I restarted the machine and reran ComboFix...Here is the log. Do I need to run anything else? I couldn't figure out how to disable spyware doctor... ComboFix 09-11-04.02 - Joe Kirsits 11/05/2009 9:29.2.4 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2791 [GMT -7:00] Running from: c:\documents and settings\Joe Kirsits\Desktop\ComboFix.exe AV: Spyware Doctor with AntiVirus *On-access scanning enabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6} AV: Symantec Endpoint Protection *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C} FW: Symantec Endpoint Protection *disabled* {BE898FE3-CD0B-4014-85A9-03DB9923DDB6} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\TEMP\logishrd\LVPrcInj01.dll . ---- Previous Run ------- . c:\documents and settings\All Users\Microsoft AData\sysnet.dll c:\documents and settings\All Users\Microsoft AData\t.sid c:\documents and settings\Joe Kirsits\Desktop\Personal Guard 2009.lnk c:\documents and settings\Joe Kirsits\Start Menu\Programs\Personal Guard 2009\Personal Guard 2009.lnk c:\documents and settings\Joe Kirsits\Start Menu\Programs\Personal Guard 2009\Uninstall.lnk c:\program files\Personal Guard 2009\config.scf c:\program files\Personal Guard 2009\mmbase.sdb c:\program files\Personal Guard 2009\personalguard.exe c:\program files\Personal Guard 2009\q.sdb c:\program files\Personal Guard 2009\uninstalls.exe c:\program files\Personal Guard 2009\vvbase.sdb c:\windows\microsoftdef.dll c:\windows\system32\a9k.bin c:\windows\system32\biserano.exe c:\windows\system32\dogubina.exe c:\windows\system32\dozilibe.dll c:\windows\system32\feresefa.dll c:\windows\system32\jaguvonu.dll c:\windows\system32\jigefuwi.exe c:\windows\system32\kataliwo.dll c:\windows\system32\kibemole.dll c:\windows\system32\kinotige.dll c:\windows\system32\kudavori.dll c:\windows\system32\logon.exe c:\windows\system32\roledufe.exe c:\windows\system32\tatokalo.exe c:\windows\system32\telemize.exe c:\windows\system32\tonasuta.dll c:\windows\system32\twain32\local.ds c:\windows\system32\twain32\user.ds c:\windows\system32\veyesera.dll c:\windows\system32\vuhodoji.dll c:\windows\system32\wapoyali.dll c:\windows\system32\yopogeli.dll c:\windows\TEMP\logishrd\LVPrcInj07.dll -- Previous Run -- Infected copy of c:\windows\system32\drivers\aec.sys was found and disinfected Restored copy from - c:\windows\system32\dllcache\aec.sys c:\windows\system32\proquota.exe was missing Restored copy from - c:\windows\system32\dllcache\proquota.exe -------- . ((((((((((((((((((((((((( Files Created from 2009-10-05 to 2009-11-05 ))))))))))))))))))))))))))))))) . 2009-11-04 21:20 . 2008-04-14 00:12 50176 ----a-w- c:\windows\system32\proquota.exe 2009-11-04 21:14 . 2009-11-04 21:14 380416 ----a-w- c:\windows\system32\winsc.exe 2009-11-04 20:51 . 2009-11-04 20:51 -------- d-----w- c:\program files\Trend Micro 2009-11-04 19:59 . 2007-10-23 16:27 110592 ----a-w- c:\documents and settings\Joe Kirsits\Application Data\U3\temp\cleanup.exe 2009-11-04 19:58 . 2008-05-02 17:41 3493888 ---ha-w- c:\documents and settings\Joe Kirsits\Application Data\U3\temp\Launchpad Removal.exe 2009-11-04 19:58 . 2009-11-04 21:03 -------- d-----w- c:\documents and settings\Joe Kirsits\Application Data\U3 2009-11-04 19:50 . 2009-11-04 19:50 -------- d--h--w- c:\windows\PIF 2009-11-04 05:37 . 2009-11-04 20:15 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-11-04 03:39 . 2009-11-04 03:39 -------- d-----w- c:\documents and settings\Joe Kirsits\Local Settings\Application Data\Threat Expert 2009-11-04 03:25 . 2009-10-08 20:14 59664 --s---w- c:\windows\system32\drivers\TfSysMon.sys 2009-11-04 03:25 . 2009-10-08 20:14 33552 --s---w- c:\windows\system32\drivers\TfNetMon.sys 2009-11-04 03:20 . 2009-11-04 03:20 -------- d-----w- c:\documents and settings\Joe Kirsits\Application Data\PC Tools 2009-11-04 02:58 . 2009-11-04 21:00 51197 ----a-w- c:\windows\spoov.exe 2009-11-04 02:58 . 2009-11-04 21:00 47872 ----a-w- c:\windows\certsystem.exe 2009-11-04 02:58 . 2009-11-04 21:00 38352 ----a-w- c:\windows\regred.exe 2009-11-04 02:58 . 2009-11-04 21:00 33149 ----a-w- c:\windows\usexplorer.exe 2009-11-04 02:58 . 2009-11-04 21:00 28320 ----a-w- c:\windows\securits.com 2009-11-03 21:26 . 2009-11-03 21:26 152576 ----a-w- c:\documents and settings\Joe Kirsits\Application Data\Sun\Java\jre1.6.0_17\lzma.dll 2009-11-03 00:34 . 2009-11-03 00:34 -------- d-----w- c:\program files\Common Files\Logitech 2009-11-03 00:32 . 2009-11-03 00:32 -------- d-----w- c:\documents and settings\Joe Kirsits\Local Settings\Application Data\Downloaded Installations 2009-11-02 23:47 . 2009-04-21 05:12 149768 ----a-w- c:\windows\system32\drivers\wpshelper.sys 2009-11-02 23:46 . 2009-09-18 01:38 92488 ----a-w- c:\windows\system32\drivers\SysPlant.sys 2009-11-02 23:45 . 2009-11-02 23:45 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL 2009-11-02 23:45 . 2009-11-02 23:45 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS 2009-11-02 23:45 . 2006-05-16 19:58 2584848 -c--a-w- c:\documents and settings\All Users\Application Data\Symantec\Cached Installs\{2EFCC193-D915-4CCB-9201-31773A27BC06}\WindowsInstaller-KB893803-x86.exe 2009-11-02 23:45 . 2009-09-18 08:54 300432 -c--a-w- c:\documents and settings\All Users\Application Data\Symantec\Cached Installs\{2EFCC193-D915-4CCB-9201-31773A27BC06}\Setup.exe 2009-11-02 23:45 . 2009-09-18 01:27 669000 -c--a-w- c:\documents and settings\All Users\Application Data\Symantec\Cached Installs\{2EFCC193-D915-4CCB-9201-31773A27BC06}\smcinst.exe 2009-11-02 23:45 . 2009-07-16 09:21 3557096 -c--a-w- c:\documents and settings\All Users\Application Data\Symantec\Cached Installs\{2EFCC193-D915-4CCB-9201-31773A27BC06}\LUSETUP.EXE 2009-11-02 23:45 . 2009-07-16 09:21 927096 -c--a-w- c:\documents and settings\All Users\Application Data\Symantec\Cached Installs\{2EFCC193-D915-4CCB-9201-31773A27BC06}\LuCheck.exe 2009-11-01 20:58 . 2009-10-11 11:17 411368 ----a-w- c:\windows\system32\deploytk.dll 2009-11-01 20:58 . 2009-11-01 20:58 152576 ----a-w- c:\documents and settings\Joe Kirsits\Application Data\Sun\Java\jre1.6.0_15\lzma.dll 2009-11-01 20:51 . 2008-04-14 00:12 116224 ----a-w- c:\windows\system32\dllcache\xrxwiadr.dll 2009-11-01 20:51 . 2001-08-18 05:36 23040 ----a-w- c:\windows\system32\dllcache\xrxwbtmp.dll 2009-11-01 20:51 . 2008-04-14 00:12 18944 ----a-w- c:\windows\system32\dllcache\xrxscnui.dll 2009-11-01 20:49 . 2001-08-17 19:13 16925 ----a-w- c:\windows\system32\dllcache\w940nd.sys 2009-11-01 20:48 . 2001-08-17 20:58 22912 ----a-w- c:\windows\system32\dllcache\umaxpcls.sys 2009-11-01 20:47 . 2004-08-04 09:00 21896 ----a-w- c:\windows\system32\dllcache\tdipx.sys 2009-11-01 20:46 . 2001-08-17 19:51 20752 ----a-w- c:\windows\system32\dllcache\sonync.sys 2009-11-01 20:45 . 2001-08-17 19:50 101760 ----a-w- c:\windows\system32\dllcache\sis300ip.sys 2009-11-01 20:44 . 2001-08-17 19:50 41216 ----a-w- c:\windows\system32\dllcache\s3mt3d.sys 2009-11-01 20:43 . 2008-04-14 00:12 363520 ----a-w- c:\windows\system32\dllcache\psisdecd.dll 2009-11-01 20:42 . 2001-08-17 21:05 25216 ----a-w- c:\windows\system32\dllcache\ovsound2.sys 2009-11-01 20:41 . 2001-08-18 05:36 38912 ----a-w- c:\windows\system32\dllcache\EXCH_ntfsdrv.dll 2009-11-01 20:40 . 2001-08-17 19:50 103296 ----a-w- c:\windows\system32\dllcache\mtxvideo.sys 2009-11-01 20:39 . 2001-08-17 20:28 797500 ----a-w- c:\windows\system32\dllcache\ltsmt.sys 2009-11-01 20:38 . 2004-08-04 09:00 59904 ----a-w- c:\windows\system32\dllcache\imkrinst.exe 2009-11-01 20:37 . 2001-08-17 20:28 67167 ----a-w- c:\windows\system32\dllcache\hsf_bsc2.sys 2009-11-01 20:36 . 2001-08-17 19:13 27165 ----a-w- c:\windows\system32\dllcache\fetnd5.sys 2009-11-01 20:35 . 2004-08-04 09:00 514587 ----a-w- c:\windows\system32\dllcache\edb500.dll 2009-11-01 20:34 . 2004-08-04 09:00 56320 ----a-w- c:\windows\system32\dllcache\convlog.exe 2009-11-01 20:33 . 2001-08-17 20:49 26624 ----a-w- c:\windows\system32\dllcache\alifir.sys 2009-11-01 20:31 . 2004-08-04 09:00 7168 ----a-w- c:\windows\system32\dllcache\wamregps.dll 2009-11-01 20:31 . 2001-08-17 21:56 66048 ----a-w- c:\windows\system32\dllcache\s3legacy.dll 2009-11-01 20:31 . 2004-08-04 09:00 7680 ----a-w- c:\windows\system32\dllcache\inetmgr.exe 2009-11-01 20:31 . 2004-08-04 09:00 19968 ----a-w- c:\windows\system32\dllcache\inetsloc.dll 2009-11-01 20:31 . 2004-08-04 09:00 169984 ----a-w- c:\windows\system32\dllcache\iisui.dll 2009-11-01 20:31 . 2004-08-04 09:00 6144 ----a-w- c:\windows\system32\dllcache\ftpsapi2.dll 2009-11-01 20:31 . 2004-08-04 09:00 5632 ----a-w- c:\windows\system32\dllcache\iisrstap.dll 2009-11-01 20:31 . 2004-08-04 09:00 14336 ----a-w- c:\windows\system32\dllcache\iisreset.exe 2009-10-30 23:58 . 2009-11-05 16:37 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP 2009-10-30 23:57 . 2009-11-04 03:20 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools 2009-10-30 23:36 . 2009-10-30 23:36 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache 2009-10-22 06:59 . 2009-10-22 06:59 -------- d-sh--w- c:\windows\system32\config\systemprofile\PrivacIE 2009-10-22 06:59 . 2009-10-22 06:59 -------- d-sh--w- c:\windows\system32\config\systemprofile\IECompatCache 2009-10-17 03:00 . 2009-10-17 03:00 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache 2009-10-10 16:49 . 2009-10-10 16:49 127872 ----a-w- c:\documents and settings\Joe Kirsits\Application Data\Move Networks\uninstall.exe 2009-10-10 16:49 . 2009-10-10 16:51 -------- d-----w- c:\documents and settings\Joe Kirsits\Application Data\Move Networks 2009-10-07 06:54 . 2009-10-07 06:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage 2009-10-07 06:53 . 2009-10-07 06:53 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache 2009-10-07 04:47 . 2009-10-07 04:47 -------- d-----w- c:\windows\system32\scripting 2009-10-07 04:47 . 2009-10-07 04:47 -------- d-----w- c:\windows\l2schemas 2009-10-07 04:47 . 2009-10-07 04:47 -------- d-----w- c:\windows\system32\en 2009-10-07 04:47 . 2009-10-07 04:47 -------- d-----w- c:\windows\system32\bits 2009-10-07 04:36 . 2009-10-07 04:36 -------- d-sh--w- c:\documents and settings\Joe Kirsits\IECompatCache 2009-10-07 04:34 . 2009-10-07 04:34 -------- d-sh--w- c:\documents and settings\Joe Kirsits\PrivacIE 2009-10-07 04:32 . 2009-10-07 04:32 -------- d-sh--w- c:\documents and settings\Joe Kirsits\IETldCache 2009-10-07 04:31 . 2009-08-07 08:48 100352 ------w- c:\windows\system32\dllcache\iecompat.dll 2009-10-07 04:31 . 2009-10-07 04:31 -------- d-----w- c:\windows\ie8updates 2009-10-07 04:30 . 2009-08-29 08:08 12800 ------w- c:\windows\system32\dllcache\xpshims.dll 2009-10-07 04:30 . 2009-08-29 08:08 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll 2009-10-07 04:30 . 2009-10-07 04:30 -------- dc-h--w- c:\windows\ie8 . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-11-04 20:59 . 2009-11-04 03:20 -------- d-----w- c:\program files\Spyware Doctor 2009-11-04 17:14 . 2008-12-03 16:48 -------- d-----w- c:\documents and settings\Joe Kirsits\Application Data\Skype 2009-11-04 17:10 . 2007-10-10 19:01 5776 ----a-w- c:\windows\system32\drivers\ADIHdAud.sys 2009-11-04 15:59 . 2008-12-03 16:51 -------- d-----w- c:\documents and settings\Joe Kirsits\Application Data\skypePM 2009-11-04 03:25 . 2009-11-04 03:20 -------- d-----w- c:\program files\Common Files\PC Tools 2009-11-03 21:27 . 2007-10-10 19:14 -------- d-----w- c:\program files\Java 2009-11-02 23:47 . 2007-10-23 17:04 -------- d-----w- c:\program files\Common Files\Symantec Shared 2009-11-02 23:47 . 2007-10-23 17:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec 2009-11-02 23:45 . 2007-10-23 17:04 -------- d-----w- c:\program files\Symantec 2009-11-02 23:45 . 2009-11-02 23:45 806 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF 2009-11-02 23:45 . 2009-11-02 23:45 7456 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT 2009-10-10 16:49 . 2009-06-16 06:35 4183416 ----a-w- c:\documents and settings\Joe Kirsits\Application Data\Move Networks\plugins\npqmp071503000010.dll 2009-10-08 20:14 . 2009-11-04 03:25 51984 --s---w- c:\windows\system32\drivers\TfFsMon.sys 2009-10-08 18:31 . 2009-11-04 03:24 149456 ----a-w- c:\windows\SGDetectionTool.dll 2009-10-08 18:31 . 2009-11-04 03:24 165840 ----a-w- c:\windows\PCTBDRes.dll 2009-10-08 18:31 . 2009-11-04 03:24 1636304 ----a-w- c:\windows\PCTBDCore.dll 2009-10-08 18:31 . 2009-11-04 03:24 767952 ----a-w- c:\windows\BDTSupport.dll 2009-10-07 06:57 . 2007-10-10 19:20 96624 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-10-07 04:49 . 2004-08-11 21:14 87699 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat 2009-10-06 23:31 . 2009-11-04 03:21 87784 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys 2009-10-02 21:19 . 2009-11-04 03:24 1152470 ----a-w- c:\windows\UDB.zip 2009-09-24 15:55 . 2009-11-04 03:21 229304 ----a-w- c:\windows\system32\drivers\pctgntdi.sys 2009-09-23 23:10 . 2009-11-04 03:21 207280 ----a-w- c:\windows\system32\drivers\PCTCore.sys 2009-09-18 01:31 . 2009-09-18 01:31 42312 ----a-w- c:\windows\system32\drivers\WPSDRVnt.sys 2009-09-18 01:30 . 2009-09-18 01:30 357704 ----a-w- c:\windows\system32\sysfer.dll 2009-09-18 01:30 . 2009-09-18 01:30 107848 ----a-w- c:\windows\system32\SymVPN.dll 2009-09-18 01:28 . 2009-09-18 01:28 87368 ----a-w- c:\windows\system32\FwsVpn.dll 2009-09-16 10:20 . 2009-10-31 20:13 7383 ----a-w- c:\windows\system32\drivers\pctcore.cat 2009-09-15 13:20 . 2009-11-04 03:21 7383 ----a-w- c:\windows\system32\drivers\pctplsg.cat 2009-09-15 09:12 . 2009-11-04 03:21 7412 ----a-w- c:\windows\system32\drivers\PCTAppEvent.cat 2009-09-15 08:01 . 2009-11-04 03:21 7387 ----a-w- c:\windows\system32\drivers\pctgntdi.cat 2009-09-11 14:18 . 2004-08-11 21:00 136192 ----a-w- c:\windows\system32\msv1_0.dll 2009-09-09 04:53 . 2009-09-09 04:52 -------- d-----w- c:\documents and settings\Joe Kirsits\Application Data\W Photo Studio 2009-09-09 04:52 . 2009-09-09 04:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Walgreens 2009-09-09 04:52 . 2007-10-28 03:48 -------- d-----w- c:\documents and settings\Joe Kirsits\Application Data\Walgreens 2009-09-09 04:52 . 2009-09-09 04:52 -------- d-----w- c:\program files\Common Files\HP 2009-09-09 04:52 . 2009-09-09 04:52 -------- d-----w- c:\program files\Walgreens 2009-09-09 04:52 . 2008-05-08 03:40 -------- d-----w- c:\documents and settings\Joe Kirsits\Application Data\W Photo Studio Viewer 2009-09-08 16:17 . 2008-03-03 02:51 0 ----a-w- c:\windows\system32\drivers\lvuvc.hs 2009-09-08 16:16 . 2008-03-03 02:51 0 ----a-w- c:\windows\system32\drivers\logiflt.iad 2009-09-04 21:03 . 2004-08-11 21:00 58880 ----a-w- c:\windows\system32\msasn1.dll 2009-09-03 23:17 . 2009-09-03 23:17 625032 ----a-w- c:\windows\system32\SymNeti.dll 2009-09-03 23:16 . 2009-09-03 23:16 242056 ----a-w- c:\windows\system32\SymRedir.dll 2009-09-03 23:03 . 2009-09-03 23:03 38448 ----a-w- c:\windows\system32\drivers\symndisv.sys 2009-09-03 23:03 . 2009-09-03 23:03 39856 ----a-w- c:\windows\system32\drivers\symids.sys 2009-09-03 23:03 . 2009-09-03 23:03 35120 ----a-w- c:\windows\system32\drivers\symndis.sys 2009-09-03 23:03 . 2009-09-03 23:03 26416 ----a-w- c:\windows\system32\drivers\symredrv.sys 2009-09-03 23:03 . 2009-09-03 23:03 188080 ----a-w- c:\windows\system32\drivers\symtdi.sys 2009-09-03 23:03 . 2009-09-03 23:03 145968 ----a-w- c:\windows\system32\drivers\symfw.sys 2009-09-03 23:03 . 2009-09-03 23:03 12720 ----a-w- c:\windows\system32\drivers\symdns.sys 2009-09-03 16:45 . 2009-11-04 03:21 70408 ----a-w- c:\windows\system32\drivers\pctplsg.sys 2009-09-03 05:22 . 2009-09-03 05:22 1961720 ----a-w- c:\documents and settings\Joe Kirsits\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe 2009-08-29 08:08 . 2004-08-11 21:00 916480 ----a-w- c:\windows\system32\wininet.dll 2009-08-26 08:00 . 2004-08-11 21:00 247326 ----a-w- c:\windows\system32\strmdll.dll 2009-08-26 03:05 . 2009-08-26 03:05 43696 ----a-w- c:\windows\system32\drivers\srtspx.sys 2009-08-26 03:05 . 2009-08-26 03:05 320560 ----a-w- c:\windows\system32\drivers\srtspl.sys 2009-08-26 03:05 . 2009-08-26 03:05 281648 ----a-w- c:\windows\system32\drivers\srtsp.sys 2009-08-15 00:04 . 2009-08-15 00:04 239088 ----a-w- c:\documents and settings\Joe Kirsits\Application Data\Mozilla\plugins\npgoogletalk.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{472734EA-242A-422B-ADF8-83D1E48CC825}"= "c:\program files\Spyware Doctor\BDT\PCTBrowserDefender.dll" [2009-10-08 395216] [HKEY_CLASSES_ROOT\clsid\{472734ea-242a-422b-adf8-83d1e48cc825}] [HKEY_CLASSES_ROOT\BrowserDefender.BDToolbar.1] [HKEY_CLASSES_ROOT\TypeLib\{175B7885-28AB-4D18-8773-7A13A99980A4}] [HKEY_CLASSES_ROOT\BrowserDefender.BDToolbar] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{472734EA-242A-422B-ADF8-83D1E48CC825}"= "c:\program files\Spyware Doctor\BDT\PCTBrowserDefender.dll" [2009-10-08 395216] [HKEY_CLASSES_ROOT\clsid\{472734ea-242a-422b-adf8-83d1e48cc825}] [HKEY_CLASSES_ROOT\BrowserDefender.BDToolbar.1] [HKEY_CLASSES_ROOT\TypeLib\{175B7885-28AB-4D18-8773-7A13A99980A4}] [HKEY_CLASSES_ROOT\BrowserDefender.BDToolbar] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472] "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2008-12-03 3882312] "Logitech Vid"="c:\program files\Logitech\Logitech Vid\vid.exe" [2009-07-16 5458704] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-06-28 141848] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-06-28 162328] "Persistence"="c:\windows\system32\igfxpers.exe" [2007-06-28 137752] "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-07-12 178712] "ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920] "RoxioDragToDisc"="c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-08-17 1116920] "PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2006-10-20 118784] "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-10-10 227328] "Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2006-01-13 483328] "ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 90112] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-09-26 267064] "BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2008-11-04 615696] "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2009-07-09 115560] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280] c:\documents and settings\Joe Kirsits\Start Menu\Programs\Startup\ DING!.lnk - c:\program files\Southwest Airlines\Ding\Ding.exe [2006-6-22 462848] Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2007-10-27 368640] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-100000000002}\SC_Acrobat.exe [2007-10-23 25214] Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\WINDOWS\\system32\\usmt\\migwiz.exe"= "c:\\Program Files\\Pinnacle\\Studio 11\\programs\\RM.exe"= "c:\\Program Files\\Pinnacle\\Studio 11\\programs\\Studio.exe"= "c:\\Program Files\\Pinnacle\\Studio 11\\programs\\PMSRegisterFile.exe"= "c:\\Program Files\\Pinnacle\\Studio 11\\programs\\umi.exe"= "c:\\Program Files\\NetMeeting\\conf.exe"= "c:\\WINDOWS\\system32\\dpvsetup.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Documents and Settings\\Joe Kirsits\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"= "c:\\Documents and Settings\\Joe Kirsits\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Program Files\\uSirius\\uSirius.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\Orb Networks\\Orb\\bin\\Orb.exe"= "c:\\Program Files\\Orb Networks\\Orb\\bin\\OrbTray.exe"= "c:\\Program Files\\Orb Networks\\Orb\\bin\\OrbStreamerClient.exe"= "c:\\Program Files\\Orb Networks\\Orb\\bin\\xmltv.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Roxio\\Drag-to-Disc\\DrgToDsc.exe"= "c:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe"= "c:\\Program Files\\Common Files\\LogiShrd\\LComMgr\\Communications_Helper.exe"= "c:\\Program Files\\ATI Technologies\\ATI.ACE\\CLI.exe"= "c:\\Program Files\\Common Files\\LogiShrd\\LQCVFX\\COCIManager.exe"= "c:\\Program Files\\Common Files\\LogiShrd\\LVCOMSER\\LVComSer.exe"= "c:\\Program Files\\iPod\\bin\\iPodService.exe"= "c:\\Program Files\\Symantec\\Symantec Endpoint Protection\\Smc.exe"= "c:\\Program Files\\Symantec\\Symantec Endpoint Protection\\SNAC.EXE"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= "c:\\Program Files\\Logitech\\Logitech Vid\\Vid.exe"= R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [11/3/2009 8:21 PM 207280] R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [11/3/2009 8:25 PM 51984] R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [11/3/2009 8:25 PM 59664] R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [11/3/2009 8:21 PM 229304] R2 ASFAgent;ASF Agent;c:\program files\Intel\ASF Agent\ASFAgent.exe [1/23/2007 12:58 AM 133968] R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [11/3/2009 8:24 PM 112592] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [11/2/2009 4:46 PM 102448] S3 AsfAlrt;AsfAlrt Service;c:\windows\system32\drivers\Asfalrt.sys [1/23/2007 12:45 AM 42832] S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [7/14/2009 12:51 PM 23888] S3 pctplsg;pctplsg;c:\windows\system32\drivers\pctplsg.sys [11/3/2009 8:21 PM 70408] S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [11/3/2009 8:20 PM 358600] S3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [11/3/2009 8:25 PM 33552] S3 ThreatFire;ThreatFire;c:\program files\Spyware Doctor\TFEngine\TFService.exe service --> c:\program files\Spyware Doctor\TFEngine\TFService.exe service [?] --- Other Services/Drivers In Memory --- *Deregistered* - mbr . Contents of the 'Scheduled Tasks' folder 2009-10-23 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 21:57] 2009-11-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3666018106-4025043593-1585384227-1005Core.job - c:\documents and settings\Joe Kirsits\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-12-03 00:10] 2009-11-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3666018106-4025043593-1585384227-1005UA.job - c:\documents and settings\Joe Kirsits\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-12-03 00:10] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.yahoo.com/ mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll . - - - - ORPHANS REMOVED - - - - BHO-{b869605e-4aeb-4d9c-a98d-777049ac8ba6} - jaguvonu.dll HKLM-Run-hemofesase - wapoyali.dll SharedTaskScheduler-{1b882e46-4bd2-43ed-90db-8414f64ca72d} - (no file) SSODL-tuvudevuh-{1b882e46-4bd2-43ed-90db-8414f64ca72d} - (no file) SSODL-SysNet-{1E6818E2-FE1C-46FB-8D79-88F244D87DA7} - c:\documents and settings\All Users\Microsoft AData\sysnet.dll Notify-NavLogon - (no file) ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-11-05 09:38 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences] @Denied: (2) (LocalSystem) "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,64,23,50,0a,5b,b5,ab,40,92,5e,03,\ "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,64,23,50,0a,5b,b5,ab,40,92,5e,03,\ . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(892) c:\windows\system32\Ati2evxx.dll - - - - - - - > 'lsass.exe'(948) c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll - - - - - - - > 'explorer.exe'(2280) c:\windows\system32\WININET.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\Ati2evxx.exe c:\windows\system32\Ati2evxx.exe c:\program files\Symantec\Symantec Endpoint Protection\Smc.exe c:\program files\Common Files\Symantec Shared\ccSvcHst.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE c:\program files\Symantec\Symantec Endpoint Protection\Rtvscan.exe c:\windows\system32\wdfmgr.exe c:\program files\Symantec\Symantec Endpoint Protection\SmcGui.exe c:\program files\Google\Google Desktop Search\GoogleDesktopIndex.exe c:\program files\ATI Technologies\ATI.ACE\CLI.EXE c:\program files\ATI Technologies\ATI.ACE\cli.exe c:\program files\ATI Technologies\ATI.ACE\cli.exe c:\program files\iPod\bin\iPodService.exe . ************************************************************************** . Completion time: 2009-11-05 9:44 - machine was rebooted ComboFix-quarantined-files.txt 2009-11-05 16:44 Pre-Run: 117,854,744,576 bytes free Post-Run: 117,808,893,952 bytes free