I think I got it FINALLY but wanted to post the following logs to be sure:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:35:56 PM, on 11/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
I:\WINDOWS\System32\smss.exe
I:\WINDOWS\system32\winlogon.exe
I:\WINDOWS\system32\services.exe
I:\WINDOWS\system32\lsass.exe
I:\WINDOWS\system32\svchost.exe
I:\WINDOWS\System32\svchost.exe
I:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
I:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
I:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
I:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
I:\WINDOWS\system32\spoolsv.exe
I:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
I:\Program Files\Symantec AntiVirus\DefWatch.exe
I:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\DLSDBNT.EXE
I:\Program Files\Norton Ghost\Agent\VProSvc.exe
I:\WINDOWS\system32\nvsvc32.exe
I:\WINDOWS\system32\svchost.exe
I:\Program Files\Symantec AntiVirus\Rtvscan.exe
I:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\DLPWDNT.EXE
I:\PROGRA~1\SYMANT~1\VPTray.exe
I:\Program Files\Norton Ghost\Agent\VProTray.exe
I:\Program Files\Common Files\Symantec Shared\ccApp.exe
I:\Program Files\Microsoft ActiveSync\wcescomm.exe
I:\WINDOWS\system32\ctfmon.exe
I:\Program Files\Energizer FileSaver\Energizer FileSaver.exe
I:\PROGRA~1\MI3AA1~1\rapimgr.exe
I:\WINDOWS\System32\svchost.exe
I:\WINDOWS\explorer.exe
I:\WINDOWS\system32\notepad.exe
I:\Program Files\Internet Explorer\iexplore.exe
I:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://drudgereport.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - I:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - I:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - I:\Program Files\TechSmith\SnagIt 9\SnagItIEAddin.dll
O4 - HKLM\..\Run: [vptray] I:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Norton Ghost 12.0] "I:\Program Files\Norton Ghost\Agent\VProTray.exe"
O4 - HKLM\..\Run: [ccApp] "I:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE I:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [H/PC Connection Agent] "I:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [ctfmon.exe] I:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Energizer FileSaver.lnk = I:\Program Files\Energizer FileSaver\Energizer FileSaver.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://I:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://I:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://I:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://I:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://I:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://I:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://I:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://I:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://I:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - I:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - I:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - I:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - I:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - I:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - I:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - I:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - I:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - I:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - I:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - I:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - I:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://atl.rexplorer.net
O15 - Trusted Zone: http://www.tdameritrade.com
O15 - Trusted Zone: *.tdameritrade.com
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {2FE68711-8830-417D-95E0-EAB307DB0447} (mpsPwLc7.PMWebSiteLogin) - https://prolog.c-b.com/pw/mpsPwLc7.CAB
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD39/JSCDL...-jc.cab&File=jinstall-6u5-windows-i586-jc.cab
O16 - DPF: {F375116A-793C-11D2-BFE1-444553540001} (First American Res MapActiveX Control) - http://realist2.firstamres.com/mapviewer/mapviewer.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O17 - HKLM\System\CCS\Services\Tcpip\..\{EE825216-61D2-4E6A-825A-EE7EFD2B9B74}: NameServer = 207.69.188.186,207.69.188.187
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - I:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - I:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - I:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - I:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - I:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - I:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Dell Printer Status Watcher (DLPWD) - Dell Inc. - I:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\DLPWDNT.EXE
O23 - Service: Dell Printer Status Database (DLSDB) - Dell Inc. - I:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\DLSDBNT.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - I:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - I:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton Ghost - Symantec Corporation - I:\Program Files\Norton Ghost\Agent\VProSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - I:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - I:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - I:\Program Files\Symantec AntiVirus\Rtvscan.exe
--
End of file - 9547 bytes
AND:
ComboFix 08-11-07.01 - Gero 2008-11-07 15:21:06.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1489 [GMT -5:00]
Running from: i:\documents and settings\Gero\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
i:\documents and settings\Gero\Application Data\shcn7wj0en95
i:\windows\system32\_cbXrQHbb.dll
i:\windows\system32\_itphdq.dll
i:\windows\system32\_rvfgst.dll
i:\windows\system32\_tuvSJCsQ.dll
i:\windows\system32\_vtUmNHYs.dll
i:\windows\system32\adKQAJjl.ini
i:\windows\system32\bbHQrXbc.ini
i:\windows\system32\CbKSAJjl.ini
i:\windows\system32\ehRYyJlm.ini
i:\windows\system32\ffokvnfc.dll
i:\windows\system32\fwjmjnej.dll
i:\windows\system32\geBstroL.dll
i:\windows\system32\gmjblsmy.dll
i:\windows\system32\klUBHkkj.ini
i:\windows\system32\knoUCcdd.ini
i:\windows\system32\lSDJknmp.ini
i:\windows\system32\lSDJknmp.ini2
i:\windows\system32\mcrh.tmp
i:\windows\system32\MUDKUvut.ini
i:\windows\system32\nnnnKeCs.dll
i:\windows\system32\omvpkexs.dll
i:\windows\system32\phcg7wj0en95.bmp
i:\windows\system32\pmnkJDSl.dll
i:\windows\system32\QsCJSvut.ini
i:\windows\system32\sstpsyyy.ini
i:\windows\system32\sxxcpexu.ini
i:\windows\system32\sYHNmUtv.ini
i:\windows\system32\trfwjd.dll
i:\windows\system32\utevxdpy.dll
i:\windows\system32\uypkxysi.ini
i:\windows\system32\vbmryqvh.dll
i:\windows\system32\vGfMoUvw.ini
i:\windows\system32\wklhkktj.dll
i:\windows\system32\xfwnrafi.dll
i:\windows\system32\yymabmdx.dll
.
((((((((((((((((((((((((( Files Created from 2008-10-07 to 2008-11-07 )))))))))))))))))))))))))))))))
.
2008-11-06 22:16 . 2008-11-07 00:16 <DIR> d-------- i:\documents and settings\Gero\I386
2008-11-06 21:20 . 2008-11-06 21:40 <DIR> d-------- i:\program files\Spybot - Search & Destroy
2008-11-06 21:20 . 2008-11-06 22:07 <DIR> d-------- i:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-06 21:13 . 2001-08-23 15:00 11,037 --a------ i:\windows\system32\RUNDLL32.EX_
2008-11-06 19:30 . 2008-10-16 14:07 23,576 --a------ i:\windows\system32\wuapi.dll.mui
2008-11-06 06:40 . 2008-11-06 06:40 313,856 --a------ i:\windows\system32\_ddcCUonk.dll
2008-11-01 12:17 . 2001-08-17 14:56 66,048 --a--c--- i:\windows\system32\dllcache\s3legacy.dll
2008-10-14 18:40 . 2008-10-14 18:40 <DIR> d-------- i:\documents and settings\All Users\Application Data\Blizzard
2008-10-08 12:47 . 2008-11-05 23:29 4,196,675 --a------ i:\windows\pfirewall.log.old
2008-10-07 10:42 . 2008-10-07 10:42 99,584 --a------ i:\windows\system32\drivers\ndisio.sys
2008-10-07 10:42 . 2008-10-07 10:42 33,792 ---h----- i:\documents and settings\Gero\bvxmg.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-07 20:24 --------- d-----w i:\program files\Symantec AntiVirus
2008-11-07 20:17 --------- d-----w i:\documents and settings\Gero\Application Data\BitTorrent
2008-10-29 04:10 --------- d-----w i:\documents and settings\All Users\Application Data\Microsoft Help
2008-10-06 23:25 --------- d-----w i:\program files\Common Files\Blizzard Entertainment
2008-10-03 05:29 --------- d-----w i:\program files\iTunes
2008-10-03 05:29 --------- d-----w i:\program files\iPod
2008-10-03 05:29 --------- d-----w i:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-03 05:28 --------- d-----w i:\program files\QuickTime
2008-10-03 05:28 --------- d-----w i:\program files\Common Files\Apple
2008-10-03 05:28 --------- d-----w i:\program files\Bonjour
2008-10-03 05:27 --------- d-----w i:\program files\Apple Software Update
2008-09-09 23:24 --------- d-----w i:\program files\DivX
2008-09-09 00:54 --------- d-----w i:\program files\WinISO
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="i:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"ctfmon.exe"="i:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"vptray"="i:\progra~1\SYMANT~1\VPTray.exe" [2006-09-27 125168]
"Norton Ghost 12.0"="i:\program files\Norton Ghost\Agent\VProTray.exe" [2008-01-10 2037088]
"ccApp"="i:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-07-19 52896]
"NvCplDaemon"="i:\windows\system32\NvCpl.dll" [2007-12-05 8523776]
i:\documents and settings\All Users\Start Menu\Programs\Startup\
Energizer FileSaver.lnk - i:\program files\Energizer FileSaver\Energizer FileSaver.exe [2003-02-19 976896]
[HKLM\~\startupfolder\I:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=i:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=i:\windows\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
--a------ 2004-12-14 02:12 483328 i:\program files\Adobe\Acrobat 7.0\Distillr\acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
--a------ 2008-10-12 21:22 287040 i:\program files\DNA\btdna.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 07:00 15360 i:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell MFP Color Laser Printer 3115cn Launcher]
--a------ 2006-12-23 14:38 635800 i:\program files\Dell Printers\Dell MFP Color Laser Printer 3115cn\Address Book Editor\Launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DLPSP]
--a------ 2006-12-07 16:52 340888 i:\program files\Dell Printers\Additional Color Laser Software\Status Monitor\dlpsp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 2006-10-27 00:47 31016 i:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
--a------ 2006-11-13 13:39 1289000 i:\program files\Microsoft ActiveSync\wcescomm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndexSearch]
--a------ 2006-06-30 18:08 40960 i:\program files\Dell Printers\paperport\IndexSearch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-10-01 17:57 289576 i:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2006-01-12 14:40 155648 i:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2007-12-05 01:41 8523776 i:\windows\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2007-12-05 01:41 81920 i:\windows\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaperPort PTD]
--a------ 2006-06-30 18:08 36864 i:\program files\Dell Printers\paperport\pptd40nt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-06 14:09 413696 i:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a------ 2004-11-02 20:24 32768 i:\program files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
--------- 2003-10-14 10:22 155648 i:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-02-22 03:25 144784 i:\program files\Java\jre1.6.0_05\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-08-30 17:43 4670704 i:\program files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2007-12-05 01:41 1626112 i:\windows\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"iPod Service"=3 (0x3)
"Apple Mobile Device"=2 (0x2)
"WZCSVC"=2 (0x2)
"FastUserSwitchingCompatibility"=3 (0x3)
"WMPNetworkSvc"=3 (0x3)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"Microsoft Office Groove Audit Service"=3 (0x3)
"Adobe LM Service"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"i:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"i:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"i:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"i:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"i:\program files\Microsoft ActiveSync\rapimgr.exe"= i:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"i:\program files\Microsoft ActiveSync\wcescomm.exe"= i:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"i:\program files\Microsoft ActiveSync\WCESMgr.exe"= i:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"i:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\World of Warcraft\\BackgroundDownloader.exe"=
"i:\\Program Files\\iTunes\\iTunes.exe"=
"i:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\World of Warcraft\\WoW-2.4.3-to-3.0.2-enUS-Win-Final-downloader.exe"=
"c:\\World of Warcraft\\WoW-1.12.x-to-2.0.1-enUS-patch-downloader.exe"=
"c:\\World of Warcraft\\WoW-1.12.0-enUS-downloader.exe"=
"i:\\WINDOWS\\explorer.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"6881:TCP"= 6881:TCP:Blizzard Downloader: 6881
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"6112:TCP"= 6112:TCP:Blizzard Downloader
"8086:TCP"= 8086:TCP:*
isabled:Blizzard
"9081:TCP"= 9081:TCP:Blizzard
"9090:TCP"= 9090:TCP:Blizzard
"9097:TCP"= 9097:TCP:Blizzard
"9100:TCP"= 9100:TCP:Blizzard
R2 DLSDB;Dell Printer Status Database;i:\program files\Dell Printers\Additional Color Laser Software\Status Monitor\DLSDBNT.EXE [2006-12-07 140184]
.
Contents of the 'Scheduled Tasks' folder
2008-11-04 i:\windows\Tasks\AppleSoftwareUpdate.job
- i:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2008-11-07 i:\windows\Tasks\At1.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-07 i:\windows\Tasks\At10.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-07 i:\windows\Tasks\At11.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-07 i:\windows\Tasks\At12.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-07 i:\windows\Tasks\At13.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-07 i:\windows\Tasks\At14.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-07 i:\windows\Tasks\At15.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-07 i:\windows\Tasks\At16.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-06 i:\windows\Tasks\At17.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-06 i:\windows\Tasks\At18.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-06 i:\windows\Tasks\At19.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-07 i:\windows\Tasks\At2.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-07 i:\windows\Tasks\At20.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-06 i:\windows\Tasks\At21.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-07 i:\windows\Tasks\At22.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-07 i:\windows\Tasks\At23.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-07 i:\windows\Tasks\At24.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-07 i:\windows\Tasks\At25.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-07 i:\windows\Tasks\At26.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-07 i:\windows\Tasks\At27.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-07 i:\windows\Tasks\At28.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-07 i:\windows\Tasks\At29.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-07 i:\windows\Tasks\At3.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-07 i:\windows\Tasks\At30.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-07 i:\windows\Tasks\At31.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-07 i:\windows\Tasks\At32.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-07 i:\windows\Tasks\At33.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-07 i:\windows\Tasks\At34.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-07 i:\windows\Tasks\At35.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-07 i:\windows\Tasks\At36.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-07 i:\windows\Tasks\At37.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-07 i:\windows\Tasks\At38.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-07 i:\windows\Tasks\At39.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-07 i:\windows\Tasks\At4.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-07 i:\windows\Tasks\At40.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-06 i:\windows\Tasks\At41.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-06 i:\windows\Tasks\At42.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-06 i:\windows\Tasks\At43.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-07 i:\windows\Tasks\At44.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-06 i:\windows\Tasks\At45.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-07 i:\windows\Tasks\At46.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-07 i:\windows\Tasks\At47.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-07 i:\windows\Tasks\At48.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-07 i:\windows\Tasks\At5.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-07 i:\windows\Tasks\At6.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-07 i:\windows\Tasks\At7.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-07 i:\windows\Tasks\At8.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-07 i:\windows\Tasks\At9.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-03 i:\windows\Tasks\Backup.job
- i:\windows\system32\ntbackup.exe [2004-08-04 07:00]
2008-11-07 i:\windows\Tasks\backupincremental.job
- i:\windows\system32\ntbackup.exe [2004-08-04 07:00]
.
- - - - ORPHANS REMOVED - - - -
BHO-{069A035F-78BA-48CB-889A-64F07D2B7A29} - i:\windows\system32\pmnkJDSl.dll
BHO-{6ED59772-F4EB-4FDE-BBB3-E939952686BF} - i:\windows\system32\nnnnKeCs.dll
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
ShellExecuteHooks-{6ED59772-F4EB-4FDE-BBB3-E939952686BF} - i:\windows\system32\nnnnKeCs.dll
MSConfigStartUp-088bbec6 - i:\windows\system32\yymabmdx.dll
MSConfigStartUp-BitZip - Powered by Miro - i:\program files\Participatory Culture Foundation\Miro\Miro.exe
MSConfigStartUp-lphcg7wj0en95 - i:\windows\system32\lphcg7wj0en95.exe
MSConfigStartUp-mkymm - i:\windows\system32\mkymm.exe
MSConfigStartUp-SearchSettings - i:\program files\Search Settings\SearchSettings.exe
MSConfigStartUp-SMshcn7wj0en95 - i:\program files\shcn7wj0en95\shcn7wj0en95.exe
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://drudgereport.com/
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
O8 -: Convert link target to Adobe PDF - i:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 -: Convert link target to existing PDF - i:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 -: Convert selected links to Adobe PDF - i:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 -: Convert selected links to existing PDF - i:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 -: Convert selection to Adobe PDF - i:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 -: Convert selection to existing PDF - i:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 -: Convert to Adobe PDF - i:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 -: Convert to existing PDF - i:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 -: E&xport to Microsoft Excel - i:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
O15 -: Trusted Zone: *.tdameritrade.com
O17 -: HKLM\CCS\Interface\{EE825216-61D2-4E6A-825A-EE7EFD2B9B74}: NameServer = 207.69.188.186,207.69.188.187
O16 -: {2FE68711-8830-417D-95E0-EAB307DB0447} - hxxps://prolog.c-b.com/pw/mpsPwLc7.CAB
i:\windows\Downloaded Program Files\mpsPwLc6.inf
i:\windows\system32\msvbvm60.dll
i:\windows\system32\oleaut32.dll
i:\windows\system32\olepro32.dll
i:\windows\system32\asycfilt.dll
i:\windows\system32\stdole2.tlb
i:\windows\system32\comcat.dll
i:\windows\Downloaded Program Files\mpsPwLc7.ocx
O16 -: {F375116A-793C-11D2-BFE1-444553540001} - hxxp://realist2.firstamres.com/mapviewer/mapviewer.cab
i:\windows\Downloaded Program Files\mapviewer.ocx
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-07 15:25:08
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
i:\program files\Common Files\Symantec Shared\ccSetMgr.exe
i:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
i:\program files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
i:\program files\Lavasoft\Ad-Aware\aawservice.exe
i:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
i:\program files\Symantec AntiVirus\DefWatch.exe
i:\program files\Norton Ghost\Agent\VProSvc.exe
i:\windows\system32\nvsvc32.exe
i:\program files\Symantec AntiVirus\Rtvscan.exe
i:\program files\Dell Printers\Additional Color Laser Software\Status Monitor\dlpwdnt.exe
i:\progra~1\MI3AA1~1\rapimgr.exe
.
**************************************************************************
.
Completion time: 2008-11-07 15:28:10 - machine was rebooted [Gero]
ComboFix-quarantined-files.txt 2008-11-07 20:28:06
Pre-Run: 254,863,142,912 bytes free
Post-Run: 254,840,377,344 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
i:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
354 --- E O F --- 2008-10-29 02:14:49
THANK YOU SO MUCH IN ADVANCE!!!
Gerie
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:35:56 PM, on 11/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
I:\WINDOWS\System32\smss.exe
I:\WINDOWS\system32\winlogon.exe
I:\WINDOWS\system32\services.exe
I:\WINDOWS\system32\lsass.exe
I:\WINDOWS\system32\svchost.exe
I:\WINDOWS\System32\svchost.exe
I:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
I:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
I:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
I:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
I:\WINDOWS\system32\spoolsv.exe
I:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
I:\Program Files\Symantec AntiVirus\DefWatch.exe
I:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\DLSDBNT.EXE
I:\Program Files\Norton Ghost\Agent\VProSvc.exe
I:\WINDOWS\system32\nvsvc32.exe
I:\WINDOWS\system32\svchost.exe
I:\Program Files\Symantec AntiVirus\Rtvscan.exe
I:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\DLPWDNT.EXE
I:\PROGRA~1\SYMANT~1\VPTray.exe
I:\Program Files\Norton Ghost\Agent\VProTray.exe
I:\Program Files\Common Files\Symantec Shared\ccApp.exe
I:\Program Files\Microsoft ActiveSync\wcescomm.exe
I:\WINDOWS\system32\ctfmon.exe
I:\Program Files\Energizer FileSaver\Energizer FileSaver.exe
I:\PROGRA~1\MI3AA1~1\rapimgr.exe
I:\WINDOWS\System32\svchost.exe
I:\WINDOWS\explorer.exe
I:\WINDOWS\system32\notepad.exe
I:\Program Files\Internet Explorer\iexplore.exe
I:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://drudgereport.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - I:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - I:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - I:\Program Files\TechSmith\SnagIt 9\SnagItIEAddin.dll
O4 - HKLM\..\Run: [vptray] I:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Norton Ghost 12.0] "I:\Program Files\Norton Ghost\Agent\VProTray.exe"
O4 - HKLM\..\Run: [ccApp] "I:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE I:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [H/PC Connection Agent] "I:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [ctfmon.exe] I:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Energizer FileSaver.lnk = I:\Program Files\Energizer FileSaver\Energizer FileSaver.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://I:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://I:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://I:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://I:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://I:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://I:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://I:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://I:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://I:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - I:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - I:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - I:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - I:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - I:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - I:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - I:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - I:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - I:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - I:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - I:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - I:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://atl.rexplorer.net
O15 - Trusted Zone: http://www.tdameritrade.com
O15 - Trusted Zone: *.tdameritrade.com
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {2FE68711-8830-417D-95E0-EAB307DB0447} (mpsPwLc7.PMWebSiteLogin) - https://prolog.c-b.com/pw/mpsPwLc7.CAB
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD39/JSCDL...-jc.cab&File=jinstall-6u5-windows-i586-jc.cab
O16 - DPF: {F375116A-793C-11D2-BFE1-444553540001} (First American Res MapActiveX Control) - http://realist2.firstamres.com/mapviewer/mapviewer.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O17 - HKLM\System\CCS\Services\Tcpip\..\{EE825216-61D2-4E6A-825A-EE7EFD2B9B74}: NameServer = 207.69.188.186,207.69.188.187
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - I:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - I:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - I:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - I:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - I:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - I:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Dell Printer Status Watcher (DLPWD) - Dell Inc. - I:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\DLPWDNT.EXE
O23 - Service: Dell Printer Status Database (DLSDB) - Dell Inc. - I:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\DLSDBNT.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - I:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - I:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton Ghost - Symantec Corporation - I:\Program Files\Norton Ghost\Agent\VProSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - I:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - I:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - I:\Program Files\Symantec AntiVirus\Rtvscan.exe
--
End of file - 9547 bytes
AND:
ComboFix 08-11-07.01 - Gero 2008-11-07 15:21:06.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1489 [GMT -5:00]
Running from: i:\documents and settings\Gero\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
i:\documents and settings\Gero\Application Data\shcn7wj0en95
i:\windows\system32\_cbXrQHbb.dll
i:\windows\system32\_itphdq.dll
i:\windows\system32\_rvfgst.dll
i:\windows\system32\_tuvSJCsQ.dll
i:\windows\system32\_vtUmNHYs.dll
i:\windows\system32\adKQAJjl.ini
i:\windows\system32\bbHQrXbc.ini
i:\windows\system32\CbKSAJjl.ini
i:\windows\system32\ehRYyJlm.ini
i:\windows\system32\ffokvnfc.dll
i:\windows\system32\fwjmjnej.dll
i:\windows\system32\geBstroL.dll
i:\windows\system32\gmjblsmy.dll
i:\windows\system32\klUBHkkj.ini
i:\windows\system32\knoUCcdd.ini
i:\windows\system32\lSDJknmp.ini
i:\windows\system32\lSDJknmp.ini2
i:\windows\system32\mcrh.tmp
i:\windows\system32\MUDKUvut.ini
i:\windows\system32\nnnnKeCs.dll
i:\windows\system32\omvpkexs.dll
i:\windows\system32\phcg7wj0en95.bmp
i:\windows\system32\pmnkJDSl.dll
i:\windows\system32\QsCJSvut.ini
i:\windows\system32\sstpsyyy.ini
i:\windows\system32\sxxcpexu.ini
i:\windows\system32\sYHNmUtv.ini
i:\windows\system32\trfwjd.dll
i:\windows\system32\utevxdpy.dll
i:\windows\system32\uypkxysi.ini
i:\windows\system32\vbmryqvh.dll
i:\windows\system32\vGfMoUvw.ini
i:\windows\system32\wklhkktj.dll
i:\windows\system32\xfwnrafi.dll
i:\windows\system32\yymabmdx.dll
.
((((((((((((((((((((((((( Files Created from 2008-10-07 to 2008-11-07 )))))))))))))))))))))))))))))))
.
2008-11-06 22:16 . 2008-11-07 00:16 <DIR> d-------- i:\documents and settings\Gero\I386
2008-11-06 21:20 . 2008-11-06 21:40 <DIR> d-------- i:\program files\Spybot - Search & Destroy
2008-11-06 21:20 . 2008-11-06 22:07 <DIR> d-------- i:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-06 21:13 . 2001-08-23 15:00 11,037 --a------ i:\windows\system32\RUNDLL32.EX_
2008-11-06 19:30 . 2008-10-16 14:07 23,576 --a------ i:\windows\system32\wuapi.dll.mui
2008-11-06 06:40 . 2008-11-06 06:40 313,856 --a------ i:\windows\system32\_ddcCUonk.dll
2008-11-01 12:17 . 2001-08-17 14:56 66,048 --a--c--- i:\windows\system32\dllcache\s3legacy.dll
2008-10-14 18:40 . 2008-10-14 18:40 <DIR> d-------- i:\documents and settings\All Users\Application Data\Blizzard
2008-10-08 12:47 . 2008-11-05 23:29 4,196,675 --a------ i:\windows\pfirewall.log.old
2008-10-07 10:42 . 2008-10-07 10:42 99,584 --a------ i:\windows\system32\drivers\ndisio.sys
2008-10-07 10:42 . 2008-10-07 10:42 33,792 ---h----- i:\documents and settings\Gero\bvxmg.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-07 20:24 --------- d-----w i:\program files\Symantec AntiVirus
2008-11-07 20:17 --------- d-----w i:\documents and settings\Gero\Application Data\BitTorrent
2008-10-29 04:10 --------- d-----w i:\documents and settings\All Users\Application Data\Microsoft Help
2008-10-06 23:25 --------- d-----w i:\program files\Common Files\Blizzard Entertainment
2008-10-03 05:29 --------- d-----w i:\program files\iTunes
2008-10-03 05:29 --------- d-----w i:\program files\iPod
2008-10-03 05:29 --------- d-----w i:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-03 05:28 --------- d-----w i:\program files\QuickTime
2008-10-03 05:28 --------- d-----w i:\program files\Common Files\Apple
2008-10-03 05:28 --------- d-----w i:\program files\Bonjour
2008-10-03 05:27 --------- d-----w i:\program files\Apple Software Update
2008-09-09 23:24 --------- d-----w i:\program files\DivX
2008-09-09 00:54 --------- d-----w i:\program files\WinISO
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="i:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"ctfmon.exe"="i:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"vptray"="i:\progra~1\SYMANT~1\VPTray.exe" [2006-09-27 125168]
"Norton Ghost 12.0"="i:\program files\Norton Ghost\Agent\VProTray.exe" [2008-01-10 2037088]
"ccApp"="i:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-07-19 52896]
"NvCplDaemon"="i:\windows\system32\NvCpl.dll" [2007-12-05 8523776]
i:\documents and settings\All Users\Start Menu\Programs\Startup\
Energizer FileSaver.lnk - i:\program files\Energizer FileSaver\Energizer FileSaver.exe [2003-02-19 976896]
[HKLM\~\startupfolder\I:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=i:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=i:\windows\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
--a------ 2004-12-14 02:12 483328 i:\program files\Adobe\Acrobat 7.0\Distillr\acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
--a------ 2008-10-12 21:22 287040 i:\program files\DNA\btdna.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 07:00 15360 i:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell MFP Color Laser Printer 3115cn Launcher]
--a------ 2006-12-23 14:38 635800 i:\program files\Dell Printers\Dell MFP Color Laser Printer 3115cn\Address Book Editor\Launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DLPSP]
--a------ 2006-12-07 16:52 340888 i:\program files\Dell Printers\Additional Color Laser Software\Status Monitor\dlpsp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 2006-10-27 00:47 31016 i:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
--a------ 2006-11-13 13:39 1289000 i:\program files\Microsoft ActiveSync\wcescomm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndexSearch]
--a------ 2006-06-30 18:08 40960 i:\program files\Dell Printers\paperport\IndexSearch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-10-01 17:57 289576 i:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2006-01-12 14:40 155648 i:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2007-12-05 01:41 8523776 i:\windows\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2007-12-05 01:41 81920 i:\windows\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaperPort PTD]
--a------ 2006-06-30 18:08 36864 i:\program files\Dell Printers\paperport\pptd40nt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-06 14:09 413696 i:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a------ 2004-11-02 20:24 32768 i:\program files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
--------- 2003-10-14 10:22 155648 i:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-02-22 03:25 144784 i:\program files\Java\jre1.6.0_05\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-08-30 17:43 4670704 i:\program files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2007-12-05 01:41 1626112 i:\windows\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"iPod Service"=3 (0x3)
"Apple Mobile Device"=2 (0x2)
"WZCSVC"=2 (0x2)
"FastUserSwitchingCompatibility"=3 (0x3)
"WMPNetworkSvc"=3 (0x3)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"Microsoft Office Groove Audit Service"=3 (0x3)
"Adobe LM Service"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"i:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"i:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"i:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"i:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"i:\program files\Microsoft ActiveSync\rapimgr.exe"= i:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"i:\program files\Microsoft ActiveSync\wcescomm.exe"= i:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"i:\program files\Microsoft ActiveSync\WCESMgr.exe"= i:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"i:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\World of Warcraft\\BackgroundDownloader.exe"=
"i:\\Program Files\\iTunes\\iTunes.exe"=
"i:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\World of Warcraft\\WoW-2.4.3-to-3.0.2-enUS-Win-Final-downloader.exe"=
"c:\\World of Warcraft\\WoW-1.12.x-to-2.0.1-enUS-patch-downloader.exe"=
"c:\\World of Warcraft\\WoW-1.12.0-enUS-downloader.exe"=
"i:\\WINDOWS\\explorer.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"6881:TCP"= 6881:TCP:Blizzard Downloader: 6881
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"6112:TCP"= 6112:TCP:Blizzard Downloader
"8086:TCP"= 8086:TCP:*

"9081:TCP"= 9081:TCP:Blizzard
"9090:TCP"= 9090:TCP:Blizzard
"9097:TCP"= 9097:TCP:Blizzard
"9100:TCP"= 9100:TCP:Blizzard
R2 DLSDB;Dell Printer Status Database;i:\program files\Dell Printers\Additional Color Laser Software\Status Monitor\DLSDBNT.EXE [2006-12-07 140184]
.
Contents of the 'Scheduled Tasks' folder
2008-11-04 i:\windows\Tasks\AppleSoftwareUpdate.job
- i:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2008-11-07 i:\windows\Tasks\At1.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-07 i:\windows\Tasks\At10.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-07 i:\windows\Tasks\At11.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-07 i:\windows\Tasks\At12.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-07 i:\windows\Tasks\At13.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-07 i:\windows\Tasks\At14.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-07 i:\windows\Tasks\At15.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-07 i:\windows\Tasks\At16.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-06 i:\windows\Tasks\At17.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-06 i:\windows\Tasks\At18.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-06 i:\windows\Tasks\At19.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-07 i:\windows\Tasks\At2.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-07 i:\windows\Tasks\At20.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-06 i:\windows\Tasks\At21.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-07 i:\windows\Tasks\At22.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-07 i:\windows\Tasks\At23.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-07 i:\windows\Tasks\At24.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-07 i:\windows\Tasks\At25.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-07 i:\windows\Tasks\At26.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-07 i:\windows\Tasks\At27.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-07 i:\windows\Tasks\At28.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-07 i:\windows\Tasks\At29.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-07 i:\windows\Tasks\At3.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-07 i:\windows\Tasks\At30.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-07 i:\windows\Tasks\At31.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-07 i:\windows\Tasks\At32.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-07 i:\windows\Tasks\At33.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-07 i:\windows\Tasks\At34.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-07 i:\windows\Tasks\At35.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-07 i:\windows\Tasks\At36.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-07 i:\windows\Tasks\At37.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-07 i:\windows\Tasks\At38.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-07 i:\windows\Tasks\At39.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-07 i:\windows\Tasks\At4.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-07 i:\windows\Tasks\At40.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-06 i:\windows\Tasks\At41.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-06 i:\windows\Tasks\At42.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-06 i:\windows\Tasks\At43.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-07 i:\windows\Tasks\At44.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-06 i:\windows\Tasks\At45.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-07 i:\windows\Tasks\At46.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-07 i:\windows\Tasks\At47.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-07 i:\windows\Tasks\At48.job
- i:\windows\system32\3F2s4tu4.exe []
2008-11-07 i:\windows\Tasks\At5.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-07 i:\windows\Tasks\At6.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-07 i:\windows\Tasks\At7.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-07 i:\windows\Tasks\At8.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-07 i:\windows\Tasks\At9.job
- i:\windows\system32\TWA3V07x.exe []
2008-11-03 i:\windows\Tasks\Backup.job
- i:\windows\system32\ntbackup.exe [2004-08-04 07:00]
2008-11-07 i:\windows\Tasks\backupincremental.job
- i:\windows\system32\ntbackup.exe [2004-08-04 07:00]
.
- - - - ORPHANS REMOVED - - - -
BHO-{069A035F-78BA-48CB-889A-64F07D2B7A29} - i:\windows\system32\pmnkJDSl.dll
BHO-{6ED59772-F4EB-4FDE-BBB3-E939952686BF} - i:\windows\system32\nnnnKeCs.dll
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
ShellExecuteHooks-{6ED59772-F4EB-4FDE-BBB3-E939952686BF} - i:\windows\system32\nnnnKeCs.dll
MSConfigStartUp-088bbec6 - i:\windows\system32\yymabmdx.dll
MSConfigStartUp-BitZip - Powered by Miro - i:\program files\Participatory Culture Foundation\Miro\Miro.exe
MSConfigStartUp-lphcg7wj0en95 - i:\windows\system32\lphcg7wj0en95.exe
MSConfigStartUp-mkymm - i:\windows\system32\mkymm.exe
MSConfigStartUp-SearchSettings - i:\program files\Search Settings\SearchSettings.exe
MSConfigStartUp-SMshcn7wj0en95 - i:\program files\shcn7wj0en95\shcn7wj0en95.exe
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://drudgereport.com/
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
O8 -: Convert link target to Adobe PDF - i:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 -: Convert link target to existing PDF - i:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 -: Convert selected links to Adobe PDF - i:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 -: Convert selected links to existing PDF - i:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 -: Convert selection to Adobe PDF - i:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 -: Convert selection to existing PDF - i:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 -: Convert to Adobe PDF - i:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 -: Convert to existing PDF - i:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 -: E&xport to Microsoft Excel - i:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
O15 -: Trusted Zone: *.tdameritrade.com
O17 -: HKLM\CCS\Interface\{EE825216-61D2-4E6A-825A-EE7EFD2B9B74}: NameServer = 207.69.188.186,207.69.188.187
O16 -: {2FE68711-8830-417D-95E0-EAB307DB0447} - hxxps://prolog.c-b.com/pw/mpsPwLc7.CAB
i:\windows\Downloaded Program Files\mpsPwLc6.inf
i:\windows\system32\msvbvm60.dll
i:\windows\system32\oleaut32.dll
i:\windows\system32\olepro32.dll
i:\windows\system32\asycfilt.dll
i:\windows\system32\stdole2.tlb
i:\windows\system32\comcat.dll
i:\windows\Downloaded Program Files\mpsPwLc7.ocx
O16 -: {F375116A-793C-11D2-BFE1-444553540001} - hxxp://realist2.firstamres.com/mapviewer/mapviewer.cab
i:\windows\Downloaded Program Files\mapviewer.ocx
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-07 15:25:08
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
i:\program files\Common Files\Symantec Shared\ccSetMgr.exe
i:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
i:\program files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
i:\program files\Lavasoft\Ad-Aware\aawservice.exe
i:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
i:\program files\Symantec AntiVirus\DefWatch.exe
i:\program files\Norton Ghost\Agent\VProSvc.exe
i:\windows\system32\nvsvc32.exe
i:\program files\Symantec AntiVirus\Rtvscan.exe
i:\program files\Dell Printers\Additional Color Laser Software\Status Monitor\dlpwdnt.exe
i:\progra~1\MI3AA1~1\rapimgr.exe
.
**************************************************************************
.
Completion time: 2008-11-07 15:28:10 - machine was rebooted [Gero]
ComboFix-quarantined-files.txt 2008-11-07 20:28:06
Pre-Run: 254,863,142,912 bytes free
Post-Run: 254,840,377,344 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
i:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
354 --- E O F --- 2008-10-29 02:14:49
THANK YOU SO MUCH IN ADVANCE!!!
Gerie