"JOSEPH" - 2007-05-11 15:10:52 Service Pack 2
ComboFix 07-05.08.3.V - Running from: "C:\Program Files\Mozilla Firefox\"
(((((((((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\jkklm.dll
C:\WINDOWS\system32\fccdcay.dll
C:\WINDOWS\system32\ssqqqoo.dll
C:\WINDOWS\system32\winzzd32.dll
C:\WINDOWS\system32\ssqolmj.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\drsmartloadb.dat
C:\WINDOWS\enewsletterpro1.dat
C:\WINDOWS\winsysupd1.dat
C:\Program Files\Common Files\Yazzle1162OinAdmin.exe
C:\Program Files\Common Files\Yazzle1162OinUninstaller.exe
C:\WINDOWS\retadpu1000272.exe
C:\Program Files\outerinfo\Terms.rtf
C:\Program Files\install.log
C:\WINDOWS\system32\wtsit.exe
C:\WINDOWS\b122.exe
C:\Program Files\Common Files\download
C:\Program Files\outerinfo
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\C\Program Files\MBOLS~1
C:\qoobox\purity\C\Program Files\Common Files\STEM32~1
((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_CMDSERVICE
-------\LEGACY_RDRIV
-------\rdriv
((((((((((((((((((((((((((((((( Files Created from 2007-04-05 to 2007-05-11 ))))))))))))))))))))))))))))))))))
2007-05-11 15:03 93,696 --a------ C:\WINDOWS\system32\drvgur.dll
2007-05-11 15:03 29,206 --a------ C:\WINDOWS\system32\awtuvuv.dll
2007-05-11 00:23 <DIR> d-------- C:\SmitfraudFix
2007-05-10 23:52 93,696 --a------ C:\WINDOWS\system32\drvnos.dll
2007-05-10 22:08 876,207 --a------ C:\SmitfraudFix.exe
2007-05-10 21:45 1,626 --a------ C:\WINDOWS\system32\tmp.reg
2007-05-10 21:33 33,280 --a------ C:\WINDOWS\system32\rundll32.exe
2007-05-10 21:31 <DIR> d-------- C:\WINDOWS\Options
2007-05-10 20:04 93,696 --a------ C:\WINDOWS\system32\drvwix.dll
2007-05-10 20:04 60,928 --a------ C:\WINDOWS\system32\sewgbour.dll
2007-05-10 20:04 2 --a------ C:\WINDOWS\system32\wtsisvit.exe
2007-05-10 18:33 99,328 --a------ C:\VundoFix.exe
2007-05-10 18:33 <DIR> d-------- C:\VundoFix Backups
2007-05-10 18:00 93,696 --a------ C:\WINDOWS\system32\drvfal.dll
2007-05-10 18:00 43 --a------ C:\Program Files\RUNME.bat
2007-05-10 18:00 12,374 --a------ C:\Program Files\install.exe
2007-05-07 21:18 <DIR> d-------- C:\DOCUME~1\JOSEPH\Incomplete
2007-05-07 21:17 <DIR> d-------- C:\DOCUME~1\JOSEPH\APPLIC~1\LimeWire
2007-05-04 21:53 <DIR> d-------- C:\DOCUME~1\TOM\APPLIC~1\Google
2007-04-25 19:54 <DIR> d-------- C:\DOCUME~1\NICOLE\APPLIC~1\InstallShield
2007-04-25 19:50 <DIR> d-------- C:\Program Files\Avanquest update
2007-04-25 19:49 25,600 --a------ C:\WINDOWS\system32\drivers\usbser.sys
2007-04-25 19:47 24,192 --a------ C:\DOCUME~1\NICOLE\usbsermptxp.sys
2007-04-25 19:47 22,768 --a------ C:\WINDOWS\system32\drivers\usbsermpt.sys
2007-04-25 19:47 22,768 --a------ C:\DOCUME~1\NICOLE\usbsermpt.sys
2007-04-25 19:46 <DIR> d-------- C:\Program Files\Motorola Phone Tools
2007-04-25 19:46 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\BVRP Software
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-05-11 19:34:56 30,577 ----a-w C:\WINDOWS\system32\tablet.dat
2007-05-09 20:13:53 -------- d-----w C:\Program Files\Soulseek
2007-05-08 22:49:39 15,196 -c--a-w C:\WINDOWS\mozver.dat
2007-05-03 02:53:34 -------- d-----w C:\Program Files\iPod
2007-04-30 23:30:46 -------- d-----w C:\Program Files\ArtMoney
2007-04-25 23:50:26 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-04-19 18:36:32 -------- d-----w C:\Program Files\America Online 9.0
2007-04-07 03:23:06 6,511 ----a-w C:\WINDOWS\system32\SpoonUninstall-Nostalgia, an Intellivision Emulator.dat
2007-04-07 03:23:06 164,352 ----a-w C:\WINDOWS\system32\SpoonUninstall.exe
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
"{02478D38-C3F9-4EFB-9B51-7695ECA05670}"="C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll"
"{4EC5F862-6FD5-7C2C-F63B-68E33DE5F89B}"="C:\WINDOWS\system32\sewgbour.dll"
"{AA58ED58-01DD-4d91-8333-CF10577473F7}"="c:\program files\google\googletoolbar3.dll"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"QuickTime Task"="\"X:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"X:\\Program Files\\iTunes\\iTunesHelper.exe\""
"SManager"="smanager.7.exe"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"PopUpStopperFreeEdition"="\"C:\\PROGRA~1\\PANICW~1\\POP-UP~1\\PSFree.exe\""
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"Yahoo! Pager"="1"
"Lynwtaw"="\"C:\\Program Files\\??mbols\\r?gsvr32.exe\""
"Usrr"="\"C:\\PROGRA~1\\COMMON~1\\STEM32~1\\dexplore.exe\" -vt ndrv"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"="Narrator.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{54D9498B-CF93-414F-8984-8CE7FDE0D391}"="C:\Program Files\ewido anti-malware\shellhook.dll"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages msv1_0\0\0
Security Packages kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages scecli\0\0
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^start menu^programs^startup^adobe gamma loader.lnk
C:\PROGRA~1\COMMON~1\Adobe\CALIBR~1\ADOBEG~1.EXE
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^start menu^programs^startup^america online 8.0 tray icon.lnk
C:\PROGRA~1\AMERIC~2.0\aoltray.exe -check
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^start menu^programs^startup^america online 9.0 tray icon.lnk
C:\PROGRA~1\AMERIC~3.0\aoltray.exe -check
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^start menu^programs^startup^bigfix.lnk
C:\PROGRA~1\BigFix\BigFix.exe /atstartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^start menu^programs^startup^compuserve 7.0 tray icon.lnk
C:\PROGRA~1\COMPUS~1.0B\cstray.exe -check
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^start menu^programs^startup^intervideo wincinema manager.lnk
C:\PROGRA~1\INTERV~1\Common\Bin\WINCIN~1.EXE
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^start menu^programs^startup^kodak easyshare software.lnk
C:\PROGRA~1\Kodak\KODAKE~1\bin\EASYSH~1.EXE -h
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^start menu^programs^startup^kodak software updater.lnk
C:\PROGRA~1\Kodak\KODAKS~1\7288971\Program\BACKWE~1.EXE
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^start menu^programs^startup^microsoft office.lnk
C:\PROGRA~1\MICROS~2\Office\OSA9.EXE -b -l
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^start menu^programs^startup^tabuserw.exe.lnk
C:\WINDOWS\system32\WTablet\TabUserW.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^joseph^start menu^programs^startup^umax vistaaccess.lnk
C:\VSTASCAN\vsaccess.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^tom^start menu^programs^startup^screen saver control.lnk
C:\WINDOWS\FSScrCtl.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\aim
C:\Program Files\AIM95\aim.exe -cnetwait.odl
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\aim6
"C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\aol spyware protection
"C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\aolspscheduler
C:\Program Files\Common Files\AOL\1137880939\ee\services\sscAntiSpywarePlugin\ver1_10_3_1\AOLSP Scheduler.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ati launchpad
"C:\Program Files\ATI Multimedia\main\launchpd.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\atipta
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bjcfd
C:\Program Files\BroadJump\Client Foundation\CFD.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bullseye network
C:\Program Files\BullsEye Network\bin\bargains.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bxb1
C:\WINDOWS\treggd.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\directx64
C:\WINDOWS\System32\DirectXset.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dxprgc
C:\Program Files\Nvrb\Kptpftj.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\emailscan
C:\Program Files\mcafee.com\antivirus\mcvsescn.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ez
C:\documents and settings\nicole\local settings\temp\ez.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hostmanager
C:\Program Files\Common Files\AOL\1137880939\ee\AOLSoftware.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hp component manager
"C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hp software update
"C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpdj taskbar utility
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hphmon05
C:\WINDOWS\System32\hphmon05.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hphupd05
C:\Program Files\Hewlett-Packard\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\hphupd05.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\internet optimizer
"C:\Program Files\Internet Optimizer\optimize.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ist service
C:\Program Files\ISTsvc\istsvc.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ituneshelper
"C:\Program Files\iTunes\iTunesHelper.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\kazaa
C:\Program Files\KaZaA\kazaa.exe /SYSTRAY
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\load
C:\OPLIMIT\ocraware.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mcafee.instantupdate.monitor
"C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /startmonitor
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\microsoft servicez manager
servicemgrz.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\microsoft updat3
mswkst32.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mpfexe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msmc
C:\WINDOWS\System32\msmc.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msmsgs
"C:\Program Files\Messenger\msmsgs.exe" /background
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr
"C:\Program Files\MSN Messenger\msnmsgr.exe" /background
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mssvc322
C:\WINDOWS\System32\MSsvc32.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\oasclnt
C:\Program Files\mcafee.com\antivirus\oasclnt.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\plaxoupdate
C:\Program Files\Plaxo\2.5.10.17\PlaxoHelper.exe -a
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\popupstopperfreeedition
"C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\quicktime task
"C:\Program Files\QuickTime\qttask.exe" -atboottime
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\secure
C:\WINDOWS\System32\Ottlzk.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sscrun
C:\Program Files\Common Files\AOL\1137880939\ee\services\sscFirewallPlugin\ver1_10_3_1\SSCRun.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sunjavaupdatesched
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\t9u65ekh
C:\WINDOWS\System32\t9u65ekh.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tkbellexe
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tray temperature
C:\DOCUME~1\JOSEPH\LOCALS~1\Temp\MiniBug.exe 1
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\version
C:\WINDOWS\System32\Epmera.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\viewmgr
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wildtangent cda
RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winsock2 driver
xabmhd.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winsvc32
C:\WINDOWS\System32\winsvc32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"svehost32"=dword:00000002
"SpywareCleanerService"=dword:00000002
"Alerter"=dword:00000003
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService DnsCache\0\0
rpcss RpcSs\0\0
imgsvc StiSvc\0\0
termsvcs TermService\0\0
HTTPFilter HTTPFilter\0\0
DcomLaunch DcomLaunch\0TermService\0\0
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost
*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_ENTDRV51
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\HP Usg Daily.job
C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer.job
C:\WINDOWS\tasks\Symantec NetDetect.job
********************************************************************
catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-05-11 15:36:26
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 2007-05-11 15:50:42 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-05-11 15:50
I can't do a "HijackThis" log because my computer deletes it upon downloading.