Hello Shaba! Sorry for the late reply. I've been on campus all day. I carried out the instuctions you posted. I still receive the error message on startup about the missing module.
ComboFix:
Matt - 06-08-24 21:06:03.15
ComboFix 06.08.24 - Running from: C:\Program Files\Mozilla Firefox
((((((((((((((((((((((((((((((((((((((((((( E-Give / Ssk's Log )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\repairs303169590.dll
C:\Documents and Settings\Matt\Application Data\Sskknwrd.dll
C:\WINDOWS\system32\bk.exe
C:\Program Files\surfsidekick 3\Ssk.exe
C:\Program Files\surfsidekick 3\SskBho.dll
C:\Program Files\surfsidekick 3\SskCore.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\Duce6.exe
C:\WINDOWS\system32\ishost.exe
C:\WINDOWS\system32\issearch.exe
C:\WINDOWS\system32\tsuninst.exe
C:\WINDOWS\thiselt.exe
C:\WINDOWS\uninst104.exe
C:\WINDOWS\system32\components
C:\Program Files\Common Files\{5C2171E0-08D2-1033-0510-020829030001}
C:\WINDOWS\Duce6.exe
C:\WINDOWS\thiselt.exe
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\QooBox\Purity\Program Files\YSTEM~1
C:\QooBox\Purity\Program Files\Common Files\FNTS~1
C:\QooBox\Purity\Program Files\Common Files\SSTEM3~1
C:\QooBox\Purity\Program Files\Common Files\SSTEM3~1\w?nspool.exe
C:\QooBox\Purity\Program Files\YSTEM~1\m?dtc.exe
C:\QooBox\Purity\WINDOWS\ICROSO~1
C:\QooBox\Purity\WINDOWS\YSTEM~1
C:\QooBox\Purity\WINDOWS\ICROSO~1\?icrosoft
C:\QooBox\Purity\WINDOWS\system32\SSEMBL~1
C:\QooBox\Purity\WINDOWS\system32\SSEMBL~1\winlogon.exe
C:\QooBox\Purity\WINDOWS\system32\SSEMBL~1\?ssembly
((((((((((((((((((((((((((((((( Files Created from 2006-07-24 to 2006-08-24 ))))))))))))))))))))))))))))))))))
2006-08-23 19:36 32,573 --a------ C:\WINDOWS\system32\adrot-uninst.exe
2006-08-23 18:48 106,496 --a------ C:\WINDOWS\Duce6.exe
2006-08-23 18:46 61,952 --a------ C:\WINDOWS\system32\xpv72e6e.dll
2006-08-23 18:46 215,308 --a------ C:\WINDOWS\Setup90.exe
2006-08-23 18:46 1,233 --a------ C:\WINDOWS\system32\xpv72e6e.sys
2006-08-23 18:45 36,864 --a------ C:\WINDOWS\thiselt.exe
2006-08-23 18:45 115,157 --a------ C:\WINDOWS\Justin.exe
2006-08-23 06:56 40,973 ---hs---- C:\WINDOWS\system32\mljkiih.dll
2006-08-23 06:36 922,777 ---hs---- C:\WINDOWS\system32\lmllm.bak2
2006-08-23 01:05 593,408 --a------ C:\WINDOWS\system32\h323msp.dll
2006-08-23 01:05 550,400 --a------ C:\WINDOWS\system32\rtcdll.dll
2006-08-23 01:05 48,640 --a------ C:\WINDOWS\system32\browser.dll
2006-08-23 01:05 454,656 --a------ C:\WINDOWS\system32\ipnathlp.dll
2006-08-23 01:05 36,864 --a------ C:\WINDOWS\system32\mf3216.dll
2006-08-23 01:02 97,280 --a------ C:\WINDOWS\system32\txflog.dll
2006-08-23 01:02 64,512 --a------ C:\WINDOWS\system32\mtxclu.dll
2006-08-23 01:02 442,880 --a------ C:\WINDOWS\system32\rpcrt4.dll
2006-08-23 01:02 226,816 --a------ C:\WINDOWS\system32\es.dll
2006-08-23 01:02 214,528 --a------ C:\WINDOWS\system32\rpcss.dll
2006-08-23 01:02 1,105,408 --a------ C:\WINDOWS\system32\ole32.dll
2006-08-23 00:58 218,624 --a------ C:\WINDOWS\system32\srrstr.dll
2006-08-23 00:54 26,112 --a------ C:\WINDOWS\system32\xpsp1hfm.exe
2006-08-22 22:11 10,240 --a------ C:\WINDOWS\CTDCRES.DLL
2006-08-22 21:55 17,408 --a------ C:\WINDOWS\system32\qmgrprxy.dll
2006-08-22 21:47 98,816 --a------ C:\WINDOWS\system32\dmstyle.dll
2006-08-22 21:47 974,848 --a------ C:\WINDOWS\system32\dxdiag.exe
2006-08-22 21:47 80,896 --a------ C:\WINDOWS\system32\dpvsetup.exe
2006-08-22 21:47 8,192 --a------ C:\WINDOWS\system32\d3d8thk.dll
2006-08-22 21:47 797,184 --a------ C:\WINDOWS\system32\d3dim700.dll
2006-08-22 21:47 76,800 --a------ C:\WINDOWS\system32\dmscript.dll
2006-08-22 21:47 733,184 --a------ C:\WINDOWS\system32\qedwipes.dll
2006-08-22 21:47 68,096 --a------ C:\WINDOWS\system32\dsdmoprp.dll
2006-08-22 21:47 68,096 --a------ C:\WINDOWS\system32\dpnhupnp.dll
2006-08-22 21:47 64,512 --a------ C:\WINDOWS\system32\amstream.dll
2006-08-22 21:47 63,768 --a------ C:\WINDOWS\system32\dxdllreg.exe
2006-08-22 21:47 602,624 --a------ C:\WINDOWS\system32\dx7vb.dll
2006-08-22 21:47 590,336 --a------ C:\WINDOWS\system32\d3dramp.dll
2006-08-22 21:47 58,368 --a------ C:\WINDOWS\system32\dmcompos.dll
2006-08-22 21:47 57,856 --a------ C:\WINDOWS\system32\dpwsockx.dll
2006-08-22 21:47 53,248 --a------ C:\WINDOWS\system32\devenum.dll
2006-08-22 21:47 524,800 --a------ C:\WINDOWS\system32\qedit.dll
2006-08-22 21:47 47,616 --a------ C:\WINDOWS\system32\d3dxof.dll
2006-08-22 21:47 47,104 --a------ C:\WINDOWS\system32\wstdecod.dll
2006-08-22 21:47 44,032 --a------ C:\WINDOWS\system32\dimap.dll
2006-08-22 21:47 436,224 --a------ C:\WINDOWS\system32\d3dim.dll
2006-08-22 21:47 4,096 --a------ C:\WINDOWS\system32\ksuser.dll
2006-08-22 21:47 394,240 --a------ C:\WINDOWS\system32\diactfrm.dll
2006-08-22 21:47 382,976 --a------ C:\WINDOWS\system32\qdvd.dll
2006-08-22 21:47 377,856 --a------ C:\WINDOWS\system32\dpnet.dll
2006-08-22 21:47 363,520 --a------ C:\WINDOWS\system32\dsound.dll
2006-08-22 21:47 354,816 --a------ C:\WINDOWS\system32\psisdecd.dll
2006-08-22 21:47 350,208 --a------ C:\WINDOWS\system32\d3drm.dll
2006-08-22 21:47 34,816 --a------ C:\WINDOWS\system32\d3dpmesh.dll
2006-08-22 21:47 34,304 --a------ C:\WINDOWS\system32\mciqtz32.dll
2006-08-22 21:47 33,280 --a------ C:\WINDOWS\system32\dmloader.dll
2006-08-22 21:47 32,768 --a------ C:\WINDOWS\system32\dpnhpast.dll
2006-08-22 21:47 31,744 --a------ C:\WINDOWS\system32\pid.dll
2006-08-22 21:47 3,072 --a------ C:\WINDOWS\system32\dpnlobby.dll
2006-08-22 21:47 3,072 --a------ C:\WINDOWS\system32\dpnaddr.dll
2006-08-22 21:47 28,160 --a------ C:\WINDOWS\system32\dplaysvr.exe
2006-08-22 21:47 276,480 --a------ C:\WINDOWS\system32\qdv.dll
2006-08-22 21:47 27,136 --a------ C:\WINDOWS\system32\dmband.dll
2006-08-22 21:47 265,728 --a------ C:\WINDOWS\system32\ddraw.dll
2006-08-22 21:47 258,424 --a------ C:\WINDOWS\system32\qasf.dll
2006-08-22 21:47 24,064 --a------ C:\WINDOWS\system32\ddrawex.dll
2006-08-22 21:47 230,400 --a------ C:\WINDOWS\system32\dplayx.dll
2006-08-22 21:47 223,232 --a------ C:\WINDOWS\system32\gcdef.dll
2006-08-22 21:47 22,016 --a------ C:\WINDOWS\system32\dpmodemx.dll
2006-08-22 21:47 203,264 --a------ C:\WINDOWS\system32\dpvoice.dll
2006-08-22 21:47 194,560 --a------ C:\WINDOWS\system32\mswebdvd.dll
2006-08-22 21:47 19,968 --a------ C:\WINDOWS\system32\dpvacm.dll
2006-08-22 21:47 186,880 --a------ C:\WINDOWS\system32\dsdmo.dll
2006-08-22 21:47 181,248 --a------ C:\WINDOWS\system32\dmime.dll
2006-08-22 21:47 18,432 --a------ C:\WINDOWS\system32\dswave.dll
