Hi,
Thank you for your help. Here are the scan logs:
ComboFix 07-08-23.5 - "AndiL" 2007-08-23 0:36:58.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.313 [GMT -5:00]
* Created a new restore point
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\_003956_.tmp.dll
C:\WINDOWS\system32\_003957_.tmp.dll
C:\WINDOWS\system32\_003958_.tmp.dll
C:\WINDOWS\system32\_003959_.tmp.dll
C:\WINDOWS\system32\_003966_.tmp.dll
C:\WINDOWS\system32\_003967_.tmp.dll
C:\WINDOWS\system32\_003968_.tmp.dll
C:\WINDOWS\system32\_003970_.tmp.dll
C:\WINDOWS\system32\_003971_.tmp.dll
C:\WINDOWS\system32\_003974_.tmp.dll
C:\WINDOWS\system32\_003975_.tmp.dll
C:\WINDOWS\system32\_003977_.tmp.dll
C:\WINDOWS\system32\_003978_.tmp.dll
C:\WINDOWS\system32\_003979_.tmp.dll
C:\WINDOWS\system32\_003981_.tmp.dll
C:\WINDOWS\system32\_003982_.tmp.dll
C:\WINDOWS\system32\_003984_.tmp.dll
C:\WINDOWS\system32\_003988_.tmp.dll
C:\WINDOWS\system32\_003989_.tmp.dll
C:\WINDOWS\system32\_003991_.tmp.dll
C:\WINDOWS\system32\_003994_.tmp.dll
C:\WINDOWS\system32\_003996_.tmp.dll
C:\WINDOWS\system32\_003997_.tmp.dll
C:\WINDOWS\system32\_003998_.tmp.dll
C:\WINDOWS\system32\_003999_.tmp.dll
C:\WINDOWS\system32\_004002_.tmp.dll
C:\WINDOWS\system32\_004004_.tmp.dll
C:\WINDOWS\system32\_004005_.tmp.dll
C:\WINDOWS\system32\_004006_.tmp.dll
C:\WINDOWS\system32\_004010_.tmp.dll
C:\WINDOWS\system32\_004012_.tmp.dll
C:\WINDOWS\system32\_004065_.tmp.dll
C:\WINDOWS\system32\_004066_.tmp.dll
C:\WINDOWS\system32\_004067_.tmp.dll
C:\WINDOWS\system32\_004068_.tmp.dll
C:\WINDOWS\system32\_004075_.tmp.dll
C:\WINDOWS\system32\_004076_.tmp.dll
C:\WINDOWS\system32\_004077_.tmp.dll
C:\WINDOWS\system32\_004079_.tmp.dll
C:\WINDOWS\system32\_004080_.tmp.dll
C:\WINDOWS\system32\_004083_.tmp.dll
C:\WINDOWS\system32\_004084_.tmp.dll
C:\WINDOWS\system32\_004086_.tmp.dll
C:\WINDOWS\system32\_004087_.tmp.dll
C:\WINDOWS\system32\_004088_.tmp.dll
C:\WINDOWS\system32\_004090_.tmp.dll
C:\WINDOWS\system32\_004091_.tmp.dll
C:\WINDOWS\system32\_004093_.tmp.dll
C:\WINDOWS\system32\_004097_.tmp.dll
C:\WINDOWS\system32\_004098_.tmp.dll
C:\WINDOWS\system32\_004100_.tmp.dll
C:\WINDOWS\system32\_004103_.tmp.dll
C:\WINDOWS\system32\_004105_.tmp.dll
C:\WINDOWS\system32\_004106_.tmp.dll
C:\WINDOWS\system32\_004107_.tmp.dll
C:\WINDOWS\system32\_004108_.tmp.dll
C:\WINDOWS\system32\_004111_.tmp.dll
C:\WINDOWS\system32\_004113_.tmp.dll
C:\WINDOWS\system32\_004114_.tmp.dll
C:\WINDOWS\system32\_004115_.tmp.dll
C:\WINDOWS\system32\_004119_.tmp.dll
C:\WINDOWS\system32\_004121_.tmp.dll
C:\WINDOWS\system32\_004122_.tmp.dll
C:\WINDOWS\system32\_004123_.tmp.dll
C:\WINDOWS\system32\_004124_.tmp.dll
C:\WINDOWS\system32\_004128_.tmp.dll
C:\WINDOWS\system32\_004129_.tmp.dll
C:\WINDOWS\system32\_004131_.tmp.dll
C:\WINDOWS\system32\_004134_.tmp.dll
C:\WINDOWS\system32\_004136_.tmp.dll
C:\WINDOWS\system32\_004137_.tmp.dll
C:\WINDOWS\system32\_004138_.tmp.dll
C:\WINDOWS\system32\_004139_.tmp.dll
C:\WINDOWS\system32\_004142_.tmp.dll
C:\WINDOWS\system32\_004144_.tmp.dll
C:\WINDOWS\system32\_004145_.tmp.dll
C:\WINDOWS\system32\_004146_.tmp.dll
C:\WINDOWS\system32\_004150_.tmp.dll
C:\WINDOWS\system32\_004152_.tmp.dll
C:\WINDOWS\system32\_006386_.tmp.dll
C:\WINDOWS\system32\_006387_.tmp.dll
C:\WINDOWS\system32\_006388_.tmp.dll
C:\WINDOWS\system32\_006389_.tmp.dll
C:\WINDOWS\system32\_006396_.tmp.dll
C:\WINDOWS\system32\_006397_.tmp.dll
C:\WINDOWS\system32\_006398_.tmp.dll
