---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 10:46:02 AM, 3/14/2006
+ Report-Checksum: 90B1E5C0
+ Scan result:
:mozilla.18:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.38:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.71:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.73:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.74:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.88:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.89:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.90:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.110:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.111:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.122:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
:mozilla.130:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.131:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.132:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.133:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.134:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.139:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup
:mozilla.141:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.142:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.150:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned with backup
:mozilla.158:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.159:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.160:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.161:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.162:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.163:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.165:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.166:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.168:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.169:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.170:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.171:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.172:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.175:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.176:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.177:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.178:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.179:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.197:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup
:mozilla.198:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup
:mozilla.199:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup
:mozilla.200:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup
:mozilla.201:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.202:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.203:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.204:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.205:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.216:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.230:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.231:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.233:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.234:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.235:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.236:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.240:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.241:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.242:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.250:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned with backup
:mozilla.253:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.257:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.258:C:\Documents and Settings\Joe Datko\Application Data\Mozilla\Firefox\Profiles\wckpl31y.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP701\A0063530.exe -> Backdoor.Aimbot.ch : Cleaned with backup
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP702\A0063752.exe -> Backdoor.Aimbot.ch : Cleaned with backup
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP702\A0063814.exe -> Not-A-Virus.RemoteAdmin.Win32.WinVNC.4 : Cleaned with backup
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP702\A0063815.exe -> Not-A-Virus.RemoteAdmin.Win32.WinVNC.4 : Cleaned with backup
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP702\A0063816.exe -> Not-A-Virus.RemoteAdmin.Win32.WinVNC.4 : Cleaned with backup
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP702\A0063817.dll -> Not-A-Virus.RemoteAdmin.Win32.WinVNC.4 : Cleaned with backup
::Report End
Logfile of HijackThis v1.99.1
Scan saved at 1:21:00 PM, on 3/14/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Symantec AntiVirus CE 9.0.1\DefWatch.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\System32\QCONSVC.EXE
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\Symantec AntiVirus CE 9.0.1\Rtvscan.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\System32\TpShocks.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
C:\WINDOWS\System32\RunDll32.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1.1\VPTray.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\IBMTOOLS\UTILS\ibmprc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Documents and Settings\Joe Datko\Desktop\Tools\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.upenn.edu...portal/view.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.upenn.edu...portal/view.php
R3 - Default URLSearchHook is missing
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [S3TRAY2] S3Tray2.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [UC_Start] C:\Program Files\IBM\Updater\\ucstartup.exe
O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [gX7y92C] C:\documents and settings\joe datko\local settings\temp\gX7y92C.exe
O4 - HKLM\..\Run: [NMY6uTRm4] C:\documents and settings\joe datko\local settings\temp\NMY6uTRm4.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1.1\VPTray.exe
O4 - HKLM\..\Run: [Dimension4] C:\PROGRA~1\DIMENS~1.0\D4.exe
O4 - HKLM\..\Run: [377Q3mP] immdit.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKCU\..\Run: [Iwo4Rgjmj] autsc.exe
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O10 - Broken Internet access because of LSP provider 'xfire_lsp.dll' missing
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} -
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} -
O16 - DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} (Java Plug-in) -
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} (Java Plug-in) -
O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} (NPKCX Control) -
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus CE 9.0.1\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Local Security Authority Subsystem Service (lsass) - Unknown owner - C:\WINDOWS\scvhost.exe (file missing)
O23 - Service: npkcsvc - INCA Internet Co., Ltd. - C:\WINDOWS\System32\npkcsvc.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus CE 9.0.1\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus CE 9.0.1\Rtvscan.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe