This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed]Pop Ups and Other Fun Thing

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello Good People of What The Tech -

Having a few fun issues with the computer lately.

1 Getting some pop ups
2 Keyboard suffers from delyed reaction. Typing misses letters if I type too fast. (I've noticed that if doing a google search topic, sometimes what I type into the google search line is mimicked in the popup ad.

I've installed and ran the followin programs per the self-help page;

ATF-Cleaner.exe
Spybot
AVG Anti-Spyware

Here is my Hi Jack This scan:

Logfile of HijackThis v1.99.1
Scan saved at 10:45:57 PM, on 1/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
I:\Nero\Nero 7\Nero StartSmart\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
g:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\RUNDLL32.EXE
I:\Nero\Nero 7\Nero StartSmart\InCD\InCD.exe
I:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
G:\program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Adobe\Acrobat 6.0\Reader\AcroRd32.exe
C:\WINDOWS\system32\WISPTIS.EXE
I:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
I:\Program Files\iTunes\iTunes.exe
i:\progra~1\azureus\Azureus.exe
C:\WINDOWS\explorer.exe
I:\Program Files\Hijack This\HijackThis.exe

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [TomcatStartup 2.5] C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe
O4 - HKLM\..\Run: [StatusClient 2.6] C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [iTunesHelper] "I:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "G:\program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - I:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://aimexpress.aol.com
O15 - Trusted Zone: www.ebay.com
O15 - Trusted Zone: http://*.oink.me.uk
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://corriherptz.axiscam.net:9552/activex/AMC.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{FB81C809-2055-49EB-A81E-7C622743A397}: NameServer = 24.247.24.53,24.247.15.53
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - g:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\nrasmrbp.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - I:\Nero\Nero 7\Nero StartSmart\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

Your help is much apprecited!!!

Ji
Welcome to What the Tech

Please rename the file listed in bold to HJT.exe
I:\Program Files\Hijack This\HijackThis.exe <– This file

I'm asking you to do this because certain infections use the default file name for HijackThis to hide 02 and 020 entries and I see you have none in your log, by changing the file name they should show up.

Please post a new HJT(HijackThis) log

Logs to include in your reply
HJT
Changed file name and here's the new log.

Thanks!
jim

Logfile of HijackThis v1.99.1
Scan saved at 8:15:16 PM, on 1/30/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
I:\Nero\Nero 7\Nero StartSmart\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
g:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\RUNDLL32.EXE
I:\Nero\Nero 7\Nero StartSmart\InCD\InCD.exe
I:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
G:\program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Adobe\Acrobat 6.0\Reader\AcroRd32.exe
C:\WINDOWS\system32\WISPTIS.EXE
I:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
C:\WINDOWS\explorer.exe
I:\Program Files\iTunes\iTunes.exe
C:\Program Files\Internet Explorer\iexplore.exe
I:\Program Files\Hijack This\HJT.exe

O2 - BHO: (no name) - {067BC363-369B-4502-A216-8168C6467512} - C:\WINDOWS\system32\efcyw.dll
O2 - BHO: {67e10a37-7312-8338-4594-df59943151f4} - {4f151349-95fd-4954-8338-213773a01e76} - C:\WINDOWS\system32\outhdgyg.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - g:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: (no name) - {CA4F0D8D-5F2B-4F16-838A-8D52249EAB21} - C:\WINDOWS\system32\khfgded.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [TomcatStartup 2.5] C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe
O4 - HKLM\..\Run: [StatusClient 2.6] C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [iTunesHelper] "I:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "G:\program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [3cd19cc1] rundll32.exe "C:\WINDOWS\system32\ctxjhbwv.dll",b
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - I:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://aimexpress.aol.com
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://corriherptz.axiscam.net:9552/activex/AMC.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{FB81C809-2055-49EB-A81E-7C622743A397}: NameServer = 24.247.24.53,24.247.15.53
O20 - Winlogon Notify: khfgded - khfgded.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - g:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\nrasmrbp.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - I:\Nero\Nero 7\Nero StartSmart\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
Please download ComboFix by sUBs from HERE or HERE

You must download it to your Desktop

Go to [external image: Posted Image] -> Run -> paste in the following single line command & click OK


"%userprofile%\desktop\combofix.exe" /killall



[external image: Posted Image]

ComboFix will automatically start, any monitoring programs will be shut down like your antivirus, antispyware programs for example.

ComboFix may restart your computer, this is normal.

When finished, it will produce a log. Please save its log to post in your next reply .

Note:
Do not mouse-click Combofix's window while it is running. That may cause it to stall.

CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

If ComboFix did not reboot your computer please reboot it now.

Post a new HijackThis log.

Logs to include in your reply
ComboFix
HJT
Holy Cow. That was intersting. It kept hangin up on the reboot and geting stuck. Whew…glad it made it through.

OK, up first the Combofix Log>>>

ComboFix 08-01-31.3 - Jim 2008-01-31 19:59:06.2 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1631 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\efcyw.dll
.
—- Previous Run ——-
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Program Files\QdrDrive
C:\WINDOWS\bundles
C:\WINDOWS\bundles\58kd52fg.exe
C:\WINDOWS\bundles\activeshopper.exe
C:\WINDOWS\bundles\adl_dh.exe
C:\WINDOWS\bundles\adl_hl.exe
C:\WINDOWS\bundles\adl_ibis_AS2.exe
C:\WINDOWS\bundles\adl_zeno.exe
C:\WINDOWS\bundles\AdSmartMedia_bundle.exe
C:\WINDOWS\bundles\adv0ltc0m.exe
C:\WINDOWS\bundles\ast_5_adsav.exe
C:\WINDOWS\bundles\b2s-162813.exe
C:\WINDOWS\bundles\Beryllium.exe
C:\WINDOWS\bundles\bs5-goodyr1.exe
C:\WINDOWS\bundles\cxt_big.exe
C:\WINDOWS\bundles\cxt_wmg.exe
C:\WINDOWS\bundles\d_ic.exe
C:\WINDOWS\bundles\Decade.exe
C:\WINDOWS\bundles\e2g51.exe
C:\WINDOWS\bundles\EDow_vl.exe
C:\WINDOWS\bundles\gogotoolsSILAWO8pi.exe
C:\WINDOWS\bundles\HLInstaller.exe
C:\WINDOWS\bundles\icmedia2_56.exe
C:\WINDOWS\bundles\ICMMedia_1cmm3d1a.exe
C:\WINDOWS\bundles\iehost.exe
C:\WINDOWS\bundles\installcasino.exe
C:\WINDOWS\bundles\KnNe1.exe
C:\WINDOWS\bundles\mfsetup.exe
C:\WINDOWS\bundles\new_vcm.exe
C:\WINDOWS\bundles\newmb.exe
C:\WINDOWS\bundles\NzI0MDo4OjEy.exe
C:\WINDOWS\bundles\package8033_MARKETING5.exe
C:\WINDOWS\bundles\pounder.exe
C:\WINDOWS\bundles\rop_marketing_1_168.exe
C:\WINDOWS\bundles\ropbundle.exe
C:\WINDOWS\bundles\sahagent-dectest1001.exe
C:\WINDOWS\bundles\sahagent-onlinetrafficbroker1001.exe
C:\WINDOWS\bundles\sahagent-seedcorn1002.exe
C:\WINDOWS\bundles\search_toolbar.exe
C:\WINDOWS\bundles\setup_Incredifind_TrafficSpec.exe
C:\WINDOWS\bundles\Setup1171.exe
C:\WINDOWS\bundles\setupactiv2.exe
C:\WINDOWS\bundles\SetupCasino.exe
C:\WINDOWS\bundles\ssee.exe
C:\WINDOWS\bundles\stlb2_seed.exe
C:\WINDOWS\bundles\ventura1.exe
C:\WINDOWS\bundles\vrinstall_icmedia.exe
C:\WINDOWS\bundles\winversion.exe
C:\WINDOWS\system32\000070.exe
C:\WINDOWS\system32\000080.exe
C:\WINDOWS\system32\abnmujrn.ini
C:\WINDOWS\system32\avovaffk.dll
C:\WINDOWS\system32\axitayyt.dll
C:\WINDOWS\system32\belrncwr.exe
C:\WINDOWS\system32\bhsnvwhe.dll
C:\WINDOWS\system32\buorvsjs.dll
C:\WINDOWS\system32\Cache
C:\WINDOWS\system32\Cache\mstub-pal_nmw_a353_r15950.exe
C:\WINDOWS\system32\Cache\mswinstall.exe
C:\WINDOWS\system32\cntkoueu.dll
C:\WINDOWS\system32\crjrqths.ini
C:\WINDOWS\system32\ctxjhbwv.dll
C:\WINDOWS\system32\dfjcnwxo.ini
C:\WINDOWS\system32\dqdrlhiv.exe
C:\WINDOWS\system32\drlggrsl.exe
C:\WINDOWS\system32\ebnotbby.exe
C:\WINDOWS\system32\efcyw.exe
C:\WINDOWS\system32\ehwvnshb.ini
C:\WINDOWS\system32\elbgrpej.dll
C:\WINDOWS\system32\escpqdfx.exe
C:\WINDOWS\system32\euaeshpq.dll
C:\WINDOWS\system32\fgmcavpo.dll
C:\WINDOWS\system32\fheesfmm.dll
C:\WINDOWS\system32\gcasafgx.dll
C:\WINDOWS\system32\goyeekpr.ini
C:\WINDOWS\system32\hkdhaxkv.dll
C:\WINDOWS\system32\hkiiwhux.ini
C:\WINDOWS\system32\hrqvovll.dll
C:\WINDOWS\system32\hytlimdk.dll
C:\WINDOWS\system32\ikrqrvnp.exe
C:\WINDOWS\system32\ipsnkyeg.dll
C:\WINDOWS\system32\jaagpetm.dll
C:\WINDOWS\system32\jdmtcwxs.ini
C:\WINDOWS\system32\jeprgble.ini
C:\WINDOWS\system32\jkhvraam.ini
C:\WINDOWS\system32\jpcwmoli.dll
C:\WINDOWS\system32\kdmiltyh.ini
C:\WINDOWS\system32\kkkaywxu.dll
C:\WINDOWS\system32\lhmxjbye.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mscjiqps.dll
C:\WINDOWS\system32\msvcsv60.dll
C:\WINDOWS\system32\mtepgaaj.ini
C:\WINDOWS\system32\nejjknrp.dll
C:\WINDOWS\system32\nrjumnba.dll
C:\WINDOWS\system32\oiucjlux.dll
C:\WINDOWS\system32\okvnuvdk.dll
C:\WINDOWS\system32\orfmsvqb.dll
C:\WINDOWS\system32\outhdgyg.dll
C:\WINDOWS\system32\oxwncjfd.dll
C:\WINDOWS\system32\pagwysnn.ini
C:\WINDOWS\system32\pcowiesu.exe
C:\WINDOWS\system32\pkxfprcf.dll
C:\WINDOWS\system32\prnkjjen.ini
C:\WINDOWS\system32\qnlvgjfs.ini
C:\WINDOWS\system32\reeskawh.ini
C:\WINDOWS\system32\rocbtqot.dll
C:\WINDOWS\system32\rpkeeyog.dll
C:\WINDOWS\system32\rwfwfusl.exe
C:\WINDOWS\system32\sfjgvlnq.dll
C:\WINDOWS\system32\swlfswkj.ini
C:\WINDOWS\system32\sxwctmdj.dll
C:\WINDOWS\system32\tjmjejww.ini
C:\WINDOWS\system32\tyyatixa.ini
C:\WINDOWS\system32\udwbxhuv.dll
C:\WINDOWS\system32\uepuxyne.dll
C:\WINDOWS\system32\ugpkfnop.ini
C:\WINDOWS\system32\uxwyakkk.ini
C:\WINDOWS\system32\vwbhjxtc.ini
C:\WINDOWS\system32\wcduspkp.dll
C:\WINDOWS\system32\wwjejmjt.dll
C:\WINDOWS\system32\wycfe.ini
C:\WINDOWS\system32\wycfe.ini2
C:\WINDOWS\system32\xgfasacg.ini
C:\WINDOWS\system32\xieiaino.dll
C:\WINDOWS\system32\xoalouwo.dll
C:\WINDOWS\system32\xtmjfefu.dll
C:\WINDOWS\system32\xuhwiikh.dll
C:\WINDOWS\system32\xuljcuio.ini
C:\WINDOWS\system32\xwtdwfmu.dll
C:\WINDOWS\system32\ybrkernf.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_DOMAINSERVICE
——-\DomainService




((((((((((((((((((((((((( Files Created from 2008-01-01 to 2008-02-01 )))))))))))))))))))))))))))))))
.

2008-01-31 00:20 . 2008-01-31 00:20 d–hs—- C:\FOUND.002
2008-01-20 13:20 . 2008-01-20 13:20 d——– C:\Documents and Settings\Jim\Application Data\Grisoft
2008-01-20 13:19 . 2008-01-20 13:19 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-20 13:19 . 2007-05-30 07:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-01-18 21:30 . 2008-01-18 21:30 d–hs—- C:\FOUND.001
2008-01-18 18:58 . 2008-01-18 18:58 d–hs—- C:\FOUND.000
2008-01-17 23:49 . 2008-01-17 23:49 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-17 22:50 . 2008-01-17 22:50 90,112 –a—— C:\WINDOWS\system32\bxbpbata.exe
2008-01-16 11:26 . 2008-01-16 11:26 3,637,248 –a—— C:\WINDOWS\system32\yxrntmfr.exe
2008-01-15 01:06 . 2008-01-15 01:06 d——– C:\WINDOWS\ERUNT
2008-01-15 00:44 . 2008-01-15 00:44 15,360 –a—— C:\WINDOWS\system32\ctfmon .exe
2008-01-14 23:52 . 2008-01-15 00:37 3,622 –a—— C:\WINDOWS\system32\tmp.reg
2008-01-14 23:50 . 2007-09-05 23:22 289,144 –a—— C:\WINDOWS\system32\VCCLSID.exe
2008-01-14 23:50 . 2006-04-27 16:49 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2008-01-14 23:50 . 2007-12-20 23:11 81,920 –a—— C:\WINDOWS\system32\IEDFix.exe
2008-01-14 23:50 . 2003-06-05 20:13 53,248 –a—— C:\WINDOWS\system32\Process.exe
2008-01-14 23:50 . 2004-07-31 17:50 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2008-01-14 23:50 . 2007-10-03 23:36 25,600 –a—— C:\WINDOWS\system32\WS2Fix.exe
2008-01-13 17:39 . 2008-01-19 12:53 155,648 –a—— C:\WINDOWS\system32\NeroCheck .exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-27 14:12 500,736 —-a-w C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\OLD8F.tmp
2008-01-18 23:58 81,920 —-a-w C:\WINDOWS\DUMP3eb5.tmp
2007-11-07 09:26 721,920 —-a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:26 721,920 ——w C:\WINDOWS\system32\dllcache\lsasrv.dll
2004-07-24 05:31 210,576 —-a-w C:\Documents and Settings\Jim\Application Data\GDIPFONTCACHEV1.DAT
2002-03-12 04:06 560 —-a-w C:\Program Files\#readme.txt
2002-03-06 22:55 88,064 —-a-w C:\Program Files\USBMN1X1.DLL
2002-03-06 22:55 7,302 —-a-w C:\Program Files\USBMM1X1.VXD
2002-03-06 22:55 32,476 —-a-w C:\Program Files\USBMM1X1.SYS
2002-03-06 22:55 234,496 —-a-w C:\Program Files\UNINSTAL.EXE
2002-03-06 22:55 2,928 —-a-w C:\Program Files\MM1X1USB.INF
2002-03-06 22:55 2,901 —-a-w C:\Program Files\USBMM1X1.INF
2002-03-06 22:55 17,920 —-a-w C:\Program Files\USBMM1X1.DLL
2002-03-06 22:55 15,740 —-a-w C:\Program Files\USB11LDR.SYS
2002-03-06 22:55 12,144 —-a-w C:\Program Files\USBMM1X1.DRV
2002-03-06 22:55 11,551 —-a-w C:\Program Files\#INSTALL.TXT
1999-03-01 12:36 74,524 —-a-w C:\Program Files\cdrwin.hlp
1999-03-01 12:36 609 —-a-w C:\Program Files\cdrwin.cnt
1999-03-01 12:36 166 —-a-w C:\Program Files\file_id.diz
1999-03-01 12:36 1,450 —-a-w C:\Program Files\cdrwin.nfo
1999-03-01 12:36 1,024 —-a-w C:\Program Files\cdrwin.dat
2005-02-12 21:43 475 –sh–w C:\WINDOWS\system32\vnek.dll
.
—-a-w		   155,648 2008-01-19 17:53:24  C:\WINDOWS\system32\NeroCheck .exe
—-a-w			15,360 2008-01-15 05:44:52  C:\WINDOWS\system32\ctfmon .exe
—-a-w		   364,544 2008-01-19 17:53:02  C:\WINDOWS\system32\spool\drivers\w32x86\3\fppdis1 .exe
—-a-w		   196,608 2008-01-19 17:53:34  C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04 .exe
—-a-w		   180,269 2008-01-20 17:53:46  C:\Program Files\Common Files\Real\Update_OB\realsched .exe
—-a-w			94,208 2008-01-13 23:17:24  C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor .exe
—-a-w		 1,694,208 2008-01-19 17:54:02  C:\Program Files\Messenger\msmsgs .exe
—-a-w		   188,416 2008-01-19 17:52:48  C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp .exe
—-a-w			61,440 2008-01-19 17:52:54  C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient .exe
—-a-w			49,263 2008-01-19 17:52:48  C:\Program Files\Java\jre1.5.0_10\bin\jusched .exe
—-a-w			68,856 2008-01-19 17:53:50  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
—-a-w		   819,262 2008-01-19 17:51:12  C:\Program Files\Trend Micro\Internet Security 2005\pccguide .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TomcatStartup 2.5"="C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe" [ ]
"StatusClient 2.6"="C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe" [ ]
"nwiz"="nwiz.exe" [2006-08-11 21:43 1519616 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-08-11 21:43 86016]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-08-11 21:43 7630848]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [ ]
"iTunesHelper"="I:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 09:36 256576]
"!AVG Anti-Spyware"="G:\program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25 6731312]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 03:56 158208]

C:\Documents and Settings\Jim\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50 113664]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\khfgded]
khfgded.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
–a—— 2005-08-30 16:34 865280 I:\Nero\Nero 7\Nero StartSmart\InCD\InCD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe

R3 XD2_DspCtrl;XD2 DSP Control;C:\WINDOWS\system32\DRIVERS\XD2_DspCtrl.sys [2006-03-22 15:38]
S2 ousbehci;NEC PCI to USB Enhanced Host Controller;C:\WINDOWS\system32\Drivers\ousbehci.sys []
S3 atirage;atirage;C:\WINDOWS\system32\DRIVERS\atiragem.sys [2001-08-17 12:48]
S3 RimSerPort;RIM Virtual Serial Port;C:\WINDOWS\system32\DRIVERS\RimSerial.sys [2005-08-16 13:02]
S3 USB11LDR;USB Midi 1x1 Loader;C:\WINDOWS\system32\drivers\usb11ldr.sys [2005-03-06 08:37]
S3 USBMM1X1;USB Midi 1x1 Driver;C:\WINDOWS\system32\drivers\usbmm1x1.sys []
S3 USBMN1X1;USB Midi 1x1;C:\WINDOWS\system32\drivers\usbmn1x1.sys [2005-03-06 08:37]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0c61f480-7b7c-11dc-bfc4-000f661c6917}]
\Shell\AutoRun\command - J:\wd_windows_tools\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8f3edc01-9b75-11dc-bfc9-000f661c6917}]
\Shell\AutoRun\command - J:\wd_windows_tools\setup.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-01-30 09:05:04 C:\WINDOWS\Tasks\{DC6DAE2D-2D62-4C1E-A4E3-8415DCA74A47}_FLICKER-JJ9HCKO_Jim.job"
- C:\WINDOWS\system32\mobsync.exe
"2008-01-31 21:20:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-31 20:42:02
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
I:\Nero\Nero 7\Nero StartSmart\InCD\InCDsrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\RUNDLL32.EXE
I:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
G:\program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
.
**************************************************************************
.
Completion time: 2008-01-31 20:44:37 - machine was rebooted [Jim]
ComboFix-quarantined-files.txt 2008-02-01 01:44:32
.
2008-01-09 08:06:37 — E O F —


