Thanks very much!!! Here are the latest logs:
================================
ComboFix log:
ComboFix 08-03-17.1 - Administrator 2008-03-18 21:23:37.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.719 [GMT -4:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Administrator\Desktop\CFScript.txt
* Created a new restore point
FILE ::
C:\WINDOWS\system32\oqonpasl.ini
.
TimeOut - Windir.dat
TimeOut - progfile.dat
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\oqonpasl.ini
.
---- Previous Run -------
.
C:\WINDOWS\BM174fffee.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\aabdctds.dll
C:\WINDOWS\system32\atnewxwt.ini
C:\WINDOWS\system32\biwcwhmm.dll
C:\WINDOWS\system32\brphcrgy.ini
C:\WINDOWS\system32\dfhkj.ini
C:\WINDOWS\system32\dfhkj.ini2
C:\WINDOWS\system32\ewfohfin.dll
C:\WINDOWS\system32\fgjlm.ini
C:\WINDOWS\system32\fgjlm.ini2
C:\WINDOWS\system32\kphbshua.dll
C:\WINDOWS\system32\kvcplduw.dll
C:\WINDOWS\system32\npqss.ini
C:\WINDOWS\system32\npqss.ini2
C:\WINDOWS\system32\qkyhvuuf.dll
C:\WINDOWS\system32\rpjtojvl.dll
C:\WINDOWS\system32\twxwenta.dll
C:\WINDOWS\system32\utstv.ini
C:\WINDOWS\system32\utstv.ini2
C:\WINDOWS\system32\xiemnrct.dll
C:\WINDOWS\system32\xkvwrtqm.dll
C:\WINDOWS\system32\ygrchprb.dll
C:\WINDOWS\system32\yqayhfyo.dll
C:\WINDOWS\system32\yyadd.ini
C:\WINDOWS\system32\yyadd.ini2
.
((((((((((((((((((((((((( Files Created from 2008-02-19 to 2008-03-19 )))))))))))))))))))))))))))))))
.
2008-03-17 22:09 . 2008-03-17 22:09 <DIR> d-------- C:\WINDOWS\ERUNT
2008-03-17 22:00 . 2008-03-17 22:26 <DIR> d-------- C:\SDFix
2008-03-17 20:29 . 2008-03-17 21:58 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-03-17 09:44 . 2008-03-17 09:44 <DIR> d-------- C:\Program Files\CCleaner
2008-03-16 20:06 . 2008-03-16 20:06 <DIR> d-------- C:\Program Files\Trend Micro
2008-03-16 02:00 . 2008-03-16 02:00 0 --a------ C:\WINDOWS\system32\SBRC.dat
2008-03-16 02:00 . 2008-03-16 02:00 0 --a------ C:\WINDOWS\system32\SBFC.dat
2008-03-14 17:34 . 2008-03-15 05:42 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-03-14 12:31 . 2008-03-15 13:45 <DIR> d-------- C:\QUARANTINE
2008-03-14 12:26 . 2007-10-24 01:47 282,112 --a------ C:\WINDOWS\system32\TBD43.tmp
2008-03-14 09:49 . 2008-03-14 09:49 <DIR> d-------- C:\Program Files\MSBuild
2008-03-14 09:25 . 2008-03-18 06:56 <DIR> d-------- C:\WINDOWS\system32\XPSViewer
2008-03-14 09:17 . 2008-03-14 09:17 <DIR> d-------- C:\Program Files\Reference Assemblies
2008-03-14 09:12 . 2006-06-29 13:07 14,048 --a------ C:\WINDOWS\system32\spmsg2.dll
2008-03-14 09:03 . 2008-03-14 09:03 <DIR> d-------- C:\Program Files\Common Files\Cisco Systems
2008-03-14 09:03 . 2008-03-14 09:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2008-03-14 09:03 . 2006-12-19 15:06 1,495,552 --a------ C:\WINDOWS\system32\epoPGPsdk.dll
2008-03-14 09:03 . 2006-12-19 15:06 280 --a------ C:\WINDOWS\system32\epoPGPsdk.dll.sig
2008-03-14 09:02 . 2007-08-13 20:50 171,240 --a------ C:\WINDOWS\system32\drivers\mfehidk.sys
2008-03-14 09:02 . 2007-08-13 20:50 72,712 --a------ C:\WINDOWS\system32\drivers\mfeavfk.sys
2008-03-14 09:02 . 2007-09-07 20:50 64,168 --a------ C:\WINDOWS\system32\drivers\mfeapfk.sys
2008-03-14 09:02 . 2007-08-13 20:50 52,200 --a------ C:\WINDOWS\system32\drivers\mfetdik.sys
2008-03-14 09:02 . 2007-08-13 20:50 34,184 --a------ C:\WINDOWS\system32\drivers\mfebopk.sys
2008-03-14 09:00 . 2008-03-14 09:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2008-03-14 08:59 . 2008-03-14 09:03 <DIR> d-------- C:\Program Files\McAfee
2008-03-14 08:59 . 2008-03-14 08:59 <DIR> d-------- C:\Program Files\Common Files\McAfee
2008-03-14 08:53 . 2006-11-13 02:02 288,768 --a------ C:\WINDOWS\system32\rhttpaa.dll
2008-03-14 08:53 . 2006-11-13 02:02 116,736 --a------ C:\WINDOWS\system32\aaclient.dll
2008-03-14 08:53 . 2006-11-13 02:02 36,352 --a------ C:\WINDOWS\system32\tsgqec.dll
2008-03-13 09:39 . 2008-03-13 09:39 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-03-12 15:19 . 2008-03-12 15:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\logs
2008-03-12 09:53 . 2008-03-12 09:53 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-03-12 09:40 . 2008-03-12 09:40 15,544 --a------ C:\WINDOWS\system32\drivers\sbhr.sys
2008-03-12 09:37 . 2008-03-12 09:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Sunbelt Software
2008-03-12 09:37 . 2008-03-12 09:37 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Sunbelt Software
2008-03-12 09:34 . 2008-03-12 09:34 <DIR> d-------- C:\Program Files\Sunbelt Software
2008-03-12 09:09 . 2008-03-12 09:41 <DIR> d-------- C:\Program Files\Exterminate It!
2008-03-10 10:08 . 2008-03-10 10:12 <DIR> d-------- C:\Program Files\CD Wave
2008-03-10 10:03 . 2008-03-10 10:03 <DIR> d-------- C:\Program Files\OpD2d
2008-03-10 09:58 . 2006-02-09 15:10 471,040 --a------ C:\WINDOWS\system32\SkinCrafter.dll
2008-03-10 09:58 . 2002-01-05 23:37 344,064 --a------ C:\WINDOWS\system32\msvcr70.dll
2008-03-10 09:58 . 2000-12-07 02:02 209,608 --a------ C:\WINDOWS\system32\TABCTL32.OCX
2008-03-10 09:58 . 2001-03-14 03:49 140,288 --a------ C:\WINDOWS\system32\comdlg32.ocx
2008-03-10 09:58 . 2004-11-12 11:14 36,864 --a------ C:\WINDOWS\system32\SCLabel.ocx
2008-03-09 18:02 . 2008-03-10 09:49 <DIR> d-------- C:\Program Files\Audacity
2008-03-09 17:22 . 2008-03-09 18:01 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Audacity
2008-03-09 17:09 . 2004-08-03 23:07 59,264 --a------ C:\WINDOWS\system32\drivers\USBAUDIO.sys
2008-03-09 17:09 . 2004-08-03 23:07 59,264 --a--c--- C:\WINDOWS\system32\dllcache\usbaudio.sys
2008-03-09 17:09 . 2004-08-04 00:56 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2008-03-09 17:09 . 2004-08-04 00:56 21,504 --a--c--- C:\WINDOWS\system32\dllcache\hidserv.dll
2008-03-09 17:09 . 2001-08-17 14:02 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2008-03-09 17:09 . 2001-08-17 14:02 9,600 --a--c--- C:\WINDOWS\system32\dllcache\hidusb.sys
2008-03-08 13:02 . 2008-03-08 13:02 <DIR> d-------- C:\Program Files\Paint.NET
2008-03-07 11:05 . 2008-03-07 11:05 <DIR> d-------- C:\WINDOWS\Freecorder Toolbar
2008-03-07 11:05 . 2008-03-07 11:05 <DIR> d-------- C:\Program Files\Freecorder Toolbar
2008-03-07 11:05 . 2008-03-16 19:43 <DIR> d-------- C:\Program Files\Freecorder
2008-03-07 11:04 . 2008-03-07 11:04 <DIR> d-------- C:\Program Files\Real
2008-03-07 10:46 . 2008-03-07 10:46 <DIR> d-------- C:\Program Files\Torrent Harvester
2008-03-05 10:35 . 2004-08-04 00:10 48,128 --a------ C:\WINDOWS\system32\drivers\61883.sys
2008-03-05 10:35 . 2004-08-04 00:10 48,128 --a--c--- C:\WINDOWS\system32\dllcache\61883.sys
2008-03-05 10:35 . 2004-08-04 00:10 38,912 --a------ C:\WINDOWS\system32\drivers\avc.sys
2008-03-05 10:35 . 2004-08-04 00:10 38,912 --a--c--- C:\WINDOWS\system32\dllcache\avc.sys
2008-03-05 09:44 . 2008-03-05 10:23 <DIR> d-------- C:\Program Files\Mojave
2008-03-05 09:44 . 1999-03-30 18:58 220,482 --a------ C:\WINDOWS\system32\DrvAgent.dll
2008-03-05 09:44 . 1999-04-30 17:39 196,096 --a------ C:\WINDOWS\system32\AgentCD.sys
2008-03-05 09:44 . 1999-03-30 19:00 191,304 --a------ C:\WINDOWS\system32\AgentCD.vxd
2008-03-05 09:44 . 1999-03-30 18:58 179,007 --a------ C:\WINDOWS\system32\DaConfig.dll
2008-03-05 09:34 . 2008-03-05 09:34 <DIR> d-------- C:\WINDOWS\system32\Dell
2008-03-04 21:31 . 2008-03-04 21:31 <DIR> d-------- C:\Program Files\RADVideo
2008-03-02 11:18 . 2008-03-02 17:53 <DIR> d-------- C:\Program Files\Ubisoft
2008-03-01 20:13 . 2008-03-01 20:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\{B9DFDEF4-3471-4379-BDBB-DEDA8A9809DF}
2008-03-01 20:11 . 2008-03-01 20:11 <DIR> d-------- C:\Program Files\Sports Mogul
2008-03-01 09:08 . 2008-03-01 09:16 <DIR> d-------- C:\Program Files\Free Net TV and Radio Player
2008-02-29 08:35 . 2008-02-29 08:35 <DIR> d-------- C:\KodakFW
2008-02-28 22:26 . 2008-02-28 22:26 <DIR> d-------- C:\Program Files\Sony
2008-02-26 18:55 . 2008-02-26 18:55 <DIR> d-------- C:\Program Files\SanDisk
2008-02-26 18:55 . 2008-02-26 18:55 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\InstallShield
2008-02-20 16:57 . 2008-02-23 20:58 <DIR> d-------- C:\HammerAutosave
2008-02-20 15:52 . 2008-02-20 15:52 <DIR> d-------- C:\Program Files\Citrix
2008-02-20 15:52 . 2008-02-20 15:56 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\ICAClient
2008-02-20 15:35 . 2008-03-02 13:17 <DIR> d-------- C:\Program Files\Steam
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-03-12 18:00 --------- d-----w C:\Program Files\Java
2008-03-12 12:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-03-11 19:22 --------- d-----w C:\Documents and Settings\Administrator\Application Data\uTorrent
2008-03-10 13:58 --------- d-----w C:\Program Files\Common Files\Download Manager
2008-03-05 13:44 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-19 11:51 --------- d-----w C:\Program Files\Handbrake
2008-02-18 14:17 --------- d-----w C:\Program Files\DVDRipSys
2008-02-14 13:32 --------- d-----w C:\Documents and Settings\Administrator\Application Data\1ClickDVDCopy
2008-02-02 16:52 --------- d-----w C:\Program Files\FLAC
2008-02-02 16:45 --------- d-----w C:\Program Files\Common Files\Ahead
2008-02-02 16:45 --------- d-----w C:\Program Files\Ahead
2008-01-24 02:08 --------- d-----w C:\Program Files\Real Alternative
2008-01-21 19:32 --------- d-----w C:\Program Files\Allok Video to FLV Converter
2008-01-20 17:08 --------- d-----w C:\Program Files\EphPod
2008-01-20 15:14 --------- d-----w C:\Program Files\Abbie's Sleep Timer for iTunes
2008-01-20 01:49 --------- d-----w C:\Program Files\Gilligames
2008-01-20 00:04 --------- d-----w C:\Program Files\1Click DVD to Divx Avi
2008-01-19 23:33 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Nero8
2008-01-05 03:50 737,280 ----a-w C:\WINDOWS\iun6002.exe
.
((((((((((((((((((((((((((((( snapshot@2008-03-17_22.55.55.95 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-03-18 02:03:09 346,608 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-03-19 01:13:49 346,608 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
- 2008-03-18 02:23:22 67,936 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-03-19 01:19:55 67,936 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-03-18 02:23:22 432,172 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-03-19 01:19:55 432,172 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-03-19 01:29:51 40,960 ----a-w C:\WINDOWS\Temp\rtdrvmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 17:46 1460560]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe" [2007-09-20 16:35 202024]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]
"FolderShare"="C:\Program Files\FolderShare\FolderShare.exe" [2005-10-30 23:12 851968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2003-10-06 15:16 5058560]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 10:51 1836328]
"Lexmark X74-X75"="C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe" [2002-10-14 16:09 57344]
"LVCOMS"="C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE" [2002-06-10 15:21 102400]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 16:57 153136]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"dvd43"="C:\Program Files\dvd43\dvd43_tray.exe" [2007-11-20 17:40 731136]
"SBCSTray"="C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe" [2007-12-21 15:30 698864]
"SpyHunter Security Suite"="C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe" [2008-01-23 14:47 847872]
"ShStatEXE"="C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.exe" [2007-08-13 20:50 111952]
"McAfeeUpdaterUI"="C:\Program Files\McAfee\Common Framework\UdaterUI.exe" [2006-12-19 11:27 136768]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2007-09-19 05:33:46 282624]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 12:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Common Files\\Nero\\Nero Web\\SetupX.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\FolderShare\\FolderShare.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Steam\\SteamApps\\bubbaw\\source sdk base\\hl2.exe"=
"C:\\Program Files\\Steam\\SteamApps\\bubbaw\\condition zero\\hl.exe"=
"C:\\Program Files\\Steam\\SteamApps\\bubbaw\\half-life\\hl.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
"C:\\Program Files\\Red Chair Software\\Anapod Explorer\\anamgr.exe"=
R0 SBHR;SBHR;C:\WINDOWS\system32\drivers\sbhr.sys [2008-03-12 09:40]
R2 agentcd

riverAgent Class Driver;C:\WINDOWS\system32\AgentCD.sys [1999-04-30 17:39]
R3 LVBulk;LVBulk Service;C:\WINDOWS\system32\DRIVERS\LVBulk.sys [2002-06-10 15:21]
R3 PID_0900_V;Logitech ClickSmart 310(PID_0900_V);C:\WINDOWS\system32\DRIVERS\LV551A V.sys [2002-06-10 15:24]
R3 pnicII;Linksys Fast Ethernet PCI Card;C:\WINDOWS\system32\DRIVERS\lne100.SYS [2001-08-17 08:12]
R3 SBAPIFS;SBAPIFS;C:\WINDOWS\system32\drivers\sbapif s.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{9c98b2d3-bade-11dc-ba13-806d6172696f}]
\Shell\AutoRun\command - D:\autoRcd.exe
*Newly Created Service* - SBAPIFS
.
Contents of the 'Scheduled Tasks' folder
"2008-01-05 00:00:32 C:\WINDOWS\Tasks\EasyShare Registration Task.job"
- C:\WINDOWS\System32\rundll32.exelC:\DOCUME~1\ALLUS E~1\APPLIC~1\Kodak\EasyShareSetup\$REGIS~1\Registr ation_7.5.30.2.sxt
_RegistrationOffer@16
"2008-03-18 06:15:01 C:\WINDOWS\Tasks\SpyHunter Scanner.job"
- C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
.
************************************************** ************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-18 21:30:17
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
.
************************************************** ************************
.
Completion time: 2008-03-18 21:35:50 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-19 01:35:40
.
2008-03-18 10:59:40 --- E O F ---
===============================
HijackThis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:40:08 PM, on 3/18/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
https://exchange.syr.edu/exchange/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
Live Search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
Live Search
R3 - URLSearchHook: (no name) - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\Scriptcl.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [SBCSTray] C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
O4 - HKLM\..\Run: [SpyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [FolderShare] "C:\Program Files\FolderShare\FolderShare.exe" /background
O4 - Startup: Anapod Manager.lnk = C:\Program Files\Red Chair Software\Anapod Explorer\anamgr.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) -
http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/wind...?1199485231692
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/micr...?1199485372052
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
--
End of file - 6822 bytes
================================
Your help has been invaluable!!! I"m very appreciative. Am I home free?
AR Wenner