Logfile of HijackThis v1.99.1
Scan saved at 1:08:53 PM, on 9/30/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Personal Firewall\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Norton Personal Firewall - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\npjpi150_07.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\npjpi150_07.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...can_unicode.cabO16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) -
http://www.symantec....rl/LSSupCtl.cabO16 - DPF: {2DFF31F9-7893-4922-AF66-C9A1EB4EBB31} (Rhapsody Player Engine) -
http://forms.real.co...ne_Inst_Win.cabO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) -
http://www.symantec....rl/SymAData.cabO16 - DPF: {E13F1132-4CA0-4005-84D3-51406E27D269} (BTDownloadCtrl Control) -
http://www.shockwave...ownloadCtrl.cabO23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\ISSVC.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Owner - 06-09-30 12:46:10.71 Service Pack 2
ComboFix 06.09.28 - Running from: "C:\"
Command switches used :: /v mfcusl ipv6monl.dll
(((((((((((((((((((((((((((((((((((((((((((((((( Vundo Log )))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\mfcusl.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\QooBox\Purity\Documents and Settings\Owner\My Documents\MCROSO~1
C:\QooBox\Purity\Documents and Settings\Owner\My Documents\MCROSO~1\M?crosoft
C:\QooBox\Purity\Program Files\ASEMBL~1
C:\QooBox\Purity\Program Files\SMANTE~1
C:\QooBox\Purity\Program Files\WNSXS~1
C:\QooBox\Purity\Program Files\SMANTE~1\SMANTE~1
C:\QooBox\Purity\WINDOWS\RACLE~1
C:\QooBox\Purity\WINDOWS\STEM32~1
C:\QooBox\Purity\WINDOWS\STEM32~1\STEM32~1
((((((((((((((((((((((((((((((( Files Created from 2006-08-30 to 2006-09-30 ))))))))))))))))))))))))))))))))))
2006-09-30 09:31 276,526 --a------ C:\combofix.exe
2006-09-30 09:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2006-09-30 09:13 40,960 --a------ C:\WINDOWS\system32\swsc.exe
2006-09-30 09:13 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2006-09-30 09:13 135,168 --a------ C:\WINDOWS\system32\swreg.exe
2006-09-29 19:26 218,112 --a------ C:\Copy of HijackThis.exe
2006-09-29 17:34 4,608 --a------ C:\WINDOWS\system32\drivers\symlcbrd.sys
2006-09-28 17:17 63,192 --a------ C:\WINDOWS\system32\ipv6monl.dll
2006-09-28 17:16 18,432 --a------ C:\svhost.exe
2006-09-22 19:31 23,434 --a------ C:\WINDOWS\system32\mljgg.exe
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-09-30 12:38 -------- d-------- C:\Program Files\Common Files
2006-09-30 11:57 -------- d-------- C:\Program Files\Common Files\Symantec Shared
2006-09-29 22:44 -------- d-------- C:\Program Files\Norton SystemWorks
2006-09-29 18:20 -------- d-------- C:\Program Files\Norton Personal Firewall
2006-09-29 18:03 -------- d-------- C:\Program Files\Symantec
2006-09-29 17:12 -------- d-------- C:\Program Files\SymNetDrv
2006-09-27 17:04 -------- dr-h----- C:\Documents and Settings\Owner\Application Data\yahoo!
2006-09-27 17:04 -------- d-------- C:\Documents and Settings\Owner\Application Data\ZangoToolbar
2006-09-26 22:53 -------- d-------- C:\Program Files\iTunes
2006-09-23 11:58 -------- d-------- C:\Program Files\Viewpoint
2006-09-21 09:12 -------- d-------- C:\Documents and Settings\Owner\Application Data\MP3Rocket
2006-09-20 14:30 -------- d-------- C:\Program Files\QuickTime
2006-09-15 22:52 91904 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2006-09-15 22:52 124016 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2006-09-15 19:37 -------- d-------- C:\Program Files\Yahoo!
2006-09-15 17:06 -------- d-------- C:\Program Files\AIM
2006-09-15 17:06 -------- d-------- C:\Documents and Settings\Owner\Application Data\Aim
2006-09-15 17:05 -------- d-------- C:\Program Files\AOD
2006-09-13 13:14 -------- d-------- C:\Program Files\Multimedia Card Reader
2006-09-13 11:49 -------- d-------- C:\Documents and Settings\Owner\Application Data\AdobeUM
2006-09-12 19:07 -------- d-------- C:\Program Files\iPod
2006-09-12 19:02 -------- d-------- C:\Program Files\Apple Software Update
2006-09-12 12:29 -------- d-------- C:\Documents and Settings\Owner\Application Data\MSN6
2006-09-11 11:53 -------- d-------- C:\Documents and Settings\Owner\Application Data\Motive
2006-09-11 11:52 -------- d-------- C:\Program Files\MSN
2006-09-08 20:55 -------- d-------- C:\Program Files\AOL
2006-09-08 20:55 -------- d-------- C:\Documents and Settings\Owner\Application Data\acccore
2006-09-08 20:54 -------- d-------- C:\Program Files\Common Files\Nullsoft
2006-09-08 20:54 -------- d-------- C:\Program Files\Common Files\aolshare
2006-09-08 20:54 -------- d-------- C:\Program Files\Common Files\AOL
2006-09-07 09:57 -------- d-------- C:\Program Files\Wide Angle Software
2006-09-03 09:18 -------- d-------- C:\Program Files\Messenger
2006-08-28 20:59 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-08-27 18:40 -------- d-------- C:\Documents and Settings\Owner\Application Data\InterVideo
2006-08-12 19:58 -------- d-------- C:\Program Files\Common Files\Sonic Shared
2006-08-12 19:57 -------- d-------- C:\Program Files\Common Files\HP
2006-08-12 19:48 -------- d-------- C:\Program Files\HP
2006-08-12 19:48 -------- d-------- C:\Program Files\Hewlett-Packard
2006-08-12 19:36 -------- d-------- C:\Documents and Settings\Owner\Application Data\HP
2006-08-12 11:49 -------- d---s---- C:\Documents and Settings\Owner\Application Data\Microsoft
2006-08-10 16:48 -------- d-------- C:\Program Files\Windows Media Player
2006-08-10 16:48 -------- d-------- C:\Program Files\Movie Maker
2006-08-10 16:48 -------- d-------- C:\Program Files\Internet Explorer
2006-08-10 16:48 -------- d-------- C:\Program Files\Common Files\System
2006-08-10 16:44 -------- d-------- C:\Program Files\Windows NT
2006-08-10 16:44 -------- d-------- C:\Program Files\Outlook Express
2006-08-10 16:44 -------- d-------- C:\Program Files\NetMeeting
2006-08-03 18:45 147495 --a------ C:\WINDOWS\system32\rmocx.dll
2006-08-03 18:44 -------- d-------- C:\Documents and Settings\Owner\Application Data\Real
2006-07-14 14:51 108144 --a------ C:\WINDOWS\system32\GEARAspi.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"BackupNotify"="c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\backupnotify.exe"
"Yahoo! Pager"="\"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe\" -quiet"
"NVIEW"="rundll32.exe nview.dll,nViewLoadHook"
"Norton SystemWorks"="\"C:\\Program Files\\Norton SystemWorks\\cfgwiz.exe\" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"="nwiz.exe /installquiet /keeploaded /nodetect"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"ViewMgr"="C:\\Program Files\\Viewpoint\\Viewpoint Manager\\ViewMgr.exe"
"Symantec NetDriver Monitor"="C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000005
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Notn"="\"C:\\WINDOWS\\STEM32~1\\winspool.exe\" -vt yazr"
"Bethgd"="C:\\Program Files\\a?sembly\\r?ndll.exe"
"kfkz"="C:\\PROGRA~1\\COMMON~1\\kfkz\\kfkzm.exe"
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Notn"="\"C:\\WINDOWS\\STEM32~1\\winspool.exe\" -vt yazr"
"Bethgd"="C:\\Program Files\\a?sembly\\r?ndll.exe"
"kfkz"="C:\\PROGRA~1\\COMMON~1\\kfkz\\kfkzm.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{54D9498B-CF93-414F-8984-8CE7FDE0D391}"="ewido shell guard"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer - Owner.job
C:\WINDOWS\tasks\Norton SystemWorks One Button Checkup.job
C:\WINDOWS\tasks\Symantec Drmc.job
Completion time: Sat 09/30/2006 12:48:15.23
ComboFix.txt
ComboFix2.txt
Owner - 06-09-30 13:04:07.34 Service Pack 2
ComboFix 06.09.28 - Running from: "C:\"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\QooBox\Purity\Documents and Settings\Owner\My Documents\MCROSO~1
C:\QooBox\Purity\Documents and Settings\Owner\My Documents\MCROSO~1\M?crosoft
C:\QooBox\Purity\Program Files\ASEMBL~1
C:\QooBox\Purity\Program Files\SMANTE~1
C:\QooBox\Purity\Program Files\WNSXS~1
C:\QooBox\Purity\Program Files\SMANTE~1\SMANTE~1
C:\QooBox\Purity\WINDOWS\RACLE~1
C:\QooBox\Purity\WINDOWS\STEM32~1
C:\QooBox\Purity\WINDOWS\STEM32~1\STEM32~1
((((((((((((((((((((((((((((((( Files Created from 2006-08-30 to 2006-09-30 ))))))))))))))))))))))))))))))))))
2006-09-30 09:31 276,526 --a------ C:\combofix.exe
2006-09-30 09:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2006-09-30 09:13 40,960 --a------ C:\WINDOWS\system32\swsc.exe
2006-09-30 09:13 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2006-09-30 09:13 135,168 --a------ C:\WINDOWS\system32\swreg.exe
2006-09-29 19:26 218,112 --a------ C:\Copy of HijackThis.exe
2006-09-29 17:34 4,608 --a------ C:\WINDOWS\system32\drivers\symlcbrd.sys
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-09-30 12:48 -------- d-------- C:\Program Files\Common Files
2006-09-30 11:57 -------- d-------- C:\Program Files\Common Files\Symantec Shared
2006-09-29 22:44 -------- d-------- C:\Program Files\Norton SystemWorks
2006-09-29 18:20 -------- d-------- C:\Program Files\Norton Personal Firewall
2006-09-29 18:03 -------- d-------- C:\Program Files\Symantec
2006-09-29 17:12 -------- d-------- C:\Program Files\SymNetDrv
2006-09-27 17:04 -------- dr-h----- C:\Documents and Settings\Owner\Application Data\yahoo!
2006-09-27 17:04 -------- d-------- C:\Documents and Settings\Owner\Application Data\ZangoToolbar
2006-09-26 22:53 -------- d-------- C:\Program Files\iTunes
2006-09-23 11:58 -------- d-------- C:\Program Files\Viewpoint
2006-09-21 09:12 -------- d-------- C:\Documents and Settings\Owner\Application Data\MP3Rocket
2006-09-20 14:30 -------- d-------- C:\Program Files\QuickTime
2006-09-15 22:52 91904 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2006-09-15 22:52 124016 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2006-09-15 19:37 -------- d-------- C:\Program Files\Yahoo!
2006-09-15 17:06 -------- d-------- C:\Program Files\AIM
2006-09-15 17:06 -------- d-------- C:\Documents and Settings\Owner\Application Data\Aim
2006-09-15 17:05 -------- d-------- C:\Program Files\AOD
2006-09-13 13:14 -------- d-------- C:\Program Files\Multimedia Card Reader
2006-09-13 11:49 -------- d-------- C:\Documents and Settings\Owner\Application Data\AdobeUM
2006-09-12 19:07 -------- d-------- C:\Program Files\iPod
2006-09-12 19:02 -------- d-------- C:\Program Files\Apple Software Update
2006-09-12 12:29 -------- d-------- C:\Documents and Settings\Owner\Application Data\MSN6
2006-09-11 11:53 -------- d-------- C:\Documents and Settings\Owner\Application Data\Motive
2006-09-11 11:52 -------- d-------- C:\Program Files\MSN
2006-09-08 20:55 -------- d-------- C:\Program Files\AOL
2006-09-08 20:55 -------- d-------- C:\Documents and Settings\Owner\Application Data\acccore
2006-09-08 20:54 -------- d-------- C:\Program Files\Common Files\Nullsoft
2006-09-08 20:54 -------- d-------- C:\Program Files\Common Files\aolshare
2006-09-08 20:54 -------- d-------- C:\Program Files\Common Files\AOL
2006-09-07 09:57 -------- d-------- C:\Program Files\Wide Angle Software
2006-09-03 09:18 -------- d-------- C:\Program Files\Messenger
2006-08-28 20:59 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-08-27 18:40 -------- d-------- C:\Documents and Settings\Owner\Application Data\InterVideo
2006-08-12 19:58 -------- d-------- C:\Program Files\Common Files\Sonic Shared
2006-08-12 19:57 -------- d-------- C:\Program Files\Common Files\HP
2006-08-12 19:48 -------- d-------- C:\Program Files\HP
2006-08-12 19:48 -------- d-------- C:\Program Files\Hewlett-Packard
2006-08-12 19:36 -------- d-------- C:\Documents and Settings\Owner\Application Data\HP
2006-08-12 11:49 -------- d---s---- C:\Documents and Settings\Owner\Application Data\Microsoft
2006-08-10 16:48 -------- d-------- C:\Program Files\Windows Media Player
2006-08-10 16:48 -------- d-------- C:\Program Files\Movie Maker
2006-08-10 16:48 -------- d-------- C:\Program Files\Internet Explorer
2006-08-10 16:48 -------- d-------- C:\Program Files\Common Files\System
2006-08-10 16:44 -------- d-------- C:\Program Files\Windows NT
2006-08-10 16:44 -------- d-------- C:\Program Files\Outlook Express
2006-08-10 16:44 -------- d-------- C:\Program Files\NetMeeting
2006-08-03 18:45 147495 --a------ C:\WINDOWS\system32\rmocx.dll
2006-08-03 18:44 -------- d-------- C:\Documents and Settings\Owner\Application Data\Real
2006-07-14 14:51 108144 --a------ C:\WINDOWS\system32\GEARAspi.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"BackupNotify"="c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\backupnotify.exe"
"Yahoo! Pager"="\"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe\" -quiet"
"NVIEW"="rundll32.exe nview.dll,nViewLoadHook"
"Norton SystemWorks"="\"C:\\Program Files\\Norton SystemWorks\\cfgwiz.exe\" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"="nwiz.exe /installquiet /keeploaded /nodetect"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"ViewMgr"="C:\\Program Files\\Viewpoint\\Viewpoint Manager\\ViewMgr.exe"
"Symantec NetDriver Monitor"="C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000005
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{54D9498B-CF93-414F-8984-8CE7FDE0D391}"="ewido shell guard"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer - Owner.job
C:\WINDOWS\tasks\Norton SystemWorks One Button Checkup.job
C:\WINDOWS\tasks\Symantec Drmc.job
Completion time: Sat 09/30/2006 13:04:54.20
ComboFix.txt
ComboFix2.txt
ComboFix3.txt
Owner - 06-09-30 9:32:21.04 Service Pack 2
ComboFix 06.09.28 - Running from: "C:\Documents and Settings\Owner\Desktop"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\wnstssu.exe
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\QooBox\Purity\Documents and Settings\Owner\My Documents\MCROSO~1
C:\QooBox\Purity\Documents and Settings\Owner\My Documents\MCROSO~1\M?crosoft
C:\QooBox\Purity\Program Files\ASEMBL~1
C:\QooBox\Purity\Program Files\SMANTE~1
C:\QooBox\Purity\Program Files\WNSXS~1
C:\QooBox\Purity\Program Files\SMANTE~1\SMANTE~1
C:\QooBox\Purity\WINDOWS\RACLE~1
C:\QooBox\Purity\WINDOWS\STEM32~1
C:\QooBox\Purity\WINDOWS\STEM32~1\STEM32~1
((((((((((((((((((((((((((((((( Files Created from 2006-08-30 to 2006-09-30 ))))))))))))))))))))))))))))))))))
2006-09-30 09:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2006-09-30 09:13 40,960 --a------ C:\WINDOWS\system32\swsc.exe
2006-09-30 09:13 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2006-09-30 09:13 135,168 --a------ C:\WINDOWS\system32\swreg.exe
2006-09-29 19:26 218,112 --a------ C:\Copy of HijackThis.exe
2006-09-29 17:34 4,608 --a------ C:\WINDOWS\system32\drivers\symlcbrd.sys
2006-09-28 17:17 63,192 --a------ C:\WINDOWS\system32\ipv6monl.dll
2006-09-28 17:16 18,432 --a------ C:\svhost.exe
2006-09-22 19:31 23,434 --a------ C:\WINDOWS\system32\mljgg.exe
2006-09-22 19:31 16,934 --a------ C:\WINDOWS\system32\mfcusl.dll
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-09-29 22:44 -------- d-------- C:\Program Files\Norton SystemWorks
2006-09-29 20:20 -------- d-------- C:\Program Files\Common Files\Symantec Shared
2006-09-29 18:20 -------- d-------- C:\Program Files\Norton Personal Firewall
2006-09-29 18:12 -------- d-------- C:\Program Files\Common Files
2006-09-29 18:03 -------- d-------- C:\Program Files\Symantec
2006-09-29 17:12 -------- d-------- C:\Program Files\SymNetDrv
2006-09-27 17:04 -------- dr-h----- C:\Documents and Settings\Owner\Application Data\yahoo!
2006-09-27 17:04 -------- d-------- C:\Documents and Settings\Owner\Application Data\ZangoToolbar
2006-09-26 22:53 -------- d-------- C:\Program Files\iTunes
2006-09-23 11:58 -------- d-------- C:\Program Files\Viewpoint
2006-09-21 09:12 -------- d-------- C:\Documents and Settings\Owner\Application Data\MP3Rocket
2006-09-20 14:30 -------- d-------- C:\Program Files\QuickTime
2006-09-15 22:52 91904 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2006-09-15 22:52 124016 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2006-09-15 19:37 -------- d-------- C:\Program Files\Yahoo!
2006-09-15 17:06 -------- d-------- C:\Program Files\AIM
2006-09-15 17:06 -------- d-------- C:\Documents and Settings\Owner\Application Data\Aim
2006-09-15 17:05 -------- d-------- C:\Program Files\AOD
2006-09-13 13:14 -------- d-------- C:\Program Files\Multimedia Card Reader
2006-09-13 11:49 -------- d-------- C:\Documents and Settings\Owner\Application Data\AdobeUM
2006-09-12 19:07 -------- d-------- C:\Program Files\iPod
2006-09-12 19:02 -------- d-------- C:\Program Files\Apple Software Update
2006-09-12 12:29 -------- d-------- C:\Documents and Settings\Owner\Application Data\MSN6
2006-09-11 11:53 -------- d-------- C:\Documents and Settings\Owner\Application Data\Motive
2006-09-11 11:52 -------- d-------- C:\Program Files\MSN
2006-09-08 20:55 -------- d-------- C:\Program Files\AOL
2006-09-08 20:55 -------- d-------- C:\Documents and Settings\Owner\Application Data\acccore
2006-09-08 20:54 -------- d-------- C:\Program Files\Common Files\Nullsoft
2006-09-08 20:54 -------- d-------- C:\Program Files\Common Files\aolshare
2006-09-08 20:54 -------- d-------- C:\Program Files\Common Files\AOL
2006-09-07 09:57 -------- d-------- C:\Program Files\Wide Angle Software
2006-09-03 09:18 -------- d-------- C:\Program Files\Messenger
2006-08-28 20:59 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-08-27 18:40 -------- d-------- C:\Documents and Settings\Owner\Application Data\InterVideo
2006-08-12 19:58 -------- d-------- C:\Program Files\Common Files\Sonic Shared
2006-08-12 19:57 -------- d-------- C:\Program Files\Common Files\HP
2006-08-12 19:48 -------- d-------- C:\Program Files\HP
2006-08-12 19:48 -------- d-------- C:\Program Files\Hewlett-Packard
2006-08-12 19:36 -------- d-------- C:\Documents and Settings\Owner\Application Data\HP
2006-08-12 11:49 -------- d---s---- C:\Documents and Settings\Owner\Application Data\Microsoft
2006-08-10 16:48 -------- d-------- C:\Program Files\Windows Media Player
2006-08-10 16:48 -------- d-------- C:\Program Files\Movie Maker
2006-08-10 16:48 -------- d-------- C:\Program Files\Internet Explorer
2006-08-10 16:48 -------- d-------- C:\Program Files\Common Files\System
2006-08-10 16:44 -------- d-------- C:\Program Files\Windows NT
2006-08-10 16:44 -------- d-------- C:\Program Files\Outlook Express
2006-08-10 16:44 -------- d-------- C:\Program Files\NetMeeting
2006-08-03 18:45 147495 --a------ C:\WINDOWS\system32\rmocx.dll
2006-08-03 18:44 -------- d-------- C:\Documents and Settings\Owner\Application Data\Real
2006-07-14 14:51 108144 --a------ C:\WINDOWS\system32\GEARAspi.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"BackupNotify"="c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\backupnotify.exe"
"Yahoo! Pager"="\"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe\" -quiet"
"NVIEW"="rundll32.exe nview.dll,nViewLoadHook"
"Norton SystemWorks"="\"C:\\Program Files\\Norton SystemWorks\\cfgwiz.exe\" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"="nwiz.exe /installquiet /keeploaded /nodetect"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"ViewMgr"="C:\\Program Files\\Viewpoint\\Viewpoint Manager\\ViewMgr.exe"
"Symantec NetDriver Monitor"="C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000005
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="
https://webmail.atl....k/bg-whole.gif""SubscribedURL"="
https://webmail.atl....k/bg-whole.gif""FriendlyName"=""
"Flags"=dword:00000001
"Position"=hex:2c,00,00,00,b2,00,00,00,f1,00,00,00,61,02,00,00,64,01,00,00,e8,\
03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:01,00,00,00
"OriginalStateInfo"=hex:18,00,00,00,12,03,00,00,19,01,00,00,61,02,00,00,64,01,\
00,00,01,00,00,40
"RestoredStateInfo"=hex:dc,ff,6d,03,09,48,e9,77,88,32,e8,77,ff,ff,ff,ff,de,60,\
e7,77,68,e1,f0,02
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\1]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Notn"="\"C:\\WINDOWS\\STEM32~1\\winspool.exe\" -vt yazr"
"Bethgd"="C:\\Program Files\\a?sembly\\r?ndll.exe"
"kfkz"="C:\\PROGRA~1\\COMMON~1\\kfkz\\kfkzm.exe"
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Notn"="\"C:\\WINDOWS\\STEM32~1\\winspool.exe\" -vt yazr"
"Bethgd"="C:\\Program Files\\a?sembly\\r?ndll.exe"
"kfkz"="C:\\PROGRA~1\\COMMON~1\\kfkz\\kfkzm.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{54D9498B-CF93-414F-8984-8CE7FDE0D391}"="ewido shell guard"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mfcusl
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
backup-20060929-192829-632
O23 - Service: Task Manager Message Service (TSKMS) - Unknown owner - C:\WINDOWS\taskms.exe
backup-20060929-192829-842
O23 - Service: Microsoft Performance WMI Adapter AddOn (WMIPervAddOn) - Unknown owner - C:\WINDOWS\wmiapsv.exe (file missing)
backup-20060929-192811-800
O23 - Service: Task Manager Message Service (TSKMS) - Unknown owner - C:\WINDOWS\taskms.exe
backup-20060929-192811-718
O23 - Service: Microsoft Performance WMI Adapter AddOn (WMIPervAddOn) - Unknown owner - C:\WINDOWS\wmiapsv.exe (file missing)
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer - Owner.job
C:\WINDOWS\tasks\Norton SystemWorks One Button Checkup.job
C:\WINDOWS\tasks\Symantec Drmc.job
Completion time: Sat 09/30/2006 9:33:45.90
ComboFix.txt