Hi oldman,
first of all let me say thanks for any help you give me.
my problem is
file name: C:\WINDOWS\system32\kbdu.dll[UPX]
Malware name: Win32:BHO-KD [trj]
I have read a few others like it and have ran combofix then ran hjt.
here are the logs thanks again for your time.
Ken Boone
my combofix log
ComboFix 08-01-20.1 - Booney 2008-01-20 11:52:36.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.234 [GMT -6:00]
Running from: C:\Documents and Settings\Booney\Local Settings\Temporary Internet Files\Content.IE5\OX2BKH2Z\ComboFix[1].exe
- Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CnsMin.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CnsMin1.zip
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CnsMin2.zip
C:\Documents and Settings\Booney\Application Data\WinTouch
C:\Documents and Settings\Booney\Application Data\WinTouch\wintouch.cfg
C:\Documents and Settings\Booney\My Documents\FNTS~1
C:\Documents and Settings\Booney\My Documents\FNTS~1\F?nts
C:\Documents and Settings\LocalService\Desktop\searchus.exe
C:\Program Files\3721
C:\Program Files\3721\assist\asbar.dll
C:\Program Files\3721\helper.dll
C:\Program Files\Accoona
C:\Program Files\Accoona\ASearchAssist.dll
C:\Program Files\akl
C:\Program Files\akl\akl.dll
C:\Program Files\akl\akl.exe
C:\Program Files\akl\curlog.htm
C:\Program Files\akl\keylog.txt
C:\Program Files\akl\readme.txt
C:\Program Files\akl\uninstall.exe
C:\Program Files\akl\unsetup.dat
C:\Program Files\akl\unsetup.exe
C:\Program Files\amsys
C:\Program Files\amsys\awmsg.dat
C:\Program Files\amsys\guid.dat
C:\Program Files\amsys\ijl15.dll
C:\Program Files\amsys\mfc42.dll
C:\Program Files\amsys\msvcrt.dll
C:\Program Files\amsys\unins000.dat
C:\Program Files\amsys\unis000.exe
C:\Program Files\amsys\winam.dat
C:\Program Files\Common Files\rtekex.html
C:\Program Files\e-zshopper
C:\Program Files\e-zshopper\BarLcher.dll
C:\Program Files\ISM
C:\Program Files\p2pnetworks
C:\Program Files\p2pnetworks\amp2pl.exe
C:\Program Files\QdrDrive
C:\Program Files\QdrDrive\QdrDrive8.dll
C:\Program Files\QdrDrive\qdrloader.exe
C:\Program Files\QdrModule
C:\Program Files\QdrModule\dic.gz
C:\Program Files\QdrModule\kwd.gz
C:\Program Files\QdrModule\QdrModule10.exe
C:\Program Files\QdrPack
C:\Program Files\QdrPack\dicts.gz
C:\Program Files\QdrPack\QdrPack11.exe
C:\Program Files\QdrPack\trgts.gz
C:\Program Files\Temporary
C:\Program Files\Words
C:\Program Files\Words\list.txt
C:\Program Files\Words\script.txt
C:\Program Files\Words\UnInstall.exe
C:\WINDOWS\764.exe
C:\WINDOWS\7search.dll
C:\WINDOWS\absolute key logger.lnk
C:\WINDOWS\aconti.exe
C:\WINDOWS\aconti.ini
C:\WINDOWS\aconti.log
C:\WINDOWS\aconti.sdb
C:\WINDOWS\acontidialer.txt
C:\WINDOWS\adbar.dll
C:\WINDOWS\b122.exe
C:\WINDOWS\b149.exe
C:\WINDOWS\cbinst$.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\daxtime.dll
C:\WINDOWS\default.htm
C:\WINDOWS\dp0.dll
C:\WINDOWS\eventlowg.dll
C:\WINDOWS\fhfmm-Uninstaller.exe
C:\WINDOWS\fhfmm.exe
C:\WINDOWS\flt.dll
C:\WINDOWS\hcwprn.exe
C:\WINDOWS\hotporn.exe
C:\WINDOWS\ie_32.exe
C:\WINDOWS\iexplorr23.dll
C:\WINDOWS\jd2002.dll
C:\WINDOWS\kkcomp$.exe
C:\WINDOWS\kkcomp.dll
C:\WINDOWS\kkcomp.exe
C:\WINDOWS\kvnab$.exe
C:\WINDOWS\kvnab.dll
C:\WINDOWS\kvnab.exe
C:\WINDOWS\liqad$.exe
C:\WINDOWS\liqad.dll
C:\WINDOWS\liqad.exe
C:\WINDOWS\liqui-Uninstaller.exe
C:\WINDOWS\liqui.dll
C:\WINDOWS\liqui.exe
C:\WINDOWS\mrofinu1053.exe
C:\WINDOWS\ngd.dll
C:\WINDOWS\pbar.dll
C:\WINDOWS\pbsysie.dll
C:\WINDOWS\settn.dll
C:\WINDOWS\spredirect.dll
C:\WINDOWS\system32\ace16win.dll
C:\WINDOWS\system32\acespy
C:\WINDOWS\system32\acespy_acelog.ndx
C:\WINDOWS\system32\acespy\systune.exe
C:\WINDOWS\system32\amqpaalb.dll
C:\WINDOWS\system32\brmbqqjt.dll
C:\WINDOWS\system32\cbcfe.ini
C:\WINDOWS\system32\cbcfe.ini2
C:\WINDOWS\system32\ccaafnom.dll
C:\WINDOWS\system32\ccisfrdx.dll
C:\WINDOWS\system32\cqpwnvnn.ini
C:\WINDOWS\system32\ddocvpsw.dll
C:\WINDOWS\system32\deewxhtr.ini
C:\WINDOWS\system32\din.ip
C:\WINDOWS\system32\dobe~1
C:\WINDOWS\system32\dpqaqlqx.bin
C:\WINDOWS\system32\dqeejciu.dll
C:\WINDOWS\system32\drivers\blank.gif
C:\WINDOWS\system32\drivers\box_2.gif
C:\WINDOWS\system32\drivers\button_buynow.gif
C:\WINDOWS\system32\drivers\button_freescan.gif
C:\WINDOWS\system32\drivers\cell_bg.gif
C:\WINDOWS\system32\drivers\cell_footer.gif
C:\WINDOWS\system32\drivers\cell_header_block.gif
C:\WINDOWS\system32\drivers\cell_header_remove.gif
C:\WINDOWS\system32\drivers\cell_header_scan.gif
C:\WINDOWS\system32\drivers\detect.htm
C:\WINDOWS\system32\drivers\download_btn.jpg
C:\WINDOWS\system32\drivers\download_now_btn.gif
C:\WINDOWS\system32\drivers\footer_back.jpg
C:\WINDOWS\system32\drivers\header_1.gif
C:\WINDOWS\system32\drivers\header_2.gif
C:\WINDOWS\system32\drivers\header_3.gif
C:\WINDOWS\system32\drivers\header_4.gif
C:\WINDOWS\system32\drivers\header_red_bg.gif
C:\WINDOWS\system32\drivers\header_red_free_scan.gif
C:\WINDOWS\system32\drivers\header_red_free_scan_bg.gif
C:\WINDOWS\system32\drivers\header_red_protect_your_pc.gif
C:\WINDOWS\system32\drivers\infected.gif
C:\WINDOWS\system32\drivers\jizzvgdn.dat
C:\WINDOWS\system32\drivers\main_back.gif
C:\WINDOWS\system32\drivers\product_2_header.gif
C:\WINDOWS\system32\drivers\product_2_name_small.gif
C:\WINDOWS\system32\drivers\product_features.gif
C:\WINDOWS\system32\drivers\pt.htm
C:\WINDOWS\system32\drivers\rating.gif
C:\WINDOWS\system32\drivers\s_detect.htm
C:\WINDOWS\system32\drivers\screenshot.jpg
C:\WINDOWS\system32\drivers\sep_hor.gif
C:\WINDOWS\system32\drivers\sep_vert.gif
C:\WINDOWS\system32\drivers\shadow.jpg
C:\WINDOWS\system32\drivers\shadow_bg.gif
C:\WINDOWS\system32\drivers\spacer.gif
C:\WINDOWS\system32\drivers\star.gif
C:\WINDOWS\system32\drivers\star_gray.gif
C:\WINDOWS\system32\drivers\star_gray_small.gif
C:\WINDOWS\system32\drivers\star_small.gif
C:\WINDOWS\system32\drivers\style.css
C:\WINDOWS\system32\drivers\v.gif
C:\WINDOWS\system32\drivers\warning_icon.gif
C:\WINDOWS\system32\drivers\win_logo.gif
C:\WINDOWS\system32\drivers\x.gif
C:\WINDOWS\system32\edneiirh.dll
C:\WINDOWS\system32\enfudsfv.dll
C:\WINDOWS\system32\ESHOPEE.exe
C:\WINDOWS\system32\fcxcigwq.dll
C:\WINDOWS\system32\fieakmkl.dll
C:\WINDOWS\system32\fjjkolci.dll
C:\WINDOWS\system32\ggpcjvcf.dll
C:\WINDOWS\system32\gheqwhlg.ini
C:\WINDOWS\system32\gkpuntpi.ini
C:\WINDOWS\system32\glhwqehg.dll
C:\WINDOWS\system32\gljnpukf.dll
C:\WINDOWS\system32\gqjfrenw.dll
C:\WINDOWS\system32\hcwwokgk.dll
C:\WINDOWS\system32\imfrpqel.dll
C:\WINDOWS\system32\iptnupkg.dll
C:\WINDOWS\system32\jjiejvdj.dll
C:\WINDOWS\system32\jnjhraoe.dll
C:\WINDOWS\system32\jriukfik.dll
C:\WINDOWS\system32\jtatqqge.dll
C:\WINDOWS\system32\kbdu.dll
C:\WINDOWS\system32\ldinfo.ldr
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\msole32.exe
C:\WINDOWS\system32\nmeqvrtr.dll
C:\WINDOWS\system32\nnvnwpqc.dll
C:\WINDOWS\system32\ofexmsbd.dll
C:\WINDOWS\system32\oiukxdnw.dll
C:\WINDOWS\system32\puhienht.dll
C:\WINDOWS\system32\qwgicxcf.ini
C:\WINDOWS\system32\rfjufkyj.dll
C:\WINDOWS\system32\rthxweed.dll
C:\WINDOWS\system32\rtrvqemn.ini
C:\WINDOWS\system32\sbmludmy.dll
C:\WINDOWS\system32\sgibjhip.dll
C:\WINDOWS\system32\sgsowsff.dll
C:\WINDOWS\system32\smante~1
C:\WINDOWS\system32\stfv.bin
C:\WINDOWS\system32\sznf.ascii
C:\WINDOWS\system32\thneihup.ini
C:\WINDOWS\system32\vfsdufne.ini
C:\WINDOWS\system32\vxddsk.exe
C:\WINDOWS\system32\whtnyjxv.dll
C:\WINDOWS\system32\wintsvsu32.exe
C:\WINDOWS\system32\wjdqdyni.dll
C:\WINDOWS\system32\wml.exe
C:\WINDOWS\system32\wnerfjqg.ini
C:\WINDOWS\system32\ymdulmbs.ini
C:\WINDOWS\system32\yrbqkhsy.dll
C:\WINDOWS\troy44.exe
C:\WINDOWS\vxddsk.exe
C:\WINDOWS\wbeCheck.exe
C:\WINDOWS\wbeInst$.exe
C:\WINDOWS\wml.exe
C:\WINDOWS\xadbrk.dll
C:\WINDOWS\xadbrk.exe
C:\WINDOWS\xadbrk.exe
C:\WINDOWS\xxxvideo.exe