPF: Yahoo! Dots -
http://download.games.yahoo.com/game...s/y/dtt1_x.cab
O16 - DPF: Yahoo! Literati -
http://download.games.yahoo.com/game...ts/y/tt0_x.cab
O16 - DPF: Yahoo! NFL StatTracker -
http://aud10.sports.yahoo.com/java/y/nflst8219_x.cab
O16 - DPF: Yahoo! Poker -
http://download.games.yahoo.com/game...ts/y/pt0_x.cab
O16 - DPF: Yahoo! Pool 2 -
http://download.games.yahoo.com/game...s/y/potc_x.cab
O16 - DPF: Yahoo! Trivia -
http://download.games.yahoo.com/game...s/y/tvt0_x.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) -
http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {0F9B4CA4-A30F-480A-841D-69B45C50A8F8} (SekureL0gin.SekureKontrol) -
http://secure2.comned.com/signuptemp...veSekurity.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?link...38&clcid=0x409
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) -
http://us.chat1.yimg.com/us.yimg.com...43/yacscom.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/S...in/AvSniff.cab
O16 - DPF: {36C66BBD-E667-4DAD-9682-58050E7C9FDC} (CDKey Class) -
http://www.cdkeybonus.com/cdkey/ITCDKey.cab
O16 - DPF: {3FE16C08-D6A7-4133-84FC-D5BFB4F7D886} (WebGameLoader Class) -
http://zone.msn.com/bingame/rtlw/def...GameLoader.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
http://apple.speedera.net/qtinstall....eInstaller.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) -
http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) -
http://ax.phobos.apple.com.edgesuite...ITDetector.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -
http://zone.msn.com/bingame/zuma/def...ploader_v5.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) -
http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) -
https://www-secure.symantec.com/tech...ActiveData.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) -
http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) -
http://pdl.stream.aol.com/downloads/...ampx_en_dl.cab
O23 - Service: Network Security Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\winiw.exe" /s (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SmartFinder Uninstall (SmartFinder_Uninstall) - Unknown owner - C:\Documents and Settings\JDG\Local Settings\Temporary Internet Files\Content.IE5\EJYP4R78\SFUninstaller[1].exe" service (file missing)
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: XtreamLok License Manager - Unknown owner - C:\WINDOWS\System32\xl.exe
SpSeHjFix Log File:
(7/13/05 4:54:24 PM) SPSeHjFix started v1.1.2
(7/13/05 4:54:24 PM) OS: WinXP Service Pack 2 (5.1.2600)
(7/13/05 4:54:24 PM) Language: english
(7/13/05 4:54:24 PM) Win-Path: C:\WINDOWS
(7/13/05 4:54:24 PM) System-Path: C:\WINDOWS\system32
(7/13/05 4:54:24 PM) Temp-Path: C:\DOCUME~1\JDG\LOCALS~1\Temp\
(7/13/05 4:54:36 PM) Disinfection started
(7/13/05 4:54:36 PM) Bad-Dll(IEP): c:\windows\xktsb.dll
(7/13/05 4:54:36 PM) UBF: 4 - UBB: 1 - UBR: 26
(7/13/05 4:54:36 PM) UBF: 4 - UBB: 1 - UBR: 26
(7/13/05 4:54:36 PM) Bad IE-pages:
deleted: HKCU\Software\Microsoft\Internet Explorer\Search, SearchAssistant: res://c:\windows\xktsb.dll/sp.html#12047
deleted: HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant: res://c:\windows\xktsb.dll/sp.html#12047
(7/13/05 4:54:36 PM) Stealth-String not found
(7/13/05 4:54:36 PM) No locked Files to delete. End without Reboot
(7/13/05 4:54:41 PM) Disinfection started
(7/13/05 4:54:41 PM) Bad-Dll(IEP): c:\windows\xktsb.dll
(7/13/05 4:54:41 PM) UBF: 4 - UBB: 1 - UBR: 26
(7/13/05 4:54:41 PM) UBF: 4 - UBB: 1 - UBR: 26
(7/13/05 4:54:41 PM) Bad IE-pages: (none)
(7/13/05 4:54:41 PM) Stealth-String not found
(7/13/05 4:54:41 PM) No locked Files to delete. End without Reboot
(7/13/05 4:55:03 PM) Disinfection started
(7/13/05 4:55:03 PM) Bad-Dll(IEP): c:\windows\xktsb.dll
(7/13/05 4:55:03 PM) UBF: 4 - UBB: 1 - UBR: 26
(7/13/05 4:55:03 PM) UBF: 4 - UBB: 1 - UBR: 26
(7/13/05 4:55:03 PM) Bad IE-pages: (none)
(7/13/05 4:55:03 PM) Stealth-String not found
(7/13/05 4:55:03 PM) No locked Files to delete. End without Reboot
(7/13/05 4:55:26 PM) SPSeHjFix started v1.1.2
(7/13/05 4:55:26 PM) OS: WinXP Service Pack 2 (5.1.2600)
(7/13/05 4:55:26 PM) Language: english
(7/13/05 4:55:26 PM) Win-Path: C:\WINDOWS
(7/13/05 4:55:26 PM) System-Path: C:\WINDOWS\system32
(7/13/05 4:55:26 PM) Temp-Path: C:\DOCUME~1\JDG\LOCALS~1\Temp\
(7/13/05 4:55:32 PM) Disinfection started
(7/13/05 4:55:32 PM) Bad-Dll(IEP): (not found)
(7/13/05 4:55:32 PM) Bad-Dll(IEP) in BHO: (not found)
(7/13/05 4:55:32 PM) UBF: 4 - UBB: 1 - UBR: 26
(7/13/05 4:55:32 PM) UBF: 4 - UBB: 1 - UBR: 26
(7/13/05 4:55:32 PM) Bad IE-pages: (none)
(7/13/05 4:55:32 PM) Stealth-String not found
(7/13/05 4:55:32 PM) Not infected->END
Panda Scan Log:
Incident Status Location
Spyware

pyware/Cydoor No disinfected C:\WINDOWS\cdmxtras
Spyware

pyware/BargainBuddy No disinfected C:\WINDOWS\system32\NLNupgradeV4_5P13.exe
Adware:Adware/MyWay No disinfected C:\WINDOWS\system32\Xcite.dll
Adware:Adware/nCase No disinfected C:\WINDOWS\system32\FLEOK
Adware:Adware/BrilliantDigitalNo disinfected Windows Registry
Adware:Adware/DownloadWare No disinfected C:\Program Files\MediaLoads*
Spyware

pyware/ISTbar No disinfected C:\Program Files\Common Files\Totem Shared
Spyware

pyware/ClearSearch No disinfected C:\WINDOWS\system32\ClrSchP0??.dll
Adware:Adware/TalkStocks No disinfected C:\WINDOWS\system32\mstbl.ocx
Adware:Adware/SAHAgent No disinfected C:\WINDOWS\system32\sahagent*.exe
Adware:Adware/SearchAid No disinfected Windows Registry
Adware:Adware/SideSearch No disinfected C:\Documents and Settings\JDG\Application Data\Lycos
Adware:Adware/BlazeFind No disinfected Windows Registry
Adware:Adware/MSView No disinfected C:\WINDOWS\system32\nostalgia.dll
Spyware

pyware/Altnet No disinfected Windows Registry
Spyware

pyware/Whazit No disinfected C:\WINDOWS\system32\fiz1
Adware:Adware/CWS.Aboutblank No disinfected Windows Registry
Adware:Adware/Antivirus-gold No disinfected C:\Documents and Settings\JDG\Application Data\Microsoft\Internet Explorer\Quick Launch\AntivirusGold 2.0.lnk
Adware:Adware/Gator No disinfected C:\Program Files\Common Files\ppetpper\nfhpeent\htjlnejn.exe.tcf
Adware:Adware/Gator No disinfected C:\Program Files\Common Files\ppetpper\peppcnapah\pnjnnflbl.exe.tcf
Adware:Adware/VirtualBouncer No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\09249232-8AB0-4C82-B484-B259DB\22855475-A4FE-46F8-ACC9-89FC84
Spyware

pyware/Altnet No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\1364BF81-B3DA-4CDA-8935-0D3B6A\07962896-0F3D-45EC-BB74-B30C02
Spyware

pyware/Altnet No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\1364BF81-B3DA-4CDA-8935-0D3B6A\07A96FF7-8F51-47F4-8FA9-AE7642
Spyware

pyware/Altnet No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\1364BF81-B3DA-4CDA-8935-0D3B6A\2245E673-988A-4C21-9F36-E3E580
Spyware

pyware/Altnet No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\1364BF81-B3DA-4CDA-8935-0D3B6A\24C304DE-0A64-447A-88C3-D352C3
Spyware

pyware/Altnet No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\1364BF81-B3DA-4CDA-8935-0D3B6A\2EB8B370-9440-4473-9921-14C9E5
Spyware

pyware/Altnet No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\1364BF81-B3DA-4CDA-8935-0D3B6A\320DFE9A-65E1-413D-B7A4-0BBE1B
Spyware

pyware/Altnet No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\1364BF81-B3DA-4CDA-8935-0D3B6A\320DFE9A-65E1-413D-B7A4-0BBE1B[sysdetect.dll]
Spyware

pyware/Altnet No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\1364BF81-B3DA-4CDA-8935-0D3B6A\3213AA3A-2D4C-4302-93DA-DA63CC
Spyware

pyware/Altnet No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\1364BF81-B3DA-4CDA-8935-0D3B6A\5274E52D-0192-4F30-AA3A-38D60D
Spyware

pyware/Altnet No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\1364BF81-B3DA-4CDA-8935-0D3B6A\5C0B0532-168E-47BA-99F9-A4545F
Spyware

pyware/Altnet No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\1364BF81-B3DA-4CDA-8935-0D3B6A\617E34AB-6E8E-4F78-8197-58F77E
Spyware

pyware/Altnet No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\1364BF81-B3DA-4CDA-8935-0D3B6A\6A95E07C-9AB3-44DE-B40D-33AECD
Adware:Adware/MyWay No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\1364BF81-B3DA-4CDA-8935-0D3B6A\71FE6599-60FD-4072-A1C6-202C3F
Adware:Adware/MyWay No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\1364BF81-B3DA-4CDA-8935-0D3B6A\71FE6599-60FD-4072-A1C6-202C3F[mySetp.exe]
Spyware

pyware/Altnet No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\1364BF81-B3DA-4CDA-8935-0D3B6A\88D3F65E-BE0E-424E-A950-EDE339
Spyware

pyware/Altnet No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\1364BF81-B3DA-4CDA-8935-0D3B6A\8D73D7F8-0DBD-4A71-A9AB-E06F24
Spyware

pyware/Altnet No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\1364BF81-B3DA-4CDA-8935-0D3B6A\9085447E-E893-445C-BE65-7935F3
Spyware

pyware/Altnet No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\1364BF81-B3DA-4CDA-8935-0D3B6A\9085447E-E893-445C-BE65-7935F3[Points Manager.exe]
Spyware

pyware/Altnet No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\1364BF81-B3DA-4CDA-8935-0D3B6A\960CD96A-23F0-457C-B15D-E8DC0F
Spyware

pyware/Altnet No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\1364BF81-B3DA-4CDA-8935-0D3B6A\A0BA2442-C030-4A25-AB58-D5DE08
Spyware

pyware/Altnet No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\1364BF81-B3DA-4CDA-8935-0D3B6A\AB3C410E-83A7-4F3B-8CF3-D14313
Spyware

pyware/Altnet No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\1364BF81-B3DA-4CDA-8935-0D3B6A\B6582C33-8486-4BE1-B256-611871
Spyware

pyware/Altnet No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\1364BF81-B3DA-4CDA-8935-0D3B6A\C869D74A-EB7C-4170-8974-A9A6D7
Spyware

pyware/Altnet No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\1364BF81-B3DA-4CDA-8935-0D3B6A\CB7FF7D8-6856-41BD-B2C5-305FCB
Spyware

pyware/Altnet No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\1364BF81-B3DA-4CDA-8935-0D3B6A\CCFF6568-F7EE-4861-B31E-37BCCE
Spyware

pyware/Altnet No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\1364BF81-B3DA-4CDA-8935-0D3B6A\E326382D-1627-48A2-82FF-8F7561
Spyware

pyware/Altnet No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\1364BF81-B3DA-4CDA-8935-0D3B6A\F850E8C2-6523-4996-BAA9-4266FD
Spyware

pyware/Altnet No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\1364BF81-B3DA-4CDA-8935-0D3B6A\F850E8C2-6523-4996-BAA9-4266FD[AltnetUninstall.exe]
Spyware

pyware/Altnet No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\1364BF81-B3DA-4CDA-8935-0D3B6A\F850E8C2-6523-4996-BAA9-4266FD[asmend.exe]
Adware:Adware/MSView No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\26E39A8E-5679-47A3-967F-2B6D3B\B44B9D1C-F27F-4474-9254-914057
Adware:Adware/InstaFinder No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\38A88E24-F777-4B77-B011-3B5F45\37E8D4B2-0F05-4B5D-846B-8E8A56
Adware:Adware/MyWay No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\62D851C8-6263-4F33-B43B-CCE57E\A957F6ED-365B-4510-B742-664F87
Adware:Adware/MyWay No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\79DB9F22-1B5E-44EF-8560-27517F\6DFBF217-D82A-484C-B47E-355989
Adware:Adware/P2PNetworking No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\8061A45F-594A-4531-BE21-DACB02\0FCC5CFB-E7F4-4E44-A4B7-0533C7
Adware:Adware/P2PNetworking No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\8061A45F-594A-4531-BE21-DACB02\2363F935-D070-445D-85A9-FB7418
Adware:Adware/P2PNetworking No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\8061A45F-594A-4531-BE21-DACB02\2E408893-9621-427E-A2B2-03B33A
Adware:Adware/P2PNetworking No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\8061A45F-594A-4531-BE21-DACB02\4EF4204A-F472-406F-AC07-263679
Adware:Adware/Medload No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\8061A45F-594A-4531-BE21-DACB02\5D53FC52-0EFB-4EC7-BEE8-3218CF
Adware:Adware/P2PNetworking No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\8061A45F-594A-4531-BE21-DACB02\68A0BA8D-D254-4E75-8B2F-528608
Adware:Adware/P2PNetworking No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\8061A45F-594A-4531-BE21-DACB02\74C8DE8D-258D-479F-97F4-9C725F
Adware:Adware/P2PNetworking No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\8061A45F-594A-4531-BE21-DACB02\9377129E-73F3-48C8-90C2-6D998C
Adware:Adware/P2PNetworking No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\8061A45F-594A-4531-BE21-DACB02\E48842EB-41A6-4756-9225-CD6A7E
Adware:Adware/P2PNetworking No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\8061A45F-594A-4531-BE21-DACB02\EF82B114-25AB-47A7-9D15-7447EB
Adware:Adware/MyWay No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\9D2688BD-AE77-4233-A938-B71A8B\51D02FAD-C9A4-4673-AF10-10236D
Adware:Adware/MyWay No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\9D2688BD-AE77-4233-A938-B71A8B\CCDC6BFC-FCDE-4282-942A-F5DC20
Adware:Adware/Medload No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\C34FC78C-A7FF-43B4-A6B0-2216AF\B5B9628E-BCC0-4161-A9CE-EBA1FF
Adware:Adware/VirtualBouncer No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\E06A5280-F03D-4F7A-B49A-255E28\EE808BEB-58D2-477B-9EF3-C1026F
Adware:Adware/Antivirus-gold No disinfected C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\82F65484-5FEC-439C-8B2F-E1593D\9B332885-A7CB-488B-9F5C-60090B
Adware:Adware/SearchAid No disinfected C:\WINDOWS\d3ub.exe
Adware:Adware/PopCapLoader No disinfected C:\WINDOWS\Downloaded Program Files\popcaploader.dll
Adware:Adware/PopCapLoader No disinfected C:\WINDOWS\Downloaded Program Files\popcaploader.inf
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\fahic.dll.tcf
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\gqisx.dll.tcf
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\hdaeo.dll.tcf
Spyware

pyware/BetterInet No disinfected C:\WINDOWS\INF\biini.inf
Adware:Adware/Transponder No disinfected C:\WINDOWS\INF\polmx2.inf
Adware:Adware/SearchAid No disinfected C:\WINDOWS\ipmo.exe
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\jvhqb.dll.tcf
Adware:Adware/WinTools No disinfected C:\WINDOWS\Key2.txt
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\likqa.dll.tcf
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\nbntv.dll.tcf
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\rvqak.dll.tcf
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\sedgh.dll.tcf
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\SYSTEM32\akuda.dll.tcf
Adware:Adware/SearchAid No disinfected C:\WINDOWS\SYSTEM32\appxd32.exe
Adware:Adware/SearchAid No disinfected C:\WINDOWS\SYSTEM32\atlxd.exe
Spyware

pyware/ClearSearch No disinfected C:\WINDOWS\SYSTEM32\ClrSchP012.dll
Spyware

pyware/ClearSearch No disinfected C:\WINDOWS\SYSTEM32\ClrSchP0121.dll
Spyware

pyware/BargainBuddy No disinfected C:\WINDOWS\SYSTEM32\cm1.dll
Spyware

pyware/Whazit No disinfected C:\WINDOWS\SYSTEM32\fiz1
Spyware

pyware/BargainBuddy No disinfected C:\WINDOWS\SYSTEM32\fly.dll
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\SYSTEM32\gchui.dll.tcf
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\SYSTEM32\hbpif.dll.tcf
Adware:Adware/Specofer No disinfected C:\WINDOWS\SYSTEM32\httppost.exe
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\SYSTEM32\hwgei.dll.tcf
Spyware

pyware/BargainBuddy No disinfected C:\WINDOWS\SYSTEM32\ignet.dll
Spyware

pyware/BargainBuddy No disinfected C:\WINDOWS\SYSTEM32\ignet2.dll
Adware:Adware/SearchAid No disinfected C:\WINDOWS\SYSTEM32\ipbh.exe
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\SYSTEM32\kcdsy.dll.tcf
Spyware

pyware/Whazit No disinfected C:\WINDOWS\SYSTEM32\kyf.dat
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\SYSTEM32\kzxjg.dll.tcf
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\SYSTEM32\maaxt.dll.tcf
Adware:Adware/SearchAid No disinfected C:\WINDOWS\SYSTEM32\mfcbz.exe
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM32\msss.exe
Adware:Adware/TalkStocks No disinfected C:\WINDOWS\SYSTEM32\mstbl.ocx
Spyware

pyware/BetterInet No disinfected C:\WINDOWS\SYSTEM32\MSView.exe
Adware:Adware/nCase No disinfected C:\WINDOWS\SYSTEM32\ncase.dll
Adware:Adware/nCase No disinfected C:\WINDOWS\SYSTEM32\ncase2.dll
Spyware

pyware/BargainBuddy No disinfected C:\WINDOWS\SYSTEM32\NLNupgradeV4_5P13.exe
Adware:Adware/MSView No disinfected C:\WINDOWS\SYSTEM32\nostalgia.dll
Spyware

pyware/BargainBuddy No disinfected C:\WINDOWS\SYSTEM32\OMsetup.exe
Adware:Adware/RCSync No disinfected C:\WINDOWS\SYSTEM32\pr1ze5.dll.tcf
Adware:Adware/RCSync No disinfected C:\WINDOWS\SYSTEM32\pr1ze5.dlltmp
Adware:Adware/RCSync No disinfected C:\WINDOWS\SYSTEM32\prizesurfer_setup.exe
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\SYSTEM32\qgcok.dll.tcf
Adware:Adware/SAHAgent No disinfected C:\WINDOWS\SYSTEM32\sahagent1003.exe
Adware:Adware/SAHAgent No disinfected C:\WINDOWS\SYSTEM32\SHAgent.dll
Adware:Adware/SAHAgent No disinfected C:\WINDOWS\SYSTEM32\SHAgent1007.dll.tcf
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\SYSTEM32\vkhzp.dll.tcf
Adware:Adware/MyWay No disinfected C:\WINDOWS\SYSTEM32\Xcite.dll
Adware:Adware/MyWay No disinfected C:\WINDOWS\SYSTEM32\Xcite.exe
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\SYSTEM32\xexaf.dll.tcf
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\SYSTEM32\ytrgd.dll
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\ucval.dll.tcf
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\xjjgm.dll.tcf
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\xktsb.dll.tcf
Adware:Adware/Startpage.VQ No disinfected C:\WINDOWS\yvmot.dll.tcf