Thanks so much! The popups have stopped, and everthing is running more smoothly:laugh:
Here are the latest log reports:
Combofix:
ComboFix 07-12-12.3 - Owner 2007-12-13 16:28:49.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.165 [GMT -6:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2007-11-13 to 2007-12-13 )))))))))))))))))))))))))))))))
.
2007-12-08 15:55 . 2007-12-09 14:12 834,700 --ahs---- C:\WINNT\system32\vlkehtwp.ini
2007-12-07 15:53 . 2007-12-08 15:53 834,640 --ahs---- C:\WINNT\system32\qkgacaaj.ini
2007-12-06 15:56 . 2007-12-07 15:24 831,735 --ahs---- C:\WINNT\system32\manxboto.ini
2007-12-05 15:56 . 2007-12-06 08:50 807,675 --ahs---- C:\WINNT\system32\xykjhdbq.ini
2007-12-04 15:52 . 2007-12-05 15:53 807,528 --ahs---- C:\WINNT\system32\dqpifetn.ini
2007-11-29 23:02 . 2007-12-01 18:35 1,206 --a------ C:\WINNT\system32\tmp.reg
2007-11-28 16:53 . 2007-11-28 16:53 <DIR> d-------- C:\Program Files\Trend Micro
2007-11-26 21:48 . 2006-10-27 15:07 66,048 --a------ C:\WINNT\ieResetIcons.exe
2007-11-25 21:17 . 2007-12-10 07:37 887 --a------ C:\WINNT\wininit.ini
2007-11-25 16:48 . 2007-11-25 16:48 <DIR> d-------- C:\Program Files\DFX
2007-11-25 14:49 . 2007-12-01 18:38 143 --a------ C:\WINNT\system32\mcrh.tmp
2007-11-25 13:18 . 2007-11-25 13:18 147,456 --a------ C:\WINNT\system32\vbzip10.dll
2007-11-25 13:15 . 2007-11-25 13:15 166,945 --a------ C:\WINNT\system32\drivers\core.cache(5).dsk
2007-11-25 13:15 . 2007-11-25 13:15 166,945 --a------ C:\WINNT\system32\drivers\core.cache(4).dsk
2007-11-25 13:15 . 2007-11-25 13:15 166,945 --a------ C:\WINNT\system32\drivers\core.cache(3).dsk
2007-11-25 13:15 . 2007-11-25 13:15 166,945 --a------ C:\WINNT\system32\drivers\core.cache(2).dsk
2007-11-25 13:15 . 2007-11-25 13:15 120 --a------ C:\n.bat
2007-11-23 10:15 . 2007-12-12 23:42 <DIR> d-------- C:\Program Files\Barbie ® Riding Club
2007-11-20 22:19 . 2007-11-20 22:20 <DIR> d-------- C:\Program Files\Picasa2
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-13 04:44 --------- d-----w C:\Program Files\LimeWire
2007-12-12 22:21 --------- d-----w C:\Documents and Settings\Owner\Application Data\PlayFirst
2007-12-10 21:46 --------- d-----w C:\Program Files\SpywareBlaster
2007-12-10 04:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2007-12-07 19:07 --------- d-----w C:\Program Files\MySpace
2007-12-02 05:57 --------- d-----w C:\Program Files\Lavasoft
2007-12-01 22:25 --------- d-----w C:\Program Files\pnotcaoh
2007-12-01 22:25 --------- d-----w C:\Program Files\iWin Games
2007-11-28 22:58 --------- d-----w C:\Program Files\QuickTime
2007-11-28 03:56 --------- d-----w C:\Program Files\Nick Jr. Arcade
2007-11-25 21:24 118,337 ----a-w C:\WINNT\Fonts\x.zip
2007-11-22 15:18 --------- d-----w C:\Program Files\ValuSoft
2007-11-21 04:19 --------- d-----w C:\Program Files\Google
2007-10-29 01:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-29 01:56 --------- d-----w C:\Program Files\MUSICMATCH
2007-10-29 01:55 --------- d-----w C:\Program Files\Dell
2007-10-26 03:34 8,460,288 ----a-w C:\WINNT\system32\dllcache\shell32.dll
2007-10-16 18:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\TEMP
2007-06-13 01:47 149,368 ----a-w C:\Documents and Settings\Owner\Application Data\GDIPFONTCACHEV1.DAT
2007-04-01 02:53 20 ---h--w C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
2005-05-13 23:12 217,073 --sha-r C:\WINNT\meta4.exe
2005-10-24 17:13 66,560 --sha-r C:\WINNT\MOTA113.exe
2005-10-14 03:27 422,400 --sha-r C:\WINNT\x2.64.exe
2007-03-09 07:12 27,648 --sha-w C:\WINNT\system32\AVSredirect.dll
2005-06-26 21:32 616,448 --sha-r C:\WINNT\system32\cygwin1.dll
2005-06-22 04:37 45,568 --sha-r C:\WINNT\system32\cygz.dll
2004-01-25 06:00 70,656 --sha-r C:\WINNT\system32\i420vfw.dll
2006-04-27 16:24 2,945,024 --sha-r C:\WINNT\system32\Smab.dll
2005-02-28 19:16 240,128 --sha-r C:\WINNT\system32\x.264.exe
2004-01-25 06:00 70,656 --sha-r C:\WINNT\system32\yv12vfw.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINNT\system32\ctfmon.exe" [2004-08-04 01:56]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Amazing3DAquariumWallpaper"="" []
"eTrustPPAP"="C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\PPActiveDetection.exe" [2006-12-22 22:23]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
R2 RioPNP;RioPNP;C:\WINNT\system32\drivers\RioPNP.sys
S2 DVC150;DVC 150B;C:\WINNT\system32\Drivers\dvc150b.sys
S2 NMSSvc;Intel(R) NMS;C:\WINNT\System32\NMSSvc.exe
S3 DSCVc;Video Capture;C:\WINNT\system32\DRIVERS\CoachVc.sys
S3 ENDETECT;ENDETECT;\??\C:\PROGRA~1\FRONTI~1\FRONTI~1\app\ENDETECT.SYS
S3 L2XPSR;L2XPSR;\??\C:\PROGRA~1\FRONTI~1\FRONTI~1\app\L2XPSR.SYS
S3 NTSTPL1;NTSTPL1;\??\C:\PROGRA~1\FRONTI~1\FRONTI~1\app\NTSTPL1.SYS
S3 PCDRDRV;Pcdr Helper Driver;\??\C:\Atf\Qctest\PCDoc\PCDRDRV.sys
S3 SilverLink;Texas Instruments SilverLink (USB GraphLink) Cable;C:\WINNT\system32\Drivers\SilvrLnk.sys
S3 TAPBIND;TAPBIND;\??\C:\PROGRA~1\FRONTI~1\FRONTI~1\app\TAPBIND1.SYS
*Newly Created Service* - NMSSVC
.
Contents of the 'Scheduled Tasks' folder
"2007-12-06 22:51:04 C:\WINNT\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-12-13 19:54:10 C:\WINNT\Tasks\PPv5Scan_Daily as Owner at 1 54 PM.job"
- C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\ppv5consumercl.exe
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-13 16:33:24
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2007-12-13 16:35:46
C:\ComboFix2.txt ... 2007-12-12 16:54
C:\ComboFix3.txt ... 2007-12-12 15:56
.
2007-11-15 13:26:54 --- E O F ---
And Hijackthis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:39:11 PM, on 12/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\PPActiveDetection.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINNT\explorer.exe
C:\Program Files\Trend Micro\HijackThis\jadite11.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: CCHelper Class - {0CF0B8EE-6596-11D5-A98E-0003470BB48E} - C:\Program Files\Panicware\Pop-Up Stopper\CCHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [eTrustPPAP] "C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\PPActiveDetection.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} (TmHcmsX Control) -
http://www.trendsecure.com/framework/control/en-US/activex/TmHcmsX.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1196554239078
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINNT\System32\NMSSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINNT\system32\ZoneLabs\vsmon.exe
--
End of file - 2979 bytes