That's not great news but I hope we can fix it. Here's the log files.
Logfile of HijackThis v1.99.1
Scan saved at 8:36:06 PM, on 12/3/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\BitTorrent_DNA\dna.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=566…age=www.msn.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {559D61D8-A64A-4677-9DB6-ACE525EC9514} - (no file)
O2 - BHO: (no name) - {7722642D-C56A-55E4-6E7E-07D5462CC3EE} - C:\Program Files\Psdjvtoc\yfetudro.dll
O2 - BHO: (no name) - {7B6E3CD8-7C3E-4130-B012-A9553EDB4C67} - (no file)
O2 - BHO: (no name) - {9319C22D-66F6-4A87-9755-0E2FABFA1847} - (no file)
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [LaunchAntiSpy] C:\Program Files\DefenderPro\TSAntiSpy.exe /startup
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\BitTorrent_DNA\dna.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Spoolsv] C:\WINDOWS\system32\spoolvs.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {64D01C7F-810D-446E-A07E-16C764235644} (AtlAtomadersCtlAttrib Class) -
http://zone.msn.com/bingame/amad/default/atomaders.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: opnmmli - opnmmli.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O21 - SSODL: E404Helper - {8906b1e9-98d7-4fce-8972-b372afe3d301} - e404d.dll (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
COMBO FIX
ComboFix 07-12-02.6 - Anderson Minnick 2007-12-03 19:52:17.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.514 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\check_LSA7.txt
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\autorun.exe
C:\Documents and Settings\Anderson Minnick\Application Data\Def\CnsMin.prf
C:\Documents and Settings\Anderson Minnick\Start Menu\Programs\Startup\findfast.exe
C:\Program Files\3269.exe
C:\Program Files\SecCenter
C:\Program Files\SecCenter\scprot4.exe.bak
C:\Program Files\ucleaner_setup.exe
C:\Program Files\Windows Media Player\hokemory555077.dll
C:\Program Files\xloader10181.exe
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\abW9
C:\Temp\abW9\tPho.log
C:\temp\tn3
C:\WINDOWS\cookies.ini
C:\WINDOWS\dobe~1
C:\WINDOWS\dobe~1\?dobe\
C:\WINDOWS\shell.exe
C:\WINDOWS\system32\buxioksj.ini
C:\WINDOWS\system32\c1
C:\WINDOWS\system32\ccnaxxop.exe
C:\WINDOWS\system32\cflfkhaw.dll
C:\WINDOWS\system32\cmiefxmi.dll
C:\WINDOWS\system32\cohxlpyc.exe
C:\WINDOWS\system32\dnpqiphi.exe
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\core.sys
C:\WINDOWS\system32\emsfnekk.exe
C:\WINDOWS\system32\eqgdtnni.dll
C:\WINDOWS\system32\esowcgvt.exe
C:\WINDOWS\system32\fjtnvvxp.exe
C:\WINDOWS\system32\gaungwei.ini
C:\WINDOWS\system32\gptytqhv.dll
C:\WINDOWS\system32\hkeopole.dll
C:\WINDOWS\system32\hsdqphuw.exe
C:\WINDOWS\system32\iewgnuag.dll
C:\WINDOWS\system32\iveirjxj.dll
C:\WINDOWS\system32\iyfafcoq.exe
C:\WINDOWS\system32\j2
C:\WINDOWS\system32\j2\ppjup83122.exe
C:\WINDOWS\system32\jjkkj.bak1
C:\WINDOWS\system32\jjkkj.bak2
C:\WINDOWS\system32\jjkkj.ini
C:\WINDOWS\system32\jjkkj.ini2
C:\WINDOWS\system32\jjkkj.tmp
C:\WINDOWS\system32\jkkjj.dll
C:\WINDOWS\system32\jskoixub.dll
C:\WINDOWS\system32\khkuevaq.ini
C:\WINDOWS\system32\kwqwvgfb.dll
C:\WINDOWS\system32\lbbuwweo.dll
C:\WINDOWS\system32\ldinfo.ldr
C:\WINDOWS\system32\lgiydgmn.dll
C:\WINDOWS\system32\lvixehjt.dll
C:\WINDOWS\system32\m8
C:\WINDOWS\system32\m8\nsts2dll1.exe
C:\WINDOWS\system32\nuiesgif.exe
C:\WINDOWS\system32\nyistnkk.exe
C:\WINDOWS\system32\ovesngnh.exe
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\povexsqn.exe
C:\WINDOWS\system32\printer.exe
C:\WINDOWS\system32\qaveukhk.dll
C:\WINDOWS\system32\qushqxgg.exe
C:\WINDOWS\system32\rlojhocl.exe
C:\WINDOWS\system32\rMa02yy
C:\WINDOWS\system32\sohwinsy.dll
C:\WINDOWS\system32\spoolvs.exe
C:\WINDOWS\system32\tjhexivl.ini
C:\WINDOWS\system32\towlhsbu.dll
C:\WINDOWS\system32\tpcwdoia
C:\WINDOWS\system32\tpcwdoia\bg1.gif
C:\WINDOWS\system32\tpcwdoia\bgtop.gif
C:\WINDOWS\system32\tpcwdoia\bottom1.gif
C:\WINDOWS\system32\tpcwdoia\essentials.gif
C:\WINDOWS\system32\tpcwdoia\icon1.ico
C:\WINDOWS\system32\tpcwdoia\install1.gif
C:\WINDOWS\system32\tpcwdoia\left1.gif
C:\WINDOWS\system32\tpcwdoia\li.gif
C:\WINDOWS\system32\tpcwdoia\logo.gif
C:\WINDOWS\system32\tpcwdoia\main.htm
C:\WINDOWS\system32\tpcwdoia\mainframe.htm
C:\WINDOWS\system32\tpcwdoia\reinstall1.gif
C:\WINDOWS\system32\tpcwdoia\right1.gif
C:\WINDOWS\system32\tpcwdoia\s1.htm
C:\WINDOWS\system32\tpcwdoia\s2.htm
C:\WINDOWS\system32\tpcwdoia\s3.htm
C:\WINDOWS\system32\tpcwdoia\SMTop1.gif
C:\WINDOWS\system32\tpcwdoia\SMTop2.gif
C:\WINDOWS\system32\tpcwdoia\SMTop3.gif
C:\WINDOWS\system32\tpcwdoia\SMTop4.gif
C:\WINDOWS\system32\tpcwdoia\soft1_off.gif
C:\WINDOWS\system32\tpcwdoia\soft1_off_ext.gif
C:\WINDOWS\system32\tpcwdoia\soft1_on.gif
C:\WINDOWS\system32\tpcwdoia\soft1_on_ext.gif
C:\WINDOWS\system32\tpcwdoia\soft2_off.gif
C:\WINDOWS\system32\tpcwdoia\soft2_off_ext.gif
C:\WINDOWS\system32\tpcwdoia\soft2_on.gif
C:\WINDOWS\system32\tpcwdoia\soft2_on_ext.gif
C:\WINDOWS\system32\tpcwdoia\soft3_off.gif
C:\WINDOWS\system32\tpcwdoia\soft3_off_ext.gif
C:\WINDOWS\system32\tpcwdoia\soft3_on.gif
C:\WINDOWS\system32\tpcwdoia\soft3_on_ext.gif
C:\WINDOWS\system32\tpcwdoia\softbottom_off.gif
C:\WINDOWS\system32\tpcwdoia\softbottom_on.gif
C:\WINDOWS\system32\tpcwdoia\softleft_off.gif
C:\WINDOWS\system32\tpcwdoia\softleft_on.gif
C:\WINDOWS\system32\tpcwdoia\top1.gif
C:\WINDOWS\system32\tpcwdoia\top2.gif
C:\WINDOWS\system32\tpcwdoia\tpcwdoia1.exe
C:\WINDOWS\system32\tpcwdoia\tpcwdoia2.exe
C:\WINDOWS\system32\tpcwdoia\tpcwdoia3.exe
C:\WINDOWS\system32\tpcwdoia\turnoff1.gif
C:\WINDOWS\system32\tpcwdoia\turnon1.gif
C:\WINDOWS\system32\vawllrvf.dll
C:\WINDOWS\system32\xdbvigdj.dll
C:\WINDOWS\system32\yevcyhlk.exe
C:\WINDOWS\tk58.exe
C:\WINDOWS\TTC-4444.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\LEGACY_CORE
——-\LEGACY_DOMAINSERVICE
——-\core
——-\DomainService
((((((((((((((((((((((((( Files Created from 2007-11-04 to 2007-12-04 )))))))))))))))))))))))))))))))
.
2007-12-03 09:16 . 2007-12-03 09:16 73,280 –a—— C:\WINDOWS\system32\pbvfehbr.dll
2007-12-01 14:11 . 2007-12-02 14:28 793,673 –ahs—- C:\WINDOWS\system32\mxfcjwts.ini
2007-11-29 18:30 . 2007-11-29 18:30 d——– C:\Documents and Settings\Anderson Minnick\Application Data\Grisoft
2007-11-29 18:30 . 2007-11-29 18:30 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-29 18:30 . 2007-05-30 07:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-11-29 15:24 . 2007-11-29 15:25 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-29 15:15 . 2007-11-29 18:45 789,968 –ahs—- C:\WINDOWS\system32\pjgnrapo.ini
2007-11-29 15:13 . 2007-12-03 19:56 d——– C:\Documents and Settings\Anderson Minnick\Application Data\Def
2007-11-29 15:13 . 2007-11-29 15:13 d——– C:\Documents and Settings\Anderson Minnick\Application Data\Bin
2007-11-29 11:14 . 2007-11-29 15:12 790,141 –ahs—- C:\WINDOWS\system32\xmxunpds.ini
2007-11-28 20:00 . 2007-11-29 11:14 789,418 –ahs—- C:\WINDOWS\system32\cfwulrgu.ini
2007-11-28 18:53 . 2007-11-29 18:37 0 –a—— C:\WINDOWS\system32\mcrh.tmp
2007-11-28 18:52 . 2007-11-28 18:52 90 –ahs—- C:\WINDOWS\klif.spi
2007-11-28 13:13 . 2007-11-28 13:13 d——– C:\WINDOWS\AntiSpy
2007-11-28 13:13 . 2007-11-29 12:00 137 –a—— C:\WINDOWS\tsiwinfile.dat
2007-11-28 13:09 . 2007-11-28 13:09 789,349 –ahs—- C:\WINDOWS\system32\uwdmlncc.ini
2007-11-27 20:00 . 2007-11-27 20:00 3,120 –a—— C:\WINDOWS\system32\DRWSJLAD.ocx
2007-11-27 20:00 . 2007-11-27 20:00 3,120 –a—— C:\WINDOWS\LJRGKDD9.ocx
2007-11-27 19:59 . 2007-11-29 11:24 d——– C:\Program Files\Defender Pro
2007-11-27 19:59 . 2007-11-28 20:00 d——– C:\Documents and Settings\All Users\Application Data\Defender Pro
2007-11-27 18:12 . 2007-11-27 18:24 10,240 –a—— C:\Program Files\spoolsv.exe
2007-11-27 18:11 . 2007-11-27 18:11 d——– C:\Program Files\Psdjvtoc
2007-11-27 18:11 . 2007-11-29 16:20 d——– C:\Documents and Settings\All Users\Application Data\Rabio
2007-11-27 18:10 . 2007-11-27 18:10 1,149,472 –a—— C:\Install
2007-11-27 18:10 . 2007-11-27 18:10 123 –a—— C:\Documents and Settings\Anderson Minnick\mit.bat
2007-11-27 17:45 . 2007-11-27 18:12 d——– C:\Program Files\Mozilla Sunbird
2007-11-27 17:45 . 2007-11-27 17:45 d——– C:\Documents and Settings\Anderson Minnick\Application Data\Talkback
2007-11-25 17:51 . 2007-11-25 17:51 d——– C:\Documents and Settings\Anderson Minnick\Application Data\CyberLink
2007-11-24 21:16 . 2007-11-24 21:16 d——– C:\Documents and Settings\Anderson Minnick\Application Data\vlc
2007-11-24 20:44 . 2007-11-24 20:44 d——– C:\Documents and Settings\Anderson Minnick\Application Data\dvdcss
2007-11-24 20:42 . 2007-11-24 20:42 d——– C:\Program Files\Windows Media Bonus Pack for Windows XP
2007-11-24 20:42 . 2007-11-24 20:42 d——– C:\Program Files\VideoLAN
2007-11-24 20:42 . 2001-11-30 19:05 131,072 –a—— C:\WINDOWS\system32\dzip32.dll
2007-11-24 20:42 . 2001-11-30 19:05 110,592 –a—— C:\WINDOWS\system32\dunzip32.dll
2007-11-22 21:41 . 2007-11-22 21:42 d——– C:\Documents and Settings\Anderson Minnick\Application Data\DivX
2007-11-22 21:38 . 2007-11-28 19:13 d——– C:\Program Files\DivX
2007-11-22 21:38 . 2007-10-19 19:56 129,784 –a—— C:\WINDOWS\system32\pxafs.dll
