Thanks for the speedy reply!
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:04:53 PM, on 2/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\xInsIDE\xInsIDE.exe
C:\Program Files\Web Buying\v1.8.8\webbuying.exe
C:\WINDOWS\system32\A?pPatch\w?aclt.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\PROGRA~1\COMMON~1\YSTEM3~1\smss.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\PnkBstrA.exe
C:\Backup\Gran Paradiso\firefox.exe
C:\Documents and Settings\Owner\Desktop\HiJackThis.exe
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: (no name) - {0E054CF4-1567-4979-92C5-118FE54F64C3} - (no file)
O2 - BHO: (no name) - {538edf60-fee4-49cd-b408-06efb32eff14} - C:\WINDOWS\system32\vneriah.dll
O2 - BHO: (no name) - {6A37B9C1-0605-00A5-0217-5F00CACE80C5} - (no file)
O2 - BHO: (no name) - {6E32EDC3-5504-00A4-0A17-5F00CACEDACD} - C:\WINDOWS\system32\rssjt.dll
O2 - BHO: (no name) - {A10E80E3-584C-4AFE-A61A-5E56861B7264} - C:\Program Files\Messenger\hyjelipu89104.dll
O2 - BHO: (no name) - {B13DAD40-E67D-4CA2-8DC1-90C5F153E690} - C:\WINDOWS\system32\jkkjj.dll (file missing)
O2 - BHO: {a2030b1c-e410-ce98-19b4-ef611e13636c} - {c63631e1-16fe-4b91-89ec-014ec1b0302a} - C:\WINDOWS\system32\jhkplign.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [3c59231a] rundll32.exe "C:\WINDOWS\system32\oxycrmjk.dll",b
O4 - HKCU\..\Run: [xInsIDE] C:\Program Files\xInsIDE\xInsIDE.exe
O4 - HKCU\..\Run: [WebBuying] C:\Program Files\Web Buying\v1.8.8\webbuying.exe
O4 - HKCU\..\Run: [Rzmounjc] C:\WINDOWS\system32\A?pPatch\w?aclt.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [Notn] "C:\PROGRA~1\COMMON~1\YSTEM3~1\smss.exe" -vt yazb
O4 - HKCU\..\Run: [AdwareAlert] C:\Program Files\AdwareAlert\AdwareAlert.exe -boot
O4 - .DEFAULT User Startup: AutoTBar.exe (User 'Default user')
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\IA\command.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\System32\PnkBstrA.exe
--
End of file - 2717 bytes
ComboFix 08-02-12.1 - Owner 2008-02-11 21:08:13.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.639 [GMT -6:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\sffpssdd.sys
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Documents and Settings\LocalService\Application Data\NetMon\domains.txt
C:\Documents and Settings\LocalService\Application Data\NetMon\log.txt
C:\Documents and Settings\Owner\Application Data\AVSystemCare
C:\Documents and Settings\Owner\Application Data\AVSystemCare\Logs\threats.log
C:\Documents and Settings\Owner\Application Data\AVSystemCare\Logs\update.log
C:\Documents and Settings\Owner\Application Data\AVSystemCare\PGE.dat
C:\Documents and Settings\Owner\Application Data\MBOLS~1
C:\Documents and Settings\Owner\ResErrors.log
C:\Documents and Settings\Owner\Start Menu\Programs\Outerinfo
C:\Documents and Settings\Owner\Start Menu\Programs\Outerinfo\Terms.lnk
C:\Documents and Settings\Owner\Start Menu\Programs\Outerinfo\Uninstall.lnk
C:\Program Files\Common Files\Yazzle1281OinAdmin.exe
C:\Program Files\Common Files\Yazzle1281OinUninstaller.exe
C:\Program Files\Common Files\ystem3~1
C:\Program Files\Common Files\ystem3~1\?ystem32\
C:\Program Files\Common Files\ystem3~1\smss.exe
C:\Program Files\outerinfo
C:\Program Files\outerinfo\FF\chrome.manifest
C:\Program Files\outerinfo\FF\components\FF.dll
C:\Program Files\outerinfo\FF\components\OuterinfoAds.xpt
C:\Program Files\outerinfo\FF\install.rdf
C:\Program Files\outerinfo\Terms.rtf
C:\Program Files\Temporary
C:\Program Files\Temporary\InsiDERInst.exe
C:\Program Files\Temporary\kernInst.exe
C:\Program Files\web buying
C:\Program Files\web buying\v1.8.8\wbuninst.exe
C:\Program Files\web buying\v1.8.8\webbuying.exe
C:\WINDOWS\b122.exe
C:\WINDOWS\b153.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\Downloaded Program Files\UGA6P_0001_N122M0611NetInstaller.exe
C:\WINDOWS\Downloaded Program Files\UGA6P_0001_N122M2210NetInstaller.exe
C:\WINDOWS\IA
C:\WINDOWS\IA\KE.vbs
C:\WINDOWS\mrofinu1000106.exe
C:\WINDOWS\mrofinu572.exe
C:\WINDOWS\system32\ac1
C:\WINDOWS\system32\appatc~1
C:\WINDOWS\system32\appatc~1\w?aclt.exe
C:\WINDOWS\system32\bhlulpfd.ini
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\sffpssdd.sys
C:\WINDOWS\system32\hcovfomp.ini
C:\WINDOWS\system32\kjmrcyxo.ini
C:\WINDOWS\system32\liytjuss.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mlnmp.ini
C:\WINDOWS\system32\mlnmp.ini2
C:\WINDOWS\system32\mniljhqw.ini
C:\WINDOWS\system32\nGpxx01
C:\WINDOWS\system32\nGpxx01\nGpxx011065.exe
C:\WINDOWS\system32\oxycrmjk.dll
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\pfendxrk.ini
C:\WINDOWS\system32\pmofvoch.dll
C:\WINDOWS\system32\rssjt.dll
C:\WINDOWS\system32\tuvwwtr.dll
C:\WINDOWS\system32\v9
C:\WINDOWS\system32\v9\rabs2135.exe
C:\WINDOWS\system32\vneriah.dll
C:\WINDOWS\system32\windows
C:\WINDOWS\system32\wscomejb.dll
C:\WINDOWS\uninstall_nmon.vbs
E:\Autorun.inf
F:\Autorun.inf
----- BITS: Possible infected sites -----
hxxp://www.download.windowsupdate.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_CMDSERVICE
-------\LEGACY_NETWORK_MONITOR
-------\LEGACY_SFFPSSDD
-------\cmdService
-------\sffpssdd
((((((((((((((((((((((((( Files Created from 2008-01-12 to 2008-02-12 )))))))))))))))))))))))))))))))
.
2008-02-11 19:27 . 2008-02-11 19:27 3,832,374 --a------ C:\C w normal settings V.bmp
2008-02-11 19:27 . 2008-02-11 19:27 3,832,374 --a------ C:\C in DM NV.bmp
2008-02-11 19:26 . 2008-02-11 19:26 3,832,374 --a------ C:\C in DM.bmp
2008-02-11 19:08 . 2008-02-11 19:27 3,832,374 --a------ C:\C w normal settings.bmp
2008-02-11 07:12 . 2008-02-11 07:12 <DIR> d-------- C:\VundoFix Backups
2008-02-11 06:48 . 2008-02-11 06:48 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2008-02-11 06:25 . 2008-02-11 06:25 0 --a------ C:\WINDOWS\system32\lgkdvgjc.dll.vir
2008-02-11 00:32 . 2008-02-11 00:32 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-11 00:32 . 2008-02-11 00:32 1,409 --a------ C:\WINDOWS\QTFont.for
2008-02-10 11:16 . 2008-02-10 11:16 72,566 --a------ C:\WINDOWS\system32\GameFly_2.ico
2008-02-10 10:54 . 2008-02-10 10:54 <DIR> d-------- C:\WINDOWS\system32\wd11
2008-02-10 10:54 . 2008-02-10 15:34 <DIR> d-------- C:\WINDOWS\system32\vb6
2008-02-10 10:54 . 2008-02-10 10:54 <DIR> d-------- C:\WINDOWS\system32\kp9
2008-02-10 10:54 . 2008-02-10 10:54 <DIR> d-------- C:\Program Files\xInsIDE
2008-02-10 10:54 . 2008-02-10 10:54 40,960 --a------ C:\WINDOWS\system32\khfcyab.dll.vir
2008-02-10 02:21 . 2008-02-11 06:25 144 --a------ C:\WINDOWS\wininit.ini
2008-02-10 02:21 . 2008-02-10 02:21 0 --a------ C:\WINDOWS\system32\lwukbsuk.dll.vir
2008-02-09 20:08 . 2008-02-09 20:08 <DIR> d-------- C:\Program Files\VUGames
2008-02-09 18:48 . 2008-02-09 18:48 <DIR> d-------- C:\Program Files\America's Army Server Manager
2008-02-09 18:43 . 2008-02-09 18:43 <DIR> d-------- C:\Program Files\SystemRequirementsLab
2008-02-09 18:43 . 2008-02-09 18:43 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\SystemRequirementsLab
2008-02-09 16:02 . 2008-02-09 16:02 <DIR> d-------- C:\Program Files\NovaLogic
2008-02-09 01:49 . 2008-02-09 01:49 <DIR> d-------- C:\Program Files\Panicware
2008-02-09 01:32 . 2008-02-09 01:32 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\AdwareAlert
2008-02-09 01:25 . 2008-02-09 01:25 163,904 --a------ C:\WINDOWS\system32\zxugnfvi.dll.vir
2008-02-08 20:48 . 2008-02-08 20:48 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2008-02-08 20:04 . 2008-02-08 20:04 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-02-07 16:06 . 2008-02-07 16:06 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Lavasoft
2008-02-07 06:52 . 2008-02-07 06:52 <DIR> dr------- C:\Documents and Settings\All Users\Application Data\SalesMon
2008-02-07 06:51 . 2001-03-08 18:30 24,064 --a------ C:\WINDOWS\system32\msxml3a.dll
2008-02-07 06:49 . 2008-02-07 06:51 <DIR> d-------- C:\Program Files\RABCO
2008-02-07 06:49 . 2008-02-07 06:49 <DIR> d-------- C:\Program Files\Drmupgds
2008-02-07 06:49 . 2008-02-07 06:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Rabio
2008-02-07 06:49 . 2008-02-07 06:49 36,864 --a------ C:\WINDOWS\mrofinu1000106.exe.tmp
2008-02-07 06:48 . 2008-02-07 06:48 <DIR> d-------- C:\WINDOWS\system32\wb3
2008-02-07 06:48 . 2008-02-08 16:52 <DIR> d-------- C:\WINDOWS\system32\rp4
2008-02-07 06:48 . 2008-02-07 06:48 <DIR> d-------- C:\WINDOWS\system32\ps5
2008-02-07 06:48 . 2008-02-08 16:52 <DIR> d-------- C:\WINDOWS\system32\cz6
2008-02-07 06:45 . 2008-02-10 10:54 36,864 --a------ C:\WINDOWS\mrofinu572.exe.tmp
2008-02-06 18:48 . 2008-02-06 18:48 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Petroglyph
2008-02-06 18:47 . 2008-02-06 18:47 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\LucasArts
2008-02-06 18:47 . 2008-02-06 18:47 98,304 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2008-02-06 18:40 . 2008-02-06 18:40 <DIR> d-------- C:\Program Files\LucasArts
2008-02-06 17:37 . 2008-02-06 17:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-02-06 16:58 . 2008-02-06 16:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\NVIDIA
2008-02-06 16:48 . 2008-02-06 16:48 <DIR> d-------- C:\WINDOWS\system32\EVGA
2008-02-03 20:00 . 2008-02-03 20:00 <DIR> d-------- C:\Program Files\Realtek AC97
2008-01-27 01:36 . 2008-01-27 01:36 <DIR> d-------- C:\Program Files\VIA
2008-01-27 01:13 . 2008-01-27 01:13 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Motive
2008-01-24 22:28 . 2008-01-24 22:28 <DIR> d-------- C:\Program Files\Miscsoftware.com
2008-01-22 20:17 . 2008-01-22 20:17 <DIR> d-------- C:\Program Files\Maxis
2008-01-22 20:17 . 2008-01-22 20:17 533 --a------ C:\WINDOWS\eReg.dat
2008-01-21 15:18 . 2008-01-21 15:19 691 --a------ C:\WINDOWS\starflight.ini
2008-01-21 14:50 . 2008-01-21 14:50 233,472 --a------ C:\WINDOWS\system32\wrap_oal.dll
2008-01-21 14:50 . 2008-01-21 14:50 81,920 --a------ C:\WINDOWS\system32\OpenAL32.dll
2008-01-20 18:10 . 2006-08-01 15:02 49,152 --a------ C:\WINDOWS\system32\ChCfg.exe
2008-01-20 18:09 . 2006-12-08 15:20 10,528,768 --a------ C:\WINDOWS\system32\RTLCPL.exe
2008-01-20 18:09 . 2007-04-16 15:28 577,536 --a------ C:\WINDOWS\soundman.exe
2008-01-20 18:09 . 2006-07-31 11:19 315,392 --a------ C:\WINDOWS\alcupd.exe
2008-01-20 18:09 . 2006-07-31 11:27 217,088 --a------ C:\WINDOWS\Alcrmv.exe
2008-01-20 18:09 . 2006-10-18 02:53 147,456 --a------ C:\WINDOWS\system32\RtlCPAPI.dll
2008-01-20 18:09 . 2002-02-05 13:54 141,016 --a------ C:\WINDOWS\system32\alsndmgr.wav
2008-01-20 17:28 . 2008-01-20 17:29 <DIR> d-------- C:\WINDOWS\.jagex_cache_32
2008-01-18 17:25 . 2008-01-18 17:25 <DIR> d-------- C:\Program Files\ArtMoney
2008-01-18 03:01 . 2008-01-18 03:01 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-01-17 15:23 . 2008-01-17 15:23 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\AdobeUM
2008-01-17 15:21 . 2008-01-17 15:21 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-01-17 06:15 . 2007-07-09 07:09 584,192 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2008-01-16 22:51 . 2008-01-16 22:51 <DIR> d-------- C:\WINDOWS\Sun
2008-01-16 21:04 . 2008-01-19 03:01 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-01-16 20:56 . 2008-01-16 20:56 <DIR> d-------- C:\Program Files\iTunes
2008-01-16 20:56 . 2008-01-16 20:56 <DIR> d-------- C:\Program Files\iPod
2008-01-16 20:56 . 2008-01-16 20:56 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Apple Computer
2008-01-16 20:55 . 2008-01-16 20:55 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-01-16 20:55 . 2008-01-16 20:56 <DIR> d-------- C:\Program Files\QuickTime
2008-01-16 20:55 . 2008-01-16 20:55 <DIR> d-------- C:\Program Files\Common Files\Apple
2008-01-16 20:55 . 2008-01-16 20:55 <DIR> d-------- C:\Program Files\Apple Software Update
2008-01-16 20:55 . 2008-01-16 20:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-01-16 20:55 . 2008-01-16 20:55 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-01-16 20:04 . 2008-01-16 20:04 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-01-16 20:01 . 2004-07-17 11:40 19,528 --a------ C:\WINDOWS\[u]0[/u]02248_.tmp
2008-01-16 20:00 . 2005-06-28 10:21 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-01-16 19:58 . 2008-01-16 19:58 <DIR> d-------- C:\WINDOWS\EHome
2008-01-15 15:57 . 2008-02-10 17:41 22,328 --a------ C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-01-15 15:56 . 2008-01-15 15:56 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-01-15 15:56 . 2008-02-10 17:41 107,832 --a------ C:\WINDOWS\system32\PnkBstrB.exe
2008-01-15 15:56 . 2008-02-09 22:20 66,872 --a------ C:\WINDOWS\system32\PnkBstrA.exe
2008-01-15 15:34 . 2001-08-17 13:48 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2008-01-15 15:34 . 2001-08-17 13:48 12,160 --a--c--- C:\WINDOWS\system32\dllcache\mouhid.sys
2008-01-14 22:23 . 2004-08-04 00:56 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-01-14 18:47 . 2008-01-14 18:47 0 --a------ C:\WINDOWS\nsreg.dat
2008-01-14 18:39 . 2006-06-14 02:47 172,416 --a------ C:\WINDOWS\system32\drivers\kmixer.sys
2008-01-14 18:39 . 2006-02-14 18:22 142,464 --a------ C:\WINDOWS\system32\drivers\aec.sys
2008-01-14 18:39 . 2006-06-14 03:00 82,944 --a------ C:\WINDOWS\system32\drivers\wdmaud.sys
2008-01-14 18:39 . 2004-08-03 23:15 60,800 --a------ C:\WINDOWS\system32\drivers\sysaudio.sys
2008-01-14 18:39 . 2001-08-17 16:00 54,272 --a------ C:\WINDOWS\system32\drivers\swmidi.sys
2008-01-14 18:39 . 2004-08-03 23:07 52,864 --a------ C:\WINDOWS\system32\drivers\dmusic.sys
2008-01-14 18:39 . 2001-08-17 16:02 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2008-01-14 18:39 . 2006-06-14 02:47 6,400 --a------ C:\WINDOWS\system32\drivers\splitter.sys
2008-01-14 18:39 . 2004-08-03 23:07 2,944 --a------ C:\WINDOWS\system32\drivers\drmkaud.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-10 02:09 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-09 06:18 --------- d-----w C:\Program Files\Hewlett-Packard
2008-02-09 06:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-09 06:11 --------- d-----w C:\Documents and Settings\Owner\Application Data\interMute
2008-01-21 00:09 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-01-14 23:47 --------- d-----w C:\Program Files\Easy Internet signup
2008-01-14 23:46 4,110 --sha-r C:\WINDOWS\system32\drivers\HP_DQ175A-ABA A420N_YC_Pavi_QMXK404_E41NAheBLU4_4_IKamet2_SASUSTek Computer INC._V2.01_B3.06_T031219_WXH1_L409_M960_J164_7AMD_8Athlon XP 3000+_92.16_111063044_N11063065_P_Z11C1044C_K_A11063059_U11063038_G11067205_O_DHWP264E.MRK
2007-11-13 19:45 806,912 ----a-w C:\WINDOWS\boinc.scr
.
[code]
----a-w 267,048 2008-01-12 10:17:38 C:\Documents and Settings\Owner\Desktop\iTunes\iTunesHelper .exe
[/code]
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A10E80E3-584C-4AFE-A61A-5E56861B7264}]
2008-02-07 19:07 217088 --a------ C:\Program Files\Messenger\hyjelipu89104.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B13DAD40-E67D-4CA2-8DC1-90C5F153E690}]
C:\WINDOWS\system32\jkkjj.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c63631e1-16fe-4b91-89ec-014ec1b0302a}]
C:\WINDOWS\system32\jhkplign.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"xInsIDE"="C:\Program Files\xInsIDE\xInsIDE.exe" [2008-02-10 10:54 57344]
"Rzmounjc"="C:\WINDOWS\system32\A?pPatch\w?aclt.exe" [ ]
"RecordNow!"="" []
"PopUpStopperFreeEdition"="C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe" [2005-03-17 11:10 536576]
"Notn"="C:\PROGRA~1\COMMON~1\YSTEM3~1\smss.exe" [ ]
"AdwareAlert"="C:\Program Files\AdwareAlert\AdwareAlert.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-08-11 21:43 7630848]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"srservice"=2 (0x2)
"ShellHWDetection"=2 (0x2)
S2 nvcap;nVidia WDM Video Capture (universal);C:\WINDOWS\system32\DRIVERS\nvcap.sys [2003-07-30 03:15]
S2 NVXBAR;nVidia WDM A/V Crossbar;C:\WINDOWS\system32\DRIVERS\NVxbar.sys [2003-07-30 03:15]
.
Contents of the 'Scheduled Tasks' folder
"2008-02-11 09:00:01 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job"
- C:\Program Files\AdwareAlert\AdwareAlert.ex
- C:\Program Files\AdwareAlert
"2008-02-06 19:56:23 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-14 23:47:15 C:\WINDOWS\Tasks\Easy Internet Sign-up.job"
- C:\Program Files\Easy Internet signup\HPSdpApp.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-11 21:11:15
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
r Running Proce
.
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\PnkBstrA.exe
.
**************************************************************************
.
Completion time: 2008-02-11 21:12:45 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-12 03:12:42
.
2008-02-09 21:33:05 --- E O F ---