This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Please help me... I'm a 'newbie' with a vi

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Please can some help me a talk me through getting my Media Centre working properly again?

I have tried all kinds of anti virus software and anti spyware, but it keeps coming back!! I constantly get pop ups from my Spybot S&D and Spyware Doctor telling me that I am infected. I have also just got 2 new shortcut icons that have appeared on my desktop saying 'Microsoft update' and 'Help and Support Centre' which direct me to download 'storageprotection' which I believe to be further spyware.

I have downloaded HijackThis and this is the log that I think I am supposed to post:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:48:52, on 20/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\FSGK32.EXE
C:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe
C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
C:\Program Files\F-Secure Internet Security\Common\FSMB32.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\F-Secure Internet Security\Common\FCH32.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\KService\KService.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsqh.exe
C:\Program Files\F-Secure Internet Security\Common\FAMEH32.EXE
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsrw.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsav32.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\PC Connectivity Solution\NclBTHandler.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\eHome\VFDTranscoder.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\WINDOWS\system\wcdvtray.exe
C:\Program Files\F-Secure Internet Security\FSGUI\ispnews.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE
C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\PROGRA~1\F-SECU~1\ANTI-S~1\fsaw.exe
C:\WINDOWS\system32\SysMonitor.exe
C:\Program Files\F-Secure Internet Security\FSGUI\fsguidll.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\kdx\KHost.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/customi…fo/bt_side.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.red.clientapps.yahoo.com/customi…arch.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/customi…fo/bt_side.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.red.clientapps.yahoo.com/customi…arch.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.aceradvantage.com/stdreg
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 66.98.238.8:3128
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local;
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {061FD4C8-798C-420F-8F26-32A0C3BE8FEF} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {201CAAD1-1A12-4423-8EA4-579FE9DE4DBD} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: (no name) - {B5E0B630-CE27-4F05-903E-CEC7E55A7760} - C:\WINDOWS\system32\mljgf.dll
O2 - BHO: (no name) - {DB0B918E-A0A8-482B-8D75-A682816B0C7B} - C:\WINDOWS\system32\tuvurqp.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [VFDTranscoder] C:\WINDOWS\eHome\VFDTranscoder.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [OWCWebCamDV] C:\WINDOWS\system\wcdvtray.exe
O4 - HKLM\..\Run: [News Service] "C:\Program Files\F-Secure Internet Security\FSGUI\ispnews.exe"
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [ImageItEncrypt] C:\WINDOWS\system32\ImageItEncrypt.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [FlashIcon] "C:\Program Files\Generic\USB Card Reader Utility v1.3\FlashIcon.exe"
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure Internet Security\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\F-Secure Internet Security\FSGUI\FSSW.EXE" /reboot
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\WINDOWS\system32\SysMonitor.exe
O4 - HKLM\..\Run: [70e51637] rundll32.exe "C:\WINDOWS\system32\jokmqhax.dll",b
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] c:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [ProxyWay] C:\Program Files\ProxyWay\proxyway.exe
O4 - HKCU\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe -all
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-21-4157354117-1041672698-3030537117-1006\..\Run: [Windows Media Center] RunDLL32.exe C:\WINDOWS\eHome\ehuihlp.dll,BootMediaCenter (User 'Nico and Jane')
O4 - HKUS\S-1-5-21-4157354117-1041672698-3030537117-1006\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (User 'Nico and Jane')
O4 - HKUS\S-1-5-21-4157354117-1041672698-3030537117-1006\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Nico and Jane')
O4 - HKUS\S-1-5-21-4157354117-1041672698-3030537117-1006\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe" -quiet (User 'Nico and Jane')
O4 - HKUS\S-1-5-21-4157354117-1041672698-3030537117-1006\..\Run: [Orb] "C:\Program Files\Orb Networks\Orb\bin\OrbTray.exe" /background (User 'Nico and Jane')
O4 - HKUS\S-1-5-21-4157354117-1041672698-3030537117-1006\..\Run: [DDC] C:\WINDOWS\system32\rhorgpgl.exe (User 'Nico and Jane')
O4 - HKUS\S-1-5-21-4157354117-1041672698-3030537117-1006\..\Run: [70e51637] rundll32.exe "C:\WINDOWS\system32\glmqsjcf.dll",b (User 'Nico and Jane')
O4 - HKUS\S-1-5-18\..\Run: [Orb] "C:\Program Files\Orb Networks\Orb\bin\OrbTray.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Orb] "C:\Program Files\Orb Networks\Orb\bin\OrbTray.exe" /background (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: F-Secure 2006.lnk = C:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure Internet Security\Anti-Spyware\blockpopups.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\Anti-Spyware\ieshield.dll
O9 - Extra 'Tools' menuitem: IE Shield… - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\Anti-Spyware\ieshield.dll
O9 - Extra button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {3F14D76D-8C1A-47CA-A2CB-34982BCD44DE} (OutlookYearView.YearPlan) - file:///D:/OutlookYearView.CAB
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1160519841906
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.1.6.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6B1DF8DD-EA51-4F75-A168-432FC4F8BC7C}: NameServer = 193.189.160.13 193.189.160.23
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\mcePhone\Skype4COM.dll
O20 - Winlogon Notify: mljhfcd - mljhfcd.dll (file missing)
O20 - Winlogon Notify: tuvurqp - C:\WINDOWS\SYSTEM32\tuvurqp.dll
O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: F-Secure 2006 (BackWeb Plug-in - 4476822) - F-Secure Internet Security 2005 - C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\KService\KService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

–
End of file - 17302 bytes

Thanks in advance for any help….
Hi! Welcome to the WTT forums.
My name is Scotty. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research.
Please be patient.

Please make a uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.
5. Click on the Save list… button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here in a reply.
Hi Scotty, I am grateful that you will look into this for me. Here is the list you requested; Acer Empowering Technology Acer ePerformance Management Acoustica Effects Pack Adobe ExtendScript Toolkit 2 Adobe ExtendScript Toolkit 2 Adobe Flash Player ActiveX Adobe Reader 7.0.9 Adobe Setup Adobe Shockwave Player BladeRunner Pro Blaze Media Pro BT Yahoo! Applications ClearType Tuning Control Panel Applet Digimax V800 DivX Codec DVD-lab Studio 1.25 F-Secure Anti-Virus 2006 GemMaster Mystic Generic USB Card Reader Utility v1.3 Google Earth HDMI Resolution Setting Utility High Definition Audio Driver Package - KB888111 HijackThis 2.0.2 Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 10 (KB903157) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB888795) Hotfix for Windows XP (KB891593) Hotfix for Windows XP (KB893357) Hotfix for Windows XP (KB895961) Hotfix for Windows XP (KB896256) Hotfix for Windows XP (KB899337) Hotfix for Windows XP (KB899510) Hotfix for Windows XP (KB902841) Hotfix for Windows XP (KB906569) Hotfix for Windows XP (KB912024) Hotfix for Windows XP (KB914440) Hotfix for Windows XP (KB915865) Hotfix for Windows XP (KB926239) Hotfix for Windows XP (KB935448) hp instant support HP Photo and Imaging 1.0 - HP PSC - HP OfficeJet HP Photo and Imaging 1.0 - HP PSC - HP OfficeJet HP Photo and Imaging 1.0 - HP PSC - HP OfficeJet Drivers hp psc 2200 series Intel® Graphics Media Accelerator Driver Intel® Matrix Storage Manager Intel® PRO Network Connections Drivers Intel® Processor ID Utility Intel® Quick Resume Technology Drivers Intel® Quick Resume Technology Drivers Intel® Viiv™ Software Kaspersky Online Scanner Logitech Audio Echo Cancellation Component Logitech Video Enumerator Logitech® Camera Driver mcePhone for Skype 2.1 Media Library Management Wizard MGTEK dopisp Microsoft .NET Framework 1.0 Hotfix (KB887998) Microsoft .NET Framework 1.0 Hotfix (KB930494) Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 2.0 Microsoft Away Mode Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office Professional Edition 2003 Microsoft User-Mode Driver Framework Feature Pack 1.5 Movie Maker Background Music Files Movie Maker Sound Effects Movie Maker Title Images MSXML 4.0 SP2 (KB925672) MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) My Movies Nokia Connectivity Cable Driver Nokia PC Suite Nokia PC Suite Nokia Software Updater NTI Backup NOW! 4.7 NTI CD & DVD-Maker OCA Client history tool install OrangeWare WebCamDV Orb Otto OutRun2006 Coast 2 Coast PaperPort 8.0 SE PC Connectivity Solution Personal License Update Wizard for Windows Media Player Photo Story 3 for Windows Picture Slide DVD 1.0 Plug and Record 1.0 Plus! MP3 Audio Converter LE PowerDVD PowerISO QuickTime Readiris 7.5 RealPlayer Realtek High Definition Audio Driver Roxio VideoWave Movie Creator Security Update for CAPICOM (KB931906) Security Update for CAPICOM (KB931906) Security Update for Microsoft .NET Framework 2.0 (KB928365) Security Update for Step By Step Interactive Training (KB898458) Security Update for Windows Internet Explorer 7 (KB928090) Security Update for Windows Internet Explorer 7 (KB929969) Security Update for Windows Internet Explorer 7 (KB931768) Security Update for Windows Internet Explorer 7 (KB933566) Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB939653) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB883939) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896422) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899588) Security Update for Windows XP (KB899589) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901190) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB903235) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB905915) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911567) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913433) Security Update for Windows XP (KB913446) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB917159) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB918899) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920214) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921398) Security Update for Windows XP (KB921503) Security Update for Windows XP (KB921883) Security Update for Windows XP (KB922616) Security Update for Windows XP (KB922760) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923694) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925486) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933729) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB937894) Security Update for Windows XP (KB938829) Security Update for Windows XP (KB941202) Security Update for Windows XP (KB941568) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB943460) Security Update for Windows XP (KB944653) SereneScreen Marine Aquarium 2.6 Sky Anytime Skype™ 3.5 Sonic Encoders Spybot - Search & Destroy Spyware Doctor 5.1 SyncToy System Requirements Lab TweakMCE UMVPLStandalone UnZixWin Extractor Update for Windows Media Player 10 (KB910393) Update for Windows Media Player 10 (KB913800) Update for Windows Media Player 10 (KB926251) Update for Windows XP (KB894391) Update for Windows XP (KB896727) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB904942) Update for Windows XP (KB908531) Update for Windows XP (KB910437) Update for Windows XP (KB911280) Update for Windows XP (KB912945) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB927891) Update for Windows XP (KB929338) Update for Windows XP (KB930916) Update for Windows XP (KB931836) Update for Windows XP (KB933360) Update for Windows XP (KB936357) Update for Windows XP (KB938828) Update for Windows XP (KB942763) Update Rollup 2 for Windows XP Media Center Edition 2005 VFDTranscoder v1.00.03 Web Media Release Candidate 1.3 WIDCOMM Bluetooth Software Windows Defender Windows Defender Signatures Windows Driver Package - Nokia (WUDFRd) WPD (03/19/2007 6.83.31.1) Windows Driver Package - Nokia Modem (02/15/2007 3.1) Windows Driver Package - Nokia Modem (11/03/2006 6.82.0.1) Windows Installer 3.1 (KB893803) Windows Internet Explorer 7 Windows Media Bonus Pack for Windows XP Windows Media Format 11 runtime Windows Media Format 11 runtime Windows Media Player 11 Windows Media Player 11 Windows Media Player Playlist Import to Excel Wizard Windows Media Player Skin Importer Windows Media Player Tray Control Windows XP Hotfix - KB867282 Windows XP Hotfix - KB873333 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888239 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890047 Windows XP Hotfix - KB890175 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB890923 Windows XP Hotfix - KB891781 Windows XP Hotfix - KB893086 Windows XP Media Center Edition 2005 KB895275 Windows XP Media Center Edition 2005 KB908246 Windows XP Media Center Edition 2005 KB925766 XviD 1.1 final uninstall Zattoo 3.0.8 beta
Hi
Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.

If you already have Combofix, please delete this copy and download it again as it's being updated regularly.

Please Download and Save Combofix from Bleeping Computer. Save it to your desktop.

If you can't download it, please try these 2 alternative sites:

Forospyware
Geeks to Go
  • Save it to your Desktop.
  • Disconnect from the Internet, than disable your anti-virus and any real-time anti-spyware monitors that are running.
  • Click Start>Run copy/paste or type "%userprofile%\desktop\combofix.exe" /killall into the Run box and click OK.
  • When finished, it shall produce a log for you. Post that log in your next reply with a new HijackThis log.
Note 1: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Note 2:Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet.

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task-Manager use the Processes tab (press ctrl alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

In your next reply post:
vundofix.txt
ComboFix.txt
New HijackThis log taken after the above scan has run
Scotty,

Just to let you know I really appreciate your help… Thanks.

I have followed what you said to the letter and have posted the 3 reports below.

Out of interest I should also metion a couple of strange things that have happened as a result of my problems that you may need to know…. Firstly I keep getting a window that pops up on start up that is called 'RUNDLL' that shows a loading error C:\WINDOWS\system32\jokmqhax.dll Secondly, my computer does not recognise any memory sticks, camera, external hard drives in any of the USB ports?!

Here are the logs;


VundoFix V6.7.7

Checking Java version…

Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.

Scan started at 21:17:21 19/12/2007

Listing files found while scanning….

C:\WINDOWS\system32\aglpmghy.dll
C:\WINDOWS\system32\ayehqpjg.dll
C:\WINDOWS\system32\bpvmglhm.dll
C:\WINDOWS\system32\chehpfje.ini
C:\WINDOWS\system32\ckpgmuyo.dll
C:\WINDOWS\system32\cleittsf.dll
C:\WINDOWS\system32\duymbxrr.dll
C:\WINDOWS\system32\ejfphehc.dll
C:\WINDOWS\system32\eugvgugh.dll
C:\WINDOWS\system32\fxmgxgjq.dll
C:\WINDOWS\system32\jocmswqs.dll
C:\WINDOWS\system32\mhlgmvpb.ini
C:\WINDOWS\system32\mljhfcd.dll
C:\WINDOWS\system32\NCTAudioCDGrabber2.dll
C:\WINDOWS\system32\NCTAudioFile2.dll
C:\WINDOWS\system32\NCTAudioPlayer2.dll
C:\WINDOWS\system32\NCTAudioRecord2.dll
C:\WINDOWS\system32\NCTAVIFile.dll
C:\WINDOWS\system32\NCTQuickTimeFile.dll
C:\WINDOWS\system32\NCTVideoCoreM.dll
C:\WINDOWS\system32\NCTWMAFile2.dll
C:\WINDOWS\system32\nshnjojw.dll
C:\WINDOWS\system32\odsqvjrh.dll
C:\WINDOWS\system32\otfjtkut.dll
C:\WINDOWS\system32\pqgswenb.dll
C:\WINDOWS\system32\qhanycmn.dll
C:\WINDOWS\system32\qjkching.dll
C:\WINDOWS\system32\rrtsficf.dll
C:\WINDOWS\system32\rrxbmyud.ini
C:\WINDOWS\system32\saxbehyi.dll
C:\WINDOWS\system32\sstqn.dll
C:\WINDOWS\system32\tiuhqkgo.dll
C:\WINDOWS\system32\wvgghacm.dll
C:\WINDOWS\system32\xkbwgabl.dll
C:\WINDOWS\system32\yhgmplga.ini

Beginning removal…

Attempting to delete C:\WINDOWS\system32\aglpmghy.dll
C:\WINDOWS\system32\aglpmghy.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ayehqpjg.dll
C:\WINDOWS\system32\ayehqpjg.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\bpvmglhm.dll
C:\WINDOWS\system32\bpvmglhm.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\chehpfje.ini
C:\WINDOWS\system32\chehpfje.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\ckpgmuyo.dll
C:\WINDOWS\system32\ckpgmuyo.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\cleittsf.dll
C:\WINDOWS\system32\cleittsf.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\duymbxrr.dll
C:\WINDOWS\system32\duymbxrr.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ejfphehc.dll
C:\WINDOWS\system32\ejfphehc.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\eugvgugh.dll
C:\WINDOWS\system32\eugvgugh.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\fxmgxgjq.dll
C:\WINDOWS\system32\fxmgxgjq.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\jocmswqs.dll
C:\WINDOWS\system32\jocmswqs.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\mhlgmvpb.ini
C:\WINDOWS\system32\mhlgmvpb.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\NCTAudioCDGrabber2.dll
C:\WINDOWS\system32\NCTAudioCDGrabber2.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\NCTAudioFile2.dll
C:\WINDOWS\system32\NCTAudioFile2.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\NCTAudioPlayer2.dll
C:\WINDOWS\system32\NCTAudioPlayer2.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\NCTAudioRecord2.dll
C:\WINDOWS\system32\NCTAudioRecord2.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\NCTAVIFile.dll
C:\WINDOWS\system32\NCTAVIFile.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\NCTQuickTimeFile.dll
C:\WINDOWS\system32\NCTQuickTimeFile.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\NCTVideoCoreM.dll
C:\WINDOWS\system32\NCTVideoCoreM.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\NCTWMAFile2.dll
C:\WINDOWS\system32\NCTWMAFile2.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\nshnjojw.dll
C:\WINDOWS\system32\nshnjojw.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\odsqvjrh.dll
C:\WINDOWS\system32\odsqvjrh.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\otfjtkut.dll
C:\WINDOWS\system32\otfjtkut.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\pqgswenb.dll
C:\WINDOWS\system32\pqgswenb.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\qhanycmn.dll
C:\WINDOWS\system32\qhanycmn.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\qjkching.dll
C:\WINDOWS\system32\qjkching.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\rrtsficf.dll
C:\WINDOWS\system32\rrtsficf.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\rrxbmyud.ini
C:\WINDOWS\system32\rrxbmyud.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\saxbehyi.dll
C:\WINDOWS\system32\saxbehyi.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\sstqn.dll
C:\WINDOWS\system32\sstqn.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\tiuhqkgo.dll
C:\WINDOWS\system32\tiuhqkgo.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\wvgghacm.dll
C:\WINDOWS\system32\wvgghacm.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\xkbwgabl.dll
C:\WINDOWS\system32\xkbwgabl.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\yhgmplga.ini
C:\WINDOWS\system32\yhgmplga.ini Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.7.7

Checking Java version…

Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.

Scan started at 23:07:02 21/12/2007

Listing files found while scanning….

C:\WINDOWS\system32\fcjsqmlg.ini
C:\WINDOWS\system32\glmqsjcf.dll
C:\WINDOWS\system32\mljgf.dll
C:\WINDOWS\system32\nupplehw.dll
C:\windows\system32\pidywgho.dll
C:\windows\system32\pidywgho.dllbox

Beginning removal…

Attempting to delete C:\WINDOWS\system32\fcjsqmlg.ini
C:\WINDOWS\system32\fcjsqmlg.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\glmqsjcf.dll
C:\WINDOWS\system32\glmqsjcf.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\mljgf.dll
C:\WINDOWS\system32\mljgf.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\nupplehw.dll
C:\WINDOWS\system32\nupplehw.dll Has been deleted!

Attempting to delete C:\windows\system32\pidywgho.dll
C:\windows\system32\pidywgho.dll Has been deleted!

Attempting to delete C:\windows\system32\pidywgho.dllbox
C:\windows\system32\pidywgho.dllbox Has been deleted!

Performing Repairs to the registry.
Done!
_________________________________________________________

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.527 [GMT 1:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\fgjlm.bak1
C:\WINDOWS\system32\fgjlm.bak2
C:\WINDOWS\system32\fgjlm.ini
C:\WINDOWS\system32\tuvurqp.dll
C:\WINDOWS\system32\vtsqo.dll
C:\WINDOWS\system32\yyadd.bak1
C:\WINDOWS\system32\yyadd.bak2
C:\WINDOWS\system32\yyadd.ini
C:\WINDOWS\system32\yyadd.ini2
C:\WINDOWS\system32\yyadd.tmp

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_DOMAINSERVICE


((((((((((((((((((((((((( Files Created from 2007-11-21 to 2007-12-21 )))))))))))))))))))))))))))))))
.

2007-12-21 23:40 . 2007-12-21 23:40 24,576 –a—— C:\WINDOWS\system32\VundoFixSVC.exe
2007-12-20 19:48 . 2007-12-20 19:48 d——– C:\Program Files\Trend Micro
2007-12-20 19:08 . 2007-12-20 19:08 165,472 –a—— C:\WINDOWS\system32\mevkxrpy.dll
2007-12-19 22:32 . 2007-12-19 22:32 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-12-19 22:32 . 2007-12-19 22:32 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-12-19 22:22 . 2007-12-22 00:20 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-19 21:17 . 2007-12-21 23:06 d——– C:\VundoFix Backups
2007-12-19 17:54 . 2007-12-19 18:32 d——– C:\Documents and Settings\Nico\Application Data\PrevxCSI
2007-12-19 17:54 . 2007-12-19 17:54 d——– C:\Documents and Settings\All Users\Application Data\Prevx
2007-12-17 10:50 . 2007-12-17 10:50 d——– C:\Documents and Settings\Nico and Jane\Application Data\DivX
2007-12-10 23:53 . 2007-12-20 19:34 d——– C:\Program Files\Spyware Doctor
2007-12-10 23:53 . 2007-12-10 23:53 d——– C:\Documents and Settings\Nico\Application Data\PC Tools
2007-12-10 23:53 . 2005-09-23 08:29 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-12-10 23:53 . 2007-12-19 21:25 74,240 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2007-12-10 23:53 . 2007-12-19 21:25 56,832 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2007-12-10 23:53 . 2007-10-18 00:14 41,288 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-12-10 23:53 . 2007-10-18 00:16 29,000 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2007-12-10 23:43 . 2007-12-11 00:04 859,881 –ahs—- C:\WINDOWS\system32\lbagwbkx.ini
2007-12-10 22:21 . 2007-12-10 23:39 859,794 –ahs—- C:\WINDOWS\system32\xahqmkoj.ini
2007-12-10 20:57 . 2007-12-10 22:20 859,692 –ahs—- C:\WINDOWS\system32\efqllbyn.ini
2007-12-10 10:08 . 2007-12-10 22:13 841,196 –ahs—- C:\WINDOWS\system32\mcahggvw.ini
2007-12-09 16:32 . 2007-12-09 16:32 834,100 –ahs—- C:\WINDOWS\system32\qjgxgmxf.ini
2007-12-07 17:56 . 2007-12-19 21:07 244 –a—— C:\WINDOWS\wininit.ini
2007-12-07 00:00 . 2007-12-21 00:58 1,252 –a—— C:\error.htm
2007-12-07 00:00 . 2007-12-21 00:00 0 –a—— C:\infect.htm
2007-12-06 13:18 . 2007-12-06 13:18 28,672 –a—— C:\WINDOWS\system32\drivers\CO_Mon.sys
2007-12-06 12:56 . 2007-12-10 20:55 955,540 –ahs—- C:\WINDOWS\system32\xvquolcw.ini
2007-12-06 12:42 . 2007-12-10 23:18 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-06 12:39 . 2007-12-06 12:54 808,008 –ahs—- C:\WINDOWS\system32\nileaxhm.ini
2007-12-06 12:14 . 2007-12-06 12:35 807,888 –ahs—- C:\WINDOWS\system32\spljbnvk.ini
2007-12-05 11:26 . 2007-12-06 12:13 669,232 –ahs—- C:\WINDOWS\system32\xvqrkjjs.ini
2007-12-05 09:55 . 2007-12-05 11:25 668,992 –ahs—- C:\WINDOWS\system32\ygqeimkc.ini
2007-12-04 01:46 . 2007-12-04 01:46 793,980 –ahs—- C:\WINDOWS\system32\lebypayu.ini
2007-12-03 13:54 . 2007-12-03 13:54 dr-h—– C:\Documents and Settings\Nico\Application Data\SecuROM
2007-12-03 13:52 . 2004-12-10 10:06 327,680 –a—— C:\WINDOWS\system32\vp6dec.ax
2007-12-03 13:52 . 2007-04-12 15:01 118,832 –a—— C:\WINDOWS\system32\SHW32.DLL
2007-12-03 13:47 . 2006-11-29 13:06 3,426,072 –a—— C:\WINDOWS\system32\d3dx9_32.dll
2007-12-03 13:47 . 2007-01-24 15:27 255,848 –a—— C:\WINDOWS\system32\xactengine2_6.dll
2007-12-03 13:47 . 2006-12-08 12:02 251,672 –a—— C:\WINDOWS\system32\xactengine2_5.dll
2007-12-03 13:46 . 2006-09-28 16:05 2,414,360 –a—— C:\WINDOWS\system32\d3dx9_31.dll
2007-12-03 13:46 . 2006-09-28 16:05 237,848 –a—— C:\WINDOWS\system32\xactengine2_4.dll
2007-12-03 13:46 . 2006-07-28 09:30 236,824 –a—— C:\WINDOWS\system32\xactengine2_3.dll
2007-12-03 13:46 . 2006-09-28 16:04 68,888 –a—— C:\WINDOWS\system32\xinput1_3.dll
2007-12-03 13:46 . 2006-07-28 09:30 62,744 –a—— C:\WINDOWS\system32\xinput1_2.dll
2007-12-03 13:46 . 2007-01-08 15:30 15,128 –a—— C:\WINDOWS\system32\x3daudio1_1.dll
2007-12-03 13:40 . 2007-12-03 13:40 37,888 –a—— C:\WINDOWS\system32\mljhfcd.dll.bak
2007-12-03 13:07 . 2007-08-24 11:00 172,032 –a—— C:\WINDOWS\system32\igfxres.dll
2007-12-02 13:06 . 2007-12-02 13:06 d——– C:\Program Files\SystemRequirementsLab
2007-12-02 12:50 . 2007-08-24 11:22 5,776,928 –a—— C:\WINDOWS\system32\drivers\igxpmp32.sys
2007-12-02 12:50 . 2007-08-24 11:23 2,575,360 –a—— C:\WINDOWS\system32\igxpdx32.dll
2007-12-02 12:50 . 2007-08-24 11:23 1,615,808 –a—— C:\WINDOWS\system32\igxpdv32.dll
2007-12-02 12:50 . 2007-08-24 11:03 176,128 –a—— C:\WINDOWS\system32\igfxrsky.lrc
2007-12-02 12:50 . 2007-08-24 11:03 172,032 –a—— C:\WINDOWS\system32\igfxrslv.lrc
2007-12-02 12:50 . 2007-08-24 11:22 150,528 –a—— C:\WINDOWS\system32\igxpgd32.dll
2007-12-02 12:50 . 2007-08-24 11:29 147,456 –a—— C:\WINDOWS\system32\igfxCoIn_v4864.dll
2007-12-02 12:50 . 2007-08-24 11:22 57,344 –a—— C:\WINDOWS\system32\igxprd32.dll
2007-12-02 12:49 . 2007-09-10 09:15 920,088 –a—— C:\WINDOWS\system32\igxpun.exe
2007-12-02 12:36 . 2007-12-03 13:54 107,888 –a—— C:\WINDOWS\system32\CmdLineExt.dll
2007-12-02 11:58 . 2007-12-02 11:58 d——– C:\Program Files\PowerISO
2007-11-25 22:00 . 2007-11-27 00:04 d——– C:\Documents and Settings\All Users\Application Data\OrbNetworks
2007-11-25 19:13 . 2007-11-25 19:15 d——– C:\Program Files\UnZixWin
2007-11-25 19:13 . 2007-11-25 19:13 249,856 ——— C:\WINDOWS\Setup1.exe
2007-11-25 19:13 . 2007-11-25 19:13 73,216 –a—— C:\WINDOWS\ST6UNST.EXE
2007-11-23 12:03 . 2007-11-23 12:03 d——– C:\Documents and Settings\LocalService\Application Data\DivX
2007-11-22 21:18 . 2007-11-25 13:25 d——– C:\Documents and Settings\Nico\Application Data\DivX
2007-11-22 20:25 . 2007-11-22 21:20 d——– C:\Program Files\DivX
2007-11-22 19:00 . 2007-11-22 19:00 d——– C:\Program Files\MCE
2007-11-22 19:00 . 2007-12-20 21:16 d——– C:\Documents and Settings\All Users\Application Data\My Movies
2007-11-22 01:53 . 2007-11-22 01:53 d——– C:\Program Files\Zattoo
2007-11-22 00:22 . 2007-12-06 10:17 d——– C:\Program Files\Pick-a-Proxy Toolbar
2007-11-21 22:02 . 2007-11-24 15:53 32 –a—— C:\WINDOWS\go
2007-11-21 18:59 . 2007-11-21 19:55 d——– C:\Program Files\ProxyWay
2007-11-21 18:03 . 2007-11-21 18:03 d——– C:\Program Files\uTorrent
2007-11-21 18:03 . 2007-12-20 01:06 d——– C:\Documents and Settings\Nico\Application Data\uTorrent
2007-11-21 16:59 . 2007-11-21 17:02 d——– C:\Documents and Settings\Nico\Application Data\Move Networks
2007-11-21 16:46 . 2007-07-04 03:04 888,832 –a—— C:\WINDOWS\system32\securenet.dll
2007-11-21 15:57 . 2007-11-21 15:57 62 –a—— C:\WINDOWS\MyProg.ini
2007-11-21 14:26 . 2007-11-21 14:26 d——– C:\Documents and Settings\Nico\Application Data\FreeCap
2007-11-21 14:24 . 2007-11-21 14:24 d——– C:\Program Files\NetConeal
2007-11-21 14:24 . 2007-12-06 10:17 125 –a—— C:\ioSpecial.ini
2007-11-21 14:15 . 2007-11-21 14:15 d——– C:\Program Files\Common Files\Download Manager

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-19 08:00 ——— d—–w C:\Documents and Settings\Nico and Jane\Application Data\Skype
2007-12-10 22:13 ——— d—–w C:\Documents and Settings\Nico\Application Data\Warez
2007-12-03 13:36 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-28 12:14 ——— d—–w C:\Documents and Settings\Nico\Application Data\Skype
2007-11-26 21:17 ——— d—–w C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-11-25 21:00 ——— d—–w C:\Program Files\Orb Networks
2007-11-23 23:24 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2007-11-23 23:24 ——— d—–w C:\Documents and Settings\All Users\Application Data\PC Suite
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-09-16 21:43 251 —-a-w C:\Program Files\wt3d.ini
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B5E0B630-CE27-4F05-903E-CEC7E55A7760}]
C:\WINDOWS\system32\mljgf.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 21:00]
"updateMgr"="c:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 15:45]
"ProxyWay"="C:\Program Files\ProxyWay\proxyway.exe" []
"kdx"="C:\WINDOWS\kdx\KHost.exe" [2007-05-11 08:46]
"eyeBeam SIP Client"="" []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"YBrowser"="C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe" [2003-12-09 12:03]
"VFDTranscoder"="C:\WINDOWS\eHome\VFDTranscoder.exe" [2006-04-19 23:12]
"Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-11 04:19]
"RTHDCPL"="RTHDCPL.EXE" [2006-04-04 16:44 C:\WINDOWS\RTHDCPL.exe]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 15:57]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2007-04-09 13:23]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-10 21:00]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-10 21:00]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2007-08-24 11:00]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 12:20]
"OWCWebCamDV"="C:\WINDOWS\system\wcdvtray.exe" [2004-05-20 08:59]
"News Service"="C:\Program Files\F-Secure Internet Security\FSGUI\ispnews.exe" [2005-05-31 13:45]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-10 21:00]
"LaunchApp"="Alaunch" []
"IndexSearch"="C:\Program Files\Scansoft\PaperPort\IndexSearch.exe" [2002-09-23 09:50]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-10 21:00]
"ImageItEncrypt"="C:\WINDOWS\system32\ImageItEncrypt.exe" [2005-12-30 22:02]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2007-08-24 11:01]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-02-21 17:59]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2007-08-24 11:01]
"FlashIcon"="C:\Program Files\Generic\USB Card Reader Utility v1.3\FlashIcon.exe" [2006-04-07 12:15]
"F-Secure TNB"="C:\Program Files\F-Secure Internet Security\TNB\TNBUtil.exe" [2005-07-18 15:51]
"F-Secure Startup Wizard"="C:\Program Files\F-Secure Internet Security\FSGUI\FSSW.exe" [2005-10-18 09:29]
"F-Secure Manager"="C:\Program Files\F-Secure Internet Security\Common\FSM32.exe" [2005-10-26 02:51]
"eRecoveryService"="C:\Acer\Empowering Technology\eRecovery\eRAgent.exe" [2006-03-30 23:18]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-29 22:01]
"AzMixerSel"="C:\Program Files\Realtek\InstallShield\AzMixerSel.exe" [2006-01-25 17:45]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 00:19 C:\WINDOWS\arpwrmsg.exe]
"Acer Empowering Technology Monitor"="C:\WINDOWS\system32\SysMonitor.exe" [2006-04-19 03:54]
"70e51637"="C:\WINDOWS\system32\jokmqhax.dll" []
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-11-02 17:24]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Orb"="C:\Program Files\Orb Networks\Orb\bin\OrbTray.exe" [2007-11-02 20:04]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 21:00]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 14:58]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2005-04-25 13:45]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26]
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-01-17 18:45:32]
F-Secure 2006.lnk - C:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe [2007-04-25 22:34:51]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoSMBalloonTip"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljhfcd]
mljhfcd.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

R0 FSFW;F-Secure Firewall Driver;C:\WINDOWS\system32\drivers\fsdfw.sys [2005-11-18 16:04]
R2 BackWeb Plug-in - 4476822;F-Secure 2006;C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE [2007-04-25 22:34]
R2 F-Secure Filter;F-Secure File System Filter;C:\Program Files\F-Secure Internet Security\Anti-Virus\Win2K\FSfilter.sys [2004-09-10 16:14]
R2 F-Secure Gatekeeper;F-Secure Gatekeeper;C:\Program Files\F-Secure Internet Security\Anti-Virus\Win2K\FSgk.sys [2007-06-02 15:13]
R2 F-Secure Recognizer;F-Secure File System Recognizer;C:\Program Files\F-Secure Internet Security\Anti-Virus\Win2K\FSrec.sys [2004-06-01 10:03]
R2 WebCamDV;WebCamDV DV to Webcam Converter;C:\WINDOWS\system32\DRIVERS\WebCamDV.sys [2004-05-11 06:27]
R3 arkbcfltr;Microsoft PS2 Keyboard Filter;C:\WINDOWS\system32\DRIVERS\arkbcfltr.sys [2005-08-03 00:19]
R3 armoucfltr;Microsoft PS2 Mouse Filter;C:\WINDOWS\system32\DRIVERS\armoucfltr.sys [2005-08-03 00:19]
R3 CXRAPTOR;MPC718 Video Capture ;C:\WINDOWS\system32\drivers\cxraptor.sys [2006-05-05 17:56]
R3 filter;filter;C:\WINDOWS\system32\drivers\filter.sys [2006-04-19 03:12]
R3 int15.sys;int15.sys;C:\Acer\Empowering Technology\eRecovery\int15.sys [2005-01-13 22:46]
R3 WCDV_Aud;WevCamDV WDM Virtual Audio Device;C:\WINDOWS\system32\drivers\wcdvaud.sys [2004-01-30 13:08]
S3 LVUSBSta;Logitech USB Monitor Filter;C:\WINDOWS\system32\drivers\lvusbsta.sys [2006-06-22 15:29]
S3 MPE;BDA MPE Filter;C:\WINDOWS\system32\DRIVERS\MPE.sys [2004-08-04 07:10]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{74c9a805-7251-11dc-9440-000ae493827f}]
\Shell\AutoRun\command - F:\setupSNK.exe

.
Contents of the 'Scheduled Tasks' folder
"2007-12-20 21:52:12 C:\WINDOWS\Tasks\BRP.job"
- C:\WINDOWS\ehome\BladeRunnerPro\BladeRunner.exe
"2007-12-21 23:13:29 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2007-12-21 08:40:36 C:\WINDOWS\Tasks\Scheduled scanning task.job"
- C:\PROGRA~1\F-SECU~1\ANTI-V~1\fsav.exeZ /HARD /ARCHIVE /DISINF /SCHED /NOBREAK /REPORT=C:\PROGRA~1\F-SECU~1\ANTI-V~1\report.txt
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-22 00:21:10
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwClose

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-22 0:22:44 - machine was rebooted
.
2007-12-20 18:24:37 — E O F —
________________________________________________________________

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:23:58, on 22/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\FSGK32.EXE
C:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe
C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
C:\Program Files\F-Secure Internet Security\Common\FSMB32.EXE
C:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\F-Secure Internet Security\Common\FCH32.EXE
C:\Program Files\KService\KService.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\F-Secure Internet Security\Common\FAMEH32.EXE
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsqh.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsrw.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsav32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\WINDOWS\eHome\VFDTranscoder.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\WINDOWS\system\wcdvtray.exe
C:\Program Files\F-Secure Internet Security\FSGUI\ispnews.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\WINDOWS\system32\SysMonitor.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\F-SECU~1\ANTI-S~1\fsaw.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\kdx\KHost.exe
C:\Program Files\F-Secure Internet Security\FSGUI\fsguidll.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe
C:\Program Files\PC Connectivity Solution\NclBTHandler.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/customi…fo/bt_side.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.red.clientapps.yahoo.com/customi…arch.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.aceradvantage.com/stdreg
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 66.98.238.8:3128
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local;
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: (no name) - {B5E0B630-CE27-4F05-903E-CEC7E55A7760} - C:\WINDOWS\system32\mljgf.dll (file missing)
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [VFDTranscoder] C:\WINDOWS\eHome\VFDTranscoder.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [OWCWebCamDV] C:\WINDOWS\system\wcdvtray.exe
O4 - HKLM\..\Run: [News Service] "C:\Program Files\F-Secure Internet Security\FSGUI\ispnews.exe"
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [ImageItEncrypt] C:\WINDOWS\system32\ImageItEncrypt.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [FlashIcon] "C:\Program Files\Generic\USB Card Reader Utility v1.3\FlashIcon.exe"
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure Internet Security\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\F-Secure Internet Security\FSGUI\FSSW.EXE" /reboot
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\WINDOWS\system32\SysMonitor.exe
O4 - HKLM\..\Run: [70e51637] rundll32.exe "C:\WINDOWS\system32\jokmqhax.dll",b
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] c:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [ProxyWay] C:\Program Files\ProxyWay\proxyway.exe
O4 - HKCU\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe -all
O4 - HKUS\S-1-5-18\..\Run: [Orb] "C:\Program Files\Orb Networks\Orb\bin\OrbTray.exe" /background (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Orb] "C:\Program Files\Orb Networks\Orb\bin\OrbTray.exe" /background (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: F-Secure 2006.lnk = C:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure Internet Security\Anti-Spyware\blockpopups.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\Anti-Spyware\ieshield.dll
O9 - Extra 'Tools' menuitem: IE Shield… - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\Anti-Spyware\ieshield.dll
O9 - Extra button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {3F14D76D-8C1A-47CA-A2CB-34982BCD44DE} (OutlookYearView.YearPlan) - file:///D:/OutlookYearView.CAB
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1160519841906
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.1.6.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\mcePhone\Skype4COM.dll
O20 - Winlogon Notify: mljhfcd - mljhfcd.dll (file missing)
O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: F-Secure 2006 (BackWeb Plug-in - 4476822) - F-Secure Internet Security 2005 - C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\KService\KService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

–
End of file - 15577 bytes
Hi


Download Flash_Disinfector from here and save it to your desktop.
Doubleclick on Flash_Disinfector.exe to run it and follow the prompts.
Wait until it has finished scanning and then exit the program.
The utility may ask you to insert your flash drive and/or other removable drives. This may include your mobile phone.
Please do so and allow the utility to clean up those drives as well.

Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back in your next reply.

After you have run the above, run Combofix again and post the new log it generates, please.
The legendary Scotty!

I have finally managed to do what you asked! The ComboFix kept stopping at stage 3, I think it was because of Spyware Doctor which I thought I had disabled!!

Anyway, the external hard drive works now on each USB….. Thanks a million.

There is still the RUNDLL message on start up, along with a 'WINDOWS - NO DISK' box (some kind of parameter error) which appears 3 times with cancel pressed each time?!

Here are the logs you asked for:


SDFix: Version 1.119

Run by [removed] on 22/12/2007 at 01:53

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\DOCUME~1\Nico\Desktop\VIRUSH~1\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting…


Normal Mode:
Checking Files:

Trojan Files Found:



Could Not Remove C:\autorun.inf


Removing Temp Files…

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

catchme 0.3.1333.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-22 01:58:36
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwClose

scanning hidden processes …

scanning hidden services & system hive …

scanning hidden registry entries …

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\\xd8\x2022\x20ac|\xff\xff\xff\xff\22\x2022\x20ac|\xf9\x2022\xd4w\2]
"5E7CEC10DF0760D4F8DAFB12FDC06CCD"=""

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services:
——————



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

Remaining Files:
—————
C:\autorun.inf Found

File Backups: - C:\DOCUME~1\Nico\Desktop\VIRUSH~1\SDFix\backups\backups.zip

Files with Hidden Attributes:

Thu 9 Aug 2007 1,024 A..HR — "C:\WINDOWS\system32\NTIBUN4.dll"
Thu 9 Aug 2007 1,024 A..HR — "C:\WINDOWS\system32\NTICDMK7.dll"
Thu 27 Apr 2006 1,024 A..HR — "C:\WINDOWS\system32\NTIFCD3.dll"
Thu 9 Aug 2007 1,024 A..HR — "C:\WINDOWS\system32\NTIMP3.dll"
Thu 9 Aug 2007 1,024 A..HR — "C:\WINDOWS\system32\NTIMPEG2.dll"
Sat 16 Sep 2006 4,348 A.SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Tue 23 Jan 2007 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Tue 27 Nov 2007 113,491,064 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\ab59ac72525ea90a47679441587835c9\BIT24.tmp"

Finished!
__________________________________________________________________

ComboFix 07-12-21.4 - Nico 2007-12-22 9:46:42.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.530 [GMT 1:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2007-11-22 to 2007-12-22 )))))))))))))))))))))))))))))))
.

2007-12-22 01:53 . 2007-12-22 01:53 d——– C:\WINDOWS\ERUNT
2007-12-21 23:40 . 2007-12-21 23:40 24,576 –a—— C:\WINDOWS\system32\VundoFixSVC.exe
2007-12-20 19:48 . 2007-12-20 19:48 d——– C:\Program Files\Trend Micro
2007-12-20 19:08 . 2007-12-20 19:08 165,472 –a—— C:\WINDOWS\system32\mevkxrpy.dll
2007-12-19 22:32 . 2007-12-19 22:32 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-12-19 22:32 . 2007-12-19 22:32 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-12-19 22:22 . 2007-12-22 09:34 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-19 21:17 . 2007-12-21 23:06 d——– C:\VundoFix Backups
2007-12-19 17:54 . 2007-12-19 18:32 d——– C:\Documents and Settings\Nico\Application Data\PrevxCSI
2007-12-19 17:54 . 2007-12-19 17:54 d——– C:\Documents and Settings\All Users\Application Data\Prevx
2007-12-17 10:50 . 2007-12-17 10:50 d——– C:\Documents and Settings\Nico and Jane\Application Data\DivX
2007-12-10 23:53 . 2007-12-20 19:34 d——– C:\Program Files\Spyware Doctor
2007-12-10 23:53 . 2007-12-10 23:53 d——– C:\Documents and Settings\Nico\Application Data\PC Tools
2007-12-10 23:53 . 2005-09-23 08:29 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-12-10 23:53 . 2007-12-19 21:25 74,240 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2007-12-10 23:53 . 2007-12-19 21:25 56,832 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2007-12-10 23:53 . 2007-10-18 00:14 41,288 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-12-10 23:53 . 2007-10-18 00:16 29,000 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2007-12-10 23:43 . 2007-12-11 00:04 859,881 –ahs—- C:\WINDOWS\system32\lbagwbkx.ini
2007-12-10 22:21 . 2007-12-10 23:39 859,794 –ahs—- C:\WINDOWS\system32\xahqmkoj.ini
2007-12-10 20:57 . 2007-12-10 22:20 859,692 –ahs—- C:\WINDOWS\system32\efqllbyn.ini
2007-12-10 10:08 . 2007-12-10 22:13 841,196 –ahs—- C:\WINDOWS\system32\mcahggvw.ini
2007-12-09 16:32 . 2007-12-09 16:32 834,100 –ahs—- C:\WINDOWS\system32\qjgxgmxf.ini
2007-12-07 17:56 . 2007-12-19 21:07 244 –a—— C:\WINDOWS\wininit.ini
2007-12-07 00:00 . 2007-12-21 00:58 1,252 –a—— C:\error.htm
2007-12-07 00:00 . 2007-12-21 00:00 0 –a—— C:\infect.htm
2007-12-06 13:18 . 2007-12-06 13:18 28,672 –a—— C:\WINDOWS\system32\drivers\CO_Mon.sys
2007-12-06 12:56 . 2007-12-10 20:55 955,540 –ahs—- C:\WINDOWS\system32\xvquolcw.ini
2007-12-06 12:42 . 2007-12-10 23:18 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-06 12:39 . 2007-12-06 12:54 808,008 –ahs—- C:\WINDOWS\system32\nileaxhm.ini
2007-12-06 12:14 . 2007-12-06 12:35 807,888 –ahs—- C:\WINDOWS\system32\spljbnvk.ini
2007-12-05 11:26 . 2007-12-06 12:13 669,232 –ahs—- C:\WINDOWS\system32\xvqrkjjs.ini
2007-12-05 09:55 . 2007-12-05 11:25 668,992 –ahs—- C:\WINDOWS\system32\ygqeimkc.ini
2007-12-04 01:46 . 2007-12-04 01:46 793,980 –ahs—- C:\WINDOWS\system32\lebypayu.ini
2007-12-03 13:54 . 2007-12-03 13:54 dr-h—– C:\Documents and Settings\Nico\Application Data\SecuROM
2007-12-03 13:52 . 2004-12-10 10:06 327,680 –a—— C:\WINDOWS\system32\vp6dec.ax
2007-12-03 13:52 . 2007-04-12 15:01 118,832 –a—— C:\WINDOWS\system32\SHW32.DLL
2007-12-03 13:47 . 2006-11-29 13:06 3,426,072 –a—— C:\WINDOWS\system32\d3dx9_32.dll
2007-12-03 13:47 . 2007-01-24 15:27 255,848 –a—— C:\WINDOWS\system32\xactengine2_6.dll
2007-12-03 13:47 . 2006-12-08 12:02 251,672 –a—— C:\WINDOWS\system32\xactengine2_5.dll
2007-12-03 13:46 . 2006-09-28 16:05 2,414,360 –a—— C:\WINDOWS\system32\d3dx9_31.dll
2007-12-03 13:46 . 2006-09-28 16:05 237,848 –a—— C:\WINDOWS\system32\xactengine2_4.dll
2007-12-03 13:46 . 2006-07-28 09:30 236,824 –a—— C:\WINDOWS\system32\xactengine2_3.dll
2007-12-03 13:46 . 2006-09-28 16:04 68,888 –a—— C:\WINDOWS\system32\xinput1_3.dll
2007-12-03 13:46 . 2006-07-28 09:30 62,744 –a—— C:\WINDOWS\system32\xinput1_2.dll
2007-12-03 13:46 . 2007-01-08 15:30 15,128 –a—— C:\WINDOWS\system32\x3daudio1_1.dll
2007-12-03 13:40 . 2007-12-03 13:40 37,888 –a—— C:\WINDOWS\system32\mljhfcd.dll.bak
2007-12-03 13:07 . 2007-08-24 11:00 172,032 –a—— C:\WINDOWS\system32\igfxres.dll
2007-12-02 13:06 . 2007-12-02 13:06 d——– C:\Program Files\SystemRequirementsLab
2007-12-02 12:50 . 2007-08-24 11:22 5,776,928 –a—— C:\WINDOWS\system32\drivers\igxpmp32.sys
2007-12-02 12:50 . 2007-08-24 11:23 2,575,360 –a—— C:\WINDOWS\system32\igxpdx32.dll
2007-12-02 12:50 . 2007-08-24 11:23 1,615,808 –a—— C:\WINDOWS\system32\igxpdv32.dll
2007-12-02 12:50 . 2007-08-24 11:03 176,128 –a—— C:\WINDOWS\system32\igfxrsky.lrc
2007-12-02 12:50 . 2007-08-24 11:03 172,032 –a—— C:\WINDOWS\system32\igfxrslv.lrc
2007-12-02 12:50 . 2007-08-24 11:22 150,528 –a—— C:\WINDOWS\system32\igxpgd32.dll
2007-12-02 12:50 . 2007-08-24 11:29 147,456 –a—— C:\WINDOWS\system32\igfxCoIn_v4864.dll
2007-12-02 12:50 . 2007-08-24 11:22 57,344 –a—— C:\WINDOWS\system32\igxprd32.dll
2007-12-02 12:49 . 2007-09-10 09:15 920,088 –a—— C:\WINDOWS\system32\igxpun.exe
2007-12-02 12:36 . 2007-12-03 13:54 107,888 –a—— C:\WINDOWS\system32\CmdLineExt.dll
2007-12-02 11:58 . 2007-12-02 11:58 d——– C:\Program Files\PowerISO
2007-11-25 22:00 . 2007-11-27 00:04 d——– C:\Documents and Settings\All Users\Application Data\OrbNetworks
2007-11-25 19:13 . 2007-11-25 19:15 d——– C:\Program Files\UnZixWin
2007-11-25 19:13 . 2007-11-25 19:13 249,856 ——— C:\WINDOWS\Setup1.exe
2007-11-25 19:13 . 2007-11-25 19:13 73,216 –a—— C:\WINDOWS\ST6UNST.EXE
2007-11-23 12:03 . 2007-11-23 12:03 d——– C:\Documents and Settings\LocalService\Application Data\DivX
2007-11-22 21:18 . 2007-11-25 13:25 d——– C:\Documents and Settings\Nico\Application Data\DivX
2007-11-22 20:25 . 2007-11-22 21:20 d——– C:\Program Files\DivX
2007-11-22 19:00 . 2007-11-22 19:00 d——– C:\Program Files\MCE
2007-11-22 19:00 . 2007-12-20 21:16 d——– C:\Documents and Settings\All Users\Application Data\My Movies
2007-11-22 01:53 . 2007-11-22 01:53 d——– C:\Program Files\Zattoo
2007-11-22 00:22 . 2007-12-06 10:17 d——– C:\Program Files\Pick-a-Proxy Toolbar

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-20 00:06 ——— d—–w C:\Documents and Settings\Nico\Application Data\uTorrent
2007-12-19 08:00 ——— d—–w C:\Documents and Settings\Nico and Jane\Application Data\Skype
2007-12-10 22:13 ——— d—–w C:\Documents and Settings\Nico\Application Data\Warez
2007-12-03 13:36 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-28 12:14 ——— d—–w C:\Documents and Settings\Nico\Application Data\Skype
2007-11-26 21:17 ——— d—–w C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-11-25 21:00 ——— d—–w C:\Program Files\Orb Networks
2007-11-23 23:24 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2007-11-23 23:24 ——— d—–w C:\Documents and Settings\All Users\Application Data\PC Suite
2007-11-21 18:55 ——— d—–w C:\Program Files\ProxyWay
2007-11-21 17:03 ——— d—–w C:\Program Files\uTorrent
2007-11-21 16:02 ——— d—–w C:\Documents and Settings\Nico\Application Data\Move Networks
2007-11-21 13:26 ——— d—–w C:\Documents and Settings\Nico\Application Data\FreeCap
2007-11-21 13:24 ——— d—–w C:\Program Files\NetConeal
2007-11-21 13:15 ——— d—–w C:\Program Files\Common Files\Download Manager
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-29 22:35 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-27 16:40 222,720 —-a-w C:\WINDOWS\system32\wmasf.dll
2007-10-20 00:56 524,288 —-a-w C:\WINDOWS\system32\DivXsm.exe
2007-10-20 00:56 3,596,288 —-a-w C:\WINDOWS\system32\qt-dx331.dll
2007-10-20 00:56 200,704 —-a-w C:\WINDOWS\system32\ssldivx.dll
2007-10-20 00:56 1,044,480 —-a-w C:\WINDOWS\system32\libdivx.dll
2007-10-20 00:54 823,296 —-a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-10-20 00:54 823,296 —-a-w C:\WINDOWS\system32\divx_xx07.dll
2007-10-20 00:54 81,920 —-a-w C:\WINDOWS\system32\dpl100.dll
2007-10-20 00:54 802,816 —-a-w C:\WINDOWS\system32\divx_xx11.dll
2007-10-20 00:54 739,840 —-a-w C:\WINDOWS\system32\DivX.dll
2007-10-20 00:54 196,608 —-a-w C:\WINDOWS\system32\dtu100.dll
2007-10-18 09:06 156,992 —-a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-10-18 09:03 593,920 —-a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-10-18 09:03 57,344 —-a-w C:\WINDOWS\system32\dpv11.dll
2007-10-18 09:03 53,248 —-a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-10-18 09:03 344,064 —-a-w C:\WINDOWS\system32\dpus11.dll
2007-10-18 09:03 294,912 —-a-w C:\WINDOWS\system32\dpu11.dll
2007-10-18 09:03 294,912 —-a-w C:\WINDOWS\system32\dpu10.dll
2007-10-18 09:02 12,288 —-a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-09-16 21:43 251 —-a-w C:\Program Files\wt3d.ini
.

((((((((((((((((((((((((((((( snapshot@2007-12-22_ 0.22.07.35 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-12-20 12:08:37 163,328 —-a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2007-12-22 00:53:10 7,172,096 —-a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000001\ntuser.dat
+ 2007-12-22 00:53:10 151,552 —-a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2007-12-20 12:08:37 163,328 —-a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2007-12-22 00:53:08 7,172,096 —-a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000001\ntuser.dat
+ 2007-12-22 00:53:08 151,552 —-a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
+ 2007-12-22 08:33:35 16,384 —-atw C:\WINDOWS\TEMP\Perflib_Perfdata_634.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{061FD4C8-798C-420F-8F26-32A0C3BE8FEF}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201CAAD1-1A12-4423-8EA4-579FE9DE4DBD}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 21:00]
"updateMgr"="c:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 15:45]
"ProxyWay"="C:\Program Files\ProxyWay\proxyway.exe" []
"kdx"="C:\WINDOWS\kdx\KHost.exe" [2007-05-11 08:46]
"eyeBeam SIP Client"="" []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"YBrowser"="C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe" [2003-12-09 12:03]
"VFDTranscoder"="C:\WINDOWS\eHome\VFDTranscoder.exe" [2006-04-19 23:12]
"Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-11 04:19]
"RTHDCPL"="RTHDCPL.EXE" [2006-04-04 16:44 C:\WINDOWS\RTHDCPL.exe]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 15:57]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2007-04-09 13:23]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-10 21:00]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-10 21:00]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2007-08-24 11:00]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 12:20]
"OWCWebCamDV"="C:\WINDOWS\system\wcdvtray.exe" [2004-05-20 08:59]
"News Service"="C:\Program Files\F-Secure Internet Security\FSGUI\ispnews.exe" [2005-05-31 13:45]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-10 21:00]
"LaunchApp"="Alaunch" []
"IndexSearch"="C:\Program Files\Scansoft\PaperPort\IndexSearch.exe" [2002-09-23 09:50]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-10 21:00]
"ImageItEncrypt"="C:\WINDOWS\system32\ImageItEncrypt.exe" [2005-12-30 22:02]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2007-08-24 11:01]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-02-21 17:59]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2007-08-24 11:01]
"FlashIcon"="C:\Program Files\Generic\USB Card Reader Utility v1.3\FlashIcon.exe" [2006-04-07 12:15]
"F-Secure TNB"="C:\Program Files\F-Secure Internet Security\TNB\TNBUtil.exe" [2005-07-18 15:51]
"F-Secure Startup Wizard"="C:\Program Files\F-Secure Internet Security\FSGUI\FSSW.exe" [2005-10-18 09:29]
"F-Secure Manager"="C:\Program Files\F-Secure Internet Security\Common\FSM32.exe" [2005-10-26 02:51]
"eRecoveryService"="C:\Acer\Empowering Technology\eRecovery\eRAgent.exe" [2006-03-30 23:18]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-29 22:01]
"AzMixerSel"="C:\Program Files\Realtek\InstallShield\AzMixerSel.exe" [2006-01-25 17:45]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 00:19 C:\WINDOWS\arpwrmsg.exe]
"Acer Empowering Technology Monitor"="C:\WINDOWS\system32\SysMonitor.exe" [2006-04-19 03:54]
"70e51637"="C:\WINDOWS\system32\jokmqhax.dll" []
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-11-02 17:24]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Orb"="C:\Program Files\Orb Networks\Orb\bin\OrbTray.exe" [2007-11-02 20:04]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 21:00]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 14:58]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2005-04-25 13:45]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26]
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-01-17 18:45:32]
F-Secure 2006.lnk - C:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe [2007-04-25 22:34:51]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoSMBalloonTip"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljhfcd]
mljhfcd.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

R0 FSFW;F-Secure Firewall Driver;C:\WINDOWS\system32\drivers\fsdfw.sys [2005-11-18 16:04]
R2 BackWeb Plug-in - 4476822;F-Secure 2006;C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE [2007-04-25 22:34]
R2 F-Secure Filter;F-Secure File System Filter;C:\Program Files\F-Secure Internet Security\Anti-Virus\Win2K\FSfilter.sys [2004-09-10 16:14]
R2 F-Secure Gatekeeper;F-Secure Gatekeeper;C:\Program Files\F-Secure Internet Security\Anti-Virus\Win2K\FSgk.sys [2007-06-02 15:13]
R2 F-Secure Recognizer;F-Secure File System Recognizer;C:\Program Files\F-Secure Internet Security\Anti-Virus\Win2K\FSrec.sys [2004-06-01 10:03]
R2 WebCamDV;WebCamDV DV to Webcam Converter;C:\WINDOWS\system32\DRIVERS\WebCamDV.sys [2004-05-11 06:27]
R3 arkbcfltr;Microsoft PS2 Keyboard Filter;C:\WINDOWS\system32\DRIVERS\arkbcfltr.sys [2005-08-03 00:19]
R3 armoucfltr;Microsoft PS2 Mouse Filter;C:\WINDOWS\system32\DRIVERS\armoucfltr.sys [2005-08-03 00:19]
R3 CXRAPTOR;MPC718 Video Capture ;C:\WINDOWS\system32\drivers\cxraptor.sys [2006-05-05 17:56]
R3 filter;filter;C:\WINDOWS\system32\drivers\filter.sys [2006-04-19 03:12]
R3 int15.sys;int15.sys;C:\Acer\Empowering Technology\eRecovery\int15.sys [2005-01-13 22:46]
R3 WCDV_Aud;WevCamDV WDM Virtual Audio Device;C:\WINDOWS\system32\drivers\wcdvaud.sys [2004-01-30 13:08]
S3 LVUSBSta;Logitech USB Monitor Filter;C:\WINDOWS\system32\drivers\lvusbsta.sys [2006-06-22 15:29]
S3 MPE;BDA MPE Filter;C:\WINDOWS\system32\DRIVERS\MPE.sys [2004-08-04 07:10]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{74c9a805-7251-11dc-9440-000ae493827f}]
\Shell\AutoRun\command - F:\setupSNK.exe

.
Contents of the 'Scheduled Tasks' folder
"2007-12-20 21:52:12 C:\WINDOWS\Tasks\BRP.job"
- C:\WINDOWS\ehome\BladeRunnerPro\BladeRunner.exe
"2007-12-22 08:36:35 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2007-12-22 00:02:38 C:\WINDOWS\Tasks\Scheduled scanning task.job"
- C:\PROGRA~1\F-SECU~1\ANTI-V~1\fsav.exeZ /HARD /ARCHIVE /DISINF /SCHED /NOBREAK /REPORT=C:\PROGRA~1\F-SECU~1\ANTI-V~1\report.txt
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-22 09:49:38
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwClose

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-22 9:50:26
C:\ComboFix2.txt … 2007-12-22 00:22
.
2007-12-20 18:24:37 — E O F —
Hello

Still plenty to do. I noticed the NoBalloonTips is disabled, which means you should be getting plenty from Windows on Startup. Do you want that enabled to stop them?

Go to http://www.virustotal.com/en/indexf.html
Copy the following line into the white textbox:
C:\WINDOWS\wininit.ini
Click Send.
Please post the results of this scan to this thread.

Remember to disconnect from the Internet and disable your anti-virus before carrying out the next instruction, and to reenable the anti-virus before reconnecting to the Internet


Open Notepad - it must be Notepad, not Wordpad.
Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

File::
C:\WINDOWS\system32\VundoFixSVC.exe
C:\WINDOWS\system32\mevkxrpy.dll
C:\WINDOWS\system32\lbagwbkx.ini
C:\WINDOWS\system32\xahqmkoj.ini
C:\WINDOWS\system32\efqllbyn.ini
C:\WINDOWS\system32\mcahggvw.ini
C:\WINDOWS\system32\qjgxgmxf.ini
C:\error.htm
C:\infect.htm
C:\WINDOWS\system32\xvquolcw.ini
C:\WINDOWS\system32\nileaxhm.ini
C:\WINDOWS\system32\spljbnvk.ini
C:\WINDOWS\system32\xvqrkjjs.ini
C:\WINDOWS\system32\ygqeimkc.ini
C:\WINDOWS\system32\lebypayu.ini
C:\WINDOWS\system32\mljhfcd.dll.bak
C:\Program Files\wt3d.ini

Folder::
C:\VundoFix Backups
C:\Documents and Settings\Nico\Application Data\Warez
C:\SDFix
C:\Vundofix

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{061FD4C8-798C-420F-8F26-32A0C3BE8FEF}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201CAAD1-1A12-4423-8EA4-579FE9DE4DBD}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"70e51637"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljhfcd]

Go to the Notepad window and click Edit > Paste
Then click File > Save
Name the file "CFScript.txt" (including the quotes)
Save the file to your Desktop

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task-Manager use the Processes tab (press ctrl alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

In your next reply post:
ComboFix.txt
New HJT log taken after the above scan has run
Scotty,

A continuous thanks for all your help.

I had to run ComboFix twice as it stalled right at the end. I think it was due to the fact it said 'do not run any other programs until finished' , at that point Spybot kicked in to ask me about registry changes! I thought I had disabled it, but maybe I am disabling things incorreclty…. I went into control panel, software explorer and disabled things that I thought eg Windows Defender, Spybot, Spyware Doctor?!

As for your first question regading 'no ballons' where do I enable that?

The other thing of interest to tell you is that I first noticed the problems (before all this) when I was in Media Centre I went to My Music and nothing was there. Then I went to WMP and it will not open. Media centre wont let me add the music files again either?! This is still the case now. Interestingly, the other User Account on the computer does not have this problem….. Is this part of the problem that you are helping me with? Also, I guess that all of the fixes you are making will sort the User Account too? I apologise if I am a bit slow with the obvious!!

Here are the logs that you requested;

File wininit.ini received on 12.22.2007 21:33:38 (CET)
Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED


Result: 0/32 (0%)
Loading server information…
Your file is queued in position: 4.
Estimated start time is between 47 and 68 seconds.
Do not close the window until scan is complete.
The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
If you are waiting for more than five minutes you have to resend your file.
Your file is being scanned by VirusTotal in this moment,
results will be shown as they're generated.
Compact Print results
Your file has expired or does not exists.
Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time.

