Hi,
and thanks for your assistance. Below are copies of the logs etc. you asked for.
Combofix:
Mikko Antila - 06-12-07 20:44:47.39 Service Pack 2
ComboFix 06.11.27W - Running from: "C:\Program Files\Mozilla Firefox"
((((((((((((((((((((((((((((((( Files Created from 2006-11-07 to 2006-12-07 ))))))))))))))))))))))))))))))))))
2006-12-06 20:02 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2006-12-06 19:58 <DIR> d-------- C:\Program Files\HTJ
2006-12-06 19:24 <DIR> d-------- C:\Program Files\RegCleaner
2006-12-06 19:12 <DIR> dr-h----- C:\Documents and Settings\Mikko Antila\Recent
2006-12-06 19:09 <DIR> d-------- C:\Program Files\CCleaner
2006-12-06 15:47 <DIR> d-------- C:\NoLopBackups
2006-12-06 13:24 <DIR> d-------- C:\Program Files\Lavasoft
2006-12-06 13:24 <DIR> d-------- C:\Documents and Settings\Mikko Antila\Application Data\Lavasoft
2006-12-05 20:15 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2006-12-05 20:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2006-12-04 00:36 <DIR> d-------- C:\Program Files\PokerRoom.com
2006-12-03 15:27 <DIR> d-------- C:\Documents and Settings\Mikko Antila\.dwa_store
2006-11-29 17:15 127,208 --a------ C:\WINDOWS\system32\mucltui.dll
2006-11-28 19:02 <DIR> d-------- C:\Program Files\Norton Internet Security
2006-11-28 19:01 91,904 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2006-11-28 19:01 124,016 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2006-11-28 19:00 <DIR> d-------- C:\Program Files\Symantec
2006-11-28 19:00 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2006-11-27 21:01 737,280 --a------ C:\WINDOWS\iun6002.exe
2006-11-27 21:01 <DIR> d-------- C:\Program Files\Codec Pack - All In 1
2006-11-27 20:35 765,952 --a------ C:\WINDOWS\system32\xvidcore.dll
2006-11-27 20:35 180,224 --a------ C:\WINDOWS\system32\xvidvfw.dll
2006-11-27 20:35 <DIR> d-------- C:\Program Files\Xvid
2006-11-26 17:50 <DIR> d-------- C:\Documents and Settings\Mikko Antila\Application Data\NetPumper
2006-11-26 17:50 <DIR> d-------- C:\Documents and Settings\Mikko Antila\Application Data\Idol Bits Corn
2006-11-26 17:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\typeeqonelive
2006-11-24 17:09 <DIR> d-------- C:\Documents and Settings\Mikko Antila\Application Data\Azureus
2006-11-24 16:53 <DIR> d-------- C:\Documents and Settings\Mikko Antila\Application Data\BitTorrent
2006-11-18 02:02 <DIR> d-------- C:\Program Files\MSXML 4.0
2006-11-18 02:01 <DIR> d-------- C:\70a091c8baadc5deab
2006-11-10 16:22 <DIR> d-------- C:\Program Files\Symantec Technical Support
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-12-07 20:44 -------- d-------- C:\Program Files\Mozilla Firefox
2006-12-07 20:34 -------- d-------- C:\Documents and Settings\Mikko Antila\Application Data\Skype
2006-12-06 20:26 -------- d-------- C:\Program Files\WinZip
2006-12-06 20:22 -------- d-------- C:\Program Files\Messenger
2006-12-06 20:21 -------- d-------- C:\Program Files\iTunes
2006-12-06 20:21 -------- d-------- C:\Program Files\Internet Explorer
2006-12-06 20:19 -------- d-------- C:\Program Files\Common Files\LightScribe
2006-12-04 10:06 -------- d-------- C:\Program Files\HoldemPoker
2006-11-28 20:19 -------- d-------- C:\Program Files\backups
2006-11-28 19:02 -------- d-------- C:\Program Files\Common Files
2006-11-10 16:10 -------- d-------- C:\Program Files\Java
2006-11-04 14:14 1245696 --a------ C:\WINDOWS\system32\msxml4.dll
2006-10-31 12:25 5198 --a------ C:\Program Files\ZeQuinT.nfo
2006-10-30 23:23 -------- d---s---- C:\Documents and Settings\Mikko Antila\Application Data\Microsoft
2006-10-30 23:07 -------- d-------- C:\Program Files\MSN Messenger
2006-10-30 23:07 -------- d-------- C:\Program Files\Common Files\Microsoft Shared
2006-10-30 22:55 -------- d-------- C:\Program Files\Microsoft Works
