I haven't gotten any popups since the last step, so I think this might have been solved. Thank You SO MUCH! As additional info goes:
CF Log
ComboFix 08-12-24.01 - Andrew 2008-12-24 16:33:31.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1663.1095 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Andrew\Desktop\CFScript.txt
* Created a new restore point
* Resident AV is active
FILE ::
c:\windows\Brohl144.ini
c:\windows\Brwmark.ini
c:\windows\Tasks\wqbevghn.job
.
((((((((((((((((((((((((( Files Created from 2008-11-25 to 2008-12-25 )))))))))))))))))))))))))))))))
.
2008-12-24 14:47 . 2008-12-24 14:47 d——– c:\program files\Trend Micro
2008-12-24 14:38 . 2008-12-24 14:38 d——– c:\program files\Malwarebytes' Anti-Malware
2008-12-24 14:38 . 2008-12-24 14:38 d——– c:\documents and settings\Andrew\Application Data\Malwarebytes
2008-12-24 14:38 . 2008-12-24 14:38 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-24 14:38 . 2008-12-03 19:52 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-24 14:38 . 2008-12-03 19:52 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-12-23 10:22 . 2008-12-23 10:22 d——– C:\_OTMoveIt
2008-12-22 08:59 . 2008-12-22 08:59 d——– c:\program files\Stardock
2008-12-22 08:59 . 2003-02-26 20:27 36,864 –a—— c:\windows\system32\wbsys.dll
2008-12-22 08:59 . 2005-01-22 18:05 20,480 –a—— c:\windows\system32\wbload.dll
2008-12-22 08:44 . 2008-12-22 08:43 502,368 –a—— c:\windows\system32\drivers\amon.sys
2008-12-22 08:44 . 2008-12-22 08:43 274,432 –a—— c:\windows\system32\imon.dll
2008-12-22 08:43 . 2008-12-24 15:04 d——– c:\program files\ESET
2008-12-20 14:21 . 2008-12-22 08:29 d——– c:\program files\SpywareBlaster
2008-12-20 14:21 . 2008-12-22 08:31 d-a—— c:\documents and settings\All Users\Application Data\TEMP
2008-12-20 14:21 . 2005-08-25 18:19 115,920 –a—— c:\windows\system32\MSINET.OCX
2008-12-20 13:41 . 2008-12-20 13:48 d——– c:\program files\Spybot - Search & Destroy
2008-12-20 13:41 . 2008-12-21 02:23 d——– c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-20 00:36 . 2008-12-20 00:36 d——– c:\documents and settings\Andrew\Application Data\AdobeUM
2008-12-19 08:47 . 2008-12-19 08:47 d——– c:\program files\Common Files\LightScribe
2008-12-19 08:45 . 2008-12-19 08:45 d——– c:\documents and settings\Andrew\Application Data\Ahead
2008-12-19 08:42 . 2008-12-19 08:46 d——– c:\program files\Common Files\Ahead
2008-12-10 19:02 . 2008-10-03 02:15 247,326 —–c— c:\windows\system32\dllcache\strmdll.dll
2008-12-08 00:48 . 2008-12-08 00:48 d——– c:\documents and settings\All Users\Application Data\FLEXnet
2008-12-07 14:06 . 2008-12-07 14:06 d——– c:\program files\Common Files\Macrovision Shared
2008-12-06 14:36 . 2008-10-16 12:38 6,066,176 —–c— c:\windows\system32\dllcache\ieframe.dll
2008-12-06 14:36 . 2007-04-17 01:32 2,455,488 —–c— c:\windows\system32\dllcache\ieapfltr.dat
2008-12-06 14:36 . 2007-03-07 21:10 991,232 —–c— c:\windows\system32\dllcache\ieframe.dll.mui
2008-12-06 14:36 . 2008-10-16 12:38 459,264 —–c— c:\windows\system32\dllcache\msfeeds.dll
2008-12-06 14:36 . 2008-10-16 12:38 383,488 —–c— c:\windows\system32\dllcache\ieapfltr.dll
2008-12-06 14:36 . 2008-10-16 12:38 267,776 —–c— c:\windows\system32\dllcache\iertutil.dll
2008-12-06 14:36 . 2008-10-16 12:38 63,488 —–c— c:\windows\system32\dllcache\icardie.dll
2008-12-06 14:36 . 2008-10-16 12:38 52,224 —–c— c:\windows\system32\dllcache\msfeedsbs.dll
2008-12-06 14:36 . 2007-08-13 18:54 33,792 –a–c— c:\windows\system32\dllcache\custsat.dll
2008-12-06 14:36 . 2008-10-16 05:11 13,824 —–c— c:\windows\system32\dllcache\ieudinit.exe
2008-12-06 10:27 . 2008-12-14 18:10 d——– c:\program files\Steam
2008-12-06 08:42 . 2008-12-06 08:42 d——– c:\program files\Common Files\Adobe Systems Shared
2008-12-06 08:42 . 2008-12-06 08:42 d——– c:\documents and settings\All Users\Application Data\Adobe Systems
2008-12-06 08:41 . 2008-12-07 14:19 d——– c:\program files\Common Files\Adobe
2008-12-04 19:21 . 2008-12-04 19:21 184 –a—— c:\windows\system32\brsvc01a.bsi
2008-12-04 19:21 . 2008-12-04 19:21 30 –a—— c:\windows\system32\brss01a.ini
2008-12-03 01:20 . 2008-12-03 01:20 d——– c:\documents and settings\Andrew\Application Data\DivX
2008-12-02 02:43 . 2008-12-02 02:43 16,826 –ah—– c:\windows\system32\brdiag.GID
2008-12-02 00:18 . 2008-10-16 14:06 268,648 –a—— c:\windows\system32\mucltui.dll
2008-12-02 00:18 . 2008-10-16 14:06 208,744 –a—— c:\windows\system32\muweb.dll
2008-12-02 00:18 . 2008-10-16 14:06 27,496 –a—— c:\windows\system32\mucltui.dll.mui
2008-12-02 00:13 . 2006-10-26 19:56 32,592 –a—— c:\windows\system32\msonpmon.dll
2008-12-02 00:11 . 2008-12-02 00:11 d——– c:\program files\MSBuild
2008-12-02 00:11 . 2008-12-02 00:11 d——– c:\program files\Microsoft Works
2008-12-02 00:05 . 2008-12-02 00:11 d——– c:\windows\SHELLNEW
2008-12-02 00:04 . 2008-12-02 00:04 dr-h—– C:\MSOCache
2008-12-02 00:04 . 2008-12-11 03:04 d——– c:\documents and settings\All Users\Application Data\Microsoft Help
2008-12-02 00:01 . 2008-12-02 00:01 d——– c:\program files\PowerISO
2008-12-01 07:34 . 2008-12-04 19:22 59 –a—— c:\windows\brmx2001.ini
2008-12-01 07:34 . 2008-12-04 19:22 40 –a—— c:\windows\opt_1440.ini
2008-12-01 07:33 . 2008-12-04 19:21 d——– c:\program files\Brownie
2008-12-01 07:33 . 2008-12-01 07:33 d——– c:\program files\Brother
2008-12-01 07:31 . 2008-12-01 07:31 d——– c:\documents and settings\Andrew\WINDOWS
2008-12-01 07:31 . 1998-01-23 12:22 304,128 –a—— c:\windows\IsUninst.exe
2008-11-28 15:33 . 2008-11-28 15:33 d——– c:\program files\MSXML 4.0
2008-11-28 12:50 . 2008-11-28 12:50 d——– c:\program files\Codec Pack - All In 1
2008-11-28 12:50 . 2008-11-28 12:49 737,280 –a—— c:\windows\iun6002.exe
2008-11-28 11:23 . 2008-09-19 13:57 120,056 –a—— c:\windows\system32\pxcpyi64.exe
2008-11-28 11:23 . 2008-09-19 13:57 118,520 –a—— c:\windows\system32\pxinsi64.exe
2008-11-28 11:22 . 2008-11-28 11:23 d——– c:\program files\DivX
2008-11-28 10:54 . 2008-11-28 10:54 d——– c:\documents and settings\Andrew\Application Data\acccore
2008-11-28 10:49 . 2008-11-28 10:49 d——– c:\documents and settings\All Users\Application Data\Viewpoint
2008-11-28 10:49 . 2008-11-28 10:54 d——– c:\documents and settings\All Users\Application Data\AOL OCP
2008-11-28 10:49 . 2008-11-28 10:49 d——– c:\documents and settings\All Users\Application Data\AOL
2008-11-28 10:49 . 2008-11-28 10:49 d——– c:\documents and settings\All Users\Application Data\acccore
2008-11-28 10:48 . 2008-11-28 10:48 d——– c:\program files\Common Files\AOL
2008-11-28 10:48 . 2008-11-28 10:53 d——– c:\program files\AIM6
2008-11-28 10:48 . 2008-11-28 10:53 467 –ah—– C:\IPH.PH
2008-11-27 23:38 . 2008-12-02 21:26 d——– c:\windows\system32\CatRoot_bak
2008-11-27 23:37 . 2008-08-28 02:04 333,056 —–c— c:\windows\system32\dllcache\srv.sys
2008-11-27 23:37 . 2008-06-13 05:10 272,128 —–c— c:\windows\system32\dllcache\bthport.sys
2008-11-27 23:37 . 2008-08-14 01:51 138,368 —–c— c:\windows\system32\dllcache\afd.sys
2008-11-27 23:36 . 2008-09-15 03:57 1,846,016 —–c— c:\windows\system32\dllcache\win32k.sys
2008-11-27 23:35 . 2008-08-14 02:00 2,180,352 —–c— c:\windows\system32\dllcache\ntoskrnl.exe
2008-11-27 23:35 . 2008-08-14 01:58 2,136,064 —–c— c:\windows\system32\dllcache\ntkrnlmp.exe
2008-11-27 23:35 . 2008-08-14 01:22 2,057,728 —–c— c:\windows\system32\dllcache\ntkrnlpa.exe
2008-11-27 23:35 . 2008-08-14 01:22 2,015,744 —–c— c:\windows\system32\dllcache\ntkrpamp.exe
2008-11-27 23:35 . 2008-04-11 10:50 683,520 —–c— c:\windows\system32\dllcache\inetcomm.dll
2008-11-27 23:35 . 2008-10-24 03:10 453,632 —–c— c:\windows\system32\dllcache\mrxsmb.sys
2008-11-27 23:35 . 2008-10-15 08:57 332,800 —–c— c:\windows\system32\dllcache\netapi32.dll
2008-11-27 18:58 . 2008-12-18 00:50 d–h—– c:\windows\$hf_mig$
2008-11-27 17:54 . 2008-11-27 17:54 d——– c:\documents and settings\All Users\Application Data\Last.fm
2008-11-27 17:53 . 2008-11-27 17:53 d——– c:\program files\Last.fm
2008-11-27 17:31 . 2008-12-23 22:38 69 –a—— c:\windows\NeroDigital.ini
2008-11-27 17:25 . 2008-11-27 17:25 d——– c:\documents and settings\Andrew\Application Data\Nero
2008-11-27 17:22 . 2008-12-19 08:42 d——– c:\program files\Nero
2008-11-27 17:22 . 2008-12-19 08:37 d——– c:\program files\Common Files\Nero
2008-11-27 17:22 . 2008-12-19 08:42 d——– c:\documents and settings\All Users\Application Data\Nero
2008-11-27 17:19 . 2008-09-04 08:42 1,106,944 —–c— c:\windows\system32\dllcache\msxml3.dll
2008-11-27 17:16 . 2008-11-27 17:16 d——– c:\program files\Windows Media Connect 2
2008-11-27 17:16 . 2006-10-04 06:06 1,197,294 —–c— c:\windows\system32\dllcache\sysmain.sdb
2008-11-27 17:16 . 2006-10-04 06:06 764,868 —–c— c:\windows\system32\dllcache\apph_sp.sdb
2008-11-27 17:16 . 2004-08-04 00:56 221,184 –a—— c:\windows\system32\wmpns.dll
2008-11-27 17:16 . 2006-10-04 06:06 217,118 —–c— c:\windows\system32\dllcache\apphelp.sdb
2008-11-27 17:15 . 2008-11-27 17:15 d——– c:\windows\system32\LogFiles
2008-11-27 17:15 . 2008-11-27 17:15 d——– c:\windows\system32\drivers\UMDF
2008-11-27 17:00 . 2008-11-27 17:02 d——– c:\program files\Winamp
2008-11-27 17:00 . 2008-11-27 17:00 d——– c:\documents and settings\Andrew\Application Data\Winamp
2008-11-27 16:35 . 2008-11-27 16:35 d——– c:\program files\Electronic Arts
2008-11-27 16:34 . 2008-05-30 14:11 3,850,760 –a—— c:\windows\system32\D3DX9_38.dll
2008-11-27 16:33 . 2008-11-27 16:33 d——– c:\windows\Logs
2008-11-27 15:53 . 2008-11-27 15:53 d——– c:\windows\Sun
2008-11-27 15:51 . 2008-11-27 15:51 d——– c:\program files\Java
2008-11-27 15:51 . 2008-11-27 15:51 410,976 –a—— c:\windows\system32\deploytk.dll
2008-11-27 15:51 . 2008-11-27 15:51 73,728 –a—— c:\windows\system32\javacpl.cpl
2008-11-27 14:15 . 2008-05-01 06:30 331,776 —–c— c:\windows\system32\dllcache\msadce.dll
2008-11-27 11:53 . 2008-11-27 11:53 d——– c:\documents and settings\All Users\Application Data\Blizzard
2008-11-27 09:26 . 2008-12-18 22:52 d——– c:\program files\World of Warcraft
2008-11-27 09:26 . 2008-11-27 09:26 d——– c:\program files\Common Files\Blizzard Entertainment
2008-11-27 09:22 . 2008-11-27 17:54 d——– c:\program files\iTunes
2008-11-27 09:22 . 2008-11-27 09:22 d——– c:\program files\iPod
2008-11-27 09:22 . 2008-12-19 08:51 d——– c:\documents and settings\Andrew\Application Data\Apple Computer
2008-11-27 09:22 . 2008-11-27 09:22 d——– c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-27 09:22 . 2008-04-17 13:12 107,368 –a—— c:\windows\system32\GEARAspi.dll
2008-11-27 09:22 . 2008-04-17 13:12 15,464 –a—— c:\windows\system32\drivers\GEARAspiWDM.sys
2008-11-27 09:21 . 2008-11-27 09:22 d—-c— c:\windows\system32\DRVSTORE
2008-11-27 09:21 . 2008-11-27 09:22 d——– c:\program files\QuickTime
2008-11-27 09:21 . 2008-11-27 09:22 d——– c:\program files\Common Files\Apple
2008-11-27 09:21 . 2008-11-27 09:21 d——– c:\program files\Apple Software Update
2008-11-27 09:21 . 2008-11-27 09:22 d——– c:\documents and settings\All Users\Application Data\Apple Computer
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-27 07:05 558,142 —-a-w c:\windows\java\Packages\YAJDJN9Z.ZIP
2008-11-27 07:05 155,995 —-a-w c:\windows\java\Packages\7PFHBT7J.ZIP
2008-11-27 07:05 ——— d—–w c:\program files\microsoft frontpage
2008-10-28 22:36 823,296 —-a-w c:\windows\system32\divx_xx0c.dll
2008-10-28 22:36 823,296 —-a-w c:\windows\system32\divx_xx07.dll
2008-10-28 22:35 815,104 —-a-w c:\windows\system32\divx_xx0a.dll
2008-10-28 22:35 802,816 —-a-w c:\windows\system32\divx_xx11.dll
2008-10-28 22:35 684,032 —-a-w c:\windows\system32\DivX.dll
2008-10-23 13:01 283,648 —-a-w c:\windows\system32\gdi32.dll
2008-10-16 22:13 202,776 —-a-w c:\windows\system32\wuweb.dll
2008-10-16 22:13 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
2008-10-16 22:12 561,688 —-a-w c:\windows\system32\wuapi.dll
2008-10-16 22:12 323,608 —-a-w c:\windows\system32\wucltui.dll
2008-10-16 22:09 92,696 —-a-w c:\windows\system32\cdm.dll
2008-10-16 22:09 51,224 —-a-w c:\windows\system32\wuauclt.exe
2008-10-16 22:09 43,544 —-a-w c:\windows\system32\wups2.dll
2008-10-16 22:08 34,328 —-a-w c:\windows\system32\wups.dll
2008-10-16 20:38 826,368 —-a-w c:\windows\system32\wininet.dll
2008-10-03 10:15 247,326 —-a-w c:\windows\system32\strmdll.dll
2008-10-01 00:43 1,286,152 —-a-w c:\windows\system32\msxml4.dll
2008-09-25 08:03 81,920 —-a-w c:\windows\system32\dpl100.dll
2008-09-25 08:03 593,920 —-a-w c:\windows\system32\dpuGUI11.dll
2008-09-25 08:03 57,344 —-a-w c:\windows\system32\dpv11.dll
2008-09-25 08:03 53,248 —-a-w c:\windows\system32\dpuGUI10.dll
2008-09-25 08:03 344,064 —-a-w c:\windows\system32\dpus11.dll
2008-09-25 08:03 294,912 —-a-w c:\windows\system32\dpu11.dll
2008-09-25 08:03 294,912 —-a-w c:\windows\system32\dpu10.dll
2008-09-25 08:03 196,608 —-a-w c:\windows\system32\dtu100.dll
2008-09-25 08:03 161,096 —-a-w c:\windows\system32\DivXCodecVersionChecker.exe
.
((((((((((((((((((((((((((((( snapshot@2008-12-24_15.12.31.15 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-12-25 00:23:35 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_250.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-10-21 50472]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2008-12-22 921600]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2008-05-16 13529088]
c:\documents and settings\Andrew\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk.disabled [2008-12-02 947]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk.disabled [2008-12-22 2335]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"PWRISOVM.EXE"=c:\program files\PowerISO\PWRISOVM.EXE
"nwiz"=nwiz.exe /install
"NvMediaCenter"=RUNDLL32.EXE c:\windows\System32\NvMcTray.dll,NvTaskbarInit
"Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe"
"NvCplDaemon"=RUNDLL32.EXE c:\windows\System32\NvCpl.dll,NvStartup
"NeroFilterCheck"=c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
""=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
S2 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\Viewpoint\Common\ViewpointService.exe" []
*Newly Created Service* - CATCHME
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: c:\windows\system32\imon.dll
O16 -: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd
O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
FF - ProfilePath - c:\documents and settings\Andrew\Application Data\Mozilla\Firefox\Profiles\rf4o9c22.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - WoW Armory
FF - prefs.js: browser.startup.homepage - hxxp://facebook.com
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-12-24 16:34:45
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'lsass.exe'(720)
c:\windows\system32\imon.dll
.
Completion time: 2008-12-24 16:35:46
ComboFix-quarantined-files.txt 2008-12-25 00:35:20
ComboFix2.txt 2008-12-25 00:29:08
ComboFix3.txt 2008-12-24 23:13:16
Pre-Run: 38,908,592,128 bytes free
Post-Run: 38,898,126,848 bytes free
266 — E O F — 2008-12-18 08:50:34
HiJackThis Log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:37:49 PM, on 12/24/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\AIM6\aim6.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk.disabled
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk.disabled
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Viewpoint Manager Service - Unknown owner - C:\Program Files\Viewpoint\Common\ViewpointService.exe (file missing)
–
End of file - 6672 bytes