ok heres the combo fix report
ComboFix 07-10-27.4 - Dan Nelson 2007-11-04 8:47:36.3 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ad-a war\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data.\dehwnaxq.dll
C:\Documents and Settings\Dan Nelson\Start Menu\Programs\Outerinfo
C:\Documents and Settings\Dan Nelson\Start Menu\Programs\Outerinfo\Terms.lnk
C:\Documents and Settings\Dan Nelson\Start Menu\Programs\Outerinfo\Uninstall.lnk
C:\Documents and Settings\Dan Nelson\Start Menu\Programs\Startup\TA_Start.lnk
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Documents and Settings\LocalService\Application Data\NetMon\domains.txt
C:\Documents and Settings\LocalService\Application Data\NetMon\log.txt
C:\Program Files\3721
C:\Program Files\3721\assist\asbar.dll
C:\Program Files\3721\helper.dll
C:\Program Files\Accoona
C:\Program Files\Accoona\ASearchAssist.dll
C:\Program Files\akl
C:\Program Files\akl\akl.dll
C:\Program Files\akl\akl.exe
C:\Program Files\akl\curlog.htm
C:\Program Files\akl\keylog.txt
C:\Program Files\akl\readme.txt
C:\Program Files\akl\uninstall.exe
C:\Program Files\akl\unsetup.dat
C:\Program Files\akl\unsetup.exe
C:\Program Files\amsys
C:\Program Files\amsys\awmsg.dat
C:\Program Files\amsys\guid.dat
C:\Program Files\amsys\ijl15.dll
C:\Program Files\amsys\mfc42.dll
C:\Program Files\amsys\msvcrt.dll
C:\Program Files\amsys\unins000.dat
C:\Program Files\amsys\unis000.exe
C:\Program Files\amsys\winam.dat
C:\Program Files\Common Files\Yazzle1162OinAdmin.exe
C:\Program Files\Common Files\Yazzle1162OinUninstaller.exe
C:\Program Files\e-zshopper
C:\Program Files\e-zshopper\BarLcher.dll
C:\Program Files\microsoft frontpage\rterter.html
C:\Program Files\network monitor
C:\Program Files\network monitor\netmon.exe
C:\Program Files\outerinfo
C:\Program Files\outerinfo\FF\chrome.manifest
C:\Program Files\outerinfo\FF\components\FF.dll
C:\Program Files\outerinfo\FF\components\OuterinfoAds.xpt
C:\Program Files\outerinfo\FF\install.rdf
C:\Program Files\outerinfo\Terms.rtf
C:\Program Files\p2pnetworks
C:\Program Files\p2pnetworks\amp2pl.exe
C:\Program Files\SecCenter
C:\Program Files\SecCenter\scprot4.exe
C:\WINDOWS\764.exe
C:\WINDOWS\7search.dll
C:\WINDOWS\aconti.exe
C:\WINDOWS\adbar.dll
C:\WINDOWS\cbinst$.exe
C:\WINDOWS\daxtime.dll
C:\WINDOWS\dp0.dll
C:\WINDOWS\eventlowg.dll
C:\WINDOWS\fhfmm-Uninstaller.exe
C:\WINDOWS\fhfmm.exe
C:\WINDOWS\flt.dll
C:\WINDOWS\hcwprn.exe
C:\WINDOWS\hotporn.exe
C:\WINDOWS\ie_32.exe
C:\WINDOWS\iexplorr23.dll
C:\WINDOWS\jd2002.dll
C:\WINDOWS\kkcomp$.exe
C:\WINDOWS\kkcomp.dll
C:\WINDOWS\kkcomp.exe
C:\WINDOWS\kvnab$.exe
C:\WINDOWS\kvnab.dll
C:\WINDOWS\kvnab.exe
C:\WINDOWS\liqad$.exe
C:\WINDOWS\liqad.dll
C:\WINDOWS\liqad.exe
C:\WINDOWS\liqui-Uninstaller.exe
C:\WINDOWS\liqui.dll
C:\WINDOWS\liqui.exe
C:\WINDOWS\ngd.dll
C:\WINDOWS\pbar.dll
C:\WINDOWS\pbsysie.dll
C:\WINDOWS\RGFuIE5lbHNvbg\asappsrv.dll
C:\WINDOWS\RGFuIE5lbHNvbg\command.exe
C:\WINDOWS\settn.dll
C:\WINDOWS\spredirect.dll
C:\WINDOWS\system32\.exe
C:\WINDOWS\system32\atmtd.dll
C:\WINDOWS\system32\atmtd.dll._
C:\WINDOWS\system32\bvgevqai
C:\WINDOWS\system32\bvgevqai\bg1.gif
C:\WINDOWS\system32\bvgevqai\bgtop.gif
C:\WINDOWS\system32\bvgevqai\bottom1.gif
C:\WINDOWS\system32\bvgevqai\bvgevqai1.exe
C:\WINDOWS\system32\bvgevqai\bvgevqai2.exe
C:\WINDOWS\system32\bvgevqai\bvgevqai3.exe
C:\WINDOWS\system32\bvgevqai\essentials.gif
C:\WINDOWS\system32\bvgevqai\icon1.ico
C:\WINDOWS\system32\bvgevqai\install1.gif
C:\WINDOWS\system32\bvgevqai\left1.gif
C:\WINDOWS\system32\bvgevqai\li.gif
C:\WINDOWS\system32\bvgevqai\logo.gif
C:\WINDOWS\system32\bvgevqai\main.htm
C:\WINDOWS\system32\bvgevqai\mainframe.htm
C:\WINDOWS\system32\bvgevqai\reinstall1.gif
C:\WINDOWS\system32\bvgevqai\right1.gif
C:\WINDOWS\system32\bvgevqai\s1.htm
C:\WINDOWS\system32\bvgevqai\s2.htm
C:\WINDOWS\system32\bvgevqai\s3.htm
C:\WINDOWS\system32\bvgevqai\SMTop1.gif
C:\WINDOWS\system32\bvgevqai\SMTop2.gif
C:\WINDOWS\system32\bvgevqai\SMTop3.gif
C:\WINDOWS\system32\bvgevqai\SMTop4.gif
C:\WINDOWS\system32\bvgevqai\soft1_off.gif
C:\WINDOWS\system32\bvgevqai\soft1_off_ext.gif
C:\WINDOWS\system32\bvgevqai\soft1_on.gif
C:\WINDOWS\system32\bvgevqai\soft1_on_ext.gif
C:\WINDOWS\system32\bvgevqai\soft2_off.gif
C:\WINDOWS\system32\bvgevqai\soft2_off_ext.gif
C:\WINDOWS\system32\bvgevqai\soft2_on.gif
C:\WINDOWS\system32\bvgevqai\soft2_on_ext.gif
C:\WINDOWS\system32\bvgevqai\soft3_off.gif
C:\WINDOWS\system32\bvgevqai\soft3_off_ext.gif
C:\WINDOWS\system32\bvgevqai\soft3_on.gif
C:\WINDOWS\system32\bvgevqai\soft3_on_ext.gif
C:\WINDOWS\system32\bvgevqai\softbottom_off.gif
C:\WINDOWS\system32\bvgevqai\softbottom_on.gif
C:\WINDOWS\system32\bvgevqai\softleft_off.gif
C:\WINDOWS\system32\bvgevqai\softleft_on.gif
C:\WINDOWS\system32\bvgevqai\top1.gif
C:\WINDOWS\system32\bvgevqai\top2.gif
C:\WINDOWS\system32\bvgevqai\turnoff1.gif
C:\WINDOWS\system32\bvgevqai\turnon1.gif
C:\WINDOWS\system32\dobe~1
C:\WINDOWS\system32\dobe~1\?hkntfs.exe
C:\WINDOWS\system32\drivers\blank.gif
C:\WINDOWS\system32\drivers\box_1.gif
C:\WINDOWS\system32\drivers\box_2.gif
C:\WINDOWS\system32\drivers\box_3.gif
C:\WINDOWS\system32\drivers\button_buynow.gif
C:\WINDOWS\system32\drivers\button_freescan.gif
C:\WINDOWS\system32\drivers\cell_bg.gif
C:\WINDOWS\system32\drivers\cell_footer.gif
C:\WINDOWS\system32\drivers\cell_header_block.gif
C:\WINDOWS\system32\drivers\cell_header_remove.gif
C:\WINDOWS\system32\drivers\cell_header_scan.gif
C:\WINDOWS\system32\drivers\detect.htm
C:\WINDOWS\system32\drivers\download_box.gif
C:\WINDOWS\system32\drivers\download_btn.jpg
C:\WINDOWS\system32\drivers\download_now_btn.gif
C:\WINDOWS\system32\drivers\footer_back.jpg
C:\WINDOWS\system32\drivers\header_1.gif
C:\WINDOWS\system32\drivers\header_2.gif
C:\WINDOWS\system32\drivers\header_3.gif
C:\WINDOWS\system32\drivers\header_4.gif
C:\WINDOWS\system32\drivers\header_red_bg.gif
C:\WINDOWS\system32\drivers\header_red_free_scan.gif
C:\WINDOWS\system32\drivers\header_red_free_scan_bg.gif
C:\WINDOWS\system32\drivers\header_red_protect_your_pc.gif
C:\WINDOWS\system32\drivers\infected.gif
C:\WINDOWS\system32\drivers\main_back.gif
C:\WINDOWS\system32\drivers\perfect_cleaner_box.jpg
C:\WINDOWS\system32\drivers\product_1_header.gif
C:\WINDOWS\system32\drivers\product_1_name_small.gif
C:\WINDOWS\system32\drivers\product_2_header.gif
C:\WINDOWS\system32\drivers\product_2_name_small.gif
C:\WINDOWS\system32\drivers\product_3_header.gif
C:\WINDOWS\system32\drivers\product_3_name_small.gif
C:\WINDOWS\system32\drivers\product_features.gif
C:\WINDOWS\system32\drivers\pt.htm
C:\WINDOWS\system32\drivers\rating.gif
C:\WINDOWS\system32\drivers\s_detect.htm
C:\WINDOWS\system32\drivers\screenshot.jpg
C:\WINDOWS\system32\drivers\sep_hor.gif
C:\WINDOWS\system32\drivers\sep_vert.gif
C:\WINDOWS\system32\drivers\shadow.jpg
C:\WINDOWS\system32\drivers\shadow_bg.gif
C:\WINDOWS\system32\drivers\spacer.gif
C:\WINDOWS\system32\drivers\spy_away_box.jpg
C:\WINDOWS\system32\drivers\star.gif
C:\WINDOWS\system32\drivers\star_gray.gif
C:\WINDOWS\system32\drivers\star_gray_small.gif
C:\WINDOWS\system32\drivers\star_small.gif
C:\WINDOWS\system32\drivers\style.css
C:\WINDOWS\system32\drivers\v.gif
C:\WINDOWS\system32\drivers\warning_icon.gif
C:\WINDOWS\system32\drivers\win_logo.gif
C:\WINDOWS\system32\drivers\x.gif
C:\WINDOWS\system32\drvhapr.dll
C:\WINDOWS\system32\ESHOPEE.exe
C:\WINDOWS\system32\iawl.dll
C:\WINDOWS\system32\ldcore.dll
C:\WINDOWS\system32\ldinfo.ldr
C:\WINDOWS\system32\msnav32.ax
C:\WINDOWS\system32\msole32.exe
C:\WINDOWS\system32\vxddsk.exe
C:\WINDOWS\system32\winrvc32.dll
C:\WINDOWS\system32\wml.exe
C:\WINDOWS\system32\wnsapisv.exe
C:\WINDOWS\uninstall_nmon.vbs
C:\WINDOWS\vxddsk.exe
C:\WINDOWS\wbeCheck.exe
C:\WINDOWS\wbeInst$.exe
C:\WINDOWS\wml.exe
C:\WINDOWS\wnsxs~1
C:\WINDOWS\wnsxs~1\msdtc.exe
C:\WINDOWS\wnsxs~1\W?nSxS\
C:\WINDOWS\xadbrk.dll
C:\WINDOWS\xadbrk.exe
C:\WINDOWS\xadbrk_.exe
C:\WINDOWS\xpupdate.exe
C:\WINDOWS\xxxvideo.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\LEGACY_CMDSERVICE
——-\LEGACY_NETWORK_MONITOR
——-\cmdService
——-\Network Monitor
((((((((((((((((((((((((( Files Created from 2007-10-04 to 2007-11-04 )))))))))))))))))))))))))))))))
.
