Contd...
SUPERA
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 06/04/2007 at 09:21 PM
Application Version : 3.8.1002
Core Rules Database Version : 3249
Trace Rules Database Version: 1260
Scan type : Complete Scan
Total Scan Time : 02:24:09
Memory items scanned : 346
Memory threats detected : 0
Registry items scanned : 3995
Registry threats detected : 0
File items scanned : 112660
File threats detected : 147
Adware.Tracking Cookie
C:\Documents and Settings\Owner.TAVSCOMP\Cookies\owner@edge.ru4[1].txt
C:\Documents and Settings\Owner.TAVSCOMP\Cookies\owner@advertising[1].txt
C:\Documents and Settings\Owner.TAVSCOMP\Cookies\owner@ads.adbrite[2].txt
C:\Documents and Settings\Owner.TAVSCOMP\Cookies\owner@tribalfusion[1].txt
C:\Documents and Settings\Owner.TAVSCOMP\Cookies\owner@2o7[1].txt
C:\Documents and Settings\Owner.TAVSCOMP\Cookies\owner@atdmt[1].txt
C:\Documents and Settings\Owner.TAVSCOMP\Cookies\owner@adbrite[1].txt
C:\Documents and Settings\Owner.TAVSCOMP\Cookies\owner@atwola[1].txt
C:\Documents and Settings\Owner.TAVSCOMP\Cookies\owner@doubleclick[1].txt
C:\Documents and Settings\Default User\Cookies\owner@4.adbrite[1].txt
C:\Documents and Settings\Default User\Cookies\owner@ad.bannerconnect[2].txt
C:\Documents and Settings\Default User\Cookies\owner@ad.iconadserver[2].txt
C:\Documents and Settings\Default User\Cookies\owner@ad.yieldmanager[1].txt
C:\Documents and Settings\Default User\Cookies\owner@adbrite[1].txt
C:\Documents and Settings\Default User\Cookies\owner@adopt.specificclick[2].txt
C:\Documents and Settings\Default User\Cookies\owner@adrevolver[1].txt
C:\Documents and Settings\Default User\Cookies\owner@adrevolver[2].txt
C:\Documents and Settings\Default User\Cookies\owner@ads.adbrite[2].txt
C:\Documents and Settings\Default User\Cookies\owner@ads.pointroll[1].txt
C:\Documents and Settings\Default User\Cookies\owner@adserver.easyad[2].txt
C:\Documents and Settings\Default User\Cookies\owner@advertising[1].txt
C:\Documents and Settings\Default User\Cookies\owner@atdmt[2].txt
C:\Documents and Settings\Default User\Cookies\owner@burstnet[1].txt
C:\Documents and Settings\Default User\Cookies\owner@casalemedia[2].txt
C:\Documents and Settings\Default User\Cookies\owner@clicksor[1].txt
C:\Documents and Settings\Default User\Cookies\owner@cpvfeed[2].txt
C:\Documents and Settings\Default User\Cookies\owner@data3.perf.overture[2].txt
C:\Documents and Settings\Default User\Cookies\owner@doubleclick[1].txt
C:\Documents and Settings\Default User\Cookies\owner@edge.ru4[2].txt
C:\Documents and Settings\Default User\Cookies\owner@ehg-hollywood.hitbox[2].txt
C:\Documents and Settings\Default User\Cookies\owner@fastclick[2].txt
C:\Documents and Settings\Default User\Cookies\owner@fortunecity[1].txt
C:\Documents and Settings\Default User\Cookies\owner@hitbox[2].txt
C:\Documents and Settings\Default User\Cookies\owner@mediaplex[1].txt
C:\Documents and Settings\Default User\Cookies\owner@perf.overture[1].txt
C:\Documents and Settings\Default User\Cookies\owner@questionmarket[1].txt
C:\Documents and Settings\Default User\Cookies\owner@realmedia[1].txt
C:\Documents and Settings\Default User\Cookies\owner@reduxads.valuead[2].txt
C:\Documents and Settings\Default User\Cookies\owner@revsci[1].txt
C:\Documents and Settings\Default User\Cookies\owner@sixapart.adbureau[1].txt
C:\Documents and Settings\Default User\Cookies\owner@statcounter[2].txt
C:\Documents and Settings\Default User\Cookies\owner@stats1.reliablestats[2].txt
C:\Documents and Settings\Default User\Cookies\owner@tacoda[2].txt
C:\Documents and Settings\Default User\Cookies\owner@trafficmp[1].txt
C:\Documents and Settings\Default User\Cookies\owner@tremor.adbureau[2].txt
C:\Documents and Settings\Default User\Cookies\owner@tribalfusion[1].txt
C:\Documents and Settings\Default User\Cookies\owner@winantispyware[2].txt
C:\Documents and Settings\Default User\Cookies\owner@www.burstbeacon[1].txt
C:\Documents and Settings\Default User\Cookies\owner@www.burstnet[1].txt
C:\Documents and Settings\Default User\Cookies\owner@zedo[2].txt
C:\Documents and Settings\Ilia and Barry\Cookies\ilia and
barry@2o7[1].txt
C:\Documents and Settings\Ilia and Barry\Cookies\ilia and
barry@ad.yieldmanager[2].txt
C:\Documents and Settings\Ilia and Barry\Cookies\ilia and
barry@adinterax[2].txt
C:\Documents and Settings\Ilia and Barry\Cookies\ilia and
barry@adopt.euroclick[2].txt
C:\Documents and Settings\Ilia and Barry\Cookies\ilia and
barry@adrevolver[1].txt
C:\Documents and Settings\Ilia and Barry\Cookies\ilia and
barry@adrevolver[2].txt
C:\Documents and Settings\Ilia and Barry\Cookies\ilia and
barry@ads.pointroll[2].txt
C:\Documents and Settings\Ilia and Barry\Cookies\ilia and
barry@advertising[2].txt
C:\Documents and Settings\Ilia and Barry\Cookies\ilia and
barry@atdmt[2].txt
C:\Documents and Settings\Ilia and Barry\Cookies\ilia and
barry@atwola[1].txt
C:\Documents and Settings\Ilia and Barry\Cookies\ilia and
barry@bluestreak[1].txt
C:\Documents and Settings\Ilia and Barry\Cookies\ilia and
barry@bs.serving-sys[1].txt
C:\Documents and Settings\Ilia and Barry\Cookies\ilia and
barry@c5.zedo[1].txt
C:\Documents and Settings\Ilia and Barry\Cookies\ilia and
barry@casalemedia[1].txt
C:\Documents and Settings\Ilia and Barry\Cookies\ilia and
barry@cdn.euroclick[1].txt
C:\Documents and Settings\Ilia and Barry\Cookies\ilia and
barry@citi.bridgetrack[2].txt
C:\Documents and Settings\Ilia and Barry\Cookies\ilia and
barry@doubleclick[1].txt
C:\Documents and Settings\Ilia and Barry\Cookies\ilia and
barry@fastclick[2].txt
C:\Documents and Settings\Ilia and Barry\Cookies\ilia and
barry@mediaplex[2].txt
C:\Documents and Settings\Ilia and Barry\Cookies\ilia and
barry@mediaservices.myspace[1].txt
C:\Documents and Settings\Ilia and Barry\Cookies\ilia and
barry@msnportal.112.2o7[1].txt
C:\Documents and Settings\Ilia and Barry\Cookies\ilia and
barry@perf.overture[1].txt
C:\Documents and Settings\Ilia and Barry\Cookies\ilia and
barry@questionmarket[2].txt
C:\Documents and Settings\Ilia and Barry\Cookies\ilia and
barry@realmedia[1].txt
C:\Documents and Settings\Ilia and Barry\Cookies\ilia and
barry@revsci[1].txt
C:\Documents and Settings\Ilia and Barry\Cookies\ilia and
barry@server.cpmstar[1].txt
C:\Documents and Settings\Ilia and Barry\Cookies\ilia and
barry@serving-sys[1].txt
C:\Documents and Settings\Ilia and Barry\Cookies\ilia and
barry@trafficmp[2].txt
C:\Documents and Settings\Ilia and Barry\Cookies\ilia and
barry@tribalfusion[1].txt
C:\Documents and Settings\Ilia and Barry\Cookies\ilia and
barry@zedo[1].txt
C:\Documents and Settings\Owner\Cookies\owner@4.adbrite[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.bannerconnect[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.iconadserver[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.yieldmanager[1].txt
C:\Documents and Settings\Owner\Cookies\owner@adbrite[1].txt
C:\Documents and Settings\Owner\Cookies\owner@adopt.specificclick[2].txt
C:\Documents and Settings\Owner\Cookies\owner@adrevolver[1].txt
C:\Documents and Settings\Owner\Cookies\owner@adrevolver[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.adbrite[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.pointroll[1].txt
C:\Documents and Settings\Owner\Cookies\owner@adserver.easyad[2].txt
C:\Documents and Settings\Owner\Cookies\owner@advertising[1].txt
C:\Documents and Settings\Owner\Cookies\owner@atdmt[2].txt
C:\Documents and Settings\Owner\Cookies\owner@burstnet[1].txt
C:\Documents and Settings\Owner\Cookies\owner@casalemedia[2].txt
C:\Documents and Settings\Owner\Cookies\owner@clicksor[1].txt
C:\Documents and Settings\Owner\Cookies\owner@cpvfeed[2].txt
C:\Documents and Settings\Owner\Cookies\owner@data3.perf.overture[2].txt
C:\Documents and Settings\Owner\Cookies\owner@doubleclick[1].txt
C:\Documents and Settings\Owner\Cookies\owner@edge.ru4[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ehg-hollywood.hitbox[2].txt
C:\Documents and Settings\Owner\Cookies\owner@fastclick[2].txt
C:\Documents and Settings\Owner\Cookies\owner@fortunecity[1].txt
C:\Documents and Settings\Owner\Cookies\owner@hitbox[2].txt
C:\Documents and Settings\Owner\Cookies\owner@mediaplex[1].txt
C:\Documents and Settings\Owner\Cookies\owner@perf.overture[1].txt
C:\Documents and Settings\Owner\Cookies\owner@questionmarket[1].txt
C:\Documents and Settings\Owner\Cookies\owner@realmedia[1].txt
C:\Documents and Settings\Owner\Cookies\owner@reduxads.valuead[2].txt
C:\Documents and Settings\Owner\Cookies\owner@revsci[1].txt
C:\Documents and Settings\Owner\Cookies\owner@sixapart.adbureau[1].txt
C:\Documents and Settings\Owner\Cookies\owner@statcounter[2].txt
C:\Documents and Settings\Owner\Cookies\owner@stats1.reliablestats[2].txt
C:\Documents and Settings\Owner\Cookies\owner@tacoda[2].txt
C:\Documents and Settings\Owner\Cookies\owner@trafficmp[1].txt
C:\Documents and Settings\Owner\Cookies\owner@tremor.adbureau[2].txt
C:\Documents and Settings\Owner\Cookies\owner@tribalfusion[1].txt
C:\Documents and Settings\Owner\Cookies\owner@winantispyware[2].txt
C:\Documents and Settings\Owner\Cookies\owner@www.burstbeacon[1].txt
C:\Documents and Settings\Owner\Cookies\owner@www.burstnet[1].txt
C:\Documents and Settings\Owner\Cookies\owner@zedo[2].txt
C:\Documents and Settings\Tim Alan.YOUR-SZ6X6SEFXO\Cookies\tim
alan@msnportal.112.2o7[1].txt
TargetSaver, Inc. Process
C:\DOCUMENTS AND SETTINGS\DEFAULT USER\LOCAL SETTINGS\TEMP\TSINSTALL_4_0_4_0_B4.EXE
C:\DOCUMENTS AND SETTINGS\OWNER\LOCAL SETTINGS\TEMP\TSINSTALL_4_0_4_0_B4.EXE
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\TSUNINST.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP7\A0005926.EXE
Trojan.Downloader-Gen/Inst2
C:\DOCUMENTS AND SETTINGS\OWNER\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\FBPNFDGC\VV[1].EXE
C:\WINDOWS\SYSTEM32\T6\DLWR.EXE
Unclassified.Unknown Origin
C:\PROGRAM FILES\COMMON FILES\WQOW\WQOWA.EXE
Adware.Unknown Origin
C:\PROGRAM FILES\COMMON FILES\WQOW\WQOWD\CLASS-BARREL
C:\PROGRAM FILES\COMMON FILES\WQOW\WQOWD\VOCABULARY
Unclassified.Unknown Origin/System
C:\PROGRAM FILES\COMMON FILES\WQOW\WQOWD\WQOWC.DLL
Adware.TargetSavers
C:\PROGRAM FILES\COMMON FILES\WQOW\WQOWP.EXE
Adware.webHancer
C:\PROGRAM FILES\HIJACKTHIS\BACKUPS\BACKUP-20070528-170248-632.DLL
Adware.ClickSpring/Yazzle
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\COMMON FILES\YAZZLE1122OINADMIN.EXE.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\COMMON FILES\YAZZLE1122OINUNINSTALLER.EXE.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\COMMON FILES\YAZZLE1275OINADMIN.EXE.VIR
C:\QOOBOX\QUARANTINE\C\PROGRAM FILES\COMMON FILES\YAZZLE1275OINUNINSTALLER.EXE.VIR
Adware.SearchClickAds
C:\QOOBOX\QUARANTINE\C\WINDOWS\STUB_MMA2.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP6\A0005828.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP6\A0005829.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP7\A0005923.EXE
Trojan.ZQuest-Installer
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\T3\DLLTK67.EXE.VIR
C:\SYSTEM VOLUME INFORMATION\_RESTORE{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP7\A0005925.EXE
Trojan.Downloader-Gen/Installer
C:\WINDOWS\B103.EXE
C:\WINDOWS\B104.EXE
Trojan.Unknown Origin
C:\WINDOWS\B129.EXE
ComboFix
"Owner" - 2007-06-04 18:50:20 Service Pack 1 NTFS
ComboFix 07-06-3 - Running from: "C:\Documents and Settings\Owner.TAVSCOMP\Desktop\"
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files\Common Files\Yazzle1122OinAdmin.exe
C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
C:\Program Files\Common Files\Yazzle1275OinAdmin.exe
C:\Program Files\Common Files\Yazzle1275OinUninstaller.exe
C:\Program Files\inetget2
C:\Program Files\ipwindows
C:\Program Files\ipwindows\UnInstall.exe
C:\Temp\0b9
C:\Temp\0b9\tmpTF.log
C:\WINDOWS\b122.exe
C:\WINDOWS\cs_cache.ini
C:\WINDOWS\stub_mma2.exe
C:\WINDOWS\system32\pog
C:\WINDOWS\system32\T3
C:\WINDOWS\system32\T3\dlltk67.exe
C:\WINDOWS\system32\T4
C:\WINDOWS\system32\tsuninst.exe
C:\WINDOWS\wr.txt
((((((((((((((((((((((((( Files Created from 2007-05-05 to 2007-06-05 )))))))))))))))))))))))))))))))
2007-06-04 18:48 d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-06-04 18:47 d-------- C:\Program Files\SUPERAntiSpyware
2007-06-04 18:47 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-06-04 18:47 d-------- C:\DOCUME~1\OWNER~1.TAV\APPLIC~1\SUPERAntiSpyware.com
2007-06-04 17:39 182,880 --a------ C:\WINDOWS\system32\iuengine.dll
2007-06-03 19:54 290,816 -ra------ C:\WINDOWS\system32\atiiiexx.dll
2007-06-03 13:48 dr-hs---- C:\cmdcons
2007-06-03 13:32 d-------- C:\WINDOWS\setup.pss
2007-06-03 13:10 72 --a------ C:\DOCUME~1\OWNER~1.TAV\test.dat
2007-06-03 13:10 d-------- C:\DOCUME~1\OWNER~1.TAV\APPLIC~1\InterTrust
2007-06-03 13:10 d-------- C:\DOCUME~1\OWNER~1.TAV\APPLIC~1\interMute
2007-06-03 13:10 d-------- C:\DOCUME~1\OWNER~1.TAV\APPLIC~1\Hewlett-Packard
2007-06-03 13:10 d-------- C:\DOCUME~1\OWNER~1.TAV\APPLIC~1\Help
2007-06-03 13:10 d-------- C:\DOCUME~1\OWNER~1.TAV\APPLIC~1\CyberLink
2007-06-03 13:10 d-------- C:\DOCUME~1\OWNER~1.TAV\APPLIC~1\ATI
2007-06-03 13:10 d-------- C:\DOCUME~1\OWNER~1.TAV\APPLIC~1\AOL
2007-06-03 13:10 d-------- C:\DOCUME~1\OWNER~1.TAV\APPLIC~1\acccore
2007-06-03 13:10 d-------- C:\DOCUME~1\OWNER~1.TAV\.limewire
2007-06-03 13:09 1,048,576 --ah----- C:\DOCUME~1\OWNER~1.TAV\NTUSER.DAT
2007-06-03 13:09 d---s---- C:\DOCUME~1\OWNER~1.TAV\UserData
2007-06-03 13:09 d-------- C:\DOCUME~1\OWNER~1.TAV\WINDOWS
2007-06-03 13:09 d-------- C:\DOCUME~1\OWNER~1.TAV\Incomplete
2007-06-03 13:09 d-------- C:\DOCUME~1\OWNER~1.TAV\APPLIC~1\You've Got Pictures Screensaver
2007-06-03 13:09 d-------- C:\DOCUME~1\OWNER~1.TAV\APPLIC~1\U3
2007-06-03 13:09 d-------- C:\DOCUME~1\OWNER~1.TAV\APPLIC~1\Symantec
2007-06-03 13:09 d-------- C:\DOCUME~1\OWNER~1.TAV\APPLIC~1\Sonic
2007-06-03 13:09 d-------- C:\DOCUME~1\OWNER~1.TAV\APPLIC~1\SampleView
2007-06-03 13:09 d-------- C:\DOCUME~1\OWNER~1.TAV\APPLIC~1\Real
2007-06-03 13:09 d-------- C:\DOCUME~1\OWNER~1.TAV\APPLIC~1\MSNInstaller
2007-06-03 13:09 d-------- C:\DOCUME~1\OWNER~1.TAV\APPLIC~1\MSN6
2007-06-03 12:55 51,072 --a------ C:\WINDOWS\system32\drivers\i8042prt.sys
2007-06-03 12:55 262,144 --a------ C:\DOCUME~1\ALLUSE~1\NTUSER.DAT
2007-06-03 12:55 23,424 --a------ C:\WINDOWS\system32\drivers\kbdclass.sys
2007-06-03 12:12 72 --a------ C:\DOCUME~1\DEFAUL~1\test.dat
2007-06-03 12:12 d---s---- C:\DOCUME~1\DEFAUL~1\UserData
2007-06-03 12:12 d-------- C:\DOCUME~1\DEFAUL~1\Incomplete
2007-06-03 12:12 d-------- C:\DOCUME~1\DEFAUL~1\APPLIC~1\You've Got Pictures Screensaver
2007-06-03 12:12 d-------- C:\DOCUME~1\DEFAUL~1\APPLIC~1\U3
2007-06-03 12:12 d-------- C:\DOCUME~1\DEFAUL~1\APPLIC~1\MSNInstaller
2007-06-03 12:12 d-------- C:\DOCUME~1\DEFAUL~1\APPLIC~1\MSN6
2007-06-03 12:12 d-------- C:\DOCUME~1\DEFAUL~1\APPLIC~1\Hewlett-Packard
2007-06-03 12:12 d-------- C:\DOCUME~1\DEFAUL~1\APPLIC~1\Help
2007-06-03 12:12 d-------- C:\DOCUME~1\DEFAUL~1\APPLIC~1\CyberLink
2007-06-03 12:12 d-------- C:\DOCUME~1\DEFAUL~1\APPLIC~1\ATI
2007-06-03 12:12 d-------- C:\DOCUME~1\DEFAUL~1\APPLIC~1\AOL
2007-06-03 12:12 d-------- C:\DOCUME~1\DEFAUL~1\APPLIC~1\acccore
2007-06-03 12:12 d-------- C:\DOCUME~1\DEFAUL~1\.limewire
2007-06-03 11:45 56,832 --a------ C:\WINDOWS\system32\drivers\sysaudio.sys
2007-06-03 11:45 50,048 --a------ C:\WINDOWS\system32\drivers\DMusic.sys
2007-06-03 11:45 28,160 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2007-06-03 11:45 24,960 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2007-06-03 11:45 2,816 --a------ C:\WINDOWS\system32\drivers\drmkaud.sys
2007-06-03 11:44 57,856 --a------ C:\WINDOWS\system32\drivers\drmk.sys
2007-06-03 11:44 134,272 --a------ C:\WINDOWS\system32\drivers\portcls.sys
2007-06-03 10:28 d-------- C:\DOCUME~1\TIMALA~1.YOU\WINDOWS
2007-06-03 10:28 d-------- C:\DOCUME~1\TIMALA~1.YOU\APPLIC~1\Symantec
2007-06-03 10:28 d-------- C:\DOCUME~1\TIMALA~1.YOU\APPLIC~1\SampleView
2007-06-03 10:28 d-------- C:\DOCUME~1\TIMALA~1.YOU\APPLIC~1\InterTrust
2007-06-03 10:28 d-------- C:\DOCUME~1\TIMALA~1.YOU\APPLIC~1\ATI
2007-06-03 08:41 78,360 --a------ C:\Program Files\uy.exe
2007-06-03 08:34 75,512 --a------ C:\WINDOWS\zllsputility.exe
2007-06-03 08:34 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2007-06-03 08:33 1,087,216 --a------ C:\WINDOWS\system32\zpeng24.dll
2007-06-03 08:33 d-------- C:\WINDOWS\system32\ZoneLabs
2007-06-03 08:20 d-------- C:\WINDOWS\Internet Logs
2007-06-02 19:53 d-------- C:\Program Files\Windows Defender
2007-06-02 11:59 1,048,576 --ah----- C:\DOCUME~1\TIMALA~1.YOU\NTUSER.DAT
2007-06-02 11:59 d-------- C:\DOCUME~1\TIMALA~1.YOU\APPLIC~1\Sonic
2007-06-02 11:59 d-------- C:\DOCUME~1\TIMALA~1.YOU\APPLIC~1\Real
2007-06-02 11:59 d-------- C:\DOCUME~1\TIMALA~1.YOU\APPLIC~1\interMute
2007-05-28 16:29 d-------- C:\WINDOWS\wqow
2007-05-28 16:29 d-------- C:\Program Files\Common Files\wqow
2007-05-26 16:08 167 --a------ C:\WINDOWS\system32\9193.bat
2007-05-26 16:07 109,343 --a------ C:\WINDOWS\system32\app.exe
2007-05-26 16:07 10,326 --a------ C:\WINDOWS\system32\install.exe
2007-05-26 16:07 d-------- C:\WINDOWS\system32\TQ0
2007-05-26 16:07 d-------- C:\WINDOWS\system32\T8
2007-05-26 16:07 d-------- C:\WINDOWS\system32\T6QaSQ
2007-05-26 16:07 d-------- C:\WINDOWS\system32\T6
2007-05-26 16:06 32,768 --a------ C:\WINDOWS\system32\setup9x.exe
2007-05-24 16:05 d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Office Genuine Advantage
2007-05-21 19:32 0 --a------ C:\WINDOWS\system32\taskkill.exe
2007-05-21 19:31 147,456 --a------ C:\WINDOWS\system32\vbzip10.dll
2007-05-20 19:03 d-------- C:\Program Files\Incomplete
2007-05-06 11:09 d-------- C:\DOCUME~1\ILIAAN~1\APPLIC~1\acccore
2007-05-05 07:42 d-------- C:\DOCUME~1\ILIAAN~1\APPLIC~1\ATI
2007-05-05 07:41 1,048,576 --ah----- C:\DOCUME~1\ILIAAN~1\NTUSER.DAT
2007-05-05 07:41 d-------- C:\DOCUME~1\ILIAAN~1\WINDOWS
2007-05-05 07:41 d-------- C:\DOCUME~1\ILIAAN~1\APPLIC~1\Symantec
2007-05-05 07:41 d-------- C:\DOCUME~1\ILIAAN~1\APPLIC~1\Sonic
2007-05-05 07:41 d-------- C:\DOCUME~1\ILIAAN~1\APPLIC~1\SampleView
2007-05-05 07:41 d-------- C:\DOCUME~1\ILIAAN~1\APPLIC~1\Real
2007-05-05 07:41 d-------- C:\DOCUME~1\ILIAAN~1\APPLIC~1\InterTrust
2007-05-05 07:41 d-------- C:\DOCUME~1\ILIAAN~1\APPLIC~1\interMute
2007-05-04 22:03 2,560 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-05-04 22:03 2,432 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-05-04 22:03 129,784 --------- C:\WINDOWS\system32\pxafs.dll
2007-05-04 22:03 118,520 --------- C:\WINDOWS\system32\pxinsi64.exe
2007-05-04 22:03 116,472 --------- C:\WINDOWS\system32\pxcpyi64.exe
2007-05-04 22:02 d-------- C:\Program Files\DivX
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-06-05 01:25:50 -------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-06-05 00:59:05 -------- d-----w C:\Program Files\AWS
2007-06-05 00:55:21 -------- d-----w C:\Program Files\Easy Internet signup
2007-06-05 00:49:18 -------- d--h--w C:\Program Files\WindowsUpdate
2007-06-05 00:31:20 417,792 ----a-w C:\Program Files\Video.exe
2007-06-05 00:31:20 417,792 ----a-w C:\Program Files\Track_03.exe
2007-06-03 20:19:14 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-06-03 17:58:39 -------- d-----w C:\Program Files\Windows NT
2007-06-03 17:58:34 -------- d-----w C:\Program Files\Movie Maker
2007-06-03 17:58:33 -------- d-----w C:\Program Files\Messenger
2007-06-03 17:28:39 -------- d-----w C:\Program Files\LimeWire
2007-05-28 21:05:34 -------- d-----w C:\Program Files\AlarmWiz
2007-05-09 03:29:58 -------- d-----w C:\Program Files\EA GAMES
2007-05-02 18:04:23 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2007-05-02 18:04:19 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-05-02 18:04:06 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-05-02 18:04:05 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2007-05-02 18:02:06 73,728 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-05-02 18:02:06 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2007-05-02 18:02:04 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-05-02 18:02:02 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-05-02 18:02:02 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2007-05-02 18:02:02 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2007-05-02 18:02:02 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2007-05-02 18:02:02 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2007-05-02 18:01:56 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-05-02 18:01:56 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2007-05-02 18:01:56 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2007-05-02 18:01:56 740,442 ----a-w C:\WINDOWS\system32\DivX.dll
2007-05-02 02:33:57 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-05-02 02:33:56 124,472 ----a-w C:\WINDOWS\system32\DivXCodecUpdateChecker.exe
2007-03-29 20:22:38 417,792 ----a-w C:\Program Files\Setup.exe
2007-03-11 17:37:25 278,528 ----a-w C:\WINDOWS\system32\livesnth.dll
2007-03-05 20:34:28 676,224 ----a-w C:\WINDOWS\system32\OGACheckControl.DLL
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx [2001-03-02 19:02]
{243B17DE-77C7-46BF-B94B-0B5F309A0E64}=C:\Program Files\Microsoft Money\System\mnyside.dll [2002-07-17 18:00]
{BDF3E430-B101-42AD-A544-FADC6B084872}=c:\Program Files\Norton AntiVirus\NavShExt.dll [2002-11-15 07:09]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 19:02]
"StorageGuard"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-02-13 08:01]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2003-04-10 03:50]
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2002-11-15 02:29]
"ccRegVfy"="c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe" [2002-11-15 02:29]
"AlcxMonitor"="ALCXMNTR.EXE" [2003-04-03 20:35 C:\WINDOWS\ALCXMNTR.EXE]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-03-03 12:00]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2002-08-20 22:08]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-05-23 10:12]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"="C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 13:55]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina]
C:\Program Files\Softex\OmniPass\opxpgina.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*
*Newly Created Service* - SASDIFSV
*Newly Created Service* - SASENUM
*Newly Created Service* - SASKUTIL
Contents of the 'Scheduled Tasks' folder
2006-09-22 02:39:10 C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1158852529.job
2007-06-03 17:34:17 C:\WINDOWS\tasks\MP Scheduled Scan.job
2007-06-05 00:46:54 C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer.job
2007-06-05 00:46:55 C:\WINDOWS\tasks\Symantec NetDetect.job
**************************************************************************
catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-06-04 18:52:44
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
Completion time: 2007-06-04 18:53:32
C:\ComboFix-quarantined-files.txt ... 2007-06-04 18:53
--- E O F ---
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files\Common Files\Yazzle1122OinAdmin.exe
C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
C:\Program Files\Common Files\Yazzle1275OinAdmin.exe
C:\Program Files\Common Files\Yazzle1275OinUninstaller.exe
C:\Program Files\inetget2
C:\Program Files\ipwindows
C:\Program Files\ipwindows\UnInstall.exe
C:\Temp\0b9
C:\Temp\0b9\tmpTF.log
C:\WINDOWS\b122.exe
C:\WINDOWS\cs_cache.ini
C:\WINDOWS\stub_mma2.exe
C:\WINDOWS\system32\pog
C:\WINDOWS\system32\T3
C:\WINDOWS\system32\T3\dlltk67.exe
C:\WINDOWS\system32\T4
C:\WINDOWS\system32\tsuninst.exe
C:\WINDOWS\wr.txt
((((((((((((((((((((((((( Files Created from 2007-05-05 to 2007-06-05 )))))))))))))))))))))))))))))))
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files\Common Files\Yazzle1122OinAdmin.exe
C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
C:\Program Files\Common Files\Yazzle1275OinAdmin.exe
C:\Program Files\Common Files\Yazzle1275OinUninstaller.exe
C:\Program Files\inetget2
C:\Program Files\ipwindows
C:\Program Files\ipwindows\UnInstall.exe
C:\Temp\0b9
C:\Temp\0b9\tmpTF.log
C:\WINDOWS\b122.exe
C:\WINDOWS\cs_cache.ini
C:\WINDOWS\stub_mma2.exe
C:\WINDOWS\system32\pog
C:\WINDOWS\system32\T3
C:\WINDOWS\system32\T3\dlltk67.exe
C:\WINDOWS\system32\T4
C:\WINDOWS\system32\tsuninst.exe
C:\WINDOWS\wr.txt
((((((((((((((((((((((((( Files Created from 2007-05-05 to 2007-06-05 )))))))))))))))))))))))))))))))