drfitzer

Members
  • Content Count

    2
  • Joined

  • Last visited

Posts posted by drfitzer

  1. I am trying to get rid of a trojan on my daughter's computer. A popup from her Norton antivirus keps appearing which says that there is a Trojan Vundo virus present. It references file c:\WINDOWS\repair\bardobc.dll. Norton says it has tried to repair it and failed, and tried to quarantine it and failed. There are no noticealbe negative effects but I'm sure that there are bad things happening that I can't see. I'm coppying the hijackthis log file below and hoe you can help. Thanks.

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 10:44:40 AM, on 12/22/2007

    Platform: Windows XP SP1 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Boot mode: Normal

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\System32\ibmpmsvc.exe

    C:\WINDOWS\System32\Ati2evxx.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\Program Files\Bonjour\mDNSResponder.exe

    C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe

    C:\Program Files\NavNT\defwatch.exe

    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

    C:\Program Files\NavNT\rtvscan.exe

    C:\WINDOWS\System32\QCONSVC.EXE

    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\TpKmpSVC.exe

    C:\Program Files\80211abg\acs.exe

    C:\WINDOWS\system32\Ati2evxx.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\System32\ctfmon.exe

    C:\Program Files\NavNT\vptray.exe

    C:\WINDOWS\System32\taskswitch.exe

    C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe

    C:\WINDOWS\System32\RunDll32.exe

    C:\WINDOWS\System32\TpScrLk.exe

    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    C:\WINDOWS\System32\TpShocks.exe

    C:\IBMTOOLS\UTILS\ibmprc.exe

    C:\Program Files\ThinkPad\UltraNav Wizard\UNavTray.EXE

    C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE

    C:\PROGRA~1\ThinkPad\CONNEC~1\QCWLIcon.exe

    C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe

    C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe

    C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe

    C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe

    C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe

    C:\Program Files\Common Files\Real\Update_OB\realsched.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    C:\PROGRA~1\MOZILLA.ORG\MOZILLA\MOZILLA.EXE

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://student.wfu.edu/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/...rch/search.html

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://student.wfu.edu/

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    O2 - BHO: (no name) - {01233619-9E4A-4499-8206-FA8463DAB9E0} - (no file)

    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll

    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

    O2 - BHO: (no name) - {67B27373-E757-4D4D-A73A-1C5C6AA0FE51} - (no file)

    O2 - BHO: (no name) - {B7490636-DACB-4CE4-A3B5-C65E5D51882C} - C:\WINDOWS\repair\bardobc.dll

    O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll

    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll

    O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe

    O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\System32\taskswitch.exe

    O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe

    O4 - HKLM\..\Run: [bMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor

    O4 - HKLM\..\Run: [bMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE

    O4 - HKLM\..\Run: [TPKBDLED] C:\WINDOWS\System32\TpScrLk.exe

    O4 - HKLM\..\Run: [TP4EX] tp4ex.exe

    O4 - HKLM\..\Run: [synTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

    O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    O4 - HKLM\..\Run: [TpShocks] TpShocks.exe

    O4 - HKLM\..\Run: [iBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe

    O4 - HKLM\..\Run: [iMJPMIG9.0] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMJP9\IMJPMIG.EXE /Preload /Migration32

    O4 - HKLM\..\Run: [CJIMETIPSYNC] C:\Program Files\Common Files\Microsoft Shared\IME\IMTC65\CHANGJIE\CINTLCFG.EXE /CJIMETIPSync

    O4 - HKLM\..\Run: [PHIMETIPSYNC] C:\Program Files\Common Files\Microsoft Shared\IME\IMTC65\PHONETIC\TINTLCFG.EXE /PHIMETIPSync

    O4 - HKLM\..\Run: [iMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload

    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe

    O4 - HKLM\..\Run: [ATIPTA] C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE

    O4 - HKLM\..\Run: [QCWLICON] C:\PROGRA~1\ThinkPad\CONNEC~1\QCWLIcon.exe

    O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe

    O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper

    O4 - HKLM\..\Run: [QCTray] C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    O4 - HKLM\..\RunOnce: [spybotDeletingA6713] command /c del "C:\Program Files\Enigma Software Group\SpyHunter\EnigmaUpdater.dll_tobedeleted_old"

