whohuhwhat
New member
Hey guys,
My norton antivirus gave me a popup notification saying that crypt.dll was infected. It said it quarantined the file but norton was (not responding). I ran adaware and spybot in safe mode. Spybot found smitfraud-c and virtumonde and attempted to "fix the problem." Unfortunately, the problem is still there.
***********
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:22:23 PM, on 2/21/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5700.0006)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Norton\defwatch.exe
C:\Program Files\Norton\rtvscan.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\MsgSys.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Logitech\G-series Software\LGDCore.exe
C:\Program Files\Logitech\G-series Software\LCDMon.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDPop3\LCDPOP3.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDCountdown\LCDCountdown.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDMedia.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDClock.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Norton\vptray.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Executor\executor.exe
C:\Program Files\D-Color\dcolor.exe
C:\Program Files\miniMIZE\miniMIZE.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Logitech\SetPoint II\SetpointII.exe
C:\Program Files\Samurize\Client.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Documents and Settings\F H e L\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\F H e L\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.netflix.com/MemberHome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID}
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O3 - Toolbar: QT TabBar - {d2bf470e-ed1c-487f-a333-2bd8835eb6ce} - mscoree.dll (file missing)
O3 - Toolbar: QT Tab Standard Buttons - {D2BF470E-ED1C-487F-A666-2BD8835EB6CE} - mscoree.dll (file missing)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\G-series Software\LCDMon.exe"
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [vptray] C:\Program Files\Norton\vptray.exe
O4 - HKLM\..\Run: [Framework Windows] frmwrk32.exe
O4 - HKLM\..\Run: [Blujeqayofikahas] rundll32.exe "C:\WINDOWS\Nqamalolacihi.dll",e
O4 - HKLM\..\Run: [jsf8uiw3jnjgffght] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\winlognn.exe
O4 - HKLM\..\Run: [Kdawat] rundll32.exe "C:\WINDOWS\upevoyoxajijohap.dll",e
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\IGN\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\F H e L\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Executor] "C:\Program Files\Executor\executor.exe" -s
O4 - HKCU\..\Run: [D-Color] C:\Program Files\D-Color\dcolor.exe
O4 - HKCU\..\Run: [miniMIZE] C:\Program Files\miniMIZE\miniMIZE.exe
O4 - HKCU\..\Run: [jsf8uiw3jnjgffght] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\winlognn.exe
O4 - HKCU\..\Run: [csjmijd96flzjwbfkdt] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\x3hvbfjjtv8.exe
O4 - HKCU\..\Run: [ml53hzopky5mipv] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\nhyyvuj.exe
O4 - HKCU\..\Run: [iw86dw5i52qpg2abdbz23egctf2a28f4pmcpi] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\p0ak6fmi2h8.exe
O4 - HKCU\..\Run: [x0mw5tjuozfwippivvn2sl6cngxvtibnen4vhw] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\m7v1ftwy3yds.exe
O4 - HKCU\..\Run: [MS AntiSpyware 2009] "C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\msas2009.exe" /autorun
O4 - HKCU\..\Run: [fbu1wi9mqx15evz9seac4dr4dhv7cish] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\uesmi0.exe
O4 - HKCU\..\Run: [fh0nq8bfbdnp0vwyd9gyw0khjqtn1t2t] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\nkalgmg3q4dc7.exe
O4 - HKCU\..\Run: [i5ncfzkqx94lxqfge] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\cigjktg9i8.exe
O4 - HKCU\..\Run: [xhq26mutp453z5yyre2mosrjt1p3t3qabnyihbq4ry0trbr] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ok8d9mu1h6rr.exe
O4 - HKCU\..\Run: [va56uiw5v2vky1o2kva3mbeaf3qp9tscczn6tje0wclmcr] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\fh452ttihhg.exe
O4 - HKCU\..\Run: [hidh0uewahesyrbuen1x3ew1azthn3mzszo22doao] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\royjhktogfcc.exe
O4 - HKCU\..\Run: [ki3tl3fuef588hlg8mk9fjluqjub3lgssr3t6oqcu] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\x1bzxx7p1y.exe
O4 - HKCU\..\Run: [jwx45bubt43na8yo6da66bhsc3vp2] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\stp1me2.exe
O4 - HKCU\..\Run: [evd68kpgf8xmrhruyc006] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\de4f3oqegc8dr.exe
O4 - HKCU\..\Run: [knwfbf3aglv15bajyn1h9j6t9u2yp51kx] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\o6fvbzdp.exe
O4 - HKCU\..\Run: [nfln919pciqaxn8emjybaaalu9cfi] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ly9degonpw.exe
O4 - HKCU\..\Run: [wexmcsfwkvvw2iluawj6la5ic74slncm1xj7mr9wc] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ellvllzp9kj.exe
O4 - HKCU\..\Run: [tam0e75vpi016e0la8tw4zkysepoo7] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ttngeq7o.exe
O4 - HKCU\..\Run: [xdw2dxi3h1gok408d8mhvmhojr] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\evnzk09hs.exe
O4 - HKCU\..\Run: [fq4b9v2gk] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ozpkjuy0rg37.exe
O4 - HKCU\..\Run: [sxfus7hjstzoz789v3vh9986rtrn2t1mtyzc3972zt] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\wiwnz3t.exe
O4 - HKCU\..\Run: [yxzrebbx5yatqswfxx0pyefjz9h1v4jn] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\xen5dwxvnymz.exe
O4 - HKCU\..\Run: [hz9pevghjfxblzwaquofdn9rojuq1rzncxc0h] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\sz9dovcx6.exe
O4 - HKCU\..\Run: [ahxpuihzgnab2c2k1e83y31dg60lcia] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\j713fih2e.exe
O4 - HKCU\..\Run: [kep8frp1nco] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\eo2iowsul9p2s.exe
O4 - HKCU\..\Run: [w3xi6cbn5jbfqx7hjnup6sho5c7d8ylgfmsm1z4n] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\scx1r569hxu.exe
O4 - HKCU\..\Run: [ymf3ff0f4mupexuc7iz7oiktj7clkyhxcbq33jkm] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\mxqh5qd6vl.exe
O4 - HKCU\..\Run: [xm972eeoitci] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\azq0b0fzy3i.exe
O4 - HKCU\..\Run: [gljnudmq7wisy8cmb1miamwsrmsd] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\c5fd4sr.exe
O4 - HKCU\..\Run: [kyuu1x56ysizqewgbnxwnjln89hld55n5d3ho60ku] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\eg78awbfx9rr.exe
O4 - HKCU\..\Run: [xo24ffzb4pvorn1549suref] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\z660kvtfly.exe
O4 - HKCU\..\Run: [er3i359chj0x00vo8nr4xhvnumc8nxiihkn1gpc1tr385lc] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\kupmg3jm7g.exe
O4 - HKCU\..\Run: [lsknx97qg6qweg0e3yho1em00qwe] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\cqwnf8adqa.exe
O4 - HKCU\..\Run: [pv6ag7lx9v] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\neyqbzh3ts.exe
O4 - HKCU\..\Run: [p34e1wufi9oaiebabjx3k5ut] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ysm91a.exe
O4 - HKCU\..\Run: [ghjwshjwa] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\njhtkgmht.exe
O4 - HKCU\..\Run: [fvneugu4p] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\q37xwc3fy.exe
O4 - HKCU\..\Run: [k2l0phiomm9ulo1kobnjjnbvbu9gfyc734ka2pb] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\em7g23581m.exe
O4 - HKCU\..\Run: [yqhtzjf4rw86tykyeodwrrjf1gmlw1e10xwkzcn] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\a7qivn9u7m54.exe
O4 - HKCU\..\Run: [lavk0ippii3qa2dpit9eq63p52ngkbhpwql] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\pyl2eto.exe
O4 - HKCU\..\Run: [vbxg2l59ax1tblbho2xbi5h8g74nhvxqt679oyp11dpqloc] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\wq16akzrbpl.exe
O4 - HKCU\..\Run: [lvn233rjwr4niw4u7h9e14wsxqxo] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\vchf8zd.exe
O4 - HKCU\..\Run: [oh4ibn5m0o24r1ajnqjuu] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\z6c0ucve.exe
O4 - HKCU\..\Run: [e6djm4qmg5v6vmryynfgvulnj3kwchvbc2ygr] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\cgqk0svvsqqb.exe
O4 - HKCU\..\Run: [n8ska376xs1vcwl7drkh4w7mxeihybbiv] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\jk95z31.exe
O4 - HKCU\..\Run: [dfq5y84cc] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\v82mgvbbcekm.exe
O4 - HKCU\..\Run: [mqf5u4lb42j8p1ugql32iareditwuvwv5g6p6owk] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\u8s8vu8.exe
O4 - HKCU\..\Run: [rmadp3z24dlnsvucin6eahja3ykrhfku0e40u98tllmxi] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\uidvu919nqpcp.exe
O4 - HKCU\..\Run: [efbcuelkll0o1hmflmspiwjj] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\mqpwdfgg.exe
O4 - HKCU\..\Run: [m971w231n2gaocexkt4qyvdvrp74geyhn34y1] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\fw1ekkrix.exe
O4 - HKCU\..\Run: [crsz8omn5k1ykda4g1hz3vgj3] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\po0pdlupf.exe
O4 - HKCU\..\Run: [uaqvk6vmyydajuhusempda4ltx8toay] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\r31wgkl39e.exe
O4 - HKCU\..\Run: [ln8yoh8mu1nspf] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\bwco08ddn8ef.exe
O4 - HKCU\..\Run: [wi7kc06nn5kwy9srfxpeub1mkz37arj59wtt9jptpd] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\x7hnnc0ih2.exe
O4 - HKCU\..\Run: [ubtau15rc0xha6bisljqkf77n6qocshcjnbab3c1z4d14gtb46] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\mt0oqj33.exe
O4 - HKCU\..\Run: [qnmbb6zva] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ep786ouu.exe
O4 - HKCU\..\Run: [wf99pp3v2j210tk8flqsv8dtjmun8plk2d] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ludk3cm.exe
O4 - HKCU\..\Run: [vre8vb305c7ifua7pqrreeqf1fshtnf3f] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\cx3q4im3.exe
O4 - HKCU\..\Run: [asg7dxsdm2t91jaqe7thcd] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\vdashkemt3oj5.exe
O4 - HKCU\..\Run: [rhefwpxpb1lke5at8txhzp] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\kgttkr07qlb.exe
O4 - HKCU\..\Run: [whu2xquxo1] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\boljbe5vyyg.exe
O4 - HKCU\..\Run: [co55jqxq9oyd1g6c57] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ems3xthfkrso.exe
O4 - HKCU\..\Run: [pz1ol9kl4oo] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\b3zrg6.exe
O4 - HKCU\..\Run: [bqlkrtwcn] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\d3ps5r7w2.exe
O4 - HKCU\..\Run: [ayy0j6ol5azqnu3u6vpyzma454] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\hs1ainkrpmx.exe
O4 - HKCU\..\Run: [sirpxuevascszslts78e0mbxuujx7vxop59f2] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\lc1bf3lj.exe
O4 - HKCU\..\Run: [jbvwd2lda7np5gb7t3su6vzs91hpm3qfmzy] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\cxs7vz.exe
O4 - HKCU\..\Run: [dmu3z3fhp1jim29j9sth02m9jownth1ky] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\v94xubtezwy6b.exe
O4 - HKCU\..\Run: [i5zc9yxgipjk6jqhq8cq31alj5yuugphs3ka3h0h6xl] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\vvn0oicj3l1v.exe
O4 - HKCU\..\Run: [ckbz5uih77i2gu94rm83s7q72wbpvl96vabos03] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\kmi13yd.exe
O4 - HKCU\..\Run: [wix010yqnk483gb] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\dsuja3oi.exe
O4 - HKCU\..\Run: [suq1io9ulh3vcf8n] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\v51k98f9.exe
O4 - HKCU\..\Run: [j3184thqyjd6xd4uws5cm38] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\nwdl9eux1qk.exe
O4 - HKCU\..\Run: [ql5yhynqnsj65wkvzmn2bdfoy48peyr4go9gu9p6gfh9pe4] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\jmfqbwmgqqq1.exe
O4 - HKCU\..\Run: [usk0p9aajkya9z] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\jy3qzno.exe
O4 - HKCU\..\Run: [nzwb3ixfewk7fo6riq1821gv17qzqxw22na] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ql5sdrgs6l.exe
O4 - HKCU\..\Run: [sh0kd94waiycl4g] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ee0epy3.exe
O4 - HKCU\..\Run: [cl92p468imcdfrvkq786u8ltnvlqg5moa19oigbls3801x] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ejjyff.exe
O4 - HKCU\..\Run: [dz9m687ckp7j0f] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\b9oe9zrpnb.exe
O4 - HKCU\..\Run: [xbhf3r8ibnhil1y5] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\fgnpnoc63md.exe
O4 - HKCU\..\Run: [y31xtpxx7fnf6oq8v8fkf8u7lerz3amnf2t7cadtged5r] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\brbotszbg.exe
O4 - HKCU\..\Run: [zapw0zv3j] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\w78c4t704.exe
O4 - HKCU\..\Run: [c6slf91pshk0keqv6enqfsp] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\cse64kfq2nz.exe
O4 - HKCU\..\Run: [xwqnr266ahnfb6] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\v828hm79.exe
O4 - HKCU\..\Run: [hozy3n6qjpokunfmhggeer22uzkg] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\oee7oribi.exe
O4 - HKCU\..\Run: [auxkxp646vv] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\u8iep3g9xnb9o.exe
O4 - HKCU\..\Run: [arj9ji0ydb4x55myaqojs7htoe8tp85] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\uy4ujnkzi.exe
O4 - HKCU\..\Run: [r0v9y4lxrzex5x7ukq1twf0im8z3rbroj6sys] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\upphi29.exe
O4 - HKCU\..\Run: [wv0dsr6anzqz7e52s68736xadwpiz7ptdh5l2] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\frp0ocbd.exe
O4 - HKCU\..\Run: [ybo2il98r7xo7hqf3g87sc4lz4fd] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\mldihq0.exe
O4 - HKCU\..\Run: [chflux04n813eqtcr] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\lgr4g74e5hgrc.exe
O4 - HKCU\..\Run: [ac64e3ep2s3qminjrfaw70vh6b002] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ajaoje7z2i3.exe
O4 - HKCU\..\Run: [wtbyz1bop124j4de] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\sfhpijyqlcw.exe
O4 - HKCU\..\Run: [ycsl9v4f3txgguf5oo6lhuhi7mp61j3963ef4avk] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\lvorv4q9.exe
O4 - HKCU\..\Run: [tfogis7cdhtezdbt74] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\d8jv4rau7u.exe
O4 - HKCU\..\Run: [e4g3rmd4ll7dptw0vjavdgnr] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\zoju7b92dulqj.exe
O4 - HKCU\..\Run: [hjnih3frph7mm6a26tum6c0] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\gsszz4rsc6.exe
O4 - HKCU\..\Run: [ifoe67k9b7qh] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\b3u6u64eo6wtt.exe
O4 - HKCU\..\Run: [axrzqcf6yode1eiz9yvhi6yzviavcb2fmljz2owbm6] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\c4dormo61a.exe
O4 - HKCU\..\Run: [k3eookxekg3b22r50bxcs0n7ryh38lzxfzyuh] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\mrw9qxu4aojxd.exe
O4 - HKCU\..\Run: [ld62oswyv12nlcd7kzsqhhm58ot3zyn] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\xawsw7.exe
O4 - HKCU\..\Run: [yzrrvui0tk7h0buco5szv4j] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\bzra939s.exe
O4 - HKCU\..\Run: [bkqhgxc5yt471z3qqe1dnhfk7xwkarfd54ehif4s] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\fe88gj.exe
O4 - HKCU\..\Run: [dgkzt0rkyrpdvjhxg3jbl9] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\j3k9tyi1.exe
O4 - HKCU\..\Run: [r1u0ip3etr54bxrjm96o8nnkx71cl8] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\c9w80ktk1.exe
O4 - HKCU\..\Run: [ka5kjmas2zqju1h4jk5bhjifnjzhgubhynq2d] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\fgc6x5e5h.exe
O4 - HKCU\..\Run: [go9jlll0hbqe2or3sju0bamt0k7s8bxxt30ue] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\i02ts1v33.exe
O4 - HKCU\..\Run: [gdrv00idqgnfzk3tsslzkphgj4qa6k] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\o0mrop.exe
O4 - HKCU\..\Run: [p9rb6ch06wboi1qypogqhskfux] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\a7b5qu.exe
O4 - HKCU\..\Run: [e8i41t8d97l7r539h31nxvwvk9eqs76z565g711dwl] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\nv0d66trvxnp.exe
O4 - HKCU\..\Run: [vb5loy3movu7xm5v2ifosvl2iocqh9ypcdjys9us7dao1] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\oa8v1ix3o.exe
O4 - HKCU\..\Run: [mf7kpb5e6pz75bqj9jh7f0sgpzipwprbem68m] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\u8oezkipb9g.exe
O4 - HKCU\..\Run: [jh9cgqouv1h6diojyc9auhtbljo] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\dnmza5hoemq.exe
O4 - HKCU\..\Run: [ykf72kue937plj] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\j2tjfka80y25.exe
O4 - HKCU\..\Run: [gkmm9midynm338vob7kk597txw99wtg0c5v9bis] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\c3mydp.exe
O4 - HKCU\..\Run: [bzb1li4tyg7mfola52pt3z3mujsgty0gi0fu4] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\p1wtszyeps.exe
O4 - HKCU\..\Run: [dfbfuv3sbdb6kin6cqrj5iydh6rynl9ugrv] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ce4s0i.exe
O4 - HKCU\..\Run: [yn9wxa1wspkmz9hz2zshoqrpg7wyp1z5e3fw3q] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\zkt16797.exe
O4 - HKCU\..\Run: [l4gqg1hbdmz69pte0vkcte0cemgy5qrpmwevtq492] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\mn6xptu9.exe
O4 - HKCU\..\Run: [lzo0mxf6et0mt1zpz7meffr4r] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\lnwndnz052b.exe
O4 - HKCU\..\Run: [ndsnzlvul9w88nlb1hrnk9djw4seku4c48fzj34oo41xjz] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\t1a5n2agg.exe
O4 - HKCU\..\Run: [bhp25ruuj8zi] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\swor5je.exe
O4 - HKCU\..\Run: [yczpbq3olwu0yp64l2bms5aluqx7u69p1rqi7u4y3lic54b] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\hu58z9.exe
O4 - HKCU\..\Run: [djs4be4zmlf0il5h] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\m2kk47g40zh.exe
O4 - HKCU\..\Run: [i9syz7lerhgybsu6t6maxj6hx8myma5xgvbbt8vxvttccjnje3] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\rc598mdrlh.exe
O4 - HKCU\..\Run: [m4wehwxxxv3zorqjjifoq1zd] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\o7tqsn1osbidv.exe
O4 - HKCU\..\Run: [nyhtvek6f9j4e519kmcw373] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\g30arssfb5b6f.exe
O4 - HKCU\..\Run: [zgddd7hfo3oid95] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\c9vqpvw02hyw.exe
O4 - HKCU\..\Run: [i5hr61u6qseux1qg8b378jia2xk2dowuey0rz5ddupxy8zaas] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\nse9v5yt5zyno.exe
O4 - HKCU\..\Run: [vpqgpsv53u0y2lv3acg3ozjxhv94] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\v1qs5ycgm5s7.exe
O4 - HKCU\..\Run: [kt71oes1d9vuwyiuiy6636fvvyy2m10] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ygxcrdo0rh4rr.exe
O4 - HKCU\..\Run: [denya6sffxa8tt6wh3uxrxodz9b4c] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\cabxdq.exe
O4 - HKCU\..\Run: [nxhtzomokaj01g364xs71236ga2s9qr9fomef43rzg2u58] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\phk5oxt5s.exe
O4 - HKCU\..\Run: [llfc3geg64tsatllw3qo] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\avroe8jv2twui.exe
O4 - HKCU\..\Run: [bbjcb16puo09smwgtaznzxjhcold204a10of] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\q8p3fxdgtb.exe
O4 - HKCU\..\Run: [py1ooulcggqhmjodm5hm628w01zvnpopekfarvi6zwyq4] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\tn37ubzbm0qm1.exe
O4 - HKCU\..\Run: [fzmj9z1bl6422o0yo2dqqa3cs] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ek36r4w.exe
O4 - HKCU\..\Run: [iek9zrg77i5ziz7e7] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\bfr6b5knwc.exe
O4 - HKCU\..\Run: [l9kw1bbxtqqxcdj9h] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ljarep4aq0irz.exe
O4 - HKCU\..\Run: [g8f8vunrx45mvo] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\pyrphfmgzbj.exe
O4 - HKCU\..\Run: [wr9vn6qq20bbn4yqttpjftpbhi00s] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\guvfo1mo.exe
O4 - HKCU\..\Run: [on3b0g597my92eg8rhvol] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\kojghwb.exe
O4 - HKCU\..\Run: [tx6djd5k5vgntr9j1vngbgp] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\hl0dfi6z1.exe
O4 - HKCU\..\Run: [oxdfokvgcioosdo3nvtxe3vznic89i1y44fg30fnewcmehmqfx] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\rixik9te.exe
O4 - HKCU\..\Run: [pw64i1llwqcw4hjra661mg4jkcr25hzr8zi47h8h5y6r3avjyy] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\zr2h13e7do7x9.exe
O4 - HKCU\..\Run: [o6j8l3pjrv] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\v79jxo69qi.exe
O4 - HKCU\..\Run: [h523azrms8ap4ib8vrw7j4ogh5kj] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\db2zy0fz7o.exe
O4 - HKCU\..\Run: [qxjcj85dyc94s1vgoghf] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\bbpa4xl5h6.exe
O4 - HKCU\..\Run: [gdj7847gzp05e4qqt5av3cz60tme86wxi4lx8d3] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\jf19osueyc.exe
O4 - HKCU\..\Run: [sqd08lf04isi07vpv8h03z0z42uph9g0ve87saua] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\xh1sb2w71us.exe
O4 - HKCU\..\Run: [ngklwbhyc25e4hksej95] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\x3kck01lku.exe
O4 - HKCU\..\Run: [uwu05ja9y] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\p9mgp4.exe
O4 - HKCU\..\Run: [kio3ehawvhd1gt5t09t1ub6bbvg3itxo4mh9neira9hpi8a78] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ifyfwq3.exe
O4 - HKCU\..\Run: [ci4etsedh50bhqyx637atzgdv8flhydloky9v4fqlcrul1zd] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\u83wahpzk.exe
O4 - HKCU\..\Run: [y33d88ky29fd378d3bqp2vjpj] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ty51ciyi9d.exe
O4 - HKCU\..\Run: [d6sd0ltjtznf] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\so034ie78.exe
O4 - HKCU\..\Run: [i89icwn3d6uinnermxyd0u03xa9mpde] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\pjokoj24fdac.exe
O4 - HKCU\..\Run: [jdk3rtmqm58fsd] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\hwv44otvy735.exe
O4 - HKCU\..\Run: [po16ugxs0jebekzacene03q0kmhnvd7] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\d7j3rsg0b1.exe
O4 - HKCU\..\Run: [w7isypcmu1yzlf6diro9bttckx0y] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\i602vod6z1ya9.exe
O4 - HKCU\..\Run: [mvtllhqjdia9] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\znq5nd8.exe
O4 - HKCU\..\Run: [np4rxbuq6u2qysbmf40ur7] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\beclzy0665zwr.exe
O4 - HKCU\..\Run: [uhm4s2a829hzx16iq8ivae6dajayktij3qaicpomye7d8h7] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\cahx4q8899m9.exe
O4 - HKCU\..\Run: [p3nwunr9kr3oaatzgoisvvrg2p] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ph9myxv.exe
O4 - HKCU\..\Run: [qz8g1i562rakfbip32eh8pzi3bwzd2aeugtd6kcwi7nco9] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\wlzrqquumfq5.exe
O4 - HKCU\..\Run: [ysf9nmvb9qtcwwx88qlv0qie29r9ie8rit423ysadwdmo] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\s6itjr.exe
O4 - HKCU\..\Run: [jn2csu59pg0xwko59r2kh1qe9] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\hz6axikk.exe
O4 - HKCU\..\Run: [btsr54fwsp70bzkj6qo0vik3jo7g9] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\t26u0p.exe
O4 - HKCU\..\Run: [jkg8xcw0qunuzgtkrxpb3iqhd] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\c65lqh.exe
O4 - HKCU\..\Run: [adihd84vumj0xe3] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\rxhmqn0pa.exe
O4 - HKCU\..\Run: [vn428vg93giyd6pqs9sujzqhmj9yqnk4myly4cjx26] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\vy0nnk.exe
O4 - HKCU\..\Run: [so1i32qqf09f7q0j2vudrbczk0ivr8hkc2aaiytnyuurh] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\kpco69god.exe
O4 - HKCU\..\Run: [rfc8851k93jivc1eaoq57lw9p3zits] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\xrlcrzfn8m6ho.exe
O4 - HKCU\..\Run: [avs003xu12yskny6jvochd4m683oqbmz0eekw6p] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\b2gedc.exe
O4 - HKCU\..\Run: [l68ijpr8cpmfo36tdfxkvr46n8ay57tn6889yat9] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\bx4exd4tl.exe
O4 - HKCU\..\Run: [jajri40tpc8l2xt6r5hd3283] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\p4zx0mi.exe
O4 - HKCU\..\Run: [i6tzttyj1pbanquxry6] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ll3612.exe
O4 - HKCU\..\Run: [oxkqmdsdh] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\h1a8x4cjjnf.exe
O4 - HKCU\..\Run: [o9gy6ghmmo6468o0de8o6pffl48b5po3eu1605lpt0c] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ax5lstol8.exe
O4 - HKCU\..\Run: [cto5sn3yjzr] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\hb5s3kt.exe
O4 - HKCU\..\Run: [fj4h4lv6qaycycovrnrqj5ovr4z6n2b] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\cc5czowuot3s.exe
O4 - HKCU\..\Run: [cgn3to5as1s2hqfxgdwpzmhju9qhn18681] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\y9cev9od1.exe
O4 - HKCU\..\Run: [xn3ifzar6mtf3ciwg23w34or6knd] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\gwouw4xmi.exe
O4 - HKCU\..\Run: [anng19a9wlwc1yjncc] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\d8cuz5ljpnla.exe
O4 - HKCU\..\Run: [py8gxt78o2or2h8v3in5gi0nwd92jcbizm3e3] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\zjhcmq8o2h.exe
O4 - HKCU\..\Run: [u86jcn017znkc2vqz6heda] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\rk7xbcnt4.exe
O4 - HKCU\..\Run: [l0zm64g1n11m7k83rxf0tsx] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\fdljn2.exe
O4 - HKCU\..\Run: [q5aivmb9munfkpo6856k7k] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\u4xkn8laq.exe
O4 - HKCU\..\Run: [whludkj3xqblqjxqbhk2rffbma2puyz2n] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\r6q01ts7.exe
O4 - HKCU\..\Run: [r5ofbdostksvpwzputl8cm85ll4hzqwawhf] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\by4lgma8.exe
O4 - HKCU\..\Run: [his135lkvp3ltcz] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\b3n5pkf.exe
O4 - HKCU\..\Run: [awwpf0gdv0kv26ccx1dpbidnqtexunahtk0ltuzkv2ytii] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\e8z5mjrpz5vv.exe
O4 - HKCU\..\Run: [ot4unm9ezn03glyimceo7ku2i14nz1g0ztipfkmwp6v8uclf] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\tzb6586.exe
O4 - Startup: Client Default.lnk = C:\Program Files\Samurize\Client.exe
O4 - Global Startup: SetPointII.lnk = ?
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\docume~1\fhel~1\locals~1\temp\ntdll64.dll
O10 - Unknown file in Winsock LSP: c:\docume~1\fhel~1\locals~1\temp\ntdll64.dll
O16 - DPF: vzTCPConfig - http://www2.verizon.net/help/fios_settings/include/vzTCPConfig.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175/7d/runaware.download.akamai.com/25175/citrix/wficat-no-eula.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.2.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1235190547000
O20 - AppInit_DLLs: wbsys.dll atxpii.dll
O22 - SharedTaskScheduler: IE Component Categories cache daemon - {553858A7-4922-4e7e-B1C1-97140C1C16EF} - C:\WINDOWS\system32\ieframe.dll
O22 - SharedTaskScheduler: jgzfkj9w38rksndfi7r4 - {C5BF49A2-94F3-42BD-F434-3604812C8955} - (no file)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Norton\defwatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Norton\rtvscan.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 27712 bytes
My norton antivirus gave me a popup notification saying that crypt.dll was infected. It said it quarantined the file but norton was (not responding). I ran adaware and spybot in safe mode. Spybot found smitfraud-c and virtumonde and attempted to "fix the problem." Unfortunately, the problem is still there.
***********
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:22:23 PM, on 2/21/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5700.0006)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Norton\defwatch.exe
C:\Program Files\Norton\rtvscan.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\MsgSys.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Logitech\G-series Software\LGDCore.exe
C:\Program Files\Logitech\G-series Software\LCDMon.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDPop3\LCDPOP3.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDCountdown\LCDCountdown.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDMedia.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDClock.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Norton\vptray.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Executor\executor.exe
C:\Program Files\D-Color\dcolor.exe
C:\Program Files\miniMIZE\miniMIZE.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Logitech\SetPoint II\SetpointII.exe
C:\Program Files\Samurize\Client.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Documents and Settings\F H e L\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\F H e L\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.netflix.com/MemberHome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID}
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O3 - Toolbar: QT TabBar - {d2bf470e-ed1c-487f-a333-2bd8835eb6ce} - mscoree.dll (file missing)
O3 - Toolbar: QT Tab Standard Buttons - {D2BF470E-ED1C-487F-A666-2BD8835EB6CE} - mscoree.dll (file missing)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\G-series Software\LCDMon.exe"
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [vptray] C:\Program Files\Norton\vptray.exe
O4 - HKLM\..\Run: [Framework Windows] frmwrk32.exe
O4 - HKLM\..\Run: [Blujeqayofikahas] rundll32.exe "C:\WINDOWS\Nqamalolacihi.dll",e
O4 - HKLM\..\Run: [jsf8uiw3jnjgffght] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\winlognn.exe
O4 - HKLM\..\Run: [Kdawat] rundll32.exe "C:\WINDOWS\upevoyoxajijohap.dll",e
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\IGN\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\F H e L\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Executor] "C:\Program Files\Executor\executor.exe" -s
O4 - HKCU\..\Run: [D-Color] C:\Program Files\D-Color\dcolor.exe
O4 - HKCU\..\Run: [miniMIZE] C:\Program Files\miniMIZE\miniMIZE.exe
O4 - HKCU\..\Run: [jsf8uiw3jnjgffght] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\winlognn.exe
O4 - HKCU\..\Run: [csjmijd96flzjwbfkdt] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\x3hvbfjjtv8.exe
O4 - HKCU\..\Run: [ml53hzopky5mipv] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\nhyyvuj.exe
O4 - HKCU\..\Run: [iw86dw5i52qpg2abdbz23egctf2a28f4pmcpi] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\p0ak6fmi2h8.exe
O4 - HKCU\..\Run: [x0mw5tjuozfwippivvn2sl6cngxvtibnen4vhw] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\m7v1ftwy3yds.exe
O4 - HKCU\..\Run: [MS AntiSpyware 2009] "C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\msas2009.exe" /autorun
O4 - HKCU\..\Run: [fbu1wi9mqx15evz9seac4dr4dhv7cish] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\uesmi0.exe
O4 - HKCU\..\Run: [fh0nq8bfbdnp0vwyd9gyw0khjqtn1t2t] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\nkalgmg3q4dc7.exe
O4 - HKCU\..\Run: [i5ncfzkqx94lxqfge] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\cigjktg9i8.exe
O4 - HKCU\..\Run: [xhq26mutp453z5yyre2mosrjt1p3t3qabnyihbq4ry0trbr] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ok8d9mu1h6rr.exe
O4 - HKCU\..\Run: [va56uiw5v2vky1o2kva3mbeaf3qp9tscczn6tje0wclmcr] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\fh452ttihhg.exe
O4 - HKCU\..\Run: [hidh0uewahesyrbuen1x3ew1azthn3mzszo22doao] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\royjhktogfcc.exe
O4 - HKCU\..\Run: [ki3tl3fuef588hlg8mk9fjluqjub3lgssr3t6oqcu] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\x1bzxx7p1y.exe
O4 - HKCU\..\Run: [jwx45bubt43na8yo6da66bhsc3vp2] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\stp1me2.exe
O4 - HKCU\..\Run: [evd68kpgf8xmrhruyc006] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\de4f3oqegc8dr.exe
O4 - HKCU\..\Run: [knwfbf3aglv15bajyn1h9j6t9u2yp51kx] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\o6fvbzdp.exe
O4 - HKCU\..\Run: [nfln919pciqaxn8emjybaaalu9cfi] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ly9degonpw.exe
O4 - HKCU\..\Run: [wexmcsfwkvvw2iluawj6la5ic74slncm1xj7mr9wc] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ellvllzp9kj.exe
O4 - HKCU\..\Run: [tam0e75vpi016e0la8tw4zkysepoo7] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ttngeq7o.exe
O4 - HKCU\..\Run: [xdw2dxi3h1gok408d8mhvmhojr] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\evnzk09hs.exe
O4 - HKCU\..\Run: [fq4b9v2gk] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ozpkjuy0rg37.exe
O4 - HKCU\..\Run: [sxfus7hjstzoz789v3vh9986rtrn2t1mtyzc3972zt] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\wiwnz3t.exe
O4 - HKCU\..\Run: [yxzrebbx5yatqswfxx0pyefjz9h1v4jn] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\xen5dwxvnymz.exe
O4 - HKCU\..\Run: [hz9pevghjfxblzwaquofdn9rojuq1rzncxc0h] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\sz9dovcx6.exe
O4 - HKCU\..\Run: [ahxpuihzgnab2c2k1e83y31dg60lcia] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\j713fih2e.exe
O4 - HKCU\..\Run: [kep8frp1nco] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\eo2iowsul9p2s.exe
O4 - HKCU\..\Run: [w3xi6cbn5jbfqx7hjnup6sho5c7d8ylgfmsm1z4n] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\scx1r569hxu.exe
O4 - HKCU\..\Run: [ymf3ff0f4mupexuc7iz7oiktj7clkyhxcbq33jkm] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\mxqh5qd6vl.exe
O4 - HKCU\..\Run: [xm972eeoitci] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\azq0b0fzy3i.exe
O4 - HKCU\..\Run: [gljnudmq7wisy8cmb1miamwsrmsd] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\c5fd4sr.exe
O4 - HKCU\..\Run: [kyuu1x56ysizqewgbnxwnjln89hld55n5d3ho60ku] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\eg78awbfx9rr.exe
O4 - HKCU\..\Run: [xo24ffzb4pvorn1549suref] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\z660kvtfly.exe
O4 - HKCU\..\Run: [er3i359chj0x00vo8nr4xhvnumc8nxiihkn1gpc1tr385lc] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\kupmg3jm7g.exe
O4 - HKCU\..\Run: [lsknx97qg6qweg0e3yho1em00qwe] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\cqwnf8adqa.exe
O4 - HKCU\..\Run: [pv6ag7lx9v] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\neyqbzh3ts.exe
O4 - HKCU\..\Run: [p34e1wufi9oaiebabjx3k5ut] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ysm91a.exe
O4 - HKCU\..\Run: [ghjwshjwa] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\njhtkgmht.exe
O4 - HKCU\..\Run: [fvneugu4p] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\q37xwc3fy.exe
O4 - HKCU\..\Run: [k2l0phiomm9ulo1kobnjjnbvbu9gfyc734ka2pb] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\em7g23581m.exe
O4 - HKCU\..\Run: [yqhtzjf4rw86tykyeodwrrjf1gmlw1e10xwkzcn] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\a7qivn9u7m54.exe
O4 - HKCU\..\Run: [lavk0ippii3qa2dpit9eq63p52ngkbhpwql] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\pyl2eto.exe
O4 - HKCU\..\Run: [vbxg2l59ax1tblbho2xbi5h8g74nhvxqt679oyp11dpqloc] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\wq16akzrbpl.exe
O4 - HKCU\..\Run: [lvn233rjwr4niw4u7h9e14wsxqxo] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\vchf8zd.exe
O4 - HKCU\..\Run: [oh4ibn5m0o24r1ajnqjuu] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\z6c0ucve.exe
O4 - HKCU\..\Run: [e6djm4qmg5v6vmryynfgvulnj3kwchvbc2ygr] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\cgqk0svvsqqb.exe
O4 - HKCU\..\Run: [n8ska376xs1vcwl7drkh4w7mxeihybbiv] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\jk95z31.exe
O4 - HKCU\..\Run: [dfq5y84cc] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\v82mgvbbcekm.exe
O4 - HKCU\..\Run: [mqf5u4lb42j8p1ugql32iareditwuvwv5g6p6owk] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\u8s8vu8.exe
O4 - HKCU\..\Run: [rmadp3z24dlnsvucin6eahja3ykrhfku0e40u98tllmxi] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\uidvu919nqpcp.exe
O4 - HKCU\..\Run: [efbcuelkll0o1hmflmspiwjj] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\mqpwdfgg.exe
O4 - HKCU\..\Run: [m971w231n2gaocexkt4qyvdvrp74geyhn34y1] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\fw1ekkrix.exe
O4 - HKCU\..\Run: [crsz8omn5k1ykda4g1hz3vgj3] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\po0pdlupf.exe
O4 - HKCU\..\Run: [uaqvk6vmyydajuhusempda4ltx8toay] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\r31wgkl39e.exe
O4 - HKCU\..\Run: [ln8yoh8mu1nspf] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\bwco08ddn8ef.exe
O4 - HKCU\..\Run: [wi7kc06nn5kwy9srfxpeub1mkz37arj59wtt9jptpd] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\x7hnnc0ih2.exe
O4 - HKCU\..\Run: [ubtau15rc0xha6bisljqkf77n6qocshcjnbab3c1z4d14gtb46] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\mt0oqj33.exe
O4 - HKCU\..\Run: [qnmbb6zva] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ep786ouu.exe
O4 - HKCU\..\Run: [wf99pp3v2j210tk8flqsv8dtjmun8plk2d] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ludk3cm.exe
O4 - HKCU\..\Run: [vre8vb305c7ifua7pqrreeqf1fshtnf3f] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\cx3q4im3.exe
O4 - HKCU\..\Run: [asg7dxsdm2t91jaqe7thcd] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\vdashkemt3oj5.exe
O4 - HKCU\..\Run: [rhefwpxpb1lke5at8txhzp] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\kgttkr07qlb.exe
O4 - HKCU\..\Run: [whu2xquxo1] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\boljbe5vyyg.exe
O4 - HKCU\..\Run: [co55jqxq9oyd1g6c57] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ems3xthfkrso.exe
O4 - HKCU\..\Run: [pz1ol9kl4oo] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\b3zrg6.exe
O4 - HKCU\..\Run: [bqlkrtwcn] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\d3ps5r7w2.exe
O4 - HKCU\..\Run: [ayy0j6ol5azqnu3u6vpyzma454] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\hs1ainkrpmx.exe
O4 - HKCU\..\Run: [sirpxuevascszslts78e0mbxuujx7vxop59f2] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\lc1bf3lj.exe
O4 - HKCU\..\Run: [jbvwd2lda7np5gb7t3su6vzs91hpm3qfmzy] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\cxs7vz.exe
O4 - HKCU\..\Run: [dmu3z3fhp1jim29j9sth02m9jownth1ky] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\v94xubtezwy6b.exe
O4 - HKCU\..\Run: [i5zc9yxgipjk6jqhq8cq31alj5yuugphs3ka3h0h6xl] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\vvn0oicj3l1v.exe
O4 - HKCU\..\Run: [ckbz5uih77i2gu94rm83s7q72wbpvl96vabos03] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\kmi13yd.exe
O4 - HKCU\..\Run: [wix010yqnk483gb] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\dsuja3oi.exe
O4 - HKCU\..\Run: [suq1io9ulh3vcf8n] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\v51k98f9.exe
O4 - HKCU\..\Run: [j3184thqyjd6xd4uws5cm38] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\nwdl9eux1qk.exe
O4 - HKCU\..\Run: [ql5yhynqnsj65wkvzmn2bdfoy48peyr4go9gu9p6gfh9pe4] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\jmfqbwmgqqq1.exe
O4 - HKCU\..\Run: [usk0p9aajkya9z] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\jy3qzno.exe
O4 - HKCU\..\Run: [nzwb3ixfewk7fo6riq1821gv17qzqxw22na] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ql5sdrgs6l.exe
O4 - HKCU\..\Run: [sh0kd94waiycl4g] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ee0epy3.exe
O4 - HKCU\..\Run: [cl92p468imcdfrvkq786u8ltnvlqg5moa19oigbls3801x] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ejjyff.exe
O4 - HKCU\..\Run: [dz9m687ckp7j0f] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\b9oe9zrpnb.exe
O4 - HKCU\..\Run: [xbhf3r8ibnhil1y5] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\fgnpnoc63md.exe
O4 - HKCU\..\Run: [y31xtpxx7fnf6oq8v8fkf8u7lerz3amnf2t7cadtged5r] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\brbotszbg.exe
O4 - HKCU\..\Run: [zapw0zv3j] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\w78c4t704.exe
O4 - HKCU\..\Run: [c6slf91pshk0keqv6enqfsp] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\cse64kfq2nz.exe
O4 - HKCU\..\Run: [xwqnr266ahnfb6] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\v828hm79.exe
O4 - HKCU\..\Run: [hozy3n6qjpokunfmhggeer22uzkg] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\oee7oribi.exe
O4 - HKCU\..\Run: [auxkxp646vv] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\u8iep3g9xnb9o.exe
O4 - HKCU\..\Run: [arj9ji0ydb4x55myaqojs7htoe8tp85] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\uy4ujnkzi.exe
O4 - HKCU\..\Run: [r0v9y4lxrzex5x7ukq1twf0im8z3rbroj6sys] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\upphi29.exe
O4 - HKCU\..\Run: [wv0dsr6anzqz7e52s68736xadwpiz7ptdh5l2] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\frp0ocbd.exe
O4 - HKCU\..\Run: [ybo2il98r7xo7hqf3g87sc4lz4fd] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\mldihq0.exe
O4 - HKCU\..\Run: [chflux04n813eqtcr] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\lgr4g74e5hgrc.exe
O4 - HKCU\..\Run: [ac64e3ep2s3qminjrfaw70vh6b002] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ajaoje7z2i3.exe
O4 - HKCU\..\Run: [wtbyz1bop124j4de] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\sfhpijyqlcw.exe
O4 - HKCU\..\Run: [ycsl9v4f3txgguf5oo6lhuhi7mp61j3963ef4avk] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\lvorv4q9.exe
O4 - HKCU\..\Run: [tfogis7cdhtezdbt74] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\d8jv4rau7u.exe
O4 - HKCU\..\Run: [e4g3rmd4ll7dptw0vjavdgnr] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\zoju7b92dulqj.exe
O4 - HKCU\..\Run: [hjnih3frph7mm6a26tum6c0] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\gsszz4rsc6.exe
O4 - HKCU\..\Run: [ifoe67k9b7qh] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\b3u6u64eo6wtt.exe
O4 - HKCU\..\Run: [axrzqcf6yode1eiz9yvhi6yzviavcb2fmljz2owbm6] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\c4dormo61a.exe
O4 - HKCU\..\Run: [k3eookxekg3b22r50bxcs0n7ryh38lzxfzyuh] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\mrw9qxu4aojxd.exe
O4 - HKCU\..\Run: [ld62oswyv12nlcd7kzsqhhm58ot3zyn] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\xawsw7.exe
O4 - HKCU\..\Run: [yzrrvui0tk7h0buco5szv4j] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\bzra939s.exe
O4 - HKCU\..\Run: [bkqhgxc5yt471z3qqe1dnhfk7xwkarfd54ehif4s] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\fe88gj.exe
O4 - HKCU\..\Run: [dgkzt0rkyrpdvjhxg3jbl9] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\j3k9tyi1.exe
O4 - HKCU\..\Run: [r1u0ip3etr54bxrjm96o8nnkx71cl8] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\c9w80ktk1.exe
O4 - HKCU\..\Run: [ka5kjmas2zqju1h4jk5bhjifnjzhgubhynq2d] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\fgc6x5e5h.exe
O4 - HKCU\..\Run: [go9jlll0hbqe2or3sju0bamt0k7s8bxxt30ue] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\i02ts1v33.exe
O4 - HKCU\..\Run: [gdrv00idqgnfzk3tsslzkphgj4qa6k] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\o0mrop.exe
O4 - HKCU\..\Run: [p9rb6ch06wboi1qypogqhskfux] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\a7b5qu.exe
O4 - HKCU\..\Run: [e8i41t8d97l7r539h31nxvwvk9eqs76z565g711dwl] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\nv0d66trvxnp.exe
O4 - HKCU\..\Run: [vb5loy3movu7xm5v2ifosvl2iocqh9ypcdjys9us7dao1] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\oa8v1ix3o.exe
O4 - HKCU\..\Run: [mf7kpb5e6pz75bqj9jh7f0sgpzipwprbem68m] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\u8oezkipb9g.exe
O4 - HKCU\..\Run: [jh9cgqouv1h6diojyc9auhtbljo] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\dnmza5hoemq.exe
O4 - HKCU\..\Run: [ykf72kue937plj] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\j2tjfka80y25.exe
O4 - HKCU\..\Run: [gkmm9midynm338vob7kk597txw99wtg0c5v9bis] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\c3mydp.exe
O4 - HKCU\..\Run: [bzb1li4tyg7mfola52pt3z3mujsgty0gi0fu4] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\p1wtszyeps.exe
O4 - HKCU\..\Run: [dfbfuv3sbdb6kin6cqrj5iydh6rynl9ugrv] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ce4s0i.exe
O4 - HKCU\..\Run: [yn9wxa1wspkmz9hz2zshoqrpg7wyp1z5e3fw3q] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\zkt16797.exe
O4 - HKCU\..\Run: [l4gqg1hbdmz69pte0vkcte0cemgy5qrpmwevtq492] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\mn6xptu9.exe
O4 - HKCU\..\Run: [lzo0mxf6et0mt1zpz7meffr4r] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\lnwndnz052b.exe
O4 - HKCU\..\Run: [ndsnzlvul9w88nlb1hrnk9djw4seku4c48fzj34oo41xjz] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\t1a5n2agg.exe
O4 - HKCU\..\Run: [bhp25ruuj8zi] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\swor5je.exe
O4 - HKCU\..\Run: [yczpbq3olwu0yp64l2bms5aluqx7u69p1rqi7u4y3lic54b] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\hu58z9.exe
O4 - HKCU\..\Run: [djs4be4zmlf0il5h] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\m2kk47g40zh.exe
O4 - HKCU\..\Run: [i9syz7lerhgybsu6t6maxj6hx8myma5xgvbbt8vxvttccjnje3] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\rc598mdrlh.exe
O4 - HKCU\..\Run: [m4wehwxxxv3zorqjjifoq1zd] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\o7tqsn1osbidv.exe
O4 - HKCU\..\Run: [nyhtvek6f9j4e519kmcw373] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\g30arssfb5b6f.exe
O4 - HKCU\..\Run: [zgddd7hfo3oid95] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\c9vqpvw02hyw.exe
O4 - HKCU\..\Run: [i5hr61u6qseux1qg8b378jia2xk2dowuey0rz5ddupxy8zaas] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\nse9v5yt5zyno.exe
O4 - HKCU\..\Run: [vpqgpsv53u0y2lv3acg3ozjxhv94] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\v1qs5ycgm5s7.exe
O4 - HKCU\..\Run: [kt71oes1d9vuwyiuiy6636fvvyy2m10] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ygxcrdo0rh4rr.exe
O4 - HKCU\..\Run: [denya6sffxa8tt6wh3uxrxodz9b4c] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\cabxdq.exe
O4 - HKCU\..\Run: [nxhtzomokaj01g364xs71236ga2s9qr9fomef43rzg2u58] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\phk5oxt5s.exe
O4 - HKCU\..\Run: [llfc3geg64tsatllw3qo] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\avroe8jv2twui.exe
O4 - HKCU\..\Run: [bbjcb16puo09smwgtaznzxjhcold204a10of] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\q8p3fxdgtb.exe
O4 - HKCU\..\Run: [py1ooulcggqhmjodm5hm628w01zvnpopekfarvi6zwyq4] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\tn37ubzbm0qm1.exe
O4 - HKCU\..\Run: [fzmj9z1bl6422o0yo2dqqa3cs] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ek36r4w.exe
O4 - HKCU\..\Run: [iek9zrg77i5ziz7e7] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\bfr6b5knwc.exe
O4 - HKCU\..\Run: [l9kw1bbxtqqxcdj9h] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ljarep4aq0irz.exe
O4 - HKCU\..\Run: [g8f8vunrx45mvo] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\pyrphfmgzbj.exe
O4 - HKCU\..\Run: [wr9vn6qq20bbn4yqttpjftpbhi00s] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\guvfo1mo.exe
O4 - HKCU\..\Run: [on3b0g597my92eg8rhvol] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\kojghwb.exe
O4 - HKCU\..\Run: [tx6djd5k5vgntr9j1vngbgp] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\hl0dfi6z1.exe
O4 - HKCU\..\Run: [oxdfokvgcioosdo3nvtxe3vznic89i1y44fg30fnewcmehmqfx] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\rixik9te.exe
O4 - HKCU\..\Run: [pw64i1llwqcw4hjra661mg4jkcr25hzr8zi47h8h5y6r3avjyy] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\zr2h13e7do7x9.exe
O4 - HKCU\..\Run: [o6j8l3pjrv] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\v79jxo69qi.exe
O4 - HKCU\..\Run: [h523azrms8ap4ib8vrw7j4ogh5kj] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\db2zy0fz7o.exe
O4 - HKCU\..\Run: [qxjcj85dyc94s1vgoghf] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\bbpa4xl5h6.exe
O4 - HKCU\..\Run: [gdj7847gzp05e4qqt5av3cz60tme86wxi4lx8d3] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\jf19osueyc.exe
O4 - HKCU\..\Run: [sqd08lf04isi07vpv8h03z0z42uph9g0ve87saua] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\xh1sb2w71us.exe
O4 - HKCU\..\Run: [ngklwbhyc25e4hksej95] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\x3kck01lku.exe
O4 - HKCU\..\Run: [uwu05ja9y] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\p9mgp4.exe
O4 - HKCU\..\Run: [kio3ehawvhd1gt5t09t1ub6bbvg3itxo4mh9neira9hpi8a78] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ifyfwq3.exe
O4 - HKCU\..\Run: [ci4etsedh50bhqyx637atzgdv8flhydloky9v4fqlcrul1zd] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\u83wahpzk.exe
O4 - HKCU\..\Run: [y33d88ky29fd378d3bqp2vjpj] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ty51ciyi9d.exe
O4 - HKCU\..\Run: [d6sd0ltjtznf] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\so034ie78.exe
O4 - HKCU\..\Run: [i89icwn3d6uinnermxyd0u03xa9mpde] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\pjokoj24fdac.exe
O4 - HKCU\..\Run: [jdk3rtmqm58fsd] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\hwv44otvy735.exe
O4 - HKCU\..\Run: [po16ugxs0jebekzacene03q0kmhnvd7] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\d7j3rsg0b1.exe
O4 - HKCU\..\Run: [w7isypcmu1yzlf6diro9bttckx0y] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\i602vod6z1ya9.exe
O4 - HKCU\..\Run: [mvtllhqjdia9] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\znq5nd8.exe
O4 - HKCU\..\Run: [np4rxbuq6u2qysbmf40ur7] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\beclzy0665zwr.exe
O4 - HKCU\..\Run: [uhm4s2a829hzx16iq8ivae6dajayktij3qaicpomye7d8h7] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\cahx4q8899m9.exe
O4 - HKCU\..\Run: [p3nwunr9kr3oaatzgoisvvrg2p] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ph9myxv.exe
O4 - HKCU\..\Run: [qz8g1i562rakfbip32eh8pzi3bwzd2aeugtd6kcwi7nco9] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\wlzrqquumfq5.exe
O4 - HKCU\..\Run: [ysf9nmvb9qtcwwx88qlv0qie29r9ie8rit423ysadwdmo] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\s6itjr.exe
O4 - HKCU\..\Run: [jn2csu59pg0xwko59r2kh1qe9] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\hz6axikk.exe
O4 - HKCU\..\Run: [btsr54fwsp70bzkj6qo0vik3jo7g9] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\t26u0p.exe
O4 - HKCU\..\Run: [jkg8xcw0qunuzgtkrxpb3iqhd] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\c65lqh.exe
O4 - HKCU\..\Run: [adihd84vumj0xe3] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\rxhmqn0pa.exe
O4 - HKCU\..\Run: [vn428vg93giyd6pqs9sujzqhmj9yqnk4myly4cjx26] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\vy0nnk.exe
O4 - HKCU\..\Run: [so1i32qqf09f7q0j2vudrbczk0ivr8hkc2aaiytnyuurh] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\kpco69god.exe
O4 - HKCU\..\Run: [rfc8851k93jivc1eaoq57lw9p3zits] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\xrlcrzfn8m6ho.exe
O4 - HKCU\..\Run: [avs003xu12yskny6jvochd4m683oqbmz0eekw6p] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\b2gedc.exe
O4 - HKCU\..\Run: [l68ijpr8cpmfo36tdfxkvr46n8ay57tn6889yat9] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\bx4exd4tl.exe
O4 - HKCU\..\Run: [jajri40tpc8l2xt6r5hd3283] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\p4zx0mi.exe
O4 - HKCU\..\Run: [i6tzttyj1pbanquxry6] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ll3612.exe
O4 - HKCU\..\Run: [oxkqmdsdh] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\h1a8x4cjjnf.exe
O4 - HKCU\..\Run: [o9gy6ghmmo6468o0de8o6pffl48b5po3eu1605lpt0c] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\ax5lstol8.exe
O4 - HKCU\..\Run: [cto5sn3yjzr] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\hb5s3kt.exe
O4 - HKCU\..\Run: [fj4h4lv6qaycycovrnrqj5ovr4z6n2b] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\cc5czowuot3s.exe
O4 - HKCU\..\Run: [cgn3to5as1s2hqfxgdwpzmhju9qhn18681] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\y9cev9od1.exe
O4 - HKCU\..\Run: [xn3ifzar6mtf3ciwg23w34or6knd] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\gwouw4xmi.exe
O4 - HKCU\..\Run: [anng19a9wlwc1yjncc] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\d8cuz5ljpnla.exe
O4 - HKCU\..\Run: [py8gxt78o2or2h8v3in5gi0nwd92jcbizm3e3] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\zjhcmq8o2h.exe
O4 - HKCU\..\Run: [u86jcn017znkc2vqz6heda] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\rk7xbcnt4.exe
O4 - HKCU\..\Run: [l0zm64g1n11m7k83rxf0tsx] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\fdljn2.exe
O4 - HKCU\..\Run: [q5aivmb9munfkpo6856k7k] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\u4xkn8laq.exe
O4 - HKCU\..\Run: [whludkj3xqblqjxqbhk2rffbma2puyz2n] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\r6q01ts7.exe
O4 - HKCU\..\Run: [r5ofbdostksvpwzputl8cm85ll4hzqwawhf] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\by4lgma8.exe
O4 - HKCU\..\Run: [his135lkvp3ltcz] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\b3n5pkf.exe
O4 - HKCU\..\Run: [awwpf0gdv0kv26ccx1dpbidnqtexunahtk0ltuzkv2ytii] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\e8z5mjrpz5vv.exe
O4 - HKCU\..\Run: [ot4unm9ezn03glyimceo7ku2i14nz1g0ztipfkmwp6v8uclf] C:\DOCUME~1\FHEL~1\LOCALS~1\Temp\tzb6586.exe
O4 - Startup: Client Default.lnk = C:\Program Files\Samurize\Client.exe
O4 - Global Startup: SetPointII.lnk = ?
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\docume~1\fhel~1\locals~1\temp\ntdll64.dll
O10 - Unknown file in Winsock LSP: c:\docume~1\fhel~1\locals~1\temp\ntdll64.dll
O16 - DPF: vzTCPConfig - http://www2.verizon.net/help/fios_settings/include/vzTCPConfig.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175/7d/runaware.download.akamai.com/25175/citrix/wficat-no-eula.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.2.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1235190547000
O20 - AppInit_DLLs: wbsys.dll atxpii.dll
O22 - SharedTaskScheduler: IE Component Categories cache daemon - {553858A7-4922-4e7e-B1C1-97140C1C16EF} - C:\WINDOWS\system32\ieframe.dll
O22 - SharedTaskScheduler: jgzfkj9w38rksndfi7r4 - {C5BF49A2-94F3-42BD-F434-3604812C8955} - (no file)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Norton\defwatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Norton\rtvscan.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 27712 bytes