next log
Hi Shaba,
Thank you

.....below my combofix log, and then new HijackThis log in next reply
kmay - 06-11-12 8:07:20.04 Service Pack 2
ComboFix 06.11.9 - Running from: "C:\Program Files\Mozilla Firefox"
((((((((((((((((((((((((((((((((((((((((((((( Look2Me's Log ))))))))))))))))))))))))))))))))))))))))))))))))))
REGISTRY ENTRIES REMOVED:
[HKEY_CLASSES_ROOT\clsid\{6FC92228-AE4E-49D4-88C9-D310A5B7FB59}]
@=""
[HKEY_CLASSES_ROOT\clsid\{6FC92228-AE4E-49D4-88C9-D310A5B7FB59}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\clsid\{6FC92228-AE4E-49D4-88C9-D310A5B7FB59}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\clsid\{6FC92228-AE4E-49D4-88C9-D310A5B7FB59}\InprocServer32]
@="C:\\WINDOWS\\system32\\mmtask.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\clsid\{4D8167CA-0158-4629-A562-0006B8AA9F7C}]
@=""
[HKEY_CLASSES_ROOT\clsid\{4D8167CA-0158-4629-A562-0006B8AA9F7C}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\clsid\{4D8167CA-0158-4629-A562-0006B8AA9F7C}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\clsid\{4D8167CA-0158-4629-A562-0006B8AA9F7C}\InprocServer32]
@="C:\\WINDOWS\\system32\\mivcrt.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\clsid\{33235E92-9056-4F7C-A089-4AEE958A1E47}]
@=""
[HKEY_CLASSES_ROOT\clsid\{33235E92-9056-4F7C-A089-4AEE958A1E47}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\clsid\{33235E92-9056-4F7C-A089-4AEE958A1E47}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\clsid\{33235E92-9056-4F7C-A089-4AEE958A1E47}\InprocServer32]
@="C:\\WINDOWS\\system32\\unrcntra.dll"
"ThreadingModel"="Apartment"
[HKEY_CLASSES_ROOT\clsid\{B9764D5F-0868-4790-834C-A077C85CEC29}]
@=""
[HKEY_CLASSES_ROOT\clsid\{B9764D5F-0868-4790-834C-A077C85CEC29}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\clsid\{B9764D5F-0868-4790-834C-A077C85CEC29}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\clsid\{B9764D5F-0868-4790-834C-A077C85CEC29}\InprocServer32]
@="C:\\WINDOWS\\system32\\wepns.dll"
"ThreadingModel"="Apartment"
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
Granting sedebugprivilege to Administrators ... successful
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
C:\Program Files\Common Files\{2469B7A9-0258-1033-0423-040402110040}
C:\Program Files\Common Files\{2469B7A9-05DC-1033-0423-040402110040}
C:\Program Files\Common Files\{2469B7A9-05DD-1033-0423-040402110040}
C:\Program Files\Common Files\{3469B7A9-0258-1033-0423-040402110040}
C:\Program Files\Common Files\{3469B7A9-05DC-1033-0423-040402110040}
C:\Program Files\Common Files\{3469B7A9-05DD-1033-0423-040402110040}
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\QooBox\Purity\WINDOWS\MBOLS~1
C:\QooBox\Purity\WINDOWS\MBOLS~1\??mbols
C:\QooBox\Purity\WINDOWS\system32\RACLE~1
C:\QooBox\Purity\WINDOWS\system32\RACLE~1\?pool32.exe
((((((((((((((((((((((((((((((( Files Created from 2006-10-12 to 2006-11-12 ))))))))))))))))))))))))))))))))))
2006-10-26 19:24 57,384 --a------ C:\WINDOWS\system32\avsda.dll
2006-10-26 19:24 32,768 --a------ C:\WINDOWS\system32\drivers\avgntdd.sys
2006-10-26 19:24 14,848 --a------ C:\WINDOWS\system32\drivers\avgntmgr.sys
2006-10-26 18:34 684,032 --a------ C:\WINDOWS\system32\libeay32.dll
2006-10-26 18:34 155,648 --a------ C:\WINDOWS\system32\ssleay32.dll
2006-10-25 16:49 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2006-10-24 10:26 0 --a------ C:\WINDOWS\system32\hr4805hue.dll
2006-10-23 00:01 1,259 --a------ C:\WINDOWS\system32\dya32315.sys
2006-10-22 09:57 21,668 --a------ C:\cvmsfitp.exe
2006-10-22 09:28 76,560 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2006-10-22 09:25 2 --a------ C:\WINDOWS\system32\wcpsu.exe
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
Rootkit driver pe386 is present. A rootkit scan is required
2006-11-12 08:07 -------- d-------- C:\Program Files\Mozilla Firefox
2006-11-12 08:07 -------- d-------- C:\Program Files\Common Files
2006-11-11 19:23 -------- d-------- C:\Program Files\Windows Media Player
2006-11-11 19:23 -------- d-------- C:\Program Files\Messenger
2006-11-11 19:23 -------- d-------- C:\Program Files\GX25 Infrared-Handset Manager
2006-11-11 19:23 -------- d-------- C:\Program Files\Adobe
2006-11-11 19:21 -------- d-------- C:\Documents and Settings\kmay\Application Data\Adobe
2006-11-03 12:41 -------- d-------- C:\Documents and Settings\kmay\Application Data\ZoomBrowser EX
2006-11-02 17:43 -------- d-------- C:\Program Files\Yahoo!
2006-11-02 17:29 -------- dr-h----- C:\Documents and Settings\kmay\Application Data\yahoo!
2006-10-31 22:35 -------- d-------- C:\Documents and Settings\kmay\Application Data\Apple Computer
2006-10-29 17:16 -------- d-------- C:\Documents and Settings\kmay\Application Data\Flickr
2006-10-29 17:05 -------- d-------- C:\Program Files\Morpheus
2006-10-27 13:51 -------- d-------- C:\Program Files\Zone Labs
2006-10-26 21:29 -------- d-------- C:\Program Files\a-squared HiJackFree
2006-10-26 19:24 -------- d-------- C:\Program Files\AntiVir PersonalEdition Classic
2006-10-25 16:47 -------- d-------- C:\Program Files\Windows Defender
2006-10-24 01:02 -------- d-------- C:\Program Files\Webroot
2006-10-22 23:04 1085 --a------ C:\Documents and Settings\kmay\Application Data\AdobeDLM.log
2006-10-11 13:00 -------- d-------- C:\Documents and Settings\kmay\Application Data\AdobeUM
2006-10-11 12:52 0 --a------ C:\Documents and Settings\kmay\Application Data\dm.ini
2006-10-08 17:48 -------- d-------- C:\Program Files\Common Files\Canon
2006-10-07 20:43 -------- d-------- C:\Documents and Settings\kmay\Application Data\DataLayer
2006-09-29 12:19 -------- d-------- C:\Program Files\iPod
2006-09-29 12:18 -------- d-------- C:\Program Files\iTunes
2006-09-29 12:15 -------- d-------- C:\Program Files\Apple Software Update
2006-09-27 10:16 -------- d-------- C:\Documents and Settings\kmay\Application Data\Canon
2006-09-13 18:01 1084416 --a------ C:\WINDOWS\system32\msxml3.dll
2006-08-26 04:45 617472 --a------ C:\WINDOWS\system32\comctl32.dll
2006-08-22 00:21 16896 --a------ C:\WINDOWS\system32\fltlib.dll
2006-08-21 21:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe
2006-08-17 00:58 100352 --a------ C:\WINDOWS\system32\6to4svc.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Inpy"="C:\\WINDOWS\\system32\\?racle\\?pool32.exe"
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"AGRSMMSG"="AGRSMMSG.exe"
"ATIModeChange"="Ati2mdxx.exe"
"SynTPLpr"="\"C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe\""
"SynTPEnh"="\"C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe\""
"Smapp"="C:\\Program Files\\Analog Devices\\SoundMAX\\SMTray.exe"
"ASUS Live Update"="\"C:\\Program Files\\ASUS\\ASUS Live Update\\ALU.exe\""
"Power_Gear"="\"C:\\Progra~1\\ASUS\\Power4 Gear\\BatteryLife.exe\" 1"
"ATIPTA"="\"C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe\""
"type32"="\"C:\\Program Files\\Microsoft IntelliType Pro\\type32.exe\""
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
"avgnt"="\"C:\\Program Files\\AntiVir PersonalEdition Classic\\avgnt.exe\" /min"
"Zone Labs Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="C:\\Program Files\\MSN Gaming Zone\\vile.html"
"SubscribedURL"=""
"FriendlyName"=""
"Flags"=dword:00000000
"Position"=hex:2c,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,00,00,e8,\
03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,00,14,00,00,00
"CurrentState"=hex:01,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,\
00,00,01,00,00,40
"RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
"Source"="C:\\Program Files\\Windows NT\\sajywy.html"
"SubscribedURL"=""
"FriendlyName"=""
"Flags"=dword:00000000
"Position"=hex:2c,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,00,00,ea,\
03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,00,14,00,00,00
"CurrentState"=hex:01,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,\
00,00,01,00,00,40
"RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\2]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,fe,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,fe,02,\
00,00,04,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,fe,02,\
00,00,01,00,00,00
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
"UPnPMonitor"="{e57ce738-33e8-4c51-8354-bb4de9d215d1}"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="avgcc"
"hkey"="HKLM"
"command"="\"C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe\" /STARTUP"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DataLayer]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DATALA~1"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\COMMON~1\\PCSuite\\DATALA~1\\DATALA~1.EXE"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\defender]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="dfndrff_e35"
"hkey"="HKLM"
"command"="c:\\\\dfndrff_e35.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Hcontrol]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Hcontrol"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\ATK0100\\Hcontrol.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="dumprep 0 -k"
"hkey"="HKLM"
"command"="%systemroot%\\system32\\dumprep 0 -k"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\keyboard]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="kybrdff_e35"
"hkey"="HKLM"
"command"="C:\\\\kybrdff_e35.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="MsnMsgr"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\newname]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="nwnmff_e34"
"hkey"="HKLM"
"command"="C:\\\\nwnmff_e34.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="TRAYAP~1"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\Nokia\\NOKIAP~1\\TRAYAP~1.EXE"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ttool]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="9129837"
"hkey"="HKCU"
"command"="C:\\WINDOWS\\9129837.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\MP Scheduled Scan.job
Completion time: 06-11-12 8:09:53.05
C:\ComboFix.txt ... 06-11-12 08:09