"slim" - 07-01-24 15:57:32 Service Pack 2
ComboFix 07-01-23.2 - Running from: "C:\Documents and Settings\slim\My Documents\download"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\DOCUME~1
C:\qoobox\purity\WINDOWS\ICROSO~1
C:\qoobox\purity\WINDOWS\system32\DOBE~1
C:\qoobox\purity\WINDOWS\system32\FNTS~1
C:\qoobox\purity\Program Files\SMBOLS~1
C:\qoobox\purity\Program Files\Common Files\MCROSO~1.NET
C:\qoobox\purity\Program Files\Common Files\YSTEM~1
C:\qoobox\purity\DOCUME~1\slim
C:\qoobox\purity\DOCUME~1\slim\Application Data
C:\qoobox\purity\DOCUME~1\slim\My Documents
C:\qoobox\purity\DOCUME~1\slim\Application Data\from.txt
C:\qoobox\purity\DOCUME~1\slim\Application Data\DOBE~1
C:\qoobox\purity\DOCUME~1\slim\Application Data\ICROSO~1
C:\qoobox\purity\DOCUME~1\slim\Application Data\WNSXS~1
C:\qoobox\purity\DOCUME~1\slim\Application Data\STEM32~1
C:\qoobox\purity\DOCUME~1\slim\Application Data\WNSXS~1\W?nSxS
C:\qoobox\purity\DOCUME~1\slim\Application Data\WNSXS~1\W?nSxS\!update-4300.0000
C:\qoobox\purity\DOCUME~1\slim\My Documents\from.txt
C:\qoobox\purity\DOCUME~1\slim\My Documents\SMBOLS~1
C:\qoobox\purity\DOCUME~1\slim\My Documents\FNTS~1
((((((((((((((((((((((((((((((( Files Created from 2006-12-24 to 2007-01-24 ))))))))))))))))))))))))))))))))))
2007-01-23 22:47 79,360 --a------ C:\WINDOWS\system32\swxcacls.exe
2007-01-23 22:47 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-01-23 22:47 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-01-23 22:47 40,960 --a------ C:\WINDOWS\system32\swsc.exe
2007-01-23 22:47 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-01-23 22:47 135,168 --a------ C:\WINDOWS\system32\swreg.exe
2007-01-22 18:42 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-01-22 17:50 7,830 --a------ C:\WINDOWS\system32\tmp.reg
2007-01-22 14:54 <DIR> d-------- C:\DOCUME~1\slim\SmitfraudFix
2007-01-22 01:15 3,120 --a------ C:\WINDOWS\system32\2d2ca2ce-704a-428c-8cbe-0736b29190aa.dll
2007-01-22 01:13 <DIR> d-------- C:\Program Files\AARONS CLIKER
2007-01-22 00:12 <DIR> d-------- C:\Program Files\Sunbelt Software
2007-01-21 21:34 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll
2007-01-21 21:32 <DIR> d-------- C:\WINDOWS\Internet Logs
2007-01-21 20:59 <DIR> d-------- C:\Program Files\HOSTS Secure
2007-01-21 20:50 21,312 --a------ C:\WINDOWS\choice.exe
2007-01-21 20:43 <DIR> d-------- C:\ie-spyad2
2007-01-21 20:35 <DIR> d-------- C:\Program Files\SpywareGuard
2007-01-21 20:30 <DIR> d-------- C:\Program Files\SpywareBlaster
2007-01-21 19:28 <DIR> d-------- C:\Program Files\Hijackthis
2007-01-21 14:43 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2007-01-21 11:36 <DIR> d-------- C:\Program Files\Registry Defender
2007-01-20 14:42 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Spybot - Search & Destroy
2007-01-20 14:25 76,560 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2007-01-20 14:23 <DIR> d-------- C:\DOCUME~1\slim\.housecall6.6
2007-01-17 15:52 <DIR> d-------- C:\DOCUME~1\slim\Application Data\AVG7
2007-01-17 15:50 <DIR> d-------- C:\DOCUME~1\LOCALS~1\Application Data\AVG7
2007-01-17 03:39 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Avg7
2007-01-11 17:35 <DIR> d-------- C:\DOCUME~1\slim\Application Data\ZangoToolbar
2007-01-11 17:34 39,936 --a------ C:\npclntax.dll
2007-01-11 13:50 <DIR> d-------- C:\DOCUME~1\slim\Application Data\Viewpoint
2007-01-10 03:00 <DIR> d-------- C:\WINDOWS\ie7updates
2007-01-07 22:55 28,672 --a------ C:\WINDOWS\system32\f3PSSavr.scr
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-12-19 01:30 2 --a------ C:\WINDOWS\system32\wapisvit.exe
2006-12-15 22:08 -------- d-------- C:\Program Files\windows live toolbar
2006-12-07 17:11 -------- d-------- C:\Program Files\yahoo!
2006-11-23 15:59 131072 --a------ C:\WINDOWS\system32\spoonuninstall.exe
2006-11-08 00:06 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-11-07 21:03 6049280 --a------ C:\WINDOWS\system32\ieframe.dll
2006-11-07 21:03 50688 --a------ C:\WINDOWS\system32\msfeedsbs.dll
2006-11-07 21:03 458752 --a------ C:\WINDOWS\system32\msfeeds.dll
2006-11-07 21:03 413696 --a------ C:\WINDOWS\system32\vbscript.dll
2006-11-07 21:03 231424 --a------ C:\WINDOWS\system32\webcheck.dll
2006-11-07 21:03 180736 --a------ C:\WINDOWS\system32\ieui.dll
2006-11-07 21:03 156160 --a------ C:\WINDOWS\system32\msls31.dll
2006-11-07 03:27 382976 --a------ C:\WINDOWS\system32\iedkcs32.dll
2006-11-07 03:27 229376 --a------ C:\WINDOWS\system32\ieaksie.dll
2006-11-07 03:26 71680 --a------ C:\WINDOWS\system32\admparse.dll
2006-11-07 03:26 55296 --a------ C:\WINDOWS\system32\iesetup.dll
2006-11-07 03:26 54784 --a------ C:\WINDOWS\system32\ie4uinit.exe
2006-11-07 03:26 43008 --a------ C:\WINDOWS\system32\iernonce.dll
2006-11-07 03:26 152064 --a------ C:\WINDOWS\system32\ieakeng.dll
2006-11-07 03:26 13312 --a------ C:\WINDOWS\system32\ieudinit.exe
2006-11-07 03:26 123904 --a------ C:\WINDOWS\system32\advpack.dll
2006-11-07 03:25 161792 --a------ C:\WINDOWS\system32\ieakui.dll
2006-11-04 14:14 1245696 --a------ C:\WINDOWS\system32\msxml4.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"Rguzmxn"="C:\\Documents and Settings\\slim\\Application Data\\?dobe\\r?ndll.exe"
"Yahoo! Pager"="\"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe\" -quiet"
"windowinside"="C:\\DOCUME~1\\slim\\APPLIC~1\\FOURPL~1\\DebugStop.exe"
"tbon"="C:\\Program Files\\TBONBin\\tbon.exe /r"
"Skype"="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"
"PhotoShow Deluxe Media Manager"="C:\\PROGRA~1\\SIMPLE~1\\PHOTOS~1\\data\\Xtras\\mssysmgr.exe"
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"Ltho"="\"C:\\DOCUME~1\\slim\\APPLIC~1\\WNSXS~1\\arpa.exe\" -vt tzt"
"ErrorSafeFree"="\"C:\\Program Files\\ErrorSafe Free\\uers.exe\" /min"
"ErrorSafe"="C:\\Program Files\\Error Safe\\ERS.exe /min"
"Aim6"="\"C:\\Program Files\\AIM6\\aim6.exe\" /d locale=en-US ee://aol/imApp"
"AdwareProtector"="C:\\Program Files\\Error Safe\\AdwareProtector.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"My Web Search Bar Search Scope Monitor"="\"C:\\PROGRA~1\\MYWEBS~1\\bar\\1.bin\\m3SrchMn.exe\" /m=0"
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
"zBrowser Launcher"="C:\\Program Files\\Logitech\\iTouch\\iTouch.exe"
"zango"="\"c:\\program files\\zango\\zango.exe\""
"WinDVR SchSvr"="\"C:\\Program Files\\Common Files\\InterVideo\\SchSvr\\SchSvr.exe\""
"wcmdmgr"="C:\\WINDOWS\\wt\\updater\\wcmdmgrl.exe -launch"
"was_check"="C:\\Program Files\\ErrorSafe Free\\PASmon.exe"
"VTTimer"="VTTimer.exe"
"VC5Player"="C:\\Program Files\\HHVcdV5Sys\\VC5Play.exe"
"UERScw"="C:\\Program Files\\ErrorSafe Free\\UERScw.exe -c"
"Typehidetonsace"="C:\\Documents and Settings\\All Users\\Application Data\\Movecreativetypehide\\kind 32.exe"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"SSBkgdUpdate"="\"C:\\Program Files\\Common Files\\Scansoft Shared\\SSBkgdUpdate\\SSBkgdupdate.exe\" -Embedding -boot"
"SoundMan"="SOUNDMAN.EXE"
"shicoxp"="C:\\WINDOWS\\shicoxp.exe"
"SetDefPrt"="C:\\Program Files\\Brother\\Brmfl04b\\BrStDvPt.exe"
"SemanticInsight"="C:\\Program Files\\RXToolBar\\Semantic Insight\\SemanticInsight.exe"
"regskindmeallite"="C:\\Documents and Settings\\All Users\\Application Data\\itch new regs kind\\PeakSlow.exe"
"RealTray"="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe SYSTEMBOOTHIDEPLAYER"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"QuickFinder Scheduler"="\"C:\\Program Files\\WordPerfect Office 11\\Programs\\QFSCHD110.EXE\""
"PowerS"="C:\\WINDOWSPowerS.exe"
"PinnacleDriverCheck"="C:\\WINDOWS\\System32\\PSDrvCheck.exe"
"pccguide.exe"="\"C:\\Program Files\\Trend Micro\\Internet Security 2006\\pccguide.exe\""
"PaperPort PTD"="C:\\Program Files\\ScanSoft\\PaperPort\\pptd40nt.exe"
"NetPumper"="\"C:\\Program Files\\NetPumper\\NetPumperIEProxy.exe\""
"Logitech Utility"="Logi_MwX.Exe"
"KernelFaultCheck"="%systemroot%\\system32\\dumprep 0 -k"
"KAZAA"="C:\\Program Files\\Kazaa\\kazaa.exe /SYSTRAY"
"IPHSend"="C:\\Program Files\\Common Files\\AOL\\IPHSend\\IPHSend.exe"
"IndexSearch"="C:\\Program Files\\ScanSoft\\PaperPort\\IndexSearch.exe"
"HostManager"="C:\\Program Files\\Common Files\\AOL\\1141366775\\ee\\AOLSoftware.exe"
"FLMK08KB"="C:\\Program Files\\Muiltmedia keyboard utility\\1.1\\MMKEYBD.EXE"
"ControlCenter2.0"="C:\\Program Files\\Brother\\ControlCenter2\\brctrcen.exe /autorun"
"bpk"="c:\\program files\\internet explorer\\bpk.exe"
"AVG7_EMC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgemc.exe"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"AOLDialer"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"
"AOL Spyware Protection"="\"C:\\PROGRA~1\\COMMON~1\\AOL\\AOLSPY~1\\AOLSP Scheduler.exe\""
"AltnetPointsManager"="c:\\program files\\altnet\\points manager\\points manager.exe -s"
"AIMPro"="\"C:\\Program Files\\AIM\\AIM Pro\\aimpro.exe\""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"NCUpdateSvc"=dword:00000002
"AOL ACS"=dword:00000002
"AVGEMS"=dword:00000002
"tmproxy"=dword:00000002
"Tmntsrv"=dword:00000002
"PcCtlCom"=dword:00000002
"SPBBCSvc"=dword:00000002
"Avg7UpdSvc"=dword:00000002
"Avg7Alrt"=dword:00000002
"iPodService"=dword:00000003
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{B9E618A2-A4FE-11D4-83C2-005004636C96}"="OE Shell Hook"
"{81559C35-8464-49F7-BB0E-07A383BEF910}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"UPnPMonitor"="{e57ce738-33e8-4c51-8354-bb4de9d215d1}"
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"none"="C:\\Program Files\\Video ActiveX Object\\pmsngr.exe"
"isamini.exe"="C:\\Program Files\\Video ActiveX Object\\isamonitor.exe"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\20571B429E30F2BA.job
C:\WINDOWS\tasks\A0B27DE1918DFCAD.job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
Completion time: 07-01-24 16:00:17
C:\ComboFix2.txt ... 07-01-23 22:43
ComboFix 07-01-23.2 - Running from: "C:\Documents and Settings\slim\My Documents\download"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\DOCUME~1
C:\qoobox\purity\WINDOWS\ICROSO~1
C:\qoobox\purity\WINDOWS\system32\DOBE~1
C:\qoobox\purity\WINDOWS\system32\FNTS~1
C:\qoobox\purity\Program Files\SMBOLS~1
C:\qoobox\purity\Program Files\Common Files\MCROSO~1.NET
C:\qoobox\purity\Program Files\Common Files\YSTEM~1
C:\qoobox\purity\DOCUME~1\slim
C:\qoobox\purity\DOCUME~1\slim\Application Data
C:\qoobox\purity\DOCUME~1\slim\My Documents
C:\qoobox\purity\DOCUME~1\slim\Application Data\from.txt
C:\qoobox\purity\DOCUME~1\slim\Application Data\DOBE~1
C:\qoobox\purity\DOCUME~1\slim\Application Data\ICROSO~1
C:\qoobox\purity\DOCUME~1\slim\Application Data\WNSXS~1
C:\qoobox\purity\DOCUME~1\slim\Application Data\STEM32~1
C:\qoobox\purity\DOCUME~1\slim\Application Data\WNSXS~1\W?nSxS
C:\qoobox\purity\DOCUME~1\slim\Application Data\WNSXS~1\W?nSxS\!update-4300.0000
C:\qoobox\purity\DOCUME~1\slim\My Documents\from.txt
C:\qoobox\purity\DOCUME~1\slim\My Documents\SMBOLS~1
C:\qoobox\purity\DOCUME~1\slim\My Documents\FNTS~1
((((((((((((((((((((((((((((((( Files Created from 2006-12-24 to 2007-01-24 ))))))))))))))))))))))))))))))))))
2007-01-23 22:47 79,360 --a------ C:\WINDOWS\system32\swxcacls.exe
2007-01-23 22:47 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-01-23 22:47 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-01-23 22:47 40,960 --a------ C:\WINDOWS\system32\swsc.exe
2007-01-23 22:47 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-01-23 22:47 135,168 --a------ C:\WINDOWS\system32\swreg.exe
2007-01-22 18:42 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-01-22 17:50 7,830 --a------ C:\WINDOWS\system32\tmp.reg
2007-01-22 14:54 <DIR> d-------- C:\DOCUME~1\slim\SmitfraudFix
2007-01-22 01:15 3,120 --a------ C:\WINDOWS\system32\2d2ca2ce-704a-428c-8cbe-0736b29190aa.dll
2007-01-22 01:13 <DIR> d-------- C:\Program Files\AARONS CLIKER
2007-01-22 00:12 <DIR> d-------- C:\Program Files\Sunbelt Software
2007-01-21 21:34 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll
2007-01-21 21:32 <DIR> d-------- C:\WINDOWS\Internet Logs
2007-01-21 20:59 <DIR> d-------- C:\Program Files\HOSTS Secure
2007-01-21 20:50 21,312 --a------ C:\WINDOWS\choice.exe
2007-01-21 20:43 <DIR> d-------- C:\ie-spyad2
2007-01-21 20:35 <DIR> d-------- C:\Program Files\SpywareGuard
2007-01-21 20:30 <DIR> d-------- C:\Program Files\SpywareBlaster
2007-01-21 19:28 <DIR> d-------- C:\Program Files\Hijackthis
2007-01-21 14:43 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2007-01-21 11:36 <DIR> d-------- C:\Program Files\Registry Defender
2007-01-20 14:42 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Spybot - Search & Destroy
2007-01-20 14:25 76,560 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2007-01-20 14:23 <DIR> d-------- C:\DOCUME~1\slim\.housecall6.6
2007-01-17 15:52 <DIR> d-------- C:\DOCUME~1\slim\Application Data\AVG7
2007-01-17 15:50 <DIR> d-------- C:\DOCUME~1\LOCALS~1\Application Data\AVG7
2007-01-17 03:39 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Avg7
2007-01-11 17:35 <DIR> d-------- C:\DOCUME~1\slim\Application Data\ZangoToolbar
2007-01-11 17:34 39,936 --a------ C:\npclntax.dll
2007-01-11 13:50 <DIR> d-------- C:\DOCUME~1\slim\Application Data\Viewpoint
2007-01-10 03:00 <DIR> d-------- C:\WINDOWS\ie7updates
2007-01-07 22:55 28,672 --a------ C:\WINDOWS\system32\f3PSSavr.scr
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-12-19 01:30 2 --a------ C:\WINDOWS\system32\wapisvit.exe
2006-12-15 22:08 -------- d-------- C:\Program Files\windows live toolbar
2006-12-07 17:11 -------- d-------- C:\Program Files\yahoo!
2006-11-23 15:59 131072 --a------ C:\WINDOWS\system32\spoonuninstall.exe
2006-11-08 00:06 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-11-07 21:03 6049280 --a------ C:\WINDOWS\system32\ieframe.dll
2006-11-07 21:03 50688 --a------ C:\WINDOWS\system32\msfeedsbs.dll
2006-11-07 21:03 458752 --a------ C:\WINDOWS\system32\msfeeds.dll
2006-11-07 21:03 413696 --a------ C:\WINDOWS\system32\vbscript.dll
2006-11-07 21:03 231424 --a------ C:\WINDOWS\system32\webcheck.dll
2006-11-07 21:03 180736 --a------ C:\WINDOWS\system32\ieui.dll
2006-11-07 21:03 156160 --a------ C:\WINDOWS\system32\msls31.dll
2006-11-07 03:27 382976 --a------ C:\WINDOWS\system32\iedkcs32.dll
2006-11-07 03:27 229376 --a------ C:\WINDOWS\system32\ieaksie.dll
2006-11-07 03:26 71680 --a------ C:\WINDOWS\system32\admparse.dll
2006-11-07 03:26 55296 --a------ C:\WINDOWS\system32\iesetup.dll
2006-11-07 03:26 54784 --a------ C:\WINDOWS\system32\ie4uinit.exe
2006-11-07 03:26 43008 --a------ C:\WINDOWS\system32\iernonce.dll
2006-11-07 03:26 152064 --a------ C:\WINDOWS\system32\ieakeng.dll
2006-11-07 03:26 13312 --a------ C:\WINDOWS\system32\ieudinit.exe
2006-11-07 03:26 123904 --a------ C:\WINDOWS\system32\advpack.dll
2006-11-07 03:25 161792 --a------ C:\WINDOWS\system32\ieakui.dll
2006-11-04 14:14 1245696 --a------ C:\WINDOWS\system32\msxml4.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"Rguzmxn"="C:\\Documents and Settings\\slim\\Application Data\\?dobe\\r?ndll.exe"
"Yahoo! Pager"="\"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe\" -quiet"
"windowinside"="C:\\DOCUME~1\\slim\\APPLIC~1\\FOURPL~1\\DebugStop.exe"
"tbon"="C:\\Program Files\\TBONBin\\tbon.exe /r"
"Skype"="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"
"PhotoShow Deluxe Media Manager"="C:\\PROGRA~1\\SIMPLE~1\\PHOTOS~1\\data\\Xtras\\mssysmgr.exe"
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"Ltho"="\"C:\\DOCUME~1\\slim\\APPLIC~1\\WNSXS~1\\arpa.exe\" -vt tzt"
"ErrorSafeFree"="\"C:\\Program Files\\ErrorSafe Free\\uers.exe\" /min"
"ErrorSafe"="C:\\Program Files\\Error Safe\\ERS.exe /min"
"Aim6"="\"C:\\Program Files\\AIM6\\aim6.exe\" /d locale=en-US ee://aol/imApp"
"AdwareProtector"="C:\\Program Files\\Error Safe\\AdwareProtector.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"My Web Search Bar Search Scope Monitor"="\"C:\\PROGRA~1\\MYWEBS~1\\bar\\1.bin\\m3SrchMn.exe\" /m=0"
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
"zBrowser Launcher"="C:\\Program Files\\Logitech\\iTouch\\iTouch.exe"
"zango"="\"c:\\program files\\zango\\zango.exe\""
"WinDVR SchSvr"="\"C:\\Program Files\\Common Files\\InterVideo\\SchSvr\\SchSvr.exe\""
"wcmdmgr"="C:\\WINDOWS\\wt\\updater\\wcmdmgrl.exe -launch"
"was_check"="C:\\Program Files\\ErrorSafe Free\\PASmon.exe"
"VTTimer"="VTTimer.exe"
"VC5Player"="C:\\Program Files\\HHVcdV5Sys\\VC5Play.exe"
"UERScw"="C:\\Program Files\\ErrorSafe Free\\UERScw.exe -c"
"Typehidetonsace"="C:\\Documents and Settings\\All Users\\Application Data\\Movecreativetypehide\\kind 32.exe"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"SSBkgdUpdate"="\"C:\\Program Files\\Common Files\\Scansoft Shared\\SSBkgdUpdate\\SSBkgdupdate.exe\" -Embedding -boot"
"SoundMan"="SOUNDMAN.EXE"
"shicoxp"="C:\\WINDOWS\\shicoxp.exe"
"SetDefPrt"="C:\\Program Files\\Brother\\Brmfl04b\\BrStDvPt.exe"
"SemanticInsight"="C:\\Program Files\\RXToolBar\\Semantic Insight\\SemanticInsight.exe"
"regskindmeallite"="C:\\Documents and Settings\\All Users\\Application Data\\itch new regs kind\\PeakSlow.exe"
"RealTray"="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe SYSTEMBOOTHIDEPLAYER"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"QuickFinder Scheduler"="\"C:\\Program Files\\WordPerfect Office 11\\Programs\\QFSCHD110.EXE\""
"PowerS"="C:\\WINDOWSPowerS.exe"
"PinnacleDriverCheck"="C:\\WINDOWS\\System32\\PSDrvCheck.exe"
"pccguide.exe"="\"C:\\Program Files\\Trend Micro\\Internet Security 2006\\pccguide.exe\""
"PaperPort PTD"="C:\\Program Files\\ScanSoft\\PaperPort\\pptd40nt.exe"
"NetPumper"="\"C:\\Program Files\\NetPumper\\NetPumperIEProxy.exe\""
"Logitech Utility"="Logi_MwX.Exe"
"KernelFaultCheck"="%systemroot%\\system32\\dumprep 0 -k"
"KAZAA"="C:\\Program Files\\Kazaa\\kazaa.exe /SYSTRAY"
"IPHSend"="C:\\Program Files\\Common Files\\AOL\\IPHSend\\IPHSend.exe"
"IndexSearch"="C:\\Program Files\\ScanSoft\\PaperPort\\IndexSearch.exe"
"HostManager"="C:\\Program Files\\Common Files\\AOL\\1141366775\\ee\\AOLSoftware.exe"
"FLMK08KB"="C:\\Program Files\\Muiltmedia keyboard utility\\1.1\\MMKEYBD.EXE"
"ControlCenter2.0"="C:\\Program Files\\Brother\\ControlCenter2\\brctrcen.exe /autorun"
"bpk"="c:\\program files\\internet explorer\\bpk.exe"
"AVG7_EMC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgemc.exe"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"AOLDialer"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"
"AOL Spyware Protection"="\"C:\\PROGRA~1\\COMMON~1\\AOL\\AOLSPY~1\\AOLSP Scheduler.exe\""
"AltnetPointsManager"="c:\\program files\\altnet\\points manager\\points manager.exe -s"
"AIMPro"="\"C:\\Program Files\\AIM\\AIM Pro\\aimpro.exe\""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"NCUpdateSvc"=dword:00000002
"AOL ACS"=dword:00000002
"AVGEMS"=dword:00000002
"tmproxy"=dword:00000002
"Tmntsrv"=dword:00000002
"PcCtlCom"=dword:00000002
"SPBBCSvc"=dword:00000002
"Avg7UpdSvc"=dword:00000002
"Avg7Alrt"=dword:00000002
"iPodService"=dword:00000003
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{B9E618A2-A4FE-11D4-83C2-005004636C96}"="OE Shell Hook"
"{81559C35-8464-49F7-BB0E-07A383BEF910}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"UPnPMonitor"="{e57ce738-33e8-4c51-8354-bb4de9d215d1}"
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"none"="C:\\Program Files\\Video ActiveX Object\\pmsngr.exe"
"isamini.exe"="C:\\Program Files\\Video ActiveX Object\\isamonitor.exe"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\20571B429E30F2BA.job
C:\WINDOWS\tasks\A0B27DE1918DFCAD.job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
Completion time: 07-01-24 16:00:17
C:\ComboFix2.txt ... 07-01-23 22:43