Ok this all started when i downloaded a crack for a program i have, i installed it... then all of a sudden i get a little red circle with an "x" in it in my system tray at the bottom right hand corner that says "your computer is infected"... and whenever i click on internet explorer i get this C:/secure32.html thing that says:
--------------------------------------------------------------------------
Detected SPYware! System error #384
__________________________________________________________________________
Your IP address is ---------. Using this address a remote computer has gained anaccess to your computer and probably is collecting the information about the sites you've visited and the files contained in the folder Temporary Internet Files. Attention! Ask for help or install the software for deleting secret information about the sites you visited.
__________________________________________________________________________
Your computer is full of evidences!
ISP of transmission: PACBELL
Your IP address: ----------
They know you're using: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; {E8E6C444-F39F-463C-AE7C-BA127300F54F}; .NET CLR 1.1.4322)
Your computer is: Windows XP
Risk status for further investigation: VERY HIGH RISK
To protect from the Spyware - click here
To prevent information transmission - click here
To delete the history of your activity, click here
--------------------------------------------------------------------------
spyware detected blah blah blah... and whenever i try to change my homepage to like yahoo it always changes back to that...
i scanned with adaware and norton anti-virus but with no avail...still there
heres my hijackthis log:
Logfile of HijackThis v1.99.1
Scan saved at 12:24:42 PM, on 1/15/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
D:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\DOCUME~1\SIMONP~1\LOCALS~1\Temp\MSI4FB.tmp
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
D:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Sony\MD Simple Burner\NetMDSB.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Sony\VAIO Media Integrated Server\Music\SSSvr.exe
C:\WINDOWS\ftgesvc.exe
C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
C:\WINDOWS\system32\ezSP_Px.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\paytime.exe
C:\winstall.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\palmOne\HOTSYNC.EXE
C:\WINDOWS\system32\DllHost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\regedit.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Simon Pilipchuk\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/wdgt3/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/wdgt3/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/wdgt3/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/wdgt3/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/wdgt3/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/wdgt3/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R3 - URLSearchHook: (no name) - {DC047B59-291C-8C58-A93B-8F248F7AD16A} - C:\WINDOWS\elrporls.dll (file missing)
O2 - BHO: (no name) - {46A7BCCC-C1AC-DE59-E2EC-E74E9A781B87} - C:\WINDOWS\elrporls.dll (file missing)
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Search - {67D102BA-B8A9-C3C1-67F8-068A48FD1359} - C:\WINDOWS\elrporls.dll (file missing)
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe
O4 - HKLM\..\Run: [usbidll] C:\WINDOWS\usbidll.exe
O4 - HKLM\..\Run: [usbienc] C:\WINDOWS\usbienc.exe
O4 - HKLM\..\Run: [zxboenc] C:\WINDOWS\zxboenc.exe
O4 - HKLM\..\Run: [zxbodll] C:\WINDOWS\zxbodll.exe
O4 - HKLM\..\Run: [zvuhenc] C:\WINDOWS\zvuhenc.exe
O4 - HKLM\..\Run: [zvuhdll] C:\WINDOWS\zvuhdll.exe
O4 - HKLM\..\Run: [zullenc] C:\WINDOWS\zullenc.exe
O4 - HKLM\..\Run: [zulldll] C:\WINDOWS\zulldll.exe
O4 - HKLM\..\Run: [ztzpenc] C:\WINDOWS\ztzpenc.exe
O4 - HKLM\..\Run: [ztzpdll] C:\WINDOWS\ztzpdll.exe
O4 - HKLM\..\Run: [ZTgServerSwitch] "c:\program files\support.com\client\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [zomdenc] C:\WINDOWS\zomdenc.exe
O4 - HKLM\..\Run: [zomddll] C:\WINDOWS\zomddll.exe
O4 - HKLM\..\Run: [zlgpenc] C:\WINDOWS\zlgpenc.exe
O4 - HKLM\..\Run: [zlgpdll] C:\WINDOWS\zlgpdll.exe
O4 - HKLM\..\Run: [zhasenc] C:\WINDOWS\zhasenc.exe
O4 - HKLM\..\Run: [zhasdll] C:\WINDOWS\zhasdll.exe
O4 - HKLM\..\Run: [zgepenc] C:\WINDOWS\zgepenc.exe
O4 - HKLM\..\Run: [zgepdll] C:\WINDOWS\zgepdll.exe
O4 - HKLM\..\Run: [zeblenc] C:\WINDOWS\zeblenc.exe
O4 - HKLM\..\Run: [zebldll] C:\WINDOWS\zebldll.exe
O4 - HKLM\..\Run: [zbbeenc] C:\WINDOWS\zbbeenc.exe
O4 - HKLM\..\Run: [zbbedll] C:\WINDOWS\zbbedll.exe
O4 - HKLM\..\Run: [zanqenc] C:\WINDOWS\zanqenc.exe
O4 - HKLM\..\Run: [zanqdll] C:\WINDOWS\zanqdll.exe
O4 - HKLM\..\Run: [yzlodll] C:\WINDOWS\yzlodll.exe
O4 - HKLM\..\Run: [yvufenc] C:\WINDOWS\yvufenc.exe
O4 - HKLM\..\Run: [yvufdll] C:\WINDOWS\yvufdll.exe
O4 - HKLM\..\Run: [ynogenc] C:\WINDOWS\ynogenc.exe
O4 - HKLM\..\Run: [ynogdll] C:\WINDOWS\ynogdll.exe
O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [yathenc] C:\WINDOWS\yathenc.exe
O4 - HKLM\..\Run: [yathdll] C:\WINDOWS\yathdll.exe
O4 - HKLM\..\Run: [yaiuenc] C:\WINDOWS\yaiuenc.exe
O4 - HKLM\..\Run: [yaiudll] C:\WINDOWS\yaiudll.exe
O4 - HKLM\..\Run: [xwgpenc] C:\WINDOWS\xwgpenc.exe
O4 - HKLM\..\Run: [xwgpdll] C:\WINDOWS\xwgpdll.exe
O4 - HKLM\..\Run: [xrgyenc] C:\WINDOWS\xrgyenc.exe
O4 - HKLM\..\Run: [xrgydll] C:\WINDOWS\xrgydll.exe
O4 - HKLM\..\Run: [xnncenc] C:\WINDOWS\xnncenc.exe
O4 - HKLM\..\Run: [xnncdll] C:\WINDOWS\xnncdll.exe
O4 - HKLM\..\Run: [xmxwenc] C:\WINDOWS\xmxwenc.exe
O4 - HKLM\..\Run: [xmxwdll] C:\WINDOWS\xmxwdll.exe
O4 - HKLM\..\Run: [xinlenc] C:\WINDOWS\xinlenc.exe
O4 - HKLM\..\Run: [xinldll] C:\WINDOWS\xinldll.exe
O4 - HKLM\..\Run: [xhtxenc] C:\WINDOWS\xhtxenc.exe
O4 - HKLM\..\Run: [xhtxdll] C:\WINDOWS\xhtxdll.exe
O4 - HKLM\..\Run: [xdroenc] C:\WINDOWS\xdroenc.exe
O4 - HKLM\..\Run: [xavdenc] C:\WINDOWS\xavdenc.exe
O4 - HKLM\..\Run: [xavddll] C:\WINDOWS\xavddll.exe
O4 - HKLM\..\Run: [wzshenc] C:\WINDOWS\wzshenc.exe
O4 - HKLM\..\Run: [wzshdll] C:\WINDOWS\wzshdll.exe
O4 - HKLM\..\Run: [wzrlenc] C:\WINDOWS\wzrlenc.exe
O4 - HKLM\..\Run: [wzrldll] C:\WINDOWS\wzrldll.exe
O4 - HKLM\..\Run: [wxhoenc] C:\WINDOWS\wxhoenc.exe
O4 - HKLM\..\Run: [wxhodll] C:\WINDOWS\wxhodll.exe
O4 - HKLM\..\Run: [wuchenc] C:\WINDOWS\wuchenc.exe
O4 - HKLM\..\Run: [wuchdll] C:\WINDOWS\wuchdll.exe
O4 - HKLM\..\Run: [wjsjdll] C:\WINDOWS\wjsjdll.exe
O4 - HKLM\..\Run: [wgaaenc] C:\WINDOWS\wgaaenc.exe
O4 - HKLM\..\Run: [vugtenc] C:\WINDOWS\vugtenc.exe
O4 - HKLM\..\Run: [vugtdll] C:\WINDOWS\vugtdll.exe
O4 - HKLM\..\Run: [vtffenc] C:\WINDOWS\vtffenc.exe
O4 - HKLM\..\Run: [vtffdll] C:\WINDOWS\vtffdll.exe
O4 - HKLM\..\Run: [vmunenc] C:\WINDOWS\vmunenc.exe
O4 - HKLM\..\Run: [vmundll] C:\WINDOWS\vmundll.exe
O4 - HKLM\..\Run: [vmlienc] C:\WINDOWS\vmlienc.exe
O4 - HKLM\..\Run: [vjewenc] C:\WINDOWS\vjewenc.exe
O4 - HKLM\..\Run: [vjewdll] C:\WINDOWS\vjewdll.exe
O4 - HKLM\..\Run: [vhgrenc] C:\WINDOWS\vhgrenc.exe
O4 - HKLM\..\Run: [vhgrdll] C:\WINDOWS\vhgrdll.exe
O4 - HKLM\..\Run: [vhaqenc] C:\WINDOWS\vhaqenc.exe
O4 - HKLM\..\Run: [vhaqdll] C:\WINDOWS\vhaqdll.exe
O4 - HKLM\..\Run: [vgkfenc] C:\WINDOWS\vgkfenc.exe
O4 - HKLM\..\Run: [vgkfdll] C:\WINDOWS\vgkfdll.exe
O4 - HKLM\..\Run: [vejcenc] C:\WINDOWS\vejcenc.exe
O4 - HKLM\..\Run: [vejcdll] C:\WINDOWS\vejcdll.exe
O4 - HKLM\..\Run: [vbyqenc] C:\WINDOWS\vbyqenc.exe
O4 - HKLM\..\Run: [vbyqdll] C:\WINDOWS\vbyqdll.exe
O4 - HKLM\..\Run: [vbquenc] C:\WINDOWS\vbquenc.exe
O4 - HKLM\..\Run: [vbqudll] C:\WINDOWS\vbqudll.exe
O4 - HKLM\..\Run: [vbfoenc] C:\WINDOWS\vbfoenc.exe
O4 - HKLM\..\Run: [vbfodll] C:\WINDOWS\vbfodll.exe
O4 - HKLM\..\Run: [VAIO Recovery] C:\Windows\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [uymmenc] C:\WINDOWS\uymmenc.exe
O4 - HKLM\..\Run: [uymmdll] C:\WINDOWS\uymmdll.exe
O4 - HKLM\..\Run: [uufxenc] C:\WINDOWS\uufxenc.exe
O4 - HKLM\..\Run: [utxjdll] C:\WINDOWS\utxjdll.exe
O4 - HKLM\..\Run: [usruenc] C:\WINDOWS\usruenc.exe
O4 - HKLM\..\Run: [usrudll] C:\WINDOWS\usrudll.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [uktjenc] C:\WINDOWS\uktjenc.exe
O4 - HKLM\..\Run: [uktjdll] C:\WINDOWS\uktjdll.exe
O4 - HKLM\..\Run: [ueteenc] C:\WINDOWS\ueteenc.exe
O4 - HKLM\..\Run: [uetedll] C:\WINDOWS\uetedll.exe
O4 - HKLM\..\Run: [ubmoenc] C:\WINDOWS\ubmoenc.exe
O4 - HKLM\..\Run: [ubmodll] C:\WINDOWS\ubmodll.exe
O4 - HKLM\..\Run: [tznpenc] C:\WINDOWS\tznpenc.exe
O4 - HKLM\..\Run: [tznpdll] C:\WINDOWS\tznpdll.exe
O4 - HKLM\..\Run: [tziienc] C:\WINDOWS\tziienc.exe
O4 - HKLM\..\Run: [tziidll] C:\WINDOWS\tziidll.exe
O4 - HKLM\..\Run: [tutcenc] C:\WINDOWS\tutcenc.exe
O4 - HKLM\..\Run: [tutcdll] C:\WINDOWS\tutcdll.exe
O4 - HKLM\..\Run: [tsndenc] C:\WINDOWS\tsndenc.exe
O4 - HKLM\..\Run: [tsnddll] C:\WINDOWS\tsnddll.exe
O4 - HKLM\..\Run: [trvpenc] C:\WINDOWS\trvpenc.exe
O4 - HKLM\..\Run: [trvpdll] C:\WINDOWS\trvpdll.exe
O4 - HKLM\..\Run: [tqqzenc] C:\WINDOWS\tqqzenc.exe
O4 - HKLM\..\Run: [tqqzdll] C:\WINDOWS\tqqzdll.exe
O4 - HKLM\..\Run: [tocqenc] C:\WINDOWS\tocqenc.exe
O4 - HKLM\..\Run: [tocqdll] C:\WINDOWS\tocqdll.exe
O4 - HKLM\..\Run: [tnisenc] C:\WINDOWS\tnisenc.exe
O4 - HKLM\..\Run: [tnisdll] C:\WINDOWS\tnisdll.exe
O4 - HKLM\..\Run: [tkyyenc] C:\WINDOWS\tkyyenc.exe
O4 - HKLM\..\Run: [tkyydll] C:\WINDOWS\tkyydll.exe
O4 - HKLM\..\Run: [tjbuenc] C:\WINDOWS\tjbuenc.exe
O4 - HKLM\..\Run: [tjbudll] C:\WINDOWS\tjbudll.exe
O4 - HKLM\..\Run: [tfatenc] C:\WINDOWS\tfatenc.exe
O4 - HKLM\..\Run: [tfatdll] C:\WINDOWS\tfatdll.exe
O4 - HKLM\..\Run: [tdfoenc] C:\WINDOWS\tdfoenc.exe
O4 - HKLM\..\Run: [tdfodll] C:\WINDOWS\tdfodll.exe
O4 - HKLM\..\Run: [tccuenc] C:\WINDOWS\tccuenc.exe
O4 - HKLM\..\Run: [tccudll] C:\WINDOWS\tccudll.exe
O4 - HKLM\..\Run: [tbrdenc] C:\WINDOWS\tbrdenc.exe
O4 - HKLM\..\Run: [tbrddll] C:\WINDOWS\tbrddll.exe
O4 - HKLM\..\Run: [tavpenc] C:\WINDOWS\tavpenc.exe
O4 - HKLM\..\Run: [tavpdll] C:\WINDOWS\tavpdll.exe
O4 - HKLM\..\Run: [swyudll] C:\WINDOWS\swyudll.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [SStb.exe] SStb.exe
O4 - HKLM\..\Run: [srqzenc] C:\WINDOWS\srqzenc.exe
O4 - HKLM\..\Run: [srqzdll] C:\WINDOWS\srqzdll.exe
O4 - HKLM\..\Run: [sqojenc] C:\WINDOWS\sqojenc.exe
O4 - HKLM\..\Run: [sqojdll] C:\WINDOWS\sqojdll.exe
O4 - HKLM\..\Run: [snzbenc] C:\WINDOWS\snzbenc.exe
O4 - HKLM\..\Run: [snzbdll] C:\WINDOWS\snzbdll.exe
O4 - HKLM\..\Run: [sjkpenc] C:\WINDOWS\sjkpenc.exe
O4 - HKLM\..\Run: [sjkpdll] C:\WINDOWS\sjkpdll.exe
O4 - HKLM\..\Run: [sjjvdll] C:\WINDOWS\sjjvdll.exe
O4 - HKLM\..\Run: [shggenc] C:\WINDOWS\shggenc.exe
O4 - HKLM\..\Run: [shggdll] C:\WINDOWS\shggdll.exe
O4 - HKLM\..\Run: [sccjenc] C:\WINDOWS\sccjenc.exe
O4 - HKLM\..\Run: [sccjdll] C:\WINDOWS\sccjdll.exe
O4 - HKLM\..\Run: [roipenc] C:\WINDOWS\roipenc.exe
O4 - HKLM\..\Run: [rmneenc] C:\WINDOWS\rmneenc.exe
O4 - HKLM\..\Run: [rmnedll] C:\WINDOWS\rmnedll.exe
O4 - HKLM\..\Run: [rmkkenc] C:\WINDOWS\rmkkenc.exe
O4 - HKLM\..\Run: [rmkkdll] C:\WINDOWS\rmkkdll.exe
O4 - HKLM\..\Run: [RJOVENC] C:\WINDOWS\RJOVENC.EXE
O4 - HKLM\..\Run: [RJOVDLL] C:\WINDOWS\RJOVDLL.EXE
O4 - HKLM\..\Run: [rjdjdll] C:\WINDOWS\rjdjdll.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [raaienc] C:\WINDOWS\raaienc.exe
O4 - HKLM\..\Run: [raaidll] C:\WINDOWS\raaidll.exe
O4 - HKLM\..\Run: [quhxenc] C:\WINDOWS\quhxenc.exe
O4 - HKLM\..\Run: [qotrenc] C:\WINDOWS\qotrenc.exe
O4 - HKLM\..\Run: [qnawenc] C:\WINDOWS\qnawenc.exe
O4 - HKLM\..\Run: [qnawdll] C:\WINDOWS\qnawdll.exe
O4 - HKLM\..\Run: [qjtlenc] C:\WINDOWS\qjtlenc.exe
O4 - HKLM\..\Run: [qjtldll] C:\WINDOWS\qjtldll.exe
O4 - HKLM\..\Run: [qbbrenc] C:\WINDOWS\qbbrenc.exe
O4 - HKLM\..\Run: [qbbrdll] C:\WINDOWS\qbbrdll.exe
O4 - HKLM\..\Run: [puzbenc] C:\WINDOWS\puzbenc.exe
O4 - HKLM\..\Run: [puzbdll] C:\WINDOWS\puzbdll.exe
O4 - HKLM\..\Run: [pmrqenc] C:\WINDOWS\pmrqenc.exe
O4 - HKLM\..\Run: [pkuvenc] C:\WINDOWS\pkuvenc.exe
O4 - HKLM\..\Run: [pkuvdll] C:\WINDOWS\pkuvdll.exe
O4 - HKLM\..\Run: [pgzeenc] C:\WINDOWS\pgzeenc.exe
O4 - HKLM\..\Run: [pgzedll] C:\WINDOWS\pgzedll.exe
O4 - HKLM\..\Run: [pfhqenc] C:\WINDOWS\pfhqenc.exe
O4 - HKLM\..\Run: [pfhqdll] C:\WINDOWS\pfhqdll.exe
O4 - HKLM\..\Run: [pcwhenc] C:\WINDOWS\pcwhenc.exe
O4 - HKLM\..\Run: [pcwhdll] C:\WINDOWS\pcwhdll.exe
O4 - HKLM\..\Run: [pcevenc] C:\WINDOWS\pcevenc.exe
O4 - HKLM\..\Run: [pcevdll] C:\WINDOWS\pcevdll.exe
O4 - HKLM\..\Run: [PaciSoft] C:\WINDOWS\system32\pacis.exe
O4 - HKLM\..\Run: [p72R38j] adi00msg.exe
O4 - HKLM\..\Run: [oxxienc] C:\WINDOWS\oxxienc.exe
O4 - HKLM\..\Run: [oxxidll] C:\WINDOWS\oxxidll.exe
O4 - HKLM\..\Run: [oxqxenc] C:\WINDOWS\oxqxenc.exe
O4 - HKLM\..\Run: [oxqxdll] C:\WINDOWS\oxqxdll.exe
O4 - HKLM\..\Run: [owioenc] C:\WINDOWS\owioenc.exe
O4 - HKLM\..\Run: [owiodll] C:\WINDOWS\owiodll.exe
O4 - HKLM\..\Run: [oulsenc] C:\WINDOWS\oulsenc.exe
O4 - HKLM\..\Run: [oulsdll] C:\WINDOWS\oulsdll.exe
O4 - HKLM\..\Run: [ojecenc] C:\WINDOWS\ojecenc.exe
O4 - HKLM\..\Run: [ojecdll] C:\WINDOWS\ojecdll.exe
O4 - HKLM\..\Run: [oinbenc] C:\WINDOWS\oinbenc.exe
O4 - HKLM\..\Run: [oinbdll] C:\WINDOWS\oinbdll.exe
O4 - HKLM\..\Run: [oelxenc] C:\WINDOWS\oelxenc.exe
O4 - HKLM\..\Run: [oegkdll] C:\WINDOWS\oegkdll.exe
O4 - HKLM\..\Run: [oachenc] C:\WINDOWS\oachenc.exe
O4 - HKLM\..\Run: [oachdll] C:\WINDOWS\oachdll.exe
O4 - HKLM\..\Run: [nwymenc] C:\WINDOWS\nwymenc.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nrkrenc] C:\WINDOWS\nrkrenc.exe
O4 - HKLM\..\Run: [nrkrdll] C:\WINDOWS\nrkrdll.exe
O4 - HKLM\..\Run: [nqhcenc] C:\WINDOWS\nqhcenc.exe
O4 - HKLM\..\Run: [nqhcdll] C:\WINDOWS\nqhcdll.exe
O4 - HKLM\..\Run: [npmuenc] C:\WINDOWS\npmuenc.exe
O4 - HKLM\..\Run: [npmudll] C:\WINDOWS\npmudll.exe
O4 - HKLM\..\Run: [norsenc] C:\WINDOWS\norsenc.exe
O4 - HKLM\..\Run: [norsdll] C:\WINDOWS\norsdll.exe
O4 - HKLM\..\Run: [nmouenc] C:\WINDOWS\nmouenc.exe
O4 - HKLM\..\Run: [nmoudll] C:\WINDOWS\nmoudll.exe
O4 - HKLM\..\Run: [nlzmdll] C:\WINDOWS\nlzmdll.exe
O4 - HKLM\..\Run: [nknrdll] C:\WINDOWS\nknrdll.exe
O4 - HKLM\..\Run: [nfjmenc] C:\WINDOWS\nfjmenc.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [nbypenc] C:\WINDOWS\nbypenc.exe
O4 - HKLM\..\Run: [nbypdll] C:\WINDOWS\nbypdll.exe
O4 - HKLM\..\Run: [nbjxenc] C:\WINDOWS\nbjxenc.exe
O4 - HKLM\..\Run: [nbjxdll] C:\WINDOWS\nbjxdll.exe
O4 - HKLM\..\Run: [mzbuenc] C:\WINDOWS\mzbuenc.exe
O4 - HKLM\..\Run: [mzbudll] C:\WINDOWS\mzbudll.exe
O4 - HKLM\..\Run: [mxbbenc] C:\WINDOWS\mxbbenc.exe
O4 - HKLM\..\Run: [mxbbdll] C:\WINDOWS\mxbbdll.exe
O4 - HKLM\..\Run: [mobmenc] C:\WINDOWS\mobmenc.exe
O4 - HKLM\..\Run: [mobmdll] C:\WINDOWS\mobmdll.exe
O4 - HKLM\..\Run: [mjbienc] C:\WINDOWS\mjbienc.exe
O4 - HKLM\..\Run: [mjbidll] C:\WINDOWS\mjbidll.exe
O4 - HKLM\..\Run: [mirpenc] C:\WINDOWS\mirpenc.exe
O4 - HKLM\..\Run: [mirpdll] C:\WINDOWS\mirpdll.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
--------------------------------------------------------------------------
Detected SPYware! System error #384
__________________________________________________________________________
Your IP address is ---------. Using this address a remote computer has gained anaccess to your computer and probably is collecting the information about the sites you've visited and the files contained in the folder Temporary Internet Files. Attention! Ask for help or install the software for deleting secret information about the sites you visited.
__________________________________________________________________________
Your computer is full of evidences!
ISP of transmission: PACBELL
Your IP address: ----------
They know you're using: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; {E8E6C444-F39F-463C-AE7C-BA127300F54F}; .NET CLR 1.1.4322)
Your computer is: Windows XP
Risk status for further investigation: VERY HIGH RISK
To protect from the Spyware - click here
To prevent information transmission - click here
To delete the history of your activity, click here
--------------------------------------------------------------------------
spyware detected blah blah blah... and whenever i try to change my homepage to like yahoo it always changes back to that...
i scanned with adaware and norton anti-virus but with no avail...still there
heres my hijackthis log:
Logfile of HijackThis v1.99.1
Scan saved at 12:24:42 PM, on 1/15/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
D:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\DOCUME~1\SIMONP~1\LOCALS~1\Temp\MSI4FB.tmp
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
D:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Sony\MD Simple Burner\NetMDSB.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Sony\VAIO Media Integrated Server\Music\SSSvr.exe
C:\WINDOWS\ftgesvc.exe
C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
C:\WINDOWS\system32\ezSP_Px.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\paytime.exe
C:\winstall.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\palmOne\HOTSYNC.EXE
C:\WINDOWS\system32\DllHost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\regedit.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Simon Pilipchuk\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/wdgt3/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/wdgt3/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/wdgt3/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/wdgt3/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/wdgt3/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/wdgt3/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R3 - URLSearchHook: (no name) - {DC047B59-291C-8C58-A93B-8F248F7AD16A} - C:\WINDOWS\elrporls.dll (file missing)
O2 - BHO: (no name) - {46A7BCCC-C1AC-DE59-E2EC-E74E9A781B87} - C:\WINDOWS\elrporls.dll (file missing)
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Search - {67D102BA-B8A9-C3C1-67F8-068A48FD1359} - C:\WINDOWS\elrporls.dll (file missing)
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe
O4 - HKLM\..\Run: [usbidll] C:\WINDOWS\usbidll.exe
O4 - HKLM\..\Run: [usbienc] C:\WINDOWS\usbienc.exe
O4 - HKLM\..\Run: [zxboenc] C:\WINDOWS\zxboenc.exe
O4 - HKLM\..\Run: [zxbodll] C:\WINDOWS\zxbodll.exe
O4 - HKLM\..\Run: [zvuhenc] C:\WINDOWS\zvuhenc.exe
O4 - HKLM\..\Run: [zvuhdll] C:\WINDOWS\zvuhdll.exe
O4 - HKLM\..\Run: [zullenc] C:\WINDOWS\zullenc.exe
O4 - HKLM\..\Run: [zulldll] C:\WINDOWS\zulldll.exe
O4 - HKLM\..\Run: [ztzpenc] C:\WINDOWS\ztzpenc.exe
O4 - HKLM\..\Run: [ztzpdll] C:\WINDOWS\ztzpdll.exe
O4 - HKLM\..\Run: [ZTgServerSwitch] "c:\program files\support.com\client\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [zomdenc] C:\WINDOWS\zomdenc.exe
O4 - HKLM\..\Run: [zomddll] C:\WINDOWS\zomddll.exe
O4 - HKLM\..\Run: [zlgpenc] C:\WINDOWS\zlgpenc.exe
O4 - HKLM\..\Run: [zlgpdll] C:\WINDOWS\zlgpdll.exe
O4 - HKLM\..\Run: [zhasenc] C:\WINDOWS\zhasenc.exe
O4 - HKLM\..\Run: [zhasdll] C:\WINDOWS\zhasdll.exe
O4 - HKLM\..\Run: [zgepenc] C:\WINDOWS\zgepenc.exe
O4 - HKLM\..\Run: [zgepdll] C:\WINDOWS\zgepdll.exe
O4 - HKLM\..\Run: [zeblenc] C:\WINDOWS\zeblenc.exe
O4 - HKLM\..\Run: [zebldll] C:\WINDOWS\zebldll.exe
O4 - HKLM\..\Run: [zbbeenc] C:\WINDOWS\zbbeenc.exe
O4 - HKLM\..\Run: [zbbedll] C:\WINDOWS\zbbedll.exe
O4 - HKLM\..\Run: [zanqenc] C:\WINDOWS\zanqenc.exe
O4 - HKLM\..\Run: [zanqdll] C:\WINDOWS\zanqdll.exe
O4 - HKLM\..\Run: [yzlodll] C:\WINDOWS\yzlodll.exe
O4 - HKLM\..\Run: [yvufenc] C:\WINDOWS\yvufenc.exe
O4 - HKLM\..\Run: [yvufdll] C:\WINDOWS\yvufdll.exe
O4 - HKLM\..\Run: [ynogenc] C:\WINDOWS\ynogenc.exe
O4 - HKLM\..\Run: [ynogdll] C:\WINDOWS\ynogdll.exe
O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [yathenc] C:\WINDOWS\yathenc.exe
O4 - HKLM\..\Run: [yathdll] C:\WINDOWS\yathdll.exe
O4 - HKLM\..\Run: [yaiuenc] C:\WINDOWS\yaiuenc.exe
O4 - HKLM\..\Run: [yaiudll] C:\WINDOWS\yaiudll.exe
O4 - HKLM\..\Run: [xwgpenc] C:\WINDOWS\xwgpenc.exe
O4 - HKLM\..\Run: [xwgpdll] C:\WINDOWS\xwgpdll.exe
O4 - HKLM\..\Run: [xrgyenc] C:\WINDOWS\xrgyenc.exe
O4 - HKLM\..\Run: [xrgydll] C:\WINDOWS\xrgydll.exe
O4 - HKLM\..\Run: [xnncenc] C:\WINDOWS\xnncenc.exe
O4 - HKLM\..\Run: [xnncdll] C:\WINDOWS\xnncdll.exe
O4 - HKLM\..\Run: [xmxwenc] C:\WINDOWS\xmxwenc.exe
O4 - HKLM\..\Run: [xmxwdll] C:\WINDOWS\xmxwdll.exe
O4 - HKLM\..\Run: [xinlenc] C:\WINDOWS\xinlenc.exe
O4 - HKLM\..\Run: [xinldll] C:\WINDOWS\xinldll.exe
O4 - HKLM\..\Run: [xhtxenc] C:\WINDOWS\xhtxenc.exe
O4 - HKLM\..\Run: [xhtxdll] C:\WINDOWS\xhtxdll.exe
O4 - HKLM\..\Run: [xdroenc] C:\WINDOWS\xdroenc.exe
O4 - HKLM\..\Run: [xavdenc] C:\WINDOWS\xavdenc.exe
O4 - HKLM\..\Run: [xavddll] C:\WINDOWS\xavddll.exe
O4 - HKLM\..\Run: [wzshenc] C:\WINDOWS\wzshenc.exe
O4 - HKLM\..\Run: [wzshdll] C:\WINDOWS\wzshdll.exe
O4 - HKLM\..\Run: [wzrlenc] C:\WINDOWS\wzrlenc.exe
O4 - HKLM\..\Run: [wzrldll] C:\WINDOWS\wzrldll.exe
O4 - HKLM\..\Run: [wxhoenc] C:\WINDOWS\wxhoenc.exe
O4 - HKLM\..\Run: [wxhodll] C:\WINDOWS\wxhodll.exe
O4 - HKLM\..\Run: [wuchenc] C:\WINDOWS\wuchenc.exe
O4 - HKLM\..\Run: [wuchdll] C:\WINDOWS\wuchdll.exe
O4 - HKLM\..\Run: [wjsjdll] C:\WINDOWS\wjsjdll.exe
O4 - HKLM\..\Run: [wgaaenc] C:\WINDOWS\wgaaenc.exe
O4 - HKLM\..\Run: [vugtenc] C:\WINDOWS\vugtenc.exe
O4 - HKLM\..\Run: [vugtdll] C:\WINDOWS\vugtdll.exe
O4 - HKLM\..\Run: [vtffenc] C:\WINDOWS\vtffenc.exe
O4 - HKLM\..\Run: [vtffdll] C:\WINDOWS\vtffdll.exe
O4 - HKLM\..\Run: [vmunenc] C:\WINDOWS\vmunenc.exe
O4 - HKLM\..\Run: [vmundll] C:\WINDOWS\vmundll.exe
O4 - HKLM\..\Run: [vmlienc] C:\WINDOWS\vmlienc.exe
O4 - HKLM\..\Run: [vjewenc] C:\WINDOWS\vjewenc.exe
O4 - HKLM\..\Run: [vjewdll] C:\WINDOWS\vjewdll.exe
O4 - HKLM\..\Run: [vhgrenc] C:\WINDOWS\vhgrenc.exe
O4 - HKLM\..\Run: [vhgrdll] C:\WINDOWS\vhgrdll.exe
O4 - HKLM\..\Run: [vhaqenc] C:\WINDOWS\vhaqenc.exe
O4 - HKLM\..\Run: [vhaqdll] C:\WINDOWS\vhaqdll.exe
O4 - HKLM\..\Run: [vgkfenc] C:\WINDOWS\vgkfenc.exe
O4 - HKLM\..\Run: [vgkfdll] C:\WINDOWS\vgkfdll.exe
O4 - HKLM\..\Run: [vejcenc] C:\WINDOWS\vejcenc.exe
O4 - HKLM\..\Run: [vejcdll] C:\WINDOWS\vejcdll.exe
O4 - HKLM\..\Run: [vbyqenc] C:\WINDOWS\vbyqenc.exe
O4 - HKLM\..\Run: [vbyqdll] C:\WINDOWS\vbyqdll.exe
O4 - HKLM\..\Run: [vbquenc] C:\WINDOWS\vbquenc.exe
O4 - HKLM\..\Run: [vbqudll] C:\WINDOWS\vbqudll.exe
O4 - HKLM\..\Run: [vbfoenc] C:\WINDOWS\vbfoenc.exe
O4 - HKLM\..\Run: [vbfodll] C:\WINDOWS\vbfodll.exe
O4 - HKLM\..\Run: [VAIO Recovery] C:\Windows\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [uymmenc] C:\WINDOWS\uymmenc.exe
O4 - HKLM\..\Run: [uymmdll] C:\WINDOWS\uymmdll.exe
O4 - HKLM\..\Run: [uufxenc] C:\WINDOWS\uufxenc.exe
O4 - HKLM\..\Run: [utxjdll] C:\WINDOWS\utxjdll.exe
O4 - HKLM\..\Run: [usruenc] C:\WINDOWS\usruenc.exe
O4 - HKLM\..\Run: [usrudll] C:\WINDOWS\usrudll.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [uktjenc] C:\WINDOWS\uktjenc.exe
O4 - HKLM\..\Run: [uktjdll] C:\WINDOWS\uktjdll.exe
O4 - HKLM\..\Run: [ueteenc] C:\WINDOWS\ueteenc.exe
O4 - HKLM\..\Run: [uetedll] C:\WINDOWS\uetedll.exe
O4 - HKLM\..\Run: [ubmoenc] C:\WINDOWS\ubmoenc.exe
O4 - HKLM\..\Run: [ubmodll] C:\WINDOWS\ubmodll.exe
O4 - HKLM\..\Run: [tznpenc] C:\WINDOWS\tznpenc.exe
O4 - HKLM\..\Run: [tznpdll] C:\WINDOWS\tznpdll.exe
O4 - HKLM\..\Run: [tziienc] C:\WINDOWS\tziienc.exe
O4 - HKLM\..\Run: [tziidll] C:\WINDOWS\tziidll.exe
O4 - HKLM\..\Run: [tutcenc] C:\WINDOWS\tutcenc.exe
O4 - HKLM\..\Run: [tutcdll] C:\WINDOWS\tutcdll.exe
O4 - HKLM\..\Run: [tsndenc] C:\WINDOWS\tsndenc.exe
O4 - HKLM\..\Run: [tsnddll] C:\WINDOWS\tsnddll.exe
O4 - HKLM\..\Run: [trvpenc] C:\WINDOWS\trvpenc.exe
O4 - HKLM\..\Run: [trvpdll] C:\WINDOWS\trvpdll.exe
O4 - HKLM\..\Run: [tqqzenc] C:\WINDOWS\tqqzenc.exe
O4 - HKLM\..\Run: [tqqzdll] C:\WINDOWS\tqqzdll.exe
O4 - HKLM\..\Run: [tocqenc] C:\WINDOWS\tocqenc.exe
O4 - HKLM\..\Run: [tocqdll] C:\WINDOWS\tocqdll.exe
O4 - HKLM\..\Run: [tnisenc] C:\WINDOWS\tnisenc.exe
O4 - HKLM\..\Run: [tnisdll] C:\WINDOWS\tnisdll.exe
O4 - HKLM\..\Run: [tkyyenc] C:\WINDOWS\tkyyenc.exe
O4 - HKLM\..\Run: [tkyydll] C:\WINDOWS\tkyydll.exe
O4 - HKLM\..\Run: [tjbuenc] C:\WINDOWS\tjbuenc.exe
O4 - HKLM\..\Run: [tjbudll] C:\WINDOWS\tjbudll.exe
O4 - HKLM\..\Run: [tfatenc] C:\WINDOWS\tfatenc.exe
O4 - HKLM\..\Run: [tfatdll] C:\WINDOWS\tfatdll.exe
O4 - HKLM\..\Run: [tdfoenc] C:\WINDOWS\tdfoenc.exe
O4 - HKLM\..\Run: [tdfodll] C:\WINDOWS\tdfodll.exe
O4 - HKLM\..\Run: [tccuenc] C:\WINDOWS\tccuenc.exe
O4 - HKLM\..\Run: [tccudll] C:\WINDOWS\tccudll.exe
O4 - HKLM\..\Run: [tbrdenc] C:\WINDOWS\tbrdenc.exe
O4 - HKLM\..\Run: [tbrddll] C:\WINDOWS\tbrddll.exe
O4 - HKLM\..\Run: [tavpenc] C:\WINDOWS\tavpenc.exe
O4 - HKLM\..\Run: [tavpdll] C:\WINDOWS\tavpdll.exe
O4 - HKLM\..\Run: [swyudll] C:\WINDOWS\swyudll.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [SStb.exe] SStb.exe
O4 - HKLM\..\Run: [srqzenc] C:\WINDOWS\srqzenc.exe
O4 - HKLM\..\Run: [srqzdll] C:\WINDOWS\srqzdll.exe
O4 - HKLM\..\Run: [sqojenc] C:\WINDOWS\sqojenc.exe
O4 - HKLM\..\Run: [sqojdll] C:\WINDOWS\sqojdll.exe
O4 - HKLM\..\Run: [snzbenc] C:\WINDOWS\snzbenc.exe
O4 - HKLM\..\Run: [snzbdll] C:\WINDOWS\snzbdll.exe
O4 - HKLM\..\Run: [sjkpenc] C:\WINDOWS\sjkpenc.exe
O4 - HKLM\..\Run: [sjkpdll] C:\WINDOWS\sjkpdll.exe
O4 - HKLM\..\Run: [sjjvdll] C:\WINDOWS\sjjvdll.exe
O4 - HKLM\..\Run: [shggenc] C:\WINDOWS\shggenc.exe
O4 - HKLM\..\Run: [shggdll] C:\WINDOWS\shggdll.exe
O4 - HKLM\..\Run: [sccjenc] C:\WINDOWS\sccjenc.exe
O4 - HKLM\..\Run: [sccjdll] C:\WINDOWS\sccjdll.exe
O4 - HKLM\..\Run: [roipenc] C:\WINDOWS\roipenc.exe
O4 - HKLM\..\Run: [rmneenc] C:\WINDOWS\rmneenc.exe
O4 - HKLM\..\Run: [rmnedll] C:\WINDOWS\rmnedll.exe
O4 - HKLM\..\Run: [rmkkenc] C:\WINDOWS\rmkkenc.exe
O4 - HKLM\..\Run: [rmkkdll] C:\WINDOWS\rmkkdll.exe
O4 - HKLM\..\Run: [RJOVENC] C:\WINDOWS\RJOVENC.EXE
O4 - HKLM\..\Run: [RJOVDLL] C:\WINDOWS\RJOVDLL.EXE
O4 - HKLM\..\Run: [rjdjdll] C:\WINDOWS\rjdjdll.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [raaienc] C:\WINDOWS\raaienc.exe
O4 - HKLM\..\Run: [raaidll] C:\WINDOWS\raaidll.exe
O4 - HKLM\..\Run: [quhxenc] C:\WINDOWS\quhxenc.exe
O4 - HKLM\..\Run: [qotrenc] C:\WINDOWS\qotrenc.exe
O4 - HKLM\..\Run: [qnawenc] C:\WINDOWS\qnawenc.exe
O4 - HKLM\..\Run: [qnawdll] C:\WINDOWS\qnawdll.exe
O4 - HKLM\..\Run: [qjtlenc] C:\WINDOWS\qjtlenc.exe
O4 - HKLM\..\Run: [qjtldll] C:\WINDOWS\qjtldll.exe
O4 - HKLM\..\Run: [qbbrenc] C:\WINDOWS\qbbrenc.exe
O4 - HKLM\..\Run: [qbbrdll] C:\WINDOWS\qbbrdll.exe
O4 - HKLM\..\Run: [puzbenc] C:\WINDOWS\puzbenc.exe
O4 - HKLM\..\Run: [puzbdll] C:\WINDOWS\puzbdll.exe
O4 - HKLM\..\Run: [pmrqenc] C:\WINDOWS\pmrqenc.exe
O4 - HKLM\..\Run: [pkuvenc] C:\WINDOWS\pkuvenc.exe
O4 - HKLM\..\Run: [pkuvdll] C:\WINDOWS\pkuvdll.exe
O4 - HKLM\..\Run: [pgzeenc] C:\WINDOWS\pgzeenc.exe
O4 - HKLM\..\Run: [pgzedll] C:\WINDOWS\pgzedll.exe
O4 - HKLM\..\Run: [pfhqenc] C:\WINDOWS\pfhqenc.exe
O4 - HKLM\..\Run: [pfhqdll] C:\WINDOWS\pfhqdll.exe
O4 - HKLM\..\Run: [pcwhenc] C:\WINDOWS\pcwhenc.exe
O4 - HKLM\..\Run: [pcwhdll] C:\WINDOWS\pcwhdll.exe
O4 - HKLM\..\Run: [pcevenc] C:\WINDOWS\pcevenc.exe
O4 - HKLM\..\Run: [pcevdll] C:\WINDOWS\pcevdll.exe
O4 - HKLM\..\Run: [PaciSoft] C:\WINDOWS\system32\pacis.exe
O4 - HKLM\..\Run: [p72R38j] adi00msg.exe
O4 - HKLM\..\Run: [oxxienc] C:\WINDOWS\oxxienc.exe
O4 - HKLM\..\Run: [oxxidll] C:\WINDOWS\oxxidll.exe
O4 - HKLM\..\Run: [oxqxenc] C:\WINDOWS\oxqxenc.exe
O4 - HKLM\..\Run: [oxqxdll] C:\WINDOWS\oxqxdll.exe
O4 - HKLM\..\Run: [owioenc] C:\WINDOWS\owioenc.exe
O4 - HKLM\..\Run: [owiodll] C:\WINDOWS\owiodll.exe
O4 - HKLM\..\Run: [oulsenc] C:\WINDOWS\oulsenc.exe
O4 - HKLM\..\Run: [oulsdll] C:\WINDOWS\oulsdll.exe
O4 - HKLM\..\Run: [ojecenc] C:\WINDOWS\ojecenc.exe
O4 - HKLM\..\Run: [ojecdll] C:\WINDOWS\ojecdll.exe
O4 - HKLM\..\Run: [oinbenc] C:\WINDOWS\oinbenc.exe
O4 - HKLM\..\Run: [oinbdll] C:\WINDOWS\oinbdll.exe
O4 - HKLM\..\Run: [oelxenc] C:\WINDOWS\oelxenc.exe
O4 - HKLM\..\Run: [oegkdll] C:\WINDOWS\oegkdll.exe
O4 - HKLM\..\Run: [oachenc] C:\WINDOWS\oachenc.exe
O4 - HKLM\..\Run: [oachdll] C:\WINDOWS\oachdll.exe
O4 - HKLM\..\Run: [nwymenc] C:\WINDOWS\nwymenc.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nrkrenc] C:\WINDOWS\nrkrenc.exe
O4 - HKLM\..\Run: [nrkrdll] C:\WINDOWS\nrkrdll.exe
O4 - HKLM\..\Run: [nqhcenc] C:\WINDOWS\nqhcenc.exe
O4 - HKLM\..\Run: [nqhcdll] C:\WINDOWS\nqhcdll.exe
O4 - HKLM\..\Run: [npmuenc] C:\WINDOWS\npmuenc.exe
O4 - HKLM\..\Run: [npmudll] C:\WINDOWS\npmudll.exe
O4 - HKLM\..\Run: [norsenc] C:\WINDOWS\norsenc.exe
O4 - HKLM\..\Run: [norsdll] C:\WINDOWS\norsdll.exe
O4 - HKLM\..\Run: [nmouenc] C:\WINDOWS\nmouenc.exe
O4 - HKLM\..\Run: [nmoudll] C:\WINDOWS\nmoudll.exe
O4 - HKLM\..\Run: [nlzmdll] C:\WINDOWS\nlzmdll.exe
O4 - HKLM\..\Run: [nknrdll] C:\WINDOWS\nknrdll.exe
O4 - HKLM\..\Run: [nfjmenc] C:\WINDOWS\nfjmenc.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [nbypenc] C:\WINDOWS\nbypenc.exe
O4 - HKLM\..\Run: [nbypdll] C:\WINDOWS\nbypdll.exe
O4 - HKLM\..\Run: [nbjxenc] C:\WINDOWS\nbjxenc.exe
O4 - HKLM\..\Run: [nbjxdll] C:\WINDOWS\nbjxdll.exe
O4 - HKLM\..\Run: [mzbuenc] C:\WINDOWS\mzbuenc.exe
O4 - HKLM\..\Run: [mzbudll] C:\WINDOWS\mzbudll.exe
O4 - HKLM\..\Run: [mxbbenc] C:\WINDOWS\mxbbenc.exe
O4 - HKLM\..\Run: [mxbbdll] C:\WINDOWS\mxbbdll.exe
O4 - HKLM\..\Run: [mobmenc] C:\WINDOWS\mobmenc.exe
O4 - HKLM\..\Run: [mobmdll] C:\WINDOWS\mobmdll.exe
O4 - HKLM\..\Run: [mjbienc] C:\WINDOWS\mjbienc.exe
O4 - HKLM\..\Run: [mjbidll] C:\WINDOWS\mjbidll.exe
O4 - HKLM\..\Run: [mirpenc] C:\WINDOWS\mirpenc.exe
O4 - HKLM\..\Run: [mirpdll] C:\WINDOWS\mirpdll.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe