Ok here is my two scans. I had a 111 objects infected and cleaned, so we will see what this does.
EWIDO SCAN LOG[/u]
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 12:45:00 PM, 4/1/2006
+ Report-Checksum: 578601F7
+ Scan result:
HKLM\SOFTWARE\Classes\PROTOCOLS\Name-Space Handler\res -> Adware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Adware.WebRebates : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\AMeOpt -> Adware.InternetOptimizer : Cleaned with backup
HKLM\SOFTWARE\SearchRelevancy -> Adware.SearchRelevancy : Cleaned with backup
HKLM\SOFTWARE\SearchRelevancy\Update -> Adware.SearchRelevancy : Cleaned with backup
[1332] C:\WINDOWS\system32\taskdir.dll -> Proxy.Lager.aq : Error during cleaning
[340] C:\WINDOWS\system32\taskdir.dll -> Proxy.Lager.aq : Error during cleaning
[1020] C:\WINDOWS\system32\taskdir.dll -> Proxy.Lager.aq : Error during cleaning
[2128] C:\WINDOWS\system32\taskdir.dll -> Proxy.Lager.aq : Error during cleaning
[3960] C:\WINDOWS\system32\taskdir.dll -> Proxy.Lager.aq : Error during cleaning
:mozilla.14:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Firefox\Profiles\iq836tru.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Firefox\Profiles\iq836tru.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Firefox\Profiles\iq836tru.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Firefox\Profiles\iq836tru.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Firefox\Profiles\iq836tru.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Firefox\Profiles\iq836tru.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Firefox\Profiles\iq836tru.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Firefox\Profiles\iq836tru.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Firefox\Profiles\iq836tru.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Firefox\Profiles\iq836tru.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Firefox\Profiles\iq836tru.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Firefox\Profiles\iq836tru.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Firefox\Profiles\iq836tru.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Firefox\Profiles\iq836tru.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Firefox\Profiles\iq836tru.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.45:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Firefox\Profiles\iq836tru.default\cookies.txt -> TrackingCookie.Centrport : Cleaned with backup
:mozilla.46:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Firefox\Profiles\iq836tru.default\cookies.txt -> TrackingCookie.Centrport : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Firefox\Profiles\iq836tru.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Firefox\Profiles\iq836tru.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.51:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Firefox\Profiles\iq836tru.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.53:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Firefox\Profiles\iq836tru.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Firefox\Profiles\iq836tru.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Firefox\Profiles\iq836tru.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Firefox\Profiles\iq836tru.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Firefox\Profiles\iq836tru.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Firefox\Profiles\iq836tru.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Firefox\Profiles\iq836tru.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Firefox\Profiles\iq836tru.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.71:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Firefox\Profiles\iq836tru.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Firefox\Profiles\iq836tru.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.73:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Firefox\Profiles\iq836tru.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.74:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Firefox\Profiles\iq836tru.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.76:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Firefox\Profiles\iq836tru.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.11:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Profiles\default\1ju5e06w.slt\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.12:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Profiles\default\1ju5e06w.slt\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Profiles\default\1ju5e06w.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Profiles\default\1ju5e06w.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Profiles\default\1ju5e06w.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Profiles\default\1ju5e06w.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Profiles\default\1ju5e06w.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Profiles\default\1ju5e06w.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Profiles\default\1ju5e06w.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Profiles\default\1ju5e06w.slt\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Profiles\default\1ju5e06w.slt\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Profiles\default\1ju5e06w.slt\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Profiles\default\1ju5e06w.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Profiles\default\1ju5e06w.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Profiles\default\1ju5e06w.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Profiles\default\1ju5e06w.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Profiles\default\1ju5e06w.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.38:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Profiles\default\1ju5e06w.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.39:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Profiles\default\1ju5e06w.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Profiles\default\1ju5e06w.slt\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.41:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Profiles\default\1ju5e06w.slt\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.42:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Profiles\default\1ju5e06w.slt\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Profiles\default\1ju5e06w.slt\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.46:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Profiles\default\1ju5e06w.slt\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Profiles\default\1ju5e06w.slt\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Profiles\default\1ju5e06w.slt\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Profiles\default\1ju5e06w.slt\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Profiles\default\1ju5e06w.slt\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.51:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Profiles\default\1ju5e06w.slt\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Profiles\default\1ju5e06w.slt\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.53:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Profiles\default\1ju5e06w.slt\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.54:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Profiles\default\1ju5e06w.slt\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.57:C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Profiles\default\1ju5e06w.slt\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Travis Greenwood\Cookies\travis greenwood@2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Travis Greenwood\Cookies\travis
[email protected][1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Travis Greenwood\Cookies\travis greenwood@advertising[1].txt -> TrackingCookie.Advertising : Cleaned with backup
C:\Documents and Settings\Travis Greenwood\Cookies\travis greenwood@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Travis Greenwood\Cookies\travis greenwood@burstnet[3].txt -> TrackingCookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Travis Greenwood\Cookies\travis greenwood@cliks[2].txt -> TrackingCookie.Cliks : Cleaned with backup
C:\Documents and Settings\Travis Greenwood\Cookies\travis greenwood@cliks[4].txt -> TrackingCookie.Cliks : Cleaned with backup
C:\Documents and Settings\Travis Greenwood\Cookies\travis greenwood@com[1].txt -> TrackingCookie.Com : Cleaned with backup
C:\Documents and Settings\Travis Greenwood\Cookies\travis
[email protected][1].txt -> TrackingCookie.Sextracker : Cleaned with backup
C:\Documents and Settings\Travis Greenwood\Cookies\travis
[email protected][2].txt -> TrackingCookie.Sexcounter : Cleaned with backup
C:\Documents and Settings\Travis Greenwood\Cookies\travis greenwood@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Travis Greenwood\Cookies\travis
[email protected][2].txt -> TrackingCookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Travis Greenwood\Cookies\travis greenwood@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Travis Greenwood\Cookies\travis
[email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Travis Greenwood\Cookies\travis greenwood@sextracker[1].txt -> TrackingCookie.Sextracker : Cleaned with backup
C:\Documents and Settings\Travis Greenwood\Cookies\travis greenwood@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Cleaned with backup
C:\Documents and Settings\Travis Greenwood\Cookies\travis
[email protected][1].txt -> TrackingCookie.Burstbeacon : Cleaned with backup
C:\Documents and Settings\Travis Greenwood\Local Settings\Temp\Cookies\travis greenwood@abetterinternet[2].txt -> TrackingCookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Travis Greenwood\Local Settings\Temp\Cookies\travis
[email protected][2].txt -> TrackingCookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Travis Greenwood\Local Settings\Temp\Cookies\travis greenwood@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Travis Greenwood\Local Settings\Temp\Cookies\travis greenwood@cliks[2].txt -> TrackingCookie.Cliks : Cleaned with backup
C:\Documents and Settings\Travis Greenwood\Local Settings\Temp\Cookies\travis
[email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Travis Greenwood\Local Settings\Temp\Cookies\travis
[email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Travis Greenwood\Local Settings\Temp\Cookies\travis
[email protected][1].txt -> TrackingCookie.Adjuggler : Cleaned with backup
C:\Documents and Settings\Travis Greenwood\Local Settings\Temp\Cookies\travis
[email protected][1].txt -> TrackingCookie.Burstbeacon : Cleaned with backup
C:\Program Files\AdStatus Service -> Adware.WinTaskAd : Cleaned with backup
C:\Program Files\SearchRelevant\SearchRelevant.dll -> Adware.Relevance : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP546\A0040683.exe -> Not-A-Virus.Downloader.Win32.DigStream.a : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\QDow_AS2.dll -> Downloader.QDown.p : Cleaned with backup
C:\WINDOWS\SYSTEM32\MB.dll -> Dropper.Small.so : Cleaned with backup
C:\WINDOWS\SYSTEM32\pajxuorq.mhw -> Trojan.Agent.qe : Cleaned with backup
C:\WINDOWS\SYSTEM32\parad.raw.exe -> Proxy.Lager.at : Cleaned with backup
C:\WINDOWS\SYSTEM32\taskdir.exe -> Proxy.Lager.at : Cleaned with backup
C:\WINDOWS\SYSTEM32\voblaizdupla.exe -> Downloader.Small.ciw : Cleaned with backup
C:\WINDOWS\SYSTEM32\__delete_on_reboot__taskdir.dll -> Proxy.Lager.aq : Cleaned with backup
::Report End
HIJACK THIS LOG[u]
Logfile of HijackThis v1.99.1
Scan saved at 12:48:15 PM, on 4/1/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\vsnpstd.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Windows Media Connect 2\WMCCFG.exe
C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
C:\Program Files\Common Files\AOL\1128570150\ee\AOLHostManager.exe
C:\Program Files\Common Files\AOL\1128570150\ee\AOLServiceHost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\taskdir~.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\ewido anti-malware\securitysuite.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\HJT\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dell4me.com/mywayR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.comcast.net/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Travis Greenwood\Application Data\Mozilla\Profiles\default\1ju5e06w.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1128570150\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [Windows Media Connect 2] "C:\Program Files\Windows Media Connect 2\WMCCFG.exe" /StartQuiet
O4 - HKLM\..\Run: [PCTAVApp] "C:\Program Files\PC Tools AntiVirus\PCTAV.exe" /MONITORSCAN
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [ATI Remote Control] C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} -
http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} -
http://www.comcastsupport.com/ (file missing)
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} -
http://online.comcast.net/help/ (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} -
http://wwws.musicmat...enWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) -
http://www.fileplane...DC_2.1.2.76.cabO16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://by3fd.bay3.ho...es/MsnPUpld.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupd...b?1108659059125O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) -
http://chat.yahoo.com/cab/yuplapp.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn...pDownloader.cabO16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} -
http://us.dl1.yimg.c...utocomplete.cabO18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)