Ok i've followed all of the instructions thus far and load time for start up is noticeably faster, I am very thankful of the help you have given, logs to follow
OTmoveit log
C:\Program Files\kernel moved successfully.
Created on 01/08/2008 19:58:19
Vundofix log
VundoFix V6.7.7
Checking Java version...
Scan started at 20:01:35 08/01/2008
Listing files found while scanning....
C:\WINDOWS\mrofinu572.exe
C:\WINDOWS\system32\iifgefd.dll
C:\WINDOWS\system32\ijllm.ini
C:\WINDOWS\system32\ijllm.ini2
C:\WINDOWS\system32\jkkkjhh.dll
C:\WINDOWS\system32\mllji.dll
C:\WINDOWS\system32\mllji.exe
C:\WINDOWS\system32\yayyxww.dll
Beginning removal...
Attempting to delete C:\WINDOWS\mrofinu572.exe
C:\WINDOWS\mrofinu572.exe Has been deleted!
Attempting to delete C:\WINDOWS\system32\iifgefd.dll
C:\WINDOWS\system32\iifgefd.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\ijllm.ini
C:\WINDOWS\system32\ijllm.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\ijllm.ini2
C:\WINDOWS\system32\ijllm.ini2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\jkkkjhh.dll
C:\WINDOWS\system32\jkkkjhh.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\mllji.dll
C:\WINDOWS\system32\mllji.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\mllji.exe
C:\WINDOWS\system32\mllji.exe Has been deleted!
Attempting to delete C:\WINDOWS\system32\yayyxww.dll
C:\WINDOWS\system32\yayyxww.dll Could not be deleted.
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\WINDOWS\system32\yayyxww.dll
C:\WINDOWS\system32\yayyxww.dll Could not be deleted.
Performing Repairs to the registry.
Done!
Beginning removal...
It would apear a file could not be deleted?
and CC log
ComboFix 08-01-07.5 - NotADMIN! 2008-01-08 20:30:12.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1708 [GMT 0:00]
Running from: C:\Documents and Settings\NotADMIN!\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\_OTMoveIt\MovedFiles\Program Files\kernel\kernel .exe
C:\Documents and Settings\NotADMIN!\Application Data\MANTEC~1
C:\Documents and Settings\NotADMIN!\Application Data\MANTEC~1\??mantec\
C:\Documents and Settings\NotADMIN!\Application Data\MANTEC~1\wucrtupd .exe
C:\Documents and Settings\NotADMIN!\Application Data\MANTEC~1\wucrtupd.exe
C:\Documents and Settings\NotADMIN!\Start Menu\Programs\Outerinfo
C:\Documents and Settings\NotADMIN!\Start Menu\Programs\Outerinfo\Terms.lnk
C:\Documents and Settings\NotADMIN!\Start Menu\Programs\Outerinfo\Uninstall.lnk
C:\Program Files\Ares\Ares .exe
C:\Program Files\Ares\Ares .exe
C:\Program Files\Ares\Ares .exe
C:\Program Files\Ares\Ares.exe
C:\Program Files\Messenger\msmsgs .exe
C:\Program Files\MSN\lawuhevol.dll
C:\Program Files\MSN\lawuhevol825.dll
C:\Program Files\MSN\lawuhevol878.dll
C:\Program Files\MSN\progyvaprak.html
C:\Program Files\Online Services\holenut4444.dll
C:\Program Files\Online Services\holenut83122.dll
C:\Program Files\outerinfo
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\WINDOWS\b122.exe
C:\WINDOWS\Downloaded Program Files\UGA6P_0001_N122M2210NetInstaller.exe
C:\WINDOWS\mrofinu1000106.exe
C:\WINDOWS\system32\dobe~1
C:\WINDOWS\system32\dobe~1\t?skmgr.exe
C:\WINDOWS\system32\ijllm.ini
C:\WINDOWS\system32\ijllm.ini2
C:\WINDOWS\system32\mllji.dll
C:\WINDOWS\system32\mllji.exe
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\RCXA.tmp
C:\WINDOWS\system32\wnsinticomsv32.exe
C:\WINDOWS\system32\wnsxs~1
C:\WINDOWS\system32\wnsxs~1\rotr.exe
C:\WINDOWS\system32\wnsxs~1\W?nSxS\
C:\WINDOWS\system32\xbc.dll
C:\WINDOWS\system32\yayyxww.dll
C:\WINDOWS\tk58.exe
Code:
<pre>
C:\Program Files\Messenger\msmsgs .exe ---> QooBox
C:\Program Files\Spybot - Search & Destroy\TeaTimer .exe ---> TeaTimer.exe
C:\_OTMoveIt\MovedFiles\Program Files\kernel\kernel .exe ---> QooBox
</pre>
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_CMDSERVICE
-------\LEGACY_NETWORK_MONITOR
((((((((((((((((((((((((( Files Created from 2007-12-08 to 2008-01-08 )))))))))))))))))))))))))))))))
.
2008-01-08 20:29 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-08 20:01 . 2008-01-08 20:23 <DIR> d-------- C:\VundoFix Backups
2008-01-08 18:06 . 2008-01-08 18:06 329,728 --a------ C:\WINDOWS\system32\RCX111.tmp
2008-01-08 18:00 . 2008-01-08 18:00 <DIR> d-------- C:\Documents and Settings\Unawesomesauce\Application Data\Ventrilo
2008-01-08 13:25 . 2008-01-08 13:25 <DIR> d-------- C:\Documents and Settings\Unawesomesauce\Application Data\Logitech
2008-01-08 13:25 . 2004-08-04 00:56 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-01-08 13:14 . 2008-01-08 13:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-08 12:52 . 2008-01-08 12:52 4,958,588 --a------ C:\WINDOWS\{00000002-00000000-0000000C-00001102-00000004-10021102}.BAK
2008-01-08 12:37 . 2008-01-08 12:37 <DIR> d-------- C:\Program Files\CCleaner
2008-01-08 12:32 . 2008-01-08 12:32 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-08 12:29 . 2008-01-08 12:29 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-01-08 12:22 . 2008-01-08 12:22 <DIR> d-------- C:\WINDOWS\system32\mi54
2008-01-08 12:22 . 2008-01-08 12:22 <DIR> d-------- C:\WINDOWS\system32\lo1
2008-01-08 12:22 . 2008-01-08 12:22 <DIR> d-------- C:\WINDOWS\system32\ardCo01
2008-01-08 12:22 . 2008-01-08 12:22 <DIR> d-------- C:\Temp\cEeer12
2008-01-08 12:22 . 2008-01-08 20:31 <DIR> d-------- C:\Temp
2008-01-08 12:22 . 2008-01-08 12:24 39,936 --a------ C:\WINDOWS\mrofinu572.exe.tmp
2008-01-08 12:17 . 2008-01-08 12:17 <DIR> d-------- C:\WINDOWS\Sun
2008-01-07 22:21 . 2008-01-07 22:21 <DIR> d-------- C:\Program Files\Miranda IM
2008-01-07 22:21 . 2008-01-07 22:21 <DIR> d-------- C:\Documents and Settings\NotADMIN!\Application Data\Miranda
2008-01-07 19:17 . 2008-01-07 19:17 <DIR> d-------- C:\Program Files\Ventrilo
2008-01-07 19:17 . 2008-01-07 19:17 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-07 19:12 . 2008-01-07 19:12 <DIR> d-------- C:\Program Files\Java
2008-01-07 19:12 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-01-07 19:11 . 2008-01-07 19:11 <DIR> d-------- C:\Program Files\Common Files\Java
2008-01-07 02:07 . 2008-01-07 22:21 <DIR> d-------- C:\Downloads
2008-01-07 02:07 . 2008-01-07 02:07 2,560 --a------ C:\WINDOWS\system32\bitcometres.dll
2008-01-07 02:06 . 2008-01-06 13:52 <DIR> d-------- C:\Program Files\BitComet
2008-01-06 16:11 . 2004-08-03 23:14 359,040 --a------ C:\WINDOWS\system32\drivers\tcpip.sys.ORIGINAL
2008-01-06 16:11 . 2008-01-06 16:11 359,040 --a--c--- C:\WINDOWS\system32\dllcache\tcpip.sys.ORIGINAL
2008-01-06 16:11 . 2008-01-06 16:11 359,040 --a--c--- C:\WINDOWS\system32\dllcache\tcpip.sys
2007-12-31 22:08 . 2007-12-31 22:08 <DIR> d-------- C:\Program Files\GCFScape
2007-12-31 20:39 . 2008-01-08 20:31 30,888 --a------ C:\WINDOWS\system32\BMXStateBkp-{00000002-00000000-0000000C-00001102-00000004-10021102}.rfx
2007-12-31 20:39 . 2008-01-08 20:31 30,888 --a------ C:\WINDOWS\system32\BMXState-{00000002-00000000-0000000C-00001102-00000004-10021102}.rfx
2007-12-31 20:39 . 2008-01-08 20:31 30,528 --a------ C:\WINDOWS\system32\BMXCtrlState-{00000002-00000000-0000000C-00001102-00000004-10021102}.rfx
2007-12-31 20:39 . 2008-01-08 20:31 30,528 --a------ C:\WINDOWS\system32\BMXBkpCtrlState-{00000002-00000000-0000000C-00001102-00000004-10021102}.rfx
2007-12-31 20:39 . 2008-01-08 20:31 11,564 --a------ C:\WINDOWS\system32\DVCState-{00000002-00000000-0000000C-00001102-00000004-10021102}.rfx
2007-12-31 20:39 . 2008-01-08 20:31 1,080 --a------ C:\WINDOWS\system32\settingsbkup.sfm
2007-12-31 20:39 . 2008-01-08 20:31 1,080 --a------ C:\WINDOWS\system32\settings.sfm
2007-12-31 20:38 . 2008-01-08 12:52 4,958,588 --a------ C:\WINDOWS\{00000002-00000000-0000000C-00001102-00000004-10021102}.CDF
2007-12-31 20:38 . 2000-12-05 09:11 4,174,814 --------- C:\WINDOWS\system32\CT4MGM.SF2
2007-12-31 20:38 . 2007-12-31 20:38 409,600 --a------ C:\WINDOWS\system32\wrap_oal.dll
2007-12-31 20:38 . 2006-08-11 15:14 86,446 --a------ C:\WINDOWS\system32\instwdm.ini
2007-12-31 20:38 . 2006-08-11 14:55 10,240 --a------ C:\WINDOWS\CTDCRES.DLL
2007-12-31 20:38 . 2006-08-11 14:56 3,072 --a------ C:\WINDOWS\CTXFIRES.DLL
2007-12-31 10:27 . 2008-01-01 00:31 <DIR> d-------- C:\Program Files\Cheat Engine
2007-12-31 10:27 . 2006-09-04 19:16 1,970,176 --a------ C:\WINDOWS\system32\d3dx9.dll
2007-12-31 10:27 . 2006-09-04 19:16 679,936 --a------ C:\WINDOWS\system32\D3DX81ab.dll
2007-12-29 00:23 . 2007-12-29 00:23 <DIR> d-------- C:\Program Files\Common Files\Adobe
2007-12-29 00:23 . 2007-12-29 00:23 <DIR> d-------- C:\Documents and Settings\NotADMIN!\Application Data\AdobeUM
2007-12-29 00:22 . 2007-12-29 00:22 <DIR> d-------- C:\WINDOWS\Cache
2007-12-29 00:18 . 2007-12-29 00:18 <DIR> d-------- C:\Program Files\Stardock
2007-12-29 00:18 . 2007-12-29 00:18 <DIR> d-------- C:\Program Files\Common Files\Stardock
2007-12-29 00:18 . 2002-01-05 06:40 487,424 --a------ C:\WINDOWS\system32\msvcp70.dll
2007-12-29 00:18 . 2002-01-05 07:37 344,064 --a------ C:\WINDOWS\system32\msvcr70.dll
2007-12-29 00:18 . 2002-01-05 06:38 54,784 --a------ C:\WINDOWS\system32\msvci70.dll
2007-12-29 00:18 . 2000-10-20 00:05 25,088 --a------ C:\WINDOWS\system32\msxml3a.dll
2007-12-21 16:47 . 2007-10-22 16:47 32 -ra------ C:\Documents and Settings\All Users\hash.dat
2007-12-21 16:39 . 2007-12-21 16:39 <DIR> d-------- C:\Program Files\Three Rings Design
2007-12-21 11:05 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2007-12-21 11:05 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2007-12-19 14:13 . 2007-12-19 14:13 <DIR> d-------- C:\Documents and Settings\NotADMIN!\Application Data\uqm
2007-12-18 21:19 . 2007-12-18 21:30 <DIR> d-------- C:\wankstain
2007-12-18 21:13 . 2007-12-18 21:13 <DIR> d---s---- C:\Documents and Settings\NotADMIN!\UserData
2007-12-18 21:11 . 2007-07-19 18:14 3,727,720 --a------ C:\WINDOWS\system32\d3dx9_35.dll
2007-12-18 20:50 . 2004-08-03 23:08 26,496 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2007-12-18 16:10 . 2007-12-18 16:10 <DIR> d-------- C:\Program Files\Hamachi
2007-12-18 16:10 . 2008-01-08 20:32 <DIR> d-------- C:\Documents and Settings\NotADMIN!\Application Data\Hamachi
2007-12-18 16:10 . 2007-12-18 16:10 25,280 --a------ C:\WINDOWS\system32\drivers\hamachi.sys
2007-12-18 00:17 . 2008-01-06 19:08 38 --a------ C:\WINDOWS\avisplitter.INI
2007-12-17 23:39 . 2007-12-17 23:39 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2007-12-17 23:33 . 2007-12-17 23:33 <DIR> d-------- C:\Documents and Settings\NotADMIN!\Application Data\vlc
2007-12-17 23:32 . 2007-12-17 23:32 <DIR> d-------- C:\Program Files\VideoLAN
2007-12-17 23:30 . 2008-01-08 20:31 <DIR> d-------- C:\Program Files\Ares
2007-12-17 20:56 . 2007-12-17 20:56 <DIR> d-------- C:\Program Files\Opera
2007-12-17 20:42 . 2007-12-17 20:42 <DIR> d-------- C:\Program Files\DAEMON Tools
2007-12-17 20:38 . 2007-12-17 20:38 646,392 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2007-12-17 20:32 . 2007-12-17 20:32 <DIR> d-------- C:\Program Files\Winamp
2007-12-17 20:32 . 2008-01-08 12:37 1,065 --a------ C:\WINDOWS\winamp.ini
2007-12-17 20:24 . 2007-12-17 20:24 <DIR> d-------- C:\Documents and Settings\NotADMIN!\Application Data\Ventrilo
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-06 16:11 359,040 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2007-12-31 20:38 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-31 20:38 --------- d-----w C:\Program Files\Creative
2007-12-31 20:38 --------- d-----w C:\Documents and Settings\NotADMIN!\Application Data\Creative
2007-12-31 20:36 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-12-17 18:32 --------- d-----w C:\Documents and Settings\NotADMIN!\Application Data\Logitech
2007-12-17 18:31 0 ---ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2007-12-17 18:31 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_LUsbFilt_01005.Wdf
2007-12-17 18:31 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2007-12-17 18:31 --------- d-----w C:\Program Files\Common Files\Logitech
2007-12-17 18:31 --------- d-----w C:\Program Files\Common Files\LogiShared
2007-12-17 18:31 --------- d-----w C:\Documents and Settings\NotADMIN!\Application Data\Leadertech
2007-12-17 18:30 --------- d-----w C:\Program Files\Logitech
2007-12-17 18:30 --------- d-----w C:\Documents and Settings\NotADMIN!\Application Data\InstallShield
2007-12-17 18:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Logitech
2007-12-17 18:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\LogiShrd
2007-12-17 18:28 --------- d-----w C:\Program Files\Microsoft ActiveSync
2007-12-17 18:12 --------- d-----w C:\Program Files\ATI Technologies
2007-12-17 18:08 --------- d-----w C:\Program Files\Intel
2007-12-17 17:30 --------- d-----w C:\Program Files\microsoft frontpage
2003-07-17 10:26 448,640 ----a-w C:\WINDOWS\inf\EL2K_N64.sys
2003-07-17 10:22 147,328 ----a-w C:\WINDOWS\inf\EL2K_XP.sys
2003-06-03 15:47 147,328 ----a-w C:\WINDOWS\inf\EL2K_2K.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ares"="C:\Program Files\Ares\Ares .exe" [ ]
"Atqt"="C:\WINDOWS\system32\?dobe\t?skmgr.exe" [ ]
"kernel"="C:\Program Files\kernel\kernel.exe" [ ]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-08 20:27 1460560]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 00:56 15360]
C:\Documents and Settings\NotADMIN!\Start Menu\Programs\Startup\
hamachi.lnk - C:\Program Files\Hamachi\hamachi.exe [2007-12-18 16:10:06]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-12-17 18:30:52]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^NotADMIN!^Start Menu^Programs^Startup^Product Registration.lnk]
path=C:\Documents and Settings\NotADMIN!\Start Menu\Programs\Startup\Product Registration.lnk
backup=C:\WINDOWS\pss\Product Registration.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
C:\Program Files\Ares\Ares.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
--a------ 2006-11-12 10:48 157592 C:\Program Files\DAEMON Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"cmdService"=2 (0x2)
R3 ctgame;Game Port;C:\WINDOWS\system32\DRIVERS\ctgame.sys [2002-12-30 10:53]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{63ba4b42-b4e4-11dc-bf50-000ea60716d8}]
\Shell\AutoRun\command - I:\NoAutoRun.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-08 20:32:31
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-08 20:33:13 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-08 20:33:04