i have now run the combofix aswell as this seems to be the next step. here is the log. If anyone can help me I would much appreciate it.combofix log
ComboFix 08-02-13.1 - teddy 2008-02-12 21:47:00.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.139 [GMT 0:00]
Running from: C:\Documents and Settings\user1\Desktop\ComboFix.exe
* Created a new restore point
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\mljgf.dll
C:\WINDOWS\system32\rqrrqol.dll
C:\Documents and Settings\All Users\Application Data\storageprotector
C:\Documents and Settings\All Users\Application Data\storageprotector\Data\ac
C:\Documents and Settings\All Users\Application Data\storageprotector\Data\em
C:\Documents and Settings\All Users\Application Data\storageprotector\Data\oid
C:\Documents and Settings\All Users\Application Data\storageprotector\Data\user
C:\Program Files\Common Files\Yazzle1281OinAdmin.exe
C:\Program Files\Common Files\Yazzle1281OinUninstaller.exe
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\isgTi19
C:\Temp\isgTi19\lPig.log
C:\WINDOWS\cookies.ini
C:\WINDOWS\mrofinu1000106.exe
C:\WINDOWS\mrofinu572.exe
C:\WINDOWS\pack.epk
C:\WINDOWS\system32\byxwvus.dll
C:\WINDOWS\system32\dpyeogkf.dll
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\eidgpqvr.ini
C:\WINDOWS\system32\fgjlm.ini
C:\WINDOWS\system32\fgjlm.ini2
c:\WINDOWS\system32\ikecmmi.dat
C:\WINDOWS\system32\ikecmmi.exe
c:\WINDOWS\system32\ikecmmi_nav.dat
c:\WINDOWS\system32\ikecmmi_navps.dat
C:\WINDOWS\system32\ljntihwjrq_navtmp.dat
C:\WINDOWS\system32\loaxoinv.ini
C:\WINDOWS\system32\luajvxyk.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mljgf.dll
C:\WINDOWS\system32\nGpxx01
C:\WINDOWS\system32\nGpxx01\nGpxx011065.exe
C:\WINDOWS\system32\nvs2.inf
C:\WINDOWS\system32\nwfoahaz.dll . . . . failed to delete
C:\WINDOWS\system32\nwfoahaz.dllbox
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\Packet.dll
C:\WINDOWS\system32\pthreadVC.dll
C:\WINDOWS\system32\raaodjmu.dll
C:\WINDOWS\system32\rmpjmamh.dll
C:\WINDOWS\system32\rqrrqol.dll
C:\WINDOWS\system32\u1
C:\WINDOWS\system32\u1\hiba3133.exe
C:\WINDOWS\system32\umcfrjim.dll
C:\WINDOWS\system32\umjdoaar.ini
C:\WINDOWS\system32\vturrro.dll
C:\WINDOWS\system32\WanPacket.dll
C:\WINDOWS\system32\windows
C:\WINDOWS\system32\wpcap.dll
C:\WINDOWS\system32\x8
C:\WINDOWS\system32\x8\liopud89104.exe
C:\WINDOWS\system32\ymrejsqj.dll
C:\WINDOWS\system32\yybeg.ini2
C:\WINDOWS\system32\z2
C:\WINDOWS\system32\nwfoahaz.dll . . . . failed to delete
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_NPF
-------\NPF
((((((((((((((((((((((((( Files Created from 2008-01-13 to 2008-02-13 )))))))))))))))))))))))))))))))
.
2008-02-13 22:11 . 2008-02-13 22:15 19,054 ---hs---- C:\WINDOWS\system32\nwfoahaz.dllbox
2008-02-13 22:11 . 2008-02-13 22:12 9,033 --a------ C:\pos4.tmp
2008-02-13 22:11 . 2008-02-13 22:12 7,033 --a------ C:\pos3.tmp
2008-02-13 22:11 . 2008-02-13 22:12 7,033 --a------ C:\pos2.tmp
2008-02-13 22:11 . 2008-02-13 22:12 5,033 --a------ C:\pos5.tmp
2008-02-12 19:33 . 2008-02-13 22:01 163,904 --a------ C:\WINDOWS\system32\nwfoahaz.dll
2008-02-12 18:28 . 2008-02-12 18:28 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-12 16:22 . 2008-02-12 19:21 <DIR> d-------- C:\VundoFix Backups
2008-02-12 00:43 . 2008-02-12 00:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Rabio
2008-02-12 00:40 . 2008-02-12 00:48 <DIR> d-------- C:\Program Files\RABCO
2008-02-12 00:40 . 2008-02-12 00:40 36,864 --a------ C:\WINDOWS\mrofinu572.exe.tmp
2008-01-29 15:52 . 2008-01-29 15:52 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-29 15:52 . 2008-01-29 15:52 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-20 04:59 . 2008-01-20 04:59 <DIR> d-------- C:\Program Files\Channel4
2008-01-20 04:57 . 2008-01-20 04:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Channel4
2008-01-19 05:31 . 2008-01-19 05:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-13 22:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kontiki
2008-02-12 17:44 --------- d-----w C:\Documents and Settings\user1\Application Data\uTorrent
2008-01-20 04:59 --------- d-----w C:\Program Files\Kontiki
2008-01-19 05:38 --------- d-----w C:\Program Files\QuickTime
2008-01-19 05:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-01-19 05:31 --------- d-----w C:\Program Files\Apple Software Update
2008-01-04 21:23 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-03 00:27 3,532 ----a-w C:\drmHeader.bin
2007-12-28 11:41 --------- d-----w C:\Program Files\DivX
2007-12-28 11:41 --------- d-----w C:\Documents and Settings\user1\Application Data\DivX
2007-12-04 01:33 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-12-04 01:33 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2007-12-04 01:33 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2007-12-04 01:33 682,496 ----a-w C:\WINDOWS\system32\DivX.dll
2007-11-29 22:30 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2007-11-29 22:30 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-11-29 22:28 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-11-28 21:55 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-11-28 21:52 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1C2E5D27-A17C-4D89-85DD-3553C189380D}]
2008-01-30 14:02 414992 --a------ C:\Program Files\RABCO\RABCO.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{66566972-2F87-4E3B-8154-2DF0C41C739B}]
C:\WINDOWS\system32\mljgf.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{79ecf0a2-7457-4aa9-b498-be13935956d6}]
C:\WINDOWS\system32\luajvxyk.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{86C510E9-97EF-4749-914F-0280247BE3A6}]
2006-01-25 19:23 128512 --a------ C:\WINDOWS\VirtualDNS.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
2008-02-13 22:01 163904 --a------ C:\WINDOWS\system32\nwfoahaz.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D36F642C-BAEC-4279-8124-4E8B05DD27EC}]
C:\WINDOWS\system32\gebcc.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F0ECB4B2-C23B-4DAE-A692-147F8954B22E}]
2008-02-08 01:07 217088 --a------ C:\Program Files\MSN Gaming Zone\tovyx89104.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:56 15360]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 11:54 5674352]
"Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 17:23 102400]
"BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" [ ]
"Mp4 Player"="C:\Program Files\Mp4 Player\Mp4Player.exe" [ ]
"MtdAcq"="C:\Program Files\Creative\Shared Files\Media Sniffer\MtdAcq.exe" [2004-07-02 10:26 122956]
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" [2008-01-30 13:11 3497984]
"kdx"="C:\Program Files\Kontiki\KHost.exe" [2007-04-23 11:23 1032640]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AuditMode"="C:\sysprep\factory.exe" [ ]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2003-10-02 22:37 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-10-02 22:19 118784]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2003-10-28 08:48 159744]
"AGRSMMSG"="AGRSMMSG.exe" [2002-12-20 21:07 87751 C:\WINDOWS\AGRSMMSG.exe]
"LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [2003-04-28 23:08 184320]
"Realtime Monitor"="C:\PROGRA~1\CA\ETRUST~1\realmon.exe" [2003-02-13 09:25 493024]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2004-12-14 17:19 221184]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2004-12-14 17:57 458752]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2004-12-14 17:51 217088]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 03:00 132496]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-02-21 13:27 180269]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 22:46 57344]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-10 15:27 385024]
"4oD"="C:\Program Files\Kontiki\KHost.exe" [2007-04-23 11:23 1032640]
"ikecmmi"="c:\windows\system32\ikecmmi.exe" [ ]
"3c7ef9e4"="C:\WINDOWS\system32\raaodjmu.dll" [ ]
"combofix"="C:\WINDOWS\system32\kmd.exe" [2004-08-04 07:56 388608]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 07:56 15360]
C:\Documents and Settings\user1\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-09-01 12:15:46 113664]
RABCO - Auto Update.lnk - C:\Program Files\RABCO\RABCOse.exe [2008-02-12 00:40:24 183216]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\nwfoahaz]
nwfoahaz.dll 2008-02-13 22:01 163904 C:\WINDOWS\system32\nwfoahaz.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rqrrqol]
rqrrqol.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
R1 d_kmd;d_kmd;C:\WINDOWS\system32\drivers\d_kmd.sys [2005-12-09 15:08]
R2 HPFECP06;HPFECP06;C:\WINDOWS\system32\drivers\HPFECP06.SYS [2005-10-24 15:19]
R3 WN6201;Wireless Network Adapter Service;C:\WINDOWS\system32\DRIVERS\WN6201.sys [2005-06-17 05:40]
S2 InoNmSrv;eTrust Antivirus Admin Server;"C:\Program Files\CA\eTrust Antivirus\InoNmSrv.exe" [2003-02-13 09:23]
S3 AgentProxySvc;AgentProxySvc;C:\WINDOWS\System32\JTAProxy.exe []
S3 wlanndi5;wlanndi5 NDIS Protocol Driver;C:\WINDOWS\system32\wlanndi5.SYS [2004-04-21 16:51]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d153dc40-6e08-11dc-b51a-0012bf555349}]
\Shell\1\Command - E:\.\RECYCLER\RECYCLER\autorun.exe
\Shell\2\Command - E:\.\RECYCLER\RECYCLER\autorun.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\RECYCLER\RECYCLER\autorun.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-02-04 16:24:15 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-12 03:30:01 C:\WINDOWS\Tasks\RegistrySmart Scheduled Scan.job"
- C:\Program Files\RegistrySmart\RegistrySmart.ex
- C:\Program Files\RegistrySmart
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-13 22:14:15
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Creative Detector = "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R???w0??w????*??w???w?x??O??wD???m???v???????????????h???h??????????wO??wD???m???v???????????????k!?s???w???w????????V??w???????w??n????????w????V??w???w???????s????g??w???w???????w???w???????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\nwfoahaz.dll
.
r Running Proce
.
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
C:\Program Files\CA\eTrust Antivirus\InoRT.exe
C:\Program Files\CA\eTrust Antivirus\InoTask.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\RABCO\X_RABCOse.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\PROGRA~1\CA\SHARED~1\SCANEN~1\InoDist.exe
C:\Program Files\MSN Messenger\livecall.exe
C:\Program Files\Java\jre1.6.0_02\bin\jucheck.exe
.
**************************************************************************
.
Completion time: 2008-02-13 22:20:58 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-13 22:20:47