I hope I did this right
odirish - 07-01-07 13:44:50.60 Service Pack 1
ComboFix 06.11.27 - Running from: "C:\Documents and Settings\odirish\Desktop"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\scmt16.exe
C:\Program Files\Common Files\Yazzle1122OinAdmin.exe
C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
C:\Program Files\Inetget2
C:\Program Files\Ipwins
C:\Program Files\Common Files\{AC7688FF-018F-1033-1104-990203260001}
C:\Program Files\Common Files\{3C7688FF-018E-1033-1104-990203260001}
C:\Program Files\Common Files\{AC7688FF-018E-1033-1104-990203260001}
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\QooBox\Purity\Documents and Settings\odirish\Application Data\SMANTE~1
C:\QooBox\Purity\Documents and Settings\odirish\Application Data\SMANTE~1\?hkdsk.exe
C:\QooBox\Purity\Program Files\Common Files\SMANTE~1
C:\QooBox\Purity\Program Files\Common Files\SMANTE~1\chkntfs.exe
C:\QooBox\Purity\Program Files\Common Files\SMANTE~1\S?mantec
((((((((((((((((((((((((((((((( Files Created from 2006-12-07 to 2007-01-07 ))))))))))))))))))))))))))))))))))
2007-01-06 20:41 <DIR> d-------- C:\Program Files\Hijackthis
2007-01-06 20:17 <DIR> d-------- C:\Program Files\Common Files\DriveCleaner Free
2007-01-06 20:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\InstallShield
2007-01-06 20:16 <DIR> d-------- C:\Program Files\Common Files\Corel
2007-01-06 20:16 <DIR> d-------- C:\My Downloads
2007-01-05 11:59 <DIR> d-------- C:\23.73.105
2007-01-04 17:27 <DIR> d-------- C:\Program Files\Ipwindows
2007-01-04 16:29 <DIR> d-------- C:\Program Files\DriveCleaner Free
2007-01-01 16:39 57,856 --a------ C:\WINDOWS\system32\kqit.dll
2007-01-01 16:39 2 --a------ C:\WINDOWS\system32\wapicc.exe
2007-01-01 16:39 <DIR> d-------- C:\Program Files\Outerinfo
2007-01-01 08:24 <DIR> d-------- C:\WINDOWS\iqmw
2007-01-01 08:24 <DIR> d-------- C:\Program Files\Common Files\iqmw
2006-12-31 03:28 36,864 --a------ C:\WINDOWS\system32\svchosts.exe
2006-12-31 03:27 2,116 --a------ C:\15242624.exe
2006-12-28 15:04 2,124 --a------ C:\WINDOWS\uwkygool.exe
2006-12-28 15:04 <DIR> d-------- C:\WINDOWS\pss
2006-12-28 12:50 <DIR> d-------- C:\Documents and Settings\odirish\Application Data\Corel Photo Album
2006-12-28 12:45 88 -r-hs---- C:\WINDOWS\system32\A0ADE11170.sys
2006-12-28 12:45 3,350 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
2006-12-28 12:36 <DIR> d-------- C:\Program Files\Corel
2006-12-14 17:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\CA
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-01-07 14:02 -------- d-------- C:\Program Files\Common Files
2007-01-07 01:14 -------- d-------- C:\Program Files\SwiftSwitch
2007-01-06 20:16 -------- d-------- C:\Program Files\Common Files\InstallShield
2006-12-29 21:22 -------- d-------- C:\Program Files\Outlook Express
2006-12-02 16:57 -------- d-------- C:\Program Files\Viewpoint
2006-12-02 16:34 -------- d-------- C:\Program Files\Common Files\Viewpoint
2006-11-29 06:29 20992 --a------ C:\WINDOWS\1.exe
2006-11-26 22:31 285 --a------ C:\WINDOWS\counter.exe
2006-11-26 02:11 -------- d-------- C:\Program Files\Java
2006-11-24 20:10 -------- d-------- C:\Program Files\MSN Games
2006-11-23 11:26 -------- d-------- C:\Program Files\Google
2006-11-14 13:59 -------- d-------- C:\Program Files\Common Files\Real
2006-11-09 22:59 -------- d-------- C:\Program Files\Common Files\Companion Wizard
2006-11-09 22:54 0 --a------ C:\Program Files\Common Files\err.log
2006-11-09 07:39 -------- d-------- C:\Program Files\SupportSoft
2006-10-29 23:34 774144 --a------ C:\Program Files\RngInterstitial.dll
2006-10-27 18:42 9817 --a------ C:\WINDOWS\system32\z1860.exe
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"Ptre"="\"C:\\PROGRA~1\\COMMON~1\\SMANTE~1\\chkntfs.exe\" -vt yazb"
"iqmw"="C:\\Program Files\\Common Files\\iqmw\\iqmwm.exe"
"Quqlqmez"="C:\\Documents and Settings\\odirish\\Application Data\\S?mantec\\?hkdsk.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"HP Software Update"="C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe"
"CaAvTray"="\"C:\\Program Files\\Yahoo!\\Antivirus\\CAVTray.exe\""
"CAVRID"="\"C:\\Program Files\\Yahoo!\\Antivirus\\CAVRID.exe\""
"YOP"="C:\\PROGRA~1\\Yahoo!\\YOP\\yop.exe /autostart"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"DC6_check"="\"C:\\Program Files\\Common Files\\dc6_startupmon.exe\""
"ERS_check"="\"C:\\Program Files\\Common Files\\ers_startupmon.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_08\\bin\\jusched.exe\""
@=""
"Corel Photo Downloader"="C:\\Program Files\\Corel\\Corel Photo Album 6\\MediaDetect.exe"
"{AC7688FF-018E-1033-1104-990203260001}"="\"C:\\Program Files\\Common Files\\{AC7688FF-018E-1033-1104-990203260001}\\Update.exe\" te-110-12-0000213"
"SDR6_Check"="\"C:\\Program Files\\Common Files\\DriveCleaner Free\\udcsdr.exe\""
"PAS_Check"="\"C:\\Program Files\\Common Files\\DriveCleaner Free\\udcpas.exe\""
"{AC7688FF-018F-1033-1104-990203260001}"="\"C:\\Program Files\\Common Files\\{AC7688FF-018F-1033-1104-990203260001}\\Update.exe\" te-110-12-0000213"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="
http://www.psecu.com...tements500.jpg""SubscribedURL"="
http://www.psecu.com...tements500.jpg""FriendlyName"=""
"Flags"=dword:00000001
"Position"=hex:2c,00,00,00,6a,02,00,00,e1,00,00,00,d1,01,00,00,d2,00,00,00,e8,\
03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:01,00,00,00
"OriginalStateInfo"=hex:18,00,00,00,6a,02,00,00,e1,00,00,00,d1,01,00,00,d2,00,\
00,00,01,00,00,40
"RestoredStateInfo"=hex:dc,ff,73,05,09,48,e9,77,88,32,e8,77,ff,ff,ff,ff,de,60,\
e7,77,40,75,24,00
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,9c,00,00,00,00,00,00,00,64,03,00,00,de,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
Completion time: 07-01-07 14:05:55.93
C:\ComboFix.txt ... 07-01-07 14:05
Logfile of HijackThis v1.99.1
Scan saved at 2:20:29 PM, on 1/7/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\WINDOWS\System32\svchosts.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Yahoo!\Antivirus\CAVTray.exe
C:\Program Files\Yahoo!\Antivirus\CAVRID.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
C:\Program Files\Common Files\DriveCleaner Free\udcsdr.exe
C:\Program Files\Common Files\DriveCleaner Free\udcpas.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\Program Files\hjt.exe\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://verizon.yahoo.comR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://verizon.yahoo.comR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
R3 - URLSearchHook: (no name) - {721A9A4B-7AFE-565E-8973-7F129342E195} - C:\WINDOWS\System32\kqit.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe,C:\WINDOWS\System32\ntos.exe,
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: - {5cf66fa8-0340-4c89-918c-1ccae81a76e4} - C:\WINDOWS\System32\luk.dll
O2 - BHO: (no name) - {721A9A4B-7AFE-565E-8973-7F129342E195} - C:\WINDOWS\System32\kqit.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: Bar888 - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRA~1\COMMON~1\{3C768~1\Bar888.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Bar888 - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRA~1\COMMON~1\{3C768~1\Bar888.dll (file missing)
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DC6_check] "C:\Program Files\Common Files\dc6_startupmon.exe"
O4 - HKLM\..\Run: [ERS_check] "C:\Program Files\Common Files\ers_startupmon.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [{AC7688FF-018E-1033-1104-990203260001}] "C:\Program Files\Common Files\{AC7688FF-018E-1033-1104-990203260001}\Update.exe" te-110-12-0000213
O4 - HKLM\..\Run: [SDR6_Check] "C:\Program Files\Common Files\DriveCleaner Free\udcsdr.exe"
O4 - HKLM\..\Run: [PAS_Check] "C:\Program Files\Common Files\DriveCleaner Free\udcpas.exe"
O4 - HKLM\..\Run: [{AC7688FF-018F-1033-1104-990203260001}] "C:\Program Files\Common Files\{AC7688FF-018F-1033-1104-990203260001}\Update.exe" te-110-12-0000213
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Ptre] "C:\PROGRA~1\COMMON~1\SMANTE~1\chkntfs.exe" -vt yazb
O4 - HKCU\..\Run: [iqmw] C:\Program Files\Common Files\iqmw\iqmwm.exe
O4 - HKCU\..\Run: [Quqlqmez] C:\Documents and Settings\odirish\Application Data\S?mantec\?hkdsk.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) -
https://activatemyds...DSL/tgctlcm.cabO16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -
http://software-dl.r...ip/RdxIE601.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://cdn2.zone.msn...ro.cab34246.cabO16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -
http://zone.msn.com/...aploader_v6.cabO23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
O23 - Service: COM+ Messages - Unknown owner - C:\WINDOWS\System32\svchosts.exe" -e te-110-12-0000213 (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE
Mary Ann