Hi is my combofix.txt and a new hijackthis log. Thanks a ton for your help!
ComboFix 08-06-16.5 - HP_Owner 2008-06-18 18:32:59.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.230 [GMT -4:00]
Running from: C:\Documents and Settings\HP_Owner\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\HP_Owner\Application Data\ASKS~1
C:\Documents and Settings\HP_Owner\Application Data\DOBE~1
C:\Documents and Settings\HP_Owner\Application Data\FNTS~1
C:\Documents and Settings\HP_Owner\Application Data\ICROSO~1
C:\Documents and Settings\HP_Owner\Application Data\MANTEC~1
C:\Documents and Settings\HP_Owner\Application Data\MCROSO~1
C:\Documents and Settings\HP_Owner\Application Data\PPATCH~1
C:\Documents and Settings\HP_Owner\Application Data\RACLE~1
C:\Documents and Settings\HP_Owner\Application Data\SMANTE~1
C:\Documents and Settings\HP_Owner\Application Data\SSTEM3~1
C:\Documents and Settings\HP_Owner\Application Data\WNSXS~1
C:\Documents and Settings\HP_Owner\My Documents\APPATC~1
C:\Documents and Settings\HP_Owner\My Documents\ASKS~1
C:\Documents and Settings\HP_Owner\My Documents\CURITY~1
C:\Documents and Settings\HP_Owner\My Documents\DOBE~1
C:\Documents and Settings\HP_Owner\My Documents\SSTEM~1
C:\Documents and Settings\HP_Owner\My Documents\SSTEM3~1
C:\Documents and Settings\HP_Owner\My Documents\TSKS~1
C:\Documents and Settings\HP_Owner\My Documents\WNSXS~1
C:\Documents and Settings\HP_Owner\My Documents\YMBOLS~1
C:\Documents and Settings\HP_Owner\My Documents\YSTEM~1
C:\Documents and Settings\HP_Owner\My Documents\YSTEM~1\?icrosoft\
C:\Documents and Settings\HP_Owner\My Documents\YSTEM~1\winword.exe
C:\Program Files\Common Files\asks~1
C:\Program Files\Common Files\asks~2
C:\Program Files\Common Files\crosof~1.net
C:\Program Files\Common Files\curity~1
C:\Program Files\Common Files\icroso~1.net
C:\Program Files\Common Files\mcroso~1
C:\Program Files\Common Files\ppatch~1
C:\Program Files\Common Files\racle~1
C:\Program Files\Common Files\sstem3~1
C:\Program Files\Common Files\stem~1
C:\Program Files\Common Files\tsks~1
C:\Program Files\crosof~1
C:\Program Files\fnts~1
C:\Program Files\icroso~1
C:\Program Files\mbols~1
C:\Program Files\scurit~1
C:\Program Files\sembly~1
C:\Program Files\smbols~1
C:\Program Files\wnsxs~1
C:\Program Files\ystem~1
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\fse
C:\Temp\fse\tmpZTF.log
C:\WINDOWS\asembl~1
C:\WINDOWS\BM2e291e11.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\crosof~1
C:\WINDOWS\crosof~1.net
C:\WINDOWS\dobe~1
C:\WINDOWS\IA
C:\WINDOWS\ppatch~1
C:\WINDOWS\pskt.ini
C:\WINDOWS\racle~1
C:\WINDOWS\rundll16.exe
C:\WINDOWS\scurit~1
C:\WINDOWS\sks~1
C:\WINDOWS\smante~1
C:\WINDOWS\sstem3~1
C:\WINDOWS\system32\affquyci.ini
C:\WINDOWS\system32\agvoxiji.ini
C:\WINDOWS\system32\aivkktbe.ini
C:\WINDOWS\system32\ajngmcfi.ini
C:\WINDOWS\system32\anyandlg.ini
C:\WINDOWS\system32\aowaydny.ini
C:\WINDOWS\system32\apnhcvwy.ini
C:\WINDOWS\system32\aqrqoqfh.dll
C:\WINDOWS\system32\asbvytgb.dll
C:\WINDOWS\system32\asembl~1
C:\WINDOWS\system32\asks~1
C:\WINDOWS\system32\ayamoqmk.ini
C:\WINDOWS\system32\bdeeg.bak1
C:\WINDOWS\system32\bdeeg.bak2
C:\WINDOWS\system32\bdeeg.ini
C:\WINDOWS\system32\bdeeg.ini2
C:\WINDOWS\system32\bdeeg.tmp
C:\WINDOWS\system32\bdqxjglh.ini
C:\WINDOWS\system32\bfpyhlqh.ini
C:\WINDOWS\system32\biysitnk.ini
C:\WINDOWS\system32\boccyksp.ini
C:\WINDOWS\system32\botvhbby.dll
C:\WINDOWS\system32\bvjoupap.ini
C:\WINDOWS\system32\bycdwnrk.ini
C:\WINDOWS\system32\cafcjppf.ini
C:\WINDOWS\system32\carwcnxm.dll
C:\WINDOWS\system32\cdyncafs.ini
C:\WINDOWS\system32\ciwcrjrj.dll
C:\WINDOWS\system32\ckfbqror.ini
C:\WINDOWS\system32\clqkeejb.dll
C:\WINDOWS\system32\cpbrlrny.ini
C:\WINDOWS\system32\cpocwlpc.dll
C:\WINDOWS\system32\crreqveq.dll
C:\WINDOWS\system32\curity~1
C:\WINDOWS\system32\cyjdnavx.ini
C:\WINDOWS\system32\cyngjkyf.dll
C:\WINDOWS\system32\dedhguht.ini
C:\WINDOWS\system32\dglxkupo.ini
C:\WINDOWS\system32\dgudwvbh.ini
C:\WINDOWS\system32\dgwebwgt.ini
C:\WINDOWS\system32\dhjtqjie.ini
C:\WINDOWS\system32\dlvhhube.ini
C:\WINDOWS\system32\dobe~1
C:\WINDOWS\system32\dobe~2
C:\WINDOWS\system32\dqueqepn.dll
C:\WINDOWS\system32\dscxxuna.ini
C:\WINDOWS\system32\dsfifoww.ini
C:\WINDOWS\system32\dvvnwkxl.ini
C:\WINDOWS\system32\eakaakuj.ini
C:\WINDOWS\system32\edtthulc.dll
C:\WINDOWS\system32\eiflmvkh.ini
C:\WINDOWS\system32\eimsnucq.ini
C:\WINDOWS\system32\eipeeunt.ini
C:\WINDOWS\system32\ekgccscr.ini
C:\WINDOWS\system32\emiqtdcd.dll
C:\WINDOWS\system32\epkatdly.ini
C:\WINDOWS\system32\eulajvvg.ini
C:\WINDOWS\system32\eupvlnqi.ini
C:\WINDOWS\system32\extoqrby.ini
C:\WINDOWS\system32\f02WtR
C:\WINDOWS\system32\f02WtR\f02WtR1065.exe
C:\WINDOWS\system32\fadijxqi.ini
C:\WINDOWS\system32\fajvbora.ini
C:\WINDOWS\system32\fapulamu.ini
C:\WINDOWS\system32\fbjcesrb.ini
C:\WINDOWS\system32\fbyecyqm.dll
C:\WINDOWS\system32\fdvrbsdt.ini
C:\WINDOWS\system32\fiwiclqp.dll
C:\WINDOWS\system32\fmkgjkpr.dll
C:\WINDOWS\system32\fubsschy.dll
C:\WINDOWS\system32\fwwtosom.ini
C:\WINDOWS\system32\fyxyruwq.ini
C:\WINDOWS\system32\ghslunqd.ini
C:\WINDOWS\system32\gimwfwey.dll
C:\WINDOWS\system32\gjs.dll
C:\WINDOWS\system32\gkcmnjuk.dll
C:\WINDOWS\system32\gkicsrok.dll
C:\WINDOWS\system32\gldnayna.dll
C:\WINDOWS\system32\gmwxuyac.dll
C:\WINDOWS\system32\govckdvs.ini
C:\WINDOWS\system32\gpxwgpwc.ini
C:\WINDOWS\system32\gqvrmeey.ini
C:\WINDOWS\system32\guvnxohl.ini
C:\WINDOWS\system32\H7
C:\WINDOWS\system32\H7\wbcabdll2.exe
C:\WINDOWS\system32\hbvwdugd.dll
C:\WINDOWS\system32\hdtnqmtg.dll
C:\WINDOWS\system32\hefrqiyr.ini
C:\WINDOWS\system32\helruukn.ini
C:\WINDOWS\system32\hfqoqrqa.ini
C:\WINDOWS\system32\hllqtush.dll
C:\WINDOWS\system32\hpysamqa.ini
C:\WINDOWS\system32\hqlhypfb.dll
C:\WINDOWS\system32\humydnge.ini
C:\WINDOWS\system32\ifcmgnja.dll
C:\WINDOWS\system32\ifhqhixg.ini
C:\WINDOWS\system32\ijtyorii.ini
C:\WINDOWS\system32\imjsbeov.ini
C:\WINDOWS\system32\iqnlvpue.dll
C:\WINDOWS\system32\isjdkchx.ini
C:\WINDOWS\system32\iufxcaqe.ini
C:\WINDOWS\system32\iveblayr.ini
C:\WINDOWS\system32\ivoxglpk.ini
C:\WINDOWS\system32\ixnxduhn.ini
C:\WINDOWS\system32\iyicokva.dll
C:\WINDOWS\system32\jaaihcew.ini
C:\WINDOWS\system32\jcicyoct.ini
C:\WINDOWS\system32\jefjednx.ini
C:\WINDOWS\system32\jehadsva.ini
C:\WINDOWS\system32\jhugvjqo.dll
C:\WINDOWS\system32\jkigssel.ini
C:\WINDOWS\system32\jkpleynh.ini
C:\WINDOWS\system32\jlsofeym.dll
C:\WINDOWS\system32\jmsonugr.ini
C:\WINDOWS\system32\jranxath.dll
C:\WINDOWS\system32\jsiaaphh.ini
C:\WINDOWS\system32\jwdadveh.ini
C:\WINDOWS\system32\jwirfoli.ini
C:\WINDOWS\system32\kauyijqd.dll
C:\WINDOWS\system32\keikwifw.ini
C:\WINDOWS\system32\kkicbxps.ini
C:\WINDOWS\system32\kknomkan.ini
C:\WINDOWS\system32\klfdilic.ini
C:\WINDOWS\system32\klvgkyxc.dll
C:\WINDOWS\system32\korscikg.ini
C:\WINDOWS\system32\ksjcvmgr.ini
C:\WINDOWS\system32\kuexqdcr.ini
C:\WINDOWS\system32\leqodmop.dll
C:\WINDOWS\system32\lffqigcl.ini
C:\WINDOWS\system32\lijnwtck.ini
C:\WINDOWS\system32\lmeuwuqb.ini
C:\WINDOWS\system32\lsrnnpwa.dll
C:\WINDOWS\system32\lwbhshht.ini
C:\WINDOWS\system32\mconkktt.dll
C:\WINDOWS\system32\mcqncekw.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mnecenyo.dll
C:\WINDOWS\system32\mnjknlxd.ini
C:\WINDOWS\system32\mratdaxo.dll
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\mvgyuatf.dll
C:\WINDOWS\system32\nctwryqw.ini
C:\WINDOWS\system32\nilbcycu.dll
C:\WINDOWS\system32\nitrocjn.ini
C:\WINDOWS\system32\njcortin.dll
C:\WINDOWS\system32\njxgqwjn.dll
C:\WINDOWS\system32\npeqeuqd.ini
C:\WINDOWS\system32\ntoghwru.ini
C:\WINDOWS\system32\nvqwnrxe.ini
C:\WINDOWS\system32\nycigeku.dll
C:\WINDOWS\system32\oadbwuip.dll
C:\WINDOWS\system32\obnpglwd.ini
C:\WINDOWS\system32\odclttjw.ini
C:\WINDOWS\system32\oeggauev.ini
C:\WINDOWS\system32\ojkmdjen.ini
C:\WINDOWS\system32\ojnblnrk.ini
C:\WINDOWS\system32\okklftmi.ini
C:\WINDOWS\system32\ootofjwq.dll
C:\WINDOWS\system32\opmtfdcw.ini
C:\WINDOWS\system32\osiogyrf.dll
C:\WINDOWS\system32\oumlsvdu.dll
C:\WINDOWS\system32\oxadtarm.ini
C:\WINDOWS\system32\paetabmh.dll
C:\WINDOWS\system32\pbtoqhcn.ini
C:\WINDOWS\system32\pbxcbocx.dll
C:\WINDOWS\system32\phbknqfq.dll
C:\WINDOWS\system32\piptwjmb.ini
C:\WINDOWS\system32\pkejsxtp.ini
C:\WINDOWS\system32\pnifjvir.ini
C:\WINDOWS\system32\pokvfhjx.ini
C:\WINDOWS\system32\pqtwbtfd.ini
C:\WINDOWS\system32\prjouvkf.ini
C:\WINDOWS\system32\prwxgfdn.ini
C:\WINDOWS\system32\ptxsjekp.dll
C:\WINDOWS\system32\pvrpwgmu.ini
C:\WINDOWS\system32\pxjdqtwe.ini
C:\WINDOWS\system32\pxsiysci.ini
C:\WINDOWS\system32\pxtlautm.ini
C:\WINDOWS\system32\qegibuer.dll
C:\WINDOWS\system32\qeucxsvt.ini
C:\WINDOWS\system32\qhpdfjlb.ini
C:\WINDOWS\system32\qhpxflla.ini
C:\WINDOWS\system32\qmigcepq.ini
C:\WINDOWS\system32\qporienr.dll
C:\WINDOWS\system32\qufmgsjq.ini
C:\WINDOWS\system32\quvrrfqg.ini
C:\WINDOWS\system32\racle~1
C:\WINDOWS\system32\racle~2
C:\WINDOWS\system32\rcowsfnp.ini
C:\WINDOWS\system32\rdclqrig.dll
C:\WINDOWS\system32\rieutynh.dll
C:\WINDOWS\system32\rnuenhjo.dll
C:\WINDOWS\system32\rpshiblh.ini
C:\WINDOWS\system32\rqthaylq.ini
C:\WINDOWS\system32\rsgvxnwd.ini
C:\WINDOWS\system32\rvwcrcwx.ini
C:\WINDOWS\system32\rvwxkxka.ini
C:\WINDOWS\system32\rwudtpmo.dll
C:\WINDOWS\system32\sbtwcagm.ini
C:\WINDOWS\system32\sddgsbms.ini
C:\WINDOWS\system32\sdmcmect.dll
C:\WINDOWS\system32\sdrpdbvg.dll
C:\WINDOWS\system32\sduuahqu.ini
C:\WINDOWS\system32\sks~1
C:\WINDOWS\system32\soedjibs.ini
C:\WINDOWS\system32\ssembl~1
C:\WINDOWS\system32\sstem3~1
C:\WINDOWS\system32\stem~1
C:\WINDOWS\system32\svdkcvog.dll
C:\WINDOWS\system32\syoiyoaa.dll
C:\WINDOWS\system32\tgojmkfg.ini
C:\WINDOWS\system32\towntbfe.ini
C:\WINDOWS\system32\tructvmf.ini
C:\WINDOWS\system32\tsks~1
C:\WINDOWS\system32\ttkknocm.ini
C:\WINDOWS\system32\txxdtghl.dll
C:\WINDOWS\system32\tynjsmmi.dll
C:\WINDOWS\system32\ucallmip.ini
C:\WINDOWS\system32\uiehwjeu.ini
C:\WINDOWS\system32\ujxekdmo.ini
C:\WINDOWS\system32\ukkljeld.ini
C:\WINDOWS\system32\ukoppaib.ini
C:\WINDOWS\system32\uqhauuds.dll
C:\WINDOWS\system32\uqscldfh.ini
C:\WINDOWS\system32\uqyetsch.ini
C:\WINDOWS\system32\urbrqsla.dll
C:\WINDOWS\system32\uruhvfbp.dll
C:\WINDOWS\system32\uvaqutuk.ini
C:\WINDOWS\system32\uyojbyft.ini
C:\WINDOWS\system32\vcpqjxbt.ini
C:\WINDOWS\system32\vebtndaj.dll
C:\WINDOWS\system32\vewqbhae.dll
C:\WINDOWS\system32\vhxihapu.ini
C:\WINDOWS\system32\vkcupmek.ini
C:\WINDOWS\system32\vlrarnuy.ini
C:\WINDOWS\system32\vpdsfdup.ini
C:\WINDOWS\system32\vwafjyqk.dll
C:\WINDOWS\system32\wdvgeicg.dll
C:\WINDOWS\system32\wfmckdqh.ini
C:\WINDOWS\system32\wgfgjwbg.dll
C:\WINDOWS\system32\wkmebrop.ini
C:\WINDOWS\system32\wkxjvnun.dll
C:\WINDOWS\system32\wrtnlfdy.dll
C:\WINDOWS\system32\wtvcoviu.ini
C:\WINDOWS\system32\wvkehiag.dll
C:\WINDOWS\system32\wvqrwmoa.dll
C:\WINDOWS\system32\wvvqytke.dll
C:\WINDOWS\system32\wwdapxms.dll
C:\WINDOWS\system32\wxwivjma.ini
C:\WINDOWS\system32\wydtgfas.dll
C:\WINDOWS\system32\xafcssbu.ini
C:\WINDOWS\system32\xakupfsq.ini
C:\WINDOWS\system32\xbjyvwwb.ini
C:\WINDOWS\system32\xcobcxbp.ini
C:\WINDOWS\system32\xfxmrgjb.dll
C:\WINDOWS\system32\xovhotkv.ini
C:\WINDOWS\system32\xtkukbdu.ini
C:\WINDOWS\system32\xtmwrjta.ini
C:\WINDOWS\system32\yajktqkt.ini
C:\WINDOWS\system32\ybuihttg.ini
C:\WINDOWS\system32\yewfwmig.ini
C:\WINDOWS\system32\ykpunmbs.ini
C:\WINDOWS\system32\ylvdfjgr.dll
C:\WINDOWS\system32\ymbols~1
C:\WINDOWS\system32\ymbols~1\i?xplore.exe
C:\WINDOWS\system32\yrvswhmk.ini
C:\WINDOWS\system32\yshsylyx.dll
C:\WINDOWS\system32\yyfvbxnb.ini
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NETWORK_MONITOR
((((((((((((((((((((((((( Files Created from 2008-05-18 to 2008-06-18 )))))))))))))))))))))))))))))))
.
2008-06-16 19:05 . 2008-06-16 19:05 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-06-16 19:05 . 2008-06-16 19:05 <DIR> d-------- C:\WINDOWS\system32\bits
2008-06-16 19:05 . 2008-06-16 19:05 <DIR> d-------- C:\WINDOWS\l2schemas
2008-06-16 19:03 . 2008-06-16 19:03 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-06-16 18:58 . 2008-06-16 18:58 <DIR> d-------- C:\WINDOWS\EHome
2008-06-16 17:26 . 2008-04-13 20:12 4,274,816 --------- C:\WINDOWS\system32\nv4_disp.dll
2008-06-16 17:25 . 2008-04-13 20:11 1,888,992 --------- C:\WINDOWS\system32\ati3duag.dll
2008-06-16 15:59 . 2008-06-16 15:59 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-16 12:05 . 2008-06-16 12:05 <DIR> d-------- C:\Program Files\QuickTime
2008-06-16 12:04 . 2008-06-16 12:04 <DIR> d-------- C:\Program Files\Apple Software Update
2008-06-16 12:04 . 2008-06-16 12:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-06-16 11:11 . 2008-06-16 21:46 0 --ahs---- C:\Documents and Settings\HP_Owner\Application Data\
0000000000t.dat
2008-06-16 11:03 . 2008-06-16 11:03 485,888 --a------ C:\Documents and Settings\HP_Owner\installer.exe
2008-06-16 09:14 . 2008-04-14 08:30 272,128 --------- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-16 09:14 . 2008-05-08 10:02 203,136 --------- C:\WINDOWS\system32\dllcache\rmcast.sys
2008-05-27 10:50 . 2008-05-27 10:50 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-05-27 10:50 . 2008-05-27 10:50 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-16 16:24 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-06-16 16:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-16 16:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-16 16:06 --------- d-----w C:\Documents and Settings\HP_Owner\Application Data\Apple Computer
2008-06-16 16:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-05-08 14:02 203,136 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-04-25 04:06 --------- d-----w C:\Program Files\PokerStars
2008-04-14 00:12 69,120 ----a-w C:\WINDOWS\notepad.exe
2008-04-14 00:12 50,688 ----a-w C:\WINDOWS\twain_32.dll
2008-04-14 00:12 34,816 ----a-w C:\WINDOWS\Help\sniffpol.dll
2008-04-14 00:12 33,280 ----a-w C:\WINDOWS\Help\sstub.dll
2008-04-14 00:12 32,866 ------w C:\WINDOWS\slrundll.exe
2008-04-14 00:12 283,648 ----a-w C:\WINDOWS\winhlp32.exe
2008-04-14 00:12 279,040 ----a-w C:\WINDOWS\Help\tshoot.dll
2008-04-14 00:12 146,432 ----a-w C:\WINDOWS\regedit.exe
2008-04-14 00:12 10,752 ----a-w C:\WINDOWS\hh.exe
2008-04-14 00:12 1,033,728 ----a-w C:\WINDOWS\explorer.exe
2008-04-14 00:11 451,072 ----a-w C:\WINDOWS\AppPatch\aclayers.dll
2008-04-14 00:11 39,424 ----a-w C:\WINDOWS\AppPatch\acadproc.dll
2008-04-14 00:11 245,248 ----a-w C:\WINDOWS\AppPatch\acspecfc.dll
2008-04-14 00:11 141,312 ----a-w C:\WINDOWS\AppPatch\aclua.dll
2008-04-14 00:11 116,224 ----a-w C:\WINDOWS\AppPatch\acxtrnal.dll
2008-04-14 00:11 1,852,928 ----a-w C:\WINDOWS\AppPatch\acgenral.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{73C2DBEC-9C77-4A76-8E52-DCA4761849A7}]
C:\WINDOWS\system32\geedb.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 20:12 15360]
"Srro"="C:\DOCUME~1\HP_Owner\MYDOCU~1\YSTEM~1\winword.exe" [ ]
"Jefcobo"="C:\Documents and Settings\HP_Owner\Application Data\?icrosoft\w?wexec.exe" [ ]
"Msqife"="C:\Documents and Settings\HP_Owner\Application Data\?dobe\s?oolsv.exe" [ ]
"Xkp"="C:\WINDOWS\system32\?ssembly\m?dtc.exe" [ ]
"Gzy"="C:\Program Files\W?nSxS\??oolsv.exe" [ ]
"Rvxbovze"="C:\Documents and Settings\HP_Owner\Application Data\W?nSxS\w?aclt.exe" [ ]
"Pqkoeqh"="C:\WINDOWS\?racle\m?hta.exe" [ ]
"Fll"="C:\WINDOWS\system32\?ymbols\i?xplore.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" [2004-03-18 03:10 61952 C:\WINDOWS\system32\Hdaudpropshortcut.exe]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-08-20 18:51 118784]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 16:02 61440]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-14 16:43 233472]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-04-17 23:41 196608]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2002-10-16 12:57 81920]
"SoundMan"="SOUNDMAN.EXE" [2004-07-28 20:40 77824 C:\WINDOWS\SOUNDMAN.EXE]
"AlcWzrd"="ALCWZRD.EXE" [2004-07-28 21:34 2551808 C:\WINDOWS\ALCWZRD.EXE]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00 132496]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 10:50 413696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\asegyvzb]
asegyvzb.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efcawvs]
efcawvs.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geedb]
C:\WINDOWS\system32\geedb.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=C:\WINDOWS\pss\HP Image Zone Fast Start.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates from HP.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk
backup=C:\WINDOWS\pss\Updates from HP.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^HP_Owner^Start Menu^Programs^Startup^TA_Start.lnk]
path=C:\Documents and Settings\HP_Owner\Start Menu\Programs\Startup\TA_Start.lnk
backup=C:\WINDOWS\pss\TA_Start.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
--a------ 2004-06-29 13:06 88363 C:\WINDOWS\AGRSMMSG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\frwf]
C:\PROGRA~1\COMMON~1\frwf\frwfm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2004-09-13 18:49 49152 C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHmon06]
--a------ 2004-06-07 14:42 659456 C:\WINDOWS\system32\hphmon06.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD06]
--a------ 2004-06-07 14:53 49152 c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
--a------ 1998-05-07 12:04 52736 c:\windows\system\hpsysdrv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Insider]
C:\Program Files\Insider\Insider.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a------ 2004-04-13 17:07 69632 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LSBWatcher]
--a------ 2004-10-14 17:54 253952 c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mcysofwo]
C:\Documents and Settings\HP_Owner\Application Data\?asks\d?xplore.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-05-27 10:50 413696 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SfKg6w]
C:\Documents and Settings\HP_Owner\Application Data\Microsoft\Windows\rayiou.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Srro]
C:\DOCUME~1\HP_Owner\MYDOCU~1\YSTEM~1\winword.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2005-01-03 19:11 32881 C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemOptimizer]
C:\WINDOWS\system32\dqueqepn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tekebyr]
C:\Program Files\MSN Gaming Zone\tekebyr22011.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinTouch]
C:\Documents and Settings\HP_Owner\Application Data\WinTouch\WinTouch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"=
"C:\\StubInstaller.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\WINDOWS\system32\kctlvaba.exe"= C:\WINDOWS\system32\kct
"C:\WINDOWS\system32\abtfkyxj.exe"= C:\WINDOWS\system32\abt
"C:\WINDOWS\system32\bnraecyi.exe"= C:\WINDOWS\system32\bnr
"C:\WINDOWS\system32\uoyrgsxa.exe"= C:\WINDOWS\system32\uoy
"C:\WINDOWS\system32\qcereyiv.exe"= C:\WINDOWS\system32\qce
"C:\WINDOWS\system32\lxqulxam.exe"= C:\WINDOWS\system32\lxq
"C:\WINDOWS\system32\nanltfqo.exe"= C:\WINDOWS\system32\nan
"C:\WINDOWS\system32\adfapsau.exe"= C:\WINDOWS\system32\adf
"C:\WINDOWS\system32\lbjcduwn.exe"= C:\WINDOWS\system32\lbj
"C:\WINDOWS\system32\vpdfabcc.exe"= C:\WINDOWS\system32\vpd
"C:\WINDOWS\system32\ioctjbjj.exe"= C:\WINDOWS\system32\ioc
"C:\WINDOWS\system32\emyrgwke.exe"= C:\WINDOWS\system32\emy
"C:\WINDOWS\system32\yyfqovrt.exe"= C:\WINDOWS\system32\yyf
"C:\WINDOWS\system32\amqtgoyj.exe"= C:\WINDOWS\system32\amq
"C:\WINDOWS\system32\spbelvni.exe"= C:\WINDOWS\system32\spb
"C:\WINDOWS\system32\xrvulrgl.exe"= C:\WINDOWS\system32\xrv
"C:\WINDOWS\system32\bnedahlx.exe"= C:\WINDOWS\system32\bne
"C:\WINDOWS\system32\dmislwrr.exe"= C:\WINDOWS\system32\dmi
"C:\WINDOWS\system32\hjswcqeb.exe"= C:\WINDOWS\system32\hjs
"C:\WINDOWS\system32\rvurunax.exe"= C:\WINDOWS\system32\rvu
"C:\WINDOWS\system32\aymreuke.exe"= C:\WINDOWS\system32\aym
"C:\WINDOWS\system32\xcalvgcu.exe"= C:\WINDOWS\system32\xca
"C:\WINDOWS\system32\eybikwpb.exe"= C:\WINDOWS\system32\eyb
"C:\WINDOWS\system32\snffjmrn.exe"= C:\WINDOWS\system32\snf
"C:\WINDOWS\system32\jrncgqnh.exe"= C:\WINDOWS\system32\jrn
"C:\WINDOWS\system32\ypklcaru.exe"= C:\WINDOWS\system32\ypk
"C:\WINDOWS\system32\nnvnjyix.exe"= C:\WINDOWS\system32\nnv
"C:\WINDOWS\system32\dgbftkyj.exe"= C:\WINDOWS\system32\dgb
"C:\WINDOWS\system32\ncvfxocu.exe"= C:\WINDOWS\system32\ncv
"C:\WINDOWS\system32\uprgsldt.exe"= C:\WINDOWS\system32\upr
"C:\WINDOWS\system32\mgkbcxkb.exe"= C:\WINDOWS\system32\mgk
"C:\WINDOWS\system32\mjbjkihg.exe"= C:\WINDOWS\system32\mjb
"C:\WINDOWS\system32\lwldrcvp.exe"= C:\WINDOWS\system32\lwl
"C:\WINDOWS\system32\oetsrray.exe"= C:\WINDOWS\system32\oet
"C:\WINDOWS\system32\afdlsram.exe"= C:\WINDOWS\system32\afd
"C:\WINDOWS\system32\xfiepelb.exe"= C:\WINDOWS\system32\xfi
"C:\WINDOWS\system32\vofmynox.exe"= C:\WINDOWS\system32\vof
"C:\WINDOWS\system32\nfrgtrbd.exe"= C:\WINDOWS\system32\nfr
"C:\WINDOWS\system32\awstydjt.exe"= C:\WINDOWS\system32\aws
"C:\WINDOWS\system32\cfiyhhrl.exe"= C:\WINDOWS\system32\cfi
"C:\WINDOWS\system32\wysrmooo.exe"= C:\WINDOWS\system32\wys
"C:\WINDOWS\system32\hnimpcpe.exe"= C:\WINDOWS\system32\hni
"C:\WINDOWS\system32\yinfnysh.exe"= C:\WINDOWS\system32\yin
"C:\WINDOWS\system32\hiijkfad.exe"= C:\WINDOWS\system32\hii
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{946850c5-1e27-11d9-baf0-806d6172696f}]
\Shell\AutoRun\command - D:\setup.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-06-16 16:04:51 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-06-18 22:43:00 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDetect.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-06-18 18:41:13
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Java\jre1.6.0_02\bin\jucheck.exe
.
**************************************************************************
.
Completion time: 2008-06-18 18:48:41 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-18 22:47:38
Pre-Run: 131,977,220,096 bytes free
Post-Run: 132,020,531,200 bytes free
555 --- E O F --- 2008-06-17 02:55:08
and the hijackthis log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:51:21 PM, on 6/18/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\hkcmd.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\QuickTime\QTTask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Java\jre1.6.0_02\bin\jucheck.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://ie.redirect.h...a...&pf=desktopR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://google.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://ie.redirect.h...a...&pf=desktopR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {73C2DBEC-9C77-4A76-8E52-DCA4761849A7} - C:\WINDOWS\system32\geedb.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Srro] "C:\DOCUME~1\HP_Owner\MYDOCU~1\YSTEM~1\winword.exe" -vt ndrv
O4 - HKCU\..\Run: [Jefcobo] "C:\Documents and Settings\HP_Owner\Application Data\?icrosoft\w?wexec.exe"
O4 - HKCU\..\Run: [Msqife] "C:\Documents and Settings\HP_Owner\Application Data\?dobe\s?oolsv.exe"
O4 - HKCU\..\Run: [Xkp] C:\WINDOWS\system32\?ssembly\m?dtc.exe
O4 - HKCU\..\Run: [Gzy] "C:\Program Files\W?nSxS\??oolsv.exe"
O4 - HKCU\..\Run: [Rvxbovze] "C:\Documents and Settings\HP_Owner\Application Data\W?nSxS\w?aclt.exe"
O4 - HKCU\..\Run: [Pqkoeqh] C:\WINDOWS\?racle\m?hta.exe
O4 - HKCU\..\Run: [Fll] C:\WINDOWS\system32\?ymbols\i?xplore.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01016526-5E80-11D8-9E86-0007E96C65AE} (SmartAccess Ctl Class) -
https://install.char...in/ssctlsma.dllO16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) -
http://asp.mathxl.co...GenXInstall.cabO16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) -
http://upload.facebo...otoUploader.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1165376022640O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) -
http://asp.mathxl.co...nstallAsst2.cabO16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} -
http://download.game...aploader_v6.cabO16 - DPF: {EEC9DBCC-04AD-4A1B-BEA7-C6DAD9515D5A} (Pearson MyEconLab Player Control) -
http://asp.mathxl.co.../EconPlayer.cabO20 - Winlogon Notify: asegyvzb - asegyvzb.dll (file missing)
O20 - Winlogon Notify: efcawvs - efcawvs.dll (file missing)
O20 - Winlogon Notify: geedb - C:\WINDOWS\system32\geedb.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
--
End of file - 7032 bytes