YAY! I feel like we're getting somewhere now (?) After all my computer fail-ness. *knock on wood* [Update: the annoying pop ups have stopped..for now (dun dun dun) But my background still has the picture. And i'm still restricted from sites such as nytimes and youtube]
And thank you so much for being so helpful and patient with me!
So you said to include "C:\ComboFix.txt" in this reply.. so:
C:\ComboFix.txt
ComboFix 10-01-28.05 - Owner 8/2010 Thu 23:19:23.1.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.949.82.1033.18.510.174 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
Error: Cfiles.dat
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet Security 2010.lnk
c:\documents and settings\Owner\Application Data\WinAntiSpyware 2006
c:\documents and settings\Owner\Application Data\WinAntiSpyware 2006\Logs\update.log
c:\documents and settings\Owner\Desktop\Internet Security 2010.lnk
c:\documents and settings\Owner\Local Settings\Application Data\{21C43D0E-6DDE-4C1E-8122-610F786C8807}
c:\documents and settings\Owner\Local Settings\Application Data\{21C43D0E-6DDE-4C1E-8122-610F786C8807}\chrome.manifest
c:\documents and settings\Owner\Local Settings\Application Data\{21C43D0E-6DDE-4C1E-8122-610F786C8807}\chrome\content\_cfg.js
c:\documents and settings\Owner\Local Settings\Application Data\{21C43D0E-6DDE-4C1E-8122-610F786C8807}\chrome\content\overlay.xul
c:\documents and settings\Owner\Local Settings\Application Data\{21C43D0E-6DDE-4C1E-8122-610F786C8807}\install.rdf
c:\documents and settings\Owner\Start Menu\Internet Security 2010.lnk
c:\program files\InternetSecurity2010
c:\program files\InternetSecurity2010\IS2010.exe
c:\recycled\NPROTECT
c:\windows\odubereb.dll
c:\windows\system32\11478.exe
c:\windows\system32\15724.exe
c:\windows\system32\16569.exe
c:\windows\system32\18467.exe
c:\windows\system32\19169.exe
c:\windows\system32\23876.exe
c:\windows\system32\25070.exe
c:\windows\system32\26500.exe
c:\windows\system32\26962.exe
c:\windows\system32\29358.exe
c:\windows\system32\32141.exe
c:\windows\system32\3967.exe
c:\windows\system32\41.exe
c:\windows\system32\6334.exe
c:\windows\system32\tmp12.tmp.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_WINDRIVER
——-\Service_WinDriver
((((((((((((((((((((((((( Files Created from 2009-12-28 to 2010-01-29 )))))))))))))))))))))))))))))))
.
2010-01-27 01:00 . 2010-01-27 01:00 ——– d—–w- c:\documents and settings\Owner\Application Data\Malwarebytes
2010-01-27 01:00 . 2010-01-07 21:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-27 01:00 . 2010-01-27 01:00 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-27 01:00 . 2010-01-27 01:00 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-27 01:00 . 2010-01-07 21:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-27 00:15 . 2010-01-28 06:11 0 —-a-w- c:\windows\Hbijemofivut.bin
2010-01-27 00:15 . 2010-01-29 03:06 120 —-a-w- c:\windows\Gqifekesuharucul.dat
2010-01-27 00:12 . 2010-01-28 03:20 25600 —-a-w- c:\windows\system32\helper32.dll
2010-01-27 00:11 . 2010-01-27 00:11 22528 —-a-w- c:\windows\system32\winlogon32.exe
2010-01-27 00:11 . 2010-01-27 00:11 22528 —-a-w- c:\windows\system32\smss32.exe
2009-12-31 15:10 . 2008-09-17 15:07 847360 —-a-w- c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\ld4162cq.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll
2009-12-31 00:42 . 2009-12-31 00:42 144160 —-a-w- c:\documents and settings\Owner\Application Data\Move Networks\uninstall.exe
2009-12-31 00:42 . 2009-12-31 00:42 1440376 —-a-w- c:\documents and settings\Owner\Application Data\Move Networks\MoveMediaPlayerWin_071503000010.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-31 00:42 . 2009-12-10 21:23 4183416 —-a-w- c:\documents and settings\Owner\Application Data\Move Networks\plugins\npqmp071503000010.dll
2009-12-22 05:42 . 2004-08-04 17:00 662016 —-a-w- c:\windows\system32\wininet.dll
2009-12-22 05:42 . 2004-08-04 17:00 81920 —-a-w- c:\windows\system32\ieencode.dll
2009-12-13 02:19 . 2009-12-13 02:19 ——– d—–w- c:\documents and settings\Owner\Application Data\ViiKiiDesktopPlugin.5E22EA0FF243470AB5EDDF282C0A5B52E9909C36.1
2009-12-13 02:18 . 2009-12-13 02:18 ——– d—–w- c:\program files\Common Files\Adobe AIR
2009-12-13 02:13 . 2009-12-13 02:19 38784 —-a-w- c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-12-13 02:13 . 2009-12-13 02:19 38784 —-a-w- c:\documents and settings\Default User\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-12-10 19:27 . 2009-12-10 19:27 97144 —-a-w- c:\documents and settings\Owner\Application Data\Move Networks\ie_bin\MovePlayerUpgrade.exe
2009-11-21 16:36 . 2004-08-04 17:00 470528 —-a-w- c:\windows\AppPatch\AcLayers.dll
2007-02-01 03:09 . 2007-02-01 03:09 5467784 —-a-w- c:\program files\CyStudioSetup.exe
2005-10-13 20:52 . 2005-10-13 20:52 32 –sha-w- c:\windows\{6721F1CE-8C6F-4985-B893-36C2D35B4BE4}.dat
2005-10-13 20:52 . 2005-10-13 20:52 32 –sha-w- c:\windows\system32\{AD77ED27-211A-462D-829F-E0868FD1A131}.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-08-26 15:32 279944 —-a-w- c:\program files\AskBarDis\bar\bin\askBar.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-8087-36EE87E26986}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-08-26 279944]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-08-26 279944]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-10-21 50472]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-23 68856]
"Veoh"="c:\program files\Veoh Networks\Veoh\VeohClient.exe" [2008-02-23 3537968]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-06-22 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-06-22 126976]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_05\bin\jusched.exe" [2005-08-26 36975]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-11-01 32768]
"BigDogPath"="c:\windows\VM_STI.EXE" [2003-01-21 40960]
"EPSON Stylus C88 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIABA.EXE" [2005-01-27 98304]
"IPHSend"="c:\program files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 124520]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-04-03 777424]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-02-29 185896]
"BearShare"="c:\program files\BearShare\BearShare.exe" [2005-09-15 3223552]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
c:\documents and settings\Owner\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
Picture Package VCD Maker.lnk - c:\program files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe [2006-11-8 106496]
Picture Package Menu.lnk - c:\program files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe [2006-11-8 151552]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\MSMSGS.EXE"=
"c:\\Program Files\\Common Files\\AOL\\1138853410\\ee\\AOLServiceHost.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1138853410\\EE\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1138853410\\EE\\aim6.exe"=
"c:\\Program Files\\SunFolder\\sunfolder.exe"=
"c:\\Program Files\\Wizet\\MxCommon\\NGLC_Maple.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\AIM6\\AIM6.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"443:TCP"= 443:TCP:ooVoo TCP 포트 443
"443:UDP"= 443:UDP:ooVoo UDP 포트 443
"37674:TCP"= 37674:TCP:ooVoo TCP 포트 37674
"37674:UDP"= 37674:UDP:ooVoo UDP 포트 37674
"37675:UDP"= 37675:UDP:ooVoo UDP 포트 37675
"57383:TCP"= 57383:TCP:Pando Media Booster
"57383:UDP"= 57383:UDP:Pando Media Booster
"37680:TCP"= 37680:TCP:ooVoo TCP port 37680
"37680:UDP"= 37680:UDP:ooVoo UDP port 37680
"37681:UDP"= 37681:UDP:ooVoo UDP port 37681
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/11/2007 6:51 PM 24652]
S3 cheetah1;cheetah1;\??\c:\documents and settings\Owner\Desktop\ce12\cheetah.sys –> c:\documents and settings\Owner\Desktop\ce12\cheetah.sys [?]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [1/26/2010 8:00 PM 38224]
S3 Mkd2kfNt;Mkd2kfNt;c:\windows\system32\drivers\Mkd2kfNT.sys [8/28/2007 3:06 PM 130816]
S3 Mkd2Usbf;Mkd2Usbf;c:\windows\system32\drivers\Mkd2UsbF.sys [8/28/2007 3:06 PM 93440]
S3 MooseKOPMA;MooseKOPMA;\??\c:\documents and settings\Owner\Desktop\trainer\trainer\MooseKOPMA.sys –> c:\documents and settings\Owner\Desktop\trainer\trainer\MooseKOPMA.sys [?]
S3 WlanUIB;NETGEAR 802.11b USB Driver;c:\windows\system32\drivers\MA111nd5.sys [3/3/2004 4:27 PM 666624]
S3 zenx1;zenx1;\??\c:\documents and settings\Owner\Desktop\ZenxEngine_LATEST\zenx.sys –> c:\documents and settings\Owner\Desktop\ZenxEngine_LATEST\zenx.sys [?]
S4 WinDefend;Windows Defender Service;c:\program files\Windows Defender\MsMpEng.exe [4/3/2006 6:12 PM 14032]
.
Contents of the 'Scheduled Tasks' folder
2010-01-21 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-04-03 23:12]
2010-01-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://google.bearshare.com/
mStart Page = hxxp://www.netian.com/
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &AOL; Toolbar Search - c:\program files\aol\aol toolbar 3.1\resources\en-US\local\search.html
LSP: c:\windows\system32\helper32.dll
DPF: {072039AB-2117-4ED5-A85F-9B9EB903E021} - hxxp://www.clubbox.co.kr/neo.fld/NowStarter.cab
DPF: {2931566C-B8A6-46C5-BF4D-E6AB9251E953} - hxxp://s.nx.com/activex/public_new/nxpm.cab
DPF: {7606693A-C18D-4567-AF85-6194FF70761E} - hxxp://app.ipop.co.kr/gom/GomWeb.cab
DPF: {A1D886C6-4039-4451-97A9-515F5BE5D4C2} - hxxp://ahnlabdownload.nefficient.co.kr/asp/cab/mkdplus.cab
DPF: {A977FF0C-8757-4E76-8533-482F91946233} - hxxp://dl.sayclub.com/sayclub/sayctl/sayax.cab
DPF: {AF11AA64-87A5-4146-AF3B-A7BD0F278485} - hxxp://download.soribada.com/down/Soribada/Setup/20061206/SBStart.CAB
DPF: {E1CDC08F-F464-4682-AE6A-7689451387C0} - hxxp://cafeimg.hanmail.net/activex/dmcm.cab?Version=1,0,0,22
DPF: {E78928A6-3D2A-4BF7-A100-F3FBAA351B49} - hxxps://www.vpay.co.kr/kvpfiles/KVPISPCTLD.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\ld4162cq.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.nytimes.com
FF - plugin: c:\documents and settings\Owner\Application Data\Move Networks\plugins\npqmp071503000010.dll
FF - plugin: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\ld4162cq.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJPI150_05.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Tjolofatahixowet - c:\windows\odubereb.dll
ShellExecuteHooks-{076394AD-7FDD-44EF-A075-32C68DBAB99B} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-28 23:29
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-1390067357-1788223648-725345543-1003\Software\Microsoft\MessengerService\GroupStateCacheU\*?????
"Name"=hex:00,b3,31,c1,5c,ce,6c,ad,e4,b4,00,00
"Collapsed"=hex:00,00,00,00
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'explorer.exe'(3900)
c:\windows\system32\shdoclc.dll
c:\windows\ime\imkr6_1\imekrcic.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\conime.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\AIM6\aolsoftware.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
.
**************************************************************************
.
Completion time: 2010-01-28 23:34:57 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-29 04:34
Pre-Run: 7,266,533,376 bytes free
Post-Run: 10,583,277,568 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - B1C1C2146216ABE4C0DA98F93151FF97