Hopefully this is everything you need.Thanks again.
ComboFix 07-11-08.3 - HP_Administrator 2007-11-14 18:57:51.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.203 [GMT -5:00]
Running from: C:\Documents and Settings\HP_Administrator\Desktop\ComboFix.exe
.
Unable to gain System Privileges
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\HP_Administrator\Desktop\Live Safety Center.lnk
C:\Documents and Settings\HP_Administrator\Desktop\Online Security Guide.lnk
C:\Documents and Settings\HP_Administrator\Favorites\Online Security Guide.lnk
C:\WINDOWS\system32\kjllm.ini
C:\WINDOWS\system32\kjllm.ini2
C:\WINDOWS\system32\mlljk.dll
C:\WINDOWS\system32\nzinnbqa.dllbox
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
-------\DomainService
((((((((((((((((((((((((( Files Created from 2007-10-15 to 2007-11-15 )))))))))))))))))))))))))))))))
.
2007-11-14 18:53 85,056 --a------ C:\WINDOWS\system32\mttqpcch.dll
2007-11-14 18:50 71,232 --a------ C:\WINDOWS\system32\otgcpdev.exe
2007-11-14 18:35 79,424 --a------ C:\WINDOWS\system32\iqthkfmx.dll
2007-11-14 18:29 71,232 --a------ C:\WINDOWS\system32\rmbxknem.exe
2007-11-13 20:39 453,120 --a--c--- C:\WINDOWS\system32\dllcache\mrxsmb.sys
2007-11-13 18:02 <DIR> d-------- C:\Program Files\Sygate
2007-11-13 18:02 83,096 --a------ C:\WINDOWS\system32\SSSensor.dll
2007-11-13 18:02 60,496 --a------ C:\WINDOWS\system32\drivers\Teefer.sys
2007-11-13 18:02 21,075 --a------ C:\WINDOWS\system32\drivers\wpsdrvnt.sys
2007-11-13 18:02 14,568 --a------ C:\WINDOWS\system32\drivers\wg6n.sys
2007-11-13 18:02 14,568 --a------ C:\WINDOWS\system32\drivers\wg5n.sys
2007-11-13 18:02 14,568 --a------ C:\WINDOWS\system32\drivers\wg4n.sys
2007-11-13 18:02 14,568 --a------ C:\WINDOWS\system32\drivers\wg3n.sys
2007-11-13 17:58 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2007-11-13 17:53 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-11-13 17:29 43,352 --a------ C:\WINDOWS\system32\wups2.dll
2007-11-13 17:11 88,128 --a------ C:\WINDOWS\system32\thjeewns.dll
2007-11-13 17:08 80,448 --a------ C:\WINDOWS\system32\camjxynx.dll
2007-11-13 17:08 71,232 --a------ C:\WINDOWS\system32\smdvqbis.exe
2007-11-12 22:42 <DIR> d-------- C:\Program Files\Trend Micro
2007-11-12 19:41 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-12 18:50 89,664 --a------ C:\WINDOWS\system32\ywspnuin.dll
2007-11-12 18:50 81,472 --a------ C:\WINDOWS\system32\urhscptl.dll
2007-11-11 18:46 88,128 --a------ C:\WINDOWS\system32\yvxkypvx.dll
2007-11-11 18:40 79,936 --a------ C:\WINDOWS\system32\dspeftyq.dll
2007-11-11 18:39 145,984 --a------ C:\WINDOWS\system32\qilaqoeu.dll
2007-11-11 18:39 145,984 --a------ C:\WINDOWS\system32\nzinnbqa.dll
2007-11-11 18:39 71,232 --a------ C:\WINDOWS\system32\rppdaxds.exe
2007-11-08 00:22 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2007-11-07 18:34 35,328 --a------ C:\WINDOWS\system32\opnkigh.dll
2007-11-07 18:30 <DIR> d-------- C:\WINDOWS\system32\Mz02r
2007-11-07 18:30 35,328 --a------ C:\WINDOWS\system32\rqrqrop.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-14 23:49 --------- d-----w C:\Program Files\Java
2007-11-14 00:00 --------- d-----w C:\Program Files\Norton Personal Firewall
2007-11-14 00:00 --------- d-----w C:\Program Files\Norton AntiVirus
2007-11-13 23:49 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-11-12 21:09 --------- d-----w C:\Program Files\Morpheus
2007-11-05 19:51 --------- d-----w C:\Program Files\City of Heroes
2007-10-23 00:23 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\AdobeUM
2007-10-07 01:04 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\Template
2007-10-07 01:01 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\ATI
2007-10-07 00:55 4,192 --sha-r C:\WINDOWS\system32\drivers\HP_PJ466AA-ABA M1170N_YC_Pavi_QMXK440_E44NAsyEPC4_4_IPuffer_SASUSTeK Computer INC._V1.xx_B3.07_T040915_WXP2_L409_M512_J200_7Intel_8Pentium 4_93_111063044_N10EC8139_P_Z11C1048C_K_A_U80862658_G10025B60.MRK
2007-10-01 23:57 --------- d-----w C:\WINDOWS\system32\config\systemprofile\Application Data\Template
2007-10-01 23:57 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Template
2007-09-23 23:54 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\OpenOffice.org2
2007-09-15 16:57 1,409 ----a-w C:\WINDOWS\Fonts\RPRSTITL.FOT
2007-09-15 16:57 1,409 ----a-w C:\WINDOWS\Fonts\RPRSTEXT.FOT
2007-09-15 16:57 1,409 ----a-w C:\WINDOWS\Fonts\RPRSSTMP.FOT
2007-09-15 16:57 1,409 ----a-w C:\WINDOWS\Fonts\RPRSSPEC.FOT
2007-09-15 16:57 1,409 ----a-w C:\WINDOWS\Fonts\RPRSSCRP.FOT
2007-09-15 16:57 1,409 ----a-w C:\WINDOWS\Fonts\RPRSREH_.FOT
2007-09-15 16:57 1,409 ----a-w C:\WINDOWS\Fonts\RPRSMET_.FOT
2007-09-15 16:57 1,409 ----a-w C:\WINDOWS\Fonts\RPRSCHOR.FOT
2007-09-15 16:57 1,409 ----a-w C:\WINDOWS\Fonts\RPRS____.FOT
2007-09-15 16:57 1,409 ----a-w C:\WINDOWS\Fonts\OPUSTEXT.FOT
2007-09-15 16:57 1,409 ----a-w C:\WINDOWS\Fonts\OPUSSE__.FOT
2007-09-15 16:57 1,409 ----a-w C:\WINDOWS\Fonts\OPUSS___.FOT
2007-09-15 16:57 1,409 ----a-w C:\WINDOWS\Fonts\OPUSROMC.FOT
2007-09-15 16:57 1,409 ----a-w C:\WINDOWS\Fonts\OPUSPC__.FOT
2007-09-15 16:57 1,409 ----a-w C:\WINDOWS\Fonts\OPUSP___.FOT
2007-09-15 16:57 1,409 ----a-w C:\WINDOWS\Fonts\OPUSO___.FOT
2007-09-15 16:57 1,409 ----a-w C:\WINDOWS\Fonts\OPUSNN__.FOT
2007-09-15 16:57 1,409 ----a-w C:\WINDOWS\Fonts\OPUSM___.FOT
2007-09-15 16:57 1,409 ----a-w C:\WINDOWS\Fonts\OPUSJAPC.FOT
2007-09-15 16:57 1,409 ----a-w C:\WINDOWS\Fonts\OPUSFS__.FOT
2007-09-15 16:57 1,409 ----a-w C:\WINDOWS\Fonts\OPUSFBE_.FOT
2007-09-15 16:57 1,409 ----a-w C:\WINDOWS\Fonts\OPUSFB__.FOT
2007-09-15 16:57 1,409 ----a-w C:\WINDOWS\Fonts\OPUSCSC_.FOT
2007-09-15 16:57 1,409 ----a-w C:\WINDOWS\Fonts\OPUSCS__.FOT
2007-09-15 16:57 1,409 ----a-w C:\WINDOWS\Fonts\OPUSC___.FOT
2007-09-15 16:57 1,409 ----a-w C:\WINDOWS\Fonts\OPUS____.FOT
2007-09-15 16:57 1,409 ----a-w C:\WINDOWS\Fonts\INKPEN2_.FOT
2007-09-15 16:57 1,409 ----a-w C:\WINDOWS\Fonts\INK2TEXT.FOT
2007-09-15 16:57 1,409 ----a-w C:\WINDOWS\Fonts\INK2SPEC.FOT
2007-09-15 16:57 1,409 ----a-w C:\WINDOWS\Fonts\INK2SCRI.FOT
2007-09-15 16:57 1,409 ----a-w C:\WINDOWS\Fonts\INK2METR.FOT
2007-09-15 16:57 1,409 ----a-w C:\WINDOWS\Fonts\INK2CHOR.FOT
2007-09-15 16:57 1,409 ----a-w C:\WINDOWS\Fonts\HELST___.FOT
2007-09-15 16:57 1,409 ----a-w C:\WINDOWS\Fonts\HELSS___.FOT
2007-09-15 16:57 1,409 ----a-w C:\WINDOWS\Fonts\HELSM___.FOT
2007-09-15 16:57 1,409 ----a-w C:\WINDOWS\Fonts\HELSINKI.FOT
2007-09-15 16:57 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\Sibelius Software
2007-09-15 16:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\Musicnotes
1989-12-12 14:10:10 993,728 --sh--r C:\WINDOWS\bwibdvy.exe
1989-12-12 14:10:10 1,114,816 --sh--r C:\WINDOWS\bwibdvyA.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{11806679-2B19-4DEF-AC71-8FC455668235}]
C:\Program Files\Movie Maker\mewofyhys83122.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1C1DD717-53B2-485E-A17B-C9977C205E10}]
2007-11-07 18:30 35328 --a------ C:\WINDOWS\system32\rqrqrop.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2DD72138-3E97-4FA5-F28C-5BE5EFBE5AAA}]
C:\Program Files\MSN Gaming Zone\qujax326.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
2007-11-11 18:39 145984 --a------ C:\WINDOWS\system32\nzinnbqa.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c3ec6330-8452-48b6-983e-7b13d4b40739}]
C:\WINDOWS\system32\mxhgfnr.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C5AAF243-1FF9-3E2E-D826-4DE673830BED}]
C:\WINDOWS\system32\qsuhn.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e01187d0-7d6f-4432-afc1-1e71256c4880}]
2007-11-14 18:35 79424 --a------ C:\WINDOWS\system32\iqthkfmx.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\nzinnbqa.dll [2007-11-11 18:39 145984]
[HKEY_CLASSES_ROOT\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2004-08-10 13:04]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 18:04]
"HPHUPD06"="c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [2004-06-07 20:53]
"HPHmon06"="C:\WINDOWS\system32\hphmon06.exe" [2004-06-07 20:42]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 22:02]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-09-03 01:54]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-14 22:43]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2003-12-09 01:18]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 19:06 C:\WINDOWS\AGRSMMSG.exe]
"SoundMan"="SOUNDMAN.EXE" [2004-07-01 20:58 C:\WINDOWS\SOUNDMAN.EXE]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2002-10-16 18:57]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-26 20:00]
"AlcWzrd"="ALCWZRD.EXE" [2004-07-06 03:05 C:\WINDOWS\ALCWZRD.EXE]
"SmcService"="C:\PROGRA~1\Sygate\SPF\smc.exe" [2004-10-15 19:40]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"686b4fa2"="C:\WINDOWS\system32\mttqpcch.dll" [2007-11-14 18:53]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 07:00]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
ATI CATALYST System Tray.lnk - C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe [2005-08-12 13:43:58]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-29 07:31:38]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{1C1DD717-53B2-485E-A17B-C9977C205E10}"= C:\WINDOWS\system32\rqrqrop.dll [2007-11-07 18:30 35328]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\nzinnbqa]
nzinnbqa.dll 2007-11-11 18:39 145984 C:\WINDOWS\system32\nzinnbqa.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rqrqrop]
rqrqrop.dll 2007-11-07 18:30 35328 C:\WINDOWS\system32\rqrqrop.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\mlljk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\686b4fa2]
rundll32.exe "C:\WINDOWS\system32\ywspnuin.dll",b
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mefetef]
C:\Program Files\Windows NT\mefetef77798.exe
.
Contents of the 'Scheduled Tasks' folder
"2007-11-11 23:38:39 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - HP_Administrator.job"
- c:\PROGRA~1\NORTON~1\Navw32.exe
"2007-10-07 02:01:46 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
"2007-11-13 00:51:42 C:\WINDOWS\Tasks\XoftSpySE 2.job"
- C:\Program Files\XoftSpySE\XoftSpy.exe
"2007-11-13 00:51:43 C:\WINDOWS\Tasks\XoftSpySE.job"
- C:\Program Files\XoftSpySE\XoftSpy.exe
.
**************************************************************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-11-14 19:10:08
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-14 19:12:47 - machine was rebooted
C:\ComboFix2.txt ... 2007-11-13 00:53
C:\ComboFix3.txt ... 2007-11-12 21:00
.
--- E O F ---
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:15:34 PM, on 11/14/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\ehome\ehtray.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\hphmon06.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktopR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktopR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktopR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktopR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {11806679-2B19-4DEF-AC71-8FC455668235} - C:\Program Files\Movie Maker\mewofyhys83122.dll (file missing)
O2 - BHO: (no name) - {1C1DD717-53B2-485E-A17B-C9977C205E10} - C:\WINDOWS\system32\rqrqrop.dll
O2 - BHO: 0 - {2DD72138-3E97-4FA5-F28C-5BE5EFBE5AAA} - C:\Program Files\MSN Gaming Zone\qujax326.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - c:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\nzinnbqa.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {c3ec6330-8452-48b6-983e-7b13d4b40739} - C:\WINDOWS\system32\mxhgfnr.dll (file missing)
O2 - BHO: (no name) - {C5AAF243-1FF9-3E2E-D826-4DE673830BED} - C:\WINDOWS\system32\qsuhn.dll (file missing)
O2 - BHO: {0884c652-17e1-1cfa-2344-f6d70d78110e} - {e01187d0-7d6f-4432-afc1-1e71256c4880} - C:\WINDOWS\system32\iqthkfmx.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\nzinnbqa.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [686b4fa2] rundll32.exe "C:\WINDOWS\system32\mttqpcch.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) -
http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/windowsupd...b?1194992922125O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cabO20 - Winlogon Notify: nzinnbqa - C:\WINDOWS\SYSTEM32\nzinnbqa.dll
O20 - Winlogon Notify: rqrqrop - C:\WINDOWS\SYSTEM32\rqrqrop.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
--
End of file - 8212 bytes