This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Hijack this log

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:37:19 PM, on 7/3/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Lavasoft\Ad-Aware\Ad-Watch.exe
C:\Program Files\Mozilla Firefox 3\firefox.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?rs=1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll (file missing)
O3 - Toolbar: nqgpedlr - {08E11E95-E8E4-43DD-B762-43F2159C8759} - C:\WINDOWS\nqgpedlr.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\Ad-Watch.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [b4d9706c] rundll32.exe "C:\WINDOWS\system32\crouhedf.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo…toUploader5.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1209676308175
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

–
End of file - 6222 bytes
Take a trip to this webpage for download links and instructions for running Combofix by sUBs: http://www.bleepingcomputer.com/combofix/how-to-use-combofix
  • Please Note: This tool may require the PC to be rebooted so close any programs you have open before you start.
  • When CF has finished, it will produce a log C:\ComboFix.txt - copy and paste it into your next reply.
  • Post a fresh HJT log as well.
  • Let me know how the PC is behaving.
Also, run HJT and click on Open the Misc Tools section.
  • Click Open Uninstall Manager…
  • Click Save list… and save it to your Desktop.
  • Copy and paste the file uninstall_list.txt into your next reply.
Well, do I HAVE to use combofix? I really don't want that recovery thing, and I really feel like it's going to mess something up. When I start using it, Avast goes nuts(mlJApQkh.dll)]! Also, when I press Save list, it just closes out and nothing happens… PLEASE HELP! I ran Ccleaner, and it cleared out like 70MB of stuff…

I really don't want that recovery thing, and I really feel like it's going to mess something up.

If you don't want to install the Recovery Console, you can skip that step. It offers an extra option should things get serious with this malware infection or a future one, but it's your PC and you can install what you want.
CF will deal with the malware just the same, whether the console is installed or not.

When I start using it, Avast goes nuts(mlJApQkh.dll)]!

Avast is identifying ComboFix as malicious, but it isn't and you should tell Avast to let it run. I will mention that Avast didn't stop this slime setting up home on your PC in the first place, so it can't be relied upon 100%.

Also, when I press Save list, it just closes out and nothing happens.

The reason that you can't save the uninstall list is because the infection is blocking the normal working of HJT. If you run CF first, then you should be able to create and save the list.
This is my Combofix log below. My computer has been running decently lately, but not as good as it used to. Below that is my uninstall list. Also, it seemed to have deleted a lot of files. Is this okay?

ComboFix 08-07-04.2 - SKUNKARIFIC CUSTOMER 2008-07-05 0:13:38.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.361 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\abfhsang.ini
C:\WINDOWS\system32\cxxlvcar.dll
C:\WINDOWS\system32\fdehuorc.ini
C:\WINDOWS\system32\fwwuisqu.dll
C:\WINDOWS\system32\gagjwrte.ini
C:\WINDOWS\system32\gnaxiggn.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\nggixang.dll
C:\WINDOWS\system32\racvlxxc.ini
C:\WINDOWS\system32\rwfmswyx.ini
C:\WINDOWS\system32\ssqQheET.dll
C:\WINDOWS\system32\TEehQqss.ini
C:\WINDOWS\system32\TEehQqss.ini2
C:\WINDOWS\system32\uqsiuwwf.ini

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_CLBDRIVER


((((((((((((((((((((((((( Files Created from 2008-06-05 to 2008-07-05 )))))))))))))))))))))))))))))))
.

2008-07-05 00:17 . 2008-07-05 00:19 294 —hs—- C:\WINDOWS\system32\abfhsang.ini
2008-07-04 17:10 . 2008-07-04 17:10 89,088 ——— C:\WINDOWS\system32\gnashfba.dll
2008-07-04 13:15 . 2008-07-04 13:15 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-07-04 13:15 . 2008-07-04 13:15 1,409 –a—— C:\WINDOWS\QTFont.for
2008-07-03 16:22 . 2008-07-03 16:22

d——– C:\Program Files\CCleaner
2008-07-03 15:36 . 2008-07-03 15:36 d——– C:\Program Files\Trend Micro
2008-07-03 15:25 . 2007-08-13 18:52 66,048 –a—— C:\WINDOWS\ieResetIcons.exe
2008-07-01 13:48 . 2004-08-04 08:00 4,224 –a—— C:\WINDOWS\system32\beep.sys
2008-07-01 11:58 . 2000-05-22 00:00 608,448 –a—— C:\WINDOWS\system32\Comctl32.ocx
2008-07-01 11:58 . 2003-05-14 21:07 389,120 –a—— C:\WINDOWS\system32\actskn43.ocx
2008-07-01 11:04 . 2008-07-01 11:04 74 –a—— C:\WINDOWS\VideoToAudioConverter.ini
2008-07-01 11:03 . 2008-07-01 11:03 3,082 –a—— C:\WINDOWS\system32\affv11300p4now.sys
2008-07-01 11:03 . 2008-07-01 11:05 5 –a—— C:\WINDOWS\system32\SySVid.dat
2008-07-01 09:33 . 2008-07-01 09:34 d——– C:\Program Files\Winamp
2008-07-01 09:33 . 2008-07-01 09:37 d——– C:\Documents and Settings\SKUNKARIFIC CUSTOMER\Application Data\Winamp
2008-07-01 09:33 . 2007-03-07 19:51 129,784 –a—— C:\WINDOWS\system32\pxafs.dll
2008-06-30 19:48 . 2008-06-30 19:48 d–h—– C:\WINDOWS\$hf_mig$
2008-06-29 12:29 . 2008-06-29 12:29 d——– C:\Documents and Settings\SKUNKARIFIC CUSTOMER\Application Data\Image Zone Express
2008-06-28 11:34 . 2008-06-28 11:34 d——– C:\Program Files\YouTube Downloader
2008-06-27 14:48 . 2008-07-04 14:04 d——– C:\Program Files\Trillian2
2008-06-25 14:57 . 2004-10-12 14:40 2,255,360 –a—— C:\WINDOWS\system32\libavcodec.dll
2008-06-25 14:57 . 2004-10-12 14:46 1,761,280 –a—— C:\WINDOWS\system32\ffdshow.ax
2008-06-25 14:57 . 2004-10-05 16:16 395,776 –a—— C:\WINDOWS\system32\libmplayer.dll
2008-06-25 14:57 . 2004-10-12 14:42 262,144 –a—— C:\WINDOWS\system32\TomsMoComp_ff.dll
2008-06-25 14:57 . 2003-04-03 00:17 172,032 –a—— C:\WINDOWS\system32\ac3filter.ax
2008-06-25 14:57 . 2004-10-04 01:50 112,640 –a—— C:\WINDOWS\system32\libmpeg2_ff.dll
2008-06-21 15:03 . 2008-06-21 15:04 d——– C:\Documents and Settings\SKUNKARIFIC CUSTOMER\Application Data\HP
2008-06-21 15:03 . 2008-06-21 15:03 d——– C:\Documents and Settings\All Users\Application Data\HP
2008-06-21 15:01 . 2008-06-21 15:02 d——– C:\Program Files\Common Files\HP
2008-06-21 14:59 . 2008-06-21 14:59 d——– C:\Program Files\Hewlett-Packard
2008-06-21 14:45 . 2008-05-22 20:08 110,415 ——— C:\WINDOWS\hpoins11.dat.temp
2008-06-21 14:45 . 2006-05-05 23:10 6,947 ——— C:\WINDOWS\hpomdl11.dat.temp
2008-06-21 14:37 . 2006-05-05 19:17 11,634 –a—— C:\WINDOWS\hpomdl11.dat
2008-06-17 21:53 . 2008-06-18 06:13 d——– C:\Temp
2008-06-17 15:08 . 2008-07-05 00:09 d——– C:\Program Files\Mozilla Firefox 3
2008-06-10 16:12 . 2008-06-10 16:27 d——– C:\Documents and Settings\SKUNKARIFIC CUSTOMER\Application Data\Azureus
2008-06-10 16:12 . 2008-06-10 16:12 d——– C:\Documents and Settings\All Users\Application Data\Azureus
2008-06-10 12:53 . 2008-06-10 12:53 d——– C:\Program Files\Lavasoft
2008-06-10 12:52 . 2008-06-10 12:52 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-06-10 06:23 . 2008-07-01 11:39 d——– C:\Documents and Settings\SKUNKARIFIC CUSTOMER\Application Data\uTorrent
2008-06-09 17:01 . 2008-06-09 17:02 664 –a—— C:\WINDOWS\system32\d3d9caps.dat
2008-06-09 06:15 . 2008-06-09 06:17 d——– C:\Program Files\Adobe PhotoShop CS3
2008-06-08 21:03 . 2008-06-08 21:03 d——– C:\Documents and Settings\SKUNKARIFIC CUSTOMER\Application Data\Publish Providers
2008-06-08 21:01 . 2008-06-08 21:01 d——– C:\Documents and Settings\SKUNKARIFIC CUSTOMER\Application Data\Sony
2008-06-08 17:48 . 2008-06-08 20:14 d——– C:\Program Files\MSBuild
2008-06-08 17:43 . 2008-06-08 17:43 d——– C:\WINDOWS\system32\XPSViewer
2008-06-08 17:42 . 2008-06-08 17:42 d——– C:\Program Files\Reference Assemblies
2008-06-08 17:42 . 2006-09-06 17:43 22,752 –a—— C:\WINDOWS\system32\spupdsvc.exe
2008-06-08 17:42 . 2006-06-29 13:07 14,048 –a—— C:\WINDOWS\system32\spmsg2.dll
2008-06-08 17:24 . 2008-06-08 17:24 d——– C:\Documents and Settings\SKUNKARIFIC CUSTOMER\Application Data\Sony Setup
2008-06-08 16:45 . 2008-06-08 16:45 d——– C:\WINDOWS\system32\QuickTime
2008-06-08 16:45 . 2008-06-08 16:45 d——– C:\Program Files\TechSmith
2008-06-08 16:45 . 2008-06-08 16:45 d——– C:\Program Files\Common Files\TechSmith Shared
2008-06-08 16:45 . 2008-06-08 16:45 d——– C:\Documents and Settings\All Users\Application Data\TechSmith
2008-06-08 16:45 . 2008-03-12 02:37 107,864 –a—— C:\WINDOWS\system32\tsccvid.dll
2008-06-08 14:23 . 2008-06-08 14:35 d——– C:\Documents and Settings\SKUNKARIFIC CUSTOMER\dwhelper
2008-06-07 19:04 . 2008-06-08 11:26 d——– C:\Program Files\RealArcade
2008-06-06 19:49 . 2004-11-28 21:25 219,136 –a—— C:\WINDOWS\system32\uxtheme.dll
2008-06-06 19:23 . 2008-06-06 19:23 0 –a—— C:\nsl82B.tmp
2008-06-06 19:21 . 2008-06-06 19:23 5,859 –a—— C:\WINDOWS\BricoPackFoldersDelete.cmd
2008-06-06 19:20 . 2008-06-06 19:20 d——– C:\WINDOWS\BricoPacks
2008-06-06 16:04 . 2008-06-06 16:19 d——– C:\Program Files\Fraps
2008-06-06 11:12 . 2008-07-04 19:57 d——– C:\Program Files\NoLimits Coasters v1.6

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-04 04:40 ——— d—–w C:\Documents and Settings\SKUNKARIFIC CUSTOMER\Application Data\OpenOffice.org2
2008-07-03 21:12 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-03 21:09 ——— d—–w C:\Program Files\SpywareBlaster
2008-06-29 02:03 ——— d—–w C:\Program Files\Orbiter 2006
2008-06-27 18:57 ——— d—–w C:\Program Files\Mozilla Thunderbird
2008-06-27 18:30 ——— d—–w C:\Program Files\Trillian
2008-06-21 19:02 ——— d—–w C:\Program Files\HP
2008-06-18 01:52 ——— d—–w C:\Program Files\Infogrames Interactive
2008-06-10 16:53 ——— d—–w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-09 10:32 ——— d—–w C:\Program Files\Common Files\Adobe
2008-06-08 20:34 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-05-31 17:49 ——— d—–w C:\Documents and Settings\SKUNKARIFIC CUSTOMER\Application Data\Talkback
2008-05-23 10:39 ——— d—–w C:\Program Files\Google
2008-05-23 00:08 ——— d—–w C:\Program Files\Common Files\Hewlett-Packard
2008-05-19 19:35 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-05-19 01:38 ——— d—–w C:\Documents and Settings\SKUNKARIFIC CUSTOMER\Application Data\Ahead
2008-05-17 21:35 ——— d—–w C:\Documents and Settings\SKUNKARIFIC CUSTOMER\Application Data\Apple Computer
2008-05-17 20:04 ——— d—–w C:\Documents and Settings\All Users\Application Data\Trymedia
2008-05-17 13:14 ——— d—–w C:\Program Files\Kodak
2008-05-17 13:14 ——— d—–w C:\Program Files\Common Files\Kodak
2008-05-17 13:08 ——— d—–w C:\Documents and Settings\All Users\Application Data\Kodak
2008-05-16 15:58 12,632 —-a-w C:\WINDOWS\system32\lsdelete.exe
2008-05-06 20:29 ——— d—–w C:\Program Files\iTunes
2008-05-06 20:29 ——— d—–w C:\Program Files\iPod
2008-05-06 20:28 ——— d—–w C:\Program Files\QuickTime
2008-05-06 20:28 ——— d—–w C:\Program Files\Bonjour
2008-05-06 20:26 ——— d—–w C:\Program Files\Apple Software Update
2008-05-06 20:26 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple
2008-05-05 17:06 ——— d—–w C:\Program Files\Common Files\Ahead
2008-05-05 17:05 ——— d—–w C:\Program Files\Nero
2008-05-05 17:05 ——— d—–w C:\Documents and Settings\All Users\Application Data\Nero
2008-05-05 15:17 ——— d—–w C:\Program Files\Alwil Software
2008-05-05 15:12 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-04-14 11:40 1,296,669 —-a-r C:\WINDOWS\SET3.tmp
2008-04-14 11:34 16,535 —-a-r C:\WINDOWS\SET8.tmp
2008-04-14 11:34 1,088,840 —-a-r C:\WINDOWS\SET4.tmp
2008-04-14 09:55 1,804 —-a-w C:\WINDOWS\system32\Dcache.bin
2008-04-14 09:51 52,736 —-a-w C:\WINDOWS\system32\wzcsapi.dll
2008-04-14 09:51 52,224 —-a-w C:\WINDOWS\system32\dmutil.dll
2008-04-14 09:51 483,840 —-a-w C:\WINDOWS\system32\wzcsvc.dll
2008-04-14 09:51 47,616 —-a-w C:\WINDOWS\system32\iyuv_32.dll
2008-04-14 09:51 47,104 —-a-w C:\WINDOWS\system32\cnbjmon.dll
2008-04-14 09:51 35,328 —-a-w C:\WINDOWS\system32\pid.dll
2008-04-14 09:51 294,912 —-a-w C:\WINDOWS\system32\msh263.drv
2008-04-14 09:51 20,992 —-a-w C:\WINDOWS\system32\hid.dll
2008-04-14 09:51 2,065,792 —-a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-04-14 09:51 16,896 —-a-w C:\WINDOWS\system32\msyuv.dll
2008-04-14 09:51 15,360 —-a-w C:\WINDOWS\system32\pjlmon.dll
2008-04-14 09:46 329,728 —-a-w C:\WINDOWS\system32\netsetup.exe
2008-04-14 09:43 92,424 —-a-w C:\WINDOWS\system32\rdpdd.dll
2008-04-14 09:43 87,176 —-a-w C:\WINDOWS\system32\rdpwsx.dll
2008-04-14 09:43 12,168 —-a-w C:\WINDOWS\system32\tsddd.dll
2008-04-14 09:41 98,304 —-a-w C:\WINDOWS\system32\actxprxy.dll
2008-04-14 09:40 53,279 —-a-w C:\WINDOWS\system32\odbcji32.dll
2008-04-14 09:40 4,126 —-a-w C:\WINDOWS\system32\msdxmlc.dll
2008-04-14 09:40 3,584 —-a-w C:\WINDOWS\system32\msafd.dll
2008-04-14 06:30 103,424 —-a-w C:\WINDOWS\system32\dpcdll.dll
2008-04-14 05:42 74,752 —-a-w C:\WINDOWS\system32\storprop.dll
2008-04-14 05:00 1,845,632 —-a-w C:\WINDOWS\system32\win32k.sys
2008-04-14 04:57 2,188,928 —-a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-04-14 04:15 17,664 —-a-w C:\WINDOWS\system32\watchdog.sys
2008-04-14 04:05 24,064 —-a-w C:\WINDOWS\system32\pidgen.dll
2008-04-14 04:01 7,424 —-a-w C:\WINDOWS\system32\kd1394.dll
2008-04-14 04:00 61,440 —-a-w C:\WINDOWS\system32\msvcrt40.dll
2008-04-14 03:45 76,800 —-a-w C:\WINDOWS\system32\msshavmsg.dll
2008-04-14 03:09 438,784 —-a-w C:\WINDOWS\system32\xpob2res.dll
2008-04-14 03:09 2,897,920 —-a-w C:\WINDOWS\system32\xpsp2res.dll
2008-04-14 03:09 187,392 —-a-w C:\WINDOWS\system32\xpsp1res.dll
2008-04-14 03:08 306,176 —-a-w C:\WINDOWS\system32\slbcsp.dll
2008-04-14 03:08 169,984 —-a-w C:\WINDOWS\system32\sccbase.dll
2008-04-14 03:08 101,888 —-a-w C:\WINDOWS\system32\gpkcsp.dll
2008-04-14 03:07 208,384 —-a-w C:\WINDOWS\system32\rsaenh.dll
2008-04-14 03:07 138,752 —-a-w C:\WINDOWS\system32\dssenh.dll
2008-04-14 02:58 2,940,928 —-a-w C:\WINDOWS\system32\wmploc.dll
2008-04-14 02:57 79,872 —-a-w C:\WINDOWS\system32\msxml6r.dll
2008-04-14 02:56 94,208 —-a-w C:\WINDOWS\system32\odbcint.dll
2008-04-14 02:56 12,288 —-a-w C:\WINDOWS\system32\odbcp32r.dll
2008-04-14 02:56 12,288 —-a-w C:\WINDOWS\system32\mscpx32r.dLL
2008-04-14 02:54 20,480 —-a-w C:\WINDOWS\system32\msorc32r.dll
2008-04-14 02:53 8,192 —-a-w C:\WINDOWS\system32\asferror.dll
2008-04-14 02:53 168,448 —-a-w C:\WINDOWS\system32\wmerror.dll
2008-04-14 02:51 733,696 —-a-w C:\WINDOWS\system32\qedwipes.dll
2008-04-14 02:39 4,096 —-a-w C:\WINDOWS\system32\dsprpres.dll
2008-04-14 02:33 63,488 —-a-w C:\WINDOWS\system32\browselc.dll
2008-04-14 02:33 549,376 —-a-w C:\WINDOWS\system32\shdoclc.dll
2008-04-14 02:24 68,768 —-a-w C:\WINDOWS\system32\mmsystem.dll
2008-04-14 02:24 53,840 —-a-w C:\WINDOWS\system32\dosx.exe
2008-04-14 02:24 5,120 —-a-w C:\WINDOWS\system32\winnls.dll
2008-04-14 02:23 92,224 —-a-w C:\WINDOWS\system32\krnl386.exe
2008-04-14 02:22 3,338 —-a-w C:\WINDOWS\system32\redir.exe
2008-04-14 02:20 42,537 —-a-w C:\WINDOWS\system32\keyboard.sys
2008-04-14 02:19 35,648 —-a-w C:\WINDOWS\system32\ntio411.sys
2008-04-14 02:19 35,424 —-a-w C:\WINDOWS\system32\ntio412.sys
2008-04-14 02:19 34,560 —-a-w C:\WINDOWS\system32\ntio804.sys
2008-04-14 02:19 34,560 —-a-w C:\WINDOWS\system32\ntio404.sys
2008-04-14 02:19 33,840 —-a-w C:\WINDOWS\system32\ntio.sys
2008-04-14 02:18 1,647,616 —-a-w C:\WINDOWS\system32\winbrand.dll
2008-04-14 02:15 216,064 —-a-w C:\WINDOWS\system32\moricons.dll
2008-04-14 01:56 56,832 —-a-w C:\WINDOWS\system32\mshtmler.dll
2008-04-14 01:53 48,128 —-a-w C:\WINDOWS\system32\msprivs.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 05:42 15360]
"AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-03-01 10:37 2321600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 01:41 8523776]
"Ad-Watch"="C:\Program Files\Lavasoft\Ad-Aware\Ad-Watch.exe" [2008-06-10 12:59 2468200]
"b4d9706c"="C:\WINDOWS\system32\gnashfba.dll" [2008-07-04 17:10 89088]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Antiwpa]
2005-09-18 04:32 5376 C:\WINDOWS\system32\antiwpa.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MSUD"= msulvc06.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
–a—— 2006-02-19 02:41 49152 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-03-30 10:36 267048 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
–a—— 2006-12-05 22:55 54832 C:\Program Files\CyberLink\PowerDVD\Language\Language.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2007-03-01 15:57 153136 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
–a—— 2007-12-05 01:41 81920 C:\WINDOWS\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-03-28 23:37 413696 C:\Program Files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
——— 2006-12-06 18:37 69216 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2008-02-22 04:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Orbiter 2006\\orbiter.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"C:\\Program Files\\Trillian\\trillian.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\Program Files\\Trillian2\\trillian.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9420:TCP"= 9420:TCP:Red Swoosh
"5000:UDP"= 5000:UDP:Red Swoosh

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-15 19:20]
R2 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B};C:\Program Files\CyberLink\PowerDVD\000.fcl [2006-11-02 16:51]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-15 19:16]
S3 s3legacy;s3legacy;C:\WINDOWS\system32\DRIVERS\s3legacy.sys [2001-08-17 09:57]

*Newly Created Service* - AD-WATCH_REAL-TIME_SCANNER
.
Contents of the 'Scheduled Tasks' folder
"2008-07-01 23:13:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
- - - - ORPHANS REMOVED - - - -

BHO-{28220052-D9A9-44B1-AB98-EDC594D238B6} - (no file)
BHO-{77D1BC45-F210-462E-86D2-CD0AF43A8585} - C:\WINDOWS\system32\ssqQheET.dll
Toolbar-{08E11E95-E8E4-43DD-B762-43F2159C8759} - (no file)
ShellExecuteHooks-{28220052-D9A9-44B1-AB98-EDC594D238B6} - (no file)
Notify-mlJApQkh - mlJApQkh.dll
MSConfigStartUp-NoteBurner - C:\Program Files\NoteBurner\VTBurnerGUI.exe
MSConfigStartUp-swg - C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-05 00:17:23
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{95808DC4-FA4A-4c74-92FE-5B863F82066B}]
"ImagePath"="\??\C:\Program Files\CyberLink\PowerDVD\000.fcl"
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\explorer.exe
-> C:\WINDOWS\system32\gnashfba.dll
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\verclsid.exe
.
**************************************************************************
.
Completion time: 2008-07-05 0:20:50 - machine was rebooted [SKUNKARIFIC CUSTOMER]
ComboFix-quarantined-files.txt 2008-07-05 04:20:42

Pre-Run: 10,643,570,688 bytes free
Post-Run: 10,553,901,056 bytes free

319


Ad-Aware
Adobe Flash Player ActiveX
Adobe Flash Player Plugin
Adobe Reader 8.1.2
Adobe Shockwave Player
Apple Software Update
avast! Antivirus
Bonjour
Camtasia Studio 5
CardRd81
CCleaner (remove only)
CCScore
CR2
ESSBrwr
ESSCDBK
ESScore
ESSCT
ESSEMAIL
ESSgui
ESShelp
ESSini
ESSPCD
ESSPDock
ESSSONIC
ESSTOOLS
ESSTUTOR
ESSvpaht
ESSvpot
Fraps (remove only)
Google Web Accelerator
HijackThis 2.0.2
HLPIndex
HLPPDOCK
HLPSFO
HP Customer Participation Program 7.0
HP Imaging Device Functions 7.0
HP Photosmart Essential
HP Photosmart, Officejet and Deskjet 7.0.A
HP Software Update
HP Solution Center 7.0
iTunes
Java™ 6 Update 5
Kodak EasyShare software
KSU
Microsoft .NET Framework 2.0
Microsoft .NET Framework 3.0
Microsoft .NET Framework 3.0
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Visual C++ 2005 Redistributable
Mozilla Firefox (2.0.0.14)
Mozilla Firefox (3.0)
Mozilla Thunderbird (2.0.0.14)
MSUlvc06 Lossless Video Codec 0.6.0 (Remove Only)
MSXML 6.0 Parser (KB925673)
Nero 7 Ultra Edition
neroxml
Notifier
NVIDIA Drivers
OCR Software by I.R.I.S 7.0
OfotoXMI
OpenOffice.org 2.4
OTtBP
OTtBPSDK
Picasa 2
PowerDVD
QuickTime
RollerCoaster Tycoon 2
rtgenxr's Building Constructor
Security Update for Windows XP (KB941569)
SFR
SHASTA
SKIN0001
SKINXSDK
SpywareBlaster 4.1
Trillian
VPRINTOL
Winamp
Windows Communication Foundation
Windows Internet Explorer 7
Windows Media Format Runtime
Windows Presentation Foundation
Windows Workflow Foundation
WinRAR archiver
WIRELESS
Xilisoft Video Converter 3


Thanks!

EDIT: sorry. here's my new Hijackthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:03:14 AM, on 7/5/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\Ad-Watch.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trillian2\trillian.exe
C:\Program Files\Alwil Software\Avast4\ashAvast.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?rs=1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {28220052-D9A9-44B1-AB98-EDC594D238B6} - (no file)
O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {77D1BC45-F210-462E-86D2-CD0AF43A8585} - C:\WINDOWS\system32\ssqQheET.dll (file missing)
O3 - Toolbar: (no name) - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - (no file)
O3 - Toolbar: (no name) - {08E11E95-E8E4-43DD-B762-43F2159C8759} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\Ad-Watch.exe
O4 - HKLM\..\Run: [b4d9706c] rundll32.exe "C:\WINDOWS\system32\gnashfba.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo…toUploader5.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1209676308175
O20 - Winlogon Notify: Antiwpa - C:\WINDOWS\SYSTEM32\antiwpa.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

–
End of file - 5771 bytes

Hey, I don't know if you've forgotten about my post, but it's been a few days. If you could take a look, that would be great! Thanks!

It's been just over 24 hours - you originally posted yesterday at 05:26 AM and edited it at 06:06 AM. Please don't use Quote Tags as it just makes the information more difficult for me to read.

ComboFix 08-07-04.2 - SKUNKARIFIC CUSTOMER 2008-07-05 0:13:38.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.361 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\abfhsang.ini
C:\WINDOWS\system32\cxxlvcar.dll
C:\WINDOWS\system32\fdehuorc.ini
C:\WINDOWS\system32\fwwuisqu.dll
C:\WINDOWS\system32\gagjwrte.ini
C:\WINDOWS\system32\gnaxiggn.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\nggixang.dll
C:\WINDOWS\system32\racvlxxc.ini
C:\WINDOWS\system32\rwfmswyx.ini
C:\WINDOWS\system32\ssqQheET.dll
C:\WINDOWS\system32\TEehQqss.ini
C:\WINDOWS\system32\TEehQqss.ini2
C:\WINDOWS\system32\uqsiuwwf.ini

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_CLBDRIVER


((((((((((((((((((((((((( Files Created from 2008-06-05 to 2008-07-05 )))))))))))))))))))))))))))))))
.

2008-07-05 00:17 . 2008-07-05 00:19 294 —hs—- C:\WINDOWS\system32\abfhsang.ini
2008-07-04 17:10 . 2008-07-04 17:10 89,088 ——— C:\WINDOWS\system32\gnashfba.dll
2008-07-04 13:15 . 2008-07-04 13:15 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-07-04 13:15 . 2008-07-04 13:15 1,409 –a—— C:\WINDOWS\QTFont.for
2008-07-03 16:22 . 2008-07-03 16:22 d——– C:\Program Files\CCleaner
2008-07-03 15:36 . 2008-07-03 15:36 d——– C:\Program Files\Trend Micro
2008-07-03 15:25 . 2007-08-13 18:52 66,048 –a—— C:\WINDOWS\ieResetIcons.exe
2008-07-01 13:48 . 2004-08-04 08:00 4,224 –a—— C:\WINDOWS\system32\beep.sys
2008-07-01 11:58 . 2000-05-22 00:00 608,448 –a—— C:\WINDOWS\system32\Comctl32.ocx
2008-07-01 11:58 . 2003-05-14 21:07 389,120 –a—— C:\WINDOWS\system32\actskn43.ocx
2008-07-01 11:04 . 2008-07-01 11:04 74 –a—— C:\WINDOWS\VideoToAudioConverter.ini
2008-07-01 11:03 . 2008-07-01 11:03 3,082 –a—— C:\WINDOWS\system32\affv11300p4now.sys
2008-07-01 11:03 . 2008-07-01 11:05 5 –a—— C:\WINDOWS\system32\SySVid.dat
2008-07-01 09:33 . 2008-07-01 09:34 d——– C:\Program Files\Winamp
2008-07-01 09:33 . 2008-07-01 09:37 d——– C:\Documents and Settings\SKUNKARIFIC CUSTOMER\Application Data\Winamp
2008-07-01 09:33 . 2007-03-07 19:51 129,784 –a—— C:\WINDOWS\system32\pxafs.dll
2008-06-30 19:48 . 2008-06-30 19:48 d–h—– C:\WINDOWS\$hf_mig$
2008-06-29 12:29 . 2008-06-29 12:29 d——– C:\Documents and Settings\SKUNKARIFIC CUSTOMER\Application Data\Image Zone Express
2008-06-28 11:34 . 2008-06-28 11:34 d——– C:\Program Files\YouTube Downloader
2008-06-27 14:48 . 2008-07-04 14:04 d——– C:\Program Files\Trillian2
2008-06-25 14:57 . 2004-10-12 14:40 2,255,360 –a—— C:\WINDOWS\system32\libavcodec.dll
2008-06-25 14:57 . 2004-10-12 14:46 1,761,280 –a—— C:\WINDOWS\system32\ffdshow.ax
2008-06-25 14:57 . 2004-10-05 16:16 395,776 –a—— C:\WINDOWS\system32\libmplayer.dll
2008-06-25 14:57 . 2004-10-12 14:42 262,144 –a—— C:\WINDOWS\system32\TomsMoComp_ff.dll
2008-06-25 14:57 . 2003-04-03 00:17 172,032 –a—— C:\WINDOWS\system32\ac3filter.ax
2008-06-25 14:57 . 2004-10-04 01:50 112,640 –a—— C:\WINDOWS\system32\libmpeg2_ff.dll
2008-06-21 15:03 . 2008-06-21 15:04 d——– C:\Documents and Settings\SKUNKARIFIC CUSTOMER\Application Data\HP
2008-06-21 15:03 . 2008-06-21 15:03 d——– C:\Documents and Settings\All Users\Application Data\HP
2008-06-21 15:01 . 2008-06-21 15:02 d——– C:\Program Files\Common Files\HP
2008-06-21 14:59 . 2008-06-21 14:59 d——– C:\Program Files\Hewlett-Packard
2008-06-21 14:45 . 2008-05-22 20:08 110,415 ——— C:\WINDOWS\hpoins11.dat.temp
2008-06-21 14:45 . 2006-05-05 23:10 6,947 ——— C:\WINDOWS\hpomdl11.dat.temp
2008-06-21 14:37 . 2006-05-05 19:17 11,634 –a—— C:\WINDOWS\hpomdl11.dat
2008-06-17 21:53 . 2008-06-18 06:13 d——– C:\Temp
2008-06-17 15:08 . 2008-07-05 00:09 d——– C:\Program Files\Mozilla Firefox 3
2008-06-10 16:12 . 2008-06-10 16:27 d——– C:\Documents and Settings\SKUNKARIFIC CUSTOMER\Application Data\Azureus
2008-06-10 16:12 . 2008-06-10 16:12 d——– C:\Documents and Settings\All Users\Application Data\Azureus
2008-06-10 12:53 . 2008-06-10 12:53 d——– C:\Program Files\Lavasoft
2008-06-10 12:52 . 2008-06-10 12:52 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-06-10 06:23 . 2008-07-01 11:39 d——– C:\Documents and Settings\SKUNKARIFIC CUSTOMER\Application Data\uTorrent
2008-06-09 17:01 . 2008-06-09 17:02 664 –a—— C:\WINDOWS\system32\d3d9caps.dat
2008-06-09 06:15 . 2008-06-09 06:17 d——– C:\Program Files\Adobe PhotoShop CS3
2008-06-08 21:03 . 2008-06-08 21:03 d——– C:\Documents and Settings\SKUNKARIFIC CUSTOMER\Application Data\Publish Providers
2008-06-08 21:01 . 2008-06-08 21:01 d——– C:\Documents and Settings\SKUNKARIFIC CUSTOMER\Application Data\Sony
2008-06-08 17:48 . 2008-06-08 20:14 d——– C:\Program Files\MSBuild
2008-06-08 17:43 . 2008-06-08 17:43 d——– C:\WINDOWS\system32\XPSViewer
2008-06-08 17:42 . 2008-06-08 17:42 d——– C:\Program Files\Reference Assemblies
2008-06-08 17:42 . 2006-09-06 17:43 22,752 –a—— C:\WINDOWS\system32\spupdsvc.exe
2008-06-08 17:42 . 2006-06-29 13:07 14,048 –a—— C:\WINDOWS\system32\spmsg2.dll
2008-06-08 17:24 . 2008-06-08 17:24 d——– C:\Documents and Settings\SKUNKARIFIC CUSTOMER\Application Data\Sony Setup
2008-06-08 16:45 . 2008-06-08 16:45 d——– C:\WINDOWS\system32\QuickTime
2008-06-08 16:45 . 2008-06-08 16:45 d——– C:\Program Files\TechSmith
2008-06-08 16:45 . 2008-06-08 16:45 d——– C:\Program Files\Common Files\TechSmith Shared
2008-06-08 16:45 . 2008-06-08 16:45 d——– C:\Documents and Settings\All Users\Application Data\TechSmith
2008-06-08 16:45 . 2008-03-12 02:37 107,864 –a—— C:\WINDOWS\system32\tsccvid.dll
2008-06-08 14:23 . 2008-06-08 14:35 d——– C:\Documents and Settings\SKUNKARIFIC CUSTOMER\dwhelper
2008-06-07 19:04 . 2008-06-08 11:26 d——– C:\Program Files\RealArcade
2008-06-06 19:49 . 2004-11-28 21:25 219,136 –a—— C:\WINDOWS\system32\uxtheme.dll
2008-06-06 19:23 . 2008-06-06 19:23 0 –a—— C:\nsl82B.tmp
2008-06-06 19:21 . 2008-06-06 19:23 5,859 –a—— C:\WINDOWS\BricoPackFoldersDelete.cmd
2008-06-06 19:20 . 2008-06-06 19:20 d——– C:\WINDOWS\BricoPacks
2008-06-06 16:04 . 2008-06-06 16:19 d——– C:\Program Files\Fraps
2008-06-06 11:12 . 2008-07-04 19:57 d——– C:\Program Files\NoLimits Coasters v1.6

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-04 04:40 ——— d—–w C:\Documents and Settings\SKUNKARIFIC CUSTOMER\Application Data\OpenOffice.org2
2008-07-03 21:12 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-03 21:09 ——— d—–w C:\Program Files\SpywareBlaster
2008-06-29 02:03 ——— d—–w C:\Program Files\Orbiter 2006
2008-06-27 18:57 ——— d—–w C:\Program Files\Mozilla Thunderbird
2008-06-27 18:30 ——— d—–w C:\Program Files\Trillian
2008-06-21 19:02 ——— d—–w C:\Program Files\HP
2008-06-18 01:52 ——— d—–w C:\Program Files\Infogrames Interactive
2008-06-10 16:53 ——— d—–w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-09 10:32 ——— d—–w C:\Program Files\Common Files\Adobe
2008-06-08 20:34 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-05-31 17:49 ——— d—–w C:\Documents and Settings\SKUNKARIFIC CUSTOMER\Application Data\Talkback
2008-05-23 10:39 ——— d—–w C:\Program Files\Google
2008-05-23 00:08 ——— d—–w C:\Program Files\Common Files\Hewlett-Packard
2008-05-19 19:35 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-05-19 01:38 ——— d—–w C:\Documents and Settings\SKUNKARIFIC CUSTOMER\Application Data\Ahead
2008-05-17 21:35 ——— d—–w C:\Documents and Settings\SKUNKARIFIC CUSTOMER\Application Data\Apple Computer
2008-05-17 20:04 ——— d—–w C:\Documents and Settings\All Users\Application Data\Trymedia
2008-05-17 13:14 ——— d—–w C:\Program Files\Kodak
2008-05-17 13:14 ——— d—–w C:\Program Files\Common Files\Kodak
2008-05-17 13:08 ——— d—–w C:\Documents and Settings\All Users\Application Data\Kodak
2008-05-16 15:58 12,632 —-a-w C:\WINDOWS\system32\lsdelete.exe
2008-05-06 20:29 ——— d—–w C:\Program Files\iTunes
2008-05-06 20:29 ——— d—–w C:\Program Files\iPod
2008-05-06 20:28 ——— d—–w C:\Program Files\QuickTime
2008-05-06 20:28 ——— d—–w C:\Program Files\Bonjour
2008-05-06 20:26 ——— d—–w C:\Program Files\Apple Software Update
2008-05-06 20:26 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple
2008-05-05 17:06 ——— d—–w C:\Program Files\Common Files\Ahead
2008-05-05 17:05 ——— d—–w C:\Program Files\Nero
2008-05-05 17:05 ——— d—–w C:\Documents and Settings\All Users\Application Data\Nero
2008-05-05 15:17 ——— d—–w C:\Program Files\Alwil Software
2008-05-05 15:12 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-04-14 11:40 1,296,669 —-a-r C:\WINDOWS\SET3.tmp
2008-04-14 11:34 16,535 —-a-r C:\WINDOWS\SET8.tmp
2008-04-14 11:34 1,088,840 —-a-r C:\WINDOWS\SET4.tmp
2008-04-14 09:55 1,804 —-a-w C:\WINDOWS\system32\Dcache.bin
2008-04-14 09:51 52,736 —-a-w C:\WINDOWS\system32\wzcsapi.dll
2008-04-14 09:51 52,224 —-a-w C:\WINDOWS\system32\dmutil.dll
2008-04-14 09:51 483,840 —-a-w C:\WINDOWS\system32\wzcsvc.dll
2008-04-14 09:51 47,616 —-a-w C:\WINDOWS\system32\iyuv_32.dll
2008-04-14 09:51 47,104 —-a-w C:\WINDOWS\system32\cnbjmon.dll
2008-04-14 09:51 35,328 —-a-w C:\WINDOWS\system32\pid.dll
2008-04-14 09:51 294,912 —-a-w C:\WINDOWS\system32\msh263.drv
2008-04-14 09:51 20,992 —-a-w C:\WINDOWS\system32\hid.dll
2008-04-14 09:51 2,065,792 —-a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-04-14 09:51 16,896 —-a-w C:\WINDOWS\system32\msyuv.dll
2008-04-14 09:51 15,360 —-a-w C:\WINDOWS\system32\pjlmon.dll
2008-04-14 09:46 329,728 —-a-w C:\WINDOWS\system32\netsetup.exe
2008-04-14 09:43 92,424 —-a-w C:\WINDOWS\system32\rdpdd.dll
2008-04-14 09:43 87,176 —-a-w C:\WINDOWS\system32\rdpwsx.dll
2008-04-14 09:43 12,168 —-a-w C:\WINDOWS\system32\tsddd.dll
2008-04-14 09:41 98,304 —-a-w C:\WINDOWS\system32\actxprxy.dll
2008-04-14 09:40 53,279 —-a-w C:\WINDOWS\system32\odbcji32.dll
2008-04-14 09:40 4,126 —-a-w C:\WINDOWS\system32\msdxmlc.dll
2008-04-14 09:40 3,584 —-a-w C:\WINDOWS\system32\msafd.dll
2008-04-14 06:30 103,424 —-a-w C:\WINDOWS\system32\dpcdll.dll
2008-04-14 05:42 74,752 —-a-w C:\WINDOWS\system32\storprop.dll
2008-04-14 05:00 1,845,632 —-a-w C:\WINDOWS\system32\win32k.sys
2008-04-14 04:57 2,188,928 —-a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-04-14 04:15 17,664 —-a-w C:\WINDOWS\system32\watchdog.sys
2008-04-14 04:05 24,064 —-a-w C:\WINDOWS\system32\pidgen.dll
2008-04-14 04:01 7,424 —-a-w C:\WINDOWS\system32\kd1394.dll
2008-04-14 04:00 61,440 —-a-w C:\WINDOWS\system32\msvcrt40.dll
2008-04-14 03:45 76,800 —-a-w C:\WINDOWS\system32\msshavmsg.dll
2008-04-14 03:09 438,784 —-a-w C:\WINDOWS\system32\xpob2res.dll
2008-04-14 03:09 2,897,920 —-a-w C:\WINDOWS\system32\xpsp2res.dll
2008-04-14 03:09 187,392 —-a-w C:\WINDOWS\system32\xpsp1res.dll
2008-04-14 03:08 306,176 —-a-w C:\WINDOWS\system32\slbcsp.dll
2008-04-14 03:08 169,984 —-a-w C:\WINDOWS\system32\sccbase.dll
2008-04-14 03:08 101,888 —-a-w C:\WINDOWS\system32\gpkcsp.dll
2008-04-14 03:07 208,384 —-a-w C:\WINDOWS\system32\rsaenh.dll
2008-04-14 03:07 138,752 —-a-w C:\WINDOWS\system32\dssenh.dll
2008-04-14 02:58 2,940,928 —-a-w C:\WINDOWS\system32\wmploc.dll
2008-04-14 02:57 79,872 —-a-w C:\WINDOWS\system32\msxml6r.dll
2008-04-14 02:56 94,208 —-a-w C:\WINDOWS\system32\odbcint.dll
2008-04-14 02:56 12,288 —-a-w C:\WINDOWS\system32\odbcp32r.dll
2008-04-14 02:56 12,288 —-a-w C:\WINDOWS\system32\mscpx32r.dLL
2008-04-14 02:54 20,480 —-a-w C:\WINDOWS\system32\msorc32r.dll
2008-04-14 02:53 8,192 —-a-w C:\WINDOWS\system32\asferror.dll
2008-04-14 02:53 168,448 —-a-w C:\WINDOWS\system32\wmerror.dll
2008-04-14 02:51 733,696 —-a-w C:\WINDOWS\system32\qedwipes.dll
2008-04-14 02:39 4,096 —-a-w C:\WINDOWS\system32\dsprpres.dll
2008-04-14 02:33 63,488 —-a-w C:\WINDOWS\system32\browselc.dll
2008-04-14 02:33 549,376 —-a-w C:\WINDOWS\system32\shdoclc.dll
2008-04-14 02:24 68,768 —-a-w C:\WINDOWS\system32\mmsystem.dll
2008-04-14 02:24 53,840 —-a-w C:\WINDOWS\system32\dosx.exe
2008-04-14 02:24 5,120 —-a-w C:\WINDOWS\system32\winnls.dll
2008-04-14 02:23 92,224 —-a-w C:\WINDOWS\system32\krnl386.exe
2008-04-14 02:22 3,338 —-a-w C:\WINDOWS\system32\redir.exe
2008-04-14 02:20 42,537 —-a-w C:\WINDOWS\system32\keyboard.sys
2008-04-14 02:19 35,648 —-a-w C:\WINDOWS\system32\ntio411.sys
2008-04-14 02:19 35,424 —-a-w C:\WINDOWS\system32\ntio412.sys
2008-04-14 02:19 34,560 —-a-w C:\WINDOWS\system32\ntio804.sys
2008-04-14 02:19 34,560 —-a-w C:\WINDOWS\system32\ntio404.sys
2008-04-14 02:19 33,840 —-a-w C:\WINDOWS\system32\ntio.sys
2008-04-14 02:18 1,647,616 —-a-w C:\WINDOWS\system32\winbrand.dll
2008-04-14 02:15 216,064 —-a-w C:\WINDOWS\system32\moricons.dll
2008-04-14 01:56 56,832 —-a-w C:\WINDOWS\system32\mshtmler.dll
2008-04-14 01:53 48,128 —-a-w C:\WINDOWS\system32\msprivs.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 05:42 15360]
"AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-03-01 10:37 2321600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 01:41 8523776]
"Ad-Watch"="C:\Program Files\Lavasoft\Ad-Aware\Ad-Watch.exe" [2008-06-10 12:59 2468200]
"b4d9706c"="C:\WINDOWS\system32\gnashfba.dll" [2008-07-04 17:10 89088]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Antiwpa]
2005-09-18 04:32 5376 C:\WINDOWS\system32\antiwpa.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MSUD"= msulvc06.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
–a—— 2006-02-19 02:41 49152 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-03-30 10:36 267048 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
–a—— 2006-12-05 22:55 54832 C:\Program Files\CyberLink\PowerDVD\Language\Language.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2007-03-01 15:57 153136 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
–a—— 2007-12-05 01:41 81920 C:\WINDOWS\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-03-28 23:37 413696 C:\Program Files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
——— 2006-12-06 18:37 69216 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2008-02-22 04:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Orbiter 2006\\orbiter.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"C:\\Program Files\\Trillian\\trillian.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\Program Files\\Trillian2\\trillian.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9420:TCP"= 9420:TCP:Red Swoosh
"5000:UDP"= 5000:UDP:Red Swoosh

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-15 19:20]
R2 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B};C:\Program Files\CyberLink\PowerDVD\000.fcl [2006-11-02 16:51]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-15 19:16]
S3 s3legacy;s3legacy;C:\WINDOWS\system32\DRIVERS\s3legacy.sys [2001-08-17 09:57]

*Newly Created Service* - AD-WATCH_REAL-TIME_SCANNER
.
Contents of the 'Scheduled Tasks' folder
"2008-07-01 23:13:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
- - - - ORPHANS REMOVED - - - -

BHO-{28220052-D9A9-44B1-AB98-EDC594D238B6} - (no file)
BHO-{77D1BC45-F210-462E-86D2-CD0AF43A8585} - C:\WINDOWS\system32\ssqQheET.dll
Toolbar-{08E11E95-E8E4-43DD-B762-43F2159C8759} - (no file)
ShellExecuteHooks-{28220052-D9A9-44B1-AB98-EDC594D238B6} - (no file)
Notify-mlJApQkh - mlJApQkh.dll
MSConfigStartUp-NoteBurner - C:\Program Files\NoteBurner\VTBurnerGUI.exe
MSConfigStartUp-swg - C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-05 00:17:23
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{95808DC4-FA4A-4c74-92FE-5B863F82066B}]
"ImagePath"="\??\C:\Program Files\CyberLink\PowerDVD\000.fcl"
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\explorer.exe
-> C:\WINDOWS\system32\gnashfba.dll
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\verclsid.exe
.
**************************************************************************
.
Completion time: 2008-07-05 0:20:50 - machine was rebooted [SKUNKARIFIC CUSTOMER]
ComboFix-quarantined-files.txt 2008-07-05 04:20:42

Pre-Run: 10,643,570,688 bytes free
Post-Run: 10,553,901,056 bytes free

319


Ad-Aware
Adobe Flash Player ActiveX
Adobe Flash Player Plugin
Adobe Reader 8.1.2
Adobe Shockwave Player
Apple Software Update
avast! Antivirus
Bonjour
Camtasia Studio 5
CardRd81
CCleaner (remove only)
CCScore
CR2
ESSBrwr
ESSCDBK
ESScore
ESSCT
ESSEMAIL
ESSgui
ESShelp
ESSini
ESSPCD
ESSPDock
ESSSONIC
ESSTOOLS
ESSTUTOR
ESSvpaht
ESSvpot
Fraps (remove only)
Google Web Accelerator
HijackThis 2.0.2
HLPIndex
HLPPDOCK
HLPSFO
HP Customer Participation Program 7.0
HP Imaging Device Functions 7.0
HP Photosmart Essential
HP Photosmart, Officejet and Deskjet 7.0.A
HP Software Update
HP Solution Center 7.0
iTunes
Java™ 6 Update 5
Kodak EasyShare software
KSU
Microsoft .NET Framework 2.0
Microsoft .NET Framework 3.0
Microsoft .NET Framework 3.0
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Visual C++ 2005 Redistributable
Mozilla Firefox (2.0.0.14)
Mozilla Firefox (3.0)
Mozilla Thunderbird (2.0.0.14)
MSUlvc06 Lossless Video Codec 0.6.0 (Remove Only)
MSXML 6.0 Parser (KB925673)
Nero 7 Ultra Edition
neroxml
Notifier
NVIDIA Drivers
OCR Software by I.R.I.S 7.0
OfotoXMI
OpenOffice.org 2.4
OTtBP
OTtBPSDK
Picasa 2
PowerDVD
QuickTime
RollerCoaster Tycoon 2
rtgenxr's Building Constructor
Security Update for Windows XP (KB941569)
SFR
SHASTA
SKIN0001
SKINXSDK
SpywareBlaster 4.1
Trillian
VPRINTOL
Winamp
Windows Communication Foundation
Windows Internet Explorer 7
Windows Media Format Runtime
Windows Presentation Foundation
Windows Workflow Foundation
WinRAR archiver
WIRELESS
Xilisoft Video Converter 3


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:03:14 AM, on 7/5/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\Ad-Watch.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trillian2\trillian.exe
C:\Program Files\Alwil Software\Avast4\ashAvast.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?rs=1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {28220052-D9A9-44B1-AB98-EDC594D238B6} - (no file)
O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {77D1BC45-F210-462E-86D2-CD0AF43A8585} - C:\WINDOWS\system32\ssqQheET.dll (file missing)
O3 - Toolbar: (no name) - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - (no file)
O3 - Toolbar: (no name) - {08E11E95-E8E4-43DD-B762-43F2159C8759} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\Ad-Watch.exe
O4 - HKLM\..\Run: [b4d9706c] rundll32.exe "C:\WINDOWS\system32\gnashfba.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo…toUploader5.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1209676308175
O20 - Winlogon Notify: Antiwpa - C:\WINDOWS\SYSTEM32\antiwpa.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

–
End of file - 5771 bytes
Your HJT log has an interesting entry: O20 - Winlogon Notify: Antiwpa - C:\WINDOWS\SYSTEM32\antiwpa.dll This is apparently "An illegal software crack used to bypass copy protection for Windows."
This forum doesn't offer support to those who illegally use software and as I can see no reason why you would have this entry unless you didn't have a legitimate copy of Windows, I have to assume that this is the case. Unless you obtain a legitimate copy, you can't receive help here i'm afraid.
Well I can honestly say that I DO have a real copy of windows. If there's ANY way I can prove it, PLEASE TELL!!!! I'll delete the file, ANYTHING, because I honestly don't know how it got there. If you need me to delete it, I will. The last thing I want is a lawsuit against Microsoft! Please help me!
Download this file.
Double click it to run it and click Continue.
Once it has finished, it will display a report.
Click Copy and post the contents into your next reply.
"Diagnostic Report (1.7.0095.0): —————————————– WGA Data–> Validation Status: Genuine Validation Code: 0 Online Validation Code: N/A Cached Validation Code: N/A Windows Product Key: *****-*****-4DCCM-FRGYT-PMPF3 Windows Product Key Hash: AXkI1GO3Rv0oAzo8QJF6Jf7iPYA= Windows Product ID: 76477-OEM-2144145-94093 Windows Product ID Type: 3 Windows License Type: OEM System Builder Windows OS version: 5.1.2600.2.00010300.3.0.hom CSVLK Server: N/A CSVLK PID: N/A ID: {41060FB3-0DE8-423C-A2A6-C1EE80B23C7A}(1) Is Admin: Yes TestCab: 0x0 WGA Version: Registered, 1.7.69.2 Signed By: Microsoft Product Name: N/A Architecture: N/A Build lab: N/A TTS Error: N/A Validation Diagnostic: 025D1FF3-171-1_63BB5E84-896-80004005 Resolution Status: N/A WgaER Data–> ThreatID(s): N/A Version: N/A WGA Notifications Data–> Cached Result: N/A, hr = 0x80070002 File Exists: No Version: N/A, hr = 0x80070002 WgaTray.exe Signed By: N/A, hr = 0x80070002 WgaLogon.dll Signed By: N/A, hr = 0x80070002 OGA Notifications Data–> Cached Result: N/A, hr = 0x80070002 Version: N/A, hr = 0x80070002 WGATray.exe Signed By: N/A, hr = 0x80070002 OGAAddin.dll Signed By: N/A, hr = 0x80070002 OGA Data–> Office Status: 109 N/A OGA Version: N/A, 0x80070002 Signed By: N/A, hr = 0x80070002 Office Diagnostics: B4D0AA8B-543-80070002_025D1FF3-171-1 Browser Data–> Proxy settings: N/A User Agent: Mozilla/4.0 (compatible; MSIE 7.0; Win32) Default Browser: C:\Program Files\Internet Explorer\IEXPLORE.exe Download signed ActiveX controls: Prompt Download unsigned ActiveX controls: Disabled Run ActiveX controls and plug-ins: Allowed Initialize and script ActiveX controls not marked as safe: Disabled Allow scripting of Internet Explorer Webbrowser control: Disabled Active scripting: Allowed Script ActiveX controls marked as safe for scripting: Allowed File Scan Data–> Other data–> Office Details: {41060FB3-0DE8-423C-A2A6-C1EE80B23C7A}1.7.0095.05.1.2600.2.00010300.3.0.homx32*****-*****-*****-*****-PMPF376477-OEM-2144145-940933S-1-5-21-854245398-152049171-1957994488Gateway E-4000 Intel Corp.RG84510A.15A.0018.P08.020817115020020817000000.000000+00013EC3CAF01842E6204090409Eastern Standard Time(GMT-05:00)03109
Download Malwarebytes' Anti-Malware from here and save it to your Desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • Ensure a checkmark is placed next to both Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware and then click Finish.
  • If an update is found, it will download and install the latest version - you'll need to clear it with your firewall.
  • Once the program has loaded, select Perform full scan and then Scan.
  • When the scan has finished, click OK and then Show Results to view the results - no surprise there!
  • If MBAM finds anything, check the box(es) and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt
Let me have the MBAM log, a fresh HJT log (run in Normal Mode) AND a description of how your PC is behaving.
Well, I did a quick scan (doing a full scan now), and here is the log:

"Malwarebytes' Anti-Malware 1.20
Database version: 935
Windows 5.1.2600 Service Pack 3

11:00:38 PM 7/9/2008
mbam-log-7-9-2008 (23-00-38).txt

Scan type: Quick Scan
Objects scanned: 8969
Time elapsed: 1 minute(s), 14 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\Interface\{b2e51014-07fc-4282-a209-d44a0954a3ca} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{214ecb4f-711e-4676-a980-0d7e821b97e5} (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{08e11e95-e8e4-43dd-b762-43f2159c8759} (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\abfhsang.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\gnashfba.dll (Trojan.Vundo) -> Delete on reboot."

Here is the Hijackthis log:

"Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:05:44 PM, on 7/9/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware\Ad-Watch.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?rs=1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {28220052-D9A9-44B1-AB98-EDC594D238B6} - (no file)
O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {77D1BC45-F210-462E-86D2-CD0AF43A8585} - (no file)
O3 - Toolbar: (no name) - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\Ad-Watch.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo…toUploader5.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1209676308175
O20 - Winlogon Notify: Antiwpa - C:\WINDOWS\SYSTEM32\antiwpa.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

–
End of file - 5385 bytes"

My computer has been running fine lately, except for Mozilla Firefox (3) and iTunes (latest version) They both take forever to start up, but once they're started, they pretty much run just fine. I'll let you know if there's anything after the full scan.
Sorry to bump, but it's only been a few minutes. Here's the second log, from the full scan, " Memory Processes Infected: 0 Memory Modules Infected: 1 Registry Keys Infected: 3 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 5 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: C:\WINDOWS\system32\antiwpa.dll (Malware.Tool) -> Unloaded module successfully. Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\antiwpa (Malware.Tool) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\QooBox\Quarantine\C\WINDOWS\system32\cxxlvcar.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully. C:\QooBox\Quarantine\C\WINDOWS\system32\nggixang.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{7B2FE2FC-6389-4E11-BD6F-A16505392306}\RP2\A0000039.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{7B2FE2FC-6389-4E11-BD6F-A16505392306}\RP2\A0000041.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\antiwpa.dll (Malware.Tool) -> Delete on reboot."
I can't do anything about either Firefox or iTunes. Firefox may improve as they fix any bugs that they still have in the latest version, and I suspect iTunes is just a born resource hog.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Run HijackThis as you did to generate a log, but this time click on 'Do a system scan only'.
Place a checkmark in the boxes to the left of the following entries, by clicking on them:

O2 - BHO: (no name) - {28220052-D9A9-44B1-AB98-EDC594D238B6} - (no file)
O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - (no file)
O2 - BHO: (no name) - {77D1BC45-F210-462E-86D2-CD0AF43A8585} - (no file)

O3 - Toolbar: (no name) - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - (no file)


CLOSE ALL OPEN WINDOWS AND BROWSERS - EXCEPT HJT and click on Fix checked

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

You are running an old version of Sun Java which needs updating:
  • Go here and click on the Download button to the right of Java Runtime Environment (JRE) 6u6.
  • Accept the license agreement by clicking the appropriate radio button and then continue.
  • Under Windows Platform - Java™ SE Runtime Environment 6 Update 6, click the Windows Offline Installation, Multi-language link.
  • Go to Add/Remove Programs and remove any entries that refer to Java 2 Runtime Environment and then reboot your PC.
  • Navigate to and delete the following folder, if it exists: C:\Program Files\Java.
  • Finally double click the installation file that you downloaded earlier.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Your log doesn't appear to show a third-party software firewall installed - if you have one, and i've missed it, please ignore this.
If you are relying the firewall that comes with Service Pack 2, then you need to install one. While the SP2 firewall is better than nothing, it doesn't monitor outgoing traffic, so anything malicious on your computer can 'phone home' at will.
If you are using a wireless router that comes with a NAT hardware firewall, this also doesn't monitor outgoing connections.

There are a few free firewalls available.
Comodo Firewall Pro, available here.
PC Tools Firewall Plus, available here.
Online Armor Free, available here.

It is important to note that you should only have one firewall installed at a time, but you can download them all to your Desktop and install each in turn to see which one you prefer.

Understanding and Using Firewalls: http://www.bleepingcomputer.com/tutorials/tutorial60.html

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

As long as all is still well, you're done. I want you to run your PC as normal for a few days and when you are happy that everything is fine, do the following:

Go to Start > Run, enter the following into the textbox and click OK: combofix /u
This will uninstall Combofix and do a little housework besides.

Create a new Restore Point - this will give a clean one should you need it in the future.
A tutorial for System Restore is available here.

The reason for waiting is that if removing the malware has caused a problem, which it occasionally does, you can put your PC back to how it was before the fix. This will re-install the malware, but an infected PC is better than an expensive paperweight!

Some bedtime reading: This is a very good tutorial about keeping your computer safe and secure on the internet.


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI