I got the desktop background changed, popups telling me my system is infected and ads for ultimate defender among other things. I have to continue the hijackthis log in another post because it is too long.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:46:02 PM, on 10/8/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\WINDOWS\System32\WgaTray.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\EarthLink 5.0\conmgr.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\BCMSMMSG.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,Search = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://out.true-counter.com/b/?101 (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer,Search = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://out.true-counter.com/a/?101 (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://out.true-counter.com/b/?101 (obfuscated)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://education.dellnet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.searchforit.com/searchbar
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://out.true-counter.com/c/?101 (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://out.true-counter.com/b/?101 (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchforit.com/searchbar
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://out.true-counter.com/a/?101 about:blank (obfuscated)
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O1 - Hosts: 216.93.168.167 sitefinder.verisign.com
O2 - BHO: (no name) - SOFTWARE - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {19B19F2E-09BC-47CF-A709-13B50B4620FC} - C:\Program Files\CSBB\CSBB.dll (file missing)
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {359F6495-6D24-4B75-8D8C-95F2DD94A24E} - C:\Program Files\CSBB\CSBB.dll (file missing)
O2 - BHO: (no name) - {38D4D5D0-423E-4220-B6F9-30918C2AE4A4} - (no file)
O2 - BHO: MSVPS System - {3ADCBC16-19FA-4C59-9C22-E17C71B5FD7A} - C:\WINDOWS\bndsrdkq.dll
O2 - BHO: (no name) - {4E7BD74F-2B8D-469E-C0FF-FA7FB592BF30} - (no file)
O2 - BHO: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: (no name) - {832BEBED-C3DA-4534-A2C2-B2FFF220C820} - (no file)
O2 - BHO: (no name) - {A9150711-B448-4878-9AF7-68C82CAD8000} - C:\Program Files\8w6fbfy3\8w6fbfy3.dll (file missing)
O2 - BHO: (no name) - {AC9CEDCC-7F9F-48E9-B9C1-1FA7962A73C1} - C:\Program Files\8w6fbfy3\8w6fbfy3.dll (file missing)
O2 - BHO: (no name) - {AF1BA546-A930-43E8-863D-9D39B1E6F976} - C:\Program Files\8w6fbfy3\8w6fbfy3.dll (file missing)
O2 - BHO: (no name) - {B5F3970B-745E-46AC-B890-E08F69777D80} - (no file)
O2 - BHO: (no name) - {B753C7C5-0942-4b7f-BC27-942B52BDAC66} - C:\PROGRA~1\ACCELE~1\StopSign\webcbrowse.dll (file missing)
O2 - BHO: (no name) - {C2365BA4-8E86-49F8-9C15-DA6600D3D79E} - C:\Program Files\8w6fbfy3\8w6fbfy3.dll (file missing)
O2 - BHO: (no name) - {C347A0AC-42B4-4E3E-9867-2412512A3D24} - C:\Program Files\8w6fbfy3\8w6fbfy3.dll (file missing)
O2 - BHO: (no name) - {C561ABA5-B6A0-46D9-9ECC-2F6F08D48824} - C:\Program Files\8w6fbfy3\8w6fbfy3.dll (file missing)
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdmcks.dll
O2 - BHO: (no name) - {CDA7FABE-7142-4004-845E-8AA884E529A8} - C:\Program Files\8w6fbfy3\8w6fbfy3.dll (file missing)
O2 - BHO: (no name) - {D36E8104-E529-4A76-9DE9-0BC52F11C8D0} - C:\Program Files\CSBB\CSBB.dll (file missing)
O2 - BHO: (no name) - {D80C4E21-C346-4E21-8E64-20746AA20AEB} - (no file)
O2 - BHO: (no name) - {E8808CC7-CE3E-4FC7-A0B2-65DCB8F91ABF} - C:\Program Files\8w6fbfy3\8w6fbfy3.dll (file missing)
O2 - BHO: (no name) - {ED182F32-4A69-4F63-B894-B69022344DAD} - C:\Program Files\8w6fbfy3\8w6fbfy3.dll (file missing)
O2 - BHO: (no name) - {F5DE8ADB-4A69-4e56-96AB-823171C8E9D8} - (no file)
O2 - BHO: (no name) - {FA67E157-C26C-4019-B3C8-BE9FE91B226A} - C:\Program Files\8w6fbfy3\8w6fbfy3.dll (file missing)
O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll
O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-C0FF-FA7FB592BF30} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (file missing)
O3 - Toolbar: BestOffers Shopping v1.20 - {7FD44536-9DF0-4034-939F-5BD4D98E3187} - C:\Program Files\TBONAS\TBONlchr.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: (no name) - {C109664B-CEB1-420b-B353-D55A561536DD} - (no file)
O3 - Toolbar: (no name) - {1a29a79a-b9c8-44a9-bedf-7fadde3cf33f} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [ConMgr.exe] "C:\Program Files\EarthLink 5.0\conmgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WebScan] "C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe" -k
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] "C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe"
O4 - HKLM\..\Run: [DeadAIM] "rundll32.exe" "C:\Program Files\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [lxbfrd] C:\WINDOWS\System32\vtlgqw.exe
O4 - HKLM\..\Run: [hnvy] C:\WINDOWS\System32\ichop.exe
O4 - HKLM\..\Run: [uykkyrz] C:\WINDOWS\System32\qfqgwyt.exe
O4 - HKLM\..\Run: [kwnh] C:\WINDOWS\System32\oegczuz.exe
O4 - HKLM\..\Run: [dfie] C:\WINDOWS\System32\cvpixdeu.exe
O4 - HKLM\..\Run: [nnlxvoy] C:\WINDOWS\System32\equsyw.exe
O4 - HKLM\..\Run: [cksob] C:\WINDOWS\System32\rlpdhsh.exe
O4 - HKLM\..\Run: [yaormqa] C:\WINDOWS\System32\qesjc.exe
O4 - HKLM\..\Run: [gqiuyx] C:\WINDOWS\System32\khlasjm.exe
O4 - HKLM\..\Run: [wwsyy] C:\WINDOWS\System32\gquncixs.exe
O4 - HKLM\..\Run: [vyhv] C:\WINDOWS\System32\dhsiwdeh.exe
O4 - HKLM\..\Run: [iukl] C:\WINDOWS\System32\fsmgq.exe
O4 - HKLM\..\Run: [wlhwdp] C:\WINDOWS\System32\rctwlkcf.exe
O4 - HKLM\..\Run: [ljat] C:\WINDOWS\System32\reorhqq.exe
O4 - HKLM\..\Run: [bdzr] C:\WINDOWS\System32\chtkh.exe
O4 - HKLM\..\Run: [yeue] C:\WINDOWS\System32\xitvso.exe
O4 - HKLM\..\Run: [gkprgs] C:\WINDOWS\System32\reeytzt.exe
O4 - HKLM\..\Run: [zxeor] C:\WINDOWS\System32\bhswnk.exe
O4 - HKLM\..\Run: [zuybvka] C:\WINDOWS\System32\wdkzhue.exe
O4 - HKLM\..\Run: [zgbjs] C:\WINDOWS\System32\dmnplb.exe
O4 - HKLM\..\Run: [ebujbxl] C:\WINDOWS\System32\fgsam.exe
O4 - HKLM\..\Run: [sqhxjnwf] C:\WINDOWS\System32\qtpqsqz.exe
O4 - HKLM\..\Run: [grow] C:\WINDOWS\System32\cpitubvt.exe
O4 - HKLM\..\Run: [zaapllqc] C:\WINDOWS\System32\xmdcppxr.exe
O4 - HKLM\..\Run: [sugqy] C:\WINDOWS\System32\osppozy.exe
O4 - HKLM\..\Run: [qaqrxgv] C:\WINDOWS\System32\oqltbu.exe
O4 - HKLM\..\Run: [nrroyj] C:\WINDOWS\System32\qlzl.exe
O4 - HKLM\..\Run: [gtpg] C:\WINDOWS\System32\lfqwa.exe
O4 - HKLM\..\Run: [oimchl] C:\WINDOWS\System32\oivhbjru.exe
O4 - HKLM\..\Run: [awqxd] C:\WINDOWS\System32\saywi.exe
O4 - HKLM\..\Run: [mdptsz] C:\WINDOWS\System32\bygltvcz.exe
O4 - HKLM\..\Run: [kfmit] C:\WINDOWS\System32\ypdgoqio.exe
O4 - HKLM\..\Run: [abvfahbu] C:\WINDOWS\System32\wzuhybb.exe
O4 - HKLM\..\Run: [cxridkkg] C:\WINDOWS\System32\okzivf.exe
O4 - HKLM\..\Run: [peyxtc] C:\WINDOWS\System32\hgqiwxbw.exe
O4 - HKLM\..\Run: [exwdz] C:\WINDOWS\System32\jjvbxpu.exe
O4 - HKLM\..\Run: [qvwlyhn] C:\WINDOWS\System32\zjnbo.exe
O4 - HKLM\..\Run: [btymsm] C:\WINDOWS\System32\gmuemk.exe
O4 - HKLM\..\Run: [gdtve] C:\WINDOWS\System32\wsilhs.exe
O4 - HKLM\..\Run: [dhhsja] C:\WINDOWS\System32\oezkcyu.exe
O4 - HKLM\..\Run: [jmtuik] C:\WINDOWS\System32\kjwdz.exe
O4 - HKLM\..\Run: [capcli] C:\WINDOWS\System32\vdcwactf.exe
O4 - HKLM\..\Run: [mwaqv] C:\WINDOWS\System32\eqcxjoqw.exe
O4 - HKLM\..\Run: [nafv] C:\WINDOWS\System32\admwgfnb.exe
O4 - HKLM\..\Run: [rbjri] C:\WINDOWS\System32\dctkolj.exe
O4 - HKLM\..\Run: [uofjbwt] C:\WINDOWS\System32\fwzcp.exe
O4 - HKLM\..\Run: [rjmzvp] c:\windows\system32\rjmzvp.exe
O4 - HKLM\..\Run: [juoob] C:\WINDOWS\System32\rcexejtt.exe
O4 - HKLM\..\Run: [ufrms] C:\WINDOWS\System32\bxjpfc.exe
O4 - HKLM\..\Run: [cwnb] C:\WINDOWS\System32\pkxz.exe
O4 - HKLM\..\Run: [biynop] C:\WINDOWS\System32\rjwfyxh.exe
O4 - HKLM\..\Run: [gvnb] C:\WINDOWS\System32\kgyyjvq.exe
O4 - HKLM\..\Run: [bzafkzh] C:\WINDOWS\System32\ubpf.exe
O4 - HKLM\..\Run: [pyzt] C:\WINDOWS\System32\tvrfg.exe
O4 - HKLM\..\Run: [xghgws] C:\WINDOWS\System32\bzyzezf.exe
O4 - HKLM\..\Run: [szlw] C:\WINDOWS\System32\nxld.exe
O4 - HKLM\..\Run: [wnau] C:\WINDOWS\System32\knjz.exe
O4 - HKLM\..\Run: [iyqpys] C:\WINDOWS\System32\llkg.exe
O4 - HKLM\..\Run: [xjllnegx] C:\WINDOWS\System32\mcccoor.exe
O4 - HKLM\..\Run: [ojyv] C:\WINDOWS\System32\noxmhj.exe
O4 - HKLM\..\Run: [cccwy] C:\WINDOWS\System32\cdkj.exe
O4 - HKLM\..\Run: [cgbpczf] C:\WINDOWS\System32\udbslo.exe
O4 - HKLM\..\Run: [wilskamx] C:\WINDOWS\System32\bbjwck.exe
O4 - HKLM\..\Run: [bcung] C:\WINDOWS\System32\oythwvar.exe
O4 - HKLM\..\Run: [swyws] C:\WINDOWS\System32\yarvm.exe
O4 - HKLM\..\Run: [StopSignSsTsMon] "Rundll32.exe" "C:\Program Files\Acceleration Software\Anti-Virus\sstsmon.dll",VerifyStatus
O4 - HKLM\..\Run: [ajpylew] C:\WINDOWS\System32\jjuvp.exe
O4 - HKLM\..\Run: [eehku] C:\WINDOWS\System32\bvsvwy.exe
O4 - HKLM\..\Run: [cqkg] C:\WINDOWS\System32\hjree.exe
O4 - HKLM\..\Run: [ylfrzafc] C:\WINDOWS\System32\lkwdw.exe
O4 - HKLM\..\Run: [kuclsrh] C:\WINDOWS\System32\adha.exe
O4 - HKLM\..\Run: [xymr] C:\WINDOWS\System32\hwkoxfl.exe
O4 - HKLM\..\Run: [knprbopo] C:\WINDOWS\System32\jecfw.exe
O4 - HKLM\..\Run: [pfoc] C:\WINDOWS\System32\tzseszm.exe
O4 - HKLM\..\Run: [pebljl] C:\WINDOWS\System32\ifcgzlni.exe
O4 - HKLM\..\Run: [hlrsyqa] C:\WINDOWS\System32\tjlkgyj.exe
O4 - HKLM\..\Run: [ulvtjx] C:\WINDOWS\System32\elrvh.exe
O4 - HKLM\..\Run: [smfcyruv] C:\WINDOWS\System32\sftndqtz.exe
O4 - HKLM\..\Run: [vdtb] C:\WINDOWS\System32\lzuuu.exe
O4 - HKLM\..\Run: [lixstrl] C:\WINDOWS\System32\ytbh.exe
O4 - HKLM\..\Run: [spzjmny] C:\WINDOWS\System32\nlomxp.exe
O4 - HKLM\..\Run: [dxjsfdn] C:\WINDOWS\System32\vdst.exe
O4 - HKLM\..\Run: [hbyxbz] C:\WINDOWS\System32\lzmo.exe
O4 - HKLM\..\Run: [ayyfrht] C:\WINDOWS\System32\tkrl.exe
O4 - HKLM\..\Run: [uhhrkzvm] C:\WINDOWS\System32\ogkodk.exe
O4 - HKLM\..\Run: [dlwhoh] C:\WINDOWS\System32\hqzaxcr.exe
O4 - HKLM\..\Run: [friaba] C:\WINDOWS\System32\cfnstj.exe
O4 - HKLM\..\Run: [jhqmbd] C:\WINDOWS\System32\qbcin.exe
O4 - HKLM\..\Run: [utqiz] C:\WINDOWS\System32\bdhbobui.exe
O4 - HKLM\..\Run: [tncsm] C:\WINDOWS\System32\vwneg.exe
O4 - HKLM\..\Run: [vflrjgsg] C:\WINDOWS\System32\oqfgxs.exe
O4 - HKLM\..\Run: [sdjt] C:\WINDOWS\System32\lgdbzv.exe
O4 - HKLM\..\Run: [iitg] C:\WINDOWS\System32\uklrvc.exe
O4 - HKLM\..\Run: [fgrikz] C:\WINDOWS\System32\rajnqy.exe
O4 - HKLM\..\Run: [eanth_system_patcher] "C:\Program Files\Acceleration Software\SystemPatcher\sys_alert.exe" /Startup
O4 - HKLM\..\Run: [stlaaymn] C:\WINDOWS\System32\zyfjw.exe
O4 - HKLM\..\Run: [ldnz] C:\WINDOWS\System32\bakt.exe
O4 - HKLM\..\Run: [qorpkjxv] C:\WINDOWS\System32\hwwhgj.exe
O4 - HKLM\..\Run: [jxfhrhxk] C:\WINDOWS\System32\xtqwgrjw.exe
O4 - HKLM\..\Run: [vzcd] C:\WINDOWS\System32\aygmwydh.exe
O4 - HKLM\..\Run: [fgeonihv] C:\WINDOWS\System32\glybj.exe
O4 - HKLM\..\Run: [ofxaupfs] C:\WINDOWS\System32\thieldi.exe
O4 - HKLM\..\Run: [ajctdbws] C:\WINDOWS\System32\fyffwrie.exe
O4 - HKLM\..\Run: [aneglun] C:\WINDOWS\System32\kwvu.exe
O4 - HKLM\..\Run: [dtbw] C:\WINDOWS\System32\hvtq.exe
O4 - HKLM\..\Run: [fhsgj] C:\WINDOWS\System32\xxkwspa.exe
O4 - HKLM\..\Run: [dfudgnut] C:\WINDOWS\System32\vvisnsg.exe
O4 - HKLM\..\Run: [vqzwgvil] C:\WINDOWS\System32\xmmyupib.exe
O4 - HKLM\..\Run: [yyhvi] C:\WINDOWS\System32\myba.exe
O4 - HKLM\..\Run: [vzrzzi] C:\WINDOWS\System32\qawlrigr.exe
O4 - HKLM\..\Run: [swyph] C:\WINDOWS\System32\xmdo.exe
O4 - HKLM\..\Run: [wylmsn] C:\WINDOWS\System32\jjeeqqr.exe
O4 - HKLM\..\Run: [bngyo] C:\WINDOWS\System32\wfxh.exe
O4 - HKLM\..\Run: [SoftwareStation] "C:\Program Files\eAcceleration\Station\station.exe" /b Startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [zhqyqu] C:\WINDOWS\System32\hhovkgv.exe r
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DaemonTools_WhenUSave_Installer] C:\Program Files\DaemonTools_WhenUSave_Installer\DaemonTools_WhenUSave_Installer.exe
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:46:02 PM, on 10/8/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\WINDOWS\System32\WgaTray.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\EarthLink 5.0\conmgr.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\BCMSMMSG.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,Search = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://out.true-counter.com/b/?101 (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer,Search = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://out.true-counter.com/a/?101 (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://out.true-counter.com/b/?101 (obfuscated)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://education.dellnet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.searchforit.com/searchbar
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://out.true-counter.com/c/?101 (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://out.true-counter.com/b/?101 (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchforit.com/searchbar
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://out.true-counter.com/a/?101 about:blank (obfuscated)
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O1 - Hosts: 216.93.168.167 sitefinder.verisign.com
O2 - BHO: (no name) - SOFTWARE - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {19B19F2E-09BC-47CF-A709-13B50B4620FC} - C:\Program Files\CSBB\CSBB.dll (file missing)
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {359F6495-6D24-4B75-8D8C-95F2DD94A24E} - C:\Program Files\CSBB\CSBB.dll (file missing)
O2 - BHO: (no name) - {38D4D5D0-423E-4220-B6F9-30918C2AE4A4} - (no file)
O2 - BHO: MSVPS System - {3ADCBC16-19FA-4C59-9C22-E17C71B5FD7A} - C:\WINDOWS\bndsrdkq.dll
O2 - BHO: (no name) - {4E7BD74F-2B8D-469E-C0FF-FA7FB592BF30} - (no file)
O2 - BHO: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: (no name) - {832BEBED-C3DA-4534-A2C2-B2FFF220C820} - (no file)
O2 - BHO: (no name) - {A9150711-B448-4878-9AF7-68C82CAD8000} - C:\Program Files\8w6fbfy3\8w6fbfy3.dll (file missing)
O2 - BHO: (no name) - {AC9CEDCC-7F9F-48E9-B9C1-1FA7962A73C1} - C:\Program Files\8w6fbfy3\8w6fbfy3.dll (file missing)
O2 - BHO: (no name) - {AF1BA546-A930-43E8-863D-9D39B1E6F976} - C:\Program Files\8w6fbfy3\8w6fbfy3.dll (file missing)
O2 - BHO: (no name) - {B5F3970B-745E-46AC-B890-E08F69777D80} - (no file)
O2 - BHO: (no name) - {B753C7C5-0942-4b7f-BC27-942B52BDAC66} - C:\PROGRA~1\ACCELE~1\StopSign\webcbrowse.dll (file missing)
O2 - BHO: (no name) - {C2365BA4-8E86-49F8-9C15-DA6600D3D79E} - C:\Program Files\8w6fbfy3\8w6fbfy3.dll (file missing)
O2 - BHO: (no name) - {C347A0AC-42B4-4E3E-9867-2412512A3D24} - C:\Program Files\8w6fbfy3\8w6fbfy3.dll (file missing)
O2 - BHO: (no name) - {C561ABA5-B6A0-46D9-9ECC-2F6F08D48824} - C:\Program Files\8w6fbfy3\8w6fbfy3.dll (file missing)
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdmcks.dll
O2 - BHO: (no name) - {CDA7FABE-7142-4004-845E-8AA884E529A8} - C:\Program Files\8w6fbfy3\8w6fbfy3.dll (file missing)
O2 - BHO: (no name) - {D36E8104-E529-4A76-9DE9-0BC52F11C8D0} - C:\Program Files\CSBB\CSBB.dll (file missing)
O2 - BHO: (no name) - {D80C4E21-C346-4E21-8E64-20746AA20AEB} - (no file)
O2 - BHO: (no name) - {E8808CC7-CE3E-4FC7-A0B2-65DCB8F91ABF} - C:\Program Files\8w6fbfy3\8w6fbfy3.dll (file missing)
O2 - BHO: (no name) - {ED182F32-4A69-4F63-B894-B69022344DAD} - C:\Program Files\8w6fbfy3\8w6fbfy3.dll (file missing)
O2 - BHO: (no name) - {F5DE8ADB-4A69-4e56-96AB-823171C8E9D8} - (no file)
O2 - BHO: (no name) - {FA67E157-C26C-4019-B3C8-BE9FE91B226A} - C:\Program Files\8w6fbfy3\8w6fbfy3.dll (file missing)
O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll
O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-C0FF-FA7FB592BF30} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (file missing)
O3 - Toolbar: BestOffers Shopping v1.20 - {7FD44536-9DF0-4034-939F-5BD4D98E3187} - C:\Program Files\TBONAS\TBONlchr.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: (no name) - {C109664B-CEB1-420b-B353-D55A561536DD} - (no file)
O3 - Toolbar: (no name) - {1a29a79a-b9c8-44a9-bedf-7fadde3cf33f} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [ConMgr.exe] "C:\Program Files\EarthLink 5.0\conmgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WebScan] "C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe" -k
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] "C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe"
O4 - HKLM\..\Run: [DeadAIM] "rundll32.exe" "C:\Program Files\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [lxbfrd] C:\WINDOWS\System32\vtlgqw.exe
O4 - HKLM\..\Run: [hnvy] C:\WINDOWS\System32\ichop.exe
O4 - HKLM\..\Run: [uykkyrz] C:\WINDOWS\System32\qfqgwyt.exe
O4 - HKLM\..\Run: [kwnh] C:\WINDOWS\System32\oegczuz.exe
O4 - HKLM\..\Run: [dfie] C:\WINDOWS\System32\cvpixdeu.exe
O4 - HKLM\..\Run: [nnlxvoy] C:\WINDOWS\System32\equsyw.exe
O4 - HKLM\..\Run: [cksob] C:\WINDOWS\System32\rlpdhsh.exe
O4 - HKLM\..\Run: [yaormqa] C:\WINDOWS\System32\qesjc.exe
O4 - HKLM\..\Run: [gqiuyx] C:\WINDOWS\System32\khlasjm.exe
O4 - HKLM\..\Run: [wwsyy] C:\WINDOWS\System32\gquncixs.exe
O4 - HKLM\..\Run: [vyhv] C:\WINDOWS\System32\dhsiwdeh.exe
O4 - HKLM\..\Run: [iukl] C:\WINDOWS\System32\fsmgq.exe
O4 - HKLM\..\Run: [wlhwdp] C:\WINDOWS\System32\rctwlkcf.exe
O4 - HKLM\..\Run: [ljat] C:\WINDOWS\System32\reorhqq.exe
O4 - HKLM\..\Run: [bdzr] C:\WINDOWS\System32\chtkh.exe
O4 - HKLM\..\Run: [yeue] C:\WINDOWS\System32\xitvso.exe
O4 - HKLM\..\Run: [gkprgs] C:\WINDOWS\System32\reeytzt.exe
O4 - HKLM\..\Run: [zxeor] C:\WINDOWS\System32\bhswnk.exe
O4 - HKLM\..\Run: [zuybvka] C:\WINDOWS\System32\wdkzhue.exe
O4 - HKLM\..\Run: [zgbjs] C:\WINDOWS\System32\dmnplb.exe
O4 - HKLM\..\Run: [ebujbxl] C:\WINDOWS\System32\fgsam.exe
O4 - HKLM\..\Run: [sqhxjnwf] C:\WINDOWS\System32\qtpqsqz.exe
O4 - HKLM\..\Run: [grow] C:\WINDOWS\System32\cpitubvt.exe
O4 - HKLM\..\Run: [zaapllqc] C:\WINDOWS\System32\xmdcppxr.exe
O4 - HKLM\..\Run: [sugqy] C:\WINDOWS\System32\osppozy.exe
O4 - HKLM\..\Run: [qaqrxgv] C:\WINDOWS\System32\oqltbu.exe
O4 - HKLM\..\Run: [nrroyj] C:\WINDOWS\System32\qlzl.exe
O4 - HKLM\..\Run: [gtpg] C:\WINDOWS\System32\lfqwa.exe
O4 - HKLM\..\Run: [oimchl] C:\WINDOWS\System32\oivhbjru.exe
O4 - HKLM\..\Run: [awqxd] C:\WINDOWS\System32\saywi.exe
O4 - HKLM\..\Run: [mdptsz] C:\WINDOWS\System32\bygltvcz.exe
O4 - HKLM\..\Run: [kfmit] C:\WINDOWS\System32\ypdgoqio.exe
O4 - HKLM\..\Run: [abvfahbu] C:\WINDOWS\System32\wzuhybb.exe
O4 - HKLM\..\Run: [cxridkkg] C:\WINDOWS\System32\okzivf.exe
O4 - HKLM\..\Run: [peyxtc] C:\WINDOWS\System32\hgqiwxbw.exe
O4 - HKLM\..\Run: [exwdz] C:\WINDOWS\System32\jjvbxpu.exe
O4 - HKLM\..\Run: [qvwlyhn] C:\WINDOWS\System32\zjnbo.exe
O4 - HKLM\..\Run: [btymsm] C:\WINDOWS\System32\gmuemk.exe
O4 - HKLM\..\Run: [gdtve] C:\WINDOWS\System32\wsilhs.exe
O4 - HKLM\..\Run: [dhhsja] C:\WINDOWS\System32\oezkcyu.exe
O4 - HKLM\..\Run: [jmtuik] C:\WINDOWS\System32\kjwdz.exe
O4 - HKLM\..\Run: [capcli] C:\WINDOWS\System32\vdcwactf.exe
O4 - HKLM\..\Run: [mwaqv] C:\WINDOWS\System32\eqcxjoqw.exe
O4 - HKLM\..\Run: [nafv] C:\WINDOWS\System32\admwgfnb.exe
O4 - HKLM\..\Run: [rbjri] C:\WINDOWS\System32\dctkolj.exe
O4 - HKLM\..\Run: [uofjbwt] C:\WINDOWS\System32\fwzcp.exe
O4 - HKLM\..\Run: [rjmzvp] c:\windows\system32\rjmzvp.exe
O4 - HKLM\..\Run: [juoob] C:\WINDOWS\System32\rcexejtt.exe
O4 - HKLM\..\Run: [ufrms] C:\WINDOWS\System32\bxjpfc.exe
O4 - HKLM\..\Run: [cwnb] C:\WINDOWS\System32\pkxz.exe
O4 - HKLM\..\Run: [biynop] C:\WINDOWS\System32\rjwfyxh.exe
O4 - HKLM\..\Run: [gvnb] C:\WINDOWS\System32\kgyyjvq.exe
O4 - HKLM\..\Run: [bzafkzh] C:\WINDOWS\System32\ubpf.exe
O4 - HKLM\..\Run: [pyzt] C:\WINDOWS\System32\tvrfg.exe
O4 - HKLM\..\Run: [xghgws] C:\WINDOWS\System32\bzyzezf.exe
O4 - HKLM\..\Run: [szlw] C:\WINDOWS\System32\nxld.exe
O4 - HKLM\..\Run: [wnau] C:\WINDOWS\System32\knjz.exe
O4 - HKLM\..\Run: [iyqpys] C:\WINDOWS\System32\llkg.exe
O4 - HKLM\..\Run: [xjllnegx] C:\WINDOWS\System32\mcccoor.exe
O4 - HKLM\..\Run: [ojyv] C:\WINDOWS\System32\noxmhj.exe
O4 - HKLM\..\Run: [cccwy] C:\WINDOWS\System32\cdkj.exe
O4 - HKLM\..\Run: [cgbpczf] C:\WINDOWS\System32\udbslo.exe
O4 - HKLM\..\Run: [wilskamx] C:\WINDOWS\System32\bbjwck.exe
O4 - HKLM\..\Run: [bcung] C:\WINDOWS\System32\oythwvar.exe
O4 - HKLM\..\Run: [swyws] C:\WINDOWS\System32\yarvm.exe
O4 - HKLM\..\Run: [StopSignSsTsMon] "Rundll32.exe" "C:\Program Files\Acceleration Software\Anti-Virus\sstsmon.dll",VerifyStatus
O4 - HKLM\..\Run: [ajpylew] C:\WINDOWS\System32\jjuvp.exe
O4 - HKLM\..\Run: [eehku] C:\WINDOWS\System32\bvsvwy.exe
O4 - HKLM\..\Run: [cqkg] C:\WINDOWS\System32\hjree.exe
O4 - HKLM\..\Run: [ylfrzafc] C:\WINDOWS\System32\lkwdw.exe
O4 - HKLM\..\Run: [kuclsrh] C:\WINDOWS\System32\adha.exe
O4 - HKLM\..\Run: [xymr] C:\WINDOWS\System32\hwkoxfl.exe
O4 - HKLM\..\Run: [knprbopo] C:\WINDOWS\System32\jecfw.exe
O4 - HKLM\..\Run: [pfoc] C:\WINDOWS\System32\tzseszm.exe
O4 - HKLM\..\Run: [pebljl] C:\WINDOWS\System32\ifcgzlni.exe
O4 - HKLM\..\Run: [hlrsyqa] C:\WINDOWS\System32\tjlkgyj.exe
O4 - HKLM\..\Run: [ulvtjx] C:\WINDOWS\System32\elrvh.exe
O4 - HKLM\..\Run: [smfcyruv] C:\WINDOWS\System32\sftndqtz.exe
O4 - HKLM\..\Run: [vdtb] C:\WINDOWS\System32\lzuuu.exe
O4 - HKLM\..\Run: [lixstrl] C:\WINDOWS\System32\ytbh.exe
O4 - HKLM\..\Run: [spzjmny] C:\WINDOWS\System32\nlomxp.exe
O4 - HKLM\..\Run: [dxjsfdn] C:\WINDOWS\System32\vdst.exe
O4 - HKLM\..\Run: [hbyxbz] C:\WINDOWS\System32\lzmo.exe
O4 - HKLM\..\Run: [ayyfrht] C:\WINDOWS\System32\tkrl.exe
O4 - HKLM\..\Run: [uhhrkzvm] C:\WINDOWS\System32\ogkodk.exe
O4 - HKLM\..\Run: [dlwhoh] C:\WINDOWS\System32\hqzaxcr.exe
O4 - HKLM\..\Run: [friaba] C:\WINDOWS\System32\cfnstj.exe
O4 - HKLM\..\Run: [jhqmbd] C:\WINDOWS\System32\qbcin.exe
O4 - HKLM\..\Run: [utqiz] C:\WINDOWS\System32\bdhbobui.exe
O4 - HKLM\..\Run: [tncsm] C:\WINDOWS\System32\vwneg.exe
O4 - HKLM\..\Run: [vflrjgsg] C:\WINDOWS\System32\oqfgxs.exe
O4 - HKLM\..\Run: [sdjt] C:\WINDOWS\System32\lgdbzv.exe
O4 - HKLM\..\Run: [iitg] C:\WINDOWS\System32\uklrvc.exe
O4 - HKLM\..\Run: [fgrikz] C:\WINDOWS\System32\rajnqy.exe
O4 - HKLM\..\Run: [eanth_system_patcher] "C:\Program Files\Acceleration Software\SystemPatcher\sys_alert.exe" /Startup
O4 - HKLM\..\Run: [stlaaymn] C:\WINDOWS\System32\zyfjw.exe
O4 - HKLM\..\Run: [ldnz] C:\WINDOWS\System32\bakt.exe
O4 - HKLM\..\Run: [qorpkjxv] C:\WINDOWS\System32\hwwhgj.exe
O4 - HKLM\..\Run: [jxfhrhxk] C:\WINDOWS\System32\xtqwgrjw.exe
O4 - HKLM\..\Run: [vzcd] C:\WINDOWS\System32\aygmwydh.exe
O4 - HKLM\..\Run: [fgeonihv] C:\WINDOWS\System32\glybj.exe
O4 - HKLM\..\Run: [ofxaupfs] C:\WINDOWS\System32\thieldi.exe
O4 - HKLM\..\Run: [ajctdbws] C:\WINDOWS\System32\fyffwrie.exe
O4 - HKLM\..\Run: [aneglun] C:\WINDOWS\System32\kwvu.exe
O4 - HKLM\..\Run: [dtbw] C:\WINDOWS\System32\hvtq.exe
O4 - HKLM\..\Run: [fhsgj] C:\WINDOWS\System32\xxkwspa.exe
O4 - HKLM\..\Run: [dfudgnut] C:\WINDOWS\System32\vvisnsg.exe
O4 - HKLM\..\Run: [vqzwgvil] C:\WINDOWS\System32\xmmyupib.exe
O4 - HKLM\..\Run: [yyhvi] C:\WINDOWS\System32\myba.exe
O4 - HKLM\..\Run: [vzrzzi] C:\WINDOWS\System32\qawlrigr.exe
O4 - HKLM\..\Run: [swyph] C:\WINDOWS\System32\xmdo.exe
O4 - HKLM\..\Run: [wylmsn] C:\WINDOWS\System32\jjeeqqr.exe
O4 - HKLM\..\Run: [bngyo] C:\WINDOWS\System32\wfxh.exe
O4 - HKLM\..\Run: [SoftwareStation] "C:\Program Files\eAcceleration\Station\station.exe" /b Startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [zhqyqu] C:\WINDOWS\System32\hhovkgv.exe r
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DaemonTools_WhenUSave_Installer] C:\Program Files\DaemonTools_WhenUSave_Installer\DaemonTools_WhenUSave_Installer.exe