Hey this is my ComboFix log, then right below it is the HJT log.
ComboFix 08-08-27.01 - haiammike 2008-08-27 14:52:53.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.465 [GMT -4:00]
Running from: C:\Documents and Settings\haiammike\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\haiammike\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\EndUser\Application Data\macromedia\Flash Player\#SharedObjects\ADPBARGY\interclick.com
C:\Documents and Settings\EndUser\Application Data\macromedia\Flash Player\#SharedObjects\ADPBARGY\interclick.com\ud.sol
C:\Documents and Settings\EndUser\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\EndUser\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\haiammike\Application Data\macromedia\Flash Player\#SharedObjects\WLQP879R\bin.clearspring.com
C:\Documents and Settings\haiammike\Application Data\macromedia\Flash Player\#SharedObjects\WLQP879R\bin.clearspring.com\clearspring.sol
C:\Documents and Settings\haiammike\Application Data\macromedia\Flash Player\#SharedObjects\WLQP879R\interclick.com
C:\Documents and Settings\haiammike\Application Data\macromedia\Flash Player\#SharedObjects\WLQP879R\interclick.com\ud.sol
C:\Documents and Settings\haiammike\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com
C:\Documents and Settings\haiammike\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com\settings.sol
C:\Documents and Settings\haiammike\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\haiammike\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\RECYCLER\ADAPT_Installer.exe
C:\WINDOWS\etbr.exe
C:\WINDOWS\privacy_danger
C:\WINDOWS\privacy_danger\images\capt.gif
C:\WINDOWS\privacy_danger\images\danger.jpg
C:\WINDOWS\privacy_danger\images\down.gif
C:\WINDOWS\privacy_danger\images\spacer.gif
C:\WINDOWS\system32\amhyjdli.dll
C:\WINDOWS\system32\bIiRtBeg.ini
C:\WINDOWS\system32\bIiRtBeg.ini2
C:\WINDOWS\system32\ddcbCspn.dll
C:\WINDOWS\system32\debpbkto.dll
C:\WINDOWS\system32\eqxuykom.dll
C:\WINDOWS\system32\geBtRiIb.dll
C:\WINDOWS\system32\hdjbqobl.dll
C:\WINDOWS\system32\hnfoha.dll
C:\WINDOWS\system32\hwryvtbk.dll
C:\WINDOWS\system32\irvptjks.dll
C:\WINDOWS\system32\jcbaveun.dll
C:\WINDOWS\system32\kvdkggcr.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\nuevabcj.ini
C:\WINDOWS\system32\oilwuc.dll
C:\WINDOWS\system32\otkbpbed.ini
C:\WINDOWS\system32\qartonsu.dll
C:\WINDOWS\system32\rcggkdvk.dll
C:\WINDOWS\system32\rddfpn.dll
C:\WINDOWS\system32\rqoxfu.dll
C:\WINDOWS\system32\rqRKARlk.dll
C:\WINDOWS\system32\rxbofkot.ini
C:\WINDOWS\system32\skjtpvri.ini
C:\WINDOWS\system32\ujjnhu.dll
C:\WINDOWS\system32\vkbyowfc.ini
C:\WINDOWS\system32\vywithew.dll
C:\WINDOWS\system32\ylmldd.dll
C:\WINDOWS\system32\yxrjgvpb.ini
----- BITS: Possible infected sites -----
http://hqsextube08.com
.
((((((((((((((((((((((((( Files Created from 2008-07-27 to 2008-08-27 )))))))))))))))))))))))))))))))
.
2008-08-26 17:41 . 2008-08-26 17:41 303,104 --a------ C:\WINDOWS\system32\hsaserem.exe
2008-08-26 17:41 . 2008-08-27 14:53 200,704 --a------ C:\WINDOWS\SysNotifier.exe
2008-08-25 16:32 . 2008-08-25 16:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-08-25 15:55 . 2008-08-25 15:55 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-08-25 11:23 . 2008-08-25 11:23 <DIR> d-------- C:\Documents and Settings\Administrator
2008-08-25 11:19 . 2008-08-25 11:19 <DIR> d-------- C:\Program Files\Trend Micro
2008-08-25 10:48 . 2008-08-25 10:48 <DIR> d-------- C:\Documents and Settings\haiammike\Application Data\Aim
2008-08-25 00:00 . 2008-08-25 00:00 <DIR> d-------- C:\Documents and Settings\haiammike
2008-08-24 22:29 . 2008-08-27 01:27 296 --a------ C:\WINDOWS\wininit.ini
2008-08-24 21:47 . 2008-08-25 12:03 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-08-24 21:47 . 2008-08-24 23:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-24 21:38 . 2008-08-24 06:45 380,928 --a------ C:\WINDOWS\rodqgpvlkoa.dll
2008-08-24 21:38 . 2008-08-24 21:38 126,976 --a------ C:\WINDOWS\kx60171.dll
2008-08-24 21:38 . 2008-08-24 06:45 86,016 --a------ C:\WINDOWS\rvoelbxt.exe
2008-08-24 07:06 . 2008-08-24 07:06 <DIR> d-------- C:\Temp
2008-08-21 21:58 . 2008-08-21 21:58 <DIR> d-------- C:\Program Files\Norton PC Checkup
2008-08-21 21:58 . 2008-08-25 17:31 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2008-08-21 19:05 . 2008-08-21 19:05 <DIR> d-------- C:\Documents and Settings\EndUser\Application Data\Apple Computer
2008-08-20 21:46 . 2008-08-24 06:51 <DIR> d-------- C:\Fraps
2008-08-20 21:23 . 2008-08-20 21:23 <DIR> d-------- C:\Program Files\Guitar Pro 5
2008-08-20 00:23 . 2008-08-21 18:58 <DIR> d-------- C:\WINDOWS\system32\Adobe
2008-08-20 00:17 . 2008-08-20 00:17 <DIR> d-------- C:\Program Files\Jasc Software Inc
2008-08-19 01:38 . 2008-08-19 03:23 <DIR> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-07-28 19:02 . 2008-07-28 19:02 <DIR> d-------- C:\Program Files\Ventrilo
2008-07-28 19:00 . 2008-07-28 19:00 <DIR> d-------- C:\Program Files\VentSrv
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-25 20:16 --------- d-----w C:\Program Files\Common Files\Adobe
2008-08-24 18:50 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-24 11:05 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-20 04:16 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-07-28 23:02 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-07-28 22:55 --------- d-----w C:\Program Files\World of Warcraft
2008-07-26 23:14 --------- d-----w C:\Documents and Settings\EndUser\Application Data\MSNInstaller
2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 15:38 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3753B44D-E02F-48B7-81B1-19A377BCCB63}]
2008-08-26 17:41 299008 --a------ C:\Documents and Settings\EndUser\Application Data\Help\tfpapi.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{72DB2104-BEAC-3D08-AFC0-554316CD0BC4}]
2008-08-24 21:38 126976 --a------ C:\WINDOWS\kx60171.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AIM"="C:\Program Files\AIM\aim.exe" [2006-08-01 15:35 67112]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:00 15360]
"AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-02-28 23:06 2321600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Camio Viewer.lnk - C:\Program Files\Jasc Software Inc\After Shot\IXApplet.exe [2002-02-11 14:59:44 53248]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tfpapi]
2008-08-26 17:41 299008 C:\Documents and Settings\EndUser\Application Data\Help\tfpapi.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\DNA\\btdna.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6112:TCP"= 6112:TCP:Blizzard Downloader
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
Toolbar-{18C388BB-5014-4906-AE38-E62BA5AA7387} - C:\WINDOWS\qalkfxor.dll
HKLM-Run-a823822d - C:\WINDOWS\system32\debpbkto.dll
SSODL-pdoskegl-{BF4920B4-730E-44B9-9A5B-DB4CE76EFDDD} - C:\WINDOWS\pdoskegl.dll
SSODL-rqbmvpso-{8558A655-C137-461E-BD0A-9C6683600527} - C:\WINDOWS\rqbmvpso.dll
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\haiammike\Application Data\Mozilla\Firefox\Profiles\rg3ak8ek.default\
FF -: plugin - C:\Program Files\DNA\plugins\npbtdna.dll
FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-08-27 15:05:03
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\Documents and Settings\EndUser\Application Data\Help\tfpapi.dll
PROCESS: C:\WINDOWS\explorer.exe
-> C:\Documents and Settings\EndUser\Application Data\Help\tfpapi.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-08-27 15:09:52 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-27 19:09:37
Pre-Run: 1,269,612,544 bytes free
Post-Run: 1,391,423,488 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
189 --- E O F --- 2008-08-15 07:06:22
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:12:04, on 8/27/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Jasc Software Inc\After Shot\IXApplet.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - Global Startup: Camio Viewer.lnk = C:\Program Files\Jasc Software Inc\After Shot\IXApplet.exe
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
--
End of file - 3608 bytes