There was no "Command" in the list that on HiJackThis
Here is the PDF Setting Uninstall Command:
MsiExec.exe /I{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}
Here is the Combofix & Hijackthis:
ComboFix 08-02-25.3 - Administrator 2008-02-27 7:48:53.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.176 [GMT -5:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\c.exe
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Documents and Settings\LocalService\Application Data\NetMon\domains.txt
C:\Documents and Settings\LocalService\Application Data\NetMon\log.txt
C:\Program Files\network monitor
C:\Program Files\network monitor\netmon.exe
C:\svchost.exe
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\isgTi19
C:\Temp\isgTi19\lPig.log
C:\WINDOWS\Fonts\-
C:\WINDOWS\system32\atmtd.dll
C:\WINDOWS\system32\atmtd.dll._
C:\WINDOWS\system32\byxyyvv.dll
C:\WINDOWS\system32\czobidkb.dllbox
C:\WINDOWS\system32\jmllm.ini
C:\WINDOWS\system32\jmllm.ini2
C:\WINDOWS\system32\knbqltfs.dll
C:\WINDOWS\system32\mllmj.dll
C:\WINDOWS\system32\msnav32.ax
C:\WINDOWS\system32\nGpxx18
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\qqoffbjy.dll
C:\WINDOWS\system32\ryjnhqsu.dll
C:\WINDOWS\system32\sftlqbnk.ini
C:\WINDOWS\system32\vtusqqp.dll
C:\WINDOWS\system32\vybeg.ini
C:\WINDOWS\system32\vybeg.ini2
C:\WINDOWS\system32\ypvucnkl.ini
C:\WINDOWS\uninstall_nmon.vbs
C:\winlogon.exe
C:\x.dat
C:\z.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_CMDSERVICE
-------\LEGACY_NETWORK_MONITOR
-------\Network Monitor
((((((((((((((((((((((((( Files Created from 2008-01-27 to 2008-02-27 )))))))))))))))))))))))))))))))
.
2008-02-26 22:21 . 2008-02-26 22:21 <DIR> d-------- C:\Program Files\IrfanView
2008-02-26 21:37 . 2008-02-26 21:38 <DIR> d-------- C:\Program Files\MagicISO
2008-02-26 18:06 . 2008-02-26 21:39 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\uTorrent
2008-02-26 17:42 . 2008-02-26 17:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-02-26 07:31 . 2008-02-26 07:31 <DIR> d-------- C:\Program Files\CCleaner
2008-02-26 01:20 . 2008-02-26 01:20 <DIR> d-------- C:\WINDOWS\Sun
2008-02-25 19:46 . 2008-02-27 08:39 163,904 --a------ C:\WINDOWS\system32\vlhxbxjv.dll
2008-02-25 07:28 . 2008-02-25 07:28 260 --a------ C:\4756.bat
2008-02-25 04:00 . 2008-02-25 04:00 91,700 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-02-25 04:00 . 2008-02-25 04:00 85,860 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-02-25 03:58 . 2008-02-25 03:58 <DIR> d-------- C:\Program Files\Kaspersky Lab
2008-02-25 03:58 . 2008-02-27 08:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-25 03:58 . 2008-02-27 08:44 1,146,912 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-02-25 03:58 . 2008-02-27 08:44 59,936 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-02-25 03:58 . 2008-02-27 08:40 12,092 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-02-25 03:58 . 2008-02-27 08:40 6,620 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-02-25 03:57 . 2008-02-25 03:57 <DIR> d-------- C:\kav
2008-02-25 03:34 . 2008-02-25 03:37 <DIR> d-------- C:\Photos
2008-02-25 03:28 . 2004-08-03 23:08 26,496 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2008-02-24 23:09 . 2008-02-24 23:09 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\acccore
2008-02-24 23:07 . 2008-02-24 23:07 <DIR> d-------- C:\Program Files\Viewpoint
2008-02-24 23:07 . 2008-02-24 23:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-02-24 23:06 . 2008-02-24 23:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AOL OCP
2008-02-24 23:06 . 2008-02-24 23:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AOL
2008-02-24 23:05 . 2008-02-24 23:05 <DIR> d-------- C:\Program Files\Common Files\AOL
2008-02-24 23:05 . 2008-02-24 23:07 <DIR> d-------- C:\Program Files\AIM6
2008-02-24 23:05 . 2008-02-24 23:07 482 --ah----- C:\IPH.PH
2008-02-24 23:03 . 2008-02-24 23:03 <DIR> d-------- C:\Program Files\QuickTime
2008-02-24 23:01 . 2007-02-20 16:04 2,463,976 --a------ C:\WINDOWS\system32\NPSWF32.dll
2008-02-24 23:01 . 2007-02-20 16:04 190,696 --a------ C:\WINDOWS\system32\NPSWF32_FlashUtil.exe
2008-02-24 22:34 . 2008-02-24 22:34 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-24 22:14 . 2008-02-24 22:14 147,456 --a------ C:\WINDOWS\system32\vbzip10.dll
2008-02-24 22:11 . 2008-02-25 07:35 <DIR> d--hs---- C:\WINDOWS\QmxhcU91dCBFbnQu
2008-02-24 22:11 . 2008-02-24 22:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-24 22:11 . 2008-02-24 22:11 40,960 --a------ C:\Documents and Settings\Administrator\f.exe
2008-02-24 22:11 . 2008-02-24 22:11 134 --a------ C:\n.bat
2008-02-24 22:10 . 2008-02-24 22:10 <DIR> d-------- C:\WINDOWS\system32\xb8
2008-02-24 22:10 . 2008-02-25 07:30 <DIR> d-------- C:\WINDOWS\system32\to2
2008-02-24 22:10 . 2008-02-25 07:28 <DIR> d-------- C:\WINDOWS\system32\ff3
2008-02-24 22:10 . 2008-02-24 22:10 <DIR> d-------- C:\WINDOWS\system32\cms4
2008-02-24 22:10 . 2008-02-27 08:05 <DIR> d-------- C:\Temp
2008-02-24 21:31 . 2008-02-25 19:11 1,681 --a------ C:\WINDOWS\mozver.dat
2008-02-24 21:28 . 2008-02-24 21:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-02-24 21:20 . 2008-02-24 21:20 <DIR> d-------- C:\Program Files\Bonjour
2008-02-24 21:14 . 2008-02-24 21:14 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-02-24 21:12 . 2008-02-24 22:59 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-02-24 21:05 . 2008-02-24 21:05 <DIR> d-------- C:\WINDOWS\VirtualEar
2008-02-24 21:05 . 2008-02-24 21:05 <DIR> d-------- C:\Program Files\Analog Devices
2008-02-24 21:05 . 2001-10-04 14:50 991,232 --a------ C:\WINDOWS\system32\virtear.dll
2008-02-24 21:05 . 2001-09-19 12:47 765,952 --a------ C:\WINDOWS\system\crlds3d.dll
2008-02-24 21:05 . 2004-09-17 09:02 732,928 --a------ C:\WINDOWS\system32\drivers\senfilt.sys
2008-02-24 21:05 . 2004-09-23 07:55 311,296 --a------ C:\WINDOWS\system32\Edcrypt.dll
2008-02-24 21:05 . 2005-01-27 15:31 260,352 --a------ C:\WINDOWS\system32\drivers\smwdm.sys
2008-02-24 21:05 . 2003-08-19 18:36 65,536 --a------ C:\WINDOWS\system32\Audio3d.dll
2008-02-24 21:05 . 2004-11-19 10:00 49,152 --a------ C:\WINDOWS\system32\DSndUp.exe
2008-02-24 21:05 . 2002-04-17 14:05 45,056 --a------ C:\WINDOWS\system32\CleanUp.exe
2008-02-24 21:05 . 2004-10-05 16:10 23,040 --a------ C:\WINDOWS\system32\PostProc.dll
2008-02-24 20:57 . 2008-02-24 20:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\OrbNetworks
2008-02-24 20:56 . 2008-02-24 20:59 <DIR> d-------- C:\Program Files\Winamp Remote
2008-02-24 20:54 . 2008-02-24 20:58 <DIR> d-------- C:\Program Files\Winamp
2008-02-24 20:54 . 2008-02-24 20:58 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Winamp
2008-02-24 20:50 . 2008-02-25 18:43 <DIR> d-------- C:\My Music
2008-02-24 20:50 . 2008-02-25 03:50 <DIR> d-------- C:\Incomplete
2008-02-24 20:49 . 2008-02-24 20:49 <DIR> d-------- C:\Program Files\Java
2008-02-24 20:49 . 2008-02-25 04:11 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\LimeWire
2008-02-24 20:49 . 2007-12-14 01:59 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-02-24 20:47 . 2008-02-24 20:47 <DIR> d-------- C:\Program Files\Common Files\Java
2008-02-24 20:38 . 2008-02-24 20:38 0 --a------ C:\WINDOWS\nsreg.dat
2008-02-24 20:36 . 2004-02-10 11:50 155,648 --a------ C:\WINDOWS\system32\igfxres.dll
2008-02-24 20:00 . 2008-02-24 20:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Prism
2008-02-24 19:59 . 2008-02-24 21:05 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-02-24 19:59 . 2008-02-24 19:59 <DIR> d-------- C:\Program Files\Dell Wireless
2008-02-24 19:59 . 2008-02-24 19:59 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2008-02-24 19:59 . 2006-10-26 12:22 1,396,827 -ra------ C:\WINDOWS\system32\PRISME5.dll
2008-02-24 19:59 . 2006-10-12 09:42 450,649 -ra------ C:\WINDOWS\system32\PRISMAPI.dll
2008-02-24 19:59 . 2006-10-12 09:44 385,113 -ra------ C:\WINDOWS\system32\PRISMSVR.exe
2008-02-24 19:59 . 2006-10-26 12:22 357,344 -ra------ C:\WINDOWS\system32\drivers\PRISMA02.sys
2008-02-24 19:59 . 2006-10-12 09:45 61,529 -ra------ C:\WINDOWS\system32\PRISMSVC.exe
2008-02-24 19:59 . 2006-10-26 12:22 49,152 -ra------ C:\WINDOWS\system32\StopSrvr.exe
2008-02-24 19:59 . 2006-10-27 18:05 49,152 -ra------ C:\WINDOWS\system32\CoPrism.dll
2008-02-24 19:59 . 2006-10-26 12:22 20,747 -ra------ C:\WINDOWS\system32\drivers\AegisP.sys
2008-02-08 18:37 . 2008-02-08 18:37 219,664 --a------ C:\WINDOWS\system32\klogon.dll
2008-02-08 18:35 . 2008-02-08 18:35 23,604 --a------ C:\WINDOWS\system32\drivers\klopp.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-25 09:11 118,222 ----a-w C:\WINDOWS\Fonts\x.zip
2008-02-22 22:54 --------- d-----w C:\Program Files\microsoft frontpage
2005-07-29 21:24 472 --sha-r C:\WINDOWS\QmxhcU91dCBFbnQu\kAU1wo6YxF1IvBkR.vbs
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1C2E5D27-A17C-4D89-85DD-3553C189380D}]
C:\Program Files\RABCO\RABCO.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{218A4EE1-F2EC-471E-B8A3-BB61A6CEE946}]
C:\WINDOWS\system32\gebyv.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="" []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-02-10 11:55 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-02-10 11:51 118784]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 03:42 144784]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-01-15 17:54 37376]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 14:42 1404928]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [2008-02-08 18:36 227856]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Wireless USB 2.0 WLAN Card Utility.lnk - C:\Program Files\Dell Wireless\PRISMCFG.exe [2008-02-24 19:59:54 921707]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PRISMAPI.DLL]
PRISMAPI.DLL 2006-10-12 09:42 450649 C:\WINDOWS\system32\PRISMAPI.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\kav\\kav7\\setup.exe"=
"C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 7.0\\avp.exe"=
"C:\\Documents and Settings\\Administrator\\Desktop\\utorrent.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
R2 PRISMSVC;PRISMSVC;C:\WINDOWS\system32\PRISMSVC.EXE [2006-10-12 09:45]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 16:38]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-12-13 13:28]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-27 08:44:35
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\PRISMSVR.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\wdfmgr.exe
.
**************************************************************************
.
Completion time: 2008-02-27 9:08:00 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-27 13:47:53
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:15:55, on 2/27/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\PRISMSVR.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\PRISMSVC.EXE
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Dell Wireless\PRISMCFG.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RabioBHO - {1C2E5D27-A17C-4D89-85DD-3553C189380D} - C:\Program Files\RABCO\RABCO.dll (file missing)
O2 - BHO: (no name) - {218A4EE1-F2EC-471E-B8A3-BB61A6CEE946} - C:\WINDOWS\system32\gebyv.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - Global Startup: Wireless USB 2.0 WLAN Card Utility.lnk = ?
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: PRISMSVC - Conexant Systems, Inc. - C:\WINDOWS\system32\PRISMSVC.EXE
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 3451 bytes