"Darren" - 07-03-10 19:59:26 Service Pack 2
ComboFix 07-03-09.3 - Running from: "C:\"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files\Outerinfo
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\Program Files\SSEMBL~1
C:\qoobox\purity\Program Files\Common Files\SSTEM3~1
C:\qoobox\purity\Program Files\Common Files\SSTEM3~1\SSTEM3~1
C:\qoobox\purity\Program Files\SSEMBL~1\??rss.exe
((((((((((((((((((((((((((((((( Files Created from 2007-02-10 to 2007-03-10 ))))))))))))))))))))))))))))))))))
2007-03-10 19:59 26,112 --a------ C:\nircmd.exe
2007-03-10 19:53 988,262 --a------ C:\ComboFix.exe
2007-03-10 18:28 <DIR> d-------- C:\Program Files\Internet Connection Counter
2007-03-10 18:24 <DIR> d-------- C:\Program Files\OptusNet Cable
2007-03-10 12:59 15,360 --a------ C:\WINDOWS\system32\drivers\NetMotCM.sys
2007-03-09 19:36 <DIR> dr-h----- C:\$VAULT$.AVG
2007-03-09 18:53 775,680 --a------ C:\WINDOWS\system32\drivers\avg7core.sys
2007-03-09 18:53 4,224 --a------ C:\WINDOWS\system32\drivers\avg7rsw.sys
2007-03-09 18:53 3,968 --a------ C:\WINDOWS\system32\drivers\avgclean.sys
2007-03-09 18:53 27,776 --a------ C:\WINDOWS\system32\drivers\avg7rsxp.sys
2007-03-09 18:53 19,392 --a------ C:\WINDOWS\system32\drivers\avgmfx86.sys
2007-03-09 18:53 <DIR> d-------- C:\DOCUME~1\LOCALS~1\APPLIC~1\AVG7
2007-03-09 18:53 <DIR> d-------- C:\DOCUME~1\Darren\APPLIC~1\AVG7
2007-03-09 18:52 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
2007-03-09 18:52 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\avg7
2007-03-09 18:44 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2007-03-09 18:44 <DIR> d-------- C:\WINDOWS\system32\ZoneLabs
2007-03-09 18:43 <DIR> d-------- C:\WINDOWS\Internet Logs
2007-03-09 17:31 56,832 --a------ C:\WINDOWS\system32\djdjfyfp.dll
2007-03-09 17:29 81,408 --a------ C:\WINDOWS\system32\abqiiyj.dll
2007-03-09 17:29 57,856 --a------ C:\WINDOWS\system32\fqawfei.dll
2007-03-07 17:35 <DIR> d-------- C:\DOCUME~1\Darren\APPLIC~1\ACD Systems
2007-03-07 17:32 <DIR> d-------- C:\Program Files\Common Files\ACD Systems
2007-03-07 17:32 <DIR> d-------- C:\Program Files\ACD Systems
2007-03-07 17:32 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\ACD Systems
2007-03-07 17:28 10,368 --a------ C:\WINDOWS\system32\drivers\pfc.sys
2007-03-07 17:19 176,128 --a------ C:\WINDOWS\system32\nvudisp.exe
2007-03-07 17:17 <DIR> d-------- C:\NVIDIA
2007-03-05 16:59 491,520 --a------ C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-03-05 16:55 <DIR> d-------- C:\DOCUME~1\LOCALS~1\APPLIC~1\Spyware Terminator
2007-03-05 16:34 <DIR> d-------- C:\hijackthis
2007-03-05 15:31 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-03-05 15:02 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-03-05 14:59 614,191 --a------ C:\WINDOWS\system32\RegistryCleanerSetup.exe
2007-03-05 14:13 <DIR> d-------- C:\VundoFix Backups
2007-03-05 13:53 <DIR> d-------- C:\Program Files\Spyware Terminator
2007-03-05 12:47 32,179 ---hs---- C:\Program Files\Common Files\Yazzle1162OinUninstaller.exe
2007-03-02 20:36 <DIR> d-------- C:\Program Files\Google
2007-03-01 19:05 352,256 --a------ C:\WINDOWS\system32\ijl15.dll
2007-03-01 19:05 265,216 --a------ C:\WINDOWS\system32\NVIEWLIB.DLL
2007-03-01 18:57 <DIR> d--hs---- C:\WINDOWS\ftpcache
2007-02-15 11:42 <DIR> d-------- C:\Program Files\SmartDraw 2007
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-03-10 16:34 -------- d-------- C:\DOCUME~1\Darren\APPLIC~1\image zone express
2007-03-02 20:36 -------- d--h----- C:\Program Files\installshield installation information
2007-02-13 13:48 -------- d-------- C:\DOCUME~1\Darren\APPLIC~1\adobe
2007-02-07 16:05 -------- d-------- C:\Program Files\online services
2007-02-05 11:58 -------- d-------- C:\DOCUME~1\Darren\APPLIC~1\leadertech
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="\"C:\\Program Files\\Common Files\\Ahead\\lib\\NMBgMonitor.exe\""
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"Fnpahkak"="\"C:\\Program Files\\?ssembly\\??rss.exe\" 99001162"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NWEReboot"=""
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"HPDJ Taskbar Utility"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\hpztsb04.exe"
"IntelliPoint"="\"C:\\Program Files\\Microsoft IntelliPoint\\ipoint.exe\""
"itype"="\"C:\\Program Files\\Microsoft IntelliType Pro\\itype.exe\""
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"anvshell"="anvshell.exe"
"LiveNote"="livenote.exe"
"Adobe Photo Downloader"="\"C:\\Program Files\\Adobe\\Photoshop Album Starter Edition\\3.0\\Apps\\apdproxy.exe\""
"InCD"="C:\\Program Files\\Nero\\Nero 7\\InCD\\InCD.exe"
"tcpipmon"="tcpipmon.exe"
"SpywareTerminator"="\"C:\\Program Files\\Spyware Terminator\\SpywareTerminatorShield.exe\""
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
"Zone Labs Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{9B8E9200-85B9-402A-BD72-C17F41CD7C97}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgw.exe /RUNONCE"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgw.exe /RUNONCE"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wincyg32
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d2460f43-2644-11db-8b6d-806d6172696f}]
Shell\AutoRun\command D:\startcablecd.exe
********************************************************************
catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-03-10 20:03:20