This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Vundo Won't remove

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have pasted my HJT log below. I went through the self help section and followed the directions there for the removal of the trojan.vundo.c.
When I ran the VundoFix it reported not finding Vundo.
I also had to rename hijackthis.exe to spyware.exe to get the 02 area to show in the logs.

Thanks ahead of time for your help.

Logfile of HijackThis v1.99.1
Scan saved at 7:08:55 AM, on 11/29/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Hijackthis\SpyWare.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://resultsmaster.com/SmartOffers/Servi…omeLeftPane.htm
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\2.bin\MWSSRCAS.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL
O2 - BHO: (no name) - {23289D39-2CC0-4C32-BC96-87DDF03B6EC7} - C:\WINDOWS\System32\ssqpn.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O2 - BHO: {68c857c6-9cd2-b85a-2b74-e2427ad8db7b} - {b7bd8da7-242e-47b2-a58b-2dc96c758c86} - C:\WINDOWS\system32\wgxedwsd.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\2.bin\MWSBAR.DLL,S
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [f86f5048] rundll32.exe "C:\WINDOWS\system32\gruwwucq.dll",b
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…p1.0.0.15-3.cab
O16 - DPF: {401F2F3A-8C56-4736-8C9E-37854F174AC9} (ProjectPoint Document) - https://folders.buzzsaw.com/!/download/…Point-BZ-EN.exe
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.maricopa.gov/assessor/gis/plugin/mgaxctrl.cab
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file://C:\Program Files\AutoCAD 2002\AcDcToday.ocx
O16 - DPF: {8C875948-9C60-4381-9248-0DF180542D53} - http://installs.spamblockerutility.com/ins…ckerutility.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://webcam5.corvettemuseum.com/activex/AxisCamControl.cab
O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Program Files\AutoCAD 2002\InstBanr.ocx
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file://C:\Program Files\AutoCAD 2002\InstFred.ocx
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Program Files\AutoCAD 2002\AcPreview.ocx
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = GTRENGINEERING.local
O17 - HKLM\Software\..\Telephony: DomainName = GTRENGINEERING.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = GTRENGINEERING.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = gtrengineering
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = GTRENGINEERING.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = gtrengineering
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = gtrengineering
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Autodesk Network Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskNetSrv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
Hi! Welcome to the WTT forums.
My name is Scotty. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research.
Please be patient.

Please make a uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.
5. Click on the Save list… button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here in a reply.
Thanks for your help Scotty. I followed your instructions. When I click on "save list" hijackthis closes. So I couldn't finish with being able to copy and paste to notepad. I'll wait for you to review the HJT log before I do anything else. A Davis
Hi

Download and Save ComboFix
  • Download this file from below:

    Here
  • Save it to your Desktop.
  • Disconnect from the Internet, than disable your anti-virus and any real-time anti-spyware monitors that are running.
  • Click Start>Run copy/paste or type "%userprofile%\desktop\combofix.exe" /killall into the Run box and click OK.
  • When finished, it shall produce a log for you. Post that log in your next reply with a new HijackThis log.
Note 1: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Note 2:Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet.

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task-Manager use the Processes tab (press ctrl alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

In your next reply post:
ComboFix.txt
New HijackThis log taken after the above scan has run
Sorry it took me a little while to get this posted. (weekend)
Below is the log from combo fix. I'll add another reply with the Hijackthis log.

ComboFix 07-12-02.7 - slangfitt 2007-12-03 6:15:34.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.536 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\cscafide\Application Data\SpamBlocker
C:\Documents and Settings\slangfitt\Application Data\SpamBlocker
C:\Documents and Settings\slangfitt\Application Data\SpamBlocker\Personal Folders
C:\Documents and Settings\slangfitt\Application Data\SpamBlockerUtility_Icons
C:\Documents and Settings\slangfitt\Application Data\SpamBlockerUtility_Icons\Registryrepair.ico
C:\Documents and Settings\slangfitt\Application Data\SpamBlockerUtility_Icons\Software_Online_8.ico
C:\Documents and Settings\slangfitt\Application Data\SpamBlockerUtility_Icons\wallpapere1.ico
C:\Program Files\FunWebProducts
C:\Program Files\FunWebProducts\ScreenSaver\Images\3E4B1EF3.urr
C:\Program Files\FunWebProducts\Shared\Cache\CursorManiaBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MailStampBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MyStationeryBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html
C:\Program Files\Hotbar
C:\Program Files\internet explorer\msimg32.dll
C:\Program Files\MyWebSearch
C:\Program Files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3HTML.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3OUTLCN.DLL
C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
C:\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL
C:\Program Files\MyWebSearch\bar\2.bin\F3BKGERR.JPG
C:\Program Files\MyWebSearch\bar\2.bin\F3BROVLY.DLL
C:\Program Files\MyWebSearch\bar\2.bin\F3CJPEG.DLL
C:\Program Files\MyWebSearch\bar\2.bin\F3DTACTL.DLL
C:\Program Files\MyWebSearch\bar\2.bin\F3HISTSW.DLL
C:\Program Files\MyWebSearch\bar\2.bin\F3HTMLMU.DLL
C:\Program Files\MyWebSearch\bar\2.bin\F3HTTPCT.DLL
C:\Program Files\MyWebSearch\bar\2.bin\F3IMSTUB.DLL
C:\Program Files\MyWebSearch\bar\2.bin\F3POPSWT.DLL
C:\Program Files\MyWebSearch\bar\2.bin\F3PSSAVR.SCR
C:\Program Files\MyWebSearch\bar\2.bin\F3REPROX.DLL
C:\Program Files\MyWebSearch\bar\2.bin\F3RESTUB.DLL
C:\Program Files\MyWebSearch\bar\2.bin\F3SCHMON.EXE
C:\Program Files\MyWebSearch\bar\2.bin\F3SCRCTR.DLL
C:\Program Files\MyWebSearch\bar\2.bin\F3SHLLVW.DLL
C:\Program Files\MyWebSearch\bar\2.bin\F3SPACER.WMV
C:\Program Files\MyWebSearch\bar\2.bin\F3WALLPP.DAT
C:\Program Files\MyWebSearch\bar\2.bin\F3WPHOOK.DLL
C:\Program Files\MyWebSearch\bar\2.bin\M3FFXTBR.JAR
C:\Program Files\MyWebSearch\bar\2.bin\M3FFXTBR.MANIFEST
C:\Program Files\MyWebSearch\bar\2.bin\M3HTML.DLL
C:\Program Files\MyWebSearch\bar\2.bin\M3IDLE.DLL
C:\Program Files\MyWebSearch\bar\2.bin\M3IMPIPE.EXE
C:\Program Files\MyWebSearch\bar\2.bin\M3MSG.DLL
C:\Program Files\MyWebSearch\bar\2.bin\M3NTSTBR.JAR
C:\Program Files\MyWebSearch\bar\2.bin\M3NTSTBR.MANIFEST
C:\Program Files\MyWebSearch\bar\2.bin\M3OUTLCN.DLL
C:\Program Files\MyWebSearch\bar\2.bin\M3PLUGIN.DLL
C:\Program Files\MyWebSearch\bar\2.bin\M3SKIN.DLL
C:\Program Files\MyWebSearch\bar\2.bin\M3SKPLAY.EXE
C:\Program Files\MyWebSearch\bar\2.bin\M3SLSRCH.EXE
C:\Program Files\MyWebSearch\bar\2.bin\M3SRCHMN.EXE
C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL
C:\Program Files\MyWebSearch\bar\2.bin\MWSOEMON.EXE
C:\Program Files\MyWebSearch\bar\2.bin\MWSOEPLG.DLL
C:\Program Files\MyWebSearch\bar\2.bin\MWSOESTB.DLL
C:\Program Files\MyWebSearch\bar\2.bin\NPMYWEBS.DLL
C:\Program Files\MyWebSearch\bar\Avatar\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Cache\00092212
C:\Program Files\MyWebSearch\bar\Cache\010F7E03
C:\Program Files\MyWebSearch\bar\Cache\166DF7D9.bin
C:\Program Files\MyWebSearch\bar\Cache\166DF901.bin
C:\Program Files\MyWebSearch\bar\Cache\166DFAA7.bin
C:\Program Files\MyWebSearch\bar\Cache\166DFBD0.bin
C:\Program Files\MyWebSearch\bar\Cache\166F45F4.bin
C:\Program Files\MyWebSearch\bar\Cache\166F46CF.bin
C:\Program Files\MyWebSearch\bar\Cache\166F5352.bin
C:\Program Files\MyWebSearch\bar\Cache\166F542C.bin
C:\Program Files\MyWebSearch\bar\Cache\69F9B1F7
C:\Program Files\MyWebSearch\bar\Cache\files.ini
C:\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S
C:\Program Files\MyWebSearch\bar\Game\CHESS.F3S
C:\Program Files\MyWebSearch\bar\Game\REVERSI.F3S
C:\Program Files\MyWebSearch\bar\History\search
C:\Program Files\MyWebSearch\bar\History\search2
C:\Program Files\MyWebSearch\bar\Message\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Notifier\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Notifier\DOG.F3S
C:\Program Files\MyWebSearch\bar\Notifier\FISH.F3S
C:\Program Files\MyWebSearch\bar\Notifier\KUNGFU.F3S
C:\Program Files\MyWebSearch\bar\Notifier\LIFEGARD.F3S
C:\Program Files\MyWebSearch\bar\Notifier\MAID.F3S
C:\Program Files\MyWebSearch\bar\Notifier\MAILBOX.F3S
C:\Program Files\MyWebSearch\bar\Notifier\OPERA.F3S
C:\Program Files\MyWebSearch\bar\Notifier\ROBOT.F3S
C:\Program Files\MyWebSearch\bar\Notifier\SEDUCT.F3S
C:\Program Files\MyWebSearch\bar\Notifier\SURFER.F3S
C:\Program Files\MyWebSearch\bar\Settings\prevcfg.htm
C:\Program Files\MyWebSearch\bar\Settings\prevcfg2.htm
C:\Program Files\MyWebSearch\bar\Settings\s_bfeats.dat
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat
C:\Program Files\MyWebSearch\bar\Settings\settings.dat
C:\Program Files\MyWebSearch\bar\Settings\settings.htm
C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
C:\Program Files\MyWebSearch\SrchAstt\2.bin\MWSSRCAS.DLL
C:\WINDOWS\cookies.ini
C:\WINDOWS\Downloaded Program Files.\HbInstIE.dll
C:\WINDOWS\Downloaded Program Files.\hotbar.inf
C:\WINDOWS\system32\agvtmlfm.dll
C:\WINDOWS\system32\brbmxuro.dll
C:\WINDOWS\SYSTEM32\cmmbhxlj.ini
C:\WINDOWS\system32\defnnsiv.dll
C:\WINDOWS\system32\efydpxvy.dll
C:\WINDOWS\system32\exaceoiu.dll
C:\WINDOWS\system32\f3PSSavr.scr
C:\WINDOWS\system32\fjbtuvjm.dll
C:\WINDOWS\system32\gruwwucq.dll
C:\WINDOWS\system32\hbbotywe.dll
C:\WINDOWS\system32\idtyxkap.dll
C:\WINDOWS\SYSTEM32\iypxjpkl.ini
C:\WINDOWS\system32\jlxhbmmc.dll
C:\WINDOWS\system32\kxfqhdqu.dll
C:\WINDOWS\system32\lenfwygw.dll
C:\WINDOWS\system32\lkpjxpyi.dll
C:\WINDOWS\system32\njvtcbuu.dll
C:\WINDOWS\SYSTEM32\npqss.bak1
C:\WINDOWS\SYSTEM32\npqss.bak2
C:\WINDOWS\SYSTEM32\npqss.ini
C:\WINDOWS\SYSTEM32\npqss.ini2
C:\WINDOWS\SYSTEM32\npqss.tmp
C:\WINDOWS\system32\pihefkro.dll
C:\WINDOWS\system32\pwawmgyv.dll
C:\WINDOWS\SYSTEM32\qcuwwurg.ini
C:\WINDOWS\system32\ruptmjlv.dll
C:\WINDOWS\System32\ssqpn.dll
C:\WINDOWS\system32\tddaqunl.dll
C:\WINDOWS\system32\teomwyak.dll
C:\WINDOWS\system32\tsmjmwdo.dll
C:\WINDOWS\system32\ubexavff.dll
C:\WINDOWS\system32\umjgayhv.dll
C:\WINDOWS\system32\upvsiglk.dll
C:\WINDOWS\system32\vtcmhxcu.dll
C:\WINDOWS\system32\wgxedwsd.dll
C:\WINDOWS\system32\xuolxatx.dll

.
((((((((((((((((((((((((( Files Created from 2007-11-03 to 2007-12-03 )))))))))))))))))))))))))))))))
.

2007-12-03 06:06 . 2007-12-03 06:06 73,280 –a—— C:\WINDOWS\SYSTEM32\uonnsrbm.dll
2007-12-03 06:00 . 2007-12-03 06:00 74,240 –a—— C:\WINDOWS\SYSTEM32\cvcjnxat.dll
2007-11-21 06:33 . 2007-11-27 06:58 784,426 –ahs—- C:\WINDOWS\SYSTEM32\vsljwbee.ini
2007-11-20 05:57 . 2007-11-20 05:57 74,512 –a—— C:\WINDOWS\SYSTEM32\rgfotmkr.dll
2007-11-15 06:43 . 2007-11-15 07:12 671,205 –ahs—- C:\WINDOWS\SYSTEM32\hwwfihhl.ini
2007-11-14 06:41 . 2007-11-15 06:41 671,136 –ahs—- C:\WINDOWS\SYSTEM32\nabyhhge.ini
2007-11-14 06:13 . 2007-09-24 23:31 69,632 –a—— C:\WINDOWS\SYSTEM32\javacpl.cpl
2007-11-14 06:12 . 2007-11-14 06:13 d——– C:\Program Files\Java
2007-11-14 06:12 . 2007-11-14 06:12 d——– C:\Program Files\Common Files\Java
2007-11-13 06:38 . 2007-11-13 06:38 65,480 –a—— C:\WINDOWS\SYSTEM32\ocyshetp.dll
2007-11-07 06:06 . 2007-11-07 06:06 65,480 –a—— C:\WINDOWS\SYSTEM32\gcfqopvy.dll
2007-11-06 06:00 . 2007-11-06 06:07 d——– C:\VundoFix Backups
2007-11-06 05:54 . 2007-11-06 05:54 65,480 –a—— C:\WINDOWS\SYSTEM32\wnnsfjeh.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-03 13:41 ——— d—–w C:\Program Files\Symantec AntiVirus
2007-11-29 19:36 ——— d—–w C:\Program Files\Puller
2007-11-15 20:05 ——— d—–w C:\Program Files\Google
2007-10-30 10:01 ——— d—–w C:\Program Files\MSXML 4.0
2004-03-01 17:54 50,320 —-a-w C:\Documents and Settings\slangfitt\Application Data\GDIPFONTCACHEV1.DAT
2004-03-01 17:54 50,320 —-a-w C:\Documents and Settings\dhorning\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95f23bd4-3774-4dd9-b818-7469a10e5016}]
2007-12-03 06:06 73280 –a—— C:\WINDOWS\system32\uonnsrbm.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2004-02-29 16:44]
"vptray"="C:\PROGRA~1\SYMANT~2\VPTray.exe" [2004-03-12 15:18]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-06-01 10:30]
"type32"="C:\Program Files\Microsoft IntelliType Pro\type32.exe" [2005-06-10 02:24]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2005-06-10 02:21]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe [2004-02-25 15:44:29]
AutoCAD Startup Accelerator.lnk - C:\Program Files\Common Files\Autodesk Shared\acstart16.exe [2004-02-25 02:35:22]
MyWebSearch Email Plugin.lnk - C:\qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE.vir [2006-02-13 15:31:37]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-04 00:56 15360 –a—— C:\WINDOWS\System32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\f86f5048]
rundll32.exe C:\WINDOWS\System32\oeuyfvfp.dll,b

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

R2 ASFAgent;ASF Agent;C:\Program Files\Intel\ASF Agent\ASFAgent.exe
R2 AsfAlrt;AsfAlrt;\??\C:\WINDOWS\System32\drivers\AsfAlrt.sys

.
**************************************************************************

catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-03 06:45:37
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-03 6:47:26 - machine was rebooted
.
— E O F —
below is the hijackthis log file.

Logfile of HijackThis v1.99.1
Scan saved at 07:06, on 2007-12-03
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~2\VPTray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\SpyWare.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gtrengineering.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http://GTR1:8080
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: {6105e01a-9647-818b-9dd4-47734db32f59} - {95f23bd4-3774-4dd9-b818-7469a10e5016} - C:\WINDOWS\system32\uonnsrbm.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE.vir
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…?p=ZNxdm824DHUS
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…p1.0.0.15-3.cab
O16 - DPF: {401F2F3A-8C56-4736-8C9E-37854F174AC9} (ProjectPoint Document) - https://folders.buzzsaw.com/!/download/…Point-BZ-EN.exe
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.maricopa.gov/assessor/gis/plugin/mgaxctrl.cab
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file://C:\Program Files\AutoCAD 2002\AcDcToday.ocx
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://webcam5.corvettemuseum.com/activex/AxisCamControl.cab
O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Program Files\AutoCAD 2002\InstBanr.ocx
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file://C:\Program Files\AutoCAD 2002\InstFred.ocx
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Program Files\AutoCAD 2002\AcPreview.ocx
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = GTRENGINEERING.local
O17 - HKLM\Software\..\Telephony: DomainName = GTRENGINEERING.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = GTRENGINEERING.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = gtrengineering
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = GTRENGINEERING.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = gtrengineering
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = gtrengineering
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Autodesk Network Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskNetSrv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
Hi


Remember to disconnect from the Internet and disable your anti-virus before carrying out the next instruction, and to reenable the anti-virus before reconnecting to the Internet


Open Notepad - it must be Notepad, not Wordpad.
Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

File::
C:\WINDOWS\SYSTEM32\uonnsrbm.dll
C:\WINDOWS\SYSTEM32\cvcjnxat.dll
C:\WINDOWS\SYSTEM32\vsljwbee.ini
C:\WINDOWS\SYSTEM32\rgfotmkr.dll
C:\WINDOWS\SYSTEM32\hwwfihhl.ini
C:\WINDOWS\SYSTEM32\nabyhhge.ini 
C:\WINDOWS\SYSTEM32\ocyshetp.dll
C:\WINDOWS\SYSTEM32\gcfqopvy.dll
C:\WINDOWS\SYSTEM32\wnnsfjeh.dll
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MyWebSearch Email Plugin.lnk

Folder::
C:\VundoFix Backups

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95f23bd4-3774-4dd9-b818-7469a10e5016}]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\f86f5048]

Go to the Notepad window and click Edit > Paste
Then click File > Save
Name the file "CFScript.txt" (including the quotes)
Save the file to your Desktop

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task-Manager use the Processes tab (press ctrl alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

In your next reply post:
ComboFix.txt
New HJT log taken after the above scan has run
The log for combofix is pasted below. I've been posting each log in seperate post because I didn't want any thing to be cut off. Do you want me to continue to post each log in different post?

For this one I am posting 1 for each log.

P.S. I will have to let the user back on the system this morning. I had a little bit of a break becuase the user was out yesterday and this earily AM.

ComboFix 07-12-02.7 - slangfitt 2007-12-03 6:15:34.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.536 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\cscafide\Application Data\SpamBlocker
C:\Documents and Settings\slangfitt\Application Data\SpamBlocker
C:\Documents and Settings\slangfitt\Application Data\SpamBlocker\Personal Folders
C:\Documents and Settings\slangfitt\Application Data\SpamBlockerUtility_Icons
C:\Documents and Settings\slangfitt\Application Data\SpamBlockerUtility_Icons\Registryrepair.ico
C:\Documents and Settings\slangfitt\Application Data\SpamBlockerUtility_Icons\Software_Online_8.ico
C:\Documents and Settings\slangfitt\Application Data\SpamBlockerUtility_Icons\wallpapere1.ico
C:\Program Files\FunWebProducts
C:\Program Files\FunWebProducts\ScreenSaver\Images\3E4B1EF3.urr
C:\Program Files\FunWebProducts\Shared\Cache\CursorManiaBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MailStampBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MyStationeryBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html
C:\Program Files\Hotbar
C:\Program Files\internet explorer\msimg32.dll
C:\Program Files\MyWebSearch
C:\Program Files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3HTML.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3OUTLCN.DLL
C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
C:\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL
C:\Program Files\MyWebSearch\bar\2.bin\F3BKGERR.JPG
C:\Program Files\MyWebSearch\bar\2.bin\F3BROVLY.DLL
C:\Program Files\MyWebSearch\bar\2.bin\F3CJPEG.DLL
C:\Program Files\MyWebSearch\bar\2.bin\F3DTACTL.DLL
C:\Program Files\MyWebSearch\bar\2.bin\F3HISTSW.DLL
C:\Program Files\MyWebSearch\bar\2.bin\F3HTMLMU.DLL
C:\Program Files\MyWebSearch\bar\2.bin\F3HTTPCT.DLL
C:\Program Files\MyWebSearch\bar\2.bin\F3IMSTUB.DLL
C:\Program Files\MyWebSearch\bar\2.bin\F3POPSWT.DLL
C:\Program Files\MyWebSearch\bar\2.bin\F3PSSAVR.SCR
C:\Program Files\MyWebSearch\bar\2.bin\F3REPROX.DLL
C:\Program Files\MyWebSearch\bar\2.bin\F3RESTUB.DLL
C:\Program Files\MyWebSearch\bar\2.bin\F3SCHMON.EXE
C:\Program Files\MyWebSearch\bar\2.bin\F3SCRCTR.DLL
C:\Program Files\MyWebSearch\bar\2.bin\F3SHLLVW.DLL
C:\Program Files\MyWebSearch\bar\2.bin\F3SPACER.WMV
C:\Program Files\MyWebSearch\bar\2.bin\F3WALLPP.DAT
C:\Program Files\MyWebSearch\bar\2.bin\F3WPHOOK.DLL
C:\Program Files\MyWebSearch\bar\2.bin\M3FFXTBR.JAR
C:\Program Files\MyWebSearch\bar\2.bin\M3FFXTBR.MANIFEST
C:\Program Files\MyWebSearch\bar\2.bin\M3HTML.DLL
C:\Program Files\MyWebSearch\bar\2.bin\M3IDLE.DLL
C:\Program Files\MyWebSearch\bar\2.bin\M3IMPIPE.EXE
C:\Program Files\MyWebSearch\bar\2.bin\M3MSG.DLL
C:\Program Files\MyWebSearch\bar\2.bin\M3NTSTBR.JAR
C:\Program Files\MyWebSearch\bar\2.bin\M3NTSTBR.MANIFEST
C:\Program Files\MyWebSearch\bar\2.bin\M3OUTLCN.DLL
C:\Program Files\MyWebSearch\bar\2.bin\M3PLUGIN.DLL
C:\Program Files\MyWebSearch\bar\2.bin\M3SKIN.DLL
C:\Program Files\MyWebSearch\bar\2.bin\M3SKPLAY.EXE
C:\Program Files\MyWebSearch\bar\2.bin\M3SLSRCH.EXE
C:\Program Files\MyWebSearch\bar\2.bin\M3SRCHMN.EXE
C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL
C:\Program Files\MyWebSearch\bar\2.bin\MWSOEMON.EXE
C:\Program Files\MyWebSearch\bar\2.bin\MWSOEPLG.DLL
C:\Program Files\MyWebSearch\bar\2.bin\MWSOESTB.DLL
C:\Program Files\MyWebSearch\bar\2.bin\NPMYWEBS.DLL
C:\Program Files\MyWebSearch\bar\Avatar\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Cache\00092212
C:\Program Files\MyWebSearch\bar\Cache\010F7E03
C:\Program Files\MyWebSearch\bar\Cache\166DF7D9.bin
C:\Program Files\MyWebSearch\bar\Cache\166DF901.bin
C:\Program Files\MyWebSearch\bar\Cache\166DFAA7.bin
C:\Program Files\MyWebSearch\bar\Cache\166DFBD0.bin
C:\Program Files\MyWebSearch\bar\Cache\166F45F4.bin
C:\Program Files\MyWebSearch\bar\Cache\166F46CF.bin
C:\Program Files\MyWebSearch\bar\Cache\166F5352.bin
C:\Program Files\MyWebSearch\bar\Cache\166F542C.bin
C:\Program Files\MyWebSearch\bar\Cache\69F9B1F7
C:\Program Files\MyWebSearch\bar\Cache\files.ini
C:\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S
C:\Program Files\MyWebSearch\bar\Game\CHESS.F3S
C:\Program Files\MyWebSearch\bar\Game\REVERSI.F3S
C:\Program Files\MyWebSearch\bar\History\search
C:\Program Files\MyWebSearch\bar\History\search2
C:\Program Files\MyWebSearch\bar\Message\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Notifier\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Notifier\DOG.F3S
C:\Program Files\MyWebSearch\bar\Notifier\FISH.F3S
C:\Program Files\MyWebSearch\bar\Notifier\KUNGFU.F3S
C:\Program Files\MyWebSearch\bar\Notifier\LIFEGARD.F3S
C:\Program Files\MyWebSearch\bar\Notifier\MAID.F3S
C:\Program Files\MyWebSearch\bar\Notifier\MAILBOX.F3S
C:\Program Files\MyWebSearch\bar\Notifier\OPERA.F3S
C:\Program Files\MyWebSearch\bar\Notifier\ROBOT.F3S
C:\Program Files\MyWebSearch\bar\Notifier\SEDUCT.F3S
C:\Program Files\MyWebSearch\bar\Notifier\SURFER.F3S
C:\Program Files\MyWebSearch\bar\Settings\prevcfg.htm
C:\Program Files\MyWebSearch\bar\Settings\prevcfg2.htm
C:\Program Files\MyWebSearch\bar\Settings\s_bfeats.dat
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat
C:\Program Files\MyWebSearch\bar\Settings\settings.dat
C:\Program Files\MyWebSearch\bar\Settings\settings.htm
C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
C:\Program Files\MyWebSearch\SrchAstt\2.bin\MWSSRCAS.DLL
C:\WINDOWS\cookies.ini
C:\WINDOWS\Downloaded Program Files.\HbInstIE.dll
C:\WINDOWS\Downloaded Program Files.\hotbar.inf
C:\WINDOWS\system32\agvtmlfm.dll
C:\WINDOWS\system32\brbmxuro.dll
C:\WINDOWS\SYSTEM32\cmmbhxlj.ini
C:\WINDOWS\system32\defnnsiv.dll
C:\WINDOWS\system32\efydpxvy.dll
C:\WINDOWS\system32\exaceoiu.dll
C:\WINDOWS\system32\f3PSSavr.scr
C:\WINDOWS\system32\fjbtuvjm.dll
C:\WINDOWS\system32\gruwwucq.dll
C:\WINDOWS\system32\hbbotywe.dll
C:\WINDOWS\system32\idtyxkap.dll
C:\WINDOWS\SYSTEM32\iypxjpkl.ini
C:\WINDOWS\system32\jlxhbmmc.dll
C:\WINDOWS\system32\kxfqhdqu.dll
C:\WINDOWS\system32\lenfwygw.dll
C:\WINDOWS\system32\lkpjxpyi.dll
C:\WINDOWS\system32\njvtcbuu.dll
C:\WINDOWS\SYSTEM32\npqss.bak1
C:\WINDOWS\SYSTEM32\npqss.bak2
C:\WINDOWS\SYSTEM32\npqss.ini
C:\WINDOWS\SYSTEM32\npqss.ini2
C:\WINDOWS\SYSTEM32\npqss.tmp
C:\WINDOWS\system32\pihefkro.dll
C:\WINDOWS\system32\pwawmgyv.dll
C:\WINDOWS\SYSTEM32\qcuwwurg.ini
C:\WINDOWS\system32\ruptmjlv.dll
C:\WINDOWS\System32\ssqpn.dll
C:\WINDOWS\system32\tddaqunl.dll
C:\WINDOWS\system32\teomwyak.dll
C:\WINDOWS\system32\tsmjmwdo.dll
C:\WINDOWS\system32\ubexavff.dll
C:\WINDOWS\system32\umjgayhv.dll
C:\WINDOWS\system32\upvsiglk.dll
C:\WINDOWS\system32\vtcmhxcu.dll
C:\WINDOWS\system32\wgxedwsd.dll
C:\WINDOWS\system32\xuolxatx.dll

.
((((((((((((((((((((((((( Files Created from 2007-11-03 to 2007-12-03 )))))))))))))))))))))))))))))))
.

2007-12-03 06:06 . 2007-12-03 06:06 73,280 –a—— C:\WINDOWS\SYSTEM32\uonnsrbm.dll
2007-12-03 06:00 . 2007-12-03 06:00 74,240 –a—— C:\WINDOWS\SYSTEM32\cvcjnxat.dll
2007-11-21 06:33 . 2007-11-27 06:58 784,426 –ahs—- C:\WINDOWS\SYSTEM32\vsljwbee.ini
2007-11-20 05:57 . 2007-11-20 05:57 74,512 –a—— C:\WINDOWS\SYSTEM32\rgfotmkr.dll
2007-11-15 06:43 . 2007-11-15 07:12 671,205 –ahs—- C:\WINDOWS\SYSTEM32\hwwfihhl.ini
2007-11-14 06:41 . 2007-11-15 06:41 671,136 –ahs—- C:\WINDOWS\SYSTEM32\nabyhhge.ini
2007-11-14 06:13 . 2007-09-24 23:31 69,632 –a—— C:\WINDOWS\SYSTEM32\javacpl.cpl
2007-11-14 06:12 . 2007-11-14 06:13 d——– C:\Program Files\Java
2007-11-14 06:12 . 2007-11-14 06:12 d——– C:\Program Files\Common Files\Java
2007-11-13 06:38 . 2007-11-13 06:38 65,480 –a—— C:\WINDOWS\SYSTEM32\ocyshetp.dll
2007-11-07 06:06 . 2007-11-07 06:06 65,480 –a—— C:\WINDOWS\SYSTEM32\gcfqopvy.dll
2007-11-06 06:00 . 2007-11-06 06:07 d——– C:\VundoFix Backups
2007-11-06 05:54 . 2007-11-06 05:54 65,480 –a—— C:\WINDOWS\SYSTEM32\wnnsfjeh.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-03 13:41 ——— d—–w C:\Program Files\Symantec AntiVirus
2007-11-29 19:36 ——— d—–w C:\Program Files\Puller
2007-11-15 20:05 ——— d—–w C:\Program Files\Google
2007-10-30 10:01 ——— d—–w C:\Program Files\MSXML 4.0
2004-03-01 17:54 50,320 —-a-w C:\Documents and Settings\slangfitt\Application Data\GDIPFONTCACHEV1.DAT
2004-03-01 17:54 50,320 —-a-w C:\Documents and Settings\dhorning\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95f23bd4-3774-4dd9-b818-7469a10e5016}]
2007-12-03 06:06 73280 –a—— C:\WINDOWS\system32\uonnsrbm.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2004-02-29 16:44]
"vptray"="C:\PROGRA~1\SYMANT~2\VPTray.exe" [2004-03-12 15:18]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-06-01 10:30]
"type32"="C:\Program Files\Microsoft IntelliType Pro\type32.exe" [2005-06-10 02:24]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2005-06-10 02:21]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe [2004-02-25 15:44:29]
AutoCAD Startup Accelerator.lnk - C:\Program Files\Common Files\Autodesk Shared\acstart16.exe [2004-02-25 02:35:22]
MyWebSearch Email Plugin.lnk - C:\qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE.vir [2006-02-13 15:31:37]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-04 00:56 15360 –a—— C:\WINDOWS\System32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\f86f5048]
rundll32.exe C:\WINDOWS\System32\oeuyfvfp.dll,b

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

R2 ASFAgent;ASF Agent;C:\Program Files\Intel\ASF Agent\ASFAgent.exe
R2 AsfAlrt;AsfAlrt;\??\C:\WINDOWS\System32\drivers\AsfAlrt.sys

.
**************************************************************************

catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-03 06:45:37
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-03 6:47:26 - machine was rebooted
.
— E O F —
Below is the hijackthis log.

Thanks for all your help, and all the great folks at WTT

Logfile of HijackThis v1.99.1
Scan saved at 06:07, on 2007-12-04
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~2\VPTray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gtrengineering.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http://GTR1:8080
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…?p=ZNxdm824DHUS
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…p1.0.0.15-3.cab
O16 - DPF: {401F2F3A-8C56-4736-8C9E-37854F174AC9} (ProjectPoint Document) - https://folders.buzzsaw.com/!/download/…Point-BZ-EN.exe
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.maricopa.gov/assessor/gis/plugin/mgaxctrl.cab
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file://C:\Program Files\AutoCAD 2002\AcDcToday.ocx
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://webcam5.corvettemuseum.com/activex/AxisCamControl.cab
O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Program Files\AutoCAD 2002\InstBanr.ocx
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file://C:\Program Files\AutoCAD 2002\InstFred.ocx
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Program Files\AutoCAD 2002\AcPreview.ocx
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = GTRENGINEERING.local
O17 - HKLM\Software\..\Telephony: DomainName = GTRENGINEERING.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = GTRENGINEERING.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = gtrengineering
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = GTRENGINEERING.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = gtrengineering
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = gtrengineering
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Autodesk Network Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskNetSrv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
Sorry about that. Not sure how I managed that. below is the log for todays date. Got a break btw the user is out sick today again so I have another day of no use on the PC.

ComboFix 07-12-02.7 - SLangfitt 2007-12-04 5:57:42.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.612 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\slangfitt\Desktop\cfscript.txt
* Created a new restore point

FILE
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MyWebSearch Email Plugin.lnk
C:\WINDOWS\SYSTEM32\cvcjnxat.dll
C:\WINDOWS\SYSTEM32\gcfqopvy.dll
C:\WINDOWS\SYSTEM32\hwwfihhl.ini
C:\WINDOWS\SYSTEM32\nabyhhge.ini
C:\WINDOWS\SYSTEM32\ocyshetp.dll
C:\WINDOWS\SYSTEM32\rgfotmkr.dll
C:\WINDOWS\SYSTEM32\uonnsrbm.dll
C:\WINDOWS\SYSTEM32\vsljwbee.ini
C:\WINDOWS\SYSTEM32\wnnsfjeh.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MyWebSearch Email Plugin.lnk
C:\VundoFix Backups
C:\VundoFix Backups\mljggeb.dll.bad
C:\WINDOWS\SYSTEM32\cvcjnxat.dll
C:\WINDOWS\SYSTEM32\gcfqopvy.dll
C:\WINDOWS\SYSTEM32\hwwfihhl.ini
C:\WINDOWS\SYSTEM32\nabyhhge.ini
C:\WINDOWS\SYSTEM32\ocyshetp.dll
C:\WINDOWS\SYSTEM32\rgfotmkr.dll
C:\WINDOWS\SYSTEM32\uonnsrbm.dll
C:\WINDOWS\SYSTEM32\vsljwbee.ini
C:\WINDOWS\SYSTEM32\wnnsfjeh.dll

.
((((((((((((((((((((((((( Files Created from 2007-11-04 to 2007-12-04 )))))))))))))))))))))))))))))))
.

2007-11-14 06:13 . 2007-09-24 23:31 69,632 –a—— C:\WINDOWS\SYSTEM32\javacpl.cpl
2007-11-14 06:12 . 2007-11-14 06:13 d——– C:\Program Files\Java
2007-11-14 06:12 . 2007-11-14 06:12 d——– C:\Program Files\Common Files\Java

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-04 13:01 ——— d—–w C:\Program Files\Symantec AntiVirus
2007-11-29 19:36 ——— d—–w C:\Program Files\Puller
2007-11-15 20:05 ——— d—–w C:\Program Files\Google
2007-10-30 10:01 ——— d—–w C:\Program Files\MSXML 4.0
2004-03-01 17:54 50,320 —-a-w C:\Documents and Settings\slangfitt\Application Data\GDIPFONTCACHEV1.DAT
2004-03-01 17:54 50,320 —-a-w C:\Documents and Settings\dhorning\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((( snapshot@2007-12-03_ 6.46.39.68 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-12-04 13:01:18 16,384 —-atw C:\WINDOWS\Temp\Perflib_Perfdata_664.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2004-02-29 16:44]
"vptray"="C:\PROGRA~1\SYMANT~2\VPTray.exe" [2004-03-12 15:18]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-06-01 10:30]
"type32"="C:\Program Files\Microsoft IntelliType Pro\type32.exe" [2005-06-10 02:24]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2005-06-10 02:21]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-04 00:56 15360 –a—— C:\WINDOWS\System32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

R2 ASFAgent;ASF Agent;C:\Program Files\Intel\ASF Agent\ASFAgent.exe
R2 AsfAlrt;AsfAlrt;\??\C:\WINDOWS\System32\drivers\AsfAlrt.sys

.
**************************************************************************

catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-04 06:03:08
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-04 6:04:55 - machine was rebooted
C:\ComboFix2.txt … 2007-12-03 06:47
.
— E O F —
Hi

Almost there.

  • Please go HERE to run PandaActiveScan…

  • Once you are on the Panda site click the Scan your PC button
  • A new window will open…click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)

  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to your desktop.Then post it in your next reply.
Took a little while to get it to complete. I had to run it a second time due to user(me) errors. The report is posted below. Incident Status Location Potentially unwanted tool:application/funweb Not disinfected c:\windows\downloaded program files\f3initialsetup1.0.0.15-3.inf Spyware:spyware/betterinet Not disinfected c:\windows\inf\banner.inf Potentially unwanted tool:application/mywebsearch Not disinfected hkey_local_machine\software\microsoft\windows\currentversion\uninstall\MyWebSearch bar Uninstall Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\slangfitt\Cookies\slangfitt@adrevolver[1].txt Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\slangfitt\Cookies\[removed][1].txt Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\slangfitt\Cookies\slangfitt@advertising[2].txt Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\slangfitt\Cookies\slangfitt@atdmt[2].txt Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\slangfitt\Cookies\slangfitt@atwola[1].txt Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\slangfitt\Cookies\slangfitt@doubleclick[1].txt Spyware:Cookie/Enhance Not disinfected C:\Documents and Settings\slangfitt\Cookies\slangfitt@enhance[1].txt Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\slangfitt\Cookies\slangfitt@fastclick[2].txt Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\slangfitt\Cookies\slangfitt@realmedia[1].txt Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\slangfitt\Cookies\slangfitt@tradedoubler[1].txt Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\slangfitt\Cookies\slangfitt@tradedoubler[2].txt Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\slangfitt\Cookies\slangfitt@tribalfusion[2].txt Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Documents and Settings\slangfitt\Desktop\ComboFix.exe[nircmd.exe] Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Documents and Settings\slangfitt\Desktop\ComboFix.exe[nircmd.cfexe] Potentially unwanted tool:Application/FunWeb Not disinfected C:\qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3HTML.DLL.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\M3MSG.DLL.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\M3PLUGIN.DLL.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\M3SLSRCH.EXE.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\M3SRCHMN.EXE.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\qoobox\Quarantine\C\Program Files\MyWebSearch\bar\2.bin\NPMYWEBS.DLL.vir Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\qoobox\Quarantine\C\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL.vir Spyware:Spyware/Vundo Not disinfected C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\agvtmlfm.dll.vir Spyware:Spyware/Vundo Not disinfected C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\efydpxvy.dll.vir Spyware:Spyware/Vundo Not disinfected C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\exaceoiu.dll.vir Spyware:Spyware/Vundo Not disinfected C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\fjbtuvjm.dll.vir Spyware:Spyware/Vundo Not disinfected C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\gcfqopvy.dll.vir Spyware:Spyware/Vundo Not disinfected C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\hbbotywe.dll.vir Spyware:Spyware/Vundo Not disinfected C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\ocyshetp.dll.vir Spyware:Spyware/Vundo Not disinfected C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\pwawmgyv.dll.vir Spyware:Spyware/Vundo Not disinfected C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\ruptmjlv.dll.vir Spyware:Spyware/Vundo Not disinfected C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\tddaqunl.dll.vir Spyware:Spyware/Vundo Not disinfected C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\tsmjmwdo.dll.vir Spyware:Spyware/Vundo Not disinfected C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\ubexavff.dll.vir Spyware:Spyware/Vundo Not disinfected C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\upvsiglk.dll.vir Spyware:Spyware/Vundo Not disinfected C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\wnnsfjeh.dll.vir Spyware:Spyware/Vundo Not disinfected C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\xuolxatx.dll.vir Spyware:Spyware/BetterInet Not disinfected C:\WINDOWS\banner.dll Virus:Generic Malware Disinfected C:\WINDOWS\Downloaded Program Files\CONFLICT.1\HbInstIE.dll Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\WINDOWS\NirCmd.exe Spyware:Spyware/Vundo Not disinfected C:\WINDOWS\SYSTEM32\bmiewdpo.dll Spyware:Spyware/Vundo Not disinfected C:\WINDOWS\SYSTEM32\fxcittgx.dll Spyware:Spyware/Vundo Not disinfected C:\WINDOWS\SYSTEM32\icrbqcfb.dll Spyware:Spyware/Vundo Not disinfected C:\WINDOWS\SYSTEM32\uxxbacrc.dll
Hi


Remember to disconnect from the Internet and disable your anti-virus before carrying out the next instruction, and to reenable the anti-virus before reconnecting to the Internet


Open Notepad - it must be Notepad, not Wordpad.
Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

File::
C:\WINDOWS\SYSTEM32\bmiewdpo.dll  
C:\WINDOWS\SYSTEM32\fxcittgx.dll
C:\WINDOWS\SYSTEM32\icrbqcfb.dll 
C:\WINDOWS\SYSTEM32\uxxbacrc.dll
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\HbInstIE.dll 
c:\windows\downloaded program files\f3initialsetup1.0.0.15-3.inf
C:\WINDOWS\banner.dll 
c:\windows\inf\banner.inf

Go to the Notepad window and click Edit > Paste
Then click File > Save
Name the file "CFScript.txt" (including the quotes)
Save the file to your Desktop

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task-Manager use the Processes tab (press ctrl alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

In your next reply post:
ComboFix.txt
New HJT log taken after the above scan has run


You may wish to keep hold of the Panda Online Scan as an extra on-demand virus-scanner.
If not you can uninstall it through Start>Control Panel>Add/Remove Programs
incoming logs :)

Have to let user on sys today btw.

ComboFix 07-12-02.7 - SLangfitt 2007-12-05 6:14:20.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.587 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\slangfitt\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\WINDOWS\banner.dll
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\HbInstIE.dll
c:\windows\downloaded program files\f3initialsetup1.0.0.15-3.inf
c:\windows\inf\banner.inf
C:\WINDOWS\SYSTEM32\bmiewdpo.dll
C:\WINDOWS\SYSTEM32\fxcittgx.dll
C:\WINDOWS\SYSTEM32\icrbqcfb.dll
C:\WINDOWS\SYSTEM32\uxxbacrc.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\banner.dll
c:\windows\downloaded program files\f3initialsetup1.0.0.15-3.inf
c:\windows\inf\banner.inf
C:\WINDOWS\SYSTEM32\bmiewdpo.dll
C:\WINDOWS\SYSTEM32\fxcittgx.dll
C:\WINDOWS\SYSTEM32\icrbqcfb.dll
C:\WINDOWS\SYSTEM32\uxxbacrc.dll

.
((((((((((((((((((((((((( Files Created from 2007-11-05 to 2007-12-05 )))))))))))))))))))))))))))))))
.

2007-12-04 08:19 . 2007-12-04 10:30 d——– C:\WINDOWS\SYSTEM32\ActiveScan
2007-12-04 08:19 . 2007-12-04 09:29 30,590 –a—— C:\WINDOWS\SYSTEM32\pavas.ico
2007-12-04 08:19 . 2007-12-04 09:29 2,550 –a—— C:\WINDOWS\SYSTEM32\Uninstall.ico
2007-12-04 08:19 . 2007-12-04 09:29 1,406 –a—— C:\WINDOWS\SYSTEM32\Help.ico
2007-11-14 06:13 . 2007-09-24 23:31 69,632 –a—— C:\WINDOWS\SYSTEM32\javacpl.cpl
2007-11-14 06:12 . 2007-11-14 06:13 d——– C:\Program Files\Java
2007-11-14 06:12 . 2007-11-14 06:12 d——– C:\Program Files\Common Files\Java

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-05 13:17 ——— d—–w C:\Program Files\Symantec AntiVirus
2007-12-04 17:16 ——— d—–w C:\Program Files\QuickTime
2007-12-04 17:15 ——— d—–w C:\Program Files\Microsoft IntelliType Pro
2007-12-04 17:15 ——— d—–w C:\Program Files\Microsoft IntelliPoint
2007-12-04 17:14 ——— d—–w C:\Program Files\Google
2007-12-04 17:13 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-12-04 17:12 ——— d—–w C:\Program Files\Common Files\Autodesk Shared
2007-11-29 19:36 ——— d—–w C:\Program Files\Puller
2007-10-30 10:01 ——— d—–w C:\Program Files\MSXML 4.0
2004-03-01 17:54 50,320 —-a-w C:\Documents and Settings\slangfitt\Application Data\GDIPFONTCACHEV1.DAT
2004-03-01 17:54 50,320 —-a-w C:\Documents and Settings\dhorning\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((( snapshot@2007-12-03_ 6.46.39.68 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-08-24 15:28:54 141,424 —-a-w C:\WINDOWS\Downloaded Program Files\asinst.dll
+ 2007-03-29 16:20:50 110,592 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\as.dll
+ 2006-10-05 23:15:26 233,472 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\ascontrol.dll
+ 2005-06-03 21:03:18 96,256 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\asmdat.dll
+ 2003-08-01 18:00:16 36,864 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\certdll.dll
+ 2005-05-20 20:42:44 86,016 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\instlsp.dll
+ 2006-02-17 01:20:20 4,608 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\memvfile.dll
+ 2005-10-26 01:08:32 348,160 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\msvcr71.dll
+ 2004-05-04 22:01:02 139,264 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pavaleas.dll
+ 2006-07-14 20:04:10 45,056 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pavdr.exe
+ 2006-04-10 17:50:02 159,832 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pavexcom.dll
+ 2006-02-14 20:05:38 94,208 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pavinas.dll
+ 2006-02-17 01:35:38 180,224 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pavoe.dll
+ 2006-10-05 23:15:38 122,880 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pavpz.dll
+ 2006-06-30 21:13:38 8,704 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pfdnnt.exe
+ 2004-02-04 21:08:42 49,152 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\port32.dll
+ 2006-08-01 20:23:10 69,632 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pscpu.dll
+ 2006-08-23 20:06:08 1,388,544 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskahk.dll
+ 2006-08-17 18:38:14 10,752 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskalloc.dll
+ 2006-09-04 18:49:54 61,440 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskas.dll
+ 2006-08-18 15:46:18 779,264 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskavs.dll
+ 2007-03-26 21:25:34 417,792 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskcmp.dll
+ 2006-08-09 17:42:24 90,112 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskfss.dll
+ 2006-07-19 17:55:58 208,896 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskhtml.dll
+ 2006-01-20 23:57:00 9,728 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskmas.dll
+ 2006-05-17 16:50:12 14,336 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskmdfs.dll
+ 2006-08-16 17:58:12 33,280 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskpack.dll
+ 2006-06-30 21:42:36 266,240 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskscs.dll
+ 2006-08-17 21:33:14 62,976 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskutil.dll
+ 2006-08-08 20:13:10 13,312 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskvfile.dll
+ 2006-08-18 15:53:08 69,632 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskvfs.dll
+ 2006-08-18 15:49:50 167,936 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\pskvm.dll
+ 2007-04-19 00:16:04 353,840 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\psscan.dll
+ 2007-01-22 21:42:48 35,328 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\rawvfile.dll
+ 1997-09-18 13:12:32 9,488 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\sporder.dll
+ 2006-03-01 00:23:40 69,632 —-a-w C:\WINDOWS\SYSTEM32\ActiveScan\tcpvfile.dll
+ 2006-08-02 19:39:06 73,728 —-a-w C:\WINDOWS\SYSTEM32\asuninst.exe
+ 2003-03-26 01:53:50 11,776 —-a-w C:\WINDOWS\SYSTEM32\ZPORT4AS.dll
+ 2007-12-05 13:17:17 16,384 —-atw C:\WINDOWS\Temp\Perflib_Perfdata_63c.dat
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2004-02-29 16:44]
"vptray"="C:\PROGRA~1\SYMANT~2\VPTray.exe" [2004-03-12 15:18]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-06-01 10:30]
"type32"="C:\Program Files\Microsoft IntelliType Pro\type32.exe" [2005-06-10 02:24]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2005-06-10 02:21]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-04 00:56 15360 –a—— C:\WINDOWS\System32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

R2 ASFAgent;ASF Agent;C:\Program Files\Intel\ASF Agent\ASFAgent.exe
R2 AsfAlrt;AsfAlrt;\??\C:\WINDOWS\System32\drivers\AsfAlrt.sys

.
**************************************************************************

catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-05 06:22:27
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-05 6:24:09 - machine was rebooted
C:\ComboFix2.txt … 2007-12-04 06:04
.
— E O F —

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI