I don't think that did much, but heres the new HJT log. Also, Ive found two places where the virus keeps resetting registry entries:-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\system]
HJT Log:-
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:54:21 AM, on 10/10/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
F:\Program Files\iTunes\iTunesHelper.exe
F:\Program Files\Pinnacle\Pinnacle PCTV\Remote\Remoterm.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\GM4IE\gm4ie.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\regedit.exe
E:\games\Audacity\Call of Duty\HiJackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IEPro\iepro.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: IE to GetRight Helper - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - E:\Program Files\GetRight\xx2gr.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [PCTVRemote] F:\Program Files\Pinnacle\Pinnacle PCTV\Remote\Remoterm.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [GM4IE] C:\Program Files\GM4IE\gm4ie.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: Download with GetRight - E:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Browser - E:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll (file missing)
O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dll (file missing)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=67633
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) -
http://www.srtest.com/srl_bin/sysreqlab3.cab
O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) -
http://www.windowsvistatestdrive.com...veXClient1.cab
O16 - DPF: {C49134CC-B5EF-458C-A442-E8DFE7B4645F} (YYGInstantPlay Control) -
http://www.yoyogames.com/downloads/activex/YoYo.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Password Validation (ccPwdSvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (file missing)
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Unknown owner - C:\Program Files\Symantec AntiVirus\DefWatch.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - g:\backup\c\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - g:\backup\c\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
--
End of file - 7994 bytes
Oh, and the Combofix log
ComboFix 08-10-06.05 - user 2008-10-10 11:39:24.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.436 [GMT 5.5:30]
Running from: G:\backup\c\Program Files\Mozilla\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\user\Application Data\rbap550.dll
C:\WINDOWS\system32\dao350.dll
C:\WINDOWS\system32\h@tkeysh@@k.dll
C:\WINDOWS\system32\x64
.
((((((((((((((((((((((((( Files Created from 2008-09-10 to 2008-10-10 )))))))))))))))))))))))))))))))
.
2009-03-15 16:27 . 2008-10-10 11:31 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2009-02-07 11:17 . 2009-02-07 11:17 <DIR> d----c--- C:\Program Files\Alcohol Soft
2008-10-10 09:49 . 2008-10-10 09:49 685,056 --a------ C:\WINDOWS\isRS-000.tmp
2008-10-05 11:32 . 2008-10-05 11:46 21,004 --ah-c--- C:\TEMP_BDT.CHA
2008-10-05 10:00 . 2008-10-05 10:00 86,528 --a------ C:\WINDOWS\bnetunin.exe
2008-10-04 20:57 . 2008-10-04 20:57 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-10-04 20:57 . 2008-10-04 20:57 <DIR> d-------- C:\Documents and Settings\user\Application Data\SUPERAntiSpyware.com
2008-10-04 20:57 . 2008-10-04 20:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-10-04 20:41 . 2008-10-04 20:41 <DIR> d-------- C:\Documents and Settings\user\Application Data\PC Tools
2008-10-04 20:41 . 2008-08-25 11:36 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-10-04 20:41 . 2008-08-25 11:36 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-10-04 20:41 . 2008-08-25 11:36 40,840 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-10-04 20:41 . 2008-06-02 15:19 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-10-04 17:51 . 2008-10-04 18:18 <DIR> d-------- C:\Program Files\Unlocker
2008-10-04 17:26 . 2008-10-06 18:50 2,852 --a------ C:\WINDOWS\system32\tmp.reg
2008-10-04 16:48 . 2008-10-04 17:35 <DIR> d--h-c--- C:\SDFix
2008-10-04 14:57 . 2008-10-04 18:19 <DIR> d--h----- C:\Program Files\sb
2008-10-03 17:12 . 2008-03-15 14:23 <DIR> d----c--- C:\Documents and Settings\Administrator.USER-08E83726E4\Application Data\Apple Computer
2008-10-03 17:12 . 2008-10-03 17:12 <DIR> d----c--- C:\Documents and Settings\Administrator.USER-08E83726E4
2008-10-03 16:24 . 2008-10-03 17:12 <DIR> d----c--- C:\Documents and Settings\TEMP
2008-10-03 15:50 . 2008-10-03 15:51 <DIR> d-------- C:\Documents and Settings\user\Application Data\dxdlls
2008-10-02 20:14 . 2008-10-02 20:14 <DIR> d-------- C:\Documents and Settings\user\Application Data\gtk-2.0
2008-10-01 21:35 . 2008-10-01 21:35 <DIR> d-------- C:\Documents and Settings\user\Application Data\Xfire Plus
2008-09-28 17:18 . 2008-09-28 17:18 0 --a------ C:\WINDOWS\wt9_1sptlEN.INI
2008-09-25 13:59 . 2008-09-25 14:00 <DIR> d--h-c--- C:\gs
2008-09-25 13:38 . 2008-09-25 13:38 <DIR> d-------- C:\Documents and Settings\user\Application Data\Ironclad Games
2008-09-18 21:17 . 1999-09-11 02:20 25,600 --a------ C:\WINDOWS\system\
007.DLL
2008-09-18 21:17 . 1999-09-11 02:20 9,504 --a------ C:\WINDOWS\system\
006.DLL
2008-09-18 21:06 . 2008-09-18 21:06 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-09-18 21:06 . 2008-09-18 21:06 <DIR> d-------- C:\WINDOWS\system32\en
2008-09-18 21:06 . 2008-09-18 21:06 <DIR> d-------- C:\WINDOWS\system32\bits
2008-09-18 21:06 . 2008-09-18 21:06 <DIR> d-------- C:\WINDOWS\l2schemas
2008-09-18 21:03 . 2008-09-18 21:06 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-09-18 09:11 . 2008-04-14 05:42 1,737,856 --a------ C:\WINDOWS\system32\mtxparhd.dll
2008-09-18 09:10 . 2008-04-14 05:41 1,888,992 --a------ C:\WINDOWS\system32\ati3duag.dll
2008-09-18 06:11 . 2008-09-18 06:11 42,320 --a------ C:\WINDOWS\system32\xfcodec.dll
2008-09-11 10:44 . 2008-09-12 15:34 <DIR> d-------- C:\Documents and Settings\user\Application Data\MiniDm
2008-09-11 10:43 . 2008-09-11 11:00 <DIR> d-------- C:\Documents and Settings\user\Application Data\IEPro
2008-09-11 10:40 . 2008-09-11 10:42 <DIR> d----c--- C:\Program Files\GM4IE
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-10 05:15 --------- dc----w C:\Program Files\Symantec
2008-10-07 11:59 --------- d-----w C:\Documents and Settings\user\Application Data\Xfire
2008-10-06 07:23 --------- dc----w C:\Program Files\Symantec AntiVirus2
2008-10-05 03:57 361,600 ----a-w C:\WINDOWS\system32\drivers\TCPIP.SYS
2008-10-04 15:27 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-10-04 12:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-03 12:06 --------- dc----w C:\Program Files\QuickTime
2008-10-02 14:44 --------- d-----w C:\Documents and Settings\user\Application Data\.gaim
2008-09-29 10:19 --------- d-----w C:\Documents and Settings\user\Application Data\LimeWire
2008-09-28 11:43 --------- d-----w C:\Documents and Settings\user\Application Data\MSNInstaller
2008-09-15 15:34 --------- d-----w C:\Documents and Settings\user\Application Data\GetRightToGo
2008-09-10 10:19 --------- dc----w C:\Program Files\Java
2008-09-01 10:35 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-01 05:32 --------- d-----w C:\Documents and Settings\user\Application Data\Games
2008-09-01 05:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\InstallShield
2008-09-01 05:23 278,984 ----a-w C:\WINDOWS\system32\drivers\atksgt.sys
2008-09-01 05:23 25,416 ----a-w C:\WINDOWS\system32\drivers\lirsgt.sys
2008-09-01 05:18 --------- dc--a-w C:\Program Files\Common Files\InstallShield
2008-09-01 04:45 --------- dc----w C:\Program Files\MSXML 6.0
2008-08-30 13:17 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-08-13 10:41 --------- dc----w C:\Program Files\Common Files\GTK
2008-07-30 12:25 69,409 ----a-w C:\WINDOWS\system32\uninst.exe
2008-07-23 06:49 32,768 ----a-w C:\WINDOWS\system32\asteriskie.exe
2008-07-23 06:48 397,379 ----a-w C:\WINDOWS\system32\paqbonus.exe
2008-07-23 06:48 311,296 ----a-w C:\WINDOWS\system32\winping.exe
2008-07-21 12:12 184,320 ----a-w C:\WINDOWS\freeze.exe
2008-07-18 18:34 664,064 ----a-w C:\WINDOWS\WLXPGSS.SCR
2008-07-18 16:40 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 16:40 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 16:40 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 16:40 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 16:39 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 16:39 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 16:39 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 16:39 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 16:37 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-18 16:37 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-01-30 10:43 88 --sha-r C:\WINDOWS\system32\20953AAD62.sys
2008-03-06 06:54 2,516 -csha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
------- Sigcheck -------
2007-10-30 22:23 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2008-06-20 16:14 360960 744e57c99232201ae98c49168b918f48 C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys
2008-06-20 17:21 361600 9aefa14bd6b182d61e3119fa5f436d3d C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys
2008-06-20 17:29 361600 ad978a1b783b5719720cff204b666c8e C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
2008-06-20 16:15 360320 2a5554fc5b1e04e131230e3ce035c3f9 C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
2004-08-04 02:44 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
2008-04-14 00:50 361344 93ea8d04ec73a85db02eb8805988f733 C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
2007-10-30 22:50 360064 90caff4b094573449a0872a0f919b178 C:\WINDOWS\$NtUninstallKB951748_0$\tcpip.sys
2008-04-14 00:50 361344 93ea8d04ec73a85db02eb8805988f733 C:\WINDOWS\ServicePackFiles\i386\TCPIP.SYS
2008-10-05 09:27 361600 d24ea301e2b36c4e975fd216ca85d8e7 C:\WINDOWS\system32\dllcache\TCPIP.SYS
2008-10-05 09:27 361600 d24ea301e2b36c4e975fd216ca85d8e7 C:\WINDOWS\system32\drivers\TCPIP.SYS
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-02-05 241080]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"GM4IE"="C:\Program Files\GM4IE\gm4ie.exe" [2006-07-23 139264]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2005-04-17 85184]
"itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [2006-11-22 813912]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2007-02-06 849280]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 218512]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-31 458752]
"iTunesHelper"="F:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 267048]
"PCTVRemote"="F:\Program Files\Pinnacle\Pinnacle PCTV\Remote\Remoterm.exe" [2002-01-28 139264]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2008-02-15 204800]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2008-02-15 208896]
"SkyTel"="SkyTel.EXE" [2006-05-15 C:\WINDOWS\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [2006-12-17 C:\WINDOWS\RTHDCPL.EXE]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-01-28 195584]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
"DisableRegistryTools"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\Shell ExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-07-23 16:28 352256 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.yv12"= yv12vfw.dll
"VIDC.XFR1"= xfcodec.dll
[HKLM\~\startupfolder\C:^Documents and Settings^user^Start Menu^Programs^Startup^LimeWire Turbo Accelerator.lnk]
path=C:\Documents and Settings\user\Start Menu\Programs\Startup\LimeWire Turbo Accelerator.lnk
backup=C:\WINDOWS\pss\LimeWire Turbo Accelerator.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
--a------ 2008-02-15 12:46 237568 C:\WINDOWS\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 225280 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"C-DillaCdaC11BA"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Auth orizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"E:\\My Web\\new\\3dsmax.exe"=
"G:\\backup\\d\\Adobe Photoshop 7.0\\Presets\\Patterns\\PostScript Patterns\\Aphex.exe"=
"E:\\Program Files\\Wyzo\\wyzo.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\WINDOWS\\system32\\dplaysvr.exe"=
"E:\\My Second Web\\_private\\LimeWire\\LimeWire.exe"=
"G:\\backup\\d\\Adobe PageMaker 7.0\\Images\\ua\\game\\bakup\\urbanassault\\Ua.exe"=
"E:\\gmax\\downloads\\cc2\\closecombat2\\Cc2.exe"=
"E:\\Program Files\\GetRight\\GetRight.exe"=
"G:\\backup\\c\\Program Files\\byo\\bin\\byond.exe"=
"G:\\backup\\c\\Program Files\\byo\\bin\\dreamseeker.exe"=
"E:\\Program Files\\Xfire\\xfire.exe"=
"E:\\games\\Audacity\\Call of Duty\\CoDMP.exe"=
"E:\\games\\Audacity\\Call of Duty\\CoDMPw0rt.exe"=
"E:\\games\\thunder\\thunbrigade\\thunbrig\\Tbrigade.exe"=
"G:\\backup\\c\\Program Files\\Freespace\\Freespace\\FS2.exe"=
"G:\\backup\\c\\Program Files\\Freespace\\Freespace\\incoming\\incoming\\incoming.exe"=
"F:\\Program Files\\iTunes\\iTunes.exe"=
"G:\\backup\\c\\Program Files\\Freespace\\Freespace\\fs2_open_3_6_9.exe"=
"G:\\backup\\c\\Program Files\\Freespace\\Freespace\\fs2_open_3_6_9_debug.exe"=
"G:\\backup\\c\\Program Files\\Freespace\\Freespace\\fs2_open_3_6_10_debug-20071007T.exe"=
"G:\\backup\\c\\Program Files\\byo\\bin\\dreamdaemon.exe"=
"G:\\backup\\c\\Program Files\\wwp\\Worms World Party\\Worms World Party.exe"=
"G:\\backup\\c\\Program Files\\Freespace\\Freespace\\fs2_open_3_6_10-20071007T.exe"=
"G:\\backup\\d\\Corel11\\sse\\Stardock Games\\Sins of a Solar Empire\\Sins of a Solar Empire.exe"=
"C:\\Program Files\\backburner 2\\manager.exe"=
"E:\\My Second Web\\_private\\LimeWire\\dls\\gta.sa\\GTA San Andreas\\samp022server.win32\\samp-server.exe"=
"E:\\My Second Web\\_private\\LimeWire\\dls\\gta.sa\\GTA San Andreas\\samp022server.win32\\SA-MP SERVER\\samp-server.exe"=
"G:\\Program Files\\Microsoft Games\\Halo Custom Edition\\haloce.exe"=
"E:\\games\\kmd.exe"=
"E:\\My Second Web\\_private\\LimeWire\\dls\\w3\\Warcraft III.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\WINDOWS\\system32\\igfxtray.exe"=
"C:\\WINDOWS\\system32\\userinit.exe"=
"C:\\WINDOWS\\system32\\hkcmd.exe"=
"C:\\WINDOWS\\system32\\NeroCheck.exe"=
"C:\\WINDOWS\\ALCMTR.EXE"=
"C:\\Program Files\\QuickTime\\qttask.exe"=
"C:\\Program Files\\Common Files\\Adobe\\Calibration\\Adobe Gamma Loader.exe"=
"C:\\WINDOWS\\RTHDCPL.EXE"=
"C:\\Program Files\\Java\\jre1.6.0_07\\bin\\jusched.exe"=
"e:\\my second web\\_private\\limewire\\dls\\w3\\worldedit.exe"=
"F:\\Program Files\\Pinnacle\\Pinnacle PCTV\\Remote\\Remoterm.exe"=
"C:\\WINDOWS\\system32\\taskmgr.exe"=
"C:\\WINDOWS\\system32\\igfxsrvc.exe"=
"g:\\backup\\c\\Program Files\\Spyware Doctor\\pctsTray.exe"= G:\\backup\\c\\Program Files\\Spyware Doctor\\pctsTray.exe
"C:\\WINDOWS\\system32\\igfxpers.exe"=
"C:\\WINDOWS\\system32\\netsh.exe"=
"C:\\Program Files\\GM4IE\\gm4ie.exe"=
"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe"=
"C:\\Program Files\\Common Files\\Apple\\Mobile Device Support\\bin\\OutlookSyncClient.exe"=
R3 AtcL002;NDIS Miniport Driver for Atheros L2 Fast Ethernet Controller;C:\WINDOWS\system32\DRIVERS\l251x86.sys [2008-04-17 30720]
R3 dac970nt;dac970nt;C:\WINDOWS\system32\drivers\rnnrl.sys [ ]
R3 pctvvbi;PCTVVBI;C:\WINDOWS\system32\DRIVERS\pctvvbi.sys [2002-04-02 6369]
S3 ASPI;Advanced SCSI Programming Interface Driver;C:\WINDOWS\System32\DRIVERS\ASPI32.sys [2002-07-17 16512]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\{27b7ea02-1b36-11dd-a576-001bfc1861eb}]
\Shell\AutoRun\command - jfvkcsy.bat
\Shell\explore\Command - jfvkcsy.bat
\Shell\open\Command - jfvkcsy.bat
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
2008-03-07 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{DA30EFF8-CCC6-4162-A20D-67402A26A215} - (no file)
HKCU-Run-WMPNSCFG - C:\Program Files\Windows Media Player\WMPNSCFG.exe
HKLM-Run-ccApp - C:\Program Files\Common Files\Symantec Shared\ccApp.exe
HKLM-Run-UnlockerAssistant - C:\Program Files\Unlocker\UnlockerAssistant.exe
MSConfigStartUp-c0 - C:\aidualc3\c0.exe
MSConfigStartUp-LimeWire Turbo Accelerator - E:\My Second Web\_private\LimeWire\turbo\LimeWire Turbo Accelerator.exe
MSConfigStartUp-TkBellExe - realsched.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\s549718h.default\
FF -: plugin - C:\Program Files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - E:\Program Files\Real\RealOne Player\v2\Netscape6\nppl3260.dll
FF -: plugin - E:\Program Files\Real\RealOne Player\v2\Netscape6\nprjplug.dll
FF -: plugin - E:\Program Files\Real\RealOne Player\v2\Netscape6\nprpjplug.dll
FF -: plugin - F:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - G:\backup\c\Program Files\Mozilla\plugins\NPGetRt.dll
FF -: plugin - G:\backup\c\Program Files\Mozilla\plugins\npnul32.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-10-10 11:41:20
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-10-10 11:44:17
ComboFix-quarantined-files.txt 2008-10-10 06:13:56
Pre-Run: 10,975,522,816 bytes free
Post-Run: 10,957,713,408 bytes free
275 --- E O F --- 2008-09-20 02:52:32