cj7eagle
Topic Starter
Was having a lot of trouble with outerinfo popups, so following the instructions on this thread http://forums.tomcoyote.org/index.php?act=…mp;t=72305&
Here are my logs…
Hijack
Logfile of HijackThis v1.99.1
Scan saved at 12:59:12 AM, on 12/17/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Philips\PSA2\skin\QveCplSk.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\AOL\1154130946\ee\AOLSoftware.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
F:\HJT\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://pool.dylantree.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: (no name) - {BC8596F3-0710-7990-6E99-51807B4A069C} - C:\WINDOWS\system32\fbynla.dll (file missing)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [QveCtl2Tray] C:\Program Files\Philips\PSA2\skin\QveCplSk.EXE C:\Program Files\Philips\PSA2\skin
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1154130946\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Oisr] "C:\DOCUME~1\JAIHER~1\MYDOCU~1\ASEMBL~1\chkdsk.exe" -vt tzt
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - Global Startup: dlbcserv.lnk = C:\Program Files\Dell Photo Printer 720\dlbcserv.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.1\resources\en-US\local\search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O20 - AppInit_DLLs: dvdplay.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: WMP54Gv4SVC - Unknown owner - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe" "WMP54Gv4.exe (file missing)
combofix
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\QooBox\Purity\Documents and Settings\Jai Herman\Application Data\CROSOF~1
C:\QooBox\Purity\Documents and Settings\Jai Herman\Application Data\CROSOF~1.NET
C:\QooBox\Purity\Documents and Settings\Jai Herman\Application Data\DOBE~1
C:\QooBox\Purity\Documents and Settings\Jai Herman\Application Data\ECURIT~1
C:\QooBox\Purity\Documents and Settings\Jai Herman\Application Data\MCROSO~1.NET
C:\QooBox\Purity\Documents and Settings\Jai Herman\Application Data\PPATCH~1
C:\QooBox\Purity\Documents and Settings\Jai Herman\Application Data\SSTEM3~1
C:\QooBox\Purity\Documents and Settings\Jai Herman\Application Data\SSTEM~1
C:\QooBox\Purity\Documents and Settings\Jai Herman\Application Data\WNSXS~1
C:\QooBox\Purity\Documents and Settings\Jai Herman\My Documents\ASEMBL~1
C:\QooBox\Purity\Documents and Settings\Jai Herman\My Documents\CURITY~1
C:\QooBox\Purity\Documents and Settings\Jai Herman\My Documents\DOBE~1
C:\QooBox\Purity\Documents and Settings\Jai Herman\My Documents\FNTS~1
C:\QooBox\Purity\Documents and Settings\Jai Herman\My Documents\FNTS~2
C:\QooBox\Purity\Documents and Settings\Jai Herman\My Documents\RACLE~1
