Hello Scot
Always good to hear from you. Apology not necessary for I believe you have other urgent and important matters to attend to than just getting rid of a few miserable bugs from my pc!!
I managed to uninstall all older versions of java except one as its uninst.isu is missing. If I can still install the newer version without adverse effect, I can live with it remaining in the control panel unless you can suggest something.
"yangyq" - 2007-07-26 14:06:09 - ComboFix 07-07-14.6 - Service Pack 2 NTFS
Command switches used :: C:\Documents and Settings\yangyq\Desktop\CFScript.txt
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\!KillBox
C:\!KillBox\Logs\kb.log
C:\Documents and Settings\yangyq\Cookies\yangyq@com[1].txt
C:\QooBox . . . . failed to delete
C:\QooBox\Quarantine . . . . failed to delete
((((((((((((((((((((((((( Files Created from 2007-06-26 to 2007-07-26 )))))))))))))))))))))))))))))))
2007-07-26 13:51 55,808 ——— C:\WINDOWS\system32\ActPanel.dll
2007-07-23 16:15 91,856 –a—— C:\WINDOWS\system32\S32EVNT1.DLL
2007-07-23 16:15 123,488 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-07-23 16:14 d——– C:\Program Files\Symantec
2007-07-23 16:13 d——– C:\Program Files\Symantec AntiVirus
2007-07-23 16:13 d——– C:\Program Files\Common Files\Symantec Shared
2007-07-23 16:13 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
2007-07-22 18:29 2,829 –a—— C:\WINDOWS\War3Unin.pif
2007-07-22 18:29 16,120 –a—— C:\WINDOWS\War3Unin.dat
2007-07-22 18:29 126,976 –a—— C:\WINDOWS\War3Unin.exe
2007-07-21 14:38 d——– C:\game
2007-07-20 23:05 8,576 –a—— C:\WINDOWS\system32\drivers\pgubnabnfdjx.sys
2007-07-18 22:56 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\MailFrontier
2007-07-18 22:55 75,932 –a—— C:\WINDOWS\system32\drivers\klick.dat
2007-07-18 22:55 75,248 –a—— C:\WINDOWS\zllsputility.exe
2007-07-18 22:55 74,396 –a—— C:\WINDOWS\system32\drivers\klin.dat
2007-07-18 22:55 110,360 –a—— C:\WINDOWS\system32\drivers\kl1.sys
2007-07-18 22:55 1,966,112 –ahs—- C:\WINDOWS\system32\drivers\fidbox.dat
2007-07-18 22:54 1,086,952 –a—— C:\WINDOWS\system32\zpeng24.dll
2007-07-18 22:54 d——– C:\WINDOWS\system32\ZoneLabs
2007-07-18 21:48 d——– C:\Program Files\Trend Micro
2007-07-17 23:34 34 —hs—- C:\Program Files\DLD.DAT
2007-07-15 21:35 26,112 –a—— C:\WINDOWS\system32\nircmd.exe
2007-07-15 18:53 drahs—- C:\autorun.inf
2007-07-14 20:22 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-14 20:19 d——– C:\Deckard
2007-07-13 22:32 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\fssg
2007-07-10 18:54 d——– C:\WINDOWS\system32\ActiveScan
2007-07-10 17:27 d——– C:\DOCUME~1\yangyq\APPLIC~1\Skype
2007-07-10 17:23 d——– C:\Program Files\Skype
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-26 06:17:14 24,092 –sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2007-07-26 03:51:58 1,632 —-a-w C:\WINDOWS\system32\d3d8caps.dat
2007-07-24 01:59:29 ——– d–h–w C:\Program Files\InstallShield Installation Information
2007-07-24 01:57:10 ——– d—–w C:\Program Files\Opera 9
2007-07-24 01:56:18 ——– d—–w C:\Program Files\Windows NT
2007-07-18 14:58:01 4,212 —h–w C:\WINDOWS\system32\zllictbl.dat
2007-07-03 11:59:39 ——– d—–w C:\DOCUME~1\yangyq\APPLIC~1\VoipStunt
2007-06-13 12:27:58 ——– d—–w C:\Program Files\Veoh Networks
2007-06-13 12:24:51 ——– d—–w C:\Program Files\DivX
2007-05-16 15:12:02 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-16 13:09:19 1,744 —-a-w C:\WINDOWS\system32\d3d9caps.dat
2007-05-13 14:26:38 1,901 —-a-w C:\WINDOWS\panose.bin
2007-05-12 10:39:34 4,096 —-a-w C:\WINDOWS\d3dx.dat
2007-05-02 01:08:19 2,560 —-a-w C:\WINDOWS\system32\BitCometRes.dll
2005-04-29 09:27:28 1,682 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
2007-03-29 22:31 394816 –a—— C:\Program Files\BitComet\tools\BitCometBHO_1.1.3.28.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 13:30]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-06-21 21:54]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-07-21 11:10]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2005-07-26 10:29]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 20:00]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Spyware Doctor"=
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-07-26 14:19:28
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-26 14:23:32 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-07-26 14:23
C:\ComboFix2.txt … 2007-07-20 08:57
C:\ComboFix3.txt … 2007-07-19 09:33
— E O F —
My antivirus popped up to say I've got 5 files of infostealer.gampass and 2 of trojan.retvorp.
Menk