Downloaded and ran the new Spybot. It found the coolwwwsearch.aff.winshow again, but was able to delete this time. System is running a little slow, but I'm pretty positive it's the antivirus program. Here's the new DSS log:
Deckard's System Scanner v20071014.68
Run by Owner on 2008-06-14 01:10:12
Computer is in Normal Mode.
--------------------------------------------------------------------------------
[color=\"red\"]Total Physical Memory: 510 MiB (512 MiB recommended).[/color]
-- HijackThis (run as Owner.exe) -----------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:10:35 AM, on 6/14/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\system32\ps2.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\PROGRA~1\Firewall\OUTPOS~1\outpost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\WINDOWS\system32\msiexec.exe
C:\Documents and Settings\Owner\Desktop\dss.exe
C:\PROGRA~1\HIJACK~1\Owner.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Outpost Firewall] C:\PROGRA~1\Firewall\OUTPOS~1\outpost.exe /waitservice
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - .DEFAULT User Startup: AutoPlay.exe (User 'Default user')
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {321FB770-1FBE-4BFE-BDC1-6F622D4FA499} -
https://setup.bellsouth.net/wizlet/PWReset/...aller_6-1-2.cabO16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) -
http://lads.myspace.com/upload/MySpaceUploader1006.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/windowsupd...b?1213061818452O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) -
http://h20270.www2.hp.com/ediags/gmn2/inst...ctDetection.cabO23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: Outpost Firewall Service (OutpostFirewall) - Agnitum - C:\PROGRA~1\Firewall\OUTPOS~1\outpost.exe
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe
--
End of file - 3957 bytes
-- Files created between 2008-05-14 and 2008-06-14 -----------------------------
2008-06-14 01:02:00 0 dr-h----- C:\Documents and Settings\Owner\Recent
2008-06-12 17:29:23 0 d-------- C:\Program Files\Avira
2008-06-12 17:29:23 0 d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-06-12 17:05:40 0 d--hs---- \RECYCLER
2008-06-12 16:18:01 0 d-------- \QooBox
2008-06-12 16:18:00 68096 --a------ C:\WINDOWS\zip.exe
2008-06-12 16:18:00 49152 --a------ C:\WINDOWS\VFind.exe
2008-06-12 16:18:00 212480 --a------ C:\WINDOWS\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists>
2008-06-12 16:18:00 136704 --a------ C:\WINDOWS\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller>
2008-06-12 16:18:00 161792 --a------ C:\WINDOWS\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor>
2008-06-12 16:18:00 98816 --a------ C:\WINDOWS\sed.exe
2008-06-12 16:18:00 80412 --a------ C:\WINDOWS\grep.exe
2008-06-12 16:18:00 89504 --a------ C:\WINDOWS\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-06-12 15:55:14 534827008 --ahs---- \hiberfil.sys
2008-06-11 20:07:03 0 d-------- C:\Documents and Settings\Owner\Application Data\Malwarebytes
2008-06-11 20:07:00 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-11 20:07:00 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-11 18:58:53 0 d-------- C:\WINDOWS\ERUNT
2008-06-11 18:58:17 0 d-------- \SDFix
2008-06-11 17:54:23 0 d-------- \Deckard
2008-06-11 16:26:23 0 d-------- C:\Program Files\InterMute
2008-06-11 15:48:47 0 d-------- C:\Documents and Settings\Owner\Application Data\Key Metric Software
2008-06-11 15:38:10 0 d-------- C:\Program Files\SpaceAnylizer
2008-06-11 15:38:10 0 d-------- C:\Program Files\Common Files\Key Metric Software
2008-06-11 15:38:08 0 d--h----- C:\Documents and Settings\All Users\Application Data\{2523FC71-7736-4A2A-B0C7-8D36B58E4800}
2008-06-11 00:48:52 0 d-------- C:\WINDOWS\System32\PreInstall
2008-06-11 00:48:44 0 d--h----- C:\WINDOWS\$hf_mig$
2008-06-11 00:29:34 0 d-------- C:\WINDOWS\System32\bits
2008-06-10 05:19:35 0 d-------- C:\Program Files\Common Files\Webroot Shared
2008-06-10 05:19:35 0 d-------- C:\Documents and Settings\All Users\Application Data\Webroot
2008-05-16 15:27:28 0 d-------- C:\Documents and Settings\Administrator\WINDOWS
2008-05-16 15:27:28 0 d--h----- C:\Documents and Settings\Administrator\Templates
2008-05-16 15:27:28 0 dr------- C:\Documents and Settings\Administrator\Start Menu
2008-05-16 15:27:28 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
2008-05-16 15:27:28 0 dr-h----- C:\Documents and Settings\Administrator\Recent
2008-05-16 15:27:28 0 d--h----- C:\Documents and Settings\Administrator\PrintHood
2008-05-16 15:27:28 0 d--h----- C:\Documents and Settings\Administrator\NetHood
2008-05-16 15:27:28 0 dr------- C:\Documents and Settings\Administrator\My Documents
2008-05-16 15:27:28 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
2008-05-16 15:27:28 0 dr------- C:\Documents and Settings\Administrator\Favorites
2008-05-16 15:27:28 0 d-------- C:\Documents and Settings\Administrator\Desktop
2008-05-16 15:27:28 0 d---s---- C:\Documents and Settings\Administrator\Cookies
2008-05-16 15:27:28 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
2008-05-16 15:27:27 2097152 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
-- Find3M Report ---------------------------------------------------------------
2008-06-14 01:03:28 786432000 --ahs---- \pagefile.sys
2008-06-13 19:31:19 0 d-------- C:\Program Files\Full Tilt Poker.Net
2008-06-12 17:46:59 0 d-------- C:\Documents and Settings\Owner\Application Data\ield
2008-06-12 16:19:00 0 d-a------ C:\Program Files\Common Files
2008-06-11 16:11:17 0 d-------- C:\Program Files\hp
2008-06-11 15:21:03 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-06-11 02:12:07 0 d-------- C:\Program Files\Visual Labels
2008-06-11 02:12:07 0 d-------- C:\Documents and Settings\Owner\Application Data\LimeWire
2008-06-10 16:57:37 0 d-------- C:\Documents and Settings\Owner\Application Data\GlobalSCAPE
2008-06-10 05:22:06 0 d-------- C:\Program Files\Winamp
2008-06-10 05:19:36 0 d-------- C:\Documents and Settings\Owner\Application Data\Webroot
2008-06-10 05:19:35 0 d-------- C:\Program Files\Webroot
2008-06-04 22:26:16 0 d-------- C:\Program Files\SoapMaker
2008-05-14 14:03:18 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-14 13:36:03 0 d-------- C:\Program Files\Common Files\ACD Systems
2008-05-14 13:36:02 0 d-------- C:\Program Files\ACD Systems
2008-04-30 03:13:32 0 d-------- C:\Program Files\Common Files\Motive
2008-04-28 22:54:35 0 d-------- C:\Documents and Settings\Owner\Application Data\Adobe
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Outpost Firewall"="C:\PROGRA~1\Firewall\OUTPOS~1\outpost.exe" [04/09/2004 05:18 PM]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [08/07/2001 09:25 PM]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [08/07/2001 08:36 PM]
"PS2"="C:\WINDOWS\system32\ps2.exe" [07/03/2001 06:13 PM]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [02/12/2008 10:06 AM]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"=Narrator.exe
"tscuninstall"=%systemroot%\system32\tscupgrd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"IMEKRMIG6.1"=108209130520750479696720982160565757815579836
"DisableRegistryTools"=0 (0x0)
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=0 (0x0)
"HideStartupScripts"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=0 (0x0)
"HideStartupScripts"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsMenu"=1 (0x1)
"NoRecentDocsHistory"=01000000
"NoSMMyDocs"=01000000
"NoSMMyPictures"=01000000
"NoSMHelp"=01000000
"NoLogoff"=0 (0x0)
"NoNetworkConnections"=01000000
"ClearRecentDocsOnExit"=1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Virtual Assistant.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Virtual Assistant.lnk
backup=C:\WINDOWS\pss\Virtual Assistant.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinGate Engine Monitor.lnk]
backup=C:\WINDOWS\pss\WinGate Engine Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinGate VPN Monitor.lnk]
backup=C:\WINDOWS\pss\WinGate VPN Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^PowerReg SchedulerV2.exe]
backup=C:\WINDOWS\pss\PowerReg SchedulerV2.exeStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\1A:Stardock TrayMonitor]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced Tools Check]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APVXDWIN]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccRegVfy]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ClrSchLoader]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CoolSwitch]
C:\WINDOWS\System32\taskswitch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell AIO Printer A920]
"C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DM_Server]
C:\PROGRA~1\COMETS~1\DM\bin\dmserver.exe /onreboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\explore]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FastUser]
C:\WINDOWS\System32\fast.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FSW]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Generic Host Process for Win32 Services]
scvhost.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\WINDOWS\System32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
c:\windows\system\hpsysdrv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
C:\WINDOWS\System32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IncrediMail]
C:\PROGRA~1\INCRED~1\bin\IncMail.exe /c
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Inet Delivery]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\inmr]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Internet Optimizer]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IST Service]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
%systemroot%\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\keymgrldr]
rundll32 setupapi,InstallHinfSection Oemkeymgr9x 128 keymgr3.inf
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ltimg80n]
C:\WINDOWS\system32\ltimg80n.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MemoryMeter]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
c:\Program Files\Microsoft Works\WkDetect.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msbb]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msmc]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
C:\Program Files\MySpace\IM\MySpaceIM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NetPeeker]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NoAds]
"C:\Program Files\NoAds\NoAds.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nod32kui]
C:\Program Files\Eset\nod32kui.exe /WAITSERVICE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Power Scan]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PS2]
C:\WINDOWS\system32\ps2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PSwitch]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RDLL]
RunDll16.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
C:\WINDOWS\SMINST\RECGUARD.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Run]
C:\WINDOWS\inetg\services.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\S3TRAY2]
S3tray2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ScanInicio]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\stcloader]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TVMD]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Tweak UI]
RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateStats]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VB_run]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Washer]
C:\Program Files\Washer\washer.exe /1
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WeatherCast]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WhenUSave]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\xp_system]
C:\WINDOWS\inetg\services.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Messenger"=2 (0x2)
"wuauserv"=2 (0x2)
-- End of Deckard's System Scanner: finished at 2008-06-14 01:11:05 ------------