what is hjt?
yes i realise now i should have contacted you before running the Combofix... here is the Combofix log anyway. btw what is hjt?
ComboFix 08-05-28.2 - 2008-05-28 23:58:38.1 - NTFSx86
Running from: C:\Documents and Settings\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\boqnrwdmmfv.dll
C:\WINDOWS\egao.exe
C:\WINDOWS\system32\ajvldicd.ini
C:\WINDOWS\system32\augudhqq.dll
C:\WINDOWS\system32\dcidlvja.dll
C:\WINDOWS\system32\klUutBeg.ini2
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\nnoUttwa.ini
C:\WINDOWS\system32\nnoUttwa.ini2
C:\WINDOWS\system32\qqhdugua.ini
C:\WINDOWS\system32\QWFPAJjl.ini
C:\WINDOWS\system32\QWFPAJjl.ini2
C:\WINDOWS\system32\rsxpaaau.ini
C:\WINDOWS\system32\vtUnnNec.dll
C:\WINDOWS\system32\wwHOUvut.ini
C:\WINDOWS\system32\wwHOUvut.ini2
C:\WINDOWS\system32\yFPrCfhk.ini
C:\WINDOWS\system32\yFPrCfhk.ini2
C:\WINDOWS\vregfwlx.dll
C:\WINDOWS\xmpstean.exe
.
((((((((((((((((((((((((( Files Created from 2008-04-28 to 2008-05-28 )))))))))))))))))))))))))))))))
.
2008-05-29 02:36 . 2008-05-29 05:18 0 --a------ C:\SMINST
2008-05-28 21:43 . 2008-05-28 21:43 322,816 --a------ C:\WINDOWS\system32\khfCrPFy.dll_old
2008-05-28 17:25 . 2008-05-28 17:26 <DIR> d-------- C:\Documents and Settings\Siti Nurbayani\E111
2008-05-28 16:46 . 2008-05-29 00:06 34,343 --ahs---- C:\Program Files\Common Files\fjOs0r.dll
2008-05-28 06:28 . 2008-05-28 23:18 715 --a------ C:\WINDOWS\wininit.ini
2008-05-28 05:30 . 2008-05-28 05:30 <DIR> d-------- C:\Program Files\Snapshot Viewer
2008-05-28 05:30 . 2008-05-28 05:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SBT
2008-05-25 16:41 . 2008-05-25 16:54 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-05-12 10:23 . 2008-05-12 10:23 <DIR> d-------- C:\WINDOWS\speech
2008-05-06 14:03 . 2008-05-13 09:53 <DIR> d-------- C:\Program Files\E230 MediaKit
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-29 04:31 --------- d-----w C:\Program Files\Oca History Tool
2008-05-29 04:31 --------- d-----w C:\Program Files\Microsoft Works
2008-05-22 00:47 --------- d-----w C:\Documents and Settings\Siti Nurbayani\Application Data\AdobeUM
2007-11-08 22:35 150 -c--a-w C:\Documents and Settings\Muhsin\Application Data\wklnhst.dat
2007-10-30 23:41 0 -c--a-w C:\Program Files\test only.txt
2007-10-26 20:47 0 -c--a-w C:\Documents and Settings\Siti Nurbayani\Application Data\wklnhst.dat
2003-08-27 22:19 36,963 ----a-r C:\Program Files\Common Files\SM1updtr.dll
2007-12-06 23:15 0 -csha-w C:\WINDOWS\SMINST\HPCD.sys
.
------- Sigcheck -------
2005-03-02 01:36 2056832 d8aba3eab509627e707a3b14f00fbb6b C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
2004-08-03 23:59 2056832 947fb1d86d14afcffdb54bf837ec25d0 C:\WINDOWS\$NtUninstallKB890859$\ntkrnlpa.exe
2005-03-02 01:34 2056832 81013f36b21c7f72cf784cc6731e0002 C:\WINDOWS\$NtUninstallKB896256$\ntkrnlpa.exe
2005-09-29 00:35 2057344 c60248dde015b0a73871a16576b7a945 C:\WINDOWS\$NtUninstallKB931784$\ntkrnlpa.exe
2005-09-29 00:35 2057344 c60248dde015b0a73871a16576b7a945 C:\WINDOWS\Driver Cache\i386\ntkrnlpa.exe
2007-02-28 10:15 2059392 4d3dbdccbf97f5ba1e74f322b155c3ba C:\WINDOWS\system32\ntkrnlpa.exe
2007-02-28 10:15 2059392 4d3dbdccbf97f5ba1e74f322b155c3ba C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2005-09-29 00:35 2057344 c60248dde015b0a73871a16576b7a945 C:\WINDOWS\system32\ReinstallBackups\
0000\DriverFiles\i386\ntkrnlpa.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9D5C4B2B-247C-4E12-A388-8D9BE1E18B42}]
C:\WINDOWS\system32\tuvUOHww.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AA4BA992-AF5A-4202-9F63-EDC55A6C2592}]
C:\WINDOWS\system32\ljJAPFWQ.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C2626E66-D21B-E628-C1DF-1DACCFA36ED2}]
2008-05-29 00:06 34343 --ahs---- C:\Program Files\Common Files\fjOs0r.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E6D48806-D28D-46BE-8D47-BF4E379A568D}]
C:\WINDOWS\system32\khfCrPFy.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FEAE9D92-2946-40B7-BFDE-D10157A1B234}]
C:\WINDOWS\system32\awttUonn.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2002-09-13 23:42 212992]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-03-23 05:17 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-03-23 05:13 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-03-23 05:17 118784]
"RTHDCPL"="RTHDCPL.EXE" [2006-09-11 18:58 16264192 C:\WINDOWS\RTHDCPL.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 13:44:06 29696]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 13:05:56 65588]
Ralink Wireless Utility.lnk.disabled [2007-06-29 16:09:18 1621]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{CC3596CB-D6C1-ECA1-AE51-DEEA63F6C21C}"= C:\Program Files\Internet Explorer\OnlO0r.dll [2008-05-29 00:06 34343]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.clmp3enc"= C:\PROGRA~1\CYBERL~1\Power2Go\CLMP3Enc.ACM
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Power2GoExpress"=
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SM1BG"=C:\WINDOWS\SM1BG.EXE
"SMSERIAL"=C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
"vptray"=C:\Program Files\NavNT\vptray.exe
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
"SkyTel"=SkyTel.EXE
"TalkTalk"="C:\Program Files\TalkTalk\bin\sprtcmd.exe" /P TalkTalk
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\Z]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a2044a21-6549-11da-a5a1-806d6172696f}]
\Shell\AutoRun\command - E:\Launch.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-29 00:07:18
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\NavLogon.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-05-29 0:10:33 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-28 23:10:24
Pre-Run: 29,041,377,280 bytes free
Post-Run: 28,993,392,640 bytes free
137 --- E O F --- 2008-05-28 01:38:33