This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Explorer popups while using Firefox! help!

50 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello! I have been following another thread on here about this same topic and I tried Dr. web Cure and malwarebytes anti-malware to no avail. Could someone please help me??? Thanks! here is my hijackthis log:

Logfile of HijackThis v1.99.1
Scan saved at 1:03:16 AM, on 1/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\QuickTime\QTTask .exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {3CAB59DF-4114-4306-9216-1759258C34D8} - C:\Program Files\Messenger\pozefomexC:\WINDOWS\system32\doc4\mmildot83122.exe.dll (file missing)
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {8E3FBDE2-7DBD-4040-85D9-29BBC559C129} - C:\WINDOWS\system32\rqrqnol.dll (file missing)
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - (no file)
O2 - BHO: {e9e59c00-91ca-1b78-6574-eb6e327a378f} - {f873a723-e6be-4756-87b1-ac1900c95e9e} - C:\WINDOWS\system32\kiqrrpam.dll
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm .exe" -startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask .exe" -atboottime
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [16447d62] rundll32.exe "C:\WINDOWS\system32\myxaasyu.dll",b
O4 - HKLM\..\Run: [MATH DOES FIRST MODE] C:\Documents and Settings\All Users\Application Data\live 64 math does\knob name.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [barb size] C:\DOCUME~1\ANDREW~1.WHA\APPLIC~1\OWNSID~1\skip chin.exe
O4 - HKCU\..\Run: [Creative Live! Cam Manager] "C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe"
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://72.32.179.44/filter/cameraviewer/isetup.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su2/CTL_V02002/ocx/15030/CTPID.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: rqrqnol - rqrqnol.dll (file missing)
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
Hi bpsig and welcome to the forums.

My name is Dave. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can sometimes take a while to research so please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.


Please download ComboFix by sUBs from HERE or HERE
  • You must download it to and run it from your Desktop
  • Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
  • Double click combofix.exe & follow the prompts.
  • When finished, it will produce a log. Please save that log to post in your next reply along with a fresh HJT log
  • Re-enable all the programs that were disabled during the running of ComboFix..

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Dave,

Thank you very much for your help!

here is my combofix log:

ComboFix 08-01-15.1 - Andrew 2008-01-14 12:55:45.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1548 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\bkR11
C:\Temp\bkR11\ftCa.log
C:\temp\tn3
C:\WINDOWS\cookies.ini
C:\WINDOWS\Fonts\a.zip
C:\WINDOWS\system32\bbc5
C:\WINDOWS\system32\cknhegsd.ini
C:\WINDOWS\system32\dccdd.ini
C:\WINDOWS\system32\dccdd.ini2
C:\WINDOWS\system32\doc4
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\core.sys
C:\WINDOWS\system32\drivers\sfsync02.sys
C:\WINDOWS\system32\dsgehnkc.dll
C:\WINDOWS\system32\kiqrrpam.dll
C:\WINDOWS\system32\myxaasyu.dll
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\rex2
C:\WINDOWS\system32\uysaaxym.ini
C:\x.dat
C:\z.dat
D:\Autorun.inf
C:\WINDOWS\Fonts\'

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_CORE
——-\LEGACY_DOMAINSERVICE
——-\LEGACY_SFSYNC02
——-\core
——-\sfsync02


((((((((((((((((((((((((( Files Created from 2007-12-15 to 2008-01-15 )))))))))))))))))))))))))))))))
.

2008-01-14 12:55 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-09 01:09 . 2008-01-09 01:09 d——– C:\Documents and Settings\Andrew.WHARTON\Application Data\ownsidlehope
2008-01-08 13:16 . 2008-01-08 13:46 d——– C:\Documents and Settings\Andrew.WHARTON\DoctorWeb
2008-01-07 20:13 . 2008-01-07 20:13 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-01-07 20:13 . 2008-01-07 20:13 d——– C:\Documents and Settings\Andrew.WHARTON\Application Data\Malwarebytes
2008-01-07 00:34 . 2008-01-07 00:34 d——– C:\Program Files\ownsidlehope
2008-01-05 01:01 . 2008-01-05 01:06 5,062 –a—— C:\WINDOWS\system32\tmp.reg
2008-01-05 01:00 . 2007-09-05 23:22 289,144 –a—— C:\WINDOWS\system32\VCCLSID.exe
2008-01-05 01:00 . 2006-04-27 16:49 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2008-01-05 01:00 . 2007-12-20 23:11 81,920 –a—— C:\WINDOWS\system32\IEDFix.exe
2008-01-05 01:00 . 2004-07-31 17:50 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2008-01-05 01:00 . 2007-10-03 23:36 25,600 –a—— C:\WINDOWS\system32\WS2Fix.exe
2008-01-03 14:22 . 2008-01-03 14:25 d——– C:\Documents and Settings\Andrew.WHARTON\Application Data\U3
2008-01-01 13:57 . 2008-01-01 13:57 d——– C:\Program Files\Polar
2007-12-28 10:17 . 2007-12-28 10:17 35,328 –a—— C:\WINDOWS\system32\LJJKJKL.0LL
2007-12-24 12:52 . 2008-01-07 00:27 94,208 –a—— C:\WINDOWS\system32\igfxtray .exe
2007-12-22 23:00 . 2008-01-07 00:27 118,784 –a—— C:\WINDOWS\system32\igfxpers .exe
2007-12-22 23:00 . 2008-01-07 00:27 77,824 –a—— C:\WINDOWS\system32\hkcmd .exe
2007-12-22 23:00 . 2008-01-07 00:28 32,768 –a—— C:\WINDOWS\V0400Mon .exe
2007-12-22 23:00 . 2008-01-03 11:04 15,360 –a—— C:\WINDOWS\system32\ctfmon .exe
2007-12-19 22:46 . 2007-12-19 22:46 147,456 –a—— C:\WINDOWS\system32\vbzip10.dll
2007-12-19 22:43 . 2007-12-19 22:43 d——– C:\WINDOWS\system32\ripd1
2007-12-19 22:43 . 2008-01-08 16:46 d——– C:\WINDOWS\system32\daSgo05
2007-12-19 22:43 . 2007-12-22 22:59 d——– C:\WINDOWS\system32\ashell3
2007-12-19 22:43 . 2007-12-19 22:43 532,810 –a—— C:\Temp\OHOWu1125.exe
2007-12-19 22:43 . 2007-12-19 22:43 134 –a—— C:\n.bat
2007-12-19 22:41 . 2007-12-28 10:16 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-15 20:02 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-01-08 22:21 ——— d—–w C:\Program Files\QuickTime
2008-01-08 22:19 ——— d—–w C:\Program Files\music_now
2008-01-08 20:32 ——— d—–w C:\Documents and Settings\All Users\Application Data\live 64 math does
2008-01-08 20:17 ——— d—–w C:\Program Files\iTunes
2008-01-08 20:17 ——— d—–w C:\Program Files\Essentials Codec Pack
2008-01-08 20:17 ——— d—–w C:\Program Files\DAEMON Tools
2008-01-08 20:17 ——— d—–w C:\Program Files\AIM
2007-12-28 17:21 ——— d—–w C:\Documents and Settings\Andrew.WHARTON\Application Data\LimeWire
2007-12-28 17:21 ——— d—–w C:\Documents and Settings\Andrew.WHARTON\Application Data\FrostWire
2007-12-23 05:58 ——— d—–w C:\Documents and Settings\Andrew.WHARTON\Application Data\Azureus
2007-12-17 04:21 ——— d—–w C:\Documents and Settings\All Users\Application Data\Dvdaxismultident
2007-12-09 05:43 ——— d—–w C:\Program Files\Java
2007-07-07 06:46 0 —-a-w C:\Documents and Settings\Andrew.WHARTON\Application Data\wklnhst.dat
.
—-a-w		 2,578,944 2008-01-07 07:44:05  C:\Documents and Settings\All Users\Application Data\live 64 math does\bait road .exe
—-a-w		 2,537,472 2008-01-07 07:29:01  C:\Documents and Settings\All Users\Application Data\live 64 math does\BAITRO~1 .EXE
—-a-w		 3,525,632 2008-01-04 16:57:48  C:\Documents and Settings\All Users\Application Data\live 64 math does\funk peak .exe
—-a-w		 3,482,624 2008-01-04 17:01:12  C:\Documents and Settings\All Users\Application Data\live 64 math does\FUNKPE~1 .EXE
—-a-w			67,112 2008-01-04 16:55:25  C:\Program Files\AIM\aim .exe
—-a-w			81,920 2008-01-08 08:22:28  C:\Program Files\Common Files\InstallShield\UpdateService\issch .exe
—-a-w		   249,856 2008-01-05 07:46:42  C:\Program Files\Common Files\InstallShield\UpdateService\isuspm		.exe
—-a-w		   249,856 2008-01-07 07:29:23  C:\Program Files\Common Files\InstallShield\UpdateService\isuspm .exe
—-a-w		   185,632 2008-01-08 08:22:30  C:\Program Files\Common Files\Real\Update_OB\realsched .exe
—-a-w			53,408 2008-01-07 07:27:59  C:\Program Files\Common Files\Symantec Shared\ccApp .exe
—-a-w		   155,648 2008-01-07 07:28:29  C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr .exe
—-a-w		   133,016 2008-01-08 08:22:30  C:\Program Files\DAEMON Tools\daemon .exe
—-a-w		   303,104 2008-01-08 08:22:31  C:\Program Files\Essentials Codec Pack\update .exe
—-a-w		   131,072 2008-01-08 08:22:28  C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl .exe
—-a-w			49,152 2008-01-07 07:27:59  C:\Program Files\Hp\HP Software Update\HPWuSchd2 .exe
—-a-w		   102,400 2008-01-07 07:27:59  C:\Program Files\Hp\QuickPlay\QPService .exe
—-a-w			40,960 2008-01-07 07:28:02  C:\Program Files\HPQ\Default Settings\cpqset .exe
—-a-w		   454,656 2008-01-07 07:27:56  C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant .exe
—-a-w		   271,672 2008-01-07 07:28:12  C:\Program Files\iTunes\iTunesHelper .exe
—-a-w		   132,496 2008-01-07 07:27:54  C:\Program Files\Java\jre1.6.0_02\bin\jusched .exe
—-a-w		   286,720 2008-01-05 07:46:53  C:\Program Files\QuickTime\QTTask			.exe
—-a-w		   761,948 2008-01-07 07:28:04  C:\Program Files\Synaptics\SynTP\SynTPEnh .exe
—-a-w		 1,885,464 2007-12-24 19:53:14  C:\RECYCLER\S-1-5-21-3693728610-3715699884-4033796838-1005\Dc155\RegistryBooster 2\RegistryBooster .exe
—-a-w		   408,576 2008-01-07 07:28:32  C:\RECYCLER\S-1-5-21-3693728610-3715699884-4033796838-1005\Dc171\skip chin .exe
—-a-w			32,768 2008-01-07 07:28:11  C:\WINDOWS\V0400Mon .exe
—-a-w			64,512 2008-01-07 07:27:53  C:\WINDOWS\ehome\ehtray .exe
—-a-w		 1,187,840 2008-01-07 07:28:11  C:\WINDOWS\SMINST\RecGuard .exe
—-a-w			15,360 2008-01-03 18:04:38  C:\WINDOWS\system32\ctfmon .exe
—-a-w			77,824 2008-01-07 07:27:56  C:\WINDOWS\system32\hkcmd .exe
—-a-w		   118,784 2008-01-07 07:27:56  C:\WINDOWS\system32\igfxpers .exe
—-a-w			94,208 2008-01-07 07:27:55  C:\WINDOWS\system32\igfxtray .exe


– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3CAB59DF-4114-4306-9216-1759258C34D8}]
C:\Program Files\Messenger\pozefomexC:\WINDOWS\system32\doc4\mmildot83122.exe.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 00:00 15360]
"barb size"="C:\DOCUME~1\ANDREW~1.WHA\APPLIC~1\OWNSID~1\skip chin.exe" [ ]
"Creative Live! Cam Manager"="C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsmqIntCert"="regsvr32 /s mqrt.dll" []
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-04-18 04:29 61952 C:\WINDOWS\system32\CHDAudPropShortcut.exe]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm .exe" [2008-01-07 00:29 249856]
"RegistryMechanic"="" []
"QuickTime Task"="C:\Program Files\QuickTime\QTTask .exe" [2008-01-05 00:46 286720]
"MATH DOES FIRST MODE"="C:\Documents and Settings\All Users\Application Data\live 64 math does\knob name.exe" [2008-01-15 13:03 2611712]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-09-27 18:17 443968]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2006-08-16 12:27:07]
HP Photosmart Premier Fast Start.lnk - C:\Program Files\Hp\Digital Imaging\bin\hpqthb08.exe [2005-09-24 10:39:30]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rqrqnol]
rqrqnol.dll

R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 14:38]
S3 VF0400Afx;VF0400 Audio FX;C:\WINDOWS\system32\Drivers\V0400Afx.sys [2007-06-10 10:01]
S3 VF0400Vfx;VF0400 Video FX;C:\WINDOWS\system32\DRIVERS\V0400VFx.sys [2007-03-05 03:45]
S3 VF0400Vid;Live! Cam Notebook Pro (VF0400);C:\WINDOWS\system32\DRIVERS\V0400Vid.sys [2007-06-06 10:01]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{000b1eee-aea1-11dc-b995-0016d42eb995}]
\Shell\AutoRun\command - G:\wd_windows_tools\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fbc7adea-ba41-11dc-b9a1-0013025bb5a0}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a

*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-01-15 20:00:00 C:\WINDOWS\Tasks\AA620524918DB830.job"
- c:\docume~1\andrew~1.wha\applic~1\ownsid~1\second curb okay.exe
"2008-01-10 16:52:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2006-11-18 17:56:42 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-15 13:02:56
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-15 13:05:56 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-15 20:05:54
.
2008-01-09 08:35:53 — E O F —
and here is my new hijackthis log:

Logfile of HijackThis v1.99.1
Scan saved at 1:07:04 PM, on 1/15/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\QuickTime\QTTask .exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {3CAB59DF-4114-4306-9216-1759258C34D8} - C:\Program Files\Messenger\pozefomexC:\WINDOWS\system32\doc4\mmildot83122.exe.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm .exe" -startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask .exe" -atboottime
O4 - HKLM\..\Run: [MATH DOES FIRST MODE] C:\Documents and Settings\All Users\Application Data\live 64 math does\knob name.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [barb size] C:\DOCUME~1\ANDREW~1.WHA\APPLIC~1\OWNSID~1\skip chin.exe
O4 - HKCU\..\Run: [Creative Live! Cam Manager] "C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe"
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://72.32.179.44/filter/cameraviewer/isetup.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su2/CTL_V02002/ocx/15030/CTPID.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: rqrqnol - rqrqnol.dll (file missing)
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\WINDOWS\system32\doc4\mmildot83122.exe.dll
C:\WINDOWS\Tasks\AA620524918DB830.job

Folder::
C:\Program Files\Messenger\pozefomex
C:\Documents and Settings\ANDREW~1.WHA\APPLIC~1\OWNSID~1
C:\Program Files\ownsidlehope
C:\Documents and Settings\All Users\Application Data\live 64 math does

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3CAB59DF-4114-4306-9216-1759258C34D8}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"barb size"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MATH DOES FIRST MODE"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rqrqnol]


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.
CF log:

ComboFix 08-01-15.1 - Andrew 2008-01-15 13:50:53.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1527 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Andrew.WHARTON\Desktop\Cfscript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\WINDOWS\system32\doc4\mmildot83122.exe.dll
C:\WINDOWS\Tasks\AA620524918DB830.job
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\live 64 math does
C:\Documents and Settings\All Users\Application Data\live 64 math does\bait road .exe
C:\Documents and Settings\All Users\Application Data\live 64 math does\BAITRO~1 .EXE
C:\Documents and Settings\All Users\Application Data\live 64 math does\funk peak .exe
C:\Documents and Settings\All Users\Application Data\live 64 math does\FUNKPE~1 .EXE
C:\Documents and Settings\All Users\Application Data\live 64 math does\knob name.exe
C:\Documents and Settings\ANDREW~1.WHA\APPLIC~1\OWNSID~1
C:\Program Files\ownsidlehope
C:\WINDOWS\Tasks\AA620524918DB830.job

.
((((((((((((((((((((((((( Files Created from 2007-12-15 to 2008-01-15 )))))))))))))))))))))))))))))))
.

2008-01-14 12:55 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-08 13:16 . 2008-01-08 13:46 d——– C:\Documents and Settings\Andrew.WHARTON\DoctorWeb
2008-01-07 20:13 . 2008-01-07 20:13 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-01-07 20:13 . 2008-01-07 20:13 d——– C:\Documents and Settings\Andrew.WHARTON\Application Data\Malwarebytes
2008-01-05 01:01 . 2008-01-05 01:06 5,062 –a—— C:\WINDOWS\system32\tmp.reg
2008-01-05 01:00 . 2007-09-05 23:22 289,144 –a—— C:\WINDOWS\system32\VCCLSID.exe
2008-01-05 01:00 . 2006-04-27 16:49 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2008-01-05 01:00 . 2007-12-20 23:11 81,920 –a—— C:\WINDOWS\system32\IEDFix.exe
2008-01-05 01:00 . 2004-07-31 17:50 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2008-01-05 01:00 . 2007-10-03 23:36 25,600 –a—— C:\WINDOWS\system32\WS2Fix.exe
2008-01-03 14:22 . 2008-01-03 14:25 d——– C:\Documents and Settings\Andrew.WHARTON\Application Data\U3
2008-01-01 13:57 . 2008-01-01 13:57 d——– C:\Program Files\Polar
2007-12-28 10:17 . 2007-12-28 10:17 35,328 –a—— C:\WINDOWS\system32\LJJKJKL.0LL
2007-12-24 12:52 . 2008-01-07 00:27 94,208 –a—— C:\WINDOWS\system32\igfxtray .exe
2007-12-22 23:00 . 2008-01-07 00:27 118,784 –a—— C:\WINDOWS\system32\igfxpers .exe
2007-12-22 23:00 . 2008-01-07 00:27 77,824 –a—— C:\WINDOWS\system32\hkcmd .exe
2007-12-22 23:00 . 2008-01-07 00:28 32,768 –a—— C:\WINDOWS\V0400Mon .exe
2007-12-22 23:00 . 2008-01-03 11:04 15,360 –a—— C:\WINDOWS\system32\ctfmon .exe
2007-12-19 22:46 . 2007-12-19 22:46 147,456 –a—— C:\WINDOWS\system32\vbzip10.dll
2007-12-19 22:43 . 2007-12-19 22:43 d——– C:\WINDOWS\system32\ripd1
2007-12-19 22:43 . 2008-01-08 16:46 d——– C:\WINDOWS\system32\daSgo05
2007-12-19 22:43 . 2007-12-22 22:59 d——– C:\WINDOWS\system32\ashell3
2007-12-19 22:43 . 2007-12-19 22:43 532,810 –a—— C:\Temp\OHOWu1125.exe
2007-12-19 22:43 . 2007-12-19 22:43 134 –a—— C:\n.bat
2007-12-19 22:41 . 2007-12-28 10:16 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-15 20:02 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-01-08 22:21 ——— d—–w C:\Program Files\QuickTime
2008-01-08 22:19 ——— d—–w C:\Program Files\music_now
2008-01-08 20:17 ——— d—–w C:\Program Files\iTunes
2008-01-08 20:17 ——— d—–w C:\Program Files\Essentials Codec Pack
2008-01-08 20:17 ——— d—–w C:\Program Files\DAEMON Tools
2008-01-08 20:17 ——— d—–w C:\Program Files\AIM
2007-12-28 17:21 ——— d—–w C:\Documents and Settings\Andrew.WHARTON\Application Data\LimeWire
2007-12-28 17:21 ——— d—–w C:\Documents and Settings\Andrew.WHARTON\Application Data\FrostWire
2007-12-23 05:58 ——— d—–w C:\Documents and Settings\Andrew.WHARTON\Application Data\Azureus
2007-12-17 04:21 ——— d—–w C:\Documents and Settings\All Users\Application Data\Dvdaxismultident
2007-12-09 05:43 ——— d—–w C:\Program Files\Java
2007-11-07 09:26 721,920 —-a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:26 721,920 ——w C:\WINDOWS\system32\dllcache\lsasrv.dll
2007-10-30 23:42 3,590,656 —-a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-30 17:20 360,064 ——w C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-29 22:35 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:35 1,287,680 ——w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-28 00:40 222,720 —-a-w C:\WINDOWS\system32\wmasf.dll
2007-10-28 00:40 222,720 ——w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-07-07 06:46 0 —-a-w C:\Documents and Settings\Andrew.WHARTON\Application Data\wklnhst.dat
2006-08-15 17:52 1,393,664 —-a-w C:\WINDOWS\Internet Logs\xDB1.tmp
2006-08-15 17:52 1,281,536 —-a-w C:\WINDOWS\Internet Logs\xDB2.tmp
2005-09-24 16:49 12,288 —-a-w C:\WINDOWS\Fonts\RandFont.dll
.
—-a-w			67,112 2008-01-04 16:55:25  C:\Program Files\AIM\aim .exe
—-a-w			81,920 2008-01-08 08:22:28  C:\Program Files\Common Files\InstallShield\UpdateService\issch .exe
—-a-w		   249,856 2008-01-05 07:46:42  C:\Program Files\Common Files\InstallShield\UpdateService\isuspm		.exe
—-a-w		   249,856 2008-01-07 07:29:23  C:\Program Files\Common Files\InstallShield\UpdateService\isuspm .exe
—-a-w		   185,632 2008-01-08 08:22:30  C:\Program Files\Common Files\Real\Update_OB\realsched .exe
—-a-w			53,408 2008-01-07 07:27:59  C:\Program Files\Common Files\Symantec Shared\ccApp .exe
—-a-w		   155,648 2008-01-07 07:28:29  C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr .exe
—-a-w		   133,016 2008-01-08 08:22:30  C:\Program Files\DAEMON Tools\daemon .exe
—-a-w		   303,104 2008-01-08 08:22:31  C:\Program Files\Essentials Codec Pack\update .exe
—-a-w		   131,072 2008-01-08 08:22:28  C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl .exe
—-a-w			49,152 2008-01-07 07:27:59  C:\Program Files\Hp\HP Software Update\HPWuSchd2 .exe
—-a-w		   102,400 2008-01-07 07:27:59  C:\Program Files\Hp\QuickPlay\QPService .exe
—-a-w			40,960 2008-01-07 07:28:02  C:\Program Files\HPQ\Default Settings\cpqset .exe
—-a-w		   454,656 2008-01-07 07:27:56  C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant .exe
—-a-w		   271,672 2008-01-07 07:28:12  C:\Program Files\iTunes\iTunesHelper .exe
—-a-w		   132,496 2008-01-07 07:27:54  C:\Program Files\Java\jre1.6.0_02\bin\jusched .exe
—-a-w		   286,720 2008-01-05 07:46:53  C:\Program Files\QuickTime\QTTask			.exe
—-a-w		   761,948 2008-01-07 07:28:04  C:\Program Files\Synaptics\SynTP\SynTPEnh .exe
—-a-w			32,768 2008-01-07 07:28:11  C:\WINDOWS\V0400Mon .exe
—-a-w			64,512 2008-01-07 07:27:53  C:\WINDOWS\ehome\ehtray .exe
—-a-w		 1,187,840 2008-01-07 07:28:11  C:\WINDOWS\SMINST\RecGuard .exe
—-a-w			15,360 2008-01-03 18:04:38  C:\WINDOWS\system32\ctfmon .exe
—-a-w			77,824 2008-01-07 07:27:56  C:\WINDOWS\system32\hkcmd .exe
—-a-w		   118,784 2008-01-07 07:27:56  C:\WINDOWS\system32\igfxpers .exe
—-a-w			94,208 2008-01-07 07:27:55  C:\WINDOWS\system32\igfxtray .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 00:00 15360]
"Creative Live! Cam Manager"="C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsmqIntCert"="regsvr32 /s mqrt.dll" []
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-04-18 04:29 61952 C:\WINDOWS\system32\CHDAudPropShortcut.exe]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm .exe" [2008-01-07 00:29 249856]
"RegistryMechanic"="" []
"QuickTime Task"="C:\Program Files\QuickTime\QTTask .exe" [2008-01-05 00:46 286720]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-09-27 18:17 443968]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2006-08-16 12:27:07]
HP Photosmart Premier Fast Start.lnk - C:\Program Files\Hp\Digital Imaging\bin\hpqthb08.exe [2005-09-24 10:39:30]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 14:38]
S3 VF0400Afx;VF0400 Audio FX;C:\WINDOWS\system32\Drivers\V0400Afx.sys [2007-06-10 10:01]
S3 VF0400Vfx;VF0400 Video FX;C:\WINDOWS\system32\DRIVERS\V0400VFx.sys [2007-03-05 03:45]
S3 VF0400Vid;Live! Cam Notebook Pro (VF0400);C:\WINDOWS\system32\DRIVERS\V0400Vid.sys [2007-06-06 10:01]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{000b1eee-aea1-11dc-b995-0016d42eb995}]
\Shell\AutoRun\command - G:\wd_windows_tools\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fbc7adea-ba41-11dc-b9a1-0013025bb5a0}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a

*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-01-10 16:52:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2006-11-18 17:56:42 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-15 13:51:52
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-15 13:52:19
ComboFix-quarantined-files.txt 2008-01-15 20:52:11
ComboFix2.txt 2008-01-15 20:05:56
.
2008-01-09 08:35:53 — E O F —
HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 1:54:12 PM, on 1/15/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\QuickTime\QTTask .exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm .exe" -startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask .exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Creative Live! Cam Manager] "C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe"
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://72.32.179.44/filter/cameraviewer/isetup.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su2/CTL_V02002/ocx/15030/CTPID.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
Hi, Just catching up here. I had never gotten email notifications on you posting back. Sorry for not getting back to you. Are you still with me here? If so I will post a CFScript to help get cleaned up. Once again, my apologies for dropping this. Dave
Since it has been so long let's get a fresh run at this with combofix. It has been updated to deal with much of what you are seeing in your log automatically.

Please delete your current version and download a fresh one. Here is the canned for running it again too…

Please download ComboFix by sUBs from HERE or HERE
  • You must download it to and run it from your Desktop
  • Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
  • Double click combofix.exe & follow the prompts.
  • When finished, it will produce a log. Please save that log to post in your next reply along with a fresh HJT log
  • Re-enable all the programs that were disabled during the running of ComboFix..

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 11:40:11 AM, on 1/25/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\QuickTime\QTTask .exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm .exe" -startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask .exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Creative Live! Cam Manager] "C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe"
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://72.32.179.44/filter/cameraviewer/isetup.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su2/CTL_V02002/ocx/15030/CTPID.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
Combofix log:

ComboFix 08-01-23.1C - Andrew 2008-01-25 11:36:15.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1583 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat

—– BITS: Possible infected sites —–

hxxp://store.urge.com
.
((((((((((((((((((((((((( Files Created from 2007-12-25 to 2008-01-25 )))))))))))))))))))))))))))))))
.

2008-01-24 11:18 . 2008-01-24 11:18 d——– C:\Program Files\SmartSound Software
2008-01-24 11:18 . 2008-01-24 11:18 d——– C:\Program Files\DivX
2008-01-24 11:18 . 2007-03-01 14:45 129,784 ——— C:\WINDOWS\system32\pxafs.dll
2008-01-24 11:15 . 2008-01-24 11:21 d——– C:\Program Files\CyberLink
2008-01-24 11:11 . 2008-01-24 21:15 d——– C:\MyWorks
2008-01-24 10:26 . 2008-01-24 17:17 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-01-24 10:26 . 2008-01-24 10:26 1,409 –a—— C:\WINDOWS\QTFont.for
2008-01-14 12:55 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-07 20:13 . 2008-01-07 20:13 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-01-05 01:01 . 2008-01-05 01:06 5,062 –a—— C:\WINDOWS\system32\tmp.reg
2008-01-05 01:00 . 2007-09-05 23:22 289,144 –a—— C:\WINDOWS\system32\VCCLSID.exe
2008-01-05 01:00 . 2006-04-27 16:49 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2008-01-05 01:00 . 2007-12-20 23:11 81,920 –a—— C:\WINDOWS\system32\IEDFix.exe
2008-01-05 01:00 . 2004-07-31 17:50 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2008-01-05 01:00 . 2007-10-03 23:36 25,600 –a—— C:\WINDOWS\system32\WS2Fix.exe
2008-01-01 13:57 . 2008-01-01 13:57 d——– C:\Program Files\Polar
2007-12-28 10:17 . 2007-12-28 10:17 35,328 –a—— C:\WINDOWS\system32\LJJKJKL.0LL

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-25 00:17 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-01-24 18:21 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-24 18:12 ——— d—–w C:\Program Files\Apple Software Update
2008-01-24 17:26 ——— d—–w C:\Program Files\iTunes
2008-01-08 22:21 ——— d—–w C:\Program Files\QuickTime
2008-01-08 22:19 ——— d—–w C:\Program Files\music_now
2008-01-08 20:17 ——— d—–w C:\Program Files\Essentials Codec Pack
2008-01-08 20:17 ——— d—–w C:\Program Files\DAEMON Tools
2008-01-08 20:17 ——— d—–w C:\Program Files\AIM
2008-01-07 07:28 32,768 —-a-w C:\WINDOWS\V0400Mon .exe
2008-01-07 07:27 94,208 —-a-w C:\WINDOWS\system32\igfxtray .exe
2008-01-07 07:27 77,824 —-a-w C:\WINDOWS\system32\hkcmd .exe
2008-01-07 07:27 118,784 —-a-w C:\WINDOWS\system32\igfxpers .exe
2008-01-03 18:04 15,360 —-a-w C:\WINDOWS\system32\ctfmon .exe
2007-12-20 05:46 147,456 —-a-w C:\WINDOWS\system32\vbzip10.dll
2007-12-20 05:43 134 —-a-w C:\n.bat
2007-12-09 05:43 ——— d—–w C:\Program Files\Java
2007-11-07 09:26 721,920 —-a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:26 721,920 ——w C:\WINDOWS\system32\dllcache\lsasrv.dll
2007-10-30 23:42 3,590,656 —-a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-30 17:20 360,064 ——w C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-29 22:35 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:35 1,287,680 ——w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-28 00:40 222,720 —-a-w C:\WINDOWS\system32\wmasf.dll
2007-10-28 00:40 222,720 ——w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\system32\dllcache\shell32.dll
2006-08-15 17:52 1,393,664 —-a-w C:\WINDOWS\Internet Logs\xDB1.tmp
2006-08-15 17:52 1,281,536 —-a-w C:\WINDOWS\Internet Logs\xDB2.tmp
2005-09-24 16:49 12,288 —-a-w C:\WINDOWS\Fonts\RandFont.dll
.
—-a-w			67,112 2008-01-04 16:55:25  C:\Program Files\AIM\aim .exe
—-a-w			81,920 2008-01-08 08:22:28  C:\Program Files\Common Files\InstallShield\UpdateService\issch .exe
—-a-w		   249,856 2008-01-05 07:46:42  C:\Program Files\Common Files\InstallShield\UpdateService\isuspm		.exe
—-a-w		   249,856 2008-01-07 07:29:23  C:\Program Files\Common Files\InstallShield\UpdateService\isuspm .exe
—-a-w		   185,632 2008-01-08 08:22:30  C:\Program Files\Common Files\Real\Update_OB\realsched .exe
—-a-w			53,408 2008-01-07 07:27:59  C:\Program Files\Common Files\Symantec Shared\ccApp .exe
—-a-w		   155,648 2008-01-07 07:28:29  C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr .exe
—-a-w		   133,016 2008-01-08 08:22:30  C:\Program Files\DAEMON Tools\daemon .exe
—-a-w		   303,104 2008-01-08 08:22:31  C:\Program Files\Essentials Codec Pack\update .exe
—-a-w		   131,072 2008-01-08 08:22:28  C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl .exe
—-a-w			49,152 2008-01-07 07:27:59  C:\Program Files\Hp\HP Software Update\HPWuSchd2 .exe
—-a-w		   102,400 2008-01-07 07:27:59  C:\Program Files\Hp\QuickPlay\QPService .exe
—-a-w			40,960 2008-01-07 07:28:02  C:\Program Files\HPQ\Default Settings\cpqset .exe
—-a-w		   454,656 2008-01-07 07:27:56  C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant .exe
—-a-w		   271,672 2008-01-07 07:28:12  C:\Program Files\iTunes\iTunesHelper .exe
—-a-w		   132,496 2008-01-07 07:27:54  C:\Program Files\Java\jre1.6.0_02\bin\jusched .exe
—-a-w		   286,720 2008-01-05 07:46:53  C:\Program Files\QuickTime\QTTask			.exe
—-a-w		   761,948 2008-01-07 07:28:04  C:\Program Files\Synaptics\SynTP\SynTPEnh .exe
—-a-w			32,768 2008-01-07 07:28:11  C:\WINDOWS\V0400Mon .exe
—-a-w			64,512 2008-01-07 07:27:53  C:\WINDOWS\ehome\ehtray .exe
—-a-w		 1,187,840 2008-01-07 07:28:11  C:\WINDOWS\SMINST\RecGuard .exe
—-a-w			15,360 2008-01-03 18:04:38  C:\WINDOWS\system32\ctfmon .exe
—-a-w			77,824 2008-01-07 07:27:56  C:\WINDOWS\system32\hkcmd .exe
—-a-w		   118,784 2008-01-07 07:27:56  C:\WINDOWS\system32\igfxpers .exe
—-a-w			94,208 2008-01-07 07:27:55  C:\WINDOWS\system32\igfxtray .exe


((((((((((((((((((((((((((((( snapshot@2008-01-15_13.52.01.82 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-15 20:50:46 229,376 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-25 18:36:02 229,376 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-15 20:50:46 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-25 18:36:02 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
- 2008-01-15 20:50:46 233,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-25 18:36:02 233,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
- 2008-01-15 20:50:46 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-25 18:36:02 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-15 20:50:46 6,225,920 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
+ 2008-01-25 18:36:03 6,225,920 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
- 2008-01-15 20:50:46 266,240 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-25 18:36:03 266,240 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2005-09-23 20:48:52 356,352 —-a-w C:\WINDOWS\eSellerateEngine.dll
- 2007-08-22 06:17:11 102,400 —-a-r C:\WINDOWS\Installer\{974C05A0-C76C-4724-A9A2-11D5D1355729}\iTunesIco.exe
+ 2008-01-24 17:26:52 102,400 —-a-r C:\WINDOWS\Installer\{974C05A0-C76C-4724-A9A2-11D5D1355729}\iTunesIco.exe
+ 2008-01-24 17:27:35 27,136 —-a-r C:\WINDOWS\Installer\{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}\AppleSoftwareUpdateIco.exe
+ 2008-01-24 18:17:45 84,876 —-a-r C:\WINDOWS\Installer\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\ARPPRODUCTICON.exe
+ 2007-03-01 21:31:23 637,534 —-a-w C:\WINDOWS\system32\DivX.dll
+ 2007-03-01 21:31:24 806,912 —-a-w C:\WINDOWS\system32\divx_xx07.dll
+ 2007-03-01 21:31:24 806,912 —-a-w C:\WINDOWS\system32\divx_xx0c.dll
+ 2007-03-01 21:31:24 790,528 —-a-w C:\WINDOWS\system32\divx_xx11.dll
+ 2007-03-01 21:56:17 118,784 —-a-w C:\WINDOWS\system32\DivXCodecUpdateChecker.exe
+ 2007-03-01 21:45:54 520,192 —-a-w C:\WINDOWS\system32\DivXsm.exe
+ 2007-03-01 21:55:48 12,288 —-a-w C:\WINDOWS\system32\DivXWMPExtType.dll
+ 2007-03-01 21:35:00 73,728 —-a-w C:\WINDOWS\system32\dpl100.dll
+ 2007-03-01 21:31:27 294,912 —-a-w C:\WINDOWS\system32\dpu10.dll
+ 2007-03-01 21:31:27 294,912 —-a-w C:\WINDOWS\system32\dpu11.dll
+ 2007-03-01 21:31:30 53,248 —-a-w C:\WINDOWS\system32\dpuGUI10.dll
+ 2007-03-01 21:31:28 593,920 —-a-w C:\WINDOWS\system32\dpuGUI11.dll
+ 2007-03-01 21:31:28 344,064 —-a-w C:\WINDOWS\system32\dpus11.dll
+ 2007-03-01 21:31:28 57,344 —-a-w C:\WINDOWS\system32\dpv11.dll
- 2006-09-27 21:53:22 36,560 —-a-w C:\WINDOWS\system32\drivers\pxhelp20.sys
+ 2007-03-01 21:45:43 36,624 ——w C:\WINDOWS\system32\drivers\pxhelp20.sys
+ 2008-01-15 09:39:58 30,464 -c–a-w C:\WINDOWS\system32\DRVSTORE\usbaapl_4351B7DAFF62FD33510D77DFAE3CF8CC82517571\usbaapl.sys
+ 2007-03-01 21:35:00 196,608 —-a-w C:\WINDOWS\system32\dtu100.dll
- 2007-06-28 14:15:06 351,384 —-a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-01-24 18:24:18 361,728 —-a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2007-03-01 21:45:32 1,044,480 —-a-w C:\WINDOWS\system32\libdivx.dll
- 2006-09-27 21:53:22 514,808 —-a-w C:\WINDOWS\system32\Px.dll
+ 2007-03-01 21:45:42 527,096 ——w C:\WINDOWS\system32\Px.dll
- 2004-09-27 07:00:00 56,832 —-a-w C:\WINDOWS\system32\pxcpya64.exe
+ 2007-03-01 21:45:42 64,760 ——w C:\WINDOWS\system32\pxcpya64.exe
- 2004-09-27 07:00:00 108,544 —-a-w C:\WINDOWS\system32\pxcpyi64.exe
+ 2007-03-01 21:45:42 116,472 ——w C:\WINDOWS\system32\pxcpyi64.exe
- 2006-09-27 21:53:22 477,944 —-a-w C:\WINDOWS\system32\pxdrv.dll
+ 2007-03-01 21:45:43 502,520 ——w C:\WINDOWS\system32\pxdrv.dll
- 2006-09-27 21:53:22 68,344 —-a-w C:\WINDOWS\system32\pxhpinst.exe
+ 2007-03-01 21:45:43 72,440 ——w C:\WINDOWS\system32\pxhpinst.exe
- 2005-01-12 09:03:00 56,320 —-a-w C:\WINDOWS\system32\pxinsa64.exe
+ 2007-03-01 21:45:42 64,760 ——w C:\WINDOWS\system32\pxinsa64.exe
- 2005-01-12 09:03:00 109,568 —-a-w C:\WINDOWS\system32\pxinsi64.exe
+ 2007-03-01 21:45:42 118,520 ——w C:\WINDOWS\system32\pxinsi64.exe
- 2006-09-27 21:53:22 183,032 —-a-w C:\WINDOWS\system32\PxMas.dll
+ 2007-03-01 21:45:44 183,032 ——w C:\WINDOWS\system32\PxMas.dll
- 2005-10-25 06:13:34 1,200,128 —-a-w C:\WINDOWS\system32\PxSFS.DLL
+ 2007-03-01 21:45:43 1,329,912 ——w C:\WINDOWS\system32\PxSFS.DLL
- 2006-09-27 21:53:23 379,640 —-a-w C:\WINDOWS\system32\PxWave.dll
+ 2007-03-01 21:45:43 379,640 ——w C:\WINDOWS\system32\PxWave.dll
+ 2007-03-01 21:45:49 3,596,288 —-a-w C:\WINDOWS\system32\qt-dx331.dll
+ 2007-03-01 21:45:32 200,704 —-a-w C:\WINDOWS\system32\ssldivx.dll
- 2006-09-27 21:53:23 39,672 —-a-w C:\WINDOWS\system32\VXBLOCK.dll
+ 2007-03-01 21:45:42 39,672 ——w C:\WINDOWS\system32\VXBLOCK.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 00:00 15360]
"Creative Live! Cam Manager"="C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsmqIntCert"="regsvr32 /s mqrt.dll" []
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-04-18 04:29 61952 C:\WINDOWS\system32\CHDAudPropShortcut.exe]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm .exe" [2008-01-07 00:29 249856]
"RegistryMechanic"="" []
"QuickTime Task"="C:\Program Files\QuickTime\QTTask .exe" [2008-01-05 00:46 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-08-15 20:15 271672]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-09-27 18:17 443968]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2006-08-16 12:27:07 25214]
HP Photosmart Premier Fast Start.lnk - C:\Program Files\Hp\Digital Imaging\bin\hpqthb08.exe [2005-09-24 10:39:30 73728]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 14:38]
S3 VF0400Afx;VF0400 Audio FX;C:\WINDOWS\system32\Drivers\V0400Afx.sys [2007-06-10 10:01]
S3 VF0400Vfx;VF0400 Video FX;C:\WINDOWS\system32\DRIVERS\V0400VFx.sys [2007-03-05 03:45]
S3 VF0400Vid;Live! Cam Notebook Pro (VF0400);C:\WINDOWS\system32\DRIVERS\V0400Vid.sys [2007-06-06 10:01]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\Shell\AutoRun\command - H:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{000b1eee-aea1-11dc-b995-0016d42eb995}]
\Shell\AutoRun\command - G:\wd_windows_tools\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{16e9d9b6-cadc-11dc-b9ba-0013025bb5a0}]
\Shell\AutoRun\command - H:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fbc7adea-ba41-11dc-b9a1-0013025bb5a0}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a

*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-01-24 17:27:34 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2006-11-18 17:56:42 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-25 11:38:39
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-25 11:39:09
ComboFix-quarantined-files.txt 2008-01-25 18:39:02
ComboFix2.txt 2008-01-15 20:52:20
ComboFix3.txt 2008-01-15 20:05:56
.
2008-01-09 08:35:53 — E O F —
Oh well I was hoping combofix would automatically deal with the program files…we'll run a script.

1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

RenV::
C:\Program Files\AIM\aim .exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch .exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm		.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm .exe
C:\Program Files\Common Files\Real\Update_OB\realsched .exe
C:\Program Files\Common Files\Symantec Shared\ccApp .exe
C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr .exe
C:\Program Files\DAEMON Tools\daemon .exe
C:\Program Files\Essentials Codec Pack\update .exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl .exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2 .exe
C:\Program Files\Hp\QuickPlay\QPService .exe
C:\Program Files\HPQ\Default Settings\cpqset .exe
C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant .exe
C:\Program Files\iTunes\iTunesHelper .exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched .exe
C:\Program Files\QuickTime\QTTask			.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh .exe
C:\WINDOWS\V0400Mon .exe
C:\WINDOWS\ehome\ehtray .exe
C:\WINDOWS\SMINST\RecGuard .exe
C:\WINDOWS\system32\ctfmon .exe
C:\WINDOWS\system32\hkcmd .exe
C:\WINDOWS\system32\igfxpers .exe
C:\WINDOWS\system32\igfxtray .exe


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

Do me a favor also and run some of the programs listed in that renv section to make sure they work.
Combofix:

ComboFix 08-01-23.1C - Andrew 2008-01-25 14:09:42.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1510 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Andrew.WHARTON\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2007-12-25 to 2008-01-25 )))))))))))))))))))))))))))))))
.

2008-01-24 11:18 . 2008-01-24 11:18 d——– C:\Program Files\SmartSound Software
2008-01-24 11:18 . 2008-01-24 11:18 d——– C:\Program Files\DivX
2008-01-24 11:18 . 2007-03-01 14:45 129,784 ——— C:\WINDOWS\system32\pxafs.dll
2008-01-24 11:15 . 2008-01-24 11:21 d——– C:\Program Files\CyberLink
2008-01-24 11:11 . 2008-01-24 21:15 d——– C:\MyWorks
2008-01-24 10:26 . 2008-01-24 17:17 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-01-24 10:26 . 2008-01-24 10:26 1,409 –a—— C:\WINDOWS\QTFont.for
2008-01-14 12:55 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-07 20:13 . 2008-01-07 20:13 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-01-05 01:01 . 2008-01-05 01:06 5,062 –a—— C:\WINDOWS\system32\tmp.reg
2008-01-05 01:00 . 2007-09-05 23:22 289,144 –a—— C:\WINDOWS\system32\VCCLSID.exe
2008-01-05 01:00 . 2006-04-27 16:49 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2008-01-05 01:00 . 2007-12-20 23:11 81,920 –a—— C:\WINDOWS\system32\IEDFix.exe
2008-01-05 01:00 . 2004-07-31 17:50 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2008-01-05 01:00 . 2007-10-03 23:36 25,600 –a—— C:\WINDOWS\system32\WS2Fix.exe
2008-01-01 13:57 . 2008-01-01 13:57 d——– C:\Program Files\Polar
2007-12-28 10:17 . 2007-12-28 10:17 35,328 –a—— C:\WINDOWS\system32\LJJKJKL.0LL

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-25 21:09 ——— d—–w C:\Program Files\QuickTime
2008-01-25 21:09 ——— d—–w C:\Program Files\iTunes
2008-01-25 21:09 ——— d—–w C:\Program Files\Essentials Codec Pack
2008-01-25 21:09 ——— d—–w C:\Program Files\DAEMON Tools
2008-01-25 21:09 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-01-25 21:09 ——— d—–w C:\Program Files\AIM
2008-01-24 18:21 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-24 18:12 ——— d—–w C:\Program Files\Apple Software Update
2008-01-08 22:19 ——— d—–w C:\Program Files\music_now
2008-01-07 07:28 32,768 —-a-w C:\WINDOWS\V0400Mon.exe
2008-01-07 07:27 94,208 —-a-w C:\WINDOWS\system32\igfxtray.exe
2008-01-07 07:27 77,824 —-a-w C:\WINDOWS\system32\hkcmd.exe
2008-01-07 07:27 64,512 —-a-w C:\WINDOWS\system32\dllcache\ehtray.exe
2008-01-07 07:27 118,784 —-a-w C:\WINDOWS\system32\igfxpers.exe
2008-01-03 18:04 15,360 —-a-w C:\WINDOWS\system32\dllcache\ctfmon.exe
2008-01-03 18:04 15,360 —-a-w C:\WINDOWS\system32\ctfmon.exe
2007-12-20 05:46 147,456 —-a-w C:\WINDOWS\system32\vbzip10.dll
2007-12-20 05:43 134 —-a-w C:\n.bat
2007-12-09 05:43 ——— d—–w C:\Program Files\Java
2007-11-07 09:26 721,920 —-a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:26 721,920 ——w C:\WINDOWS\system32\dllcache\lsasrv.dll
2007-10-30 23:42 3,590,656 —-a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-30 17:20 360,064 ——w C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-29 22:35 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:35 1,287,680 ——w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-28 00:40 222,720 —-a-w C:\WINDOWS\system32\wmasf.dll
2007-10-28 00:40 222,720 ——w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\system32\dllcache\shell32.dll
2006-08-15 17:52 1,393,664 —-a-w C:\WINDOWS\Internet Logs\xDB1.tmp
2006-08-15 17:52 1,281,536 —-a-w C:\WINDOWS\Internet Logs\xDB2.tmp
2005-09-24 16:49 12,288 —-a-w C:\WINDOWS\Fonts\RandFont.dll
.

((((((((((((((((((((((((((((( snapshot_2008-01-25_11.38.51.33 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-07 07:27:53 64,512 —-a-w C:\WINDOWS\ehome\ehtray.exe
- 2008-01-25 18:36:02 229,376 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-25 21:09:29 229,376 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-25 18:36:02 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-25 21:09:29 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
- 2008-01-25 18:36:02 233,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-25 21:09:29 233,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
- 2008-01-25 18:36:02 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-25 21:09:29 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-25 18:36:03 6,225,920 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
+ 2008-01-25 21:09:29 6,225,920 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
- 2008-01-25 18:36:03 266,240 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-25 21:09:29 266,240 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-07 07:28:11 1,187,840 —-a-w C:\WINDOWS\SMINST\RecGuard.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-01-03 11:04 15360]
"Creative Live! Cam Manager"="C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe" [2008-01-07 00:28 155648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsmqIntCert"="regsvr32 /s mqrt.dll" []
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-04-18 04:29 61952 C:\WINDOWS\system32\CHDAudPropShortcut.exe]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm .exe" [ ]
"RegistryMechanic"="" []
"QuickTime Task"="C:\Program Files\QuickTime\QTTask .exe" [ ]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-07 00:28 271672]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-09-27 18:17 443968]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2006-08-16 12:27:07 25214]
HP Photosmart Premier Fast Start.lnk - C:\Program Files\Hp\Digital Imaging\bin\hpqthb08.exe [2005-09-24 10:39:30 73728]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 14:38]
S3 VF0400Afx;VF0400 Audio FX;C:\WINDOWS\system32\Drivers\V0400Afx.sys [2007-06-10 10:01]
S3 VF0400Vfx;VF0400 Video FX;C:\WINDOWS\system32\DRIVERS\V0400VFx.sys [2007-03-05 03:45]
S3 VF0400Vid;Live! Cam Notebook Pro (VF0400);C:\WINDOWS\system32\DRIVERS\V0400Vid.sys [2007-06-06 10:01]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\Shell\AutoRun\command - H:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{000b1eee-aea1-11dc-b995-0016d42eb995}]
\Shell\AutoRun\command - G:\wd_windows_tools\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{16e9d9b6-cadc-11dc-b9ba-0013025bb5a0}]
\Shell\AutoRun\command - H:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fbc7adea-ba41-11dc-b9a1-0013025bb5a0}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a

*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-01-24 17:27:34 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2006-11-18 17:56:42 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-25 14:10:27
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-25 14:10:56
ComboFix-quarantined-files.txt 2008-01-25 21:10:49
ComboFix2.txt 2008-01-25 18:39:10
ComboFix3.txt 2008-01-15 20:52:20
ComboFix4.txt 2008-01-15 20:05:56
.
2008-01-09 08:35:53 — E O F —

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI