This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed]Too Many Popups

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm new to security and i'm seeing massive amounts of popups and my comp is barely working.
Here is my Hijackthis log, thank you i appreciate your help:




Logfile of HijackThis v1.99.1
Scan saved at 10:22:27 PM, on 8/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\COMMON~1\STEM~1\csrss.exe
C:\WINDOWS\TEMP\bot85B3.tmp
C:\WINDOWS\system32\eyypkcgx.exe
C:\WINDOWS\system32\nbwuncuj.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\??mantec\??ool32.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O1 - Hosts: 12.129.205.209 search.netscape.com12.129.205.209 sitefinder.verisign.com
O1 - Hosts: 12.129.205.209 search.netscape.com12.129.205.209 sitefinder.verisign.com
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll (file missing)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [{08-87-74-4E-ZN}] C:\WINDOWS\SYSTEM32\dwdsrngt.exe CHD003
O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\system32\vmbfsjnd.dll",forkonce
O4 - HKLM\..\RunOnce: [SpybotDeletingA3453] command /c del "C:\WINDOWS\system32\spoolsvv.exe_tobedeleted"
O4 - HKLM\..\RunOnce: [SpybotDeletingC929] cmd /c del "C:\WINDOWS\system32\spoolsvv.exe_tobedeleted"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6831] command /c del "C:\WINDOWS\SYSTEM32\vedxg4am1et2.exe_tobedeleted"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4341] cmd /c del "C:\WINDOWS\SYSTEM32\vedxg4am1et2.exe_tobedeleted"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1928] command /c del "C:\WINDOWS\SYSTEM32\vedxga4m1et4.exe_tobedeleted"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4766] cmd /c del "C:\WINDOWS\SYSTEM32\vedxga4m1et4.exe_tobedeleted"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8148] command /c del "C:\WINDOWS\SYSTEM32\vedxga3me2.exe_tobedeleted"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9186] cmd /c del "C:\WINDOWS\SYSTEM32\vedxga3me2.exe_tobedeleted"
O4 - HKLM\..\RunOnce: [SpybotDeletingA622] command /c del "C:\WINDOWS\SYSTEM32\vedxga5me3.exe_tobedeleted"
O4 - HKLM\..\RunOnce: [SpybotDeletingC204] cmd /c del "C:\WINDOWS\SYSTEM32\vedxga5me3.exe_tobedeleted"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3711] command /c del "C:\WINDOWS\SYSTEM32\vedxga4me1.exe_tobedeleted"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1520] cmd /c del "C:\WINDOWS\SYSTEM32\vedxga4me1.exe_tobedeleted"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aida] "C:\PROGRA~1\COMMON~1\STEM~1\csrss.exe" -vt yazb
O4 - HKCU\..\RunOnce: [SpybotDeletingB9592] command /c del "C:\WINDOWS\system32\spoolsvv.exe_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7572] cmd /c del "C:\WINDOWS\system32\spoolsvv.exe_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4189] command /c del "C:\WINDOWS\SYSTEM32\vedxg4am1et2.exe_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6234] cmd /c del "C:\WINDOWS\SYSTEM32\vedxg4am1et2.exe_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5928] command /c del "C:\WINDOWS\SYSTEM32\vedxga4m1et4.exe_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4328] cmd /c del "C:\WINDOWS\SYSTEM32\vedxga4m1et4.exe_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingB852] command /c del "C:\WINDOWS\SYSTEM32\vedxga3me2.exe_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3829] cmd /c del "C:\WINDOWS\SYSTEM32\vedxga3me2.exe_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingB212] command /c del "C:\WINDOWS\SYSTEM32\vedxga5me3.exe_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6344] cmd /c del "C:\WINDOWS\SYSTEM32\vedxga5me3.exe_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8073] command /c del "C:\WINDOWS\SYSTEM32\vedxga4me1.exe_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2685] cmd /c del "C:\WINDOWS\SYSTEM32\vedxga4me1.exe_tobedeleted"
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…DSL/tgctlcm.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab46479.cab
O16 - DPF: {1FE5F6CD-7490-4428-9E79-830E8CC55B8B} (VCView Class) - http://24.193.222.199:12345/control/VCViewAtl.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (ZoneBuddy Class) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab32846.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab32846.cab
O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) - http://zone.msn.com/bingame/zpagames/zpa_shvl.cab50560.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (StadiumProxy Class) - http://zone.msn.com/binframework/v10/StProxy.cab41227.cab
O20 - AppInit_DLLs: c:\windows\system32\ldcore.dll
O21 - SSODL: DCOM Server 20509 - {2C1CD3D7-86AC-4068-93BC-A02304B20509} - (no file)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: DomainService - - C:\WINDOWS\system32\eyypkcgx.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: RoxMediaDB - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
O23 - Service: Roxio Hard Drive Watcher (RoxWatch) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Hello aeroskunk and welcome to the TomCoyote Forums

My name is Trevuren and I will be helping you with your problem.


A. Please provide a list of uninstallable programs.

To Provide a List of Installed Programs
  • Run HijackThis.
  • Click Config>>Miscellaneous Tools>>Open Uninstall Manager>>Save List
  • Save list to Desktop
  • Copy the Notepad list and Paste it into this thread.

B. Please download this file - combofix.exe by sUBs
  • You must download it to your Desktop
  • Double click combofix.exe & follow the prompts.
  • When finished, it will produce a log. Please save that log to post in your next reply along with a fresh HJT log.
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

Regards,

Trevuren
Thanks Trevuren, and thanks for the reply!


The uninstallable programs are as follows:

Ad-aware 6 Personal
Adobe Acrobat 6.0 Professional
Adobe Download Manager 1.2 (Remove Only)
Adobe InDesign 2.0
Adobe PageMaker 7.0
Adobe Reader 6.0.1
Adobe SVG Viewer 3.0
America Online (Choose which version to remove)
AOL Coach Version 1.0(Build:20030807.3)
AOL Instant Messenger
Audacity 1.2.0
Authentium AntiVirus SDK - 2
avast! Antivirus
BCM V.92 56K Modem
Cakewalk Media Mixer
Cakewalk Music Creator 3
Cakewalk VST Adapter 4
Canon Camera Window for ZoomBrowser EX
Canon PhotoRecord
Canon RAW Image Task for ZoomBrowser EX
Canon RemoteCapture Task for ZoomBrowser EX
Canon Utilities File Viewer Utility 1.3
Canon Utilities PhotoStitch 3.1
Canon Utilities RemoteCapture 2.7
Canon Utilities ZoomBrowser EX
CCleaner (remove only)
Civilization III - Gold Edition
CuteFTP 6 Home
CuteHTML
Dawn of War - Dark Crusade
Dell Digital Jukebox Driver
Dell Media Experience
Dell Solution Center
DellSupport
DivX Codec
DivX Content Uploader
DivX Converter
DivX Player
DivX Web Player
DS21Patch
DVDSentry
EPSON CardMonitor
EPSON Copy Utility
EPSON ES CX6400 Manual
EPSON Photo Print
EPSON PhotoStarter3.0
EPSON Printer Software
EPSON Scan
EPSON Smart Panel
Google Toolbar for Internet Explorer
Hijackthis 1.99.1
HijackThis 1.99.1
Intel® PRO Network Adapters and Drivers
Intel® PROSet
Internet Explorer Default Page
Jasc Paint Shop Photo Album
Jasc Paint Shop Pro 8 Dell Edition
Java 2 Runtime Environment, SE v1.4.2
LimeWire Pro
Logitech Gaming Software
Macromedia Contribute 2
Macromedia Dreamweaver MX 2004
Macromedia Extension Manager
Macromedia Fireworks MX 2004
Macromedia Flash Paper
Memorex exPressit Label Design Studio
Microsoft .NET Framework 1.1
Microsoft Data Access Components KB870669
Microsoft Encarta Encyclopedia Standard 2003
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Money 2003
Microsoft Money 2003 System Pack
Microsoft National Language Support Downlevel APIs
Microsoft Picture It! Photo 7.0
Microsoft Streets and Trips 2002
Microsoft Word 2002
Microsoft Works 2003 Setup Launcher
Microsoft Works 7.0
Microsoft Works Suite Add-in for Microsoft Word
Modem Helper
Mozilla Firefox (2.0)
MSXML 4.0 SP2 (KB927978)
NavRules 2.2.4
NoteWorthy Composer
NVIDIA Drivers
PowerDVD
PPSDKRedistributables
QuickTime
Radialpoint Security Services
RealOne Player
Reptile
Roxio RecordNow Premier
Sausage Software Common Files Package
ScanToWeb
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Shockwave
Sonic RecordNow!
Sound Blaster Live!
Spybot - Search & Destroy 1.4
Verizon Online DSL
Verizon Online Help and Support
Verizon PC Security Checkup
Verizon Servicepoint 1.3.21
Viewpoint Media Player
Virtual Sound Canvas DXi
Winamp (remove only)
Windows Internet Explorer 7
Windows Media Format Runtime
Windows Media Player 10
Windows XP Service Pack 2
WinMX
WinRAR archiver
WinZip
X-Cleaner Deluxe
Yahoo! Install Manager




…The combofix log:

ComboFix 07-08-14 - "Mike" 2007-08-13 23:01:46.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.561 [GMT -4:00]
* Created a new restore point


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\ALLUSE~1\APPLIC~1.\salesmonitor
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007\Data\Abbr
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007\Data\ProductCode
C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiSpyware 2007\Data\Abbr
C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiSpyware 2007\Data\ProductCode
C:\DOCUME~1\LOCALS~1\APPLIC~1\.rdr.ini
C:\DOCUME~1\Mike\APPLIC~1.\winantispyware 2007
C:\DOCUME~1\Mike\APPLIC~1.\winantispyware 2007\Logs\update.log
C:\DOCUME~1\Mike\APPLIC~1\..\err.log
C:\DOCUME~1\Mike\APPLIC~1\Microsoft\20509.dat
C:\DOCUME~1\Mike\APPLIC~1\WinAntiSpyware 2007\Logs\update.log
C:\DOCUME~1\Mike\STARTM~1\Programs.\Outerinfo
C:\DOCUME~1\Mike\STARTM~1\Programs.\Outerinfo\Terms.lnk
C:\DOCUME~1\Mike\STARTM~1\Programs\Startup.\TA_Start.lnk
C:\DOCUME~1\NETWOR~1\APPLIC~1\.rdr.ini
C:\DOCUME~1\NETWOR~1\APPLIC~1\install.dat
C:\Documents and Settings\All Users.\documents\settings
C:\Documents and Settings\All Users.\documents\settings\desktop.ini
C:\Program Files\Common Files\homeqyrid5555.dll
C:\Program Files\Common Files\stem~1
C:\Program Files\Common Files\stem~1\??stem\
C:\Program Files\Common Files\stem~1\csrss.exe
C:\Program Files\Common Files\winantispyware 2007
C:\Program Files\Common Files\WinAntiSpyware 2007\err.log
C:\Program Files\Common Files\winantispyware 2007\err.log
C:\Program Files\Common Files\WinAntiSpyware 2007\uwas7cw.exe
C:\Program Files\Common Files\winantispyware 2007\uwas7cw.exe
C:\Program Files\Common Files\winantispyware 2007\WAS7Mon.exe
C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe
C:\Program Files\mantec~1
C:\Program Files\mantec~1\??ool32.exe
C:\Program Files\MSN\prohdyx.html
C:\Program Files\outerinfo
C:\Program Files\outerinfo\Terms.rtf
C:\Program Files\TTC.dll
C:\Program Files\XEROX\homeqyrid2.dll
C:\Program Files\XEROX\homeqyrid4444.dll
C:\tempc2
C:\tempc2\tmpFF.log
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\temp\brr
C:\temp\brr\tmpZTF.log
C:\Temp\fse
C:\Temp\fse\tmpZTF.log
C:\WINDOWS\csrss.exe
C:\WINDOWS\deskcfg.dat
C:\WINDOWS\g4356cbvy63.exe
C:\WINDOWS\spooldr.exe
C:\WINDOWS\sstem3~1
C:\WINDOWS\system32\1_exception.nls
C:\WINDOWS\system32\2045243641.dll
C:\WINDOWS\system32\b02FdUe
C:\WINDOWS\system32\byxwvtr.dll
C:\WINDOWS\system32\C1
C:\WINDOWS\system32\C3
C:\WINDOWS\system32\C3\wr7317.exe
C:\WINDOWS\system32\C5
C:\WINDOWS\system32\C9
C:\WINDOWS\system32\ckrumxbe.dll
C:\WINDOWS\SYSTEM32\cltlljxq.ini
C:\WINDOWS\system32\config\system~1\applic~1\install.dat
C:\WINDOWS\system32\config\systemprofile\application data\.rdr.ini
C:\WINDOWS\system32\configs
C:\WINDOWS\system32\ddcaabc.dll
C:\WINDOWS\system32\ddcyaby.dll
C:\WINDOWS\system32\dkekovxu.dll
C:\WINDOWS\SYSTEM32\dnjsfbmv.ini
C:\WINDOWS\system32\driver
C:\WINDOWS\system32\driver\w717.exe
C:\WINDOWS\system32\drivers\alert_icon.gif
C:\WINDOWS\system32\drivers\blank.gif
C:\WINDOWS\system32\drivers\box_1.gif
C:\WINDOWS\system32\drivers\box_2.gif
C:\WINDOWS\system32\drivers\box_3.gif
C:\WINDOWS\system32\drivers\button_buynow.gif
C:\WINDOWS\system32\drivers\button_freescan.gif
C:\WINDOWS\system32\drivers\close_icon.gif
C:\WINDOWS\system32\drivers\detect.htm
C:\WINDOWS\system32\drivers\download_box.gif
C:\WINDOWS\system32\drivers\footer_back.jpg
C:\WINDOWS\system32\drivers\fopn.sys
C:\WINDOWS\system32\drivers\header_1.gif
C:\WINDOWS\system32\drivers\header_2.gif
C:\WINDOWS\system32\drivers\header_3.gif
C:\WINDOWS\system32\drivers\header_4.gif
C:\WINDOWS\system32\drivers\header_bg.gif
C:\WINDOWS\system32\drivers\icon_warning.gif
C:\WINDOWS\system32\drivers\infected.gif
C:\WINDOWS\system32\drivers\main_back.gif
C:\WINDOWS\system32\drivers\perfect_cleaner_box.jpg
C:\WINDOWS\system32\drivers\product_1_header.gif
C:\WINDOWS\system32\drivers\product_1_name_small.gif
C:\WINDOWS\system32\drivers\product_2_header.gif
C:\WINDOWS\system32\drivers\product_2_name_small.gif
C:\WINDOWS\system32\drivers\product_3_header.gif
C:\WINDOWS\system32\drivers\product_3_name_small.gif
C:\WINDOWS\system32\drivers\product_features.gif
C:\WINDOWS\system32\drivers\pt.htm
C:\WINDOWS\system32\drivers\remove_spyware_button.gif
C:\WINDOWS\system32\drivers\s_detect.htm
C:\WINDOWS\system32\drivers\secuity_center_logo.gif
C:\WINDOWS\system32\drivers\sep_hor.gif
C:\WINDOWS\system32\drivers\sep_vert.gif
C:\WINDOWS\system32\drivers\shadow.jpg
C:\WINDOWS\system32\drivers\spacer.gif
C:\WINDOWS\system32\drivers\spy_away_box.jpg
C:\WINDOWS\system32\drivers\star.gif
C:\WINDOWS\system32\drivers\star_gray.gif
C:\WINDOWS\system32\drivers\star_gray_small.gif
C:\WINDOWS\system32\drivers\star_small.gif
C:\WINDOWS\system32\drivers\style.css
C:\WINDOWS\system32\drivers\v.gif
C:\WINDOWS\system32\drivers\warning_icon.gif
C:\WINDOWS\system32\drivers\win_logo.gif
C:\WINDOWS\system32\drivers\x.gif
C:\WINDOWS\system32\E5
C:\WINDOWS\system32\E5\wb720.exe
C:\WINDOWS\SYSTEM32\ebxmurkc.ini
C:\WINDOWS\system32\efcdbxv.dll
C:\WINDOWS\SYSTEM32\egjlm.bak1
C:\WINDOWS\SYSTEM32\egjlm.bak2
C:\WINDOWS\SYSTEM32\egjlm.ini
C:\WINDOWS\system32\eyypkcgx.exe
C:\WINDOWS\system32\f02WtR
C:\WINDOWS\system32\f02WtR\f02WtR1065.exe
C:\WINDOWS\system32\f06WtR
C:\WINDOWS\system32\f06WtR\f06WtR1083.exe
C:\WINDOWS\system32\F2
C:\WINDOWS\system32\F3
C:\WINDOWS\system32\guargwem.exe
C:\WINDOWS\system32\iaokglp.dll
C:\WINDOWS\system32\jcrrjtxs.exe
C:\WINDOWS\system32\kaclncki.exe
C:\WINDOWS\system32\kdqydgay.exe
C:\WINDOWS\system32\kjkefyiy.exe
C:\WINDOWS\system32\l3acdb.dll
C:\WINDOWS\system32\ldcore.dll
C:\WINDOWS\system32\ldinfo.ldr
C:\WINDOWS\system32\lgrtxmax.exe
C:\WINDOWS\system32\ljjgghf.dll
C:\WINDOWS\system32\mfojvwtu.exe
C:\WINDOWS\system32\mljge.dll
C:\WINDOWS\system32\msbind32.exe
C:\WINDOWS\system32\nbwuncuj.exe
C:\WINDOWS\system32\pmnoljg.dll
C:\WINDOWS\system32\psnodjcd.dll
C:\WINDOWS\system32\pwinlmdt.exe
C:\WINDOWS\system32\qomkhff.dll
C:\WINDOWS\system32\qxjlltlc.dll
C:\WINDOWS\system32\rorlqipv.dll
C:\WINDOWS\system32\setup155.exe
C:\WINDOWS\system32\vedxg3am1et3.exe
C:\WINDOWS\system32\vmbfsjnd.dll
C:\WINDOWS\system32\vpmgcylp.dll
C:\WINDOWS\system32\W3
C:\WINDOWS\system32\W3\tdwn23.exe
C:\WINDOWS\system32\win
C:\WINDOWS\system32\WinCore32.exe
C:\WINDOWS\system32\wnsapiit32.exe
C:\WINDOWS\system32\wvsdsbmy.dll
C:\WINDOWS\system32\yaacwbga.exe
C:\WINDOWS\system32\yayvtsq.dll
C:\WINDOWS\SYSTEM32\ymbsdsvw.ini
C:\WINDOWS\system32\ynol.dll
C:\WINDOWS\system32\zxdnt3d.cfg
C:\WINDOWS\TTC-4444.exe
C:\WINDOWS\TTC-5555.exe
C:\WINDOWS\uninst1014.exe
C:\WINDOWS\zsons0578.exe


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\LEGACY_CMDSERVICE
——-\LEGACY_DOMAINSERVICE
——-\LEGACY_FOPN
——-\LEGACY_NET_AGENT
——-\DomainService
——-\Net Agent
——-\nm


((((((((((((((((((((((((( Files Created from 2007-07-14 to 2007-08-14 )))))))))))))))))))))))))))))))


2007-08-13 22:59 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-10 22:57 d——– C:\Program Files\CCleaner
2007-08-10 22:02 d——– C:\hijackthis
2007-08-10 21:24 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-08-06 16:35 d–h—– C:\WINDOWS\PIF
2007-08-06 16:20 d——– C:\Program Files\Common Files\Scanner
2007-08-06 16:20 d——– C:\Program Files\Common Files\Authentium
2007-08-06 16:14 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Verizon
2007-08-05 22:24 d–hs—- C:\WINDOWS\TWlrZQ
2007-08-03 22:38 d——– C:\Program Files\X-Cleaner
2007-08-03 22:37 2,285,336 –a—— C:\xcleaner_full_setup.exe
2007-08-03 19:28 192,622 –a—— C:\WINDOWS\SYSTEM32\owintmdt.exe
2007-07-29 00:57 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
2007-07-15 23:27 d——– C:\DOCUME~1\Mike\APPLIC~1\WinRAR
2007-07-14 23:45 1,207,026 –a—— C:\wrar370.exe


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-13 22:52 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-08-13 22:49 ——— d——– C:\Program Files\AIM+
2007-08-10 23:01 ——— d——– C:\Program Files\EA SPORTS
2007-08-10 22:35 ——— d——– C:\Program Files\Google
2007-08-07 02:44 ——— d——– C:\Program Files\BitTorrent
2007-08-07 02:34 ——— d——– C:\Program Files\IrfanView
2007-08-06 16:20 ——— d——– C:\Program Files\Verizon
2007-08-06 16:01 375296 –a—— C:\WINDOWS\system32\drivers\tcpip.sys
2007-08-06 16:01 375296 –a—— C:\WINDOWS\system32\dllcache\tcpip.sys
2007-08-03 20:18 ——— d——– C:\Program Files\IEForge
2007-06-20 19:35 6820520 –a—— C:\FirefoxGoogleToolbarSetup.exe
2007-06-15 23:24 ——— d——– C:\Program Files\America Online 9.0
2007-06-15 22:25 ——— d——– C:\Program Files\Viewpoint
2007-05-16 11:12 86528 ——— C:\WINDOWS\system32\dllcache\directdb.dll
2007-05-16 11:12 85504 ——— C:\WINDOWS\system32\dllcache\wabimp.dll
2007-05-16 11:12 683520 –a—— C:\WINDOWS\system32\inetcomm.dll
2007-05-16 11:12 683520 ——— C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-05-16 11:12 510976 ——— C:\WINDOWS\system32\dllcache\wab32.dll
2007-05-16 11:12 1314816 ——— C:\WINDOWS\system32\dllcache\msoe.dll
2006-08-14 18:08 976020 –a—— C:\Program Files\BDAXP.cab
2006-08-14 18:08 917318 –a—— C:\Program Files\Apr2006_MDX1_x86.cab
2006-08-14 18:08 88102 –a—— C:\Program Files\AUG2006_xinput_x64.cab
2006-08-14 18:08 87989 –a—— C:\Program Files\Apr2006_xinput_x64.cab
2006-08-14 18:08 86925 –a—— C:\Program Files\Oct2005_xinput_x64.cab
2006-08-14 18:08 82338 –a—— C:\Program Files\dxupdate.cab
2006-08-14 18:08 74520 –a—— C:\Program Files\DSETUP.dll
2006-08-14 18:08 703080 –a—— C:\Program Files\BDA.cab
2006-08-14 18:08 484632 –a—— C:\Program Files\DXSETUP.exe
2006-08-14 18:08 47018 –a—— C:\Program Files\AUG2006_xinput_x86.cab
2006-08-14 18:08 46898 –a—— C:\Program Files\Apr2006_xinput_x86.cab
2006-08-14 18:08 46247 –a—— C:\Program Files\Oct2005_xinput_x86.cab
2006-08-14 18:08 41995 –a—— C:\Program Files\dxdllreg_x86.cab
2006-08-14 18:08 4163518 –a—— C:\Program Files\Apr2006_MDX1_x86_Archive.cab
2006-08-14 18:08 2248984 –a—— C:\Program Files\dsetup32.dll
2006-08-14 18:08 183863 –a—— C:\Program Files\AUG2006_XACT_x64.cab
2006-08-14 18:08 181745 –a—— C:\Program Files\JUN2006_XACT_x64.cab
2006-08-14 18:08 180021 –a—— C:\Program Files\Apr2006_XACT_x64.cab
2006-08-14 18:08 179247 –a—— C:\Program Files\Feb2006_XACT_x64.cab
2006-08-14 18:08 15493481 –a—— C:\Program Files\DirectX.cab
2006-08-14 18:08 1398718 –a—— C:\Program Files\Apr2006_d3dx9_30_x64.cab
2006-08-14 18:08 138195 –a—— C:\Program Files\AUG2006_XACT_x86.cab
2006-08-14 18:08 1363684 –a—— C:\Program Files\Feb2006_d3dx9_29_x64.cab
2006-08-14 18:08 1358864 –a—— C:\Program Files\Dec2005_d3dx9_28_x64.cab
2006-08-14 18:08 1351430 –a—— C:\Program Files\Aug2005_d3dx9_27_x64.cab
2006-08-14 18:08 1348242 –a—— C:\Program Files\Apr2005_d3dx9_25_x64.cab
2006-08-14 18:08 134631 –a—— C:\Program Files\JUN2006_XACT_x86.cab
2006-08-14 18:08 133991 –a—— C:\Program Files\Apr2006_XACT_x86.cab
2006-08-14 18:08 1336890 –a—— C:\Program Files\Jun2005_d3dx9_26_x64.cab
2006-08-14 18:08 133297 –a—— C:\Program Files\Feb2006_XACT_x86.cab
2006-08-14 18:08 13265040 –a—— C:\Program Files\dxnt.cab
2006-08-14 18:08 1248387 –a—— C:\Program Files\Feb2005_d3dx9_24_x64.cab
2006-08-14 18:08 1156363 –a—— C:\Program Files\BDANT.cab
2006-08-14 18:08 1116109 –a—— C:\Program Files\Apr2006_d3dx9_30_x86.cab
2006-08-14 18:08 1085608 –a—— C:\Program Files\Feb2006_d3dx9_29_x86.cab
2006-08-14 18:08 1080344 –a—— C:\Program Files\Dec2005_d3dx9_28_x86.cab
2006-08-14 18:08 1079850 –a—— C:\Program Files\Apr2005_d3dx9_25_x86.cab
2006-08-14 18:08 1078532 –a—— C:\Program Files\Aug2005_d3dx9_27_x86.cab
2006-08-14 18:08 1065813 –a—— C:\Program Files\Jun2005_d3dx9_26_x86.cab
2006-08-14 18:08 1014113 –a—— C:\Program Files\Feb2005_d3dx9_24_x86.cab

C:\WINDOWS\system32\drivers\tcpip.sys … is infected !! (additional data below)
359,936 2005-05-25 19:07:12 C:\WINDOWS\$hf_mig$\KB893066\SP2QFE\tcpip.sys
360,448 2006-01-13 17:07:08 C:\WINDOWS\$hf_mig$\KB913446\SP2QFE\tcpip.sys
360,576 2006-04-20 12:18:35 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
332,928 2002-08-29 11:00:00 C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
359,040 2004-08-04 06:14:40 C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
375,296 2007-08-06 20:01:50 C:\WINDOWS\SYSTEM32\DLLCACHE\tcpip.sys
375,296 2007-08-06 20:01:53 C:\WINDOWS\SYSTEM32\DRIVERS\tcpip.sys


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0706A660-14F0-4EE3-FC9B-467C68CC84B4}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3F3E26F5-9CAC-4AA9-B343-0FA3CE5D0658}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E2426436-B558-4374-843F-F4548DEE5EB5}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 13:22]
"{08-87-74-4E-ZN}"="C:\WINDOWS\SYSTEM32\dwdsrngt.exe" []
"hotygep"="C:\Program Files\Internet Explorer\hotygep1.exe" [2007-08-07 16:30]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]
"SpybotDeletingC9677"=cmd /c del "C:\WINDOWS\SYSTEM32\ldcore.dll_tobedeleted_old"
"SpybotSnD"="C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"=Narrator.exe

C:\Documents and Settings\Mike\Start Menu\Programs\Startup\
DESKTOP.INI [2002-09-03 11:00:00]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
DESKTOP.INI [2002-09-03 11:00:00]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
@=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
Source= C:\Program Files\MSN\prohdyx.html
FriendlyName=

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
backup=C:\WINDOWS\pss\Acrobat Assistant.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Mike^Start Menu^Programs^Startup^PowerReg Scheduler V3.exe]
path=C:\Documents and Settings\Mike\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe
backup=C:\WINDOWS\pss\PowerReg Scheduler V3.exeStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Mike^Start Menu^Programs^Startup^TA_Start.lnk]
path=C:\Documents and Settings\Mike\Start Menu\Programs\Startup\TA_Start.lnk
backup=C:\WINDOWS\pss\TA_Start.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Mike^Start Menu^Programs^Startup^Think-Adz.lnk]
path=C:\Documents and Settings\Mike\Start Menu\Programs\Startup\Think-Adz.lnk
backup=C:\WINDOWS\pss\Think-Adz.lnkStartup


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Instant Messanger]
aim.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avserve.exe]
C:\WINDOWS\avserve.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bantool]
C:\WINDOWS\system32\ie_ban.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
BCMSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
"C:\Program Files\DellSupport\DSAgnt.exe" /startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\diagent]
"C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
C:\WINDOWS\System32\DLA\DLACTRLW.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDSentry]
C:\WINDOWS\System32\DSentry.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ExploreUpdSched]
C:\WINDOWS\system32\owintmdt.exe SKY009

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ezwzsmdA]
C:\WINDOWS\ezwzsmdA.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Febcdtgx]
"C:\Program Files\??mantec\??ool32.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\g4356cbvy63]
C:\WINDOWS\g4356cbvy63

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IS CfgWiz]
C:\Program Files\Common Files\Symantec Shared\cfgwiz.exe /GUID NIS /CMDLINE "REBOOT"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Update]
msawindows.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
"C:\Program Files\Microsoft Money\System\mnyexpr.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge]
C:\PROGRA~1\Verizon\SMARTB~1\MotiveSB.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBInstall]
C:\DOCUME~1\Mike\LOCALS~1\Temp\MBDownloader_876919.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\WINDOWS\System32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
"C:\Program Files\Dell\Media Experience\PCMService.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\rdcmxnovdon]
C:\WINDOWS\System32\fugaxhsf.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
"C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatchTray.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
C:\WINDOWS\retadpu1000106.exe 61A847B5BBF72813329B385772FF01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Salestart]
"C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Service Pack 1]
C:\WINDOWS\system32\vedxg6ame4.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemOptimizer]
rundll32.exe "C:\WINDOWS\system32\wvsdsbmy.dll",forkonce

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
C:\WINDOWS\UpdReg.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\URLLSTCK.exe]
C:\Program Files\Norton Internet Security\UrlLstCk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VerizonServicepoint.exe]
C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinCore32.exe]
C:\WINDOWS\system32\WinCore32.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\X-Cleaner Deluxe]
"C:\PROGRA~1\X-CLEA~1\XCleaner_full.exe" -turbo -autostart -NOREBOOT

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{08-87-74-4E-ZN}]
c:\windows\system32\lsdsregl.exe SKY009

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WANMiniportService"=2 (0x2)
"Viewpoint Manager Service"=2 (0x2)
"RoxLiveShare"=2 (0x2)
"Net Agent"=2 (0x2)
"DSBrokerService"=3 (0x3)

R0 PzWDM;PzWDM;C:\WINDOWS\system32\Drivers\PzWDM.sys
R3 BCMModem;BCM V.92 56K Modem;C:\WINDOWS\system32\DRIVERS\BCMSM.sys
R3 P16X;Creative SB Live! Series (WDM);C:\WINDOWS\system32\drivers\P16X.sys
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver;C:\WINDOWS\system32\drivers\WmBEnum.sys
R3 WmXlCore;Logitech WingMan Translation Layer Driver;C:\WINDOWS\system32\drivers\WmXlCore.sys
S3 hamachi_oem;PlayLinc Adapter;C:\WINDOWS\system32\DRIVERS\gan_adapter.sys
S3 PortRst;PortRst;C:\WINDOWS\system32\DRIVERS\PortRst.sys
S3 WmFilter;Logitech WingMan HID Filter Driver;C:\WINDOWS\system32\drivers\WmFilter.sys
S3 WmVirHid;Logitech Virtual Hid Device Driver;C:\WINDOWS\system32\drivers\WmVirHid.sys


**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-13 23:10:02
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

**************************************************************************

Completion time: 2007-08-13 23:11:45 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-08-13 23:11

— E O F —










…And a fresh HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 11:31:06 PM, on 8/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\hotygep1.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\msiexec.exe
C:\Documents and Settings\Mike\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: 0 - {0706A660-14F0-4EE3-FC9B-467C68CC84B4} - (no file)
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {3F3E26F5-9CAC-4AA9-B343-0FA3CE5D0658} - \
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {E2426436-B558-4374-843F-F4548DEE5EB5} - (no file)
O3 - Toolbar: (no name) - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [{08-87-74-4E-ZN}] C:\WINDOWS\SYSTEM32\dwdsrngt.exe CHD003
O4 - HKLM\..\Run: [hotygep] C:\Program Files\Internet Explorer\hotygep1.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…DSL/tgctlcm.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab46479.cab
O16 - DPF: {1FE5F6CD-7490-4428-9E79-830E8CC55B8B} (VCView Class) - http://24.193.222.199:12345/control/VCViewAtl.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (ZoneBuddy Class) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab32846.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab32846.cab
O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) - http://zone.msn.com/bingame/zpagames/zpa_shvl.cab50560.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (StadiumProxy Class) - http://zone.msn.com/binframework/v10/StProxy.cab41227.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: RoxMediaDB - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
O23 - Service: Roxio Hard Drive Watcher (RoxWatch) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Thanks Trevuren, and thanks for the reply!


The uninstallable programs are as follows:

Ad-aware 6 Personal
Adobe Acrobat 6.0 Professional
Adobe Download Manager 1.2 (Remove Only)
Adobe InDesign 2.0
Adobe PageMaker 7.0
Adobe Reader 6.0.1
Adobe SVG Viewer 3.0
America Online (Choose which version to remove)
AOL Coach Version 1.0(Build:20030807.3)
AOL Instant Messenger
Audacity 1.2.0
Authentium AntiVirus SDK - 2
avast! Antivirus
BCM V.92 56K Modem
Cakewalk Media Mixer
Cakewalk Music Creator 3
Cakewalk VST Adapter 4
Canon Camera Window for ZoomBrowser EX
Canon PhotoRecord
Canon RAW Image Task for ZoomBrowser EX
Canon RemoteCapture Task for ZoomBrowser EX
Canon Utilities File Viewer Utility 1.3
Canon Utilities PhotoStitch 3.1
Canon Utilities RemoteCapture 2.7
Canon Utilities ZoomBrowser EX
CCleaner (remove only)
Civilization III - Gold Edition
CuteFTP 6 Home
CuteHTML
Dawn of War - Dark Crusade
Dell Digital Jukebox Driver
Dell Media Experience
Dell Solution Center
DellSupport
DivX Codec
DivX Content Uploader
DivX Converter
DivX Player
DivX Web Player
DS21Patch
DVDSentry
EPSON CardMonitor
EPSON Copy Utility
EPSON ES CX6400 Manual
EPSON Photo Print
EPSON PhotoStarter3.0
EPSON Printer Software
EPSON Scan
EPSON Smart Panel
Google Toolbar for Internet Explorer
Hijackthis 1.99.1
HijackThis 1.99.1
Intel® PRO Network Adapters and Drivers
Intel® PROSet
Internet Explorer Default Page
Jasc Paint Shop Photo Album
Jasc Paint Shop Pro 8 Dell Edition
Java 2 Runtime Environment, SE v1.4.2
LimeWire Pro
Logitech Gaming Software
Macromedia Contribute 2
Macromedia Dreamweaver MX 2004
Macromedia Extension Manager
Macromedia Fireworks MX 2004
Macromedia Flash Paper
Memorex exPressit Label Design Studio
Microsoft .NET Framework 1.1
Microsoft Data Access Components KB870669
Microsoft Encarta Encyclopedia Standard 2003
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Money 2003
Microsoft Money 2003 System Pack
Microsoft National Language Support Downlevel APIs
Microsoft Picture It! Photo 7.0
Microsoft Streets and Trips 2002
Microsoft Word 2002
Microsoft Works 2003 Setup Launcher
Microsoft Works 7.0
Microsoft Works Suite Add-in for Microsoft Word
Modem Helper
Mozilla Firefox (2.0)
MSXML 4.0 SP2 (KB927978)
NavRules 2.2.4
NoteWorthy Composer
NVIDIA Drivers
PowerDVD
PPSDKRedistributables
QuickTime
Radialpoint Security Services
RealOne Player
Reptile
Roxio RecordNow Premier
Sausage Software Common Files Package
ScanToWeb
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Shockwave
Sonic RecordNow!
Sound Blaster Live!
Spybot - Search & Destroy 1.4
Verizon Online DSL
Verizon Online Help and Support
Verizon PC Security Checkup
Verizon Servicepoint 1.3.21
Viewpoint Media Player
Virtual Sound Canvas DXi
Winamp (remove only)
Windows Internet Explorer 7
Windows Media Format Runtime
Windows Media Player 10
Windows XP Service Pack 2
WinMX
WinRAR archiver
WinZip
X-Cleaner Deluxe
Yahoo! Install Manager




…The combofix log:

ComboFix 07-08-14 - "Mike" 2007-08-13 23:01:46.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.561 [GMT -4:00]
* Created a new restore point


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\ALLUSE~1\APPLIC~1.\salesmonitor
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007\Data\Abbr
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007\Data\ProductCode
C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiSpyware 2007\Data\Abbr
C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiSpyware 2007\Data\ProductCode
C:\DOCUME~1\LOCALS~1\APPLIC~1\.rdr.ini
C:\DOCUME~1\Mike\APPLIC~1.\winantispyware 2007
C:\DOCUME~1\Mike\APPLIC~1.\winantispyware 2007\Logs\update.log
C:\DOCUME~1\Mike\APPLIC~1\..\err.log
C:\DOCUME~1\Mike\APPLIC~1\Microsoft\20509.dat
C:\DOCUME~1\Mike\APPLIC~1\WinAntiSpyware 2007\Logs\update.log
C:\DOCUME~1\Mike\STARTM~1\Programs.\Outerinfo
C:\DOCUME~1\Mike\STARTM~1\Programs.\Outerinfo\Terms.lnk
C:\DOCUME~1\Mike\STARTM~1\Programs\Startup.\TA_Start.lnk
C:\DOCUME~1\NETWOR~1\APPLIC~1\.rdr.ini
C:\DOCUME~1\NETWOR~1\APPLIC~1\install.dat
C:\Documents and Settings\All Users.\documents\settings
C:\Documents and Settings\All Users.\documents\settings\desktop.ini
C:\Program Files\Common Files\homeqyrid5555.dll
C:\Program Files\Common Files\stem~1
C:\Program Files\Common Files\stem~1\??stem\
C:\Program Files\Common Files\stem~1\csrss.exe
C:\Program Files\Common Files\winantispyware 2007
C:\Program Files\Common Files\WinAntiSpyware 2007\err.log
C:\Program Files\Common Files\winantispyware 2007\err.log
C:\Program Files\Common Files\WinAntiSpyware 2007\uwas7cw.exe
C:\Program Files\Common Files\winantispyware 2007\uwas7cw.exe
C:\Program Files\Common Files\winantispyware 2007\WAS7Mon.exe
C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe
C:\Program Files\mantec~1
C:\Program Files\mantec~1\??ool32.exe
C:\Program Files\MSN\prohdyx.html
C:\Program Files\outerinfo
C:\Program Files\outerinfo\Terms.rtf
C:\Program Files\TTC.dll
C:\Program Files\XEROX\homeqyrid2.dll
C:\Program Files\XEROX\homeqyrid4444.dll
C:\tempc2
C:\tempc2\tmpFF.log
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\temp\brr
C:\temp\brr\tmpZTF.log
C:\Temp\fse
C:\Temp\fse\tmpZTF.log
C:\WINDOWS\csrss.exe
C:\WINDOWS\deskcfg.dat
C:\WINDOWS\g4356cbvy63.exe
C:\WINDOWS\spooldr.exe
C:\WINDOWS\sstem3~1
C:\WINDOWS\system32\1_exception.nls
C:\WINDOWS\system32\2045243641.dll
C:\WINDOWS\system32\b02FdUe
C:\WINDOWS\system32\byxwvtr.dll
C:\WINDOWS\system32\C1
C:\WINDOWS\system32\C3
C:\WINDOWS\system32\C3\wr7317.exe
C:\WINDOWS\system32\C5
C:\WINDOWS\system32\C9
C:\WINDOWS\system32\ckrumxbe.dll
C:\WINDOWS\SYSTEM32\cltlljxq.ini
C:\WINDOWS\system32\config\system~1\applic~1\install.dat
C:\WINDOWS\system32\config\systemprofile\application data\.rdr.ini
C:\WINDOWS\system32\configs
C:\WINDOWS\system32\ddcaabc.dll
C:\WINDOWS\system32\ddcyaby.dll
C:\WINDOWS\system32\dkekovxu.dll
C:\WINDOWS\SYSTEM32\dnjsfbmv.ini
C:\WINDOWS\system32\driver
C:\WINDOWS\system32\driver\w717.exe
C:\WINDOWS\system32\drivers\alert_icon.gif
C:\WINDOWS\system32\drivers\blank.gif
C:\WINDOWS\system32\drivers\box_1.gif
C:\WINDOWS\system32\drivers\box_2.gif
C:\WINDOWS\system32\drivers\box_3.gif
C:\WINDOWS\system32\drivers\button_buynow.gif
C:\WINDOWS\system32\drivers\button_freescan.gif
C:\WINDOWS\system32\drivers\close_icon.gif
C:\WINDOWS\system32\drivers\detect.htm
C:\WINDOWS\system32\drivers\download_box.gif
C:\WINDOWS\system32\drivers\footer_back.jpg
C:\WINDOWS\system32\drivers\fopn.sys
C:\WINDOWS\system32\drivers\header_1.gif
C:\WINDOWS\system32\drivers\header_2.gif
C:\WINDOWS\system32\drivers\header_3.gif
C:\WINDOWS\system32\drivers\header_4.gif
C:\WINDOWS\system32\drivers\header_bg.gif
C:\WINDOWS\system32\drivers\icon_warning.gif
C:\WINDOWS\system32\drivers\infected.gif
C:\WINDOWS\system32\drivers\main_back.gif
C:\WINDOWS\system32\drivers\perfect_cleaner_box.jpg
C:\WINDOWS\system32\drivers\product_1_header.gif
C:\WINDOWS\system32\drivers\product_1_name_small.gif
C:\WINDOWS\system32\drivers\product_2_header.gif
C:\WINDOWS\system32\drivers\product_2_name_small.gif
C:\WINDOWS\system32\drivers\product_3_header.gif
C:\WINDOWS\system32\drivers\product_3_name_small.gif
C:\WINDOWS\system32\drivers\product_features.gif
C:\WINDOWS\system32\drivers\pt.htm
C:\WINDOWS\system32\drivers\remove_spyware_button.gif
C:\WINDOWS\system32\drivers\s_detect.htm
C:\WINDOWS\system32\drivers\secuity_center_logo.gif
C:\WINDOWS\system32\drivers\sep_hor.gif
C:\WINDOWS\system32\drivers\sep_vert.gif
C:\WINDOWS\system32\drivers\shadow.jpg
C:\WINDOWS\system32\drivers\spacer.gif
C:\WINDOWS\system32\drivers\spy_away_box.jpg
C:\WINDOWS\system32\drivers\star.gif
C:\WINDOWS\system32\drivers\star_gray.gif
C:\WINDOWS\system32\drivers\star_gray_small.gif
C:\WINDOWS\system32\drivers\star_small.gif
C:\WINDOWS\system32\drivers\style.css
C:\WINDOWS\system32\drivers\v.gif
C:\WINDOWS\system32\drivers\warning_icon.gif
C:\WINDOWS\system32\drivers\win_logo.gif
C:\WINDOWS\system32\drivers\x.gif
C:\WINDOWS\system32\E5
C:\WINDOWS\system32\E5\wb720.exe
C:\WINDOWS\SYSTEM32\ebxmurkc.ini
C:\WINDOWS\system32\efcdbxv.dll
C:\WINDOWS\SYSTEM32\egjlm.bak1
C:\WINDOWS\SYSTEM32\egjlm.bak2
C:\WINDOWS\SYSTEM32\egjlm.ini
C:\WINDOWS\system32\eyypkcgx.exe
C:\WINDOWS\system32\f02WtR
C:\WINDOWS\system32\f02WtR\f02WtR1065.exe
C:\WINDOWS\system32\f06WtR
C:\WINDOWS\system32\f06WtR\f06WtR1083.exe
C:\WINDOWS\system32\F2
C:\WINDOWS\system32\F3
C:\WINDOWS\system32\guargwem.exe
C:\WINDOWS\system32\iaokglp.dll
C:\WINDOWS\system32\jcrrjtxs.exe
C:\WINDOWS\system32\kaclncki.exe
C:\WINDOWS\system32\kdqydgay.exe
C:\WINDOWS\system32\kjkefyiy.exe
C:\WINDOWS\system32\l3acdb.dll
C:\WINDOWS\system32\ldcore.dll
C:\WINDOWS\system32\ldinfo.ldr
C:\WINDOWS\system32\lgrtxmax.exe
C:\WINDOWS\system32\ljjgghf.dll
C:\WINDOWS\system32\mfojvwtu.exe
C:\WINDOWS\system32\mljge.dll
C:\WINDOWS\system32\msbind32.exe
C:\WINDOWS\system32\nbwuncuj.exe
C:\WINDOWS\system32\pmnoljg.dll
C:\WINDOWS\system32\psnodjcd.dll
C:\WINDOWS\system32\pwinlmdt.exe
C:\WINDOWS\system32\qomkhff.dll
C:\WINDOWS\system32\qxjlltlc.dll
C:\WINDOWS\system32\rorlqipv.dll
C:\WINDOWS\system32\setup155.exe
C:\WINDOWS\system32\vedxg3am1et3.exe
C:\WINDOWS\system32\vmbfsjnd.dll
C:\WINDOWS\system32\vpmgcylp.dll
C:\WINDOWS\system32\W3
C:\WINDOWS\system32\W3\tdwn23.exe
C:\WINDOWS\system32\win
C:\WINDOWS\system32\WinCore32.exe
C:\WINDOWS\system32\wnsapiit32.exe
C:\WINDOWS\system32\wvsdsbmy.dll
C:\WINDOWS\system32\yaacwbga.exe
C:\WINDOWS\system32\yayvtsq.dll
C:\WINDOWS\SYSTEM32\ymbsdsvw.ini
C:\WINDOWS\system32\ynol.dll
C:\WINDOWS\system32\zxdnt3d.cfg
C:\WINDOWS\TTC-4444.exe
C:\WINDOWS\TTC-5555.exe
C:\WINDOWS\uninst1014.exe
C:\WINDOWS\zsons0578.exe


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\LEGACY_CMDSERVICE
——-\LEGACY_DOMAINSERVICE
——-\LEGACY_FOPN
——-\LEGACY_NET_AGENT
——-\DomainService
——-\Net Agent
——-\nm


((((((((((((((((((((((((( Files Created from 2007-07-14 to 2007-08-14 )))))))))))))))))))))))))))))))


2007-08-13 22:59 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-10 22:57 d——– C:\Program Files\CCleaner
2007-08-10 22:02 d——– C:\hijackthis
2007-08-10 21:24 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-08-06 16:35 d–h—– C:\WINDOWS\PIF
2007-08-06 16:20 d——– C:\Program Files\Common Files\Scanner
2007-08-06 16:20 d——– C:\Program Files\Common Files\Authentium
2007-08-06 16:14 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Verizon
2007-08-05 22:24 d–hs—- C:\WINDOWS\TWlrZQ
2007-08-03 22:38 d——– C:\Program Files\X-Cleaner
2007-08-03 22:37 2,285,336 –a—— C:\xcleaner_full_setup.exe
2007-08-03 19:28 192,622 –a—— C:\WINDOWS\SYSTEM32\owintmdt.exe
2007-07-29 00:57 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
2007-07-15 23:27 d——– C:\DOCUME~1\Mike\APPLIC~1\WinRAR
2007-07-14 23:45 1,207,026 –a—— C:\wrar370.exe


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-13 22:52 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-08-13 22:49 ——— d——– C:\Program Files\AIM+
2007-08-10 23:01 ——— d——– C:\Program Files\EA SPORTS
2007-08-10 22:35 ——— d——– C:\Program Files\Google
2007-08-07 02:44 ——— d——– C:\Program Files\BitTorrent
2007-08-07 02:34 ——— d——– C:\Program Files\IrfanView
2007-08-06 16:20 ——— d——– C:\Program Files\Verizon
2007-08-06 16:01 375296 –a—— C:\WINDOWS\system32\drivers\tcpip.sys
2007-08-06 16:01 375296 –a—— C:\WINDOWS\system32\dllcache\tcpip.sys
2007-08-03 20:18 ——— d——– C:\Program Files\IEForge
2007-06-20 19:35 6820520 –a—— C:\FirefoxGoogleToolbarSetup.exe
2007-06-15 23:24 ——— d——– C:\Program Files\America Online 9.0
2007-06-15 22:25 ——— d——– C:\Program Files\Viewpoint
2007-05-16 11:12 86528 ——— C:\WINDOWS\system32\dllcache\directdb.dll
2007-05-16 11:12 85504 ——— C:\WINDOWS\system32\dllcache\wabimp.dll
2007-05-16 11:12 683520 –a—— C:\WINDOWS\system32\inetcomm.dll
2007-05-16 11:12 683520 ——— C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-05-16 11:12 510976 ——— C:\WINDOWS\system32\dllcache\wab32.dll
2007-05-16 11:12 1314816 ——— C:\WINDOWS\system32\dllcache\msoe.dll
2006-08-14 18:08 976020 –a—— C:\Program Files\BDAXP.cab
2006-08-14 18:08 917318 –a—— C:\Program Files\Apr2006_MDX1_x86.cab
2006-08-14 18:08 88102 –a—— C:\Program Files\AUG2006_xinput_x64.cab
2006-08-14 18:08 87989 –a—— C:\Program Files\Apr2006_xinput_x64.cab
2006-08-14 18:08 86925 –a—— C:\Program Files\Oct2005_xinput_x64.cab
2006-08-14 18:08 82338 –a—— C:\Program Files\dxupdate.cab
2006-08-14 18:08 74520 –a—— C:\Program Files\DSETUP.dll
2006-08-14 18:08 703080 –a—— C:\Program Files\BDA.cab
2006-08-14 18:08 484632 –a—— C:\Program Files\DXSETUP.exe
2006-08-14 18:08 47018 –a—— C:\Program Files\AUG2006_xinput_x86.cab
2006-08-14 18:08 46898 –a—— C:\Program Files\Apr2006_xinput_x86.cab
2006-08-14 18:08 46247 –a—— C:\Program Files\Oct2005_xinput_x86.cab
2006-08-14 18:08 41995 –a—— C:\Program Files\dxdllreg_x86.cab
2006-08-14 18:08 4163518 –a—— C:\Program Files\Apr2006_MDX1_x86_Archive.cab
2006-08-14 18:08 2248984 –a—— C:\Program Files\dsetup32.dll
2006-08-14 18:08 183863 –a—— C:\Program Files\AUG2006_XACT_x64.cab
2006-08-14 18:08 181745 –a—— C:\Program Files\JUN2006_XACT_x64.cab
2006-08-14 18:08 180021 –a—— C:\Program Files\Apr2006_XACT_x64.cab
2006-08-14 18:08 179247 –a—— C:\Program Files\Feb2006_XACT_x64.cab
2006-08-14 18:08 15493481 –a—— C:\Program Files\DirectX.cab
2006-08-14 18:08 1398718 –a—— C:\Program Files\Apr2006_d3dx9_30_x64.cab
2006-08-14 18:08 138195 –a—— C:\Program Files\AUG2006_XACT_x86.cab
2006-08-14 18:08 1363684 –a—— C:\Program Files\Feb2006_d3dx9_29_x64.cab
2006-08-14 18:08 1358864 –a—— C:\Program Files\Dec2005_d3dx9_28_x64.cab
2006-08-14 18:08 1351430 –a—— C:\Program Files\Aug2005_d3dx9_27_x64.cab
2006-08-14 18:08 1348242 –a—— C:\Program Files\Apr2005_d3dx9_25_x64.cab
2006-08-14 18:08 134631 –a—— C:\Program Files\JUN2006_XACT_x86.cab
2006-08-14 18:08 133991 –a—— C:\Program Files\Apr2006_XACT_x86.cab
2006-08-14 18:08 1336890 –a—— C:\Program Files\Jun2005_d3dx9_26_x64.cab
2006-08-14 18:08 133297 –a—— C:\Program Files\Feb2006_XACT_x86.cab
2006-08-14 18:08 13265040 –a—— C:\Program Files\dxnt.cab
2006-08-14 18:08 1248387 –a—— C:\Program Files\Feb2005_d3dx9_24_x64.cab
2006-08-14 18:08 1156363 –a—— C:\Program Files\BDANT.cab
2006-08-14 18:08 1116109 –a—— C:\Program Files\Apr2006_d3dx9_30_x86.cab
2006-08-14 18:08 1085608 –a—— C:\Program Files\Feb2006_d3dx9_29_x86.cab
2006-08-14 18:08 1080344 –a—— C:\Program Files\Dec2005_d3dx9_28_x86.cab
2006-08-14 18:08 1079850 –a—— C:\Program Files\Apr2005_d3dx9_25_x86.cab
2006-08-14 18:08 1078532 –a—— C:\Program Files\Aug2005_d3dx9_27_x86.cab
2006-08-14 18:08 1065813 –a—— C:\Program Files\Jun2005_d3dx9_26_x86.cab
2006-08-14 18:08 1014113 –a—— C:\Program Files\Feb2005_d3dx9_24_x86.cab

C:\WINDOWS\system32\drivers\tcpip.sys … is infected !! (additional data below)
359,936 2005-05-25 19:07:12 C:\WINDOWS\$hf_mig$\KB893066\SP2QFE\tcpip.sys
360,448 2006-01-13 17:07:08 C:\WINDOWS\$hf_mig$\KB913446\SP2QFE\tcpip.sys
360,576 2006-04-20 12:18:35 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
332,928 2002-08-29 11:00:00 C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
359,040 2004-08-04 06:14:40 C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
375,296 2007-08-06 20:01:50 C:\WINDOWS\SYSTEM32\DLLCACHE\tcpip.sys
375,296 2007-08-06 20:01:53 C:\WINDOWS\SYSTEM32\DRIVERS\tcpip.sys


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0706A660-14F0-4EE3-FC9B-467C68CC84B4}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3F3E26F5-9CAC-4AA9-B343-0FA3CE5D0658}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E2426436-B558-4374-843F-F4548DEE5EB5}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 13:22]
"{08-87-74-4E-ZN}"="C:\WINDOWS\SYSTEM32\dwdsrngt.exe" []
"hotygep"="C:\Program Files\Internet Explorer\hotygep1.exe" [2007-08-07 16:30]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]
"SpybotDeletingC9677"=cmd /c del "C:\WINDOWS\SYSTEM32\ldcore.dll_tobedeleted_old"
"SpybotSnD"="C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"=Narrator.exe

C:\Documents and Settings\Mike\Start Menu\Programs\Startup\
DESKTOP.INI [2002-09-03 11:00:00]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
DESKTOP.INI [2002-09-03 11:00:00]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
@=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
Source= C:\Program Files\MSN\prohdyx.html
FriendlyName=

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
backup=C:\WINDOWS\pss\Acrobat Assistant.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Mike^Start Menu^Programs^Startup^PowerReg Scheduler V3.exe]
path=C:\Documents and Settings\Mike\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe
backup=C:\WINDOWS\pss\PowerReg Scheduler V3.exeStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Mike^Start Menu^Programs^Startup^TA_Start.lnk]
path=C:\Documents and Settings\Mike\Start Menu\Programs\Startup\TA_Start.lnk
backup=C:\WINDOWS\pss\TA_Start.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Mike^Start Menu^Programs^Startup^Think-Adz.lnk]
path=C:\Documents and Settings\Mike\Start Menu\Programs\Startup\Think-Adz.lnk
backup=C:\WINDOWS\pss\Think-Adz.lnkStartup


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Instant Messanger]
aim.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avserve.exe]
C:\WINDOWS\avserve.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bantool]
C:\WINDOWS\system32\ie_ban.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
BCMSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
"C:\Program Files\DellSupport\DSAgnt.exe" /startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\diagent]
"C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
C:\WINDOWS\System32\DLA\DLACTRLW.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDSentry]
C:\WINDOWS\System32\DSentry.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ExploreUpdSched]
C:\WINDOWS\system32\owintmdt.exe SKY009

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ezwzsmdA]
C:\WINDOWS\ezwzsmdA.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Febcdtgx]
"C:\Program Files\??mantec\??ool32.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\g4356cbvy63]
C:\WINDOWS\g4356cbvy63

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IS CfgWiz]
C:\Program Files\Common Files\Symantec Shared\cfgwiz.exe /GUID NIS /CMDLINE "REBOOT"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Update]
msawindows.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
"C:\Program Files\Microsoft Money\System\mnyexpr.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge]
C:\PROGRA~1\Verizon\SMARTB~1\MotiveSB.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBInstall]
C:\DOCUME~1\Mike\LOCALS~1\Temp\MBDownloader_876919.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\WINDOWS\System32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
"C:\Program Files\Dell\Media Experience\PCMService.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\rdcmxnovdon]
C:\WINDOWS\System32\fugaxhsf.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
"C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatchTray.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
C:\WINDOWS\retadpu1000106.exe 61A847B5BBF72813329B385772FF01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Salestart]
"C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Service Pack 1]
C:\WINDOWS\system32\vedxg6ame4.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemOptimizer]
rundll32.exe "C:\WINDOWS\system32\wvsdsbmy.dll",forkonce

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
C:\WINDOWS\UpdReg.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\URLLSTCK.exe]
C:\Program Files\Norton Internet Security\UrlLstCk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VerizonServicepoint.exe]
C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinCore32.exe]
C:\WINDOWS\system32\WinCore32.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\X-Cleaner Deluxe]
"C:\PROGRA~1\X-CLEA~1\XCleaner_full.exe" -turbo -autostart -NOREBOOT

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{08-87-74-4E-ZN}]
c:\windows\system32\lsdsregl.exe SKY009

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WANMiniportService"=2 (0x2)
"Viewpoint Manager Service"=2 (0x2)
"RoxLiveShare"=2 (0x2)
"Net Agent"=2 (0x2)
"DSBrokerService"=3 (0x3)

R0 PzWDM;PzWDM;C:\WINDOWS\system32\Drivers\PzWDM.sys
R3 BCMModem;BCM V.92 56K Modem;C:\WINDOWS\system32\DRIVERS\BCMSM.sys
R3 P16X;Creative SB Live! Series (WDM);C:\WINDOWS\system32\drivers\P16X.sys
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver;C:\WINDOWS\system32\drivers\WmBEnum.sys
R3 WmXlCore;Logitech WingMan Translation Layer Driver;C:\WINDOWS\system32\drivers\WmXlCore.sys
S3 hamachi_oem;PlayLinc Adapter;C:\WINDOWS\system32\DRIVERS\gan_adapter.sys
S3 PortRst;PortRst;C:\WINDOWS\system32\DRIVERS\PortRst.sys
S3 WmFilter;Logitech WingMan HID Filter Driver;C:\WINDOWS\system32\drivers\WmFilter.sys
S3 WmVirHid;Logitech Virtual Hid Device Driver;C:\WINDOWS\system32\drivers\WmVirHid.sys


**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-13 23:10:02
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

**************************************************************************

Completion time: 2007-08-13 23:11:45 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-08-13 23:11

— E O F —










…And a fresh HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 11:31:06 PM, on 8/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\hotygep1.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\msiexec.exe
C:\Documents and Settings\Mike\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: 0 - {0706A660-14F0-4EE3-FC9B-467C68CC84B4} - (no file)
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {3F3E26F5-9CAC-4AA9-B343-0FA3CE5D0658} - \
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {E2426436-B558-4374-843F-F4548DEE5EB5} - (no file)
O3 - Toolbar: (no name) - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [{08-87-74-4E-ZN}] C:\WINDOWS\SYSTEM32\dwdsrngt.exe CHD003
O4 - HKLM\..\Run: [hotygep] C:\Program Files\Internet Explorer\hotygep1.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…DSL/tgctlcm.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab46479.cab
O16 - DPF: {1FE5F6CD-7490-4428-9E79-830E8CC55B8B} (VCView Class) - http://24.193.222.199:12345/control/VCViewAtl.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (ZoneBuddy Class) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab32846.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab32846.cab
O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) - http://zone.msn.com/bingame/zpagames/zpa_shvl.cab50560.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (StadiumProxy Class) - http://zone.msn.com/binframework/v10/StProxy.cab41227.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: RoxMediaDB - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
O23 - Service: Roxio Hard Drive Watcher (RoxWatch) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Thanks Trevuren, and thanks for the reply!


The uninstallable programs are as follows:

Ad-aware 6 Personal
Adobe Acrobat 6.0 Professional
Adobe Download Manager 1.2 (Remove Only)
Adobe InDesign 2.0
Adobe PageMaker 7.0
Adobe Reader 6.0.1
Adobe SVG Viewer 3.0
America Online (Choose which version to remove)
AOL Coach Version 1.0(Build:20030807.3)
AOL Instant Messenger
Audacity 1.2.0
Authentium AntiVirus SDK - 2
avast! Antivirus
BCM V.92 56K Modem
Cakewalk Media Mixer
Cakewalk Music Creator 3
Cakewalk VST Adapter 4
Canon Camera Window for ZoomBrowser EX
Canon PhotoRecord
Canon RAW Image Task for ZoomBrowser EX
Canon RemoteCapture Task for ZoomBrowser EX
Canon Utilities File Viewer Utility 1.3
Canon Utilities PhotoStitch 3.1
Canon Utilities RemoteCapture 2.7
Canon Utilities ZoomBrowser EX
CCleaner (remove only)
Civilization III - Gold Edition
CuteFTP 6 Home
CuteHTML
Dawn of War - Dark Crusade
Dell Digital Jukebox Driver
Dell Media Experience
Dell Solution Center
DellSupport
DivX Codec
DivX Content Uploader
DivX Converter
DivX Player
DivX Web Player
DS21Patch
DVDSentry
EPSON CardMonitor
EPSON Copy Utility
EPSON ES CX6400 Manual
EPSON Photo Print
EPSON PhotoStarter3.0
EPSON Printer Software
EPSON Scan
EPSON Smart Panel
Google Toolbar for Internet Explorer
Hijackthis 1.99.1
HijackThis 1.99.1
Intel® PRO Network Adapters and Drivers
Intel® PROSet
Internet Explorer Default Page
Jasc Paint Shop Photo Album
Jasc Paint Shop Pro 8 Dell Edition
Java 2 Runtime Environment, SE v1.4.2
LimeWire Pro
Logitech Gaming Software
Macromedia Contribute 2
Macromedia Dreamweaver MX 2004
Macromedia Extension Manager
Macromedia Fireworks MX 2004
Macromedia Flash Paper
Memorex exPressit Label Design Studio
Microsoft .NET Framework 1.1
Microsoft Data Access Components KB870669
Microsoft Encarta Encyclopedia Standard 2003
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Money 2003
Microsoft Money 2003 System Pack
Microsoft National Language Support Downlevel APIs
Microsoft Picture It! Photo 7.0
Microsoft Streets and Trips 2002
Microsoft Word 2002
Microsoft Works 2003 Setup Launcher
Microsoft Works 7.0
Microsoft Works Suite Add-in for Microsoft Word
Modem Helper
Mozilla Firefox (2.0)
MSXML 4.0 SP2 (KB927978)
NavRules 2.2.4
NoteWorthy Composer
NVIDIA Drivers
PowerDVD
PPSDKRedistributables
QuickTime
Radialpoint Security Services
RealOne Player
Reptile
Roxio RecordNow Premier
Sausage Software Common Files Package
ScanToWeb
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Shockwave
Sonic RecordNow!
Sound Blaster Live!
Spybot - Search & Destroy 1.4
Verizon Online DSL
Verizon Online Help and Support
Verizon PC Security Checkup
Verizon Servicepoint 1.3.21
Viewpoint Media Player
Virtual Sound Canvas DXi
Winamp (remove only)
Windows Internet Explorer 7
Windows Media Format Runtime
Windows Media Player 10
Windows XP Service Pack 2
WinMX
WinRAR archiver
WinZip
X-Cleaner Deluxe
Yahoo! Install Manager




…The combofix log:

ComboFix 07-08-14 - "Mike" 2007-08-13 23:01:46.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.561 [GMT -4:00]
* Created a new restore point


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\ALLUSE~1\APPLIC~1.\salesmonitor
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007\Data\Abbr
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007\Data\ProductCode
C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiSpyware 2007\Data\Abbr
C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiSpyware 2007\Data\ProductCode
C:\DOCUME~1\LOCALS~1\APPLIC~1\.rdr.ini
C:\DOCUME~1\Mike\APPLIC~1.\winantispyware 2007
C:\DOCUME~1\Mike\APPLIC~1.\winantispyware 2007\Logs\update.log
C:\DOCUME~1\Mike\APPLIC~1\..\err.log
C:\DOCUME~1\Mike\APPLIC~1\Microsoft\20509.dat
C:\DOCUME~1\Mike\APPLIC~1\WinAntiSpyware 2007\Logs\update.log
C:\DOCUME~1\Mike\STARTM~1\Programs.\Outerinfo
C:\DOCUME~1\Mike\STARTM~1\Programs.\Outerinfo\Terms.lnk
C:\DOCUME~1\Mike\STARTM~1\Programs\Startup.\TA_Start.lnk
C:\DOCUME~1\NETWOR~1\APPLIC~1\.rdr.ini
C:\DOCUME~1\NETWOR~1\APPLIC~1\install.dat
C:\Documents and Settings\All Users.\documents\settings
C:\Documents and Settings\All Users.\documents\settings\desktop.ini
C:\Program Files\Common Files\homeqyrid5555.dll
C:\Program Files\Common Files\stem~1
C:\Program Files\Common Files\stem~1\??stem\
C:\Program Files\Common Files\stem~1\csrss.exe
C:\Program Files\Common Files\winantispyware 2007
C:\Program Files\Common Files\WinAntiSpyware 2007\err.log
C:\Program Files\Common Files\winantispyware 2007\err.log
C:\Program Files\Common Files\WinAntiSpyware 2007\uwas7cw.exe
C:\Program Files\Common Files\winantispyware 2007\uwas7cw.exe
C:\Program Files\Common Files\winantispyware 2007\WAS7Mon.exe
C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe
C:\Program Files\mantec~1
C:\Program Files\mantec~1\??ool32.exe
C:\Program Files\MSN\prohdyx.html
C:\Program Files\outerinfo
C:\Program Files\outerinfo\Terms.rtf
C:\Program Files\TTC.dll
C:\Program Files\XEROX\homeqyrid2.dll
C:\Program Files\XEROX\homeqyrid4444.dll
C:\tempc2
C:\tempc2\tmpFF.log
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\temp\brr
C:\temp\brr\tmpZTF.log
C:\Temp\fse
C:\Temp\fse\tmpZTF.log
C:\WINDOWS\csrss.exe
C:\WINDOWS\deskcfg.dat
C:\WINDOWS\g4356cbvy63.exe
C:\WINDOWS\spooldr.exe
C:\WINDOWS\sstem3~1
C:\WINDOWS\system32\1_exception.nls
C:\WINDOWS\system32\2045243641.dll
C:\WINDOWS\system32\b02FdUe
C:\WINDOWS\system32\byxwvtr.dll
C:\WINDOWS\system32\C1
C:\WINDOWS\system32\C3
C:\WINDOWS\system32\C3\wr7317.exe
C:\WINDOWS\system32\C5
C:\WINDOWS\system32\C9
C:\WINDOWS\system32\ckrumxbe.dll
C:\WINDOWS\SYSTEM32\cltlljxq.ini
C:\WINDOWS\system32\config\system~1\applic~1\install.dat
C:\WINDOWS\system32\config\systemprofile\application data\.rdr.ini
C:\WINDOWS\system32\configs
C:\WINDOWS\system32\ddcaabc.dll
C:\WINDOWS\system32\ddcyaby.dll
C:\WINDOWS\system32\dkekovxu.dll
C:\WINDOWS\SYSTEM32\dnjsfbmv.ini
C:\WINDOWS\system32\driver
C:\WINDOWS\system32\driver\w717.exe
C:\WINDOWS\system32\drivers\alert_icon.gif
C:\WINDOWS\system32\drivers\blank.gif
C:\WINDOWS\system32\drivers\box_1.gif
C:\WINDOWS\system32\drivers\box_2.gif
C:\WINDOWS\system32\drivers\box_3.gif
C:\WINDOWS\system32\drivers\button_buynow.gif
C:\WINDOWS\system32\drivers\button_freescan.gif
C:\WINDOWS\system32\drivers\close_icon.gif
C:\WINDOWS\system32\drivers\detect.htm
C:\WINDOWS\system32\drivers\download_box.gif
C:\WINDOWS\system32\drivers\footer_back.jpg
C:\WINDOWS\system32\drivers\fopn.sys
C:\WINDOWS\system32\drivers\header_1.gif
C:\WINDOWS\system32\drivers\header_2.gif
C:\WINDOWS\system32\drivers\header_3.gif
C:\WINDOWS\system32\drivers\header_4.gif
C:\WINDOWS\system32\drivers\header_bg.gif
C:\WINDOWS\system32\drivers\icon_warning.gif
C:\WINDOWS\system32\drivers\infected.gif
C:\WINDOWS\system32\drivers\main_back.gif
C:\WINDOWS\system32\drivers\perfect_cleaner_box.jpg
C:\WINDOWS\system32\drivers\product_1_header.gif
C:\WINDOWS\system32\drivers\product_1_name_small.gif
C:\WINDOWS\system32\drivers\product_2_header.gif
C:\WINDOWS\system32\drivers\product_2_name_small.gif
C:\WINDOWS\system32\drivers\product_3_header.gif
C:\WINDOWS\system32\drivers\product_3_name_small.gif
C:\WINDOWS\system32\drivers\product_features.gif
C:\WINDOWS\system32\drivers\pt.htm
C:\WINDOWS\system32\drivers\remove_spyware_button.gif
C:\WINDOWS\system32\drivers\s_detect.htm
C:\WINDOWS\system32\drivers\secuity_center_logo.gif
C:\WINDOWS\system32\drivers\sep_hor.gif
C:\WINDOWS\system32\drivers\sep_vert.gif
C:\WINDOWS\system32\drivers\shadow.jpg
C:\WINDOWS\system32\drivers\spacer.gif
C:\WINDOWS\system32\drivers\spy_away_box.jpg
C:\WINDOWS\system32\drivers\star.gif
C:\WINDOWS\system32\drivers\star_gray.gif
C:\WINDOWS\system32\drivers\star_gray_small.gif
C:\WINDOWS\system32\drivers\star_small.gif
C:\WINDOWS\system32\drivers\style.css
C:\WINDOWS\system32\drivers\v.gif
C:\WINDOWS\system32\drivers\warning_icon.gif
C:\WINDOWS\system32\drivers\win_logo.gif
C:\WINDOWS\system32\drivers\x.gif
C:\WINDOWS\system32\E5
C:\WINDOWS\system32\E5\wb720.exe
C:\WINDOWS\SYSTEM32\ebxmurkc.ini
C:\WINDOWS\system32\efcdbxv.dll
C:\WINDOWS\SYSTEM32\egjlm.bak1
C:\WINDOWS\SYSTEM32\egjlm.bak2
C:\WINDOWS\SYSTEM32\egjlm.ini
C:\WINDOWS\system32\eyypkcgx.exe
C:\WINDOWS\system32\f02WtR
C:\WINDOWS\system32\f02WtR\f02WtR1065.exe
C:\WINDOWS\system32\f06WtR
C:\WINDOWS\system32\f06WtR\f06WtR1083.exe
C:\WINDOWS\system32\F2
C:\WINDOWS\system32\F3
C:\WINDOWS\system32\guargwem.exe
C:\WINDOWS\system32\iaokglp.dll
C:\WINDOWS\system32\jcrrjtxs.exe
C:\WINDOWS\system32\kaclncki.exe
C:\WINDOWS\system32\kdqydgay.exe
C:\WINDOWS\system32\kjkefyiy.exe
C:\WINDOWS\system32\l3acdb.dll
C:\WINDOWS\system32\ldcore.dll
C:\WINDOWS\system32\ldinfo.ldr
C:\WINDOWS\system32\lgrtxmax.exe
C:\WINDOWS\system32\ljjgghf.dll
C:\WINDOWS\system32\mfojvwtu.exe
C:\WINDOWS\system32\mljge.dll
C:\WINDOWS\system32\msbind32.exe
C:\WINDOWS\system32\nbwuncuj.exe
C:\WINDOWS\system32\pmnoljg.dll
C:\WINDOWS\system32\psnodjcd.dll
C:\WINDOWS\system32\pwinlmdt.exe
C:\WINDOWS\system32\qomkhff.dll
C:\WINDOWS\system32\qxjlltlc.dll
C:\WINDOWS\system32\rorlqipv.dll
C:\WINDOWS\system32\setup155.exe
C:\WINDOWS\system32\vedxg3am1et3.exe
C:\WINDOWS\system32\vmbfsjnd.dll
C:\WINDOWS\system32\vpmgcylp.dll
C:\WINDOWS\system32\W3
C:\WINDOWS\system32\W3\tdwn23.exe
C:\WINDOWS\system32\win
C:\WINDOWS\system32\WinCore32.exe
C:\WINDOWS\system32\wnsapiit32.exe
C:\WINDOWS\system32\wvsdsbmy.dll
C:\WINDOWS\system32\yaacwbga.exe
C:\WINDOWS\system32\yayvtsq.dll
C:\WINDOWS\SYSTEM32\ymbsdsvw.ini
C:\WINDOWS\system32\ynol.dll
C:\WINDOWS\system32\zxdnt3d.cfg
C:\WINDOWS\TTC-4444.exe
C:\WINDOWS\TTC-5555.exe
C:\WINDOWS\uninst1014.exe
C:\WINDOWS\zsons0578.exe


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\LEGACY_CMDSERVICE
——-\LEGACY_DOMAINSERVICE
——-\LEGACY_FOPN
——-\LEGACY_NET_AGENT
——-\DomainService
——-\Net Agent
——-\nm


((((((((((((((((((((((((( Files Created from 2007-07-14 to 2007-08-14 )))))))))))))))))))))))))))))))


2007-08-13 22:59 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-10 22:57 d——– C:\Program Files\CCleaner
2007-08-10 22:02 d——– C:\hijackthis
2007-08-10 21:24 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-08-06 16:35 d–h—– C:\WINDOWS\PIF
2007-08-06 16:20 d——– C:\Program Files\Common Files\Scanner
2007-08-06 16:20 d——– C:\Program Files\Common Files\Authentium
2007-08-06 16:14 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Verizon
2007-08-05 22:24 d–hs—- C:\WINDOWS\TWlrZQ
2007-08-03 22:38 d——– C:\Program Files\X-Cleaner
2007-08-03 22:37 2,285,336 –a—— C:\xcleaner_full_setup.exe
2007-08-03 19:28 192,622 –a—— C:\WINDOWS\SYSTEM32\owintmdt.exe
2007-07-29 00:57 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
2007-07-15 23:27 d——– C:\DOCUME~1\Mike\APPLIC~1\WinRAR
2007-07-14 23:45 1,207,026 –a—— C:\wrar370.exe


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-13 22:52 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-08-13 22:49 ——— d——– C:\Program Files\AIM+
2007-08-10 23:01 ——— d——– C:\Program Files\EA SPORTS
2007-08-10 22:35 ——— d——– C:\Program Files\Google
2007-08-07 02:44 ——— d——– C:\Program Files\BitTorrent
2007-08-07 02:34 ——— d——– C:\Program Files\IrfanView
2007-08-06 16:20 ——— d——– C:\Program Files\Verizon
2007-08-06 16:01 375296 –a—— C:\WINDOWS\system32\drivers\tcpip.sys
2007-08-06 16:01 375296 –a—— C:\WINDOWS\system32\dllcache\tcpip.sys
2007-08-03 20:18 ——— d——– C:\Program Files\IEForge
2007-06-20 19:35 6820520 –a—— C:\FirefoxGoogleToolbarSetup.exe
2007-06-15 23:24 ——— d——– C:\Program Files\America Online 9.0
2007-06-15 22:25 ——— d——– C:\Program Files\Viewpoint
2007-05-16 11:12 86528 ——— C:\WINDOWS\system32\dllcache\directdb.dll
2007-05-16 11:12 85504 ——— C:\WINDOWS\system32\dllcache\wabimp.dll
2007-05-16 11:12 683520 –a—— C:\WINDOWS\system32\inetcomm.dll
2007-05-16 11:12 683520 ——— C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-05-16 11:12 510976 ——— C:\WINDOWS\system32\dllcache\wab32.dll
2007-05-16 11:12 1314816 ——— C:\WINDOWS\system32\dllcache\msoe.dll
2006-08-14 18:08 976020 –a—— C:\Program Files\BDAXP.cab
2006-08-14 18:08 917318 –a—— C:\Program Files\Apr2006_MDX1_x86.cab
2006-08-14 18:08 88102 –a—— C:\Program Files\AUG2006_xinput_x64.cab
2006-08-14 18:08 87989 –a—— C:\Program Files\Apr2006_xinput_x64.cab
2006-08-14 18:08 86925 –a—— C:\Program Files\Oct2005_xinput_x64.cab
2006-08-14 18:08 82338 –a—— C:\Program Files\dxupdate.cab
2006-08-14 18:08 74520 –a—— C:\Program Files\DSETUP.dll
2006-08-14 18:08 703080 –a—— C:\Program Files\BDA.cab
2006-08-14 18:08 484632 –a—— C:\Program Files\DXSETUP.exe
2006-08-14 18:08 47018 –a—— C:\Program Files\AUG2006_xinput_x86.cab
2006-08-14 18:08 46898 –a—— C:\Program Files\Apr2006_xinput_x86.cab
2006-08-14 18:08 46247 –a—— C:\Program Files\Oct2005_xinput_x86.cab
2006-08-14 18:08 41995 –a—— C:\Program Files\dxdllreg_x86.cab
2006-08-14 18:08 4163518 –a—— C:\Program Files\Apr2006_MDX1_x86_Archive.cab
2006-08-14 18:08 2248984 –a—— C:\Program Files\dsetup32.dll
2006-08-14 18:08 183863 –a—— C:\Program Files\AUG2006_XACT_x64.cab
2006-08-14 18:08 181745 –a—— C:\Program Files\JUN2006_XACT_x64.cab
2006-08-14 18:08 180021 –a—— C:\Program Files\Apr2006_XACT_x64.cab
2006-08-14 18:08 179247 –a—— C:\Program Files\Feb2006_XACT_x64.cab
2006-08-14 18:08 15493481 –a—— C:\Program Files\DirectX.cab
2006-08-14 18:08 1398718 –a—— C:\Program Files\Apr2006_d3dx9_30_x64.cab
2006-08-14 18:08 138195 –a—— C:\Program Files\AUG2006_XACT_x86.cab
2006-08-14 18:08 1363684 –a—— C:\Program Files\Feb2006_d3dx9_29_x64.cab
2006-08-14 18:08 1358864 –a—— C:\Program Files\Dec2005_d3dx9_28_x64.cab
2006-08-14 18:08 1351430 –a—— C:\Program Files\Aug2005_d3dx9_27_x64.cab
2006-08-14 18:08 1348242 –a—— C:\Program Files\Apr2005_d3dx9_25_x64.cab
2006-08-14 18:08 134631 –a—— C:\Program Files\JUN2006_XACT_x86.cab
2006-08-14 18:08 133991 –a—— C:\Program Files\Apr2006_XACT_x86.cab
2006-08-14 18:08 1336890 –a—— C:\Program Files\Jun2005_d3dx9_26_x64.cab
2006-08-14 18:08 133297 –a—— C:\Program Files\Feb2006_XACT_x86.cab
2006-08-14 18:08 13265040 –a—— C:\Program Files\dxnt.cab
2006-08-14 18:08 1248387 –a—— C:\Program Files\Feb2005_d3dx9_24_x64.cab
2006-08-14 18:08 1156363 –a—— C:\Program Files\BDANT.cab
2006-08-14 18:08 1116109 –a—— C:\Program Files\Apr2006_d3dx9_30_x86.cab
2006-08-14 18:08 1085608 –a—— C:\Program Files\Feb2006_d3dx9_29_x86.cab
2006-08-14 18:08 1080344 –a—— C:\Program Files\Dec2005_d3dx9_28_x86.cab
2006-08-14 18:08 1079850 –a—— C:\Program Files\Apr2005_d3dx9_25_x86.cab
2006-08-14 18:08 1078532 –a—— C:\Program Files\Aug2005_d3dx9_27_x86.cab
2006-08-14 18:08 1065813 –a—— C:\Program Files\Jun2005_d3dx9_26_x86.cab
2006-08-14 18:08 1014113 –a—— C:\Program Files\Feb2005_d3dx9_24_x86.cab

C:\WINDOWS\system32\drivers\tcpip.sys … is infected !! (additional data below)
359,936 2005-05-25 19:07:12 C:\WINDOWS\$hf_mig$\KB893066\SP2QFE\tcpip.sys
360,448 2006-01-13 17:07:08 C:\WINDOWS\$hf_mig$\KB913446\SP2QFE\tcpip.sys
360,576 2006-04-20 12:18:35 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
332,928 2002-08-29 11:00:00 C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
359,040 2004-08-04 06:14:40 C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
375,296 2007-08-06 20:01:50 C:\WINDOWS\SYSTEM32\DLLCACHE\tcpip.sys
375,296 2007-08-06 20:01:53 C:\WINDOWS\SYSTEM32\DRIVERS\tcpip.sys


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0706A660-14F0-4EE3-FC9B-467C68CC84B4}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3F3E26F5-9CAC-4AA9-B343-0FA3CE5D0658}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E2426436-B558-4374-843F-F4548DEE5EB5}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 13:22]
"{08-87-74-4E-ZN}"="C:\WINDOWS\SYSTEM32\dwdsrngt.exe" []
"hotygep"="C:\Program Files\Internet Explorer\hotygep1.exe" [2007-08-07 16:30]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]
"SpybotDeletingC9677"=cmd /c del "C:\WINDOWS\SYSTEM32\ldcore.dll_tobedeleted_old"
"SpybotSnD"="C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"=Narrator.exe

C:\Documents and Settings\Mike\Start Menu\Programs\Startup\
DESKTOP.INI [2002-09-03 11:00:00]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
DESKTOP.INI [2002-09-03 11:00:00]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
@=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
Source= C:\Program Files\MSN\prohdyx.html
FriendlyName=

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
backup=C:\WINDOWS\pss\Acrobat Assistant.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Mike^Start Menu^Programs^Startup^PowerReg Scheduler V3.exe]
path=C:\Documents and Settings\Mike\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe
backup=C:\WINDOWS\pss\PowerReg Scheduler V3.exeStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Mike^Start Menu^Programs^Startup^TA_Start.lnk]
path=C:\Documents and Settings\Mike\Start Menu\Programs\Startup\TA_Start.lnk
backup=C:\WINDOWS\pss\TA_Start.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Mike^Start Menu^Programs^Startup^Think-Adz.lnk]
path=C:\Documents and Settings\Mike\Start Menu\Programs\Startup\Think-Adz.lnk
backup=C:\WINDOWS\pss\Think-Adz.lnkStartup


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Instant Messanger]
aim.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avserve.exe]
C:\WINDOWS\avserve.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bantool]
C:\WINDOWS\system32\ie_ban.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
BCMSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
"C:\Program Files\DellSupport\DSAgnt.exe" /startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\diagent]
"C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
C:\WINDOWS\System32\DLA\DLACTRLW.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDSentry]
C:\WINDOWS\System32\DSentry.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ExploreUpdSched]
C:\WINDOWS\system32\owintmdt.exe SKY009

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ezwzsmdA]
C:\WINDOWS\ezwzsmdA.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Febcdtgx]
"C:\Program Files\??mantec\??ool32.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\g4356cbvy63]
C:\WINDOWS\g4356cbvy63

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IS CfgWiz]
C:\Program Files\Common Files\Symantec Shared\cfgwiz.exe /GUID NIS /CMDLINE "REBOOT"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Update]
msawindows.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
"C:\Program Files\Microsoft Money\System\mnyexpr.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge]
C:\PROGRA~1\Verizon\SMARTB~1\MotiveSB.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBInstall]
C:\DOCUME~1\Mike\LOCALS~1\Temp\MBDownloader_876919.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\WINDOWS\System32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
"C:\Program Files\Dell\Media Experience\PCMService.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\rdcmxnovdon]
C:\WINDOWS\System32\fugaxhsf.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
"C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatchTray.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
C:\WINDOWS\retadpu1000106.exe 61A847B5BBF72813329B385772FF01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Salestart]
"C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Service Pack 1]
C:\WINDOWS\system32\vedxg6ame4.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemOptimizer]
rundll32.exe "C:\WINDOWS\system32\wvsdsbmy.dll",forkonce

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
C:\WINDOWS\UpdReg.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\URLLSTCK.exe]
C:\Program Files\Norton Internet Security\UrlLstCk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VerizonServicepoint.exe]
C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinCore32.exe]
C:\WINDOWS\system32\WinCore32.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\X-Cleaner Deluxe]
"C:\PROGRA~1\X-CLEA~1\XCleaner_full.exe" -turbo -autostart -NOREBOOT

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{08-87-74-4E-ZN}]
c:\windows\system32\lsdsregl.exe SKY009

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WANMiniportService"=2 (0x2)
"Viewpoint Manager Service"=2 (0x2)
"RoxLiveShare"=2 (0x2)
"Net Agent"=2 (0x2)
"DSBrokerService"=3 (0x3)

R0 PzWDM;PzWDM;C:\WINDOWS\system32\Drivers\PzWDM.sys
R3 BCMModem;BCM V.92 56K Modem;C:\WINDOWS\system32\DRIVERS\BCMSM.sys
R3 P16X;Creative SB Live! Series (WDM);C:\WINDOWS\system32\drivers\P16X.sys
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver;C:\WINDOWS\system32\drivers\WmBEnum.sys
R3 WmXlCore;Logitech WingMan Translation Layer Driver;C:\WINDOWS\system32\drivers\WmXlCore.sys
S3 hamachi_oem;PlayLinc Adapter;C:\WINDOWS\system32\DRIVERS\gan_adapter.sys
S3 PortRst;PortRst;C:\WINDOWS\system32\DRIVERS\PortRst.sys
S3 WmFilter;Logitech WingMan HID Filter Driver;C:\WINDOWS\system32\drivers\WmFilter.sys
S3 WmVirHid;Logitech Virtual Hid Device Driver;C:\WINDOWS\system32\drivers\WmVirHid.sys


**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-13 23:10:02
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

**************************************************************************

Completion time: 2007-08-13 23:11:45 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-08-13 23:11

— E O F —










…And a fresh HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 11:31:06 PM, on 8/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\hotygep1.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\msiexec.exe
C:\Documents and Settings\Mike\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: 0 - {0706A660-14F0-4EE3-FC9B-467C68CC84B4} - (no file)
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {3F3E26F5-9CAC-4AA9-B343-0FA3CE5D0658} - \
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {E2426436-B558-4374-843F-F4548DEE5EB5} - (no file)
O3 - Toolbar: (no name) - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [{08-87-74-4E-ZN}] C:\WINDOWS\SYSTEM32\dwdsrngt.exe CHD003
O4 - HKLM\..\Run: [hotygep] C:\Program Files\Internet Explorer\hotygep1.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…DSL/tgctlcm.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab46479.cab
O16 - DPF: {1FE5F6CD-7490-4428-9E79-830E8CC55B8B} (VCView Class) - http://24.193.222.199:12345/control/VCViewAtl.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (ZoneBuddy Class) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab32846.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab32846.cab
O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) - http://zone.msn.com/bingame/zpagames/zpa_shvl.cab50560.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (StadiumProxy Class) - http://zone.msn.com/binframework/v10/StProxy.cab41227.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: RoxMediaDB - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
O23 - Service: Roxio Hard Drive Watcher (RoxWatch) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
It is going to take us quite some time to clean up this mess so let's get started.


A. I see that Viewpoint is installed. Viewpoint, Viewpoint Manager, Viewpoint Media Player are Viewpoint components which are installed as a side effect of installing other software, most notably AOL and AOL Instant Messenger (AIM). Viewpoint Manager is responsible for managing and updating Viewpoint Media Player’s components. You can disable this using the Viewpoint Manager Control Panel found in the Windows Control Panel menu. By selecting Disable auto-updating for the Viewpoint Manager – the player will no longer attempt to check for updates. Anything that is installed without your consent is suspect. Read what Viewpoint says and make your own decision.

To provide a satisfying consumer experience and to operate effectively, the Viewpoint Media Player periodically sends information to servers at Viewpoint. Each installation of the Viewpoint Media Player is identifiable to Viewpoint via a Customer Unique Identifier (CUID), an alphanumeric identifier embedded in the Viewpoint Media Player. The Viewpoint Media Player randomly generates the CUID during installation and uses it to indicate a unique installation of the product. A CUID is never connected to a user's name, email address, or other personal contact information. CUIDs are used for the sole purpose of filtering redundant information. Each of these information exchanges occurs anonymously.


Viewpoint Manager is considered as foistware instead of malware since it is installed without user's approval but doesn't spy or do anything "bad". This may change, read Viewpoint to Plunge Into Adware
I recommend that you remove the Viewpoint products; however, decide for yourself. To uninstall the Viewpoint components (Viewpoint, Viewpoint Manager, Viewpoint Media Player):

1. Click Start, then Settings, then click Control Panel.
2. In Control Panel, double-click Add or Remove Programs.
3. In Add or Remove Programs, Remove the Viewpoint component
4. Do the same for each Viewpoint component.


B. The first thing that requires fixing is the following.

C:\WINDOWS\system32\drivers\tcpip.sys … is infected !! (additional data below)


There are a couple of ways of doing it. We will start off with the file transfer method first:


Open Notepad and copy and paste the content of the following codebox into it:

@echo off
(
copy /y /b C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys C:\WINDOWS\system32\dllcache
copy /y /b C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys C:\WINDOWS\system32\drivers
vfind -tf %systemroot%\tcpip.sys
)>>log.txt
notepad log.txt

Save this as look.bat , choose to save as **all files* and place it on your desktop.
This is how the batch should look afterwards: [external image: Posted Image]
Doubleclick look.bat
Notepad will open with some txt in it. Copy and paste the contents in your next reply.


C. Please run ComboFix again and post the ComboFix.txt that will popup as well as log.txt
1 file(s) copied.
1 file(s) copied.
C:\WINDOWS\$hf_mig$\KB893066\SP2QFE\tcpip.sys
C:\WINDOWS\$hf_mig$\KB913446\SP2QFE\tcpip.sys
C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
C:\WINDOWS\SYSTEM32\DLLCACHE\tcpip.sys
C:\WINDOWS\SYSTEM32\DRIVERS\tcpip.sys







And….






ComboFix 07-08-14 - "Mike" 2007-08-14 18:32:45.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.672 [GMT -4:00]


((((((((((((((((((((((((( Files Created from 2007-07-14 to 2007-08-14 )))))))))))))))))))))))))))))))


2007-08-13 23:47 94,416 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\aswmon2.sys
2007-08-13 23:47 92,848 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\aswmon.sys
2007-08-13 23:47 783,224 –a—— C:\WINDOWS\SYSTEM32\aswBoot.exe
2007-08-13 23:47 42,912 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\aswTdi.sys
2007-08-13 23:47 26,624 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\aavmker4.sys
2007-08-13 23:47 23,152 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\aswRdr.sys
2007-08-13 22:59 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-10 22:57 d——– C:\Program Files\CCleaner
2007-08-10 22:02 d——– C:\hijackthis
2007-08-10 21:24 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-08-06 16:35 d–h—– C:\WINDOWS\PIF
2007-08-06 16:20 d——– C:\Program Files\Common Files\Scanner
2007-08-06 16:20 d——– C:\Program Files\Common Files\Authentium
2007-08-06 16:14 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Verizon
2007-08-05 22:24 d–hs—- C:\WINDOWS\TWlrZQ
2007-08-03 22:38 d——– C:\Program Files\X-Cleaner
2007-08-03 22:37 2,285,336 –a—— C:\xcleaner_full_setup.exe
2007-08-03 19:28 192,622 –a—— C:\WINDOWS\SYSTEM32\owintmdt.exe
2007-07-29 00:57 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
2007-07-15 23:27 d——– C:\DOCUME~1\Mike\APPLIC~1\WinRAR
2007-07-14 23:45 1,207,026 –a—— C:\wrar370.exe


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-14 18:27 ——— d——– C:\Program Files\Viewpoint
2007-08-13 22:52 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-08-13 22:49 ——— d——– C:\Program Files\AIM+
2007-08-10 23:01 ——— d——– C:\Program Files\EA SPORTS
2007-08-10 22:35 ——— d——– C:\Program Files\Google
2007-08-07 02:44 ——— d——– C:\Program Files\BitTorrent
2007-08-07 02:34 ——— d——– C:\Program Files\IrfanView
2007-08-06 16:20 ——— d——– C:\Program Files\Verizon
2007-08-03 20:18 ——— d——– C:\Program Files\IEForge
2007-07-27 17:57 95608 –a—— C:\WINDOWS\system32\AVASTSS.scr
2007-06-20 19:35 6820520 –a—— C:\FirefoxGoogleToolbarSetup.exe
2007-06-15 23:24 ——— d——– C:\Program Files\America Online 9.0
2007-05-16 11:12 86528 ——— C:\WINDOWS\system32\dllcache\directdb.dll
2007-05-16 11:12 85504 ——— C:\WINDOWS\system32\dllcache\wabimp.dll
2007-05-16 11:12 683520 –a—— C:\WINDOWS\system32\inetcomm.dll
2007-05-16 11:12 683520 ——— C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-05-16 11:12 510976 ——— C:\WINDOWS\system32\dllcache\wab32.dll
2007-05-16 11:12 1314816 ——— C:\WINDOWS\system32\dllcache\msoe.dll
2006-08-14 18:08 976020 –a—— C:\Program Files\BDAXP.cab
2006-08-14 18:08 917318 –a—— C:\Program Files\Apr2006_MDX1_x86.cab
2006-08-14 18:08 88102 –a—— C:\Program Files\AUG2006_xinput_x64.cab
2006-08-14 18:08 87989 –a—— C:\Program Files\Apr2006_xinput_x64.cab
2006-08-14 18:08 86925 –a—— C:\Program Files\Oct2005_xinput_x64.cab
2006-08-14 18:08 82338 –a—— C:\Program Files\dxupdate.cab
2006-08-14 18:08 74520 –a—— C:\Program Files\DSETUP.dll
2006-08-14 18:08 703080 –a—— C:\Program Files\BDA.cab
2006-08-14 18:08 484632 –a—— C:\Program Files\DXSETUP.exe
2006-08-14 18:08 47018 –a—— C:\Program Files\AUG2006_xinput_x86.cab
2006-08-14 18:08 46898 –a—— C:\Program Files\Apr2006_xinput_x86.cab
2006-08-14 18:08 46247 –a—— C:\Program Files\Oct2005_xinput_x86.cab
2006-08-14 18:08 41995 –a—— C:\Program Files\dxdllreg_x86.cab
2006-08-14 18:08 4163518 –a—— C:\Program Files\Apr2006_MDX1_x86_Archive.cab
2006-08-14 18:08 2248984 –a—— C:\Program Files\dsetup32.dll
2006-08-14 18:08 183863 –a—— C:\Program Files\AUG2006_XACT_x64.cab
2006-08-14 18:08 181745 –a—— C:\Program Files\JUN2006_XACT_x64.cab
2006-08-14 18:08 180021 –a—— C:\Program Files\Apr2006_XACT_x64.cab
2006-08-14 18:08 179247 –a—— C:\Program Files\Feb2006_XACT_x64.cab
2006-08-14 18:08 15493481 –a—— C:\Program Files\DirectX.cab
2006-08-14 18:08 1398718 –a—— C:\Program Files\Apr2006_d3dx9_30_x64.cab
2006-08-14 18:08 138195 –a—— C:\Program Files\AUG2006_XACT_x86.cab
2006-08-14 18:08 1363684 –a—— C:\Program Files\Feb2006_d3dx9_29_x64.cab
2006-08-14 18:08 1358864 –a—— C:\Program Files\Dec2005_d3dx9_28_x64.cab
2006-08-14 18:08 1351430 –a—— C:\Program Files\Aug2005_d3dx9_27_x64.cab
2006-08-14 18:08 1348242 –a—— C:\Program Files\Apr2005_d3dx9_25_x64.cab
2006-08-14 18:08 134631 –a—— C:\Program Files\JUN2006_XACT_x86.cab
2006-08-14 18:08 133991 –a—— C:\Program Files\Apr2006_XACT_x86.cab
2006-08-14 18:08 1336890 –a—— C:\Program Files\Jun2005_d3dx9_26_x64.cab
2006-08-14 18:08 133297 –a—— C:\Program Files\Feb2006_XACT_x86.cab
2006-08-14 18:08 13265040 –a—— C:\Program Files\dxnt.cab
2006-08-14 18:08 1248387 –a—— C:\Program Files\Feb2005_d3dx9_24_x64.cab
2006-08-14 18:08 1156363 –a—— C:\Program Files\BDANT.cab
2006-08-14 18:08 1116109 –a—— C:\Program Files\Apr2006_d3dx9_30_x86.cab
2006-08-14 18:08 1085608 –a—— C:\Program Files\Feb2006_d3dx9_29_x86.cab
2006-08-14 18:08 1080344 –a—— C:\Program Files\Dec2005_d3dx9_28_x86.cab
2006-08-14 18:08 1079850 –a—— C:\Program Files\Apr2005_d3dx9_25_x86.cab
2006-08-14 18:08 1078532 –a—— C:\Program Files\Aug2005_d3dx9_27_x86.cab
2006-08-14 18:08 1065813 –a—— C:\Program Files\Jun2005_d3dx9_26_x86.cab
2006-08-14 18:08 1014113 –a—— C:\Program Files\Feb2005_d3dx9_24_x86.cab


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0706A660-14F0-4EE3-FC9B-467C68CC84B4}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3F3E26F5-9CAC-4AA9-B343-0FA3CE5D0658}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E2426436-B558-4374-843F-F4548DEE5EB5}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 13:22]
"{08-87-74-4E-ZN}"="C:\WINDOWS\SYSTEM32\dwdsrngt.exe" []
"hotygep"="C:\Program Files\Internet Explorer\hotygep1.exe" [2007-08-07 16:30]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-07-27 18:03]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"=Narrator.exe

C:\Documents and Settings\Mike\Start Menu\Programs\Startup\
DESKTOP.INI [2002-09-03 11:00:00]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
DESKTOP.INI [2002-09-03 11:00:00]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
@=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
Source= C:\Program Files\MSN\prohdyx.html
FriendlyName=

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
backup=C:\WINDOWS\pss\Acrobat Assistant.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Mike^Start Menu^Programs^Startup^PowerReg Scheduler V3.exe]
path=C:\Documents and Settings\Mike\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe
backup=C:\WINDOWS\pss\PowerReg Scheduler V3.exeStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Mike^Start Menu^Programs^Startup^TA_Start.lnk]
path=C:\Documents and Settings\Mike\Start Menu\Programs\Startup\TA_Start.lnk
backup=C:\WINDOWS\pss\TA_Start.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Mike^Start Menu^Programs^Startup^Think-Adz.lnk]
path=C:\Documents and Settings\Mike\Start Menu\Programs\Startup\Think-Adz.lnk
backup=C:\WINDOWS\pss\Think-Adz.lnkStartup


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Instant Messanger]
aim.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avserve.exe]
C:\WINDOWS\avserve.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bantool]
C:\WINDOWS\system32\ie_ban.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
BCMSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
"C:\Program Files\DellSupport\DSAgnt.exe" /startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\diagent]
"C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
C:\WINDOWS\System32\DLA\DLACTRLW.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDSentry]
C:\WINDOWS\System32\DSentry.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ExploreUpdSched]
C:\WINDOWS\system32\owintmdt.exe SKY009

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ezwzsmdA]
C:\WINDOWS\ezwzsmdA.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Febcdtgx]
"C:\Program Files\??mantec\??ool32.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\g4356cbvy63]
C:\WINDOWS\g4356cbvy63

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IS CfgWiz]
C:\Program Files\Common Files\Symantec Shared\cfgwiz.exe /GUID NIS /CMDLINE "REBOOT"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Update]
msawindows.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
"C:\Program Files\Microsoft Money\System\mnyexpr.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge]
C:\PROGRA~1\Verizon\SMARTB~1\MotiveSB.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBInstall]
C:\DOCUME~1\Mike\LOCALS~1\Temp\MBDownloader_876919.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\WINDOWS\System32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
"C:\Program Files\Dell\Media Experience\PCMService.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\rdcmxnovdon]
C:\WINDOWS\System32\fugaxhsf.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
"C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatchTray.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
C:\WINDOWS\retadpu1000106.exe 61A847B5BBF72813329B385772FF01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Salestart]
"C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Service Pack 1]
C:\WINDOWS\system32\vedxg6ame4.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemOptimizer]
rundll32.exe "C:\WINDOWS\system32\wvsdsbmy.dll",forkonce

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
C:\WINDOWS\UpdReg.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\URLLSTCK.exe]
C:\Program Files\Norton Internet Security\UrlLstCk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VerizonServicepoint.exe]
C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinCore32.exe]
C:\WINDOWS\system32\WinCore32.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\X-Cleaner Deluxe]
"C:\PROGRA~1\X-CLEA~1\XCleaner_full.exe" -turbo -autostart -NOREBOOT

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{08-87-74-4E-ZN}]
c:\windows\system32\lsdsregl.exe SKY009

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WANMiniportService"=2 (0x2)
"Viewpoint Manager Service"=2 (0x2)
"RoxLiveShare"=2 (0x2)
"Net Agent"=2 (0x2)
"DSBrokerService"=3 (0x3)

R0 PzWDM;PzWDM;C:\WINDOWS\system32\Drivers\PzWDM.sys
R3 BCMModem;BCM V.92 56K Modem;C:\WINDOWS\system32\DRIVERS\BCMSM.sys
R3 P16X;Creative SB Live! Series (WDM);C:\WINDOWS\system32\drivers\P16X.sys
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver;C:\WINDOWS\system32\drivers\WmBEnum.sys
R3 WmXlCore;Logitech WingMan Translation Layer Driver;C:\WINDOWS\system32\drivers\WmXlCore.sys
S3 hamachi_oem;PlayLinc Adapter;C:\WINDOWS\system32\DRIVERS\gan_adapter.sys
S3 PortRst;PortRst;C:\WINDOWS\system32\DRIVERS\PortRst.sys
S3 WmFilter;Logitech WingMan HID Filter Driver;C:\WINDOWS\system32\drivers\WmFilter.sys
S3 WmVirHid;Logitech Virtual Hid Device Driver;C:\WINDOWS\system32\drivers\WmVirHid.sys


**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-14 18:35:24
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-14 18:36:09
C:\ComboFix-quarantined-files.txt … 2007-08-14 18:35
C:\ComboFix2.txt … 2007-08-13 23:11

— E O F —








Also, i removed Viewpoint.
A. 1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\WINDOWS\SYSTEM32\owintmdt.exe
C:\Documents and Settings\Mike\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe
C:\WINDOWS\pss\PowerReg Scheduler V3.exeStartup
C:\Documents and Settings\Mike\Start Menu\Programs\Startup\TA_Start.lnk
C:\WINDOWS\pss\TA_Start.lnkStartup
C:\WINDOWS\pss\Think-Adz.lnkStartup
C:\WINDOWS\avserve.exe
C:\WINDOWS\system32\ie_ban.exe
C:\WINDOWS\system32\owintmdt.exe
C:\WINDOWS\ezwzsmdA.exe
C:\WINDOWS\g4356cbvy63
C:\WINDOWS\System32\fugaxhsf.exe
C:\WINDOWS\retadpu1000106.exe
C:\WINDOWS\system32\vedxg6ame4.exe
c:\windows\system32\lsdsregl.exe

Folder::
C:\Program Files\Viewpoint
C:\WINDOWS\TWlrZQ

Registry::
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0706A660-14F0-4EE3-FC9B-467C68CC84B4}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3F3E26F5-9CAC-4AA9-B343-0FA3CE5D0658}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E2426436-B558-4374-843F-F4548DEE5EB5}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"{08-87-74-4E-ZN}"=-
"hotygep"=-
[-HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Mike^Start Menu^Programs^Startup^PowerReg Scheduler V3.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Mike^Start Menu^Programs^Startup^TA_Start.lnk]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Mike^Start Menu^Programs^Startup^Think-Adz.lnk]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avserve.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bantool]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ExploreUpdSched]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ezwzsmdA]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Febcdtgx]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\g4356cbvy63]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBInstall]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\rdcmxnovdon]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Salestart]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Service Pack 1]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemOptimizer]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{08-87-74-4E-ZN}]


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

B. Please use the Internet Explorer browser, and do an online scan with Kaspersky Online Scanner
Click Yes, when prompted to install its ActiveX component.
(Note.. for Internet Explorer 7 users: If at any time you have trouble with the "Accept" button of the license, click on the "Zoom" tool located at the bottom right of the IE window and set the zoom to 75 %. Once the license has been accepted, reset to 100%.)
The program launches and downloads the latest definition files.
  • Once the files are downloaded click on Next
  • Click on Scan Settings and configure as follows:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:Scan Archives
      Scan Mail Bases
  • Click OK and, under select a target to scan, select My Computer
When the scan is done, in the Scan is completed window (below), any infection is displayed.
There is no option to clean/disinfect, however, we need to analyze the information on the report.
[external image: Posted Image]
[external image: Posted Image]
To obtain the report:
Click on: Save Report As (above - red blinking arrow)
Next, in the Save as prompt, Save in area, select: Desktop
In the File name area, use KScan, or something similar
In Save as type, click the drop arrow and select: Text file [*.txt]
Then, click: Save
Please post the Kaspersky Online Scanner Report in your reply, along with a fresh HijackThis log


C. Reports/logs to Post:
  • ComboFix.txt
  • Fresh HJT log
  • Kaspersky log
I hope you are well and not experiencing any difficulties carrying out my last set of instructions. If you are, do not hesitate to ask for further explanations. If however, your problem has been solved or you no longer require our assistance, please advise us accordingly and we will archive your topic.

Trevuren

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI