Ok, I am back. The following logs are here
Combofix
Panda
Hijack
"Alec" - 2007-06-29 23:26:52 - ComboFix 07-06-28.4 - Service Pack 2 NTFS
Command switches used :: C:\Documents and Settings\Alec\Desktop\ComboFix-Do.txt
((((((((((((((((((((((((( Files Created from 2007-05-28 to 2007-06-30 )))))))))))))))))))))))))))))))
2007-06-29 17:31 <DIR> d-------- C:\Program Files\WinAVI Video Converter
2007-06-29 17:28 <DIR> d-------- C:\Program Files\RADVideo
2007-06-29 15:57 <DIR> d-------- C:\WINDOWS\LastGood
2007-06-29 15:56 <DIR> d-------- C:\Program Files\Windows Live
2007-06-29 15:56 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\WindowsLiveInstaller
2007-06-29 15:55 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
2007-06-28 11:08 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-06-28 00:10 59,427 --a------ C:\WINDOWS\system32\tmp1390.tmp.dll
2007-06-27 21:38 134,917 --a------ C:\WINDOWS\awtqqq.dll
2007-06-27 21:06 <DIR> d-------- C:\Deckard
2007-06-27 21:01 59,427 --a------ C:\WINDOWS\system32\tmp12FE.tmp.dll
2007-06-27 19:48 <DIR> d-------- C:\ie-spyad
2007-06-27 19:21 <DIR> d-------- C:\Program Files\SpywareBlaster
2007-06-27 16:25 59,427 --a------ C:\WINDOWS\system32\tmp415.tmp.dll
2007-06-27 16:21 134,917 --a------ C:\WINDOWS\xxywur.dll
2007-06-27 15:52 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2007-06-27 15:37 134,917 --a------ C:\WINDOWS\gebbxx.dll
2007-06-27 12:20 59,427 --a------ C:\WINDOWS\system32\tmp3B.tmp.dll
2007-06-27 11:56 59,427 --a------ C:\WINDOWS\system32\tmp25.tmp.dll
2007-06-27 11:37 59,427 --a------ C:\WINDOWS\system32\tmp1E.tmp.dll
2007-06-27 11:12 49,252 --a------ C:\WINDOWS\system32\ddccy.exe
2007-06-27 10:51 49,252 --a------ C:\WINDOWS\system32\gebcy.exe
2007-06-27 10:44 59,427 --a------ C:\WINDOWS\system32\tmp7D.tmp.dll
2007-06-27 09:37 59,427 --a------ C:\WINDOWS\system32\tmp61.tmp.dll
2007-06-27 09:24 59,427 --a------ C:\WINDOWS\system32\tmp49.tmp.dll
2007-06-27 09:19 49,252 --a------ C:\WINDOWS\system32\gebyw.exe
2007-06-26 22:33 135,052 --a------ C:\WINDOWS\pmnkih.dll
2007-06-26 21:57 59,480 --a------ C:\WINDOWS\system32\tmp30F.tmp.dll
2007-06-26 21:25 59,480 --a------ C:\WINDOWS\system32\tmp306.tmp.dll
2007-06-26 20:48 59,480 --a------ C:\WINDOWS\system32\tmp2EE.tmp.dll
2007-06-26 20:42 49,252 --a------ C:\WINDOWS\system32\mljjk.exe
2007-06-26 20:19 135,052 --a------ C:\WINDOWS\vttssp.dll
2007-06-26 19:31 59,480 --a------ C:\WINDOWS\system32\tmp23A.tmp.dll
2007-06-26 18:33 59,480 --a------ C:\WINDOWS\system32\tmp1A2.tmp.dll
2007-06-26 17:13 59,480 --a------ C:\WINDOWS\system32\tmp15A.tmp.dll
2007-06-26 15:44 59,480 --a------ C:\WINDOWS\system32\tmp132.tmp.dll
2007-06-26 11:49 59,480 --a------ C:\WINDOWS\system32\tmpB0.tmp.dll
2007-06-26 11:24 59,480 --a------ C:\WINDOWS\system32\tmpA4.tmp.dll
2007-06-26 10:48 <DIR> d-------- C:\Program Files\SuperAdBlocker.com
2007-06-26 10:48 <DIR> d-------- C:\DOCUME~1\Alec\APPLIC~1\SuperAdBlocker.com
2007-06-26 10:41 <DIR> d-------- C:\Program Files\NoAdware5.0
2007-06-26 10:34 59,480 --a------ C:\WINDOWS\system32\tmp34.tmp.dll
2007-06-26 09:39 59,480 --a------ C:\WINDOWS\system32\tmp21.tmp.dll
2007-06-26 09:34 49,252 --a------ C:\WINDOWS\system32\pmkhi.exe
2007-06-25 23:07 49,252 --a------ C:\WINDOWS\system32\jkhhi.exe
2007-06-25 22:40 49,252 --a------ C:\WINDOWS\system32\vturs.exe
2007-06-25 21:44 135,052 --a------ C:\WINDOWS\geedeb.dll
2007-06-25 21:07 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-06-25 18:15 135,052 --a------ C:\WINDOWS\tuvtqo.dll
2007-06-25 17:38 135,052 --a------ C:\WINDOWS\xxxuvs.dll
2007-06-25 17:38 135,052 --a------ C:\WINDOWS\vttqpo.dll
2007-06-25 16:23 <DIR> d-------- C:\WINDOWS\McAfee.com
2007-06-25 15:40 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2007-06-25 13:44 <DIR> d-------- C:\WINDOWS\pss
2007-06-25 12:45 <DIR> d-------- C:\Program Files\Roguescanfix
2007-06-25 12:05 135,052 --a------ C:\WINDOWS\mlkklm.dll
2007-06-25 12:00 <DIR> d-------- C:\DOCUME~1\LOCALS~1\APPLIC~1\SiteAdvisor
2007-06-25 11:59 <DIR> d-------- C:\Program Files\SiteAdvisor
2007-06-25 11:59 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SiteAdvisor
2007-06-25 11:59 <DIR> d-------- C:\DOCUME~1\Alec\APPLIC~1\SiteAdvisor
2007-06-25 11:58 143,360 --a------ C:\WINDOWS\system32\dunzip32.dll
2007-06-25 11:56 71,496 --a------ C:\WINDOWS\system32\drivers\mfeavfk.sys
2007-06-25 11:56 37,480 --a------ C:\WINDOWS\system32\drivers\mfesmfk.sys
2007-06-25 11:56 34,184 --a------ C:\WINDOWS\system32\drivers\mfebopk.sys
2007-06-25 11:56 32,008 --a------ C:\WINDOWS\system32\drivers\mferkdk.sys
2007-06-25 11:56 170,408 --a------ C:\WINDOWS\system32\drivers\mfehidk.sys
2007-06-25 11:55 109,608 --a------ C:\WINDOWS\system32\drivers\Mpfp.sys
2007-06-25 11:55 <DIR> d-------- C:\Program Files\McAfee.com
2007-06-25 11:54 <DIR> d-------- C:\Program Files\McAfee
2007-06-25 11:54 <DIR> d-------- C:\Program Files\Common Files\McAfee
2007-06-24 22:49 <DIR> d-------- C:\SDAT
2007-06-24 22:45 18,658,085 --a------ C:\sdat5059.exe
2007-06-24 22:37 4,020 --a------ C:\WINDOWS\system32\tmp.reg
2007-06-24 22:25 557,056 --a------ C:\DOCUME~1\Alec\GoToAssist_phone__320_en.exe
2007-06-13 16:11 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\acccore
2007-06-13 16:09 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Contacts
2007-06-11 21:13 <DIR> d--hs---- C:\WINDOWS\CSC
2007-06-02 22:09 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-06-02 17:58 <DIR> d-------- C:\Program Files\Symantec AntiVirus
2007-06-02 17:58 <DIR> d-------- C:\Program Files\Symantec
2007-06-02 17:58 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2007-06-02 17:58 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
2007-05-30 20:24 <DIR> d-------- C:\DOCUME~1\Alec\APPLIC~1\McAfee
2007-05-30 19:40 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-05-30 18:19 59,480 --a------ C:\WINDOWS\system32\tmp97.tmp.dll
2007-05-30 16:41 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-05-30 16:41 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-05-30 16:41 <DIR> d-------- C:\DOCUME~1\Alec\APPLIC~1\SUPERAntiSpyware.com
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-06-29 15:42:40 -------- d-----w C:\Program Files\Google
2007-06-29 15:40:00 -------- d-----w C:\Program Files\Digital Line Detect
2007-06-29 15:40:00 -------- d-----w C:\Program Files\DellSupport
2007-06-29 15:29:13 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-06-29 15:22:00 -------- d-----w C:\Program Files\Dell
2007-06-29 15:21:21 -------- d-----w C:\Program Files\AIM
2007-06-29 15:21:05 -------- d-----w C:\DOCUME~1\Alec\APPLIC~1\Aim
2007-06-28 21:19:47 115,200 ----a-w C:\outsound.bin
2007-06-28 02:11:44 4,548 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2007-06-28 02:11:42 56 --sh--r C:\WINDOWS\system32\F3C9371233.sys
2007-06-27 21:23:54 -------- d-----w C:\Program Files\AIM6
2007-06-25 21:33:06 -------- d-----w C:\Program Files\Stardock
2007-06-25 21:28:21 -------- d-----w C:\Program Files\GhostSurf 2005
2007-06-25 21:18:21 -------- d-----w C:\Program Files\Common Files\Real
2007-06-25 03:42:15 -------- d-----w C:\Program Files\mIRC
2007-06-25 03:18:29 -------- d-----w C:\Program Files\GameSpy Arcade
2007-05-30 21:56:08 -------- d-----w C:\Program Files\LimeWire
2007-05-30 21:08:26 384 ----a-w C:\DOCUME~1\Alec\APPLIC~1\internaldb6334.dat
2007-05-30 20:36:44 194 ----a-w C:\DOCUME~1\Alec\APPLIC~1\internaldb8467.dat
2007-05-30 20:36:44 18,432 ----a-w C:\DOCUME~1\Alec\APPLIC~1\internaldb41.dat
2007-05-29 21:43:46 -------- d-----w C:\Program Files\VstPlugins
2007-05-29 21:42:28 -------- d-----w C:\Program Files\Image-Line
2007-05-29 21:18:15 -------- d-----w C:\Program Files\Common Files\Download Manager
2007-05-25 01:45:05 -------- d-----w C:\Program Files\MUSICMATCH
2007-05-19 01:01:20 -------- d-----w C:\DOCUME~1\Alec\APPLIC~1\Lavasoft
2007-05-18 01:45:36 -------- d-----w C:\Program Files\Microsoft Games
2007-05-17 17:09:54 51,568 ----a-w C:\WINDOWS\system32\sirenacm.dll
2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-12 15:51:21 -------- d-----w C:\Program Files\Microsoft Easy Assist
2007-04-26 00:15:44 182,745 ----a-w C:\WINDOWS\4-efb7bab6499fc415ee93f4097033deae.exe
2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-17 02:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-17 02:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 02:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 02:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 02:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 02:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 02:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 02:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-04-17 02:44:20 271,224 ----a-w C:\WINDOWS\system32\mucltui.dll
2007-04-17 02:44:18 208,248 ----a-w C:\WINDOWS\system32\muweb.dll
2007-04-03 19:12:42 513,152 ----a-w C:\WINDOWS\system32\WmaCDriverV32.sys
2007-03-17 14:30:56 56 --sh--r C:\WINDOWS\system32\5CF562FE09.sys
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{00000000-6C30-11D8-9363-000AE6309654}=C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABBHO.dll [2007-06-05 09:38]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-23 02:20 C:\WINDOWS\stsystra.exe]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 18:19]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 15:57]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 12:44]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 12:44]
"Corel Photo Downloader"="C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe" [2005-08-31 13:06]
"nwiz"="nwiz.exe" [2006-10-22 12:22 C:\WINDOWS\system32\nwiz.exe]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-05-14 16:41]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"MskAgentexe"="C:\Program Files\McAfee\MSK\MskAgent.exe" [2007-01-17 16:30]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6066\SiteAdv.exe" [2007-03-30 11:42]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 07:00]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-02-06 21:54]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-05-17 13:11]
"Aim6"="" []
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 11:09]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-03-27 15:22]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
"SuperAdBlocker"="C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SAdBlock.exe" [2007-06-05 09:41]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"=Narrator.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoDispAppearancePage"=0 (0x0)
"NoColorChoice"=0 (0x0)
"NoSizeChoice"=0 (0x0)
"NoDispBackgroundPage"=0 (0x0)
"NoDispScrSavPage"=0 (0x0)
"NoDispCPL"=0 (0x0)
"NoVisualStyleChoice"=0 (0x0)
"NoDispSettingsPage"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoActiveDesktopChanges"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSaveSettings"=0 (0x0)
"NoThemesTab"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"="C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 13:55]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000D7}"="C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABSEHB.DLL" [2006-11-07 12:58]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SABWinLogon]
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
AutoRun\command- D:\launcher\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
AutoRun\command- E:\setup.exe
*Newly Created Service* - USNJSVC
*Newly Created Service* - WLSETUPSVC
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\KB910393
rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\EasyCDBlock.inf,PerUserInstall
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{407408d4-94ed-4d86-ab69-a7f649d112ee}
%SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection QuickLaunchShortcut 640 %systemroot%\inf\mcdftreg.inf
Contents of the 'Scheduled Tasks' folder
2007-06-25 15:55:31 C:\WINDOWS\tasks\McDefragTask.job
2007-06-25 15:55:28 C:\WINDOWS\tasks\McQcTask.job
**************************************************************************
catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-06-29 23:31:18
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
Completion time: 2007-06-29 23:32:43
C:\ComboFix-quarantined-files.txt ... 2007-06-29 23:32
C:\ComboFix2.txt ... 2007-06-28 11:36
--- E O F ---
Incident Status Location
Potentially unwanted tool:application/funweb Not disinfected hkey_local_machine\software\Fun Web Products
Potentially unwanted tool:application/mywebsearch Not disinfected hkey_classes_root\clsid\{A4730EBE-43A6-443e-9776-36915D323AD3}
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Alec\Cookies\alec@2o7[1].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Alec\Cookies\alec@ad.yieldmanager[2].txt
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Alec\Cookies\alec@advertising[1].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Alec\Cookies\alec@atdmt[2].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Alec\Cookies\alec@atwola[1].txt
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Alec\Cookies\alec@casalemedia[2].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Alec\Cookies\alec@com[1].txt
Spyware:Cookie/Date Not disinfected C:\Documents and Settings\Alec\Cookies\alec@date[1].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Alec\Cookies\alec@doubleclick[1].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Alec\Cookies\alec@drivecleaner[2].txt
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Alec\Cookies\alec@errorsafe[2].txt
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Alec\Cookies\alec@fastclick[2].txt
Spyware:Cookie/Findwhat Not disinfected C:\Documents and Settings\Alec\Cookies\alec@findwhat[1].txt
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Alec\Cookies\alec@mediaplex[1].txt
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Alec\Cookies\alec@searchportal.information[1].txt
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Alec\Cookies\alec@statcounter[1].txt
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Alec\Cookies\alec@stats1.reliablestats[1].txt
Spyware:Cookie/Systemdoctor Not disinfected C:\Documents and Settings\Alec\Cookies\alec@systemdoctor[1].txt
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Alec\Cookies\alec@winantivirus[1].txt
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Alec\Cookies\alec@www.errorsafe[1].txt
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Documents and Settings\Alec\Desktop\ComboFix.exe[nircmd.exe]
Adware:Adware/WebSearch Not disinfected C:\QooBox\Quarantine\C\WINDOWS\system32\tmp10C.tmp.dll.vir
Spyware:Spyware/Vundo Not disinfected C:\QooBox\Quarantine\catchme2007-06-29_233117.79.zip[geedeb.dll]
Spyware:Spyware/Vundo Not disinfected C:\QooBox\Quarantine\catchme2007-06-29_233117.79.zip[mlkklm.dll]
Spyware:Spyware/Vundo Not disinfected C:\QooBox\Quarantine\catchme2007-06-29_233117.79.zip[pmnkih.dll]
Spyware:Spyware/Vundo Not disinfected C:\QooBox\Quarantine\catchme2007-06-29_233117.79.zip[tuvtqo.dll]
Spyware:Spyware/Vundo Not disinfected C:\QooBox\Quarantine\catchme2007-06-29_233117.79.zip[vttqpo.dll]
Spyware:Spyware/Vundo Not disinfected C:\QooBox\Quarantine\catchme2007-06-29_233117.79.zip[vttssp.dll]
Spyware:Spyware/Vundo Not disinfected C:\QooBox\Quarantine\catchme2007-06-29_233117.79.zip[xxxuvs.dll]
Adware:Adware/eZula Not disinfected C:\WINDOWS\4-efb7bab6499fc415ee93f4097033deae.exe[²ΡΗ]
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\WINDOWS\nircmd.exe
Logfile of HijackThis v1.99.1
Scan saved at 5:37:39 PM, on 7/1/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABSVC.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\OpenSA\Apache2\bin\Apache.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\OpenSA\Apache2\bin\Apache.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\SiteAdvisor\6066\SAService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\McAfee\MSK\MskAgent.exe
C:\Program Files\SiteAdvisor\6066\SiteAdv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SAdBlock.exe
C:\Program Files\Sandisk\Common\Bin\WinCinemaMgr.exe
c:\program files\common files\installshield\updateservice\isuspm.exe
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe
C:\Program Files\NETGEAR\WG111v2 Configuration Utility\RtWLan.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\program files\aim6\anotify.exe
C:\Program Files\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: SuperAdBlockerBHO Class - {00000000-6C30-11D8-9363-000AE6309654} - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABBHO.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O3 - Toolbar: Super Ad Blocker Toolbar - {B4B3001E-0F56-4E51-8250-BDE11547EC55} - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\sabtb.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6066\SiteAdv.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [SuperAdBlocker] C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SAdBlock.exe
O4 - Global Startup: WinCinema Manager.lnk = C:\Program Files\Sandisk\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: WG111v2 Smart Wizard Wireless Setting.lnk = ?
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) -
https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} -
http://www.fileplanet.com/fpdlmgr/ca..._2.3.2.100.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsof...?1173546185312
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) -
https://rtc4.webresponse.one.microso.../TLIEFlash.CAB
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/actives...ree/asinst.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/ge...sh/swflash.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) -
https://aimprods01.webex.com/client/...ex/ieatgpc.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) -
http://download.mcafee.com/molbin/is...59/mcfscan.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O20 - Winlogon Notify: !SABWinLogon - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABWINLO.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: McAfee Application Installer Cleanup (0053331183323682) (0053331183323682mcinstcleanup) - Unknown owner - C:\WINDOWS\TEMP\005333~1.EXE (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apache2 - Unknown owner - C:\OpenSA\Apache2\bin\Apache.exe" -k runservice (file missing)
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Super Ad Blocker Service (SABSVC) - SuperAdBlocker.com - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABSVC.EXE
O23 - Service: SiteAdvisor Service - McAfee, Inc. - C:\Program Files\SiteAdvisor\6066\SAService.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe