[quote name=\'guestolo\' post=\'452967\' date=\'Dec 26 2008, 03:40 AM\']Download ComboFix from one of these locations:
[color=\"#0000ff\"]Link 1[/color][color=\"#0000ff\"]Link 2[/color][color=\"#0000ff\"]Link 3[/color][color=\"#ff0000\"]
Save it ONLY to your Desktop[/color]
--------------------------------------------------------------------
[color=\"#2e8b57\"]Temporarily Disable your AntiVirus, AntiSpyware and Firewall applications, usually via a right click on the System Tray icon. They may otherwise interfere with this tool[/color]
- Double click on ComboFix.exe & follow the prompts.
- As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
- Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
[color=\"#2e8b57\"]**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
[/color]
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the
C:\ComboFix.txt in your next reply
NOTE: Do not mouseclick inside ComboFix window as it's running, it may cause it to stall
ComboFix will run again on startup, it will prompt that it's creating a log
This process could take up to 10 minutes, let it run uninterrupted please[/quote]
**************Symantec did not pop up last night blocking anything. Not sure if that means anything, but just fyi********************************
ComboFix 08-12-25.04 - Owner 2008-12-26 11:47:15.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.504.220 [GMT -5:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\iAlmcoin.dll
c:\windows\system32\ilituwoh.ini
c:\windows\system32\oleperas.ini
c:\windows\system32\yapadoyi.exe
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-11-26 to 2008-12-26 )))))))))))))))))))))))))))))))
.
2008-12-25 21:40 . 2008-12-25 21:40 <DIR> d-------- c:\program files\Trend Micro
2008-12-25 14:52 . 2008-04-13 20:12 159,232 --a------ c:\windows\system32\ptpusd.dll
2008-12-25 14:52 . 2001-08-17 22:36 5,632 --a------ c:\windows\system32\ptpusb.dll
2008-12-23 19:25 . 2006-09-18 17:55 109,744 --a------ c:\windows\system32\drivers\SYMEVENT.SYS
2008-12-23 19:25 . 2006-09-18 17:55 48,816 --a------ c:\windows\system32\S32EVNT1.DLL
2008-12-23 19:24 . 2008-12-25 14:09 <DIR> d-------- c:\program files\Symantec AntiVirus
2008-12-23 19:24 . 2008-12-23 19:25 <DIR> d-------- c:\program files\Symantec
2008-12-23 18:12 . 2008-12-23 18:12 0 --a------ c:\windows\vpc32.INI
2008-12-23 10:35 . 2008-12-23 10:35 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-12-23 10:35 . 2008-12-23 10:35 <DIR> d-------- c:\documents and settings\Owner\Application Data\Malwarebytes
2008-12-23 10:35 . 2008-12-23 10:35 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-23 10:35 . 2008-12-03 19:54 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-23 10:35 . 2008-12-03 19:54 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-01 19:25 . 2008-12-01 19:25 <DIR> d-------- c:\windows\Cache
2008-12-01 19:25 . 2006-11-01 15:52 765,952 --a------ c:\windows\system32\xvidcore.dll
2008-12-01 19:25 . 2006-11-01 15:54 180,224 --a------ c:\windows\system32\xvidvfw.dll
2008-12-01 19:25 . 2006-11-01 16:26 77,824 --a------ c:\windows\system32\xvid.ax
2008-12-01 19:25 . 2004-03-09 11:39 8,704 --a------ c:\windows\system32\vidccleaner.exe
2008-12-01 19:24 . 2008-12-01 19:24 <DIR> d-------- c:\program files\Samsung
2008-12-01 19:24 . 1998-07-09 20:41 217,088 --a------ c:\windows\system32\skjpeg40.dll
2008-12-01 19:24 . 1998-03-04 11:40 83,968 --a------ c:\windows\system32\Skbase40.dll
2008-12-01 19:23 . 2008-12-01 19:23 <DIR> d-------- c:\documents and settings\Owner\Application Data\InstallShield
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-25 18:05 --------- d-----w c:\documents and settings\Owner\Application Data\Apple Computer
2008-12-24 00:26 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-12-24 00:24 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2008-12-24 00:04 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-23 23:27 --------- d-----w c:\documents and settings\All Users\Application Data\Memo save stupid creative
2008-12-23 18:21 --------- d-----w c:\program files\Microsoft SQL Server
2008-11-18 20:44 --------- d-----w c:\program files\iTunes
2008-11-18 20:44 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-18 20:43 --------- d-----w c:\program files\iPod
2008-11-18 20:43 --------- d-----w c:\program files\Apple Software Update
2008-11-18 20:41 --------- d-----w c:\program files\Common Files\Apple
2008-11-09 03:09 --------- d-----w c:\documents and settings\Owner\Application Data\Image Zone Express
2008-11-09 03:07 --------- d-----w c:\documents and settings\Owner\Application Data\Printer Info Cache
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 20:38 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-16 19:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 19:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-03 10:02 247,326 ----a-w c:\windows\system32\strmdll.dll
2008-09-30 21:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-08-01 17:09 23 ----a-w c:\documents and settings\Owner\jagex_runescape_preferences.dat
2008-12-19 02:27 67,688 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2008-12-19 02:27 54,368 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-12-19 02:27 34,944 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2008-12-19 02:27 46,712 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-12-19 02:27 172,136 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
2003-12-27 19:12 0 --sha-w c:\windows\SMINST\HPCD.sys
2008-09-21 00:47 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008092020080921\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BackupNotify"="c:\program files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exe" [2003-06-22 24576]
"RealPlayer"="c:\program files\Real\RealOne Player\realplay.exe" [2006-07-02 1003520]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"NVIEW"="nview.dll" [2003-05-03 c:\windows\system32\nview.dll]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-08-20 118784]
"CamMonitor"="c:\program files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe" [2002-10-07 90112]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"HPHUPD05"="c:\program files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [2003-05-23 49152]
"HPHmon05"="c:\windows\System32\hphmon05.exe" [2003-05-23 483328]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2003-08-23 151597]
"AutoTKit"="c:\hp\bin\AUTOTKIT.EXE" [2003-06-18 53248]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-13 212992]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2003-05-03 4640768]
"mmtask"="c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe" [2003-02-24 53248]
"QuickFinder Scheduler"="c:\program files\WordPerfect Office 11\Programs\QFSCHD110.EXE" [2003-03-07 77887]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-08-20 155648]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2005-03-23 217088]
"ezShieldProtector for Px"="c:\windows\system32\ezSP_Px.exe" [2002-08-20 40960]
"ddoctorv2"="c:\program files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2008-04-24 202560]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-11-07 111936]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-07-19 52896]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-10-24 125120]
"nwiz"="nwiz.exe" [2003-05-03 c:\windows\system32\nwiz.exe]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 c:\windows\ALCXMNTR.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ALUAlert"="c:\program files\Symantec\LiveUpdate\ALUNotify.exe" [2006-08-25 100032]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina]
2003-02-21 05:50 40960 c:\program files\Softex\OmniPass\OPXPGina.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\Apple\\Mobile Device Support\\bin\\AppleMobileDeviceService.exe"=
"c:\\WINDOWS\\system32\\WgaTray.exe"=
"c:\\WINDOWS\\system32\\userinit.exe"=
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-12-23 99376]
S3 pohci13F;pohci13F;\??\c:\docume~1\Owner\LOCALS~1\Temp\pohci13F.sys []
S3 SavRoam;SAVRoam;"c:\program files\Symantec AntiVirus\SavRoam.exe" [2006-10-24 116416]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b51da3c8-84a1-11db-9bc2-000ea61348ea}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
2008-12-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2004-02-16 c:\windows\Tasks\Easy Internet Sign-up.job
- c:\program files\Easy Internet signup\HPSdpApp.exe []
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-msnmsgr - c:\program files\MSN Messenger\msnmsgr.exe
HKLM-Run-Piolet - c:\progra~1\Piolet\Piolet.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uDefault_Search_URL = hxxp://srch-us9.hpwis.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mWindow Title = Windows Internet Explorer provided by Comcast
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = localhost
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
IE: &Search - ?p=ZRfox000(3)
O16 -: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd
O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
c:\windows\Downloaded Program Files\tgctlsi.dll - c:\windows\Downloaded Program Files\sprtexternal.dll
O16 -: {42D06124-98A2-47EC-8098-3778B58CE7D5}
hxxps://actsvr.comcastonline.com/techtools/dl/Comcast%20Activation%20Controls.cab
c:\windows\Downloaded Program Files\sprtexternal.inf
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\xfcvsxko.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/?.home=ytff
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-12-26 11:58:26
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(516)
c:\program files\Softex\OmniPass\opxpgina.dll
.
Completion time: 2008-12-26 12:02:53
ComboFix-quarantined-files.txt 2008-12-26 17:01:32
Pre-Run: 42,604,265,472 bytes free
Post-Run: 48,887,169,024 bytes free
196 --- E O F --- 2008-12-24 00:09:41