ComboFix 07-07-30.2 - "Ginny" 2007-08-01 15:55:24.1 [GMT -7:00] - NTFS
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.True
* Created a new restore point
(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\cbxwxyw.dll
C:\WINDOWS\system32\cdfhxqyg.dll
C:\WINDOWS\system32\cueqfkmb.dll
C:\WINDOWS\system32\evqsnbgq.dll
C:\WINDOWS\system32\ffqimphe.dll
C:\WINDOWS\system32\fwutlari.dll
C:\WINDOWS\system32\gwyrybun.dll
C:\WINDOWS\system32\jkkjhhg.dll
C:\WINDOWS\system32\khfdcyy.dll
C:\WINDOWS\system32\lucmwmaa.dll
C:\WINDOWS\system32\opnlmjk.dll
C:\WINDOWS\system32\oxelmxpg.dll
C:\WINDOWS\system32\ssqollm.dll
C:\WINDOWS\system32\wkpjumoh.dll
C:\WINDOWS\system32\wsbvmyhe.dll
C:\WINDOWS\system32\wucysavu.dll
C:\WINDOWS\system32\xhtytcfh.dll
C:\WINDOWS\system32\xhtytcfh.dll
C:\WINDOWS\system32\bmkfqeuc.ini
C:\WINDOWS\system32\ehymvbsw.ini2
C:\WINDOWS\system32\ehymvbsw.tmp
C:\WINDOWS\system32\yyadd.bak1
C:\WINDOWS\system32\yyadd.bak2
C:\WINDOWS\system32\yyadd.ini
C:\WINDOWS\system32\yyadd.ini2
C:\WINDOWS\system32\yyadd.tmp
C:\WINDOWS\system32\ehymvbsw.ini2
C:\WINDOWS\system32\ehymvbsw.tmp
C:\WINDOWS\system32\yyadd.bak1
C:\WINDOWS\system32\yyadd.bak2
C:\WINDOWS\system32\yyadd.ini
C:\WINDOWS\system32\yyadd.ini2
C:\WINDOWS\system32\yyadd.tmp
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\Ginny\APPLIC~1.\.rdr.ini
C:\DOCUME~1\Ginny\APPLIC~1.\macromedia\Flash Player\#SharedObjects\D5HK977S\
www.broadcaster.com
C:\DOCUME~1\Ginny\APPLIC~1.\macromedia\Flash Player\#SharedObjects\D5HK977S\
www.broadcaster.com\played_list.sol
C:\DOCUME~1\Ginny\APPLIC~1.\macromedia\Flash Player\#SharedObjects\D5HK977S\
www.broadcaster.com\video_queue.sol
C:\DOCUME~1\Ginny\APPLIC~1.\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#
www.broadcaster.com
C:\DOCUME~1\Ginny\APPLIC~1.\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#
www.broadcaster.com\settings.sol
C:\DOCUME~1\Ginny\APPLIC~1.\ssembl~1
C:\DOCUME~1\Ginny\APPLIC~1.\winantispyware 2007 free
C:\DOCUME~1\Ginny\APPLIC~1.\winantispyware 2007 free\description.txt
C:\DOCUME~1\Ginny\APPLIC~1.\winantispyware 2007 free\DownloadUWAS7.url
C:\DOCUME~1\Ginny\APPLIC~1\install.dat
C:\DOCUME~1\Ginny\MYDOCU~1.\ymante~1
C:\DOCUME~1\Ginny\MYDOCU~1.\ymante~1\w?auboot.exe
C:\Documents and Settings\Ginny.\err.log
C:\Program Files\appatc~1
C:\Program Files\Common Files\dobe~1
C:\Program Files\Common Files\rtejeg.html
C:\Program Files\Common Files\Yazzle1162OinUninstaller.exe
C:\Program Files\Common Files\Yazzle1281OinUninstaller.exe
C:\Program Files\Common Files\Yazzle1552OinUninstaller.exe
C:\Program Files\Windows NT\menoxufap4.dll
C:\Program Files\Windows NT\menoxufap83122.dll
C:\WINDOWS\180ax.exe
C:\WINDOWS\2020search.dll
C:\WINDOWS\764.exe
C:\WINDOWS\7search.dll
C:\WINDOWS\b104.exe
C:\WINDOWS\bjam.dll
C:\WINDOWS\cdsm32.dll
C:\WINDOWS\DOWNLO~1\UWA7P_0001_N91M0809NetInstaller.exe
C:\WINDOWS\flt.dll
C:\WINDOWS\mspphe.dll
C:\WINDOWS\pbar.dll
C:\WINDOWS\rau001978.exe
C:\WINDOWS\saiemod.dll
C:\WINDOWS\salm.exe
C:\WINDOWS\satmat.exe
C:\WINDOWS\swin32.dll
C:\WINDOWS\system32\awqmt.dll
C:\WINDOWS\system32\b02FdUe
C:\WINDOWS\system32\b06FdUe
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\config\systemprofile\application data\.rdr.ini
C:\WINDOWS\system32\drivers\fopn.sys
C:\WINDOWS\system32\gtv_sd.bin
C:\WINDOWS\system32\L1
C:\WINDOWS\system32\L1\mwspasrt83122.exe
C:\WINDOWS\system32\L11
C:\WINDOWS\system32\L3
C:\WINDOWS\system32\L5
C:\WINDOWS\system32\L7
C:\WINDOWS\system32\mrdsregl.exe
C:\WINDOWS\system32\msixu.dll
C:\WINDOWS\system32\sl.bin
C:\WINDOWS\system32\vxddsk.exe
C:\WINDOWS\system32\wer8274.dll
C:\WINDOWS\system32\win
C:\WINDOWS\system32\wml.exe
C:\WINDOWS\system32\wnscpcc.exe
C:\WINDOWS\temp\salm.exe
C:\WINDOWS\TISKY009.exe
C:\WINDOWS\uninst2.htm
C:\WINDOWS\unist1.htm
C:\WINDOWS\updatetc.exe
C:\WINDOWS\wml.exe
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_FOPN
-------\LEGACY_NET_AGENT
-------\LEGACY_WINDOWS_OVERLAY_COMPONENTS
-------\Net Agent
((((((((((((((((((((((((( Files Created from 2007-07-01 to 2007-08-01 )))))))))))))))))))))))))))))))
2007-08-01 15:52 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-01 14:12 d-------- C:\Program Files\Trend Micro
2007-08-01 14:05 125,504 --a------ C:\WINDOWS\system32\jjxhnqtj.dll
2007-07-31 21:10 d-------- C:\DOCUME~1\dayne\APPLIC~1\Yahoo!
2007-07-31 17:40 125,504 --a------ C:\WINDOWS\system32\gcfopggp.dll
2007-07-31 17:14 125,504 --a------ C:\WINDOWS\system32\fxukjcxl.dll
2007-07-31 16:51 d-------- C:\DOCUME~1\dayne\APPLIC~1\SpywareBot
2007-07-31 16:51 d-------- C:\DOCUME~1\dayne\APPLIC~1\GTek
2007-07-31 16:50 696,320 --a------ C:\DOCUME~1\dayne\NTUSER.DAT
2007-07-31 16:50 d-------- C:\DOCUME~1\dayne\APPLIC~1\Google
2007-07-31 16:11 125,504 --a------ C:\WINDOWS\system32\erkjlcwm.dll
2007-07-31 16:06 d-------- C:\Program Files\RegCure
2007-07-30 22:59 125,504 --a------ C:\WINDOWS\system32\lghsjsoi.dll
2007-07-30 19:48 400,997 --a------ C:\Temp\bY001.exe
2007-07-30 19:29 d-------- C:\WINDOWS\network diagnostic
2007-07-30 18:42 d-------- C:\WINDOWS\LMIDC.tmp
2007-07-27 19:54 126,016 --a------ C:\WINDOWS\system32\plyoumdr.dll
2007-07-27 13:57 4 --a------ C:\WINDOWS\system32\stfv.bin
2007-07-27 13:57 11,264 --a------ C:\WINDOWS\vxddsk.exe
2007-07-24 18:21 d-------- C:\DOCUME~1\Ginny\APPLIC~1\SpywareBot
2007-07-24 18:20 18,672 --a------ C:\WINDOWS\system32\drivers\antispyfilter.sys
2007-07-24 18:20 d-------- C:\Program Files\SpywareBot
2007-07-22 09:47 d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
2007-07-22 09:46 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-07-21 16:52 192,606 --a------ C:\WINDOWS\system32\kwinsndt.exe
2007-07-21 16:51 d-------- C:\Temp\brr
2007-07-21 16:51 d-------- C:\Temp\0c2
2007-07-21 16:51 d-------- C:\Temp
2007-07-21 16:21 d-------- C:\Program Files\ISM
2007-07-18 16:07 d-------- C:\Program Files\Big Kahuna Reef 2
2007-07-18 16:07 d-------- C:\DOCUME~1\Ginny\APPLIC~1\SpinTop
2007-07-13 17:59 d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion
2007-07-13 17:41 107,688 --a------ C:\WINDOWS\TrueInstall.exe
2007-07-13 17:30 d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL OCP
2007-07-13 17:26 d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL Downloads
