And here's the ComboFix log:
ComboFix 08-04-03.3 - Roger 2008-04-03 18:15:51.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1557 [GMT -7:00]
Running from: C:\Documents and Settings\Roger\My Documents\My Completed Downloads\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BM5b393edc.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\acbeg.ini
C:\WINDOWS\system32\acbeg.ini2
C:\WINDOWS\system32\edeeg.ini
C:\WINDOWS\system32\edeeg.ini2
C:\WINDOWS\system32\hhhkj.ini
C:\WINDOWS\system32\hhhkj.ini2
C:\WINDOWS\system32\jkkijjk.dll
C:\WINDOWS\system32\nnnmp.ini
C:\WINDOWS\system32\nnnmp.ini2
C:\WINDOWS\system32\vxxochil.dll
.
((((((((((((((((((((((((( Files Created from 2008-03-04 to 2008-04-04 )))))))))))))))))))))))))))))))
.
2008-04-03 17:59 . 2008-04-03 18:06 <DIR> d-------- C:\VundoFix Backups
2008-04-02 23:49 . 2008-04-02 23:49 294 --ahs---- C:\WINDOWS\system32\ubnmqsnm.ini
2008-04-02 23:45 . 2008-04-02 23:45 91,712 --------- C:\WINDOWS\system32\rwhlnoxw.dll_old
2008-04-02 06:40 . 2008-04-02 06:40 294 --ahs---- C:\WINDOWS\system32\ehvhkuhp.ini
2008-04-02 06:37 . 2008-04-02 06:37 265,728 --a------ C:\WINDOWS\system32\pmnnn.dll_old
2008-03-28 23:33 . 2008-03-28 23:33 <DIR> d--hs---- C:\WINDOWS\ftpcache
2008-03-17 18:19 . 2008-03-17 18:19 <DIR> d-------- C:\Program Files\Mindscape
2008-03-17 09:19 . 2008-03-17 09:27 <DIR> d-------- C:\Program Files\RegCleaner
2008-03-16 08:56 . 2008-03-16 08:59 <DIR> d--h----- C:\Program Files\Zero G Registry
2008-03-16 08:56 . 2008-03-16 08:56 <DIR> d-------- C:\Program Files\Ubisoft
2008-03-16 08:56 . 2008-03-16 08:56 <DIR> d--h----- C:\Documents and Settings\Roger\InstallAnywhere
2008-03-16 07:16 . 2008-03-31 00:10 <DIR> d-------- C:\Program Files\TuneUp Utilities 2007
2008-03-14 19:09 . 2008-03-14 19:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-03-14 19:09 . 2007-03-29 04:42 29,704 --a------ C:\WINDOWS\system32\uxtuneup.dll
2008-03-14 19:05 . 2008-03-14 19:05 <DIR> d-------- C:\Documents and Settings\Roger\Application Data\Uniblue
2008-03-12 06:35 . 2008-03-12 06:36 <DIR> d-------- C:\Documents and Settings\Roger\.SunDownloadManager
2008-03-11 13:20 . 2004-08-03 23:08 26,496 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2008-03-11 12:23 . 2008-03-16 10:18 <DIR> d-------- C:\Program Files\Mozilla Firefox 3 Beta 4
2008-03-11 09:01 . 2008-03-11 09:01 <DIR> d-------- C:\Program Files\InterMute
2008-03-09 23:04 . 2008-04-03 17:53 434 --a------ C:\WINDOWS\wininit.ini
2008-03-09 22:45 . 2008-04-02 22:15 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-03-09 22:45 . 2005-08-25 18:19 115,920 --a------ C:\WINDOWS\system32\MSINET.OCX
2008-03-09 22:21 . 2008-03-09 22:21 <DIR> d-------- C:\Program Files\GoldEsel
2008-03-09 22:21 . 2008-03-09 22:21 <DIR> d-------- C:\Program Files\Ahead
2008-03-08 19:06 . 2008-03-08 19:06 <DIR> d-------- C:\Program Files\CCleaner
2008-03-08 18:56 . 2008-03-08 18:56 <DIR> d-------- C:\Documents and Settings\Roger\Application Data\SystemRequirementsLab
2008-03-04 20:49 . 2008-03-04 20:49 <DIR> d-------- C:\Program Files\Wizards of the Coast
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-04 01:17 --------- d-----w C:\Program Files\PeerGuardian2
2008-04-04 01:14 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-03 06:30 --------- d-----w C:\Documents and Settings\Roger\Application Data\Azureus
2008-04-03 06:19 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-04-03 05:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-04-01 00:21 --------- d-----w C:\Documents and Settings\Roger\Application Data\Apple Computer
2008-03-18 01:19 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-17 16:16 382 ----a-w C:\Program Files\Shortcut to Program Files.lnk
2008-03-16 14:15 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-03-15 02:15 --------- d-----w C:\Program Files\Azureus
2008-03-07 04:32 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-03-07 04:32 23,904 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-03-07 04:32 10,537 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-03-02 03:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-02 03:46 --------- d-----w C:\Program Files\Lavasoft
2008-03-02 03:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-02 03:24 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-03-01 05:31 --------- d-----w C:\Program Files\MagicDisc
2008-02-27 02:20 --------- d-----w C:\Program Files\Google
2008-02-26 20:22 --------- d-----w C:\Program Files\WinAce
2008-02-23 05:49 --------- d-----w C:\Program Files\PCPitstop
2008-02-23 04:44 --------- d-----w C:\Documents and Settings\Roger\Application Data\OfficeUpdate12
2008-02-23 04:43 --------- d-----w C:\Program Files\Snapshot Viewer
2008-02-23 03:41 --------- d-----w C:\Program Files\Common Files\Sonic Shared
2008-02-23 03:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sonic
2008-02-23 03:40 --------- d-----w C:\Program Files\Common Files\HP
2008-02-23 03:38 --------- d-----w C:\Program Files\Hewlett-Packard
2008-02-23 02:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\SBT
2008-02-23 02:03 --------- d-----w C:\Program Files\microsoft frontpage
2008-02-23 01:58 --------- d-----w C:\Documents and Settings\Roger\Application Data\Microsoft Web Folders
2008-02-23 01:25 --------- d-----w C:\Program Files\iTunes
2008-02-23 01:25 --------- d-----w C:\Program Files\iPod
2008-02-23 01:25 --------- d-----w C:\Program Files\Bonjour
2008-02-23 01:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-02-23 01:24 --------- d-----w C:\Program Files\QuickTime
2008-02-23 01:24 --------- d-----w C:\Program Files\Common Files\Apple
2008-02-23 01:24 --------- d-----w C:\Program Files\Apple Software Update
2008-02-23 01:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2008-02-22 01:22 --------- d-----w C:\Program Files\Atari
2008-02-22 01:08 --------- d-----w C:\Documents and Settings\Roger\Application Data\Ahead
2008-02-21 02:05 --------- d-----w C:\Program Files\Combined Community Codec Pack
2008-02-21 00:28 --------- d-----w C:\Program Files\MagicISO
2008-02-20 13:10 --------- d-----w C:\Program Files\MSXML 4.0
2008-02-19 21:54 --------- d-----w C:\Documents and Settings\Roger\Application Data\HP
2008-02-19 19:49 --------- d-----w C:\Program Files\Common Files\Ahead
2008-02-19 19:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ahead
2008-02-19 19:48 --------- d-----w C:\Program Files\Nero
2008-02-19 19:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
2008-02-19 19:27 --------- d-----w C:\Documents and Settings\Roger\Application Data\Grisoft
2008-02-19 19:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-19 18:58 --------- d-----w C:\Documents and Settings\Roger\Application Data\Media Player Classic
2008-02-19 18:47 --------- d-----w C:\Program Files\VideoLAN
2008-02-19 16:16 --------- d-----w C:\Program Files\DAP
2008-02-19 00:29 96,256 ----a-w C:\WINDOWS\system32\drivers\mcdbus.sys
2008-02-15 04:46 --------- d-----w C:\Documents and Settings\Roger\Application Data\TuneUp Software
2008-02-15 04:41 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-02-15 04:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\Azureus
2008-02-15 04:35 --------- d-----w C:\Program Files\Java
2008-02-15 04:34 --------- d-----w C:\Program Files\Common Files\Java
2008-02-15 04:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-02-15 04:09 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-02-15 04:09 --------- d-----w C:\Program Files\Yahoo!
2008-02-15 04:09 --------- d-----w C:\Program Files\Windows Live
2008-02-15 04:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-02-15 00:05 --------- d-----w C:\Program Files\Logitech
2008-02-15 00:05 --------- d-----w C:\Program Files\Common Files\Logitech
2008-02-15 00:04 --------- d-----w C:\Program Files\Common Files\Logishrd
2008-02-14 00:53 --------- d-----w C:\Program Files\HP
2008-02-14 00:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP
2008-02-14 00:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\LogiShrd
2008-02-14 00:12 --------- d-----w C:\Program Files\MSXML 6.0
2008-02-14 00:05 --------- d-----w C:\Program Files\MSBuild
2008-02-14 00:03 --------- d-----w C:\Program Files\Reference Assemblies
2008-02-14 00:01 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-02-12 14:08 --------- d-----w C:\Program Files\Norton 360
2008-02-12 10:03 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-02-12 10:03 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-02-12 10:03 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-02-12 10:03 --------- d-----w C:\Program Files\Symantec
2008-02-12 07:37 --------- d-----w C:\Documents and Settings\Roger\Application Data\Symantec
2008-02-12 06:41 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-12 06:32 --------- d-----w C:\Documents and Settings\Roger\Application Data\AdobeUM
2008-02-12 06:14 --------- d-----w C:\Program Files\SystemRequirementsLab
2008-02-12 05:31 --------- d-----w C:\Program Files\NVIDIA Corporation
2008-02-12 05:31 --------- d-----w C:\Program Files\Common Files\NVIDIA Shared
2008-02-12 05:31 --------- d-----w C:\Program Files\Common Files\InstallShield
2005-05-12 06:36 12,288 ----a-w C:\WINDOWS\Fonts\RandFont.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0ea8df73-ed55-4826-96da-2893539a928c}]
C:\WINDOWS\system32\rwhlnoxw.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8327BE17-3FD9-49A6-B0FC-1B9B97B93223}]
C:\WINDOWS\system32\jkhhh.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{84287134-BD27-4D64-95A3-E4CAFD38FBCA}]
C:\WINDOWS\system32\pmnnn.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8CB46795-9901-49BC-91C2-4E527BB6CADC}]
C:\WINDOWS\system32\ssttr.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-02-11 23:31 171448]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
"PeerGuardian"="C:\Program Files\PeerGuardian2\pg2.exe" [2005-09-18 18:40 1421824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVRaidService"="C:\WINDOWS\system32\nvraidservice.exe" [2004-09-02 00:25 83968]
"NVMixerTray"="C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [2004-10-07 17:53 131072]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-07-17 18:54 116072]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 01:41 8523776]
"nwiz"="nwiz.exe" [2007-12-05 01:41 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 01:41 81920]
"googletalk"="C:\Program Files\Google\Google Talk\googletalk.exe" [2007-01-01 14:22 3739648]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-17 09:50 19968 C:\WINDOWS\LOGI_MWX.EXE]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 02:25 6731312]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 15:57 153136]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 23:12 49152]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 17:38 583048]
"580a0d40"="C:\WINDOWS\system32\mnsqmnbu.dll" [ ]
"BM5b393edc"="C:\WINDOWS\system32\lkuqmyqe.dll" [ ]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-21 01:15:54 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkkijjk]
jkkijjk.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" -atboottime
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\Program Files\\DAP\\DAP.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"=
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main.exe"=
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main_amdxp.exe"=
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwupdate.exe"=
"C:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2server.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-04 05:00]
S3 FXDRV;FXDRV;D:\Fxdrv.sys []
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0c18c8ef-d8b3-11dc-8c14-806d6172696f}]
\Shell\AutoRun\command - D:\setup.exe
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-03-22 00:15:00 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
"2008-03-31 20:36:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-04-03 18:19:17
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
.
**************************************************************************
.
Completion time: 2008-04-03 18:21:30 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-04 01:21:27
Pre-Run: 57,673,150,464 bytes free
Post-Run: 57,528,811,520 bytes free
.
2008-03-12 10:01:20 --- E O F ---