Thank you for your response,
This is my girlfriend's computer. I'm not sure why sp2 is not installed. I know it was online, and I know that automatic updates was/is turned on. So, I'm not sure.
After my initial post, I uninstalled both f-secure and SpyDr. Before going back online, I will make sure there is adequate protection. Will also make sure sp2 gets installed.
Here are the logs:
Logfile of HijackThis v1.99.1
Scan saved at 4:46:42 PM, on 11/28/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.emachines.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.c...rch/search.html
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {009AFE83-E233-4239-94B2-6379E961F631} - C:\WINDOWS\System32\enncmnnd.dll (file missing)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {135B1B31-252E-4715-9B37-BFA3AB2AB6AD} - C:\WINDOWS\System32\awtsr.dll (file missing)
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {62D8C559-3DF4-4591-886C-9DFC840D3106} - C:\WINDOWS\System32\enncmnnd.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O12 - Plugin for .m4a: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O20 - Winlogon Notify: awtsr - C:\WINDOWS\System32\awtsr.dll (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: __c0014CDE - C:\WINDOWS\System32\__c0014CDE.dat (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
360Share Pro(remove only)
Adobe Flash Player 9 ActiveX
Adobe Reader 6.0
Adobe Shockwave Player
America Online (Choose which version to remove)
AOL Coach Version 1.0(Build:20030807.3)
AOL Instant Messenger (SM)
Apple Software Update
Atlantis - Trial by Fire
AVG 7.5
CCleaner (remove only)
CompuServe
eMachines Bay Reader
Google Earth
Google Photos Screensaver
Google Toolbar for Firefox
Google Toolbar for Internet Explorer
Google Updater
HijackThis 1.99.1
ICQ
Intel® Extreme Graphics Driver
Intel® PRO Network Adapters and Drivers
Internet Explorer Q831167
iTunes
Java 2 Runtime Environment, SE v1.4.2
Learn2 Player (Uninstall Only)
Lexmark 4200 Series
Lexmark 4200 Series Fax Solutions
Microsoft Money 2004
Microsoft Money 2004 System Pack
Microsoft Works 7.0
Mozilla Firefox (2.0.0.1)
Netscape 6 (6.2.1)
PHOTOfunSTUDIO -viewer-
PowerDVD
Public Messenger ver 2.03
QuickTime
RealPlayer Basic
Realtek AC'97 Audio
Search
Sierra On-Line Games (Remove only)
SoftV92 Data Fax Modem with SmartCP
Update for Windows XP (KB898461)
Viewpoint Media Player (Remove Only)
Winamp (remove only)
Windows Backup Utility
Yahoo! Browser Services
Yahoo! Install Manager
Yahoo! Internet Mail
Yahoo! Messenger
Yahoo! Toolbar
ComboFix 07-11-19.4C - John 2007-11-28 13:56:36.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.334 [GMT -8:00]
Running from: K:\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\Common Files\{3000E~1
C:\Program Files\Common Files\{E000E~1
C:\Program Files\Common Files\{E000E~2
C:\Program Files\Common Files\Yazzle1281OinAdmin.exe
C:\Program Files\FunWebProducts
C:\Program Files\FunWebProducts\ScreenSaver\Images\
0032E20F.urr
C:\Program Files\FunWebProducts\Shared\Cache\AvatarSmallBtn-new.html
C:\Program Files\FunWebProducts\Shared\Cache\AvatarSmallBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\CursorManiaBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\FunBuddyIconBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MailStampBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MyFunCardsIMBtn-new.html
C:\Program Files\FunWebProducts\Shared\Cache\MyFunCardsIMBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MyStationeryBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html
C:\Program Files\MyWebSearch
C:\Program Files\MyWebSearch\bar\1.bin\F3BKGERR.JPG
C:\Program Files\MyWebSearch\bar\1.bin\F3CJPEG.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3DTACTL.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3IMSTUB.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3PSSAVR.SCR
C:\Program Files\MyWebSearch\bar\1.bin\F3REPROX.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3RESTUB.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3SCHMON.EXE
C:\Program Files\MyWebSearch\bar\1.bin\F3SPACER.WMV
C:\Program Files\MyWebSearch\bar\1.bin\F3WALLPP.DAT
C:\Program Files\MyWebSearch\bar\1.bin\F3WPHOOK.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.JAR
C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.MANIFEST
C:\Program Files\MyWebSearch\bar\1.bin\M3HTML.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3IDLE.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3IMPIPE.EXE
C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.JAR
C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.MANIFEST
C:\Program Files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE
C:\Program Files\MyWebSearch\bar\1.bin\M3SLSRCH.EXE
C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL
C:\Program Files\MyWebSearch\bar\1.bin\NPMYWEBS.DLL
C:\Program Files\MyWebSearch\bar\Avatar\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Cache\
00178973
C:\Program Files\MyWebSearch\bar\Cache\
00185C63.bin
C:\Program Files\MyWebSearch\bar\Cache\
00185FCE.bin
C:\Program Files\MyWebSearch\bar\Cache\
0018629D.bin
C:\Program Files\MyWebSearch\bar\Cache\
0018651E.bin
C:\Program Files\MyWebSearch\bar\Cache\
0032B737
C:\Program Files\MyWebSearch\bar\Cache\
0032BEE7
C:\Program Files\MyWebSearch\bar\Cache\
0032C2A1.bin
C:\Program Files\MyWebSearch\bar\Cache\
0032C715.bin
C:\Program Files\MyWebSearch\bar\Cache\
0032CBF7.bin
C:\Program Files\MyWebSearch\bar\Cache\
0032CE1A.bin
C:\Program Files\MyWebSearch\bar\Cache\
00B9EF6D.bin
C:\Program Files\MyWebSearch\bar\Cache\
00B9F1DE.bin
C:\Program Files\MyWebSearch\bar\Cache\
00B9F47E.bin
C:\Program Files\MyWebSearch\bar\Cache\
00B9F633.bin
C:\Program Files\MyWebSearch\bar\Cache\files.ini
C:\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S
C:\Program Files\MyWebSearch\bar\Game\CHESS.F3S
C:\Program Files\MyWebSearch\bar\Game\REVERSI.F3S
C:\Program Files\MyWebSearch\bar\History\search2
C:\Program Files\MyWebSearch\bar\Message\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Notifier\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Notifier\DOG.F3S
C:\Program Files\MyWebSearch\bar\Notifier\FISH.F3S
C:\Program Files\MyWebSearch\bar\Notifier\KUNGFU.F3S
C:\Program Files\MyWebSearch\bar\Notifier\LIFEGARD.F3S
C:\Program Files\MyWebSearch\bar\Notifier\MAID.F3S
C:\Program Files\MyWebSearch\bar\Notifier\MAILBOX.F3S
C:\Program Files\MyWebSearch\bar\Notifier\OPERA.F3S
C:\Program Files\MyWebSearch\bar\Notifier\ROBOT.F3S
C:\Program Files\MyWebSearch\bar\Notifier\SEDUCT.F3S
C:\Program Files\MyWebSearch\bar\Notifier\SURFER.F3S
C:\Program Files\MyWebSearch\bar\Settings\prevcfg2.htm
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat
C:\Program Files\MyWebSearch\bar\Settings\setting2.htm
C:\Program Files\MyWebSearch\bar\Settings\settings.dat
C:\Program Files\spysheriff
C:\Program Files\spysheriff\base.avd
C:\Program Files\spysheriff\base001.avd
C:\Program Files\spysheriff\base002.avd
C:\Program Files\spysheriff\found.wav
C:\Program Files\spysheriff\notfound.wav
C:\Program Files\spysheriff\removed.wav
C:\Program Files\spysheriff\SpySheriff.dvm
C:\Program Files\spysheriff\SpySheriff.exe
C:\WINDOWS\system32\arfcwwbs.exe
C:\WINDOWS\system32\bcnvinrk.dll
C:\WINDOWS\system32\bkibhcwx.exe
C:\WINDOWS\system32\blbydghy.exe
C:\WINDOWS\system32\bvcnnxyi.exe
C:\WINDOWS\system32\cbqnlccv.exe
C:\WINDOWS\system32\ctl3dv.dll
C:\WINDOWS\system32\dgyexvxp.exe
C:\WINDOWS\system32\drivers\wybupstc.dat
C:\WINDOWS\system32\drxjuoxu.dll
C:\WINDOWS\system32\gsnutwbe.exe
C:\WINDOWS\system32\jukugdtp.dll
C:\WINDOWS\system32\lfepdicm.exe
C:\WINDOWS\system32\mhmhehkp.dll
C:\WINDOWS\system32\mjgxkdac.exe
C:\WINDOWS\system32\nefkrjri.dll
C:\WINDOWS\system32\njdwwjmn.exe
C:\WINDOWS\system32\nmrjinxv.dll
C:\WINDOWS\system32\nnvkhhmr.dll
C:\WINDOWS\system32\pkhehmhm.ini
C:\WINDOWS\system32\qpcdqrul.exe
C:\WINDOWS\system32\qrwkbjhi.exe
C:\WINDOWS\system32\rmhhkvnn.ini
C:\WINDOWS\system32\vqexxqpu.exe
C:\WINDOWS\system32\vxnijrmn.ini
C:\WINDOWS\system32\winjrqsj.exe
C:\WINDOWS\system32\xkyimunc.dll
C:\WINDOWS\system32\ybpjikcr.exe
C:\xcrashdump.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_AXGLWXEE
-------\LEGACY_CLIENT_IP-IPX
-------\LEGACY_DOMAINSERVICE
-------\axglwxee
-------\Client IP-IPX
-------\DomainService
((((((((((((((((((((((((( Files Created from 2007-10-28 to 2007-11-28 )))))))))))))))))))))))))))))))
.
2007-11-20 15:17 <DIR> d-------- C:\WINDOWS\Google Toolbar
2007-11-20 14:53 <DIR> d-------- C:\Documents and Settings\Cindy\Application Data\AVG7
2007-11-20 11:15 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2007-11-20 11:15 <DIR> d-------- C:\Documents and Settings\John\Application Data\AVG7
2007-11-20 11:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-20 11:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2007-11-20 08:26 <DIR> d-------- C:\Program Files\CCleaner
2007-11-17 13:38 <DIR> d-------- C:\Documents and Settings\John\Application Data\Lavasoft
2007-11-17 13:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-17 13:29 <DIR> d-------- C:\Documents and Settings\John\Application Data\U3
2007-11-17 13:06 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS
2007-11-17 13:06 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2007-11-17 11:56 <DIR> d-------- C:\Documents and Settings\John\Application Data\Panasonic
2007-11-09 21:55 71,188 --a------ C:\WINDOWS\system32\nkxwbayo.exe
2007-11-09 09:20 71,188 --a------ C:\WINDOWS\system32\vouijqog.exe
2007-11-08 08:03 71,188 --a------ C:\WINDOWS\system32\slnhrlih.exe
2007-10-28 12:01 <DIR> d-------- C:\Documents and Settings\Cindy\Application Data\Panasonic
2007-10-28 11:57 <DIR> d-------- C:\Documents and Settings\Cindy\Application Data\Apple Computer
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-20 23:22 --------- d-----w C:\Program Files\Google
2007-11-20 23:22 --------- d-----w C:\Program Files\F-Secure
2007-11-20 23:17 --------- d-----w C:\Program Files\Panasonic
2007-11-20 23:02 --------- d-----w C:\Program Files\BigFix
2007-11-20 21:58 --------- d-----w C:\Program Files\QuickTime
2007-11-20 21:58 --------- d-----w C:\Program Files\Lexmark 4200 Series
2007-11-20 15:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2007-11-10 05:53 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-10-28 19:54 --------- d-----w C:\Program Files\iTunes
2007-10-27 21:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\PC Tools
2007-05-20 02:22 1,499,350 --sha-w C:\WINDOWS\system32\rstwa.bak1
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{009AFE83-E233-4239-94B2-6379E961F631}]
C:\WINDOWS\System32\enncmnnd.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{135B1B31-252E-4715-9B37-BFA3AB2AB6AD}]
C:\WINDOWS\System32\awtsr.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{549B5CA7-4A86-11D7-A4DF-000874180BB3}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{62D8C559-3DF4-4591-886C-9DFC840D3106}]
C:\WINDOWS\System32\enncmnnd.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-11-20 11:14]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-11-20 11:14]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-04-15 20:27:22]
[hklm\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{bd0fc212-0a36-4232-83cc-2063fb9282e0}"= C:\WINDOWS\System32\qzviz.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtsr]
C:\WINDOWS\System32\awtsr.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\__c0014CDE]
C:\WINDOWS\System32\__c0014CDE.dat
.
Contents of the 'Scheduled Tasks' folder
"2007-11-19 00:22:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-28 14:02:06
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-28 14:02:57 - machine was rebooted
.
--- E O F ---
Thanks