2006-10-30 22:51 -------- d-------- C:\Program Files\QuickTime
2006-10-30 22:50 -------- d-------- C:\Program Files\Easy Internet signup
2006-10-30 21:53 -------- d-------- C:\Program Files\iolo
2006-10-30 15:37 -------- d-------- C:\Documents and Settings\Mikko Antila\Application Data\Mozilla
2006-10-25 10:53 -------- d-------- C:\Program Files\WinTrade
2006-10-25 10:50 -------- d-------- C:\Program Files\Common Files\Wise Installation Wizard
2006-10-25 09:41 -------- d-------- C:\Documents and Settings\Mikko Antila\Application Data\Help
2006-10-25 09:36 0 -rahs---- C:\MSDOS.SYS
2006-10-25 09:36 0 -rahs---- C:\IO.SYS
2006-10-25 09:35 -------- d-------- C:\Program Files\sanakirja
2006-10-25 09:34 -------- d-------- C:\Program Files\WinRAR
2006-10-23 20:59 -------- d-------- C:\Program Files\Acro Software
2006-10-23 20:58 -------- d-------- C:\Program Files\GPLGS
2006-10-13 14:35 142336 --a------ C:\WINDOWS\system32\nwprovau.dll
2006-09-13 07:01 1084416 --a------ C:\WINDOWS\system32\msxml3.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"Skype"="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"
"Amok okay"="C:\\DOCUME~1\\MIKKOA~1\\APPLIC~1\\IDOLBI~1\\Poll stupid.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ATIPTA"="\"C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_09\\bin\\jusched.exe\""
"HP Software Update"="C:\\Program Files\\Hp\\HP Software Update\\HPWuSchd2.exe"
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"hpWirelessAssistant"="C:\\Program Files\\hpq\\HP Wireless Assistant\\HP Wireless Assistant.exe"
"iTunesHelper"="C:\\Program Files\\iTunes\\iTunesHelper.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"LSBWatcher"="c:\\hp\\drivers\\hplsbwatcher\\lsburnwatcher.exe"
"eabconfg.cpl"="C:\\Program Files\\HPQ\\Quick Launch Buttons\\EabServr.exe /Start"
"Cpqset"="C:\\Program Files\\HPQ\\Default Settings\\cpqset.exe"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"oneliveroamlies"="C:\\Documents and Settings\\All Users\\Application Data\\typeeqonelive\\datefirst.exe"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,fe,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer - Mikko Antila.job
Completion time: 06-12-07 20:45:27.01
C:\ComboFix.txt ... 06-12-07 20:45
Fresh HTJ log:
Logfile of HijackThis v1.99.1
Scan saved at 20:56:48, on 07/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HTJ\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.hp.comR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://www.hp.com/O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [oneliveroamlies] C:\Documents and Settings\All Users\Application Data\typeeqonelive\datefirst.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Amok okay] C:\DOCUME~1\MIKKOA~1\APPLIC~1\IDOLBI~1\Poll stupid.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) -
http://download.ewid...oOnlineScan.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.micros...b?1164739406046O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoft...free/asinst.cabO18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
..the findlop log:
Mikko Antila - 06-12-07 20:44:47.39 Service Pack 2
ComboFix 06.11.27W - Running from: "C:\Program Files\Mozilla Firefox"
((((((((((((((((((((((((((((((( Files Created from 2006-11-07 to 2006-12-07 ))))))))))))))))))))))))))))))))))
2006-12-06 20:02 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2006-12-06 19:58 <DIR> d-------- C:\Program Files\HTJ
2006-12-06 19:24 <DIR> d-------- C:\Program Files\RegCleaner
2006-12-06 19:12 <DIR> dr-h----- C:\Documents and Settings\Mikko Antila\Recent
2006-12-06 19:09 <DIR> d-------- C:\Program Files\CCleaner
2006-12-06 15:47 <DIR> d-------- C:\NoLopBackups
2006-12-06 13:24 <DIR> d-------- C:\Program Files\Lavasoft
2006-12-06 13:24 <DIR> d-------- C:\Documents and Settings\Mikko Antila\Application Data\Lavasoft
2006-12-05 20:15 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2006-12-05 20:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2006-12-04 00:36 <DIR> d-------- C:\Program Files\PokerRoom.com
2006-12-03 15:27 <DIR> d-------- C:\Documents and Settings\Mikko Antila\.dwa_store
2006-11-29 17:15 127,208 --a------ C:\WINDOWS\system32\mucltui.dll
2006-11-28 19:02 <DIR> d-------- C:\Program Files\Norton Internet Security
2006-11-28 19:01 91,904 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2006-11-28 19:01 124,016 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2006-11-28 19:00 <DIR> d-------- C:\Program Files\Symantec
2006-11-28 19:00 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2006-11-27 21:01 737,280 --a------ C:\WINDOWS\iun6002.exe
2006-11-27 21:01 <DIR> d-------- C:\Program Files\Codec Pack - All In 1
2006-11-27 20:35 765,952 --a------ C:\WINDOWS\system32\xvidcore.dll
2006-11-27 20:35 180,224 --a------ C:\WINDOWS\system32\xvidvfw.dll
2006-11-27 20:35 <DIR> d-------- C:\Program Files\Xvid
2006-11-26 17:50 <DIR> d-------- C:\Documents and Settings\Mikko Antila\Application Data\NetPumper
2006-11-26 17:50 <DIR> d-------- C:\Documents and Settings\Mikko Antila\Application Data\Idol Bits Corn
2006-11-26 17:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\typeeqonelive
2006-11-24 17:09 <DIR> d-------- C:\Documents and Settings\Mikko Antila\Application Data\Azureus
2006-11-24 16:53 <DIR> d-------- C:\Documents and Settings\Mikko Antila\Application Data\BitTorrent
2006-11-18 02:02 <DIR> d-------- C:\Program Files\MSXML 4.0
2006-11-18 02:01 <DIR> d-------- C:\70a091c8baadc5deab
2006-11-10 16:22 <DIR> d-------- C:\Program Files\Symantec Technical Support
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-12-07 20:44 -------- d-------- C:\Program Files\Mozilla Firefox
2006-12-07 20:34 -------- d-------- C:\Documents and Settings\Mikko Antila\Application Data\Skype
2006-12-06 20:26 -------- d-------- C:\Program Files\WinZip
2006-12-06 20:22 -------- d-------- C:\Program Files\Messenger
2006-12-06 20:21 -------- d-------- C:\Program Files\iTunes
2006-12-06 20:21 -------- d-------- C:\Program Files\Internet Explorer
2006-12-06 20:19 -------- d-------- C:\Program Files\Common Files\LightScribe
2006-12-04 10:06 -------- d-------- C:\Program Files\HoldemPoker
2006-11-28 20:19 -------- d-------- C:\Program Files\backups
2006-11-28 19:02 -------- d-------- C:\Program Files\Common Files
2006-11-10 16:10 -------- d-------- C:\Program Files\Java
2006-11-04 14:14 1245696 --a------ C:\WINDOWS\system32\msxml4.dll
2006-10-31 12:25 5198 --a------ C:\Program Files\ZeQuinT.nfo
2006-10-30 23:23 -------- d---s---- C:\Documents and Settings\Mikko Antila\Application Data\Microsoft
2006-10-30 23:07 -------- d-------- C:\Program Files\MSN Messenger
2006-10-30 23:07 -------- d-------- C:\Program Files\Common Files\Microsoft Shared
2006-10-30 22:55 -------- d-------- C:\Program Files\Microsoft Works
2006-10-30 22:51 -------- d-------- C:\Program Files\QuickTime
2006-10-30 22:50 -------- d-------- C:\Program Files\Easy Internet signup
2006-10-30 21:53 -------- d-------- C:\Program Files\iolo
2006-10-30 15:37 -------- d-------- C:\Documents and Settings\Mikko Antila\Application Data\Mozilla
2006-10-25 10:53 -------- d-------- C:\Program Files\WinTrade
2006-10-25 10:50 -------- d-------- C:\Program Files\Common Files\Wise Installation Wizard
2006-10-25 09:41 -------- d-------- C:\Documents and Settings\Mikko Antila\Application Data\Help
2006-10-25 09:36 0 -rahs---- C:\MSDOS.SYS
2006-10-25 09:36 0 -rahs---- C:\IO.SYS
2006-10-25 09:35 -------- d-------- C:\Program Files\sanakirja
2006-10-25 09:34 -------- d-------- C:\Program Files\WinRAR
2006-10-23 20:59 -------- d-------- C:\Program Files\Acro Software
2006-10-23 20:58 -------- d-------- C:\Program Files\GPLGS
2006-10-13 14:35 142336 --a------ C:\WINDOWS\system32\nwprovau.dll
2006-09-13 07:01 1084416 --a------ C:\WINDOWS\system32\msxml3.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"Skype"="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"
"Amok okay"="C:\\DOCUME~1\\MIKKOA~1\\APPLIC~1\\IDOLBI~1\\Poll stupid.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ATIPTA"="\"C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_09\\bin\\jusched.exe\""
"HP Software Update"="C:\\Program Files\\Hp\\HP Software Update\\HPWuSchd2.exe"
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"hpWirelessAssistant"="C:\\Program Files\\hpq\\HP Wireless Assistant\\HP Wireless Assistant.exe"
"iTunesHelper"="C:\\Program Files\\iTunes\\iTunesHelper.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"LSBWatcher"="c:\\hp\\drivers\\hplsbwatcher\\lsburnwatcher.exe"
"eabconfg.cpl"="C:\\Program Files\\HPQ\\Quick Launch Buttons\\EabServr.exe /Start"
"Cpqset"="C:\\Program Files\\HPQ\\Default Settings\\cpqset.exe"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"oneliveroamlies"="C:\\Documents and Settings\\All Users\\Application Data\\typeeqonelive\\datefirst.exe"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,fe,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer - Mikko Antila.job
Completion time: 06-12-07 20:45:27.01
C:\ComboFix.txt ... 06-12-07 20:45
...and finally HTJ uninstall list:
Ad-Aware SE Personal
Adobe Reader 7.0.8
Adobe Shockwave Player
Athlon 64 Processor Driver
ATI Control Panel
ATI Display Driver
CC_ccProxyExt
ccCommon
CCleaner (remove only)
ccPxyCore
Codec Pack - All In 1 6.0.3.0
Conexant AC-Link Audio
CutePDF Writer 2.6
High Definition Audio Driver Package - KB835221
HijackThis 1.99.1
Hotfix for Windows XP (KB896256)
HP Help and Support
HP Software Update
HP User Guides 0008
HP Wireless Assistant 1.01 C1
InterVideo WinDVD
iolo technologies' System Mechanic
iTunes
J2SE Runtime Environment 5.0 Update 5
J2SE Runtime Environment 5.0 Update 9
LiveReg (Symantec Corporation)
LiveUpdate 3.0 (Symantec Corporation)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB886903)
Microsoft Office XP Professional ja FrontPage
Microsoft Works
Mozilla Firefox (2.0)
MSN
MSRedist
MSXML 4.0 SP2 (KB927978)
Norton AntiSpam
Norton AntiVirus 2005
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security 2005 (Symantec Corporation)
Norton Security Center
Norton WMI Update
Norton WMI Update
Panda ActiveScan
PokerRoom.com (remove only)
Quick Launch Buttons 5.20 D2
QuickTime
RealPlayer
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893066)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB925486)
Skype 2.5
Soft Data Fax Modem with SmartCP
Sonic Audio Module
Sonic Copy Module
Sonic Data Module
Sonic Express Labeler
Sonic MyDVD Plus
Sonic Update Manager
SPBBC
Spybot - Search & Destroy 1.4
Symantec Script Blocking Installer
Symantec Technical Support Web Controls
SymNet
Synaptics Pointing Device Driver
Texas Instruments PCIxx21/x515 drivers.
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Winamp (remove only)
Windows Installer 3.1 (KB893803)
Windows Live Messenger
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB883667
Windows XP Hotfix - KB884575
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885464
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885855
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888239
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB888402
Windows XP Hotfix - KB889673
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB892559
WinRAR archiver
WinTrade
WinZip
Xvid 1.1.2 final uninstall
Thanks again!
br,
Mikko