ComboFix Log
Dear Blade81, dear goodness, i so hope i'm doing all of this right. have been working on the instructions since 4pm mst & must admit am feeling like a dumb blonde (but i'm not even blonde!) wanted to contact you to a couple times for clarification but not wanting to bother you. i'll keep on going at it & praying alot! :banghead:
ComboFix 07-10-09.3 - Owner 2007-10-09 23:54:50.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.585 [GMT -7:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
Command switches used :: C:\Program Files\Trend Micro\HijackThis\CFScript.txt
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\System Doctor Free
C:\Documents and Settings\All Users\Application Data\System Doctor Free\Data\hours
C:\Documents and Settings\All Users\Application Data\System Doctor Free\Data\ProductCode
C:\Documents and Settings\All Users\Application Data\System Doctor
C:\Documents and Settings\All Users\Application Data\System Doctor\Data\Abbr
C:\Documents and Settings\All Users\Application Data\System Doctor\Data\ActivationCode
C:\Documents and Settings\All Users\Application Data\System Doctor\Data\cid
C:\Documents and Settings\All Users\Application Data\System Doctor\Data\CustomerEmail
C:\Documents and Settings\All Users\Application Data\System Doctor\Data\CustomerName
C:\Documents and Settings\All Users\Application Data\System Doctor\Data\OID
C:\Documents and Settings\All Users\Application Data\System Doctor\Data\PCID
C:\Documents and Settings\All Users\Application Data\System Doctor\Data\ProductCode
C:\Documents and Settings\All Users\Application Data\System Doctor\Data\Suspicious
C:\Documents and Settings\Owner\Application Data\System Doctor
C:\Documents and Settings\Owner\Application Data\System Doctor\Logs\update.log
C:\Program Files\DriveCleaner Freeware
C:\Program Files\DriveCleaner Freeware\Activate.dat
C:\Program Files\DriveCleaner Freeware\Appbase\AE_CD_Cr.dat
C:\Program Files\DriveCleaner Freeware\Appbase\AReadr4.dat
C:\Program Files\DriveCleaner Freeware\Appbase\AReadr5.dat
C:\Program Files\DriveCleaner Freeware\Appbase\ASDSEEpv.dat
C:\Program Files\DriveCleaner Freeware\Appbase\ASPack.dat
C:\Program Files\DriveCleaner Freeware\Appbase\Babylon.dat
C:\Program Files\DriveCleaner Freeware\Appbase\BDelphi5.dat
C:\Program Files\DriveCleaner Freeware\Appbase\CatchUp.dat
C:\Program Files\DriveCleaner Freeware\Appbase\CBuildr5.dat
C:\Program Files\DriveCleaner Freeware\Appbase\CCGA.dat
C:\Program Files\DriveCleaner Freeware\Appbase\CManager.dat
C:\Program Files\DriveCleaner Freeware\Appbase\CuteFTP4.dat
C:\Program Files\DriveCleaner Freeware\Appbase\CuteHTML.dat
C:\Program Files\DriveCleaner Freeware\Appbase\DAcceler.dat
C:\Program Files\DriveCleaner Freeware\Appbase\DiscJug.dat
C:\Program Files\DriveCleaner Freeware\Appbase\ECDCreat4.dat
C:\Program Files\DriveCleaner Freeware\Appbase\Far.dat
C:\Program Files\DriveCleaner Freeware\Appbase\FFTsks.dat
C:\Program Files\DriveCleaner Freeware\Appbase\FlashFXP.dat
C:\Program Files\DriveCleaner Freeware\Appbase\FrntPage.dat
C:\Program Files\DriveCleaner Freeware\Appbase\FrontPEx.dat
C:\Program Files\DriveCleaner Freeware\Appbase\FtpEXP.dat
C:\Program Files\DriveCleaner Freeware\Appbase\FtpVoya.dat
C:\Program Files\DriveCleaner Freeware\Appbase\GetRight.dat
C:\Program Files\DriveCleaner Freeware\Appbase\GoZilla.dat
C:\Program Files\DriveCleaner Freeware\Appbase\GravMRU.dat
C:\Program Files\DriveCleaner Freeware\Appbase\H_TxtPad.dat
C:\Program Files\DriveCleaner Freeware\Appbase\HomeSite.dat
C:\Program Files\DriveCleaner Freeware\Appbase\HotDogPr.dat
C:\Program Files\DriveCleaner Freeware\Appbase\IconExtr.dat
C:\Program Files\DriveCleaner Freeware\Appbase\iMesh.dat
C:\Program Files\DriveCleaner Freeware\Appbase\ImgReady3.dat
C:\Program Files\DriveCleaner Freeware\Appbase\InsShExp.dat
C:\Program Files\DriveCleaner Freeware\Appbase\JASC_P_P.dat
C:\Program Files\DriveCleaner Freeware\Appbase\KaZaA.dat
C:\Program Files\DriveCleaner Freeware\Appbase\LView.dat
C:\Program Files\DriveCleaner Freeware\Appbase\MacDir.dat
C:\Program Files\DriveCleaner Freeware\Appbase\MacDrWea.dat
C:\Program Files\DriveCleaner Freeware\Appbase\MicAng.dat
C:\Program Files\DriveCleaner Freeware\Appbase\MicDes.dat
C:\Program Files\DriveCleaner Freeware\Appbase\MM_CON.dat
C:\Program Files\DriveCleaner Freeware\Appbase\MMUnDisk.dat
C:\Program Files\DriveCleaner Freeware\Appbase\Morpheus.dat
C:\Program Files\DriveCleaner Freeware\Appbase\MPaint.dat
C:\Program Files\DriveCleaner Freeware\Appbase\MPicPub.dat
C:\Program Files\DriveCleaner Freeware\Appbase\MPImaGal.dat
C:\Program Files\DriveCleaner Freeware\Appbase\MSExplorer.dat
C:\Program Files\DriveCleaner Freeware\Appbase\MSoffice.dat
C:\Program Files\DriveCleaner Freeware\Appbase\MSRegEdit.dat
C:\Program Files\DriveCleaner Freeware\Appbase\MSWMP.dat
C:\Program Files\DriveCleaner Freeware\Appbase\MSWordPad.dat
C:\Program Files\DriveCleaner Freeware\Appbase\Nero.dat
C:\Program Files\DriveCleaner Freeware\Appbase\NetShow.dat
C:\Program Files\DriveCleaner Freeware\Appbase\NTBackup.dat
C:\Program Files\DriveCleaner Freeware\Appbase\pfilelst.xda
C:\Program Files\DriveCleaner Freeware\Appbase\PhotShel.dat
C:\Program Files\DriveCleaner Freeware\Appbase\PHPCoder.dat
C:\Program Files\DriveCleaner Freeware\Appbase\PowerZIP.dat
C:\Program Files\DriveCleaner Freeware\Appbase\RapidBr.dat
C:\Program Files\DriveCleaner Freeware\Appbase\RealAuPl.dat
C:\Program Files\DriveCleaner Freeware\Appbase\RealDown.dat
C:\Program Files\DriveCleaner Freeware\Appbase\SecurCRT.dat
C:\Program Files\DriveCleaner Freeware\Appbase\SL_BlWin.dat
C:\Program Files\DriveCleaner Freeware\Appbase\SmartClr.dat
C:\Program Files\DriveCleaner Freeware\Appbase\Sonique.dat
C:\Program Files\DriveCleaner Freeware\Appbase\StuffIt.dat
C:\Program Files\DriveCleaner Freeware\Appbase\TelepPro.dat
C:\Program Files\DriveCleaner Freeware\Appbase\UGifAnim.dat
C:\Program Files\DriveCleaner Freeware\Appbase\UltraEd.dat
C:\Program Files\DriveCleaner Freeware\Appbase\UMedStud.dat
C:\Program Files\DriveCleaner Freeware\Appbase\UPhImpV.dat
C:\Program Files\DriveCleaner Freeware\Appbase\UPhotoEx.dat
C:\Program Files\DriveCleaner Freeware\Appbase\UVidStud.dat
C:\Program Files\DriveCleaner Freeware\Appbase\VNC.dat
C:\Program Files\DriveCleaner Freeware\Appbase\WebFeret.dat
C:\Program Files\DriveCleaner Freeware\Appbase\WebReap.dat
C:\Program Files\DriveCleaner Freeware\Appbase\WinACE.dat
C:\Program Files\DriveCleaner Freeware\Appbase\WinGate.dat
C:\Program Files\DriveCleaner Freeware\Appbase\WinRAR.dat
C:\Program Files\DriveCleaner Freeware\Appbase\WinZIP.dat
C:\Program Files\DriveCleaner Freeware\Appbase\WiseInst.dat
C:\Program Files\DriveCleaner Freeware\Appbase\wordslst.xda
C:\Program Files\DriveCleaner Freeware\Appbase\YahooPl.dat
C:\Program Files\DriveCleaner Freeware\Appbase\ZipMagic.dat
C:\Program Files\DriveCleaner Freeware\AV.dat
C:\Program Files\DriveCleaner Freeware\bnlink.dat
C:\Program Files\DriveCleaner Freeware\err.log
C:\Program Files\DriveCleaner Freeware\img\button.gif
C:\Program Files\DriveCleaner Freeware\img\button2.gif
C:\Program Files\DriveCleaner Freeware\img\header.gif
C:\Program Files\DriveCleaner Freeware\img\logo.gif
C:\Program Files\DriveCleaner Freeware\img\spacer.gif
C:\Program Files\DriveCleaner Freeware\img\top_line.gif
C:\Program Files\DriveCleaner Freeware\img\top1.jpg
C:\Program Files\DriveCleaner Freeware\img\top2.jpg
C:\Program Files\DriveCleaner Freeware\lapv.dat
C:\Program Files\DriveCleaner Freeware\license.rtf
C:\Program Files\DriveCleaner Freeware\manual.url
C:\Program Files\DriveCleaner Freeware\pv.dat
C:\Program Files\DriveCleaner Freeware\readme.rtf
C:\Program Files\DriveCleaner Freeware\remnag.dat
C:\Program Files\DriveCleaner Freeware\ScanReport.dat
C:\Program Files\DriveCleaner Freeware\Schedule.dat
C:\Program Files\DriveCleaner Freeware\sr.log
C:\Program Files\DriveCleaner Freeware\support.url
C:\Program Files\DriveCleaner Freeware\UDC.xml
C:\Program Files\DriveCleaner Freeware\UDC6.url
C:\Program Files\DriveCleaner Freeware\unins000.dat
C:\Program Files\DriveCleaner Freeware\UninstallPage.html
C:\Program Files\DriveCleaner Freeware\up.dat
C:\Program Files\DriveCleaner Freeware\updater.dat
C:\Program Files\DriveCleaner Freeware\vbpv.dat
.
((((((((((((((((((((((((( Files Created from 2007-09-10 to 2007-10-10 )))))))))))))))))))))))))))))))
.
2007-10-09 22:30 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-10-09 02:50 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-04 03:55 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-10-04 03:54 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-10-04 00:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-10-03 07:29 <DIR> d-------- C:\Program Files\Trend Micro
2007-09-28 04:50 <DIR> d-------- C:\Program Files\AOL 9.0a
2007-09-28 04:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AOL Downloads
2007-09-28 04:46 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AOL
2007-09-23 01:42 10,920 --a------ C:\aolconnfix.exe
2007-09-22 05:57 <DIR> d-------- C:\Program Files\Common Files\aolback
2007-09-22 05:55 <DIR> d-------- C:\Program Files\AOL 9.0
2007-09-22 04:43 <DIR> d-------- C:\Program Files\Common Files\aolshare
2007-09-22 04:40 <DIR> d--h----- C:\TEMP
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-01 19:39 --------- d-----w C:\Documents and Settings\Owner\Application Data\AOL
2007-09-28 11:58 --------- d-----w C:\Program Files\Common Files\AOL
2007-09-28 11:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL
2007-09-22 08:23 --------- d-----w C:\Program Files\System Doctor
2007-09-22 08:09 --------- d-----w C:\Program Files\RegistrySmart
2007-09-22 07:56 --------- d-----w C:\Program Files\Pure Networks
2007-09-11 08:51 --------- d-----w C:\Program Files\Paint Shop Pro 5
2007-09-04 06:55 --------- d-----w C:\Documents and Settings\Owner\Application Data\RegistrySmart
2007-08-22 10:42 --------- d-----w C:\Program Files\HSN
2007-08-22 06:09 --------- d-----w C:\Documents and Settings\Owner\Application Data\Sammsoft
2007-08-11 01:11 --------- d-----w C:\Program Files\Uniblue
2007-04-08 06:56 472 -c--a-w C:\Documents and Settings\Owner\Application Data\wklnhst.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Recguard"="%WINDIR%\SMINST\RECGUARD.EXE" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-12-14 04:42]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-09-13 21:29]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [2006-11-07 14:49]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-01-31 19:52]
"HostManager"="C:\Program Files\Common Files\AOL\1190465712\ee\AOLSoftware.exe" [2006-09-25 17:52]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PhotoShow Deluxe Media Manager"="C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\xtras\mssysmgr.exe" [2005-08-16 08:43]
"HSN Skin Tools Alerts"="C:\Program Files\HSN\bar\1.bin\hsnSkPly.exe" []
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 16:24]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45]
"AOL Fast Start"="C:\Program Files\AOL 9.0a\AOL.exe" [2007-04-17 23:48]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"=Narrator.exe
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Power2GoExpress"=NA
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BigFix.lnk
backup=C:\WINDOWS\pss\BigFix.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Creating Keepsakes Scrapbook Designer Event Reminder.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Creating Keepsakes Scrapbook Designer Event Reminder.lnk
backup=C:\WINDOWS\pss\Creating Keepsakes Scrapbook Designer Event Reminder.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Event Reminder.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Event Reminder.lnk
backup=C:\WINDOWS\pss\Event Reminder.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Fast Start]
"C:\Program Files\America Online 9.0\AOL.EXE" -b
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Spyware Protection]
"C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ClientGW]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
C:\WINDOWS\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eSnips]
"C:\Program Files\eSnips\ClientGW.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
C:\Program Files\Common Files\AOL\1145965187\EE\AOLHostManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PhotoShow Deluxe Media Manager]
C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder]
%WINDIR%\Creator\Remind_XP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
*Newly Created Service* - AVGASCLN
.
Contents of the 'Scheduled Tasks' folder
"2007-10-09 10:30:00 C:\WINDOWS\Tasks\RegistrySmart Scheduled Scan.job"
- C:\Program Files\RegistrySmart\RegistrySmart.exe
"2007-10-10 01:11:00 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2007-08-11 01:11:41 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
.
**************************************************************************
catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-10-09 23:55:59
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-09 23:56:36
C:\ComboFix-quarantined-files.txt ... 2007-10-09 23:56
C:\ComboFix2.txt ... 2007-10-09 23:35
C:\ComboFix3.txt ... 2007-10-09 03:08
.
--- E O F ---