Right, here's first the Combo Log file, then another HijackThis Log file, both run in safe mode.
"Steve" - 07-01-31 19:54:07 Service Pack 2
ComboFix 07.01.31 - Running from: "E:\Task manager problem"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\vbuzip10.dll
C:\WINDOWS\system32\drivers\npf.sys
((((((((((((((((((((((((((((((( Files Created from 2006-12-31 to 2007-01-31 ))))))))))))))))))))))))))))))))))
2007-01-31 19:46 <DIR> d-------- C:\Program Files\RegistryFix
2007-01-30 17:35 <DIR> d-------- C:\Program Files\Hijackthis
2007-01-28 22:28 <DIR> d-------- C:\WINDOWS\LastGood
2007-01-28 17:03 <DIR> d-------- C:\DOCUME~1\Steve\DoctorWeb
2007-01-28 00:09 1,079,808 --a------ C:\WINDOWS\system32\AutoPartNt.exe
2007-01-27 17:12 <DIR> d-------- C:\Program Files\SymNetDrv
2007-01-27 16:37 <DIR> d-------- C:\DOCUME~1\NETWOR~1\Application Data\Symantec
2007-01-27 16:17 34,578 --a------ C:\WINDOWS\system32\drivers\NPDRIVER.SYS
2007-01-27 16:16 2,397 --a------ C:\WINDOWS\system32\drivers\symlcbrd.sys
2007-01-27 16:15 91,904 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2007-01-27 16:15 124,016 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-01-27 16:15 <DIR> d-------- C:\Program Files\Symantec
2007-01-27 16:15 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2007-01-27 16:15 <DIR> d-------- C:\DOCUME~1\Steve\Application Data\Symantec
2007-01-27 16:15 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Symantec
2007-01-27 11:48 <DIR> d-------- C:\DOCUME~1\Steve\Application Data\Gena01
2007-01-25 23:10 <DIR> d--h----- C:\WINDOWS\XPize
2007-01-25 23:09 <DIR> d-------- C:\Program Files\Zuma Deluxe
2007-01-25 23:09 <DIR> d-------- C:\Program Files\Winamp
2007-01-25 23:08 <DIR> d-------- C:\Program Files\win32pad_1_5_10
2007-01-25 23:08 <DIR> d-------- C:\Program Files\VMware
2007-01-25 23:08 <DIR> d-------- C:\DOCUME~1\XPPRESP3\Application Data\Gena01
2007-01-25 23:06 568,850 --a------ C:\WINDOWS\system32\x264vfw.dll
2007-01-25 23:06 5,120 --a------ C:\WINDOWS\system32\ff_vfw.dll
2007-01-25 23:06 286,720 --a------ C:\WINDOWS\system32\3ivxVfWCodec.dll
2007-01-25 23:06 157,696 --a------ C:\WINDOWS\system32\unrar.dll
2007-01-25 23:06 1,415,680 --a------ C:\WINDOWS\system32\WMV9VCM.dll
2007-01-25 23:06 1,024,000 --a------ C:\WINDOWS\system32\3ivx.dll
2007-01-25 23:06 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2007-01-25 23:06 <DIR> d-------- C:\Program Files\Internet Download Manager
2007-01-25 23:06 <DIR> d-------- C:\Program Files\CCleaner
2007-01-25 23:06 <DIR> d-------- C:\DOCUME~1\Steve\Application Data\bsplayer
2007-01-18 20:49 40,960 --a------ C:\WINDOWS\system32\vbalFlBr6.dll
2007-01-18 20:49 40,960 --a------ C:\WINDOWS\system\vbalFlBr6.dll
2007-01-18 20:26 143,360 --a------ C:\WINDOWS\system\vbuzip10.dll
2007-01-18 20:25 143,360 --a------ C:\vbuzip10.dll
2007-01-18 20:22 <DIR> d-------- C:\Program Files\Chilkat Software Inc
2007-01-18 00:22 <DIR> d-------- C:\smiley
2007-01-17 17:58 <DIR> d-------- C:\CAPWIN
2007-01-17 17:56 796,672 --a------ C:\WINDOWS\GPInstall.exe
2007-01-16 19:41 <DIR> d-------- C:\testfolder
2007-01-15 22:23 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2007-01-15 21:23 <DIR> d-------- C:\Program Files\XStandard
2007-01-15 18:05 <DIR> d-------- C:\XStandard
2007-01-15 08:22 <DIR> d-------- C:\Program Files\Microsoft SQL Server 2005 Mobile Edition
2007-01-15 08:22 <DIR> d-------- C:\Program Files\Microsoft Device Emulator
2007-01-15 08:09 <DIR> d-------- C:\Program Files\MSBuild
2007-01-15 08:01 <DIR> d-------- C:\WINDOWS\Symbols
2007-01-15 08:01 <DIR> d-------- C:\Program Files\HTML Help Workshop
2007-01-15 08:01 <DIR> d-------- C:\Program Files\Common Files\Business Objects
2007-01-15 08:01 <DIR> d-------- C:\Program Files\CE Remote Tools
2007-01-15 08:01 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\PreEmptive Solutions
2007-01-15 07:55 <DIR> d-------- C:\Program Files\Microsoft Visual Studio 8
2007-01-15 07:55 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Microsoft Help
2007-01-13 21:57 <DIR> d-------- C:\Program Files\DVDFab Platinum 3
2007-01-12 23:56 66,048 --a------ C:\WINDOWS\system32\agcmn.dll
2007-01-12 23:56 50,880 --a------ C:\WINDOWS\system32\agproxy.dll
2007-01-12 23:56 47,936 --a------ C:\WINDOWS\system32\wgrs.dll
2007-01-12 23:56 43,824 --a------ C:\WINDOWS\system32\agprtcl.dll
2007-01-12 23:56 42,368 --a------ C:\WINDOWS\system32\agconnct.dll
2007-01-12 23:56 416,000 --a------ C:\WINDOWS\system32\agsnet.dll
2007-01-12 23:56 40,712 --a------ C:\WINDOWS\system32\agcrypto.dll
2007-01-12 23:56 34,592 --a------ C:\WINDOWS\system32\agnet.dll
2007-01-12 23:56 34,464 --a------ C:\WINDOWS\system32\agcehdlr.dll
2007-01-12 23:56 25,152 --a------ C:\WINDOWS\system32\agcncmn.dll
2007-01-12 23:56 146,736 --a------ C:\WINDOWS\system32\agclcmn.dll
2007-01-12 23:56 111,376 --a------ C:\WINDOWS\system32\expat.dll
2007-01-12 21:40 143,360 --a------ C:\WINDOWS\system32\Unzip32.dll
2007-01-12 21:40 143,360 --a------ C:\WINDOWS\system\Unzip32.dll
2007-01-12 21:40 133,120 --a------ C:\WINDOWS\system32\zip32.dll
2007-01-12 21:40 133,120 --a------ C:\WINDOWS\system\zip32.dll
2007-01-09 22:42 <DIR> d-------- C:\WINDOWS\ie7updates
2007-01-09 19:32 <DIR> d-------- C:\DOCUME~1\Steve\Application Data\DivX
2007-01-09 19:24 20,640 --------- C:\WINDOWS\system32\drivers\PxHelp20.sys
2007-01-09 19:24 109,568 --------- C:\WINDOWS\system32\pxinsi64.exe
2007-01-09 19:24 108,544 --------- C:\WINDOWS\system32\pxcpyi64.exe
2007-01-09 19:14 13,560 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
2007-01-09 19:09 639,224 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2007-01-08 23:44 <DIR> d-------- C:\DOCUME~1\Steve\Application Data\Nero
2007-01-08 22:56 <DIR> d-------- C:\Program Files\vso3
2007-01-08 21:10 87,608 --a------ C:\DOCUME~1\Steve\Application Data\ezpinst.exe
2007-01-08 21:10 47,360 --a------ C:\DOCUME~1\Steve\Application Data\pcouffin.sys
2007-01-08 21:10 <DIR> d-------- C:\Program Files\vso2
2007-01-08 21:10 <DIR> d-------- C:\DOCUME~1\Steve\Application Data\Vso
2007-01-08 20:35 <DIR> d-------- C:\Program Files\ImTOO
2007-01-08 20:33 <DIR> d-------- C:\Program Files\Apollo DivX to DVD Creator
2007-01-08 20:27 <DIR> d-------- C:\Program Files\Easy Avi Divx Xvid to DVD Burner
2007-01-08 20:23 692,224 --a------ C:\WINDOWS\system32\ciaResSvr20.dll
2007-01-08 20:23 53,248 --a------ C:\WINDOWS\system32\ciaXPRegSvr20.DLL
2007-01-08 20:23 40,960 --a------ C:\WINDOWS\system32\ciaSubClsSvr.DLL
2007-01-08 20:15 <DIR> d-------- C:\Program Files\Smart DVD CD Burner
2007-01-06 22:18 <DIR> d-------- C:\Program Files\Anton Tomov
2007-01-02 21:19 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-01-31 19:47 -------- d-------- C:\Program Files\plaxo
2007-01-27 11:12 -------- d-------- C:\Program Files\microsoft activesync
2007-01-27 10:48 -------- d-------- C:\Program Files\tweaknow powerpack 2006
2007-01-21 15:55 -------- d-------- C:\Program Files\divx
2007-01-17 19:01 -------- d-------- C:\Program Files\avantgo
2007-01-16 23:27 56 -r-hs---- C:\WINDOWS\system32\ea3d9152f0.sys
2007-01-15 18:07 -------- d---s---- C:\DOCUME~1\Steve\Application Data\microsoft
2007-01-15 08:28 -------- d-------- C:\Program Files\microsoft sql server
2007-01-15 08:25 -------- d-------- C:\Program Files\microsoft.net
2007-01-15 08:08 -------- d-------- C:\Program Files\Common Files\merge modules
2007-01-15 00:32 -------- d-------- C:\Program Files\Common Files\adobe
2007-01-15 00:30 -------- d-------- C:\DOCUME~1\Steve\Application Data\adobe
2007-01-14 23:43 -------- d-------- C:\Program Files\epson print cd
2007-01-14 23:42 -------- d-------- C:\DOCUME~1\Steve\Application Data\copytodvd
2007-01-12 23:56 -------- d--h----- C:\Program Files\installshield installation information
2007-01-09 00:58 -------- d-------- C:\DOCUME~1\Steve\Application Data\ahead
2007-01-08 21:10 7824 --a------ C:\DOCUME~1\Steve\Application Data\pcouffin.cat
2007-01-08 21:10 47360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys
2007-01-08 21:10 34 --a------ C:\DOCUME~1\Steve\Application Data\pcouffin.log
2007-01-08 21:10 1144 --a------ C:\DOCUME~1\Steve\Application Data\pcouffin.inf
2007-01-08 21:10 -------- d-------- C:\Program Files\vso
2007-01-07 18:10 -------- d-------- C:\Program Files\wm recorder 10
2007-01-07 18:03 -------- d-------- C:\Program Files\msi
2007-01-02 21:23 -------- d-------- C:\Program Files\windows media connect 2
2006-12-27 10:17 -------- d-------- C:\Program Files\plato dvd to pocket pc converter
2006-12-27 01:50 -------- d-------- C:\Program Files\pqdvd
2006-12-26 16:21 -------- d-------- C:\Program Files\compact flash gps card
2006-12-26 14:18 2508 --a------ C:\DOCUME~1\Steve\Application Data\$_hpcst$.hpc
2006-12-12 16:30 520192 --a------ C:\WINDOWS\system32\divxsm.exe
2006-12-12 16:30 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2006-12-12 16:30 200704 --a------ C:\WINDOWS\system32\ssldivx.dll
2006-12-12 16:30 1044480 --a------ C:\WINDOWS\system32\libdivx.dll
2006-12-12 16:25 806912 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2006-12-12 16:25 806912 --a------ C:\WINDOWS\system32\divx_xx07.dll
2006-12-12 16:25 790528 --a------ C:\WINDOWS\system32\divx_xx11.dll
2006-12-12 16:25 73728 --a------ C:\WINDOWS\system32\dpl100.dll
2006-12-12 16:25 635486 --a------ C:\WINDOWS\system32\divx.dll
2006-12-12 16:25 593920 --a------ C:\WINDOWS\system32\dpugui11.dll
2006-12-12 16:25 57344 --a------ C:\WINDOWS\system32\dpv11.dll
2006-12-12 16:25 53248 --a------ C:\WINDOWS\system32\dpugui10.dll
2006-12-12 16:25 344064 --a------ C:\WINDOWS\system32\dpus11.dll
2006-12-12 16:25 294912 --a------ C:\WINDOWS\system32\dpu11.dll
2006-12-12 16:25 294912 --a------ C:\WINDOWS\system32\dpu10.dll
2006-12-12 16:25 196608 --a------ C:\WINDOWS\system32\dtu100.dll
2006-12-12 16:24 12288 --a------ C:\WINDOWS\system32\divxwmpexttype.dll
2006-12-12 16:24 118784 --a------ C:\WINDOWS\system32\divxcodecupdatechecker.exe
2006-12-08 00:22 -------- d-------- C:\Program Files\dvd2one v2
2006-12-02 17:53 -------- d-------- C:\Program Files\code advisor for visual basic 6
2006-12-02 17:52 -------- d-------- C:\Program Files\Common Files\wise installation wizard
2006-12-02 12:27 -------- d-------- C:\Program Files\Common Files\installshield
2006-11-20 08:42 33280 --a------ C:\WINDOWS\system32\snmp.exe
2006-11-08 05:06 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-11-07 21:03 6049280 --------- C:\WINDOWS\system32\ieframe.dll
2006-11-07 21:03 50688 --------- C:\WINDOWS\system32\msfeedsbs.dll
2006-11-07 21:03 458752 --------- C:\WINDOWS\system32\msfeeds.dll
2006-11-07 21:03 413696 --a------ C:\WINDOWS\system32\vbscript.dll
2006-11-07 21:03 231424 --a------ C:\WINDOWS\system32\webcheck.dll
2006-11-07 21:03 180736 --------- C:\WINDOWS\system32\ieui.dll
2006-11-07 21:03 156160 --a------ C:\WINDOWS\system32\msls31.dll
2006-11-07 03:27 382976 --a------ C:\WINDOWS\system32\iedkcs32.dll
2006-11-07 03:27 229376 --a------ C:\WINDOWS\system32\ieaksie.dll
2006-11-07 03:26 71680 --a------ C:\WINDOWS\system32\admparse.dll
2006-11-07 03:26 55296 --a------ C:\WINDOWS\system32\iesetup.dll
2006-11-07 03:26 54784 --a------ C:\WINDOWS\system32\ie4uinit.exe
2006-11-07 03:26 43008 --a------ C:\WINDOWS\system32\iernonce.dll
2006-11-07 03:26 152064 --a------ C:\WINDOWS\system32\ieakeng.dll
2006-11-07 03:26 13312 --a------ C:\WINDOWS\system32\ieudinit.exe
2006-11-07 03:26 123904 --a------ C:\WINDOWS\system32\advpack.dll
2006-11-07 03:25 161792 --a------ C:\WINDOWS\system32\ieakui.dll
2006-11-04 20:25 1321744 --a------ C:\WINDOWS\system32\msxml6.dll
2006-11-04 14:14 1245696 --a------ C:\WINDOWS\system32\msxml4.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"ATI Scheduler"="C:\\Program Files\\ATI Multimedia\\main\\ATISched.EXE"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"PlaxoUpdate"="C:\\Program Files\\Plaxo\\2.11.1.5\\PlaxoHelper.exe -a"
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="\"C:\\Program Files\\Common Files\\Ahead\\lib\\NMBgMonitor.exe\""
"H/PC Connection Agent"="\"C:\\PROGRA~1\\MI3AA1~1\\wcescomm.exe\""
"WMPNSCFG"="C:\\Program Files\\Windows Media Player\\WMPNSCFG.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"Zone Labs Client"="C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe"
"OSSelectorReinstall"="C:\\Program Files\\Common Files\\Acronis\\Acronis Disk Director\\oss_reinstall.exe"
"TrueImageMonitor.exe"="C:\\Program Files\\Acronis\\TrueImage\\TrueImageMonitor.exe"
"Acronis Scheduler2 Service"="\"C:\\Program Files\\Common Files\\Acronis\\Schedule2\\schedhlp.exe\""
"ISUSPM Startup"="C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\UPDATE~1\\ISUSPM.exe -startup"
"ISUSScheduler"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe\" -start"
"Acrobat Assistant 7.0"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Distillr\\Acrotray.exe\""
"ATICCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe\" runtime -Delay"
"SoundMan"="SOUNDMAN.EXE"
"EPSON Stylus Photo RX640 Series"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_FATIAME.EXE /P31 \"EPSON Stylus Photo RX640 Series\" /O6 \"USB001\" /M \"Stylus Photo RX640\""
"EEventManager"="C:\\Program Files\\EPSON\\Creativity Suite\\Event Manager\\EEventManager.exe"
"NWEReboot"=""
"InCD"="C:\\Program Files\\Nero\\Nero 7\\InCD\\InCD.exe"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"Advanced Tools Check"="D:\\PROGRA~1\\NORTON~1\\AdvTools\\ADVCHK.EXE"
"Symantec NetDriver Monitor"="C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe /Consumer"
"WinPatrol"="C:\\Program Files\\BillP Studios\\WinPatrol\\winpatrol.exe"
"KernelFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,\
65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b,00
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"appinit_dlls"="pushow42.dll"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{54D9498B-CF93-414F-8984-8CE7FDE0D391}"="ewido shell guard"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"ALUAlert"="C:\\Program Files\\Symantec\\LiveUpdate\\ALUNotify.exe"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"ALUAlert"="C:\\Program Files\\Symantec\\LiveUpdate\\ALUNotify.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"=dword:00000001
"NoRemoteRecursiveEvents"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDesktop"=dword:00000000
"NoViewContextMenu"=dword:00000000
"NoSaveSettings"=dword:00000000
"NoSharedDocuments"=hex:00,00,00,00
"NoRecentDocsMenu"=dword:00000001
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\taskmgr.exe]
"Debugger"="C:\\WINDOWS\\procexp.exe"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\append.job
C:\WINDOWS\tasks\defrag.job
C:\WINDOWS\tasks\Event 1.job
C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer.job
C:\WINDOWS\tasks\Symantec NetDetect.job
Completion time: 07-01-31 19:58:03
Now Hijackthis Log file:
Logfile of HijackThis v1.99.1
Scan saved at 20:15:59, on 31/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {02DCA195-602B-4B1F-83FF-381B7E804BDB} - C:\WINDOWS\system32\HDBHO.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [OSSelectorReinstall] C:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall.exe
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [EPSON Stylus Photo RX640 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAME.EXE /P31 "EPSON Stylus Photo RX640 Series" /O6 "USB001" /M "Stylus Photo RX640"
O4 - HKLM\..\Run: [EEventManager] C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] D:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ATI Scheduler] C:\Program Files\ATI Multimedia\main\ATISched.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\2.11.1.5\PlaxoHelper.exe -a
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\PROGRA~1\MI3AA1~1\wcescomm.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: RC.exe.lnk = C:\Program Files\DTV\DVB-T USB 2.0\RC.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.EXE
O4 - Global Startup: PC Alert 4.lnk = C:\Program Files\MSI\PC Alert 4\PCAlert4.exe
O8 - Extra context menu item: &Search -
http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZNxmk571YYGB
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) -
https://www-secure.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) -
https://www-secure.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {08BEF711-06DA-48B2-9534-802ECAA2E4F9} (PlxInstall Class) -
https://www.plaxo.com/down/latest/PlaxoInstall.cab
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) -
https://signup.msn.com/pages/MsnInstC.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) -
https://www-secure.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {4E330863-6A11-11D0-BFD8-006097237877} (InstallFromTheWeb ActiveX Control) -
http://tw.msi.com.tw/autobios/client/iftwclix.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1136051890234
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1135990190406
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) -
https://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O20 - AppInit_DLLs: pushow42.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodata Limited License Service - Autodata Limited - C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: LiveUpdate - Unknown owner - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~2.EXE (file missing)
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - D:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - D:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: SAVScan - Symantec Corporation - D:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Any Help?
Stevo.