This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Very dangerous malware, please help.

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

First of all, here's my log:

Logfile of HijackThis v1.99.1
Scan saved at 1:05:03 PM, on 11/18/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\WNSXS~1\wowexec.exe
C:\Program Files\QdrModule\QdrModule9.exe
C:\Program Files\QdrPack\QdrPack9.exe
C:\Documents and Settings\Owner\Application Data\?ymantec\??plorer.exe
C:\WINDOWS\System32\gearsec.exe
C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\LimeWire\LimeWire 4.0.8\LimeWire.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\laadekgw.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [MMTray] C:\PROGRA~1\MUSICM~1\MUSICM~1\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [482cd4e4] rundll32.exe "C:\WINDOWS\System32\tbmxuxtk.dll",b
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Notn] "C:\WINDOWS\WNSXS~1\wowexec.exe" -vt yazb
O4 - HKCU\..\Run: [QdrModule9] "C:\Program Files\QdrModule\QdrModule9.exe"
O4 - HKCU\..\Run: [QdrPack9] "C:\Program Files\QdrPack\QdrPack9.exe"
O4 - HKCU\..\Run: [Pior] "C:\Documents and Settings\Owner\Application Data\?ymantec\??plorer.exe"
O4 - HKCU\..\Run: [WinAble] C:\Program Files\WinAble\winable.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: IMStart.lnk = C:\Program Files\InterMute\IMStart.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: LimeWire 4.0.8.lnk = C:\Program Files\LimeWire\LimeWire 4.0.8\LimeWire.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1194905396093
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1194905372609
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\System32\dlwmrmfk.exe (file missing)
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe


________________________________________________________________________________
_________

I'm using Windows XP SP1 , and I have also seen many others with my same problem as me, but the way to fix mine will probably be different than anyone elses. there is a yellow caution sign constantly blinking on the toolbar icons, giving me false warnings about trojans, viruses etc. Also two icons popped up when I first got it, but when you delete the 2 icons they just come back . Also a "security toolbar 7.1" was installed or set onto my toolbars without me knowing, and somehow they made it so i would have to uncheck google toolbar to take the view off of it, and vise versa with unchecking security toolbar. Heres what I've tried so far: using ad-aware SE personal (after it deleted the virus, it instantly came back) , using the search option in my computer to find parts of the virus (only found the icons..), putting links it pops me up to on the "restricted sites" list (tools/internet options, security tab–but it didnt work), reformatting my computer but NOT completely – (I used the option to keep data files on my computer). None of these worked, I thought reformatting did, but about 3 hours after it was reformatted it came back. I Searched for this problem on google, I found this website. I looked around the forums and see that you guys are pretty succesful in solving peoples problems, hoping you can solve mine. If I were to ever have another computer problem, this would definently be the place to go. Here are the links and pop up tittles:

www.savetheinformation.com
www.protectroom.com
security alert: NetWorm-i.virus@fp
system alert: Trojan-Spy.win32@mx
W32.Myzor.FK@yf
securityonpage.com
spyware.CyberLog-X

And I hope you don't mind if I have a picture of some of the pop ups, the toolbar, etc too: [external image: Posted Image]


Thanks again for any help that will be given!!! :D —- Please Tell me if a left anything out, or you need more information.

Also, I saw on another person with the same situations topic, it was said this was a very dangerous malware, and tracked sign-ins, etc. So I gave a fake email just to be safe, please use this if you wish to contact me Via E-mail: Mikejones23 (AT)hotmail.com

and it was also said on the topic that the person should change passwords on accounts and such, Should I also do this?
Hello and Welcome to the forum.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.

Open the HijackThis Folder. Find the file HijackThis.exe, Right Click on the file and Select Rename. Rename Hijackthis.exe to Spyware.exe.

After the above:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.


Next:

Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.
Thanks for the reply. I followed the instructions.

heres the logs you requested:



VundoFix V6.6.2

Checking Java version…

Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.4
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.

Scan started at 12:38:49 PM 11/21/2007

Listing files found while scanning….

C:\windows\system32\iwfmliun.dll
C:\WINDOWS\system32\laadekgw.dll
C:\windows\system32\laadekgw.dllbox
C:\windows\system32\mllmm.dll
C:\windows\system32\mmllm.ini
C:\windows\system32\mmllm.ini2

Beginning removal…

Attempting to delete C:\windows\system32\iwfmliun.dll
C:\windows\system32\iwfmliun.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\laadekgw.dll
C:\WINDOWS\system32\laadekgw.dll Has been deleted!

Attempting to delete C:\windows\system32\laadekgw.dllbox
C:\windows\system32\laadekgw.dllbox Has been deleted!

Attempting to delete C:\windows\system32\mllmm.dll
C:\windows\system32\mllmm.dll Has been deleted!

Attempting to delete C:\windows\system32\mmllm.ini
C:\windows\system32\mmllm.ini Has been deleted!

Attempting to delete C:\windows\system32\mmllm.ini2
C:\windows\system32\mmllm.ini2 Has been deleted!

Performing Repairs to the registry.
Done!



Logfile of HijackThis v1.99.1
Scan saved at 1:13:54 PM, on 11/21/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\gearsec.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\WNSXS~1\wowexec.exe
C:\Program Files\QdrModule\QdrModule9.exe
C:\Program Files\QdrPack\QdrPack9.exe
C:\Documents and Settings\Owner\Application Data\?ymantec\??plorer.exe
C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\O1MZCHYV\VundoFix[1].exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Hijackthis\Spyware.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {080ADB38-E56D-4D8E-AF8B-4D87E85BA517} - C:\WINDOWS\System32\sstqo.dll
O2 - BHO: {8427a75c-22eb-170a-2f54-fdc94c342223} - {322243c4-9cdf-45f2-a071-be22c57a7248} - C:\WINDOWS\System32\ylhofaof.dll
O2 - BHO: (no name) - {6D350BE7-3630-4C77-8B4D-C08281546092} - C:\WINDOWS\System32\mllmm.dll (file missing)
O2 - BHO: BndShell3 BHO Class - {875A1348-7674-42aa-ADAC-B4F36A004A2D} - C:\Program Files\QdrDrive\QdrDrive8.dll (file missing)
O2 - BHO: (no name) - {92F8F316-37FB-4522-8B58-4AE600830396} - C:\WINDOWS\System32\rrzcqag.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: (no name) - {BBB05D9E-0297-404D-A6BF-D8F2876B84A6} - C:\WINDOWS\System32\vtuvwuu.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {C2FAF744-62F8-4C23-DA58-4AE600835991} - C:\WINDOWS\System32\ouos.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {11A69AE4-FBED-4832-A2BF-45AF82825583} - (no file)
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [MMTray] C:\PROGRA~1\MUSICM~1\MUSICM~1\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [482cd4e4] rundll32.exe "C:\WINDOWS\System32\lugcnqsl.dll",b
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Notn] "C:\WINDOWS\WNSXS~1\wowexec.exe" -vt yazb
O4 - HKCU\..\Run: [QdrModule9] "C:\Program Files\QdrModule\QdrModule9.exe"
O4 - HKCU\..\Run: [QdrPack9] "C:\Program Files\QdrPack\QdrPack9.exe"
O4 - HKCU\..\Run: [Pior] "C:\Documents and Settings\Owner\Application Data\?ymantec\??plorer.exe"
O4 - HKCU\..\Run: [WinAble] C:\Program Files\WinAble\winable.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: IMStart.lnk = C:\Program Files\InterMute\IMStart.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: LimeWire 4.0.8.lnk = C:\Program Files\LimeWire\LimeWire 4.0.8\LimeWire.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1194905396093
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1194905372609
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: vtuvwuu - C:\WINDOWS\SYSTEM32\vtuvwuu.dll
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\System32\dlwmrmfk.exe (file missing)
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
You still have some bad guys.

Download ComboFix from Here to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you, combofix.txt. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick while its running. That may cause it to stall
Alright, I followed the prompts, it rebooted my computer, and now it says it's creating a log for me. There might not be anything wrong, but it's been stuck at "Preparing log report. Do not run any programs until combofix is finished. FINDSTR: Search string too long" for about 10 minutes now, what should I do? close it and click on combofix?
by the way, it's looking alot better! no security toolbar, pop ups or anything

Heres the logs:

ComboFix 07-11-19.3 - Owner 2007-11-21 16:13:45.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.12 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\ddcyy.dll
C:\WINDOWS\system32\yycdd.ini
C:\WINDOWS\system32\yycdd.ini2
.
—- Previous Run ——-
.
C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\Owner\Application Data\Install.dat
C:\Documents and Settings\Owner\Application Data\macromedia\Flash Player\#SharedObjects\4VR459QX\www.broadcaster.com
C:\Documents and Settings\Owner\Application Data\macromedia\Flash Player\#SharedObjects\4VR459QX\www.broadcaster.com\played_list.sol
C:\Documents and Settings\Owner\Application Data\macromedia\Flash Player\#SharedObjects\4VR459QX\www.broadcaster.com\video_queue.sol
C:\Documents and Settings\Owner\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\Documents and Settings\Owner\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol
C:\Documents and Settings\Owner\Application Data\Sskcwrd.dll
C:\Documents and Settings\Owner\Application Data\Sskknwrd.dll
C:\Documents and Settings\Owner\Application Data\Sskuknwrd.dll
C:\Documents and Settings\Owner\Application Data\YMANTE~1
C:\Documents and Settings\Owner\Application Data\YMANTE~1\??plorer.exe
C:\Documents and Settings\Owner\Desktop\Live Safety Center.lnk
C:\Documents and Settings\Owner\Desktop\Online Security Guide.lnk
C:\Documents and Settings\Owner\Favorites\Online Security Guide.lnk
C:\Documents and Settings\Owner\Start Menu\Programs\Internet Speed Monitor
C:\Documents and Settings\Owner\Start Menu\Programs\Internet Speed Monitor\Check Now.lnk
C:\Documents and Settings\Owner\Start Menu\Programs\Internet Speed Monitor\Uninstall.lnk
C:\Documents and Settings\Owner\Start Menu\Programs\Outerinfo
C:\Documents and Settings\Owner\Start Menu\Programs\Outerinfo\Terms.lnk
C:\Documents and Settings\Owner\Start Menu\Programs\Outerinfo\Uninstall.lnk
C:\Program Files\Common Files\WinSoftware
C:\Program Files\Common Files\Yazzle1552OinAdmin.exe
C:\Program Files\Common Files\Yazzle1552OinUninstaller.exe
C:\Program Files\outerinfo
C:\Program Files\outerinfo\FF\chrome.manifest
C:\Program Files\outerinfo\FF\components\FF.dll
C:\Program Files\outerinfo\FF\components\OuterinfoAds.xpt
C:\Program Files\outerinfo\FF\install.rdf
C:\Program Files\outerinfo\Terms.rtf
C:\Program Files\QdrPack
C:\Program Files\QdrPack\dicts.gz
C:\Program Files\QdrPack\QdrPack9.exe
C:\Program Files\QdrPack\trgts.gz
C:\Program Files\TBONAS
C:\Program Files\TBONAS\update.zip
C:\Program Files\Temporary
C:\Program Files\WinAble
C:\WINDOWS\bundles
C:\WINDOWS\bundles\2504040901.exe
C:\WINDOWS\bundles\49gh43sd.exe
C:\WINDOWS\bundles\77_350_i.exe
C:\WINDOWS\bundles\adv0ltc0m.exe_
C:\WINDOWS\bundles\CSV7P070.exe_
C:\WINDOWS\bundles\d_otbp.exe_
C:\WINDOWS\bundles\dealhelper.exe_
C:\WINDOWS\bundles\HelperInstaller.exe_
C:\WINDOWS\bundles\ICMedia-350.exe
C:\WINDOWS\bundles\james_dh.exe
C:\WINDOWS\bundles\omni2.exe
C:\WINDOWS\bundles\optimizejames.exe_
C:\WINDOWS\bundles\runsearch.exe_
C:\WINDOWS\bundles\s4Sept.exe_
C:\WINDOWS\bundles\saie1101.exe_
C:\WINDOWS\bundles\setup_silent_25040.exe
C:\WINDOWS\bundles\setup_silent_26221.exe_
C:\WINDOWS\bundles\setup356.exe
C:\WINDOWS\bundles\shopinst.exe_
C:\WINDOWS\bundles\thin-117-1-x-x.exe
C:\WINDOWS\bundles\TVM_B5_Bundle_8.EXE
C:\WINDOWS\bundles\txdesuf.exe_
C:\WINDOWS\bundles\vl_ezstub.exe_
C:\WINDOWS\cookies.ini
C:\WINDOWS\Downloaded Program Files.\file.exe
C:\WINDOWS\Downloaded Program Files\UWFX5LP_0001_0715NetInstaller.exe
C:\WINDOWS\system32\oqtss.ini
C:\WINDOWS\system32\oqtss.ini2
C:\WINDOWS\system32\ouos.dll
C:\WINDOWS\system32\sembly~1
C:\WINDOWS\system32\sstqo.dll
C:\WINDOWS\system32\wtstr.exe
C:\WINDOWS\wnsxs~1
C:\WINDOWS\wnsxs~1\W?nSxS\
C:\WINDOWS\wnsxs~1\wowexec.exe
D:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_DOMAINSERVICE
——-\DomainService




((((((((((((((((((((((((( Files Created from 2007-10-21 to 2007-11-21 )))))))))))))))))))))))))))))))
.

2007-11-21 16:22 0 C:\WINDOWS\system32\lsqncgul.tmp
2007-11-21 12:38 d——– C:\VundoFix Backups
2007-11-21 03:52 1,754,577 —hs—- C:\WINDOWS\system32\lsqncgul.ini
2007-11-21 03:52 85,056 –a—— C:\WINDOWS\system32\lugcnqsl.dll
2007-11-21 03:52 80,960 –a—— C:\WINDOWS\system32\ylhofaof.dll
2007-11-21 03:52 71,232 –a—— C:\WINDOWS\system32\togavrkn.exe
2007-11-20 03:57 84,544 –a—— C:\WINDOWS\system32\amsswaah.dll
2007-11-20 03:54 688,812 —hs—- C:\WINDOWS\system32\sjntdvtd.ini
2007-11-20 03:54 85,056 –a—— C:\WINDOWS\system32\dtvdtnjs.dll
2007-11-18 22:44 79,424 –a—— C:\WINDOWS\system32\ypxlxatb.dll
2007-11-18 22:41 688,660 —hs—- C:\WINDOWS\system32\edcphxqi.ini
2007-11-18 22:38 71,232 –a—— C:\WINDOWS\system32\yonkmexx.exe
2007-11-17 23:41 d——– C:\Documents and Settings\All Users\Application Data\Google Updater
2007-11-17 23:04 0 –a—— C:\WINDOWS\system32\mcrh.tmp
2007-11-17 22:48 678,220 —hs—- C:\WINDOWS\system32\ktxuxmbt.ini
2007-11-17 22:47 85,056 –a—— C:\WINDOWS\system32\tbmxuxtk.dll
2007-11-17 15:12 2,238 –a—— C:\WINDOWS\system32\ClickToFindandFixErrors_US.ico
2007-11-17 08:28 d——– C:\Program Files\QdrModule
2007-11-17 08:27 d——– C:\Program Files\QdrDrive
2007-11-17 08:27 36,352 –a—— C:\WINDOWS\system32\vtuvwuu.dll
2007-11-17 08:27 35,840 –a—— C:\WINDOWS\mrofinu72.exe
2007-11-13 23:27 d——– C:\Program Files\SymNetDrv
2007-11-13 06:19 159,744 –a—— C:\WINDOWS\system32\igfxres.dll
2007-11-13 05:56 593,408 —–c— C:\WINDOWS\system32\dllcache\xpsp2res.dll
2007-11-13 05:43 134,272 –a—— C:\WINDOWS\system32\drivers\portcls.sys
2007-11-13 05:43 134,272 –a–c— C:\WINDOWS\system32\dllcache\portcls.sys
2007-11-13 05:43 57,856 –a—— C:\WINDOWS\system32\drivers\drmk.sys
2007-11-13 05:40 831,519 –a–c— C:\WINDOWS\system32\dllcache\mswdat10.dll
2007-11-13 05:40 614,431 –a–c— C:\WINDOWS\system32\dllcache\mswstr10.dll
2007-11-13 05:40 380,957 –a—— C:\WINDOWS\system32\expsrv.dll
2007-11-13 05:40 348,189 –a–c— C:\WINDOWS\system32\dllcache\msxbde40.dll
2007-11-13 05:40 258,077 –a—— C:\WINDOWS\system32\mstext40.dll
2007-11-13 05:40 258,077 –a–c— C:\WINDOWS\system32\dllcache\mstext40.dll
2007-11-13 05:40 30,749 –a—— C:\WINDOWS\system32\vbajet32.dll
2007-11-13 05:40 30,749 –a–c— C:\WINDOWS\system32\dllcache\vbajet32.dll
2007-11-12 22:05 21,760 –a–c— C:\WINDOWS\system32\dllcache\usbstor.sys
2007-11-12 17:54 209,280 –a–c— C:\WINDOWS\system32\dllcache\update.sys
2007-11-12 17:53 991,232 –a—— C:\WINDOWS\system32\esent.dll
2007-11-12 17:50 595,968 –a—— C:\WINDOWS\system32\xpsp2res.dll
2007-11-12 17:50 307,200 –a–c— C:\WINDOWS\system32\dllcache\netapi32.dll
2007-11-12 17:50 260,096 –a—— C:\WINDOWS\system32\mstask.dll
2007-11-12 17:50 260,096 –a–c— C:\WINDOWS\system32\dllcache\mstask.dll
2007-11-12 17:50 172,544 –a–c— C:\WINDOWS\system32\dllcache\schedsvc.dll
2007-11-12 17:50 10,752 –a–c— C:\WINDOWS\system32\dllcache\mstinit.exe
2007-11-12 17:18 22,752 –a—— C:\WINDOWS\system32\spupdsvc.exe
2007-11-12 17:16 d——– C:\WINDOWS\system32\bits
2007-11-12 17:13 361,984 –a–c— C:\WINDOWS\system32\dllcache\qmgr.dll
2007-11-12 17:13 331,776 –a—— C:\WINDOWS\system32\winhttp.dll
2007-11-12 17:13 331,776 –a–c— C:\WINDOWS\system32\dllcache\winhttp.dll
2007-11-12 17:13 17,408 –a–c— C:\WINDOWS\system32\dllcache\qmgrprxy.dll
2007-11-12 17:13 7,680 —–c— C:\WINDOWS\system32\dllcache\bitsprx2.dll
2007-11-12 17:13 7,680 ——— C:\WINDOWS\system32\bitsprx2.dll
2007-11-12 17:13 7,168 —–c— C:\WINDOWS\system32\dllcache\bitsprx3.dll
2007-11-12 17:13 7,168 ——— C:\WINDOWS\system32\bitsprx3.dll
2007-11-12 17:10 549,720 –a—— C:\WINDOWS\system32\wuapi.dll
2007-11-12 17:10 325,976 –a—— C:\WINDOWS\system32\wucltui.dll
2007-11-12 17:10 216,408 –a—— C:\WINDOWS\system32\wuaucpl.cpl
2007-11-12 17:10 43,352 –a—— C:\WINDOWS\system32\wups2.dll
2007-11-12 17:10 34,136 –a—— C:\WINDOWS\system32\wucltui.dll.mui
2007-11-12 17:10 33,624 –a—— C:\WINDOWS\system32\wups.dll
2007-11-12 17:10 25,944 –a—— C:\WINDOWS\system32\wuaucpl.cpl.mui
2007-11-12 17:10 25,944 –a—— C:\WINDOWS\system32\wuapi.dll.mui
2007-11-12 17:10 20,312 –a—— C:\WINDOWS\system32\wuaueng.dll.mui
2007-11-11 18:06 208,896 –a—— C:\WINDOWS\system32\wmpns.dll
2007-11-11 17:24 d——– C:\Program Files\7-Zip
2007-11-11 16:48 d——– C:\Documents and Settings\Owner\Application Data\Musicmatch
2007-11-11 16:13 d——– C:\Documents and Settings\Owner\Shared
2007-11-11 16:11 d——– C:\Documents and Settings\Owner\Incomplete
2007-11-11 16:05 3,620 -rahs—- C:\WINDOWS\system32\drivers\HP_PC130A-ABA SR1111NX NA430_YC_Pres_QMXQ422_E43NAheREG3_4_IGamila Giovani Neon series_SMICRO-STAR INTERNATIONAL CO., LTD_V030_B3.10_T040415_WXH1_L409_M248_J40_7Intel_8Celeron_92.53_1_N10EC8139_P_Z_
K_A808624C5_U808624C2.MRK
2007-11-11 16:03 d——– C:\WINDOWS\system32\config\systemprofile\WINDOWS
2007-11-11 16:03 593,408 –a—— C:\WINDOWS\system32\h323msp.dll
2007-11-11 16:03 548,352 –a–c— C:\WINDOWS\system32\dllcache\rtcdll.dll
2007-11-11 16:03 439,808 –a—— C:\WINDOWS\system32\ipnathlp.dll
2007-11-11 16:03 364,544 –a–c— C:\WINDOWS\system32\dllcache\callcont.dll
2007-11-11 16:03 253,952 –a–c— C:\WINDOWS\system32\dllcache\mst120.dll
2007-11-11 16:03 253,440 –a—— C:\WINDOWS\system32\h323.tsp
2007-11-11 16:03 73,728 –a–c— C:\WINDOWS\system32\dllcache\nmcom.dll
2007-11-11 16:03 40,960 —–c— C:\WINDOWS\system32\dllcache\evtgprov.dll
2007-11-11 16:03 36,864 –a—— C:\WINDOWS\system32\mf3216.dll
2007-11-11 16:02 974,336 –a—— C:\WINDOWS\system32\msdtctm.dll
2007-11-11 16:02 499,200 –a—— C:\WINDOWS\system32\comuid.dll
2007-11-11 16:02 368,640 –a—— C:\WINDOWS\system32\msdtcprx.dll
2007-11-11 16:02 220,672 –a–c— C:\WINDOWS\system32\dllcache\catsrv.dll
2007-11-11 16:02 150,528 –a—— C:\WINDOWS\system32\msdtcuiu.dll
2007-11-11 16:02 110,080 –a—— C:\WINDOWS\system32\clbcatex.dll
2007-11-11 16:02 97,280 –a—— C:\WINDOWS\system32\txflog.dll
2007-11-11 16:02 97,280 –a–c— C:\WINDOWS\system32\dllcache\txflog.dll
2007-11-11 16:02 83,456 –a–c— C:\WINDOWS\system32\dllcache\mtxoci.dll
2007-11-11 16:02 64,512 –a–c— C:\WINDOWS\system32\dllcache\mtxclu.dll
2007-11-11 15:59 51,072 –a—— C:\WINDOWS\system32\drivers\i8042prt.sys
2007-11-11 15:59 23,424 –a—— C:\WINDOWS\system32\drivers\kbdclass.sys
2007-11-11 14:23 dr-hsc— C:\WINDOWS\system32\dllcache
2007-11-09 21:48 d——– C:\Program Files\styleamen
2007-11-03 12:44 d——– C:\Documents and Settings\All Users\Application Data\Apple

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{322243c4-9cdf-45f2-a071-be22c57a7248}]
2007-11-21 03:52 80960 –a—— C:\WINDOWS\System32\ylhofaof.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D350BE7-3630-4C77-8B4D-C08281546092}]
C:\WINDOWS\System32\mllmm.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{875A1348-7674-42aa-ADAC-B4F36A004A2D}]
C:\Program Files\QdrDrive\QdrDrive8.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{92F8F316-37FB-4522-8B58-4AE600830396}]
C:\WINDOWS\System32\rrzcqag.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BBB05D9E-0297-404D-A6BF-D8F2876B84A6}]
2007-11-17 08:27 36352 –a—— C:\WINDOWS\System32\vtuvwuu.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2002-08-21 01:08]
"Notn"="C:\WINDOWS\WNSXS~1\wowexec.exe" []
"QdrModule9"="C:\Program Files\QdrModule\QdrModule9.exe" [2007-11-01 14:51]
"Pior"="C:\Documents and Settings\Owner\Application Data\?ymantec\??plorer.exe" []
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-17 23:42]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2004-04-02 03:49]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 19:04]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2004-08-20 15:51]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 22:02]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-04-02 04:43]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2004-01-16 22:16]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-13 23:43]
"VTTimer"="VTTimer.exe" []
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2003-08-15 03:59]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2003-09-12 22:13]
"Reminder"="C:\Windows\Creator\Remind_XP.exe" [2003-12-18 02:31]
"MMTray"="C:\PROGRA~1\MUSICM~1\MUSICM~1\mm_tray.exe" [2006-01-17 13:03]
"mmtask"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe" [2006-01-17 13:03]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 13:47 C:\WINDOWS\ALCXMNTR.EXE]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2004-08-20 15:55]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2007-11-13 23:27]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2004-04-02 05:04]
"482cd4e4"="C:\WINDOWS\System32\lugcnqsl.dll" [2007-11-21 03:52]

C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
IMStart.lnk - C:\Program Files\InterMute\IMStart.exe [2004-04-02 05:02:27]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 01:05:26]
Compaq Connections.lnk - C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe [2004-04-02 19:04:03]
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-11-17 23:41:55]
LimeWire 4.0.8.lnk - C:\Program Files\LimeWire\LimeWire 4.0.8\LimeWire.exe [2004-07-14 13:03:16]

[hklm\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{BBB05D9E-0297-404D-A6BF-D8F2876B84A6}"= C:\WINDOWS\System32\vtuvwuu.dll [2007-11-17 08:27 36352]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtuvwuu]
vtuvwuu.dll 2007-11-17 08:27 36352 C:\WINDOWS\system32\vtuvwuu.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\System32\ddcyy.dll


.
Contents of the 'Scheduled Tasks' folder
"2007-11-21 21:00:00 C:\WINDOWS\Tasks\AF5BC035918C71A9.job"
- c:\docume~1\owner\applic~1\stylea~1\Second Great Bags.exe
"2007-11-19 13:24:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2006-11-06 01:40:59 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job"
- c:\PROGRA~1\NORTON~1\Navw32.exeh/task:
"2007-11-14 04:24:08 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-21 16:22:49
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-21 16:26:13 - machine was rebooted
.
— E O F —










Logfile of HijackThis v1.99.1
Scan saved at 4:33:15 PM, on 11/21/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\gearsec.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\mm_tray.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\QdrModule\QdrModule9.exe
C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\LimeWire\LimeWire 4.0.8\LimeWire.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Hijackthis\Spyware.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: {8427a75c-22eb-170a-2f54-fdc94c342223} - {322243c4-9cdf-45f2-a071-be22c57a7248} - C:\WINDOWS\System32\ylhofaof.dll
O2 - BHO: (no name) - {6D350BE7-3630-4C77-8B4D-C08281546092} - C:\WINDOWS\System32\mllmm.dll (file missing)
O2 - BHO: BndShell3 BHO Class - {875A1348-7674-42aa-ADAC-B4F36A004A2D} - C:\Program Files\QdrDrive\QdrDrive8.dll (file missing)
O2 - BHO: (no name) - {92F8F316-37FB-4522-8B58-4AE600830396} - C:\WINDOWS\System32\rrzcqag.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: (no name) - {BBB05D9E-0297-404D-A6BF-D8F2876B84A6} - C:\WINDOWS\System32\vtuvwuu.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [MMTray] C:\PROGRA~1\MUSICM~1\MUSICM~1\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [482cd4e4] rundll32.exe "C:\WINDOWS\System32\lugcnqsl.dll",b
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Notn] "C:\WINDOWS\WNSXS~1\wowexec.exe" -vt yazb
O4 - HKCU\..\Run: [QdrModule9] "C:\Program Files\QdrModule\QdrModule9.exe"
O4 - HKCU\..\Run: [Pior] "C:\Documents and Settings\Owner\Application Data\?ymantec\??plorer.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: IMStart.lnk = C:\Program Files\InterMute\IMStart.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: LimeWire 4.0.8.lnk = C:\Program Files\LimeWire\LimeWire 4.0.8\LimeWire.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1194905396093
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1194905372609
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: vtuvwuu - C:\WINDOWS\SYSTEM32\vtuvwuu.dll
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
Well all was looking good until just now, I turned on the monitor and there was savetheinformation.com and the pop ups again. This could have been caused by me not replying soon enough yesterday, since you said some more malware was on my pc. To get to the point, I redid all the steps you gave me before and have new logs —> I hope it's enough to start where we left off wednesday..sorry for any extra trouble. Heres the New Vundofix and Hijack log:



VundoFix V6.6.2

Checking Java version…

Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.4
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.

Scan started at 5:59:44 PM 11/22/2007

Listing files found while scanning….

C:\windows\system32\xhpnadcm.dll
C:\WINDOWS\System32\yudkzaak.dll
C:\windows\system32\yudkzaak.dllbox

Beginning removal…

Attempting to delete C:\windows\system32\xhpnadcm.dll
C:\windows\system32\xhpnadcm.dll Has been deleted!

Attempting to delete C:\WINDOWS\System32\yudkzaak.dll
C:\WINDOWS\System32\yudkzaak.dll Could not be deleted.

Attempting to delete C:\windows\system32\yudkzaak.dllbox
C:\windows\system32\yudkzaak.dllbox Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal…

Attempting to delete C:\WINDOWS\System32\yudkzaak.dll
C:\WINDOWS\System32\yudkzaak.dll Has been deleted!

Performing Repairs to the registry.
Done!






Logfile of HijackThis v1.99.1
Scan saved at 6:43:47 PM, on 11/22/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\qdwclhnl.exe
C:\WINDOWS\System32\gearsec.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\mrofinu572.exe
C:\Program Files\QdrModule\QdrModule9.exe
C:\Program Files\Insider\Insider.exe
C:\Documents and Settings\Owner\Application Data\WinTouch\WinTouch.exe
C:\Documents and Settings\Owner\Application Data\Microsoft\Windows\ckjkufj.exe
C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Hijackthis\Spyware.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: {f1348e8f-7a1c-7429-35a4-d495b5a033b6} - {6b330a5b-594d-4a53-9247-c1a7f8e8431f} - C:\WINDOWS\System32\evatupkm.dll
O2 - BHO: (no name) - {6D350BE7-3630-4C77-8B4D-C08281546092} - C:\WINDOWS\System32\mllmm.dll (file missing)
O2 - BHO: BndShell3 BHO Class - {875A1348-7674-42aa-ADAC-B4F36A004A2D} - C:\Program Files\QdrDrive\QdrDrive8.dll (file missing)
O2 - BHO: (no name) - {8F9F61A0-6BEA-44AF-B739-CF10C81EF3D0} - C:\WINDOWS\System32\ddaby.dll
O2 - BHO: (no name) - {92F8F316-37FB-4522-8B58-4AE600830396} - C:\WINDOWS\System32\rrzcqag.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: (no name) - {BBB05D9E-0297-404D-A6BF-D8F2876B84A6} - C:\WINDOWS\System32\vtuvwuu.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {11A69AE4-FBED-4832-A2BF-45AF82825583} - (no file)
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu572.exe 61A847B5BBF728173599284503996897C881250221C8670836AC4FA7C8833201749139
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\AntiSpywareSuite\bm.exe" dm=http://antispywaresuite.com; ad=http://antispywaresuite.com
O4 - HKLM\..\Run: [rtasks] C:\Program Files\AntiSpywareSuite\rtasks.exe
O4 - HKLM\..\Run: [482cd4e4] rundll32.exe "C:\WINDOWS\System32\aekttrty.dll",b
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [QdrModule9] "C:\Program Files\QdrModule\QdrModule9.exe"
O4 - HKCU\..\Run: [Pior] "C:\Documents and Settings\Owner\Application Data\?ymantec\??plorer.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Insider] C:\Program Files\Insider\Insider.exe
O4 - HKCU\..\Run: [WinTouch] C:\Documents and Settings\Owner\Application Data\WinTouch\WinTouch.exe
O4 - HKCU\..\Run: [SfKg6w] C:\Documents and Settings\Owner\Application Data\Microsoft\Windows\ckjkufj.exe
O4 - Startup: IMStart.lnk = C:\Program Files\InterMute\IMStart.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: LimeWire 4.0.8.lnk = C:\Program Files\LimeWire\LimeWire 4.0.8\LimeWire.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1194905396093
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1194905372609
O16 - DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} - http://awbeta.net-nucleus.com/FIX/WinATS.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: vtuvwuu - C:\WINDOWS\SYSTEM32\vtuvwuu.dll
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: DomainService - - C:\WINDOWS\System32\qdwclhnl.exe
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe






Heres the New Combofix and Hijackthis logs:

ComboFix 07-11-19.3 - Owner 2007-11-22 18:50:21.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.55 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.

Unable to gain System Privileges

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data.\salesmonitor
C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Documents and Settings\LocalService\Application Data\NetMon\domains.txt
C:\Documents and Settings\LocalService\Application Data\NetMon\log.txt
C:\Documents and Settings\Owner\Application Data\PPATCH~1
C:\Documents and Settings\Owner\Application Data\WinTouch\wintouch.cfg
C:\Documents and Settings\Owner\Application Data\WinTouch\WinTouch.exe
C:\Documents and Settings\Owner\Application Data\WinTouch\WTUninstaller.exe
C:\Program Files\AntiSpywareSuite
C:\Program Files\AntiSpywareSuite\history.db
C:\Program Files\AntiSpywareSuite\ResErrors.log
C:\Program Files\Common Files\mqzo
C:\Program Files\Common Files\mqzo\mqzoa.exe
C:\Program Files\Common Files\mqzo\mqzoa.lck
C:\Program Files\Common Files\mqzo\mqzod\class-barrel
C:\Program Files\Common Files\mqzo\mqzod\mqzoc.dll
C:\Program Files\Common Files\mqzo\mqzod\vocabulary
C:\Program Files\Common Files\mqzo\mqzol.exe
C:\Program Files\Common Files\mqzo\mqzol.lck
C:\Program Files\Common Files\mqzo\mqzom.lck
C:\Program Files\Common Files\mqzo\mqzop.exe
C:\Program Files\Common Files\mqzo\mqzop.lck
C:\Program Files\inetget2
C:\Program Files\Insider
C:\Program Files\Insider\Insider.exe
C:\Program Files\Insider\UnInstall.exe
C:\Program Files\network monitor
C:\Program Files\network monitor\netmon.exe
C:\Program Files\WindowsUpdate\rtelebipr.html
C:\UGA6P
C:\WINDOWS\b104.exe
C:\WINDOWS\b111.exe
C:\WINDOWS\b128.exe
C:\WINDOWS\b138.exe
C:\WINDOWS\b147.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\IA
C:\WINDOWS\IA\KE.vbs
C:\WINDOWS\mqzo
C:\WINDOWS\mqzo\mqzo.dat
C:\WINDOWS\mqzo\wu
C:\WINDOWS\system32\ddaby.dll
C:\WINDOWS\system32\winnb58.dll
C:\WINDOWS\system32\ybadd.ini
C:\WINDOWS\system32\ybadd.ini2
C:\WINDOWS\system32\yudkzaak.dllbox
C:\WINDOWS\uninstall_nmon.vbs

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_CMDSERVICE
——-\LEGACY_DOMAINSERVICE
——-\LEGACY_NETWORK_MONITOR
——-\cmdService
——-\DomainService


((((((((((((((((((((((((( Files Created from 2007-10-23 to 2007-11-23 )))))))))))))))))))))))))))))))
.

2007-11-22 18:52 20,810 —hs—- C:\WINDOWS\system32\gdqrjiln.dllbox
2007-11-22 18:51 145,984 –a—— C:\WINDOWS\system32\gdqrjiln.dll
2007-11-22 18:39 79,936 –a—— C:\WINDOWS\system32\evatupkm.dll
2007-11-22 18:36 1,841,657 –ahs—- C:\WINDOWS\system32\ytrttkea.ini
2007-11-22 18:36 85,056 –a—— C:\WINDOWS\system32\aekttrty.dll
2007-11-22 18:36 71,232 –a—— C:\WINDOWS\system32\eewdssov.exe
2007-11-22 17:25 1,843,829 –ahs—- C:\WINDOWS\system32\dypaftdt.ini
2007-11-22 17:19 79,936 –a—— C:\WINDOWS\system32\uhofgyrq.dll
2007-11-22 17:16 71,232 –a—— C:\WINDOWS\system32\qdwclhnl.exe
2007-11-21 17:02 36,864 –a—— C:\WINDOWS\system32\vtusqno.dll
2007-11-21 17:01 36,864 –a—— C:\WINDOWS\system32\ssqrrpq.dll
2007-11-21 17:01 35,840 –a—— C:\WINDOWS\17PHolmes572.exe
2007-11-21 16:59 d——– C:\Documents and Settings\Owner\Application Data\AntiSpywareSuite
2007-11-21 16:58 1,060,864 –a—— C:\WINDOWS\system32\mfc71.dll
2007-11-21 16:58 499,712 –a—— C:\WINDOWS\system32\msvcp71.dll
2007-11-21 16:58 348,160 –a—— C:\WINDOWS\system32\msvcr71.dll
2007-11-21 16:58 89,088 –a—— C:\WINDOWS\system32\atl71.dll
2007-11-21 16:58 24,064 –a—— C:\WINDOWS\system32\msxml3a.dll
2007-11-21 16:57 35,840 –a—— C:\WINDOWS\mrofinu572.exe
2007-11-21 16:56 36,864 –a—— C:\WINDOWS\system32\rqrrppq.dll
2007-11-21 12:38 d——– C:\VundoFix Backups
2007-11-21 03:52 71,232 –a—— C:\WINDOWS\system32\togavrkn.exe
2007-11-20 03:57 84,544 –a—— C:\WINDOWS\system32\amsswaah.dll
2007-11-20 03:54 688,812 –ahs—- C:\WINDOWS\system32\sjntdvtd.ini
2007-11-20 03:54 85,056 –a—— C:\WINDOWS\system32\dtvdtnjs.dll
2007-11-20 03:49 71,232 –a—— C:\WINDOWS\system32\qcnqttaj.exe
2007-11-18 22:44 79,424 –a—— C:\WINDOWS\system32\ypxlxatb.dll
2007-11-18 22:41 688,660 –ahs—- C:\WINDOWS\system32\edcphxqi.ini
2007-11-18 22:38 71,232 –a—— C:\WINDOWS\system32\yonkmexx.exe
2007-11-17 23:41 d——– C:\Documents and Settings\All Users\Application Data\Google Updater
2007-11-17 22:47 85,056 –a—— C:\WINDOWS\system32\tbmxuxtk.dll
2007-11-17 15:12 2,238 –a—— C:\WINDOWS\system32\ClickToFindandFixErrors_US.ico
2007-11-17 08:28 d——– C:\Program Files\QdrModule
2007-11-17 08:27 d——– C:\Program Files\QdrDrive
2007-11-17 08:27 36,352 –a—— C:\WINDOWS\system32\vtuvwuu.dll
2007-11-17 08:27 35,840 –a—— C:\WINDOWS\mrofinu72.exe
2007-11-13 23:27 d——– C:\Program Files\SymNetDrv
2007-11-13 05:56 593,408 –a–c— C:\WINDOWS\system32\dllcache\xpsp2res.dll
2007-11-13 05:43 134,272 –a—— C:\WINDOWS\system32\drivers\portcls.sys
2007-11-13 05:43 134,272 –a–c— C:\WINDOWS\system32\dllcache\portcls.sys
2007-11-13 05:43 57,856 –a—— C:\WINDOWS\system32\drivers\drmk.sys
2007-11-13 05:40 831,519 –a—— C:\WINDOWS\system32\mswdat10.dll
2007-11-13 05:40 831,519 –a–c— C:\WINDOWS\system32\dllcache\mswdat10.dll
2007-11-13 05:40 614,431 –a—— C:\WINDOWS\system32\mswstr10.dll
2007-11-13 05:40 614,431 –a–c— C:\WINDOWS\system32\dllcache\mswstr10.dll
2007-11-13 05:40 380,957 –a—— C:\WINDOWS\system32\expsrv.dll
2007-11-13 05:40 348,189 –a—— C:\WINDOWS\system32\msxbde40.dll
2007-11-13 05:40 348,189 –a–c— C:\WINDOWS\system32\dllcache\msxbde40.dll
2007-11-13 05:40 258,077 –a—— C:\WINDOWS\system32\mstext40.dll
2007-11-13 05:40 258,077 –a–c— C:\WINDOWS\system32\dllcache\mstext40.dll
2007-11-13 05:40 30,749 –a—— C:\WINDOWS\system32\vbajet32.dll
2007-11-13 05:40 30,749 –a–c— C:\WINDOWS\system32\dllcache\vbajet32.dll
2007-11-12 22:05 21,760 –a–c— C:\WINDOWS\system32\dllcache\usbstor.sys
2007-11-12 17:54 209,280 –a–c— C:\WINDOWS\system32\dllcache\update.sys
2007-11-12 17:53 991,232 –a—— C:\WINDOWS\system32\esent.dll
2007-11-12 17:50 595,968 –a—— C:\WINDOWS\system32\xpsp2res.dll
2007-11-12 17:50 307,200 –a–c— C:\WINDOWS\system32\dllcache\netapi32.dll
2007-11-12 17:50 260,096 –a—— C:\WINDOWS\system32\mstask.dll
2007-11-12 17:50 260,096 –a–c— C:\WINDOWS\system32\dllcache\mstask.dll
2007-11-12 17:50 172,544 –a—— C:\WINDOWS\system32\schedsvc.dll
2007-11-12 17:50 172,544 –a–c— C:\WINDOWS\system32\dllcache\schedsvc.dll
2007-11-12 17:50 10,752 –a—— C:\WINDOWS\system32\mstinit.exe
2007-11-12 17:50 10,752 –a–c— C:\WINDOWS\system32\dllcache\mstinit.exe
2007-11-12 17:40 271,224 –a—— C:\WINDOWS\system32\mucltui.dll
2007-11-12 17:40 30,072 –a—— C:\WINDOWS\system32\mucltui.dll.mui
2007-11-12 17:18 22,752 –a—— C:\WINDOWS\system32\spupdsvc.exe
2007-11-12 17:16 d——– C:\WINDOWS\system32\bits
2007-11-12 17:13 361,984 –a–c— C:\WINDOWS\system32\dllcache\qmgr.dll
2007-11-12 17:13 331,776 –a—— C:\WINDOWS\system32\winhttp.dll
2007-11-12 17:13 331,776 –a–c— C:\WINDOWS\system32\dllcache\winhttp.dll
2007-11-12 17:13 17,408 –a—— C:\WINDOWS\system32\qmgrprxy.dll
2007-11-12 17:13 17,408 –a–c— C:\WINDOWS\system32\dllcache\qmgrprxy.dll
2007-11-12 17:13 7,680 –a–c— C:\WINDOWS\system32\dllcache\bitsprx2.dll
2007-11-12 17:13 7,680 –a—— C:\WINDOWS\system32\bitsprx2.dll
2007-11-12 17:13 7,168 –a–c— C:\WINDOWS\system32\dllcache\bitsprx3.dll
2007-11-12 17:13 7,168 –a—— C:\WINDOWS\system32\bitsprx3.dll
2007-11-12 17:10 549,720 –a—— C:\WINDOWS\system32\wuapi.dll
2007-11-12 17:10 325,976 –a—— C:\WINDOWS\system32\wucltui.dll
2007-11-12 17:10 216,408 –a—— C:\WINDOWS\system32\wuaucpl.cpl
2007-11-12 17:10 43,352 –a—— C:\WINDOWS\system32\wups2.dll
2007-11-12 17:10 34,136 –a—— C:\WINDOWS\system32\wucltui.dll.mui
2007-11-12 17:10 33,624 –a—— C:\WINDOWS\system32\wups.dll
2007-11-12 17:10 25,944 –a—— C:\WINDOWS\system32\wuaucpl.cpl.mui
2007-11-12 17:10 25,944 –a—— C:\WINDOWS\system32\wuapi.dll.mui
2007-11-12 17:10 20,312 –a—— C:\WINDOWS\system32\wuaueng.dll.mui
2007-11-11 18:06 208,896 –a—— C:\WINDOWS\system32\wmpns.dll
2007-11-11 16:48 d——– C:\Documents and Settings\Owner\Application Data\Musicmatch
2007-11-11 16:13 d——– C:\Documents and Settings\Owner\Shared
2007-11-11 16:11 d——– C:\Documents and Settings\Owner\Incomplete
2007-11-11 16:05 3,620 -rahs—- C:\WINDOWS\system32\drivers\HP_PC130A-ABA SR1111NX NA430_YC_Pres_QMXQ422_E43NAheREG3_4_IGamila Giovani Neon series_SMICRO-STAR INTERNATIONAL CO., LTD_V030_B3.10_T040415_WXH1_L409_M248_J40_7Intel_8Celeron_92.53_1_N10EC8139_P_Z_
K_A808624C5_U808624C2.MRK
2007-11-11 16:03 d——– C:\WINDOWS\system32\config\systemprofile\WINDOWS
2007-11-11 16:03 548,352 –a—— C:\WINDOWS\system32\rtcdll.dll
2007-11-11 16:03 548,352 –a–c— C:\WINDOWS\system32\dllcache\rtcdll.dll
2007-11-11 16:03 364,544 –a–c— C:\WINDOWS\system32\dllcache\callcont.dll
2007-11-11 16:03 253,952 –a–c— C:\WINDOWS\system32\dllcache\mst120.dll
2007-11-11 16:03 73,728 –a–c— C:\WINDOWS\system32\dllcache\nmcom.dll
2007-11-11 16:03 40,960 –a–c— C:\WINDOWS\system32\dllcache\evtgprov.dll
2007-11-11 16:02 974,336 –a—— C:\WINDOWS\system32\msdtctm.dll
2007-11-11 16:02 535,552 –a—— C:\WINDOWS\system32\rpcrt4.dll
2007-11-11 16:02 499,200 –a—— C:\WINDOWS\system32\comuid.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6b330a5b-594d-4a53-9247-c1a7f8e8431f}]
2007-11-22 18:39 79936 –a—— C:\WINDOWS\System32\evatupkm.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D350BE7-3630-4C77-8B4D-C08281546092}]
C:\WINDOWS\System32\mllmm.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{875A1348-7674-42aa-ADAC-B4F36A004A2D}]
C:\Program Files\QdrDrive\QdrDrive8.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{92F8F316-37FB-4522-8B58-4AE600830396}]
C:\WINDOWS\System32\rrzcqag.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
2007-11-22 18:51 145984 –a—— C:\WINDOWS\system32\gdqrjiln.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BBB05D9E-0297-404D-A6BF-D8F2876B84A6}]
2007-11-17 08:27 36352 –a—— C:\WINDOWS\System32\vtuvwuu.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\gdqrjiln.dll [2007-11-22 18:51 145984]

[HKEY_CLASSES_ROOT\clsid\{11a69ae4-fbed-4832-a2bf-45af82825583}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\gdqrjiln.dll [2007-11-22 18:51 145984]

[HKEY_CLASSES_ROOT\clsid\{11a69ae4-fbed-4832-a2bf-45af82825583}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2002-08-21 01:08]
"QdrModule9"="C:\Program Files\QdrModule\QdrModule9.exe" [2007-11-01 14:51]
"Pior"="C:\Documents and Settings\Owner\Application Data\?ymantec\??plorer.exe" []
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-17 23:42]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2004-04-02 03:49]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 19:04]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2004-08-20 15:51]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 22:02]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-04-02 04:43]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2004-01-16 22:16]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-13 23:43]
"VTTimer"="VTTimer.exe" []
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2003-08-15 03:59]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2003-09-12 22:13]
"Reminder"="C:\Windows\Creator\Remind_XP.exe" [2003-12-18 02:31]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 13:47 C:\WINDOWS\ALCXMNTR.EXE]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2004-08-20 15:55]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2007-11-13 23:27]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2004-04-02 05:04]
"482cd4e4"="C:\WINDOWS\System32\aekttrty.dll" [2007-11-22 18:36]

C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
IMStart.lnk - C:\Program Files\InterMute\IMStart.exe [2004-04-02 05:02:27]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 01:05:26]
Compaq Connections.lnk - C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe [2004-04-02 19:04:03]
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-11-17 23:41:55]
LimeWire 4.0.8.lnk - C:\Program Files\LimeWire\LimeWire 4.0.8\LimeWire.exe [2004-07-14 13:03:16]

[hklm\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{BBB05D9E-0297-404D-A6BF-D8F2876B84A6}"= C:\WINDOWS\System32\vtuvwuu.dll [2007-11-17 08:27 36352]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gdqrjiln]
gdqrjiln.dll 2007-11-22 18:51 145984 C:\WINDOWS\system32\gdqrjiln.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtuvwuu]
vtuvwuu.dll 2007-11-17 08:27 36352 C:\WINDOWS\system32\vtuvwuu.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\System32\ddaby.dll


.
Contents of the 'Scheduled Tasks' folder
"2007-11-23 00:00:01 C:\WINDOWS\Tasks\AF5BC035918C71A9.job"
- c:\docume~1\owner\applic~1\stylea~1\Second Great Bags.exe
"2007-11-19 13:24:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2006-11-06 01:40:59 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job"
- c:\PROGRA~1\NORTON~1\Navw32.exe
"2007-11-14 04:24:08 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-22 19:03:21
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-22 19:07:49 - machine was rebooted
C:\ComboFix2.txt … 2007-11-21 16:26
.
— E O F —




Logfile of HijackThis v1.99.1
Scan saved at 7:16:49 PM, on 11/22/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\gearsec.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\Program Files\QdrModule\QdrModule9.exe
C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Hijackthis\Spyware.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: {f1348e8f-7a1c-7429-35a4-d495b5a033b6} - {6b330a5b-594d-4a53-9247-c1a7f8e8431f} - C:\WINDOWS\System32\evatupkm.dll
O2 - BHO: (no name) - {6D350BE7-3630-4C77-8B4D-C08281546092} - C:\WINDOWS\System32\mllmm.dll (file missing)
O2 - BHO: BndShell3 BHO Class - {875A1348-7674-42aa-ADAC-B4F36A004A2D} - C:\Program Files\QdrDrive\QdrDrive8.dll (file missing)
O2 - BHO: (no name) - {92F8F316-37FB-4522-8B58-4AE600830396} - C:\WINDOWS\System32\rrzcqag.dll (file missing)
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\gdqrjiln.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: (no name) - {B340E3F3-6E5F-47D9-900C-88D8E99EF786} - C:\WINDOWS\System32\vtsqn.dll
O2 - BHO: (no name) - {BBB05D9E-0297-404D-A6BF-D8F2876B84A6} - C:\WINDOWS\System32\vtuvwuu.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\gdqrjiln.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [482cd4e4] rundll32.exe "C:\WINDOWS\System32\aekttrty.dll",b
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [QdrModule9] "C:\Program Files\QdrModule\QdrModule9.exe"
O4 - HKCU\..\Run: [Pior] "C:\Documents and Settings\Owner\Application Data\?ymantec\??plorer.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: IMStart.lnk = C:\Program Files\InterMute\IMStart.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: LimeWire 4.0.8.lnk = C:\Program Files\LimeWire\LimeWire 4.0.8\LimeWire.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1194905396093
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1194905372609
O16 - DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} - http://awbeta.net-nucleus.com/FIX/WinATS.cab
O20 - Winlogon Notify: gdqrjiln - C:\WINDOWS\SYSTEM32\gdqrjiln.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: vtuvwuu - C:\WINDOWS\SYSTEM32\vtuvwuu.dll
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe




this time, the trojan (toolbar, pop ups, etc.) doesn't look like it's went away too much, unlike last time when it looked like almost everything was gone when I used vundo.

Thankyou for any help in advance.
Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\lsqncgul.tmp
C:\WINDOWS\system32\lsqncgul.ini
C:\WINDOWS\system32\lugcnqsl.dll
C:\WINDOWS\system32\ylhofaof.dll
C:\WINDOWS\system32\togavrkn.exe
C:\WINDOWS\system32\amsswaah.dll
C:\WINDOWS\system32\sjntdvtd.ini
C:\WINDOWS\system32\dtvdtnjs.dll
C:\WINDOWS\system32\ypxlxatb.dll
C:\WINDOWS\system32\edcphxqi.ini
C:\WINDOWS\system32\yonkmexx.exe
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\ktxuxmbt.ini
C:\WINDOWS\system32\tbmxuxtk.dll
C:\WINDOWS\system32\vtuvwuu.dll
C:\WINDOWS\mrofinu72.exe
C:\WINDOWS\System32\rrzcqag.dll
C:\Documents and Settings\Owner\Application Data\?ymantec\??plorer.exe
C:\WINDOWS\WNSXS~1\wowexec.exe
C:\WINDOWS\System32\ddcyy.dll

Folder::
C:\VundoFix Backups
C:\Program Files\QdrModule
C:\Program Files\QdrDrive

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{322243c4-9cdf-45f2-a071-be22c57a7248}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D350BE7-3630-4C77-8B4D-C08281546092}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{875A1348-7674-42aa-ADAC-B4F36A004A2D}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{92F8F316-37FB-4522-8B58-4AE600830396}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BBB05D9E-0297-404D-A6BF-D8F2876B84A6}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Notn"=-
"QdrModule9"=-
"Pior"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"482cd4e4"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{BBB05D9E-0297-404D-A6BF-D8F2876B84A6}"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtuvwuu]


Save this as Save this as "CFScript"


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.
Heres the logs:

ComboFix 07-11-19.3 - Owner 2007-11-23 9:12:22.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.98 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\Owner\Favorites\Online Security Guide.lnk
C:\Program Files\QdrDrive
C:\Program Files\QdrDrive\qdrloader.exe
C:\Program Files\QdrModule
C:\Program Files\QdrModule\dic.gz
C:\Program Files\QdrModule\kwd.gz
C:\Program Files\QdrModule\QdrModule9.exe
C:\VundoFix Backups
C:\VundoFix Backups\iwfmliun.dll.bad
C:\VundoFix Backups\laadekgw.dll.bad
C:\VundoFix Backups\laadekgw.dllbox.bad
C:\VundoFix Backups\mllmm.dll.bad
C:\VundoFix Backups\mmllm.ini.bad
C:\VundoFix Backups\mmllm.ini2.bad
C:\VundoFix Backups\xhpnadcm.dll.bad
C:\VundoFix Backups\yudkzaak.dll.bad
C:\VundoFix Backups\yudkzaak.dllbox.bad
C:\WINDOWS\system32\gdqrjiln.dllbox
C:\WINDOWS\system32\nqstv.ini
C:\WINDOWS\system32\nqstv.ini2
C:\WINDOWS\System32\vtsqn.dll

.
((((((((((((((((((((((((( Files Created from 2007-10-23 to 2007-11-23 )))))))))))))))))))))))))))))))
.

2007-11-23 09:18 20,810 —hs—- C:\WINDOWS\system32\gdqrjiln.dllbox
2007-11-22 18:51 145,984 –a—— C:\WINDOWS\system32\gdqrjiln.dll
2007-11-22 18:39 79,936 –a—— C:\WINDOWS\system32\evatupkm.dll
2007-11-22 18:36 2,318,954 —hs—- C:\WINDOWS\system32\ytrttkea.ini
2007-11-22 18:36 85,056 –a—— C:\WINDOWS\system32\aekttrty.dll
2007-11-22 18:36 71,232 –a—— C:\WINDOWS\system32\eewdssov.exe
2007-11-22 17:25 1,843,829 –ahs—- C:\WINDOWS\system32\dypaftdt.ini
2007-11-22 17:19 79,936 –a—— C:\WINDOWS\system32\uhofgyrq.dll
2007-11-22 17:16 71,232 –a—— C:\WINDOWS\system32\qdwclhnl.exe
2007-11-21 17:02 36,864 –a—— C:\WINDOWS\system32\vtusqno.dll
2007-11-21 17:01 36,864 –a—— C:\WINDOWS\system32\ssqrrpq.dll
2007-11-21 17:01 35,840 –a—— C:\WINDOWS\17PHolmes572.exe
2007-11-21 16:59 d——– C:\Documents and Settings\Owner\Application Data\AntiSpywareSuite
2007-11-21 16:58 1,060,864 –a—— C:\WINDOWS\system32\mfc71.dll
2007-11-21 16:58 499,712 –a—— C:\WINDOWS\system32\msvcp71.dll
2007-11-21 16:58 348,160 –a—— C:\WINDOWS\system32\msvcr71.dll
2007-11-21 16:58 89,088 –a—— C:\WINDOWS\system32\atl71.dll
2007-11-21 16:58 24,064 –a—— C:\WINDOWS\system32\msxml3a.dll
2007-11-21 16:57 35,840 –a—— C:\WINDOWS\mrofinu572.exe
2007-11-21 16:56 36,864 –a—— C:\WINDOWS\system32\rqrrppq.dll
2007-11-21 03:52 71,232 –a—— C:\WINDOWS\system32\togavrkn.exe
2007-11-20 03:57 84,544 –a—— C:\WINDOWS\system32\amsswaah.dll
2007-11-20 03:54 688,812 –ahs—- C:\WINDOWS\system32\sjntdvtd.ini
2007-11-20 03:54 85,056 –a—— C:\WINDOWS\system32\dtvdtnjs.dll
2007-11-20 03:49 71,232 –a—— C:\WINDOWS\system32\qcnqttaj.exe
2007-11-18 22:44 79,424 –a—— C:\WINDOWS\system32\ypxlxatb.dll
2007-11-18 22:41 688,660 –ahs—- C:\WINDOWS\system32\edcphxqi.ini
2007-11-18 22:38 71,232 –a—— C:\WINDOWS\system32\yonkmexx.exe
2007-11-17 23:41 d——– C:\Documents and Settings\All Users\Application Data\Google Updater
2007-11-17 22:47 85,056 –a—— C:\WINDOWS\system32\tbmxuxtk.dll
2007-11-17 15:12 2,238 –a—— C:\WINDOWS\system32\ClickToFindandFixErrors_US.ico
2007-11-17 08:27 36,352 –a—— C:\WINDOWS\system32\vtuvwuu.dll
2007-11-17 08:27 35,840 –a—— C:\WINDOWS\mrofinu72.exe
2007-11-13 23:27 d——– C:\Program Files\SymNetDrv
2007-11-13 05:56 593,408 –a–c— C:\WINDOWS\system32\dllcache\xpsp2res.dll
2007-11-13 05:43 134,272 –a—— C:\WINDOWS\system32\drivers\portcls.sys
2007-11-13 05:43 134,272 –a–c— C:\WINDOWS\system32\dllcache\portcls.sys
2007-11-13 05:43 57,856 –a—— C:\WINDOWS\system32\drivers\drmk.sys
2007-11-13 05:40 831,519 –a—— C:\WINDOWS\system32\mswdat10.dll
2007-11-13 05:40 831,519 –a–c— C:\WINDOWS\system32\dllcache\mswdat10.dll
2007-11-13 05:40 614,431 –a—— C:\WINDOWS\system32\mswstr10.dll
2007-11-13 05:40 614,431 –a–c— C:\WINDOWS\system32\dllcache\mswstr10.dll
2007-11-13 05:40 380,957 –a—— C:\WINDOWS\system32\expsrv.dll
2007-11-13 05:40 348,189 –a—— C:\WINDOWS\system32\msxbde40.dll
2007-11-13 05:40 348,189 –a–c— C:\WINDOWS\system32\dllcache\msxbde40.dll
2007-11-13 05:40 258,077 –a—— C:\WINDOWS\system32\mstext40.dll
2007-11-13 05:40 258,077 –a–c— C:\WINDOWS\system32\dllcache\mstext40.dll
2007-11-13 05:40 30,749 –a—— C:\WINDOWS\system32\vbajet32.dll
2007-11-13 05:40 30,749 –a–c— C:\WINDOWS\system32\dllcache\vbajet32.dll
2007-11-12 22:05 21,760 –a–c— C:\WINDOWS\system32\dllcache\usbstor.sys
2007-11-12 17:54 209,280 –a–c— C:\WINDOWS\system32\dllcache\update.sys
2007-11-12 17:53 991,232 –a—— C:\WINDOWS\system32\esent.dll
2007-11-12 17:50 595,968 –a—— C:\WINDOWS\system32\xpsp2res.dll
2007-11-12 17:50 307,200 –a–c— C:\WINDOWS\system32\dllcache\netapi32.dll
2007-11-12 17:50 260,096 –a—— C:\WINDOWS\system32\mstask.dll
2007-11-12 17:50 260,096 –a–c— C:\WINDOWS\system32\dllcache\mstask.dll
2007-11-12 17:50 172,544 –a—— C:\WINDOWS\system32\schedsvc.dll
2007-11-12 17:50 172,544 –a–c— C:\WINDOWS\system32\dllcache\schedsvc.dll
2007-11-12 17:50 10,752 –a—— C:\WINDOWS\system32\mstinit.exe
2007-11-12 17:50 10,752 –a–c— C:\WINDOWS\system32\dllcache\mstinit.exe
2007-11-12 17:40 271,224 –a—— C:\WINDOWS\system32\mucltui.dll
2007-11-12 17:40 30,072 –a—— C:\WINDOWS\system32\mucltui.dll.mui
2007-11-12 17:18 22,752 –a—— C:\WINDOWS\system32\spupdsvc.exe
2007-11-12 17:16 d——– C:\WINDOWS\system32\bits
2007-11-12 17:13 361,984 –a–c— C:\WINDOWS\system32\dllcache\qmgr.dll
2007-11-12 17:13 331,776 –a—— C:\WINDOWS\system32\winhttp.dll
2007-11-12 17:13 331,776 –a–c— C:\WINDOWS\system32\dllcache\winhttp.dll
2007-11-12 17:13 17,408 –a—— C:\WINDOWS\system32\qmgrprxy.dll
2007-11-12 17:13 17,408 –a–c— C:\WINDOWS\system32\dllcache\qmgrprxy.dll
2007-11-12 17:13 7,680 –a–c— C:\WINDOWS\system32\dllcache\bitsprx2.dll
2007-11-12 17:13 7,680 –a—— C:\WINDOWS\system32\bitsprx2.dll
2007-11-12 17:13 7,168 –a–c— C:\WINDOWS\system32\dllcache\bitsprx3.dll
2007-11-12 17:13 7,168 –a—— C:\WINDOWS\system32\bitsprx3.dll
2007-11-12 17:10 549,720 –a—— C:\WINDOWS\system32\wuapi.dll
2007-11-12 17:10 325,976 –a—— C:\WINDOWS\system32\wucltui.dll
2007-11-12 17:10 216,408 –a—— C:\WINDOWS\system32\wuaucpl.cpl
2007-11-12 17:10 43,352 –a—— C:\WINDOWS\system32\wups2.dll
2007-11-12 17:10 34,136 –a—— C:\WINDOWS\system32\wucltui.dll.mui
2007-11-12 17:10 33,624 –a—— C:\WINDOWS\system32\wups.dll
2007-11-12 17:10 25,944 –a—— C:\WINDOWS\system32\wuaucpl.cpl.mui
2007-11-12 17:10 25,944 –a—— C:\WINDOWS\system32\wuapi.dll.mui
2007-11-12 17:10 20,312 –a—— C:\WINDOWS\system32\wuaueng.dll.mui
2007-11-11 18:06 208,896 –a—— C:\WINDOWS\system32\wmpns.dll
2007-11-11 16:48 d——– C:\Documents and Settings\Owner\Application Data\Musicmatch
2007-11-11 16:13 d——– C:\Documents and Settings\Owner\Shared
2007-11-11 16:11 d——– C:\Documents and Settings\Owner\Incomplete
2007-11-11 16:05 3,620 -rahs—- C:\WINDOWS\system32\drivers\HP_PC130A-ABA SR1111NX NA430_YC_Pres_QMXQ422_E43NAheREG3_4_IGamila Giovani Neon series_SMICRO-STAR INTERNATIONAL CO., LTD_V030_B3.10_T040415_WXH1_L409_M248_J40_7Intel_8Celeron_92.53_1_N10EC8139_P_Z_
K_A808624C5_U808624C2.MRK
2007-11-11 16:03 d——– C:\WINDOWS\system32\config\systemprofile\WINDOWS
2007-11-11 16:03 548,352 –a—— C:\WINDOWS\system32\rtcdll.dll
2007-11-11 16:03 548,352 –a–c— C:\WINDOWS\system32\dllcache\rtcdll.dll
2007-11-11 16:03 364,544 –a–c— C:\WINDOWS\system32\dllcache\callcont.dll
2007-11-11 16:03 253,952 –a–c— C:\WINDOWS\system32\dllcache\mst120.dll
2007-11-11 16:03 73,728 –a–c— C:\WINDOWS\system32\dllcache\nmcom.dll
2007-11-11 16:03 40,960 –a–c— C:\WINDOWS\system32\dllcache\evtgprov.dll
2007-11-11 16:02 974,336 –a—— C:\WINDOWS\system32\msdtctm.dll
2007-11-11 16:02 535,552 –a—— C:\WINDOWS\system32\rpcrt4.dll
2007-11-11 16:02 499,200 –a—— C:\WINDOWS\system32\comuid.dll
2007-11-11 16:02 368,640 –a—— C:\WINDOWS\system32\msdtcprx.dll
2007-11-11 16:02 220,672 –a–c— C:\WINDOWS\system32\dllcache\catsrv.dll
2007-11-11 16:02 150,528 –a—— C:\WINDOWS\system32\msdtcuiu.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6b330a5b-594d-4a53-9247-c1a7f8e8431f}]
2007-11-22 18:39 79936 –a—— C:\WINDOWS\System32\evatupkm.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
2007-11-22 18:51 145984 –a—— C:\WINDOWS\system32\gdqrjiln.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BBB05D9E-0297-404D-A6BF-D8F2876B84A6}]
2007-11-17 08:27 36352 –a—— C:\WINDOWS\system32\vtuvwuu.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\gdqrjiln.dll [2007-11-22 18:51 145984]

[HKEY_CLASSES_ROOT\clsid\{11a69ae4-fbed-4832-a2bf-45af82825583}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\gdqrjiln.dll [2007-11-22 18:51 145984]

[HKEY_CLASSES_ROOT\clsid\{11a69ae4-fbed-4832-a2bf-45af82825583}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2002-08-21 01:08]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-17 23:42]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2004-04-02 03:49]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 19:04]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2004-08-20 15:51]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 22:02]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-04-02 04:43]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2004-01-16 22:16]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-13 23:43]
"VTTimer"="VTTimer.exe" []
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2003-08-15 03:59]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2003-09-12 22:13]
"Reminder"="C:\Windows\Creator\Remind_XP.exe" [2003-12-18 02:31]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 13:47 C:\WINDOWS\ALCXMNTR.EXE]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2004-08-20 15:55]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2007-11-13 23:27]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2004-04-02 05:04]

C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
IMStart.lnk - C:\Program Files\InterMute\IMStart.exe [2004-04-02 05:02:27]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 01:05:26]
Compaq Connections.lnk - C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe [2004-04-02 19:04:03]
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-11-17 23:41:55]
LimeWire 4.0.8.lnk - C:\Program Files\LimeWire\LimeWire 4.0.8\LimeWire.exe [2004-07-14 13:03:16]

[hklm\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{BBB05D9E-0297-404D-A6BF-D8F2876B84A6}"= C:\WINDOWS\system32\vtuvwuu.dll [2007-11-17 08:27 36352]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gdqrjiln]
gdqrjiln.dll 2007-11-22 18:51 145984 C:\WINDOWS\system32\gdqrjiln.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtuvwuu]
vtuvwuu.dll 2007-11-17 08:27 36352 C:\WINDOWS\system32\vtuvwuu.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\\WINDOWS\\System32\\vtsqn


.
Contents of the 'Scheduled Tasks' folder
"2007-11-23 03:00:00 C:\WINDOWS\Tasks\AF5BC035918C71A9.job"
- c:\docume~1\owner\applic~1\stylea~1\Second Great Bags.exe
"2007-11-19 13:24:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2006-11-06 01:40:59 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job"
- c:\PROGRA~1\NORTON~1\Navw32.exeh/task:
"2007-11-14 04:24:08 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-23 09:19:11
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-23 9:23:05 - machine was rebooted
C:\ComboFix2.txt … 2007-11-22 19:07
C:\ComboFix3.txt … 2007-11-21 16:26
.
— E O F —






Logfile of HijackThis v1.99.1
Scan saved at 9:29:04 AM, on 11/23/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\gearsec.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\LimeWire\LimeWire 4.0.8\LimeWire.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Hijackthis\Spyware.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: {f1348e8f-7a1c-7429-35a4-d495b5a033b6} - {6b330a5b-594d-4a53-9247-c1a7f8e8431f} - C:\WINDOWS\System32\evatupkm.dll
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\gdqrjiln.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: (no name) - {BBB05D9E-0297-404D-A6BF-D8F2876B84A6} - C:\WINDOWS\system32\vtuvwuu.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {DFD38E31-BC7C-436E-8E0B-06CB3E6C36B9} - C:\WINDOWS\System32\awtsp.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\gdqrjiln.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: IMStart.lnk = C:\Program Files\InterMute\IMStart.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: LimeWire 4.0.8.lnk = C:\Program Files\LimeWire\LimeWire 4.0.8\LimeWire.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1194905396093
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1194905372609
O16 - DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} - http://awbeta.net-nucleus.com/FIX/WinATS.cab
O20 - Winlogon Notify: gdqrjiln - C:\WINDOWS\SYSTEM32\gdqrjiln.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: vtuvwuu - C:\WINDOWS\SYSTEM32\vtuvwuu.dll
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\gdqrjiln.dllbox
C:\WINDOWS\system32\gdqrjiln.dll
C:\WINDOWS\system32\evatupkm.dll
C:\WINDOWS\system32\ytrttkea.ini
C:\WINDOWS\system32\aekttrty.dll
C:\WINDOWS\system32\eewdssov.exe
C:\WINDOWS\system32\dypaftdt.ini
C:\WINDOWS\system32\uhofgyrq.dll
C:\WINDOWS\system32\qdwclhnl.exe
C:\WINDOWS\system32\vtusqno.dll
C:\WINDOWS\system32\ssqrrpq.dll
C:\WINDOWS\17PHolmes572.exe
C:\WINDOWS\mrofinu572.exe
C:\WINDOWS\system32\rqrrppq.dll
C:\WINDOWS\system32\togavrkn.exe
C:\WINDOWS\system32\amsswaah.dll
C:\WINDOWS\system32\sjntdvtd.ini
C:\WINDOWS\system32\dtvdtnjs.dll
C:\WINDOWS\system32\qcnqttaj.exe
C:\WINDOWS\system32\ypxlxatb.dll
C:\WINDOWS\system32\edcphxqi.ini
C:\WINDOWS\system32\yonkmexx.exe
C:\WINDOWS\system32\tbmxuxtk.dll
C:\WINDOWS\system32\vtuvwuu.dll
C:\WINDOWS\mrofinu72.exe
C:\\WINDOWS\\System32\\vtsqn
c:\docume~1\owner\applic~1\stylea~1\Second Great Bags.exe
C:\WINDOWS\Tasks\AF5BC035918C71A9.job
C:\WINDOWS\System32\awtsp.dll

Folder::
c:\docume~1\owner\applic~1\stylea~1

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6b330a5b-594d-4a53-9247-c1a7f8e8431f}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BBB05D9E-0297-404D-A6BF-D8F2876B84A6}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{11A69AE4-FBED-4832-A2BF-45AF82825583}]
[-HKEY_CLASSES_ROOT\clsid\{11a69ae4-fbed-4832-a2bf-45af82825583}]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{11A69AE4-FBED-4832-A2BF-45AF82825583}]
[-HKEY_CLASSES_ROOT\clsid\{11a69ae4-fbed-4832-a2bf-45af82825583}]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gdqrjiln]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtuvwuu]


Save this as Save this as "CFScript"


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.
it's starting to look alot better.

Heres the logs:


ComboFix 07-11-19.3 - Owner 2007-11-23 11:48:06.5 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\\WINDOWS\\System32\\vtsqn
c:\docume~1\owner\applic~1\stylea~1\Second Great Bags.exe
C:\WINDOWS\17PHolmes572.exe
C:\WINDOWS\mrofinu572.exe
C:\WINDOWS\mrofinu72.exe
C:\WINDOWS\system32\aekttrty.dll
C:\WINDOWS\system32\amsswaah.dll
C:\WINDOWS\System32\awtsp.dll
C:\WINDOWS\system32\dtvdtnjs.dll
C:\WINDOWS\system32\dypaftdt.ini
C:\WINDOWS\system32\edcphxqi.ini
C:\WINDOWS\system32\eewdssov.exe
C:\WINDOWS\system32\evatupkm.dll
C:\WINDOWS\system32\gdqrjiln.dll
C:\WINDOWS\system32\gdqrjiln.dllbox
C:\WINDOWS\system32\qcnqttaj.exe
C:\WINDOWS\system32\qdwclhnl.exe
C:\WINDOWS\system32\rqrrppq.dll
C:\WINDOWS\system32\sjntdvtd.ini
C:\WINDOWS\system32\ssqrrpq.dll
C:\WINDOWS\system32\tbmxuxtk.dll
C:\WINDOWS\system32\togavrkn.exe
C:\WINDOWS\system32\uhofgyrq.dll
C:\WINDOWS\system32\vtusqno.dll
C:\WINDOWS\system32\vtuvwuu.dll
C:\WINDOWS\system32\yonkmexx.exe
C:\WINDOWS\system32\ypxlxatb.dll
C:\WINDOWS\system32\ytrttkea.ini
C:\WINDOWS\Tasks\AF5BC035918C71A9.job
.

Unable to gain System Privileges

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\owner\applic~1\stylea~1
c:\docume~1\owner\applic~1\stylea~1\0
c:\docume~1\owner\applic~1\stylea~1\awwxjegg.exe
c:\docume~1\owner\applic~1\stylea~1\city shim.exe
c:\docume~1\owner\applic~1\stylea~1\eihnufwx.exe
c:\docume~1\owner\applic~1\stylea~1\gypfmvpp.exe
c:\docume~1\owner\applic~1\stylea~1\hqbarmbp.exe
c:\docume~1\owner\applic~1\stylea~1\kbihczwj.exe
c:\docume~1\owner\applic~1\stylea~1\loqoqumc.exe
c:\docume~1\owner\applic~1\stylea~1\loyavnqt.exe
c:\docume~1\owner\applic~1\stylea~1\lrbobnxj.exe
c:\docume~1\owner\applic~1\stylea~1\mixzfkht.exe
c:\docume~1\owner\applic~1\stylea~1\rmkodktb.exe
c:\docume~1\owner\applic~1\stylea~1\Second Great Bags.exe
c:\docume~1\owner\applic~1\stylea~1\uwpdxtru.exe
c:\docume~1\owner\applic~1\stylea~1\znsjvtfw.exe
C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\Owner\Desktop\Live Safety Center.lnk
C:\Documents and Settings\Owner\Desktop\Online Security Guide.lnk
C:\Documents and Settings\Owner\Favorites\Online Security Guide.lnk
C:\WINDOWS\17PHolmes572.exe
C:\WINDOWS\mrofinu572.exe
C:\WINDOWS\mrofinu72.exe
C:\WINDOWS\system32\aekttrty.dll
C:\WINDOWS\system32\amsswaah.dll
C:\WINDOWS\System32\awtsp.dll
C:\WINDOWS\system32\dtvdtnjs.dll
C:\WINDOWS\system32\dypaftdt.ini
C:\WINDOWS\system32\edcphxqi.ini
C:\WINDOWS\system32\eewdssov.exe
C:\WINDOWS\system32\evatupkm.dll
C:\WINDOWS\system32\gdqrjiln.dll
C:\WINDOWS\system32\gdqrjiln.dllbox
C:\WINDOWS\system32\pstwa.ini
C:\WINDOWS\system32\pstwa.ini2
C:\WINDOWS\system32\qcnqttaj.exe
C:\WINDOWS\system32\qdwclhnl.exe
C:\WINDOWS\system32\rqrrppq.dll
C:\WINDOWS\system32\sjntdvtd.ini
C:\WINDOWS\system32\ssqrrpq.dll
C:\WINDOWS\system32\tbmxuxtk.dll
C:\WINDOWS\system32\togavrkn.exe
C:\WINDOWS\system32\uhofgyrq.dll
C:\WINDOWS\system32\vtusqno.dll
C:\WINDOWS\system32\vtuvwuu.dll
C:\WINDOWS\system32\yonkmexx.exe
C:\WINDOWS\system32\ypxlxatb.dll
C:\WINDOWS\system32\ytrttkea.ini
C:\WINDOWS\Tasks\AF5BC035918C71A9.job

.
((((((((((((((((((((((((( Files Created from 2007-10-23 to 2007-11-23 )))))))))))))))))))))))))))))))
.

2007-11-21 16:59 d——– C:\Documents and Settings\Owner\Application Data\AntiSpywareSuite
2007-11-21 16:58 1,060,864 –a—— C:\WINDOWS\system32\mfc71.dll
2007-11-21 16:58 499,712 –a—— C:\WINDOWS\system32\msvcp71.dll
2007-11-21 16:58 348,160 –a—— C:\WINDOWS\system32\msvcr71.dll
2007-11-21 16:58 89,088 –a—— C:\WINDOWS\system32\atl71.dll
2007-11-21 16:58 24,064 –a—— C:\WINDOWS\system32\msxml3a.dll
2007-11-17 23:41 d——– C:\Documents and Settings\All Users\Application Data\Google Updater
2007-11-17 15:12 2,238 –a—— C:\WINDOWS\system32\ClickToFindandFixErrors_US.ico
2007-11-13 23:27 d——– C:\Program Files\SymNetDrv
2007-11-13 05:56 593,408 –a–c— C:\WINDOWS\system32\dllcache\xpsp2res.dll
2007-11-13 05:43 134,272 –a—— C:\WINDOWS\system32\drivers\portcls.sys
2007-11-13 05:43 134,272 –a–c— C:\WINDOWS\system32\dllcache\portcls.sys
2007-11-13 05:43 57,856 –a—— C:\WINDOWS\system32\drivers\drmk.sys
2007-11-13 05:40 831,519 –a—— C:\WINDOWS\system32\mswdat10.dll
2007-11-13 05:40 831,519 –a–c— C:\WINDOWS\system32\dllcache\mswdat10.dll
2007-11-13 05:40 614,431 –a—— C:\WINDOWS\system32\mswstr10.dll
2007-11-13 05:40 614,431 –a–c— C:\WINDOWS\system32\dllcache\mswstr10.dll
2007-11-13 05:40 380,957 –a—— C:\WINDOWS\system32\expsrv.dll
2007-11-13 05:40 348,189 –a—— C:\WINDOWS\system32\msxbde40.dll
2007-11-13 05:40 348,189 –a–c— C:\WINDOWS\system32\dllcache\msxbde40.dll
2007-11-13 05:40 258,077 –a—— C:\WINDOWS\system32\mstext40.dll
2007-11-13 05:40 258,077 –a–c— C:\WINDOWS\system32\dllcache\mstext40.dll
2007-11-13 05:40 30,749 –a—— C:\WINDOWS\system32\vbajet32.dll
2007-11-13 05:40 30,749 –a–c— C:\WINDOWS\system32\dllcache\vbajet32.dll
2007-11-12 22:05 21,760 –a–c— C:\WINDOWS\system32\dllcache\usbstor.sys
2007-11-12 17:54 209,280 –a–c— C:\WINDOWS\system32\dllcache\update.sys
2007-11-12 17:53 991,232 –a—— C:\WINDOWS\system32\esent.dll
2007-11-12 17:50 595,968 –a—— C:\WINDOWS\system32\xpsp2res.dll
2007-11-12 17:50 307,200 –a–c— C:\WINDOWS\system32\dllcache\netapi32.dll
2007-11-12 17:50 260,096 –a—— C:\WINDOWS\system32\mstask.dll
2007-11-12 17:50 260,096 –a–c— C:\WINDOWS\system32\dllcache\mstask.dll
2007-11-12 17:50 172,544 –a—— C:\WINDOWS\system32\schedsvc.dll
2007-11-12 17:50 172,544 –a–c— C:\WINDOWS\system32\dllcache\schedsvc.dll
2007-11-12 17:50 10,752 –a—— C:\WINDOWS\system32\mstinit.exe
2007-11-12 17:50 10,752 –a–c— C:\WINDOWS\system32\dllcache\mstinit.exe
2007-11-12 17:40 271,224 –a—— C:\WINDOWS\system32\mucltui.dll
2007-11-12 17:40 30,072 –a—— C:\WINDOWS\system32\mucltui.dll.mui
2007-11-12 17:18 22,752 –a—— C:\WINDOWS\system32\spupdsvc.exe
2007-11-12 17:16 d——– C:\WINDOWS\system32\bits
2007-11-12 17:13 361,984 –a–c— C:\WINDOWS\system32\dllcache\qmgr.dll
2007-11-12 17:13 331,776 –a—— C:\WINDOWS\system32\winhttp.dll
2007-11-12 17:13 331,776 –a–c— C:\WINDOWS\system32\dllcache\winhttp.dll
2007-11-12 17:13 17,408 –a—— C:\WINDOWS\system32\qmgrprxy.dll
2007-11-12 17:13 17,408 –a–c— C:\WINDOWS\system32\dllcache\qmgrprxy.dll
2007-11-12 17:13 7,680 –a–c— C:\WINDOWS\system32\dllcache\bitsprx2.dll
2007-11-12 17:13 7,680 –a—— C:\WINDOWS\system32\bitsprx2.dll
2007-11-12 17:13 7,168 –a–c— C:\WINDOWS\system32\dllcache\bitsprx3.dll
2007-11-12 17:13 7,168 –a—— C:\WINDOWS\system32\bitsprx3.dll
2007-11-12 17:10 549,720 –a—— C:\WINDOWS\system32\wuapi.dll
2007-11-12 17:10 325,976 –a—— C:\WINDOWS\system32\wucltui.dll
2007-11-12 17:10 216,408 –a—— C:\WINDOWS\system32\wuaucpl.cpl
2007-11-12 17:10 43,352 –a—— C:\WINDOWS\system32\wups2.dll
2007-11-12 17:10 34,136 –a—— C:\WINDOWS\system32\wucltui.dll.mui
2007-11-12 17:10 33,624 –a—— C:\WINDOWS\system32\wups.dll
2007-11-12 17:10 25,944 –a—— C:\WINDOWS\system32\wuaucpl.cpl.mui
2007-11-12 17:10 25,944 –a—— C:\WINDOWS\system32\wuapi.dll.mui
2007-11-12 17:10 20,312 –a—— C:\WINDOWS\system32\wuaueng.dll.mui
2007-11-11 18:06 208,896 –a—— C:\WINDOWS\system32\wmpns.dll
2007-11-11 16:48 d——– C:\Documents and Settings\Owner\Application Data\Musicmatch
2007-11-11 16:13 d——– C:\Documents and Settings\Owner\Shared
2007-11-11 16:11 d——– C:\Documents and Settings\Owner\Incomplete
2007-11-11 16:05 3,620 -rahs—- C:\WINDOWS\system32\drivers\HP_PC130A-ABA SR1111NX NA430_YC_Pres_QMXQ422_E43NAheREG3_4_IGamila Giovani Neon series_SMICRO-STAR INTERNATIONAL CO., LTD_V030_B3.10_T040415_WXH1_L409_M248_J40_7Intel_8Celeron_92.53_1_N10EC8139_P_Z_
K_A808624C5_U808624C2.MRK
2007-11-11 16:03 d——– C:\WINDOWS\system32\config\systemprofile\WINDOWS
2007-11-11 16:03 548,352 –a—— C:\WINDOWS\system32\rtcdll.dll
2007-11-11 16:03 548,352 –a–c— C:\WINDOWS\system32\dllcache\rtcdll.dll
2007-11-11 16:03 364,544 –a–c— C:\WINDOWS\system32\dllcache\callcont.dll
2007-11-11 16:03 253,952 –a–c— C:\WINDOWS\system32\dllcache\mst120.dll
2007-11-11 16:03 73,728 –a–c— C:\WINDOWS\system32\dllcache\nmcom.dll
2007-11-11 16:03 40,960 –a–c— C:\WINDOWS\system32\dllcache\evtgprov.dll
2007-11-11 16:02 974,336 –a—— C:\WINDOWS\system32\msdtctm.dll
2007-11-11 16:02 535,552 –a—— C:\WINDOWS\system32\rpcrt4.dll
2007-11-11 16:02 499,200 –a—— C:\WINDOWS\system32\comuid.dll
2007-11-11 16:02 368,640 –a—— C:\WINDOWS\system32\msdtcprx.dll
2007-11-11 16:02 220,672 –a–c— C:\WINDOWS\system32\dllcache\catsrv.dll
2007-11-11 16:02 150,528 –a—— C:\WINDOWS\system32\msdtcuiu.dll
2007-11-11 16:02 110,080 –a—— C:\WINDOWS\system32\clbcatex.dll
2007-11-11 16:02 97,280 –a—— C:\WINDOWS\system32\txflog.dll
2007-11-11 16:02 97,280 –a–c— C:\WINDOWS\system32\dllcache\txflog.dll
2007-11-11 16:02 83,456 –a–c— C:\WINDOWS\system32\dllcache\mtxoci.dll
2007-11-11 16:02 64,512 –a–c— C:\WINDOWS\system32\dllcache\mtxclu.dll
2007-11-11 15:59 51,072 –a—— C:\WINDOWS\system32\drivers\i8042prt.sys
2007-11-11 15:59 23,424 –a—— C:\WINDOWS\system32\drivers\kbdclass.sys
2007-11-11 14:23 dr-hsc— C:\WINDOWS\system32\dllcache
2007-11-09 21:48 d——– C:\Program Files\styleamen
2007-11-03 12:44 d——– C:\Documents and Settings\All Users\Application Data\Apple

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2002-08-21 01:08]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-17 23:42]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2004-04-02 03:49]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 19:04]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2004-08-20 15:51]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 22:02]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-04-02 04:43]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2004-01-16 22:16]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-13 23:43]
"VTTimer"="VTTimer.exe" []
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2003-08-15 03:59]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2003-09-12 22:13]
"Reminder"="C:\Windows\Creator\Remind_XP.exe" [2003-12-18 02:31]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 13:47 C:\WINDOWS\ALCXMNTR.EXE]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2004-08-20 15:55]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2007-11-13 23:27]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2004-04-02 05:04]

C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
IMStart.lnk - C:\Program Files\InterMute\IMStart.exe [2004-04-02 05:02:27]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 01:05:26]
Compaq Connections.lnk - C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe [2004-04-02 19:04:03]
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-11-17 23:41:55]
LimeWire 4.0.8.lnk - C:\Program Files\LimeWire\LimeWire 4.0.8\LimeWire.exe [2004-07-14 13:03:16]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\System32\awtsp.dll


.
Contents of the 'Scheduled Tasks' folder
"2007-11-19 13:24:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2006-11-06 01:40:59 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job"
- c:\PROGRA~1\NORTON~1\Navw32.exeh/task:
"2007-11-14 04:24:08 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-23 11:57:12
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-23 11:59:47 - machine was rebooted
C:\ComboFix2.txt … 2007-11-23 09:23
C:\ComboFix3.txt … 2007-11-22 19:07
.
— E O F —






Logfile of HijackThis v1.99.1
Scan saved at 12:02:30 PM, on 11/23/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\LimeWire\LimeWire 4.0.8\LimeWire.exe
C:\WINDOWS\System32\gearsec.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Hijackthis\Spyware.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: IMStart.lnk = C:\Program Files\InterMute\IMStart.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: LimeWire 4.0.8.lnk = C:\Program Files\LimeWire\LimeWire 4.0.8\LimeWire.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1194905396093
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1194905372609
O16 - DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} - http://awbeta.net-nucleus.com/FIX/WinATS.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
I suggest you do this:

You need to update SunJava.
Updating Java:
Download the latest version of Java Runtime Environment (JRE) 6.
  • Scroll down to where it says Java Runtime Environment (JRE) 6u2
    The Java SE Runtime Environment (JRE) allows end-users to run Java applications.
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name. It should have the [external image: Posted Image] icon next to it.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on 6-windowsi586-p.exe to install the newest version.
Once installed you can test to see that it is in fact installed
Sun Java Test
http://www.java.com/en/download/installed.jsp


After the above:


Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a checkmark/tick in the box on the left side on these:

O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} - http://awbeta.net-nucleus.com/FIX/WinATS.cab

Close ALL windows and browsers except HijackThis and click "Fix checked"


Delete this File if listed:
C:\ALCXMNTR.EXE

Empty Recycle Bin

Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Here you go:

Logfile of HijackThis v1.99.1
Scan saved at 12:50:09 PM, on 11/23/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\igfxtray.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\LimeWire\LimeWire 4.0.8\LimeWire.exe
C:\Program Files\InterMute\IMStart.exe
C:\WINDOWS\System32\gearsec.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Hijackthis\Spyware.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: IMStart.lnk = C:\Program Files\InterMute\IMStart.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: LimeWire 4.0.8.lnk = C:\Program Files\LimeWire\LimeWire 4.0.8\LimeWire.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1194905396093
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1194905372609
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe




My computer is behaving normally now. there's no sign of the virus anymore, every program runs fine, and there's no problem with rebooting. I don't see pop ups anymore either.
but I do have a few questions:

do you have any idea of how this virus most likely came onto my computer in the first place?

Should I uninstall limewire just to be safe?

I have anti-virus software, but none i'm aware of that monitor my computer 24/7. ad-aware SE and norton are the only two, but the only time they do anything is if I do a scan manually. and I don't want to buy ad-aware to get the "ad-watch" option.
Is there any free program that you would know of that I could use, that will watch for viruses, etc. 24/7?

Thanks for the help so far.
Limewire itself is safe but it always depends on what you download.

To answer your other questions:

Good job :thumbup:

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.

    • [external image: Posted Image]
  • If shown the disclaimer, Select "2"


Here's my usual all clean post

Log looks good :D


You need to create a new Clean restore point.

Note: This will remove all previous Restore Points

Click Start Menu > Run > copy and paste

%SystemRoot%\System32\restore\rstrui.exe

Press OK. Choose Create a Restore Point then click Next. Name it (something you'll remember) and click Create, when the confirmation screen shows the restore point has been created click Close.

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Check "Hide file extensions for known file types."
Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
Check "Hide protected operating system files."
Click Apply, and then click OK.

  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
    (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
    Without a firewall your computer is succeptible to being hacked and taken over.
    I am very serious about this and see it happen almost every day with my clients.
    Simply using a Firewall in its default configuration can lower your risk greatly.

    For a tutorial on Firewalls and a listing of some available ones see the link below:

    Understanding and Using Firewalls

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
    This will ensure your computer has always the latest security updates available installed on your computer.
    If there are new updates to install, install them immediately, reboot your computer, and revisit the site
    until there are no more critical updates.

  • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option.
    This will provide realtime spyware & hijacker protection on your computer alongside your virus protection.
    You should also scan your computer with this program on a regular basis just as you would an antivirus software.

    A tutorial on installing & using this product can be found here:

    Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers
  • Install SpywareBlaster - SpywareBlaster will add a large list of programs and sites into your Internet Explorer
    settings that will protect you from running and downloading known malicious programs.

    A tutorial on installing & using this product can be found here:

    Using SpywareBlaster to protect your computer from Spyware and Malware

  • IE-SPYAD puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.

    Using IE-SPYAD to help block unwanted sites and activities

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly.
    Without regular updates you WILL NOT be protected when new malicious programs are released.

Only run one Anti-Virus and Firewall program.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI