Hi Ryan,
MyToolbar and SurfSideKick were not listed in Add/Remove Programs but the other two were.
Thanks,
Perry
Dad - 06-09-27 22:30:50.14 Service Pack 1
ComboFix 06.09.27 - Running from: "C:\Documents and Settings\Dad\Desktop"
((((((((((((((((((((((((((((((((((((((((((((( Look2Me's Log ))))))))))))))))))))))))))))))))))))))))))))))))))
REGISTRY ENTRIES REMOVED:
[HKEY_CLASSES_ROOT\CLSID\{09C36710-146C-4FE6-90F5-C918A39D1DFD}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{09C36710-146C-4FE6-90F5-C918A39D1DFD}\Implemented Categories]
@=""
[HKEY_CLASSES_ROOT\CLSID\{09C36710-146C-4FE6-90F5-C918A39D1DFD}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""
[HKEY_CLASSES_ROOT\CLSID\{09C36710-146C-4FE6-90F5-C918A39D1DFD}\InprocServer32]
@="C:\\WINDOWS\\system32\\iprnonce.dll"
"ThreadingModel"="Apartment"
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
FILES REMOVED:
C:\WINDOWS\system32\f00olad31d0.dll
C:\WINDOWS\system32\fplq0335e.dll
C:\WINDOWS\system32\gp44l3hq1.dll
C:\WINDOWS\system32\gp8sl3l71.dll
C:\WINDOWS\system32\gpr8l39u1.dll
C:\WINDOWS\system32\hr4m05h1e.dll
C:\WINDOWS\system32\iprnonce.dll
C:\WINDOWS\system32\jt2407fqe.dll
C:\WINDOWS\system32\l8r00i9me8.dll
C:\WINDOWS\system32\meminst.dll
C:\WINDOWS\system32\mrdxmlc.dll
C:\WINDOWS\system32\mv40l9hm1.dll
C:\WINDOWS\system32\p26slcj71fo.dll
C:\WINDOWS\system32\q268lcju1fo8.dll
C:\WINDOWS\system32\q6nulg5916.dll
C:\WINDOWS\system32\r0r60a9sed.dll
C:\WINDOWS\system32\s2pulc791f.dll
C:\WINDOWS\system32\s488lelu1hq8.dll
C:\WINDOWS\system32\synike.dll
C:\WINDOWS\system32\guard.tmp
Granting sedebugprivilege to Administrators ... successful
((((((((((((((((((((((((((((((((((((((((((((( Qoologic's Log )))))))))))))))))))))))))))))))))))))))))))))))))))
* * * PRE-RUN - Filepaths extracted from the Registry * * * * * * * * * * * * * * * * * * * * * *
O4 - HKCU\...\Run C:\WINDOWS\system32\ctmpyq.exe
O4 - HKLM\...\Run C:\WINDOWS\System32\ctmpyq.exe
F2 -REG:system.ini: Shell C:\WINDOWS\System32\sedty.exe
F2 -REG:system.ini: UserInit C:\WINDOWS\system32\dykxjvf.exe
* * * PRE-RUN - Filepaths extracted by Memory Dump * * * * * * * * * * * * * * * * * * * * * *
C:\WINDOWS\system32\ctmpyq.exe
C:\WINDOWS\system32\ibmqpyq.dll
C:\WINDOWS\system32\dykxjvf.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\tcyqf.exe
C:\WINDOWS\aptwp.dll
C:\WINDOWS\system32\hrbtk.dat
C:\WINDOWS\system32\sedty.exe
* * * POST-RUN - Files in the Quarantine folder * * * * * * * * * * * * * * * * * * * * * * * * *
06-07-31 14:06 127488 ctmpyq.exe.qoo
06-07-31 14:06 127488 tcyqf.exe.qoo
06-09-26 20:16 127488 hrbtk.dat.qoo
06-09-26 21:13 73216 fdfvwrf.dll.qoo
06-07-31 14:06 51712 ibmqpyq.dll.qoo
06-07-31 14:06 28672 sedty.exe.qoo
06-07-31 14:06 23552 dykxjvf.exe.qoo
06-09-27 22:24 265 aptwp.dll.qoo
06-09-26 21:12 53 voweve.dat.qoo
DO NOT DELETE ANY FILES FROM THIS DIRECTORY UNLESS INSTRUCTED TO
((((((((((((((((((((((((((((((((((((((((((( E-Give / Ssk's Log )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\repairs303169590.dll
