Really need to get rid of this one, please help.
Here is my log:
Logfile of HijackThis v1.99.1
Scan saved at 11:23:37 AM, on 7/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\mnmsrvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\COMMON~1\FNTS~1\javaw.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\steve.corley\My Documents\?asks\??ool32.exe
C:\Program Files\Nortel Networks\Extranet_serv.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\WinZip\winzip32.exe
C:\DOCUME~1\STEVE~1.COR\LOCALS~1\Temp\HijackThis.exe
O4 - HKLM\..\Run: [GPLv3] rundll32.exe "C:\WINDOWS\system32\rsqqktgv.dll",realset
O4 - HKLM\..\RunOnce: [!CleanupNetMeetingDispDriver] "C:\WINDOWS\system32\rundll32.exe" msconf.dll,CleanupNetMeetingDispDriver 0
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Tair] "C:\PROGRA~1\COMMON~1\FNTS~1\javaw.exe" -vt ndrv
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O16 - DPF: {100C659D-2B0B-4BEF-B79A-34E4659B9A9C} (Pivotal ePower Lifecycle Engine (Version 5.7) - Platform Access (rdaclnt.dll)) - https://avenerm.avendra.com/epower/cab/RDACLNT.CAB
O16 - DPF: {149006D7-3F51-49CD-8BB7-B57B07255F28} (Pivotal eRelationship Active Access (Version 5.7) - Static list Support (rdauistaticlists.dll)) - https://avenerm.avendra.com/epower/cab/RDAUISTATICLISTS.CAB
O16 - DPF: {154E3A83-BDE2-441E-A22C-EDAED67CF23A} (Pivotal eRelationship Active Access (Version 5.7) - Resources (rdares.dll)) - https://avenerm.avendra.com/epower/cab/RDARES.CAB
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {286BCCBE-B061-4EF3-BAFA-C6D36F164DAB} (Pivotal eRelationship Active Access (Version 5.7) - Portal Preferences Page (rprefs.dll)) - https://avenerm.avendra.com/epower/cab/RDAPREFS.CAB
O16 - DPF: {309F16B3-B30C-4114-BE89-E63C4F593B41} (Pivotal eRelationship Active Access (Version 5.7) - Smart Portal (rdaprtl.dll)) - https://avenerm.avendra.com/epower/cab/RDAPRTL.CAB
O16 - DPF: {44F898AB-C146-4252-AEDC-7D46B32F7FA8} (Pivotal eRelationship Active Access (Version 5.7) - Report Interface (rdaRprt.dll)) - https://avenerm.avendra.com/epower/cab/RDARPRT.CAB
O16 - DPF: {46286333-DFFE-48FC-BF9A-DE461D8E682E} (Pivotal eRelationship Active Access (Version 5.7) - Colour Scheme Details (rdashare.dll)) - https://avenerm.avendra.com/epower/cab/RDASHARE.CAB
O16 - DPF: {644A61B8-C407-46D4-B455-05696AB16017} (Pivotal eRelationship Active Access (Version 5.7) - Charting Class (rdachart.dll)) - https://avenerm.avendra.com/epower/cab/RDACHART.CAB
O16 - DPF: {678C83FA-9073-466B-B4B2-D33A80C8BF62} (Pivotal eRelationship Active Access (Version 5.7) - Letter Express Options (RdaUI.dll)) - https://avenerm.avendra.com/epower/cab/RDAUI.CAB
O16 - DPF: {8C42DAC2-0B6A-4F80-9794-3130E1C28345} (Pivotal eRelationship Active Access (Version 5.7) - Email Connector (rdaemail.dll)) - https://avenerm.avendra.com/epower/cab/RDAEMAIL.CAB
O16 - DPF: {A4BD9732-328D-11D4-BB89-00A0C9843488} (Pivotal ePower Lifecycle Engine (Version 5.7) - EMail Class (rn1sendx.dll)) - https://avenerm.avendra.com/epower/cab/RN1SENDX.CAB
O16 - DPF: {AE4F48D0-6A0A-11D3-9FB0-005004A79108} (Pivotal eRelationship Active Access (Version 5.7) - Plug-in Result Return Collection (dfoutils.dll)) - https://avenerm.avendra.com/epower/cab/DFOUTILS.CAB
O16 - DPF: {B6656F10-AE21-470F-8435-4030A8C05C9E} (Pivotal eRelationship Active Access (version 5.7) - Shortcut Menu Handler) - https://avenerm.avendra.com/epower/cab/RSHORTCUT.CAB
O16 - DPF: {E774F171-CCB6-424B-877B-1D4F95DF60AD} (Pivotal eRelationship Active Access (Version 5.7) - Letter Express (rdaletex.dll)) - https://avenerm.avendra.com/epower/cab/RDALETEX.CAB
O16 - DPF: {F9FEBBA1-5C27-4CC5-817C-C26AC8861DFD} (Pivotal ePower Lifecycle Engine (Version 5.7) - Component Catalog (rdaobjcreate.dll)) - https://avenerm.avendra.com/epower/cab/RDAOBJCREATE.CAB
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = avendra.com
O17 - HKLM\Software\..\Telephony: DomainName = avendra.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{CA3C4394-C34E-4D7C-ACB6-B51DC0B68CBB}: NameServer = 172.31.19.110,172.31.19.111
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = avendra.com
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Nortel Networks\Extranet_serv.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files\Common Framework\FrameworkService.exe" /ServiceStart (file missing)
Here is my log:
Logfile of HijackThis v1.99.1
Scan saved at 11:23:37 AM, on 7/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\mnmsrvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\COMMON~1\FNTS~1\javaw.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\steve.corley\My Documents\?asks\??ool32.exe
C:\Program Files\Nortel Networks\Extranet_serv.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\WinZip\winzip32.exe
C:\DOCUME~1\STEVE~1.COR\LOCALS~1\Temp\HijackThis.exe
O4 - HKLM\..\Run: [GPLv3] rundll32.exe "C:\WINDOWS\system32\rsqqktgv.dll",realset
O4 - HKLM\..\RunOnce: [!CleanupNetMeetingDispDriver] "C:\WINDOWS\system32\rundll32.exe" msconf.dll,CleanupNetMeetingDispDriver 0
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Tair] "C:\PROGRA~1\COMMON~1\FNTS~1\javaw.exe" -vt ndrv
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O16 - DPF: {100C659D-2B0B-4BEF-B79A-34E4659B9A9C} (Pivotal ePower Lifecycle Engine (Version 5.7) - Platform Access (rdaclnt.dll)) - https://avenerm.avendra.com/epower/cab/RDACLNT.CAB
O16 - DPF: {149006D7-3F51-49CD-8BB7-B57B07255F28} (Pivotal eRelationship Active Access (Version 5.7) - Static list Support (rdauistaticlists.dll)) - https://avenerm.avendra.com/epower/cab/RDAUISTATICLISTS.CAB
O16 - DPF: {154E3A83-BDE2-441E-A22C-EDAED67CF23A} (Pivotal eRelationship Active Access (Version 5.7) - Resources (rdares.dll)) - https://avenerm.avendra.com/epower/cab/RDARES.CAB
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {286BCCBE-B061-4EF3-BAFA-C6D36F164DAB} (Pivotal eRelationship Active Access (Version 5.7) - Portal Preferences Page (rprefs.dll)) - https://avenerm.avendra.com/epower/cab/RDAPREFS.CAB
O16 - DPF: {309F16B3-B30C-4114-BE89-E63C4F593B41} (Pivotal eRelationship Active Access (Version 5.7) - Smart Portal (rdaprtl.dll)) - https://avenerm.avendra.com/epower/cab/RDAPRTL.CAB
O16 - DPF: {44F898AB-C146-4252-AEDC-7D46B32F7FA8} (Pivotal eRelationship Active Access (Version 5.7) - Report Interface (rdaRprt.dll)) - https://avenerm.avendra.com/epower/cab/RDARPRT.CAB
O16 - DPF: {46286333-DFFE-48FC-BF9A-DE461D8E682E} (Pivotal eRelationship Active Access (Version 5.7) - Colour Scheme Details (rdashare.dll)) - https://avenerm.avendra.com/epower/cab/RDASHARE.CAB
O16 - DPF: {644A61B8-C407-46D4-B455-05696AB16017} (Pivotal eRelationship Active Access (Version 5.7) - Charting Class (rdachart.dll)) - https://avenerm.avendra.com/epower/cab/RDACHART.CAB
O16 - DPF: {678C83FA-9073-466B-B4B2-D33A80C8BF62} (Pivotal eRelationship Active Access (Version 5.7) - Letter Express Options (RdaUI.dll)) - https://avenerm.avendra.com/epower/cab/RDAUI.CAB
O16 - DPF: {8C42DAC2-0B6A-4F80-9794-3130E1C28345} (Pivotal eRelationship Active Access (Version 5.7) - Email Connector (rdaemail.dll)) - https://avenerm.avendra.com/epower/cab/RDAEMAIL.CAB
O16 - DPF: {A4BD9732-328D-11D4-BB89-00A0C9843488} (Pivotal ePower Lifecycle Engine (Version 5.7) - EMail Class (rn1sendx.dll)) - https://avenerm.avendra.com/epower/cab/RN1SENDX.CAB
O16 - DPF: {AE4F48D0-6A0A-11D3-9FB0-005004A79108} (Pivotal eRelationship Active Access (Version 5.7) - Plug-in Result Return Collection (dfoutils.dll)) - https://avenerm.avendra.com/epower/cab/DFOUTILS.CAB
O16 - DPF: {B6656F10-AE21-470F-8435-4030A8C05C9E} (Pivotal eRelationship Active Access (version 5.7) - Shortcut Menu Handler) - https://avenerm.avendra.com/epower/cab/RSHORTCUT.CAB
O16 - DPF: {E774F171-CCB6-424B-877B-1D4F95DF60AD} (Pivotal eRelationship Active Access (Version 5.7) - Letter Express (rdaletex.dll)) - https://avenerm.avendra.com/epower/cab/RDALETEX.CAB
O16 - DPF: {F9FEBBA1-5C27-4CC5-817C-C26AC8861DFD} (Pivotal ePower Lifecycle Engine (Version 5.7) - Component Catalog (rdaobjcreate.dll)) - https://avenerm.avendra.com/epower/cab/RDAOBJCREATE.CAB
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = avendra.com
O17 - HKLM\Software\..\Telephony: DomainName = avendra.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{CA3C4394-C34E-4D7C-ACB6-B51DC0B68CBB}: NameServer = 172.31.19.110,172.31.19.111
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = avendra.com
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Nortel Networks\Extranet_serv.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files\Common Framework\FrameworkService.exe" /ServiceStart (file missing)