Help! I have a problem that i can't get off my computer. I keep running S&D and sometimes it says it fixes it but it doesn't. I have turned off sys restore and tried that to no avail. here are the kaspersky log and hjt log. thank you.
C:\WINDOWS\83122.0xe/data0004 Infected: Trojan-Clicker.Win32.Small.jf skipped
C:\WINDOWS\83122.0xe NSIS: infected - 1 skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{1E2928AD-60EC-40CA-9D0C-EFA581CD7AE3}.crmlog Object is locked skipped
C:\WINDOWS\retadpu1000106.0xe Infected: Trojan-Downloader.Win32.Agent.bls skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\akegyptd.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\arieioca.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\awfengen.0xe Infected: Trojan.Win32.Agent.ny skipped
C:\WINDOWS\system32\badfjrbi.0ll Infected: Trojan-Spy.Win32.Agent.ps skipped
C:\WINDOWS\system32\bfwtmrmy.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\bnifkvyw.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\ccxkxkpg.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\cftrrxkr.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\cgkfhyly.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\checkdll\d77012.0xe Infected: Trojan-Downloader.Win32.Small.eqn skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\cskwgyuv.0xe Infected: Trojan.Win32.Small.ju skipped
C:\WINDOWS\system32\dwjidewe.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\ekjgkopu.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\esgppqjm.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\eublrnwq.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\eukceajg.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\f02WtR\f02WtR1065.0xe Infected: Trojan-Downloader.Win32.VB.awj skipped
C:\WINDOWS\system32\fgfgqpxs.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\fmmrfrrq.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\fqghbqma.0ll Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\WINDOWS\system32\frsrvmyn.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\fwivhncl.0ll Infected: Trojan.Win32.BH
skipped
C:\WINDOWS\system32\gkvtjwit.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\grxtjpof.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\gtjgnwax.0xe Infected: Trojan.Win32.Small.ju skipped
C:\WINDOWS\system32\gtppdykc.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\gwfoctjc.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\hrirpfwx.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\hwjvorgv.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\ibtgmosa.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\isvcfyao.0xe Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\WINDOWS\system32\jagofede.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\jrmpuggo.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\jsqdwlee.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\jthalcug.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\kcewemef.0ll Infected: Trojan.Win32.BH
skipped
C:\WINDOWS\system32\kesaydhe.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\khqpcdhy.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\lhgcnpro.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\ljraalsq.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\lmmifxbp.0xe Infected: Trojan.Win32.Small.ju skipped
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\system32\mcknkycl.0ll Infected: Trojan-Spy.Win32.Agent.ps skipped
C:\WINDOWS\system32\mcpseqot.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\mpyoeelt.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\MsDtc\MSDTC.LOG Object is locked skipped
C:\WINDOWS\system32\MsDtc\Trace\dtctrace.log Object is locked skipped
C:\WINDOWS\system32\obetscln.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\obnbncgr.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\ocndlcjk.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\oellsdbp.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\paljwckv.0xe Infected: Trojan.Win32.Small.ju skipped
C:\WINDOWS\system32\ptelvfcp.0ll Infected: Trojan.Win32.BH
skipped
C:\WINDOWS\system32\puessloy.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\pwqrwcvq.0xe Infected: Trojan.Win32.Agent.amc skipped
C:\WINDOWS\system32\qaferjrp.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\qfodjqbf.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\qmievxer.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\qrkdlfbu.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\qxovcixa.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\qyhcnbkf.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\rdisslrm.0ll Infected: Trojan.Win32.BH
skipped
C:\WINDOWS\system32\rntqudtp.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\rpscescm.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\rsxijpag.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\sgsrkpyl.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\sgvghohp.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\sopnyycj.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\taeevniw.0ll Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\WINDOWS\system32\tcepioen.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\tjicufhc.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\tqburbcf.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\txqefdqg.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\uifkmosb.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\ushxsaaq.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\utoftvef.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\uywcusda.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\vdlbpxvf.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\vgcggmkw.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\vgvqkntc.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\wmpskwhf.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\wnaaucwf.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\xbuxclja.0ll Infected: Trojan.Win32.BH
skipped
C:\WINDOWS\system32\xeelshtm.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\xfdtwmdu.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\xjqryoqx.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\xobaepyq.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\xsppteiu.0ll Infected: Trojan.Win32.BH
skipped
C:\WINDOWS\system32\xuhwofvs.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\xyohgrgy.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\ydjbhegb.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\yetkwpqe.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\yunyrqpi.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\yvjtkvpp.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\yyxfhpom.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
C:\DOCUME~1\Tony\LOCALS~1\Temp\JETF82.tmp Object is locked skipped
C:\DOCUME~1\Tony\LOCALS~1\Temp\snapsnet.0xe/data0005 Infected: Trojan-Downloader.Win32.VB.awj skipped
C:\DOCUME~1\Tony\LOCALS~1\Temp\snapsnet.0xe NSIS: infected - 1 skipped
C:\DOCUME~1\Tony\LOCALS~1\Temp\yazzlesnet.0xe/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eg skipped
C:\DOCUME~1\Tony\LOCALS~1\Temp\yazzlesnet.0xe NSIS: infected - 1 skipped
HJT
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:36:58 PM, on 8/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Charter High-Speed Security Suite\Anti-Virus\fsgk32st.exe
C:\Program Files\Charter High-Speed Security Suite\Anti-Virus\FSGK32.EXE
C:\Program Files\Charter High-Speed Security Suite\Common\FSMA32.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Charter High-Speed Security Suite\Anti-Virus\fssm32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\hphmon05.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\WINDOWS\system32\bcmntray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Charter High-Speed Security Suite\Common\FSLAUNCH.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=pavilion&pf=laptop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.netscape.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q304&bd=pavilion&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q304&bd=pavilion&pf=laptop
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\bcmntray
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Charter High-Speed Security Suite\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Charter High-Speed Security Suite\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BackupNotify] C:\Program Files\HP\Digital Imaging\bin\backupnotify.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: V CAST Music Monitor.lnk = C:\Program Files\Verizon Wireless\V CAST Music Essentials Manager\V CAST Music Monitor.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q304&bd=pavilion&pf=laptop
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab46479.cab
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (ZoneBuddy Class) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab32846.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab32846.cab
O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} (ZPA_TexasHoldem Object) - http://zone.msn.com/bingame/zpagames/zpa_txhe.cab45837.cab
O16 - DPF: {AF087E66-838E-4A97-8A0B-0DDDA5DEA239} (OTAutoInstall Class) - https://streaming.endeavors.com/microsoft/imaging/clientdownloads/OTAI.CAB
C:\WINDOWS\83122.0xe/data0004 Infected: Trojan-Clicker.Win32.Small.jf skipped
C:\WINDOWS\83122.0xe NSIS: infected - 1 skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{1E2928AD-60EC-40CA-9D0C-EFA581CD7AE3}.crmlog Object is locked skipped
C:\WINDOWS\retadpu1000106.0xe Infected: Trojan-Downloader.Win32.Agent.bls skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\akegyptd.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\arieioca.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\awfengen.0xe Infected: Trojan.Win32.Agent.ny skipped
C:\WINDOWS\system32\badfjrbi.0ll Infected: Trojan-Spy.Win32.Agent.ps skipped
C:\WINDOWS\system32\bfwtmrmy.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\bnifkvyw.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\ccxkxkpg.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\cftrrxkr.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\cgkfhyly.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\checkdll\d77012.0xe Infected: Trojan-Downloader.Win32.Small.eqn skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\cskwgyuv.0xe Infected: Trojan.Win32.Small.ju skipped
C:\WINDOWS\system32\dwjidewe.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\ekjgkopu.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\esgppqjm.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\eublrnwq.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\eukceajg.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\f02WtR\f02WtR1065.0xe Infected: Trojan-Downloader.Win32.VB.awj skipped
C:\WINDOWS\system32\fgfgqpxs.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\fmmrfrrq.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\fqghbqma.0ll Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\WINDOWS\system32\frsrvmyn.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\fwivhncl.0ll Infected: Trojan.Win32.BH
C:\WINDOWS\system32\gkvtjwit.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\grxtjpof.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\gtjgnwax.0xe Infected: Trojan.Win32.Small.ju skipped
C:\WINDOWS\system32\gtppdykc.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\gwfoctjc.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\hrirpfwx.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\hwjvorgv.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\ibtgmosa.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\isvcfyao.0xe Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\WINDOWS\system32\jagofede.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\jrmpuggo.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\jsqdwlee.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\jthalcug.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\kcewemef.0ll Infected: Trojan.Win32.BH
C:\WINDOWS\system32\kesaydhe.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\khqpcdhy.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\lhgcnpro.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\ljraalsq.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\lmmifxbp.0xe Infected: Trojan.Win32.Small.ju skipped
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\system32\mcknkycl.0ll Infected: Trojan-Spy.Win32.Agent.ps skipped
C:\WINDOWS\system32\mcpseqot.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\mpyoeelt.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\MsDtc\MSDTC.LOG Object is locked skipped
C:\WINDOWS\system32\MsDtc\Trace\dtctrace.log Object is locked skipped
C:\WINDOWS\system32\obetscln.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\obnbncgr.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\ocndlcjk.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\oellsdbp.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\paljwckv.0xe Infected: Trojan.Win32.Small.ju skipped
C:\WINDOWS\system32\ptelvfcp.0ll Infected: Trojan.Win32.BH
C:\WINDOWS\system32\puessloy.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\pwqrwcvq.0xe Infected: Trojan.Win32.Agent.amc skipped
C:\WINDOWS\system32\qaferjrp.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\qfodjqbf.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\qmievxer.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\qrkdlfbu.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\qxovcixa.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\qyhcnbkf.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\rdisslrm.0ll Infected: Trojan.Win32.BH
C:\WINDOWS\system32\rntqudtp.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\rpscescm.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\rsxijpag.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\sgsrkpyl.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\sgvghohp.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\sopnyycj.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\taeevniw.0ll Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\WINDOWS\system32\tcepioen.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\tjicufhc.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\tqburbcf.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\txqefdqg.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\uifkmosb.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\ushxsaaq.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\utoftvef.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\uywcusda.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\vdlbpxvf.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\vgcggmkw.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\vgvqkntc.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\wmpskwhf.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\wnaaucwf.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\xbuxclja.0ll Infected: Trojan.Win32.BH
C:\WINDOWS\system32\xeelshtm.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\xfdtwmdu.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\xjqryoqx.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\xobaepyq.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\xsppteiu.0ll Infected: Trojan.Win32.BH
C:\WINDOWS\system32\xuhwofvs.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\xyohgrgy.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\ydjbhegb.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\yetkwpqe.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\yunyrqpi.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\yvjtkvpp.0ll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\system32\yyxfhpom.0ll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
C:\DOCUME~1\Tony\LOCALS~1\Temp\JETF82.tmp Object is locked skipped
C:\DOCUME~1\Tony\LOCALS~1\Temp\snapsnet.0xe/data0005 Infected: Trojan-Downloader.Win32.VB.awj skipped
C:\DOCUME~1\Tony\LOCALS~1\Temp\snapsnet.0xe NSIS: infected - 1 skipped
C:\DOCUME~1\Tony\LOCALS~1\Temp\yazzlesnet.0xe/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eg skipped
C:\DOCUME~1\Tony\LOCALS~1\Temp\yazzlesnet.0xe NSIS: infected - 1 skipped
HJT
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:36:58 PM, on 8/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Charter High-Speed Security Suite\Anti-Virus\fsgk32st.exe
C:\Program Files\Charter High-Speed Security Suite\Anti-Virus\FSGK32.EXE
C:\Program Files\Charter High-Speed Security Suite\Common\FSMA32.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Charter High-Speed Security Suite\Anti-Virus\fssm32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\hphmon05.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\WINDOWS\system32\bcmntray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Charter High-Speed Security Suite\Common\FSLAUNCH.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=pavilion&pf=laptop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.netscape.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q304&bd=pavilion&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q304&bd=pavilion&pf=laptop
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\bcmntray
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Charter High-Speed Security Suite\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Charter High-Speed Security Suite\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BackupNotify] C:\Program Files\HP\Digital Imaging\bin\backupnotify.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: V CAST Music Monitor.lnk = C:\Program Files\Verizon Wireless\V CAST Music Essentials Manager\V CAST Music Monitor.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q304&bd=pavilion&pf=laptop
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab46479.cab
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (ZoneBuddy Class) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab32846.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab32846.cab
O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} (ZPA_TexasHoldem Object) - http://zone.msn.com/bingame/zpagames/zpa_txhe.cab45837.cab
O16 - DPF: {AF087E66-838E-4A97-8A0B-0DDDA5DEA239} (OTAutoInstall Class) - https://streaming.endeavors.com/microsoft/imaging/clientdownloads/OTAI.CAB