C:\WINDOWS\system32\_006400_.tmp.dll
C:\WINDOWS\system32\_006401_.tmp.dll
C:\WINDOWS\system32\_006404_.tmp.dll
C:\WINDOWS\system32\_006405_.tmp.dll
C:\WINDOWS\system32\_006407_.tmp.dll
C:\WINDOWS\system32\_006408_.tmp.dll
C:\WINDOWS\system32\_006409_.tmp.dll
C:\WINDOWS\system32\_006411_.tmp.dll
C:\WINDOWS\system32\_006412_.tmp.dll
C:\WINDOWS\system32\_006413_.tmp.dll
C:\WINDOWS\system32\_006414_.tmp.dll
C:\WINDOWS\system32\_006418_.tmp.dll
C:\WINDOWS\system32\_006419_.tmp.dll
C:\WINDOWS\system32\_006421_.tmp.dll
C:\WINDOWS\system32\_006424_.tmp.dll
C:\WINDOWS\system32\_006426_.tmp.dll
C:\WINDOWS\system32\_006427_.tmp.dll
C:\WINDOWS\system32\_006428_.tmp.dll
C:\WINDOWS\system32\_006429_.tmp.dll
C:\WINDOWS\system32\_006432_.tmp.dll
C:\WINDOWS\system32\_006434_.tmp.dll
C:\WINDOWS\system32\_006435_.tmp.dll
C:\WINDOWS\system32\_006436_.tmp.dll
C:\WINDOWS\system32\_006440_.tmp.dll
C:\WINDOWS\system32\_006442_.tmp.dll
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup
C:\WINDOWS\system32\drivers\fad.sys
F:\Autorun.inf
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_WINNOTIFY
((((((((((((((((((((((((( Files Created from 2007-07-23 to 2007-08-23 )))))))))))))))))))))))))))))))
2007-08-23 00:34 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-18 22:52 82,248 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\iksyssec.sys
2007-08-18 22:52 57,672 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\iksysflt.sys
2007-08-18 22:52 40,264 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\ikfilesec.sys
2007-08-18 22:52 29,000 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\kcom.sys
2007-08-18 22:52 <DIR> d-------- C:\Program Files\Spyware Doctor
2007-08-18 22:52 <DIR> d-------- C:\DOCUME~1\AndiL\APPLIC~1\PC Tools
2007-08-18 22:50 626,688 --a------ C:\WINDOWS\SYSTEM32\msvcr80.dll
2007-08-18 21:43 77,312 --a------ C:\WINDOWS\ua2.dll
2007-08-17 23:57 <DIR> d-------- C:\WINDOWS\Google Toolbar
2007-08-17 19:44 4,398 --a------ C:\WINDOWS\SYSTEM32\tmp.reg
2007-08-11 16:50 4,096 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\ohciusb.sys
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-23 00:30 --------- d-------- C:\DOCUME~1\AndiL\APPLIC~1\WeatherBug
2007-08-23 00:30 --------- d-------- C:\DOCUME~1\AndiL\APPLIC~1\WeatherBug
2007-08-22 23:49 --------- d-------- C:\DOCUME~1\AndiL\APPLIC~1\BayScribe
2007-08-22 23:49 --------- d-------- C:\DOCUME~1\AndiL\APPLIC~1\BayScribe
2007-08-21 08:40 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\GuruNet
2007-08-18 21:48 --------- d-------- C:\Program Files\Pink Calendar
2007-08-18 21:30 131584 --a------ C:\WINDOWS\system32\SpoonUninstall.exe
2007-08-18 00:05 --------- d-------- C:\Program Files\Collectorz.com
2007-08-18 00:03 --------- d-------- C:\Program Files\ICQ
2007-08-18 00:02 --------- d-------- C:\Program Files\WS_FTP Pro
2007-08-18 00:00 --------- d-------- C:\Program Files\MUSICMATCH
2007-08-17 23:59 --------- d-------- C:\Program Files\Ahead
2007-08-17 23:55 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-08-17 23:53 --------- d-------- C:\Program Files\Critical Thinking Software
2007-08-17 23:52 --------- d--h----- C:\Program Files\Zero G Registry
2007-08-17 23:52 --------- d-------- C:\Program Files\Critical Thinking Demos
2007-08-17 23:50 --------- d-------- C:\Program Files\Spelling Bee Tutor-PDA
2007-08-17 23:48 --------- d-------- C:\Program Files\Yahoo!
2007-08-17 23:48 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo
2007-08-13 09:41 --------- d-------- C:\Program Files\Red NoteBook
2007-08-11 16:16 --------- d-------- C:\Program Files\Creative
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\dllcache\cdm.dll
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\dllcache\wuauclt.exe
2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\dllcache\wuaueng.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll
2007-07-29 13:02 --------- d-------- C:\Program Files\BayScribe
2007-07-19 12:20 --------- d-------- C:\Program Files\Google
2007-07-05 13:44 --------- d-------- C:\DOCUME~1\AndiL\APPLIC~1\Sibelius Software
2007-07-05 13:44 --------- d-------- C:\DOCUME~1\AndiL\APPLIC~1\Sibelius Software
2007-07-05 13:42 --------- d-------- C:\Program Files\Sibelius Software
2007-06-22 23:29 --------- d-------- C:\Program Files\PopCap Games
2005-09-19 12:30 774144 --a------ C:\Program Files\RngInterstitial.dll
2005-05-18 00:18 224590 --a--c--- C:\WINDOWS\Fonts.\PCSimplicitee.exe
2005-05-18 00:18 145088 --a--c--- C:\WINDOWS\Fonts.\PCHardBall.exe
2005-05-18 00:18 141355 --a--c--- C:\WINDOWS\Fonts.\PCmichelle.exe
2005-05-18 00:18 138703 --a--c--- C:\WINDOWS\Fonts.\PCBrita.exe
2005-05-18 00:17 233454 --a--c--- C:\WINDOWS\Fonts.\PCLewis.exe
2005-05-18 00:17 146103 --a--c--- C:\WINDOWS\Fonts.\PCScratchPad.exe
2005-05-18 00:17 133873 --a--c--- C:\WINDOWS\Fonts.\pcplayful.exe
2005-05-18 00:17 128153 --a--c--- C:\WINDOWS\Fonts.\PCBigStick.exe
2005-05-18 00:17 124681 --a--c--- C:\WINDOWS\Fonts.\PCKnobbish.exe
2005-05-18 00:16 134489 --a--c--- C:\WINDOWS\Fonts.\PCGoo.exe
2005-05-18 00:16 131330 --a--c--- C:\WINDOWS\Fonts.\PCSketched.exe
2005-05-18 00:16 130498 --a--c--- C:\WINDOWS\Fonts.\PCEightBall.exe
2005-05-18 00:16 130000 --a--c--- C:\WINDOWS\Fonts.\PCJennPen.exe
2005-05-18 00:14 130751 --a--c--- C:\WINDOWS\Fonts.\PCSquirrelly.exe
2005-05-07 21:49 6132 --a--c--- C:\Program Files\top52--0047.htm
2005-05-07 21:48 6132 --a--c--- C:\Program Files\top52--0028.htm
2005-05-07 21:47 1039189 --a--c--- C:\Program Files1mp3ins.exe
2005-04-17 12:07 1584088 --a--c--- C:\Program Files\earpro4setup.exe
2005-03-29 23:05 131072 --a--c--- C:\Program Files\Setup.exe
2005-03-27 20:08 10831584 --a--c--- C:\Program Files\PestPatrolv5.exe
2004-10-20 21:18 376672 --a--c--- C:\Program Files\DLM_2200043_ENU.exe
2004-06-22 21:03 411329 --a--c--- C:\Program Files\slimlist.exe
2004-05-04 11:50 8029451 --a--c--- C:\Program Files\SetupPestPatrolHome.exe
2004-04-07 09:28 2736029 --a--c--- C:\Program Files\treepadplus.zip
2004-02-19 23:15 457 --a--c--- C:\Program Files\INSTALL.LOG
2003-05-21 19:10 3662787 --a--c--- C:\Program Files\spybotsd12.exe
2003-05-15 11:17 2838184 --a--c--- C:\Program Files\ica32.exe
2003-05-13 23:30 260684 --a--c--- C:\Program Files\ICQMessageArchive.exe
2003-05-13 18:14 1897672 --a--c--- C:\Program Files\winzip81.exe
2003-05-12 22:51 660696 --a--c--- C:\Program Files\rednotebook19b.exe
2003-05-12 18:55 5082328 --a--c--- C:\Program Files\cuteftppro.exe
2003-05-12 18:48 3025408 --a--c--- C:\Program Files\cuteftp.exe
2003-05-12 18:16 3978384 --a--c--- C:\Program Files\icqpro2003a.exe
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5E028439-81C7-4B82-BC74-25156306F532}]
2007-06-14 09:10 258048 --a------ C:\Program Files\BayScribe\bayscribe.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2004-08-20 15:55]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2004-08-20 15:51]
"FinePrint Dispatcher v5"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe" [2003-06-17 10:12]
"DVDSentry"="C:\WINDOWS\System32\DSentry.exe" [2002-08-14 18:22]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2003-04-29 18:31]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 04:59 C:\WINDOWS\BCMSMMSG.exe]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2002-07-09 21:45]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 2006\pccguide.exe" [2006-03-08 13:30]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 19:58]
"F5D9050"="C:\Program Files\Belkin\F5D9050\Belkinwcui.exe" [2006-03-14 16:52]
"TrueImageMonitor.exe"="C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe" [2005-09-21 13:16]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2002-08-29 05:00]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Weather"="C:\Program Files\AWS\WeatherBug\Weather.exe" [2005-06-07 13:58]
"PhotoShow Deluxe Media Manager"="C:\PROGRA~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe" []
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-20 20:14]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\WINDOWS\System32\hanonvt.ini
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 relog_ap
"Notification Packages"= :\WINDOWS\System32\srrstr.dll cecli
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 8.0 Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 8.0 Tray Icon.lnk
backup=C:\WINDOWS\pss\America Online 8.0 Tray Icon.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Device Detector 2.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Device Detector 2.lnk
backup=C:\WINDOWS\pss\Device Detector 2.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^eFax Tray Menu.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\eFax Tray Menu.lnk
backup=C:\WINDOWS\pss\eFax Tray Menu.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^GuruNet.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\GuruNet.lnk
backup=C:\WINDOWS\pss\GuruNet.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Printkey2000.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Printkey2000.lnk
backup=C:\WINDOWS\pss\Printkey2000.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^AndiL^Start Menu^Programs^Startup^eBot.lnk]
path=C:\Documents and Settings\AndiL\Start Menu\Programs\Startup\eBot.lnk
backup=C:\WINDOWS\pss\eBot.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^AndiL^Start Menu^Programs^Startup^HotSync Manager.lnk]
path=C:\Documents and Settings\AndiL\Start Menu\Programs\Startup\HotSync Manager.lnk
backup=C:\WINDOWS\pss\HotSync Manager.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service]
"C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
"C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CaISSDT]
"C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell AIO Printer A940]
"C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E6TaskPanel]
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" -winstart
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eTrustPPAP]
"C:\Program Files\CA\eTrust PestPatrol\PPActiveDetection.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
C:\Program Files\Ahead\InCD\InCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mirabilis ICQ]
C:\PROGRA~1\ICQ\ICQNet.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyStartUp10.0]
"C:\Program Files\Microsoft Money\System\Activation.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
"C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TB_setup]
C:\DOCUME~1\AndiL\LOCALS~1\Temp\TB_ANI~1.EXE /dcheck
R0 snapman;Acronis Snapshots Manager;C:\WINDOWS\System32\DRIVERS\snapman.sys
R0 timounter;Acronis TrueImage Backup Archive Explorer;C:\WINDOWS\System32\DRIVERS\timntr.sys
R2 ohciusb;Open Host Controller Miniport USB Driver;\??\C:\WINDOWS\System32\drivers\ohciusb.sys
R2 tifsfilter;Acronis TrueImage FS Filter;C:\WINDOWS\System32\DRIVERS\tifsfilt.sys
R3 BCMModem;BCM V.92 56K Modem;C:\WINDOWS\System32\DRIVERS\BCMSM.sys
R3 StreamSurge;StreamSurge Driver (miniport);C:\WINDOWS\System32\DRIVERS\ss.sys
S2 InCDsrvR;InCD Helper (read only);C:\Program Files\Ahead\InCD\InCDsrv.exe -r
S3 StMp3Rec;Player Recovery Device Control Driver;C:\WINDOWS\System32\Drivers\StMp3Rec.sys
S3 VNUSB;VN Series Device;C:\WINDOWS\System32\DRIVERS\VNUSB.sys
*Newly Created Service* - ALG
*Newly Created Service* - GTNDIS5
*Newly Created Service* - IPNAT
*Newly Created Service* - SHAREDACCESS
Contents of the 'Scheduled Tasks' folder
2007-08-22 23:01:11 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
2007-08-21 06:56:23 C:\WINDOWS\Tasks\PPv5Scan_Daily as AndiL at 1 55 AM.job - C:\Program Files\CA\eTrust PestPatrol\ppv5consumercl.exe
2007-08-14 17:12:02 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job - C:\Program Files\Uniblue\SpeedUpMyPC\SpeedUpMyPC.exe
2007-05-16 17:12:19 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job - C:\Program Files\Uniblue\SpeedUpMyPC\SpeedUpMyPC.exe
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-08-23 00:55:17
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-08-23 1:01:38 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-08-23 01:01
--- E O F ---
Logfile of HijackThis v1.99.1
Scan saved at 1:03:06 AM, on 8/23/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\cisvc.exe
C:\PROGRA~1\TRENDM~1\INTERN~3\PcCtlCom.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\Photodex\ProShowGold\progold3\ScsiAccess.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Trend Micro\Internet Security 2006\pccguide.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Belkin\F5D9050\Belkinwcui.exe
C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\DvzCommon\DvzMsgr.exe
C:\Program Files\eFax Messenger Plus\Dllcmd32.exe
C:\Program Files\Pink Calendar\PinkCal.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~3\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~3\tmproxy.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\PROGRA~1\TRENDM~1\INTERN~3\TmPfw.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\cidaemon.exe
C:\unzipped\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.refdesk.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Trend Micro Antifraud Toolbar - {06647158-359E-4D10-A8DE-E6145DA90BE9} - C:\PROGRA~1\TRENDM~1\INTERN~3\PccIeBar.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: BayScribeBHO - {5E028439-81C7-4B82-BC74-25156306F532} - C:\Program Files\BayScribe\bayscribe.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: My Web Search Bar BHO - {8EAB99C1-F9EC-4b64-A4BA-D9BCAE8779C2} - C:\Program Files\MyWebSearchWB\bar\1.bin\W6BAR.DLL (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: Trend Micro Antifraud Toolbar - {871F91FD-3A92-4988-A842-16AB2CFF5AF1} - C:\PROGRA~1\TRENDM~1\INTERN~3\PccIeBar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [FinePrint Dispatcher v5] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2006\pccguide.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [F5D9050] C:\Program Files\Belkin\F5D9050\Belkinwcui.exe
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Ahead\NEROPH~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: .lnk = C:\WINDOWS\SYSTEM32\regsvc.exe
O4 - Startup: PinkCal.lnk = C:\Program Files\Pink Calendar\PinkCal.exe
O4 - Global Startup: Dataviz Messenger.lnk = C:\WINDOWS\DvzCommon\DvzMsgr.exe
O4 - Global Startup: Live Menu.lnk = C:\Program Files\eFax Messenger Plus\Dllcmd32.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Search -
http://bar.mywebsear...?p=ZNxdm824DHUS
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Add to EverNote - res://C:\Program Files\EverNote\EverNote\enbar.dll/2000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: GuruNet... - file:C:\Program Files\GuruNet\Html\atiemenu.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Add to EverNote - {A5ABA0BB-F195-40d8-A5E9-0801153E6597} - C:\Program Files\EverNote\EverNote\enbar.dll
O9 - Extra 'Tools' menuitem: Add to EverNote - {A5ABA0BB-F195-40d8-A5E9-0801153E6597} - C:\Program Files\EverNote\EverNote\enbar.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: ppctlcab -
http://www.pestscan....er/ppctlcab.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -
http://ak.imgfarm.co...tup1.0.0.15.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) -
http://download.weat...Transporter.cab?
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) -
http://www.pestscan....r/axscanner.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
http://appldnld.m7z....iTunesSetup.exe
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} -
http://toolbar.googl...gleActivate.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) -
http://www.sibelius....tiveXPlugin.cab
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} (Photodex Presenter AX control) -
http://www.photodex.com/pxplay.cab
O20 - AppInit_DLLs: C:\WINDOWS\System32\hanonvt.ini
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LWWLicenseService - WoltersKluwerLWW - C:\Program Files\Common Files\WoltersKluwerLWW Shared\Service\LWWLicenseService.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~3\PcCtlCom.exe
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowGold\progold3\ScsiAccess.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~3\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~3\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~3\tmproxy.exe