Thanks for responding to my help topic! Here is the log you requested.
"Compaq_Owner" - 2007-07-27 9:18:50 - ComboFix 07-07-23.6 - Service Pack 2 NTFS
(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\cvmbbaun.dll
C:\WINDOWS\system32\tncjdadr.dll
C:\WINDOWS\system32\yorcrxcs.dll
C:\WINDOWS\system32\xycdd.bak1
C:\WINDOWS\system32\xycdd.bak2
C:\WINDOWS\system32\xycdd.ini
C:\WINDOWS\system32\tuvuurq.dll
C:\WINDOWS\system32\tuvuurq.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\COMPAQ~1\APPLIC~1.\curity~1
C:\DOCUME~1\COMPAQ~1\APPLIC~1.\dobe~1
C:\DOCUME~1\COMPAQ~1\APPLIC~1.\dobe~2
C:\DOCUME~1\COMPAQ~1\APPLIC~1.\fnts~1
C:\DOCUME~1\COMPAQ~1\APPLIC~1.\icroso~1
C:\DOCUME~1\COMPAQ~1\APPLIC~1.\icroso~1.net
C:\DOCUME~1\COMPAQ~1\APPLIC~1.\mantec~1
C:\DOCUME~1\COMPAQ~1\APPLIC~1.\mcroso~1
C:\DOCUME~1\COMPAQ~1\APPLIC~1.\ppatch~1
C:\DOCUME~1\COMPAQ~1\APPLIC~1.\racle~1
C:\DOCUME~1\COMPAQ~1\APPLIC~1.\racle~2
C:\DOCUME~1\COMPAQ~1\APPLIC~1.\sks~1
C:\DOCUME~1\COMPAQ~1\APPLIC~1.\smante~1
C:\DOCUME~1\COMPAQ~1\APPLIC~1.\ssembl~1
C:\DOCUME~1\COMPAQ~1\APPLIC~1.\tsks~1
C:\DOCUME~1\COMPAQ~1\APPLIC~1.\ymante~1
C:\DOCUME~1\COMPAQ~1\APPLIC~1.\ystem~1
C:\DOCUME~1\COMPAQ~1\MYDOCU~1.\crosof~1.net
C:\DOCUME~1\COMPAQ~1\MYDOCU~1.\crosof~1.net\javaw.exe
C:\DOCUME~1\COMPAQ~1\MYDOCU~1.\mantec~1
C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Rar$EX01.000\about ao\_desktop.ini
C:\Program Files\appatc~1
C:\Program Files\asembl~1
C:\Program Files\asks~1
C:\Program Files\Common Files\asks~1
C:\Program Files\Common Files\crosof~1.net
C:\Program Files\Common Files\dobe~1
C:\Program Files\Common Files\fnts~1
C:\Program Files\Common Files\fnts~2
C:\Program Files\Common Files\mantec~1
C:\Program Files\Common Files\mcroso~1.net
C:\Program Files\Common Files\ppatch~1
C:\Program Files\Common Files\scurit~1
C:\Program Files\Common Files\scurit~1\spoolsv.exe
C:\Program Files\Common Files\sembly~1
C:\Program Files\Common Files\ssembl~1
C:\Program Files\Common Files\sstem3~1
C:\Program Files\Common Files\stem~1
C:\Program Files\Common Files\stem32~1
C:\Program Files\Common Files\tsks~1
C:\Program Files\Common Files\windows
C:\Program Files\Common Files\wnsxs~1
C:\Program Files\Common Files\ymante~1
C:\Program Files\Common Files\ymbols~1
C:\Program Files\crosof~1.net
C:\Program Files\dobe~1
C:\Program Files\ecurit~1
C:\Program Files\fnts~1
C:\Program Files\fnts~2
C:\Program Files\mantec~1
C:\Program Files\outerinfo
C:\Program Files\outerinfo\outerinfo.ico
C:\Program Files\outerinfo\Terms.rtf
C:\Program Files\ppatch~1
C:\Program Files\racle~1
C:\Program Files\scurit~1
C:\Program Files\smante~1
C:\Program Files\smbols~1
C:\Program Files\ssembl~1
C:\Program Files\sstem~1
C:\Program Files\sstem3~1
C:\Program Files\stem~1
C:\Program Files\stem32~1
C:\Program Files\wnsxs~1
C:\Program Files\ystem~1
C:\WINDOWS\appatc~1
C:\WINDOWS\asembl~1
C:\WINDOWS\asks~1
C:\WINDOWS\asks~2
C:\WINDOWS\crosof~1
C:\WINDOWS\dobe~1
C:\WINDOWS\ecurit~1
C:\WINDOWS\fnts~1
C:\WINDOWS\ppatch~1
C:\WINDOWS\pppatc~1
C:\WINDOWS\pppatc~2
C:\WINDOWS\sembly~1
C:\WINDOWS\system32\appatc~1
C:\WINDOWS\system32\asks~1
C:\WINDOWS\system32\curity~1
C:\WINDOWS\system32\dobe~1
C:\WINDOWS\system32\drivers\sfsync02.sys
C:\WINDOWS\system32\ecurit~1
C:\WINDOWS\system32\fnts~1
C:\WINDOWS\system32\fnts~2
C:\WINDOWS\system32\mantec~1
C:\WINDOWS\system32\mbols~1
C:\WINDOWS\system32\pppatc~1
C:\WINDOWS\system32\sks~1
C:\WINDOWS\system32\smante~1
C:\WINDOWS\system32\smbols~1
C:\WINDOWS\system32\ssembl~1
C:\WINDOWS\system32\sstem~1
C:\WINDOWS\system32\stem~1
C:\WINDOWS\system32\tsks~1
C:\WINDOWS\system32\ymante~1
C:\WINDOWS\system32\ymbols~1
C:\WINDOWS\system32\ystem~1
C:\WINDOWS\system32\ystem3~1
C:\WINDOWS\tsks~1
C:\WINDOWS\wnsxs~1
C:\WINDOWS\ymante~1
C:\WINDOWS\ymbols~1
C:\WINDOWS\ystem~1
C:\WINDOWS\ystem3~1
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_SFSYNC02
-------\sfsync02
((((((((((((((((((((((((( Files Created from 2007-06-27 to 2007-07-27 )))))))))))))))))))))))))))))))
2007-07-27 09:26 0 --a------ C:\WINDOWS\system32\sfsync02.dll
2007-07-27 09:17 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-27 05:52 69,184 --a------ C:\WINDOWS\system32\outaenlb.dll
2007-07-26 10:21 <DIR> d-------- C:\Program Files\Pop up Blocker
2007-07-26 04:40 126,016 --a------ C:\WINDOWS\system32\ruqidode.dll
2007-07-25 07:11 <DIR> d-------- C:\DOCUME~1\COMPAQ~1\APPLIC~1\Yahoo!
2007-07-25 04:45 126,016 --a------ C:\WINDOWS\system32\kxftbynw.dll
2007-07-25 04:34 1,765,610 --ahs---- C:\WINDOWS\system32\hjllm.bak2
2007-07-24 16:04 6,466 --ahs---- C:\WINDOWS\system32\hjllm.bak1
2007-07-24 16:04 228,960 --a------ C:\WINDOWS\system32\mlljh.dll
2007-07-24 08:22 6,471 --ahs---- C:\WINDOWS\system32\ybeeg.bak1
2007-07-24 07:18 6,471 --ahs---- C:\WINDOWS\system32\nqtss.bak2
2007-07-24 03:53 6,511 --ahs---- C:\WINDOWS\system32\ccbeg.bak1
2007-07-24 02:15 6,471 --ahs---- C:\WINDOWS\system32\rqstv.bak1
2007-07-23 21:52 6,471 --ahs---- C:\WINDOWS\system32\mmllm.bak1
2007-07-23 20:16 6,511 --ahs---- C:\WINDOWS\system32\xyadd.bak1
2007-07-23 08:23 6,471 --ahs---- C:\WINDOWS\system32\hgjlm.bak1
2007-07-23 07:43 <DIR> d-------- C:\Program Files\StarWarsGalaxies
2007-07-23 07:42 <DIR> d-------- C:\Program Files\Sony
2007-07-23 06:57 6,471 --ahs---- C:\WINDOWS\system32\ppqss.bak1
2007-07-23 05:48 6,489 --ahs---- C:\WINDOWS\system32\wycdd.bak1
2007-07-23 02:39 6,489 --ahs---- C:\WINDOWS\system32\egjlm.bak1
2007-07-23 01:06 6,488 --ahs---- C:\WINDOWS\system32\ijllm.bak1
2007-07-22 23:35 6,529 --ahs---- C:\WINDOWS\system32\hhhkj.bak1
2007-07-22 22:30 6,489 --ahs---- C:\WINDOWS\system32\rrqss.bak1
2007-07-22 20:14 6,528 --ahs---- C:\WINDOWS\system32\tstwa.bak1
2007-07-22 17:37 6,488 --ahs---- C:\WINDOWS\system32\nqtss.bak1
2007-07-22 16:35 6,488 --ahs---- C:\WINDOWS\system32\cccdd.bak1
2007-07-22 07:32 6,489 --ahs---- C:\WINDOWS\system32\bcbeg.bak1
2007-07-22 04:50 6,528 --ahs---- C:\WINDOWS\system32\bbadd.bak1
2007-07-20 23:32 6,529 --ahs---- C:\WINDOWS\system32\rqtwa.bak1
2007-07-20 16:21 6,529 --ahs---- C:\WINDOWS\system32\sttss.bak1
2007-07-20 12:40 6,405 --ahs---- C:\WINDOWS\system32\rrutv.bak1
2007-07-20 11:30 6,365 --ahs---- C:\WINDOWS\system32\jlkkj.bak1
2007-07-16 16:10 <DIR> d-------- C:\Program Files\Trend Micro
2007-07-16 02:58 <DIR> d-------- C:\Program Files\Windows Defender
2007-07-11 11:56 <DIR> d-------- C:\Program Files\Panicware
2007-07-10 17:24 546 --a------ C:\WINDOWS\system32\V0503365.dat
2007-07-10 17:03 86,016 --a------ C:\WINDOWS\unvise32.exe
2007-07-10 17:03 <DIR> d-------- C:\Program Files\Spyware Sweeper
2007-07-09 08:54 <DIR> d-------- C:\Program Files\DAEMON Tools
2007-07-09 08:50 682,232 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2007-07-09 02:30 <DIR> d-------- C:\DOCUME~1\Admin\APPLIC~1\Help
2007-07-09 01:39 <DIR> d-------- C:\Program Files\ElcomSoft
2007-07-09 01:04 <DIR> d-------- C:\Program Files\Intelore
2007-07-08 06:36 <DIR> d-------- C:\NeverwinterNights
2007-07-08 03:46 <DIR> d-------- C:\X
2007-07-08 03:36 <DIR> d-------- C:\Program Files\WarRock
2007-07-08 02:30 <DIR> d-------- C:\DOCUME~1\Admin\APPLIC~1\Viewpoint
2007-07-08 02:01 200,704 --a------ C:\WINDOWS\system32\teulKit.dll
2007-07-08 01:59 <DIR> d-------- C:\Program Files\CRS
2007-07-08 01:46 942,080 --a------ C:\cg.dll
2007-07-08 01:46 823,296 --a------ C:\BDAdClient.dll
2007-07-08 01:46 794 --a------ C:\wwiiol_netcheck.bat
2007-07-08 01:46 651,264 --a------ C:\libeay32.dll
2007-07-08 01:46 536,576 --a------ C:\SETTINGS.exe
2007-07-08 01:46 502,272 --a------ C:\granny2.dll
2007-07-08 01:46 28,672 --a------ C:\ExtTools.dll
2007-07-08 01:46 176,128 --a------ C:\cgGL.dll
2007-07-08 01:46 147,456 --a------ C:\ssleay32.dll
2007-07-08 01:46 118,784 --a------ C:\OpenThreadsWin32.dll
2007-07-08 01:46 <DIR> d-------- C:\Data
2007-07-03 23:02 <DIR> d-------- C:\SFX
2007-07-03 23:02 <DIR> d-------- C:\Music
2007-07-03 23:01 <DIR> d-------- C:\Program Files\Dvondrake Studios
2007-06-27 02:26 <DIR> d-------- C:\DOCUME~1\Admin\APPLIC~1\BitTorrent
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-26 15:38:27 -------- d-----w C:\Program Files\MAIET
2007-07-25 23:29:03 -------- d-----w C:\Program Files\Trillian
2007-07-23 12:57:18 -------- d-----w C:\Program Files\NCH Swift Sound
2007-07-23 11:42:51 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-07-22 07:31:03 -------- d-----w C:\Program Files\Audiolib CD Ripper
2007-07-18 21:46:20 3,649 ----a-w C:\WINDOWS\viassary-hp.reg
2007-07-16 09:37:03 -------- d-----w C:\Program Files\MyWay
2007-07-15 06:00:21 -------- d-----w C:\Program Files\World of Warcraft
2007-07-14 09:17:18 -------- d-----w C:\Program Files\FreeRIP2
2007-07-11 01:11:25 -------- d-----w C:\Program Files\Intel
2007-07-10 20:26:12 562,688 --sh--r C:\WINDOWS\Intel.DLL
2007-07-03 17:14:59 -------- d-----w C:\Program Files\M3 GAME Manager
2007-07-02 01:21:31 -------- d-----w C:\Program Files\CaveStory
2007-06-04 20:50:15 -------- d-----w C:\Program Files\QuickTime
2007-06-04 20:48:16 -------- d-----w C:\Program Files\Bonjour
2007-06-04 20:38:25 -------- d-----w C:\Program Files\Common Files\Macrovision Shared
2007-05-29 16:54:16 -------- d-----w C:\Program Files\Warcraft III
2007-05-23 11:41:45 23,123 ----a-w C:\WINDOWS\War3Unin.dat
2007-05-23 05:08:57 2,829 ----a-w C:\WINDOWS\War3Unin.pif
2007-05-23 05:08:57 126,976 ----a-w C:\WINDOWS\War3Unin.exe
2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2006-04-15 02:17:19 204 ----a-w C:\Program Files\27N7KRTJ.bat
2006-06-28 17:19:17 56 --sh--r C:\WINDOWS\system32\9C08340B19.sys
2006-06-28 17:19:17 1,890 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1BB54790-BC1E-41F0-907D-E5FD3183A024}]
2007-07-24 16:04 228960 --a------ C:\WINDOWS\system32\mlljh.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{266D83FB-4B1D-1AEB-6B2C-1FE4C7B0B2C8}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5BD182B2-06C0-4C58-96BD-DD32DCEBE8B5}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6A95F53E-6B84-3D21-AB40-69E337E4FA98}]
C:\WINDOWS\system32\vqe.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6AB512D2-8A3A-8FC9-1B7B-DA581C7AF1CC}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{938A8A03-A938-4019-B764-03FF8D167D79}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A389EEE9-4702-4269-B360-42602056CAB0}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AD6DC212-54AD-5F5D-D947-599090D33A98}]
C:\WINDOWS\system32\yhwpg.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C883552B-CB9D-CE3C-BF41-996C2F1F539A}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EC138C13-53D7-4184-99A3-504066C43FBE}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F60604AA-9816-C6E8-694B-C929AA8168C0}]
C:\WINDOWS\system32\mpz.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F8889485-0F3E-0E90-4108-58F077CD6D92}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD2A7D3A-3DA1-4CA5-AD39-B4C3A72B567F}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-26 01:34]
"SMSERIAL"="sm56hlpr.exe" [2005-01-24 05:56 C:\WINDOWS\sm56hlpr.exe]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 16:54]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-05-27 22:57]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd.exe" [2003-08-04 17:28]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 08:38]
"DXDllRegExe"="dxdllreg.exe" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe" [2005-06-03 03:52]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-05-27 23:06]
"nwiz"="nwiz.exe" [2005-12-10 04:06 C:\WINDOWS\system32\nwiz.exe]
"D-Link Air Utility"="C:\Program Files\D-Link\Air Utility\AirCFG.exe" [2003-06-26 18:13]
"vxdman"="WTFCTF.exe" []
"sbin"="panel_its.exe" []
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-05-09 17:06]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 06:03]
"ISUSScheduler"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe" [2004-06-16 06:03]
"BlockChecker"="C:\Program Files\Block Checker\block-checker.exe" []
"ViewMgr"="C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe" [2007-01-04 17:38]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-09 00:02]
"DownloadAccelerator"="C:\Program Files\DAP\DAP.exe" [2005-10-31 11:45]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:00]
"xwiz"="cnftips.exe" []
"ftbar"="NopeZ.exe" []
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" []
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-12-31 18:11]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" []
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2005-05-31 01:04]
"BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" [2007-03-01 19:11]
"Pop up Blocker"="C:\Program Files\Pop up Blocker\pd.exe" [2007-01-12 17:43]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 19:24]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t
C:\Documents and Settings\Compaq_Owner\Start Menu\Programs\Startup\
dxva_sig.txt [2007-04-27 17:05:01]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoBandCustomize"=0 (0x0)
"NoMovingBands"=0 (0x0)
"NoCloseDragDropBands"=0 (0x0)
"NoSetTaskbar"=0 (0x0)
"NoToolbarsOnTaskbar"=0 (0x0)
"NoSaveSettings"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddcyx]
C:\WINDOWS\system32\ddcyx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gebcc]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mlljh]
C:\WINDOWS\system32\mlljh.dll 2007-07-24 16:04 228960 C:\WINDOWS\system32\mlljh.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tuvuurq]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wintuh32]
wintuh32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=arpa.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Compaq Connections.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Compaq Connections.lnk
backup=C:\WINDOWS\pss\Compaq Connections.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Compaq_Owner^Start Menu^Programs^Startup^360Share Pro On Startup.lnk]
path=C:\Documents and Settings\Compaq_Owner\Start Menu\Programs\Startup\360Share Pro On Startup.lnk
backup=C:\WINDOWS\pss\360Share Pro On Startup.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"PlugPlay"=2 (0x2)
"iPodService"=3 (0x3)
"EventSystem"=3 (0x3)
R0 fasttx2k;fasttx2k;C:\WINDOWS\system32\DRIVERS\fasttx2k.sys
R0 srescan;srescan;C:\WINDOWS\system32\ZoneLabs\srescan.sys
R0 uagp35;Microsoft AGPv3.5 Filter;C:\WINDOWS\system32\DRIVERS\uagp35.sys
R1 AFS2K;AFS2k;C:\WINDOWS\system32\drivers\AFS2K.sys
R2 NIOC;NIOC Service;\??\C:\WINDOWS\system32\NIOC.SYS
R2 WZCBDLService;WZCBDL Service;"C:\Program Files\WZCBDL Service\WZCBDLS.exe"
R2 X4HSX32;X4HSX32;\??\C:\Program Files\GameTap\bin\Release\X4HSX32.Sys
R3 HidUsb;Microsoft HID Class Driver;C:\WINDOWS\system32\DRIVERS\hidusb.sys
R3 NETR33X;D-Link Air Wireless Adapter(RTL) NT Driver;C:\WINDOWS\system32\DRIVERS\NETR33X.SYS
R3 smserial;smserial;C:\WINDOWS\system32\DRIVERS\smserial.sys
R3 usbccgp;Microsoft USB Generic Parent Driver;C:\WINDOWS\system32\DRIVERS\usbccgp.sys
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver;C:\WINDOWS\system32\DRIVERS\usbehci.sys
R3 usbhub;USB2 Enabled Hub;C:\WINDOWS\system32\DRIVERS\usbhub.sys
R3 USBSTOR;USB Mass Storage Driver;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver;C:\WINDOWS\system32\DRIVERS\usbuhci.sys
S0 szkg;szkg;C:\WINDOWS\system32\DRIVERS\szkg.sys
S1 NPPTNT2;NPPTNT2;\??\C:\WINDOWS\system32\npptNT2.sys
S2 RPCSE;Remote Procedure Call (RPC) MO;C:\Program Files\Intel\Intel
S3 asbp2poa;asbp2poa;\??\C:\DOCUME~1\Admin\LOCALS~1\Temp\asbp2poa.sys
S3 EagleNT;EagleNT;\??\C:\WINDOWS\system32\drivers\EagleNT.sys
S3 Fax;Fax;C:\WINDOWS\system32\fxssvc.exe
S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\fetnd5.sys
S3 FETNDISB;VIA Rhine Family Fast Ethernet Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\fetnd5b.sys
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12;C:\WINDOWS\system32\DRIVERS\HPZius12.sys
S3 npkcusb;npkcusb;\??\C:\Program Files\Lineage II\system\npkcusb.sys
S3 PcdrNdisuio;PCDRNDISUIO Usermode I/O Protocol;C:\WINDOWS\system32\DRIVERS\pcdrndisuio.sys
S3 PSSdk21;PSSdk21;\??\C:\WINDOWS\system32\Drivers\HNPsSdk.drv
S3 swanarp;swanarp;\??\C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\swanarp.sys
S3 usbaudio;USB Audio Driver (WDM);C:\WINDOWS\system32\drivers\usbaudio.sys
S3 usbprint;Microsoft USB PRINTER Class;C:\WINDOWS\system32\DRIVERS\usbprint.sys
S3 usbscan;USB Scanner Driver;C:\WINDOWS\system32\DRIVERS\usbscan.sys
S3 viagfx;viagfx;C:\WINDOWS\system32\DRIVERS\vtmini.sys
S3 XDva016;XDva016;\??\C:\WINDOWS\system32\XDva016.sys
S3 XDva019;XDva019;\??\C:\WINDOWS\system32\XDva019.sys
S3 xnacc;Microsoft Common Controller For Windows Driver Service;C:\WINDOWS\system32\DRIVERS\xnacc.sys
S3 XTrapD12;XTrapD12;\??\C:\WINDOWS\system32\XTrapD12.sys
Contents of the 'Scheduled Tasks' folder
2006-03-22 21:49:00 C:\WINDOWS\tasks\Easy Internet Sign-up.job
2007-07-27 13:37:45 C:\WINDOWS\tasks\MP Scheduled Scan.job
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-07-27 09:36:56
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-27 9:43:25 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-07-27 09:43
--- E O F ---
------
And here is another Highjackthis log (after I ran combofix).
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:47:37 AM, on 7/27/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\WZCBDL Service\WZCBDLS.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe
C:\WINDOWS\sm56hlpr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\D-Link\Air Utility\AirCFG.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\DAP\DAP.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://ie.redirect.hp.com/svs/rdr?TY...rio&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = gamefaqs.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://ie.redirect.hp.com/svs/rdr?TY...rio&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://ie.redirect.hp.com/svs/rdr?TY...rio&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about
:blank
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://ie.redirect.hp.com/svs/rdr?TY...rio&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: DAP Bar - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - C:\Program Files\DAP\DAPIEBar.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [D-Link Air Utility] C:\Program Files\D-Link\Air Utility\AirCFG.exe
O4 - HKLM\..\Run: [vxdman] WTFCTF.exe
O4 - HKLM\..\Run: [sbin] panel_its.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe" -start
O4 - HKLM\..\Run: [BlockChecker] C:\Program Files\Block Checker\block-checker.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP.EXE" /STARTUP
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [xwiz] cnftips.exe
O4 - HKCU\..\Run: [ftbar] NopeZ.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [Pop up Blocker] "C:\Program Files\Pop up Blocker\pd.exe" Minimize
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: dxva_sig.txt
O4 - Startup: Registration .LNK = C:\Program Files\Ubisoft\Tom Clancy's Splinter Cell Chaos Theory\Register\RegistrationReminder.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: &Search -
http://speedbar.myway.com/menusearch.html?p=MG1
O8 - Extra context menu item: Add To Compaq Organize... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: PD - {4D80582B-A041-4CDC-BF41-1AE8CB5E5423} - C:\Program Files\Pop up Blocker\pd.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O16 - DPF: {3C403675-B43C-410B-BF56-D4D1FB68356C} (ActiveXPortal Control) -
http://72.29.80.113/OCX/gwnet.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) -
https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsof...?1154795972937
O20 - AppInit_DLLs: arpa.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Remote Procedure Call (RPC) MO (RPCSE) - Unknown owner - C:\Program.exe (file missing)
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WZCBDL Service (WZCBDLService) - D-Link - C:\Program Files\WZCBDL Service\WZCBDLS.exe
--
End of file - 11771 bytes