here is the combofix.txt
JD - 06-09-07 19:06:36.54
ComboFix 06.09.04BT - Running from: C:\Documents and Settings\JD\Desktop
Microsoft Windows XP [Version 5.1.2600]
((((((((((((((((((((((((((((((((((((((((((((( Look2Me's Log ))))))))))))))))))))))))))))))))))))))))))))))))))
REGISTRY ENTRIES REMOVED:
[HKEY_CLASSES_ROOT\CLSID\{1A873AE5-B9FB-4B86-A5B5-143442D28EB7}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{1A873AE5-B9FB-4B86-A5B5-143442D28EB7}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{1A873AE5-B9FB-4B86-A5B5-143442D28EB7}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{1A873AE5-B9FB-4B86-A5B5-143442D28EB7}\InprocServer32]
@="C:\\WINDOWS\\system32\\sdprv.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{CDDA789F-9BAB-4D12-8F05-6AA15B22F9C2}]
@=""
"IDEx"="AD"
[HKEY_CLASSES_ROOT\CLSID\{CDDA789F-9BAB-4D12-8F05-6AA15B22F9C2}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{CDDA789F-9BAB-4D12-8F05-6AA15B22F9C2}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{CDDA789F-9BAB-4D12-8F05-6AA15B22F9C2}\InprocServer32]
@="C:\\WINDOWS\\system32\\svncui.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{625DA14A-B827-4B0F-993F-5EDC692C03B8}]
@=""
"IDEx"="AD"
[HKEY_CLASSES_ROOT\CLSID\{625DA14A-B827-4B0F-993F-5EDC692C03B8}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{625DA14A-B827-4B0F-993F-5EDC692C03B8}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{625DA14A-B827-4B0F-993F-5EDC692C03B8}\InprocServer32]
@="C:\\WINDOWS\\system32\\tzpelib.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{D3F061FA-36FD-4839-8855-1E5A35FD9467}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{D3F061FA-36FD-4839-8855-1E5A35FD9467}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{D3F061FA-36FD-4839-8855-1E5A35FD9467}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{D3F061FA-36FD-4839-8855-1E5A35FD9467}\InprocServer32]
@="C:\\WINDOWS\\system32\\dfvoice.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{441379EA-EAB3-42D2-81BB-2C32C1259C48}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{441379EA-EAB3-42D2-81BB-2C32C1259C48}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{441379EA-EAB3-42D2-81BB-2C32C1259C48}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{441379EA-EAB3-42D2-81BB-2C32C1259C48}\InprocServer32]
@="C:\\WINDOWS\\system32\\rDsmontr.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{6212C207-B053-43D6-959C-9EDB65AF3959}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{6212C207-B053-43D6-959C-9EDB65AF3959}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{6212C207-B053-43D6-959C-9EDB65AF3959}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{6212C207-B053-43D6-959C-9EDB65AF3959}\InprocServer32]
@="C:\\WINDOWS\\system32\\asvpack.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\CLSID\{F49728FE-72CE-4C80-8816-1AA782B4F830}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{F49728FE-72CE-4C80-8816-1AA782B4F830}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{F49728FE-72CE-4C80-8816-1AA782B4F830}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{F49728FE-72CE-4C80-8816-1AA782B4F830}\InprocServer32]
@="C:\\WINDOWS\\system32\\hzcoin.dll"
"ThreadingModel"="Apartment"
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
Granting sedebugprivilege to Administrators ... successful
((((((((((((((((((((((((((((((((((((((((((((( Qoologic's Log )))))))))))))))))))))))))))))))))))))))))))))))))))
* * * PRE-RUN - Filepaths extracted from the Registry * * * * * * * * * * * * * * * * * * * * * *
O4 - HKEY_CURRENT_USER\...\Run C:\WINDOWS\system32\hnwmca.exe
O4 - HKEY_LOCAL_MACHINE\...\Run C:\WINDOWS\system32\hnwmca.exe
F2 -REG:system.ini: Shell C:\WINDOWS\system32\wxnqc.exe
F2 -REG:system.ini: UserInit C:\WINDOWS\system32\isutmfp.exe
* * * PRE-RUN - Filepaths extracted by Memory Dump * * * * * * * * * * * * * * * * * * * * * *
2006-09-05 15:13 127488 C:\WINDOWS\system32\hnwmca.exe
2006-09-05 15:13 51712 C:\WINDOWS\system32\nvwmtib.dll
2006-09-05 15:13 23552 C:\WINDOWS\system32\isutmfp.exe
2006-09-05 15:13 127488 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\yvjni.exe
2006-09-07 19:03 482 C:\WINDOWS\fjdst.dll
2006-09-06 09:20 127488 C:\WINDOWS\system32\mllpo.dat
2006-09-05 15:13 28672 C:\WINDOWS\system32\wxnqc.exe
* * * POST-RUN - Files in the Quarantine folder * * * * * * * * * * * * * * * * * * * * * * * * *
06-09-06 09:20 127488 mllpo.dat.qoo
06-09-05 15:13 127488 hnwmca.exe.qoo
06-09-05 15:13 51712 nvwmtib.dll.qoo
06-09-05 15:13 28672 wxnqc.exe.qoo
06-09-06 00:05 53 wwovpv.dat.qoo
DO NOT DELETE ANY FILES FROM THIS DIRECTORY UNLESS INSTRUCTED TO
((((((((((((((((((((((((((((((((((((((((((( E-Give / Ssk's Log )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Documents and Settings\JD\Application Data\Sskcwrd.dll
C:\Documents and Settings\JD\Application Data\Sskknwrd.dll
C:\Documents and Settings\JD\Application Data\Sskuknwrd.dll
C:\Documents and Settings\New\Application Data\Sskknwrd.dll
C:\Documents and Settings\New\Application Data\Sskuknwrd.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\teller2.chk
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\uninst104.exe
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Program Files\batty2
C:\Program Files\Deskbar
C:\Program Files\TheSearchAccelerator
C:\Program Files\Common Files\{008736E8-07E3-1033-0909-020209180001}
((((((((((((((((((((((((((((((( Files Created from 2006-08-07 to 2006-09-07 ))))))))))))))))))))))))))))))))))
2006-09-07 18:52 73,728 --a------ C:\WINDOWS\system32\pv.exe
2006-09-07 18:52 39,184 --a------ C:\WINDOWS\system32\Ntrights.exe
2006-09-07 18:52 175,616 --a------ C:\WINDOWS\system32\strings.exe
2006-09-07 18:52 16,384 --a------ C:\WINDOWS\system32\restart.exe
2006-09-07 18:52 126,976 --a------ C:\WINDOWS\system32\zip.exe
2006-09-07 18:52 11,254 --a------ C:\WINDOWS\system32\locate.com
2006-09-06 14:04 24,296 --a------ C:\WINDOWS\icont.exe
2006-09-06 01:01 61,952 --a------ C:\WINDOWS\system32\jir0dd51.dll
2006-09-06 01:01 1,233 --a------ C:\WINDOWS\system32\jir0dd51.sys
2006-09-06 00:08 29,696 --a------ C:\WINDOWS\system32\w1d7083a.dll
2006-09-06 00:00 53,120 --a------ C:\WINDOWS\srvcrxvkwb.exe
2006-09-06 00:00 48,190 --a------ C:\WINDOWS\RDFX4.exe
2006-09-06 00:00 36,608 --a------ C:\WINDOWS\nem220.dll
2006-09-06 00:00 215,308 --a------ C:\WINDOWS\srvwebchvq.exe
2006-09-05 22:42 8 --a------ C:\WINDOWS\syspol32.sys
2006-09-05 15:31 45,090 --a------ C:\WINDOWS\system32\omdsregj.exe
2006-09-05 15:14 928 --a------ C:\WINDOWS\system32\winpfg32.sys
2006-09-05 15:14 1,233 --a------ C:\WINDOWS\system32\qru08376.sys
2006-09-05 15:13 482 --a------ C:\WINDOWS\fjdst.dll
2006-09-05 15:13 23,552 --a------ C:\WINDOWS\system32\isutmfp.exe
2006-09-05 15:13 186,223 --a------ C:\WINDOWS\srvyteblbh.exe
2006-09-05 15:12 215,308 --a------ C:\WINDOWS\srvxtagzpz.exe
2006-09-05 15:12 192 --a------ C:\WINDOWS\system32\ggg.bat
2006-09-05 15:11 32,768 --a------ C:\WINDOWS\system32\setup9x.exe
2006-09-05 15:11 20,480 --a------ C:\WINDOWS\system32\dr.exe
2006-09-05 15:11 138,862 --a------ C:\WINDOWS\system32\install.exe
2006-09-03 20:44 9 --a------ C:\WINDOWS\winxfigt.sys
2006-08-31 14:19 0 --a------ C:\WINDOWS\b.exe
2006-08-21 13:48 53,248 --a------ C:\WINDOWS\uni_ehhhh.exe
2006-08-07 08:17 61,440 --a------ C:\WINDOWS\system32\BattyRun2.dll
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-09-07 19:09 -------- d-------- C:\Program Files\Common Files
2006-09-07 19:02 -------- d-------- C:\Program Files\Mozilla Firefox
2006-09-06 20:07 -------- d-------- C:\Program Files\Hijackthis
2006-09-06 15:41 -------- d-------- C:\Documents and Settings\JD\Application Data\Sun
2006-09-06 14:58 -------- d-------- C:\Program Files\XoftSpy
2006-09-06 14:54 -------- d-------- C:\Program Files\PartyGaming
2006-09-06 14:52 -------- d-------- C:\Program Files\Trillian
2006-09-06 14:51 -------- d-------- C:\Program Files\Sexy Party
2006-09-06 14:48 -------- d-------- C:\Program Files\QuickTime
2006-09-06 14:43 -------- d-------- C:\Program Files\Shareaza
2006-09-06 14:25 -------- d-------- C:\Program Files\LimeWire
2006-09-06 14:22 -------- d-------- C:\Documents and Settings\JD\Application Data\Macromedia
2006-09-06 14:22 -------- d-------- C:\Documents and Settings\JD\Application Data\LimeWire
2006-09-06 14:20 -------- d-------- C:\Program Files\Internet Optimizer
2006-09-06 14:19 -------- d--h----- C:\Documents and Settings\JD\Application Data\GTek
2006-09-06 14:19 -------- d---s---- C:\Documents and Settings\JD\Application Data\Microsoft
2006-09-06 14:19 -------- d-------- C:\Documents and Settings\JD\Application Data\AOL
2006-09-06 14:18 -------- d-------- C:\Documents and Settings\JD\Application Data\Identities
2006-09-06 14:08 -------- d-------- C:\Documents and Settings\JD\Application Data\Mozilla
2006-09-06 13:52 -------- d-------- C:\Documents and Settings\JD\Application Data\Media Player Classic
2006-09-06 10:22 -------- d-------- C:\Program Files\Lavasoft
2006-09-06 00:00 -------- d-------- C:\Program Files\Windows NT
2006-09-06 00:00 -------- d-------- C:\Program Files\MSN Gaming Zone
2006-09-06 00:00 -------- d-------- C:\Program Files\ComPlus Applications
2006-09-05 16:09 -------- d-------- C:\Program Files\Common Files\wqwu
2006-09-03 20:31 -------- d-------- C:\Program Files\ZPP
2006-09-01 08:42 -------- d-------- C:\Program Files\Internet Explorer
2006-08-31 14:05 -------- d-------- C:\Program Files\YourSiteBar
2006-08-18 14:13 -------- d-------- C:\Program Files\thriXXX
2006-08-05 07:40 -------- d-------- C:\Program Files\Absolute Poker
2006-08-05 07:36 -------- d-------- C:\Program Files\_uninstallation_info
2006-08-01 21:21 -------- d-------- C:\Program Files\America Online 9.0
2006-07-27 06:24 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-07-21 01:24 72704 --a------ C:\WINDOWS\system32\hlink.dll
2006-07-07 21:19 -------- d-------- C:\Program Files\Common Files\AOL
2006-07-07 21:19 -------- d-------- C:\Program Files\AOL
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"Cmaudio"="RunDll32 cmicnfg.cpl,CMICtrlWnd"
"AdBlocker"="C:\\Program Files\\3B Software\\3B Ad Blocker Pro\\AdBlocker.exe"
"SoundMan"="SOUNDMAN.EXE"
"HostManager"="C:\\Program Files\\Common Files\\AOL\\1124005563\\ee\\AOLSoftware.exe"
"AOLDialer"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"
"RealTray"="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe SYSTEMBOOTHIDEPLAYER"
"Pure Networks Port Magic"="\"C:\\PROGRA~1\\PURENE~1\\PORTMA~1\\PortAOL.exe\" -Run"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"IPHSend"="C:\\Program Files\\Common Files\\AOL\\IPHSend\\IPHSend.exe"
"qru08376"="RUNDLL32.EXE w140968e.dll,n 0040837200000003140968e"
"win32078861416"="C:\\WINDOWS\\win32078861416.exe"
"jir0dd51"="RUNDLL32.EXE w1d7083a.dll,n 0040dd4d000000031d7083a"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AOLCC"="\"C:\\Program Files\\AOL Computer Check-Up\\ACCAgnt.exe\" /startup"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,de,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,f2,01,00,00,b9,00,00,00,7c,00,00,00,72,00,\
00,00,01,00,00,00
Completion time: Thu 09/07/2006 19:10:54.67
ComboFix.txt
and here is the hijack report
Logfile of HijackThis v1.99.1
Scan saved at 7:14:12 PM, on 9/7/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\AOL\1124005563\ee\AOLSoftware.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\AOL Computer Check-Up\ACCAgnt.exe
c:\program files\common files\aol\1124005563\ee\services\antiSpywareApp\ver2_0_27_1\AOLSP Scheduler.exe
c:\program files\common files\aol\1124005563\ee\aolsoftware.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Hijackthis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.yahoo.com/R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://www.adnet-plus.com/banners.phpO4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [AdBlocker] C:\Program Files\3B Software\3B Ad Blocker Pro\AdBlocker.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1124005563\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [qru08376] RUNDLL32.EXE w140968e.dll,n 0040837200000003140968e
O4 - HKLM\..\Run: [win32078861416] C:\WINDOWS\win32078861416.exe
O4 - HKLM\..\Run: [jir0dd51] RUNDLL32.EXE w1d7083a.dll,n 0040dd4d000000031d7083a
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [AOLCC] "C:\Program Files\AOL Computer Check-Up\ACCAgnt.exe" /startup
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\nwinnpex.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for .UVR: C:\Program Files\Internet Explorer\Plugins\NPUPano.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3C200107-2959-4C6E-91B8-F6D911B398A8} (Driver_Detective_v43_Members.DD_v43) -
http://www.drivershq...v43_Members.CABO16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -
https://objects.aol....83/mcinsctl.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1120405854828O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} -
https://objects.aol....,20/McGDMgr.cabO18 - Filter: text/html - {994D478A-45D0-4DB4-AE27-738B1E346F99} - (no file)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe