Also, I get a RUNDLL message when I load up Windows that says: "Error loading C:\WINDOWS\system32\drvab.dll The specified module could not be found."
I'm sure this is just a product of us tearing out the bad stuff from my system, and what is left is searching desperately for itself, but I figured I'd mention it just in case.
Thanks
Here's the log
Jacob R - 06-11-30 23:18:36.48 Service Pack 2
ComboFix 06.11.27W - Running from: "C:\Documents and Settings\Jacob R\Desktop"
((((((((((((((((((((((((((((((((((((((((((((( Qoologic's Log )))))))))))))))))))))))))))))))))))))))))))))))))))
* * * POST-RUN - Files in the Quarantine folder * * * * * * * * * * * * * * * * * * * * * * * * *
DO NOT DELETE ANY FILES FROM THIS DIRECTORY UNLESS INSTRUCTED TO
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\keyboard1.dat
C:\WINDOWS\system32\issearch.exe
C:\Program Files\windows
C:\WINDOWS\system32\components
C:\Program Files\Common Files\{143BECB9-07CE-1033-0719-040403300001}
C:\Program Files\Common Files\{343BECB9-07CE-1033-0719-040403300001}
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\QooBox\Purity\Documents and Settings\Jacob R\Application Data\YSTEM~1
C:\QooBox\Purity\Documents and Settings\Jacob R\My Documents\CROSOF~1
C:\QooBox\Purity\Documents and Settings\Jacob R\My Documents\DOBE~1
C:\QooBox\Purity\Documents and Settings\Jacob R\My Documents\CROSOF~1\CROSOF~1
C:\QooBox\Purity\Documents and Settings\Jacob R\My Documents\CROSOF~1\dvdplay.exe
C:\QooBox\Purity\Program Files\WNSXS~1
C:\QooBox\Purity\Program Files\WNSXS~1\?ti2evxx.exe
((((((((((((((((((((((((((((((( Files Created from 2006-10-30 to 2006-11-30 ))))))))))))))))))))))))))))))))))
2006-11-29 20:27 56,320 --a------ C:\WINDOWS\system32\vgxhlxsk.dll
2006-11-29 10:21 53,248 --a------ C:\WINDOWS\system32\Process.exe
2006-11-29 10:21 40,960 --a------ C:\WINDOWS\system32\swsc.exe
2006-11-29 10:21 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2006-11-29 10:21 135,168 --a------ C:\WINDOWS\system32\swreg.exe
2006-11-29 09:47 <DIR> d-------- C:\VundoFix Backups
2006-11-28 21:55 <DIR> d-------- C:\Documents and Settings\Jacob R\Application Data\dvdcss
2006-11-27 19:41 88,340 --a------ C:\WINDOWS\system32\oglarloe.exe
2006-11-27 19:41 42,516 --a------ C:\WINDOWS\system32\iwddsnnf.dll
2006-11-27 19:41 <DIR> d-a------ C:\Program Files\VSAdd-in
2006-11-21 23:21 40,973 --------- C:\WINDOWS\system32\wvustrr.dll
2006-11-21 22:10 2 --a------ C:\WINDOWS\system32\wcpcc.exe
2006-11-21 21:44 <DIR> d-------- C:\WINDOWS\wkqk
2006-11-21 21:44 <DIR> d-------- C:\Program Files\Common Files\wkqk
2006-11-21 21:14 77,824 --a------ C:\WINDOWS\system32\fmrmhc.dll
2006-11-21 21:06 <DIR> d-------- C:\Program Files\Photoshop
2006-11-18 00:03 <DIR> d-------- C:\Program Files\Delta
2006-11-17 20:45 <DIR> d-------- C:\Documents and Settings\Jacob R\Application Data\fltk.org
2006-11-07 22:33 <DIR> d-------- C:\Program Files\Burning Crusade Closed Beta
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-11-30 23:20 -------- d-------- C:\Program Files\PeerGuardian2
2006-11-30 23:19 -------- d-------- C:\Program Files\Common Files
2006-11-30 21:51 -------- d-------- C:\Documents and Settings\Jacob R\Application Data\Hamachi
2006-11-30 14:35 -------- d-------- C:\Program Files\World of Warcraft
2006-11-30 14:31 -------- d-------- C:\Program Files\Steam
2006-11-29 09:13 -------- d-------- C:\Documents and Settings\Jacob R\Application Data\Azureus
2006-11-27 19:26 -------- d-------- C:\Program Files\ewido anti-malware
2006-11-22 00:06 -------- d-------- C:\Program Files\DAEMON Tools
2006-11-21 21:31 -------- d-------- C:\Program Files\Symantec
2006-11-21 07:22 -------- d-------- C:\Program Files\Trillian
2006-11-09 18:36 -------- d-------- C:\Documents and Settings\Jacob R\Application Data\Ventrilo
2006-11-09 16:24 -------- d-------- C:\Program Files\Common Files\AOL
2006-11-07 22:44 -------- d-------- C:\Program Files\Common Files\Blizzard Entertainment
2006-11-07 22:31 -------- d-------- C:\Program Files\AOL
2006-11-07 22:26 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-11-02 16:09 -------- d-------- C:\Program Files\Ventrilo
2006-10-18 22:42 -------- d-------- C:\Program Files\Google
2006-10-16 10:58 -------- d-------- C:\Program Files\Mozilla Firefox
2006-10-09 10:54 -------- d-------- C:\Documents and Settings\Jacob R\Application Data\Real
2006-10-09 10:54 -------- d-------- C:\Documents and Settings\Jacob R\Application Data\Media Player Classic
2006-10-09 10:41 -------- d-------- C:\Program Files\K-Lite Codec Pack
2006-10-03 20:05 -------- d-------- C:\Program Files\WebCamXP
2006-10-03 15:03 15440 --a------ C:\WINDOWS\system32\drivers\hamachi.sys
2006-09-28 12:05 5886725 --a------ C:\WINDOWS\PP.exe
2006-09-28 12:05 28672 --a------ C:\WINDOWS\system32\LicenceWM.exe
2006-09-25 14:43 98304 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2006-09-15 22:52 91904 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2006-09-13 22:14 593938 --a------ C:\WINDOWS\system32\x264vfw.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Bandwidth Monitor Pro"="\"C:\\Program Files\\Bandwidth Monitor Pro\\Bandwidth Monitor Pro.exe\" /minimized"
"Steam"="\"c:\\program files\\steam\\steam.exe\" -silent"
"PeerGuardian"="C:\\Program Files\\PeerGuardian2\\pg2.exe"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.0.720.3640\\GoogleToolbarNotifier.exe"
"Uble"="\"C:\\DOCUME~1\\JACOBR~1\\MYDOCU~1\\CROSOF~1\\dvdplay.exe\" -vt ndrv"
"Okkuv"="C:\\Program Files\\W?nSxS\\?ti2evxx.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"PtiuPbmd"="Rundll32.exe ptipbm.dll,SetWriteBack"
"ATICCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe\" runtime -Delay"
"Cmaudio"="RunDll32 cmicnfg.cpl,CMICtrlWnd"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"xload"="\"C:\\WINDOWS\\xload.exe\""
"Symantec NetDriver Monitor"="C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe /Consumer"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"CTHelper"="CTHELPER.EXE"
"Adobe Version Cue CS2"="\"C:\\Program Files\\Adobe\\Adobe Version Cue CS2\\ControlPanel\\VersionCueCS2Tray.exe\""
"Acrobat Assistant 7.0"="\"C:\\Program Files\\Adobe\\Adobe Acrobat 7.0\\Distillr\\Acrotray.exe\""
"WinVNC"="\"C:\\Program Files\\UltraVNC\\winvnc.exe\" -servicehelper"
"DAEMON Tools"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
"CTDrive"="rundll32.exe C:\\WINDOWS\\system32\\drvzab.dll,startup"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,c2,01,00,00,00,00,00,00,3e,03,00,00,c4,03,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,d2,03,00,00,23,00,00,00,1c,01,00,00,27,01,\
00,00,01,00,00,00
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
"{0bad5052-665d-40d4-a9bd-a2891eaafb42}"="boucicault"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{54D9498B-CF93-414F-8984-8CE7FDE0D391}"="ewido shell guard"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
"boucicault"="{0bad5052-665d-40d4-a9bd-a2891eaafb42}"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKLM"
"command"=""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"mschedsvc"=dword:00000003
"winvnc"=dword:00000002
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winrge32
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer - Jacob R.job
Completion time: 06-11-30 23:22:31.79
C:\ComboFix.txt ... 06-11-30 23:22