Hi Sam thanks for fast reply.
Here is the log:
Kevin - 06-08-27 22:50:56.57
ComboFix 06.08.27BT - Running from: C:\Documents and Settings\Kevin\Desktop
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files\Common Files\Y1123OU.exe
C:\WINDOWS\system32\ishost.exe
C:\WINDOWS\system32\ismon.exe
C:\WINDOWS\system32\winsys.exe
C:\Program Files\ToolBar888
C:\Program Files\winupdates
C:\Program Files\Common Files\{CC65EBDA-0924-1033-0510-050921040001}
C:\Program Files\Common Files\{CC65EBDA-0951-1033-0510-050921040001}
C:\WINDOWS\system32\ishost.exe
C:\WINDOWS\system32\ismon.exe
C:\Program Files\Cowabanga
C:\WINDOWS\system32\components
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\QooBox\Purity\Documents and Settings\Kevin\Application Data\ICROSO~1.NET
C:\QooBox\Purity\Documents and Settings\Kevin\My Documents\SSTEM3~1
C:\QooBox\Purity\Documents and Settings\Kevin\My Documents\SSTEM3~1\spool32.exe
C:\QooBox\Purity\Documents and Settings\Kevin\My Documents\SSTEM3~1\SSTEM3~1
C:\QooBox\Purity\Program Files\WNSXS~1
C:\QooBox\Purity\Program Files\Common Files\RACLE~1
C:\QooBox\Purity\Program Files\Common Files\YSTEM~1
C:\QooBox\Purity\Program Files\Common Files\RACLE~1\??oolsv.exe
C:\QooBox\Purity\WINDOWS\system32\PPATCH~1
((((((((((((((((((((((((((((((( Files Created from 2006-07-27 to 2006-08-27 ))))))))))))))))))))))))))))))))))
2006-08-27 21:23 139,264 --a------ C:\WINDOWS\system32\vre.dll
2006-08-27 21:02 40,973 ---hs---- C:\WINDOWS\system32\xxyvsqp.dll
2006-08-27 21:02 13,312 --a------ C:\WINDOWS\system32\2f0f5fed.exe
2006-08-27 19:42 635,898 ---hs---- C:\WINDOWS\system32\srutv.bak1
2006-08-27 19:42 13,844 --a------ C:\WINDOWS\system32\otypaemx.exe
2006-08-27 19:41 573,492 ---hs---- C:\WINDOWS\system32\vturs.dll
2006-08-21 19:47 637,465 ---hs---- C:\WINDOWS\system32\ybadd.bak2
2006-08-21 19:47 13,844 --a------ C:\WINDOWS\system32\plptbvki.exe
2006-08-20 19:46 573,492 --ahs---- C:\WINDOWS\system32\ddaby.dll.vir
2006-08-20 19:25 721,602 ---hs---- C:\WINDOWS\system32\nqtss.bak1
2006-08-20 19:24 573,492 --ahs---- C:\WINDOWS\system32\sstqn.dll.vir
2006-08-20 18:43 5,120 --a------ C:\WINDOWS\system32\ismon.exe
2006-08-20 18:43 36,368 --a------ C:\WINDOWS\system32\ishost.exe
2006-08-19 22:52 180,224 --a-s---- C:\WINDOWS\system32\archlib.dll
2006-08-18 18:47 117,760 --------- C:\WINDOWS\system32\xmllite.dll
2006-08-12 11:36 40,973 --------- C:\WINDOWS\system32\awtqnkh.dll
2006-08-09 22:57 561,179 --a------ C:\WINDOWS\system32\dao360.dll
2006-08-09 22:57 185 --a------ C:\WINDOWS\system32\msblcd32.dll
2006-08-09 00:35 9,728 --a------ C:\WINDOWS\system32\sysinfoX64.sys
2006-08-09 00:35 8,192 --a------ C:\WINDOWS\system32\sysinfo.sys
2006-08-09 00:35 69,632 --a------ C:\WINDOWS\system32\sw24.exe
2006-08-09 00:35 208,896 --a------ C:\WINDOWS\system32\sw20.exe
2006-08-09 00:35 114,688 --a------ C:\WINDOWS\system32\sysinfo.dll
2006-08-08 22:42 94,208 --a------ C:\WINDOWS\system32\GTW32N50.dll
2006-08-08 22:42 40,960 --a------ C:\WINDOWS\system32\airlink101.dll
2006-08-08 22:42 15,872 --a------ C:\WINDOWS\system32\GTNDIS5.sys
2006-08-04 16:57 2 --a------ C:\WINDOWS\system32\wnstssv.exe
2006-08-04 16:54 18,944 --------- C:\WINDOWS\system32\winjks32.dll
2006-08-04 14:20 89,088 --a------ C:\WINDOWS\system32\atl71.dll
2006-08-04 14:20 1,047,552 --a------ C:\WINDOWS\system32\MFC71u.dll
2006-08-04 14:05 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2006-07-29 19:32 48,936 --a------ C:\WINDOWS\system32\sirenacm.dll
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-08-27 22:51 -------- d-------- C:\Program Files\Common Files
2006-08-27 00:39 -------- d-------- C:\Documents and Settings\Kevin\Application Data\Xfire
2006-08-27 00:38 -------- d-------- C:\Documents and Settings\Kevin\Application Data\Xfire Plus
2006-08-25 14:52 -------- d-------- C:\Program Files\PokerRoom.com
2006-08-23 22:09 -------- d-------- C:\Program Files\Windows Media Player
2006-08-22 20:18 98304 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2006-08-22 20:13 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-08-22 15:58 -------- d-------- C:\Documents and Settings\Kevin\Application Data\Apple Computer
2006-08-20 19:27 -------- d-------- C:\Program Files\Common Files\Java
2006-08-20 19:19 -------- d-------- C:\Documents and Settings\Kevin\Application Data\greateachsurf
2006-08-20 18:47 -------- d-------- C:\Program Files\Yahoo!
2006-08-19 22:56 -------- d-------- C:\Documents and Settings\Kevin\Application Data\Tenebril
2006-08-19 11:48 -------- d-------- C:\Program Files\MSN Messenger
2006-08-19 11:47 -------- d-------- C:\Program Files\Common Files\Microsoft Shared
2006-08-19 10:28 -------- d-------- C:\Program Files\iPod
2006-08-19 00:17 -------- d-------- C:\Program Files\Internet Explorer
2006-08-17 22:52 -------- d-------- C:\Program Files\Common Files\Wise Installation Wizard
2006-08-16 16:39 -------- d-------- C:\Program Files\HoldemPoker
2006-08-15 18:55 -------- d-------- C:\Program Files\MTV Networks
2006-08-13 12:15 -------- d-------- C:\Program Files\America's Army Server Manager
2006-08-12 11:34 -------- d-------- C:\Documents and Settings\Kevin\Application Data\TrojanHunter
2006-08-12 10:22 -------- d---s---- C:\Documents and Settings\Kevin\Application Data\Microsoft
2006-08-10 19:30 -------- d-------- C:\Documents and Settings\Kevin\Application Data\NetPumper
2006-08-10 15:41 -------- d-------- C:\Documents and Settings\Kevin\Application Data\BitTorrent
2006-08-09 22:57 -------- d-------- C:\Program Files\AF Uninstalls
2006-08-08 22:42 17801 --a------ C:\WINDOWS\system32\drivers\AegisP.sys
2006-08-08 13:36 65 --a------ C:\WINDOWS\taskmen.pif
2006-08-04 14:21 -------- d-------- C:\Documents and Settings\Kevin\Application Data\Logitech
2006-08-04 14:20 -------- d-------- C:\Program Files\Common Files\Logitech
2006-07-28 22:34 -------- d-------- C:\Program Files\AGEIA Technologies
2006-07-28 14:41 -------- d-------- C:\Program Files\Sierra On-Line
2006-07-27 09:24 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-07-23 13:15 -------- d-------- C:\Program Files\Poker.com
2006-07-21 04:24 72704 --a------ C:\WINDOWS\system32\hlink.dll
2006-07-20 15:58 -------- d-------- C:\Documents and Settings\Kevin\Application Data\Microgaming
2006-07-15 00:44 -------- d-------- C:\Documents and Settings\Kevin\Application Data\Microsoft Games
2006-07-15 00:15 223128 --a------ C:\WINDOWS\system32\drivers\dtscsi.sys
2006-07-15 00:14 96256 --a------ C:\WINDOWS\system32\drivers\sptd2381.sys
2006-07-15 00:14 643072 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2006-07-11 19:35 -------- d-------- C:\Program Files\directx
2006-07-03 17:40 778240 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2006-07-03 17:40 778240 --a------ C:\WINDOWS\system32\divx_xx07.dll
2006-07-03 17:40 761856 --a------ C:\WINDOWS\system32\divx_xx11.dll
2006-07-03 17:40 620180 --a------ C:\WINDOWS\system32\DivX.dll
2006-06-28 11:28 -------- d-------- C:\Program Files\Dell
2006-06-23 09:28 5512704 --------- C:\WINDOWS\system32\ieframe.dll
2006-06-23 09:28 47616 --------- C:\WINDOWS\system32\msfeedsbs.dll
2006-06-23 09:28 454144 --------- C:\WINDOWS\system32\msfeeds.dll
2006-06-23 09:28 413696 --a------ C:\WINDOWS\system32\vbscript.dll
2006-06-23 09:28 223744 --a------ C:\WINDOWS\system32\webcheck.dll
2006-06-23 09:28 179200 --------- C:\WINDOWS\system32\ieui.dll
2006-06-23 09:28 155648 --a------ C:\WINDOWS\system32\msls31.dll
2006-06-23 05:41 172544 --------- C:\WINDOWS\system32\WinFXDocObj.exe
2006-06-23 05:40 78848 --a------ C:\WINDOWS\system32\ieencode.dll
2006-06-23 05:40 40960 --a------ C:\WINDOWS\system32\url.dll
2006-06-23 05:39 99328 --a------ C:\WINDOWS\system32\occache.dll
2006-06-23 05:39 39424 --a------ C:\WINDOWS\system32\licmgr10.dll
2006-06-23 05:37 14336 --a------ C:\WINDOWS\system32\corpol.dll
2006-06-23 05:34 81920 --a------ C:\WINDOWS\system32\admparse.dll
2006-06-23 05:34 50688 --a------ C:\WINDOWS\system32\ie4uinit.exe
2006-06-23 05:34 372736 --a------ C:\WINDOWS\system32\iedkcs32.dll
2006-06-23 05:34 228864 --a------ C:\WINDOWS\system32\ieaksie.dll
2006-06-23 05:34 167936 --a------ C:\WINDOWS\system32\ieakeng.dll
2006-06-23 05:33 54272 --a------ C:\WINDOWS\system32\iesetup.dll
2006-06-23 05:33 41984 --a------ C:\WINDOWS\system32\iernonce.dll
2006-06-23 05:33 121856 --a------ C:\WINDOWS\system32\advpack.dll
2006-06-23 05:30 11776 --------- C:\WINDOWS\system32\msfeedssync.exe
2006-06-23 05:29 55296 --------- C:\WINDOWS\system32\icardie.dll
2006-06-23 05:29 35328 --a------ C:\WINDOWS\system32\imgutil.dll
2006-06-23 05:27 251392 --------- C:\WINDOWS\system32\iertutil.dll
2006-06-23 05:26 45568 --a------ C:\WINDOWS\system32\mshta.exe
2006-06-23 04:46 377856 --------- C:\WINDOWS\system32\ieapfltr.dll
2006-06-23 04:45 48640 --a------ C:\WINDOWS\system32\mshtmler.dll
2006-06-23 04:41 172032 --a------ C:\WINDOWS\system32\ieakui.dll
2006-06-21 15:44 109568 -----c--- C:\WINDOWS\system32\pxinsi64.exe
2006-06-21 06:49 53248 --a------ C:\WINDOWS\system32\dpuGUI10.dll
2006-06-21 06:43 520192 --a------ C:\WINDOWS\system32\DivXsm.exe
2006-06-21 06:43 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2006-06-21 06:42 200704 --a------ C:\WINDOWS\system32\ssldivx.dll
2006-06-21 06:42 1044480 --a------ C:\WINDOWS\system32\libdivx.dll
2006-06-21 06:34 90112 --a------ C:\WINDOWS\system32\dpl100.dll
2006-06-21 06:34 593920 --a------ C:\WINDOWS\system32\dpuGUI11.dll
2006-06-21 06:34 57344 --a------ C:\WINDOWS\system32\dpv11.dll
2006-06-21 06:34 344064 --a------ C:\WINDOWS\system32\dpus11.dll
2006-06-21 06:34 294912 --a------ C:\WINDOWS\system32\dpu11.dll
2006-06-21 06:34 294912 --a------ C:\WINDOWS\system32\dpu10.dll
2006-06-21 06:34 200704 --a------ C:\WINDOWS\system32\dtu100.dll
2006-06-21 06:33 12288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll
2006-06-21 06:33 118784 --a------ C:\WINDOWS\system32\DivXCodecUpdateChecker.exe
2006-06-19 15:18 23552 --------- C:\WINDOWS\system32\idndl.dll
2006-06-19 15:18 22752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2006-06-19 15:18 20480 --------- C:\WINDOWS\system32\normaliz.dll
2006-06-01 19:09 208896 --a--c--- C:\WINDOWS\system32\nvusmb.exe
2006-06-01 19:09 208896 --a--c--- C:\WINDOWS\system32\nvunrm.exe
2006-06-01 19:09 208896 --a--c--- C:\WINDOWS\system32\NVUNINST.EXE
2006-06-01 19:09 208896 --a--c--- C:\WINDOWS\system32\nvuide.exe
2006-06-01 19:09 208896 --a--c--- C:\WINDOWS\system32\nvuaudio.exe
2006-06-01 19:09 208896 -----c--- C:\WINDOWS\system32\nvudisp.exe
2006-06-01 17:22 888832 --a------ C:\WINDOWS\system32\nvmobls.dll
2006-06-01 17:22 5652480 --a------ C:\WINDOWS\system32\nvdisps.dll
2006-06-01 17:22 5246976 --a------ C:\WINDOWS\system32\nvdispsr.dll
2006-06-01 17:22 462848 --a------ C:\WINDOWS\system32\nvmccssr.dll
2006-06-01 17:22 3100672 --a------ C:\WINDOWS\system32\nvgames.dll
2006-06-01 17:22 2977792 --a------ C:\WINDOWS\system32\nvvitvsr.dll
2006-06-01 17:22 2924544 --a------ C:\WINDOWS\system32\nvvitvs.dll
2006-06-01 17:22 2916352 --a------ C:\WINDOWS\system32\nvgamesr.dll
2006-06-01 17:22 2859008 --a------ C:\WINDOWS\system32\nvmoblsr.dll
2006-06-01 17:22 188416 --a------ C:\WINDOWS\system32\nvmccss.dll
2006-06-01 17:22 1740800 --a------ C:\WINDOWS\system32\nvwssr.dll
2006-06-01 17:22 1257472 --a------ C:\WINDOWS\system32\nvwss.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVMixerTray"="\"C:\\Program Files\\NVIDIA Corporation\\NvMixer\\NVMixerTray.exe\""
"SmartGuardian"="E:\\Program Files\\SmartSpeed\\ITESmart.exe"
"NVIDIA nTune"="\"E:\\Program Files\\Ntune\\\\nTune.exe\" clear"
"NVCLOCK"="rundll32 nvclock.dll,fnNvclock"
"mmtask"="\"E:\\Program Files\\Musicmatch\\Musicmatch Jukebox\\mmtask.exe\""
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"DownloadAccelerator"="\"E:\\Program Files\\DAP\\DAP.EXE\" /STARTUP"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"SunJavaUpdateSched"="\"E:\\Program Files\\Java\\jre1.5.0_08\\bin\\jusched.exe\""
"MSConfig"="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\MSConfig.exe /auto"
"2f0f5fed.exe"="C:\\WINDOWS\\system32\\2f0f5fed.exe"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"2f0f5fed.exe"="C:\\Documents and Settings\\Kevin\\Local Settings\\Application Data\\2f0f5fed.exe"
"Trti"="\"C:\\DOCUME~1\\Kevin\\MYDOCU~1\\SSTEM3~1\\spool32.exe\" -vt yazr"
"Cbpcf"="C:\\Program Files\\Common Files\\?racle\\??oolsv.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoCDBurning"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,80,03,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{5A3E97DD-2A08-48BC-8F43-C0DEABC90266}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"
"{668B1E21-4DE0-450A-AB10-121220442EA6}"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^3D!Turbo Experience.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\3D!Turbo Experience.lnk"
"backup"="C:\\WINDOWS\\pss\\3D!Turbo Experience.lnkCommon Startup"
"location"="Common Startup"
"command"="E:\\PROGRA~1\\MSI\\3D!TUR~1\\3D!Turbo.exe "
"item"="3D!Turbo Experience"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SpyCatcher Protector.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\SpyCatcher Protector.lnk"
"backup"="C:\\WINDOWS\\pss\\SpyCatcher Protector.lnkCommon Startup"
"location"="Common Startup"
"command"="E:\\PROGRA~1\\SPYCAT~1\\PROTEC~1.EXE "
"item"="SpyCatcher Protector"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\BearShare]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="BearShare"
"hkey"="HKLM"
"command"="\"E:\\Program Files\\Opera\\BearShare.exe\" /pause"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Burnmeetteamflag]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="browse default"
"hkey"="HKLM"
"command"="C:\\Documents and Settings\\All Users\\Application Data\\ELSELOUDBURNMEET\\browse default.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\cash bib]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="BALLBINBOOB"
"hkey"="HKCU"
"command"="C:\\DOCUME~1\\Kevin\\APPLIC~1\\GREATE~1\\BALLBINBOOB.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\ctfmon.exe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ctfmon"
"hkey"="HKCU"
"command"="C:\\WINDOWS\\system32\\ctfmon.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\DAEMON Tools]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="daemon"
"hkey"="HKLM"
"command"="\"E:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\desktop]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="idemlog"
"hkey"="HKCU"
"command"="C:\\WINDOWS\\system32\\idemlog.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\EssSpkPhone]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="essspk"
"hkey"="HKLM"
"command"="essspk.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\iTunesHelper]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="iTunesHelper"
"hkey"="HKLM"
"command"="\"E:\\Program Files\\iTunes\\iTunesHelper.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\JAguAr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="CToolBar"
"hkey"="HKLM"
"command"="CToolBar.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Logitech Utility]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Logi_MwX"
"hkey"="HKLM"
"command"="Logi_MwX.Exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\MON76234]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="bingo9"
"hkey"="HKCU"
"command"="bingo9.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\MsnMsgr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="MsnMsgr"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\newbreed]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Kargo"
"hkey"="HKLM"
"command"="Kargo.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\PSPVideo9]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="pspVideo9"
"hkey"="HKLM"
"command"="C:\\Program Files\\pspvideo9\\pspVideo9.exe -t"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"E:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\SmartSpeed]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SmartSpeed2"
"hkey"="HKLM"
"command"="C:\\Program Files\\Smart-Speed\\SmartSpeed2.0.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\SpyCatcher Reminder]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SpyCatcher"
"hkey"="HKLM"
"command"="\"E:\\Program Files\\SpyCatcher 2006\\SpyCatcher.exe\" reminder"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Steam]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Steam"
"hkey"="HKCU"
"command"="E:\\Program Files\\Valve\\Steam\\\\Steam.exe -silent"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\SW20]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="sw20"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\sw20.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\SW24]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="sw24"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\sw24.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\SysSupport]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="keybdll"
"hkey"="HKCU"
"command"="keybdll.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\THGuard]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="THGuard"
"hkey"="HKLM"
"command"="\"E:\\TrojanHunter 4.5\\THGuard.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Two Degrees]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Two Degrees"
"hkey"="HKCU"
"command"="\"E:\\Program Files\\Two Degrees\\Two Degrees.exe\" /server"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\UnSpyPC]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="UnSpyPC"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\UnSpyPC\\UnSpyPC.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\services]
"ewido anti-spyware 4.0 guard"=dword:00000002
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vturs
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winjks32
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xxyvsqp
~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
backup-20060827-194617-472
O20 - Winlogon Notify: winjks32 - C:\WINDOWS\SYSTEM32\winjks32.dll
backup-20060827-194617-279
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
backup-20060827-194617-608
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
backup-20060827-194617-709
O17 - HKLM\System\CCS\Services\Tcpip\..\{FEA34390-D0AB-42E8-8BA9-523B7C2B8E3C}: NameServer = 85.255.113.150,85.255.112.12
backup-20060827-194617-933
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
backup-20060827-194617-995
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
backup-20060827-194617-784
O15 - Trusted Zone:
http://locator.cdn.imageservr.combackup-20060827-194617-322
O11 - Options group: [INTERNATIONAL] International*
backup-20060827-194617-839
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
backup-20060827-194617-247
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
backup-20060827-194617-546
O2 - BHO: (no name) - {A4F94C0C-54A7-4DB1-9AF3-B22E63D00303} - (no file)
backup-20060827-194617-788
O2 - BHO: (no name) - {A4F94C0C-54A7-4DB1-9AF3-B22E63D00304} - (no file)
backup-20060827-194617-347
O2 - BHO: (no name) - {A4F94C0C-54A7-4DB1-9AF3-B22E63D00311} - (no file)
backup-20060827-194617-849
O2 - BHO: (no name) - {A4F94C0C-54A7-4DB1-9AF3-B22E63D00309} - (no file)
backup-20060827-194617-305
O2 - BHO: (no name) - {DF00FFA0-AEA9-4EA8-A10F-8BB9A7F8508C} - (no file)
backup-20060827-194617-952
O2 - BHO: (no name) - {C02D8750-12EE-1237-B8C0-37B6AA9425C3} - (no file)
backup-20060827-194617-706
O2 - BHO: (no name) - {A4F94C0C-54A7-4DB1-9AF3-B22E63D00305} - (no file)
backup-20060827-194617-771
O2 - BHO: (no name) - {A4F94C0C-54A7-4DB1-9AF3-B22E63D00306} - (no file)
backup-20060827-194617-119
O2 - BHO: (no name) - {A4F94C0C-54A7-4DB1-9AF3-B22E63D00320} - (no file)
backup-20060827-194617-116
O2 - BHO: (no name) - {82EF4D84-D6CE-1EF0-AE5F-5878579E35B7} - (no file)
backup-20060827-194616-394
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
backup-20060827-194616-903
O2 - BHO: (no name) - {5E9968ED-5186-44DC-B46B-82B4EDE5B86D} - (no file)
backup-20060827-194616-657
O2 - BHO: (no name) - {621D36CC-09F4-44F6-BA4C-C8FBEAA00207} - (no file)
backup-20060827-194616-441
O2 - BHO: (no name) - {5A3E97DD-2A08-48BC-8F43-C0DEABC90266} - C:\WINDOWS\system32\awtqnkh.dll
backup-20060827-194616-710
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - E:\Program Files\Opera\GetRight\xx2gr.dll
backup-20060827-194616-421
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....cid={SUB_CLCID}backup-20060827-194616-244
O2 - BHO: (no name) - {0A87E45F-537A-40B4-B812-E2544C21A09F} - (no file)
backup-20060827-194616-511
O2 - BHO: (no name) - {0B5F7FDF-0717-45BF-B49D-695F3168C7FE} - (no file)
backup-20060827-194616-263
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896backup-20060827-194616-867
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896backup-20060827-194616-108
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=54729backup-20060820-192916-446
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} -
http://yax-download.....cab?refid=1123backup-20060820-192916-271
O4 - HKCU\..\Run: [2f0f5fed.exe] C:\Documents and Settings\Kevin\Local Settings\Application Data\2f0f5fed.exe
backup-20060820-192916-354
O4 - HKLM\..\Run: [2f0f5fed.exe] C:\WINDOWS\system32\2f0f5fed.exe
backup-20060820-152002-403
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} -
http://launch.gamesp...nch/alaunch.cabbackup-20060820-152001-429
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
backup-20060820-152001-272
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
backup-20060820-152001-792
R3 - Default URLSearchHook is missing
backup-20060813-154859-156
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) -
http://fdl.msn.com/z...s/heartbeat.cabbackup-20060813-154859-328
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://zone.msn.com/...ro.cab34246.cabbackup-20060813-154859-550
O16 - DPF: {AED98630-0251-4E83-917D-43A23D66D507} (Download Helper Class) -
http://activex.micro...n7/dlhelper.cabbackup-20060813-154859-863
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
backup-20060813-154859-904
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
backup-20060813-154859-124
O8 - Extra context menu item: Open with GetRight Browser - E:\Program Files\Opera\GetRight\GRbrowse.htm
backup-20060813-154859-341
O4 - HKLM\..\Run: [SpeedOptimizer] E:\PROGRA~1\DAP\SPEEDO~1\SPO.EXE -s
backup-20060812-134726-585
O9 - Extra button: Poker.com - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - C:\Program Files\Poker.com\poker.exe (HKCU)
backup-20060812-134726-126
O9 - Extra button: Royal Vegas Poker - {FA4904B4-1FAF-4afd-886C-C19D2297BA62} - C:\Program Files\royalvegasMPP\MPPoker.exe (file missing)
backup-20060812-134726-357
O9 - Extra 'Tools' menuitem: Absolute Poker - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
backup-20060812-134726-224
O9 - Extra button: Absolute Poker - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
backup-20060812-134726-576
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - E:\Program Files\PartyPoker\PartyPoker.exe (file missing)
backup-20060812-134726-714
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - E:\Program Files\PartyPoker\PartyPoker.exe (file missing)
backup-20060812-134726-841
O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - E:\Program Files\EmpirePoker\EmpirePoker.exe (file missing)
backup-20060812-134726-723
O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - E:\Program Files\EmpirePoker\EmpirePoker.exe (file missing)
backup-20060812-134726-867
O9 - Extra button: Poker.com - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - C:\Program Files\Poker.com\poker.exe
backup-20060812-134726-481
O9 - Extra 'Tools' menuitem: Intertops Poker - {5706EACE-252A-4af9-AA8D-1F8813B50469} - E:\Program Files\Intertops Poker\IntertopsPoker.exe (file missing)
backup-20060812-134726-778
O9 - Extra button: Intertops Poker - {5706EACE-252A-4af9-AA8D-1F8813B50469} - E:\Program Files\Intertops Poker\IntertopsPoker.exe (file missing)
backup-20060812-134726-888
O8 - Extra context menu item: Download with NetPumper - E:\NetPumper\AddUrl.htm
backup-20060812-134726-678
O8 - Extra context menu item: Download with GetRight - E:\Program Files\Opera\GetRight\GRdownload.htm
backup-20060812-134726-898
O4 - HKCU\..\Run: [cash bib] C:\DOCUME~1\Kevin\APPLIC~1\GREATE~1\BALLBINBOOB.exe
backup-20060812-134726-981
O4 - HKCU\..\Run: [BitTorrent] "E:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
backup-20060812-105844-862
O4 - HKLM\..\Run: [NetPumper] "E:\NetPumper\NetPumperIEProxy.exe"
backup-20060812-105844-945
O3 - Toolbar: DAP Bar - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - E:\Program Files\DAP\DAPIEBar.dll
Completion time: Sun 08/27/2006 22:52:42.43
ComboFix.txt