Thanks for the help so far... Here is the log from the Hijack this set up (looks like a mess):
Combo fix log below....
Logfile of HijackThis v1.99.1
Scan saved at 12:09:49 AM, on 11/16/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
F:\WINNT\System32\smss.exe
F:\WINNT\system32\winlogon.exe
F:\WINNT\system32\services.exe
F:\WINNT\system32\lsass.exe
F:\WINNT\system32\svchost.exe
F:\WINNT\system32\spoolsv.exe
F:\WINNT\System32\svchost.exe
F:\Program Files\CA\eTrust\InoculateIT\InoRpc.exe
F:\Program Files\CA\eTrust\InoculateIT\InoRT.exe
F:\Program Files\CA\eTrust\InoculateIT\InoTask.exe
F:\WINNT\LogWatNT.exe
F:\WINNT\system32\regsvc.exe
F:\WINNT\system32\stisvc.exe
F:\WINNT\System32\WBEM\WinMgmt.exe
F:\Program Files\Linksys Wireless-G PCI Adapter\WLService.exe
F:\WINNT\system32\svchost.exe
F:\Program Files\Linksys Wireless-G PCI Adapter\WMP54Gv4.exe
F:\WINNT\Explorer.EXE
F:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
F:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
F:\Program Files\iTunes\iTunesHelper.exe
F:\Program Files\QuickTime\qttask.exe
F:\Program Files\iPod\bin\iPodService.exe
F:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
F:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
F:\WINNT\explorer.exe
F:\WINNT\system32\PPPATC~1\attrib.exe
F:\Program Files\Common Files\Real\Update_OB\realsched.exe
F:\Program Files\Internet Explorer\iexplore.exe
F:\Documents and Settings\Adam Bor\My Documents\?icrosoft.NET\?explore.exe
F:\Program Files\Hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://red.clientapp.../search/ie.htmlR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://football.fant...hoo.com/f2/5881R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://football.fant...hoo.com/f2/5881R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://red.clientapp...//www.yahoo.comR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: (no name) - {B02F7BED-EC7D-B1A2-7BE2-C39EFD405EB8} - F:\WINNT\system32\udemewbn.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - F:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - F:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - F:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - F:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBarBHO.dll
O2 - BHO: (no name) - {B02F7BED-EC7D-B1A2-7BE2-C39EFD405EB8} - F:\WINNT\system32\udemewbn.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - F:\WINNT\System32\msdxm.ocx
O3 - Toolbar: (no name) - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - (no file)
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - F:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - F:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [TkBellExe] "F:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [PCSuiteTrayApplication] F:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [DataLayer] F:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Yahoo! Pager] "F:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Hsuh] "F:\WINNT\system32\PPPATC~1\attrib.exe" -vt ndrv
O8 - Extra context menu item: &Viewpoint Search - res://F:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
O8 - Extra context menu item: &Yahoo! Search - file:///F:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///F:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///F:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///F:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - F:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - F:\Program Files\AIM95\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - F:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - F:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - F:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - F:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O12 - Plugin for .spop: F:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0F9B4CA4-A30F-480A-841D-69B45C50A8F8} (SekureL0gin.SekureKontrol) -
http://secure2.comne...iveSekurity.cabO16 - DPF: {1E2941E3-8E63-11D4-9D5A-00902742D6E0} (iNotes Class) -
https://millithunder....com/iNotes.cabO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - F:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) -
http://web1.shutterf...ds/Uploader.cabO23 - Service: Ati HotKey Poller - Unknown owner - F:\WINNT\System32\Ati2evxx.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - F:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: eTrust InoculateIT RPC Server (InoRPC) - Computer Associates International, Inc. - F:\Program Files\CA\eTrust\InoculateIT\InoRpc.exe
O23 - Service: eTrust InoculateIT Realtime Server (InoRT) - Computer Associates International, Inc. - F:\Program Files\CA\eTrust\InoculateIT\InoRT.exe
O23 - Service: eTrust InoculateIT Job Server (InoTask) - Computer Associates International, Inc. - F:\Program Files\CA\eTrust\InoculateIT\InoTask.exe
O23 - Service: iPodService - Apple Computer, Inc. - F:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Event Log Watch (LogWatch) - Unknown owner - F:\WINNT\LogWatNT.exe
O23 - Service: WMP54Gv4SVC - Unknown owner - F:\Program Files\Linksys Wireless-G PCI Adapter\WLService.exe" "WMP54Gv4.exe (file missing)
Combo FIx Log:Adam Bor - Thu 11/16/2006 0:21:53.72 Service Pack 4
ComboFix 06.11.9 - Running from: "F:\Documents and Settings\Adam Bor\Desktop"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
F:\WINNT\system32\wapisvsu.exe
F:\Program Files\Common Files\Yazzle1409OinUninstaller.exe
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
F:\QooBox\Purity\Documents and Settings\Adam Bor\My Documents\ICROSO~1.NET
F:\QooBox\Purity\Documents and Settings\Adam Bor\My Documents\ICROSO~1.NET\?explore.exe
F:\QooBox\Purity\Program Files\Common Files\PPATCH~1
F:\QooBox\Purity\WINNT\system32\PPPATC~1
F:\QooBox\Purity\WINNT\system32\PPPATC~1\attrib.exe
F:\QooBox\Purity\WINNT\system32\PPPATC~1\?ppPatch
F:\QooBox\Purity\WINNT\system32\PPPATC~1\?ppPatch\ctxad-494.0000
F:\QooBox\Purity\WINNT\system32\PPPATC~1\?ppPatch\ctxad-494.0001
F:\QooBox\Purity\WINNT\system32\PPPATC~1\?ppPatch\ctxad-494.0002
F:\QooBox\Purity\WINNT\system32\PPPATC~1\?ppPatch\ctxad-494.0003
F:\QooBox\Purity\WINNT\system32\PPPATC~1\?ppPatch\ctxad-503.0000
F:\QooBox\Purity\WINNT\system32\PPPATC~1\?ppPatch\ctxad-503.0001
F:\QooBox\Purity\WINNT\system32\PPPATC~1\?ppPatch\ctxad-503.0002
F:\QooBox\Purity\WINNT\system32\PPPATC~1\?ppPatch\ctxad-503.0003
F:\QooBox\Purity\WINNT\system32\PPPATC~1\?ppPatch\ctxad-503.0004
F:\QooBox\Purity\WINNT\system32\PPPATC~1\?ppPatch\ctxad-503.0005
F:\QooBox\Purity\WINNT\system32\PPPATC~1\?ppPatch\ctxad-503.0006
F:\QooBox\Purity\WINNT\system32\PPPATC~1\?ppPatch\ctxad-505.0000
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
F:\QooBox\Purity\Documents and Settings\Adam Bor\My Documents\ICROSO~1.NET
F:\QooBox\Purity\Documents and Settings\Adam Bor\My Documents\ICROSO~1.NET\?explore.exe
F:\QooBox\Purity\Program Files\Common Files\PPATCH~1
F:\QooBox\Purity\WINNT\system32\PPPATC~1
F:\QooBox\Purity\WINNT\system32\PPPATC~1\attrib.exe
F:\QooBox\Purity\WINNT\system32\PPPATC~1\?ppPatch
F:\QooBox\Purity\WINNT\system32\PPPATC~1\?ppPatch\ctxad-494.0000
F:\QooBox\Purity\WINNT\system32\PPPATC~1\?ppPatch\ctxad-494.0001
F:\QooBox\Purity\WINNT\system32\PPPATC~1\?ppPatch\ctxad-494.0002
F:\QooBox\Purity\WINNT\system32\PPPATC~1\?ppPatch\ctxad-494.0003
F:\QooBox\Purity\WINNT\system32\PPPATC~1\?ppPatch\ctxad-503.0000
F:\QooBox\Purity\WINNT\system32\PPPATC~1\?ppPatch\ctxad-503.0001
F:\QooBox\Purity\WINNT\system32\PPPATC~1\?ppPatch\ctxad-503.0002
F:\QooBox\Purity\WINNT\system32\PPPATC~1\?ppPatch\ctxad-503.0003
F:\QooBox\Purity\WINNT\system32\PPPATC~1\?ppPatch\ctxad-503.0004
F:\QooBox\Purity\WINNT\system32\PPPATC~1\?ppPatch\ctxad-503.0005
F:\QooBox\Purity\WINNT\system32\PPPATC~1\?ppPatch\ctxad-503.0006
F:\QooBox\Purity\WINNT\system32\PPPATC~1\?ppPatch\ctxad-505.0000
((((((((((((((((((((((((((((((( Files Created from 2006-10-16 to 2006-11-16 ))))))))))))))))))))))))))))))))))
2006-11-16 00:20 360 --a------ F:\Combo.bat
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-11-16 00:18 -------- d-a------ F:\Program Files\Common Files
2006-11-16 00:09 -------- d-------- F:\Program Files\Hijackthis
2006-11-12 22:48 -------- d-------- F:\Program Files\Media
2006-11-12 20:38 -------- d-------- F:\Program Files\XoftSpySE
2006-11-02 21:45 -------- d-------- F:\Program Files\Yahoo!
2006-11-02 21:45 -------- d-------- F:\Program Files\Common Files\Scanner
2006-10-12 23:12 -------- d-------- F:\Program Files\OIN Search
2006-10-05 21:09 -------- d-------- F:\Program Files\FileZilla
2006-09-12 06:48 1713536 --a------ F:\WINNT\system32\NTKRNLPA.EXE
2006-09-12 06:48 1690880 --a------ F:\WINNT\system32\NTOSKRNL.EXE
2006-09-05 23:58 1110528 --a------ F:\WINNT\system32\msxml3.dll
2006-08-28 03:44 530192 --a------ F:\WINNT\system32\comctl32.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Yahoo! Pager"="\"F:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe\" -quiet"
"Hsuh"="\"F:\\WINNT\\system32\\PPPATC~1\\attrib.exe\" -vt ndrv"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"Synchronization Manager"="mobsync.exe /logon"
"TkBellExe"="\"F:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"PCSuiteTrayApplication"="F:\\Program Files\\Nokia\\Nokia PC Suite 6\\LaunchApplication.exe -onlytray"
"DataLayer"="F:\\Program Files\\Common Files\\PCSuite\\DataLayer\\DataLayer.exe"
"iTunesHelper"="\"F:\\Program Files\\iTunes\\iTunesHelper.exe\""
"QuickTime Task"="\"F:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000003
"Settings"=dword:00000001
"GeneralFlags"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e4,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=dword:c0000004
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,f0,01,00,00,1f,00,00,00,80,00,00,00,76,00,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"^SetupICWDesktop"="F:\\Program Files\\Internet Explorer\\Connection Wizard\\icwconn1.exe /desktop"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000095
"CDRAutoRun"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000095
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"Network.ConnectionTray"="{7007ACCF-3202-11D1-AAD2-00805FC1270E}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
Contents of the 'Scheduled Tasks' folder
F:\WINNT\tasks\XoftSpySE.job
Completion time: Thu 2006-11-16 0:30:22.70
F:\ComboFix.txt ... 06-11-16 00:30
F:\ComboFix2.txt ... 06-11-16 00:19