This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Internet being used by something

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am having a problem with internet usage. Something is using my internet connection and I can not figure it out. It is making my access almost unusable. :rant2: I have followed steps for removal using zone alarm, stinger, Ewido, Spybot, Adaware, CWShredder, and VX2 cleaner. I also installled Netlimiter2 to track what is using my connection but I am still at a loss.

Ewido finds the oikafo.exe everytime I reboot. I always tell it to clean but it keeps re-appearing. When I use Zone Alarm to restrict certain prcesses from accessing the internet, I end up with the NT Authority/system shutting down error. :( Any advice would be greatly appreciated.

Here is my hijackthis log

————————————-

Logfile of HijackThis v1.99.1
Scan saved at 8:31:44 AM, on 8/19/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\oikafo.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\erbef.exe
C:\WINDOWS\system32\erbef.exe
C:\WINDOWS\system32\erbef.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\Program Files\NetLimiter 2 Monitor\nlsvc.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\M-Audio Uno\UnoInst.exe
C:\Program Files\NetLimiter 2 Monitor\NLClient.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
C:\WINDOWS\Twain_32\FlatBed\HotKey.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\system32\hphmon06.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\AGRSMMSG.exe
c:\windows\system\hpsysdrv.exe
C:\Documents and Settings\HP_Administrator\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://owa.cliu.org/exchweb/logon.asp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\erbef.exe
F2 - REG:system.ini: UserInit=userinit.exe,pniipub.exe
N3 - Netscape 7: user_pref("browser.startup.homepage", "http:/www.google.com"); (C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Profiles\default\m3chy5b2.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Profiles\default\m3chy5b2.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [AdobeVersionCue] C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
O4 - HKLM\..\Run: [HotKey] C:\WINDOWS\Twain_32\FlatBed\HotKey.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [InstantAccess] C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE /h
O4 - HKLM\..\Run: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
O4 - HKLM\..\Run: [naorem] C:\WINDOWS\system32\oikafo.exe reg_run
O4 - HKLM\..\Run: [newname] C:\\nwnmfg_7.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe" -start
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\RunServices: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [mfc71enu] C:\WINDOWS\system32\mfc71enu.exe
O4 - HKCU\..\Run: [kwvsg] C:\WINDOWS\system32\oikafo.exe reg_run
O4 - HKCU\..\Run: [CAS2] "C:\Program Files\System Files\System.exe"
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5AA5A569-F96F-4628-A528-8B3698F558BB} (HS_live Control) - http://install.homestead.com/~site/Install…ive/HS_live.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe
O23 - Service: apcups.exe - Unknown owner - C:\WINDOWS\system32\apcups.exe
O23 - Service: CWShredder Service - Unknown owner - C:\Program Files\InterMute\SpySubtract\CWShredder.exe (file missing)
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: icwdial.exe - Unknown owner - C:\WINDOWS\system32\icwdial.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MSSQL$MICROSOFTSMLBIZ - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe" -sMICROSOFTSMLBIZ (file missing)
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe (file missing)
O23 - Service: NetLimiter (nlsvc) - Locktime Software - C:\Program Files\NetLimiter 2 Monitor\nlsvc.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SQLAgent$MICROSOFTSMLBIZ - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlagent.EXE" -i MICROSOFTSMLBIZ (file missing)
O23 - Service: Uno Installer (UnoInstallerService) - Unknown owner - C:\Program Files\M-Audio Uno\UnoInst.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Welcome !! Please take note of the following while we are working together:
  • Your fix may take a couple posts so please be patient even if you don't see immediate results.
  • I will working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine is clear. Absence of symptoms does not mean that everything is clear.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's definitely better to be sure and safe than sorry.
***************************************

1. Download combofix.exe by sUBs and save it to your desktop.
2. <> combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Warning: Please do not mouseclick combofix's window while it is running. This may cause it to stall.

Open HijackThis, click Config, click Misc Tools
Click "Open Uninstall Manager"
Click "Save List" (generates uninstall_list.txt)
Click Save, copy and paste the results in your next post.

In your next post, please include
  • new hijackthis log
  • combofix log
  • uninstall list
*use separate posts to ensure the logs don't get cut off!

*************************
Hello agrarianmonk!

Thank you for helping me. I ran the combofix.exe and will now run highjackThis
I will post results seperatly as you sugggested.
Below is the log from combofix

———————————–


((((((((((((((((((((((((((((((((((((((((((((( Qoologic's Log )))))))))))))))))))))))))))))))))))))))))))))))))))


* * * PRE-RUN - Filepaths extracted from the Registry * * * * * * * * * * * * * * * * * * * * * *


F2 -REG:system.ini: UserInit C:\WINDOWS\system32\pniipub.exe


* * * PRE-RUN - Filepaths from Locate * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


2006-08-20 09:24 325 –a—— C:\WINDOWS\mdqhv.dll
2006-08-16 17:05 127488 –a—— C:\WINDOWS\system32\tgydq.dat
2006-08-04 11:37 73728 –a—— C:\WINDOWS\system32\dpl100.dll
2006-08-04 11:37 196608 –a—— C:\WINDOWS\system32\dtu100.dll
2006-07-28 11:30 53 –a—— C:\WINDOWS\vwbqol.dat
2006-07-21 04:24 72704 –a—— C:\WINDOWS\system32\hlink.dll
2006-06-21 06:43 520192 –a—— C:\WINDOWS\system32\DivXsm.exe
2006-06-21 06:42 200704 –a—— C:\WINDOWS\system32\ssldivx.dll
2006-06-21 06:42 1044480 –a—— C:\WINDOWS\system32\libdivx.dll
2006-06-21 06:34 57344 –a—— C:\WINDOWS\system32\dpv11.dll
2006-06-21 06:34 344064 –a—— C:\WINDOWS\system32\dpus11.dll
2006-06-21 06:34 294912 –a—— C:\WINDOWS\system32\dpu11.dll
2006-06-21 06:34 294912 –a—— C:\WINDOWS\system32\dpu10.dll


* * * POST-RUN - Files in the Quarantine folder * * * * * * * * * * * * * * * * * * * * * * * * *


06-08-16 17:05 127488 tgydq.dat.qoo
06-08-20 09:24 325 mdqhv.dll.qoo
06-07-28 11:30 53 vwbqol.dat.qoo

DO NOT DELETE ANY FILES FROM THIS DIRECTORY UNLESS INSTRUCTED TO


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\newname.dat
C:\kybrdfg_7.exe
C:\WINDOWS\system32\icon_mediamotor.exe
C:\WINDOWS\system32\ts_mediamotor.exe
C:\WINDOWS\uninstall_nmon.vbs
C:\Documents and Settings\LocalService\Application Data\NetMon


((((((((((((((((((((((((((((((( Files Created from 2006-07-20 to 2006-08-20 ))))))))))))))))))))))))))))))))))


2006-08-16 17:05 23,552 C:\WINDOWS\system32\pniipub.exe
2006-08-11 18:14 32,976 C:\WINDOWS\system32\uninstIcn.exe
2006-08-11 18:13 16,384 C:\WINDOWS\system32\loadadv559.exe
2006-08-11 18:13 14,336 C:\WINDOWS\system32\test.exe
2006-08-04 11:37 196,608 C:\WINDOWS\system32\dtu100.dll
2006-07-28 09:29 0 C:\WINDOWS\system32ghynf.exe


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))

Rootkit driver pe386 is present. A rootkit scan is required

2006-08-19 18:53 ——– d——– C:\Program Files\Mozilla Firefox
2006-08-19 08:09 ——– d——– C:\Program Files\ewido anti-spyware 4.0
2006-08-18 07:33 ——– d——– C:\Documents and Settings\HP_Administrator\Application Data\Locktime
2006-08-16 17:36 ——– d——– C:\Program Files\NetLimiter 2 Monitor
2006-08-16 17:34 ——– d——– C:\Program Files\Zone Labs
2006-08-16 17:05 23552 –a—— C:\WINDOWS\system32\pniipub.exe
2006-08-15 09:04 ——– d——– C:\Program Files\Audacity
2006-08-13 21:07 ——– d——– C:\Documents and Settings\HP_Administrator\Application Data\Adobe
2006-08-13 14:09 ——– d——– C:\Program Files\VideoraiPodConverter
2006-08-13 14:09 ——– d——– C:\Program Files\PSP ToolKit
2006-08-13 13:46 ——– d—s—- C:\Documents and Settings\HP_Administrator\Application Data\Microsoft
2006-08-13 13:45 ——– d——– C:\Program Files\Photo Story 3 for Windows
2006-08-13 09:09 ——– d——– C:\Program Files\Common Files\fiqo
2006-08-13 07:18 ——– d——– C:\Program Files\Common Files
2006-08-12 21:19 16384 –a—— C:\WINDOWS\system32\loadadv559.exe
2006-08-12 21:17 14336 –a—— C:\WINDOWS\system32\test.exe
2006-08-12 00:44 ——– d——– C:\Documents and Settings\HP_Administrator\Application Data\Lavasoft
2006-08-11 23:41 ——– d——– C:\Program Files\Lavasoft
2006-08-11 23:10 ——– d–h—– C:\Program Files\InstallShield Installation Information
2006-08-11 23:02 ——– d——– C:\Program Files\SP
2006-08-11 23:00 ——– d——– C:\Program Files\Windows Media Connect 2
2006-08-11 18:29 ——– d——– C:\Program Files\Internet Explorer
2006-08-11 18:14 32976 –a—— C:\WINDOWS\system32\uninstIcn.exe
2006-08-11 12:36 ——– d——– C:\Program Files\DivX
2006-08-04 11:37 73728 –a—— C:\WINDOWS\system32\dpl100.dll
2006-08-04 11:37 196608 –a—— C:\WINDOWS\system32\dtu100.dll
2006-07-30 15:27 ——– d——– C:\Program Files\Panicware
2006-07-29 09:20 ——– d——– C:\Program Files\ComPlus Applications
2006-07-29 08:30 ——– d——– C:\Program Files\Spyware Doctor
2006-07-28 11:29 ——– d——– C:\Program Files\Messenger
2006-07-28 09:29 0 –a—— C:\WINDOWS\system32ghynf.exe
2006-07-27 09:24 679424 –a—— C:\WINDOWS\system32\inetcomm.dll
2006-07-26 22:05 3596288 –a—— C:\WINDOWS\system32\qt-dx331.dll
2006-07-21 04:24 72704 –a—— C:\WINDOWS\system32\hlink.dll
2006-07-18 18:04 6236 –a—— C:\Documents and Settings\HP_Administrator\Application Data\GdiplusUpgrade_MSIApproach_Wrapper.log
2006-07-16 17:18 ——– d——– C:\Program Files\Motorola Phone Tools
2006-07-16 17:17 22768 –a—— C:\WINDOWS\system32\drivers\usbsermpt.sys
2006-07-16 17:16 ——– d——– C:\Program Files\LiveUpdate
2006-07-03 17:40 778240 –a—— C:\WINDOWS\system32\divx_xx0c.dll
2006-07-03 17:40 778240 –a—— C:\WINDOWS\system32\divx_xx07.dll
2006-07-03 17:40 761856 –a—— C:\WINDOWS\system32\divx_xx11.dll
2006-07-03 17:40 620180 –a—— C:\WINDOWS\system32\DivX.dll
2006-06-30 07:36 ——– d——– C:\Program Files\Common Files\Scanner
2006-06-30 07:35 ——– d——– C:\Documents and Settings\HP_Administrator\Application Data\Netscape
2006-06-30 07:34 ——– d——– C:\Program Files\Netscape
2006-06-29 09:15 ——– d——– C:\Program Files\Vortex
2006-06-28 15:01 118784 –a—— C:\WINDOWS\dsdxirmv.exe
2006-06-28 14:59 ——– d——– C:\Program Files\Cakewalk
2006-06-28 14:14 ——– d——– C:\Documents and Settings\HP_Administrator\Application Data\Identities
2006-06-28 14:14 ——– d——– C:\Documents and Settings\HP_Administrator\Application Data\Cakewalk
2006-06-23 07:28 ——– d——– C:\Program Files\Windows Media Player
2006-06-21 15:44 20640 ——— C:\WINDOWS\system32\drivers\pxhelp20.sys
2006-06-21 15:44 109568 ——— C:\WINDOWS\system32\pxinsi64.exe
2006-06-21 06:49 53248 –a—— C:\WINDOWS\system32\dpuGUI10.dll
2006-06-21 06:43 520192 –a—— C:\WINDOWS\system32\DivXsm.exe
2006-06-21 06:42 200704 –a—— C:\WINDOWS\system32\ssldivx.dll
2006-06-21 06:42 1044480 –a—— C:\WINDOWS\system32\libdivx.dll
2006-06-21 06:34 593920 –a—— C:\WINDOWS\system32\dpuGUI11.dll
2006-06-21 06:34 57344 –a—— C:\WINDOWS\system32\dpv11.dll
2006-06-21 06:34 344064 –a—— C:\WINDOWS\system32\dpus11.dll
2006-06-21 06:34 294912 –a—— C:\WINDOWS\system32\dpu11.dll
2006-06-21 06:34 294912 –a—— C:\WINDOWS\system32\dpu10.dll
2006-06-21 06:33 12288 –a—— C:\WINDOWS\system32\DivXWMPExtType.dll
2006-06-21 06:33 118784 –a—— C:\WINDOWS\system32\DivXCodecUpdateChecker.exe
2006-06-20 18:48 ——– d——– C:\Program Files\Common Files\ScanSoft Shared
2006-06-20 18:08 ——– d——– C:\Program Files\TextBridge Pro 9.0
2006-06-20 15:17 ——– d——– C:\Program Files\PowerTracks DirectX Plugins
2006-06-20 14:33 ——– d——– C:\Program Files\Alfred Interactive
2006-06-20 13:43 ——– d——– C:\Program Files\Harmonic Vision
2006-06-20 13:25 ——– d——– C:\Program Files\Sibelius Software
2006-06-20 13:18 ——– d——– C:\Program Files\Rising Software
2006-06-20 13:05 53065 –a—— C:\Program Files\uninstal.log
2006-06-20 11:28 ——– d——– C:\Documents and Settings\HP_Administrator\Application Data\Sibelius Software
2006-06-20 10:58 ——– d——– C:\Program Files\Common Files\Borland Shared
2006-06-20 10:18 ——– d——– C:\Program Files\Neuratron PhotoScore
2006-06-20 10:18 ——– d——– C:\Documents and Settings\HP_Administrator\Application Data\Neuratron
2006-06-20 10:12 604 –ah—– C:\Program Files\STLL Notifier
2006-06-20 10:04 ——– d——– C:\Program Files\Native Instruments


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\\WINDOWS\\ehome\\ehtray.exe"
"HotKeysCmds"="C:\\WINDOWS\\system32\\hkcmd.exe"
"Persistence"="C:\\WINDOWS\\system32\\igfxpers.exe"
"HPBootOp"="\"C:\\Program Files\\Hewlett-Packard\\HP Boot Optimizer\\HPBootOp.exe\" /run"
"LSBWatcher"="c:\\hp\\drivers\\hplsbwatcher\\lsburnwatcher.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"HPDJ Taskbar Utility"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\hpztsb04.exe"
"vptray"="C:\\PROGRA~1\\SYMANT~1\\SYMANT~1\\vptray.exe"
"AdobeVersionCue"="C:\\Program Files\\Adobe\\Adobe Version Cue\\ControlPanel\\VersionCueTray.exe"
"HotKey"="C:\\WINDOWS\\Twain_32\\FlatBed\\HotKey.exe"
"HP Software Update"="C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"RTHDCPL"="RTHDCPL.EXE"
"Alcmtr"="ALCMTR.EXE"
"InstantAccess"="C:\\PROGRA~1\\TEXTBR~1.0\\Bin\\INSTAN~1.EXE /h"
"RegisterDropHandler"="C:\\PROGRA~1\\TEXTBR~1.0\\Bin\\REGIST~1.EXE"
"ISUSPM Startup"="C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\UPDATE~1\\ISUSPM.exe -startup"
"ISUSScheduler"="\"C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\UPDATE~1\\issch.exe\" -start"
"!ewido"="\"C:\\Program Files\\ewido anti-spyware 4.0\\ewido.exe\" /minimized"
"Zone Labs Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
"HPHmon06"="C:\\WINDOWS\\system32\\hphmon06.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"mfc71enu"="C:\\WINDOWS\\system32\\mfc71enu.exe"
"PopUpStopperFreeEdition"="\"C:\\PROGRA~1\\PANICW~1\\POP-UP~1\\PSFree.exe\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Runservices]
"RegisterDropHandler"="C:\\PROGRA~1\\TEXTBR~1.0\\Bin\\REGIST~1.EXE"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"InstallVisualStyle"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,\
63,65,73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,5c,52,6f,79,61,6c,65,2e,\
6d,73,73,74,79,6c,65,73,00
"InstallTheme"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,63,65,\
73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,2e,74,68,65,6d,65,00

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"NoActiveDesktop"=dword:00000000
"ForceActiveDesktopOn"=dword:00000001
"NoActiveDesktopChanges"=hex:00,00,00,00
"NoSaveSettings"=dword:00000000
"NoThemesTab"=dword:00000000

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"NoDispAppearancePage"=dword:00000000
"NoColorChoice"=dword:00000000
"NoSizeChoice"=dword:00000000
"NoDispBackgroundPage"=dword:00000000
"NoDispScrSavPage"=dword:00000000
"NoDispCPL"=dword:00000000
"NoVisualStyleChoice"=dword:00000000
"NoDispSettingsPage"=dword:00000000

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,4e,00,00,00,00,00,00,00,b2,03,00,00,e2,02,\
00,00,04,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,4e,00,00,00,00,00,00,00,b2,03,00,00,e2,02,\
00,00,01,00,00,00

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"



Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Symantec NetDetect.job

Completion time: Sun 08/20/2006 9:35:55.79
ComboFix.txt
Here is the uninstall list! ——————————- Ad-Aware SE Personal Adobe Acrobat - Reader 6.0.2 Update Adobe Acrobat 6.0.1 Professional Adobe Acrobat and Reader 6.0.3 Update Adobe Acrobat and Reader 6.0.4 Update Adobe Acrobat and Reader 6.0.5 Update Adobe Atmosphere Player for Acrobat and Adobe Reader Adobe Creative Suite Adobe SVG Viewer 3.0 Agere Systems PCI Soft Modem Audacity 1.2.4 Auralia 3 Avanquest update AviSynth 2.5 Band-in-a-Box 2006 Binary Vortex v2.6 Blasterball 2 from HP Media Center (remove only) Blasterball 2 Holidays from HP Media Center (remove only) Blasterball 2 Remix from HP Media Center (remove only) Bounce Symphony from HP Media Center (remove only) Cakewalk Audio Finder Tool Cakewalk VST Adapter [removed] Cakewalk VST Adapter [removed] CoolCam Camera Suite Crystal Maze from HP Media Center (remove only) Digital Media Converter 2.62 DivX DivX Converter DivX Player DivX Web Player DreamStation DXi DreamStation DXi2 Easy Internet Sign-up ewido anti-spyware 4.0 Final Drive Nitro from HP Media Center (remove only) First Step Guide Forethought GdiplusUpgrade GemMaster Mystic GPL Ghostscript 8.15 GPL Ghostscript Fonts Help and Support Additions High Definition Audio Driver Package - KB888111 HighMAT Extension to Microsoft Windows XP CD Writing Wizard HijackThis 1.99.1 Homestead SiteBuilder Homestead SiteBuilder LPX Hotfix for Windows Media Player 10 (KB903157) Hotfix for Windows Media Player 10 (KB910393) Hotfix for Windows XP (KB888795) Hotfix for Windows XP (KB891593) Hotfix for Windows XP (KB895961) Hotfix for Windows XP (KB896344) Hotfix for Windows XP (KB899337) Hotfix for Windows XP (KB899510) Hotfix for Windows XP (KB902841) Hotfix for Windows XP (KB912024) Hoyle Classic Games HP Boot Optimizer hp deskjet 930c series (Remove only) HP Deskjet Printer Preload HP Image Zone 4.8.6 HP Image Zone Express HP Image Zone for Media Center PC HP Image Zone Plus 4.8.6 HP Photosmart Cameras 4.5 HP PSC & OfficeJet 4.7 HP Software Update HP Tunes HPIZplus450 Icons ImageMixer VCD2 Intel® Graphics Media Accelerator Driver Intel® PRO Network Connections Drivers InterVideo WinDVD Player iPod for Windows 2006-01-10 iTunes J2SE Runtime Environment 5.0 J2SE Runtime Environment 5.0 Update 4 J2SE Runtime Environment 5.0 Update 6 Java 2 Runtime Environment, SE v1.4.1_02 Java Web Start KBD Lexibox Deluxe from HP Media Center (remove only) LiveUpdate 1.7 (Symantec Corporation) Macromedia Dreamweaver MX Macromedia Extension Manager Macromedia Flash Player 8 Macromedia Shockwave Player Microsoft .NET Framework 1.0 Hotfix (KB887998) Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB886903) Microsoft .NET Framework 2.0 Microsoft Base Smart Card Cryptographic Service Provider Package Microsoft Office Outlook 2003 with Business Contact Manager Update Microsoft Office Professional Edition 2003 Microsoft Office XP Media Content Microsoft Office XP Pro Step by Step Interactive Microsoft Office XP Professional with FrontPage Microsoft Plus! Dancer LE Microsoft Plus! Digital Media Edition Installer Microsoft Plus! Photo Story 2 LE Microsoft SQL Server Desktop Engine (MICROSOFTSMLBIZ) Microsoft User-Mode Driver Framework Feature Pack 1.0.0 (Pre-Release 5348) Microsoft Works Motorola Phone Tools Mozilla Firefox (1.5.0.6) Mpeg2Decoder 1.1 MSN Music Assistant Music Ace Maestro Musition 2 muvee autoProducer 4.0 muvee autoProducer unPlugged - HPD Native Instruments Sibelius Player NetLimiter 2 Monitor (remove only) Netscape (7.2) Netscape Browser (remove only) Neuratron PhotoScore Otto Overball from HP Media Center (remove only) PC-Doctor for Windows PG Music DirectX Plugins [removed] Phoenix Assault from HP Media Center (remove only) Photo Story 3 for Windows Photosmart 320,370,7400,8100,8400 Series Picture Package Polar Bowler from HP Media Center (remove only) Polar Golfer from HP Media Center (remove only) Pop-Up Stopper Free Edition PowerTalk 1.2.2 PS2 PSP Toolkit 1.1 Python 2.2 pywin32 extensions (build 203) Python 2.2.3 Quicklinks QuickTime RealPlayer Realtek High Definition Audio Driver Security Update for Microsoft .NET Framework 2.0 (KB917283) Security Update for Step By Step Interactive Training (KB898458) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows XP (KB883939) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893066) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896422) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB896688) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899588) Security Update for Windows XP (KB899589) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB903235) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB905915) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB908531) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911567) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912812) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913446) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB916281) Security Update for Windows XP (KB917159) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB918899) Security Update for Windows XP (KB920214) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB921398) Security Update for Windows XP (KB921883) Security Update for Windows XP (KB922616) Shooting Stars Pool from HP Media Center (remove only) Sibelius 4 Sibelius Compass Sibelius Groovy Shapes Sibelius Instruments Sierra Utilities SlowView 0.9.9.5 Slyder from HP Media Center (remove only) Snood for Windows version 3.01-W SONAR 5 Producer Edition SONAR Home Studio 4 Sonic Encoders Sonic Express Labeler Sonic MyDVD Plus Sonic RecordNow Audio Sonic RecordNow Copy Sonic RecordNow Data Sonic Update Manager Sony USB Driver Spybot - Search & Destroy 1.2 Spyware Doctor 3.2 Starclass Super Granny from HP Media Center (remove only) Symantec AntiVirus Client TextBridge Pro 9.0 Tradewinds from HP Media Center (remove only) Ulead Photo Express 4.0 SE Uno Update for Windows Media Player 10 (KB913800) Update for Windows XP (KB894391) Update for Windows XP (KB896727) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB900930) Update for Windows XP (KB904942) Update for Windows XP (KB910437) Update for Windows XP (KB911280) Update for Windows XP (KB916595) Update Rollup 2 for Windows XP Media Center Edition 2005 Updates from HP USB Scanner VeloMaster Lite CW Videora iPod Converter 0.91 Virtual Sound Canvas DXi Windows Genuine Advantage v1.3.0254.0 Windows Installer 3.1 (KB893803) Windows Media Connect Windows Media Format 11 runtime Windows Media Format 11 runtime Windows Media Player 10 Hotfix [See KB889858 for more information] Windows Media Player 11 Windows Media Player 11 Windows XP Hotfix - KB867282 Windows XP Hotfix - KB873333 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB883667 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885354 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB885884 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB887742 Windows XP Hotfix - KB887797 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890175 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891220 Windows XP Hotfix - KB891781 Windows XP Hotfix - KB893086 Windows XP Media Center Edition 2005 KB888316 Windows XP Media Center Edition 2005 KB895678 Windows XP Media Center Edition 2005 KB914548 ZoneAlarm
And here is the new HighjackThis log

BTW, after running combofix, Ewido did not find the oikafo.exe problem on reboot!

————————-

Logfile of HijackThis v1.99.1
Scan saved at 9:54:39 AM, on 8/20/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\Program Files\NetLimiter 2 Monitor\nlsvc.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\M-Audio Uno\UnoInst.exe
C:\Program Files\NetLimiter 2 Monitor\NLClient.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\igfxpers.exe
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
C:\WINDOWS\Twain_32\FlatBed\HotKey.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\system32\hphmon06.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\AGRSMMSG.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\Netscape\Netscape\Netscp.exe
C:\Documents and Settings\HP_Administrator\Desktop\hijackthis\HijackThis.exe
C:\WINDOWS\system32\notepad.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://owa.cliu.org/exchweb/logon.asp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R3 - Default URLSearchHook is missing
N3 - Netscape 7: user_pref("browser.startup.homepage", "http:/www.google.com"); (C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Profiles\default\m3chy5b2.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Profiles\default\m3chy5b2.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [AdobeVersionCue] C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
O4 - HKLM\..\Run: [HotKey] C:\WINDOWS\Twain_32\FlatBed\HotKey.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [InstantAccess] C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE /h
O4 - HKLM\..\Run: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe" -start
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\RunServices: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [mfc71enu] C:\WINDOWS\system32\mfc71enu.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5AA5A569-F96F-4628-A528-8B3698F558BB} (HS_live Control) - http://install.homestead.com/~site/Install…ive/HS_live.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe
O23 - Service: apcups.exe - Unknown owner - C:\WINDOWS\system32\apcups.exe
O23 - Service: CWShredder Service - Unknown owner - C:\Program Files\InterMute\SpySubtract\CWShredder.exe (file missing)
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: icwdial.exe - Unknown owner - C:\WINDOWS\system32\icwdial.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MSSQL$MICROSOFTSMLBIZ - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe" -sMICROSOFTSMLBIZ (file missing)
O23 - Service: NetLimiter (nlsvc) - Locktime Software - C:\Program Files\NetLimiter 2 Monitor\nlsvc.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SQLAgent$MICROSOFTSMLBIZ - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlagent.EXE" -i MICROSOFTSMLBIZ (file missing)
O23 - Service: Uno Installer (UnoInstallerService) - Unknown owner - C:\Program Files\M-Audio Uno\UnoInst.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
looks like you have pe386 mailbot rootkit; let's remove it before doing anything else.

Rookitrevealer

Please download Rootkit Revealer (link is at the very bottom of the page)
  • Unzip it to your desktop.
  • Open the rootkitrevealer folder and double-click rootkitrevealer.exe
  • Click the Scan button (bottom right)
  • While RootkitRevealer is scanning, shutdown your computer. This is important because the rootkit removes itself from your computer while the rootkit scanner is scanning to avoid detection, but once the scan stops, the rootkit reinstalls itself. Shutting your computer down during scanning will prevent the rootkit from reinstalling itself.
  • afterwards, turn on your computer, and please post another combofix log
thanks,
thanks agrarianmonk!!

here is the new combofix log

——————


((((((((((((((((((((((((((((((( Files Created from 2006-07-20 to 2006-08-20 ))))))))))))))))))))))))))))))))))


2006-08-16 17:05 23,552 C:\WINDOWS\system32\pniipub.exe
2006-08-11 18:14 32,976 C:\WINDOWS\system32\uninstIcn.exe
2006-08-11 18:13 16,384 C:\WINDOWS\system32\loadadv559.exe
2006-08-11 18:13 14,336 C:\WINDOWS\system32\test.exe
2006-08-04 11:37 196,608 C:\WINDOWS\system32\dtu100.dll
2006-07-28 09:29 0 C:\WINDOWS\system32ghynf.exe


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))

Rootkit driver pe386 is present. A rootkit scan is required

2006-08-20 09:50 ——– d——– C:\Program Files\SP
2006-08-19 18:53 ——– d——– C:\Program Files\Mozilla Firefox
2006-08-19 08:09 ——– d——– C:\Program Files\ewido anti-spyware 4.0
2006-08-18 07:33 ——– d——– C:\Documents and Settings\HP_Administrator\Application Data\Locktime
2006-08-16 17:36 ——– d——– C:\Program Files\NetLimiter 2 Monitor
2006-08-16 17:34 ——– d——– C:\Program Files\Zone Labs
2006-08-16 17:05 23552 –a—— C:\WINDOWS\system32\pniipub.exe
2006-08-15 09:04 ——– d——– C:\Program Files\Audacity
2006-08-13 21:07 ——– d——– C:\Documents and Settings\HP_Administrator\Application Data\Adobe
2006-08-13 14:09 ——– d——– C:\Program Files\VideoraiPodConverter
2006-08-13 14:09 ——– d——– C:\Program Files\PSP ToolKit
2006-08-13 13:46 ——– d—s—- C:\Documents and Settings\HP_Administrator\Application Data\Microsoft
2006-08-13 13:45 ——– d——– C:\Program Files\Photo Story 3 for Windows
2006-08-13 09:09 ——– d——– C:\Program Files\Common Files\fiqo
2006-08-13 07:18 ——– d——– C:\Program Files\Common Files
2006-08-12 21:19 16384 –a—— C:\WINDOWS\system32\loadadv559.exe
2006-08-12 21:17 14336 –a—— C:\WINDOWS\system32\test.exe
2006-08-12 00:44 ——– d——– C:\Documents and Settings\HP_Administrator\Application Data\Lavasoft
2006-08-11 23:41 ——– d——– C:\Program Files\Lavasoft
2006-08-11 23:10 ——– d–h—– C:\Program Files\InstallShield Installation Information
2006-08-11 23:00 ——– d——– C:\Program Files\Windows Media Connect 2
2006-08-11 18:29 ——– d——– C:\Program Files\Internet Explorer
2006-08-11 18:14 32976 –a—— C:\WINDOWS\system32\uninstIcn.exe
2006-08-11 12:36 ——– d——– C:\Program Files\DivX
2006-08-04 11:37 73728 –a—— C:\WINDOWS\system32\dpl100.dll
2006-08-04 11:37 196608 –a—— C:\WINDOWS\system32\dtu100.dll
2006-07-30 15:27 ——– d——– C:\Program Files\Panicware
2006-07-29 09:20 ——– d——– C:\Program Files\ComPlus Applications
2006-07-29 08:30 ——– d——– C:\Program Files\Spyware Doctor
2006-07-28 11:29 ——– d——– C:\Program Files\Messenger
2006-07-28 09:29 0 –a—— C:\WINDOWS\system32ghynf.exe
2006-07-27 09:24 679424 –a—— C:\WINDOWS\system32\inetcomm.dll
2006-07-26 22:05 3596288 –a—— C:\WINDOWS\system32\qt-dx331.dll
2006-07-21 04:24 72704 –a—— C:\WINDOWS\system32\hlink.dll
2006-07-18 18:04 6236 –a—— C:\Documents and Settings\HP_Administrator\Application Data\GdiplusUpgrade_MSIApproach_Wrapper.log
2006-07-16 17:18 ——– d——– C:\Program Files\Motorola Phone Tools
2006-07-16 17:17 22768 –a—— C:\WINDOWS\system32\drivers\usbsermpt.sys
2006-07-16 17:16 ——– d——– C:\Program Files\LiveUpdate
2006-07-03 17:40 778240 –a—— C:\WINDOWS\system32\divx_xx0c.dll
2006-07-03 17:40 778240 –a—— C:\WINDOWS\system32\divx_xx07.dll
2006-07-03 17:40 761856 –a—— C:\WINDOWS\system32\divx_xx11.dll
2006-07-03 17:40 620180 –a—— C:\WINDOWS\system32\DivX.dll
2006-06-30 07:36 ——– d——– C:\Program Files\Common Files\Scanner
2006-06-30 07:35 ——– d——– C:\Documents and Settings\HP_Administrator\Application Data\Netscape
2006-06-30 07:34 ——– d——– C:\Program Files\Netscape
2006-06-29 09:15 ——– d——– C:\Program Files\Vortex
2006-06-28 15:01 118784 –a—— C:\WINDOWS\dsdxirmv.exe
2006-06-28 14:59 ——– d——– C:\Program Files\Cakewalk
2006-06-28 14:14 ——– d——– C:\Documents and Settings\HP_Administrator\Application Data\Identities
2006-06-28 14:14 ——– d——– C:\Documents and Settings\HP_Administrator\Application Data\Cakewalk
2006-06-23 07:28 ——– d——– C:\Program Files\Windows Media Player
2006-06-21 15:44 20640 ——— C:\WINDOWS\system32\drivers\pxhelp20.sys
2006-06-21 15:44 109568 ——— C:\WINDOWS\system32\pxinsi64.exe
2006-06-21 06:49 53248 –a—— C:\WINDOWS\system32\dpuGUI10.dll
2006-06-21 06:43 520192 –a—— C:\WINDOWS\system32\DivXsm.exe
2006-06-21 06:42 200704 –a—— C:\WINDOWS\system32\ssldivx.dll
2006-06-21 06:42 1044480 –a—— C:\WINDOWS\system32\libdivx.dll
2006-06-21 06:34 593920 –a—— C:\WINDOWS\system32\dpuGUI11.dll
2006-06-21 06:34 57344 –a—— C:\WINDOWS\system32\dpv11.dll
2006-06-21 06:34 344064 –a—— C:\WINDOWS\system32\dpus11.dll
2006-06-21 06:34 294912 –a—— C:\WINDOWS\system32\dpu11.dll
2006-06-21 06:34 294912 –a—— C:\WINDOWS\system32\dpu10.dll
2006-06-21 06:33 12288 –a—— C:\WINDOWS\system32\DivXWMPExtType.dll
2006-06-21 06:33 118784 –a—— C:\WINDOWS\system32\DivXCodecUpdateChecker.exe
2006-06-20 18:48 ——– d——– C:\Program Files\Common Files\ScanSoft Shared
2006-06-20 18:08 ——– d——– C:\Program Files\TextBridge Pro 9.0
2006-06-20 15:17 ——– d——– C:\Program Files\PowerTracks DirectX Plugins
2006-06-20 14:33 ——– d——– C:\Program Files\Alfred Interactive
2006-06-20 13:43 ——– d——– C:\Program Files\Harmonic Vision
2006-06-20 13:25 ——– d——– C:\Program Files\Sibelius Software
2006-06-20 13:18 ——– d——– C:\Program Files\Rising Software
2006-06-20 13:05 53065 –a—— C:\Program Files\uninstal.log
2006-06-20 11:28 ——– d——– C:\Documents and Settings\HP_Administrator\Application Data\Sibelius Software
2006-06-20 10:58 ——– d——– C:\Program Files\Common Files\Borland Shared
2006-06-20 10:18 ——– d——– C:\Program Files\Neuratron PhotoScore
2006-06-20 10:18 ——– d——– C:\Documents and Settings\HP_Administrator\Application Data\Neuratron
2006-06-20 10:12 604 –ah—– C:\Program Files\STLL Notifier
2006-06-20 10:04 ——– d——– C:\Program Files\Native Instruments


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\\WINDOWS\\ehome\\ehtray.exe"
"HotKeysCmds"="C:\\WINDOWS\\system32\\hkcmd.exe"
"Persistence"="C:\\WINDOWS\\system32\\igfxpers.exe"
"HPBootOp"="\"C:\\Program Files\\Hewlett-Packard\\HP Boot Optimizer\\HPBootOp.exe\" /run"
"LSBWatcher"="c:\\hp\\drivers\\hplsbwatcher\\lsburnwatcher.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"HPDJ Taskbar Utility"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\hpztsb04.exe"
"vptray"="C:\\PROGRA~1\\SYMANT~1\\SYMANT~1\\vptray.exe"
"AdobeVersionCue"="C:\\Program Files\\Adobe\\Adobe Version Cue\\ControlPanel\\VersionCueTray.exe"
"HotKey"="C:\\WINDOWS\\Twain_32\\FlatBed\\HotKey.exe"
"HP Software Update"="C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"RTHDCPL"="RTHDCPL.EXE"
"Alcmtr"="ALCMTR.EXE"
"InstantAccess"="C:\\PROGRA~1\\TEXTBR~1.0\\Bin\\INSTAN~1.EXE /h"
"RegisterDropHandler"="C:\\PROGRA~1\\TEXTBR~1.0\\Bin\\REGIST~1.EXE"
"ISUSPM Startup"="C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\UPDATE~1\\ISUSPM.exe -startup"
"ISUSScheduler"="\"C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\UPDATE~1\\issch.exe\" -start"
"!ewido"="\"C:\\Program Files\\ewido anti-spyware 4.0\\ewido.exe\" /minimized"
"Zone Labs Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
"HPHmon06"="C:\\WINDOWS\\system32\\hphmon06.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"mfc71enu"="C:\\WINDOWS\\system32\\mfc71enu.exe"
"PopUpStopperFreeEdition"="\"C:\\PROGRA~1\\PANICW~1\\POP-UP~1\\PSFree.exe\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Runservices]
"RegisterDropHandler"="C:\\PROGRA~1\\TEXTBR~1.0\\Bin\\REGIST~1.EXE"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"InstallVisualStyle"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,\
63,65,73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,5c,52,6f,79,61,6c,65,2e,\
6d,73,73,74,79,6c,65,73,00
"InstallTheme"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,63,65,\
73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,2e,74,68,65,6d,65,00

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"NoActiveDesktop"=dword:00000000
"ForceActiveDesktopOn"=dword:00000001
"NoActiveDesktopChanges"=hex:00,00,00,00
"NoSaveSettings"=dword:00000000
"NoThemesTab"=dword:00000000

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"NoDispAppearancePage"=dword:00000000
"NoColorChoice"=dword:00000000
"NoSizeChoice"=dword:00000000
"NoDispBackgroundPage"=dword:00000000
"NoDispScrSavPage"=dword:00000000
"NoDispCPL"=dword:00000000
"NoVisualStyleChoice"=dword:00000000
"NoDispSettingsPage"=dword:00000000

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,4e,00,00,00,00,00,00,00,b2,03,00,00,e2,02,\
00,00,04,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,4e,00,00,00,00,00,00,00,b2,03,00,00,e2,02,\
00,00,01,00,00,00

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"



Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Symantec NetDetect.job

Completion time: Sun 08/20/2006 11:55:53.82
ComboFix.txt
ComboFix2.txt
hmm…that didn't work too well :(

try this:

Please create a new subfolder in the Program Files folder called GMER. If you have an older version of GMER installed, you must delete it. Download GMER and extract it to the C:\program files\GMER folder. Next, run the Gmer.exe program by double-clicking the executable file (gmer.exe) in Windows Explorer. You may be prompted to scan immediately if GMER detects rootkit activity. If you are prompted to scan your system click "yes" to begin the scan. If you are not prompted, Click the "Rootkit" tab, then click "Scan".

At the end of the scan, click "Copy" to copy the scan results to the clipboard. Then paste the results in a notepad file and also paste them back in a reply here.
I tried it twice. Each time it prompted to scan right away. When I did, it only got 1/2 way through and it shut my computer down. When it re-booted, I got a message that said "the system has recovered from a serious error"
Below is the log as far as it got

——————————–

GMER 1.0.11.11181 - http://www.gmer.net
Rootkit 2006-08-20 12:39:55
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.11 —-

SYSENTER ? AA363105 <– ROOTKIT !!!

—- Devices - GMER 1.0.11 —-

Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE [AA2302A0] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_CLOSE [AA2302A0] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CONTROL [AA2302A0] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_INTERNAL_DEVICE_CONTROL [AA2302A0] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_CLEANUP [AA2302A0] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE [AA2302A0] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLOSE [AA2302A0] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CONTROL [AA2302A0] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL [AA2302A0] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLEANUP [AA2302A0] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE [AA2302A0] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_CLOSE [AA2302A0] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CONTROL [AA2302A0] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_INTERNAL_DEVICE_CONTROL [AA2302A0] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_CLEANUP [AA2302A0] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE [AA2302A0] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLOSE [AA2302A0] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_DEVICE_CONTROL [AA2302A0] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_INTERNAL_DEVICE_CONTROL [AA2302A0] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLEANUP [AA2302A0] vsdatant.sys

—- Processes - GMER 1.0.11 —-

Process guard.exe (*** hidden *** ) [732] 8637D768 <– ROOTKIT !!!

—- Services - GMER 1.0.11 —-

Service C:\WINDOWS\system32\lzx32.sys (*** hidden *** ) [SYSTEM] pe386 <– ROOTKIT !!!

—- EOF - GMER 1.0.11 —-
Ok, let's try this:

Please print out these instructions to follow during the recovery console portion.

To remove the infection, perform the following steps:

1. Reboot your system using the Windows Recovery Console (using your Windows installation CD - click on the hyperlink for details).
2. Copy a non-executable file from the Windows directory over the Alternate Data Stream by running the following command:

* copy c:\windows\win.ini c:\windows\System32\Drivers\lzx32.sys

Please note that the copy command will fail but the malicious file has actually been truncated to zero-length.

Then exit the recovery console by typing "exit" (without the quotes) and then remove your windows cd from your drive and reboot your computer.

After booting into normal windows, post another combofix log.
I'm not sure if I did this right. I do not have a CD. I did no receive one with my computer purchase. What I have instead is a partition on the hard drive (D:/) that is the recovery console. I only have 3 choices when I run this, I have D:\I386 - D:\MiniNT - or c:\WINDOWS.
I used the C:\WINDOWS and tried typing in the command you suggested but it keeps saying "command not recognized" so I don't think I am doing something right.
advice?
WOO HOO
I think it worked. I was typing in the "*" from the command but then I read on the MS site that you can not use wild cards (sorry, it's been a while since I have had to type code) When I did not use the "*" it said 1 file copied.
Here is my new combofix log

again, I really appreciate all your help!

————————————-

((((((((((((((((((((((((((((((( Files Created from 2006-07-21 to 2006-08-21 ))))))))))))))))))))))))))))))))))


2006-08-16 17:05 23,552 C:\WINDOWS\system32\pniipub.exe
2006-08-11 18:14 32,976 C:\WINDOWS\system32\uninstIcn.exe
2006-08-11 18:13 16,384 C:\WINDOWS\system32\loadadv559.exe
2006-08-11 18:13 14,336 C:\WINDOWS\system32\test.exe
2006-08-04 11:37 196,608 C:\WINDOWS\system32\dtu100.dll
2006-07-28 09:29 0 C:\WINDOWS\system32ghynf.exe


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))

Rootkit driver pe386 is present. A rootkit scan is required

2006-08-20 12:22 ——– d——– C:\Program Files\GMER
2006-08-20 09:50 ——– d——– C:\Program Files\SP
2006-08-19 18:53 ——– d——– C:\Program Files\Mozilla Firefox
2006-08-19 08:09 ——– d——– C:\Program Files\ewido anti-spyware 4.0
2006-08-18 07:33 ——– d——– C:\Documents and Settings\HP_Administrator\Application Data\Locktime
2006-08-16 17:36 ——– d——– C:\Program Files\NetLimiter 2 Monitor
2006-08-16 17:34 ——– d——– C:\Program Files\Zone Labs
2006-08-16 17:05 23552 –a—— C:\WINDOWS\system32\pniipub.exe
2006-08-15 09:04 ——– d——– C:\Program Files\Audacity
2006-08-13 21:07 ——– d——– C:\Documents and Settings\HP_Administrator\Application Data\Adobe
2006-08-13 14:09 ——– d——– C:\Program Files\VideoraiPodConverter
2006-08-13 14:09 ——– d——– C:\Program Files\PSP ToolKit
2006-08-13 13:46 ——– d—s—- C:\Documents and Settings\HP_Administrator\Application Data\Microsoft
2006-08-13 13:45 ——– d——– C:\Program Files\Photo Story 3 for Windows
2006-08-13 09:09 ——– d——– C:\Program Files\Common Files\fiqo
2006-08-13 07:18 ——– d——– C:\Program Files\Common Files
2006-08-12 21:19 16384 –a—— C:\WINDOWS\system32\loadadv559.exe
2006-08-12 21:17 14336 –a—— C:\WINDOWS\system32\test.exe
2006-08-12 00:44 ——– d——– C:\Documents and Settings\HP_Administrator\Application Data\Lavasoft
2006-08-11 23:41 ——– d——– C:\Program Files\Lavasoft
2006-08-11 23:10 ——– d–h—– C:\Program Files\InstallShield Installation Information
2006-08-11 23:00 ——– d——– C:\Program Files\Windows Media Connect 2
2006-08-11 18:29 ——– d——– C:\Program Files\Internet Explorer
2006-08-11 18:14 32976 –a—— C:\WINDOWS\system32\uninstIcn.exe
2006-08-11 12:36 ——– d——– C:\Program Files\DivX
2006-08-04 11:37 73728 –a—— C:\WINDOWS\system32\dpl100.dll
2006-08-04 11:37 196608 –a—— C:\WINDOWS\system32\dtu100.dll
2006-07-30 15:27 ——– d——– C:\Program Files\Panicware
2006-07-29 09:20 ——– d——– C:\Program Files\ComPlus Applications
2006-07-29 08:30 ——– d——– C:\Program Files\Spyware Doctor
2006-07-28 11:29 ——– d——– C:\Program Files\Messenger
2006-07-28 09:29 0 –a—— C:\WINDOWS\system32ghynf.exe
2006-07-27 09:24 679424 –a—— C:\WINDOWS\system32\inetcomm.dll
2006-07-26 22:05 3596288 –a—— C:\WINDOWS\system32\qt-dx331.dll
2006-07-21 04:24 72704 –a—— C:\WINDOWS\system32\hlink.dll
2006-07-18 18:04 6236 –a—— C:\Documents and Settings\HP_Administrator\Application Data\GdiplusUpgrade_MSIApproach_Wrapper.log
2006-07-16 17:18 ——– d——– C:\Program Files\Motorola Phone Tools
2006-07-16 17:17 22768 –a—— C:\WINDOWS\system32\drivers\usbsermpt.sys
2006-07-16 17:16 ——– d——– C:\Program Files\LiveUpdate
2006-07-03 17:40 778240 –a—— C:\WINDOWS\system32\divx_xx0c.dll
2006-07-03 17:40 778240 –a—— C:\WINDOWS\system32\divx_xx07.dll
2006-07-03 17:40 761856 –a—— C:\WINDOWS\system32\divx_xx11.dll
2006-07-03 17:40 620180 –a—— C:\WINDOWS\system32\DivX.dll
2006-06-30 07:36 ——– d——– C:\Program Files\Common Files\Scanner
2006-06-30 07:35 ——– d——– C:\Documents and Settings\HP_Administrator\Application Data\Netscape
2006-06-30 07:34 ——– d——– C:\Program Files\Netscape
2006-06-29 09:15 ——– d——– C:\Program Files\Vortex
2006-06-28 15:01 118784 –a—— C:\WINDOWS\dsdxirmv.exe
2006-06-28 14:59 ——– d——– C:\Program Files\Cakewalk
2006-06-28 14:14 ——– d——– C:\Documents and Settings\HP_Administrator\Application Data\Identities
2006-06-28 14:14 ——– d——– C:\Documents and Settings\HP_Administrator\Application Data\Cakewalk
2006-06-23 07:28 ——– d——– C:\Program Files\Windows Media Player
2006-06-21 15:44 20640 ——— C:\WINDOWS\system32\drivers\pxhelp20.sys
2006-06-21 15:44 109568 ——— C:\WINDOWS\system32\pxinsi64.exe
2006-06-21 06:49 53248 –a—— C:\WINDOWS\system32\dpuGUI10.dll
2006-06-21 06:43 520192 –a—— C:\WINDOWS\system32\DivXsm.exe
2006-06-21 06:42 200704 –a—— C:\WINDOWS\system32\ssldivx.dll
2006-06-21 06:42 1044480 –a—— C:\WINDOWS\system32\libdivx.dll
2006-06-21 06:34 593920 –a—— C:\WINDOWS\system32\dpuGUI11.dll
2006-06-21 06:34 57344 –a—— C:\WINDOWS\system32\dpv11.dll
2006-06-21 06:34 344064 –a—— C:\WINDOWS\system32\dpus11.dll
2006-06-21 06:34 294912 –a—— C:\WINDOWS\system32\dpu11.dll
2006-06-21 06:34 294912 –a—— C:\WINDOWS\system32\dpu10.dll
2006-06-21 06:33 12288 –a—— C:\WINDOWS\system32\DivXWMPExtType.dll
2006-06-21 06:33 118784 –a—— C:\WINDOWS\system32\DivXCodecUpdateChecker.exe
2006-06-20 13:05 53065 –a—— C:\Program Files\uninstal.log
2006-06-20 10:12 604 –ah—– C:\Program Files\STLL Notifier


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\\WINDOWS\\ehome\\ehtray.exe"
"HotKeysCmds"="C:\\WINDOWS\\system32\\hkcmd.exe"
"Persistence"="C:\\WINDOWS\\system32\\igfxpers.exe"
"HPBootOp"="\"C:\\Program Files\\Hewlett-Packard\\HP Boot Optimizer\\HPBootOp.exe\" /run"
"LSBWatcher"="c:\\hp\\drivers\\hplsbwatcher\\lsburnwatcher.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"HPDJ Taskbar Utility"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\hpztsb04.exe"
"vptray"="C:\\PROGRA~1\\SYMANT~1\\SYMANT~1\\vptray.exe"
"AdobeVersionCue"="C:\\Program Files\\Adobe\\Adobe Version Cue\\ControlPanel\\VersionCueTray.exe"
"HotKey"="C:\\WINDOWS\\Twain_32\\FlatBed\\HotKey.exe"
"HP Software Update"="C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"RTHDCPL"="RTHDCPL.EXE"
"Alcmtr"="ALCMTR.EXE"
"InstantAccess"="C:\\PROGRA~1\\TEXTBR~1.0\\Bin\\INSTAN~1.EXE /h"
"RegisterDropHandler"="C:\\PROGRA~1\\TEXTBR~1.0\\Bin\\REGIST~1.EXE"
"ISUSPM Startup"="C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\UPDATE~1\\ISUSPM.exe -startup"
"ISUSScheduler"="\"C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\UPDATE~1\\issch.exe\" -start"
"!ewido"="\"C:\\Program Files\\ewido anti-spyware 4.0\\ewido.exe\" /minimized"
"Zone Labs Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
"HPHmon06"="C:\\WINDOWS\\system32\\hphmon06.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"mfc71enu"="C:\\WINDOWS\\system32\\mfc71enu.exe"
"PopUpStopperFreeEdition"="\"C:\\PROGRA~1\\PANICW~1\\POP-UP~1\\PSFree.exe\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Runservices]
"RegisterDropHandler"="C:\\PROGRA~1\\TEXTBR~1.0\\Bin\\REGIST~1.EXE"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"InstallVisualStyle"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,\
63,65,73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,5c,52,6f,79,61,6c,65,2e,\
6d,73,73,74,79,6c,65,73,00
"InstallTheme"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,63,65,\
73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,2e,74,68,65,6d,65,00

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"NoActiveDesktop"=dword:00000000
"ForceActiveDesktopOn"=dword:00000001
"NoActiveDesktopChanges"=hex:00,00,00,00
"NoSaveSettings"=dword:00000000
"NoThemesTab"=dword:00000000

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"NoDispAppearancePage"=dword:00000000
"NoColorChoice"=dword:00000000
"NoSizeChoice"=dword:00000000
"NoDispBackgroundPage"=dword:00000000
"NoDispScrSavPage"=dword:00000000
"NoDispCPL"=dword:00000000
"NoVisualStyleChoice"=dword:00000000
"NoDispSettingsPage"=dword:00000000

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,4e,00,00,00,00,00,00,00,b2,03,00,00,e2,02,\
00,00,04,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,4e,00,00,00,00,00,00,00,b2,03,00,00,e2,02,\
00,00,01,00,00,00

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"



Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Symantec NetDetect.job

Completion time: Mon 08/21/2006 7:25:05.62
ComboFix.txt
ComboFix2.txt
ComboFix3.txt
Do you recognize this folder?

C:\Program Files\Common Files\fiqo

Let me know in your next post.



1. Please download The Avenger by Swandog46 to your Desktop.
  • Click on Avenger.zip to open the file
  • Extract avenger.exe to your desktop
2. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):

Drivers to unload:
pe386

Files to delete:
C:\WINDOWS\system32\pniipub.exe
C:\WINDOWS\system32\uninstIcn.exe
C:\WINDOWS\system32\loadadv559.exe
C:\WINDOWS\system32\test.exe
C:\WINDOWS\system32ghynf.exe
C:\WINDOWS\system32\uninstIcn.exe


Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


3. Now, start The Avenger program by clicking on its icon on your desktop.
  • Under "Script file to execute" choose "Input Script Manually".
  • Now click on the Magnifying Glass icon which will open a new window titled "View/edit script"
  • Paste the text copied to clipboard into this window by pressing (Ctrl+V).
  • Click Done
  • Now click on the Green Light to begin execution of the script
  • Answer "Yes" twice when prompted.
4. The Avenger will automatically do the following:
  • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
5. Please copy/paste the content of c:\avenger.txt into your reply along with a fresh HJT log by using Add/Reply

Then, please run combofix again and post the log it generates.

In your next post, please include…

new hijackthis log
combofix log
avenger log
a description of how your computer is running
WOOOOO HOOOO again. My computer seems to be working like it's old self
My interenet connection has been restored!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
here are the 3 logs you requested
HighjackThis first

—————————–

Logfile of HijackThis v1.99.1
Scan saved at 6:15:56 PM, on 8/21/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\Program Files\NetLimiter 2 Monitor\nlsvc.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\M-Audio Uno\UnoInst.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\igfxpers.exe
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
C:\WINDOWS\Twain_32\FlatBed\HotKey.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\system32\hphmon06.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
C:\WINDOWS\system32\notepad.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\PROGRA~1\NETSCAPE\NETSCAPE\NETSCP.EXE
c:\windows\system\hpsysdrv.exe
C:\Documents and Settings\HP_Administrator\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://owa.cliu.org/exchweb/logon.asp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R3 - Default URLSearchHook is missing
N3 - Netscape 7: user_pref("browser.startup.homepage", "http:/www.google.com"); (C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Profiles\default\m3chy5b2.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Profiles\default\m3chy5b2.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [AdobeVersionCue] C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
O4 - HKLM\..\Run: [HotKey] C:\WINDOWS\Twain_32\FlatBed\HotKey.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [InstantAccess] C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE /h
O4 - HKLM\..\Run: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe" -start
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [wkmnmamx] C:\wnjmofgc.bat
O4 - HKLM\..\RunServices: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [mfc71enu] C:\WINDOWS\system32\mfc71enu.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5AA5A569-F96F-4628-A528-8B3698F558BB} (HS_live Control) - http://install.homestead.com/~site/Install…ive/HS_live.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe
O23 - Service: apcups.exe - Unknown owner - C:\WINDOWS\system32\apcups.exe
O23 - Service: CWShredder Service - Unknown owner - C:\Program Files\InterMute\SpySubtract\CWShredder.exe (file missing)
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: icwdial.exe - Unknown owner - C:\WINDOWS\system32\icwdial.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MSSQL$MICROSOFTSMLBIZ - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe" -sMICROSOFTSMLBIZ (file missing)
O23 - Service: NetLimiter (nlsvc) - Locktime Software - C:\Program Files\NetLimiter 2 Monitor\nlsvc.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SQLAgent$MICROSOFTSMLBIZ - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlagent.EXE" -i MICROSOFTSMLBIZ (file missing)
O23 - Service: Uno Installer (UnoInstallerService) - Unknown owner - C:\Program Files\M-Audio Uno\UnoInst.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: YBIEDGZ - Unknown owner - C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\YBIEDGZ.exe (file missing)
O23 - Service: ZS - Unknown owner - C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\ZS.exe (file missing)
combofix next ——————————- ((((((((((((((((((((((((((((((( Files Created from 2006-07-21 to 2006-08-21 )))))))))))))))))))))))))))))))))) 2006-08-20 12:09 69,780 C:\WINDOWS\system32\lzx32.sys 2006-08-04 11:37 196,608 C:\WINDOWS\system32\dtu100.dll (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2006-08-21 18:14 ——– d——– C:\Program Files\ewido anti-spyware 4.0 2006-08-21 17:59 ——– d——– C:\Program Files\Common Files\Wise Installation Wizard 2006-08-21 17:59 ——– d——– C:\Program Files\Common Files 2006-08-21 17:54 69780 –a—— C:\WINDOWS\system32\lzx32.sys 2006-08-20 12:22 ——– d——– C:\Program Files\GMER 2006-08-20 09:50 ——– d——– C:\Program Files\SP 2006-08-19 18:53 ——– d——– C:\Program Files\Mozilla Firefox 2006-08-18 07:33 ——– d——– C:\Documents and Settings\HP_Administrator\Application Data\Locktime 2006-08-16 17:36 ——– d——– C:\Program Files\NetLimiter 2 Monitor 2006-08-16 17:34 ——– d——– C:\Program Files\Zone Labs 2006-08-15 09:04 ——– d——– C:\Program Files\Audacity 2006-08-13 21:07 ——– d——– C:\Documents and Settings\HP_Administrator\Application Data\Adobe 2006-08-13 14:09 ——– d——– C:\Program Files\VideoraiPodConverter 2006-08-13 14:09 ——– d——– C:\Program Files\PSP ToolKit 2006-08-13 13:46 ——– d—s—- C:\Documents and Settings\HP_Administrator\Application Data\Microsoft 2006-08-13 13:45 ——– d——– C:\Program Files\Photo Story 3 for Windows 2006-08-13 09:09 ——– d——– C:\Program Files\Common Files\fiqo 2006-08-12 00:44 ——– d——– C:\Documents and Settings\HP_Administrator\Application Data\Lavasoft 2006-08-11 23:41 ——– d——– C:\Program Files\Lavasoft 2006-08-11 23:10 ——– d–h—– C:\Program Files\InstallShield Installation Information 2006-08-11 23:00 ——– d——– C:\Program Files\Windows Media Connect 2 2006-08-11 18:29 ——– d——– C:\Program Files\Internet Explorer 2006-08-11 12:36 ——– d——– C:\Program Files\DivX 2006-08-04 11:37 73728 –a—— C:\WINDOWS\system32\dpl100.dll 2006-08-04 11:37 196608 –a—— C:\WINDOWS\system32\dtu100.dll 2006-07-30 15:27 ——– d——– C:\Program Files\Panicware 2006-07-29 09:20 ——– d——– C:\Program Files\ComPlus Applications 2006-07-29 08:30 ——– d——– C:\Program Files\Spyware Doctor 2006-07-28 11:29 ——– d——– C:\Program Files\Messenger 2006-07-27 09:24 679424 –a—— C:\WINDOWS\system32\inetcomm.dll 2006-07-26 22:05 3596288 –a—— C:\WINDOWS\system32\qt-dx331.dll 2006-07-21 04:24 72704 –a—— C:\WINDOWS\system32\hlink.dll 2006-07-18 18:04 6236 –a—— C:\Documents and Settings\HP_Administrator\Application Data\GdiplusUpgrade_MSIApproach_Wrapper.log 2006-07-16 17:18 ——– d——– C:\Program Files\Motorola Phone Tools 2006-07-16 17:17 22768 –a—— C:\WINDOWS\system32\drivers\usbsermpt.sys 2006-07-16 17:16 ——– d——– C:\Program Files\LiveUpdate 2006-07-03 17:40 778240 –a—— C:\WINDOWS\system32\divx_xx0c.dll 2006-07-03 17:40 778240 –a—— C:\WINDOWS\system32\divx_xx07.dll 2006-07-03 17:40 761856 –a—— C:\WINDOWS\system32\divx_xx11.dll 2006-07-03 17:40 620180 –a—— C:\WINDOWS\system32\DivX.dll 2006-06-30 07:36 ——– d——– C:\Program Files\Common Files\Scanner 2006-06-30 07:35 ——– d——– C:\Documents and Settings\HP_Administrator\Application Data\Netscape 2006-06-30 07:34 ——– d——– C:\Program Files\Netscape 2006-06-29 09:15 ——– d——– C:\Program Files\Vortex 2006-06-28 15:01 118784 –a—— C:\WINDOWS\dsdxirmv.exe 2006-06-28 14:59 ——– d——– C:\Program Files\Cakewalk 2006-06-28 14:14 ——– d——– C:\Documents and Settings\HP_Administrator\Application Data\Identities 2006-06-28 14:14 ——– d——– C:\Documents and Settings\HP_Administrator\Application Data\Cakewalk 2006-06-23 07:28 ——– d——– C:\Program Files\Windows Media Player 2006-06-21 15:44 20640 ——— C:\WINDOWS\system32\drivers\pxhelp20.sys 2006-06-21 15:44 109568 ——— C:\WINDOWS\system32\pxinsi64.exe 2006-06-21 06:49 53248 –a—— C:\WINDOWS\system32\dpuGUI10.dll 2006-06-21 06:43 520192 –a—— C:\WINDOWS\system32\DivXsm.exe 2006-06-21 06:42 200704 –a—— C:\WINDOWS\system32\ssldivx.dll 2006-06-21 06:42 1044480 –a—— C:\WINDOWS\system32\libdivx.dll 2006-06-21 06:34 593920 –a—— C:\WINDOWS\system32\dpuGUI11.dll 2006-06-21 06:34 57344 –a—— C:\WINDOWS\system32\dpv11.dll 2006-06-21 06:34 344064 –a—— C:\WINDOWS\system32\dpus11.dll 2006-06-21 06:34 294912 –a—— C:\WINDOWS\system32\dpu11.dll 2006-06-21 06:34 294912 –a—— C:\WINDOWS\system32\dpu10.dll 2006-06-21 06:33 12288 –a—— C:\WINDOWS\system32\DivXWMPExtType.dll 2006-06-21 06:33 118784 –a—— C:\WINDOWS\system32\DivXCodecUpdateChecker.exe 2006-06-20 13:05 53065 –a—— C:\Program Files\uninstal.log 2006-06-20 10:12 604 –ah—– C:\Program Files\STLL Notifier (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ehTray"="C:\\WINDOWS\\ehome\\ehtray.exe" "HotKeysCmds"="C:\\WINDOWS\\system32\\hkcmd.exe" "Persistence"="C:\\WINDOWS\\system32\\igfxpers.exe" "HPBootOp"="\"C:\\Program Files\\Hewlett-Packard\\HP Boot Optimizer\\HPBootOp.exe\" /run" "LSBWatcher"="c:\\hp\\drivers\\hplsbwatcher\\lsburnwatcher.exe" "SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe" "HPDJ Taskbar Utility"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\hpztsb04.exe" "vptray"="C:\\PROGRA~1\\SYMANT~1\\SYMANT~1\\vptray.exe" "AdobeVersionCue"="C:\\Program Files\\Adobe\\Adobe Version Cue\\ControlPanel\\VersionCueTray.exe" "HotKey"="C:\\WINDOWS\\Twain_32\\FlatBed\\HotKey.exe" "HP Software Update"="C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe" "iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\"" "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "RTHDCPL"="RTHDCPL.EXE" "Alcmtr"="ALCMTR.EXE" "InstantAccess"="C:\\PROGRA~1\\TEXTBR~1.0\\Bin\\INSTAN~1.EXE /h" "RegisterDropHandler"="C:\\PROGRA~1\\TEXTBR~1.0\\Bin\\REGIST~1.EXE" "ISUSPM Startup"="C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\UPDATE~1\\ISUSPM.exe -startup" "ISUSScheduler"="\"C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\UPDATE~1\\issch.exe\" -start" "!ewido"="\"C:\\Program Files\\ewido anti-spyware 4.0\\ewido.exe\" /minimized" "Zone Labs Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\"" "HPHmon06"="C:\\WINDOWS\\system32\\hphmon06.exe" "wkmnmamx"="C:\\wnjmofgc.bat" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI] "Installed"="1" "NoChange"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS] "Installed"="1" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe" "mfc71enu"="C:\\WINDOWS\\system32\\mfc71enu.exe" "PopUpStopperFreeEdition"="\"C:\\PROGRA~1\\PANICW~1\\POP-UP~1\\PSFree.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Runservices] "RegisterDropHandler"="C:\\PROGRA~1\\TEXTBR~1.0\\Bin\\REGIST~1.EXE" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] "dontdisplaylastusername"=dword:00000000 "legalnoticecaption"="" "legalnoticetext"="" "shutdownwithoutlogon"=dword:00000001 "undockwithoutlogon"=dword:00000001 "InstallVisualStyle"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,\ 63,65,73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,5c,52,6f,79,61,6c,65,2e,\ 6d,73,73,74,79,6c,65,73,00 "InstallTheme"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,63,65,\ 73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,2e,74,68,65,6d,65,00 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 "NoActiveDesktop"=dword:00000000 "ForceActiveDesktopOn"=dword:00000001 "NoActiveDesktopChanges"=hex:00,00,00,00 "NoSaveSettings"=dword:00000000 "NoThemesTab"=dword:00000000 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] "NoDispAppearancePage"=dword:00000000 "NoColorChoice"=dword:00000000 "NoSizeChoice"=dword:00000000 "NoDispBackgroundPage"=dword:00000000 "NoDispScrSavPage"=dword:00000000 "NoDispCPL"=dword:00000000 "NoVisualStyleChoice"=dword:00000000 "NoDispSettingsPage"=dword:00000000 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components] "DeskHtmlVersion"=dword:00000110 "DeskHtmlMinorVersion"=dword:00000005 "Settings"=dword:00000001 "GeneralFlags"=dword:00000001 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" "Flags"=dword:00000002 "Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,00,00,00,\ 00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:04,00,00,40 "OriginalStateInfo"=hex:18,00,00,00,4e,00,00,00,00,00,00,00,b2,03,00,00,e2,02,\ 00,00,04,00,00,40 "RestoredStateInfo"=hex:18,00,00,00,4e,00,00,00,00,00,00,00,b2,03,00,00,e2,02,\ 00,00,01,00,00,00 [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run] [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\sharedtaskscheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks] "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"="" "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0" Contents of the 'Scheduled Tasks' folder C:\WINDOWS\tasks\Symantec NetDetect.job Completion time: Mon 08/21/2006 18:17:41.62 ComboFix.txt ComboFix2.txt ComboFix3.txt

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI