crazy E2G and E2Give

2»

Comments

  • TroganTrogan London, UK
    edited July 2006
    No problem! The bad entries are still in your HJT log.

    You may want to print or save the following:

    Please download Ewido to your Desktop or to your usual Download Folder.
    http://www.ewido.net/en/download/
    • Install Ewido by double clicking the installer.
    • Follow the prompts. Make sure that Launch Ewido is checked.
    • On the main screen under Your Computer's security.
      • Click on Change state next to Resident shield. It should now change to inactive.
      • Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
      • Wait until you see the Update succesfull message.
        Note: If the Update now option is grayed out, follow the steps below.
        • Click on Update on the toolbar.
        • Under Manual update, click on the Start Update button.
        • Wait until you see the Update succesfull message.
    • Right-click the Ewido Tray Icon and select Exit. Confirm by clicking Yes.
    If you are having problems with the updater, you can use this link to manually update ewido.
    Ewido manual updates.
    Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that Ewido is closed before installing the update.

    Now go back into Safe Mode:

    Once in Safe Mode, remove the following HJT entries:

    O2 - BHO: CControl Object - {3643ABC2-21BF-46B9-B230-F247DB0C6FD6} - C:\Program Files\E2G\IeBHOs.dll (file missing)
    O20 - AppInit_DLLs: inicfg32.dll


    Still in Safe Mode

    View hidden files and folders:
    • Click Start.
    • Open My Computer.
    • Select the Tools menu and click Folder Options.
    • Select the View Tab.
    • Under the Hidden files and folders heading select Show hidden files and folders.
    • Uncheck the Hide protected operating system files (recommended) option.
    • Click Yes to confirm.
    • Click OK.

    Next, find and delete the following:

    C:\Program Files\E2G << this folder
    C:\WINDOWS\system32\inicfg32.dll << this file

    =====

    Close ALL open Windows / Programs / Folders. Please start Ewido and run a full scan.
    • Click on Scanner on the toolbar.
    • Click on the Settings tab.
      • Under How to act?
        • Click on Recommended Action and choose Quarantine from the popup menu.
      • Under How to scan?
        • All checkboxes should be ticked.
      • Under Possibly unwanted software:
        • All checkboxes should be ticked.
      • Under Reports:
        • Select Automatically generate report after every scan and uncheck Only if threats were found.
      • Under What to scan?
        • Select Scan every file.
    • Click on the Scan tab.
    • Click on Complete System Scan to start the scan process.
    • Let the program scan the machine.
    • When the scan has finished, follow the instructions below.
      IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
      • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
      • At the bottom of the window click on the Apply all Actions button. (3)
        scan1nx.jpg
    • When done, click the Save Scan Report button.
      • Click the Save Report as button.
      • Save the report to your Desktop.
    • Right-click the Ewido Tray Icon and select Exit. Confirm by clicking Yes.
    Reboot into Normal Mode, and post a new HJT log, along with the Ewido log.
  • PsycoKillrPsycoKillr Mason City, Iowa
    edited July 2006
    ok i'll do that. thank God for system restore. I inadvertantly pasted the HJT log to the killbox and ran it. after the reboot i had no internet and most of my programs were gone. lol
  • TroganTrogan London, UK
    edited July 2006
    :eek3::hair:
  • PsycoKillrPsycoKillr Mason City, Iowa
    edited July 2006
    ok here's the ewido report.

    ewido anti-spyware - Scan Report

    + Created at: 2:19:49 PM 07/26/2006

    + Scan result:



    C:\Documents and Settings\Tami Sloss\Local Settings\Temp\180131F.tmp -> Adware.180Solutions : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Local Settings\Temp\180B.tmp -> Adware.180Solutions : Cleaned with backup (quarantined).
    C:\Program Files\BearShare\BearShareZangoInstaller.exe/clientax.dll -> Adware.180Solutions : Error during cleaning.
    C:\WINDOWS\Downloaded Program Files\ClientAX.dll -> Adware.180Solutions : Cleaned with backup (quarantined).
    HKU\S-1-5-21-1060284298-1336601894-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{56F1D444-11BF-4879-A12B-79CF0177F038} -> Adware.180Solutions : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\IeBHOs.Control -> Adware.E2G : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\IeBHOs.Control.1 -> Adware.E2G : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\IeBHOs.Control\CLSID -> Adware.E2G : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\IeBHOs.Control\CurVer -> Adware.E2G : Cleaned with backup (quarantined).
    C:\!KillBox\inicfg32.dll -> Adware.E2give : Cleaned with backup (quarantined).
    C:\!KillBox\inicfg32.dll( 1) -> Adware.E2give : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\inicfg32.dll -> Adware.E2give : Error during cleaning.
    [1176] C:\WINDOWS\system32\inicfg32.dll -> Adware.E2give : Error during cleaning.
    [792] C:\WINDOWS\system32\inicfg32.dll -> Adware.E2give : Error during cleaning.
    C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE_tobedeleted -> Adware.Websearch : Cleaned with backup (quarantined).
    C:\Program Files\Mozilla Firefox\plugins\npclntax.dll -> Adware.Zango : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Local Settings\Temporary Internet Files\Content.IE5\03ZBEOXT\popup[1].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Local Settings\Temporary Internet Files\Content.IE5\L2W6V9TS\popup[1].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Local Settings\Temporary Internet Files\Content.IE5\LKWNTX4H\popup[1].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
    C:\WINDOWS\Downloaded Program Files\popcaploader.dll -> Not-A-Virus.Downloader.Win32.PopCap.b : Cleaned with backup (quarantined).
    C:\WINDOWS\Downloaded Program Files\USDR6_0001_D09M0706NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Cleaned with backup (quarantined).
    C:\WINDOWS\Downloaded Program Files\USDR6_0001_D17M1107NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Local Settings\Temporary Internet Files\Content.IE5\TUZ9XY8I\ll.easyweepa[1].htm -> Not-A-Virus.Exploit.HTML.Mht : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@aavalue[2].txt[/email] -> TrackingCookie.Aavalue : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@paidmarketingpanel.aavalue[1].txt[/email] -> TrackingCookie.Aavalue : Cleaned with backup (quarantined).
    :mozilla.128:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\6qdxr283.Default User\cookies.txt -> TrackingCookie.Abcsearch : Cleaned with backup (quarantined).
    :mozilla.129:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\6qdxr283.Default User\cookies.txt -> TrackingCookie.Abcsearch : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@rotator.dex.adjuggler[2].txt[/email] -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@thunderbolt.adjuggler[2].txt[/email] -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@www.burstbeacon[1].txt[/email] -> TrackingCookie.Burstbeacon : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@www.burstbeacon[1].txt[/email] -> TrackingCookie.Burstbeacon : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@burstnet[1].txt[/email] -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@www.burstnet[1].txt[/email] -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@burstnet[1].txt[/email] -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@www.burstnet[2].txt[/email] -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
    :mozilla.160:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\6qdxr283.Default User\cookies.txt -> TrackingCookie.Clickbank : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@clickbank[1].txt[/email] -> TrackingCookie.Clickbank : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@com[1].txt[/email] -> TrackingCookie.Com : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@com[1].txt[/email] -> TrackingCookie.Com : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@cpvfeed[2].txt[/email] -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined).
    :mozilla.165:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\6qdxr283.Default User\cookies.txt -> TrackingCookie.Enhance : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@c.enhance[2].txt[/email] -> TrackingCookie.Enhance : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@c.enhance[2].txt[/email] -> TrackingCookie.Enhance : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@estat[1].txt[/email] -> TrackingCookie.Estat : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@adopt.euroclick[2].txt[/email] -> TrackingCookie.Euroclick : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@adopt.euroclick[2].txt[/email] -> TrackingCookie.Euroclick : Cleaned with backup (quarantined).
    :mozilla.235:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\6qdxr283.Default User\cookies.txt -> TrackingCookie.Goclick : Cleaned with backup (quarantined).
    :mozilla.236:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\6qdxr283.Default User\cookies.txt -> TrackingCookie.Goclick : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@ilead.itrack[1].txt[/email] -> TrackingCookie.Itrack : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@komtrack[2].txt[/email] -> TrackingCookie.Komtrack : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@sales.liveperson[1].txt[/email] -> TrackingCookie.Liveperson : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@image.masterstats[2].txt[/email] -> TrackingCookie.Masterstats : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@www.myaffiliateprogram[2].txt[/email] -> TrackingCookie.Myaffiliateprogram : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@www.myaffiliateprogram[1].txt[/email] -> TrackingCookie.Myaffiliateprogram : Cleaned with backup (quarantined).
    :mozilla.349:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\l29xgpih.default\cookies.txt -> TrackingCookie.Realcastmedia : Cleaned with backup (quarantined).
    :mozilla.350:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\l29xgpih.default\cookies.txt -> TrackingCookie.Realcastmedia : Cleaned with backup (quarantined).
    :mozilla.351:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\l29xgpih.default\cookies.txt -> TrackingCookie.Realcastmedia : Cleaned with backup (quarantined).
    :mozilla.352:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\l29xgpih.default\cookies.txt -> TrackingCookie.Realcastmedia : Cleaned with backup (quarantined).
    :mozilla.353:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\l29xgpih.default\cookies.txt -> TrackingCookie.Realcastmedia : Cleaned with backup (quarantined).
    :mozilla.354:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\l29xgpih.default\cookies.txt -> TrackingCookie.Realcastmedia : Cleaned with backup (quarantined).
    :mozilla.355:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\l29xgpih.default\cookies.txt -> TrackingCookie.Realcastmedia : Cleaned with backup (quarantined).
    :mozilla.356:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\l29xgpih.default\cookies.txt -> TrackingCookie.Realcastmedia : Cleaned with backup (quarantined).
    :mozilla.357:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\l29xgpih.default\cookies.txt -> TrackingCookie.Realcastmedia : Cleaned with backup (quarantined).
    :mozilla.358:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\l29xgpih.default\cookies.txt -> TrackingCookie.Realcastmedia : Cleaned with backup (quarantined).
    :mozilla.359:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\l29xgpih.default\cookies.txt -> TrackingCookie.Realcastmedia : Cleaned with backup (quarantined).
    :mozilla.360:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\l29xgpih.default\cookies.txt -> TrackingCookie.Realcastmedia : Cleaned with backup (quarantined).
    :mozilla.361:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\l29xgpih.default\cookies.txt -> TrackingCookie.Realcastmedia : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@ads.realcastmedia[2].txt[/email] -> TrackingCookie.Realcastmedia : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@stats1.reliablestats[1].txt[/email] -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@stats1.reliablestats[2].txt[/email] -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
    :mozilla.255:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\l29xgpih.default\cookies.txt -> TrackingCookie.Starware : Cleaned with backup (quarantined).
    :mozilla.256:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\l29xgpih.default\cookies.txt -> TrackingCookie.Starware : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@h.starware[2].txt[/email] -> TrackingCookie.Starware : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@h.starware[2].txt[/email] -> TrackingCookie.Starware : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@statcounter[1].txt[/email] -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
    :mozilla.187:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\6qdxr283.Default User\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
    :mozilla.188:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\6qdxr283.Default User\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@anad.tacoda[1].txt[/email] -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@anat.tacoda[1].txt[/email] -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@tacoda[1].txt[/email] -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@anad.tacoda[1].txt[/email] -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@anat.tacoda[2].txt[/email] -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@tacoda[1].txt[/email] -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@login.tracking101[1].txt[/email] -> TrackingCookie.Tracking101 : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@login.tracking101[1].txt[/email] -> TrackingCookie.Tracking101 : Cleaned with backup (quarantined).
    :mozilla.199:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\l29xgpih.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@webstat[2].txt[/email] -> TrackingCookie.Web-stat : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@weborama[2].txt[/email] -> TrackingCookie.Weborama : Cleaned with backup (quarantined).
    :mozilla.494:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\l29xgpih.default\cookies.txt -> TrackingCookie.Yadro : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@yadro[2].txt[/email] -> TrackingCookie.Yadro : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@yadro[1].txt[/email] -> TrackingCookie.Yadro : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@ad.yieldmanager[1].txt[/email] -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@yieldmanager[1].txt[/email] -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@ad.yieldmanager[2].txt[/email] -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@yieldmanager[1].txt[/email] -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    :mozilla.51:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\6qdxr283.Default User\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
    :mozilla.52:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\6qdxr283.Default User\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).


    ::Report end
  • PsycoKillrPsycoKillr Mason City, Iowa
    edited July 2006
    and here's the HJT log

    Logfile of HijackThis v1.99.1
    Scan saved at 2:25:04 PM, on 07/26/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
    C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
    C:\WINDOWS\system32\LVCOMSX.EXE
    C:\Program Files\Logitech\Video\LogiTray.exe
    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
    C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    C:\Program Files\Common Files\KTTC Desktop Alert\TrueWeather.exe
    C:\Program Files\Logitech\Video\FxSvr2.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: CControl Object - {3643ABC2-21BF-46B9-B230-F247DB0C6FD6} - C:\Program Files\E2G\IeBHOs.dll (file missing)
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
    O4 - HKLM\..\Run: [Lexmark X83 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
    O4 - HKLM\..\Run: [Lexmark X83 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
    O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
    O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
    O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKLM\..\Run: [eTrustPPAP] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust PestPatrol Anti-Spyware\PPActiveDetection.exe"
    O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL,S
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
    O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
    O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
    O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
    O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
    O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    O4 - Global Startup: KTTC Desktop Alert.lnk = C:\Program Files\Common Files\KTTC Desktop Alert\TrueWeather.exe
    O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
    O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZN
    O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
    O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
    O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [CDNCLIENT] Chinese Navigation
    O16 - DPF: 6th Street Omaha Poker by pogo - http://game1.pogo.com/applet-6.6.4.21/omaha/omaha-en_US.cab
    O16 - DPF: Aces Up! by pogo - http://game1.pogo.com/applet-6.6.5.22/aces/aces-en_US.cab
    O16 - DPF: Backgammon by pogo - http://game1.pogo.com/applet-6.6.5.22/backgammon/backgammon-en_US.cab
    O16 - DPF: Battle Phlinx by pogo - http://game1.pogo.com/applet-6.6.5.31/battlephlinx/battlephlinx-en_US.cab
    O16 - DPF: Blackjack by pogo - http://game1.pogo.com/applet-6.6.0.34/blackjack/blackjack-en_US.cab
    O16 - DPF: Blooop by pogo - http://game1.pogo.com/applet-6.6.5.31/cascade/cascade-en_US.cab
    O16 - DPF: Bowling by pogo - http://game1.pogo.com/applet-6.7.0.40/bowling/bowling-en_US.cab
    O16 - DPF: Canasta by pogo - http://game1.pogo.com/applet-6.6.5.31/canasta/canasta-en_US.cab
    O16 - DPF: Checkers by pogo - http://game1.pogo.com/applet-6.5.3.44/checkers2/checkers-en_US.cab
    O16 - DPF: Dice City Roller by pogo - http://game1.pogo.com/applet-6.7.1.23/ytz/ytz-en_US.cab
    O16 - DPF: Dice Derby by pogo - http://game1.pogo.com/applet-6.6.2.21/checkeredflag/checkeredflag-en_US.cab
    O16 - DPF: Euchre by pogo - http://game1.pogo.com/applet-6.5.2.26/euchre/euchre-en_US.cab
    O16 - DPF: First Class Solitaire by pogo - http://game1.pogo.com/applet-6.6.0.34/firstclass2/firstclass2-en_US.cab
    O16 - DPF: Fortune Bingo by pogo - http://game1.pogo.com/applet-6.6.5.31/superbingo/superbingo-en_US.cab
    O16 - DPF: Greenback Bayou by pogo - http://game1.pogo.com/applet-6.6.5.22/greenback/greenback-en_US.cab
    O16 - DPF: Harvest Mania by pogo - http://game1.pogo.com/applet-6.6.3.34/harvest/harvest-en_US.cab
    O16 - DPF: Hearts by pogo - http://game1.pogo.com/applet-6.6.4.29/hearts/hearts-en_US.cab
    O16 - DPF: High Stakes Poker by pogo - http://game1.pogo.com/applet-6.5.4.27/drawpoker/drawpoker-en_US.cab
    O16 - DPF: Jigsaw Detective by pogo - http://game1.pogo.com/applet-6.7.0.40/jigsaw/jigsaw-en_US.cab
    O16 - DPF: Jungle Gin by pogo - http://game1.pogo.com/applet-6.5.2.33/gin/gin-en_US.cab
    O16 - DPF: Lost Temple Poker by pogo - http://game1.pogo.com/applet-6.6.5.31/mhpoker/mhpoker-en_US.cab
    O16 - DPF: Lottso by pogo - http://game1.pogo.com/applet-6.7.0.32/lottso/lottso-en_US.cab
    O16 - DPF: Mah Jong Garden by pogo - http://game1.pogo.com/applet-6.6.5.31/mahjong/mahjong-en_US.cab
    O16 - DPF: Multiline Slots by pogo - http://game1.pogo.com/applet-6.3.3.27/mlslots/mlslots-ob-assets.cab
    O16 - DPF: Pai Gow by pogo - http://game1.pogo.com/applet-6.6.5.31/paigow/paigow-en_US.cab
    O16 - DPF: Payday FreeCell by pogo - http://game1.pogo.com/applet-6.5.0.45/freecell/freecell-ob-assets.cab
    O16 - DPF: Penguin Blocks by pogo - http://game1.pogo.com/applet-6.5.1.31/penguins/penguins-en_US.cab
    O16 - DPF: Phlinx by pogo - http://game1.pogo.com/applet-6.7.0.32/flinger/flinger-en_US.cab
    O16 - DPF: Pinochle by pogo - http://game1.pogo.com/applet-6.6.3.34/pinochle/pinochle-en_US.cab
    O16 - DPF: Pirate's Gold by pogo - http://game1.pogo.com/applet-6.7.0.32/piratesgold/piratesgold-en_US.cab
    O16 - DPF: Pop Fu by pogo - http://game1.pogo.com/applet-6.6.5.22/popfu/popfu-en_US.cab
    O16 - DPF: PoppaZoppa by pogo - http://game1.pogo.com/applet-6.6.0.27/poppazoppa/poppazoppa-en_US.cab
    O16 - DPF: Poppit by pogo - http://game1.pogo.com/applet-6.7.0.40/poppit2/poppit2-en_US.cab
    O16 - DPF: Quick Quack by pogo - http://game1.pogo.com/applet-6.6.0.27/hotstreak/hotstreak-en_US.cab
    O16 - DPF: QWERTY by pogo - http://game1.pogo.com/applet-6.6.2.35/squares/squares-en_US.cab
    O16 - DPF: Ride The Tide by pogo - http://game1.pogo.com/applet-6.5.3.44/ride/ride-en_US.cab
    O16 - DPF: Showbiz Slots 2 by pogo - http://game1.pogo.com/applet-6.6.1.29/slots/showbiz2-en_US.cab
    O16 - DPF: Shuffle Bump by pogo - http://game1.pogo.com/applet-6.7.0.32/puck/puck-en_US.cab
    O16 - DPF: Spades 2 by pogo - http://game1.pogo.com/applet-6.6.1.29/spades2/spades2-en_US.cab
    O16 - DPF: Spades by pogo - http://game1.pogo.com/applet-6.5.0.45/spades/spades-ob-assets.cab
    O16 - DPF: Spider Solitaire by pogo - http://game1.pogo.com/applet-6.6.2.21/spider/spider-en_US.cab
    O16 - DPF: Squelchies by pogo - http://game1.pogo.com/applet-6.6.4.21/squelchies/squelchies-en_US.cab
    O16 - DPF: Sweet Tooth TM by pogo - http://game1.pogo.com/applet-6.6.2.35/sweettooth/sweettooth-en_US.cab
    O16 - DPF: Texas Hold'em Poker by pogo - http://game1.pogo.com/applet-6.6.5.31/holdem/holdem-en_US.cab
    O16 - DPF: Tri-Peaks by pogo - http://game1.pogo.com/applet-6.7.0.32/peaks/peaks-en_US.cab
    O16 - DPF: Tumble Bees by pogo - http://game1.pogo.com/applet-6.6.5.31/jumbee/jumbee-en_US.cab
    O16 - DPF: Wonderland Memories by pogo - http://game1.pogo.com/applet-6.5.3.37/memories/memories-en_US.cab
    O16 - DPF: Word Whomp by pogo - http://game1.pogo.com/applet-6.6.2.21/wordwhomp2/whomp2-en_US.cab
    O16 - DPF: WordJong by pogo - http://game1.pogo.com/applet-6.7.0.40/wordjong/wordjong-en_US.cab
    O16 - DPF: World Class Solitaire by pogo - http://game1.pogo.com/applet-6.7.0.32/worldclass/worldclass-en_US.cab
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
    O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (AlternaTIFF ActiveX) - http://www.alternatiff.com/install/00/alttiff.cab
    O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://groups.msn.com/controls/PhotoUC/MsnPUpld.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1103826001202
    O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
    O16 - DPF: {94EB57FE-2720-496C-B33F-D9353C6E23F7} (F-Secure Online Scanner 2.1) - http://support.f-secure.com/ols/fscax.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://www.sonypictures.com/games/gamehouse/SproutLauncher.cab
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.popcap.com/games/popcaploader_v6.cab
    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
    O18 - Protocol: bw+0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw+0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw-0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw-0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw00 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw00s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw10 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw10s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw20 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw20s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw30 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw30s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw40 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw40s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw50 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw50s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw60 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw60s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw70 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw70s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw80 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw80s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw90 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw90s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwa0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwa0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwb0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwb0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwc0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwc0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwd0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwd0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwe0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwe0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwf0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwf0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O18 - Protocol: bwg0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwg0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwh0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwh0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwi0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwi0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwj0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwj0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwk0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwk0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwl0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwl0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwm0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwm0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwn0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwn0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwo0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwo0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwp0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwp0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwq0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwq0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwr0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwr0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bws0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bws0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwt0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwt0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwu0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwu0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwv0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwv0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bww0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bww0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwx0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwx0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwy0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwy0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwz0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwz0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: offline-8876480 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O20 - AppInit_DLLs: inicfg32.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
    O23 - Service: FAH@C:+Documents and Settings+Tami Sloss+Local Settings+Temporary Internet Files+Content.IE5+03ZBEOXT+FAH504-Console[1].exe - Unknown owner - C:\Documents and Settings\Tami Sloss\Local Settings\Temporary Internet Files\Content.IE5\03ZBEOXT\FAH504-Console[1].exe (file missing)
    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
  • TroganTrogan London, UK
    edited July 2006
    Could you run E2TakeOut once more and post its log please.
  • PsycoKillrPsycoKillr Mason City, Iowa
    edited July 2006
    and as for the inicfg32. i'm getting an error stating that it is in use by another person or program and can not be removed, even though all programs are shut down when i try.
  • PsycoKillrPsycoKillr Mason City, Iowa
    edited July 2006
    E2TakeOut v1.01 [http://www.malwarebytes.org]

    Removed! C:\WINDOWS\system32\inicfg32.dll
    Removed orphaned leftovers
    AppInit key reset :rockon:
  • TroganTrogan London, UK
    edited July 2006
    Finally...we're getting somewhere.

    OK, can you post a new HijackThis log please, along with an Uninstall list.
  • PsycoKillrPsycoKillr Mason City, Iowa
    edited July 2006
    here's the uninstall.
    Ad-Aware SE Personal
    Adobe Reader 7.0
    Avant Browser (remove only)
    BearShare
    CCScore
    Crazy Browser version 2.0.1
    Demolition Derby & Figure 8 Race
    ESSCDBK
    ESScore
    ESSgui
    ESShelp
    ESSini
    ESSPCD
    ESSSONIC
    ESSTOOLS
    ESSvpaht
    ESSvpot
    ewido anti-spyware 4.0
    Google Toolbar for Internet Explorer
    Hijackthis 1.99.1
    HijackThis 1.99.1
    HLPIndex
    HLPRFO
    J2SE Runtime Environment 5.0 Update 6
    Java 2 Runtime Environment, SE v1.4.2_12
    Kodak EasyShare software
    KTTC Desktop Alert
    Lexmark X83
    LimeWire
    Logitech Print Service
    Logitech QuickCam Software
    Logitech® Camera Driver
    Macromedia Flash Player 8
    Macromedia Shockwave Player
    Microsoft Office XP Small Business
    Mozilla Firefox (1.0.4)
    MSN Messenger 7.0
    MSN Music Assistant
    Mystery Case Files - Huntsville
    Mystery Case Files - Prime Suspects
    Notifier
    NVIDIA Display Driver
    OTtBPSDK
    PCDADDIN
    PCDHELP
    Pop-Up Stopper Free Edition
    RenGuard
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player 10 (KB911565)
    Security Update for Windows Media Player 10 (KB917734)
    Security Update for Windows XP (KB883939)
    Security Update for Windows XP (KB890046)
    Security Update for Windows XP (KB893756)
    Security Update for Windows XP (KB896358)
    Security Update for Windows XP (KB896422)
    Security Update for Windows XP (KB896423)
    Security Update for Windows XP (KB896424)
    Security Update for Windows XP (KB896428)
    Security Update for Windows XP (KB896688)
    Security Update for Windows XP (KB899587)
    Security Update for Windows XP (KB899588)
    Security Update for Windows XP (KB899591)
    Security Update for Windows XP (KB900725)
    Security Update for Windows XP (KB901017)
    Security Update for Windows XP (KB901214)
    Security Update for Windows XP (KB902400)
    Security Update for Windows XP (KB903235)
    Security Update for Windows XP (KB904706)
    Security Update for Windows XP (KB905414)
    Security Update for Windows XP (KB905749)
    Security Update for Windows XP (KB905915)
    Security Update for Windows XP (KB908519)
    Security Update for Windows XP (KB908531)
    Security Update for Windows XP (KB911280)
    Security Update for Windows XP (KB911562)
    Security Update for Windows XP (KB911567)
    Security Update for Windows XP (KB911927)
    Security Update for Windows XP (KB912812)
    Security Update for Windows XP (KB912919)
    Security Update for Windows XP (KB913446)
    Security Update for Windows XP (KB913580)
    Security Update for Windows XP (KB914388)
    Security Update for Windows XP (KB914389)
    Security Update for Windows XP (KB916281)
    Security Update for Windows XP (KB917159)
    Security Update for Windows XP (KB917344)
    Security Update for Windows XP (KB917953)
    Security Update for Windows XP (KB918439)
    SFR
    SHASTA
    SKIN0001
    SKINXSDK
    Spybot - Search & Destroy 1.3
    SpywareBlaster v3.5.1
    Update for Windows XP (KB894391)
    Update for Windows XP (KB896727)
    Update for Windows XP (KB898461)
    Update for Windows XP (KB900485)
    Update for Windows XP (KB910437)
    Update for Windows XP (KB916595)
    VPRINTOL
    Windows Defender Signatures
    Windows Genuine Advantage v1.3.0254.0
    Windows Installer 3.1 (KB893803)
    Windows Installer 3.1 (KB893803)
    Windows Media Format Runtime
    Windows Media Player 10
    Windows XP Hotfix - KB834707
    Windows XP Hotfix - KB867282
    Windows XP Hotfix - KB873333
    Windows XP Hotfix - KB873339
    Windows XP Hotfix - KB885250
    Windows XP Hotfix - KB885835
    Windows XP Hotfix - KB885836
    Windows XP Hotfix - KB885884
    Windows XP Hotfix - KB886185
    Windows XP Hotfix - KB887472
    Windows XP Hotfix - KB887742
    Windows XP Hotfix - KB888113
    Windows XP Hotfix - KB888302
    Windows XP Hotfix - KB890047
    Windows XP Hotfix - KB890175
    Windows XP Hotfix - KB890859
    Windows XP Hotfix - KB890923
    Windows XP Hotfix - KB891781
    Windows XP Hotfix - KB893066
    Windows XP Hotfix - KB893086
    Windows XP Service Pack 2
    WIRELESS
    Yahoo! Messenger

    and HJT log
    Logfile of HijackThis v1.99.1
    Scan saved at 2:40:20 PM, on 07/26/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\Program Files\ewido anti-spyware 4.0\guard.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
    C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
    C:\WINDOWS\system32\LVCOMSX.EXE
    C:\Program Files\Logitech\Video\LogiTray.exe
    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
    C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
    C:\Program Files\Logitech\Video\FxSvr2.exe
    C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    C:\Program Files\Common Files\KTTC Desktop Alert\TrueWeather.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
    O4 - HKLM\..\Run: [Lexmark X83 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
    O4 - HKLM\..\Run: [Lexmark X83 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
    O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
    O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
    O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKLM\..\Run: [eTrustPPAP] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust PestPatrol Anti-Spyware\PPActiveDetection.exe"
    O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL,S
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
    O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
    O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
    O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
    O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
    O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    O4 - Global Startup: KTTC Desktop Alert.lnk = C:\Program Files\Common Files\KTTC Desktop Alert\TrueWeather.exe
    O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
    O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZN
    O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
    O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
    O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [CDNCLIENT] Chinese Navigation
    O16 - DPF: 6th Street Omaha Poker by pogo - http://game1.pogo.com/applet-6.6.4.21/omaha/omaha-en_US.cab
    O16 - DPF: Aces Up! by pogo - http://game1.pogo.com/applet-6.6.5.22/aces/aces-en_US.cab
    O16 - DPF: Backgammon by pogo - http://game1.pogo.com/applet-6.6.5.22/backgammon/backgammon-en_US.cab
    O16 - DPF: Battle Phlinx by pogo - http://game1.pogo.com/applet-6.6.5.31/battlephlinx/battlephlinx-en_US.cab
    O16 - DPF: Blackjack by pogo - http://game1.pogo.com/applet-6.6.0.34/blackjack/blackjack-en_US.cab
    O16 - DPF: Blooop by pogo - http://game1.pogo.com/applet-6.6.5.31/cascade/cascade-en_US.cab
    O16 - DPF: Bowling by pogo - http://game1.pogo.com/applet-6.7.0.40/bowling/bowling-en_US.cab
    O16 - DPF: Canasta by pogo - http://game1.pogo.com/applet-6.6.5.31/canasta/canasta-en_US.cab
    O16 - DPF: Checkers by pogo - http://game1.pogo.com/applet-6.5.3.44/checkers2/checkers-en_US.cab
    O16 - DPF: Dice City Roller by pogo - http://game1.pogo.com/applet-6.7.1.23/ytz/ytz-en_US.cab
    O16 - DPF: Dice Derby by pogo - http://game1.pogo.com/applet-6.6.2.21/checkeredflag/checkeredflag-en_US.cab
    O16 - DPF: Euchre by pogo - http://game1.pogo.com/applet-6.5.2.26/euchre/euchre-en_US.cab
    O16 - DPF: First Class Solitaire by pogo - http://game1.pogo.com/applet-6.6.0.34/firstclass2/firstclass2-en_US.cab
    O16 - DPF: Fortune Bingo by pogo - http://game1.pogo.com/applet-6.6.5.31/superbingo/superbingo-en_US.cab
    O16 - DPF: Greenback Bayou by pogo - http://game1.pogo.com/applet-6.6.5.22/greenback/greenback-en_US.cab
    O16 - DPF: Harvest Mania by pogo - http://game1.pogo.com/applet-6.6.3.34/harvest/harvest-en_US.cab
    O16 - DPF: Hearts by pogo - http://game1.pogo.com/applet-6.6.4.29/hearts/hearts-en_US.cab
    O16 - DPF: High Stakes Poker by pogo - http://game1.pogo.com/applet-6.5.4.27/drawpoker/drawpoker-en_US.cab
    O16 - DPF: Jigsaw Detective by pogo - http://game1.pogo.com/applet-6.7.0.40/jigsaw/jigsaw-en_US.cab
    O16 - DPF: Jungle Gin by pogo - http://game1.pogo.com/applet-6.5.2.33/gin/gin-en_US.cab
    O16 - DPF: Lost Temple Poker by pogo - http://game1.pogo.com/applet-6.6.5.31/mhpoker/mhpoker-en_US.cab
    O16 - DPF: Lottso by pogo - http://game1.pogo.com/applet-6.7.0.32/lottso/lottso-en_US.cab
    O16 - DPF: Mah Jong Garden by pogo - http://game1.pogo.com/applet-6.6.5.31/mahjong/mahjong-en_US.cab
    O16 - DPF: Multiline Slots by pogo - http://game1.pogo.com/applet-6.3.3.27/mlslots/mlslots-ob-assets.cab
    O16 - DPF: Pai Gow by pogo - http://game1.pogo.com/applet-6.6.5.31/paigow/paigow-en_US.cab
    O16 - DPF: Payday FreeCell by pogo - http://game1.pogo.com/applet-6.5.0.45/freecell/freecell-ob-assets.cab
    O16 - DPF: Penguin Blocks by pogo - http://game1.pogo.com/applet-6.5.1.31/penguins/penguins-en_US.cab
    O16 - DPF: Phlinx by pogo - http://game1.pogo.com/applet-6.7.0.32/flinger/flinger-en_US.cab
    O16 - DPF: Pinochle by pogo - http://game1.pogo.com/applet-6.6.3.34/pinochle/pinochle-en_US.cab
    O16 - DPF: Pirate's Gold by pogo - http://game1.pogo.com/applet-6.7.0.32/piratesgold/piratesgold-en_US.cab
    O16 - DPF: Pop Fu by pogo - http://game1.pogo.com/applet-6.6.5.22/popfu/popfu-en_US.cab
    O16 - DPF: PoppaZoppa by pogo - http://game1.pogo.com/applet-6.6.0.27/poppazoppa/poppazoppa-en_US.cab
    O16 - DPF: Poppit by pogo - http://game1.pogo.com/applet-6.7.0.40/poppit2/poppit2-en_US.cab
    O16 - DPF: Quick Quack by pogo - http://game1.pogo.com/applet-6.6.0.27/hotstreak/hotstreak-en_US.cab
    O16 - DPF: QWERTY by pogo - http://game1.pogo.com/applet-6.6.2.35/squares/squares-en_US.cab
    O16 - DPF: Ride The Tide by pogo - http://game1.pogo.com/applet-6.5.3.44/ride/ride-en_US.cab
    O16 - DPF: Showbiz Slots 2 by pogo - http://game1.pogo.com/applet-6.6.1.29/slots/showbiz2-en_US.cab
    O16 - DPF: Shuffle Bump by pogo - http://game1.pogo.com/applet-6.7.0.32/puck/puck-en_US.cab
    O16 - DPF: Spades 2 by pogo - http://game1.pogo.com/applet-6.6.1.29/spades2/spades2-en_US.cab
    O16 - DPF: Spades by pogo - http://game1.pogo.com/applet-6.5.0.45/spades/spades-ob-assets.cab
    O16 - DPF: Spider Solitaire by pogo - http://game1.pogo.com/applet-6.6.2.21/spider/spider-en_US.cab
    O16 - DPF: Squelchies by pogo - http://game1.pogo.com/applet-6.6.4.21/squelchies/squelchies-en_US.cab
    O16 - DPF: Sweet Tooth TM by pogo - http://game1.pogo.com/applet-6.6.2.35/sweettooth/sweettooth-en_US.cab
    O16 - DPF: Texas Hold'em Poker by pogo - http://game1.pogo.com/applet-6.6.5.31/holdem/holdem-en_US.cab
    O16 - DPF: Tri-Peaks by pogo - http://game1.pogo.com/applet-6.7.0.32/peaks/peaks-en_US.cab
    O16 - DPF: Tumble Bees by pogo - http://game1.pogo.com/applet-6.6.5.31/jumbee/jumbee-en_US.cab
    O16 - DPF: Wonderland Memories by pogo - http://game1.pogo.com/applet-6.5.3.37/memories/memories-en_US.cab
    O16 - DPF: Word Whomp by pogo - http://game1.pogo.com/applet-6.6.2.21/wordwhomp2/whomp2-en_US.cab
    O16 - DPF: WordJong by pogo - http://game1.pogo.com/applet-6.7.0.40/wordjong/wordjong-en_US.cab
    O16 - DPF: World Class Solitaire by pogo - http://game1.pogo.com/applet-6.7.0.32/worldclass/worldclass-en_US.cab
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
    O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (AlternaTIFF ActiveX) - http://www.alternatiff.com/install/00/alttiff.cab
    O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://groups.msn.com/controls/PhotoUC/MsnPUpld.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1103826001202
    O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
    O16 - DPF: {94EB57FE-2720-496C-B33F-D9353C6E23F7} (F-Secure Online Scanner 2.1) - http://support.f-secure.com/ols/fscax.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://www.sonypictures.com/games/gamehouse/SproutLauncher.cab
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.popcap.com/games/popcaploader_v6.cab
    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
    O18 - Protocol: bw+0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw+0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw-0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw-0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw00 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw00s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw10 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw10s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw20 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw20s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw30 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw30s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw40 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw40s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw50 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw50s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw60 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw60s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw70 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw70s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw80 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw80s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw90 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw90s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwa0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwa0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwb0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwb0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwc0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwc0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwd0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwd0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwe0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwe0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwf0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwf0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O18 - Protocol: bwg0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwg0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwh0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwh0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwi0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwi0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwj0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwj0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwk0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwk0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwl0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwl0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwm0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwm0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwn0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwn0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwo0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwo0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwp0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwp0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwq0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwq0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwr0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwr0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bws0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bws0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwt0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwt0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwu0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwu0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwv0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwv0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bww0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bww0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwx0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwx0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwy0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwy0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwz0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwz0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: offline-8876480 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
    O23 - Service: FAH@C:+Documents and Settings+Tami Sloss+Local Settings+Temporary Internet Files+Content.IE5+03ZBEOXT+FAH504-Console[1].exe - Unknown owner - C:\Documents and Settings\Tami Sloss\Local Settings\Temporary Internet Files\Content.IE5\03ZBEOXT\FAH504-Console[1].exe (file missing)
    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
  • TroganTrogan London, UK
    edited July 2006
    Thanks for the logs. Some updating and cleaning to do now.

    Uninstall the following:

    BearShare << Optional, but recommend its removal
    LimeWire << Optional, but recommend its removal
    J2SE Runtime Environment 5.0 Update 6
    Java 2 Runtime Environment, SE v1.4.2_12
    Spybot - Search & Destroy 1.3


    Then:
    Download the latest version of Java Runtime Environment, and install it to your computer.

    Download the latest version of Spybot Search & Destroy 1.4 from here

    =====

    Open HijackThis
    - Click the Do a system scan only button
    - Check the following entries (below)

    O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL,S
    O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe


    - Close ALL open windows (especially Internet Explorer!)
    Click Fix Checked

    Delete the following folder:
    C:\Program Files\MyWebSearch

    =====

    Please run this online scan:

    Panda ActiveScan

    - Once you are on the Panda site, click the Scan your PC button
    - A new window will open...click the Check Now button
    - Enter your Country
    - Enter your State/Province
    - Enter your e-mail address and click send
    - Select either Home User or Company
    - Click the big Scan Now button
    - If it wants to install an ActiveX component allow it
    - It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
    - When download is complete, click on Local Disks to start the scan
    - When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.

    Post the contents of the Panda scan report, along with a new HijackThis Log. Also, try running BlackLight again and post the log. it should work now.
  • PsycoKillrPsycoKillr Mason City, Iowa
    edited July 2006
    Here's the HJT log.

    Logfile of HijackThis v1.99.1
    Scan saved at 3:21:57 PM, on 07/26/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\Program Files\ewido anti-spyware 4.0\guard.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
    C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
    C:\WINDOWS\system32\LVCOMSX.EXE
    C:\Program Files\Logitech\Video\LogiTray.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
    C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
    C:\Program Files\Logitech\Video\FxSvr2.exe
    C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    C:\Program Files\Common Files\KTTC Desktop Alert\TrueWeather.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
    O4 - HKLM\..\Run: [Lexmark X83 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
    O4 - HKLM\..\Run: [Lexmark X83 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
    O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
    O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
    O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
    O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
    O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
    O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
    O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    O4 - Global Startup: KTTC Desktop Alert.lnk = C:\Program Files\Common Files\KTTC Desktop Alert\TrueWeather.exe
    O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
    O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZN
    O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
    O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
    O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [CDNCLIENT] Chinese Navigation
    O16 - DPF: 6th Street Omaha Poker by pogo - http://game1.pogo.com/applet-6.6.4.21/omaha/omaha-en_US.cab
    O16 - DPF: Aces Up! by pogo - http://game1.pogo.com/applet-6.6.5.22/aces/aces-en_US.cab
    O16 - DPF: Backgammon by pogo - http://game1.pogo.com/applet-6.6.5.22/backgammon/backgammon-en_US.cab
    O16 - DPF: Battle Phlinx by pogo - http://game1.pogo.com/applet-6.6.5.31/battlephlinx/battlephlinx-en_US.cab
    O16 - DPF: Blackjack by pogo - http://game1.pogo.com/applet-6.6.0.34/blackjack/blackjack-en_US.cab
    O16 - DPF: Blooop by pogo - http://game1.pogo.com/applet-6.6.5.31/cascade/cascade-en_US.cab
    O16 - DPF: Bowling by pogo - http://game1.pogo.com/applet-6.7.0.40/bowling/bowling-en_US.cab
    O16 - DPF: Canasta by pogo - http://game1.pogo.com/applet-6.6.5.31/canasta/canasta-en_US.cab
    O16 - DPF: Checkers by pogo - http://game1.pogo.com/applet-6.5.3.44/checkers2/checkers-en_US.cab
    O16 - DPF: Dice City Roller by pogo - http://game1.pogo.com/applet-6.7.1.23/ytz/ytz-en_US.cab
    O16 - DPF: Dice Derby by pogo - http://game1.pogo.com/applet-6.6.2.21/checkeredflag/checkeredflag-en_US.cab
    O16 - DPF: Euchre by pogo - http://game1.pogo.com/applet-6.5.2.26/euchre/euchre-en_US.cab
    O16 - DPF: First Class Solitaire by pogo - http://game1.pogo.com/applet-6.6.0.34/firstclass2/firstclass2-en_US.cab
    O16 - DPF: Fortune Bingo by pogo - http://game1.pogo.com/applet-6.6.5.31/superbingo/superbingo-en_US.cab
    O16 - DPF: Greenback Bayou by pogo - http://game1.pogo.com/applet-6.6.5.22/greenback/greenback-en_US.cab
    O16 - DPF: Harvest Mania by pogo - http://game1.pogo.com/applet-6.6.3.34/harvest/harvest-en_US.cab
    O16 - DPF: Hearts by pogo - http://game1.pogo.com/applet-6.6.4.29/hearts/hearts-en_US.cab
    O16 - DPF: High Stakes Poker by pogo - http://game1.pogo.com/applet-6.5.4.27/drawpoker/drawpoker-en_US.cab
    O16 - DPF: Jigsaw Detective by pogo - http://game1.pogo.com/applet-6.7.0.40/jigsaw/jigsaw-en_US.cab
    O16 - DPF: Jungle Gin by pogo - http://game1.pogo.com/applet-6.5.2.33/gin/gin-en_US.cab
    O16 - DPF: Lost Temple Poker by pogo - http://game1.pogo.com/applet-6.6.5.31/mhpoker/mhpoker-en_US.cab
    O16 - DPF: Lottso by pogo - http://game1.pogo.com/applet-6.7.0.32/lottso/lottso-en_US.cab
    O16 - DPF: Mah Jong Garden by pogo - http://game1.pogo.com/applet-6.6.5.31/mahjong/mahjong-en_US.cab
    O16 - DPF: Multiline Slots by pogo - http://game1.pogo.com/applet-6.3.3.27/mlslots/mlslots-ob-assets.cab
    O16 - DPF: Pai Gow by pogo - http://game1.pogo.com/applet-6.6.5.31/paigow/paigow-en_US.cab
    O16 - DPF: Payday FreeCell by pogo - http://game1.pogo.com/applet-6.5.0.45/freecell/freecell-ob-assets.cab
    O16 - DPF: Penguin Blocks by pogo - http://game1.pogo.com/applet-6.5.1.31/penguins/penguins-en_US.cab
    O16 - DPF: Phlinx by pogo - http://game1.pogo.com/applet-6.7.0.32/flinger/flinger-en_US.cab
    O16 - DPF: Pinochle by pogo - http://game1.pogo.com/applet-6.6.3.34/pinochle/pinochle-en_US.cab
    O16 - DPF: Pirate's Gold by pogo - http://game1.pogo.com/applet-6.7.0.32/piratesgold/piratesgold-en_US.cab
    O16 - DPF: Pop Fu by pogo - http://game1.pogo.com/applet-6.6.5.22/popfu/popfu-en_US.cab
    O16 - DPF: PoppaZoppa by pogo - http://game1.pogo.com/applet-6.6.0.27/poppazoppa/poppazoppa-en_US.cab
    O16 - DPF: Poppit by pogo - http://game1.pogo.com/applet-6.7.0.40/poppit2/poppit2-en_US.cab
    O16 - DPF: Quick Quack by pogo - http://game1.pogo.com/applet-6.6.0.27/hotstreak/hotstreak-en_US.cab
    O16 - DPF: QWERTY by pogo - http://game1.pogo.com/applet-6.6.2.35/squares/squares-en_US.cab
    O16 - DPF: Ride The Tide by pogo - http://game1.pogo.com/applet-6.5.3.44/ride/ride-en_US.cab
    O16 - DPF: Showbiz Slots 2 by pogo - http://game1.pogo.com/applet-6.6.1.29/slots/showbiz2-en_US.cab
    O16 - DPF: Shuffle Bump by pogo - http://game1.pogo.com/applet-6.7.0.32/puck/puck-en_US.cab
    O16 - DPF: Spades 2 by pogo - http://game1.pogo.com/applet-6.6.1.29/spades2/spades2-en_US.cab
    O16 - DPF: Spades by pogo - http://game1.pogo.com/applet-6.5.0.45/spades/spades-ob-assets.cab
    O16 - DPF: Spider Solitaire by pogo - http://game1.pogo.com/applet-6.6.2.21/spider/spider-en_US.cab
    O16 - DPF: Squelchies by pogo - http://game1.pogo.com/applet-6.6.4.21/squelchies/squelchies-en_US.cab
    O16 - DPF: Sweet Tooth TM by pogo - http://game1.pogo.com/applet-6.6.2.35/sweettooth/sweettooth-en_US.cab
    O16 - DPF: Texas Hold'em Poker by pogo - http://game1.pogo.com/applet-6.6.5.31/holdem/holdem-en_US.cab
    O16 - DPF: Tri-Peaks by pogo - http://game1.pogo.com/applet-6.7.0.32/peaks/peaks-en_US.cab
    O16 - DPF: Tumble Bees by pogo - http://game1.pogo.com/applet-6.6.5.31/jumbee/jumbee-en_US.cab
    O16 - DPF: Wonderland Memories by pogo - http://game1.pogo.com/applet-6.5.3.37/memories/memories-en_US.cab
    O16 - DPF: Word Whomp by pogo - http://game1.pogo.com/applet-6.6.2.21/wordwhomp2/whomp2-en_US.cab
    O16 - DPF: WordJong by pogo - http://game1.pogo.com/applet-6.7.0.40/wordjong/wordjong-en_US.cab
    O16 - DPF: World Class Solitaire by pogo - http://game1.pogo.com/applet-6.7.0.32/worldclass/worldclass-en_US.cab
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
    O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (AlternaTIFF ActiveX) - http://www.alternatiff.com/install/00/alttiff.cab
    O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://groups.msn.com/controls/PhotoUC/MsnPUpld.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1103826001202
    O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
    O16 - DPF: {94EB57FE-2720-496C-B33F-D9353C6E23F7} (F-Secure Online Scanner 2.1) - http://support.f-secure.com/ols/fscax.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://www.sonypictures.com/games/gamehouse/SproutLauncher.cab
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.popcap.com/games/popcaploader_v6.cab
    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
    O18 - Protocol: bw+0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw+0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw-0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw-0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw00 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw00s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw10 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw10s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw20 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw20s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw30 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw30s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw40 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw40s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw50 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw50s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw60 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw60s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw70 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw70s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw80 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw80s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw90 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw90s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwa0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwa0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwb0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwb0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwc0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwc0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwd0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwd0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwe0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwe0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwf0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwf0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O18 - Protocol: bwg0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwg0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwh0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwh0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwi0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwi0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwj0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwj0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwk0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwk0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwl0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwl0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwm0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwm0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwn0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwn0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwo0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwo0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwp0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwp0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwq0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwq0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwr0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwr0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bws0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bws0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwt0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwt0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwu0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwu0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwv0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwv0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bww0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bww0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwx0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwx0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwy0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwy0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwz0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwz0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: offline-8876480 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
    O23 - Service: FAH@C:+Documents and Settings+Tami Sloss+Local Settings+Temporary Internet Files+Content.IE5+03ZBEOXT+FAH504-Console[1].exe - Unknown owner - C:\Documents and Settings\Tami Sloss\Local Settings\Temporary Internet Files\Content.IE5\03ZBEOXT\FAH504-Console[1].exe (file missing)
    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

    and the Panda log

    Incident Status Location

    Spyware:Cookie/64.62.232 Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@64.62.232[4].txt[/email]
    Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@888[1].txt[/email]
    Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@888[2].txt[/email]
    Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@adopt.hbmediapro[1].txt[/email]
    Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@atwola[2].txt[/email]
    Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@azjmp[2].txt[/email]
    Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@bannerlandia.com[1].txt[/email]
    Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@belnk[1].txt[/email]
    Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@bravenet[1].txt[/email]
    Spyware:Cookie/Cassava Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@cassava[1].txt[/email]
    Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@cgi-bin[3].txt[/email]
    Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@cgi-bin[6].txt[/email]
    Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@cgi-bin[7].txt[/email]
    Spyware:Cookie/360i Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@ct.360i[1].txt[/email]
    Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@did-it[1].txt[/email]
    Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@dist.belnk[2].txt[/email]
    Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@errorsafe[2].txt[/email]
    Spyware:Cookie/fe.lea.lycos Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@fe.lea.lycos[1].txt[/email]
    Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@gostats[1].txt[/email]
    Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@go[1].txt[/email]
    Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@go[2].txt[/email]
    Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@go[4].txt[/email]
    Spyware:Cookie/Screensavers Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@i.screensavers[1].txt[/email]
    Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@image.checkmystats.com[2].txt[/email]
    Spyware:Cookie/DomainSponsor Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@landing.domainsponsor[1].txt[/email]
    Spyware:Cookie/OfferOptimizer Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@offeroptimizer[2].txt[/email]
    Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@realmedia[1].txt[/email]
    Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@searchportal.information[2].txt[/email]
    Spyware:Cookie/Target Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@target[2].txt[/email]
    Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@toplist[1].txt[/email]
    Spyware:Cookie/WebPower Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@webpower[2].txt[/email]
    Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@www.errorsafe[2].txt[/email]
    Spyware:Cookie/myaffiliateprogram Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@www.myaffiliateprogram[1].txt[/email]
    Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@xiti[1].txt[/email]
    Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@adopt.hbmediapro[1].txt[/email]
    Spyware:Cookie/NewMedia Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@anm.co[2].txt[/email]
    Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@atwola[1].txt[/email]
    Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@azjmp[1].txt[/email]
    Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@belnk[1].txt[/email]
    Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@cgi-bin[1].txt[/email]
    Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@cgi-bin[2].txt[/email]
    Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@cgi-bin[6].txt[/email]
    Spyware:Cookie/360i Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@ct.360i[2].txt[/email]
    Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@did-it[1].txt[/email]
    Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@dist.belnk[2].txt[/email]
    Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@gostats[2].txt[/email]
    Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@go[1].txt[/email]
    Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@image.checkmystats.com[2].txt[/email]
    Spyware:Cookie/Research-int Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@research-int[1].txt[/email]
    Spyware:Cookie/WebPower Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@webpower[1].txt[/email]
    Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@xiti[1].txt[/email]
  • TroganTrogan London, UK
    edited July 2006
    Go to Start > Control Panel > Internet Options.
    Under the General tab click the Delete Files... button; check the Delete all offline content box and press OK. Next, click the Delete Cookies... button and press OK

    Go to "Start" -> "Run" and type in the box: "cleanmgr" press OK. Select the drive where your Operating System is installed (Default is C:) and press OK. Let Disk Cleanup scan your system for files to remove (it takes a few minutes!). On the next screen make sure these 3 options are checked
    • Temporary Files
    • Temporary Internet Files
    • Recycle Bin
    and then press "OK" to remove.

    =====

    Your HijackThis log is clean. :thumbsup:

    Let me know how things are now.
  • PsycoKillrPsycoKillr Mason City, Iowa
    edited July 2006
    Trojan I must say when I first saw this site I was a little leery because so many sites say they can help but in fact things just get worse. NOT HERE. You sat there and helped not only me but I'm sure other ppl with their problems. Thank you for the help and patience. I'm going to be one very happy person now, and so will my wife because now she can play her pogo without the windows defender popping up in the middle of a game with the e2g worning. Once again Thank You:respect::cheers: Everything is clean now.:rockon:
  • TroganTrogan London, UK
    edited July 2006
    Your welcome! Thanks for sticking with me. E2Give is a nasty piece of Spyware that doesn't go easily.

    Glad you've joined Team93. Hope you'll be sticking around. :thumbsup:

    Let me know if we can mark this resolved?
  • PsycoKillrPsycoKillr Mason City, Iowa
    edited July 2006
    I'll definitely be sticking around. and as for the thread, we can close it. everything is back to normal so I'm not worried. Plus I have you guys incase something else happens. lol
  • TroganTrogan London, UK
    edited July 2006
    We'll be here if you need help again. Hopefully, it won't be E2Give! :D

    I'l mark this resolved!
This discussion has been closed.