Virtumonde! please help

Morjill

New member
Have run S&D repeatedly in and out of Safe mode.

Thanks in advance
Ray

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:25:25 PM, on 9/22/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18241)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\program files\powerstrip\pstrip.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Raymond\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [PowerStrip] c:\program files\powerstrip\pstrip.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [AIMPro] "C:\Program Files\AIM\AIM Pro\aimpro.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.line6.net
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) - http://www.windowsvistatestdrive.com/mm/ActiveX/VMRCActiveXClient1.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1208043461281
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - AppInit_DLLs: wbsys.dll hlwqtn.dll lnkdop.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

--
End of file - 7965 bytes
 
Hi Morjill

Rename HijackThis.exe to Morjill.exe and post back a fresh HijackThis log, please :)
 
Interesting request:), but done!

Thanks!


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:02:55 PM, on 9/24/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18241)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\program files\powerstrip\pstrip.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Raymond\Desktop\Morjill.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: (no name) - {09C72999-5C10-41A3-A524-24661D942003} - C:\WINDOWS\system32\efcdDVPH.dll
O2 - BHO: {5a788a6c-00eb-cf0b-b3d4-af511f5b56f2} - {2f65b5f1-15fa-4d3b-b0fc-be00c6a887a5} - C:\WINDOWS\system32\fpqsqu.dll
O2 - BHO: (no name) - {4271771D-8C95-45B3-BBBE-647905C24638} - (no file)
O2 - BHO: (no name) - {49E7E212-185E-4B1A-81AA-2569449CCF7A} - C:\WINDOWS\system32\ljJAQHBT.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {78c2a303-574f-4fa6-b850-aedcc57ab4ac} - (no file)
O2 - BHO: (no name) - {A7A0A4B4-9EBF-41B9-A4E3-55A1EABDBF15} - (no file)
O2 - BHO: CoTGT_BHO Class - {C333CF63-767F-4831-94AC-E683D962C63C} - (no file)
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [PowerStrip] c:\program files\powerstrip\pstrip.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [AIMPro] "C:\Program Files\AIM\AIM Pro\aimpro.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe"
O4 - HKLM\..\Run: [e0155403] rundll32.exe "C:\WINDOWS\system32\sidlmpwi.dll",b
O4 - HKLM\..\Run: [BMe326679f] Rundll32.exe "C:\WINDOWS\system32\uyecscxb.dll",s
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.line6.net
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) - http://www.windowsvistatestdrive.com/mm/ActiveX/VMRCActiveXClient1.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1208043461281
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - AppInit_DLLs: wbsys.dll hlwqtn.dll fpqsqu.dll
O20 - Winlogon Notify: efcdDVPH - C:\WINDOWS\SYSTEM32\efcdDVPH.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

--
End of file - 9000 bytes
 
I asked you to do that because infection you have hides certain HijackThis entries if process named HijackThis is running :)

Create own folder for HijackThis to desktop and move it into that folder.

After that:

We will begin with ComboFix. Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Please ensure you read this guide carefully and install the Recovery Console first.

The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

Once installed, you should see a blue screen prompt that says:

The Recovery Console was successfully installed.

Please continue as follows:

  1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link
    Remember to re-enable them afterwards.

  2. Click Yes to allow ComboFix to continue scanning for malware.

When the tool is finished, it will produce a report for you.

Please include the following reports for further review, and so we may continue cleansing the system:

C:\ComboFix.txt
New HijackThis log.


A word of warning: Please do not run ComboFix on your own. This tool is not a toy and not for everyday use.
 
Things seem a bit better. I did get one popup asking me to install AV2008, or some such thing. And just now go the huge popup telling me I have dangerous spyware... install Antivirus 2009 to fix...

After I posted last time, I compared the 2 HJT logs and figured out that there were "new" entries after changing the prg name...:cool:

Here's the Combofix log:

ComboFix 08-09-24.11 - Raymond 2008-09-25 8:17:49.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2007 [GMT -5:00]
Running from: C:\Documents and Settings\Raymond\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Hunter\Application Data\.#
C:\Documents and Settings\Hunter\Application Data\.#\MBX@1454@A35028.###
C:\Documents and Settings\Hunter\Application Data\.#\MBX@1454@A35038.###
C:\Documents and Settings\Hunter\Application Data\.#\MBX@1454@A35058.###
C:\Documents and Settings\Hunter\Application Data\.#\MBX@1454@A35098.###
C:\Documents and Settings\Hunter\Application Data\.#\MBX@1454@A35198.###
C:\Documents and Settings\Hunter\Application Data\.#\MBX@1454@A351A8.###
C:\Documents and Settings\Hunter\Application Data\.#\MBX@1454@A351B8.###
C:\Documents and Settings\Hunter\Cookies\hunter@2o7[2].txt
C:\Documents and Settings\Hunter\Cookies\hunter@ad.yieldmanager[2].txt
C:\Documents and Settings\Hunter\Cookies\hunter@clicktorrent[2].txt
C:\Documents and Settings\Hunter\Cookies\hunter@insightexpressai[1].txt
C:\Documents and Settings\Hunter\Cookies\hunter@track.bestbuy[1].txt
C:\Documents and Settings\Hunter\Cookies\hunter@www35.vzw[2].txt
C:\Documents and Settings\Hunter\Desktop\Vista Antivirus 2008.lnk
C:\Documents and Settings\Jillian\Cookies\jillian@advertising[2].txt
C:\Documents and Settings\Jillian\Cookies\jillian@track.bestbuy[1].txt
C:\Documents and Settings\Jillian\Cookies\jillian@www35.vzw[3].txt
C:\Documents and Settings\Morgan\Cookies\morgan@advertising[2].txt
C:\Documents and Settings\Morgan\Cookies\morgan@cubics[2].txt
C:\Documents and Settings\Morgan\Cookies\morgan@insightexpressai[2].txt
C:\Documents and Settings\Morgan\Cookies\morgan@trafficmp[1].txt
C:\Documents and Settings\Raymond\Cookies\raymond@2o7[2].txt
C:\Documents and Settings\Raymond\Cookies\raymond@a.amd[2].txt
C:\Documents and Settings\Raymond\Cookies\raymond@cubics[2].txt
C:\Documents and Settings\Raymond\Cookies\raymond@insightexpressai[2].txt
C:\Documents and Settings\Raymond\Cookies\raymond@revsci[2].txt
C:\Documents and Settings\Raymond\Cookies\raymond@specificclick[2].txt
C:\Documents and Settings\Raymond\Cookies\raymond@specificclick[3].txt
C:\Documents and Settings\Raymond\Cookies\raymond@turn[1].txt
C:\Documents and Settings\Raymond\Cookies\raymond@www35.vzw[2].txt
C:\Program Files\MicroAV
C:\Program Files\MicroAV\MicroAV.ooo
C:\Program Files\MicroAV\MicroAV0.dat
C:\Program Files\MicroAV\MicroAV1.dat
C:\Program Files\VAV
C:\Program Files\VAV\vav.ooo
C:\WINDOWS\BMe326679f.txt
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\avdoerby.ini
C:\WINDOWS\system32\efcdDVPH.dll
C:\WINDOWS\system32\hyiuroyp.ini
C:\WINDOWS\system32\iwpmldis.ini
C:\WINDOWS\system32\lphcraaj0ea2g.exe
C:\WINDOWS\system32\oaqypxvn.ini
C:\WINDOWS\system32\qodahpei.ini
C:\WINDOWS\system32\TBHQAJjl.ini
C:\WINDOWS\system32\wtujlvoe.dll
C:\WINDOWS\system32\wwjdyglc.ini

.
((((((((((((((((((((((((( Files Created from 2008-08-25 to 2008-09-25 )))))))))))))))))))))))))))))))
.

2008-09-25 08:37 . 2008-09-25 08:37 22 --a------ C:\WINDOWS\pskt.ini
2008-09-24 20:10 . 2008-09-24 20:10 116,224 --a------ C:\WINDOWS\system32\qclslp.dll
2008-09-24 20:10 . 2008-09-24 20:10 116,224 --a------ C:\WINDOWS\system32\iphcyutu.dll
2008-09-24 20:07 . 2008-09-24 20:07 89,600 --a------ C:\WINDOWS\system32\ybreodva.dll
2008-09-24 20:05 . 2008-09-24 20:05 97,280 --a------ C:\WINDOWS\system32\katjxxfl.dll
2008-09-24 20:01 . 2008-09-24 20:01 97,280 --a------ C:\WINDOWS\system32\mbumdsqk.dll
2008-09-24 19:01 . 2008-09-24 19:01 113,152 --a------ C:\WINDOWS\system32\nfhuxkex.dll
2008-09-24 19:01 . 2008-09-24 19:01 113,152 --a------ C:\WINDOWS\system32\fpqsqu.dll
2008-09-24 18:56 . 2008-09-24 18:56 99,328 --a------ C:\WINDOWS\system32\uyecscxb.dll
2008-09-22 03:13 . 2008-09-22 03:13 113,152 --a------ C:\WINDOWS\system32\lnkdop.dll
2008-09-22 03:13 . 2008-09-22 03:13 113,152 --a------ C:\WINDOWS\system32\hqcsbgel.dll
2008-09-22 03:10 . 2008-09-22 03:10 90,624 --a------ C:\WINDOWS\system32\pyoruiyh.dll
2008-09-21 21:10 . 2008-09-21 21:10 113,152 --a------ C:\WINDOWS\system32\thxgiega.dll
2008-09-21 21:10 . 2008-09-21 21:10 113,152 --a------ C:\WINDOWS\system32\icjivb.dll
2008-09-21 21:08 . 2008-09-21 21:08 90,624 --a------ C:\WINDOWS\system32\iephadoq.dll
2008-09-21 21:01 . 2008-09-21 21:01 113,152 --a------ C:\WINDOWS\system32\lmfrbfcu.dll
2008-09-21 21:01 . 2008-09-21 21:01 113,152 --a------ C:\WINDOWS\system32\hlwqtn.dll
2008-09-21 21:01 . 2008-09-21 21:01 97,792 --a------ C:\WINDOWS\system32\kujskaqm.dll
2008-09-21 20:59 . 2008-09-21 20:59 113,152 --a------ C:\WINDOWS\system32\yufamqcn.dll
2008-09-21 20:59 . 2008-09-21 20:59 113,152 --a------ C:\WINDOWS\system32\yjzfpq.dll
2008-09-21 20:57 . 2008-09-21 20:57 97,792 --a------ C:\WINDOWS\system32\kgwamoii.dll
2008-09-21 18:46 . 2008-09-21 18:46 113,152 --a------ C:\WINDOWS\system32\wwozsz.dll
2008-09-21 18:46 . 2008-09-21 18:46 113,152 --a------ C:\WINDOWS\system32\qicksjkr.dll
2008-09-21 18:46 . 2008-09-21 18:46 97,792 --a------ C:\WINDOWS\system32\vmsyxiby.dll
2008-09-21 18:42 . 2008-09-21 18:42 97,792 --a------ C:\WINDOWS\system32\nndykeat.dll
2008-09-21 18:40 . 2008-09-25 08:37 111,588 --a------ C:\WINDOWS\BMe326679f.xml
2008-09-21 18:39 . 2008-09-21 18:40 97,792 --a------ C:\WINDOWS\system32\ilxnfsrb.dll
2008-09-21 18:38 . 2008-09-25 08:18 893,396 --ahs---- C:\WINDOWS\system32\TBHQAJjl.ini2
2008-09-21 18:38 . 2008-09-21 18:38 252,928 --a------ C:\WINDOWS\system32\ljJAQHBT.dll
2008-09-21 10:21 . 2008-09-21 10:21 <DIR> d-------- C:\Program Files\Electronic Arts
2008-09-21 10:21 . 2008-09-21 10:21 <DIR> d-------- C:\Documents and Settings\Hunter\Application Data\SPORE Creature Creator
2008-09-21 10:21 . 2008-09-21 10:21 107,888 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2008-09-10 21:19 . 2008-09-10 21:19 <DIR> d-------- C:\Documents and Settings\Hunter\Application Data\Media Player Classic
2008-09-09 18:26 . 2008-09-09 18:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-09-09 18:23 . 2008-09-09 18:25 <DIR> d-------- C:\Program Files\QuickTime Alternative
2008-09-09 18:23 . 2008-09-09 18:23 <DIR> d-------- C:\Program Files\Media Player Classic
2008-09-09 18:15 . 2008-09-09 18:15 <DIR> d-------- C:\Program Files\Windows Installer Clean Up
2008-09-09 18:14 . 2008-09-09 18:14 <DIR> d-------- C:\Program Files\MSECACHE
2008-09-09 17:02 . 2008-09-05 22:16 1,900,544 --a------ C:\WINDOWS\system32\usbaaplrc.dll
2008-09-08 23:30 . 2008-09-08 23:30 <DIR> d-------- C:\Documents and Settings\Raymond\Application Data\NCH Software
2008-09-08 23:29 . 2008-09-08 23:29 <DIR> d-------- C:\Program Files\NCH Software
2008-09-08 23:29 . 2008-09-08 23:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NCH Software
2008-09-06 21:52 . 2008-09-06 21:52 7,680 --ahs---- C:\WINDOWS\Thumbs.db
2008-09-06 15:09 . 2008-09-06 15:09 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-09-06 15:09 . 2008-09-06 15:09 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
2008-09-03 21:31 . 2008-09-03 21:31 <DIR> d--hs---- C:\Documents and Settings\Raymond\PrivacIE
2008-09-03 18:31 . 2008-09-03 18:31 <DIR> d--hs---- C:\Documents and Settings\Jillian\PrivacIE
2008-09-03 18:30 . 2008-09-03 18:30 <DIR> d--hs---- C:\Documents and Settings\Morgan\PrivacIE
2008-09-03 18:28 . 2008-09-03 18:28 <DIR> d--hs---- C:\Documents and Settings\Hunter\PrivacIE
2008-09-03 18:20 . 2008-09-03 18:22 <DIR> d--h-c--- C:\WINDOWS\ie8
2008-08-29 10:18 . 2008-08-29 10:18 87,336 --a------ C:\WINDOWS\system32\dns-sd.exe
2008-08-29 09:53 . 2008-08-29 09:53 61,440 --a------ C:\WINDOWS\system32\dnssd.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-25 13:23 --------- d-----w C:\Program Files\Symantec AntiVirus
2008-09-22 02:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-22 02:10 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-09-22 02:03 --------- d-----w C:\Program Files\Thoosje Sidebar V2.3
2008-09-22 02:01 --------- d-----w C:\Program Files\Line6
2008-09-21 23:26 --------- d-----w C:\Documents and Settings\Hunter\Application Data\LimeWire
2008-09-21 15:21 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-19 03:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\pdf995
2008-09-18 03:52 --------- d-----w C:\Documents and Settings\Raymond\Application Data\LimeWire
2008-09-09 23:26 --------- d-----w C:\Program Files\iTunes
2008-09-09 23:23 --------- d-----w C:\Documents and Settings\Hunter\Application Data\Apple Computer
2008-09-09 23:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-09-09 22:08 --------- d-----w C:\Program Files\Bonjour
2008-09-09 22:07 --------- d-----w C:\Program Files\QuickTime
2008-09-09 22:06 --------- d-----w C:\Program Files\Common Files\Apple
2008-09-07 15:22 --------- d-----w C:\Documents and Settings\Jillian\Application Data\LimeWire
2008-09-06 03:16 36,864 ----a-w C:\WINDOWS\system32\drivers\usbaapl.sys
2008-08-23 00:22 --------- d-----w C:\Program Files\Apple Software Update
2008-08-22 23:53 --------- d-----w C:\Program Files\Virtual Trumpet
2008-08-22 23:47 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-08-22 23:47 249,856 ------w C:\WINDOWS\Setup1.exe
2008-08-22 01:15 --------- d-----w C:\Program Files\Google
2008-08-21 18:46 --------- d-----w C:\Program Files\WinISD
2008-08-15 21:17 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-15 21:16 --------- d-----w C:\Documents and Settings\Hunter\Application Data\Sony
2008-08-15 21:16 --------- d-----w C:\Documents and Settings\Hunter\Application Data\Publish Providers
2008-08-14 05:39 --------- d-----w C:\Program Files\PowerStrip
2008-08-10 16:22 --------- d-----w C:\Program Files\NBC Direct Beta
2008-08-10 16:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\ExtendMedia
2008-08-10 16:19 --------- d-----w C:\Program Files\OpenCase
2008-08-04 22:56 --------- d-----w C:\Program Files\Microsoft.NET
2008-08-04 22:56 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-08-03 17:58 --------- d-----w C:\Program Files\Singular Inversions
2008-08-03 02:23 --------- d-----w C:\Program Files\Safari
2008-07-31 22:33 --------- d-----w C:\Program Files\SceneCaster
2008-07-25 02:06 12,416 ----a-w C:\WINDOWS\system32\drivers\wpsnuio.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{49E7E212-185E-4B1A-81AA-2569449CCF7A}]
2008-09-21 18:38 252928 --a------ C:\WINDOWS\system32\ljJAQHBT.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-15 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2006-03-15 158208]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-09-06 413696]
"PowerStrip"="c:\program files\powerstrip\pstrip.exe" [2008-05-01 726776]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2006-01-12 155648]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-09-08 289576]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 64512]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-03-24 53408]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe" [2006-09-14 61440]
"e0155403"="C:\WINDOWS\system32\ybreodva.dll" [2008-09-24 89600]
"BMe326679f"="C:\WINDOWS\system32\katjxxfl.dll" [2008-09-24 97280]
"SoundMan"="SOUNDMAN.EXE" [2004-07-01 C:\WINDOWS\SOUNDMAN.EXE]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
2008-04-29 21:58 210168 C:\Program Files\Stardock\Object Desktop\WindowBlinds\WbSrv.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wbsys.dll hlwqtn.dll qclslp.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SavRoam"=3 (0x3)
"ose"=3 (0x3)
"OpenCASE Media Agent"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Adobe\\Photoshop Elements 5.0\\AdobePhotoshopElementsMediaServer.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\OpenCase\\OpenCASE Media Agent\\PandoBinaries\\NBCPandoREST.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56577:TCP"= 56577:TCP:PandoRest Listening Port

R2 PStrip;PStrip;C:\WINDOWS\system32\drivers\pstrip.sys [2007-07-14 27992]
S3 L6POD;L6 PODxt Service;C:\WINDOWS\system32\Drivers\L6POD.sys [2008-06-10 521472]
S3 L6PODX3LV;POD X3 Live Service;C:\WINDOWS\system32\Drivers\L6PODX3LV.sys [2008-06-10 521472]
S4 OpenCASE Media Agent;OpenCASE Media Agent;C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe [2008-08-03 835208]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0917102a-3cb6-11dd-ad8b-0004617c5863}]
\Shell\AutoRun\command - E:\InstallTomTomHOME.exe
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -

BHO-{09C72999-5C10-41A3-A524-24661D942003} - C:\WINDOWS\system32\efcdDVPH.dll
BHO-{4271771D-8C95-45B3-BBBE-647905C24638} - (no file)
BHO-{78c2a303-574f-4fa6-b850-aedcc57ab4ac} - (no file)
BHO-{A7A0A4B4-9EBF-41B9-A4E3-55A1EABDBF15} - (no file)
HKCU-Run-EasyLinkAdvisor - C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
HKLM-Run-AIMPro - C:\Program Files\AIM\AIM Pro\aimpro.exe
ShellExecuteHooks-{09C72999-5C10-41A3-A524-24661D942003} - C:\WINDOWS\system32\efcdDVPH.dll


.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.cnn.com/
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O15 -: Trusted Zone: *.line6.net
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-25 08:37:28
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


C:\WINDOWS\pskt.ini 22 bytes
C:\WINDOWS\BMe326679f.txt 133 bytes
C:\WINDOWS\system32\avdoerby.ini 920090 bytes

scan completed successfully
hidden files: 3

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\ComboFix\pv.cfexe
.
**************************************************************************
.
Completion time: 2008-09-25 8:43:45 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-25 13:43:42

Pre-Run: 25,579,831,296 bytes free
Post-Run: 27,507,408,896 bytes free

268 --- E O F --- 2008-09-11 08:04:22


and here'sthe HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:50:58 AM, on 9/25/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18241)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\svchost.exe
C:\program files\powerstrip\pstrip.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\Raymond\Desktop\Hijack this\Morjill.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {9F5AA6FC-F61D-4E12-85CD-37EC197658FF} - C:\WINDOWS\system32\ljJAQHBT.dll
O2 - BHO: CoTGT_BHO Class - {C333CF63-767F-4831-94AC-E683D962C63C} - (no file)
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [PowerStrip] c:\program files\powerstrip\pstrip.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe"
O4 - HKLM\..\Run: [e0155403] rundll32.exe "C:\WINDOWS\system32\ybreodva.dll",b
O4 - HKLM\..\Run: [BMe326679f] Rundll32.exe "C:\WINDOWS\system32\katjxxfl.dll",s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.line6.net
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) - http://www.windowsvistatestdrive.com/mm/ActiveX/VMRCActiveXClient1.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1208043461281
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - AppInit_DLLs: wbsys.dll hlwqtn.dll qclslp.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

--
End of file - 7595 bytes
 
Yes, we are not done.

To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.

You will now be presented with a screen similar to the one below:

uninstall-man.jpg


5. Click on the Save list... button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here on your next reply.
 
Done!


AC3D 6.2.05
Ad-Aware
Adobe Anchor Service CS3
Adobe Asset Services CS3
Adobe Bridge CS3
Adobe Bridge Start Meeting
Adobe Camera Raw 4.0
Adobe CMaps
Adobe Color Common Settings
Adobe Color EU Extra Settings
Adobe Color JA Extra Settings
Adobe Color NA Recommended Settings
Adobe Device Central CS3
Adobe ExtendScript Toolkit 2
Adobe Flash CS3
Adobe Flash CS3 Professional
Adobe Flash Player 9 ActiveX
Adobe Flash Player ActiveX
Adobe Flash Player Plugin
Adobe Flash Video Encoder
Adobe Help Center 2.1
Adobe Help Viewer CS3
Adobe Linguistics CS3
Adobe PDF Library Files
Adobe Photoshop Elements 5.0
Adobe Reader 7.0
Adobe Setup
Adobe Type Support
Adobe Update Manager CS3
Adobe Version Cue CS3 Client
Adobe WinSoft Linguistics Plugin
Apple Mobile Device Support
Apple Software Update
ATI - Software Uninstall Utility
ATI Display Driver
Bonjour
Canon PIXMA iP4000
DUXUS CLOCK FONT (1.0.0)
FaceGen Modeller 3.1
Finale NotePad 2008
FlyakiteOSX
FontCreator 5.6
Google Gears
Google SketchUp 6
Google SketchUp 6
HijackThis 2.0.2
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 10 (KB903157)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB888795)
Hotfix for Windows XP (KB891593)
Hotfix for Windows XP (KB895961)
Hotfix for Windows XP (KB899337)
Hotfix for Windows XP (KB899510)
Hotfix for Windows XP (KB902841)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
Hotfix for Windows XP (KB952287)
iTunes
J2SE Runtime Environment 5.0 Update 11
J2SE Runtime Environment 5.0 Update 4
Java(TM) 6 Update 4
Java(TM) 6 Update 5
Line 6 Edit (remove only)
Line 6 Uninstaller
LiveUpdate 3.0 (Symantec Corporation)
Macromedia Flash Player 8
Microsoft .NET Framework 1.0 Hotfix (KB930494)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft .NET Framework 3.0 Service Pack 1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
MobileMe Control Panel
MSXML 6.0 Parser (KB933579)
NBC Direct Beta
NCH Tone Generator
Nero Suite
NVIDIA Drivers
OpenCASE Media Agent
PDF Settings
Pdf995 (installed by TaxCut)
PdfEdit995 (installed by TaxCut)
Photo Story 3 for Windows
PowerStrip 3 (remove only)
QuickTime
QuickTime Alternative 1.68 beta
Realtek AC'97 Audio
RK Launcher iVista Leopard
Safari
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937894)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB941693)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944338)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB945553)
Security Update for Windows XP (KB946026)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB947864)
Security Update for Windows XP (KB948590)
Security Update for Windows XP (KB948881)
Security Update for Windows XP (KB950749)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Sonic Foundry ACID 4.0
Sony ACID Music Studio 7.0
Sony Vegas Pro 8.0
SPORE™ Creature Creator Trial Edition
Spybot - Search & Destroy
Symantec AntiVirus
TaxCut Alabama 2007
TaxCut Premium + State + Efile 2007
TightVNC 1.3.9
Unprotect and Rip 2.11
Update for Windows Media Player 10 (KB913800)
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB925720)
Update for Windows XP (KB927891)
Update for Windows XP (KB930916)
Update for Windows XP (KB932823-v3)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB951072-v2)
Update Rollup 2 for Windows XP Media Center Edition 2005
Virtual Trumpet
Web Easy Professional 6
WindowBlinds
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Installer Clean Up
Windows Internet Explorer 7
Windows Internet Explorer 8 Beta 2
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows Presentation Foundation
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Media Center Edition 2005 KB925766
WinISD beta
winpwn 1.0.0.3 RC1
WinRAR archiver
 
Open notepad and copy/paste the text in the codebox below into it:

Code:
Rootkit::
C:\WINDOWS\pskt.ini 
C:\WINDOWS\BMe326679f.txt 
C:\WINDOWS\system32\avdoerby.ini 

File::
C:\WINDOWS\system32\qclslp.dll
C:\WINDOWS\system32\iphcyutu.dll
C:\WINDOWS\system32\ybreodva.dll
C:\WINDOWS\system32\katjxxfl.dll
C:\WINDOWS\system32\mbumdsqk.dll
C:\WINDOWS\system32\nfhuxkex.dll
C:\WINDOWS\system32\fpqsqu.dll
C:\WINDOWS\system32\uyecscxb.dll
C:\WINDOWS\system32\lnkdop.dll
C:\WINDOWS\system32\hqcsbgel.dll
C:\WINDOWS\system32\pyoruiyh.dll
C:\WINDOWS\system32\thxgiega.dll
C:\WINDOWS\system32\icjivb.dll
C:\WINDOWS\system32\iephadoq.dll
C:\WINDOWS\system32\lmfrbfcu.dll
C:\WINDOWS\system32\hlwqtn.dll
C:\WINDOWS\system32\kujskaqm.dll
C:\WINDOWS\system32\yufamqcn.dll
C:\WINDOWS\system32\yjzfpq.dll
C:\WINDOWS\system32\kgwamoii.dll
C:\WINDOWS\system32\wwozsz.dll
C:\WINDOWS\system32\qicksjkr.dll
C:\WINDOWS\system32\vmsyxiby.dll
C:\WINDOWS\system32\nndykeat.dll
C:\WINDOWS\BMe326679f.xml
C:\WINDOWS\system32\ilxnfsrb.dll
C:\WINDOWS\system32\TBHQAJjl.ini2
C:\WINDOWS\system32\ljJAQHBT.dll

Folder::
C:\Documents and Settings\Hunter\Application Data\LimeWire
C:\Documents and Settings\Jillian\Application Data\LimeWire

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"="wbsys.dll"

[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{49E7E212-185E-4B1A-81AA-2569449CCF7A}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BMe326679f"=-
"SoundMan"=-

Save this as "CFScript"

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

CFScriptB-4.gif


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.
 
two things: After the reboot during the combofix run, I got a windows msg: "Error Loading c:\windows\system32\ybreodva.dll"
Also (and I meant to post this before) both times I've run combofix (downloaded from the link you gave me), it tells me there is a newer version available, but i told it not to update because I'm trying to do exactly what you tell to...

Here's the new combofix log:

ComboFix 08-09-24.11 - Raymond 2008-09-25 9:22:01.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2038 [GMT -5:00]
Running from: C:\Documents and Settings\Raymond\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Raymond\Desktop\CFScript.txt
* Created a new restore point

FILE ::
C:\WINDOWS\BMe326679f.xml
C:\WINDOWS\system32\fpqsqu.dll
C:\WINDOWS\system32\hlwqtn.dll
C:\WINDOWS\system32\hqcsbgel.dll
C:\WINDOWS\system32\icjivb.dll
C:\WINDOWS\system32\iephadoq.dll
C:\WINDOWS\system32\ilxnfsrb.dll
C:\WINDOWS\system32\iphcyutu.dll
C:\WINDOWS\system32\katjxxfl.dll
C:\WINDOWS\system32\kgwamoii.dll
C:\WINDOWS\system32\kujskaqm.dll
C:\WINDOWS\system32\ljJAQHBT.dll
C:\WINDOWS\system32\lmfrbfcu.dll
C:\WINDOWS\system32\lnkdop.dll
C:\WINDOWS\system32\mbumdsqk.dll
C:\WINDOWS\system32\nfhuxkex.dll
C:\WINDOWS\system32\nndykeat.dll
C:\WINDOWS\system32\pyoruiyh.dll
C:\WINDOWS\system32\qclslp.dll
C:\WINDOWS\system32\qicksjkr.dll
C:\WINDOWS\system32\TBHQAJjl.ini2
C:\WINDOWS\system32\thxgiega.dll
C:\WINDOWS\system32\uyecscxb.dll
C:\WINDOWS\system32\vmsyxiby.dll
C:\WINDOWS\system32\wwozsz.dll
C:\WINDOWS\system32\ybreodva.dll
C:\WINDOWS\system32\yjzfpq.dll
C:\WINDOWS\system32\yufamqcn.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Hunter\Application Data\LimeWire
C:\Documents and Settings\Hunter\Application Data\LimeWire\.AppSpecialShare\Itouch.Iphone.Apps.PACK.15.BGMRK.torrent
C:\Documents and Settings\Hunter\Application Data\LimeWire\.AppSpecialShare\Itouch.Iphone.Apps.PACK.15.BGMRK.torrent.bak
C:\Documents and Settings\Hunter\Application Data\LimeWire\active.mojito
C:\Documents and Settings\Hunter\Application Data\LimeWire\createtimes.cache
C:\Documents and Settings\Hunter\Application Data\LimeWire\fileurns.bak
C:\Documents and Settings\Hunter\Application Data\LimeWire\fileurns.cache
C:\Documents and Settings\Hunter\Application Data\LimeWire\filters.props
C:\Documents and Settings\Hunter\Application Data\LimeWire\gnutella.net
C:\Documents and Settings\Hunter\Application Data\LimeWire\installation.props
C:\Documents and Settings\Hunter\Application Data\LimeWire\library.dat
C:\Documents and Settings\Hunter\Application Data\LimeWire\limewire.props
C:\Documents and Settings\Hunter\Application Data\LimeWire\mojito.props
C:\Documents and Settings\Hunter\Application Data\LimeWire\questions.props
C:\Documents and Settings\Hunter\Application Data\LimeWire\responses.cache
C:\Documents and Settings\Hunter\Application Data\LimeWire\simpp.xml
C:\Documents and Settings\Hunter\Application Data\LimeWire\spam.dat
C:\Documents and Settings\Hunter\Application Data\LimeWire\tables.props
C:\Documents and Settings\Hunter\Application Data\LimeWire\themes\windows_theme.lwtp
C:\Documents and Settings\Hunter\Application Data\LimeWire\themes\windows_theme\01_star.gif
C:\Documents and Settings\Hunter\Application Data\LimeWire\themes\windows_theme\02_star.gif
C:\Documents and Settings\Hunter\Application Data\LimeWire\themes\windows_theme\03_star.gif
C:\Documents and Settings\Hunter\Application Data\LimeWire\themes\windows_theme\04_star.gif
C:\Documents and Settings\Hunter\Application Data\LimeWire\themes\windows_theme\05_star.gif
C:\Documents and Settings\Hunter\Application Data\LimeWire\themes\windows_theme\chat.gif
C:\Documents and Settings\Hunter\Application Data\LimeWire\themes\windows_theme\forward_dn.gif
C:\Documents and Settings\Hunter\Application Data\LimeWire\themes\windows_theme\forward_up.gif
C:\Documents and Settings\Hunter\Application Data\LimeWire\themes\windows_theme\kill.gif
C:\Documents and Settings\Hunter\Application Data\LimeWire\themes\windows_theme\kill_on.gif
C:\Documents and Settings\Hunter\Application Data\LimeWire\themes\windows_theme\logo.png
C:\Documents and Settings\Hunter\Application Data\LimeWire\themes\windows_theme\notsearching.png
C:\Documents and Settings\Hunter\Application Data\LimeWire\themes\windows_theme\pause_dn.gif
C:\Documents and Settings\Hunter\Application Data\LimeWire\themes\windows_theme\pause_up.gif
C:\Documents and Settings\Hunter\Application Data\LimeWire\themes\windows_theme\play_dn.gif
C:\Documents and Settings\Hunter\Application Data\LimeWire\themes\windows_theme\play_up.gif
C:\Documents and Settings\Hunter\Application Data\LimeWire\themes\windows_theme\question.gif
C:\Documents and Settings\Hunter\Application Data\LimeWire\themes\windows_theme\rewind_dn.gif
C:\Documents and Settings\Hunter\Application Data\LimeWire\themes\windows_theme\rewind_up.gif
C:\Documents and Settings\Hunter\Application Data\LimeWire\themes\windows_theme\searching.gif
C:\Documents and Settings\Hunter\Application Data\LimeWire\themes\windows_theme\stop_dn.gif
C:\Documents and Settings\Hunter\Application Data\LimeWire\themes\windows_theme\stop_up.gif
C:\Documents and Settings\Hunter\Application Data\LimeWire\themes\windows_theme\theme.txt
C:\Documents and Settings\Hunter\Application Data\LimeWire\themes\windows_theme\version.txt
C:\Documents and Settings\Hunter\Application Data\LimeWire\themes\windows_theme\warning.gif
C:\Documents and Settings\Hunter\Application Data\LimeWire\ttrees.cache
C:\Documents and Settings\Hunter\Application Data\LimeWire\ttroot.cache
C:\Documents and Settings\Hunter\Application Data\LimeWire\version.xml
C:\Documents and Settings\Hunter\Application Data\LimeWire\xml\data\audio.sxml
C:\Documents and Settings\Jillian\Application Data\LimeWire
C:\Documents and Settings\Jillian\Application Data\LimeWire\active.mojito
C:\Documents and Settings\Jillian\Application Data\LimeWire\createtimes.cache
C:\Documents and Settings\Jillian\Application Data\LimeWire\fileurns.bak
C:\Documents and Settings\Jillian\Application Data\LimeWire\fileurns.cache
C:\Documents and Settings\Jillian\Application Data\LimeWire\filters.props
C:\Documents and Settings\Jillian\Application Data\LimeWire\gnutella.net
C:\Documents and Settings\Jillian\Application Data\LimeWire\installation.props
C:\Documents and Settings\Jillian\Application Data\LimeWire\library.dat
C:\Documents and Settings\Jillian\Application Data\LimeWire\limewire.props
C:\Documents and Settings\Jillian\Application Data\LimeWire\mojito.props
C:\Documents and Settings\Jillian\Application Data\LimeWire\questions.props
C:\Documents and Settings\Jillian\Application Data\LimeWire\responses.cache
C:\Documents and Settings\Jillian\Application Data\LimeWire\simpp.xml
C:\Documents and Settings\Jillian\Application Data\LimeWire\spam.dat
C:\Documents and Settings\Jillian\Application Data\LimeWire\tables.props
C:\Documents and Settings\Jillian\Application Data\LimeWire\themes\windows_theme.lwtp
C:\Documents and Settings\Jillian\Application Data\LimeWire\themes\windows_theme\01_star.gif
C:\Documents and Settings\Jillian\Application Data\LimeWire\themes\windows_theme\02_star.gif
C:\Documents and Settings\Jillian\Application Data\LimeWire\themes\windows_theme\03_star.gif
C:\Documents and Settings\Jillian\Application Data\LimeWire\themes\windows_theme\04_star.gif
C:\Documents and Settings\Jillian\Application Data\LimeWire\themes\windows_theme\05_star.gif
C:\Documents and Settings\Jillian\Application Data\LimeWire\themes\windows_theme\chat.gif
C:\Documents and Settings\Jillian\Application Data\LimeWire\themes\windows_theme\forward_dn.gif
C:\Documents and Settings\Jillian\Application Data\LimeWire\themes\windows_theme\forward_up.gif
C:\Documents and Settings\Jillian\Application Data\LimeWire\themes\windows_theme\kill.gif
C:\Documents and Settings\Jillian\Application Data\LimeWire\themes\windows_theme\kill_on.gif
C:\Documents and Settings\Jillian\Application Data\LimeWire\themes\windows_theme\logo.png
C:\Documents and Settings\Jillian\Application Data\LimeWire\themes\windows_theme\notsearching.png
C:\Documents and Settings\Jillian\Application Data\LimeWire\themes\windows_theme\pause_dn.gif
C:\Documents and Settings\Jillian\Application Data\LimeWire\themes\windows_theme\pause_up.gif
C:\Documents and Settings\Jillian\Application Data\LimeWire\themes\windows_theme\play_dn.gif
C:\Documents and Settings\Jillian\Application Data\LimeWire\themes\windows_theme\play_up.gif
C:\Documents and Settings\Jillian\Application Data\LimeWire\themes\windows_theme\question.gif
C:\Documents and Settings\Jillian\Application Data\LimeWire\themes\windows_theme\rewind_dn.gif
C:\Documents and Settings\Jillian\Application Data\LimeWire\themes\windows_theme\rewind_up.gif
C:\Documents and Settings\Jillian\Application Data\LimeWire\themes\windows_theme\searching.gif
C:\Documents and Settings\Jillian\Application Data\LimeWire\themes\windows_theme\stop_dn.gif
C:\Documents and Settings\Jillian\Application Data\LimeWire\themes\windows_theme\stop_up.gif
C:\Documents and Settings\Jillian\Application Data\LimeWire\themes\windows_theme\theme.txt
C:\Documents and Settings\Jillian\Application Data\LimeWire\themes\windows_theme\version.txt
C:\Documents and Settings\Jillian\Application Data\LimeWire\themes\windows_theme\warning.gif
C:\Documents and Settings\Jillian\Application Data\LimeWire\ttrees.cache
C:\Documents and Settings\Jillian\Application Data\LimeWire\ttroot.cache
C:\Documents and Settings\Jillian\Application Data\LimeWire\version.xml
C:\Documents and Settings\Jillian\Application Data\LimeWire\xml\data\audio.sxml
C:\WINDOWS\BMe326679f.txt
C:\WINDOWS\BMe326679f.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\avdoerby.ini
C:\WINDOWS\system32\fpqsqu.dll
C:\WINDOWS\system32\hlwqtn.dll
C:\WINDOWS\system32\hqcsbgel.dll
C:\WINDOWS\system32\icjivb.dll
C:\WINDOWS\system32\iephadoq.dll
C:\WINDOWS\system32\ilxnfsrb.dll
C:\WINDOWS\system32\iphcyutu.dll
C:\WINDOWS\system32\katjxxfl.dll
C:\WINDOWS\system32\kgwamoii.dll
C:\WINDOWS\system32\kujskaqm.dll
C:\WINDOWS\system32\ljJAQHBT.dll
C:\WINDOWS\system32\lmfrbfcu.dll
C:\WINDOWS\system32\lnkdop.dll
C:\WINDOWS\system32\mbumdsqk.dll
C:\WINDOWS\system32\nfhuxkex.dll
C:\WINDOWS\system32\nndykeat.dll
C:\WINDOWS\system32\pyoruiyh.dll
C:\WINDOWS\system32\qclslp.dll
C:\WINDOWS\system32\qicksjkr.dll
C:\WINDOWS\system32\TBHQAJjl.ini
C:\WINDOWS\system32\TBHQAJjl.ini2
C:\WINDOWS\system32\thxgiega.dll
C:\WINDOWS\system32\uyecscxb.dll
C:\WINDOWS\system32\vmsyxiby.dll
C:\WINDOWS\system32\wwozsz.dll
C:\WINDOWS\system32\ybreodva.dll
C:\WINDOWS\system32\yjzfpq.dll
C:\WINDOWS\system32\yufamqcn.dll

.
((((((((((((((((((((((((( Files Created from 2008-08-25 to 2008-09-25 )))))))))))))))))))))))))))))))
.

2008-09-21 10:21 . 2008-09-21 10:21 <DIR> d-------- C:\Program Files\Electronic Arts
2008-09-21 10:21 . 2008-09-21 10:21 <DIR> d-------- C:\Documents and Settings\Hunter\Application Data\SPORE Creature Creator
2008-09-21 10:21 . 2008-09-21 10:21 107,888 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2008-09-10 21:19 . 2008-09-10 21:19 <DIR> d-------- C:\Documents and Settings\Hunter\Application Data\Media Player Classic
2008-09-09 18:26 . 2008-09-09 18:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-09-09 18:23 . 2008-09-09 18:25 <DIR> d-------- C:\Program Files\QuickTime Alternative
2008-09-09 18:23 . 2008-09-09 18:23 <DIR> d-------- C:\Program Files\Media Player Classic
2008-09-09 18:15 . 2008-09-09 18:15 <DIR> d-------- C:\Program Files\Windows Installer Clean Up
2008-09-09 18:14 . 2008-09-09 18:14 <DIR> d-------- C:\Program Files\MSECACHE
2008-09-09 17:02 . 2008-09-05 22:16 1,900,544 --a------ C:\WINDOWS\system32\usbaaplrc.dll
2008-09-08 23:30 . 2008-09-08 23:30 <DIR> d-------- C:\Documents and Settings\Raymond\Application Data\NCH Software
2008-09-08 23:29 . 2008-09-08 23:29 <DIR> d-------- C:\Program Files\NCH Software
2008-09-08 23:29 . 2008-09-08 23:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NCH Software
2008-09-06 21:52 . 2008-09-06 21:52 7,680 --ahs---- C:\WINDOWS\Thumbs.db
2008-09-06 15:09 . 2008-09-06 15:09 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-09-06 15:09 . 2008-09-06 15:09 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
2008-09-03 21:31 . 2008-09-03 21:31 <DIR> d--hs---- C:\Documents and Settings\Raymond\PrivacIE
2008-09-03 18:31 . 2008-09-03 18:31 <DIR> d--hs---- C:\Documents and Settings\Jillian\PrivacIE
2008-09-03 18:30 . 2008-09-03 18:30 <DIR> d--hs---- C:\Documents and Settings\Morgan\PrivacIE
2008-09-03 18:28 . 2008-09-03 18:28 <DIR> d--hs---- C:\Documents and Settings\Hunter\PrivacIE
2008-09-03 18:20 . 2008-09-03 18:22 <DIR> d--h-c--- C:\WINDOWS\ie8
2008-08-29 10:18 . 2008-08-29 10:18 87,336 --a------ C:\WINDOWS\system32\dns-sd.exe
2008-08-29 09:53 . 2008-08-29 09:53 61,440 --a------ C:\WINDOWS\system32\dnssd.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-25 13:23 --------- d-----w C:\Program Files\Symantec AntiVirus
2008-09-22 02:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-22 02:10 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-09-22 02:03 --------- d-----w C:\Program Files\Thoosje Sidebar V2.3
2008-09-22 02:01 --------- d-----w C:\Program Files\Line6
2008-09-21 15:21 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-19 03:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\pdf995
2008-09-18 03:52 --------- d-----w C:\Documents and Settings\Raymond\Application Data\LimeWire
2008-09-09 23:26 --------- d-----w C:\Program Files\iTunes
2008-09-09 23:23 --------- d-----w C:\Documents and Settings\Hunter\Application Data\Apple Computer
2008-09-09 23:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-09-09 22:08 --------- d-----w C:\Program Files\Bonjour
2008-09-09 22:07 --------- d-----w C:\Program Files\QuickTime
2008-09-09 22:06 --------- d-----w C:\Program Files\Common Files\Apple
2008-09-06 03:16 36,864 ----a-w C:\WINDOWS\system32\drivers\usbaapl.sys
2008-08-23 00:22 --------- d-----w C:\Program Files\Apple Software Update
2008-08-22 23:53 --------- d-----w C:\Program Files\Virtual Trumpet
2008-08-22 23:47 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-08-22 23:47 249,856 ------w C:\WINDOWS\Setup1.exe
2008-08-22 01:15 --------- d-----w C:\Program Files\Google
2008-08-21 18:46 --------- d-----w C:\Program Files\WinISD
2008-08-15 21:17 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-15 21:16 --------- d-----w C:\Documents and Settings\Hunter\Application Data\Sony
2008-08-15 21:16 --------- d-----w C:\Documents and Settings\Hunter\Application Data\Publish Providers
2008-08-14 05:39 --------- d-----w C:\Program Files\PowerStrip
2008-08-10 16:22 --------- d-----w C:\Program Files\NBC Direct Beta
2008-08-10 16:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\ExtendMedia
2008-08-10 16:19 --------- d-----w C:\Program Files\OpenCase
2008-08-04 22:56 --------- d-----w C:\Program Files\Microsoft.NET
2008-08-04 22:56 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-08-03 17:58 --------- d-----w C:\Program Files\Singular Inversions
2008-08-03 02:23 --------- d-----w C:\Program Files\Safari
2008-07-31 22:33 --------- d-----w C:\Program Files\SceneCaster
2008-07-25 02:06 12,416 ----a-w C:\WINDOWS\system32\drivers\wpsnuio.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-15 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2006-03-15 158208]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-09-06 413696]
"PowerStrip"="c:\program files\powerstrip\pstrip.exe" [2008-05-01 726776]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2006-01-12 155648]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-09-08 289576]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 64512]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-03-24 53408]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe" [2006-09-14 61440]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
2008-04-29 21:58 210168 C:\Program Files\Stardock\Object Desktop\WindowBlinds\WbSrv.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wbsys.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SavRoam"=3 (0x3)
"ose"=3 (0x3)
"OpenCASE Media Agent"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Adobe\\Photoshop Elements 5.0\\AdobePhotoshopElementsMediaServer.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\OpenCase\\OpenCASE Media Agent\\PandoBinaries\\NBCPandoREST.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56577:TCP"= 56577:TCP:PandoRest Listening Port

R2 PStrip;PStrip;C:\WINDOWS\system32\drivers\pstrip.sys [2007-07-14 27992]
S3 L6POD;L6 PODxt Service;C:\WINDOWS\system32\Drivers\L6POD.sys [2008-06-10 521472]
S3 L6PODX3LV;POD X3 Live Service;C:\WINDOWS\system32\Drivers\L6PODX3LV.sys [2008-06-10 521472]
S4 OpenCASE Media Agent;OpenCASE Media Agent;C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe [2008-08-03 835208]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0917102a-3cb6-11dd-ad8b-0004617c5863}]
\Shell\AutoRun\command - E:\InstallTomTomHOME.exe
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -

BHO-{9F5AA6FC-F61D-4E12-85CD-37EC197658FF} - C:\WINDOWS\system32\ljJAQHBT.dll
HKLM-Run-e0155403 - C:\WINDOWS\system32\ybreodva.dll



**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-25 09:26:16
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
C:\ComboFix\pv.cfexe
.
**************************************************************************
.
Completion time: 2008-09-25 9:31:29 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-25 14:31:25
ComboFix2.txt 2008-09-25 13:43:47

Pre-Run: 29,195,010,048 bytes free
Post-Run: 29,182,525,440 bytes free

322 --- E O F --- 2008-09-11 08:04:22


*****Yes, I did have limewire:red:, but uninstalled it before my first post here****


New HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:39:05 AM, on 9/25/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18241)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\program files\powerstrip\pstrip.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Raymond\Desktop\Hijack this\Morjill.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: CoTGT_BHO Class - {C333CF63-767F-4831-94AC-E683D962C63C} - (no file)
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [PowerStrip] c:\program files\powerstrip\pstrip.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.line6.net
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) - http://www.windowsvistatestdrive.com/mm/ActiveX/VMRCActiveXClient1.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1208043461281
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

--
End of file - 7113 bytes
 
Yes but there were traces of LimeWire left.

"After the reboot during the combofix run, I got a windows msg: "Error Loading c:\windows\system32\ybreodva.dll""

Yes but it should be gone now:


- - - - ORPHANS REMOVED - - - -

BHO-{9F5AA6FC-F61D-4E12-85CD-37EC197658FF} - C:\WINDOWS\system32\ljJAQHBT.dll
HKLM-Run-e0155403 - C:\WINDOWS\system32\ybreodva.dll

Please go to Kaspersky website and perform an online antivirus scan.

Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

  1. Read through the requirements and privacy statement and click on Accept button.
  2. It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  3. When the downloads have finished, click on Settings.
  4. Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
  5. Click on My Computer under Scan.
  6. Once the scan is complete, it will display the results. Click on View Scan Report.
  7. You will see a list of infected items there. Click on Save Report As....
  8. Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  9. Please post this log in your next reply along with a fresh HijackThis log.

If you need a tutorial, see here
 
Shaba,
Kaspersky is scanning - just over an hour into it and it's at 41% complete. unfortunately, I have to go to a meeting that starts in an hour (@1730gmt). I'll have to leave the scan running and post results when I get back. The meeting will last at least 2hrs. I could come straight back to this if you are going to be available, otherwise we'll have to start again tomorrow (assuming you sleep at night! - Finland, right?). Is there anything I should or could do in the interim?

Thanks very much for your time and help so far.
Ray
 
I'm Back!

Kaspersky Log:
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Thursday, September 25, 2008
Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Thursday, September 25, 2008 14:58:36
Records in database: 1258880
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
F:\

Scan statistics:
Files scanned: 132771
Threat name: 19
Infected objects: 56
Suspicious objects: 0
Duration of the scan: 03:31:46


File name / Threat name / Threats count
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04840000.VBN Infected: Backdoor.Win32.Frauder.fb 6
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04840000.VBN Infected: not-a-virus:FraudTool.Win32.UltimateAntivirus.cp 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04840000.VBN Infected: not-a-virus:FraudTool.Win32.SpywarePreventer.y 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04840001.VBN Infected: Backdoor.Win32.Frauder.fb 6
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04840001.VBN Infected: not-a-virus:FraudTool.Win32.UltimateAntivirus.cp 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04840001.VBN Infected: not-a-virus:FraudTool.Win32.SpywarePreventer.y 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04840003.VBN Infected: not-a-virus:FraudTool.Win32.UltimateAntivirus.bm 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04840003.VBN Infected: not-a-virus:FraudTool.Win32.MSAntivirus.g 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04840004.VBN Infected: not-a-virus:FraudTool.Win32.UltimateAntivirus.bm 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04840004.VBN Infected: not-a-virus:FraudTool.Win32.MSAntivirus.g 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04840013.VBN Infected: not-a-virus:FraudTool.Win32.UltimateAntivirus.cp 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04840013.VBN Infected: not-a-virus:FraudTool.Win32.SpywarePreventer.y 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04840014.VBN Infected: not-a-virus:FraudTool.Win32.UltimateAntivirus.cp 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\04840014.VBN Infected: not-a-virus:FraudTool.Win32.SpywarePreventer.y 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07D00000\4FD70239.VBN Infected: Backdoor.Win32.Frauder.fb 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07D00001\4FD702BB.VBN Infected: Backdoor.Win32.Frauder.fb 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07D00002\4FD702FD.VBN Infected: Backdoor.Win32.Frauder.fb 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07D00003\4FD70325.VBN Infected: Backdoor.Win32.Frauder.fb 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07D00004\4FD7035B.VBN Infected: Backdoor.Win32.Frauder.fb 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07D00005\4FD70396.VBN Infected: Backdoor.Win32.Frauder.fb 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07D00006\4FD70656.VBN Infected: Backdoor.Win32.Frauder.fb 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08CC0000\48CC334A.VBN Infected: Backdoor.Win32.Rbot.erx 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08CC0001\48CC3407.VBN Infected: Backdoor.Win32.Rbot.erx 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0A740001\4A7D4079.VBN Infected: Trojan-Downloader.WMA.Wimad.l 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C100000\4CD6D8AD.VBN Infected: Trojan-Downloader.WMA.Wimad.n 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0C300000.VBN Infected: Trojan.Win32.BHO.eye 1
C:\Documents and Settings\Hunter\Desktop\tightvnc-1.3.9-setup.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.1370 1
C:\Documents and Settings\Hunter\My Documents\Applications\keygen.exe Infected: Trojan.Win32.Buzus.yro 1
C:\Documents and Settings\Hunter\My Documents\LimeWire\Saved\spore.ipa Crack by Frost.zip Infected: Trojan.Win32.Buzus.yro 1
C:\QooBox\Quarantine\C\WINDOWS\system32\fpqsqu.dll.vir Infected: Trojan.Win32.Inject.ich 1
C:\QooBox\Quarantine\C\WINDOWS\system32\hqcsbgel.dll.vir Infected: Trojan.Win32.Inject.ich 1
C:\QooBox\Quarantine\C\WINDOWS\system32\iephadoq.dll.vir Infected: Trojan.Win32.Monder.psn 1
C:\QooBox\Quarantine\C\WINDOWS\system32\ilxnfsrb.dll.vir Infected: Trojan.Win32.Monder.pso 1
C:\QooBox\Quarantine\C\WINDOWS\system32\katjxxfl.dll.vir Infected: Trojan.Win32.Monder.qdz 1
C:\QooBox\Quarantine\C\WINDOWS\system32\kgwamoii.dll.vir Infected: Trojan.Win32.Monder.pso 1
C:\QooBox\Quarantine\C\WINDOWS\system32\kujskaqm.dll.vir Infected: Trojan.Win32.Monder.pso 1
C:\QooBox\Quarantine\C\WINDOWS\system32\lnkdop.dll.vir Infected: Trojan.Win32.Inject.ich 1
C:\QooBox\Quarantine\C\WINDOWS\system32\mbumdsqk.dll.vir Infected: Trojan.Win32.Monder.qdz 1
C:\QooBox\Quarantine\C\WINDOWS\system32\nfhuxkex.dll.vir Infected: Trojan.Win32.Inject.ich 1
C:\QooBox\Quarantine\C\WINDOWS\system32\nndykeat.dll.vir Infected: Trojan.Win32.Monder.pso 1
C:\QooBox\Quarantine\C\WINDOWS\system32\pyoruiyh.dll.vir Infected: Trojan.Win32.Inject.icf 1
C:\QooBox\Quarantine\C\WINDOWS\system32\uyecscxb.dll.vir Infected: Trojan.Win32.Monder.puh 1
C:\QooBox\Quarantine\C\WINDOWS\system32\vmsyxiby.dll.vir Infected: Trojan.Win32.Monder.pso 1
C:\QooBox\Quarantine\C\WINDOWS\system32\ybreodva.dll.vir Infected: Trojan.Win32.Monder.qea 1
F:\Hunter\My Documents\Shared\02 Track 2.wma Infected: Trojan-Downloader.WMA.Wimad.l 1
F:\Hunter\My Documents\Shared\Adobe.Dreamweaver.CS3.rar Infected: Trojan-Dropper.Win32.Delf.xo 1

The selected area was scanned.


Fresh HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:35:39 PM, on 9/25/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18241)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\program files\powerstrip\pstrip.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Raymond\Desktop\Hijack this\Morjill.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: CoTGT_BHO Class - {C333CF63-767F-4831-94AC-E683D962C63C} - (no file)
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [PowerStrip] c:\program files\powerstrip\pstrip.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.line6.net
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) - http://www.windowsvistatestdrive.com/mm/ActiveX/VMRCActiveXClient1.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1208043461281
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

--
End of file - 7017 bytes
 
It appears that your adobe products are not legit:

F:\Hunter\My Documents\Shared\Adobe.Dreamweaver.CS3.rar Infected: Trojan-Dropper.Win32.Delf.xo 1

So please uninstall every Adobe product except Adobe Reader 7.0 and post back a fresh uninstall list.
 
Uninstall list generated from HJT like we did before:


AC3D 6.2.05
Ad-Aware
Adobe Reader 7.0
Apple Mobile Device Support
Apple Software Update
ATI - Software Uninstall Utility
ATI Display Driver
Bonjour
Canon PIXMA iP4000
DUXUS CLOCK FONT (1.0.0)
FaceGen Modeller 3.1
Finale NotePad 2008
FlyakiteOSX
FontCreator 5.6
Google Gears
Google SketchUp 6
Google SketchUp 6
HijackThis 2.0.2
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 10 (KB903157)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB888795)
Hotfix for Windows XP (KB891593)
Hotfix for Windows XP (KB895961)
Hotfix for Windows XP (KB899337)
Hotfix for Windows XP (KB899510)
Hotfix for Windows XP (KB902841)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
Hotfix for Windows XP (KB952287)
iTunes
J2SE Runtime Environment 5.0 Update 11
J2SE Runtime Environment 5.0 Update 4
Java(TM) 6 Update 4
Java(TM) 6 Update 5
Line 6 Edit (remove only)
Line 6 Uninstaller
LiveUpdate 3.0 (Symantec Corporation)
Macromedia Flash Player 8
Microsoft .NET Framework 1.0 Hotfix (KB930494)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft .NET Framework 3.0 Service Pack 1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
MobileMe Control Panel
MSXML 6.0 Parser (KB933579)
NBC Direct Beta
NCH Tone Generator
Nero Suite
NVIDIA Drivers
OpenCASE Media Agent
Pdf995 (installed by TaxCut)
PdfEdit995 (installed by TaxCut)
Photo Story 3 for Windows
PowerStrip 3 (remove only)
QuickTime
QuickTime Alternative 1.68 beta
Realtek AC'97 Audio
RK Launcher iVista Leopard
Safari
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937894)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB941693)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944338)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB945553)
Security Update for Windows XP (KB946026)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB947864)
Security Update for Windows XP (KB948590)
Security Update for Windows XP (KB948881)
Security Update for Windows XP (KB950749)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Sonic Foundry ACID 4.0
Sony ACID Music Studio 7.0
Sony Vegas Pro 8.0
SPORE™ Creature Creator Trial Edition
Spybot - Search & Destroy
Symantec AntiVirus
TaxCut Alabama 2007
TaxCut Premium + State + Efile 2007
TightVNC 1.3.9
TrueRTA
Unprotect and Rip 2.11
Update for Windows Media Player 10 (KB913800)
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB925720)
Update for Windows XP (KB927891)
Update for Windows XP (KB930916)
Update for Windows XP (KB932823-v3)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB951072-v2)
Update Rollup 2 for Windows XP Media Center Edition 2005
Virtual Trumpet
Web Easy Professional 6
WindowBlinds
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Installer Clean Up
Windows Internet Explorer 7
Windows Internet Explorer 8 Beta 2
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows Presentation Foundation
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Media Center Edition 2005 KB925766
WinISD beta
winpwn 1.0.0.3 RC1
WinRAR archiver
 
Empty these folders:

C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\
C:\Documents and Settings\Hunter\My Documents\LimeWire\
C:\QooBox\Quarantine\
F:\Hunter\My Documents\Shared\

Delete this:

C:\Documents and Settings\Hunter\My Documents\Applications\keygen.exe

Empty Recycle Bin.

Still problems?
 
Much better performance now - Thank you. No popups at all. I rebooted, updated and ran Spybot and it found "virtumonde.atr" - 4 registry entries. I let it fix problems and it reported success. Then rebooted, scanned again and it reported clean. Then I immunized.

Then I used Spybot tools to show System startup applications and I see several suspicious entries: "YUR372.exe", "YUR373.exe", and "YUR374.exe". There's another with a very long string of "8"s as a name...

Another thing I have to tell you related to the startup is that all this time I've had windows booting with a selective startup...:oops: I don't know why I didn't tell you already - I hope I haven't wasted your time. I just clicked past it everytime it came up and didn't think about it. Clearly, we've made progress though?:red:

Here's a fresh HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:16:03 PM, on 9/26/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18241)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\OpenCase\OpenCASE Media Agent\PandoBinaries\NBCPandoREST.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\program files\powerstrip\pstrip.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Raymond\Desktop\Hijack this\Morjill.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: CoTGT_BHO Class - {C333CF63-767F-4831-94AC-E683D962C63C} - (no file)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime Alternative\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PowerStrip] c:\program files\powerstrip\pstrip.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.line6.net
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) - http://www.windowsvistatestdrive.com/mm/ActiveX/VMRCActiveXClient1.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1208043461281
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: OpenCASE Media Agent - ExtendMedia Inc. - C:\Program Files\OpenCase\OpenCASE Media Agent\MediaAgent.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

--
End of file - 6687 bytes
 
"Then I used Spybot tools to show System startup applications and I see several suspicious entries: "YUR372.exe", "YUR373.exe", and "YUR374.exe". There's another with a very long string of "8"s as a name..."

Are those disabled by Spybot?
 
No. There are color codes on that screen - a couple of green entries, some yellow, and the rest are white. No reds at all. and it has a checkmark by everything - indicating that everything will run. I can manually uncheck them... Maybe these are orphan entries after the cleaning?

You didn't ask for it, so maybe you don't need it, but here's the System startup log from spybot:

--- Spybot - Search & Destroy version: 1.6.0 (build: 20080707) ---

2008-07-07 blindman.exe (1.0.0.8)
2008-07-07 SDFiles.exe (1.6.0.4)
2008-07-07 SDMain.exe (1.0.0.6)
2008-07-07 SDShred.exe (1.0.2.3)
2008-07-07 SDUpdate.exe (1.6.0.8)
2008-07-07 SDWinSec.exe (1.0.0.12)
2008-07-07 SpybotSD.exe (1.6.0.30)
2008-08-18 TeaTimer.exe (1.6.2.23)
2008-07-12 unins000.exe (51.49.0.0)
2008-07-07 Update.exe (1.6.0.7)
2008-07-07 advcheck.dll (1.6.1.12)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2008-07-07 SDHelper.dll (1.6.0.12)
2008-06-19 sqlite3.dll
2008-07-07 Tools.dll (2.1.5.7)
2008-09-02 Includes\Adware.sbi
2008-09-09 Includes\AdwareC.sbi
2008-06-03 Includes\Cookies.sbi
2008-09-02 Includes\Dialer.sbi
2008-09-09 Includes\DialerC.sbi
2008-07-23 Includes\HeavyDuty.sbi
2008-09-02 Includes\Hijackers.sbi
2008-09-02 Includes\HijackersC.sbi
2008-09-09 Includes\Keyloggers.sbi
2008-09-23 Includes\KeyloggersC.sbi
2004-11-29 Includes\LSP.sbi
2008-09-09 Includes\Malware.sbi
2008-09-23 Includes\MalwareC.sbi
2008-09-02 Includes\PUPS.sbi
2008-09-11 Includes\PUPSC.sbi
2007-11-07 Includes\Revision.sbi
2008-06-18 Includes\Security.sbi
2008-09-02 Includes\SecurityC.sbi
2008-06-03 Includes\Spybots.sbi
2008-06-03 Includes\SpybotsC.sbi
2008-09-09 Includes\Spyware.sbi
2008-09-23 Includes\SpywareC.sbi
2008-06-03 Includes\Tracks.uti
2008-09-16 Includes\Trojans.sbi
2008-09-23 Includes\TrojansC.sbi
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll

Located: HK_LM:Run, AppleSyncNotifier
command: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
file: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
size: 111936
MD5: 3C59CB80D1849128C14FF2B3245419BE

Located: HK_LM:Run, ccApp
command: "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
file: C:\Program Files\Common Files\Symantec Shared\ccApp.exe
size: 53408
MD5: 8C5D5B71E4E8A1FB8F1FA6CC57FE411E

Located: HK_LM:Run, ehTray
command: C:\WINDOWS\ehome\ehtray.exe
file: C:\WINDOWS\ehome\ehtray.exe
size: 64512
MD5: 7A21E06385E748E9CB0252F1BBC493F1

Located: HK_LM:Run, iTunesHelper
command: "C:\Program Files\iTunes\iTunesHelper.exe"
file: C:\Program Files\iTunes\iTunesHelper.exe
size: 289576
MD5: A7FA648719063B234A434A089FC0F49D

Located: HK_LM:Run, NeroFilterCheck
command: C:\WINDOWS\system32\NeroCheck.exe
file: C:\WINDOWS\system32\NeroCheck.exe
size: 155648
MD5: C93AB037A8C792D5F8A1A9FC88A7C7C5

Located: HK_LM:Run, PowerStrip
command: c:\program files\powerstrip\pstrip.exe
file: c:\program files\powerstrip\pstrip.exe
size: 726776
MD5: 512238DA1A3C5DAB59BDFD93DA363292

Located: HK_LM:Run, QuickTime Task
command: "C:\Program Files\QuickTime Alternative\qttask.exe" -atboottime
file: C:\Program Files\QuickTime Alternative\qttask.exe
size: 413696
MD5: 6CD5C3276C83F72677D647F27EE14ABD

Located: HK_CU:Run, \YUR372.exe
where: PE_C_HUNTER...
command: C:\Windows\system32\YUR372.exe
file: C:\Windows\system32\YUR372.exe
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: HK_CU:Run, \YUR373.exe
where: PE_C_HUNTER...
command: C:\Windows\system32\YUR373.exe
file: C:\Windows\system32\YUR373.exe
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: HK_CU:Run, \YUR374.exe
where: PE_C_HUNTER...
command: C:\Windows\system32\YUR374.exe
file: C:\Windows\system32\YUR374.exe
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: HK_CU:Run, ctfmon.exe
where: PE_C_HUNTER...
command: C:\WINDOWS\system32\ctfmon.exe
file: C:\WINDOWS\system32\ctfmon.exe
size: 15360
MD5: 24232996A38C0B0CF151C2140AE29FC8

Located: HK_CU:Run, Google Update
where: PE_C_HUNTER...
command: "C:\Documents and Settings\Hunter\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
file: C:\Documents and Settings\Hunter\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
size: 133104
MD5: 626A24ED1228580B9518C01930936DF9

Located: HK_CU:Run, ctfmon.exe
where: PE_C_JILLIAN...
command: C:\WINDOWS\system32\ctfmon.exe
file: C:\WINDOWS\system32\ctfmon.exe
size: 15360
MD5: 24232996A38C0B0CF151C2140AE29FC8

Located: HK_CU:Run, MSMSGS
where: PE_C_JILLIAN...
command: "C:\Program Files\Messenger\msmsgs.exe" /background
file: C:\Program Files\Messenger\msmsgs.exe
size: 1694208
MD5: 74E6E96C6F0E2ECA4EDBB7F7A468F259

Located: HK_CU:Run,
where: PE_C_MORGAN...
command:
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: HK_CU:Run, 888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888SOFTWARE\Microsoft\Windows\CurrentVersion\Run
where: PE_C_MORGAN...
command: 8888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888SOFTWARE\Microsoft\Windows\CurrentVersion\Run
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: HK_CU:Run, ctfmon.exe
where: PE_C_MORGAN...
command: C:\WINDOWS\system32\ctfmon.exe
file: C:\WINDOWS\system32\ctfmon.exe
size: 15360
MD5: 24232996A38C0B0CF151C2140AE29FC8

Located: HK_CU:Run, MSMSGS
where: PE_C_MORGAN...
command: "C:\Program Files\Messenger\msmsgs.exe" /background
file: C:\Program Files\Messenger\msmsgs.exe
size: 1694208
MD5: 74E6E96C6F0E2ECA4EDBB7F7A468F259

Located: HK_CU:Run, QuickTime Task
where: PE_C_MORGAN...
command: "C:\Program Files\QuickTime\QTTask.exe" -atboottime
file: C:\Program Files\QuickTime\QTTask.exe
size: 413696
MD5: 6CD5C3276C83F72677D647F27EE14ABD

Located: HK_CU:Run, ctfmon.exe
where: S-1-5-21-1220945662-448539723-839522115-1003...
command: C:\WINDOWS\system32\ctfmon.exe
file: C:\WINDOWS\system32\ctfmon.exe
size: 15360
MD5: 24232996A38C0B0CF151C2140AE29FC8

Located: Startup (common), Adobe Reader Speed Launch.lnk
where: C:\Documents and Settings\All Users\Start Menu\Programs\Startup...
command: C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
file: C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
size: 29696
MD5: DEB88AEF013DD1EEFB462D7CAD642166

Located: WinLogon, AtiExtEvent
command: Ati2evxx.dll
file: Ati2evxx.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, crypt32chain
command: crypt32.dll
file: crypt32.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, cryptnet
command: cryptnet.dll
file: cryptnet.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, cscdll
command: cscdll.dll
file: cscdll.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, NavLogon
command: C:\WINDOWS\system32\NavLogon.dll
file: C:\WINDOWS\system32\NavLogon.dll
size: 43760
MD5: 7B5FB0E0A5FBDDF32A3A13581E5E50D5

Located: WinLogon, ScCertProp
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, Schedule
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, sclgntfy
command: sclgntfy.dll
file: sclgntfy.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, SensLogn
command: WlNotify.dll
file: WlNotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, termsrv
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, WBSrv
command: C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll
file: C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll
size: 210168
MD5: 20BFA5A67E6AD66CD433A66637129C22

Located: WinLogon, wlballoon
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!
 
Are there multiple user accounts?

If so, please post HijackThis from each account.
 
Back
Top