This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]Need Expert Review

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Would someone more expert than myself look at the log below, please.

I ran Avast AV, Spybot S&D and AdAware on my fairly new system (refurbished and reformatted Dell Optiplex GX 240) and found a number of trojans which I either quarantined as recommended by AVast, or removed with S&D, but one of them was WIN32.VB.ahq which I understand is a notoriously difficult remove.

Would appreciate any comments or advice

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:15:55 AM, on 8/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\NoAds\NoAds.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HiJackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\Explorer.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [IESet] IExplorer.dll .dbt
O4 - HKLM\..\RunServices: [IESet] IExplorer.dll .dbt
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NoAds] "C:\Program Files\NoAds\NoAds.exe"
O4 - HKCU\..\Run: [BitTorrent] "C:\Documents and Settings\T & C\My Documents\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [IESet] IExplorer.dll .dbt
O4 - HKUS\S-1-5-18\..\Run: [IESet] IExplorer.dll .dbt (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [IESet] IExplorer.dll .dbt (User 'Default user')
O4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\lldsrngq.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.amaena.com
O15 - Trusted Zone: *.drivecleaner.com
O15 - Trusted Zone: *.errorprotector.com
O15 - Trusted Zone: *.errorsafe.com
O15 - Trusted Zone: *.systemdoctor.com
O15 - Trusted Zone: *.winantispyware.com
O15 - Trusted Zone: *.winantivirus.com
O15 - Trusted Zone: *.winfixer.com
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (AlternaTIFF ActiveX) - https://www.rcashasp.com/rcash/apps/realmtiff.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {25365FF3-2746-4230-9DA7-163CCA318309} (Automatic Driver Installation Control) - http://inst.c-wss.com/n035p/EN/install/gtdownlr.cab
O16 - DPF: {3BA3B159-7533-4F96-A2CE-EE5894BBD3D5} (Scanner.SysScanner) - http://i.dell.com/images/global/js/scanner/SYSSCANNER.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O16 - DPF: {E5ABEB00-B357-4884-9949-77B2C71A7EE3} (BoardCtl Class) - http://www.intel.com/design/motherbd/boardid/BoardID.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
Hi nomanselizabeth,

Your computer appears to have been infected by a keylogging trojan. These programs have the ability to steal passwords and other information from your system. If you use your computer for sensitive purposes such as internet banking then I recommend you take the following steps immediately:
  • Use another, uninfected computer to change all your internet passwords, especially ones with financial implications such as banks, paypal, ebay, etc. You should also change the passwords for any other site you use.
  • Call your bank(s), credit card company or any other institution which may be affected and advise them that your login/password or credit card information may have been stolen and ask what steps to take with regard to your account.
  • Consider what other private information could possibly have been taken from your computer and take appropriate steps
Please download ComboFix to your desktop
  • Double click combofix.exe and follow the prompts.
  • Note: Do not click ComboFix's window while it's running - it may cause it to stall!
  • When finished, it shall produce a log for you, please post it in your next response.
Once complete, please post the Combofix report and a new HijackThis log.
Thank you for your help.

I ran ComboFix as directed. Here is the log. I have also attached a new HiJack this log.

A new IE icon appeared after the Combo Fix reboot on my desktop - is this a result of the ComboFix run?

Also, as I mentioned I have Windows Firewall activated, keep Avast AV in realtime protection with the modules active, run SpyBot and Adaware and keep NoAds active for popups, but still seem to be seeing a lot of trojans and spyware. What additional would you recommend to stop this from fouling up my system every few days?




ComboFix 07-08-17.2 - "User" 2007-08-20 8:17:28.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.218 [GMT -4:00]
* Created a new restore point


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\User\STARTM~1\Programs\Startup.\TA_Start.lnk
C:\Temp\fse
C:\WINDOWS\notedad.exe
C:\windows\system32\explorer.exe
C:\WINDOWS\system32\explorer.exe
C:\WINDOWS\system32\f02WtR
C:\WINDOWS\system32\iexplorer.dll .dbt
C:\WINDOWS\system32\mp43.exe


((((((((((((((((((((((((( Files Created from 2007-07-20 to 2007-08-20 )))))))))))))))))))))))))))))))


2007-08-20 08:15 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-19 21:03 4,096 –a—— C:\WINDOWS\system32\drivers\ohciusb.sys
2007-08-19 21:03 13,824 –a—— C:\WINDOWS\system32\regsvc.exe
2007-08-19 18:40 22,752 –a—— C:\WINDOWS\system32\spupdsvc.exe
2007-08-19 18:40 d–h—– C:\WINDOWS\$hf_mig$
2007-08-19 18:40 d——– C:\WINDOWS\system32\PreInstall
2007-08-19 18:37 43,352 –a—— C:\WINDOWS\system32\wups2.dll
2007-08-19 18:37 d——– C:\WINDOWS\system32\SoftwareDistribution
2007-08-19 07:39 d——– C:\Program Files\uTorrent
2007-08-19 07:39 d——– C:\DOCUME~1\T&C~1\APPLIC~1\uTorrent
2007-08-18 23:06 d——– C:\DOCUME~1\T&C~1\APPLIC~1\BitTorrent
2007-08-18 23:03 d——– C:\Program Files\BitTorrent
2007-08-18 23:03 d——– C:\DOCUME~1\User\APPLIC~1\BitTorrent
2007-08-17 01:02 d——– C:\Temp
2007-08-16 08:35 d——– C:\Program Files\City of Heroes
2007-08-15 23:01 d——– C:\City of Heroes
2007-08-12 15:02 d——– C:\WINDOWS\pss
2007-08-12 14:58 401,720 –a—— C:\Program Files\HiJackThis.exe
2007-08-12 12:57 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\PopCap
2007-08-08 17:46 d——– C:\DOCUME~1\T&C~1\Incomplete
2007-08-08 17:34 d——– C:\DOCUME~1\T&C~1\APPLIC~1\LimeWire
2007-08-08 09:13 d—s—- C:\DOCUME~1\T&C~1\UserData
2007-08-08 07:42 1,835,008 –ah—– C:\DOCUME~1\T&C~1\NTUSER.DAT
2007-08-06 19:47 d——– C:\SIERRA
2007-08-06 17:46 98,304 –a—— C:\WINDOWS\system32\atiiprxx.exe
2007-08-06 17:46 45,056 –a—— C:\WINDOWS\system32\atiicpxx.dll
2007-08-06 17:46 40,960 –a—— C:\WINDOWS\system32\Ati2mdxx.exe
2007-08-06 17:46 4,608 –a—— C:\WINDOWS\system32\atiicdxx.sys
2007-08-06 17:46 307,294 –a—— C:\WINDOWS\system32\atiicdxx.dll
2007-08-06 17:46 237,568 –a—— C:\WINDOWS\system32\atiiiexx.dll
2007-08-06 17:46 102,400 –a—— C:\WINDOWS\system32\Atiidtxx.dll
2007-08-06 17:46 1,519,712 –a—— C:\WINDOWS\system32\atioglaa.dll
2007-08-06 17:43 d——– C:\WINDOWS\system32\Dell
2007-08-06 17:43 d——– C:\Program Files\Dell
2007-08-06 17:34 12,160 –a—— C:\WINDOWS\system32\drivers\mouhid.sys
2007-08-06 17:30 d——– C:\WINDOWS\CSC
2007-08-06 17:27 524,288 –ah—– C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-08-04 21:57 d——– C:\WoW-2.0.0-enUS-Installer
2007-08-04 16:20 d——– C:\Program Files\Driver Cleaner Pro
2007-08-04 16:14 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinZip
2007-07-22 09:51 81,768 –a—— C:\WINDOWS\system32\xinput1_3.dll
2007-07-22 09:51 62,744 –a—— C:\WINDOWS\system32\xinput1_2.dll
2007-07-22 09:51 443,752 –a—— C:\WINDOWS\system32\d3dx10_34.dll
2007-07-22 09:51 443,752 –a—— C:\WINDOWS\system32\d3dx10_33.dll
2007-07-22 09:51 3,497,832 –a—— C:\WINDOWS\system32\d3dx9_34.dll
2007-07-22 09:51 3,495,784 –a—— C:\WINDOWS\system32\d3dx9_33.dll
2007-07-22 09:51 3,426,072 –a—— C:\WINDOWS\system32\d3dx9_32.dll
2007-07-22 09:51 266,088 –a—— C:\WINDOWS\system32\xactengine2_8.dll
2007-07-22 09:51 261,480 –a—— C:\WINDOWS\system32\xactengine2_7.dll
2007-07-22 09:51 255,848 –a—— C:\WINDOWS\system32\xactengine2_6.dll
2007-07-22 09:51 251,672 –a—— C:\WINDOWS\system32\xactengine2_5.dll
2007-07-22 09:51 237,848 –a—— C:\WINDOWS\system32\xactengine2_4.dll
2007-07-22 09:51 236,824 –a—— C:\WINDOWS\system32\xactengine2_3.dll
2007-07-22 09:51 2,414,360 –a—— C:\WINDOWS\system32\d3dx9_31.dll
2007-07-22 09:51 18,280 –a—— C:\WINDOWS\system32\x3daudio1_2.dll
2007-07-22 09:51 15,128 –a—— C:\WINDOWS\system32\x3daudio1_1.dll
2007-07-22 09:51 1,124,720 –a—— C:\WINDOWS\system32\D3DCompiler_34.dll
2007-07-22 09:51 1,123,696 –a—— C:\WINDOWS\system32\D3DCompiler_33.dll
2007-07-22 09:50 2,297,552 –a—— C:\WINDOWS\system32\d3dx9_26.dll
2007-07-22 09:49 d–h—– C:\WINDOWS\msdownld.tmp
2007-07-22 09:49 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
2007-07-22 09:44 664 –a—— C:\WINDOWS\system32\d3d9caps.dat
2007-07-21 21:05 d——– C:\DOCUME~1\User\APPLIC~1\ATI
2007-07-21 20:30 d——– C:\WINDOWS\system32\ReinstallBackups
2007-07-21 20:29 d–h—– C:\Program Files\InstallShield Installation Information
2007-07-21 20:24 870,784 –a—— C:\WINDOWS\system32\ati3d1ag.dll
2007-07-21 20:24 701,440 –a—— C:\WINDOWS\system32\drivers\ati2mtag.sys
2007-07-21 20:24 516,768 –a—— C:\WINDOWS\system32\ativvaxx.dll
2007-07-21 20:24 229,376 –a—— C:\WINDOWS\system32\ati2cqag.dll
2007-07-21 20:24 201,728 –a—— C:\WINDOWS\system32\ati2dvag.dll
2007-07-21 20:24 1,888,992 –a—— C:\WINDOWS\system32\ati3duag.dll
2007-07-21 04:49 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2007-07-20 11:28 8,704 –a—— C:\WINDOWS\system32\kbdjpn.dll
2007-07-20 11:28 8,192 –a—— C:\WINDOWS\system32\kbdkor.dll
2007-07-20 11:28 6,144 –a—— C:\WINDOWS\system32\kbd106.dll
2007-07-20 11:28 6,144 –a—— C:\WINDOWS\system32\kbd101c.dll
2007-07-20 11:28 6,144 –a—— C:\WINDOWS\system32\kbd101b.dll
2007-07-20 11:28 5,632 –a—— C:\WINDOWS\system32\kbd103.dll


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-20 03:24 ——— d——– C:\Program Files\Messenger
2007-08-19 18:56 1040 –a—— C:\Program Files\hijackthis.log
2007-08-17 18:22 ——— d——– C:\DOCUME~1\User\APPLIC~1\LimeWire
2007-08-15 17:56 ——— d——– C:\Program Files\Google
2007-08-15 17:55 ——— d——– C:\Program Files\Common Files\InstallShield
2007-08-15 13:03 ——— d——– C:\Program Files\LimeWire
2007-08-12 16:29 9344 –a—— C:\WINDOWS\system32\drivers\NSDriver.sys
2007-08-12 16:29 8320 –a—— C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-07-28 18:31 177100 –a—— C:\Program Files\Marvel HC errata.pdf
2007-07-27 18:07 783224 –a—— C:\WINDOWS\system32\aswBoot.exe
2007-07-27 18:02 94416 –a—— C:\WINDOWS\system32\drivers\aswmon2.sys
2007-07-27 18:02 92848 –a—— C:\WINDOWS\system32\drivers\aswmon.sys
2007-07-27 18:00 23152 –a—— C:\WINDOWS\system32\drivers\aswRdr.sys
2007-07-27 17:59 42912 –a—— C:\WINDOWS\system32\drivers\aswTdi.sys
2007-07-27 17:58 26624 –a—— C:\WINDOWS\system32\drivers\aavmker4.sys
2007-07-27 17:57 95608 –a—— C:\WINDOWS\system32\AvastSS.scr
2007-07-24 07:55 5677749 –a—— C:\Program Files\SWMinis.mod
2007-07-17 22:35 3344 –a—— C:\WINDOWS\pchealth\helpctr\PackageStore\SkuStore.bin
2007-07-17 22:34 9328 –a—— C:\WINDOWS\pchealth\helpctr\Config\Cntstore.bin
2007-07-17 06:51 ——— d——– C:\Program Files\Alwil Software
2007-07-17 06:13 ——— d——– C:\DOCUME~1\User\APPLIC~1\Google
2007-07-16 19:44 ——— d——– C:\Program Files\Lavasoft
2007-07-16 19:43 ——— d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-07-16 19:41 ——— d——– C:\Program Files\NoAds
2007-07-16 19:23 ——— d——– C:\DOCUME~1\User\APPLIC~1\Gtek
2007-06-29 11:11 ——— d——– C:\Program Files\Microsoft ActiveSync
2007-06-29 11:05 ——— d——– C:\Program Files\Ahead
2007-06-29 10:52 0 -rahs—- C:\MSDOS.SYS
2007-06-29 10:52 0 -rahs—- C:\IO.SYS
2007-06-29 10:52 0 –a—— C:\CONFIG.SYS
2007-06-29 10:52 0 –a—— C:\AUTOEXEC.BAT
2007-06-29 10:52 ——— d——– C:\Program Files\microsoft frontpage
2007-06-29 10:50 ——— d–h—– C:\Program Files\WindowsUpdate
2007-06-29 10:49 ——— d——– C:\Program Files\Online Services
2007-06-29 10:49 ——— d——– C:\Program Files\Common Files\MSSoap
2007-06-29 10:48 ——— d——– C:\Program Files\Movie Maker
2007-06-29 10:47 ——— d——– C:\Program Files\MSN Gaming Zone
2007-06-29 10:46 ——— d——– C:\Program Files\Windows NT
2007-06-29 06:47 ——— d——– C:\Program Files\Common Files\SpeechEngines
2007-06-29 06:47 ——— d——– C:\Program Files\Common Files\ODBC
2007-06-26 21:50 118784 ——— C:\WINDOWS\system32\ati2evxx.dll
2007-06-26 02:08 1104896 –a—— C:\WINDOWS\system32\msxml3.dll
2007-06-19 09:31 282112 –a—— C:\WINDOWS\system32\gdi32.dll
2007-06-13 06:23 1033216 –a—— C:\WINDOWS\explorer.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 05:50]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-07-27 18:03]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24]
"NoAds"="C:\Program Files\NoAds\NoAds.exe" [2007-07-16 19:41]
"BitTorrent"="C:\Documents and Settings\T & C\My Documents\bittorrent.exe" []

C:\Documents and Settings\User\Start Menu\Programs\Startup\
.lnk - C:\WINDOWS\system32\regsvc.exe [2007-08-19 21:03:58]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]

R2 ohciusb;Open Host Controller Miniport USB Driver;\??\C:\WINDOWS\system32\drivers\ohciusb.sys
R3 ati2mtaa;ati2mtaa;C:\WINDOWS\system32\DRIVERS\ati2mtaa.sys
S3 ATICDSDr;ATICDSDr;\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ATICDSDr.sys


**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-20 08:25:32
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-20 8:27:18 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-08-20 08:27

— E O F —





HJT log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:37:42 AM, on 8/20/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\NoAds\NoAds.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\MICROS~2\Office10\OUTLOOK.EXE
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NoAds] "C:\Program Files\NoAds\NoAds.exe"
O4 - HKCU\..\Run: [BitTorrent] "C:\Documents and Settings\T & C\My Documents\bittorrent.exe" –force_start_minimized
O4 - Startup: .lnk = C:\WINDOWS\system32\regsvc.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.amaena.com
O15 - Trusted Zone: *.drivecleaner.com
O15 - Trusted Zone: *.errorprotector.com
O15 - Trusted Zone: *.errorsafe.com
O15 - Trusted Zone: *.systemdoctor.com
O15 - Trusted Zone: *.winantispyware.com
O15 - Trusted Zone: *.winantivirus.com
O15 - Trusted Zone: *.winfixer.com
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (AlternaTIFF ActiveX) - https://www.rcashasp.com/rcash/apps/realmtiff.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} (TmHcmsX Control) - http://www.trendsecure.com/framework/contr…vex/TmHcmsX.CAB
O16 - DPF: {25365FF3-2746-4230-9DA7-163CCA318309} (Automatic Driver Installation Control) - http://inst.c-wss.com/n035p/EN/install/gtdownlr.cab
O16 - DPF: {3BA3B159-7533-4F96-A2CE-EE5894BBD3D5} (Scanner.SysScanner) - http://i.dell.com/images/global/js/scanner/SYSSCANNER.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1187563012921
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O16 - DPF: {E5ABEB00-B357-4884-9949-77B2C71A7EE3} (BoardCtl Class) - http://www.intel.com/design/motherbd/boardid/BoardID.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

–
End of file - 5255 bytes
Hi nomanselizabeth,

A new IE icon appeared after the Combo Fix reboot on my desktop - is this a result of the ComboFix run?

Yes ComboFix sets some things back to default, you can delete it if you prefer.

What additional would you recommend to stop this from fouling up my system every few days?

I'll give you some recommendations on this when we've finished cleaning.

There is a new autostart entry on your computer which is unusual:

Startup: .lnk = C:\WINDOWS\system32\regsvc.exe

Do you know anything about this?

Please upload the file for scanning:
Open http://virusscan.jotti.org/
Copy/paste this file and path into the white box at the top:

C:\WINDOWS\system32\regsvc.exe

Press Submit - this will submit the file for testing.
Please wait for all the scanners to finish then copy and paste the results in your next response.

Note: If Jotti is busy, you can use VirusTotal instead.

You have Bittorrent, a P2P file sharing program installed on your computer. This program does not come bundled with malware as some similar programs do, but peer-to-peer file sharing networks are one of the biggest sources of malware we see. Anything downloaded from them cannot be trusted to be clean, because even if the file appears to be what it claims to be, it can have malware embedded in it.
I recommend you remove it, but of course the choice is yours.
You can remove Bittorrent via Start->Control Panel->Add/Remove Programs.

Then, open HijackThis, choose Do a system scan only and place a checkmark next to the following lines:

O15 - Trusted Zone: *.amaena.com
O15 - Trusted Zone: *.drivecleaner.com
O15 - Trusted Zone: *.errorprotector.com
O15 - Trusted Zone: *.errorsafe.com
O15 - Trusted Zone: *.systemdoctor.com
O15 - Trusted Zone: *.winantispyware.com
O15 - Trusted Zone: *.winantivirus.com
O15 - Trusted Zone: *.winfixer.com
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab


Then close all open windows apart from HijackThis, press Fix checked, OK the prompt and close HijackThis.

Make hidden/system files and folders visible:
Click Start -> My Computer
Select the Tools menu, click Folder Options and select the View tab
Under the Hidden files and folders heading SELECT Show hidden files and folders
UNCHECK the Hide extensions for known file types option
UNCHECK the Hide protected operating system files (recommended) option
Click Yes to confirm and press OK

Use Windows Explorer to find and delete the following file (if present):

C:\WINDOWS\system32\lldsrngq.exe

If this file isn't present then that's OK but if you have trouble deleting it, please let me know in your next response.

Then please do an online scan with Kaspersky:

Open Kaspersky Online Scanner in Internet Explorer

You will be prompted to install an ActiveX component from Kaspersky,
Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT and then Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • The program will start to scan your system.
  • Once the scan is complete, click on the Save as Text button and save the file to your desktop
Once complete, please post the Jotti results, the Kaspersky report and a new HijackThis log.
Here are the results from Virus Total - Iam continuing with your other instructions and will post again after running Kaspersky

File regsvc.exe received on 08.20.2007 21:09:23 (CET)

Result: 10/32 (31.25%)

Antivirus Version Last Update Result
AhnLab-V3 2007.8.21.0 2007.08.20 -
AntiVir 7.4.1.62 2007.08.20 HEUR/Malware
Authentium 4.93.8 2007.08.20 -
Avast 4.7.1029.0 2007.08.20 -
AVG 7.5.0.484 2007.08.20 -
BitDefender 7.2 2007.08.20 -
CAT-QuickHeal 9.00 2007.08.20 (Suspicious) - DNAScan
ClamAV 0.91 2007.08.20 -
DrWeb 4.33 2007.08.20 -
eSafe 7.0.15.0 2007.08.20 Suspicious Trojan/Worm
eTrust-Vet 31.1.5069 2007.08.18 -
Ewido 4.0 2007.08.20 -
FileAdvisor 1 2007.08.20 -
Fortinet 2.91.0.0 2007.08.20 W32/Haxdoor.PN!tr
F-Prot 4.3.2.48 2007.08.20 -
F-Secure 6.70.13030.0 2007.08.20 -
Ikarus T3.1.1.12 2007.08.20 Backdoor.Win32.Prorat.19.i
Kaspersky 4.0.2.24 2007.08.20 -
McAfee 5101 2007.08.20 -
Microsoft 1.2803 2007.08.20 -
NOD32v2 2471 2007.08.20 -
Norman 5.80.02 2007.08.20 -
Panda 9.0.0.4 2007.08.19 Rootkit/Haxdoor.PN
Prevx1 V2 2007.08.20 Win32.Worm.Feebs.Gen
Rising 19.36.60.00 2007.08.19 -
Sophos 4.20.0 2007.08.12 Mal/Basine-C
Sunbelt 2.2.907.0 2007.08.18 VIPRE.Suspicious
Symantec 10 2007.08.20 -
TheHacker 6.1.8.171 2007.08.20 -
VBA32 3.12.2.2 2007.08.20 -
VirusBuster 4.3.26:9 2007.08.20 -
Webwasher-Gateway 6.0.1 2007.08.20 Heuristic.Malware
Additional information
File size: 13824 bytes
MD5: faac85feeea49234352afdc8a4dae731
SHA1: ecdd9dd5b76277dd89395937b9f0b339368d33bf
packers: PECOMPACT, BINARYRES
packers: PecBundle, PECompact
Prevx info: http://fileinfo.prevx.com/fileinfo.asp?PX5…A81A80001DF412E
Sunbelt info: VIPRE.Suspicious is a generic detection for potential threats that are deemed suspicious through heuristics.
OK Here is Kaspersky and the new HJT - I swear it looks like its getting worse. (I did not yet uninstall the BitTorrent program)

Kaspersky Report

KASPERSKY ONLINE SCANNER REPORT
Monday, August 20, 2007 5:32:26 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 20/08/2007
Kaspersky Anti-Virus database records: 386240


Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
A:\
C:\
D:\
E:\

Scan Statistics
Total number of scanned objects 66928
Number of viruses found 8
Number of infected objects 35
Number of suspicious objects 2
Duration of the scan process 01:26:52

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle.zip/Yazzle1281OinUninstaller.exe Suspicious: Password-protected-EXE skipped

C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle.zip ZIP: suspicious - 1 skipped

C:\Documents and Settings\All Users\Documents\My Music\My Music2 Track 2.wma Infected: Trojan-Downloader.WMA.Wimad.k skipped

C:\Documents and Settings\All Users\Documents\My Music\My Music3 Track 3.wma Infected: Trojan-Downloader.WMA.Wimad.k skipped

C:\Documents and Settings\All Users\Documents\My Music\My Music4 Track 4.wma Infected: Trojan-Downloader.WMA.Wimad.k skipped

C:\Documents and Settings\All Users\Documents\My Music\My Music\Rare Recording.wma Infected: Trojan-Downloader.WMA.Wimad.k skipped

C:\Documents and Settings\All Users\Documents\My Music\My Music\Top of Charts - 2004.wma Infected: Trojan-Downloader.WMA.Wimad.k skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\T & C\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\T & C\Local Settings\Application Data\Microsoft\Media Player\CurrentDatabase_59R.wmdb Object is locked skipped

C:\Documents and Settings\T & C\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\T & C\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\T & C\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\T & C\Local Settings\Temp\svchost.exe Infected: Trojan-Downloader.Win32.VB.awk skipped

C:\Documents and Settings\T & C\Local Settings\Temp\~DF16A7.tmp Object is locked skipped

C:\Documents and Settings\T & C\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\T & C\Local Settings\Temporary Internet Files\Content.IE5\SPYV05EB\BitTorrent-5.0.8[1].exe/stream/data0013 Infected: not-a-virus:AdWare.Win32.Look2Me.aj skipped

C:\Documents and Settings\T & C\Local Settings\Temporary Internet Files\Content.IE5\SPYV05EB\BitTorrent-5.0.8[1].exe/stream Infected: not-a-virus:AdWare.Win32.Look2Me.aj skipped

C:\Documents and Settings\T & C\Local Settings\Temporary Internet Files\Content.IE5\SPYV05EB\BitTorrent-5.0.8[1].exe NSIS: infected - 2 skipped

C:\Documents and Settings\T & C\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\T & C\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\User\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\User\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\User\Local Settings\Temp\~DF2CC0.tmp Object is locked skipped

C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\User\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\User\ntuser.dat.LOG Object is locked skipped

C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped

C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped

C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped

C:\Program Files\backups\backup-20070820-152757-522.dll Infected: not-a-virus:Downloader.Win32.PopCap.b skipped

C:\Program Files\BitTorrent\BitTorrentIE.2.dll Infected: not-a-virus:AdWare.Win32.Look2Me.aj skipped

C:\RECYCLER\S-1-5-21-343818398-492894223-1801674531-1004\Dc10\BitTorrentIE.2.dll Infected: not-a-virus:AdWare.Win32.Look2Me.aj skipped

C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

C:\System Volume Information\_restore{8082F812-7DE0-4395-9071-65A4AB6F696D}\RP14\A0002767.exe Infected: Trojan-Clicker.Win32.VB.qs skipped

C:\System Volume Information\_restore{8082F812-7DE0-4395-9071-65A4AB6F696D}\RP14\A0002775.exe Infected: Trojan-Clicker.Win32.VB.qs skipped

C:\System Volume Information\_restore{8082F812-7DE0-4395-9071-65A4AB6F696D}\RP30\A0003560.exe Infected: Trojan-Clicker.Win32.VB.qs skipped

C:\System Volume Information\_restore{8082F812-7DE0-4395-9071-65A4AB6F696D}\RP32\A0009764.exe Infected: Trojan-Clicker.Win32.VB.qs skipped

C:\System Volume Information\_restore{8082F812-7DE0-4395-9071-65A4AB6F696D}\RP32\A0019764.exe Infected: Trojan-Clicker.Win32.VB.qs skipped

C:\System Volume Information\_restore{8082F812-7DE0-4395-9071-65A4AB6F696D}\RP32\A0024789.exe Infected: Trojan-Clicker.Win32.VB.qs skipped

C:\System Volume Information\_restore{8082F812-7DE0-4395-9071-65A4AB6F696D}\RP33\A0024895.exe Infected: Trojan-Clicker.Win32.VB.qs skipped

C:\System Volume Information\_restore{8082F812-7DE0-4395-9071-65A4AB6F696D}\RP33\A0024905.exe Infected: Trojan-Clicker.Win32.VB.qs skipped

C:\System Volume Information\_restore{8082F812-7DE0-4395-9071-65A4AB6F696D}\RP34\A0024917.exe Infected: Trojan-Clicker.Win32.VB.qs skipped

C:\System Volume Information\_restore{8082F812-7DE0-4395-9071-65A4AB6F696D}\RP35\A0024932.exe Infected: Trojan-Clicker.Win32.VB.qs skipped

C:\System Volume Information\_restore{8082F812-7DE0-4395-9071-65A4AB6F696D}\RP35\A0024945.exe Infected: Trojan-Clicker.Win32.VB.qs skipped

C:\System Volume Information\_restore{8082F812-7DE0-4395-9071-65A4AB6F696D}\RP37\A0025019.exe Infected: Trojan-Clicker.Win32.VB.qs skipped

C:\System Volume Information\_restore{8082F812-7DE0-4395-9071-65A4AB6F696D}\RP47\A0028237.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped

C:\System Volume Information\_restore{8082F812-7DE0-4395-9071-65A4AB6F696D}\RP47\A0028239.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped

C:\System Volume Information\_restore{8082F812-7DE0-4395-9071-65A4AB6F696D}\RP47\A0028240.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.r skipped

C:\System Volume Information\_restore{8082F812-7DE0-4395-9071-65A4AB6F696D}\RP51\A0029146.exe/stream/data0013 Infected: not-a-virus:AdWare.Win32.Look2Me.aj skipped

C:\System Volume Information\_restore{8082F812-7DE0-4395-9071-65A4AB6F696D}\RP51\A0029146.exe/stream Infected: not-a-virus:AdWare.Win32.Look2Me.aj skipped

C:\System Volume Information\_restore{8082F812-7DE0-4395-9071-65A4AB6F696D}\RP51\A0029146.exe NSIS: infected - 2 skipped

C:\System Volume Information\_restore{8082F812-7DE0-4395-9071-65A4AB6F696D}\RP51\change.log Object is locked skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\SchedLgU.Txt Object is locked skipped

C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped

C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped

C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped

C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\default Object is locked skipped

C:\WINDOWS\system32\config\default.LOG Object is locked skipped

C:\WINDOWS\system32\config\SAM Object is locked skipped

C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\SECURITY Object is locked skipped

C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

C:\WINDOWS\system32\config\software Object is locked skipped

C:\WINDOWS\system32\config\software.LOG Object is locked skipped

C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\system Object is locked skipped

C:\WINDOWS\system32\config\system.LOG Object is locked skipped

C:\WINDOWS\system32\h323log.txt Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

C:\WINDOWS\Temp\Perflib_Perfdata_4a0.dat Object is locked skipped

C:\WINDOWS\WindowsUpdate.log Object is locked skipped

E:\Documents\My Music\My Music2 Track 2.wma Infected: Trojan-Downloader.WMA.Wimad.k skipped

E:\Documents\My Music\My Music3 Track 3.wma Infected: Trojan-Downloader.WMA.Wimad.k skipped

E:\Documents\My Music\My Music4 Track 4.wma Infected: Trojan-Downloader.WMA.Wimad.k skipped

E:\Documents\My Music\My Music\Rare Recording.wma Infected: Trojan-Downloader.WMA.Wimad.k skipped

E:\Documents\My Music\My Music\Top of Charts - 2004.wma Infected: Trojan-Downloader.WMA.Wimad.k skipped

E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

E:\System Volume Information\_restore{8082F812-7DE0-4395-9071-65A4AB6F696D}\RP51\change.log Object is locked skipped

Scan process completed.





HJT

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:45:44 PM, on 8/20/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\NoAds\NoAds.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\imapi.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\msiexec.exe
C:\PROGRA~1\MICROS~2\Office10\OUTLOOK.EXE
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NoAds] "C:\Program Files\NoAds\NoAds.exe"
O4 - HKCU\..\Run: [BitTorrent] "C:\Documents and Settings\T & C\My Documents\bittorrent.exe" –force_start_minimized
O4 - HKUS\S-1-5-21-343818398-492894223-1801674531-1004\..\Run: [BitTorrent] "C:\Documents and Settings\T & C\My Documents\bittorrent.exe" –force_start_minimized (User 'T & C')
O4 - HKUS\S-1-5-21-343818398-492894223-1801674531-1004\..\Run: [IESet] IExplorer.dll .dbt (User 'T & C')
O4 - S-1-5-21-343818398-492894223-1801674531-1004 Startup: .lnk = C:\WINDOWS\system32\regsvc.exe (User 'T & C')
O4 - S-1-5-21-343818398-492894223-1801674531-1004 Startup: TA_Start.lnk = C:\WINDOWS\system32\lldsrngq.exe (User 'T & C')
O4 - S-1-5-21-343818398-492894223-1801674531-1004 User Startup: .lnk = C:\WINDOWS\system32\regsvc.exe (User 'T & C')
O4 - S-1-5-21-343818398-492894223-1801674531-1004 User Startup: TA_Start.lnk = C:\WINDOWS\system32\lldsrngq.exe (User 'T & C')
O4 - Startup: .lnk = C:\WINDOWS\system32\regsvc.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (AlternaTIFF ActiveX) - https://www.rcashasp.com/rcash/apps/realmtiff.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} (TmHcmsX Control) - http://www.trendsecure.com/framework/contr…vex/TmHcmsX.CAB
O16 - DPF: {25365FF3-2746-4230-9DA7-163CCA318309} (Automatic Driver Installation Control) - http://inst.c-wss.com/n035p/EN/install/gtdownlr.cab
O16 - DPF: {3BA3B159-7533-4F96-A2CE-EE5894BBD3D5} (Scanner.SysScanner) - http://i.dell.com/images/global/js/scanner/SYSSCANNER.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1187563012921
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {E5ABEB00-B357-4884-9949-77B2C71A7EE3} (BoardCtl Class) - http://www.intel.com/design/motherbd/boardid/BoardID.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

–
End of file - 5842 bytes
Hi nomanselizabeth,

Yes there's still plenty going on, don't worry we'll get it clean :)

Then, open HijackThis, choose Do a system scan only and place a checkmark next to the following lines:

O4 - HKUS\S-1-5-21-343818398-492894223-1801674531-1004\..\Run: [IESet] IExplorer.dll .dbt (User 'T & C')
O4 - S-1-5-21-343818398-492894223-1801674531-1004 Startup: .lnk = C:\WINDOWS\system32\regsvc.exe (User 'T & C')
O4 - S-1-5-21-343818398-492894223-1801674531-1004 Startup: TA_Start.lnk = C:\WINDOWS\system32\lldsrngq.exe (User 'T & C')
O4 - S-1-5-21-343818398-492894223-1801674531-1004 User Startup: .lnk = C:\WINDOWS\system32\regsvc.exe (User 'T & C')
O4 - S-1-5-21-343818398-492894223-1801674531-1004 User Startup: TA_Start.lnk = C:\WINDOWS\system32\lldsrngq.exe (User 'T & C')
O4 - Startup: .lnk = C:\WINDOWS\system32\regsvc.exe


Then close all open windows apart from HijackThis, press Fix checked, OK the prompt and close HijackThis.


Next:
  • Check that combofix.exe is on your Desktop
  • Then open Notepad: press Start->Run, type notepad and click OK
  • Copy/paste the contents of the below code box into Notepad:
    File::
    C:\Documents and Settings\All Users\Documents\My Music\My Music2 Track 2.wma
    C:\Documents and Settings\All Users\Documents\My Music\My Music3 Track 3.wma
    C:\Documents and Settings\All Users\Documents\My Music\My Music4 Track 4.wma
    C:\Documents and Settings\All Users\Documents\My Music\My Music\Rare Recording.wma
    C:\Documents and Settings\All Users\Documents\My Music\My Music\Top of Charts - 2004.wma
    C:\Documents and Settings\T & C\Local Settings\Temp\svchost.exe
    C:\Documents and Settings\T & C\Local Settings\Temporary Internet Files\Content.IE5\SPYV05EB\BitTorrent-5.0.8[1].exe
    C:\Program Files\BitTorrent\BitTorrentIE.2.dll
    E:\Documents\My Music\My Music2 Track 2.wma
    E:\Documents\My Music\My Music3 Track 3.wma
    E:\Documents\My Music\My Music4 Track 4.wma
    E:\Documents\My Music\My Music\Rare Recording.wma
    E:\Documents\My Music\My Music\Top of Charts - 2004.wma
    C:\WINDOWS\system32\lldsrngq.exe
    C:\WINDOWS\system32\regsvc.exe
  • Save this to your Desktop as CFScript.

    [external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
Note: Do not click ComboFix's window while it's running - it may cause it to stall!

Clean Spybots quarantined files:
Open Spybot - Search & Destroy
Select Recovery from the menu on the left side
Select infected item(s) and choose Purge selected items
Close Spybot - Search & Destroy

Also, empty your recycle bin

Once complete, please post the new ComboFix report and another HijackThis log.
OK. DOne as directed. Here is the latest ComboFix and HJT

ComboFix 07-08-17.2 - "User" 2007-08-21 7:32:02.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.328 [GMT -4:00]
Command switches used :: C:\Documents and Settings\User\Desktop\CFScript.txt
* Created a new restore point

FILE::
C:\Documents and Settings\All Users\Documents\My Music\My Music2 Track 2.wma
C:\Documents and Settings\All Users\Documents\My Music\My Music3 Track 3.wma
C:\Documents and Settings\All Users\Documents\My Music\My Music4 Track 4.wma
C:\Documents and Settings\All Users\Documents\My Music\My Music\Rare Recording.wma
C:\Documents and Settings\All Users\Documents\My Music\My Music\Top of Charts - 2004.wma
C:\Documents and Settings\T & C\Local Settings\Temp\svchost.exe
C:\Documents and Settings\T & C\Local Settings\Temporary Internet Files\Content.IE5\SPYV05EB\BitTorrent-5.0.8[1].exe
C:\Program Files\BitTorrent\BitTorrentIE.2.dll
E:\Documents\My Music\My Music2 Track 2.wma
E:\Documents\My Music\My Music3 Track 3.wma
E:\Documents\My Music\My Music4 Track 4.wma
E:\Documents\My Music\My Music\Rare Recording.wma
E:\Documents\My Music\My Music\Top of Charts - 2004.wma
C:\WINDOWS\system32\lldsrngq.exe
C:\WINDOWS\system32\regsvc.exe


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Documents and Settings\T & C\Local Settings\Temp\svchost.exe
C:\Documents and Settings\T & C\Local Settings\Temporary Internet Files\Content.IE5\SPYV05EB\BitTorrent-5.0.8[1].exe
C:\Program Files\BitTorrent\BitTorrentIE.2.dll
C:\WINDOWS\system32\regsvc.exe


((((((((((((((((((((((((( Files Created from 2007-07-21 to 2007-08-21 )))))))))))))))))))))))))))))))


2007-08-20 17:42 d——– C:\kav
2007-08-20 15:32 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-08-20 15:32 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-08-20 15:27 d——– C:\Program Files\backups
2007-08-20 08:15 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-19 21:03 4,096 –a—— C:\WINDOWS\system32\drivers\ohciusb.sys
2007-08-19 18:40 22,752 –a—— C:\WINDOWS\system32\spupdsvc.exe
2007-08-19 18:40 d–h—– C:\WINDOWS\$hf_mig$
2007-08-19 18:40 d——– C:\WINDOWS\system32\PreInstall
2007-08-19 18:37 43,352 –a—— C:\WINDOWS\system32\wups2.dll
2007-08-19 18:37 d——– C:\WINDOWS\system32\SoftwareDistribution
2007-08-19 07:39 d——– C:\Program Files\uTorrent
2007-08-19 07:39 d——– C:\DOCUME~1\T&C~1\APPLIC~1\uTorrent
2007-08-18 23:06 d——– C:\DOCUME~1\T&C~1\APPLIC~1\BitTorrent
2007-08-18 23:03 d——– C:\Program Files\BitTorrent
2007-08-18 23:03 d——– C:\DOCUME~1\User\APPLIC~1\BitTorrent
2007-08-17 01:02 d——– C:\Temp
2007-08-16 08:35 d——– C:\Program Files\City of Heroes
2007-08-15 23:01 d——– C:\City of Heroes
2007-08-12 15:02 d——– C:\WINDOWS\pss
2007-08-12 14:58 401,720 –a—— C:\Program Files\HiJackThis.exe
2007-08-08 17:46 d——– C:\DOCUME~1\T&C~1\Incomplete
2007-08-08 17:34 d——– C:\DOCUME~1\T&C~1\APPLIC~1\LimeWire
2007-08-08 09:13 d—s—- C:\DOCUME~1\T&C~1\UserData
2007-08-08 07:42 1,835,008 –ah—– C:\DOCUME~1\T&C~1\NTUSER.DAT
2007-08-06 19:47 d——– C:\SIERRA
2007-08-06 17:46 98,304 –a—— C:\WINDOWS\system32\atiiprxx.exe
2007-08-06 17:46 45,056 –a—— C:\WINDOWS\system32\atiicpxx.dll
2007-08-06 17:46 40,960 –a—— C:\WINDOWS\system32\Ati2mdxx.exe
2007-08-06 17:46 4,608 –a—— C:\WINDOWS\system32\atiicdxx.sys
2007-08-06 17:46 307,294 –a—— C:\WINDOWS\system32\atiicdxx.dll
2007-08-06 17:46 237,568 –a—— C:\WINDOWS\system32\atiiiexx.dll
2007-08-06 17:46 102,400 –a—— C:\WINDOWS\system32\Atiidtxx.dll
2007-08-06 17:46 1,519,712 –a—— C:\WINDOWS\system32\atioglaa.dll
2007-08-06 17:43 d——– C:\WINDOWS\system32\Dell
2007-08-06 17:43 d——– C:\Program Files\Dell
2007-08-06 17:34 12,160 –a—— C:\WINDOWS\system32\drivers\mouhid.sys
2007-08-06 17:30 d——– C:\WINDOWS\CSC
2007-08-06 17:27 524,288 –ah—– C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-08-04 21:57 d——– C:\WoW-2.0.0-enUS-Installer
2007-08-04 16:20 d——– C:\Program Files\Driver Cleaner Pro
2007-08-04 16:14 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinZip
2007-07-22 09:51 81,768 –a—— C:\WINDOWS\system32\xinput1_3.dll
2007-07-22 09:51 62,744 –a—— C:\WINDOWS\system32\xinput1_2.dll
2007-07-22 09:51 443,752 –a—— C:\WINDOWS\system32\d3dx10_34.dll
2007-07-22 09:51 443,752 –a—— C:\WINDOWS\system32\d3dx10_33.dll
2007-07-22 09:51 3,497,832 –a—— C:\WINDOWS\system32\d3dx9_34.dll
2007-07-22 09:51 3,495,784 –a—— C:\WINDOWS\system32\d3dx9_33.dll
2007-07-22 09:51 3,426,072 –a—— C:\WINDOWS\system32\d3dx9_32.dll
2007-07-22 09:51 266,088 –a—— C:\WINDOWS\system32\xactengine2_8.dll
2007-07-22 09:51 261,480 –a—— C:\WINDOWS\system32\xactengine2_7.dll
2007-07-22 09:51 255,848 –a—— C:\WINDOWS\system32\xactengine2_6.dll
2007-07-22 09:51 251,672 –a—— C:\WINDOWS\system32\xactengine2_5.dll
2007-07-22 09:51 237,848 –a—— C:\WINDOWS\system32\xactengine2_4.dll
2007-07-22 09:51 236,824 –a—— C:\WINDOWS\system32\xactengine2_3.dll
2007-07-22 09:51 2,414,360 –a—— C:\WINDOWS\system32\d3dx9_31.dll
2007-07-22 09:51 18,280 –a—— C:\WINDOWS\system32\x3daudio1_2.dll
2007-07-22 09:51 15,128 –a—— C:\WINDOWS\system32\x3daudio1_1.dll
2007-07-22 09:51 1,124,720 –a—— C:\WINDOWS\system32\D3DCompiler_34.dll
2007-07-22 09:51 1,123,696 –a—— C:\WINDOWS\system32\D3DCompiler_33.dll
2007-07-22 09:50 2,297,552 –a—— C:\WINDOWS\system32\d3dx9_26.dll
2007-07-22 09:49 d–h—– C:\WINDOWS\msdownld.tmp
2007-07-22 09:49 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
2007-07-22 09:44 664 –a—— C:\WINDOWS\system32\d3d9caps.dat
2007-07-21 21:05 d——– C:\DOCUME~1\User\APPLIC~1\ATI
2007-07-21 20:30 d——– C:\WINDOWS\system32\ReinstallBackups
2007-07-21 20:29 d–h—– C:\Program Files\InstallShield Installation Information
2007-07-21 20:24 870,784 –a—— C:\WINDOWS\system32\ati3d1ag.dll
2007-07-21 20:24 701,440 –a—— C:\WINDOWS\system32\drivers\ati2mtag.sys
2007-07-21 20:24 516,768 –a—— C:\WINDOWS\system32\ativvaxx.dll
2007-07-21 20:24 229,376 –a—— C:\WINDOWS\system32\ati2cqag.dll
2007-07-21 20:24 201,728 –a—— C:\WINDOWS\system32\ati2dvag.dll
2007-07-21 20:24 1,888,992 –a—— C:\WINDOWS\system32\ati3duag.dll
2007-07-21 04:49 221,184 –a—— C:\WINDOWS\system32\wmpns.dll


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-20 17:45 5843 –a—— C:\Program Files\hijackthis.log
2007-08-20 03:24 ——— d——– C:\Program Files\Messenger
2007-08-17 18:22 ——— d——– C:\DOCUME~1\User\APPLIC~1\LimeWire
2007-08-15 17:56 ——— d——– C:\Program Files\Google
2007-08-15 17:55 ——— d——– C:\Program Files\Common Files\InstallShield
2007-08-15 13:03 ——— d——– C:\Program Files\LimeWire
2007-08-12 16:29 9344 –a—— C:\WINDOWS\system32\drivers\NSDriver.sys
2007-08-12 16:29 8320 –a—— C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-07-28 18:31 177100 –a—— C:\Program Files\Marvel HC errata.pdf
2007-07-27 18:07 783224 –a—— C:\WINDOWS\system32\aswBoot.exe
2007-07-27 18:02 94416 –a—— C:\WINDOWS\system32\drivers\aswmon2.sys
2007-07-27 18:02 92848 –a—— C:\WINDOWS\system32\drivers\aswmon.sys
2007-07-27 18:00 23152 –a—— C:\WINDOWS\system32\drivers\aswRdr.sys
2007-07-27 17:59 42912 –a—— C:\WINDOWS\system32\drivers\aswTdi.sys
2007-07-27 17:58 26624 –a—— C:\WINDOWS\system32\drivers\aavmker4.sys
2007-07-27 17:57 95608 –a—— C:\WINDOWS\system32\AvastSS.scr
2007-07-24 07:55 5677749 –a—— C:\Program Files\SWMinis.mod
2007-07-17 22:35 3344 –a—— C:\WINDOWS\pchealth\helpctr\PackageStore\SkuStore.bin
2007-07-17 22:34 9328 –a—— C:\WINDOWS\pchealth\helpctr\Config\Cntstore.bin
2007-07-17 06:51 ——— d——– C:\Program Files\Alwil Software
2007-07-17 06:13 ——— d——– C:\DOCUME~1\User\APPLIC~1\Google
2007-07-16 19:44 ——— d——– C:\Program Files\Lavasoft
2007-07-16 19:43 ——— d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-07-16 19:41 ——— d——– C:\Program Files\NoAds
2007-07-16 19:23 ——— d——– C:\DOCUME~1\User\APPLIC~1\Gtek
2007-06-29 11:11 ——— d——– C:\Program Files\Microsoft ActiveSync
2007-06-29 11:05 ——— d——– C:\Program Files\Ahead
2007-06-29 10:52 0 -rahs—- C:\MSDOS.SYS
2007-06-29 10:52 0 -rahs—- C:\IO.SYS
2007-06-29 10:52 0 –a—— C:\CONFIG.SYS
2007-06-29 10:52 0 –a—— C:\AUTOEXEC.BAT
2007-06-29 10:52 ——— d——– C:\Program Files\microsoft frontpage
2007-06-29 10:50 ——— d–h—– C:\Program Files\WindowsUpdate
2007-06-29 10:49 ——— d——– C:\Program Files\Online Services
2007-06-29 10:49 ——— d——– C:\Program Files\Common Files\MSSoap
2007-06-29 10:48 ——— d——– C:\Program Files\Movie Maker
2007-06-29 10:47 ——— d——– C:\Program Files\MSN Gaming Zone
2007-06-29 10:46 ——— d——– C:\Program Files\Windows NT
2007-06-29 06:47 ——— d——– C:\Program Files\Common Files\SpeechEngines
2007-06-29 06:47 ——— d——– C:\Program Files\Common Files\ODBC
2007-06-26 21:50 118784 ——— C:\WINDOWS\system32\ati2evxx.dll
2007-06-26 02:08 1104896 –a—— C:\WINDOWS\system32\msxml3.dll
2007-06-19 09:31 282112 –a—— C:\WINDOWS\system32\gdi32.dll
2007-06-13 06:23 1033216 –a—— C:\WINDOWS\explorer.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 05:50]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-07-27 18:03]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24]
"NoAds"="C:\Program Files\NoAds\NoAds.exe" [2007-07-16 19:41]
"BitTorrent"="C:\Documents and Settings\T & C\My Documents\bittorrent.exe" []

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]

R2 ohciusb;Open Host Controller Miniport USB Driver;\??\C:\WINDOWS\system32\drivers\ohciusb.sys
R3 ati2mtaa;ati2mtaa;C:\WINDOWS\system32\DRIVERS\ati2mtaa.sys
S3 ATICDSDr;ATICDSDr;\??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ATICDSDr.sys


**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-21 07:37:10
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-21 7:39:02 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-08-21 07:38
C:\ComboFix2.txt … 2007-08-20 08:27

— E O F —



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:43:32 AM, on 8/21/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\NoAds\NoAds.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\MICROS~2\Office10\OUTLOOK.EXE
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NoAds] "C:\Program Files\NoAds\NoAds.exe"
O4 - HKCU\..\Run: [BitTorrent] "C:\Documents and Settings\T & C\My Documents\bittorrent.exe" –force_start_minimized
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (AlternaTIFF ActiveX) - https://www.rcashasp.com/rcash/apps/realmtiff.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} (TmHcmsX Control) - http://www.trendsecure.com/framework/contr…vex/TmHcmsX.CAB
O16 - DPF: {25365FF3-2746-4230-9DA7-163CCA318309} (Automatic Driver Installation Control) - http://inst.c-wss.com/n035p/EN/install/gtdownlr.cab
O16 - DPF: {3BA3B159-7533-4F96-A2CE-EE5894BBD3D5} (Scanner.SysScanner) - http://i.dell.com/images/global/js/scanner/SYSSCANNER.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1187563012921
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {E5ABEB00-B357-4884-9949-77B2C71A7EE3} (BoardCtl Class) - http://www.intel.com/design/motherbd/boardid/BoardID.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

–
End of file - 4937 bytes

Looks a lot better. Also have uninstalled the BitTorrent program
Hi nomanselizabeth,

Looks a lot better. Also have uninstalled the BitTorrent program

Yes it certainly does look better :) Good job with the BitTorrent program, we can now remove it's autostart entry using HijackThis:
Open HijackThis, choose Do a system scan only and place a checkmark next to the following line:

O4 - HKCU\..\Run: [BitTorrent] "C:\Documents and Settings\T & C\My Documents\bittorrent.exe" –force_start_minimized


Then close all open windows apart from HijackThis, press Fix checked, OK the prompt and close HijackThis.

Now please re-scan with Kaspersky using the same instructions as before to make sure we've got everything.

Once complete, please post the Kaspersky log and a new HijackThis log.
OK Silver. here is the latest KASPERSKY REPORT Tuesday, August 21, 2007 2:50:32 PM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.93.0 Kaspersky Anti-Virus database last update: 21/08/2007 Kaspersky Anti-Virus database records: 386800 Scan Settings Scan using the following antivirus database extended Scan Archives true Scan Mail Bases true Scan Target My Computer A:\ C:\ D:\ E:\ Scan Statistics Total number of scanned objects 66000 Number of viruses found 5 Number of infected objects 17 Number of suspicious objects 0 Duration of the scan process 01:29:41 Infected Object Name Virus Name Last Action C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\User\Cookies\index.dat Object is locked skipped C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\User\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\User\Local Settings\History\History.IE5\MSHist012007081320070820\index.dat Object is locked skipped C:\Documents and Settings\User\Local Settings\History\History.IE5\MSHist012007082020070821\index.dat Object is locked skipped C:\Documents and Settings\User\Local Settings\History\History.IE5\MSHist012007082120070822\index.dat Object is locked skipped C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\User\NTUSER.DAT Object is locked skipped C:\Documents and Settings\User\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\User\UserData\index.dat Object is locked skipped C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt Object is locked skipped C:\Program Files\backups\backup-20070820-152757-522.dll Infected: not-a-virus:Downloader.Win32.PopCap.b skipped C:\QooBox\Quarantine\C\Documents and Settings\T & C\Local Settings\Temp\svchost.exe.vir Infected: Trojan-Downloader.Win32.VB.awk skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{8082F812-7DE0-4395-9071-65A4AB6F696D}\RP14\A0002767.exe Infected: Trojan-Clicker.Win32.VB.qs skipped C:\System Volume Information\_restore{8082F812-7DE0-4395-9071-65A4AB6F696D}\RP14\A0002775.exe Infected: Trojan-Clicker.Win32.VB.qs skipped C:\System Volume Information\_restore{8082F812-7DE0-4395-9071-65A4AB6F696D}\RP30\A0003560.exe Infected: Trojan-Clicker.Win32.VB.qs skipped C:\System Volume Information\_restore{8082F812-7DE0-4395-9071-65A4AB6F696D}\RP32\A0009764.exe Infected: Trojan-Clicker.Win32.VB.qs skipped C:\System Volume Information\_restore{8082F812-7DE0-4395-9071-65A4AB6F696D}\RP32\A0019764.exe Infected: Trojan-Clicker.Win32.VB.qs skipped C:\System Volume Information\_restore{8082F812-7DE0-4395-9071-65A4AB6F696D}\RP32\A0024789.exe Infected: Trojan-Clicker.Win32.VB.qs skipped C:\System Volume Information\_restore{8082F812-7DE0-4395-9071-65A4AB6F696D}\RP33\A0024895.exe Infected: Trojan-Clicker.Win32.VB.qs skipped C:\System Volume Information\_restore{8082F812-7DE0-4395-9071-65A4AB6F696D}\RP33\A0024905.exe Infected: Trojan-Clicker.Win32.VB.qs skipped C:\System Volume Information\_restore{8082F812-7DE0-4395-9071-65A4AB6F696D}\RP34\A0024917.exe Infected: Trojan-Clicker.Win32.VB.qs skipped C:\System Volume Information\_restore{8082F812-7DE0-4395-9071-65A4AB6F696D}\RP35\A0024932.exe Infected: Trojan-Clicker.Win32.VB.qs skipped C:\System Volume Information\_restore{8082F812-7DE0-4395-9071-65A4AB6F696D}\RP35\A0024945.exe Infected: Trojan-Clicker.Win32.VB.qs skipped C:\System Volume Information\_restore{8082F812-7DE0-4395-9071-65A4AB6F696D}\RP37\A0025019.exe Infected: Trojan-Clicker.Win32.VB.qs skipped C:\System Volume Information\_restore{8082F812-7DE0-4395-9071-65A4AB6F696D}\RP47\A0028237.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped C:\System Volume Information\_restore{8082F812-7DE0-4395-9071-65A4AB6F696D}\RP47\A0028239.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped C:\System Volume Information\_restore{8082F812-7DE0-4395-9071-65A4AB6F696D}\RP47\A0028240.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.r skipped C:\System Volume Information\_restore{8082F812-7DE0-4395-9071-65A4AB6F696D}\RP53\change.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\Temp\Perflib_Perfdata_4a4.dat Object is locked skipped C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped E:\System Volume Information\_restore{8082F812-7DE0-4395-9071-65A4AB6F696D}\RP53\change.log Object is locked skipped Scan process completed.
…and HJT log


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:53:49 PM, on 8/21/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\NoAds\NoAds.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NoAds] "C:\Program Files\NoAds\NoAds.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (AlternaTIFF ActiveX) - https://www.rcashasp.com/rcash/apps/realmtiff.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} (TmHcmsX Control) - http://www.trendsecure.com/framework/contr…vex/TmHcmsX.CAB
O16 - DPF: {25365FF3-2746-4230-9DA7-163CCA318309} (Automatic Driver Installation Control) - http://inst.c-wss.com/n035p/EN/install/gtdownlr.cab
O16 - DPF: {3BA3B159-7533-4F96-A2CE-EE5894BBD3D5} (Scanner.SysScanner) - http://i.dell.com/images/global/js/scanner/SYSSCANNER.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1187563012921
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {E5ABEB00-B357-4884-9949-77B2C71A7EE3} (BoardCtl Class) - http://www.intel.com/design/motherbd/boardid/BoardID.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

–
End of file - 4720 bytes
Hi nomanselizabeth, Looks good - all those Kaspersky detections are in System Restore which we'll clean up shortly and one HijackThis backup has been detected. How's your machine running now?
Hi nomanselizabeth,

Great to hear things are running better, and I think your machine is now clean of malware :)

Some important final steps:

You should now delete ComboFix.exe from your Desktop. Also delete this folder:
C:\QooBox

Re-hide hidden/system files and folders:
Click Start -> My Computer
Select the Tools menu, click Folder Options and select the View tab
Under the Hidden files and folders heading SELECT Do not show hidden files and folders
CHECK the Hide extensions for known file types option
CHECK the Hide protected operating system files (recommended) option
Press OK

Create a new, clean System Restore point which you can use in case of future system problems:
Press Start->All Programs->Accessories->System Tools->System Restore
Select Create a restore point, then Next, type a name like All Clean then press the Create button and once it's done press Close

Now remove old, infected System Restore points:
Next click Start->Run and type cleanmgr in the box and press OK
Ensure the boxes for Temporary Files and Temporary Internet Files are checked, you can choose to check other boxes if you wish but they are not required.
Select the More Options tab, under System Restore press Clean up… and say Yes to the prompt
Press OK and Yes to confirm

Here are some tips to help you keep your computer clean:

I have Windows Firewall activated, keep Avast AV in realtime protection with the modules active, run SpyBot and Adaware and keep NoAds active for popups, but still seem to be seeing a lot of trojans and spyware. What additional would you recommend to stop this from fouling up my system every few days?


Your antivirus program is very good and no need to change anything there. Both Spybot and Ad-Aware are excellent programs, however they don't offer much in the way of real-time protection - that means they can only clean up malware after it is already on your machine which sometimes is too late. I recommend you install antispyware software with real-time capabilities - this means it protects you from system changes and spyware while you are working, not just removing malware after it has been installed. There are a range of paid-for and free packages available, a free one I can recommend is Windows Defender, available here:
http://www.microsoft.com/athome/security/s…re/default.mspx

You should consider installing a Personal Firewall program. The Windows firewall does a good job at blocking unwanted inbound connections, but I recommend you use additional firewall software as it will improve the security of your computer by monitoring and controlling outbound connections to the internet as well as inbound. There are various free packages available, such as Sunbelt Personal Firewall and Zone Alarm:
http://www.sunbelt-software.com/Home-Home-…sonal-Firewall/
http://www.zonelabs.com/

Spywareblaster is a free program which prevents the download and installation of Internet Explorer ActiveX based malware by immunizing your system against it. You can download Spywareblaster from here and a tutorial to help you get started is available here.

Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

Please take care when downloading programs. One of the easiest ways to be infected is to download freeware/shareware programs which come laden with malware - this includes allowing websites to install browser plug-ins orActiveX controls. Before downloading, it is crucial to check whether the source is reputable.
One way to check is to use McAfee SiteAdvisor. Copy the domain name into the space provided and SiteAdvisor will give you a report on the website which can help you decide if it is safe. They also have a toolbar for IE and Firefox which adds this functionality to your browser.

Find out more about how to prevent infection in the future
http://forum.malwareremoval.com/viewtopic.php?p=33687

Please post back to let me know that you have read this, and if there are any further issues.
Thank you Silver. I have followed your instructions, and have downloaded SpywareBlaster and WindowsDefender. I will download a firewall program probably tomorrow. Everything is fine now, and again, I can't thank you enough for your help. Jo Miller

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI