This is what's happening to my computer. I turn it on and when it's all booted up and everything, all these windows and applications pops up by themselves. Here are what opens up:
C:\WINNT\System
C:\Windows
WordPad (and it says "C:/Document. Cannot find this file. Please cerify that the correct path and file name are given")
C:\WINNT\system32\WBEM\Performance
FreeCell
Spider
3D Pinball for Windows
C:\WINNT\Security
C:\WINNT\System32\Microsoft
C:\WINNT\system32\WBEM\XML
An ad pop-up.
And a warning that says:
"Window XP Set-Up
Please go to Control Panel to install and configure system components"
How can I fix this?
Here's my log:
Logfile of HijackThis v1.99.1
Scan saved at 4:01:47 PM, on 7/29/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\Winamp\winampa.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINNT\System32\wdfmgr.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\WINNT\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrator\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Sympatico
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\RunServices: [Microsoft LSASS Service] mslsass.exe
O4 - HKLM\..\RunServices: [MSN] msnmsg.exe
O4 - HKCU\..\Run: [Windows TM] SVPHOST.exe
O4 - HKCU\..\Run: [starter] scvhostingg.exe
O4 - HKCU\..\Run: [*windows update] wscxt.exe
O4 - HKCU\..\Run: [*Microsoft Update] wstcl.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [@C:\WINNT\system32\netshell.dll,-1200] Network Connections
O4 - HKCU\..\Run: [@shell32.dll,-21779] My Pictures
O4 - HKCU\..\Run: [@C:\WINNT\system32\SHELL32.dll,-9319] Printers and Faxes
O4 - HKCU\..\Run: [@C:\WINNT\system32\SHELL32.dll,-9216] My Computer
O4 - HKCU\..\Run: [@C:\WINNT\system32\SHELL32.dll,-9217] My Network Places
O4 - HKCU\..\Run: [@explorer.exe,-7021] &Help and Support
O4 - HKCU\..\Run: [@explorer.exe,-7020] &Search
O4 - HKCU\..\Run: [@explorer.exe,-7023] &Run...
O4 - HKCU\..\Run: [C:\Program Files\Internet Explorer\iexplore.exe] Internet Explorer
O4 - HKCU\..\Run: [C:\Program Files\MSN Messenger\msnmsgr.exe] MSN Messenger
O4 - HKCU\..\Run: [@explorer.exe,-7024] Internet
O4 - HKCU\..\Run: [@explorer.exe,-7025] E-mail
O4 - HKCU\..\Run: [@C:\Program Files\Internet Explorer\iexplore.exe,-702] Internet Explorer
O4 - HKCU\..\Run: [C:\Program Files\AIM\aim.exe] AOL Instant Messenger
O4 - HKCU\..\Run: [@shdoclc.dll,-10241] Open &Home Page
O4 - HKCU\..\Run: [@C:\WINNT\system32\SHELL32.dll,-8503] S&earch...
O4 - HKCU\..\Run: [@C:\WINNT\system32\mycomput.dll,-400] Mana&ge
O4 - HKCU\..\Run: [@shell32.dll,-31232] System Tasks
O4 - HKCU\..\Run: [@shell32.dll,-31294] View system information
O4 - HKCU\..\Run: [@shell32.dll,-31327] Add or remove programs
O4 - HKCU\..\Run: [@shell32.dll,-31312] Change a setting
O4 - HKCU\..\Run: [@shell32.dll,-31272] Other Places
O4 - HKCU\..\Run: [@shell32.dll,-21785] Shared Documents
O4 - HKCU\..\Run: [@shell32.dll,-31274] Details
O4 - HKCU\..\Run: [C:\WINNT\Explorer.EXE] Windows Explorer
O4 - HKCU\..\Run: [@C:\WINNT\system32\SHELL32.dll,-22913] Shows the disk drives and hardware connected to this computer.
O4 - HKCU\..\Run: [C:\Program Files\Winamp\winamp.exe] Winamp
O4 - HKCU\..\Run: [@C:\WINNT\System32\setupapi.dll,-2000] Setup Information
O4 - HKCU\..\Run: [@C:\WINNT\system32\notepad.exe,-469] Text Document
O4 - HKCU\..\Run: [@shell32.dll,-31317] System Tasks
O4 - HKCU\..\Run: [@shell32.dll,-31321] Hide the contents of this drive
O4 - HKCU\..\Run: [@shell32.dll,-31292] Search for files or folders
O4 - HKCU\..\Run: [@shell32.dll,-31233] File and Folder Tasks
O4 - HKCU\..\Run: [@shell32.dll,-31236] Make a new folder
O4 - HKCU\..\Run: [@shell32.dll,-31260] Publish this folder to the Web
O4 - HKCU\..\Run: [@shell32.dll,-31374] Share this folder
O4 - HKCU\..\Run: [@shell32.dll,-31254] Rename this folder
O4 - HKCU\..\Run: [@shell32.dll,-31256] Move this folder
O4 - HKCU\..\Run: [@shell32.dll,-31258] Copy this folder
O4 - HKCU\..\Run: [@shell32.dll,-31380] E-mail this folder's files
O4 - HKCU\..\Run: [@shell32.dll,-31262] Delete this folder
O4 - HKCU\..\Run: [@C:\WINNT\System32\zipfldr.dll,-10195] Compressed (zipped) Folder
O4 - HKCU\..\Run: [@shell32.dll,-31242] Rename this file
O4 - HKCU\..\Run: [@shell32.dll,-31244] Move this file
O4 - HKCU\..\Run: [@shell32.dll,-31246] Copy this file
O4 - HKCU\..\Run: [@shell32.dll,-31248] Publish this file to the Web
O4 - HKCU\..\Run: [@shell32.dll,-31370] E-mail this file
O4 - HKCU\..\Run: [@shell32.dll,-31250] Print this file
O4 - HKCU\..\Run: [@shell32.dll,-31252] Delete this file
O4 - HKCU\..\Run: [@shell32.dll,-31275] This section displays the size, file type, and other information about a selected item.
O4 - HKCU\..\Run: [@shell32.dll,-22075] Windows Catalog
O4 - HKCU\..\Run: [@C:\WINNT\inf\unregmp2.exe,-4] Windows Media Player
O4 - HKCU\..\Run: [@C:\WINNT\system32\rcbdyctl.dll,-152] Remote Assistance
O4 - HKCU\..\Run: [@shell32.dll,-21773] Games
O4 - HKCU\..\Run: [@shell32.dll,-21768] Communications
O4 - HKCU\..\Run: [@shell32.dll,-21788] System Tools
O4 - HKCU\..\Run: [@shell32.dll,-22019] Calculator
O4 - HKCU\..\Run: [@shell32.dll,-22054] Paint
O4 - HKCU\..\Run: [@C:\WINNT\System32\sti_ci.dll,-11] Scanner and Camera Wizard
O4 - HKCU\..\Run: [@shell32.dll,-22069] WordPad
O4 - HKCU\..\Run: [@%SystemRoot%\system32\shell32.dll,-22566] Creates and edits drawings, and displays and edits scanned photos.
O4 - HKCU\..\Run: [C:\WINNT\system32\mspaint.exe] Paint
O4 - HKCU\..\Run: [C:\Program Files\Windows Media Player\wmplayer.exe] Windows Media Player
O4 - HKCU\..\Run: [C:\WINNT\System32\shimgvw.dll] Windows Picture and Fax Viewer
O4 - HKCU\..\Run: [C:\PROGRA~1\MICROG~1\PICTUR~1\Pp70.exe] Picture Publisher
O4 - HKCU\..\Run: [C:\Program Files\Adobe\Photoshop 7.0\Photoshop.exe] Adobe Photoshop
O4 - HKCU\..\Run: [C:\Program Files\Windows NT\Accessories\ImageVue\KodakImg.exe] IMAGE VIEWER
O4 - HKCU\..\Run: [@shimgvw.dll,-550] Pre&view
O4 - HKCU\..\Run: [@shdoclc.dll,-881] Finds and displays information and Web sites on the Internet
O4 - HKCU\..\Run: [@shell32.dll,-21762] Administrative Tools
O4 - HKCU\..\Run: [@shell32.dll,-21787] Startup
O4 - HKCU\..\Run: [@shell32.dll,-22031] HyperTerminal
O4 - HKCU\..\Run: [@C:\WINNT\System32\mstsc.exe,-4000] Remote Desktop Connection
O4 - HKCU\..\Run: [@C:\WINNT\system32\netshell.dll,-1010] New Connection Wizard
O4 - HKCU\..\Run: [@C:\WINNT\system32\hnetwiz.dll,-3085] Network Setup Wizard
O4 - HKCU\..\Run: [@C:\WINNT\system32\fxsres.dll,-110] Send a Fax...
O4 - HKCU\..\Run: [@C:\WINNT\system32\fxsres.dll,-112] Fax Cover Page Editor
O4 - HKCU\..\Run: [@C:\WINNT\system32\fxsres.dll,-114] Fax Console
O4 - HKCU\..\Run: [@shell32.dll,-22066] Volume Control
O4 - HKCU\..\Run: [@shell32.dll,-22061] Sound Recorder
O4 - HKCU\..\Run: [@shell32.dll,-22021] Character Map
O4 - HKCU\..\Run: [@shell32.dll,-22018] Backup
O4 - HKCU\..\Run: [@shell32.dll,-22027] Disk Defragmenter
O4 - HKCU\..\Run: [@shell32.dll,-22026] Disk Cleanup
O4 - HKCU\..\Run: [@shell32.dll,-22058] Scheduled Tasks
O4 - HKCU\..\Run: [@C:\WINNT\system32\usmt\migwiz.exe,-202] Files and Settings Transfer Wizard
O4 - HKCU\..\Run: [@C:\WINNT\system32\restore\rstrui.exe,-2048] System Restore
O4 - HKCU\..\Run: [@shell32.dll,-22063] System Information
O4 - HKCU\..\Run: [@shell32.dll,-22025] Data Sources (ODBC)
O4 - HKCU\..\Run: [@shell32.dll,-22023] Computer Management
O4 - HKCU\..\Run: [@C:\WINNT\System32\comres.dll,-661] Component Services
O4 - HKCU\..\Run: [@shell32.dll,-22040] Local Security Policy
O4 - HKCU\..\Run: [@shell32.dll,-22029] Event Viewer
O4 - HKCU\..\Run: [@shell32.dll,-22059] Services
O4 - HKCU\..\Run: [@shell32.dll,-22055] Performance
O4 - HKCU\..\Run: [@C:\WINNT\system32\mshearts.exe,-413] Hearts
O4 - HKCU\..\Run: [@shell32.dll,-22030] FreeCell
O4 - HKCU\..\Run: [@C:\PROGRA~1\MSNGAM~1\Windows\hrtzres.dll,-1212] Internet Hearts
O4 - HKCU\..\Run: [@C:\PROGRA~1\MSNGAM~1\Windows\chkrres.dll,-1212] Internet Checkers
O4 - HKCU\..\Run: [@C:\PROGRA~1\MSNGAM~1\Windows\bckgres.dll,-1212] Internet Backgammon
O4 - HKCU\..\Run: [@shell32.dll,-22045] Minesweeper
O4 - HKCU\..\Run: [@C:\PROGRA~1\MSNGAM~1\Windows\shvlres.dll,-1212] Internet Spades
O4 - HKCU\..\Run: [@C:\PROGRA~1\MSNGAM~1\Windows\rvseres.dll,-1212] Internet Reversi
O4 - HKCU\..\Run: [@C:\WINNT\system32\spider.exe,-56] Spider Solitaire
O4 - HKCU\..\Run: [@shell32.dll,-22060] Solitaire
O4 - HKCU\..\Run: [@shell32.dll,-22057] Pinball
O4 - HKCU\..\Run: [C:\WINNT\System32\ssstars.scr] Starfield Screen Saver
O4 - HKCU\..\Run: [C:\Program Files\StealthBot\StealthBot v2.6R3.exe] StealthBot v2.6
O4 - HKCU\..\Run: [@%SystemRoot%\inf\unregmp2.exe,-155] Plays your digital media including music, videos, CDs, DVDs, and Internet Radio.
O4 - HKCU\..\Run: [@C:\Program Files\NetMeeting\conf.exe,-12345] H.323 Internet Telephony
O4 - HKCU\..\Run: [@C:\WINNT\system32\accwiz.exe,-16] Accessibility Wizard settings
O4 - HKCU\..\Run: [@C:\WINNT\inf\unregmp2.exe,-9909] Windows Media Audio/Video file
O4 - HKCU\..\Run: [@C:\WINNT\inf\unregmp2.exe,-9910] Windows Media Audio/Video playlist
O4 - HKCU\..\Run: [@C:\WINNT\system32\SHELL32.dll,-22978] Briefcase
O4 - HKCU\..\Run: [@C:\WINNT\System32\ntbackup.exe,-40] Windows Backup File
O4 - HKCU\..\Run: [@C:\WINNT\System32\pdh.dll,-10023] Performance Monitor File
O4 - HKCU\..\Run: [@C:\WINNT\System32\shimgvw.dll,-304] Bitmap Image
O4 - HKCU\..\Run: [@C:\WINNT\System32\cryptext.dll,-6145] Security Catalog
O4 - HKCU\..\Run: [@C:\WINNT\System32\cdfview.dll,-4610] Channel File
O4 - HKCU\..\Run: [@C:\WINNT\System32\cryptext.dll,-6108] Security Certificate
O4 - HKCU\..\Run: [@C:\Program Files\NetMeeting\conf.exe,-12346] SpeedDial
O4 - HKCU\..\Run: [@C:\WINNT\system32\fxscover.exe,-2523] Fax Cover Page File
O4 - HKCU\..\Run: [@C:\WINNT\System32\cryptext.dll,-6110] Certificate Revocation List
O4 - HKCU\..\Run: [@C:\WINNT\system32\netshell.dll,-1300] Dialup Networking File
O4 - HKCU\..\Run: [@C:\WINNT\System32\shimgvw.dll,-301] EMF Image
O4 - HKCU\..\Run: [@C:\Program Files\NetMeeting\conf.exe,-12347] Intel IPhone Compatible
O4 - HKCU\..\Run: [@C:\Program Files\Internet Explorer\Connection Wizard\icwres.dll,-20003] Internet Communication Settings
O4 - HKCU\..\Run: [@C:\WINNT\System32\shimgvw.dll,-303] JPEG Image
O4 - HKCU\..\Run: [@C:\WINNT\System32\wshext.dll,-4804] JScript Script File
O4 - HKCU\..\Run: [@C:\WINNT\System32\wshext.dll,-4805] JScript Encoded Script File
O4 - HKCU\..\Run: [@C:\WINNT\inf\unregmp2.exe,-9907] MIDI Sequence
O4 - HKCU\..\Run: [@C:\WINNT\inf\unregmp2.exe,-10003] Movie file (mpeg)
O4 - HKCU\..\Run: [@C:\WINNT\system32\mmcbase.dll,-130] Microsoft Common Console Document
O4 - HKCU\..\Run: [@C:\WINNT\System32\msi.dll,-34] Windows Installer Package
O4 - HKCU\..\Run: [@C:\WINNT\System32\msi.dll,-35] Windows Installer Patch
O4 - HKCU\..\Run: [@C:\WINNT\System32\RCBdyctl.dll,-150] Microsoft Remote Assistance Incident
O4 - HKCU\..\Run: [@C:\Program Files\Movie Maker\1033\wmm2res.dll,-63097] Windows Movie Maker Project
O4 - HKCU\..\Run: [@C:\WINNT\PCHealth\HelpCtr\Binaries\msinfo.dll,-391] MSInfo Document
O4 - HKCU\..\Run: [@C:\Program Files\NetMeeting\nmwb.dll,-1234] Microsoft NetMeeting T126 Compatible Whiteboard Document
O4 - HKCU\..\Run: [@C:\WINNT\System32\cryptext.dll,-6111] PKCS #7 Certificates
O4 - HKCU\..\Run: [@C:\WINNT\System32\cryptext.dll,-6113] PKCS #7 Signature
O4 - HKCU\..\Run: [@C:\WINNT\System32\scrobj.dll,-8192] Windows Script Component
O4 - HKCU\..\Run: [@C:\WINNT\system32\shscrap.dll,-258] Scrap object
O4 - HKCU\..\Run: [@C:\WINNT\inf\unregmp2.exe,-9904] AU Format Sound
O4 - HKCU\..\Run: [@C:\WINNT\System32\cryptext.dll,-6112] Microsoft Serialized Certificate Store
O4 - HKCU\..\Run: [@C:\WINNT\System32\cryptext.dll,-6109] Certificate Trust List
O4 - HKCU\..\Run: [@C:\WINNT\System32\wshext.dll,-4803] VBScript Encoded Script File
O4 - HKCU\..\Run: [@C:\WINNT\System32\wshext.dll,-4802] VBScript Script File
O4 - HKCU\..\Run: [@C:\WINNT\inf\unregmp2.exe,-9911] Windows Media Audio shortcut
O4 - HKCU\..\Run: [@C:\WINNT\inf\unregmp2.exe,-9920] Windows Media Player Download Package
O4 - HKCU\..\Run: [@C:\WINNT\System32\shimgvw.dll,-307] WMF Image
O4 - HKCU\..\Run: [@C:\WINNT\inf\unregmp2.exe,-9919] Windows Media Player File
O4 - HKCU\..\Run: [@C:\WINNT\inf\unregmp2.exe,-9915] Windows Media Player Skin File
O4 - HKCU\..\Run: [@C:\WINNT\inf\unregmp2.exe,-9914] Windows Media Audio/Video file
O4 - HKCU\..\Run: [@C:\WINNT\inf\unregmp2.exe,-9916] Windows Media Player Skin Package
O4 - HKCU\..\Run: [@C:\WINNT\inf\unregmp2.exe,-9923] Windows Media playlist
O4 - HKCU\..\Run: [@"C:\Program Files\Windows NT\Accessories\WORDPAD.EXE",-208] Write Document
O4 - HKCU\..\Run: [@C:\WINNT\System32\wshext.dll,-4801] Windows Script File
O4 - HKCU\..\Run: [@C:\WINNT\System32\wshext.dll,-4800] Windows Script Host Settings File
O4 - HKCU\..\Run: [@C:\WINNT\inf\unregmp2.exe,-9913] Windows Media Audio/Video playlist
O4 - HKCU\..\Run: [@C:\WINNT\System32\msxml3r.dll,-1] XML Document
O4 - HKCU\..\Run: [@C:\WINNT\System32\msxml3r.dll,-2] XSL Stylesheet
O4 - HKCU\..\Run: [C:\Program Files\Starcraft\starcraft.exe] Starcraft
O4 - HKCU\..\Run: [@C:\WINNT\system32\SHELL32.dll,-8964] Recycle Bin
O4 - HKCU\..\Run: [@shdoclc.dll,-880] Internet Explorer
O4 - HKCU\..\Run: [@shell32.dll,-22016] Accessibility Wizard
O4 - HKCU\..\Run: [C:\Program Files\LimeWire Pro\LimeWire\LimeWire.exe] LimeWire
O4 - HKCU\..\Run: [@shell32.dll,-31276] Music Tasks
O4 - HKCU\..\Run: [@shell32.dll,-31278] Play all
O4 - HKCU\..\Run: [@shell32.dll,-31281] Shop for music online
O4 - HKCU\..\Run: [@shell32.dll,-28995] Shared Music
O4 - HKCU\..\Run: [@C:\WINNT\inf\unregmp2.exe,-9912] Windows Media Audio file
O4 - HKCU\..\Run: [C:\WINNT\System32\zipfldr.dll] Compressed (zipped) Folders
O4 - HKCU\..\Run: [@zipfldr.dll,-10300] Folder Tasks
O4 - HKCU\..\Run: [@zipfldr.dll,-10302] Extract all files
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: Yahoo! Literati - http://download.game...nts/y/tt3_x.cab
O16 - DPF: Yahoo! Towers 2.0 - http://download.game...ts/y/ywt0_x.cab
O16 - DPF: Yahoo! Word Racer - http://download.game...nts/y/wt1_x.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...er.cab31267.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcaf...84/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by102fd.bay10...es/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1106710003244
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zon...ro.cab32846.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcaf...,21/mcgdmgr.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zon...wn.cab31267.cab
O20 - Winlogon Notify: AVPexec - C:\WINNT\SYSTEM32\comctrl32.dll
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Pml Driver - HP - C:\WINNT\System32\HPHipm09.exe