| Hi this is the error message i get when trying to run bullguard "The ordinal 2381 could not be located in the dynamic link library MFC80U.DLL
here is my combofix log
ComboFix 08-03-01 - Nancy 2008-02-29 13:44:51.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.680 [GMT -5:00] Running from: E:\Documents and Settings\Nancy\Desktop\ComboFix.exe * Created a new restore point
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color] .
((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) .
E:\WINDOWS\system32\_000003_.tmp.dll E:\WINDOWS\system32\_000006_.tmp.dll E:\WINDOWS\system32\_000007_.tmp.dll E:\WINDOWS\system32\_000008_.tmp.dll E:\WINDOWS\system32\_000010_.tmp.dll E:\WINDOWS\system32\_000011_.tmp.dll E:\WINDOWS\system32\_000013_.tmp.dll
. ((((((((((((((((((((((((( Files Created from 2008-02-01 to 2008-03-01 ))))))))))))))))))))))))))))))) .
2008-02-29 12:32 . 2008-02-29 12:32 <DIR> d-------- E:\Program Files\SUPERAntiSpyware 2008-02-29 12:32 . 2008-02-29 12:32 <DIR> d-------- E:\Documents and Settings\Nancy\Application Data\SUPERAntiSpyware.com 2008-02-29 12:32 . 2008-02-29 12:32 <DIR> d-------- E:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com 2008-02-29 12:31 . 2004-08-04 02:56 388,608 --a------ E:\CF7902.exe 2008-02-29 12:26 . 2008-02-29 12:26 <DIR> d-------- E:\Program Files\CCleaner 2008-02-29 12:18 . 2008-02-29 12:18 <DIR> d-------- E:\Program Files\MSN Games 2008-02-29 12:18 . 2008-02-29 12:20 <DIR> d-a------ E:\Documents and Settings\All Users\Application Data\TEMP 2008-02-29 11:45 . 2008-02-29 11:45 <DIR> d-------- E:\Program Files\ReflexiveArcade 2008-02-29 11:41 . 2008-02-29 11:41 <DIR> d-------- E:\Documents and Settings\Nancy\Application Data\Uniblue 2008-02-29 10:07 . 2006-02-03 14:21 1,079,808 --a------ E:\WINDOWS\system32\mfc80u.dll 2008-02-29 10:04 . 2008-02-29 10:04 <DIR> d-------- E:\Program Files\Uniblue 2008-02-29 10:04 . 2008-02-29 10:04 <DIR> d-------- E:\Documents and Settings\Debbie\Application Data\Uniblue 2008-02-28 21:34 . 2008-02-28 21:34 22 --a------ E:\WINDOWS\iexplore.ini 2008-02-28 19:02 . 2008-02-28 19:02 <DIR> d-------- E:\MicroGaming 2008-02-24 18:55 . 2008-02-24 18:55 <DIR> d-------- E:\Documents and Settings\All Users\Application Data\MumboJumbo 2008-02-24 09:30 . 2008-02-24 09:30 227 --a------ E:\WINDOWS\HP_CounterReport_Update_HPSU.ini 2008-02-24 09:30 . 2008-02-24 09:30 214 --a------ E:\WINDOWS\HP_48BitScanUpdatePatch.ini 2008-02-24 09:26 . 2008-02-24 09:26 234 --a------ E:\WINDOWS\PrnHlpLogConfig.ini 2008-02-24 09:26 . 2008-02-24 09:26 217 --a------ E:\WINDOWS\HP_IZClosingDiscErrorPatch.ini 2008-02-24 09:26 . 2008-02-24 09:26 214 --a------ E:\WINDOWS\HP_InstantSHareJPG.ini 2008-02-24 09:25 . 2008-02-24 09:25 221 --a------ E:\WINDOWS\HP_RedboxHprblog_HPSU.ini 2008-02-22 21:46 . 2008-02-22 21:46 <DIR> d-------- E:\Program Files\MSXML 4.0 2008-02-22 21:22 . 2008-02-22 21:22 <DIR> d-------- E:\Program Files\BullGuard Software 2008-02-22 21:22 . 2008-02-22 23:44 <DIR> d-------- E:\Documents and Settings\Debbie\Application Data\BullGuard 2008-02-22 21:22 . 2008-02-23 11:11 <DIR> d-------- E:\Documents and Settings\All Users\Application Data\BullGuard 2008-02-22 21:22 . 2003-09-12 10:08 55,888 --a------ E:\WINDOWS\system32\drivers\Teefer.sys 2008-02-22 21:22 . 2003-09-12 10:08 18,515 --a------ E:\WINDOWS\system32\drivers\wpsdrvnt.sys 2008-02-22 21:22 . 2003-09-12 10:08 11,914 --a------ E:\WINDOWS\system32\drivers\wg3n.sys 2008-02-22 21:05 . 2008-02-22 21:05 <DIR> d-------- E:\Program Files\MumboJumbo 2008-02-22 20:53 . 2007-08-01 13:05 765,952 --a------ E:\WINDOWS\system32\xvidcore.dll 2008-02-22 20:53 . 2007-08-01 13:05 180,224 --a------ E:\WINDOWS\system32\xvidvfw.dll 2008-02-22 20:53 . 2007-08-01 13:05 77,824 --a------ E:\WINDOWS\system32\xvid.ax 2008-02-22 20:43 . 2008-02-22 20:43 <DIR> d-------- E:\Documents and Settings\Debbie\Application Data\InstallShield 2008-02-22 08:33 . 2008-02-22 08:33 <DIR> d-------- E:\Documents and Settings\All Users\Application Data\HP 2008-02-22 08:32 . 2008-02-22 08:32 <DIR> d-------- E:\Program Files\Common Files\Sonic Shared 2008-02-22 08:32 . 2008-02-22 08:32 <DIR> d-------- E:\Documents and Settings\All Users\Application Data\Sonic 2008-02-22 08:31 . 2008-02-22 08:32 <DIR> d-------- E:\Program Files\Common Files\HP 2008-02-22 08:30 . 2008-02-22 08:30 <DIR> d-------- E:\Program Files\Hewlett-Packard 2008-02-22 08:29 . 2008-02-22 08:29 <DIR> d-------- E:\Program Files\Common Files\Hewlett-Packard 2008-02-22 08:29 . 2007-01-19 11:46 49,920 --a------ E:\WINDOWS\system32\drivers\HPZid412.sys 2008-02-22 08:29 . 2007-01-19 11:46 16,496 --a------ E:\WINDOWS\system32\drivers\HPZipr12.sys 2008-02-22 08:28 . 2005-03-15 14:36 77,824 -ra------ E:\WINDOWS\system32\hpzids01.dll 2008-02-22 08:28 . 2005-05-05 08:51 37,376 --a------ E:\WINDOWS\system32\hpz3l3xu.dll 2008-02-22 08:28 . 2005-10-21 19:52 21,568 --a------ E:\WINDOWS\system32\drivers\HPZius12.sys 2008-02-22 08:28 . 2004-08-04 00:58 15,104 --a------ E:\WINDOWS\system32\drivers\usbscan.sys 2008-02-22 08:28 . 2004-08-04 00:58 15,104 --a--c--- E:\WINDOWS\system32\dllcache\usbscan.sys 2008-02-22 08:27 . 2004-09-29 12:12 278,584 --a------ E:\WINDOWS\system32\HPZidr12.dll 2008-02-22 08:27 . 2004-09-29 12:15 204,800 --a------ E:\WINDOWS\system32\HPZipr12.dll 2008-02-22 08:27 . 2004-09-29 12:09 94,208 --a------ E:\WINDOWS\system32\HPZipt12.dll 2008-02-22 08:27 . 2007-08-09 02:27 73,728 --a------ E:\WINDOWS\system32\HPZipm12.exe 2008-02-22 08:27 . 2004-09-29 12:08 61,440 --a------ E:\WINDOWS\system32\HPZinw12.exe 2008-02-22 08:27 . 2004-09-29 12:09 57,344 --a------ E:\WINDOWS\system32\HPZisn12.dll 2008-02-22 08:26 . 2008-02-22 08:33 <DIR> d-------- E:\Program Files\HP 2008-02-22 08:26 . 2004-08-04 01:08 26,496 --a--c--- E:\WINDOWS\system32\dllcache\usbstor.sys 2008-02-22 08:26 . 2004-08-04 01:01 25,856 --a------ E:\WINDOWS\system32\drivers\usbprint.sys 2008-02-22 08:26 . 2004-08-04 01:01 25,856 --a--c--- E:\WINDOWS\system32\dllcache\usbprint.sys 2008-02-22 08:22 . 2008-02-22 08:22 <DIR> d-------- E:\Documents and Settings\Debbie\Application Data\HP 2008-02-22 08:22 . 2008-02-22 08:34 88,398 --a------ E:\WINDOWS\hpoins06.dat 2008-02-22 08:22 . 2005-06-02 22:31 5,389 --------- E:\WINDOWS\hpomdl06.dat 2008-02-22 08:21 . 2008-02-22 08:21 392,320 --a------ E:\WINDOWS\system32\drivers\timntr.sys 2008-02-22 08:21 . 2008-02-22 08:21 120,992 --a------ E:\WINDOWS\system32\drivers\snapman.sys 2008-02-22 08:21 . 2008-02-22 08:21 32,768 --a------ E:\WINDOWS\system32\drivers\tifsfilt.sys 2008-02-22 08:20 . 2008-02-22 08:20 <DIR> d-------- E:\Program Files\Maxtor 2008-02-22 08:20 . 2008-02-22 08:21 <DIR> d-------- E:\Program Files\Common Files\Maxtor 2008-02-22 08:18 . 2008-02-22 08:18 <DIR> d-------- E:\Program Files\Seagate 2008-02-22 08:18 . 2008-02-29 12:32 <DIR> d-------- E:\Program Files\Common Files\Wise Installation Wizard 2008-02-22 08:16 . 2008-02-23 11:28 <DIR> d-------- E:\Program Files\Microsoft Works 2008-02-22 08:06 . 2008-02-22 08:06 <DIR> d-------- E:\Program Files\MSXML 6.0 2008-02-22 07:34 . 2007-12-06 21:21 6,066,176 -----c--- E:\WINDOWS\system32\dllcache\ieframe.dll 2008-02-22 07:34 . 2007-06-30 22:31 2,455,488 -----c--- E:\WINDOWS\system32\dllcache\ieapfltr.dat 2008-02-22 07:34 . 2007-06-30 22:36 991,232 -----c--- E:\WINDOWS\system32\dllcache\ieframe.dll.mui 2008-02-22 07:34 . 2007-12-06 21:21 459,264 -----c--- E:\WINDOWS\system32\dllcache\msfeeds.dll 2008-02-22 07:34 . 2007-12-06 21:21 383,488 -----c--- E:\WINDOWS\system32\dllcache\ieapfltr.dll 2008-02-22 07:34 . 2007-12-06 21:21 267,776 -----c--- E:\WINDOWS\system32\dllcache\iertutil.dll 2008-02-22 07:34 . 2007-12-06 21:21 63,488 -----c--- E:\WINDOWS\system32\dllcache\icardie.dll 2008-02-22 07:34 . 2007-12-06 21:21 52,224 -----c--- E:\WINDOWS\system32\dllcache\msfeedsbs.dll 2008-02-22 07:34 . 2007-12-06 06:00 13,824 -----c--- E:\WINDOWS\system32\dllcache\ieudinit.exe 2008-02-22 07:31 . 2007-08-13 18:54 33,792 --a--c--- E:\WINDOWS\system32\dllcache\custsat.dll 2008-02-22 07:28 . 2008-02-22 07:28 <DIR> d-------- E:\Program Files\MSBuild 2008-02-22 07:23 . 2008-02-22 08:10 <DIR> d-------- E:\WINDOWS\system32\XPSViewer 2008-02-22 07:23 . 2008-02-22 07:23 <DIR> d-------- E:\Program Files\Reference Assemblies 2008-02-22 07:22 . 2008-02-22 07:22 <DIR> d-------- E:\526dcc98f9d0e7b1c8f6a1 2008-02-22 07:22 . 2006-06-29 13:07 14,048 --------- E:\WINDOWS\system32\spmsg2.dll 2008-02-22 07:19 . 2008-02-22 07:19 <DIR> d-------- E:\Program Files\Windows Media Connect 2 2008-02-22 07:19 . 2006-10-04 09:06 1,197,294 -----c--- E:\WINDOWS\system32\dllcache\sysmain.sdb 2008-02-22 07:19 . 2006-10-04 09:06 764,868 -----c--- E:\WINDOWS\system32\dllcache\apph_sp.sdb 2008-02-22 07:19 . 2006-10-04 09:06 217,118 -----c--- E:\WINDOWS\system32\dllcache\apphelp.sdb 2008-02-22 07:18 . 2008-02-22 07:18 <DIR> d-------- E:\WINDOWS\system32\LogFiles 2008-02-22 07:18 . 2008-02-22 07:18 <DIR> d-------- E:\WINDOWS\system32\drivers\UMDF 2008-02-22 07:18 . 2008-02-22 07:18 <DIR> d-------- E:\Users 2008-02-22 07:18 . 2008-02-22 07:18 <DIR> d-------- E:\d2c68025371dd9187d8e8c 2008-02-22 07:18 . 2008-02-22 07:18 <DIR> d-------- E:\274035f0fc7fe893e72e091c499735c5 2008-02-22 07:06 . 2006-11-13 01:02 288,768 --------- E:\WINDOWS\system32\rhttpaa.dll 2008-02-22 07:06 . 2006-11-13 01:02 116,736 --------- E:\WINDOWS\system32\aaclient.dll 2008-02-22 07:06 . 2006-11-13 01:02 36,352 --------- E:\WINDOWS\system32\tsgqec.dll 2008-02-22 07:03 . 2007-07-09 08:16 582,656 -----c--- E:\WINDOWS\system32\dllcache\rpcrt4.dll 2008-02-22 07:02 . 2005-10-20 17:20 1,082,368 --a------ E:\WINDOWS\system32\SET209.tmp 2008-02-22 06:57 . 2008-02-22 06:57 <DIR> d-------- E:\WINDOWS\system32\Lang 2008-02-22 06:57 . 2008-02-22 06:57 940,794 --a------ E:\WINDOWS\system32\LoopyMusic.wav 2008-02-22 06:57 . 2008-02-22 06:57 146,650 --a------ E:\WINDOWS\system32\BuzzingBee.wav
. (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-02-26 23:43 155,995 ----a-w E:\WINDOWS\java\Packages\171J1JXV.ZIP 2008-02-23 01:55 --------- d--h--w E:\Program Files\InstallShield Installation Information 2008-02-22 11:53 --------- d-----w E:\Program Files\Common Files\InstallShield 2008-02-22 10:39 --------- d-----w E:\Program Files\EuroTool 2008-02-22 10:16 315,392 ----a-w E:\WINDOWS\HideWin.exe 2008-02-22 10:16 --------- d-----w E:\Program Files\ITE 2008-02-22 10:15 --------- d-----w E:\Program Files\Driver 2008-02-22 10:14 --------- d-----w E:\Program Files\VIA 2008-02-22 10:04 --------- d-----w E:\Program Files\microsoft frontpage 2005-05-12 04:36 12,288 ----a-w E:\WINDOWS\Fonts\RandFont.dll .
((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="E:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360] "MSMSGS"="E:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208] "SUPERAntiSpyware"="E:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-02-28 14:23 1481968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="E:\WINDOWS\System32\NvCpl.dll" [2007-03-07 08:49 8425472] "nwiz"="nwiz.exe" [2007-03-07 08:49 1622016 E:\WINDOWS\system32\nwiz.exe] "NvMediaCenter"="E:\WINDOWS\System32\NvMcTray.dll" [2007-03-07 08:49 81920] "RTHDCPL"="RTHDCPL.EXE" [2007-06-13 14:49 16377344 E:\WINDOWS\RTHDCPL.exe] "zBrowser Launcher"="E:\Program Files\Logitech\iTouch\iTouch.exe" [2001-10-09 01:59 200704] "EM_EXEC"="E:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE" [2001-10-09 09:41 35328] "MaxBlastMonitor.exe"="E:\Program Files\Maxtor\MaxBlast\MaxBlastMonitor.exe" [2007-04-20 07:59 1169720] "AcronisTimounterMonitor"="E:\Program Files\Maxtor\MaxBlast\TimounterMonitor.exe" [2007-04-20 08:09 1945712] "Acronis Scheduler2 Service"="E:\Program Files\Common Files\Maxtor\Schedule2\schedhlp.exe" [2007-04-20 08:03 149024] "HP Software Update"="E:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 23:12 49152]
E:\Documents and Settings\All Users\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - E:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 23:23:26 282624] HP Image Zone Fast Start.lnk - E:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2005-05-12 00:49:24 73728] Microsoft Works Calendar Reminders.lnk - E:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [1999-09-04 17:23:00 53317]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= E:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] E:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 E:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Authentication Packages REG_MULTI_SZ msv1_0 relog_ap
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"= "E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"= "E:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"= "E:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"= "E:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"= "E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"= "E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"= "E:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"= "E:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"= "E:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"= "E:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"= "E:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"= "E:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"= "E:\\Users\\Public\\Phantom EFX\\OnlineCasino\\Bin\\Prelauncher.exe"= "E:\\Users\\Public\\Phantom EFX\\OnlineCasino\\Launcher\\OLCLauncher.exe"=
R0 ViBus;ViBus;E:\WINDOWS\system32\DRIVERS\ViBus.sys [2007-03-26 15:26] R0 videX32;videX32;E:\WINDOWS\system32\DRIVERS\videX32.sys [2007-03-29 11:36] R0 ViPrt;VIA SATA IDE Device Driver;E:\WINDOWS\system32\DRIVERS\ViPrt.sys [2007-03-26 15:26] R1 BIOS;BIOS;E:\WINDOWS\System32\drivers\BIOS.sys [2005-03-16 01:23] R3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service;E:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2007-02-27 03:14] R3 LCcfltr;Logitech USB Filter Driver;E:\WINDOWS\system32\drivers\lccfltr.sys [2001-11-30 04:42] S3 FileSpy5;BullGuard File Monitor;E:\Program Files\BullGuard Software\BullGuard\filespy5.sys [2008-02-23 11:16] S3 Reconn;BullGuard Email Monitor;E:\Program Files\BullGuard Software\BullGuard\reconn.sys [2008-02-23 11:16]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bg5 REG_MULTI_SZ BGMainSvc BsFileSpy BsMailProxy BsFirewall
. **************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2008-03-01 13:48:09 Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully hidden files: 0
************************************************************************** . ------------------------ Other Running Processes ------------------------ . E:\Program Files\Common Files\Maxtor\Schedule2\schedul2.exe E:\WINDOWS\System32\nvsvc32.exe E:\WINDOWS\system32\RUNDLL32.EXE E:\Program Files\Logitech\iTouch\kbdtray.exe E:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe E:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe . ************************************************************************** . Completion time: 2008-03-01 13:49:52 - machine was rebooted [Nancy] ComboFix-quarantined-files.txt 2008-03-01 18:49:50 . 2008-02-29 14:57:59 --- E O F ---
here is my HJT log
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 1:51:42 PM, on 3/1/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16608) Boot mode: Normal
Running processes: E:\WINDOWS\System32\smss.exe E:\WINDOWS\system32\winlogon.exe E:\WINDOWS\system32\services.exe E:\WINDOWS\system32\lsass.exe E:\WINDOWS\system32\svchost.exe E:\WINDOWS\System32\svchost.exe E:\WINDOWS\system32\spoolsv.exe E:\Program Files\Common Files\Maxtor\Schedule2\schedul2.exe E:\WINDOWS\System32\svchost.exe E:\WINDOWS\System32\nvsvc32.exe E:\WINDOWS\system32\RUNDLL32.EXE E:\WINDOWS\RTHDCPL.EXE E:\Program Files\Logitech\iTouch\iTouch.exe E:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE E:\Program Files\Maxtor\MaxBlast\MaxBlastMonitor.exe E:\Program Files\Maxtor\MaxBlast\TimounterMonitor.exe E:\Program Files\Common Files\Maxtor\Schedule2\schedhlp.exe E:\Program Files\HP\HP Software Update\HPWuSchd2.exe E:\WINDOWS\system32\ctfmon.exe E:\Program Files\Messenger\msmsgs.exe E:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe E:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe E:\Program Files\Logitech\iTouch\kbdtray.exe E:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe E:\WINDOWS\System32\svchost.exe E:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe E:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe E:\WINDOWS\explorer.exe E:\WINDOWS\system32\wuauclt.exe E:\WINDOWS\system32\notepad.exe E:\Program Files\Internet Explorer\IEXPLORE.EXE E:\Documents and Settings\Nancy\Local Settings\Temporary Internet Files\Content.IE5\TFHEKH11\HiJackThis[1].exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE E:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE E:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [zBrowser Launcher] E:\Program Files\Logitech\iTouch\iTouch.exe O4 - HKLM\..\Run: [EM_EXEC] E:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE O4 - HKLM\..\Run: [MaxBlastMonitor.exe] E:\Program Files\Maxtor\MaxBlast\MaxBlastMonitor.exe O4 - HKLM\..\Run: [AcronisTimounterMonitor] E:\Program Files\Maxtor\MaxBlast\TimounterMonitor.exe O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "E:\Program Files\Common Files\Maxtor\Schedule2\schedhlp.exe" O4 - HKLM\..\Run: [HP Software Update] E:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKCU\..\Run: [ctfmon.exe] E:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "E:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [SUPERAntiSpyware] E:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = E:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O4 - Global Startup: HP Image Zone Fast Start.lnk = E:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ? O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1203675012890O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/bingame/chnz/default/mjolauncher.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cabO16 - DPF: {C86FF4B0-AA1D-46D4-8612-025FB86583C7} (AstoundLauncher Control) - http://zone.msn.com/bingame/jobo/default/AstoundLauncher.cab#version=1,0,0,10O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabO20 - Winlogon Notify: !SASWinLogon - E:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - E:\Program Files\Common Files\Maxtor\Schedule2\schedul2.exe O23 - Service: BullGuard LiveUpdate (BGLiveSvc) - BullGuard Software - E:\Program Files\BullGuard Software\BullGuard\BullGuardUpdate.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - E:\WINDOWS\System32\nvsvc32.exe O23 - Service: Pml Driver HPZ12 - HP - E:\WINDOWS\system32\HPZipm12.exe
-- End of file - 5349 bytes
any help would be nice. |