I followed each of the steps you outlined. Here are the results:
Here's the Ewido scan:
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 1:42:25 PM, 9/10/2005
+ Report-Checksum: 539C12F8
+ Scan result:
:mozilla.6:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.10:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.38:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.39:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.51:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.53:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.54:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.55:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.56:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.57:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.58:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.71:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.73:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.74:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.75:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.76:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.77:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.78:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.79:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.80:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.81:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.88:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.92:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.93:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.94:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.95:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.96:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.97:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.98:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.101:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.102:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.103:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.106:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.107:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.129:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.130:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.131:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.132:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.133:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.134:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.135:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.136:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.138:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.139:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.140:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.141:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.154:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.155:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.156:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.157:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.159:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.165:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
:mozilla.170:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.171:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.172:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.173:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.174:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.175:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.176:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.184:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.185:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.224:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.225:C:\Documents and Settings\Randall Fullington\Application Data\Mozilla\Firefox\Profiles\604phxf7.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Documents and Settings\Randall Fullington\Cookies\randall fullington@abetterinternet[1].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Randall Fullington\Cookies\randall
[email protected][2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\WINDOWS\Nail.exe.tcf -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\rpdacswqw.exe -> Adware.BetterInternet : Cleaned with backup
::Report End
Here's the Panda ActiveScan Log:
Incident Status Location
Adware:Adware/PurityScan No disinfected C:\WINDOWS\system32\cqma.dll
Adware:Adware/PurityScan No disinfected C:\Program Files\ipee\othb.exe
Adware:adware/pacimedia No disinfected C:\DOCUMENTS AND SETTINGS\RANDALL FULLINGTON\FAVORITES\1111\1111.url
Adware:adware/purityscan No disinfected C:\DOCUMENTS AND SETTINGS\RANDALL FULLINGTON\LOCAL SETTINGS\TEMP\!update.exe
Adware:adware program No disinfected C:\WINDOWS\SYSTEM32\cache32dsrf4535dfs
Adware:adware/enhsrch No disinfected Windows Registry
Adware:Adware/BigTrafficNet No disinfected C:\1.exe
Adware:Adware/PurityScan No disinfected C:\Documents and Settings\Randall Fullington\Local Settings\Temp\!update.exe
Adware:Adware/PurityScan No disinfected C:\Documents and Settings\Randall Fullington\Local Settings\Temporary Internet Files\Content.IE5\WPYBO52N\!update-2595[1].0000
Adware:Adware/PurityScan No disinfected C:\Program Files\ipee\othb.exe
Adware:Adware/PurityScan No disinfected C:\WINDOWS\system32\cqma.dll
Finally, here's the HijackThis log:
Logfile of HijackThis v1.99.1
Scan saved at 3:03:51 PM, on 9/10/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\CU VPN\cvpnd.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\WINDOWS\System32\hphmon05.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\DIGStream\digstream.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\??erinit.exe
C:\Program Files\ipee\othb.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopOE.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Randall Fullington\Desktop\hijackthis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://qus8l.hpwis.comR3 - Default URLSearchHook is missing
O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINDOWS\dsr.dll (file missing)
O2 - BHO: PicShow Class - {4487598C-2EC7-43A2-870E-6D8D720FDD9F} - C:\WINDOWS\system32\pkshjxhr.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {63F61551-E847-5CCD-8007-10557E812B48} - C:\WINDOWS\system32\mqjdpaw.dll (file missing)
O2 - BHO: Google Desktop Search Capture - {7c1ce531-09e9-4fc5-9803-1c2956615786} - C:\Program Files\Google\Google Desktop Search\GoogleDesktopIE.dll
O2 - BHO: (no name) - {7CD83B42-80A1-FE21-8219-AE1820D9C4CC} - C:\WINDOWS\system32\enh.dll (file missing)
O2 - BHO: (no name) - {88C00221-E396-9A48-EC08-CABE3A0864C6} - C:\WINDOWS\system32\cqma.dll
O2 - BHO: (no name) - {C0C5675B-DDB7-A961-CB0A-ADC8198529C6} - C:\WINDOWS\system32\idqcz.dll (file missing)
O2 - BHO: (no name) - {C2679512-7BFF-0328-DEE8-0182C91F2FC3} - C:\WINDOWS\system32\eamezbd.dll (file missing)
O2 - BHO: (no name) - {C9C5675E-DDB2-AA6C-CB0D-AAC86DFF29C5} - C:\WINDOWS\system32\idqcz.dll (file missing)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [bL] C:\documents and settings\randall fullington\local settings\temp\bL.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [Krxgy] C:\WINDOWS\system32\??erinit.exe
O4 - HKCU\..\Run: [pshower] C:\WINDOWS\system32\pshwr.exe
O4 - HKCU\..\Run: [Aaou] C:\Program Files\ipee\othb.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: University of Colorado at Boulder VPN Client.lnk = C:\Program Files\CU VPN\vpngui.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe
O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://qus8l.hpwis.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
http://messenger.zon...kr.cab30149.cabO16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
http://appldnld.m7z....iTunesSetup.exeO16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) -
http://tools.ebayimg...l_v1-0-3-17.cabO16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab30149.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoft...free/asinst.cabO16 - DPF: {F5C90925-ABBF-4475-88F5-8622B452BA9E} (Compaq System Data Class) -
http://ipgweb.cce.hp...er/SysQuery.cabO16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) -
http://messenger.zon...wn.cab30149.cabO23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\CU VPN\cvpnd.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe