Alright here are the new logs
________________________
ComboFix 08-01-23.1C - Owner 2008-01-27 15:51:43.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.161 [GMT -6:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point
FILE
C:\temp1509984.bat
C:\temp1747328.bat
C:\temp268312.bat
C:\temp292625.bat
C:\temp579203.bat
C:\temp778671.bat
C:\WINDOWS\2b31038d97b5ca91fa13ffd9f93133fb.ini
C:\WINDOWS\system32\1171.bat
C:\WINDOWS\system32\4434.bat
C:\WINDOWS\system32\aucgvgtp.dll
C:\WINDOWS\system32\bqstiknx.dll
C:\WINDOWS\system32\cdfslhbw.ini
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\mcdd.sys
C:\WINDOWS\system32\ide21201.vxd
C:\WINDOWS\system32\plytqxmp.dll
C:\WINDOWS\system32\uirjwnsv.dll
C:\WINDOWS\system32\vbzip10.dll
C:\WINDOWS\viassary-hp.reg
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\temp\cXzz9
C:\temp\gTiis19
C:\temp\gTiis19\lTig.log
C:\temp\tn3
C:\temp1509984.bat
C:\temp1747328.bat
C:\temp268312.bat
C:\temp292625.bat
C:\temp579203.bat
C:\temp778671.bat
C:\WINDOWS\2b31038d97b5ca91fa13ffd9f93133fb.ini
C:\WINDOWS\system32\1171.bat
C:\WINDOWS\system32\4434.bat
C:\WINDOWS\system32\aucgvgtp.dll
C:\WINDOWS\system32\bqstiknx.dll
C:\WINDOWS\system32\cdfslhbw.ini
C:\WINDOWS\system32\comz7
C:\WINDOWS\system32\dob3
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\mcdd.sys
C:\WINDOWS\system32\extz1
C:\WINDOWS\system32\extz1\lovstadcom2.exe
C:\WINDOWS\system32\ide21201.vxd
C:\WINDOWS\system32\nGpxx07
C:\WINDOWS\system32\nGpxx07\nGpxx071084.exe
C:\WINDOWS\system32\nui4
C:\WINDOWS\system32\plytqxmp.dll
C:\WINDOWS\system32\uirjwnsv.dll
C:\WINDOWS\system32\vbzip10.dll
C:\WINDOWS\system32\winzs6
C:\WINDOWS\viassary-hp.reg
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_MCDD
-------\mcdd
((((((((((((((((((((((((( Files Created from 2007-12-27 to 2008-01-27 )))))))))))))))))))))))))))))))
.
2008-01-27 13:28 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\Nircmd.exe
2008-01-24 14:59 . 2008-01-24 14:59 <DIR> d-------- C:\Program Files\Windows Defender
2008-01-24 14:57 . 2008-01-24 14:57 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2008-01-24 14:53 . 2008-01-24 14:53 <DIR> d-------- C:\Program Files\PopupPopper
2008-01-24 14:53 . 2002-02-15 15:02 1,326,080 --a------ C:\WINDOWS\system32\vcl60.bpl
2008-01-24 14:53 . 2002-02-15 15:02 676,352 --a------ C:\WINDOWS\system32\rtl60.bpl
2008-01-24 14:53 . 2001-05-21 23:00 213,504 --a------ C:\WINDOWS\system32\vclx60.bpl
2008-01-24 13:01 . 2001-08-17 22:36 8,704 --a------ C:\WINDOWS\system32\kbdjpn.dll
2008-01-24 09:07 . 2008-01-27 16:02 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-24 09:07 . 2008-01-24 09:07 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-22 09:48 . 2007-09-11 11:55 52,496 --a------ C:\WINDOWS\system32\drivers\tmactmon.sys
2008-01-22 09:48 . 2007-09-11 11:55 52,368 --a------ C:\WINDOWS\system32\drivers\tmevtmgr.sys
2008-01-22 09:42 . 2008-01-27 11:36 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-21 13:18 . 2007-09-11 11:55 138,512 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-01-21 10:41 . 2008-01-21 21:53 <DIR> d-------- C:\Program Files\Microsoft Windows OneCare Live
2008-01-20 14:26 . 2008-01-20 14:26 27,004 --a------ C:\WINDOWS\system32\min.exe
2008-01-20 11:46 . 2008-01-20 14:04 <DIR> d-------- C:\Program Files\Sims2
2008-01-20 09:25 . 2008-01-20 09:26 <DIR> d-------- C:\Program Files\Roller Coaster Tycoon 2
2008-01-17 18:05 . 2008-01-20 11:54 <DIR> dr------- C:\Program Files\Tycoon Games
2008-01-17 09:00 . 2008-01-19 15:08 <DIR> d-------- C:\Program Files\Zoo Tycoon
2008-01-10 15:27 . 2008-01-10 15:27 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-01-10 15:27 . 2008-01-10 15:27 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-27 22:02 3,651 ----a-w C:\WINDOWS\viassary-hp.reg
2008-01-27 19:43 --------- d-----w C:\Program Files\Ares
2008-01-23 16:18 --------- d-----w C:\Program Files\iTunes
2008-01-23 16:18 --------- d-----w C:\Program Files\iPod
2008-01-23 16:13 --------- d-----w C:\Program Files\QuickTime
2008-01-22 15:27 --------- d-----w C:\Program Files\Lavasoft
2008-01-22 01:36 --------- d-----w C:\Program Files\Java
2008-01-20 21:09 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-20 21:06 --------- d-----w C:\Program Files\interMute
2008-01-20 20:58 --------- d-----w C:\Program Files\LimeWire
2008-01-20 20:22 737,280 ----a-w C:\WINDOWS\iun6002.exe
2007-12-17 00:29 65,936 ----a-w C:\WINDOWS\system32\drivers\tmtdi.sys
2007-12-17 00:29 35,856 ----a-w C:\WINDOWS\system32\drivers\tmpreflt.sys
2007-12-17 00:29 202,768 ----a-w C:\WINDOWS\system32\drivers\tmxpflt.sys
2007-12-17 00:29 1,126,072 ----a-w C:\WINDOWS\system32\drivers\vsapint.sys
.
((((((((((((((((((((((((((((( snapshot@2008-01-27_13.53.11.73 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-27 19:30:08 241,664 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
+ 2008-01-27 21:51:36 241,664 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
- 2008-01-27 19:30:08 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
+ 2008-01-27 21:51:36 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
- 2008-01-27 19:30:08 237,568 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\NTUSER.DAT
+ 2008-01-27 21:51:36 237,568 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\NTUSER.DAT
- 2008-01-27 19:30:09 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
+ 2008-01-27 21:51:37 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
- 2008-01-27 19:30:09 3,043,328 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000005\NTUSER.DAT
+ 2008-01-27 21:51:37 3,043,328 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000005\NTUSER.DAT
- 2008-01-27 19:30:09 147,456 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000006\UsrClass.dat
+ 2008-01-27 21:51:37 147,456 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000006\UsrClass.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45 313472]
"RecordNow!"="" []
"MSMSGS"="C:\Program Files\Messenger\MSMSGS.exe" [2004-10-13 10:24 1694208]
"BackupNotify"="c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe" [2004-01-09 03:34 32768]
"ares"="C:\Program Files\Ares\Ares.exe" [2005-02-22 20:52 1202176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UfSeAgnt.exe"="C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe" [2007-12-16 18:29 1393928]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20 866584]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-10 15:27 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 03:22 267048]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe [2006-11-29 20:36:41 49254]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 14:19:24 237568]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
Quicken Scheduled Updates.lnk - C:\Program Files\Quicken\bagent.exe [2003-07-30 06:49:48 57344]
Updates from HP.lnk - C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe [2004-01-20 21:59:55 16384]
.
Contents of the 'Scheduled Tasks' folder
"2008-01-23 15:50:06 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-27 22:04:09 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2008-01-27 22:15:00 C:\WINDOWS\Tasks\User_Feed_Synchronization-{90E8AAE0-A15F-4E38-8DD9-A3549D810920}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-27 16:03:47
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-27 16:16:26 - machine was rebooted [Owner]
ComboFix-quarantined-files.txt 2008-01-27 22:16:23
ComboFix2.txt 2008-01-27 19:53:29
.
2008-01-25 09:02:14 --- E O F ---
_____________________________________
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:18:00 PM, on 1/27/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Trend Micro\Internet Security\UfUpdUi.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - S-1-5-18 Startup: AutoTBar.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: AutoTBar.exe (User 'Default user')
O4 - .DEFAULT User Startup: AutoTBar.exe (User 'Default user')
O4 - Startup: FlashSwitch.lnk = C:\Program Files\FlashSwitch\FlashSw.exe
O4 - Startup: Organize.lnk = ?
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) -
http://photos.walmar...martActivia.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://gfx1.hotmail....es/MSNPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.mi...b?1189902715406
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.mi...b?1189902703218
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) -
https://h17000.www1....loadManager.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.m...ash/swflash.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
--
End of file - 5853 bytes
______________________________________________
thanks so much