ComboFix 08-06-10.5 - Owner 2008-06-12 13:59:30.2 - NTFSx86
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\smp.bat
C:\temp\
0b9
C:\temp\
0b9\tmpTF.log
C:\temp\tn3
C:\WINDOWS\icroso~1
C:\WINDOWS\icroso~1.net
C:\WINDOWS\msettings.ini
C:\WINDOWS\system32\180ax.exe
C:\WINDOWS\system32\biprep.exe
C:\WINDOWS\system32\drivers\remove_spyware_button.gif
C:\WINDOWS\system32\fnts~1
C:\WINDOWS\system32\lclcfg32.ini
C:\WINDOWS\system32\lfd32.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\salm.exe
C:\WINDOWS\system32\satmat.exe
C:\WINDOWS\system32\sl.bin
C:\WINDOWS\system32\smante~1
C:\WINDOWS\system32\sstem3~1
C:\WINDOWS\system32\stera.log
C:\WINDOWS\system32\susp.exe
C:\WINDOWS\system32\tsks~1
C:\WINDOWS\system32\updatetc.exe
C:\WINDOWS\system32\wmvds32.dll
C:\WINDOWS\xhelper.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_FOPN
((((((((((((((((((((((((( Files Created from 2008-05-12 to 2008-06-12 )))))))))))))))))))))))))))))))
.
2008-06-12 12:23 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-06-12 12:18 . 2008-06-12 12:21 <DIR> d-------- C:\Documents and Settings\Owner\.SunDownloadManager
2008-06-12 00:46 . 2008-06-12 00:46 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Talkback
2008-06-12 00:13 . 2008-06-12 00:13 118 --a------ C:\WINDOWS\system32\MRT.INI
2008-06-11 23:49 . 2008-06-11 23:49 <DIR> d-------- C:\Program Files\DSS
2008-06-11 23:09 . 2008-06-11 23:09 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-11 23:09 . 2008-06-11 23:09 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Malwarebytes
2008-06-11 23:09 . 2008-06-11 23:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-11 23:09 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-11 23:09 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-11 20:48 . 2008-06-11 20:48 <DIR> d-------- C:\Deckard
2008-06-11 12:29 . 2008-06-11 19:14 793 --a------ C:\WINDOWS\wininit.ini
2008-06-11 03:00 . 2008-06-11 03:00 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-06-07 01:57 . 2008-06-07 01:58 <DIR> d-------- C:\Program Files\GNU Solfege
2008-06-07 01:55 . 2008-06-07 01:59 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\gtk-2.0
2008-06-07 01:55 . 2008-06-07 01:55 <DIR> d-------- C:\Documents and Settings\Owner\.thumbnails
2008-06-07 01:53 . 2008-06-07 01:59 <DIR> d-------- C:\Documents and Settings\Owner\.gimp-2.4
2008-06-07 01:51 . 2008-06-07 01:51 <DIR> d-------- C:\Program Files\GIMP-2.0
2008-06-04 23:51 . 2008-06-04 23:57 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Winamp
2008-05-31 20:30 . 2008-05-31 20:30 0 --a------ C:\WINDOWS\iPlayer.INI
2008-05-31 20:26 . 2008-05-31 20:29 <DIR> d-------- C:\Program Files\InterActual
2008-05-22 23:38 . 2008-05-22 23:38 <DIR> d-------- C:\WINDOWS\Favorites
2008-05-21 16:37 . 2007-03-07 19:51 129,784 --a------ C:\WINDOWS\system32\pxafs.dll
2008-05-21 15:49 . 2003-02-28 18:26 49,424 --a------ C:\WINDOWS\system32\clspack.exe
2008-05-21 00:30 . 2008-05-21 00:30 33,760 --a------ C:\e2z8nb.exe
2008-05-21 00:24 . 2008-05-21 00:24 <DIR> d-------- C:\d849c1e3033d766ce7
2008-05-20 19:41 . 2005-10-20 18:33 991,232 --a------ C:\WINDOWS\system32\esent.dll
2008-05-20 19:27 . 2008-05-20 19:27 <DIR> d-------- C:\Program Files\Lavasoft
2008-05-20 19:27 . 2008-05-20 19:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-20 19:24 . 2008-05-20 19:24 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-20 19:22 . 2008-05-20 19:22 21,031,280 --a------ C:\aaw2007.exe
2008-05-20 19:13 . 2008-05-20 19:13 <DIR> d-------- C:\Program Files\CCleaner
2008-05-20 19:13 . 2008-05-20 19:13 2,897,456 --a------ C:\ccsetup207.exe
2008-05-20 19:00 . 2007-07-30 19:18 34,136 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2008-05-20 19:00 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-05-20 19:00 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-05-20 19:00 . 2007-07-30 19:18 20,312 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-12 17:36 --------- d-----w C:\Program Files\Java
2008-06-12 04:13 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-06-12 04:13 --------- d-----w C:\Program Files\AIM
2008-06-11 15:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-11 01:07 --------- d-----w C:\Documents and Settings\Owner\Application Data\Skype
2008-06-05 03:57 --------- d-----w C:\Program Files\Winamp
2008-05-31 02:25 --------- d-----w C:\Program Files\Common Files\zkmi
2008-05-26 01:19 --------- d-----w C:\Documents and Settings\Owner\Application Data\AdobeUM
2008-05-23 04:47 --------- d-----w C:\Program Files\Common Files\Adobe
2008-05-22 18:04 --------- d-----w C:\Program Files\LimeWire
2008-05-21 16:37 --------- d-----w C:\Documents and Settings\Owner\Application Data\MSN6
2008-05-21 00:50 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-05-21 00:47 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-21 00:45 --------- d-----w C:\Program Files\Whale Communications
2008-05-21 00:39 --------- d-----w C:\Program Files\Gateway
2008-05-21 00:37 --------- d-----w C:\Program Files\AOL Deskbar
2007-07-10 17:57 382 ----a-w C:\Documents and Settings\Owner\Application Data\internaldb6334.dat
2007-07-10 16:20 194 ----a-w C:\Documents and Settings\Owner\Application Data\internaldb8467.dat
2007-07-10 16:20 18,432 ----a-w C:\Documents and Settings\Owner\Application Data\internaldb41.dat
2001-09-28 22:00 164,864 ------w C:\Program Files\UNWISE.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2006-11-07 11:29 50736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-04-01 14:49 36352]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="C:\WINDOWS\System32\Macromed\Flash\FlashUtil9b.exe" [ ]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 17:38]
.
Contents of the 'Scheduled Tasks' folder
"2008-06-12 04:00:00 C:\WINDOWS\Tasks\At1.job"
- C:\WINDOWS\System32\8uR6R0wl.exe
"2008-06-11 13:00:00 C:\WINDOWS\Tasks\At10.job"
- C:\WINDOWS\System32\8uR6R0wl.exe
"2008-06-11 14:00:00 C:\WINDOWS\Tasks\At11.job"
- C:\WINDOWS\System32\8uR6R0wl.exe
"2008-06-11 15:00:00 C:\WINDOWS\Tasks\At12.job"
- C:\WINDOWS\System32\8uR6R0wl.exe
"2008-06-12 16:00:00 C:\WINDOWS\Tasks\At13.job"
- C:\WINDOWS\System32\8uR6R0wl.exe
"2008-06-12 17:00:00 C:\WINDOWS\Tasks\At14.job"
- C:\WINDOWS\System32\8uR6R0wl.exe
"2008-06-12 18:00:00 C:\WINDOWS\Tasks\At15.job"
- C:\WINDOWS\System32\8uR6R0wl.exe
"2008-06-11 19:00:00 C:\WINDOWS\Tasks\At16.job"
- C:\WINDOWS\System32\8uR6R0wl.exe
"2008-06-11 20:00:00 C:\WINDOWS\Tasks\At17.job"
- C:\WINDOWS\System32\8uR6R0wl.exe
"2008-06-11 21:00:00 C:\WINDOWS\Tasks\At18.job"
- C:\WINDOWS\System32\8uR6R0wl.exe
"2008-06-11 22:00:00 C:\WINDOWS\Tasks\At19.job"
- C:\WINDOWS\System32\8uR6R0wl.exe
"2008-06-12 05:00:00 C:\WINDOWS\Tasks\At2.job"
- C:\WINDOWS\System32\8uR6R0wl.exe
"2008-06-11 23:00:00 C:\WINDOWS\Tasks\At20.job"
- C:\WINDOWS\System32\8uR6R0wl.exe
"2008-06-12 00:00:00 C:\WINDOWS\Tasks\At21.job"
- C:\WINDOWS\System32\8uR6R0wl.exe
"2008-06-12 01:00:00 C:\WINDOWS\Tasks\At22.job"
- C:\WINDOWS\System32\8uR6R0wl.exe
"2008-06-12 02:00:00 C:\WINDOWS\Tasks\At23.job"
- C:\WINDOWS\System32\8uR6R0wl.exe
"2008-06-12 03:00:00 C:\WINDOWS\Tasks\At24.job"
- C:\WINDOWS\System32\8uR6R0wl.exe
"2008-06-12 04:00:00 C:\WINDOWS\Tasks\At25.job"
- C:\WINDOWS\System32\3CqkNm2O.exe
"2008-06-12 05:00:00 C:\WINDOWS\Tasks\At26.job"
- C:\WINDOWS\System32\3CqkNm2O.exe
"2008-06-12 06:00:00 C:\WINDOWS\Tasks\At27.job"
- C:\WINDOWS\System32\3CqkNm2O.exe
"2008-06-12 07:00:00 C:\WINDOWS\Tasks\At28.job"
- C:\WINDOWS\System32\3CqkNm2O.exe
"2008-06-12 08:00:00 C:\WINDOWS\Tasks\At29.job"
- C:\WINDOWS\System32\3CqkNm2O.exe
"2008-06-12 06:00:00 C:\WINDOWS\Tasks\At3.job"
- C:\WINDOWS\System32\8uR6R0wl.exe
"2008-06-12 09:00:00 C:\WINDOWS\Tasks\At30.job"
- C:\WINDOWS\System32\3CqkNm2O.exe
"2008-06-11 10:00:00 C:\WINDOWS\Tasks\At31.job"
- C:\WINDOWS\System32\3CqkNm2O.exe
"2008-06-11 11:00:00 C:\WINDOWS\Tasks\At32.job"
- C:\WINDOWS\System32\3CqkNm2O.exe
"2008-06-11 12:00:00 C:\WINDOWS\Tasks\At33.job"
- C:\WINDOWS\System32\3CqkNm2O.exe
"2008-06-11 13:00:00 C:\WINDOWS\Tasks\At34.job"
- C:\WINDOWS\System32\3CqkNm2O.exe
"2008-06-11 14:00:00 C:\WINDOWS\Tasks\At35.job"
- C:\WINDOWS\System32\3CqkNm2O.exe
"2008-06-11 15:00:00 C:\WINDOWS\Tasks\At36.job"
- C:\WINDOWS\System32\3CqkNm2O.exe
"2008-06-12 16:00:00 C:\WINDOWS\Tasks\At37.job"
- C:\WINDOWS\System32\3CqkNm2O.exe
"2008-06-12 17:00:00 C:\WINDOWS\Tasks\At38.job"
- C:\WINDOWS\System32\3CqkNm2O.exe
"2008-06-12 18:00:00 C:\WINDOWS\Tasks\At39.job"
- C:\WINDOWS\System32\3CqkNm2O.exe
"2008-06-12 07:00:00 C:\WINDOWS\Tasks\At4.job"
- C:\WINDOWS\System32\8uR6R0wl.exe
"2008-06-11 19:00:00 C:\WINDOWS\Tasks\At40.job"
- C:\WINDOWS\System32\3CqkNm2O.exe
"2008-06-11 20:00:00 C:\WINDOWS\Tasks\At41.job"
- C:\WINDOWS\System32\3CqkNm2O.exe
"2008-06-11 21:00:00 C:\WINDOWS\Tasks\At42.job"
- C:\WINDOWS\System32\3CqkNm2O.exe
"2008-06-11 22:00:00 C:\WINDOWS\Tasks\At43.job"
- C:\WINDOWS\System32\3CqkNm2O.exe
"2008-06-11 23:00:00 C:\WINDOWS\Tasks\At44.job"
- C:\WINDOWS\System32\3CqkNm2O.exe
"2008-06-12 00:00:00 C:\WINDOWS\Tasks\At45.job"
- C:\WINDOWS\System32\3CqkNm2O.exe
"2008-06-12 01:00:00 C:\WINDOWS\Tasks\At46.job"
- C:\WINDOWS\System32\3CqkNm2O.exe
"2008-06-12 02:00:00 C:\WINDOWS\Tasks\At47.job"
- C:\WINDOWS\System32\3CqkNm2O.exe
"2008-06-12 03:00:00 C:\WINDOWS\Tasks\At48.job"
- C:\WINDOWS\System32\3CqkNm2O.exe
"2008-06-12 04:22:00 C:\WINDOWS\Tasks\At49.job"
- C:\WINDOWS\System32\MJnrE4NC.exe
"2008-06-12 08:00:00 C:\WINDOWS\Tasks\At5.job"
- C:\WINDOWS\System32\8uR6R0wl.exe
"2008-06-12 05:00:00 C:\WINDOWS\Tasks\At50.job"
- C:\WINDOWS\System32\MJnrE4NC.exe
"2008-06-12 06:00:00 C:\WINDOWS\Tasks\At51.job"
- C:\WINDOWS\System32\MJnrE4NC.exe
"2008-06-12 07:00:00 C:\WINDOWS\Tasks\At52.job"
- C:\WINDOWS\System32\MJnrE4NC.exe
"2008-06-12 08:00:00 C:\WINDOWS\Tasks\At53.job"
- C:\WINDOWS\System32\MJnrE4NC.exe
"2008-06-12 09:00:00 C:\WINDOWS\Tasks\At54.job"
- C:\WINDOWS\System32\MJnrE4NC.exe
"2008-06-11 10:00:00 C:\WINDOWS\Tasks\At55.job"
- C:\WINDOWS\System32\MJnrE4NC.exe
"2008-06-11 11:00:00 C:\WINDOWS\Tasks\At56.job"
- C:\WINDOWS\System32\MJnrE4NC.exe
"2008-06-11 12:00:00 C:\WINDOWS\Tasks\At57.job"
- C:\WINDOWS\System32\MJnrE4NC.exe
"2008-06-11 13:00:00 C:\WINDOWS\Tasks\At58.job"
- C:\WINDOWS\System32\MJnrE4NC.exe
"2008-06-11 14:00:00 C:\WINDOWS\Tasks\At59.job"
- C:\WINDOWS\System32\MJnrE4NC.exe
"2008-06-12 09:00:00 C:\WINDOWS\Tasks\At6.job"
- C:\WINDOWS\System32\8uR6R0wl.exe
"2008-06-11 15:00:00 C:\WINDOWS\Tasks\At60.job"
- C:\WINDOWS\System32\MJnrE4NC.exe
"2008-06-12 16:00:00 C:\WINDOWS\Tasks\At61.job"
- C:\WINDOWS\System32\MJnrE4NC.exe
"2008-06-12 17:00:00 C:\WINDOWS\Tasks\At62.job"
- C:\WINDOWS\System32\MJnrE4NC.exe
"2008-06-12 18:00:02 C:\WINDOWS\Tasks\At63.job"
- C:\WINDOWS\System32\MJnrE4NC.exe
"2008-06-11 19:00:00 C:\WINDOWS\Tasks\At64.job"
- C:\WINDOWS\System32\MJnrE4NC.exe
"2008-06-11 20:00:00 C:\WINDOWS\Tasks\At65.job"
- C:\WINDOWS\System32\MJnrE4NC.exe
"2008-06-11 21:00:00 C:\WINDOWS\Tasks\At66.job"
- C:\WINDOWS\System32\MJnrE4NC.exe
"2008-06-11 22:00:00 C:\WINDOWS\Tasks\At67.job"
- C:\WINDOWS\System32\MJnrE4NC.exe
"2008-06-11 23:00:00 C:\WINDOWS\Tasks\At68.job"
- C:\WINDOWS\System32\MJnrE4NC.exe
"2008-06-12 00:00:00 C:\WINDOWS\Tasks\At69.job"
- C:\WINDOWS\System32\MJnrE4NC.exe
"2008-06-11 10:00:00 C:\WINDOWS\Tasks\At7.job"
- C:\WINDOWS\System32\8uR6R0wl.exe
"2008-06-12 01:00:00 C:\WINDOWS\Tasks\At70.job"
- C:\WINDOWS\System32\MJnrE4NC.exe
"2008-06-12 02:00:00 C:\WINDOWS\Tasks\At71.job"
- C:\WINDOWS\System32\MJnrE4NC.exe
"2008-06-12 03:00:00 C:\WINDOWS\Tasks\At72.job"
- C:\WINDOWS\System32\MJnrE4NC.exe
"2008-06-11 11:00:00 C:\WINDOWS\Tasks\At8.job"
- C:\WINDOWS\System32\8uR6R0wl.exe
"2008-06-11 12:00:00 C:\WINDOWS\Tasks\At9.job"
- C:\WINDOWS\System32\8uR6R0wl.exe
"2008-06-07 00:32:26 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - Owner.job"
- C:\PROGRA~1\NORTON~1\Navw32.exeh/task:
"2008-06-12 18:09:00 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDetect.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-06-12 14:09:13
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\CCSETMGR.EXE
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCEVTMGR.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
C:\Program Files\Norton AntiVirus\NAVAPSVC.EXE
C:\Program Files\Norton AntiVirus\IWP\NPFMNTOR.EXE
C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Symantec\LiveUpdate\AUPDATE.EXE
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
.
**************************************************************************
.
Completion time: 2008-06-12 14:13:47 - machine was rebooted [Owner]
ComboFix-quarantined-files.txt 2008-06-12 18:13:38
Pre-Run: 45,205,434,880 bytes free
Post-Run: 46,061,892,096 bytes free
315 --- E O F --- 2008-06-12 04:13:58
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:15:29 PM, on 6/12/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.clusty.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = actsvr.comcastonline.com:8100
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = cdn
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US
ee://aol/imAppO4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil9b.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil9b.exe (User 'Default user')
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.1\resources\en-US\local\search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\npjpi160_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\npjpi160_06.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) -
http://www.comcastsupport.com/sdcxuser/asp/tgctlsr.cabO16 - DPF: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} (Microsoft VM) -
file://D:\GAMES\msjavx86_3805.exe
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) -
http://upload.facebook.com/controls/Fac ... loader.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupda ... 5173701078O16 - DPF: {72C9EA8F-8965-40C2-ABAD-D460A5815F86} (hostCntrlIE Class) -
http://host.oddcast.com/hostClientIE.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
https://download.macromedia.com/pub/sho ... wflash.cabO23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Sigmatel PassThru (PassThru) - Unknown owner - C:\Program Files\SigmaTel\C-Major Audio\ControlPanel\passthru.exe
O23 - Service: PrismXL - Lanovation - C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 8368 bytes
Thank you once again for your helpfulness. I will not hesitate to let anyone with malware problems know that you are the experts, and to come to you. And a special thanks to you, Chris, for being so prompt, courteous, and helpful. You have made a positive impression on me I won't soon forget.