alright heres the logs,let me know whats next. hard to watch football and do this at the same time…Dallas better pick it up.
EDIT: TaskManager WORKS!!!!!!!!!!!!! MrC your the man, hopefully there aint to much more to do.
ComboFIx Log
ComboFix 07-10-12.4 - Pepsi or Coke 2007-10-14 16:47:14.1 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\Downloads\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\d.exe
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CnsMin.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CnsMin1.zip
C:\Program Files\amsys
C:\Program Files\amsys\awmsg.dat
C:\Program Files\amsys\guid.dat
C:\Program Files\amsys\ijl15.dll
C:\Program Files\amsys\mfc42.dll
C:\Program Files\amsys\msvcrt.dll
C:\Program Files\amsys\unins000.dat
C:\Program Files\amsys\unis000.exe
C:\Program Files\amsys\winam.dat
C:\Program Files\p2pnetworks
C:\Program Files\p2pnetworks\amp2pl.exe
C:\WINDOWS\7search.dll
C:\WINDOWS\aconti.exe
C:\WINDOWS\adbar.dll
C:\WINDOWS\bck1.dat
C:\WINDOWS\bck1.dat
C:\WINDOWS\cbinst$.exe
C:\WINDOWS\daxtime.dll
C:\WINDOWS\dp0.dll
C:\WINDOWS\eventlowg.dll
C:\WINDOWS\fhfmm-Uninstaller.exe
C:\WINDOWS\fhfmm.exe
C:\WINDOWS\flt.dll
C:\WINDOWS\hcwprn.exe
C:\WINDOWS\hotporn.exe
C:\WINDOWS\ie_32.exe
C:\WINDOWS\iexplorr23.dll
C:\WINDOWS\jd2002.dll
C:\WINDOWS\kkcomp$.exe
C:\WINDOWS\kkcomp.dll
C:\WINDOWS\kkcomp.exe
C:\WINDOWS\kvnab$.exe
C:\WINDOWS\kvnab.exe
C:\WINDOWS\liqad$.exe
C:\WINDOWS\liqad.dll
C:\WINDOWS\liqad.exe
C:\WINDOWS\liqui-Uninstaller.exe
C:\WINDOWS\liqui.dll
C:\WINDOWS\liqui.exe
C:\WINDOWS\ngd.dll
C:\WINDOWS\pbsysie.dll
C:\WINDOWS\settn.dll
C:\WINDOWS\spredirect.dll
C:\WINDOWS\system32\gtv_sd.bin
C:\WINDOWS\system32\vxddsk.exe
C:\WINDOWS\vxddsk.exe
C:\WINDOWS\wbeCheck.exe
C:\WINDOWS\wbeInst$.exe
C:\WINDOWS\winh32.exe
C:\WINDOWS\wml.exe
C:\WINDOWS\xadbrk.dll
C:\WINDOWS\xadbrk.exe
C:\WINDOWS\xadbrk_.exe
C:\WINDOWS\xxxvideo.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\LEGACY_ASC3550O
——-\LEGACY_NTMLSVC
——-\NtmlSvc
((((((((((((((((((((((((( Files Created from 2007-09-14 to 2007-10-14 )))))))))))))))))))))))))))))))
.
2007-10-14 16:52 158,432 –a—— C:\WINDOWS\system32\48537aca.sys
2007-10-14 16:46 57,856 –a—— C:\WINDOWS\NirCmd.exe
2007-10-14 15:18 158,432 –a—— C:\WINDOWS\system32\6d38306d.sys
2007-10-14 14:23 51,921 –a—— C:\WINDOWS\system32\detectd2.exe
2007-10-14 14:23 50,176 –a—— C:\WINDOWS\system32\sockver2.dll
2007-10-14 14:23 34,844 –a—— C:\uuuj.exe
2007-10-14 11:04 289,144 –a—— C:\WINDOWS\system32\VCCLSID.exe
2007-10-14 11:04 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2007-10-14 11:04 61,440 –a—— C:\WINDOWS\system32\Process.exe
2007-10-14 11:04 35,840 –a—— C:\WINDOWS\system32\WS2Fix.exe
2007-10-14 10:54 158,496 –a—— C:\WINDOWS\system32\90dbebfb.sys
2007-10-14 10:54 50,176 –a—— C:\WINDOWS\system32\sockver1.dll
2007-10-14 10:54 39,941 –a—— C:\WINDOWS\system32\conf.dat
2007-10-14 10:53 d——– C:\Program Files\SUPERAntiSpyware
2007-10-14 10:53 d——– C:\Documents and Settings\Pepsi or Coke\Application Data\SUPERAntiSpyware.com
2007-10-14 10:53 d——– C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-10-13 16:08 d——– C:\Documents and Settings\Pepsi or Coke\Application Data\Abra Academy2
2007-10-13 12:47 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-10-13 03:18 4 –a—— C:\WINDOWS\system32\stfv.bin
2007-10-13 03:17 d——– C:\WINDOWS\system32\acespy
2007-10-12 17:22 d——– C:\Documents and Settings\Pepsi or Coke\Application Data\ForgottenRiddles
2007-10-12 16:02 d——– C:\Program Files\iWin Games
2007-10-12 15:34 d——– C:\Program Files\Profitville_at
2007-10-12 15:27 d——– C:\Program Files\PiratePoppers_at
2007-10-11 13:47 d——– C:\Documents and Settings\Pepsi or Coke\Application Data\Gearbox Software
2007-10-11 06:09 d——– C:\Program Files\Wise Registry Cleaner
2007-10-11 06:09 d——– C:\Program Files\Wise Disk Cleaner
2007-10-11 03:56 d—s—- C:\Documents and Settings\Pepsi or Coke\UserData
2007-10-11 03:54 d——– C:\WINDOWS\SxsCaPendDel
2007-10-11 03:20 d——– C:\WINDOWS\system32\AGEIA
2007-10-11 03:20 d——– C:\Program Files\AGEIA Technologies
2007-10-11 03:19 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-10-10 15:58 d——– C:\Program Files\Cannon Blast
2007-10-10 12:23 d——– C:\Program Files\Windows Installer Clean Up
2007-10-10 12:23 d——– C:\Program Files\MSECACHE
2007-10-10 07:52 d——– C:\Program Files\SystemRequirementsLab
2007-10-10 07:51 d——– C:\Documents and Settings\Pepsi or Coke\Application Data\SystemRequirementsLab
2007-10-09 18:49 153 –a—— C:\WINDOWS\system32\delFSF.bat
2007-10-08 18:44 d——– C:\Documents and Settings\Pepsi or Coke\Application Data\PlayFirst
2007-10-08 18:44 d——– C:\Documents and Settings\All Users\Application Data\PlayFirst
2007-10-08 10:34 27,648 –a—— C:\whekdwjb.exe
2007-10-08 10:34 19,456 –a—— C:\dcksdix.exe
2007-10-07 20:06 d——– C:\Documents and Settings\Pepsi or Coke\Application Data\Big Fish Games
2007-10-07 19:33 9,216 –a—— C:\WINDOWS\_MSRSTRT.EXE
2007-10-07 11:08 d——– C:\Program Files\Ubisoft
2007-10-06 19:27 d——– C:\Documents and Settings\Pepsi or Coke\Application Data\Legends of pirates
2007-10-05 17:07 438,272 –a—— C:\WINDOWS\system32\vp6vfw.dll
2007-10-05 17:07 118,832 –a—— C:\WINDOWS\system32\SHW32.DLL
2007-10-05 17:01 3,426,072 –a—— C:\WINDOWS\system32\d3dx9_32.dll
2007-10-05 17:01 2,414,360 –a—— C:\WINDOWS\system32\d3dx9_31.dll
2007-10-05 17:01 255,848 –a—— C:\WINDOWS\system32\xactengine2_6.dll
2007-10-05 17:01 251,672 –a—— C:\WINDOWS\system32\xactengine2_5.dll
2007-10-05 17:01 237,848 –a—— C:\WINDOWS\system32\xactengine2_4.dll
2007-10-05 17:01 68,888 –a—— C:\WINDOWS\system32\xinput1_3.dll
2007-10-05 17:01 15,128 –a—— C:\WINDOWS\system32\x3daudio1_1.dll
2007-10-05 14:08 dr-h—– C:\Documents and Settings\Pepsi or Coke\Application Data\SecuROM
2007-10-05 14:08 107,888 –a—— C:\WINDOWS\system32\CmdLineExt.dll
2007-10-05 14:00 d——– C:\Program Files\EA Sports
2007-10-05 12:02 d——– C:\Program Files\USB TWIN SHOCK
2007-10-05 12:02 344,064 –a—— C:\WINDOWS\Property.exe
2007-10-05 12:02 291,840 –a—— C:\WINDOWS\FCVAP64.dll
2007-10-05 12:02 163,904 –a—— C:\WINDOWS\GetWinVer.exe
2007-10-05 12:02 152,064 –a—— C:\WINDOWS\setreg.exe
2007-10-05 12:02 86,016 –a—— C:\WINDOWS\EZFRD64.dll
2007-10-05 08:14 d——– C:\Program Files\PowerISO
2007-10-04 09:07 d——– C:\Documents and Settings\All Users\Application Data\RealArcade
2007-10-02 16:00 d——– C:\Documents and Settings\All Users\Application Data\55-68-q8-17-55-4p
2007-09-29 20:54 d–hs—- C:\WINDOWS\ftpcache
2007-09-24 17:59 d——– C:\Documents and Settings\Pepsi or Coke\Application Data\Pogo Games
2007-09-23 01:11 d——– C:\Program Files\Common Files\LogiShrd
2007-09-15 19:40 d——– C:\Program Files\Star Defender 4
2007-09-14 22:20 10,240 –a—— C:\WINDOWS\CTDCRES.DLL
2007-09-14 22:12 602,112 ——— C:\WINDOWS\system32\ati2sgag.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-14 18:51 ——— d—–w C:\Program Files\Shockwave.com
2007-10-14 17:55 ——— d—–w C:\Program Files\Games
2007-10-14 14:43 ——— d—–w C:\Documents and Settings\Pepsi or Coke\Application Data\Azureus
2007-10-13 21:08 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-10-13 19:47 ——— d—–w C:\Program Files\iWin.com
2007-10-12 22:26 ——— d—–w C:\Documents and Settings\All Users\Application Data\7Wonders2
2007-10-12 19:58 ——— d—–w C:\Program Files\Oberon Media
2007-10-11 08:29 ——— d—–w C:\Program Files\GHOSTHunters_at
2007-10-11 08:27 ——— d—–w C:\Program Files\Azureus
2007-10-11 07:53 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-10-10 19:34 ——— d—–w C:\Program Files\Common Files\Real
2007-10-10 19:05 ——— d—–w C:\Program Files\Common Files\Labtec
2007-10-10 18:59 ——— d—–w C:\Program Files\GameHouse
2007-10-10 11:38 ——— d—–w C:\Program Files\Full Tilt Poker
2007-10-10 09:07 22,328 —-a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-10-07 20:47 ——— d—–w C:\Documents and Settings\Pepsi or Coke\Application Data\LimeWire
2007-10-04 19:11 ——— d–h–r C:\Documents and Settings\Pepsi or Coke\Application Data\yahoo!
2007-10-04 19:11 ——— d—–w C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-10-04 19:09 ——— d—–w C:\Program Files\Yahoo!
2007-10-01 10:55 ——— d—–w C:\Program Files\America's Army
2007-09-23 05:11 ——— d—–w C:\Program Files\Labtec
2007-09-15 02:22 ——— d—–w C:\Program Files\Creative
2007-09-15 02:06 ——— d—–w C:\Program Files\Driver Cleaner Pro
2007-09-14 14:03 ——— d—–w C:\Documents and Settings\Pepsi or Coke\Application Data\GameHouse
2007-09-13 18:58 ——— d—–w C:\Documents and Settings\Pepsi or Coke\Application Data\pixelStorm
2007-09-13 17:39 ——— d—–w C:\Documents and Settings\Pepsi or Coke\Application Data\AlwaysNeat
2007-09-13 04:45 ——— d—–w C:\Program Files\LimeWire
2007-09-12 17:43 ——— d—–w C:\Program Files\MSXML 4.0
2007-09-11 15:12 774,144 —-a-w C:\Program Files\RngInterstitial.dll
2007-09-11 15:12 ——— d—–w C:\Program Files\Real
2007-09-11 12:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\iWin Games
2007-09-10 14:35 ——— d—–w C:\Documents and Settings\Pepsi or Coke\Application Data\vlc
2007-09-10 14:34 ——— d—–w C:\Program Files\VideoLAN
2007-09-09 22:20 ——— d—–w C:\Documents and Settings\Pepsi or Coke\Application Data\iWin
2007-09-09 22:11 ——— d—–w C:\Program Files\Mysteryville
2007-09-09 21:02 ——— d—–w C:\Program Files\ReflexiveArcade
2007-09-09 19:26 ——— d—–w C:\Documents and Settings\Pepsi or Coke\Application Data\SpinTop
2007-09-09 18:27 ——— d—–w C:\Documents and Settings\Pepsi or Coke\Application Data\Mysteryville2
2007-09-09 18:21 ——— d—–w C:\Documents and Settings\All Users\Application Data\Trymedia
2007-09-09 03:36 ——— d—–w C:\Program Files\MSN Messenger
2007-09-09 00:21 ——— d—–w C:\Program Files\NEC DISPLAY SOLUTIONS
2007-09-08 22:13 ——— d—–w C:\Documents and Settings\Pepsi or Coke\Application Data\atitray
2007-09-08 22:12 ——— d—–w C:\Program Files\Ray Adams
2007-09-08 20:22 ——— d—–w C:\Program Files\Common Files\InstallShield
2007-09-08 19:12 ——— d—–w C:\Documents and Settings\All Users\Application Data\n7-89-o9-3r-4t-r9
2007-09-08 10:55 ——— d—–w C:\Program Files\Java
2007-09-08 10:54 ——— d—–w C:\Program Files\Common Files\Java
2007-09-07 22:47 ——— d—–w C:\Documents and Settings\Pepsi or Coke\Application Data\Creative
2007-09-07 22:21 ——— d—–w C:\Program Files\Trend Micro
2007-09-07 22:21 ——— d—–w C:\Documents and Settings\All Users\Application Data\Trend Micro
2007-09-07 22:02 ——— d—–w C:\Program Files\microsoft frontpage
2007-08-22 02:33 46,432 —-a-w C:\WINDOWS\system32\drivers\ativvpxx.vp
2007-08-22 02:07 2,417,664 —-a-w C:\WINDOWS\system32\drivers\ati2mtag.sys
2007-08-22 01:13 49,152 —-a-w C:\WINDOWS\system32\drivers\ati2erec.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe" [2006-08-25 11:25]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-03-06 17:48]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2007-04-09 08:23]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OE"="C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe" [2006-08-18 13:06]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sysfldr]
sysfldr.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
"C:\Program Files\Labtec\WebCam10\WebCam10.exe" /hide
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
C:\Program Files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"usnjsvc"=3 (0x3)
"LVSrvLauncher"=2 (0x2)
R1 atitray;atitray;\??\C:\Program Files\Ray Adams\ATI Tray Tools\atitray.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
AutoRun\command - E:\Autorun.exe
.
**************************************************************************
catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-10-14 16:52:25
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwOpenFile
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-14 16:56:16 - machine was rebooted
.
— E O F —
Hijackthis log
Logfile of HijackThis v1.99.1
Scan saved at 5:01:50 PM, on 10/14/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\HijackThis.exe
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKCU\..\Run: [OE] "C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: sysfldr - sysfldr.dll (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe