ok here are both logs
and watta ya know ssqpo.dll got deleted
VundoFix V6.1.2
Checking Java version...
Java version is 1.4.2.4
Java version is 1.5.0.7
Scan started at 1:15:43 AM 8/25/2006
Listing files found while scanning....
C:\WINDOWS\system32\ssqpo.dll
C:\WINDOWS\system32\opqss.ini
C:\WINDOWS\system32\opqss.bak2
Beginning removal...
Attempting to delete C:\WINDOWS\system32\ssqpo.dll
C:\WINDOWS\system32\ssqpo.dll Could not be deleted.
Attempting to delete C:\WINDOWS\system32\opqss.ini
C:\WINDOWS\system32\opqss.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\opqss.bak2
C:\WINDOWS\system32\opqss.bak2 Has been deleted!
Performing Repairs to the registry.
Done!
VundoFix V6.1.2
Checking Java version...
Java version is 1.4.2.4
Java version is 1.5.0.7
Scan started at 1:22:59 AM 8/25/2006
Listing files found while scanning....
C:\WINDOWS\system32\ssqpo.dll
Beginning removal...
Attempting to delete C:\WINDOWS\system32\ssqpo.dll
C:\WINDOWS\system32\ssqpo.dll Has been deleted!
Performing Repairs to the registry.
Done!
John Doe - 06-08-25 1:33:35.37
ComboFix 06.08.24 - Running from: C:\Documents and Settings\John Doe\Desktop
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\QooBox\Purity\Documents and Settings\John Doe\My Documents\MANTEC~1
C:\QooBox\Purity\Program Files\CROSOF~1
C:\QooBox\Purity\WINDOWS\SSTEM~1
((((((((((((((((((((((((((((((( Files Created from 2006-07-25 to 2006-08-25 ))))))))))))))))))))))))))))))))))
2006-08-25 01:28 9,216 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2006-08-24 22:11 13,844 --a------ C:\WINDOWS\system32\shymuxba.exe
2006-08-15 15:25 12,308 --a------ C:\WINDOWS\system32\fdbxkjkm.exe
2006-08-14 15:25 2,580 --a------ C:\WINDOWS\system32\cncxfatu.exe
2006-08-14 15:25 12,308 --a------ C:\WINDOWS\system32\lmstmjqq.exe
2006-08-06 16:36 98,304 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2006-07-28 18:46 77,824 --a------ C:\WINDOWS\system32\driverif.dll
2006-07-28 18:46 75,776 --a------ C:\WINDOWS\zllsputility.exe
2006-07-28 18:46 733,236 --a------ C:\WINDOWS\system32\vete.dll
2006-07-28 18:46 653,072 --a------ C:\WINDOWS\system32\imsinstall.dll
2006-07-28 18:46 12,288 --a------ C:\WINDOWS\system32\vetntmsg.dll
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-08-25 01:32 -------- d-------- C:\Program Files\Mozilla Firefox
2006-08-24 17:25 -------- d-------- C:\Documents and Settings\John Doe\Application Data\uTorrent
2006-08-24 16:15 -------- d-------- C:\Documents and Settings\John Doe\Application Data\Adobe
2006-08-22 18:57 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-08-22 10:33 -------- d-------- C:\Program Files\Microsoft Games
2006-08-22 10:24 -------- d---s---- C:\Documents and Settings\John Doe\Application Data\Microsoft
2006-08-19 18:56 -------- d-------- C:\Program Files\Wings of POWER II WWII FIGHTERS
2006-08-17 23:38 -------- d-------- C:\Program Files\mIRC
2006-08-16 12:22 -------- d-------- C:\Program Files\Windows Media Player
2006-08-15 12:19 -------- d-------- C:\Program Files\FlashGet
2006-08-13 14:54 -------- d-------- C:\Program Files\Microsoft IntelliType Pro
2006-08-10 01:30 -------- d-------- C:\Program Files\MSXML 4.0
2006-08-10 01:26 -------- d-------- C:\Program Files\Common Files\Microsoft Shared
2006-08-03 18:17 -------- d-------- C:\Program Files\Return to Castle Wolfenstein
2006-07-28 18:50 -------- d-------- C:\Documents and Settings\John Doe\Application Data\MailFrontier
2006-07-28 18:46 -------- d-------- C:\Program Files\Zone Labs
