Jabuck,
I'm sorry for not getting back to you sooner. Something came up that required my attention over the last two days.
I removed the lines from Highjack This like you said. Did any of those have anything to do with the Trojan and the Highjack spyware in my Topic's title or were they lines you just knew didn't belong? The reason I ask is because I want to know if XoftSpySE and SpyHunter had actually found something on my computer or whether they were just trying to get me to buy their software.
As for the ComboFix log, it's posted below.
ComboFix 07-12-09.1 - Eugene Stevens 2007-12-11 1:40:29.1 - NTFSx86
Running from: C:\temp\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\regsvr32.dll
.
((((((((((((((((((((((((( Files Created from 2007-11-11 to 2007-12-11 )))))))))))))))))))))))))))))))
.
2007-12-11 01:34 . 2007-12-11 01:34 1,596,353 --a------ C:\temp\ComboFix.exe
2007-12-10 10:18 . 2007-12-10 10:19 979,850 --a------ C:\temp\SmitfraudFix.zip
2007-12-10 01:19 . 2007-12-10 01:19 <DIR> d-------- C:\Documents and Settings\Administrator.GENE\Application Data\spweng
2007-12-09 22:37 . 2007-12-09 23:11 <DIR> d-------- C:\Program Files\SpywareGuard
2007-12-09 22:36 . 2007-12-09 22:37 2,062,665 --a------ C:\temp\spywareguardsetup.exe
2007-12-09 12:23 . 2007-12-09 12:23 7,467,056 --a------ C:\temp\spybotsd15.exe
2007-12-09 05:52 . 2007-12-09 05:52 <DIR> d-------- C:\Documents and Settings\Eugene Stevens\Application Data\Grisoft
2007-12-09 05:50 . 2007-12-09 05:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-09 05:50 . 2007-05-30 06:10 10,872 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2007-12-09 05:47 . 2007-12-09 05:48 12,413,440 --a------ C:\temp\avgas-setup-7.5.1.43.exe
2007-12-09 04:32 . 2006-10-04 08:06 1,197,294 -----c--- C:\WINDOWS\SYSTEM32\DLLCACHE\sysmain.sdb
2007-12-09 04:32 . 2006-10-04 08:06 764,868 -----c--- C:\WINDOWS\SYSTEM32\DLLCACHE\apph_sp.sdb
2007-12-09 04:32 . 2006-10-04 08:06 217,118 -----c--- C:\WINDOWS\SYSTEM32\DLLCACHE\apphelp.sdb
2007-12-04 18:14 . 2007-09-21 10:35 91,328 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\msfwdrv.sys
2007-12-04 18:11 . 2007-09-21 10:35 116,416 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\msfwhlpr.sys
2007-12-04 18:02 . 2007-07-06 16:09 70,928 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\MpFilter.sys
2007-12-04 17:54 . 2007-03-29 06:56 409,600 -----c--- C:\WINDOWS\SYSTEM32\DLLCACHE\qmgr.dll
2007-12-04 17:54 . 2007-03-29 06:56 18,944 -----c--- C:\WINDOWS\SYSTEM32\DLLCACHE\qmgrprxy.dll
2007-12-04 17:54 . 2007-03-29 06:56 8,192 -----c--- C:\WINDOWS\SYSTEM32\DLLCACHE\bitsprx2.dll
2007-12-04 17:54 . 2007-03-29 06:56 7,168 -----c--- C:\WINDOWS\SYSTEM32\DLLCACHE\bitsprx4.dll
2007-12-04 17:54 . 2007-03-29 06:56 7,168 -----c--- C:\WINDOWS\SYSTEM32\DLLCACHE\bitsprx3.dll
2007-12-04 17:54 . 2007-03-29 06:56 7,168 --------- C:\WINDOWS\SYSTEM32\bitsprx4.dll
2007-11-28 21:48 . 2007-11-29 00:10 <DIR> d-------- C:\BondageByRequest.com
2007-11-28 03:01 . 2007-11-28 03:01 <DIR> d-------- C:\Program Files\Lavasoft
2007-11-28 03:01 . 2007-11-28 03:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-11-28 02:57 . 2007-11-29 23:54 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-11-28 02:57 . 2007-11-28 02:57 21,216,112 --a------ C:\temp\aaw2007.exe
2007-11-28 01:42 . 2007-11-28 01:43 21,306,051 --a------ C:\temp\PC_DAZStudio_1_8_1_5.exe
2007-11-27 23:48 . 2007-11-28 01:36 <DIR> d-------- C:\Program Files\DAZ
2007-11-27 23:30 . 2007-11-27 23:30 <DIR> d-------- C:\Program Files\Common Files\DAZ
2007-11-27 22:44 . 2007-11-27 23:23 128,164,451 --a------ C:\temp\Bryce5_5_Free_Setup.exe
2007-11-25 22:06 . 2007-11-25 22:09 <DIR> d-------- C:\Program Files\XoftSpySE
2007-11-25 22:05 . 2007-11-25 22:05 3,178,952 --a------ C:\temp\XoftSpySE433_263.exe
2007-11-25 20:47 . 2007-12-09 20:30 <DIR> d-------- C:\Program Files\Enigma Software Group
2007-11-12 04:50 . 2007-11-12 04:50 1,156,096 --a------ C:\temp\iview410_setup.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-11 08:24 --------- d-----w C:\Program Files\Microsoft Windows OneCare Live
2007-12-11 06:39 --------- d-----w C:\Documents and Settings\Eugene Stevens\Application Data\spweng
2007-12-11 06:25 --------- d-----w C:\Documents and Settings\Eugene Stevens\Application Data\uTorrent
2007-12-10 07:21 --------- d-----w C:\Program Files\SpywareBlaster
2007-12-10 07:19 --------- d-----w C:\Program Files\SpyWare Killer
2007-12-09 18:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-04 18:33 927 ----a-w C:\Program Files\PG-Ripper.exe.config
2007-12-01 06:53 --------- d-----w C:\Program Files\uTorrent
2007-11-30 06:00 --------- d-----w C:\Program Files\Anonymizer
2007-11-28 07:27 --------- d-----w C:\Program Files\Common Files\Adobe
2007-11-19 12:00 --------- d-----w C:\Program Files\eMule
2007-11-12 10:52 --------- d-----w C:\Program Files\IrfanView
2007-11-07 22:24 32,256 ----a-w C:\WINDOWS\SYSTEM32\dzbryce6.dll
2007-11-07 22:24 180,224 ----a-w C:\WINDOWS\SYSTEM32\dzwrapper.dll
2007-11-07 22:20 8,704,000 ----a-w C:\WINDOWS\SYSTEM32\dzcore.dll
2007-11-07 22:20 65,536 ----a-w C:\WINDOWS\SYSTEM32\dzcarrara.dll
2007-11-07 22:06 6,131,712 ----a-w C:\WINDOWS\SYSTEM32\daz-qt-mt.dll
2007-11-07 22:06 1,785,856 ----a-w C:\WINDOWS\SYSTEM32\daz-qsa.dll
2007-11-07 21:56 2,076,672 ----a-w C:\WINDOWS\SYSTEM32\dz3delight.dll
2007-11-02 11:29 --------- d-----w C:\Program Files\Pando Networks
2007-11-02 10:34 3,888 -c--a-w C:\WINDOWS\system32\drivers\NTHANDLE.SYS
2007-10-29 08:58 26,624 -csha-w C:\Program Files\Thumbs.db
2007-10-29 06:33 361,721 ----a-w C:\OneCareSupportData.zip
2007-10-28 21:33 --------- d-----w C:\Program Files\HP
2007-10-28 21:33 --------- d-----w C:\Program Files\Hewlett-Packard
2007-10-27 08:02 --------- d-----w C:\Documents and Settings\Default User\Application Data\DivX
2007-10-26 18:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-10-26 02:15 --------- d-----w C:\Program Files\Java
2007-10-24 23:36 --------- d-----w C:\Program Files\Trend Micro
2007-10-22 22:31 --------- d-----w C:\Program Files\HiDownload
2007-10-22 20:52 --------- d-----w C:\Program Files\ShellExView
2007-10-22 20:05 39,424 ----a-w C:\WINDOWS\zipinst.exe
2007-10-12 17:29 827,392 ----a-w C:\Program Files\PG-Ripper.exe
2007-10-12 17:29 8,192 ----a-w C:\Program Files\PG-Ripper.resources.dll
2007-10-07 12:53 25,755,448 ----a-w C:\WINDOWS\wmp11-windowsxp-x86-enu.exe
2004-09-24 06:10 439,510 -c--a-w C:\Program Files\VirusScan.reg
2004-03-11 21:11 995,042 -c--a-w C:\Program Files\VS6sp6B3.cab
2004-03-11 21:11 25,080 -c--a-w C:\Program Files\sp698vbo.inf
2004-03-11 21:11 10,010,624 -c--a-w C:\Program Files\VS6sp6B2.cab
2004-03-11 21:10 9,036,800 -c--a-w C:\Program Files\VS6sp6B1.cab
2004-03-11 21:08 55,791 -c----w C:\Program Files\sp698vbo.stf
2004-03-11 21:08 1,636 -c----w C:\Program Files\setupsp6.lst
2004-03-11 19:01 989,512 -c--a-w C:\Program Files\vbrun60.cab
2004-03-11 02:40 90,507 -c--a-w C:\Program Files\Mci32.cab
2004-03-11 02:40 70,077 -c--a-w C:\Program Files\ComDlg32.CAB
2004-03-11 02:40 697,692 -c--a-w C:\Program Files\Msvbvm60.cab
2004-03-11 02:40 66,476 -c--a-w C:\Program Files\msinet.cab
2004-03-11 02:40 64,259 -c--a-w C:\Program Files\MSAdoDc.CAB
2004-03-11 02:40 63,773 -c--a-w C:\Program Files\mswinsck.cab
2004-03-11 02:40 513,864 -c--a-w C:\Program Files\MSComCtl.CAB
2004-03-11 02:40 346,485 -c--a-w C:\Program Files\MSComCt2.CAB
2004-03-11 02:40 246,297 -c--a-w C:\Program Files\msrdo20.cab
2004-03-11 02:40 143,598 -c--a-w C:\Program Files\comct332.cab
2004-03-11 02:40 142,755 -c--a-w C:\Program Files\msdbrptr.cab
2004-03-11 02:40 133,247 -c--a-w C:\Program Files\MSDatGrd.CAB
2004-03-11 02:40 118,085 -c--a-w C:\Program Files\MSFlxGrd.CAB
2004-03-11 02:40 115,971 -c--a-w C:\Program Files\TabCtl32.CAB
2004-03-11 02:40 108,611 -c--a-w C:\Program Files\MSWcRun.CAB
2004-03-11 02:40 105,135 -c--a-w C:\Program Files\RichTx32.CAB
2004-03-11 02:39 60,699 -c--a-w C:\Program Files\msstdfmt.cab
2004-03-11 02:39 37,721 -c--a-w C:\Program Files\MSBind.CAB
2004-03-09 21:45 397,072 -c--a-w C:\Program Files\mswless.ocx
2004-03-09 21:45 107,008 -c--a-w C:\Program Files\msscript.ocx
2004-02-24 01:35 3,027,068 -c--a-w C:\Program Files\msvbvm60.dbg
2004-02-18 01:56 110,080 -c----w C:\Program Files\sp698vbo.dll
2004-02-11 22:36 6,308 -c----w C:\Program Files\readme.htm
2004-02-11 18:32 2,302 -c----w C:\Program Files\eula.txt
2003-10-30 05:24 784 -c--a-w C:\Documents and Settings\Eugene Stevens\Application Data\mpauth.dat
2003-09-30 02:44 3,148,826 -c--a-w C:\Program Files\MSK4556UUS.EXE
2003-07-01 14:27 3,684,032 -c--a-w C:\Program Files\spybotsd12.exe
2003-06-29 22:58 1,786,691 -c--a-w C:\Program Files\HiNetRecorderSetup.exe
2003-06-11 18:34 207,759 -c--a-w C:\Program Files\INSTALL.LOG
2003-01-14 19:58 487,481 -c--a-w C:\Program Files\jscript.dll
2003-01-14 19:58 438,330 -c--a-w C:\Program Files\vbscript.dll
2001-03-30 16:54 149 -c----w C:\Program Files\setup.ini
2000-11-29 20:34 4,291 -c----w C:\Program Files\toc.htm
2000-07-15 19:44 244 -c--a-w C:\Program Files\style.gif
2000-07-15 19:44 227 -c--a-w C:\Program Files\comments.gif
2000-07-15 19:44 216 -c--a-w C:\Program Files\clientsc.gif
2000-07-15 19:44 207 -c--a-w C:\Program Files\anchorwi.gif
2000-07-15 19:44 196 -c--a-w C:\Program Files\unknownt.gif
2000-07-15 19:44 190 -c--a-w C:\Program Files\pend.gif
2000-07-15 19:44 189 -c--a-w C:\Program Files\pbgn.gif
2000-07-15 19:44 183 -c--a-w C:\Program Files\br.gif
2000-07-15 19:44 175 -c--a-w C:\Program Files\spanend.gif
2000-07-15 19:44 171 -c--a-w C:\Program Files\formend.gif
2000-07-15 19:44 170 -c--a-w C:\Program Files\spanbgn.gif
2000-07-15 19:44 168 -c--a-w C:\Program Files\formbgn.gif
2000-07-15 19:44 164 -c--a-w C:\Program Files\divend.gif
2000-07-15 19:44 160 -c--a-w C:\Program Files\divbgn.gif
2000-07-15 19:43 84 -c----w C:\Program Files\setup.tdf
2000-07-15 19:10 26,896 -c--a-w C:\Program Files\dispex.dll
2000-06-13 17:47 2,718 -c----w C:\Program Files\redist.txt
2000-06-13 15:33 2,482 -c--a-w C:\Program Files\mswless.dep
2000-06-13 15:29 74,352 -c----w C:\Program Files\setupsp6.exe
2000-06-13 15:29 371,200 -c----w C:\Program Files\acmsetup.exe
2000-06-13 15:29 32,256 -c----w C:\Program Files\selfreg.dll
2000-06-13 15:29 283,136 -c----w C:\Program Files\mssetup.dll
2000-06-13 15:29 14,490 -c----w C:\Program Files\acmsetup.hlp
2000-05-31 20:39 62,411 -c--a-w C:\Program Files\MSDERUN.CAB
2005-01-28 22:35 56 --sh--r C:\WINDOWS\SYSTEM32\A3E3032145.sys
2005-01-28 22:35 1,682 --sha-w C:\WINDOWS\SYSTEM32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 10:24]
"ANONYMIZER_SPYWAREKILLER"="C:\Program Files\SpyWare Killer\spywarekiller.exe" [2004-06-04 08:12]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 11:09]
"PRIVANAL"="" []
"IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2006-07-16 19:35]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56]
"Iomega Active Disk"="C:\Program Files\Iomega\AutoDisk\AD2KClient.exe" [2001-06-21 07:47]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 20:05]
"Pando"="C:\Program Files\Pando Networks\Pando\Pando.exe" [2007-10-31 13:57]
"SPYKILLER"="C:\Program Files\Anonymizer\sk\SpyWareKiller.exe" [2004-02-12 12:31]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MMTray"="C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe" [2002-08-14 16:29]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-08-20 14:55]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-08-20 14:51]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2005-09-03 18:21]
"MXO Auto Loader"="C:\WINDOWS\MXOALDR.EXE" [2003-04-07 18:09]
"AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2006-02-25 10:04]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 22:11]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2005-10-28 12:08]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-12-15 19:41]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-07-28 01:15]
"OneCareUI"="C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe" [2007-11-19 09:38]
"POINTER"="point32.exe" []
"MaxtorOneTouch"="C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe" [2003-05-21 15:30]
"Iomega Startup Options"="C:\Program Files\Iomega\Common\ImgStart.exe" [2001-01-17 16:33]
"Iomega Drive Icons"="C:\Program Files\Iomega\DriveIcons\ImgIcon.exe" [2001-06-20 12:25]
"DVDSentry"="C:\WINDOWS\System32\DSentry.exe" [2002-08-14 17:22]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-03 23:31]
"IMEKRMIG6.1"="C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE" [2002-08-29 04:00]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 03:25]
C:\Documents and Settings\Eugene Stevens\Start Menu\Programs\Startup\
SpywareGuard.lnk - C:\Program Files\SpywareGuard\sgmain.exe [2003-08-29 19:05:35]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
America Online 8.0 Tray Icon.lnk - C:\Program Files\America Online 8.0\aoltray.exe [2003-06-11 12:38:43]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2003-06-11 12:28:42]
DriveSelect.lnk - C:\Program Files\321Studios\Xpress\DriveSelect.exe [2003-05-05 13:19:37]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-04 18:28:24]
HP Image Zone Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-04 18:50:52]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2006-09-25 21:46:24]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\OneCareMP]
@="Service"
R1 MSFWHLPR;MSFWHLPR;C:\WINDOWS\system32\DRIVERS\msfwhlpr.sys
R2 FastPara;FastPara;C:\WINDOWS\system32\drivers\FastPara.sys
R2 MSFWDrv;MSFWDrv;C:\WINDOWS\system32\DRIVERS\msfwdrv.sys
R3 MpFilter;Microsoft Malware Protection Driver;C:\WINDOWS\system32\DRIVERS\MpFilter.sys
R3 XIRLINK;Veo PC Camera;C:\WINDOWS\system32\DRIVERS\ucdnt.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a61079ba-456f-11dc-88ab-00038a000015}]
\Shell\AutoRun\command - K:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
"2007-06-05 20:35:31 C:\WINDOWS\Tasks\MP Scheduled Quick Scan.job"
- C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MpCmdRun.exe
"2007-12-10 09:11:29 C:\WINDOWS\Tasks\WebReg psc 1600 series.job"
- C:\Program Files\HP\Digital Imaging\bin\hpqwrg.exe
"2007-12-11 08:06:45 C:\WINDOWS\Tasks\XoftSpySE 2.job"
- C:\Program Files\XoftSpySE\XoftSpy.exe
"2007-12-09 02:26:54 C:\WINDOWS\Tasks\XoftSpySE.job"
- C:\Program Files\XoftSpySE\XoftSpy.exe
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\DOCUME~1\EUGENE~1\LOCALS~1\Temp\vohejlxj.dll
.
**************************************************************************
catchme 0.3.1331 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-11 02:26:55
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-11 2:34:28 - machine was rebooted
.
--- E O F ---