I turned off the IE SpySweeper settings. Actually, I had SpySweeper completely shutdown when I did the previous CFScript fix. This time around, I only shut off the IE settings as suggested.
Here are the ComboFix and HijackThis logs, both prior to restart after fix:
Combofix
ComboFix 09-01-02.01 - Charlie 2009-01-04 20:04:19.11 - NTFSx86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Charlie\Desktop\CFScript.txt
.
((((((((((((((((((((((((( Files Created from 2008-12-05 to 2009-01-05 )))))))))))))))))))))))))))))))
.
2009-01-04 18:13 . 2009-01-04 18:13 d——– c:\documents and settings\Kelli\Application Data\Apple Computer
2008-12-30 13:58 . 2008-12-30 13:58 d——– c:\program files\ASUS
2008-12-30 13:58 . 2004-02-27 00:00 962,612 –a—— c:\windows\system32\mfc42d.dll
2008-12-30 13:58 . 2004-02-17 00:00 434,252 –a—— c:\windows\system32\MSVCRTD.DLL
2008-12-30 13:58 . 2005-01-28 03:44 24,576 -ra—— c:\windows\system32\AsIO.dll
2008-12-30 13:58 . 2004-09-07 11:41 5,120 –a—— c:\windows\system32\drivers\AsInsHelp64.sys
2008-12-30 13:58 . 2004-10-14 04:52 4,962 -ra—— c:\windows\system32\drivers\AsIO.sys
2008-12-30 13:58 . 2004-03-10 14:31 3,328 –a—— c:\windows\system32\drivers\AsInsHelp32.sys
2008-12-30 13:57 . 2008-12-30 13:57 5,950 –a—— c:\windows\Ascd_tmp.ini
2008-12-30 12:28 . 2008-12-30 12:28 48,035 –a—— c:\windows\BS_DEF.sys
2008-12-29 20:19 . 2008-12-29 20:19 d——– c:\program files\Malwarebytes' Anti-Malware
2008-12-29 20:19 . 2008-12-29 20:19 d——– c:\documents and settings\Charlie\Application Data\Malwarebytes
2008-12-29 20:19 . 2008-12-29 20:19 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-29 20:19 . 2008-12-03 19:52 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-29 20:19 . 2008-12-03 19:52 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-12-29 19:13 . 2008-12-29 19:13 d——– c:\program files\ERUNT
2008-12-28 20:59 . 2008-12-28 20:59 d——– c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2008-12-27 14:03 . 2008-12-27 14:03 d——– c:\documents and settings\Kelli\Application Data\HP
2008-12-20 13:22 . 2009-01-04 18:06 d——– c:\documents and settings\Kelli\Application Data\HPAppData
2008-12-19 21:02 . 2009-01-04 20:01 d——– c:\documents and settings\Charlie\Application Data\HPAppData
2008-12-19 20:58 . 2008-12-19 20:58 d——– c:\documents and settings\Charlie\Application Data\HP
2008-12-19 20:54 . 2008-12-19 20:54 d——– c:\documents and settings\All Users\Application Data\WEBREG
2008-12-19 20:53 . 2008-12-19 20:53 d——– c:\documents and settings\All Users\Application Data\Hewlett-Packard
2008-12-19 20:53 . 2007-10-30 04:25 49,920 -ra—— c:\windows\system32\drivers\HPZid412.sys
2008-12-19 20:53 . 2007-10-30 04:25 16,496 -ra—— c:\windows\system32\drivers\HPZipr12.sys
2008-12-19 20:52 . 2007-11-08 09:52 271,704 -ra—— c:\windows\system32\hpzids01.dll
2008-12-19 20:52 . 2007-10-20 18:25 117,760 –a—— c:\windows\system32\hpzll5mu.dll
2008-12-19 20:52 . 2007-10-30 04:25 21,568 -ra—— c:\windows\system32\drivers\HPZius12.sys
2008-12-19 20:51 . 2007-10-30 04:11 581,632 -ra—— c:\windows\system32\hpotscl6.dll
2008-12-19 20:51 . 2007-10-30 04:25 372,736 -ra—— c:\windows\system32\hppldcoi.dll
2008-12-19 20:51 . 2007-10-30 04:25 309,760 -ra—— c:\windows\system32\difxapi.dll
2008-12-19 20:51 . 2007-10-30 04:11 303,104 -ra—— c:\windows\system32\hpovst15.dll
2008-12-19 20:46 . 2008-12-19 20:46 d——– c:\documents and settings\All Users\Application Data\HP Product Assistant
2008-12-19 20:46 . 2008-12-19 20:46 d——– c:\documents and settings\All Users\Application Data\HP
2008-12-19 20:45 . 2008-12-19 20:45 d——– c:\program files\Common Files\Hewlett-Packard
2008-12-19 20:44 . 2008-12-19 20:46 d——– c:\program files\Hewlett-Packard
2008-12-19 20:43 . 2008-04-13 14:45 32,128 –a—— c:\windows\system32\drivers\usbccgp.sys
2008-12-19 20:43 . 2008-04-13 14:45 32,128 –a–c— c:\windows\system32\dllcache\usbccgp.sys
2008-12-19 20:43 . 2008-04-13 14:47 25,856 –a—— c:\windows\system32\drivers\usbprint.sys
2008-12-19 20:43 . 2008-04-13 14:47 25,856 –a–c— c:\windows\system32\dllcache\usbprint.sys
2008-12-19 20:42 . 2008-12-19 20:54 157,480 –a—— c:\windows\hpoins27.dat
2008-12-19 20:42 . 2008-01-18 10:56 932 ——— c:\windows\hpomdl27.dat
2008-12-10 21:14 . 2008-12-10 21:14 d——– c:\windows\system32\ernet explorer
2008-12-09 16:22 . 2008-10-03 05:02 247,326 —–c— c:\windows\system32\dllcache\strmdll.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-05 00:28 ——— d—–w c:\program files\PestPatrol
2009-01-04 22:51 7,304 —-a-w c:\windows\TMP0001.TMP
2008-12-30 18:58 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-30 18:17 ——— d—–w c:\program files\Common Files\InstallShield
2008-12-20 01:48 ——— d—–w c:\program files\HP
2008-12-09 00:07 ——— d—–w c:\program files\Common Files\Adobe
2008-12-07 05:02 ——— d—–w c:\program files\Java
2008-12-01 22:08 ——— d—–w c:\program files\TrojanHunter 5.0
2008-12-01 22:02 ——— d—–w c:\program files\Spybot - Search & Destroy
2008-12-01 22:02 ——— d—–w c:\program files\Panda Security
2008-12-01 22:02 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-01 22:00 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2008-12-01 21:58 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2008-12-01 21:58 ——— d—–w c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-27 05:39 ——— d—–w c:\program files\iTunes
2008-11-27 05:34 ——— d—–w c:\program files\Common Files\LightScribe
2008-11-27 05:33 ——— d—–w c:\program files\Bonjour
2008-11-27 04:08 ——— d—–w c:\documents and settings\Charlie\Application Data\TrojanHunter
2008-11-26 05:31 ——— d—–w c:\documents and settings\All Users\Application Data\PrevxCSI
2008-11-25 22:40 ——— d—–w c:\program files\QuickTime
2008-11-25 22:25 2,001 —-a-w c:\program files\uninstal.log
2008-11-21 18:41 ——— d—–w c:\program files\Common Files\Symantec Shared
2008-11-21 18:20 805 —-a-w c:\windows\system32\drivers\SYMEVENT.INF
2008-11-21 18:20 10,671 —-a-w c:\windows\system32\drivers\SYMEVENT.CAT
2008-11-21 17:02 ——— d—–w c:\documents and settings\Charlie\Application Data\Symantec
2008-11-21 05:08 ——— d—–w c:\program files\AVG
2008-11-21 04:02 ——— d—–w c:\program files\F-Group
2008-11-20 21:44 ——— d—–w c:\program files\Trend Micro
2008-11-20 20:24 164 —-a-w C:\install.dat
2008-11-20 20:14 ——— d—–w c:\program files\Rhapsody
2008-11-19 03:02 ——— d—–w c:\program files\Exterminate It!
2008-11-13 22:11 1,553,272 —-a-w c:\windows\WRSetup.dll
2008-11-12 21:02 29,808 —-a-w c:\windows\system32\drivers\ssfs0bbc.sys
2008-11-12 21:02 23,152 —-a-w c:\windows\system32\drivers\sshrmd.sys
2008-11-12 21:02 170,608 —-a-w c:\windows\system32\drivers\ssidrv.sys
2008-11-10 10:43 410,984 —-a-w c:\windows\system32\deploytk.dll
2008-10-23 22:27 183,120 —-a-w c:\windows\system32\PnkBstrB.exe
2008-10-23 12:36 286,720 —-a-w c:\windows\system32\gdi32.dll
2008-10-16 20:38 826,368 —-a-w c:\windows\system32\wininet.dll
2008-10-16 19:13 202,776 —-a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:12 561,688 —-a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 323,608 —-a-w c:\windows\system32\wucltui.dll
2008-10-16 19:09 92,696 —-a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 —-a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 43,544 —-a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 —-a-w c:\windows\system32\wups.dll
2008-10-16 19:06 268,648 —-a-w c:\windows\system32\mucltui.dll
2008-10-16 19:06 208,744 —-a-w c:\windows\system32\muweb.dll
2008-08-03 01:11 22,328 —-a-w c:\documents and settings\Charlie\Application Data\PnkBstrK.sys
2002-05-21 15:00 1,362 —-a-r c:\program files\ReadMe.txt
.
((((((((((((((((((((((((((((( snapshot_2009-01-01_17.10.52.54 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-08-15 02:17:55 102,400 —-a-r c:\windows\Installer\{3DE0053C-FD9A-483E-B7C9-B06E4392206E}\iTunesIco.exe
+ 2009-01-04 23:13:34 102,400 —-a-r c:\windows\Installer\{3DE0053C-FD9A-483E-B7C9-B06E4392206E}\iTunesIco.exe
- 2009-01-01 21:44:09 32,768 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-01-03 04:27:48 32,768 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-01-01 21:44:09 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-01-03 04:27:48 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-01-01 21:44:09 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-01-03 04:27:48 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-12-30 16:21:37 59,984 —-a-w c:\windows\system32\perfc009.dat
+ 2009-01-02 02:54:58 59,780 —-a-w c:\windows\system32\perfc009.dat
- 2008-12-30 16:21:37 397,890 —-a-w c:\windows\system32\perfh009.dat
+ 2009-01-02 02:54:58 397,560 —-a-w c:\windows\system32\perfh009.dat
+ 2009-01-04 22:53:05 16,384 —-atw c:\windows\temp\Perflib_Perfdata_608.dat
+ 2009-01-05 01:09:02 3,472 —-a-w c:\windows\temp\wrstemp\S-1-5-18.dat
+ 2009-01-05 01:09:02 4,182 —-a-w c:\windows\temp\wrstemp\S-1-5-19.dat
+ 2009-01-05 01:09:02 4,250 —-a-w c:\windows\temp\wrstemp\S-1-5-20.dat
+ 2009-01-05 01:09:02 5,060 —-a-w c:\windows\temp\wrstemp\S-1-5-21-2052111302-1123561945-839522115-1004.dat
+ 2009-01-05 01:09:02 4,930 —-a-w c:\windows\temp\wrstemp\S-1-5-21-2052111302-1123561945-839522115-1005.dat
+ 2009-01-05 01:09:02 4,460 —-a-w c:\windows\temp\wrstemp\S-1-5-21-2052111302-1123561945-839522115-500.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\BackupIconOverlayId]
@="{2EE61E5C-8F94-4AAB-8A80-D2A8CD1FEDAD}"
[HKEY_CLASSES_ROOT\CLSID\{2EE61E5C-8F94-4AAB-8A80-D2A8CD1FEDAD}]
2008-11-13 17:04 238968 –a—— c:\program files\Webroot\WebrootSecurity\Backup\CtxMenu_1_0_0_10.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-10-11 1961984]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 81920]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"kmw_run.exe"="c:\windows\system32\kmw_run.exe" [2006-08-03 106496]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"ADUserMon"="c:\program files\Iomega\AutoDisk\ADUserMon.exe" [2002-09-24 147456]
"Iomega Drive Icons"="c:\program files\Iomega\DriveIcons\ImgIcon.exe" [2002-08-13 86016]
"Deskup"="c:\program files\Iomega\DriveIcons\deskup.exe" [2002-07-16 32768]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"NVMixerTray"="c:\program files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [2004-12-20 131072]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"nwiz"="c:\windows\system32\nwiz.exe" [2008-10-07 1630208]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"PestPatrol Control Center"="c:\progra~1\PESTPA~1\PPControl.exe" [2004-11-15 98304]
"PPMemCheck"="c:\progra~1\PESTPA~1\PPMemCheck.exe" [2004-04-02 148480]
"CookiePatrol"="c:\progra~1\PESTPA~1\CookiePatrol.exe" [2005-01-10 73728]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"hpqSRMon"="c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"SpySweeper"="c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe" [2008-11-13 6273400]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2007-03-28 724992]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoViewOnDrive"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= ctwdm32.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@="Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\WINDOWS\\system32\\ftp.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Activision\\Call of Duty 2\\CoD2MP_s.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\EA GAMES\\Command & Conquer Generals Zero Hour\\game.dat"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqkygrp.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2624:UDP"= 2624:UDP:Windows Media Format SDK (iexplore.exe)
"2630:UDP"= 2630:UDP:Windows Media Format SDK (iexplore.exe)
"2638:UDP"= 2638:UDP:Windows Media Format SDK (iexplore.exe)
"2648:UDP"= 2648:UDP:Windows Media Format SDK (iexplore.exe)
"2650:UDP"= 2650:UDP:Windows Media Format SDK (iexplore.exe)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2009-01-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2008-12-29 c:\windows\Tasks\wrSpySweeper_L1BEF856852D441F892D396D617FD6860.job
- c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe [2008-11-13 17:11]
2008-12-29 c:\windows\Tasks\wrSpySweeper_L1BEF856852D441F892D396D617FD6860.job
- c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe [2008-11-13 17:11]
2008-12-29 c:\windows\Tasks\wrSpySweeper_L1BEF856852D441F892D396D617FD6860.job
- a:\,d:\,e:\,f:\,g:\,h:\ []
2008-12-29 c:\windows\Tasks\wrSpySweeper_L1BEF856852D441F892D396D617FD6860.job
- a:\","c:\","d:\","e:\","f:\","g:\","H:\" []
2009-01-02 c:\windows\Tasks\wrSpySweeper_L72DB844171114AD6A727718740278D5F.job
- c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe [2008-11-13 17:11]
2009-01-02 c:\windows\Tasks\wrSpySweeper_L72DB844171114AD6A727718740278D5F.job
- c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe [2008-11-13 17:11]
2009-01-02 c:\windows\Tasks\wrSpySweeper_L72DB844171114AD6A727718740278D5F.job
- a:\","c:\","d:\","e:\","f:\","g:\","H:\" []
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.wlns.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O16 -: DirectAnimation Java Classes - c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd
O16 -: Microsoft XML Parser for Java - c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
c:\windows\Downloaded Program Files\WSSystemInformation.dll - O16 -: {03DF0933-6E10-4D32-9835-B9A815622831}
hxxps://gopublic.wspan.com/secure/DLLs/WSSystemInformation.cab
c:\windows\Downloaded Program Files\WSSystemInformation.inf
c:\windows\Downloaded Program Files\sysreqlab3.dll - O16 -: {1E54D648-B804-468d-BC78-4AFFED8E262E}
hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
c:\windows\Downloaded Program Files\SysReqLab3.osd
c:\windows\Downloaded Program Files\CONFLICT.1\Manager.exe - c:\windows\Downloaded Program Files\CONFLICT.1\DownloadManagerV2.ocx
O16 -: {4871A87A-BFDD-4106-8153-FFDE2BAC2967}
hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab
c:\windows\Downloaded Program Files\DownloadManagerV2.inf
c:\windows\Downloaded Program Files\ScmDirCtl.dll - O16 -: {52454909-B15F-11D3-83A3-000083613743}
hxxps://go4f.wspan.com/secure/DLLs/SCMDirCtl.CAB
c:\windows\Downloaded Program Files\ScmDirCtl.inf
c:\windows\Downloaded Program Files\WSEmul3.ocx - O16 -: {6FC2871E-004B-4141-B9C0-59708BD96CCE}
hxxps://go4f.wspan.com/Secure/DLLs/WSEMUL3.CAB
c:\windows\Downloaded Program Files\wsemul3.inf
c:\windows\Downloaded Program Files\CONFLICT.1\WSMap.vbs - c:\windows\Downloaded Program Files\CONFLICT.1\WSFileIO3.dll
O16 -: {7B72C3FC-34B5-4504-B4BE-EB38971A0888}
hxxps://gopublic.wspan.com/Secure/Dlls/WSFileIO3.cab
c:\windows\Downloaded Program Files\CONFLICT.1\wsfileio3.inf
c:\windows\Downloaded Program Files\WSPrint3.ocx - O16 -: {7DB7E238-1425-4434-8B05-6453AD6A49C6}
hxxps://go4f.wspan.com/secure/DLLs/WSPrint3.CAB
c:\windows\Downloaded Program Files\wsprint3.inf
c:\windows\Downloaded Program Files\WSKeyBoardTranslator.dll - O16 -: {85788258-6ACF-4FC1-A2CD-3BD248065AB9}
hxxps://go4f.wspan.com/Secure/DLLs/WSKeyboardTranslator.cab
c:\windows\Downloaded Program Files\WSKeyBoardTranslator.inf
c:\windows\Downloaded Program Files\WSMap.vbs - c:\windows\Downloaded Program Files\WSFileIO2.dll
O16 -: {8D33B6F0-1E74-419C-BBEF-D00E976A3A5D}
hxxps://go4f.wspan.com//Secure/DLLs/WSFileIO2.cab
c:\windows\Downloaded Program Files\wsfileio2.inf
c:\windows\Downloaded Program Files\WSBrowserConfig.dll - O16 -: {9145A52A-9B22-4858-AEE7-74D6C7D3F366}
hxxps://go4f.wspan.com/secure/DLLs/WSBrowserConfig.cab
c:\windows\Downloaded Program Files\wsbrowserconfig.inf
c:\windows\Downloaded Program Files\WSCustInstSrv.dll - O16 -: {A4D41E3A-613D-11D3-85B2-400011500081}
hxxps://go1f.wspan.com/secure/DLLs/WSCustInst.CAB
c:\windows\Downloaded Program Files\WSCustInst.inf
c:\windows\Downloaded Program Files\wspancal.dll - O16 -: {D4233B6D-88A0-11D3-BC29-400011500032}
hxxps://go4f.wspan.com/scripts/us/bin/WSCAL.CAB
c:\windows\Downloaded Program Files\wspancal.inf
c:\windows\WSODBC32.dll - c:\windows\Downloaded Program Files\SCMCtl1.dll
O16 -: {EFFFC7A6-4D95-4A18-8A14-FEB082D9C67D}
hxxps://go1f.wspan.com/secure/DLLs/WSSCM1.CAB
c:\windows\Downloaded Program Files\WSSCM1.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-04 20:08:35
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Iomega Activity Disk2]
"ImagePath"="\"\""
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'explorer.exe'(3520)
c:\windows\system32\kmw_dll.dll
c:\windows\system32\WOW32.dll
c:\program files\Webroot\WebrootSecurity\Backup\CtxMenu_1_0_0_10.dll
c:\program files\Iomega\DriveIcons\IMGHOOK.DLL
- - - - - - - > 'explorer.exe'(1024)
c:\windows\system32\kmw_dll.dll
c:\windows\system32\WOW32.dll
c:\program files\Webroot\WebrootSecurity\Backup\CtxMenu_1_0_0_10.dll
.
Completion time: 2009-01-04 20:09:51
ComboFix-quarantined-files.txt 2009-01-05 01:09:45
ComboFix2.txt 2009-01-03 04:23:22
ComboFix3.txt 2009-01-03 02:31:53
ComboFix4.txt 2009-01-01 22:41:42
ComboFix5.txt 2009-01-05 01:03:45
Pre-Run: 52,995,940,352 bytes free
Post-Run: 53,046,767,616 bytes free
315 — E O F — 2008-12-18 01:19:28
HiJackThis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:10:47 PM, on 1/4/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
C:\Program Files\Webroot\WebrootSecurity\SSU.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\kmw_run.exe
C:\WINDOWS\system32\KMW_SHOW.EXE
C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.wlns.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - (no file)
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [kmw_run.exe] "C:\WINDOWS\system32\kmw_run.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] "C:\WINDOWS\system32\NeroCheck.exe"
O4 - HKLM\..\Run: [ADUserMon] "C:\Program Files\Iomega\AutoDisk\ADUserMon.exe"
O4 - HKLM\..\Run: [Iomega Drive Icons] "C:\Program Files\Iomega\DriveIcons\ImgIcon.exe"
O4 - HKLM\..\Run: [Deskup] "C:\Program Files\Iomega\DriveIcons\deskup.exe" /IMGSTART
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [NvCplDaemon] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "C:\WINDOWS\system32\nwiz.exe" /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NvMediaCenter] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [PestPatrol Control Center] "c:\PROGRA~1\PESTPA~1\PPControl.exe"
O4 - HKLM\..\Run: [PPMemCheck] "c:\PROGRA~1\PESTPA~1\PPMemCheck.exe"
O4 - HKLM\..\Run: [CookiePatrol] "c:\PROGRA~1\PESTPA~1\CookiePatrol.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [hpqSRMon] "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSRMon.exe"
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmon.exe"
O4 - HKUS\S-1-5-21-2052111302-1123561945-839522115-1004\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" (User '?')
O4 - HKUS\S-1-5-21-2052111302-1123561945-839522115-1004\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (User '?')
O4 - HKUS\S-1-5-21-2052111302-1123561945-839522115-1004\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear (User '?')
O4 - HKUS\S-1-5-21-2052111302-1123561945-839522115-1004\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmon.exe" (User '?')
O4 - HKUS\S-1-5-21-2052111302-1123561945-839522115-1005\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmon.exe" (User '?')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O16 - DPF: {03DF0933-6E10-4D32-9835-B9A815622831} (WSSystemInfo Class) -
https://gopublic.wspan.com/secure/DLLs/WSSy…Information.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) -
http://www.nvidia.com/content/DriverDownlo…/sysreqlab3.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/as…abs/tgctlsr.cab
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.1.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-3-48.cab
O16 - DPF: {52454909-B15F-11D3-83A3-000083613743} (SCMDir Class) -
https://go4f.wspan.com/secure/DLLs/SCMDirCtl.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/…b?1173070605140
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdat…b?1173112912250
O16 - DPF: {6FC2871E-004B-4141-B9C0-59708BD96CCE} (WSEmul Control 3) -
https://go4f.wspan.com/Secure/DLLs/WSEMUL3.CAB
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownlo…iaSmartScan.cab
O16 - DPF: {7B72C3FC-34B5-4504-B4BE-EB38971A0888} (WSFileIO Class 3) -
https://gopublic.wspan.com/Secure/Dlls/WSFileIO3.cab
O16 - DPF: {7DB7E238-1425-4434-8B05-6453AD6A49C6} (WSPrint3 Control) -
https://go4f.wspan.com/secure/DLLs/WSPrint3.CAB
O16 - DPF: {85788258-6ACF-4FC1-A2CD-3BD248065AB9} (WSKeyboardMap Class) -
https://go4f.wspan.com/Secure/DLLs/WSKeyboardTranslator.cab
O16 - DPF: {8D33B6F0-1E74-419C-BBEF-D00E976A3A5D} (WSFileIO Class 2) -
https://go4f.wspan.com//Secure/DLLs/WSFileIO2.cab
O16 - DPF: {9145A52A-9B22-4858-AEE7-74D6C7D3F366} (BrowserConfig Class) -
https://go4f.wspan.com/secure/DLLs/WSBrowserConfig.cab
O16 - DPF: {A4D41E3A-613D-11D3-85B2-400011500081} (WSCustInst Class) -
https://go1f.wspan.com/secure/DLLs/WSCustInst.CAB
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {D4233B6D-88A0-11D3-BC29-400011500032} (WspGoCal Class) -
https://go4f.wspan.com/scripts/us/bin/WSCAL.CAB
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O16 - DPF: {EFFFC7A6-4D95-4A18-8A14-FEB082D9C67D} (SCM Class1) -
https://go1f.wspan.com/secure/DLLs/WSSCM1.CAB
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) -
http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.1.6.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
–
End of file - 11783 bytes
Before restart, the fix deleted the "SOS" registry key, however the key did come back after restart.
One other note, over the past couple weeks I get a message now and then telling me Windows had to restore a registry key, doesn't say which one, but just says one had to be restored.