2007-07-10 22:41 d-------- C:\DOCUME~1\Ginny\Contacts
2007-07-10 22:40 d----c--- C:\WINDOWS\system32\DRVSTORE
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-01 16:00 --------- d-------- C:\Program Files\Windows NT
2007-07-30 21:39 --------- d-------- C:\DOCUME~1\Ginny\APPLIC~1\Move Networks
2007-07-27 13:57 801 --a------ C:\WINDOWS\system32\drivers\system_stable_header_small.gif
2007-07-27 13:57 6533 --a------ C:\WINDOWS\system32\drivers\system_stable_box_small.jpg
2007-07-27 13:57 579 --a------ C:\WINDOWS\system32\drivers\spy_away_header_small.gif
2007-07-27 13:57 567 --a------ C:\WINDOWS\system32\drivers\users_rating.gif
2007-07-27 13:57 291 --a------ C:\WINDOWS\system32\drivers\v.gif
2007-07-27 13:57 283 --a------ C:\WINDOWS\system32\drivers\x.gif
2007-07-27 13:57 1636 --a------ C:\WINDOWS\system32\drivers\system_stable_header.gif
2007-07-27 13:57 15075 --a------ C:\WINDOWS\system32\drivers\system_stable_box.jpg
2007-07-27 13:56 945 --a------ C:\WINDOWS\system32\drivers\s_detect.htm
2007-07-27 13:56 841 --a------ C:\WINDOWS\system32\drivers\perfect_cleaner_header_small.gif
2007-07-27 13:56 811 --a------ C:\WINDOWS\system32\drivers\download_btn.gif
2007-07-27 13:56 746 --a------ C:\WINDOWS\system32\drivers\buy_btn.gif
2007-07-27 13:56 737 --a------ C:\WINDOWS\system32\drivers\logo_bg.gif
2007-07-27 13:56 6575 --a------ C:\WINDOWS\system32\drivers\remove_spyware_button.gif
2007-07-27 13:56 64 --a------ C:\WINDOWS\system32\drivers\close_icon.gif
2007-07-27 13:56 6373 --a------ C:\WINDOWS\system32\drivers\secuity_center_logo.gif
2007-07-27 13:56 580 --a------ C:\WINDOWS\system32\drivers\features.gif
2007-07-27 13:56 5097 --a------ C:\WINDOWS\system32\drivers\spy_away_box_small.jpg
2007-07-27 13:56 50169 --a------ C:\WINDOWS\system32\drivers\pt.htm
2007-07-27 13:56 4825 --a------ C:\WINDOWS\system32\drivers\detect.htm
2007-07-27 13:56 4557 --a------ C:\WINDOWS\system32\drivers\perfect_cleaner_box_small.jpg
2007-07-27 13:56 427 --a------ C:\WINDOWS\system32\drivers\4_stars.gif
2007-07-27 13:56 365 --a------ C:\WINDOWS\system32\drivers\5_stars.gif
2007-07-27 13:56 360 --a------ C:\WINDOWS\system32\drivers\header_bg.gif
2007-07-27 13:56 3099 --a------ C:\WINDOWS\system32\drivers\logo.gif
2007-07-27 13:56 2186 --a------ C:\WINDOWS\system32\drivers\alert_icon.gif
2007-07-27 13:56 1804 --a------ C:\WINDOWS\system32\drivers\perfect_cleaner_header.gif
2007-07-27 13:56 14484 --a------ C:\WINDOWS\system32\drivers\protect.gif
2007-07-27 13:56 13618 --a------ C:\WINDOWS\system32\drivers\spy_away_box.jpg
2007-07-27 13:56 1139 --a------ C:\WINDOWS\system32\drivers\spy_away_header.gif
2007-07-27 13:56 10260 --a------ C:\WINDOWS\system32\drivers\perfect_cleaner_box.jpg
2007-07-27 13:56 1014 --a------ C:\WINDOWS\system32\drivers\icon_warning.gif
2007-07-24 18:36 --------- d-------- C:\Program Files\Free Offers from Freeze.com
2007-07-23 15:57 --------- d-------- C:\Program Files\Google
2007-07-22 20:34 --------- d-------- C:\DOCUME~1\Ginny\APPLIC~1\Google
2007-07-14 15:36 --------- d-------- C:\DOCUME~1\Ginny\APPLIC~1\Yahoo!
2007-07-13 18:21 --------- d-------- C:\Program Files\TruePoker
2007-07-13 18:04 --------- d-------- C:\Program Files\MySpace
2007-07-13 17:57 --------- d-------- C:\Program Files\Yahoo!
2007-07-13 17:46 --------- d-------- C:\Program Files\Common Files\AOL
2007-07-13 17:40 --------- d-------- C:\Program Files\Verizon Online
2007-07-13 17:35 --------- d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-07-13 17:30 --------- d-------- C:\Program Files\Dell
2007-07-13 17:28 --------- d-------- C:\Program Files\Common Files\Corel
2007-07-13 17:27 --------- d-------- C:\Program Files\Common Files\Oberon Media
2007-06-25 06:53 53248 --a------ C:\WINDOWS\uninst1014.exe
2007-06-03 18:28 --------- d-------- C:\Program Files\HP
2007-05-16 08:12 683520 --a------ C:\WINDOWS\system32\inetcomm.dll
2007-05-11 19:07 98958 --a------ C:\WINDOWS\hpiins02.dat
2007-04-18 21:20 48112 --a------ C:\DOCUME~1\Ginny\APPLIC~1\GDIPFONTCACHEV1.DAT
2006-08-05 19:23:10 104 --sh--r C:\WINDOWS\system32\CF4CCD37CE.sys
2006-08-05 19:23:12 4,184 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000026-8735-428D-B81F-DD098223B25F}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{13197ace-6851-45c3-a7ff-c281324d5489}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{156D49D8-D21C-819B-4912-F88DB926D49E}]
C:\WINDOWS\system32\awzfhytc.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{19D3A5DB-A5A3-4F95-9713-833AE4B950A4}]
C:\WINDOWS\system32\msdn_lib.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30000273-8230-4dd4-be4f-6889d1e74167}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4e1075f4-eec4-4a86-add7-cd5f52858c31}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53C330D6-A4AB-419B-B45D-FD4411C1FEF4}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5dafd089-24b1-4c5e-bd42-8ca72550717b}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{669695bc-a811-4a9d-8cdf-ba8c795f261e}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8674aea0-9d3d-11d9-99dc-00600f9a01f1}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{965a592f-8efa-4250-8630-7960230792f1}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AC9E5397-5F85-42AB-B9D1-33B5B4D87364}]
C:\WINDOWS\system32\ddayy.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b8875bfe-b021-11d4-bfa8-00508b8e9bd3}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ca1d1b05-9c66-11d5-a009-000103c1e50b}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{cf021f40-3e14-23a5-cba2-717765728274}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fc3a74e5-f281-4f10-ae1e-733078684f3c}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-02-02 23:10]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-08-01 14:22]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpywareBot"="C:\Program Files\SpywareBot\SpywareBot.exe" [2007-07-23 07:42]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:00]
"Sen"="C:\DOCUME~1\Ginny\APPLIC~1\SSEMBL~1\notepad.exe" []
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-06-11 18:16]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"MySpaceIM"=C:\Program Files\MySpace\IM\MySpaceIM.exe
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= C:\Program Files\Common Files\rtejeg.html
FriendlyName=
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddayy]
C:\WINDOWS\system32\ddayy.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\opnmnlj]
opnmnlj.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winzzc32]
winzzc32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Fast Start.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk
backup=C:\WINDOWS\pss\HP Photosmart Premier Fast Start.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=C:\WINDOWS\pss\QuickBooks Update Agent.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Ginny^Start Menu^Programs^Startup^DING!.lnk]
path=C:\Documents and Settings\Ginny\Start Menu\Programs\Startup\DING!.lnk
backup=C:\WINDOWS\pss\DING!.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
"C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avp]
C:\WINDOWS\TEMP\win55.tmp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cggxzicA]
C:\WINDOWS\cggxzicA.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Corel Photo Downloader]
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
"C:\Program Files\DellSupport\DSAgnt.exe" /startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\g4356cbvy63]
C:\WINDOWS\g4356cbvy63
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\WINDOWS\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM]
"C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
"C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
"C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]
C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
C:\PROGRA~1\MUSICM~1\MUSICM~3\mm_tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKDetectorExe]
C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
C:\Program Files\MySpace\IM\MySpaceIM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
C:\WINDOWS\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sen]
"C:\DOCUME~1\Ginny\APPLIC~1\SSEMBL~1\notepad.exe" -vt yazb
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\smgr]
mgrs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
C:\Program Files\Analog Devices\Core\smax4pnp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareBot]
C:\Program Files\SpywareBot\SpywareBot.exe -boot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\System]
C:\WINDOWS\system32\kernelwind32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemOptimizer]
rundll32.exe "C:\WINDOWS\system32\lghsjsoi.dll",forkonce
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows update loader]
C:\Windows\xpupdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wqzian]
"C:\Documents and Settings\Ginny\My Documents\?ymantec\w?auboot.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
R1 AntiSpyFilter;AntiSpyFilter;C:\WINDOWS\system32\DRIVERS\antispyfilter.sys
R2 ASCTRM;ASCTRM;C:\WINDOWS\system32\drivers\ASCTRM.sys
R2 dsunidrv;DellSupport UniDriver;C:\WINDOWS\system32\DRIVERS\dsunidrv.sys
R2 SpywareBotSrv;SpywareBot Scanning Engine;"C:\Program Files\SpywareBot\SpywareBotSrv.srv.exe"
R3 E100B;Intel(R) PRO Adapter Driver;C:\WINDOWS\system32\DRIVERS\e100b325.sys
R3 ROOTMODEM;Microsoft Legacy Modem Driver;C:\WINDOWS\system32\Drivers\RootMdm.sys
R3 senfilt;senfilt;C:\WINDOWS\system32\drivers\senfilt.sys
S3 ApiMon;ApiMon;\??\C:\WINDOWS\system32\drivers\ApiMon.sys
S3 DSproct;DSproct;\??\C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys
S3 TnIDriver;TnIDriver;\??\C:\DOCUME~1\Ginny\LOCALS~1\Temp\tniFC.tmp
S3 wanatw;WAN Miniport (ATW);C:\WINDOWS\system32\DRIVERS\wanatw4.sys
S4 agpCPQ;Compaq AGP Bus Filter;C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{F146C9B1-VMVQ-A9RC-NUFL-D02300B4E999}]
C:\WINDOWS\system32\tmrsrv32.exe
Contents of the 'Scheduled Tasks' folder
2007-08-01 23:02:29 C:\WINDOWS\Tasks\RegCure Program Check.job - C:\Program Files\RegCure\RegCure.exe
2007-07-31 23:06:37 C:\WINDOWS\Tasks\RegCure.job - C:\Program Files\RegCure\RegCure.exe
2007-08-01 23:02:53 C:\WINDOWS\Tasks\SpywareBot Scheduled Scan.job - C:\Program Files\SpywareBot\SpywareBot.exe
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-08-01 16:02:39
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:00000190
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-08-01 16:04:50 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-08-01 16:04
--- E O F ---