Hi. My PC seems to be running okay, but is still infected. My background is fine, I am not getting any virtual memory messages, and computer response time is good, so there have been quite a few big improvements. When I restarted after running the Hijakthis fix for the items you mentioned, my spyware told me that it found 6 infections on startup - 4 tracking cookies and some registry values.
(1)
ComboFix 08-01-05.7 - Casey Costello 2008-01-05 6:45:53.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.807 [GMT -5:00]
Running from: C:\Documents and Settings\Casey Costello\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2007-12-05 to 2008-01-05 )))))))))))))))))))))))))))))))
.
2008-01-05 06:40 . 2008-01-05 06:40 103,302 --a------ C:\sr0
2008-01-05 06:40 . 2008-01-05 06:40 3,308 --a------ C:\sr0.1
2008-01-05 06:40 . 2008-01-05 06:40 2,503 --a------ C:\sr0.2
2008-01-04 06:20 . 2008-01-04 07:12 2,664 --a------ C:\s3v4.2
2008-01-03 19:29 . 2008-01-04 07:12 5,875,019 --a------ C:\s3v4
2008-01-03 19:29 . 2008-01-04 07:12 3,518 --a------ C:\s3v4.1
2008-01-03 06:50 . 2008-01-03 07:03 2,746 --a------ C:\s114
2008-01-02 18:56 . 2008-01-02 18:59 115,299 --a------ C:\s2kc.2
2008-01-02 18:56 . 2008-01-02 18:59 88,255 --a------ C:\s2kc.1
2008-01-02 18:56 . 2008-01-02 18:59 15,912 --a------ C:\s2kc.3
2008-01-02 18:56 . 2008-01-02 18:59 4,781 --a------ C:\s2kc
2008-01-01 13:00 . 2008-01-01 14:24 1,117,957 --a------ C:\smg.1
2008-01-01 13:00 . 2008-01-01 14:24 74,696 --a------ C:\smg.2
2008-01-01 13:00 . 2008-01-01 14:24 3,528 --a------ C:\smg
2008-01-01 12:42 . 2008-01-04 07:26 4,996 --a------ C:\WINDOWS\system32\tmp.reg
2008-01-01 11:51 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-01 09:05 . 2008-01-01 11:43 2,587 --a------ C:\sfc.a
2007-12-31 18:00 . 2008-01-01 11:43 11,414 --a------ C:\sfc.6
2007-12-31 18:00 . 2008-01-01 11:43 3,299 --a------ C:\sfc.7
2007-12-31 18:00 . 2008-01-01 11:43 3,109 --a------ C:\sfc.8
2007-12-31 18:00 . 2008-01-01 11:43 2,738 --a------ C:\sfc.9
2007-12-31 18:00 . 2008-01-01 11:43 2,515 --a------ C:\sfc.5
2007-12-30 10:55 . 2008-01-01 11:43 12,965 --a------ C:\sfc.1
2007-12-30 10:55 . 2008-01-01 11:43 7,112 --a------ C:\sfc.3
2007-12-30 10:55 . 2008-01-01 11:43 2,679 --a------ C:\sfc.2
2007-12-30 10:55 . 2008-01-01 11:43 1,834 --a------ C:\sfc.4
2007-12-29 21:30 . 2007-12-29 21:30 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-29 21:26 . 2007-12-29 22:04 3,605 --a------ C:\sqc.5
2007-12-29 21:26 . 2007-12-29 22:04 2,883 --a------ C:\sqc.6
2007-12-29 20:55 . 2007-12-29 20:55 <DIR> d-------- C:\Documents and Settings\Casey Costello\Application Data\ParetoLogic
2007-12-29 20:54 . 2007-12-29 20:54 <DIR> d-------- C:\Program Files\ParetoLogic
2007-12-29 20:54 . 2007-12-29 20:54 <DIR> d-------- C:\Program Files\Common Files\ParetoLogic
2007-12-29 20:54 . 2007-12-29 20:55 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ParetoLogic
2007-12-29 20:54 . 2007-12-29 20:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Downloaded Installations
2007-12-29 20:09 . 2007-12-29 21:02 <DIR> d-------- C:\Program Files\RegCure
2007-12-29 17:06 . 2007-12-29 17:06 <DIR> d-------- C:\Documents and Settings\Casey Costello\Application Data\Grisoft
2007-12-29 17:05 . 2007-12-29 17:05 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-29 17:05 . 2007-05-30 07:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-12-29 09:28 . 2007-12-29 09:31 185,139 --a------ C:\s1oc.5
2007-12-29 09:28 . 2007-12-29 09:31 6,520 --a------ C:\s1oc.1
2007-12-29 09:28 . 2007-12-29 09:31 4,079 --a------ C:\s1oc.4
2007-12-29 09:28 . 2007-12-29 09:31 2,626 --a------ C:\s1oc.8
2007-12-29 09:28 . 2007-12-29 09:31 2,585 --a------ C:\s1oc.3
2007-12-29 09:28 . 2007-12-29 09:31 2,575 --a------ C:\s1oc.2
2007-12-29 09:28 . 2007-12-29 09:31 1,993 --a------ C:\s1oc.7
2007-12-29 09:28 . 2007-12-29 09:31 1,797 --a------ C:\s1oc
2007-12-29 09:28 . 2007-12-29 09:31 1,671 --a------ C:\s1oc.6
2007-12-27 19:39 . 2007-12-27 19:39 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2007-12-27 19:34 . 2007-12-27 19:46 2,579 --a------ C:\s3sk.2
2007-12-27 19:23 . 2007-12-27 19:46 8,849 --a------ C:\s3sk
2007-12-27 19:23 . 2007-12-27 19:46 3,117 --a------ C:\s3sk.1
2007-12-27 18:43 . 2007-12-27 18:43 <DIR> d-------- C:\WINDOWS\RegistryCleaner
2007-12-27 17:49 . 2007-12-27 17:49 <DIR> d-------- C:\Documents and Settings\Casey Costello\Application Data\System Tweaker
2007-12-27 15:31 . 2007-12-29 17:20 <DIR> d-------- C:\Program Files\Uniblue
2007-12-27 15:31 . 2007-12-27 15:31 <DIR> d-------- C:\Documents and Settings\Casey Costello\Application Data\Uniblue
2007-12-27 15:31 . 2007-12-27 15:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Uniblue
2007-12-27 14:17 . 2007-12-27 18:24 199,167 --a------ C:\sfg.1
2007-12-27 14:17 . 2007-12-27 18:24 2,551 --a------ C:\sfg
2007-12-27 03:34 . 2007-12-27 10:31 79,933 --a------ C:\s2ik.j
2007-12-27 03:34 . 2007-12-27 10:31 14,505 --a------ C:\s2ik.d
2007-12-27 03:34 . 2007-12-27 10:31 2,834 --a------ C:\s2ik.g
2007-12-27 03:34 . 2007-12-27 10:31 2,714 --a------ C:\s2ik.h
2007-12-27 03:34 . 2007-12-27 10:31 2,636 --a------ C:\s2ik.e
2007-12-27 03:34 . 2007-12-27 10:31 2,636 --a------ C:\s2ik.c
2007-12-27 03:34 . 2007-12-27 10:31 2,632 --a------ C:\s2ik.i
2007-12-27 03:34 . 2007-12-27 10:31 1,997 --a------ C:\s2ik.f
2007-12-23 17:41 . 2007-12-23 18:04 464,343 --a------ C:\smo.3
2007-12-23 17:41 . 2007-12-23 18:04 2,929 --a------ C:\smo
2007-12-23 17:41 . 2007-12-23 18:04 2,572 --a------ C:\smo.1
2007-12-23 17:41 . 2007-12-23 18:04 2,038 --a------ C:\smo.2
2007-12-22 17:44 . 2007-12-22 18:12 1,802,068 --a------ C:\sn4.2
2007-12-22 17:44 . 2007-12-22 18:12 14,204 --a------ C:\sn4
2007-12-22 17:44 . 2007-12-22 18:12 2,659 --a------ C:\sn4.1
2007-12-19 21:32 . 2008-01-04 07:46 <DIR> d-------- C:\Program Files\Spyware Doctor
2007-12-19 21:32 . 2007-12-19 21:32 <DIR> d-------- C:\Documents and Settings\Casey Costello\Application Data\PC Tools
2007-12-19 21:32 . 2007-10-04 17:10 79,688 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2007-12-19 21:32 . 2007-10-04 17:10 62,280 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2007-12-19 21:32 . 2007-10-04 17:10 41,288 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-12-19 21:32 . 2007-10-04 17:11 29,000 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2007-12-19 20:38 . 2007-12-19 21:22 89,906 --a------ C:\s1dc.4
2007-12-19 20:34 . 2008-01-05 06:42 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-19 16:37 . 2007-12-19 16:42 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2007-12-19 16:14 . 2007-12-19 16:14 <DIR> d-------- C:\WINDOWS\system32\runtime
2007-12-19 16:12 . 2007-12-19 16:12 <DIR> d-------- C:\Program Files\Norton Security Scan
2007-12-19 15:33 . 2005-09-23 08:29 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-12-19 12:51 . 2007-12-19 12:51 <DIR> d-------- C:\Program Files\Windows Sidebar
2007-12-19 12:50 . 2007-12-19 13:00 123,952 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-12-19 12:50 . 2007-12-19 13:00 60,800 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2007-12-19 12:50 . 2007-12-19 13:00 10,740 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-12-19 12:50 . 2007-12-19 13:00 805 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-12-19 10:58 . 2007-12-19 10:58 <DIR> d-------- C:\Documents and Settings\Casey Costello\Application Data\Tenebril
2007-12-19 10:48 . 2007-12-19 10:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Tenebril
2007-12-19 10:45 . 2007-12-19 10:45 <DIR> d-------- C:\WINDOWS\system32\tenarchlib
2007-12-19 10:45 . 2005-10-12 23:10 180,224 --a-s---- C:\WINDOWS\system32\archlib.dll
2007-12-19 10:22 . 2007-12-19 10:57 <DIR> d-------- C:\Program Files\Netcom3 Cleaner
2007-12-19 08:55 . 2007-12-19 09:21 11,624 --a------ C:\s31o.8
2007-12-19 08:55 . 2007-12-19 09:21 4,954 --a------ C:\s31o.7
2007-12-19 08:55 . 2007-12-19 09:21 2,453 --a------ C:\s31o.9
2007-12-18 17:07 . 2007-12-19 08:38 14,581 --a------ C:\so4.1
2007-12-18 17:07 . 2007-12-19 08:38 11,908 --a------ C:\so4
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-05 11:30 --------- d-----w C:\Documents and Settings\Casey Costello\Application Data\Viewpoint
2008-01-05 11:26 --------- d-----w C:\Program Files\Java
2008-01-04 11:33 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-01-01 16:40 --------- d-----w C:\Program Files\AIM6
2008-01-01 16:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-01-01 14:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2007-12-30 02:06 --------- d-----w C:\Program Files\Google
2007-12-30 02:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\QuickTime
2007-12-30 01:37 --------- d-----w C:\Program Files\PC-Doctor for Windows
2007-12-29 21:59 --------- d-----w C:\Program Files\Punch! 5 in 1
2007-12-20 11:56 --------- d-----w C:\Program Files\Yahoo!
2007-12-20 03:00 --------- d-----w C:\Program Files\Common Files\Adobe
2007-12-20 02:55 --------- d-----w C:\Program Files\Common Files\Real
2007-12-19 18:03 --------- d-----w C:\Program Files\Norton AntiVirus
2007-12-19 18:00 --------- d-----w C:\Program Files\Symantec
2007-12-19 17:59 --------- d-----w C:\Documents and Settings\Casey Costello\Application Data\Yahoo!
2007-12-19 17:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2007-12-19 16:31 --------- d-----w C:\Program Files\AWS
2007-12-19 14:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\BVRP Software
2007-12-17 01:48 --------- d-----w C:\Documents and Settings\Casey Costello\Application Data\AdobeUM
2007-12-01 04:57 43,696 ----a-w C:\WINDOWS\system32\drivers\srtspx.sys
2007-12-01 04:57 317,616 ----a-w C:\WINDOWS\system32\drivers\srtspl.sys
2007-12-01 04:57 279,088 ----a-w C:\WINDOWS\system32\drivers\srtsp.sys
2007-12-01 04:57 10,549 ----a-w C:\WINDOWS\system32\drivers\srtspx.cat
2007-12-01 04:57 10,549 ----a-w C:\WINDOWS\system32\drivers\srtspl.cat
2007-12-01 04:57 10,545 ----a-w C:\WINDOWS\system32\drivers\srtsp.cat
2007-12-01 04:57 1,430 ----a-w C:\WINDOWS\system32\drivers\srtspl.inf
2007-12-01 04:57 1,421 ----a-w C:\WINDOWS\system32\drivers\srtspx.inf
2007-12-01 04:57 1,415 ----a-w C:\WINDOWS\system32\drivers\srtsp.inf
2007-11-28 00:50 --------- d-----w C:\Program Files\iTunes
2007-11-28 00:50 --------- d-----w C:\Program Files\iPod
2007-11-28 00:30 --------- d-----w C:\Program Files\QuickTime
2007-11-28 00:27 --------- d-----w C:\Program Files\Apple Software Update
2007-11-28 00:25 --------- d-----w C:\Program Files\Common Files\Apple
2007-11-28 00:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-30 23:42 3,590,656 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-27 22:40 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 22:40 222,720 ----a-w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-10 23:56 824,832 ----a-w C:\WINDOWS\system32\dllcache\wininet.dll
2007-10-10 23:56 232,960 ----a-w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-10-10 23:56 1,159,680 ----a-w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-10-10 23:55 671,232 ----a-w C:\WINDOWS\system32\dllcache\mstime.dll
2007-10-10 23:55 63,488 ------w C:\WINDOWS\system32\dllcache\icardie.dll
2007-10-10 23:55 6,065,664 ------w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-10-10 23:55 52,224 ------w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-10-10 23:55 478,208 ----a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-10-10 23:55 459,264 ------w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-10-10 23:55 44,544 ----a-w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-10-10 23:55 384,512 ----a-w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-10-10 23:55 383,488 ------w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-10-10 23:55 27,648 ----a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-10-10 23:55 267,776 ------w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-10-10 23:55 230,400 ----a-w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-10-10 23:55 214,528 ----a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-10-10 23:55 193,024 ----a-w C:\WINDOWS\system32\dllcache\msrating.dll
2007-10-10 23:55 153,088 ----a-w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-10-10 23:55 132,608 ----a-w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-10-10 23:55 124,928 ----a-w C:\WINDOWS\system32\dllcache\advpack.dll
2007-10-10 23:55 105,984 ----a-w C:\WINDOWS\system32\dllcache\url.dll
2007-10-10 23:55 102,400 ----a-w C:\WINDOWS\system32\dllcache\occache.dll
2007-10-10 10:59 70,656 ----a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-10-10 10:59 625,152 ----a-w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-10-10 10:59 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-10-10 05:46 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-08-18 11:24 7,028,144 ----a-w C:\Documents and Settings\Casey Costello\medic6.exe
2006-05-29 15:40 24,192 ----a-w C:\Documents and Settings\Casey Costello\usbsermptxp.sys
2006-05-29 15:40 22,768 ----a-w C:\Documents and Settings\Casey Costello\usbsermpt.sys
2005-01-10 03:38 184,808 ----a-w C:\Documents and Settings\Casey Costello\Application Data\shb.dat
2004-06-02 22:56 32 --sha-w C:\WINDOWS\{04BA7690-7AED-4E2D-A830-82D0143E5C73}.dat
2004-12-15 12:15 56 --sh--r C:\WINDOWS\system32\
0D93706C9A.sys
2004-12-27 01:31 1,682 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2004-06-02 22:56 32 --sha-w C:\WINDOWS\system32\{8318FDD1-6A65-4069-9DA2-CBB6F145CF10}.dat
.
(((((((((((((((((((((((((((((
snapshot@2008-01-01_11.59.08.65 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-05 11:37:05 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_b34.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2007-12-19 12:52 116088 --a------ C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"tgcmd"="" []
"spc_w"="C:\Program Files\NZSearch\nzspc.exe" [2004-11-09 03:29 286786]
"IBM RecordNow!"="" []
"ibmmessages"="C:\Program Files\IBM\Messages By IBM\ibmmessages.exe" [2003-04-09 21:03 532480]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"="irprops.cpl" [2004-08-04 02:56 380416 C:\WINDOWS\system32\irprops.cpl]
"Smapp"="C:\Program Files\Analog Devices\SoundMAX\SMTray.exe" [2002-11-08 17:50 98304]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2003-07-10 06:25 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-07-10 06:13 114688]
"UC_Start"="C:\IBMTools\Updater\ucstartup.exe" [2003-03-17 16:27 32768]
"ibmmessages"="c:\Program Files\IBM\Messages By IBM\ibmmessages.exe" [2003-04-09 21:03 532480]
"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.exe" [2002-02-04 21:32 53248]
"InstantAccess"="C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.exe" [1998-12-10 12:57 37376]
"RegisterDropHandler"="C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE" [1998-12-10 11:33 23040]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-03-20 17:34 213936]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 01:01 110592]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-09-02 01:05 127035]
"ISUSScheduler"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe" [2006-03-20 17:34 86960]
"Net-It Launcher"="C:\WINDOWS\system32\NILaunch.exe" [1998-02-05 14:16 24576]
"HostManager"="C:\Program Files\Common Files\AOL\1144029693\ee\AOLSoftware.exe" [2006-05-09 19:24 50760]
"IPHSend"="C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 11:59 124520]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-03-20 17:34 213936]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-11-14 23:43 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-15 13:11 267048]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-08-25 00:07 51048]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2007-08-24 23:53 714608]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-12-19 21:55 185632]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25 6731312]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-10-02 16:27 1065288]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"RegisterDropHandler"="C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE" [1998-12-10 11:33 23040]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-04 02:56 53760 C:\WINDOWS\system32\narrator.exe]
C:\Documents and Settings\Casey Costello\Start Menu\Programs\Startup\
GoZone iSync.lnk - C:\Program Files\GoZone\GoZone_iSync.exe [2007-05-05 14:46:52]
Natural Desktop.lnk - C:\Program Files\Stardock\DesktopGadgets\NaturalDesktop\NaturalDesktop.exe [2006-03-11 20:35:33]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Snsicon.lnk - C:\Program Files\Second Nature\Snsicon.exe [2005-01-06 08:51:54]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"LockTaskbar"= 0 (0x0)
R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" [2007-08-25 00:07]
R3 S6U12BScanner;MUSTEK 1200 UB Still Image Device Service;C:\WINDOWS\system32\drivers\usbscan.sys [2004-08-04 00:58]
R3 SymIMMP;SymIMMP;C:\WINDOWS\system32\DRIVERS\SymIM.sys [2007-08-09 19:27]
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2007-05-29 13:55]
S3 DCamUSBVeo532;Veo Web Camera;C:\WINDOWS\system32\Drivers\ubVeo532.sys [2002-07-01 17:30]
S3 PCDRDRV;Pcdr Helper Driver;C:\PROGRA~1\PC-DOC~1\DIAGNO~1\PCDRDRV.sys []
S3 SymIM;Symantec Network Security Intermediate Filter Service;C:\WINDOWS\system32\DRIVERS\SymIM.sys [2007-08-09 19:27]
.
Contents of the 'Scheduled Tasks' folder
"2007-12-19 17:56:39 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Casey Costello.job"
- C:\Program Files\Norton AntiVirus\Navw32.exeh/TASK:
"2007-12-30 01:55:13 C:\WINDOWS\Tasks\ParetoLogic Update.job"
- C:\Program Files\Common Files\ParetoLogic\UUS2\Pareto_Update.exe
"2008-01-05 11:39:17 C:\WINDOWS\Tasks\RegCure Program Check.job"
- C:\Program Files\RegCure\RegCure.exe
"2007-12-30 01:09:38 C:\WINDOWS\Tasks\RegCure.job"
- C:\Program Files\RegCure\RegCure.exe
"2008-01-01 17:00:00 C:\WINDOWS\Tasks\Uniblue SpyEraser.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-01-05 06:54:38
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
-> C:\PROGRA~1\TEXTBR~1.0\Bin\TBMHOOK.dll
.
Completion time: 2008-01-05 6:57:25
ComboFix-quarantined-files.txt 2008-01-05 11:57:11
ComboFix2.txt 2008-01-01 18:10:41
ComboFix3.txt 2008-01-01 17:00:25
.
2007-12-19 15:05:30 --- E O F ---
(2)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:38:18 AM, on 1/5/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\RegCure\RegCure.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe
C:\WINDOWS\system32\NILaunch.exe
C:\Program Files\Common Files\AOL\1144029693\ee\AOLSoftware.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\NZSearch\nzspc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Second Nature\Snsicon.exe
C:\Program Files\GoZone\GoZone_iSync.exe
C:\Program Files\Stardock\DesktopGadgets\NaturalDesktop\NaturalDesktop.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\bmwebcfg.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\WINDOWS\system32\RioMSC.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Sprint\Sprint PCS Connection Manager\CMSPCSUtilSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wuauclt.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://cm.my.yahoo.com/O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O3 - Toolbar: ZeroBar - {F5735C15-1FB2-41FE-BA12-242757E69DDE} - C:\Program Files\NetZero\Toolbar.dll
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [UC_Start] C:\IBMTools\Updater\ucstartup.exe
O4 - HKLM\..\Run: [ibmmessages] c:\Program Files\IBM\Messages By IBM\ibmmessages.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [InstantAccess] C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE /h
O4 - HKLM\..\Run: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe" -start
O4 - HKLM\..\Run: [Net-It Launcher] C:\WINDOWS\system32\NILaunch.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1144029693\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\RunServices: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
O4 - HKCU\..\Run: [spc_w] "C:\Program Files\NZSearch\nzspc.exe" -w
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: GoZone iSync.lnk = C:\Program Files\GoZone\GoZone_iSync.exe
O4 - Startup: Natural Desktop.lnk = C:\Program Files\Stardock\DesktopGadgets\NaturalDesktop\NaturalDesktop.exe
O4 - Global Startup: Snsicon.lnk = C:\Program Files\Second Nature\Snsicon.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.1\resources\en-US\local\search.html
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {01111C00-3E00-11D2-8470-0060089874ED} (Support.com ActionRunner Class) -
http://help.rr.com/Foundrysdccommon/download/tgctlar.cabO16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) -
http://activation.rr.com/install/downloads/tgctlcm.cabO16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cabO16 - DPF: {2DFF31F9-7893-4922-AF66-C9A1EB4EBB31} (Rhapsody Player Engine) -
http://software-dl.real.com/26f4efcf556a85...ne_Inst_Win.cabO16 - DPF: {5CB1506E-1DEA-4E63-89A7-E40E52AEA1FD} (OnagerCtrl Class) -
http://usfulfillment.puretracks.com/onager.cabO16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) -
http://cdn.scan.onecare.live.com/resource/...lscbase4009.cabO16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cabO16 - DPF: {6632A7E9-FE1F-43D2-A04A-A15951ED63E0} -
http://mediaplayer.walmart.com/installer/install.cabO16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) -
https://webdl.symantec.com/activex/symdlmgr.cabO16 - DPF: {6CEDB6B5-4859-4E3A-BCA2-FB8E565B8AD9} (JNILoader Control) -
http://emeetings.humana.com/sametime/STMee...STJNILoader.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdat...b?1141779362156O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} -
http://mediaplayer.walmart.com/installer/install.cabO16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} (IBM Access Support) -
http://www-307.ibm.com/pc/support/IbmEgath.cabO16 - DPF: {CAFEEFAC-0014-0001-0004-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_04) -
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bytemobile Web Configurator (bmwebcfg) - Bytemobile, Inc. - C:\WINDOWS\system32\bmwebcfg.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Rio MSC Manager (RioMSC) - Digital Networks North America, Inc. - C:\WINDOWS\system32\RioMSC.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Sprint PCS v3 Utility Service - Sprint Spectrum, L.L.C - C:\Program Files\Sprint\Sprint PCS Connection Manager\CMSPCSUtilSvc.exe
O23 - Service: SupportSoft Sprocket Service (medicsp2) (sprtsvc_medicsp2) - Sprint Spectrum, L.L.C - (no file)
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
--
End of file - 12826 bytes