Here are the two logs... I will put combo fixes first, than Hijack this! My Computer froze halfway through a first combofix run, so I had to do a second one. This is the log from the second, so more couldve been deleted, or whatever else combofix does!!!!
ComboFix 07-10-12.4 - James 2007-10-12 13:11:21.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.24 [GMT -4:00]
Running from: C:\Documents and Settings\James\Local Settings\Temporary Internet Files\Content.IE5\W56FGHQV\ComboFix[1].exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\James\Application Data\WinTouch\config.cfg.04acfdb6317b640d7b7e685ccec82542
C:\Documents and Settings\James\Application Data\WinTouch\wintouch.cfg
C:\Documents and Settings\James\Application Data\WinTouch\WinTouch.exe
C:\Documents and Settings\James\Application Data\WinTouch\WTUninstaller.exe
C:\Documents and Settings\James\Start Menu\Programs\Outerinfo
C:\Documents and Settings\James\Start Menu\Programs\Startup\ta_start.lnk
C:\Documents and Settings\James\Start Menu\Programs\Startup\TA_Start.lnk
C:\Documents and Settings\James\Start Menu\Programs\Startup\think-adz.lnk
C:\WINDOWS\Downloaded Program Files\DinerDash.1.0.0.89
C:\WINDOWS\system32\accfe.bak2
C:\WINDOWS\system32\accfe.ini
C:\WINDOWS\system32\cbxwtrr.dll
C:\WINDOWS\system32\dwdsrngt.exe
C:\WINDOWS\system32\efcca.dll
C:\WINDOWS\system32\f02WtR
C:\WINDOWS\system32\msnav32.ax
C:\WINDOWS\system32\nwinomds.exe
C:\WINDOWS\system32\winpfz32.sys
C:\WINDOWS\system32\Z1
C:\WINDOWS\system32\zxdnt3d.cfg
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_CMDSERVICE
-------\LEGACY_DOMAINSERVICE
-------\LEGACY_NETWORK_MONITOR
-------\cmdService
-------\DomainService
-------\Network Monitor
((((((((((((((((((((((((( Files Created from 2007-09-12 to 2007-10-12 )))))))))))))))))))))))))))))))
.
2007-10-12 12:36 52,782 --a------ C:\WINDOWS\system32\lndsrngs.exe
2007-10-11 21:55 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-11 14:15 <DIR> d-------- C:\Program Files\Temporary
2007-10-11 12:18 <DIR> d-------- C:\WINDOWS\system32\vMW02a
2007-10-11 12:18 <DIR> d-------- C:\Temp\xOe
2007-10-09 22:37 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2007-10-09 22:37 <DIR> d-------- C:\WINDOWS\ehome
2007-10-09 22:30 5,504 --a------ C:\WINDOWS\system32\drivers\smbali.sys
2007-10-09 22:25 891,711 --a------ C:\WINDOWS\system32\drivers\nv4_mini.sys
2007-10-09 22:24 3,494,303 --a------ C:\WINDOWS\system32\nv4_disp.dll
2007-10-09 22:20 13,056 --a------ C:\WINDOWS\system32\drivers\wacompen.sys
2007-10-09 22:19 18,944 --a------ C:\WINDOWS\system32\faxpatch.exe
2007-10-09 22:19 11,904 --a------ C:\WINDOWS\system32\drivers\mutohpen.sys
2007-10-09 22:19 6,912 --a------ C:\WINDOWS\system32\drivers\hidir.sys
2007-10-09 22:18 63,663 --a------ C:\WINDOWS\system32\drivers\atinrvxx.sys
2007-10-09 22:18 36,463 --a------ C:\WINDOWS\system32\drivers\atintuxx.sys
2007-10-09 22:18 34,735 --a------ C:\WINDOWS\system32\drivers\atinxsxx.sys
2007-10-09 22:18 30,671 --a------ C:\WINDOWS\system32\drivers\atinraxx.sys
2007-10-09 22:18 29,455 --a------ C:\WINDOWS\system32\drivers\atinxbxx.sys
2007-10-09 22:18 26,367 --a------ C:\WINDOWS\system32\drivers\atinsnxx.sys
2007-10-09 22:18 21,343 --a------ C:\WINDOWS\system32\drivers\atinttxx.sys
2007-10-09 22:18 12,047 --a------ C:\WINDOWS\system32\drivers\atinpdxx.sys
2007-10-09 22:17 56,591 --a------ C:\WINDOWS\system32\drivers\atinbtxx.sys
2007-10-09 22:17 11,615 --a------ C:\WINDOWS\system32\drivers\atinmdxx.sys
2007-10-09 22:16 377,984 --a------ C:\WINDOWS\system32\ati2dvaa.dll
2007-10-09 22:16 327,040 --a------ C:\WINDOWS\system32\drivers\ati2mtaa.sys
2007-10-09 15:47 <DIR> d--hs---- C:\found.001
2007-10-08 23:22 313,856 --a------ C:\WINDOWS\system32\dx3j.dll
2007-10-08 23:22 171,280 --a------ C:\WINDOWS\system32\jit.dll
2007-10-08 23:22 139,536 --a------ C:\WINDOWS\system32\javaee.dll
2007-10-08 23:22 46,352 --a------ C:\WINDOWS\setdebug.exe
2007-10-08 23:22 6,550 --a------ C:\WINDOWS\jautoexp.dat
2007-10-08 20:23 184,320 --a------ C:\WINDOWS\system32\
0x2mbgOG.dll
2007-10-08 16:51 <DIR> d-------- C:\Program Files\ISM2
2007-10-08 10:29 7,395 --a------ C:\sysbxzg.exe
2007-10-07 16:44 35,840 --a------ C:\WINDOWS\tsitra72.exe
2007-10-07 14:46 <DIR> d-------- C:\Documents and Settings\James\Contacts
2007-10-07 14:45 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-10-07 14:43 184,320 --a------ C:\WINDOWS\system32\Nd264IaK.dll
2007-10-07 12:36 184,320 --a------ C:\WINDOWS\system32\
0od7yJIt.dll
2007-10-07 11:08 184,320 --a------ C:\WINDOWS\system32\3A41O046.dll
2007-10-06 22:09 463,168 -ra------ C:\WINDOWS\system32\drivers\ar5211.sys
2007-10-06 22:08 <DIR> d-------- C:\Program Files\Dynex Wireless G Adapter
2007-10-06 22:08 40,960 --a------ C:\WINDOWS\system32\WGNBC.dll
2007-10-06 22:08 17,801 --a------ C:\WINDOWS\system32\drivers\AegisP.sys
2007-10-06 17:55 94,208 --a------ C:\WINDOWS\system32\GTW32N50.dll
2007-10-06 17:55 15,872 --a------ C:\WINDOWS\system32\GTNDIS5.sys
2007-09-18 15:37 <DIR> d-------- C:\Program Files\Google
2007-09-18 15:36 <DIR> d-------- C:\Program Files\Picasa2
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-12 01:59 246 ----a-w C:\Program Files\Common Files\qubas
2007-10-09 03:25 --------- d-----w C:\Program Files\QuickTime
2007-10-07 18:46 --------- d-----w C:\Program Files\MSN Messenger
2007-10-07 14:36 --------- d-----w C:\Program Files\Common Files\Adobe
2007-10-06 22:48 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-09-01 02:59 --------- d-----w C:\Program Files\MSN Games
2007-09-01 02:30 --------- d-----w C:\Documents and Settings\LocalService\Application Data\NetMon
2006-12-05 02:47 42,264 ----a-w C:\Documents and Settings\Timmy\Application Data\GDIPFONTCACHEV1.DAT
2006-08-07 05:00 42,264 ----a-w C:\Documents and Settings\James\Application Data\GDIPFONTCACHEV1.DAT
2005-07-29 20:24:26 472 --sha-r C:\WINDOWS\SmFtZXM\mAIQtrg.vbs
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0E6BD8DE-4415-0FBB-6554-4E71B6769192}]
C:\WINDOWS\System32\nbhzbzs.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{13822A64-B4F2-857B-A73D-E82B5A9682CD}]
C:\WINDOWS\System32\acccd.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7923B4D4-31F5-4996-9F4A-0CD1D4DA4881}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{85589B5D-D53D-4237-A677-46B82EA275F3}]
2007-10-08 20:23 184320 --a------ C:\WINDOWS\System32\
0x2mbgOG.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8C6D5A56-791E-4fe8-9D64-81781FA15D68}]
C:\Program Files\ISM\BndDrive6.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{99C5FE5B-349C-2460-EC2C-3976166F56C9}]
C:\WINDOWS\System32\kxggeeot.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D52E4F35-EE1D-4086-4088-C729525854B8}]
C:\Program Files\Common Files\qubas.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"@"="" []
"PreloadApp"="c:\hp\drivers\printers\photosmart\hphprld.exe" [2001-12-12 11:05]
"{6E-EF-F7-78-ZN}"="c:\windows\system32\dwdsrngt.exe" [2007-10-12 13:23]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:54]
"Tza"="C:\WINDOWS\?asks\r?gedit.exe" []
"Aaou"="C:\WINDOWS\System32\PPPATC~1\winword.exe" []
"ISMModule6"="C:\Program Files\ISM\ISMModule6.exe" []
"ISMPack6"="C:\Program Files\ISM2\ISMPack6.exe" [2007-09-28 09:27]
"MSMSGS"="C:\Program Files\Messenger\MSMSGS.exe" [2004-11-15 16:18]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"<NO NAME>"=
C:\Documents and Settings\James\Start Menu\Programs\Startup\
TA_Start.lnk - C:\WINDOWS\system32\dwdsrngt.exe [2007-10-12 13:23:23]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\
0]
Source= C:\Program Files\Common Files\rtekehd.html
FriendlyName=
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Billminder.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Billminder.lnk
backup=C:\WINDOWS\pss\Billminder.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
backup=C:\WINDOWS\pss\Quicken Scheduled Updates.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Startup.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Startup.lnk
backup=C:\WINDOWS\pss\Quicken Startup.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
R1 cdudf_xp;cdudf_xp;C:\WINDOWS\System32\drivers\cdudf_xp.sys
R1 pwd_2k;pwd_2k;C:\WINDOWS\System32\drivers\pwd_2k.sys
R1 UdfReadr_xp;UdfReadr_xp;C:\WINDOWS\System32\drivers\UdfReadr_xp.sys
R2 CdaD10BA;CdaD10BA;\??\C:\WINDOWS\System32\drivers\CdaD10BA.SYS
R2 Dynex DX-WGNBC WLService;Dynex DX-WGNBC Service;C:\Program Files\Dynex Wireless G Adapter\WLService.exe
R2 StreamDispatcher;StreamDispatcher;C:\WINDOWS\System32\DRIVERS\strmdisp.sys
R3 CALIAUD;Conexant AMC 3D ENVIRONMENTAL AUDIO;C:\WINDOWS\System32\drivers\caliaud.sys
R3 CALIHALA;CALIHALA;C:\WINDOWS\System32\drivers\calihal.sys
R3 DKbFltr;Dritek HotKey Keyboard Filter Driver;C:\WINDOWS\System32\Drivers\DKbFltr.SYS
R3 DP83815;National Semiconductor Corp. DP83815/816 NDIS 5.0 Miniport Driver;C:\WINDOWS\System32\DRIVERS\DP83815.SYS
R3 mmc_2K;mmc_2K;C:\WINDOWS\System32\drivers\mmc_2K.sys
S3 ALiIRDA;ALi Infrared Device Driver;C:\WINDOWS\System32\DRIVERS\aliirda.sys
S3 allegro;ESS Allegro Audio Driver (WDM);C:\WINDOWS\System32\drivers\es198x.sys
S3 CE3;Xircom Ethernet Adapter 10/100 Service;C:\WINDOWS\System32\DRIVERS\ce3n5.sys
S3 dvd_2K;dvd_2K;C:\WINDOWS\System32\drivers\dvd_2K.sys
S3 ICAM5USB;Intel® PC Camera CS110;C:\WINDOWS\System32\Drivers\Icam5USB.sys
S3 LEX_NIC_SERVICE;IEEE 802.11 Wireless NIC Win2000 Driver;C:\WINDOWS\System32\DRIVERS\Express.sys
*Newly Created Service* - GTNDIS5
.
Contents of the 'Scheduled Tasks' folder
"2007-08-15 21:17:04 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job"
- C:\PROGRA~1\NORTON~1\NAVW32.exe
"2005-04-15 03:29:09 C:\WINDOWS\Tasks\Registration reminder 1.job"
- C:\WINDOWS\System32\OOBE\oobebaln.exe
"2005-04-15 03:29:10 C:\WINDOWS\Tasks\Registration reminder 2.job"
- C:\WINDOWS\System32\OOBE\oobebaln.exe
"2005-04-15 03:29:10 C:\WINDOWS\Tasks\Registration reminder 3.job"
- C:\WINDOWS\System32\OOBE\oobebaln.exe
"2005-08-29 01:01:23 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-10-12 13:22:15
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\WINDOWS\system32\dwdsrngt.exe
C:\WINDOWS\system32\msnav32.ax
C:\WINDOWS\system32\owinolds.exe
C:\WINDOWS\system32\winpfz32.sys
C:\WINDOWS\system32\zxdnt3d.cfg
scan completed successfully
hidden files: 5
**************************************************************************
.
Completion time: 2007-10-12 13:24:52 - machine was rebooted
.
--- E O F ---
=========================================================
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:26:27 PM, on 10/12/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Dynex Wireless G Adapter\WLService.exe
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\Dynex Wireless G Adapter\WLanCfgG.exe
C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\ISM2\ISMPack6.exe
C:\Program Files\Messenger\MSMSGS.EXE
c:\windows\system32\dwdsrngt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\owinolds.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\James\Desktop\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://store.presari...t...c02&lc=0409O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_6_2_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {0E6BD8DE-4415-0FBB-6554-4E71B6769192} - C:\WINDOWS\System32\nbhzbzs.dll (file missing)
O2 - BHO: (no name) - {13822A64-B4F2-857B-A73D-E82B5A9682CD} - C:\WINDOWS\System32\acccd.dll (file missing)
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - c:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: (no name) - {7923B4D4-31F5-4996-9F4A-0CD1D4DA4881} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: WebAssist - {85589B5D-D53D-4237-A677-46B82EA275F3} - C:\WINDOWS\System32\0x2mbgOG.dll
O2 - BHO: BndDrive2 BHO Class - {8C6D5A56-791E-4fe8-9D64-81781FA15D68} - C:\Program Files\ISM\BndDrive6.dll (file missing)
O2 - BHO: (no name) - {99C5FE5B-349C-2460-EC2C-3976166F56C9} - C:\WINDOWS\System32\kxggeeot.dll (file missing)
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: 0 - {D52E4F35-EE1D-4086-4088-C729525854B8} - C:\Program Files\Common Files\qubas.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_6_2_0.dll
O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
O4 - HKLM\..\Run: [{6E-EF-F7-78-ZN}] c:\windows\system32\dwdsrngt.exe CHD003
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Tza] C:\WINDOWS\?asks\r?gedit.exe
O4 - HKCU\..\Run: [Aaou] "C:\WINDOWS\System32\PPPATC~1\winword.exe" -vt yazb
O4 - HKCU\..\Run: [ISMModule6] "C:\Program Files\ISM\ISMModule6.exe"
O4 - HKCU\..\Run: [ISMPack6] "C:\Program Files\ISM2\ISMPack6.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\dwdsrngt.exe
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\owinolds.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: Advisor - {2516874A-8BF8-4FF9-865A-D7D5C67FFADE} - C:\Program Files\COMPAQ\Compaq Advisor\bin\rbaLauncher.exe (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=1c02&lc=0409
O15 - Trusted Zone: *.drivecleaner.com
O15 - Trusted Zone: *.errorprotector.com
O15 - Trusted Zone: *.systemdoctor.com
O15 - Trusted Zone: *.winantispyware.com
O15 - Trusted Zone: *.winantivirus.com
O15 - Trusted Zone: *.drivecleaner.com (HKLM)
O15 - Trusted Zone: *.errorprotector.com (HKLM)
O15 - Trusted Zone: *.systemdoctor.com (HKLM)
O15 - Trusted Zone: *.winantispyware.com (HKLM)
O15 - Trusted Zone: *.winantivirus.com (HKLM)
O16 - DPF: Yahoo! Pool 2 -
http://download2.gam...ts/y/poti_x.cabO16 - DPF: Yahoo! Pyramids -
http://download2.gam...ts/y/pyt1_x.cabO16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) -
http://zone.msn.com/...UI.cab46479.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} -
http://www.driveclea...leanerstart.cabO16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (ZoneBuddy Class) -
http://zone.msn.com/...dy.cab32846.cabO16 - DPF: {3FE16C08-D6A7-4133-84FC-D5BFB4F7D886} (WebGameLoader Class) -
http://zone.msn.com/...bGameLoader.cabO16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) -
http://zone.msn.com/...at.cab32846.cabO16 - DPF: {8C279F4E-917E-4CD2-8DF0-D9C73C0CE763} (ZPA_WheelOfFortune Object) -
http://zone.msn.com/...of.cab40641.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn...pDownloader.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://cdn2.zone.msn...ro.cab53083.cabO16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (StadiumProxy Class) -
http://zone.msn.com/...xy.cab41227.cabO16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} (CPlayFirstDinerDashControl Object) -
http://zone.msn.com/...sh.1.0.0.89.cabO16 - DPF: {DD8C9372-35FD-4F7D-8CE4-909ABCFAB2C5} - ms-its:mhtml:file://c:\\nores.mht!
http://adxtnet.net/c...::/xpreload.ocxO16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -
http://download.game...aploader_v6.cabO16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) -
http://fdl.msn.com/z...s/heartbeat.cabO20 - AppInit_DLLs:
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Dynex DX-WGNBC Service (Dynex DX-WGNBC WLService) - Unknown owner - C:\Program Files\Dynex Wireless G Adapter\WLService.exe
O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O24 - Desktop Component 0: (no name) - C:\Program Files\Common Files\rtekehd.html
--
End of file - 9319 bytes
Thank you for your continuing help!!!
Edited by mandy_1803, 12 October 2007 - 08:31 PM.