I loaded Microsofts OneCare trial, and that seemed to clean up some of it...but everything keeps coming back. I also ran your ComboFix program...only by using my work PC, downloading the file (since my infected PC would even let me go to a site related to ComboFix), saved it as a draft in my Yahoo email, then saved/ran it from my infected PC. ComboFix doesn't seem to work for me after the first run I did. I ran a program called Ad-AWARE SE Personal, and that seemed to clean up the Vitromunde problem..and it seems to disable the "prunnet.exe" file that I found out was bad...but I am still having major problems. It occasionally goes to a blue screen that talks about needing to load an Antivirus program, then a fake Microsoft reboot screen, then back to the desktop. All of my icons and status bar at the bottom of XP suddenly disappear and only come back after a reboot. It's a mess...please help.
DDS (Version 1.1.0) - NTFSx86
Run by Jeremy at 22:07:33.78 on 2009-01-06
Internet Explorer: 7.0.5730.11
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.503.104 [GMT -5:00]
AV: AT&T Internet Security Suite AT&T Anti-Virus *On-access scanning disabled* (Updated)
AV: Norton AntiVirus *On-access scanning disabled* (Outdated)
AV: Windows Live OneCare *On-access scanning enabled* (Updated)
FW: Windows Live OneCare Firewall *enabled*
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\AT&T\AT&T Internet Security Suite\Fws.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe
C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\system32\slserv.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\AT&T\Internet Security Wizard\ISW.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe
C:\Documents and Settings\Jeremy\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.charlotteobserver.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://my.netzero.net/s/search?r=minisearch
mSearchAssistant = hxxp://my.netzero.net/s/search?r=minisearch
uURLSearchHooks: URLSearchHook Class: {37d2cdbf-2af4-44aa-8113-bd0d2da3c2b8} - c:\program files\nzsearch\SearchEnh1.dll
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
BHO: NoExplorer - No File
BHO: {243b17de-77c7-46bf-b94b-0b5f309a0e64} - c:\program files\microsoft money\system\mnyside.dll
BHO: BellSouth Toolbar: {4e7bd74f-2b8d-469e-8cbd-fd60bb9aae2e} - c:\progra~1\blstoo~1\BLSTOO~1.DLL
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar2.dll
BHO: CNavExtBho Class: {bdf3e430-b101-42ad-a544-fadc6b084872} - c:\program files\norton antivirus\NavShExt.dll
BHO: {dd0e8895-77f6-4c47-a691-8a080bbdc538} - c:\windows\system32\nnNeBUKB.dll
BHO: {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No File
TB: Norton AntiVirus: {42cdd1bf-3ffb-4238-8ad1-7859df00b1d6} - c:\program files\norton antivirus\NavShExt.dll
TB: ZeroBar: {f5735c15-1fb2-41fe-ba12-242757e69dde} - c:\program files\netzero\Toolbar.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
TB: BellSouth Toolbar: {4e7bd74f-2b8d-469e-8cbd-fd60bb9aae2e} - c:\progra~1\blstoo~1\BLSTOO~1.DLL
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar2.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [spc_w] "c:\program files\nzsearch\nzspc.exe" -w
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [DW6] "c:\program files\the weather channel fw\desktop\DesktopWeather.exe"
uRun: [prunnet] "c:\windows\system32\prunnet.exe"
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [Symantec NetDriver Monitor] c:\progra~1\symnet~1\SNDMon.exe /Consumer
mRun: [RealTray] c:\program files\real\realplayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
mRun: [HelpCenter] c:\program files\bellsouth\helpcenter\bin\sprtcmd.exe /P HelpCenter
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_03\bin\jusched.exe"
mRun: [ISW.exe] "c:\program files\at&t\internet security wizard\ISW.exe" /AUTORUN
mRun: [-FreedomNeedsReboot] "c:\program files\at&t\at&t internet security suite\ZkRunOnceR.exe"
mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.2\apps\apdproxy.exe"
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [prunnet] "c:\windows\system32\prunnet.exe"
mRun: [OneCareUI] "c:\program files\microsoft windows onecare live\winssnotify.exe"
dRun: [msiexec.exe] msiconf.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\bigfix.lnk - c:\program files\bigfix\BigFix.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\kodake~1.lnk - c:\program files\kodak\kodak easyshare software\bin\EasyShare.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\kodaks~1.lnk - c:\program files\kodak\kodak software updater\7288971\program\Kodak Software Updater.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
IE: Display All Images with Full Quality - "c:\program files\netzero\qsacc\appres.dll/228"
IE: Display Image with Full Quality - "c:\program files\netzero\qsacc\appres.dll/227"
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {6224f700-cba3-4071-b251-47cb894244cd} - c:\program files\icq\ICQ.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
IE: {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - {DD6687B5-CB43-4211-BFC9-2942CCBDCB3E} - c:\program files\microsoft money\system\mnyside.dll
Trusted Zone: turbotax.com
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Notify: fcCtUKeb - fcCtUKeb.dll
Notify: igfxcui - igfxsrvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
SEH: {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - No File
LSA: Authentication Packages = msv1_0 c:\windows\system32\nnNeBUKB
============= SERVICES / DRIVERS ===============
R1 SAVRT;SAVRT;c:\program files\norton antivirus\savrt.sys [2006-2-5 305288]
R1 SAVRTPEL;SAVRTPEL;c:\program files\norton antivirus\savrtpel.sys [2006-2-5 37000]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20060330.035\NAVENG.Sys [2006-4-2 77864]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20060330.035\NavEx15.Sys [2006-4-2 750952]
=============== Created Last 30 ================
2009-01-06 19:35 <DIR> --d----- C:\ComboFix
2009-01-06 19:35 389,120 a------- c:\windows\system32\CF7226.exe
2009-01-06 19:35 389,120 a------- c:\windows\system32\CF7219.exe
2009-01-05 23:42 40,960 a------- c:\windows\system32\bubnfmfe.dll
2009-01-05 23:04 195 a------- C:\Start_.cmd
2009-01-05 23:04 389,120 a------- c:\windows\system32\CF28154.exe
2009-01-05 23:04 389,120 a------- c:\windows\system32\CF28145.exe
2009-01-05 23:03 389,120 a------- c:\windows\system32\cmd.execf
2009-01-05 00:58 <DIR> a-dshr-- C:\cmdcons
2009-01-05 00:53 161,792 a------- c:\windows\SWREG.exe
2009-01-05 00:53 98,816 a------- c:\windows\sed.exe
2009-01-05 00:53 389,120 a------- c:\windows\system32\CF29477.exe
2009-01-05 00:52 2,888,012 a----r-- C:\ComboFix.exe
2009-01-04 23:28 1,307,356 ---sh--- c:\windows\system32\rlwcunlu.ini
2009-01-04 23:17 40,960 a------- c:\windows\system32\dbfcbbgy.dll
2009-01-04 15:01 3,960 a------- c:\windows\system32\OEMINFO.PNF
2009-01-04 09:14 <DIR> --d----- c:\program files\CA Yahoo! Anti-Spy
2009-01-04 01:59 0 a------- c:\windows\system32\drivers\seneka.sys
2009-01-04 01:41 91,328 a------- c:\windows\system32\drivers\msfwdrv.sys
2009-01-04 01:41 116,416 a------- c:\windows\system32\drivers\msfwhlpr.sys
2009-01-04 01:36 53,168 a------- c:\windows\system32\drivers\MpFilter.sys
2009-01-04 01:30 <DIR> --d----- c:\program files\Microsoft Windows OneCare Live
2009-01-04 01:08 0 a------- c:\windows\system32\mcrh.tmp
2009-01-03 21:54 82,944 a------- c:\windows\system32\msiconf.exe
2009-01-03 21:47 40,960 a------- c:\windows\system32\twsnnwto.dll
2009-01-03 21:45 1,307,356 ---sh--- c:\windows\system32\pjvpwvwx.ini
2009-01-03 21:44 2,461 a------- c:\windows\system32\senekadf.dat
2009-01-03 21:44 59 a------- c:\windows\system32\seneka.dat
2009-01-03 21:44 2,257 a--sh--- c:\windows\system32\BKUBeNnn.ini2
2009-01-03 21:44 2,257 a--sh--- c:\windows\system32\BKUBeNnn.ini
2009-01-03 21:44 284,160 a------- c:\windows\system32\nnNeBUKB.dll
2009-01-03 21:39 17,023 a------- c:\windows\system32\senekalog.dat
2009-01-03 21:38 114,688 a------- c:\windows\system32\prunnet.exe
2008-12-23 22:31 <DIR> --d----- c:\program files\iPod
2008-12-23 22:31 <DIR> --d----- c:\program files\iTunes
2008-12-23 22:31 <DIR> --d----- c:\docume~1\alluse~1\applic~1\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
==================== Find3M ====================
2008-10-23 07:36 286,720 a------- c:\windows\system32\gdi32.dll
2008-10-16 15:38 826,368 a------- c:\windows\system32\wininet.dll
2008-10-16 14:06 268,648 a------- c:\windows\system32\mucltui.dll
2008-10-16 14:06 208,744 a------- c:\windows\system32\muweb.dll
2007-05-14 22:27 66,269 -------- c:\program files\INSTALL.LOG
2006-10-20 21:39 194,376 a------- c:\docume~1\jeremy\applic~1\shb.dat
2008-08-29 09:44 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008082920080830\index.dat
============= FINISH: 22:09:02.37 ===============