This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Serious Issue (HELP HELP HELP)

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OK, here goes… I tried to post a new topic in the other forum, but it would not. Apart of my issues is that I cannot run HiJackThis, so maybe an admin can move this post later. I had trouble installing a game for my son, I had to download a few things to recover a CD and now I'm in a world of hurt. I have a pretty nice computer that a friend of mine built awhile back, but he has no experience with this issue. Which is: When the computer boots, after I select my profile (and enter my password) Windows XP boots and after a short while (Issue #1) a message appears saying : "setting up personalized settings for upda" in a small box. I also have this issue with (Issue #2) a "Shrinker demonstration version" box that appears saying "This program was compressed with the demonstration version of Shrinker, the .EXE, .DLL and .OCX compressor from Blink, Inc. (www.blinkinc.com). Please select Yes to continue." After selecting "yes" the box disappears only to reappear several times. After about 4 times it stops. Next problem (Issue #3). To try and narrow the issue, I try to Ctrl+Alt+Del to get the Windows Task Manager running to see what foreign programs might be running to create this issue. However, the minute I get the Task Manager up, it disappears. I then go Start > Run > "msconfig" and the dialog box for this feature never pops up. Next problem (Issue #4). Even as I type now, my computer is constantly chopping as I will type fast only to have some letter appear and then stall… Appear! Stall… Appear! As if the computer is loading some seriously big stuff. Next problem (Issue #5). Some not all, programs do not launch. For instance, JFile Recovery program (which I used to help with my son's game) fails to launch. This is the same error I get with AVG. I have several anti-virus programs. But cannot get AVG working to produce a log file. I have run the ATF Cleaner and Spybot. Nothing out of the ordinary has helped. I cannot system restore or anything. Please help… Steve
OK, I safe mode'd a system restore. However, the only system restore date available was around the same time (within an hour) that I caught the virus. I was able to run the HiJackThis and have this to say:

C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\Profiler\LWEmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\symantecupdate20071208.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wi-compact.com/Forum/index.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [exflashservice] "C:\Program Files\EPOX\EFS\EZ_FLASH_SERVICE.exe" "5000"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ManualRun] "D:\AUTORUN\AutoRun"
O4 - HKLM\..\Run: [BtcMouseMaestro] "C:\Program Files\MMaestro\KMaestro.exe"
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [GoogleUpdate] C:\Program Files\Internet Explorer\Down(0).EXE
O4 - HKLM\..\Run: [Service32] C:\WINDOWS\system32\schost.exe
O4 - HKLM\..\Run: [MSUpdater] System32i.exe
O4 - HKLM\..\Run: [AGEIA PhysX SysTray] C:\Program Files\AGEIA Technologies\TrayIcon.exe
O4 - HKLM\..\RunServices: [MSUpdater] System32i.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Logitech Profiler.lnk = ?
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} (CoGSManager Class) - http://gamingzone.ubisoft.com/dev/packages/GSManager.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3EC5C936-3D16-4D21-BA21-7C5E6424AF3A}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CS1\Services\Tcpip\..\{3EC5C936-3D16-4D21-BA21-7C5E6424AF3A}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CS2\Services\Tcpip\..\{3EC5C936-3D16-4D21-BA21-7C5E6424AF3A}: NameServer = 208.67.222.222,208.67.220.220
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NetmanConnections (NetworkConnections) - Unknown owner - C:\WINDOWS\system32\wonlog.ini
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: wampapache - Unknown owner - C:\Program Files\wamp\bin\apache\apache2.2.6\bin\httpd.exe" -k runservice (file missing)
O23 - Service: wampmysqld - Unknown owner - C:\Program Files\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe" wampmysqld (file missing)

Fortunately, problems #1, #2, and #3 have ceased. Anything here?

Steve
Hello and welcome to the Forum

* Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can click next icon next to the files found: [external image: Posted Image]
  • If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:
    [external image: Posted Image]
    This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
  • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web you saved previously in your next reply.
Before I could scan, Dr. Web Scanner found a virus/trojan called msmg.exe that I had blocked. I am afraid that after I have the anti-virus program removed, it will release it back onto my computer. Either way, here is the scan results. byxvvut.dll;c:\windows\system32;Trojan.Virtumod.240;Invalid path to file ; A0041942.dll;C:\System Volume Information\_restore{427FB5F6-DA2E-4290-9C57-A6082BC374B3}\RP296;Trojan.Inject.origin;Moved.; A0049840.dll;C:\System Volume Information\_restore{427FB5F6-DA2E-4290-9C57-A6082BC374B3}\RP359;Trojan.Fakealert.370;Moved.; A0049849.exe;C:\System Volume Information\_restore{427FB5F6-DA2E-4290-9C57-A6082BC374B3}\RP360;Trojan.MulDrop.9708;Moved.; A0049867.exe;C:\System Volume Information\_restore{427FB5F6-DA2E-4290-9C57-A6082BC374B3}\RP360;Trojan.MulDrop.9708;Moved.; A0050126.dll;C:\System Volume Information\_restore{427FB5F6-DA2E-4290-9C57-A6082BC374B3}\RP365;Trojan.DownLoader.35919;Moved.; A0050411.dll;C:\System Volume Information\_restore{427FB5F6-DA2E-4290-9C57-A6082BC374B3}\RP367;Trojan.Virtumod.240;Moved.; A0050412.exe;C:\System Volume Information\_restore{427FB5F6-DA2E-4290-9C57-A6082BC374B3}\RP367;Trojan.MulDrop.9708;Moved.; xxyxxvs.dll;C:\WINDOWS\system32;Trojan.Virtumod.240;Moved.; Registry Healer_Setup.exe;E:\Programs\Registry Healer;BackDoor.Graybird;Moved.; A0043318.exe;E:\System Volume Information\_restore{427FB5F6-DA2E-4290-9C57-A6082BC374B3}\RP313;BackDoor.Graybird;Moved.; After the scan SpiDer Guard found a Trojan.Juan and now a Trojan.Virtumod.240 in that same byxvvut.dll file that it usually is in - can I just outright delete it? Or will it make any difference? Help! Thanks, Steve
I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.

Next:


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:

Download ComboFix from Here to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you, combofix.txt. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick while its running. That may cause it to stall
After the ComboFix reboot, Windows prompted me to block/unblock a program called "System32i", I am assuming this was the ComboFix program. Also, my default web browser was changed to Mozilla to IE, anything helpful? Here is the ComboFix report:

ComboFix 07-12-09.1 - Kampfzentrum 2007-12-10 16:29:19.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1477 [GMT -6:00]
Running from: F:\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\_000006_.tmp.dll
C:\WINDOWS\system32\_000009_.tmp.dll
C:\WINDOWS\system32\_000010_.tmp.dll
C:\WINDOWS\system32\drivers\sfsync02.sys
C:\WINDOWS\system32\gjkkj.ini2
C:\WINDOWS\system32\hgjlm.ini
C:\WINDOWS\system32\hgjlm.ini2
C:\WINDOWS\system32\mljgh.dll
C:\WINDOWS\system32\pqstv.ini2

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_SFSYNC02
——-\sfsync02


((((((((((((((((((((((((( Files Created from 2007-11-10 to 2007-12-10 )))))))))))))))))))))))))))))))
.

2007-12-10 05:16 . 2007-12-10 05:16 d——– C:\Program Files\PM Studios
2007-12-09 21:30 . 2007-12-09 21:44 d——– C:\Documents and Settings\Kampfzentrum\DoctorWeb
2007-12-09 21:30 . 2007-12-09 21:31 77,824 –a—-t- C:\WINDOWS\system32\DRWEBSP.DLL
2007-12-09 21:29 . 2007-12-10 16:30 d——– C:\Program Files\DrWeb
2007-12-09 21:28 . 2007-12-09 21:28 d——– C:\Documents and Settings\Kampfzentrum\Application Data\InstallShield
2007-12-09 20:38 . 2007-12-09 20:38 d——– C:\Program Files\ATF Cleaner
2007-12-09 19:32 . 2007-12-09 19:32 426 –a—— C:\WINDOWS\system32\temp.dat
2007-12-09 19:18 . 2007-12-09 19:18 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-09 18:30 . 2007-05-30 06:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-12-09 17:57 . 2007-12-09 19:16 d——– C:\Program Files\Spybot
2007-12-09 17:57 . 2007-12-09 19:16 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-09 17:34 . 2007-12-09 19:18 d——– C:\Documents and Settings\Kampfzentrum\Application Data\AdwareAlert
2007-12-09 16:05 . 2000-02-22 21:38 206,272 –a—— C:\WINDOWS\system32\drivers\udfreadr.BAK
2007-12-09 15:57 . 2002-02-22 18:02 206,208 –a—— C:\WINDOWS\system32\drivers\udfreadr.sys
2007-12-09 15:57 . 2002-02-22 18:10 90,112 –a—— C:\WINDOWS\system32\udfrunin.exe
2007-12-09 07:13 . 2007-09-06 05:09 801,144 –a—— C:\WINDOWS\system32\aswBoot.exe
2007-12-09 07:13 . 2004-01-09 04:13 380,928 –a—— C:\WINDOWS\system32\actskin4.ocx
2007-12-09 07:13 . 2007-09-06 05:00 95,608 –a—— C:\WINDOWS\system32\AvastSS.scr
2007-12-09 07:13 . 2007-09-06 05:05 94,416 –a—— C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-09 07:13 . 2007-09-06 05:05 92,848 –a—— C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-09 07:13 . 2007-09-06 05:02 42,912 –a—— C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-09 07:13 . 2007-09-06 05:00 26,624 –a—— C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-09 07:13 . 2007-09-06 05:03 23,152 –a—— C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-09 07:12 . 2007-12-09 07:12 d——– C:\Program Files\Alwil Software
2007-12-08 22:52 . 2007-12-09 18:42 108,336 –a—— C:\WINDOWS\mswinsck.ocx
2007-12-08 22:34 . 2007-12-08 22:34 d–h—– C:\Program Files\WinfiX
2007-12-08 20:25 . 2007-12-08 20:25 80,448 –a—— C:\WINDOWS\system32\dmsfwfmj.#ll
2007-12-08 19:34 . 2007-12-08 19:34 98,304 –a—— C:\WINDOWS\system32\CmdLineExt.dll
2007-12-08 19:32 . 2007-12-08 19:32 d——– C:\WINDOWS\system32\ageia
2007-12-08 19:32 . 2007-12-08 19:32 d——– C:\Program Files\AGEIA Technologies
2007-12-08 16:47 . 2007-04-04 18:53 81,768 –a—— C:\WINDOWS\system32\xinput1_3.dll
2007-12-08 16:25 . 2007-12-08 16:25 35,840 –a—— C:\WINDOWS\system32\byxvvut.#ll
2007-12-08 14:48 . 2007-12-08 14:48 d——– C:\Documents and Settings\Kampfzentrum\Application Data\KALiNKOsoft
2007-12-08 14:48 . 2007-12-08 14:48 36,864 –a—— C:\WINDOWS\system32\dxinputdll.dll
2007-12-04 18:26 . 2007-12-04 18:27 d——– C:\Documents and Settings\All Users\Application Data\GlobalSCAPE
2007-12-04 18:25 . 2007-12-04 18:25 d——– C:\Documents and Settings\Kampfzentrum\Application Data\GlobalSCAPE
2007-12-03 21:27 . 2007-12-03 21:27 d——– C:\Program Files\LSoft Technologies
2007-12-01 13:58 . 2007-12-01 13:59 d——– C:\Program Files\FPXpress
2007-12-01 13:21 . 2004-11-22 20:56 913,560 –a—— C:\WINDOWS\system32\wodFtpDLX.ocx
2007-12-01 13:21 . 2007-12-05 10:44 13 –a—— C:\WINDOWS\system32\WinSys32.crc
2007-12-01 13:20 . 2007-12-09 08:09 d——– C:\Program Files\CoffeeCup Software
2007-12-01 13:20 . 1999-03-22 12:29 233,472 –a—— C:\WINDOWS\system32\Ilda32.dll
2007-12-01 13:20 . 1998-06-17 04:00 18,944 –a—— C:\WINDOWS\system32\BORLNDMM.DLL
2007-12-01 12:44 . 2007-12-01 12:44 149,916 –a—— C:\tmp.exe
2007-12-01 07:42 . 2007-12-01 07:42 d——– C:\Program Files\AceBIT
2007-12-01 07:42 . 2003-08-29 16:36 1,079,808 –a—— C:\WINDOWS\system32\we.dll
2007-12-01 07:42 . 2003-07-22 03:40 430,080 –a—— C:\WINDOWS\system32\wodSFTP.ocx
2007-12-01 07:42 . 2003-07-22 03:38 425,984 –a—— C:\WINDOWS\system32\wodKeys.dll
2007-12-01 07:42 . 2003-07-22 03:37 385,024 –a—— C:\WINDOWS\system32\wodSFTP.dll
2007-12-01 06:22 . 2007-12-09 20:10 d——– C:\Program Files\Spyware Doctor
2007-12-01 06:22 . 2007-12-01 06:22 d——– C:\Documents and Settings\Kampfzentrum\Application Data\PC Tools
2007-12-01 06:22 . 2007-10-18 00:16 79,688 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2007-12-01 06:22 . 2007-10-18 00:15 62,280 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2007-12-01 06:22 . 2007-10-18 00:14 41,288 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-12-01 06:22 . 2007-10-18 00:16 29,000 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2007-12-01 06:20 . 2005-09-23 08:29 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-11-29 17:15 . 2007-11-29 17:15 d——– C:\Program Files\PremiumSoft
2007-11-28 20:18 . 2007-11-28 20:22 d——– C:\Program Files\wamp
2007-11-28 15:59 . 2007-12-09 10:24 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2007-11-28 15:59 . 2007-11-28 15:59 1,409 –a—— C:\WINDOWS\QTFont.for
2007-11-28 15:58 . 2007-11-28 15:59 d——– C:\Program Files\iTunes
2007-11-28 15:58 . 2007-11-28 15:58 d——– C:\Program Files\iPod
2007-11-27 21:39 . 2007-11-28 21:57 d——– C:\Program Files\phpDesigner 2008
2007-11-27 21:39 . 2007-11-28 21:57 d——– C:\Documents and Settings\Kampfzentrum\Application Data\phpDesigner 2008
2007-11-27 21:29 . 2007-11-27 21:29 d——– C:\Program Files\7-Zip
2007-11-27 21:09 . 2007-11-27 21:09 d——– C:\Program Files\Windows Script Control
2007-11-27 21:09 . 2007-11-27 21:09 d——– C:\Program Files\Common Files\e.World
2007-11-27 21:09 . 2007-11-27 21:09 0 –a—— C:\WINDOWS\system32\UNWISE.INI
2007-11-27 21:08 . 2007-11-27 21:09 d——– C:\Program Files\PHPMaker 5
2007-11-27 21:08 . 2002-07-26 17:02 153,088 –a—— C:\WINDOWS\system32\UNWISE.EXE
2007-11-24 16:08 . 2007-11-24 16:09 d——– C:\Program Files\CrystalButton2
2007-11-22 22:32 . 2007-12-08 19:21 d——– C:\Program Files\Ubisoft
2007-11-18 13:05 . 2007-11-18 13:05 150,643 –ah—– C:\_crash.dmp
2007-11-18 13:05 . 2007-11-18 13:05 58,902 –ah—– C:\report.zip
2007-11-14 23:43 . 2007-11-14 23:43 65,536 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2007-11-14 23:43 . 2007-11-14 23:43 49,152 –a—— C:\WINDOWS\system32\QuickTime.qts

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-10 03:29 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-10 01:16 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\Azureus
2007-12-09 14:39 ——— d—–w C:\Program Files\Babylon
2007-12-09 04:19 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\Vso
2007-12-08 21:17 ——— d—–w C:\Program Files\Azureus
2007-11-28 21:57 ——— d—–w C:\Program Files\QuickTime
2007-11-26 02:17 ——— d—–w C:\Program Files\Soulseek
2007-11-24 03:35 22,328 —-a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-11-23 04:32 ——— d—–w C:\Program Files\Common Files\InstallShield
2007-11-17 22:21 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\BitTorrent
2007-11-13 23:05 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-11-04 15:03 ——— d—–w C:\Program Files\AIM
2007-11-04 15:02 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\Aim
2007-11-04 13:03 ——— d—–w C:\Program Files\Common Files\Apple
2007-11-04 13:03 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple
2007-10-28 21:28 ——— d—–w C:\Program Files\WorkTime
2007-10-27 21:23 22,746,840 —-a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_10_27_16_22_24_full.dmp.zip
2007-10-26 03:02 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\Babylon
2007-10-26 02:33 ——— d—–w C:\Documents and Settings\All Users\Application Data\Babylon
2007-10-25 02:46 ——— d—–w C:\Program Files\Text to Speech Maker
2007-10-25 02:35 ——— d—–w C:\Program Files\NCT
2007-10-25 02:11 ——— d—–w C:\Program Files\GameSpy Arcade
2007-10-25 01:23 ——— d—–w C:\Program Files\VirtualDJ
2007-10-25 01:21 ——— d—–w C:\Program Files\RegHealer
2007-10-20 12:15 ——— d—–w C:\Program Files\Magic Video Converter
2007-10-14 13:25 ——— d—–w C:\Program Files\Xilisoft
2007-10-14 13:05 ——— d—–w C:\Program Files\FileSee
2007-10-14 01:20 ——— d—–w C:\Documents and Settings\All Users\Application Data\SongbirdVLC
2007-10-14 01:18 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\Songbird
2007-10-13 21:15 ——— d—–w C:\Program Files\Soulseek-Test
2007-02-05 13:56 87,608 —-a-w C:\Documents and Settings\Kampfzentrum\Application Data\ezpinst.exe
2007-02-05 13:56 47,360 —-a-w C:\Documents and Settings\Kampfzentrum\Application Data\pcouffin.sys
2007-06-13 11:26 1,397,760 –sha-r C:\WINDOWS\system32\System32i.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{f7486279-8be6-4505-8f3c-b26c2cd92eee}]
C:\WINDOWS\system32\dmsfwfmj.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AutoCAD Digital Signatures Icon Overlay Handler]
@={36A21736-36C2-4C11-8ACB-D4136F2B57BD}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 1 (GFS Unread Stub)]
@={99FD978C-D287-4F50-827F-B2C658EDA8E7}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 2 (GFS Stub)]
@={AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)]
@={920E6DB1-9907-4370-B3A0-BAFC03D81399}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 3 (GFS Folder)]
@={16F3DD56-1AF5-4347-846D-7C10C4192619}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 4 (GFS Unread Mark)]
@={2916C86E-86A6-43FE-8112-43ABE6BF8DCC}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Offline Files]

[HKEY_CLASSES_ROOT\CLSID\{36A21736-36C2-4C11-8ACB-D4136F2B57BD}]
2006-03-04 23:55 185448 –a—— C:\WINDOWS\system32\AcSignIcon.dll

[HKEY_CLASSES_ROOT\CLSID\{99FD978C-D287-4F50-827F-B2C658EDA8E7}]
2006-10-27 02:48 2210608 –a—— C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL

[HKEY_CLASSES_ROOT\CLSID\{AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}]
2006-10-27 02:48 2210608 –a—— C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL

[HKEY_CLASSES_ROOT\CLSID\{920E6DB1-9907-4370-B3A0-BAFC03D81399}]
2006-10-27 02:48 2210608 –a—— C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL

[HKEY_CLASSES_ROOT\CLSID\{16F3DD56-1AF5-4347-846D-7C10C4192619}]
2006-10-27 02:48 2210608 –a—— C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL

[HKEY_CLASSES_ROOT\CLSID\{2916C86E-86A6-43FE-8112-43ABE6BF8DCC}]
2006-10-27 02:48 2210608 –a—— C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 16:56]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSUpdater"="System32i.exe" [2007-06-13 05:26 C:\WINDOWS\system32\System32i.exe]
"exflashservice"="C:\Program Files\EPOX\EFS\EZ_FLASH_SERVICE.exe" [2006-05-02 03:26]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-09-25 11:12]
"SoundMan"="SOUNDMAN.EXE" [2006-03-01 02:22 C:\WINDOWS\soundman.exe]
"ManualRun"="D:\AUTORUN\AutoRun" []
"BtcMouseMaestro"="C:\Program Files\MMaestro\KMaestro.exe" [2005-11-09 03:18]
"CoolSwitch"="C:\WINDOWS\system32\taskswitch.exe" [2002-03-19 19:30]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"GoogleUpdate"="C:\Program Files\Internet Explorer\Down(0).EXE" [2007-11-22 08:55]
"Wise-FTP Scheduler"="" []
"Service32"="C:\WINDOWS\system32\schost.exe" []
"AGEIA PhysX SysTray"="C:\Program Files\AGEIA Technologies\TrayIcon.exe" [2006-03-20 13:43]
"SpIDerNT"="C:\PROGRA~1\DrWeb\spiderui.exe" [2007-10-01 16:17]
"DrWebScheduler"="C:\Program Files\DrWeb\DRWEBSCD.EXE" [2007-09-19 16:04]
"SpIDerMail"="C:\Program Files\DrWeb\spiderml.exe" [2007-11-26 18:21]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"MSUpdater"="System32i.exe" [2007-06-13 05:26 C:\WINDOWS\system32\System32i.exe]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Logitech Profiler.lnk - C:\Program Files\Logitech\Profiler\LWEmon.exe [2007-08-26 17:34:21]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\byxvvut]
byxvvut.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=C:\WINDOWS\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoCAD Startup Accelerator.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoCAD Startup Accelerator.lnk
backup=C:\WINDOWS\pss\AutoCAD Startup Accelerator.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
2006-01-12 20:52 483328 –a—— C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2007-05-11 02:06 40048 –a—— C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
2007-09-06 05:06 79224 –a—— C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Babylon Client]
C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
C:\Program Files\BitTorrent\bittorrent.exe –force_start_minimized

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CrawlerNotes]
c:\progra~1\crawler\notes\cnotes.exe /notes

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EA Core]
C:\Program Files\Electronic Arts\EA Link\Core.exe -silent

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2006-10-27 02:47 31016 –a—— C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2007-11-15 13:11 267048 –a—— C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nod32kui]
C:\Program Files\Eset\nod32kui.exe /WAITSERVICE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pinnacle Game Profiler]
C:\Program Files\KALiNKOsoft\Pinnacle Game Profiler\pinnacle.exe -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SDTray]
2007-11-02 17:24 1065800 –a—— C:\Program Files\Spyware Doctor\SDTrayApp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wise-FTP Scheduler]
2003-08-29 16:35 1246720 –a—— C:\Program Files\AceBIT\WISE-FTP\WF_Scheduler.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe -quiet

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZoneAlarm Client]
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

R1 UdfReadr;UdfReadr;C:\WINDOWS\system32\drivers\UdfReadr.sys
R2 AdobeActiveFileMonitor;Adobe Active File Monitor;C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
R2 SPIDER;SpIDer Guard File System Monitor;\??\C:\PROGRA~1\DrWeb\spider.sys
R2 SPIDERNT;SpIDer Guard for Windows;C:\PROGRA~1\DrWeb\spidernt.exe
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver;C:\WINDOWS\system32\drivers\WmBEnum.sys
R3 WmFilter;Logitech WingMan HID Filter Driver;C:\WINDOWS\system32\drivers\WmFilter.sys
R3 WmVirHid;Logitech Virtual Hid Device Driver;C:\WINDOWS\system32\drivers\WmVirHid.sys
R3 WmXlCore;Logitech WingMan Translation Layer Driver;C:\WINDOWS\system32\drivers\WmXlCore.sys
S2 NetworkConnections;NetmanConnections;C:\WINDOWS\system32\wonlog.ini
S3 Hpzodisft_;Hpzodisft_;C:\WINDOWS\system32\bootok.exe
S3 StMp3Rec;Player Recovery Device Control Driver;C:\WINDOWS\system32\Drivers\StMp3Rec.sys
S3 wampapache;wampapache;"C:\Program Files\wamp\bin\apache\apache2.2.6\bin\httpd.exe" -k runservice
S3 wampmysqld;wampmysqld;"C:\Program Files\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe" wampmysqld

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
aeyfoc REG_MULTI_SZ aeyfoc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fe1dd150-ed26-11db-8902-001a703119a4}]
\Shell\AutoRun\command - G:\setupSNK.exe


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{1D072F95-FA9D-5367-BDD9-91013F603BE4}]
C:\Program Files\WinfiX\server.exe s

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CAC7B150-B41B-B8F0-F160-F2F006DD303D}]
C:\WINDOWS\msmg.exe
.
Contents of the 'Scheduled Tasks' folder
"2007-12-10 09:00:00 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job"
- C:\Program Files\AdwareAlert\AdwareAlert.ex
- C:\Program Files\AdwareAlert
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\DOCUME~1\KAMPFZ~1\LOCALS~1\Temp\ppeulkwv.dll
.
**************************************************************************

catchme 0.3.1331 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-10 16:37:37
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
GoogleUpdate = C:\Program Files\Internet Explorer\Down(0).EXE??l???????????????????G?o?o?g?l?e?U?p?d?a?t?e?????r???????????????????????e???????????????????????r

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-10 16:39:40 - machine was rebooted
.
— E O F —
While I'm looking through th escan. please do this:

Please go to http://virusscan.jotti.org , click on Browse, and upload the following file for analysis:

C:\WINDOWS\system32\System32i.exe

Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.


If Jotti is too busy you can try these.

http://www.kaspersky.com/scanforvirus.html


http://www.virustotal.com/en/indexf.html
Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\dmsfwfmj.#ll
C:\WINDOWS\system32\byxvvut.#ll
C:\WINDOWS\system32\System32i.exe
C:\WINDOWS\system32\schost.exe

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{f7486279-8be6-4505-8f3c-b26c2cd92eee}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSUpdater"=-
"ManualRun"=-
"Service32"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"MSUpdater"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\byxvvut]


Save this as Save this as "CFScript"


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
Alright, here is what Jotti found. It appears the file is seriously corrupted:

A-Squared Found nothing
AntiVir Found BDS/Ciadoor.GN.614
ArcaVir Found Trojan.Ciadoor.Gn
Avast Found nothing
AVG Antivirus Found BackDoor.Generic9.DYV
BitDefender Found DeepScan:Generic.Malware.G!SKI!!FLMPWBVPkprng.A4673D80
ClamAV Found PUA.Packed.Themida
CPsecure Found BackDoor.W32.Ciadoor.gn
Dr.Web Found nothing
F-Prot Antivirus Found Possibly a new variant of W32/NewMalware-Mr-T-Inspector!Maximus
F-Secure Anti-Virus Found Backdoor.Win32.Ciadoor.gn
Fortinet Found W32/Ciadoor.GN!tr.bdr
Ikarus Found MemScanBackdoor.VB.EV
Kaspersky Anti-Virus Found Backdoor.Win32.Ciadoor.gn
NOD32 Found nothing
Norman Virus Control Found Banker.gen4
Panda Antivirus Found nothing
Rising Antivirus Found nothing
Sophos Antivirus Found nothing
VirusBuster Found nothing
VBA32 Found nothing

OK, here is ComboFix Report:

ComboFix 07-12-09.1 - Kampfzentrum 2007-12-10 17:46:42.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1440 [GMT -6:00]
Running from: F:\ComboFix.exe
Command switches used :: F:\CFScript.txt
* Created a new restore point

FILE
C:\WINDOWS\system32\byxvvut.#ll
C:\WINDOWS\system32\dmsfwfmj.#ll
C:\WINDOWS\system32\schost.exe
C:\WINDOWS\system32\System32i.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\byxvvut.#ll
C:\WINDOWS\system32\dmsfwfmj.#ll
C:\WINDOWS\system32\System32i.exe

.
((((((((((((((((((((((((( Files Created from 2007-11-10 to 2007-12-10 )))))))))))))))))))))))))))))))
.

2007-12-10 05:16 . 2007-12-10 05:16 d——– C:\Program Files\PM Studios
2007-12-09 21:30 . 2007-12-09 21:44 d——– C:\Documents and Settings\Kampfzentrum\DoctorWeb
2007-12-09 21:30 . 2007-12-09 21:31 77,824 –a—-t- C:\WINDOWS\system32\DRWEBSP.DLL
2007-12-09 21:29 . 2007-12-10 16:30 d——– C:\Program Files\DrWeb
2007-12-09 21:28 . 2007-12-09 21:28 d——– C:\Documents and Settings\Kampfzentrum\Application Data\InstallShield
2007-12-09 20:38 . 2007-12-09 20:38 d——– C:\Program Files\ATF Cleaner
2007-12-09 19:32 . 2007-12-09 19:32 426 –a—— C:\WINDOWS\system32\temp.dat
2007-12-09 19:18 . 2007-12-09 19:18 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-09 18:30 . 2007-05-30 06:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-12-09 17:57 . 2007-12-09 19:16 d——– C:\Program Files\Spybot
2007-12-09 17:57 . 2007-12-09 19:16 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-09 17:34 . 2007-12-09 19:18 d——– C:\Documents and Settings\Kampfzentrum\Application Data\AdwareAlert
2007-12-09 16:05 . 2000-02-22 21:38 206,272 –a—— C:\WINDOWS\system32\drivers\udfreadr.BAK
2007-12-09 15:57 . 2002-02-22 18:02 206,208 –a—— C:\WINDOWS\system32\drivers\udfreadr.sys
2007-12-09 15:57 . 2002-02-22 18:10 90,112 –a—— C:\WINDOWS\system32\udfrunin.exe
2007-12-09 07:13 . 2007-09-06 05:09 801,144 –a—— C:\WINDOWS\system32\aswBoot.exe
2007-12-09 07:13 . 2004-01-09 04:13 380,928 –a—— C:\WINDOWS\system32\actskin4.ocx
2007-12-09 07:13 . 2007-09-06 05:00 95,608 –a—— C:\WINDOWS\system32\AvastSS.scr
2007-12-09 07:13 . 2007-09-06 05:05 94,416 –a—— C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-09 07:13 . 2007-09-06 05:05 92,848 –a—— C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-09 07:13 . 2007-09-06 05:02 42,912 –a—— C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-09 07:13 . 2007-09-06 05:00 26,624 –a—— C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-09 07:13 . 2007-09-06 05:03 23,152 –a—— C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-09 07:12 . 2007-12-09 07:12 d——– C:\Program Files\Alwil Software
2007-12-08 22:52 . 2007-12-09 18:42 108,336 –a—— C:\WINDOWS\mswinsck.ocx
2007-12-08 22:34 . 2007-12-08 22:34 d–h—– C:\Program Files\WinfiX
2007-12-08 19:34 . 2007-12-08 19:34 98,304 –a—— C:\WINDOWS\system32\CmdLineExt.dll
2007-12-08 19:32 . 2007-12-08 19:32 d——– C:\WINDOWS\system32\ageia
2007-12-08 19:32 . 2007-12-08 19:32 d——– C:\Program Files\AGEIA Technologies
2007-12-08 16:47 . 2007-04-04 18:53 81,768 –a—— C:\WINDOWS\system32\xinput1_3.dll
2007-12-08 14:48 . 2007-12-08 14:48 d——– C:\Documents and Settings\Kampfzentrum\Application Data\KALiNKOsoft
2007-12-08 14:48 . 2007-12-08 14:48 36,864 –a—— C:\WINDOWS\system32\dxinputdll.dll
2007-12-04 18:26 . 2007-12-04 18:27 d——– C:\Documents and Settings\All Users\Application Data\GlobalSCAPE
2007-12-04 18:25 . 2007-12-04 18:25 d——– C:\Documents and Settings\Kampfzentrum\Application Data\GlobalSCAPE
2007-12-03 21:27 . 2007-12-03 21:27 d——– C:\Program Files\LSoft Technologies
2007-12-01 13:58 . 2007-12-01 13:59 d——– C:\Program Files\FPXpress
2007-12-01 13:21 . 2004-11-22 20:56 913,560 –a—— C:\WINDOWS\system32\wodFtpDLX.ocx
2007-12-01 13:21 . 2007-12-05 10:44 13 –a—— C:\WINDOWS\system32\WinSys32.crc
2007-12-01 13:20 . 2007-12-09 08:09 d——– C:\Program Files\CoffeeCup Software
2007-12-01 13:20 . 1999-03-22 12:29 233,472 –a—— C:\WINDOWS\system32\Ilda32.dll
2007-12-01 13:20 . 1998-06-17 04:00 18,944 –a—— C:\WINDOWS\system32\BORLNDMM.DLL
2007-12-01 12:44 . 2007-12-01 12:44 149,916 –a—— C:\tmp.exe
2007-12-01 07:42 . 2007-12-01 07:42 d——– C:\Program Files\AceBIT
2007-12-01 07:42 . 2003-08-29 16:36 1,079,808 –a—— C:\WINDOWS\system32\we.dll
2007-12-01 07:42 . 2003-07-22 03:40 430,080 –a—— C:\WINDOWS\system32\wodSFTP.ocx
2007-12-01 07:42 . 2003-07-22 03:38 425,984 –a—— C:\WINDOWS\system32\wodKeys.dll
2007-12-01 07:42 . 2003-07-22 03:37 385,024 –a—— C:\WINDOWS\system32\wodSFTP.dll
2007-12-01 06:22 . 2007-12-09 20:10 d——– C:\Program Files\Spyware Doctor
2007-12-01 06:22 . 2007-12-01 06:22 d——– C:\Documents and Settings\Kampfzentrum\Application Data\PC Tools
2007-12-01 06:22 . 2007-10-18 00:16 79,688 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2007-12-01 06:22 . 2007-10-18 00:15 62,280 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2007-12-01 06:22 . 2007-10-18 00:14 41,288 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-12-01 06:22 . 2007-10-18 00:16 29,000 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2007-12-01 06:20 . 2005-09-23 08:29 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-11-29 17:15 . 2007-11-29 17:15 d——– C:\Program Files\PremiumSoft
2007-11-28 20:18 . 2007-11-28 20:22 d——– C:\Program Files\wamp
2007-11-28 15:59 . 2007-12-09 10:24 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2007-11-28 15:59 . 2007-11-28 15:59 1,409 –a—— C:\WINDOWS\QTFont.for
2007-11-28 15:58 . 2007-11-28 15:59 d——– C:\Program Files\iTunes
2007-11-28 15:58 . 2007-11-28 15:58 d——– C:\Program Files\iPod
2007-11-27 21:39 . 2007-11-28 21:57 d——– C:\Program Files\phpDesigner 2008
2007-11-27 21:39 . 2007-11-28 21:57 d——– C:\Documents and Settings\Kampfzentrum\Application Data\phpDesigner 2008
2007-11-27 21:29 . 2007-11-27 21:29 d——– C:\Program Files\7-Zip
2007-11-27 21:09 . 2007-11-27 21:09 d——– C:\Program Files\Windows Script Control
2007-11-27 21:09 . 2007-11-27 21:09 d——– C:\Program Files\Common Files\e.World
2007-11-27 21:09 . 2007-11-27 21:09 0 –a—— C:\WINDOWS\system32\UNWISE.INI
2007-11-27 21:08 . 2007-11-27 21:09 d——– C:\Program Files\PHPMaker 5
2007-11-27 21:08 . 2002-07-26 17:02 153,088 –a—— C:\WINDOWS\system32\UNWISE.EXE
2007-11-24 16:08 . 2007-11-24 16:09 d——– C:\Program Files\CrystalButton2
2007-11-22 22:32 . 2007-12-08 19:21 d——– C:\Program Files\Ubisoft
2007-11-18 13:05 . 2007-11-18 13:05 150,643 –ah—– C:\_crash.dmp
2007-11-18 13:05 . 2007-11-18 13:05 58,902 –ah—– C:\report.zip
2007-11-14 23:43 . 2007-11-14 23:43 65,536 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2007-11-14 23:43 . 2007-11-14 23:43 49,152 –a—— C:\WINDOWS\system32\QuickTime.qts

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-10 03:29 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-10 01:16 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\Azureus
2007-12-09 14:39 ——— d—–w C:\Program Files\Babylon
2007-12-09 04:19 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\Vso
2007-12-08 21:17 ——— d—–w C:\Program Files\Azureus
2007-11-28 21:57 ——— d—–w C:\Program Files\QuickTime
2007-11-26 02:17 ——— d—–w C:\Program Files\Soulseek
2007-11-24 03:35 22,328 —-a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-11-24 03:33 107,832 —-a-w C:\WINDOWS\system32\PnkBstrB.exe
2007-11-23 04:32 ——— d—–w C:\Program Files\Common Files\InstallShield
2007-11-17 22:21 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\BitTorrent
2007-11-13 23:05 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-11-04 15:03 ——— d—–w C:\Program Files\AIM
2007-11-04 15:02 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\Aim
2007-11-04 13:03 ——— d—–w C:\Program Files\Common Files\Apple
2007-11-04 13:03 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple
2007-10-29 00:03 172,032 —-a-w C:\WINDOWS\system32\Down(0).exe
2007-10-28 21:28 ——— d—–w C:\Program Files\WorkTime
2007-10-27 21:23 22,746,840 —-a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_10_27_16_22_24_full.dmp.zip
2007-10-26 03:02 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\Babylon
2007-10-26 02:33 ——— d—–w C:\Documents and Settings\All Users\Application Data\Babylon
2007-10-25 02:46 ——— d—–w C:\Program Files\Text to Speech Maker
2007-10-25 02:35 ——— d—–w C:\Program Files\NCT
2007-10-25 02:11 ——— d—–w C:\Program Files\GameSpy Arcade
2007-10-25 01:23 ——— d—–w C:\Program Files\VirtualDJ
2007-10-25 01:21 ——— d—–w C:\Program Files\RegHealer
2007-10-20 12:15 ——— d—–w C:\Program Files\Magic Video Converter
2007-10-14 13:25 ——— d—–w C:\Program Files\Xilisoft
2007-10-14 13:05 ——— d—–w C:\Program Files\FileSee
2007-10-14 01:20 ——— d—–w C:\Documents and Settings\All Users\Application Data\SongbirdVLC
2007-10-14 01:18 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\Songbird
2007-10-13 21:15 ——— d—–w C:\Program Files\Soulseek-Test
2007-02-05 13:56 87,608 —-a-w C:\Documents and Settings\Kampfzentrum\Application Data\ezpinst.exe
2007-02-05 13:56 47,360 —-a-w C:\Documents and Settings\Kampfzentrum\Application Data\pcouffin.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{f7486279-8be6-4505-8f3c-b26c2cd92eee}]
C:\WINDOWS\system32\dmsfwfmj.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AutoCAD Digital Signatures Icon Overlay Handler]
@={36A21736-36C2-4C11-8ACB-D4136F2B57BD}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 1 (GFS Unread Stub)]
@={99FD978C-D287-4F50-827F-B2C658EDA8E7}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 2 (GFS Stub)]
@={AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)]
@={920E6DB1-9907-4370-B3A0-BAFC03D81399}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 3 (GFS Folder)]
@={16F3DD56-1AF5-4347-846D-7C10C4192619}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 4 (GFS Unread Mark)]
@={2916C86E-86A6-43FE-8112-43ABE6BF8DCC}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Offline Files]

[HKEY_CLASSES_ROOT\CLSID\{36A21736-36C2-4C11-8ACB-D4136F2B57BD}]
2006-03-04 23:55 185448 –a—— C:\WINDOWS\system32\AcSignIcon.dll

[HKEY_CLASSES_ROOT\CLSID\{99FD978C-D287-4F50-827F-B2C658EDA8E7}]
2006-10-27 02:48 2210608 –a—— C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL

[HKEY_CLASSES_ROOT\CLSID\{AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}]
2006-10-27 02:48 2210608 –a—— C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL

[HKEY_CLASSES_ROOT\CLSID\{920E6DB1-9907-4370-B3A0-BAFC03D81399}]
2006-10-27 02:48 2210608 –a—— C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL

[HKEY_CLASSES_ROOT\CLSID\{16F3DD56-1AF5-4347-846D-7C10C4192619}]
2006-10-27 02:48 2210608 –a—— C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL

[HKEY_CLASSES_ROOT\CLSID\{2916C86E-86A6-43FE-8112-43ABE6BF8DCC}]
2006-10-27 02:48 2210608 –a—— C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 16:56]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSUpdater"="System32i.exe" []
"exflashservice"="C:\Program Files\EPOX\EFS\EZ_FLASH_SERVICE.exe" [2006-05-02 03:26]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-09-25 11:12]
"SoundMan"="SOUNDMAN.EXE" [2006-03-01 02:22 C:\WINDOWS\soundman.exe]
"ManualRun"="D:\AUTORUN\AutoRun" []
"BtcMouseMaestro"="C:\Program Files\MMaestro\KMaestro.exe" [2005-11-09 03:18]
"CoolSwitch"="C:\WINDOWS\system32\taskswitch.exe" [2002-03-19 19:30]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"GoogleUpdate"="C:\Program Files\Internet Explorer\Down(0).EXE" [2007-11-22 08:55]
"Wise-FTP Scheduler"="" []
"Service32"="C:\WINDOWS\system32\schost.exe" []
"AGEIA PhysX SysTray"="C:\Program Files\AGEIA Technologies\TrayIcon.exe" [2006-03-20 13:43]
"SpIDerNT"="C:\PROGRA~1\DrWeb\spiderui.exe" [2007-10-01 16:17]
"DrWebScheduler"="C:\Program Files\DrWeb\DRWEBSCD.EXE" [2007-09-19 16:04]
"SpIDerMail"="C:\Program Files\DrWeb\spiderml.exe" [2007-11-26 18:21]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"MSUpdater"="System32i.exe" []

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Logitech Profiler.lnk - C:\Program Files\Logitech\Profiler\LWEmon.exe [2007-08-26 17:34:21]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\byxvvut]
byxvvut.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=C:\WINDOWS\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoCAD Startup Accelerator.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoCAD Startup Accelerator.lnk
backup=C:\WINDOWS\pss\AutoCAD Startup Accelerator.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
2006-01-12 20:52 483328 –a—— C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2007-05-11 02:06 40048 –a—— C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
2007-09-06 05:06 79224 –a—— C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Babylon Client]
C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
C:\Program Files\BitTorrent\bittorrent.exe –force_start_minimized

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CrawlerNotes]
c:\progra~1\crawler\notes\cnotes.exe /notes

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EA Core]
C:\Program Files\Electronic Arts\EA Link\Core.exe -silent

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2006-10-27 02:47 31016 –a—— C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2007-11-15 13:11 267048 –a—— C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nod32kui]
C:\Program Files\Eset\nod32kui.exe /WAITSERVICE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pinnacle Game Profiler]
C:\Program Files\KALiNKOsoft\Pinnacle Game Profiler\pinnacle.exe -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SDTray]
2007-11-02 17:24 1065800 –a—— C:\Program Files\Spyware Doctor\SDTrayApp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wise-FTP Scheduler]
2003-08-29 16:35 1246720 –a—— C:\Program Files\AceBIT\WISE-FTP\WF_Scheduler.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe -quiet

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZoneAlarm Client]
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

R1 UdfReadr;UdfReadr;C:\WINDOWS\system32\drivers\UdfReadr.sys
R2 AdobeActiveFileMonitor;Adobe Active File Monitor;C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
R2 SPIDER;SpIDer Guard File System Monitor;\??\C:\PROGRA~1\DrWeb\spider.sys
R2 SPIDERNT;SpIDer Guard for Windows;C:\PROGRA~1\DrWeb\spidernt.exe
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver;C:\WINDOWS\system32\drivers\WmBEnum.sys
R3 WmFilter;Logitech WingMan HID Filter Driver;C:\WINDOWS\system32\drivers\WmFilter.sys
R3 WmVirHid;Logitech Virtual Hid Device Driver;C:\WINDOWS\system32\drivers\WmVirHid.sys
R3 WmXlCore;Logitech WingMan Translation Layer Driver;C:\WINDOWS\system32\drivers\WmXlCore.sys
S2 NetworkConnections;NetmanConnections;C:\WINDOWS\system32\wonlog.ini
S3 Hpzodisft_;Hpzodisft_;C:\WINDOWS\system32\bootok.exe
S3 StMp3Rec;Player Recovery Device Control Driver;C:\WINDOWS\system32\Drivers\StMp3Rec.sys
S3 wampapache;wampapache;"C:\Program Files\wamp\bin\apache\apache2.2.6\bin\httpd.exe" -k runservice
S3 wampmysqld;wampmysqld;"C:\Program Files\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe" wampmysqld

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
aeyfoc REG_MULTI_SZ aeyfoc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e7bbac42-b3cf-11db-8b54-806d6172696f}]
\Shell\AutoRun\command - D:\Autorun\UbiAutorun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fe1dd150-ed26-11db-8902-001a703119a4}]
\Shell\AutoRun\command - G:\setupSNK.exe


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{1D072F95-FA9D-5367-BDD9-91013F603BE4}]
C:\Program Files\WinfiX\server.exe s

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CAC7B150-B41B-B8F0-F160-F2F006DD303D}]
C:\WINDOWS\msmg.exe
.
Contents of the 'Scheduled Tasks' folder
"2007-12-10 09:00:00 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job"
- C:\Program Files\AdwareAlert\AdwareAlert.ex
- C:\Program Files\AdwareAlert
.
**************************************************************************

catchme 0.3.1331 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-10 17:49:03
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
GoogleUpdate = C:\Program Files\Internet Explorer\Down(0).EXE??l???????????????????G?o?o?g?l?e?U?p?d?a?t?e?????r???????????????????????e???????????????????????r

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-10 17:50:09
C:\ComboFix2.txt … 2007-12-10 16:39
.
— E O F —

And - in final - here is the HiJackThis log:

Logfile of HijackThis v1.99.1
Scan saved at 5:51:40 PM, on 12/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Internet Explorer\IExPlOrE.ExE
C:\WINDOWS\system32\PnkBstrA.exe
C:\PROGRA~1\DrWeb\spidernt.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\MMaestro\KMaestro.exe
C:\WINDOWS\system32\taskswitch.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Internet Explorer\Down(0).EXE
C:\Program Files\AGEIA Technologies\TrayIcon.exe
C:\PROGRA~1\DrWeb\spiderui.exe
C:\Program Files\DrWeb\spiderml.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\Profiler\LWEmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wi-compact.com/Forum/index.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [exflashservice] "C:\Program Files\EPOX\EFS\EZ_FLASH_SERVICE.exe" "5000"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [BtcMouseMaestro] "C:\Program Files\MMaestro\KMaestro.exe"
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [GoogleUpdate] C:\Program Files\Internet Explorer\Down(0).EXE
O4 - HKLM\..\Run: [AGEIA PhysX SysTray] C:\Program Files\AGEIA Technologies\TrayIcon.exe
O4 - HKLM\..\Run: [SpIDerNT] C:\PROGRA~1\DrWeb\spiderui.exe /agent
O4 - HKLM\..\Run: [DrWebScheduler] "C:\Program Files\DrWeb\DRWEBSCD.EXE"
O4 - HKLM\..\Run: [SpIDerMail] "C:\Program Files\DrWeb\spiderml.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Logitech Profiler.lnk = ?
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\drwebsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\drwebsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\drwebsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\drwebsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\drwebsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\drwebsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} (CoGSManager Class) - http://gamingzone.ubisoft.com/dev/packages/GSManager.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3EC5C936-3D16-4D21-BA21-7C5E6424AF3A}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CS1\Services\Tcpip\..\{3EC5C936-3D16-4D21-BA21-7C5E6424AF3A}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CS2\Services\Tcpip\..\{3EC5C936-3D16-4D21-BA21-7C5E6424AF3A}: NameServer = 208.67.222.222,208.67.220.220
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NetmanConnections (NetworkConnections) - Unknown owner - C:\WINDOWS\system32\wonlog.ini
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: SpIDer Guard for Windows (SPIDERNT) - Doctor Web, Ltd. - C:\PROGRA~1\DrWeb\spidernt.exe
O23 - Service: wampapache - Unknown owner - C:\Program Files\wamp\bin\apache\apache2.2.6\bin\httpd.exe" -k runservice (file missing)
O23 - Service: wampmysqld - Unknown owner - C:\Program Files\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe" wampmysqld (file missing)

Thanks.
Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\WinSys32.crc
C:\WINDOWS\system32\Down(0).exe
C:\WINDOWS\system32\dmsfwfmj.dll

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{f7486279-8be6-4505-8f3c-b26c2cd92eee}]


Save this as Save this as "CFScript"


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
Here is ComboFix:

ComboFix 07-12-09.1 - Kampfzentrum 2007-12-10 18:34:06.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1484 [GMT -6:00]
Running from: F:\ComboFix.exe
Command switches used :: F:\CFScript.txt
* Created a new restore point

FILE
C:\WINDOWS\system32\dmsfwfmj.dll
C:\WINDOWS\system32\Down(0).exe
C:\WINDOWS\system32\WinSys32.crc
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\Down(0).exe
C:\WINDOWS\system32\WinSys32.crc

.
((((((((((((((((((((((((( Files Created from 2007-11-11 to 2007-12-11 )))))))))))))))))))))))))))))))
.

2007-12-10 05:16 . 2007-12-10 05:16 d——– C:\Program Files\PM Studios
2007-12-09 21:30 . 2007-12-09 21:44 d——– C:\Documents and Settings\Kampfzentrum\DoctorWeb
2007-12-09 21:30 . 2007-12-09 21:31 77,824 –a—-t- C:\WINDOWS\system32\DRWEBSP.DLL
2007-12-09 21:29 . 2007-12-10 16:30 d——– C:\Program Files\DrWeb
2007-12-09 21:28 . 2007-12-09 21:28 d——– C:\Documents and Settings\Kampfzentrum\Application Data\InstallShield
2007-12-09 20:38 . 2007-12-09 20:38 d——– C:\Program Files\ATF Cleaner
2007-12-09 19:32 . 2007-12-09 19:32 426 –a—— C:\WINDOWS\system32\temp.dat
2007-12-09 19:18 . 2007-12-09 19:18 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-09 18:30 . 2007-05-30 06:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-12-09 17:57 . 2007-12-09 19:16 d——– C:\Program Files\Spybot
2007-12-09 17:57 . 2007-12-09 19:16 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-09 17:34 . 2007-12-09 19:18 d——– C:\Documents and Settings\Kampfzentrum\Application Data\AdwareAlert
2007-12-09 16:05 . 2000-02-22 21:38 206,272 –a—— C:\WINDOWS\system32\drivers\udfreadr.BAK
2007-12-09 15:57 . 2002-02-22 18:02 206,208 –a—— C:\WINDOWS\system32\drivers\udfreadr.sys
2007-12-09 15:57 . 2002-02-22 18:10 90,112 –a—— C:\WINDOWS\system32\udfrunin.exe
2007-12-09 07:13 . 2007-09-06 05:09 801,144 –a—— C:\WINDOWS\system32\aswBoot.exe
2007-12-09 07:13 . 2004-01-09 04:13 380,928 –a—— C:\WINDOWS\system32\actskin4.ocx
2007-12-09 07:13 . 2007-09-06 05:00 95,608 –a—— C:\WINDOWS\system32\AvastSS.scr
2007-12-09 07:13 . 2007-09-06 05:05 94,416 –a—— C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-09 07:13 . 2007-09-06 05:05 92,848 –a—— C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-09 07:13 . 2007-09-06 05:02 42,912 –a—— C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-09 07:13 . 2007-09-06 05:00 26,624 –a—— C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-09 07:13 . 2007-09-06 05:03 23,152 –a—— C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-09 07:12 . 2007-12-09 07:12 d——– C:\Program Files\Alwil Software
2007-12-08 22:52 . 2007-12-09 18:42 108,336 –a—— C:\WINDOWS\mswinsck.ocx
2007-12-08 22:34 . 2007-12-08 22:34 d–h—– C:\Program Files\WinfiX
2007-12-08 19:34 . 2007-12-08 19:34 98,304 –a—— C:\WINDOWS\system32\CmdLineExt.dll
2007-12-08 19:32 . 2007-12-08 19:32 d——– C:\WINDOWS\system32\ageia
2007-12-08 19:32 . 2007-12-08 19:32 d——– C:\Program Files\AGEIA Technologies
2007-12-08 16:47 . 2007-04-04 18:53 81,768 –a—— C:\WINDOWS\system32\xinput1_3.dll
2007-12-08 14:48 . 2007-12-08 14:48 d——– C:\Documents and Settings\Kampfzentrum\Application Data\KALiNKOsoft
2007-12-08 14:48 . 2007-12-08 14:48 36,864 –a—— C:\WINDOWS\system32\dxinputdll.dll
2007-12-04 18:26 . 2007-12-04 18:27 d——– C:\Documents and Settings\All Users\Application Data\GlobalSCAPE
2007-12-04 18:25 . 2007-12-04 18:25 d——– C:\Documents and Settings\Kampfzentrum\Application Data\GlobalSCAPE
2007-12-03 21:27 . 2007-12-03 21:27 d——– C:\Program Files\LSoft Technologies
2007-12-01 13:58 . 2007-12-01 13:59 d——– C:\Program Files\FPXpress
2007-12-01 13:21 . 2004-11-22 20:56 913,560 –a—— C:\WINDOWS\system32\wodFtpDLX.ocx
2007-12-01 13:20 . 2007-12-09 08:09 d——– C:\Program Files\CoffeeCup Software
2007-12-01 13:20 . 1999-03-22 12:29 233,472 –a—— C:\WINDOWS\system32\Ilda32.dll
2007-12-01 13:20 . 1998-06-17 04:00 18,944 –a—— C:\WINDOWS\system32\BORLNDMM.DLL
2007-12-01 12:44 . 2007-12-01 12:44 149,916 –a—— C:\tmp.exe
2007-12-01 07:42 . 2007-12-01 07:42 d——– C:\Program Files\AceBIT
2007-12-01 07:42 . 2003-08-29 16:36 1,079,808 –a—— C:\WINDOWS\system32\we.dll
2007-12-01 07:42 . 2003-07-22 03:40 430,080 –a—— C:\WINDOWS\system32\wodSFTP.ocx
2007-12-01 07:42 . 2003-07-22 03:38 425,984 –a—— C:\WINDOWS\system32\wodKeys.dll
2007-12-01 07:42 . 2003-07-22 03:37 385,024 –a—— C:\WINDOWS\system32\wodSFTP.dll
2007-12-01 06:22 . 2007-12-09 20:10 d——– C:\Program Files\Spyware Doctor
2007-12-01 06:22 . 2007-12-01 06:22 d——– C:\Documents and Settings\Kampfzentrum\Application Data\PC Tools
2007-12-01 06:22 . 2007-10-18 00:16 79,688 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2007-12-01 06:22 . 2007-10-18 00:15 62,280 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2007-12-01 06:22 . 2007-10-18 00:14 41,288 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-12-01 06:22 . 2007-10-18 00:16 29,000 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2007-12-01 06:20 . 2005-09-23 08:29 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-11-29 17:15 . 2007-11-29 17:15 d——– C:\Program Files\PremiumSoft
2007-11-28 20:18 . 2007-11-28 20:22 d——– C:\Program Files\wamp
2007-11-28 15:59 . 2007-12-09 10:24 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2007-11-28 15:59 . 2007-11-28 15:59 1,409 –a—— C:\WINDOWS\QTFont.for
2007-11-28 15:58 . 2007-11-28 15:59 d——– C:\Program Files\iTunes
2007-11-28 15:58 . 2007-11-28 15:58 d——– C:\Program Files\iPod
2007-11-27 21:39 . 2007-11-28 21:57 d——– C:\Program Files\phpDesigner 2008
2007-11-27 21:39 . 2007-11-28 21:57 d——– C:\Documents and Settings\Kampfzentrum\Application Data\phpDesigner 2008
2007-11-27 21:29 . 2007-11-27 21:29 d——– C:\Program Files\7-Zip
2007-11-27 21:09 . 2007-11-27 21:09 d——– C:\Program Files\Windows Script Control
2007-11-27 21:09 . 2007-11-27 21:09 d——– C:\Program Files\Common Files\e.World
2007-11-27 21:09 . 2007-11-27 21:09 0 –a—— C:\WINDOWS\system32\UNWISE.INI
2007-11-27 21:08 . 2007-11-27 21:09 d——– C:\Program Files\PHPMaker 5
2007-11-27 21:08 . 2002-07-26 17:02 153,088 –a—— C:\WINDOWS\system32\UNWISE.EXE
2007-11-24 16:08 . 2007-11-24 16:09 d——– C:\Program Files\CrystalButton2
2007-11-22 22:32 . 2007-12-08 19:21 d——– C:\Program Files\Ubisoft
2007-11-18 13:05 . 2007-11-18 13:05 150,643 –ah—– C:\_crash.dmp
2007-11-18 13:05 . 2007-11-18 13:05 58,902 –ah—– C:\report.zip
2007-11-14 23:43 . 2007-11-14 23:43 65,536 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2007-11-14 23:43 . 2007-11-14 23:43 49,152 –a—— C:\WINDOWS\system32\QuickTime.qts

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-10 03:29 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-10 01:16 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\Azureus
2007-12-09 14:39 ——— d—–w C:\Program Files\Babylon
2007-12-09 04:19 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\Vso
2007-12-08 21:17 ——— d—–w C:\Program Files\Azureus
2007-11-28 21:57 ——— d—–w C:\Program Files\QuickTime
2007-11-26 02:17 ——— d—–w C:\Program Files\Soulseek
2007-11-24 03:35 22,328 —-a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-11-24 03:33 107,832 —-a-w C:\WINDOWS\system32\PnkBstrB.exe
2007-11-23 04:32 ——— d—–w C:\Program Files\Common Files\InstallShield
2007-11-17 22:21 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\BitTorrent
2007-11-13 23:05 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-11-04 15:03 ——— d—–w C:\Program Files\AIM
2007-11-04 15:02 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\Aim
2007-11-04 13:03 ——— d—–w C:\Program Files\Common Files\Apple
2007-11-04 13:03 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple
2007-10-28 21:28 ——— d—–w C:\Program Files\WorkTime
2007-10-27 21:23 22,746,840 —-a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_10_27_16_22_24_full.dmp.zip
2007-10-26 03:02 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\Babylon
2007-10-26 02:33 ——— d—–w C:\Documents and Settings\All Users\Application Data\Babylon
2007-10-25 02:46 ——— d—–w C:\Program Files\Text to Speech Maker
2007-10-25 02:35 ——— d—–w C:\Program Files\NCT
2007-10-25 02:11 ——— d—–w C:\Program Files\GameSpy Arcade
2007-10-25 01:23 ——— d—–w C:\Program Files\VirtualDJ
2007-10-25 01:21 ——— d—–w C:\Program Files\RegHealer
2007-10-20 12:15 ——— d—–w C:\Program Files\Magic Video Converter
2007-10-14 13:25 ——— d—–w C:\Program Files\Xilisoft
2007-10-14 13:05 ——— d—–w C:\Program Files\FileSee
2007-10-14 01:20 ——— d—–w C:\Documents and Settings\All Users\Application Data\SongbirdVLC
2007-10-14 01:18 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\Songbird
2007-10-13 21:15 ——— d—–w C:\Program Files\Soulseek-Test
2007-02-05 13:56 87,608 —-a-w C:\Documents and Settings\Kampfzentrum\Application Data\ezpinst.exe
2007-02-05 13:56 47,360 —-a-w C:\Documents and Settings\Kampfzentrum\Application Data\pcouffin.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AutoCAD Digital Signatures Icon Overlay Handler]
@={36A21736-36C2-4C11-8ACB-D4136F2B57BD}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 1 (GFS Unread Stub)]
@={99FD978C-D287-4F50-827F-B2C658EDA8E7}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 2 (GFS Stub)]
@={AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)]
@={920E6DB1-9907-4370-B3A0-BAFC03D81399}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 3 (GFS Folder)]
@={16F3DD56-1AF5-4347-846D-7C10C4192619}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 4 (GFS Unread Mark)]
@={2916C86E-86A6-43FE-8112-43ABE6BF8DCC}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Offline Files]

[HKEY_CLASSES_ROOT\CLSID\{36A21736-36C2-4C11-8ACB-D4136F2B57BD}]
2006-03-04 23:55 185448 –a—— C:\WINDOWS\system32\AcSignIcon.dll

[HKEY_CLASSES_ROOT\CLSID\{99FD978C-D287-4F50-827F-B2C658EDA8E7}]
2006-10-27 02:48 2210608 –a—— C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL

[HKEY_CLASSES_ROOT\CLSID\{AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}]
2006-10-27 02:48 2210608 –a—— C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL

[HKEY_CLASSES_ROOT\CLSID\{920E6DB1-9907-4370-B3A0-BAFC03D81399}]
2006-10-27 02:48 2210608 –a—— C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL

[HKEY_CLASSES_ROOT\CLSID\{16F3DD56-1AF5-4347-846D-7C10C4192619}]
2006-10-27 02:48 2210608 –a—— C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL

[HKEY_CLASSES_ROOT\CLSID\{2916C86E-86A6-43FE-8112-43ABE6BF8DCC}]
2006-10-27 02:48 2210608 –a—— C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 16:56]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"exflashservice"="C:\Program Files\EPOX\EFS\EZ_FLASH_SERVICE.exe" [2006-05-02 03:26]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-09-25 11:12]
"SoundMan"="SOUNDMAN.EXE" [2006-03-01 02:22 C:\WINDOWS\soundman.exe]
"BtcMouseMaestro"="C:\Program Files\MMaestro\KMaestro.exe" [2005-11-09 03:18]
"CoolSwitch"="C:\WINDOWS\system32\taskswitch.exe" [2002-03-19 19:30]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"GoogleUpdate"="C:\Program Files\Internet Explorer\Down(0).EXE" [2007-11-22 08:55]
"Wise-FTP Scheduler"="" []
"AGEIA PhysX SysTray"="C:\Program Files\AGEIA Technologies\TrayIcon.exe" [2006-03-20 13:43]
"SpIDerNT"="C:\PROGRA~1\DrWeb\spiderui.exe" [2007-10-01 16:17]
"DrWebScheduler"="C:\Program Files\DrWeb\DRWEBSCD.EXE" [2007-09-19 16:04]
"SpIDerMail"="C:\Program Files\DrWeb\spiderml.exe" [2007-11-26 18:21]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Logitech Profiler.lnk - C:\Program Files\Logitech\Profiler\LWEmon.exe [2007-08-26 17:34:21]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=C:\WINDOWS\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoCAD Startup Accelerator.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoCAD Startup Accelerator.lnk
backup=C:\WINDOWS\pss\AutoCAD Startup Accelerator.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
2006-01-12 20:52 483328 –a—— C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2007-05-11 02:06 40048 –a—— C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
2007-09-06 05:06 79224 –a—— C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Babylon Client]
C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
C:\Program Files\BitTorrent\bittorrent.exe –force_start_minimized

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CrawlerNotes]
c:\progra~1\crawler\notes\cnotes.exe /notes

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EA Core]
C:\Program Files\Electronic Arts\EA Link\Core.exe -silent

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2006-10-27 02:47 31016 –a—— C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2007-11-15 13:11 267048 –a—— C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nod32kui]
C:\Program Files\Eset\nod32kui.exe /WAITSERVICE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pinnacle Game Profiler]
C:\Program Files\KALiNKOsoft\Pinnacle Game Profiler\pinnacle.exe -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SDTray]
2007-11-02 17:24 1065800 –a—— C:\Program Files\Spyware Doctor\SDTrayApp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wise-FTP Scheduler]
2003-08-29 16:35 1246720 –a—— C:\Program Files\AceBIT\WISE-FTP\WF_Scheduler.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe -quiet

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZoneAlarm Client]
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

R1 UdfReadr;UdfReadr;C:\WINDOWS\system32\drivers\UdfReadr.sys
R2 AdobeActiveFileMonitor;Adobe Active File Monitor;C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
R2 SPIDER;SpIDer Guard File System Monitor;\??\C:\PROGRA~1\DrWeb\spider.sys
R2 SPIDERNT;SpIDer Guard for Windows;C:\PROGRA~1\DrWeb\spidernt.exe
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver;C:\WINDOWS\system32\drivers\WmBEnum.sys
R3 WmFilter;Logitech WingMan HID Filter Driver;C:\WINDOWS\system32\drivers\WmFilter.sys
R3 WmVirHid;Logitech Virtual Hid Device Driver;C:\WINDOWS\system32\drivers\WmVirHid.sys
R3 WmXlCore;Logitech WingMan Translation Layer Driver;C:\WINDOWS\system32\drivers\WmXlCore.sys
S2 NetworkConnections;NetmanConnections;C:\WINDOWS\system32\wonlog.ini
S3 Hpzodisft_;Hpzodisft_;C:\WINDOWS\system32\bootok.exe
S3 StMp3Rec;Player Recovery Device Control Driver;C:\WINDOWS\system32\Drivers\StMp3Rec.sys
S3 wampapache;wampapache;"C:\Program Files\wamp\bin\apache\apache2.2.6\bin\httpd.exe" -k runservice
S3 wampmysqld;wampmysqld;"C:\Program Files\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe" wampmysqld

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
aeyfoc REG_MULTI_SZ aeyfoc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fe1dd150-ed26-11db-8902-001a703119a4}]
\Shell\AutoRun\command - G:\setupSNK.exe


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{1D072F95-FA9D-5367-BDD9-91013F603BE4}]
C:\Program Files\WinfiX\server.exe s

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CAC7B150-B41B-B8F0-F160-F2F006DD303D}]
C:\WINDOWS\msmg.exe
.
Contents of the 'Scheduled Tasks' folder
"2007-12-10 09:00:00 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job"
- C:\Program Files\AdwareAlert\AdwareAlert.ex
- C:\Program Files\AdwareAlert
.
**************************************************************************

catchme 0.3.1331 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-10 18:35:46
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
GoogleUpdate = C:\Program Files\Internet Explorer\Down(0).EXE??l???????????????????G?o?o?g?l?e?U?p?d?a?t?e?????r???????????????????????e???????????????????????r

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-10 18:36:59
C:\ComboFix2.txt … 2007-12-10 17:50
C:\ComboFix3.txt … 2007-12-10 16:39
.
— E O F —

And HiJackThis:

Logfile of HijackThis v1.99.1
Scan saved at 6:38:05 PM, on 12/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Internet Explorer\IExPlOrE.ExE
C:\WINDOWS\system32\PnkBstrA.exe
C:\PROGRA~1\DrWeb\spidernt.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\MMaestro\KMaestro.exe
C:\WINDOWS\system32\taskswitch.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Internet Explorer\Down(0).EXE
C:\Program Files\AGEIA Technologies\TrayIcon.exe
C:\PROGRA~1\DrWeb\spiderui.exe
C:\Program Files\DrWeb\spiderml.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\Profiler\LWEmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wi-compact.com/Forum/index.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [exflashservice] "C:\Program Files\EPOX\EFS\EZ_FLASH_SERVICE.exe" "5000"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [BtcMouseMaestro] "C:\Program Files\MMaestro\KMaestro.exe"
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [GoogleUpdate] C:\Program Files\Internet Explorer\Down(0).EXE
O4 - HKLM\..\Run: [AGEIA PhysX SysTray] C:\Program Files\AGEIA Technologies\TrayIcon.exe
O4 - HKLM\..\Run: [SpIDerNT] C:\PROGRA~1\DrWeb\spiderui.exe /agent
O4 - HKLM\..\Run: [DrWebScheduler] "C:\Program Files\DrWeb\DRWEBSCD.EXE"
O4 - HKLM\..\Run: [SpIDerMail] "C:\Program Files\DrWeb\spiderml.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Logitech Profiler.lnk = ?
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\drwebsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\drwebsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\drwebsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\drwebsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\drwebsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\drwebsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} (CoGSManager Class) - http://gamingzone.ubisoft.com/dev/packages/GSManager.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3EC5C936-3D16-4D21-BA21-7C5E6424AF3A}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CS1\Services\Tcpip\..\{3EC5C936-3D16-4D21-BA21-7C5E6424AF3A}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CS2\Services\Tcpip\..\{3EC5C936-3D16-4D21-BA21-7C5E6424AF3A}: NameServer = 208.67.222.222,208.67.220.220
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NetmanConnections (NetworkConnections) - Unknown owner - C:\WINDOWS\system32\wonlog.ini
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: SpIDer Guard for Windows (SPIDERNT) - Doctor Web, Ltd. - C:\PROGRA~1\DrWeb\spidernt.exe
O23 - Service: wampapache - Unknown owner - C:\Program Files\wamp\bin\apache\apache2.2.6\bin\httpd.exe" -k runservice (file missing)
O23 - Service: wampmysqld - Unknown owner - C:\Program Files\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe" wampmysqld (file missing)

My computer seems to be running pretty nice. I cannot say that anything is wrong with it. Should I run a virus scan? Is Virtumonde still in here?
  • Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
  • Please do not re-connect your machine back to the Internet until Combofix has completely finished.

Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\Down(0).exe
C:\WINDOWS\system32\WinSys32.crc


Save this as Save this as "CFScript"


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
Disconnected Internet while ComboFix ran, however, I always am getting an error before I start the program (I thought it was normal), it says:

"The instruction at "0x7c9111e0" referenced memory at "0x0020006b". The memory could not be "read".

Also, everytime I run ComboFix I get a IE shortcut placed on my menu.

Here we go again:

ComboFix 07-12-09.1 - Kampfzentrum 2007-12-10 20:16:15.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1532 [GMT -6:00]
Running from: F:\ComboFix.exe
Command switches used :: F:\CFScript.txt
* Created a new restore point

FILE
C:\WINDOWS\system32\Down(0).exe
C:\WINDOWS\system32\WinSys32.crc
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\drivers\sfsync02.sys

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_SFSYNC02
——-\sfsync02


((((((((((((((((((((((((( Files Created from 2007-11-11 to 2007-12-11 )))))))))))))))))))))))))))))))
.

2007-12-10 05:16 . 2007-12-10 05:16 d——– C:\Program Files\PM Studios
2007-12-09 21:30 . 2007-12-09 21:44 d——– C:\Documents and Settings\Kampfzentrum\DoctorWeb
2007-12-09 21:30 . 2007-12-09 21:31 77,824 –a—-t- C:\WINDOWS\system32\DRWEBSP.DLL
2007-12-09 21:29 . 2007-12-10 18:43 d——– C:\Program Files\DrWeb
2007-12-09 21:28 . 2007-12-09 21:28 d——– C:\Documents and Settings\Kampfzentrum\Application Data\InstallShield
2007-12-09 20:38 . 2007-12-09 20:38 d——– C:\Program Files\ATF Cleaner
2007-12-09 19:32 . 2007-12-09 19:32 426 –a—— C:\WINDOWS\system32\temp.dat
2007-12-09 19:18 . 2007-12-09 19:18 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-09 18:30 . 2007-05-30 06:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-12-09 17:57 . 2007-12-09 19:16 d——– C:\Program Files\Spybot
2007-12-09 17:57 . 2007-12-09 19:16 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-09 17:34 . 2007-12-09 19:18 d——– C:\Documents and Settings\Kampfzentrum\Application Data\AdwareAlert
2007-12-09 16:05 . 2000-02-22 21:38 206,272 –a—— C:\WINDOWS\system32\drivers\udfreadr.BAK
2007-12-09 15:57 . 2002-02-22 18:02 206,208 –a—— C:\WINDOWS\system32\drivers\udfreadr.sys
2007-12-09 15:57 . 2002-02-22 18:10 90,112 –a—— C:\WINDOWS\system32\udfrunin.exe
2007-12-09 07:13 . 2007-09-06 05:09 801,144 –a—— C:\WINDOWS\system32\aswBoot.exe
2007-12-09 07:13 . 2004-01-09 04:13 380,928 –a—— C:\WINDOWS\system32\actskin4.ocx
2007-12-09 07:13 . 2007-09-06 05:00 95,608 –a—— C:\WINDOWS\system32\AvastSS.scr
2007-12-09 07:13 . 2007-09-06 05:05 94,416 –a—— C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-09 07:13 . 2007-09-06 05:05 92,848 –a—— C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-09 07:13 . 2007-09-06 05:02 42,912 –a—— C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-09 07:13 . 2007-09-06 05:00 26,624 –a—— C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-09 07:13 . 2007-09-06 05:03 23,152 –a—— C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-09 07:12 . 2007-12-09 07:12 d——– C:\Program Files\Alwil Software
2007-12-08 22:52 . 2007-12-09 18:42 108,336 –a—— C:\WINDOWS\mswinsck.ocx
2007-12-08 22:34 . 2007-12-08 22:34 d–h—– C:\Program Files\WinfiX
2007-12-08 19:34 . 2007-12-08 19:34 98,304 –a—— C:\WINDOWS\system32\CmdLineExt.dll
2007-12-08 19:32 . 2007-12-08 19:32 d——– C:\WINDOWS\system32\ageia
2007-12-08 19:32 . 2007-12-08 19:32 d——– C:\Program Files\AGEIA Technologies
2007-12-08 16:47 . 2007-04-04 18:53 81,768 –a—— C:\WINDOWS\system32\xinput1_3.dll
2007-12-08 14:48 . 2007-12-08 14:48 d——– C:\Documents and Settings\Kampfzentrum\Application Data\KALiNKOsoft
2007-12-08 14:48 . 2007-12-08 14:48 36,864 –a—— C:\WINDOWS\system32\dxinputdll.dll
2007-12-04 18:26 . 2007-12-04 18:27 d——– C:\Documents and Settings\All Users\Application Data\GlobalSCAPE
2007-12-04 18:25 . 2007-12-04 18:25 d——– C:\Documents and Settings\Kampfzentrum\Application Data\GlobalSCAPE
2007-12-03 21:27 . 2007-12-03 21:27 d——– C:\Program Files\LSoft Technologies
2007-12-01 13:58 . 2007-12-01 13:59 d——– C:\Program Files\FPXpress
2007-12-01 13:21 . 2004-11-22 20:56 913,560 –a—— C:\WINDOWS\system32\wodFtpDLX.ocx
2007-12-01 13:20 . 2007-12-09 08:09 d——– C:\Program Files\CoffeeCup Software
2007-12-01 13:20 . 1999-03-22 12:29 233,472 –a—— C:\WINDOWS\system32\Ilda32.dll
2007-12-01 13:20 . 1998-06-17 04:00 18,944 –a—— C:\WINDOWS\system32\BORLNDMM.DLL
2007-12-01 12:44 . 2007-12-01 12:44 149,916 –a—— C:\tmp.exe
2007-12-01 07:42 . 2007-12-01 07:42 d——– C:\Program Files\AceBIT
2007-12-01 07:42 . 2003-08-29 16:36 1,079,808 –a—— C:\WINDOWS\system32\we.dll
2007-12-01 07:42 . 2003-07-22 03:40 430,080 –a—— C:\WINDOWS\system32\wodSFTP.ocx
2007-12-01 07:42 . 2003-07-22 03:38 425,984 –a—— C:\WINDOWS\system32\wodKeys.dll
2007-12-01 07:42 . 2003-07-22 03:37 385,024 –a—— C:\WINDOWS\system32\wodSFTP.dll
2007-12-01 06:22 . 2007-12-09 20:10 d——– C:\Program Files\Spyware Doctor
2007-12-01 06:22 . 2007-12-01 06:22 d——– C:\Documents and Settings\Kampfzentrum\Application Data\PC Tools
2007-12-01 06:22 . 2007-10-18 00:16 79,688 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2007-12-01 06:22 . 2007-10-18 00:15 62,280 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2007-12-01 06:22 . 2007-10-18 00:14 41,288 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-12-01 06:22 . 2007-10-18 00:16 29,000 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2007-12-01 06:20 . 2005-09-23 08:29 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-11-29 17:15 . 2007-11-29 17:15 d——– C:\Program Files\PremiumSoft
2007-11-28 20:18 . 2007-11-28 20:22 d——– C:\Program Files\wamp
2007-11-28 15:59 . 2007-12-09 10:24 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2007-11-28 15:59 . 2007-11-28 15:59 1,409 –a—— C:\WINDOWS\QTFont.for
2007-11-28 15:58 . 2007-11-28 15:59 d——– C:\Program Files\iTunes
2007-11-28 15:58 . 2007-11-28 15:58 d——– C:\Program Files\iPod
2007-11-27 21:39 . 2007-11-28 21:57 d——– C:\Program Files\phpDesigner 2008
2007-11-27 21:39 . 2007-11-28 21:57 d——– C:\Documents and Settings\Kampfzentrum\Application Data\phpDesigner 2008
2007-11-27 21:29 . 2007-11-27 21:29 d——– C:\Program Files\7-Zip
2007-11-27 21:09 . 2007-11-27 21:09 d——– C:\Program Files\Windows Script Control
2007-11-27 21:09 . 2007-11-27 21:09 d——– C:\Program Files\Common Files\e.World
2007-11-27 21:09 . 2007-11-27 21:09 0 –a—— C:\WINDOWS\system32\UNWISE.INI
2007-11-27 21:08 . 2007-11-27 21:09 d——– C:\Program Files\PHPMaker 5
2007-11-27 21:08 . 2002-07-26 17:02 153,088 –a—— C:\WINDOWS\system32\UNWISE.EXE
2007-11-24 16:08 . 2007-11-24 16:09 d——– C:\Program Files\CrystalButton2
2007-11-22 22:32 . 2007-12-08 19:21 d——– C:\Program Files\Ubisoft
2007-11-18 13:05 . 2007-11-18 13:05 150,643 –ah—– C:\_crash.dmp
2007-11-18 13:05 . 2007-11-18 13:05 58,902 –ah—– C:\report.zip
2007-11-14 23:43 . 2007-11-14 23:43 65,536 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2007-11-14 23:43 . 2007-11-14 23:43 49,152 –a—— C:\WINDOWS\system32\QuickTime.qts

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-11 00:42 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\Azureus
2007-12-10 03:29 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-09 14:39 ——— d—–w C:\Program Files\Babylon
2007-12-09 04:19 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\Vso
2007-12-08 21:17 ——— d—–w C:\Program Files\Azureus
2007-11-28 21:57 ——— d—–w C:\Program Files\QuickTime
2007-11-26 02:17 ——— d—–w C:\Program Files\Soulseek
2007-11-24 03:35 22,328 —-a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-11-23 04:32 ——— d—–w C:\Program Files\Common Files\InstallShield
2007-11-17 22:21 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\BitTorrent
2007-11-13 23:05 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-11-04 15:03 ——— d—–w C:\Program Files\AIM
2007-11-04 15:02 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\Aim
2007-11-04 13:03 ——— d—–w C:\Program Files\Common Files\Apple
2007-11-04 13:03 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple
2007-10-28 21:28 ——— d—–w C:\Program Files\WorkTime
2007-10-26 03:02 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\Babylon
2007-10-26 02:33 ——— d—–w C:\Documents and Settings\All Users\Application Data\Babylon
2007-10-25 02:46 ——— d—–w C:\Program Files\Text to Speech Maker
2007-10-25 02:35 ——— d—–w C:\Program Files\NCT
2007-10-25 02:11 ——— d—–w C:\Program Files\GameSpy Arcade
2007-10-25 01:23 ——— d—–w C:\Program Files\VirtualDJ
2007-10-25 01:21 ——— d—–w C:\Program Files\RegHealer
2007-10-20 12:15 ——— d—–w C:\Program Files\Magic Video Converter
2007-10-14 13:25 ——— d—–w C:\Program Files\Xilisoft
2007-10-14 13:05 ——— d—–w C:\Program Files\FileSee
2007-10-14 01:20 ——— d—–w C:\Documents and Settings\All Users\Application Data\SongbirdVLC
2007-10-14 01:18 ——— d—–w C:\Documents and Settings\Kampfzentrum\Application Data\Songbird
2007-10-13 21:15 ——— d—–w C:\Program Files\Soulseek-Test
2007-02-05 13:56 87,608 —-a-w C:\Documents and Settings\Kampfzentrum\Application Data\ezpinst.exe
2007-02-05 13:56 47,360 —-a-w C:\Documents and Settings\Kampfzentrum\Application Data\pcouffin.sys
.

((((((((((((((((((((((((((((( snapshot@2007-12-10_16.38.35.60 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-12-11 02:19:59 16,384 —-atw C:\WINDOWS\Temp\Perflib_Perfdata_5e0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AutoCAD Digital Signatures Icon Overlay Handler]
@={36A21736-36C2-4C11-8ACB-D4136F2B57BD}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 1 (GFS Unread Stub)]
@={99FD978C-D287-4F50-827F-B2C658EDA8E7}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 2 (GFS Stub)]
@={AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)]
@={920E6DB1-9907-4370-B3A0-BAFC03D81399}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 3 (GFS Folder)]
@={16F3DD56-1AF5-4347-846D-7C10C4192619}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Groove Explorer Icon Overlay 4 (GFS Unread Mark)]
@={2916C86E-86A6-43FE-8112-43ABE6BF8DCC}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Offline Files]

[HKEY_CLASSES_ROOT\CLSID\{36A21736-36C2-4C11-8ACB-D4136F2B57BD}]
2006-03-04 23:55 185448 –a—— C:\WINDOWS\system32\AcSignIcon.dll

[HKEY_CLASSES_ROOT\CLSID\{99FD978C-D287-4F50-827F-B2C658EDA8E7}]
2006-10-27 02:48 2210608 –a—— C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL

[HKEY_CLASSES_ROOT\CLSID\{AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}]
2006-10-27 02:48 2210608 –a—— C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL

[HKEY_CLASSES_ROOT\CLSID\{920E6DB1-9907-4370-B3A0-BAFC03D81399}]
2006-10-27 02:48 2210608 –a—— C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL

[HKEY_CLASSES_ROOT\CLSID\{16F3DD56-1AF5-4347-846D-7C10C4192619}]
2006-10-27 02:48 2210608 –a—— C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL

[HKEY_CLASSES_ROOT\CLSID\{2916C86E-86A6-43FE-8112-43ABE6BF8DCC}]
2006-10-27 02:48 2210608 –a—— C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 16:56]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"exflashservice"="C:\Program Files\EPOX\EFS\EZ_FLASH_SERVICE.exe" [2006-05-02 03:26]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-09-25 11:12]
"SoundMan"="SOUNDMAN.EXE" [2006-03-01 02:22 C:\WINDOWS\soundman.exe]
"BtcMouseMaestro"="C:\Program Files\MMaestro\KMaestro.exe" [2005-11-09 03:18]
"CoolSwitch"="C:\WINDOWS\system32\taskswitch.exe" [2002-03-19 19:30]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"GoogleUpdate"="C:\Program Files\Internet Explorer\Down(0).EXE" [2007-11-22 08:55]
"Wise-FTP Scheduler"="" []
"AGEIA PhysX SysTray"="C:\Program Files\AGEIA Technologies\TrayIcon.exe" [2006-03-20 13:43]
"SpIDerNT"="C:\PROGRA~1\DrWeb\spiderui.exe" [2007-10-01 16:17]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Logitech Profiler.lnk - C:\Program Files\Logitech\Profiler\LWEmon.exe [2007-08-26 17:34:21]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=C:\WINDOWS\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoCAD Startup Accelerator.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoCAD Startup Accelerator.lnk
backup=C:\WINDOWS\pss\AutoCAD Startup Accelerator.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
2006-01-12 20:52 483328 –a—— C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2007-05-11 02:06 40048 –a—— C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
2007-09-06 05:06 79224 –a—— C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Babylon Client]
C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
C:\Program Files\BitTorrent\bittorrent.exe –force_start_minimized

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CrawlerNotes]
c:\progra~1\crawler\notes\cnotes.exe /notes

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EA Core]
C:\Program Files\Electronic Arts\EA Link\Core.exe -silent

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2006-10-27 02:47 31016 –a—— C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2007-11-15 13:11 267048 –a—— C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nod32kui]
C:\Program Files\Eset\nod32kui.exe /WAITSERVICE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pinnacle Game Profiler]
C:\Program Files\KALiNKOsoft\Pinnacle Game Profiler\pinnacle.exe -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SDTray]
2007-11-02 17:24 1065800 –a—— C:\Program Files\Spyware Doctor\SDTrayApp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wise-FTP Scheduler]
2003-08-29 16:35 1246720 –a—— C:\Program Files\AceBIT\WISE-FTP\WF_Scheduler.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe -quiet

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZoneAlarm Client]
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

R1 UdfReadr;UdfReadr;C:\WINDOWS\system32\drivers\UdfReadr.sys
R2 AdobeActiveFileMonitor;Adobe Active File Monitor;C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
R2 SPIDER;SpIDer Guard File System Monitor;\??\C:\PROGRA~1\DrWeb\spider.sys
R2 SPIDERNT;SpIDer Guard for Windows;C:\PROGRA~1\DrWeb\spidernt.exe
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver;C:\WINDOWS\system32\drivers\WmBEnum.sys
R3 WmFilter;Logitech WingMan HID Filter Driver;C:\WINDOWS\system32\drivers\WmFilter.sys
R3 WmVirHid;Logitech Virtual Hid Device Driver;C:\WINDOWS\system32\drivers\WmVirHid.sys
R3 WmXlCore;Logitech WingMan Translation Layer Driver;C:\WINDOWS\system32\drivers\WmXlCore.sys
S2 NetworkConnections;NetmanConnections;C:\WINDOWS\system32\wonlog.ini
S3 Hpzodisft_;Hpzodisft_;C:\WINDOWS\system32\bootok.exe
S3 StMp3Rec;Player Recovery Device Control Driver;C:\WINDOWS\system32\Drivers\StMp3Rec.sys
S3 wampapache;wampapache;"C:\Program Files\wamp\bin\apache\apache2.2.6\bin\httpd.exe" -k runservice
S3 wampmysqld;wampmysqld;"C:\Program Files\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe" wampmysqld

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
aeyfoc REG_MULTI_SZ aeyfoc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fe1dd150-ed26-11db-8902-001a703119a4}]
\Shell\AutoRun\command - G:\setupSNK.exe


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{1D072F95-FA9D-5367-BDD9-91013F603BE4}]
C:\Program Files\WinfiX\server.exe s

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CAC7B150-B41B-B8F0-F160-F2F006DD303D}]
C:\WINDOWS\msmg.exe
.
Contents of the 'Scheduled Tasks' folder
"2007-12-10 09:00:00 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job"
- C:\Program Files\AdwareAlert\AdwareAlert.ex
- C:\Program Files\AdwareAlert
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\DOCUME~1\KAMPFZ~1\LOCALS~1\Temp\ppeulkwv.dll
.
**************************************************************************

catchme 0.3.1331 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-10 20:20:55
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
GoogleUpdate = C:\Program Files\Internet Explorer\Down(0).EXE??l???????????????????G?o?o?g?l?e?U?p?d?a?t?e?????r???????????????????????e???????????????????????r

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-10 20:22:18 - machine was rebooted
C:\ComboFix2.txt … 2007-12-10 18:37
C:\ComboFix3.txt … 2007-12-10 17:50
.
— E O F —
Logfile of HijackThis v1.99.1
Scan saved at 6:55:12 PM, on 12/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\IExPlOrE.ExE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Program Files\MMaestro\KMaestro.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\taskswitch.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Internet Explorer\Down(0).EXE
C:\Program Files\AGEIA Technologies\TrayIcon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\Profiler\LWEmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\Acrobat.exe
C:\DOCUME~1\KAMPFZ~1\LOCALS~1\Temp\Adobelm_Cleanup.0001
C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
C:\DOCUME~1\KAMPFZ~1\LOCALS~1\Temp\Adobelm_Cleanup.0001
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wi-compact.com/Forum/index.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [exflashservice] "C:\Program Files\EPOX\EFS\EZ_FLASH_SERVICE.exe" "5000"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [BtcMouseMaestro] "C:\Program Files\MMaestro\KMaestro.exe"
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [GoogleUpdate] C:\Program Files\Internet Explorer\Down(0).EXE
O4 - HKLM\..\Run: [AGEIA PhysX SysTray] C:\Program Files\AGEIA Technologies\TrayIcon.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Logitech Profiler.lnk = ?
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} (CoGSManager Class) - http://gamingzone.ubisoft.com/dev/packages/GSManager.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3EC5C936-3D16-4D21-BA21-7C5E6424AF3A}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CS1\Services\Tcpip\..\{3EC5C936-3D16-4D21-BA21-7C5E6424AF3A}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CS2\Services\Tcpip\..\{3EC5C936-3D16-4D21-BA21-7C5E6424AF3A}: NameServer = 208.67.222.222,208.67.220.220
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NetmanConnections (NetworkConnections) - Unknown owner - C:\WINDOWS\system32\wonlog.ini
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: wampapache - Unknown owner - C:\Program Files\wamp\bin\apache\apache2.2.6\bin\httpd.exe" -k runservice (file missing)
O23 - Service: wampmysqld - Unknown owner - C:\Program Files\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe" wampmysqld (file missing)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI