Hi there, I'm sorry to report that I have a malware infection. I've tried to get rid of it using Kaspersky but it hasn't removed the problem.
I've done a HJT scan and a ComboFix scan. ComboFix was run first, then HJT. Thanks in advance for your help :D

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:14:09 PM, on 7/3/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\WINDOWS\system32\CTSvcCDA.EXE
C:\Program Files\NetLimiter 2 Pro\nlsvc.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\RhinoSoft.com\Serv-U\ServUDaemon.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\Folder Guard XP\FGKey.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\WIPFW\bin\ipfw.exe
C:\Program Files\DynDNS Updater\DynDNS.exe
C:\Program Files\uTorrent\utorrent.exe
C:\Program Files\Red Chair Software\Notmad Explorer\notmgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [FG_Monitor] C:\Program Files\Folder Guard XP\FGKey.exe /Start
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DynDNS Updater] "C:\Program Files\DynDNS Updater\DynDNS.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\utorrent.exe"
O4 - HKUS\S-1-5-19\..\Run: [msnsc] C:\WINDOWS\system32\msnsc.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [SAFE6_SAFE] "C:\Program Files\Steganos Safe 6\safe.exe" /booting (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [msnsc] C:\WINDOWS\system32\msnsc.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [msnsc] C:\WINDOWS\system32\msnsc.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnsc] C:\WINDOWS\system32\msnsc.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'Default user')
O4 - Startup: Notmad Manager.lnk = C:\Program Files\Red Chair Software\Notmad Explorer\notmgr.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: iSiloX Clipper - {C86027A6-12A1-4298-B6EA-A42AC6EE6C7C} - C:\Program Files\iSilo\iSiloX\iSiloXIE.dll (HKCU)
O9 - Extra 'Tools' menuitem: iSiloX Clipper… - {C86027A6-12A1-4298-B6EA-A42AC6EE6C7C} - C:\Program Files\iSilo\iSiloX\iSiloXIE.dll (HKCU)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1205202892467
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1205202823217
O18 - Protocol: intu-qt2007 - {026BF40D-BA05-467B-9F1F-AD0D7A3F5F11} - C:\Program Files\QuickTax 2007\ic2007pp.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTSvcCDA.EXE
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: ipfw_helper (ipfw) - Unknown owner - C:\Program Files\WIPFW\bin\ipfw.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NetLimiter (nlsvc) - Locktime Software - C:\Program Files\NetLimiter 2 Pro\nlsvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Serv-U FTP Server (Serv-U) - Rhino Software, Inc. [removed] - C:\Program Files\RhinoSoft.com\Serv-U\ServUDaemon.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: XAMPP Service (XAMPP) - Unknown owner - C:\Program Files\xampp\service.exe (file missing)

–
End of file - 9431 bytes










ComboFix 08-07-02.5 - thecoffeeman 2008-07-03 16:55:22.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.553 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\BMffe1d468.txt
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\btfunc.dll
C:\WINDOWS\system32\kemvmhmx.ini
C:\WINDOWS\system32\nWEeLnmp.ini
C:\WINDOWS\system32\nWEeLnmp.ini2
C:\WINDOWS\system32\xxcmyqyp.ini

.
((((((((((((((((((((((((( Files Created from 2008-06-03 to 2008-07-03 )))))))))))))))))))))))))))))))
.

2008-07-03 15:05 . 2008-07-03 15:05 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-07-03 15:05 . 2008-07-03 15:05 1,409 –a—— C:\WINDOWS\QTFont.for
2008-07-03 14:18 . 2008-07-03 14:18 d——– C:\Documents and Settings\All Users\Application Data\REDCINE
2008-07-03 14:17 . 2008-07-03 14:17 d——– C:\Program Files\REDCINE
2008-07-03 08:52 . 2008-07-03 10:41 d——– C:\Program Files\The GodFather
2008-07-02 16:15 . 2008-07-02 16:15 d——– C:\Program Files\Red Chair Software
2008-07-02 16:15 . 2008-07-02 16:15 d——– C:\Documents and Settings\thecoffeeman\Application Data\Red Chair Software
2008-07-02 12:32 . 2007-02-13 12:30 36,096 –a—— C:\WINDOWS\system32\drivers\ip_fw.sys
2008-07-02 12:32 . 2006-12-25 16:05 31,744 –a—— C:\WINDOWS\system32\ipfw.exe
2008-07-02 12:31 . 2008-07-02 12:31 d——– C:\Program Files\WIPFW
2008-06-28 23:07 . 2008-06-28 23:07 d——– C:\Deckard
2008-06-28 22:52 . 2008-06-28 22:52 d——– C:\_OTMoveIt
2008-06-27 00:01 . 2008-06-28 23:04 110,359 –a—— C:\WINDOWS\BMffe1d468.xml
2008-06-22 15:53 . 2008-06-22 15:54 0 –a—— C:\u

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-03 22:03 17,393,184 –sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-07-03 22:01 25,184 –sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-07-03 22:01 243,392 –sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-07-03 22:01 224,288 –sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-07-03 22:01 ——— d—–w C:\Documents and Settings\thecoffeeman\Application Data\uTorrent
2008-07-03 05:00 ——— d—–w C:\Program Files\DynDNS Updater
2008-07-02 21:57 ——— d—–w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-07-02 00:16 ——— d—–w C:\Program Files\Zoom Player 5
2008-06-21 19:18 ——— d—–w C:\Documents and Settings\thecoffeeman\Application Data\AdobeUM
2008-06-05 03:30 ——— d—–w C:\Documents and Settings\thecoffeeman\Application Data\Vso
2008-06-01 17:13 ——— d—–w C:\Program Files\PDF Password Cracker v3.0
2008-05-29 19:38 88,774 —-a-w C:\WINDOWS\system32\drivers\klick.dat
2008-05-28 15:49 96,966 —-a-w C:\WINDOWS\system32\drivers\klin.dat
2008-05-28 15:49 112,144 —-a-w C:\WINDOWS\system32\drivers\kl1.sys
2008-05-04 23:20 ——— d—–w C:\Program Files\ImgBurn
2007-03-25 21:15 87,608 —-a-w C:\Documents and Settings\thecoffeeman\Application Data\ezpinst.exe
2007-03-25 21:15 47,360 —-a-w C:\Documents and Settings\thecoffeeman\Application Data\pcouffin.sys
2004-09-28 02:00 26,240 —-a-w C:\WINDOWS\inf\RAMDSK.SYS
2007-01-29 18:16 88 –sha-r C:\WINDOWS\system32\163516DE40.sys
2007-01-29 18:16 2,098 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.



——- Sigcheck ——-

2006-04-20 07:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
2006-01-12 21:03 360448 2a4818aea80acd2c95d7d92d2f3155f8 C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
2007-01-05 23:44 359808 b4e29943b4b04bd5e7381546848e6669 C:\WINDOWS\system32\drivers\TCPIP.SYS

2006-01-12 21:04 2187904 c3b84871dece94e335b96fafd756316c C:\WINDOWS\system32\ntoskrnl.exe

2006-01-12 20:46 1075200 2deaca71a7fd77205f59d48d76b2f565 C:\WINDOWS\explorer.exe
.
((((((((((((((((((((((((((((( snapshot@2008-05-02_16.38.28.53 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-02 21:29:17 2,048 –s-a-w C:\WINDOWS\bootstat.dat
+ 2008-07-03 22:03:23 2,048 –s-a-w C:\WINDOWS\bootstat.dat
- 2000-08-31 13:00:00 73,728 —-a-w C:\WINDOWS\fdsv.exe
+ 2000-08-31 13:00:00 89,504 —-a-w C:\WINDOWS\fdsv.exe
+ 2008-07-03 19:17:29 25,214 —-a-r C:\WINDOWS\Installer\{441B4BCC-098F-450B-A8AF-81D6E1B622E7}\_301d1075.exe
+ 2008-07-03 19:17:29 25,214 —-a-r C:\WINDOWS\Installer\{441B4BCC-098F-450B-A8AF-81D6E1B622E7}\_69e55ddc.exe
+ 2008-07-03 19:17:29 25,214 —-a-r C:\WINDOWS\Installer\{441B4BCC-098F-450B-A8AF-81D6E1B622E7}\_942b74.exe
- 2000-08-31 13:00:00 28,160 —-a-w C:\WINDOWS\Nircmd.exe
+ 2000-08-31 13:00:00 28,672 —-a-w C:\WINDOWS\Nircmd.exe
- 2006-12-20 14:23:59 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-07-01 23:57:38 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2006-12-20 14:23:59 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-07-01 23:57:38 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2006-12-20 14:23:59 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-07-01 23:57:38 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-12-29 00:51:04 195,344 —-a-w C:\WINDOWS\system32\drivers\klif.sys
+ 2007-12-13 18:28:40 24,592 —-a-w C:\WINDOWS\system32\drivers\klim5.sys
+ 2008-02-08 23:35:42 23,604 —-a-w C:\WINDOWS\system32\drivers\klopp.dat
+ 2008-02-08 23:37:44 219,664 —-a-w C:\WINDOWS\system32\klogon.dll
- 2007-10-11 19:12:48 1,468,968 —-a-w C:\WINDOWS\system32\LegitCheckControl.dll
+ 2008-03-30 14:05:44 1,488,688 —-a-w C:\WINDOWS\system32\LegitCheckControl.dll
- 2006-06-19 15:20:42 312,112 —-a-w C:\WINDOWS\system32\WgaLogon.dll
+ 2008-03-30 14:06:02 200,064 —-a-w C:\WINDOWS\system32\WgaLogon.dll
- 2006-06-19 15:19:26 253,744 —-a-w C:\WINDOWS\system32\WgaTray.exe
+ 2008-03-30 14:06:20 332,672 —-a-w C:\WINDOWS\system32\WgaTray.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 12:54 5674352]
"DynDNS Updater"="C:\Program Files\DynDNS Updater\DynDNS.exe" [2006-09-17 10:32 1352704]
"uTorrent"="C:\Program Files\uTorrent\utorrent.exe" [2008-01-30 21:43 219952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\Program Files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 16:48 479232]
"zBrowser Launcher"="C:\Program Files\Logitech\iTouch\iTouch.exe" [2004-03-18 09:33 892928]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 11:40 155648]
"FG_Monitor"="C:\Program Files\Folder Guard XP\FGKey.exe" [2007-02-24 23:00 132680]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-10-28 16:05 344064]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [2008-02-08 18:36 227856]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnsc"="C:\WINDOWS\system32\msnsc.exe" [2006-01-12 20:36 62054]
"SAFE6_SAFE"="C:\Program Files\Steganos Safe 6\safe.exe" [N/A]

C:\Documents and Settings\thecoffeeman\Start Menu\Programs\Startup\
Notmad Manager.lnk - C:\Program Files\Red Chair Software\Notmad Explorer\notmgr.exe [2006-03-03 21:43:20 1264128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.imc"= imc32.acm
"msacm.l3codecp"= l3codecp.acm
"VIDC.i263"= i263_32.drv
"msacm.dvacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm
"msacm.MPEGacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG\MPEGacm.acm
"msacm.ulmp3acm"= C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG\ulmp3acm.acm

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=C:\WINDOWS\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HOTSYNCSHORTCUTNAME.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HOTSYNCSHORTCUTNAME.lnk
backup=C:\WINDOWS\pss\HOTSYNCSHORTCUTNAME.lnkCommon Startup
=

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
–a—— 2006-01-12 20:52 483328 C:\Program Files\Adobe\Acrobat 7.0\Distillr\acrotray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlackFooX 3]
–a—— 2007-03-21 20:31 475136 C:\Program Files\SlySoft\AnyDVD\BlackFooX3.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BMffe1d468]
C:\WINDOWS\system32\ffmpwkxt.dll [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\fcd2e7f4]
C:\WINDOWS\system32\qpynvsjy.dll [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2007-12-11 12:10 267048 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Miro]
C:\Program Files\Participatory Culture Foundation\Miro\Miro.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Orb]
–a—— 2008-01-07 15:02 495616 C:\Program Files\Winamp Remote\bin\OrbTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
–a—— 2005-12-13 08:49 217088 C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PcSync]
–a—— 2006-03-06 11:34 1302528 C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
–a—— 2007-08-06 19:05 200704 C:\Program Files\PowerISO\PWRISOVM.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2007-12-11 10:56 286720 C:\Program Files\QuickTime Alternative\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SAFE6_SAFE]
C:\Program Files\Steganos Safe 6\safe.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
–a—— 2006-03-30 15:45 313472 C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UVS11 Preload]
——— 2007-07-23 13:55 341232 C:\Program Files\Ulead Systems\Ulead VideoStudio 11\uvPL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\µTorrent]
–a—— 2008-01-30 21:43 219952 C:\Program Files\uTorrent\utorrent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WD Button Manager]
–a—— 2008-01-13 18:05 364544 C:\WINDOWS\system32\WDBtnMgr.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"AnyDVD"=C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\uTorrent\\utorrent.exe"=
"E:\\Mircs\\upp_2.00_build_2004.03.05\\mirc_upp.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\FlashFXP\\flashfxp.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"C:\\Program Files\\Winamp\\winamp.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 7.0.1.325\\English\\setup.exe"=
"K:\\Mircs\\upp_2.00_build_2004.03.05\\mirc_upp.exe"=
"C:\\Program Files\\Red Chair Software\\Notmad Explorer\\notmgr.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\RemoteAdminSettings]
"RemoteAddresses"= *
"Enabled"= 1 (0x1)

R0 uliagpkx;ULi AGP Bus Filter Driver;C:\WINDOWS\system32\DRIVERS\agpkx.sys [2005-05-03 10:31]
R1 nltdi;nltdi;C:\WINDOWS\system32\drivers\nltdi.sys [2006-09-13 17:01]
R2 devdpl;devdpl;C:\WINDOWS\system32\DRIVERS\devdpl.sys [2003-03-05 13:47]
R2 FGUARD32;FGUARD32;C:\Program Files\Folder Guard XP\FGUARD32.SYS [2007-02-24 23:00]
R2 ipfw;ipfw_helper;C:\Program Files\WIPFW\bin\ipfw.exe [2006-12-25 16:05]
R2 litdpl;litdpl;C:\WINDOWS\system32\DRIVERS\litdpl.sys [2003-03-05 13:47]
R2 Serv-U;Serv-U FTP Server;C:\Program Files\RhinoSoft.com\Serv-U\ServUDaemon.exe [2007-01-09 22:31]
R2 UxTuneUp;TuneUp Design Expansion;C:\WINDOWS\System32\svchost.exe [2006-01-12 20:38]
R3 AC97ALI;Service for AC'97 Driver (WDM);C:\WINDOWS\system32\drivers\ali55wdm.sys [2004-08-27 13:29]
R3 HCWBT8XX;Hauppauge WinTV 848/9 WDM Video Driver;C:\WINDOWS\system32\drivers\HCWBT8XX.sys [2006-01-25 16:14]
R3 ip_fw;ipfw kernel-mode driver;C:\WINDOWS\system32\DRIVERS\ip_fw.sys [2007-02-13 12:30]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-12-13 13:28]
R3 ULI5261XP;ULi M526X Ethernet NT Driver;C:\WINDOWS\system32\DRIVERS\ULILAN51.SYS [2005-03-22 13:36]
R3 WDC_SAM;WD SCSI Pass Thru driver;C:\WINDOWS\system32\DRIVERS\wdcsam.sys [2006-09-07 21:16]
S2 XAMPP;XAMPP Service;C:\Program Files\xampp\service.exe []

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\I]
\Shell\AutoRun\command - I:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{554c4c9d-05c0-11dd-beff-00138f7f0e36}]
\Shell\AutoRun\command - I:\wd_windows_tools\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cc44cf08-00fb-11dc-92ab-00138f7f0e36}]
\Shell\AutoRun\command - F:\setupSNK.exe

.
- - - - ORPHANS REMOVED - - - -

ShellExecuteHooks-{C5E84927-CFF0-4CA3-A068-02E7C01C1E7C} - (no file)
Notify-NavLogon - (no file)
Notify-nnnNfCSm - nnnNfCSm.dll


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-03 17:04:09
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\WINDOWS\system32\CTSVCCDA.EXE
C:\Program Files\NetLimiter 2 Pro\nlsvc.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\PROGRA~1\FOLDER~1\FGKey.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-07-03 17:12:09 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-03 22:11:34
ComboFix2.txt 2008-06-27 05:05:12
ComboFix3.txt 2008-05-02 21:39:02

Pre-Run: 18,597,859,328 bytes free
Post-Run: 18,630,492,160 bytes free

259