ninety_black
2008-04-24, 01:20
Having a great time trying to get this off my computer. Thanks Kazaa!!
I was trying to fix this without posting (before I read the sticky) so I kind of already ran combo fix. Sorry if this has screwed something up. I'll post the first hijack this that was prior to combo fix, combo fix, and then the hijack that I ran after combo fix.
BEFORE COMBO FIX:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:44:17 PM, on 4/23/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
O2 - BHO: (no name) - {13C8D01F-6CEE-4456-B38E-369E9DB3D62C} - (no file)
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\NppBho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5CD40953-A9B9-48F3-BD1D-14348130B8ED} - C:\WINDOWS\system32\ssqOHbXP.dll (file missing)
O2 - BHO: (no name) - {7DBD297E-EEF0-47A8-8765-33471C0A017B} - (no file)
O2 - BHO: (no name) - {87E306D0-BFC2-41C6-9C40-3A0DC2653707} - C:\WINDOWS\system32\xxyvVLFu.dll (file missing)
O2 - BHO: (no name) - {9473a864-0d46-4045-aa3d-36194ffe1d0b} - (no file)
O2 - BHO: (no name) - {B364ABBA-49C8-48DB-B04F-2533FB0BC5E6} - C:\WINDOWS\system32\khfDvusr.dll (file missing)
O2 - BHO: (no name) - {e3d65d0f-43f2-45e4-9c25-a300487e6acf} - (no file)
O2 - BHO: (no name) - {EB10CB39-0C8E-4FF0-A73B-E20447CA249B} - C:\WINDOWS\system32\xxyvvVOh.dll (file missing)
O2 - BHO: (no name) - {EE5A1465-1E73-4784-8F63-45983FDF0DB8} - (no file)
O2 - BHO: (no name) - {F205E454-10A8-49A6-A2DC-8EAB747CB1E4} - (no file)
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\UIBHO.dll
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Instafinder] C:\Program Files\Instafinder\instafinder.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [04b8d3b4] rundll32.exe "C:\WINDOWS\system32\ioguetdf.dll",b
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: Rundll32.exe "C:\WINDOWS\system32\fokbofpf.dll",s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - S-1-5-18 Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Filter hijack: text/html - (no CLSID) - (no file)
O20 - Winlogon Notify: rqRKBUmL - C:\WINDOWS\
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
--
End of file - 6262 bytes
COMBO FIX:
ComboFix 08-04-22.5 - Nate 2008-04-23 17:46:45.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.103 [GMT -4:00]
Running from: C:\Documents and Settings\Nathan the Great\Desktop\ComboFix.exe
* Created a new restore point
[b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\cookies.ini
C:\WINDOWS\Fonts\a.zip
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\fccArSll.dll
C:\WINDOWS\system32\hOVvvyxx.ini
C:\WINDOWS\system32\hOVvvyxx.ini2
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\PXbHOqss.ini
C:\WINDOWS\system32\PXbHOqss.ini2
C:\WINDOWS\system32\rsuvDfhk.ini
C:\WINDOWS\system32\rsuvDfhk.ini2
C:\WINDOWS\system32\uFLVvyxx.ini
C:\WINDOWS\system32\uFLVvyxx.ini2
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CMDSERVICE
((((((((((((((((((((((((( Files Created from 2008-03-23 to 2008-04-23 )))))))))))))))))))))))))))))))
.
2008-04-23 17:46 . 2008-04-23 17:46 1,024 --ah----- C:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG
2008-04-23 16:30 . 2008-04-23 16:30 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-23 03:09 . 2008-04-23 03:09 <DIR> d-------- C:\VundoFix Backups
2008-04-23 02:05 . 2008-04-23 15:53 1,540,824 --ahs---- C:\WINDOWS\system32\fdteugoi.ini
2008-04-22 22:37 . 2008-04-22 22:37 <DIR> d-------- C:\WINDOWS\ERUNT
2008-04-22 22:35 . 2008-04-22 23:29 <DIR> d-------- C:\SDFix
2008-04-22 21:28 . 2008-04-23 01:02 1,541,029 --ahs---- C:\WINDOWS\system32\fbtfadbq.ini
2008-04-22 21:08 . 2008-04-22 21:08 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-04-22 19:41 . 2008-04-22 19:41 <DIR> d-------- C:\Documents and Settings\Administrator.USER-6D314D2170
2008-04-22 19:41 . 2008-04-23 17:46 1,024 --ah----- C:\Documents and Settings\Administrator.USER-6D314D2170\NTUSER.DAT.LOG
2008-04-22 17:05 . 2008-04-22 20:09 1,540,797 --ahs---- C:\WINDOWS\system32\hvbjowij.ini
2008-04-22 17:01 . 2008-04-22 20:21 2,374 --a------ C:\WINDOWS\system32\tmp.reg
2008-04-22 04:57 . 2008-04-23 15:26 385 --a------ C:\WINDOWS\wininit.ini
2008-04-22 02:53 . 2008-04-22 02:53 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-22 02:53 . 2008-04-22 02:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-22 02:16 . 2008-04-22 02:16 10,344 --a------ C:\WINDOWS\system32\drivers\symlcbrd.sys
2008-04-21 16:14 . 2008-04-21 20:05 1,540,644 --ahs---- C:\WINDOWS\system32\cyjgobek.ini
2008-04-21 13:44 . 2008-03-06 21:32 23,904 --a------ C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-04-21 13:44 . 2008-03-06 21:32 10,537 --a------ C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-04-21 13:44 . 2008-03-06 21:32 706 --a------ C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-04-21 04:17 . 2008-04-21 04:17 <DIR> d-------- C:\Documents and Settings\Nathan the Great\Application Data\Symantec
2008-04-21 03:36 . 2008-04-22 01:14 <DIR> d-------- C:\Program Files\Norton 360
2008-04-21 03:30 . 2008-04-21 04:54 123,952 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-04-21 03:30 . 2008-04-21 04:54 60,800 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-04-21 03:30 . 2008-04-21 04:54 10,740 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-04-21 03:30 . 2008-04-21 04:54 805 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-04-21 03:22 . 2008-04-21 04:54 <DIR> d-------- C:\Program Files\Symantec
2008-04-21 03:19 . 2008-04-21 20:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2008-04-21 03:16 . 2008-04-21 20:16 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2008-04-20 22:55 . 2008-04-20 22:55 <DIR> d-------- C:\Program Files\Lavasoft
2008-04-20 22:55 . 2008-04-20 22:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-20 22:52 . 2008-04-20 22:52 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-20 22:10 . 2008-04-22 21:17 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-20 16:09 . 2008-04-20 20:53 1,540,996 --ahs---- C:\WINDOWS\system32\ggpqcbnc.ini
2008-04-20 16:09 . 2008-04-23 03:55 109,794 --a------ C:\WINDOWS\BM078be028.xml
2008-04-20 16:01 . 2008-04-20 16:01 298,311 --a------ C:\WINDOWS\system32\gside.exe
2008-04-20 16:01 . 2008-04-20 16:01 88,961 --a------ C:\WINDOWS\system32\mysidesearch_sidebar_uninstall.exe
2008-04-20 07:01 . 2008-04-20 07:01 147,456 --a------ C:\WINDOWS\system32\vbzip10.dll
2008-04-20 02:32 . 2008-04-20 06:53 <DIR> d---s---- C:\Documents and Settings\Administrator
2008-04-20 02:32 . 2008-04-23 17:46 1,024 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT.LOG
2008-04-19 23:24 . 2008-04-19 23:24 399,930 --a------ C:\WINDOWS\system32\g87.exe
2008-04-19 23:24 . 2008-04-19 23:24 200,768 --a------ C:\WINDOWS\system32\tcntskdn.exe
2008-04-19 23:24 . 2008-04-19 23:24 863 --a------ C:\WINDOWS\system32\winpfz33.sys
2008-04-19 23:23 . 2008-04-21 15:11 <DIR> d-------- C:\WINDOWS\system32\xcsDd18
2008-04-19 23:23 . 2008-04-19 23:23 <DIR> d-------- C:\WINDOWS\system32\Vb1
2008-04-19 23:23 . 2008-04-21 15:10 <DIR> d-------- C:\WINDOWS\system32\trcTMP
2008-04-19 23:23 . 2008-04-19 23:23 <DIR> d-------- C:\WINDOWS\system32\slNew
2008-04-19 23:23 . 2008-04-21 00:47 <DIR> d-------- C:\WINDOWS\system32\iTmp
2008-04-19 23:23 . 2008-04-19 23:23 <DIR> d-------- C:\temp\berDrv11
2008-04-19 23:23 . 2008-04-19 23:23 37,888 --a------ C:\WINDOWS\system32\rqRKBUmL.dll.vir
2008-04-19 23:07 . 2008-04-21 13:11 <DIR> d-------- C:\Documents and Settings\Nathan the Great\Application Data\LimeWire
2008-04-19 23:03 . 2008-04-19 23:03 <DIR> d-------- C:\WINDOWS\Sun
2008-04-19 23:03 . 2008-04-19 23:06 <DIR> d-------- C:\Program Files\Google
2008-04-18 02:53 . 2008-03-01 09:06 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-04-18 02:53 . 2007-06-30 23:31 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-04-18 02:53 . 2007-06-30 23:36 991,232 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-04-18 02:53 . 2008-03-01 09:06 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-04-18 02:53 . 2008-03-01 09:06 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-04-18 02:53 . 2008-03-01 09:06 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-04-18 02:53 . 2008-03-01 09:06 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-04-18 02:53 . 2008-03-01 09:06 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-04-18 02:53 . 2008-02-22 06:00 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-04-17 22:43 . 2006-09-06 17:43 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-04-17 21:15 . 2008-04-17 21:15 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-04-17 20:17 . 2008-04-17 20:17 <DIR> d-------- C:\Program Files\Need2Find
2008-04-17 20:07 . 2008-04-17 20:07 249,856 --------- C:\WINDOWS\Setup1.exe
2008-04-17 20:07 . 2008-04-17 20:07 73,216 --a------ C:\WINDOWS\ST6UNST.EXE
2008-04-17 19:14 . 2008-04-17 19:14 <DIR> d--hs---- C:\Documents and Settings\Nathan the Great\UserData
2008-04-17 19:00 . 2008-04-17 19:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-04-17 18:58 . 2008-04-17 18:58 <DIR> d-------- C:\Program Files\Yahoo!
2008-04-17 18:50 . 2008-04-18 03:22 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-04-17 18:50 . 2005-11-24 19:51 245,248 --a------ C:\WINDOWS\system32\drivers\rt73.sys
2008-04-17 18:50 . 2003-10-13 15:30 94,208 --a------ C:\WINDOWS\system32\GTW32N50.dll
2008-04-17 18:50 . 2005-11-03 17:41 32,768 --a------ C:\WINDOWS\system32\GTGina.dll
2008-04-17 18:50 . 2003-09-25 23:28 31,930 --a------ C:\WINDOWS\system32\GTNDIS3.VXD
2008-04-17 18:50 . 2005-02-01 18:18 17,992 --a------ C:\WINDOWS\system32\drivers\bcm42rly.sys
2008-04-17 18:50 . 2005-02-01 18:18 17,992 --a------ C:\WINDOWS\system32\bcm42rly.sys
2008-04-17 18:50 . 2005-02-01 18:18 17,992 --a------ C:\WINDOWS\bcm42rly.sys
2008-04-17 18:50 . 2003-09-25 22:15 15,872 --a------ C:\WINDOWS\system32\GTNDIS5.sys
2008-04-17 18:48 . 2008-04-17 18:48 <DIR> d-------- C:\Linksys Driver
2008-04-14 23:45 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-04-14 23:45 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2008-04-08 19:33 . 2008-04-08 16:33 68,096 --------- C:\WINDOWS\b155.exe_old
2008-04-01 02:21 . 2008-04-01 02:22 <DIR> d-------- C:\Program Files\WinMilleBornes
2008-04-01 01:34 . 2008-04-01 01:34 <DIR> d-------- C:\Program Files\Driver-Soft
2008-04-01 01:34 . 2004-03-09 17:45 662,288 --a------ C:\WINDOWS\system32\MSCOMCT2.OCX
2008-03-25 05:00 . 2008-04-22 23:23 <DIR> d-------- C:\temp
2008-03-25 01:23 . 2008-04-20 20:51 <DIR> d-------- C:\quiz
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-14 06:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-03-21 22:04 --------- d-----w C:\Program Files\Microsoft Works
2008-03-21 22:03 --------- d-----w C:\Program Files\MSBuild
2008-03-21 21:36 --------- d-----w C:\Program Files\microsoft frontpage
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5CD40953-A9B9-48F3-BD1D-14348130B8ED}]
C:\WINDOWS\system32\ssqOHbXP.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{87E306D0-BFC2-41C6-9C40-3A0DC2653707}]
C:\WINDOWS\system32\xxyvVLFu.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B364ABBA-49C8-48DB-B04F-2533FB0BC5E6}]
C:\WINDOWS\system32\khfDvusr.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EB10CB39-0C8E-4FF0-A73B-E20447CA249B}]
C:\WINDOWS\system32\xxyvvVOh.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-28 08:00 15360]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-08-30 17:43 4670704]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-04-19 23:05 171448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 17:38 583048]
"Instafinder"="C:\Program Files\Instafinder\instafinder.exe" [ ]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 01:47 31016]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-07-17 21:54 116072]
"04b8d3b4"="C:\WINDOWS\system32\ioguetdf.dll" [ ]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [ ]
"BM078be028"="C:\WINDOWS\system32\fokbofpf.dll" [ ]
C:\Documents and Settings\Nathan the Great\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 21:24:54 98632]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rqRKBUmL]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= ctwdm32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Network Monitor"=2 (0x2)
"ccEvtMgr"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
*Newly Created Service* - COMHOST
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-23 17:56:27
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\devldr32.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\Ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2008-04-23 18:01:37 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-23 22:01:31
Pre-Run: 10,406,461,440 bytes free
Post-Run: 10,375,315,456 bytes free
202 --- E O F --- 2008-04-20 02:39:17
HIJACK RAN AFTER COMBOFIX:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:03:03 PM, on 4/23/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\NppBho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5CD40953-A9B9-48F3-BD1D-14348130B8ED} - C:\WINDOWS\system32\ssqOHbXP.dll (file missing)
O2 - BHO: (no name) - {87E306D0-BFC2-41C6-9C40-3A0DC2653707} - C:\WINDOWS\system32\xxyvVLFu.dll (file missing)
O2 - BHO: (no name) - {B364ABBA-49C8-48DB-B04F-2533FB0BC5E6} - C:\WINDOWS\system32\khfDvusr.dll (file missing)
O2 - BHO: (no name) - {EB10CB39-0C8E-4FF0-A73B-E20447CA249B} - C:\WINDOWS\system32\xxyvvVOh.dll (file missing)
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Instafinder] C:\Program Files\Instafinder\instafinder.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [04b8d3b4] rundll32.exe "C:\WINDOWS\system32\ioguetdf.dll",b
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [BM078be028] Rundll32.exe "C:\WINDOWS\system32\fokbofpf.dll",s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - S-1-5-18 Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: rqRKBUmL - C:\WINDOWS\
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
--
End of file - 5954 bytes
Thanks for any help
I was trying to fix this without posting (before I read the sticky) so I kind of already ran combo fix. Sorry if this has screwed something up. I'll post the first hijack this that was prior to combo fix, combo fix, and then the hijack that I ran after combo fix.
BEFORE COMBO FIX:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:44:17 PM, on 4/23/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
O2 - BHO: (no name) - {13C8D01F-6CEE-4456-B38E-369E9DB3D62C} - (no file)
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\NppBho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5CD40953-A9B9-48F3-BD1D-14348130B8ED} - C:\WINDOWS\system32\ssqOHbXP.dll (file missing)
O2 - BHO: (no name) - {7DBD297E-EEF0-47A8-8765-33471C0A017B} - (no file)
O2 - BHO: (no name) - {87E306D0-BFC2-41C6-9C40-3A0DC2653707} - C:\WINDOWS\system32\xxyvVLFu.dll (file missing)
O2 - BHO: (no name) - {9473a864-0d46-4045-aa3d-36194ffe1d0b} - (no file)
O2 - BHO: (no name) - {B364ABBA-49C8-48DB-B04F-2533FB0BC5E6} - C:\WINDOWS\system32\khfDvusr.dll (file missing)
O2 - BHO: (no name) - {e3d65d0f-43f2-45e4-9c25-a300487e6acf} - (no file)
O2 - BHO: (no name) - {EB10CB39-0C8E-4FF0-A73B-E20447CA249B} - C:\WINDOWS\system32\xxyvvVOh.dll (file missing)
O2 - BHO: (no name) - {EE5A1465-1E73-4784-8F63-45983FDF0DB8} - (no file)
O2 - BHO: (no name) - {F205E454-10A8-49A6-A2DC-8EAB747CB1E4} - (no file)
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\UIBHO.dll
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Instafinder] C:\Program Files\Instafinder\instafinder.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [04b8d3b4] rundll32.exe "C:\WINDOWS\system32\ioguetdf.dll",b
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: Rundll32.exe "C:\WINDOWS\system32\fokbofpf.dll",s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - S-1-5-18 Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Filter hijack: text/html - (no CLSID) - (no file)
O20 - Winlogon Notify: rqRKBUmL - C:\WINDOWS\
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
--
End of file - 6262 bytes
COMBO FIX:
ComboFix 08-04-22.5 - Nate 2008-04-23 17:46:45.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.103 [GMT -4:00]
Running from: C:\Documents and Settings\Nathan the Great\Desktop\ComboFix.exe
* Created a new restore point
[b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\cookies.ini
C:\WINDOWS\Fonts\a.zip
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\fccArSll.dll
C:\WINDOWS\system32\hOVvvyxx.ini
C:\WINDOWS\system32\hOVvvyxx.ini2
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\PXbHOqss.ini
C:\WINDOWS\system32\PXbHOqss.ini2
C:\WINDOWS\system32\rsuvDfhk.ini
C:\WINDOWS\system32\rsuvDfhk.ini2
C:\WINDOWS\system32\uFLVvyxx.ini
C:\WINDOWS\system32\uFLVvyxx.ini2
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CMDSERVICE
((((((((((((((((((((((((( Files Created from 2008-03-23 to 2008-04-23 )))))))))))))))))))))))))))))))
.
2008-04-23 17:46 . 2008-04-23 17:46 1,024 --ah----- C:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG
2008-04-23 16:30 . 2008-04-23 16:30 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-23 03:09 . 2008-04-23 03:09 <DIR> d-------- C:\VundoFix Backups
2008-04-23 02:05 . 2008-04-23 15:53 1,540,824 --ahs---- C:\WINDOWS\system32\fdteugoi.ini
2008-04-22 22:37 . 2008-04-22 22:37 <DIR> d-------- C:\WINDOWS\ERUNT
2008-04-22 22:35 . 2008-04-22 23:29 <DIR> d-------- C:\SDFix
2008-04-22 21:28 . 2008-04-23 01:02 1,541,029 --ahs---- C:\WINDOWS\system32\fbtfadbq.ini
2008-04-22 21:08 . 2008-04-22 21:08 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-04-22 19:41 . 2008-04-22 19:41 <DIR> d-------- C:\Documents and Settings\Administrator.USER-6D314D2170
2008-04-22 19:41 . 2008-04-23 17:46 1,024 --ah----- C:\Documents and Settings\Administrator.USER-6D314D2170\NTUSER.DAT.LOG
2008-04-22 17:05 . 2008-04-22 20:09 1,540,797 --ahs---- C:\WINDOWS\system32\hvbjowij.ini
2008-04-22 17:01 . 2008-04-22 20:21 2,374 --a------ C:\WINDOWS\system32\tmp.reg
2008-04-22 04:57 . 2008-04-23 15:26 385 --a------ C:\WINDOWS\wininit.ini
2008-04-22 02:53 . 2008-04-22 02:53 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-22 02:53 . 2008-04-22 02:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-22 02:16 . 2008-04-22 02:16 10,344 --a------ C:\WINDOWS\system32\drivers\symlcbrd.sys
2008-04-21 16:14 . 2008-04-21 20:05 1,540,644 --ahs---- C:\WINDOWS\system32\cyjgobek.ini
2008-04-21 13:44 . 2008-03-06 21:32 23,904 --a------ C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-04-21 13:44 . 2008-03-06 21:32 10,537 --a------ C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-04-21 13:44 . 2008-03-06 21:32 706 --a------ C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-04-21 04:17 . 2008-04-21 04:17 <DIR> d-------- C:\Documents and Settings\Nathan the Great\Application Data\Symantec
2008-04-21 03:36 . 2008-04-22 01:14 <DIR> d-------- C:\Program Files\Norton 360
2008-04-21 03:30 . 2008-04-21 04:54 123,952 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-04-21 03:30 . 2008-04-21 04:54 60,800 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-04-21 03:30 . 2008-04-21 04:54 10,740 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-04-21 03:30 . 2008-04-21 04:54 805 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-04-21 03:22 . 2008-04-21 04:54 <DIR> d-------- C:\Program Files\Symantec
2008-04-21 03:19 . 2008-04-21 20:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2008-04-21 03:16 . 2008-04-21 20:16 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2008-04-20 22:55 . 2008-04-20 22:55 <DIR> d-------- C:\Program Files\Lavasoft
2008-04-20 22:55 . 2008-04-20 22:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-20 22:52 . 2008-04-20 22:52 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-20 22:10 . 2008-04-22 21:17 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-20 16:09 . 2008-04-20 20:53 1,540,996 --ahs---- C:\WINDOWS\system32\ggpqcbnc.ini
2008-04-20 16:09 . 2008-04-23 03:55 109,794 --a------ C:\WINDOWS\BM078be028.xml
2008-04-20 16:01 . 2008-04-20 16:01 298,311 --a------ C:\WINDOWS\system32\gside.exe
2008-04-20 16:01 . 2008-04-20 16:01 88,961 --a------ C:\WINDOWS\system32\mysidesearch_sidebar_uninstall.exe
2008-04-20 07:01 . 2008-04-20 07:01 147,456 --a------ C:\WINDOWS\system32\vbzip10.dll
2008-04-20 02:32 . 2008-04-20 06:53 <DIR> d---s---- C:\Documents and Settings\Administrator
2008-04-20 02:32 . 2008-04-23 17:46 1,024 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT.LOG
2008-04-19 23:24 . 2008-04-19 23:24 399,930 --a------ C:\WINDOWS\system32\g87.exe
2008-04-19 23:24 . 2008-04-19 23:24 200,768 --a------ C:\WINDOWS\system32\tcntskdn.exe
2008-04-19 23:24 . 2008-04-19 23:24 863 --a------ C:\WINDOWS\system32\winpfz33.sys
2008-04-19 23:23 . 2008-04-21 15:11 <DIR> d-------- C:\WINDOWS\system32\xcsDd18
2008-04-19 23:23 . 2008-04-19 23:23 <DIR> d-------- C:\WINDOWS\system32\Vb1
2008-04-19 23:23 . 2008-04-21 15:10 <DIR> d-------- C:\WINDOWS\system32\trcTMP
2008-04-19 23:23 . 2008-04-19 23:23 <DIR> d-------- C:\WINDOWS\system32\slNew
2008-04-19 23:23 . 2008-04-21 00:47 <DIR> d-------- C:\WINDOWS\system32\iTmp
2008-04-19 23:23 . 2008-04-19 23:23 <DIR> d-------- C:\temp\berDrv11
2008-04-19 23:23 . 2008-04-19 23:23 37,888 --a------ C:\WINDOWS\system32\rqRKBUmL.dll.vir
2008-04-19 23:07 . 2008-04-21 13:11 <DIR> d-------- C:\Documents and Settings\Nathan the Great\Application Data\LimeWire
2008-04-19 23:03 . 2008-04-19 23:03 <DIR> d-------- C:\WINDOWS\Sun
2008-04-19 23:03 . 2008-04-19 23:06 <DIR> d-------- C:\Program Files\Google
2008-04-18 02:53 . 2008-03-01 09:06 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-04-18 02:53 . 2007-06-30 23:31 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-04-18 02:53 . 2007-06-30 23:36 991,232 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-04-18 02:53 . 2008-03-01 09:06 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-04-18 02:53 . 2008-03-01 09:06 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-04-18 02:53 . 2008-03-01 09:06 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-04-18 02:53 . 2008-03-01 09:06 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-04-18 02:53 . 2008-03-01 09:06 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-04-18 02:53 . 2008-02-22 06:00 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-04-17 22:43 . 2006-09-06 17:43 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-04-17 21:15 . 2008-04-17 21:15 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-04-17 20:17 . 2008-04-17 20:17 <DIR> d-------- C:\Program Files\Need2Find
2008-04-17 20:07 . 2008-04-17 20:07 249,856 --------- C:\WINDOWS\Setup1.exe
2008-04-17 20:07 . 2008-04-17 20:07 73,216 --a------ C:\WINDOWS\ST6UNST.EXE
2008-04-17 19:14 . 2008-04-17 19:14 <DIR> d--hs---- C:\Documents and Settings\Nathan the Great\UserData
2008-04-17 19:00 . 2008-04-17 19:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-04-17 18:58 . 2008-04-17 18:58 <DIR> d-------- C:\Program Files\Yahoo!
2008-04-17 18:50 . 2008-04-18 03:22 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-04-17 18:50 . 2005-11-24 19:51 245,248 --a------ C:\WINDOWS\system32\drivers\rt73.sys
2008-04-17 18:50 . 2003-10-13 15:30 94,208 --a------ C:\WINDOWS\system32\GTW32N50.dll
2008-04-17 18:50 . 2005-11-03 17:41 32,768 --a------ C:\WINDOWS\system32\GTGina.dll
2008-04-17 18:50 . 2003-09-25 23:28 31,930 --a------ C:\WINDOWS\system32\GTNDIS3.VXD
2008-04-17 18:50 . 2005-02-01 18:18 17,992 --a------ C:\WINDOWS\system32\drivers\bcm42rly.sys
2008-04-17 18:50 . 2005-02-01 18:18 17,992 --a------ C:\WINDOWS\system32\bcm42rly.sys
2008-04-17 18:50 . 2005-02-01 18:18 17,992 --a------ C:\WINDOWS\bcm42rly.sys
2008-04-17 18:50 . 2003-09-25 22:15 15,872 --a------ C:\WINDOWS\system32\GTNDIS5.sys
2008-04-17 18:48 . 2008-04-17 18:48 <DIR> d-------- C:\Linksys Driver
2008-04-14 23:45 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-04-14 23:45 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2008-04-08 19:33 . 2008-04-08 16:33 68,096 --------- C:\WINDOWS\b155.exe_old
2008-04-01 02:21 . 2008-04-01 02:22 <DIR> d-------- C:\Program Files\WinMilleBornes
2008-04-01 01:34 . 2008-04-01 01:34 <DIR> d-------- C:\Program Files\Driver-Soft
2008-04-01 01:34 . 2004-03-09 17:45 662,288 --a------ C:\WINDOWS\system32\MSCOMCT2.OCX
2008-03-25 05:00 . 2008-04-22 23:23 <DIR> d-------- C:\temp
2008-03-25 01:23 . 2008-04-20 20:51 <DIR> d-------- C:\quiz
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-14 06:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-03-21 22:04 --------- d-----w C:\Program Files\Microsoft Works
2008-03-21 22:03 --------- d-----w C:\Program Files\MSBuild
2008-03-21 21:36 --------- d-----w C:\Program Files\microsoft frontpage
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5CD40953-A9B9-48F3-BD1D-14348130B8ED}]
C:\WINDOWS\system32\ssqOHbXP.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{87E306D0-BFC2-41C6-9C40-3A0DC2653707}]
C:\WINDOWS\system32\xxyvVLFu.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B364ABBA-49C8-48DB-B04F-2533FB0BC5E6}]
C:\WINDOWS\system32\khfDvusr.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EB10CB39-0C8E-4FF0-A73B-E20447CA249B}]
C:\WINDOWS\system32\xxyvvVOh.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-28 08:00 15360]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-08-30 17:43 4670704]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-04-19 23:05 171448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 17:38 583048]
"Instafinder"="C:\Program Files\Instafinder\instafinder.exe" [ ]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 01:47 31016]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-07-17 21:54 116072]
"04b8d3b4"="C:\WINDOWS\system32\ioguetdf.dll" [ ]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [ ]
"BM078be028"="C:\WINDOWS\system32\fokbofpf.dll" [ ]
C:\Documents and Settings\Nathan the Great\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 21:24:54 98632]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rqRKBUmL]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= ctwdm32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Network Monitor"=2 (0x2)
"ccEvtMgr"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
*Newly Created Service* - COMHOST
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-23 17:56:27
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\devldr32.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\Ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2008-04-23 18:01:37 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-23 22:01:31
Pre-Run: 10,406,461,440 bytes free
Post-Run: 10,375,315,456 bytes free
202 --- E O F --- 2008-04-20 02:39:17
HIJACK RAN AFTER COMBOFIX:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:03:03 PM, on 4/23/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\NppBho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5CD40953-A9B9-48F3-BD1D-14348130B8ED} - C:\WINDOWS\system32\ssqOHbXP.dll (file missing)
O2 - BHO: (no name) - {87E306D0-BFC2-41C6-9C40-3A0DC2653707} - C:\WINDOWS\system32\xxyvVLFu.dll (file missing)
O2 - BHO: (no name) - {B364ABBA-49C8-48DB-B04F-2533FB0BC5E6} - C:\WINDOWS\system32\khfDvusr.dll (file missing)
O2 - BHO: (no name) - {EB10CB39-0C8E-4FF0-A73B-E20447CA249B} - C:\WINDOWS\system32\xxyvvVOh.dll (file missing)
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Instafinder] C:\Program Files\Instafinder\instafinder.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [04b8d3b4] rundll32.exe "C:\WINDOWS\system32\ioguetdf.dll",b
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [BM078be028] Rundll32.exe "C:\WINDOWS\system32\fokbofpf.dll",s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - S-1-5-18 Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: rqRKBUmL - C:\WINDOWS\
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
--
End of file - 5954 bytes
Thanks for any help