My HiJackthis log:
I expect it to be full of crap ^^
-----------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:47:52 PM, on 11/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Norton AntiVirus\Norton AntiVirus\Engine\16.0.0.125\ccSvcHst.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\Program Files\Norton AntiVirus\Norton AntiVirus\Engine\16.0.0.125\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\ps2.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
C:\Program Files\WildTangent\Apps\GameChannel.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\WINDOWS\system32\igfxtray.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\LTMSG.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Plaxo\3.16.0.49\PlaxoHelper_en.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
C:\Program Files\ArcSoft\PhotoImpression 5\PI Monitor.exe
C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Java\jre1.6.0_02\bin\jucheck.exe
C:\WINDOWS\SoftwareDistribution\Download\a09af09928e177cd9ba61ead21886d9e\update\update.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://srch-qus9.hpwis.com/R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://portal.wowway.net/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.yahoo.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.com/customize/ie/defaul...rch/search.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.comR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak =
http://www.wowway.com/R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0CF46468-AC82-9EC5-5B79-008AA7762D88} - C:\Program Files\Ziztmutr\cgilvgjh.dll (file missing)
O2 - BHO: (no name) - {158A95B4-1F79-3B06-78BF-0424CDB17C2E} - C:\Program Files\Ztqacway\ddikgary.dll (file missing)
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {261C35B4-9283-6344-C5C0-005CF873D624} - C:\Program Files\Kihxksmy\meghaajp.dll (file missing)
O2 - BHO: (no name) - {2BAD0253-E6F1-0EB1-50C6-08D1DF0D4119} - C:\Program Files\Dljdirmz\tcfjcmjk.dll (file missing)
O2 - BHO: (no name) - {39C6B6C8-E01E-3175-B583-04FDA1EE088B} - C:\Program Files\Cunzkvux\zruxevfi.dll (file missing)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {62780D18-D103-03D3-323A-01F43008B839} - C:\Program Files\Zmdzdabd\bwbgrxmn.dll (file missing)
O2 - BHO: (no name) - {65FF10BB-F36A-68E9-AA35-02257E958C1F} - C:\Program Files\Esjocaup\goncrdzw.dll (file missing)
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Norton AntiVirus\Engine\16.0.0.125\IPSBHO.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O2 - BHO: (no name) - {CC358019-D328-40B4-8E2D-818CE142616C} - C:\WINDOWS\system32\rqrspqq.dll (file missing)
O2 - BHO: PersonalWebBHO - {D35980CB-66DF-477B-BF63-64EB8F48CB3A} - C:\Program Files\Claria\PersonalWeb\PersonalWebIE_v1108.dll
O2 - BHO: (no name) - {D5FD0C23-8963-4741-BF49-EC79463ABF08} - C:\WINDOWS\system32\geedc.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [WT GameChannel] C:\Program Files\WildTangent\Apps\GameChannel.exe
O4 - HKLM\..\Run: [QuickFinder Scheduler] "c:\Program Files\WordPerfect Office 11\Programs\QFSCHD110.EXE"
O4 - HKLM\..\Run: [PkIifOLC9] C:\WINDOWS\prabjnbr.exe
O4 - HKLM\..\Run: [¢‰¸K0¨4W
}ïÃzî[8C:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\prabjnbr.exe
O4 - HKLM\..\Run: [¢‰¸K0¨4W
}ïÃzîžigÃC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\prabjnbr.exe
O4 - HKLM\..\Run: [¢‰¸K0æquot;@æquot;ÃÃ]§ú"ü‰üžiC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\prabjnbr.exe
O4 - HKLM\..\Run: [¢‰¸K0æquot;@æquot;ÃÃ]§ú"ü‰¸K0C:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\prabjnbr.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [¢‰¸K0æquot;ÃÃ]§ú"ü‰üžigÃC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\prabjnbr.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [Spam Blocker for Outlook Express] C:\PROGRA~1\SPAMBL~1\Bin\461~1.0\SBInst.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [SpySpotter System Defender] C:\Program Files\SpySpotter3\Defender.exe -startup
O4 - HKLM\..\Run: [PersonalWeb] "C:\Program Files\Claria\PersonalWeb\PersonalWeb.exe"
O4 - HKLM\..\Run: [MsgCenterExe] "C:\Program Files\Common Files\Real\Update_OB\RealOneMessageCenter.exe" -osboot
O4 - HKLM\..\Run: [avp] C:\WINDOWS\avp.exe
O4 - HKLM\..\Run: [smgr] mgrs.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [MSOffice] rundll32.exe "C:\WINDOWS\system32\tqtgcydh.dll",sitypnow
O4 - HKLM\..\Run: [durmvufi] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\durmvufi.dll"
O4 - HKLM\..\Run: [lolyboho] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\lolyboho.dll"
O4 - HKLM\..\Run: [dsbgrora] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\dsbgrora.dll"
O4 - HKLM\..\Run: [bideberg] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\bideberg.dll"
O4 - HKLM\..\Run: [ejkhupqb] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\ejkhupqb.dll"
O4 - HKLM\..\Run: [tefovmzc] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\tefovmzc.dll"
O4 - HKLM\..\Run: [ubcnurin] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\ubcnurin.dll"
O4 - HKLM\..\Run: [kvilmxah] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\kvilmxah.dll"
O4 - HKLM\..\Run: [evcpodwp] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\evcpodwp.dll"
O4 - HKLM\..\Run: [cbqjefur] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\cbqjefur.dll"
O4 - HKLM\..\Run: [qrgnwjut] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\qrgnwjut.dll"
O4 - HKLM\..\Run: [otepcjgz] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\otepcjgz.dll"
O4 - HKLM\..\Run: [yhipebkr] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\yhipebkr.dll"
O4 - HKLM\..\Run: [lsxahobc] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\lsxahobc.dll"
O4 - HKLM\..\Run: [dejuvqhq] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\dejuvqhq.dll"
O4 - HKLM\..\Run: [gzivqhgh] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\gzivqhgh.dll"
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\3.16.0.49\PlaxoHelper_en.exe -a
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpeedItUpEX] C:\Program Files\Speeditup Free\SpeedItUp.exe -MINI
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [PlaxoSysTray] C:\Program Files\Plaxo\3.16.0.49\PlaxoSysTray.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKLM\..\Policies\Explorer\Run: [aAFgPd1P3X] rundll32.exe "C:\WINDOWS\system32\ndaTqsVqrX.dll",DllCleanServer
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - .DEFAULT User Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: PI Monitor.lnk = C:\Program Files\ArcSoft\PhotoImpression 5\PI Monitor.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspxO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: download.adobe.com
O15 - Trusted Zone:
http://www.adobe.comO15 - Trusted Zone:
www.agesanctuary.comO15 - Trusted Zone: *.agesanctuary.com
O15 - Trusted Zone:
http://www.airsoftforum.comO15 - Trusted Zone:
http://www.wireless.att.comO15 - Trusted Zone:
http://www.azlyrics.comO15 - Trusted Zone:
http://www.cbs.comO15 - Trusted Zone: dl.cdn-downloads.com
O15 - Trusted Zone:
http://www.comedycentral.comO15 - Trusted Zone:
http://monopoly.corsis.comO15 - Trusted Zone:
http://www.dodge.comO15 - Trusted Zone:
www.dvdzip.orgO15 - Trusted Zone:
http://dnama.dyndns.orgO15 - Trusted Zone:
http://www.exoticcarrental.comO15 - Trusted Zone:
http://www.eyeslipsface.comO15 - Trusted Zone:
http://halo2.filefront.comO15 - Trusted Zone:
http://*.findmeatune.comO15 - Trusted Zone:
http://www.forbes.comO15 - Trusted Zone:
http://www.fox.comO15 - Trusted Zone:
http://www.fraps.comO15 - Trusted Zone:
http://www.freedownloadscenter.comO15 - Trusted Zone:
www.games.comO15 - Trusted Zone:
http://www.games.comO15 - Trusted Zone: download2.gamespot.com
O15 - Trusted Zone:
www.heatwolephoto.comO15 - Trusted Zone:
http://aom.heavengames.comO15 - Trusted Zone:
http://www.hobbytron.comO15 - Trusted Zone:
www.igzones.comO15 - Trusted Zone:
www.igzones.netO15 - Trusted Zone: downloadmirror.intel.com
O15 - Trusted Zone:
http://www.macomb.k12.mi.usO15 - Trusted Zone:
http://www.limewire.comO15 - Trusted Zone:
http://www.liveperson.comO15 - Trusted Zone: cnn-4.vo.llnwd.net
O15 - Trusted Zone:
http://classifieds.macombdaily.comO15 - Trusted Zone: fpdownload.macromedia.com
O15 - Trusted Zone:
http://www.maidmarian.comO15 - Trusted Zone:
http://www.mapquest.comO15 - Trusted Zone:
http://*.megavideo.comO15 - Trusted Zone:
www.micro-sys.dkO15 - Trusted Zone:
http://www.mileyworld.comO15 - Trusted Zone:
http://bb.misd.netO15 - Trusted Zone: rsddownload.motorola.com
O15 - Trusted Zone:
http://www.mozilla.comO15 - Trusted Zone:
http://download.mozilla.orgO15 - Trusted Zone:
http://www.mypyramid.govO15 - Trusted Zone:
http://users.bigpond.net.auO15 - Trusted Zone: tucows.netnitco.net
O15 - Trusted Zone: ftp-mozilla.netscape.com
O15 - Trusted Zone:
http://www.nfl.comO15 - Trusted Zone:
http://www.nick.comO15 - Trusted Zone:
http://www.nintendo.comO15 - Trusted Zone:
www.oxygenxml.comO15 - Trusted Zone:
http://www.pearsonsuccessnet.comO15 - Trusted Zone:
http://www.phunland.comO15 - Trusted Zone:
www.piettes.comO15 - Trusted Zone: download.piratesonline.com
O15 - Trusted Zone:
http://www.playnet.comO15 - Trusted Zone:
http://www.profootballhof.comO15 - Trusted Zone:
http://*.qvc.comO15 - Trusted Zone:
www.readyroom.orgO15 - Trusted Zone: software-dl.real.com
O15 - Trusted Zone:
http://www.rivals.comO15 - Trusted Zone:
http://www.roman-empire.netO15 - Trusted Zone:
http://www.rottentomatoes.comO15 - Trusted Zone: mp3support.sandisk.com
O15 - Trusted Zone:
http://www.sega.comO15 - Trusted Zone:
www.sharewareguide.netO15 - Trusted Zone:
http://*.sourceforge.netO15 - Trusted Zone:
http://www.southparkzone.comO15 - Trusted Zone: *.symantec product downloads
O15 - Trusted Zone: lcsitemain.symantec.com
O15 - Trusted Zone: lcsitemain.symantyc.com
O15 - Trusted Zone:
http://mail.tenibac.comO15 - Trusted Zone:
http://*.thefuntimesguide.comO15 - Trusted Zone:
http://www.totalwar.comO15 - Trusted Zone:
www.transformersgame.comO15 - Trusted Zone:
www.trendsecure.comO15 - Trusted Zone:
http://www.verizonwireless.comO15 - Trusted Zone:
www.vob-converter.comO15 - Trusted Zone:
http://upload.wikimedia.orgO15 - Trusted Zone:
http://en.wikipedia.orgO15 - Trusted Zone:
http://portal.wowway.netO15 - Trusted Zone: download.yimg.com
O15 - Trusted Zone:
http://*.youtube.comO15 - Trusted Zone: *.zango.com
O15 - Trusted Zone: *.zangocash.com
O15 - Trusted Zone:
www.zelda.comO16 - DPF: {00000005-0000-0000-0000-100011000004} -
http://c.imputati.com/l/6cdf283501374c8c07...86362523_35.exeO16 - DPF: {051D0E35-F4E3-4C8D-B411-AB0875F4C683} (Anark Client 4.0 ActiveX Control) -
http://install.anark.com/client/version4/w...en/AMClient.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) -
http://download2.citrix.com/FILES/en/produ...rent/ica32t.exeO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5F3B3060-09E0-44C6-86F7-BC7B02B57BEE} -
http://downloads.shopathomeselect.com/ward...tall_wm1001.cabO16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) -
http://www.nvidia.com/content/DriverDownlo.../sysreqlab2.cabO16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -
http://us.games2.yimg.com/download.games.y...ctl_0_0_0_2.ocxO16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) -
https://webdl.symantec.com/activex/symdlmgr.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdat...b?1126907207156O16 - DPF: {771A1334-6B08-4A6B-AEDC-CF994BA2CEBE} -
http://www.ysbweb.com/ist/softwares/v4.0/ysb_regular.cabO16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) -
http://www.nick.com/common/groove/gx/GrooveAX28.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cabO16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) -
http://a532.g.akamai.net/f/532/6712/4h/pla...0/Installer.exeO16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) -
http://a532.g.akamai.net/f/532/6712/5m/vir...l/installer.exeO16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -
http://www.popcap.com/games/popcaploader_v6.cabO16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) -
http://fdl.msn.com/zone/datafiles/heartbeat.cabO16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} -
http://download.spyspotter.com/spyspotter/...rCabInstall.cabO20 - Winlogon Notify: geedc - C:\WINDOWS\system32\geedc.dll (file missing)
O20 - Winlogon Notify: rqrspqq - rqrspqq.dll (file missing)
O20 - Winlogon Notify: winccf32 - winccf32.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: Norton AntiVirus - Symantec Corporation - C:\Program Files\Norton AntiVirus\Norton AntiVirus\Engine\16.0.0.125\ccSvcHst.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O24 - Desktop Component 0: (no name) -
http://www.wildgames.com/ECS/ECSData/DP/wt..._pack_large.gifO24 - Desktop Component 1: (no name) -
http://portal.wowway.com/templates/maya/im...els_date_bg.gif--
End of file - 21353 bytes