2006-07-27 17:35 -------- d-------- C:\Documents and Settings\John Doe\Application Data\Ahead
2006-07-24 23:32 65556 --a------ C:\WINDOWS\system32\samuuvut.exe
2006-07-23 22:16 -------- d-------- C:\Documents and Settings\John Doe\Application Data\dvdcss
2006-07-23 22:13 -------- d-------- C:\Program Files\Advanced JPEG Compressor
2006-07-23 22:06 -------- d-------- C:\Program Files\Microsoft ActiveSync
2006-07-23 22:05 -------- d-------- C:\Program Files\WinRAR
2006-07-23 22:05 -------- d-------- C:\Program Files\PowerISO
2006-07-23 22:05 -------- d-------- C:\Program Files\Microsoft.NET
2006-07-23 22:05 -------- d-------- C:\Program Files\Microsoft Works
2006-07-23 22:05 -------- d-------- C:\Program Files\Microsoft Visual Studio
2006-07-23 22:05 -------- d-------- C:\Program Files\Common Files\System
2006-07-23 22:05 -------- d-------- C:\Program Files\Common Files\DESIGNER
2006-07-23 22:05 -------- d-------- C:\Program Files\Common Files
2006-07-20 19:23 -------- d-------- C:\Program Files\Xilisoft
2006-07-18 20:33 -------- d-------- C:\Program Files\Microsoft Office
2006-07-16 23:48 737280 --a------ C:\WINDOWS\iun6002.exe
2006-07-16 00:27 18048 --a------ C:\WINDOWS\system32\drivers\lirsgt.sys
2006-07-16 00:27 165376 --a------ C:\WINDOWS\system32\drivers\atksgt.sys
2006-07-15 23:59 -------- d-------- C:\Program Files\Smart Projects
2006-07-10 19:36 -------- d-------- C:\Program Files\uTorrent
2006-07-08 20:01 -------- d-------- C:\Documents and Settings\John Doe\Application Data\ArcSoft
2006-07-08 19:57 -------- d-------- C:\Program Files\ArcSoft
2006-07-08 19:48 -------- d-------- C:\Program Files\Common Files\Adobe Systems Shared
2006-07-08 19:47 -------- d-------- C:\Program Files\Common Files\Adobe
2006-07-08 19:46 -------- d-------- C:\Program Files\Adobe
2006-07-08 19:35 -------- d-------- C:\Program Files\Jasc Software Inc
2006-07-08 19:35 -------- d-------- C:\Documents and Settings\John Doe\Application Data\Jasc Software Inc
2006-07-08 19:34 -------- d-------- C:\Program Files\Common Files\SWF Studio
2006-07-07 18:42 -------- d-------- C:\Program Files\Nero
2006-07-07 18:42 -------- d-------- C:\Program Files\Common Files\Ahead
2006-06-30 15:48 -------- d-------- C:\Documents and Settings\John Doe\Application Data\Leadertech
2006-06-29 19:43 51472 --a------ C:\WINDOWS\system32\imagecfg.exe
2006-06-29 19:02 -------- d-------- C:\Documents and Settings\John Doe\Application Data\Google
2006-06-29 14:34 2 --a------ C:\WINDOWS\system32\wnscptr.exe
2006-06-28 01:26 -------- d-------- C:\Program Files\On2 Technologies
2006-06-28 01:24 -------- d-------- C:\Program Files\DivX
2006-06-27 19:38 -------- d-------- C:\Program Files\SpywareGuard
2006-06-27 19:28 -------- d-------- C:\Program Files\Lavasoft
2006-06-27 19:28 -------- d-------- C:\Documents and Settings\John Doe\Application Data\Lavasoft
2006-06-27 11:05 -------- d-------- C:\Documents and Settings\John Doe\Application Data\vlc
2006-06-27 10:58 -------- d-------- C:\Program Files\VideoLAN
2006-06-26 01:57 -------- d-------- C:\Program Files\Java
2006-06-25 17:51 -------- d-------- C:\Program Files\EA SPORTS
2006-06-25 16:13 -------- d-------- C:\Documents and Settings\John Doe\Application Data\AdobeUM
2006-06-25 16:11 1561 --a------ C:\Documents and Settings\John Doe\Application Data\AdobeDLM.log
2006-06-25 16:11 0 --a------ C:\Documents and Settings\John Doe\Application Data\dm.ini
2006-06-25 16:10 -------- d-------- C:\Program Files\Yahoo!
2006-06-24 15:06 81920 -r------- C:\WINDOWS\bwUnin-6.1.4.61-8876480L.exe
2006-06-24 03:13 0 -rahs---- C:\MSDOS.SYS
2006-06-24 03:13 0 -rahs---- C:\IO.SYS
2006-06-24 03:13 0 --a------ C:\CONFIG.SYS
2006-06-24 03:13 0 --a------ C:\AUTOEXEC.BAT
2006-06-23 23:01 62 --ahs---- C:\Documents and Settings\John Doe\Application Data\desktop.ini
2006-06-16 14:34 48936 --a------ C:\WINDOWS\system32\sirenacm.dll
2006-06-15 17:55 778240 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2006-06-15 17:55 778240 --a------ C:\WINDOWS\system32\divx_xx07.dll
2006-06-15 17:55 761856 --a------ C:\WINDOWS\system32\divx_xx11.dll
2006-06-15 17:55 620180 --a------ C:\WINDOWS\system32\DivX.dll
2006-06-15 12:14 53248 --a------ C:\WINDOWS\system32\cdh00.dll
2006-06-14 13:49 118784 --a------ C:\WINDOWS\system32\DivXCodecUpdateChecker.exe
2006-06-13 00:39 1388544 --a------ C:\WINDOWS\system32\MSVBVM60.dll
2006-06-12 15:22 520192 --a------ C:\WINDOWS\system32\DivXsm.exe
2006-05-31 17:17 32768 --a------ C:\WINDOWS\system32\MetarDownload.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_07\\bin\\jusched.exe"
"SoundMan"="SOUNDMAN.EXE"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"type32"="\"C:\\Program Files\\Microsoft IntelliType Pro\\type32.exe\""
"DAEMON Tools"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
"Adobe Photo Downloader"="\"C:\\Program Files\\Adobe\\Photoshop Album Starter Edition\\3.0\\Apps\\apdproxy.exe\""
"NWEReboot"=""
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"Zone Labs Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"Steam"=""
"Logitech Desktop Messenger"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Users\\John Doe\\NewVersion\\setup-8876480.exe -ReportOnly"
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="\"C:\\Program Files\\Common Files\\Ahead\\lib\\NMBgMonitor.exe\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,e2,03,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wintfj32
~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
backup-20060823-203705-544
O15 - Trusted Zone:
http://www.winantiviruspro.combackup-20060823-203705-600
O15 - Trusted Zone:
http://download.cdn.winsoftware.combackup-20060823-203705-344
O15 - Trusted Zone:
http://www.winantivirus.combackup-20060823-203705-241
O15 - Trusted Zone:
http://locator1.cdn.imagesrvr.combackup-20060823-203705-149
O15 - Trusted Zone:
http://www.amaena.combackup-20060823-203705-846
O15 - Trusted Zone:
http://locator.cdn.imageservr.combackup-20060823-203705-878
O15 - Trusted Zone:
http://scanner.sysprotect.combackup-20060823-203705-145
O15 - Trusted Zone:
http://*.systemdoctor.com Completion time: Fri 08/25/2006 1:34:50.79
ComboFix.txt