Hey, Richie, thanks for the welcome, and for the help!
I followed the steps you suggested, and things seem to have gone well generally, but there were a few glitches. While I don't know if they are significant, I'll tell you about them anyway, and let YOU decide, since you're the one who knows what he's doing. :-)
When I ran VundoFix.exe, it scanned, listed about fifteen located files, and began the deletion process. Right before the reboot, it gave an error message saying something along the lines of "Cannot import c:\vundofix.reg," which it attributed to a possible disk or hardware error. My hard drives are only about two months old, and have never produced any error messages or Event Viewer entries in that time. After the reboot, VundoFix did NOT restart, so I assume that means it successfully deleted all the files. My Event Viewer does show an entry stating "The VundoFix Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: No action."
When I ran ComboFix.exe, the experience was similar. It appeared to run fine, but then generated two error messages. The first one said that my maximum registry file size was set too low...even though, when I checked it later, the maximum was set to 54 megs and the actual size was only 31 megs. My Event Viewer does show an entry stating "Application popup: Windows - Low On Registry Space : Your maximum registry size is too small. To ensure that Windows runs properly, increase your maximum registry size. For more information, see Help." The other error message appeared in a window with "Registry Editor" in the title bar and the message "Cannot import creg.cf. Error in accessing the registry." ComboFix also did not create a log file, but after a while, it DID display a log in Notepad, which I saved as ComboFixLog.txt. My Event Viewer does show an entry stating "The combofix service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion."
When I renamed HJT to xyz.bat and ran it by clicking the scan + log button, it actually ran to completion (the first time it has done so on my computer).
I have not done any checking to see if my computer is now running correctly, but I did notice that, when IE started to allow me to make this posting, ONLY this one instance started, and there were no extra IE windows with ads in them. That's promising! :-)
Here are the log files you requested:
1. VundoFix.txt
VundoFix V6.4.2
Checking Java version...
Sun Java not detected
Scan started at 9:52:53 AM 6/4/2007
Listing files found while scanning....
c:\winnt\inf\comdb.dll
C:\WINNT\system32\ddcwkdqw.dll
C:\WINNT\system32\fiqqmibr.dll
C:\WINNT\system32\hggebaa.dll
C:\WINNT\system32\jkblhvcs.dll
C:\WINNT\system32\jklnn.bak1
C:\WINNT\system32\jklnn.bak2
C:\WINNT\system32\jklnn.ini
C:\WINNT\system32\khfecdc.dll
C:\WINNT\system32\nemldjcx.ini
C:\WINNT\system32\nnlkj.dll
C:\WINNT\system32\urqoomm.dll
C:\WINNT\system32\utstv.ini
C:\WINNT\system32\vtstu.dll
C:\WINNT\system32\xcjdlmen.dll
Beginning removal...
Attempting to delete c:\winnt\inf\comdb.dll
c:\winnt\inf\comdb.dll Has been deleted!
Attempting to delete C:\WINNT\system32\fiqqmibr.dll
C:\WINNT\system32\fiqqmibr.dll Has been deleted!
Attempting to delete C:\WINNT\system32\hggebaa.dll
C:\WINNT\system32\hggebaa.dll Has been deleted!
Attempting to delete C:\WINNT\system32\jkblhvcs.dll
C:\WINNT\system32\jkblhvcs.dll Has been deleted!
Attempting to delete C:\WINNT\system32\jklnn.bak1
C:\WINNT\system32\jklnn.bak1 Has been deleted!
Attempting to delete C:\WINNT\system32\jklnn.bak2
C:\WINNT\system32\jklnn.bak2 Has been deleted!
Attempting to delete C:\WINNT\system32\jklnn.ini
C:\WINNT\system32\jklnn.ini Has been deleted!
Attempting to delete C:\WINNT\system32\khfecdc.dll
C:\WINNT\system32\khfecdc.dll Has been deleted!
Attempting to delete C:\WINNT\system32\nemldjcx.ini
C:\WINNT\system32\nemldjcx.ini Has been deleted!
Attempting to delete C:\WINNT\system32\nnlkj.dll
C:\WINNT\system32\nnlkj.dll Has been deleted!
Attempting to delete C:\WINNT\system32\urqoomm.dll
C:\WINNT\system32\urqoomm.dll Has been deleted!
Attempting to delete C:\WINNT\system32\utstv.ini
C:\WINNT\system32\utstv.ini Has been deleted!
Attempting to delete C:\WINNT\system32\vtstu.dll
C:\WINNT\system32\vtstu.dll Has been deleted!
Attempting to delete C:\WINNT\system32\xcjdlmen.dll
C:\WINNT\system32\xcjdlmen.dll Has been deleted!
Performing Repairs to the registry.
Done!
2. ComboFixLog.txt
"Uralten" - 06/04/2007 10:09:35 Service Pack 4
ComboFix 07-06-4 - Running from: "C:\Documents and Settings\Uralten\Desktop\"
(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINNT\system32\wxkpaemi.exe
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\URALTEN\APPLIC~1.\macromedia\Flash Player\#SharedObjects\KZP9DMAU\www.broadcaster.com
C:\DOCUME~1\URALTEN\APPLIC~1.\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\Program Files\Common Files\Yazzle1281OinUninstaller.exe
C:\WINNT\inf\ntp2.ini
C:\WINNT\system32\drivers\npf.sys
C:\WINNT\system32\packet.dll
C:\WINNT\system32\pthreadVC.dll
C:\WINNT\system32\wanpacket.dll
C:\WINNT\system32\wpcap.dll
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_NM
-------\LEGACY_NPF
-------\nm
-------\NPF
((((((((((((((((((((((((( Files Created from 2007-05-04 to 2007-06-04 )))))))))))))))))))))))))))))))
2007-06-04 10:13 <DIR> d-------- C:\Temp\3.tmp
2007-06-04 09:52 <DIR> d-------- C:\VundoFix Backups
2007-06-03 19:33 2,580 --a------ C:\WINNT\system32\cuqnogoh.exe
2007-06-01 21:47 2,580 --a------ C:\WINNT\system32\ljpdyexr.exe
2007-06-01 11:22 <DIR> d-------- C:\Program Files\Registrar Lite
2007-05-24 20:32 69,824 --a------ C:\WINNT\system32\drivers\LxrJD31d.sys
2007-05-24 20:32 61,440 --a------ C:\WINNT\system32\LxrJD20Sat.dll
2007-05-24 20:32 53,248 --a------ C:\WINNT\system32\LxrJD31s.exe
2007-05-24 20:32 249,856 --a------ C:\WINNT\system32\LxrJD31.dll
2007-05-24 20:32 167,936 --a------ C:\WINNT\system32\LxrJD31c.exe
2007-05-24 20:32 146,432 --a------ C:\WINNT\system32\LxrJD31p.exe
2007-05-10 09:36 <DIR> d-------- C:\WINNT\nview
2007-05-10 09:31 176,128 --a------ C:\WINNT\system32\nvudisp.exe
2007-05-10 09:18 208,896 --a------ C:\WINNT\system32\NVUNINST.EXE
2007-05-09 09:55 1,632 --a------ C:\WINNT\system32\d3d8caps.dat
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-05-23 23:18:56 1,744 ----a-w C:\WINNT\system32\d3d9caps.dat
2007-04-09 14:46:06 -------- d-----w C:\Program Files\VIA Technologies, Inc
2007-04-05 14:48:36 4,212 ---h--w C:\WINNT\system32\zllictbl.dat
2007-04-05 07:17:40 2,854,400 ----a-w C:\WINNT\system32\msi.dll
2007-03-13 09:44:50 245,520 ----a-w C:\WINNT\system32\WINSRV.DLL
2007-03-09 05:02:00 75,512 ----a-w C:\WINNT\zllsputility.exe
2007-03-09 05:01:42 1,087,216 ----a-w C:\WINNT\system32\zpeng24.dll
2007-03-06 11:17:48 381,200 ----a-w C:\WINNT\system32\USER32.DLL
2007-03-06 11:17:46 38,160 ----a-w C:\WINNT\system32\mf3216.dll
2007-03-06 11:17:46 235,280 ----a-w C:\WINNT\system32\GDI32.DLL
2007-03-06 06:12:22 1,641,936 ----a-w C:\WINNT\system32\WIN32K.SYS
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [06-12-18 04:16 ]
{53707962-6F74-2D53-2644-206D7942484F}=C:\Programs\Utils\SpyBot\SDHelper.dll [05-05-31 01:04 ]
{7DB2D5A0-7241-4E79-B68D-6309F01C5231}=c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll [06-12-22 16:02 ]
{C3231A73-A39D-47BE-A08F-A7B937A6F30B}=C:\WINNT\system32\nnlkj.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Logitech Utility"="Logi_MwX.Exe" [03-12-17 09:50 C:\WINNT\LOGI_MWX.EXE]
"InCD"="C:\Programs\Ahead\InCD\InCD.exe" [04-08-27 02:01 ]
"Tweak UI"="TWEAKUI.CPL" [96-11-08 14:33 C:\WINNT\system32\TWEAKUI.CPL]
"itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [05-12-04 16:38 ]
"Synchronization Manager"="mobsync.exe" [03-06-19 13:05 C:\WINNT\system32\mobsync.exe]
"ZoneAlarm Client"="C:\Programs\Utils\ZoneAlarm\zlclient.exe" [07-03-09 00:02 ]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Weather"="C:\PROGRA~1\AWS\WEATHE~1\WEATHER.exe" [06-01-06 09:57 ]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [06-11-07 09:29 ]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"^SetupICWDesktop"=C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSaveSettings"=00000000
"NoStartBanner"=01000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"NvMediaCenter"=RUNDLL32.EXE C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
"nwiz"=nwiz.exe /install
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*
Contents of the 'Scheduled Tasks' folder
2007-05-21 15:42:02 C:\WINNT\tasks\AppleSoftwareUpdate.job
2007-06-02 00:05:32 C:\WINNT\tasks\Daily.job
2007-06-02 00:15:14 C:\WINNT\tasks\Outlook.job
2007-05-30 00:30:38 C:\WINNT\tasks\System State.job
2007-05-31 22:25:30 C:\WINNT\tasks\CD-RW Backup.job
2007-05-30 00:45:12 C:\WINNT\tasks\Identities.job
2007-06-01 18:00:14 C:\WINNT\tasks\McQcTask.job
(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINNT\system32\wxkpaemi.exe
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\URALTEN\APPLIC~1.\macromedia\Flash Player\#SharedObjects\KZP9DMAU\www.broadcaster.com
C:\DOCUME~1\URALTEN\APPLIC~1.\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\Program Files\Common Files\Yazzle1281OinUninstaller.exe
C:\WINNT\inf\ntp2.ini
C:\WINNT\system32\drivers\npf.sys
C:\WINNT\system32\packet.dll
C:\WINNT\system32\pthreadVC.dll
C:\WINNT\system32\wanpacket.dll
C:\WINNT\system32\wpcap.dll
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_NM
-------\LEGACY_NPF
-------\nm
-------\NPF
((((((((((((((((((((((((( Files Created from 2007-05-04 to 2007-06-04 )))))))))))))))))))))))))))))))
2007-06-04 10:14 16,384 --a----t- C:\WINNT\system32\Perflib_Perfdata_760.dat
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-05-23 23:18:56 1,744 ----a-w C:\WINNT\system32\d3d9caps.dat
2007-04-09 14:46:06 -------- d-----w C:\Program Files\VIA Technologies, Inc
2007-04-05 14:48:36 4,212 ---h--w C:\WINNT\system32\zllictbl.dat
2007-04-05 07:17:40 2,854,400 ----a-w C:\WINNT\system32\msi.dll
2007-03-13 09:44:50 245,520 ----a-w C:\WINNT\system32\WINSRV.DLL
2007-03-09 05:02:00 75,512 ----a-w C:\WINNT\zllsputility.exe
2007-03-09 05:01:42 1,087,216 ----a-w C:\WINNT\system32\zpeng24.dll
2007-03-06 11:17:48 381,200 ----a-w C:\WINNT\system32\USER32.DLL
2007-03-06 11:17:46 38,160 ----a-w C:\WINNT\system32\mf3216.dll
2007-03-06 11:17:46 235,280 ----a-w C:\WINNT\system32\GDI32.DLL
2007-03-06 06:12:22 1,641,936 ----a-w C:\WINNT\system32\WIN32K.SYS
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [06-12-18 04:16 ]
{53707962-6F74-2D53-2644-206D7942484F}=C:\Programs\Utils\SpyBot\SDHelper.dll [05-05-31 01:04 ]
{7DB2D5A0-7241-4E79-B68D-6309F01C5231}=c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll [06-12-22 16:02 ]
{C3231A73-A39D-47BE-A08F-A7B937A6F30B}=C:\WINNT\system32\nnlkj.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Logitech Utility"="Logi_MwX.Exe" [03-12-17 09:50 C:\WINNT\LOGI_MWX.EXE]
"InCD"="C:\Programs\Ahead\InCD\InCD.exe" [04-08-27 02:01 ]
"Tweak UI"="TWEAKUI.CPL" [96-11-08 14:33 C:\WINNT\system32\TWEAKUI.CPL]
"itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [05-12-04 16:38 ]
"Synchronization Manager"="mobsync.exe" [03-06-19 13:05 C:\WINNT\system32\mobsync.exe]
"ZoneAlarm Client"="C:\Programs\Utils\ZoneAlarm\zlclient.exe" [07-03-09 00:02 ]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Weather"="C:\PROGRA~1\AWS\WEATHE~1\WEATHER.exe" [06-01-06 09:57 ]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [06-11-07 09:29 ]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"^SetupICWDesktop"=C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSaveSettings"=00000000
"NoStartBanner"=01000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"NvMediaCenter"=RUNDLL32.EXE C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
"nwiz"=nwiz.exe /install
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*
Contents of the 'Scheduled Tasks' folder
2007-05-21 15:42:02 C:\WINNT\tasks\AppleSoftwareUpdate.job
2007-06-02 00:05:32 C:\WINNT\tasks\Daily.job
2007-06-02 00:15:14 C:\WINNT\tasks\Outlook.job
2007-05-30 00:30:38 C:\WINNT\tasks\System State.job
2007-05-31 22:25:30 C:\WINNT\tasks\CD-RW Backup.job
2007-05-30 00:45:12 C:\WINNT\tasks\Identities.job
2007-06-01 18:00:14 C:\WINNT\tasks\McQcTask.job
**************************************************************************
catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.netRootkit scan 2007-06-04 10:20:01
Windows 5.0.2195 Service Pack 4 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-06-04 10:20:27 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 07-06-04 10:20
--- E O F ---
3. HJT Log
Logfile of HijackThis v1.99.1
Scan saved at 10:22:24 AM, on 6/4/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\Programs\VPN\cvpnd.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINNT\System32\svchost.exe
C:\Programs\Ahead\InCD\InCDsrv.exe
C:\WINNT\system32\LxrJD31s.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\system32\ZONELABS\vsmon.exe
C:\WINNT\system32\CMD.EXE
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\ComboFix\19593.cfexe
C:\Programs\Ahead\InCD\InCD.exe
C:\System\Mouse\MouseWare\system\em_exec.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Programs\Utils\ZoneAlarm\zlclient.exe
C:\PROGRA~1\AWS\WEATHE~1\WEATHER.EXE
C:\Program Files\AIM6\aim6.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Programs\Utils\FileEx\FileEx.exe
C:\Programs\Utils\Corral\iconcorl.exe
C:\Programs\Utils\KeyText\KeyText.exe
C:\Programs\Utils\Moon\MoonIcon.exe
C:\Programs\Utils\PassKeep\PassKeep.exe
C:\Programs\Utils\TrayDay\TrayDay.exe
C:\Programs\Utils\PassKeep\PassKeep.exe
C:\WINNT\system32\ntvdm.exe
C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
C:\WINNT\system32\CHKDSK.EXE
C:\ComboFix\sed.cfexe
C:\WINNT\system32\CMD.EXE
C:\WINNT\system32\findstr.exe
C:\ComboFix\sed.cfexe
C:\Program Files\HijackThis\xyz.bat
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programs\Utils\SpyBot\SDHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: (no name) - {C3231A73-A39D-47BE-A08F-A7B937A6F30B} - C:\WINNT\system32\nnlkj.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [InCD] C:\Programs\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Programs\Utils\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\WEATHER.EXE 1
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - Global Startup: Outlook Express.lnk = C:\Program Files\Outlook Express\msimn.exe
O4 - Global Startup: File-Ex.lnk = C:\Programs\Utils\FileEx\FileEx.exe
O4 - Global Startup: Icon Corral.lnk = C:\Programs\Utils\Corral\iconcorl.exe
O4 - Global Startup: KeyText.lnk = C:\Programs\Utils\KeyText\KeyText.exe
O4 - Global Startup: Moon Phase Icon.lnk = C:\Programs\Utils\Moon\MoonIcon.exe
O4 - Global Startup: Password Keeper.lnk = C:\Programs\Utils\PassKeep\PassKeep.exe
O4 - Global Startup: TrayDay.lnk = C:\Programs\Utils\TrayDay\TrayDay.exe
O4 - Global Startup: OnTime.lnk = C:\Programs\OTW\OTWIN.EXE
O4 - Global Startup: VPN Client.lnk = C:\Programs\VPN\ipsecdialer.exe
O4 - Global Startup: Organizer.lnk = C:\Lotus\organize\org6.exe
O9 - Extra button: Web Entry - {B4E30F61-16D9-11D3-85D1-005004229569} - c:\lotus\organize\bandobjs.dll
O16 - DPF: {156BF4B7-AE3A-4365-BD88-95A75AF8F09D} (HPSDDX Class) -
http://www.hp.com/cpso-support-new/SDD/hpsddObjSigned.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) -
http://download.mcafee.com/molbin/shared/m...01/mcinsctl.cabO16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) -
http://download.mcafee.com/molbin/shared/m...,26/mcgdmgr.cabO23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Programs\VPN\cvpnd.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Programs\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINNT\SYSTEM32\LxrJD31s.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZONELABS\vsmon.exe