2007-11-03 21:25 18,432 –a—— C:\WINDOWS\fkwggshm.exe
2007-11-03 21:22 d——– C:\Program Files\yhaxuxgh
2007-11-03 21:22 d——– C:\Program Files\Wjsltbcq
2007-11-03 21:22 36,864 –a—— C:\WINDOWS\system32\xxyywxx.dll
2007-11-03 21:21 104,960 –a—— C:\WINDOWS\system32\drvhap.dll
2007-11-03 21:09 4 –a—— C:\WINDOWS\system32\stfv.bin
2007-11-03 21:07 d——– C:\WINDOWS\system32\acespy
2007-11-03 21:07 16,640 –a—— C:\WINDOWS\system32\ace16win.dll
2007-10-30 19:23 12 –a—— C:\WINDOWS\system32\dpqaqlqx.bin
2007-10-30 19:22 d–hs—- C:\WINDOWS\RGFuIE5lbHNvbg
2007-10-30 19:22 123,908 –a—— C:\WINDOWS\system32\vvgeowbv.exe
2007-10-30 19:22 21,504 –a—— C:\WINDOWS\system32\aivskurq.dll
2007-10-28 19:14 d——– C:\Program Files\LBT
2007-10-28 10:29 d——– C:\Program Files\SUPERAntiSpyware
2007-10-28 10:29 d——– C:\Documents and Settings\Dan Nelson\Application Data\SUPERAntiSpyware.com
2007-10-28 10:29 d——– C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-10-26 22:13 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-10-26 22:13 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-10-26 18:20 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-10-26 11:46 4,528 –a—— C:\WINDOWS\system32\tmp.reg
2007-10-26 11:44 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2007-10-26 11:44 61,440 –a—— C:\WINDOWS\system32\Process.exe
2007-10-26 11:44 57,856 –a—— C:\WINDOWS\system32\dumphive.exe
2007-10-26 11:14 d——– C:\Program Files\Lavasoft
2007-10-26 11:14 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-10-26 11:12 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-10-25 19:37 d——– C:\VundoFix Backups
2007-10-09 13:17 584,192 ——— C:\WINDOWS\system32\dllcache\rpcrt4.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-04 16:56 ——— d—–w C:\Program Files\microsoft frontpage
2007-10-27 02:36 ——— d—–w C:\Program Files\QuickTime
2007-10-27 02:35 ——— d—–w C:\Program Files\Microsoft Streets & Trips
2007-10-27 02:35 ——— d—–w C:\Program Files\Microsoft Location Finder
2007-10-27 02:34 ——— d—–w C:\Program Files\ICopyDVDs2(2)
2007-10-27 02:34 ——— d—–w C:\Program Files\Easy Internet signup
2007-10-27 02:32 ——— d—–w C:\Program Files\AIM
2007-10-26 20:17 ——— d—–w C:\Program Files\Microsoft Works
2007-10-26 19:13 ——— d—–w C:\Documents and Settings\Dan Nelson\Application Data\Lavasoft
2007-10-19 02:33 ——— d—–w C:\Program Files\AirPort
2007-10-16 00:49 ——— d—–w C:\Documents and Settings\Emily\Application Data\U3
2007-09-12 14:05 ——— d—–w C:\Program Files\iTunes
2007-09-12 14:05 ——— d—–w C:\Program Files\iPod
2007-09-12 14:01 ——— d—–w C:\Program Files\Common Files\Apple
2007-09-09 01:07 ——— d—–w C:\Program Files\Joost
2007-08-22 13:12 474,112 ——w C:\WINDOWS\system32\dllcache\shlwapi.dll
2007-08-22 13:12 151,040 ——w C:\WINDOWS\system32\dllcache\cdfview.dll
2007-08-22 13:12 1,494,528 ——w C:\WINDOWS\system32\dllcache\shdocvw.dll
2007-08-22 13:12 1,054,208 ——w C:\WINDOWS\system32\dllcache\danim.dll
2007-08-22 13:12 1,022,976 ——w C:\WINDOWS\system32\dllcache\browseui.dll
2007-08-21 06:15 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-21 06:15 683,520 ——w C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-08-20 10:04 824,832 —-a-w C:\WINDOWS\system32\dllcache\wininet.dll
2007-08-20 10:04 671,232 —-a-w C:\WINDOWS\system32\dllcache\mstime.dll
2007-08-20 10:04 63,488 ——w C:\WINDOWS\system32\dllcache\icardie.dll
2007-08-20 10:04 6,058,496 ——w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-08-20 10:04 52,224 ——w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-08-20 10:04 477,696 —-a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-08-20 10:04 459,264 ——w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-08-20 10:04 44,544 ——w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-08-20 10:04 384,512 ——w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-08-20 10:04 383,488 ——w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-08-20 10:04 3,584,512 —-a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-08-20 10:04 27,648 —-a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-08-20 10:04 267,776 ——w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-08-20 10:04 232,960 ——w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-08-20 10:04 230,400 ——w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-08-20 10:04 214,528 —-a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-08-20 10:04 193,024 —-a-w C:\WINDOWS\system32\dllcache\msrating.dll
2007-08-20 10:04 153,088 ——w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-08-20 10:04 132,608 —-a-w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-08-20 10:04 124,928 ——w C:\WINDOWS\system32\dllcache\advpack.dll
2007-08-20 10:04 105,984 ——w C:\WINDOWS\system32\dllcache\url.dll
2007-08-20 10:04 102,400 ——w C:\WINDOWS\system32\dllcache\occache.dll
2007-08-20 10:04 1,152,000 —-a-w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-08-17 10:21 631,808 ——w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-08-17 10:20 70,144 ——w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-08-17 10:20 20,480 ——w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-08-17 07:34 161,792 ——w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-08-14 01:54 413,696 —-a-w C:\WINDOWS\system32\vbscript.dll
2007-08-14 01:54 413,696 ——w C:\WINDOWS\system32\dllcache\vbscript.dll
2007-08-14 01:54 33,792 —-a-w C:\WINDOWS\system32\dllcache\custsat.dll
2007-08-14 01:54 191,488 —-a-w C:\WINDOWS\system32\dllcache\iepeers.dll
2007-08-14 01:54 156,160 —-a-w C:\WINDOWS\system32\msls31.dll
2007-08-14 01:54 156,160 ——w C:\WINDOWS\system32\dllcache\msls31.dll
2007-08-14 01:45 78,336 —-a-w C:\WINDOWS\system32\ieencode.dll
2007-08-14 01:45 78,336 ——w C:\WINDOWS\system32\dllcache\ieencode.dll
2007-08-14 01:44 75,776 —-a-w C:\WINDOWS\system32\dllcache\iedw.exe
2007-08-14 01:44 40,960 —-a-w C:\WINDOWS\system32\licmgr10.dll
2007-08-14 01:44 40,960 ——w C:\WINDOWS\system32\dllcache\licmgr10.dll
2007-08-14 01:42 17,408 —-a-w C:\WINDOWS\system32\corpol.dll
2007-08-14 01:42 17,408 ——w C:\WINDOWS\system32\dllcache\corpol.dll
2007-08-14 01:39 92,672 —-a-w C:\WINDOWS\system32\dllcache\inseng.dll
2007-08-14 01:39 71,680 —-a-w C:\WINDOWS\system32\admparse.dll
2007-08-14 01:39 71,680 ——w C:\WINDOWS\system32\dllcache\admparse.dll
2007-08-14 01:39 55,296 —-a-w C:\WINDOWS\system32\iesetup.dll
2007-08-14 01:39 55,296 ——w C:\WINDOWS\system32\dllcache\iesetup.dll
2007-08-14 01:38 491,520 —-a-w C:\WINDOWS\system32\dllcache\jscript.dll
2007-08-14 01:36 44,544 —-a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-08-14 01:36 36,352 —-a-w C:\WINDOWS\system32\imgutil.dll
2007-08-14 01:36 36,352 ——w C:\WINDOWS\system32\dllcache\imgutil.dll
2007-08-14 01:35 346,624 —-a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-08-14 01:32 52,224 —-a-w C:\WINDOWS\system32\mshta.exe
2007-08-14 01:32 52,224 ——w C:\WINDOWS\system32\dllcache\mshta.exe
2007-08-14 01:18 60,416 ——w C:\WINDOWS\system32\dllcache\hmmapi.dll
2007-08-14 01:01 48,128 —-a-w C:\WINDOWS\system32\mshtmler.dll
2007-08-14 01:01 48,128 ——w C:\WINDOWS\system32\dllcache\mshtmler.dll
2005-07-29 23:24:26 472 –sha-r C:\WINDOWS\RGFuIE5lbHNvbg\l3IRKHc5vJhSv0.vbs
.
((((((((((((((((((((((((((((( snapshot@2007-10-26_19.58.04.93 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-07-12 23:28:55 765,952 —-a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\SP2QFE\vgx.dll
+ 2007-03-06 01:22:36 14,048 —-a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\spmsg.dll
+ 2007-03-06 01:22:41 213,216 —-a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\spuninst.exe
+ 2007-03-06 01:22:34 22,752 —-a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 —-a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\update\update.exe
+ 2007-03-06 01:23:51 371,424 —-a-w C:\WINDOWS\$hf_mig$\KB938127-IE7\update\updspapi.dll
+ 2007-08-20 10:02:09 124,928 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\advpack.dll
+ 2007-08-20 10:02:11 214,528 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\dxtrans.dll
+ 2007-08-20 10:02:09 132,608 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\extmgr.dll
+ 2007-08-20 10:02:09 63,488 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\icardie.dll
+ 2007-08-17 10:12:34 77,312 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\ie4uinit.exe
+ 2007-08-20 10:02:09 153,088 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\ieakeng.dll
+ 2007-08-20 10:02:09 230,400 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\ieaksie.dll
+ 2007-08-17 07:29:55 161,792 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\ieakui.dll
+ 2007-04-17 09:24:57 2,455,488 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\ieapfltr.dat
+ 2007-08-20 10:02:09 383,488 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\ieapfltr.dll
+ 2007-08-20 10:02:09 387,584 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\iedkcs32.dll
+ 2007-08-20 10:02:10 6,066,176 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\ieframe.dll
+ 2007-08-20 10:02:10 44,544 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\iernonce.dll
+ 2007-08-20 10:02:10 267,776 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\iertutil.dll
+ 2007-08-17 10:12:35 20,480 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\ieudinit.exe
+ 2007-08-17 10:12:49 631,808 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\iexplore.exe
+ 2007-08-20 10:02:10 27,648 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\jsproxy.dll
+ 2007-08-20 10:02:10 459,264 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\msfeeds.dll
+ 2007-08-20 10:02:10 52,224 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\msfeedsbs.dll
+ 2007-08-20 10:02:11 3,592,192 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\mshtml.dll
+ 2007-08-20 10:02:11 478,208 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\mshtmled.dll
+ 2007-08-20 10:02:11 193,024 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\msrating.dll
+ 2007-08-20 10:02:11 671,232 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\mstime.dll
+ 2007-08-20 10:02:11 102,400 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\occache.dll
+ 2007-08-20 10:02:11 105,984 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\url.dll
+ 2007-08-20 10:02:11 1,161,728 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\urlmon.dll
+ 2007-08-20 10:02:11 232,960 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\webcheck.dll
+ 2007-08-20 10:02:11 825,344 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\wininet.dll
+ 2007-03-06 01:22:36 14,048 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\spmsg.dll
+ 2007-03-06 01:22:41 213,216 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\spuninst.exe
+ 2007-03-06 01:22:34 22,752 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\update\spcustom.dll
+ 2007-03-06 01:22:59 716,000 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\update\update.exe
+ 2007-03-06 01:23:51 371,424 —-a-w C:\WINDOWS\$hf_mig$\KB939653-IE7\update\updspapi.dll
- 2007-10-26 16:51:17 145,920 —-a-w C:\WINDOWS\catchme.exe
+ 2007-10-26 17:51:17 136,192 —-a-w C:\WINDOWS\catchme.exe
- 2007-03-13 17:57:10 163,328 —-a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
+ 2007-03-13 18:57:10 163,328 —-a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
+ 2004-08-04 08:00:00 61,440 -c–a-w C:\WINDOWS\ie7\admparse.dll
+ 2004-08-04 08:00:00 99,840 -c–a-w C:\WINDOWS\ie7\advpack.dll
+ 2004-08-04 08:00:00 35,328 -c–a-w C:\WINDOWS\ie7\corpol.dll
+ 2004-08-11 08:45:04 28,672 -c–a-w C:\WINDOWS\ie7\custsat.dll
+ 2007-08-22 13:12:16 357,888 -c–a-w C:\WINDOWS\ie7\dxtmsft.dll
+ 2007-08-22 13:12:16 205,312 -c–a-w C:\WINDOWS\ie7\dxtrans.dll
+ 2007-08-22 13:12:16 55,808 -c–a-w C:\WINDOWS\ie7\extmgr.dll
+ 2004-08-04 08:00:00 40,960 -c–a-w C:\WINDOWS\ie7\ie4uinit.exe
+ 2004-08-04 08:00:00 139,264 -c–a-w C:\WINDOWS\ie7\ieakeng.dll
+ 2004-08-04 08:00:00 216,576 -c–a-w C:\WINDOWS\ie7\ieaksie.dll
+ 2004-08-04 08:00:00 221,184 -c–a-w C:\WINDOWS\ie7\ieakui.dll
+ 2004-08-04 08:00:00 323,584 -c–a-w C:\WINDOWS\ie7\iedkcs32.dll
+ 2007-08-21 10:30:45 25,088 -c–a-w C:\WINDOWS\ie7\iedw.exe
+ 2004-08-04 08:00:00 81,920 -c–a-w C:\WINDOWS\ie7\ieencode.dll
+ 2007-08-22 13:12:16 251,392 -c–a-w C:\WINDOWS\ie7\iepeers.dll
+ 2004-08-04 08:00:00 48,640 -c–a-w C:\WINDOWS\ie7\iernonce.dll
+ 2004-08-04 08:00:00 62,976 -c–a-w C:\WINDOWS\ie7\iesetup.dll
+ 2004-08-04 08:00:00 35,840 -c–a-w C:\WINDOWS\ie7\imgutil.dll
+ 2007-08-22 13:12:16 96,256 -c–a-w C:\WINDOWS\ie7\inseng.dll
+ 2006-05-18 05:24:25 450,560 -c–a-w C:\WINDOWS\ie7\jscript.dll
+ 2007-08-22 13:12:16 16,384 -c–a-w C:\WINDOWS\ie7\jsproxy.dll
+ 2004-08-04 08:00:00 22,016 -c–a-w C:\WINDOWS\ie7\licmgr10.dll
+ 2004-08-04 08:00:00 35,840 -c–a-w C:\WINDOWS\ie7\mshta.exe
+ 2007-08-22 13:12:17 3,058,176 -c–a-w C:\WINDOWS\ie7\mshtml.dll
+ 2007-08-22 13:12:17 449,024 -c–a-w C:\WINDOWS\ie7\mshtmled.dll
+ 2004-08-04 08:00:00 56,832 -c–a-w C:\WINDOWS\ie7\mshtmler.dll
+ 2004-08-04 08:00:00 146,432 -c–a-w C:\WINDOWS\ie7\msls31.dll
+ 2007-08-22 13:12:17 146,432 -c–a-w C:\WINDOWS\ie7\msrating.dll
+ 2007-08-22 13:12:17 532,480 -c–a-w C:\WINDOWS\ie7\mstime.dll
+ 2004-08-04 08:00:00 96,256 -c–a-w C:\WINDOWS\ie7\occache.dll
+ 2007-08-22 13:12:17 39,424 -c–a-w C:\WINDOWS\ie7\pngfilt.dll
+ 2007-08-14 01:54:42 32,960 -c–a-w C:\WINDOWS\ie7\spuninst\iecustom.dll
+ 2007-08-14 01:52:06 72,704 -c–a-w C:\WINDOWS\ie7\spuninst\ieResetIcons.exe
+ 2006-09-07 00:43:16 213,216 -c–a-w C:\WINDOWS\ie7\spuninst\spuninst.exe
+ 2006-09-07 00:43:18 371,424 -c–a-w C:\WINDOWS\ie7\spuninst\updspapi.dll
+ 2004-08-04 08:00:00 37,888 -c–a-w C:\WINDOWS\ie7\url.dll
+ 2007-08-22 13:12:18 615,424 -c–a-w C:\WINDOWS\ie7\urlmon.dll
+ 2004-08-04 08:00:00 417,792 -c–a-w C:\WINDOWS\ie7\vbscript.dll
+ 2007-06-26 15:13:22 851,968 -c–a-w C:\WINDOWS\ie7\vgx.dll
+ 2004-08-04 08:00:00 276,480 -c–a-w C:\WINDOWS\ie7\webcheck.dll
+ 2007-08-22 13:12:18 658,944 -c–a-w C:\WINDOWS\ie7\wininet.dll
+ 2007-03-06 01:22:41 213,216 -c—-w C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c—-w C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\updspapi.dll
+ 2007-08-14 01:54:10 765,952 -c—-w C:\WINDOWS\ie7updates\KB938127-IE7\vgx.dll
+ 2007-08-14 01:39:00 123,904 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\advpack.dll
+ 2007-08-14 01:35:38 214,528 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\dxtrans.dll
+ 2007-08-14 01:54:10 131,584 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\extmgr.dll
+ 2007-08-14 01:36:26 61,952 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\icardie.dll
+ 2007-08-14 01:39:06 61,440 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ie4uinit.exe
+ 2007-08-14 01:39:06 61,440 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ie4uinit.exe.000
+ 2007-08-14 01:39:26 152,064 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieakeng.dll
+ 2007-08-14 01:39:54 229,376 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieaksie.dll
+ 2007-08-14 00:56:54 161,792 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieakui.dll
+ 2007-02-12 23:10:12 2,451,312 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieapfltr.dat
+ 2007-07-11 19:27:48 383,488 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieapfltr.dll
+ 2007-08-14 01:39:50 382,976 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\iedkcs32.dll
+ 2007-08-14 01:54:10 6,049,280 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieframe.dll
+ 2007-08-14 01:39:10 43,008 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\iernonce.dll
+ 2007-08-14 01:34:04 266,752 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\iertutil.dll
+ 2007-08-14 01:39:10 19,968 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieudinit.exe
+ 2007-08-14 01:43:56 628,736 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\iexplore.exe
+ 2007-08-14 01:43:56 628,736 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\iexplore.exe.000
+ 2007-08-14 01:54:10 27,136 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\jsproxy.dll
+ 2007-08-14 01:54:10 458,752 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\msfeeds.dll
+ 2007-08-14 01:54:10 50,688 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\msfeedsbs.dll
+ 2007-08-14 01:54:12 3,578,368 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\mshtml.dll
+ 2007-08-14 01:54:10 475,648 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\mshtmled.dll
+ 2007-08-14 01:44:26 192,000 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\msrating.dll
+ 2007-08-14 01:54:10 670,720 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\mstime.dll
+ 2007-08-14 01:44:06 101,376 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\occache.dll
+ 2007-03-06 01:22:41 213,216 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\updspapi.dll
+ 2007-08-14 01:44:30 105,984 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\url.dll
+ 2007-08-14 01:54:10 1,162,240 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\urlmon.dll
+ 2007-08-14 01:54:10 231,424 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\webcheck.dll
+ 2007-08-14 01:54:10 818,688 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\wininet.dll
+ 2007-10-28 18:29:07 36,352 —-a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF11.exe
+ 2007-10-28 18:29:07 25,600 —-a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
+ 2007-10-28 18:29:07 71,680 —-a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
+ 2007-11-04 05:07:56 25,344 —-a-w C:\WINDOWS\system32\acespy\systune.exe
- 2004-08-04 08:00:00 99,840 —-a-w C:\WINDOWS\system32\advpack.dll
+ 2007-08-20 10:04:34 124,928 —-a-w C:\WINDOWS\system32\advpack.dll
- 2005-04-01 10:02:36 360,448 —-a-w C:\WINDOWS\system32\ati2evxx.exe
+ 2005-04-01 10:02:36 368,640 —-a-w C:\WINDOWS\system32\ati2evxx.exe
- 2007-10-27 02:49:41 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2007-11-04 16:59:26 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2007-10-27 02:49:41 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-11-04 16:59:26 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-10-27 02:49:41 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-11-04 16:59:26 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-04-17 09:32:38 2,455,488 ——w C:\WINDOWS\system32\dllcache\ieapfltr.dat
- 2007-06-26 15:13:22 851,968 ——w C:\WINDOWS\system32\dllcache\vgx.dll
+ 2007-07-12 23:31:54 765,952 —-a-w C:\WINDOWS\system32\dllcache\vgx.dll
- 2007-08-22 13:12:16 357,888 —-a-w C:\WINDOWS\system32\dxtmsft.dll
+ 2007-08-14 01:35:46 346,624 —-a-w C:\WINDOWS\system32\dxtmsft.dll
- 2007-08-22 13:12:16 205,312 —-a-w C:\WINDOWS\system32\dxtrans.dll
+ 2007-08-20 10:04:34 214,528 —-a-w C:\WINDOWS\system32\dxtrans.dll
- 2007-08-22 13:12:16 55,808 —-a-w C:\WINDOWS\system32\extmgr.dll
+ 2007-08-20 10:04:34 132,608 —-a-w C:\WINDOWS\system32\extmgr.dll
+ 2007-08-20 10:04:34 63,488 —-a-w C:\WINDOWS\system32\icardie.dll
+ 2006-06-29 15:05:44 26,112 ——w C:\WINDOWS\system32\idndl.dll
- 2004-08-04 08:00:00 40,960 —-a-w C:\WINDOWS\system32\ie4uinit.exe
+ 2007-08-17 10:20:54 70,144 —-a-w C:\WINDOWS\system32\ie4uinit.exe
- 2004-08-04 08:00:00 139,264 —-a-w C:\WINDOWS\system32\ieakeng.dll
+ 2007-08-20 10:04:34 153,088 —-a-w C:\WINDOWS\system32\ieakeng.dll
- 2004-08-04 08:00:00 216,576 —-a-w C:\WINDOWS\system32\ieaksie.dll
+ 2007-08-20 10:04:35 230,400 —-a-w C:\WINDOWS\system32\ieaksie.dll
- 2004-08-04 08:00:00 221,184 —-a-w C:\WINDOWS\system32\ieakui.dll
+ 2007-08-17 07:34:25 161,792 —-a-w C:\WINDOWS\system32\ieakui.dll
+ 2007-04-17 09:32:38 2,455,488 —-a-w C:\WINDOWS\system32\ieapfltr.dat
+ 2007-08-20 10:04:35 383,488 —-a-w C:\WINDOWS\system32\ieapfltr.dll
- 2004-08-04 08:00:00 323,584 —-a-w C:\WINDOWS\system32\iedkcs32.dll
+ 2007-08-20 10:04:35 384,512 —-a-w C:\WINDOWS\system32\iedkcs32.dll
+ 2007-08-20 10:04:37 6,058,496 —-a-w C:\WINDOWS\system32\ieframe.dll
- 2007-08-22 13:12:16 251,392 —-a-w C:\WINDOWS\system32\iepeers.dll
+ 2007-08-14 01:54:10 191,488 —-a-w C:\WINDOWS\system32\iepeers.dll
- 2004-08-04 08:00:00 48,640 —-a-w C:\WINDOWS\system32\iernonce.dll
+ 2007-08-20 10:04:38 44,544 —-a-w C:\WINDOWS\system32\iernonce.dll
+ 2007-08-20 10:04:38 267,776 —-a-w C:\WINDOWS\system32\iertutil.dll
+ 2007-08-17 10:20:54 20,480 —-a-w C:\WINDOWS\system32\ieudinit.exe
+ 2007-08-14 01:54:10 180,736 ——w C:\WINDOWS\system32\ieui.dll
- 2007-08-22 13:12:16 96,256 —-a-w C:\WINDOWS\system32\inseng.dll
+ 2007-08-14 01:39:02 92,672 —-a-w C:\WINDOWS\system32\inseng.dll
- 2006-05-18 05:24:25 450,560 —-a-w C:\WINDOWS\system32\jscript.dll
+ 2007-08-14 01:38:04 491,520 —-a-w C:\WINDOWS\system32\jscript.dll
- 2007-08-22 13:12:16 16,384 —-a-w C:\WINDOWS\system32\jsproxy.dll
+ 2007-08-20 10:04:39 27,648 —-a-w C:\WINDOWS\system32\jsproxy.dll
+ 2005-05-24 19:27:16 213,048 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 22:47:20 102,400 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 22:49:54 950,272 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
+ 2007-08-20 10:04:39 459,264 —-a-w C:\WINDOWS\system32\msfeeds.dll
+ 2007-08-20 10:04:39 52,224 —-a-w C:\WINDOWS\system32\msfeedsbs.dll
+ 2007-08-14 01:36:40 18,944 ——w C:\WINDOWS\system32\msfeedssync.exe
- 2007-08-22 13:12:17 3,058,176 —-a-w C:\WINDOWS\system32\mshtml.dll
+ 2007-08-20 10:04:41 3,584,512 —-a-w C:\WINDOWS\system32\mshtml.dll
- 2007-08-22 13:12:17 449,024 —-a-w C:\WINDOWS\system32\mshtmled.dll
+ 2007-08-20 10:04:41 477,696 —-a-w C:\WINDOWS\system32\mshtmled.dll
- 2007-08-22 13:12:17 146,432 —-a-w C:\WINDOWS\system32\msrating.dll
+ 2007-08-20 10:04:41 193,024 —-a-w C:\WINDOWS\system32\msrating.dll
- 2007-08-22 13:12:17 532,480 —-a-w C:\WINDOWS\system32\mstime.dll
+ 2007-08-20 10:04:42 671,232 —-a-w C:\WINDOWS\system32\mstime.dll
+ 2006-06-29 00:59:26 24,576 ——w C:\WINDOWS\system32\nlsdl.dll
+ 2006-06-29 15:05:44 23,552 ——w C:\WINDOWS\system32\normaliz.dll
- 2004-08-04 08:00:00 96,256 —-a-w C:\WINDOWS\system32\occache.dll
+ 2007-08-20 10:04:42 102,400 —-a-w C:\WINDOWS\system32\occache.dll
- 2007-03-28 23:24:03 54,010 —-a-w C:\WINDOWS\system32\perfc009.dat
+ 2007-11-04 16:38:52 54,010 —-a-w C:\WINDOWS\system32\perfc009.dat
- 2007-03-28 23:24:03 383,822 —-a-w C:\WINDOWS\system32\perfh009.dat
+ 2007-11-04 16:38:53 383,822 —-a-w C:\WINDOWS\system32\perfh009.dat
- 2007-08-22 13:12:17 39,424 —-a-w C:\WINDOWS\system32\pngfilt.dll
+ 2007-08-14 01:36:12 44,544 —-a-w C:\WINDOWS\system32\pngfilt.dll
- 2005-10-12 23:12:25 14,048 —-a-w C:\WINDOWS\system32\spmsg.dll
+ 2007-03-06 01:22:36 14,048 ——w C:\WINDOWS\system32\spmsg.dll
- 2005-06-10 23:53:32 57,856 —-a-w C:\WINDOWS\system32\spoolsv.exe
+ 2005-06-10 23:53:32 64,512 —-a-w C:\WINDOWS\system32\spoolsv.exe
- 2005-06-28 17:21:34 22,752 —-a-w C:\WINDOWS\system32\spupdsvc.exe
+ 2006-09-07 00:43:16 22,752 —-a-w C:\WINDOWS\system32\spupdsvc.exe
- 2007-07-23 01:39:27 289,280 —-a-w C:\WINDOWS\system32\swreg.exe
+ 2007-07-23 02:39:27 279,552 —-a-w C:\WINDOWS\system32\swreg.exe
- 2004-08-04 08:00:00 37,888 —-a-w C:\WINDOWS\system32\url.dll
+ 2007-08-20 10:04:42 105,984 —-a-w C:\WINDOWS\system32\url.dll
- 2007-08-22 13:12:18 615,424 —-a-w C:\WINDOWS\system32\urlmon.dll
+ 2007-08-20 10:04:42 1,152,000 —-a-w C:\WINDOWS\system32\urlmon.dll
- 2004-08-04 08:00:00 218,112 —-a-w C:\WINDOWS\system32\wbem\wmiprvse.exe
+ 2004-08-04 08:00:00 224,768 —-a-w C:\WINDOWS\system32\wbem\wmiprvse.exe
- 2005-01-28 21:44:28 38,912 —-a-w C:\WINDOWS\system32\wdfmgr.exe
+ 2005-01-28 21:44:28 45,568 —-a-w C:\WINDOWS\system32\wdfmgr.exe
- 2004-08-04 08:00:00 49,152 —-a-w C:\WINDOWS\system32\wdigest.dll
+ 2006-03-24 04:37:50 49,152 —-a-w C:\WINDOWS\system32\wdigest.dll
- 2004-08-04 08:00:00 276,480 —-a-w C:\WINDOWS\system32\webcheck.dll
+ 2007-08-20 10:04:42 232,960 —-a-w C:\WINDOWS\system32\webcheck.dll
+ 2007-08-14 01:45:16 212,992 ——w C:\WINDOWS\system32\WinFXDocObj.exe
- 2007-08-22 13:12:18 658,944 —-a-w C:\WINDOWS\system32\wininet.dll
+ 2007-08-20 10:04:43 824,832 —-a-w C:\WINDOWS\system32\wininet.dll
+ 2006-07-14 15:51:51 121,856 ——w C:\WINDOWS\system32\xmllite.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000000-d9e3-4bc6-a0bd-3d0ca4be5271}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000012-890e-4aac-afd9-eff6954a34dd}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{029e02f0-a0e5-4b19-b958-7bf2db29fb13}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06dfedaa-6196-11d5-bfc8-00508b4a487d}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1adbcce8-cf84-441e-9b38-afc7a19c06a4}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{391B174C-A6B7-C9D7-6743-01F7A0D663D6}]
2007-11-03 21:22 106496 –a—— C:\Program Files\Wjsltbcq\bgskgnpz.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{51641ef3-8a7a-4d84-8659-b0911e947cc8}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53C330D6-A4AB-419B-B45D-FD4411C1FEF4}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54645654-2225-4455-44A1-9F4543D34546}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{57F0A11D-9DE0-43A3-91FD-4DFCAEB67BB8}]
2007-08-02 05:43 282624 –a—— C:\Program Files\MSN\mezokepow555077.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{669695bc-a811-4a9d-8cdf-ba8c795f261e}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6abc861a-31e7-4d91-b43b-d3c98f22a5c0}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{89032A20-4370-487E-AB80-2251EC374249}]
2007-11-03 21:22 36864 –a—— C:\WINDOWS\system32\xxyywxx.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{944864a5-3916-46e2-96a9-a2e84f3f1208}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a4a435cf-3583-11d4-91bd-0048546a1450}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A6E432B4-D4C2-43B3-BF55-C364F8F7362A}]
2007-10-30 19:22 21504 –a—— C:\WINDOWS\system32\aivskurq.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b8875bfe-b021-11d4-bfa8-00508b8e9bd3}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c2680e10-1655-4a0e-87f8-4259325a84b7}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c4ca6559-2cf1-48b6-96b2-8340a06fd129}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c5af2622-8c75-4dfb-9693-23ab7686a456}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ca1d1b05-9c66-11d5-a009-000103c1e50b}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d8efadf1-9009-11d6-8c73-608c5dc19089}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9147a0a-a866-4214-b47c-da821891240f}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9306072-417e-43e3-81d5-369490beef7c}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-03-22 20:05]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe" [2005-03-04 02:36]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-04-11 14:21]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 22:11]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2005-02-02 04:12]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-02-02 04:11]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 12:24]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 12:54]
"EPSON Stylus CX3800 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.exe" [2005-02-07 11:00]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2006-01-06 11:07]
"HPHmon04"="C:\WINDOWS\system32\hphmon04.exe" [2006-01-06 11:07]
"HPHUPD04"="C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe" []
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 15:40]
"HostManager"="C:\Program Files\Common Files\AOL\1140899242\ee\AOLHostManager.exe" [2005-08-02 11:33]
"AIMPro"="C:\Program Files\AIM\AIM Pro\aimpro.exe" []
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe" [2006-09-14 06:55]
"AirPort Base Station Agent"="C:\Program Files\AirPort\APAgent.exe" [2007-07-11 15:54]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-07 15:55]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 05:24]
"{17-75-5B-BE-ZN}"="C:\Documents and Settings\Dan Nelson\Local Settings\Temp\T0CHD001.exe" [2007-10-30 19:21]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 08:24]
"Microsoft Location Finder"="C:\Program Files\Microsoft Location Finder\LocationFinder.exe" [2005-08-24 18:25]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-07-31 10:45]
"Nero PhotoShow Media Manager"="C:\PROGRA~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe" [2006-05-10 11:52]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-14 12:13]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:00]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 13:06]
"Tbsa"="C:\WINDOWS\WNSXS~1\msdtc.exe" []
"Kjwfty"="C:\WINDOWS\system32\?dobe\?hkntfs.exe" []
C:\Documents and Settings\Dan Nelson\Start Menu\Programs\Startup\
TA_Start.lnk - C:\Documents and Settings\Dan Nelson\Local Settings\Temp\T0CHD001.exe [2007-10-30 19:21:41]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
"{89032A20-4370-487E-AB80-2251EC374249}"= C:\WINDOWS\system32\xxyywxx.dll [2007-11-03 21:22 36864]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xxyywxx]
xxyywxx.dll 2007-11-03 21:22 36864 C:\WINDOWS\system32\xxyywxx.dll
.
Contents of the 'Scheduled Tasks' folder
"2007-10-20 19:41:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
"2007-10-27 16:08:24 C:\WINDOWS\Tasks\Symantec NetDetect.job"
.
**************************************************************************
catchme 0.3.1239 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-04 09:01:35
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
C:\WINDOWS\system32\msnav32.ax 17 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
Completion time: 2007-11-04 9:07:03 - machine was rebooted
C:\ComboFix2.txt … 2007-10-26 20:37
C:\ComboFix3.txt … 2007-10-26 19:00
.
— E O F —
heres the hjt report
Logfile of HijackThis v1.99.1
Scan saved at 9:08:51 AM, on 11/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymSCUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\WINDOWS\system32\hphmon04.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe
C:\Program Files\AirPort\APAgent.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\AOL\1140899242\ee\AOLHostManager.exe
C:\Program Files\Microsoft Location Finder\LocationFinder.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\AOL\1140899242\ee\AOLServiceHost.exe
C:\PROGRA~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\WINDOWS\system32\dwwin.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll
O2 - BHO: (no name) - {00000000-d9e3-4bc6-a0bd-3d0ca4be5271} - (no file)
O2 - BHO: (no name) - {00000012-890e-4aac-afd9-eff6954a34dd} - (no file)
O2 - BHO: (no name) - {029e02f0-a0e5-4b19-b958-7bf2db29fb13} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {06dfedaa-6196-11d5-bfc8-00508b4a487d} - (no file)
O2 - BHO: (no name) - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - (no file)
O2 - BHO: (no name) - {1adbcce8-cf84-441e-9b38-afc7a19c06a4} - (no file)
O2 - BHO: (no name) - {2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71} - (no file)
O2 - BHO: (no name) - {391B174C-A6B7-C9D7-6743-01F7A0D663D6} - C:\Program Files\Wjsltbcq\bgskgnpz.dll
O2 - BHO: (no name) - {51641ef3-8a7a-4d84-8659-b0911e947cc8} - (no file)
O2 - BHO: (no name) - {53C330D6-A4AB-419B-B45D-FD4411C1FEF4} - (no file)
O2 - BHO: (no name) - {54645654-2225-4455-44A1-9F4543D34546} - (no file)
O2 - BHO: (no name) - {57F0A11D-9DE0-43A3-91FD-4DFCAEB67BB8} - C:\Program Files\MSN\mezokepow555077.dll
O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file)
O2 - BHO: (no name) - {6abc861a-31e7-4d91-b43b-d3c98f22a5c0} - (no file)
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll
O2 - BHO: (no name) - {89032A20-4370-487E-AB80-2251EC374249} - C:\WINDOWS\system32\xxyywxx.dll
O2 - BHO: (no name) - {944864a5-3916-46e2-96a9-a2e84f3f1208} - (no file)
O2 - BHO: (no name) - {a4a435cf-3583-11d4-91bd-0048546a1450} - (no file)
O2 - BHO: aivskurq.msdn_hlp - {A6E432B4-D4C2-43B3-BF55-C364F8F7362A} - C:\WINDOWS\system32\aivskurq.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file)
O2 - BHO: (no name) - {c2680e10-1655-4a0e-87f8-4259325a84b7} - (no file)
O2 - BHO: (no name) - {c4ca6559-2cf1-48b6-96b2-8340a06fd129} - (no file)
O2 - BHO: (no name) - {c5af2622-8c75-4dfb-9693-23ab7686a456} - (no file)
O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file)
O2 - BHO: (no name) - {d8efadf1-9009-11d6-8c73-608c5dc19089} - (no file)
O2 - BHO: (no name) - {e9147a0a-a866-4214-b47c-da821891240f} - (no file)
O2 - BHO: (no name) - {e9306072-417e-43e3-81d5-369490beef7c} - (no file)
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [EPSON Stylus CX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE /P26 "EPSON Stylus CX3800 Series" /O6 "USB001" /M "Stylus CX3800"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\system32\hphmon04.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1140899242\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [AIMPro] "C:\Program Files\AIM\AIM Pro\aimpro.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe"
O4 - HKLM\..\Run: [AirPort Base Station Agent] "C:\Program Files\AirPort\APAgent.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [{17-75-5B-BE-ZN}] C:\Documents and Settings\Dan Nelson\Local Settings\Temp\T0CHD001.exe CHD001
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft Location Finder] "C:\Program Files\Microsoft Location Finder\LocationFinder.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Nero PhotoShow Media Manager] C:\PROGRA~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Tbsa] "C:\WINDOWS\WNSXS~1\msdtc.exe" -vt yazb
O4 - HKCU\..\Run: [Kjwfty] C:\WINDOWS\system32\?dobe\?hkntfs.exe
O4 - Startup: TA_Start.lnk = C:\Documents and Settings\Dan Nelson\Local Settings\Temp\T0CHD001.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 4.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=laptop
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {38F5F92F-BD40-40DF-A569-6C1FCB638190} (InSPECS3_0 Control) - http://www.powerleap.com/cab_files/InSPECS3_0.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: xxyywxx - C:\WINDOWS\SYSTEM32\xxyywxx.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\system32\HPHipm11.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
thanks!!