"USER" - 07-01-26 11:42:07 Service Pack 2
ComboFix 07-01-25 - Running from: "C:\Documents and Settings\USER\Desktop"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\unsvchosts.lzma
C:\Program Files\Common Files\{30E0A~1
C:\Program Files\Common Files\{90E0A~1
C:\Program Files\Cowabanga
C:\WINDOWS\system32\svchosts.exe
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\DOCUME~1
C:\qoobox\purity\DOCUME~1\USER
C:\qoobox\purity\DOCUME~1\USER\Application Data
C:\qoobox\purity\DOCUME~1\USER\My Documents
C:\qoobox\purity\DOCUME~1\USER\Application Data\from.txt
C:\qoobox\purity\DOCUME~1\USER\Application Data\ICROSO~1
C:\qoobox\purity\DOCUME~1\USER\My Documents\from.txt
C:\qoobox\purity\DOCUME~1\USER\My Documents\YSTEM3~1
C:\qoobox\purity\WINDOWS\PPPATC~1
((((((((((((((((((((((((((((((( Files Created from 2006-12-26 to 2007-01-26 ))))))))))))))))))))))))))))))))))
2007-01-26 11:43 <DIR> d-------- C:\WINDOWS\erdnt
2007-01-26 10:05 <DIR> d-------- C:\DOCUME~1\USER\Application Data\ądobe
2007-01-17 20:47 <DIR> d-------- C:\Program Files\Mozilla Firefox
2007-01-17 20:45 5,971,432 --a------ C:\Program Files\Firefox Setup 2.0.0.1.exe
2007-01-15 20:16 <DIR> d-------- C:\WINDOWS\system32\bak
2007-01-09 00:45 <DIR> d-------- C:\DOCUME~1\USER\Application Data\acccore
2007-01-09 00:44 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\AOL OCP
2007-01-09 00:43 <DIR> d-------- C:\Program Files\Viewpoint
2007-01-09 00:43 <DIR> d-------- C:\Program Files\Common Files\Nullsoft
2007-01-09 00:43 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Viewpoint
2007-01-09 00:43 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\AOL
2007-01-09 00:42 <DIR> d-------- C:\Program Files\Common Files\AOL
2007-01-09 00:42 <DIR> d-------- C:\Program Files\AIM6
2007-01-09 00:40 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\AOL Downloads
2007-01-08 23:44 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Google
2007-01-08 23:27 <DIR> d-------- C:\WINDOWS\Sun
2007-01-08 23:27 <DIR> d-------- C:\DOCUME~1\USER\Application Data\Sun
2007-01-08 23:22 <DIR> d-------- C:\Program Files\Google
2007-01-08 23:22 <DIR> d-------- C:\DOCUME~1\USER\Application Data\Google
2007-01-08 23:21 <DIR> d-------- C:\Program Files\Java
2007-01-08 23:18 <DIR> d-------- C:\Program Files\Common Files\Java
2007-01-07 22:34 <DIR> d-------- C:\DOCUME~1\USER\Application Data\Zoner
2007-01-07 21:42 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2007-01-07 21:42 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll
2007-01-07 21:42 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2007-01-06 12:06 <DIR> d-------- C:\Program Files\iPod
2007-01-06 12:06 <DIR> d-------- C:\DOCUME~1\USER\Application Data\Apple Computer
2007-01-06 12:05 <DIR> d-------- C:\Program Files\QuickTime
2007-01-06 12:05 <DIR> d-------- C:\Program Files\iTunes
2007-01-06 12:04 <DIR> d-------- C:\Program Files\Apple Software Update
2007-01-06 12:04 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Apple Computer
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-01-26 10:37 -------- d--h----- C:\Program Files\installshield installation information
2007-01-26 10:05 -------- d-------- C:\Documents and Settings\USER\Application Data\ądobe
2007-01-23 20:02 -------- d-------- C:\Program Files\ati technologies
2007-01-17 20:47 -------- d-------- C:\Documents and Settings\USER\Application Data\mozilla
2007-01-15 20:53 -------- d-------- C:\Program Files\apoint
2007-01-15 20:47 38924 --a------ C:\WINDOWS\system32\zcfgsvc.exe
2007-01-15 20:47 38924 --a------ C:\WINDOWS\system32\wltray.exe
2007-01-15 20:16 -------- d-------- C:\Program Files\messenger
2007-01-14 18:02 -------- d-------- C:\Documents and Settings\USER\Application Data\openoffice.org2
2007-01-13 15:55 -------- d-------- C:\Documents and Settings\USER\Application Data\apple computer
2007-01-09 00:45 -------- d-------- C:\Documents and Settings\USER\Application Data\acccore
2007-01-08 23:27 -------- d-------- C:\Documents and Settings\USER\Application Data\sun
2007-01-08 23:22 -------- d-------- C:\Documents and Settings\USER\Application Data\google
2007-01-07 22:34 -------- d-------- C:\Documents and Settings\USER\Application Data\zoner
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"Google Desktop Search"="\"C:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe\" /startup"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.908.8472\\GoogleToolbarNotifier.exe"
"Aim6"="\"C:\\Program Files\\AIM6\\aim6.exe\" /d locale=en-US ee://aol/imApp"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"Apoint"="C:\\Program Files\\Apoint\\Apoint.exe"
"Broadcom Wireless Manager UI"="C:\\WINDOWS\\system32\\WLTRAY.exe"
"ZCfgSvc.exe"="C:\\WINDOWS\\system32\\ZCfgSvc.exe"
"PRONoMgr.exe"="C:\\Program Files\\Intel\\NCS\\PROSet\\PRONoMgr.exe"
"Dell QuickSet"="C:\\Program Files\\Dell\\QuickSet\\quickset.exe"
"PCTVOICE"="pctspk.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_10\\bin\\jusched.exe\""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
Completion time: 07-01-26 11:45:42
HERE IS THE ANTIVIRUS PROGRAM REPORT:
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 2:07:34 PM 1/26/2007
+ Scan result:
C:\System Volume Information\_restore{098A718E-B7A7-4024-B16D-E30C3B0C0ACF}\RP53\A0012365.exe -> Adware.ClickSpring : Cleaned.
C:\System Volume Information\_restore{098A718E-B7A7-4024-B16D-E30C3B0C0ACF}\RP53\A0012360.dll -> Adware.MaxSearch : Cleaned.
C:\System Volume Information\_restore{098A718E-B7A7-4024-B16D-E30C3B0C0ACF}\RP51\A0012297.exe -> Adware.MediaTicket : Cleaned.
C:\System Volume Information\_restore{098A718E-B7A7-4024-B16D-E30C3B0C0ACF}\RP48\A0007044.exe -> Adware.PurityScan : Cleaned.
C:\System Volume Information\_restore{098A718E-B7A7-4024-B16D-E30C3B0C0ACF}\RP48\A0008041.dll -> Adware.PurityScan : Cleaned.
C:\System Volume Information\_restore{098A718E-B7A7-4024-B16D-E30C3B0C0ACF}\RP51\A0012283.dll -> Adware.PurityScan : Cleaned.
C:\System Volume Information\_restore{098A718E-B7A7-4024-B16D-E30C3B0C0ACF}\RP53\A0012362.exe -> Adware.Softomate : Cleaned.
C:\System Volume Information\_restore{098A718E-B7A7-4024-B16D-E30C3B0C0ACF}\RP53\A0012363.dll -> Adware.Softomate : Cleaned.
C:\System Volume Information\_restore{098A718E-B7A7-4024-B16D-E30C3B0C0ACF}\RP53\A0012379.exe -> Downloader.Agent.bca : Cleaned.
:mozilla.114:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.69:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.70:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.71:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.72:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.73:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.74:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.28:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.29:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.30:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.31:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.32:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.27:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.56:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.57:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.58:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.59:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.60:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.61:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.62:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.63:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.110:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Clickbank : Cleaned.
:mozilla.43:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\USER\Cookies\user@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.105:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.106:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.107:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.108:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\USER\Cookies\[email protected][2].txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.51:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.52:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.53:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.54:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.55:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.111:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.97:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.118:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.119:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.100:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.101:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.98:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.99:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.75:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.76:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.77:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.78:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.79:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.80:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.81:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.82:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.83:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.84:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.85:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.86:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.38:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.40:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.41:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.42:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.44:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.46:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\iqmme1rd.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\USER\Cookies\[email protected][1].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\System Volume Information\_restore{098A718E-B7A7-4024-B16D-E30C3B0C0ACF}\RP48\A0007049.exe -> Trojan.Small : Cleaned.
C:\System Volume Information\_restore{098A718E-B7A7-4024-B16D-E30C3B0C0ACF}\RP50\A0011289.exe -> Trojan.Small : Cleaned.
C:\System Volume Information\_restore{098A718E-B7A7-4024-B16D-E30C3B0C0ACF}\RP51\A0012292.exe -> Trojan.Small : Cleaned.
C:\System Volume Information\_restore{098A718E-B7A7-4024-B16D-E30C3B0C0ACF}\RP53\A0012337.exe -> Trojan.Small : Cleaned.
::Report end
THANK YOU AGAIN!!!
James