2006-08-22 21:47 177,152 --a------ C:\WINDOWS\system32\qcap.dll
2006-08-22 21:47 168,960 --a------ C:\WINDOWS\system32\dinput8.dll
2006-08-22 21:47 16,896 --a------ C:\WINDOWS\system32\msyuv.dll
2006-08-22 21:47 16,896 --a------ C:\WINDOWS\system32\dpnsvr.exe
2006-08-22 21:47 151,552 --a------ C:\WINDOWS\system32\dinput.dll
2006-08-22 21:47 13,312 --a------ C:\WINDOWS\system32\msdmo.dll
2006-08-22 21:47 112,128 --a------ C:\WINDOWS\system32\dpvvox.dll
2006-08-22 21:47 104,448 --a------ C:\WINDOWS\system32\dmusic.dll
2006-08-22 21:47 100,864 --a------ C:\WINDOWS\system32\dmsynth.dll
2006-08-22 21:47 1,294,336 --a------ C:\WINDOWS\system32\dsound3d.dll
2006-08-22 21:47 1,246,208 --a------ C:\WINDOWS\system32\quartz.dll
2006-08-22 21:47 1,230,336 --a------ C:\WINDOWS\system32\msvidctl.dll
2006-08-22 21:47 1,189,888 --a------ C:\WINDOWS\system32\dx8vb.dll
2006-08-22 21:47 1,179,648 --a------ C:\WINDOWS\system32\d3d8.dll
2006-08-22 21:36 127,208 --a------ C:\WINDOWS\system32\mucltui.dll
2006-08-21 20:02 361,984 --a------ C:\WINDOWS\system32\qmgr.dll
2006-08-21 20:01 90,624 --a------ C:\WINDOWS\system32\msoert2.dll
2006-08-21 20:01 9,728 --a------ C:\WINDOWS\system32\mstinit.exe
2006-08-21 20:01 77,824 --a------ C:\WINDOWS\system32\isign32.dll
2006-08-21 20:01 73,728 --a------ C:\WINDOWS\system32\ils.dll
2006-08-21 20:01 69,632 --a------ C:\WINDOWS\system32\icwdial.dll
2006-08-21 20:01 65,536 --a------ C:\WINDOWS\system32\msconf.dll
2006-08-21 20:01 61,952 --a------ C:\WINDOWS\system32\srclient.dll
2006-08-21 20:01 61,440 --a------ C:\WINDOWS\system32\icwphbk.dll
2006-08-21 20:01 47,616 --a------ C:\WINDOWS\system32\inetres.dll
2006-08-21 20:01 40,960 --a------ C:\WINDOWS\system32\safrslv.dll
2006-08-21 20:01 39,424 --a------ C:\WINDOWS\system32\safrcdlg.dll
2006-08-21 20:01 33,280 --a------ C:\WINDOWS\system32\racpldlg.dll
2006-08-21 20:01 32,768 --a------ C:\WINDOWS\system32\mnmsrvc.exe
2006-08-21 20:01 32,384 --a------ C:\WINDOWS\system32\mnmdd.dll
2006-08-21 20:01 28,672 --a------ C:\WINDOWS\system32\isrdbg32.dll
2006-08-21 20:01 266,240 --a------ C:\WINDOWS\system32\inetcfg.dll
2006-08-21 20:01 26,624 --a------ C:\WINDOWS\system32\safrdm.dll
2006-08-21 20:01 250,368 --a------ C:\WINDOWS\system32\mstask.dll
2006-08-21 20:01 24,576 --a------ C:\WINDOWS\system32\nmmkcert.dll
2006-08-21 20:01 228,864 --a------ C:\WINDOWS\system32\msoeacct.dll
2006-08-21 20:01 158,720 --a------ C:\WINDOWS\system32\schedsvc.dll
2006-08-21 20:01 155,136 --a------ C:\WINDOWS\system32\srsvc.dll
2006-08-21 19:59 98,816 --a------ C:\WINDOWS\system32\clipbrd.exe
2006-08-21 19:59 88,576 --a------ C:\WINDOWS\system32\tscfgwmi.dll
2006-08-21 19:59 85,504 --a------ C:\WINDOWS\system32\catsrvps.dll
2006-08-21 19:59 8,704 --a------ C:\WINDOWS\system32\icaapi.dll
2006-08-21 19:59 73,864 --a------ C:\WINDOWS\system32\rdpwsx.dll
2006-08-21 19:59 61,952 --a------ C:\WINDOWS\system32\rdshost.exe
2006-08-21 19:59 6,144 --a------ C:\WINDOWS\system32\msdtc.exe
2006-08-21 19:59 57,344 --a------ C:\WINDOWS\system32\licwmi.dll
2006-08-21 19:59 56,320 --a------ C:\WINDOWS\system32\remotepg.dll
2006-08-21 19:59 54,784 --a------ C:\WINDOWS\system32\msdtclog.dll
2006-08-21 19:59 534,016 --a------ C:\WINDOWS\system32\spider.exe
2006-08-21 19:59 53,248 --a------ C:\WINDOWS\system32\servdeps.dll
2006-08-21 19:59 503,296 --a------ C:\WINDOWS\system32\mstscax.dll
2006-08-21 19:59 41,984 --a------ C:\WINDOWS\system32\rdpclip.exe
2006-08-21 19:59 40,448 --a------ C:\WINDOWS\system32\tscupgrd.exe
2006-08-21 19:59 4,096 --a------ C:\WINDOWS\system32\wuauserv.dll
2006-08-21 19:59 385,536 --a------ C:\WINDOWS\system32\mstsc.exe
2006-08-21 19:59 339,968 --a------ C:\WINDOWS\system32\mspaint.exe
2006-08-21 19:59 32,768 --a------ C:\WINDOWS\system32\cfgbkend.dll
2006-08-21 19:59 197,632 -ra------ C:\WINDOWS\system32\termsrv.dll
2006-08-21 19:59 18,432 --a------ C:\WINDOWS\system32\qprocess.exe
2006-08-21 19:59 179,200 --a------ C:\WINDOWS\system32\accwiz.exe
2006-08-21 19:59 174,592 --a------ C:\WINDOWS\system32\cmprops.dll
2006-08-21 19:59 16,384 --a------ C:\WINDOWS\system32\mmfutil.dll
2006-08-21 19:59 14,848 --a------ C:\WINDOWS\system32\rdpsnd.dll
2006-08-21 19:59 134,656 --a------ C:\WINDOWS\system32\rdchost.dll
2006-08-21 19:59 130,048 --a------ C:\WINDOWS\system32\sessmgr.exe
2006-08-21 19:59 124,416 --a------ C:\WINDOWS\system32\sndrec32.exe
2006-08-21 19:59 124,184 --a------ C:\WINDOWS\system32\wuauclt.exe
2006-08-21 19:59 12,288 --a------ C:\WINDOWS\system32\rdsaddin.exe
2006-08-21 19:59 116,736 --a------ C:\WINDOWS\system32\mplay32.exe
2006-08-21 19:59 1,343,768 --a------ C:\WINDOWS\system32\wuaueng.dll
2006-08-21 19:32 70,656 --a------ C:\WINDOWS\system32\storprop.dll
2006-08-21 19:32 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll
2006-08-21 19:32 13,312 --a------ C:\WINDOWS\system32\irclass.dll
2006-08-21 17:51 13,844 --a------ C:\WINDOWS\system32\mwjxseim.exe
2006-08-21 17:50 925,946 ---hs---- C:\WINDOWS\system32\lmllm.bak1
2006-08-21 17:50 573,492 ---hs---- C:\WINDOWS\system32\mllml.dll
2006-08-21 17:45 2 --a------ C:\WINDOWS\system32\wnscpsu.exe
2006-08-21 17:45 155,136 --a------ C:\WINDOWS\system32\oins.exe
2006-08-21 17:41 159,744 --a------ C:\WINDOWS\sys015456957121.exe
2006-08-21 15:48 53,248 --a------ C:\WINDOWS\uni_ehhhh.exe
2006-08-21 10:36 78,848 --a------ C:\WINDOWS\system32\nsi279.dll
2006-08-21 09:47 58,880 --a------ C:\WINDOWS\system32\adrotate.dll
2006-08-20 22:40 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2006-08-20 13:02 11,776 --a------ C:\WINDOWS\INRES.DLL
2006-08-20 12:57 208,896 --a------ C:\WINDOWS\system32\nvudisp.exe
2006-08-20 12:55 208,896 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2006-08-20 12:49 62,744 --a------ C:\WINDOWS\system32\xinput1_2.dll
2006-08-20 12:49 236,824 --a------ C:\WINDOWS\system32\xactengine2_3.dll
2006-08-20 12:49 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-08-24 21:07 -------- d-a------ C:\Program Files\Common Files
2006-08-24 21:05 -------- d-------- C:\Program Files\Mozilla Firefox
2006-08-23 23:54 -------- d-------- C:\Documents and Settings\Matt\Application Data\Skype
2006-08-23 22:46 -------- d-------- C:\Program Files\Hijack This!
2006-08-23 22:42 -------- d-------- C:\Documents and Settings\Matt\Application Data\Ventrilo
2006-08-23 21:29 -------- d-------- C:\Program Files\Trillian
2006-08-23 21:27 -------- d-------- C:\Documents and Settings\Matt\Application Data\TrojanHunter
2006-08-23 19:21 -------- d-------- C:\Program Files\TrojanHunter 4.5
2006-08-23 19:11 -------- d-------- C:\Program Files\Creative
2006-08-23 18:38 -------- d-------- C:\Program Files\Lavasoft
2006-08-23 18:38 -------- d-------- C:\Documents and Settings\Matt\Application Data\Lavasoft
2006-08-23 01:05 -------- d-------- C:\Program Files\NetMeeting
2006-08-23 00:33 -------- d-------- C:\Program Files\ewido anti-spyware 4.0
2006-08-22 23:29 -------- d-------- C:\Program Files\EphPod
2006-08-22 22:30 -------- d-------- C:\Program Files\CleanUp!
2006-08-22 22:14 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-08-22 22:13 -------- d-------- C:\Documents and Settings\Matt\Application Data\Creative
2006-08-22 22:06 -------- d-------- C:\Program Files\World of Warcraft
2006-08-22 21:24 -------- d-------- C:\Program Files\Mozilla Thunderbird
2006-08-22 21:18 -------- d--h----- C:\Program Files\WindowsUpdate
2006-08-22 20:53 -------- d-------- C:\Program Files\Belkin
2006-08-21 20:07 -------- d-------- C:\Program Files\Windows Media Player
2006-08-21 20:02 -------- d-------- C:\Program Files\Movie Maker
2006-08-21 20:01 -------- d-------- C:\Program Files\Outlook Express
2006-08-21 20:01 -------- d-------- C:\Program Files\Internet Explorer
2006-08-21 20:01 -------- d-------- C:\Program Files\Common Files\System
2006-08-21 19:59 -------- d-------- C:\Program Files\Windows NT
2006-08-21 19:52 -------- d-------- C:\Program Files\Lexmark X1100 Series
2006-08-20 17:27 -------- d-------- C:\Program Files\Warcraft III
2006-08-18 14:09 -------- d-------- C:\Program Files\Common Files\Blizzard Entertainment
2006-08-17 14:50 -------- d-------- C:\Documents and Settings\Matt\Application Data\Sun
2006-08-17 01:14 -------- d-------- C:\Program Files\WinZip
2006-07-27 08:24 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-06-01 17:22 888832 --a------ C:\WINDOWS\system32\nvmobls.dll
2006-06-01 17:22 86016 --a------ C:\WINDOWS\system32\nvmctray.dll
2006-06-01 17:22 81920 --a------ C:\WINDOWS\system32\nvwddi.dll
2006-06-01 17:22 794624 --a------ C:\WINDOWS\system32\nvcplui.exe
2006-06-01 17:22 7618560 --a------ C:\WINDOWS\system32\nvcpl.dll
2006-06-01 17:22 581632 --a------ C:\WINDOWS\system32\nvhwvid.dll
2006-06-01 17:22 5652480 --a------ C:\WINDOWS\system32\nvdisps.dll
2006-06-01 17:22 5632000 --a------ C:\WINDOWS\system32\nvoglnt.dll
2006-06-01 17:22 5246976 --a------ C:\WINDOWS\system32\nvdispsr.dll
2006-06-01 17:22 466944 --a------ C:\WINDOWS\system32\nvshell.dll
2006-06-01 17:22 462848 --a------ C:\WINDOWS\system32\nvmccssr.dll
2006-06-01 17:22 4529408 --a------ C:\WINDOWS\system32\nv4_disp.dll
2006-06-01 17:22 45056 --a------ C:\WINDOWS\system32\nvmccsrs.dll
2006-06-01 17:22 442368 --a------ C:\WINDOWS\system32\nvappbar.exe
2006-06-01 17:22 425984 --a------ C:\WINDOWS\system32\keystone.exe
2006-06-01 17:22 35840 --a------ C:\WINDOWS\system32\nvcodins.dll
2006-06-01 17:22 35840 --a------ C:\WINDOWS\system32\nvcod.dll
2006-06-01 17:22 311296 --a------ C:\WINDOWS\system32\nvexpbar.dll
2006-06-01 17:22 3100672 --a------ C:\WINDOWS\system32\nvgames.dll
2006-06-01 17:22 2977792 --a------ C:\WINDOWS\system32\nvvitvsr.dll
2006-06-01 17:22 2924544 --a------ C:\WINDOWS\system32\nvvitvs.dll
2006-06-01 17:22 2916352 --a------ C:\WINDOWS\system32\nvgamesr.dll
2006-06-01 17:22 286720 --a------ C:\WINDOWS\system32\nvnt4cpl.dll
2006-06-01 17:22 2859008 --a------ C:\WINDOWS\system32\nvmoblsr.dll
2006-06-01 17:22 229376 --a------ C:\WINDOWS\system32\nvmccs.dll
2006-06-01 17:22 196608 --a------ C:\WINDOWS\system32\nvapi.dll
2006-06-01 17:22 188416 --a------ C:\WINDOWS\system32\nvmccss.dll
2006-06-01 17:22 1740800 --a------ C:\WINDOWS\system32\nvwssr.dll
2006-06-01 17:22 1662976 --a------ C:\WINDOWS\system32\nvwdmcpl.dll
2006-06-01 17:22 155715 --a------ C:\WINDOWS\system32\nvsvc32.exe
2006-06-01 17:22 1519616 --a------ C:\WINDOWS\system32\nwiz.exe
2006-06-01 17:22 147456 --a------ C:\WINDOWS\system32\nvcolor.exe
2006-06-01 17:22 1466368 --a------ C:\WINDOWS\system32\nview.dll
2006-06-01 17:22 1339392 --a------ C:\WINDOWS\system32\nvdspsch.exe
2006-06-01 17:22 1257472 --a------ C:\WINDOWS\system32\nvwss.dll
2006-06-01 17:22 1019904 --a------ C:\WINDOWS\system32\nvwimg.dll
2006-06-01 17:22 1011712 --a------ C:\WINDOWS\system32\nvcpluir.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpdReg"="C:\\WINDOWS\\Updreg.exe"
"Jet Detection"="C:\\Program Files\\Creative\\SBAudigy\\PROGRAM\\ADGJDet.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvMcTray.dll,NvTaskbarInit"
"CTHelper"="CTHELPER.EXE"
"THGuard"="\"C:\\Program Files\\TrojanHunter 4.5\\THGuard.exe\""
"xpv72e6e"="RUNDLL32.EXE w3c66798.dll,n 00372e6b000000023c66798"
"sys015456957121"="C:\\WINDOWS\\sys015456957121.exe"
"adstart"="\"iexplore.exe\" \"
http://iesettingsupdate\""[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CursorXP"="\"C:\\Program Files\\CursorXP\\CursorXP.exe\" -s"
"ef5d5a26.exe"="C:\\Documents and Settings\\Matt\\Local Settings\\Application Data\\ef5d5a26.exe"
"Ncao"="\"C:\\WINDOWS\\System32\\SSEMBL~1\\winlogon.exe\" -vt yax"
"Pikwai"="C:\\Program Files\\?ystem\\m?dtc.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoActiveDesktopChanges"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"DisableTaskMgr"=dword:00000000
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=hex:5f,00,00,00
@=""
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000000
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e7,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=dword:40000004
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
"{259BA022-2005-45E9-A965-10EDB9C00618}"="Windowz Updater"
"{A4F94C0C-54A7-4DB1-9AF3-B22E63D00322}"="g322"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{5A3E97DD-2A08-48BC-8F43-C0DEABC90266}"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Microsoft Office.lnk]
"path"="C:\\Documents and Settings\\All Users.WINDOWS\\Start Menu\\Programs\\Startup\\Microsoft Office.lnk"
"backup"="C:\\WINDOWS\\pss\\Microsoft Office.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\MICROS~2\\Office10\\OSA.EXE -b -l"
"item"="Microsoft Office"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^Matt^Start Menu^Programs^Startup^Adobe Gamma.lnk]
"path"="C:\\Documents and Settings\\Matt\\Start Menu\\Programs\\Startup\\Adobe Gamma.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Gamma.lnkStartup"
"location"="Startup"
"command"="C:\\PROGRA~1\\COMMON~1\\Adobe\\CALIBR~1\\ADOBEG~1.EXE "
"item"="Adobe Gamma"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^Matt^Start Menu^Programs^Startup^HotSync Manager.lnk]
"path"="C:\\Documents and Settings\\Matt\\Start Menu\\Programs\\Startup\\HotSync Manager.lnk"
"backup"="C:\\WINDOWS\\pss\\HotSync Manager.lnkStartup"
"location"="Startup"
"command"="C:\\PROGRA~1\\palmOne\\HOTSYNC.EXE "
"item"="HotSync Manager"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\!ewido]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ewido"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\ewido anti-spyware 4.0\\ewido.exe\" /minimized"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\iTunesHelper]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="iTunesHelper"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Lexmark X1100 Series]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="lxbkbmgr"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Lexmark X1100 Series\\lxbkbmgr.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\MSMSGS]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msmsgs"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\nwiz]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="nwiz"
"hkey"="HKLM"
"command"="nwiz.exe /install"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\SunJavaUpdateSched]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="jusched"
"hkey"="HKLM"
"command"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"inimapping"="0"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\h618
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljkiih
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mllml
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wineak32
Completion time: Thu 08/24/2006 21:13:29.24
ComboFix.txt
Hijack Log:
Logfile of HijackThis v1.99.1
Scan saved at 9:44:01 PM, on 8/24/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\TrojanHunter 4.5\THGuard.exe
C:\WINDOWS\sys015456957121.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\WgaTray.exe
C:\Program Files\Hijack This!\HijackThis.exe
F2 - REG:system.ini: UserInit=userinit.exe
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [Jet Detection] C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.5\THGuard.exe"
O4 - HKLM\..\Run: [xpv72e6e] RUNDLL32.EXE w3c66798.dll,n 00372e6b000000023c66798
O4 - HKLM\..\Run: [sys015456957121] C:\WINDOWS\sys015456957121.exe
O4 - HKCU\..\Run: [CursorXP] "C:\Program Files\CursorXP\CursorXP.exe" -s
O4 - HKCU\..\Run: [ef5d5a26.exe] C:\Documents and Settings\Matt\Local Settings\Application Data\ef5d5a26.exe
O4 - Global Startup: Belkin Wireless USB Utility.lnk = C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O15 - Trusted Zone: *.elitemediagroup.net
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.mmohsix.com
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) -
http://www.creative....026/CTSUEng.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.micros...b?1156300299077O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} -
http://yax-download.....cab?refid=1123O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoft...free/asinst.cabO16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) -
http://www.creative....15026/CTPID.cabO23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe