[quote name=\'guestolo\' post=\'238270\' date=\'Nov 12 2006, 04:53 PM\']Can I just have a look at another log, see if uncovers any other files that may be bad
Download this file -
Combofix.exe and save it too desktop
Double click
combofix.exe & follow the prompts.
When finished, it shall produce a log for you.
Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Post the log from combofix please[/quote]
Here is the COMBOFIX log:
Administrator - 06-11-13 7:39:01.02 Service Pack 2
ComboFix 06.11.9 - Running from: "C:\Documents and Settings\Administrator\Desktop"
((((((((((((((((((((((((((((((( Files Created from 2006-10-13 to 2006-11-13 ))))))))))))))))))))))))))))))))))
2006-11-01 12:50 114,688 --a------ C:\WINDOWS\system32\calc.exe
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-11-13 07:37 -------- d-------- C:\Program Files\Mozilla Firefox
2006-11-12 12:04 -------- d-------- C:\Program Files\iTunes
2006-11-12 12:04 -------- d-------- C:\Documents and Settings\Administrator\Application Data\Apple Computer
2006-11-12 12:03 -------- d-------- C:\Program Files\iPod
2006-11-12 12:02 -------- d-------- C:\Program Files\QuickTime
2006-11-08 17:00 -------- d-------- C:\Program Files\UniDream PowerBatch
2006-11-04 11:31 -------- d-------- C:\Program Files\Easy Thumbnails
2006-10-28 06:30 -------- d-------- C:\Program Files\Windows NT
2006-10-12 21:33 -------- d-------- C:\Program Files\EPSON
2006-10-12 05:50 -------- d-------- C:\Documents and Settings\Administrator\Application Data\iPodder
2006-10-04 08:46 -------- d-------- C:\Program Files\Juice
2006-10-01 09:19 -------- d-------- C:\Documents and Settings\Administrator\Application Data\Snapfish
2006-09-21 19:53 -------- d-------- C:\Documents and Settings\Administrator\Application Data\AdobeUM
2006-09-20 22:37 -------- d-------- C:\Documents and Settings\Administrator\Application Data\Adobe
2006-09-19 15:44 15664 --a------ C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
2006-09-19 15:43 109360 --a------ C:\WINDOWS\system32\GEARAspi.dll
2006-09-18 06:49 -------- d-------- C:\Program Files\AntiVir PersonalEdition Classic
2006-09-15 22:41 -------- d-------- C:\Program Files\LimeWire
2006-09-13 00:01 1084416 --a------ C:\WINDOWS\system32\msxml3.dll
2006-08-25 10:45 617472 --a------ C:\WINDOWS\system32\comctl32.dll
2006-08-22 23:31 5906432 --------- C:\WINDOWS\system32\ieframe.dll
2006-08-22 23:31 50688 --------- C:\WINDOWS\system32\msfeedsbs.dll
2006-08-22 23:31 457728 --------- C:\WINDOWS\system32\msfeeds.dll
2006-08-22 23:31 413696 --a------ C:\WINDOWS\system32\vbscript.dll
2006-08-22 23:31 225792 --a------ C:\WINDOWS\system32\webcheck.dll
2006-08-22 23:31 175616 --------- C:\WINDOWS\system32\ieui.dll
2006-08-22 23:31 152064 --a------ C:\WINDOWS\system32\msls31.dll
2006-08-22 23:18 78336 --a------ C:\WINDOWS\system32\ieencode.dll
2006-08-22 23:18 206336 --------- C:\WINDOWS\system32\WinFXDocObj.exe
2006-08-22 23:17 40448 --a------ C:\WINDOWS\system32\licmgr10.dll
2006-08-22 23:17 105472 --a------ C:\WINDOWS\system32\url.dll
2006-08-22 23:17 100352 --a------ C:\WINDOWS\system32\occache.dll
2006-08-22 23:16 16896 --a------ C:\WINDOWS\system32\corpol.dll
2006-08-22 23:14 378368 --a------ C:\WINDOWS\system32\iedkcs32.dll
2006-08-22 23:14 229376 --a------ C:\WINDOWS\system32\ieaksie.dll
2006-08-22 23:13 71680 --a------ C:\WINDOWS\system32\admparse.dll
2006-08-22 23:13 55296 --a------ C:\WINDOWS\system32\iesetup.dll
2006-08-22 23:13 54784 --a------ C:\WINDOWS\system32\ie4uinit.exe
2006-08-22 23:13 43008 --a------ C:\WINDOWS\system32\iernonce.dll
2006-08-22 23:13 152064 --a------ C:\WINDOWS\system32\ieakeng.dll
2006-08-22 23:13 122880 --a------ C:\WINDOWS\system32\advpack.dll
2006-08-22 23:13 11776 --a------ C:\WINDOWS\system32\ieudinit.exe
2006-08-22 23:11 12288 --------- C:\WINDOWS\system32\msfeedssync.exe
2006-08-22 23:10 61440 --------- C:\WINDOWS\system32\icardie.dll
2006-08-22 23:10 35328 --a------ C:\WINDOWS\system32\imgutil.dll
2006-08-22 23:09 262656 --------- C:\WINDOWS\system32\iertutil.dll
2006-08-22 23:07 45568 --a------ C:\WINDOWS\system32\mshta.exe
2006-08-22 22:37 48128 --a------ C:\WINDOWS\system32\mshtmler.dll
2006-08-22 22:36 380928 --------- C:\WINDOWS\system32\ieapfltr.dll
2006-08-22 22:30 161792 --a------ C:\WINDOWS\system32\ieakui.dll
2006-08-21 07:21 16896 --a------ C:\WINDOWS\system32\fltlib.dll
2006-08-21 04:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe
2006-08-16 06:58 100352 --a------ C:\WINDOWS\system32\6to4svc.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"AdaptecDirectCD"="C:\\Program Files\\Adaptec\\Easy CD Creator 5\\DirectCD\\DirectCD.exe"
"HP Lamp"="C:\\Program Files\\Hewlett-Packard\\HP PrecisionScan\\PrecisionScan\\HPLamp.exe"
"QBCD Autorun"="E:\\autorun.exe restart QB_SEQUENCE first"
"STOPzilla"="\"C:\\Program Files\\STOPzilla!\\Stopzilla.exe\" /autorun"
"avgnt"="\"C:\\Program Files\\AntiVir PersonalEdition Classic\\avgnt.exe\" /min"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"
"EPSON Stylus C82 Series"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_S0HIC1.EXE /P23 \"EPSON Stylus C82 Series\" /O6 \"USB001\" /M \"Stylus C82\""
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"Source"="
http://us.i1.yimg.com/us.yimg.com/i/ww/m6v8c.gif"
"SubscribedURL"="
http://us.i1.yimg.com/us.yimg.com/i/ww/m6v8c.gif"
"FriendlyName"=""
"Flags"=dword:00000001
"Position"=hex:2c,00,00,00,94,00,00,00,a0,00,00,00,e4,02,00,00,30,00,00,00,e8,\
03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:01,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,94,00,00,00,a0,00,00,00,e4,02,00,00,30,00,\
00,00,01,00,00,40
"RestoredStateInfo"=hex:dc,ff,1a,03,09,48,e9,77,88,32,e8,77,ff,ff,ff,ff,de,60,\
e7,77,60,c8,20,00
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,a0,00,00,00,01,00,00,00,80,02,00,00,3b,02,00,00,ea,\
03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:01,00,00,00
"OriginalStateInfo"=hex:18,00,00,00,a0,00,00,00,00,00,00,00,80,02,00,00,3c,02,\
00,00,04,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,a0,00,00,00,00,00,00,00,80,02,00,00,3c,02,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NVMCTRAY.DLL,NvTaskbarInit"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NVMCTRAY.DLL,NvTaskbarInit"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
"{553858A7-4922-4e7e-B1C1-97140C1C16EF}"="IE Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"CDRAutoRun"=dword:00000000
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"CDRAutoRun"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
"path"="C:\\Documents and Settings\\Administrator\\Start Menu\\Programs\\Startup\\LimeWire On Startup.lnk"
"backup"="C:\\WINDOWS\\pss\\LimeWire On Startup.lnkStartup"
"location"="Startup"
"command"="C:\\PROGRA~1\\LimeWire\\LimeWire.exe -startup"
"item"="LimeWire On Startup"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Billminder.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Billminder.lnk"
"backup"="C:\\WINDOWS\\pss\\Billminder.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\QUICKENW\\BILLMIND.EXE -startup"
"item"="Billminder"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ypager"
"hkey"="HKCU"
"command"="C:\\Program Files\\Yahoo!\\Messenger\\ypager.exe -quiet"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
backup-20051116-011819-286
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
backup-20051116-011819-549
O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone
backup-20051116-011819-137
O15 - Trusted IP range: 195.190.118.157 (HKLM)
backup-20051116-011819-475
O15 - Trusted Zone: *.searchmeup.cc (HKLM)
backup-20051116-011819-144
O15 - Trusted Zone: *.skoobidoo.com (HKLM)
backup-20051116-011819-276
O15 - Trusted Zone: *.skoobidoo.com
backup-20051116-011819-470
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://red.clientapps.yahoo.com/customize/...//www.yahoo.combackup-20051116-011819-387
R3 - Default URLSearchHook is missing
backup-20051116-011819-377
O15 - Trusted Zone: *.searchmeup.cc
backup-20051116-011819-167
O4 - HKLM\..\Run: [bxuphqj] C:\WINDOWS\System32\vqxwebw.exe r
backup-20051116-011819-562
O4 - HKCU\..\Run: [Munj] C:\WINDOWS\System32\mzg.exe
Completion time: 06-11-13 7:40:34.60
C:\ComboFix.txt ... 06-11-13 07:40