Thank you so much for your help.
When I got to the step in Hijack This to "Fix Checked" I got a message that said "Registry editing has been disabled by your administrator". It looked like it went ahead and did it anyway, but I'm not sure. The computer seems to be acting exactly the same way as before (except the desktop background is gone now). I still can't access the control panel and still get the "This operation has been canceled due to restrictions..." message.
Anyway, here are the logs.
First, the old SD Fix log.
SDFix: Version 1.99
Run by Bud on Sat 08/18/2007 at 03:30 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: H:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
No Trojan Files Found
Removing Temp Files...
ADS Check:
H:\WINDOWS
No streams found.
H:\WINDOWS\system32
No streams found.
H:\WINDOWS\system32\svchost.exe
No streams found.
H:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"H:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\SAGENT4.EXE"="H:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\SAGENT4.EXE:*:Enabled:SAgent4"
"H:\\Program Files\\Messenger\\msmsgs.exe"="H:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"H:\\Program Files\\Microtek\\ScanWizard Pro\\LANServer.exe"="H:\\Program Files\\Microtek\\ScanWizard Pro\\LANServer.exe:*:Enabled:LAN Server"
"H:\\Program Files\\QuickTime\\QuickTimePlayer.exe"="H:\\Program Files\\QuickTime\\QuickTimePlayer.exe:*:Enabled:QuickTime Player"
"H:\\Program Files\\Pinnacle\\Studio 10\\programs\\RM.exe"="H:\\Program Files\\Pinnacle\\Studio 10\\programs\\RM.exe:*:Enabled:Render Manager"
"H:\\Program Files\\Pinnacle\\Studio 10\\programs\\Studio.exe"="H:\\Program Files\\Pinnacle\\Studio 10\\programs\\Studio.exe:*:Enabled:Studio"
"H:\\Program Files\\Pinnacle\\Studio 10\\programs\\PMSRegisterFile.exe"="H:\\Program Files\\Pinnacle\\Studio 10\\programs\\PMSRegisterFile.exe:*:Enabled:PMSRegisterFile"
"H:\\Program Files\\Pinnacle\\Studio 10\\programs\\umi.exe"="H:\\Program Files\\Pinnacle\\Studio 10\\programs\\umi.exe:*:Enabled:umi"
"H:\\Program Files\\Grisoft\\AVG7\\avginet.exe"="H:\\Program Files\\Grisoft\\AVG7\\avginet.exe:*:Enabled:avginet.exe"
"H:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"="H:\\Program Files\\Grisoft\\AVG7\\avgemc.exe:*:Enabled:avgemc.exe"
"H:\\Program Files\\Last.fm\\LastFM.exe"="H:\\Program Files\\Last.fm\\LastFM.exe:*:Enabled:LastFM"
"H:\\Program Files\\iTunes\\iTunes.exe"="H:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"H:\\Program Files\\Mozilla Firefox\\firefox.exe"="H:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Disabled:Firefox"
"H:\\Program Files\\Real\\RealPlayer\\realplay.exe"="H:\\Program Files\\Real\\RealPlayer\\realplay.exe:*:Enabled:RealPlayer"
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"="C:\\Program Files\\Real\\RealPlayer\\realplay.exe:*:Enabled:RealPlayer"
"%windir%\\system32\\winav.exe"="%windir%\\system32\\winav.exe:*:Enabled:@xpsp2res.dll,-22019"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\system32\\winav.exe"="%windir%\\system32\\winav.exe:*:Enabled:@xpsp2res.dll,-22019"
Remaining Files:
---------------
Files with Hidden Attributes:
H:\Documents and Settings\Bud\Application Data\U3\temp\Launchpad Removal.exe
H:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp
Finished
SmitFraudFix v2.213b
Scan done at 13:34:41.03, Mon 08/20/2007
Run from H:\Documents and Settings\Bud\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Killing process
»»»»»»»»»»»»»»»»»»»»»»»» hosts
192.168.200.3 ad.doubleclick.net
192.168.200.3 ad.fastclick.net
192.168.200.3 ads.fastclick.net
192.168.200.3 atdmt.com
192.168.200.3 awaps.net
192.168.200.3 banner.fastclick.net
192.168.200.3 banners.fastclick.net
192.168.200.3 click.atdmt.com
192.168.200.3 clicks.atdmt.com
192.168.200.3 engine.awaps.net
192.168.200.3 fastclick.net
192.168.200.3 ftp.avp.ch
192.168.200.3 ftp.kasperskylab.ru
192.168.200.3 updates5.kaspersky-labs.com
192.168.200.3 www.awaps.net
192.168.200.3 www.symantec.com
192.168.200.3 www.viruslist.ru
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
»»»»»»»»»»»»»»»»»»»»»»»» DNS
HKLM\SYSTEM\CCS\Services\Tcpip\..\{00470301-F087-47F6-9DF2-36B131E78226}: DhcpNameServer=192.168.254.254
HKLM\SYSTEM\CS1\Services\Tcpip\..\{00470301-F087-47F6-9DF2-36B131E78226}: DhcpNameServer=192.168.254.254
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.254.254
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.254.254
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
Registry Cleaning done.
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» End
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Monday, August 20, 2007 3:38:59 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 20/08/2007
Kaspersky Anti-Virus database records: 386240
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
F:\
H:\
Y:\
Z:\
Scan Statistics:
Total number of scanned objects: 137868
Number of viruses found: 9
Number of infected objects: 39
Number of suspicious objects: 0
Duration of the scan process: 01:31:09
Infected Object Name / Virus Name / Last Action
C:\iwctrllog.txt Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
H:\Documents and Settings\All Users\Application Data\AVG7\Log\emc.log Object is locked skipped
H:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
H:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
H:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
H:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
H:\Documents and Settings\Bud\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SUPERANTISPYWARE.LOG Object is locked skipped
H:\Documents and Settings\Bud\Cookies\index.dat Object is locked skipped
H:\Documents and Settings\Bud\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
H:\Documents and Settings\Bud\Desktop\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
H:\Documents and Settings\Bud\Desktop\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
H:\Documents and Settings\Bud\Desktop\SmitfraudFix.exe RarSFX: infected - 2 skipped
H:\Documents and Settings\Bud\Desktop\Torpark 2.0.0.3a\App\Tconfig.exe/data0004 Infected: not-a-virus:RiskTool.Win32.FWDisabler.a skipped
H:\Documents and Settings\Bud\Desktop\Torpark 2.0.0.3a\App\Tconfig.exe NSIS: infected - 1 skipped
H:\Documents and Settings\Bud\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
H:\Documents and Settings\Bud\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
H:\Documents and Settings\Bud\Local Settings\Application Data\Mozilla\Firefox\Profiles\oc0vko1u.default\Cache\63329BDCd01/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
H:\Documents and Settings\Bud\Local Settings\Application Data\Mozilla\Firefox\Profiles\oc0vko1u.default\Cache\63329BDCd01/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
H:\Documents and Settings\Bud\Local Settings\Application Data\Mozilla\Firefox\Profiles\oc0vko1u.default\Cache\63329BDCd01 RarSFX: infected - 2 skipped
H:\Documents and Settings\Bud\Local Settings\History\History.IE5\index.dat Object is locked skipped
H:\Documents and Settings\Bud\Local Settings\History\History.IE5\MSHist012007082020070821\index.dat Object is locked skipped
H:\Documents and Settings\Bud\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
H:\Documents and Settings\Bud\ntuser.dat Object is locked skipped
H:\Documents and Settings\Bud\NTUSER.DAT.LOG Object is locked skipped
H:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
H:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
H:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
H:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
H:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
H:\Documents and Settings\LocalService\ntuser.dat Object is locked skipped
H:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
H:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
H:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
H:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
H:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
H:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
H:\Documents and Settings\NetworkService\ntuser.dat Object is locked skipped
H:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
H:\RECYCLER\NPROTECT�166917.DBX/[From from <pw-conf@ebay.com> forward (org good) [db-null]][Date Sat, 08 Apr 2006 20:10:11 -0400]/UNNAMED/UNNAMED/html Infected: Trojan-Spy.HTML.Bayfraud.kl skipped
H:\RECYCLER\NPROTECT�166917.DBX/[From from <pw-conf@ebay.com> forward (org good) [db-null]][Date Sat, 08 Apr 2006 20:10:11 -0400]/UNNAMED/UNNAMED Infected: Trojan-Spy.HTML.Bayfraud.kl skipped
H:\RECYCLER\NPROTECT�166917.DBX/[From from <pw-conf@ebay.com> forward (org good) [db-null]][Date Sat, 08 Apr 2006 20:10:11 -0400]/UNNAMED Infected: Trojan-Spy.HTML.Bayfraud.kl skipped
H:\RECYCLER\NPROTECT�166917.DBX Mail MS Outlook 5: infected - 3 skipped
H:\SDFix\backups\HOSTS Infected: Trojan.Win32.Qhost.my skipped
H:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
H:\System Volume Information\_restore{36ADF857-E310-417A-A961-A48F78699DE5}\RP177\A0062002.ini Infected: Trojan-Downloader.Win32.Agent.bxx skipped
H:\System Volume Information\_restore{36ADF857-E310-417A-A961-A48F78699DE5}\RP178\A0062051.exe/stream/data0006 Infected: Trojan-Downloader.Win32.Zlob.bzl skipped
H:\System Volume Information\_restore{36ADF857-E310-417A-A961-A48F78699DE5}\RP178\A0062051.exe/stream Infected: Trojan-Downloader.Win32.Zlob.bzl skipped
H:\System Volume Information\_restore{36ADF857-E310-417A-A961-A48F78699DE5}\RP178\A0062051.exe NSIS: infected - 2 skipped
H:\System Volume Information\_restore{36ADF857-E310-417A-A961-A48F78699DE5}\RP179\A0062296.ocx Infected: Trojan.Win32.Agent.ahq skipped
H:\System Volume Information\_restore{36ADF857-E310-417A-A961-A48F78699DE5}\RP179\A0062338.exe/stream/data0006 Infected: Trojan-Downloader.Win32.Zlob.bzl skipped
H:\System Volume Information\_restore{36ADF857-E310-417A-A961-A48F78699DE5}\RP179\A0062338.exe/stream Infected: Trojan-Downloader.Win32.Zlob.bzl skipped
H:\System Volume Information\_restore{36ADF857-E310-417A-A961-A48F78699DE5}\RP179\A0062338.exe NSIS: infected - 2 skipped
H:\System Volume Information\_restore{36ADF857-E310-417A-A961-A48F78699DE5}\RP182\A0062357.exe/stream/data0006 Infected: Trojan-Downloader.Win32.Zlob.bzl skipped
H:\System Volume Information\_restore{36ADF857-E310-417A-A961-A48F78699DE5}\RP182\A0062357.exe/stream Infected: Trojan-Downloader.Win32.Zlob.bzl skipped
H:\System Volume Information\_restore{36ADF857-E310-417A-A961-A48F78699DE5}\RP182\A0062357.exe NSIS: infected - 2 skipped
H:\System Volume Information\_restore{36ADF857-E310-417A-A961-A48F78699DE5}\RP182\A0062591.ini Infected: Trojan-Downloader.Win32.Agent.bxx skipped
H:\System Volume Information\_restore{36ADF857-E310-417A-A961-A48F78699DE5}\RP182\A0063646.dll Infected: not-a-virus:AdWare.Win32.Agent.bn skipped
H:\System Volume Information\_restore{36ADF857-E310-417A-A961-A48F78699DE5}\RP182\A0063647.dll Infected: not-a-virus:AdWare.Win32.Agent.bn skipped
H:\System Volume Information\_restore{36ADF857-E310-417A-A961-A48F78699DE5}\RP182\A0063669.exe/stream/data0006 Infected: Trojan-Downloader.Win32.Zlob.bzl skipped
H:\System Volume Information\_restore{36ADF857-E310-417A-A961-A48F78699DE5}\RP182\A0063669.exe/stream Infected: Trojan-Downloader.Win32.Zlob.bzl skipped
H:\System Volume Information\_restore{36ADF857-E310-417A-A961-A48F78699DE5}\RP182\A0063669.exe NSIS: infected - 2 skipped
H:\System Volume Information\_restore{36ADF857-E310-417A-A961-A48F78699DE5}\RP191\A0073229.ini Infected: Trojan-Downloader.Win32.Agent.bxx skipped
H:\System Volume Information\_restore{36ADF857-E310-417A-A961-A48F78699DE5}\RP191\A0073246.ini Infected: Trojan-Downloader.Win32.Agent.bxx skipped
H:\System Volume Information\_restore{36ADF857-E310-417A-A961-A48F78699DE5}\RP193\change.log Object is locked skipped
H:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
H:\WINDOWS\SchedLgU.Txt Object is locked skipped
H:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
H:\WINDOWS\Sti_Trace.log Object is locked skipped
H:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
H:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
H:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
H:\WINDOWS\system32\config\default Object is locked skipped
H:\WINDOWS\system32\config\DEFAULT.LOG Object is locked skipped
H:\WINDOWS\system32\config\SAM Object is locked skipped
H:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
H:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
H:\WINDOWS\system32\config\SECURITY Object is locked skipped
H:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
H:\WINDOWS\system32\config\software Object is locked skipped
H:\WINDOWS\system32\config\SOFTWARE.LOG Object is locked skipped
H:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
H:\WINDOWS\system32\config\system Object is locked skipped
H:\WINDOWS\system32\config\SYSTEM.LOG Object is locked skipped
H:\WINDOWS\system32\drivers\etc\hosts.20070816-173029.backup Infected: Trojan.Win32.Qhost.mg skipped
H:\WINDOWS\system32\drivers\etc\hosts.20070818-172541.backup Infected: Trojan.Win32.Qhost.mg skipped
H:\WINDOWS\system32\drivers\etc\hosts.20070818-172542.backup Infected: Trojan.Win32.Qhost.mg skipped
H:\WINDOWS\system32\h323log.txt Object is locked skipped
H:\WINDOWS\system32\hanonvt.ini Infected: Trojan-Downloader.Win32.Agent.bxx skipped
H:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
H:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
H:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
H:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
H:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
H:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
H:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
H:\WINDOWS\wiadebug.log Object is locked skipped
H:\WINDOWS\wiaservc.log Object is locked skipped
H:\WINDOWS\WindowsUpdate.log Object is locked skipped
Z:\SmitfraudFix.zip/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
Z:\SmitfraudFix.zip ZIP: infected - 1 skipped
Scan process completed.
This HijackThis log is from after everything else was done.
Logfile of HijackThis v1.99.1
Scan saved at 3:44:45 PM, on 8/20/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
H:\WINDOWS\System32\smss.exe
H:\WINDOWS\system32\winlogon.exe
H:\WINDOWS\system32\services.exe
H:\WINDOWS\system32\lsass.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\system32\spoolsv.exe
H:\WINDOWS\Explorer.EXE
H:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
H:\Program Files\Icons\SetIcon.exe
H:\WINDOWS\system32\RUNDLL32.EXE
H:\PROGRA~1\Grisoft\AVG7\avgcc.exe
H:\Program Files\QuickTime\qttask.exe
H:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIA.EXE
H:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
H:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE
H:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIA.EXE
H:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIA.EXE
H:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
H:\Program Files\Messenger\msmsgs.exe
H:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe
H:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
H:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
H:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
H:\Program Files\AntiVir PersonalEdition Classic\sched.exe
H:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
H:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
H:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
H:\PROGRA~1\Grisoft\AVG7\avgemc.exe
H:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
H:\WINDOWS\system32\nvsvc32.exe
H:\WINDOWS\System32\svchost.exe
H:\Documents and Settings\All Users\Application Data\U3\U3Launcher\LaunchU3.exe
H:\Program Files\Nikon\PictureProject\NkbMonitor.exe
H:\WINDOWS\System32\svchost.exe
H:\Program Files\Internet Explorer\iexplore.exe
H:\Program Files\HijackThis\HijackThis.exe
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - H:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - h:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SetIcon] H:\Program Files\Icons\SetIcon.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE H:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE H:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [PCLEPCI] H:\PROGRA~1\Pinnacle\PPE\PPE.EXE
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [AVG7_CC] H:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "H:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PinnacleDriverCheck] H:\WINDOWS\system32\\PSDrvCheck.exe
O4 - HKLM\..\Run: [\\BLACKDELL\EPSON Stylus Photo R220 Series] H:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIA.EXE /P42 "\\BLACKDELL\EPSON Stylus Photo R220 Series" /O6 "USB001" /M "Stylus Photo R220"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "H:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [\\EMS\EPSON Stylus Photo R200 Series cd] H:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE /P39 "\\EMS\EPSON Stylus Photo R200 Series cd" /O6 "USB002" /M "Stylus Photo R200"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "H:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Auto EPSON Stylus Photo R220 Series (Index) on EMS] H:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIA.EXE /P50 "Auto EPSON Stylus Photo R220 Series (Index) on EMS" /O19 "\\EMS\EPSON220Index" /M "Stylus Photo R220"
O4 - HKLM\..\Run: [Auto EPSON Stylus Photo R220 Series (CD Cover) on EMS] H:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIA.EXE /P53 "Auto EPSON Stylus Photo R220 Series (CD Cover) on EMS" /O16 "\\EMS\EPSON220CD" /M "Stylus Photo R220"
O4 - HKLM\..\Run: [avgnt] "H:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [MSMSGS] "H:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [\\BLACKDELL\EPSON Stylus Photo R200 Series] H:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE /P42 "\\BLACKDELL\EPSON Stylus Photo R200 Series" /M "Stylus Photo R200" /EF "HKCU"
O4 - HKCU\..\Run: [IW_Drop_Icon] H:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe /DropDisc
O4 - HKCU\..\Run: [swg] H:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] H:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Adobe Gamma Loader.lnk.disabled
O4 - Global Startup: ColorVisionStartup.lnk = H:\Program Files\PANTONE COLORVISION\Startup\ColorVisionStartup.exe
O4 - Global Startup: LaunchU3.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = H:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NkbMonitor.exe.lnk = H:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - H:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - H:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky.com/kos/eng/partner/d...can_unicode.cabO20 - AppInit_DLLs: H:\WINDOWS\system32\hanonvt.ini
O20 - Winlogon Notify: !SASWinLogon - H:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - H:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - H:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - H:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Unknown owner - H:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - H:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - H:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - H:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - H:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - H:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - H:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - H:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - H:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - H:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - H:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - H:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - H:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - H:\Program Files\Spyware Doctor\swdsvc.exe