Okay, the computer's disconnected from the internet. Haven't used any programs since my last post at least, because I knew this crap seems to just keep coming back. Here are the logs you requested:
Username "Cranium X" - 06/18/2008 10:26:26 [Fixwareout edited 9/01/2007]
~~~~~ Prerun check
Successfully flushed the DNS Resolver Cache.
System was rebooted successfully.
~~~~~ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "System"=""
....
....
~~~~~ Misc files.
....
~~~~~ Checking for older varients.
....
~~~~~ Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE"
"Alcmtr"="ALCMTR.EXE"
"JMB36X IDE Setup"="C:\\WINDOWS\\RaidTool\\xInsIDE.exe"
"36X Raid Configurer"="C:\\WINDOWS\\system32\\xRaidSetup.exe boot"
"GEST"="="
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"AVG8_TRAY"="C:\\PROGRA~1\\AVG\\AVG8\\avgtray.exe"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_06\\bin\\jusched.exe\""
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
....
Hosts file was reset, If you use a custom hosts file please replace it...
~~~~~ End report ~~~~~
ComboFix 08-06-16.5 - Cranium X 2008-06-18 10:30:40.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3170 [GMT -4:00]
Running from: C:\Documents and Settings\Cranium X\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BMb7748ce8.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\jtkxjmwj.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\olvmkifj.dll
C:\WINDOWS\system32\TBIjmnmp.ini
C:\WINDOWS\system32\TBIjmnmp.ini2
.
((((((((((((((((((((((((( Files Created from 2008-05-18 to 2008-06-18 )))))))))))))))))))))))))))))))
.
2008-06-18 10:26 . 2008-06-18 10:28 <DIR> d-------- C:\fixwareout
2008-06-17 22:40 . 2008-06-17 22:40 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-17 22:40 . 2008-06-17 22:40 <DIR> d-------- C:\Documents and Settings\Cranium X\Application Data\Malwarebytes
2008-06-17 22:40 . 2008-06-17 22:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-17 22:40 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-17 22:40 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-17 22:38 . 2008-06-17 22:38 <DIR> d-------- C:\VundoFix Backups
2008-06-17 22:00 . 2008-06-17 22:00 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-17 20:33 . 2008-06-17 20:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Empyre Group
2008-06-17 20:32 . 2008-06-17 20:32 <DIR> d-------- C:\Program Files\Dillie-O Digital
2008-06-17 20:32 . 2008-06-17 20:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Dillie-O Digital
2008-06-17 19:56 . 2008-06-18 10:29 104 --a------ C:\WINDOWS\system32\NvApps.xml
2008-06-17 14:58 . 2008-06-17 14:58 <DIR> d-------- C:\WINDOWS\Sun
2008-06-17 12:51 . 2008-06-17 22:19 499 --a------ C:\WINDOWS\wininit.ini
2008-06-17 12:38 . 2008-06-17 12:38 <DIR> d-------- C:\Program Files\Empyre Group
2008-06-16 18:18 . 2008-06-16 18:18 <DIR> d-------- C:\Documents and Settings\Cranium X\Application Data\InstallShield Installation Information
2008-06-16 18:17 . 2008-06-16 18:17 <DIR> d-------- C:\Program Files\Unreal Tournament 3 Demo
2008-06-16 18:16 . 2008-06-16 18:16 <DIR> d-------- C:\WINDOWS\system32\AGEIA
2008-06-16 18:16 . 2008-06-16 18:16 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-06-16 18:16 . 2008-06-16 18:16 <DIR> d-------- C:\Program Files\AGEIA Technologies
2008-06-16 14:45 . 2008-06-16 14:45 0 --------- C:\WINDOWS\WB.ini
2008-06-16 14:34 . 2008-06-16 14:34 <DIR> d-------- C:\Program Files\Stardock
2008-06-16 14:34 . 2008-04-26 16:14 42,672 --a------ C:\WINDOWS\system32\wbsys.dll
2008-06-16 14:30 . 2008-06-17 23:01 <DIR> d--h----- C:\$AVG8.VAULT$
2008-06-16 14:13 . 2008-06-16 14:18 <DIR> d-------- C:\Program Files\Winamp
2008-06-16 14:13 . 2008-06-16 14:25 1,065 --a------ C:\WINDOWS\winamp.ini
2008-06-16 14:05 . 2008-06-16 14:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WinZip
2008-06-16 13:55 . 2008-06-16 13:55 <DIR> d-------- C:\Program Files\OpenOffice.org 2.4
2008-06-16 13:54 . 2008-06-16 22:11 <DIR> d-------- C:\BitTorrent Files
2008-06-16 13:46 . 2008-06-17 10:48 <DIR> d-------- C:\Documents and Settings\Cranium X\Application Data\Azureus
2008-06-16 13:46 . 2008-06-16 13:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Azureus
2008-06-16 13:46 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-06-16 13:45 . 2008-06-16 13:55 <DIR> d-------- C:\Program Files\Java
2008-06-16 13:45 . 2008-06-16 13:45 <DIR> d-------- C:\Program Files\Common Files\Java
2008-06-16 13:43 . 2008-06-17 10:48 <DIR> d-------- C:\Program Files\Azureus
2008-06-16 13:25 . 2008-04-23 00:16 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-06-16 13:25 . 2007-04-17 05:32 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-06-16 13:25 . 2007-03-08 01:10 991,232 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-06-16 13:25 . 2008-04-23 00:16 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-06-16 13:25 . 2008-04-23 00:16 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-06-16 13:25 . 2008-04-23 00:16 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-06-16 13:25 . 2008-04-23 00:16 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-06-16 13:25 . 2008-04-23 00:16 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-06-16 13:25 . 2008-04-22 03:39 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-06-16 13:20 . 2008-06-16 13:21 <DIR> d-------- C:\WINDOWS\system32\URTTemp
2008-06-16 13:20 . 2008-04-14 08:30 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-16 13:20 . 2008-04-14 08:30 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-16 13:17 . 2008-06-16 13:27 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-06-16 13:17 . 2006-09-06 17:43 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-06-16 13:15 . 2008-06-16 13:15 <DIR> d--hs---- C:\Documents and Settings\Cranium X\UserData
2008-06-16 13:15 . 2007-07-30 19:19 43,352 --a------ C:\WINDOWS\system32\wups2.dll
2008-06-16 13:15 . 2007-07-30 19:18 34,136 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2008-06-16 13:15 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-06-16 13:15 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-06-16 13:15 . 2007-07-30 19:18 20,312 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2008-06-16 13:06 . 2008-06-16 13:06 <DIR> d-------- C:\Documents and Settings\Cranium X\Application Data\ACD Systems
2008-06-16 13:04 . 2008-06-16 13:04 <DIR> d-------- C:\Program Files\Common Files\ACD Systems
2008-06-16 13:04 . 2008-06-16 13:04 <DIR> d-------- C:\Program Files\ACD Systems
2008-06-16 13:04 . 2008-06-16 13:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ACD Systems
2008-06-16 13:03 . 2008-06-16 13:03 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-06-16 13:03 . 2008-06-16 13:03 10,368 --a------ C:\WINDOWS\system32\drivers\pfc.sys
2008-06-16 12:34 . 2008-06-16 12:36 <DIR> d-------- C:\Program Files\Common Files\Ahead
2008-06-16 12:34 . 2008-06-16 12:34 <DIR> d-------- C:\Program Files\Ahead
2008-06-16 12:34 . 2001-07-06 14:41 569,344 --a------ C:\WINDOWS\system32\imagr5.dll
2008-06-16 12:34 . 2001-07-06 12:44 544,768 --a------ C:\WINDOWS\system32\imagx5.dll
2008-06-16 12:34 . 2001-07-06 18:24 283,920 --a------ C:\WINDOWS\system32\ImagXpr5.dll
2008-06-16 12:34 . 2001-07-09 11:50 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
2008-06-16 12:34 . 2000-06-26 11:45 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll
2008-06-16 12:34 . 2001-06-26 08:15 38,912 --a------ C:\WINDOWS\system32\picn20.dll
2008-06-16 12:31 . 2008-06-16 12:31 <DIR> d-------- C:\Program Files\simplemu
2008-06-15 23:48 . 2008-06-18 10:17 12 --a------ C:\WINDOWS\dirsaver.ini
2008-06-15 23:18 . 2008-06-15 23:18 5,049,472 --a------ C:\WINDOWS\Dancing Lizard Gals.scr
2008-06-15 23:12 . 2008-06-18 00:01 <DIR> d-------- C:\Program Files\Trillian
2008-06-15 23:02 . 2008-06-15 23:04 <DIR> d-------- C:\WINDOWS\Icons
2008-06-15 22:55 . 2008-06-15 22:55 <DIR> d-------- C:\WINDOWS\nvidia icons
2008-06-15 22:55 . 2008-06-15 22:56 <DIR> d-------- C:\WINDOWS\NV39921524.TMP
2008-06-15 22:54 . 2008-06-15 22:54 <DIR> d-------- C:\NVIDIA
2008-06-15 22:52 . 2008-06-15 22:52 <DIR> d-------- C:\Program Files\SystemRequirementsLab
2008-06-15 22:39 . 2008-06-15 22:41 <DIR> d-------- C:\Program Files\eMule
2008-06-14 20:24 . 2008-06-16 23:22 <DIR> d-------- C:\Emulators
2008-06-14 18:27 . 2008-06-14 18:27 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2008-06-14 18:27 . 2008-06-14 18:27 <DIR> d-------- C:\Documents and Settings\Cranium X\Application Data\Media Player Classic
2008-06-14 17:24 . 2008-06-14 17:24 <DIR> d-------- C:\Program Files\CCleaner
2008-06-14 17:22 . 2008-06-14 17:22 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-06-14 17:22 . 2008-06-14 17:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-14 17:18 . 2008-06-18 09:52 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-06-14 17:18 . 2008-06-14 17:18 <DIR> d-------- C:\Program Files\AVG
2008-06-14 17:18 . 2008-06-14 17:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-06-14 17:18 . 2008-06-14 17:18 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-06-14 17:18 . 2008-06-14 17:18 75,272 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-06-14 17:18 . 2008-06-14 17:18 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-06-14 16:51 . 2008-06-14 16:54 <DIR> d-------- C:\Program Files\JetMailMonitor
2008-06-14 16:50 . 2003-06-25 16:05 266,360 --a------ C:\WINDOWS\system32\TweakUI.exe
2008-06-14 16:50 . 2002-06-21 15:09 160,217 --a------ C:\WINDOWS\system32\PowerToysLicense.rtf
2008-06-14 16:35 . 2008-06-14 16:35 <DIR> d-------- C:\Documents and Settings\Cranium X\Application Data\Talkback
2008-06-14 16:34 . 2008-06-18 10:18 <DIR> d-------- C:\Program Files\Mozilla Thunderbird
2008-06-14 16:34 . 2008-06-18 10:18 <DIR> d-------- C:\Documents and Settings\Cranium X\Application Data\Thunderbird
2008-06-14 16:08 . 2008-06-14 16:08 <DIR> d-------- C:\Logs
2008-06-14 15:45 . 2008-06-14 15:45 1,160 --a------ C:\WINDOWS\mozver.dat
2008-06-14 15:10 . 2008-04-14 00:15 26,368 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2008-06-14 14:31 . 2007-08-13 19:21 1,351,254 --a------ C:\WINDOWS\iObject.bmp
2008-06-14 14:15 . 2008-06-14 14:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-06-14 14:12 . 2008-06-14 14:12 <DIR> d-------- C:\Program Files\Yahoo!
2008-06-14 13:54 . 2008-06-14 13:54 0 --a------ C:\WINDOWS\nsreg.dat
2008-06-14 13:47 . 2001-08-17 13:48 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2008-06-14 13:47 . 2001-08-17 13:48 12,160 --a--c--- C:\WINDOWS\system32\dllcache\mouhid.sys
2008-06-14 13:47 . 2008-04-14 00:15 10,368 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2008-06-14 13:47 . 2008-04-14 00:15 10,368 --a--c--- C:\WINDOWS\system32\dllcache\hidusb.sys
2008-06-14 11:26 . 2008-06-14 11:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\media center programs
2008-06-14 03:06 . 2008-06-17 20:57 <DIR> d-------- C:\Program Files\World of Warcraft
2008-06-14 03:06 . 2008-06-14 03:06 <DIR> d-------- C:\Program Files\Common Files\Blizzard Entertainment
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-18 01:02 --------- d-----w C:\Program Files\Steam
2008-06-14 20:51 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-14 14:36 --------- d-----w C:\Program Files\Funcom
2008-06-14 14:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\Funcom
2008-06-14 06:48 --------- d-----w C:\Program Files\Realtek
2008-06-14 06:48 --------- d-----w C:\Documents and Settings\Cranium X\Application Data\InstallShield
2008-06-14 06:47 16,608 ----a-w C:\WINDOWS\gdrv.sys
2008-06-14 06:46 315,392 ----a-w C:\WINDOWS\HideWin.exe
2008-06-14 06:45 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-06-14 06:43 --------- d-----w C:\Program Files\Intel
2008-06-14 06:32 --------- d-----w C:\Program Files\microsoft frontpage
2008-05-08 14:02 203,136 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-03 02:46 6,554,496 ----a-w C:\WINDOWS\system32\drivers\nv4_mini.sys
2006-06-15 17:29 23,552 ----a-w C:\Program Files\mozilla firefox\plugins\DrvMgt.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5DA8D715-1510-45B3-9496-1783926B4033}]
C:\WINDOWS\system32\qoMeEULB.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D0335330-6173-47B6-A34F-D38A3A89E1D6}]
C:\WINDOWS\system32\pmnmjIBT.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 08:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-02-13 02:31 16857600 C:\WINDOWS\RTHDCPL.exe]
"JMB36X IDE Setup"="C:\WINDOWS\RaidTool\xInsIDE.exe" [2007-03-20 02:36 36864]
"36X Raid Configurer"="C:\WINDOWS\system32\xRaidSetup.exe" [2007-08-29 04:55 1966080]
"GEST"="=" []
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-02 22:46 13529088]
"nwiz"="nwiz.exe" [2008-05-02 22:46 1630208 C:\WINDOWS\system32\nwiz.exe]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-06-14 17:18 1177368]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-02 22:46 86016]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
jetMailMonitor.lnk - C:\Program Files\JetMailMonitor\JetMM.exe [2008-06-14 16:51:10 651264]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 01000000
"NoLogoff"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll 2008-06-16 15:16 210168 C:\Program Files\Stardock\Object Desktop\WindowBlinds\WbSrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
"VIDC.ACDV"= ACDV.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\b447bf74]
C:\WINDOWS\system32\orqrjcof.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BMb7748ce8]
C:\WINDOWS\system32\vnkwgadb.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\Unreal Tournament 3 Demo\\Binaries\\UT3Demo.exe"=
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-06-14 17:18]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-06-14 17:18]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-06-14 17:18]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-06-14 17:18]
S3 gdrv;gdrv;C:\WINDOWS\gdrv.sys [2008-06-14 02:47]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-18 10:33:42
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-06-18 10:35:23 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-18 14:35:21
Pre-Run: 564,134,313,984 bytes free
Post-Run: 564,171,665,408 bytes free
226
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:38:47 AM, on 6/18/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\JetMailMonitor\JetMM.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5DA8D715-1510-45B3-9496-1783926B4033} - C:\WINDOWS\system32\qoMeEULB.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: (no name) - {D0335330-6173-47B6-A34F-D38A3A89E1D6} - C:\WINDOWS\system32\pmnmjIBT.dll (file missing)
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\xRaidSetup.exe boot
O4 - HKLM\..\Run: [GEST] =
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: jetMailMonitor.lnk = C:\Program Files\JetMailMonitor\JetMM.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) -
http://dev.srtest.com/srl_bin/sysreqlab3.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1213636516984
O17 - HKLM\System\CCS\Services\Tcpip\..\{5DF883A6-29EC-417F-8546-D6D669E98E3D}: NameServer = 208.67.222.222,208.67.220.220
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 4648 bytes