OK, heres the combofix log...
MIKE - 06-09-04 12:59:50.14
ComboFix 06.09.04BT - Running from: C:\Documents and Settings\MIKE\Desktop
Microsoft Windows XP [Version 5.1.2600]
((((((((((((((((((((((((((((((((((((((((((( E-Give / Ssk's Log )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\repairs303169584.dll
C:\Documents and Settings\DUSTY\Application Data\Sskknwrd.dll
C:\Documents and Settings\MIKE\Application Data\Sskknwrd.dll
C:\Documents and Settings\TINA\Application Data\Sskknwrd.dll
C:\Program Files\surfsidekick 3\Ssk.exe
C:\Program Files\surfsidekick 3\SskBho.dll
C:\Program Files\surfsidekick 3\SskCore.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\cfg32.exe
C:\Program Files\Common Files\services.exe
C:\WINDOWS\system32\tpuninstall.exe
C:\WINDOWS\system32\tsuninst.exe
C:\WINDOWS\uni_ehhh.exe
C:\Program Files\Common Files\mc-58-12-0000106.exe
C:\Program Files\Common Files\misc001
C:\Program Files\Common Files\simtest
C:\Program Files\Common Files\svchostsys
C:\Program Files\DNS
C:\Program Files\Inetget2
C:\Program Files\TClock
C:\Program Files\windows
C:\Program Files\Ipwins
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\QooBox\Purity\Documents and Settings\MIKE\Application Data\FNTS~1
C:\QooBox\Purity\Documents and Settings\MIKE\Application Data\ICROSO~1
C:\QooBox\Purity\Documents and Settings\MIKE\Application Data\PPPATC~1
C:\QooBox\Purity\Documents and Settings\MIKE\Application Data\SMBOLS~1
C:\QooBox\Purity\Program Files\FNTS~1
C:\QooBox\Purity\Program Files\SCURIT~1
C:\QooBox\Purity\Program Files\YSTEM3~1
C:\QooBox\Purity\Program Files\Common Files\CROSOF~1
C:\QooBox\Purity\Program Files\Common Files\CROSOF~1.NET
C:\QooBox\Purity\Program Files\Common Files\ECURIT~1
C:\QooBox\Purity\Program Files\Common Files\FNTS~1
C:\QooBox\Purity\Program Files\Common Files\MBOLS~1
C:\QooBox\Purity\Program Files\Common Files\RACLE~1
C:\QooBox\Purity\Program Files\Common Files\SEMBLY~1
C:\QooBox\Purity\Program Files\Common Files\SKS~1
C:\QooBox\Purity\Program Files\Common Files\SMBOLS~1
C:\QooBox\Purity\Program Files\Common Files\YMBOLS~1
C:\QooBox\Purity\WINDOWS\ICROSO~1.NET
C:\QooBox\Purity\WINDOWS\SSEMBL~1
((((((((((((((((((((((((((((((( Files Created from 2006-08-04 to 2006-09-04 ))))))))))))))))))))))))))))))))))
No new files created in this timespan
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) )))
2006-09-04 13:02 -------- d-a------ C:\Program Files\Common Files
2006-09-03 17:26 -------- d-------- C:\Program Files\ewido anti-spyware 4.0
2006-09-03 17:25 -------- d-------- C:\Program Files\PrintView
2006-09-03 17:25 -------- d-------- C:\Program Files\Acceleration Software
2006-09-02 23:26 -------- d-------- C:\Program Files\Ventrilo
2006-09-02 01:52 -------- d-------- C:\Program Files\Movie Maker
2006-08-31 10:33 -------- d-------- C:\Program Files\Weather
2006-08-31 00:29 -------- d-------- C:\Program Files\AIM
2006-08-30 15:15 -------- d-------- C:\Program Files\PC Tools AntiVirus
2006-08-30 14:48 -------- d-------- C:\Program Files\WinRAR
2006-08-29 16:02 -------- d-------- C:\Program Files\Mp3wavstudio
2006-08-28 18:34 -------- d-------- C:\Program Files\mIRC
2006-08-28 12:44 -------- d-------- C:\Program Files\audio-mp3-converter
2006-08-28 09:40 -------- d-------- C:\Program Files\Teamspeak2_RC2
2006-08-27 22:10 350 --a------ C:\WINDOWS\gfoga.dll
2006-08-26 21:15 -------- d-------- C:\Program Files\America's Army
2006-08-26 12:00 -------- d-------- C:\Program Files\Adobe
2006-08-26 10:16 -------- d-------- C:\Program Files\HammerHead
2006-08-25 09:12 -------- d-------- C:\Program Files\MSN
2006-08-24 13:12 -------- d-------- C:\Program Files\Messenger
2006-08-24 11:14 -------- d-------- C:\Program Files\GameSpy Arcade
2006-08-23 15:51 -------- d-------- C:\Program Files\Wolfenstein - Enemy Territory
2006-08-22 00:44 -------- d-------- C:\Program Files\AimOne_AlltoMP3
2006-08-21 14:06 -------- d-------- C:\Program Files\Winamp
2006-08-18 14:02 -------- d-------- C:\Program Files\Unitebar
2006-08-17 13:00 -------- d-------- C:\Program Files\Common Files\Softwin
2006-08-15 19:18 -------- d-------- C:\Program Files\Common Files\eAcceleration
2006-08-15 19:14 -------- d-------- C:\Program Files\MSN Gaming Zone
2006-08-15 10:38 -------- d-------- C:\Program Files\AOD
2006-08-15 08:43 -------- d-------- C:\Program Files\Microsoft ActiveSync
2006-08-10 23:05 -------- d-------- C:\Program Files\EQArticle
2006-08-10 15:58 -------- d--h----- C:\Program Files\WindowsUpdate
2006-08-10 11:31 -------- d-------- C:\Program Files\Mozilla Firefox
2006-08-08 15:56 -------- d-------- C:\Program Files\Online Services
2006-08-06 10:43 -------- d-------- C:\Program Files\Outlook Express
2006-08-04 13:39 -------- d-------- C:\Program Files\Google
2006-08-03 19:20 342636 ---hs---- C:\Program Files\Common Files\FIELD_AFFID.exe
2006-08-02 15:28 -------- d-------- C:\Program Files\GameHouse
2006-08-01 23:02 -------- d-------- C:\Program Files\Windows NT
2006-07-31 12:24 -------- d-------- C:\Program Files\WAV to MP3 Encoder
2006-07-31 09:49 -------- d-------- C:\Program Files\BAB.stats
2006-07-27 18:32 -------- d-------- C:\Program Files\Browser MOUSE
2006-07-27 09:24 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-07-21 13:11 -------- d-------- C:\Program Files\Hasbro Interactive
2006-07-21 13:09 -------- d-------- C:\Program Files\Starcraft
2006-07-21 04:24 72704 --a------ C:\WINDOWS\system32\hlink.dll
2006-07-18 19:01 32208 ---hs---- C:\Program Files\Common Files\Y1304OU.exe
2006-07-18 19:01 234248 -rah----- C:\WINDOWS\Tagasuarus2.exe
2006-07-18 19:01 183887 -rah----- C:\WINDOWS\YazzleBundle-1304.exe
2006-07-17 22:15 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-07-17 22:15 -------- d-------- C:\Program Files\EA GAMES
2006-07-05 15:46 -------- d-------- C:\Program Files\EQBranch
2006-07-04 20:53 -------- d-------- C:\Program Files\MSN Messenger
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"RoxioEngineUtility"="\"C:\\Program Files\\Common Files\\Roxio Shared\\System\\EngUtil.exe\""
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_05\\bin\\jusched.exe"
"ViewMgr"="C:\\Program Files\\Viewpoint\\Viewpoint Manager\\ViewMgr.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"lhgwwir"="c:\\windows\\system32\\lhgwwir.exe"
"MoodLogic Updater"="C:\\Program Files\\MoodLogic\\Service\\Updater.exe"
"Dinst"="C:\\WINDOWS\\dinst.exe"
"qpyrjskA"="C:\\WINDOWS\\qpyrjskA.exe"
"FLMOFFICE4DMOUSE"="C:\\Program Files\\Browser MOUSE\\mouse32a.exe"
"necexkb"="C:\\WINDOWS\\system32\\kayzcb.exe r"
"Mchrbb"="C:\\Program Files\\Ourvc\\Yucccw.exe"
"xij"="C:\\WINDOWS\\xij.exe"
"dykgxkczuzv"="C:\\WINDOWS\\System32\\lhgwwir. exe"
"w0e987df.dll"="RUNDLL32.EXE w0e987df.dll,I2 000ebe2d00e987df"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"ftexc"="C:\\WINDOWS\\system32\\mptft.exe"
"!ewido"="\"C:\\Program Files\\ewido anti-spyware 4.0\\ewido.exe\" /minimized"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\OptionalComponents]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.ex e"
"Pvn"="C:\\WINDOWS\\system32\\d?dplay.exe"
"EQTraffic"="\"C:\\Program Files\\EQTraffic\\EQTraffic.exe\""
"Csan"="\"C:\\DOCUME~1\\MIKE\\MYDOCU~1\\FNTS~1\\ar pa.exe\" -vt yazr"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NVMCTRAY.DLL,NvTaskbarInit"
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"blaadm"="C:\\WINDOWS\\system32\\blaadm.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\policies\explorer\Run]
"blaadm"="C:\\WINDOWS\\system32\\blaadm.exe"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000000
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="C:\\Program Files\\Online Services\\howyvyka.html"
"SubscribedURL"=""
"FriendlyName"=""
"Flags"=dword:00002000
"Position"=hex:2c,00,00,00,64,00,00,00,64,00,00,00 ,58,02,00,00,c8,00,00,00,e8,\
03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00 ,00,00,14,00,00,00
"CurrentState"=dword:40000001
"OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64 ,00,00,00,58,02,00,00,c8,00,\
00,00,01,00,00,00
"RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\1]
"Source"="\\"
"SubscribedURL"=""
"FriendlyName"=""
"Flags"=dword:00002000
"Position"=hex:2c,00,00,00,64,00,00,00,64,00,00,00 ,58,02,00,00,c8,00,00,00,ea,\
03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00 ,00,00,14,00,00,00
"CurrentState"=dword:40000001
"OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64 ,00,00,00,58,02,00,00,c8,00,\
00,00,01,00,00,00
"RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\2]
"Source"="C:\\WINDOWS\\system32\\ad.html"
"SubscribedURL"=""
"FriendlyName"=""
"Flags"=dword:00002000
"Position"=hex:2c,00,00,00,64,00,00,00,64,00,00,00 ,58,02,00,00,c8,00,00,00,ec,\
03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00 ,00,00,14,00,00,00
"CurrentState"=dword:40000001
"OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64 ,00,00,00,58,02,00,00,c8,00,\
00,00,01,00,00,00
"RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\3]
"Source"="about:Home"
"SubscribedURL"="about:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,a0,00,00,00,00,00,00,00 ,80,02,00,00,3a,02,00,00,ee,\
03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00 ,00,00,00,00,00,00
"CurrentState"=dword:40000004
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff ,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23 ,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\Cur rentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"CDRAutoRun"=dword:00000000
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\Cur rentVersion\policies\explorer\Run]
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\polic ies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"CDRAutoRun"=dword:00000000
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\polic ies\explorer\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{F2A0229A-C4CA-4789-B606-973D24DCDD1C}"="McAfee AntiSpyware Shell Extension"
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\BDMCon]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersio n\\Run"
"item"="bdmcon"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\Softwin\\BITDEF~1\\bdmcon .exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\BDNewsAgent]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersio n\\Run"
"item"="bdnagent"
"hkey"="HKLM"
"command"="\"C:\\PROGRA~1\\Softwin\\BITDEF~1\\bdna gent.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\BDOESRV]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersio n\\Run"
"item"="bdoesrv"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Softwin\\BitDefender9\\bdoesrv.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\BDSwitchAgent]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersio n\\Run"
"item"="bdswitch"
"hkey"="HKLM"
"command"="\"C:\\PROGRA~1\\Softwin\\BITDEF~1\\bdsw itch.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\MCAgentExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersio n\\Run"
"item"="mcagent"
"hkey"="HKLM"
"command"="c:\\PROGRA~1\\mcafee.com\\agent\\mcagen t.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\McRegWiz]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersio n\\Run"
"item"="McRegWiz"
"hkey"="HKLM"
"command"="C:\\Program Files\\McAfee.com\\Agent\\McRegWiz.exe /autorun"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\MCUpdateExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersio n\\Run"
"item"="mcupdate"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\mcafee.com\\agent\\mcupda te.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\StopSignSsTsMon]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersio n\\Run"
"item"="sstsmon0"
"hkey"="HKLM"
"command"="Rundll32.exe \"C:\\Program Files\\Acceleration Software\\Anti-Virus\\sstsmon0.dll\",VerifyStatus"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\SurfSideKick 3]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersio n\\Run"
"item"="Ssk"
"hkey"="HKLM"
"command"="C:\\Program Files\\SurfSideKick 3\\Ssk.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\VirusScan Online]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersio n\\Run"
"item"="mcvsshld"
"hkey"="HKLM"
"command"="\"c:\\PROGRA~1\\mcafee.com\\vso\\mcvssh ld.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\VSOCheckTask]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersio n\\Run"
"item"="mcmnhdlr"
"hkey"="HKLM"
"command"="\"c:\\PROGRA~1\\mcafee.com\\vso\\mcmnhd lr.exe\" /checktask"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\webscan]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersio n\\Run"
"item"="stopsignav"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Acceleration Software\\Anti-Virus\\stopsignav.exe\" -k"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\_AntiSpyware]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersio n\\Run"
"item"="MssCli"
"hkey"="HKLM"
"command"="C:\\Program Files\\McAfee\\McAfee AntiSpyware\\MssCli.exe"
"inimapping"="0"
Completion time: Mon 09/04/2006 13:06:55.00
ComboFix.txt
moving on to AproposFix
|