thank you very much. i ran ewido, and here are the logs:
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 12:01:52 PM, 8/2/2005
+ Report-Checksum: A7D8286A
+ Scan result:
HKLM\SOFTWARE\tsvcin -> Spyware.Look2Me : Cleaned with backup
HKU\S-1-5-21-2073824365-825305547-733396139-1005\Software\LQ -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\ebrown\Cookies\ebrown@trafficmp[2].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\ebrown\Cookies\
[email protected][2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\ebrown\Local Settings\Temp\temp.frE8E2\EliteToolBar version 60.dll -> Spyware.EliteBar : Cleaned with backup
C:\old hard drive\Program Files\Hotbar\bin\4.3.6.0\HbHostOE.dll -> Spyware.HotBar : Cleaned with backup
C:\old hard drive\Program Files\Hotbar\bin\4.3.9.0\hbhostoe.dll -> Spyware.HotBar : Cleaned with backup
C:\old hard drive\Program Files\MySearch\bar\1.bin\NPMYSRCH.DLL -> Spyware.MyWay : Cleaned with backup
C:\old hard drive\Program Files\MySearch\bar\1.bin\S4BAR.DLL -> Spyware.MyWay : Cleaned with backup
C:\old hard drive\Program Files\MyWebSearch\bar\2.bin\MWSOEMON.EXE -> Spyware.MyWebSearch : Cleaned with backup
C:\old hard drive\Program Files\MyWebSearch\bar\2.bin\MWSOEPLG.DLL -> Spyware.MyWebSearch : Cleaned with backup
C:\old hard drive\WINDOWS\Downloaded Program Files\OTXMedia.dll -> Spyware.OTXMedia : Cleaned with backup
C:\old hard drive\WINDOWS\Profiles\e brown\Cookies\anyuser@mysearch[1].txt -> Spyware.Cookie.Mysearch : Cleaned with backup
C:\old hard drive\WINDOWS\Profiles\e brown\Cookies\
[email protected][1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\old hard drive\WINDOWS\Profiles\e brown\Cookies\
[email protected][1].txt -> Spyware.Cookie.Link4ads : Cleaned with backup
C:\old hard drive\WINDOWS\Profiles\e brown\Cookies\
[email protected][2].txt -> Spyware.Cookie.Link4ads : Cleaned with backup
C:\old hard drive\WINDOWS\Profiles\e brown\Cookies\
[email protected][3].txt -> Spyware.Cookie.Link4ads : Cleaned with backup
C:\old hard drive\WINDOWS\Profiles\e brown\Cookies\
[email protected][2].txt -> Spyware.Cookie.Porntrack : Cleaned with backup
C:\old hard drive\WINDOWS\Profiles\e brown\Cookies\
[email protected][1].txt -> Spyware.Cookie.Porntrack : Cleaned with backup
C:\old hard drive\WINDOWS\Profiles\e brown\Cookies\
[email protected][1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\old hard drive\WINDOWS\Profiles\e brown\Cookies\
[email protected][2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\old hard drive\WINDOWS\Profiles\e brown\Cookies\
[email protected][3].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\old hard drive\WINDOWS\Profiles\e brown\Cookies\
[email protected][2].txt -> Spyware.Cookie.Adbutler : Cleaned with backup
C:\old hard drive\WINDOWS\Profiles\e brown\Cookies\
[email protected][2].txt -> Spyware.Cookie.247media : Cleaned with backup
C:\old hard drive\WINDOWS\Profiles\e brown\Cookies\default@preferences[2].txt -> Spyware.Cookie.Preferences : Cleaned with backup
C:\old hard drive\WINDOWS\Profiles\e brown\Cookies\
[email protected][2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\old hard drive\WINDOWS\Profiles\e brown\Cookies\
[email protected][1].txt -> Spyware.Cookie.Porntrack : Cleaned with backup
C:\old hard drive\WINDOWS\Profiles\e brown\Cookies\
[email protected][1].txt -> Spyware.Cookie.Porntrack : Cleaned with backup
C:\old hard drive\WINDOWS\Profiles\e brown\Cookies\
[email protected][1].txt -> Spyware.Cookie.Porntrack : Cleaned with backup
C:\old hard drive\WINDOWS\Profiles\e brown\Cookies\
[email protected][1].txt -> Spyware.Cookie.Excite : Cleaned with backup
C:\old hard drive\WINDOWS\Profiles\e brown\Cookies\
[email protected][1].txt -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup
C:\old hard drive\WINDOWS\Profiles\e brown\Cookies\
[email protected][1].txt -> Spyware.Cookie.Popuptraffic : Cleaned with backup
C:\old hard drive\WINDOWS\Profiles\e brown\Cookies\e
[email protected][2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\old hard drive\WINDOWS\Profiles\e brown\Cookies\e brown@abetterinternet[2].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\old hard drive\WINDOWS\Profiles\e brown\Cookies\e
[email protected][2].txt -> Spyware.Cookie.Ru4 : Cleaned with backup
C:\old hard drive\WINDOWS\Profiles\e brown\Cookies\e
[email protected][1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\old hard drive\WINDOWS\Profiles\e brown\Cookies\e brown@specificpop[1].txt -> Spyware.Cookie.Specificpop : Cleaned with backup
C:\old hard drive\WINDOWS\Profiles\e brown\Cookies\e brown@trafficmp[1].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\old hard drive\WINDOWS\Profiles\e brown\Cookies\e
[email protected][1].txt -> Spyware.Cookie.Enigmasoftwaregroup : Cleaned with backup
C:\old hard drive\WINDOWS\Profiles\e brown\Cookies\e
[email protected][1].txt -> Spyware.Cookie.Enigmasoftwaregroup : Cleaned with backup
C:\old hard drive\WINDOWS\Profiles\e brown\Cookies\msantiago@2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\old hard drive\WINDOWS\Profiles\e brown\Cookies\msantiago@abetterinternet[1].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\old hard drive\WINDOWS\Profiles\e brown\Cookies\msantiago@abetterinternet[3].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\old hard drive\WINDOWS\Profiles\e brown\Cookies\
[email protected][1].txt -> Spyware.Cookie.Trafficvenue : Cleaned with backup
C:\old hard drive\WINDOWS\Profiles\e brown\Cookies\msantiago@hypertracker[2].txt -> Spyware.Cookie.Hypertracker : Cleaned with backup
C:\old hard drive\WINDOWS\Profiles\e brown\Cookies\msantiago@mysearch[1].txt -> Spyware.Cookie.Mysearch : Cleaned with backup
C:\old hard drive\WINDOWS\Profiles\e brown\Cookies\msantiago@specificpop[2].txt -> Spyware.Cookie.Specificpop : Cleaned with backup
C:\old hard drive\WINDOWS\Profiles\e brown\Cookies\msantiago@trafficmp[2].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\old hard drive\WINDOWS\Profiles\e brown\Cookies\msantiago@trafficmp[4].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\old hard drive\WINDOWS\Profiles\e brown\Cookies\msantiago@trafficvenue[1].txt -> Spyware.Cookie.Trafficvenue : Cleaned with backup
C:\old hard drive\WINDOWS\Profiles\e brown\Cookies\
[email protected][1].txt -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup
C:\Program Files\Ftk\ftk.dll -> Spyware.FlashEnhancer : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP373\A0023141.exe -> Spyware.AdURL : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP374\A0023260.dll -> Adware.eZula : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP374\A0023268.exe -> Spyware.VirtualBouncer : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP374\A0023270.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP374\A0023273.exe -> Spyware.Couponage : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP377\A0023290.exe -> Spyware.VirtualBouncer : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP377\A0023295.dll -> Spyware.FlashEnhancer : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP377\A0023313.dll -> Spyware.VirtualBouncer : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP377\A0023314.dll -> Spyware.VirtualBouncer : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP377\A0023315.dll -> Spyware.VirtualBouncer : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP377\A0023316.dll -> Spyware.VirtualBouncer : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP377\A0023320.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP377\A0023329.exe -> Adware.eZula : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP377\A0023330.exe -> TrojanDownloader.Delmed.a : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP377\A0023331.exe -> Adware.eZula : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP377\A0023332.exe -> TrojanDownloader.Delmed.a : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP377\A0023339.dll -> Spyware.FlashEnhancer : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP377\A0023342.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP377\A0023362.dll -> Spyware.FlashEnhancer : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP377\A0023364.exe -> Spyware.Zestyfind : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP377\A0023365.exe -> Spyware.AdURL : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP380\A0023385.dll -> Spyware.FlashEnhancer : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP381\A0023423.dll -> Spyware.FlashEnhancer : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP382\A0023463.dll -> Spyware.FlashEnhancer : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP383\A0023478.dll -> Spyware.FlashEnhancer : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP383\A0023487.dll -> Spyware.FlashEnhancer : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP383\A0023493.dll -> Spyware.FlashEnhancer : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP383\A0023503.dll -> Spyware.FlashEnhancer : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP383\A0023509.dll -> Spyware.FlashEnhancer : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP385\A0023559.dll -> Spyware.FlashEnhancer : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP386\A0023599.DLL -> Spyware.ClearSearch : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP386\A0023615.dll -> Spyware.NewDotNet : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP386\A0023617.dll -> Spyware.NewDotNet : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP386\A0023618.exe -> Spyware.NewDotNet : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP386\A0023628.exe -> Spyware.NewDotNet : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP386\A0023633.exe -> Adware.SAHA : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP386\A0023640.exe -> Adware.SAHA : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP386\A0023643.exe -> Spyware.Delfin : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP386\A0023645.ocx -> Spyware.Delfin : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP386\A0023646.dll -> Spyware.Delfin : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP386\A0023651.dll -> Spyware.FlashEnhancer : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP386\A0023658.dll -> Spyware.FlashEnhancer : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP387\A0023689.dll -> Spyware.FlashEnhancer : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP389\A0023775.dll -> Spyware.FlashEnhancer : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP390\A0023805.dll -> Spyware.FlashEnhancer : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP390\A0023836.dll -> Spyware.FlashEnhancer : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP391\A0023860.dll -> Spyware.FlashEnhancer : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP392\A0023884.dll -> Spyware.FlashEnhancer : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP393\A0023921.dll -> Spyware.FlashEnhancer : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP394\A0023967.dll -> Spyware.FlashEnhancer : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP395\A0023999.dll -> Spyware.FlashEnhancer : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP397\A0024040.dll -> Spyware.FlashEnhancer : Cleaned with backup
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP400\A0024830.dll -> Spyware.FlashEnhancer : Cleaned with backup
C:\WINDOWS\SYSTEM\UpdInst.exe -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\SYSTEM32\dn6201joe.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\SYSTEM32\elitejwd32.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\SYSTEM32\elitemwv32.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\SYSTEM32\elitersv32.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\SYSTEM32\elitewaw32.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\SYSTEM32\elitewsh32.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\SYSTEM32\OEESVR32.DLL -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\SYSTEM32\sohcinst.dll -> Spyware.Look2Me : Cleaned with backup
::Report End
new hijack this log after reboot:
Logfile of HijackThis v1.99.1
Scan saved at 12:06:19 PM, on 8/2/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\PROGRA~1\TOSHIBA\TOSHIB~1\sc3docmon.exe
C:\Program Files\DIGStream\digstream.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\program files\tvs\tvs_b.exe
C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
C:\WINDOWS\MXOALDR.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Guidescope\guide.exe
C:\Program Files\Trend Micro\Tmas\Tmas.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Dell\OpenManage\Client\Iap.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dell.comR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.courtexpr...et2/default.cfmR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.dell.comR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:8000
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: FlashEnhancer Ext - {5EDB03AF-0341-4e96-9E9B-3171522E4BAF} - c:\Program Files\Fla\fla.dll (file missing)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [ToshibaSC3DocMon] C:\PROGRA~1\TOSHIBA\TOSHIB~1\sc3docmon.exe
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] C:\Program Files\Corel\Corel Graphics 12\Languages\EN\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=011905 serial=DR12WTX-9999998-YSP lang=EN
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [tvs_b] C:\program files\tvs\tvs_b.exe
O4 - HKLM\..\Run: [checkrun] C:\windows\system32\elitemwv32.exe
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
O4 - HKLM\..\Run: [MXO Auto Loader] C:\WINDOWS\MXOALDR.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Guidescope.lnk = C:\Program Files\Guidescope\guide.exe
O4 - Global Startup: Trend Micro Anti-Spyware.lnk = C:\Program Files\Trend Micro\Tmas\Tmas.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai...all/xscan53.cabO16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) -
https://tlr.webex.co...bex/ieatgpc.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{D196B815-910A-4D48-939C-7157E3316B1C}: NameServer = 64.52.33.5,64.52.5.5
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Iap - Dell Computer Corporation - C:\Program Files\Dell\OpenManage\Client\Iap.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
thanks again