will do the above; i ran combofix off the link, still have the toolbar and browser's getting hijacked. here's combofix log, i'll run vundo in the meantime. i'll be back tomorrow, gotta hit the road in a few minutes
thank you for your patience. got some to spare? lol
ComboFix 07-11-08.3 - TeeTime King 2007-11-19 15:04:54.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.49 [GMT -5:00]
Running from: C:\Documents and Settings\TeeTime King\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\TeeTime King\Desktop\Live Safety Center.lnk
C:\Documents and Settings\TeeTime King\Desktop\Online Security Guide.lnk
C:\Documents and Settings\TeeTime King\Favorites\Online Security Guide.lnk
C:\WINDOWS\system32\hnxkjdav.dllbox
.
---- Previous Run -------
.
C:\Documents and Settings\Administrator\Desktop\Live Safety Center.lnk
C:\Documents and Settings\Administrator\Desktop\Online Security Guide.lnk
C:\Documents and Settings\Administrator\Favorites\Online Security Guide.lnk
C:\Documents and Settings\All Users\Desktop\AntiSpywareBot.lnk
C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\All Users\Start Menu\Programs.\AntiSpywareBot
C:\Documents and Settings\All Users\Start Menu\Programs.\AntiSpywareBot\AntiSpywareBot on the Web.lnk
C:\Documents and Settings\All Users\Start Menu\Programs.\AntiSpywareBot\AntiSpywareBot.lnk
C:\Documents and Settings\All Users\Start Menu\Programs.\AntiSpywareBot\Uninstall AntiSpywareBot.lnk
C:\Documents and Settings\TeeTime King\Application Data\AntiSpywareBot
C:\Documents and Settings\TeeTime King\Application Data\AntiSpywareBot\DataBase.ref
C:\Documents and Settings\TeeTime King\Application Data\AntiSpywareBot\Log\2007 Nov 19 - 03_00_21 AM_327.log
C:\Documents and Settings\TeeTime King\Application Data\AntiSpywareBot\Log\2007 Nov 19 - 03_00_49 AM_358.log
C:\Documents and Settings\TeeTime King\Application Data\AntiSpywareBot\Log\2007 Nov 19 - 11_38_54 AM_953.log
C:\Documents and Settings\TeeTime King\Application Data\AntiSpywareBot\Log\2007 Nov 19 - 12_46_28 PM_028.log
C:\Documents and Settings\TeeTime King\Application Data\AntiSpywareBot\rs.dat
C:\Documents and Settings\TeeTime King\Application Data\AntiSpywareBot\Settings\CustomScan.stg
C:\Documents and Settings\TeeTime King\Application Data\AntiSpywareBot\Settings\IgnoreList.stg
C:\Documents and Settings\TeeTime King\Application Data\AntiSpywareBot\Settings\ScanInfo.stg
C:\Documents and Settings\TeeTime King\Application Data\AntiSpywareBot\Settings\ScanResults.stg
C:\Documents and Settings\TeeTime King\Application Data\AntiSpywareBot\Settings\SelectedFolders.stg
C:\Documents and Settings\TeeTime King\Application Data\AntiSpywareBot\Settings\Settings.stg
C:\Documents and Settings\TeeTime King\Desktop\Live Safety Center.lnk
C:\Documents and Settings\TeeTime King\Desktop\Online Security Guide.lnk
C:\Documents and Settings\TeeTime King\Favorites\Online Security Guide.lnk
C:\Documents and Settings\TeeTime King\g2mdlhlpx.exe
C:\Program Files\AntiSpywareBot
C:\Program Files\AntiSpywareBot\AntiSpywareBot.exe
C:\Program Files\AntiSpywareBot\AntiSpywareBot.url
C:\Program Files\AntiSpywareBot\Launcher.exe
C:\Program Files\AntiSpywareBot\unins000.dat
C:\Program Files\AntiSpywareBot\unins000.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\hnxkjdav.dllbox
C:\WINDOWS\Tasks.\AntiSpywareBot Scheduled Scan.job
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_NWSAPAGENT
-------\NwSapAgent
((((((((((((((((((((((((( Files Created from 2007-10-19 to 2007-11-19 )))))))))))))))))))))))))))))))
.
2007-11-19 13:43 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-18 16:46 689,039 ---hs---- C:\WINDOWS\SYSTEM32\fiaexuwq.ini2
2007-11-12 11:59 <DIR> d-------- C:\Program Files\Spyware Doctor
2007-11-12 11:59 <DIR> d-------- C:\Documents and Settings\TeeTime King\Application Data\PC Tools
2007-11-12 11:59 79,688 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\iksyssec.sys
2007-11-12 11:59 62,280 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\iksysflt.sys
2007-11-12 11:59 41,288 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\ikfilesec.sys
2007-11-12 11:59 29,000 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\kcom.sys
2007-11-12 11:58 626,688 --a------ C:\WINDOWS\SYSTEM32\msvcr80.dll
2007-11-12 10:54 2,040 --a------ C:\WINDOWS\SYSTEM32\tmp.reg
2007-11-12 10:53 289,144 --a------ C:\WINDOWS\SYSTEM32\VCCLSID.exe
2007-11-12 10:53 288,417 --a------ C:\WINDOWS\SYSTEM32\SrchSTS.exe
2007-11-12 10:53 53,248 --a------ C:\WINDOWS\SYSTEM32\Process.exe
2007-11-12 10:53 51,200 --a------ C:\WINDOWS\SYSTEM32\dumphive.exe
2007-11-12 10:53 25,600 --a------ C:\WINDOWS\SYSTEM32\WS2Fix.exe
2007-11-11 13:47 79,936 --a------ C:\WINDOWS\SYSTEM32\mkidovjq.dll
2007-11-11 13:43 88,128 --a------ C:\WINDOWS\SYSTEM32\qwuxeaif.dll
2007-11-11 13:41 71,232 --a------ C:\WINDOWS\SYSTEM32\augoonwa.exe
2007-11-11 13:19 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-11-11 13:19 <DIR> d-------- C:\Documents and Settings\TeeTime King\Application Data\SUPERAntiSpyware.com
2007-11-11 13:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-11-11 13:18 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-11-10 15:36 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
2007-11-10 14:10 <DIR> d-------- C:\Program Files\SpyNoMore
2007-11-10 14:10 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2007-11-10 13:42 271,224 --a------ C:\WINDOWS\SYSTEM32\mucltui.dll
2007-11-10 13:42 207,736 --a------ C:\WINDOWS\SYSTEM32\muweb.dll
2007-11-10 03:00 22,752 --a------ C:\WINDOWS\SYSTEM32\spupdsvc.exe
2007-11-10 02:45 81,472 --a------ C:\WINDOWS\SYSTEM32\fftcsmly.dll
2007-11-10 02:44 71,232 --a------ C:\WINDOWS\SYSTEM32\juowiyal.exe
2007-11-09 16:57 112,840 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\msfwhlpr.sys
2007-11-09 16:57 88,008 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\msfwdrv.sys
2007-11-09 16:54 <DIR> d----c--- C:\WINDOWS\SYSTEM32\DRVSTORE
2007-11-09 16:54 67,784 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\MpFilter.sys
2007-11-09 16:52 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-11-09 16:21 <DIR> d-------- C:\Program Files\Microsoft Windows OneCare Live
2007-11-09 14:23 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2007-11-08 14:44 86,080 --a------ C:\WINDOWS\SYSTEM32\cmgnfvgq.dll
2007-11-08 14:44 80,448 --a------ C:\WINDOWS\SYSTEM32\rktbcakt.dll
2007-11-08 14:43 71,232 --a------ C:\WINDOWS\SYSTEM32\cluglbcc.exe
2007-11-07 14:47 79,936 --a------ C:\WINDOWS\SYSTEM32\nedorywe.dll
2007-11-07 14:45 145,984 --a------ C:\WINDOWS\SYSTEM32\hnxkjdav.dll
2007-11-07 14:45 71,232 --a------ C:\WINDOWS\SYSTEM32\svgatmef.exe
2007-11-07 14:44 145,984 --a------ C:\WINDOWS\SYSTEM32\fjpaurvl.dll
2007-11-06 13:51 2,560 --a------ C:\WINDOWS\trest.exe
2007-11-06 13:51 2,560 --a------ C:\syszzgi.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-09 19:26 --------- d-----w C:\Program Files\e-Range
2007-11-06 19:03 --------- d-----w C:\Documents and Settings\TeeTime King\Application Data\AdobeUM
2007-10-14 14:47 --------- d-----w C:\Program Files\The Print Shop 20
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
2007-11-07 14:45 145984 --a------ C:\WINDOWS\system32\hnxkjdav.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e8386141-2674-4e98-a9fd-b11550a9adc1}]
2007-11-11 13:47 79936 --a------ C:\WINDOWS\system32\mkidovjq.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\hnxkjdav.dll [2007-11-07 14:45 145984]
[HKEY_CLASSES_ROOT\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 16:42]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-08-20 16:55]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-08-20 16:51]
"OSCD_Creator"="c:\Dell\PreODM.EXE" [2004-10-31 06:21]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 12:03]
"IntelMeM"="C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 21:12]
"mmtask"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe" [2004-09-14 09:50]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2005-02-24 18:49]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-02-24 18:50]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 07:38]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 01:41]
"OneCareUI"="C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe" [2007-10-01 09:53]
"2439119d"="C:\WINDOWS\system32\qwuxeaif.dll" [2007-11-11 13:43]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-08-04 02:06]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]
"OSCD_Creator"=C:\Dell\PreODM.EXE /2
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06]
America Online 9.0 Tray Icon.lnk - C:\Program Files\America Online 9.0\aoltray.exe [2005-02-24 18:48:32]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 03:21:22]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gebxuvu]
gebxuvu.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\hnxkjdav]
hnxkjdav.dll 2007-11-07 14:45 145984 C:\WINDOWS\SYSTEM32\hnxkjdav.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\OneCareMP]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"
R1 MSFWHLPR;MSFWHLPR;C:\WINDOWS\system32\DRIVERS\msfwhlpr.sys
R2 MSFWDrv;MSFWDrv;C:\WINDOWS\system32\DRIVERS\msfwdrv.sys
R2 msfwsvc;OneCare Firewall;"C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe"
R2 OneCareMP;OneCare AntiSpyware and AntiVirus;"C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe"
R3 DS2490;DS2490 (USB Host for 1-Wire Network);C:\WINDOWS\system32\Drivers\DS2490.sys
R3 EloBus;Elobus Filter Driver;C:\WINDOWS\system32\DRIVERS\EloBus.sys
R3 EloSer;Elo Serial Driver;C:\WINDOWS\system32\DRIVERS\EloSer.sys
R3 MpFilter;Microsoft Malware Protection Driver;C:\WINDOWS\system32\DRIVERS\MpFilter.sys
.
Contents of the 'Scheduled Tasks' folder
"2007-11-16 23:30:05 C:\WINDOWS\Tasks\McAfee.com Scan for Viruses - My Computer (1) (2T_PROSHOP-TeeTime King).job"
.
**************************************************************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-19 15:11:53
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
OSCD_Creator = C:\Dell\PreODM.EXE /2??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-19 15:18:17 - machine was rebooted
.
--- E O F ---