Kris - 06-08-21 18:26:55.82
ComboFix 06.08.18 - Running from: C:\
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\bszip.dll
((((((((((((((((((((((((((((((( Files Created from 2006-07-21 to 2006-08-21 ))))))))))))))))))))))))))))))))))
2006-08-21 17:47 296,182 C:\combofix.exe
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) )))
2006-08-21 17:47 296182 --a------ C:\combofix.exe
2006-08-21 17:43 -------- d-------- C:\Program Files\Dl_cats
2006-08-18 12:16 88 -r-hs---- C:\WINDOWS\system32\384F756848.sys
2006-08-18 12:16 3350 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
2006-08-15 18:52 -------- dr-h----- C:\Documents and Settings\Kris\Application Data\yahoo!
2006-08-15 17:50 -------- d-------- C:\Program Files\Webshots
2006-08-15 17:42 -------- d-------- C:\Program Files\Internet Explorer
2006-08-11 08:51 -------- d-------- C:\Program Files\CCleaner
2006-08-09 11:49 -------- d-------- C:\Program Files\Mozilla Firefox
2006-08-08 13:17 -------- d-------- C:\Program Files\MSN Messenger
2006-08-08 12:43 -------- d-------- C:\Program Files\HijackThis
2006-08-08 10:28 251392 --a------ C:\Program Files\hijackthis_sfx.exe
2006-08-08 10:21 -------- d-------- C:\Program Files\Lavasoft
2006-08-08 10:21 -------- d-------- C:\Documents and Settings\Kris\Application Data\Lavasoft
2006-07-27 08:24 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-07-25 17:36 5346892 --a------ C:\Program Files\260.wmv
2006-07-21 17:51 4218825 --a------ C:\Program Files\Ma___Pa_Kettle_Math.wmv
2006-07-21 03:24 72704 --a------ C:\WINDOWS\system32\hlink.dll
2006-07-19 18:07 2992142 --a------ C:\Program Files\Prank.wmv
2006-07-19 18:07 1335808 --a------ C:\Program Files\Lee_THINGSTH.pps
2006-07-18 17:30 3041521 --a------ C:\Program Files\Toilet-Head-Prank.wmv
2006-07-16 07:57 -------- d-------- C:\Documents and Settings\Kris\Application Data\Mozilla
2006-07-16 07:56 5118288 --a------ C:\Program Files\Firefox Setup 1.5.0.4.exe
2006-06-30 21:18 -------- d-------- C:\Program Files\Yahoo!
2006-06-27 06:17 -------- d-------- C:\Documents and Settings\Kris\Application Data\AdobeUM
2006-06-27 06:15 -------- d-------- C:\Program Files\Adobe
2006-06-26 18:48 31680 --a------ C:\WINDOWS\system32\drivers\Pcouffin.sys
2006-06-26 18:48 -------- d-------- C:\Program Files\321Studios
2006-05-22 20:24 5010672 --a--c--- C:\WINDOWS\WindowsXP-KB912945-x86-ENU.exe
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"MCUpdateExe"="C:\\PROGRA~1\\mcafee.com\\agent\\Mc Update.exe"
"MCAgentExe"="c:\\PROGRA~1\\mcafee.com\\agent\\mca gent.exe"
"ISUSScheduler"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe\" -start"
"ISUSPM Startup"="\"c:\\Program Files\\Common Files\\InstallShield\\UpdateService\\isuspm.exe\" -startup"
"IAAnotif"="C:\\Program Files\\Intel\\Intel Matrix Storage Manager\\iaanotif.exe"
"DMXLauncher"="C:\\Program Files\\Dell\\Media Experience\\DMXLauncher.exe"
"CTSysVol"="C:\\Program Files\\Creative\\SBAudigy2ZS\\Surround Mixer\\CTSysVol.exe /r"
"CTHelper"="CTHELPER.EXE"
"CTDVDDET"="\"C:\\Program Files\\Creative\\SBAudigy2ZS\\DVDAudio\\CTDVDDET.E XE\""
"VirusScan Online"="C:\\Program Files\\McAfee.com\\VSO\\mcvsshld.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"VSOCheckTask"="\"C:\\PROGRA~1\\McAfee.com\\VSO\\m cmnhdlr.exe\" /checktask"
"UpdReg"="C:\\WINDOWS\\UpdReg.EXE"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"OASClnt"="C:\\Program Files\\McAfee.com\\VSO\\oasclnt.exe"
"MimBoot"="C:\\PROGRA~1\\MUSICM~1\\MUSICM~3\\mimbo ot.exe"
"MPFExe"="C:\\PROGRA~1\\McAfee.com\\PERSON~1\\MpfT ray.exe"
"dla"="C:\\WINDOWS\\system32\\dla\\tfswctrl.ex e"
@=""
"DLCDCATS"="rundll32 C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\ DLCDtime.dll,_RunDLLEntry@16"
"dlcdmon.exe"="\"C:\\Program Files\\Dell Photo AIO Printer 944\\dlcdmon.exe\""
"MemoryCardManager"="\"C:\\Program Files\\Dell Photo AIO Printer 944\\memcard.exe\""
"MSKAGENTEXE"="C:\\PROGRA~1\\McAfee\\SPAMKI~1\\Msk Agent.exe"
"MSKDetectorExe"="C:\\PROGRA~1\\McAfee\\SPAMKI~1\\ MskDetct.exe /startup"
"!ewido"="\"C:\\Documents and Settings\\Kris\\My Documents\\Programs\\ewido-antispyware4.0\\ewido anti-spyware 4.0\\ewido.exe\" /minimized"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\OptionalComponents]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"DellSupport"="\"C:\\Program Files\\Dell Support\\DSAgnt.exe\" /startup"
"CursorXP"="\"C:\\Program Files\\CursorXP\\CursorXP.exe\" -s"
"PhotoShow Deluxe Media Manager"="C:\\PROGRA~1\\SIMPLE~1\\PHOTOS~1\\data\\ Xtras\\mssysmgr.exe"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.ex e"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\policies\explorer]
"NoCDBurning"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run-]
"Eraser"="C:\\Documents and Settings\\Kris\\My Documents\\Programs\\Eraser\\Eraser\\eraser.exe -hide"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\policies\explorer\Run]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00 ,34,03,00,00,e0,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00 ,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff ,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23 ,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\Cur rentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\polic ies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\shellexecutehooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run-]
"DVDLauncher"="\"C:\\Program Files\\CyberLink\\PowerDVD\\DVDLauncher.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"RealTray"="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe SYSTEMBOOTHIDEPLAYER"
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\McAfee.com Scan for Viruses - My Computer (OFFICE-Kris).job
Completion time: Mon 08/21/2006 18:27:56.42
ComboFix.txt
Originally Posted by Neal