THEN THE HJT Log

Logfile of HijackThis v1.99.1
Scan saved at 20:50, on 2008-01-31
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
I:\Nero\Nero 7\Nero StartSmart\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
g:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\RUNDLL32.EXE
I:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
G:\program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
I:\Program Files\Hijack This\HJT.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - g:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [TomcatStartup 2.5] C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe
O4 - HKLM\..\Run: [StatusClient 2.6] C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [iTunesHelper] "I:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "G:\program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - I:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://aimexpress.aol.com
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://corriherptz.axiscam.net:9552/activex/AMC.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{FB81C809-2055-49EB-A81E-7C622743A397}: NameServer = 24.247.24.53,24.247.15.53
O20 - Winlogon Notify: khfgded - khfgded.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - g:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - I:\Nero\Nero 7\Nero StartSmart\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
Please save the code below to Notepad and save it as CFScript.txt to your Desktop.
File::
C:\WINDOWS\system32\bxbpbata.exe
C:\WINDOWS\system32\yxrntmfr.exe
C:\WINDOWS\system32\IEDFix.exe

Driver::
ousbehci

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Works Update Detection"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\khfgded]

RENV::
—-a-w		   155,648 2008-01-19 17:53:24  C:\WINDOWS\system32\NeroCheck .exe
—-a-w			15,360 2008-01-15 05:44:52  C:\WINDOWS\system32\ctfmon .exe
—-a-w		   364,544 2008-01-19 17:53:02  C:\WINDOWS\system32\spool\drivers\w32x86\3\fppdis1 .exe
—-a-w		   196,608 2008-01-19 17:53:34  C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04 .exe
—-a-w		   180,269 2008-01-20 17:53:46  C:\Program Files\Common Files\Real\Update_OB\realsched .exe
—-a-w			94,208 2008-01-13 23:17:24  C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor .exe
—-a-w		 1,694,208 2008-01-19 17:54:02  C:\Program Files\Messenger\msmsgs .exe
—-a-w		   188,416 2008-01-19 17:52:48  C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp .exe
—-a-w			61,440 2008-01-19 17:52:54  C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient .exe
—-a-w			49,263 2008-01-19 17:52:48  C:\Program Files\Java\jre1.5.0_10\bin\jusched .exe
—-a-w			68,856 2008-01-19 17:53:50  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
—-a-w		   819,262 2008-01-19 17:51:12  C:\Program Files\Trend Micro\Internet Security 2005\pccguide .exe
Now please drag CFScript.txt on the ComboFix icon on your Desktop as shown below.
[external image: Posted Image]

ComboFix will automatically start up and run, please save it's log when finished.

If ComboFix does not reboot your system, please do so now.

Please post a new HJT log and let me know how your computer is running now. Are you having problems with running any programs?
So far, so good.

Here's the new HJT log…

Logfile of HijackThis v1.99.1
Scan saved at 06:31, on 2008-02-01
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
I:\Nero\Nero 7\Nero StartSmart\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
g:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\RUNDLL32.EXE
I:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\wuauclt.exe
G:\program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
I:\Program Files\Hijack This\HJT.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - g:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [TomcatStartup 2.5] C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe
O4 - HKLM\..\Run: [StatusClient 2.6] C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [iTunesHelper] "I:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "G:\program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - I:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://aimexpress.aol.com
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://corriherptz.axiscam.net:9552/activex/AMC.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{FB81C809-2055-49EB-A81E-7C622743A397}: NameServer = 24.247.24.53,24.247.15.53
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - g:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - I:\Nero\Nero 7\Nero StartSmart\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
You didn't include your ComboFix log, did you follow my instructions for CFScript? If so please post the log and if not please do so.
Sorry about that. Your message said to save the combofix log but didn't mention posting it. I thought it was weird, but I didn't want to second guess you for fear that you'd make fun of me!.

Anywho, so, yes I ran the CF script as you instructed.

Now, here's the post of the combofix log:

ComboFix 08-01-31.3 - Jim 2008-02-01 6:18:03.3 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1506 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Jim\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\WINDOWS\system32\bxbpbata.exe
C:\WINDOWS\system32\IEDFix.exe
C:\WINDOWS\system32\yxrntmfr.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\bxbpbata.exe
C:\WINDOWS\system32\IEDFix.exe
C:\WINDOWS\system32\yxrntmfr.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_OUSBEHCI
——-\ousbehci


((((((((((((((((((((((((( Files Created from 2008-01-01 to 2008-02-01 )))))))))))))))))))))))))))))))
.

2008-01-31 21:04 . 2008-01-31 21:04 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-01-31 21:04 . 2008-01-31 21:04 1,409 –a—— C:\WINDOWS\QTFont.for
2008-01-31 00:20 . 2008-01-31 00:20 d–hs—- C:\FOUND.002
2008-01-20 13:20 . 2008-01-20 13:20 d——– C:\Documents and Settings\Jim\Application Data\Grisoft
2008-01-20 13:19 . 2008-01-20 13:19 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-20 13:19 . 2007-05-30 07:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-01-18 21:30 . 2008-01-18 21:30 d–hs—- C:\FOUND.001
2008-01-18 18:58 . 2008-01-18 18:58 d–hs—- C:\FOUND.000
2008-01-17 23:49 . 2008-01-17 23:49 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-15 01:06 . 2008-01-15 01:06 d——– C:\WINDOWS\ERUNT
2008-01-15 00:44 . 2008-01-15 00:44 15,360 –a—— C:\WINDOWS\system32\ctfmon .exe
2008-01-14 23:52 . 2008-01-15 00:37 3,622 –a—— C:\WINDOWS\system32\tmp.reg
2008-01-14 23:50 . 2007-09-05 23:22 289,144 –a—— C:\WINDOWS\system32\VCCLSID.exe
2008-01-14 23:50 . 2006-04-27 16:49 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2008-01-14 23:50 . 2003-06-05 20:13 53,248 –a—— C:\WINDOWS\system32\Process.exe
2008-01-14 23:50 . 2004-07-31 17:50 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2008-01-14 23:50 . 2007-10-03 23:36 25,600 –a—— C:\WINDOWS\system32\WS2Fix.exe
2008-01-13 17:39 . 2008-01-19 12:53 155,648 –a—— C:\WINDOWS\system32\NeroCheck .exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-27 14:12 500,736 —-a-w C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\OLD8F.tmp
2008-01-18 23:58 81,920 —-a-w C:\WINDOWS\DUMP3eb5.tmp
2007-11-07 09:26 721,920 —-a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:26 721,920 ——w C:\WINDOWS\system32\dllcache\lsasrv.dll
2004-07-24 05:31 210,576 —-a-w C:\Documents and Settings\Jim\Application Data\GDIPFONTCACHEV1.DAT
2002-03-12 04:06 560 —-a-w C:\Program Files\#readme.txt
2002-03-06 22:55 88,064 —-a-w C:\Program Files\USBMN1X1.DLL
2002-03-06 22:55 7,302 —-a-w C:\Program Files\USBMM1X1.VXD
2002-03-06 22:55 32,476 —-a-w C:\Program Files\USBMM1X1.SYS
2002-03-06 22:55 234,496 —-a-w C:\Program Files\UNINSTAL.EXE
2002-03-06 22:55 2,928 —-a-w C:\Program Files\MM1X1USB.INF
2002-03-06 22:55 2,901 —-a-w C:\Program Files\USBMM1X1.INF
2002-03-06 22:55 17,920 —-a-w C:\Program Files\USBMM1X1.DLL
2002-03-06 22:55 15,740 —-a-w C:\Program Files\USB11LDR.SYS
2002-03-06 22:55 12,144 —-a-w C:\Program Files\USBMM1X1.DRV
2002-03-06 22:55 11,551 —-a-w C:\Program Files\#INSTALL.TXT
1999-03-01 12:36 74,524 —-a-w C:\Program Files\cdrwin.hlp
1999-03-01 12:36 609 —-a-w C:\Program Files\cdrwin.cnt
1999-03-01 12:36 166 —-a-w C:\Program Files\file_id.diz
1999-03-01 12:36 1,450 —-a-w C:\Program Files\cdrwin.nfo
1999-03-01 12:36 1,024 —-a-w C:\Program Files\cdrwin.dat
2005-02-12 21:43 475 –sh–w C:\WINDOWS\system32\vnek.dll
.
—-a-w		   155,648 2008-01-19 17:53:24  C:\WINDOWS\system32\NeroCheck .exe
—-a-w			15,360 2008-01-15 05:44:52  C:\WINDOWS\system32\ctfmon .exe
—-a-w		   364,544 2008-01-19 17:53:02  C:\WINDOWS\system32\spool\drivers\w32x86\3\fppdis1 .exe
—-a-w		   196,608 2008-01-19 17:53:34  C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04 .exe
—-a-w		   180,269 2008-01-20 17:53:46  C:\Program Files\Common Files\Real\Update_OB\realsched .exe
—-a-w			94,208 2008-01-13 23:17:24  C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor .exe
—-a-w		 1,694,208 2008-01-19 17:54:02  C:\Program Files\Messenger\msmsgs .exe
—-a-w		   188,416 2008-01-19 17:52:48  C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp .exe
—-a-w			61,440 2008-01-19 17:52:54  C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient .exe
—-a-w			49,263 2008-01-19 17:52:48  C:\Program Files\Java\jre1.5.0_10\bin\jusched .exe
—-a-w			68,856 2008-01-19 17:53:50  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
—-a-w		   819,262 2008-01-19 17:51:12  C:\Program Files\Trend Micro\Internet Security 2005\pccguide .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TomcatStartup 2.5"="C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe" [ ]
"StatusClient 2.6"="C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe" [ ]
"nwiz"="nwiz.exe" [2006-08-11 21:43 1519616 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-08-11 21:43 86016]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-08-11 21:43 7630848]
"iTunesHelper"="I:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 09:36 256576]
"!AVG Anti-Spyware"="G:\program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25 6731312]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 03:56 158208]

C:\Documents and Settings\Jim\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50 113664]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
–a—— 2005-08-30 16:34 865280 I:\Nero\Nero 7\Nero StartSmart\InCD\InCD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe

R3 XD2_DspCtrl;XD2 DSP Control;C:\WINDOWS\system32\DRIVERS\XD2_DspCtrl.sys [2006-03-22 15:38]
S3 atirage;atirage;C:\WINDOWS\system32\DRIVERS\atiragem.sys [2001-08-17 12:48]
S3 RimSerPort;RIM Virtual Serial Port;C:\WINDOWS\system32\DRIVERS\RimSerial.sys [2005-08-16 13:02]
S3 USB11LDR;USB Midi 1x1 Loader;C:\WINDOWS\system32\drivers\usb11ldr.sys [2005-03-06 08:37]
S3 USBMM1X1;USB Midi 1x1 Driver;C:\WINDOWS\system32\drivers\usbmm1x1.sys []
S3 USBMN1X1;USB Midi 1x1;C:\WINDOWS\system32\drivers\usbmn1x1.sys [2005-03-06 08:37]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0c61f480-7b7c-11dc-bfc4-000f661c6917}]
\Shell\AutoRun\command - J:\wd_windows_tools\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8f3edc01-9b75-11dc-bfc9-000f661c6917}]
\Shell\AutoRun\command - J:\wd_windows_tools\setup.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-01-30 09:05:04 C:\WINDOWS\Tasks\{DC6DAE2D-2D62-4C1E-A4E3-8415DCA74A47}_FLICKER-JJ9HCKO_Jim.job"
- C:\WINDOWS\system32\mobsync.exeH /Schedule=
"2008-01-31 21:20:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-01 06:26:06
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
I:\Nero\Nero 7\Nero StartSmart\InCD\InCDsrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\RUNDLL32.EXE
I:\Program Files\iTunes\iTunesHelper.exe
G:\program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-02-01 6:28:42 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-01 11:28:38
ComboFix2.txt 2008-02-01 01:44:40
.
2008-01-09 08:06:37 — E O F —


AND THE HJT LOG (same one, from Feb 1, but reposted so you don't have to flip around the post)

Logfile of HijackThis v1.99.1
Scan saved at 06:31, on 2008-02-01
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
I:\Nero\Nero 7\Nero StartSmart\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
g:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\RUNDLL32.EXE
I:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\wuauclt.exe
G:\program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
I:\Program Files\Hijack This\HJT.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - g:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [TomcatStartup 2.5] C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe
O4 - HKLM\..\Run: [StatusClient 2.6] C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [iTunesHelper] "I:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "G:\program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - I:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://aimexpress.aol.com
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://corriherptz.axiscam.net:9552/activex/AMC.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{FB81C809-2055-49EB-A81E-7C622743A397}: NameServer = 24.247.24.53,24.247.15.53
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - g:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - I:\Nero\Nero 7\Nero StartSmart\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
I know this may be frustrated but I need you to delete your copy of ComboFix, download and run a newer version. This is important because this newer version of ComboFix fixes a bug that has been hindering the success of some aspects of my CFScript.

Please delete all versions of ComboFix you currently have.

Now please reboot your Computer.

Please download ComboFix by sUBs from HERE or HERE

You must download it to your Desktop

Go to [external image: Posted Image] -> Run -> paste in the following single line command & click OK


"%userprofile%\desktop\combofix.exe" /killall



[external image: Posted Image]

ComboFix will automatically start, any monitoring programs will be shut down like your antivirus, antispyware programs for example.

ComboFix may restart your computer, this is normal.

When finished, it will produce a log. Please save its log to post in your next reply .

Note:
Do not mouse-click Combofix's window while it is running. That may cause it to stall.

CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

If ComboFix did not reboot your Computer please reboot it now.

Please post a new HJT log.

Logs to include in your reply
ComboFix
HJT
Not frustrating at all. I appreciate your time and your commitment to fixing my machine!

I DL'd the Combofix from the link you provided.

One thing that's worth mentioning is that when the computer reboots; it just started launching a WINDOWS SYSTEM CONFIGUATION UTILITY. I canncelld out of it, but I'm not sure it that's causing some problems.

Here's the new Combofix Log:

ComboFix 08-02.02.5 - Jim 2008-02-02 13:57:20.4 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1635 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-01-02 to 2008-02-02 )))))))))))))))))))))))))))))))
.

2008-01-31 21:04 . 2008-02-02 12:23 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-01-31 21:04 . 2008-01-31 21:04 1,409 –a—— C:\WINDOWS\QTFont.for
2008-01-31 00:20 . 2008-01-31 00:20 d–hs—- C:\FOUND.002
2008-01-20 13:20 . 2008-01-20 13:20 d——– C:\Documents and Settings\Jim\Application Data\Grisoft
2008-01-20 13:19 . 2008-01-20 13:19 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-20 13:19 . 2007-05-30 07:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-01-18 21:30 . 2008-01-18 21:30 d–hs—- C:\FOUND.001
2008-01-18 18:58 . 2008-01-18 18:58 d–hs—- C:\FOUND.000
2008-01-17 23:49 . 2008-01-17 23:49 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-15 01:06 . 2008-01-15 01:06 d——– C:\WINDOWS\ERUNT
2008-01-15 00:58 . 2008-01-12 09:23 d——– C:\SDFix
2008-01-15 00:44 . 2008-01-15 00:44 15,360 –a—— C:\WINDOWS\system32\ctfmon .exe
2008-01-14 23:52 . 2008-01-15 00:37 3,622 –a—— C:\WINDOWS\system32\tmp.reg
2008-01-14 23:50 . 2007-09-05 23:22 289,144 –a—— C:\WINDOWS\system32\VCCLSID.exe
2008-01-14 23:50 . 2006-04-27 16:49 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2008-01-14 23:50 . 2003-06-05 20:13 53,248 –a—— C:\WINDOWS\system32\Process.exe
2008-01-14 23:50 . 2004-07-31 17:50 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2008-01-14 23:50 . 2007-10-03 23:36 25,600 –a—— C:\WINDOWS\system32\WS2Fix.exe
2008-01-14 23:30 . 2008-01-14 23:30 d——– C:\fixwareout
2008-01-13 17:39 . 2008-01-19 12:53 155,648 –a—— C:\WINDOWS\system32\NeroCheck .exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-27 14:12 500,736 —-a-w C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\OLD8F.tmp
2008-01-18 23:58 81,920 —-a-w C:\WINDOWS\DUMP3eb5.tmp
2007-11-07 09:26 721,920 —-a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:26 721,920 ——w C:\WINDOWS\system32\dllcache\lsasrv.dll
2004-07-24 05:31 210,576 —-a-w C:\Documents and Settings\Jim\Application Data\GDIPFONTCACHEV1.DAT
2002-03-12 04:06 560 —-a-w C:\Program Files\#readme.txt
2002-03-06 22:55 88,064 —-a-w C:\Program Files\USBMN1X1.DLL
2002-03-06 22:55 7,302 —-a-w C:\Program Files\USBMM1X1.VXD
2002-03-06 22:55 32,476 —-a-w C:\Program Files\USBMM1X1.SYS
2002-03-06 22:55 234,496 —-a-w C:\Program Files\UNINSTAL.EXE
2002-03-06 22:55 2,928 —-a-w C:\Program Files\MM1X1USB.INF
2002-03-06 22:55 2,901 —-a-w C:\Program Files\USBMM1X1.INF
2002-03-06 22:55 17,920 —-a-w C:\Program Files\USBMM1X1.DLL
2002-03-06 22:55 15,740 —-a-w C:\Program Files\USB11LDR.SYS
2002-03-06 22:55 12,144 —-a-w C:\Program Files\USBMM1X1.DRV
2002-03-06 22:55 11,551 —-a-w C:\Program Files\#INSTALL.TXT
1999-03-01 12:36 74,524 —-a-w C:\Program Files\cdrwin.hlp
1999-03-01 12:36 609 —-a-w C:\Program Files\cdrwin.cnt
1999-03-01 12:36 166 —-a-w C:\Program Files\file_id.diz
1999-03-01 12:36 1,450 —-a-w C:\Program Files\cdrwin.nfo
1999-03-01 12:36 1,024 —-a-w C:\Program Files\cdrwin.dat
2005-02-12 21:43 475 –sh–w C:\WINDOWS\system32\vnek.dll
.
—-a-w		   155,648 2008-01-19 17:53:24  C:\WINDOWS\system32\NeroCheck .exe
—-a-w			15,360 2008-01-15 05:44:52  C:\WINDOWS\system32\ctfmon .exe
—-a-w		   364,544 2008-01-19 17:53:02  C:\WINDOWS\system32\spool\drivers\w32x86\3\fppdis1 .exe
—-a-w		   196,608 2008-01-19 17:53:34  C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04 .exe
—-a-w		   180,269 2008-01-20 17:53:46  C:\Program Files\Common Files\Real\Update_OB\realsched .exe
—-a-w			94,208 2008-01-13 23:17:24  C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor .exe
—-a-w		 1,694,208 2008-01-19 17:54:02  C:\Program Files\Messenger\msmsgs .exe
—-a-w		   188,416 2008-01-19 17:52:48  C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp .exe
—-a-w			61,440 2008-01-19 17:52:54  C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient .exe
—-a-w			49,263 2008-01-19 17:52:48  C:\Program Files\Java\jre1.5.0_10\bin\jusched .exe
—-a-w			68,856 2008-01-19 17:53:50  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
—-a-w		   819,262 2008-01-19 17:51:12  C:\Program Files\Trend Micro\Internet Security 2005\pccguide .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TomcatStartup 2.5"="C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe" [ ]
"StatusClient 2.6"="C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe" [ ]
"nwiz"="nwiz.exe" [2006-08-11 21:43 1519616 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-08-11 21:43 86016]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-08-11 21:43 7630848]
"iTunesHelper"="I:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 09:36 256576]
"!AVG Anti-Spyware"="G:\program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25 6731312]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 03:56 158208]

C:\Documents and Settings\Jim\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50 113664]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
–a—— 2005-08-30 16:34 865280 I:\Nero\Nero 7\Nero StartSmart\InCD\InCD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe

R3 XD2_DspCtrl;XD2 DSP Control;C:\WINDOWS\system32\DRIVERS\XD2_DspCtrl.sys [2006-03-22 15:38]
S3 atirage;atirage;C:\WINDOWS\system32\DRIVERS\atiragem.sys [2001-08-17 12:48]
S3 RimSerPort;RIM Virtual Serial Port;C:\WINDOWS\system32\DRIVERS\RimSerial.sys [2005-08-16 13:02]
S3 USB11LDR;USB Midi 1x1 Loader;C:\WINDOWS\system32\drivers\usb11ldr.sys [2005-03-06 08:37]
S3 USBMM1X1;USB Midi 1x1 Driver;C:\WINDOWS\system32\drivers\usbmm1x1.sys []
S3 USBMN1X1;USB Midi 1x1;C:\WINDOWS\system32\drivers\usbmn1x1.sys [2005-03-06 08:37]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0c61f480-7b7c-11dc-bfc4-000f661c6917}]
\Shell\AutoRun\command - J:\wd_windows_tools\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8f3edc01-9b75-11dc-bfc9-000f661c6917}]
\Shell\AutoRun\command - J:\wd_windows_tools\setup.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-01-30 09:05:04 C:\WINDOWS\Tasks\{DC6DAE2D-2D62-4C1E-A4E3-8415DCA74A47}_FLICKER-JJ9HCKO_Jim.job"
- C:\WINDOWS\system32\mobsync.exeH /Schedule=
"2008-01-31 21:20:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-02 14:32:36
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
I:\Nero\Nero 7\Nero StartSmart\InCD\InCDsrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-02-02 14:35:07 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-02 19:35:02
ComboFix3.txt 2008-02-01 01:44:40
ComboFix2.txt 2008-02-01 11:28:44
.
2008-01-09 08:06:37 — E O F —


And a new HJT log….

Logfile of HijackThis v1.99.1
Scan saved at 14:41, on 2008-02-02
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
I:\Nero\Nero 7\Nero StartSmart\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
g:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
I:\Program Files\iTunes\iTunesHelper.exe
G:\program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
I:\Program Files\Hijack This\HJT.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - g:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [TomcatStartup 2.5] C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe
O4 - HKLM\..\Run: [StatusClient 2.6] C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [iTunesHelper] "I:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "G:\program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - I:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://aimexpress.aol.com
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://corriherptz.axiscam.net:9552/activex/AMC.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{FB81C809-2055-49EB-A81E-7C622743A397}: NameServer = 24.247.24.53,24.247.15.53
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - g:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - I:\Nero\Nero 7\Nero StartSmart\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
Please save the code below to Notepad and save it as CFScript.txt to your Desktop.
RENV::
—-a-w		   155,648 2008-01-19 17:53:24  C:\WINDOWS\system32\NeroCheck .exe
—-a-w			15,360 2008-01-15 05:44:52  C:\WINDOWS\system32\ctfmon .exe
—-a-w		   364,544 2008-01-19 17:53:02  C:\WINDOWS\system32\spool\drivers\w32x86\3\fppdis1 .exe
—-a-w		   196,608 2008-01-19 17:53:34  C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04 .exe
—-a-w		   180,269 2008-01-20 17:53:46  C:\Program Files\Common Files\Real\Update_OB\realsched .exe
—-a-w			94,208 2008-01-13 23:17:24  C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor .exe
—-a-w		 1,694,208 2008-01-19 17:54:02  C:\Program Files\Messenger\msmsgs .exe
—-a-w		   188,416 2008-01-19 17:52:48  C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp .exe
—-a-w			61,440 2008-01-19 17:52:54  C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient .exe
—-a-w			49,263 2008-01-19 17:52:48  C:\Program Files\Java\jre1.5.0_10\bin\jusched .exe
—-a-w			68,856 2008-01-19 17:53:50  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
—-a-w		   819,262 2008-01-19 17:51:12  C:\Program Files\Trend Micro\Internet Security 2005\pccguide .exe
Now please drag CFScript.txt on the ComboFix icon on your Desktop as shown below.
[external image: Posted Image]

ComboFix will automatically start up and run, please save it's log when finished.

If ComboFix does not reboot your system, please do so now.

Please post a new HJT log.

Logs to include in your reply
ComboFix
HJT
Thanks, here's the ComboFix Log:

ComboFix 08-02.02.5 - Jim 2008-02-03 8:36:26.5 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1483 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Jim\Desktop\CFScript.txt

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-01-03 to 2008-02-03 )))))))))))))))))))))))))))))))
.

2008-01-31 00:20 . 2008-01-31 00:20 d–hs—- C:\FOUND.002
2008-01-20 13:20 . 2008-01-20 13:20 d——– C:\Documents and Settings\Jim\Application Data\Grisoft
2008-01-20 13:19 . 2008-01-20 13:19 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-20 13:19 . 2007-05-30 07:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-01-18 21:30 . 2008-01-18 21:30 d–hs—- C:\FOUND.001
2008-01-18 18:58 . 2008-01-18 18:58 d–hs—- C:\FOUND.000
2008-01-17 23:49 . 2008-01-17 23:49 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-15 01:06 . 2008-01-15 01:06 d——– C:\WINDOWS\ERUNT
2008-01-15 00:58 . 2008-01-12 09:23 d——– C:\SDFix
2008-01-15 00:44 . 2008-01-15 00:44 15,360 –a—— C:\WINDOWS\system32\dllcache\ctfmon.exe
2008-01-15 00:44 . 2008-01-15 00:44 15,360 –a—— C:\WINDOWS\system32\ctfmon.exe
2008-01-14 23:52 . 2008-01-15 00:37 3,622 –a—— C:\WINDOWS\system32\tmp.reg
2008-01-14 23:50 . 2007-09-05 23:22 289,144 –a—— C:\WINDOWS\system32\VCCLSID.exe
2008-01-14 23:50 . 2006-04-27 16:49 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2008-01-14 23:50 . 2003-06-05 20:13 53,248 –a—— C:\WINDOWS\system32\Process.exe
2008-01-14 23:50 . 2004-07-31 17:50 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2008-01-14 23:50 . 2007-10-03 23:36 25,600 –a—— C:\WINDOWS\system32\WS2Fix.exe
2008-01-14 23:30 . 2008-01-14 23:30 d——– C:\fixwareout
2008-01-13 17:39 . 2008-01-19 12:53 155,648 –a—— C:\WINDOWS\system32\NeroCheck.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-27 14:12 500,736 —-a-w C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\OLD8F.tmp
2008-01-18 23:58 81,920 —-a-w C:\WINDOWS\DUMP3eb5.tmp
2007-11-07 09:26 721,920 —-a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:26 721,920 ——w C:\WINDOWS\system32\dllcache\lsasrv.dll
2004-07-24 05:31 210,576 —-a-w C:\Documents and Settings\Jim\Application Data\GDIPFONTCACHEV1.DAT
2002-03-12 04:06 560 —-a-w C:\Program Files\#readme.txt
2002-03-06 22:55 88,064 —-a-w C:\Program Files\USBMN1X1.DLL
2002-03-06 22:55 7,302 —-a-w C:\Program Files\USBMM1X1.VXD
2002-03-06 22:55 32,476 —-a-w C:\Program Files\USBMM1X1.SYS
2002-03-06 22:55 234,496 —-a-w C:\Program Files\UNINSTAL.EXE
2002-03-06 22:55 2,928 —-a-w C:\Program Files\MM1X1USB.INF
2002-03-06 22:55 2,901 —-a-w C:\Program Files\USBMM1X1.INF
2002-03-06 22:55 17,920 —-a-w C:\Program Files\USBMM1X1.DLL
2002-03-06 22:55 15,740 —-a-w C:\Program Files\USB11LDR.SYS
2002-03-06 22:55 12,144 —-a-w C:\Program Files\USBMM1X1.DRV
2002-03-06 22:55 11,551 —-a-w C:\Program Files\#INSTALL.TXT
1999-03-01 12:36 74,524 —-a-w C:\Program Files\cdrwin.hlp
1999-03-01 12:36 609 —-a-w C:\Program Files\cdrwin.cnt
1999-03-01 12:36 166 —-a-w C:\Program Files\file_id.diz
1999-03-01 12:36 1,450 —-a-w C:\Program Files\cdrwin.nfo
1999-03-01 12:36 1,024 —-a-w C:\Program Files\cdrwin.dat
2005-02-12 21:43 475 –sh–w C:\WINDOWS\system32\vnek.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-19 12:53 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TomcatStartup 2.5"="C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe" [2008-01-19 12:52 188416]
"StatusClient 2.6"="C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe" [2008-01-19 12:52 61440]
"nwiz"="nwiz.exe" [2006-08-11 21:43 1519616 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-08-11 21:43 86016]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-08-11 21:43 7630848]
"iTunesHelper"="I:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 09:36 256576]
"!AVG Anti-Spyware"="G:\program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25 6731312]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 03:56 158208]

C:\Documents and Settings\Jim\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50 113664]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
–a—— 2005-08-30 16:34 865280 I:\Nero\Nero 7\Nero StartSmart\InCD\InCD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2008-01-19 12:54 1694208 C:\Program Files\Messenger\msmsgs.exe

R3 XD2_DspCtrl;XD2 DSP Control;C:\WINDOWS\system32\DRIVERS\XD2_DspCtrl.sys [2006-03-22 15:38]
S3 atirage;atirage;C:\WINDOWS\system32\DRIVERS\atiragem.sys [2001-08-17 12:48]
S3 RimSerPort;RIM Virtual Serial Port;C:\WINDOWS\system32\DRIVERS\RimSerial.sys [2005-08-16 13:02]
S3 USB11LDR;USB Midi 1x1 Loader;C:\WINDOWS\system32\drivers\usb11ldr.sys [2005-03-06 08:37]
S3 USBMM1X1;USB Midi 1x1 Driver;C:\WINDOWS\system32\drivers\usbmm1x1.sys []
S3 USBMN1X1;USB Midi 1x1;C:\WINDOWS\system32\drivers\usbmn1x1.sys [2005-03-06 08:37]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0c61f480-7b7c-11dc-bfc4-000f661c6917}]
\Shell\AutoRun\command - J:\wd_windows_tools\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8f3edc01-9b75-11dc-bfc9-000f661c6917}]
\Shell\AutoRun\command - J:\wd_windows_tools\setup.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-01-30 09:05:04 C:\WINDOWS\Tasks\{DC6DAE2D-2D62-4C1E-A4E3-8415DCA74A47}_FLICKER-JJ9HCKO_Jim.job"
- C:\WINDOWS\system32\mobsync.exeH /Schedule=
"2008-01-31 21:20:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-03 08:41:33
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-03 8:44:48
ComboFix-quarantined-files.txt 2008-02-03 13:44:38
ComboFix4.txt 2008-02-01 01:44:40
ComboFix3.txt 2008-02-01 11:28:44
ComboFix2.txt 2008-02-02 19:35:10
.
2008-01-09 08:06:37 — E O F —


And the HJT Log:

Logfile of HijackThis v1.99.1
Scan saved at 08:56, on 2008-02-03
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
I:\Nero\Nero 7\Nero StartSmart\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
g:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe
C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\javaw.exe
I:\Program Files\iTunes\iTunesHelper.exe
G:\program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
I:\Program Files\Hijack This\HJT.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - g:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [TomcatStartup 2.5] C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe
O4 - HKLM\..\Run: [StatusClient 2.6] C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [iTunesHelper] "I:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "G:\program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - I:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://aimexpress.aol.com
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://corriherptz.axiscam.net:9552/activex/AMC.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{FB81C809-2055-49EB-A81E-7C622743A397}: NameServer = 24.247.24.53,24.247.15.53
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - g:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - I:\Nero\Nero 7\Nero StartSmart\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
Everything seems real good on my end.

One final question…I am still have the System Configuration Utility warning window open upon start up. It's indicating that i'm in diagnostic mode and that switching back to Normal mode will start Windows normally and UNDO the changes made to the System Configuration Utility.

So, Is switching back to normal mode going to undo anything we changed?

Thanks in advance for all your help, it's amazing that there's a service like this out here to help.

J

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI