This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infected with various Viruses

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Thanks for reading…

My son downloaded an exe that infected this computer, and now I am inundated with virus reports via NAV and SpyBot S&D.

NAV reports trojans and various other viruses - sysmtem keeps hijacking my hosts file and have problems reachin various sites including gmail and google. Lots of ads popups and redirections

Here is the HJT log please help this is my work computer and I'm struglin' at the moment !!!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:51:57 PM, on 3/18/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20978)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Quebecor World\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\MDAEMON7.2\App\MDaemon.exe
C:\WINDOWS\system32\mnmsrvc.exe
C:\Program Files\MySQL\MySQL Server 5.1\bin\mysqld.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\MDAEMON7.2\App\CFEngine.exe
C:\MDAEMON7.2\SpamAssassin\MDSpamD.exe
C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\vmnat.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Program Files\DynDNS Updater\DynDNS.exe
C:\WINDOWS\VistaDrive\VistaDrive.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ASUS\AASP\1.00.23\aaCenter.exe
C:\Program Files\DU Meter\DUMeter.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Symantec AntiVirus\DoScan.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe
C:\Program Files\Pure Networks\Network Magic\nmapp.exe
C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
C:\Program Files\VMware\VMware Workstation\vmware-tray.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Documents and Settings\edsdev\My Documents\Install\mTorrent\utorrent.exe
C:\PROGRA~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\Documents and Settings\edsdev\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\DOCUME~1\edsdev\LOCALS~1\Temp\e5mc9l.exe
C:\DOCUME~1\edsdev\LOCALS~1\Temp\e5mc9l.exe
C:\DOCUME~1\edsdev\LOCALS~1\Temp\pk4m80.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\httpd\OHTTPD.exe
C:\Inetpub\MBY\Source\SSL_Email.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ntdll64.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\edsdev\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Documents and Settings\edsdev\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\edsdev\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://securityresponse.symantec.com/avcen…?vid=4294905956
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} - C:\WINDOWS\system32\geBsrOfD.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [VistaDrive] C:\WINDOWS\VistaDrive\VistaDrive.exe
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe
O4 - HKLM\..\Run: [JMB36X Configure] C:\WINDOWS\system32\JMRaidSetup.exe boot
O4 - HKLM\..\Run: [AsusServiceProvider] C:\Program Files\ASUS\AASP\1.00.23\aaCenter.exe
O4 - HKLM\..\Run: [AsusStartupHelp] C:\Program Files\ASUS\AASP\1.00.23\AsRunHelp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [CTCheck] C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [nmctxth] "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe 1
O4 - HKLM\..\Run: [vmware-tray] "C:\Program Files\VMware\VMware Workstation\vmware-tray.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Lkululaqocubalep] rundll32.exe "C:\WINDOWS\Twamanite.dll",e
O4 - HKLM\..\Run: [Oxirilecol] rundll32.exe "C:\WINDOWS\oziwulevefifizo.dll",e
O4 - HKLM\..\Run: [f437e6ac] rundll32.exe "C:\WINDOWS\system32\uuitakvn.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [µTorrent] "C:\Documents and Settings\edsdev\My Documents\Install\mTorrent\utorrent.exe"
O4 - HKCU\..\Run: [Nero PhotoShow Media Manager] C:\PROGRA~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Documents and Settings\edsdev\My Documents\Install\mTorrent\utorrent.exe"
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\edsdev\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [12ZFG94-F641-2SF-K31P-5N1ER6H6L2] C:\RECYCLER\S-1-5-21-1626365692-8186809043-412549959-6939\service.exe
O4 - HKCU\..\Run: [12CFG914-K641-25SF-N35P] C:\RECYCLER\S-1-5-21-0243336033-3052116373-381863308-1853\vslena1.exe
O4 - HKCU\..\Run: [12CFG515-K641-55SF-N55P] C:\RECYCLER\S-1-5-21-0243336035-3055115375-381863305-1553\vslmq.exe
O4 - HKCU\..\Run: [gzgk03iivxnxf2gqm] C:\DOCUME~1\edsdev\LOCALS~1\Temp\j36equ.exe
O4 - HKCU\..\Run: [i2tbd3k1ns] C:\DOCUME~1\edsdev\LOCALS~1\Temp\si4zkw.exe
O4 - HKCU\..\Run: [cneas0532z0nifnwwnvbzmorwv] C:\DOCUME~1\edsdev\LOCALS~1\Temp\fi29un01mj.exe
O4 - HKCU\..\Run: [butqgxgsvn41w0ijm76x1c7zj0po4vd9f90givc28mk] C:\DOCUME~1\edsdev\LOCALS~1\Temp\nnvwx8f6o.exe
O4 - HKCU\..\Run: [nfsabdw8yuyvixyvkspdjixfj9u] C:\DOCUME~1\edsdev\LOCALS~1\Temp\uxmhx54klt.exe
O4 - HKCU\..\Run: [zqmqs8gldq8hj4ew93jchai2cl2se32nsszrk1naga6lm] C:\DOCUME~1\edsdev\LOCALS~1\Temp\vmx08vac2.exe
O4 - HKCU\..\Run: [pqwq6bx6lf] C:\DOCUME~1\edsdev\LOCALS~1\Temp\actjw2kmbgqej.exe
O4 - HKCU\..\Run: [z69ksu8c1] C:\DOCUME~1\edsdev\LOCALS~1\Temp\n81h569e9bvn.exe
O4 - HKCU\..\Run: [f13o4ccm1clhkszn41kigugdsirug9t53lakraasoo] C:\DOCUME~1\edsdev\LOCALS~1\Temp\pk4m80.exe
O4 - HKCU\..\Run: [birwxu7pz70l2k45peok03cw3tr5gabzgimkwd0d5i] C:\DOCUME~1\edsdev\LOCALS~1\Temp\bbq6vv3adby.exe
O4 - HKCU\..\Run: [Windows Resurections] C:\DOCUME~1\edsdev\LOCALS~1\Temp\e5mc9l.exe
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')
O4 - Startup: OHTTPD.exe.lnk = C:\httpd\OHTTPD.exe
O4 - Global Startup: Quebecor World VPN Client.lnk = C:\Program Files\Quebecor World\VPN Client\vpngui.exe
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\docume~1\edsdev\locals~1\temp\ntdll64.dll
O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware workstation\vsocklib.dll
O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware workstation\vsocklib.dll
O10 - Unknown file in Winsock LSP: c:\docume~1\edsdev\locals~1\temp\ntdll64.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/u…can_unicode.cab
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/26.26/uploader2.cab
O16 - DPF: {4788DE0A-3552-49EA-AC8C-233DA52523B9} (AxLoaderPassword Class) - http://www.blackberry.com/devicesoftware/AxLoader.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1228840181047
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1228840173656
O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} (View22RTE Class) - http://hgtv.view22.com/view22/app/view22rte.cab
O16 - DPF: {BCFA4759-1193-4EC3-92A0-F03F6461DA78} (TABSFileup Class) - http://ibbank.net/manual/TABSFileupU.cab
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} (Photodex Presenter AX control) - http://www.photodex.com/pxplay.cab
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://quebecorworld.webex.com/client/T26L…bex/ieatgpc.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: intu-qt2007 - {026BF40D-BA05-467B-9F1F-AD0D7A3F5F11} - C:\Program Files\QuickTax 2007\ic2007pp.dll
O20 - Winlogon Notify: gebsrofd - C:\WINDOWS\SYSTEM32\geBsrOfD.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Indexing Service (CiSvc) - Unknown owner - C:\WINDOWS\system32\cisvc.exe (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Quebecor World\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: DynDNS Updater Service (DynDNS_Updater_Service) - Kana Solution - C:\Program Files\DynDNS Updater\DynDNS.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate1c9858574dbdb80) (gupdate1c9858574dbdb80) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: MDaemon email server (MDaemon) - Alt-N Technologies, Ltd. - C:\MDAEMON7.2\App\MDaemon.exe
O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: Pure Networks Platform Service (nmservice) - Cisco Systems, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SiSoftware Deployment Agent Service (SandraAgentSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Professional Business 2009.SP2\RpcAgentSrv.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: VMware Agent Service (ufad-ws60) - VMware, Inc. - C:\Program Files\VMware\VMware Workstation\vmware-ufad.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C:\WINDOWS\

–
End of file - 21591 bytes


Thanks
Ian
Due to the large numbers of HJT logs being posted, there are four things that you need to be aware of.

1) If you have already posted this log at another forum, you need to post here that you have done so and this topic will be closed.
Multiple posting not only ties up valuable resources, but could also result is some unpleasant side-effects for your system if you follow two sets of instructions at the same time.
If, during research, an identical log is identified at another forum, this thread will be closed.

2) If you don't post a meaningful reply to any of my posts within five days, this thread will be closed. Due to limited free time, I can only have so many open threads at any one time and if yours isn't active, somebody else's will be.
If, by omission, the thread hasn't be closed after five days and you post, it will just serve as a reminder to me to close it.
Please note that "I just dropped in to say Hi!" isn't a meaningful reply!

3) Malware removal is a tricky business, and malware writers don't tend to worry about the damage their creations do, so it is advisable to back-up all important files BEFORE we start. Although most cases have a successful conclusion, on occasion things don't go according to plan and it is better to be prepared for the worst.

4) Back-ups can get lost or damaged, so make two if the files are that important to you!

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Take a trip to this webpage for download links and instructions for running Combofix by sUBs: http://www.bleepingcomputer.com/combofix/how-to-use-combofix *
  • Please be aware that this tool may require the PC to be rebooted so close any programs you have open before you start.
  • When CF has finished, it will produce a log - C:\ComboFix.txt - copy and paste it into your next reply.
  • Post a fresh HJT log as well.
  • Let me know how the PC is behaving.
* There are two points to note from the instructions page:

1) The Recovery Console.

It is recommended that you install this as, in certain circumstances, it may be the difference between a successful repair and a reformat. If you are uncertain as to whether or not you already have the Recovery Console installed, simply run CF and it will prompt you if it does not detect it.
CF will complete it's removal tasks without the installation of the Console, so you are free to choose whether you want to complete this step, but it is in your interests to do so.

2) Disabling your Anti-Virus.

CF has been the victim of false-positive detections on occasion and a resident AV may incorrectly identify and delete part of the tool which won't do it much good. If you don't disable your AV, you may not get the results you hoped for!

Also, run HJT and click on Open the Misc Tools section.
  • Click Open Uninstall Manager…
  • Click Save list… and save it to your Desktop.
  • Copy and paste the file uninstall_list.txt into your next reply.
Thanks for your reply

Ran combofix here is the log

ComboFix 09-03-18.01 - EdsDev 2009-03-19 14:41:43.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1385 [GMT -7:00]
Running from: c:\documents and settings\[removed]\My Documents\Install\ComBoFix\ComboFix.exe
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated)
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\edsdev\LOCALS~1\Temp\mousehook.dll
c:\docume~1\edsdev\LOCALS~1\Temp\ntdll64.dll
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\edsdev\Application Data\inst.exe
c:\windows\system32\ahtn.htm
c:\windows\system32\dNTvyyxx.ini
c:\windows\system32\dNTvyyxx.ini2
c:\windows\system32\drivers\seneka.sys
c:\windows\system32\EfhkmUvw.ini
c:\windows\system32\EfhkmUvw.ini2
c:\windows\system32\elrzsc.dll
c:\windows\system32\gbtlroqy.dll
c:\windows\system32\init32.exe
c:\windows\system32\kqdqhomf.dll
c:\windows\system32\ntdll64.exe
c:\windows\system32\nvkatiuu.ini
c:\windows\system32\nvkatiuu.ini2
c:\windows\system32\nvkatiuu.tmp
c:\windows\system32\ovfsthkdhjhwloqrpyeniktbaprrpojeehoiav.dll
c:\windows\system32\ovfsthqcabprkyxfewmnntoafnhifjnmxdrtov.dll
c:\windows\system32\ovfsthsfqplouwtgscnqnyiiembldqtdsqdyua.dll
c:\windows\system32\Plugins
c:\windows\system32\Plugins\ml\ml_pmp_device_My Zen.ini
c:\windows\system32\Pncrt.dll
c:\windows\system32\pqpYIkkj.ini
c:\windows\system32\pqpYIkkj.ini2
c:\windows\system32\test.ttt
c:\windows\system32\tmp.reg
c:\windows\system32\warning.gif
c:\windows\system32\win32hlp.cnf
c:\windows\system32\yqefodfi.dll
c:\windows\system32\yqorltbg.ini

—– BITS: Possible infected sites —–

hxxp://sunmicro.ht.rd.llnw.net
Infected copy of c:\windows\system32\userinit.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\userinit.exe



.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_ovfsthxiofwrsmbwynlgkxcejdxxuehfcbidya
——-\Service_SENEKA


((((((((((((((((((((((((( Files Created from 2009-02-19 to 2009-03-19 )))))))))))))))))))))))))))))))
.

2009-03-19 07:33 . 2009-03-19 07:33 12,288 –a—— C:\mtaueu.exe
2009-03-18 20:31 . 2009-03-18 20:31 133,632 –a—— c:\windows\oziwulevefifizo.dll
2009-03-18 20:18 . 2009-03-19 12:08 43 –a—— c:\windows\system32\ovfsthecsborddxddeltvujdlvmfkrlotytirx.dat
2009-03-18 20:12 . 2009-03-18 20:12 0 –a—— c:\windows\system32\drivers\ovfsth.sys
2009-03-18 20:09 . 2009-03-19 14:54 106,094 –a—— c:\windows\system32\drivers\glaide32.sys
2009-03-18 20:09 . 2009-03-19 14:54 106,094 –a—— c:\windows\system32\drivers\a436c795.sys
2009-03-18 20:08 . 2009-03-19 07:33 124,416 –a—— C:\lwoa.exe
2009-03-18 20:08 . 2009-03-18 20:08 99,328 –a—— C:\klil.exe
2009-03-18 20:08 . 2009-03-18 20:08 41,984 –a—— c:\windows\Twamanite.dll
2009-03-18 20:08 . 2009-03-18 20:08 41,984 –a—— C:\pctbuvw.exe
2009-03-18 20:08 . 2009-03-19 07:33 41,984 –a—— C:\eoxxwqw.exe
2009-03-18 20:08 . 2009-03-19 07:33 27,648 –a—— C:\mbackyt.exe
2009-03-18 20:08 . 2009-03-19 14:11 23,539 –a—— c:\windows\system32\ovfsthbxwbcxghiuksoxoivlrqkjjonlfwkvdh.dat
2009-03-18 20:08 . 2009-03-19 07:33 10,240 –a—— C:\wkaqjah.exe
2009-03-18 20:08 . 2009-03-19 07:33 2 –a—— C:\-197663229
2009-03-17 20:06 . 2009-03-18 07:10 d——– c:\program files\BPFTP Server
2009-03-17 20:06 . 2009-03-17 20:06 563,200 –a—— c:\windows\BPFTPSERVER.EXE
2009-03-17 20:06 . 2009-03-17 20:06 463 –a—— c:\windows\FTPsrv.ini
2009-03-17 20:06 . 2009-03-17 20:06 0 –a—— c:\windows\Hitometer_UL.top
2009-03-17 20:06 . 2009-03-17 20:06 0 –a—— c:\windows\Hitometer_DL.top
2009-03-14 22:35 . 2009-03-14 22:35 d——– c:\program files\GPLGS
2009-03-14 22:35 . 2009-03-14 22:35 d——– c:\program files\Acro Software
2009-03-14 22:35 . 2007-07-12 22:33 87,552 –a—— c:\windows\system32\cpwmon2k.dll
2009-03-12 17:48 . 2009-01-09 12:19 1,089,593 ——— c:\windows\system32\dllcache\ntprint.cat
2009-03-12 16:45 . 2009-03-12 16:45 685,056 –a—— c:\windows\isRS-000.tmp
2009-03-12 16:45 . 2009-02-11 10:19 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-03-12 16:44 . 2009-02-11 10:19 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-12 15:53 . 2009-03-12 15:53 d——– c:\windows\system32\XPSViewer
2009-03-12 15:53 . 2009-03-12 15:53 d——– c:\program files\Reference Assemblies
2009-03-12 15:52 . 2009-03-12 17:29 d——– c:\windows\SxsCaPendDel
2009-03-12 15:52 . 2009-03-12 15:53 d——– C:\469437b12f102a211470bb85325447
2009-03-12 15:52 . 2008-07-06 05:06 1,676,288 ——— c:\windows\system32\xpssvcs.dll
2009-03-12 15:52 . 2008-07-06 05:06 1,676,288 ——— c:\windows\system32\dllcache\xpssvcs.dll
2009-03-12 15:52 . 2008-07-06 03:50 597,504 ——— c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-03-12 15:52 . 2008-07-06 05:06 575,488 ——— c:\windows\system32\xpsshhdr.dll
2009-03-12 15:52 . 2008-07-06 05:06 575,488 ——— c:\windows\system32\dllcache\xpsshhdr.dll
2009-03-12 15:52 . 2008-07-06 05:06 117,760 ——— c:\windows\system32\prntvpt.dll
2009-03-12 15:52 . 2008-07-06 05:06 89,088 ——— c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-03-12 15:42 . 2008-06-17 12:02 8,461,312 ——— c:\windows\system32\dllcache\shell32.dll
2009-03-12 15:42 . 2008-12-04 23:54 144,896 ——— c:\windows\system32\dllcache\schannel.dll
2009-03-11 17:09 . 2009-03-11 17:09 d——– c:\documents and settings\All Users\Application Data\NCH Swift Sound
2009-02-27 11:16 . 2009-02-27 11:16 d——– c:\program files\LG Software Innovations

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-19 21:54 ——— d—–w c:\program files\Symantec AntiVirus
2009-03-19 21:54 ——— d—–w c:\documents and settings\NetworkService\Application Data\VMware
2009-03-19 21:54 ——— d—–w c:\documents and settings\All Users\Application Data\VMware
2009-03-19 21:37 ——— d—–w c:\documents and settings\edsdev\Application Data\uTorrent
2009-03-19 21:12 ——— d—–w c:\documents and settings\All Users\Application Data\Google Updater
2009-03-19 14:35 ——— d—–w c:\documents and settings\edsdev\Application Data\Skype
2009-03-19 07:04 ——— d—–w c:\program files\DynDNS Updater
2009-03-19 03:11 ——— d—–w c:\program files\DU Meter
2009-03-16 23:33 ——— d—–w c:\program files\nbpro42
2009-03-15 16:22 ——— d—–w c:\documents and settings\edsdev\Application Data\dvdcss
2009-03-14 01:42 ——— d—–w c:\documents and settings\edsdev\Application Data\Vso
2009-03-13 00:54 ——— d—–w c:\program files\Java
2009-03-13 00:46 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-03-13 00:29 ——— d—–w c:\program files\Spybot - Search & Destroy
2009-03-13 00:29 ——— d—–w c:\program files\Microsoft Silverlight
2009-03-13 00:29 ——— d—–w c:\program files\Malwarebytes' Anti-Malware
2009-03-13 00:21 ——— d—–r c:\program files\Skype
2009-03-13 00:18 ——— d—–w c:\documents and settings\All Users\Application Data\Skype
2009-03-13 00:09 ——— d—–w c:\documents and settings\edsdev\Application Data\skypePM
2009-03-12 23:08 ——— d—–w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-03-12 22:53 ——— d—–w c:\program files\MSBuild
2009-03-01 01:16 ——— d—–w c:\program files\WinTidy
2009-02-27 18:18 ——— d—–w c:\documents and settings\All Users\Application Data\1Click DVD Copy Pro
2009-02-12 22:12 ——— d—–w c:\documents and settings\edsdev\Application Data\VMware
2009-02-11 00:14 ——— d—–w c:\program files\Google
2009-02-10 03:41 ——— d—–w c:\documents and settings\edsdev\Application Data\foobar2000
2009-02-10 03:29 ——— d—–w c:\program files\foobar2000
2009-02-09 22:46 ——— d—–w c:\program files\NCH Swift Sound
2009-02-06 03:19 ——— d—–w c:\program files\Xtralogic
2009-01-29 21:36 ——— d—–w c:\documents and settings\edsdev\Application Data\Unity
2009-01-29 21:31 ——— d—–w c:\program files\Unity
2009-01-29 21:30 ——— d—–w c:\program files\OneGlobalConnect
2009-01-29 21:30 ——— d—–w c:\program files\Common Files\Adobe AIR
2009-01-26 21:30 ——— d—–w c:\program files\Microsoft Virtual PC
2009-01-26 01:42 ——— d—–w c:\documents and settings\edsdev\Application Data\Windows Search
2009-01-26 01:37 ——— d—–w c:\program files\Windows Desktop Search
2009-01-23 01:43 ——— d—–w c:\documents and settings\edsdev\Application Data\Windows Desktop Search
2009-01-21 07:20 ——— d—–w c:\documents and settings\All Users\Application Data\Rosetta Stone
2009-01-21 01:32 ——— d—–w c:\documents and settings\edsdev\Application Data\Winamp
2009-01-21 01:31 ——— d—–w c:\program files\Winamp
2009-01-21 00:54 ——— d—–w c:\program files\VIA
2009-01-20 07:07 ——— d—–w c:\program files\Rosetta Stone
2009-01-20 05:11 ——— d—–w c:\program files\Common Files\logishrd
2009-01-20 05:09 ——— d—–w c:\program files\Logitech
2009-01-20 05:08 ——— d—–w c:\documents and settings\All Users\Application Data\LogiShrd
2009-01-19 07:26 ——— d—–w c:\documents and settings\edsdev\Application Data\Photodex
2009-01-19 06:53 ——— d—–w c:\program files\Photodex Presenter
2009-01-15 15:07 319,488 —-a-w c:\windows\HideWin.exe
2008-12-31 20:20 75 —-a-w c:\documents and settings\edsdev\fixdns.bat
2008-11-22 00:10 47,360 —-a-w c:\documents and settings\edsdev\Application Data\pcouffin.sys
2008-04-24 14:51 56,912 —-a-w c:\documents and settings\edsdev\g2mdlhlpx.exe
2007-12-18 19:59 32 —-a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2007-07-20 22:23 996 —-a-w c:\documents and settings\edsdev\jc627.dat
2007-06-19 04:12 24,192 —-a-w c:\documents and settings\edsdev\usbsermptxp.sys
2007-06-19 04:12 22,768 —-a-w c:\documents and settings\edsdev\usbsermpt.sys
2007-05-27 21:16 87,608 —-a-w c:\documents and settings\edsdev\Application Data\ezpinst.exe
2007-05-20 23:33 61 —-a-w c:\documents and settings\edsdev\QUICKLOG.BAT
2008-12-01 19:59 27,976 —-a-w c:\program files\mozilla firefox\plugins\atgpcdec.dll
2008-12-01 19:59 126,360 —-a-w c:\program files\mozilla firefox\plugins\atgpcext.dll
2008-12-01 19:59 46,408 —-a-w c:\program files\mozilla firefox\plugins\atmccli.dll
2008-08-07 16:03 98,712 —-a-w c:\program files\mozilla firefox\plugins\ieatgpc.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"µTorrent"="c:\documents and settings\edsdev\My Documents\Install\mTorrent\utorrent.exe" [2009-02-09 270128]
"Nero PhotoShow Media Manager"="c:\progra~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe" [2006-01-13 249856]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-13 68856]
"uTorrent"="c:\documents and settings\edsdev\My Documents\Install\mTorrent\utorrent.exe" [2009-02-09 270128]
"CTSyncU.exe"="c:\program files\Creative\Sync Manager Unicode\CTSyncU.exe" [2007-07-17 868352]
"Google Update"="c:\documents and settings\edsdev\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-02 133104]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-03-06 24095528]
"12ZFG94-F641-2SF-K31P-5N1ER6H6L2"="c:\recycler\S-1-5-21-1626365692-8186809043-412549959-6939\service.exe" [2009-03-18 43008]
"12CFG914-K641-25SF-N35P"="c:\recycler\S-1-5-21-0243336033-3052116373-381863308-1853\vslena1.exe" [2009-03-18 25118]
"12CFG515-K641-55SF-N55P"="c:\recycler\S-1-5-21-0243336035-3055115375-381863305-1553\vslmq.exe" [2009-03-19 25118]
""="c:\docume~1\edsdev\LOCALS~1\Temp\gbjqnt0.exe" [2009-03-19 10241]
"Windows Resurections"="c:\docume~1\edsdev\LOCALS~1\Temp\gbjqnt0.exe" [2009-03-19 10241]
"Diagnostic Manager"="c:\docume~1\edsdev\LOCALS~1\Temp\2518866424.exe" [2009-03-19 22529]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VistaDrive"="c:\windows\VistaDrive\VistaDrive.exe" [2006-10-05 280779]
"JMB36X IDE Setup"="c:\windows\JM\JMInsIDE.exe" [2006-10-30 36864]
"JMB36X Configure"="c:\windows\system32\JMRaidSetup.exe" [2006-10-30 1953792]
"AsusServiceProvider"="c:\program files\ASUS\AASP\1.00.23\aaCenter.exe" [2007-01-05 597504]
"AsusStartupHelp"="c:\program files\ASUS\AASP\1.00.23\AsRunHelp.exe" [2006-12-28 363008]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-19 7700480]
"DU Meter"="c:\program files\DU Meter\DUMeter.exe" [2004-08-25 1465856]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-11-21 52840]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2007-03-14 125632]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-02-05 849280]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2007-04-23 228088]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-02-18 2221352]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2008-02-28 570664]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2008-03-14 233472]
"CTCheck"="c:\program files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe" [2007-11-06 397312]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 116040]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2008-09-14 648488]
"nmapp"="c:\program files\Pure Networks\Network Magic\nmapp.exe" [2008-12-10 705832]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-04-19 86016]
"HDAudDeck"="c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe" [2008-04-10 29757440]
"vmware-tray"="c:\program files\VMware\VMware Workstation\vmware-tray.exe" [2008-10-29 96816]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-12-20 2656528]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-09-12 36352]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-12 148888]
"Lkululaqocubalep"="c:\windows\Twamanite.dll" [2009-03-18 41984]
"Oxirilecol"="c:\windows\oziwulevefifizo.dll" [2009-03-18 133632]
"nwiz"="nwiz.exe" [2007-04-19 c:\windows\system32\nwiz.exe]
"MsmqIntCert"="mqrt.dll" [2008-04-13 c:\windows\system32\mqrt.dll]
"Framework Windows"="frmwrk32.exe" [2009-03-19 c:\windows\system32\frmwrk32.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="shell32" [X]
"nltide_3"="advpack.dll" [2008-12-20 c:\windows\system32\advpack.dll]

c:\documents and settings\BA\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]

c:\documents and settings\edsdev\Start Menu\Programs\Startup\
OHTTPD.exe.lnk - c:\httpd\OHTTPD.exe [2007-05-19 237568]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Quebecor World VPN Client.lnk - c:\program files\Quebecor World\VPN Client\vpngui.exe [2008-02-28 1537064]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 1 (0x1)
"DisableTaskMgr"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"NoFolderOptions"= 1 (0x1)
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-436374069-1972579041-839522115-1005\Scripts\Logon\0\0]
"Script"=numlock.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-436374069-1972579041-839522115-1006\Scripts\Logon\0\0]
"Script"=numlock.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-436374069-1972579041-839522115-1012\Scripts\Logon\0\0]
"Script"=numlock.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-436374069-1972579041-839522115-1013\Scripts\Logon\0\0]
"Script"=numlock.vbs

[HKLM\~\startupfolder\C:^Documents and Settings^edsdev^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\edsdev\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^edsdev^Start Menu^Programs^Startup^Quick'n Easy FTP Server.lnk]
path=c:\documents and settings\edsdev\Start Menu\Programs\Startup\Quick'n Easy FTP Server.lnk
backup=c:\windows\pss\Quick'n Easy FTP Server.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
–a—— 2009-02-09 20:19 270128 c:\documents and settings\edsdev\My Documents\Install\mTorrent\utorrent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"NMIndexingService"=3 (0x3)
"NBService"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mqsvc.exe"=
"c:\\MDAEMON7.2\\App\\MDaemon.exe"=
"c:\\Documents and Settings\\edsdev\\My Documents\\Install\\mTorrent\\utorrent.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
"c:\\WINDOWS\\system32\\ftp.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\httpd\\OHTTPD.exe"=
"c:\\Inetpub\\MBY\\Go\\MBY.dll"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Professional Business 2009.SP2\\RpcAgentSrv.exe"=
"c:\\Program Files\\VMware\\VMware Workstation\\vmware-authd.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Professional Business 2009.SP2\\WNt500x86\\RpcSandraSrv.exe"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone V3\\RosettaStoneVersion3.exe"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone V3\\support\\bin\\RosettaStoneLtdServices.exe"=
"c:\\Program Files\\BPFTP Server\\bpftpserver.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"18681:TCP"= 18681:TCP:BitComet 18681 TCP
"18681:UDP"= 18681:UDP:BitComet 18681 UDP
"27127:TCP"= 27127:TCP:BitComet 27127 TCP
"27127:UDP"= 27127:UDP:BitComet 27127 UDP
"22200:TCP"= 22200:TCP:BitComet 22200 TCP
"22200:UDP"= 22200:UDP:BitComet 22200 UDP
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"465:TCP"= 465:TCP:SSLGmail
"67:UDP"= 67:UDP:DHCP Discovery Service
""=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R2 MDaemon;MDaemon email server;c:\mdaemon7.2\App\MDaemon.exe [2007-05-19 1539072]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2008-01-19 24652]
R2 vmci;VMware vmci;c:\windows\system32\drivers\vmci.sys [2008-10-29 54960]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-03-07 101936]
R3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1e51x86.sys [2009-01-15 38400]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2009-01-15 222976]
S1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys –> c:\program files\SUPERAntiSpyware\SASKUTIL.sys [?]
S2 FCF;FCF;c:\windows\system32\svchost.exe:exe.exe []
S2 gupdate1c9858574dbdb80;Google Update Service (gupdate1c9858574dbdb80);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-02 133104]
S2 sdryo;Sdryo;c:\windows\System32\svchost.exe -k netsvcs [2004-08-11 14336]
S2 uamyf;uamyf;c:\windows\System32\svchost.exe -k netsvcs [2004-08-11 14336]
S3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\atl01_xp.sys [2007-05-18 35840]
S3 SandraAgentSrv;SiSoftware Deployment Agent Service;c:\program files\SiSoftware\SiSoftware Sandra Professional Business 2009.SP2\RpcAgentSrv.exe [2008-12-31 98488]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [2007-03-14 116416]

— Other Services/Drivers In Memory —

*NewlyCreated* - beep

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
boepnhadyk
Hiancofpw
Sdryo
uamyf
.
Contents of the 'Scheduled Tasks' folder

2009-03-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2009-03-19 c:\windows\Tasks\fixdns.job
- c:\documents and settings\edsdev\fixdns.bat [2008-12-31 13:20]

2009-03-19 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-02 15:27]

2009-03-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-436374069-1972579041-839522115-1005.job
- c:\documents and settings\edsdev\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-02 16:50]

2008-10-02 c:\windows\Tasks\Project1.job
- c:\delphi6\Bin\Project1.exe [2008-11-13 02:10]

2009-03-19 c:\windows\Tasks\SSL_Email.job
- c:\inetpub\MBY\Source\SSL_Email.exe [2009-02-05 09:53]

2009-03-19 c:\windows\Tasks\User_Feed_Synchronization-{DA8DAFB1-3A66-4C0F-B30A-BEB362FEFD3C}.job
- c:\windows\system32\msfeedssync.exe [2007-02-10 18:18]
.
- - - - ORPHANS REMOVED - - - -

BHO-{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} - (no file)
HKLM-Run-Adobe Photo Downloader - c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
Notify-gebsrofd - (no file)
MSConfigStartUp-LogitechCommunicationsManager - c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
MSConfigStartUp-LogitechQuickCamRibbon - c:\program files\Logitech\QuickCam10\QuickCam10.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://my.yahoo.com/
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = hxxp://securityresponse.symantec.com/avcenter/cgi-bin/virauto.cgi?vid=4294905956
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
LSP: c:\program files\VMware\VMware Workstation\vsocklib.dll
Trusted Zone: facebook.com\register
TCP: {4AA393DC-E66B-4ECF-B05E-E696BF2FAA88} = 192.168.0.1
Handler: intu-qt2007 - {026BF40D-BA05-467b-9F1F-AD0D7A3F5F11} - c:\program files\QuickTax 2007\ic2007pp.dll
DPF: {BCFA4759-1193-4EC3-92A0-F03F6461DA78} - hxxp://ibbank.net/manual/TABSFileupU.cab
FF - ProfilePath - c:\documents and settings\edsdev\Application Data\Mozilla\Firefox\Profiles\9v7pnvnr.default\
FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/
FF - plugin: c:\documents and settings\edsdev\Application Data\Mozilla\plugins\npPxPlay.dll
FF - plugin: c:\documents and settings\edsdev\Local Settings\Application Data\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa2.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npatgpc.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npsharedview.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll

—- FIREFOX POLICIES —-
FF - user.js: general.useragent.extra.zencast - Creative ZENcast v2.00.13.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-19 14:54:30
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HDAudDeck = c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe 1????????????????????????????????????????????????

scanning hidden files …


c:\windows\system32\frmwrk32.exe 27648 bytes executable

scan completed successfully
hidden files: 1

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet007\Services\fcf]
"ImagePath"="c:\windows\system32\svchost.exe:exe.exe"

[HKEY_LOCAL_MACHINE\System\ControlSet007\Services\MySQL]
"ImagePath"="\"c:\program files\MySQL\MySQL Server 5.1\bin\mysqld\" –defaults-file=\"c:\program files\MySQL\MySQL Server 5.1\my.ini\" MySQL"

[HKEY_LOCAL_MACHINE\System\ControlSet007\Services\6edef7de]
"ImagePath"="\SystemRoot\System32\drivers\6edef7de.sys"

[HKEY_LOCAL_MACHINE\System\ControlSet007\Services\a436c795]
"ImagePath"="\SystemRoot\System32\drivers\a436c795.sys"
–

[HKEY_LOCAL_MACHINE\System\ControlSet007\Services\glaide32]
"ImagePath"="\??\c:\windows\system32\drivers\glaide32.sys"
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
c:\windows\system32\msdtc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\InterVideo\DeviceService\DevSvc.exe
c:\windows\system32\CTSVCCDA.EXE
c:\program files\Quebecor World\VPN Client\cvpnd.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
c:\windows\system32\mnmsrvc.exe
c:\program files\MySQL\MySQL Server 5.1\bin\mysqld.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\IoctlSvc.exe
c:\program files\Photodex\ProShowProducer\scsiaccess.exe
c:\windows\system32\snmp.exe
c:\mdaemon7.2\App\CFEngine.exe
c:\mdaemon7.2\SpamAssassin\MDSpamD.exe
c:\program files\Symantec AntiVirus\Rtvscan.exe
c:\windows\system32\vmnat.exe
c:\windows\system32\searchindexer.exe
c:\windows\system32\mqsvc.exe
c:\program files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
c:\program files\VMware\VMware Workstation\vmware-authd.exe
c:\windows\system32\vmnetdhcp.exe
c:\program files\DynDNS Updater\DynDNS.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\mqtgsvc.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
c:\windows\system32\rundll32.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\logishrd\LQCVFX\COCIManager.exe
c:\windows\system32\rundll32.exe
c:\program files\Windows Live\Messenger\usnsvc.exe
.
**************************************************************************
.
Completion time: 2009-03-19 15:02:05 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-19 22:01:57
ComboFix2.txt 2008-04-13 18:59:02

Pre-Run: 140,348,325,888 bytes free
Post-Run: 140,356,968,448 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

Current=7 Default=7 Failed=6 LastKnownGood=9 Sets=1,2,3,4,5,6,7,8,9
460
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~

Here is the uninstall list

1Click DVD Copy Pro [removed]
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
7-Zip 4.62
Acoustica MP3 CD Burner
Ad-Aware 2007
Adobe AIR
Adobe AIR
Adobe Anchor Service CS3
Adobe Asset Services CS3
Adobe Bridge CS3
Adobe Bridge Start Meeting
Adobe Camera Raw 4.0
Adobe CMaps
Adobe Default Language CS3
Adobe Device Central CS3
Adobe Dreamweaver CS3
Adobe Dreamweaver CS3
Adobe ExtendScript Toolkit 2
Adobe ExtendScript Toolkit 2
Adobe Extension Manager CS3
Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Flex Builder 3
Adobe Help Viewer CS3
Adobe PDF Library Files
Adobe Photoshop Album 2.0
Adobe Reader 8.1.3
Adobe Setup
Adobe Setup
Adobe Shockwave Player
Adobe Type Support
Adobe Update Manager CS3
Adobe Version Cue CS3 Client
AnyDVD
Apple Mobile Device Support
Apple Software Update
Atheros Communications Inc.® AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver
Attansic Giga Ethernet Utility
Attansic L1 Gigabit Ethernet Driver
Attribute Changer 5.23
AudibleManager
AusLogics Disk Defrag
Autopano Pro
BlackBerry Desktop Software 4.2.2
BlackBerry Desktop Software 4.2.2
Bonjour
Borland Delphi 6
BulletProof FTP Server (remove only)
CleanUp!
ConvertXtoDVD [removed]
ConvertXtoDVD 2.99.10.600
ConvertXtoDVD [removed]
CPL All-in-One
Creative System Information
Creative ZEN
Critical Update for Windows Media Player 11 (KB959772)
CutePDF Writer 2.7
Defraggler (remove only)
Dell Printer Software Uninstall
Destinator PC Portal Maps Installer
DivX Content Uploader
DivX Converter
DivX Player
DivX Web Player
DivxToDVD 0.5.2
DU Meter
DVD Flick
DVD Shrink 3.2
DynDNS Updater 3.1
Express Burn
ExpressQuantumGrid 4 Suite for Delphi 6
FolderIcon XP 1.0 - MeaningData.com
foobar2000 v0.9.6.2
Google Earth
Google Earth Pro
Google Update Helper
Google Updater
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB915800-v4)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB961118)
Icon Restore 1.0
Imagistik Image Viewer
ImgBurn
InterVideo DeviceService
InterVideo DVDCopy5
iTunes
Java™ 6 Update 12
Java™ 6 Update 2
Java™ 6 Update 3
Java™ 6 Update 5
Java™ 6 Update 6
Java™ 6 Update 7
Java™ SE Runtime Environment 6 Update 1
JMB36X Raid Configurer
Kaspersky Online Scanner
K-Lite Codec Pack 4.4.2 (Full)
LiveUpdate 3.1 (Symantec Corporation)
Logitech Harmony Remote Software 7
Logitech Legacy USB Camera Driver Package
Logitech QuickCam
Logitech QuickCam Driver Package
Logitech Updater
Malwarebytes' Anti-Malware
Media Converter SA Edition
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 1.1 SP1 with KB886903 Hotfix
Microsoft .NET Framework 2.0 SDK - ENU
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office Live Meeting 2005
Microsoft Office Live Meeting 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft SharedView (Beta)
Microsoft Silverlight
Microsoft SQL Server 2000
Microsoft SQL Server Management Studio Express
Microsoft Virtual PC 2007 SP1
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 SP1 Redistributable
Microsoft Visual J# 1.1 Redistributable Package
Microsoft Visual J# 2.0 Redistributable Package
Mozilla Firefox (3.0.7)
MSXML 4.0 SP2 (KB936181)
MSXML 6.0 Parser (KB933579)
MySQL Server 5.1
MySQL Tools for 5.0
Nero 8
Nero PhotoShow Deluxe 4
neroxml
Network Magic
NVIDIA Drivers
OneGlobalConnect
PC Probe II
Photodex Presenter
Photomatix Pro version 3.0
PhotoME
Picasa 3
PowerISO
ProShow Producer
QuickPar 0.9
QuickTax 2007
QuickTime
QVT/Term
Realtek High Definition Audio Driver
Remote Control USB Driver
Rosetta Stone V3
Roxio Media Manager
Security Update for 2007 Microsoft Office System (KB951550)
Security Update for 2007 Microsoft Office System (KB951944)
Security Update for 2007 Microsoft Office System (KB958439)
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Microsoft Office Excel 2007 (KB958437)
Security Update for Microsoft Office OneNote 2007 (KB950130)
Security Update for Microsoft Office PowerPoint 2007 (KB951338)
Security Update for Microsoft Office Publisher 2007 (KB950114)
Security Update for Microsoft Office system 2007 (KB954326)
Security Update for Microsoft Office system 2007 (KB956828)
Security Update for Microsoft Office Word 2007 (KB956358)
Security Update for Visio 2007 (KB947590)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
SimpleDivX
SiSoftware Sandra Professional Business 2009.SP2
Skype™ 4.0
SMC Barricade Print Server Monitor
SnagIt32 v4.3
Sony Noise Reduction Plug-In 2.0e
Sony Sound Forge 9.0
Spelling Dictionaries Support For Adobe Reader 8
Spybot - Search & Destroy
Symantec AntiVirus
ThumbView_Lite 1.0
TreeSize Free V1.77
Undelete Plus 2.8
UnInstall Icon Restore 1.0
Unity Web Player
Unlocker 1.8.5
Update for Microsoft Office 2007 Help for Common Features (KB957244)
Update for Microsoft Office Access 2007 Help (KB957241)
Update for Microsoft Office Excel 2007 Help (KB957242)
Update for Microsoft Office InfoPath 2007 Help (KB957243)
Update for Microsoft Office OneNote 2007 Help (KB957245)
Update for Microsoft Office Outlook 2007 (KB952142)
Update for Microsoft Office Outlook 2007 Help (KB957246)
Update for Microsoft Office PowerPoint 2007 Help (KB957247)
Update for Microsoft Office Publisher 2007 Help (KB957249)
Update for Microsoft Office Word 2007 Help (KB957252)
Update for Microsoft Script Editor Help (KB957253)
Update for Office 2007 (KB946691)
Update for Outlook 2007 Junk Email Filter (kb962871)
Update for Windows XP (KB943729)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
VCRedistSetup
VHD Utility 1.0.2
VIA Platform Device Manager
VideoLAN VLC media player 0.8.6a
Viewpoint Manager (Remove Only)
Viewpoint Media Player
Virtual Earth 3D (Beta)
Vista Drive Indicator!
VMware Workstation
VNC Free Edition 4.1.2
VPN Client
WebEx
Winamp
WinAVI Video Converter
Windows Imaging Component
Windows Live installer
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Media Format 11 runtime
Windows Media Player 11
Windows Search 4.0
Windows XP Service Pack 3
WinRAR archiver
WinTidy 1.0.11
WinUtilities 5.2
WinZip 11.1
ZENcast Organizer

