Thank you for your help. If you have other suggestions, remember I can't use normal mode for more than a few seconds.
- AVG won't start on that computer. I tried in Safe mode too. I tried to uninstall it but I get an error message.
- I did a full scan with Norton in safe mode. Nothing found.
- I looked for *censored*.exe, it's not there.
- O4 - HKLM\..\Run: [SystemMgr] C:\WINDOWS\system32\Ir32_b.exe is not there anymore. Maybe because I did a system restore?
Combofix:
"Administrator" - 2007-06-24 11:49:17 - ComboFix 07-06-23.5 - Service Pack 2 NTFS [SAFE MODE]
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\msxml3a.dll
((((((((((((((((((((((((( Files Created from 2007-05-24 to 2007-06-24 )))))))))))))))))))))))))))))))
2007-06-24 11:49 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-06-24 11:37 524,288 --ah----- C:\DOCUME~1\ADMINI~1.PAT\NTUSER.DAT
2007-06-24 11:25 <DIR> d-------- C:\Program Files\Norton Internet Security
2007-06-24 11:00 624,784 --a------ C:\WINDOWS\system32\SymNeti.dll
2007-06-24 08:46 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft(2)
2007-06-21 18:25 786,432 --a------ C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-06-21 18:16 4,075,520 --a------ C:\DOCUME~1\Patrick\ntuser.dat
2007-06-21 18:16 233,472 --a------ C:\DOCUME~1\LOCALS~1\ntuser.dat
2007-06-18 17:23 <DIR> d-------- C:\WINDOWS\system32\SoftwareDistribution
2007-06-16 16:25 <DIR> dr-h----- C:\DOCUME~1\Patrick\APPLIC~1\CrystalSpace
2007-06-16 15:55 <DIR> d-------- C:\Program Files\The Adventure Company
2007-06-10 10:44 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2007-06-03 19:45 143,360 --a------ C:\WINDOWS\system32\unzip32.dll
2007-06-03 19:45 <DIR> d-------- C:\Program Files\IceChat7
2007-06-03 19:45 <DIR> d-------- C:\DOCUME~1\Patrick\APPLIC~1\IceChat
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-06-24 15:27:10 -------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-06-24 15:25:30 -------- d-----w C:\Program Files\Symantec
2007-05-24 11:20:54 -------- d-----w C:\Program Files\3DO
2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-14 00:09:23 -------- d-----w C:\Program Files\QuickTime
2007-05-14 00:08:28 -------- d-----w C:\Program Files\Apple Software Update
2007-05-12 17:35:43 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-05-12 13:26:41 -------- d-----w C:\Program Files\Ubisoft
2007-05-08 11:16:43 -------- d-----w C:\Program Files\SlySoft
2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-24 10:50:02 -------- d-----w C:\Program Files\Website Downloader
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-17 02:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-17 02:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 02:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 02:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 02:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 02:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 02:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 02:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-04-07 16:26:43 48,776 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2007-03-30 10:10:55 37,540 ----a-w C:\WINDOWS\system32\Ir32_a.exe
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{1E8A6170-7264-4D0F-BEAE-D42A53123C75}=C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll [2007-01-11 19:04]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll [2005-11-10 14:22]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-02-23 16:45]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 17:41]
"RemoteControl"="C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2003-12-08 17:35]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-10-12 20:29]
"SoundMan"="SOUNDMAN.EXE" [2006-11-17 06:42 C:\WINDOWS\soundman.exe]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 17:59]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2007-01-13 19:11]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^gameutil.exe.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\gameutil.exe.lnk
backup=C:\WINDOWS\pss\gameutil.exe.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
"C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CapFax]
C:\Program Files\Classic PhoneTools\CapFax.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
"C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
C:\Program Files\Ahead\InCD\InCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RedLine Taskbar]
C:\Program Files\RedLine\Taskbar.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
*Newly Created Service* - COMHOST
Contents of the 'Scheduled Tasks' folder
2007-06-13 10:33:01 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
**************************************************************************
catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.netRootkit scan 2007-06-24 11:51:27
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Avg7Core]
"ImagePath"="\SystemRoot\System32\Drivers\avg7core.sys"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Avg7UpdSvc]
"ImagePath"="C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe"
Completion time: 2007-06-24 11:51:49
C:\ComboFix-quarantined-files.txt ... 2007-06-24 11:51
--- E O F ---