I uninstalled Mcaffees,whic at the last scan just before I uninstalled it said her system was clean,I installed the latest version of Nod32,updated it,and ran a detailed scan which proceeded to find about 145 problems.
I set it to delete what it could,there were several files it could not do anything to even after I ran it again in windows safe mode.I then updated and ran Spybot SD whih she had been using but had forgotten to update in about 8 months ,and it found more adware and some of it could not be removed even with a reboot.
Becoming desperate,I went to the Panda Software website and downloaded Total Scan,which I bought when it found 117 instances of spyware,adware and viruses because it said it could remove them all,it did not get all of what it found either.
Here is the scan log for it.
;***********************************************************************************************************************************************************************************
ANALYSIS: 2007-07-17 09:15:41
PROTECTIONS: 1
MALWARE: 31
SUSPECTS: 1
;***********************************************************************************************************************************************************************************
PROTECTIONS
Description Version Active Updated
;===================================================================================================================================================================================
ESET NOD32 antivirus system 2.70 2.70 Yes Yes
;===================================================================================================================================================================================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===================================================================================================================================================================================
00000431 adware/ist.istbar Adware No 1 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{42F2C9BA-614F-47c0-B3E3-ECFD34EED658}
00001888 adware/dyfuca Adware No 0 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000010-6F7D-442C-93E3-4A4827C2E4C8}
00018331 adware/gator Adware No 0 Yes Yes c:\windows\gatorpatch.log
00018331 adware/gator Adware No 0 Yes Yes c:\windows\gatorpdpplugin.log
00032731 application/mywebsearch HackTools No 0 Yes No hkey_classes_root\clsid\{9afb8248-617f-460d-9366-d71cdeda3179}
00032731 application/mywebsearch HackTools No 0 Yes No HKEY_LOCAL_MACHINE\software\classes\CLSID\{9AFB8248-617F-460d-9366-D71CDEDA3179}
00032731 application/mywebsearch HackTools No 0 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EAB-A523-4961-B6BB-170DE4475CCA}
00032731 application/mywebsearch HackTools No 0 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44cf-8957-5838F569A31D}
00032731 application/mywebsearch HackTools No 0 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
00034291 adware/surfaccuracy Adware No 1 Yes No hkey_local_machine\software\microsoft\windows\currentversion\app management\arpcache\sacc
00034463 adware/wupd Adware No 0 Yes No hkey_classes_root\install.install
00034463 adware/wupd Adware No 0 Yes No hkey_classes_root\clsid\{205ff73b-ca67-11d5-99dd-444553540013}
00034463 adware/wupd Adware No 0 Yes No HKEY_LOCAL_MACHINE\software\classes\CLSID\{205FF73B-CA67-11D5-99DD-444553540013}
00034463 adware/wupd Adware No 0 Yes No hkey_classes_root\install.install.1
00035917 adware/ist.sidefind Adware No 0 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A3FDD654-A057-4971-9844-4ED8E67DBBB8}
00035917 adware/ist.sidefind Adware No 0 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{10E42047-DEB9-4535-A118-B3F6EC39B807}
00042191 adware/ist.yoursitebar Adware No 0 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{86227D9C-0EFE-4F8A-AA55-30386A3F5686}
00096053 application/funweb HackTools No 0 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}
00096053 application/funweb HackTools No 0 Yes Yes c:\windows\downloaded program files\f3initialsetup1.0.0.15.inf
00096053 application/funweb HackTools No 0 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
00096053 application/funweb HackTools No 0 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9FF05104-B030-46FC-94B8-81276E4E27DF}
00101555 Application/KillApp.B HackTools No 0 Yes Yes C:\hp\bin\KillIt.exe
00103967 adware/dealhelper Adware No 0 Yes No hkey_local_machine\software\classes\appid\dhbrwsr.exe
00103967 adware/dealhelper Adware No 0 Yes No hkey_local_machine\software\classes\appid\dhsvr.exe
00103967 adware/dealhelper Adware No 0 Yes No hkey_classes_root\appid\dhbrwsr.exe
00103967 adware/dealhelper Adware No 0 Yes No hkey_classes_root\appid\dhsvr.exe
00103967 adware/dealhelper Adware No 0 Yes No hkey_classes_root\clsid\{d848a3ca-0bfb-4de0-ba9e-a57f0cca1c13}
00103967 adware/dealhelper Adware No 0 Yes No hkey_local_machine\software\classes\dealhlpr.band
00103967 adware/dealhelper Adware No 0 Yes No hkey_local_machine\software\classes\dealhlpr.band.1
00103967 adware/dealhelper Adware No 0 Yes No hkey_local_machine\software\classes\dealpop.cdealhelperpopup
00103967 adware/dealhelper Adware No 0 Yes No hkey_local_machine\software\classes\dealpop.cdealhelperpopup.1
00103967 adware/dealhelper Adware No 0 Yes No hkey_local_machine\software\classes\dealpop.dealpopevents
00103967 adware/dealhelper Adware No 0 Yes No hkey_local_machine\software\classes\dealpop.dealpopevents.1
00103967 adware/dealhelper Adware No 0 Yes No hkey_local_machine\software\classes\dhbrwsr.browserwindows
00103967 adware/dealhelper Adware No 0 Yes No hkey_local_machine\software\classes\dhbrwsr.browserwindows.1
00103967 adware/dealhelper Adware No 0 Yes No hkey_local_machine\software\classes\dhp.dhevents
00103967 adware/dealhelper Adware No 0 Yes No hkey_local_machine\software\classes\dhp.dhevents.1
00103967 adware/dealhelper Adware No 0 Yes No hkey_local_machine\software\classes\dhsvr.cfiledatabase
00103967 adware/dealhelper Adware No 0 Yes No hkey_local_machine\software\classes\dhsvr.cfiledatabase.1
00103967 adware/dealhelper Adware No 0 Yes No hkey_local_machine\software\classes\dhsvr.dbhelper
00103967 adware/dealhelper Adware No 0 Yes No hkey_local_machine\software\classes\dhsvr.dbhelper.1
00103967 adware/dealhelper Adware No 0 Yes No hkey_classes_root\clsid\{bfef1779-0e92-45a1-bf5e-55991007f912}
00103967 adware/dealhelper Adware No 0 Yes No hkey_local_machine\software\classes\dhsvr.even.1
00103967 adware/dealhelper Adware No 0 Yes No hkey_local_machine\software\classes\dhsvr.webdealevents
00103967 adware/dealhelper Adware No 0 Yes No hkey_local_machine\software\classes\dhsvr.webdealevents.1
00103967 adware/dealhelper Adware No 0 Yes No hkey_classes_root\clsid\{b8e910b5-7452-4a29-b121-08e8cf09ec07}
00103967 adware/dealhelper Adware No 0 Yes No hkey_classes_root\clsid\{8ee1aaf5-ed6b-4601-b333-cd30ffb8b39d}
00103967 adware/dealhelper Adware No 0 Yes No hkey_classes_root\clsid\{8b477303-698c-4eed-b9f6-c715842fbe33}
00103967 adware/dealhelper Adware No 0 Yes No hkey_classes_root\clsid\{6dd8b352-21a7-4c24-ac49-e9b4730c1823}
00103967 adware/dealhelper Adware No 0 Yes No hkey_classes_root\clsid\{54a41ae7-b358-4d41-98bd-bbbffdf5186b}
00103967 adware/dealhelper Adware No 0 Yes No hkey_classes_root\clsid\{1a2883f2-fdc7-4af2-b136-203adb475dd7}
00103967 adware/dealhelper Adware No 0 Yes No hkey_current_user\software\timesynchonization
00103967 adware/dealhelper Adware No 0 Yes No hkey_current_user\software\dealhelper
00103967 adware/dealhelper Adware No 0 Yes No hkey_classes_root\clsid\{f00586de-a432-4b9f-877d-e29cd87efdd6}
00103967 adware/dealhelper Adware No 0 Yes No HKEY_LOCAL_MACHINE\Software\Microsoft\Code Store Database\Distribution Units\{FE4BBEA8-1EFD-4B8A-BD1B-341CCDBEEAA6}
00103967 adware/dealhelper Adware No 0 Yes No HKEY_LOCAL_MACHINE\software\classes\CLSID\{D848A3CA-0BFB-4DE0-BA9E-A57F0CCA1C13}
00103967 adware/dealhelper Adware No 0 Yes No HKEY_LOCAL_MACHINE\software\classes\CLSID\{8B477303-698C-4EED-B9F6-C715842FBE33}
00103967 adware/dealhelper Adware No 0 Yes No HKEY_LOCAL_MACHINE\software\classes\CLSID\{6dd8b352-21a7-4c24-ac49-e9b4730c1823}
00103967 adware/dealhelper Adware No 0 Yes No HKEY_LOCAL_MACHINE\software\classes\CLSID\{8ee1aaf5-ed6b-4601-b333-cd30ffb8b39d}
00103967 adware/dealhelper Adware No 0 Yes No HKEY_LOCAL_MACHINE\software\classes\CLSID\{b8e910b5-7452-4a29-b121-08e8cf09ec07}
00103967 adware/dealhelper Adware No 0 Yes No HKEY_LOCAL_MACHINE\software\classes\CLSID\{bfef1779-0e92-45a1-bf5e-55991007f912}
00103967 adware/dealhelper Adware No 0 Yes No HKEY_LOCAL_MACHINE\software\classes\CLSID\{f00586de-a432-4b9f-877d-e29cd87efdd6}
00103967 adware/dealhelper Adware No 0 Yes No HKEY_CLASSES_ROOT\Interface\{c2e6831b-822b-4a1f-9ef1-1d3eb7d3e985}
00103967 adware/dealhelper Adware No 0 Yes No HKEY_CLASSES_ROOT\Interface\{c9679631-7060-443f-bd37-88f9410ed8c3}
00103967 adware/dealhelper Adware No 0 Yes No HKEY_CLASSES_ROOT\Interface\{06e53101-654c-45eb-bff6-e37e13b5972a}
00103967 adware/dealhelper Adware No 0 Yes No HKEY_CLASSES_ROOT\Interface\{0b16b278-b2e3-4cbf-85b5-e058878f728f}
00103967 adware/dealhelper Adware No 0 Yes No HKEY_CLASSES_ROOT\Interface\{1da40091-14b4-4c21-8170-a2ceede90b10}
00103967 adware/dealhelper Adware No 0 Yes No HKEY_CLASSES_ROOT\Interface\{3afae37a-56a3-4850-b599-4da9a9104b82}
00103967 adware/dealhelper Adware No 0 Yes No HKEY_CLASSES_ROOT\Interface\{81739076-56b7-42ec-a0aa-692794fded1a}
00103967 adware/dealhelper Adware No 0 Yes No HKEY_CLASSES_ROOT\Interface\{bf9ee3a0-1a02-4265-a65f-ac4d4447f6bf}
00103967 adware/dealhelper Adware No 0 Yes No HKEY_CLASSES_ROOT\Interface\{f3816084-9608-485a-b63b-cad8f931577e}
00103967 adware/dealhelper Adware No 0 Yes No HKEY_CLASSES_ROOT\TypeLib\{4b76f69e-247a-4617-aba9-95774658afc5}
00103967 adware/dealhelper Adware No 0 Yes No HKEY_CLASSES_ROOT\Interface\{3d89a731-9f4a-418f-a997-2d633c7c404c}
00103967 adware/dealhelper Adware No 0 Yes No HKEY_CLASSES_ROOT\TypeLib\{25ab1639-3f81-45a8-8318-2dafba8b8f3d}
00103967 adware/dealhelper Adware No 0 Yes No HKEY_CLASSES_ROOT\TypeLib\{771262e0-8feb-4e78-b292-b01c4071b9d1}
00103967 adware/dealhelper Adware No 0 Yes No HKEY_LOCAL_MACHINE\software\classes\CLSID\{54a41ae7-b358-4d41-98bd-bbbffdf5186b}
00103967 adware/dealhelper Adware No 0 Yes No HKEY_LOCAL_MACHINE\software\classes\CLSID\{1a2883f2-fdc7-4af2-b136-203adb475dd7}
00103967 adware/dealhelper Adware No 0 Yes No HKEY_CLASSES_ROOT\AppID\{a57afb0f-c63e-4ae2-8a7b-bca01ba32cc5}
00103967 adware/dealhelper Adware No 0 Yes No HKEY_CLASSES_ROOT\AppID\{a1f53f1d-fb2d-4fe0-8ee8-7bbe69999d9f}
00103967 adware/dealhelper Adware No 0 Yes Yes c:\windows\dhp2.dll
00103967 adware/dealhelper Adware No 0 Yes Yes c:\windows\dhkw1.bin
00103967 adware/dealhelper Adware No 0 Yes No hkey_local_machine\software\classes\dhsvr.even
00139059 Cookie/Traffic Marketplace TrackingCookie No 0 Yes Yes C:\Documents and Settings\Owner\Cookies\owner@trafficmp[2].txt
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes Yes C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@doubleclick[1].txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes Yes C:\Documents and Settings\Owner\Cookies\owner@atdmt[2].txt
00145460 Cookie/2o7 TrackingCookie No 0 Yes Yes C:\Documents and Settings\Owner\Cookies\owner@2o7[2].txt
00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes Yes C:\Documents and Settings\Owner\Cookies\owner@tribalfusion[1].txt
00167747 Cookie/Azjmp TrackingCookie No 0 Yes Yes C:\Documents and Settings\Owner\Cookies\owner@azjmp[1].txt
00168062 Adware/DealHelper Adware No 0 Yes Yes C:\System Volume Information\_restore{6CD01810-EFB9-4AF0-A405-DE07EB8CD51D}\RP1269\A0126563.exe
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes Yes C:\Documents and Settings\Owner\Cookies\owner@serving-sys[1].txt
00168093 Cookie/Serving-sys TrackingCookie No 0 Yes Yes C:\Documents and Settings\Owner\Cookies\owner@bs.serving-sys[1].txt
00170495 Cookie/PointRoll TrackingCookie No 0 Yes Yes C:\Documents and Settings\Owner\Cookies\owner@ads.pointroll[2].txt
00170554 Cookie/Overture TrackingCookie No 0 Yes Yes C:\Documents and Settings\Owner\Cookies\owner@overture[1].txt
00170556 Cookie/RealMedia TrackingCookie No 0 Yes Yes C:\Documents and Settings\Owner\Cookies\owner@realmedia[1].txt
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes Yes C:\Documents and Settings\Owner\Cookies\owner@questionmarket[1].txt
00187950 Cookie/bravenetA TrackingCookie No 0 Yes Yes C:\Documents and Settings\Owner\Cookies\owner@bravenet[1].txt
00213030 application/regclean32 HackTools No 0 Yes No hkey_local_machine\software\registry cleaner
00213030 application/regclean32 HackTools No 0 Yes No hkey_current_user\software\registry cleaner
00213030 application/regclean32 HackTools No 0 Yes Yes c:\documents and settings\owner\application data\registry cleaner
00213030 application/regclean32 HackTools No 0 Yes No hkey_local_machine\software\microsoft\windows\currentversion\uninstall\registry cleaner
00241098 Application/Winfixer2005 HackTools No 0 Yes Yes C:\Documents and Settings\Owner\Local Settings\Temp\ICD2.tmp\UWFX5_0001_N57M2112NetInstaller.exe
00241098 Application/Winfixer2005 HackTools No 0 Yes Yes C:\Documents and Settings\Owner\Local Settings\Temp\ICD3.tmp\UWFX5_0001_N57M2112NetInstaller.exe
00241098 Application/Winfixer2005 HackTools No 0 Yes Yes C:\Documents and Settings\Owner\Local Settings\Temp\ICD4.tmp\UWFX5_0001_N57M2112NetInstaller.exe
00241098 Application/Winfixer2005 HackTools No 0 Yes Yes C:\Documents and Settings\Owner\Local Settings\Temp\ICD5.tmp\UWFX5_0001_N57M2112NetInstaller.exe
00241098 Application/Winfixer2005 HackTools No 0 Yes Yes C:\WINDOWS\Downloaded Program Files\CONFLICT.2\UWFX5_0001_N57M2112NetInstaller.exe
00241098 Application/Winfixer2005 HackTools No 0 Yes Yes C:\WINDOWS\Downloaded Program Files\CONFLICT.4\UWFX5_0001_N57M2112NetInstaller.exe
00241098 Application/Winfixer2005 HackTools No 0 Yes Yes C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UWFX5_0001_N57M2112NetInstaller.exe
00241098 Application/Winfixer2005 HackTools No 0 Yes Yes C:\WINDOWS\Downloaded Program Files\CONFLICT.3\UWFX5_0001_N57M2112NetInstaller.exe
00249100 Cookie/Cgi-bin TrackingCookie No 0 Yes Yes C:\Documents and Settings\Owner\Cookies\owner@cgi-bin[2].txt
00262020 Cookie/Atwola TrackingCookie No 0 Yes Yes C:\Documents and Settings\Owner\Cookies\owner@atwola[1].txt
00278769 Application/PRScheduler HackTools No 0 Yes Yes C:\WINDOWS\pss\PowerReg Scheduler.exeStartup
00365126 Application/MyWebSearch HackTools No 0 Yes Yes C:\Program Files\Internet Explorer\msimg32.dll
;===================================================================================================================================================================================
SUSPECTS
Location
;===================================================================================================================================================================================
C:\WINDOWS\system32\zejwaqwg.exe[HBTVSetup.exe][HBTV.exe]
;===================================================================================================================================================================================
After running that I figured I better come to the experts for help so I downloaded Hijack this and ran a scan,Here is the log for it.
Logfile of HijackThis v1.99.1
Scan saved at 9:26:51 AM, on 7/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Canon\MultiPASS4\MPSERVIC.EXE
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Canon\MultiPASS4\MPDBMgr.exe
C:\Documents and Settings\Owner\Desktop\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us7.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us7.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us7.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us7.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://smunet.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us7.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://us7.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://us7.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = sas.r21.mchsi.com:8000
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.r21.mchsi.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O2 - BHO: PopKill Class - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Zero Knowledge\Freedom\pkR.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: ZKBho Class - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Zero Knowledge\Freedom\FreeBHOR.dll
O2 - BHO: (no name) - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: MktBrowser - {17A27031-71FC-11d4-815C-005004D0F1FA} - C:\Program Files\MarketBrowser\lmt\MarketBrowser_Launch.xpy
O9 - Extra 'Tools' menuitem: MarketBrowser - {17A27031-71FC-11d4-815C-005004D0F1FA} - C:\Program Files\MarketBrowser\lmt\MarketBrowser_Launch.xpy
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: 3 Point Showdown by pogo - http://game1.pogo.com/applet-6.4.2.23/t ... assets.cab
O16 - DPF: 6th Street Omaha Poker by pogo - http://game1.pogo.com/applet-6.6.4.21/o ... -en_US.cab
O16 - DPF: Aces Up! by pogo - http://game1.pogo.com/applet-6.6.4.21/a ... -en_US.cab
O16 - DPF: Ali Baba Slots TM by pogo - http://game1.pogo.com/applet-6.6.1.37/s ... -en_US.cab
O16 - DPF: Backgammon by pogo - http://game1.pogo.com/applet-6.6.0.27/b ... -en_US.cab
O16 - DPF: Battle Phlinx by pogo - http://game1.pogo.com/applet-6.6.2.35/b ... -en_US.cab
O16 - DPF: Blackjack by pogo - http://game1.pogo.com/applet-6.6.0.34/b ... -en_US.cab
O16 - DPF: Blooop by pogo - http://game1.pogo.com/applet-6.6.3.34/c ... -en_US.cab
O16 - DPF: Buckaroo Blackjack TM by pogo - http://game1.pogo.com/applet-6.6.0.34/v ... -en_US.cab
O16 - DPF: Checkers by pogo - http://game1.pogo.com/applet-6.6.2.35/c ... -en_US.cab
O16 - DPF: Chess by pogo - http://game1.pogo.com/applet-6.5.5.36/c ... -en_US.cab
O16 - DPF: Cribbage by pogo - http://game1.pogo.com/applet-6.6.2.21/c ... -en_US.cab
O16 - DPF: Dice Derby by pogo - http://game1.pogo.com/applet-6.6.2.21/c ... -en_US.cab
O16 - DPF: Dominoes by pogo - http://game1.pogo.com/applet-6.6.4.21/d ... -en_US.cab
O16 - DPF: Double Deuce Poker by pogo - http://game1.pogo.com/applet-6.6.4.21/v ... -en_US.cab
O16 - DPF: EA Sports Web Soccer by pogo - http://game1.pogo.com/applet-6.2.5.28/s ... assets.cab
O16 - DPF: Euchre by pogo - http://game1.pogo.com/applet-6.6.4.21/e ... -en_US.cab
O16 - DPF: EZ Win Bingo by pogo - http://game1.pogo.com/applet-6.5.4.34/b ... -en_US.cab
O16 - DPF: First Class Solitaire by pogo - http://game1.pogo.com/applet-6.6.3.34/f ... -en_US.cab
O16 - DPF: Fortune Bingo by pogo - http://game1.pogo.com/applet-6.6.4.21/s ... -en_US.cab
O16 - DPF: Greenback Bayou by pogo - http://game1.pogo.com/applet-6.6.2.21/g ... -en_US.cab
O16 - DPF: Harvest Mania by pogo - http://game1.pogo.com/applet-6.6.3.34/h ... -en_US.cab
O16 - DPF: Hearts by pogo - http://game1.pogo.com/applet-6.5.1.24/h ... -en_US.cab
O16 - DPF: High Stakes Poker by pogo - http://game1.pogo.com/applet-6.5.4.27/d ... -en_US.cab
O16 - DPF: High Stakes Pool by pogo - http://game1.pogo.com/applet-6.6.2.21/p ... -en_US.cab
O16 - DPF: Jokers Wild Poker by pogo - http://game1.pogo.com/applet-6.6.2.35/v ... -en_US.cab
O16 - DPF: Keno by pogo - http://game1.pogo.com/applet-6.5.4.34/k ... -en_US.cab
O16 - DPF: Lost Temple Poker by pogo - http://game1.pogo.com/applet-6.6.0.27/m ... -en_US.cab
O16 - DPF: Lottso by pogo - http://game1.pogo.com/applet-6.6.4.21/l ... -en_US.cab
O16 - DPF: Mah Jong Garden by pogo - http://game1.pogo.com/applet-6.6.4.21/m ... -en_US.cab
O16 - DPF: Multiline Slots by pogo - http://game1.pogo.com/applet-6.6.2.21/m ... -en_US.cab
O16 - DPF: Pai Gow by pogo - http://game1.pogo.com/applet-6.6.2.21/p ... -en_US.cab
O16 - DPF: Payday FreeCell by pogo - http://game1.pogo.com/applet-6.6.0.27/f ... -en_US.cab
O16 - DPF: Pebble Beach Golf by pogo - http://game1.pogo.com/applet-6.5.2.33/p ... -en_US.cab
O16 - DPF: Penguin Blocks by pogo - http://game1.pogo.com/applet-6.5.3.37/p ... -en_US.cab
O16 - DPF: Perfect Pair Solitaire by pogo - http://game1.pogo.com/applet-6.5.3.44/w ... -en_US.cab
O16 - DPF: Phlinx by pogo - http://game1.pogo.com/applet-6.6.1.37/f ... -en_US.cab
O16 - DPF: Pinochle by pogo - http://game1.pogo.com/applet-6.6.3.34/p ... -en_US.cab
O16 - DPF: Pop Fu by pogo - http://game1.pogo.com/applet-6.6.0.27/p ... -en_US.cab
O16 - DPF: PoppaZoppa by pogo - http://game1.pogo.com/applet-6.6.3.34/p ... -en_US.cab
O16 - DPF: Poppit by pogo - http://game1.pogo.com/applet-6.6.3.34/p ... -en_US.cab
O16 - DPF: Quick Quack by pogo - http://game1.pogo.com/applet-6.6.0.27/h ... -en_US.cab
O16 - DPF: QWERTY by pogo - http://game1.pogo.com/applet-6.6.2.35/s ... -en_US.cab
O16 - DPF: Ride The Tide by pogo - http://game1.pogo.com/applet-6.6.0.27/r ... -en_US.cab
O16 - DPF: SciFi Slots by pogo - http://game1.pogo.com/applet-6.6.1.29/s ... -en_US.cab
O16 - DPF: Showbiz Slots 2 by pogo - http://game1.pogo.com/applet-6.6.1.29/s ... -en_US.cab
O16 - DPF: Showbiz Slots by pogo - http://game1.pogo.com/applet-6.6.2.21/s ... -en_US.cab
O16 - DPF: Shuffle Bump by pogo - http://game1.pogo.com/applet-6.6.3.34/p ... -en_US.cab
O16 - DPF: Spades 2 by pogo - http://game1.pogo.com/applet-6.6.0.27/s ... -en_US.cab
O16 - DPF: Spades by pogo - http://game1.pogo.com/applet-6.4.4.34/s ... assets.cab
O16 - DPF: Spider Solitaire by pogo - http://game1.pogo.com/applet-6.6.0.27/s ... -en_US.cab
O16 - DPF: Squelchies by pogo - http://game1.pogo.com/applet-6.6.4.21/s ... -en_US.cab
O16 - DPF: Stax by pogo - http://game1.pogo.com/applet-6.5.1.24/s ... -en_US.cab
O16 - DPF: Stellar Sweeper by pogo - http://game1.pogo.com/applet-6.6.2.21/s ... -en_US.cab
O16 - DPF: Sweet Tooth TM by pogo - http://game1.pogo.com/applet-6.6.0.27/s ... -en_US.cab
O16 - DPF: Texas Hold'em Poker by pogo - http://game1.pogo.com/applet-6.5.3.37/h ... -en_US.cab
O16 - DPF: Tumble Bees by pogo - http://game1.pogo.com/applet-6.5.3.44/j ... -en_US.cab
O16 - DPF: Turbo 21 TM by pogo - http://game1.pogo.com/applet-6.6.4.21/t ... -en_US.cab
O16 - DPF: Vert Skater by pogo - http://game1.pogo.com/applet-6.2.2.66/v ... assets.cab
O16 - DPF: Video Poker by pogo - http://game1.pogo.com/applet-6.6.2.21/v ... -en_US.cab
O16 - DPF: Word Whomp by pogo - http://game1.pogo.com/applet-6.6.2.21/w ... -en_US.cab
O16 - DPF: Word Whomp Whackdown by pogo - http://game1.pogo.com/applet-6.6.2.21/w ... -en_US.cab
O16 - DPF: WordJong by pogo - http://game1.pogo.com/applet-6.4.2.30/w ... assets.cab
O16 - DPF: World Class Solitaire by pogo - http://game1.pogo.com/applet-6.6.4.21/w ... -en_US.cab
O16 - DPF: Yahoo! Pinochle - http://download.games.yahoo.com/games/c ... /ut2_x.cab
O16 - DPF: {0335A685-ED24-4F7B-A08E-3BD15D84E668} - http://dl.filekicker.com/send/file/1289 ... PSetup.cab
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540013} (CInstall Class) - http://adserver.sharewareonline.com/ads ... nstall.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp.com/rdqcpc/downloads/sysinfo.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.av.aol.com/molbin/share ... insctl.cab
O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - http://www.nanoscan.com/as/v1/cabs/ascstubie.cab
O16 - DPF: {8436FE12-31DB-48BF-83BF-FE682F9160B4} (NanoInstaller Class) - http://www.nanoscan.com/cabs/nanoinst.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://rtc1.webresponse.one.microsoft. ... EFlash.CAB
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/a ... _en_dl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.av.aol.com/molbin/share ... cgdmgr.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://aolweb03.pogo.com/game/deluxe/in ... der_v6.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3F8EC5CF-F515-4373-BE66-7C9A80B12B8D}: NameServer = 216.51.211.234,216.51.211.233
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MpService - Canon Inc. - C:\Program Files\Canon\MultiPASS4\MPSERVIC.EXE
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe