Hi again

Ok here is the new info~ Thanks yet again!!
ComboFix 07-09-04.4 - "Liz" 2007-09-04 12:35:48.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2497 [GMT -4:00]
Command switches used :: C:\Documents and Settings\Liz\Desktop\CFScript.txt
* Created a new restore point
FILE::
C:\WINDOWS\system32\drvxaf.dll
C:\WINDOWS\system32\drvxafr.dll
C:\WINDOWS\system32\drvhor.dll
C:\WINDOWS\system32\drvhorr.dll
C:\WINDOWS\system32\drvtax.dll
C:\WINDOWS\system32\drvtaxr.dll
C:\Program Files\setup.exe
C:\WINDOWS\system32\drvleb.dll
C:\WINDOWS\system32\drvlebr.dll
C:\WINDOWS\system32\drvcak.dll
C:\WINDOWS\system32\drvcakr.dll
C:\DOCUME~1\ALLUSE~1\APPLIC~1\pwhwlgxm.dll
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\ALLUSE~1\APPLIC~1\pwhwlgxm.dll
C:\DOCUME~1\Liz\APPLIC~1\BitTorrent
C:\DOCUME~1\Liz\APPLIC~1\BitTorrent\bittorrent.log
C:\DOCUME~1\Liz\APPLIC~1\BitTorrent\data\metainfo\23643dd7ac6a915ff05f4ad20fd462dca4e5dde3
C:\DOCUME~1\Liz\APPLIC~1\BitTorrent\data\metainfo\2f8f6e4d3b378cae8d1cd239f0caaa907ad41af4
C:\DOCUME~1\Liz\APPLIC~1\BitTorrent\data\metainfo\50dd8881d513772005ab51b9f9f6f9b222bfec68
C:\DOCUME~1\Liz\APPLIC~1\BitTorrent\data\metainfo\623398f284f3be9f9939314629698b26eca4ec87
C:\DOCUME~1\Liz\APPLIC~1\BitTorrent\data\metainfo\632f6f4c648e68c01a2c679c4add34e408af5753
C:\DOCUME~1\Liz\APPLIC~1\BitTorrent\data\metainfo\6f955a5b63a6c13dcda1bee7615a5742d61e4b15
C:\DOCUME~1\Liz\APPLIC~1\BitTorrent\data\metainfo\78006ad7f6bb50664ee3adb729ed4a2b9f0c48f8
C:\DOCUME~1\Liz\APPLIC~1\BitTorrent\data\metainfo\8395810d6529f17d23e4f26a263c1f8796eec5b9
C:\DOCUME~1\Liz\APPLIC~1\BitTorrent\data\routing_table
C:\DOCUME~1\Liz\APPLIC~1\BitTorrent\data\ui_config
C:\DOCUME~1\Liz\APPLIC~1\BitTorrent\data\ui_state
C:\DOCUME~1\Liz\APPLIC~1\LimeWire
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\.NetworkShare\LimeWireWin4.14.8.exe
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\412splashfree.png
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\createtimes.cache
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\data.ser
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\fileurns.bak
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\fileurns.cache
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\filters.props
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\gnutella.net
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\installation.props
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\library.dat
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\limewire.props
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\pub1.key
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\public.key
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\questions.props
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\responses.cache
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\secureMessage.key
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\simpp.xml
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\spam.dat
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\tables.props
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\black_theme.lwtp
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\black_theme1_star.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\black_theme2_star.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\black_theme3_star.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\black_theme4_star.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\black_theme5_star.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\black_theme\chat.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\black_theme\dir_closed.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\black_theme\dir_open.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\black_theme\forward_dn.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\black_theme\forward_up.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\black_theme\kill.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\black_theme\kill_on.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\black_theme\lime.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\black_theme\logo.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\black_theme\notsearching.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\black_theme\pause_dn.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\black_theme\pause_up.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\black_theme\play_dn.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\black_theme\play_up.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\black_theme\question.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\black_theme\rewind_dn.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\black_theme\rewind_up.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\black_theme\searching.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\black_theme\splash.png
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\black_theme\splashpro.png
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\black_theme\stop_dn.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\black_theme\stop_up.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\black_theme\theme.txt
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\black_theme\warning.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\classic_theme.lwtp
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\classic_theme1_star.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\classic_theme2_star.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\classic_theme3_star.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\classic_theme4_star.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\classic_theme5_star.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\classic_theme\chat.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\classic_theme\dir_closed.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\classic_theme\dir_open.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\classic_theme\forward_dn.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\classic_theme\forward_up.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\classic_theme\kill.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\classic_theme\logo.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\classic_theme\notsearching.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\classic_theme\pause_dn.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\classic_theme\pause_up.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\classic_theme\play_dn.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\classic_theme\play_up.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\classic_theme\question.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\classic_theme\rewind_dn.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\classic_theme\rewind_up.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\classic_theme\search.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\classic_theme\searching.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\classic_theme\splash.png
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\classic_theme\splashpro.png
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\classic_theme\stop_dn.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\classic_theme\stop_up.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\classic_theme\theme.txt
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\classic_theme\warning.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\limewire_theme.lwtp
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\limewire_theme1_star.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\limewire_theme2_star.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\limewire_theme3_star.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\limewire_theme4_star.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\limewire_theme5_star.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\limewire_theme\chat.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\limewire_theme\dir_closed.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\limewire_theme\dir_open.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\limewire_theme\forward_dn.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\limewire_theme\forward_up.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\limewire_theme\kill.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\limewire_theme\kill_on.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\limewire_theme\lime.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\limewire_theme\logo.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\limewire_theme\notsearching.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\limewire_theme\pause_dn.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\limewire_theme\pause_up.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\limewire_theme\play_dn.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\limewire_theme\play_up.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\limewire_theme\question.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\limewire_theme\rewind_dn.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\limewire_theme\rewind_up.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\limewire_theme\searching.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\limewire_theme\splash.png
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\limewire_theme\splashpro.png
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\limewire_theme\stop_dn.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\limewire_theme\stop_up.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\limewire_theme\theme.txt
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\limewire_theme\warning.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\other_theme.lwtp
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\other_theme1_star.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\other_theme2_star.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\other_theme3_star.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\other_theme4_star.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\other_theme5_star.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\other_theme\chat.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\other_theme\forward_dn.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\other_theme\forward_up.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\other_theme\kill.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\other_theme\kill_on.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\other_theme\logo.png
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\other_theme\notsearching.png
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\other_theme\pause_dn.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\other_theme\pause_up.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\other_theme\play_dn.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\other_theme\play_up.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\other_theme\question.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\other_theme\rewind_dn.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\other_theme\rewind_up.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\other_theme\searching.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\other_theme\splash.png
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\other_theme\splashpro.png
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\other_theme\stop_dn.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\other_theme\stop_up.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\other_theme\theme.txt
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\other_theme\warning.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\windows_theme.lwtp
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\windows_theme1_star.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\windows_theme2_star.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\windows_theme3_star.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\windows_theme4_star.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\windows_theme5_star.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\windows_theme\chat.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\windows_theme\forward_dn.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\windows_theme\forward_up.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\windows_theme\kill.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\windows_theme\kill_on.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\windows_theme\logo.png
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\windows_theme\notsearching.png
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\windows_theme\pause_dn.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\windows_theme\pause_up.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\windows_theme\play_dn.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\windows_theme\play_up.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\windows_theme\question.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\windows_theme\rewind_dn.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\windows_theme\rewind_up.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\windows_theme\searching.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\windows_theme\splash.png
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\windows_theme\splashpro.png
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\windows_theme\stop_dn.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\windows_theme\stop_up.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\windows_theme\theme.txt
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\themes\windows_theme\warning.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\ttree.cache
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\update.xml
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\version.key
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\version.xml
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\xml\data\application.sxml
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\xml\data\audio.sxml
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\xml\data\delete_me
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\xml\data\video.sxml
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\xml\misc\application.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\xml\misc\audio.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\xml\misc\document.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\xml\misc\image.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\xml\misc\video.gif
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\xml\schemas\application.xsd
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\xml\schemas\audio.xsd
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\xml\schemas\document.xsd
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\xml\schemas\image.xsd
C:\DOCUME~1\Liz\APPLIC~1\LimeWire\xml\schemas\video.xsd
C:\Program Files\BitTorrent
C:\Program Files\BitTorrent\addrmap.dat
C:\Program Files\BitTorrent\plugin.inf
C:\Program Files\Jbdhpigo
C:\Program Files\Jbdhpigo\wgauzast.dll
C:\Program Files\LimeWire
C:\Program Files\LimeWire\.NetworkShare\LimeWirePackedJars4.12.11.7z
C:\Program Files\LimeWire\.NetworkShare\LimeWireWin4.12.11.exe
C:\Program Files\LimeWire\clink.jar
C:\Program Files\LimeWire\commons-httpclient.jar
C:\Program Files\LimeWire\commons-logging.jar
C:\Program Files\LimeWire\commons-net.jar
C:\Program Files\LimeWire\COPYING
C:\Program Files\LimeWire\daap.jar
C:\Program Files\LimeWire\data.ser
C:\Program Files\LimeWire\donotremove.htm
C:\Program Files\LimeWire\GenericWindowsUtils.dll
C:\Program Files\LimeWire\hashes
C:\Program Files\LimeWire\hs_err_pid5208.log
C:\Program Files\LimeWire\hs_err_pid6128.log
C:\Program Files\LimeWire\i18n.jar
C:\Program Files\LimeWire\icu4j.jar
C:\Program Files\LimeWire\id3v2.jar
C:\Program Files\LimeWire\install.log
C:\Program Files\LimeWire\jcraft.jar
C:\Program Files\LimeWire\jl011.jar
C:\Program Files\LimeWire\jmdns.jar
C:\Program Files\LimeWire\language.prop
C:\Program Files\LimeWire\LimeWire On Startup.lnk
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\LimeWire\LimeWire.ico
C:\Program Files\LimeWire\LimeWire.jar
C:\Program Files\LimeWire\LimeWire20.dll
C:\Program Files\LimeWire\log4j.jar
C:\Program Files\LimeWire\log4j.properties
C:\Program Files\LimeWire\looks.jar
C:\Program Files\LimeWire\MessagesBundle.properties
C:\Program Files\LimeWire\MessagesBundles.jar
C:\Program Files\LimeWire\mp3sp14.jar
C:\Program Files\LimeWire\pmf.ico
C:\Program Files\LimeWire\ProgressTabs.jar
C:\Program Files\LimeWire\root\magnet10\badge.img
C:\Program Files\LimeWire\root\magnet10\canHandle.img
C:\Program Files\LimeWire\root\magnet10\limewire.gif
C:\Program Files\LimeWire\root\magnet10\options.js
C:\Program Files\LimeWire\root\magnet10\silentdetect.js
C:\Program Files\LimeWire\SOURCE
C:\Program Files\LimeWire\spacer.gif
C:\Program Files\LimeWire\themes.jar
C:\Program Files\LimeWire\tritonus.jar
C:\Program Files\LimeWire\uninstall.exe
C:\Program Files\LimeWire\unpack.log
C:\Program Files\LimeWire\update.ver
C:\Program Files\LimeWire\vorbis.jar
C:\Program Files\LimeWire\WindowsFirewall.dll
C:\Program Files\LimeWire\WindowsV5PlusUtils.dll
C:\Program Files\LimeWire\xerces.jar
C:\Program Files\LimeWire\xml-apis.jar
C:\Program Files\LimeWire\xml.war
C:\Program Files\setup.exe
C:\Program Files\zmvcdgno
C:\Program Files\zmvcdgno\hmpajarw.dll
C:\WINDOWS\system32\drvcak.dll
C:\WINDOWS\system32\drvcakr.dll
C:\WINDOWS\system32\drvhor.dll
C:\WINDOWS\system32\drvhorr.dll
C:\WINDOWS\system32\drvleb.dll
C:\WINDOWS\system32\drvlebr.dll
C:\WINDOWS\system32\drvtax.dll
C:\WINDOWS\system32\drvtaxr.dll
C:\WINDOWS\system32\drvxaf.dll
C:\WINDOWS\system32\drvxafr.dll
((((((((((((((((((((((((( Files Created from 2007-08-04 to 2007-09-04 )))))))))))))))))))))))))))))))
2007-09-04 08:39 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-09-04 04:56 <DIR> d-------- C:\DOCUME~1\Liz\APPLIC~1\PlayFirst
2007-09-04 04:56 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\PlayFirst
2007-09-04 04:36 <DIR> d-------- C:\Program Files\ReflexiveArcade
2007-09-04 03:20 1,156 --a------ C:\WINDOWS\mozver.dat
2007-09-04 01:23 2,732 --a------ C:\WINDOWS\system32\tmp.reg
2007-09-04 01:22 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-09-04 01:22 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-09-04 01:22 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-09-04 00:54 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2007-09-03 12:35 <DIR> d-------- C:\DOCUME~1\LOCALS~1\APPLIC~1\WinRAR
2007-09-03 12:13 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-09-03 07:19 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll
2007-09-03 07:19 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
2007-09-03 06:40 <DIR> d-------- C:\DOCUME~1\Liz\APPLIC~1\Yahoo!
2007-09-03 06:40 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion
2007-09-03 05:31 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia
2007-09-03 05:31 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sandlot Games
2007-09-03 05:30 <DIR> d-------- C:\Program Files\Yahoo! Games
2007-09-03 05:30 <DIR> d-------- C:\Program Files\Yahoo!
2007-08-26 01:12 974,848 --a------ C:\WINDOWS\system32\mfc70.dll
2007-08-26 01:12 524,288 --a------ C:\WINDOWS\system32\xvidcore.dll
2007-08-26 01:12 487,424 --a------ C:\WINDOWS\system32\msvcp70.dll
2007-08-26 01:12 413,760 --a------ C:\WINDOWS\system32\mpg4c32.dll
2007-08-26 01:12 261,632 --a------ C:\WINDOWS\system32\mcdvd_32.dll
2007-08-26 01:12 24,576 --a------ C:\WINDOWS\system32\msxml3a.dll
2007-08-26 01:12 139,264 --a------ C:\WINDOWS\system32\xvidvfw.dll
2007-08-26 01:12 1,700,352 --a------ C:\WINDOWS\system32\GdiPlus.dll
2007-08-26 01:12 <DIR> d-------- C:\Program Files\Common Files\AVSMedia
2007-08-26 01:12 <DIR> d-------- C:\Program Files\AVSMedia
2007-08-22 00:48 <DIR> d-------- C:\Program Files\Common Files\Scanner
2007-08-19 06:06 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-08-19 06:05 <DIR> d-------- C:\Program Files\ReadWrite Korean
2007-08-16 09:57 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-08-15 17:29 <DIR> d-------- C:\Program Files\Windows Journal Viewer
2007-08-15 17:27 <DIR> d-------- C:\Program Files\MSN Messenger
2007-08-15 03:02 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2007-08-05 22:06 <DIR> d-------- C:\Program Files\Real Alternative
2007-08-05 22:06 <DIR> d-------- C:\Program Files\Media Player Classic
2007-08-05 22:06 <DIR> d-------- C:\DOCUME~1\Liz\APPLIC~1\Real
2007-08-05 22:06 <DIR> d-------- C:\DOCUME~1\Liz\APPLIC~1\Media Player Classic
2007-08-05 22:06 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Real
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-09-04 14:23 --------- d-------- C:\DOCUME~1\Liz\APPLIC~1\WTablet
2007-09-04 14:23 --------- d-------- C:\DOCUME~1\Liz\APPLIC~1\Skype
2007-08-26 01:06 --------- d-------- C:\DOCUME~1\Liz\APPLIC~1\DivX
2007-08-24 00:52 --------- d-------- C:\Program Files\mIRC
2007-08-22 00:48 --------- d-------- C:\Program Files\CA
2007-08-22 00:48 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\CA
2007-08-15 05:31 --------- d-------- C:\DOCUME~1\LOCALS~1\APPLIC~1\WTablet
2007-08-06 22:08 --------- d-------- C:\Program Files\DivX
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 207736 --a------ C:\WINDOWS\system32\muweb.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll
2007-07-26 19:06 9464 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-07-26 19:06 9336 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-07-26 19:06 524288 --a------ C:\WINDOWS\system32\DivXsm.exe
2007-07-26 19:06 43528 --------- C:\WINDOWS\system32\drivers\PxHelp20.sys
2007-07-26 19:06 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2007-07-26 19:06 200704 --a------ C:\WINDOWS\system32\ssldivx.dll
2007-07-26 19:06 144704 --a------ C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-07-26 19:06 129784 --------- C:\WINDOWS\system32\pxafs.dll
2007-07-26 19:06 120056 --------- C:\WINDOWS\system32\pxcpyi64.exe
2007-07-26 19:06 118520 --------- C:\WINDOWS\system32\pxinsi64.exe
2007-07-26 19:06 1044480 --a------ C:\WINDOWS\system32\libdivx.dll
2007-07-26 19:03 823296 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2007-07-26 19:03 823296 --a------ C:\WINDOWS\system32\divx_xx07.dll
2007-07-26 19:03 81920 --a------ C:\WINDOWS\system32\dpl100.dll
2007-07-26 19:03 802816 --a------ C:\WINDOWS\system32\divx_xx11.dll
2007-07-26 19:03 740442 --a------ C:\WINDOWS\system32\DivX.dll
2007-07-26 19:03 593920 --a------ C:\WINDOWS\system32\dpuGUI11.dll
2007-07-26 19:03 57344 --a------ C:\WINDOWS\system32\dpv11.dll
2007-07-26 19:03 53248 --a------ C:\WINDOWS\system32\dpuGUI10.dll
2007-07-26 19:03 344064 --a------ C:\WINDOWS\system32\dpus11.dll
2007-07-26 19:03 294912 --a------ C:\WINDOWS\system32\dpu11.dll
2007-07-26 19:03 294912 --a------ C:\WINDOWS\system32\dpu10.dll
2007-07-26 19:03 196608 --a------ C:\WINDOWS\system32\dtu100.dll
2007-07-26 19:03 12288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll
2007-07-25 03:40 --------- d-------- C:\Program Files\QuickTime
2007-07-25 03:40 --------- d-------- C:\Program Files\iTunes
2007-07-25 03:40 --------- d-------- C:\Program Files\iPod
2007-07-25 03:40 --------- d-------- C:\DOCUME~1\Liz\APPLIC~1\Apple Computer
2007-07-25 03:40 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
2007-07-25 03:39 --------- d-------- C:\Program Files\Apple Software Update
2007-07-25 03:38 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
2007-07-23 23:55 --------- d-------- C:\Program Files\TrueSwitch
2007-07-23 07:24 879832 --a------ C:\WINDOWS\system32\drivers\vetefile.sys
2007-07-23 07:24 108360 --a------ C:\WINDOWS\system32\drivers\veteboot.sys
2007-07-22 17:14 --------- d-------- C:\Program Files\XemiComputers
2007-07-22 17:14 --------- d-------- C:\DOCUME~1\Liz\APPLIC~1\XemiComputers
2007-07-22 17:14 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\XemiComputers
2007-07-22 17:10 --------- d-------- C:\Program Files\Software by Design
2007-07-18 02:39 --------- d-------- C:\DOCUME~1\Liz\APPLIC~1\Opera
2007-07-16 16:03 --------- d-------- C:\DOCUME~1\Liz\APPLIC~1\Google
2007-07-16 16:02 --------- d-------- C:\Program Files\Google
2007-07-10 17:01 --------- d-------- C:\Program Files\EPSON
2007-07-10 15:37 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-06-26 02:08 1104896 --a------ C:\WINDOWS\system32\msxml3.dll
2007-06-19 09:31 282112 --a------ C:\WINDOWS\system32\gdi32.dll
2007-06-13 06:23 1033216 --a------ C:\WINDOWS\explorer.exe
2003-06-20 03:05 49776 --a------ C:\WINDOWS\inf\usbhub20.sys
2003-06-20 03:05 24752 --a------ C:\WINDOWS\inf\hidclass.sys
2003-06-20 03:05 20688 --a------ C:\WINDOWS\inf\usbd.sys
2003-06-20 03:05 19728 --a------ C:\WINDOWS\inf\usbehci.sys
2003-06-20 03:05 138288 --a------ C:\WINDOWS\inf\usbport.sys
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="sttray.exe" []
"IntelAudioStudio"="C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" [2006-09-21 10:36]
"cctray"="C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe" [2007-09-03 02:09]
"CAVRID"="C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2007-05-16 09:24]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 12:22]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24]
"erelcnoh"="C:\Program Files\zmvcdgno\hmpajarw.dll" []
"pwhwlgxm"="regsvr32 /u C:\Documents and Settings\All Users\Application Data\pwhwlgxm.dll" []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-28 08:00]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-04-27 17:17]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-05-18 13:14]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54]
"Active Desktop Calendar"="C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe" [2007-05-10 11:24]
"BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" []
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]
NETGEAR WG111T Smart Wizard.lnk - C:\Program Files\NETGEAR\WG111T Configuration Utility\wlan111t.exe [2007-05-23 17:22:45]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Liz^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\Liz\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
C:\Program Files\Common Files\Adobe\Updater\AdobeUpdater.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
"C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
"C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus Photo R200 Series]
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE /P30 "EPSON Stylus Photo R200 Series" /O6 "USB001" /M "Stylus Photo R200"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NWEReboot]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
R3 AR5523;NETGEAR WG111T USB2.0 Wireless Card Service;C:\WINDOWS\system32\DRIVERS\wg11tnd5.sys
R3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;\??\C:\WINDOWS\system32\DNINDIS5.SYS
R3 PPCtlPriv;PPCtlPriv;"C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe"
R3 wacommousefilter;Wacom Mouse Filter Driver;C:\WINDOWS\system32\DRIVERS\wacommousefilter.sys
R3 wacomvhid;Wacom Virtual Hid Driver;C:\WINDOWS\system32\DRIVERS\wacomvhid.sys
S3 ATHFMWDL;NETGEAR WG111T bootloader driver;C:\WINDOWS\system32\Drivers\ATHFMWDL.sys
Contents of the 'Scheduled Tasks' folder
"2007-08-31 18:21:46 C:\WINDOWS\Tasks\CAAntiSpywareScan_Daily as Liz at 9 48 AM.job"
- C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAAntiSpyware.exe
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-09-04 14:22:02
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-09-04 14:36:38 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-09-04 14:36
C:\ComboFix2.txt ... 2007-09-04 08:59
--- E O F ---
Logfile of HijackThis v1.99.1
Scan saved at 3:03:18 PM, on 9/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\WTablet\TabUserW.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\NETGEAR\WG111T Configuration Utility\wlan111t.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\WINDOWS\system32\Tablet.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Liz\Desktop\HijackThis.exe
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [IntelAudioStudio] "C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" TRAY
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [erelcnoh] rundll32.exe "C:\Program Files\zmvcdgno\hmpajarw.dll",Init
O4 - HKLM\..\Run: [pwhwlgxm] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\pwhwlgxm.dll"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Active Desktop Calendar] C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NETGEAR WG111T Smart Wizard.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) -
http://www.slide.com...ageUploader.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) -
http://upload.facebo...otoUploader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) -
http://download.divx...owserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.mi...b?1187212866046
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) -
http://javadl-esd.su...ows-i586-jc.cab
O16 - DPF: {FFFFFFFF-CAFE-BABE-BABE-00AA0055595A} -
http://www.networkso...rueSwitchEC.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe