Hey there.. thought i might have a huge problem here so here we go! OK I renamed hijackthis.exe to feemo.exe. With AVG I d/l that in an attempt to fix this problem but never really used it... as it was the free version didn't give me the option to deactivate resident shield so I uninstalled the program as I have VET.
Here are my logs, appreciate your help
Fiona - 07-01-08 20:02:42.48 Service Pack 2
ComboFix 06.11.27 - Running from: "C:\Documents and Settings\Fiona\My Documents"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files\Common Files\Yazzle1122OinAdmin.exe
C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
C:\Program Files\Common Files\{F8CBE7C1-0638-1033-1118-04100620003d}
C:\Program Files\Common Files\{38CBE7C1-0639-1033-1118-04100620003d}
C:\Program Files\Common Files\{F8CBE7C1-0639-1033-1118-04100620003d}
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\QooBox\Purity\Documents and Settings\Fiona\My Documents\CROSOF~1.NET
C:\QooBox\Purity\Documents and Settings\Fiona\My Documents\CROSOF~1.NET\notepad.exe
C:\QooBox\Purity\WINDOWS\system32\SMANTE~1
C:\QooBox\Purity\WINDOWS\system32\SMANTE~1\dexplore.exe
C:\QooBox\Purity\WINDOWS\system32\SMANTE~1\S?mantec
((((((((((((((((((((((((((((((( Files Created from 2006-12-08 to 2007-01-08 ))))))))))))))))))))))))))))))))))
2007-01-02 13:46 <DIR> d-------- C:\hijackthis
2007-01-02 13:25 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2007-01-02 13:17 <DIR> d-------- C:\007da66ddd89a5e392
2007-01-02 12:42 <DIR> d-------- C:\Program Files\SpywareBlaster
2006-12-29 21:37 <DIR> d-------- C:\fafff9897ac5c98edfb668
2006-12-29 21:29 <DIR> d-------- C:\{10000001-0000-0000-0962-0A190027901B}
2006-12-29 21:29 <DIR> d-------- C:\{00003A34-0000-0000-4AE2-1453FF4CC3DB}
2006-12-29 20:26 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2006-12-29 18:16 <DIR> d-------- C:\ad530409a701414e0d680bd19e18
2006-12-29 17:22 57,856 --a------ C:\WINDOWS\system32\nnlpmqt.dll
2006-12-29 17:22 <DIR> d-------- C:\Program Files\Outerinfo
2006-12-29 16:50 <DIR> d-------- C:\Program Files\Ipwindows
2006-12-29 16:20 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2006-12-29 16:02 <DIR> d-------- C:\VundoFix Backups
2006-12-29 15:26 <DIR> d-------- C:\b08fbcbc3b9ac1d3dc
2006-12-29 14:57 22,541 ---hs---- C:\WINDOWS\system32\mljkjkj.dll
2006-12-29 13:39 <DIR> d-------- C:\b2784fab85c506a9075b98
2006-12-29 12:58 72,704 --a------ C:\WINDOWS\system32\drvfer.dll
2006-12-29 12:58 22,541 ---hs---- C:\WINDOWS\system32\rqrsqol.dll
2006-12-29 10:33 72,704 --a------ C:\WINDOWS\system32\drvtuj.dll
2006-12-29 10:33 22,541 ---hs---- C:\WINDOWS\system32\awtrrqp.dll
2006-12-29 10:32 <DIR> d-------- C:\e8e925309986e7b4ca
2006-12-29 10:06 <DIR> d-------- C:\a09e99407d0fbcb338
2006-12-29 10:00 <DIR> d-------- C:\0cb0a2c3cb88e5dcb3077d3a19
2006-12-28 22:21 <DIR> d-------- C:\WINDOWS\Minidump
2006-12-28 22:18 <DIR> d-------- C:\WINDOWS\network diagnostic
2006-12-28 22:15 <DIR> d-------- C:\bfd2688386319c1f5d3470bdec055017
2006-12-28 22:11 22,541 ---hs---- C:\WINDOWS\system32\hggfebb.dll
2006-12-28 19:00 88,340 --a------ C:\WINDOWS\system32\bmdlohco.exe
2006-12-28 19:00 81,684 --a------ C:\WINDOWS\system32\xnchwirv.dll
2006-12-28 19:00 44,060 --a------ C:\WINDOWS\system32\gidnahxa.dll
2006-12-28 18:54 72,704 --a------ C:\WINDOWS\system32\drvxeb.dll
2006-12-28 18:53 22,541 ---hs---- C:\WINDOWS\system32\efcbxwv.dll
2006-12-28 18:17 <DIR> d-------- C:\Documents and Settings\Fiona\Application Data\funkitron
2006-12-28 17:48 <DIR> d-------- C:\Program Files\Shockwave.com
2006-12-20 15:29 28,672 --a------ C:\WINDOWS\system32\f3PSSavr.scr
2006-12-18 14:44 <DIR> d-------- C:\Documents and Settings\Fiona\Application Data\Leadertech
2006-12-16 15:46 <DIR> d-------- C:\Program Files\MySpace
2006-12-16 15:46 <DIR> d-------- C:\Documents and Settings\Fiona\Application Data\MySpace
2006-12-15 08:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\CA
2006-12-08 19:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Trymedia
2006-12-08 19:06 <DIR> d-------- C:\Program Files\iWin.com
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
Rootkit driver pe386 is present. A rootkit scan is required
2007-01-08 20:04 -------- d-a------ C:\Program Files\Common Files
2007-01-02 13:49 -------- d-------- C:\Program Files\Windows Defender
2007-01-02 13:48 -------- d-------- C:\Program Files\Spybot - Search & Destroy
2007-01-02 13:48 -------- d-------- C:\Program Files\MSN Messenger
2007-01-02 13:48 -------- d-------- C:\Program Files\Internet Explorer
2006-12-28 22:49 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-12-18 14:44 -------- d-------- C:\Documents and Settings\Fiona\Application Data\Adobe
2006-12-14 19:09 -------- d-------- C:\Program Files\Outlook Express
2006-12-14 19:09 -------- d-------- C:\Program Files\Common Files\System
2006-12-14 17:04 -------- d-------- C:\Documents and Settings\Fiona\Application Data\LimeWire
2006-12-10 19:01 -------- d-------- C:\Program Files\Mozilla Firefox
2006-12-04 21:26 -------- d---s---- C:\Documents and Settings\Fiona\Application Data\Microsoft
2006-12-02 18:31 -------- d-------- C:\Documents and Settings\Fiona\Application Data\Image Zone Express
2006-12-02 18:28 -------- d-------- C:\Program Files\HP
2006-12-02 18:28 -------- d-------- C:\Program Files\Common Files\HP
2006-11-28 22:21 -------- d-------- C:\Program Files\OSD
2006-11-28 22:18 -------- d-------- C:\Program Files\Common Files\Teleca Shared
2006-11-27 18:45 60416 --------- C:\WINDOWS\system32\tzchange.exe
2006-11-21 19:58 8 --a------ C:\Documents and Settings\Fiona\Application Data\NMM-MetaData.db
2006-11-20 03:02 -------- d-------- C:\Program Files\MSXML 4.0
2006-11-17 23:08 -------- d-------- C:\Program Files\Java
2006-11-12 09:21 -------- d-------- C:\Documents and Settings\Fiona\Application Data\DivX
2006-11-10 22:41 -------- d-------- C:\Documents and Settings\Fiona\Application Data\Mozilla
2006-11-10 22:10 -------- d-------- C:\Program Files\DivX
2006-11-10 21:53 -------- d-------- C:\Program Files\Windows Media Player
2006-11-10 21:53 -------- d-------- C:\Program Files\Windows Media Connect 2
2006-11-08 15:06 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-11-04 14:14 1245696 --a------ C:\WINDOWS\system32\msxml4.dll
2006-11-02 18:07 29744 --a------ C:\Documents and Settings\Fiona\Application Data\PatchUpdate_HP_CounterReport_Update_HPSU.log
2006-11-02 17:59 2080 --a------ C:\Documents and Settings\Fiona\Application Data\HPSU_48BitScanUpdate.log
2006-11-02 17:57 36498 --a------ C:\Documents and Settings\Fiona\Application Data\Update_HP_RedboxHprblog_HPSU.log
2006-11-02 17:55 139264 --a------ C:\WINDOWS\system32\hpzjrd01.dll
2006-10-19 23:56 713216 --a------ C:\WINDOWS\system32\sxs.dll
2006-10-18 22:58 8704 --a------ C:\WINDOWS\system32\wdfmgr.exe
2006-10-18 22:58 8704 --a------ C:\WINDOWS\system32\uwdf.exe
2006-10-18 22:47 99840 --a------ C:\WINDOWS\system32\wmpshell.dll
2006-10-18 22:47 991744 --a------ C:\WINDOWS\system32\drmv2clt.dll
2006-10-18 22:47 937984 --a------ C:\WINDOWS\system32\WMNetMgr.dll
2006-10-18 22:47 8231936 --a------ C:\WINDOWS\system32\wmploc.dll
2006-10-18 22:47 767488 --------- C:\WINDOWS\system32\WMVSENCD.dll
2006-10-18 22:47 757248 --a------ C:\WINDOWS\system32\wmadmod.dll
2006-10-18 22:47 7168 --a------ C:\WINDOWS\system32\asferror.dll
2006-10-18 22:47 656896 --------- C:\WINDOWS\system32\WMVXENCD.dll
2006-10-18 22:47 63488 --a------ C:\WINDOWS\system32\wpdmtpus.dll
2006-10-18 22:47 629760 --a------ C:\WINDOWS\system32\wpd_ci.dll
2006-10-18 22:47 613376 --------- C:\WINDOWS\system32\wmpmde.dll
2006-10-18 22:47 603648 --a------ C:\WINDOWS\system32\WMSPDMOD.dll
2006-10-18 22:47 542720 --a------ C:\WINDOWS\system32\blackbox.dll
2006-10-18 22:47 535040 --------- C:\WINDOWS\system32\wmdrmsdk.dll
2006-10-18 22:47 429056 --a------ C:\WINDOWS\system32\wmdrmdev.dll
2006-10-18 22:47 414208 --a------ C:\WINDOWS\system32\msscp.dll
2006-10-18 22:47 4096 --a------ C:\WINDOWS\system32\wmvdmoe2.dll
2006-10-18 22:47 4096 --a------ C:\WINDOWS\system32\wmvdmod.dll
2006-10-18 22:47 4096 --a------ C:\WINDOWS\system32\WMVADVE.DLL
2006-10-18 22:47 4096 --a------ C:\WINDOWS\system32\WMVADVD.dll
2006-10-18 22:47 4096 --a------ C:\WINDOWS\system32\wmsdmoe2.dll
2006-10-18 22:47 4096 --a------ C:\WINDOWS\system32\wmsdmod.dll
2006-10-18 22:47 4096 --a------ C:\WINDOWS\system32\wdfapi.dll
2006-10-18 22:47 4096 --a------ C:\WINDOWS\system32\MPG4DMOD.dll
2006-10-18 22:47 4096 --a------ C:\WINDOWS\system32\MP4SDMOD.dll
2006-10-18 22:47 4096 --a------ C:\WINDOWS\system32\MP43DMOD.dll
2006-10-18 22:47 38400 --------- C:\WINDOWS\system32\wpdshextres.dll
2006-10-18 22:47 37376 --a------ C:\WINDOWS\system32\wmdmps.dll
2006-10-18 22:47 35840 --a------ C:\WINDOWS\system32\wpdconns.dll
2006-10-18 22:47 356352 --a------ C:\WINDOWS\system32\wpdsp.dll
2006-10-18 22:47 348672 --a------ C:\WINDOWS\system32\wmdrmnet.dll
2006-10-18 22:47 33792 --a------ C:\WINDOWS\system32\wmdmlog.dll
2006-10-18 22:47 321536 --a------ C:\WINDOWS\system32\mswmdm.dll
2006-10-18 22:47 317440 --------- C:\WINDOWS\system32\MP4SDECD.dll
2006-10-18 22:47 314880 --a------ C:\WINDOWS\system32\wmpdxm.dll
2006-10-18 22:47 295936 --------- C:\WINDOWS\system32\wmpeffects.dll
2006-10-18 22:47 284160 --a------ C:\WINDOWS\system32\portabledeviceapi.dll
2006-10-18 22:47 276992 --a------ C:\WINDOWS\system32\audiodev.dll
2006-10-18 22:47 27136 --a------ C:\WINDOWS\system32\mspmsnsv.dll
2006-10-18 22:47 2603008 --------- C:\WINDOWS\system32\WpdShext.dll
2006-10-18 22:47 259072 --------- C:\WINDOWS\system32\MPG4DECD.dll
2006-10-18 22:47 259072 --------- C:\WINDOWS\system32\MP43DECD.dll
2006-10-18 22:47 2450944 --a------ C:\WINDOWS\system32\wmvcore.dll
2006-10-18 22:47 242688 --a------ C:\WINDOWS\system32\wmpasf.dll
2006-10-18 22:47 229376 --a------ C:\WINDOWS\system32\cewmdm.dll
2006-10-18 22:47 227328 --a------ C:\WINDOWS\system32\wmerror.dll
2006-10-18 22:47 222208 --a------ C:\WINDOWS\system32\wmasf.dll
2006-10-18 22:47 212992 --a------ C:\WINDOWS\system32\mfplat.dll
2006-10-18 22:47 211456 --a------ C:\WINDOWS\system32\qasf.dll
2006-10-18 22:47 204288 --a------ C:\WINDOWS\system32\wmpsrcwp.dll
2006-10-18 22:47 199168 --------- C:\WINDOWS\system32\PortableDeviceWMDRM.dll
2006-10-18 22:47 179712 --a------ C:\WINDOWS\system32\msnetobj.dll
2006-10-18 22:47 175616 --a------ C:\WINDOWS\system32\mspmsp.dll
2006-10-18 22:47 166912 --a------ C:\WINDOWS\system32\portabledevicetypes.dll
2006-10-18 22:47 1661440 --a------ C:\WINDOWS\system32\wmpencen.dll
2006-10-18 22:47 1574912 --------- C:\WINDOWS\system32\WMVENCOD.dll
2006-10-18 22:47 157184 --a------ C:\WINDOWS\system32\wmidx.dll
2006-10-18 22:47 154624 --a------ C:\WINDOWS\system32\wpdmtp.dll
2006-10-18 22:47 1543680 --------- C:\WINDOWS\system32\WMVDECOD.dll
2006-10-18 22:47 1382912 --------- C:\WINDOWS\system32\WMVSDECD.dll
2006-10-18 22:47 133632 --a------ C:\WINDOWS\system32\wpdshserviceobj.dll
2006-10-18 22:47 1329152 --a------ C:\WINDOWS\system32\WMSPDMOE.dll
2006-10-18 22:47 132096 --------- C:\WINDOWS\system32\PortableDeviceWiaCompat.dll
2006-10-18 22:47 130048 --------- C:\WINDOWS\system32\wmpps.dll
2006-10-18 22:47 11264 --a------ C:\WINDOWS\system32\LAPRXY.dll
2006-10-18 22:47 1117696 --a------ C:\WINDOWS\system32\WMADMOE.dll
2006-10-18 22:47 101888 --------- C:\WINDOWS\system32\PortableDeviceClassExtension.dll
2006-10-18 21:03 100864 --a------ C:\WINDOWS\system32\logagent.exe
2006-10-18 21:00 249856 --------- C:\WINDOWS\system32\drmupgds.exe
2006-10-18 21:00 17408 --------- C:\WINDOWS\system32\wpdshextautoplay.exe
2006-10-13 22:35 65536 --a------ C:\WINDOWS\system32\nwwks.dll
2006-10-13 22:35 64000 --a------ C:\WINDOWS\system32\nwapi32.dll
2006-10-13 22:35 142336 --a------ C:\WINDOWS\system32\nwprovau.dll
2006-10-09 19:51 130048 --a------ C:\WINDOWS\system32\SpoonUninstall.exe
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"startkey"="C:\\WINDOWS\\system32\\setup.dll"
"Auru"="\"C:\\WINDOWS\\system32\\SMANTE~1\\dexplore.exe\" -vt yazb"
"Ekr"="C:\\Documents and Settings\\Fiona\\My Documents\\??crosoft.NET\\notepad.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"IgfxTray"="C:\\WINDOWS\\system32\\igfxtray.exe"
"HotKeysCmds"="C:\\WINDOWS\\system32\\hkcmd.exe"
"SynTPLpr"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"QMusic2"="\"C:\\Program Files\\BenQ\\QMusic2\\QMAgent.exe\""
"Ulead AutoDetector"="C:\\Program Files\\Ulead Systems\\Ulead Photo Explorer 8.0 SE Basic\\Monitor.exe"
"PRONoMgr.exe"="c:\\Program Files\\Intel\\PROSetWireless\\NCS\\PROSet\\PRONoMgr.exe"
"CaAvTray"="\"C:\\Program Files\\CA\\eTrust Vet Antivirus\\CAVTray.exe\""
"CAVRID"="\"C:\\Program Files\\CA\\eTrust Vet Antivirus\\CAVRID.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_09\\bin\\jusched.exe\""
"HP Software Update"="C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"BigDogPath"="C:\\WINDOWS\\VM_STI.EXE VIMICRO USB PC Camera"
"PCSuiteTrayApplication"="C:\\PROGRA~1\\Nokia\\NOKIAP~1\\LAUNCH~1.EXE -startup"
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"{F8CBE7C1-0639-1033-1118-04100620003d}"="\"C:\\Program Files\\Common Files\\{F8CBE7C1-0639-1033-1118-04100620003d}\\Update.exe\" mc-110-12-0000272"
"{F8CBE7C1-0638-1033-1118-04100620003d}"="\"C:\\Program Files\\Common Files\\{F8CBE7C1-0638-1033-1118-04100620003d}\\Update.exe\" mc-110-12-0000272"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,f2,01,00,00,b9,00,00,00,7c,00,00,00,72,00,\
00,00,01,00,00,00
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=""
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\MP Scheduled Scan.job
Completion time: 07-01-08 20:05:39.92
C:\ComboFix.txt ... 07-01-08 20:05