Here's the newest logs:
Logfile of HijackThis v1.99.0
Scan saved at 9:48:10 PM, on 1/17/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINNT\system32\spoolsv.exe
D:\common files\Symantec Shared\ccEvtMgr.exe
D:\common files\Symantec Shared\SNDSrvc.exe
C:\WINNT\Explorer.EXE
D:\common files\Real\Update_OB\evntsvc.exe
D:\common files\Symantec Shared\ccApp.exe
D:\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
D:\WCAT\wcat.exe
C:\Program Files\TGTSoft\StyleXP\StyleXP.exe
D:\Spybot - Search & Destroy\Spybot - Search & Destroy\TeaTimer.exe
C:\Documents and Settings\Duane Berger\Application Data\csoo.exe
C:\Program Files\SpyKiller\spykiller.exe
C:\Program Files\BestPopUpKiller\BestPopupKiller.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
D:\ZoneAlarm\zapro.exe
C:\WINNT\System32\CTsvcCDA.exe
d:\cox anti-spy\app\CurtainsSysSvcNt.exe
D:\NORTON~1\NORTON~2\GHOSTS~2.EXE
D:\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
D:\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\WINNT\System32\devldr32.exe
C:\Program Files\Messenger\msmsgs.exe
D:\AIM95\aim.exe
D:\Firefox\firefox.exe
G:\apps\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AuthBHO.cBHO - {A4D90779-6CB2-4752-83C2-A2AB4D9A672D} - D:\cox anti-spy\app\AuthBHO.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {D714A94F-123A-45CC-8F03-040BCAF82AD6} - C:\WINNT\Downloaded Program Files\SbCIe02a.dll
O3 - Toolbar: (no name) - {B1E741E7-1E77-40D4-9FD8-51949B9CCBD0} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Cox Popup Blocker - {64634180-B0EA-48B6-82B7-9620D33362C1} - D:\cox anti-spy\app\AuthBHO.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [TkBellExe] D:\common files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKLM\..\Run: [ccApp] D:\common files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [GhostStartTrayApp] D:\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
O4 - HKCU\..\Run: [WatchCat] D:\WCAT\wcat.exe
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [AntiPopUp] D:\AntiPopUp\AntiPopUp.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Spybot - Search & Destroy\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SuperAdBlocker] D:\Superadblocker\SAdBlock.exe
O4 - HKCU\..\Run: [Oeas] C:\Documents and Settings\Duane Berger\Application Data\csoo.exe
O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
O4 - HKCU\..\Run: [BestPopUpKiller] C:\Program Files\BestPopUpKiller\BestPopupKiller.exe /startup
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Microsoft Office.lnk = D:\OfficeXP\Office10\OSA.EXE
O4 - Global Startup: strings.exe
O4 - Global Startup: ZoneAlarm Pro.lnk = D:\ZoneAlarm\zapro.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\OfficeXP\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra button: SideStep - {3E230861-5C87-11D3-A1C6-00105A1B41B8} - C:\WINNT\Downloaded Program Files\SbCIe02a.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\AIM95\aim.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .mpg: D:\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .qcp: D:\Internet Explorer\PLUGINS\npqtplugin2.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupdate.microsoft.com/v5co…b?1099505939921
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} -
http://toolbar.google.com/data/en/deleon/1…n/GoogleNav.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) -
http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O23 - Service: Symantec Event Manager - Symantec Corporation - D:\common files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - D:\common files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTsvcCDA.exe
O23 - Service: Curtains for Windows System Service - Authentium, Inc. - d:\cox anti-spy\app\CurtainsSysSvcNt.exe
O23 - Service: GhostStartService - Symantec Corporation - D:\NORTON~1\NORTON~2\GHOSTS~2.EXE
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - D:\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection - Symantec Corporation - D:\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: Super Ad Blocker Service - Unknown - D:\Superadblocker\SABSVC.EXE (file missing)
O23 - Service: ScriptBlocking Service - Symantec Corporation - D:\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - D:\common files\Symantec Shared\SNDSrvc.exe
O23 - Service: STOPzilla Local Service - Unknown - D:\STOPzilla!\szntsvc.exe (file missing)
O23 - Service: StyleXPService - Unknown - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINNT\system32\ZoneLabs\vsmon.exe
————————————————————————————————–\
Warning! This utility will find legitimate files in addition to malware.
Do not remove anything unless you are sure you know what you're doing.
Find.bat is running from: G:\apps\FINDIT2\Find It NT-2K-XP
——- System Files in System32 Directory ——-
Volume in drive C is ROOT
Volume Serial Number is 08F3-2F9B
Directory of C:\WINNT\System32
01/17/2005 01:45 PM dllcache
01/11/2005 06:00 PM 32 {41EBD602-5F8E-488A-89C7-1950C824730A}.dat
01/11/2005 05:42 PM 32 {952E6322-2186-476E-BF6C-4DE176337D26}.dat
01/11/2005 05:40 PM 32 {EE622A92-EDB7-4ED8-8262-F60DC5989714}.dat
01/11/2005 05:40 PM 32 {297DD1DF-C034-423D-B35F-EA4B5587B5BA}.dat
01/11/2005 05:40 PM 32 {1ED60785-7758-4C43-97E0-576BF84B12B0}.dat
01/11/2005 05:37 PM 32 {A3CB91D1-220F-4F6E-90D7-F546D3771778}.dat
6 File(s) 192 bytes
1 Dir(s) 5,698,301,952 bytes free
——- Hidden Files in System32 Directory ——-
Volume in drive C is ROOT
Volume Serial Number is 08F3-2F9B
Directory of C:\WINNT\System32
01/17/2005 01:45 PM dllcache
01/17/2005 01:09 PM 124 vsconfig.xml
01/11/2005 06:00 PM 32 {41EBD602-5F8E-488A-89C7-1950C824730A}.dat
01/11/2005 05:42 PM 32 {952E6322-2186-476E-BF6C-4DE176337D26}.dat
01/11/2005 05:40 PM 32 {EE622A92-EDB7-4ED8-8262-F60DC5989714}.dat
01/11/2005 05:40 PM 32 {297DD1DF-C034-423D-B35F-EA4B5587B5BA}.dat
01/11/2005 05:40 PM 32 {1ED60785-7758-4C43-97E0-576BF84B12B0}.dat
01/11/2005 05:37 PM 32 {A3CB91D1-220F-4F6E-90D7-F546D3771778}.dat
04/13/2003 10:36 PM 4,212 zllictbl.dat
03/05/2003 12:26 AM 488 WindowsLogon.manifest
03/05/2003 12:26 AM 488 logonui.exe.manifest
03/05/2003 12:26 AM 749 sapi.cpl.manifest
03/05/2003 12:26 AM 749 nwc.cpl.manifest
03/05/2003 12:26 AM 749 cdplayer.exe.manifest
03/05/2003 12:26 AM 749 wuaucpl.cpl.manifest
03/05/2003 12:26 AM 749 ncpa.cpl.manifest
03/06/2002 06:29 PM GroupPolicy
03/06/2002 06:23 PM 21,692 folder.htt
16 File(s) 30,941 bytes
2 Dir(s) 5,698,297,856 bytes free
———— Files Named "Guard" —————
Volume in drive C is ROOT
Volume Serial Number is 08F3-2F9B
Directory of C:\WINNT\System32
—— Temp Files in System32 Directory ——
Volume in drive C is ROOT
Volume Serial Number is 08F3-2F9B
Directory of C:\WINNT\System32
09/23/2002 03:10 PM 544,256 SET1B.tmp
12/07/1999 06:00 AM 2,577 CONFIG.TMP
05/07/1999 01:00 AM 140,288 ~GLH0005.TMP
05/05/1999 09:22 PM 63,760 mpg2splt.ax.tmp
08/09/1998 07:07 AM 118,784 ~GLH000d.TMP
5 File(s) 869,665 bytes
0 Dir(s) 5,698,297,856 bytes free
—————— User Agent —————-
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{48F6B995-E9BE-41DA-AEA9-7F63F27EEE59}"=""
————- Keys Under Notify ————-
REGEDIT4
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,33,32,2e,64,6c,6c,00
"Logoff"="ChainWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,6e,65,74,2e,64,6c,6c,00
"Logoff"="CryptnetWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\MCD]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINNT\\system32\\ir04l5dq1.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,63,6c,67,6e,74,66,79,2e,64,6c,6c,00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
————- Locate.com Results ————-
C:\WINNT\SYSTEM32\
vsconfig.xml Mon Jan 17 2005 1:09:24p A..H. 124 0.12 K
{1ed60~1.dat Tue Jan 11 2005 5:40:56p A.SH. 32 0.03 K
{297dd~1.dat Tue Jan 11 2005 5:40:56p A.SH. 32 0.03 K
{41ebd~1.dat Tue Jan 11 2005 6:00:42p A.SH. 32 0.03 K
{952e6~1.dat Tue Jan 11 2005 5:42:48p A.SH. 32 0.03 K
{a3cb9~1.dat Tue Jan 11 2005 5:37:42p A.SH. 32 0.03 K
{ee622~1.dat Tue Jan 11 2005 5:40:56p A.SH. 32 0.03 K
7 items found: 7 files, 0 directories.
Total of file sizes: 316 bytes 0.31 K
——– Strings.exe Qoologic Results ——–
——— Strings.exe Aspack Results ———
————– HKLM Run Key —————-
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="D:\\common files\\Real\\Update_OB\\evntsvc.exe -osboot"
"ccApp"="D:\\common files\\Symantec Shared\\ccApp.exe"
"GhostStartTrayApp"="D:\\Norton SystemWorks\\Norton Ghost\\GhostStartTrayApp.exe"