Let me begin by thanking you both once again for your continued assistance. I appreciate your checking my previous logs for residual hadardous material. Wisperer, I completed your latest HijackThis recommendations and thanks for the extra knowledge regarding my local resource hogs. FYI, I use DirectCD only to read CDs created by other unsuspecting DirectCD users, not for my own CD creation.
As for the firewall bit, I've also done some research on problems related to a disabled Windows Firewall and found evidence of missing files, which I'll continue to troubleshoot via Microsoft Knowledge Base. I am open to acquiring another software firewall but I thought the following is first worth mentioning: I recently put into a commission a Netgear ProSafe VPN Firewall (FVS124G) which touts a robust firewall. With regard to this, should I still continue down the avenue of additional software firewall?
OK Navigator, now on with your latest prescription. I've completed your recommended tasks, including re-running combofix. The logs are below:
AVG report:
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 2:54:41 PM 11/6/2006
+ Scan result:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Antispyware Soldier_is1 -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00110011-4B0B-44D5-9718-90C88817369B} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{086AE192-23A6-48D6-96EC-715F53797E85} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11904CE8-632A-4856-A7CC-00B33FE71BD8} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{150FA160-130D-451F-B863-B655061432BA} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{17DA0C9E-4A27-4AC5-BB75-5D24B8CDB972} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1C4DA27D-4D52-4465-A089-98E01BB725CA} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1F48AA48-C53A-4E21-85E7-AC7CC6B5FFB1} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1F48AA48-C53A-4E21-85E7-AC7CC6B5FFB2} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{202A961F-23AE-42B1-9505-FFE3C818D717} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2D38A51A-23C9-48A1-A33C-48675AA2B494} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2E246FAE-8420-11D9-870D-000C2917DE7F} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2E9CAFF6-30C7-4208-8807-E79D4EC6F806} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{479FD0CF-5BE9-4C63-8CDA-B6D371C67BD5} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5753791B-F607-48CA-814E-91C14D081F9E} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7070A8F9-08A4-CA47-0AB0-1EB9E4EE1F3B} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{746455FE-D059-47E7-AF0E-140E03F5A447} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{860C2F6B-CA82-4282-9187-BECCBB66F0AF} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{87185E78-A61B-4DB3-965A-3235BBD7A622} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8DC8F96D-34F7-1501-A2A4-631341AA3AC1} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9C5875B8-93F3-429D-FF34-660B206D897A} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A2595F37-48D0-46A1-9B51-478591A97764} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A6F42CAD-2559-48DF-AF30-89E480AF5DFA} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CA0E28FA-1AFD-4C21-A8DC-70EB5BE2F076} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CF021F40-3E14-23A5-CBA2-717765721306} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D1AC752E-883F-4ED8-8828-B618C3A72152} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E2B2B5A1-B48C-4886-A318-723916A01024} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E2DDF680-9905-4DEE-8C64-0A5DE7FE133C} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E3EEBBE8-9CAB-4C76-B26A-747E25EBB4C6} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E6D5237D-A6C7-4C83-A67F-F9F15586FA62} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E7AFFF2A-1B57-49C7-BF6B-E5123394C970} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FCADDC14-BD46-408A-9842-CDBE1C6D37EB} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD9BC004-8331-4457-B830-4759FF704C22} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FE2D25C1-C1DB-4B5E-9390-AF1CB5302F32} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FF1BF4C7-4E08-4A28-A43F-9D60A9F7A880} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF} -> Adware.Generic : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpywareSheriff_is1 -> Adware.SpywareSheriff : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7A7E6D97-B492-4884-9ABB-C31281DCC4F2} -> Adware.VipSearcher : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1B68470C-2DEF-493B-8A4A-8E2D81BE4EA5} -> Downloader.Delf : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{15ACE85C-0BB1-42D1-9E32-07EB0506675A} -> Downloader.Small.nl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{10D46C47-9CC4-4020-9B0D-DBC231C1AA72}\RP1204\A0095547.exe -> Downloader.Tibs.ir : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{10D46C47-9CC4-4020-9B0D-DBC231C1AA72}\RP1201\A0093369.exe -> Downloader.VB.apa : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{10D46C47-9CC4-4020-9B0D-DBC231C1AA72}\RP1204\A0095549.exe -> Downloader.VB.apa : Cleaned with backup (quarantined).
C:\Documents and Settings\Bob's Photo\Cookies\bob's photo@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Bob's Photo\Cookies\bob's photo@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Bob's Photo\Cookies\bob's photo@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\Bob's Photo\Cookies\bob's photo@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.15:C:\Documents and Settings\Bob's Photo\Application Data\Mozilla\Profiles\default\of0zc65i.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.16:C:\Documents and Settings\Bob's Photo\Application Data\Mozilla\Profiles\default\of0zc65i.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.17:C:\Documents and Settings\Bob's Photo\Application Data\Mozilla\Profiles\default\of0zc65i.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.18:C:\Documents and Settings\Bob's Photo\Application Data\Mozilla\Profiles\default\of0zc65i.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.11:C:\Documents and Settings\Bob's Photo\Application Data\Mozilla\Profiles\default\of0zc65i.slt\cookies.txt -> TrackingCookie.Sextracker : Cleaned.
:mozilla.12:C:\Documents and Settings\Bob's Photo\Application Data\Mozilla\Profiles\default\of0zc65i.slt\cookies.txt -> TrackingCookie.Sextracker : Cleaned.
:mozilla.13:C:\Documents and Settings\Bob's Photo\Application Data\Mozilla\Profiles\default\of0zc65i.slt\cookies.txt -> TrackingCookie.Sextracker : Cleaned.
:mozilla.14:C:\Documents and Settings\Bob's Photo\Application Data\Mozilla\Profiles\default\of0zc65i.slt\cookies.txt -> TrackingCookie.Sextracker : Cleaned.
:mozilla.19:C:\Documents and Settings\Bob's Photo\Application Data\Mozilla\Profiles\default\of0zc65i.slt\cookies.txt -> TrackingCookie.Sextracker : Cleaned.
:mozilla.25:C:\Documents and Settings\Bob's Photo\Application Data\Mozilla\Profiles\default\of0zc65i.slt\cookies.txt -> TrackingCookie.Sextracker : Cleaned.
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B212D577-05B7-4963-911E-4A8588160DFA} -> Trojan.Delf.nj : Cleaned with backup (quarantined).
C:\WINDOWS\system32\msmapi32.exe -> Trojan.VB.atw : Cleaned with backup (quarantined).
::Report end
_____________________________________________________
combofix log:
Bob's Photo - 06-11-06 15:01:37.56 Service Pack 2
ComboFix 06.10.19 - Running from: "C:\Documents and Settings\Bob's Photo\Desktop"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\vxgamet1.exe
((((((((((((((((((((((((((((((( Files Created from 2006-10-06 to 2006-11-06 ))))))))))))))))))))))))))))))))))
2006-11-01 16:04 30,976 --a------ C:\WINDOWS\system32\ace16win.dll
2006-11-01 15:20 76,560 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2006-10-25 12:21 29,440 --a------ C:\WINDOWS\system32\VXH8JKDQ6.EXE
2006-10-25 12:21 25,344 --a------ C:\WINDOWS\system32\winmuse.exe
2006-10-25 12:21 25,088 --a------ C:\WINDOWS\system32\VXH8JKDQ2.EXE
2006-10-25 12:21 14,848 --a------ C:\WINDOWS\system32\kernels64.exe
2006-10-25 12:20 8,960 --a------ C:\WINDOWS\mtwirl32.dll
2006-10-25 12:20 17,408 --a------ C:\WINDOWS\avpcc.dll
2006-10-24 09:58 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2006-10-23 17:38 31,744 --a------ C:\WINDOWS\system32\perfont.exe
2006-10-23 17:37 28,160 --a------ C:\WINDOWS\wininet32.exe
2006-10-23 17:37 17,408 --a------ C:\WINDOWS\waol.exe
2006-10-23 11:40 8,448 --a------ C:\WINDOWS\system32\win32hp.dll
2006-10-23 11:40 29,952 --a------ C:\WINDOWS\systemcritical.exe
2006-10-23 11:40 29,952 --a------ C:\WINDOWS\cpan.dll
2006-10-23 11:40 28,672 --a------ C:\WINDOWS\winmgnt.exe
2006-10-23 11:40 27,648 --a------ C:\WINDOWS\x.exe
2006-10-23 11:40 26,880 --a------ C:\WINDOWS\win64.exe
2006-10-23 11:40 26,112 --a------ C:\WINDOWS\winajbm.dll
2006-10-23 11:40 26,112 --a------ C:\WINDOWS\inetdctr.dll
2006-10-23 11:40 22,016 --a------ C:\WINDOWS\win32e.exe
2006-10-23 11:40 20,736 --a------ C:\WINDOWS\system32\iewd.exe
2006-10-23 11:40 20,480 --a------ C:\WINDOWS\accesss.exe
2006-10-23 11:40 19,968 --a------ C:\WINDOWS\system32\proqlaim.exe
2006-10-23 11:40 19,456 --a------ C:\WINDOWS\dialup.exe
2006-10-23 11:40 18,176 --a------ C:\WINDOWS\system32\msmsn.exe
2006-10-23 11:40 18,176 --a------ C:\WINDOWS\spp3.dll
2006-10-23 11:40 17,664 --a------ C:\WINDOWS\window.exe
2006-10-23 11:40 16,640 --a------ C:\WINDOWS\time.exe
2006-10-23 11:40 16,384 --a------ C:\WINDOWS\systeem.exe
2006-10-23 11:40 16,384 --a------ C:\WINDOWS\clrssn.exe
2006-10-23 11:40 16,128 --a------ C:\WINDOWS\users32.exe
2006-10-23 11:40 14,336 --a------ C:\WINDOWS\y.exe
2006-10-23 11:40 13,056 --a------ C:\WINDOWS\system32\performent202.dll
2006-10-23 11:40 12,800 --a------ C:\WINDOWS\xplugin.dll
2006-10-23 11:39 13,824 --a------ C:\WINDOWS\system32\intr32.dll
2006-10-10 22:37 479,232 --a------ C:\WINDOWS\system32\PICSDK.dll
2006-10-10 22:37 45,056 --a------ C:\WINDOWS\system32\EpPicPrt.dll
2006-10-10 22:37 45,056 --a------ C:\WINDOWS\system32\EpPicMgr.dll
2006-10-10 22:34 82,944 --a------ C:\WINDOWS\system32\EAL.EXE
2006-10-10 22:34 80,219 --a------ C:\WINDOWS\system32\E_FLM9SA.DLL
2006-10-10 22:34 64,000 --a------ C:\WINDOWS\system32\E_FBCB9SA.DLL
2006-10-10 22:34 34,304 --a------ C:\WINDOWS\system32\E_FBCH9SA.DLL
2006-10-10 22:34 309,760 --a------ C:\WINDOWS\system32\EAL32.DLL
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-11-06 11:43 -------- d-------- C:\Program Files\HJT
2006-11-01 15:20 -------- d-------- C:\Program Files\Internet Explorer
2006-10-31 14:25 -------- d-------- C:\Documents and Settings\Bob's Photo\Application Data\U3
2006-10-25 11:07 -------- d-------- C:\Program Files\Google
2006-10-24 09:58 -------- d-------- C:\Program Files\Grisoft
2006-10-24 09:37 -------- d-------- C:\Program Files\NoAdware4
2006-10-23 21:38 -------- d-------- C:\Program Files\Enigma Software Group
2006-10-23 18:33 -------- d-------- C:\Program Files\Windows Defender
2006-10-23 13:17 -------- d-------- C:\Documents and Settings\Bob's Photo\Application Data\Lavasoft
2006-10-23 13:16 -------- d-------- C:\Program Files\Mozilla Firefox
2006-10-23 13:15 -------- d-------- C:\Documents and Settings\Bob's Photo\Application Data\Google
2006-10-23 13:13 -------- d-------- C:\Program Files\Lavasoft
2006-10-06 17:23 -------- d-------- C:\Documents and Settings\Bob's Photo\Application Data\Leadertech
2006-10-06 17:22 -------- d-------- C:\Program Files\EPSON
2006-10-05 11:23 6276 --a------ C:\WINDOWS\system32\ertfsogd.exe
2006-09-19 13:04 5332 --a------ C:\WINDOWS\system32\qiiksriy.exe
2006-09-12 23:01 1084416 --a------ C:\WINDOWS\system32\msxml3.dll
2006-09-12 12:37 5332 --a------ C:\WINDOWS\system32\snsvidjf.exe
2006-08-26 08:14 7476 --a------ C:\WINDOWS\system32\ijqoceyf.exe
2006-08-25 09:45 617472 --a------ C:\WINDOWS\system32\comctl32.dll
2006-08-21 06:21 16896 --a------ C:\WINDOWS\system32\fltlib.dll
2006-08-21 03:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe
2006-08-17 18:13 0 --a------ C:\WINDOWS\system32\cmmgr32.exe
2006-08-17 18:13 0 --a------ C:\WINDOWS\ORUN32.EXE
2006-08-16 05:58 100352 --a------ C:\WINDOWS\system32\6to4svc.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Iomega Active Disk"="C:\\Program Files\\Iomega\\AutoDisk\\AD2KClient.exe"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"Smapp"="C:\\Program Files\\Analog Devices\\SoundMAX\\Smtray.exe"
"WorksFUD"="C:\\Program Files\\Microsoft Works\\wkfud.exe"
"Microsoft Works Portfolio"="C:\\Program Files\\Microsoft Works\\WksSb.exe /AllUsers"
"Microsoft Works Update Detection"="C:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\WkUFind.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"MCAgentExe"="C:\\Program Files\\McAfee.com\\Agent\\mcagent.exe"
"MCUpdateExe"="C:\\Program Files\\McAfee.com\\Agent\\mcupdate.exe /embedding"
"Iomega Startup Options"="C:\\Program Files\\Iomega\\Common\\ImgStart.exe"
"Iomega Drive Icons"="C:\\Program Files\\Iomega\\DriveIcons\\ImgIcon.exe"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"EPSON Stylus Photo R2400"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_FATI9SA.EXE /P24 \"EPSON Stylus Photo R2400\" /O6 \"USB002\" /M \"Stylus Photo R2400\""
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000000
"GeneralFlags"=dword:00000004
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"="Narrator.exe"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\runonce]
"RunNarrator"="Narrator.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=""
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"DisableTaskMgr"=dword:00000000
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"CDRAutoRun"=dword:00000000
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"CDRAutoRun"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SASWinLogon
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\MP Scheduled Scan.job
Completion time: 06-11-06 15:02:27.64
C:\ComboFix.txt ... 06-11-06 15:02
C:\ComboFix2.txt ... 06-11-01 18:22
____________________________________________________________
blacklight log:
11/06/06 15:20:16 [Info]: BlackLight Engine 1.0.47 initialized
11/06/06 15:20:16 [Info]: OS: 5.1 build 2600 (Service Pack 2)
11/06/06 15:20:16 [Note]: 7019 4
11/06/06 15:20:16 [Note]: 7005 0
11/06/06 15:20:18 [Note]: 7006 0
11/06/06 15:20:18 [Note]: 7011 308
11/06/06 15:20:18 [Note]: 7026 0
11/06/06 15:20:19 [Note]: 7026 0
11/06/06 15:20:27 [Note]: FSRAW library version 1.7.1020
11/06/06 15:26:44 [Note]: 2000 1012
11/06/06 15:26:44 [Note]: 2000 1012
11/06/06 15:26:44 [Note]: 2000 1012
11/06/06 15:26:44 [Note]: 2000 1012
11/06/06 15:26:44 [Note]: 2000 1012
11/06/06 15:26:44 [Note]: 2000 1012
11/06/06 15:26:44 [Note]: 2000 1012
11/06/06 16:00:16 [Note]: 7007 0
___________________________________________________________
Hope this is useful. Forgive me if I'm delayed in checking future posts. It looks like the e-mail notifications don't send once the string continues to a second page. I'll check back intermittently.
As for the firewall bit, I've also done some research on problems related to a disabled Windows Firewall and found evidence of missing files, which I'll continue to troubleshoot via Microsoft Knowledge Base. I am open to acquiring another software firewall but I thought the following is first worth mentioning: I recently put into a commission a Netgear ProSafe VPN Firewall (FVS124G) which touts a robust firewall. With regard to this, should I still continue down the avenue of additional software firewall?
OK Navigator, now on with your latest prescription. I've completed your recommended tasks, including re-running combofix. The logs are below:
AVG report:
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 2:54:41 PM 11/6/2006
+ Scan result:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Antispyware Soldier_is1 -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00110011-4B0B-44D5-9718-90C88817369B} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{086AE192-23A6-48D6-96EC-715F53797E85} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11904CE8-632A-4856-A7CC-00B33FE71BD8} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{150FA160-130D-451F-B863-B655061432BA} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{17DA0C9E-4A27-4AC5-BB75-5D24B8CDB972} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1C4DA27D-4D52-4465-A089-98E01BB725CA} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1F48AA48-C53A-4E21-85E7-AC7CC6B5FFB1} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1F48AA48-C53A-4E21-85E7-AC7CC6B5FFB2} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{202A961F-23AE-42B1-9505-FFE3C818D717} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2D38A51A-23C9-48A1-A33C-48675AA2B494} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2E246FAE-8420-11D9-870D-000C2917DE7F} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2E9CAFF6-30C7-4208-8807-E79D4EC6F806} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{479FD0CF-5BE9-4C63-8CDA-B6D371C67BD5} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5753791B-F607-48CA-814E-91C14D081F9E} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7070A8F9-08A4-CA47-0AB0-1EB9E4EE1F3B} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{746455FE-D059-47E7-AF0E-140E03F5A447} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{860C2F6B-CA82-4282-9187-BECCBB66F0AF} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{87185E78-A61B-4DB3-965A-3235BBD7A622} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8DC8F96D-34F7-1501-A2A4-631341AA3AC1} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9C5875B8-93F3-429D-FF34-660B206D897A} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A2595F37-48D0-46A1-9B51-478591A97764} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A6F42CAD-2559-48DF-AF30-89E480AF5DFA} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CA0E28FA-1AFD-4C21-A8DC-70EB5BE2F076} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CF021F40-3E14-23A5-CBA2-717765721306} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D1AC752E-883F-4ED8-8828-B618C3A72152} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E2B2B5A1-B48C-4886-A318-723916A01024} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E2DDF680-9905-4DEE-8C64-0A5DE7FE133C} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E3EEBBE8-9CAB-4C76-B26A-747E25EBB4C6} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E6D5237D-A6C7-4C83-A67F-F9F15586FA62} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E7AFFF2A-1B57-49C7-BF6B-E5123394C970} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FCADDC14-BD46-408A-9842-CDBE1C6D37EB} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD9BC004-8331-4457-B830-4759FF704C22} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FE2D25C1-C1DB-4B5E-9390-AF1CB5302F32} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FF1BF4C7-4E08-4A28-A43F-9D60A9F7A880} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF} -> Adware.Generic : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpywareSheriff_is1 -> Adware.SpywareSheriff : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7A7E6D97-B492-4884-9ABB-C31281DCC4F2} -> Adware.VipSearcher : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1B68470C-2DEF-493B-8A4A-8E2D81BE4EA5} -> Downloader.Delf : Cleaned with backup (quarantined).
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{15ACE85C-0BB1-42D1-9E32-07EB0506675A} -> Downloader.Small.nl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{10D46C47-9CC4-4020-9B0D-DBC231C1AA72}\RP1204\A0095547.exe -> Downloader.Tibs.ir : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{10D46C47-9CC4-4020-9B0D-DBC231C1AA72}\RP1201\A0093369.exe -> Downloader.VB.apa : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{10D46C47-9CC4-4020-9B0D-DBC231C1AA72}\RP1204\A0095549.exe -> Downloader.VB.apa : Cleaned with backup (quarantined).
C:\Documents and Settings\Bob's Photo\Cookies\bob's photo@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Bob's Photo\Cookies\bob's photo@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Bob's Photo\Cookies\bob's photo@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\Bob's Photo\Cookies\bob's photo@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.15:C:\Documents and Settings\Bob's Photo\Application Data\Mozilla\Profiles\default\of0zc65i.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.16:C:\Documents and Settings\Bob's Photo\Application Data\Mozilla\Profiles\default\of0zc65i.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.17:C:\Documents and Settings\Bob's Photo\Application Data\Mozilla\Profiles\default\of0zc65i.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.18:C:\Documents and Settings\Bob's Photo\Application Data\Mozilla\Profiles\default\of0zc65i.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.11:C:\Documents and Settings\Bob's Photo\Application Data\Mozilla\Profiles\default\of0zc65i.slt\cookies.txt -> TrackingCookie.Sextracker : Cleaned.
:mozilla.12:C:\Documents and Settings\Bob's Photo\Application Data\Mozilla\Profiles\default\of0zc65i.slt\cookies.txt -> TrackingCookie.Sextracker : Cleaned.
:mozilla.13:C:\Documents and Settings\Bob's Photo\Application Data\Mozilla\Profiles\default\of0zc65i.slt\cookies.txt -> TrackingCookie.Sextracker : Cleaned.
:mozilla.14:C:\Documents and Settings\Bob's Photo\Application Data\Mozilla\Profiles\default\of0zc65i.slt\cookies.txt -> TrackingCookie.Sextracker : Cleaned.
:mozilla.19:C:\Documents and Settings\Bob's Photo\Application Data\Mozilla\Profiles\default\of0zc65i.slt\cookies.txt -> TrackingCookie.Sextracker : Cleaned.
:mozilla.25:C:\Documents and Settings\Bob's Photo\Application Data\Mozilla\Profiles\default\of0zc65i.slt\cookies.txt -> TrackingCookie.Sextracker : Cleaned.
HKU\S-1-5-21-1294642078-3233042676-1574323382-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B212D577-05B7-4963-911E-4A8588160DFA} -> Trojan.Delf.nj : Cleaned with backup (quarantined).
C:\WINDOWS\system32\msmapi32.exe -> Trojan.VB.atw : Cleaned with backup (quarantined).
::Report end
_____________________________________________________
combofix log:
Bob's Photo - 06-11-06 15:01:37.56 Service Pack 2
ComboFix 06.10.19 - Running from: "C:\Documents and Settings\Bob's Photo\Desktop"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\vxgamet1.exe
((((((((((((((((((((((((((((((( Files Created from 2006-10-06 to 2006-11-06 ))))))))))))))))))))))))))))))))))
2006-11-01 16:04 30,976 --a------ C:\WINDOWS\system32\ace16win.dll
2006-11-01 15:20 76,560 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2006-10-25 12:21 29,440 --a------ C:\WINDOWS\system32\VXH8JKDQ6.EXE
2006-10-25 12:21 25,344 --a------ C:\WINDOWS\system32\winmuse.exe
2006-10-25 12:21 25,088 --a------ C:\WINDOWS\system32\VXH8JKDQ2.EXE
2006-10-25 12:21 14,848 --a------ C:\WINDOWS\system32\kernels64.exe
2006-10-25 12:20 8,960 --a------ C:\WINDOWS\mtwirl32.dll
2006-10-25 12:20 17,408 --a------ C:\WINDOWS\avpcc.dll
2006-10-24 09:58 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2006-10-23 17:38 31,744 --a------ C:\WINDOWS\system32\perfont.exe
2006-10-23 17:37 28,160 --a------ C:\WINDOWS\wininet32.exe
2006-10-23 17:37 17,408 --a------ C:\WINDOWS\waol.exe
2006-10-23 11:40 8,448 --a------ C:\WINDOWS\system32\win32hp.dll
2006-10-23 11:40 29,952 --a------ C:\WINDOWS\systemcritical.exe
2006-10-23 11:40 29,952 --a------ C:\WINDOWS\cpan.dll
2006-10-23 11:40 28,672 --a------ C:\WINDOWS\winmgnt.exe
2006-10-23 11:40 27,648 --a------ C:\WINDOWS\x.exe
2006-10-23 11:40 26,880 --a------ C:\WINDOWS\win64.exe
2006-10-23 11:40 26,112 --a------ C:\WINDOWS\winajbm.dll
2006-10-23 11:40 26,112 --a------ C:\WINDOWS\inetdctr.dll
2006-10-23 11:40 22,016 --a------ C:\WINDOWS\win32e.exe
2006-10-23 11:40 20,736 --a------ C:\WINDOWS\system32\iewd.exe
2006-10-23 11:40 20,480 --a------ C:\WINDOWS\accesss.exe
2006-10-23 11:40 19,968 --a------ C:\WINDOWS\system32\proqlaim.exe
2006-10-23 11:40 19,456 --a------ C:\WINDOWS\dialup.exe
2006-10-23 11:40 18,176 --a------ C:\WINDOWS\system32\msmsn.exe
2006-10-23 11:40 18,176 --a------ C:\WINDOWS\spp3.dll
2006-10-23 11:40 17,664 --a------ C:\WINDOWS\window.exe
2006-10-23 11:40 16,640 --a------ C:\WINDOWS\time.exe
2006-10-23 11:40 16,384 --a------ C:\WINDOWS\systeem.exe
2006-10-23 11:40 16,384 --a------ C:\WINDOWS\clrssn.exe
2006-10-23 11:40 16,128 --a------ C:\WINDOWS\users32.exe
2006-10-23 11:40 14,336 --a------ C:\WINDOWS\y.exe
2006-10-23 11:40 13,056 --a------ C:\WINDOWS\system32\performent202.dll
2006-10-23 11:40 12,800 --a------ C:\WINDOWS\xplugin.dll
2006-10-23 11:39 13,824 --a------ C:\WINDOWS\system32\intr32.dll
2006-10-10 22:37 479,232 --a------ C:\WINDOWS\system32\PICSDK.dll
2006-10-10 22:37 45,056 --a------ C:\WINDOWS\system32\EpPicPrt.dll
2006-10-10 22:37 45,056 --a------ C:\WINDOWS\system32\EpPicMgr.dll
2006-10-10 22:34 82,944 --a------ C:\WINDOWS\system32\EAL.EXE
2006-10-10 22:34 80,219 --a------ C:\WINDOWS\system32\E_FLM9SA.DLL
2006-10-10 22:34 64,000 --a------ C:\WINDOWS\system32\E_FBCB9SA.DLL
2006-10-10 22:34 34,304 --a------ C:\WINDOWS\system32\E_FBCH9SA.DLL
2006-10-10 22:34 309,760 --a------ C:\WINDOWS\system32\EAL32.DLL
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-11-06 11:43 -------- d-------- C:\Program Files\HJT
2006-11-01 15:20 -------- d-------- C:\Program Files\Internet Explorer
2006-10-31 14:25 -------- d-------- C:\Documents and Settings\Bob's Photo\Application Data\U3
2006-10-25 11:07 -------- d-------- C:\Program Files\Google
2006-10-24 09:58 -------- d-------- C:\Program Files\Grisoft
2006-10-24 09:37 -------- d-------- C:\Program Files\NoAdware4
2006-10-23 21:38 -------- d-------- C:\Program Files\Enigma Software Group
2006-10-23 18:33 -------- d-------- C:\Program Files\Windows Defender
2006-10-23 13:17 -------- d-------- C:\Documents and Settings\Bob's Photo\Application Data\Lavasoft
2006-10-23 13:16 -------- d-------- C:\Program Files\Mozilla Firefox
2006-10-23 13:15 -------- d-------- C:\Documents and Settings\Bob's Photo\Application Data\Google
2006-10-23 13:13 -------- d-------- C:\Program Files\Lavasoft
2006-10-06 17:23 -------- d-------- C:\Documents and Settings\Bob's Photo\Application Data\Leadertech
2006-10-06 17:22 -------- d-------- C:\Program Files\EPSON
2006-10-05 11:23 6276 --a------ C:\WINDOWS\system32\ertfsogd.exe
2006-09-19 13:04 5332 --a------ C:\WINDOWS\system32\qiiksriy.exe
2006-09-12 23:01 1084416 --a------ C:\WINDOWS\system32\msxml3.dll
2006-09-12 12:37 5332 --a------ C:\WINDOWS\system32\snsvidjf.exe
2006-08-26 08:14 7476 --a------ C:\WINDOWS\system32\ijqoceyf.exe
2006-08-25 09:45 617472 --a------ C:\WINDOWS\system32\comctl32.dll
2006-08-21 06:21 16896 --a------ C:\WINDOWS\system32\fltlib.dll
2006-08-21 03:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe
2006-08-17 18:13 0 --a------ C:\WINDOWS\system32\cmmgr32.exe
2006-08-17 18:13 0 --a------ C:\WINDOWS\ORUN32.EXE
2006-08-16 05:58 100352 --a------ C:\WINDOWS\system32\6to4svc.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Iomega Active Disk"="C:\\Program Files\\Iomega\\AutoDisk\\AD2KClient.exe"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"Smapp"="C:\\Program Files\\Analog Devices\\SoundMAX\\Smtray.exe"
"WorksFUD"="C:\\Program Files\\Microsoft Works\\wkfud.exe"
"Microsoft Works Portfolio"="C:\\Program Files\\Microsoft Works\\WksSb.exe /AllUsers"
"Microsoft Works Update Detection"="C:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\WkUFind.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"MCAgentExe"="C:\\Program Files\\McAfee.com\\Agent\\mcagent.exe"
"MCUpdateExe"="C:\\Program Files\\McAfee.com\\Agent\\mcupdate.exe /embedding"
"Iomega Startup Options"="C:\\Program Files\\Iomega\\Common\\ImgStart.exe"
"Iomega Drive Icons"="C:\\Program Files\\Iomega\\DriveIcons\\ImgIcon.exe"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"EPSON Stylus Photo R2400"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_FATI9SA.EXE /P24 \"EPSON Stylus Photo R2400\" /O6 \"USB002\" /M \"Stylus Photo R2400\""
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000000
"GeneralFlags"=dword:00000004
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"="Narrator.exe"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\runonce]
"RunNarrator"="Narrator.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=""
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"DisableTaskMgr"=dword:00000000
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"CDRAutoRun"=dword:00000000
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"CDRAutoRun"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SASWinLogon
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\MP Scheduled Scan.job
Completion time: 06-11-06 15:02:27.64
C:\ComboFix.txt ... 06-11-06 15:02
C:\ComboFix2.txt ... 06-11-01 18:22
____________________________________________________________
blacklight log:
11/06/06 15:20:16 [Info]: BlackLight Engine 1.0.47 initialized
11/06/06 15:20:16 [Info]: OS: 5.1 build 2600 (Service Pack 2)
11/06/06 15:20:16 [Note]: 7019 4
11/06/06 15:20:16 [Note]: 7005 0
11/06/06 15:20:18 [Note]: 7006 0
11/06/06 15:20:18 [Note]: 7011 308
11/06/06 15:20:18 [Note]: 7026 0
11/06/06 15:20:19 [Note]: 7026 0
11/06/06 15:20:27 [Note]: FSRAW library version 1.7.1020
11/06/06 15:26:44 [Note]: 2000 1012
11/06/06 15:26:44 [Note]: 2000 1012
11/06/06 15:26:44 [Note]: 2000 1012
11/06/06 15:26:44 [Note]: 2000 1012
11/06/06 15:26:44 [Note]: 2000 1012
11/06/06 15:26:44 [Note]: 2000 1012
11/06/06 15:26:44 [Note]: 2000 1012
11/06/06 16:00:16 [Note]: 7007 0
___________________________________________________________
Hope this is useful. Forgive me if I'm delayed in checking future posts. It looks like the e-mail notifications don't send once the string continues to a second page. I'll check back intermittently.