"kenneth fiddy" - 07-03-19 21:44:22 Service Pack 2
ComboFix 07-03-15.2 - Running from: "C:\Documents and Settings\kenneth fiddy\Desktop"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files\InetGet2\apcsetup.exe
C:\DOCUME~1\LOCALS~1\APPLIC~1\NetMon
C:\Program Files\Common Files\{30E08~1
C:\Program Files\Common Files\{B0E08~4
C:\Program Files\Common Files\{B0E08~3
C:\Program Files\Common Files\{B0E08~2
C:\Program Files\Common Files\{B0E08~1
C:\Program Files\InetGet2
C:\Program Files\outlook
C:\Program Files\winupdates
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\DOCUME~1
C:\qoobox\purity\DOCUME~1\KENNET~1
C:\qoobox\purity\DOCUME~1\KENNET~1\APPLIC~1
C:\qoobox\purity\DOCUME~1\KENNET~1\APPLIC~1\FNTS~1
C:\qoobox\purity\DOCUME~1\KENNET~1\APPLIC~1\from.txt
C:\qoobox\purity\Program Files\PPPATC~1
C:\qoobox\purity\Program Files\SSEMBL~1
C:\qoobox\purity\WINDOWS\SMBOLS~1
C:\qoobox\purity\WINDOWS\SMBOLS~1\attrib.exe
C:\qoobox\purity\WINDOWS\SMBOLS~1\s?mbols
C:\qoobox\purity\WINDOWS\SMBOLS~1\s?mbols\ctxad-546.0000
C:\qoobox\purity\WINDOWS\SMBOLS~1\s?mbols\ctxad-546.0001
C:\qoobox\purity\WINDOWS\SMBOLS~1\s?mbols\ctxad-546.0002
C:\qoobox\purity\WINDOWS\SMBOLS~1\s?mbols\ctxad-546.0003
C:\qoobox\purity\WINDOWS\SMBOLS~1\s?mbols\ctxad-546.0004
C:\qoobox\purity\WINDOWS\SMBOLS~1\s?mbols\ctxad-546.0005
C:\qoobox\purity\WINDOWS\SMBOLS~1\s?mbols\ctxad-546.0006
((((((((((((((((((((((((((((((( Files Created from 2007-02-19 to 2007-03-19 ))))))))))))))))))))))))))))))))))
2007-03-18 22:29 <DIR> d-------- C:\DOCUME~1\KENNET~1\APPLIC~1\Leadertech
2007-03-18 22:28 <DIR> d-------- C:\Program Files\Executive Software
2007-03-18 22:16 49,152 --a------ C:\WINDOWS\InstFunc.exe
2007-03-18 22:16 337,320 --a------ C:\WINDOWS\difxapi.dll
2007-03-18 22:16 12,288 --a------ C:\WINDOWS\InstFunc.dll
2007-03-18 22:02 <DIR> d-------- C:\DOCUME~1\KENNET~1\APPLIC~1\Sun
2007-03-18 21:26 <DIR> d-------- C:\Program Files\Lavasoft
2007-03-18 21:26 <DIR> d-------- C:\DOCUME~1\KENNET~1\APPLIC~1\Lavasoft
2007-03-17 00:16 79,360 --a------ C:\WINDOWS\system32\swxcacls.exe
2007-03-17 00:16 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-03-17 00:16 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-03-17 00:16 40,960 --a------ C:\WINDOWS\system32\swsc.exe
2007-03-17 00:16 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-03-17 00:16 135,168 --a------ C:\WINDOWS\system32\swreg.exe
2007-03-16 23:47 2,464 --a------ C:\WINDOWS\system32\tmp.reg
2007-03-15 22:29 <DIR> d-------- C:\DOCUME~1\ADMINI~1\WINDOWS
2007-03-15 22:29 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\CyberLink
2007-03-15 22:28 786,432 --a------ C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-03-06 10:41 <DIR> d-------- C:\DOCUME~1\KENNET~1\APPLIC~1\LimeWire
2007-03-03 13:22 <DIR> d-------- C:\Program Files\Java
2007-03-03 13:18 <DIR> d-------- C:\Program Files\Common Files\Java
2007-03-03 11:06 335 --a------ C:\WINDOWS\nsreg.dat
2007-03-03 09:28 <DIR> d-------- C:\DOCUME~1\LOCALS~1\APPLIC~1\Adobe
2007-03-01 20:55 <DIR> d-------- C:\372d40043214ac390891bb43a52fba3d
2007-03-01 20:44 90,112 --a------ C:\DOCUME~1\KENNET~1\smsc.exe
2007-03-01 20:40 203,149 --a------ C:\DOCUME~1\KENNET~1\sm.exe
2007-03-01 20:29 63 --a------ C:\WINDOWS\system32\yyd.bat
2007-03-01 20:28 75 --a------ C:\WINDOWS\system32\n.bat
2007-03-01 20:28 45,358 --a------ C:\WINDOWS\system32\x.dat
2007-03-01 20:28 35,328 --a------ C:\WINDOWS\system32\xtz.exe
2007-02-27 13:05 63 --a------ C:\DOCUME~1\VIVIEN~1\yyd.bat
2007-02-27 13:05 <DIR> d-------- C:\DOCUME~1\VIVIEN~1\APPLIC~1\MSN6
2007-02-27 13:04 75 --a------ C:\DOCUME~1\VIVIEN~1\n.bat
2007-02-27 13:04 35,328 --a------ C:\DOCUME~1\VIVIEN~1\xtz.exe
2007-02-27 13:03 90,112 --a------ C:\DOCUME~1\VIVIEN~1\smsc.exe
2007-02-27 13:03 0 --a------ C:\DOCUME~1\VIVIEN~1\x.dat
2007-02-27 13:00 203,149 --a------ C:\DOCUME~1\VIVIEN~1\sm.exe
2007-02-26 21:31 771 --a------ C:\DOCUME~1\KENNET~1\x.dat
2007-02-26 21:31 77 --a------ C:\DOCUME~1\KENNET~1\n.bat
2007-02-26 21:31 63 --a------ C:\DOCUME~1\KENNET~1\yyd.bat
2007-02-26 21:30 35,328 --a------ C:\DOCUME~1\KENNET~1\xtz.exe
2007-02-19 20:53 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-03-16 00:50 -------- d--h----- C:\Program Files\installshield installation information
2007-03-03 19:32 -------- d--h----- C:\Program Files\Common Files\uninstall information
2007-02-27 11:16 -------- d-------- C:\Program Files\lexmark x1100 series
2007-02-19 20:50 -------- d-------- C:\Program Files\pceye2000
2007-02-19 20:42 -------- d-------- C:\Program Files\Common Files\teleca shared
2007-02-05 19:07 147456 --a------ C:\WINDOWS\system32\vbzip10.dll
2007-02-03 15:06 -------- d-------- C:\Program Files\storehelp
2007-02-03 12:46 0 --a------ C:\WINDOWS\system32\taskkill.exe
2007-01-23 04:56 16896 --a------ C:\WINDOWS\system32\drivers\srvkp.sys
2007-01-23 04:55 1571001 --a------ C:\WINDOWS\system32\sisgl.dll
2007-01-23 04:39 3514368 --a------ C:\WINDOWS\system32\sisgrv.dll
2007-01-23 04:35 317952 --a------ C:\WINDOWS\system32\drivers\sisgrp.sys
2007-01-23 04:34 9728 --a------ C:\WINDOWS\system32\sispins2.dll
2007-01-23 04:32 49152 --a------ C:\WINDOWS\system32\sisbase.dll
2007-01-23 04:32 258048 --a------ C:\WINDOWS\system32\sisparse.dll
2007-01-23 04:32 172032 --a------ C:\WINDOWS\system32\sisinst.dll
2007-01-08 19:01 17408 --a------ C:\WINDOWS\system32\corpol.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SoundMan"="SOUNDMAN.EXE"
"RemoteControl"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""
"Lexmark X1100 Series"="\"C:\\Program Files\\Lexmark X1100 Series\\lxbkbmgr.exe\""
"McafWelcome"="C:\\Program Files\\McAfee.com\\Agent\\mcwelcom.exe"
"Adobe Photo Downloader"="\"C:\\Program Files\\Adobe\\Photoshop Album Starter Edition\\3.0\\Apps\\apdproxy.exe\""
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"SpeedTouch USB Diagnostics"="\"C:\\Program Files\\Thomson\\SpeedTouch USB\\Dragdiag.exe\" /icon"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_10\\bin\\jusched.exe\""
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Power2GoExpress"="\"C:\\Program Files\\CyberLink\\Power2Go\\Power2GoExpress.exe\""
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
********************************************************************
catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.netscanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-03-19 21:47:20
Logfile of HijackThis v1.99.1
Scan saved at 21:55:29, on 19/03/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Documents and Settings\kenneth fiddy\Desktop\removal programs\HJK\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [McafWelcome] C:\Program Files\McAfee.com\Agent\mcwelcom.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.iqon.ie
O16 - DPF: RaptisoftGameLoader -
http://www.miniclip.com/hamsterball/raptisoftgameloader.cabO20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
Its running very sweet for a Celery 2.2ghz
sorry did not mean to say that ,it slipped out
thanks for your continued support