This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]Devious New Malware

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello My pc has just been infected by a new virus from China with the following problems: - prevents more well known antivirus programs from working - links given in google search on its exe files cannot be opened, IE would be closed automatically - safe mode disallowed - System Restore disallowed - both files cannot be ended in Task Manager - well known online scans are disallowed though panda was able to indicate this detail only: For meex.exe no obvious problem apparent. Sending report to panda was also disallowed. This scan did not indicate the following files, however, other Chinese sites state this: [] . Opening these folders was disallowed. Another apparent problem is hijacking but I'm not sure if this is related to that virus. However, after installing HijackThis, there is something wrong with the downloaded file, its icon is 'incomplete' and opening HJTsetup would lead to the menu Open With - Choose the program you want to use to open this file:. Perhaps the virus is preventing this as well. Any help would be much appreciated.
Hi! Welcome to the Tom Coyote forums.
My name is Scotty. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research.
Please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
My posts to you will be checked by one of the Forum Admins, so my replies may take a little longer.
Hello menk

Download Deckard's System Scanner (DSS) to your Desktop. Note: You must be logged onto an account with administrator privileges.
  • Close all applications and windows.
  • Double-click on dss.exe to run it, and follow the prompts.
  • When the scan is complete, two text files will open - main.txt <- this one will be maximized and extra.txt<-this one will be minimized
  • Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt and the extra.txt to your post. in your reply

Download and Run ComboFix
  • Download this file from below:

    Here
  • Then double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply with a new HijackThis log.
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

If the above fail, answer the questions below, please.

Do you have access to another computer with a cd drive and burning capabilities or a USB pen drive? If so, is the infected computer still able to connect to the net also?
Hello Scotty

Thank you for assisting. I've downloaded DSS but there was no reaction when double-clicking dss.exe. However I was able to get the log from Combofix:

"yangyq" - 2007-07-14 20:25:19 - ComboFix 07-07-14.6 - Service Pack 2 NTFS


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\ALLUSE~1\APPLIC~1.\microsoft\pctools
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\microsoft\pctools\pctools.dll
C:\Program Files\Common Files\cpush
C:\Program Files\Common Files\cpush\cpush.1dll
C:\Program Files\Common Files\cpush\Uninst.1exe
C:\Program Files\meex.exe
C:\setup.exe
C:\WINDOWS\cnsinfo.dat
C:\WINDOWS\KB611311.log
C:\WINDOWS\mppds.exe
C:\WINDOWS\msimms32.exe
C:\WINDOWS\system32\d3d1caps.srg
C:\WINDOWS\system32\drivers\acpidisk.sys
C:\WINDOWS\system32\mppds.dll
C:\WINDOWS\system32\mprmsgse.axz
C:\WINDOWS\system32\mscpx32r.det
C:\WINDOWS\system32\msimms32.dll
C:\WINDOWS\system32\remotedbg.dll
C:\WINDOWS\system32\upxdnd.dll
C:\WINDOWS\system32\wwzoerx.exe
C:\WINDOWS\temp\~my1.tmp
C:\WINDOWS\upxdnd.exe


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\LEGACY_ACPIDISK
——-\LEGACY_CELINDRV
——-\acpidisk
——-\RemoteDbg


((((((((((((((((((((((((( Files Created from 2007-06-14 to 2007-07-14 )))))))))))))))))))))))))))))))


2007-07-14 20:22 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-14 20:19 d——– C:\Deckard
2007-07-14 19:04 24,576 –a—— C:\WINDOWS\TIMHost.exe
2007-07-14 19:04 11,264 –a—— C:\WINDOWS\system32\TIMHost.dll
2007-07-14 19:01 34 —hs—- C:\Program Files\DLD.DAT
2007-07-13 22:32 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\fssg
2007-07-11 20:50 168,452 –a—— C:\WINDOWS\system32\drivers\mxdispdr.sys
2007-07-10 20:30 99 –a—— C:\WINDOWS\system32\pfdnnt_actions.sys
2007-07-10 18:54 d——– C:\WINDOWS\system32\ActiveScan
2007-07-10 17:27 d——– C:\DOCUME~1\yangyq\APPLIC~1\Skype
2007-07-10 17:24 28,672 –a—— C:\WINDOWS\system32\promote.dll
2007-07-10 17:23 d——– C:\Program Files\Skype
2007-07-09 23:10 42,496 –a—— C:\WINDOWS\system32\sexit.dat
2007-07-09 20:16 44,636 —hs—- C:\Program Files\meex.exe


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-13 11:29:12 14 –sh–w C:\Program Files\.inf
2007-07-09 12:16:43 169 –sh–w C:\Program Files\cfkbyse.inf
2007-07-03 11:59:39 ——– d—–w C:\DOCUME~1\yangyq\APPLIC~1\VoipStunt
2007-06-13 12:29:53 ——– d–h–w C:\Program Files\InstallShield Installation Information
2007-06-13 12:27:58 ——– d—–w C:\Program Files\Veoh Networks
2007-06-13 12:24:51 ——– d—–w C:\Program Files\DivX
2007-05-28 14:34:23 ——– d—–w C:\Program Files\Opera 9
2007-05-24 04:09:11 ——– d—–w C:\Program Files\Windows Live Toolbar
2007-05-23 07:50:03 ——– d—–w C:\Program Files\Windows Desktop Search
2007-05-16 15:12:02 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-16 13:09:19 1,744 —-a-w C:\WINDOWS\system32\d3d9caps.dat
2007-05-16 13:07:43 ——– d—–w C:\Program Files\QuickTime
2007-05-13 14:26:38 1,901 —-a-w C:\WINDOWS\panose.bin
2007-05-12 10:39:34 4,096 —-a-w C:\WINDOWS\d3dx.dat
2007-05-02 01:08:19 2,560 —-a-w C:\WINDOWS\system32\BitCometRes.dll
2007-04-25 14:21:15 144,896 —-a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:23 2,854,400 —-a-w C:\WINDOWS\system32\msi.dll
2007-04-16 14:47:36 33,624 —-a-w C:\WINDOWS\system32\wups.dll
2007-04-16 14:45:54 1,710,936 —-a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-16 14:45:48 549,720 —-a-w C:\WINDOWS\system32\wuapi.dll
2007-04-16 14:45:42 325,976 —-a-w C:\WINDOWS\system32\wucltui.dll
2007-04-16 14:45:36 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
2007-04-16 14:45:28 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
2007-04-16 14:45:20 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-16 14:45:20 43,352 —-a-w C:\WINDOWS\system32\wups2.dll
2007-04-16 14:44:20 271,224 —-a-w C:\WINDOWS\system32\mucltui.dll
2007-04-16 14:44:18 208,248 —-a-w C:\WINDOWS\system32\muweb.dll
2005-04-29 09:27:28 56 –sha-r C:\WINDOWS\system32\13AA3AD2F8.sys
2005-04-29 09:27:28 1,682 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0FA24E3E-422C-4D94-A125-104F32352C90}]
2007-07-10 17:24 28672 –a—— C:\WINDOWS\system32\promote.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
2007-03-29 22:31 394816 –a—— C:\Program Files\BitComet\tools\BitCometBHO_1.1.3.28.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2006-12-15 03:23 440056 –a—— C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" [2006-12-15 03:23]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 13:30]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"cfkbyse"="C:\Program Files\Common Files\System\cfhskjn.exe" [2007-05-31 07:54]
"kwjkpww"="C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe" [2007-05-31 07:54]
"@"="C:\Program Files\Common Files\Microsoft Shared\" [2007-07-10 21:36]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 20:00]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45]
"@"="" []

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Spyware Doctor"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{91B1E846-2BEF-4345-8848-7699C7C9935F}"="C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysWFGQQ2.dll" [2007-07-14 19:03]
"{12311A42-AC1B-158F-FD32-5674345F23A1}"="C:\WINDOWS\system32\dhapri.dll" [2004-08-04 11:13]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=dhapri.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\360rpt.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\360Safe.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\360tray.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\adam.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\AgentSvr.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\AppSvc32.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\ArSwp.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\AST.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\autoruns.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avconsol.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avgrssvc.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\AvMonitor.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avp.com]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avp.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\CCenter.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\ccSvcHst.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\EGHOST.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\FileDsty.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\FTCleanerShell.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\FYFireWall.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\HijackThis.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\IceSword.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\iparmo.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Iparmor.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\isPwdSvc.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kabaload.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KaScrScn.SCR]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KASMain.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KASTask.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KAV32.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KAVDX.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KAVPF.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KAVPFW.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KAVSetup.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KAVStart.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KISLnchr.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KMailMon.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KMFilter.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KPFW32.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KPFW32X.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KPfwSvc.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KRegEx.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KRepair.com]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KsLoader.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KVCenter.kxp]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KvDetect.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KvfwMcl.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KVMonXP.kxp]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KVMonXP_1.kxp]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kvol.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kvolself.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KvReport.kxp]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KVScan.kxp]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KVSrvXP.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KVStub.kxp]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kvupload.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kvwsc.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KvXP.kxp]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KvXP_1.kxp]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KWatch.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KWatch9x.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KWatchX.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\loaddll.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\MagicSet.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\mcconsol.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\mmqczj.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\mmsk.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Navapsvc.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Navapw32.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\nod32.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\nod32krn.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\nod32kui.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NPFMntor.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\PFW.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\PFWLiveUpdate.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\QHSET.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\QQDoctor.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\QQKav.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Ras.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Rav.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\RavMon.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\RavMonD.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\RavStub.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\RavTask.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\RegClean.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\rfwcfg.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\rfwmain.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\rfwsrv.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\RsAgent.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Rsaupd.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\rstrui.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\runiep.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\safelive.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\scan32.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\shcfg32.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\SmartUp.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\SREng.EXE]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\symlcsvc.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\SysSafe.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\TrojanDetector.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Trojanwall.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\TrojDie.kxp]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UIHost.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UmxAgent.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UmxAttachment.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UmxCfg.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UmxFwHlp.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UmxPol.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\upiea.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UpLive.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\USBCleaner.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\vsstat.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\webscanx.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\WoptiClean.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

SafeBoot registry key needs repairs. This machine cannot enter Safe Mode.
~~\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{05a6d150-2de4-11dc-b6d3-00e05e394056}]
AutoRun\command- F:\kwjkpww.exe
explore\Command- F:\kwjkpww.exe
open\Command- F:\kwjkpww.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{07d1e690-463e-11db-9464-00e05e394056}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Toy.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{38cae550-6974-11db-94d0-00e05e394056}]
1\Command- .\RECYCLER\RECYCLER\autorun.exe
2\Command- .\RECYCLER\RECYCLER\autorun.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\RECYCLER\RECYCLER\autorun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{38cae552-6974-11db-94d0-00e05e394056}]
1\Command- .\RECYCLER\RECYCLER\autorun.exe
2\Command- .\RECYCLER\RECYCLER\autorun.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\RECYCLER\RECYCLER\autorun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4c9044d2-9321-11db-8805-00e05e394056}]
Auto\command- RavMonE.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RavMonE.exe e

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{57de17e0-7a09-11db-94f3-00e05e394056}]
AutoRun\command- ~tmp0.1st.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5f3d4c14-f6c7-11db-b636-00e05e394056}]
1\Command- F:\.\recycled\info.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\recycled\info.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{933560f1-29f9-11dc-b6c4-00e05e394056}]
AutoRun\command- F:\kwjkpww.exe
explore\Command- F:\kwjkpww.exe
open\Command- F:\kwjkpww.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{be32d7b0-c2a6-11da-9289-00e05e394056}]
AutoRun\command- EXPLORER.EXE
explore\Command- EXPLORER.EXE
open\Command- EXPLORER.EXE


**************************************************************************

catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-14 20:31:11
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-14 20:33:52 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-07-14 20:33

— E O F —

But I have the same problem as mentioned in my first post with regards HijackThis.

To your last 2 questions, I have access to other pc to burn or copy files with USB and I'm still able to go online with my infected pc, as I'm doing now.
Hello menk

Sorry for the delayed response, but youve had 3 experts and me looking this one over.

Please inset your flashdrive / memory stick first.
download & run this file - Flash_Disinfector.exe

Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\promote.dll
C:\WINDOWS\system32\sexit.dat
C:\Program Files\meex.exe
C:\WINDOWS\TIMHost.exe
C:\WINDOWS\system32\TIMHost.dll
C:\WINDOWS\system32\drivers\mxdispdr.sys
C:\Program Files\.inf
C:\Program Files\cfkbyse.inf
C:\WINDOWS\system32\13AA3AD2F8.sys
C:\Program Files\Common Files\System\cfhskjn.exe
C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0FA24E3E-422C-4D94-A125-104F32352C90}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cfkbyse"=-
"kwjkpww"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{12311A42-AC1B-158F-FD32-5674345F23A1}"=-
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}]
@="DiskDrive" 
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=""
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{05a6d150-2de4-11dc-b6d3-00e05e394056}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{07d1e690-463e-11db-9464-00e05e394056}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{38cae550-6974-11db-94d0-00e05e394056}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{38cae552-6974-11db-94d0-00e05e394056}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4c9044d2-9321-11db-8805-00e05e394056}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5f3d4c14-f6c7-11db-b636-00e05e394056}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{933560f1-29f9-11dc-b6c4-00e05e394056}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{be32d7b0-c2a6-11da-9289-00e05e394056}]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\360rpt.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\360Safe.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\360tray.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\adam.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\AgentSvr.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\AppSvc32.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\ArSwp.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\AST.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\autoruns.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avconsol.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avgrssvc.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\AvMonitor.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avp.com]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avp.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\CCenter.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\ccSvcHst.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\EGHOST.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\FileDsty.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\FTCleanerShell.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\FYFireWall.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\HijackThis.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\IceSword.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\iparmo.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Iparmor.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\isPwdSvc.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kabaload.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KaScrScn.SCR]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KASMain.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KASTask.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KAV32.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KAVDX.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KAVPF.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KAVPFW.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KAVSetup.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KAVStart.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KISLnchr.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KMailMon.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KMFilter.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KPFW32.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KPFW32X.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KPfwSvc.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KRegEx.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KRepair.com]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KsLoader.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KVCenter.kxp]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KvDetect.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KvfwMcl.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KVMonXP.kxp]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KVMonXP_1.kxp]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kvol.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kvolself.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KvReport.kxp]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KVScan.kxp]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KVSrvXP.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KVStub.kxp]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kvupload.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kvwsc.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KvXP.kxp]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KvXP_1.kxp]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KWatch.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KWatch9x.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KWatchX.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\loaddll.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\MagicSet.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\mcconsol.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\mmqczj.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\mmsk.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Navapsvc.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Navapw32.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\nod32.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\nod32krn.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\nod32kui.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NPFMntor.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\PFW.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\PFWLiveUpdate.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\QHSET.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\QQDoctor.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\QQKav.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Ras.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Rav.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\RavMon.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\RavMonD.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\RavStub.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\RavTask.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\RegClean.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\rfwcfg.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\rfwmain.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\rfwsrv.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\RsAgent.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Rsaupd.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\rstrui.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\runiep.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\safelive.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\scan32.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\shcfg32.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\SmartUp.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\SREng.EXE]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\symlcsvc.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\SysSafe.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\TrojanDetector.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Trojanwall.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\TrojDie.kxp]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UIHost.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UmxAgent.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UmxAttachment.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UmxCfg.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UmxFwHlp.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UmxPol.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\upiea.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UpLive.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\USBCleaner.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\vsstat.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\webscanx.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\WoptiClean.exe]

Save this as "CFScript"

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log with a new HijackThis log.
Thank you guys for looking into this! I've downloaded Flash_Disinfector.exe and run it. Only 2 prompts - a popup saying if I have a flash drive, plug it in and click ok to begin (even though I already have the stick in) and, after awhile I got another popup, Finish but no notepad popup for saving the file after clicking Ok. The thing that did happen was My Documents popped up instead though I did not find any .txt file in there. I did this a few times with the same result. Sorry, did I miss a step somewhere?
I don't mean to butt in, but is the Combofix.exe and CFScript.txt on the desktop? If not, please move them to the desktop and try it again. They both need to be on the desktop.

[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

Then post the results log
Yes, the Combofix.exe is on the desktop but there is no CFScript.txt. As I've posted, there was no .txt file appearing after the Flash_Disinfector.exe scan.
Hi Menk

You might be getting a little confused here. Running Flash Disinfect doesnt produce a script. If you have followed that first instruction, we will move on to the next. To make things a little easier Im going to include an attachment in this post.

📎CFScript.txt

Now right-click on the word CFScript.txt above, and click Save Target As. In the window that opens, click on Desktop and then Save, and follow the next instructions.

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log with a new HijackThis log.
Hello Mac70

Yes I was expecting some script to popup. Thanks for enlightening me! :) and here is the log:

"yangyq" - 2007-07-16 20:50:29 - ComboFix 07-07-14.6 - Service Pack 2 NTFS
Command switches used :: C:\Documents and Settings\yangyq\Desktop\index.htm


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Program Files\meex.exe
C:\WINDOWS\mppds.exe
C:\WINDOWS\msimms32.exe
C:\WINDOWS\system32\3222.dll
C:\WINDOWS\system32\mppds.dll
C:\WINDOWS\system32\msimms32.dll
C:\WINDOWS\system32\remotedbg.dll
C:\WINDOWS\system32\upxdnd.dll
C:\WINDOWS\temp\~my1.tmp
C:\WINDOWS\upxdnd.exe


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\LEGACY_CELINDRV
——-\RemoteDbg


((((((((((((((((((((((((( Files Created from 2007-06-16 to 2007-07-16 )))))))))))))))))))))))))))))))


2007-07-16 20:51 34 —hs—- C:\Program Files\DLD.DAT
2007-07-16 09:01 23,552 –a—— C:\WINDOWS\system32\cajcte.dll
2007-07-16 09:01 11,264 –a—— C:\WINDOWS\system32\wbzpvt.dll
2007-07-16 09:00 22,016 –a—— C:\WINDOWS\system32\htqkse.dll
2007-07-15 21:35 26,112 –a—— C:\WINDOWS\system32\nircmd.exe
2007-07-15 18:53 drahs—- C:\autorun.inf
2007-07-14 20:22 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-14 20:19 d——– C:\Deckard
2007-07-14 19:04 27,648 –a—— C:\WINDOWS\TIMHost.exe
2007-07-14 19:04 11,264 –a—— C:\WINDOWS\system32\TIMHost.dll
2007-07-13 22:32 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\fssg
2007-07-11 20:50 168,452 –a—— C:\WINDOWS\system32\drivers\mxdispdr.sys
2007-07-10 20:30 99 –a—— C:\WINDOWS\system32\pfdnnt_actions.sys
2007-07-10 18:54 d——– C:\WINDOWS\system32\ActiveScan
2007-07-10 17:27 d——– C:\DOCUME~1\yangyq\APPLIC~1\Skype
2007-07-10 17:24 28,672 –a—— C:\WINDOWS\system32\promote.dll
2007-07-10 17:23 d——– C:\Program Files\Skype
2007-07-09 23:10 42,496 –a—— C:\WINDOWS\system32\sexit.dat
2007-07-09 20:16 44,636 —hs—- C:\Program Files\meex.exe


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-13 11:29:12 14 –sh–w C:\Program Files\.inf
2007-07-09 12:16:43 169 –sh–w C:\Program Files\cfkbyse.inf
2007-07-03 11:59:39 ——– d—–w C:\DOCUME~1\yangyq\APPLIC~1\VoipStunt
2007-06-13 12:29:53 ——– d–h–w C:\Program Files\InstallShield Installation Information
2007-06-13 12:27:58 ——– d—–w C:\Program Files\Veoh Networks
2007-06-13 12:24:51 ——– d—–w C:\Program Files\DivX
2007-05-28 14:34:23 ——– d—–w C:\Program Files\Opera 9
2007-05-24 04:09:11 ——– d—–w C:\Program Files\Windows Live Toolbar
2007-05-23 07:50:03 ——– d—–w C:\Program Files\Windows Desktop Search
2007-05-16 15:12:02 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-16 13:09:19 1,744 —-a-w C:\WINDOWS\system32\d3d9caps.dat
2007-05-16 13:07:43 ——– d—–w C:\Program Files\QuickTime
2007-05-13 14:26:38 1,901 —-a-w C:\WINDOWS\panose.bin
2007-05-12 10:39:34 4,096 —-a-w C:\WINDOWS\d3dx.dat
2007-05-02 01:08:19 2,560 —-a-w C:\WINDOWS\system32\BitCometRes.dll
2007-04-25 14:21:15 144,896 —-a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:23 2,854,400 —-a-w C:\WINDOWS\system32\msi.dll
2007-04-16 14:47:36 33,624 —-a-w C:\WINDOWS\system32\wups.dll
2007-04-16 14:45:54 1,710,936 —-a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-16 14:45:48 549,720 —-a-w C:\WINDOWS\system32\wuapi.dll
2007-04-16 14:45:42 325,976 —-a-w C:\WINDOWS\system32\wucltui.dll
2007-04-16 14:45:36 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
2007-04-16 14:45:28 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
2007-04-16 14:45:20 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-16 14:45:20 43,352 —-a-w C:\WINDOWS\system32\wups2.dll
2007-04-16 14:44:20 271,224 —-a-w C:\WINDOWS\system32\mucltui.dll
2007-04-16 14:44:18 208,248 —-a-w C:\WINDOWS\system32\muweb.dll
2005-04-29 09:27:28 56 –sha-r C:\WINDOWS\system32\13AA3AD2F8.sys
2005-04-29 09:27:28 1,682 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0FA24E3E-422C-4D94-A125-104F32352C90}]
2007-07-10 17:24 28672 –a—— C:\WINDOWS\system32\promote.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
2007-03-29 22:31 394816 –a—— C:\Program Files\BitComet\tools\BitCometBHO_1.1.3.28.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2006-12-15 03:23 440056 –a—— C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" [2006-12-15 03:23]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 13:30]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"cfkbyse"="C:\Program Files\Common Files\System\cfhskjn.exe" [2007-05-31 07:54]
"kwjkpww"="C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe" [2007-05-31 07:54]
"@"="C:\Program Files\Common Files\Microsoft Shared\" [2007-07-10 21:36]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 20:00]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45]
"@"="" []

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Spyware Doctor"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{91B1E846-2BEF-4345-8848-7699C7C9935F}"="C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysWFGQQ2.dll" [2007-07-16 20:52]
"{12311A42-AC1B-158F-FD32-5674345F23A1}"="C:\WINDOWS\system32\dhapri.dll" [2004-08-04 11:13]
"{26368135-64FA-BC34-DA32-DCF4FD431C92}"="C:\WINDOWS\system32\qhbpri.dll" [2004-08-04 20:58]
"{3495D328-661A-4FB0-BA67-8ACDD1704D1E}"="C:\WINDOWS\system32\3222.dll" []

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=qhbpri.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\360rpt.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\360Safe.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\360tray.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\adam.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\AgentSvr.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\AppSvc32.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\ArSwp.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\AST.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\autoruns.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avconsol.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avgrssvc.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\AvMonitor.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avp.com]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avp.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\CCenter.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\ccSvcHst.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\EGHOST.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\FileDsty.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\FTCleanerShell.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\FYFireWall.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\HijackThis.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\IceSword.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\iparmo.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Iparmor.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\isPwdSvc.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kabaload.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KaScrScn.SCR]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KASMain.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KASTask.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KAV32.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KAVDX.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KAVPF.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KAVPFW.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KAVSetup.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KAVStart.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KISLnchr.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KMailMon.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KMFilter.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KPFW32.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KPFW32X.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KPfwSvc.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KRegEx.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KRepair.com]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KsLoader.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KVCenter.kxp]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KvDetect.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KvfwMcl.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KVMonXP.kxp]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KVMonXP_1.kxp]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kvol.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kvolself.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KvReport.kxp]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KVScan.kxp]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KVSrvXP.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KVStub.kxp]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kvupload.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kvwsc.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KvXP.kxp]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KvXP_1.kxp]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KWatch.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KWatch9x.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KWatchX.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\loaddll.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\MagicSet.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\mcconsol.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\mmqczj.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\mmsk.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Navapsvc.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Navapw32.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\nod32.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\nod32krn.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\nod32kui.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NPFMntor.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\PFW.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\PFWLiveUpdate.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\QHSET.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\QQDoctor.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\QQKav.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Ras.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Rav.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\RavMon.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\RavMonD.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\RavStub.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\RavTask.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\RegClean.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\rfwcfg.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\rfwmain.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\rfwsrv.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\RsAgent.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Rsaupd.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\rstrui.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\runiep.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\safelive.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\scan32.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\shcfg32.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\SmartUp.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\SREng.EXE]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\symlcsvc.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\SysSafe.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\TrojanDetector.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Trojanwall.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\TrojDie.kxp]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UIHost.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UmxAgent.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UmxAttachment.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UmxCfg.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UmxFwHlp.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UmxPol.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\upiea.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UpLive.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\USBCleaner.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\vsstat.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\webscanx.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\WoptiClean.exe]
Debugger=C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

SafeBoot registry key needs repairs. This machine cannot enter Safe Mode.
~~\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{05a6d150-2de4-11dc-b6d3-00e05e394056}]
AutoRun\command- F:\kwjkpww.exe
explore\Command- F:\kwjkpww.exe
open\Command- F:\kwjkpww.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{07d1e690-463e-11db-9464-00e05e394056}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Toy.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{38cae550-6974-11db-94d0-00e05e394056}]
1\Command- .\RECYCLER\RECYCLER\autorun.exe
2\Command- .\RECYCLER\RECYCLER\autorun.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\RECYCLER\RECYCLER\autorun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{38cae552-6974-11db-94d0-00e05e394056}]
1\Command- .\RECYCLER\RECYCLER\autorun.exe
2\Command- .\RECYCLER\RECYCLER\autorun.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\RECYCLER\RECYCLER\autorun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4c9044d2-9321-11db-8805-00e05e394056}]
Auto\command- RavMonE.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RavMonE.exe e

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{57de17e0-7a09-11db-94f3-00e05e394056}]
AutoRun\command- ~tmp0.1st.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5f3d4c14-f6c7-11db-b636-00e05e394056}]
1\Command- F:\.\recycled\info.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\recycled\info.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{933560f1-29f9-11dc-b6c4-00e05e394056}]
AutoRun\command- F:\kwjkpww.exe
explore\Command- F:\kwjkpww.exe
open\Command- F:\kwjkpww.exe


**************************************************************************

catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-16 20:56:38
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-16 20:58:49 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-07-16 20:58
C:\ComboFix2.txt … 2007-07-14 20:33

— E O F —

BTW, there is a popup with heading 16 bit ms-dos subsystem and the listed file is 11222.exe with this message 'The NTVDM CPU has executed an illegal instruction. CS:0557 IP:01bd OP: 63 65 6e 74 65 choose 'close' to terminate the application.

Menk
Hiya menk

Download F-Secure Blacklight (fsbl.exe) to the desktop from here.

Open it and click Accept Agreement.
Click Scan.
After the scan is complete, click Next, then Exit.
It will create a log on the desktop named fsbl-xxxxxxx.log (the xxxxxxx will be the date and time of the scan)
Save the log to your desktop. Paste the log in your next reply.
Hello Scot There was no log created but the summary in the Finish menu says that there are no hidden items or items queued for renaming. menk
One more thing, Scot. Couple of days ago I downloaded a trial version of f-secure's antivirus which said I should remove other antivirus programmes and firewall. Now I'm stranded because f-secure's programme has been blocked and I cannot reinstall any other av programme or firewall. It seems windows firewall has also been turned off and cannot be turned on again. A popup says 'vsmon.exe failed to start because zpeng24.dll not found. Re-installing the app may fix this.' I don't know what app that .dll is in reference to. I'm concerned over the numerous intrusions I used to get, so how can I get the zone alarm reinstalled?
Hi menk

You seem to have made an error with the CFScript. Can we try again?

Open Notepad and Copy/Paste the text in the codebox below into it:

File::
C:\WINDOWS\system32\promote.dll
C:\WINDOWS\system32\sexit.dat
C:\Program Files\meex.exe
C:\WINDOWS\TIMHost.exe
C:\WINDOWS\system32\TIMHost.dll
C:\WINDOWS\system32\drivers\mxdispdr.sys
C:\Program Files\.inf
C:\Program Files\cfkbyse.inf
C:\WINDOWS\system32\13AA3AD2F8.sys
C:\Program Files\Common Files\System\cfhskjn.exe
C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0FA24E3E-422C-4D94-A125-104F32352C90}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cfkbyse"=-
"kwjkpww"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{12311A42-AC1B-158F-FD32-5674345F23A1}"=-
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}]
@="DiskDrive" 
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=""
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{05a6d150-2de4-11dc-b6d3-00e05e394056}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{07d1e690-463e-11db-9464-00e05e394056}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{38cae550-6974-11db-94d0-00e05e394056}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{38cae552-6974-11db-94d0-00e05e394056}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4c9044d2-9321-11db-8805-00e05e394056}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5f3d4c14-f6c7-11db-b636-00e05e394056}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{933560f1-29f9-11dc-b6c4-00e05e394056}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{be32d7b0-c2a6-11da-9289-00e05e394056}]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\360rpt.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\360Safe.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\360tray.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\adam.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\AgentSvr.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\AppSvc32.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\ArSwp.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\AST.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\autoruns.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avconsol.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avgrssvc.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\AvMonitor.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avp.com]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avp.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\CCenter.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\ccSvcHst.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\EGHOST.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\FileDsty.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\FTCleanerShell.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\FYFireWall.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\HijackThis.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\IceSword.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\iparmo.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Iparmor.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\isPwdSvc.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kabaload.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KaScrScn.SCR]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KASMain.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KASTask.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KAV32.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KAVDX.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KAVPF.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KAVPFW.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KAVSetup.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KAVStart.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KISLnchr.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KMailMon.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KMFilter.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KPFW32.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KPFW32X.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KPfwSvc.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KRegEx.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KRepair.com]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KsLoader.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KVCenter.kxp]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KvDetect.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KvfwMcl.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KVMonXP.kxp]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KVMonXP_1.kxp]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kvol.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kvolself.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KvReport.kxp]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KVScan.kxp]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KVSrvXP.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KVStub.kxp]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kvupload.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\kvwsc.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KvXP.kxp]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KvXP_1.kxp]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KWatch.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KWatch9x.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\KWatchX.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\loaddll.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\MagicSet.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\mcconsol.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\mmqczj.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\mmsk.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Navapsvc.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Navapw32.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\nod32.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\nod32krn.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\nod32kui.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\NPFMntor.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\PFW.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\PFWLiveUpdate.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\QHSET.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\QQDoctor.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\QQKav.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Ras.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Rav.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\RavMon.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\RavMonD.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\RavStub.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\RavTask.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\RegClean.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\rfwcfg.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\rfwmain.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\rfwsrv.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\RsAgent.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Rsaupd.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\rstrui.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\runiep.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\safelive.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\scan32.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\shcfg32.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\SmartUp.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\SREng.EXE]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\symlcsvc.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\SysSafe.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\TrojanDetector.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Trojanwall.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\TrojDie.kxp]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UIHost.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UmxAgent.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UmxAttachment.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UmxCfg.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UmxFwHlp.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UmxPol.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\upiea.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\UpLive.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\USBCleaner.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\vsstat.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\webscanx.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\WoptiClean.exe]

Save this as "CFScript"

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log with a new HijackThis log.

Only move the CFScript into the Combofix icon, nothing else. To copy the text from the codebox start at the bottm, the last letter and, holding down the mouse button, move up until everything within the box is highlighted blue, then right-click and select copy. With Notepad open right-click inside it and select Paste.
If you have questions, dont be afraid to ask.
Appreciate your patience, Scot. I hope I got the log right this time!

"yangyq" - 2007-07-17 23:36:09 - ComboFix 07-07-14.6 - Service Pack 2 NTFS
Command switches used :: C:\Documents and Settings\yangyq\Desktop\CFScript.txt


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Program Files\.inf
C:\Program Files\cfkbyse.inf
C:\Program Files\Common Files\Microsoft Shared\vnwpbns.exe
C:\Program Files\Common Files\System\cfhskjn.exe
C:\Program Files\meex.exe
C:\WINDOWS\cmdbcs.exe
C:\WINDOWS\mppds.exe
C:\WINDOWS\msimms32.exe
C:\WINDOWS\system32\13AA3AD2F8.sys
C:\WINDOWS\system32\cmdbcs.dll
C:\WINDOWS\system32\drivers\mxdispdr.sys
C:\WINDOWS\system32\mppds.dll
C:\WINDOWS\system32\msimms32.dll
C:\WINDOWS\system32\promote.dll
C:\WINDOWS\system32\remotedbg.dll
C:\WINDOWS\system32\sexit.dat
C:\WINDOWS\system32\TIMHost.dll
C:\WINDOWS\system32\upxdnd.dll
C:\WINDOWS\temp\~my1.tmp
C:\WINDOWS\TIMHost.exe
C:\WINDOWS\upxdnd.exe


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\LEGACY_CELINDRV
——-\RemoteDbg


((((((((((((((((((((((((( Files Created from 2007-06-17 to 2007-07-17 )))))))))))))))))))))))))))))))


2007-07-17 23:34 34 —hs—- C:\Program Files\DLD.DAT
2007-07-16 09:01 23,552 –a—— C:\WINDOWS\system32\cajcte.dll
2007-07-16 09:01 11,264 –a—— C:\WINDOWS\system32\wbzpvt.dll
2007-07-16 09:00 22,016 –a—— C:\WINDOWS\system32\htqkse.dll
2007-07-15 21:35 26,112 –a—— C:\WINDOWS\system32\nircmd.exe
2007-07-15 18:53 drahs—- C:\autorun.inf
2007-07-14 20:22 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-14 20:19 d——– C:\Deckard
2007-07-13 22:32 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\fssg
2007-07-10 20:30 99 –a—— C:\WINDOWS\system32\pfdnnt_actions.sys
2007-07-10 18:54 d——– C:\WINDOWS\system32\ActiveScan
2007-07-10 17:27 d——– C:\DOCUME~1\yangyq\APPLIC~1\Skype
2007-07-10 17:23 d——– C:\Program Files\Skype


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-03 11:59:39 ——– d—–w C:\DOCUME~1\yangyq\APPLIC~1\VoipStunt
2007-06-13 12:29:53 ——– d–h–w C:\Program Files\InstallShield Installation Information
2007-06-13 12:27:58 ——– d—–w C:\Program Files\Veoh Networks
2007-06-13 12:24:51 ——– d—–w C:\Program Files\DivX
2007-05-28 14:34:23 ——– d—–w C:\Program Files\Opera 9
2007-05-24 04:09:11 ——– d—–w C:\Program Files\Windows Live Toolbar
2007-05-23 07:50:03 ——– d—–w C:\Program Files\Windows Desktop Search
2007-05-16 15:12:02 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-16 13:09:19 1,744 —-a-w C:\WINDOWS\system32\d3d9caps.dat
2007-05-13 14:26:38 1,901 —-a-w C:\WINDOWS\panose.bin
2007-05-12 10:39:34 4,096 —-a-w C:\WINDOWS\d3dx.dat
2007-05-02 01:08:19 2,560 —-a-w C:\WINDOWS\system32\BitCometRes.dll
2007-04-25 14:21:15 144,896 —-a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:23 2,854,400 —-a-w C:\WINDOWS\system32\msi.dll
2005-04-29 09:27:28 1,682 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
2007-03-29 22:31 394816 –a—— C:\Program Files\BitComet\tools\BitCometBHO_1.1.3.28.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2006-12-15 03:23 440056 –a—— C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" [2006-12-15 03:23]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 13:30]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"@"="C:\Program Files\Common Files\Microsoft Shared\" [2007-07-17 23:40]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 20:00]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45]
"@"="" []

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Spyware Doctor"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{91B1E846-2BEF-4345-8848-7699C7C9935F}"="C:\Program Files\Common Files\Microsoft Shared\MSINFO\SysWFGQQ2.dll" [2007-07-17 23:36]
"{26368135-64FA-BC34-DA32-DCF4FD431C92}"="C:\WINDOWS\system32\qhbpri.dll" [2004-08-04 20:58]
"{3495D328-661A-4FB0-BA67-8ACDD1704D1E}"="C:\WINDOWS\system32\3222.dll" []
"{12311A42-AC1B-158F-FD32-5674345F23A1}"="C:\WINDOWS\system32\dhapri.dll" [2004-08-04 11:13]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=dhapri.dll

SafeBoot registry key needs repairs. This machine cannot enter Safe Mode.
~~\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{57de17e0-7a09-11db-94f3-00e05e394056}]
AutoRun\command- ~tmp0.1st.exe


**************************************************************************

catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-17 23:42:51
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-17 23:45:26 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-07-17 23:45
C:\ComboFix2.txt … 2007-07-16 20:58
C:\ComboFix3.txt … 2007-07-14 20:33

— E O F —

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI