This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Trojan.Virtumonde

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,
New to the forums so bear with me :/
Yesterday my computer began random popups and programs would unexplainably error and crash. I did a scan with Ad-Aware Spybot and Spydoctor, removing quite a few things, but this Trojan.Virtumonde won't go away, every 5 seconds it tries to run something, but Spydoctor blocks it, quite annoying as i get a popup message each time it is blocked.
Here is my HJT log file hopefully you can shed some light on what I can do to kill this pesky virus.

Logfile of HijackThis v1.99.1
Scan saved at 7:16:00 PM, on 9/28/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Java\jre1.6.0_01\bin\jucheck.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\WINDOWS\system32\jiohpqqi.exe
C:\Program Files\Hijackthis\HijackThis.exe

O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [{8F-FF-F8-8A-ZN}] C:\windows\system32\kjdsregp.exe OLI001
O4 - HKLM\..\Run: [au] C:\Program Files\Dealio\DealioAU.exe
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [SearchIndexer] rundll32.exe "C:\WINDOWS\system32\htxtpokt.dll",sitypnow
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Exif Launcher.lnk = ?
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by130fd.bay130.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1180232250640
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1180233980218
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: DomainService - - C:\WINDOWS\system32\jiohpqqi.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe

Let me know if anything else will help solve this.

Thanks in advance,
Sid
Hi! Welcome to the WTT forums.
My name is Scotty. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research.
Please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please make a uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.
5. Click on the Save list… button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here in a reply.

Rename HijackThis
There is a possibility an infection which is hiding part of the HijackThis log because it's called hijackthis.exe.
Please rename hijackthis.exe to iseeu.exe by right-clicking on the Desktop icon and selecting Rename.

Now scan again and post a new log, please.
Thanks for all your assistance

My computer is much worse now :/ internet explorer closes within minutes of me opening it, or a adware tries to install itself
Also, the resolution is set to 640 x 480 and I cannot change it, hopefully this can be fixed as well

STEP 1:
For some reason hijackthis wouldn't allow me to save the uninstall list, I had to copy paste each one. Any ideas what might be wrong with that?

Ad-Aware 2007
Adobe Flash Player 9 ActiveX
Adobe Reader 8.1.0
Adobe® Photoshop® Album Starter Edition 3.2
AirPlus G
ANIO Service
ANIWZCS2 Service
Apple Software Update
BitTyrant
Creative Audio Console
Dealio Toolbar
DivX Codec
DivX Converter
FEAR
ffdshow (remove only)
FinePixViewer Resource
FinePixViewer Ver.5.1
Fraps
FUJIFILM USB Driver
Hijackthis 1.99.1
HijackThis 1.99.1
ImageMixer VCD2 LE for FinePix
Java™ 6 Update 2
Java™ SE Development Kit 6 Update 1
Java™ SE Runtime Environment 6 Update 1
Logitech SetPoint
Microsoft .NET Framework 2.0
Microsoft Visual C++ 2005 Redistributable
NVIDIA Drivers
QuickTime
Security Update for Microsoft .NET Framework 2.0 (KB928365)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 8 (KB917734)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Sony Vegas Movie Studio Platinum 8.0
Spybot - Search & Destroy 1.4
Spyware Doctor 5.1
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB938828)
Ventrilo Client
Windows Installer 3.1 (KB893803)
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Media Encoder 9 Series
Windows Media Encoder 9 Series
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Service Pack 2
WinRAR archiver
World of Warcraft
Xvid 1.1.3 final uninstall



STEP 2:
Renamed and here is the current log

Logfile of HijackThis v1.99.1
Scan saved at 9:11:56 AM, on 9/29/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\WINDOWS\system32\pftlddac.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Hijackthis\iseeu.exe
C:\Program Files\Internet Explorer\iexplore.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {4AADFB9A-D38F-4618-B01F-090E8462DA19} - C:\WINDOWS\system32\sstqn.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {579AD4B8-7FD4-4F64-8287-EABE3C1BB5FF} - C:\WINDOWS\system32\jkhff.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {B69B73E9-EB5C-4129-9259-175D58ABC06e} - C:\WINDOWS\system32\ohgxmxhs.dll
O2 - BHO: (no name) - {CF46BFB3-2ACC-441b-B82B-36B9562C7FF1} - C:\WINDOWS\system32\rtbjrbjq.dll
O2 - BHO: (no name) - {F4002052-AB29-4B33-8C8D-0E99084564EC} - C:\WINDOWS\system32\byxyaby.dll
O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [{8F-FF-F8-8A-ZN}] C:\windows\system32\kjdsregp.exe OLI001
O4 - HKLM\..\Run: [au] C:\Program Files\Dealio\DealioAU.exe
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SearchIndexer] rundll32.exe "C:\WINDOWS\system32\mloveuis.dll",sitypnow
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Exif Launcher.lnk = ?
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by130fd.bay130.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1180232250640
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1180233980218
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: awvtq - C:\WINDOWS\
O20 - Winlogon Notify: byxyaby - C:\WINDOWS\SYSTEM32\byxyaby.dll
O20 - Winlogon Notify: gebyy - C:\WINDOWS\system32\gebyy.dll (file missing)
O20 - Winlogon Notify: jkhff - C:\WINDOWS\system32\jkhff.dll
O20 - Winlogon Notify: mljjg - C:\WINDOWS\
O20 - Winlogon Notify: sstqn - C:\WINDOWS\
O20 - Winlogon Notify: vtsqn - C:\WINDOWS\
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe

Thanks again for all your help.
Sid
Hi Sid

You have no anti-virus on your computer. It is important you install one now before we continue with your fix. Check this out for a list of free AV scanners, AVG is highly recommended

Download and Run ComboFix
  • Download this file from below:

    Here
  • Disconnect from the Internet, than disable your anti-virus and any real-time anti-spyware monitors that are running.
  • Then double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply with a new HijackThis log.
Note 1: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Note 2:Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet.
Okay sorry for the late reply, had to take care of some things.


Here is the log from ComboFix


ComboFix 07-09-30.4 - Robert 2007-09-30 17:54:52.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1669 [GMT -5:00]
Running from: D:\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2007-08-28 to 2007-09-30 )))))))))))))))))))))))))))))))
.

2007-09-30 17:54 d——– C:\WINDOWS\system32\LogFiles
2007-09-29 17:46 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-09-28 23:40 4,628 –a—— C:\WINDOWS\system32\npqptunx.exe
2007-09-28 21:41 4,628 –a—— C:\WINDOWS\system32\apylcsbf.exe
2007-09-28 21:38 167,444 –a—— C:\WINDOWS\system32\dsetblyl.exe
2007-09-28 20:17 167,444 –a—— C:\WINDOWS\system32\svbaocev.exe
2007-09-28 19:31 167,444 –a—— C:\WINDOWS\system32\dbdahbdd.exe
2007-09-28 19:29 d——– C:\Program Files\New Folder
2007-09-28 19:15 488,144 –a—— C:\Program Files\HJTsetup.exe
2007-09-28 19:13 167,444 –a—— C:\WINDOWS\system32\eciordye.exe
2007-09-28 10:12 167,444 –a—— C:\WINDOWS\system32\qayfygnl.exe
2007-09-28 10:05 167,444 –a—— C:\WINDOWS\system32\rmdshyqf.exe
2007-09-28 09:48 167,444 –a—— C:\WINDOWS\system32\yxxadcyx.exe
2007-09-28 08:53 79,688 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2007-09-28 08:53 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-09-28 08:53 62,280 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2007-09-28 08:53 41,288 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-09-28 08:53 29,000 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2007-09-28 08:53 d——– C:\Program Files\Spyware Doctor
2007-09-28 08:53 d——– C:\Documents and Settings\Robert\Application Data\PC Tools
2007-09-27 17:24 153 –a—— C:\WINDOWS\system32\delFSF.bat
2007-09-27 01:10 7,388 –a—— C:\fteylbk.exe
2007-09-27 01:10 28,160 –a—— C:\arca.exe
2007-09-27 01:10 158,432 –a—— C:\WINDOWS\system32\986e5b52.sys
2007-09-27 01:09 45,867 –a—— C:\fbipukh.exe
2007-09-27 01:09 d——– C:\WINDOWS\Web Download
2007-09-20 20:37 d——– C:\Documents and Settings\Robert\Application Data\Sony
2007-09-20 20:37 d——– C:\Documents and Settings\Robert\Application Data\Publish Providers
2007-09-20 19:57 d——– C:\Program Files\Vstplugins
2007-09-20 19:57 d——– C:\Documents and Settings\All Users\Application Data\Sony
2007-09-20 19:56 d——– C:\Program Files\Sony
2007-09-20 19:52 d——– C:\Program Files\Sony Setup
2007-09-20 19:52 d——– C:\Documents and Settings\Robert\Application Data\Sony Setup
2007-09-20 19:32 d–h—– C:\WINDOWS\msdownld.tmp
2007-09-20 19:32 d——– C:\WINDOWS\system32\windows media
2007-09-20 19:32 d——– C:\Program Files\Windows Media Components
2007-09-20 18:50 765,952 –a—— C:\WINDOWS\system32\xvidcore.dll
2007-09-20 18:50 180,224 –a—— C:\WINDOWS\system32\xvidvfw.dll
2007-09-20 18:50 d——– C:\Program Files\Xvid
2007-09-20 17:25 d——– C:\Documents and Settings\Robert\Application Data\DivX
2007-09-20 12:43 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-09-20 12:42 d——– C:\Fraps
2007-09-19 19:40 d——– C:\Documents and Settings\Robert\Application Data\Azureus
2007-09-19 19:40 d——– C:\Documents and Settings\All Users\Application Data\Azureus
2007-09-17 13:23 823,296 –a—— C:\WINDOWS\system32\divx_xx0c.dll
2007-09-17 13:23 823,296 –a—— C:\WINDOWS\system32\divx_xx07.dll
2007-09-17 13:22 802,816 –a—— C:\WINDOWS\system32\divx_xx11.dll
2007-09-17 13:22 739,840 –a—— C:\WINDOWS\system32\DivX.dll
2007-09-17 01:07 8,491,008 –a—— C:\WINDOWS\system32\nvcpl.dll
2007-09-17 01:07 6,746,112 –a—— C:\WINDOWS\system32\nvoglnt.dll
2007-09-11 18:14 156,992 –a—— C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-09-11 04:17 81,920 –a—— C:\WINDOWS\system32\frapsvid.dll
2007-08-28 17:26 d——– C:\Documents and Settings\Robert\Application Data\Apple Computer
2007-08-20 19:26 81,920 –a—— C:\WINDOWS\system32\dpl100.dll
2007-08-20 19:26 196,608 –a—— C:\WINDOWS\system32\dtu100.dll
2007-08-15 17:33 524,288 –a—— C:\WINDOWS\system32\DivXsm.exe
2007-08-15 17:33 3,596,288 –a—— C:\WINDOWS\system32\qt-dx331.dll
2007-08-15 17:33 200,704 –a—— C:\WINDOWS\system32\ssldivx.dll
2007-08-15 17:33 1,044,480 –a—— C:\WINDOWS\system32\libdivx.dll
2007-08-15 17:31 593,920 –a—— C:\WINDOWS\system32\dpuGUI11.dll
2007-08-15 17:31 57,344 –a—— C:\WINDOWS\system32\dpv11.dll
2007-08-15 17:31 53,248 –a—— C:\WINDOWS\system32\dpuGUI10.dll
2007-08-15 17:31 344,064 –a—— C:\WINDOWS\system32\dpus11.dll
2007-08-15 17:31 294,912 –a—— C:\WINDOWS\system32\dpu11.dll
2007-08-15 17:31 294,912 –a—— C:\WINDOWS\system32\dpu10.dll
2007-08-15 17:30 12,288 –a—— C:\WINDOWS\system32\DivXWMPExtType.dll
2007-08-15 03:01 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2007-08-04 21:10 d——– C:\Program Files\Octoshape Streaming Services

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-28 10:35 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-09-28 09:54 ——— d——– C:\Program Files\Google
2007-09-28 09:51 ——— d——– C:\Documents and Settings\All Users\Application Data\Google
2007-09-27 08:21 9344 –a—— C:\WINDOWS\system32\drivers\NSDriver.sys
2007-09-27 08:21 8320 –a—— C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-09-25 17:10 ——— d——– C:\Program Files\World of Warcraft
2007-09-21 18:21 ——— d——– C:\Program Files\BitTyrant
2007-09-19 19:40 ——— d——– C:\Documents and Settings\Robert\Application Data\BitTyrant
2007-09-17 02:10 356352 –a—— C:\WINDOWS\system32\nvusmb.exe
2007-09-17 02:10 356352 –a—— C:\WINDOWS\system32\nvunrm.exe
2007-09-17 02:10 356352 –a—— C:\WINDOWS\system32\NVUNINST.EXE
2007-09-17 02:10 356352 –a—— C:\WINDOWS\system32\nvuide.exe
2007-09-17 02:10 356352 –a—— C:\WINDOWS\system32\nvudisp.exe
2007-09-17 02:10 356352 –a—— C:\WINDOWS\system32\nvuaudio.exe
2007-09-17 01:07 81920 –a—— C:\WINDOWS\system32\nvwddi.dll
2007-09-17 01:07 81920 –a—— C:\WINDOWS\system32\nvmctray.dll
2007-09-17 01:07 753664 –a—— C:\WINDOWS\system32\nvcplui.exe
2007-09-17 01:07 6853088 –a—— C:\WINDOWS\system32\drivers\nv4_mini.sys
2007-09-17 01:07 6344704 –a—— C:\WINDOWS\system32\nvdisps.dll
2007-09-17 01:07 5783040 –a—— C:\WINDOWS\system32\nv4_disp.dll
2007-09-17 01:07 466944 –a—— C:\WINDOWS\system32\nvshell.dll
2007-09-17 01:07 45056 –a—— C:\WINDOWS\system32\nvmccsrs.dll
2007-09-17 01:07 442368 –a—— C:\WINDOWS\system32\nvappbar.exe
2007-09-17 01:07 425984 –a—— C:\WINDOWS\system32\keystone.exe
2007-09-17 01:07 36864 –a—— C:\WINDOWS\system32\nvcodins.dll
2007-09-17 01:07 36864 –a—— C:\WINDOWS\system32\nvcod.dll
2007-09-17 01:07 364544 –a—— C:\WINDOWS\system32\nvapi.dll
2007-09-17 01:07 3551232 –a—— C:\WINDOWS\system32\nvvitvs.dll
2007-09-17 01:07 3334144 –a—— C:\WINDOWS\system32\nvgames.dll
2007-09-17 01:07 307200 –a—— C:\WINDOWS\system32\nvexpbar.dll
2007-09-17 01:07 286720 –a—— C:\WINDOWS\system32\nvnt4cpl.dll
2007-09-17 01:07 2371584 –a—— C:\WINDOWS\system32\nvwss.dll
2007-09-17 01:07 229376 –a—— C:\WINDOWS\system32\nvmccs.dll
2007-09-17 01:07 188416 –a—— C:\WINDOWS\system32\nvmccss.dll
2007-09-17 01:07 1703936 –a—— C:\WINDOWS\system32\nvwdmcpl.dll
2007-09-17 01:07 1626112 –a—— C:\WINDOWS\system32\nwiz.exe
2007-09-17 01:07 155716 –a—— C:\WINDOWS\system32\nvsvc32.exe
2007-09-17 01:07 1478656 –a—— C:\WINDOWS\system32\nview.dll
2007-09-17 01:07 147456 –a—— C:\WINDOWS\system32\nvcolor.exe
2007-09-17 01:07 1339392 –a—— C:\WINDOWS\system32\nvdspsch.exe
2007-09-17 01:07 1150976 –a—— C:\WINDOWS\system32\nvmobls.dll
2007-09-17 01:07 1019904 –a—— C:\WINDOWS\system32\nvwimg.dll
2007-07-30 19:19 92504 –a—— C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 –a—— C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 –a—— C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 –a—— C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 –a—— C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 271224 –a—— C:\WINDOWS\system32\mucltui.dll
2007-07-30 19:19 207736 –a—— C:\WINDOWS\system32\muweb.dll
2007-07-30 19:19 203096 –a—— C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 –a—— C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 –a—— C:\WINDOWS\system32\wups.dll
2007-07-14 14:58 86016 –a—— C:\WINDOWS\system32\OpenAL32.dll
2007-07-14 14:58 413696 –a—— C:\WINDOWS\system32\wrap_oal.dll
2007-06-26 01:08 1104896 –a—— C:\WINDOWS\system32\msxml3.dll
2007-06-19 08:31 282112 –a—— C:\WINDOWS\system32\gdi32.dll
2007-06-13 05:23 1033216 –a—— C:\WINDOWS\explorer.exe
.

– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4AADFB9A-D38F-4618-B01F-090E8462DA19}]
C:\WINDOWS\system32\sstqn.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"D-Link AirPlus G"="C:\Program Files\D-Link\AirPlus G\AirGCFG.exe" [2005-03-18 04:34]
"ANIWZCS2Service"="C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2004-12-16 17:49]
"NVMixerTray"="C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" []
"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.exe" [2002-02-04 22:32]
"nwiz"="nwiz.exe" [2007-09-17 01:07 C:\WINDOWS\system32\nwiz.exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-05-20 14:46 C:\WINDOWS\KHALMNPR.Exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"CTHelper"="CTHELPER.EXE" [2006-08-17 11:32 C:\WINDOWS\CTHELPER.EXE]
"CTxfiHlp"="CTXFIHLP.EXE" [2006-08-17 11:32 C:\WINDOWS\system32\CTXFIHLP.EXE]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 11:09]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-07-21 10:16]
"{8F-FF-F8-8A-ZN}"="C:\windows\system32\kjdsregp.exe" []
"au"="C:\Program Files\Dealio\DealioAU.exe" []
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-09-17 01:07]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-09-17 01:07]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-09-29 17:34]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Exif Launcher.lnk - C:\Program Files\FinePixViewer\QuickDCF.exe [2007-05-26 21:45:31]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-05-27 10:49:14]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Exif Launcher.lnk - C:\Program Files\FinePixViewer\QuickDCF.exe [2007-05-26 21:45:31]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-05-27 10:49:14]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awvtq]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gebyy]
C:\WINDOWS\system32\gebyy.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljjg]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sstqn]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtsqn]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"

R1 vcdrom;Virtual CD-ROM Device Driver;\??\C:\WINDOWS\system32\drivers\VCdRom.sys
R3 ha20x2k;Creative 20X HAL Driver;C:\WINDOWS\system32\drivers\ha20x2k.sys
S3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);C:\WINDOWS\system32\DRIVERS\A3AB.sys
S3 PciCon;PciCon;\??\E:\PciCon.sys


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{98843dee-0bf5-11dc-a6f5-806d6172696f}]
AutoRun\command- E:\setup.exe

.
Contents of the 'Scheduled Tasks' folder
"2007-09-25 17:01:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-30 17:56:19
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-09-30 17:56:45
C:\ComboFix-quarantined-files.txt … 2007-09-30 17:56
C:\ComboFix2.txt … 2007-09-30 17:53
.
— E O F —


Thanks again for all your help.
Sid
Hi

You have no anti-virus on your computer. It is important you install one now before we continue with your fix. Check this out for a list of free AV scanners, AVG is highly recommended.

P2P Warning!
Please note that as long as you are using any form of Peer-to-Peer networking and downloading files from non-documented sources, you can expect infestations of malware to occur
Once upon a time, P2P file sharing was fairly safe. That is no longer true. You may continue to use P2P sharing at your own risk; however, please keep in mind that this practice may be the source of your current malware infestation
Additional information on the safety of Peer to Peer programs themselves is here :
Clean/Infected P2P Programs
Please refrain from using your P2P during the course of your fix, so you dont risk inviting more malware onto your computer.

Let me see a new HijackThis log when you have installed an anti-virus.
I installed it AVG earlier actually, wasn't sure if you wanted me to run a scan or not so I installed it, then disabled it to run the ComboFix. Anyway I ran a scan, it found a few things and deleted them, then ran hijackthis.

Here is the log of the latest hijackthis scan

Logfile of HijackThis v1.99.1
Scan saved at 9:08:04 PM, on 9/30/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\Hijackthis\iseeu.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {4AADFB9A-D38F-4618-B01F-090E8462DA19} - C:\WINDOWS\system32\sstqn.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [{8F-FF-F8-8A-ZN}] C:\windows\system32\kjdsregp.exe OLI001
O4 - HKLM\..\Run: [au] C:\Program Files\Dealio\DealioAU.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Exif Launcher.lnk = ?
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by130fd.bay130.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1180232250640
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1180233980218
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: awvtq - C:\WINDOWS\
O20 - Winlogon Notify: gebyy - C:\WINDOWS\system32\gebyy.dll (file missing)
O20 - Winlogon Notify: mljjg - C:\WINDOWS\
O20 - Winlogon Notify: sstqn - C:\WINDOWS\
O20 - Winlogon Notify: vtsqn - C:\WINDOWS\
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe


Thanks again for your help
Sid
Hello

Go to http://www.virustotal.com/en/indexf.html
Copy the following line into the white textbox:
C:\WINDOWS\system32\986e5b52.sys
Click Send.
Please post the results of this scan to this thread.

Open Notepad and Copy/Paste the text in the codebox below into it:

File::
C:\WINDOWS\system32\npqptunx.exe
C:\WINDOWS\system32\apylcsbf.exe
C:\WINDOWS\system32\dsetblyl.exe 
C:\WINDOWS\system32\svbaocev.exe
C:\WINDOWS\system32\dbdahbdd.exe
C:\WINDOWS\system32\eciordye.exe
C:\WINDOWS\system32\qayfygnl.exe
C:\WINDOWS\system32\rmdshyqf.exe
C:\WINDOWS\system32\yxxadcyx.exe
C:\WINDOWS\system32\delFSF.bat
C:\fteylbk.exe
C:\arca.exe
C:\fbipukh.exe
C:\WINDOWS\system32\sstqn.dll
C:\windows\system32\kjdsregp.exe
C:\WINDOWS\system32\gebyy.dll

Folder::
C:\Program Files\Dealio

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4AADFB9A-D38F-4618-B01F-090E8462DA19}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"{8F-FF-F8-8A-ZN}"=-
"au"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awvtq]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gebyy] 
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljjg]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sstqn]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtsqn]

Save this as "CFScript"

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log with a new HijackThis log.
OK, here is the log from VirusTotal-

File 986e5b52.sys received on 09.30.2007 17:54:08 (CET)
Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED


Result: 1/32 (3.13%)
Loading server information…
Your file is queued in position: 1.
Estimated start time is between 39 and 56 seconds.
Do not close the window until scan is complete.
The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
If you are waiting for more than five minutes you have to resend your file.
Your file is being scanned by VirusTotal in this moment,
results will be shown as they're generated.
Compact Print results
Your file has expired or does not exists.
Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time.

You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.
Email:


Antivirus Version Last Update Result
AhnLab-V3 2007.9.29.0 2007.09.28 -
AntiVir 7.6.0.18 2007.09.28 -
Authentium 4.93.8 2007.09.29 -
Avast 4.7.1043.0 2007.09.30 -
AVG 7.5.0.488 2007.09.30 -
BitDefender 7.2 2007.09.30 -
CAT-QuickHeal 9.00 2007.09.29 -
ClamAV 0.91.2 2007.09.30 -
DrWeb 4.33 2007.09.30 -
eSafe 7.0.15.0 2007.09.29 -
eTrust-Vet 31.2.5174 2007.09.30 -
Ewido 4.0 2007.09.30 -
FileAdvisor 1 2007.09.30 -
Fortinet 3.11.0.0 2007.09.30 -
F-Prot 4.3.2.48 2007.09.29 -
F-Secure 6.70.13030.0 2007.09.29 -
Ikarus T3.1.1.12 2007.09.30 -
Kaspersky 7.0.0.125 2007.09.30 -
McAfee 5130 2007.09.28 -
Microsoft 1.2803 2007.09.30 -
NOD32v2 2560 2007.09.30 -
Norman 5.80.02 2007.09.28 -
Panda 9.0.0.4 2007.09.30 -
Prevx1 V2 2007.09.30 -
Rising 19.42.61.00 2007.09.30 -
Sophos 4.22.0 2007.09.30 -
Sunbelt 2.2.907.0 2007.09.28 -
Symantec 10 2007.09.30 -
TheHacker 6.2.6.073 2007.09.28 -
VBA32 3.12.2.4 2007.09.30 -
VirusBuster 4.3.26:9 2007.09.29 -
Webwasher-Gateway 6.0.1 2007.09.28 Win32.Malware.gen!82 (suspicious)
Additional information
File size: 158432 bytes
MD5: 791b9fc0c4dcb529497ca07ae271eba9
SHA1: 5eaf0c38ad6efc88f56c911206557f69c58231d7


Here are the results from ComboFix



ComboFix 07-09-30.4 - Robert 2007-10-01 11:14:27.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1669 [GMT -5:00]
Running from: D:\ComboFix.exe
Command switches used :: D:\[removed]
* Created a new restore point

FILE::
C:\WINDOWS\system32\npqptunx.exe
C:\WINDOWS\system32\apylcsbf.exe
C:\WINDOWS\system32\dsetblyl.exe
C:\WINDOWS\system32\svbaocev.exe
C:\WINDOWS\system32\dbdahbdd.exe
C:\WINDOWS\system32\eciordye.exe
C:\WINDOWS\system32\qayfygnl.exe
C:\WINDOWS\system32\rmdshyqf.exe
C:\WINDOWS\system32\yxxadcyx.exe
C:\WINDOWS\system32\delFSF.bat
C:\fteylbk.exe
C:\arca.exe
C:\fbipukh.exe
C:\WINDOWS\system32\sstqn.dll
C:\windows\system32\kjdsregp.exe
C:\WINDOWS\system32\gebyy.dll
.

((((((((((((((((((((((((( Files Created from 2007-09-01 to 2007-10-01 )))))))))))))))))))))))))))))))
.

2007-09-30 17:54 d——– C:\WINDOWS\system32\LogFiles
2007-09-29 17:46 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-09-28 19:29 d——– C:\Program Files\New Folder
2007-09-28 19:15 488,144 –a—— C:\Program Files\HJTsetup.exe
2007-09-28 08:53 79,688 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2007-09-28 08:53 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-09-28 08:53 62,280 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2007-09-28 08:53 41,288 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-09-28 08:53 29,000 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2007-09-28 08:53 d——– C:\Program Files\Spyware Doctor
2007-09-28 08:53 d——– C:\Documents and Settings\Robert\Application Data\PC Tools
2007-09-27 01:10 158,432 –a—— C:\WINDOWS\system32\986e5b52.sys
2007-09-27 01:09 d——– C:\WINDOWS\Web Download
2007-09-20 20:37 d——– C:\Documents and Settings\Robert\Application Data\Sony
2007-09-20 20:37 d——– C:\Documents and Settings\Robert\Application Data\Publish Providers
2007-09-20 19:57 d——– C:\Program Files\Vstplugins
2007-09-20 19:57 d——– C:\Documents and Settings\All Users\Application Data\Sony
2007-09-20 19:56 d——– C:\Program Files\Sony
2007-09-20 19:52 d——– C:\Program Files\Sony Setup
2007-09-20 19:52 d——– C:\Documents and Settings\Robert\Application Data\Sony Setup
2007-09-20 19:32 d–h—– C:\WINDOWS\msdownld.tmp
2007-09-20 19:32 d——– C:\WINDOWS\system32\windows media
2007-09-20 19:32 d——– C:\Program Files\Windows Media Components
2007-09-20 18:50 765,952 –a—— C:\WINDOWS\system32\xvidcore.dll
2007-09-20 18:50 180,224 –a—— C:\WINDOWS\system32\xvidvfw.dll
2007-09-20 18:50 d——– C:\Program Files\Xvid
2007-09-20 17:25 d——– C:\Documents and Settings\Robert\Application Data\DivX
2007-09-20 12:43 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-09-20 12:42 d——– C:\Fraps
2007-09-19 19:40 d——– C:\Documents and Settings\Robert\Application Data\Azureus
2007-09-19 19:40 d——– C:\Documents and Settings\All Users\Application Data\Azureus
2007-09-17 13:23 823,296 –a—— C:\WINDOWS\system32\divx_xx0c.dll
2007-09-17 13:23 823,296 –a—— C:\WINDOWS\system32\divx_xx07.dll
2007-09-17 13:22 802,816 –a—— C:\WINDOWS\system32\divx_xx11.dll
2007-09-17 13:22 739,840 –a—— C:\WINDOWS\system32\DivX.dll
2007-09-17 01:07 8,491,008 –a—— C:\WINDOWS\system32\nvcpl.dll
2007-09-17 01:07 6,746,112 –a—— C:\WINDOWS\system32\nvoglnt.dll
2007-09-11 18:14 156,992 –a—— C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-09-11 04:17 81,920 –a—— C:\WINDOWS\system32\frapsvid.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-28 10:35 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-09-28 09:54 ——— d——– C:\Program Files\Google
2007-09-28 09:51 ——— d——– C:\Documents and Settings\All Users\Application Data\Google
2007-09-27 20:04 ——— d——– C:\Program Files\Octoshape Streaming Services
2007-09-27 08:21 9344 –a—— C:\WINDOWS\system32\drivers\NSDriver.sys
2007-09-27 08:21 8320 –a—— C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-09-25 17:10 ——— d——– C:\Program Files\World of Warcraft
2007-09-21 18:21 ——— d——– C:\Program Files\BitTyrant
2007-09-19 19:40 ——— d——– C:\Documents and Settings\Robert\Application Data\BitTyrant
2007-09-17 02:10 356352 –a—— C:\WINDOWS\system32\nvusmb.exe
2007-09-17 02:10 356352 –a—— C:\WINDOWS\system32\nvunrm.exe
2007-09-17 02:10 356352 –a—— C:\WINDOWS\system32\NVUNINST.EXE
2007-09-17 02:10 356352 –a—— C:\WINDOWS\system32\nvuide.exe
2007-09-17 02:10 356352 –a—— C:\WINDOWS\system32\nvudisp.exe
2007-09-17 02:10 356352 –a—— C:\WINDOWS\system32\nvuaudio.exe
2007-09-17 01:07 81920 –a—— C:\WINDOWS\system32\nvwddi.dll
2007-09-17 01:07 81920 –a—— C:\WINDOWS\system32\nvmctray.dll
2007-09-17 01:07 753664 –a—— C:\WINDOWS\system32\nvcplui.exe
2007-09-17 01:07 6853088 –a—— C:\WINDOWS\system32\drivers\nv4_mini.sys
2007-09-17 01:07 6344704 –a—— C:\WINDOWS\system32\nvdisps.dll
2007-09-17 01:07 5783040 –a—— C:\WINDOWS\system32\nv4_disp.dll
2007-09-17 01:07 466944 –a—— C:\WINDOWS\system32\nvshell.dll
2007-09-17 01:07 45056 –a—— C:\WINDOWS\system32\nvmccsrs.dll
2007-09-17 01:07 442368 –a—— C:\WINDOWS\system32\nvappbar.exe
2007-09-17 01:07 425984 –a—— C:\WINDOWS\system32\keystone.exe
2007-09-17 01:07 36864 –a—— C:\WINDOWS\system32\nvcodins.dll
2007-09-17 01:07 36864 –a—— C:\WINDOWS\system32\nvcod.dll
2007-09-17 01:07 364544 –a—— C:\WINDOWS\system32\nvapi.dll
2007-09-17 01:07 3551232 –a—— C:\WINDOWS\system32\nvvitvs.dll
2007-09-17 01:07 3334144 –a—— C:\WINDOWS\system32\nvgames.dll
2007-09-17 01:07 307200 –a—— C:\WINDOWS\system32\nvexpbar.dll
2007-09-17 01:07 286720 –a—— C:\WINDOWS\system32\nvnt4cpl.dll
2007-09-17 01:07 2371584 –a—— C:\WINDOWS\system32\nvwss.dll
2007-09-17 01:07 229376 –a—— C:\WINDOWS\system32\nvmccs.dll
2007-09-17 01:07 188416 –a—— C:\WINDOWS\system32\nvmccss.dll
2007-09-17 01:07 1703936 –a—— C:\WINDOWS\system32\nvwdmcpl.dll
2007-09-17 01:07 1626112 –a—— C:\WINDOWS\system32\nwiz.exe
2007-09-17 01:07 155716 –a—— C:\WINDOWS\system32\nvsvc32.exe
2007-09-17 01:07 1478656 –a—— C:\WINDOWS\system32\nview.dll
2007-09-17 01:07 147456 –a—— C:\WINDOWS\system32\nvcolor.exe
2007-09-17 01:07 1339392 –a—— C:\WINDOWS\system32\nvdspsch.exe
2007-09-17 01:07 1150976 –a—— C:\WINDOWS\system32\nvmobls.dll
2007-09-17 01:07 1019904 –a—— C:\WINDOWS\system32\nvwimg.dll
2007-08-28 17:26 ——— d——– C:\Documents and Settings\Robert\Application Data\Apple Computer
2007-08-20 19:26 81920 –a—— C:\WINDOWS\system32\dpl100.dll
2007-08-20 19:26 196608 –a—— C:\WINDOWS\system32\dtu100.dll
2007-08-15 17:33 524288 –a—— C:\WINDOWS\system32\DivXsm.exe
2007-08-15 17:33 3596288 –a—— C:\WINDOWS\system32\qt-dx331.dll
2007-08-15 17:33 200704 –a—— C:\WINDOWS\system32\ssldivx.dll
2007-08-15 17:33 1044480 –a—— C:\WINDOWS\system32\libdivx.dll
2007-08-15 17:31 593920 –a—— C:\WINDOWS\system32\dpuGUI11.dll
2007-08-15 17:31 57344 –a—— C:\WINDOWS\system32\dpv11.dll
2007-08-15 17:31 53248 –a—— C:\WINDOWS\system32\dpuGUI10.dll
2007-08-15 17:31 344064 –a—— C:\WINDOWS\system32\dpus11.dll
2007-08-15 17:31 294912 –a—— C:\WINDOWS\system32\dpu11.dll
2007-08-15 17:31 294912 –a—— C:\WINDOWS\system32\dpu10.dll
2007-08-15 17:30 12288 –a—— C:\WINDOWS\system32\DivXWMPExtType.dll
2007-07-30 19:19 92504 –a—— C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 –a—— C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 –a—— C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 –a—— C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 –a—— C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 271224 –a—— C:\WINDOWS\system32\mucltui.dll
2007-07-30 19:19 207736 –a—— C:\WINDOWS\system32\muweb.dll
2007-07-30 19:19 203096 –a—— C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 –a—— C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 –a—— C:\WINDOWS\system32\wups.dll
2007-07-14 14:58 86016 –a—— C:\WINDOWS\system32\OpenAL32.dll
2007-07-14 14:58 413696 –a—— C:\WINDOWS\system32\wrap_oal.dll
.

– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"D-Link AirPlus G"="C:\Program Files\D-Link\AirPlus G\AirGCFG.exe" [2005-03-18 04:34]
"ANIWZCS2Service"="C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2004-12-16 17:49]
"NVMixerTray"="C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" []
"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.exe" [2002-02-04 22:32]
"nwiz"="nwiz.exe" [2007-09-17 01:07 C:\WINDOWS\system32\nwiz.exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-05-20 14:46 C:\WINDOWS\KHALMNPR.Exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"CTHelper"="CTHELPER.EXE" [2006-08-17 11:32 C:\WINDOWS\CTHELPER.EXE]
"CTxfiHlp"="CTXFIHLP.EXE" [2006-08-17 11:32 C:\WINDOWS\system32\CTXFIHLP.EXE]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 11:09]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-07-21 10:16]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-09-17 01:07]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-09-17 01:07]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-09-29 17:34]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Exif Launcher.lnk - C:\Program Files\FinePixViewer\QuickDCF.exe [2007-05-26 21:45:31]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-05-27 10:49:14]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Exif Launcher.lnk - C:\Program Files\FinePixViewer\QuickDCF.exe [2007-05-26 21:45:31]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-05-27 10:49:14]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"

R1 vcdrom;Virtual CD-ROM Device Driver;\??\C:\WINDOWS\system32\drivers\VCdRom.sys
R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);C:\WINDOWS\system32\DRIVERS\A3AB.sys
R3 ha20x2k;Creative 20X HAL Driver;C:\WINDOWS\system32\drivers\ha20x2k.sys
S3 PciCon;PciCon;\??\E:\PciCon.sys


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{98843dee-0bf5-11dc-a6f5-806d6172696f}]
AutoRun\command- E:\setup.exe

.
Contents of the 'Scheduled Tasks' folder
"2007-09-25 17:01:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-01 11:16:03
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-10-01 11:16:25
C:\ComboFix-quarantined-files.txt … 2007-10-01 11:16
C:\ComboFix2.txt … 2007-09-30 17:56
C:\ComboFix3.txt … 2007-09-30 17:53
.
— E O F —


Log from hijackthis-

Logfile of HijackThis v1.99.1
Scan saved at 11:17:46 AM, on 10/1/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Hijackthis\iseeu.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Exif Launcher.lnk = ?
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by130fd.bay130.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1180232250640
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1180233980218
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe



Thanks yet again for the help :)
Sid
Hi

Looking much better :thumbup:

Please do an online scan with Kaspersky Online Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database:

      + Extended(If available otherwise Standard)
    • Scan Options:

      + Scan Archives
      + Scan Mail Bases
  • Click OK
  • Now under select a target to scan select My Computer
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
Here you go, KASPERSKY ONLINE SCANNER REPORT Monday, October 01, 2007 4:38:08 PM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.93.1 Kaspersky Anti-Virus database last update: 30/09/2007 Kaspersky Anti-Virus database records: 425677 Scan Settings Scan using the following antivirus database extended Scan Archives true Scan Mail Bases true Scan Target My Computer A:\ C:\ D:\ E:\ Scan Statistics Total number of scanned objects 70263 Number of viruses found 3 Number of infected objects 27 Number of suspicious objects 0 Duration of the scan process 00:41:14 Infected Object Name Virus Name Last Action C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Robert\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Robert\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Robert\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Robert\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Robert\Local Settings\History\History.IE5\MSHist012007100120071002\index.dat Object is locked skipped C:\Documents and Settings\Robert\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Robert\NTUSER.DAT Object is locked skipped C:\Documents and Settings\Robert\ntuser.dat.LOG Object is locked skipped C:\qoobox\Quarantine\C\WINDOWS\system32\cmpgxeur.exe.vir Infected: Trojan.Win32.Agent.bck skipped C:\qoobox\Quarantine\C\WINDOWS\system32\csycbunv.exe.vir Infected: Trojan.Win32.Agent.bck skipped C:\qoobox\Quarantine\C\WINDOWS\system32\ehcwpmaa.exe.vir Infected: Trojan.Win32.Agent.bck skipped C:\qoobox\Quarantine\C\WINDOWS\system32\irfqfcfj.exe.vir Infected: Trojan.Win32.Agent.bck skipped C:\qoobox\Quarantine\C\WINDOWS\system32\ivuwenoc.exe.vir Infected: Trojan.Win32.Agent.bck skipped C:\qoobox\Quarantine\C\WINDOWS\system32\pftlddac.exe.vir Infected: Trojan.Win32.Agent.bck skipped C:\qoobox\Quarantine\C\WINDOWS\system32\vwvemdyg.exe.vir Infected: Trojan.Win32.Agent.bck skipped C:\qoobox\Quarantine\C\WINDOWS\system32\wdptpssj.exe.vir Infected: Trojan.Win32.Agent.bck skipped C:\qoobox\Quarantine\catchme2007-09-30_175159.96.zip/jkhff.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped C:\qoobox\Quarantine\catchme2007-09-30_175159.96.zip/byxyaby.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped C:\qoobox\Quarantine\catchme2007-09-30_175159.96.zip ZIP: infected - 2 skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{298C77E5-3B05-49AF-AF95-C9F97B870F44}\RP246\A0023136.exe Object is locked skipped C:\System Volume Information\_restore{298C77E5-3B05-49AF-AF95-C9F97B870F44}\RP246\A0024139.sys Object is locked skipped C:\System Volume Information\_restore{298C77E5-3B05-49AF-AF95-C9F97B870F44}\RP247\A0026151.exe Infected: Trojan.Win32.Agent.bck skipped C:\System Volume Information\_restore{298C77E5-3B05-49AF-AF95-C9F97B870F44}\RP247\A0026264.sys Object is locked skipped C:\System Volume Information\_restore{298C77E5-3B05-49AF-AF95-C9F97B870F44}\RP252\A0026826.exe Infected: Trojan.Win32.Agent.bck skipped C:\System Volume Information\_restore{298C77E5-3B05-49AF-AF95-C9F97B870F44}\RP252\A0027846.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped C:\System Volume Information\_restore{298C77E5-3B05-49AF-AF95-C9F97B870F44}\RP252\A0027847.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped C:\System Volume Information\_restore{298C77E5-3B05-49AF-AF95-C9F97B870F44}\RP252\A0027848.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped C:\System Volume Information\_restore{298C77E5-3B05-49AF-AF95-C9F97B870F44}\RP253\A0027943.exe Object is locked skipped C:\System Volume Information\_restore{298C77E5-3B05-49AF-AF95-C9F97B870F44}\RP253\A0029147.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped C:\System Volume Information\_restore{298C77E5-3B05-49AF-AF95-C9F97B870F44}\RP255\A0033158.exe Infected: Trojan.Win32.Agent.bck skipped C:\System Volume Information\_restore{298C77E5-3B05-49AF-AF95-C9F97B870F44}\RP255\A0033159.exe Infected: Trojan.Win32.Agent.bck skipped C:\System Volume Information\_restore{298C77E5-3B05-49AF-AF95-C9F97B870F44}\RP255\A0033160.exe Infected: Trojan.Win32.Agent.bck skipped C:\System Volume Information\_restore{298C77E5-3B05-49AF-AF95-C9F97B870F44}\RP255\A0033161.exe Infected: Trojan.Win32.Agent.bck skipped C:\System Volume Information\_restore{298C77E5-3B05-49AF-AF95-C9F97B870F44}\RP255\A0033162.exe Infected: Trojan.Win32.Agent.bck skipped C:\System Volume Information\_restore{298C77E5-3B05-49AF-AF95-C9F97B870F44}\RP255\A0033163.exe Infected: Trojan.Win32.Agent.bck skipped C:\System Volume Information\_restore{298C77E5-3B05-49AF-AF95-C9F97B870F44}\RP255\A0033164.exe Infected: Trojan.Win32.Agent.bck skipped C:\System Volume Information\_restore{298C77E5-3B05-49AF-AF95-C9F97B870F44}\RP255\A0033165.exe Infected: Trojan.Win32.Agent.bck skipped C:\System Volume Information\_restore{298C77E5-3B05-49AF-AF95-C9F97B870F44}\RP255\A0033272.dll Object is locked skipped C:\System Volume Information\_restore{298C77E5-3B05-49AF-AF95-C9F97B870F44}\RP255\A0033375.exe Object is locked skipped C:\System Volume Information\_restore{298C77E5-3B05-49AF-AF95-C9F97B870F44}\RP255\A0033380.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped C:\System Volume Information\_restore{298C77E5-3B05-49AF-AF95-C9F97B870F44}\RP255\A0033381.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped C:\System Volume Information\_restore{298C77E5-3B05-49AF-AF95-C9F97B870F44}\RP256\A0033421.exe Object is locked skipped C:\System Volume Information\_restore{298C77E5-3B05-49AF-AF95-C9F97B870F44}\RP256\A0033422.exe Object is locked skipped C:\System Volume Information\_restore{298C77E5-3B05-49AF-AF95-C9F97B870F44}\RP256\A0033423.exe Object is locked skipped C:\System Volume Information\_restore{298C77E5-3B05-49AF-AF95-C9F97B870F44}\RP256\A0033424.exe Object is locked skipped C:\System Volume Information\_restore{298C77E5-3B05-49AF-AF95-C9F97B870F44}\RP256\A0033425.exe Object is locked skipped C:\System Volume Information\_restore{298C77E5-3B05-49AF-AF95-C9F97B870F44}\RP256\A0033426.exe Object is locked skipped C:\System Volume Information\_restore{298C77E5-3B05-49AF-AF95-C9F97B870F44}\RP256\A0033427.exe Object is locked skipped C:\System Volume Information\_restore{298C77E5-3B05-49AF-AF95-C9F97B870F44}\RP256\A0033428.exe Object is locked skipped C:\System Volume Information\_restore{298C77E5-3B05-49AF-AF95-C9F97B870F44}\RP256\A0033429.exe Object is locked skipped C:\System Volume Information\_restore{298C77E5-3B05-49AF-AF95-C9F97B870F44}\RP256\A0033430.exe Object is locked skipped C:\System Volume Information\_restore{298C77E5-3B05-49AF-AF95-C9F97B870F44}\RP256\A0033431.exe Object is locked skipped C:\System Volume Information\_restore{298C77E5-3B05-49AF-AF95-C9F97B870F44}\RP256\A0033432.exe Object is locked skipped C:\System Volume Information\_restore{298C77E5-3B05-49AF-AF95-C9F97B870F44}\RP258\change.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped D:\System Volume Information\_restore{298C77E5-3B05-49AF-AF95-C9F97B870F44}\RP256\A0033433.exe Object is locked skipped Scan process completed. Thanks again Sid
Hi Sid

Delete the Combofix icon from your Desktop.

To enable the viewing of Hidden files follow these steps:
  • Close all programs so that you are at your desktop.
  • Double-click on the My Computer icon (or click Start, then select My Computer)
  • Select the Tools menu and click Folder Options.
  • After the new window appears select the View tab.
  • Put a checkmark in the checkbox labeled Display the contents of system folders.
  • Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
  • Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
  • Remove the checkmark from the checkbox labeled Hide protected operating system files.
  • Press the Apply button and then the OK button and shutdown My Computer.
    Now your computer is configured to show all hidden files.

Navigate to and delete the following file and folders, if they are present

File:
C:\WINDOWS\system32\986e5b52.sys

Folders:
C:\Combofix
C:\Qoobox

This is my usual speech for when you are clean, which you appear to be.

Please follow these simple steps in order to keep your computer clean and secure:
Disable and Enable System Restore.

It's also a good idea to Flush your System Restore points after ridding yourself of malware:
  • Click Start | Help and Support | Undo changes to your computer with System Restore.
  • Click Create A Restore Point then click Next. Give it a name it and then click Create, then Close.
  • Close the Help and Support Center box.
  • Click Start | Run and type Cleanmgr
  • Select (C: ) then click OK.
  • Click the More Options tab.
  • Click Clean Up in the System Restore Section.
This will remove all previous restore points except the newly created one.

Re hide your system files To do so, please follow the steps below:
  • Double-click My Computer.
  • Click the Tools menu, and then click Folder Options.
  • Click the View tab.
  • Put a check by "Hide file extensions for known file types."
  • Under the "Hidden files" folder, select "Do not show hidden files and folders."
  • Check "Hide protected operating system files."
  • Click Apply, and then click OK.

Here are some free programs I recommend, although you will not need them all. Spybot S&D and Winpatrol are definites though.

Spybot Search and Destroy
Download it from here . Just choose a mirror and off you go.
Find here the tutorial on how to use Spybot properly here

Install Spyware Guard
Download it from here
Find here the tutorial on how to use Spyware Guard here

Install SpyWare Blaster
Download it from here
Find here the tutorial on how to use Spyware Blaster here

Install WinPatrol
Download it from here
Here you can find information about how WinPatrol works here


Make sure your Windows is ALWAYS up to date!

An unpatched Windows is vulnerable and even with the "best" Antivirus and Firewall installed, malware will find its way through.
So visit http://windowsupdate.microsoft.com/ to download and install the latest updates.


Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Please check out Tony Klein's article "How did I get infected in the first place?"


Follow this list and your potential for being infected again will reduce dramatically.

Glad I was able to help.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI