Yes I did run everything I will get you the logs for each... sorry I missed that.
Thanks!
ComboFix:
ComboFix 08-04-15.1 - Scott 2008-04-15 18:07:24.1 - NTFSx86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1743 [GMT -5:00]
Running from: C:\Documents and Settings\Scott\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\AutoRun.inf
C:\WINDOWS\system32\jpaoqqrv.dll
C:\WINDOWS\system32\mWyGMnpo.ini
C:\WINDOWS\system32\mWyGMnpo.ini2
C:\WINDOWS\system32\opnMGyWm.dll
C:\WINDOWS\system32\wccxwshe.dll
C:\WINDOWS\system32\xrjehsuw.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
((((((((((((((((((((((((( Files Created from 2008-03-15 to 2008-04-15 )))))))))))))))))))))))))))))))
.
2008-04-15 16:15 . 2008-04-15 16:15 <DIR> d-------- C:\WINDOWS\ERUNT
2008-04-15 15:46 . 2008-04-15 16:37 <DIR> d-------- C:\SDFix
2008-04-15 15:33 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-04-15 15:33 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-04-15 15:33 . 2008-04-14 19:28 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-04-15 15:33 . 2008-04-12 13:49 82,432 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-04-15 15:33 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-04-15 15:33 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-04-15 15:33 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-04-15 15:33 . 2008-04-15 15:33 2,262 --a------ C:\WINDOWS\system32\tmp.reg
2008-04-15 13:09 . 2008-04-15 13:09 13,778 --a------ C:\Please download.docx
2008-04-15 12:38 . 2008-04-15 12:38 401,720 --a------ C:\HiJackThis.exe
2008-04-15 11:19 . 2008-04-15 11:19 921 --a------ C:\WINDOWS\QSFVExit.bat
2008-04-15 10:01 . 2008-04-15 10:01 127 --a------ C:\WINDOWS\system32\MRT.INI
2008-04-14 13:25 . 2008-04-14 13:25 3,648 --a------ C:\WINDOWS\system32\ayishxjg.dll
2008-04-13 13:23 . 2008-04-13 13:23 3,648 --a------ C:\WINDOWS\system32\nwytgoox.dll
2008-04-12 13:21 . 2008-04-15 18:02 101,119 --a------ C:\WINDOWS\BMbb516eeb.xml
2008-04-12 13:21 . 2008-04-12 13:21 3,648 --a------ C:\WINDOWS\system32\wnpdoujm.dll
2008-04-12 01:13 . 2008-04-12 23:49 <DIR> d-------- C:\Documents and Settings\Scott\Application Data\LimeWire
2008-04-05 18:03 . 2008-04-05 18:03 <DIR> d-------- C:\Program Files\ProVenture
2008-04-05 18:03 . 2008-04-05 18:03 <DIR> d-------- C:\Program Files\Common Files\MySoftware
2008-04-05 18:03 . 1995-03-03 00:00 348,160 --------- C:\WINDOWS\system32\MFC30.DLL
2008-04-05 18:03 . 1998-05-13 18:49 72,704 --a------ C:\WINDOWS\system32\odbctl32.dll
2008-04-05 18:03 . 2002-05-13 10:47 53,248 --------- C:\WINDOWS\system32\regdll.dll
2008-04-05 18:03 . 1999-07-01 22:55 46,517 --a------ C:\WINDOWS\system32\msorcl32.hlp
2008-04-05 18:03 . 1999-07-01 23:02 37,062 --a------ C:\WINDOWS\system32\odbcinst.hlp
2008-04-05 18:03 . 1999-07-01 22:55 1,731 --a------ C:\WINDOWS\system32\msorcl32.cnt
2008-04-05 18:03 . 1999-07-01 23:02 324 --a------ C:\WINDOWS\system32\odbcinst.cnt
2008-03-30 18:11 . 2008-03-30 18:15 <DIR> d-------- C:\FlexLM
2008-03-22 20:40 . 2008-04-12 23:47 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-03-22 20:40 . 2008-03-22 20:40 1,409 --a------ C:\WINDOWS\QTFont.for
2008-03-18 15:56 . 2008-03-18 15:56 <DIR> d-------- C:\Program Files\SolidWorks (2)
2008-03-18 07:38 . 2008-03-18 07:38 <DIR> d-------- C:\Program Files\SolidWorks08_3.1
2008-03-17 22:31 . 2008-03-18 07:39 <DIR> d-------- C:\Program Files\Common Files\Solidworks Data08
2008-03-17 22:29 . 2008-03-18 16:13 <DIR> d-------- C:\Program Files\Common Files\SolidWorks Installation Manager
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-15 17:06 --------- d-----w C:\Documents and Settings\Scott\Application Data\AVG7
2008-04-15 15:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-04-14 01:31 --------- d-----w C:\Program Files\dvdSanta
2008-04-13 04:49 --------- d-----w C:\Documents and Settings\Scott\Application Data\uTorrent
2008-04-12 06:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-04-12 06:13 --------- d-----w C:\Program Files\LimeWire
2008-04-11 03:34 --------- d-----w C:\Documents and Settings\Scott\Application Data\IM
2008-04-08 17:44 --------- d-----w C:\Documents and Settings\Scott\Application Data\SolidWorks
2008-04-05 23:04 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-05 23:03 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-18 21:01 --------- d-----w C:\Program Files\SolidWorks
2008-03-18 21:01 --------- d-----w C:\Program Files\Common Files\SolidWorks Shared
2008-03-18 21:01 --------- d-----w C:\Program Files\Common Files\eDrawings2008
2008-03-18 03:41 --------- d-----w C:\Program Files\SolidWorks08
2008-03-10 06:26 --------- d-----w C:\Documents and Settings\Scott\Application Data\U3
2008-03-10 00:45 --------- d-----w C:\Program Files\Palm
2008-03-09 00:29 --------- d-----w C:\Documents and Settings\Scott\Application Data\Arcsoft
2008-03-08 03:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\HotSync
2008-03-08 02:59 53,248 ----a-w C:\WINDOWS\PalmDevC.dll
2008-03-08 02:59 16,694 ----a-w C:\WINDOWS\system32\drivers\PalmUSBD.sys
2008-03-08 02:59 --------- d-----w C:\Documents and Settings\Scott\Application Data\HotSync
2008-02-29 05:01 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-02-24 05:25 --------- d-----w C:\Program Files\Common Files\AliasWavefront Shared
2008-02-24 05:15 --------- d--h--w C:\Program Files\Zero G Registry
2008-02-22 00:30 94,208 ----a-w C:\WINDOWS\DIIUnin.exe
2008-02-22 00:30 2,829 ----a-w C:\WINDOWS\DIIUnin.pif
2008-02-19 23:29 --------- d-----w C:\Program Files\Mindscape
2008-02-19 12:46 --------- d-----w C:\Program Files\QuickSFV
2008-02-19 06:55 --------- d-----w C:\Documents and Settings\Scott\Application Data\Bioshock
2008-02-16 02:43 --------- d-----w C:\Program Files\SystemRequirementsLab
2008-02-16 02:43 --------- d-----w C:\Documents and Settings\Scott\Application Data\SystemRequirementsLab
2008-02-11 21:25 56,912 ----a-w C:\Documents and Settings\Scott\g2mdlhlpx.exe
2007-09-11 11:59 22,328 ----a-w C:\Documents and Settings\Scott\Application Data\PnkBstrK.sys
2007-01-31 03:02 251 ----a-w C:\Program Files\wt3d.ini
2006-12-20 16:14 32 ----a-r C:\Documents and Settings\All Users\hash.dat
2005-10-30 10:18 56 --sh--r C:\WINDOWS\system32\E6072C46B3.sys
2005-10-30 10:18 3,350 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-04-25 08:50 139264]
"CTSysVol"="C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe" [2003-09-17 10:43 57344]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 01:00 90112]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-17 09:50 19968 C:\WINDOWS\LOGI_MWX.EXE]
"HPHmon05"="C:\WINDOWS\system32\hphmon05.exe" [2005-07-07 23:55 491520]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-08-24 15:46 7696384]
"nwiz"="nwiz.exe" [2006-08-24 15:46 1617920 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="NvMCTray.dll" [2006-08-24 15:46 86016 C:\WINDOWS\system32\nvmctray.dll]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-19 02:05 219136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2007-02-05 16:39 294400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\kHawTmLE]
kHawTmLE.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll 2007-02-07 18:31 226992 C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\WbSrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wbsys.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
--a------ 2004-07-27 16:50 221184 C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
--a------ 2007-01-19 12:54 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Macromedia\\Dreamweaver 4\\Dreamweaver.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"J:\\Games\\Quake 3\\quake3.exe"=
"J:\\Games\\Area 51\\A51.exe"=
"C:\\Games\\Sierra\\FEAR\\fpupdate.exe"=
"C:\\Games\\Sierra\\FEAR\\FEAR.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"=
"C:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=
"C:\\Games\\EA GAMES\\Need for Speed Most Wanted\\speed.exe"=
"C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"C:\\Program Files\\Macromedia\\Dreamweaver MX\\Dreamweaver.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"J:\\Program Files\\ITunes\\iTunes.exe"=
"J:\\Games\\Starcraft\\StarCraft.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Games\\Infogrames Interactive\\Civilization IV\\Civilization4.exe"=
"C:\\Games\\Infogrames Interactive\\Civilization IV\\Beyond the Sword\\Civ4BeyondSword.exe"=
"C:\\Games\\Infogrames Interactive\\Civilization IV\\Beyond the Sword\\Civ4BeyondSword_PitBoss.exe"=
R2 PDMWorks Workgroup Server;PDMWorks Workgroup Server;"C:\Program Files\SolidWorks (2)\PDMWorks Workgroup Server\Vault\pdmwService.exe" [2007-09-09 05:48]
S3 PsSdk30;PsSdk30;C:\WINDOWS\system32\Drivers\PsSdk30.drv []
S4 aliasdocserver;Alias Documentation Server;"K:\Program Files\Alias\Maya6.0\docs\Wrapper.exe" -s "K:\Program Files\Alias\Maya6.0\docs/Wrapper.conf" []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - G:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f2f9e6e3-c712-11dc-9041-00123f756013}]
\Shell\AutoRun\command - G:\LaunchU3.exe
.
Contents of the 'Scheduled Tasks' folder
"2007-10-25 03:38:31 C:\WINDOWS\Tasks\dfrg.job"
- C:\WINDOWS\system32\dfrg.msc
"2007-10-27 04:12:00 C:\WINDOWS\Tasks\HP Usg Daily.job"
- C:\Program Files\Hewlett-Packard\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\pexpress\hphped05.exe
"2007-10-26 22:00:00 C:\WINDOWS\Tasks\RegCure Program Check.job"
- C:\Program Files\RegCure\RegCure.exe
"2007-10-25 12:09:03 C:\WINDOWS\Tasks\RegCure.job"
- C:\Program Files\RegCure\RegCure.exe
"2007-02-17 07:01:50 C:\WINDOWS\Tasks\Uniblue SpyEraser.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-04-15 18:14:31
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PSSdk21]
"ImagePath"="\??\C:\WINDOWS\system32\Drivers\HNPsSdk.drv"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PsSdk30]
"ImagePath"="\??\C:\WINDOWS\system32\Drivers\PsSdk30.drv"
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\CTSVCCDA.EXE
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Logitech\MouseWare\system\EM_EXEC.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\MRT.exe
.
**************************************************************************
.
Completion time: 2008-04-15 18:21:09 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-15 23:21:06
Pre-Run: 38,128,197,632 bytes free
Post-Run: 38,000,594,944 bytes free
.
2008-04-15 15:05:40 --- E O F ---
Hack This:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:37:03 PM, on 4/15/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\SolidWorks (2)\PDMWorks Workgroup Server\Vault\pdmwService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\hphmon05.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\WINDOWS\system32\MRT.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\explorer.exe
C:\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_framework.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\Hewlett-Packard\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\Hewlett-Packard\Smart Web
Thanks,
Scott Baugh, CSWP