I did that hijackthis thing.And here is the results, i really need help , the winbluesoft keeps coming to my computer screen.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:41:35, on 5.06.2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\system32\PnkBstrA.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Elaborate Bytes\DVD Region Killer\RegKillTray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\SweetIM\Messenger\SweetIM.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\setup2.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\system32\svchost.exe
C:\Documents and Settings\kristjan\Desktop\HiJack(GP)This.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.co.uk/0SEENWW/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.co.uk/0SEENWW/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com/?SearchSource=10&ctid=CT2077543
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\cocbb.dll/sp.html#37049%resultposition.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\cocbb.dll/sp.html#37049%resultposition.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\cocbb.dll/sp.html#37049%resultposition.net
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.co.uk/0SEENWW/SAOS01?FORM=TOOLBR
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
R3 - URLSearchHook: (no name) - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - (no file)
R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll
O2 - BHO: (no name) - {032F02E7-5716-7D60-3E88-9B6309146D54} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {15175C75-F477-8EB4-3C8F-02C0FB819959} - (no file)
O2 - BHO: (no name) - {165E2A96-F6EF-8EAA-AA3B-BCF19E677FD4} - (no file)
O2 - BHO: (no name) - {1A3AAC53-69B3-F769-1199-284A99589CE9} - (no file)
O2 - BHO: (no name) - {22A99D53-6CB9-33A5-DED6-D04F5F0F1AE8} - (no file)
O2 - BHO: (no name) - {2A69B4ED-A44E-115C-7B00-D6A6A2337148} - (no file)
O2 - BHO: (no name) - {2AD4D876-81B0-B087-D7C1-18BD7A709292} - (no file)
O2 - BHO: (no name) - {30B4B4C0-2D48-47C3-EB7B-42CFEDCAC207} - (no file)
O2 - BHO: (no name) - {30B9D3B6-3171-041B-C2E4-A7FD55558A20} - (no file)
O2 - BHO: (no name) - {322C1801-FA23-AB9E-7F00-648E62563F51} - (no file)
O2 - BHO: (no name) - {34008A69-BA68-8165-F6D2-77FCBCE7DCC4} - (no file)
O2 - BHO: (no name) - {3741C5ED-4EDB-B11A-EFEE-169A682E180C} - (no file)
O2 - BHO: (no name) - {4310B657-55A0-9397-B42A-4550F263DFCA} - (no file)
O2 - BHO: (no name) - {452CE4BD-6993-E987-C954-8D53652EE101} - (no file)
O2 - BHO: (no name) - {4A35DEC1-AC71-E2CC-AA75-FE86733D32EC} - (no file)
O2 - BHO: (no name) - {4D7AAE7E-60D8-7CE4-E215-285680E2A5E4} - (no file)
O2 - BHO: (no name) - {4D9FC428-C242-144C-B27B-F27F0CC116BE} - (no file)
O2 - BHO: (no name) - {5E7086B3-1C13-BC89-057F-D412593714CD} - (no file)
O2 - BHO: (no name) - {696C280D-491E-BCE6-CB54-6602CC3C3A0C} - (no file)
O2 - BHO: (no name) - {6CAEDB06-E5D2-0957-5F14-D24A99FB0FA4} - (no file)
O2 - BHO: (no name) - {6F7408EF-74FB-6985-7708-21C38BE457B2} - (no file)
O2 - BHO: (no name) - {7941CA3D-DE09-D3B7-ABB4-A41A008C96ED} - (no file)
O2 - BHO: (no name) - {8452BC65-9E1F-8A0C-B537-38BCC7650B62} - (no file)
O2 - BHO: Class - {8795DBCC-3869-2C17-CA6F-F9FF44CDA69E} - C:\WINDOWS\system32\javaqa.dll (file missing)
O2 - BHO: (no name) - {8C5AF52A-29FE-EBE7-5E7E-D3B62AE9D3CE} - (no file)
O2 - BHO: (no name) - {9618C8D5-BD90-A94C-567A-B42B32CBCDCB} - (no file)
O2 - BHO: (no name) - {9627E89A-ADC6-335C-80FB-709684853BA6} - (no file)
O2 - BHO: (no name) - {9A8B99A7-1546-27CF-9FA1-CDE07BAAF512} - (no file)
O2 - BHO: (no name) - {9B1A2625-49C3-7881-A453-1C2B2E4282F9} - (no file)
O2 - BHO: (no name) - {A3ABABDA-544D-9E70-AE96-BE2F5DCF0B5A} - (no file)
O2 - BHO: (no name) - {A6907CEB-9625-B7AC-4916-7411F6766CB8} - (no file)
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {C649E716-3432-9ED8-A74F-7B789784477D} - (no file)
O2 - BHO: (no name) - {CFBA6A8B-141A-EFF7-2284-53A16D783BE4} - (no file)
O2 - BHO: (no name) - {D59AC151-F00C-3509-5093-1C3589B36680} - (no file)
O2 - BHO: (no name) - {EFF0DA76-9796-3B9F-3EC2-35A88D1F24F6} - (no file)
O2 - BHO: (no name) - {F4758A19-4B23-B61B-0125-C805E79FBA5A} - (no file)
O2 - BHO: (no name) - {FBA5235F-EC2A-A50C-81E0-3492DB3393E2} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: ALOT Toolbar - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: SweetIM Toolbar - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O3 - Toolbar: (no name) - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - (no file)
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar1.dll
O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [RegKillTray] C:\Program Files\Elaborate Bytes\DVD Region Killer\RegKillTray.exe
O4 - HKLM\..\Run: [ElbyCheckRegKill] "C:\Program Files\Elaborate Bytes\DVD Region
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:41:35, on 5.06.2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\system32\PnkBstrA.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Elaborate Bytes\DVD Region Killer\RegKillTray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\SweetIM\Messenger\SweetIM.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\setup2.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\system32\svchost.exe
C:\Documents and Settings\kristjan\Desktop\HiJack(GP)This.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.co.uk/0SEENWW/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.co.uk/0SEENWW/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com/?SearchSource=10&ctid=CT2077543
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\cocbb.dll/sp.html#37049%resultposition.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\cocbb.dll/sp.html#37049%resultposition.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\cocbb.dll/sp.html#37049%resultposition.net
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.co.uk/0SEENWW/SAOS01?FORM=TOOLBR
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
R3 - URLSearchHook: (no name) - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - (no file)
R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll
O2 - BHO: (no name) - {032F02E7-5716-7D60-3E88-9B6309146D54} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {15175C75-F477-8EB4-3C8F-02C0FB819959} - (no file)
O2 - BHO: (no name) - {165E2A96-F6EF-8EAA-AA3B-BCF19E677FD4} - (no file)
O2 - BHO: (no name) - {1A3AAC53-69B3-F769-1199-284A99589CE9} - (no file)
O2 - BHO: (no name) - {22A99D53-6CB9-33A5-DED6-D04F5F0F1AE8} - (no file)
O2 - BHO: (no name) - {2A69B4ED-A44E-115C-7B00-D6A6A2337148} - (no file)
O2 - BHO: (no name) - {2AD4D876-81B0-B087-D7C1-18BD7A709292} - (no file)
O2 - BHO: (no name) - {30B4B4C0-2D48-47C3-EB7B-42CFEDCAC207} - (no file)
O2 - BHO: (no name) - {30B9D3B6-3171-041B-C2E4-A7FD55558A20} - (no file)
O2 - BHO: (no name) - {322C1801-FA23-AB9E-7F00-648E62563F51} - (no file)
O2 - BHO: (no name) - {34008A69-BA68-8165-F6D2-77FCBCE7DCC4} - (no file)
O2 - BHO: (no name) - {3741C5ED-4EDB-B11A-EFEE-169A682E180C} - (no file)
O2 - BHO: (no name) - {4310B657-55A0-9397-B42A-4550F263DFCA} - (no file)
O2 - BHO: (no name) - {452CE4BD-6993-E987-C954-8D53652EE101} - (no file)
O2 - BHO: (no name) - {4A35DEC1-AC71-E2CC-AA75-FE86733D32EC} - (no file)
O2 - BHO: (no name) - {4D7AAE7E-60D8-7CE4-E215-285680E2A5E4} - (no file)
O2 - BHO: (no name) - {4D9FC428-C242-144C-B27B-F27F0CC116BE} - (no file)
O2 - BHO: (no name) - {5E7086B3-1C13-BC89-057F-D412593714CD} - (no file)
O2 - BHO: (no name) - {696C280D-491E-BCE6-CB54-6602CC3C3A0C} - (no file)
O2 - BHO: (no name) - {6CAEDB06-E5D2-0957-5F14-D24A99FB0FA4} - (no file)
O2 - BHO: (no name) - {6F7408EF-74FB-6985-7708-21C38BE457B2} - (no file)
O2 - BHO: (no name) - {7941CA3D-DE09-D3B7-ABB4-A41A008C96ED} - (no file)
O2 - BHO: (no name) - {8452BC65-9E1F-8A0C-B537-38BCC7650B62} - (no file)
O2 - BHO: Class - {8795DBCC-3869-2C17-CA6F-F9FF44CDA69E} - C:\WINDOWS\system32\javaqa.dll (file missing)
O2 - BHO: (no name) - {8C5AF52A-29FE-EBE7-5E7E-D3B62AE9D3CE} - (no file)
O2 - BHO: (no name) - {9618C8D5-BD90-A94C-567A-B42B32CBCDCB} - (no file)
O2 - BHO: (no name) - {9627E89A-ADC6-335C-80FB-709684853BA6} - (no file)
O2 - BHO: (no name) - {9A8B99A7-1546-27CF-9FA1-CDE07BAAF512} - (no file)
O2 - BHO: (no name) - {9B1A2625-49C3-7881-A453-1C2B2E4282F9} - (no file)
O2 - BHO: (no name) - {A3ABABDA-544D-9E70-AE96-BE2F5DCF0B5A} - (no file)
O2 - BHO: (no name) - {A6907CEB-9625-B7AC-4916-7411F6766CB8} - (no file)
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {C649E716-3432-9ED8-A74F-7B789784477D} - (no file)
O2 - BHO: (no name) - {CFBA6A8B-141A-EFF7-2284-53A16D783BE4} - (no file)
O2 - BHO: (no name) - {D59AC151-F00C-3509-5093-1C3589B36680} - (no file)
O2 - BHO: (no name) - {EFF0DA76-9796-3B9F-3EC2-35A88D1F24F6} - (no file)
O2 - BHO: (no name) - {F4758A19-4B23-B61B-0125-C805E79FBA5A} - (no file)
O2 - BHO: (no name) - {FBA5235F-EC2A-A50C-81E0-3492DB3393E2} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: ALOT Toolbar - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: SweetIM Toolbar - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O3 - Toolbar: (no name) - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - (no file)
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar1.dll
O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [RegKillTray] C:\Program Files\Elaborate Bytes\DVD Region Killer\RegKillTray.exe
O4 - HKLM\..\Run: [ElbyCheckRegKill] "C:\Program Files\Elaborate Bytes\DVD Region