Ken,
Here is the Spybot report with the 3 items checked as instructed.
--- Search result list ---
DriveCleaner 2006: Program directory (Directory, nothing done)
C:\Documents and Settings\All Users\Application Data\SalesMonitor\
DriveCleaner 2006: Program directory (Directory, nothing done)
C:\Documents and Settings\All Users\Application Data\SalesMonitor\Data\
--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---
2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2005-07-08 unins000.exe (51.41.0.0)
2005-05-31 Update.exe (1.4.0.0)
2007-05-23 advcheck.dll (1.5.3.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2007-07-31 Tools.dll (2.1.2.0)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2007-08-08 Includes\Cookies.sbi (*)
2007-07-25 Includes\Dialer.sbi (*)
2007-08-08 Includes\DialerC.sbi (*)
2007-07-11 Includes\Hijackers.sbi (*)
2007-08-08 Includes\HijackersC.sbi (*)
2007-07-25 Includes\Keyloggers.sbi (*)
2007-08-08 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2007-08-01 Includes\Malware.sbi (*)
2007-08-08 Includes\MalwareC.sbi (*)
2007-08-08 Includes\PUPS.sbi (*)
2007-08-08 Includes\PUPSC.sbi (*)
2007-08-08 Includes\Revision.sbi (*)
2007-05-30 Includes\Security.sbi (*)
2007-08-08 Includes\SecurityC.sbi (*)
2007-08-01 Includes\Spybots.sbi (*)
2007-08-08 Includes\SpybotsC.sbi (*)
2005-02-17 Includes\Tracks.uti
2007-08-01 Includes\Trojans.sbi (*)
2007-08-08 Includes\TrojansC.sbi (*)
2007-06-06 Plugins\TCPIPAddress.dll
--- Browser helper object list ---
{02478D38-C3F9-4EFB-9B51-7695ECA05670} (&Yahoo! Toolbar Helper)
BHO name:
CLSID name: &Yahoo! Toolbar Helper
description: Yahoo Companion!
classification: Legitimate
known filename: Ycomp*_*_*_*.dll
info link:
http://companion.yahoo.com/
info source: TonyKlein
Path: C:\Program Files\Yahoo!\Companion\Installs\cpn4\
Long name: yt.dll
Short name:
Date (created): 05/30/2007 1:18:26 PM
Date (last access): 08/10/2007 3:00:46 PM
Date (last write): 05/30/2007 1:18:26 PM
Filesize: 808472
Attributes: archive
MD5: 10555A800613C8613AF53FAD54F1C23F
CRC32: 7582E210
Version: 2007.5.30.1
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
BHO name:
CLSID name: AcroIEHlprObj Class
description: Adobe Acrobat reader
classification: Legitimate
known filename: AcroIEhelper.ocx<br>AcroIEhelper.dll
info link:
http://www.adobe.com/products/acrobat/readstep2.html
info source: TonyKlein
Path: C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\
Long name: AcroIEHelper.ocx
Short name: ACROIE~1.OCX
Date (created): 07/09/2002 9:19:22 AM
Date (last access): 08/10/2007 3:00:46 PM
Date (last write): 04/16/2001 3:39:02 PM
Filesize: 37808
Attributes:
MD5: 8394ABFC1BE196A62C9F532511936DF7
CRC32: 71D6E350
Version: 1.0.0.1
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} (Yahoo! IE Services Button)
BHO name:
CLSID name: Yahoo! IE Services Button
Path: C:\PROGRA~1\Yahoo!\Common\
Long name: yiesrvc.dll
Short name:
Date (created): 05/30/2007 1:34:22 PM
Date (last access): 08/10/2007 3:00:46 PM
Date (last write): 10/31/2006 3:33:54 PM
Filesize: 198136
Attributes: archive
MD5: F8981F09E8DA4FDB7F6B6E2B5361AEAE
CRC32: 2CDBBB6C
Version: 2006.10.31.3
--- ActiveX list ---
Microsoft XML Parser for Java (Microsoft XML Parser for Java)
DPF name: Microsoft XML Parser for Java
CLSID name:
Installer:
Codebase: file://C:\WINDOWS\Java\classes\xmldso.cab
description:
classification: Legitimate
known filename: %WINDIR%\Java\classes\xmldso.cab
info link:
info source: Patrick M. Kolla
ppctlcab (ppctlcab)
DPF name: ppctlcab
CLSID name:
Installer:
Codebase:
http://www.pestscan.com/scanner/ppctlcab.cab
description:
classification: Legitimate
known filename:
info link:
info source: Safer Networking Ltd.
Yahoo! MahJong Solitaire (Yahoo! MahJong Solitaire)
DPF name: Yahoo! MahJong Solitaire
CLSID name:
Installer:
Codebase:
http://download.games.yahoo.com/games/clients/y/mjst4_x.cab
description:
classification: Legitimate
known filename:
info link:
info source: Safer Networking Ltd.
{19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} (MSSecurityAdvisor Class)
DPF name:
CLSID name: MSSecurityAdvisor Class
Installer: C:\WINDOWS\Downloaded Program Files\msSecAdv.inf
Codebase:
http://download.microsoft.com/downl...-a3de-373c3e5552fc/msSecAdv.cab?1083710290218
description:
classification: Legitimate
known filename: mssecadv.dll
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\System32\
Long name: mssecadv.dll
Short name:
Date (created): 09/08/2003 10:30:46 AM
Date (last access): 08/10/2007 2:35:38 PM
Date (last write): 09/08/2003 10:30:46 AM
Filesize: 36960
Attributes: archive
MD5: A4282FD762CE1C4FFA665538E335CFF0
CRC32: 51ECFB75
Version: 5.4.3790.14
{215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6)
DPF name:
CLSID name: Trend Micro ActiveX Scan Agent 6.6
Installer: C:\WINDOWS\Downloaded Program Files\CONFLICT.1\hcImpl.inf
Codebase:
http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
description:
classification: Legitimate
known filename: Housecall_ActiveX.dll
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\Downloaded Program Files\CONFLICT.1\
Long name: Housecall_ActiveX.dll
Short name: HOUSEC~1.DLL
Date (created): 03/05/2007 8:26:20 PM
Date (last access): 08/10/2007 3:00:46 PM
Date (last write): 03/05/2007 8:26:20 PM
Filesize: 385536
Attributes: archive
MD5: BF3D59E4AF25CB1CD3B3886BE1B118D2
CRC32: A1C98A94
Version: 6.51.0.1020
{2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class)
DPF name:
CLSID name: ICSScannerLight Class
Installer: C:\WINDOWS\Downloaded Program Files\ICSScannerLight.inf
Codebase:
http://download.zonelabs.com/bin/free/cm/ICSCM.cab
description:
classification: Legitimate
known filename: ICSScannerLight.dll
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\Downloaded Program Files\
Long name: ICSScannerLight.dll
Short name: ICSSCA~1.DLL
Date (created): 03/29/2004 3:42:32 PM
Date (last access): 08/10/2007 2:13:32 PM
Date (last write): 03/29/2004 3:42:32 PM
Filesize: 786432
Attributes: archive
MD5: 1D9B3A211E5A3AE2BD77384A8A825410
CRC32: 6A70E9F6
Version: 1.0.5.1
{2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen)
DPF name:
CLSID name: PPSDKActiveXScanner.MainScreen
Installer: C:\WINDOWS\Downloaded Program Files\PPSDKActiveXScanner.INF
Codebase:
http://www.pestscan.com/scanner/axscanner.cab
description:
classification: Legitimate
known filename: PPSDKActiveXScanner.ocx
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\Downloaded Program Files\
Long name: PPSDKActiveXScanner.ocx
Short name: PPSDKA~1.OCX
Date (created): 03/17/2004 1:41:36 AM
Date (last access): 08/10/2007 3:00:48 PM
Date (last write): 03/17/2004 1:41:36 AM
Filesize: 170608
Attributes: archive
MD5: 6EA60ECEBA1D024CE2106C7D9DB78AB1
CRC32: 26FCC8AB
Version: 1.5.0.1
{30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (Installation Support)
DPF name:
CLSID name: Installation Support
Installer: C:\WINDOWS\Downloaded Program Files\yinst.inf
Codebase: C:\Program Files\Yahoo!\Common\Yinsthelper.dll
description: Yahoo! Installation helper
classification: Legitimate
known filename: %SystemRoot%\Downloaded Program Files\yinsthelper.dll
info link:
info source: Patrick M. Kolla
Path: C:\Program Files\Yahoo!\Common\
Long name: YInstHelper.dll
Short name: YINSTH~1.DLL
Date (created): 03/15/2007 6:13:06 PM
Date (last access): 08/10/2007 3:00:48 PM
Date (last write): 03/15/2007 6:13:06 PM
Filesize: 209448
Attributes: archive
MD5: 4380A4799E826AF03FD975B4A71E9268
CRC32: 423BF1F7
Version: 2007.3.15.1
{33564D57-0000-0010-8000-00AA00389B71} ()
DPF name:
CLSID name:
Installer: C:\WINDOWS\Downloaded Program Files\WMV9VCM.inf
Codebase:
http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
description:
classification: Legitimate
known filename:
info link:
info source: Safer Networking Ltd.
{4E888414-DB8F-11D1-9CD9-00C04F98436A} (Microsoft.WinRep)
DPF name:
CLSID name: Microsoft.WinRep
Installer: C:\WINDOWS\Downloaded Program Files\winrep.inf
Codebase:
https://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab
description:
classification: Open for discussion
known filename: Winrep.dll
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\System32\
Long name: Winrep.dll
Short name:
Date (created): 09/06/2002 5:07:56 PM
Date (last access): 08/10/2007 2:52:40 PM
Date (last write): 09/06/2002 5:07:56 PM
Filesize: 434176
Attributes: archive
MD5: 99D4CC36B0B504B4B0C60BE21189BE1D
CRC32: AEE58997
Version: 3.1.2.0
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class)
DPF name:
CLSID name: MUWebControl Class
Installer: C:\WINDOWS\Downloaded Program Files\muweb.inf
Codebase:
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1181004992187
description:
classification: Legitimate
known filename: muweb.dll
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\system32\
Long name: muweb.dll
Short name:
Date (created): 05/26/2005 4:19:32 AM
Date (last access): 08/10/2007 2:23:50 PM
Date (last write): 04/16/2007 10:44:18 PM
Filesize: 208248
Attributes: archive
MD5: DA90D6CEE1622D0427B5974C6A4F6B1F
CRC32: FDD90640
Version: 7.0.6000.374
{6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5)
DPF name:
CLSID name: Housecall ActiveX 6.5
Installer: C:\WINDOWS\Downloaded Program Files\hcImpl.inf
Codebase:
http://us-housecall.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
description:
classification: Legitimate
known filename: Housecall_ActiveX.dll
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\Downloaded Program Files\
Long name: Housecall_ActiveX.dll
Short name: HOUSEC~1.DLL
Date (created): 01/16/2006 4:27:16 PM
Date (last access): 08/10/2007 3:00:48 PM
Date (last write): 01/16/2006 4:27:16 PM
Filesize: 347136
Attributes: archive
MD5: D6DF1E562EEA41CE919CBC7E2F761CB5
CRC32: A0FFAC11
Version: 6.5.1.9
{7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class)
DPF name:
CLSID name: WScanCtl Class
Installer: C:\WINDOWS\Downloaded Program Files\webscan.inf
Codebase:
http://www.ca.com/us/securityadvisor/virusinfo/webscan.cab
description:
classification: Legitimate
known filename: webscan.dll
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\Downloaded Program Files\
Long name: webscan.dll
Short name:
Date (created): 11/20/2006 12:02:34 PM
Date (last access): 08/10/2007 2:13:32 PM
Date (last write): 11/20/2006 12:02:34 PM
Filesize: 180282
Attributes: archive
MD5: 76EA3ABECE61FBA3C07F61E42BB0CA48
CRC32: AECD0E4D
Version: 1.1.0.1049
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C} ()
DPF name:
CLSID name:
Installer: C:\WINDOWS\Downloaded Program Files\erma.inf
Codebase:
http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
description:
classification: Open for discussion
known filename:
info link:
info source: Safer Networking Ltd.
{90C9629E-CD32-11D3-BBFB-00105A1F0D68} ()
DPF name:
CLSID name:
Installer: C:\WINDOWS\Downloaded Program Files\isetup.inf
Codebase:
http://www.installengine.com/engine/isetup.cab
description:
classification: Open for discussion
known filename: isetup.dll
info link:
info source: Safer Networking Ltd.
{99B6E512-3893-4155-9964-8EB8E06099CB} (WebSpyWareKiller Class)
DPF name:
CLSID name: WebSpyWareKiller Class
Installer: C:\WINDOWS\Downloaded Program Files\WebSWK.inf
Codebase:
http://download.zonelabs.com/bin/promotions/spywaredetector/WebSWK.cab
description:
classification: Legitimate
known filename: WebSWK.dll
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\Downloaded Program Files\
Long name: WebSWK.dll
Short name:
Date (created): 12/01/2004 5:40:32 PM
Date (last access): 08/10/2007 2:13:34 PM
Date (last write): 12/01/2004 5:40:32 PM
Filesize: 151552
Attributes: archive
MD5: 551866E549A6080DB092423AA36FD142
CRC32: E27F11FB
Version: 1.0.0.17
{9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner)
DPF name:
CLSID name: Anonymizer Anti-Spyware Scanner
Installer: C:\WINDOWS\Downloaded Program Files\CONFLICT.1\WebAAS.inf
Codebase:
http://download.zonelabs.com/bin/promotions/spywaredetector/WebAAS.cab
description:
classification: Legitimate
known filename: WebAAS.dll
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\Downloaded Program Files\CONFLICT.1\
Long name: WebAAS.dll
Short name:
Date (created): 01/20/2005 3:04:18 PM
Date (last access): 08/10/2007 3:00:48 PM
Date (last write): 01/20/2005 3:04:18 PM
Filesize: 151552
Attributes: archive
MD5: 05CE1F289570DC4337D615B6669E065D
CRC32: F52B9D12
Version: 1.0.0.23
{9F1C11AA-197B-4942-BA54-47A8489BB47F} ()
DPF name:
CLSID name:
Installer: C:\WINDOWS\Downloaded Program Files\iuctl.inf
Codebase:
http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38063.3924189815
description: Windows Update
classification: Legitimate
known filename: %WINDIR%\System32\iuctl.dll,iuengine.dll
info link:
info source: Patrick M. Kolla