All finished with combofix scan here are the results. Thank's again,ComboFix 08-09-19.09 - HP_Owner 2008-09-20 9:27:00.1 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\HP_Owner\Application Data\YSTEM3~1
C:\Documents and Settings\SMITH FAMILY\Cookies\smith_family@insightexpressai[1].txt
C:\Program Files\Common Files\scurit~1
C:\Program Files\Common Files\stem32~1
C:\WINDOWS\system32\actskn43.ocx
C:\WINDOWS\system32\kr_done1
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-08-20 to 2008-09-20 )))))))))))))))))))))))))))))))
.
2008-09-19 16:17 . 2008-09-19 16:17 d——– C:\WINDOWS\LastGood.Tmp
2008-09-19 16:11 . 2008-09-19 16:11 d——– C:\WINDOWS\system32\scripting
2008-09-19 16:11 . 2008-09-19 16:11 d——– C:\WINDOWS\system32\bits
2008-09-19 16:11 . 2008-09-19 16:11 d——– C:\WINDOWS\l2schemas
2008-09-19 16:08 . 2008-09-19 16:11 d——– C:\WINDOWS\ServicePackFiles
2008-09-19 15:59 . 2008-09-19 15:59 d——– C:\WINDOWS\EHome
2008-09-18 20:11 . 2008-04-13 20:12 1,737,856 ——— C:\WINDOWS\system32\mtxparhd.dll
2008-09-18 20:10 . 2008-04-13 20:11 1,888,992 ——— C:\WINDOWS\system32\ati3duag.dll
2008-09-18 19:51 . 2008-06-13 07:05 272,128 ——— C:\WINDOWS\system32\drivers\bthport.sys
2008-09-18 19:51 . 2008-06-13 07:05 272,128 —–c— C:\WINDOWS\system32\dllcache\bthport.sys
2008-09-18 19:49 . 2008-05-08 10:02 203,136 —–c— C:\WINDOWS\system32\dllcache\rmcast.sys
2008-09-18 19:47 . 2008-04-11 15:04 691,712 —–c— C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-09-18 14:53 . 2008-09-18 14:58 d——– C:\fixwareout
2008-08-25 12:32 . 2008-08-25 12:32 d——– C:\Documents and Settings\Guest\Application Data\School Zone Preferences
2008-08-25 12:30 . 2008-08-25 12:30 52 –a—— C:\WINDOWS\PhatMan.ini
2008-08-25 12:28 . 2004-10-21 21:59 d——– C:\Documents and Settings\Guest\WINDOWS
2008-08-25 12:28 . 2008-08-25 12:30 d——– C:\Documents and Settings\Guest\Application Data\Symantec
2008-08-25 12:28 . 2004-10-21 22:52 d——– C:\Documents and Settings\Guest\Application Data\Sonic
2008-08-25 12:28 . 2004-10-21 22:52 d——– C:\Documents and Settings\Guest\Application Data\SampleView
2008-08-25 12:28 . 2004-10-21 21:58 d——– C:\Documents and Settings\Guest\Application Data\Apple Computer
2008-08-25 12:28 . 2008-08-25 12:28 d——– C:\Documents and Settings\Guest
2008-08-24 20:47 . 2008-08-24 20:48 d——– C:\Program Files\VirtualDJ
2008-08-24 15:46 . 2008-08-24 15:47 d——– C:\Program Files\iTunes
2008-08-24 15:42 . 2008-08-25 16:56 d——– C:\Program Files\Bonjour
2008-08-24 15:40 . 2008-08-24 15:41 d——– C:\Program Files\QuickTime
2008-08-24 15:36 . 2008-08-24 15:36 d——– C:\Program Files\Apple Software Update
2008-08-24 15:35 . 2008-08-24 15:35 d——– C:\Program Files\Common Files\Apple
2008-08-24 15:35 . 2008-08-24 15:35 d——– C:\Documents and Settings\All Users\Application Data\Apple
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-20 13:32 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-09-20 13:27 ——— d—–w C:\Documents and Settings\HP_Owner\Application Data\MSN6
2008-09-20 12:43 ——— d—–w C:\Program Files\MSN Messenger
2008-09-20 12:41 3,645 —-a-w C:\WINDOWS\viassary-hp.reg
2008-09-20 00:32 ——— d—–w C:\Documents and Settings\SMITH FAMILY\Application Data\MSN6
2008-09-19 20:14 77,824 —-a-w C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\HPQ\XPXWWPP5\plugin\bin\WinVerifyTrust.dll
2008-09-16 11:09 ——— d—–w C:\Program Files\Norton 360
2008-09-13 19:22 ——— d—–w C:\Program Files\Incomplete
2008-09-13 18:47 ——— d—–w C:\Program Files\LimeWire
2008-08-31 16:09 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-08-25 20:57 ——— d—–w C:\Program Files\AMT
2008-08-25 00:58 ——— d—–w C:\Program Files\PhatNoise Media Manager
2008-08-24 19:56 ——— d—–w C:\Documents and Settings\HP_Owner\Application Data\Apple Computer
2008-08-24 19:47 ——— d—–w C:\Program Files\iPod
2008-08-24 19:40 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-08-13 19:53 ——— d—–w C:\Program Files\Java
2008-07-30 21:42 23,888 —-a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-07-30 21:28 706 —-a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-07-30 21:28 10,537 —-a-w C:\WINDOWS\system32\drivers\coh_mon.cat
2008-07-07 20:26 253,952 —-a-w C:\WINDOWS\system32\es.dll
2008-07-01 11:48 60,800 —-a-w C:\WINDOWS\system32\S32EVNT1.DLL
2008-06-24 22:12 295,936 ——w C:\WINDOWS\system32\wmpeffects.dll
2008-06-24 16:43 74,240 —-a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 16:57 826,368 —-a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:46 245,248 —-a-w C:\WINDOWS\system32\mswsock.dll
2007-11-12 00:12 2,420 —-a-w C:\Documents and Settings\HP_Owner\Application Data\wklnhst.dat
2005-01-30 19:14 0 –sha-w C:\WINDOWS\SMINST\HPCD.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayExcluded]
@="{4433A54A-1AC8-432F-90FC-85F045CF383C}"
[HKEY_CLASSES_ROOT\CLSID\{4433A54A-1AC8-432F-90FC-85F045CF383C}]
2008-02-26 04:34 576352 –a—— C:\Program Files\Common Files\Symantec Shared\Backup\buShell.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayPending]
@="{F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225}"
[HKEY_CLASSES_ROOT\CLSID\{F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225}]
2008-02-26 04:34 576352 –a—— C:\Program Files\Common Files\Symantec Shared\Backup\buShell.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayProtected]
@="{476D0EA3-80F9-48B5-B70B-05E677C9C148}"
[HKEY_CLASSES_ROOT\CLSID\{476D0EA3-80F9-48B5-B70B-05E677C9C148}]
2008-02-26 04:34 576352 –a—— C:\Program Files\Common Files\Symantec Shared\Backup\buShell.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"Acme.PCHButton"="C:\PROGRA~1\HELPAN~1\HPQ\XPXWWPP5\plugin\bin\PCHButton.exe" [2004-10-21 159744]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-08-21 118784]
"HPHUPD06"="c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [2004-06-07 49152]
"HPHmon06"="C:\WINDOWS\system32\hphmon06.exe" [2004-06-07 659456]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 61440]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-10-21 180269]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-14 233472]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2002-10-16 81920]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-15 253952]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 413696]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 172032]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2003-09-13 50688]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-02-18 51048]
"osCheck"="C:\Program Files\Norton 360\osCheck.exe" [2008-02-26 988512]
"PNAgent"="C:\Program Files\PhatNoise Media Manager\PNAgent.exe" [2005-04-13 40960]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 C:\WINDOWS\ALCXMNTR.EXE]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 C:\WINDOWS\AGRSMMSG.exe]
"SoundMan"="SOUNDMAN.EXE" [2004-07-29 C:\WINDOWS\SOUNDMAN.EXE]
"AlcWzrd"="ALCWZRD.EXE" [2004-07-29 C:\WINDOWS\ALCWZRD.EXE]
C:\Documents and Settings\HP_Owner\Start Menu\Programs\Startup\
HP Organize.lnk - C:\Program Files\Hewlett-Packard\HP Organize\bin\displayAgent.exe [2004-10-21 36864]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SpySubtract.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SpySubtract.lnk
backup=C:\WINDOWS\pss\SpySubtract.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^HP_Owner^Start Menu^Programs^Startup^Picture Motion Browser Media Check Tool.lnk]
path=C:\Documents and Settings\HP_Owner\Start Menu\Programs\Startup\Picture Motion Browser Media Check Tool.lnk
backup=C:\WINDOWS\pss\Picture Motion Browser Media Check Tool.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^HP_Owner^Start Menu^Programs^Startup^SpySubtract.lnk]
path=C:\Documents and Settings\HP_Owner\Start Menu\Programs\Startup\SpySubtract.lnk
backup=C:\WINDOWS\pss\SpySubtract.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
–a—— 2008-07-22 20:42 116040 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-07-30 10:47 289064 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"LightScribeService"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"iPod Service"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"=
"C:\\Program Files\\interMute\\SpySubtract\\SpySub.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
R2 LiveUpdate Notice;LiveUpdate Notice;C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2008-02-18 149352]
R3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-07-30 23888]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\K]
\Shell\AutoRun\command - K:\start.exe
*Newly Created Service* - COMHOST
*Newly Created Service* - PROCEXP90
*Newly Created Service* - USNJSVC
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
ShellExecuteHooks-{FA010552-4A27-4cb1-A1BB-3E2D697F1639} - (no file)
.
——- Supplementary Scan ——-
.
R0 -: HKCU-Main,Default_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
R0 -: HKLM-Main,Search Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
O8 -: &Windows Live Search - C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 -: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-09-20 09:32:59
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-09-20 9:39:07
ComboFix-quarantined-files.txt 2008-09-20 13:39:03
Pre-Run: 155,829,813,248 bytes free
Post-Run: 156,259,569,664 bytes free
196 — E O F — 2008-09-19 20:19:56