C:\Documents and Settings\Dad\Application Data\Sskcwrd.dll
C:\Documents and Settings\Dad\Application Data\Sskdmns.dll
C:\Documents and Settings\Dad\Application Data\Sskknwrd.dll
C:\Documents and Settings\Dad\Application Data\Sskuknwrd.dll
C:\WINDOWS\system32\bk.exe
C:\Program Files\surfsidekick 3\Ssk.exe
C:\Program Files\surfsidekick 3\SskBho.dll
C:\Program Files\surfsidekick 3\SskCore.dll
C:\WINDOWS\KIUJ0V.EXE
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
C:\WINDOWS\system32\repairs303169590.dll
C:\Program Files\surfsidekick 3\Ssk.exe
C:\Program Files\surfsidekick 3\SskBho.dll
C:\Program Files\surfsidekick 3\SskCore.dll
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\cfg32.exe
C:\WINDOWS\SYSC00.exe
C:\webnexmknew.exe
C:\Program Files\Common Files\elitemediagroupoinuninstaller.exe
C:\WINDOWS\system32\aaa00000.dll
C:\WINDOWS\system32\aaa00000.sys
C:\WINDOWS\system32\afdaqd3.exe
C:\WINDOWS\system32\apbzk.exe
C:\WINDOWS\system32\BattyRun.dll
C:\WINDOWS\system32\bez6n4r21.exe
C:\WINDOWS\system32\cvn0.exe
C:\WINDOWS\system32\cymmh.exe
C:\WINDOWS\system32\dexplore.dll
C:\WINDOWS\system32\dwdsregt.exe
C:\WINDOWS\system32\ftuninst.exe
C:\WINDOWS\system32\ghynf.exe
C:\WINDOWS\system32\ishost.exe
C:\WINDOWS\system32\ismini.exe
C:\WINDOWS\system32\kernels8.exe
C:\WINDOWS\system32\l3jdfs.exe
C:\WINDOWS\system32\mptft.exe
C:\WINDOWS\system32\n9nyb.exe
C:\WINDOWS\system32\redist.dll
C:\WINDOWS\system32\redistributor.exe
C:\WINDOWS\system32\scmt16.exe
C:\WINDOWS\system32\tfthot.exe
C:\WINDOWS\system32\tsuninst.exe
C:\WINDOWS\system32\vf1v62x.dll
C:\WINDOWS\system32\vp1i4.exe
C:\WINDOWS\system32\VSL05.exe
C:\WINDOWS\system32\wfxqhv.exe
C:\WINDOWS\system32\whcixm7.exe
C:\WINDOWS\system32\WinNB58.dll
C:\WINDOWS\system32\xeymi.dll
C:\WINDOWS\system32\y3aqsoepa.exe
C:\WINDOWS\system32\zqskw.exe
C:\visfx500new.exe
C:\WINDOWS\elpp100drop.exe
C:\WINDOWS\offun.exe
C:\WINDOWS\pf78.exe
C:\WINDOWS\ssqbn.exe
C:\WINDOWS\system32afdaqd3.exe
C:\WINDOWS\system32bez6n4r21.exe
C:\WINDOWS\system32cymmh.exe
C:\WINDOWS\system32ftuninst.exe
C:\WINDOWS\system32ghynf.exe
C:\WINDOWS\system32n9nyb.exe
C:\WINDOWS\System32tfthot.exe
C:\WINDOWS\system32y3aqsoepa.exe
C:\WINDOWS\thiselt.exe
C:\WINDOWS\uni_eh.exe
C:\WINDOWS\uni_ehhh.exe
C:\WINDOWS\unin101.exe
C:\WINDOWS\uninst104.exe
C:\WINDOWS\YOINSI.exe
C:\WINDOWS\MirarSetup_876075.exe
C:\WINDOWS\Eim03.exe
C:\WINDOWS\uni_ehhhh.exe
C:\Program Files\Common Files\Yazzle1438OinAdmin.exe
C:\Program Files\Common Files\Yazzle1438OinUninstaller.exe
C:\Program Files\Common Files\Yazzle1440OinAdmin.exe
C:\Program Files\Common Files\Yazzle1440OinUninstaller.exe
C:\Program Files\Common Files\Yazzle1452OinAdmin.exe
C:\Program Files\Common Files\Yazzle1452OinUninstaller.exe
C:\WINDOWS\uninstall_nmon.vbs
C:\WINDOWS\system32\w0017700.dll
C:\WINDOWS\system32\w00193ee.dll
C:\WINDOWS\system32\w001c09b.dll
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Program Files\Common Files\misc001
C:\Program Files\Common Files\simtest
C:\Program Files\Common Files\svchostsys
C:\Program Files\elticons
C:\Program Files\PSLister
C:\Program Files\Common Files\{64AF2382-0952-1033-1022-020816020001}
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\QooBox\Purity\Documents and Settings\Dad\Application Data\ICROSO~1
C:\QooBox\Purity\Documents and Settings\Dad\Application Data\ICROSO~1\nslookup.exe
C:\QooBox\Purity\Documents and Settings\Dad\Application Data\ICROSO~1\?icrosoft
C:\QooBox\Purity\Documents and Settings\Dad\My Documents\ICROSO~1.NET
C:\QooBox\Purity\WINDOWS\MANTEC~1
C:\QooBox\Purity\WINDOWS\SCURIT~1
C:\QooBox\Purity\WINDOWS\system32\RACLE~1
C:\QooBox\Purity\WINDOWS\system32\RACLE~1\iexplore.exe
C:\QooBox\Purity\WINDOWS\system32\RACLE~1\RACLE~1
((((((((((((((((((((((((((((((( Files Created from 2006-08-27 to 2006-09-27 ))))))))))))))))))))))))))))))))))
2006-09-27 20:18 830,553 ---hs---- C:\WINDOWS\system32\kjkmp.bak1
2006-09-27 20:18 577,588 ---hs---- C:\WINDOWS\system32\pmkjk.dll
2006-09-27 20:18 45,525 --a------ C:\WINDOWS\system32\bqrinpdd.dll
2006-09-27 20:18 143,380 --a------ C:\WINDOWS\system32\ieubrque.exe
2006-09-26 21:17 215,308 --a------ C:\WINDOWS\srvqygatrh.exe
2006-09-26 21:15 45,092 --a------ C:\WINDOWS\system32\ondsregj.exe
2006-09-26 21:14 4,786 --a------ C:\WINDOWS\system32\sachosts.exe
2006-09-26 21:13 93,696 --a------ C:\WINDOWS\system32\whuwobn.dll
2006-09-26 21:13 9,906 --a------ C:\WINDOWS\system32\sachostp.exe
2006-09-26 21:13 8,192 --a------ C:\yomhbmm.exe
2006-09-26 21:13 6,176 --a------ C:\WINDOWS\system32\z12.exe
2006-09-26 21:13 6,144 --a------ C:\WINDOWS\system32\msvcrl.dll
2006-09-26 21:13 5,332 --a------ C:\WINDOWS\system32\z13.exe
2006-09-26 21:13 5,298 --a------ C:\WINDOWS\system32\sachostc.exe
2006-09-26 21:13 32,768 --a------ C:\WINDOWS\system32\z11.exe
2006-09-26 21:13 26,152 --a------ C:\WINDOWS\sachostx.exe
2006-09-26 21:13 15 --a------ C:\WINDOWS\system32\dlh9jkdq8.exe
2006-09-26 21:13 131,072 --a------ C:\WINDOWS\system32\qftoxhm.dll
2006-09-26 21:12 892 --a------ C:\WINDOWS\system32\winpfg32.sys
2006-09-26 21:12 76,288 --a------ C:\bfdncc.exe
2006-09-26 21:12 547,824 -r-hs---- C:\WINDOWS\trnkgahA.exe
2006-09-26 21:12 53,120 --a------ C:\WINDOWS\srvjbibfen.exe
2006-09-26 21:12 518,784 -r-hs---- C:\WINDOWS\trnkgah.exe
2006-09-26 21:12 45,312 --a------ C:\WINDOWS\tct101.dll
2006-09-26 21:12 45,065 --a------ C:\WINDOWS\TIELT001.exe
2006-09-26 21:12 3,749 --a------ C:\WINDOWS\sysldr32.exe
2006-09-26 21:12 215,308 --a------ C:\WINDOWS\Setup90.exe
2006-09-26 21:12 183,476 --a------ C:\WINDOWS\srvmmcgxeg.exe
2006-09-26 21:12 168,062 --a------ C:\WINDOWS\system32\owinopes.exe
2006-09-26 21:12 15,872 --a------ C:\WINDOWS\system32\winrwq32.dll
2006-09-26 21:12 139,264 --a------ C:\WINDOWS\MirarSetup_876057.exe
2006-09-26 21:11 32,768 --a------ C:\WINDOWS\DXCecho.exe
2006-09-26 21:11 32,256 --a------ C:\WINDOWS\system32\dmonwv.dll
2006-09-26 21:11 268,581 --a------ C:\WINDOWS\popupwithcast.exe
2006-09-26 21:11 2,560 --a------ C:\WINDOWS\ac3_0018.exe
2006-09-26 21:11 2,560 --a------ C:\WINDOWS\ac3_0002.exe
2006-09-22 09:38 53,248 --a------ C:\WINDOWS\109uninst.exe
2006-09-22 09:36 53,248 --a------ C:\WINDOWS\uni_7eh.exe
2006-09-22 09:34 163,840 --a------ C:\WINDOWS\win32090168919949.exe
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-09-27 22:31 -------- d-------- C:\Program Files\Common Files
2006-09-27 20:42 -------- d-------- C:\Program Files\Hijackthis
2006-09-27 20:18 -------- d-------- C:\Program Files\VSToolbar
2006-09-26 21:20 -------- d-------- C:\Program Files\STOPzilla!
2006-09-26 21:13 2 --a------ C:\WINDOWS\system32\wnstssv.exe
2006-09-26 21:13 0 --a------ C:\Program Files\Common Files\ntldr.sys
2006-09-26 21:12 -------- d--h----- C:\Program Files\BHO Plugin
2006-09-26 21:12 -------- d-------- C:\Program Files\PSDream
2006-09-26 21:12 -------- d-------- C:\Program Files\popupwithcast
2006-09-26 21:11 32768 --a------ C:\WINDOWS\unstall.exe
2006-09-26 21:11 163840 --a------ C:\WINDOWS\sys101689199490.exe
2006-08-23 22:40 -------- d-------- C:\Program Files\ProSiteFinder
2006-08-23 22:40 -------- d-------- C:\Program Files\Hszwex
2006-08-23 22:40 -------- d-------- C:\Program Files\DIGStream
2006-08-23 22:40 -------- d-------- C:\Program Files\Common Files\iqif
2006-08-23 22:40 -------- d-------- C:\Program Files\Batty
2006-08-23 22:40 -------- d-------- C:\Program Files\Axqbdkt
2006-08-23 20:09 5120 --a------ C:\WINDOWS\SYSHOST.DLL
2006-08-23 20:07 -------- d-------- C:\Program Files\CleanUp!
2006-08-21 17:41 159744 --a------ C:\WINDOWS\VapeG22.exe
2006-08-21 17:41 159744 --a------ C:\WINDOWS\ms069490168919.exe
2006-08-21 17:41 159744 --a------ C:\WINDOWS\ms059949016891.exe
2006-08-14 21:36 1167 --a------ C:\WINDOWS\system32\olj65522.sys
2006-08-14 19:52 78848 --a------ C:\WINDOWS\system32\nsb21.dll
2006-08-11 11:05 155648 --a------ C:\WINDOWS\sys039199490168.exe
2006-08-11 11:05 155648 --a------ C:\WINDOWS\ms041994901689.exe
2006-08-07 00:55 -------- d-------- C:\Program Files\Symantec
2006-08-07 00:48 -------- d-------- C:\Program Files\TrojanHunter 4.2
2006-08-06 18:59 183296 --a-s---- C:\WINDOWS\NDNuninstall7_22.exe
2006-08-06 18:46 8464 --a------ C:\WINDOWS\system32\sporder.dll
2006-08-06 18:46 25105 --a------ C:\WINDOWS\idlemg.exe
2006-08-06 18:46 -------- d-------- C:\Program Files\rdso
2006-08-06 18:45 61952 --a------ C:\WINDOWS\system32\olj65522.dll
2006-08-06 18:45 -------- d-------- C:\Program Files\Xnvy
2006-08-06 18:45 -------- d-------- C:\Program Files\PSHope
2006-08-06 00:00 -------- d-------- C:\Program Files\Yjwvf
2006-07-31 23:49 0 --a------ C:\Documents and Settings\Dad\Application Data\internaldb41.dat
2006-07-31 23:45 32443 --a------ C:\WINDOWS\system32\uninstIcn.exe
2006-07-31 23:43 69632 --a------ C:\WINDOWS\system32\nfilhomn.dll
2006-07-31 23:43 69632 --a------ C:\WINDOWS\system32\daidbdaa.dll
2006-07-31 23:43 235134 --a------ C:\WINDOWS\srvjdgmjyb.exe
2006-07-31 23:43 184829 --a------ C:\WINDOWS\srvmfirurl.exe
2006-07-31 23:42 96768 --------- C:\WINDOWS\system32\repairs303169590.dll
2006-07-31 23:42 93664 --ahs---- C:\Program Files\Common Files\Y1304OU.exe
2006-07-31 23:42 183887 --a------ C:\WINDOWS\YazzleBundle-1304.exe
2006-07-31 23:42 143360 --a------ C:\WINDOWS\win32089016891994.exe
2006-07-31 23:42 -------- d-a------ C:\Program Files\SurfSideKick 3
2006-07-31 23:41 57344 --a------ C:\WINDOWS\ddhb.exe
2006-07-31 23:41 234248 --a------ C:\WINDOWS\Tagasuarus2.exe
2006-07-31 14:11 143360 --a------ C:\WINDOWS\win32074901689199.exe
2006-07-31 14:06 53248 --a------ C:\xxqap.exe
2006-07-31 14:06 53248 --a------ C:\tyojb.exe
2006-07-31 14:06 53248 --a------ C:\pvhjfte.exe
2006-07-31 14:06 28672 --a------ C:\WINDOWS\system32\iqqr.exe
2006-07-31 14:06 143360 --a------ C:\WINDOWS\sys0168919949012006.exe
2006-07-31 14:05 6581 --a------ C:\WINDOWS\svchost.exe
2006-07-31 14:05 6581 --a------ C:\WINDOWS\24545243171.exe
2006-07-31 14:05 6289 --a------ C:\WINDOWS\r836l32p.exe
2006-07-31 14:05 6253 --a------ C:\WINDOWS\loadnew.exe
2006-07-31 14:05 4096 -rah----- C:\WINDOWS\system32\syst2.dll
2006-07-31 14:05 10217 -r-h----- C:\WINDOWS\system32\win_3y4.exe
2006-07-31 14:05 0 --a------ C:\WINDOWS\dc2g41d4.exe
2006-07-13 15:13 36864 --a------ C:\WINDOWS\system32\ahnciup.exe
2006-07-13 15:13 1163264 --a------ C:\WINDOWS\system32\fhsxc.exe
2006-07-13 09:38 389120 --a------ C:\WINDOWS\system32\nodeipproc.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"Aida"="\"C:\\WINDOWS\\System32\\RACLE~1\\iexplore.exe\" -vt yazb"
"Ddvc"="C:\\WINDOWS\\System32\\?hkntfs.exe"
"PSHope"="\"C:\\Program Files\\PSHope\\PSHope.exe\""
"PSDream"="\"C:\\Program Files\\PSDream\\PSDream.exe\""
"Winsvr"="C:\\DOCUME~1\\Dad\\LOCALS~1\\Temp\\stdrun165632.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="RUNDLL32.EXE NvQTwk,NvCplDaemon initialize"
"diagent"="\"C:\\Program Files\\Creative\\SBLive\\Diagnostics\\diagent.exe\" startup"
"UpdReg"="C:\\WINDOWS\\UpdReg.EXE"
"AdaptecDirectCD"="\"C:\\Program Files\\Roxio\\Easy CD Creator 5\\DirectCD\\DirectCD.exe\""
"MMTray"="C:\\Program Files\\MUSICMATCH\\MUSICMATCH Jukebox\\mm_tray.exe"
"WorksFUD"="C:\\Program Files\\Microsoft Works\\wkfud.exe"
"Microsoft Works Portfolio"="C:\\Program Files\\Microsoft Works\\WksSb.exe /AllUsers"
"Microsoft Works Update Detection"="C:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\WkUFind.exe"
"MoneyStartUp10.0"="\"C:\\Program Files\\Microsoft Money\\System\\Activation.exe\""
"NAV Agent"="C:\\PROGRA~1\\NORTON~1\\navapw32.exe"
"DIGStream"="C:\\Program Files\\DIGStream\\digstream.exe"
"STOPzilla"="\"C:\\Program Files\\STOPzilla!\\Stopzilla.exe\" /autorun"
"Symantec NetDriver Monitor"="C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe /Consumer"
"SSC_UserPrompt"="C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\UsrPrmpt.exe"
"Share-to-Web Namespace Daemon"="C:\\Program Files\\Hewlett-Packard\\HP Share-to-Web\\hpgs2wnd.exe"
"abu"="abu.exe"
"ankkta"="C:\\WINDOWS\\System32\\dnjzck.exe r"
"cfxgjlm"="C:\\WINDOWS\\System32\\igsixnn.exe r"
"ckpngf"="c:\\windows\\system32\\jcqodc.exe r"
"dcefbr"="C:\\WINDOWS\\System32\\aholljo.exe r"
"dfzbfu"="c:\\windows\\system32\\raozve.exe r"
"Dinst"="C:\\WINDOWS\\dinst.exe"
"dxcnas"="C:\\WINDOWS\\System32\\blbrsel.exe r"
"gmnaku"="C:\\WINDOWS\\System32\\lrjsyn.exe r"
"hgebpqz"="C:\\WINDOWS\\System32\\eknzxdv.exe r"
"koodgu"="C:\\WINDOWS\\System32\\upxhhz.exe r"
"muiipb"="C:\\WINDOWS\\System32\\vvyceu.exe r"
"pathddv"="C:\\WINDOWS\\System32\\ucehdns.exe r"
"ProSiteFinder"="C:\\Program Files\\ProSiteFinder\\prositefinder.exe"
"qisbvy"="c:\\windows\\system32\\yfsjgs.exe r"
"qwubex"="C:\\WINDOWS\\System32\\bkxywz.exe r"
"rlktuf"="C:\\WINDOWS\\System32\\lmavuge.exe r"
"ttupt"="C:\\WINDOWS\\ttupt.exe"
"vfpopb"="C:\\WINDOWS\\System32\\panckza.exe r"
"vwwkgx"="c:\\windows\\system32\\jopvag.exe r"
"wwzoga"="C:\\WINDOWS\\System32\\fgxufu.exe r"
"xlxllo"="C:\\WINDOWS\\System32\\ptttynn.exe r"
"xsehqd"="C:\\WINDOWS\\System32\\cdqowl.exe r"
"zqxvkx"="C:\\WINDOWS\\System32\\zthomuw.exe r"
"KernelFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,\
65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b,00
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"loaddr"="C:\\DOCUME~1\\Dad\\LOCALS~1\\Temp\\silver.exe"
"k6mmN5IOU"="\"C:\\WINDOWS\\System32\\wfxqhv.exe\""
"ad8rIU3s"="C:\\WINDOWS\\System32\\cvn0.exe"
"win32074901689199"="C:\\WINDOWS\\win32074901689199.exe"
"epy9J"="\"C:\\WINDOWS\\System32\\l3jdfs.exe\""
"wGzyM6F48"="C:\\WINDOWS\\System32\\apbzk.exe"
"sys016891994901"="C:\\WINDOWS\\sys016891994901.exe"
"win32089016891994"="C:\\WINDOWS\\win32089016891994.exe"
"ftexc"="C:\\WINDOWS\\System32\\mptft.exe"
"ehlkhjcA"="C:\\WINDOWS\\ehlkhjcA.exe"
"olj65522"="RUNDLL32.EXE w002f8be.dll,n 0026552000000003002f8be"
"w0031f9f.dll"="RUNDLL32.EXE w0031f9f.dll,I2 0026552000031f9f"
"AUNPS2"="RUNDLL32 AUNPS2.DLL,_Run@16"
"cfgmgr52"="RunDLL32.EXE C:\\WINDOWS\\cfgmgr52.dll,DllRun"
"ms039199490168"="C:\\WINDOWS\\ms039199490168.exe"
"ms059949016891"="C:\\WINDOWS\\ms059949016891.exe"
"win32090168919949"="C:\\WINDOWS\\win32090168919949.exe"
"sys101689199490"="C:\\WINDOWS\\sys101689199490.exe"
"septpop06apsept"="C:\\program files\\popupwithcast\\septpop06apsept.exe"
"{F2-23-38-82-ZN}"="C:\\windows\\system32\\ondsregj.exe ELT001"
"ms069490168919"="C:\\WINDOWS\\ms069490168919.exe"
"sys039199490168"="C:\\WINDOWS\\sys039199490168.exe"
"whuwobn.dll"="C:\\WINDOWS\\System32\\rundll32.exe C:\\WINDOWS\\System32\\whuwobn.dll,duyhkwc"
"sachost"="C:\\WINDOWS\\sachostx.exe"
"ms041994901689"="C:\\WINDOWS\\ms041994901689.exe"
"trnkgahA"="C:\\WINDOWS\\trnkgahA.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Runonce]
"AAW"=""
"VundoFix"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Runonceex]
@=""
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000000
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=dword:40000004
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,f2,01,00,00,b9,00,00,00,7c,00,00,00,72,00,\
00,00,01,00,00,00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{54D9498B-CF93-414F-8984-8CE7FDE0D391}"="ewido shell guard"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"NoActiveDesktop"=dword:00000000
"ClassicShell"=dword:00000000
"ForceActiveDesktopOn"=dword:00000000
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
@=""
"NoDriveTypeAutoRun"=hex:5f,00,00,00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run]
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"CDRAutoRun"=dword:00000000
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"CDRAutoRun"=dword:00000000
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmkjk
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winrwq32
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp officejet 6100 series#1129011854.job
C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer.job
C:\WINDOWS\tasks\Symantec NetDetect.job
Completion time: Wed 09/27/2006 22:34:45.29
ComboFix.txt
Logfile of HijackThis v1.99.1
Scan saved at 10:36:52 PM, on 9/27/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.mrfindalo...asp?si=20073&k=R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://www.mrfindalo...asp?si=20073&k=R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [STOPzilla] "C:\Program Files\STOPzilla!\Stopzilla.exe" /autorun
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [abu] abu.exe
O4 - HKLM\..\Run: [ankkta] C:\WINDOWS\System32\dnjzck.exe r
O4 - HKLM\..\Run: [cfxgjlm] C:\WINDOWS\System32\igsixnn.exe r
O4 - HKLM\..\Run: [ckpngf] c:\windows\system32\jcqodc.exe r
O4 - HKLM\..\Run: [dcefbr] C:\WINDOWS\System32\aholljo.exe r
O4 - HKLM\..\Run: [dfzbfu] c:\windows\system32\raozve.exe r
O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe
O4 - HKLM\..\Run: [dxcnas] C:\WINDOWS\System32\blbrsel.exe r
O4 - HKLM\..\Run: [gmnaku] C:\WINDOWS\System32\lrjsyn.exe r
O4 - HKLM\..\Run: [hgebpqz] C:\WINDOWS\System32\eknzxdv.exe r
O4 - HKLM\..\Run: [koodgu] C:\WINDOWS\System32\upxhhz.exe r
O4 - HKLM\..\Run: [muiipb] C:\WINDOWS\System32\vvyceu.exe r
O4 - HKLM\..\Run: [pathddv] C:\WINDOWS\System32\ucehdns.exe r
O4 - HKLM\..\Run: [ProSiteFinder] C:\Program Files\ProSiteFinder\prositefinder.exe
O4 - HKLM\..\Run: [qisbvy] c:\windows\system32\yfsjgs.exe r
O4 - HKLM\..\Run: [qwubex] C:\WINDOWS\System32\bkxywz.exe r
O4 - HKLM\..\Run: [rlktuf] C:\WINDOWS\System32\lmavuge.exe r
O4 - HKLM\..\Run: [ttupt] C:\WINDOWS\ttupt.exe
O4 - HKLM\..\Run: [vfpopb] C:\WINDOWS\System32\panckza.exe r
O4 - HKLM\..\Run: [vwwkgx] c:\windows\system32\jopvag.exe r
O4 - HKLM\..\Run: [wwzoga] C:\WINDOWS\System32\fgxufu.exe r
O4 - HKLM\..\Run: [xlxllo] C:\WINDOWS\System32\ptttynn.exe r
O4 - HKLM\..\Run: [xsehqd] C:\WINDOWS\System32\cdqowl.exe r
O4 - HKLM\..\Run: [zqxvkx] C:\WINDOWS\System32\zthomuw.exe r
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [loaddr] C:\DOCUME~1\Dad\LOCALS~1\Temp\silver.exe
O4 - HKLM\..\Run: [k6mmN5IOU] "C:\WINDOWS\System32\wfxqhv.exe"
O4 - HKLM\..\Run: [ad8rIU3s] C:\WINDOWS\System32\cvn0.exe
O4 - HKLM\..\Run: [win32074901689199] C:\WINDOWS\win32074901689199.exe
O4 - HKLM\..\Run: [epy9J] "C:\WINDOWS\System32\l3jdfs.exe"
O4 - HKLM\..\Run: [wGzyM6F48] C:\WINDOWS\System32\apbzk.exe
O4 - HKLM\..\Run: [sys016891994901] C:\WINDOWS\sys016891994901.exe
O4 - HKLM\..\Run: [win32089016891994] C:\WINDOWS\win32089016891994.exe
O4 - HKLM\..\Run: [ftexc] C:\WINDOWS\System32\mptft.exe
O4 - HKLM\..\Run: [ehlkhjcA] C:\WINDOWS\ehlkhjcA.exe
O4 - HKLM\..\Run: [olj65522] RUNDLL32.EXE w002f8be.dll,n 0026552000000003002f8be
O4 - HKLM\..\Run: [w0031f9f.dll] RUNDLL32.EXE w0031f9f.dll,I2 0026552000031f9f
O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
O4 - HKLM\..\Run: [ms039199490168] C:\WINDOWS\ms039199490168.exe
O4 - HKLM\..\Run: [ms059949016891] C:\WINDOWS\ms059949016891.exe
O4 - HKLM\..\Run: [win32090168919949] C:\WINDOWS\win32090168919949.exe
O4 - HKLM\..\Run: [sys101689199490] C:\WINDOWS\sys101689199490.exe
O4 - HKLM\..\Run: [septpop06apsept] C:\program files\popupwithcast\septpop06apsept.exe
O4 - HKLM\..\Run: [{F2-23-38-82-ZN}] C:\windows\system32\ondsregj.exe ELT001
O4 - HKLM\..\Run: [ms069490168919] C:\WINDOWS\ms069490168919.exe
O4 - HKLM\..\Run: [sys039199490168] C:\WINDOWS\sys039199490168.exe
O4 - HKLM\..\Run: [whuwobn.dll] C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\whuwobn.dll,duyhkwc
O4 - HKLM\..\Run: [sachost] C:\WINDOWS\sachostx.exe
O4 - HKLM\..\Run: [ms041994901689] C:\WINDOWS\ms041994901689.exe
O4 - HKLM\..\Run: [trnkgahA] C:\WINDOWS\trnkgahA.exe
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Aida] "C:\WINDOWS\System32\RACLE~1\iexplore.exe" -vt yazb
O4 - HKCU\..\Run: [Ddvc] C:\WINDOWS\System32\?hkntfs.exe
O4 - HKCU\..\Run: [PSHope] "C:\Program Files\PSHope\PSHope.exe"
O4 - HKCU\..\Run: [PSDream] "C:\Program Files\PSDream\PSDream.exe"
O4 - HKCU\..\Run: [Winsvr] C:\DOCUME~1\Dad\LOCALS~1\Temp\stdrun165632.exe
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\dwdsregt.exe
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\owinopes.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office2000\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: officejet 6100.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O15 - Trusted Zone: *.elitemediagroup.net
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....467&clcid=0x409O16 - DPF: {97B79133-88F0-45F0-8D57-0F2EF27D9C66} -
http://85.255.114.166/1/rdgUS2404.exeO16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} (View22RTE Class) -
http://hgtv1.view22....p/view22rte.cabO16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) -
http://www.stopzilla...ller/dwnldr.cabO20 - AppInit_DLLs: repairs303169590.dll
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: STOPzilla Local Service - International Software Systems Solutions - C:\Program Files\STOPzilla!\szntsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\trnkgah.exe