I didn't started the TDS-3 scan in safe mode, had to do some work related stuff and broke my concentration on your instructions. Hope it didn't set your efforts back. I ran it a 2nd time in safe mode so I provided both scans. The 1st run identified several "positive IDs, the 2nd identified 3. These log showed the machine was a "flea ravaged mut"!
TDS-3 logs:
!st logScan Control Dumped @ 23:10:54 31-05-05
Positive identification: TrojanClicker.Win32.Spywad.b
File: c:\windows\system32\bdd.exe
Suspicious Filename: HTA file in suspicious location
File: c:\msupdate.hta
Positive identification: TrojanClicker.Win32.Spywad.b
File: c:\!submit\bnu.exe
Suspicious Filename: Dual extensions
File: c:\documents and settings\munchie\desktop\worksheet scrap '50 ...'.shs
Suspicious Filename: Dual extensions
File: c:\program files\bittorrent-3.4.1.exe
Positive identification (DLL): Adware.Apropos.e (dll)
File: c:\program files\cxtpls\cxtpls.dll
Positive identification (DLL): Adware.Apropos.f (dll)
File: c:\program files\cxtpls\wingenerics.dll
Positive identification (DLL): TrojanDownloader.Win32.Agent.ex11 (dll)
File: c:\program files\hjt\backups\backup-20050524-215836-566.dll
Suspicious Filename: Dual extensions
File: c:\program files\hp\digital imaging\hpis\temp\install.wse.exe
Suspicious Filename: Dual extensions
File: c:\program files\ripper\setupdvddecrypter_3.5.1.0.exe
Positive identification (DLL): TrojanDownloader.Win32.Agent.lz (dll)
File: c:\windows\apiat.dll
Positive identification: Trojan.Win32.Agent.bi2
File: c:\windows\crfn32.exe
Positive identification: TrojanClicker.Win32.Spywad.b
File: c:\windows\hku.exe
Positive identification: Adware.Toolbar.UCMore Dropper.e
File: c:\windows\iemenuextension.exe
Positive identification: Trojan.Win32.Agent.bi2
File: c:\windows\iprs32.exe
Positive identification: Trojan.Win32.Agent.bi2
File: c:\windows\javayo32.exe
Positive identification: TrojanClicker.Win32.Spywad.b
File: c:\windows\juf.exe
Positive identification: TrojanClicker.Win32.Spywad.b
File: c:\windows\kho.exe
Positive identification (DLL): TrojanDownloader.Win32.Agent.lz (dll)
File: c:\windows\mfcoa32.dll
Positive identification (DLL): TrojanDownloader.Win32.Agent.ne (dll)
File: c:\windows\ntjk.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\sysys.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\wingd32.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\winpj32.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\winrf32.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\winum.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\winuz32.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\winwh.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\winyv32.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\winzl.dll
Positive identification (DLL): TrojanDownloader.Win32.Agent.lz (dll)
File: c:\windows\system32\addke.dll
Positive identification: TrojanClicker.Win32.Spywad.b
File: c:\windows\system32\aip.exe
Positive identification: TrojanClicker.Win32.Spywad.b
File: c:\windows\system32\bdd.exe
Positive identification: Trojan.Win32.Agent.bi2
File: c:\windows\system32\d3ap.exe
Positive identification: TrojanClicker.Win32.Spywad.b
File: c:\windows\system32\die.exe
Positive identification: TrojanClicker.Win32.Spywad.b
File: c:\windows\system32\eno.exe
Positive identification: TrojanClicker.Win32.Spywad.b
File: c:\windows\system32\ern.exe
Positive identification: TrojanClicker.Win32.Spywad.b
File: c:\windows\system32\fgl.exe
Positive identification: TrojanClicker.Win32.Spywad.b
File: c:\windows\system32\ieq.exe
Positive identification: Trojan.Win32.Agent.bi2
File: c:\windows\system32\javarg32.exe
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\mssh32.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\msst.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\mstm32.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\msum.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\mswf32.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\msxr32.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\netbi.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\netbr.dll
Positive identification: Trojan.Win32.Agent.bi1
File: c:\windows\system32\netda.exe
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\netge32.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\netiy.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\netlp.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\netpx.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\netrg32.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\nettb32.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\nettr.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\netuj32.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\netur32.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\netwz32.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\netyv32.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\ntah.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\ntdb.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\ntfs.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\nthw32.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\ntme32.dll
Positive identification: Trojan.Win32.Agent.bi2
File: c:\windows\system32\ntmo.exe
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\ntre32.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\ntvu.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\ntwm.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\ntxa32.dll
Positive identification: TrojanDownloader.Win32.Agent.bq17
File: c:\windows\system32\ntxf.exe
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\ntxk.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\ntxq.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\ntyd.dll
Positive identification: TrojanClicker.Win32.Small.ed1
File: c:\windows\system32\open32_uninstall.exe
Positive identification: TrojanClicker.Win32.Spywad.b
File: c:\windows\system32\ppc.exe
Positive identification: Adware.Sahat.o3
File: c:\windows\system32\q17i9a4j.exe
Positive identification (DLL): Adware.Sahat.l (dll)
File: c:\windows\system32\qh4mkbv9.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\sdkba32.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\sdkcu.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\sdkdl.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\sdked32.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\sdkkt32.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\sdkmh.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\sdkmk32.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\sdkoo32.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\sdkps32.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\sdkrb32.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\sdkrh32.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\sdkwp32.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\sdkzv.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\sdkzy32.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\sysao.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\sysap.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\sysci32.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\sysij.dll
Positive identification (DLL): TrojanDownloader.Win32.Agent.lz (dll)
File: c:\windows\system32\sysiw32.dll
Positive identification (DLL): TrojanDownloader.Win32.Agent.lz (dll)
File: c:\windows\system32\sysng32.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\sysoa.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\sysrm32.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\sysry32.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\sysso32.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\systp32.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\sysua.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\sysvn32.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\syswe32.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\sysxo.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\sysym.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\winbj.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\winho32.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\winir.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\winms.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\winnq32.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\winpo32.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\winrj.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\winvz32.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\winye.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\winzf.dll
Positive identification (DLL): TrojanDropper.Win32.Small.tn1 (dll)
File: c:\windows\system32\winzf32.dll
2nd logScan Control Dumped @ 00:26:54 01-06-05
Suspicious Filename: HTA file in suspicious location
File: c:\msupdate.hta
Suspicious Filename: Dual extensions
File: c:\documents and settings\munchie\desktop\worksheet scrap '50 ...'.shs
Suspicious Filename: Dual extensions
File: c:\program files\bittorrent-3.4.1.exe
Suspicious Filename: Dual extensions
File: c:\program files\hp\digital imaging\hpis\temp\install.wse.exe
Suspicious Filename: Dual extensions
File: c:\program files\ripper\setupdvddecrypter_3.5.1.0.exe
Positive identification: TrojanClicker.Win32.Spywad.b
File: c:\windows\ljh.exe
Positive identification: TrojanClicker.Win32.Spywad.b
File: c:\windows\system32\thl.exe
Here is the RKFiles.log:C:\Program Files\SPYGUARD\rkfiles
PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, THERE MIGHT BE LEGIT FILES LISTED AND PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
Files Found in system Folder............
------------------------
C:\WINDOWS\system32\dfrg.msc: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAQAAAAAwGpEc213
Files Found in all users startup Folder............
------------------------
Files Found in all users windows Folder............
------------------------
Finished
bye
Here is the HJT log:Logfile of HijackThis v1.99.1
Scan saved at 12:30:10 AM, on 6/1/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\SPYGUARD\AVWUPSRV.EXE
C:\Program Files\SPYGUARD\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\HP\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\HP\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\HJT\hijackthis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O1 - Hosts: 64.91.255.87
www.dcsresearch.comO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\HP\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Egd] C:\WINDOWS\System32\Aip.exe
O4 - HKLM\..\Run: [Men] C:\WINDOWS\Kho.exe
O4 - HKLM\..\Run: [Oem] C:\WINDOWS\System32\Eno.exe
O4 - HKLM\..\Run: [Nhr] C:\WINDOWS\System32\Die.exe
O4 - HKLM\..\Run: [Jbc] C:\WINDOWS\System32\Bdd.exe
O4 - HKLM\..\Run: [Nke] C:\WINDOWS\System32\Ieq.exe
O4 - HKLM\..\Run: [Qol] C:\WINDOWS\System32\Fgl.exe
O4 - HKLM\..\Run: [Idc] C:\WINDOWS\System32\Ppc.exe
O4 - HKLM\..\Run: [Djo] C:\WINDOWS\System32\Ern.exe
O4 - HKLM\..\Run: [Vcg] C:\WINDOWS\Hku.exe
O4 - HKLM\..\Run: [Ulh] C:\WINDOWS\Juf.exe
O4 - HKLM\..\Run: [Rfd] C:\WINDOWS\System32\Thl.exe
O4 - HKLM\..\Run: [Oog] C:\WINDOWS\Ljh.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [Egd] C:\WINDOWS\System32\Aip.exe
O4 - HKCU\..\Run: [Men] C:\WINDOWS\Kho.exe
O4 - HKCU\..\Run: [Jbc] C:\WINDOWS\System32\Bdd.exe
O4 - HKCU\..\Run: [Qol] C:\WINDOWS\System32\Fgl.exe
O4 - HKCU\..\Run: [Idc] C:\WINDOWS\System32\Ppc.exe
O4 - HKCU\..\Run: [Djo] C:\WINDOWS\System32\Ern.exe
O4 - HKCU\..\Run: [Vcg] C:\WINDOWS\Hku.exe
O4 - HKCU\..\Run: [Ulh] C:\WINDOWS\Juf.exe
O4 - HKCU\..\Run: [Rfd] C:\WINDOWS\System32\Thl.exe
O4 - HKCU\..\Run: [Oog] C:\WINDOWS\Ljh.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) -
http://www.creative.com/su/ocx/12119/CTSUEng.cabO16 - DPF: {15B782AF-55D8-11D1-B477-006097098764} (Macromedia Authorware Web Player Control) -
http://www.phgenit.com/plugin/awarewebplay...cab/awswaxf.cabO16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
http://a1540.g.akamai.net/7/1540/52/200312...meInstaller.exeO16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) -
https://www-secure.symantec.com/techsupp/ac...ta/SymAData.cabO16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) -
https://www-secure.symantec.com/techsupp/ac.../ActiveData.cabO16 - DPF: {ED6D016A-12F8-4871-BEDC-CE13AAAB4F0B} (DD_v4_Member.DDv4) -
http://www.drivershq.com/members/DD_v4_Member.CABO16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) -
http://www.creative.com/su/ocx/12119/CTPID.cabO23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\SPYGUARD\AVWUPSRV.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\SPYGUARD\ewido\security suite\ewidoctrl.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe