alleymize
2007-02-17, 20:55
I am not sure what this thing is that keeps annoying me with popups that just won't go away. I have scanned with Spybot, Adware, LSPfix, NoLop wich did find something, spyware blaster, trojanhunter and spywaredoctor and whatever else I could find and I still get popups, even when I don't have explore open. I also use Maxthon and it does the same in it as well. Not sure what the trigger is because sometimes I can go a few hours with nothing and then I will get a bunch with every web page I open. I ran Hijackthis and removed some items and still get the popups. Here is my newest log if anyone can offer any help it would greatly be appreciated.
Logfile of HijackThis v1.99.1
Scan saved at 1:55:11 PM, on 2/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
J:\WINDOWS\System32\smss.exe
J:\WINDOWS\system32\winlogon.exe
J:\WINDOWS\system32\services.exe
J:\WINDOWS\system32\lsass.exe
J:\WINDOWS\system32\svchost.exe
J:\WINDOWS\System32\svchost.exe
J:\WINDOWS\system32\spoolsv.exe
J:\Program Files\AutoMate 6\AMTS.exe
J:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
J:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
J:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
J:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
J:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
J:\Program Files\HHVcdV6Sys\VC6SecS.exe
J:\WINDOWS\Explorer.EXE
J:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
J:\WINDOWS\system32\WgaTray.exe
J:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
J:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
J:\Program Files\HHVcdV6Sys\VC6Play.exe
J:\Program Files\AutoMate 6\AMEM.exe
J:\Program Files\Dynamic\Dynamic Submission V7\Scheduler.exe
J:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe
J:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
J:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
J:\Program Files\Novosoft\Handy Backup\hbagent.exe
J:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
J:\Program Files\WinZip\WZQKPICK.EXE
j:\progra~1\maxthon\maxthon.exe
J:\Program Files\KeyText\KeyText.exe
J:\Program Files\Extensis\Suitcase 9.2\Suitcase.exe
J:\Program Files\KeyText\KeyText.exe
J:\Program Files\Maxthon\Maxthon.exe
J:\Program Files\Virtual CD v6\System\VC6Tray.exe
J:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE
J:\Program Files\Maxthon\Maxthon.exe
J:\WINDOWS\system32\winlogon.exe
J:\WINDOWS\system32\rdpclip.exe
J:\WINDOWS\system32\logonui.exe
J:\WINDOWS\system32\logon.scr
J:\HJT\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - J:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Sample IE BHO - {45E1A125-41A3-4253-A5EC-3354A4E7C56D} - J:\Program Files\Novosoft\Handy Backup\Plugins\LinkSave.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - J:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - J:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - J:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - J:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - J:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "J:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [VC6Player] "J:\Program Files\HHVcdV6Sys\VC6Play.exe"
O4 - HKLM\..\Run: [pccguide.exe] "J:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"
O4 - HKLM\..\Run: [AutoMate6] "J:\Program Files\AutoMate 6\AMEM.exe"
O4 - HKLM\..\Run: [DSScheduler] "J:\Program Files\Dynamic\Dynamic Submission V7\Scheduler.exe" \1
O4 - HKLM\..\Run: [flagmpegstyleshim] J:\Documents and Settings\All Users\Application Data\Bike Dash Flag Mpeg\PUREHECK.exe
O4 - HKCU\..\Run: [OE] "J:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [RoboForm] "J:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "J:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - HKCU\..\Run: [Bind drive] J:\DOCUME~1\TimPC\APPLIC~1\GPLSTY~1\32 move flap.exe
O4 - HKCU\..\Run: [Handy Backup 5.4] "J:\Program Files\Novosoft\Handy Backup\hbagent.exe" -logon
O4 - Startup: Adobe Gamma.lnk = J:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: KeyText.lnk = J:\Program Files\KeyText\KeyText.exe
O4 - Startup: Shortcut to Suitcase.exe.lnk = J:\Program Files\Extensis\Suitcase 9.2\Suitcase.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: QuickBooks Update Agent.lnk = J:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: WinZip Quick Pick.lnk = J:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Convert link target to Adobe PDF - res://J:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://J:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://J:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://J:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://J:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://J:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://J:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://J:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Customize Menu - file://J:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://J:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://J:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: Save Forms - file://J:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://J:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://J:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://J:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://J:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://J:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://J:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - J:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - J:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - J:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1162148797093
O20 - Winlogon Notify: hblogon - J:\WINDOWS\SYSTEM32\hblogon.dll
O20 - Winlogon Notify: WgaLogon - J:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - J:\WINDOWS\
O23 - Service: Adobe LM Service - Adobe Systems - J:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AutoMate 6 (AutoMate6) - Network Automation, Inc. - J:\Program Files\AutoMate 6\AMTS.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - J:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - J:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - J:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - J:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - J:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - J:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - J:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: Virtual CD v6 Management Service (VC6SecS) - H+H Software GmbH - J:\Program Files\HHVcdV6Sys\VC6SecS.exe
Logfile of HijackThis v1.99.1
Scan saved at 1:55:11 PM, on 2/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
J:\WINDOWS\System32\smss.exe
J:\WINDOWS\system32\winlogon.exe
J:\WINDOWS\system32\services.exe
J:\WINDOWS\system32\lsass.exe
J:\WINDOWS\system32\svchost.exe
J:\WINDOWS\System32\svchost.exe
J:\WINDOWS\system32\spoolsv.exe
J:\Program Files\AutoMate 6\AMTS.exe
J:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
J:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
J:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
J:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
J:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
J:\Program Files\HHVcdV6Sys\VC6SecS.exe
J:\WINDOWS\Explorer.EXE
J:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
J:\WINDOWS\system32\WgaTray.exe
J:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
J:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
J:\Program Files\HHVcdV6Sys\VC6Play.exe
J:\Program Files\AutoMate 6\AMEM.exe
J:\Program Files\Dynamic\Dynamic Submission V7\Scheduler.exe
J:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe
J:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
J:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
J:\Program Files\Novosoft\Handy Backup\hbagent.exe
J:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
J:\Program Files\WinZip\WZQKPICK.EXE
j:\progra~1\maxthon\maxthon.exe
J:\Program Files\KeyText\KeyText.exe
J:\Program Files\Extensis\Suitcase 9.2\Suitcase.exe
J:\Program Files\KeyText\KeyText.exe
J:\Program Files\Maxthon\Maxthon.exe
J:\Program Files\Virtual CD v6\System\VC6Tray.exe
J:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE
J:\Program Files\Maxthon\Maxthon.exe
J:\WINDOWS\system32\winlogon.exe
J:\WINDOWS\system32\rdpclip.exe
J:\WINDOWS\system32\logonui.exe
J:\WINDOWS\system32\logon.scr
J:\HJT\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - J:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Sample IE BHO - {45E1A125-41A3-4253-A5EC-3354A4E7C56D} - J:\Program Files\Novosoft\Handy Backup\Plugins\LinkSave.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - J:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - J:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - J:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - J:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - J:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "J:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [VC6Player] "J:\Program Files\HHVcdV6Sys\VC6Play.exe"
O4 - HKLM\..\Run: [pccguide.exe] "J:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"
O4 - HKLM\..\Run: [AutoMate6] "J:\Program Files\AutoMate 6\AMEM.exe"
O4 - HKLM\..\Run: [DSScheduler] "J:\Program Files\Dynamic\Dynamic Submission V7\Scheduler.exe" \1
O4 - HKLM\..\Run: [flagmpegstyleshim] J:\Documents and Settings\All Users\Application Data\Bike Dash Flag Mpeg\PUREHECK.exe
O4 - HKCU\..\Run: [OE] "J:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [RoboForm] "J:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "J:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - HKCU\..\Run: [Bind drive] J:\DOCUME~1\TimPC\APPLIC~1\GPLSTY~1\32 move flap.exe
O4 - HKCU\..\Run: [Handy Backup 5.4] "J:\Program Files\Novosoft\Handy Backup\hbagent.exe" -logon
O4 - Startup: Adobe Gamma.lnk = J:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: KeyText.lnk = J:\Program Files\KeyText\KeyText.exe
O4 - Startup: Shortcut to Suitcase.exe.lnk = J:\Program Files\Extensis\Suitcase 9.2\Suitcase.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: QuickBooks Update Agent.lnk = J:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: WinZip Quick Pick.lnk = J:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Convert link target to Adobe PDF - res://J:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://J:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://J:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://J:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://J:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://J:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://J:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://J:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Customize Menu - file://J:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://J:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://J:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: Save Forms - file://J:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://J:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://J:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://J:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://J:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://J:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://J:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - J:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - J:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - J:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1162148797093
O20 - Winlogon Notify: hblogon - J:\WINDOWS\SYSTEM32\hblogon.dll
O20 - Winlogon Notify: WgaLogon - J:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - J:\WINDOWS\
O23 - Service: Adobe LM Service - Adobe Systems - J:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AutoMate 6 (AutoMate6) - Network Automation, Inc. - J:\Program Files\AutoMate 6\AMTS.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - J:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - J:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - J:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - J:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - J:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - J:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - J:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: Virtual CD v6 Management Service (VC6SecS) - H+H Software GmbH - J:\Program Files\HHVcdV6Sys\VC6SecS.exe