I've been through all the steps + panda scan. I've ran avg anit-spyware, superantispyware, spybot sd, ad-aware 2007, and just got through combofix. Post it's Log along with a new hijack log. Is there anybody out there?
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:03:41 PM, on 3/26/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Alltel\QuickLink Mobile\QuickLink Mobile.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [Instafinder] C:\Program Files\Instafinder\instafinder.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) -
http://www.musicnote...ad/mnviewer.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -
http://ak.exe.imgfar...p1.0.0.15-3.cabO16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) -
http://lads.myspace....ploader1006.cabO16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) -
http://ipgweb.cce.hp...ads/sysinfo.cabO16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) -
http://static.slide....ageUploader.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoft...free/asinst.cabO16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -
http://download.game...aploader_v6.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{20F66A4B-A3E6-4ADC-92B1-0B72EC828167}: NameServer = 166.102.165.11 166.102.165.13
O17 - HKLM\System\CS1\Services\Tcpip\..\{20F66A4B-A3E6-4ADC-92B1-0B72EC828167}: NameServer = 166.102.165.11 166.102.165.13
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: efcdaaa - efcdaaa.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
--
End of file - 7491 bytes
ComboFix 08-03-25.4 - Todd 2008-03-26 14:15:13.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.111 [GMT -5:00]
Running from: C:\Documents and Settings\Todd\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Todd\Application Data\Adssite Advanced Toolbar
C:\Documents and Settings\Todd\Application Data\Adssite Advanced Toolbar\selected.xml
C:\Documents and Settings\Todd\Application Data\FunWebProducts
C:\Program Files\Adssite Advanced Toolbar
C:\Program Files\FunWebProducts
C:\Program Files\MyWebSearch
C:\Program Files\MyWebSearch\bar\History\search2
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat
C:\Program Files\MyWebSearch\bar\Settings\setting2.htm
C:\Program Files\MyWebSearch\bar\Settings\settings.dat
C:\Program Files\outlook
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\bkR11\ftCa.log
C:\Temp\gbRve12
C:\Temp\gbRve12\csLioes.log
C:\WINDOWS\BM0ade429f.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\Fonts\a.zip
C:\WINDOWS\Fonts\acrsecB.fon
C:\WINDOWS\pskt.ini
C:\WINDOWS\smdat32a.sys
C:\WINDOWS\smdat32m.sys
C:\WINDOWS\system32\accdd.ini
C:\WINDOWS\system32\accdd.ini2
C:\WINDOWS\system32\adssitesuggest.dll
C:\WINDOWS\system32\aqVreo18
C:\WINDOWS\system32\aqVreo18\aqVreo182328.exe
C:\WINDOWS\system32\asfhgkbf.ini
C:\WINDOWS\system32\awtsr.dll
C:\WINDOWS\system32\dgqboift.dll
C:\WINDOWS\system32\efcdaaa.dll
C:\WINDOWS\system32\erflmdwt.dll
C:\WINDOWS\system32\fbkghfsa.dll
C:\WINDOWS\system32\fdqctvte.dll
C:\WINDOWS\system32\ffrfyqlv.dll
C:\WINDOWS\system32\gdtjjlhi.dll
C:\WINDOWS\system32\gubshvss.ini
C:\WINDOWS\system32\hbeevaqa.dll
C:\WINDOWS\system32\ibxnblhc.dll
C:\WINDOWS\system32\ihljjtdg.ini
C:\WINDOWS\system32\ikmlswxq.dll
C:\WINDOWS\system32\inouparb.dll
C:\WINDOWS\system32\jxafoovb.dll
C:\WINDOWS\system32\kmd.exe
C:\WINDOWS\system32\krdyexxh.dll
C:\WINDOWS\system32\lebplwgb.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mwckcsqp.dll
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\pqsckcwm.ini
C:\WINDOWS\system32\rstwa.ini
C:\WINDOWS\system32\rstwa.ini2
C:\WINDOWS\system32\srutv.ini
C:\WINDOWS\system32\srutv.ini2
C:\WINDOWS\system32\ssttu.dll
C:\WINDOWS\system32\ssvhsbug.dll
C:\WINDOWS\system32\tuvstus.dll
C:\WINDOWS\system32\twdmlfre.ini
C:\WINDOWS\system32\udpomvyo.dll
C:\WINDOWS\system32\UpMedia\SearchTool.dll
C:\WINDOWS\system32\UpMedia\uninstallSE.exe
C:\WINDOWS\system32\uttss.ini
C:\WINDOWS\system32\uttss.ini2
C:\WINDOWS\system32\wjbcinim.dll
C:\x.dat
C:\z.dat
.
---- Previous Run -------
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\bkR11
C:\Temp\bkR11\ftCa.log
C:\WINDOWS\system32\auujalmj.dll
C:\WINDOWS\system32\byjiybkf.dll
C:\WINDOWS\system32\enqrimsq.dll
C:\WINDOWS\system32\fwdedvsn.dll
C:\WINDOWS\system32\jsjnbbwl.dll
C:\WINDOWS\system32\kjkmp.ini
C:\WINDOWS\system32\kjkmp.ini2
C:\WINDOWS\system32\kmuijxuf.dll
C:\WINDOWS\system32\oswujset.dll
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\pjgwmctk.dll
C:\WINDOWS\system32\qctsshhi.dll
C:\WINDOWS\system32\sqvboehr.dll
C:\WINDOWS\system32\udqlamcd.dll
C:\WINDOWS\system32\UpMedia
C:\WINDOWS\system32\UpMedia\SearchTool.dll
C:\WINDOWS\system32\UpMedia\uninstallSE.exe
C:\WINDOWS\system32\wsbubsax.dll
C:\WINDOWS\system32\xtigqppm.dll
C:\WINDOWS\system32\ynaprqug.dll
C:\x.dat
C:\z.dat
C:\WINDOWS\Fonts\'
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_TnIDriver
((((((((((((((((((((((((( Files Created from 2008-02-26 to 2008-03-26 )))))))))))))))))))))))))))))))
.
2008-03-25 16:46 . 2008-03-25 16:46 <DIR> d-------- C:\Program Files\Lavasoft
2008-03-25 16:46 . 2008-03-25 16:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-25 03:01 . 2008-03-25 03:01 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-03-25 00:42 . 2008-03-25 00:42 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-03-25 00:42 . 2008-03-25 09:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-24 22:56 . 2008-03-25 00:26 354 ---hs---- C:\WINDOWS\system32\recybhvr.ini
2008-03-24 15:10 . 2008-03-24 15:10 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2008-03-24 13:31 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-03-24 13:31 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-03-24 13:31 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-03-23 22:38 . 2008-03-23 22:38 <DIR> d-------- C:\WINDOWS\.jagex_cache_32
2008-03-23 22:26 . 2008-03-23 22:44 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-23 22:25 . 2008-03-23 22:47 <DIR> d-------- C:\Program Files\Windows Live
2008-03-23 22:24 . 2008-03-23 22:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-03-23 14:17 . 2008-03-25 16:45 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-23 10:03 . 2008-03-23 10:03 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Grisoft
2008-03-23 09:31 . 2008-03-23 09:31 29,696 ---hs---- C:\Documents and Settings\Todd\lsass.exe
2008-03-22 11:43 . 2008-03-22 11:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Banner Maker Pro for Flash
2008-03-22 11:20 . 2008-03-22 11:20 84,761 --a------ C:\WINDOWS\system32\mysidesearch_sidebar_uninstall.exe
2008-03-22 11:19 . 2008-03-22 11:19 80,121 --a------ C:\WINDOWS\system32\adzgalore-remove.exe
2008-03-22 11:19 . 2008-03-22 11:19 40,713 --a------ C:\WINDOWS\system32\cpmsky-uninst.exe
2008-03-22 11:11 . 2008-03-23 09:25 <DIR> d-------- C:\WINDOWS\system32\usnv
2008-03-22 11:11 . 2008-03-22 11:11 <DIR> d-------- C:\WINDOWS\system32\mp2
2008-03-22 11:11 . 2008-03-23 09:25 <DIR> d-------- C:\WINDOWS\system32\FxTmp
2008-03-22 11:11 . 2008-03-22 11:11 37,376 --a------ C:\WINDOWS\mrofinu1188.exe.tmp
2008-03-22 11:11 . 2008-03-23 09:32 37,376 --a------ C:\WINDOWS\mrofinu1188.exe
2008-03-22 11:11 . 2008-03-22 11:11 2,671 --a------ C:\WINDOWS\17PHolmes1000106.exe
2008-03-22 11:10 . 2008-03-22 11:10 5,632 --a------ C:\dllhost.exe
2008-03-22 11:10 . 2008-03-22 11:10 2,671 --a------ C:\WINDOWS\da.exe
2008-03-18 07:19 . 2008-03-18 07:19 153,600 --a------ C:\WINDOWS\system32\mysidesearch_sidebar.dll
2008-03-17 21:28 . 2008-03-17 21:28 268 --ah----- C:\sqmdata15.sqm
2008-03-17 21:28 . 2008-03-17 21:28 244 --ah----- C:\sqmnoopt15.sqm
2008-03-13 22:49 . 2008-03-13 22:49 268 --ah----- C:\sqmdata14.sqm
2008-03-13 22:49 . 2008-03-13 22:49 244 --ah----- C:\sqmnoopt14.sqm
2008-03-08 13:26 . 2008-03-08 13:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PopCap
2008-03-07 08:58 . 2008-03-07 08:58 60,416 --a------ C:\WINDOWS\system32\cpmsky.dll
2008-03-06 14:27 . 2008-03-06 14:27 268 --ah----- C:\sqmdata13.sqm
2008-03-06 14:27 . 2008-03-06 14:27 244 --ah----- C:\sqmnoopt13.sqm
2008-03-06 10:07 . 2008-03-06 10:07 268 --ah----- C:\sqmdata12.sqm
2008-03-06 10:07 . 2008-03-06 10:07 244 --ah----- C:\sqmnoopt12.sqm
2008-03-06 08:46 . 2008-03-06 08:46 268 --ah----- C:\sqmdata11.sqm
2008-03-06 08:46 . 2008-03-06 08:46 244 --ah----- C:\sqmnoopt11.sqm
2008-03-05 23:29 . 2008-03-05 23:29 268 --ah----- C:\sqmdata10.sqm
2008-03-05 23:29 . 2008-03-05 23:29 244 --ah----- C:\sqmnoopt10.sqm
2008-03-05 02:45 . 2008-03-05 02:45 268 --ah----- C:\sqmdata09.sqm
2008-03-05 02:45 . 2008-03-05 02:45 244 --ah----- C:\sqmnoopt09.sqm
2008-03-04 22:30 . 2008-03-04 22:30 268 --ah----- C:\sqmdata08.sqm
2008-03-04 22:30 . 2008-03-04 22:30 244 --ah----- C:\sqmnoopt08.sqm
2008-03-01 17:54 . 2008-03-01 17:54 268 --ah----- C:\sqmdata07.sqm
2008-03-01 17:54 . 2008-03-01 17:54 244 --ah----- C:\sqmnoopt07.sqm
2008-03-01 10:55 . 2008-03-01 10:55 268 --ah----- C:\sqmdata06.sqm
2008-03-01 10:55 . 2008-03-01 10:55 244 --ah----- C:\sqmnoopt06.sqm
2008-02-29 23:56 . 2008-03-04 11:00 <DIR> d-------- C:\Documents and Settings\Todd\Application Data\DivX
2008-02-29 23:54 . 2008-03-06 10:09 <DIR> d-------- C:\Program Files\DivX
2008-02-29 19:24 . 2008-02-29 19:24 <DIR> d-------- C:\Program Files\Ligos
2008-02-29 19:24 . 2000-06-23 15:05 136,704 --a------ C:\WINDOWS\system32\iacenc.dll
2008-02-29 18:58 . 2008-02-29 18:58 36 ---h----- C:\WINDOWS\system32\swk.ini
2008-02-29 18:41 . 2008-02-29 18:41 <DIR> d-------- C:\Program Files\WinAVIVideoConverter
2008-02-29 03:21 . 2008-02-29 03:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NCH Software
2008-02-28 22:11 . 2005-09-25 21:11 2,494,464 --a------ C:\WINDOWS\system\advrcntr2.dll
2008-02-28 21:56 . 2008-02-28 21:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Musicnotes
2008-02-28 17:43 . 2008-02-28 17:43 <DIR> d-------- C:\Program Files\Apple Software Update
2008-02-28 17:43 . 2008-02-28 17:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-02-28 14:58 . 2008-02-28 14:58 <DIR> d-------- C:\Documents and Settings\Todd\Application Data\Smith Micro
2008-02-28 14:53 . 2007-02-08 20:28 26,656 --a------ C:\WINDOWS\system32\kwutil2k.dll
2008-02-28 14:52 . 2008-02-28 14:53 <DIR> d-------- C:\Program Files\Kyocera Wireless Corp
2008-02-28 14:52 . 2008-02-28 14:52 <DIR> d-------- C:\Program Files\Alltel
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-24 20:11 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-03-24 14:35 --------- d-----w C:\Program Files\Common Files\LightScribe
2008-03-23 22:10 --------- d-----w C:\Program Files\Photo DVD Maker Professional
2008-03-23 22:02 --------- d-----w C:\Program Files\DVD Photo Slideshow Professional
2008-03-23 19:18 --------- d-----w C:\Documents and Settings\Todd\Application Data\SUPERAntiSpyware.com
2008-03-23 19:07 --------- d-----w C:\Documents and Settings\Todd\Application Data\LimeWire
2008-03-22 18:11 --------- d-----w C:\Program Files\LimeWire
2008-03-18 17:16 --------- d-----w C:\Program Files\d2
2008-03-18 16:42 --------- d-----w C:\Program Files\Diablo II
2008-03-18 02:36 --------- d-----w C:\Program Files\XoftSpySE
2008-03-18 02:34 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-18 02:30 --------- d-----w C:\Program Files\Eusing Free Registry Cleaner
2008-03-08 17:08 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-06 15:02 --------- d-----w C:\Program Files\NCH Swift Sound
2008-03-06 14:59 --------- d-----w C:\Documents and Settings\Todd\Application Data\NCH Swift Sound
2008-02-28 05:55 --------- d-----w C:\Program Files\Pure Sudoku
2008-02-21 02:05 43,528 ------w C:\WINDOWS\system32\drivers\pxhelp20.sys
2008-02-18 16:15 --------- d-----w C:\Program Files\Instafinder
2008-02-18 15:06 --------- d-----w C:\Program Files\Need2Find
2008-02-18 15:05 --------- d-----w C:\Program Files\Kazaa
2008-02-18 15:03 905 ----a-w C:\WINDOWS\Fonts\acrsecI.fon
2008-02-18 14:00 --------- d-----w C:\Program Files\Java
2008-02-15 00:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2008-02-14 18:06 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-02-14 16:25 --------- d-----w C:\Program Files\BearShare Applications
2008-02-10 14:28 --------- d-----w C:\Program Files\Trend Micro
2008-02-08 20:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-02-08 17:33 --------- d-----w C:\Documents and Settings\Todd\Application Data\Grisoft
2008-02-08 17:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-08 15:37 --------- d-----w C:\Documents and Settings\Todd\Application Data\SpywareBot
2008-01-26 17:42 --------- d-----w C:\Program Files\Paint.NET
2008-01-26 17:20 --------- d-----w C:\Program Files\MSBuild
2008-01-26 17:19 --------- d-----w C:\Program Files\Reference Assemblies
2008-01-26 17:01 --------- d-----w C:\Program Files\MSXML 6.0
2007-12-16 18:09 18,432 ----a-w C:\Documents and Settings\Todd\Application Data\internaldb41.dat
2007-12-16 15:35 374 ----a-w C:\Documents and Settings\Todd\Application Data\internaldb6334.dat
2007-12-16 15:25 555 ----a-w C:\Documents and Settings\Todd\Application Data\internaldb8467.dat
2006-11-30 01:33 774,144 ----a-w C:\Program Files\RngInterstitial.dll
2006-06-07 13:44 91,480 ----a-w C:\Documents and Settings\Todd\Application Data\GDIPFONTCACHEV1.DAT
2006-02-11 13:51 0 ----a-w C:\Documents and Settings\Todd\Application Data\wklnhst.dat
2004-10-19 21:38 11,052,037 ----a-w C:\Documents and Settings\Todd\Application Data\HCSetup2.0_IW.5.1.exe
2001-07-26 22:58 47 ----a-w C:\Program Files\ACMonitor_X73.ini
2001-07-05 18:46 8,116 ----a-w C:\Program Files\OSLO3071b2.USB
2001-05-11 17:39 53,248 ----a-w C:\Program Files\ACMonitor_X73.exe
2001-05-08 22:36 114,688 ----a-w C:\Program Files\lxarscan.dll
2001-04-23 20:22 1,437 ----a-w C:\Program Files\gtx73.ini
2001-02-22 15:54 768 ----a-w C:\Program Files\x73_lut.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:00 15360]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-02-27 11:39 1310720]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-04-11 12:00 339968]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-04-01 17:11 794624]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2005-02-02 07:12 102492]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-02-02 07:11 692316]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-17 01:11 49152]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24 286720]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 15:24 290816]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2005-02-17 16:01 233534]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 15:54 253952]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 18:50 221184]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 18:50 81920]
"hpqSRMon"="C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 17:31 80896]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 04:42 144784]
"Instafinder"="C:\Program Files\Instafinder\instafinder.exe" [ ]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04 83360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoLogOff"= 1
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-02-27 11:39 282624 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efcdaaa]
efcdaaa.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
R3 HSFHWATI;HSFHWATI;C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys [2004-12-15 10:18]
R3 kwkpcusb;Kyocera CDMA Wireless Modem Driver for KPC;C:\WINDOWS\system32\DRIVERS\kwusbnt.sys [2007-02-08 20:28]
R3 VmbInfce;VmbInfce;C:\WINDOWS\system32\drivers\vmbinfce.sys [2007-01-29 11:32]
S3 DMSKSSRh;DMSKSSRh;C:\DOCUME~1\Todd\LOCALS~1\Temp\DMSKSSRh.sys []
S3 USB_RNDIS_XP;Westell WireSpeed Dual Connect Modem;C:\WINDOWS\system32\DRIVERS\usb8023.sys [2004-08-04 03:00]
.
Contents of the 'Scheduled Tasks' folder
"2008-03-06 02:14:09 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-03-26 08:00:00 C:\WINDOWS\Tasks\MacroVirus Scheduled Scan.job"
- C:\Program Files\MacroVirus\MacroVirus.ex
- C:\Program Files\MacroVirus
"2008-03-26 08:00:00 C:\WINDOWS\Tasks\SpywareBot Scheduled Scan.job"
- C:\Program Files\SpywareBot\SpywareBot.ex
- C:\Program Files\SpywareBot
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-03-26 14:43:53
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe????????6?9?9?8??????? ???B?????????????hLC? ??????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
.
**************************************************************************
.
Completion time: 2008-03-26 14:48:02 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-26 19:47:56
.
2008-03-25 08:01:28 --- E O F ---