Ok, here is my uninstall list:
Ad-Aware SE Personal
Adobe Acrobat 7.0.1 and Reader 7.0.1 Update
Adobe Acrobat 7.0.2 and Reader 7.0.2 Update
Adobe Download Manager 2.0 (Remove Only)
Adobe Reader 7.0
AIM Toolbar
AOL Instant Messenger
DivX
DivX Player
ewido security suite
Eyetide Viewer
Google Toolbar for Internet Explorer
HighMAT Extension to Microsoft Windows XP CD Writing Wizard
HijackThis 1.99.1
Hotfix for Windows XP (KB896344)
iPod for Windows 2005-03-23
iPod for Windows 2005-06-26
iPod for Windows User Guide
iPod System Software Updater 2.1
iTunes
J2SE Runtime Environment 5.0 Update 1
J2SE Runtime Environment 5.0 Update 2
Java 2 Runtime Environment Standard Edition v1.3.1_04
LimeWire
LimeWire 4.8.1
LiveUpdate 2.0 (Symantec Corporation)
Macromedia Shockwave Player
Maniac Mansion Deluxe
Media Access
Mega Camera Manager
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB886903)
Microsoft Data Access Components KB870669
Microsoft Office 2000 SR-1 Premium
Microsoft Windows Journal Viewer
MLB.com Playball
MSXML4 Parser
Musicmatch® Jukebox
OIN
QuickTime
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893066)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB903235)
Symantec AntiVirus
The New Adventures of Zak McKracken
Tony Hawk's Pro Skater 2
Trend Micro Anti-Spyware
Update for Windows XP (KB898461)
Verizon Online
Verizon Online Support Center
Viewpoint Media Player
WeatherBug
WildTangent Web Driver
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
Here is my scan report:
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 3:27:32 PM, 7/29/2005
+ Report-Checksum: 8446EF2C
+ Scan result:
HKLM\SOFTWARE\AutoLoader -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\AutoLoader\AproposClient -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\AutoLoader\oyou1IJjIIJM -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\AutoLoader\oyoY1IJjIIJM -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{B5AB638F-D76C-415B-A8F2-F3CEAC502212} -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA} -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{B548B7D8-3D03-4AED-A6A1-4251FAD00C10} -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{B99A727F-0782-4A71-BCC2-6E1E66414904} -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA} -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\MediaAccess.Installer -> Spyware.WinAd : Cleaned with backup
HKLM\SOFTWARE\Classes\MediaAccess.Installer\CLSID -> Spyware.WinAd : Cleaned with backup
HKLM\SOFTWARE\Classes\MediaAccess.Installer\CurVer -> Spyware.WinAd : Cleaned with backup
HKLM\SOFTWARE\Envolo -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Envolo\AutoUpdate -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Envolo\AutoUpdate\State -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Envolo\AutoUpdate\Tasks -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AproposClient -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AutoUpdate -> Spyware.AproposMedia : Cleaned with backup
HKU\S-1-5-21-1202660629-1343024091-1708537768-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3643ABC2-21BF-46B9-B230-F247DB0C6FD6} -> Spyware.E2Give : Cleaned with backup
[512] C:\WINDOWS\system32\dgser.dll -> Spyware.Look2Me : Error during cleaning
[1104] C:\WINDOWS\system32\ccmsnap.dll -> Spyware.Look2Me : Error during cleaning
[1704] C:\WINDOWS\system32\ccmsnap.dll -> Spyware.Look2Me : Error during cleaning
C:\WINDOWS\SYSTEM\UpdInst.exe -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\SYSTEM32\mhxoci.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\SYSTEM32\wyauserv.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\SYSTEM32\SSK39.exe -> TrojanDropper.Small.qn : Cleaned with backup
C:\WINDOWS\SYSTEM32\auto_update_uninstall.exe -> Spyware.AproposMedia : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\marissa
[email protected][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\marissa
[email protected][1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\marissa noll@yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\WINDOWS\TEMP\Cookies\marissa
[email protected][2].txt -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\WINDOWS\TEMP\Temporary Internet Files\Content.IE5\IL85QTST\AutoUpdaterInstaller[1].exe -> TrojanDownloader.Apropo.g : Cleaned with backup
C:\WINDOWS\TEMP\MediaAccessInstPack.exe -> Spyware.WinAD : Cleaned with backup
C:\WINDOWS\TEMP\180sainstallersca.exe/clientax.dll -> Spyware.180Solutions : Cleaned with backup
C:\WINDOWS\TEMP\AutoUpdate0\auto_update_install.exe -> Spyware.AproposMedia : Cleaned with backup
C:\Program Files\Common Files\Verizon Online\SFP\vzbb.dll -> Spyware.MegaSearch : Cleaned with backup
C:\Program Files\Media Access\MediaAccC.dll -> Spyware.WinAD : Cleaned with backup
C:\Documents and Settings\Marissa Noll\Local Settings\Temp\Temporary Internet Files\Content.IE5\SJFFA855\Installer[1].exe -> Spyware.Look2Me : Cleaned with backup
C:\Documents and Settings\Marissa Noll\Local Settings\Temp\Cookies\marissa noll@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Marissa Noll\Local Settings\Temp\Cookies\marissa noll@paycounter[1].txt -> Spyware.Cookie.Paycounter : Cleaned with backup
C:\Documents and Settings\Marissa Noll\Local Settings\Temp\Cookies\marissa noll@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Marissa Noll\Local Settings\Temp\Cookies\marissa
[email protected][2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Marissa Noll\Local Settings\Temp\Cookies\marissa noll@sexlist[1].txt -> Spyware.Cookie.Sexlist : Cleaned with backup
C:\Documents and Settings\Marissa Noll\Local Settings\Temp\Cookies\marissa
[email protected][2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Marissa Noll\Local Settings\Temp\Cookies\marissa
[email protected][1].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Marissa Noll\Local Settings\Temp\Cookies\marissa
[email protected][2].txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
C:\Documents and Settings\Marissa Noll\Local Settings\Temp\Cookies\marissa
[email protected][1].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\Marissa Noll\Local Settings\Temp\Cookies\marissa noll@serving-sys[2].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\Marissa Noll\Local Settings\Temp\Cookies\marissa noll@trafficmp[1].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\Marissa Noll\Local Settings\Temp\Cookies\marissa noll@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\Marissa Noll\Local Settings\Temp\Cookies\marissa noll@shopathomeselect[1].txt -> Spyware.Cookie.Shopathomeselect : Cleaned with backup
C:\Documents and Settings\Marissa Noll\Local Settings\Temp\Cookies\marissa noll@advertising[1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Marissa Noll\Local Settings\Temp\Cookies\marissa
[email protected][1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Documents and Settings\Marissa Noll\Local Settings\Temp\Cookies\marissa noll@valueclick[2].txt -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\Documents and Settings\Marissa Noll\Local Settings\Temp\Cookies\marissa noll@casalemedia[1].txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\Marissa Noll\Local Settings\Temp\Cookies\marissa noll@targetnet[1].txt -> Spyware.Cookie.Targetnet : Cleaned with backup
C:\Documents and Settings\Marissa Noll\Local Settings\Temp\Cookies\marissa
[email protected][2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Marissa Noll\Local Settings\Temp\Cookies\marissa noll@fastclick[2].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Documents and Settings\Marissa Noll\Local Settings\Temp\Cookies\marissa noll@paypopup[2].txt -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Documents and Settings\Marissa Noll\Local Settings\Temp\Cookies\marissa
[email protected][2].txt -> Spyware.Cookie.Shopathomeselect : Cleaned with backup
C:\Documents and Settings\Marissa Noll\Local Settings\Temp\Cookies\marissa
[email protected][2].txt -> Spyware.Cookie.Shopathomeselect : Cleaned with backup
C:\Documents and Settings\Marissa Noll\Local Settings\Temp\Cookies\marissa
[email protected][1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\Marissa Noll\Local Settings\Temp\Cookies\marissa
[email protected][2].txt -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\Documents and Settings\Marissa Noll\Local Settings\Temp\Cookies\marissa noll@overture[2].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\Marissa Noll\Local Settings\Temp\Cookies\marissa
[email protected][1].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Marissa Noll\Local Settings\Temp\Cookies\marissa noll@burstnet[2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Marissa Noll\Local Settings\Temp\Cookies\marissa noll@statcounter[1].txt -> Spyware.Cookie.Statcounter : Cleaned with backup
C:\Documents and Settings\Marissa Noll\Local Settings\Temp\Cookies\marissa noll@2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Marissa Noll\Local Settings\Temp\Cookies\marissa
[email protected][2].txt -> Spyware.Cookie.Counted : Cleaned with backup
C:\Documents and Settings\Marissa Noll\Local Settings\Temp\Cookies\marissa
[email protected][2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Marissa Noll\Local Settings\Temp\Cookies\marissa
[email protected][2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Marissa Noll\Local Settings\Temporary Internet Files\Content.IE5\LSNRSZC7\AppWrap[1].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\Marissa Noll\Local Settings\Temporary Internet Files\Content.IE5\LSNRSZC7\AppWrap[2].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\Marissa Noll\Local Settings\Temporary Internet Files\Content.IE5\1VZNT9Q6\AppWrap[1].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\Marissa Noll\Local Settings\Temporary Internet Files\Content.IE5\BKXSGD6E\AppWrap[1].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\System Volume Information\_restore{C4FC8C15-35F9-4C38-BE39-527EC5A664D0}\RP432\A0079425.exe -> Spyware.MediaTickets : Cleaned with backup
C:\System Volume Information\_restore{C4FC8C15-35F9-4C38-BE39-527EC5A664D0}\RP432\A0079664.exe -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{C4FC8C15-35F9-4C38-BE39-527EC5A664D0}\RP432\A0079665.DLL -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{C4FC8C15-35F9-4C38-BE39-527EC5A664D0}\RP432\A0079666.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{C4FC8C15-35F9-4C38-BE39-527EC5A664D0}\RP432\A0079667.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{C4FC8C15-35F9-4C38-BE39-527EC5A664D0}\RP432\A0079668.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{C4FC8C15-35F9-4C38-BE39-527EC5A664D0}\RP432\A0079669.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{C4FC8C15-35F9-4C38-BE39-527EC5A664D0}\RP432\A0079670.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{C4FC8C15-35F9-4C38-BE39-527EC5A664D0}\RP432\A0079671.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{C4FC8C15-35F9-4C38-BE39-527EC5A664D0}\RP432\A0079672.dll -> TrojanDownloader.Braidupdate.d : Cleaned with backup
C:\System Volume Information\_restore{C4FC8C15-35F9-4C38-BE39-527EC5A664D0}\RP432\A0079673.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{C4FC8C15-35F9-4C38-BE39-527EC5A664D0}\RP432\A0079674.exe -> Spyware.MarketScore : Cleaned with backup
C:\System Volume Information\_restore{C4FC8C15-35F9-4C38-BE39-527EC5A664D0}\RP432\A0079675.exe -> Spyware.PurityScan : Cleaned with backup
C:\System Volume Information\_restore{C4FC8C15-35F9-4C38-BE39-527EC5A664D0}\RP432\A0079676.dll -> Spyware.WildTangent : Cleaned with backup
C:\System Volume Information\_restore{C4FC8C15-35F9-4C38-BE39-527EC5A664D0}\RP432\A0079677.dll -> Spyware.WildTangent : Cleaned with backup
C:\System Volume Information\_restore{C4FC8C15-35F9-4C38-BE39-527EC5A664D0}\RP432\A0079690.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{C4FC8C15-35F9-4C38-BE39-527EC5A664D0}\RP433\A0079778.exe -> Spyware.MediaTickets : Cleaned with backup
C:\System Volume Information\_restore{C4FC8C15-35F9-4C38-BE39-527EC5A664D0}\RP434\A0079783.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{C4FC8C15-35F9-4C38-BE39-527EC5A664D0}\RP434\A0079819.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{C4FC8C15-35F9-4C38-BE39-527EC5A664D0}\RP434\A0079827.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{C4FC8C15-35F9-4C38-BE39-527EC5A664D0}\RP434\A0079835.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{C4FC8C15-35F9-4C38-BE39-527EC5A664D0}\RP434\A0079839.EXE -> TrojanDownloader.Small.aal : Cleaned with backup
C:\System Volume Information\_restore{C4FC8C15-35F9-4C38-BE39-527EC5A664D0}\RP434\A0079841.exe -> Spyware.WinAD : Cleaned with backup
C:\System Volume Information\_restore{C4FC8C15-35F9-4C38-BE39-527EC5A664D0}\RP434\A0079842.exe -> Spyware.WinAD : Cleaned with backup
C:\System Volume Information\_restore{C4FC8C15-35F9-4C38-BE39-527EC5A664D0}\RP434\A0079843.exe -> TrojanDownloader.Apropo.ae : Cleaned with backup
C:\System Volume Information\_restore{C4FC8C15-35F9-4C38-BE39-527EC5A664D0}\RP434\A0079852.dll -> Spyware.Look2Me : Cleaned with backup
::Report End
And here is my Hijackthis report:
Logfile of HijackThis v1.99.1
Scan saved at 3:50:37 PM, on 7/29/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.5.0_02\bin\jucheck.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\etb\pokapoka62.exe
C:\PROGRA~1\MUSICM~1\MUSICM~2\MMDiag.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Trend Micro\Tmas\Tmas.exe
C:\Program Files\Eyetide Media\Eyetide Viewer\EyetideController.exe
C:\Program Files\Verizon Online\bin\mpbtn.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\MUSICM~1\COMMON\COMPON~1\MMCOMP~1.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Documents and Settings\Marissa Noll\Desktop\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL =
http://searchmiracle.com/sp.phpR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [A70F6A1D-0195-42a2-934C-D8AC0F7C08EB] rundll32.exe E6F1873B.DLL,D9EBC318C
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [System service62] C:\WINDOWS\etb\pokapoka62.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\WEATHER.EXE 1
O4 - Startup: Eyetide Launcher.lnk = C:\Program Files\Eyetide Media\Eyetide Viewer\EyetideController.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\bin\matcli.exe
O4 - Global Startup: Trend Micro Anti-Spyware.lnk = C:\Program Files\Trend Micro\Tmas\Tmas.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar3.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar3.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar3.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar3.dll/cmtrans.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} (WildTangent Active Launcher) -
http://install.wildt...iveLauncher.cabO16 - DPF: {4208FB4D-4E53-4F5A-BF7A-3E047DDB5281} (ActiveX Control) -
http://www.icannnews.../ST/ActiveX.ocxO16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -
http://download.mcaf...90/mcinsctl.cabO16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai...all/xscan53.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn...pDownloader.cabO16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} -
http://download.mcaf...,23/mcgdmgr.cabO20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O20 - Winlogon Notify: Themes - C:\WINDOWS\system32\dgser.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NAI ePO Agent Install (NAIMServInst) - Unknown owner - C:\DOCUME~1\MARISS~1\LOCALS~1\Temp\unz2B.tmp\FramePkg.exe (file missing)
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe