Alright, I uninstalled all the old Javas and installed the new one as directed above. Here are the Kaspersky, OTMoveIt and HJT logs:
KASPERSKY LOG:
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Wednesday, February 11, 2009
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Wednesday, February 11, 2009 02:44:38
Records in database: 1780352
--------------------------------------------------------------------------------
Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes
Scan area - My Computer:
C:\
D:\
E:\
Scan statistics:
Files scanned: 66123
Threat name: 6
Infected objects: 10
Suspicious objects: 0
Duration of the scan: 01:37:19
File name / Threat name / Threats count
C:\Backup\01\Desktop Stuff\Programs\AGSetup0606.exe Infected: not-a-virus:AdWare.Win32.Gator.1050 1
C:\Backup\01\Desktop Stuff\Programs\AGSetup0608.exe Infected: not-a-virus:AdWare.Win32.BiSpy.ac 1
C:\Backup\01\Desktop Stuff\Programs\AGSetup0608.exe Infected: not-a-virus:AdWare.Win32.OnFlow.d 1
C:\Backup\01\Desktop Stuff\Programs\AGSetup0608.exe Infected: not-a-virus:AdWare.Win32.Gator.1050 1
C:\Documents and Settings\Administrator\DoctorWeb\Quarantine\A0042700.exe Infected: not-a-virus:Server-FTP.Win32.Serv-U.3017 1
C:\Documents and Settings\Administrator\DoctorWeb\Quarantine\susetup.exe Infected: not-a-virus:Server-FTP.Win32.Serv-U.3017 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F640000.VBN Infected: Trojan-Downloader.Java.OpenConnection.ar 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F640001.VBN Infected: Trojan-Downloader.Java.OpenConnection.ar 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F640002.VBN Infected: Exploit.Java.Gimsh.a 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F640003.VBN Infected: Exploit.Java.Gimsh.a 1
The selected area was scanned.
OTMOVEIT LOG:
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== FILES ==========
File/Folder c:\windows\system32\F1FDCABD70.sys not found.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\Arj.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\avlib.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\Avp1.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\AvpMgr.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\btimages.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\CAB.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\dmap.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\dtreg.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\FsDrvPlg.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\FSSync.dll scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\HashCont.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\HashMD5.PPL scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\HCCMP.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\ichk2.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\iChkSA.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\Inflate.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\IWGen.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\kave.dll scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\kosglue-7.0.25.0.dll scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\lha.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\L_llio.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\MailMsg.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\mdb.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\MDMAP.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\MemModSc.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\MemScan.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\minizip.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\MKavIO.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\msoe.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\nfio.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\NTFSstrm.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\prKernel.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\prLoader.dll scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\prseqio.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\PrUtil.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\Quantum.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\rar.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\ScanningProcess.exe scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\sfdb.PPL scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\TempFile.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\thpimpl.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\UniArc.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\UnLZX.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\UnStored.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\WDiskIO.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\hsperfdata_Administrator\3324 scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\hsperfdata_Administrator\3596 scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_7ac.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_be4.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
File delete failed. C:\Documents and Settings\Administrator\Application Data\Sun\Java\Deployment\cache\6.0\14\757e808e-7528103b scheduled to be deleted on reboot.
Java cache emptied.
Temp folders emptied.
Explorer started successfully
OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02112009_102719
Files moved on Reboot...
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\Arj.ppl moved successfully.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\avlib.ppl moved successfully.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\Avp1.ppl moved successfully.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\AvpMgr.ppl moved successfully.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\btimages.ppl moved successfully.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\CAB.ppl moved successfully.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\dmap.ppl moved successfully.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\dtreg.ppl moved successfully.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\FsDrvPlg.ppl moved successfully.
DllUnregisterServer procedure not found in C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\FSSync.dll
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\FSSync.dll NOT unregistered.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\FSSync.dll moved successfully.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\HashCont.ppl moved successfully.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\HashMD5.PPL moved successfully.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\HCCMP.ppl moved successfully.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\ichk2.ppl moved successfully.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\iChkSA.ppl moved successfully.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\Inflate.ppl moved successfully.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\IWGen.ppl moved successfully.
DllUnregisterServer procedure not found in C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\kave.dll
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\kave.dll NOT unregistered.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\kave.dll moved successfully.
DllUnregisterServer procedure not found in C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\kosglue-7.0.25.0.dll
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\kosglue-7.0.25.0.dll NOT unregistered.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\kosglue-7.0.25.0.dll moved successfully.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\lha.ppl moved successfully.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\L_llio.ppl moved successfully.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\MailMsg.ppl moved successfully.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\mdb.ppl moved successfully.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\MDMAP.ppl moved successfully.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\MemModSc.ppl moved successfully.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\MemScan.ppl moved successfully.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\minizip.ppl moved successfully.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\MKavIO.ppl moved successfully.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\msoe.ppl moved successfully.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\nfio.ppl moved successfully.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\NTFSstrm.ppl moved successfully.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\prKernel.ppl moved successfully.
DllUnregisterServer procedure not found in C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\prLoader.dll
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\prLoader.dll NOT unregistered.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\prLoader.dll moved successfully.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\prseqio.ppl moved successfully.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\PrUtil.ppl moved successfully.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\Quantum.ppl moved successfully.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\rar.ppl moved successfully.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\ScanningProcess.exe moved successfully.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\sfdb.PPL moved successfully.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\TempFile.ppl moved successfully.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\thpimpl.ppl moved successfully.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\UniArc.ppl moved successfully.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\UnLZX.ppl moved successfully.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\UnStored.ppl moved successfully.
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\jkos-Administrator\binaries\WDiskIO.ppl moved successfully.
File C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\hsperfdata_Administrator\3324 not found!
File C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\hsperfdata_Administrator\3596 not found!
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
File C:\WINDOWS\temp\Perflib_Perfdata_7ac.dat not found!
File C:\WINDOWS\temp\Perflib_Perfdata_be4.dat not found!
C:\Documents and Settings\Administrator\Application Data\Sun\Java\Deployment\cache\6.0\14\757e808e-7528103b moved successfully.
HJT LOG:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:38:30 AM, on 2/11/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft SQL Server\MSSQL$ACT7\Binn\sqlservr.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\AccelerometerSt.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\WINDOWS\SMINST\Scheduler.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\WINDOWS\system32\hphmon03.exe
C:\Program Files\ACT\ACT for Windows\Act8.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Documents and Settings\Administrator\Desktop\HiJackThis\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://windowsupdate.microsoft.com/O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Act.UI.InternetExplorer.Plugins.AttachFile.CAttachFile - {D5233FCD-D258-4903-89B8-FB1568E7413D} - mscoree.dll (file missing)
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [AccelerometerSysTrayApplet] C:\WINDOWS\system32\AccelerometerSt.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\Sminst\Recguard.exe
O4 - HKLM\..\Run: [Reminder] C:\WINDOWS\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [Scheduler] C:\WINDOWS\SMINST\Scheduler.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\system32\hphmon03.exe
O4 - HKLM\..\Run: [Act! Preloader] "C:\Program Files\ACT\ACT for Windows\Act8.exe" -stayrunning
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MaxMenuMgr] "C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Attach Web page to ACT! contact - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra 'Tools' menuitem: Attach Web page to ACT! contact... - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.mi...b?1190578224890O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.mi...b?1191777544218O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) -
http://download.eset...lineScanner.cabO16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) -
https://join-test.we...bex/ieatgpc.cabO17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = CapitolRealtyServices.com
O17 - HKLM\Software\..\Telephony: DomainName = CapitolRealtyServices.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{D245ED96-FBB3-43B4-9421-A47030385714}: NameServer = 192.168.200.1
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = CapitolRealtyServices.com
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: PC Angel (PCA) - SoftThinks - C:\WINDOWS\SMINST\PCAngel.exe
O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
--
End of file - 10339 bytes
Thanks!