Guestolo,
Sorry about running the wrong version of Hijackthis.
Here's my correct log:
Logfile of HijackThis v1.99.1
Scan saved at 8:57:46 PM, on 11/10/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\McAfee\McAfee Internet Security\GUARDDOG.EXE
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\PMJ151LA.BIN
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\McAfee\McAfee Firewall\CPD.EXE
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee\McAfee Internet Security\GUARDDOG.EXE
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\McAfee\McAfee Firewall\CPD.EXE
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE
C:\WINDOWS\System32\hphmon05.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe
C:\Program Files\McAfee\McAfee VirusScan\VSStat.exe
C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\macromed\flash\GetFlash.exe
C:\Program Files\Creative\MediaSource\RemoteControl\OSDMenu.EXE
C:\Program Files\Creative\MediaSource\RemoteControl\OSDEAX.exe
C:\WINDOWS\System32\wuauclt.exe
C:\unzipped\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.meshcomputers.comR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: McAfee VirusScan - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - C:\Program Files\McAfee\McAfee VirusScan\VSCShellExtension.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTDVDDET] C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
O4 - HKLM\..\Run: [Camera Detector] C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE -autorun
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\mcupdate.exe
O4 - HKLM\..\Run: [McAfee Guardian] "C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe" /SU
O4 - HKLM\..\Run: [VirusScanMSC] "C:\Program Files\McAfee\McAfee VirusScan\VSStat.exe" /EMBEDDING
O4 - HKLM\..\Run: [IFSplash] ImmSplsh.exe
O4 - HKCU\..\Run: [RemoteCenter] C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /STARTMONITOR
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Download all by Net Transport - C:\Program Files\Xi\NetTransport 2\NTAddList.html
O8 - Extra context menu item: Download by Net Transport - C:\Program Files\Xi\NetTransport 2\NTAddLink.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O10 - Broken Internet access because of LSP provider 'xfire_lsp_9028.dll' missing
O14 - IERESET.INF: START_PAGE_URL=http://www.meshcomputers.com
O16 - DPF: {03177121-226B-11D4-B0BE-005004AD3039} (UploaderCtrl Class) -
http://members14.clubphoto.com/_img/upload...tl_uploader.cabO16 - DPF: {08BEF711-06DA-48B2-9534-802ECAA2E4F9} (PlxInstall Class) -
http://down.plaxo.com/down/release/PlaxoInstall.cabO16 - DPF: {18D9C485-7EEC-4395-95DA-DC3875B10E81} (TEInstallPlugIn) -
http://www.skylinesoft.com/interactive/ter...stallPlugIn.cabO16 - DPF: {3a4f9191-65a8-11d5-85c1-0001023952c1} (TE) -
http://www.skylinesoft.com/interactive/ter.../install/TE.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cabO16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -
http://www.popcap.com/games/popcaploader_v6.cabO16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) -
http://fdl.msn.com/zone/datafiles/heartbeat.cabO16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) -
http://www.gamespot.com/KDX22/download/kdx.cabO23 - Service: AVSync Manager (AvSynMgr) - Network Associates, Inc. - C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: McAfee Internet Security (GuardDogEXE) - Unknown owner - C:\Program Files\McAfee\McAfee Internet Security\GUARDDOG.EXE" /SERVICE (file missing)
O23 - Service: McAfee Firewall - Unknown owner - C:\Program Files\McAfee\McAfee Firewall\CPD.EXE" /SERVICE (file missing)
O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PMJ151 AutoLaunch Service (PMJ151LA) - Matsu[censored]a Electric Industrial Co. ,Ltd, - C:\WINDOWS\PMJ151LA.BIN
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\WINDOWS\System32\x10nets.exe (file missing)
And here's the log a run under my wife's profile:
Logfile of HijackThis v1.99.1
Scan saved at 8:56:41 PM, on 11/10/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\McAfee\McAfee Internet Security\GUARDDOG.EXE
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\PMJ151LA.BIN
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\McAfee\McAfee Firewall\CPD.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee\McAfee Internet Security\GUARDDOG.EXE
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
C:\Program Files\McAfee\McAfee Firewall\CPD.EXE
C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE
C:\WINDOWS\System32\hphmon05.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe
C:\Program Files\McAfee\McAfee VirusScan\VSStat.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\Plaxo\2.1.0.80\InstallStub.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\system32\winlogon.exe
C:\Program Files\Creative\MediaSource\RemoteControl\OSDMenu.EXE
C:\Program Files\Creative\MediaSource\RemoteControl\OSDEAX.exe
C:\WINDOWS\System32\wuauclt.exe
C:\unzipped\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://69.50.191.52/1076/sp.phpR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://69.50.191.52/1076/R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.meshcomputers.comR1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://bestsearch.cc/1076/search.php?qq=R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Tiscali Internet Access
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: McAfee VirusScan - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - C:\Program Files\McAfee\McAfee VirusScan\VSCShellExtension.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTDVDDET] C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
O4 - HKLM\..\Run: [Camera Detector] C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE -autorun
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\mcupdate.exe
O4 - HKLM\..\Run: [McAfee Guardian] "C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe" /SU
O4 - HKLM\..\Run: [VirusScanMSC] "C:\Program Files\McAfee\McAfee VirusScan\VSStat.exe" /EMBEDDING
O4 - HKLM\..\Run: [IFSplash] ImmSplsh.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [SB Audigy 2 Startup Menu] C:\Program Files\Creative\SBAudigy2ZS\Program\Startup Menu\ChkColor.EXE
O4 - HKCU\..\Run: [RemoteCenter] C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [PlaxoUpdate] C:\WINDOWS\Plaxo\2.1.0.80\InstallStub.exe -a
O4 - HKCU\..\Run: [Imv] C:\WINDOWS\Lmn.exe
O4 - HKCU\..\Run: [Hoe] C:\WINDOWS\Ume.exe
O4 - HKCU\..\Run: [Nns] C:\WINDOWS\System32\Ifc.exe
O4 - HKCU\..\Run: [Clp] C:\WINDOWS\Luu.exe
O4 - HKCU\..\Run: [Hub] C:\WINDOWS\Hio.exe
O4 - HKCU\..\Run: [Sre] C:\WINDOWS\Iki.exe
O4 - HKCU\..\Run: [Sci] C:\WINDOWS\Lbq.exe
O4 - HKCU\..\Run: [Gja] C:\WINDOWS\Udh.exe
O4 - HKCU\..\Run: [Lds] C:\WINDOWS\Oje.exe
O4 - HKCU\..\Run: [Kcm] C:\WINDOWS\System32\Tkf.exe
O4 - HKCU\..\Run: [Mes] C:\WINDOWS\Niu.exe
O4 - HKCU\..\Run: [Sbk] C:\WINDOWS\System32\Flv.exe
O4 - HKCU\..\Run: [Jtn] C:\WINDOWS\Nro.exe
O4 - HKCU\..\Run: [Tao] C:\WINDOWS\System32\Akf.exe
O4 - HKCU\..\Run: [Klt] C:\WINDOWS\Nbe.exe
O4 - HKCU\..\Run: [Ohn] C:\WINDOWS\System32\Neg.exe
O4 - HKCU\..\Run: [Bou] C:\WINDOWS\System32\Kme.exe
O4 - HKCU\..\Run: [Jek] C:\WINDOWS\System32\Icv.exe
O4 - HKCU\..\Run: [Pia] C:\WINDOWS\System32\Vgh.exe
O4 - HKCU\..\Run: [Hea] C:\WINDOWS\System32\Ubt.exe
O4 - HKCU\..\Run: [Jgc] C:\WINDOWS\System32\Vct.exe
O4 - HKCU\..\Run: [Evh] C:\WINDOWS\Jre.exe
O4 - HKCU\..\Run: [Sju] C:\WINDOWS\System32\Uva.exe
O4 - HKCU\..\Run: [Uai] C:\WINDOWS\Lfa.exe
O4 - HKCU\..\Run: [Mkh] C:\WINDOWS\System32\Pji.exe
O4 - HKCU\..\Run: [Qrh] C:\WINDOWS\Hfs.exe
O4 - HKCU\..\Run: [Ijo] C:\WINDOWS\Qaj.exe
O4 - HKCU\..\Run: [Osi] C:\WINDOWS\System32\Eqo.exe
O4 - HKCU\..\Run: [Bno] C:\WINDOWS\System32\Maa.exe
O4 - HKCU\..\Run: [Vfg] C:\WINDOWS\System32\Vbo.exe
O4 - HKCU\..\Run: [Jks] C:\WINDOWS\System32\Gje.exe
O4 - HKCU\..\Run: [Npr] C:\WINDOWS\Rvo.exe
O4 - HKCU\..\Run: [Mpu] C:\WINDOWS\System32\Niv.exe
O4 - HKCU\..\Run: [Rcq] C:\WINDOWS\System32\Irh.exe
O4 - HKCU\..\Run: [Mjm] C:\WINDOWS\Uon.exe
O4 - HKCU\..\Run: [Peh] C:\WINDOWS\Mhn.exe
O4 - HKCU\..\Run: [Hlk] C:\WINDOWS\Qne.exe
O4 - HKCU\..\Run: [Tsl] C:\WINDOWS\Mti.exe
O4 - HKCU\..\Run: [Dqm] C:\WINDOWS\System32\Tcq.exe
O4 - HKCU\..\Run: [Fqd] C:\WINDOWS\Sat.exe
O4 - HKCU\..\Run: [Huv] C:\WINDOWS\Roc.exe
O4 - HKCU\..\Run: [Mqa] C:\WINDOWS\Jom.exe
O4 - HKCU\..\Run: [Evs] C:\WINDOWS\Nda.exe
O4 - HKCU\..\Run: [Gqu] C:\WINDOWS\Ngp.exe
O4 - HKCU\..\Run: [Cid] C:\WINDOWS\System32\Ess.exe
O4 - HKCU\..\Run: [Gis] C:\WINDOWS\Acp.exe
O4 - HKCU\..\Run: [Rps] C:\WINDOWS\System32\Dtm.exe
O4 - HKCU\..\Run: [Jea] C:\WINDOWS\System32\Hdp.exe
O4 - HKCU\..\Run: [Pnd] C:\WINDOWS\System32\Nff.exe
O4 - HKCU\..\Run: [Bku] C:\WINDOWS\System32\Sca.exe
O4 - HKCU\..\Run: [Pad] C:\WINDOWS\System32\Psj.exe
O4 - HKCU\..\Run: [Cbh] C:\WINDOWS\Qnf.exe
O4 - HKCU\..\Run: [Bnu] C:\WINDOWS\Evh.exe
O4 - HKCU\..\Run: [Eer] C:\WINDOWS\Rgm.exe
O4 - HKCU\..\Run: [Bkj] C:\WINDOWS\System32\Arb.exe
O4 - HKCU\..\Run: [Eka] C:\WINDOWS\System32\Omr.exe
O4 - HKCU\..\Run: [Vme] C:\WINDOWS\Hun.exe
O4 - HKCU\..\Run: [Tva] C:\WINDOWS\System32\Uuu.exe
O4 - HKCU\..\Run: [Acb] C:\WINDOWS\System32\Bnf.exe
O4 - HKCU\..\Run: [Ldl] C:\WINDOWS\Kma.exe
O4 - HKCU\..\Run: [Mbs] C:\WINDOWS\System32\Ejo.exe
O4 - HKCU\..\Run: [Scn] C:\WINDOWS\Ibv.exe
O4 - HKCU\..\Run: [Ovn] C:\WINDOWS\Fjg.exe
O4 - HKCU\..\Run: [Omr] C:\WINDOWS\Ooi.exe
O4 - HKCU\..\Run: [Fji] C:\WINDOWS\Dbg.exe
O4 - HKCU\..\Run: [Jjr] C:\WINDOWS\Cvc.exe
O4 - HKCU\..\Run: [Esh] C:\WINDOWS\Ldg.exe
O4 - HKCU\..\Run: [Dcs] C:\WINDOWS\Nqd.exe
O4 - HKCU\..\Run: [Irt] C:\WINDOWS\Sqi.exe
O4 - HKCU\..\Run: [Lsl] C:\WINDOWS\System32\Juj.exe
O4 - HKCU\..\Run: [Lbr] C:\WINDOWS\System32\Ncj.exe
O4 - HKCU\..\Run: [Omv] C:\WINDOWS\System32\Efp.exe
O4 - HKCU\..\Run: [Ssa] C:\WINDOWS\Ugd.exe
O4 - HKCU\..\Run: [Lnp] C:\WINDOWS\Ofo.exe
O4 - HKCU\..\Run: [Tda] C:\WINDOWS\Ugg.exe
O4 - HKCU\..\Run: [Hgd] C:\WINDOWS\System32\Rfn.exe
O4 - HKCU\..\Run: [Amh] C:\WINDOWS\Pvb.exe
O4 - HKCU\..\Run: [Ofj] C:\WINDOWS\Muk.exe
O4 - HKCU\..\Run: [Jvf] C:\WINDOWS\System32\Feo.exe
O4 - HKCU\..\Run: [Fsl] C:\WINDOWS\Crl.exe
O4 - HKCU\..\Run: [Tur] C:\WINDOWS\Jfi.exe
O4 - HKCU\..\Run: [Mdd] C:\WINDOWS\Hjh.exe
O4 - HKCU\..\Run: [Lqe] C:\WINDOWS\Psp.exe
O4 - HKCU\..\Run: [Nqi] C:\WINDOWS\System32\Pts.exe
O4 - HKCU\..\Run: [Msf] C:\WINDOWS\Jbp.exe
O4 - HKCU\..\Run: [Dlu] C:\WINDOWS\System32\Vud.exe
O4 - HKCU\..\Run: [Okf] C:\WINDOWS\Veb.exe
O4 - HKCU\..\Run: [Hem] C:\WINDOWS\System32\Hib.exe
O4 - HKCU\..\Run: [Rli] C:\WINDOWS\System32\Cdr.exe
O4 - HKCU\..\Run: [Qdl] C:\WINDOWS\Lph.exe
O4 - HKCU\..\Run: [Qip] C:\WINDOWS\System32\Hve.exe
O4 - HKCU\..\Run: [Quj] C:\WINDOWS\Urk.exe
O4 - HKCU\..\Run: [Dqo] C:\WINDOWS\Qlm.exe
O4 - HKCU\..\Run: [Vov] C:\WINDOWS\Pou.exe
O4 - HKCU\..\Run: [Fec] C:\WINDOWS\System32\Bdn.exe
O4 - HKCU\..\Run: [Tqi] C:\WINDOWS\Jho.exe
O4 - HKCU\..\Run: [Gak] C:\WINDOWS\System32\Dgb.exe
O4 - HKCU\..\Run: [Fgm] C:\WINDOWS\Ldi.exe
O4 - HKCU\..\Run: [Rev] C:\WINDOWS\Kdk.exe
O4 - HKCU\..\Run: [Pmv] C:\WINDOWS\Rps.exe
O4 - HKCU\..\Run: [Hiq] C:\WINDOWS\System32\Uuc.exe
O4 - HKCU\..\Run: [Mjp] C:\WINDOWS\Dkm.exe
O4 - HKCU\..\Run: [Tmu] C:\WINDOWS\System32\Ele.exe
O4 - HKCU\..\Run: [Nto] C:\WINDOWS\Rlc.exe
O4 - HKCU\..\Run: [Qah] C:\WINDOWS\Rbk.exe
O4 - HKCU\..\Run: [Eae] C:\WINDOWS\Bqn.exe
O4 - HKCU\..\Run: [Crq] C:\WINDOWS\System32\Rtg.exe
O4 - HKCU\..\Run: [Ebd] C:\WINDOWS\System32\Tuo.exe
O4 - HKCU\..\Run: [Cnk] C:\WINDOWS\Bvi.exe
O4 - HKCU\..\Run: [Hku] C:\WINDOWS\System32\Pch.exe
O4 - HKCU\..\Run: [Rmm] C:\WINDOWS\Ugq.exe
O4 - HKCU\..\Run: [Jqm] C:\WINDOWS\System32\Grl.exe
O4 - HKCU\..\Run: [Lru] C:\WINDOWS\System32\Tqf.exe
O4 - HKCU\..\Run: [Pob] C:\WINDOWS\Dgo.exe
O4 - HKCU\..\Run: [Rkk] C:\WINDOWS\Veq.exe
O4 - HKCU\..\Run: [Evd] C:\WINDOWS\Fik.exe
O4 - HKCU\..\Run: [Irq] C:\WINDOWS\System32\Rhh.exe
O4 - HKCU\..\Run: [Gtg] C:\WINDOWS\System32\Dlu.exe
O4 - HKCU\..\Run: [Gbt] C:\WINDOWS\Vss.exe
O4 - HKCU\..\Run: [Men] C:\WINDOWS\System32\Mfs.exe
O4 - HKCU\..\Run: [Cov] C:\WINDOWS\System32\Hir.exe
O4 - HKCU\..\Run: [Ntj] C:\WINDOWS\System32\Hai.exe
O4 - HKCU\..\Run: [Lud] C:\WINDOWS\System32\Rgr.exe
O4 - HKCU\..\Run: [Eko] C:\WINDOWS\System32\Grp.exe
O4 - HKCU\..\Run: [Stl] C:\WINDOWS\Ilr.exe
O4 - HKCU\..\Run: [Jnb] C:\WINDOWS\Obq.exe
O4 - HKCU\..\Run: [Ism] C:\WINDOWS\Mtk.exe
O4 - HKCU\..\Run: [Mdl] C:\WINDOWS\System32\Fvq.exe
O4 - HKCU\..\Run: [Nba] C:\WINDOWS\System32\Gst.exe
O4 - HKCU\..\Run: [Joo] C:\WINDOWS\Gja.exe
O4 - HKCU\..\Run: [Ajt] C:\WINDOWS\Jao.exe
O4 - HKCU\..\Run: [Oce] C:\WINDOWS\System32\Fjm.exe
O4 - HKCU\..\Run: [Skp] C:\WINDOWS\System32\Eol.exe
O4 - HKCU\..\Run: [Krb] C:\WINDOWS\System32\Tmj.exe
O4 - HKCU\..\Run: [Ifv] C:\WINDOWS\Hqn.exe
O4 - HKCU\..\Run: [Miu] C:\WINDOWS\Gsu.exe
O4 - HKCU\..\Run: [Iqj] C:\WINDOWS\System32\Rcf.exe
O4 - HKCU\..\Run: [Pjp] C:\WINDOWS\Glt.exe
O4 - HKCU\..\Run: [Bht] C:\WINDOWS\System32\Brq.exe
O4 - HKCU\..\Run: [Pok] C:\WINDOWS\Sja.exe
O4 - HKCU\..\Run: [Ljk] C:\WINDOWS\System32\Ava.exe
O4 - HKCU\..\Run: [Clv] C:\WINDOWS\Qeu.exe
O4 - HKCU\..\Run: [Ibn] C:\WINDOWS\Vje.exe
O4 - HKCU\..\Run: [Hlr] C:\WINDOWS\System32\Cna.exe
O4 - HKCU\..\Run: [Trj] C:\WINDOWS\Fst.exe
O4 - HKCU\..\Run: [Jps] C:\WINDOWS\Vnc.exe
O4 - HKCU\..\Run: [Gvv] C:\WINDOWS\Mah.exe
O4 - HKCU\..\Run: [Glt] C:\WINDOWS\System32\Hkm.exe
O4 - HKCU\..\Run: [Ivd] C:\WINDOWS\System32\Jit.exe
O4 - HKCU\..\Run: [Vgm] C:\WINDOWS\System32\Iok.exe
O4 - HKCU\..\Run: [Kqt] C:\WINDOWS\System32\Rkd.exe
O4 - HKCU\..\Run: [Dgp] C:\WINDOWS\Ffk.exe
O4 - HKCU\..\Run: [Svj] C:\WINDOWS\System32\Vfe.exe
O4 - HKCU\..\Run: [Gvb] C:\WINDOWS\Sko.exe
O4 - HKCU\..\Run: [Dan] C:\WINDOWS\Djk.exe
O4 - HKCU\..\Run: [Nng] C:\WINDOWS\System32\Hjt.exe
O4 - HKCU\..\Run: [Vrf] C:\WINDOWS\System32\Pne.exe
O4 - HKCU\..\Run: [Qbf] C:\WINDOWS\System32\Oek.exe
O4 - HKCU\..\Run: [Ijs] C:\WINDOWS\System32\Rto.exe
O4 - HKCU\..\Run: [Hds] C:\WINDOWS\System32\Som.exe
O4 - HKCU\..\Run: [Eun] C:\WINDOWS\System32\Utb.exe
O4 - HKCU\..\Run: [Mrd] C:\WINDOWS\Vor.exe
O4 - HKCU\..\Run: [Jvt] C:\WINDOWS\System32\Lot.exe
O4 - HKCU\..\Run: [Ver] C:\WINDOWS\System32\Ndc.exe
O4 - HKCU\..\Run: [Dct] C:\WINDOWS\System32\Sds.exe
O4 - HKCU\..\Run: [Kqi] C:\WINDOWS\Kss.exe
O4 - HKCU\..\Run: [Opj] C:\WINDOWS\System32\Ibr.exe
O4 - HKCU\..\Run: [Hht] C:\WINDOWS\System32\Mki.exe
O4 - HKCU\..\Run: [Gst] C:\WINDOWS\System32\Rhf.exe
O4 - HKCU\..\Run: [Nbp] C:\WINDOWS\System32\Vre.exe
O4 - HKCU\..\Run: [Pju] C:\WINDOWS\Fsk.exe
O4 - HKCU\..\Run: [Vim] C:\WINDOWS\System32\Ufn.exe
O4 - HKCU\..\Run: [Qfo] C:\WINDOWS\Bjd.exe
O4 - HKCU\..\Run: [Qmt] C:\WINDOWS\System32\Hgf.exe
O4 - HKCU\..\Run: [Fsn] C:\WINDOWS\Fic.exe
O4 - HKCU\..\Run: [Kpd] C:\WINDOWS\Evn.exe
O4 - HKCU\..\Run: [Ocr] C:\WINDOWS\System32\Por.exe
O4 - HKCU\..\Run: [Hdv] C:\WINDOWS\Rrf.exe
O4 - HKCU\..\Run: [Erk] C:\WINDOWS\System32\Jsb.exe
O4 - HKCU\..\Run: [Cng] C:\WINDOWS\Ffj.exe
O4 - HKCU\..\Run: [Fcb] C:\WINDOWS\Kpq.exe
O4 - HKCU\..\Run: [Frf] C:\WINDOWS\System32\Rpe.exe
O4 - HKCU\..\Run: [Bvr] C:\WINDOWS\Fun.exe
O4 - HKCU\..\Run: [Pma] C:\WINDOWS\System32\Gdt.exe
O4 - HKCU\..\Run: [Etr] C:\WINDOWS\Mep.exe
O4 - HKCU\..\Run: [Rjp] C:\WINDOWS\Igd.exe
O4 - HKCU\..\Run: [Boj] C:\WINDOWS\System32\Pnu.exe
O4 - HKCU\..\Run: [Obl] C:\WINDOWS\System32\Nli.exe
O4 - HKCU\..\Run: [Nem] C:\WINDOWS\System32\Pdh.exe
O4 - HKCU\..\Run: [Nnj] C:\WINDOWS\Nog.exe
O4 - HKCU\..\Run: [Lar] C:\WINDOWS\System32\Vvk.exe
O4 - HKCU\..\Run: [Npm] C:\WINDOWS\Mst.exe
O4 - HKCU\..\Run: [Tmq] C:\WINDOWS\System32\Uam.exe
O4 - HKCU\..\Run: [Kct] C:\WINDOWS\Hkk.exe
O4 - HKCU\..\Run: [Gml] C:\WINDOWS\Vea.exe
O4 - HKCU\..\Run: [Hfu] C:\WINDOWS\System32\Cft.exe
O4 - HKCU\..\Run: [Fef] C:\WINDOWS\Nff.exe
O4 - HKCU\..\Run: [Dao] C:\WINDOWS\System32\Sld.exe
O4 - HKCU\..\Run: [Csc] C:\WINDOWS\System32\Jtc.exe
O4 - HKCU\..\Run: [Hpn] C:\WINDOWS\Ehf.exe
O4 - HKCU\..\Run: [Tnc] C:\WINDOWS\System32\Rnl.exe
O4 - HKCU\..\Run: [Tkd] C:\WINDOWS\System32\Tfq.exe
O4 - HKCU\..\Run: [Cuf] C:\WINDOWS\Ijl.exe
O4 - HKCU\..\Run: [Ebk] C:\WINDOWS\System32\Vqr.exe
O4 - HKCU\..\Run: [Vep] C:\WINDOWS\System32\Rih.exe
O4 - HKCU\..\Run: [Odr] C:\WINDOWS\System32\Fti.exe
O4 - HKCU\..\Run: [Vsr] C:\WINDOWS\Ptp.exe
O4 - HKCU\..\Run: [Ker] C:\WINDOWS\System32\Olh.exe
O4 - HKCU\..\Run: [Oaa] C:\WINDOWS\System32\Ukl.exe
O4 - HKCU\..\Run: [Tod] C:\WINDOWS\Buc.exe
O4 - HKCU\..\Run: [Eed] C:\WINDOWS\System32\Lpi.exe
O4 - HKCU\..\Run: [Oae] C:\WINDOWS\System32\Geq.exe
O4 - HKCU\..\Run: [Sfb] C:\WINDOWS\System32\Fem.exe
O4 - HKCU\..\Run: [Hba] C:\WINDOWS\Tpm.exe
O4 - HKCU\..\Run: [Tup] C:\WINDOWS\Hcu.exe
O4 - HKCU\..\Run: [Ljh] C:\WINDOWS\Bun.exe
O4 - HKCU\..\Run: [Mlm] C:\WINDOWS\System32\Fdt.exe
O4 - HKCU\..\Run: [Jsr] C:\WINDOWS\System32\Uem.exe
O4 - HKCU\..\Run: [Erm] C:\WINDOWS\Min.exe
O4 - HKCU\..\Run: [Rar] C:\WINDOWS\System32\Vba.exe
O4 - HKCU\..\Run: [Vkl] C:\WINDOWS\Jfo.exe
O4 - HKCU\..\Run: [Ukv] C:\WINDOWS\System32\Gqr.exe
O4 - HKCU\..\Run: [Ace] C:\WINDOWS\Jjn.exe
O4 - HKCU\..\Run: [Llq] C:\WINDOWS\Nat.exe
O4 - HKCU\..\Run: [Qce] C:\WINDOWS\Uoj.exe
O4 - HKCU\..\Run: [Pmg] C:\WINDOWS\Erc.exe
O4 - HKCU\..\Run: [Jog] C:\WINDOWS\Dvd.exe
O4 - HKCU\..\Run: [Pba] C:\WINDOWS\System32\Iol.exe
O4 - HKCU\..\Run: [Vau] C:\WINDOWS\System32\Mpf.exe
O4 - HKCU\..\Run: [Gub] C:\WINDOWS\Rtf.exe
O4 - HKCU\..\Run: [Sjt] C:\WINDOWS\System32\Luc.exe
O4 - HKCU\..\Run: [Mel] C:\WINDOWS\Tch.exe
O4 - HKCU\..\Run: [Nal] C:\WINDOWS\System32\Ipc.exe
O4 - HKCU\..\Run: [Nok] C:\WINDOWS\Ial.exe
O4 - HKCU\..\Run: [Pto] C:\WINDOWS\Dda.exe
O4 - HKCU\..\Run: [Tko] C:\WINDOWS\Bfi.exe
O4 - HKCU\..\Run: [Ugl] C:\WINDOWS\System32\Vbg.exe
O4 - HKCU\..\Run: [Brm] C:\WINDOWS\System32\Oaq.exe
O4 - HKCU\..\Run: [Fio] C:\WINDOWS\Agb.exe
O4 - HKCU\..\Run: [Ohe] C:\WINDOWS\Rvu.exe
O4 - HKCU\..\Run: [Gut] C:\WINDOWS\Qbj.exe
O4 - HKCU\..\Run: [Iuu] C:\WINDOWS\Lkp.exe
O4 - HKCU\..\Run: [Cre] C:\WINDOWS\System32\Adk.exe
O4 - HKCU\..\Run: [Oqe] C:\WINDOWS\System32\Qut.exe
O4 - HKCU\..\Run: [Nci] C:\WINDOWS\Ejj.exe
O4 - HKCU\..\Run: [Fmn] C:\WINDOWS\Hnu.exe
O4 - HKCU\..\Run: [Pni] C:\WINDOWS\Uve.exe
O4 - HKCU\..\Run: [Qak] C:\WINDOWS\System32\Joo.exe
O4 - HKCU\..\Run: [Gpk] C:\WINDOWS\Fpn.exe
O4 - HKCU\..\Run: [Ntr] C:\WINDOWS\Fpc.exe
O4 - HKCU\..\Run: [Fjv] C:\WINDOWS\System32\Nbn.exe
O4 - HKCU\..\Run: [Fce] C:\WINDOWS\Hph.exe
O4 - HKCU\..\Run: [Gjs] C:\WINDOWS\System32\Jld.exe
O4 - HKCU\..\Run: [Rfb] C:\WINDOWS\System32\Vhh.exe
O4 - HKCU\..\Run: [Ihq] C:\WINDOWS\Uvh.exe
O4 - HKCU\..\Run: [Tvk] C:\WINDOWS\Llv.exe
O4 - HKCU\..\Run: [Afe] C:\WINDOWS\System32\Api.exe
O4 - HKCU\..\Run: [Pkd] C:\WINDOWS\Hor.exe
O4 - HKCU\..\Run: [Gvc] C:\WINDOWS\Lnc.exe
O4 - HKCU\..\Run: [Uub] C:\WINDOWS\Ark.exe
O4 - HKCU\..\Run: [Ugp] C:\WINDOWS\Mbo.exe
O4 - HKCU\..\Run: [Rbb] C:\WINDOWS\Eug.exe
O4 - HKCU\..\Run: [Udk] C:\WINDOWS\Opa.exe
O4 - HKCU\..\Run: [Htk] C:\WINDOWS\System32\Atd.exe
O4 - HKCU\..\Run: [Gsd] C:\WINDOWS\Scd.exe
O4 - HKCU\..\Run: [Bdm] C:\WINDOWS\System32\Lev.exe
O4 - HKCU\..\Run: [Utp] C:\WINDOWS\System32\Ikf.exe
O4 - HKCU\..\Run: [Qqf] C:\WINDOWS\Oun.exe
O4 - HKCU\..\Run: [Nuf] C:\WINDOWS\Rhp.exe
O4 - HKCU\..\Run: [Jji] C:\WINDOWS\Cjc.exe
O4 - HKCU\..\Run: [Aki] C:\WINDOWS\System32\Sbg.exe
O4 - HKCU\..\Run: [Jcl] C:\WINDOWS\System32\Ihv.exe
O4 - HKCU\..\Run: [Mcc] C:\WINDOWS\Vmq.exe
O4 - HKCU\..\Run: [Kui] C:\WINDOWS\Bjh.exe
O4 - HKCU\..\Run: [Unk] C:\WINDOWS\Kqc.exe
O4 - HKCU\..\Run: [Fgv] C:\WINDOWS\System32\Usr.exe
O4 - HKCU\..\Run: [Stv] C:\WINDOWS\System32\Egl.exe
O4 - HKCU\..\Run: [Sth] C:\WINDOWS\System32\Pro.exe
O4 - HKCU\..\Run: [Pei] C:\WINDOWS\Bqp.exe
O4 - HKCU\..\Run: [Qmb] C:\WINDOWS\System32\Prs.exe
O4 - HKCU\..\Run: [Jlq] C:\WINDOWS\Kpp.exe
O4 - HKCU\..\Run: [Avp] C:\WINDOWS\Nlp.exe
O4 - HKCU\..\Run: [Lpi] C:\WINDOWS\Dqo.exe
O4 - HKCU\..\Run: [Iar] C:\WINDOWS\System32\Chb.exe
O4 - HKCU\..\Run: [Igo] C:\WINDOWS\System32\Ctt.exe
O4 - HKCU\..\Run: [Aak] C:\WINDOWS\Efv.exe
O4 - HKCU\..\Run: [Son] C:\WINDOWS\Ghd.exe
O4 - HKCU\..\Run: [Dep] C:\WINDOWS\Vpi.exe
O4 - HKCU\..\Run: [Lto] C:\WINDOWS\Naj.exe
O4 - HKCU\..\Run: [Svh] C:\WINDOWS\Nht.exe
O4 - HKCU\..\Run: [Hou] C:\WINDOWS\Bcn.exe
O4 - HKCU\..\Run: [Isj] C:\WINDOWS\Upu.exe
O4 - HKCU\..\Run: [Bsn] C:\WINDOWS\Imj.exe
O4 - HKCU\..\Run: [Qcc] C:\WINDOWS\Hvn.exe
O4 - HKCU\..\Run: [Vvp] C:\WINDOWS\Hct.exe
O4 - HKCU\..\Run: [Ttn] C:\WINDOWS\Bpv.exe
O4 - HKCU\..\Run: [Gah] C:\WINDOWS\Qvt.exe
O4 - HKCU\..\Run: [Pjv] C:\WINDOWS\Ebg.exe
O4 - HKCU\..\Run: [Qgl] C:\WINDOWS\Bhb.exe
O4 - HKCU\..\Run: [Vfd] C:\WINDOWS\Gha.exe
O4 - HKCU\..\Run: [Qol] C:\WINDOWS\Jid.exe
O4 - HKCU\..\Run: [Fag] C:\WINDOWS\System32\Sme.exe
O4 - HKCU\..\Run: [Peo] C:\WINDOWS\Bms.exe
O4 - HKCU\..\Run: [Lhd] C:\WINDOWS\System32\Ktc.exe
O4 - HKCU\..\Run: [Mjr] C:\WINDOWS\Dch.exe
O4 - HKCU\..\Run: [Knl] C:\WINDOWS\System32\Qlg.exe
O4 - HKCU\..\Run: [Emp] C:\WINDOWS\System32\Ord.exe
O4 - HKCU\..\Run: [Aru] C:\WINDOWS\Hpk.exe
O4 - HKCU\..\Run: [Jcn] C:\WINDOWS\System32\Iqg.exe
O4 - HKCU\..\Run: [Rlf] C:\WINDOWS\System32\Knn.exe
O4 - HKCU\..\Run: [Kjv] C:\WINDOWS\Mqq.exe
O4 - HKCU\..\Run: [Vda] C:\WINDOWS\Gqi.exe
O4 - HKCU\..\Run: [Tfk] C:\WINDOWS\System32\Vjl.exe
O4 - HKCU\..\Run: [Eob] C:\WINDOWS\System32\Tms.exe
O4 - HKCU\..\Run: [Eav] C:\WINDOWS\System32\Nnr.exe
O4 - HKCU\..\Run: [Vil] C:\WINDOWS\Npt.exe
O4 - HKCU\..\Run: [Fvi] C:\WINDOWS\Tik.exe
O4 - HKCU\..\Run: [Ifl] C:\WINDOWS\Kln.exe
O4 - HKCU\..\Run: [Old] C:\WINDOWS\Lol.exe
O4 - HKCU\..\Run: [Jao] C:\WINDOWS\System32\Ehi.exe
O4 - HKCU\..\Run: [Mte] C:\WINDOWS\Rtl.exe
O4 - HKCU\..\Run: [Qrm] C:\WINDOWS\System32\Lrk.exe
O4 - HKCU\..\Run: [Dfi] C:\WINDOWS\Usa.exe
O4 - HKCU\..\Run: [Tih] C:\WINDOWS\Nio.exe
O4 - HKCU\..\Run: [Ssc] C:\WINDOWS\Idp.exe
O4 - HKCU\..\Run: [Uqt] C:\WINDOWS\Ton.exe
O4 - HKCU\..\Run: [Bjd] C:\WINDOWS\System32\Qch.exe
O4 - HKCU\..\Run: [Uhb] C:\WINDOWS\System32\Ktt.exe
O4 - HKCU\..\Run: [Eti] C:\WINDOWS\System32\Qae.exe
O4 - HKCU\..\Run: [Gpb] C:\WINDOWS\System32\Vsq.exe
O4 - HKCU\..\Run: [Olf] C:\WINDOWS\Bfc.exe
O4 - HKCU\..\Run: [Ecp] C:\WINDOWS\Giu.exe
O4 - HKCU\..\Run: [Ere] C:\WINDOWS\System32\Fua.exe
O4 - HKCU\..\Run: [Sqv] C:\WINDOWS\System32\Pts.exe
O4 - HKCU\..\Run: [Obq] C:\WINDOWS\System32\Kvc.exe
O4 - HKCU\..\Run: [Kaj] C:\WINDOWS\Ivn.exe
O4 - HKCU\..\Run: [IDMan] C:\PROGRA~1\INTERN~2\IDMan.exe /onboot
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Search -
http://bar.mywebsearch.com/menusearch.html?p=ZSzeb033O8 - Extra context menu item: Download All Links with IDM - C:\PROGRA~1\INTERN~2\IEGetAll.htm
O8 - Extra context menu item: Download with IDM - C:\PROGRA~1\INTERN~2\IEExt.htm
O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O10 - Broken Internet access because of LSP provider 'xfire_lsp_9028.dll' missing
O14 - IERESET.INF: START_PAGE_URL=http://www.meshcomputers.com
O16 - DPF: {03177121-226B-11D4-B0BE-005004AD3039} (UploaderCtrl Class) -
http://members14.clubphoto.com/_img/upload...tl_uploader.cabO16 - DPF: {08BEF711-06DA-48B2-9534-802ECAA2E4F9} (PlxInstall Class) -
http://down.plaxo.com/down/release/PlaxoInstall.cabO16 - DPF: {18D9C485-7EEC-4395-95DA-DC3875B10E81} (TEInstallPlugIn) -
http://www.skylinesoft.com/interactive/ter...stallPlugIn.cabO16 - DPF: {3a4f9191-65a8-11d5-85c1-0001023952c1} (TE) -
http://www.skylinesoft.com/interactive/ter.../install/TE.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cabO16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -
http://www.popcap.com/games/popcaploader_v6.cabO16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) -
http://fdl.msn.com/zone/datafiles/heartbeat.cabO16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) -
http://www.gamespot.com/KDX22/download/kdx.cabO23 - Service: AVSync Manager (AvSynMgr) - Network Associates, Inc. - C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: McAfee Internet Security (GuardDogEXE) - Unknown owner - C:\Program Files\McAfee\McAfee Internet Security\GUARDDOG.EXE" /SERVICE (file missing)
O23 - Service: McAfee Firewall - Unknown owner - C:\Program Files\McAfee\McAfee Firewall\CPD.EXE" /SERVICE (file missing)
O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PMJ151 AutoLaunch Service (PMJ151LA) - Matsu[censored]a Electric Industrial Co. ,Ltd, - C:\WINDOWS\PMJ151LA.BIN
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\WINDOWS\System32\x10nets.exe (file missing)
Seems there's lots here that needs checking!!
Here's the result from Rootkitrevealer:
HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32* 9/4/2005 3:16 PM 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32* 9/4/2005 3:16 PM 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32* 9/4/2005 3:16 PM 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32* 9/4/2005 3:16 PM 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32* 9/4/2005 3:16 PM 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32* 9/4/2005 3:16 PM 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32* 9/4/2005 3:16 PM 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32* 9/4/2005 3:16 PM 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32* 9/4/2005 3:16 PM 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32* 9/4/2005 3:16 PM 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32* 9/4/2005 3:16 PM 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32* 9/4/2005 3:16 PM 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Sonic Desktop Software\Common\LibraryFilesFolder 9/5/2005 6:24 PM 87 bytes Data mismatch between Windows API and raw hive data.
Thanks again,
Jarcy