thanks again cretemonster the info you required are below but before that 2 of the 4 items you asked me to check and delete in hijackthis were not present
O4 - HKCU\..\Run: [rundll32] C:\WINDOWS\rundll.exe
O4 - HKCU\..\Run: [Ooaa] "C:\DOCUME~1\johnny\MYDOCU~1\CROSOF~1.NET\dllhost.exe" -vt yazb
here are the 3 logs you requested
1
VirusTotalVirusTotal is a free file analisys service that works using several antivirus engines.
Select file : DistributeSSL
Enter your email, choose the file to be scanned with multiple antivirus engines and click Send.Menu:
News Hot news in the virus/antivirus sector.
Estadisticas Statistics of VirusTotal procesing.
Virustotal More info about Virustotal.
STATUS: FINISHEDComplete scanning result of "wnsapiit.exe", received in VirusTotal at 10.17.2006, 18:13:07 (CET).
Antivirus Version Update Result
AntiVir 7.2.0.30 10.17.2006 no virus found
Authentium 4.93.8 10.16.2006 no virus found
Avast 4.7.892.0 10.17.2006 no virus found
AVG 386 10.17.2006 no virus found
BitDefender 7.2 10.17.2006 no virus found
CAT-QuickHeal 8.00 10.17.2006 no virus found
ClamAV devel-20060426 10.17.2006 no virus found
DrWeb 4.33 10.17.2006 no virus found
eTrust-InoculateIT 23.73.24 10.17.2006 no virus found
eTrust-Vet 30.3.3139 10.17.2006 no virus found
Ewido 4.0 10.17.2006 no virus found
Fortinet 2.82.0.0 10.17.2006 no virus found
F-Prot 3.16f 10.16.2006 no virus found
F-Prot4 4.2.1.29 10.16.2006 no virus found
Ikarus 0.2.65.0 10.17.2006 no virus found
Kaspersky 4.0.2.24 10.17.2006 no virus found
McAfee 4874 10.16.2006 no virus found
Microsoft 1.1603 10.17.2006 no virus found
NOD32v2 1.1807 10.17.2006 no virus found
Norman 5.80.02 10.16.2006 no virus found
Panda 9.0.0.4 10.17.2006 no virus found
Sophos 4.10.0 10.15.2006 no virus found
TheHacker 6.0.1.099 10.16.2006 no virus found
UNA 1.83 10.16.2006 no virus found
VBA32 3.11.1 10.17.2006 no virus found
VirusBuster 4.3.7:9 10.17.2006 no virus found
Aditional Information
File size: 2 bytes
MD5: 4f3dd0ffb3e41c5f74b5b0d8c1f10bb5
SHA1: e688cf7414fb701c4495010d43a4eaaaeac71768
VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.
> Go to: Home Contactar En Espańol
--------------------------------------------------------------------------------
www.virustotal.com :: ©Hispasec Sistemas 2004-06:: e-mail info@virustotal.com
2
johnny - 06-10-17 17:29:55.53 Service Pack 2
ComboFix 06.10.16 - Running from: "C:\"
Command switches used :: /v rnfzz
((((((((((((((((((((((((((((((( Files Created from 2006-09-17 to 2006-10-17 ))))))))))))))))))))))))))))))))))
2006-10-17 11:06 276,886 --a------ C:\combofix.exe
2006-10-16 17:23 77,824 --a------ C:\WINDOWS\system32\driverif.dll
2006-10-16 17:23 733,236 --a------ C:\WINDOWS\system32\vete.dll
2006-10-16 17:23 541,733 --a------ C:\WINDOWS\system32\drivers\vetmonnt.sys
2006-10-16 17:23 21,605 --a------ C:\WINDOWS\system32\drivers\vet-filt.sys
2006-10-16 17:23 15,668 --a------ C:\WINDOWS\system32\drivers\vet-rec.sys
2006-10-16 17:23 12,288 --a------ C:\WINDOWS\system32\vetntmsg.dll
2006-10-16 17:23 108,453 --a------ C:\WINDOWS\system32\drivers\vetfddnt.sys
2006-10-13 22:29 81,920 --a------ C:\WINDOWS\system32\SGUserInfo.dll
2006-10-13 22:29 37,224 --a------ C:\WINDOWS\system32\SageStorage.dll
2006-10-13 22:29 356,352 --a------ C:\WINDOWS\system32\SGINFMR.dll
2006-10-13 22:29 348,216 --a------ C:\WINDOWS\system32\SW9DBC32.dll
2006-10-13 22:29 253,952 --a------ C:\WINDOWS\system32\SageBankReconciliation.dll
2006-10-13 22:29 167,936 --a------ C:\WINDOWS\system32\SGXMLQry.dll
2006-10-13 22:29 143,360 --a------ C:\WINDOWS\system32\SageNatWestBankline.dll
2006-10-13 22:29 143,360 --a------ C:\WINDOWS\system32\SageBarclaysBusinessMasterII.dll
2006-10-13 22:29 139,264 --a------ C:\WINDOWS\system32\SGISAQry.dll
2006-10-13 22:29 139,264 --a------ C:\WINDOWS\system32\SageBankPayments.dll
2006-10-13 22:29 135,168 --a------ C:\WINDOWS\system32\SageNatWestOnline.dll
2006-10-13 22:29 135,168 --a------ C:\WINDOWS\system32\SageBarclaysOnline.dll
2006-10-13 22:29 127,352 --a------ C:\WINDOWS\system32\SageSoftwareUpdate.dll
2006-10-13 22:29 126,976 --a------ C:\WINDOWS\system32\SGInfProgressBar.dll
2006-10-13 22:29 126,976 --a------ C:\WINDOWS\system32\sageebanking.dll
2006-10-13 22:29 126,976 --a------ C:\WINDOWS\system32\SageBankBalances.dll
2006-10-13 22:29 119,160 --a------ C:\WINDOWS\system32\SageFolderBrowse.dll
2006-10-02 14:11 52,224 --a------ C:\WINDOWS\system32\Crypserv.exe
2006-10-02 14:11 27,648 -ra------ C:\WINDOWS\Setup_ck.exe
2006-10-02 14:11 24,608 --a------ C:\WINDOWS\system32\Ckldrv.sys
2006-10-02 14:11 18,432 --a------ C:\WINDOWS\Setup_ck.dll
2006-10-02 14:11 165,888 --a------ C:\WINDOWS\Ckconfig.exe
2006-10-02 14:11 11,776 --a------ C:\WINDOWS\Ckrfresh.exe
2006-10-01 18:08 2 --a------ C:\WINDOWS\system32\wnsapiit.exe
2006-09-27 19:52 295,952 --a------ C:\WINDOWS\SCRANTIC.SCR
2006-09-21 18:08 47,360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-10-17 16:02 -------- d-------- C:\Program Files\PacificPoker
2006-10-17 12:59 -------- d-------- C:\Documents and Settings\johnny\Application Data\Vso
2006-10-17 11:46 -------- d-------- C:\Program Files\Morpheus
2006-10-17 11:41 -------- d-------- C:\Program Files\LimeWire Acceleration Patch
2006-10-16 23:00 -------- d-------- C:\Program Files\Absolute Poker
2006-10-16 17:43 -------- d-------- C:\Program Files\Noble Poker
2006-10-16 17:36 -------- d-------- C:\Documents and Settings\johnny\Application Data\MailFrontier
2006-10-15 12:42 -------- d-------- C:\Program Files\Mystery Case Files - Prime Suspects
2006-10-13 22:30 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-10-13 22:29 -------- d-------- C:\Program Files\Sage EBanking
2006-10-13 22:29 -------- d-------- C:\Program Files\Informer50
2006-10-13 22:28 -------- d-------- C:\Program Files\Sage
2006-10-13 22:28 -------- d-------- C:\Program Files\Common Files\Sage Line50
2006-10-13 22:28 -------- d-------- C:\Program Files\Common Files
2006-10-13 14:10 -------- d-------- C:\Program Files\Common Files\Microsoft Shared
2006-10-10 18:20 -------- d-------- C:\Documents and Settings\johnny\Application Data\Morpheus
2006-10-08 18:55 -------- d-------- C:\Program Files\FinalAlert 2 Yuri's Revenge
2006-10-08 17:56 441328 --a------ C:\Documents and Settings\johnny\Application Data\NMM-MetaData.db
2006-10-06 22:20 -------- d-------- C:\Documents and Settings\johnny\Application Data\Microgaming
2006-10-06 13:34 -------- d-------- C:\Program Files\LimeWire
2006-10-05 17:37 -------- d-------- C:\Program Files\Spyware Doctor
2006-10-05 16:44 51072 --a------ C:\WINDOWS\system32\drivers\ikhlayer.sys
2006-10-05 16:44 30592 --a------ C:\WINDOWS\system32\drivers\ikhfile.sys
2006-10-04 14:42 -------- d-------- C:\Program Files\SmartDraw 7
2006-10-04 01:45 -------- d-------- C:\Documents and Settings\johnny\Application Data\dvdcss
2006-10-02 14:26 -------- d-------- C:\Program Files\Mystery Case Files Huntsville
2006-10-01 18:08 -------- d-------- C:\Documents and Settings\johnny\Application Data\ąppPatch
2006-09-29 19:18 -------- d-------- C:\Program Files\PokerTimeMPP
2006-09-27 09:27 778656 --a------ C:\WINDOWS\system32\drivers\avg7core.sys
2006-09-24 15:44 -------- d-------- C:\Program Files\ACD Systems
2006-09-21 18:22 -------- d-------- C:\Program Files\vso
2006-09-21 18:08 81920 --a------ C:\Documents and Settings\johnny\Application Data\ezpinst.exe
2006-09-21 18:08 7176 --a------ C:\Documents and Settings\johnny\Application Data\pcouffin.cat
2006-09-21 18:08 47360 --a------ C:\Documents and Settings\johnny\Application Data\pcouffin.sys
2006-09-21 18:08 34 --a------ C:\Documents and Settings\johnny\Application Data\pcouffin.log
2006-09-21 18:08 1144 --a------ C:\Documents and Settings\johnny\Application Data\pcouffin.inf
2006-09-19 13:00 -------- d---s---- C:\Documents and Settings\johnny\Application Data\Microsoft
2006-09-17 00:31 -------- d-------- C:\Program Files\American Conquest
2006-09-16 19:13 -------- d-------- C:\Program Files\Sierra
2006-09-13 16:25 -------- d-------- C:\Documents and Settings\johnny\Application Data\VSO_HWE
2006-09-13 06:01 1084416 --a------ C:\WINDOWS\system32\msxml3.dll
2006-09-10 10:24 -------- d-------- C:\Documents and Settings\johnny\Application Data\SmartDraw
2006-09-08 19:22 -------- d-------- C:\Program Files\Collectorz.com
2006-09-05 11:52 -------- d-------- C:\Program Files\e-PDF To Word Converter
2006-09-05 11:45 -------- d-------- C:\Documents and Settings\johnny\Application Data\Adobe
2006-09-05 11:36 -------- d-------- C:\Program Files\Common Files\Adobe Systems Shared
2006-09-05 11:34 -------- d-------- C:\Program Files\Common Files\Adobe
2006-08-29 12:58 -------- d-------- C:\Documents and Settings\johnny\Application Data\Nokia Multimedia Player
2006-08-29 12:57 -------- d-------- C:\Documents and Settings\johnny\Application Data\Datalayer
2006-08-28 21:01 -------- d-------- C:\Program Files\Poker.com
2006-08-28 15:32 -------- d-------- C:\Documents and Settings\johnny\Application Data\Atari
2006-08-27 20:31 -------- d-------- C:\Program Files\LDC Theory Test 2005
2006-08-25 16:45 617472 --a------ C:\WINDOWS\system32\comctl32.dll
2006-08-24 07:04 -------- d-------- C:\Documents and Settings\johnny\Application Data\AVG7
2006-08-23 23:38 75776 --a------ C:\WINDOWS\zllsputility.exe
2006-08-21 13:21 16896 --a------ C:\WINDOWS\system32\fltlib.dll
2006-08-21 10:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe
2006-08-21 10:14 128896 --a------ C:\WINDOWS\system32\drivers\fltmgr.sys
2006-08-21 09:55 -------- d-------- C:\Program Files\Flight3
2006-08-16 12:58 100352 --a------ C:\WINDOWS\system32\6to4svc.dll
2006-08-14 14:10 98304 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2006-07-27 14:24 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-07-21 09:24 72704 --a------ C:\WINDOWS\system32\hlink.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"PinnacleDriverCheck"="C:\\WINDOWS\\system32\\PSDrvCheck.exe"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
@=""
"Zone Labs Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000005
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,de,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
"Spyware Doctor"=""
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
"Spyware Doctor"=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoDispAppearancePage"=dword:00000000
"NoColorChoice"=dword:00000000
"NoSizeChoice"=dword:00000000
"NoDispBackgroundPage"=dword:00000000
"NoDispScrSavPage"=dword:00000000
"NoDispCPL"=dword:00000000
"NoVisualStyleChoice"=dword:00000000
"NoDispSettingsPage"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000000
"NoActiveDesktop"=dword:00000000
"NoSaveSettings"=dword:00000000
"ClassicShell"=dword:00000000
"NoThemesTab"=dword:00000000
"ForceActiveDesktopOn"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"DisableTaskMgr"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoActiveDesktopChanges"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Acrobat Speed Launcher.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Acrobat Speed Launcher.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\WINDOWS\\Installer\\{AC76BA86-1033-0000-7760-000000000002}\\SC_Acrobat.exe "
"item"="Adobe Acrobat Speed Launcher"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Gamma Loader.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Gamma Loader.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\COMMON~1\\Adobe\\CALIBR~1\\ADOBEG~1.EXE "
"item"="Adobe Gamma Loader"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Reader Speed Launch.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Adobe\\ACROBA~2.0\\Reader\\READER~1.EXE "
"item"="Adobe Reader Speed Launch"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ZoneAlarm Pro.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\ZoneAlarm Pro.lnk"
"backup"="C:\\WINDOWS\\pss\\ZoneAlarm Pro.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\Program Files\\Zone Labs\\ZoneAlarm\\zapro.exe -nopopup"
"item"="ZoneAlarm Pro"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^johnny^Start Menu^Programs^Startup^RollerCoaster Tycoon 3 Registration.lnk]
"path"="C:\\Documents and Settings\\johnny\\Start Menu\\Programs\\Startup\\RollerCoaster Tycoon 3 Registration.lnk"
"backup"="C:\\WINDOWS\\pss\\RollerCoaster Tycoon 3 Registration.lnkStartup"
"location"="Startup"
"command"="C:\\Documents and Settings\\johnny\\Local Settings\\Temp\\{1575BDB2-E6D6-45D8-A92F-E27FC698A11F}\\{907B4640-266B-4A21-92FB-CD1A86CD0F63}\\ATR1.exe /remind /language=ENG /PRNM=\"RollerCoaster Tycoon 3\"/PRMP=\"RCT3\"/SKUN=\"PCXX\"/GTYP=\"STRY\""
"item"="RollerCoaster Tycoon 3 Registration"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="OEMReset"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\Options\\OEMReset.exe /Audit"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Acrotray"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Distillr\\Acrotray.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AutoLoaderAproposClient]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="CXTPLS~1"
"hkey"="HKLM"
"command"="\"C:\\temp\\CXTPLS~1.EXE\" /PC=CP.CDT4 /ShowLegalNote=nonbranded /ForSupportedBrowsers /HideUninstall /HideDir"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BullsEye Network]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="bargains"
"hkey"="HKLM"
"command"="C:\\Program Files\\BullsEye Network\\bin\\bargains.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="CloneCDTray"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\SlySoft\\CloneCD\\CloneCDTray.exe\" /s"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dlkav]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="n?tdde"
"hkey"="HKCU"
"command"="C:\\Documents and Settings\\johnny\\Application Data\\?ppPatch\\n?tdde.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMprocess]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="IM-svr"
"hkey"="HKLM"
"command"="C:\\Program Files\\IM Names\\IM-svr.EXE"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Internet Optimizer]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="optimize"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Internet Optimizer\\optimize.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBt3RQd9h]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="helsink"
"hkey"="HKCU"
"command"="helsink.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Media Pass]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="MediaPassK"
"hkey"="HKLM"
"command"="C:\\Program Files\\Media Pass\\MediaPassK.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msmsgs"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="MsnMsgr"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NBJ"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Ahead\\Nero BackItUp\\NBJ.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NeroCheck"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="nwiz"
"hkey"="HKLM"
"command"="nwiz.exe /install"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="LAUNCH~1"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\Nokia\\NOKIAP~1\\LAUNCH~1.EXE -startup"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\salm]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="salm"
"hkey"="HKLM"
"command"="c:\\temp\\salm.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Skype"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="jusched"
"hkey"="HKLM"
"command"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="realsched"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VVSN]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="VVSN"
"hkey"="HKLM"
"command"="C:\\Program Files\\VVSN\\VVSN.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
Completion time: 06-10-17 17:31:37.01
C:\ComboFix.txt ... 06-10-17 17:31
C:\ComboFix2.txt ... 06-10-17 11:13
3
Scanning Report
Tuesday, October 17, 2006 17:46:27 - 18:53:24
Computer name: WHITESHOES-1
Scanning type: Scan system for viruses, rootkits, spyware
Target: C:\
--------------------------------------------------------------------------------
Result: 30 malware found
Adware.2Search (spyware)
System (Disinfected)
Adware.Pop (spyware)
System (Disinfected)
Adware.WeirWeb (spyware)
System (Disinfected)
SpyFalcon (spyware)
System (Disinfected)
Tracking Cookie (spyware)
System (Disinfected)
System
System
System
System
System
System
System
System
System
System
System
System
System
System
System
System
System
System
System
TrustCleaner (spyware)
System (Disinfected)
W32/Agent.AJAK.dropper (virus)
C:\DOCUMENTS AND SETTINGS\JOHNNY\MY DOCUMENTS\BRANDON\RANDOM MUSIC\ACCESS.EXE (Submitted)
W32/DLoader.LJP (virus)
C:\WINDOWS\DOWNLOADED PROGRAM FILES\MINICLIPGAMELOADER.DLL (Submitted)
W32/DLoader.UGN (virus)
C:\PROGRAM FILES\IM NAMES\IMNAMES.EXE (Submitted)
W32/Dialer.MWN (virus)
C:\WINDOWS\ADIRAS.EXE (Submitted)
WinAD (spyware)
System (Disinfected)
--------------------------------------------------------------------------------
Statistics
Scanned:
Files: 41517
System: 5027
Not scanned: 3
Actions:
Disinfected: 7
Renamed: 0
Deleted: 0
None: 23
Submitted: 4
Files not scanned:
C:\PAGEFILE.SYS
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT
C:\WINDOWS\SOFTWAREDISTRIBUTION\EVENTCACHE\{AAB0EEFA-873D-4378-A160-3A2D4EAF194E}.BIN
--------------------------------------------------------------------------------
Options
Scanning engines:
F-Secure AVP: 6.0.171, 2006-10-17
F-Secure Libra: 2.4.1, 2006-10-17
F-Secure Orion: 1.2.37, 2006-10-16
F-Secure Blacklight: 1.0.31, 0000-00-00
F-Secure Draco: 1.0.35, 0259-24-212
F-Secure Pegasus: 1.19.0, 2006-08-29
Scanning options:
Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB LNK WSF {* PDF ZL? XML ZIP XXX
Use Advanced heuristics
--------------------------------------------------------------------------------
Copyright © 1998-2006 Product support |Send virus sample to F-Secure
F-Secure assumes no responsibility for material created or published by third parties that F-Secure World Wide Web pages have a link to. Unless you have clearly stated otherwise, by submitting material to any of our servers, for example by E-mail or via our F-Secure's CGI E-mail, you agree that the material you make available may be published in the F-Secure World Wide Pages or hard-copy publications. You will reach F-Secure public web site by clicking on underlined links. While doing this, your access will be logged to our private access statistics with your domain name.This information will not be given to any third party. You agree not to take action against us in relation to material that you submit. Unless you have clearly stated otherwise, by submitting material you warrant that F-Secure may incorporate any concepts described in it in the F-Secure products/publications without liability.
tia