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

ANd here is the latest HJT log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:05:02 PM, on 3/19/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20978)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Quebecor World\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\MDAEMON7.2\App\MDaemon.exe
C:\WINDOWS\system32\mnmsrvc.exe
C:\Program Files\MySQL\MySQL Server 5.1\bin\mysqld.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
C:\WINDOWS\System32\snmp.exe
C:\MDAEMON7.2\App\CFEngine.exe
C:\WINDOWS\system32\svchost.exe
C:\MDAEMON7.2\SpamAssassin\MDSpamD.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\vmnat.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\Program Files\DynDNS Updater\DynDNS.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\VistaDrive\VistaDrive.exe
C:\Program Files\ASUS\AASP\1.00.23\aaCenter.exe
C:\Program Files\DU Meter\DUMeter.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe
C:\Program Files\Pure Networks\Network Magic\nmapp.exe
C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
C:\Program Files\VMware\VMware Workstation\vmware-tray.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Documents and Settings\edsdev\My Documents\Install\mTorrent\utorrent.exe
C:\PROGRA~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\Documents and Settings\edsdev\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\httpd\OHTTPD.exe
C:\DOCUME~1\edsdev\LOCALS~1\Temp\gbjqnt0.exe
C:\DOCUME~1\edsdev\LOCALS~1\Temp\gbjqnt0.exe
C:\WINDOWS\system32\frmwrk32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Inetpub\MBY\Source\SSL_Email.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\DOCUME~1\edsdev\LOCALS~1\Temp\3195461628.exe
C:\DOCUME~1\edsdev\LOCALS~1\Temp\3222805378.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://securityresponse.symantec.com/avcen…?vid=4294905956
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [VistaDrive] C:\WINDOWS\VistaDrive\VistaDrive.exe
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe
O4 - HKLM\..\Run: [JMB36X Configure] C:\WINDOWS\system32\JMRaidSetup.exe boot
O4 - HKLM\..\Run: [AsusServiceProvider] C:\Program Files\ASUS\AASP\1.00.23\aaCenter.exe
O4 - HKLM\..\Run: [AsusStartupHelp] C:\Program Files\ASUS\AASP\1.00.23\AsRunHelp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [CTCheck] C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [nmctxth] "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe 1
O4 - HKLM\..\Run: [vmware-tray] "C:\Program Files\VMware\VMware Workstation\vmware-tray.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Lkululaqocubalep] rundll32.exe "C:\WINDOWS\Twamanite.dll",e
O4 - HKLM\..\Run: [Oxirilecol] rundll32.exe "C:\WINDOWS\oziwulevefifizo.dll",e
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [µTorrent] "C:\Documents and Settings\edsdev\My Documents\Install\mTorrent\utorrent.exe"
O4 - HKCU\..\Run: [Nero PhotoShow Media Manager] C:\PROGRA~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Documents and Settings\edsdev\My Documents\Install\mTorrent\utorrent.exe"
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\edsdev\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [12ZFG94-F641-2SF-K31P-5N1ER6H6L2] C:\RECYCLER\S-1-5-21-1626365692-8186809043-412549959-6939\service.exe
O4 - HKCU\..\Run: [12CFG914-K641-25SF-N35P] C:\RECYCLER\S-1-5-21-0243336033-3052116373-381863308-1853\vslena1.exe
O4 - HKCU\..\Run: [12CFG515-K641-55SF-N55P] C:\RECYCLER\S-1-5-21-0243336035-3055115375-381863305-1553\vslmq.exe
O4 - HKCU\..\Run: [Windows Resurections] C:\DOCUME~1\edsdev\LOCALS~1\Temp\gbjqnt0.exe
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')
O4 - Startup: OHTTPD.exe.lnk = C:\httpd\OHTTPD.exe
O4 - Global Startup: Quebecor World VPN Client.lnk = C:\Program Files\Quebecor World\VPN Client\vpngui.exe
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware workstation\vsocklib.dll
O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware workstation\vsocklib.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/u…can_unicode.cab
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/26.26/uploader2.cab
O16 - DPF: {4788DE0A-3552-49EA-AC8C-233DA52523B9} (AxLoaderPassword Class) - http://www.blackberry.com/devicesoftware/AxLoader.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1228840181047
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1228840173656
O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} (View22RTE Class) - http://hgtv.view22.com/view22/app/view22rte.cab
O16 - DPF: {BCFA4759-1193-4EC3-92A0-F03F6461DA78} (TABSFileup Class) - http://ibbank.net/manual/TABSFileupU.cab
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} (Photodex Presenter AX control) - http://www.photodex.com/pxplay.cab
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://quebecorworld.webex.com/client/T26L…bex/ieatgpc.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: intu-qt2007 - {026BF40D-BA05-467B-9F1F-AD0D7A3F5F11} - C:\Program Files\QuickTax 2007\ic2007pp.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Indexing Service (CiSvc) - Unknown owner - C:\WINDOWS\system32\cisvc.exe (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Quebecor World\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: DynDNS Updater Service (DynDNS_Updater_Service) - Kana Solution - C:\Program Files\DynDNS Updater\DynDNS.exe
O23 - Service: FCF (fcf) - Unknown owner - C:\WINDOWS\system32\svchost.exe:exe.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate1c9858574dbdb80) (gupdate1c9858574dbdb80) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: MDaemon email server (MDaemon) - Alt-N Technologies, Ltd. - C:\MDAEMON7.2\App\MDaemon.exe
O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: Pure Networks Platform Service (nmservice) - Cisco Systems, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SiSoftware Deployment Agent Service (SandraAgentSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Professional Business 2009.SP2\RpcAgentSrv.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: VMware Agent Service (ufad-ws60) - VMware, Inc. - C:\Program Files\VMware\VMware Workstation\vmware-ufad.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C:\WINDOWS\

–
End of file - 19846 bytes


System is reporting Spyware problem and also OS wants me to install Windows XP Professional CDRom as some system files have been changed

2 Files were reported as problems when system rebooted

Downloader.MisLeaderApp… 2 diferent files were classed under this warning

Over to you…

Thanks again
You've still got multiple slime onboard. Download Malwarebytes' Anti-Malware from here and save it to your Desktop - unless you already have it, in which case skip to the "updating" bit below.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • Ensure a checkmark is placed next to both Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware and then click Finish.
  • If an update is found, it will download and install the latest version - you'll need to clear it with your firewall.
  • Once the program has loaded, select Perform full scan and then Scan.
  • When the scan has finished, click OK and then Show Results to view the results - no surprise there!
  • If MBAM finds anything, check the box(es) and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt
Let me have the MBAM log, a fresh HJT log (run in Normal Mode) AND a description of how your PC is behaving.
Ran the Malware scan (took a while!!) and it found 28 objects that I removed and the program asked to me to reboot which I did

The system is much better but I am having problems accessing the internet when clicking on a link in a mail message, and the icons on the desktop do not repaint themselves when I move a window over them!! thats new, its as if something is stopping the desktop from repainting… ooops the icons repainted themselves after about 5 mins!!

Nav still reports it needs to reboot to perform remedial action, I am not seeing any NAV reports of trojans or viruses. It seems stable apart from the click a link problem

Here is the HJT log followed by Malware's report

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:32:32 PM, on 3/19/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20978)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Quebecor World\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\MDAEMON7.2\App\MDaemon.exe
C:\WINDOWS\system32\mnmsrvc.exe
C:\Program Files\MySQL\MySQL Server 5.1\bin\mysqld.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\MDAEMON7.2\App\CFEngine.exe
C:\MDAEMON7.2\SpamAssassin\MDSpamD.exe
C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\vmnat.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
C:\Inetpub\MBY\Source\SSL_Email.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\Program Files\DynDNS Updater\DynDNS.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\VistaDrive\VistaDrive.exe
C:\Program Files\ASUS\AASP\1.00.23\aaCenter.exe
C:\Program Files\DU Meter\DUMeter.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe
C:\Program Files\Pure Networks\Network Magic\nmapp.exe
C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
C:\Program Files\VMware\VMware Workstation\vmware-tray.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\PROGRA~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Documents and Settings\edsdev\My Documents\Install\mTorrent\utorrent.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\Documents and Settings\edsdev\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\httpd\OHTTPD.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\MICROS~1\Office12\OUTLOOK.EXE
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://securityresponse.symantec.com/avcen…?vid=4294905956
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [VistaDrive] C:\WINDOWS\VistaDrive\VistaDrive.exe
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe
O4 - HKLM\..\Run: [JMB36X Configure] C:\WINDOWS\system32\JMRaidSetup.exe boot
O4 - HKLM\..\Run: [AsusServiceProvider] C:\Program Files\ASUS\AASP\1.00.23\aaCenter.exe
O4 - HKLM\..\Run: [AsusStartupHelp] C:\Program Files\ASUS\AASP\1.00.23\AsRunHelp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [CTCheck] C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [nmctxth] "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe 1
O4 - HKLM\..\Run: [vmware-tray] "C:\Program Files\VMware\VMware Workstation\vmware-tray.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [µTorrent] "C:\Documents and Settings\edsdev\My Documents\Install\mTorrent\utorrent.exe"
O4 - HKCU\..\Run: [Nero PhotoShow Media Manager] C:\PROGRA~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Documents and Settings\edsdev\My Documents\Install\mTorrent\utorrent.exe"
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\edsdev\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')
O4 - Startup: OHTTPD.exe.lnk = C:\httpd\OHTTPD.exe
O4 - Global Startup: Quebecor World VPN Client.lnk = C:\Program Files\Quebecor World\VPN Client\vpngui.exe
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware workstation\vsocklib.dll
O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware workstation\vsocklib.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/u…can_unicode.cab
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/26.26/uploader2.cab
O16 - DPF: {4788DE0A-3552-49EA-AC8C-233DA52523B9} (AxLoaderPassword Class) - http://www.blackberry.com/devicesoftware/AxLoader.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1228840181047
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1228840173656
O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} (View22RTE Class) - http://hgtv.view22.com/view22/app/view22rte.cab
O16 - DPF: {BCFA4759-1193-4EC3-92A0-F03F6461DA78} (TABSFileup Class) - http://ibbank.net/manual/TABSFileupU.cab
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} (Photodex Presenter AX control) - http://www.photodex.com/pxplay.cab
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://quebecorworld.webex.com/client/T26L…bex/ieatgpc.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: intu-qt2007 - {026BF40D-BA05-467B-9F1F-AD0D7A3F5F11} - C:\Program Files\QuickTax 2007\ic2007pp.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Indexing Service (CiSvc) - Unknown owner - C:\WINDOWS\system32\cisvc.exe (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Quebecor World\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: DynDNS Updater Service (DynDNS_Updater_Service) - Kana Solution - C:\Program Files\DynDNS Updater\DynDNS.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate1c9858574dbdb80) (gupdate1c9858574dbdb80) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: MDaemon email server (MDaemon) - Alt-N Technologies, Ltd. - C:\MDAEMON7.2\App\MDaemon.exe
O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: Pure Networks Platform Service (nmservice) - Cisco Systems, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SiSoftware Deployment Agent Service (SandraAgentSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Professional Business 2009.SP2\RpcAgentSrv.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: VMware Agent Service (ufad-ws60) - VMware, Inc. - C:\Program Files\VMware\VMware Workstation\vmware-ufad.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C:\WINDOWS\

–
End of file - 18945 bytes
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Malwarebytes' Anti-Malware 1.34
Database version: 1873
Windows 5.1.2600 Service Pack 3

3/19/2009 6:04:45 PM
mbam-log-2009-03-19 (18-04-45).txt

Scan type: Full Scan (C:\|)
Objects scanned: 405633
Time elapsed: 2 hour(s), 14 minute(s), 52 second(s)

Memory Processes Infected: 3
Memory Modules Infected: 1
Registry Keys Infected: 1
Registry Values Infected: 7
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 50

Memory Processes Infected:
C:\Documents and Settings\edsdev\Local Settings\temp\gbjqnt0.exe (Trojan.Agent) -> Unloaded process successfully.
C:\Documents and Settings\edsdev\Local Settings\temp\gbjqnt0.exe (Trojan.Agent) -> Unloaded process successfully.
C:\Documents and Settings\edsdev\Local Settings\temp\3222805378.exe (Trojan.Agent) -> Unloaded process successfully.

Memory Modules Infected:
C:\WINDOWS\waylk.dll (Trojan.Agent) -> Delete on reboot.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\uamyf (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\windows resurections (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\12cfg515-k641-55sf-n55p (Trojan.Backdoor) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lkululaqocubalep (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\oxirilecol (Trojan.Agent) -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\12zfg94-f641-2sf-k31p-5n1er6h6l2 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\12cfg914-k641-25sf-n35p (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\diagnostic manager (Trojan.Downloader) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\edsdev\Local Settings\temp\gbjqnt0.exe (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\waylk.dll (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\edsdev\Local Settings\temp\3222805378.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-0243336035-3055115375-381863305-1553\vslmq.exe (Trojan.Backdoor) -> Quarantined and deleted successfully.
C:\eoxxwqw.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\lwoa.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\pctbuvw.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\edsdev\Application Data\bcxuyrd.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\edsdev\Application Data\bcxuyrd1.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\edsdev\Local Settings\temp\107.exe (Trojan.Backdoor) -> Quarantined and deleted successfully.
C:\Documents and Settings\edsdev\Local Settings\temp\2518866424.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\edsdev\Local Settings\temp\3195461628.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\edsdev\My Documents\Install\XP\une\XP_key-essentials\XP_keygen.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\edsdev\My Documents\Install\XP\XPKeyGen\AllXPKeygenMTSv1.00.4\XPKey v5.12.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\edsdev\My Documents\Install\XP\XPKeyGen\AllXPKeygenMTSv1.00.4\ServicePack1\How to Install the Windows XP SP1_files\XPKey.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\DOCUME~1\edsdev\LOCALS~1\Temp\ntdll64.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\ntdll64.exe.vir (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\gbtlroqy.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\kqdqhomf.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\userinit.exe.vir (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\yqefodfi.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7B8710BA-3E6E-43DB-BACC-E270F76A5335}\RP781\A0098241.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7B8710BA-3E6E-43DB-BACC-E270F76A5335}\RP781\A0098242.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7B8710BA-3E6E-43DB-BACC-E270F76A5335}\RP781\A0098252.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7B8710BA-3E6E-43DB-BACC-E270F76A5335}\RP781\A0098265.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7B8710BA-3E6E-43DB-BACC-E270F76A5335}\RP781\A0098271.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7B8710BA-3E6E-43DB-BACC-E270F76A5335}\RP781\A0098272.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7B8710BA-3E6E-43DB-BACC-E270F76A5335}\RP781\A0098277.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7B8710BA-3E6E-43DB-BACC-E270F76A5335}\RP781\A0098278.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7B8710BA-3E6E-43DB-BACC-E270F76A5335}\RP781\A0098315.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7B8710BA-3E6E-43DB-BACC-E270F76A5335}\RP781\A0098285.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7B8710BA-3E6E-43DB-BACC-E270F76A5335}\RP781\A0098287.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7B8710BA-3E6E-43DB-BACC-E270F76A5335}\RP781\A0098288.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7B8710BA-3E6E-43DB-BACC-E270F76A5335}\RP781\A0098310.exe (Trojan.Backdoor) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7B8710BA-3E6E-43DB-BACC-E270F76A5335}\RP781\A0098312.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7B8710BA-3E6E-43DB-BACC-E270F76A5335}\RP781\A0098313.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7B8710BA-3E6E-43DB-BACC-E270F76A5335}\RP781\A0098314.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ntdll64.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\Twamanite.dll (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\oziwulevefifizo.dll (Trojan.Agent) -> Delete on reboot.
C:\RECYCLER\S-1-5-21-1626365692-8186809043-412549959-6939\service.exe (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\drivers\ovfsth.sys (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ovfsthbxwbcxghiuksoxoivlrqkjjonlfwkvdh.dat (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ovfsthecsborddxddeltvujdlvmfkrlotytirx.dat (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\glaide32.sys (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\drivers\beep.sys (Fake.Beep.Sys) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\warning.gif (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ahtn.htm (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\win32hlp.cnf (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\edsdev\Local Settings\temp\208673846.exe (Trojan.Downloader) -> Delete on reboot.


I will reboot and let NAV do its thing to see if that error goes away

Looking forward to your response to these latest logs

Thanks again for all your help
You may need to set Windows to show All Hidden Files and Folders.
Instructions can be found here.
** These files are hidden to stop you accidentally removing something important.
It is advisable to hide them again after fixing your computer. **

1) Run HijackThis as you did to generate a log, but this time click on 'Do a system scan only'.
Place a checkmark in the boxes to the left of the following entries, by clicking on them:

O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C:\WINDOWS\

CLOSE ALL OPEN WINDOWS AND BROWSERS - EXCEPT HJT and click on Fix checked

2) Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
3) Remove any/all of the following files/folders that you can find:

Files

C:\mtaueu.exe
c:\windows\oziwulevefifizo.dll
c:\windows\system32\drivers\ovfsth.sys
c:\windows\system32\drivers\a436c795.sys
C:\klil.exe
c:\windows\Twamanite.dll
C:\mbackyt.exe
C:\wkaqjah.exe
C:\-197663229
c:\windows\system32\frmwrk32.exe
c:\windows\System32\drivers\6edef7de.sys"
c:\windows\System32\drivers\a436c795.sys"


As an example:
To delete C:\WINDOWS\system32\filetogo.bye
Double click the My Computer icon on your Desktop.
Double click on Local Disc (C:)
Double click on the Windows folder,
Double click on the System 32 folder,
Right click on filetogo.bye and from the menu that appears, click on 'Delete'


4) Boot into normal mode.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Run HJT and click on Open the Misc Tools section.
  • Click the Open ADS Spy… button.
  • Uncheck "Quick scan (Windows base folder only)"
  • Click the Scan button to the left of the Save log… button.
  • If there are any detections when the scan has completed, click the Save log… button.
  • When the "Save ADS Spy log…" window open, click the Save button.
  • The log will be displayed in a Notepad window and when you close it, it will be saved by default to your Desktop.
  • Copy and paste the contents of the file adsspy.txt into your next reply, or let me know that the scan was clean.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Pay a visit to the Kaspersky Online Scanner 7 - I.E. is preferred for this scan.
  • Read the Information panel and then click Accept.
  • Allow the ActiveX download if necessary.
  • Both the anti-virus engine and database will need to be downloaded, which may take a little time.
  • Once this has been completed, select My Computer from the Scan section on the left hand side.
  • Put the kettle on!
  • Although it is recommended by Kaspersky that you should disable your anti-virus scanner before starting this scan, it should work OK with it still active - it does on my PC.
    Although you may find the scan speed increases if you carry out this step, I never like to disable my resident scanner while online, so I don't.
  • When the scan has completed, click View scan report at the bottom.
  • Click Save Report As…
  • Enter a name for the file in the Filename: text box and then click the down arrow to the right of Save as type: and select text file (*.txt)
  • Click Save and pick a location for the file - the Desktop is always handy.
Copy and paste the report into your next reply along with a fresh HJT log, run in Normal Mode, and a description of how your PC is behaving.

Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.
Wow that took a while

Looks like I need to replace NAV. Computer seems to be running normally - NAV can scan now.I get the occasional redirection in the browser.

Here is the HJT log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:25:02 AM, on 3/21/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20978)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Quebecor World\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\MDAEMON7.2\App\MDaemon.exe
C:\WINDOWS\system32\mnmsrvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\MySQL\MySQL Server 5.1\bin\mysqld.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\MDAEMON7.2\App\CFEngine.exe
C:\MDAEMON7.2\SpamAssassin\MDSpamD.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\vmnat.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
C:\WINDOWS\VistaDrive\VistaDrive.exe
C:\Program Files\ASUS\AASP\1.00.23\aaCenter.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\Program Files\DU Meter\DUMeter.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\DynDNS Updater\DynDNS.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe
C:\Program Files\Pure Networks\Network Magic\nmapp.exe
C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
C:\Program Files\VMware\VMware Workstation\vmware-tray.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Documents and Settings\edsdev\My Documents\Install\mTorrent\utorrent.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\Documents and Settings\edsdev\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\httpd\OHTTPD.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Documents and Settings\edsdev\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\edsdev\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\edsdev\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Microsoft Virtual PC\Virtual PC.exe
C:\PROGRA~1\MICROS~1\Office12\OUTLOOK.EXE
C:\Documents and Settings\edsdev\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\edsdev\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://securityresponse.symantec.com/avcen…?vid=4294905956
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O1 - Hosts: 172.23.157.25 intranet.qwinc.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [VistaDrive] C:\WINDOWS\VistaDrive\VistaDrive.exe
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe
O4 - HKLM\..\Run: [JMB36X Configure] C:\WINDOWS\system32\JMRaidSetup.exe boot
O4 - HKLM\..\Run: [AsusServiceProvider] C:\Program Files\ASUS\AASP\1.00.23\aaCenter.exe
O4 - HKLM\..\Run: [AsusStartupHelp] C:\Program Files\ASUS\AASP\1.00.23\AsRunHelp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [CTCheck] C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [nmctxth] "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe 1
O4 - HKLM\..\Run: [vmware-tray] "C:\Program Files\VMware\VMware Workstation\vmware-tray.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [µTorrent] "C:\Documents and Settings\edsdev\My Documents\Install\mTorrent\utorrent.exe"
O4 - HKCU\..\Run: [Nero PhotoShow Media Manager] C:\PROGRA~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Documents and Settings\edsdev\My Documents\Install\mTorrent\utorrent.exe"
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\edsdev\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - Startup: OHTTPD.exe.lnk = C:\httpd\OHTTPD.exe
O4 - Global Startup: Quebecor World VPN Client.lnk = C:\Program Files\Quebecor World\VPN Client\vpngui.exe
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware workstation\vsocklib.dll
O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware workstation\vsocklib.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/u…can_unicode.cab
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/26.26/uploader2.cab
O16 - DPF: {4788DE0A-3552-49EA-AC8C-233DA52523B9} (AxLoaderPassword Class) - http://www.blackberry.com/devicesoftware/AxLoader.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1228840181047
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1228840173656
O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} (View22RTE Class) - http://hgtv.view22.com/view22/app/view22rte.cab
O16 - DPF: {BCFA4759-1193-4EC3-92A0-F03F6461DA78} (TABSFileup Class) - http://ibbank.net/manual/TABSFileupU.cab
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} (Photodex Presenter AX control) - http://www.photodex.com/pxplay.cab
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://quebecorworld.webex.com/client/T26L…bex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4AA393DC-E66B-4ECF-B05E-E696BF2FAA88}: NameServer = 192.168.0.1
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: intu-qt2007 - {026BF40D-BA05-467B-9F1F-AD0D7A3F5F11} - C:\Program Files\QuickTax 2007\ic2007pp.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Indexing Service (CiSvc) - Unknown owner - C:\WINDOWS\system32\cisvc.exe (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Quebecor World\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: DynDNS Updater Service (DynDNS_Updater_Service) - Kana Solution - C:\Program Files\DynDNS Updater\DynDNS.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate1c9858574dbdb80) (gupdate1c9858574dbdb80) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: MDaemon email server (MDaemon) - Alt-N Technologies, Ltd. - C:\MDAEMON7.2\App\MDaemon.exe
O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: Pure Networks Platform Service (nmservice) - Cisco Systems, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SiSoftware Deployment Agent Service (SandraAgentSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Professional Business 2009.SP2\RpcAgentSrv.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: VMware Agent Service (ufad-ws60) - VMware, Inc. - C:\Program Files\VMware\VMware Workstation\vmware-ufad.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C:\WINDOWS\

–
End of file - 19585 bytes



Here is the ADS log file

C:\Documents and Settings\All Users\Application Data\TEMP : 1B682472 (172 bytes)
C:\Documents and Settings\All Users\Application Data\TEMP : A31FAD21 (155 bytes)
C:\Documents and Settings\All Users\Application Data\TEMP : 1B682472 (172 bytes)
C:\Documents and Settings\All Users\Application Data\TEMP : A31FAD21 (155 bytes)
C:\Documents and Settings\BA\Favorites\Botanus.com-Bulbs.url : favicon (2238 bytes)
C:\Documents and Settings\BA\Favorites\Canada Post - business-personal.url : favicon (894 bytes)
C:\Documents and Settings\BA\Favorites\CI Funds Home Page.url : favicon (822 bytes)
C:\Documents and Settings\BA\Favorites\Coast Capital Savings Credit Union - Personal.url : favicon (1150 bytes)
C:\Documents and Settings\BA\Favorites\Contact Us 5th Avenue Theatre.url : favicon (1150 bytes)
C:\Documents and Settings\BA\Favorites\E-cards and Web Cards by Jacquie Lawson, animated e-cards, Christmas cards.url : favicon (9662 bytes)
C:\Documents and Settings\BA\Favorites\Ed Jones.url : favicon (198 bytes)
C:\Documents and Settings\BA\Favorites\Flower Gardening Made Easy Logo Image.url : favicon (3638 bytes)
C:\Documents and Settings\BA\Favorites\Health and Medical Information produced by doctors - MedicineNet.com.url : favicon (1150 bytes)
C:\Documents and Settings\BA\Favorites\Heuchera, new perennials from tissue culture Terra Nova Nurseries.url : favicon (822 bytes)
C:\Documents and Settings\BA\Favorites\hotwire.com Discount airfare, hotel resHotwire.com-Extended Stays America-Bellview North.url : favicon (2238 bytes)
C:\Documents and Settings\BA\Favorites\Pacific Blue Cross BC.url : favicon (2238 bytes)
C:\Documents and Settings\BA\Favorites\Perennials.com Archived Newsletters.url : favicon (894 bytes)
C:\Documents and Settings\BA\Favorites\Perennials.com Welcome to Heritage Perennials.url : favicon (894 bytes)
C:\Documents and Settings\BA\Favorites\Price Reports - EMA.url : favicon (318 bytes)
C:\Documents and Settings\BA\Favorites\Shade gardening tips.url : favicon (3638 bytes)
C:\Documents and Settings\BA\Favorites\Start At Home Home & Garden Television.url : favicon (1406 bytes)
C:\Documents and Settings\BA\Favorites\TD Waterhouse - Markets & Research.url : favicon (318 bytes)
C:\Documents and Settings\BA\Favorites\The New Perennial Club.url : favicon (894 bytes)
C:\Documents and Settings\BA\Favorites\Wayside Gardens Mail order Choice Perennials, Bulbs, Shrubs, and Roses.url : favicon (3638 bytes)
C:\Documents and Settings\edsdev\Favorites\Camera Labs.url : favicon (1406 bytes)
C:\Documents and Settings\edsdev\Favorites\Digital Camera Reviews and News Digital Photography Review Forums, Glossary, FAQ.url : favicon (7782 bytes)
C:\Documents and Settings\edsdev\Favorites\Links\409.url : favicon (894 bytes)
C:\Documents and Settings\edsdev\Favorites\Links\AnandTech.url : favicon (2494 bytes)
C:\Documents and Settings\edsdev\Favorites\Links\ASTALAVISTA.url : favicon (1406 bytes)
C:\Documents and Settings\edsdev\Favorites\Links\AVS Blue Ray players.url : favicon (318 bytes)
C:\Documents and Settings\edsdev\Favorites\Links\AVS Forum Subs.url : favicon (318 bytes)
C:\Documents and Settings\edsdev\Favorites\Links\axxo.url : favicon (318 bytes)
C:\Documents and Settings\edsdev\Favorites\Links\CITIZENWATCH.com Welcome to Citizen Watches Online.url : favicon (25214 bytes)
C:\Documents and Settings\edsdev\Favorites\Links\CNET.url : favicon (1078 bytes)
C:\Documents and Settings\edsdev\Favorites\Links\F1-Live.url : favicon (3262 bytes)
C:\Documents and Settings\edsdev\Favorites\Links\FB.url : favicon (1150 bytes)
C:\Documents and Settings\edsdev\Favorites\Links\Google.url : favicon (1406 bytes)
C:\Documents and Settings\edsdev\Favorites\Links\GrandPrix.url : favicon (1150 bytes)
C:\Documents and Settings\edsdev\Favorites\Links\IQ.url : favicon (1078 bytes)
C:\Documents and Settings\edsdev\Favorites\Links\IQW.PK.url : favicon (6598 bytes)
C:\Documents and Settings\edsdev\Favorites\Links\Malware Project.url : favicon (3638 bytes)
C:\Documents and Settings\edsdev\Favorites\Links\NCIX.url : favicon (1406 bytes)
C:\Documents and Settings\edsdev\Favorites\Links\PB Movies.url : favicon (824 bytes)
C:\Documents and Settings\edsdev\Favorites\Links\Pirate Bay.url : favicon (824 bytes)
C:\Documents and Settings\edsdev\Favorites\Links\QW Topix.url : favicon (1406 bytes)
C:\Documents and Settings\edsdev\Favorites\Links\RADEON.url : favicon (1406 bytes)
C:\Documents and Settings\edsdev\Favorites\Links\The official U.S. time.url : favicon (1406 bytes)
C:\Documents and Settings\edsdev\Favorites\Links\TheFixer.url : favicon (1150 bytes)
C:\Documents and Settings\edsdev\Favorites\Links\Torry's New Components.url : favicon (766 bytes)
C:\Documents and Settings\edsdev\My Documents\Install\google earth\Google Earth Pro 4.0.2737\Crack\Masters of Warez.url : favicon (1406 bytes)
C:\WINDOWS\Cursors\arrow_n.cur : NEDTA.DAT (6144 bytes)

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~

Here is Kaspersky log
——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Saturday, March 21, 2009
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Saturday, March 21, 2009 00:06:35
Records in database: 1942442
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
I:\

Scan statistics:
Files scanned: 294308
Threat name: 23
Infected objects: 42
Suspicious objects: 53
Duration of the scan: 08:10:11


File name / Threat name / Threats count
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02600000.VBN Infected: Trojan.Win32.Agent.btjt 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0FAC0001\4FEDB72B.VBN Infected: Trojan-Downloader.Win32.Agent.bmqq 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0FAC0002\4FEDB74E.VBN Infected: Trojan-Downloader.Win32.Agent.bmqq 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\16C00000\5FC30E18.VBN Infected: not-a-virus:PSWTool.Win32.RAS.g 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\16C00000\5FC30E18.VBN Infected: not-a-virus:PSWTool.Win32.RAS.a 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\38C40000.VBN Infected: Trojan-PSW.Win32.Delf.bnh 1
C:\Documents and Settings\edsdev\Desktop\SmitfraudFix.exe Infected: Hoax.Win32.Renos.dws 1
C:\Documents and Settings\edsdev\Local Settings\Application Data\Google\Chrome\User Data\Default\Cache\f_001e9f Infected: not-a-virus:FraudTool.Win32.SmitFraudFixTool.a 1
C:\Documents and Settings\edsdev\My Documents\Downloads\AVG Anti-Virus 8.0.0 + New Serial Expiry Yr 2025\avg_avwt_stf_all_8_199a1389.exe Infected: Trojan-Downloader.Win32.Agent.bgsp 1
C:\Documents and Settings\edsdev\My Documents\Downloads\BulletProof.FTP.Server.v2.3.1.26.Plus.Crack-Auschwitz\BulletProof.FTP.Server.v2.3.1.26.Plus.Crack-Auschwitz\crack\bpftpserver.exe Infected: Trojan.Win32.Agent.bqrp 1
C:\Documents and Settings\edsdev\My Documents\Downloads\BulletProof.FTP.Server.v2.3.1.26.Plus.Crack-Auschwitz\BulletProof.FTP.Server.v2.3.1.26.Plus.Crack-Auschwitz\ftpsetup.exe Infected: not-a-virus:Server-FTP.Win32.BulletProof.231 1
C:\Documents and Settings\edsdev\My Documents\Downloads\BulletProof.FTP.Server.v2.3.1.26.Plus.Crack-Auschwitz.rar Infected: Trojan.Win32.Agent.bqrp 1
C:\Documents and Settings\edsdev\My Documents\Downloads\BulletProof.FTP.Server.v2.3.1.26.Plus.Crack-Auschwitz.rar Infected: not-a-virus:Server-FTP.Win32.BulletProof.231 1
C:\Documents and Settings\edsdev\My Documents\Downloads\EAVBE32.3.0.669.rar Infected: Trojan.Win32.Monderb.gqa 1
C:\Documents and Settings\edsdev\My Documents\Downloads\Gregs\AntiVirus\AVG Anti-Virus 8.0.0 + New Serial Expiry Yr 2025\avg_avwt_stf_all_8_199a1389.exe Infected: Trojan-Downloader.Win32.Agent.bgsp 1
C:\Documents and Settings\edsdev\My Documents\Downloads\ISTCqdeK_m-su640a.zip Infected: not-a-virus:Server-FTP.Win32.Serv-U.6404 5
C:\Documents and Settings\edsdev\My Documents\Downloads\VSO_ConvertXtoDVD_3.1.0.26___Keygen.rar Infected: Trojan-Dropper.Win32.VB.bme 1
C:\Documents and Settings\edsdev\My Documents\Install\FTPServ-U4.0\sugerman.exe Infected: not-a-virus:Server-FTP.Win32.Serv-U.4103 1
C:\MDAEMON\CFILTER\QUARANT\cf10814464.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf1105713664.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf116242704.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf11876630.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf12357955.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf1264566.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf1280223257.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf13314504.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf135572225.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf1360827061.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf1402514296.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf145416968.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf153961193.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf1550420720.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf1660731978.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf166691006.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf1711118391.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf1744019882.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf1894227187.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf1967818560.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf2000414077.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf203068884.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf2076032334.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf207816707.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf2086416996.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf2152413846.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf22745938.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf236639378.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf2685932465.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf26922105.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf275432208.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf2889521625.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf2905532187.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf291734693.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf3208216832.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf361510496.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf385020558.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf480817995.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf494723438.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf526021813.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf542816120.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf56473610.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf58213043.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf634022930.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf63588657.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf64135614.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf6618363.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf713221553.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf733612958.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf827717476.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf953916768.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf967813058.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON\CFILTER\QUARANT\cf979627900.att Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\MDAEMON7.2\CFilter\QUARANT\cf113953879.txt Infected: Trojan-Spy.HTML.Bayfraud.bu 1
C:\MDAEMON7.2\CFilter\QUARANT\cf116304992.txt Infected: Trojan-Spy.HTML.Bayfraud.dc 1
C:\MDAEMON7.2\CFilter\QUARANT\cf149712901.txt Infected: Trojan-Spy.HTML.Fraud.f 1
C:\MDAEMON7.2\CFilter\QUARANT\cf1579018089.txt Infected: Trojan-Spy.HTML.Bayfraud.dc 1
C:\MDAEMON7.2\CFilter\QUARANT\cf1772430235.txt Infected: Trojan-Spy.HTML.Fraud.l 1
C:\MDAEMON7.2\CFilter\QUARANT\cf1886629983.txt Infected: Trojan-Spy.HTML.Bayfraud.dc 1
C:\MDAEMON7.2\CFilter\QUARANT\cf201056869.txt Infected: Trojan-Spy.HTML.Paylap.dl 1
C:\MDAEMON7.2\CFilter\QUARANT\cf2183920490.txt Infected: Trojan-Spy.HTML.Bayfraud.dc 1
C:\MDAEMON7.2\CFilter\QUARANT\cf2899532106.txt Infected: Trojan-Spy.HTML.Fraud.f 1
C:\MDAEMON7.2\CFilter\QUARANT\cf517424329.txt Infected: Trojan-Spy.HTML.Bayfraud.dc 1
C:\MDAEMON7.2\CFilter\QUARANT\cf82652773.txt Infected: Trojan-Spy.HTML.Bayfraud.dc 1
C:\MDAEMON7.2\CFilter\QUARANT\cf84352865.txt Infected: Trojan-Spy.HTML.Paylap.m 1
C:\Program Files\RealVNC\VNC4\vncconfig.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 1
C:\Program Files\RealVNC\VNC4\vncviewer.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 1
C:\Program Files\RealVNC\VNC4\winvnc4.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 1
C:\Program Files\RealVNC\VNC4\wm_hooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 1
C:\Program Files\Serv-U\ServUAdmin.exe.bak Infected: not-a-virus:Server-FTP.Win32.Serv-U.6404 1
C:\Program Files\Serv-U\ServUDaemon.exe.bak Infected: not-a-virus:Server-FTP.Win32.Serv-U.6404 1
C:\Qoobox\Quarantine\C\DOCUME~1\edsdev\LOCALS~1\Temp\mousehook.dll.vir Infected: Trojan.Win32.Agent.bvxh 1
C:\WINDOWS\BPFTPSERVER.EXE Infected: not-a-virus:Server-FTP.Win32.BulletProof.231 1

The selected area was scanned.
There are a number of files that Kav identifies as malicious: C:\Documents and Settings\edsdev\My Documents\Downloads\AVG Anti-Virus 8.0.0 + New Serial Expiry Yr 2025\avg_avwt_stf_all_8_199a1389.exe Infected: Trojan-Downloader.Win32.Agent.bgsp 1 C:\Documents and Settings\edsdev\My Documents\Downloads\BulletProof.FTP.Server.v2.3.1.26.Plus.Crack-Auschwitz\BulletProof.FTP.Server.v2.3.1.26.Plus.Crack-Auschwitz\crack\bpftpserver.exe Infected: Trojan.Win32.Agent.bqrp 1 C:\Documents and Settings\edsdev\My Documents\Downloads\BulletProof.FTP.Server.v2.3.1.26.Plus.Crack-Auschwitz\BulletProof.FTP.Server.v2.3.1.26.Plus.Crack-Auschwitz\ftpsetup.exe Infected: not-a-virus:Server-FTP.Win32.BulletProof.231 1 C:\Documents and Settings\edsdev\My Documents\Downloads\BulletProof.FTP.Server.v2.3.1.26.Plus.Crack-Auschwitz.rar Infected: Trojan.Win32.Agent.bqrp 1 C:\Documents and Settings\edsdev\My Documents\Downloads\BulletProof.FTP.Server.v2.3.1.26.Plus.Crack-Auschwitz.rar Infected: not-a-virus:Server-FTP.Win32.BulletProof.231 1 C:\Documents and Settings\edsdev\My Documents\Downloads\EAVBE32.3.0.669.rar Infected: Trojan.Win32.Monderb.gqa 1 C:\Documents and Settings\edsdev\My Documents\Downloads\Gregs\AntiVirus\AVG Anti-Virus 8.0.0 + New Serial Expiry Yr 2025\avg_avwt_stf_all_8_199a1389.exe Infected: Trojan-Downloader.Win32.Agent.bgsp 1 C:\Documents and Settings\edsdev\My Documents\Downloads\ISTCqdeK_m-su640a.zip Infected: not-a-virus:Server-FTP.Win32.Serv-U.6404 5 C:\Documents and Settings\edsdev\My Documents\Downloads\VSO_ConvertXtoDVD_3.1.0.26___Keygen.rar Infected: Trojan-Dropper.Win32.VB.bme 1 C:\Documents and Settings\edsdev\My Documents\Install\FTPServ-U4.0\sugerman.exe Infected: not-a-virus:Server-FTP.Win32.Serv-U.4103 1 C:\Program Files\Serv-U\ServUAdmin.exe.bak Infected: not-a-virus:Server-FTP.Win32.Serv-U.6404 1 C:\Program Files\Serv-U\ServUDaemon.exe.bak Infected: not-a-virus:Server-FTP.Win32.Serv-U.6404 1 C:\WINDOWS\BPFTPSERVER.EXE Infected: not-a-virus:Server-FTP.Win32.BulletProof.231 1 I'll leave it too you to decide which of those is legitimately on your system and which isn't - you know your computer better than I do. If you don't recognize it, get rid. I also suggest that you try to avoid acquiring files that offer "cracks" and other methods of avoiding the need to obtain legitimate software as they do tend to harbour nasties - you'd be surprised how inconsiderate malware writers are! I'd like you to delete your copy of ComboFix, download a fresh copy and run it as before, posting the new log and HJT log etc… There won't be any need to install the Recovery Console again as once is enough.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI