Ok thanks for the help. Some of the files you told me "fix" werent there so im guessing theres no problem there. And also I was having some problems getting the internet running but its ok now. Which is why i took so long to responed >_<
But heres my new highjackthis log...
Logfile of HijackThis v1.99.1
Scan saved at 4:57:35 PM, on 2/21/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Kerio\Personal Firewall\persfw.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\sdkeu32.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\WINDOWS\system32\atlvc32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner\Desktop\Hijack\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\qgnwm.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\qgnwm.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\qgnwm.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\qgnwm.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\qgnwm.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\qgnwm.dll/sp.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\qgnwm.dll/sp.html#28129
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {04FA0937-0930-1006-31A1-535AEA9649FE} - C:\WINDOWS\netzh.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [Windows Registry Repair Pro] C:\Program Files\3B Software\Windows Registry Repair Pro\Windows Registry Repair Pro.exe -X
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [atlvc32.exe] C:\WINDOWS\system32\atlvc32.exe
O4 - HKLM\..\RunOnce: [sdkeu32.exe] C:\WINDOWS\system32\sdkeu32.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mp4: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
O12 - Plugin for .mpga: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.frame.crazywinnings.com
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O15 - Trusted IP range: 206.161.125.149
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/MsnMesse...pDownloader.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{90168CF9-AF3F-4537-9AE0-AE14D4AACAA3}: NameServer = 66.209.94.3 66.209.94.4
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Kerio Personal Firewall (PersFw) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall\persfw.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Network Security Service (%AF夶À¨) - Unknown owner - C:\WINDOWS\nsreg.dat:rxney.exe (file missing)
And heres my AboutBuster Log file...
Scanned at: 3:33:12 PM on: 2/21/2005
-- Scan 1 ---------------------------
About:Buster Version 4.0
Reference List : 19
Removed Data Streams:
C:\WINDOWS\JBKGLKOP.ini:pewvi
C:\WINDOWS\qool.exe:wzwtf
Removed 2 Random Key Entries
Removed! : C:\WINDOWS\jdsfd.dat
Removed! : C:\WINDOWS\lwqrh.dat
Removed! : C:\WINDOWS\vzvhe.dat
Removed! : C:\WINDOWS\xkzcw.dat
********************************
Removed sys\explorer.exe (fake)
********************************
-----------------------------
Removed! infected hosts file.
Attempted Clean Of Temp folder.
Removed Uninstall Key (HSA)
Removed Uninstall Key (SE)
Removed Uninstall Key (SW)
Pages Reset... Done!
-- Scan 2 ---------------------------
About:Buster Version 4.0
Reference List : 19
Removed Data Streams:
C:\WINDOWS\JBKGLKOP.ini:pewvi
C:\WINDOWS\qool.exe:wzwtf
Attempted Clean Of Temp folder.
Pages Reset... Done!
And heres my adsspy log...
C:\WINDOWS\BCMSMMSG.exe : mttqta (11592 bytes)
C:\WINDOWS\bisqb.txt : eumwnd (7471 bytes)
C:\WINDOWS\Blue Lace 16.bmp : oyeohg (10752 bytes)
C:\WINDOWS\Blue Lace 16.bmp : sxbcbx (11592 bytes)
C:\WINDOWS\bootstat.dat : cegrg (10752 bytes)
C:\WINDOWS\bootstat.dat : kcagkl (10752 bytes)
C:\WINDOWS\bootstat.dat : lptvog (10752 bytes)
C:\WINDOWS\cbecv.dll : fpiopd (10752 bytes)
C:\WINDOWS\clock.avi : hzxcbr (0 bytes)
C:\WINDOWS\clock.avi : kpupvz (7305 bytes)
C:\WINDOWS\clspack.exe : eiiyoz (10752 bytes)
C:\WINDOWS\clspack.exe : pvpojy (64000 bytes)
C:\WINDOWS\cmsetacl.log : yqttjn (29256 bytes)
C:\WINDOWS\Coffee Bean.bmp : eqmaqr (29696 bytes)
C:\WINDOWS\COM+.log : qmsmf (10752 bytes)
C:\WINDOWS\comsetup.log : cdllfn (29184 bytes)
C:\WINDOWS\comsetup.log : dqeuxk (3547 bytes)
C:\WINDOWS\comsetup.log : ialicx (11592 bytes)
C:\WINDOWS\comsetup.log : wjbmij (29256 bytes)
C:\WINDOWS\control.ini : angyjx (10752 bytes)
C:\WINDOWS\corelpf.lrs : dkeolj (10752 bytes)
C:\WINDOWS\corelpf.lrs : jmlsh (29696 bytes)
C:\WINDOWS\desktop.ini : sormdz (29184 bytes)
C:\WINDOWS\DtcInstall.log : gmkyu (29696 bytes)
C:\WINDOWS\DtcInstall.log : kttsso (29184 bytes)
C:\WINDOWS\DtcInstall.log : ynojw (96127 bytes)
C:\WINDOWS\dvyyi.dll : yrwpvq (29696 bytes)
C:\WINDOWS\EventSystem.log : syaesb (29696 bytes)
C:\WINDOWS\explorer.scf : mwuted (10752 bytes)
C:\WINDOWS\extrac32.exe : suosro (11592 bytes)
C:\WINDOWS\FaxSetup.log : xaehx (96477 bytes)
C:\WINDOWS\FeatherTexture.bmp : amkbjd (29256 bytes)
C:\WINDOWS\FeatherTexture.bmp : exeyyn (29256 bytes)
C:\WINDOWS\FeatherTexture.bmp : nbbeh (10752 bytes)
C:\WINDOWS\FeatherTexture.bmp : qmzwq (10752 bytes)
C:\WINDOWS\Greenstone.bmp : zcakhy (7305 bytes)
C:\WINDOWS\Greenstone.bmp : zjpty (29696 bytes)
C:\WINDOWS\gzsrk.dll : gxvvko (68096 bytes)
C:\WINDOWS\hatteo.dll : asqiy (10752 bytes)
C:\WINDOWS\hatteo.dll : ijcno (55808 bytes)
C:\WINDOWS\hatteo.dll : ydbvel (29184 bytes)
C:\WINDOWS\hpqEmlSz.INI : bqxhae (10752 bytes)
C:\WINDOWS\hpqEmlSz.INI : yxsiny (68096 bytes)
C:\WINDOWS\IE4 Error Log.txt : cddvdl (3547 bytes)
C:\WINDOWS\iis6.log : ltbau (29696 bytes)
C:\WINDOWS\iis6.log : zkfewy (29256 bytes)
C:\WINDOWS\irawn.dll : nqclhk (7305 bytes)
C:\WINDOWS\irawn.dll : rkqwsx (29184 bytes)
C:\WINDOWS\IsUninst.exe : luptut (10752 bytes)
C:\WINDOWS\jautoexp.dat : asxptu (11592 bytes)
C:\WINDOWS\javant.dll : fempsf (11592 bytes)
C:\WINDOWS\javant.dll : nsfsyy (29696 bytes)
C:\WINDOWS\javant.dll : wvserf (29256 bytes)
C:\WINDOWS\jkuxp.txt : dlizqh (7471 bytes)
C:\WINDOWS\jvime.log : ifpigs (7305 bytes)
C:\WINDOWS\KB828741.log : vmsnkr (3567 bytes)
C:\WINDOWS\KB835732.log : yyvulu (29256 bytes)
C:\WINDOWS\KB840987.log : aginjd (3567 bytes)
C:\WINDOWS\KB840987.log : onlsmu (64000 bytes)
C:\WINDOWS\KB841356.log : smuiw (96127 bytes)
C:\WINDOWS\KB841533.log : lilsyf (11591 bytes)
C:\WINDOWS\KB842773.log : thbtdn (68096 bytes)
C:\WINDOWS\KB871250.log : lnnny (10752 bytes)
C:\WINDOWS\KB873376.log : ejvysh (7305 bytes)
C:\WINDOWS\KB873376.log : qckmbr (11592 bytes)
C:\WINDOWS\KB885836.log : mcpmcp (10752 bytes)
C:\WINDOWS\KB888302.log : gpilp (29256 bytes)
C:\WINDOWS\KB888302.log : jbllu (96127 bytes)
C:\WINDOWS\KB890175.log : cbdro (10752 bytes)
C:\WINDOWS\KB891711.log : ebqlhu (10752 bytes)
C:\WINDOWS\mfckz.dll : exzqtz (68096 bytes)
C:\WINDOWS\msgsocm.log : huxru (96127 bytes)
C:\WINDOWS\msoffice.ini : jisbk (96477 bytes)
C:\WINDOWS\ntdtcsetup.log : rzruhw (29256 bytes)
C:\WINDOWS\ocgen.log : caxabh (11592 bytes)
C:\WINDOWS\ocgen.log : ckqylv (7305 bytes)
C:\WINDOWS\ocgen.log : dotpk (10752 bytes)
C:\WINDOWS\ocgen.log : ldfgul (10752 bytes)
C:\WINDOWS\ocgen.log : vnmjk (56320 bytes)
C:\WINDOWS\ocmsn.log : icaxpm (7305 bytes)
C:\WINDOWS\ocmsn.log : jiplbn (7305 bytes)
C:\WINDOWS\ocmsn.log : ujetg (10752 bytes)
C:\WINDOWS\ODBCINST.INI : bhnopg (10752 bytes)
C:\WINDOWS\odcau.dll : vbiges (7471 bytes)
C:\WINDOWS\OEWABLog.txt : actcrw (3347 bytes)
C:\WINDOWS\OEWABLog.txt : aolyu (10752 bytes)
C:\WINDOWS\OEWABLog.txt : cjiqdy (3347 bytes)
C:\WINDOWS\OEWABLog.txt : edxlxo (29696 bytes)
C:\WINDOWS\OEWABLog.txt : vkidnx (3567 bytes)
C:\WINDOWS\OEWABLog.txt : xjxuzz (10752 bytes)
C:\WINDOWS\PowerReg.dat : tdlhlh (70144 bytes)
C:\WINDOWS\PowerReg.dat : uiljj (11591 bytes)
C:\WINDOWS\Prairie Wind.bmp : mkadxi (70144 bytes)
C:\WINDOWS\Prairie Wind.bmp : pooqy (11591 bytes)
C:\WINDOWS\Prairie Wind.bmp : spvdo (29696 bytes)
C:\WINDOWS\Q327979.log : dvjpd (10752 bytes)
C:\WINDOWS\Q328213.log : ryptfg (10752 bytes)
C:\WINDOWS\Q328213.log : twawh (11591 bytes)
C:\WINDOWS\Q328213.log : yzhil (96127 bytes)
C:\WINDOWS\Q329048.log : btgot (29696 bytes)
C:\WINDOWS\Q329048.log : iohva (7305 bytes)
C:\WINDOWS\Q329909.log : hsjyh (56320 bytes)
C:\WINDOWS\Q329909.log : wwcug (29696 bytes)
C:\WINDOWS\Q331953.log : fbpbx (7305 bytes)
C:\WINDOWS\Q331953.log : kzigzr (29256 bytes)
C:\WINDOWS\Q331953.log : mxtbj (7305 bytes)
C:\WINDOWS\Q331953.log : qazng (10752 bytes)
C:\WINDOWS\Q811789.log : vyflwn (11592 bytes)
C:\WINDOWS\Q813862.log : apzbv (3347 bytes)
C:\WINDOWS\Q815485.log : eydgd (3347 bytes)
C:\WINDOWS\Q815485.log : xchhz (3347 bytes)
C:\WINDOWS\Q816979.log : ldjzpb (10752 bytes)
C:\WINDOWS\Q816979.log : oyyrqx (7305 bytes)
C:\WINDOWS\Q816982.log : qdsmt (55808 bytes)
C:\WINDOWS\Q816982.log : zqffc (11591 bytes)
C:\WINDOWS\qmjoy.dll : dwtfjm (29696 bytes)
C:\WINDOWS\regedit.exe : dvnyiz (11592 bytes)
C:\WINDOWS\regopt.log : rbsljw (29184 bytes)
C:\WINDOWS\Rhododendron.bmp : abzij (29696 bytes)
C:\WINDOWS\Rhododendron.bmp : acpeb (96127 bytes)
C:\WINDOWS\Rhododendron.bmp : aumtc (11591 bytes)
C:\WINDOWS\Rhododendron.bmp : ltqtnz (7305 bytes)
C:\WINDOWS\Rhododendron.bmp : mjwjm (11591 bytes)
C:\WINDOWS\Rhododendron.bmp : wmfss (7305 bytes)
C:\WINDOWS\Rhododendron.bmp : xlovyg (11591 bytes)
C:\WINDOWS\River Sumida.bmp : pmrus (10752 bytes)
C:\WINDOWS\salm_gdf.dat : dujghk (3547 bytes)
C:\WINDOWS\Santa Fe Stucco.bmp : gwqrfl (7471 bytes)
C:\WINDOWS\Santa Fe Stucco.bmp : pfqxu (3347 bytes)
C:\WINDOWS\SchedLgU.Txt : ckxpe (10752 bytes)
C:\WINDOWS\SchedLgU.Txt : csbds (3347 bytes)
C:\WINDOWS\SchedLgU.Txt : eoxnkf (10752 bytes)
C:\WINDOWS\SchedLgU.Txt : yucus (3347 bytes)
C:\WINDOWS\sdkxz.exe : tocyrg (55808 bytes)
C:\WINDOWS\sdkxz.exe : wubmcm (68096 bytes)
C:\WINDOWS\sessmgr.setup.log : cwcwj (3347 bytes)
C:\WINDOWS\sessmgr.setup.log : vegvgb (10752 bytes)
C:\WINDOWS\sessmgr.setup.log : yxjwzw (3567 bytes)
C:\WINDOWS\sessmgr.setup.log : zhvkr (7305 bytes)
C:\WINDOWS\sessmgr.setup.log : zxzkir (3347 bytes)
C:\WINDOWS\setdebug.exe : rycbbg (64000 bytes)
C:\WINDOWS\setupact.log : rvbxel (29256 bytes)
C:\WINDOWS\setupapi.log : nmiha (29696 bytes)
C:\WINDOWS\setuplog.txt : ewgdlo (7305 bytes)
C:\WINDOWS\slrundll.exe : cbgoay (7471 bytes)
C:\WINDOWS\Soap Bubbles.bmp : pciqr (11591 bytes)
C:\WINDOWS\Soap Bubbles.bmp : qhswf (10752 bytes)
C:\WINDOWS\Sti_Trace.log : coudrz (10752 bytes)
C:\WINDOWS\Sti_Trace.log : wwzigy (3547 bytes)
C:\WINDOWS\Sti_Trace.log : ytlxl (11591 bytes)
C:\WINDOWS\svcpack.log : ndjhwl (3567 bytes)
C:\WINDOWS\syskq.exe : pxroia (68096 bytes)
C:\WINDOWS\system.ini : sspizr (11592 bytes)
C:\WINDOWS\system.ini : xrxav (29696 bytes)
C:\WINDOWS\syszy32.dll : gaqzgl (7305 bytes)
C:\WINDOWS\syszy32.dll : gdcmqw (64000 bytes)
C:\WINDOWS\TASKMAN.EXE : hiqfc (11591 bytes)
C:\WINDOWS\TASKMAN.EXE : setio (3347 bytes)
C:\WINDOWS\TSearch.INI : abile (7305 bytes)
C:\WINDOWS\TSearch.INI : frqtiw (11592 bytes)
C:\WINDOWS\TSearch.INI : hdisga (11592 bytes)
C:\WINDOWS\twain.dll : bngvb (3347 bytes)
C:\WINDOWS\twain.dll : hozion (7305 bytes)
C:\WINDOWS\twain.dll : rljvoj (7305 bytes)
C:\WINDOWS\twain.dll : rubsvx (55808 bytes)
C:\WINDOWS\twunk_16.exe : zxtpke (10752 bytes)
C:\WINDOWS\twunk_32.exe : pwcnwu (10752 bytes)
C:\WINDOWS\twunk_32.exe : zosoix (3347 bytes)
C:\WINDOWS\ubswr.dll : ovdmjz (68096 bytes)
C:\WINDOWS\ubswr.dll : rydueo (29696 bytes)
C:\WINDOWS\ubswr.dll : sfudcn (3567 bytes)
C:\WINDOWS\UniFish3.exe : eqaxbd (11592 bytes)
C:\WINDOWS\UniFish3.exe : hwmaye (29184 bytes)
C:\WINDOWS\UniFish3.exe : spktkz (55808 bytes)
C:\WINDOWS\unvise32qt.exe : jtlryt (68096 bytes)
C:\WINDOWS\unvise32qt.exe : kyeqxx (68096 bytes)
C:\WINDOWS\unvise32qt.exe : lvdov (11591 bytes)
C:\WINDOWS\unvise32qt.exe : yssehl (29184 bytes)
C:\WINDOWS\UP9ASP.INI : cphqv (56320 bytes)
C:\WINDOWS\UP9ASP.INI : eixwbi (11591 bytes)
C:\WINDOWS\UP9ASP.INI : gcsgd (11591 bytes)
C:\WINDOWS\UP9ASP.INI : jxkzha (4402 bytes)
C:\WINDOWS\UP9ASP.INI : zyxgvj (10752 bytes)
C:\WINDOWS\uqttp.log : ufftmg (68096 bytes)
C:\WINDOWS\vb.ini : fdjjvd (10752 bytes)
C:\WINDOWS\vb.ini : pdkkm (55808 bytes)
C:\WINDOWS\vbaddin.ini : dnouq (7305 bytes)
C:\WINDOWS\vbaddin.ini : rzqlpt (29184 bytes)
C:\WINDOWS\vmmreg32.dll : cnexek (7305 bytes)
C:\WINDOWS\win.ini : cqfcn (10752 bytes)
C:\WINDOWS\win.ini : klwws (11591 bytes)
C:\WINDOWS\win.ini : pjipxv (7305 bytes)
C:\WINDOWS\win.ini : rwdrr (7305 bytes)
C:\WINDOWS\winamp.ini : asvvsb (4402 bytes)
C:\WINDOWS\Windows Update.log : cshses (11591 bytes)
C:\WINDOWS\Windows Update.log : npphax (68096 bytes)
C:\WINDOWS\winhelp.exe : opzmm (3347 bytes)
C:\WINDOWS\wininit.ini : adlzti (55808 bytes)
C:\WINDOWS\wininit.ini : fornuv (68096 bytes)
C:\WINDOWS\wininit.ini : vnhpo (7305 bytes)
C:\WINDOWS\winnt256.bmp : nmkkae (7305 bytes)
C:\WINDOWS\winnt256.bmp : nsqnj (29696 bytes)
C:\WINDOWS\WORDPAD.INI : ckqluw (10752 bytes)
C:\WINDOWS\WORDPAD.INI : fncqcp (3347 bytes)
C:\WINDOWS\yiqtp.dll : rzftfm (29184 bytes)
C:\WINDOWS\yiqtp.dll : wkwtnx (10752 bytes)
C:\WINDOWS\_default.pif : hmzmbs (29184 bytes)
C:\WINDOWS\{552E1F9E-D45F-422B-8355-D84CC9F12F1C}.dat : qmlaq (10752 bytes)
Thanks for all the help you've provided me with. :thumb: