logs
Here are both log reports...
Another FYI: I could not access the internet, so I used HijackThis to delete both the WINPOP and OUTERINFO entries... I tried a bunch of other things, but I kept getting PAGE NOT FOUND in the browser, and was therefore unable to even check this forum! I removed them, and was then able to access the internet again, so here are the logs...
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:32:44 PM, on 8/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - Startup: BackgroundImage.lnk = C:\WINDOWS\bg.bat
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
--
End of file - 1799 bytes
ComboFix 07-08-09.3 - "Default" 2007-08-10 19:16:35.1 -
FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.101 [GMT -4:00]
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\Default\APPLIC~1.\asks~1
C:\DOCUME~1\LOCALS~1\APPLIC~1\.rdr.ini
C:\DOCUME~1\LOCALS~1\APPLIC~1\install.dat
C:\DOCUME~1\NETWOR~1\APPLIC~1\.rdr.ini
C:\DOCUME~1\NETWOR~1\APPLIC~1\install.dat
C:\temp\0c2
C:\temp\0c2\tmpFF.log
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\temp\brr
C:\temp\brr\tmpZTF.log
C:\Temp\fse
C:\Temp\fse\tmpZTF.log
C:\temp\tn3
C:\WINDOWS\b122.exe
C:\WINDOWS\csrss.exe
C:\WINDOWS\g4356cbvy63.exe
C:\WINDOWS\start.exe
C:\WINDOWS\system32\b02FdUe
C:\WINDOWS\system32\b02FdUe\b02FdUe1065.exe
C:\WINDOWS\system32\b06FdUe
C:\WINDOWS\system32\b06FdUe\b06FdUe1083.exe
C:\WINDOWS\system32\C1
C:\WINDOWS\system32\C3
C:\WINDOWS\system32\C5
C:\WINDOWS\system32\C9
C:\WINDOWS\system32\configs
C:\WINDOWS\system32\driver
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\core.sys
C:\WINDOWS\system32\f06WtR
C:\WINDOWS\system32\f06WtR\f06WtR1083.exe
C:\WINDOWS\system32\F2
C:\WINDOWS\system32\F3
C:\WINDOWS\system32\ldinfo.ldr
C:\WINDOWS\system32\msbind32.exe
C:\WINDOWS\system32\NSIS.Library.RegTool.v2.{3B775F6F-3BFC-41E0-8995-45FD53118BCF}.exe
C:\WINDOWS\system32\NSIS.Library.RegTool.v2.{C06D05F2-8762-4B3C-918E-AB5DF8C16367}.exe
C:\WINDOWS\system32\NSIS.Library.RegTool.v2.{C0901534-E3EA-47A9-A5F9-65F9CC878A9E}.exe
C:\WINDOWS\system32\setup155.exe
C:\WINDOWS\system32\W3
C:\WINDOWS\system32\wcpsvit32.exe
C:\WINDOWS\system32\win
C:\WINDOWS\system32\zxdnt3d.cfg
C:\WINDOWS\TISKY009.exe
C:\WINDOWS\uni_eh44.exe
C:\WINDOWS\uninst1014.exe
C:\WINDOWS\wr.txt
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_CORE
-------\LEGACY_NET_AGENT
-------\LEGACY_WINDOWS_OVERLAY_COMPONENTS
-------\LEGACY_WINIO
-------\core
-------\Net Agent
((((((((((((((((((((((((( Files Created from 2007-07-10 to 2007-08-10 )))))))))))))))))))))))))))))))
2007-08-10 19:15 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-09 15:00 <DIR> d-------- C:\Program Files\Trend Micro
2007-08-08 01:26 <DIR> d-------- C:\Program Files\Enigma Software Group
2007-08-08 00:47 <DIR> d-------- C:\!KillBox
2007-08-08 00:11 2,097,152 --ah----- C:\DOCUME~1\ADMINI~1\ntuser.dat
2007-08-07 12:46 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2007-08-06 23:26 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
2007-08-06 21:15 1,356 --a------ C:\WINDOWS\SYSTEM32\tmp.reg
2007-08-06 21:02 <DIR> d-------- C:\Program Files\RogueRemover FREE
2007-08-06 09:33 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-08-05 22:24 76,560 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\tmcomm.sys
2007-08-05 16:49 <DIR> d-------- C:\DOCUME~1\Default\.housecall6.6
2007-08-05 15:44 95,608 --a------ C:\WINDOWS\SYSTEM32\AvastSS.scr
2007-08-05 15:44 94,416 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\aswmon2.sys
2007-08-05 15:44 92,848 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\aswmon.sys
2007-08-05 15:44 42,912 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\aswTdi.sys
2007-08-05 15:44 26,624 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\aavmker4.sys
2007-08-05 15:44 23,152 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\aswRdr.sys
2007-08-05 15:43 783,224 --a------ C:\WINDOWS\SYSTEM32\aswBoot.exe
2007-08-05 13:45 4,212 ---h----- C:\WINDOWS\SYSTEM32\zllictbl.dat
2007-08-05 13:45 <DIR> d-------- C:\WINDOWS\SYSTEM32\ZoneLabs
2007-08-05 08:48 6,507 ---hs---- C:\WINDOWS\SYSTEM32\cfggh.bak1
2007-08-04 10:39 <DIR> d-------- C:\Program Files\Common Files\Palo Alto Software
2007-08-03 19:10 1,729,590 ---hs---- C:\WINDOWS\SYSTEM32\ppoqr.bak2
2007-08-03 17:52 510 ---hs---- C:\WINDOWS\SYSTEM32\ppoqr.ini2
2007-08-03 17:43 <DIR> d-------- C:\DOCUME~1\Default\APPLIC~1\Lavasoft
2007-08-03 16:34 0 --a------ C:\WINDOWS\Gwang.exe
2007-08-03 16:30 192,587 --a------ C:\WINDOWS\SYSTEM32\nwintmdt.exe
2007-07-11 12:57 <DIR> d-------- C:\DOCUME~1\Default\APPLIC~1\Talkback
2007-07-10 17:49 <DIR> d-------- C:\Program Files\FileZilla
2007-07-10 17:48 <DIR> d-------- C:\Program Files\MWAInc
2007-07-10 00:28 <DIR> d-------- C:\Program Files\Zub
2007-07-10 00:21 1,524 --a------ C:\WINDOWS\SYSTEM32\d3d8caps.dat
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-10 17:48 73216 --a------ C:\WINDOWS\ST6UNST.EXE
2007-07-10 17:48 249856 --------- C:\WINDOWS\Setup1.exe
2007-07-04 00:47 --------- d-------- C:\Program Files\dlink
2007-06-06 01:45 162448 --a------ C:\DOCUME~1\Default\APPLIC~1\GDIPFONTCACHEV1.DAT
2003-01-06 15:47 967 --a------ C:\WINDOWS\pif\SPLASH.PIF
2002-11-14 12:20 36864 --a------ C:\DOCUME~1\Default\APPLIC~1\UnPhP.exe
2002-01-25 10:00 36969 --------- C:\Program Files\Common Files\tppupd98.dll
2000-09-12 18:48 967 --a------ C:\WINDOWS\pif\INSTALL.PIF
1999-04-23 22:22 126976 --a------ C:\WINDOWS\msapps\Grphflt\MSJPEG32.DLL
2005-10-14 01:27:00 422,400 --sha-r C:\WINDOWS\x2.64.exe
2005-05-13 21:12:00 217,073 --sha-r C:\WINDOWS\meta4.exe
2005-10-24 15:13:58 66,560 --sha-r C:\WINDOWS\MOTA113.exe
2005-02-28 17:16:22 240,128 --sha-r C:\WINDOWS\SYSTEM32\x.264.exe
2006-04-27 14:24:24 2,945,024 --sha-r C:\WINDOWS\SYSTEM32\Smab.dll
2005-07-14 16:31:20 27,648 --sha-r C:\WINDOWS\SYSTEM32\AVSredirect.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Zone Labs Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2005-11-15 00:51]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-07-27 18:03]
C:\Documents and Settings\Default\Start Menu\Programs\Startup\
BackgroundImage.lnk - C:\WINDOWS\bg.bat [2007-04-16 17:34:59]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"EditLevel"=0 (0x0)
"NoClose"=0 (0x0)
"NoFileMenu"=0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"EditLevel"=0 (0x0)
"NoClose"=0 (0x0)
"NoSaveSettings"=0 (0x0)
"NoFileMenu"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
backup=C:\WINDOWS\pss\Quicken Scheduled Updates.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Default^Start Menu^Programs^Startup^TA_Start.lnk]
path=C:\Documents and Settings\Default\Start Menu\Programs\Startup\TA_Start.lnk
backup=C:\WINDOWS\pss\TA_Start.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Default^Start Menu^Programs^Startup^Think-Adz.lnk]
path=C:\Documents and Settings\Default\Start Menu\Programs\Startup\Think-Adz.lnk
backup=C:\WINDOWS\pss\Think-Adz.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\%%DELETE_VALUE%%]
CreateCD50
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
c:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bantool]
C:\WINDOWS\system32\ie_ban.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ExploreUpdSched]
C:\WINDOWS\system32\nwintmdt.exe SKY009
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\g4356cbvy63]
C:\WINDOWS\g4356cbvy63
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Iaau]
"C:\WINDOWS\system32\ICROSO~1.NET\iexplore.exe" -vt yazb
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\isltnplA]
C:\WINDOWS\isltnplA.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBInstall]
C:\DOCUME~1\Default\LOCALS~1\Temp\MBDownloader_876919.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\WINDOWS\SYSTEM32\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
C:\WINDOWS\retadpu361.exe 61A847B5BBF72811349A284503996897C881250221C8670836AC4FA7C8833201749139
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemOptimizer]
rundll32.exe "C:\WINDOWS\system32\xxfuaxjl.dll",forkonce
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemTray]
SysTray.Exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{F7-73-32-29-ZN}]
C:\windows\system32\lsdsrngp.exe SKY009
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=2 (0x2)
"wscsvc"=2 (0x2)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"msnmsgr"="C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /background
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"ScanRegistry"=c:\windows\scanregw.exe /autorun
"TaskMonitor"=c:\windows\taskmon.exe
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
"AtiCwd32"=Aticwd32.exe
"AtiKey"=Atitask.exe
"SoundFusion"=RunDll32 cwcprops.cpl,CrystalControlWnd
"LexStart"=Lexstart.exe
"LXSUPMON"=C:\WINDOWS\SYSTEM\LXSUPMON.EXE RUN
"RealTray"=C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
"QuickTime Task"="C:\WINDOWS\SYSTEM32\QTTASK.EXE" -atboottime
"WinampAgent"="C:\PROGRAM FILES\WINAMP\WINAMPa.exe"
"iamapp"=c:\Program Files\Norton Internet Security\IAMAPP.EXE
"NAV Agent"=c:\PROGRA~1\NORTON~1\NAVAPW32.EXE
"EPSON Stylus C82 Series"=C:\WINDOWS\SYSTEM\E_S10IC2.EXE /P23 "EPSON Stylus C82 Series" /O5 "LPT1:" /M "Stylus C82"
"Ink Monitor"=C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
"CreateCD50"="c:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe" -r
"AdaptecDirectCD"="c:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
"AtariBanner"="C:\Program Files\Infogrames\Atari Anniversary Edition\Volume 2\Banner.exe" /0
"TB_setup"=C:\WINDOWS\TEMP\TB_SETUP.EXE /dcheck
"Easykey"=C:\Program Files\Easy Keyboard\Easykey.exe
"Omnipage"=c:\Program Files\ScanSoft\OmniPageSE\opware32.exe
"ScanSoft Product Registration Reminder"="C:\PROGRAM FILES\SCANSOFT\OMNIPAGESE\EREGENG\NAVBROWSER.EXE" /r /i "C:\PROGRAM FILES\SCANSOFT\OMNIPAGESE\EREGENG\NavLoad.ini"
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
"DVDTray"=C:\Program Files\HP DVD\Umbrella\DVDTray.exe
"DVDBitSet"=C:\Program Files\HP DVD\Umbrella\DVDBitSet.exe /NOUI
"TPP Auto Loader"=C:\WINDOWS\TPPALDR.EXE
"Motive SmartBridge"=C:\PROGRA~1\NETASS~1\SMARTB~1\MotiveSB.exe
"StandardInstall"=
"VVSN"=C:\PROGRAM FILES\VVSN\VVSN.EXE
"WhenUSave"="C:\Program Files\Save\Save.exe"
"WhenUSearch"="C:\Program Files\WhenUSearch\Search.exe"
"WhenUSearchWHSE"="C:\Program Files\WhenUSearch\whse.exe"
"LoadQM"=loadqm.exe
"avast! Web Scanner"=C:\PROGRA~1\ALWILS~1\AVAST4\ASHWEBSV.EXE
"GW Port Controller"=C:\Program Files\Samsung\SmarThru\PORTCTRL.EXE
"Zone Labs Client"="C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE"
"DeskAd Service"=C:\PROGRAM FILES\DESKAD SERVICE\DESKADSERV.EXE
"webHancer Agent"="C:\Program Files\webHancer\Programs\whAgent.exe"
"webHancer Survey Companion"="C:\Program Files\webHancer\Programs\whSurvey.exe"
"salm"=c:\temp\salm.exe
"Gene USB Monitor"=C:\WINDOWS\SYSTEM32\USBMONIT.EXE
"MsgCenterExe"="C:\Program Files\Common Files\Real\Update_OB\RealOneMessageCenter.exe" -osboot
"StillImageMonitor"=C:\WINDOWS\SYSTEM32\STIMON.EXE
"zango"="c:\program files\zango\zango.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"Zone Labs Client"=C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices-]
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
"TrueVector"=C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
"ScriptBlocking"="C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
"nisserv"=c:\Program Files\Norton Internet Security\NISSERV.EXE
"SAgent2ExePath"=C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
"EAgent95ExePath"=C:\Program Files\Common Files\EPSON\EBAPI\eEBAgent.exe
"Machine Debug Manager"=C:\WINDOWS\SYSTEM32\MDM.EXE
"avast!"=C:\Program Files\Alwil Software\Avast4\ashServ.exe
"SchedulingAgent"=mstask.exe
"KB891711"=c:\windows\SYSTEM\KB891711\KB891711.EXE
R0 sbp2port;SBP-2 Transport/Protocol Bus Driver;C:\WINDOWS\system32\DRIVERS\sbp2port.sys
R1 cdudf_xp;cdudf_xp;C:\WINDOWS\system32\drivers\cdudf_xp.sys
R1 Pwd_2k;Pwd_2k;C:\WINDOWS\system32\drivers\Pwd_2k.sys
R1 Udfreadr_xp;Udfreadr_xp;C:\WINDOWS\system32\drivers\Udfreadr_xp.sys
R3 atirage3;atirage3;C:\WINDOWS\system32\DRIVERS\atimpae.sys
R3 FETNDISB;D-Link DFE-530TX PCI Fast Ethernet Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\dlkfet5b.sys
R3 NtApm;NT Apm/Legacy Interface Driver;C:\WINDOWS\system32\DRIVERS\NtApm.sys
S3 dvd_2K;dvd_2K;C:\WINDOWS\system32\drivers\dvd_2K.sys
S3 mmc_2K;mmc_2K;C:\WINDOWS\system32\drivers\mmc_2K.sys
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>IEPerUser]
RUNDLL32.EXE IEDKCS32.DLL,BrandIE4 SIGNUP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\MmoptPreferredAudioDevices]
rundll32.exe shell32.dll,Control_RunDLL mmsys.cpl,@0,SPCI\VEN_1013&DEV_6003&SUBSYS_00000000&REV_01\BUS_00&DEV_0B&FUNC_00
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
"C:\PROGRA~1\OUTLOO~1\setup50.exe" /APP:OE /CALLER:IE50 /user /install
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}.Restore]
rundll32.exe advpack.dll,UserUnInstStubWrapper {44BBA840-CC51-11CF-AAFA-00AA00B6015C}
"C:\PROGRA~1\OUTLOO~1\setup50.exe" /APP:OE /CALLER:IE50 /user /uninstall
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
"C:\PROGRA~1\OUTLOO~1\setup50.exe" /APP:WAB /CALLER:IE50 /user /install
"C:\PROGRA~1\OUTLOO~1\setup50.exe" /APP:WAB /CALLER:IE50 /user /install
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}]
C:\WINDOWS\SYSTEM32\UPDCRL.EXE -e -u C:\WINDOWS\SYSTEM\verisignpub1.crl
Contents of the 'Scheduled Tasks' folder
2007-08-08 00:00:02 C:\WINDOWS\Tasks\Backup.job - C:\PROGRA~1\ACCESS~1\BACKUP\MSBACKUP.EXE
2007-08-08 00:00:02 C:\WINDOWS\Tasks\Disk Cleanup.job - C:\WINDOWS\CLEANMGR.EXE
2007-08-09 00:00:02 C:\WINDOWS\Tasks\Disk Defragmenter.job - C:\WINDOWS\DEFRAG.EXE
2007-08-04 00:00:02 C:\WINDOWS\Tasks\McAfee VirusScan.job - C:\PROGRA~1\NETWOR~1\MCAFEE~1\SCAN32.EXE
2007-08-06 23:00:02 C:\WINDOWS\Tasks\ScanDisk.job - C:\WINDOWS\SCANDSKW.EXE
2007-08-04 23:00:02 C:\WINDOWS\Tasks\Tune-up Application Start.job
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-08-10 19:23:16
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-08-10 19:25:47 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-08-10 19:25
--- E O F ---