This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijack log - can't use google search engine w/o being redirected

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Thanks to anyone who can help.

Logfile of HijackThis v1.99.1
Scan saved at 8:16:13 PM, on 6/28/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\BacsTray.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\COMMAN~1\COMMAN~1\untray.exe
C:\PROGRA~1\COMMAN~1\COMMAN~1\dvprpt.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Microsoft Money\System\mnyexpr.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\1XConfig.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
C:\Program Files\FirstClass\fcc32.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Command Software\Command AntiVirus\avinitnt.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\Command Software\Command AntiVirus\schscnt.exe
C:\Program Files\Command Software\Command AntiVirus\dvprpt.exe
C:\Program Files\Command Software\Command AntiVirus\avtray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\Josh\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
O1 - Hosts: localhost 127.0.0.1
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINDOWS\system32\angsr.dll (file missing)
O2 - BHO: XBTB09580 - {213C7491-5A0D-4b99-8B6B-1498B14B398F} - C:\PROGRA~1\WORDRE~1\WORDRE~1.DLL (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: WordReferenceEnEs - {5776A2BC-D803-47F6-9DC0-8344DB8D604C} - C:\Program Files\WordReferenceEnEs\wordreferenceEnEs.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINDOWS\system32\angsr.dll (file missing)
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [bacstray] BacsTray.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [untray] C:\PROGRA~1\COMMAN~1\COMMAN~1\untray.exe
O4 - HKLM\..\Run: [CSAV_CheckViruses] C:\PROGRA~1\COMMAN~1\COMMAN~1\vchk.exe
O4 - HKLM\..\Run: [avtray] C:\PROGRA~1\COMMAN~1\COMMAN~1\avtray.exe
O4 - HKLM\..\Run: [dvprpt] C:\PROGRA~1\COMMAN~1\COMMAN~1\dvprpt.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [dmmns.exe] C:\WINDOWS\system32\dmmns.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office Outlook 2003 (2).lnk = ?
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - https://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish.com/SnapfishActivia.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1129417033334
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{113724AF-6692-4AC8-9057-722427E7A40C}: NameServer = 85.255.114.8,85.255.112.189
O17 - HKLM\System\CS1\Services\Tcpip\..\{113724AF-6692-4AC8-9057-722427E7A40C}: NameServer = 85.255.114.8,85.255.112.189
O17 - HKLM\System\CS2\Services\Tcpip\..\{113724AF-6692-4AC8-9057-722427E7A40C}: NameServer = 85.255.114.8,85.255.112.189
O20 - Winlogon Notify: Sebring - C:\WINDOWS\System32\LgNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: avinitnt - Command Software Systems, Inc. - C:\Program Files\Command Software\Command AntiVirus\avinitnt.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: schscnt - Command Software Systems, Inc. - C:\Program Files\Command Software\Command AntiVirus\schscnt.exe
Welcome to the forum. :wavey:

Your computer has been hijacked by people in the Ukraine. What you have is a Wareout infection.

85.255.112.0 - 85.255.127.255
Inhoster hosting company
OOO Inhoster, Poltavskij Shliax 24, Kharkiv, 61000, Ukraine


Please download FixWareout from one of these sites:
Fixwareout.exe
Fixwareout.exe

* Save it to your desktop and run it.
* Click Next, then Install, make sure "Run fixit" is checked and click Finish.
* The fix will begin; follow the prompts.
* You will be asked to reboot your computer; please do so.
* Your system may take longer than usual to load; this is normal.
* Once the desktop loads, a text will open (report.txt). Post it in your next reply.

Please make a PERMANANT folder for Hijack This!

Important: Create a folder on the C: drive called C:\HJT.
You can do this by going to My Computer (Windows key+e) then double click on C: then right click and select New then Folder and name it HJT. MOVE (drag-and-drop) HijackThis into this folder.

If required a tutorial is here = Hijackthis Folder Tutorial

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):
(Note: Some of these may already have been removed by Fixwareout.exe)

O2 - BHO: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINDOWS\system32\angsr.dll (file missing)

O2 - BHO: XBTB09580 - {213C7491-5A0D-4b99-8B6B-1498B14B398F} - C:\PROGRA~1\WORDRE~1\WORDRE~1.DLL (file missing)

O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)

O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

O3 - Toolbar: WordReferenceEnEs - {5776A2BC-D803-47F6-9DC0-8344DB8D604C} - C:\Program Files\WordReferenceEnEs\wordreferenceEnEs.dll (file missing)

O3 - Toolbar: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINDOWS\system32\angsr.dll (file missing)

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

O4 - HKLM\..\Run: [dmmns.exe] C:\WINDOWS\system32\dmmns.exe

O17 - HKLM\System\CCS\Services\Tcpip\..\{113724AF-6692-4AC8-9057-722427E7A40C}: NameServer = 85.255.114.8,85.255.112.189

O17 - HKLM\System\CS1\Services\Tcpip\..\{113724AF-6692-4AC8-9057-722427E7A40C}: NameServer = 85.255.114.8,85.255.112.189

O17 - HKLM\System\CS2\Services\Tcpip\..\{113724AF-6692-4AC8-9057-722427E7A40C}: NameServer = 85.255.114.8,85.255.112.189

Then click "Fix checked" and close Hijack This!.

Reboot in "safe" mode.

Delete all of the following noted (in red) file(s)/FOLDER(s) you can find:

c:\windows\system32\dmmns.exe <— file

Some malware files may be "hidden".
Be sure to show hidden files when looking for these file(s) and/or folder(s).

Reboot in normal mode and "copy/paste" a new HijackThis! log file, along with the contents of this file:

C:\fixwareout\report.txt

into this thread. :)
Micah 6:8,

Thank you very much for your help.

I have done as you suggested. When I searched fro the "dmmns.exe" files in safe mode, ennabling (sp?) the "show hidden files" feature, I did not find any. Good, bad, indifferent?

Here is the hijack log:
Logfile of HijackThis v1.99.1
Scan saved at 9:39:31 AM, on 6/29/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Command Software\Command AntiVirus\avinitnt.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\Program Files\Command Software\Command AntiVirus\schscnt.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\1XConfig.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\BacsTray.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\PROGRA~1\COMMAN~1\COMMAN~1\untray.exe
C:\PROGRA~1\COMMAN~1\COMMAN~1\avtray.exe
C:\PROGRA~1\COMMAN~1\COMMAN~1\dvprpt.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\Program Files\Microsoft Money\System\mnyexpr.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Josh\Desktop\Misc. stuff\Spyware and Virus Protection\HJT\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [bacstray] BacsTray.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [untray] C:\PROGRA~1\COMMAN~1\COMMAN~1\untray.exe
O4 - HKLM\..\Run: [CSAV_CheckViruses] C:\PROGRA~1\COMMAN~1\COMMAN~1\vchk.exe
O4 - HKLM\..\Run: [avtray] C:\PROGRA~1\COMMAN~1\COMMAN~1\avtray.exe
O4 - HKLM\..\Run: [dvprpt] C:\PROGRA~1\COMMAN~1\COMMAN~1\dvprpt.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office Outlook 2003 (2).lnk = ?
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - https://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish.com/SnapfishActivia.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1129417033334
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O20 - Winlogon Notify: Sebring - C:\WINDOWS\System32\LgNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: avinitnt - Command Software Systems, Inc. - C:\Program Files\Command Software\Command AntiVirus\avinitnt.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: schscnt - Command Software Systems, Inc. - C:\Program Files\Command Software\Command AntiVirus\schscnt.exe

Here is the fixwareout log:
Fixwareout ver 1.003
Last edited 04/26/2006
Post this report in the forums please

Reg Entries that were deleted
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\xedocne
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\repiwoh
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\23plhps
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\mgcppp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\tesvaf
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\32refaselif
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\zsimd
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\xedocne
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\gib_ogol
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\repiwoh
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\llun
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\23plhps
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\mgcppp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\tesvaf
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\32refaselif
…

Microsoft ® Windows Script Host Version 5.6
Random Runs removed from HKLM
"dmisz.exe"=-
…

PLEASE NOTE, There WILL be LEGIT FILES LISTED. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
Example ipsec6.exe is lagitamate

»»»»» Search by size and names…

»»»»» Misc files

»»»»» Checking for older varients covered by the Rem3 tool

»»»»»
Search five digit cs, dm and jb files
This WILL/CAN also list Legit Files, Submit them at Virustotal
C:\WINDOWS\SYSTEM32\DMISZ.EXE 44,130 2004-08-04
C:\WINDOWS\SYSTEM32\DMMGS.EXE 44,130 2004-08-04

Again, thank you very much for your assistance.

Josh

P.S. If you have the time, I was wondering if you might have suggestions for the following:

1) Whenever I try and update my Ad-aware, my computer shuts down to a blue screen. This happened shortly after I installed a newer version of Ad-aware. (From October of 2004 to February of 2005, this was not a problem; since then, I get the blue screen)

2) When leaving safe mode, "End Program - Sample" appears, and after I let the "End Program" run its course, "Sample" still won't close and I have to "End Now". I'm unsure if this is normal.
The log looks good. :thumbup:

Delete these files, if you can find them:

C:\WINDOWS\SYSTEM32\DMISZ.EXE
C:\WINDOWS\SYSTEM32\DMMGS.EXE

Adaware Problem

There are instructions in this post on how to update Adaware manually.

If that doesn't work, I'd uninstall it, reboot and re-install it.

Safe mode Problem

Please download/unzip this:

Registry Search by Bobbi Flekman

on regsearch.exe, and search for this:

Sample

It may take a while to run, so be patient. When finished, the search results will appear in your text editor,

Paste the contents of the results into your next post.
:)
Micah 6:8,

Thanks again.

Here's the Steelwerx log:

REGEDIT4

; Registry Search 2.0 by Bobbi Flekman © 2005
; Version: 2.0.1.0

; Results at 6/29/2006 10:34:22 AM for strings:
; 'sample'
; Strings excluded from search:
; (None)
; Search in:
; Registry Keys Registry Values Registry Data
; HKEY_LOCAL_MACHINE HKEY_USERS


[HKEY_LOCAL_MACHINE\SOFTWARE\Apple Computer, Inc.\QuickTime\Installed Files\Sample.mov]

[HKEY_LOCAL_MACHINE\SOFTWARE\Apple Computer, Inc.\QuickTime\Installed Files\Sample.mov]
"Full Path"="C:\\Program Files\\QuickTime\\Sample.mov"

[HKEY_LOCAL_MACHINE\SOFTWARE\Apple Computer, Inc.\QuickTime\Installed Files\Sample.qtif]

[HKEY_LOCAL_MACHINE\SOFTWARE\Apple Computer, Inc.\QuickTime\Installed Files\Sample.qtif]
"Full Path"="C:\\Program Files\\QuickTime\\Sample.qtif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Apple Computer, Inc.\QuickTime\Recent Movies]
"QuickTime Sample Movie"="2,c:\\Program Files\\QuickTime\\Sample.mov"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{7F1232EE-44D7-4494-AB8B-CC61B10E21A5}]
"FriendlyName"="WMT Sample Information Filter"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{C1F400A0-3F08-11D3-9F0B-006008039E37}]
"FriendlyName"="SampleGrabber"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7F1232EE-44D7-4494-AB8B-CC61B10E21A5}]
@="WMT Sample Info Filter"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C1F400A0-3F08-11D3-9F0B-006008039E37}]
@="Sample Grabber"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\9040AC1900063D11C8EF10054038389C]
"ExcelSampleFiles"="EXCELFiles"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4C778378-93FB-42DA-A0D0-BA4329915892}]
@="IWMEncSampleControl"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Multimedia\Components\Informational\playback_DefaultPlaylist\Files\File0]
@="C:\\DOCUME~1\\ALLUSE~1\\DOCUME~1\\MYMUSI~1\\SAMPLE~2\\Favorites – 4 and 5 star rated.wpl"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Multimedia\Components\Informational\playback_DefaultPlaylist\Files\File1]
@="C:\\DOCUME~1\\ALLUSE~1\\DOCUME~1\\MYMUSI~1\\SAMPLE~2\\High bitrate media in my library.wpl"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Multimedia\Components\Informational\playback_DefaultPlaylist\Files\File2]
@="C:\\DOCUME~1\\ALLUSE~1\\DOCUME~1\\MYMUSI~1\\SAMPLE~2\\Low bitrate media in my library.wpl"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\RealNetworks\Update\6.0\Preferences\Components\rjeplug:1.0\File6]
@="C:\\Program Files\\Real\\RealOne Player\\Producer\\Tools\\audioresampler.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Intuit\TurboTax Deluxe 2005\Uninstall\Application\File]
"C:\\Program Files\\TurboTax\\Deluxe 2005\\32bit\\local\\dlg\\proReviewSample.htm"=dword:00000001
"C:\\Program Files\\TurboTax\\Deluxe 2005\\32bit\\local\\easystep\\qbImportInterviewSample.gif"=dword:00000001
"C:\\Program Files\\TurboTax\\Deluxe 2005\\32bit\\local\\img\\proReviewSample01.gif"=dword:00000001
"C:\\Program Files\\TurboTax\\Deluxe 2005\\32bit\\local\\img\\proReviewSample02.gif"=dword:00000001
"C:\\Program Files\\TurboTax\\Deluxe 2005\\32bit\\local\\img\\proReviewSample03.gif"=dword:00000001
"C:\\Program Files\\TurboTax\\Deluxe 2005\\32bit\\local\\img\\proReviewSample04.gif"=dword:00000001
"C:\\Program Files\\TurboTax\\Deluxe 2005\\32bit\\local\\img\\proReviewSample05.gif"=dword:00000001
"C:\\Program Files\\TurboTax\\Deluxe 2005\\32bit\\local\\img\\proReviewSample06.gif"=dword:00000001
"C:\\Program Files\\TurboTax\\Deluxe 2005\\32bit\\local\\img\\proSampleBullet.gif"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Lake\LakeControl\1.0\Filters\{LakeID-2206cde2-842b5e5f-b1b27976}]
"SampleRate"=dword:0000bb80

[HKEY_LOCAL_MACHINE\SOFTWARE\Lake\LakeControl\1.0\Filters\{LakeID-27789224-140001f7-70c9f70b}]
"SampleRate"=dword:0000bb80

[HKEY_LOCAL_MACHINE\SOFTWARE\Lake\LakeControl\1.0\Filters\{LakeID-2cea37b4-3e9f990b-4f06ea95}]
"SampleRate"=dword:0000bb80

[HKEY_LOCAL_MACHINE\SOFTWARE\Lake\LakeControl\1.0\Filters\{LakeID-8d4f6791-ae909c5d-c0f27ce0}]
"SampleRate"=dword:0000ac44

[HKEY_LOCAL_MACHINE\SOFTWARE\Lake\LakeControl\1.0\Filters\{LakeID-bac6d6de-7145cbbf-348ea9f0}]
"SampleRate"=dword:0000ac44

[HKEY_LOCAL_MACHINE\SOFTWARE\Lake\LakeControl\1.0\Filters\{LakeID-c9cde313-5abfc82e-9b9c19a2}]
"SampleRate"=dword:0000ac44

[HKEY_LOCAL_MACHINE\SOFTWARE\Lake\LakeControl\1.0\Filters\{LakeID-dfc55ae3-5c246bcc-d8688c4d}]
"SampleRate"=dword:0000bb80

[HKEY_LOCAL_MACHINE\SOFTWARE\Lake\LakeControl\1.0\Filters\{LakeID-f86b11c4-6b11a83c-69538d22}]
"SampleRate"=dword:0000ac44

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MediaPlayer\Preferences]
"MyPlayLists"="C:\\DOCUME~1\\ALLUSE~1\\DOCUME~1\\MYMUSI~1\\SAMPLE~2"
"ObfuscatedSamplePlaylistsPath"="C:\\Documents and Settings\\All Users\\Documents\\My Music\\0ABC85D5"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MediaPlayer\Settings\MP3Encoding]
"LowRateSample"=dword:00005dc0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MediaPlayer\Setup]
"PlaylistName"="Sample Playlist"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\11.0\Outlook\Setup]
"CreateSamples"=dword:00000783

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\Jasc Software Inc\\Paint Shop Pro 8\\Sample Images\\"=""
"C:\\Program Files\\Microsoft Office\\OFFICE11\\SAMPLES\\"=""
"C:\\Program Files\\SPSSStudent\\Tutorial\\sample_files\\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6B84821DAB28FDA449714A9A164F1866]
"10C226343D5126E4A99DDBC700F74D25"="C:\\Program Files\\SPSSStudent\\Tutorial\\sample_files\\accidents.sav"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C77192D4D9C9BA94086DBC3B46DE77E0]
"9040AC1900063D11C8EF10054038389C"="C:\\Program Files\\Microsoft Office\\OFFICE11\\SAMPLES\\SOLVSAMP.XLS"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040AC1900063D11C8EF10054038389C\Features]
"ExcelSampleFiles"="-uxl@WHZb?TxokbUB=`'EXCELFiles"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ContentIndex\Language\Dutch_Dutch]
"ISAPIIDQErrorFile"="/iissamples/issamples/IDQError.htx"
"ISAPIHTXErrorFile"="/iissamples/issamples/HTXError.htx"
"ISAPIRestrictionErrorFile"="/iissamples/issamples/ResError.htx"
"ISAPIDefaultErrorFile"="/iissamples/issamples/DefError.htx"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ContentIndex\Language\English_UK]
"ISAPIIDQErrorFile"="/iissamples/issamples/IDQError.htx"
"ISAPIHTXErrorFile"="/iissamples/issamples/HTXError.htx"
"ISAPIRestrictionErrorFile"="/iissamples/issamples/ResError.htx"
"ISAPIDefaultErrorFile"="/iissamples/issamples/DefError.htx"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ContentIndex\Language\English_US]
"ISAPIIDQErrorFile"="/iissamples/issamples/IDQError.htx"
"ISAPIHTXErrorFile"="/iissamples/issamples/HTXError.htx"
"ISAPIRestrictionErrorFile"="/iissamples/issamples/ResError.htx"
"ISAPIDefaultErrorFile"="/iissamples/issamples/DefError.htx"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ContentIndex\Language\French_French]
"ISAPIIDQErrorFile"="/iissamples/issamples/IDQError.htx"
"ISAPIHTXErrorFile"="/iissamples/issamples/HTXError.htx"
"ISAPIRestrictionErrorFile"="/iissamples/issamples/ResError.htx"
"ISAPIDefaultErrorFile"="/iissamples/issamples/DefError.htx"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ContentIndex\Language\German_German]
"ISAPIIDQErrorFile"="/iissamples/issamples/IDQError.htx"
"ISAPIHTXErrorFile"="/iissamples/issamples/HTXError.htx"
"ISAPIRestrictionErrorFile"="/iissamples/issamples/ResError.htx"
"ISAPIDefaultErrorFile"="/iissamples/issamples/DefError.htx"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ContentIndex\Language\Italian_Italian]
"ISAPIIDQErrorFile"="/iissamples/issamples/IDQError.htx"
"ISAPIHTXErrorFile"="/iissamples/issamples/HTXError.htx"
"ISAPIRestrictionErrorFile"="/iissamples/issamples/ResError.htx"
"ISAPIDefaultErrorFile"="/iissamples/issamples/DefError.htx"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ContentIndex\Language\Neutral]
"ISAPIIDQErrorFile"="/iissamples/issamples/IDQError.htx"
"ISAPIHTXErrorFile"="/iissamples/issamples/HTXError.htx"
"ISAPIRestrictionErrorFile"="/iissamples/issamples/ResError.htx"
"ISAPIDefaultErrorFile"="/iissamples/issamples/DefError.htx"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ContentIndex\Language\Spanish_Modern]
"ISAPIIDQErrorFile"="/iissamples/issamples/IDQError.htx"
"ISAPIHTXErrorFile"="/iissamples/issamples/HTXError.htx"
"ISAPIRestrictionErrorFile"="/iissamples/issamples/ResError.htx"
"ISAPIDefaultErrorFile"="/iissamples/issamples/DefError.htx"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ContentIndex\Language\Swedish_Default]
"ISAPIIDQErrorFile"="/iissamples/issamples/IDQError.htx"
"ISAPIHTXErrorFile"="/iissamples/issamples/HTXError.htx"
"ISAPIRestrictionErrorFile"="/iissamples/issamples/ResError.htx"
"ISAPIDefaultErrorFile"="/iissamples/issamples/DefError.htx"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ContentIndex\Language\Thai_Default]
"ISAPIIDQErrorFile"="/iissamples/issamples/IDQError.htx"
"ISAPIHTXErrorFile"="/iissamples/issamples/HTXError.htx"
"ISAPIRestrictionErrorFile"="/iissamples/issamples/ResError.htx"
"ISAPIDefaultErrorFile"="/iissamples/issamples/DefError.htx"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MediaCategories\{9DB7B9E0-C555-11D0-8A2B-00A0C9255AC1}]
"Name"="Sample Rate Converter"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PnP\PciIrqRouting\IrqRoutingTables]
; Contents of value:
; 
"VLSI Sample"=hex:18,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
; Contents of value:
; 
"Intel 430MX Motherboard Sample"=hex:18,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\ACPI\PNP0F13\4&61f3b4b&0\Device Parameters]
"SampleRate"=dword:00000064

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\ContentIndex\Language\Dutch_Dutch]
"ISAPIIDQErrorFile"="/iissamples/issamples/IDQError.htx"
"ISAPIHTXErrorFile"="/iissamples/issamples/HTXError.htx"
"ISAPIRestrictionErrorFile"="/iissamples/issamples/ResError.htx"
"ISAPIDefaultErrorFile"="/iissamples/issamples/DefError.htx"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\ContentIndex\Language\English_UK]
"ISAPIIDQErrorFile"="/iissamples/issamples/IDQError.htx"
"ISAPIHTXErrorFile"="/iissamples/issamples/HTXError.htx"
"ISAPIRestrictionErrorFile"="/iissamples/issamples/ResError.htx"
"ISAPIDefaultErrorFile"="/iissamples/issamples/DefError.htx"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\ContentIndex\Language\English_US]
"ISAPIIDQErrorFile"="/iissamples/issamples/IDQError.htx"
"ISAPIHTXErrorFile"="/iissamples/issamples/HTXError.htx"
"ISAPIRestrictionErrorFile"="/iissamples/issamples/ResError.htx"
"ISAPIDefaultErrorFile"="/iissamples/issamples/DefError.htx"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\ContentIndex\Language\French_French]
"ISAPIIDQErrorFile"="/iissamples/issamples/IDQError.htx"
"ISAPIHTXErrorFile"="/iissamples/issamples/HTXError.htx"
"ISAPIRestrictionErrorFile"="/iissamples/issamples/ResError.htx"
"ISAPIDefaultErrorFile"="/iissamples/issamples/DefError.htx"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\ContentIndex\Language\German_German]
"ISAPIIDQErrorFile"="/iissamples/issamples/IDQError.htx"
"ISAPIHTXErrorFile"="/iissamples/issamples/HTXError.htx"
"ISAPIRestrictionErrorFile"="/iissamples/issamples/ResError.htx"
"ISAPIDefaultErrorFile"="/iissamples/issamples/DefError.htx"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\ContentIndex\Language\Italian_Italian]
"ISAPIIDQErrorFile"="/iissamples/issamples/IDQError.htx"
"ISAPIHTXErrorFile"="/iissamples/issamples/HTXError.htx"
"ISAPIRestrictionErrorFile"="/iissamples/issamples/ResError.htx"
"ISAPIDefaultErrorFile"="/iissamples/issamples/DefError.htx"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\ContentIndex\Language\Neutral]
"ISAPIIDQErrorFile"="/iissamples/issamples/IDQError.htx"
"ISAPIHTXErrorFile"="/iissamples/issamples/HTXError.htx"
"ISAPIRestrictionErrorFile"="/iissamples/issamples/ResError.htx"
"ISAPIDefaultErrorFile"="/iissamples/issamples/DefError.htx"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\ContentIndex\Language\Spanish_Modern]
"ISAPIIDQErrorFile"="/iissamples/issamples/IDQError.htx"
"ISAPIHTXErrorFile"="/iissamples/issamples/HTXError.htx"
"ISAPIRestrictionErrorFile"="/iissamples/issamples/ResError.htx"
"ISAPIDefaultErrorFile"="/iissamples/issamples/DefError.htx"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\ContentIndex\Language\Swedish_Default]
"ISAPIIDQErrorFile"="/iissamples/issamples/IDQError.htx"
"ISAPIHTXErrorFile"="/iissamples/issamples/HTXError.htx"
"ISAPIRestrictionErrorFile"="/iissamples/issamples/ResError.htx"
"ISAPIDefaultErrorFile"="/iissamples/issamples/DefError.htx"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\ContentIndex\Language\Thai_Default]
"ISAPIIDQErrorFile"="/iissamples/issamples/IDQError.htx"
"ISAPIHTXErrorFile"="/iissamples/issamples/HTXError.htx"
"ISAPIRestrictionErrorFile"="/iissamples/issamples/ResError.htx"
"ISAPIDefaultErrorFile"="/iissamples/issamples/DefError.htx"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\MediaCategories\{9DB7B9E0-C555-11D0-8A2B-00A0C9255AC1}]
"Name"="Sample Rate Converter"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PnP\PciIrqRouting\IrqRoutingTables]
; Contents of value:
; 
"VLSI Sample"=hex:18,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
; Contents of value:
; 
"Intel 430MX Motherboard Sample"=hex:18,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\ACPI\PNP0F13\4&61f3b4b&0\Device Parameters]
"SampleRate"=dword:00000064

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ContentIndex\Language\Dutch_Dutch]
"ISAPIIDQErrorFile"="/iissamples/issamples/IDQError.htx"
"ISAPIHTXErrorFile"="/iissamples/issamples/HTXError.htx"
"ISAPIRestrictionErrorFile"="/iissamples/issamples/ResError.htx"
"ISAPIDefaultErrorFile"="/iissamples/issamples/DefError.htx"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ContentIndex\Language\English_UK]
"ISAPIIDQErrorFile"="/iissamples/issamples/IDQError.htx"
"ISAPIHTXErrorFile"="/iissamples/issamples/HTXError.htx"
"ISAPIRestrictionErrorFile"="/iissamples/issamples/ResError.htx"
"ISAPIDefaultErrorFile"="/iissamples/issamples/DefError.htx"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ContentIndex\Language\English_US]
"ISAPIIDQErrorFile"="/iissamples/issamples/IDQError.htx"
"ISAPIHTXErrorFile"="/iissamples/issamples/HTXError.htx"
"ISAPIRestrictionErrorFile"="/iissamples/issamples/ResError.htx"
"ISAPIDefaultErrorFile"="/iissamples/issamples/DefError.htx"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ContentIndex\Language\French_French]
"ISAPIIDQErrorFile"="/iissamples/issamples/IDQError.htx"
"ISAPIHTXErrorFile"="/iissamples/issamples/HTXError.htx"
"ISAPIRestrictionErrorFile"="/iissamples/issamples/ResError.htx"
"ISAPIDefaultErrorFile"="/iissamples/issamples/DefError.htx"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ContentIndex\Language\German_German]
"ISAPIIDQErrorFile"="/iissamples/issamples/IDQError.htx"
"ISAPIHTXErrorFile"="/iissamples/issamples/HTXError.htx"
"ISAPIRestrictionErrorFile"="/iissamples/issamples/ResError.htx"
"ISAPIDefaultErrorFile"="/iissamples/issamples/DefError.htx"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ContentIndex\Language\Italian_Italian]
"ISAPIIDQErrorFile"="/iissamples/issamples/IDQError.htx"
"ISAPIHTXErrorFile"="/iissamples/issamples/HTXError.htx"
"ISAPIRestrictionErrorFile"="/iissamples/issamples/ResError.htx"
"ISAPIDefaultErrorFile"="/iissamples/issamples/DefError.htx"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ContentIndex\Language\Neutral]
"ISAPIIDQErrorFile"="/iissamples/issamples/IDQError.htx"
"ISAPIHTXErrorFile"="/iissamples/issamples/HTXError.htx"
"ISAPIRestrictionErrorFile"="/iissamples/issamples/ResError.htx"
"ISAPIDefaultErrorFile"="/iissamples/issamples/DefError.htx"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ContentIndex\Language\Spanish_Modern]
"ISAPIIDQErrorFile"="/iissamples/issamples/IDQError.htx"
"ISAPIHTXErrorFile"="/iissamples/issamples/HTXError.htx"
"ISAPIRestrictionErrorFile"="/iissamples/issamples/ResError.htx"
"ISAPIDefaultErrorFile"="/iissamples/issamples/DefError.htx"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ContentIndex\Language\Swedish_Default]
"ISAPIIDQErrorFile"="/iissamples/issamples/IDQError.htx"
"ISAPIHTXErrorFile"="/iissamples/issamples/HTXError.htx"
"ISAPIRestrictionErrorFile"="/iissamples/issamples/ResError.htx"
"ISAPIDefaultErrorFile"="/iissamples/issamples/DefError.htx"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ContentIndex\Language\Thai_Default]
"ISAPIIDQErrorFile"="/iissamples/issamples/IDQError.htx"
"ISAPIHTXErrorFile"="/iissamples/issamples/HTXError.htx"
"ISAPIRestrictionErrorFile"="/iissamples/issamples/ResError.htx"
"ISAPIDefaultErrorFile"="/iissamples/issamples/DefError.htx"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MediaCategories\{9DB7B9E0-C555-11D0-8A2B-00A0C9255AC1}]
"Name"="Sample Rate Converter"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\PnP\PciIrqRouting\IrqRoutingTables]
; Contents of value:
; 
"VLSI Sample"=hex:18,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00
; Contents of value:
; 
"Intel 430MX Motherboard Sample"=hex:18,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\ACPI\PNP0F13\4&61f3b4b&0\Device Parameters]
"SampleRate"=dword:00000064

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"@C:\\WINDOWS\\inf\\unregmp2.exe,-161"="Sample Playlists"

[HKEY_USERS\S-1-5-21-1915252640-990530783-3061874673-1009\Software\Google\CommonSettings]
"WMSServers"="http://atlas.walis.wa.gov.au/servlet/com.esri.wms.Esrimap http://blackice.pfc.forestry.ca/cubestor/c…rv/cubeserv.cgi http://ceoware2.ccrs.nrcan.gc.ca/cubewerx/…rv/cubeserv.cgi http://cgdi-dev.geoconnections.org/cgi-bin/tomatlasmapper http://cgns.nrcan.gc.ca/wms/cubeserv.cgi http://clearinghouse1.fgdc.gov/scripts/ogc/ms.pl http://demo.cubewerx.com/demo/cubeserv/cubeserv.cgi http://dev.geographynetwork.ca/ogcwms/serv….wms.WMSServlet http://edcw2ks51.cr.usgs.gov/servlet/com.esri.wms.Esrimap http://gis.vibamt.dk/ArealInfo/AI_WMS.asp http://gisdata.usgs.net/servlet/com.esri.wms.Esrimap http://globe.digitalearth.gov/viz-bin/wmt.cgi http://iceds.ge.ucl.ac.uk/cgi-bin/wms http://linuxgurrl.agr.ca/cgi-bin/mapeco http://maps.customweather.com/image http://maps1.intergraph.com/wms/ussample/request.asp http://maps1.intergraph.com/wms/world/request.asp http://mapserv2.esrin.esa.it/cubestor/cubeserv/cubeserv.cgi http://mapster.esri.com/ows1/servlet/com.e….wms.WMSServlet http://nautilus.baruch.sc.edu/wms/seacoos_in_situ http://nautilus.baruch.sc.edu/wms/seacoos_rs http://redspider.us/CarbonProject/wfs/BOSTON_PG http://regis.intergraph.com/wfs/dcmetro/request.asp http://slkapps2.env.gov.bc.ca/servlet/com.esri.wms.Esrimap http://terraservice.net/ogccapabilities.ashx http://wms.cits.nrcan.gc.ca/cgi-bin/cubeserv.cgi http://wms.jpl.nasa.gov/wms.cgi http://www.demis.nl/mapserver/request.asp http://www.geographynetwork.com/servlet/com.esri.wms.Esrimap http://www.gis2.nrw.de/wmsconnector/wms/stobo http://www.gworks.ca/site/lib/wms/simple_wms.php http://www.lifemapper.org/Services/WMS/ http://www.nztopoonline.linz.govt.nz/wmsco…sri.wms.Esrimap http://www2.demis.nl/mapserver/request.asp http://www2.dmsolutions.ca/cgi-bin/mswms_gmap "

[HKEY_USERS\S-1-5-21-1915252640-990530783-3061874673-1009\Software\Google\GECommonSettings]
"WMSServers"="http://atlas.walis.wa.gov.au/servlet/com.esri.wms.Esrimap http://blackice.pfc.forestry.ca/cubestor/c…rv/cubeserv.cgi http://ceoware2.ccrs.nrcan.gc.ca/cubewerx/…rv/cubeserv.cgi http://cgdi-dev.geoconnections.org/cgi-bin/tomatlasmapper http://cgns.nrcan.gc.ca/wms/cubeserv.cgi http://clearinghouse1.fgdc.gov/scripts/ogc/ms.pl http://demo.cubewerx.com/demo/cubeserv/cubeserv.cgi http://dev.geographynetwork.ca/ogcwms/serv….wms.WMSServlet http://edcw2ks51.cr.usgs.gov/servlet/com.esri.wms.Esrimap http://gis.vibamt.dk/ArealInfo/AI_WMS.asp http://gisdata.usgs.net/servlet/com.esri.wms.Esrimap http://globe.digitalearth.gov/viz-bin/wmt.cgi http://iceds.ge.ucl.ac.uk/cgi-bin/wms http://linuxgurrl.agr.ca/cgi-bin/mapeco http://maps.customweather.com/image http://maps1.intergraph.com/wms/ussample/request.asp http://maps1.intergraph.com/wms/world/request.asp http://mapserv2.esrin.esa.it/cubestor/cubeserv/cubeserv.cgi http://mapster.esri.com/ows1/servlet/com.e….wms.WMSServlet http://nautilus.baruch.sc.edu/wms/seacoos_in_situ http://nautilus.baruch.sc.edu/wms/seacoos_rs http://redspider.us/CarbonProject/wfs/BOSTON_PG http://regis.intergraph.com/wfs/dcmetro/request.asp http://slkapps2.env.gov.bc.ca/servlet/com.esri.wms.Esrimap http://terraservice.net/ogccapabilities.ashx http://wms.cits.nrcan.gc.ca/cgi-bin/cubeserv.cgi http://wms.jpl.nasa.gov/wms.cgi http://www.demis.nl/mapserver/request.asp http://www.geographynetwork.com/servlet/com.esri.wms.Esrimap http://www.gis2.nrw.de/wmsconnector/wms/stobo http://www.gworks.ca/site/lib/wms/simple_wms.php http://www.lifemapper.org/Services/WMS/ http://www.nztopoonline.linz.govt.nz/wmsco…sri.wms.Esrimap http://www2.demis.nl/mapserver/request.asp http://www2.dmsolutions.ca/cgi-bin/mswms_gmap "

[HKEY_USERS\S-1-5-21-1915252640-990530783-3061874673-1009\Software\Jasc\Paint Shop Photo Album Dell Edition\Recent Album List]
"Proj1"="C:\\Program Files\\Jasc Software Inc\\Paint Shop Photo Album\\Samples"

[HKEY_USERS\S-1-5-21-1915252640-990530783-3061874673-1009\Software\Jasc\Paint Shop Photo Album Dell Edition\State]
"AlbumList"="C:\\Program Files\\Jasc Software Inc\\Paint Shop Photo Album\\Samples"

[HKEY_USERS\S-1-5-21-1915252640-990530783-3061874673-1009\Software\Lake\LakeControl\1.0\DolbyHph\Selected]
"SampleRate"=dword:0000bb80

[HKEY_USERS\S-1-5-21-1915252640-990530783-3061874673-1009\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\samplegals.com]

[HKEY_USERS\S-1-5-21-1915252640-990530783-3061874673-1009\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"@C:\\WINDOWS\\inf\\unregmp2.exe,-161"="Sample Playlists"

[HKEY_USERS\S-1-5-21-1915252640-990530783-3061874673-1009\Software\RealNetworks\Visualizations]
"VizSampleRate"=dword:00000014

[HKEY_USERS\S-1-5-21-1915252640-990530783-3061874673-1009\Software\SPSS\SPSS for Windows Student Version\12.0\Graphics\Legends]
"MinSampleSpacing"="0.250000"
"ScaleSampleSpacing"="0.050000"

[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"@C:\\WINDOWS\\inf\\unregmp2.exe,-161"="Sample Playlists"

; End Of The Log…

Josh
:scratch: Why not try this. Boot in "safe mode". Make a HijackThis! log. Boot in normal mode. Post the log in this thread. Maybe that will shed some light. :)
Micah 6:8,

Sorry for the delay. Here is the log:

Logfile of HijackThis v1.99.1
Scan saved at 7:48:56 AM, on 7/3/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Administrator\Desktop\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.dell.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [bacstray] BacsTray.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [untray] C:\PROGRA~1\COMMAN~1\COMMAN~1\untray.exe
O4 - HKLM\..\Run: [CSAV_CheckViruses] C:\PROGRA~1\COMMAN~1\COMMAN~1\vchk.exe
O4 - HKLM\..\Run: [avtray] C:\PROGRA~1\COMMAN~1\COMMAN~1\avtray.exe
O4 - HKLM\..\Run: [dvprpt] C:\PROGRA~1\COMMAN~1\COMMAN~1\dvprpt.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office Outlook 2003 (2).lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\npjpi150_07.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\npjpi150_07.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - https://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish.com/SnapfishActivia.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1129417033334
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O20 - Winlogon Notify: Sebring - C:\WINDOWS\System32\LgNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: avinitnt - Command Software Systems, Inc. - C:\Program Files\Command Software\Command AntiVirus\avinitnt.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: schscnt - Command Software Systems, Inc. - C:\Program Files\Command Software\Command AntiVirus\schscnt.exe

Have a great 4th!!
Josh
This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI