I get the 404 errors as well as DNS and others at random sites. I can't remember if they are sites that I frequent cause I do a LOT of surfing, and when I do encounter a site that has links to these Not Found pages I usually don't go back to them. The only I can remember going back to several times with the same results is a link from this site...
http://www.spywareremove.com/products.shtml
and this the link...
http://www.justrealmail.com/affiliat...=4&productid=2
I did everything as you suggested, except Norton Antivirus won't run in safe mode. Maybe it's because its part of NIS???
Anyway here are the logs you requested...
Ewido ( it's not called Anti Malware anymore, it's Anti Spyware and it's not free anymore...30 day trial. Just thought I'd let you know. Who cares, right. As long as it works)...
If you would rather read them without them being all scrunched up I'm sending them as attachments also, so you can open them up in notepad with out them being word wrapped.
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 2:59:02 AM 7/1/2006
+ Scan result:
C:\Program Files\180search assistant -> Adware.180Solutions : Cleaned with backup (quarantined).
C:\Program Files\180searchassistant -> Adware.180Solutions : Cleaned with backup (quarantined).
C:\Program Files\instafink -> Adware.404Search : Cleaned with backup (quarantined).
C:\Program Files\altnet -> Adware.Altnet : Cleaned with backup (quarantined).
C:\Program Files\aprps -> Adware.Apropos : Cleaned with backup (quarantined).
C:\Program Files\autoupdate -> Adware.Apropos : Cleaned with backup (quarantined).
C:\Program Files\cxtpls -> Adware.Apropos : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\ZToolbar.ParamWr -> Adware.Azsearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\ZToolbar.ParamWr.1 -> Adware.Azsearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\ZToolbar.ParamWr\CLSID -> Adware.Azsearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\ZToolbar.ParamWr\CurVer -> Adware.Azsearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\ZToolbar.StockBar -> Adware.Azsearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\ZToolbar.StockBar.1 -> Adware.Azsearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\ZToolbar.StockBar\CLSID -> Adware.Azsearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\ZToolbar.StockBar\CurVer -> Adware.Azsearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\ZToolbar.activator -> Adware.Azsearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\ZToolbar.activator.1 -> Adware.Azsearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\ZToolbar.activator\CLSID -> Adware.Azsearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\ZToolbar.activator\CurVer -> Adware.Azsearch : Cleaned with backup (quarantined).
C:\Program Files\bullseye network -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\navisearch -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\tbonbin -> Adware.BetterInternet : Cleaned with backup (quarantined).
C:\WINDOWS\nail.exe -> Adware.BetterInternet : Cleaned with backup (quarantined).
C:\WINDOWS\nail.exe\Readme.txt -> Adware.BetterInternet : Cleaned with backup (quarantined).
C:\WINDOWS\svcproc.exe -> Adware.BetterInternet : Cleaned with backup (quarantined).
C:\WINDOWS\svcproc.exe\Readme.txt -> Adware.BetterInternet : Cleaned with backup (quarantined).
C:\Program Files\cashback -> Adware.CashBack : Cleaned with backup (quarantined).
C:\WINDOWS\system32\adcache -> Adware.Cydoor : Cleaned with backup (quarantined).
C:\Program Files\hotbar -> Adware.HotBar : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\YazzleActiveX.ocx -> Adware.MediaTickets : Cleaned with backup (quarantined).
C:\WINDOWS\YAXUninst.exe -> Adware.MediaTickets : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{a19ef336-01d4-48e6-926a-fe7e1c747aed} -> Adware.MWSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{da7ff3f8-08be-4cac-bc00-94d91c6ae7f4} -> Adware.MWSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{a19ef336-01d4-48e6-926a-fe7e1c747aed} -> Adware.MWSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{da7ff3f8-08be-4cac-bc00-94d91c6ae7f4} -> Adware.MWSearch : Cleaned with backup (quarantined).
HKU\S-1-5-21-1078081533-796845957-682003330-1003\Software\Microsoft\Windows\
CurrentVersion\Ext\Stats\{A19EF336-01D4-48E6-926A-FE7E1C747AED} -> Adware.MWSearch : Cleaned with backup (quarantined).
HKU\S-1-5-21-1078081533-796845957-682003330-1003\Software\Microsoft\Windows\
CurrentVersion\Ext\Stats\{DA7FF3F8-08BE-4CAC-BC00-94D91C6AE7F4} -> Adware.MWSearch : Cleaned with backup (quarantined).
C:\Program Files\newdotnet -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\Program Files\psguard -> Adware.PSGuard : Cleaned with backup (quarantined).
C:\Program Files\rxtoolbar -> Adware.RXToolbar : Cleaned with backup (quarantined).
C:\Program Files\save -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\Program Files\whenusearch -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\Program Files\sidefind -> Adware.SideFind : Cleaned with backup (quarantined).
C:\Program Files\spyfalcon -> Adware.SpyFalcon : Cleaned with backup (quarantined).
C:\Program Files\starware -> Adware.Starware : Cleaned with backup (quarantined).
C:\Program Files\surfaccuracy -> Adware.SurfAccuracy : Cleaned with backup (quarantined).
C:\Program Files\surfsidekick 3 -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\Program Files\winfixer 2005 -> Adware.WinFixer : Cleaned with backup (quarantined).
C:\Program Files\adstatus service -> Adware.WinTaskAd : Cleaned with backup (quarantined).
C:\Documents and Settings\WONDERFULME888\Local Settings\Temporary Internet Files\Content.IE5\8V1BIIND\w[1].php -> Downloader.Agent.anm : Cleaned with backup (quarantined).
C:\WINDOWS\system32\awvtssp.dll -> Downloader.Agent.anm : Cleaned with backup (quarantined).
C:\Andy\HijackThis\backups\backup-20060701-013802-185.dll -> Downloader.ConHook.aa : Cleaned with backup (quarantined).
C:\Andy\HijackThis\backups\backup-20060701-013915-804.dll -> Downloader.ConHook.aa : Cleaned with backup (quarantined).
C:\WINDOWS\system32\mlljj.exe -> Dropper.Agent.amr : Cleaned with backup (quarantined).
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq19.tmp\ld2E4E.tmp -> Not-A-Virus.Hoax.Win32.Renos.dv : Ignored.
C:\Documents and Settings\Kids\Cookies\kids@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Kids\Cookies\kids@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\WONDERFULME888\Cookies\wonderfulme888@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Program Files\Privacy Crusader Full\quarantine\andy@112.2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Kids\Cookies\kids@adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Kids\Cookies\kids@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Kids\Cookies\kids@citi.bridgetrack[1].txt -> TrackingCookie.Bridgetrack : Cleaned.
C:\Documents and Settings\WONDERFULME888\Cookies\wonderfulme888@www.burstbeacon[2].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\WONDERFULME888\Cookies\wonderfulme888@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\WONDERFULME888\Cookies\wonderfulme888@www.burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Program Files\Privacy Crusader Full\quarantine\andy@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Kids\Cookies\kids@as.casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\Kids\Cookies\kids@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\Kids\Cookies\kids@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Program Files\Privacy Crusader Full\quarantine\andy@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Program Files\Privacy Crusader Full\quarantine\andy@com[2].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Kids\Cookies\kids@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Kids\Cookies\kids@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\Kids\Cookies\kids@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Program Files\Privacy Crusader Full\quarantine\andy@www.myaffiliateprogram[1].txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
C:\Documents and Settings\Kids\Cookies\kids@data4.perf.overture[2].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\WONDERFULME888\Cookies\wonderfulme888@data2.perf.overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Kids\Cookies\kids@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\Kids\Cookies\kids@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2B.tmp -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\Kids\Cookies\kids@edge.ru4[1].txt -> TrackingCookie.Ru4 : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2C.tmp -> TrackingCookie.Serving-sys : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2D.tmp -> TrackingCookie.Spylog : Cleaned.
C:\Documents and Settings\Kids\Cookies\kids@h.starware[1].txt -> TrackingCookie.Starware : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2E.tmp -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\Kids\Cookies\kids@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\WONDERFULME888\Cookies\wonderfulme888@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Kids\Cookies\kids@login.tracking101[2].txt -> TrackingCookie.Tracking101 : Cleaned.
C:\Documents and Settings\WONDERFULME888\Cookies\wonderfulme888@login.tracking101[2].txt -> TrackingCookie.Tracking101 : Cleaned.
C:\Documents and Settings\Kids\Cookies\kids@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Cleaned.
C:\Documents and Settings\Kids\Cookies\kids@trafficmp[1].txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Documents and Settings\Kids\Cookies\kids@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2F.tmp -> TrackingCookie.Tribalfusion : Cleaned.
C:\Program Files\Privacy Crusader Full\quarantine\andy@web-stat[2].txt -> TrackingCookie.Web-stat : Cleaned.
C:\Program Files\Privacy Crusader Full\quarantine\andy@webstat[1].txt -> TrackingCookie.Web-stat : Cleaned.
C:\Documents and Settings\WONDERFULME888\Cookies\wonderfulme888@free.wegcash[2].txt -> TrackingCookie.Wegcash : Cleaned.
C:\Documents and Settings\Kids\Cookies\kids@zedo[2].txt -> TrackingCookie.Zedo : Cleaned.
C:\WINDOWS\system32\dxmpp.dll -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\system32\dxmpp.dll\Readme.txt -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ginuerep.dll -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ginuerep.dll\Readme.txt -> Trojan.Small : Cleaned with backup (quarantined).
::Report end
*******************************************************
And the HijackThis log...
Logfile of HijackThis v1.99.1
Scan saved at 5:57:35 AM, on 7/1/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\CDBurnerXP\NMSAccess.exe
C:\Program Files\Advanced Registry Doctor\RegManServ.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Wisdom-soft ScreenHunter Free\ScreenHunter.exe
C:\Program Files\Webshots\webshots.scr
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Andy\HijackThis\HijackThis.exe
C:\WINDOWS\system32\svchost.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.com/customize/ie/...ch/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: (no name) - Disabled:AutorunsDisabled - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\saIE.dll
O2 - BHO: (no name) - {11359F4A-B191-42d7-905A-594F8CF0387B} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: &Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Startup: MiniMinder.lnk = C:\Program Files\MiniMind\MiniMind.exe
O4 - Startup: ScreenHunter.exe.lnk = C:\Program Files\Wisdom-soft ScreenHunter Free\ScreenHunter.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: &Yahoo! Search -
file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Download all with Free Download Manager -
file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager -
file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download web site with Free Download Manager -
file://C:\Program Files\Free Download Manager\dlpage.htm
O8 - Extra context menu item: Download with Free Download Manager -
file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: Post Image to Blog - res://C:\WINDOWS\ImageShackToolbar\ImageShackToolbar.dll/5003
O8 - Extra context menu item: Tag This Image - res://C:\WINDOWS\ImageShackToolbar\ImageShackToolbar.dll/5002
O8 - Extra context menu item: Upload All Images to ImageShack - res://C:\WINDOWS\ImageShackToolbar\ImageShackToolbar.dll/5000
O8 - Extra context menu item: Upload Image to ImageShack - res://C:\WINDOWS\ImageShackToolbar\ImageShackToolbar.dll/5001
O8 - Extra context menu item: Yahoo! &Dictionary -
file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps -
file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS -
file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {8A29A683-DF4A-4C79-8356-E9FB08ADEAC6} - C:\Program Files\IEGuard\IEGuardManager.exe
O9 - Extra 'Tools' menuitem: IEGuard - {8A29A683-DF4A-4C79-8356-E9FB08ADEAC6} - C:\Program Files\IEGuard\IEGuardManager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - SolidConverterPDF - (no file) (HKCU)
O15 - Trusted Zone: *..reg.imageshack.us
O15 - Trusted Zone: *..toolbar.imageshack.us
O15 - Trusted Zone:
http://toolbar.imageshack.us
O15 - Trusted Zone: *.imageshack.us
O15 - Trusted Zone: *..softpedia.com
O16 - DPF: {00000000-0000-0000-0000-100000000003} -
http://code.trasferimento.biz/l/9e8f...73ae4c8_35.exe
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) -
http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) -
http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) -
http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) -
http://www.creative.com/su/ocx/15015/CTSUEng.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) -
http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} -
O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) -
https://www.windowsonecare.com/insta...SSWebAgent.CAB
O16 - DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} (Hewlett-Packard Online Support Services) -
http://h50203.www5.hp.com/HPISWeb/Cu...ataManager.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) -
http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) -
http://dlmanager.akamaitools.com.edg...ex-2.0.4.4.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/S...in/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) -
http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) -
http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) -
http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) -
http://www.pcpitstop.com/pestscan/pestscan.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) -
http://scan.safety.live.com/resource...scbase7617.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O16 - DPF: {6932D140-ABC4-4073-A44C-D4A541665E35} (ImageShack Toolbar) -
http://toolbar.imageshack.us/toolbar...ackToolbar.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsof...?1143565502468
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} (YazzleActiveX Control) -
http://yax-download.yazzle.net/Yazzl...cab?refid=1123
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) -
http://www3.ca.com/securityadvisor/v...fo/webscan.cab
O16 - DPF: {8EC18CE2-D7B4-11D2-88C8-006008A717FD} (NCSView Class) -
http://63.241.168.238/ae/ecwplugins/ncs1.cab
O16 - DPF: {90F7E144-984F-4FA6-83A7-C9C8DCB9974C} (RSActiveXObj Control) -
http://www.radarsync.com/RSActiveX.ocx
O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) -
http://www.pcpitstop.com/mhLbl.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/actives...ree/asinst.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) -
https://h17000.www1.hp.com/ewfrf-JAV...oadManager.ocx
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} -
http://www.trendmicro.com/spyware-scan/as4web.cab
O16 - DPF: {BDD2F926-8158-4F62-9E0D-B3B75FD1F07F} (McObjectFactory Class) -
http://download.mcafee.com/molbin/sh...,2/mcmysec.cab
O16 - DPF: {BDEE1959-AB6B-4745-A29B-F492861102CC} (CamRegCleanControl Object) -
http://www.amustsoft.com/onlineregis...RegCleaner.cab
O16 - DPF: {CD17FAAA-17B4-4736-AAEF-436EDC304C8C} (ContentAuditX Control) -
https://www.contentwatch.com/audit/i...ditControl.cab
O16 - DPF: {D7BF3304-138B-4DD5-86EE-491BB6A2286C} -
http://www.globosoft.info/globobar.cab
O16 - DPF: {E856B973-45FD-4559-8F82-EAB539144667} (Dell PC Checkup Installer Control) -
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) -
http://driveragent.com/files/driveragent.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) -
http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?326
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) -
http://download.mcafee.com/molbin/is...69/mcfscan.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) -
http://www.creative.com/su/ocx/15021/CTPID.cab
O18 - Protocol: bw+0 - {B451C6F2-8605-476C-820B-C2E0F22AB754} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
[DMR: Additional Logitech 018 entries snipped for ease of viewing]
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: offline-8876480 - {B451C6F2-8605-476C-820B-C2E0F22AB754} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O20 - Winlogon Notify: AutorunsDisabled - C:\WINDOWS\
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winrge32 - C:\WINDOWS\SYSTEM32\winrge32.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccess.exe
O23 - Service: Registry Management Service (RegManServ) - Unknown owner - C:\Program Files\Advanced Registry Doctor\RegManServ.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
*******************************************************
Oh, after all this, I opened Manage Addons and ds3m32.dll was still there as a browser helper. I disabled it and after I closed and reopened IE it was gone.