    O4 - HKLM\..\RunOnce: [spybotDeletingC7681] cmd /c del "C:\Program Files\Enigma Software Group\SpyHunter\EnigmaUpdater.dll_tobedeleted_old"

    O4 - HKLM\..\RunOnce: [spybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck

    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe

    O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup

    O4 - HKCU\..\RunOnce: [spybotDeletingB5060] command /c del "C:\Program Files\Enigma Software Group\SpyHunter\EnigmaUpdater.dll_tobedeleted_old"

    O4 - HKCU\..\RunOnce: [spybotDeletingD3748] cmd /c del "C:\Program Files\Enigma Software Group\SpyHunter\EnigmaUpdater.dll_tobedeleted_old"

    O4 - HKUS\S-1-5-18\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background (User 'SYSTEM')

    O4 - HKUS\.DEFAULT\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background (User 'Default user')

    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm

    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\aim.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)

    O11 - Options group: [JAVA_IBM] Java (IBM)

    O12 - Plugin for .csm: C:\Program Files\Internet Explorer\Plugins\npchime.dll

    O12 - Plugin for .csml: C:\Program Files\Internet Explorer\Plugins\npchime.dll

    O12 - Plugin for .cub: C:\Program Files\Internet Explorer\Plugins\npchime.dll

    O12 - Plugin for .cube: C:\Program Files\Internet Explorer\Plugins\npchime.dll

    O12 - Plugin for .dx: C:\Program Files\Internet Explorer\Plugins\npchime.dll

    O12 - Plugin for .emb: C:\Program Files\Internet Explorer\Plugins\npchime.dll

    O12 - Plugin for .embl: C:\Program Files\Internet Explorer\Plugins\npchime.dll

    O12 - Plugin for .gau: C:\Program Files\Internet Explorer\Plugins\npchime.dll

    O12 - Plugin for .jdx: C:\Program Files\Internet Explorer\Plugins\npchime.dll

    O12 - Plugin for .mol: C:\Program Files\Internet Explorer\Plugins\npchime.dll

    O12 - Plugin for .mop: C:\Program Files\Internet Explorer\Plugins\npchime.dll

    O12 - Plugin for .mts: C:\Program Files\MetaCreations\MetaStream\npmetastream.dll

    O12 - Plugin for .NPSSView: C:\Program Files\Seagate Software\Viewers\ActiveXViewer\NPssView.dll

    O12 - Plugin for .pdb: C:\Program Files\Internet Explorer\Plugins\npchime.dll

    O12 - Plugin for .rxn: C:\Program Files\Internet Explorer\Plugins\npchime.dll

    O12 - Plugin for .scr: C:\Program Files\Internet Explorer\Plugins\npchime.dll

    O12 - Plugin for .skc: C:\Program Files\Internet Explorer\Plugins\npchime.dll

    O12 - Plugin for .spt: C:\Program Files\Internet Explorer\Plugins\npchime.dll

    O12 - Plugin for .tgf: C:\Program Files\Internet Explorer\Plugins\npchime.dll

    O12 - Plugin for .xyz: C:\Program Files\Internet Explorer\Plugins\npchime.dll

    O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.com/SnapfishActivia.cab

    O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200312...meInstaller.exe

    O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab

    O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/..._1/axofupld.cab

    O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab

    O16 - DPF: {A1337CC4-FF8E-11D1-9C48-00A0CC20E0D0} (EZListings) - http://www.therealyellowpageslive.net/live/ezlistng.cab

    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = deacnet.wfu.edu

    O17 - HKLM\Software\..\Telephony: DomainName = deacnet.wfu.edu

    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = deacnet.wfu.edu

    O20 - Winlogon Notify: bardobc - C:\WINDOWS\repair\bardobc.dll

    O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\Program Files\80211abg\acs.exe

    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe

    O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe

    O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe

    O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe

    O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe

    O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe

    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe

    O23 - Service: Alias Maya 5.0 PLE Help Server (Maya5PLEHelpServer) - Unknown owner - C:\Program Files\AliasWavefront\Maya 5.0 Personal Learning Edition\docs\Wrapper.exe

    O23 - Service: Intel NCS NetService (NetSvc) - IntelĀ® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe

    O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe

    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe

    O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)

    O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE

    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

    O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe

  2. I am trying to get rid of a trojan on my daughter's computer. A popup from her Norton antivirus keps appearing which says that there is a Trojan Vundo virus present. It references file c:\WINDOWS\repair\bardobc.dll. Norton says it has tried to repair it and failed, and tried to quarantine it and failed. There are no noticealbe negative effects but I'm sure that there are bad things happening that I can't see. I'm coppying the hijackthis log file below and hoe you can help. Thanks.

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 10:44:40 AM, on 12/22/2007

    Platform: Windows XP SP1 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Boot mode: Normal

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\System32\ibmpmsvc.exe

    C:\WINDOWS\System32\Ati2evxx.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\Program Files\Bonjour\mDNSResponder.exe

    C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe

    C:\Program Files\NavNT\defwatch.exe

    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

    C:\Program Files\NavNT\rtvscan.exe

    C:\WINDOWS\System32\QCONSVC.EXE

    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\TpKmpSVC.exe

    C:\Program Files\80211abg\acs.exe

    C:\WINDOWS\system32\Ati2evxx.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\System32\ctfmon.exe

    C:\Program Files\NavNT\vptray.exe

    C:\WINDOWS\System32\taskswitch.exe

    C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe

    C:\WINDOWS\System32\RunDll32.exe

    C:\WINDOWS\System32\TpScrLk.exe

    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    C:\WINDOWS\System32\TpShocks.exe

    C:\IBMTOOLS\UTILS\ibmprc.exe

    C:\Program Files\ThinkPad\UltraNav Wizard\UNavTray.EXE

    C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE

    C:\PROGRA~1\ThinkPad\CONNEC~1\QCWLIcon.exe

    C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe

    C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe

    C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe

    C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe

    C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe

    C:\Program Files\Common Files\Real\Update_OB\realsched.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    C:\PROGRA~1\MOZILLA.ORG\MOZILLA\MOZILLA.EXE

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://student.wfu.edu/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/...rch/search.html

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://student.wfu.edu/

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    O2 - BHO: (no name) - {01233619-9E4A-4499-8206-FA8463DAB9E0} - (no file)

    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll

    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

    O2 - BHO: (no name) - {67B27373-E757-4D4D-A73A-1C5C6AA0FE51} - (no file)

    O2 - BHO: (no name) - {B7490636-DACB-4CE4-A3B5-C65E5D51882C} - C:\WINDOWS\repair\bardobc.dll

    O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll

    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll

    O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe

    O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\System32\taskswitch.exe

    O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe

    O4 - HKLM\..\Run: [bMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor

    O4 - HKLM\..\Run: [bMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE

    O4 - HKLM\..\Run: [TPKBDLED] C:\WINDOWS\System32\TpScrLk.exe

    O4 - HKLM\..\Run: [TP4EX] tp4ex.exe

    O4 - HKLM\..\Run: [synTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

    O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

    O4 - HKLM\..\Run: [TpShocks] TpShocks.exe

    O4 - HKLM\..\Run: [iBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe

    O4 - HKLM\..\Run: [iMJPMIG9.0] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMJP9\IMJPMIG.EXE /Preload /Migration32

    O4 - HKLM\..\Run: [CJIMETIPSYNC] C:\Program Files\Common Files\Microsoft Shared\IME\IMTC65\CHANGJIE\CINTLCFG.EXE /CJIMETIPSync

    O4 - HKLM\..\Run: [PHIMETIPSYNC] C:\Program Files\Common Files\Microsoft Shared\IME\IMTC65\PHONETIC\TINTLCFG.EXE /PHIMETIPSync

    O4 - HKLM\..\Run: [iMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload

    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe

    O4 - HKLM\..\Run: [ATIPTA] C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE

    O4 - HKLM\..\Run: [QCWLICON] C:\PROGRA~1\ThinkPad\CONNEC~1\QCWLIcon.exe

    O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe

    O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper

    O4 - HKLM\..\Run: [QCTray] C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    O4 - HKLM\..\RunOnce: [spybotDeletingA6713] command /c del "C:\Program Files\Enigma Software Group\SpyHunter\EnigmaUpdater.dll_tobedeleted_old"

    O4 - HKLM\..\RunOnce: [spybotDeletingC7681] cmd /c del "C:\Program Files\Enigma Software Group\SpyHunter\EnigmaUpdater.dll_tobedeleted_old"

    O4 - HKLM\..\RunOnce: [spybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck

    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe

    O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup

    O4 - HKCU\..\RunOnce: [spybotDeletingB5060] command /c del "C:\Program Files\Enigma Software Group\SpyHunter\EnigmaUpdater.dll_tobedeleted_old"

    O4 - HKCU\..\RunOnce: [spybotDeletingD3748] cmd /c del "C:\Program Files\Enigma Software Group\SpyHunter\EnigmaUpdater.dll_tobedeleted_old"

    O4 - HKUS\S-1-5-18\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background (User 'SYSTEM')

    O4 - HKUS\.DEFAULT\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background (User 'Default user')

    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm

    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\aim.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)

    O11 - Options group: [JAVA_IBM] Java (IBM)

    O12 - Plugin for .csm: C:\Program Files\Internet Explorer\Plugins\npchime.dll

    O12 - Plugin for .csml: C:\Program Files\Internet Explorer\Plugins\npchime.dll

    O12 - Plugin for .cub: C:\Program Files\Internet Explorer\Plugins\npchime.dll

    O12 - Plugin for .cube: C:\Program Files\Internet Explorer\Plugins\npchime.dll

    O12 - Plugin for .dx: C:\Program Files\Internet Explorer\Plugins\npchime.dll

    O12 - Plugin for .emb: C:\Program Files\Internet Explorer\Plugins\npchime.dll

    O12 - Plugin for .embl: C:\Program Files\Internet Explorer\Plugins\npchime.dll

    O12 - Plugin for .gau: C:\Program Files\Internet Explorer\Plugins\npchime.dll

    O12 - Plugin for .jdx: C:\Program Files\Internet Explorer\Plugins\npchime.dll

    O12 - Plugin for .mol: C:\Program Files\Internet Explorer\Plugins\npchime.dll

    O12 - Plugin for .mop: C:\Program Files\Internet Explorer\Plugins\npchime.dll

    O12 - Plugin for .mts: C:\Program Files\MetaCreations\MetaStream\npmetastream.dll

    O12 - Plugin for .NPSSView: C:\Program Files\Seagate Software\Viewers\ActiveXViewer\NPssView.dll

    O12 - Plugin for .pdb: C:\Program Files\Internet Explorer\Plugins\npchime.dll

    O12 - Plugin for .rxn: C:\Program Files\Internet Explorer\Plugins\npchime.dll

    O12 - Plugin for .scr: C:\Program Files\Internet Explorer\Plugins\npchime.dll

    O12 - Plugin for .skc: C:\Program Files\Internet Explorer\Plugins\npchime.dll

    O12 - Plugin for .spt: C:\Program Files\Internet Explorer\Plugins\npchime.dll

    O12 - Plugin for .tgf: C:\Program Files\Internet Explorer\Plugins\npchime.dll

    O12 - Plugin for .xyz: C:\Program Files\Internet Explorer\Plugins\npchime.dll

    O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.com/SnapfishActivia.cab

    O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200312...meInstaller.exe

    O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab

    O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/..._1/axofupld.cab

    O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab

    O16 - DPF: {A1337CC4-FF8E-11D1-9C48-00A0CC20E0D0} (EZListings) - http://www.therealyellowpageslive.net/live/ezlistng.cab

    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = deacnet.wfu.edu

    O17 - HKLM\Software\..\Telephony: DomainName = deacnet.wfu.edu

    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = deacnet.wfu.edu

    O20 - Winlogon Notify: bardobc - C:\WINDOWS\repair\bardobc.dll

    O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\Program Files\80211abg\acs.exe

    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe

    O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe

    O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe

    O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe

    O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe

    O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe

    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe

    O23 - Service: Alias Maya 5.0 PLE Help Server (Maya5PLEHelpServer) - Unknown owner - C:\Program Files\AliasWavefront\Maya 5.0 Personal Learning Edition\docs\Wrapper.exe

    O23 - Service: Intel NCS NetService (NetSvc) - IntelĀ® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe

    O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe

    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe

    O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)

    O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE

    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

    O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe