ComboFix 08-01-23.1C - Tony 2008-01-25 15:29:53.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.245 [GMT -5:00]
Running from: C:\Documents and Settings\Tony\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Tony\Desktop\CFScript.txt
* Created a new restore point[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
FILE
C:\WINDOWS\SYSTEM32\adssite-remove.exe
C:\WINDOWS\SYSTEM32\hurjfnpu.ini
C:\WINDOWS\SYSTEM32\jpewocmz.ini
C:\WINDOWS\SYSTEM32\qhuxebwq.ini
C:\WINDOWS\SYSTEM32\rightonadz-uninst.exe
C:\WINDOWS\SYSTEM32\shbxdcjh.ini
C:\WINDOWS\SYSTEM32\xgjrihqs.ini
C:\WINDOWS\winshow .exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\AntiSpywareApp
C:\Program Files\AntiSpywareApp\AntiSpyware.exe
C:\Program Files\AntiSpywareApp\AntiSpyware.url
C:\Program Files\AntiSpywareApp\Launcher.exe
C:\Program Files\AntiSpywareApp\unins000.dat
C:\Program Files\AntiSpywareApp\unins000.exe
C:\temp\cEeer12
C:\temp\cEeer12\skAt.log
C:\WINDOWS\SYSTEM32\adssite-remove.exe
C:\WINDOWS\SYSTEM32\aj2
C:\WINDOWS\SYSTEM32\ardCo02
C:\WINDOWS\SYSTEM32\hurjfnpu.ini
C:\WINDOWS\SYSTEM32\jpewocmz.ini
C:\WINDOWS\SYSTEM32\mr9
C:\WINDOWS\SYSTEM32\qhuxebwq.ini
C:\WINDOWS\SYSTEM32\rightonadz-uninst.exe
C:\WINDOWS\SYSTEM32\shbxdcjh.ini
C:\WINDOWS\SYSTEM32\xgjrihqs.ini
C:\WINDOWS\winshow .exe
.
((((((((((((((((((((((((( Files Created from 2007-12-25 to 2008-01-25 )))))))))))))))))))))))))))))))
.
2008-01-25 15:23 . 2008-01-25 15:23 <DIR> d-------- C:\WINDOWS\LastGood
2008-01-24 22:41 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\Nircmd.exe
2008-01-24 18:21 . 2008-01-24 22:09 <DIR> d-------- C:\VundoFix Backups
2008-01-23 23:40 . 2008-01-23 23:40 1,906 --a------ C:\WINDOWS\SYSTEM32\tmp.reg
2008-01-23 23:39 . 2008-01-23 23:38 289,144 --a------ C:\WINDOWS\SYSTEM32\VCCLSID.exe
2008-01-23 23:39 . 2008-01-23 23:38 288,417 --a------ C:\WINDOWS\SYSTEM32\SrchSTS.exe
2008-01-23 23:39 . 2008-01-23 23:38 81,920 --a------ C:\WINDOWS\SYSTEM32\IEDFix.exe
2008-01-23 23:39 . 2008-01-23 23:38 53,248 --a------ C:\WINDOWS\SYSTEM32\Process.exe
2008-01-23 23:39 . 2008-01-23 23:38 51,200 --a------ C:\WINDOWS\SYSTEM32\dumphive.exe
2008-01-23 23:39 . 2008-01-23 23:38 25,600 --a------ C:\WINDOWS\SYSTEM32\WS2Fix.exe
2008-01-23 23:35 . 2008-01-23 23:35 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-15 21:41 . 2008-01-15 21:41 81,920 --a------ C:\WINDOWS\SYSTEM32\csrcli32.dll
2008-01-15 21:41 . 2008-01-15 21:41 58,880 --a------ C:\WINDOWS\SYSTEM32\urikon.dll
2008-01-15 21:41 . 2008-01-15 21:41 18,944 --a------ C:\WINDOWS\SYSTEM32\msdfmap.dll
2008-01-15 21:41 . 2008-01-15 21:41 6,656 --a------ C:\WINDOWS\SYSTEM32\md4hsh.dll
2008-01-15 21:41 . 2008-01-15 21:41 2,528 --a------ C:\WINDOWS\SYSTEM32\nvnatv.sys
2008-01-13 22:07 . 2004-08-12 08:58 1,875,968 --a--c--- C:\WINDOWS\SYSTEM32\DLLCACHE\msir3jp.lex
2008-01-13 22:06 . 2004-08-12 08:58 13,463,552 --a--c--- C:\WINDOWS\SYSTEM32\DLLCACHE\hwxjpn.dll
2008-01-13 22:05 . 2004-08-12 08:58 1,677,824 --a--c--- C:\WINDOWS\SYSTEM32\DLLCACHE\chsbrkr.dll
2008-01-13 21:59 . 2008-01-13 21:59 749 -rah----- C:\WINDOWS\WindowsShell.Manifest
2008-01-13 21:59 . 2008-01-13 21:59 749 -rah----- C:\WINDOWS\SYSTEM32\wuaucpl.cpl.manifest
2008-01-13 21:59 . 2008-01-13 21:59 749 -rah----- C:\WINDOWS\SYSTEM32\sapi.cpl.manifest
2008-01-13 21:59 . 2008-01-13 21:59 749 -rah----- C:\WINDOWS\SYSTEM32\ncpa.cpl.manifest
2008-01-13 21:59 . 2008-01-13 21:59 488 -rah----- C:\WINDOWS\SYSTEM32\logonui.exe.manifest
2008-01-13 16:28 . 2008-01-21 17:28 536,141,824 --a------ C:\WINDOWS\MEMORY.DMP
2008-01-13 12:14 . 2008-01-24 21:36 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-13 12:14 . 2008-01-13 12:14 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-13 11:55 . 2008-01-13 11:57 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2008-01-13 11:39 . 2008-01-13 11:39 268 --ah----- C:\sqmdata06.sqm
2008-01-13 11:39 . 2008-01-13 11:39 244 --ah----- C:\sqmnoopt06.sqm
2008-01-13 00:07 . 2008-01-13 08:39 155,648 --a------ C:\WINDOWS\SYSTEM32\NeroCheck.exe
2008-01-02 00:20 . 2008-01-13 03:55 174,592 --a------ C:\WINDOWS\SYSTEM32\lexpps.exe
2008-01-02 00:20 . 2008-01-02 00:20 172 --ah----- C:\sqmnoopt05.sqm
2008-01-02 00:20 . 2008-01-02 00:20 172 --ah----- C:\sqmdata05.sqm
2008-01-01 23:34 . 2008-01-01 23:34 268 --ah----- C:\sqmdata04.sqm
2008-01-01 23:34 . 2008-01-01 23:34 244 --ah----- C:\sqmnoopt04.sqm
2007-12-27 14:32 . 2007-12-27 14:32 268 --ah----- C:\sqmdata03.sqm
2007-12-27 14:32 . 2007-12-27 14:32 244 --ah----- C:\sqmnoopt03.sqm
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-25 20:29 --------- d-----w C:\Program Files\SymNetDrv
2008-01-25 20:29 --------- d-----w C:\Program Files\Norton Internet Security
2008-01-25 20:29 --------- d-----w C:\Program Files\MSN Messenger
2008-01-25 20:29 --------- d-----w C:\Program Files\iTunes
2008-01-25 20:29 --------- d-----w C:\Program Files\DellSupport
2008-01-25 20:29 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-01-25 04:37 --------- d-----w C:\Program Files\QuickTime
2008-01-25 04:37 --------- d-----w C:\Program Files\Apoint
2008-01-02 05:52 --------- d-----w C:\Program Files\Pure Networks
2007-12-26 12:59 --------- d-----w C:\Program Files\MasterCook
2007-12-24 01:40 --------- d-----w C:\Program Files\America Online 9.0a
2007-12-20 01:35 --------- d-----w C:\Program Files\Common Files\Adobe
2007-12-02 13:10 --------- d-----w C:\Program Files\Windows Live Toolbar
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-12 08:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"{00-04-41-11-ZN}"="c:\windows\system32\dwdsrngt .exe" [ ]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 05:59 122880 C:\WINDOWS\BCMSMMSG.exe]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [ ]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HPAiODevice(hp officejet g series) - 1.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HPAiODevice(hp officejet g series) - 1.lnk
backup=C:\WINDOWS\pss\HPAiODevice(hp officejet g series) - 1.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=C:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Tony^Start Menu^Programs^Startup^TA_Start.lnk]
path=C:\Documents and Settings\Tony\Start Menu\Programs\Startup\TA_Start.lnk
backup=C:\WINDOWS\pss\TA_Start.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Spyware Protection]
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
--a------ 2008-01-13 08:39 34904 C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
C:\Program Files\Apoint\Apoint.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
--a------ 2008-01-13 08:39 339968 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
--a------ 2003-08-29 05:59 122880 C:\WINDOWS\BCMSMMSG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
--a------ 2008-01-13 08:39 71280 C:\Program Files\Common Files\Symantec Shared\ccApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-12 08:56 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell QuickSet]
C:\Program Files\Dell\QuickSet\quickset .exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
--a------ 2008-01-13 09:10 159832 C:\Program Files\Common Files\AOL\1107714629\ee\AOLHostManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-01-13 00:07 278528 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
--a------ 2008-01-13 08:40 32768 C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
C:\WINDOWS\system32\awtqo.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
--a------ 2008-01-13 08:39 188416 C:\Program Files\Logitech\Video\ISStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
--a------ 2008-01-13 00:07 53248 c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
--a------ 2008-01-13 00:08 200704 C:\Program Files\Microsoft Money\System\mnyexpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-08-04 01:06 1667584 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnappau]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2008-01-13 11:36 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2008-01-13 08:39 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
--a------ 2008-01-13 00:31 290816 C:\Program Files\Dell\Media Experience\PCMService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pure Networks Port Magic]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask .exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
--a------ 2008-01-13 00:07 208941 C:\Program Files\Real\RealPlayer\RealPlay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sonic RecordNow!]
--a------ 2008-01-13 11:36 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
--a------ 2008-01-13 00:07 100056 C:\PROGRA~1\SYMNET~1\SNDMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-01-13 00:07 180269 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\troy44]
C:\WINDOWS\troy44.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\troy44 ]
C:\WINDOWS\troy44 .exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
--a------ 2008-01-13 00:07 110592 C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
--a------ 2008-01-13 08:40 313472 C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\URLLSTCK.exe]
--a------ 2008-01-13 00:07 70800 C:\Program Files\Norton Internet Security\UrlLstCk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ViewMgr]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WildTangent CDA]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WT GameChannel]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{00-04-41-11-ZN}]
c:\windows\system32\dwdsrngt .exe
R1 nvnatv;NVidia Native rendering;C:\WINDOWS\system32\nvnatv.sys [2008-01-15 21:41]
S3 NuVision;Hauppauge WinTV USB Pro (NTSC);C:\WINDOWS\system32\DRIVERS\NUVision.sys [2003-04-30 14:59]
S3 PhilCam8116;Logitech QuickCam Pro 3000(PID_08B0);C:\WINDOWS\system32\DRIVERS\CamDrL21.sys [2002-12-10 05:53]
.
Contents of the 'Scheduled Tasks' folder
"2008-01-24 23:14:48 C:\WINDOWS\Tasks\AntiSpyware Scheduled Scan.job"
- C:\Program Files\AntiSpywareApp\AntiSpyware .ex
- C:\Program Files\AntiSpywareApp
"2008-01-25 10:35:03 C:\WINDOWS\Tasks\Check