C:\QooBox\Purity\Documents and Settings\Jai Herman\My Documents\RACLE~2
C:\QooBox\Purity\Documents and Settings\Jai Herman\My Documents\SKS~1
C:\QooBox\Purity\Documents and Settings\Jai Herman\My Documents\SMBOLS~1
C:\QooBox\Purity\Documents and Settings\Jai Herman\My Documents\SSTEM~1
C:\QooBox\Purity\Documents and Settings\Jai Herman\My Documents\WNSXS~1
C:\QooBox\Purity\Documents and Settings\Jai Herman\My Documents\YMANTE~1
C:\QooBox\Purity\Documents and Settings\Jai Herman\My Documents\YMBOLS~1
C:\QooBox\Purity\Documents and Settings\Jai Herman\My Documents\ASEMBL~1\ASEMBL~1
C:\QooBox\Purity\Documents and Settings\Jai Herman\My Documents\ASEMBL~1\chkdsk.exe
C:\QooBox\Purity\Program Files\CROSOF~1.NET
C:\QooBox\Purity\Program Files\FNTS~1
C:\QooBox\Purity\Program Files\MANTEC~1
C:\QooBox\Purity\Program Files\PPATCH~1
C:\QooBox\Purity\Program Files\SKS~1
C:\QooBox\Purity\Program Files\SSEMBL~1
C:\QooBox\Purity\Program Files\SSTEM~1
C:\QooBox\Purity\Program Files\YSTEM3~1
C:\QooBox\Purity\Program Files\YSTEM~1
C:\QooBox\Purity\Program Files\Common Files\APPATC~1
C:\QooBox\Purity\Program Files\Common Files\ASEMBL~1
C:\QooBox\Purity\Program Files\Common Files\ASKS~1
C:\QooBox\Purity\Program Files\Common Files\CROSOF~1
C:\QooBox\Purity\Program Files\Common Files\ECURIT~1
C:\QooBox\Purity\Program Files\Common Files\FNTS~1
C:\QooBox\Purity\Program Files\Common Files\ICROSO~1
C:\QooBox\Purity\Program Files\Common Files\ICROSO~1.NET
C:\QooBox\Purity\Program Files\Common Files\RACLE~1
C:\QooBox\Purity\Program Files\Common Files\RACLE~2
C:\QooBox\Purity\Program Files\Common Files\SCURIT~1
C:\QooBox\Purity\Program Files\Common Files\SKS~1
C:\QooBox\Purity\Program Files\Common Files\SMBOLS~1
C:\QooBox\Purity\Program Files\Common Files\SSEMBL~1
C:\QooBox\Purity\Program Files\Common Files\SSTEM3~1
C:\QooBox\Purity\WINDOWS\CROSOF~1
C:\QooBox\Purity\WINDOWS\CROSOF~1.NET
C:\QooBox\Purity\WINDOWS\DOBE~1
C:\QooBox\Purity\WINDOWS\FNTS~1
C:\QooBox\Purity\WINDOWS\MBOLS~1
C:\QooBox\Purity\WINDOWS\MCROSO~1.NET
C:\QooBox\Purity\WINDOWS\PPATCH~1
C:\QooBox\Purity\WINDOWS\SEMBLY~1
C:\QooBox\Purity\WINDOWS\SSTEM~1
C:\QooBox\Purity\WINDOWS\STEM32~1
C:\QooBox\Purity\WINDOWS\YMANTE~1
C:\QooBox\Purity\WINDOWS\YSTEM3~1
C:\QooBox\Purity\WINDOWS\system32\CROSOF~1.NET
C:\QooBox\Purity\WINDOWS\system32\CURITY~1
C:\QooBox\Purity\WINDOWS\system32\ICROSO~1
C:\QooBox\Purity\WINDOWS\system32\MBOLS~1
C:\QooBox\Purity\WINDOWS\system32\MCROSO~1.NET
C:\QooBox\Purity\WINDOWS\system32\RACLE~1
C:\QooBox\Purity\WINDOWS\system32\RACLE~2
C:\QooBox\Purity\WINDOWS\system32\SMBOLS~1
C:\QooBox\Purity\WINDOWS\system32\SSEMBL~1
C:\QooBox\Purity\WINDOWS\system32\STEM~1
C:\QooBox\Purity\WINDOWS\system32\WNSXS~1
C:\QooBox\Purity\WINDOWS\system32\YMANTE~1
C:\QooBox\Purity\WINDOWS\system32\YMBOLS~1
((((((((((((((((((((((((((((((( Files Created from 2006-11-16 to 2006-12-16 ))))))))))))))))))))))))))))))))))
2006-12-06 08:18 d——– C:\Program Files\Common Files\Download Manager
2006-12-05 07:15 94,208 –a—— C:\WINDOWS\system32\GTW32N50.dll
2006-12-05 07:15 356,096 –a—— C:\WINDOWS\system32\rt61.sys
2006-12-05 07:15 356,096 –a—— C:\WINDOWS\system32\drivers\rt61.sys
2006-12-05 07:15 243,328 –a—— C:\WINDOWS\system32\rt2500.sys
2006-12-05 07:15 20,747 –a—— C:\WINDOWS\system32\drivers\AegisP.sys
2006-12-05 07:15 17,992 –a—— C:\WINDOWS\system32\drivers\bcm42rly.sys
2006-12-05 07:15 17,992 –a—— C:\WINDOWS\system32\bcm42rly.sys
2006-12-05 07:15 17,992 –a—— C:\WINDOWS\bcm42rly.sys
2006-12-05 07:15 15,872 –a—— C:\WINDOWS\system32\GTNDIS5.sys
2006-12-05 07:14 d——– C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor
2006-11-17 18:03 852,042 –a—— C:\WINDOWS\system32\Lemmings Revolution.exe
2006-11-17 18:03 56,832 –a—— C:\WINDOWS\system32\Iyvu9_32.dll
2006-11-17 18:03 d——– C:\WINDOWS\system32\SavedSystemFiles
2006-11-17 08:04 d——– C:\WINDOWS\system32\appmgmt
2006-11-17 08:04 d——– C:\WINDOWS\SxsCaPendDel
2006-11-16 21:13 d——– C:\Documents and Settings\Jai Herman\Application Data\Jasc Software Inc
2006-11-16 21:12 d——– C:\Program Files\Jasc Software Inc
2006-11-16 21:12 d——– C:\Program Files\Dell Photo Printer 720
2006-11-16 21:12 d——– C:\Program Files\Dell Computer
2006-11-16 21:12 d——– C:\Documents and Settings\All Users\Application Data\Dell Photo Printer 720
2006-11-16 21:06 25,856 –a—— C:\WINDOWS\system32\drivers\usbprint.sys
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-12-17 00:03 ——– d——– C:\Program Files\Symantec AntiVirus
2006-12-17 00:01 ——– d——– C:\Program Files\Common Files
2006-12-16 23:56 ——– d——– C:\Documents and Settings\Jai Herman\Application Data\AdobeUM
2006-12-16 23:54 122 –a—— C:\Documents and Settings\Jai Herman\Application Data\iScrobbler.ini
2006-12-16 22:50 ——– d——– C:\Documents and Settings\Jai Herman\Application Data\Xfire
2006-12-16 03:03 ——– d——– C:\Program Files\PokerStars
2006-12-13 03:02 ——– d——– C:\Program Files\Internet Explorer
2006-12-13 03:01 ——– d——– C:\Program Files\Outlook Express
2006-12-13 03:01 ——– d——– C:\Program Files\Common Files\System
2006-12-11 14:49 ——– d——– C:\Documents and Settings\Jai Herman\Application Data\teamspeak2
2006-12-08 23:12 ——– d—s—- C:\Program Files\Xfire
2006-12-08 14:15 ——– d——– C:\Program Files\AIM
2006-12-08 14:05 ——– d——– C:\Program Files\AOD
2006-12-07 00:29 2374472 –a—— C:\WINDOWS\system32\wmvcore.dll
2006-12-05 07:27 ——– d——– C:\Program Files\Google
2006-12-05 07:26 ——– d——– C:\Program Files\Yahoo!
2006-12-05 07:15 ——– d–h—– C:\Program Files\InstallShield Installation Information
2006-11-17 18:03 ——– d——– C:\Program Files\Intel
2006-11-17 08:03 ——– d——– C:\Program Files\MasqueAIM
2006-11-16 21:13 ——– d—s—- C:\Documents and Settings\Jai Herman\Application Data\Microsoft
2006-11-08 00:06 679424 –a—— C:\WINDOWS\system32\inetcomm.dll
2006-10-19 08:56 713216 –a—— C:\WINDOWS\system32\sxs.dll
2006-10-13 07:35 65536 –a—— C:\WINDOWS\system32\nwwks.dll
2006-10-13 07:35 64000 –a—— C:\WINDOWS\system32\nwapi32.dll
2006-10-13 07:35 142336 –a—— C:\WINDOWS\system32\nwprovau.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Steam"="\"c:\\program files\\valve\\steam\\steam.exe\" -silent"
"AIM"="C:\\Program Files\\AIM\\aim.exe -cnetwait.odl"
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"Oisr"="\"C:\\DOCUME~1\\JAIHER~1\\MYDOCU~1\\ASEMBL~1\\chkdsk.exe\" -vt tzt"
"Aim6"="\"C:\\Program Files\\Common Files\\AOL\\Launch\\AOLLaunch.exe\" /d locale=en-US ee://aol/imApp"
"updateMgr"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\AdobeUpdateManager.exe\" AcRdB7_0_7"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.0.720.3640\\GoogleToolbarNotifier.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"vptray"="C:\\PROGRA~1\\SYMANT~1\\VPTray.exe"
"WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"
"ViewMgr"="C:\\Program Files\\Viewpoint\\Viewpoint Manager\\ViewMgr.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"ATICCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe\" runtime -Delay"
"QveCtl2Tray"="C:\\Program Files\\Philips\\PSA2\\skin\\QveCplSk.EXE C:\\Program Files\\Philips\\PSA2\\skin"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"HostManager"="C:\\Program Files\\Common Files\\AOL\\1154130946\\ee\\AOLSoftware.exe"
"IPHSend"="C:\\Program Files\\Common Files\\AOL\\IPHSend\\IPHSend.exe"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="http://myspace-016.vo.llnwd.net/00566/61/01/566461016_l.jpg"
"SubscribedURL"="http://myspace-016.vo.llnwd.net/00566/61/01/566461016_l.jpg"
"FriendlyName"=""
"Flags"=dword:00001001
"Position"=hex:2c,00,00,00,12,03,00,00,19,01,00,00,58,02,00,00,c2,01,00,00,e8,\
03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:01,00,00,00
"OriginalStateInfo"=hex:18,00,00,00,12,03,00,00,19,01,00,00,58,02,00,00,c2,01,\
00,00,01,00,00,40
"RestoredStateInfo"=hex:14,6d,0f,06,41,c0,b4,74,18,c4,0c,09,68,de,0f,06,20,6d,\
0f,06,72,07,00,00
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,\
00,00,04,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,\
00,00,01,00,00,00
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
Completion time: 06-12-17 0:04:10.93
C:\ComboFix.txt … 06-12-17 00:04
AVG
———————————————————
AVG Anti-Spyware - Scan Report
———————————————————
+ Created at: 12:53:41 AM 12/17/2006
+ Scan result:
C:\System Volume Information\_restore{B75888F9-2B98-4DC1-995A-5391B5AF2989}\RP556\A0089340.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B75888F9-2B98-4DC1-995A-5391B5AF2989}\RP558\A0089352.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B75888F9-2B98-4DC1-995A-5391B5AF2989}\RP581\A0094138.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B75888F9-2B98-4DC1-995A-5391B5AF2989}\RP582\A0094350.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B75888F9-2B98-4DC1-995A-5391B5AF2989}\RP586\A0097534.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B75888F9-2B98-4DC1-995A-5391B5AF2989}\RP588\A0097656.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B75888F9-2B98-4DC1-995A-5391B5AF2989}\RP591\A0100024.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B75888F9-2B98-4DC1-995A-5391B5AF2989}\RP591\A0100075.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\WINDOWS\system32\__delete_on_reboot__d_v_d_p_l_a_y_._d_l_l_ -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\WINDOWS\system32\agzp.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\WINDOWS\system32\fmohksz.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\WINDOWS\system32\imwijz.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B75888F9-2B98-4DC1-995A-5391B5AF2989}\RP556\A0089341.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B75888F9-2B98-4DC1-995A-5391B5AF2989}\RP581\A0094139.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B75888F9-2B98-4DC1-995A-5391B5AF2989}\RP586\A0097535.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B75888F9-2B98-4DC1-995A-5391B5AF2989}\RP588\A0097731.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B75888F9-2B98-4DC1-995A-5391B5AF2989}\RP591\A0100020.exe -> Trojan.Small : Cleaned with backup (quarantined).
::Report end
Here are my logs…
Hijack
Logfile of HijackThis v1.99.1
Scan saved at 12:59:12 AM, on 12/17/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Philips\PSA2\skin\QveCplSk.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\AOL\1154130946\ee\AOLSoftware.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
F:\HJT\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://pool.dylantree.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: (no name) - {BC8596F3-0710-7990-6E99-51807B4A069C} - C:\WINDOWS\system32\fbynla.dll (file missing)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [QveCtl2Tray] C:\Program Files\Philips\PSA2\skin\QveCplSk.EXE C:\Program Files\Philips\PSA2\skin
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1154130946\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Oisr] "C:\DOCUME~1\JAIHER~1\MYDOCU~1\ASEMBL~1\chkdsk.exe" -vt tzt
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - Global Startup: dlbcserv.lnk = C:\Program Files\Dell Photo Printer 720\dlbcserv.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.1\resources\en-US\local\search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O20 - AppInit_DLLs: dvdplay.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: WMP54Gv4SVC - Unknown owner - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe" "WMP54Gv4.exe (file missing)
combofix
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\QooBox\Purity\Documents and Settings\Jai Herman\Application Data\CROSOF~1
C:\QooBox\Purity\Documents and Settings\Jai Herman\Application Data\CROSOF~1.NET
C:\QooBox\Purity\Documents and Settings\Jai Herman\Application Data\DOBE~1
C:\QooBox\Purity\Documents and Settings\Jai Herman\Application Data\ECURIT~1
C:\QooBox\Purity\Documents and Settings\Jai Herman\Application Data\MCROSO~1.NET
C:\QooBox\Purity\Documents and Settings\Jai Herman\Application Data\PPATCH~1
C:\QooBox\Purity\Documents and Settings\Jai Herman\Application Data\SSTEM3~1
C:\QooBox\Purity\Documents and Settings\Jai Herman\Application Data\SSTEM~1
C:\QooBox\Purity\Documents and Settings\Jai Herman\Application Data\WNSXS~1
C:\QooBox\Purity\Documents and Settings\Jai Herman\My Documents\ASEMBL~1
C:\QooBox\Purity\Documents and Settings\Jai Herman\My Documents\CURITY~1
C:\QooBox\Purity\Documents and Settings\Jai Herman\My Documents\DOBE~1
C:\QooBox\Purity\Documents and Settings\Jai Herman\My Documents\FNTS~1
C:\QooBox\Purity\Documents and Settings\Jai Herman\My Documents\FNTS~2
C:\QooBox\Purity\Documents and Settings\Jai Herman\My Documents\RACLE~1
C:\QooBox\Purity\Documents and Settings\Jai Herman\My Documents\RACLE~2
C:\QooBox\Purity\Documents and Settings\Jai Herman\My Documents\SKS~1
C:\QooBox\Purity\Documents and Settings\Jai Herman\My Documents\SMBOLS~1
C:\QooBox\Purity\Documents and Settings\Jai Herman\My Documents\SSTEM~1
C:\QooBox\Purity\Documents and Settings\Jai Herman\My Documents\WNSXS~1
C:\QooBox\Purity\Documents and Settings\Jai Herman\My Documents\YMANTE~1
C:\QooBox\Purity\Documents and Settings\Jai Herman\My Documents\YMBOLS~1
C:\QooBox\Purity\Documents and Settings\Jai Herman\My Documents\ASEMBL~1\ASEMBL~1
C:\QooBox\Purity\Documents and Settings\Jai Herman\My Documents\ASEMBL~1\chkdsk.exe
C:\QooBox\Purity\Program Files\CROSOF~1.NET
C:\QooBox\Purity\Program Files\FNTS~1
C:\QooBox\Purity\Program Files\MANTEC~1
C:\QooBox\Purity\Program Files\PPATCH~1
C:\QooBox\Purity\Program Files\SKS~1
C:\QooBox\Purity\Program Files\SSEMBL~1
C:\QooBox\Purity\Program Files\SSTEM~1
C:\QooBox\Purity\Program Files\YSTEM3~1
C:\QooBox\Purity\Program Files\YSTEM~1
C:\QooBox\Purity\Program Files\Common Files\APPATC~1
C:\QooBox\Purity\Program Files\Common Files\ASEMBL~1
C:\QooBox\Purity\Program Files\Common Files\ASKS~1
C:\QooBox\Purity\Program Files\Common Files\CROSOF~1
C:\QooBox\Purity\Program Files\Common Files\ECURIT~1
C:\QooBox\Purity\Program Files\Common Files\FNTS~1
C:\QooBox\Purity\Program Files\Common Files\ICROSO~1
C:\QooBox\Purity\Program Files\Common Files\ICROSO~1.NET
C:\QooBox\Purity\Program Files\Common Files\RACLE~1
C:\QooBox\Purity\Program Files\Common Files\RACLE~2
C:\QooBox\Purity\Program Files\Common Files\SCURIT~1
C:\QooBox\Purity\Program Files\Common Files\SKS~1
C:\QooBox\Purity\Program Files\Common Files\SMBOLS~1
C:\QooBox\Purity\Program Files\Common Files\SSEMBL~1
C:\QooBox\Purity\Program Files\Common Files\SSTEM3~1
C:\QooBox\Purity\WINDOWS\CROSOF~1
C:\QooBox\Purity\WINDOWS\CROSOF~1.NET
C:\QooBox\Purity\WINDOWS\DOBE~1
C:\QooBox\Purity\WINDOWS\FNTS~1
C:\QooBox\Purity\WINDOWS\MBOLS~1
C:\QooBox\Purity\WINDOWS\MCROSO~1.NET
C:\QooBox\Purity\WINDOWS\PPATCH~1
C:\QooBox\Purity\WINDOWS\SEMBLY~1
C:\QooBox\Purity\WINDOWS\SSTEM~1
C:\QooBox\Purity\WINDOWS\STEM32~1
C:\QooBox\Purity\WINDOWS\YMANTE~1
C:\QooBox\Purity\WINDOWS\YSTEM3~1
C:\QooBox\Purity\WINDOWS\system32\CROSOF~1.NET
C:\QooBox\Purity\WINDOWS\system32\CURITY~1
C:\QooBox\Purity\WINDOWS\system32\ICROSO~1
C:\QooBox\Purity\WINDOWS\system32\MBOLS~1
C:\QooBox\Purity\WINDOWS\system32\MCROSO~1.NET
C:\QooBox\Purity\WINDOWS\system32\RACLE~1
C:\QooBox\Purity\WINDOWS\system32\RACLE~2
C:\QooBox\Purity\WINDOWS\system32\SMBOLS~1
C:\QooBox\Purity\WINDOWS\system32\SSEMBL~1
C:\QooBox\Purity\WINDOWS\system32\STEM~1
C:\QooBox\Purity\WINDOWS\system32\WNSXS~1
C:\QooBox\Purity\WINDOWS\system32\YMANTE~1
C:\QooBox\Purity\WINDOWS\system32\YMBOLS~1
((((((((((((((((((((((((((((((( Files Created from 2006-11-16 to 2006-12-16 ))))))))))))))))))))))))))))))))))
2006-12-06 08:18 d——– C:\Program Files\Common Files\Download Manager
2006-12-05 07:15 94,208 –a—— C:\WINDOWS\system32\GTW32N50.dll
2006-12-05 07:15 356,096 –a—— C:\WINDOWS\system32\rt61.sys
2006-12-05 07:15 356,096 –a—— C:\WINDOWS\system32\drivers\rt61.sys
2006-12-05 07:15 243,328 –a—— C:\WINDOWS\system32\rt2500.sys
2006-12-05 07:15 20,747 –a—— C:\WINDOWS\system32\drivers\AegisP.sys
2006-12-05 07:15 17,992 –a—— C:\WINDOWS\system32\drivers\bcm42rly.sys
2006-12-05 07:15 17,992 –a—— C:\WINDOWS\system32\bcm42rly.sys
2006-12-05 07:15 17,992 –a—— C:\WINDOWS\bcm42rly.sys
2006-12-05 07:15 15,872 –a—— C:\WINDOWS\system32\GTNDIS5.sys
2006-12-05 07:14 d——– C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor
2006-11-17 18:03 852,042 –a—— C:\WINDOWS\system32\Lemmings Revolution.exe
2006-11-17 18:03 56,832 –a—— C:\WINDOWS\system32\Iyvu9_32.dll
2006-11-17 18:03 d——– C:\WINDOWS\system32\SavedSystemFiles
2006-11-17 08:04 d——– C:\WINDOWS\system32\appmgmt
2006-11-17 08:04 d——– C:\WINDOWS\SxsCaPendDel
2006-11-16 21:13 d——– C:\Documents and Settings\Jai Herman\Application Data\Jasc Software Inc
2006-11-16 21:12 d——– C:\Program Files\Jasc Software Inc
2006-11-16 21:12 d——– C:\Program Files\Dell Photo Printer 720
2006-11-16 21:12 d——– C:\Program Files\Dell Computer
2006-11-16 21:12 d——– C:\Documents and Settings\All Users\Application Data\Dell Photo Printer 720
2006-11-16 21:06 25,856 –a—— C:\WINDOWS\system32\drivers\usbprint.sys
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-12-17 00:03 ——– d——– C:\Program Files\Symantec AntiVirus
2006-12-17 00:01 ——– d——– C:\Program Files\Common Files
2006-12-16 23:56 ——– d——– C:\Documents and Settings\Jai Herman\Application Data\AdobeUM
2006-12-16 23:54 122 –a—— C:\Documents and Settings\Jai Herman\Application Data\iScrobbler.ini
2006-12-16 22:50 ——– d——– C:\Documents and Settings\Jai Herman\Application Data\Xfire
2006-12-16 03:03 ——– d——– C:\Program Files\PokerStars
2006-12-13 03:02 ——– d——– C:\Program Files\Internet Explorer
2006-12-13 03:01 ——– d——– C:\Program Files\Outlook Express
2006-12-13 03:01 ——– d——– C:\Program Files\Common Files\System
2006-12-11 14:49 ——– d——– C:\Documents and Settings\Jai Herman\Application Data\teamspeak2
2006-12-08 23:12 ——– d—s—- C:\Program Files\Xfire
2006-12-08 14:15 ——– d——– C:\Program Files\AIM
2006-12-08 14:05 ——– d——– C:\Program Files\AOD
2006-12-07 00:29 2374472 –a—— C:\WINDOWS\system32\wmvcore.dll
2006-12-05 07:27 ——– d——– C:\Program Files\Google
2006-12-05 07:26 ——– d——– C:\Program Files\Yahoo!
2006-12-05 07:15 ——– d–h—– C:\Program Files\InstallShield Installation Information
2006-11-17 18:03 ——– d——– C:\Program Files\Intel
2006-11-17 08:03 ——– d——– C:\Program Files\MasqueAIM
2006-11-16 21:13 ——– d—s—- C:\Documents and Settings\Jai Herman\Application Data\Microsoft
2006-11-08 00:06 679424 –a—— C:\WINDOWS\system32\inetcomm.dll
2006-10-19 08:56 713216 –a—— C:\WINDOWS\system32\sxs.dll
2006-10-13 07:35 65536 –a—— C:\WINDOWS\system32\nwwks.dll
2006-10-13 07:35 64000 –a—— C:\WINDOWS\system32\nwapi32.dll
2006-10-13 07:35 142336 –a—— C:\WINDOWS\system32\nwprovau.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Steam"="\"c:\\program files\\valve\\steam\\steam.exe\" -silent"
"AIM"="C:\\Program Files\\AIM\\aim.exe -cnetwait.odl"
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"Oisr"="\"C:\\DOCUME~1\\JAIHER~1\\MYDOCU~1\\ASEMBL~1\\chkdsk.exe\" -vt tzt"
"Aim6"="\"C:\\Program Files\\Common Files\\AOL\\Launch\\AOLLaunch.exe\" /d locale=en-US ee://aol/imApp"
"updateMgr"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\AdobeUpdateManager.exe\" AcRdB7_0_7"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.0.720.3640\\GoogleToolbarNotifier.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"vptray"="C:\\PROGRA~1\\SYMANT~1\\VPTray.exe"
"WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"
"ViewMgr"="C:\\Program Files\\Viewpoint\\Viewpoint Manager\\ViewMgr.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"ATICCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe\" runtime -Delay"
"QveCtl2Tray"="C:\\Program Files\\Philips\\PSA2\\skin\\QveCplSk.EXE C:\\Program Files\\Philips\\PSA2\\skin"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"HostManager"="C:\\Program Files\\Common Files\\AOL\\1154130946\\ee\\AOLSoftware.exe"
"IPHSend"="C:\\Program Files\\Common Files\\AOL\\IPHSend\\IPHSend.exe"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="http://myspace-016.vo.llnwd.net/00566/61/01/566461016_l.jpg"
"SubscribedURL"="http://myspace-016.vo.llnwd.net/00566/61/01/566461016_l.jpg"
"FriendlyName"=""
"Flags"=dword:00001001
"Position"=hex:2c,00,00,00,12,03,00,00,19,01,00,00,58,02,00,00,c2,01,00,00,e8,\
03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:01,00,00,00
"OriginalStateInfo"=hex:18,00,00,00,12,03,00,00,19,01,00,00,58,02,00,00,c2,01,\
00,00,01,00,00,40
"RestoredStateInfo"=hex:14,6d,0f,06,41,c0,b4,74,18,c4,0c,09,68,de,0f,06,20,6d,\
0f,06,72,07,00,00
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,\
00,00,04,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,\
00,00,01,00,00,00
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
Completion time: 06-12-17 0:04:10.93
C:\ComboFix.txt … 06-12-17 00:04
AVG
———————————————————
AVG Anti-Spyware - Scan Report
———————————————————
+ Created at: 12:53:41 AM 12/17/2006
+ Scan result:
C:\System Volume Information\_restore{B75888F9-2B98-4DC1-995A-5391B5AF2989}\RP556\A0089340.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B75888F9-2B98-4DC1-995A-5391B5AF2989}\RP558\A0089352.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B75888F9-2B98-4DC1-995A-5391B5AF2989}\RP581\A0094138.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B75888F9-2B98-4DC1-995A-5391B5AF2989}\RP582\A0094350.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B75888F9-2B98-4DC1-995A-5391B5AF2989}\RP586\A0097534.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B75888F9-2B98-4DC1-995A-5391B5AF2989}\RP588\A0097656.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B75888F9-2B98-4DC1-995A-5391B5AF2989}\RP591\A0100024.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B75888F9-2B98-4DC1-995A-5391B5AF2989}\RP591\A0100075.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\WINDOWS\system32\__delete_on_reboot__d_v_d_p_l_a_y_._d_l_l_ -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\WINDOWS\system32\agzp.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\WINDOWS\system32\fmohksz.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\WINDOWS\system32\imwijz.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B75888F9-2B98-4DC1-995A-5391B5AF2989}\RP556\A0089341.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B75888F9-2B98-4DC1-995A-5391B5AF2989}\RP581\A0094139.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B75888F9-2B98-4DC1-995A-5391B5AF2989}\RP586\A0097535.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B75888F9-2B98-4DC1-995A-5391B5AF2989}\RP588\A0097731.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B75888F9-2B98-4DC1-995A-5391B5AF2989}\RP591\A0100020.exe -> Trojan.Small : Cleaned with backup (quarantined).
::Report end