wilbertneedhelp
Gebruiker
- Lid geworden
- 1 apr 2004
- Berichten
- 171
Logfile of HijackThis v1.98.2
Scan saved at 15:55:46, on 8-12-2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Stardock\SDMCP.exe
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe
C:\WINDOWS\SYSTEM32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Wilbert\Application Data\ora?y.exe
C:\Program Files\Webshots\WebshotsTray.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\AvidSDMService.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\odcfg.exe
C:\WINDOWS\System32\getdns.exe
C:\Program Files\GameSpy Arcade\aphex.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
F:\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = http://fastsearchweb.com/srh.php?q=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.gxzvawbhmwckwzreaib.com/...JvC9dTLzmralyfRS890FOKHgOkidUoF3lQB/TuGc8.jpg
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.fyiyoeiqfnnihchiqrhpp.us/rPIzSwPORzTtxXvhhXas7HuCGyfL943eM7_Yl0Xvu6g.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Richfind - {9A32764D-C423-425F-8F25-B3EA46D6843E} - C:\WINDOWS\System32\Q736781.dll
R3 - URLSearchHook: Richfind - {FD2D30F5-1896-4CA7-9CFF-211D65623C17} - C:\WINDOWS\System32\Q736781.dll
R3 - URLSearchHook: Richfind - {9E03FA62-E8B6-4D79-BF35-511EE6FC24D0} - C:\WINDOWS\System32\Q736781.dll
R3 - URLSearchHook: Richfind - {BCE951DB-8285-41F0-AF88-402C467F6AFB} - C:\WINDOWS\System32\Q777500.dll
R3 - URLSearchHook: Richfind - {2E5ADE04-A5B8-4BCA-AEDD-98B75EBB49CB} - C:\WINDOWS\System32\Q775250.dll
O2 - BHO: Richfind - {3FCBF801-5694-4ED6-8E83-064300C3F4C7} - C:\WINDOWS\System32\Q775250.dll
O2 - BHO: Richfind - {7BDDDDAE-AFB1-4285-A489-F84A28982996} - C:\WINDOWS\System32\Q777500.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: FreshBar - {06ABAA2D-34AB-4902-A326-409BD9B9A7A5} - C:\WINDOWS\System32\iecust.dll
O3 - Toolbar: Richfind - {E6D743B9-CA38-45D3-A232-033AF10B9B47} - C:\WINDOWS\System32\Q736781.dll
O3 - Toolbar: Richfind - {0970B2D7-A87B-49DF-8F23-D2BAEF1BEAC4} - C:\WINDOWS\System32\Q736781.dll
O3 - Toolbar: Richfind - {A72AFC57-1212-46DA-83F7-BCBEA65E4786} - C:\WINDOWS\System32\Q736781.dll
O3 - Toolbar: Richfind - {856355B9-1800-4D72-92B0-31A91E751A9C} - C:\WINDOWS\System32\Q777500.dll
O3 - Toolbar: Richfind - {C54BC0AC-5486-4684-8E68-C827BF6BE3FE} - C:\WINDOWS\System32\Q775250.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [7xcQjq] C:\documents and settings\wilbert\local settings\temp\7xcQjq.exe
O4 - HKLM\..\Run: [5tm] C:\documents and settings\wilbert\local settings\temp\5tm.exe
O4 - HKLM\..\Run: [p16qmu] C:\documents and settings\wilbert\local settings\temp\p16qmu.exe
O4 - HKLM\..\Run: [9e6df3b1f2f7] C:\WINDOWS\System32\authz342.exe
O4 - HKLM\..\Run: [5FHLPHD5C9Q8H6] C:\WINDOWS\System32\Eruz6x9.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Deaf Site] C:\DOCUME~1\Wilbert\APPLIC~1\ARMYNU~1\heckless.exe
O4 - HKCU\..\Run: [Tesr] C:\Documents and Settings\Wilbert\Application Data\ora?y.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
O4 - Startup: WKCALREM.LNK = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Richfind - {00000000-0000-0000-0000-000000000000} - (no file)
O9 - Extra button: Richfind - {0970B2D7-A87B-49DF-8F23-D2BAEF1BEAC4} - C:\WINDOWS\System32\Q736781.dll
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\maxspeed.exe
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\maxspeed.exe
O9 - Extra button: Richfind - {856355B9-1800-4D72-92B0-31A91E751A9C} - C:\WINDOWS\System32\Q777500.dll
O9 - Extra button: Richfind - {A72AFC57-1212-46DA-83F7-BCBEA65E4786} - C:\WINDOWS\System32\Q736781.dll
O9 - Extra button: Richfind - {C54BC0AC-5486-4684-8E68-C827BF6BE3FE} - C:\WINDOWS\System32\Q775250.dll
O9 - Extra button: Richfind - {E6D743B9-CA38-45D3-A232-033AF10B9B47} - C:\WINDOWS\System32\Q736781.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O15 - Trusted Zone: http://*.search-soft.net
O16 - DPF: {02C20140-76F8-4763-83D5-B660107B7A90} -
O16 - DPF: {11212111-2121-1311-1141-115611111222} - ms-its:mhtml:file://d: oo.mht!http://fastsearchweb.com/counter/new/x.chm::/update.exe
O16 - DPF: {14A3221B-1678-1982-A355-7263B1281987} - ms-its:mhtml:file://c:\nosuch.mht!http://www.awmdabest.com/bltd/572.chm::/file.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/1294dd5d94a9acbd9806/netzip/RdxIE601.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1100606398108
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab27513.cab
O16 - DPF: {E3E34A32-3A6A-47CC-B4E3-B8B86715D388} (MBoom Class) - http://pain.gamepoint.net/msn2/2003/ds/sintgame/marsepein/dll/boom.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll
O18 - Filter: text/html - {9B82B7B1-E38E-4CF3-9465-FFFB8E4D3536} - C:\WINDOWS\System32\Q775250.dll
O18 - Filter: text/plain - {9B82B7B1-E38E-4CF3-9465-FFFB8E4D3536} - C:\WINDOWS\System32\Q775250.dll
Scan saved at 15:55:46, on 8-12-2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Stardock\SDMCP.exe
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe
C:\WINDOWS\SYSTEM32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Wilbert\Application Data\ora?y.exe
C:\Program Files\Webshots\WebshotsTray.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\AvidSDMService.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\odcfg.exe
C:\WINDOWS\System32\getdns.exe
C:\Program Files\GameSpy Arcade\aphex.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
F:\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = http://fastsearchweb.com/srh.php?q=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.gxzvawbhmwckwzreaib.com/...JvC9dTLzmralyfRS890FOKHgOkidUoF3lQB/TuGc8.jpg
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.fyiyoeiqfnnihchiqrhpp.us/rPIzSwPORzTtxXvhhXas7HuCGyfL943eM7_Yl0Xvu6g.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Richfind - {9A32764D-C423-425F-8F25-B3EA46D6843E} - C:\WINDOWS\System32\Q736781.dll
R3 - URLSearchHook: Richfind - {FD2D30F5-1896-4CA7-9CFF-211D65623C17} - C:\WINDOWS\System32\Q736781.dll
R3 - URLSearchHook: Richfind - {9E03FA62-E8B6-4D79-BF35-511EE6FC24D0} - C:\WINDOWS\System32\Q736781.dll
R3 - URLSearchHook: Richfind - {BCE951DB-8285-41F0-AF88-402C467F6AFB} - C:\WINDOWS\System32\Q777500.dll
R3 - URLSearchHook: Richfind - {2E5ADE04-A5B8-4BCA-AEDD-98B75EBB49CB} - C:\WINDOWS\System32\Q775250.dll
O2 - BHO: Richfind - {3FCBF801-5694-4ED6-8E83-064300C3F4C7} - C:\WINDOWS\System32\Q775250.dll
O2 - BHO: Richfind - {7BDDDDAE-AFB1-4285-A489-F84A28982996} - C:\WINDOWS\System32\Q777500.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: FreshBar - {06ABAA2D-34AB-4902-A326-409BD9B9A7A5} - C:\WINDOWS\System32\iecust.dll
O3 - Toolbar: Richfind - {E6D743B9-CA38-45D3-A232-033AF10B9B47} - C:\WINDOWS\System32\Q736781.dll
O3 - Toolbar: Richfind - {0970B2D7-A87B-49DF-8F23-D2BAEF1BEAC4} - C:\WINDOWS\System32\Q736781.dll
O3 - Toolbar: Richfind - {A72AFC57-1212-46DA-83F7-BCBEA65E4786} - C:\WINDOWS\System32\Q736781.dll
O3 - Toolbar: Richfind - {856355B9-1800-4D72-92B0-31A91E751A9C} - C:\WINDOWS\System32\Q777500.dll
O3 - Toolbar: Richfind - {C54BC0AC-5486-4684-8E68-C827BF6BE3FE} - C:\WINDOWS\System32\Q775250.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [7xcQjq] C:\documents and settings\wilbert\local settings\temp\7xcQjq.exe
O4 - HKLM\..\Run: [5tm] C:\documents and settings\wilbert\local settings\temp\5tm.exe
O4 - HKLM\..\Run: [p16qmu] C:\documents and settings\wilbert\local settings\temp\p16qmu.exe
O4 - HKLM\..\Run: [9e6df3b1f2f7] C:\WINDOWS\System32\authz342.exe
O4 - HKLM\..\Run: [5FHLPHD5C9Q8H6] C:\WINDOWS\System32\Eruz6x9.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Deaf Site] C:\DOCUME~1\Wilbert\APPLIC~1\ARMYNU~1\heckless.exe
O4 - HKCU\..\Run: [Tesr] C:\Documents and Settings\Wilbert\Application Data\ora?y.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
O4 - Startup: WKCALREM.LNK = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Richfind - {00000000-0000-0000-0000-000000000000} - (no file)
O9 - Extra button: Richfind - {0970B2D7-A87B-49DF-8F23-D2BAEF1BEAC4} - C:\WINDOWS\System32\Q736781.dll
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\maxspeed.exe
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\maxspeed.exe
O9 - Extra button: Richfind - {856355B9-1800-4D72-92B0-31A91E751A9C} - C:\WINDOWS\System32\Q777500.dll
O9 - Extra button: Richfind - {A72AFC57-1212-46DA-83F7-BCBEA65E4786} - C:\WINDOWS\System32\Q736781.dll
O9 - Extra button: Richfind - {C54BC0AC-5486-4684-8E68-C827BF6BE3FE} - C:\WINDOWS\System32\Q775250.dll
O9 - Extra button: Richfind - {E6D743B9-CA38-45D3-A232-033AF10B9B47} - C:\WINDOWS\System32\Q736781.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O15 - Trusted Zone: http://*.search-soft.net
O16 - DPF: {02C20140-76F8-4763-83D5-B660107B7A90} -
O16 - DPF: {11212111-2121-1311-1141-115611111222} - ms-its:mhtml:file://d: oo.mht!http://fastsearchweb.com/counter/new/x.chm::/update.exe
O16 - DPF: {14A3221B-1678-1982-A355-7263B1281987} - ms-its:mhtml:file://c:\nosuch.mht!http://www.awmdabest.com/bltd/572.chm::/file.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/1294dd5d94a9acbd9806/netzip/RdxIE601.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1100606398108
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab27513.cab
O16 - DPF: {E3E34A32-3A6A-47CC-B4E3-B8B86715D388} (MBoom Class) - http://pain.gamepoint.net/msn2/2003/ds/sintgame/marsepein/dll/boom.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll
O18 - Filter: text/html - {9B82B7B1-E38E-4CF3-9465-FFFB8E4D3536} - C:\WINDOWS\System32\Q775250.dll
O18 - Filter: text/plain - {9B82B7B1-E38E-4CF3-9465-FFFB8E4D3536} - C:\WINDOWS\System32\Q775250.dll