Gimpi

Members
  • Content Count

    21
  • Joined

  • Last visited

Posts posted by Gimpi

  1. Ok, so I got this ViewSonic E90f 19" PerfectFlat monitor about a month ago. love it. works great, looks amazing. Except for one thing. Whenever the monitor turns of and turns back on, or goes to screensaver and back, it resizes itself. It will position itself outside of the viewing area and just change its dimensions. It is really annoying to have to fix it every day, sometimes more than once. Any suggestions as to how I could fix this? Thanks.

    -gimpi

  2. I recently had the same issue with my Dell. Here is what I did to fix it, after many attempts:

    Note: Only do the following if you are using Windows XP I'm not sure if it will work in previous versions of Windows.

    • Right click on 'My Computer'.
    • Click the 'Advanced' tab.
    • Go down and click 'Device Manager'.
    • Open up the 'Sound' field.
    • Right click on your sound card and hit 'uninstall'.
    • It will ask you are you sure. Hit 'ok' or 'yes'.
    • Restart your computer and it will reinstall the soundcard.

    Hope that helps.

    -gimp

  3. here ya go Jeff.

    Logfile of HijackThis v1.99.0

    Scan saved at 1:04:14 PM, on 12/31/2004

    Platform: Windows XP SP1 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\SYSTEM32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\Nhksrv.exe

    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe

    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe

    C:\WINDOWS\SYSTEM32\CTsvcCDA.EXE

    C:\Program Files\Executive Software\DiskeeperLite\DKService.exe

    C:\WINDOWS\System32\nvsvc32.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\System32\MsPMSPSv.exe

    C:\WINDOWS\SYSTEM32\winlogon.exe

    C:\WINDOWS\Explorer.EXE

    C:\Program Files\HP CD-DVD\Umbrella\DVDTray.exe

    C:\WINDOWS\System32\CTHELPER.EXE

    C:\Program Files\Common Files\Logitech\QCDriver2\LVCOMS.EXE

    C:\Program Files\MultiMedia Keyboard\MultiMedia Keyboard\1.1\KbdAp32A.exe

    C:\Program Files\Browser MOUSE\mouse32a.exe

    C:\Program Files\Google\Gmail Notifier\G001-1.0.24.0\gnotify.exe

    C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe

    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe

    C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe

    C:\Program Files\Eraser\eraser.exe

    C:\Program Files\Pulse\Pulse.exe

    C:\Program Files\WinRoll\winroll.exe

    C:\Program Files\ConquerCam\ConquerCam.exe

    C:\Program Files\Gaim\gaim.exe

    C:\Program Files\Coolmon\CoolMon.exe

    C:\Program Files\Kerio\Personal Firewall 4\Kerio.exe

    C:\Program Files\Sirus Pad\ShirusuPad\ShirusuPad.exe

    C:\Program Files\T Clock\tclock.exe

    C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe

    C:\Program Files\Mozilla Thunderbird\thunderbird.exe

    C:\Program Files\mIRC\mirc.exe

    C:\WINDOWS\system32\ntvdm.exe

    C:\Program Files\Mozilla Firefox\firefox.exe

    C:\Program Files\Hijack This\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.geekygimp.com/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

    O2 - BHO: QuickSearch SearchBar - {82315A18-6CFB-44a7-BDFD-90E36537C252} - C:\Program Files\QuickSearch\QuickSearchBar3_28.dll

    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

    O3 - Toolbar: QuickSearch SearchBar - {82315A18-6CFB-44a7-BDFD-90E36537C252} - C:\Program Files\QuickSearch\QuickSearchBar3_28.dll

    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN

    O4 - HKLM\..\Run: [sysMetrix] C:\Program Files\SysMetrix\SysMetrix.exe

    O4 - HKLM\..\Run: [DVDBitSet] "C:\Program Files\HP CD-DVD\Umbrella\DVDBitSet.exe" /NOUI

    O4 - HKLM\..\Run: [DVDTray] "C:\Program Files\HP CD-DVD\Umbrella\DVDTray.exe

    O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE

    O4 - HKLM\..\Run: [updReg] C:\WINDOWS\UpdReg.EXE

    O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"

    O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run

    O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver2\LVCOMS.EXE

    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit

    O4 - HKLM\..\Run: [LWBKEYBOARD] C:\Program Files\MultiMedia Keyboard\MultiMedia Keyboard\1.1\KbdAp32A.exe

    O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Browser MOUSE\mouse32a.exe

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.24.0\gnotify.exe

    O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe

    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP

    O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe

    O4 - HKCU\..\Run: [sTYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide

    O4 - HKCU\..\Run: [Eraser] C:\Program Files\Eraser\eraser.exe -hide

    O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe

    O4 - HKCU\..\Run: [Pulse] C:\Program Files\Pulse\Pulse.exe -splash

    O4 - HKCU\..\Run: [WinRoll] "C:\Program Files\WinRoll\winroll.exe"

    O4 - HKCU\..\Run: [shirusuPad] C:\Program Files\sticky\ShirusuPad\ShirusuPad.exe

    O4 - HKCU\..\Run: [ConquerCam] C:\Program Files\ConquerCam\ConquerCam.exe /tray

    O4 - HKCU\..\Run: [Gaim] C:\Program Files\Gaim\gaim.exe

    O4 - Startup: CoolMon.lnk = C:\Program Files\Coolmon\CoolMon.exe

    O4 - Startup: Kerio.lnk = C:\Program Files\Kerio\Personal Firewall 4\Kerio.exe

    O4 - Startup: SirusPad.lnk = C:\Program Files\Sirus Pad\ShirusuPad\ShirusuPad.exe

    O4 - Startup: T Clock.lnk = C:\Program Files\T Clock\tclock.exe

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll

    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll

    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll

    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

    O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

    O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/12119/CTSUEng.cab

    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB

    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab30149.cab

    O16 - DPF: {31FD415A-1103-4329-B323-2DE693146C4E} (InstallHelper Class) - http://survey.prod.there.com/qualsurvey/Th...stallHelper.cab

    O16 - DPF: {50F65670-1729-11D2-A51F-0020AFE5D502} (ForumChat) - http://objects.compuserve.com/chat/RTCChat.cab

    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1095391470609

    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab

    O16 - DPF: {78960E0E-0B0C-11D4-8997-00104BD12D94} (AV Class) - http://www.pcpitstop.com/antivirus/PCPAV.CAB

    O16 - DPF: {7A32634B-029C-4836-A023-528983982A49} - http://fdl.msn.com/public/chat/msnchat42.cab

    O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab

    O16 - DPF: {88D8E8B7-A33B-4417-A385-8373484D43ED} (InstallHelper Class) - http://survey.prod.there.com/qualsurvey/Th...stallHelper.cab

    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab30149.cab

    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab

    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab

    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab

    O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/12119/CTPID.cab

    O20 - AppInit_DLLs: PAVWAIT.DLL

    O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe

    O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe

    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\SYSTEM32\CTsvcCDA.EXE

    O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\DiskeeperLite\DKService.exe

    O23 - Service: IMAPI CD-Burning COM Service - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe

    O23 - Service: Kerio Personal Firewall 4 - Unknown - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe (file missing)

    O23 - Service: Netropa NHK Server - Unknown - C:\WINDOWS\Nhksrv.exe

    O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

    O23 - Service: StyleXPService - Unknown - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe

    thanks.

    -gimpi

  4. (Sorry if this is the wrong forum, I didn't really know where to put this)

    I might be getting a laptop from my dad's girlfriend. This isn't any laptop. No, no my friend. This is a six year old Toshiba Satellite 100CS [link]. I don't know if that are it's exact specs, but it's close. So, my question to you is, what the hell should I do with it? I want it to be a learning experience sorta thing. I thought of the obvious of putting linux on it and tinkering around a bit, but I want to do something else too, and I haven't a clue what. Thanks.

    -gimpi

  5. -_-

    Logfile of HijackThis v1.99.0

    Scan saved at 10:41:59 PM, on 12/23/2004

    Platform: Windows XP SP1 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\system32\cisvc.exe

    c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe

    C:\WINDOWS\System32\nvsvc32.exe

    C:\WINDOWS\System32\svchost.exe

    c:\PROGRA~1\mcafee.com\vso\mcshield.exe

    C:\WINDOWS\Explorer.EXE

    C:\Program Files\Real\RealPlayer\RealPlay.exe

    C:\Program Files\McAfee.com\Agent\mcagent.exe

    C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe

    C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe

    C:\Program Files\Common Files\Dell\EUSW\Support.exe

    C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe

    C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe

    C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe

    C:\Program Files\Messenger\msmsgs.exe

    C:\Program Files\AIM95\aim.exe

    C:\Program Files\Digital Line Detect\DLG.exe

    C:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exe

    C:\WINDOWS\System32\wuauclt.exe

    C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe

    C:\WINDOWS\System32\hpoipm07.exe

    C:\WINDOWS\System32\wuauclt.exe

    C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe

    C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe

    C:\Program Files\HJT\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.longnet.net/login.asp

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

    O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll

    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

    O2 - BHO: Band Class - {CC378B83-9577-44D0-B4F8-0DD965E176FC} - C:\Program Files\eSyndicate\esyn.dll

    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER

    O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe

    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe

    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"

    O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"

    O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe

    O4 - HKLM\..\Run: [share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe

    O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe

    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

    O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl

    O4 - HKCU\..\Run: [PopUpStopperCompanion] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSComp.exe"

    O4 - HKCU\..\Run: [ClockSync] C:\PROGRA~1\CLOCKS~1\Sync.exe /q

    O4 - HKCU\..\Run: [Tsa2] C:\PROGRA~1\COMMON~1\tsa\tsm2.exe

    O4 - Global Startup: Digital Line Detect.lnk = ?

    O4 - Global Startup: HPAiODevice(hp officejet d series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exe

    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe

    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll

    O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

    O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

    O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://us.games2.yimg.com/download.games.y...ctl_0_0_0_1.ocx

    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab

    O16 - DPF: {CFCB7308-782F-11D4-BE27-000102598CE4} (NPX Control) - http://kr.pristontale.com/nprotect/nprotect/npx.cab

    O23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exe

    O23 - Service: McAfee.com VirusScan Online Realtime Engine - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe

    O23 - Service: IntelĀ® NMS - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe

    O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

  6. Last one I hope.

    Logfile of HijackThis v1.99.0

    Scan saved at 10:18:11 PM, on 12/23/2004

    Platform: Windows XP SP1 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\system32\cisvc.exe

    c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe

    C:\WINDOWS\System32\nvsvc32.exe

    C:\WINDOWS\System32\svchost.exe

    c:\PROGRA~1\mcafee.com\vso\mcshield.exe

    C:\WINDOWS\Explorer.EXE

    C:\Program Files\Real\RealPlayer\RealPlay.exe

    C:\Program Files\McAfee.com\Agent\mcagent.exe

    C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe

    C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe

    C:\Program Files\Common Files\Dell\EUSW\Support.exe

    C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe

    C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe

    C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe

    C:\Program Files\Messenger\msmsgs.exe

    C:\Program Files\AIM95\aim.exe

    C:\Program Files\Digital Line Detect\DLG.exe

    C:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exe

    C:\WINDOWS\system32\ICSXML\inetmp3.exe

    C:\WINDOWS\System32\wuauclt.exe

    C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe

    C:\WINDOWS\System32\hpoipm07.exe

    C:\WINDOWS\System32\wuauclt.exe

    C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe

    C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe

    C:\Documents and Settings\Jodi Koch\Desktop\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.longnet.net/login.asp

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1

    R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - (no file)

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

    O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll

    O2 - BHO: CATLEvents Object - {3EC8E271-FAB9-418a-8A8E-65AEB4029E64} - C:\DOCUME~1\CHRISK~1\LOCALS~1\Temp\rvskab.dat

    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

    O2 - BHO: CATLEvents Object - {8109AF33-6949-4833-8881-43DCC232B7B2} - C:\DOCUME~1\CHRISK~1\LOCALS~1\Temp\rvskab.dat

    O2 - BHO: Band Class - {CC378B83-9577-44D0-B4F8-0DD965E176FC} - C:\Program Files\eSyndicate\esyn.dll

    O2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\Jodi Koch\Local Settings\Temp\yBV.dll

    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER

    O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe

    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe

    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"

    O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"

    O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe

    O4 - HKLM\..\Run: [share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe

    O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe

    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

    O4 - HKLM\..\RunOnce: [*olecat] C:\WINDOWS\security\Database\olecat.exe rerun

    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

    O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl

    O4 - HKCU\..\Run: [PopUpStopperCompanion] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSComp.exe"

    O4 - HKCU\..\Run: [ClockSync] C:\PROGRA~1\CLOCKS~1\Sync.exe /q

    O4 - HKCU\..\Run: [Tsa2] C:\PROGRA~1\COMMON~1\tsa\tsm2.exe

    O4 - HKCU\..\RunOnce: [*WinLogon] C:\WINDOWS\system32\ICSXML\inetmp3.exe ren time:1103658999

    O4 - Global Startup: Digital Line Detect.lnk = ?

    O4 - Global Startup: HPAiODevice(hp officejet d series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exe

    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe

    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll

    O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

    O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

    O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://us.games2.yimg.com/download.games.y...ctl_0_0_0_1.ocx

    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab

    O16 - DPF: {CFCB7308-782F-11D4-BE27-000102598CE4} (NPX Control) - http://kr.pristontale.com/nprotect/nprotect/npx.cab

    O23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exe

    O23 - Service: McAfee.com VirusScan Online Realtime Engine - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe

    O23 - Service: IntelĀ® NMS - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe

    O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

  7. One more time...I hope...

    Logfile of HijackThis v1.99.0

    Scan saved at 8:46:27 PM, on 12/23/2004

    Platform: Windows XP SP1 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\system32\cisvc.exe

    c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe

    C:\WINDOWS\System32\nvsvc32.exe

    C:\WINDOWS\System32\svchost.exe

    c:\PROGRA~1\mcafee.com\vso\mcshield.exe

    C:\WINDOWS\System32\wuauclt.exe

    C:\WINDOWS\Explorer.EXE

    C:\Program Files\Real\RealPlayer\RealPlay.exe

    C:\Program Files\McAfee.com\Agent\mcagent.exe

    C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe

    C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe

    C:\Program Files\Common Files\Dell\EUSW\Support.exe

    C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe

    C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe

    C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe

    C:\WINDOWS\System32\wuauclt.exe

    C:\docume~1\chrisk~1\locals~1\temp\yWY.exe

    C:\documents and settings\chris koch\local settings\temp\ZeX69Fea.exe

    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe

    C:\WINDOWS\System32\d3detobj.exe

    C:\windows\8ScUs5OP.exe

    C:\windows\x.exe

    C:\Program Files\Messenger\msmsgs.exe

    C:\Program Files\AIM95\aim.exe

    C:\Program Files\Digital Line Detect\DLG.exe

    C:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exe

    C:\WINDOWS\Tasks\vbexp.exe

    C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe

    C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe

    C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe

    C:\Documents and Settings\Jodi Koch\Desktop\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.longnet.net/login.asp

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - (no file)

    O1 - Hosts: com

    O1 - Hosts: nu.com

    O1 - Hosts: nu.com

    O1 - Hosts: enu.com

    O1 - Hosts: enu.com

    O1 - Hosts: henu.com

    O1 - Hosts: henu.com

    O1 - Hosts: .whenu.com

    O1 - Hosts: .whenu.com

    O1 - Hosts: c.whenu.com

    O1 - Hosts: c.whenu.com

    O1 - Hosts: nc.whenu.com

    O1 - Hosts: nc.whenu.com

    O2 - BHO: (no name) - SOFTWARE - (no file)

    O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:\Program Files\CxtPls\cxtpls.dll

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

    O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll

    O2 - BHO: CATLEvents Object - {3EC8E271-FAB9-418a-8A8E-65AEB4029E64} - C:\DOCUME~1\CHRISK~1\LOCALS~1\Temp\rvskab.dat

    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

    O2 - BHO: (no name) - {72AC6865-B1D3-4C32-A27B-4B3BF04DE655} - (no file)

    O2 - BHO: CATLEvents Object - {8109AF33-6949-4833-8881-43DCC232B7B2} - C:\DOCUME~1\CHRISK~1\LOCALS~1\Temp\rvskab.dat

    O2 - BHO: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)

    O2 - BHO: (no name) - {C69FA570-7FDE-4C49-A7BC-CB1CF24BE66B} - (no file)

    O2 - BHO: Band Class - {CC378B83-9577-44D0-B4F8-0DD965E176FC} - C:\Program Files\eSyndicate\esyn.dll

    O2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\Jodi Koch\Local Settings\Temp\HcpUW6Kh.dll

    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER

    O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe

    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe

    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"

    O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"

    O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe

    O4 - HKLM\..\Run: [share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe

    O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe

    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

    O4 - HKLM\..\Run: [dpf0WR] C:\docume~1\chrisk~1\locals~1\temp\dpf0WR.exe

    O4 - HKLM\..\Run: [yWY] C:\docume~1\chrisk~1\locals~1\temp\yWY.exe

    O4 - HKLM\..\Run: [ZeX69Fea] C:\documents and settings\chris koch\local settings\temp\ZeX69Fea.exe

    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe

    O4 - HKLM\..\Run: [*cabole] C:\WINDOWS\AppPatch\cabole.exe

    O4 - HKLM\..\Run: [*wmsac] C:\WINDOWS\system\wmsac.exe

    O4 - HKLM\..\Run: [*catwms] C:\WINDOWS\Microsoft.NET\catwms.exe

    O4 - HKLM\..\Run: [*antidoc] C:\WINDOWS\msagent\CHARS\antidoc.exe

    O4 - HKLM\..\Run: [*dllc] C:\WINDOWS\Registration\dllc.exe

    O4 - HKLM\..\Run: [*ipabr] C:\WINDOWS\ipabr.exe

    O4 - HKLM\..\Run: [*svcinet] C:\WINDOWS\system\svcinet.exe

    O4 - HKLM\..\Run: [*pcwave] C:\WINDOWS\assembly\temp\pcwave.exe

    O4 - HKLM\..\Run: [*libexp] C:\WINDOWS\Cursors\libexp.exe

    O4 - HKLM\..\Run: [*adcom] C:\WINDOWS\addins\adcom.exe

    O4 - HKLM\..\Run: [vs9k3EO] d3detobj.exe

    O4 - HKLM\..\Run: [*mfcftp] C:\WINDOWS\system32\CatRoot2\mfcftp.exe

    O4 - HKLM\..\Run: [*binole] C:\WINDOWS\Registration\binole.exe

    O4 - HKLM\..\Run: [8ScUs5OP] C:\windows\8ScUs5OP.exe

    O4 - HKLM\..\Run: [x] C:\windows\x.exe

    O4 - HKLM\..\RunOnce: [*ftpcr] C:\WINDOWS\ServicePackFiles\ftpcr.exe rerun

    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

    O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl

    O4 - HKCU\..\Run: [PopUpStopperCompanion] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSComp.exe"

    O4 - HKCU\..\Run: [ClockSync] C:\PROGRA~1\CLOCKS~1\Sync.exe /q

    O4 - HKCU\..\Run: [Tsa2] C:\PROGRA~1\COMMON~1\tsa\tsm2.exe

    O4 - HKCU\..\RunOnce: [*WinLogon] C:\WINDOWS\Tasks\vbexp.exe ren time:1103658999

    O4 - Global Startup: Digital Line Detect.lnk = ?

    O4 - Global Startup: HPAiODevice(hp officejet d series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exe

    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe

    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll

    O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://us.games2.yimg.com/download.games.y...ctl_0_0_0_1.ocx

    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab

    O16 - DPF: {CFCB7308-782F-11D4-BE27-000102598CE4} (NPX Control) - http://kr.pristontale.com/nprotect/nprotect/npx.cab

    O23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exe

    O23 - Service: McAfee.com VirusScan Online Realtime Engine - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe

    O23 - Service: IntelĀ® NMS - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe

    O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

    -gimp

  8. Alright, ran housecall, it killed 37 trojans. :-x Here's the log.

    Logfile of HijackThis v1.99.0

    Scan saved at 8:36:31 PM, on 12/23/2004

    Platform: Windows XP SP1 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\system32\cisvc.exe

    c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe

    C:\WINDOWS\System32\nvsvc32.exe

    C:\WINDOWS\System32\svchost.exe

    c:\PROGRA~1\mcafee.com\vso\mcshield.exe

    C:\WINDOWS\system32\cidaemon.exe

    C:\WINDOWS\system32\cidaemon.exe

    C:\Program Files\Real\RealPlayer\RealPlay.exe

    C:\Program Files\McAfee.com\Agent\mcagent.exe

    C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe

    C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe

    C:\Program Files\Common Files\Dell\EUSW\Support.exe

    C:\WINDOWS\System32\wuauclt.exe

    C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe

    C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe

    C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe

    C:\docume~1\chrisk~1\locals~1\temp\dpf0WR.exe

    C:\docume~1\chrisk~1\locals~1\temp\yWY.exe

    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe

    C:\WINDOWS\System32\d3detobj.exe

    C:\Program Files\Messenger\msmsgs.exe

    C:\Program Files\AIM95\aim.exe

    C:\Program Files\Digital Line Detect\DLG.exe

    C:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exe

    C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe

    c:\windows\8ScUs5OP.exe

    C:\WINDOWS\Tasks\pcav.exe

    C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe

    C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe

    c:\windows\x.exe

    C:\Program Files\CxtPls\CxtPls.exe

    C:\Program Files\Internet Explorer\IEXPLORE.EXE

    C:\WINDOWS\explorer.exe

    C:\Documents and Settings\Jodi Koch\Desktop\HijackThis.exe

    C:\WINDOWS\system\svrwin.exe

    F:\Programs\Misc\TinyIRC\TinyIRC.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.longnet.net/login.asp

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - (no file)

    O1 - Hosts: com

    O1 - Hosts: nu.com

    O1 - Hosts: nu.com

    O1 - Hosts: enu.com

    O1 - Hosts: enu.com

    O1 - Hosts: henu.com

    O1 - Hosts: henu.com

    O1 - Hosts: .whenu.com

    O1 - Hosts: .whenu.com

    O1 - Hosts: c.whenu.com

    O1 - Hosts: c.whenu.com

    O1 - Hosts: nc.whenu.com

    O1 - Hosts: nc.whenu.com

    O2 - BHO: (no name) - SOFTWARE - (no file)

    O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:\Program Files\CxtPls\cxtpls.dll

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

    O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll

    O2 - BHO: CATLEvents Object - {3EC8E271-FAB9-418a-8A8E-65AEB4029E64} - C:\DOCUME~1\CHRISK~1\LOCALS~1\Temp\rvskab.dat

    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

    O2 - BHO: (no name) - {72AC6865-B1D3-4C32-A27B-4B3BF04DE655} - (no file)

    O2 - BHO: CATLEvents Object - {8109AF33-6949-4833-8881-43DCC232B7B2} - C:\DOCUME~1\CHRISK~1\LOCALS~1\Temp\rvskab.dat

    O2 - BHO: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)

    O2 - BHO: (no name) - {C69FA570-7FDE-4C49-A7BC-CB1CF24BE66B} - (no file)

    O2 - BHO: Band Class - {CC378B83-9577-44D0-B4F8-0DD965E176FC} - C:\Program Files\eSyndicate\esyn.dll

    O2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\Jodi Koch\Local Settings\Temp\98Z6LTm.dll

    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER

    O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe

    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe

    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"

    O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"

    O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe

    O4 - HKLM\..\Run: [share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe

    O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe

    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

    O4 - HKLM\..\Run: [dpf0WR] C:\docume~1\chrisk~1\locals~1\temp\dpf0WR.exe

    O4 - HKLM\..\Run: [yWY] C:\docume~1\chrisk~1\locals~1\temp\yWY.exe

    O4 - HKLM\..\Run: [ZeX69Fea] C:\documents and settings\chris koch\local settings\temp\ZeX69Fea.exe

    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe

    O4 - HKLM\..\Run: [*cabole] C:\WINDOWS\AppPatch\cabole.exe

    O4 - HKLM\..\Run: [*wmsac] C:\WINDOWS\system\wmsac.exe

    O4 - HKLM\..\Run: [*catwms] C:\WINDOWS\Microsoft.NET\catwms.exe

    O4 - HKLM\..\Run: [*antidoc] C:\WINDOWS\msagent\CHARS\antidoc.exe

    O4 - HKLM\..\Run: [*dllc] C:\WINDOWS\Registration\dllc.exe

    O4 - HKLM\..\Run: [*ipabr] C:\WINDOWS\ipabr.exe

    O4 - HKLM\..\Run: [*svcinet] C:\WINDOWS\system\svcinet.exe

    O4 - HKLM\..\Run: [*pcwave] C:\WINDOWS\assembly\temp\pcwave.exe

    O4 - HKLM\..\Run: [*libexp] C:\WINDOWS\Cursors\libexp.exe

    O4 - HKLM\..\Run: [*adcom] C:\WINDOWS\addins\adcom.exe

    O4 - HKLM\..\Run: [vs9k3EO] d3detobj.exe

    O4 - HKLM\..\Run: [*mfcftp] C:\WINDOWS\system32\CatRoot2\mfcftp.exe

    O4 - HKLM\..\Run: [*binole] C:\WINDOWS\Registration\binole.exe

    O4 - HKLM\..\Run: [8ScUs5OP] c:\windows\8ScUs5OP.exe

    O4 - HKLM\..\Run: [x] c:\windows\x.exe

    O4 - HKLM\..\RunOnce: [*pcwave] C:\WINDOWS\assembly\temp\pcwave.exe rerun

    O4 - HKLM\..\RunOnce: [*mfcftp] C:\WINDOWS\system32\CatRoot2\mfcftp.exe rerun

    O4 - HKLM\..\RunOnce: [*binole] C:\WINDOWS\Registration\binole.exe rerun

    O4 - HKLM\..\RunOnce: [*adcom] C:\WINDOWS\addins\adcom.exe rerun

    O4 - HKLM\..\RunOnce: [*libexp] C:\WINDOWS\Cursors\libexp.exe rerun

    O4 - HKLM\..\RunOnce: [*wmsinet] C:\WINDOWS\Config\wmsinet.exe rerun

    O4 - HKLM\..\RunOnce: [*faxlog] C:\WINDOWS\assembly\temp\faxlog.exe rerun

    O4 - HKLM\..\RunOnce: [*vgakb] C:\WINDOWS\Microsoft.NET\vgakb.exe rerun

    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

    O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl

    O4 - HKCU\..\Run: [PopUpStopperCompanion] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSComp.exe"

    O4 - HKCU\..\Run: [ClockSync] C:\PROGRA~1\CLOCKS~1\Sync.exe /q

    O4 - HKCU\..\Run: [Tsa2] C:\PROGRA~1\COMMON~1\tsa\tsm2.exe

    O4 - HKCU\..\RunOnce: [*WinLogon] C:\WINDOWS\system\svrwin.exe ren time:1103658999

    O4 - Global Startup: Digital Line Detect.lnk = ?

    O4 - Global Startup: HPAiODevice(hp officejet d series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exe

    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe

    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll

    O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://us.games2.yimg.com/download.games.y...ctl_0_0_0_1.ocx

    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab

    O16 - DPF: {CFCB7308-782F-11D4-BE27-000102598CE4} (NPX Control) - http://kr.pristontale.com/nprotect/nprotect/npx.cab

    O23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exe

    O23 - Service: McAfee.com VirusScan Online Realtime Engine - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe

    O23 - Service: IntelĀ® NMS - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe

    O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

    -gimp

  9. Alright heres another, note: the longnet stuff is ok, it's for long reality where she works. Thanks again.

    Logfile of HijackThis v1.99.0

    Scan saved at 7:59:33 PM, on 12/23/2004

    Platform: Windows XP SP1 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\system32\cisvc.exe

    c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe

    C:\WINDOWS\System32\nvsvc32.exe

    C:\WINDOWS\System32\svchost.exe

    c:\PROGRA~1\mcafee.com\vso\mcshield.exe

    C:\WINDOWS\system32\cidaemon.exe

    C:\WINDOWS\system32\cidaemon.exe

    C:\Program Files\Real\RealPlayer\RealPlay.exe

    C:\Program Files\McAfee.com\Agent\mcagent.exe

    C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe

    C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe

    C:\Program Files\Common Files\Dell\EUSW\Support.exe

    C:\WINDOWS\System32\wuauclt.exe

    C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe

    C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe

    C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe

    C:\docume~1\chrisk~1\locals~1\temp\dpf0WR.exe

    C:\docume~1\chrisk~1\locals~1\temp\yWY.exe

    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe

    C:\WINDOWS\System32\d3detobj.exe

    C:\Program Files\Messenger\msmsgs.exe

    C:\Program Files\AIM95\aim.exe

    C:\PROGRA~1\COMMON~1\tsa\tsm2.exe

    C:\Program Files\Digital Line Detect\DLG.exe

    C:\PROGRA~1\COMMON~1\tsa\ts2.exe

    C:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exe

    C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe

    c:\windows\8ScUs5OP.exe

    C:\WINDOWS\Tasks\pcav.exe

    C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe

    C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe

    c:\windows\x.exe

    C:\Program Files\CxtPls\CxtPls.exe

    C:\Program Files\Internet Explorer\IEXPLORE.EXE

    C:\WINDOWS\explorer.exe

    C:\Documents and Settings\Jodi Koch\Desktop\HijackThis.exe

    C:\WINDOWS\system\svrwin.exe

    F:\Programs\Misc\TinyIRC\TinyIRC.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.longnet.net/login.asp

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - (no file)

    O1 - Hosts: com

    O1 - Hosts: nu.com

    O1 - Hosts: nu.com

    O1 - Hosts: enu.com

    O1 - Hosts: enu.com

    O1 - Hosts: henu.com

    O1 - Hosts: henu.com

    O1 - Hosts: .whenu.com

    O1 - Hosts: .whenu.com

    O1 - Hosts: c.whenu.com

    O1 - Hosts: c.whenu.com

    O1 - Hosts: nc.whenu.com

    O1 - Hosts: nc.whenu.com

    O2 - BHO: (no name) - SOFTWARE - (no file)

    O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:\Program Files\CxtPls\cxtpls.dll

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

    O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll

    O2 - BHO: CATLEvents Object - {3EC8E271-FAB9-418a-8A8E-65AEB4029E64} - C:\DOCUME~1\CHRISK~1\LOCALS~1\Temp\rvskab.dat

    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

    O2 - BHO: (no name) - {72AC6865-B1D3-4C32-A27B-4B3BF04DE655} - (no file)

    O2 - BHO: CATLEvents Object - {8109AF33-6949-4833-8881-43DCC232B7B2} - C:\DOCUME~1\CHRISK~1\LOCALS~1\Temp\rvskab.dat

    O2 - BHO: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)

    O2 - BHO: (no name) - {C69FA570-7FDE-4C49-A7BC-CB1CF24BE66B} - (no file)

    O2 - BHO: Band Class - {CC378B83-9577-44D0-B4F8-0DD965E176FC} - C:\Program Files\eSyndicate\esyn.dll

    O2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\Jodi Koch\Local Settings\Temp\98Z6LTm.dll

    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER

    O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe

    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe

    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"

    O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"

    O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe

    O4 - HKLM\..\Run: [share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe

    O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe

    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

    O4 - HKLM\..\Run: [dpf0WR] C:\docume~1\chrisk~1\locals~1\temp\dpf0WR.exe

    O4 - HKLM\..\Run: [yWY] C:\docume~1\chrisk~1\locals~1\temp\yWY.exe

    O4 - HKLM\..\Run: [ZeX69Fea] C:\documents and settings\chris koch\local settings\temp\ZeX69Fea.exe

    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe

    O4 - HKLM\..\Run: [*cabole] C:\WINDOWS\AppPatch\cabole.exe

    O4 - HKLM\..\Run: [*wmsac] C:\WINDOWS\system\wmsac.exe

    O4 - HKLM\..\Run: [*catwms] C:\WINDOWS\Microsoft.NET\catwms.exe

    O4 - HKLM\..\Run: [*antidoc] C:\WINDOWS\msagent\CHARS\antidoc.exe

    O4 - HKLM\..\Run: [*dllc] C:\WINDOWS\Registration\dllc.exe

    O4 - HKLM\..\Run: [*ipabr] C:\WINDOWS\ipabr.exe

    O4 - HKLM\..\Run: [*svcinet] C:\WINDOWS\system\svcinet.exe

    O4 - HKLM\..\Run: [*pcwave] C:\WINDOWS\assembly\temp\pcwave.exe

    O4 - HKLM\..\Run: [*libexp] C:\WINDOWS\Cursors\libexp.exe

    O4 - HKLM\..\Run: [*adcom] C:\WINDOWS\addins\adcom.exe

    O4 - HKLM\..\Run: [vs9k3EO] d3detobj.exe

    O4 - HKLM\..\Run: [*mfcftp] C:\WINDOWS\system32\CatRoot2\mfcftp.exe

    O4 - HKLM\..\Run: [*binole] C:\WINDOWS\Registration\binole.exe

    O4 - HKLM\..\Run: [8ScUs5OP] c:\windows\8ScUs5OP.exe

    O4 - HKLM\..\Run: [x] c:\windows\x.exe

    O4 - HKLM\..\RunOnce: [*pcwave] C:\WINDOWS\assembly\temp\pcwave.exe rerun

    O4 - HKLM\..\RunOnce: [*mfcftp] C:\WINDOWS\system32\CatRoot2\mfcftp.exe rerun

    O4 - HKLM\..\RunOnce: [*binole] C:\WINDOWS\Registration\binole.exe rerun

    O4 - HKLM\..\RunOnce: [*adcom] C:\WINDOWS\addins\adcom.exe rerun

    O4 - HKLM\..\RunOnce: [*libexp] C:\WINDOWS\Cursors\libexp.exe rerun

    O4 - HKLM\..\RunOnce: [*wmsinet] C:\WINDOWS\Config\wmsinet.exe rerun

    O4 - HKLM\..\RunOnce: [*faxlog] C:\WINDOWS\assembly\temp\faxlog.exe rerun

    O4 - HKLM\..\RunOnce: [*vgakb] C:\WINDOWS\Microsoft.NET\vgakb.exe rerun

    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

    O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl

    O4 - HKCU\..\Run: [PopUpStopperCompanion] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSComp.exe"

    O4 - HKCU\..\Run: [ClockSync] C:\PROGRA~1\CLOCKS~1\Sync.exe /q

    O4 - HKCU\..\Run: [Tsa2] C:\PROGRA~1\COMMON~1\tsa\tsm2.exe

    O4 - HKCU\..\RunOnce: [*WinLogon] C:\WINDOWS\system\svrwin.exe ren time:1103658999

    O4 - Global Startup: Digital Line Detect.lnk = ?

    O4 - Global Startup: HPAiODevice(hp officejet d series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exe

    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe

    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll

    O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://us.games2.yimg.com/download.games.y...ctl_0_0_0_1.ocx

    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab

    O16 - DPF: {CFCB7308-782F-11D4-BE27-000102598CE4} (NPX Control) - http://kr.pristontale.com/nprotect/nprotect/npx.cab

    O23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exe

    O23 - Service: McAfee.com VirusScan Online Realtime Engine - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe

    O23 - Service: IntelĀ® NMS - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe

    O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

  10. I really need your help here guys. Please, read this log and tell me what to do. I won't be here all night, so, the sooner the better. Thanks.

    Logfile of HijackThis v1.99.0

    Scan saved at 7:29:11 PM, on 12/23/2004

    Platform: Windows XP SP1 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\system32\cisvc.exe

    c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe

    C:\WINDOWS\System32\nvsvc32.exe

    C:\WINDOWS\System32\svchost.exe

    c:\PROGRA~1\mcafee.com\vso\mcshield.exe

    C:\WINDOWS\system32\cidaemon.exe

    C:\WINDOWS\system32\cidaemon.exe

    C:\Program Files\Real\RealPlayer\RealPlay.exe

    C:\Program Files\McAfee.com\Agent\mcagent.exe

    C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe

    C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe

    C:\Program Files\Common Files\Dell\EUSW\Support.exe

    C:\WINDOWS\System32\wuauclt.exe

    C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe

    C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe

    C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe

    C:\docume~1\chrisk~1\locals~1\temp\dpf0WR.exe

    C:\docume~1\chrisk~1\locals~1\temp\yWY.exe

    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe

    C:\WINDOWS\System32\d3detobj.exe

    C:\Program Files\Messenger\msmsgs.exe

    C:\Program Files\AIM95\aim.exe

    C:\PROGRA~1\COMMON~1\tsa\tsm2.exe

    C:\Program Files\Digital Line Detect\DLG.exe

    C:\PROGRA~1\COMMON~1\tsa\ts2.exe

    C:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exe

    C:\WINDOWS\system\diskweb.exe

    C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe

    c:\windows\8ScUs5OP.exe

    C:\WINDOWS\Tasks\pcav.exe

    C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe

    C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe

    c:\windows\x.exe

    C:\Program Files\CxtPls\CxtPls.exe

    C:\Program Files\Internet Explorer\IEXPLORE.EXE

    C:\WINDOWS\explorer.exe

    C:\Documents and Settings\Jodi Koch\Desktop\HijackThis.exe

    C:\WINDOWS\system\svrwin.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.longnet.net/login.asp

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - (no file)

    O1 - Hosts: com

    O1 - Hosts: nu.com

    O1 - Hosts: nu.com

    O1 - Hosts: enu.com

    O1 - Hosts: enu.com

    O1 - Hosts: henu.com

    O1 - Hosts: henu.com

    O1 - Hosts: .whenu.com

    O1 - Hosts: .whenu.com

    O1 - Hosts: c.whenu.com

    O1 - Hosts: c.whenu.com

    O1 - Hosts: nc.whenu.com

    O1 - Hosts: nc.whenu.com

    O2 - BHO: (no name) - SOFTWARE - (no file)

    O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:\Program Files\CxtPls\cxtpls.dll

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

    O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll

    O2 - BHO: CATLEvents Object - {3EC8E271-FAB9-418a-8A8E-65AEB4029E64} - C:\DOCUME~1\CHRISK~1\LOCALS~1\Temp\rvskab.dat

    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

    O2 - BHO: (no name) - {72AC6865-B1D3-4C32-A27B-4B3BF04DE655} - (no file)

    O2 - BHO: CATLEvents Object - {8109AF33-6949-4833-8881-43DCC232B7B2} - C:\DOCUME~1\CHRISK~1\LOCALS~1\Temp\rvskab.dat

    O2 - BHO: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)

    O2 - BHO: (no name) - {C69FA570-7FDE-4C49-A7BC-CB1CF24BE66B} - (no file)

    O2 - BHO: Band Class - {CC378B83-9577-44D0-B4F8-0DD965E176FC} - C:\Program Files\eSyndicate\esyn.dll

    O2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\Jodi Koch\Local Settings\Temp\98Z6LTm.dll

    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER

    O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe

    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe

    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"

    O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"

    O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe

    O4 - HKLM\..\Run: [share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe

    O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe

    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

    O4 - HKLM\..\Run: [dpf0WR] C:\docume~1\chrisk~1\locals~1\temp\dpf0WR.exe

    O4 - HKLM\..\Run: [yWY] C:\docume~1\chrisk~1\locals~1\temp\yWY.exe

    O4 - HKLM\..\Run: [ZeX69Fea] C:\documents and settings\chris koch\local settings\temp\ZeX69Fea.exe

    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe

    O4 - HKLM\..\Run: [*cabole] C:\WINDOWS\AppPatch\cabole.exe

    O4 - HKLM\..\Run: [*wmsac] C:\WINDOWS\system\wmsac.exe

    O4 - HKLM\..\Run: [*catwms] C:\WINDOWS\Microsoft.NET\catwms.exe

    O4 - HKLM\..\Run: [*antidoc] C:\WINDOWS\msagent\CHARS\antidoc.exe

    O4 - HKLM\..\Run: [*dllc] C:\WINDOWS\Registration\dllc.exe

    O4 - HKLM\..\Run: [*ipabr] C:\WINDOWS\ipabr.exe

    O4 - HKLM\..\Run: [*svcinet] C:\WINDOWS\system\svcinet.exe

    O4 - HKLM\..\Run: [*faxcr] C:\WINDOWS\assembly\temp\faxcr.exe

    O4 - HKLM\..\Run: [*pcwave] C:\WINDOWS\assembly\temp\pcwave.exe

    O4 - HKLM\..\Run: [*libexp] C:\WINDOWS\Cursors\libexp.exe

    O4 - HKLM\..\Run: [*adcom] C:\WINDOWS\addins\adcom.exe

    O4 - HKLM\..\Run: [vs9k3EO] d3detobj.exe

    O4 - HKLM\..\Run: [*mfcftp] C:\WINDOWS\system32\CatRoot2\mfcftp.exe

    O4 - HKLM\..\Run: [*binole] C:\WINDOWS\Registration\binole.exe

    O4 - HKLM\..\Run: [8ScUs5OP] c:\windows\8ScUs5OP.exe

    O4 - HKLM\..\Run: [x] c:\windows\x.exe

    O4 - HKLM\..\RunOnce: [*pcwave] C:\WINDOWS\assembly\temp\pcwave.exe rerun

    O4 - HKLM\..\RunOnce: [*mfcftp] C:\WINDOWS\system32\CatRoot2\mfcftp.exe rerun

    O4 - HKLM\..\RunOnce: [*binole] C:\WINDOWS\Registration\binole.exe rerun

    O4 - HKLM\..\RunOnce: [*adcom] C:\WINDOWS\addins\adcom.exe rerun

    O4 - HKLM\..\RunOnce: [*libexp] C:\WINDOWS\Cursors\libexp.exe rerun

    O4 - HKLM\..\RunOnce: [*wmsinet] C:\WINDOWS\Config\wmsinet.exe rerun

    O4 - HKLM\..\RunOnce: [*faxlog] C:\WINDOWS\assembly\temp\faxlog.exe rerun

    O4 - HKLM\..\RunOnce: [*faxcr] C:\WINDOWS\assembly\temp\faxcr.exe rerun

    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

    O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl

    O4 - HKCU\..\Run: [PopUpStopperCompanion] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSComp.exe"

    O4 - HKCU\..\Run: [ClockSync] C:\PROGRA~1\CLOCKS~1\Sync.exe /q

    O4 - HKCU\..\Run: [Tsa2] C:\PROGRA~1\COMMON~1\tsa\tsm2.exe

    O4 - HKCU\..\RunOnce: [*WinLogon] C:\WINDOWS\system\svrwin.exe ren time:1103658999

    O4 - Global Startup: Digital Line Detect.lnk = ?

    O4 - Global Startup: HPAiODevice(hp officejet d series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exe

    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe

    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll

    O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://us.games2.yimg.com/download.games.y...ctl_0_0_0_1.ocx

    O16 - DPF: {CFCB7308-782F-11D4-BE27-000102598CE4} (NPX Control) - http://kr.pristontale.com/nprotect/nprotect/npx.cab

    O23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exe

    O23 - Service: McAfee.com VirusScan Online Realtime Engine - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe

    O23 - Service: IntelĀ® NMS - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe

    O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

    -gimp

  11. From everything I've heard from people, DSL is much better than satellite. Satellite there is much more lag (the signal has to go from your computer, to a satellite in space, to the server, back to the satellite and back to your computer) and the download and upload speeds are much slower if i'm not mistakin'. Not to mention, dsl is much, much more cheaper than satellite.

    -gimpi

  12. When you connect to the network, type the following into the status window:

    /mode <your nick> +x

    This will make it so that if someone does a /dns on you, they cannot get your ip address. If you use a perform script, you can simple add the line...

    /mode $me +x

    ...and it will do it everytime you connect to that network.

    -cory

  13. * DLLCompare Log version(1.0.0.125)

    Files Found that Windows does not See or cannot Access

    *Not everything listed here means you are infected!

    ________________________________________________

    C:\WINDOWS\SYSTEM32\mfc42d.dll Fri Jul 14 2000 11:00:00p A.SH. 929,844 908.05 K

    C:\WINDOWS\SYSTEM32\mfcn42d.dll Fri Jul 14 2000 11:00:00p A.SH. 41,013 40.05 K

    C:\WINDOWS\SYSTEM32\msvcrtd.dll Fri Jul 14 2000 11:00:00p A.SH. 434,252 424.07 K

    ________________________________________________

    1,329 items found: 1,329 files (3 H/S), 0 directories.

    Total of file sizes: 277,120,458 bytes 264.28 M

    Administrator Account = True

    AppInit_DLLs value = PAVWAIT.DLL (not hidden)

    --------------------End log---------------------

  14. next...

    Logfile of HijackThis v1.98.2

    Scan saved at 10:31:03 PM, on 10/30/2004

    Platform: Windows XP SP1 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\SYSTEM32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\Nhksrv.exe

    C:\PROGRA~1\Grisoft\AVG6\avgserv.exe

    C:\WINDOWS\SYSTEM32\CTsvcCDA.EXE

    C:\Program Files\Executive Software\DiskeeperLite\DKService.exe

    C:\WINDOWS\System32\nvsvc32.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\System32\MsPMSPSv.exe

    C:\WINDOWS\Explorer.EXE

    C:\Program Files\HP CD-DVD\Umbrella\DVDTray.exe

    C:\WINDOWS\System32\CTHELPER.EXE

    C:\Program Files\Common Files\Logitech\QCDriver2\LVCOMS.EXE

    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe

    C:\Program Files\MultiMedia Keyboard\MultiMedia Keyboard\1.1\KbdAp32A.exe

    C:\Program Files\Browser MOUSE\mouse32a.exe

    C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe

    C:\Program Files\Google\Gmail Notifier\G001-1.0.23.0\gnotify.exe

    C:\Program Files\Eraser\eraser.exe

    C:\Program Files\ConquerCam\ConquerCam.exe

    C:\Program Files\Pulse\Pulse.exe

    C:\Program Files\WinRoll\winroll.exe

    C:\Program Files\Gaim\gaim.exe

    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

    C:\Program Files\Coolmon\CoolMon.exe

    C:\Program Files\Sirus Pad\ShirusuPad\ShirusuPad.exe

    C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe

    C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe

    C:\Program Files\Mozilla Thunderbird\thunderbird.exe

    C:\Program Files\T Clock\tclock.exe

    C:\Program Files\Google\Google Desktop Search\GoogleDesktopOE.exe

    C:\Program Files\mIRC\mirc.exe

    C:\Program Files\Kerio\Personal Firewall 4\Kerio.exe

    C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe

    C:\Program Files\Mozilla Firefox\firefox.exe

    C:\Program Files\Hijack This\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.geekygimp.com/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

    O2 - BHO: Google Desktop Search Capture - {7c1ce531-09e9-4fc5-9803-1c2956615786} - C:\Program Files\Google\Google Desktop Search\GoogleDesktopIE.dll

    O2 - BHO: QuickSearch Search Bar - {82315A18-6CFB-44a7-BDFD-90E36537C252} - C:\Program Files\QuickSearch\QuickSearchBar1_27.dll

    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

    O3 - Toolbar: QuickSearch Search Bar - {82315A18-6CFB-44a7-BDFD-90E36537C252} - C:\Program Files\QuickSearch\QuickSearchBar1_27.dll

    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN

    O4 - HKLM\..\Run: [sysMetrix] C:\Program Files\SysMetrix\SysMetrix.exe

    O4 - HKLM\..\Run: [DVDBitSet] "C:\Program Files\HP CD-DVD\Umbrella\DVDBitSet.exe" /NOUI

    O4 - HKLM\..\Run: [DVDTray] "C:\Program Files\HP CD-DVD\Umbrella\DVDTray.exe

    O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE

    O4 - HKLM\..\Run: [updReg] C:\WINDOWS\UpdReg.EXE

    O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"

