SUPER Anti Spyware LOG
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 07/16/2007 at 08:02 PM
Application Version : 3.9.1008
Core Rules Database Version : 3259
Trace Rules Database Version: 1270
Scan type : Complete Scan
Total Scan Time : 01:18:27
Memory items scanned : 155
Memory threats detected : 0
Registry items scanned : 4592
Registry threats detected : 5
File items scanned : 33121
File threats detected : 73
Adware.Tracking Cookie
C:\Documents and Settings\Joanne\Cookies\joanne@cgi-bin[2].txt
C:\Documents and Settings\Joanne\Cookies\joanne@ad.zanox[1].txt
C:\Documents and Settings\Joanne\Cookies\joanne@mediaplex[1].txt
C:\Documents and Settings\Joanne\Cookies\joanne@videoegg.adbureau[2].txt
C:\Documents and Settings\Joanne\Cookies\joanne@mediaonenetwork[1].txt
C:\Documents and Settings\Joanne\Cookies\joanne@partypoker[2].txt
C:\Documents and Settings\Joanne\Cookies\joanne@casalemedia[1].txt
C:\Documents and Settings\Joanne\Cookies\joanne@4.adbrite[1].txt
C:\Documents and Settings\Joanne\Cookies\joanne@ads.monster[1].txt
C:\Documents and Settings\Joanne\Cookies\joanne@tradedoubler[1].txt
C:\Documents and Settings\Joanne\Cookies\joanne@ads.glispa[2].txt
C:\Documents and Settings\Joanne\Cookies\joanne@hitbox[1].txt
C:\Documents and Settings\Joanne\Cookies\joanne@a[1].txt
C:\Documents and Settings\Joanne\Cookies\joanne@ad.yieldmanager[2].txt
C:\Documents and Settings\Joanne\Cookies\joanne@media.sensis.com[1].txt
C:\Documents and Settings\Joanne\Cookies\joanne@msnportal.112.2o7[2].txt
C:\Documents and Settings\Joanne\Cookies\joanne@advertising[1].txt
C:\Documents and Settings\Joanne\Cookies\joanne@adbrite[1].txt
C:\Documents and Settings\Joanne\Cookies\joanne@server.iad.liveperson[1].txt
C:\Documents and Settings\Joanne\Cookies\joanne@drivecleaner[1].txt
C:\Documents and Settings\Joanne\Cookies\joanne@adopt.euroclick[2].txt
C:\Documents and Settings\Joanne\Cookies\joanne@bs.serving-sys[2].txt
C:\Documents and Settings\Joanne\Cookies\joanne@tracker.mediatracker.co[2].txt
C:\Documents and Settings\Joanne\Cookies\joanne@cassava[1].txt
C:\Documents and Settings\Joanne\Cookies\joanne@atdmt[2].txt
C:\Documents and Settings\Joanne\Cookies\joanne@sensismediasmart.com[1].txt
C:\Documents and Settings\Joanne\Cookies\joanne@acvs.mediaonenetwork[2].txt
C:\Documents and Settings\Joanne\Cookies\joanne@stats1.reliablestats[1].txt
C:\Documents and Settings\Joanne\Cookies\joanne@adinterax[2].txt
C:\Documents and Settings\Joanne\Cookies\joanne@doubleclick[1].txt
C:\Documents and Settings\Joanne\Cookies\joanne@[1].txt
C:\Documents and Settings\Joanne\Cookies\joanne@2o7[2].txt
C:\Documents and Settings\Joanne\Cookies\joanne@www.winantiviruspro[1].txt
C:\Documents and Settings\Joanne\Cookies\joanne@statse.webtrendslive[1].txt
C:\Documents and Settings\Joanne\Cookies\joanne@statcounter[2].txt
C:\Documents and Settings\Joanne\Cookies\joanne@e-2dj6wjloejcpkkq.stats.esomniture[2].txt
C:\Documents and Settings\Joanne\Cookies\joanne@gemoney.112.2o7[1].txt
C:\Documents and Settings\Joanne\Cookies\joanne@winantivirus[1].txt
C:\Documents and Settings\Joanne\Cookies\joanne@e-2dj6wfl4ondjwap.stats.esomniture[2].txt
C:\Documents and Settings\Joanne\Cookies\joanne@partygaming.122.2o7[1].txt
C:\Documents and Settings\Joanne\Cookies\joanne@www.etracker.com[2].txt
C:\Documents and Settings\Joanne\Cookies\joanne@fastclick[2].txt
C:\Documents and Settings\Joanne\Cookies\joanne@e-2dj6waliwmdzeeq.stats.esomniture[1].txt
C:\Documents and Settings\Joanne\Cookies\joanne@hc2.humanclick[1].txt
C:\Documents and Settings\Joanne\Cookies\joanne@ehg-starcomworldwide.hitbox[1].txt
C:\Documents and Settings\Joanne\Cookies\joanne@www.winantispyware[2].txt
C:\Documents and Settings\Joanne\Cookies\joanne@888[1].txt
C:\Documents and Settings\Joanne\Cookies\joanne@56081914[2].txt
C:\Documents and Settings\Joanne\Cookies\joanne@overture[2].txt
C:\Documents and Settings\Joanne\Cookies\joanne@1069428106[1].txt
C:\Documents and Settings\Joanne\Cookies\joanne@www.ezytrack[2].txt
C:\Documents and Settings\Joanne\Cookies\joanne@20206613[2].txt
C:\Documents and Settings\Joanne\Cookies\joanne@www.amaena[2].txt
C:\Documents and Settings\Joanne\Cookies\joanne@winantispyware[3].txt
C:\Documents and Settings\Joanne\Cookies\joanne@cpvfeed[2].txt
C:\Documents and Settings\Joanne\Cookies\joanne@serving-sys[1].txt
C:\Documents and Settings\Joanne\Cookies\joanne@pamedia.com[1].txt
C:\Documents and Settings\Joanne\Cookies\joanne@virginmoneyaustralia.122.2o7[1].txt
C:\Documents and Settings\Joanne\Cookies\joanne@realmedia[1].txt
C:\Documents and Settings\Joanne\Cookies\joanne@clicksector[2].txt
C:\Documents and Settings\Joanne\Cookies\joanne@winantispyware[2].txt
C:\Documents and Settings\Ketura\Cookies\ketura@2o7[1].txt
C:\Documents and Settings\Ketura\Cookies\ketura@ad.yieldmanager[2].txt
C:\Documents and Settings\Ketura\Cookies\ketura@atdmt[2].txt
C:\Documents and Settings\Ketura\Cookies\ketura@doubleclick[1].txt
C:\Documents and Settings\Ketura\Cookies\ketura@drivecleaner[2].txt
C:\Documents and Settings\Ketura\Cookies\ketura@fastclick[1].txt
C:\Documents and Settings\Ketura\Cookies\ketura@media.fastclick[2].txt
C:\Documents and Settings\Ketura\Cookies\ketura@msnportal.112.2o7[1].txt
C:\Documents and Settings\Ketura\Cookies\ketura@msnprod.oberon-media[1].txt
C:\Documents and Settings\Ketura\Cookies\ketura@questionmarket[2].txt
Adware.ClickSpring/Yazzle
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yazzle1122Oin
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yazzle1122Oin#DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yazzle1122Oin#UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yazzle1122Oin#HelpLink
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yazzle1122Oin#Publisher
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\COMMON FILES\YAZZLE1122OINUNINSTALLER.EXE.VIR
Unclassified.PC MightyMax
C:\DOCUMENTS AND SETTINGS\ALL USERS\DOCUMENTS\JOANNES STUFF\JOANNE\SECURITY AND PROGRAMS\PCMIGHTYMAXSETUP.EXE
------------------------------------------------------------------------------------------------------------------
COMBO Fix LOG
"Joanne" - 2007-07-16 20:16:50 - ComboFix 07-07-14.3 - Service Pack 2 NTFS
((((((((((((((((((((((((( Files Created from 2007-06-16 to 2007-07-16 )))))))))))))))))))))))))))))))
2007-07-16 18:32 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-07-16 18:32 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-07-16 18:32 <DIR> d-------- C:\DOCUME~1\Joanne\APPLIC~1\SUPERAntiSpyware.com
2007-07-16 18:32 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-07-16 14:19 <DIR> d-------- C:\DOCUME~1\Ketura\APPLIC~1\NCH Swift Sound
2007-07-14 14:30 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-13 23:43 <DIR> d-------- C:\Program Files\Synonyms and Antonyms
2007-07-10 19:16 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2007-07-10 19:16 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2007-07-10 00:41 <DIR> d-------- C:\Program Files\SymNetDrv
2007-07-10 00:38 79 --a------ C:\WINDOWS\delay.reg
2007-07-09 19:11 <DIR> d-------- C:\Program Files\Norton Internet Security
2007-07-09 19:10 <DIR> d-------- C:\DOCUME~1\Joanne\APPLIC~1\Symantec
2007-07-09 19:09 91,904 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2007-07-09 19:09 124,016 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-07-09 19:08 <DIR> d-------- C:\Program Files\Symantec
2007-07-09 19:07 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2007-07-09 19:07 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
2007-07-09 18:39 167 --a------ C:\DOCUME~1\Joanne\8103.bat
2007-07-08 19:59 167 --a------ C:\DOCUME~1\Joanne\6996.bat
2007-07-08 15:58 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2007-07-08 14:19 167 --a------ C:\DOCUME~1\Joanne\3333.bat
2007-07-07 12:25 167 --a------ C:\DOCUME~1\Joanne\2347.bat
2007-07-06 19:25 167 --a------ C:\DOCUME~1\Joanne\4725.bat
2007-07-06 12:33 167 --a------ C:\DOCUME~1\Joanne\8940.bat
2007-07-06 00:01 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-07-06 00:01 <DIR> d-------- C:\WINDOWS\system32\PreInstall
2007-07-05 23:05 <DIR> d-------- C:\WINDOWS\system32\SoftwareDistribution
2007-07-05 22:57 <DIR> d---s---- C:\DOCUME~1\Joanne\UserData
2007-07-05 22:49 167 --a------ C:\DOCUME~1\Joanne\4632.bat
2007-07-05 12:49 167 --a------ C:\DOCUME~1\Joanne\4944.bat
2007-07-05 12:36 167 --a------ C:\DOCUME~1\Joanne\5079.bat
2007-07-04 22:49 167 --a------ C:\DOCUME~1\Joanne\2809.bat
2007-07-04 22:46 <DIR> d-------- C:\WINDOWS\system32\QuickTime
2007-07-04 22:46 <DIR> d-------- C:\Program Files\QuickTime
2007-07-04 22:46 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\QuickTime
2007-07-04 22:45 <DIR> d-------- C:\Program Files\eMedia Starter Guitar Lessons
2007-07-04 21:59 2,560 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-07-04 21:59 2,432 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-07-04 21:59 <DIR> d-------- C:\Program Files\Picasa2
2007-07-04 21:59 <DIR> d-------- C:\Program Files\Google
2007-07-04 21:58 <DIR> d-------- C:\Program Files\Photo To Sketch
2007-07-04 21:58 <DIR> d-------- C:\Program Files\NCH Swift Sound
2007-07-04 21:58 <DIR> d-------- C:\DOCUME~1\Joanne\APPLIC~1\NCH Swift Sound
2007-07-04 21:54 167 --a------ C:\DOCUME~1\Joanne\1934.bat
2007-07-04 20:55 141 --a------ C:\DOCUME~1\Ketura\3090.bat
2007-07-04 17:52 25,600 --a------ C:\WINDOWS\system32\drivers\usbser.sys
2007-07-04 17:45 <DIR> d-------- C:\DOCUME~1\Joanne\APPLIC~1\Help
2007-07-04 17:14 147,456 --a------ C:\WINDOWS\system32\vbzip10.dll
2007-07-04 16:47 <DIR> d-------- C:\DOCUME~1\Joanne\APPLIC~1\WinRAR
2007-07-04 16:33 <DIR> d--hs---- C:\DOCUME~1\Joanne\Complete
2007-07-04 15:32 <DIR> d-------- C:\WINDOWS\pss
2007-07-04 10:43 <DIR> d-------- C:\DOCUME~1\Ketura\Incomplete
2007-07-04 10:42 <DIR> d-------- C:\DOCUME~1\Ketura\APPLIC~1\LimeWire
2007-07-04 02:54 0 --a------ C:\WINDOWS\system32\taskkill.exe
2007-07-04 02:39 <DIR> d-------- C:\DOCUME~1\Joanne\Shared
2007-07-04 02:39 <DIR> d-------- C:\DOCUME~1\Joanne\Incomplete
2007-07-04 02:37 <DIR> d-------- C:\Program Files\LimeWire
2007-07-04 02:25 <DIR> d-------- C:\DOCUME~1\Joanne\.limewire
2007-07-03 22:37 <DIR> d-------- C:\etax2007
2007-07-03 19:40 <DIR> d-------- C:\DOCUME~1\Ketura\APPLIC~1\Talkback
2007-07-03 02:20 82,944 --a------ C:\WINDOWS\system32\drivers\wdmaud.sys
2007-07-03 02:20 7,552 --a------ C:\WINDOWS\system32\drivers\MSKSSRV.sys
2007-07-03 02:20 60,800 --a------ C:\WINDOWS\system32\drivers\sysaudio.sys
2007-07-03 02:20 54,272 --a------ C:\WINDOWS\system32\drivers\swmidi.sys
2007-07-03 02:20 52,864 --a------ C:\WINDOWS\system32\drivers\DMusic.sys
2007-07-03 02:20 5,376 --a------ C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2007-07-03 02:20 2,944 --a------ C:\WINDOWS\system32\drivers\drmkaud.sys
2007-07-03 02:20 172,416 --a------ C:\WINDOWS\system32\drivers\kmixer.sys
2007-07-03 02:20 142,464 --a------ C:\WINDOWS\system32\drivers\aec.sys
2007-07-03 02:19 6,400 --a------ C:\WINDOWS\system32\drivers\splitter.sys
2007-07-03 02:19 4,992 --a------ C:\WINDOWS\system32\drivers\MSPQM.sys
2007-07-03 02:19 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys
2007-07-03 02:19 27,164 --a------ C:\WINDOWS\system32\drivers\CE3N5.SYS
2007-07-03 02:18 870,784 --a------ C:\WINDOWS\system32\ati3d1ag.dll
2007-07-03 02:18 701,440 --a------ C:\WINDOWS\system32\drivers\ati2mtag.sys
2007-07-03 02:18 57,472 --a------ C:\WINDOWS\system32\drivers\redbook.sys
2007-07-03 02:18 516,768 --a------ C:\WINDOWS\system32\ativvaxx.dll
2007-07-03 02:18 229,376 --a------ C:\WINDOWS\system32\ati2cqag.dll
2007-07-03 02:18 201,728 --a------ C:\WINDOWS\system32\ati2dvag.dll
2007-07-03 02:18 1,888,992 --a------ C:\WINDOWS\system32\ati3duag.dll
2007-07-03 02:17 96,256 --a------ C:\WINDOWS\system32\drivers\ac97intc.sys
2007-07-03 02:17 9,344 --a------ C:\WINDOWS\system32\drivers\compbatt.sys
2007-07-03 02:17 74,240 --a------ C:\WINDOWS\system32\usbui.dll
2007-07-03 02:17 60,288 --a------ C:\WINDOWS\system32\drivers\drmk.sys
2007-07-03 02:17 42,368 --a------ C:\WINDOWS\system32\drivers\AGP440.SYS
2007-07-03 02:17 4,096 --a------ C:\WINDOWS\system32\ksuser.dll
2007-07-03 02:17 145,792 --a------ C:\WINDOWS\system32\drivers\portcls.sys
2007-07-03 02:17 14,080 --a------ C:\WINDOWS\system32\drivers\CmBatt.sys
2007-07-03 02:17 14,080 --a------ C:\WINDOWS\system32\drivers\battc.sys
2007-07-03 02:15 9,936 --a------ C:\WINDOWS\system\LZEXPAND.DLL
2007-07-03 02:15 9,008 --a------ C:\WINDOWS\system\VER.DLL
2007-07-03 02:15 85,020 --a------ C:\WINDOWS\system32\dgsetup.dll
2007-07-03 02:15 82,944 --a------ C:\WINDOWS\system\OLECLI.DLL
2007-07-03 02:15 8,704 --a------ C:\WINDOWS\system32\batt.dll
2007-07-03 02:15 8,192 -ra------ C:\WINDOWS\system32\kbdhept.dll
2007-07-03 02:15 74,752 --a------ C:\WINDOWS\system32\storprop.dll
2007-07-03 02:15 7,168 -ra------ C:\WINDOWS\system32\kbdcz.dll
2007-07-03 02:15 69,584 --a------ C:\WINDOWS\system\AVICAP.DLL
2007-07-03 02:15 69,120 --a------ C:\WINDOWS\NOTEPAD.EXE
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-16 12:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-16 12:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2001-04-16 16:39 37808 --------- C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2007-03-14 03:43 501400 --a------ C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9ECB9560-04F9-4bbc-943D-298DDF1699E1}]
2004-08-31 10:29 103568 --a------ C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BDF3E430-B101-42AD-A544-FADC6B084872}]
2005-01-10 12:20 218736 --a------ C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 17:32]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PowerBar"="" []
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-14 02:24]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-06-11 18:16]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:54]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-28 22:00]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"="C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 13:55]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll --a------ 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
C:\Program Files\Ahead\InCD\InCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\msnmsgr.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCTVOICE]
pctspk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"gusvc"=3 (0x3)
"InCDsrv"=2 (0x2)
"WZCSVC"=2 (0x2)
"Themes"=2 (0x2)
"Netlogon"=3 (0x3)
"ISSVC"=2 (0x2)
"ImapiService"=3 (0x3)
"HTTPFilter"=3 (0x3)
"helpsvc"=2 (0x2)
"FastUserSwitchingCompatibility"=3 (0x3)
"COMSysApp"=3 (0x3)
"CiSvc"=3 (0x3)
"AudioSrv"=2 (0x2)
"SPBBCSvc"=2 (0x2)
"SNDSrvc"=2 (0x2)
"ose"=3 (0x3)
Contents of the 'Scheduled Tasks' folder
2007-07-13 10:05:46 C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer - Joanne.job
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-07-16 20:19:23
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
PowerBar = ?W?????????????????????????????????????????????????????????????|p??|????m??|?`?w????????PW????@?8?@?????PW??c"?s???s??????@?????N'?s?W2?L|?s????????????u??s????????c"?s???s??????@?8?@?N'?s${2??$@?8?@?8?@?????????0{2?`C2????s???s W2??C2?`C2?0i?s?????????W2????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-16 20:20:37
C:\ComboFix-quarantined-files.txt ... 2007-07-16 20:20
C:\ComboFix2.txt ... 2007-07-14 18:07
C:\ComboFix3.txt ... 2007-07-14 14:37
--- E O F ---
------------------------------------------------------------------------------------------------------------------
HJT LOG
Logfile of HijackThis v1.99.1
Scan saved at 9:09:55 PM, on 7/16/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Common Files\Symantec Shared\AdBlocking\NSMdtr.exe
C:\Documents and Settings\Joanne\My Documents\My Downloads\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://au.yahoo.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{37C62339-655F-4570-A7BC-1A5B193A7DFE}: NameServer = 203.134.12.90 203.134.102.90
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe