Follow the prompts. Make sure that Launch Ewido is checked.
On the main screen under Your Computer's security.
Click on Change state next to Resident shield. It should now change to inactive.
Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
Wait until you see the Update succesfull message. Note: If the Update now option is grayed out, follow the steps below.
Click on Update on the toolbar.
Under Manual update, click on the Start Update button.
Wait until you see the Update succesfull message.
Right-click the Ewido Tray Icon and select Exit. Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update ewido. Ewido manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that Ewido is closed before installing the update.
Now go back into Safe Mode:
Once in Safe Mode, remove the following HJT entries:
Under the Hidden files and folders heading select Show hidden files and folders.
Uncheck the Hide protected operating system files (recommended) option.
Click Yes to confirm.
Click OK.
Next, find and delete the following:
C:\Program Files\E2G << this folder
C:\WINDOWS\system32\inicfg32.dll << this file
=====
Close ALL open Windows / Programs / Folders. Please start Ewido and run a full scan.
Click on Scanner on the toolbar.
Click on the Settings tab.
Under How to act?
Click on Recommended Action and choose Quarantine from the popup menu.
Under How to scan?
All checkboxes should be ticked.
Under Possibly unwanted software:
All checkboxes should be ticked.
Under Reports:
Select Automatically generate report after every scan and uncheck Only if threats were found.
Under What to scan?
Select Scan every file.
Click on the Scan tab.
Click on Complete System Scan to start the scan process.
Let the program scan the machine.
When the scan has finished, follow the instructions below. IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
Make sure that Set all elements to: shows Quarantine(1), if not click on the link and choose Quarantine from the popup menu. (2)
At the bottom of the window click on the Apply all Actions button. (3)
When done, click the Save Scan Report button.
Click the Save Report as button.
Save the report to your Desktop.
Right-click the Ewido Tray Icon and select Exit. Confirm by clicking Yes.
Reboot into Normal Mode, and post a new HJT log, along with the Ewido log.
ok i'll do that. thank God for system restore. I inadvertantly pasted the HJT log to the killbox and ran it. after the reboot i had no internet and most of my programs were gone. lol
Logfile of HijackThis v1.99.1
Scan saved at 2:25:04 PM, on 07/26/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
and as for the inicfg32. i'm getting an error stating that it is in use by another person or program and can not be removed, even though all programs are shut down when i try.
here's the uninstall.
Ad-Aware SE Personal
Adobe Reader 7.0
Avant Browser (remove only)
BearShare
CCScore
Crazy Browser version 2.0.1
Demolition Derby & Figure 8 Race
ESSCDBK
ESScore
ESSgui
ESShelp
ESSini
ESSPCD
ESSSONIC
ESSTOOLS
ESSvpaht
ESSvpot
ewido anti-spyware 4.0
Google Toolbar for Internet Explorer
Hijackthis 1.99.1
HijackThis 1.99.1
HLPIndex
HLPRFO
J2SE Runtime Environment 5.0 Update 6
Java 2 Runtime Environment, SE v1.4.2_12
Kodak EasyShare software
KTTC Desktop Alert
Lexmark X83
LimeWire
Logitech Print Service
Logitech QuickCam Software
Logitech® Camera Driver
Macromedia Flash Player 8
Macromedia Shockwave Player
Microsoft Office XP Small Business
Mozilla Firefox (1.0.4)
MSN Messenger 7.0
MSN Music Assistant
Mystery Case Files - Huntsville
Mystery Case Files - Prime Suspects
Notifier
NVIDIA Display Driver
OTtBPSDK
PCDADDIN
PCDHELP
Pop-Up Stopper Free Edition
RenGuard
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918439)
SFR
SHASTA
SKIN0001
SKINXSDK
Spybot - Search & Destroy 1.3
SpywareBlaster v3.5.1
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
VPRINTOL
Windows Defender Signatures
Windows Genuine Advantage v1.3.0254.0
Windows Installer 3.1 (KB893803)
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB834707
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
WIRELESS
Yahoo! Messenger
and HJT log
Logfile of HijackThis v1.99.1
Scan saved at 2:40:20 PM, on 07/26/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
- Once you are on the Panda site, click the Scan your PC button
- A new window will open...click the Check Now button
- Enter your Country
- Enter your State/Province
- Enter your e-mail address and click send
- Select either Home User or Company
- Click the big Scan Now button
- If it wants to install an ActiveX component allow it
- It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
- When download is complete, click on Local Disks to start the scan
- When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
Post the contents of the Panda scan report, along with a new HijackThis Log. Also, try running BlackLight again and post the log. it should work now.
Logfile of HijackThis v1.99.1
Scan saved at 3:21:57 PM, on 07/26/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Spyware:Cookie/64.62.232 Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@64.62.232[4].txt[/email]
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@888[1].txt[/email]
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@888[2].txt[/email]
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@adopt.hbmediapro[1].txt[/email]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@atwola[2].txt[/email]
Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@azjmp[2].txt[/email]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@bannerlandia.com[1].txt[/email]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@belnk[1].txt[/email]
Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@bravenet[1].txt[/email]
Spyware:Cookie/Cassava Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@cassava[1].txt[/email]
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@cgi-bin[3].txt[/email]
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@cgi-bin[6].txt[/email]
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@cgi-bin[7].txt[/email]
Spyware:Cookie/360i Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@ct.360i[1].txt[/email]
Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@did-it[1].txt[/email]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@dist.belnk[2].txt[/email]
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@errorsafe[2].txt[/email]
Spyware:Cookie/fe.lea.lycos Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@fe.lea.lycos[1].txt[/email]
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@gostats[1].txt[/email]
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@go[1].txt[/email]
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@go[2].txt[/email]
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@go[4].txt[/email]
Spyware:Cookie/Screensavers Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@i.screensavers[1].txt[/email]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@image.checkmystats.com[2].txt[/email]
Spyware:Cookie/DomainSponsor Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@landing.domainsponsor[1].txt[/email]
Spyware:Cookie/OfferOptimizer Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@offeroptimizer[2].txt[/email]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@realmedia[1].txt[/email]
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@searchportal.information[2].txt[/email]
Spyware:Cookie/Target Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@target[2].txt[/email]
Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@toplist[1].txt[/email]
Spyware:Cookie/WebPower Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@webpower[2].txt[/email]
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@www.errorsafe[2].txt[/email]
Spyware:Cookie/myaffiliateprogram Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@www.myaffiliateprogram[1].txt[/email]
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@xiti[1].txt[/email]
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@adopt.hbmediapro[1].txt[/email]
Spyware:Cookie/NewMedia Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@anm.co[2].txt[/email]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@atwola[1].txt[/email]
Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@azjmp[1].txt[/email]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@belnk[1].txt[/email]
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@cgi-bin[1].txt[/email]
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@cgi-bin[2].txt[/email]
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@cgi-bin[6].txt[/email]
Spyware:Cookie/360i Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@ct.360i[2].txt[/email]
Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@did-it[1].txt[/email]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@dist.belnk[2].txt[/email]
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@gostats[2].txt[/email]
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@go[1].txt[/email]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@image.checkmystats.com[2].txt[/email]
Spyware:Cookie/Research-int Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@research-int[1].txt[/email]
Spyware:Cookie/WebPower Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@webpower[1].txt[/email]
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@xiti[1].txt[/email]
Go to Start > Control Panel > Internet Options.
Under the General tab click the Delete Files... button; check the Delete all offline content box and press OK. Next, click the Delete Cookies... button and press OK
Go to "Start" -> "Run" and type in the box: "cleanmgr" press OK. Select the drive where your Operating System is installed (Default is C:) and press OK. Let Disk Cleanup scan your system for files to remove (it takes a few minutes!). On the next screen make sure these 3 options are checked
Trojan I must say when I first saw this site I was a little leery because so many sites say they can help but in fact things just get worse. NOT HERE. You sat there and helped not only me but I'm sure other ppl with their problems. Thank you for the help and patience. I'm going to be one very happy person now, and so will my wife because now she can play her pogo without the windows defender popping up in the middle of a game with the e2g worning. Once again Thank You Everything is clean now.
I'll definitely be sticking around. and as for the thread, we can close it. everything is back to normal so I'm not worried. Plus I have you guys incase something else happens. lol
Comments
You may want to print or save the following:
Please download Ewido to your Desktop or to your usual Download Folder.
http://www.ewido.net/en/download/
- Install Ewido by double clicking the installer.
- Follow the prompts. Make sure that Launch Ewido is checked.
- On the main screen under Your Computer's security.
- Click on Change state next to Resident shield. It should now change to inactive.
- Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
- Wait until you see the Update succesfull message.
- Click on Update on the toolbar.
- Under Manual update, click on the Start Update button.
- Wait until you see the Update succesfull message.
- Right-click the Ewido Tray Icon and select Exit. Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update ewido.Note: If the Update now option is grayed out, follow the steps below.
Ewido manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that Ewido is closed before installing the update.
Now go back into Safe Mode:
Once in Safe Mode, remove the following HJT entries:
O2 - BHO: CControl Object - {3643ABC2-21BF-46B9-B230-F247DB0C6FD6} - C:\Program Files\E2G\IeBHOs.dll (file missing)
O20 - AppInit_DLLs: inicfg32.dll
Still in Safe Mode
View hidden files and folders:
Next, find and delete the following:
C:\Program Files\E2G << this folder
C:\WINDOWS\system32\inicfg32.dll << this file
=====
Close ALL open Windows / Programs / Folders. Please start Ewido and run a full scan.
- Click on Scanner on the toolbar.
- Click on the Settings tab.
- Under How to act?
- Click on Recommended Action and choose Quarantine from the popup menu.
- Under How to scan?
- All checkboxes should be ticked.
- Under Possibly unwanted software:
- All checkboxes should be ticked.
- Under Reports:
- Select Automatically generate report after every scan and uncheck Only if threats were found.
- Under What to scan?
- Select Scan every file.
- Click on the Scan tab.
- Click on Complete System Scan to start the scan process.
- Let the program scan the machine.
- When the scan has finished, follow the instructions below.
- Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
- At the bottom of the window click on the Apply all Actions button. (3)

- When done, click the Save Scan Report button.
- Click the Save Report as button.
- Save the report to your Desktop.
- Right-click the Ewido Tray Icon and select Exit. Confirm by clicking Yes.
Reboot into Normal Mode, and post a new HJT log, along with the Ewido log.IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
ewido anti-spyware - Scan Report
+ Created at: 2:19:49 PM 07/26/2006
+ Scan result:
C:\Documents and Settings\Tami Sloss\Local Settings\Temp\180131F.tmp -> Adware.180Solutions : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Local Settings\Temp\180B.tmp -> Adware.180Solutions : Cleaned with backup (quarantined).
C:\Program Files\BearShare\BearShareZangoInstaller.exe/clientax.dll -> Adware.180Solutions : Error during cleaning.
C:\WINDOWS\Downloaded Program Files\ClientAX.dll -> Adware.180Solutions : Cleaned with backup (quarantined).
HKU\S-1-5-21-1060284298-1336601894-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{56F1D444-11BF-4879-A12B-79CF0177F038} -> Adware.180Solutions : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\IeBHOs.Control -> Adware.E2G : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\IeBHOs.Control.1 -> Adware.E2G : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\IeBHOs.Control\CLSID -> Adware.E2G : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\IeBHOs.Control\CurVer -> Adware.E2G : Cleaned with backup (quarantined).
C:\!KillBox\inicfg32.dll -> Adware.E2give : Cleaned with backup (quarantined).
C:\!KillBox\inicfg32.dll( 1) -> Adware.E2give : Cleaned with backup (quarantined).
C:\WINDOWS\system32\inicfg32.dll -> Adware.E2give : Error during cleaning.
[1176] C:\WINDOWS\system32\inicfg32.dll -> Adware.E2give : Error during cleaning.
[792] C:\WINDOWS\system32\inicfg32.dll -> Adware.E2give : Error during cleaning.
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE_tobedeleted -> Adware.Websearch : Cleaned with backup (quarantined).
C:\Program Files\Mozilla Firefox\plugins\npclntax.dll -> Adware.Zango : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Local Settings\Temporary Internet Files\Content.IE5\03ZBEOXT\popup[1].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Local Settings\Temporary Internet Files\Content.IE5\L2W6V9TS\popup[1].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Local Settings\Temporary Internet Files\Content.IE5\LKWNTX4H\popup[1].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\popcaploader.dll -> Not-A-Virus.Downloader.Win32.PopCap.b : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\USDR6_0001_D09M0706NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\USDR6_0001_D17M1107NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Local Settings\Temporary Internet Files\Content.IE5\TUZ9XY8I\ll.easyweepa[1].htm -> Not-A-Virus.Exploit.HTML.Mht : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@aavalue[2].txt[/email] -> TrackingCookie.Aavalue : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@paidmarketingpanel.aavalue[1].txt[/email] -> TrackingCookie.Aavalue : Cleaned with backup (quarantined).
:mozilla.128:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\6qdxr283.Default User\cookies.txt -> TrackingCookie.Abcsearch : Cleaned with backup (quarantined).
:mozilla.129:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\6qdxr283.Default User\cookies.txt -> TrackingCookie.Abcsearch : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@rotator.dex.adjuggler[2].txt[/email] -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@thunderbolt.adjuggler[2].txt[/email] -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@www.burstbeacon[1].txt[/email] -> TrackingCookie.Burstbeacon : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@www.burstbeacon[1].txt[/email] -> TrackingCookie.Burstbeacon : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@burstnet[1].txt[/email] -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@www.burstnet[1].txt[/email] -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@burstnet[1].txt[/email] -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@www.burstnet[2].txt[/email] -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.160:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\6qdxr283.Default User\cookies.txt -> TrackingCookie.Clickbank : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@clickbank[1].txt[/email] -> TrackingCookie.Clickbank : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@com[1].txt[/email] -> TrackingCookie.Com : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@com[1].txt[/email] -> TrackingCookie.Com : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@cpvfeed[2].txt[/email] -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined).
:mozilla.165:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\6qdxr283.Default User\cookies.txt -> TrackingCookie.Enhance : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@c.enhance[2].txt[/email] -> TrackingCookie.Enhance : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@c.enhance[2].txt[/email] -> TrackingCookie.Enhance : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@estat[1].txt[/email] -> TrackingCookie.Estat : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@adopt.euroclick[2].txt[/email] -> TrackingCookie.Euroclick : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@adopt.euroclick[2].txt[/email] -> TrackingCookie.Euroclick : Cleaned with backup (quarantined).
:mozilla.235:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\6qdxr283.Default User\cookies.txt -> TrackingCookie.Goclick : Cleaned with backup (quarantined).
:mozilla.236:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\6qdxr283.Default User\cookies.txt -> TrackingCookie.Goclick : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@ilead.itrack[1].txt[/email] -> TrackingCookie.Itrack : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@komtrack[2].txt[/email] -> TrackingCookie.Komtrack : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@sales.liveperson[1].txt[/email] -> TrackingCookie.Liveperson : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@image.masterstats[2].txt[/email] -> TrackingCookie.Masterstats : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@www.myaffiliateprogram[2].txt[/email] -> TrackingCookie.Myaffiliateprogram : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@www.myaffiliateprogram[1].txt[/email] -> TrackingCookie.Myaffiliateprogram : Cleaned with backup (quarantined).
:mozilla.349:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\l29xgpih.default\cookies.txt -> TrackingCookie.Realcastmedia : Cleaned with backup (quarantined).
:mozilla.350:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\l29xgpih.default\cookies.txt -> TrackingCookie.Realcastmedia : Cleaned with backup (quarantined).
:mozilla.351:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\l29xgpih.default\cookies.txt -> TrackingCookie.Realcastmedia : Cleaned with backup (quarantined).
:mozilla.352:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\l29xgpih.default\cookies.txt -> TrackingCookie.Realcastmedia : Cleaned with backup (quarantined).
:mozilla.353:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\l29xgpih.default\cookies.txt -> TrackingCookie.Realcastmedia : Cleaned with backup (quarantined).
:mozilla.354:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\l29xgpih.default\cookies.txt -> TrackingCookie.Realcastmedia : Cleaned with backup (quarantined).
:mozilla.355:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\l29xgpih.default\cookies.txt -> TrackingCookie.Realcastmedia : Cleaned with backup (quarantined).
:mozilla.356:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\l29xgpih.default\cookies.txt -> TrackingCookie.Realcastmedia : Cleaned with backup (quarantined).
:mozilla.357:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\l29xgpih.default\cookies.txt -> TrackingCookie.Realcastmedia : Cleaned with backup (quarantined).
:mozilla.358:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\l29xgpih.default\cookies.txt -> TrackingCookie.Realcastmedia : Cleaned with backup (quarantined).
:mozilla.359:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\l29xgpih.default\cookies.txt -> TrackingCookie.Realcastmedia : Cleaned with backup (quarantined).
:mozilla.360:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\l29xgpih.default\cookies.txt -> TrackingCookie.Realcastmedia : Cleaned with backup (quarantined).
:mozilla.361:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\l29xgpih.default\cookies.txt -> TrackingCookie.Realcastmedia : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@ads.realcastmedia[2].txt[/email] -> TrackingCookie.Realcastmedia : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@stats1.reliablestats[1].txt[/email] -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@stats1.reliablestats[2].txt[/email] -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
:mozilla.255:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\l29xgpih.default\cookies.txt -> TrackingCookie.Starware : Cleaned with backup (quarantined).
:mozilla.256:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\l29xgpih.default\cookies.txt -> TrackingCookie.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@h.starware[2].txt[/email] -> TrackingCookie.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@h.starware[2].txt[/email] -> TrackingCookie.Starware : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@statcounter[1].txt[/email] -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.187:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\6qdxr283.Default User\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.188:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\6qdxr283.Default User\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@anad.tacoda[1].txt[/email] -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@anat.tacoda[1].txt[/email] -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@tacoda[1].txt[/email] -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@anad.tacoda[1].txt[/email] -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@anat.tacoda[2].txt[/email] -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@tacoda[1].txt[/email] -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@login.tracking101[1].txt[/email] -> TrackingCookie.Tracking101 : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@login.tracking101[1].txt[/email] -> TrackingCookie.Tracking101 : Cleaned with backup (quarantined).
:mozilla.199:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\l29xgpih.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@webstat[2].txt[/email] -> TrackingCookie.Web-stat : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@weborama[2].txt[/email] -> TrackingCookie.Weborama : Cleaned with backup (quarantined).
:mozilla.494:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\l29xgpih.default\cookies.txt -> TrackingCookie.Yadro : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@yadro[2].txt[/email] -> TrackingCookie.Yadro : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@yadro[1].txt[/email] -> TrackingCookie.Yadro : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@ad.yieldmanager[1].txt[/email] -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@yieldmanager[1].txt[/email] -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@ad.yieldmanager[2].txt[/email] -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@yieldmanager[1].txt[/email] -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.51:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\6qdxr283.Default User\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.52:C:\Documents and Settings\Tami Sloss\Application Data\Mozilla\Firefox\Profiles\6qdxr283.Default User\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
::Report end
Logfile of HijackThis v1.99.1
Scan saved at 2:25:04 PM, on 07/26/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Common Files\KTTC Desktop Alert\TrueWeather.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: CControl Object - {3643ABC2-21BF-46B9-B230-F247DB0C6FD6} - C:\Program Files\E2G\IeBHOs.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Lexmark X83 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
O4 - HKLM\..\Run: [Lexmark X83 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [eTrustPPAP] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust PestPatrol Anti-Spyware\PPActiveDetection.exe"
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL,S
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KTTC Desktop Alert.lnk = C:\Program Files\Common Files\KTTC Desktop Alert\TrueWeather.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZN
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [CDNCLIENT] Chinese Navigation
O16 - DPF: 6th Street Omaha Poker by pogo - http://game1.pogo.com/applet-6.6.4.21/omaha/omaha-en_US.cab
O16 - DPF: Aces Up! by pogo - http://game1.pogo.com/applet-6.6.5.22/aces/aces-en_US.cab
O16 - DPF: Backgammon by pogo - http://game1.pogo.com/applet-6.6.5.22/backgammon/backgammon-en_US.cab
O16 - DPF: Battle Phlinx by pogo - http://game1.pogo.com/applet-6.6.5.31/battlephlinx/battlephlinx-en_US.cab
O16 - DPF: Blackjack by pogo - http://game1.pogo.com/applet-6.6.0.34/blackjack/blackjack-en_US.cab
O16 - DPF: Blooop by pogo - http://game1.pogo.com/applet-6.6.5.31/cascade/cascade-en_US.cab
O16 - DPF: Bowling by pogo - http://game1.pogo.com/applet-6.7.0.40/bowling/bowling-en_US.cab
O16 - DPF: Canasta by pogo - http://game1.pogo.com/applet-6.6.5.31/canasta/canasta-en_US.cab
O16 - DPF: Checkers by pogo - http://game1.pogo.com/applet-6.5.3.44/checkers2/checkers-en_US.cab
O16 - DPF: Dice City Roller by pogo - http://game1.pogo.com/applet-6.7.1.23/ytz/ytz-en_US.cab
O16 - DPF: Dice Derby by pogo - http://game1.pogo.com/applet-6.6.2.21/checkeredflag/checkeredflag-en_US.cab
O16 - DPF: Euchre by pogo - http://game1.pogo.com/applet-6.5.2.26/euchre/euchre-en_US.cab
O16 - DPF: First Class Solitaire by pogo - http://game1.pogo.com/applet-6.6.0.34/firstclass2/firstclass2-en_US.cab
O16 - DPF: Fortune Bingo by pogo - http://game1.pogo.com/applet-6.6.5.31/superbingo/superbingo-en_US.cab
O16 - DPF: Greenback Bayou by pogo - http://game1.pogo.com/applet-6.6.5.22/greenback/greenback-en_US.cab
O16 - DPF: Harvest Mania by pogo - http://game1.pogo.com/applet-6.6.3.34/harvest/harvest-en_US.cab
O16 - DPF: Hearts by pogo - http://game1.pogo.com/applet-6.6.4.29/hearts/hearts-en_US.cab
O16 - DPF: High Stakes Poker by pogo - http://game1.pogo.com/applet-6.5.4.27/drawpoker/drawpoker-en_US.cab
O16 - DPF: Jigsaw Detective by pogo - http://game1.pogo.com/applet-6.7.0.40/jigsaw/jigsaw-en_US.cab
O16 - DPF: Jungle Gin by pogo - http://game1.pogo.com/applet-6.5.2.33/gin/gin-en_US.cab
O16 - DPF: Lost Temple Poker by pogo - http://game1.pogo.com/applet-6.6.5.31/mhpoker/mhpoker-en_US.cab
O16 - DPF: Lottso by pogo - http://game1.pogo.com/applet-6.7.0.32/lottso/lottso-en_US.cab
O16 - DPF: Mah Jong Garden by pogo - http://game1.pogo.com/applet-6.6.5.31/mahjong/mahjong-en_US.cab
O16 - DPF: Multiline Slots by pogo - http://game1.pogo.com/applet-6.3.3.27/mlslots/mlslots-ob-assets.cab
O16 - DPF: Pai Gow by pogo - http://game1.pogo.com/applet-6.6.5.31/paigow/paigow-en_US.cab
O16 - DPF: Payday FreeCell by pogo - http://game1.pogo.com/applet-6.5.0.45/freecell/freecell-ob-assets.cab
O16 - DPF: Penguin Blocks by pogo - http://game1.pogo.com/applet-6.5.1.31/penguins/penguins-en_US.cab
O16 - DPF: Phlinx by pogo - http://game1.pogo.com/applet-6.7.0.32/flinger/flinger-en_US.cab
O16 - DPF: Pinochle by pogo - http://game1.pogo.com/applet-6.6.3.34/pinochle/pinochle-en_US.cab
O16 - DPF: Pirate's Gold by pogo - http://game1.pogo.com/applet-6.7.0.32/piratesgold/piratesgold-en_US.cab
O16 - DPF: Pop Fu by pogo - http://game1.pogo.com/applet-6.6.5.22/popfu/popfu-en_US.cab
O16 - DPF: PoppaZoppa by pogo - http://game1.pogo.com/applet-6.6.0.27/poppazoppa/poppazoppa-en_US.cab
O16 - DPF: Poppit by pogo - http://game1.pogo.com/applet-6.7.0.40/poppit2/poppit2-en_US.cab
O16 - DPF: Quick Quack by pogo - http://game1.pogo.com/applet-6.6.0.27/hotstreak/hotstreak-en_US.cab
O16 - DPF: QWERTY by pogo - http://game1.pogo.com/applet-6.6.2.35/squares/squares-en_US.cab
O16 - DPF: Ride The Tide by pogo - http://game1.pogo.com/applet-6.5.3.44/ride/ride-en_US.cab
O16 - DPF: Showbiz Slots 2 by pogo - http://game1.pogo.com/applet-6.6.1.29/slots/showbiz2-en_US.cab
O16 - DPF: Shuffle Bump by pogo - http://game1.pogo.com/applet-6.7.0.32/puck/puck-en_US.cab
O16 - DPF: Spades 2 by pogo - http://game1.pogo.com/applet-6.6.1.29/spades2/spades2-en_US.cab
O16 - DPF: Spades by pogo - http://game1.pogo.com/applet-6.5.0.45/spades/spades-ob-assets.cab
O16 - DPF: Spider Solitaire by pogo - http://game1.pogo.com/applet-6.6.2.21/spider/spider-en_US.cab
O16 - DPF: Squelchies by pogo - http://game1.pogo.com/applet-6.6.4.21/squelchies/squelchies-en_US.cab
O16 - DPF: Sweet Tooth TM by pogo - http://game1.pogo.com/applet-6.6.2.35/sweettooth/sweettooth-en_US.cab
O16 - DPF: Texas Hold'em Poker by pogo - http://game1.pogo.com/applet-6.6.5.31/holdem/holdem-en_US.cab
O16 - DPF: Tri-Peaks by pogo - http://game1.pogo.com/applet-6.7.0.32/peaks/peaks-en_US.cab
O16 - DPF: Tumble Bees by pogo - http://game1.pogo.com/applet-6.6.5.31/jumbee/jumbee-en_US.cab
O16 - DPF: Wonderland Memories by pogo - http://game1.pogo.com/applet-6.5.3.37/memories/memories-en_US.cab
O16 - DPF: Word Whomp by pogo - http://game1.pogo.com/applet-6.6.2.21/wordwhomp2/whomp2-en_US.cab
O16 - DPF: WordJong by pogo - http://game1.pogo.com/applet-6.7.0.40/wordjong/wordjong-en_US.cab
O16 - DPF: World Class Solitaire by pogo - http://game1.pogo.com/applet-6.7.0.32/worldclass/worldclass-en_US.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (AlternaTIFF ActiveX) - http://www.alternatiff.com/install/00/alttiff.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://groups.msn.com/controls/PhotoUC/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1103826001202
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
O16 - DPF: {94EB57FE-2720-496C-B33F-D9353C6E23F7} (F-Secure Online Scanner 2.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://www.sonypictures.com/games/gamehouse/SproutLauncher.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.popcap.com/games/popcaploader_v6.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O18 - Protocol: bw+0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O20 - AppInit_DLLs: inicfg32.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: FAH@C:+Documents and Settings+Tami Sloss+Local Settings+Temporary Internet Files+Content.IE5+03ZBEOXT+FAH504-Console[1].exe - Unknown owner - C:\Documents and Settings\Tami Sloss\Local Settings\Temporary Internet Files\Content.IE5\03ZBEOXT\FAH504-Console[1].exe (file missing)
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
Removed! C:\WINDOWS\system32\inicfg32.dll
Removed orphaned leftovers
AppInit key reset
OK, can you post a new HijackThis log please, along with an Uninstall list.
Ad-Aware SE Personal
Adobe Reader 7.0
Avant Browser (remove only)
BearShare
CCScore
Crazy Browser version 2.0.1
Demolition Derby & Figure 8 Race
ESSCDBK
ESScore
ESSgui
ESShelp
ESSini
ESSPCD
ESSSONIC
ESSTOOLS
ESSvpaht
ESSvpot
ewido anti-spyware 4.0
Google Toolbar for Internet Explorer
Hijackthis 1.99.1
HijackThis 1.99.1
HLPIndex
HLPRFO
J2SE Runtime Environment 5.0 Update 6
Java 2 Runtime Environment, SE v1.4.2_12
Kodak EasyShare software
KTTC Desktop Alert
Lexmark X83
LimeWire
Logitech Print Service
Logitech QuickCam Software
Logitech® Camera Driver
Macromedia Flash Player 8
Macromedia Shockwave Player
Microsoft Office XP Small Business
Mozilla Firefox (1.0.4)
MSN Messenger 7.0
MSN Music Assistant
Mystery Case Files - Huntsville
Mystery Case Files - Prime Suspects
Notifier
NVIDIA Display Driver
OTtBPSDK
PCDADDIN
PCDHELP
Pop-Up Stopper Free Edition
RenGuard
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918439)
SFR
SHASTA
SKIN0001
SKINXSDK
Spybot - Search & Destroy 1.3
SpywareBlaster v3.5.1
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
VPRINTOL
Windows Defender Signatures
Windows Genuine Advantage v1.3.0254.0
Windows Installer 3.1 (KB893803)
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB834707
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
WIRELESS
Yahoo! Messenger
and HJT log
Logfile of HijackThis v1.99.1
Scan saved at 2:40:20 PM, on 07/26/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Common Files\KTTC Desktop Alert\TrueWeather.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Lexmark X83 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
O4 - HKLM\..\Run: [Lexmark X83 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [eTrustPPAP] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust PestPatrol Anti-Spyware\PPActiveDetection.exe"
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL,S
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KTTC Desktop Alert.lnk = C:\Program Files\Common Files\KTTC Desktop Alert\TrueWeather.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZN
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [CDNCLIENT] Chinese Navigation
O16 - DPF: 6th Street Omaha Poker by pogo - http://game1.pogo.com/applet-6.6.4.21/omaha/omaha-en_US.cab
O16 - DPF: Aces Up! by pogo - http://game1.pogo.com/applet-6.6.5.22/aces/aces-en_US.cab
O16 - DPF: Backgammon by pogo - http://game1.pogo.com/applet-6.6.5.22/backgammon/backgammon-en_US.cab
O16 - DPF: Battle Phlinx by pogo - http://game1.pogo.com/applet-6.6.5.31/battlephlinx/battlephlinx-en_US.cab
O16 - DPF: Blackjack by pogo - http://game1.pogo.com/applet-6.6.0.34/blackjack/blackjack-en_US.cab
O16 - DPF: Blooop by pogo - http://game1.pogo.com/applet-6.6.5.31/cascade/cascade-en_US.cab
O16 - DPF: Bowling by pogo - http://game1.pogo.com/applet-6.7.0.40/bowling/bowling-en_US.cab
O16 - DPF: Canasta by pogo - http://game1.pogo.com/applet-6.6.5.31/canasta/canasta-en_US.cab
O16 - DPF: Checkers by pogo - http://game1.pogo.com/applet-6.5.3.44/checkers2/checkers-en_US.cab
O16 - DPF: Dice City Roller by pogo - http://game1.pogo.com/applet-6.7.1.23/ytz/ytz-en_US.cab
O16 - DPF: Dice Derby by pogo - http://game1.pogo.com/applet-6.6.2.21/checkeredflag/checkeredflag-en_US.cab
O16 - DPF: Euchre by pogo - http://game1.pogo.com/applet-6.5.2.26/euchre/euchre-en_US.cab
O16 - DPF: First Class Solitaire by pogo - http://game1.pogo.com/applet-6.6.0.34/firstclass2/firstclass2-en_US.cab
O16 - DPF: Fortune Bingo by pogo - http://game1.pogo.com/applet-6.6.5.31/superbingo/superbingo-en_US.cab
O16 - DPF: Greenback Bayou by pogo - http://game1.pogo.com/applet-6.6.5.22/greenback/greenback-en_US.cab
O16 - DPF: Harvest Mania by pogo - http://game1.pogo.com/applet-6.6.3.34/harvest/harvest-en_US.cab
O16 - DPF: Hearts by pogo - http://game1.pogo.com/applet-6.6.4.29/hearts/hearts-en_US.cab
O16 - DPF: High Stakes Poker by pogo - http://game1.pogo.com/applet-6.5.4.27/drawpoker/drawpoker-en_US.cab
O16 - DPF: Jigsaw Detective by pogo - http://game1.pogo.com/applet-6.7.0.40/jigsaw/jigsaw-en_US.cab
O16 - DPF: Jungle Gin by pogo - http://game1.pogo.com/applet-6.5.2.33/gin/gin-en_US.cab
O16 - DPF: Lost Temple Poker by pogo - http://game1.pogo.com/applet-6.6.5.31/mhpoker/mhpoker-en_US.cab
O16 - DPF: Lottso by pogo - http://game1.pogo.com/applet-6.7.0.32/lottso/lottso-en_US.cab
O16 - DPF: Mah Jong Garden by pogo - http://game1.pogo.com/applet-6.6.5.31/mahjong/mahjong-en_US.cab
O16 - DPF: Multiline Slots by pogo - http://game1.pogo.com/applet-6.3.3.27/mlslots/mlslots-ob-assets.cab
O16 - DPF: Pai Gow by pogo - http://game1.pogo.com/applet-6.6.5.31/paigow/paigow-en_US.cab
O16 - DPF: Payday FreeCell by pogo - http://game1.pogo.com/applet-6.5.0.45/freecell/freecell-ob-assets.cab
O16 - DPF: Penguin Blocks by pogo - http://game1.pogo.com/applet-6.5.1.31/penguins/penguins-en_US.cab
O16 - DPF: Phlinx by pogo - http://game1.pogo.com/applet-6.7.0.32/flinger/flinger-en_US.cab
O16 - DPF: Pinochle by pogo - http://game1.pogo.com/applet-6.6.3.34/pinochle/pinochle-en_US.cab
O16 - DPF: Pirate's Gold by pogo - http://game1.pogo.com/applet-6.7.0.32/piratesgold/piratesgold-en_US.cab
O16 - DPF: Pop Fu by pogo - http://game1.pogo.com/applet-6.6.5.22/popfu/popfu-en_US.cab
O16 - DPF: PoppaZoppa by pogo - http://game1.pogo.com/applet-6.6.0.27/poppazoppa/poppazoppa-en_US.cab
O16 - DPF: Poppit by pogo - http://game1.pogo.com/applet-6.7.0.40/poppit2/poppit2-en_US.cab
O16 - DPF: Quick Quack by pogo - http://game1.pogo.com/applet-6.6.0.27/hotstreak/hotstreak-en_US.cab
O16 - DPF: QWERTY by pogo - http://game1.pogo.com/applet-6.6.2.35/squares/squares-en_US.cab
O16 - DPF: Ride The Tide by pogo - http://game1.pogo.com/applet-6.5.3.44/ride/ride-en_US.cab
O16 - DPF: Showbiz Slots 2 by pogo - http://game1.pogo.com/applet-6.6.1.29/slots/showbiz2-en_US.cab
O16 - DPF: Shuffle Bump by pogo - http://game1.pogo.com/applet-6.7.0.32/puck/puck-en_US.cab
O16 - DPF: Spades 2 by pogo - http://game1.pogo.com/applet-6.6.1.29/spades2/spades2-en_US.cab
O16 - DPF: Spades by pogo - http://game1.pogo.com/applet-6.5.0.45/spades/spades-ob-assets.cab
O16 - DPF: Spider Solitaire by pogo - http://game1.pogo.com/applet-6.6.2.21/spider/spider-en_US.cab
O16 - DPF: Squelchies by pogo - http://game1.pogo.com/applet-6.6.4.21/squelchies/squelchies-en_US.cab
O16 - DPF: Sweet Tooth TM by pogo - http://game1.pogo.com/applet-6.6.2.35/sweettooth/sweettooth-en_US.cab
O16 - DPF: Texas Hold'em Poker by pogo - http://game1.pogo.com/applet-6.6.5.31/holdem/holdem-en_US.cab
O16 - DPF: Tri-Peaks by pogo - http://game1.pogo.com/applet-6.7.0.32/peaks/peaks-en_US.cab
O16 - DPF: Tumble Bees by pogo - http://game1.pogo.com/applet-6.6.5.31/jumbee/jumbee-en_US.cab
O16 - DPF: Wonderland Memories by pogo - http://game1.pogo.com/applet-6.5.3.37/memories/memories-en_US.cab
O16 - DPF: Word Whomp by pogo - http://game1.pogo.com/applet-6.6.2.21/wordwhomp2/whomp2-en_US.cab
O16 - DPF: WordJong by pogo - http://game1.pogo.com/applet-6.7.0.40/wordjong/wordjong-en_US.cab
O16 - DPF: World Class Solitaire by pogo - http://game1.pogo.com/applet-6.7.0.32/worldclass/worldclass-en_US.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (AlternaTIFF ActiveX) - http://www.alternatiff.com/install/00/alttiff.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://groups.msn.com/controls/PhotoUC/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1103826001202
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
O16 - DPF: {94EB57FE-2720-496C-B33F-D9353C6E23F7} (F-Secure Online Scanner 2.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://www.sonypictures.com/games/gamehouse/SproutLauncher.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.popcap.com/games/popcaploader_v6.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O18 - Protocol: bw+0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: FAH@C:+Documents and Settings+Tami Sloss+Local Settings+Temporary Internet Files+Content.IE5+03ZBEOXT+FAH504-Console[1].exe - Unknown owner - C:\Documents and Settings\Tami Sloss\Local Settings\Temporary Internet Files\Content.IE5\03ZBEOXT\FAH504-Console[1].exe (file missing)
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
Uninstall the following:
BearShare << Optional, but recommend its removal
LimeWire << Optional, but recommend its removal
J2SE Runtime Environment 5.0 Update 6
Java 2 Runtime Environment, SE v1.4.2_12
Spybot - Search & Destroy 1.3
Then:
Download the latest version of Java Runtime Environment, and install it to your computer.
Download the latest version of Spybot Search & Destroy 1.4 from here
=====
Open HijackThis
- Click the Do a system scan only button
- Check the following entries (below)
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL,S
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
- Close ALL open windows (especially Internet Explorer!)
Click Fix Checked
Delete the following folder:
C:\Program Files\MyWebSearch
=====
Please run this online scan:
Panda ActiveScan
- Once you are on the Panda site, click the Scan your PC button
- A new window will open...click the Check Now button
- Enter your Country
- Enter your State/Province
- Enter your e-mail address and click send
- Select either Home User or Company
- Click the big Scan Now button
- If it wants to install an ActiveX component allow it
- It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
- When download is complete, click on Local Disks to start the scan
- When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
Post the contents of the Panda scan report, along with a new HijackThis Log. Also, try running BlackLight again and post the log. it should work now.
Logfile of HijackThis v1.99.1
Scan saved at 3:21:57 PM, on 07/26/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Common Files\KTTC Desktop Alert\TrueWeather.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Lexmark X83 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
O4 - HKLM\..\Run: [Lexmark X83 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KTTC Desktop Alert.lnk = C:\Program Files\Common Files\KTTC Desktop Alert\TrueWeather.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZN
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [CDNCLIENT] Chinese Navigation
O16 - DPF: 6th Street Omaha Poker by pogo - http://game1.pogo.com/applet-6.6.4.21/omaha/omaha-en_US.cab
O16 - DPF: Aces Up! by pogo - http://game1.pogo.com/applet-6.6.5.22/aces/aces-en_US.cab
O16 - DPF: Backgammon by pogo - http://game1.pogo.com/applet-6.6.5.22/backgammon/backgammon-en_US.cab
O16 - DPF: Battle Phlinx by pogo - http://game1.pogo.com/applet-6.6.5.31/battlephlinx/battlephlinx-en_US.cab
O16 - DPF: Blackjack by pogo - http://game1.pogo.com/applet-6.6.0.34/blackjack/blackjack-en_US.cab
O16 - DPF: Blooop by pogo - http://game1.pogo.com/applet-6.6.5.31/cascade/cascade-en_US.cab
O16 - DPF: Bowling by pogo - http://game1.pogo.com/applet-6.7.0.40/bowling/bowling-en_US.cab
O16 - DPF: Canasta by pogo - http://game1.pogo.com/applet-6.6.5.31/canasta/canasta-en_US.cab
O16 - DPF: Checkers by pogo - http://game1.pogo.com/applet-6.5.3.44/checkers2/checkers-en_US.cab
O16 - DPF: Dice City Roller by pogo - http://game1.pogo.com/applet-6.7.1.23/ytz/ytz-en_US.cab
O16 - DPF: Dice Derby by pogo - http://game1.pogo.com/applet-6.6.2.21/checkeredflag/checkeredflag-en_US.cab
O16 - DPF: Euchre by pogo - http://game1.pogo.com/applet-6.5.2.26/euchre/euchre-en_US.cab
O16 - DPF: First Class Solitaire by pogo - http://game1.pogo.com/applet-6.6.0.34/firstclass2/firstclass2-en_US.cab
O16 - DPF: Fortune Bingo by pogo - http://game1.pogo.com/applet-6.6.5.31/superbingo/superbingo-en_US.cab
O16 - DPF: Greenback Bayou by pogo - http://game1.pogo.com/applet-6.6.5.22/greenback/greenback-en_US.cab
O16 - DPF: Harvest Mania by pogo - http://game1.pogo.com/applet-6.6.3.34/harvest/harvest-en_US.cab
O16 - DPF: Hearts by pogo - http://game1.pogo.com/applet-6.6.4.29/hearts/hearts-en_US.cab
O16 - DPF: High Stakes Poker by pogo - http://game1.pogo.com/applet-6.5.4.27/drawpoker/drawpoker-en_US.cab
O16 - DPF: Jigsaw Detective by pogo - http://game1.pogo.com/applet-6.7.0.40/jigsaw/jigsaw-en_US.cab
O16 - DPF: Jungle Gin by pogo - http://game1.pogo.com/applet-6.5.2.33/gin/gin-en_US.cab
O16 - DPF: Lost Temple Poker by pogo - http://game1.pogo.com/applet-6.6.5.31/mhpoker/mhpoker-en_US.cab
O16 - DPF: Lottso by pogo - http://game1.pogo.com/applet-6.7.0.32/lottso/lottso-en_US.cab
O16 - DPF: Mah Jong Garden by pogo - http://game1.pogo.com/applet-6.6.5.31/mahjong/mahjong-en_US.cab
O16 - DPF: Multiline Slots by pogo - http://game1.pogo.com/applet-6.3.3.27/mlslots/mlslots-ob-assets.cab
O16 - DPF: Pai Gow by pogo - http://game1.pogo.com/applet-6.6.5.31/paigow/paigow-en_US.cab
O16 - DPF: Payday FreeCell by pogo - http://game1.pogo.com/applet-6.5.0.45/freecell/freecell-ob-assets.cab
O16 - DPF: Penguin Blocks by pogo - http://game1.pogo.com/applet-6.5.1.31/penguins/penguins-en_US.cab
O16 - DPF: Phlinx by pogo - http://game1.pogo.com/applet-6.7.0.32/flinger/flinger-en_US.cab
O16 - DPF: Pinochle by pogo - http://game1.pogo.com/applet-6.6.3.34/pinochle/pinochle-en_US.cab
O16 - DPF: Pirate's Gold by pogo - http://game1.pogo.com/applet-6.7.0.32/piratesgold/piratesgold-en_US.cab
O16 - DPF: Pop Fu by pogo - http://game1.pogo.com/applet-6.6.5.22/popfu/popfu-en_US.cab
O16 - DPF: PoppaZoppa by pogo - http://game1.pogo.com/applet-6.6.0.27/poppazoppa/poppazoppa-en_US.cab
O16 - DPF: Poppit by pogo - http://game1.pogo.com/applet-6.7.0.40/poppit2/poppit2-en_US.cab
O16 - DPF: Quick Quack by pogo - http://game1.pogo.com/applet-6.6.0.27/hotstreak/hotstreak-en_US.cab
O16 - DPF: QWERTY by pogo - http://game1.pogo.com/applet-6.6.2.35/squares/squares-en_US.cab
O16 - DPF: Ride The Tide by pogo - http://game1.pogo.com/applet-6.5.3.44/ride/ride-en_US.cab
O16 - DPF: Showbiz Slots 2 by pogo - http://game1.pogo.com/applet-6.6.1.29/slots/showbiz2-en_US.cab
O16 - DPF: Shuffle Bump by pogo - http://game1.pogo.com/applet-6.7.0.32/puck/puck-en_US.cab
O16 - DPF: Spades 2 by pogo - http://game1.pogo.com/applet-6.6.1.29/spades2/spades2-en_US.cab
O16 - DPF: Spades by pogo - http://game1.pogo.com/applet-6.5.0.45/spades/spades-ob-assets.cab
O16 - DPF: Spider Solitaire by pogo - http://game1.pogo.com/applet-6.6.2.21/spider/spider-en_US.cab
O16 - DPF: Squelchies by pogo - http://game1.pogo.com/applet-6.6.4.21/squelchies/squelchies-en_US.cab
O16 - DPF: Sweet Tooth TM by pogo - http://game1.pogo.com/applet-6.6.2.35/sweettooth/sweettooth-en_US.cab
O16 - DPF: Texas Hold'em Poker by pogo - http://game1.pogo.com/applet-6.6.5.31/holdem/holdem-en_US.cab
O16 - DPF: Tri-Peaks by pogo - http://game1.pogo.com/applet-6.7.0.32/peaks/peaks-en_US.cab
O16 - DPF: Tumble Bees by pogo - http://game1.pogo.com/applet-6.6.5.31/jumbee/jumbee-en_US.cab
O16 - DPF: Wonderland Memories by pogo - http://game1.pogo.com/applet-6.5.3.37/memories/memories-en_US.cab
O16 - DPF: Word Whomp by pogo - http://game1.pogo.com/applet-6.6.2.21/wordwhomp2/whomp2-en_US.cab
O16 - DPF: WordJong by pogo - http://game1.pogo.com/applet-6.7.0.40/wordjong/wordjong-en_US.cab
O16 - DPF: World Class Solitaire by pogo - http://game1.pogo.com/applet-6.7.0.32/worldclass/worldclass-en_US.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (AlternaTIFF ActiveX) - http://www.alternatiff.com/install/00/alttiff.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://groups.msn.com/controls/PhotoUC/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1103826001202
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
O16 - DPF: {94EB57FE-2720-496C-B33F-D9353C6E23F7} (F-Secure Online Scanner 2.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://www.sonypictures.com/games/gamehouse/SproutLauncher.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.popcap.com/games/popcaploader_v6.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O18 - Protocol: bw+0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {911E590D-080B-4DD3-8B48-EED31C7F756A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: FAH@C:+Documents and Settings+Tami Sloss+Local Settings+Temporary Internet Files+Content.IE5+03ZBEOXT+FAH504-Console[1].exe - Unknown owner - C:\Documents and Settings\Tami Sloss\Local Settings\Temporary Internet Files\Content.IE5\03ZBEOXT\FAH504-Console[1].exe (file missing)
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
and the Panda log
Incident Status Location
Spyware:Cookie/64.62.232 Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@64.62.232[4].txt[/email]
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@888[1].txt[/email]
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@888[2].txt[/email]
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@adopt.hbmediapro[1].txt[/email]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@atwola[2].txt[/email]
Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@azjmp[2].txt[/email]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@bannerlandia.com[1].txt[/email]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@belnk[1].txt[/email]
Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@bravenet[1].txt[/email]
Spyware:Cookie/Cassava Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@cassava[1].txt[/email]
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@cgi-bin[3].txt[/email]
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@cgi-bin[6].txt[/email]
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@cgi-bin[7].txt[/email]
Spyware:Cookie/360i Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@ct.360i[1].txt[/email]
Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@did-it[1].txt[/email]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@dist.belnk[2].txt[/email]
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@errorsafe[2].txt[/email]
Spyware:Cookie/fe.lea.lycos Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@fe.lea.lycos[1].txt[/email]
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@gostats[1].txt[/email]
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@go[1].txt[/email]
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@go[2].txt[/email]
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@go[4].txt[/email]
Spyware:Cookie/Screensavers Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@i.screensavers[1].txt[/email]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@image.checkmystats.com[2].txt[/email]
Spyware:Cookie/DomainSponsor Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@landing.domainsponsor[1].txt[/email]
Spyware:Cookie/OfferOptimizer Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@offeroptimizer[2].txt[/email]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@realmedia[1].txt[/email]
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@searchportal.information[2].txt[/email]
Spyware:Cookie/Target Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@target[2].txt[/email]
Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@toplist[1].txt[/email]
Spyware:Cookie/WebPower Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@webpower[2].txt[/email]
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@www.errorsafe[2].txt[/email]
Spyware:Cookie/myaffiliateprogram Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@www.myaffiliateprogram[1].txt[/email]
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Tami Sloss\Cookies\tami [email]sloss@xiti[1].txt[/email]
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@adopt.hbmediapro[1].txt[/email]
Spyware:Cookie/NewMedia Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@anm.co[2].txt[/email]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@atwola[1].txt[/email]
Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@azjmp[1].txt[/email]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@belnk[1].txt[/email]
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@cgi-bin[1].txt[/email]
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@cgi-bin[2].txt[/email]
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@cgi-bin[6].txt[/email]
Spyware:Cookie/360i Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@ct.360i[2].txt[/email]
Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@did-it[1].txt[/email]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@dist.belnk[2].txt[/email]
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@gostats[2].txt[/email]
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@go[1].txt[/email]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@image.checkmystats.com[2].txt[/email]
Spyware:Cookie/Research-int Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@research-int[1].txt[/email]
Spyware:Cookie/WebPower Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@webpower[1].txt[/email]
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Tami Sloss\Local Settings\Temp\Cookies\tami [email]sloss@xiti[1].txt[/email]
Under the General tab click the Delete Files... button; check the Delete all offline content box and press OK. Next, click the Delete Cookies... button and press OK
Go to "Start" -> "Run" and type in the box: "cleanmgr" press OK. Select the drive where your Operating System is installed (Default is C:) and press OK. Let Disk Cleanup scan your system for files to remove (it takes a few minutes!). On the next screen make sure these 3 options are checked
- Temporary Files
- Temporary Internet Files
- Recycle Bin
and then press "OK" to remove.=====
Your HijackThis log is clean.
Let me know how things are now.
Glad you've joined Team93. Hope you'll be sticking around.
Let me know if we can mark this resolved?
I'l mark this resolved!