kunchi
Topic Starter
I was using IE tabs in Firefox to avoid using IE itself.
I was seeing an issue that if I switched my www.igoogle.com tab's IE would start spamming multiple open windows for my igoogle page from that tab.
I have uninstalled the IE tab to try to stop it but would like to clean off this laptop if there is something still there:
Here is my HijackThis LOG:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:24:55 PM, on 4/22/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Altiris\AClient\AClient.exe
C:\Program Files\Symantec\Backup Exec System Recovery\Agent\VProSvc.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Oracle\Ora92\bin\omtsreco.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\StacSV.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\Program Files\Symantec\Backup Exec System Recovery\Agent\VProTray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\stsystra.exe
C:\Program Files\Apoint\ApMsgFwd.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Altiris\AClient\AClntUsr.EXE
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://syminfo.ges.symantec.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://syminfo.ges.symantec.com/
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [Symantec Backup Exec System Recovery 7.0] "C:\Program Files\Symantec\Backup Exec System Recovery\Agent\VProTray.exe"
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [Korean IME Migration] C:\PROGRA~1\COMMON~1\MICROS~1\IME12\IMEKR\IMKRMIG.EXE /UNINSTALL
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMJPMIG12.0] C:\Program Files\Common Files\Microsoft Shared\IME12\IMEJP\IMJPRMZB.EXE /RmZombie
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AeXAgentLogon] C:\Program Files\Altiris\Altiris Agent\AeXAgentActivate.exe /logon
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [AClntUsr] C:\Program Files\Altiris\AClient\AClntUsr.EXE
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: VPN Client.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.acs
O15 - Trusted Zone: http://symantec.atgnow.com
O15 - Trusted Zone: http://*.ausy-notes
O15 - Trusted Zone: http://*.crmsiebel
O15 - Trusted Zone: http://order-ops-americas.custhelp.com
O15 - Trusted Zone: http://order-ops-apj.custhelp.com
O15 - Trusted Zone: http://order-ops-emea.custhelp.com
O15 - Trusted Zone: http://order-ops-global.custhelp.com
O15 - Trusted Zone: http://symantec.custhelp.com
O15 - Trusted Zone: http://symantec-apc-en.custhelp.com
O15 - Trusted Zone: http://symantec-consumer-tams.custhelp.com
O15 - Trusted Zone: http://symantec-de.custhelp.com
O15 - Trusted Zone: http://symantec-emea-en.custhelp.com
O15 - Trusted Zone: http://symantec-fr.custhelp.com
O15 - Trusted Zone: http://symantec-japan.custhelp.com
O15 - Trusted Zone: http://symantec-osg.custhelp.com
O15 - Trusted Zone: http://symantec-osg-vip.custhelp.com
O15 - Trusted Zone: http://symantecacc.custhelp.com
O15 - Trusted Zone: http://*.deptwebs
O15 - Trusted Zone: http://*.glc
O15 - Trusted Zone: http://*.gotomeeting.com
O15 - Trusted Zone: http://*.gss
O15 - Trusted Zone: http://*.irdu-notes
O15 - Trusted Zone: http://*.jato-notes
O15 - Trusted Zone: *.journyx.com
O15 - Trusted Zone: http://*.mymeetings.com
O15 - Trusted Zone: *.mysymantec.com
O15 - Trusted Zone: http://sitecatalyst.omniture.com
O15 - Trusted Zone: http://*.prg
O15 - Trusted Zone: http://symantec.quickarrow.com
O15 - Trusted Zone: http://*.salesdev
O15 - Trusted Zone: http://*.salesreports
O15 - Trusted Zone: *.symantec.com
O15 - Trusted Zone: http://*.syminfo
O15 - Trusted Zone: http://*.symlearn
O15 - Trusted Zone: http://*.sympeople
O15 - Trusted Zone: http://*.trainingreports
O15 - Trusted Zone: http://*.uscu-notes
O15 - Trusted Zone: http://*.usnn-notes
O15 - Trusted Zone: http://*.ussm-notes
O15 - Trusted Zone: http://*.ussp-notes
O15 - Trusted Zone: *.veritas.com
O15 - Trusted Zone: http://*.vnet
O15 - Trusted Zone: http://*.acs (HKLM)
O15 - Trusted Zone: http://symantec.atgnow.com (HKLM)
O15 - Trusted Zone: http://*.ausy-notes (HKLM)
O15 - Trusted Zone: http://*.crmsiebel (HKLM)
O15 - Trusted Zone: http://order-ops-americas.custhelp.com (HKLM)
O15 - Trusted Zone: http://order-ops-apj.custhelp.com (HKLM)
O15 - Trusted Zone: http://order-ops-emea.custhelp.com (HKLM)
O15 - Trusted Zone: http://order-ops-global.custhelp.com (HKLM)
O15 - Trusted Zone: http://symantec.custhelp.com (HKLM)
O15 - Trusted Zone: http://symantec-apc-en.custhelp.com (HKLM)
O15 - Trusted Zone: http://symantec-consumer-tams.custhelp.com (HKLM)
O15 - Trusted Zone: http://symantec-de.custhelp.com (HKLM)
O15 - Trusted Zone: http://symantec-emea-en.custhelp.com (HKLM)
O15 - Trusted Zone: http://symantec-fr.custhelp.com (HKLM)
O15 - Trusted Zone: http://symantec-japan.custhelp.com (HKLM)
O15 - Trusted Zone: http://symantec-osg.custhelp.com (HKLM)
O15 - Trusted Zone: http://symantec-osg-vip.custhelp.com (HKLM)
O15 - Trusted Zone: http://symantecacc.custhelp.com (HKLM)
O15 - Trusted Zone: http://*.deptwebs (HKLM)
O15 - Trusted Zone: http://*.glc (HKLM)
O15 - Trusted Zone: http://*.gotomeeting.com (HKLM)
O15 - Trusted Zone: http://*.gss (HKLM)
O15 - Trusted Zone: http://*.irdu-notes (HKLM)
O15 - Trusted Zone: http://*.jato-notes (HKLM)
O15 - Trusted Zone: *.journyx.com (HKLM)
O15 - Trusted Zone: http://*.mymeetings.com (HKLM)
O15 - Trusted Zone: *.mysymantec.com (HKLM)
O15 - Trusted Zone: http://sitecatalyst.omniture.com (HKLM)
O15 - Trusted Zone: http://*.prg (HKLM)
O15 - Trusted Zone: http://symantec.quickarrow.com (HKLM)
O15 - Trusted Zone: http://*.salesdev (HKLM)
O15 - Trusted Zone: http://*.salesreports (HKLM)
O15 - Trusted Zone: *.symantec.com (HKLM)
O15 - Trusted Zone: http://*.syminfo (HKLM)
O15 - Trusted Zone: http://*.symlearn (HKLM)
O15 - Trusted Zone: http://*.sympeople (HKLM)
O15 - Trusted Zone: http://*.trainingreports (HKLM)
O15 - Trusted Zone: http://*.uscu-notes (HKLM)
O15 - Trusted Zone: http://*.usnn-notes (HKLM)
O15 - Trusted Zone: http://*.ussm-notes (HKLM)
O15 - Trusted Zone: http://*.ussp-notes (HKLM)
O15 - Trusted Zone: *.veritas.com (HKLM)
O15 - Trusted Zone: http://*.vnet (HKLM)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = enterprise.veritas.com
O17 - HKLM\Software\..\Telephony: DomainName = enterprise.veritas.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = enterprise.veritas.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = ges.symantec.com,enterprise.veritas.com,corp.symantec.com,veritas.com,symantec.c
om,altiris.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = ges.symantec.com,enterprise.veritas.com,corp.symantec.com,veritas.com,symantec.c
om,altiris.com
O20 - AppInit_DLLs:
O23 - Service: Altiris Client Service (AClient) - Altiris, Inc. - C:\Program Files\Altiris\AClient\AClient.exe
O23 - Service: Altiris Agent (AeXNSClient) - Altiris, Inc. - C:\Program Files\Altiris\Altiris Agent\aexnsagent.exe
O23 - Service: AltirisAgentProvider - Altiris, Inc. - C:\Program Files\Altiris\Altiris Agent\Agents\WMIProviderAgent\AltirisAgentProvider.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Backup Exec System Recovery - Symantec Corporation - C:\Program Files\Symantec\Backup Exec System Recovery\Agent\VProSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPassConnectEngine - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPassConnectEngine.exe
O23 - Service: iPassPeriodicUpdateApp - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe
O23 - Service: iPassPeriodicUpdateService - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~2.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OracleMTSRecoveryService - Oracle Corporation - C:\Oracle\Ora92\bin\omtsreco.exe
O23 - Service: OracleOraHome92ClientCache - Unknown owner - C:\Oracle\Ora92\BIN\ONRSD.EXE
O23 - Service: Symantec Auto-upgrade Agent (Smcinst) - Unknown owner - C:\Program Files\Symantec\Symantec Endpoint Protection\SmcLU\Setup\smcinst.exe (file missing)
O23 - Service: Symantec Management Client (SmcService) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
O23 - Service: Symantec Network Access Control (SNAC) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\WINDOWS\system32\StacSV.exe
O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
–
End of file - 13659 bytes
I was seeing an issue that if I switched my www.igoogle.com tab's IE would start spamming multiple open windows for my igoogle page from that tab.
I have uninstalled the IE tab to try to stop it but would like to clean off this laptop if there is something still there:
Here is my HijackThis LOG:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:24:55 PM, on 4/22/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Altiris\AClient\AClient.exe
C:\Program Files\Symantec\Backup Exec System Recovery\Agent\VProSvc.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Oracle\Ora92\bin\omtsreco.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\StacSV.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\Program Files\Symantec\Backup Exec System Recovery\Agent\VProTray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\stsystra.exe
C:\Program Files\Apoint\ApMsgFwd.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Altiris\AClient\AClntUsr.EXE
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://syminfo.ges.symantec.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://syminfo.ges.symantec.com/
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [Symantec Backup Exec System Recovery 7.0] "C:\Program Files\Symantec\Backup Exec System Recovery\Agent\VProTray.exe"
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [Korean IME Migration] C:\PROGRA~1\COMMON~1\MICROS~1\IME12\IMEKR\IMKRMIG.EXE /UNINSTALL
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMJPMIG12.0] C:\Program Files\Common Files\Microsoft Shared\IME12\IMEJP\IMJPRMZB.EXE /RmZombie
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AeXAgentLogon] C:\Program Files\Altiris\Altiris Agent\AeXAgentActivate.exe /logon
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [AClntUsr] C:\Program Files\Altiris\AClient\AClntUsr.EXE
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: VPN Client.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.acs
O15 - Trusted Zone: http://symantec.atgnow.com
O15 - Trusted Zone: http://*.ausy-notes
O15 - Trusted Zone: http://*.crmsiebel
O15 - Trusted Zone: http://order-ops-americas.custhelp.com
O15 - Trusted Zone: http://order-ops-apj.custhelp.com
O15 - Trusted Zone: http://order-ops-emea.custhelp.com
O15 - Trusted Zone: http://order-ops-global.custhelp.com
O15 - Trusted Zone: http://symantec.custhelp.com
O15 - Trusted Zone: http://symantec-apc-en.custhelp.com
O15 - Trusted Zone: http://symantec-consumer-tams.custhelp.com
O15 - Trusted Zone: http://symantec-de.custhelp.com
O15 - Trusted Zone: http://symantec-emea-en.custhelp.com
O15 - Trusted Zone: http://symantec-fr.custhelp.com
O15 - Trusted Zone: http://symantec-japan.custhelp.com
O15 - Trusted Zone: http://symantec-osg.custhelp.com
O15 - Trusted Zone: http://symantec-osg-vip.custhelp.com
O15 - Trusted Zone: http://symantecacc.custhelp.com
O15 - Trusted Zone: http://*.deptwebs
O15 - Trusted Zone: http://*.glc
O15 - Trusted Zone: http://*.gotomeeting.com
O15 - Trusted Zone: http://*.gss
O15 - Trusted Zone: http://*.irdu-notes
O15 - Trusted Zone: http://*.jato-notes
O15 - Trusted Zone: *.journyx.com
O15 - Trusted Zone: http://*.mymeetings.com
O15 - Trusted Zone: *.mysymantec.com
O15 - Trusted Zone: http://sitecatalyst.omniture.com
O15 - Trusted Zone: http://*.prg
O15 - Trusted Zone: http://symantec.quickarrow.com
O15 - Trusted Zone: http://*.salesdev
O15 - Trusted Zone: http://*.salesreports
O15 - Trusted Zone: *.symantec.com
O15 - Trusted Zone: http://*.syminfo
O15 - Trusted Zone: http://*.symlearn
O15 - Trusted Zone: http://*.sympeople
O15 - Trusted Zone: http://*.trainingreports
O15 - Trusted Zone: http://*.uscu-notes
O15 - Trusted Zone: http://*.usnn-notes
O15 - Trusted Zone: http://*.ussm-notes
O15 - Trusted Zone: http://*.ussp-notes
O15 - Trusted Zone: *.veritas.com
O15 - Trusted Zone: http://*.vnet
O15 - Trusted Zone: http://*.acs (HKLM)
O15 - Trusted Zone: http://symantec.atgnow.com (HKLM)
O15 - Trusted Zone: http://*.ausy-notes (HKLM)
O15 - Trusted Zone: http://*.crmsiebel (HKLM)
O15 - Trusted Zone: http://order-ops-americas.custhelp.com (HKLM)
O15 - Trusted Zone: http://order-ops-apj.custhelp.com (HKLM)
O15 - Trusted Zone: http://order-ops-emea.custhelp.com (HKLM)
O15 - Trusted Zone: http://order-ops-global.custhelp.com (HKLM)
O15 - Trusted Zone: http://symantec.custhelp.com (HKLM)
O15 - Trusted Zone: http://symantec-apc-en.custhelp.com (HKLM)
O15 - Trusted Zone: http://symantec-consumer-tams.custhelp.com (HKLM)
O15 - Trusted Zone: http://symantec-de.custhelp.com (HKLM)
O15 - Trusted Zone: http://symantec-emea-en.custhelp.com (HKLM)
O15 - Trusted Zone: http://symantec-fr.custhelp.com (HKLM)
O15 - Trusted Zone: http://symantec-japan.custhelp.com (HKLM)
O15 - Trusted Zone: http://symantec-osg.custhelp.com (HKLM)
O15 - Trusted Zone: http://symantec-osg-vip.custhelp.com (HKLM)
O15 - Trusted Zone: http://symantecacc.custhelp.com (HKLM)
O15 - Trusted Zone: http://*.deptwebs (HKLM)
O15 - Trusted Zone: http://*.glc (HKLM)
O15 - Trusted Zone: http://*.gotomeeting.com (HKLM)
O15 - Trusted Zone: http://*.gss (HKLM)
O15 - Trusted Zone: http://*.irdu-notes (HKLM)
O15 - Trusted Zone: http://*.jato-notes (HKLM)
O15 - Trusted Zone: *.journyx.com (HKLM)
O15 - Trusted Zone: http://*.mymeetings.com (HKLM)
O15 - Trusted Zone: *.mysymantec.com (HKLM)
O15 - Trusted Zone: http://sitecatalyst.omniture.com (HKLM)
O15 - Trusted Zone: http://*.prg (HKLM)
O15 - Trusted Zone: http://symantec.quickarrow.com (HKLM)
O15 - Trusted Zone: http://*.salesdev (HKLM)
O15 - Trusted Zone: http://*.salesreports (HKLM)
O15 - Trusted Zone: *.symantec.com (HKLM)
O15 - Trusted Zone: http://*.syminfo (HKLM)
O15 - Trusted Zone: http://*.symlearn (HKLM)
O15 - Trusted Zone: http://*.sympeople (HKLM)
O15 - Trusted Zone: http://*.trainingreports (HKLM)
O15 - Trusted Zone: http://*.uscu-notes (HKLM)
O15 - Trusted Zone: http://*.usnn-notes (HKLM)
O15 - Trusted Zone: http://*.ussm-notes (HKLM)
O15 - Trusted Zone: http://*.ussp-notes (HKLM)
O15 - Trusted Zone: *.veritas.com (HKLM)
O15 - Trusted Zone: http://*.vnet (HKLM)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = enterprise.veritas.com
O17 - HKLM\Software\..\Telephony: DomainName = enterprise.veritas.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = enterprise.veritas.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = ges.symantec.com,enterprise.veritas.com,corp.symantec.com,veritas.com,symantec.c
om,altiris.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = ges.symantec.com,enterprise.veritas.com,corp.symantec.com,veritas.com,symantec.c
om,altiris.com
O20 - AppInit_DLLs:
O23 - Service: Altiris Client Service (AClient) - Altiris, Inc. - C:\Program Files\Altiris\AClient\AClient.exe
O23 - Service: Altiris Agent (AeXNSClient) - Altiris, Inc. - C:\Program Files\Altiris\Altiris Agent\aexnsagent.exe
O23 - Service: AltirisAgentProvider - Altiris, Inc. - C:\Program Files\Altiris\Altiris Agent\Agents\WMIProviderAgent\AltirisAgentProvider.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Backup Exec System Recovery - Symantec Corporation - C:\Program Files\Symantec\Backup Exec System Recovery\Agent\VProSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPassConnectEngine - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPassConnectEngine.exe
O23 - Service: iPassPeriodicUpdateApp - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe
O23 - Service: iPassPeriodicUpdateService - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~2.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OracleMTSRecoveryService - Oracle Corporation - C:\Oracle\Ora92\bin\omtsreco.exe
O23 - Service: OracleOraHome92ClientCache - Unknown owner - C:\Oracle\Ora92\BIN\ONRSD.EXE
O23 - Service: Symantec Auto-upgrade Agent (Smcinst) - Unknown owner - C:\Program Files\Symantec\Symantec Endpoint Protection\SmcLU\Setup\smcinst.exe (file missing)
O23 - Service: Symantec Management Client (SmcService) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
O23 - Service: Symantec Network Access Control (SNAC) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\WINDOWS\system32\StacSV.exe
O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
–
End of file - 13659 bytes