thank you for the reply.
ok I finished running combofix and here's the log:
ComboFix 08-06-20.4 - Ed 2008-06-26 17:20:21.5 - NTFSx86
Running from: C:\Documents and Settings\Ed\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BMa3e09c2d.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\DNUwwyay.ini
C:\WINDOWS\system32\DNUwwyay.ini2
C:\WINDOWS\system32\lpdhwqqy.ini
C:\WINDOWS\system32\yaywwUND.dll
.
((((((((((((((((((((((((( Files Created from 2008-05-26 to 2008-06-26 )))))))))))))))))))))))))))))))
.
2008-06-26 18:04 . 2008-06-26 18:04 22 --a------ C:\WINDOWS\pskt.ini
2008-06-26 18:04 . 2008-06-26 18:09 0 --a------ C:\WINDOWS\BMa3e09c2d.xml
2008-06-25 19:09 . 2008-06-25 19:09 106,496 --a------ C:\WINDOWS\system32\rbyvrlix.dll
2008-06-25 19:06 . 2008-06-25 19:06 81,920 --a------ C:\WINDOWS\system32\yqqwhdpl.dll
2008-06-25 19:05 . 2008-06-25 19:05 91,136 --a------ C:\WINDOWS\system32\pipbewuv.dll
2008-06-25 18:48 . 2008-06-25 18:48 294 --ahs---- C:\WINDOWS\system32\dwbmseuf.ini
2008-06-25 04:08 . 2008-06-25 04:08 99,840 --a------ C:\WINDOWS\system32\sfnhyxjw.dll
2008-06-25 04:06 . 2008-06-25 04:06 91,136 --a------ C:\WINDOWS\system32\urjuruvh.dll
2008-06-24 21:19 . 2008-06-24 21:19 25,088 --a------ C:\WINDOWS\system32\ddcBSJYo.dll
2008-06-24 21:19 . 2008-06-24 21:19 25,088 --a------ C:\WINDOWS\system32\awtrSkKD.dll
2008-06-24 21:18 . 2008-06-24 21:18 25,088 --a------ C:\WINDOWS\system32\efcCttsP.dll
2008-06-24 21:16 . 2008-06-24 21:16 81,920 --a------ C:\WINDOWS\system32\aecfquig.dll
2008-06-24 21:15 . 2008-06-24 21:15 99,840 --a------ C:\WINDOWS\system32\mqtoaoux.dll
2008-06-24 21:14 . 2008-06-24 21:14 91,136 --a------ C:\WINDOWS\system32\wwdmsbld.dll
2008-06-24 21:11 . 2008-06-24 21:11 25,088 --a------ C:\WINDOWS\system32\ddcAtqnO.dll
2008-06-24 21:10 . 2008-06-24 21:10 25,088 --a------ C:\WINDOWS\system32\wvUoNFYO.dll
2008-06-24 21:10 . 2008-06-24 21:10 25,088 --a------ C:\WINDOWS\system32\wvUOIaxy.dll
2008-06-24 21:10 . 2008-06-24 21:10 25,088 --a------ C:\WINDOWS\system32\wvUmnnKb.dll
2008-06-24 21:08 . 2008-06-24 21:08 25,088 --a------ C:\WINDOWS\system32\yayxvUMf.dll
2008-06-24 21:07 . 2008-06-24 21:07 25,088 --a------ C:\WINDOWS\system32\geBsrSLF.dll
2008-06-23 21:36 . 2008-06-23 21:36 <DIR> d-------- C:\Documents and Settings\Ed\Application Data\eMule
2008-06-21 05:37 . 2008-06-21 05:37 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-06-21 05:37 . 2008-06-21 05:37 1,409 --a------ C:\WINDOWS\QTFont.for
2008-06-16 14:41 . 2008-06-16 14:41 <DIR> d-------- C:\Program Files\PowerISO
2008-06-15 20:35 . 2008-06-15 20:43 <DIR> d-------- C:\Program Files\Flv Audio Extractor
2008-06-10 19:31 . 2008-06-13 09:10 272,128 --a------ C:\WINDOWS\system32\drivers\bthport.sys
2008-06-10 19:31 . 2008-06-13 09:10 272,128 --a------ C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-10 17:38 . 2008-03-21 13:57 14,640 --a------ C:\WINDOWS\system32\spmsgXP_2k3.dll
2008-06-10 17:38 . 2008-06-10 17:38 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2008-06-10 17:38 . 2008-06-10 17:38 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_zumbus_01007.Wdf
2008-06-08 07:57 . 2008-06-08 07:57 <DIR> d-------- C:\Documents and Settings\George.COMPUTER\Application Data\Move Networks
2008-06-01 18:18 . 2008-06-01 21:33 117 --a------ C:\WINDOWS\CIV.INI
2008-06-01 13:09 . 2008-06-01 13:09 <DIR> d-------- C:\Documents and Settings\Ed\Application Data\InstallShield
2008-06-01 13:06 . 2008-06-01 13:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\InterVideo
2008-06-01 13:04 . 2008-06-01 13:05 <DIR> d-------- C:\Program Files\Common Files\Ulead Systems
2008-06-01 08:08 . 2008-06-01 08:08 <DIR> d-------- C:\Documents and Settings\George.COMPUTER\Application Data\Ulead Systems
2008-05-31 14:06 . 2008-05-31 14:06 <DIR> d-------- C:\Program Files\Common Files\InterVideo
2008-05-31 14:04 . 2008-05-31 14:04 <DIR> d-------- C:\Program Files\Windows Media Components
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-26 21:55 96,256 -c--a-w C:\WINDOWS\system32\drivers\sptddrv1.sys
2008-06-26 20:24 --------- d-----w C:\Program Files\StepMania CVS
2008-06-24 19:35 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-06-24 01:36 --------- d-----w C:\Program Files\eMule
2008-06-23 00:59 --------- d-----w C:\Documents and Settings\Ed\Application Data\Skype
2008-06-22 21:36 --------- d-----w C:\Documents and Settings\Ed\Application Data\skypePM
2008-06-18 21:37 --------- d-----w C:\Program Files\LimeWire
2008-06-17 05:32 11,836 -c--a-w C:\Documents and Settings\Ed\Application Data\wklnhst.dat
2008-06-16 19:30 --------- d-----w C:\Program Files\Common Files\Adobe
2008-06-10 23:39 --------- d-----w C:\Program Files\Zune
2008-06-08 01:26 --------- d-----w C:\Program Files\mIRC
2008-06-01 17:04 --------- d-----w C:\Program Files\Ulead Systems
2008-06-01 17:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ulead Systems
2008-06-01 17:02 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-01 16:23 --------- d-----w C:\Documents and Settings\Ed\Application Data\Ulead Systems
2008-05-30 08:27 --------- d-----w C:\Program Files\DivX
2008-05-29 17:10 --------- d-----w C:\Program Files\Lexmark X1100 Series
2008-05-29 08:56 --------- d-----w C:\Program Files\Last.fm
2008-05-20 03:02 --------- d-----w C:\Documents and Settings\Ed\Application Data\vlc
2008-05-18 02:46 --------- d-----w C:\Program Files\AllToAVI
2008-05-13 01:53 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-05-13 01:53 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-05-13 01:51 200,704 -c--a-w C:\WINDOWS\system32\ssldivx.dll
2008-05-13 01:51 1,044,480 -c--a-w C:\WINDOWS\system32\libdivx.dll
2008-05-13 01:49 161,096 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-05-13 01:49 12,288 -c--a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-05-12 23:16 --------- d-----w C:\Program Files\Java
2008-05-12 21:52 --------- d-----w C:\Program Files\iTunes
2008-05-12 03:26 --------- d-----w C:\Program Files\Trend Micro
2008-05-12 03:12 --------- d-----w C:\Program Files\Lavasoft
2008-05-12 03:12 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-05-12 03:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-12 03:09 --------- d-----w C:\Program Files\Vcsron
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\dllcache\rmcast.sys
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\dllcache\quartz.dll
2008-05-04 21:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\AVG7
2008-05-04 20:30 --------- d-----w C:\Program Files\jv16 PowerTools 2008
2008-05-03 13:55 --------- d-----w C:\Documents and Settings\George.COMPUTER\Application Data\LimeWire
2008-05-02 20:20 --------- d-----w C:\Program Files\Pcsx2_0.9.4
2008-05-02 20:20 --------- d-----w C:\Documents and Settings\Ed\Application Data\Metacafe
2008-05-02 20:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Metacafe
2008-05-01 20:33 --------- d-----w C:\Program Files\Autodesk
2008-04-29 23:56 61,856 ----a-w C:\WINDOWS\system32\ZuneBusEnum.exe
2008-04-29 23:56 245,664 ----a-w C:\WINDOWS\system32\ZuneWlanCfgSvc.exe
2008-04-29 23:39 70,144 ----a-w C:\WINDOWS\system32\ZuneIpTransport.dll
2008-04-29 23:39 62,464 ----a-w C:\WINDOWS\system32\ZuneUsbTransport.dll
2008-04-29 23:39 40,704 ----a-w C:\WINDOWS\system32\drivers\zumbus.sys
2008-04-29 23:39 35,328 ----a-w C:\WINDOWS\system32\ZuneUsbCOnnection.dll
2008-04-29 23:39 145,408 ----a-w C:\WINDOWS\system32\ZuneMTPZ.dll
2008-04-24 02:16 3,591,680 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-04-22 07:40 625,664 ----a-w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-04-22 07:39 70,656 ----a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-04-22 07:39 13,824 ----a-w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-04-20 05:07 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll
2008-04-17 23:11 1,112,288 ----a-w C:\WINDOWS\system32\WdfCoInstaller01007.dll
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\dllcache\msjint40.dll
2007-11-16 22:19 32 -c--a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2007-07-16 21:32 81,920 ----a-w C:\Documents and Settings\Ed\Application Data\ezpinst.exe
2007-07-16 21:32 47,360 ----a-w C:\Documents and Settings\Ed\Application Data\pcouffin.sys
2007-07-16 21:06 87,608 ----a-w C:\Documents and Settings\Ed\Application Data\inst.exe
2007-05-21 06:53 534 -c--a-w C:\Documents and Settings\Andy.COMPUTER\Application Data\wklnhst.dat
2007-04-27 02:00 604 -c-ha-w C:\Program Files\STLL Notifier
2007-03-28 23:06 696 -c--a-w C:\Documents and Settings\Compaq_Owner\Application Data\wklnhst.dat
2007-01-17 19:48 439,296 -c--a-w C:\Documents and Settings\Compaq_Owner\GoToAssist_phone__317_en.exe
2006-03-14 01:54 840 -c--a-w C:\Documents and Settings\Emma.GEORGEMMA.000\Application Data\wklnhst.dat
2006-03-01 00:56 4,506 -c--a-w C:\Documents and Settings\Ed.GEORGEMMA\Application Data\wklnhst.dat
2006-02-14 23:35 508 -c--a-w C:\Documents and Settings\Andy.GEORGEMMA\Application Data\wklnhst.dat
2005-12-05 22:54 774,144 -c--a-w C:\Program Files\RngInterstitial.dll
2005-07-29 21:24 472 -csha-r C:\WINDOWS\R2VvcmdlIE1lbG9odXNreQ\lZpSwAx5KHY5v36CxrhOyk.vbs
2006-08-10 00:30 56 --sha-r C:\WINDOWS\system32\957DCF128A.sys
2006-08-10 00:30 848 -csha-w C:\WINDOWS\system32\KGyGaAvL.sys
2006-08-26 19:57 130,905 -csha-w C:\WINDOWS\system32\srsc.dat
.
<pre>
----a-w 67,112 2008-03-24 18:30:15 C:\Program Files\AIM\aim .exe
-c--a-w 50,528 2008-03-24 18:30:17 C:\Program Files\AIM6\aim6 .exe
-c--a-w 75,392 2008-02-15 20:51:03 C:\Program Files\Alwil Software\Avast4\ashDisp .exe
-c--a-w 970,752 2008-03-18 21:14:53 C:\Program Files\Common Files\Adobe\Updater\AdobeUpdater .exe
-c--a-w 157,592 2008-02-15 20:51:02 C:\Program Files\DAEMON Tools\daemon .exe
-c--a-w 68,856 2008-02-14 23:15:23 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
-c--a-w 1,694,208 2008-03-18 21:14:53 C:\Program Files\Messenger\msmsgs .exe
-c--a-w 282,624 2008-02-05 20:48:35 C:\Program Files\QuickTime\qttask .exe
----a-w 648,704 2008-02-05 20:47:26 C:\Program Files\QuickTime\qttask .exe
-c--a-w 648,704 2008-02-05 01:20:20 C:\Program Files\QuickTime\qttask .exe
----a-w 648,704 2008-02-04 21:41:32 C:\Program Files\QuickTime\qttask .exe
----a-w 648,704 2008-02-03 21:06:33 C:\Program Files\QuickTime\qttask .exe
-c--a-w 648,704 2008-02-03 14:38:35 C:\Program Files\QuickTime\qttask .exe
----a-w 648,704 2008-02-02 18:52:52 C:\Program Files\QuickTime\qttask .exe
----a-w 648,704 2008-02-02 11:31:00 C:\Program Files\QuickTime\qttask .exe
----a-w 282,624 2008-02-14 00:36:17 C:\Program Files\QuickTime\qttask .exe
----a-w 648,704 2008-02-14 00:35:24 C:\Program Files\QuickTime\qttask .exe
----a-w 648,704 2008-02-13 20:48:23 C:\Program Files\QuickTime\qttask .exe
----a-w 648,704 2008-02-13 03:42:49 C:\Program Files\QuickTime\qttask .exe
----a-w 648,704 2008-02-12 20:05:13 C:\Program Files\QuickTime\qttask .exe
----a-w 648,704 2008-02-11 20:19:26 C:\Program Files\QuickTime\qttask .exe
----a-w 648,704 2008-02-10 18:55:52 C:\Program Files\QuickTime\qttask .exe
----a-w 648,704 2008-02-09 17:46:16 C:\Program Files\QuickTime\qttask .exe
----a-w 648,704 2008-02-08 21:03:58 C:\Program Files\QuickTime\qttask .exe
----a-w 648,704 2008-02-14 23:13:16 C:\Program Files\QuickTime\qttask .exe
----a-w 648,704 2008-02-14 22:38:09 C:\Program Files\QuickTime\qttask .exe
----a-w 21,760,296 2008-03-21 04:49:35 C:\Program Files\Skype\Phone\Skype .exe
-c--a-w 58,368 2008-02-15 20:21:41 C:\Program Files\Sound Volume Hotkeys\SoundVolumeHotkeys .exe
----a-w 3,481,600 2008-03-06 18:48:27 C:\Program Files\Veoh Networks\Veoh\VeohClient .exe
-c--a-w 166,304 2008-02-11 20:21:05 C:\Program Files\Zune\ZuneLauncher .exe
-c--a-w 102,400 2008-02-15 20:51:01 C:\WINDOWS\tsnp2std .exe
-c--a-w 339,968 2008-02-15 20:22:07 C:\WINDOWS\vsnp2std .exe
-c--a-w 208,952 2008-03-24 23:19:41 C:\WINDOWS\ime\imjp8_1\IMJPMIG .EXE
-c--a-w 44,032 2008-03-24 23:19:40 C:\WINDOWS\ime\imkr6_1\IMEKRMIG .EXE
----a-w 15,360 2008-03-24 23:19:57 C:\WINDOWS\system32\ctfmon .exe
----a-w 174,592 2008-03-22 14:05:58 C:\WINDOWS\system32\lexpps .exe
-c--a-w 98,304 2008-02-15 20:22:05 C:\WINDOWS\system32\ps2 .exe
-c--a-w 59,392 2008-03-24 23:19:46 C:\WINDOWS\system32\IME\PINTLGNT\ImScInst .exe
-c--a-w 455,168 2008-03-24 23:19:48 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP .EXE
</pre>
------- Sigcheck -------
2007-06-13 06:23 975360 9784e0719124e4a23989aef9e7ca02d6 C:\WINDOWS\explorer.exe
2007-06-13 07:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2007-06-13 06:23 975360 9784e0719124e4a23989aef9e7ca02d6 C:\WINDOWS\system32\dllcache\explorer.exe
2004-08-04 08:00 14848 340a992968d7fecb91161a0636f15beb C:\WINDOWS\system32\lsass.exe
2004-08-04 08:00 13312 84885f9b82f4d55c6146ebf6065d75d2 C:\WINDOWS\system32\dllcache\lsass.exe
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
-c--a-w 57,344 2005-06-07 03:46:24 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\bak\apdproxy.exe
-c--a-w 67,160 2005-08-05 19:08:26 C:\Program Files\AIM\bak\aim.exe
-c--a-w 180,269 2005-04-20 12:18:13 C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe
-c--a-w 58,992 2005-03-23 20:34:32 C:\Program Files\Common Files\Symantec Shared\bak\ccApp.exe
-c--a-w 133,016 2005-12-10 14:57:19 C:\Program Files\DAEMON Tools\bak\daemon.exe
-c--a-w 164,792 2006-10-10 20:20:52 C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.4150\bak\GoogleToolbarNotifier.exe
-c--a-w 229,952 2006-09-25 18:54:24 C:\Program Files\iTunes\bak\iTunesHelper.exe
-c--a-w 155,648 2006-03-26 17:05:59 C:\Program Files\QuickTime\bak\qttask.exe
-c--a-w 15,360 2004-08-04 12:00:00 C:\WINDOWS\system32\bak\ctfmon.exe
----a-w 15,360 2004-08-04 12:00:00 C:\WINDOWS\system32\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{349DB5C9-FBB0-4D84-AD5B-25AE40D17EE8}]
C:\Documents and Settings\Ed\Local Settings\Temporary Internet Files\Content.IE5\PV7BMU7E\3077ahntdksr[1].dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4ca3f9a3-9488-4f34-8276-a783f6a41295}]
2008-06-26 18:27 106496 --a------ C:\WINDOWS\system32\urnkihru.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8CDC07BE-A091-4455-B4CF-AA75F9854F3F}]
2008-06-26 18:06 319488 --a------ C:\WINDOWS\system32\qoMGAqpn.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C5E84927-CFF0-4CA3-A068-02E7C01C1E7C}]
2008-06-24 21:07 25088 --a------ C:\WINDOWS\system32\geBsrSLF.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DC549FE2-5615-457D-8244-A3A1ADF7B23F}]
C:\WINDOWS\system32\ssqrs.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\JARFile]
@={45A9B2C0-0D04-4AE6-B2F6-544B5C5E1EF3}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:00 15360]
"Aim6"="" []
"EventLog"="C:\WINDOWS\system32\event.exe" [ ]
"Vcsron"="C:\Program Files\Vcsron\Vcsron.exe" [2008-05-07 14:20 57344]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [ ]
"tsnp2std"="C:\WINDOWS\tsnp2std.exe" [ ]
"snp2std"="C:\WINDOWS\vsnp2std.exe" [ ]
"PS2"="C:\WINDOWS\system32\ps2.exe" [ ]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 08:00 208952]
"IMEKRMIG6.1"="C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-04 08:00 44032]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 08:00 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 08:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 08:00 455168]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 13:47 57344 C:\WINDOWS\ALCXMNTR.EXE]
"6565676F716C7171"="3F3F0000000000.exe" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"UVS11 Preload"="C:\Program Files\Ulead Systems\Ulead VideoStudio 11\uvPL.exe" [2007-07-23 13:55 341232]
"Zune Launcher"="c:\Program Files\Zune\ZuneLauncher.exe" [2008-04-29 19:56 158624]
"My Web Search Bar Search Scope Monitor"="C:\PROGRA~1\MYWEBS~1\bar\3.bin\m3SrchMn.exe" [ ]
"BMa3e09c2d"="C:\WINDOWS\system32\mjfrvewd.dll" [2008-06-26 18:22 91648]
"a0d3afb1"="C:\WINDOWS\system32\vxbyyclb.dll" [2008-06-26 18:24 80896]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-06-17 14:57 145920]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe" [2008-03-24 23:21 218496]
C:\Documents and Settings\Compaq_Owner\Start Menu\Programs\Startup\
Last.fm Helper.lnk - C:\Program Files\Last.fm\LastFMHelper.exe [2007-06-28 17:49:41 106496]
RocketDock.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe [2007-03-18 18:05:02 630784]
C:\Documents and Settings\Ed.GEORGEMMA\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2008-06-05 15:04:30 147456]
C:\Documents and Settings\Emma.GEORGEMMA.000\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2008-06-05 15:04:30 147456]
C:\Documents and Settings\George\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2008-06-05 15:04:30 147456]
C:\Documents and Settings\George.COMPUTER\Start Menu\Programs\Startup\
RocketDock.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe [2007-03-18 18:05:02 630784]
C:\Documents and Settings\Andy\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2008-06-05 15:04:30 147456]
C:\Documents and Settings\Andy.COMPUTER\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2008-06-05 15:04:30 147456]
C:\Documents and Settings\Andy.GEORGEMMA\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2008-06-05 15:04:30 147456]
C:\Documents and Settings\Andy.GEORGEMMA.000\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2008-06-05 15:04:30 147456]
C:\Documents and Settings\Ed\Start Menu\Programs\Startup\
RocketDock.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe [2007-03-18 18:05:02 630784]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{A6F5090F-D9EC-4263-9D7D-2968C5179291}"= C:\WINDOWS\system32\cbXNDssR.dll [ ]
"{C5E84927-CFF0-4CA3-A068-02E7C01C1E7C}"= C:\WINDOWS\system32\geBsrSLF.dll [2008-06-24 21:07 25088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"ZJvdzCxv"= {A0D3AF1F-0A79-05B5-082D-E56E99FFDA61} - C:\WINDOWS\system32\whjpxua.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
avgwlntf.dll 2007-06-14 21:29 9216 C:\WINDOWS\system32\avgwlntf.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geBsrSLF]
geBsrSLF.dll 2008-06-24 21:07 25088 C:\WINDOWS\system32\geBsrSLF.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mfc850]
mfc850.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljhfdd]
mljhfdd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\spoolsvc]
spoolsvc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm
"msacm.MPEGacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG\MPEGacm.acm
"msacm.ulmp3acm"= C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG\ulmp3acm.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\qoMGAqpn
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Compaq Connections.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Compaq Connections.lnk
backup=C:\WINDOWS\pss\Compaq Connections.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SpySubtract.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SpySubtract.lnk
backup=C:\WINDOWS\pss\SpySubtract.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Ed^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=C:\Documents and Settings\Ed\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=C:\WINDOWS\pss\LimeWire On Startup.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bpk]
C:\WINDOWS\system32\bpk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
c:\Program Files\Common Files\Symantec Shared\ccApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 08:00 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPBootOp]
--a--c--- 2005-02-26 01:34 245760 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X1100 Series]
--a------ 2003-08-19 06:43 57344 C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LSBWatcher]
--a--c--- 2004-10-14 16:54 253952 c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiSPower]
--a--c--- 2005-01-04 19:54 49152 C:\WINDOWS\system32\SiSPower.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\spoolsvc]
C:\WINDOWS\system32\spoolsvc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Compaq Connections\\6750491\\Program\\Compaq Connections.exe"=
"C:\\Program Files\\Google\\Google Earth\\GoogleEarth.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\BitComet\\BitComet.exe"=
"C:\\Program Files\\mIRC\\mirc.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\WINDOWS\\system32\\fxsclnt.exe"=
"C:\\Program Files\\Destiny\\RadioDestiny Broadcaster\\RadioDestiny Broadcaster.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Last.fm\\LastFM.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype .exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\PPMate\\PPMate\\ppmate.exe"=
"C:\\Program Files\\Joost\\xulrunner\\tvprunner.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"25:TCP"= 25:TCP:Outlook Express
"9172:TCP"= 9172:TCP:BitComet 9172 TCP
"9172:UDP"= 9172:UDP:BitComet 9172 UDP
"22405:TCP"= 22405:TCP:BitComet 22405 TCP
"22405:UDP"= 22405:UDP:BitComet 22405 UDP
"49000:TCP"= 49000:TCP:BitComet 49000 TCP
"49000:UDP"= 49000:UDP:BitComet 49000 UDP
"19524:TCP"= 19524:TCP:BitComet 19524 TCP
"19524:UDP"= 19524:UDP:BitComet 19524 UDP
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 17:38]
R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2008-04-29 19:39]
R2 ZuneBusEnum;Zune Bus Enumerator;c:\WINDOWS\system32\ZuneBusEnum.exe [2008-04-29 19:56]
S3 SNP2STD;USB2.0 PC Camera (SNP2STD);C:\WINDOWS\system32\DRIVERS\snp2sxp.sys [2005-09-21 14:31]
S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;c:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2008-04-29 19:56]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6778F1EE-80BB-4F27-BC69-F91B843782CD}]
C:\Documents and Settings\Ed\Application Data\Microsoft\cfgmgr.vbs
.
Contents of the 'Scheduled Tasks' folder
"2008-06-21 09:37:38 C:\WINDOWS\Tasks\HubTask 0 {0E7C166E-2D2F-4269-9034-DE1898BF2B1A} 0~0.job"
- C:\Program Files\Common Files\Sonic Shared\Sonic Central\Main\Mediahub.exe;Sched HubTask 0 {0E7C166E-2D2F-4269-9034-DE1898BF2B1A} 0~0
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-06-26 18:00:57
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\WINDOWS\system32\lpdhwqqy.ini 294 bytes
C:\WINDOWS\system32\qoMGAqpn.dll 319488 bytes executable
scan completed successfully
hidden files: 2
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\geBsrSLF.dll
PROCESS: C:\WINDOWS\explorer.exe
-> C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.dll
-> C:\WINDOWS\system32\vxbyyclb.dll
-> C:\WINDOWS\system32\mjfrvewd.dll
.
------------------------ Other Running Processes ------------------------
.
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPROXY.EXE
C:\Program Files\Common Files\Symantec Shared\CCSETMGR.EXE
C:\Program Files\Norton Internet Security\Norton AntiVirus\NAVAPSVC.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2008-06-26 18:57:55 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-26 22:57:33
ComboFix2.txt 2008-06-25 23:36:32
ComboFix3.txt 2008-06-25 08:35:18
ComboFix4.txt 2008-05-12 22:44:13
Pre-Run: 27,649,556,480 bytes free
Post-Run: 27,621,965,824 bytes free
427 --- E O F --- 2008-06-20 10:23:33