Combofix log:Start Time= Tue 07/25/2006 17:45:17.89
Running from: C:\Documents and Settings\Rage\Desktop
(((((((((((((((((((((((((((((((((((((((((((((((( Ssk's Log )))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\repairs303169590.dll
C:\Documents and Settings\Rage\Application Data\Sskcwrd.dll
C:\Documents and Settings\Rage\Application Data\Sskdmns.dll
C:\Documents and Settings\Rage\Application Data\Sskknwrd.dll
C:\Documents and Settings\Rage\Application Data\Sskuknwrd.dll
C:\Documents and Settings\Rage\Local Settings\Temporary Internet Files\Ssk.log
C:\WINDOWS\Prefetch\SSK.EXE-02BBBF01.pf
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
17:50:44.26
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-07-24 09:41:10 ( .D... ) "C:\Program Files\TClock"
2006-07-24 07:14:28 ( .D... ) "C:\Documents and Settings\Rage\Application Data\SystemDoctor 2006 Free"
2006-07-24 07:06:58 0 ( A.... ) "C:\Documents and Settings\Rage\Application Data\internaldb41.dat"
2006-07-24 07:04:32 236818 ( A.... ) "C:\Program Files\Common Files\EliteMediaGroupOinUninstaller.exe"
2006-07-24 07:04:30 81920 ( A.... ) "C:\WINDOWS\system32\csrss.dll"
2006-07-24 07:04:22 129649 ( A.... ) "C:\WINDOWS\elpp100drop.exe"
2006-07-24 07:04:22 30208 ( A.... ) "C:\WINDOWS\ss1205.exe"
2006-07-24 07:04:20 32768 ( A.... ) "C:\WINDOWS\unstall.exe"
2006-07-24 07:04:20 ( .D... ) "C:\Program Files\eaci"
2006-07-24 07:04:12 359634 ( A.... ) "C:\WINDOWS\media_motor_bundle.exe"
2006-07-24 07:04:06 226536 ( A.... ) "C:\WINDOWS\whCC-GIANT.exe"
2006-07-24 07:03:50 208896 ( A.... ) "C:\WINDOWS\system32\v199.dll"
2006-07-24 07:03:50 28672 ( A.... ) "C:\WINDOWS\system32\hvzead7v.exe"
2006-07-24 07:03:48 380928 ( A.... ) "C:\WINDOWS\system32\WinNB58.dll"
2006-07-24 07:03:42 102400 ( A.... ) "C:\WINDOWS\mirar.exe"
2006-07-24 07:03:34 8491 ( A.... ) "C:\WINDOWS\thiselt.exe"
2006-07-24 06:59:30 ( .D... ) "C:\Program Files\Common Files\{F82E3AF6-0960-1033-0920-020202070001}"
2006-07-04 12:38:16 98304 ( A.... ) "C:\WINDOWS\W2BNEUnin.exe"
2006-06-21 17:38:40 235228 ( A.... ) "C:\WINDOWS\system32\icon_mediamotor.exe"
2006-06-21 17:38:16 115239 ( A.... ) "C:\WINDOWS\system32\ts_mediamotor.exe"
2006-05-31 20:09:08 ( .D... ) "C:\Program Files\SereneScreen"
2006-05-25 01:22:06 53248 ( A.... ) "C:\WINDOWS\bdoscandel.exe"
2006-05-14 19:25:48 286720 ( ..... ) "C:\WINDOWS\Setup1.exe"
2006-05-07 13:26:58 154112 ( A.... ) "C:\WINDOWS\system32\dxr.dll"
2006-05-07 13:26:38 83456 ( A.... ) "C:\WINDOWS\system32\dsmux.exe"
2006-05-07 13:24:54 99840 ( A.... ) "C:\WINDOWS\system32\mkx.dll"
2006-05-07 13:24:42 51200 ( A.... ) "C:\WINDOWS\system32\avi.dll"
2006-05-07 13:24:30 61440 ( A.... ) "C:\WINDOWS\system32\mmfinfo.dll"
2006-05-07 13:24:16 65536 ( A.... ) "C:\WINDOWS\system32\mp4.dll"
2006-05-07 13:24:04 57856 ( A.... ) "C:\WINDOWS\system32\ogm.dll"
2006-05-07 13:23:46 45568 ( A.... ) "C:\WINDOWS\system32\mkzlib.dll"
2006-05-07 13:23:42 23552 ( A.... ) "C:\WINDOWS\system32\mkunicode.dll"
(((((((((((((((((((((((((((((((((((((( Files Created - Last 30days )))))))))))))))))))))))))))))))))))))))))))
2006-07-24 21:53 1,072,549,888 C:\hiberfil.sys
2006-07-24 07:04 89,088 C:\WINDOWS\system32\atl71.dll
2006-07-24 07:04 81,920 C:\WINDOWS\system32\csrss.dll
2006-07-24 07:04 499,712 C:\WINDOWS\system32\msvcp71.dll
2006-07-24 07:04 30,208 C:\WINDOWS\ss1205.exe
2006-07-24 07:04 129,649 C:\WINDOWS\elpp100drop.exe
2006-07-24 07:04 1,060,864 C:\WINDOWS\system32\mfc71.dll
2006-07-24 07:03 8,491 C:\WINDOWS\thiselt.exe
2006-07-24 07:03 380,928 C:\WINDOWS\system32\WinNB58.dll
2006-07-24 07:03 359,634 C:\WINDOWS\media_motor_bundle.exe
2006-07-24 07:03 32,768 C:\WINDOWS\unstall.exe
2006-07-24 07:03 28,672 C:\WINDOWS\system32\hvzead7v.exe
2006-07-24 07:03 226,536 C:\WINDOWS\whCC-GIANT.exe
2006-07-24 07:03 208,896 C:\WINDOWS\system32\v199.dll
2006-07-24 07:03 102,400 C:\WINDOWS\mirar.exe
2006-07-04 12:38 98,304 C:\WINDOWS\W2BNEUnin.exe
2006-06-21 17:38 235,228 C:\WINDOWS\system32\icon_mediamotor.exe
2006-06-21 17:38 115,239 C:\WINDOWS\system32\ts_mediamotor.exe
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"IMONTRAY"="C:\\Program Files\\Intel\\Intel® Active Monitor\\imontray.exe"
"ShStatEXE"="\"C:\\Program Files\\Network Associates\\VirusScan\\SHSTAT.EXE\" /STANDALONE"
"McAfeeUpdaterUI"="\"C:\\Program Files\\Network Associates\\Common Framework\\UpdaterUI.exe\" /StartedFromRunKey"
"Google Desktop Search"="\"C:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe\" /startup"
"ATICCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe\" runtime -Delay"
@=""
"Launch LGDCore"="\"C:\\Program Files\\Logitech\\G-series Software\\LGDCore.exe\" /SHOWHIDE"
"Launch LCDMon"="\"C:\\Program Files\\Logitech\\G-series Software\\LCDMon.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"SystemDoctor 2006 Free"="C:\\Program Files\\SystemDoctor 2006 Free\\sd2006.exe -scan"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"TClock.exe"="C:\\Program Files\\TClock\\tclock_install.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]
"dj8BT0wp"="\"C:\\WINDOWS\\system32\\hvzead7v.exe\" -Yli9"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonceex]
"flags"=dword:00000008
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonceex\000]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]
"{F82E3AF6-0960-1033-0920-020202070001}"="\"C:\\Program Files\\Common Files\\{F82E3AF6-0960-1033-0920-020202070001}\\Update.exe\" mc-110-12-0000103"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,96,00,00,00,00,00,00,00,6a,04,00,00,c4,03,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,c4,02,\
00,00,04,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,c4,02,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Color Calibration.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Color Calibration.lnk"
"backup"="C:\\WINDOWS\\pss\\Color Calibration.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\SEC\\MAGICT~1.6_C\\GAMMAT~1.EXE "
"item"="Color Calibration"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^MagicTune3.6.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\MagicTune3.6.lnk"
"backup"="C:\\WINDOWS\\pss\\MagicTune3.6.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\SEC\\MAGICT~1.6_C\\MAGICT~2.EXE "
"item"="MagicTune3.6"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Pinnacle Scheduler.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Pinnacle Scheduler.lnk"
"backup"="C:\\WINDOWS\\pss\\Pinnacle Scheduler.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Pinnacle\\SHARED~1\\Programs\\SCHEDU~1\\PCLESC~1.EXE "
"item"="Pinnacle Scheduler"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AceGain LiveUpdate]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="LiveUpdate"
"hkey"="HKLM"
"command"="C:\\Program Files\\Otsego\\LiveUpdate.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="aim"
"hkey"="HKCU"
"command"="C:\\PROGRA~1\\AIM\\aim.exe -cnetwait.odl"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CXMon]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Hpi_Monitor"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Hewlett-Packard\\PhotoSmart\\Photo Imaging\\Hpi_Monitor.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="daemon"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\D-Tools\\daemon.exe\" -lang 1033 -noicon"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Jet Detection]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ADGJDet"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Creative\\SBLive\\PROGRAM\\ADGJDet.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msmsgs"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msnmsgr"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Norton Ghost 9.0]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="GhostTray"
"hkey"="HKLM"
"command"="C:\\Program Files\\Symantec\\Norton Ghost\\Agent\\GhostTray.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NvCpl"
"hkey"="HKLM"
"command"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NvMcTray"
"hkey"="HKLM"
"command"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="nwiz"
"hkey"="HKLM"
"command"="nwiz.exe /install"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PDVDServ"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Share-to-Web Namespace Daemon]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="hpgs2wnd"
"hkey"="HKLM"
"command"="C:\\Program Files\\Hewlett-Packard\\PhotoSmart\\HP Share-to-Web\\hpgs2wnd.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="jusched"
"hkey"="HKLM"
"command"="C:\\Program Files\\Java\\jre1.5.0_01\\bin\\jusched.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="evntsvc"
"hkey"="HKLM"
"command"="C:\\Program Files\\Common Files\\Real\\Update_OB\\evntsvc.exe -osboot"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPP Auto Loader]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="TPPALDR"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\TPPALDR.EXE"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="UpdReg"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\UpdReg.EXE"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WINDVDPatch]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="CTHELPER"
"hkey"="HKLM"
"command"="CTHELPER.EXE"
"inimapping"="0"
Contents of the 'Scheduled Tasks' folder
Completion time: Tue 07/25/2006 17:50:55.25
ComboFix ver 06.07.15 - This logfile is located at C:\ComboFix.txt
Ewido Report:---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 7:10:42 PM 7/25/2006
+ Scan result:
G:\Backup\My Documents\ZangoMessenger.exe -> Adware.180Solutions : Cleaned with backup (quarantined).
G:\Backup\Programs\ZangoMessenger.exe -> Adware.180Solutions : Cleaned with backup (quarantined).
C:\WINDOWS\system32\nseF5.dll -> Adware.Ezula : Cleaned with backup (quarantined).
C:\QUARANTINE\mmxsnet.exe.Vir -> Adware.MediaMotor : Cleaned with backup (quarantined).
C:\QUARANTINE\mmxsnet[1].exe.Vir -> Adware.MediaMotor : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\amm06.ocx -> Adware.MediaMotor : Cleaned with backup (quarantined).
C:\WINDOWS\unstall.exe -> Adware.MediaMotor : Cleaned with backup (quarantined).
C:\WINDOWS\system32\WinNB58.dll -> Adware.Mirar : Cleaned with backup (quarantined).
C:\WINDOWS\mirar.exe -> Adware.NetNucleus : Cleaned with backup (quarantined).
C:\WINDOWS\system32\csrss.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Clickspring -> Adware.PurityScan : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\SystemDoctor 2006 Free -> Adware.SystemDoctor2006 : Cleaned with backup (quarantined).
C:\WINDOWS\webhdll.dll_tobedeleted -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\WINDOWS\whCC-GIANT.exe/WhAgent.exe -> Adware.WebHancer : Error during cleaning.
C:\WINDOWS\Downloaded Program Files\3138302D2D2D.exe -> Downloader.Adload.ai : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\3138302D2D2D.exe -> Downloader.Adload.ai : Cleaned with backup (quarantined).
C:\WINDOWS\ss1205.exe -> Dropper.Small.qn : Cleaned with backup (quarantined).
E:\Greg\Hacker\hacker\SC-KeyLog2.exe -> Logger.SCKeyLog.20 : Cleaned with backup (quarantined).
E:\Programs\Prank_progz\pranks\fakefmt.zip/fakefmt.exe -> Not-A-Virus.BadJoke.Win32.FakeFormat.105 : Error during cleaning.
E:\Programs\AIM_files\AIM Files.rar/AIM Files\Other Aim Progs\Buddy Kill 2.4\BuddyKill.zip/Buddy Kill/BuddyKill.exe -> Not-A-Virus.DoS.Win32.BKill.b : Error during cleaning.
C:\WINDOWS\Downloaded Program Files\USDR6_0001_D08M0404NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\USDR6_0001_D17M1107NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Cleaned with backup (quarantined).
E:\Greg\Hacker\old_stuff_11_7_03\aenima.zip/testserv.exe -> Not-A-Virus.EmailFlooder.Win32.Aenima.20 : Error during cleaning.
E:\Greg\Hacker\hacker\Utilities\X-Scan-v2.3-en.zip/dat/cgi.lst -> Not-A-Virus.Exploit.IIS.WebDir : Error during cleaning.
E:\Programs\AIM_files\AIM Files.rar/AIM Files\Other Aim Progs\Aim Amp\AimAmp.zip/AimAmp/aimamp.exe -> Not-A-Virus.Flooder.Win32.VB.aq : Error during cleaning.
E:\Programs\AIM_files\tools\AimAmp.zip/AimAmp/aimamp.exe -> Not-A-Virus.Flooder.Win32.VB.aq : Error during cleaning.
E:\Programs\AIM_files\AIM Files.rar/AIM Files\Other Aim Progs\Chat Spam\chatspam.zip/chatspam/chatspam.exe -> Not-A-Virus.Flooder.Win32.VB.au : Error during cleaning.
E:\Greg\Hacker\hacker\Utilities\X-Scan-v2.3-en.zip/Xscan.exe -> Not-A-Virus.HackTool.Win32.XScan.23 : Error during cleaning.
E:\Greg\Hacker\hacker\Utilities\X-Scan-v2.3-en.zip/xscan_gui.exe -> Not-A-Virus.HackTool.Win32.XScan.23 : Error during cleaning.
E:\Greg\Hacker\hacker\X-Scan\Xscan.exe -> Not-A-Virus.HackTool.Win32.XScan.23 : Cleaned with backup (quarantined).
E:\Greg\Hacker\hacker\X-Scan\xscan_gui.exe -> Not-A-Virus.HackTool.Win32.XScan.23 : Cleaned with backup (quarantined).
E:\Programs\AIM_files\AIM Files.rar/AIM Files\Other Aim Progs\Evil Intentions 2\EvilIntentions2.zip/aimocx.ocx -> Not-A-Virus.IMFlooder.Win32.QuietStorm : Error during cleaning.
E:\Programs\AIM_files\tools\EvilIntentions2.zip/aimocx.ocx -> Not-A-Virus.IMFlooder.Win32.QuietStorm : Error during cleaning.
E:\Greg\Hacker\old_stuff_11_7_03\watchkeystrokes.zip/Vprotkkd._vx -> Not-A-Virus.Monitor.Win32.KeyKey.121 : Error during cleaning.
E:\Greg\Hacker\old_stuff_11_7_03\watchkeystrokes.zip/slman._ex -> Not-A-Virus.Monitor.Win32.KeyKey.121 : Error during cleaning.
E:\Greg\Hacker\old_stuff_11_7_03\watchkeystrokes.zip/Vkeykeyd._vx -> Not-A-Virus.Monitor.Win32.KeyKey.122 : Error during cleaning.
E:\Greg\Hacker\old_stuff_11_7_03\watchkeystrokes.zip/kkmon._ex -> Not-A-Virus.Monitor.Win32.KeyKey.122 : Error during cleaning.
E:\Greg\Hacker\old_stuff_11_7_03\wgatescan-22.zip/wGateScan-2_2.exe -> Not-A-Virus.NetTool.Win32.WinGateScan.22 : Error during cleaning.
E:\Programs\VNC\vncviewer\vncviewer.exe -> Not-A-Virus.RemoteAdmin.Win32.WinVNC.333 : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\rage@247realmedia[1].txt -> TrackingCookie.247realmedia : Cleaned with backup (quarantined).
:mozilla.6:C:\Documents and Settings\Rage\Application Data\Mozilla\Profiles\default\of2h70wj.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.7:C:\Documents and Settings\Rage\Application Data\Mozilla\Profiles\default\of2h70wj.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\rage@2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\rage@adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][1].txt -> TrackingCookie.Addynamix : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][1].txt -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\rage@adrevolver[2].txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][1].txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][1].txt -> TrackingCookie.Adserver : Cleaned with backup (quarantined).
:mozilla.15:C:\Documents and Settings\Rage\Application Data\Mozilla\Firefox\Profiles\9zazwsaa.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.17:C:\Documents and Settings\Rage\Application Data\Mozilla\Firefox\Profiles\9zazwsaa.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.18:C:\Documents and Settings\Rage\Application Data\Mozilla\Firefox\Profiles\9zazwsaa.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.21:C:\Documents and Settings\Rage\Application Data\Mozilla\Firefox\Profiles\9zazwsaa.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.24:C:\Documents and Settings\Rage\Application Data\Mozilla\Firefox\Profiles\9zazwsaa.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\rage@bluestreak[2].txt -> TrackingCookie.Bluestreak : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][2].txt -> TrackingCookie.Bridgetrack : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][1].txt -> TrackingCookie.Burstbeacon : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\rage@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.39:C:\Documents and Settings\Rage\Application Data\Mozilla\Firefox\Profiles\9zazwsaa.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.40:C:\Documents and Settings\Rage\Application Data\Mozilla\Firefox\Profiles\9zazwsaa.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.41:C:\Documents and Settings\Rage\Application Data\Mozilla\Firefox\Profiles\9zazwsaa.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.42:C:\Documents and Settings\Rage\Application Data\Mozilla\Firefox\Profiles\9zazwsaa.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\rage@com[1].txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\rage@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined).
:mozilla.16:C:\Documents and Settings\Rage\Application Data\Mozilla\Firefox\Profiles\9zazwsaa.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][1].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][1].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][1].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][1].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][1].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][2].txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.56:C:\Documents and Settings\Rage\Application Data\Mozilla\Firefox\Profiles\9zazwsaa.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.57:C:\Documents and Settings\Rage\Application Data\Mozilla\Firefox\Profiles\9zazwsaa.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\rage@findwhat[1].txt -> TrackingCookie.Findwhat : Cleaned with backup (quarantined).
:mozilla.69:C:\Documents and Settings\Rage\Application Data\Mozilla\Firefox\Profiles\9zazwsaa.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.71:C:\Documents and Settings\Rage\Application Data\Mozilla\Firefox\Profiles\9zazwsaa.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\rage@kmpads[2].txt -> TrackingCookie.Kmpads : Cleaned with backup (quarantined).
:mozilla.58:C:\Documents and Settings\Rage\Application Data\Mozilla\Firefox\Profiles\9zazwsaa.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][1].txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][2].txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\rage@overture[2].txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][1].txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][1].txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\rage@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][1].txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\rage@revenue[1].txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][2].txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\rage@serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][2].txt -> TrackingCookie.Specificclick : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][1].txt -> TrackingCookie.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][1].txt -> TrackingCookie.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\rage@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][1].txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][1].txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\rage@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][2].txt -> TrackingCookie.Tracking101 : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\rage@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined).
:mozilla.30:C:\Documents and Settings\Rage\Application Data\Mozilla\Firefox\Profiles\9zazwsaa.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.31:C:\Documents and Settings\Rage\Application Data\Mozilla\Firefox\Profiles\9zazwsaa.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.32:C:\Documents and Settings\Rage\Application Data\Mozilla\Firefox\Profiles\9zazwsaa.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.33:C:\Documents and Settings\Rage\Application Data\Mozilla\Firefox\Profiles\9zazwsaa.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.34:C:\Documents and Settings\Rage\Application Data\Mozilla\Firefox\Profiles\9zazwsaa.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.35:C:\Documents and Settings\Rage\Application Data\Mozilla\Firefox\Profiles\9zazwsaa.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.36:C:\Documents and Settings\Rage\Application Data\Mozilla\Firefox\Profiles\9zazwsaa.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.37:C:\Documents and Settings\Rage\Application Data\Mozilla\Firefox\Profiles\9zazwsaa.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\rage@trafficmp[1].txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.54:C:\Documents and Settings\Rage\Application Data\Mozilla\Firefox\Profiles\9zazwsaa.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.55:C:\Documents and Settings\Rage\Application Data\Mozilla\Firefox\Profiles\9zazwsaa.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][2].txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\rage@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][2].txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined).
:mozilla.38:C:\Documents and Settings\Rage\Application Data\Mozilla\Firefox\Profiles\9zazwsaa.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.43:C:\Documents and Settings\Rage\Application Data\Mozilla\Firefox\Profiles\9zazwsaa.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.44:C:\Documents and Settings\Rage\Application Data\Mozilla\Firefox\Profiles\9zazwsaa.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.45:C:\Documents and Settings\Rage\Application Data\Mozilla\Firefox\Profiles\9zazwsaa.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.46:C:\Documents and Settings\Rage\Application Data\Mozilla\Firefox\Profiles\9zazwsaa.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.47:C:\Documents and Settings\Rage\Application Data\Mozilla\Firefox\Profiles\9zazwsaa.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\
[email protected][1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\rage@yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
C:\Documents and Settings\Rage\Cookies\rage@zedo[2].txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
E:\Greg\Text\websites\Dark Edge.zip/Dark Edge/CGI-Bin/NEW CGI SCRIPTS/gallery_maker_pro_1.5.zip/patch.exe -> Trojan.Proxcrak.A : Error during cleaning.
E:\Greg\Text\websites\Darkweb.zip/Darkweb/CGI-Bin/NEW CGI SCRIPTS/gallery_maker_pro_1.5.zip/patch.exe -> Trojan.Proxcrak.A : Error during cleaning.
::Report end
Hijack this log (after running thru everything):C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\GEARSec.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe
C:\Program Files\Intel\Intel® Active Monitor\imontray.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Logitech\G-series Software\LGDCore.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\Logitech\G-series Software\LCDMon.exe
C:\Program Files\Logitech\G-series Software\SDK\G15NetSpeed.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Intel® Active Monitor\imonnt.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Documents and Settings\Rage\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://finance.yahoo.com/O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [IMONTRAY] C:\Program Files\Intel\Intel® Active Monitor\imontray.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\G-series Software\LCDMon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - Global Startup: Greg_startup.bat
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar3.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar3.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar3.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar3.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar3.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{68D76D08-F776-468D-927B-4F04A45B2E73}: NameServer = 192.168.1.1
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
O23 - Service: Intel® Active Monitor (imonNT) - Intel Corp. - C:\Program Files\Intel\Intel® Active Monitor\imonnt.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe
Thanks for the help!!! :thumbsup: