Before i post the logs....everything has seemed to gone really basic in view and im not able to see any graphics on my computer....its like text only on some websites and i dont kno the cause of it....this only happens when im on the internet and don't know hot fix it if you could help that would be great...thanks
here are the logs
HiJackThis Log
Logfile of HijackThis v1.99.1
Scan saved at 8:28:58 PM, on 9/8/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\2Wire\2PortalMon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Agnitum\OUTPOS~1.0\outpost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Hijackthis\HijackThis.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe"
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\McAgent.exe
O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\2PortalMon.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Outpost Firewall] C:\PROGRA~1\Agnitum\OUTPOS~1.0\outpost.exe /waitservice
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone:
http://download.windowsupdate.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} -
http://ax.phobos.app.../ITDetector.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Outpost Firewall Service (OutpostFirewall) - Agnitum - C:\PROGRA~1\Agnitum\OUTPOS~1.0\outpost.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE
AVG Anti-Spyware Log
The program didnt allow me to save this report and when i went to the report section no report was saved.
ComboFix Log
ComboFix 07-09-08.7 - "DJ DHoLa" 2007-09-08 14:28:27.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.125 [GMT -7:00]
Command switches used :: C:\Documents and Settings\DJ DHoLa\Desktop\CFScript.txt
* Created a new restore point
FILE::
C:\WINDOWS\SYSTEM32\jquidfmp.dll
C:\WINDOWS\SYSTEM32\ioowslai.dll
C:\WINDOWS\SYSTEM32\ymtwavcn.dll
C:\WINDOWS\SYSTEM32\xxhjrtcj.dll
C:\WINDOWS\SYSTEM32\vmqfrvba.dll
C:\WINDOWS\SYSTEM32\xllfhmgv.dll
C:\WINDOWS\SYSTEM32\rwbcxtog.dll
C:\WINDOWS\SYSTEM32\cuwsnfmd.dll
C:\WINDOWS\SYSTEM32\otiwyuae.dll
C:\WINDOWS\SYSTEM32\hngoeqei.dll
C:\WINDOWS\SYSTEM32\byvrydon.dll
C:\WINDOWS\SYSTEM32\kkpulchl.dll
C:\WINDOWS\SYSTEM32\ypjuteko.dll
C:\WINDOWS\SYSTEM32\jjuafcsg.dll
C:\WINDOWS\SYSTEM32\xxpexfwc.dll
C:\WINDOWS\SYSTEM32\qflannpc.dll
C:\WINDOWS\SYSTEM32\ggjslkoa.dll
C:\WINDOWS\SYSTEM32\coogaxtm.dll
C:\WINDOWS\SYSTEM32\ajepapdp.dll
C:\WINDOWS\SYSTEM32\liecdqti.dll
C:\WINDOWS\SYSTEM32\subegnto.dll
C:\WINDOWS\SYSTEM32\notgkyas.dll
C:\WINDOWS\SYSTEM32\vpxpcbpi.dll
C:\Program Files\setup.exe
C:\WINDOWS\SYSTEM32\fpvnougb.dll
C:\Documents and Settings\DJDHOL~1\load.exe
C:\DOCUME~1\DJDHOL~1\load.exe
C:\DOCUME~1\DJDHOL~1\APPLIC~1\nekieefdm.exe
C:\Program Files\ucleaner_setup.exe
C:\WINDOWS\mgrs.exe
C:\WINDOWS\SYSTEM32\nqtss.bak1
C:\WINDOWS\SYSTEM32\winosz32(2).dll
C:\WINDOWS\system32\it_pl.dll
C:\WINDOWS\system32\it_reg.exe
C:\WINDOWS\system32\jquidfmp.dll
C:\WINDOWS\system32\ioowslai.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\DOCUME~1\DJDHOL~1\APPLIC~1.\Ultimate Cleaner
C:\DOCUME~1\DJDHOL~1\APPLIC~1.\Ultimate Cleaner\settings.dat
C:\DOCUME~1\DJDHOL~1\APPLIC~1\macromedia\Flash Player\#SharedObjects\33VQB3NW\www.broadcaster.com
C:\DOCUME~1\DJDHOL~1\APPLIC~1\macromedia\Flash Player\#SharedObjects\33VQB3NW\www.broadcaster.com\played_list.sol
C:\DOCUME~1\DJDHOL~1\APPLIC~1\macromedia\Flash Player\#SharedObjects\33VQB3NW\www.broadcaster.com\video_queue.sol
C:\DOCUME~1\DJDHOL~1\APPLIC~1\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\DOCUME~1\DJDHOL~1\APPLIC~1\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol
C:\DOCUME~1\DJDHOL~1\APPLIC~1\nekieefdm.exe
C:\DOCUME~1\DJDHOL~1\APPLIC~1\Ultimate Cleaner\settings.dat
C:\DOCUME~1\DJDHOL~1\Desktop\Find Spyware Remover.lnk
C:\DOCUME~1\DJDHOL~1\Desktop\Free Online Dating.lnk
C:\DOCUME~1\DJDHOL~1\Desktop\Go to Casino.lnk
C:\DOCUME~1\DJDHOL~1\load.exe
C:\DOCUME~1\Nirmal\Desktop\Find Spyware Remover.lnk
C:\DOCUME~1\Nirmal\Desktop\Free Online Dating.lnk
C:\DOCUME~1\Nirmal\Desktop\Go to Casino.lnk
C:\Documents and Settings\DJDHOL~1\load.exe
C:\Program Files\Magicantispy
C:\Program Files\Magicantispy\Magicantispy.exe
C:\Program Files\Magicantispy\Magicantispy0.my
C:\Program Files\Magicantispy\Magicantispy1.my
C:\Program Files\setup.exe
C:\Program Files\ucleaner_setup.exe
C:\Program Files\Ultimate Cleaner
C:\VundoFix Backups
C:\VundoFix Backups\abadd.bak1.bad
C:\VundoFix Backups\abadd.bak2.bad
C:\VundoFix Backups\abadd.ini.bad
C:\VundoFix Backups\abadd.ini2.bad
C:\VundoFix Backups\abadd.tmp.bad
C:\VundoFix Backups\addmorefiles.txt
C:\VundoFix Backups\ddaba.dll.bad
C:\VundoFix Backups\drvvun.dll.bad
C:\VundoFix Backups\drvvunr.dll.bad
C:\VundoFix Backups\efcbyab.dll.bad
C:\VundoFix Backups\fccbxvs.dll.bad
C:\VundoFix Backups\pokcusol.dll.bad
C:\VundoFix Backups\vqdcnbrb.dll.bad
C:\WINDOWS\180ax.exe
C:\WINDOWS\2020search.dll
C:\WINDOWS\2020search2.dll
C:\WINDOWS\7search.dll
C:\WINDOWS\bacffe.ini
C:\WINDOWS\bi.dll
C:\WINDOWS\biprep.exe
C:\WINDOWS\bjam.dll
C:\WINDOWS\bokja.exe
C:\WINDOWS\Casino.ico
C:\WINDOWS\cdsm32.dll
C:\WINDOWS\cookies.ini
C:\WINDOWS\effcab.dll
C:\WINDOWS\flt.dll
C:\WINDOWS\Free Online Dating.ico
C:\WINDOWS\mspphe.dll
C:\WINDOWS\mssvr.exe
C:\WINDOWS\opoqpo.ini
C:\WINDOWS\opqopo.dll
C:\WINDOWS\pbar.dll
C:\WINDOWS\saiemod.dll
C:\WINDOWS\salm.exe
C:\WINDOWS\satmat.exe
C:\WINDOWS\Spyware Remover.ico
C:\WINDOWS\stcloader.exe
C:\WINDOWS\swin32.dll
C:\WINDOWS\sysrlb32.exe
C:\WINDOWS\SYSTEM32\ajepapdp.dll
C:\WINDOWS\system32\ajepapdp.dll
C:\WINDOWS\SYSTEM32\byvrydon.dll
C:\WINDOWS\system32\byvrydon.dll
C:\WINDOWS\system32\coogaxtm.dll
C:\WINDOWS\SYSTEM32\coogaxtm.dll
C:\WINDOWS\system32\cuwsnfmd.dll
C:\WINDOWS\SYSTEM32\cuwsnfmd.dll
C:\WINDOWS\system32\drivers\alert_icon.gif
C:\WINDOWS\system32\drivers\close_icon.gif
C:\WINDOWS\system32\drivers\detect.htm
C:\WINDOWS\system32\drivers\header_bg.gif
C:\WINDOWS\system32\drivers\icon_warning.gif
C:\WINDOWS\system32\drivers\remove_spyware_button.gif
C:\WINDOWS\system32\drivers\s_detect.htm
C:\WINDOWS\system32\drivers\secuity_center_logo.gif
C:\WINDOWS\SYSTEM32\fpvnougb.dll
C:\WINDOWS\system32\fpvnougb.dll
C:\WINDOWS\system32\ggjslkoa.dll
C:\WINDOWS\SYSTEM32\ggjslkoa.dll
C:\WINDOWS\system32\hlpsrv.exe
C:\WINDOWS\system32\hngoeqei.dll
C:\WINDOWS\SYSTEM32\hngoeqei.dll
C:\WINDOWS\SYSTEM32\ialswooi.ini
C:\WINDOWS\system32\ioowslai.dll
C:\WINDOWS\SYSTEM32\ioowslai.dll
C:\WINDOWS\system32\it_pl.dll
C:\WINDOWS\system32\it_reg.exe
C:\WINDOWS\system32\jjuafcsg.dll
C:\WINDOWS\SYSTEM32\jjuafcsg.dll
C:\WINDOWS\system32\jquidfmp.dll
C:\WINDOWS\SYSTEM32\jquidfmp.dll
C:\WINDOWS\system32\kkpulchl.dll
C:\WINDOWS\SYSTEM32\kkpulchl.dll
C:\WINDOWS\system32\lfd32.ini
C:\WINDOWS\system32\liecdqti.dll
C:\WINDOWS\SYSTEM32\liecdqti.dll
C:\WINDOWS\system32\msixu.dll
C:\WINDOWS\system32\notgkyas.dll
C:\WINDOWS\SYSTEM32\notgkyas.dll
C:\WINDOWS\SYSTEM32\nqtss.bak1
C:\WINDOWS\SYSTEM32\otiwyuae.dll
C:\WINDOWS\system32\otiwyuae.dll
C:\WINDOWS\SYSTEM32\qflannpc.dll
C:\WINDOWS\system32\qflannpc.dll
C:\WINDOWS\SYSTEM32\rwbcxtog.dll
C:\WINDOWS\system32\rwbcxtog.dll
C:\WINDOWS\system32\sl.bin
C:\WINDOWS\system32\subegnto.dll
C:\WINDOWS\SYSTEM32\subegnto.dll
C:\WINDOWS\SYSTEM32\vmqfrvba.dll
C:\WINDOWS\system32\vmqfrvba.dll
C:\WINDOWS\SYSTEM32\vpxpcbpi.dll
C:\WINDOWS\system32\vpxpcbpi.dll
C:\WINDOWS\system32\vxddsk.exe
C:\WINDOWS\system32\wer8274.dll
C:\WINDOWS\SYSTEM32\winosz32(2).dll
C:\WINDOWS\system32\wml.exe
C:\WINDOWS\system32\xllfhmgv.dll
C:\WINDOWS\SYSTEM32\xllfhmgv.dll
C:\WINDOWS\system32\xxhjrtcj.dll
C:\WINDOWS\SYSTEM32\xxhjrtcj.dll
C:\WINDOWS\SYSTEM32\xxpexfwc.dll
C:\WINDOWS\system32\xxpexfwc.dll
C:\WINDOWS\system32\ymtwavcn.dll
C:\WINDOWS\SYSTEM32\ymtwavcn.dll
C:\WINDOWS\SYSTEM32\ypjuteko.dll
C:\WINDOWS\system32\ypjuteko.dll
C:\WINDOWS\updatetc.exe
C:\WINDOWS\voiceip.dll
C:\WINDOWS\vxddsk.exe
C:\WINDOWS\wml.exe
((((((((((((((((((((((((( Files Created from 2007-08-08 to 2007-09-08 )))))))))))))))))))))))))))))))
.
2007-09-08 14:09 10,872 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2007-09-06 17:45 478 --a------ C:\CFCleanUp.bat
2007-09-06 14:01 <DIR> d-------- C:\Program Files\Common Files\Agnitum Shared
2007-09-06 14:01 <DIR> d-------- C:\Program Files\Agnitum
2007-08-20 12:41 53,248 --a------ C:\WINDOWS\SYSTEM32\Process.exe
2007-08-20 12:41 51,200 --a------ C:\WINDOWS\SYSTEM32\dumphive.exe
2007-08-20 12:41 288,417 --a------ C:\WINDOWS\SYSTEM32\SrchSTS.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-07 02:00 --------- d-------- C:\Program Files\DC++
2007-09-07 01:23 --------- d-------- C:\Program Files\Steam
2007-09-06 14:04 --------- d-------- C:\Program Files\Common Files\Symantec Shared
2007-09-06 13:54 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
2007-08-29 17:42 --------- d-------- C:\Program Files\AV Music Morpher Gold
2007-07-30 12:08 --------- d-------- C:\Program Files\PokerStars
2007-07-19 10:10 --------- d-------- C:\Program Files\MSN Messenger
2007-06-17 00:11 51200 --a------ C:\WINDOWS\nircmd.exe
2007-06-13 03:23 1033216 --a------ C:\WINDOWS\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-06-30 12:33]
"IPInSightMonitor 01"="C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe" [2003-07-14 12:30]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\McUpdate.exe" [2004-10-25 12:08]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\McAgent.exe" [2004-08-17 19:26]
"2wSysTray"="C:\Program Files\2Wire\2PortalMon.exe" [2004-09-15 01:52]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-12-20 20:04]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-12-05 15:14]
"Outpost Firewall"="C:\PROGRA~1\Agnitum\OUTPOS~1.0\outpost.exe" [2002-06-14 16:20]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AIM"="C:\Program Files\AIM\aim.exe" [2003-08-01 08:31]
"Steam"="" []
"BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" [2007-03-01 16:11]
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
DESKTOP.INI [2004-08-10 12:04:12]
C:\DOCUME~1\ADMINI~1\STARTM~1\Programs\Startup\
DESKTOP.INI [2004-08-10 12:04:12]
C:\DOCUME~1\DJDHOL~1\STARTM~1\Programs\Startup\
DESKTOP.INI [2004-08-10 12:04:12]
C:\DOCUME~1\Nirmal\STARTM~1\Programs\Startup\
DESKTOP.INI [2004-08-10 12:04:12]
C:\DOCUME~1\oTHaZ\STARTM~1\Programs\Startup\
DESKTOP.INI [2004-08-10 12:04:12]
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\STARTM~1\Programs\Startup\
DESKTOP.INI [2004-08-10 12:04:12]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
C:\Program Files\AIM\aim.exe -cnetwait.odl
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avp]
C:\WINDOWS\TEMP\win4D.tmp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
"C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bw45Rjc9W]
C:\Program Files\asdfe57\SPBS.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
"C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeadAIM]
rundll32.exe "C:\PROGRA~1\AIM\\DeadAIM.ocm",ExportedCheckODLs
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell AIO Printer A920]
"C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
"C:\Program Files\Dell Support\DSAgnt.exe" /startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
C:\WINDOWS\system32\dla\tfswctrl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\gah95on6]
C:\WINDOWS\system32\gah95on6.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\WINDOWS\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelMeM]
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Internet Optimizer]
"C:\Program Files\Internet Optimizer\optimize.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\joyping]
C:\DOCUME~1\DJDHOL~1\APPLIC~1\PLAYNU~1\ErrorRemoteFind.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogCashDrvSkip]
C:\Documents and Settings\All Users\Application Data\corn link log cash\user start.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCAgentExe]
c:\PROGRA~1\mcafee.com\agent\McAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCUpdateExe]
C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Media Pass]
C:\Program Files\Media Pass\MediaPass.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MessengerPlus3]
"C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsft Windows Adapter 5.1.3013]
C:\Documents and Settings\DJ DHoLa\Application Data\nekieefdm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MPFExe]
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\msnmsgr.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NAV CfgWiz]
"C:\Program Files\Norton AntiVirus\CfgWiz.exe" /GUID {0D7956A2-5A08-4ec2-A72C-DF8495A66016} /MODE CfgWiz /CMDLINE "REBOOT"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
"C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sen]
"C:\WINDOWS\ASEMBL~1\dexplore.exe" -vt yazb
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\setup]
rundll32.exe "C:\WINDOWS\opqopo.dll",realset
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
"C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSC_UserPrompt]
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
"c:\program files\steam\steam.exe" -silent
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
"C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ViewMgr]
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirusScan Online]
"c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VSOCheckTask]
"c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"mnmsrvc"=3 (0x3)
"MCVSRte"=2 (0x2)
"mcupdmgr.exe"=3 (0x3)
"McShield"=2 (0x2)
"iPodService"=3 (0x3)
"ColdFusion Management Service"=2 (0x2)
"ColdFusion Management Repository"=2 (0x2)
"ColdFusion Graphing Server"=2 (0x2)
"Cold Fusion RDS"=2 (0x2)
"Cold Fusion Executive"=2 (0x2)
"Cold Fusion Application Server"=2 (0x2)
"ClusterCATS Service"=2 (0x2)
R1 cdudf_xp;cdudf_xp;C:\WINDOWS\system32\drivers\cdudf_xp.sys
R1 DVDVRRdr_xp;DVDVRRdr_xp;C:\WINDOWS\system32\drivers\DVDVRRdr_xp.sys
R1 pwd_2k;pwd_2k;C:\WINDOWS\system32\drivers\pwd_2k.sys
R1 sdcplh;sdcplh;C:\WINDOWS\system32\drivers\sdcplh.sys
R1 UDFReadr;UDFReadr;C:\WINDOWS\system32\drivers\UDFReadr.sys
R1 VFILT;Outpost Firewall Kernel Driver;\??\C:\PROGRA~1\Agnitum\OUTPOS~1.0\kernel\2000\FILTNT.SYS
R3 2WIREPCP;2Wire USB;C:\WINDOWS\system32\DRIVERS\2WirePCP.sys
R3 ADBLOCK.DLL;Outpost Firewall PlugIn (ADBLOCK.DLL);\??\C:\PROGRA~1\Agnitum\OUTPOS~1.0\kernel\ADBLOCK.DLL
R3 CONTENT.DLL;Outpost Firewall PlugIn (CONTENT.DLL);\??\C:\PROGRA~1\Agnitum\OUTPOS~1.0\kernel\CONTENT.DLL
R3 DNSCACHE.DLL;Outpost Firewall PlugIn (DNSCACHE.DLL);\??\C:\PROGRA~1\Agnitum\OUTPOS~1.0\kernel\DNSCACHE.DLL
R3 FTPFILT.DLL;Outpost Firewall PlugIn (FTPFILT.DLL);\??\C:\PROGRA~1\Agnitum\OUTPOS~1.0\kernel\FTPFILT.DLL
R3 HTMLFILT.DLL;Outpost Firewall PlugIn (HTMLFILT.DLL);\??\C:\PROGRA~1\Agnitum\OUTPOS~1.0\kernel\HTMLFILT.DLL
R3 HTTPFILT.DLL;Outpost Firewall PlugIn (HTTPFILT.DLL);\??\C:\PROGRA~1\Agnitum\OUTPOS~1.0\kernel\HTTPFILT.DLL
R3 IMAPFILT.DLL;Outpost Firewall PlugIn (IMAPFILT.DLL);\??\C:\PROGRA~1\Agnitum\OUTPOS~1.0\kernel\IMAPFILT.DLL
R3 MAILFILT.DLL;Outpost Firewall PlugIn (MAILFILT.DLL);\??\C:\PROGRA~1\Agnitum\OUTPOS~1.0\kernel\MAILFILT.DLL
R3 mmc_2K;mmc_2K;C:\WINDOWS\system32\drivers\mmc_2K.sys
R3 NNTPFILT.DLL;Outpost Firewall PlugIn (NNTPFILT.DLL);\??\C:\PROGRA~1\Agnitum\OUTPOS~1.0\kernel\NNTPFILT.DLL
R3 POP3FILT.DLL;Outpost Firewall PlugIn (POP3FILT.DLL);\??\C:\PROGRA~1\Agnitum\OUTPOS~1.0\kernel\POP3FILT.DLL
R3 PROTECT.DLL;Outpost Firewall PlugIn (PROTECT.DLL);\??\C:\PROGRA~1\Agnitum\OUTPOS~1.0\kernel\PROTECT.DLL
S3 1d226aef-23ef-4b18-af46-5559c7b3b451;1d226aef-23ef-4b18-af46-5559c7b3b451;\??\D:\CDS300\cds300.dll
S3 dvd_2K;dvd_2K;C:\WINDOWS\system32\drivers\dvd_2K.sys
S3 NaiFiltr;NaiFiltr;C:\WINDOWS\system32\DRIVERS\NaiFiltr.sys
S3 Wdm1;USB Bridge Cable Driver;C:\WINDOWS\system32\Drivers\usbbc.sys
S4 Cold Fusion Application Server;Cold Fusion Application Server;C:\CFusion\Bin\cfserver.exe
S4 Cold Fusion Executive;ColdFusion Executive;C:\CFusion\Bin\cfexec.exe
S4 Cold Fusion RDS;ColdFusion RDS;C:\CFusion\Bin\cfrdsservice.exe
S4 ColdFusion Management Repository;ColdFusion Management Repository Server;"C:\CFusion\jrun\bin\jrun.exe" -jrundir "C:\CFusion\jrun" -nt "ColdFusion Management Repository" "cfam"
*Newly Created Service* - AVGASCLN
.
Contents of the 'Scheduled Tasks' folder
"2007-09-08 05:51:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-09-08 21:32:00 C:\WINDOWS\Tasks\McAfee.com Update Check (DGM5G461-Owner).job"
- c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
"2007-09-08 21:36:00 C:\WINDOWS\Tasks\McAfee.com Update Check (DJ-DHOLA-DJ DHoLa).job"
- C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
"2007-09-08 21:36:00 C:\WINDOWS\Tasks\McAfee.com Update Check (DJ-DHOLA-Nirmal).job"
- C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
"2007-09-08 21:35:00 C:\WINDOWS\Tasks\McAfee.com Update Check (DJ-DHOLA-oTHaZ).job"
- C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
.
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-09-08 14:38:32
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-09-08 14:40:16 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-09-08 14:39
C:\ComboFix2.txt ... 2007-09-06 17:54
C:\ComboFix3.txt ... 2007-08-20 12:31
.
--- E O F ---