Ran VundoFix, came up with about 12-16files, reboot to delete, came up with 4, reboot to delete again, came up with none. Immediately rebooted in safe made and ran ComboFix, seemed to do wonders, after reboot everything running 3000% better, got a popup on the way to this site, but I'me sure I can remove that with spyware doctor like I did before, it just came back after every reboot. Thank You so much for your time. here is the VundoFix, ComboFix, and HijackThis logs, in that order seperated by a line of o's. Thanks so much again this was far worse than any infection I've evr ran into.
ooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
VundoFix V6.7.7
Checking Java version...
Java version is 1.5.0.4
Old versions of java are exploitable and should be removed.
Scan started at 19:59:11 2008-01-17
Listing files found while scanning....
C:\WINDOWS\system32\ezSP_Px.exe
C:\WINDOWS\system32\geebc.exe
C:\WINDOWS\system32\iifdcya.dll
C:\WINDOWS\system32\NCTAudioCDGrabber2.dll
C:\WINDOWS\system32\NCTAudioFile2.dll
C:\WINDOWS\system32\NCTAudioPlayer2.dll
C:\WINDOWS\system32\NCTAudioRecord2.dll
C:\WINDOWS\system32\NCTAVIFile.dll
C:\WINDOWS\system32\NCTQuickTimeFile.dll
C:\WINDOWS\system32\NCTVideoCoreM.dll
C:\WINDOWS\system32\NCTWMAFile2.dll
C:\WINDOWS\system32\qrqss.ini
C:\WINDOWS\system32\qrqss.ini2
C:\WINDOWS\system32\ssqrq.dll
C:\WINDOWS\system32\ssqrq.exe
Beginning removal...
Attempting to delete C:\WINDOWS\system32\ezSP_Px.exe
C:\WINDOWS\system32\ezSP_Px.exe Has been deleted!
Attempting to delete C:\WINDOWS\system32\geebc.exe
C:\WINDOWS\system32\geebc.exe Has been deleted!
Attempting to delete C:\WINDOWS\system32\iifdcya.dll
C:\WINDOWS\system32\iifdcya.dll Could not be deleted.
Attempting to delete C:\WINDOWS\system32\NCTAudioCDGrabber2.dll
C:\WINDOWS\system32\NCTAudioCDGrabber2.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\NCTAudioFile2.dll
C:\WINDOWS\system32\NCTAudioFile2.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\NCTAudioPlayer2.dll
C:\WINDOWS\system32\NCTAudioPlayer2.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\NCTAudioRecord2.dll
C:\WINDOWS\system32\NCTAudioRecord2.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\NCTAVIFile.dll
C:\WINDOWS\system32\NCTAVIFile.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\NCTQuickTimeFile.dll
C:\WINDOWS\system32\NCTQuickTimeFile.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\NCTVideoCoreM.dll
C:\WINDOWS\system32\NCTVideoCoreM.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\NCTWMAFile2.dll
C:\WINDOWS\system32\NCTWMAFile2.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\qrqss.ini
C:\WINDOWS\system32\qrqss.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\qrqss.ini2
C:\WINDOWS\system32\qrqss.ini2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\ssqrq.dll
C:\WINDOWS\system32\ssqrq.dll Could not be deleted.
Attempting to delete C:\WINDOWS\system32\ssqrq.exe
C:\WINDOWS\system32\ssqrq.exe Has been deleted!
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\WINDOWS\system32\iifdcya.dll
C:\WINDOWS\system32\iifdcya.dll Could not be deleted.
Attempting to delete C:\WINDOWS\system32\qrqss.ini
C:\WINDOWS\system32\qrqss.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\qrqss.ini2
C:\WINDOWS\system32\qrqss.ini2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\ssqrq.dll
C:\WINDOWS\system32\ssqrq.dll Has been deleted!
Performing Repairs to the registry.
Done!
Beginning removal...
ooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
ComboFix 08-01-16.4 - Seth 2008-01-17 22:23:44.1 - NTFSx86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.332 [GMT -5:00]
Running from: C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\My Documents\ASEMBL~1
C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\My Documents\ASEMBL~1\r?gedit.exe
C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\Start Menu\Programs\Startup\PowerReg Scheduler .exe
C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\Start Menu\Programs\Startup\PowerReg Scheduler .exe
C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\Start Menu\Programs\Startup\PowerReg Scheduler .exe
C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\Start Menu\Programs\Startup\PowerReg Scheduler .exe
C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\Start Menu\Programs\Startup\PowerReg Scheduler .exe
C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\Start Menu\Programs\Startup\PowerReg Scheduler .exe
C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\Start Menu\Programs\Startup\PowerReg Scheduler .exe
C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\Start Menu\Programs\Startup\PowerReg Scheduler .exe
C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\Start Menu\Programs\Startup\PowerReg Scheduler .exe
C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\Start Menu\Programs\Startup\PowerReg Scheduler .exe
C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\Start Menu\Programs\Startup\PowerReg Scheduler .exe
C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\Start Menu\Programs\Startup\PowerReg Scheduler .exe
C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\Start Menu\Programs\Startup\PowerReg Scheduler .exe
C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\Start Menu\Programs\Startup\PowerReg Scheduler .exe
C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\Start Menu\Programs\Startup\PowerReg Scheduler V3 .exe
C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\Start Menu\Programs\Startup\PowerReg Scheduler V3 .exe
C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\Start Menu\Programs\Startup\PowerReg Scheduler V3 .exe
C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\Start Menu\Programs\Startup\PowerReg Scheduler V3 .exe
C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\Start Menu\Programs\Startup\PowerReg Scheduler V3 .exe
C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\Start Menu\Programs\Startup\PowerReg Scheduler V3 .exe
C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\Start Menu\Programs\Startup\PowerReg Scheduler V3 .exe
C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\Start Menu\Programs\Startup\PowerReg Scheduler V3 .exe
C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\Start Menu\Programs\Startup\PowerReg Scheduler V3 .exe
C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\Start Menu\Programs\Startup\PowerReg Scheduler V3 .exe
C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\Start Menu\Programs\Startup\PowerReg Scheduler V3 .exe
C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\Start Menu\Programs\Startup\PowerReg Scheduler V3 .exe
C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\Start Menu\Programs\Startup\PowerReg Scheduler V3 .exe
C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\Start Menu\Programs\Startup\PowerReg Scheduler V3 .exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Common Files\download
C:\Program Files\Common Files\Real\Update_OB\realsched .exe
C:\Program Files\Common Files\windows
C:\Program Files\Common Files\windows\ack.html
C:\Program Files\Common Files\windows\AutoIt3.exe
C:\Program Files\Common Files\windows\autoitscript.au3
C:\Program Files\Common Files\windows\psapi.dll
C:\Program Files\Common Files\windows\request.html
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Dot1XCfg\Dot1XCfg.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched .exe
C:\Program Files\Messenger\msmsgs .exe
C:\Program Files\PowerISO\PWRISOVM .EXE
C:\Program Files\QdrDrive
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD .exe
C:\Program Files\Sony\SonicStage\SsAAD .exe
C:\Program Files\Spyware Doctor\swdoctor .exe
C:\Program Files\Spyware Doctor\swdoctor .exe
C:\Program Files\Spyware Doctor\swdoctor .exe
C:\Program Files\Temporary
C:\Program Files\winupdate
C:\WINDOWS\b.exe
C:\WINDOWS\b103.exe
C:\WINDOWS\b122.exe
C:\WINDOWS\b128.exe
C:\WINDOWS\b138.exe
C:\WINDOWS\b151.exe
C:\WINDOWS\mrofinu72.exe
C:\WINDOWS\system32\
000080.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\ctfmon.exe.tmp
C:\WINDOWS\system32\ecurit~1
C:\WINDOWS\system32\ecurit~1\?ecurity\
C:\WINDOWS\system32\ecurit~1\tracert .exe
C:\WINDOWS\system32\ecurit~1\tracert.exe
C:\WINDOWS\system32\iifdcya.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\qrqss.ini
C:\WINDOWS\system32\qrqss.ini2
C:\WINDOWS\system32\RCX89.tmp
C:\WINDOWS\system32\ssqrq.dll
C:\WINDOWS\system32\ssqrq.exe
C:\WINDOWS\system32\wintsvcc32.exe
C:\WINDOWS\system32\zqhyd.dll
D:\Autorun.inf
<pre>
C:\Program Files\AIM6\aim6 .exe ---> aim6.exe
C:\Program Files\Common Files\Real\Update_OB\realsched .exe ---> QooBox
C:\Program Files\DAEMON Tools\daemon .exe ---> daemon.exe
C:\Program Files\Dot1XCfg\Dot1XCfg .exe ---> Dot1XCfg.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched .exe ---> QooBox
C:\Program Files\Messenger\msmsgs .exe ---> QooBox
C:\Program Files\PowerISO\PWRISOVM .EXE ---> QooBox
Error moving C:\Program Files\QuickTime\qttask .exe to C:\Program Files\QuickTime\qttask.exe: 5.
C:\Program Files\SlySoft\AnyDVD\AnyDVD .exe ---> QooBox
C:\Program Files\Sony\SonicStage\SsAAD .exe ---> QooBox
C:\Program Files\Spyware Doctor\swdoctor .exe ---> swdoctor.exe
C:\Program Files\Spyware Doctor\swdoctor .exe ---> swdoctor.exe
C:\WINDOWS\system32\ctfmon .exe ---> ctfmon.exe
</pre>
.
.
((((((((((((((((((((((((( Files Created from 2007-12-18 to 2008-01-18 )))))))))))))))))))))))))))))))
.
2008-01-17 19:59 . 2008-01-17 22:03 <DIR> d-------- C:\VundoFix Backups
2008-01-16 16:59 . 2008-01-16 16:59 72,566 --a------ C:\WINDOWS\system32\GameFly_2.ico
2008-01-16 13:40 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-13 18:36 . 2008-01-14 20:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-13 14:28 . 2008-01-15 19:25 389,120 --a------ C:\WINDOWS\system32\ezSP_Px .exe
2008-01-13 13:33 . 2008-01-17 22:39 <DIR> d-------- C:\Program Files\Dot1XCfg
2008-01-13 13:29 . 2008-01-15 16:58 39,936 --a------ C:\WINDOWS\mrofinu72.exe.tmp
2008-01-12 14:56 . 2008-01-12 14:56 <DIR> d-------- C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\Application Data\CrystalSpace
2008-01-12 14:56 . 2008-01-12 14:56 <DIR> d-------- C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\Application Data\CrystalApp
2008-01-01 15:45 . 2008-01-01 15:45 <DIR> d-------- C:\Program Files\7-Zip
2007-12-30 17:41 . 2007-12-30 17:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WildTangent
2007-12-30 17:40 . 2007-12-30 17:40 <DIR> d-------- C:\Program Files\HP Games
2007-12-30 04:31 . 2007-12-30 04:31 1,409 --a------ C:\WINDOWS\QTFont.for
2007-12-30 04:30 . 2008-01-12 12:31 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-12-29 14:43 . 2007-12-29 15:10 <DIR> d-------- C:\PICTURES
2007-12-22 23:17 . 2007-12-22 23:17 <DIR> d-------- C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\Application Data\InstallShield
2007-12-18 16:39 . 2007-12-18 16:39 <DIR> d-------- C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\Application Data\vlc
2007-12-18 16:37 . 2007-12-18 16:37 <DIR> d-------- C:\Program Files\VideoLAN
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-18 03:39 --------- d-----w C:\Program Files\Spyware Doctor
2008-01-18 03:39 --------- d-----w C:\Program Files\DAEMON Tools
2008-01-18 03:39 --------- d-----w C:\Program Files\AIM6
2008-01-18 03:33 --------- d-----w C:\Program Files\QuickTime
2008-01-18 03:33 --------- d-----w C:\Program Files\PowerISO
2008-01-18 03:12 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-15 22:24 --------- d-----w C:\Program Files\Hewlett-Packard
2008-01-12 17:44 --------- d-----w C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\Application Data\uTorrent
2008-01-01 23:10 --------- d-----w C:\Program Files\AIRFLO
2007-12-27 20:35 --------- d-----w C:\Program Files\LimeWire
2007-12-23 04:17 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-17 11:30 --------- d-----w C:\Program Files\JoWooD
2007-12-16 23:11 --------- d-----w C:\Program Files\DOSBox-0.65
2007-11-30 15:23 97,216 ----a-w C:\WINDOWS\system32\drivers\AnyDVD.sys
2007-11-24 23:25 --------- d-----w C:\Program Files\Coupons
2007-11-23 23:05 685,816 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2007-11-23 22:24 --------- d-----w C:\Program Files\Atari
2007-11-20 01:53 --------- d-----w C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\Application Data\Free Download Manager
2005-12-24 22:15 251 ----a-w C:\Program Files\wt3d.ini
2005-09-25 22:24 12,800 ----a-w C:\Documents and Settings\Brenda\a.exe
.
<pre>
----a-w 598,016 2008-01-18 03:41:25 C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\Start Menu\Programs\Startup\PowerReg Scheduler .exe
----a-w 567,296 2008-01-18 03:41:26 C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\Start Menu\Programs\Startup\PowerReg Scheduler V3 .exe
----a-w 260,062 2005-09-05 15:19:42 C:\FILES\LimeWire\Ogre Battle 64 - Person of Lordly Caliber (U) [!]\Diablo II CD Key Generator .exe
----a-w 448,512 2008-01-16 00:25:17 C:\Program Files\QuickTime\qttask .exe
----a-w 389,120 2008-01-16 00:25:14 C:\WINDOWS\system32\ezSP_Px .exe
</pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3D266504-0FBC-4d3f-9E7C-4077A77C7DC4}]
2007-08-10 02:00 217088 --a------ C:\Program Files\Live Search Club Toolbar\LiveSearchClubToolbarBho.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4E81A936-E5C3-4BC1-9853-35736D1822DE}]
2008-01-17 22:41 336384 --a------ C:\WINDOWS\system32\ssqrq.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5}
{2318C2B1-4965-11D4-9B18-009027A5CD4F}
{719D74AB-1AF9-43A1-8C62-D8750628D93E}
[HKEY_CLASSES_ROOT\clsid\{719d74ab-1af9-43a1-8c62-d8750628d93e}]
[HKEY_CLASSES_ROOT\LiveToolbar.LiveToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{7507B80F-C1DE-4b0a-A0BA-120C64075F11}]
[HKEY_CLASSES_ROOT\LiveToolbar.LiveToolbar]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [ ]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-01-15 19:25 2226688]
"Spyware Doctor"="C:\Program Files\Spyware Doctor\swdoctor .exe" [ ]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-01-17 22:41 412160]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2008-01-17 22:41 520192]
"Amhgr"="C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\My Documents\a?sembly\r?gedit.exe" [ ]
"Dot1XCfg"="C:\Program Files\Dot1XCfg\Dot1XCfg.exe" [2008-01-17 22:41 401408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe" [ ]
"ezShieldProtector for Px"="C:\WINDOWS\system32\ezSP_Px .exe" [2008-01-15 19:25 389120]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-07-20 20:07 7110656]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-01-15 19:25 521216]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [2008-01-15 19:25 448512]
"SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [2008-01-15 19:25 452096]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2008-01-15 19:25 476672]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2008-01-15 19:25 559104]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Spyware Doctor"="" []
C:\Documents and Settings\Seth\Start Menu\Programs\Startup\
PowerReg Scheduler.exe [2005-07-23 12:35:10]
C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\Start Menu\Programs\Startup\
GameSpot Download Manager.lnk - C:\Program Files\GameSpot\GDM_TrayApp.exe [2007-08-28 12:23:00]
PowerReg Scheduler .exe [2008-01-17 22:41:25]
PowerReg Scheduler V3 .exe [2008-01-17 22:41:26]
PowerReg Scheduler V3.exe [2008-01-17 22:41:28]
PowerReg Scheduler.exe [2008-01-17 22:41:29]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26]
Extender Resource Monitor.lnk - C:\WINDOWS\ehome\RMSysTry.exe [2005-10-20 18:55:40]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-05 04:28:24]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 15:05:56]
Service Manager.lnk - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2002-12-17 16:23:32]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows]
"load"=C:\WINDOWS\system32\ssqrq.exe
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\ssqrq
R2 DNADownloader;DNADownloader;C:\Program Files\GameSpot\DownloadManager_Win32.exe [2007-08-28 12:33]
R2 RMSvc;Media Center Extender Resource Monitor;C:\WINDOWS\ehome\RMSvc.exe [2005-10-20 18:55]
R3 USB_RNDIS_XP;Westell USB Network Interface;C:\WINDOWS\system32\DRIVERS\usb8023.sys [2004-08-10 07:00]
S3 QWAVE;QWAVE service;C:\WINDOWS\system32\svchost.exe [2004-08-10 07:00]
S3 samhid;samhid;C:\WINDOWS\system32\drivers\samhid.sys [2004-07-14 12:51]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
QWAVE REG_MULTI_SZ QWAVE
.
Contents of the 'Scheduled Tasks' folder
"2007-12-26 15:48:30 C:\WINDOWS\Tasks\HubTask 0 {0E7C166E-2D2F-4269-9034-DE1898BF2B1A} 0~0.job"
- C:\Program Files\Common Files\Sonic Shared\Sonic Central\Main\Mediahub.exe;Sched HubTask 0 {0E7C166E-2D2F-4269-9034-DE1898BF2B1A} 0~0
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-17 22:40:32
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\WINDOWS\system32\ssqrq.exe 339968 bytes executable
scan completed successfully
hidden files: 1
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.2180]
-> C:\WINDOWS\system32\ssqrq.dll
.
Completion time: 2008-01-17 22:46:10 - machine was rebooted [Seth]
ComboFix-quarantined-files.txt 2008-01-18 03:46:05
ooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:05:11 PM, on 1/17/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\GameSpot\DownloadManager_Win32.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\ehome\RMSvc.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\ehome\McrdSvc.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Dot1XCfg\Dot1XCfg.exe
C:\Program Files\GameSpot\GDM_TrayApp.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\AIM6\aim6 .exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\Desktop\HiJackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://ie.redirect.hp.com/svs/rdr?TY...rm1=seconduser
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.daemonsearch.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
F3 - REG:win.ini: load=C:\WINDOWS\system32\ssqrq.exe
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O3 - Toolbar: Live Search Club Toolbar - {719D74AB-1AF9-43a1-8C62-D8750628D93E} - C:\Program Files\Live Search Club Toolbar\Toolbar.dll
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe" /run
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px .exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor .exe" /Q
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [Amhgr] "C:\Documents and Settings\Seth.YOUR-55E5F9E3D2.000\My Documents\a?sembly\r?gedit.exe"
O4 - HKCU\..\Run: [Dot1XCfg] C:\Program Files\Dot1XCfg\Dot1XCfg.exe
O4 - HKUS\S-1-5-18\..\Run: [Spyware Doctor] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Spyware Doctor] (User 'Default user')
O4 - Startup: GameSpot Download Manager.lnk = C:\Program Files\GameSpot\GDM_TrayApp.exe
O4 - Startup: PowerReg Scheduler .exe
O4 - Startup: PowerReg Scheduler V3 .exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Extender Resource Monitor.lnk = C:\WINDOWS\ehome\RMSysTry.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) -
https://components.viewpoint.com/MTS...?noreloadredir
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsu...?1133305996812
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) -
http://www.systemrequirementslab.com/sysreqlab2.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) -
http://www.acclaim.com/cabs/acclaim_v4.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/ge...sh/swflash.cab
O23 - Service: DNADownloader - CNET Networks - C:\Program Files\GameSpot\DownloadManager_Win32.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
--
End of file - 9370 bytes
ooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
Thanks so Much yet again!