    O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run

    O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver2\LVCOMS.EXE

    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit

    O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe

    O4 - HKLM\..\Run: [LWBKEYBOARD] C:\Program Files\MultiMedia Keyboard\MultiMedia Keyboard\1.1\KbdAp32A.exe

    O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Browser MOUSE\mouse32a.exe

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP

    O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.23.0\gnotify.exe

    O4 - HKCU\..\Run: [sTYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide

    O4 - HKCU\..\Run: [Eraser] C:\Program Files\Eraser\eraser.exe -hide

    O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe

    O4 - HKCU\..\Run: [ConquerCam] C:\Program Files\ConquerCam\ConquerCam.exe /tray

    O4 - HKCU\..\Run: [Pulse] C:\Program Files\Pulse\Pulse.exe -splash

    O4 - HKCU\..\Run: [WinRoll] "C:\Program Files\WinRoll\winroll.exe"

    O4 - HKCU\..\Run: [shirusuPad] C:\Program Files\sticky\ShirusuPad\ShirusuPad.exe

    O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe

    O4 - HKCU\..\Run: [Gaim] C:\Program Files\Gaim\gaim.exe

    O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup

    O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian pr14\PeerGuardian_1.99b_pr14.exe

    O4 - Startup: CoolMon.lnk = C:\Program Files\Coolmon\CoolMon.exe

    O4 - Startup: SirusPad.lnk = C:\Program Files\Sirus Pad\ShirusuPad\ShirusuPad.exe

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll

    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll

    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll

    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

    O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

    O10 - Unknown file in Winsock LSP: c:\program files\google\google desktop search\googledesktopnetwork1.dll

    O10 - Unknown file in Winsock LSP: c:\program files\google\google desktop search\googledesktopnetwork1.dll

    O10 - Unknown file in Winsock LSP: c:\program files\google\google desktop search\googledesktopnetwork1.dll

    O10 - Unknown file in Winsock LSP: c:\program files\google\google desktop search\googledesktopnetwork1.dll

    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

    O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/12119/CTSUEng.cab

    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB

    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab30149.cab

    O16 - DPF: {31FD415A-1103-4329-B323-2DE693146C4E} (InstallHelper Class) - http://survey.prod.there.com/qualsurvey/Th...stallHelper.cab

    O16 - DPF: {50F65670-1729-11D2-A51F-0020AFE5D502} (ForumChat) - http://objects.compuserve.com/chat/RTCChat.cab

    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1095391470609

    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/bcd48c1...all/xscan53.cab

    O16 - DPF: {78960E0E-0B0C-11D4-8997-00104BD12D94} (AV Class) - http://www.pcpitstop.com/antivirus/PCPAV.CAB

    O16 - DPF: {7A32634B-029C-4836-A023-528983982A49} - http://fdl.msn.com/public/chat/msnchat42.cab

    O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab

    O16 - DPF: {88D8E8B7-A33B-4417-A385-8373484D43ED} (InstallHelper Class) - http://survey.prod.there.com/qualsurvey/Th...stallHelper.cab

    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab30149.cab

    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab

    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab

    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab

    O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/12119/CTPID.cab

    O20 - AppInit_DLLs: PAVWAIT.DLL

  15. Logfile of HijackThis v1.98.2

    Scan saved at 10:10:46 PM, on 10/30/2004

    Platform: Windows XP SP1 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\SYSTEM32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\Nhksrv.exe

    C:\PROGRA~1\Grisoft\AVG6\avgserv.exe

    C:\WINDOWS\SYSTEM32\CTsvcCDA.EXE

    C:\Program Files\Executive Software\DiskeeperLite\DKService.exe

    C:\WINDOWS\System32\nvsvc32.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\System32\MsPMSPSv.exe

    C:\WINDOWS\Explorer.EXE

    C:\Program Files\HP CD-DVD\Umbrella\DVDTray.exe

    C:\WINDOWS\System32\CTHELPER.EXE

    C:\Program Files\Common Files\Logitech\QCDriver2\LVCOMS.EXE

    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe

    C:\Program Files\MultiMedia Keyboard\MultiMedia Keyboard\1.1\KbdAp32A.exe

    C:\Program Files\Browser MOUSE\mouse32a.exe

    C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe

    C:\Program Files\Google\Gmail Notifier\G001-1.0.23.0\gnotify.exe

    C:\WINDOWS\System32\rundll32.exe

    C:\Program Files\Eraser\eraser.exe

    C:\Program Files\Pulse\Pulse.exe

    C:\Program Files\WinRoll\winroll.exe

    C:\Program Files\Gaim\gaim.exe

    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

    C:\Program Files\Coolmon\CoolMon.exe

    C:\Program Files\Sirus Pad\ShirusuPad\ShirusuPad.exe

    C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe

    C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe

    C:\Program Files\T Clock\tclock.exe

    C:\Program Files\Google\Google Desktop Search\GoogleDesktopOE.exe

    C:\Program Files\Mozilla Thunderbird\thunderbird.exe

    C:\Program Files\mIRC\mirc.exe

    C:\Program Files\Mozilla Firefox\firefox.exe

    C:\Program Files\Kerio\Personal Firewall 4\Kerio.exe

    C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe

    C:\Program Files\WinRAR\WinRAR.exe

    C:\DOCUME~1\Cory\LOCALS~1\Temp\Rar$EX00.016\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.geekygimp.com/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

    O2 - BHO: Google Desktop Search Capture - {7c1ce531-09e9-4fc5-9803-1c2956615786} - C:\Program Files\Google\Google Desktop Search\GoogleDesktopIE.dll

    O2 - BHO: QuickSearch Search Bar - {82315A18-6CFB-44a7-BDFD-90E36537C252} - C:\Program Files\QuickSearch\QuickSearchBar1_27.dll

    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

    O3 - Toolbar: QuickSearch Search Bar - {82315A18-6CFB-44a7-BDFD-90E36537C252} - C:\Program Files\QuickSearch\QuickSearchBar1_27.dll

    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN

    O4 - HKLM\..\Run: [sysMetrix] C:\Program Files\SysMetrix\SysMetrix.exe

    O4 - HKLM\..\Run: [DVDBitSet] "C:\Program Files\HP CD-DVD\Umbrella\DVDBitSet.exe" /NOUI

    O4 - HKLM\..\Run: [DVDTray] "C:\Program Files\HP CD-DVD\Umbrella\DVDTray.exe

    O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE

    O4 - HKLM\..\Run: [updReg] C:\WINDOWS\UpdReg.EXE

    O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"

    O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run

    O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver2\LVCOMS.EXE

    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit

    O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe

    O4 - HKLM\..\Run: [LWBKEYBOARD] C:\Program Files\MultiMedia Keyboard\MultiMedia Keyboard\1.1\KbdAp32A.exe

    O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Browser MOUSE\mouse32a.exe

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP

    O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.23.0\gnotify.exe

    O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s

    O4 - HKCU\..\Run: [sTYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide

    O4 - HKCU\..\Run: [Eraser] C:\Program Files\Eraser\eraser.exe -hide

    O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe

    O4 - HKCU\..\Run: [ConquerCam] C:\Program Files\ConquerCam\ConquerCam.exe /tray

    O4 - HKCU\..\Run: [Pulse] C:\Program Files\Pulse\Pulse.exe -splash

    O4 - HKCU\..\Run: [WinRoll] "C:\Program Files\WinRoll\winroll.exe"

    O4 - HKCU\..\Run: [shirusuPad] C:\Program Files\sticky\ShirusuPad\ShirusuPad.exe

    O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe

    O4 - HKCU\..\Run: [Gaim] C:\Program Files\Gaim\gaim.exe

    O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup

    O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian pr14\PeerGuardian_1.99b_pr14.exe

    O4 - Startup: CoolMon.lnk = C:\Program Files\Coolmon\CoolMon.exe

    O4 - Startup: SirusPad.lnk = C:\Program Files\Sirus Pad\ShirusuPad\ShirusuPad.exe

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll

    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll

    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll

    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

    O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

    O10 - Unknown file in Winsock LSP: c:\program files\google\google desktop search\googledesktopnetwork1.dll

    O10 - Unknown file in Winsock LSP: c:\program files\google\google desktop search\googledesktopnetwork1.dll

    O10 - Unknown file in Winsock LSP: c:\program files\google\google desktop search\googledesktopnetwork1.dll

    O10 - Unknown file in Winsock LSP: c:\program files\google\google desktop search\googledesktopnetwork1.dll

    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

    O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/12119/CTSUEng.cab

    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB

    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab30149.cab

    O16 - DPF: {31FD415A-1103-4329-B323-2DE693146C4E} (InstallHelper Class) - http://survey.prod.there.com/qualsurvey/Th...stallHelper.cab

    O16 - DPF: {50F65670-1729-11D2-A51F-0020AFE5D502} (ForumChat) - http://objects.compuserve.com/chat/RTCChat.cab

    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1095391470609

    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/bcd48c1...all/xscan53.cab

    O16 - DPF: {78960E0E-0B0C-11D4-8997-00104BD12D94} (AV Class) - http://www.pcpitstop.com/antivirus/PCPAV.CAB

    O16 - DPF: {7A32634B-029C-4836-A023-528983982A49} - http://fdl.msn.com/public/chat/msnchat42.cab

    O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab

    O16 - DPF: {88D8E8B7-A33B-4417-A385-8373484D43ED} (InstallHelper Class) - http://survey.prod.there.com/qualsurvey/Th...stallHelper.cab

    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab30149.cab

    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab

    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab

    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab

    O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/12119/CTPID.cab

    O20 - AppInit_DLLs: PAVWAIT.DLL

  16. Thanks. :-)

    Logfile of HijackThis v1.97.7

    Scan saved at 10:07:41 PM, on 10/30/2004

    Platform: Windows XP SP1 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\SYSTEM32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\Nhksrv.exe

    C:\PROGRA~1\Grisoft\AVG6\avgserv.exe

    C:\WINDOWS\SYSTEM32\CTsvcCDA.EXE

    C:\Program Files\Executive Software\DiskeeperLite\DKService.exe

    C:\WINDOWS\System32\nvsvc32.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\System32\MsPMSPSv.exe

    C:\WINDOWS\Explorer.EXE

    C:\Program Files\HP CD-DVD\Umbrella\DVDTray.exe

    C:\WINDOWS\System32\CTHELPER.EXE

    C:\Program Files\Common Files\Logitech\QCDriver2\LVCOMS.EXE

    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe

    C:\Program Files\MultiMedia Keyboard\MultiMedia Keyboard\1.1\KbdAp32A.exe

    C:\Program Files\Browser MOUSE\mouse32a.exe

    C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe

    C:\Program Files\Google\Gmail Notifier\G001-1.0.23.0\gnotify.exe

    C:\WINDOWS\System32\rundll32.exe

    C:\Program Files\Eraser\eraser.exe

    C:\Program Files\Pulse\Pulse.exe

    C:\Program Files\WinRoll\winroll.exe

    C:\Program Files\Gaim\gaim.exe

    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

    C:\Program Files\Coolmon\CoolMon.exe

    C:\Program Files\Sirus Pad\ShirusuPad\ShirusuPad.exe

    C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe

    C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe

    C:\Program Files\T Clock\tclock.exe

    C:\Program Files\Google\Google Desktop Search\GoogleDesktopOE.exe

    C:\Program Files\Mozilla Thunderbird\thunderbird.exe

    C:\Program Files\mIRC\mirc.exe

    C:\Program Files\Mozilla Firefox\firefox.exe

    C:\Program Files\Kerio\Personal Firewall 4\Kerio.exe

    C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe

    C:\Program Files\Hijack This\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.geekygimp.com/

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

    O2 - BHO: Google Desktop Search Capture - {7c1ce531-09e9-4fc5-9803-1c2956615786} - C:\Program Files\Google\Google Desktop Search\GoogleDesktopIE.dll

    O2 - BHO: (no name) - {82315A18-6CFB-44a7-BDFD-90E36537C252} - C:\Program Files\QuickSearch\QuickSearchBar1_27.dll

    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

    O3 - Toolbar: QuickSearch Search Bar - {82315A18-6CFB-44a7-BDFD-90E36537C252} - C:\Program Files\QuickSearch\QuickSearchBar1_27.dll

    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN

    O4 - HKLM\..\Run: [sysMetrix] C:\Program Files\SysMetrix\SysMetrix.exe

    O4 - HKLM\..\Run: [DVDBitSet] "C:\Program Files\HP CD-DVD\Umbrella\DVDBitSet.exe" /NOUI

    O4 - HKLM\..\Run: [DVDTray] "C:\Program Files\HP CD-DVD\Umbrella\DVDTray.exe

    O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE

    O4 - HKLM\..\Run: [updReg] C:\WINDOWS\UpdReg.EXE

    O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"

    O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run

    O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver2\LVCOMS.EXE

    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit

    O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe

    O4 - HKLM\..\Run: [LWBKEYBOARD] C:\Program Files\MultiMedia Keyboard\MultiMedia Keyboard\1.1\KbdAp32A.exe

    O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Browser MOUSE\mouse32a.exe

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP

    O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.23.0\gnotify.exe

    O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s

    O4 - HKCU\..\Run: [sTYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide

    O4 - HKCU\..\Run: [Eraser] C:\Program Files\Eraser\eraser.exe -hide

    O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe

    O4 - HKCU\..\Run: [ConquerCam] C:\Program Files\ConquerCam\ConquerCam.exe /tray

    O4 - HKCU\..\Run: [Pulse] C:\Program Files\Pulse\Pulse.exe -splash

    O4 - HKCU\..\Run: [WinRoll] "C:\Program Files\WinRoll\winroll.exe"

    O4 - HKCU\..\Run: [shirusuPad] C:\Program Files\sticky\ShirusuPad\ShirusuPad.exe

    O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe

    O4 - HKCU\..\Run: [Gaim] C:\Program Files\Gaim\gaim.exe

    O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup

    O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian pr14\PeerGuardian_1.99b_pr14.exe

    O4 - Startup: CoolMon.lnk = C:\Program Files\Coolmon\CoolMon.exe

    O4 - Startup: SirusPad.lnk = C:\Program Files\Sirus Pad\ShirusuPad\ShirusuPad.exe

    O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)

    O9 - Extra button: PartyPoker.com (HKLM)

    O9 - Extra 'Tools' menuitem: PartyPoker.com (HKLM)

    O9 - Extra button: Messenger (HKLM)

    O9 - Extra 'Tools' menuitem: Messenger (HKLM)

    O10 - Unknown file in Winsock LSP: c:\program files\google\google desktop search\googledesktopnetwork1.dll

    O10 - Unknown file in Winsock LSP: c:\program files\google\google desktop search\googledesktopnetwork1.dll

    O10 - Unknown file in Winsock LSP: c:\program files\google\google desktop search\googledesktopnetwork1.dll

    O10 - Unknown file in Winsock LSP: c:\program files\google\google desktop search\googledesktopnetwork1.dll

    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

    O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/12119/CTSUEng.cab

    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB

    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab30149.cab

    O16 - DPF: {31FD415A-1103-4329-B323-2DE693146C4E} (InstallHelper Class) - http://survey.prod.there.com/qualsurvey/Th...stallHelper.cab

    O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6...922/wmv9VCM.CAB

    O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab

    O16 - DPF: {50F65670-1729-11D2-A51F-0020AFE5D502} (ForumChat) - http://objects.compuserve.com/chat/RTCChat.cab

    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1095391470609

    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/bcd48c1...all/xscan53.cab

    O16 - DPF: {78960E0E-0B0C-11D4-8997-00104BD12D94} (AV Class) - http://www.pcpitstop.com/antivirus/PCPAV.CAB

    O16 - DPF: {7A32634B-029C-4836-A023-528983982A49} - http://fdl.msn.com/public/chat/msnchat42.cab

    O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab

    O16 - DPF: {88D8E8B7-A33B-4417-A385-8373484D43ED} (InstallHelper Class) - http://survey.prod.there.com/qualsurvey/Th...stallHelper.cab

    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab30149.cab

    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab

    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - http://v4.windowsupdate.microsoft.com/CAB/...7898.6881018519

    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab

    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab

    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab

    O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/12119/CTPID.cab