Combofix log:
Michael - 06-12-31 13:22:40.10 Service Pack 2
ComboFix 06.11.27 - Running from: "C:\Documents and Settings\Michael\Desktop"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\QooBox\Purity\Documents and Settings\Michael\Application Data\FNTS~1
C:\QooBox\Purity\Documents and Settings\Michael\Application Data\SSEMBL~1
C:\QooBox\Purity\Documents and Settings\Michael\Application Data\STEM~1
C:\QooBox\Purity\Documents and Settings\Michael\My Documents\SEMBLY~1
C:\QooBox\Purity\Documents and Settings\Michael\My Documents\STEM~1
C:\QooBox\Purity\Documents and Settings\Michael\My Documents\WNSXS~1
C:\QooBox\Purity\Documents and Settings\Michael\My Documents\STEM~1\??stem
C:\QooBox\Purity\Program Files\SCURIT~1
C:\QooBox\Purity\Program Files\YMANTE~1
C:\QooBox\Purity\Program Files\Common Files\CROSOF~1
C:\QooBox\Purity\Program Files\Common Files\MANTEC~1
C:\QooBox\Purity\Program Files\Common Files\RACLE~1
C:\QooBox\Purity\Program Files\Common Files\SMBOLS~1
C:\QooBox\Purity\Program Files\YMANTE~1\s?oolsv.exe
C:\QooBox\Purity\WINDOWS\SEMBLY~1
C:\QooBox\Purity\WINDOWS\system32\MANTEC~1
C:\QooBox\Purity\WINDOWS\system32\WNSXS~1
((((((((((((((((((((((((((((((( Files Created from 2006-11-31 to 2006-12-31 ))))))))))))))))))))))))))))))))))
2006-12-31 07:34 816,672 --a------ C:\WINDOWS\system32\drivers\avg7core.sys
2006-12-31 07:34 4,960 --a------ C:\WINDOWS\system32\drivers\avgtdi.sys
2006-12-31 07:34 4,224 --a------ C:\WINDOWS\system32\drivers\avg7rsw.sys
2006-12-31 07:34 3,968 --a------ C:\WINDOWS\system32\drivers\avgclean.sys
2006-12-31 07:34 28,416 --a------ C:\WINDOWS\system32\drivers\avg7rsxp.sys
2006-12-31 07:34 18,240 --a------ C:\WINDOWS\system32\drivers\avgmfx86.sys
2006-12-31 07:34 <DIR> d-------- C:\Program Files\Grisoft
2006-12-31 07:34 <DIR> d-------- C:\Documents and Settings\Michael\Application Data\AVG7
2006-12-31 07:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2006-12-31 07:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2006-12-31 07:14 <DIR> d-------- C:\!KillBox
2006-12-30 15:58 <DIR> d-------- C:\Program Files\HJT
2006-12-29 09:16 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2006-12-28 18:29 684,032 --a------ C:\WINDOWS\system32\libeay32.dll
2006-12-28 18:29 155,648 --a------ C:\WINDOWS\system32\ssleay32.dll
2006-12-28 18:29 15,872 --a------ C:\WINDOWS\system32\drivers\sshrmd.sys
2006-12-28 18:29 15,360 --a------ C:\WINDOWS\system32\drivers\sskbfd.sys
2006-12-28 18:29 14,848 --a------ C:\WINDOWS\system32\drivers\SSFS0509.sys
2006-12-28 18:29 122,368 --a------ C:\WINDOWS\system32\drivers\ssidrv.sys
2006-12-28 18:29 <DIR> d-------- C:\Program Files\Webroot
2006-12-28 18:23 <DIR> d-------- C:\Documents and Settings\Michael\Application Data\Webroot
2006-12-28 18:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Webroot
2006-12-28 15:05 <DIR> d-------- C:\Program Files\NoAdware5.0
2006-12-28 13:57 <DIR> d-------- C:\Program Files\RegistrySmart
2006-12-27 15:55 <DIR> d-------- C:\Program Files\Outerinfo
2006-12-26 15:34 <DIR> d-------- C:\Program Files\SpywareBot
2006-12-24 08:30 <DIR> dr-h----- C:\Documents and Settings\Michael\Recent
2006-12-01 06:51 <DIR> d-------- C:\receipes
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-12-31 09:04 -------- d-------- C:\Program Files\Dl_cats
2006-12-31 09:02 -------- d-------- C:\Documents and Settings\Michael\Application Data\AdobeUM
2006-12-31 06:46 -------- d-------- C:\Program Files\MyWebSearch
2006-12-30 17:14 -------- d-------- C:\Program Files\Common Files
2006-12-30 07:58 6216 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
2006-12-30 07:58 104 -r-hs---- C:\WINDOWS\system32\FEF2815F70.sys
2006-12-28 14:06 -------- d-------- C:\Program Files\ewido anti-malware
2006-12-27 15:55 2 --a------ C:\WINDOWS\system32\wintsvcc.exe
2006-12-26 15:52 -------- d-------- C:\Program Files\Spybot - Search & Destroy
2006-12-26 15:52 -------- d-------- C:\Documents and Settings\Michael\Application Data\Spybot - Search & Destroy
2006-12-26 14:48 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-12-26 14:48 -------- d-------- C:\Program Files\Common Files\Sonic Shared
2006-12-13 16:58 -------- d-------- C:\Program Files\Outlook Express
2006-12-13 16:58 -------- d-------- C:\Program Files\Common Files\System
2006-12-07 00:29 2374472 --a------ C:\WINDOWS\system32\wmvcore.dll
2006-12-02 07:13 -------- d-------- C:\Program Files\HP DeskJet 970C Series
2006-12-02 06:26 -------- d---s---- C:\Documents and Settings\Michael\Application Data\Microsoft
2006-12-02 06:26 -------- d-------- C:\Program Files\Jasc Software Inc
2006-12-02 06:26 -------- d-------- C:\Documents and Settings\Michael\Application Data\Jasc Software Inc
2006-11-23 06:26 -------- d-------- C:\Program Files\Internet Explorer
2006-11-20 03:42 33280 --a------ C:\WINDOWS\system32\snmp.exe
2006-11-16 09:00 -------- d-------- C:\Program Files\Dell Photo AIO Printer 924
2006-11-08 00:06 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-11-07 21:03 6049280 --------- C:\WINDOWS\system32\ieframe.dll
2006-11-07 21:03 50688 --------- C:\WINDOWS\system32\msfeedsbs.dll
2006-11-07 21:03 458752 --------- C:\WINDOWS\system32\msfeeds.dll
2006-11-07 21:03 413696 --a------ C:\WINDOWS\system32\vbscript.dll
2006-11-07 21:03 231424 --a------ C:\WINDOWS\system32\webcheck.dll
2006-11-07 21:03 180736 --------- C:\WINDOWS\system32\ieui.dll
2006-11-07 21:03 156160 --a------ C:\WINDOWS\system32\msls31.dll
2006-11-07 03:27 382976 --a------ C:\WINDOWS\system32\iedkcs32.dll
2006-11-07 03:27 229376 --a------ C:\WINDOWS\system32\ieaksie.dll
2006-11-07 03:26 71680 --a------ C:\WINDOWS\system32\admparse.dll
2006-11-07 03:26 55296 --a------ C:\WINDOWS\system32\iesetup.dll
2006-11-07 03:26 54784 --a------ C:\WINDOWS\system32\ie4uinit.exe
2006-11-07 03:26 43008 --a------ C:\WINDOWS\system32\iernonce.dll
2006-11-07 03:26 152064 --a------ C:\WINDOWS\system32\ieakeng.dll
2006-11-07 03:26 13312 --a------ C:\WINDOWS\system32\ieudinit.exe
2006-11-07 03:26 123904 --a------ C:\WINDOWS\system32\advpack.dll
2006-11-07 03:25 161792 --a------ C:\WINDOWS\system32\ieakui.dll
2006-11-04 14:14 1245696 --a------ C:\WINDOWS\system32\msxml4.dll
2006-10-19 08:56 713216 --a------ C:\WINDOWS\system32\sxs.dll
2006-10-17 12:06 78336 --a------ C:\WINDOWS\system32\ieencode.dll
2006-10-17 12:05 40960 --a------ C:\WINDOWS\system32\licmgr10.dll
2006-10-17 12:05 206336 --------- C:\WINDOWS\system32\WinFXDocObj.exe
2006-10-17 12:05 105984 --a------ C:\WINDOWS\system32\url.dll
2006-10-17 12:04 101376 --a------ C:\WINDOWS\system32\occache.dll
2006-10-17 12:03 17408 --a------ C:\WINDOWS\system32\corpol.dll
2006-10-17 11:58 61952 --------- C:\WINDOWS\system32\icardie.dll
2006-10-17 11:58 12288 --------- C:\WINDOWS\system32\msfeedssync.exe
2006-10-17 11:57 36352 --a------ C:\WINDOWS\system32\imgutil.dll
2006-10-17 11:57 266752 --------- C:\WINDOWS\system32\iertutil.dll
2006-10-17 11:56 45568 --a------ C:\WINDOWS\system32\mshta.exe
2006-10-17 11:28 48128 --a------ C:\WINDOWS\system32\mshtmler.dll
2006-10-17 11:27 380928 --------- C:\WINDOWS\system32\ieapfltr.dll
2006-10-13 07:35 65536 --a------ C:\WINDOWS\system32\nwwks.dll
2006-10-13 07:35 64000 --a------ C:\WINDOWS\system32\nwapi32.dll
2006-10-13 07:35 142336 --a------ C:\WINDOWS\system32\nwprovau.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"DellSupport"="\"C:\\Program Files\\Dell Support\\DSAgnt.exe\" /startup"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"swg"="\"C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.908.5008\\GoogleToolbarNotifier.exe\""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SigmatelSysTrayApp"="stsystra.exe"
"IAAnotif"="\"C:\\Program Files\\Intel\\Intel Matrix Storage Manager\\iaanotif.exe\""
"ATIPTA"="\"C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe\""
"DMXLauncher"="\"C:\\Program Files\\Dell\\Media Experience\\DMXLauncher.exe\""
"RealTray"="\"C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe\" SYSTEMBOOTHIDEPLAYER"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"MMTray"="C:\\PROGRA~1\\MUSICM~1\\MUSICM~3\\mm_tray.exe"
"ISUSPM Startup"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\isuspm.exe\" -startup"
"ISUSScheduler"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe\" -start"
"DLA"="C:\\WINDOWS\\System32\\DLA\\DLACTRLW.EXE"
"MimBoot"="C:\\PROGRA~1\\MUSICM~1\\MUSICM~3\\mimboot.exe"
"AudioHQ"="\"C:\\Program Files\\Creative\\SBLive\\AudioHQ\\AHQTB.EXE\""
"CTSysVol"="\"C:\\PROGRAM FILES\\CREATIVE\\SURROUNDMIXER\\CTSYSVOL.EXE\""
"masqform.exe"="\"C:\\Program Files\\PureEdge\\Viewer 6.0\\masqform.exe\" -UpdateCurrentUser"
"HPDJ Taskbar Utility"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\hpztsb04.exe"
"REGSHAVE"="\"C:\\Program Files\\REGSHAVE\\REGSHAVE.EXE\" /AUTORUN"
"Disc Detector"="\"C:\\Program Files\\Creative\\ShareDLL\\CtNotify.exe\""
"DLCCCATS"="rundll32 C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\DLCCtime.dll,_RunDLLEntry@16"
"dlccmon.exe"="\"C:\\Program Files\\Dell Photo AIO Printer 924\\dlccmon.exe\""
"SpySweeper"="\"C:\\Program Files\\Webroot\\Spy Sweeper\\SpySweeperUI.exe\" /startintray"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe\""
"AVG7_CC"="\"C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe\" /STARTUP"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000005
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e1,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoCDBurning"=dword:00000000
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"HP Software Update"="\"C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe\""
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\WebrootSpySweeperService
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\wrSpySweeperTrialSweep.job
Completion time: 06-12-31 13:23:44.92
C:\ComboFix.txt ... 06-12-31 13:23
C:\ComboFix2.txt ... 06-12-30 17:15