You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.
Email:


Antivirus Version Last Update Result
AhnLab-V3 2007.12.22.10 2007.12.21 -
AntiVir 7.6.0.46 2007.12.22 -
Authentium 4.93.8 2007.12.22 -
Avast 4.7.1098.0 2007.12.22 -
AVG 7.5.0.516 2007.12.22 -
BitDefender 7.2 2007.12.22 -
CAT-QuickHeal 9.00 2007.12.22 -
ClamAV 0.91.2 2007.12.22 -
DrWeb 4.44.0.09170 2007.12.22 -
eSafe 7.0.15.0 2007.12.20 -
eTrust-Vet 31.3.5395 2007.12.21 -
Ewido 4.0 2007.12.22 -
FileAdvisor 1 2007.12.22 -
Fortinet 3.14.0.0 2007.12.22 -
F-Prot 4.4.2.54 2007.12.22 -
F-Secure 6.70.13030.0 2007.12.21 -
Ikarus T3.1.1.15 2007.12.22 -
Kaspersky 7.0.0.125 2007.12.22 -
McAfee 5191 2007.12.21 -
Microsoft 1.3109 2007.12.22 -
NOD32v2 2742 2007.12.22 -
Norman 5.80.02 2007.12.21 -
Panda 9.0.0.4 2007.12.22 -
Prevx1 V2 2007.12.22 -
Rising 20.23.52.00 2007.12.22 -
Sophos 4.24.0 2007.12.22 -
Sunbelt 2.2.907.0 2007.12.21 -
Symantec 10 2007.12.22 -
TheHacker 6.2.9.168 2007.12.22 -
VBA32 3.12.2.5 2007.12.21 -
VirusBuster 4.3.26:9 2007.12.22 -
Webwasher-Gateway 6.6.2 2007.12.22 -
Additional information
File size: 244 bytes
MD5: f2dd79e9e39d0b13c88fd8e9d1e49f67
SHA1: f053590eac7c0dc5a290d3c2ad8c41d4a117997c
PEiD: -
_________________________________________________________

ComboFix 07-12-21.4 - Nico 2007-12-22 22:11:34.7 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.426 [GMT 1:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
C:\Documents and Settings\Nico\Application Data\Warez
C:\error.htm
C:\infect.htm
C:\Program Files\wt3d.ini
C:\VundoFix Backups
C:\VundoFix Backups\addmorefiles.txt
C:\VundoFix Backups\aglpmghy.dll.bad
C:\VundoFix Backups\ayehqpjg.dll.bad
C:\VundoFix Backups\bpvmglhm.dll.bad
C:\VundoFix Backups\chehpfje.ini.bad
C:\VundoFix Backups\ckpgmuyo.dll.bad
C:\VundoFix Backups\cleittsf.dll.bad
C:\VundoFix Backups\duymbxrr.dll.bad
C:\VundoFix Backups\ejfphehc.dll.bad
C:\VundoFix Backups\eugvgugh.dll.bad
C:\VundoFix Backups\fcjsqmlg.ini.bad
C:\VundoFix Backups\fxmgxgjq.dll.bad
C:\VundoFix Backups\glmqsjcf.dll.bad
C:\VundoFix Backups\jocmswqs.dll.bad
C:\VundoFix Backups\mhlgmvpb.ini.bad
C:\VundoFix Backups\mljgf.dll.bad
C:\VundoFix Backups\NCTAudioCDGrabber2.dll.bad
C:\VundoFix Backups\NCTAudioFile2.dll.bad
C:\VundoFix Backups\NCTAudioPlayer2.dll.bad
C:\VundoFix Backups\NCTAudioRecord2.dll.bad
C:\VundoFix Backups\NCTAVIFile.dll.bad
C:\VundoFix Backups\NCTQuickTimeFile.dll.bad
C:\VundoFix Backups\NCTVideoCoreM.dll.bad
C:\VundoFix Backups\NCTWMAFile2.dll.bad
C:\VundoFix Backups\nshnjojw.dll.bad
C:\VundoFix Backups\nupplehw.dll.bad
C:\VundoFix Backups\odsqvjrh.dll.bad
C:\VundoFix Backups\otfjtkut.dll.bad
C:\VundoFix Backups\pidywgho.dll.bad
C:\VundoFix Backups\pidywgho.dllbox.bad
C:\VundoFix Backups\pqgswenb.dll.bad
C:\VundoFix Backups\qhanycmn.dll.bad
C:\VundoFix Backups\qjkching.dll.bad
C:\VundoFix Backups\rrtsficf.dll.bad
C:\VundoFix Backups\rrxbmyud.ini.bad
C:\VundoFix Backups\saxbehyi.dll.bad
C:\VundoFix Backups\sstqn.dll.bad
C:\VundoFix Backups\tiuhqkgo.dll.bad
C:\VundoFix Backups\wvgghacm.dll.bad
C:\VundoFix Backups\xkbwgabl.dll.bad
C:\VundoFix Backups\yhgmplga.ini.bad
C:\WINDOWS\system32\efqllbyn.ini
C:\WINDOWS\system32\lbagwbkx.ini
C:\WINDOWS\system32\lebypayu.ini
C:\WINDOWS\system32\mcahggvw.ini
C:\WINDOWS\system32\mevkxrpy.dll
C:\WINDOWS\system32\mljhfcd.dll.bak
C:\WINDOWS\system32\nileaxhm.ini
C:\WINDOWS\system32\qjgxgmxf.ini
C:\WINDOWS\system32\spljbnvk.ini
C:\WINDOWS\system32\VundoFixSVC.exe
C:\WINDOWS\system32\xahqmkoj.ini
C:\WINDOWS\system32\xvqrkjjs.ini
C:\WINDOWS\system32\xvquolcw.ini
C:\WINDOWS\system32\ygqeimkc.ini

.
((((((((((((((((((((((((( Files Created from 2007-11-22 to 2007-12-22 )))))))))))))))))))))))))))))))
.

2007-12-22 01:53 . 2007-12-22 01:53 d——– C:\WINDOWS\ERUNT
2007-12-20 19:48 . 2007-12-20 19:48 d——– C:\Program Files\Trend Micro
2007-12-19 22:32 . 2007-12-19 22:32 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-12-19 22:32 . 2007-12-19 22:32 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-12-19 22:22 . 2007-12-22 22:05 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-19 17:54 . 2007-12-19 18:32 d——– C:\Documents and Settings\Nico\Application Data\PrevxCSI
2007-12-19 17:54 . 2007-12-19 17:54 d——– C:\Documents and Settings\All Users\Application Data\Prevx
2007-12-17 10:50 . 2007-12-17 10:50 d——– C:\Documents and Settings\Nico and Jane\Application Data\DivX
2007-12-10 23:53 . 2007-12-20 19:34 d——– C:\Program Files\Spyware Doctor
2007-12-10 23:53 . 2007-12-10 23:53 d——– C:\Documents and Settings\Nico\Application Data\PC Tools
2007-12-10 23:53 . 2005-09-23 08:29 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-12-10 23:53 . 2007-12-19 21:25 74,240 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2007-12-10 23:53 . 2007-12-19 21:25 56,832 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2007-12-10 23:53 . 2007-10-18 00:14 41,288 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-12-10 23:53 . 2007-10-18 00:16 29,000 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2007-12-07 17:56 . 2007-12-19 21:07 244 –a—— C:\WINDOWS\wininit.ini
2007-12-06 13:18 . 2007-12-06 13:18 28,672 –a—— C:\WINDOWS\system32\drivers\CO_Mon.sys
2007-12-06 12:42 . 2007-12-10 23:18 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-03 13:54 . 2007-12-03 13:54 dr-h—– C:\Documents and Settings\Nico\Application Data\SecuROM
2007-12-03 13:52 . 2004-12-10 10:06 327,680 –a—— C:\WINDOWS\system32\vp6dec.ax
2007-12-03 13:52 . 2007-04-12 15:01 118,832 –a—— C:\WINDOWS\system32\SHW32.DLL
2007-12-03 13:47 . 2006-11-29 13:06 3,426,072 –a—— C:\WINDOWS\system32\d3dx9_32.dll
2007-12-03 13:47 . 2007-01-24 15:27 255,848 –a—— C:\WINDOWS\system32\xactengine2_6.dll
2007-12-03 13:47 . 2006-12-08 12:02 251,672 –a—— C:\WINDOWS\system32\xactengine2_5.dll
2007-12-03 13:46 . 2006-09-28 16:05 2,414,360 –a—— C:\WINDOWS\system32\d3dx9_31.dll
2007-12-03 13:46 . 2006-09-28 16:05 237,848 –a—— C:\WINDOWS\system32\xactengine2_4.dll
2007-12-03 13:46 . 2006-07-28 09:30 236,824 –a—— C:\WINDOWS\system32\xactengine2_3.dll
2007-12-03 13:46 . 2006-09-28 16:04 68,888 –a—— C:\WINDOWS\system32\xinput1_3.dll
2007-12-03 13:46 . 2006-07-28 09:30 62,744 –a—— C:\WINDOWS\system32\xinput1_2.dll
2007-12-03 13:46 . 2007-01-08 15:30 15,128 –a—— C:\WINDOWS\system32\x3daudio1_1.dll
2007-12-03 13:07 . 2007-08-24 11:00 172,032 –a—— C:\WINDOWS\system32\igfxres.dll
2007-12-02 13:06 . 2007-12-02 13:06 d——– C:\Program Files\SystemRequirementsLab
2007-12-02 12:50 . 2007-08-24 11:22 5,776,928 –a—— C:\WINDOWS\system32\drivers\igxpmp32.sys
2007-12-02 12:50 . 2007-08-24 11:23 2,575,360 –a—— C:\WINDOWS\system32\igxpdx32.dll
2007-12-02 12:50 . 2007-08-24 11:23 1,615,808 –a—— C:\WINDOWS\system32\igxpdv32.dll
2007-12-02 12:50 . 2007-08-24 11:03 176,128 –a—— C:\WINDOWS\system32\igfxrsky.lrc
2007-12-02 12:50 . 2007-08-24 11:03 172,032 –a—— C:\WINDOWS\system32\igfxrslv.lrc
2007-12-02 12:50 . 2007-08-24 11:22 150,528 –a—— C:\WINDOWS\system32\igxpgd32.dll
2007-12-02 12:50 . 2007-08-24 11:29 147,456 –a—— C:\WINDOWS\system32\igfxCoIn_v4864.dll
2007-12-02 12:50 . 2007-08-24 11:22 57,344 –a—— C:\WINDOWS\system32\igxprd32.dll
2007-12-02 12:49 . 2007-09-10 09:15 920,088 –a—— C:\WINDOWS\system32\igxpun.exe
2007-12-02 12:36 . 2007-12-03 13:54 107,888 –a—— C:\WINDOWS\system32\CmdLineExt.dll
2007-12-02 11:58 . 2007-12-02 11:58 d——– C:\Program Files\PowerISO
2007-11-25 22:00 . 2007-11-27 00:04 d——– C:\Documents and Settings\All Users\Application Data\OrbNetworks
2007-11-25 19:13 . 2007-11-25 19:15 d——– C:\Program Files\UnZixWin
2007-11-25 19:13 . 2007-11-25 19:13 249,856 ——— C:\WINDOWS\Setup1.exe
2007-11-25 19:13 . 2007-11-25 19:13 73,216 –a—— C:\WINDOWS\ST6UNST.EXE
2007-11-23 12:03 . 2007-11-23 12:03 d——– C:\Documents and Settings\LocalService\Application Data\DivX
2007-11-22 21:18 . 2007-11-25 13:25 d——– C:\Documents and Settings\Nico\Application Data\DivX
2007-11-22 20:25 . 2007-11-22 21:20 d——– C:\Program Files\DivX
2007-11-22 19:00 . 2007-11-22 19:00 d——– C:\Program Files\MCE
2007-11-22 19:00 . 2007-12-22 10:32 d——– C:\Documents and Settings\All Users\Application Data\My Movies
2007-11-22 00:22 . 2007-12-06 10:17 d——– C:\Program Files\Pick-a-Proxy Toolbar

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-20 00:06 ——— d—–w C:\Documents and Settings\Nico\Application Data\uTorrent
2007-12-19 08:00 ——— d—–w C:\Documents and Settings\Nico and Jane\Application Data\Skype
2007-12-03 13:36 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-28 12:14 ——— d—–w C:\Documents and Settings\Nico\Application Data\Skype
2007-11-26 21:17 ——— d—–w C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-11-25 21:00 ——— d—–w C:\Program Files\Orb Networks
2007-11-23 23:24 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2007-11-23 23:24 ——— d—–w C:\Documents and Settings\All Users\Application Data\PC Suite
2007-11-21 18:55 ——— d—–w C:\Program Files\ProxyWay
2007-11-21 17:03 ——— d—–w C:\Program Files\uTorrent
2007-11-21 16:02 ——— d—–w C:\Documents and Settings\Nico\Application Data\Move Networks
2007-11-21 13:26 ——— d—–w C:\Documents and Settings\Nico\Application Data\FreeCap
2007-11-21 13:24 ——— d—–w C:\Program Files\NetConeal
2007-11-21 13:15 ——— d—–w C:\Program Files\Common Files\Download Manager
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-29 22:35 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-27 16:40 222,720 —-a-w C:\WINDOWS\system32\wmasf.dll
2007-10-20 00:56 524,288 —-a-w C:\WINDOWS\system32\DivXsm.exe
2007-10-20 00:56 3,596,288 —-a-w C:\WINDOWS\system32\qt-dx331.dll
2007-10-20 00:56 200,704 —-a-w C:\WINDOWS\system32\ssldivx.dll
2007-10-20 00:56 1,044,480 —-a-w C:\WINDOWS\system32\libdivx.dll
2007-10-20 00:54 823,296 —-a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-10-20 00:54 823,296 —-a-w C:\WINDOWS\system32\divx_xx07.dll
2007-10-20 00:54 81,920 —-a-w C:\WINDOWS\system32\dpl100.dll
2007-10-20 00:54 802,816 —-a-w C:\WINDOWS\system32\divx_xx11.dll
2007-10-20 00:54 739,840 —-a-w C:\WINDOWS\system32\DivX.dll
2007-10-20 00:54 196,608 —-a-w C:\WINDOWS\system32\dtu100.dll
2007-10-18 09:06 156,992 —-a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-10-18 09:03 593,920 —-a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-10-18 09:03 57,344 —-a-w C:\WINDOWS\system32\dpv11.dll
2007-10-18 09:03 53,248 —-a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-10-18 09:03 344,064 —-a-w C:\WINDOWS\system32\dpus11.dll
2007-10-18 09:03 294,912 —-a-w C:\WINDOWS\system32\dpu11.dll
2007-10-18 09:03 294,912 —-a-w C:\WINDOWS\system32\dpu10.dll
2007-10-18 09:02 12,288 —-a-w C:\WINDOWS\system32\DivXWMPExtType.dll
.

((((((((((((((((((((((((((((( snapshot@2007-12-22_ 0.22.07.35 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-12-20 12:08:37 163,328 —-a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2007-12-22 00:53:10 7,172,096 —-a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000001\ntuser.dat
+ 2007-12-22 00:53:10 151,552 —-a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2007-12-20 12:08:37 163,328 —-a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2007-12-22 00:53:08 7,172,096 —-a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000001\ntuser.dat
+ 2007-12-22 00:53:08 151,552 —-a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
+ 2007-12-22 21:05:19 16,384 —-atw C:\WINDOWS\TEMP\Perflib_Perfdata_63c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"kdx"="C:\WINDOWS\kdx\KHost.exe" [2007-05-11 08:46]
"eyeBeam SIP Client"="" []
"ProxyWay"="C:\Program Files\ProxyWay\proxyway.exe" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 21:00]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"YBrowser"="C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe" [2003-12-09 12:03]
"VFDTranscoder"="C:\WINDOWS\eHome\VFDTranscoder.exe" [2006-04-19 23:12]
"Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-11 04:19]
"RTHDCPL"="RTHDCPL.EXE" [2006-04-04 16:44 C:\WINDOWS\RTHDCPL.exe]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2007-04-09 13:23]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-10 21:00]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-10 21:00]
"OWCWebCamDV"="C:\WINDOWS\system\wcdvtray.exe" [2004-05-20 08:59]
"News Service"="C:\Program Files\F-Secure Internet Security\FSGUI\ispnews.exe" [2005-05-31 13:45]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-10 21:00]
"LaunchApp"="Alaunch" []
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-10 21:00]
"ImageItEncrypt"="C:\WINDOWS\system32\ImageItEncrypt.exe" [2005-12-30 22:02]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-02-21 17:59]
"FlashIcon"="C:\Program Files\Generic\USB Card Reader Utility v1.3\FlashIcon.exe" [2006-04-07 12:15]
"F-Secure TNB"="C:\Program Files\F-Secure Internet Security\TNB\TNBUtil.exe" [2005-07-18 15:51]
"F-Secure Startup Wizard"="C:\Program Files\F-Secure Internet Security\FSGUI\FSSW.exe" [2005-10-18 09:29]
"F-Secure Manager"="C:\Program Files\F-Secure Internet Security\Common\FSM32.exe" [2005-10-26 02:51]
"eRecoveryService"="C:\Acer\Empowering Technology\eRecovery\eRAgent.exe" [2006-03-30 23:18]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-29 22:01]
"AzMixerSel"="C:\Program Files\Realtek\InstallShield\AzMixerSel.exe" [2006-01-25 17:45]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 00:19 C:\WINDOWS\arpwrmsg.exe]
"Acer Empowering Technology Monitor"="C:\WINDOWS\system32\SysMonitor.exe" [2006-04-19 03:54]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-11-02 17:24]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 15:57]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2007-08-24 11:00]
"IndexSearch"="C:\Program Files\Scansoft\PaperPort\IndexSearch.exe" [2002-09-23 09:50]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2007-08-24 11:01]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Orb"="C:\Program Files\Orb Networks\Orb\bin\OrbTray.exe" [2007-11-02 20:04]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 21:00]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 14:58]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2005-04-25 13:45]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26]
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-01-17 18:45:32]
F-Secure 2006.lnk - C:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe [2007-04-25 22:34:51]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoSMBalloonTip"= 1 (0x1)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

R0 FSFW;F-Secure Firewall Driver;C:\WINDOWS\system32\drivers\fsdfw.sys [2005-11-18 16:04]
R2 BackWeb Plug-in - 4476822;F-Secure 2006;C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE [2007-04-25 22:34]
R2 F-Secure Filter;F-Secure File System Filter;C:\Program Files\F-Secure Internet Security\Anti-Virus\Win2K\FSfilter.sys [2004-09-10 16:14]
R2 F-Secure Gatekeeper;F-Secure Gatekeeper;C:\Program Files\F-Secure Internet Security\Anti-Virus\Win2K\FSgk.sys [2007-06-02 15:13]
R2 F-Secure Recognizer;F-Secure File System Recognizer;C:\Program Files\F-Secure Internet Security\Anti-Virus\Win2K\FSrec.sys [2004-06-01 10:03]
R2 WebCamDV;WebCamDV DV to Webcam Converter;C:\WINDOWS\system32\DRIVERS\WebCamDV.sys [2004-05-11 06:27]
R3 arkbcfltr;Microsoft PS2 Keyboard Filter;C:\WINDOWS\system32\DRIVERS\arkbcfltr.sys [2005-08-03 00:19]
R3 armoucfltr;Microsoft PS2 Mouse Filter;C:\WINDOWS\system32\DRIVERS\armoucfltr.sys [2005-08-03 00:19]
R3 CXRAPTOR;MPC718 Video Capture ;C:\WINDOWS\system32\drivers\cxraptor.sys [2006-05-05 17:56]
R3 filter;filter;C:\WINDOWS\system32\drivers\filter.sys [2006-04-19 03:12]
R3 int15.sys;int15.sys;C:\Acer\Empowering Technology\eRecovery\int15.sys [2005-01-13 22:46]
R3 WCDV_Aud;WevCamDV WDM Virtual Audio Device;C:\WINDOWS\system32\drivers\wcdvaud.sys [2004-01-30 13:08]
S3 LVUSBSta;Logitech USB Monitor Filter;C:\WINDOWS\system32\drivers\lvusbsta.sys [2006-06-22 15:29]
S3 MPE;BDA MPE Filter;C:\WINDOWS\system32\DRIVERS\MPE.sys [2004-08-04 07:10]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{74c9a805-7251-11dc-9440-000ae493827f}]
\Shell\AutoRun\command - F:\setupSNK.exe

.
Contents of the 'Scheduled Tasks' folder
"2007-12-20 21:52:12 C:\WINDOWS\Tasks\BRP.job"
- C:\WINDOWS\ehome\BladeRunnerPro\BladeRunner.exe
"2007-12-22 21:08:16 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2007-12-22 00:02:38 C:\WINDOWS\Tasks\Scheduled scanning task.job"
- C:\PROGRA~1\F-SECU~1\ANTI-V~1\fsav.exeZ /HARD /ARCHIVE /DISINF /SCHED /NOBREAK /REPORT=C:\PROGRA~1\F-SECU~1\ANTI-V~1\report.txt
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-22 22:13:39
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwClose

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-22 22:14:26
C:\ComboFix2.txt … 2007-12-22 09:50
C:\ComboFix3.txt … 2007-12-22 00:22
.
2007-12-20 18:24:37 — E O F —
_______________________________________________________

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:15:24, on 22/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\FSGK32.EXE
C:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe
C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
C:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe
C:\Program Files\F-Secure Internet Security\Common\FSMB32.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\KService\KService.exe
C:\Program Files\F-Secure Internet Security\Common\FCH32.EXE
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\F-Secure Internet Security\Common\FAMEH32.EXE
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsqh.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsrw.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsav32.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\WINDOWS\eHome\VFDTranscoder.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\WINDOWS\system\wcdvtray.exe
C:\Program Files\F-Secure Internet Security\FSGUI\ispnews.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE
C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\WINDOWS\system32\SysMonitor.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\igfxpers.exe
C:\PROGRA~1\F-SECU~1\ANTI-S~1\fsaw.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\kdx\KHost.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\F-Secure Internet Security\FSGUI\fsguidll.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/customi…fo/bt_side.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.red.clientapps.yahoo.com/customi…arch.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.aceradvantage.com/stdreg
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 66.98.238.8:3128
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local;
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [VFDTranscoder] C:\WINDOWS\eHome\VFDTranscoder.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [OWCWebCamDV] C:\WINDOWS\system\wcdvtray.exe
O4 - HKLM\..\Run: [News Service] "C:\Program Files\F-Secure Internet Security\FSGUI\ispnews.exe"
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [ImageItEncrypt] C:\WINDOWS\system32\ImageItEncrypt.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
O4 - HKLM\..\Run: [FlashIcon] "C:\Program Files\Generic\USB Card Reader Utility v1.3\FlashIcon.exe"
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure Internet Security\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\F-Secure Internet Security\FSGUI\FSSW.EXE" /reboot
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\WINDOWS\system32\SysMonitor.exe
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKCU\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe -all
O4 - HKCU\..\Run: [ProxyWay] C:\Program Files\ProxyWay\proxyway.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [Orb] "C:\Program Files\Orb Networks\Orb\bin\OrbTray.exe" /background (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Orb] "C:\Program Files\Orb Networks\Orb\bin\OrbTray.exe" /background (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: F-Secure 2006.lnk = C:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure Internet Security\Anti-Spyware\blockpopups.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\Anti-Spyware\ieshield.dll
O9 - Extra 'Tools' menuitem: IE Shield… - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\Anti-Spyware\ieshield.dll
O9 - Extra button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {3F14D76D-8C1A-47CA-A2CB-34982BCD44DE} (OutlookYearView.YearPlan) - file:///D:/OutlookYearView.CAB
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1160519841906
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.1.6.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\mcePhone\Skype4COM.dll
O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: F-Secure 2006 (BackWeb Plug-in - 4476822) - F-Secure Internet Security 2005 - C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\KService\KService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

–
End of file - 14663 bytes
Hi

My fault. Spybot's Teatimer has to be disabled under Advanced Mode. I should have posted instructions for that, which I will do now.

I cant say for sure if the infection is causing your Media Player/music problems. And infections normally spread through all user accounts, and the tools we use deal with all at once.
Maybe your user acount is corrupted. Let's clean you up first and go from there.



Disable Teatimer
First:
  • Right click Spybot in the System Tray (looks like a calendar with a padlock symbol)
  • Choose Exit Spybot S&D Resident
Second:
  • Open Spybot S&D
  • Click Mode, check Advanced Mode
  • Go To Left Panel, Click Tools, then also in left panel, click Resident
  • If your firewall raises a question, say OK
  • Uncheck the box labeled Resident Tea-Timer and OK any prompts.
  • Use File, Exit to terminate Spybot
  • Reboot your machine for the changes to take effect.

Please do an online scan with Kaspersky Online Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database:

      + Extended(If available otherwise Standard)
    • Scan Options:

      + Scan Archives
      + Scan Mail Bases
  • Click OK
  • Now under select a target to scan select My Computer
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button
  • Save the file to your desktop.
  • Copy and paste that information in your next post.

With the exception of Internet Explorer, which is needed for the Kaspersky Scan, keep ALL programs closed until the scan is complete. This includes your Anti-Virus. Once you have installed kaspersky and updated the definitions, once it starts scanning, you can disconnect from the internet.
Hi Scotty, As you metioned on a previous posr…'still some work to do' as the scan found 6 viruses! Here is the log; ——————————————————————————- KASPERSKY ONLINE SCANNER REPORT Sunday, December 23, 2007 3:55:04 PM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.98.0 Kaspersky Anti-Virus database last update: 23/12/2007 Kaspersky Anti-Virus database records: 492137 ——————————————————————————- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: C:\ D:\ E:\ F:\ G:\ I:\ Scan Statistics: Total number of scanned objects: 80026 Number of viruses found: 6 Number of infected objects: 25 Number of suspicious objects: 0 Duration of the scan process: 01:18:14 Infected Object Name / Virus Name / Last Action C:\autorun.inf\lpt3.This folder was created by Flash_Disinfector Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\eHome\logs\ehRecvr.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-12072006-002926.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2007-12-23_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp Object is locked skipped C:\Documents and Settings\All Users\DRM\drmstore.hds Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Nico\Application Data\ispnews\ispn.ini Object is locked skipped C:\Documents and Settings\Nico\Application Data\ispnews\ispnc.items Object is locked skipped C:\Documents and Settings\Nico\Application Data\ispnews\ispnr.items Object is locked skipped C:\Documents and Settings\Nico\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Nico\Local Settings\Application Data\ApplicationHistory\SysMonitor.exe.49302a1.ini.inuse Object is locked skipped C:\Documents and Settings\Nico\Local Settings\Application Data\Microsoft\Media Player\CurrentDatabase_360.wmdb Object is locked skipped C:\Documents and Settings\Nico\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Nico\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Nico\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{41746D53-B7FD-4CCB-BCB6-19F9FAB60194} Object is locked skipped C:\Documents and Settings\Nico\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Nico\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Nico\ntuser.dat Object is locked skipped C:\Documents and Settings\Nico\ntuser.dat.LOG Object is locked skipped C:\Program Files\F-Secure Internet Security\Anti-Virus\dbupdate.log Object is locked skipped C:\Program Files\F-Secure Internet Security\Anti-Virus\Qrt.log Object is locked skipped C:\Program Files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\cache.dat Object is locked skipped C:\Program Files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\chandir.dat Object is locked skipped C:\Program Files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\chandir.idx Object is locked skipped C:\Program Files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\chn.dat Object is locked skipped C:\Program Files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\chn.idx Object is locked skipped C:\Program Files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\D0000000.FCS Object is locked skipped C:\Program Files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\fsbwupst.log Object is locked skipped C:\Program Files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\inuse.txt Object is locked skipped C:\Program Files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\L0000001.FCS Object is locked skipped C:\Program Files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\main.log Object is locked skipped C:\Program Files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\prs.dat Object is locked skipped C:\Program Files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\prs.idx Object is locked skipped C:\Program Files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\prs_die.dat Object is locked skipped C:\Program Files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\prs_die.idx Object is locked skipped C:\Program Files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\prs_dnd.dat Object is locked skipped C:\Program Files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\prs_dnd.idx Object is locked skipped C:\Program Files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\prs_ext.dat Object is locked skipped C:\Program Files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\prs_ext.idx Object is locked skipped C:\Program Files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\prs_rcv.dat Object is locked skipped C:\Program Files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\prs_rcv.idx Object is locked skipped C:\Program Files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\storydb.dat Object is locked skipped C:\Program Files\F-Secure Internet Security\backweb\4476822\Users\Default\Data\storydb.idx Object is locked skipped C:\Program Files\F-Secure Internet Security\Common\admin.pub Object is locked skipped C:\Program Files\F-Secure Internet Security\Common\policy.bpf Object is locked skipped C:\Program Files\F-Secure Internet Security\Common\policy.ipf Object is locked skipped C:\Program Files\KService\data\error.log Object is locked skipped C:\qoobox\Quarantine\C\VundoFix Backups\aglpmghy.dll.bad.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped C:\qoobox\Quarantine\C\VundoFix Backups\ayehqpjg.dll.bad.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped C:\qoobox\Quarantine\C\VundoFix Backups\ckpgmuyo.dll.bad.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped C:\qoobox\Quarantine\C\VundoFix Backups\cleittsf.dll.bad.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped C:\qoobox\Quarantine\C\VundoFix Backups\duymbxrr.dll.bad.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped C:\qoobox\Quarantine\C\VundoFix Backups\ejfphehc.dll.bad.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped C:\qoobox\Quarantine\C\VundoFix Backups\eugvgugh.dll.bad.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped C:\qoobox\Quarantine\C\VundoFix Backups\fxmgxgjq.dll.bad.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped C:\qoobox\Quarantine\C\VundoFix Backups\glmqsjcf.dll.bad.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped C:\qoobox\Quarantine\C\VundoFix Backups\jocmswqs.dll.bad.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped C:\qoobox\Quarantine\C\VundoFix Backups\nshnjojw.dll.bad.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped C:\qoobox\Quarantine\C\VundoFix Backups\nupplehw.dll.bad.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped C:\qoobox\Quarantine\C\VundoFix Backups\odsqvjrh.dll.bad.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.ak skipped C:\qoobox\Quarantine\C\VundoFix Backups\otfjtkut.dll.bad.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped C:\qoobox\Quarantine\C\VundoFix Backups\pqgswenb.dll.bad.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped C:\qoobox\Quarantine\C\VundoFix Backups\qhanycmn.dll.bad.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.ak skipped C:\qoobox\Quarantine\C\VundoFix Backups\qjkching.dll.bad.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped C:\qoobox\Quarantine\C\VundoFix Backups\saxbehyi.dll.bad.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped C:\qoobox\Quarantine\C\VundoFix Backups\tiuhqkgo.dll.bad.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped C:\qoobox\Quarantine\C\VundoFix Backups\wvgghacm.dll.bad.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped C:\qoobox\Quarantine\C\VundoFix Backups\xkbwgabl.dll.bad.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped C:\qoobox\Quarantine\C\WINDOWS\system32\mljhfcd.dll.bak.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.bhw skipped C:\qoobox\Quarantine\catchme2007-12-22_ 02052.56.zip/tuvurqp.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.cll skipped C:\qoobox\Quarantine\catchme2007-12-22_ 02052.56.zip ZIP: infected - 1 skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{226C1E91-E31F-4C6A-B817-617E548040CA}\RP2\A0000010.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.cll skipped C:\System Volume Information\_restore{226C1E91-E31F-4C6A-B817-617E548040CA}\RP4\change.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{CD8D8E17-9203-4A90-9702-726FC8C94FA9}.crmlog Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb Object is locked skipped C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log Object is locked skipped C:\WINDOWS\SoftwareDistribution\DataStore\Logs\tmp.edb Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\IntelDH.evt Object is locked skipped C:\WINDOWS\system32\config\Internet.evt Object is locked skipped C:\WINDOWS\system32\config\Media Ce.evt Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\TEMP\Perflib_Perfdata_724.dat Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped D:\autorun.inf\lpt3.This folder was created by Flash_Disinfector Object is locked skipped D:\Recorded TV\TempRec\TempSBE\MSDVRMM_1613226999_12779520_2365 Object is locked skipped D:\Recorded TV\TempRec\TempSBE\MSDVRMM_1613226999_1441792_2376 Object is locked skipped D:\Recorded TV\TempRec\TempSBE\MSDVRMM_1613226999_393216_2373 Object is locked skipped D:\Recorded TV\TempRec\TempSBE\MSDVRMM_1613226999_917504_2368 Object is locked skipped D:\Recorded TV\TempRec\TempSBE\SBE1.tmp Object is locked skipped D:\Recorded TV\TempRec\TempSBE\SBE2.tmp Object is locked skipped D:\Recorded TV\TempRec\TempSBE\SBE3.tmp Object is locked skipped D:\Recorded TV\TempRec\TempSBE\SBE4.tmp Object is locked skipped D:\Recorded TV\TempRec\{09B3D01B-CDBB-4D08-A843-2AE55C10C3C6}.TmpSBE Object is locked skipped D:\Recorded TV\TempRec\{4E3B9654-2233-49D3-9383-C337F4591098}.TmpSBE Object is locked skipped D:\Recorded TV\TempRec\{B30CC18B-DAC3-49C4-84BD-C0F0A5C82D31}.TmpSBE Object is locked skipped D:\Recorded TV\TempRec\{EB31ED6D-CB7C-45AD-9524-5FAFAF744353}.TmpSBE Object is locked skipped D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped D:\System Volume Information\_restore{226C1E91-E31F-4C6A-B817-617E548040CA}\RP4\change.log Object is locked skipped Scan process completed.
Hi

Actually, the virus's are in quarantine or infected restore points, which I will be about to take care of. ;)

You may wish to keep hold of the Kaspersky Online Scan as an extra on-demand virus-scanner.
If not you can uninstall it through Start>Control Panel>Add/Remove Programs


Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the x and the /u, it needs to be there.

    [external image: Posted Image]
  • When shown the disclaimer, Select "2"


Now you can re-enable Teatimer by following my steps from earlier, then post a new HijackThis log.
Scotty,

Out of interest it did not give me the option 2 or a disclaimer! It did uninstall ComboFix though which I guess was the point.

As usual, log requested below;

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:13:38, on 23/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\FSGK32.EXE
C:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe
C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
C:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe
C:\Program Files\F-Secure Internet Security\Common\FSMB32.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\KService\KService.exe
C:\Program Files\F-Secure Internet Security\Common\FCH32.EXE
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\F-Secure Internet Security\Common\FAMEH32.EXE
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsqh.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsrw.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsav32.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\WINDOWS\eHome\VFDTranscoder.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\WINDOWS\system\wcdvtray.exe
C:\Program Files\F-Secure Internet Security\FSGUI\ispnews.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE
C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\WINDOWS\system32\SysMonitor.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\kdx\KHost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\F-SECU~1\ANTI-S~1\fsaw.exe
C:\Program Files\F-Secure Internet Security\FSGUI\fsguidll.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/customi…fo/bt_side.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.red.clientapps.yahoo.com/customi…arch.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.aceradvantage.com/stdreg
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 66.98.238.8:3128
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local;
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [VFDTranscoder] C:\WINDOWS\eHome\VFDTranscoder.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [OWCWebCamDV] C:\WINDOWS\system\wcdvtray.exe
O4 - HKLM\..\Run: [News Service] "C:\Program Files\F-Secure Internet Security\FSGUI\ispnews.exe"
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [ImageItEncrypt] C:\WINDOWS\system32\ImageItEncrypt.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
O4 - HKLM\..\Run: [FlashIcon] "C:\Program Files\Generic\USB Card Reader Utility v1.3\FlashIcon.exe"
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure Internet Security\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\F-Secure Internet Security\FSGUI\FSSW.EXE" /reboot
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\WINDOWS\system32\SysMonitor.exe
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\RunOnce: [KB926239] rundll32.exe apphelp.dll,ShimFlushCache
O4 - HKCU\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe -all
O4 - HKCU\..\Run: [ProxyWay] C:\Program Files\ProxyWay\proxyway.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [Orb] "C:\Program Files\Orb Networks\Orb\bin\OrbTray.exe" /background (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Orb] "C:\Program Files\Orb Networks\Orb\bin\OrbTray.exe" /background (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: F-Secure 2006.lnk = C:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure Internet Security\Anti-Spyware\blockpopups.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\Anti-Spyware\ieshield.dll
O9 - Extra 'Tools' menuitem: IE Shield… - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\Anti-Spyware\ieshield.dll
O9 - Extra button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {3F14D76D-8C1A-47CA-A2CB-34982BCD44DE} (OutlookYearView.YearPlan) - file:///D:/OutlookYearView.CAB
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1160519841906
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.1.6.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6B1DF8DD-EA51-4F75-A168-432FC4F8BC7C}: NameServer = 193.189.160.13 193.189.160.23
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\mcePhone\Skype4COM.dll
O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: F-Secure 2006 (BackWeb Plug-in - 4476822) - F-Secure Internet Security 2005 - C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\KService\KService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

–
End of file - 15113 bytes
Hi

I should edit that bit out. It's probably been removed now.

Congratulations, you appear to be malware free.

Here is a free program I recommend.

Install WinPatrol
Download it from here
Here you can find information about how WinPatrol works here



Make sure your Windows is ALWAYS up to date!

An unpatched Windows is vulnerable and even with the "best" Antivirus and Firewall installed, malware will find its way through.
So visit http://windowsupdate.microsoft.com/ to download and install the latest updates.


Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Please check out Tony Klein's article "How did I get infected in the first place?"


Follow this list and your potential for being infected again will reduce dramatically.

I'd be grateful if you could reply to this post so that I know you have read it and, if you've no other questions, the thread can be closed.
Scotty, I can't thank you enough, you have been an absolute legend…. I am going to miss sending all thise log files!! I have 2 questions; Firstly you said that I have viruses in Quarentine… By deleting ComboFix does that remove them too? Secondly, the problem with Media Centre/WMP that appeared from this virus still exists, is that something for you to help with or could you direct me somewhere please? Thanks again and best wishes for you and your family for Christmas and Happy New Year!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI