Owner - 06-11-11 0:51:09.60 Service Pack 2
ComboFix 06.11.9 - Running from: "C:\Documents and Settings\Owner\Desktop"
((((((((((((((((((((((((((((((((((((((((((( E-Give / Ssk's Log )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\dxclib303562752.dll
C:\Program Files\DeluxeCommunications\DxcBho.dll
C:\Program Files\DeluxeCommunications\DxcCore.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\nwnmff_e54.exe
C:\Documents and Settings\Owner\setup9X.exe
C:\WINDOWS\system32\wnsintsv.exe
C:\Program Files\Windows NT\kyzesehu.html
C:\Program Files\Common Files\howy.html
C:\Program Files\outlook
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\QooBox\Purity\Documents and Settings\Owner\Application Data\STEM32~1
C:\QooBox\Purity\WINDOWS\CURITY~1
C:\QooBox\Purity\WINDOWS\CURITY~1\winspool.exe
C:\QooBox\Purity\WINDOWS\CURITY~1\??curity
C:\QooBox\Purity\WINDOWS\CURITY~1\??curity\ctxad-501.0000
C:\QooBox\Purity\WINDOWS\CURITY~1\??curity\ctxad-501.0001
C:\QooBox\Purity\WINDOWS\CURITY~1\??curity\ctxad-501.0002
C:\QooBox\Purity\WINDOWS\CURITY~1\??curity\ctxad-503.0000
C:\QooBox\Purity\WINDOWS\CURITY~1\??curity\ctxad-503.0001
C:\QooBox\Purity\WINDOWS\CURITY~1\??curity\ctxad-503.0002
C:\QooBox\Purity\WINDOWS\CURITY~1\??curity\ctxad-503.0003
C:\QooBox\Purity\WINDOWS\CURITY~1\??curity\ctxad-503.0004
C:\QooBox\Purity\WINDOWS\CURITY~1\??curity\ctxad-503.0005
((((((((((((((((((((((((((((((( Files Created from 2006-10-11 to 2006-11-11 ))))))))))))))))))))))))))))))))))
2006-11-10 14:27 44,544 --a------ C:\WINDOWS\system32\msxml4a.dll
2006-11-10 14:27 198,144 --a------ C:\WINDOWS\system32\_psisdecd.dll
2006-11-10 14:27 1,645,320 --a------ C:\WINDOWS\system32\gdiplus.dll
2006-11-10 12:47 204 --a------ C:\Documents and Settings\Owner\jdkfjdskfjkdsjf.bat
2006-11-10 12:46 32,768 --a------ C:\Documents and Settings\Owner\install.exe
2006-11-10 12:46 24,576 --a------ C:\Documents and Settings\Owner\dr.exe
2006-11-10 12:44 997,376 -r-hs---- C:\WINDOWS\zdlilbrA.exe
2006-11-10 12:44 69,632 --a------ C:\WINDOWS\system32\pgedlpnc.dll
2006-11-10 12:44 55,808 --a------ C:\WINDOWS\zdlilbr.exe
2006-11-10 12:44 204 --a------ C:\WINDOWS\system32\jdkfjdskfjkdsjf.bat
2006-11-10 12:44 20,480 --a------ C:\mc44a54.exe
2006-11-10 12:44 2,560 --a------ C:\ac3_0003.exe
2006-11-10 12:44 178,306 --a------ C:\WINDOWS\ac3_0008.exe
2006-11-10 12:44 1,284 --a------ C:\WINDOWS\system32\bere5ce3.sys
2006-11-10 12:43 8,464 --a------ C:\WINDOWS\system32\sporder.dll
2006-11-10 12:43 45,056 --a------ C:\WINDOWS\system32nrnqetwbz.exe
2006-11-10 12:43 45,056 --a------ C:\mpnaaq7.exe
2006-11-10 12:43 356,352 --a------ C:\162.exe
2006-11-10 12:43 323,072 --a------ C:\165.exe
2006-11-10 12:43 32,768 --a------ C:\WINDOWS\system32\setup9X.exe
2006-11-10 12:43 32,768 --a------ C:\WINDOWS\system32\install.exe
2006-11-10 12:43 28,672 --a------ C:\WINDOWS\system32hlvi6wkjc.exe
2006-11-10 12:43 28,672 --a------ C:\WINDOWS\system32\hlvi6wkjc.exe
2006-11-10 12:43 266,240 --a------ C:\yz02.exe
2006-11-10 12:43 24,576 --a------ C:\WINDOWS\system32\ysjaevwx.exe
2006-11-10 12:43 24,576 --a------ C:\WINDOWS\system32\dr.exe
2006-11-10 12:43 217,276 --a------ C:\WINDOWS\srvittac.exe
2006-11-10 12:43 20,480 --a------ C:\WINDOWS\stub_mm3.exe
2006-11-10 12:43 167,936 --a------ C:\WINDOWS\ms05769188-1401.exe
2006-11-10 12:43 0 --a------ C:\WINDOWS\system32ysjaevwx.exe
2006-11-05 18:49 10 --a------ C:\WINDOWS\smdat32m.sys
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-11-11 00:51 -------- d-------- C:\Program Files\Windows NT
2006-11-11 00:51 -------- d-------- C:\Program Files\Common Files
2006-11-11 00:50 2614 --a------ C:\Documents and Settings\Owner\Application Data\.googlewebacchosts
2006-11-11 00:50 -------- d-------- C:\Program Files\WinRAR
2006-11-11 00:49 -------- d-------- C:\Program Files\Messenger
2006-11-11 00:48 -------- d-------- C:\Program Files\Internet Explorer
2006-11-11 00:44 -------- d-------- C:\Program Files\AIM
2006-11-11 00:24 -------- d-------- C:\Program Files\Hijackthis
2006-11-10 23:43 -------- d-------- C:\Program Files\CONEXANT
2006-11-10 23:42 -------- d-------- C:\Program Files\ArtisanDVDPlayer
2006-11-10 14:27 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-11-10 14:27 -------- d-------- C:\Program Files\CyberLink
2006-11-10 14:03 -------- d-------- C:\Program Files\Windows Plus
2006-11-10 13:58 -------- d-------- C:\Program Files\Morpheus
2006-11-10 13:56 -------- d-------- C:\Program Files\Lavasoft
2006-11-10 13:56 -------- d-------- C:\Documents and Settings\Owner\Application Data\Lavasoft
2006-11-10 13:48 -------- d-------- C:\Program Files\DivX
2006-11-10 12:44 93664 --ahs---- C:\Program Files\Common Files\Y1324OU.exe
2006-11-10 12:33 -------- d-------- C:\Program Files\SimPE
2006-11-10 12:32 -------- d-------- C:\Program Files\InterActual
2006-11-09 13:37 -------- d-------- C:\Program Files\Google
2006-11-07 21:43 -------- d-------- C:\Program Files\NCH Swift Sound
2006-11-07 21:43 -------- d-------- C:\Documents and Settings\Owner\Application Data\RecordPad
2006-11-07 21:43 -------- d-------- C:\Documents and Settings\Owner\Application Data\NCH Swift Sound
2006-11-05 21:55 -------- d-------- C:\Program Files\Common Files\AOL
2006-11-05 18:55 -------- d-------- C:\Program Files\iMesh Applications
2006-11-05 18:53 -------- d-------- C:\Program Files\RXToolBar
2006-11-05 18:49 -------- d-------- C:\Program Files\Need2Find
2006-11-05 16:20 -------- d-------- C:\Program Files\DVD Shrink
2006-11-03 10:35 -------- d-------- C:\Program Files\AOL
2006-11-03 10:35 -------- d-------- C:\Program Files\AOD
2006-11-03 10:34 -------- d-------- C:\Program Files\Common Files\aolshare
2006-10-19 17:15 -------- d-------- C:\Program Files\EA GAMES
2006-10-12 12:11 -------- d---s---- C:\Documents and Settings\Owner\Application Data\Microsoft
2006-10-07 21:34 -------- d-------- C:\Documents and Settings\Owner\Application Data\DivX
2006-10-07 21:19 -------- d-------- C:\Program Files\WMV9_VCM
2006-10-02 14:04 806912 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2006-10-02 14:04 806912 --a------ C:\WINDOWS\system32\divx_xx07.dll
2006-10-02 14:04 790528 --a------ C:\WINDOWS\system32\divx_xx11.dll
2006-10-02 14:04 635486 --a------ C:\WINDOWS\system32\DivX.dll
2006-09-15 16:21 53248 --a------ C:\WINDOWS\uninst108.exe
2006-09-15 16:16 53248 --a------ C:\WINDOWS\uni_e6h.exe
2006-09-13 00:01 1084416 --a------ C:\WINDOWS\system32\msxml3.dll
2006-08-25 10:45 617472 --a------ C:\WINDOWS\system32\comctl32.dll
2006-08-21 07:21 16896 --a--c--- C:\WINDOWS\system32\fltlib.dll
2006-08-21 04:14 23040 --a--c--- C:\WINDOWS\system32\fltmc.exe
2006-08-16 06:58 100352 --a------ C:\WINDOWS\system32\6to4svc.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"Aim6"=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"LanguageShortcut"="\"C:\\Program Files\\CyberLink\\PowerDVD\\Language\\Language.exe\""
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"PCMService"="\"C:\\Program Files\\CyberLink\\PowerCinema\\PCMService.exe\""
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="C:\\Program Files\\Windows NT\\kyzesehu.html"
"SubscribedURL"=""
"FriendlyName"=""
"Flags"=dword:00002000
"Position"=hex:2c,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,00,00,e8,\
03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,00,14,00,00,00
"CurrentState"=dword:40000001
"OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,\
00,00,01,00,00,00
"RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
"Source"="C:\\Program Files\\Common Files\\howy.html"
"SubscribedURL"=""
"FriendlyName"=""
"Flags"=dword:00002000
"Position"=hex:2c,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,00,00,ea,\
03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,00,14,00,00,00
"CurrentState"=dword:40000001
"OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,\
00,00,01,00,00,00
"RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\2]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,e2,03,00,00,ec,\
03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=dword:40000004
"OriginalStateInfo"=hex:18,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,\
00,00,04,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Power2GoExpress"="NA"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"Power2GoExpress"="NA"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"InstallVisualStyle"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,\
63,65,73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,5c,52,6f,79,61,6c,65,2e,\
6d,73,73,74,79,6c,65,73,00
"InstallTheme"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,63,65,\
73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,2e,74,68,65,6d,65,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"CDRAutoRun"=dword:00000000
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"CDRAutoRun"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\ISP signup reminder 2.job
Completion time: 06-11-11 0:53:33.75
C:\ComboFix.txt ... 06-11-11 00:53