ComboFix 07-06-18.2 - C:\Documents and Settings\Jules\Desktop\ComboFix.exe
"Jules" - 2007-07-02 21:06:20 - Service Pack 2 NTFS
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Temp\tn3
C:\WINDOWS\b122.exe
C:\WINDOWS\cs_cache.ini
C:\WINDOWS\rau001978.exe
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\fad.sys
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\packet.dll
C:\WINDOWS\system32\pthreadVC.dll
C:\WINDOWS\system32\wpcap.dll
C:\WINDOWS\wr.txt
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_NET_AGENT
-------\LEGACY_NPF
-------\Net Agent
-------\NPF
((((((((((((((((((((((((( Files Created from 2007-06-03 to 2007-07-03 )))))))))))))))))))))))))))))))
2007-07-02 21:05 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-07-01 23:35 <DIR> d-------- C:\DOCUME~1\Jules\APPLIC~1\acccore
2007-07-01 23:35 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL OCP
2007-07-01 23:34 <DIR> d-------- C:\Program Files\Viewpoint
2007-07-01 23:34 <DIR> d-------- C:\Program Files\AIM6
2007-07-01 23:33 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL Downloads
2007-07-01 21:22 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-07-01 21:22 <DIR> d-------- C:\DOCUME~1\Jules\APPLIC~1\SUPERAntiSpyware.com
2007-07-01 21:22 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-07-01 21:18 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-07-01 10:40 <DIR> d-------- C:\VundoFix Backups
2007-06-28 05:15 626,688 --a------ C:\WINDOWS\SYSTEM32\msvcr80.dll
2007-06-28 03:59 22,080 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\sshrmd.sys
2007-06-28 03:59 21,056 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\sskbfd.sys
2007-06-28 03:59 20,544 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\SSFS0509.sys
2007-06-28 03:59 144,960 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\ssidrv.sys
2007-06-28 03:59 <DIR> d-------- C:\Program Files\Webroot
2007-06-28 03:59 <DIR> d-------- C:\DOCUME~1\NETWOR~1\APPLIC~1\Webroot
2007-06-28 03:59 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Webroot
2007-06-28 02:48 <DIR> d-------- C:\DOCUME~1\Jules\APPLIC~1\Lavasoft
2007-06-27 19:01 <DIR> d--hs---- C:\$RECYCLE.BIN
2007-06-27 17:51 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Geek Squad
2007-06-21 01:35 1,813,296 --ahs---- C:\WINDOWS\SYSTEM32\svyay.bak2
2007-06-16 01:52 <DIR> d-------- C:\DOCUME~1\Jules\APPLIC~1\Webroot
2007-06-14 03:05 1,808,203 --ahs---- C:\WINDOWS\SYSTEM32\svyay.bak1
2007-06-14 02:17 <DIR> d-------- C:\WINDOWS\SYSTEM32\win
2007-06-14 02:17 <DIR> d-------- C:\WINDOWS\SYSTEM32\S7
2007-06-14 02:17 <DIR> d-------- C:\WINDOWS\SYSTEM32\S6
2007-06-14 02:17 <DIR> d-------- C:\WINDOWS\SYSTEM32\S2
2007-06-14 02:17 <DIR> d-------- C:\WINDOWS\SYSTEM32\S1
2007-06-14 02:16 <DIR> d-------- C:\WINDOWS\SYSTEM32\o02PrEz
2007-06-14 02:16 <DIR> d-------- C:\Temp
2007-06-11 22:03 <DIR> d-------- C:\Program Files\utorrent
2007-06-11 22:03 <DIR> d-------- C:\DOCUME~1\Jules\APPLIC~1\uTorrent
2007-06-11 22:01 <DIR> d-------- C:\DOCUME~1\Jules\APPLIC~1\DivX
2007-06-11 21:59 <DIR> d-------- C:\Program Files\DivX
2007-06-11 21:58 80 -rahs---- C:\WINDOWS\SYSTEM32\225E2EA418.dll
2007-06-11 21:58 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Protexis
2007-06-08 22:53 55,546 --a------ C:\WINDOWS\SYSTEM32\vr-remove.exe
2007-06-08 22:52 382 --a------ C:\DOCUME~1\Jules\APPLIC~1\internaldb6334.dat
2007-06-08 22:52 194 --a------ C:\DOCUME~1\Jules\APPLIC~1\internaldb8467.dat
2007-06-08 22:52 18,432 --a------ C:\DOCUME~1\Jules\APPLIC~1\internaldb41.dat
2007-06-08 22:52 <DIR> d-------- C:\WINDOWS\SYSTEM32\UpMedia
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-02 03:36:00 -------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-07-02 03:34:19 -------- d-----w C:\Program Files\Common Files\AOL
2007-07-02 03:33:09 -------- d-----w C:\Program Files\AIM
2007-07-02 03:10:40 -------- d-----w C:\Program Files\VideoLAN
2007-07-02 03:10:32 -------- d-----w C:\Program Files\Verizon Online
2007-07-02 03:10:27 -------- d-----w C:\Program Files\Motive
2007-07-02 03:10:00 -------- d-----w C:\Program Files\Common Files\Motive
2007-06-30 20:14:52 -------- d-----w C:\DOCUME~1\Jules\APPLIC~1\U3
2007-06-29 12:20:00 -------- d-----w C:\Program Files\Norton Internet Security
2007-06-20 21:06:12 -------- d-----w C:\Program Files\Symantec
2007-05-20 14:47:44 48,776 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2007-05-20 14:47:44 115,000 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-17 02:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-17 02:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 02:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 02:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 02:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 02:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 02:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 02:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll [2003-11-03 16:17]
{4A6729D2-B7E7-4171-A9D1-865C68D8BBB2}=C:\Program Files\Common Files\pote.dll []
{53707962-6F74-2D53-2644-206D7942484F}=C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2005-05-31 02:04]
{5CA3D70E-1895-11CF-8E15-001234567890}=C:\WINDOWS\system32\dla\tfswshx.dll [2004-08-13 03:05]
{9ECB9560-04F9-4bbc-943D-298DDF1699E1}=C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll [2006-02-06 23:35]
{A8F38D8D-E480-4D52-B7A2-731BB6995FDD}=C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll [2007-04-02 19:19]
{AA58ED58-01DD-4d91-8333-CF10577473F7}=c:\program files\google\googletoolbar2.dll [2006-12-16 11:08]
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}=C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll [2007-06-09 10:57]
{B652A044-3EA8-4B90-B660-34F8E324C8DE}=C:\WINDOWS\system32\yayvs.dll []
{C5DBFB94-D04E-420A-B521-2410ED4D108C}=\ [2007-07-02 21:13]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2005-05-04 17:21]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-06-16 08:03]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-06-16 06:03]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-09-07 18:08]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-22 22:19]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00]
"SFP"="C:\Program Files\Common Files\Verizon Online\SFP\vzSFPWin.exe" [2003-04-11 10:29]
"OuterinfoUpdate"="C:\Program Files\Outerinfo\OuterinfoUpdate.exe" []
"Outerinfo"="C:\Program Files\Outerinfo\Outerinfo.exe" []
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
"Aim6"="" []
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= C:\Program Files\NetMeeting\wuoprypre.html
FriendlyName=
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"="C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 13:55]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PCANotify]
PCANotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
C:\Program Files\AIM\aim.exe -cnetwait.odl
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
C:\Program Files\Apoint\Apoint.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CAVRID]
"C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell QuickSet]
C:\Program Files\Dell\QuickSet\quickset.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellHelp]
C:\Dell\DellHelp\DellHelp.exe /c
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
"C:\Program Files\DellSupport\DSAgnt.exe" /startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMXLauncher]
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
"C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Turtle Beach Audio Advantage Micro]
"C:\Program Files\Turtle Beach\AudioAdvantageMicro\TBAA.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
"C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebBuying]
C:\Program Files\Web Buying\v1.7.4\webbuying.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinPop]
C:\Program Files\WinPop\winpop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WLANKEEPER"=2 (0x2)
"Viewpoint Manager Service"=2 (0x2)
"RioMSC"=2 (0x2)
"RegSrvc"=2 (0x2)
"ose"=3 (0x3)
"Net Agent"=2 (0x2)
"MDM"=2 (0x2)
"iPodService"=3 (0x3)
"EvtEng"=2 (0x2)
"DSBrokerService"=3 (0x3)
"comHost"=3 (0x3)
"Automatic LiveUpdate Scheduler"=2 (0x2)
"AOL ACS"=2 (0x2)
*Newly Created Service* - COMHOST
Contents of the 'Scheduled Tasks' folder
2007-06-09 02:46:11 C:\WINDOWS\tasks\Norton AntiVirus - Run Full System Scan - Jules.job
2007-07-03 01:07:00 C:\WINDOWS\tasks\Symantec NetDetect.job
**************************************************************************
catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-07-02 21:13:43
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-02 21:16:56 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-07-02 21:16
--- E O F ---