When windows is started emylthro.exe is executed and resides in mem. All it does is set the homepage on IE to a porn site, and create in /windows/temp a .tmp file with a random name like hxvc7391.TMP They were always llllnnn.TMP Emylthro.exe stayed resident in mem but did nothing after it executed the .TMP. This .tmp created an icon in the systray called Music Search Online, but actually linked to a hard-core porn site. I connected once to see where it took me, but hit the LOCK switch on ZoneAlarm as soon as it started asking to upload some more s/ware. I set the firewall to deny the Music Search Online access to all networks. Proxomitron killed all the popups and ads so I don't know how many there were, but I expect the site is popoup central.
anyway. That's the story. I'll run regclean again to clean up the mess.
Next step is to remove the programs listed in add/remove programs that don't have an attachment to anything.
The kid who installed this mongrel bastard thing has had all his PC priveliges revoked. I was so pissed off with him I told his mum exactly what he'd been doing:
Surfing the 'net for hard core lesbian porn.