Trev,
Here is the combofix log that came up. I don't see where it says Combofix.txt, but it's the only log that came up. Also, you should know that I was unable to find either Defender or Symantec to disable the items you wanted disabled. The computer couldn't find either program, apparently. You should also know that while i was opening combofix, my choices were run or save, and I hit run, which it did. It did not put anything on my desktop. Should I redo it?
Your text under instruction #4 about going to the run box and copy/pasting that command ending in killall…. I assume that was to do only if the system couldn't reconnect to the internet. I did not do any of that…hope I read it right.
Heres the CF log…I'll do a new HJT log in a minute as soon as I find the link for it.
ComboFix 08-02-25.3 - mom 2008-02-28 19:40:40.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.583 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Local Settings\Temporary Internet Files\Content.IE5\ZFO5F0PK\ComboFix[1].exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\Common Files\Yazzle1552OinUninstaller.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\icroso~1.net\?icrosoft.NET\
C:\WINDOWS\system32\aslnlept.ini
C:\WINDOWS\system32\bhhxlvcw.ini
C:\WINDOWS\system32\bndqnaws.dll
C:\WINDOWS\system32\clhshcnq.ini
C:\WINDOWS\system32\daniaaxx.dll
C:\WINDOWS\system32\delljuva.ini
C:\WINDOWS\system32\efhkj.ini
C:\WINDOWS\system32\efhkj.ini2
C:\WINDOWS\system32\ehvpibbf.dll
C:\WINDOWS\system32\esgwipyq.ini
C:\WINDOWS\system32\fbbipvhe.ini
C:\WINDOWS\system32\ftihbmdl.dll
C:\WINDOWS\system32\fxmpfxhq.dll
C:\WINDOWS\system32\gofkfwns.ini
C:\WINDOWS\system32\iflgdjkd.ini
C:\WINDOWS\system32\ineefbpf.dll
C:\WINDOWS\system32\iochckwu.ini
C:\WINDOWS\system32\iqfieyiv.dll
C:\WINDOWS\system32\jemxwtdj.dll
C:\WINDOWS\system32\jgmfmnci.ini
C:\WINDOWS\system32\jhnpigbg.dll
C:\WINDOWS\system32\jkhfe.dll
C:\WINDOWS\system32\kefmlfii.ini
C:\WINDOWS\system32\kinkltar.ini
C:\WINDOWS\system32\kwctbitc.ini
C:\WINDOWS\system32\ladvjtgl.ini
C:\WINDOWS\system32\lmwgrdbq.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mlohnqyu.ini
C:\WINDOWS\system32\mowcktys.ini
C:\WINDOWS\system32\mqguyenf.ini
C:\WINDOWS\system32\nisypnjj.ini
C:\WINDOWS\system32\nlaadlbo.dll
C:\WINDOWS\system32\okdusqne.ini
C:\WINDOWS\system32\oxxaqvjk.ini
C:\WINDOWS\system32\oywxwspi.ini
C:\WINDOWS\system32\pttmiwbq.ini
C:\WINDOWS\system32\qbsajbqb.ini
C:\WINDOWS\system32\qiuqjvsx.dll
C:\WINDOWS\system32\rbgasnbi.ini
C:\WINDOWS\system32\ruaflnxg.ini
C:\WINDOWS\system32\twbtneyl.ini
C:\WINDOWS\system32\ugpgmbnk.ini
C:\WINDOWS\system32\ujyteqng.dll
C:\WINDOWS\system32\uqsiyuhd.ini
C:\WINDOWS\system32\uvlhvisv.ini
C:\WINDOWS\system32\uylgdxye.ini
C:\WINDOWS\system32\viyeifqi.ini
C:\WINDOWS\system32\wcvlxhhb.dll
C:\WINDOWS\system32\xiwixniu.dll
C:\WINDOWS\system32\xkhdlopk.dll
.
—- Previous Run ——-
.
C:\Program Files\Common Files\Yazzle1552OinUninstaller.exe
C:\Program Files\QdrDrive
C:\Program Files\ystem3~1
C:\WINDOWS\cookies.ini
C:\WINDOWS\icroso~1.net
C:\WINDOWS\icroso~1.net\?icrosoft.NET\
C:\WINDOWS\system32\aslnlept.ini
C:\WINDOWS\system32\bhhxlvcw.ini
C:\WINDOWS\system32\bndqnaws.dll
C:\WINDOWS\system32\clhshcnq.ini
C:\WINDOWS\system32\daniaaxx.dll
C:\WINDOWS\system32\delljuva.ini
C:\WINDOWS\system32\efhkj.ini
C:\WINDOWS\system32\efhkj.ini2
C:\WINDOWS\system32\ehvpibbf.dll
C:\WINDOWS\system32\esgwipyq.ini
C:\WINDOWS\system32\fbbipvhe.ini
C:\WINDOWS\system32\ftihbmdl.dll
C:\WINDOWS\system32\fxmpfxhq.dll
C:\WINDOWS\system32\gofkfwns.ini
C:\WINDOWS\system32\iflgdjkd.ini
C:\WINDOWS\system32\ineefbpf.dll
C:\WINDOWS\system32\iochckwu.ini
C:\WINDOWS\system32\iqfieyiv.dll
C:\WINDOWS\system32\jemxwtdj.dll
C:\WINDOWS\system32\jgmfmnci.ini
C:\WINDOWS\system32\jhnpigbg.dll
C:\WINDOWS\system32\jkhfe.dll
C:\WINDOWS\system32\kefmlfii.ini
C:\WINDOWS\system32\kinkltar.ini
C:\WINDOWS\system32\kwctbitc.ini
C:\WINDOWS\system32\ladvjtgl.ini
C:\WINDOWS\system32\lmwgrdbq.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mlohnqyu.ini
C:\WINDOWS\system32\mowcktys.ini
C:\WINDOWS\system32\mqguyenf.ini
C:\WINDOWS\system32\nisypnjj.ini
C:\WINDOWS\system32\nlaadlbo.dll
C:\WINDOWS\system32\okdusqne.ini
C:\WINDOWS\system32\oxxaqvjk.ini
C:\WINDOWS\system32\oywxwspi.ini
C:\WINDOWS\system32\pttmiwbq.ini
C:\WINDOWS\system32\qbsajbqb.ini
C:\WINDOWS\system32\qiuqjvsx.dll
C:\WINDOWS\system32\rbgasnbi.ini
C:\WINDOWS\system32\ruaflnxg.ini
C:\WINDOWS\system32\twbtneyl.ini
C:\WINDOWS\system32\ugpgmbnk.ini
C:\WINDOWS\system32\ujyteqng.dll
C:\WINDOWS\system32\uqsiyuhd.ini
C:\WINDOWS\system32\uvlhvisv.ini
C:\WINDOWS\system32\uylgdxye.ini
C:\WINDOWS\system32\viyeifqi.ini
C:\WINDOWS\system32\wcvlxhhb.dll
C:\WINDOWS\system32\xiwixniu.dll
C:\WINDOWS\system32\xkhdlopk.dll
.
((((((((((((((((((((((((( Files Created from 2008-01-28 to 2008-02-29 )))))))))))))))))))))))))))))))
.
2008-02-26 19:51 . 2008-02-26 19:51 d——– C:\Documents and Settings\All Users\Application Data\WinZip
2008-02-25 20:54 . 2008-02-25 20:54 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-02-25 20:54 . 2008-02-25 20:54 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-20 16:36 . 2008-02-20 16:36 d——– C:\Program Files\Trend Micro
2008-02-20 10:48 . 2008-02-20 11:33 d——– C:\Program Files\Windows Defender
2008-02-15 11:42 . 2008-02-19 20:13 6,112 –a—— C:\WINDOWS\BM333f20f1.xml
2008-02-15 11:42 . 2008-02-20 11:33 22 –a—— C:\WINDOWS\pskt.ini
2008-01-29 21:52 . 2008-02-20 12:39 d——– C:\Program Files\Symantec AntiVirus
2008-01-29 21:52 . 2008-01-29 21:52 d——– C:\Program Files\Symantec
2008-01-29 21:52 . 2008-01-29 21:52 110,952 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-01-29 21:52 . 2008-01-29 21:52 48,768 –a—— C:\WINDOWS\system32\S32EVNT1.DLL
2008-01-29 21:52 . 2008-01-29 21:52 8,014 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-01-29 21:52 . 2008-01-29 21:52 805 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-01-29 21:41 . 2008-01-29 21:44 d——– C:\WINDOWS\SxsCaPendDel
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-20 17:39 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-02-20 17:19 ——— d—–w C:\Program Files\Java
2008-02-15 17:22 ——— d—–w C:\Program Files\Palm
2008-01-30 21:35 ——— d—–w C:\Program Files\TagRename
2008-01-27 02:26 ——— d—–w C:\Program Files\QuickTime
2008-01-27 02:26 ——— d—–w C:\Program Files\Microsoft ActiveSync
2008-01-27 02:26 ——— d—–w C:\Program Files\Linksys EasyLink Advisor
2008-01-27 02:26 ——— d—–w C:\Program Files\iTunes
2008-01-24 16:19 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-24 16:19 ——— d—–w C:\Program Files\William O'Neil + Co. Inc
2008-01-24 16:19 ——— d—–w C:\Documents and Settings\mom\Application Data\InstallShield
2008-01-10 14:52 ——— d—–w C:\Program Files\Windows Media Connect 2
2008-01-04 01:33 ——— d—–w C:\Documents and Settings\mom\Application Data\Arcsoft
2008-01-04 00:47 16,694 —-a-w C:\WINDOWS\system32\drivers\PalmUSBD.sys
2007-12-30 13:58 ——— d—–w C:\Program Files\MSN Games
2006-01-29 01:15 146,364 –sh–r C:\WINDOWS\MsxwCtrl.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"winNT updatc"="wupgrd.exe" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [ ]
"BootSkin Startup Jobs"="C:\Program Files\Stardock\WinCustomize\BootSkin\BootSkin.exe" [ ]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [ ]
"pdfFactory Pro Dispatcher v2"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe" [ ]
"DeadAIM"="C:\Program Files\AIM\\DeadAIM.ocm" [2004-02-28 12:12 144896]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" []
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\Program Files\Google\Gmail Notifier\gnotify.exe" [ ]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [ ]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [ ]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [ ]
"vptray"="C:\PROGRA~1\SYMANT~1\\vptray.exe" [ ]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"winNT updatc"="wupgrd.exe" []
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HOTSYNCSHORTCUTNAME.lnk - C:\Program Files\Palm\Hotsync.exe [2004-06-09 14:27:34 471040]
hpoddt01.exe.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-04-06 00:06:58 28672]
officejet 6100.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe [2003-04-05 23:37:38 147456]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2008-02-08 11:10:00 394856]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="LogonUI.EXE"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
R0 si3112r;Silicon Image SiI 3112 SATARaid Controller;C:\WINDOWS\system32\drivers\si3112r.sys [2003-05-08 22:55]
R0 SiWinAcc;SiWinAcc;C:\WINDOWS\system32\drivers\SiWinAcc.sys [2003-02-11 19:37]
S3 LCcfltr;Logitech USB Filter Driver;C:\WINDOWS\system32\drivers\lccfltr.sys [2002-07-09 04:50]
S3 USBMON;USB Monitor Device Driver;C:\WINDOWS\system32\Drivers\usbmon.sys [2002-06-23 23:00]
S3 z520bus;Sony Ericsson 520 driver (WDM);C:\WINDOWS\system32\DRIVERS\z520bus.sys [2005-07-26 11:13]
S3 z520mdfl;Sony Ericsson 520 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\z520mdfl.sys [2005-07-26 11:15]
S3 z520mdm;Sony Ericsson 520 USB WMC Modem Drivers;C:\WINDOWS\system32\DRIVERS\z520mdm.sys [2005-07-26 11:15]
S3 z520mgmt;Sony Ericsson 520 USB WMC Device Management Drivers;C:\WINDOWS\system32\DRIVERS\z520mgmt.sys [2005-07-26 11:16]
S3 z520obex;Sony Ericsson 520 USB WMC OBEX Interface Drivers;C:\WINDOWS\system32\DRIVERS\z520obex.sys [2005-07-26 11:18]
.
Contents of the 'Scheduled Tasks' folder
"2007-07-02 01:26:11 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp officejet 6100 series#1153076945.job"
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe:-I
"2008-02-29 00:47:30 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-28 19:48:55
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINDOWS\system32\HPZipm12.exe
.
**************************************************************************
.
Completion time: 2008-02-28 19:50:46 - machine was rebooted [mom]
ComboFix-quarantined-files.txt 2008-02-29 00:50:43
.
2008-02-27 11:32:55 — E O F —