And here is the combo fix text...I have no idea yet how things are running, but will say IE took forever to load to come here...not sure if that is good or bad...
ComboFix 07-12-12.3 - Andrea 2007-12-11 18:31:57.1 - NTFSx86
Running from: C:\Documents and Settings\Andrea\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Starware337
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\epiRSS.bmp
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\epiRSS.png
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\epiSearch.bmp
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\epiSearch.png
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\FindIt.bmp
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\FindItHot.bmp
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\findithotxp.png
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\finditxp.png
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\Highlight.bmp
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\HighlightHot.bmp
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\highlighthotxp.png
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\highlightxp.png
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\logo.bmp
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\logoxp.bmp
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\Reference.bmp
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\ReferenceHot.bmp
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\referencehotxp.png
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\referencexp.png
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\Weather.bmp
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\weatherhotxp.png
C:\Documents and Settings\All Users\Application Data\Starware337\buttons\weatherxp.png
C:\Documents and Settings\All Users\Application Data\Starware337\contexts\Error.xml
C:\Documents and Settings\All Users\Application Data\Starware337\contexts\related.xml
C:\Documents and Settings\All Users\Application Data\Starware337\contexts\Travel.xml
C:\Documents and Settings\All Users\Application Data\Starware337\images\walertXP.bmp
C:\Documents and Settings\All Users\Application Data\Starware337\SimpleUpdate\ProductMessagingConfig.xml
C:\Documents and Settings\All Users\Application Data\Starware337\SimpleUpdate\ProductMessagingConfig.xml.backup
C:\Documents and Settings\All Users\Application Data\Starware337\SimpleUpdate\SimpleUpdateConfig.xml
C:\Documents and Settings\All Users\Application Data\Starware337\SimpleUpdate\SimpleUpdateConfig.xml.backup
C:\Documents and Settings\All Users\Application Data\Starware337\SimpleUpdate\TimerManagerConfig.xml
C:\Documents and Settings\All Users\Application Data\Starware337\SimpleUpdate\TimerManagerConfig.xml.backup
C:\Documents and Settings\All Users\Application Data\Starware337\U0B8FB654.exe
C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\Andrea\Application Data\Starware337
C:\Documents and Settings\Andrea\Application Data\Starware337\BrowserSearch\BrowserSearch.xml
C:\Documents and Settings\Andrea\Application Data\Starware337\BrowserSearch\BrowserSearch.xml.backup
C:\Documents and Settings\Andrea\Application Data\Starware337\ErrorSearch\ErrorSearchOptions.xml
C:\Documents and Settings\Andrea\Application Data\Starware337\ErrorSearch\ErrorSearchOptions.xml.backup
C:\Documents and Settings\Andrea\Application Data\Starware337\Games\GamesOptions.xml
C:\Documents and Settings\Andrea\Application Data\Starware337\Games\GamesOptions.xml.backup
C:\Documents and Settings\Andrea\Application Data\Starware337\Games\images\active\Games0.bmp
C:\Documents and Settings\Andrea\Application Data\Starware337\Layouts\ToolbarLayout.xml
C:\Documents and Settings\Andrea\Application Data\Starware337\Layouts\ToolbarLayout.xml.backup
C:\Documents and Settings\Andrea\Application Data\Starware337\Manager\ManagerOptions.xml
C:\Documents and Settings\Andrea\Application Data\Starware337\Manager\ManagerOptions.xml.backup
C:\Documents and Settings\Andrea\Application Data\Starware337\Movies\images\active\Movies0.bmp
C:\Documents and Settings\Andrea\Application Data\Starware337\Movies\MoviesOptions.xml
C:\Documents and Settings\Andrea\Application Data\Starware337\Movies\MoviesOptions.xml.backup
C:\Documents and Settings\Andrea\Application Data\Starware337\Recipes\RecipesOptions.xml
C:\Documents and Settings\Andrea\Application Data\Starware337\Recipes\RecipesOptions.xml.backup
C:\Documents and Settings\Andrea\Application Data\Starware337\RecipeSearch\RecipeSearchOptions.xml
C:\Documents and Settings\Andrea\Application Data\Starware337\RecipeSearch\RecipeSearchOptions.xml.backup
C:\Documents and Settings\Andrea\Application Data\Starware337\Reference\ReferenceOptions.xml
C:\Documents and Settings\Andrea\Application Data\Starware337\Reference\ReferenceOptions.xml.backup
C:\Documents and Settings\Andrea\Application Data\Starware337\RelatedSearch\RelatedSearchOptions.xml
C:\Documents and Settings\Andrea\Application Data\Starware337\RelatedSearch\RelatedSearchOptions.xml.backup
C:\Documents and Settings\Andrea\Application Data\Starware337\ScreensaversMarketingSitePager\images\active\ScreensaversMarketingSitePager0.bmp
C:\Documents and Settings\Andrea\Application Data\Starware337\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml
C:\Documents and Settings\Andrea\Application Data\Starware337\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml.backup
C:\Documents and Settings\Andrea\Application Data\Starware337\SearchAssistPlus\SearchAssistPlusOptions.xml
C:\Documents and Settings\Andrea\Application Data\Starware337\SearchAssistPlus\SearchAssistPlusOptions.xml.backup
C:\Documents and Settings\Andrea\Application Data\Starware337\SearchMatch\SearchMatchOptions.xml
C:\Documents and Settings\Andrea\Application Data\Starware337\SearchMatch\SearchMatchOptions.xml.backup
C:\Documents and Settings\Andrea\Application Data\Starware337\Toolbar\TBProductsOptions.xml
C:\Documents and Settings\Andrea\Application Data\Starware337\Toolbar\TBProductsOptions.xml.backup
C:\Documents and Settings\Andrea\Application Data\Starware337\ToolbarLogo\ToolbarLogoOptions.xml
C:\Documents and Settings\Andrea\Application Data\Starware337\ToolbarLogo\ToolbarLogoOptions.xml.backup
C:\Documents and Settings\Andrea\Application Data\Starware337\ToolbarSearch\ToolbarSearchOptions.xml
C:\Documents and Settings\Andrea\Application Data\Starware337\ToolbarSearch\ToolbarSearchOptions.xml.backup
C:\Documents and Settings\Andrea\Application Data\Starware337\TravelSearch\TravelSearchOptions.xml
C:\Documents and Settings\Andrea\Application Data\Starware337\TravelSearch\TravelSearchOptions.xml.backup
C:\Documents and Settings\Andrea\Application Data\Starware337\Weather\AlertArchive.xml
C:\Documents and Settings\Andrea\Application Data\Starware337\Weather\WeatherOptions.xml
C:\Documents and Settings\Andrea\Application Data\Starware337\Weather\WeatherOptions.xml.backup
C:\Documents and Settings\Andrea\Favorites\Online Security Guide.lnk
C:\Program Files\Starware337
C:\Program Files\Starware337\bin\Starware337.dll
C:\Program Files\Starware337\brand.bmp
C:\Program Files\Starware337\icons\star_16.ico
C:\Program Files\Starware337\Starware337Config.xml
C:\Program Files\Starware337\Starware337Uninstall.exe
C:\Temp\bkR11
C:\WINDOWS\b111.exe
C:\WINDOWS\b122.exe
C:\WINDOWS\b138.exe
C:\WINDOWS\b147.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\mrofinu572.exe
C:\WINDOWS\system32\amrnwvfq.dll
C:\WINDOWS\system32\aorrnmdl.dll
C:\WINDOWS\system32\apkonyds.exe
C:\WINDOWS\system32\avrfpwxg.dll
C:\WINDOWS\system32\cnbxsygo.dll
C:\WINDOWS\SYSTEM32\cwtsffne.ini
C:\WINDOWS\system32\drivers\fad.sys
C:\WINDOWS\SYSTEM32\egjlm.ini
C:\WINDOWS\SYSTEM32\egjlm.ini2
C:\WINDOWS\system32\enffstwc.dll
C:\WINDOWS\system32\hjnsdjjx.dll
C:\WINDOWS\SYSTEM32\ioqcrcqt.ini
C:\WINDOWS\system32\iuinclul.dll
C:\WINDOWS\system32\laqbulax.exe
C:\WINDOWS\SYSTEM32\lulcniui.ini
C:\WINDOWS\system32\mljge.dll
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\pcvoffjy.dll
C:\WINDOWS\system32\pmnljii.dll
C:\WINDOWS\system32\pnkoyoie.dll
C:\WINDOWS\SYSTEM32\qfvwnrma.ini
C:\WINDOWS\system32\rqropmn.dll
C:\WINDOWS\system32\sagpcfxf.exe
C:\WINDOWS\system32\skpddnxh.dll
C:\WINDOWS\system32\ssqqrsr.dll
C:\WINDOWS\system32\tjwotxmh.dll
C:\WINDOWS\system32\tqcrcqoi.dll
C:\WINDOWS\system32\uscnunus.dll
C:\WINDOWS\system32\whfhwsdx.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
((((((((((((((((((((((((( Files Created from 2007-11-13 to 2007-12-13 )))))))))))))))))))))))))))))))
.
2007-12-12 20:12 . <DIR> C:\WINDOWS\LastGood.Tmp
2007-12-11 16:21 . 2007-12-12 21:42 1,393 --a------ C:\WINDOWS\imsins.BAK
2007-12-10 22:34 . 2007-12-10 22:34 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-09 21:30 . 2007-12-10 21:31 858,884 --ahs---- C:\WINDOWS\SYSTEM32\nxsujbkb.ini
2007-12-08 13:52 . 2007-12-08 13:52 294 --ahs---- C:\WINDOWS\SYSTEM32\qxjuivqa.ini
2007-12-05 22:11 . 2007-12-06 22:45 832,610 --ahs---- C:\WINDOWS\SYSTEM32\niduaqws.ini
2007-12-05 07:11 . 2007-12-05 07:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-12-05 07:10 . 2007-12-05 07:10 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-12-04 20:56 . 2007-12-05 22:10 806,242 --ahs---- C:\WINDOWS\SYSTEM32\ycpxxkvo.ini
2007-12-03 23:13 . 2007-12-03 23:13 24,576 --a------ C:\WINDOWS\SYSTEM32\VundoFixSVC.exe
2007-12-03 20:21 . 2007-12-03 23:13 <DIR> d-------- C:\VundoFix Backups
2007-12-02 21:00 . 2007-12-03 19:59 793,751 --ahs---- C:\WINDOWS\SYSTEM32\meimxjbx.ini
2007-12-02 19:23 . 2007-12-08 14:14 143 --a------ C:\WINDOWS\SYSTEM32\mcrh.tmp
2007-12-02 16:47 . 2007-12-02 16:47 793,664 --ahs---- C:\WINDOWS\SYSTEM32\waudftwk.tmp
2007-12-02 16:47 . 2007-12-02 16:47 793,664 --ahs---- C:\WINDOWS\SYSTEM32\waudftwk.ini
2007-12-02 16:24 . 2007-12-02 16:33 3,498 --a------ C:\WINDOWS\SYSTEM32\tmp.reg
2007-12-02 00:30 . 2007-09-05 23:22 289,144 --a------ C:\WINDOWS\SYSTEM32\VCCLSID.exe
2007-12-02 00:30 . 2006-04-27 16:49 288,417 --a------ C:\WINDOWS\SYSTEM32\SrchSTS.exe
2007-12-02 00:30 . 2003-06-05 20:13 53,248 --a------ C:\WINDOWS\SYSTEM32\Process.exe
2007-12-02 00:30 . 2004-07-31 17:50 51,200 --a------ C:\WINDOWS\SYSTEM32\dumphive.exe
2007-12-02 00:30 . 2007-10-03 23:36 25,600 --a------ C:\WINDOWS\SYSTEM32\WS2Fix.exe
2007-11-29 21:52 . 2007-11-29 21:52 35,840 --a------ C:\WINDOWS\mrofinu572.exe.tmp
2007-11-29 21:50 . 2007-11-29 21:50 <DIR> d-------- C:\WINDOWS\SYSTEM32\daSgo01
2007-11-29 21:50 . 2007-12-12 19:01 <DIR> d-------- C:\Temp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-11 23:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2007-12-11 02:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-11 02:41 --------- d-----w C:\Program Files\SpywareBlaster
2007-12-07 03:41 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-12-05 12:12 --------- d-----w C:\Program Files\Lavasoft
2007-11-30 17:57 --------- d-----w C:\Program Files\Broderbund
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-12 14:30 --------- d-----w C:\Documents and Settings\Andrea\Application Data\AdobeUM
2007-10-15 22:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\EPSON
2007-10-15 22:53 --------- d-----w C:\Program Files\EPSON
2007-10-15 16:00 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-07-10 03:57 142,864 ----a-w C:\Documents and Settings\Andrea\Application Data\GDIPFONTCACHEV1.DAT
2005-03-02 18:04 34,916 ----a-w C:\WINDOWS\Fonts\addict.zip
2005-03-02 18:04 33,197 ----a-w C:\WINDOWS\Fonts\adler.zip
2005-03-02 18:01 34,254 ----a-w C:\WINDOWS\Fonts\aidancing.zip
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{18e8e412-dc74-4b87-b019-5ba3793912e3}]
C:\WINDOWS\system32\avrfpwxg.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F3C619-0377-4D04-8D92-18F028CAFFD1}]
C:\WINDOWS\system32\mljge.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45]
"Sonic RecordNow!"="" []
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24]
"Insider"="C:\Program Files\Insider\Insider.exe" []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2003-05-02 18:21]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2003-05-02 18:15]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-09-03 02:04]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2006-09-05 20:22]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-19 08:59]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2003-12-09 00:17]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-19 08:59]
"5870b7aa"="C:\WINDOWS\system32\amrnwvfq.dll" []
"combofix"="C:\WINDOWS\system32\cmd.exe" [2004-08-04 02:56]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"SFCDisable"=dword:00000004
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnljii]
pmnljii.dll
S3 {5C8B2B62-A385-11d5-A78B-00104B672758};AIM 3.0 Part 01 Codec Driver CH-7017-A;C:\WINDOWS\system32\drivers\A311.sys
S3 {5C8B2B65-A385-11d5-A78B-00104B672758};AIM 3.0 Part 01 Codec Driver CH-7017-B;C:\WINDOWS\system32\drivers\A310.sys
S3 WRSWanDD;iVasion PoET Adapter;C:\WINDOWS\system32\DRIVERS\WrKPoETNic2000.sys
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2007-10-20 12:21:54 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Andrea.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exe
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2007-12-12 22:20:09
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2007-12-12 22:33:48 - machine was rebooted
.
2007-12-11 22:11:16 --- E O F ---