this is the avg log
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 9:35:44 PM 11/28/2006
+ Scan result:
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP194\A0055898.dll -> Adware.Aws : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP213\A0059233.dll -> Adware.Aws : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP184\A0054912.exe -> Adware.ClickSpring : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP179\A0054328.dll -> Adware.EZula : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP183\A0054740.dll -> Adware.EZula : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP184\A0054874.dll -> Adware.EZula : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP184\A0054982.dll -> Adware.EZula : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP186\A0055124.dll -> Adware.EZula : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP186\A0055145.dll -> Adware.EZula : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP187\A0055274.dll -> Adware.EZula : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP189\A0055403.dll -> Adware.EZula : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP191\A0055463.dll -> Adware.EZula : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP191\A0055464.dll -> Adware.EZula : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP191\A0055465.dll -> Adware.EZula : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP195\A0056169.dll -> Adware.EZula : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP198\A0056270.dll -> Adware.EZula : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP234\A0067147.dll -> Adware.EZula : No action taken.
C:\Documents and Settings\Tyler\Local Settings\Temporary Internet Files\Content.IE5\PELA8UAA\122[1].net -> Adware.Maxifiles : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP189\A0055327.exe -> Adware.Maxifiles : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP238\A0069763.ocx -> Adware.MediaMotor : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP209\A0057802.dll -> Adware.PrintView : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP238\A0069730.dll -> Adware.PurityScan : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP213\A0059235.dll -> Adware.Softomate : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP232\A0066084.dll -> Adware.Softomate : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP232\A0066085.exe -> Adware.Softomate : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP232\A0066086.exe -> Adware.Softomate : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP234\A0067158.exe -> Adware.Softomate : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP234\A0067529.dll -> Adware.Softomate : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP234\A0067530.exe -> Adware.Softomate : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP238\A0068668.exe -> Adware.Softomate : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP238\A0068703.exe -> Adware.Softomate : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP239\A0069786.exe -> Adware.Softomate : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP239\A0069787.dll -> Adware.Softomate : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP247\A0070375.exe -> Adware.Softomate : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP213\A0059234.exe -> Adware.SurfSide : No action taken.
C:\!KillBox\justin_new.exe -> Adware.TrafficSol : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP171\A0052355.dll -> Adware.TrafficSol : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP234\A0067145.dll -> Adware.TrafficSol : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP238\A0068690.exe -> Adware.TrafficSol : No action taken.
C:\WINDOWS\system32\adrotate.dll -> Adware.TrafficSol : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP221\A0059580.exe -> Adware.Trymedia : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP238\A0069728.dll -> Adware.Virtumonde : No action taken.
C:\WINDOWS\system32\cbxywtt.dll -> Adware.Virtumonde : No action taken.
C:\WINDOWS\system32\gebbxyv.dll -> Adware.Virtumonde : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP173\A0052763.exe -> Adware.ZenoSearch : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP173\A0052765.exe -> Adware.ZenoSearch : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP173\A0052766.exe -> Adware.ZenoSearch : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP178\A0054134.exe -> Adware.ZenoSearch : No action taken.
C:\Documents and Settings\Tyler\Local Settings\Temporary Internet Files\Content.IE5\PELA8UAA\wlzip32[1].exe -> Downloader.Agent.bca : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP213\A0059229.exe -> Downloader.Agent.c : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP130\A0032923.dll -> Downloader.Zlob.aix : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP133\A0033529.dll -> Downloader.Zlob.ajg : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP232\A0066088.exe -> Downloader.Zlob.axt : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP234\A0066177.exe -> Downloader.Zlob.aya : No action taken.
C:\WINDOWS\system32\CompControls.ocx -> Not-A-Virus.Monitor.Win32.PCTattletale.a : No action taken.
C:\WINDOWS\system32\MSN32.dll -> Not-A-Virus.Monitor.Win32.PCTattletale.a : No action taken.
C:\WINDOWS\system32\explorer32\chattext.dll -> Not-A-Virus.Monitor.Win32.PCTattletale.a : No action taken.
C:\Program Files\Cain\Abel.dll -> Not-A-Virus.PSWTool.Win32.Cain.284 : No action taken.
C:\Program Files\Cain\Abel.exe -> Not-A-Virus.PSWTool.Win32.Cain.284 : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP131\A0032936.dll -> Not-A-Virus.PSWTool.Win32.Cain.284 : No action taken.
C:\System Volume Information\_restore{A4A08791-9E85-41CF-B774-D096D3F6C4B9}\RP131\A0032946.exe -> Not-A-Virus.PSWTool.Win32.Cain.284 : No action taken.
:mozilla.85:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\5vcz6odh.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.86:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\5vcz6odh.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.19:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\5vcz6odh.default\cookies.txt -> TrackingCookie.Atdmt : No action taken.
:mozilla.56:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\5vcz6odh.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.57:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\5vcz6odh.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.58:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\5vcz6odh.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.59:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\5vcz6odh.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.60:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\5vcz6odh.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.61:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\5vcz6odh.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.21:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\5vcz6odh.default\cookies.txt -> TrackingCookie.Doubleclick : No action taken.
:mozilla.54:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\5vcz6odh.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.55:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\5vcz6odh.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.73:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\5vcz6odh.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.94:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\5vcz6odh.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
C:\Documents and Settings\Tom\Cookies\tom@mediaplex[1].txt -> TrackingCookie.Mediaplex : No action taken.
:mozilla.76:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\5vcz6odh.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken.
:mozilla.77:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\5vcz6odh.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken.
:mozilla.31:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\5vcz6odh.default\cookies.txt -> TrackingCookie.Reliablestats : No action taken.
:mozilla.33:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\5vcz6odh.default\cookies.txt -> TrackingCookie.Reliablestats : No action taken.
:mozilla.35:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\5vcz6odh.default\cookies.txt -> TrackingCookie.Reliablestats : No action taken.
:mozilla.36:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\5vcz6odh.default\cookies.txt -> TrackingCookie.Reliablestats : No action taken.
C:\Documents and Settings\Tom\Cookies\
[email protected][2].txt -> TrackingCookie.Reliablestats : No action taken.
:mozilla.20:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\5vcz6odh.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
:mozilla.22:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\5vcz6odh.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
:mozilla.23:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\5vcz6odh.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
:mozilla.24:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\5vcz6odh.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
:mozilla.65:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\5vcz6odh.default\cookies.txt -> TrackingCookie.Webtrendslive : No action taken.
:mozilla.66:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\5vcz6odh.default\cookies.txt -> TrackingCookie.Webtrendslive : No action taken.
::Report end
and this is the smitfraud fix log
\SmitFraudFix v2.125
Scan done at 21:38:37.37, Tue 11/28/2006
Run from C:\Documents and Settings\Tom\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix run in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Killing process
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
Registry Cleaning done.
»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» End
and this is the new hjt log it worldnt let me save the uninstall list.... the program just shut down
Logfile of HijackThis v1.99.1
Scan saved at 9:59:20 PM, on 11/28/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PCCTLCOM.EXE
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TMPROXY.EXE
C:\WINDOWS\system32\wdfmgr.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TMPFW.EXE
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\WINDOWS\SYSTEM32\explorer32\WinsysMngr32.exe
C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
C:\WINDOWS\System32\wbem\unsecapp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRAM FILES\BITTORRENT\BITTORRENT.EXE
C:\DOCUME~1\TYLER\LOCALS~1\TEMP\RAR$EX00.328\PROCEXP.EXE
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\System32\nvraidservice.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\SYSTEM32\explorer32\WinsysMngr32.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\wbem\unsecapp.exe
C:\PROGRAM FILES\MOZILLA FIREFOX\FIREFOX.EXE
C:\Program Files\Trend Micro\Internet Security 2006\pccguide.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Plaxo\2.11.1.5\PlaxoHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\PROGRAM FILES\YAHOO!\WIDGETENGINE\YAHOOWIDGETENGINE.EXE
C:\PROGRAM FILES\YAHOO!\WIDGETENGINE\YAHOOWIDGETENGINE.EXE
C:\Program Files\Yahoo!\WidgetEngine\YahooWidgetEngine.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\EXPLORER.EXE
C:\DOCUME~1\TYLER\LOCALS~1\TEMP\RAR$EX00.328\PROCEXP.EXE
C:\PROGRA~1\TRENDM~1\INTERN~1\PCCMAIN.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\HijackThis.exe
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\System32\nvraidservice.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [winload32] C:\WINDOWS\SYSTEM32\Winload32.exe
O4 - HKLM\..\Run: [WinLoad] C:\WINDOWS\system32\Winload.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [McAfee Guardian] C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe /SU
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MPFTray] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.5\THGuard.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1133741024\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2006\pccguide.exe"
O4 - HKLM\..\Run: [Tray Temperature] C:\DOCUME~1\Tyler\LOCALS~1\Temp\MiniBug.exe 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\2.11.1.5\PlaxoHelper.exe -a
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ATI Remote Control] C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\WidgetEngine\YahooWidgetEngine.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: eBay - Homepage - {EF79EAC5-3452-4E02-B8BD-BA4C89F1AC7A} - C:\Program Files\IrfanView\Ebay\Ebay.htm
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: Yahoo! Chat -
http://us.chat1.yimg...t/c381/chat.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.5) -
http://housecall65.t...ivex/hcImpl.cabO16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) -
http://us.chat1.yimg...v45/yacscom.cabO16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -
http://download.mcaf...83/mcinsctl.cabO16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} -
http://download.bitd...can8/oscan8.cabO16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) -
http://www.amiuptoda...pdatePortal.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupd...b?1073001353796O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} -
http://download.mcaf...,20/mcgdmgr.cabO16 - DPF: {BF985246-09BF-11D2-BE62-006097DF57F6} -
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} -
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)