Combofix list
Pierrick - 06-09-24 17:40:39.56 Service Pack 2
ComboFix 06.09.23.2 - Running from: "C:\Documents and Settings\Pierrick\Desktop"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\ssn6tuu.exe
C:\WINDOWS\system32\VSL03.exe
C:\ucmoreiex.exe
C:\WINDOWS\unin101.exe
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Program Files\Common Files\misc001
C:\Program Files\Common Files\simtest
C:\Program Files\windows
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\QooBox\Purity\Program Files\STEM~1
C:\QooBox\Purity\Program Files\STEM~1\??stem
C:\QooBox\Purity\WINDOWS\RACLE~1
C:\QooBox\Purity\WINDOWS\RACLE~1\RACLE~1
C:\QooBox\Purity\WINDOWS\system32\ECURIT~1
C:\QooBox\Purity\WINDOWS\system32\SKS~1
C:\QooBox\Purity\WINDOWS\system32\SKS~1\c?rss.exe
((((((((((((((((((((((((((((((( Files Created from 2006-08-24 to 2006-09-24 ))))))))))))))))))))))))))))))))))
2006-09-23 18:14 17,992 --a------ C:\WINDOWS\system32\bcm42rly.sys
2006-09-17 17:56 20,480 --a------ C:\WINDOWS\system32\UnInstall_KAccess.exe
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-09-24 17:41 -------- d-a------ C:\Program Files\Common Files
2006-09-24 17:30 -------- d-------- C:\Documents and Settings\Pierrick\Application Data\Skype
2006-09-24 14:20 -------- d-------- C:\Documents and Settings\Pierrick\Application Data\Google
2006-09-24 12:33 -------- d-------- C:\Program Files\Mozilla Firefox
2006-09-24 12:20 -------- d-------- C:\Program Files\Java
2006-09-24 12:06 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-09-23 19:30 -------- d-------- C:\Program Files\Gpotato
2006-09-23 18:16 -------- d-------- C:\Program Files\Funk Software
2006-09-23 18:16 -------- d-------- C:\Program Files\Common Files\Funk Software
2006-09-23 18:14 -------- d-------- C:\Program Files\Linksys
2006-09-17 17:56 -------- d-------- C:\Program Files\KSIGN
2006-09-17 15:07 -------- d-------- C:\Program Files\Ntreev
2006-09-11 15:31 -------- d-------- C:\Program Files\GameSpy Arcade
2006-09-11 15:28 -------- d-------- C:\Program Files\Microsoft Games
2006-09-04 17:45 -------- d-------- C:\Program Files\AOL
2006-08-25 11:27 -------- d-------- C:\Program Files\Triggersoft
2006-08-25 10:11 -------- d-------- C:\Program Files\Oberon Media
2006-08-21 05:21 16896 --a------ C:\WINDOWS\system32\fltlib.dll
2006-08-21 02:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe
2006-08-21 02:14 128896 --------- C:\WINDOWS\system32\drivers\fltmgr.sys
2006-08-19 16:13 65536 --a------ C:\WINDOWS\IFinst27.exe
2006-08-19 12:27 -------- d-------- C:\Program Files\Viewpoint
2006-08-18 21:54 -------- d-------- C:\Program Files\Silkroad
2006-08-18 20:18 -------- d-------- C:\Program Files\Common Files\AOL
2006-08-18 20:15 -------- d-------- C:\Program Files\America Online 9.0a
2006-08-16 23:05 -------- d-------- C:\Program Files\ewido anti-malware
2006-08-16 07:38 -------- d-------- C:\Program Files\Internet Explorer
2006-08-15 22:55 -------- d-------- C:\Program Files\Advanced Messenger Plus
2006-08-09 04:09 -------- d-------- C:\Program Files\MSN Messenger
2006-08-09 04:09 -------- d-------- C:\Program Files\Common Files\Microsoft Shared
2006-08-09 04:08 -------- d-------- C:\Program Files\Mozilla Firefox 2 Beta 1
2006-08-09 04:07 -------- d-------- C:\Program Files\Ludiclub
2006-07-28 00:49 -------- d-------- C:\Documents and Settings\Pierrick\Application Data\Mozilla
2006-07-27 06:24 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-07-21 01:24 72704 --a------ C:\WINDOWS\system32\hlink.dll
2006-06-01 16:23 32177 ---hs---- C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"AOL Fast Start"="\"C:\\Program Files\\America Online 9.0a\\Email RemovedEXE\" -b"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RealTray"="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe SYSTEMBOOTHIDEPLAYER"
"CARPService"="carpserv.exe"
"PaperPort PTD"="C:\\Program Files\\Scansoft\\PaperPort\\pptd40nt.exe"
"IndexSearch"="C:\\Program Files\\Scansoft\\PaperPort\\IndexSearch.exe"
"VSOCheckTask"="\"c:\\PROGRA~1\\mcafee.com\\vso\\mcmnhdlr.exe\" /checktask"
"VirusScan Online"="\"c:\\PROGRA~1\\mcafee.com\\vso\\mcvsshld.exe\""
"MCAgentExe"="c:\\PROGRA~1\\mcafee.com\\agent\\mcagent.exe"
"MCUpdateExe"="c:\\PROGRA~1\\mcafee.com\\agent\\mcupdate.exe"
"RoxioEngineUtility"="\"C:\\Program Files\\Common Files\\Roxio Shared\\System\\EngUtil.exe\""
"RoxioDragToDisc"="\"C:\\Program Files\\Roxio\\Easy CD Creator 6\\DragToDisc\\DrgToDsc.exe\""
"WG511WLU"="C:\\Program Files\\NETGEAR\\WG511\\Utility\\WG511WLU.exe"
"HostManager"="C:\\Program Files\\Common Files\\AOL\\1101576836\\ee\\AOLSoftware.exe"
"AOLDialer"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"
"LIU"="C:\\Program Files\\Logitech\\QuickCam\\RUBICON.EXE"
"DXM6Patch_981116"="C:\\WINDOWS\\p_981116.exe /Q:A"
"LVComs"="C:\\WINDOWS\\system32\\LVCOMS.EXE"
"OASClnt"="C:\\Program Files\\McAfee.com\\VSO\\oasclnt.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"SynTPLpr"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"IPHSend"="C:\\Program Files\\Common Files\\AOL\\IPHSend\\IPHSend.exe"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_08\\bin\\jusched.exe\""
"CleanUp"="C:\\PROGRA~1\\McAfee.com\\Shared\\mcappins.exe /v=3 /cleanup"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Runonceex]
@=""
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000000
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="C:\\Program Files\\Messenger\\howywyw.html"
"SubscribedURL"=""
"FriendlyName"=""
"Flags"=dword:00002000
"Position"=hex:2c,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,00,00,e8,\
03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,00,14,00,00,00
"CurrentState"=hex:01,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,\
00,00,01,00,00,00
"RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\1]
"Source"="C:\\WINDOWS\\system32\\ad.html"
"SubscribedURL"=""
"FriendlyName"=""
"Flags"=dword:00002000
"Position"=hex:2c,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,00,00,ea,\
03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,00,14,00,00,00
"CurrentState"=hex:01,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,\
00,00,01,00,00,00
"RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\2]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,86,01,00,00,00,00,00,00,7a,02,00,00,e2,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,12,03,00,00,23,00,00,00,dc,00,00,00,d2,00,\
00,00,01,00,00,00
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mfuz"="C:\\PROGRA~1\\COMMON~1\\mfuz\\mfuzm.exe"
"CU1"="C:\\Program Files\\Common Files\\VCClient\\VCClient.exe"
"CU2"="C:\\Program Files\\Common Files\\VCClient\\VCMain.exe"
"Aaou"="\"C:\\PROGRA~1\\STEM~1\\iexplore.exe\" -vt yazr"
"services32"="C:\\Program Files\\Common Files\\Windows\\mc-110-12-0000325.exe"
"nrwka"="C:\\WINDOWS\\system32\\relrxa.exe reg_run"
"EQAdvice"="\"C:\\Program Files\\EQAdvice\\EQAdvice.exe\""
"Dskxah"="C:\\WINDOWS\\system32\\SKS~1\\CRSS~1.EXE"
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mfuz"="C:\\PROGRA~1\\COMMON~1\\mfuz\\mfuzm.exe"
"CU1"="C:\\Program Files\\Common Files\\VCClient\\VCClient.exe"
"CU2"="C:\\Program Files\\Common Files\\VCClient\\VCMain.exe"
"Aaou"="\"C:\\PROGRA~1\\STEM~1\\iexplore.exe\" -vt yazr"
"services32"="C:\\Program Files\\Common Files\\Windows\\mc-110-12-0000325.exe"
"nrwka"="C:\\WINDOWS\\system32\\relrxa.exe reg_run"
"EQAdvice"="\"C:\\Program Files\\EQAdvice\\EQAdvice.exe\""
"Dskxah"="C:\\WINDOWS\\system32\\SKS~1\\CRSS~1.EXE"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{54D9498B-CF93-414F-8984-8CE7FDE0D391}"="ewido shell guard"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"CDRAutoRun"=dword:00000000
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"CDRAutoRun"=dword:00000000
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\McAfee.com Scan for Viruses - My Computer (MICHAELONE-michael).job
C:\WINDOWS\tasks\McAfee.com Scan for Viruses - My Computer (MICHAELONE-Pierrick).job
Completion time: Sun 09/24/2006 17:43:03.80
ComboFix.txt
Uninstaller Manager
Ad-Aware SE Personal
Adobe Acrobat 6.0 Standard
AOL Coach Version 1.0(Build:20030807.3)
AOL Coach Version 2.0(Build:20041026.5 en)
AOL Uninstaller (Choose which Products to Remove)
ATI Display Driver
Brother MFL Pro Suite
CardRd81
CCHelp
CCScore
CleanUp!
Conexant 56K ACLink Modem
Conexant AC-Link Audio
CR2
Creative WebCam Center
Creative WebCam Instant Driver (1.00.08.0416)
DivX
Easy CD & DVD Creator 6
ESSAdpt
ESSANUP
ESSBrwr
ESSCAM
ESSCDBK
ESScore
ESSCT
ESSEMAIL
ESSgui
ESShelp
ESSini
ESSPCD
ESSPDock
ESSSONIC
ESSTUTOR
ESSvpaht
ESSvpot
ewido anti-malware
GameSpy Arcade
Google Toolbar for Internet Explorer
Google Updater
HighMAT Extension to Microsoft Windows XP CD Writing Wizard
HijackThis 1.99.1
HLPCCTR
HLPIndex
HLPPDOCK
HLPSFO
Hotfix for Windows XP (KB896344)
J2SE Runtime Environment 5.0 Update 8
Java 2 Runtime Environment, SE v1.4.2_06
Java Web Start
KSignAccessToolkit v1.0
KSU
Macromedia Flash Player 8
Macromedia Shockwave Player
McAfee SecurityCenter
McAfee VirusScan
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB886903)
Microsoft Halo Trial
Microsoft NetShow Tools 2.0
Microsoft Office 97, Professional Edition
Microsoft Outlook 97 Purchase Requests Form (Remove only)
Mozilla Firefox (1.5.0.7)
MSXML 4.0 SP2 Parser and SDK
NETGEAR WG511 54 Mbps Wireless PC Card
Netscape (7.2)
Notifier
Odyssey Client
OfotoXMI
OTtBP
OTtBPSDK
Panda ActiveScan
PaperPort 8.0 SE
PCDLNCH
Quicklinks
QuickTime
RealPlayer Basic
Rose Online
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
SFR
SFR2
Skype 2.5
SpaceCowboy
Synaptics Pointing Device Driver
TricksterEng
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB900930)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
VCAMCEN
Viewpoint Media Player
VPRINTOL
WildTangent Web Driver
Windows Genuine Advantage v1.3.0254.0
Windows Installer 3.1 (KB893803)
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB834707
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
Wireless-G Notebook Adapter
X Access
Yazzle by OIN