Hey Piatan.
Well its not going so well on my end.
Heres the status. Ran the microworldsystems program and I was stunned at the number of infections (25000+). Decided to run the microsoft Beta to remove what it could and then I installed and ran the ewido program. It shut down due to some error twice after about 70% scan completed. I than reran the microworld program again but the report was again brutal. I tried to post it but the machine locked up. Disconnected and did some investigating and found that the log from the microworld scan is 14.2 megs . I guess when I tried to cut and paste it while online it just froze in fear. remember i'm on dial up. I'm not sure I can upload it in a zipped form or not but know it would have been a record length post !!
I will post the current hijack and hope it helps.
I also looked at the services.msc again and the RPC Helper has shifted itself back to automatic from the setting of disable. I guess it shouldn't suprize me that it can turn it self back on. I did disable it again for what thats worth.
OK here's the Hijack log and I may try a second post with the other log next.
Frustrated. Av8tor
Logfile of HijackThis v1.99.1
Scan saved at 1:45:23 PM, on 6/3/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\WINDOWS\iptp.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe
C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\sdkev32.exe
C:\Documents and Settings\default\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\mjmnk.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\cebfi.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\mjmnk.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\mjmnk.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\mjmnk.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\cebfi.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\cebfi.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: Class - {2D83144A-96F5-FD55-350C-BB36CBABB8B2} - C:\WINDOWS\system32\msyf.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Class - {FD53AF3D-B5A4-3DEC-C009-E2E6791F3EE9} - C:\WINDOWS\system32\ieya32.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.1424.0\en-us\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [iptp.exe] C:\WINDOWS\iptp.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\RunOnce: [crmn.exe] C:\WINDOWS\crmn.exe
O4 - HKLM\..\RunOnce: [sdkol.exe] C:\WINDOWS\sdkol.exe
O4 - HKLM\..\RunOnce: [ieur32.exe] C:\WINDOWS\system32\ieur32.exe
O4 - HKLM\..\RunOnce: [apiwj.exe] C:\WINDOWS\system32\apiwj.exe
O4 - HKLM\..\RunOnce: [mscz.exe] C:\WINDOWS\mscz.exe
O4 - HKLM\..\RunOnce: [ieya.exe] C:\WINDOWS\system32\ieya.exe
O4 - HKLM\..\RunOnce: [netie32.exe] C:\WINDOWS\system32\netie32.exe
O4 - HKLM\..\RunOnce: [ipcn32.exe] C:\WINDOWS\ipcn32.exe
O4 - HKLM\..\RunOnce: [netcn32.exe] C:\WINDOWS\netcn32.exe
O4 - HKLM\..\RunOnce: [sysqq32.exe] C:\WINDOWS\sysqq32.exe
O4 - HKLM\..\RunOnce: [ntbd32.exe] C:\WINDOWS\system32\ntbd32.exe
O4 - HKLM\..\RunOnce: [apigf.exe] C:\WINDOWS\system32\apigf.exe
O4 - HKLM\..\RunOnce: [ipii32.exe] C:\WINDOWS\system32\ipii32.exe
O4 - HKLM\..\RunOnce: [atldi.exe] C:\WINDOWS\system32\atldi.exe
O4 - HKLM\..\RunOnce: [apiml.exe] C:\WINDOWS\apiml.exe
O4 - HKLM\..\RunOnce: [javanm.exe] C:\WINDOWS\system32\javanm.exe
O4 - HKLM\..\RunOnce: [appqv32.exe] C:\WINDOWS\system32\appqv32.exe
O4 - HKLM\..\RunOnce: [d3bo32.exe] C:\WINDOWS\system32\d3bo32.exe
O4 - HKLM\..\RunOnce: [netvh32.exe] C:\WINDOWS\netvh32.exe
O4 - HKLM\..\RunOnce: [msjw.exe] C:\WINDOWS\msjw.exe
O4 - HKLM\..\RunOnce: [iept32.exe] C:\WINDOWS\iept32.exe
O4 - HKLM\..\RunOnce: [d3kx.exe] C:\WINDOWS\system32\d3kx.exe
O4 - HKLM\..\RunOnce: [cryt.exe] C:\WINDOWS\cryt.exe
O4 - HKLM\..\RunOnce: [sdkcd.exe] C:\WINDOWS\system32\sdkcd.exe
O4 - HKLM\..\RunOnce: [ipra32.exe] C:\WINDOWS\system32\ipra32.exe
O4 - HKLM\..\RunOnce: [iepl.exe] C:\WINDOWS\iepl.exe
O4 - HKLM\..\RunOnce: [addot.exe] C:\WINDOWS\system32\addot.exe
O4 - HKLM\..\RunOnce: [netdq32.exe] C:\WINDOWS\netdq32.exe
O4 - HKLM\..\RunOnce: [wincq.exe] C:\WINDOWS\wincq.exe
O4 - HKLM\..\RunOnce: [javaby.exe] C:\WINDOWS\javaby.exe
O4 - HKLM\..\RunOnce: [addim32.exe] C:\WINDOWS\addim32.exe
O4 - HKLM\..\RunOnce: [iexc32.exe] C:\WINDOWS\iexc32.exe
O4 - HKLM\..\RunOnce: [winwj32.exe] C:\WINDOWS\system32\winwj32.exe
O4 - HKLM\..\RunOnce: [crhc.exe] C:\WINDOWS\crhc.exe
O4 - HKLM\..\RunOnce: [d3ku.exe] C:\WINDOWS\system32\d3ku.exe
O4 - HKLM\..\RunOnce: [atlex.exe] C:\WINDOWS\atlex.exe
O4 - HKLM\..\RunOnce: [apidv32.exe] C:\WINDOWS\apidv32.exe
O4 - HKLM\..\RunOnce: [addck32.exe] C:\WINDOWS\system32\addck32.exe
O4 - HKLM\..\RunOnce: [crve32.exe] C:\WINDOWS\crve32.exe
O4 - HKLM\..\RunOnce: [appbs.exe] C:\WINDOWS\appbs.exe
O4 - HKLM\..\RunOnce: [mfcbg32.exe] C:\WINDOWS\system32\mfcbg32.exe
O4 - HKLM\..\RunOnce: [winkt.exe] C:\WINDOWS\system32\winkt.exe
O4 - HKLM\..\RunOnce: [javayv.exe] C:\WINDOWS\javayv.exe
O4 - HKLM\..\RunOnce: [nttz32.exe] C:\WINDOWS\system32\nttz32.exe
O4 - HKLM\..\RunOnce: [atlko.exe] C:\WINDOWS\atlko.exe
O4 - HKLM\..\RunOnce: [msjw32.exe] C:\WINDOWS\msjw32.exe
O4 - HKLM\..\RunOnce: [ieje32.exe] C:\WINDOWS\ieje32.exe
O4 - HKLM\..\RunOnce: [sdkna32.exe] C:\WINDOWS\sdkna32.exe
O4 - HKLM\..\RunOnce: [javaht32.exe] C:\WINDOWS\system32\javaht32.exe
O4 - HKLM\..\RunOnce: [crhb.exe] C:\WINDOWS\system32\crhb.exe
O4 - HKLM\..\RunOnce: [sdkpc.exe] C:\WINDOWS\system32\sdkpc.exe
O4 - HKLM\..\RunOnce: [sysfz32.exe] C:\WINDOWS\system32\sysfz32.exe
O4 - HKLM\..\RunOnce: [mfcpp32.exe] C:\WINDOWS\system32\mfcpp32.exe
O4 - HKLM\..\RunOnce: [ipon32.exe] C:\WINDOWS\ipon32.exe
O4 - HKLM\..\RunOnce: [atlmd32.exe] C:\WINDOWS\system32\atlmd32.exe
O4 - HKLM\..\RunOnce: [syslq32.exe] C:\WINDOWS\syslq32.exe
O4 - HKLM\..\RunOnce: [mfcml.exe] C:\WINDOWS\system32\mfcml.exe
O4 - HKLM\..\RunOnce: [atlvl.exe] C:\WINDOWS\atlvl.exe
O4 - HKLM\..\RunOnce: [systy.exe] C:\WINDOWS\system32\systy.exe
O4 - HKLM\..\RunOnce: [mfcjn32.exe] C:\WINDOWS\mfcjn32.exe
O4 - HKLM\..\RunOnce: [ntzd32.exe] C:\WINDOWS\ntzd32.exe
O4 - HKLM\..\RunOnce: [apijd.exe] C:\WINDOWS\apijd.exe
O4 - HKLM\..\RunOnce: [crys32.exe] C:\WINDOWS\system32\crys32.exe
O4 - HKLM\..\RunOnce: [apifg32.exe] C:\WINDOWS\system32\apifg32.exe
O4 - HKLM\..\RunOnce: [netfw32.exe] C:\WINDOWS\netfw32.exe
O4 - HKLM\..\RunOnce: [ntzh.exe] C:\WINDOWS\system32\ntzh.exe
O4 - HKLM\..\RunOnce: [msow32.exe] C:\WINDOWS\msow32.exe
O4 - HKLM\..\RunOnce: [addee.exe] C:\WINDOWS\addee.exe
O4 - HKLM\..\RunOnce: [apiii32.exe] C:\WINDOWS\system32\apiii32.exe
O4 - HKLM\..\RunOnce: [sdknk32.exe] C:\WINDOWS\system32\sdknk32.exe
O4 - HKLM\..\RunOnce: [addhv32.exe] C:\WINDOWS\addhv32.exe
O4 - HKLM\..\RunOnce: [appsq.exe] C:\WINDOWS\appsq.exe
O4 - HKLM\..\RunOnce: [sysws32.exe] C:\WINDOWS\sysws32.exe
O4 - HKLM\..\RunOnce: [mfcgt32.exe] C:\WINDOWS\mfcgt32.exe
O4 - HKLM\..\RunOnce: [netfy.exe] C:\WINDOWS\system32\netfy.exe
O4 - HKLM\..\RunOnce: [iplx.exe] C:\WINDOWS\iplx.exe
O4 - HKLM\..\RunOnce: [sysld32.exe] C:\WINDOWS\system32\sysld32.exe
O4 - HKLM\..\RunOnce: [netlx32.exe] C:\WINDOWS\system32\netlx32.exe
O4 - HKLM\..\RunOnce: [apiau.exe] C:\WINDOWS\apiau.exe
O4 - HKLM\..\RunOnce: [netnr.exe] C:\WINDOWS\netnr.exe
O4 - HKLM\..\RunOnce: [systn.exe] C:\WINDOWS\system32\systn.exe
O4 - HKLM\..\RunOnce: [mfcdm32.exe] C:\WINDOWS\mfcdm32.exe
O4 - HKLM\..\RunOnce: [d3xx32.exe] C:\WINDOWS\system32\d3xx32.exe
O4 - HKLM\..\RunOnce: [appaj.exe] C:\WINDOWS\appaj.exe
O4 - HKLM\..\RunOnce: [netli32.exe] C:\WINDOWS\netli32.exe
O4 - HKLM\..\RunOnce: [syswn.exe] C:\WINDOWS\system32\syswn.exe
O4 - HKLM\..\RunOnce: [netry32.exe] C:\WINDOWS\netry32.exe
O4 - HKLM\..\RunOnce: [javapg32.exe] C:\WINDOWS\javapg32.exe
O4 - HKLM\..\RunOnce: [winfb32.exe] C:\WINDOWS\system32\winfb32.exe
O4 - HKLM\..\RunOnce: [iptq.exe] C:\WINDOWS\system32\iptq.exe
O4 - HKLM\..\RunOnce: [apiuq.exe] C:\WINDOWS\apiuq.exe
O4 - HKLM\..\RunOnce: [sdkmr32.exe] C:\WINDOWS\sdkmr32.exe
O4 - HKLM\..\RunOnce: [sysib32.exe] C:\WINDOWS\system32\sysib32.exe
O4 - HKLM\..\RunOnce: [ieqd.exe] C:\WINDOWS\ieqd.exe
O4 - HKLM\..\RunOnce: [sdkqr.exe] C:\WINDOWS\sdkqr.exe
O4 - HKLM\..\RunOnce: [netfg.exe] C:\WINDOWS\netfg.exe
O4 - HKLM\..\RunOnce: [winkc.exe] C:\WINDOWS\system32\winkc.exe
O4 - HKLM\..\RunOnce: [ipnw32.exe] C:\WINDOWS\ipnw32.exe
O4 - HKLM\..\RunOnce: [atlyv32.exe] C:\WINDOWS\atlyv32.exe
O4 - HKLM\..\RunOnce: [atldl32.exe] C:\WINDOWS\system32\atldl32.exe
O4 - HKLM\..\RunOnce: [mfclt.exe] C:\WINDOWS\system32\mfclt.exe
O4 - HKLM\..\RunOnce: [sysqv32.exe] C:\WINDOWS\system32\sysqv32.exe
O4 - HKLM\..\RunOnce: [msrw32.exe] C:\WINDOWS\msrw32.exe
O4 - HKLM\..\RunOnce: [crgl32.exe] C:\WINDOWS\crgl32.exe
O4 - HKLM\..\RunOnce: [winea32.exe] C:\WINDOWS\system32\winea32.exe
O4 - HKLM\..\RunOnce: [sdkei.exe] C:\WINDOWS\sdkei.exe
O4 - HKLM\..\RunOnce: [appsc.exe] C:\WINDOWS\system32\appsc.exe
O4 - HKLM\..\RunOnce: [apiim32.exe] C:\WINDOWS\system32\apiim32.exe
O4 - HKLM\..\RunOnce: [addyb.exe] C:\WINDOWS\addyb.exe
O4 - HKLM\..\RunOnce: [nthi32.exe] C:\WINDOWS\nthi32.exe
O4 - HKLM\..\RunOnce: [ntvh32.exe] C:\WINDOWS\system32\ntvh32.exe
O4 - HKLM\..\RunOnce: [sdkhq32.exe] C:\WINDOWS\sdkhq32.exe
O4 - HKLM\..\RunOnce: [ipwp.exe] C:\WINDOWS\ipwp.exe
O4 - HKLM\..\RunOnce: [atluc.exe] C:\WINDOWS\system32\atluc.exe
O4 - HKLM\..\RunOnce: [ienv32.exe] C:\WINDOWS\ienv32.exe
O4 - HKLM\..\RunOnce: [javadk.exe] C:\WINDOWS\system32\javadk.exe
O4 - HKLM\..\RunOnce: [sdkmj.exe] C:\WINDOWS\system32\sdkmj.exe
O4 - HKLM\..\RunOnce: [netqv.exe] C:\WINDOWS\system32\netqv.exe
O4 - HKLM\..\RunOnce: [addaq32.exe] C:\WINDOWS\system32\addaq32.exe
O4 - HKLM\..\RunOnce: [crfk32.exe] C:\WINDOWS\crfk32.exe
O4 - HKLM\..\RunOnce: [syswr.exe] C:\WINDOWS\syswr.exe
O4 - HKLM\..\RunOnce: [appay.exe] C:\WINDOWS\system32\appay.exe
O4 - HKLM\..\RunOnce: [addjw.exe] C:\WINDOWS\addjw.exe
O4 - HKLM\..\RunOnce: [addps32.exe] C:\WINDOWS\addps32.exe
O4 - HKLM\..\RunOnce: [netyn32.exe] C:\WINDOWS\system32\netyn32.exe
O4 - HKLM\..\RunOnce: [netni32.exe] C:\WINDOWS\netni32.exe
O4 - HKLM\..\RunOnce: [ieno32.exe] C:\WINDOWS\system32\ieno32.exe
O4 - HKLM\..\RunOnce: [javafr32.exe] C:\WINDOWS\javafr32.exe
O4 - HKLM\..\RunOnce: [apifk32.exe] C:\WINDOWS\apifk32.exe
O4 - HKLM\..\RunOnce: [javaoh.exe] C:\WINDOWS\javaoh.exe
O4 - HKLM\..\RunOnce: [nettp32.exe] C:\WINDOWS\nettp32.exe
O4 - HKLM\..\RunOnce: [ipyf32.exe] C:\WINDOWS\ipyf32.exe
O4 - HKLM\..\RunOnce: [nethm.exe] C:\WINDOWS\system32\nethm.exe
O4 - HKLM\..\RunOnce: [sysyn.exe] C:\WINDOWS\system32\sysyn.exe
O4 - HKLM\..\RunOnce: [winbf.exe] C:\WINDOWS\winbf.exe
O4 - HKLM\..\RunOnce: [apprp32.exe] C:\WINDOWS\system32\apprp32.exe
O4 - HKLM\..\RunOnce: [atlnh32.exe] C:\WINDOWS\system32\atlnh32.exe
O4 - HKLM\..\RunOnce: [atlaa.exe] C:\WINDOWS\system32\atlaa.exe
O4 - HKLM\..\RunOnce: [addax.exe] C:\WINDOWS\addax.exe
O4 - HKLM\..\RunOnce: [apitu32.exe] C:\WINDOWS\apitu32.exe
O4 - HKLM\..\RunOnce: [ieej32.exe] C:\WINDOWS\system32\ieej32.exe
O4 - HKLM\..\RunOnce: [javauy.exe] C:\WINDOWS\javauy.exe
O4 - HKLM\..\RunOnce: [javaxo.exe] C:\WINDOWS\javaxo.exe
O4 - HKLM\..\RunOnce: [crdc32.exe] C:\WINDOWS\crdc32.exe
O4 - HKLM\..\RunOnce: [appmi.exe] C:\WINDOWS\appmi.exe
O4 - HKLM\..\RunOnce: [winrw32.exe] C:\WINDOWS\system32\winrw32.exe
O4 - HKLM\..\RunOnce: [sysvr32.exe] C:\WINDOWS\sysvr32.exe
O4 - HKLM\..\RunOnce: [addrm.exe] C:\WINDOWS\system32\addrm.exe
O4 - HKLM\..\RunOnce: [winam.exe] C:\WINDOWS\winam.exe
O4 - HKLM\..\RunOnce: [msfr.exe] C:\WINDOWS\system32\msfr.exe
O4 - HKLM\..\RunOnce: [apipb32.exe] C:\WINDOWS\system32\apipb32.exe
O4 - HKLM\..\RunOnce: [atlll.exe] C:\WINDOWS\system32\atlll.exe
O4 - HKLM\..\RunOnce: [sysdd32.exe] C:\WINDOWS\sysdd32.exe
O4 - HKLM\..\RunOnce: [ietu32.exe] C:\WINDOWS\system32\ietu32.exe
O4 - HKLM\..\RunOnce: [mfcst.exe] C:\WINDOWS\system32\mfcst.exe
O4 - HKLM\..\RunOnce: [ntdt32.exe] C:\WINDOWS\system32\ntdt32.exe
O4 - HKLM\..\RunOnce: [sysvv.exe] C:\WINDOWS\system32\sysvv.exe
O4 - HKLM\..\RunOnce: [sdkop.exe] C:\WINDOWS\sdkop.exe
O4 - HKLM\..\RunOnce: [mshf.exe] C:\WINDOWS\system32\mshf.exe
O4 - HKLM\..\RunOnce: [ipaw32.exe] C:\WINDOWS\system32\ipaw32.exe
O4 - HKLM\..\RunOnce: [mfctb.exe] C:\WINDOWS\mfctb.exe
O4 - HKLM\..\RunOnce: [netpt32.exe] C:\WINDOWS\netpt32.exe
O4 - HKLM\..\RunOnce: [ippb32.exe] C:\WINDOWS\ippb32.exe
O4 - HKLM\..\RunOnce: [javalh.exe] C:\WINDOWS\system32\javalh.exe
O4 - HKLM\..\RunOnce: [javafb32.exe] C:\WINDOWS\javafb32.exe
O4 - HKLM\..\RunOnce: [apikx32.exe] C:\WINDOWS\system32\apikx32.exe
O4 - HKLM\..\RunOnce: [sdkco32.exe] C:\WINDOWS\sdkco32.exe
O4 - HKLM\..\RunOnce: [ntrd.exe] C:\WINDOWS\system32\ntrd.exe
O4 - HKLM\..\RunOnce: [sdkxz.exe] C:\WINDOWS\system32\sdkxz.exe
O4 - HKLM\..\RunOnce: [sdkph.exe] C:\WINDOWS\sdkph.exe
O4 - HKLM\..\RunOnce: [javafn32.exe] C:\WINDOWS\system32\javafn32.exe
O4 - HKLM\..\RunOnce: [msks.exe] C:\WINDOWS\msks.exe
O4 - HKLM\..\RunOnce: [crss32.exe] C:\WINDOWS\system32\crss32.exe
O4 - HKLM\..\RunOnce: [atlqq.exe] C:\WINDOWS\system32\atlqq.exe
O4 - HKLM\..\RunOnce: [crzp32.exe] C:\WINDOWS\crzp32.exe
O4 - HKLM\..\RunOnce: [mfckc32.exe] C:\WINDOWS\system32\mfckc32.exe
O4 - HKLM\..\RunOnce: [mfcks32.exe] C:\WINDOWS\mfcks32.exe
O4 - HKLM\..\RunOnce: [ielb.exe] C:\WINDOWS\system32\ielb.exe
O4 - HKLM\..\RunOnce: [msmb32.exe] C:\WINDOWS\msmb32.exe
O4 - HKLM\..\RunOnce: [ippw32.exe] C:\WINDOWS\ippw32.exe
O4 - HKLM\..\RunOnce: [mfcdh.exe] C:\WINDOWS\mfcdh.exe
O4 - HKLM\..\RunOnce: [ipsf32.exe] C:\WINDOWS\system32\ipsf32.exe
O4 - HKLM\..\RunOnce: [javatx32.exe] C:\WINDOWS\system32\javatx32.exe
O4 - HKLM\..\RunOnce: [msvz.exe] C:\WINDOWS\system32\msvz.exe
O4 - HKLM\..\RunOnce: [msbo32.exe] C:\WINDOWS\msbo32.exe
O4 - HKLM\..\RunOnce: [msql32.exe] C:\WINDOWS\system32\msql32.exe
O4 - HKLM\..\RunOnce: [sysrc32.exe] C:\WINDOWS\system32\sysrc32.exe
O4 - HKLM\..\RunOnce: [mspb32.exe] C:\WINDOWS\system32\mspb32.exe
O4 - HKLM\..\RunOnce: [addxp32.exe] C:\WINDOWS\system32\addxp32.exe
O4 - HKLM\..\RunOnce: [mspn.exe] C:\WINDOWS\system32\mspn.exe
O4 - HKLM\..\RunOnce: [netbj.exe] C:\WINDOWS\netbj.exe
O4 - HKLM\..\RunOnce: [msjz32.exe] C:\WINDOWS\system32\msjz32.exe
O4 - HKLM\..\RunOnce: [winaq32.exe] C:\WINDOWS\winaq32.exe
O4 - HKLM\..\RunOnce: [ntrc32.exe] C:\WINDOWS\ntrc32.exe
O4 - HKLM\..\RunOnce: [appkw32.exe] C:\WINDOWS\appkw32.exe
O4 - HKLM\..\RunOnce: [javacy32.exe] C:\WINDOWS\javacy32.exe
O4 - HKLM\..\RunOnce: [atlke32.exe] C:\WINDOWS\atlke32.exe
O4 - HKLM\..\RunOnce: [sysgk.exe] C:\WINDOWS\sysgk.exe
O4 - HKLM\..\RunOnce: [sdkff.exe] C:\WINDOWS\sdkff.exe
O4 - HKLM\..\RunOnce: [addaj.exe] C:\WINDOWS\addaj.exe
O4 - HKLM\..\RunOnce: [iepy.exe] C:\WINDOWS\system32\iepy.exe
O4 - HKLM\..\RunOnce: [javazr32.exe] C:\WINDOWS\system32\javazr32.exe
O4 - HKLM\..\RunOnce: [javabc.exe] C:\WINDOWS\javabc.exe
O4 - HKLM\..\RunOnce: [crtk.exe] C:\WINDOWS\crtk.exe
O4 - HKLM\..\RunOnce: [ntqz.exe] C:\WINDOWS\ntqz.exe
O4 - HKLM\..\RunOnce: [atlhh32.exe] C:\WINDOWS\atlhh32.exe
O4 - HKLM\..\RunOnce: [javaqf.exe] C:\WINDOWS\system32\javaqf.exe
O4 - HKLM\..\RunOnce: [ipfu.exe] C:\WINDOWS\system32\ipfu.exe
O4 - HKLM\..\RunOnce: [crbs32.exe] C:\WINDOWS\system32\crbs32.exe
O4 - HKLM\..\RunOnce: [mfcjy32.exe] C:\WINDOWS\system32\mfcjy32.exe
O4 - HKLM\..\RunOnce: [wingc32.exe] C:\WINDOWS\system32\wingc32.exe
O4 - HKLM\..\RunOnce: [d3wr32.exe] C:\WINDOWS\d3wr32.exe
O4 - HKLM\..\RunOnce: [apiro.exe] C:\WINDOWS\apiro.exe
O4 - HKLM\..\RunOnce: [d3eh.exe] C:\WINDOWS\d3eh.exe
O4 - HKLM\..\RunOnce: [msli.exe] C:\WINDOWS\system32\msli.exe
O4 - HKLM\..\RunOnce: [crfi.exe] C:\WINDOWS\crfi.exe
O4 - HKLM\..\RunOnce: [apppr.exe] C:\WINDOWS\system32\apppr.exe
O4 - HKLM\..\RunOnce: [d3dw32.exe] C:\WINDOWS\d3dw32.exe
O4 - HKLM\..\RunOnce: [msmy32.exe] C:\WINDOWS\msmy32.exe
O4 - HKLM\..\RunOnce: [ipte32.exe] C:\WINDOWS\system32\ipte32.exe
O4 - HKLM\..\RunOnce: [sdkln.exe] C:\WINDOWS\system32\sdkln.exe
O4 - HKLM\..\RunOnce: [ipgx.exe] C:\WINDOWS\ipgx.exe
O4 - HKLM\..\RunOnce: [iewp.exe] C:\WINDOWS\system32\iewp.exe
O4 - HKLM\..\RunOnce: [javasb32.exe] C:\WINDOWS\javasb32.exe
O4 - HKLM\..\RunOnce: [netqr.exe] C:\WINDOWS\system32\netqr.exe
O4 - HKLM\..\RunOnce: [ntdi.exe] C:\WINDOWS\ntdi.exe
O4 - HKLM\..\RunOnce: [addpg32.exe] C:\WINDOWS\system32\addpg32.exe
O4 - HKLM\..\RunOnce: [msfo32.exe] C:\WINDOWS\msfo32.exe
O4 - HKLM\..\RunOnce: [iene.exe] C:\WINDOWS\iene.exe
O4 - HKLM\..\RunOnce: [d3vy32.exe] C:\WINDOWS\d3vy32.exe
O4 - HKLM\..\RunOnce: [mfcpc32.exe] C:\WINDOWS\mfcpc32.exe
O4 - HKLM\..\RunOnce: [mfcxk32.exe] C:\WINDOWS\mfcxk32.exe
O4 - HKLM\..\RunOnce: [winwa.exe] C:\WINDOWS\system32\winwa.exe
O4 - HKLM\..\RunOnce: [netsr.exe] C:\WINDOWS\system32\netsr.exe
O4 - HKLM\..\RunOnce: [crez32.exe] C:\WINDOWS\crez32.exe
O4 - HKLM\..\RunOnce: [sdkoi.exe] C:\WINDOWS\system32\sdkoi.exe
O4 - HKLM\..\RunOnce: [apikm.exe] C:\WINDOWS\system32\apikm.exe
O4 - HKLM\..\RunOnce: [ipyw32.exe] C:\WINDOWS\system32\ipyw32.exe
O4 - HKLM\..\RunOnce: [javawd.exe] C:\WINDOWS\system32\javawd.exe
O4 - HKLM\..\RunOnce: [syssz32.exe] C:\WINDOWS\system32\syssz32.exe
O4 - HKLM\..\RunOnce: [d3ci.exe] C:\WINDOWS\system32\d3ci.exe
O4 - HKLM\..\RunOnce: [apprv.exe] C:\WINDOWS\system32\apprv.exe
O4 - HKLM\..\RunOnce: [d3uu.exe] C:\WINDOWS\system32\d3uu.exe
O4 - HKLM\..\RunOnce: [winss32.exe] C:\WINDOWS\system32\winss32.exe
O4 - HKLM\..\RunOnce: [d3ct32.exe] C:\WINDOWS\system32\d3ct32.exe
O4 - HKLM\..\RunOnce: [ntbi.exe] C:\WINDOWS\ntbi.exe
O4 - HKLM\..\RunOnce: [atlay32.exe] C:\WINDOWS\atlay32.exe
O4 - HKLM\..\RunOnce: [javadp32.exe] C:\WINDOWS\system32\javadp32.exe
O4 - HKLM\..\RunOnce: [ipbv.exe] C:\WINDOWS\ipbv.exe
O4 - HKLM\..\RunOnce: [apikv.exe] C:\WINDOWS\system32\apikv.exe
O4 - HKLM\..\RunOnce: [sysps32.exe] C:\WINDOWS\sysps32.exe
O4 - HKLM\..\RunOnce: [d3kv.exe] C:\WINDOWS\system32\d3kv.exe
O4 - HKLM\..\RunOnce: [ipjl32.exe] C:\WINDOWS\system32\ipjl32.exe
O4 - HKLM\..\RunOnce: [ienl32.exe] C:\WINDOWS\ienl32.exe
O4 - HKLM\..\RunOnce: [crli.exe] C:\WINDOWS\system32\crli.exe
O4 - HKLM\..\RunOnce: [javauj.exe] C:\WINDOWS\system32\javauj.exe
O4 - HKLM\..\RunOnce: [iprw32.exe] C:\WINDOWS\iprw32.exe
O4 - HKLM\..\RunOnce: [ipbc.exe] C:\WINDOWS\system32\ipbc.exe
O4 - HKLM\..\RunOnce: [ntoz32.exe] C:\WINDOWS\system32\ntoz32.exe
O4 - HKLM\..\RunOnce: [ipvw32.exe] C:\WINDOWS\ipvw32.exe
O4 - HKLM\..\RunOnce: [netvs.exe] C:\WINDOWS\system32\netvs.exe
O4 - HKLM\..\RunOnce: [sysap.exe] C:\WINDOWS\system32\sysap.exe
O4 - HKLM\..\RunOnce: [d3eb.exe] C:\WINDOWS\d3eb.exe
O4 - HKLM\..\RunOnce: [apptq32.exe] C:\WINDOWS\system32\apptq32.exe
O4 - HKLM\..\RunOnce: [addil.exe] C:\WINDOWS\addil.exe
O4 - HKLM\..\RunOnce: [atlwp.exe] C:\WINDOWS\atlwp.exe
O4 - HKLM\..\RunOnce: [atlqj32.exe] C:\WINDOWS\atlqj32.exe
O4 - HKLM\..\RunOnce: [crta32.exe] C:\WINDOWS\crta32.exe
O4 - HKLM\..\RunOnce: [javaix32.exe] C:\WINDOWS\javaix32.exe
O4 - HKLM\..\RunOnce: [apiyn.exe] C:\WINDOWS\system32\apiyn.exe
O4 - HKLM\..\RunOnce: [winxc32.exe] C:\WINDOWS\system32\winxc32.exe
O4 - HKLM\..\RunOnce: [ipbm.exe] C:\WINDOWS\ipbm.exe
O4 - HKLM\..\RunOnce: [javafq32.exe] C:\WINDOWS\javafq32.exe
O4 - HKLM\..\RunOnce: [msku.exe] C:\WINDOWS\system32\msku.exe
O4 - HKLM\..\RunOnce: [atlne.exe] C:\WINDOWS\system32\atlne.exe
O4 - HKLM\..\RunOnce: [iemu32.exe] C:\WINDOWS\system32\iemu32.exe
O4 - HKLM\..\RunOnce: [appxs.exe] C:\WINDOWS\appxs.exe
O4 - HKLM\..\RunOnce: [apifg.exe] C:\WINDOWS\system32\apifg.exe
O4 - HKLM\..\RunOnce: [crmv.exe] C:\WINDOWS\system32\crmv.exe
O4 - HKLM\..\RunOnce: [netuj32.exe] C:\WINDOWS\system32\netuj32.exe
O4 - HKLM\..\RunOnce: [winyf32.exe] C:\WINDOWS\system32\winyf32.exe
O4 - HKLM\..\RunOnce: [d3gh32.exe] C:\WINDOWS\system32\d3gh32.exe
O4 - HKLM\..\RunOnce: [msgp32.exe] C:\WINDOWS\msgp32.exe
O4 - HKLM\..\RunOnce: [javaqx.exe] C:\WINDOWS\javaqx.exe
O4 - HKLM\..\RunOnce: [d3jq32.exe] C:\WINDOWS\d3jq32.exe
O4 - HKLM\..\RunOnce: [sdkhu32.exe] C:\WINDOWS\system32\sdkhu32.exe
O4 - HKLM\..\RunOnce: [winfr32.exe] C:\WINDOWS\winfr32.exe
O4 - HKLM\..\RunOnce: [d3vg32.exe] C:\WINDOWS\system32\d3vg32.exe
O4 - HKLM\..\RunOnce: [msdw32.exe] C:\WINDOWS\system32\msdw32.exe
O4 - HKLM\..\RunOnce: [addmp32.exe] C:\WINDOWS\addmp32.exe
O4 - HKLM\..\RunOnce: [sysxt32.exe] C:\WINDOWS\system32\sysxt32.exe
O4 - HKLM\..\RunOnce: [javakv32.exe] C:\WINDOWS\javakv32.exe
O4 - HKLM\..\RunOnce: [appnv32.exe] C:\WINDOWS\system32\appnv32.exe
O4 - HKLM\..\RunOnce: [netmo32.exe] C:\WINDOWS\system32\netmo32.exe
O4 - HKLM\..\RunOnce: [crnv32.exe] C:\WINDOWS\crnv32.exe
O4 - HKLM\..\RunOnce: [crba32.exe] C:\WINDOWS\system32\crba32.exe
O4 - HKLM\..\RunOnce: [sdkmg.exe] C:\WINDOWS\system32\sdkmg.exe
O4 - HKLM\..\RunOnce: [windx32.exe] C:\WINDOWS\windx32.exe
O4 - HKLM\..\RunOnce: [sdkev32.exe] C:\WINDOWS\system32\sdkev32.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: officejet 6100.lnk = ?
O4 - Global Startup: Camio Viewer 3.2.lnk = C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Ask Jeeves Search - res://C:\WINDOWS\System32\askbarAB.dll/cmd-search-selection
O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Dictionary Search - res://C:\WINDOWS\System32\askbarAB.dll/cmd-search-selection-word
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Look Up in &Encyclopedia - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra 'Tools' menuitem: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra 'Tools' menuitem: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Dell Home - {08DCFC6C-B6E4-480C-95A4-FC64F37B787E} - http://www.dellnet.com (file missing) (HKCU)
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: eCrew Delta Technology V13100 -
http://ecrew.delta-air.com/classes/cst/eCrew13100.cab
O16 - DPF: eCrew Delta Technology V13112 -
http://ecrew.delta-air.com/classes/cst/eCrew13112.cab
O16 - DPF: eCrew Delta Technology V1381 -
http://10.1.44.53/classes/cst/eCrew1381.cab
O16 - DPF: eCrew Delta Technology V1397 -
http://10.1.44.53/classes/cst/eCrew1397.cab
O16 - DPF: eCrew Delta Technology V1410 -
http://ecrew.delta-air.com/classes/cst/eCrew1410.cab
O16 - DPF: eCrew Delta Technology V14102 -
http://ecrew.delta-air.com/eCrew14102.cab
O16 - DPF: eCrew Delta Technology V14120 -
http://ecrew.delta-air.com/eCrew14120.cab
O16 - DPF: eCrew Delta Technology V14141 -
http://ecrew.delta-air.com/eCrew14141.cab
O16 - DPF: eCrew Delta Technology V14169 -
http://ecrew.delta-air.com/eCrew14169.cab
O16 - DPF: eCrew Delta Technology V14170 -
http://ecrew.delta-air.com/eCrew14170.cab
O16 - DPF: eCrew Delta Technology V14180 -
http://ecrew.delta-air.com/eCrew14180.cab
O16 - DPF: eCrew Delta Technology V14200 -
http://ecrew.delta-air.com/eCrew14200.cab
O16 - DPF: eCrew Delta Technology V1451 -
http://ecrew.delta-air.com/eCrew1451.cab
O16 - DPF: eCrew Delta Technology V1472 -
http://ecrew.delta-air.com/eCrew1472.cab
O16 - DPF: eCrew Delta Technology V1486 -
http://ecrew.delta-air.com/eCrew1486.cab
O16 - DPF: eCrew Delta Technology V1491 -
http://ecrew.delta-air.com/eCrew1491.cab
O16 - DPF: {058025FC-4416-436B-ACFD-03E6224C901C} (FileInfo Class) -
http://diagnostics.support.hp.com/motivedo…w/ipgaxctrl.cab
O16 - DPF: {4855C21B-E452-4661-A702-ED3493CE74DF} (AJ Installer Control) -
http://sp.ask.com/docs/toolbar/download/askbar-inst.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupdate.microsoft.com/v5co…b?1093355041187
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {C3498BF0-2C07-43C8-99D0-434B038334A6} (VDLaunch Class) -
http://www.catharon.com/download/plugins/ievdl2.ocx
O16 - DPF: {DED22F57-FEE2-11D0-953B-00C04FD9152D} (CarPoint Auto-Pricer Control) -
http://carpoint.msn.com/components/ocx/aut…/autopricer.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) -
http://h30043.www3.hp.com/aio/eng/check/qdiagh.cab?312
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\netjo.exe (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe