I've recently experienced mass slowdown on my computer, to the point where it will freeze for 5 minutes or so. Sometimes this would happen browsing the internet, other times merely browsing the folders on my computer. When it occured, I could turn off the laptop by no other means than removing the battery.
I decided to run all the malware stuff I had, because it had been ages since I'd done so... the result was over 200 objects deleted, which lead me to believe an infection could be the problem.
I've now followed all the steps on the sticky, and would very much appreciate any further help any of you can give me! The good news is that so far (fingers crossed), after following the steps in the sticky, the computer has been running a lot more smoothly.
Here's the Panda results:
;*******************************************************************************
*********************************************************************************
*******************
ANALYSIS: 2008-04-14 17:09:52
PROTECTIONS: 1
MALWARE: 46
SUSPECTS: 4
;*******************************************************************************
*********************************************************************************
*******************
PROTECTIONS
Description Version Active Updated
;===============================================================================
=================================================================================
===================
eTrust EZ Antivirus 7.1.8.0 Yes Yes
;===============================================================================
=================================================================================
===================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===============================================================================
=================================================================================
===================
00000431 adware/ist.istbar Adware No 1 Yes No hkey_current_user\software\microsoft\errlook
00029926 Dialer.Gen Dialers No 0 Yes No C:\Program Files\DivX\Movies\Babestation.exe
00034463 adware/wupd Adware No 0 Yes No c:\program files\mediagateway
00040527 spyware/surfsidekick Spyware No 1 Yes No c:\documents and settings\mike\local settings\temporary internet files\ssk.log
00145393 Cookie/Tradedoubler TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\cpymewib.default\cookies.txt[.tradedoubler.com/]
00145393 Cookie/Tradedoubler TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\cpymewib.default\cookies.txt[.tradedoubler.com/]
00167642 Cookie/Com.com TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\cpymewib.default\cookies.txt[.com.com/]
00167647 Cookie/Yadro TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\cpymewib.default\cookies.txt[.yadro.ru/]
00167677 Cookie/WebPower TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\cpymewib.default\cookies.txt[.webpower.com/]
00167704 Cookie/Xiti TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\cpymewib.default\cookies.txt[.xiti.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\cpymewib.default\cookies.txt[.statcounter.com/]
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\cpymewib.default\cookies.txt[ad.yieldmanager.com/]
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\cpymewib.default\cookies.txt[ad.yieldmanager.com/]
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\cpymewib.default\cookies.txt[ad.yieldmanager.com/]
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\cpymewib.default\cookies.txt[ad.yieldmanager.com/]
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\cpymewib.default\cookies.txt[ad.yieldmanager.com/]
00168061 Cookie/Apmebf TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\cpymewib.default\cookies.txt[.apmebf.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\cpymewib.default\cookies.txt[.serving-sys.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\cpymewib.default\cookies.txt[.serving-sys.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\cpymewib.default\cookies.txt[.serving-sys.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\cpymewib.default\cookies.txt[.serving-sys.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\cpymewib.default\cookies.txt[.serving-sys.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\cpymewib.default\cookies.txt[.serving-sys.com/]
00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\cpymewib.default\cookies.txt[.bs.serving-sys.com/]
00170556 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\cpymewib.default\cookies.txt[.realmedia.com/]
00170557 Cookie/Com.com TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\cpymewib.default\cookies.txt[.terra.com.br/]
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\cpymewib.default\cookies.txt[.questionmarket.com/]
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\cpymewib.default\cookies.txt[.questionmarket.com/]
00172221 Cookie/Zedo TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\cpymewib.default\cookies.txt[.zedo.com/]
00184846 Cookie/Adrevolver TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\cpymewib.default\cookies.txt[.adrevolver.com/]
00199984 Cookie/Searchportal TrackingCookie No 0 Yes No C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\cpymewib.default\cookies.txt[.searchportal.information.com/]
00217379 adware/dollarrevenue Adware No 1 Yes No c:\windows\keyboard191.dat
00219235 adware/commad Adware No 0 Yes No hkey_local_machine\system\controlset001\enum\root\legacy_network_monitor
00255160 adware/shorty Adware No 0 Yes No hkey_current_user\software\dns
00261537 Adware/Zango Adware No 0 Yes No C:\System Volume Information\_restore{C6C72350-ACB0-4062-8055-9B8A990CF9C1}\RP562\A0132962.exe
00262492 Adware/CommAd Adware No 0 Yes No C:\WINDOWS\TWlrZQ\nq5Otk.vbs
00266219 adware/yazzle Adware No 0 Yes No hkey_local_machine\software\microsoft\windows\currentversion\uninstall\yazzleactivex
00266219 adware/yazzle Adware No 0 Yes No c:\windows\downloaded program files\yazzleactivex.inf
00266219 adware/yazzle Adware No 0 Yes No HKEY_LOCAL_MACHINE\Software\Microsoft\Code Store Database\Distribution Units\{74CD40EA-EF77-4BAD-808A-B5982DA73F20}
00273493 Adware/PurityScan Adware No 0 Yes No C:\Program Files\Common Files\Yazzle1122OinAdmin.exe
00276072 Adware/YazzleSudoku Adware No 0 Yes No C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
00277553 Adware/Zango Adware No 0 Yes No C:\System Volume Information\_restore{C6C72350-ACB0-4062-8055-9B8A990CF9C1}\RP562\A0132960.exe
00277600 Adware/PurityScan Adware No 0 Yes No C:\WINDOWS\Sуmantec\сhkntfs.exe
00279708 Adware/NewAds Adware No 0 Yes No C:\Program Files\Microsoft Works\WKWAT.exe
00279708 Adware/NewAds Adware No 0 Yes No C:\Program Files\Atheros\arccsel.exe
00297769 Bck/TclockBased.A Virus/Trojan No 0 No No C:\PROGRAM FILES\TCLOCK\TCLOCK_INSTALL.EXE[tclock.exe]
00297769 Bck/TclockBased.A Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{C6C72350-ACB0-4062-8055-9B8A990CF9C1}\RP593\A0148435.exe
00297769 Bck/TclockBased.A Virus/Trojan No 0 No No C:\Program Files\TClock\tclock_install.exe[tclock.exe]
00297772 Bck/TclockBased.A Virus/Trojan No 0 Yes No C:\PROGRAM FILES\TCLOCK\TCLOCK_INSTALL.EXE
00297772 Bck/TclockBased.A Virus/Trojan No 0 Yes No C:\Program Files\TClock\tclock_install.exe
00317878 Adware/Yazzle Adware No 0 Yes No C:\WINDOWS\YAXUninst.exe
00365139 Application/MyWebSearch HackTools No 0 Yes No C:\System Volume Information\_restore{C6C72350-ACB0-4062-8055-9B8A990CF9C1}\RP589\A0143470.DLL
00516288 Application/MyWebSearch HackTools No 0 Yes No C:\System Volume Information\_restore{C6C72350-ACB0-4062-8055-9B8A990CF9C1}\RP589\A0143473.DLL
00516289 Application/MyWebSearch HackTools No 0 Yes No C:\System Volume Information\_restore{C6C72350-ACB0-4062-8055-9B8A990CF9C1}\RP589\A0143476.EXE
00516290 Application/MyWebSearch HackTools No 0 Yes No C:\System Volume Information\_restore{C6C72350-ACB0-4062-8055-9B8A990CF9C1}\RP589\A0144413.EXE
00516290 Application/MyWebSearch HackTools No 0 Yes No C:\Documents and Settings\Mike\Local Settings\Temp\temp.fr119D\bar\1.bin\M3SRCHMN.EXE
00516291 Application/MyWebSearch HackTools No 0 Yes No C:\System Volume Information\_restore{C6C72350-ACB0-4062-8055-9B8A990CF9C1}\RP589\A0143449.DLL
00516293 Application/MyWebSearch HackTools No 0 Yes No C:\System Volume Information\_restore{C6C72350-ACB0-4062-8055-9B8A990CF9C1}\RP589\A0143478.DLL
00516293 Application/MyWebSearch HackTools No 0 Yes No C:\Program Files\Mozilla Firefox\plugins\NPMyWebS.dll
01048427 Generic Malware Virus/Trojan No 0 Yes No C:\Program Files\Quark\QuarkXPress 6.0\Quark.exe
01048427 Generic Malware Virus/Trojan No 0 Yes No C:\Program Files\Quark\QuarkXPress 6.0\Quark.BAK
01048427 Generic Malware Virus/Trojan No 0 Yes No C:\Documents and Settings\Mike\My Documents\My Stuff\Programs\QUARK EXPRESS 6.0\Quark.XPress.v6.build.1341._FOR_WINDOWS_WITH.SERIAL\QuarkXPress60 Win 1341\Serial + Crack\Quark.exe
01048427 Generic Malware Virus/Trojan No 0 Yes No C:\Documents and Settings\Mike\My Documents\My Stuff\Programs\QUARK EXPRESS 6.0\QUARK EXPRESS 6.0.zip[Quark.XPress.v6.build.1341._FOR_WINDOWS_WITH.SERIAL/QuarkXPress60 Win 1341/Serial + Crack/Quark.exe]
01049070 Generic Malware Virus/Trojan No 0 Yes No C:\Program Files\Quark\QuarkXPress 6.0\Required Components\Quark1.exe
01049070 Generic Malware Virus/Trojan No 0 Yes No C:\Documents and Settings\Mike\My Documents\My Stuff\Programs\QUARK EXPRESS 6.0\Quark.XPress.v6.build.1341._FOR_WINDOWS_WITH.SERIAL\QuarkXPress60 Win 1341\Serial + Crack\Quark1.exe
01049070 Generic Malware Virus/Trojan No 0 Yes No C:\Documents and Settings\Mike\My Documents\My Stuff\Programs\QUARK EXPRESS 6.0\QUARK EXPRESS 6.0.zip[Quark.XPress.v6.build.1341._FOR_WINDOWS_WITH.SERIAL/QuarkXPress60 Win 1341/Serial + Crack/Quark1.exe]
02095979 Dialer.ISB Dialers No 1 Yes No C:\WINDOWS\system32\oobe\ISPSoftware\BTYahoo\BroadbandFromBT.exe
02870087 Trj/Downloader.RGV Virus/Trojan Yes 1 Yes No C:\WINDOWS\SYSTEM32\SYSUDISK.EXE
02885355 Adware/Zango Adware No 0 Yes No C:\Documents and Settings\Mike\My Documents\My Stuff\Programs\Setup.exe
02894799 Adware/Zango Adware No 0 Yes No C:\Program Files\Zango\bin\10.1.181.0\ZangoSA.exe
;===============================================================================
=================================================================================
===================
SUSPECTS
Sent Location 6
;===============================================================================
=================================================================================
===================
No C:\PROGRAM FILES\GREATMEMO\GREATMEMO.EXE 6
No C:\PROGRAM FILES\SHOPPINGREPORT\BIN\2.0.26\SHOPPINGREPORT.DLL 6
No C:\PROGRAM FILES\WEATHER\WEATHER.EXE 6
No C:\Documents and Settings\Mike\Application Data\Мicrosoft.NET\javaw.exe 6
;===============================================================================
=================================================================================
===================
VULNERABILITIES
Id Severity Description 6
;===============================================================================
=================================================================================
===================
;===============================================================================
=================================================================================
===================
Here's the Hijackthis Log, having run all the requested checks, etc:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:34:15, on 14/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ACS.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetMsg.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Windows Media Connect 2\WMCCFG.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\WINDOWS\system32\SysUdisk.exe
C:\Program Files\Kontiki\KHost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Program Files\TClock\TClock.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\GreatMemo\GreatMemo.exe
C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.2.4
R3 - Default URLSearchHook is missing
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ShoppingReport - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Zango /fleok=1D8A83A5C2E618769DAD612A1FBB39BFE4976E26CAEDA120180A196D6093 - {E1BACF55-35E1-4E47-9247-2D48660E5545} - C:\Program Files\Zango\bin\10.1.181.0\HostIE.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Zango - {E1BACF55-35E1-4E47-9247-2D48660E5545} - C:\Program Files\Zango\bin\10.1.181.0\HostIE.dll (file missing)
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [NI.UWA6P_0001_N73M1004] "C:\WINDOWS\TEMP\Temporary Internet Files\Content.IE5\07D2E452\WinAntiVirusPro2006FreeInstall[1].exe" -nag /BEFOREINSTALL
O4 - HKLM\..\Run: [Windows Media Connect 2] "C:\Program Files\Windows Media Connect 2\WMCCFG.exe" /StartQuiet
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [YeppStudioAgent] C:\Program Files\Samsung\SamsungMediaStudio4.1\SamsungMediaStudioAgent.exe
O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=0
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [SysUdisk.exe] C:\WINDOWS\system32\SysUdisk.exe
O4 - HKLM\..\Run: [ZangoOE] C:\Program Files\Zango\bin\10.1.181.0\OEAddOn.exe
O4 - HKLM\..\Run: [ZangoSA] "C:\Program Files\Zango\bin\10.1.181.0\ZangoSA.exe"
O4 - HKLM\..\Run: [4oD] "C:\Program Files\Kontiki\KHost.exe" -all
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [WeatherDPA] "C:\Program Files\Zango\bin\10.1.181.0\Weather.exe" -auto
O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: GreatMemo.lnk = C:\Program Files\GreatMemo\GreatMemo.exe
O4 - Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Startup: Weather.lnk = C:\Program Files\Weather\Weather.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &Search - http://edits.mywebse...?p=ZUxdm021YYGB
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll
O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoft...s/as2stubie.cab
O16 - DPF: {4EDD7E56-3BAA-13B6-D0D4-4A6A2FE914A6} - http://69.50.173.166/1/rdgGB2404.exe
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebo...toUploader3.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebo...otoUploader.cab
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.....cab?refid=1123
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zon...ro.cab32846.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zon...ss.cab31267.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - http://dlm.tools.aka...vex-2.2.1.6.cab
O20 - Winlogon Notify: Extensions - C:\WINDOWS\system32\c400ledm1h0a.dll (file missing)
O20 - Winlogon Notify: winfit32 - C:\WINDOWS\SYSTEM32\winfit32.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\ACS.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetMsg.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 13607 bytes
Thanks for your time and help!
Mike