2007-11-22 21:38 . 2007-10-19 19:56 9,464 ——— C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-11-22 21:38 . 2007-10-19 19:56 9,336 ——— C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-11-21 23:52 . 2007-11-21 23:52 0 –a—— C:\WINDOWS\tosOBEX.INI
2007-11-21 23:51 . 2007-11-21 23:51 d——– C:\Documents and Settings\Anderson Minnick\Application Data\Toshiba
2007-11-12 14:37 . 2007-11-12 14:37 d——– C:\Program Files\BitTorrent_DNA
2007-11-12 14:37 . 2007-12-03 19:58 d——– C:\Documents and Settings\Anderson Minnick\Application Data\BitTorrent DNA
2007-11-12 14:37 . 2007-11-24 20:45 d——– C:\Documents and Settings\Anderson Minnick\Application Data\BitTorrent
2007-11-11 16:28 . 2007-11-11 16:28 155,136 –a—— C:\WINDOWS\Doc1.doc
2007-11-09 13:11 . 2007-11-09 13:11 d——– C:\Program Files\iPod
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-29 00:13 ——— d—–w C:\Program Files\QuickTime
2007-11-29 00:13 ——— d—–w C:\Program Files\Modem Helper
2007-11-29 00:13 ——— d—–w C:\Program Files\Dell
2007-11-09 18:11 ——— d—–w C:\Program Files\iTunes
2007-10-29 17:40 ——— d—–w C:\Documents and Settings\Anderson Minnick\Application Data\MusicUploader
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-20 00:56 524,288 —-a-w C:\WINDOWS\system32\DivXsm.exe
2007-10-20 00:56 43,528 ——w C:\WINDOWS\system32\drivers\pxhelp20.sys
2007-10-20 00:56 3,596,288 —-a-w C:\WINDOWS\system32\qt-dx331.dll
2007-10-20 00:56 200,704 —-a-w C:\WINDOWS\system32\ssldivx.dll
2007-10-20 00:56 120,056 —-a-w C:\WINDOWS\system32\pxcpyi64.exe
2007-10-20 00:56 118,520 —-a-w C:\WINDOWS\system32\pxinsi64.exe
2007-10-20 00:56 1,044,480 —-a-w C:\WINDOWS\system32\libdivx.dll
2007-10-20 00:54 823,296 —-a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-10-20 00:54 823,296 —-a-w C:\WINDOWS\system32\divx_xx07.dll
2007-10-20 00:54 81,920 —-a-w C:\WINDOWS\system32\dpl100.dll
2007-10-20 00:54 802,816 —-a-w C:\WINDOWS\system32\divx_xx11.dll
2007-10-20 00:54 739,840 —-a-w C:\WINDOWS\system32\DivX.dll
2007-10-20 00:54 196,608 —-a-w C:\WINDOWS\system32\dtu100.dll
2007-10-18 09:06 156,992 —-a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-10-18 09:03 593,920 —-a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-10-18 09:03 57,344 —-a-w C:\WINDOWS\system32\dpv11.dll
2007-10-18 09:03 53,248 —-a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-10-18 09:03 344,064 —-a-w C:\WINDOWS\system32\dpus11.dll
2007-10-18 09:03 294,912 —-a-w C:\WINDOWS\system32\dpu11.dll
2007-10-18 09:03 294,912 —-a-w C:\WINDOWS\system32\dpu10.dll
2007-10-18 09:02 12,288 —-a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-10-10 01:40 ——— d—–w C:\Documents and Settings\Anderson Minnick\Application Data\Apple Computer
2007-10-07 17:44 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-10-05 22:19 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL OCP
2007-10-05 22:18 ——— d—–w C:\Program Files\AIM6
2007-10-05 22:18 ——— d—–w C:\Documents and Settings\Anderson Minnick\Application Data\acccore
2007-10-05 22:18 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2007-10-05 22:16 ——— d—–w C:\Program Files\Common Files\AOL
2007-10-04 20:51 ——— d—–w C:\Program Files\AxBx
2007-09-12 18:52 53,248 —-a-w C:\WINDOWS\hg173.exe
2007-09-12 18:50 53,248 —-a-w C:\WINDOWS\df87173.exe
2006-12-03 01:05 2,522 —-a-w C:\Program Files\func.js
2006-11-25 07:57 482 —-a-w C:\Program Files\Del.js
2005-07-29 21:24 472 –sha-r C:\WINDOWS\TWFydGluIE1pbm5pY2s\nqIVx35RKHYDvAcDsZP.vbs
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4CB8F4B4-5F66-4D9E-BC3B-184596A58824}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{559D61D8-A64A-4677-9DB6-ACE525EC9514}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7722642D-C56A-55E4-6E7E-07D5462CC3EE}]
2007-11-27 18:11 110592 –a—— C:\Program Files\Psdjvtoc\yfetudro.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7B6E3CD8-7C3E-4130-B012-A9553EDB4C67}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9319C22D-66F6-4A87-9755-0E2FABFA1847}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A48A15DA-A31A-4403-ACE2-09B450EBA9FF}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FCD85C5E-B272-4CB8-9B01-38CE170A14A9}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2005-11-15 18:44]
"Aim6"="" []
"BitTorrent DNA"="C:\Program Files\BitTorrent_DNA\dna.exe" [2007-11-12 14:37]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2005-05-31 01:04]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-09-13 16:33]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 14:59]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-12-03 21:00]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2005-03-04 11:26]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-09-10 13:51]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-10-19 20:16]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-02 18:36]
"LaunchAntiSpy"="C:\Program Files\DefenderPro\TSAntiSpy.exe" []
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2004-12-22 13:42:22]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2005-06-03 01:22:01]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"E404Helper"= {8906b1e9-98d7-4fce-8972-b372afe3d301} - e404d.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-09-07 16:08 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\opnmmli]
opnmmli.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchIndexer]
rundll32.exe C:\WINDOWS\system32\hgcessog.dll,sitypnow
S1 SAVOnAccessControl;SAVOnAccessControl;C:\WINDOWS\system32\DRIVERS\savonaccesscontrol.sys
S1 SAVOnAccessFilter;SAVOnAccessFilter;C:\WINDOWS\system32\DRIVERS\savonaccessfilter.sys
.
Contents of the 'Scheduled Tasks' folder
"2007-11-28 18:15:36 C:\WINDOWS\Tasks\AntiSpy.job"
- C:\Program Files\DefenderPro\TSAntiSpy.exe
"2007-11-15 18:09:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-12-04 00:57:00 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDetect.exe
.
**************************************************************************
catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-03 20:00:53
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-03 20:01:28 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-10-07 13:13
C:\ComboFix2.txt … 2007-10-07 13:13
.
— E O F —
Thank you very much for your help. What's the next step?