++ And the Second / Last:
========================================================
Lissa - 06-11-16 18:45:07.89 Service Pack 1
ComboFix 06.11.9 - Running from: "C:\Utilities"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\QooBox\Purity\Documents and Settings\Lissa\Application Data\SKS~1
C:\QooBox\Purity\Program Files\ICROSO~1.NET
C:\QooBox\Purity\Program Files\STEM32~1
C:\QooBox\Purity\Program Files\Common Files\CROSOF~1
C:\QooBox\Purity\Program Files\Common Files\CURITY~1
C:\QooBox\Purity\Program Files\Common Files\FNTS~1
C:\QooBox\Purity\Program Files\Common Files\ICROSO~1.NET
C:\QooBox\Purity\Program Files\Common Files\SEMBLY~1
C:\QooBox\Purity\Program Files\Common Files\FNTS~1\i?xplore_exe.vir
C:\QooBox\Purity\Program Files\Common Files\SEMBLY~1\rundll32.exe
C:\QooBox\Purity\Program Files\Common Files\SEMBLY~1\??sembly
C:\QooBox\Purity\Program Files\ICROSO~1.NET\bak
C:\QooBox\Purity\Program Files\ICROSO~1.NET\ICROSO~1.NET
C:\QooBox\Purity\Program Files\ICROSO~1.NET\wuauclt.exe
C:\QooBox\Purity\WINDOWS\CROSOF~1
C:\QooBox\Purity\WINDOWS\FNTS~1
C:\QooBox\Purity\WINDOWS\ICROSO~1.NET
C:\QooBox\Purity\WINDOWS\MBOLS~1
C:\QooBox\Purity\WINDOWS\PPPATC~1
C:\QooBox\Purity\WINDOWS\SMBOLS~1
C:\QooBox\Purity\WINDOWS\system32\PPPATC~1
((((((((((((((((((((((((((((((( Files Created from 2006-10-16 to 2006-11-16 ))))))))))))))))))))))))))))))))))
2006-11-16 18:31 731,683 ---hs---- C:\WINDOWS\system32\klnmp.bak1
2006-11-16 17:16 126,996 --a------ C:\WINDOWS\system32\qptivimf.dll
2006-11-16 14:44 126,976 --a------ C:\WINDOWS\system32\rvxj.dll
2006-11-12 22:25 131,072 --------- C:\WINDOWS\system32\mqfl.dll
2006-11-12 01:35 731,747 ---hs---- C:\WINDOWS\system32\klnmp.ini2
2006-11-11 18:44 126,976 --------- C:\WINDOWS\system32\hncfmyog.dll
2006-11-11 18:43 110,612 --a------ C:\WINDOWS\system32\jhywcnsa.exe
2006-11-11 18:25 692,276 --------- C:\WINDOWS\system32\pmnlk.dll
2006-11-09 15:40 692,276 ---hs---- C:\WINDOWS\system32\ssttu.dll
2006-11-09 15:35 227,376 -r-hs---- C:\WINDOWS\xupcstgA.exe
2006-11-09 15:34 28,672 --a------ C:\WINDOWS\system32\pfbo0yj.exe
2006-11-09 15:34 28,672 --a------ C:\WINDOWS\system32\hlvi6wkjc.exe
2006-11-09 15:34 24,576 --a------ C:\WINDOWS\system32\ysjaevwx.exe
2006-11-09 15:34 200,704 --a------ C:\WINDOWS\system32\p2jlseh8.dll
2006-11-09 15:33 40,973 ---hs---- C:\WINDOWS\system32\wvuttrr.dll
2006-11-09 15:33 135,168 --a------ C:\WINDOWS\system32\e0pnii5i6.exe
2006-11-03 13:33 76,736 --a------ C:\WINDOWS\MySpaceIM_Setup.exe
2006-10-17 09:11 45,985 --a------ C:\WINDOWS\system32\ViscalcUninstaller.exe
2006-10-17 09:11 405,504 --a------ C:\WINDOWS\system32\vcbhoerh.dll
2006-10-17 09:11 36,864 --a------ C:\WINDOWS\system32\vismersb.exe
2006-10-17 09:11 118,784 --a------ C:\WINDOWS\system32\italfds.exe
2006-10-16 04:25 139,282 --a------ C:\set.exe
2006-10-16 04:16 918 --a------ C:\WINDOWS\system32\winpfg32.sys
2006-10-16 04:16 44,888 --a------ C:\WINDOWS\system32\CAUnst.exe
2006-10-16 04:16 409,600 --------- C:\WINDOWS\system32\tcblusoh.dll
2006-10-16 04:16 36,864 --a------ C:\WINDOWS\system32\slimxcqy.exe
2006-10-16 04:16 24,576 --a------ C:\WINDOWS\system32\msxml3a.dll
2006-10-16 04:16 221,523 --a------ C:\WINDOWS\1011_justin.exe
2006-10-16 04:16 1,259 --a------ C:\WINDOWS\system32\omcde359.sys
2006-10-16 04:11 2 --a------ C:\WINDOWS\system32\wtssvit.exe
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-11-16 18:45 -------- d-a------ C:\Program Files\Common Files
2006-11-16 14:44 -------- d-------- C:\Documents and Settings\Lissa\Application Data\àppPatch
2006-11-15 13:45 -------- d-------- C:\Program Files\QuickTime
2006-11-15 13:42 -------- d-------- C:\Program Files\Internet Explorer
2006-11-15 13:40 -------- d-------- C:\Program Files\Common Files\rzzo
2006-11-12 00:43 -------- d--h----- C:\Program Files\WindowsUpdate
2006-11-09 17:37 -------- d-------- C:\Program Files\Messenger
2006-11-07 15:49 -------- d-------- C:\Program Files\Morpheus
2006-11-03 13:36 -------- d-------- C:\Documents and Settings\Lissa\Application Data\MySpace
2006-11-03 13:35 -------- d-------- C:\Program Files\MySpace
2006-10-11 13:07 252752 --a------ C:\WINDOWS\system32\odc.dll
2006-10-11 12:56 115134 --a------ C:\WINDOWS\system32\justin.exe
2006-10-11 11:37 96911 --a------ C:\WINDOWS\system32\ts_www.exe
2006-09-29 01:24 73748 --a------ C:\WINDOWS\system32\loouoieg.dll
2006-09-29 01:24 45525 --a------ C:\WINDOWS\system32\nrkcklpo.dll
2006-09-27 22:49 45525 --a------ C:\WINDOWS\system32\nredfiot.dll
2006-09-27 22:14 45525 --a------ C:\WINDOWS\system32\oigqijoo.dll
2006-09-27 21:56 45525 --a------ C:\WINDOWS\system32\vrbfgvev.dll
2006-09-27 21:56 143380 --a------ C:\WINDOWS\system32\abclmnfd.exe
2006-09-27 21:51 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-09-27 21:44 94720 --a------ C:\WINDOWS\system32\dcdfami.dll
2006-09-27 21:44 72704 --a------ C:\WINDOWS\system32\aejgdii.dll
2006-09-18 00:34 -------- d-------- C:\Program Files\AIM
2006-09-15 16:21 53248 --a------ C:\WINDOWS\uninst108.exe
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Aaou"="\"C:\\PROGRA~1\\COMMON~1\\SEMBLY~1\\rundll32.exe\" -vt ndrv"
"Ixu"="C:\\Documents and Settings\\Lissa\\Application Data\\?ppPatch\\l?gonui.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"AGRSMMSG"="AGRSMMSG.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="C:\\Program Files\\Common Files\\xunyk.html"
"SubscribedURL"=""
"FriendlyName"=""
"Flags"=dword:00002000
"Position"=hex:2c,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,00,00,e8,\
03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,00,14,00,00,00
"CurrentState"=hex:01,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,\
00,00,01,00,00,00
"RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
"Source"="C:\\Program Files\\WindowsUpdate\\vilohob.html"
"SubscribedURL"=""
"FriendlyName"=""
"Flags"=dword:00002000
"Position"=hex:2c,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,00,00,ea,\
03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,00,14,00,00,00
"CurrentState"=hex:01,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,\
00,00,01,00,00,00
"RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\2]
"Source"="C:\\WINDOWS\\System32\\ad.html"
"SubscribedURL"=""
"FriendlyName"=""
"Flags"=dword:00002000
"Position"=hex:2c,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,00,00,ec,\
03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,00,14,00,00,00
"CurrentState"=hex:01,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,\
00,00,01,00,00,40
"RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\3]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,00,00,ee,\
03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:01,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"ItalU"="C:\\WINDOWS\\System32\\italfds.exe"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"ItalU"="C:\\WINDOWS\\System32\\italfds.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
"{C7CF1142-0785-4B12-A280-B64681E4D45E}"="z"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"NoActiveDesktop"=dword:00000000
"ClassicShell"=dword:00000000
"ForceActiveDesktopOn"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
"aaahtm"="C:\\WINDOWS\\System32\\aaahtm.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoCDBurning"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Chckup"="C:\\WINDOWS\\System32\\Netverchk.exe"
"Aaou"="\"C:\\PROGRA~1\\ICROSO~1.NET\\wuauclt.exe\" -vt ndrv"
"DeluxeCommunications"="C:\\Program Files\\DeluxeCommunications\\Dxc.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"DeluxeCommunications"="C:\\Program Files\\DeluxeCommunications\\Dxc.exe"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnlk
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
Completion time: 06-11-16 18:45:39.31
C:\ComboFix.txt ... 06-11-16 18:45
C:\ComboFix2.txt ... 06-11-16 18:42
================================================

I see DeluxeCommunications is popping in--
again --
I got the info on that from Bleepingcomputer, & thought we'd killed it two days ago. Guess not.
How's that phrase ~ "Bloody Hell" ?? :bigthumb:
/.