This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Virtumonde and other Trojans

30 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

On 12/24 after loading iTunes for a new iPod, pc started exhibiting abnormal behavior. PC was slow, really slow,
Updated Avast anti-virus and downloaded Spybot S&D after 10 hrs, 1 System recovery to 12/23, 12 Spybot S&Ds, numerous virus scans the pc seems to be running better but not quite right.

Virtumonde was the key culprit at first but no longer shows up. This came from a Spybot log from 12/26

Virtumonde: [SBI $42352499] User settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-1790839409-2520269449-3199803468-1006\Software\Microsoft\rdfa

Virtumonde: [SBI $47E741CD] Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws

Virtumonde: [SBI $7342F9D9] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-1790839409-2520269449-3199803468-1006\Software\Microsoft\aldd

Statcounter: [SBI $61F39AC8] Tracking cookie (Internet Explorer: Mark) (Cookie, nothing done)


WebTrends live: [SBI $61F39AC8] Tracking cookie (Internet Explorer: Mark) (Cookie, nothing done)


DoubleClick: [SBI $61F39AC8] Tracking cookie (Internet Explorer: Mark) (Cookie, nothing done)


DirectTrack: [SBI $61F39AC8] Tracking cookie (Internet Explorer: Mark) (Cookie, nothing done)


DirectTrack: [SBI $61F39AC8] Tracking cookie (Internet Explorer: Mark) (Cookie, nothing done)



— Spybot - Search & Destroy version: 1.5 (build: 20070830) —

2007-08-31 blindman.exe (1.0.0.6)
2007-08-31 SDMain.exe (1.0.0.4)
2007-08-31 SDUpdate.exe ([removed])
2007-08-31 SDWinSec.exe (1.0.0.8)
2007-08-31 SpybotSD.exe ([removed])
2007-12-25 TeaTimer .exe (1.5.0.9)
2007-12-25 TeaTimer.exe (1.5.0.9)
2007-12-25 unins000.exe ([removed])
2007-08-31 Update.exe (1.4.0.5)
2007-08-31 advcheck.dll (1.5.3.0)
2007-04-02 aports.dll (2.1.0.0)
2007-04-02 DelZip179.dll (1.79.5.3)
2007-08-31 SDHelper.dll (1.5.0.8)
2007-08-31 Tools.dll (2.1.2.0)
2007-12-19 Includes\Cookies.sbi (*)
2007-10-31 Includes\Dialer.sbi (*)
2007-12-19 Includes\DialerC.sbi (*)
2007-11-07 Includes\Hijackers.sbi (*)
2007-12-19 Includes\HijackersC.sbi (*)
2007-10-04 Includes\Keyloggers.sbi (*)
2007-12-19 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2007-11-07 Includes\Malware.sbi (*)
2007-12-19 Includes\MalwareC.sbi (*)
2007-10-24 Includes\PUPS.sbi (*)
2007-12-19 Includes\PUPSC.sbi (*)
2007-12-19 Includes\Revision.sbi (*)
2007-05-30 Includes\Security.sbi (*)
2007-12-19 Includes\SecurityC.sbi (*)
2007-11-07 Includes\Spybots.sbi (*)
2007-12-19 Includes\SpybotsC.sbi (*)
2007-11-06 Includes\Tracks.uti
2007-12-12 Includes\Trojans.sbi (*)
2007-12-19 Includes\TrojansC.sbi (*)
2008-12-24 Plugins\TCPIPAddress.dll


now a something called Crypt Regscan shows up when I run Spybot S&D, btw I ran this S&D in Safe Mode
Ran the Hijack this log today and here is what I Have

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:31:29 PM, on 12/27/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM .exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol .exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask .exe
C:\Program Files\Dell\Media Experience\DMXLauncher .exe
C:\WINDOWS\system32\igfxpers .exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1 .EXE
C:\WINDOWS\system32\hkcmd .exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe
C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip .exe
C:\WINDOWS\system32\dla\tfswctrl .exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp .exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ .exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient .exe
C:\Program Files\DellSupport\DSAgnt .exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer .exe
C:\WINDOWS\DvzCommon\DvzMsgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\WiFiConnector\NintendoWFCReg.exe
C:\Program Files\Outlook Express\msimn.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.myway.com/jsp/dellsidebar.jsp?p=DE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotwheelscollectors.com/default.aspx
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [EPSON Stylus CX5400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE /P19 "EPSON Stylus CX5400" /O6 "USB001" /M "Stylus CX5400"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\\PSDrvCheck.exe
O4 - HKLM\..\Run: [PCLEUSBTip] C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "C:\WINDOWS\system32\PCLECoInst.dll",CheckUSBController
O4 - HKLM\..\Run: [USBToolTip] "C:\Program Files\Pinnacle\Shared Files\\Programs\USBTip\USBTip.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe" -scheduler
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Regscan] C:\WINDOWS\system32\regscan.exe
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Dataviz Messenger.lnk = C:\WINDOWS\DvzCommon\DvzMsgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Run Nintendo Wi-Fi USB Connector Registration Tool.lnk = C:\Program Files\WiFiConnector\NintendoWFCReg.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} - http://a19.g.akamai.net/7/19/7125/4058/ftp…ver/Coupons.cab
O16 - DPF: {D2349304-8F9E-4A54-ACF6-0F6104B44209} (SketchCtl.Pic1) - http://auditor.cuyahogacounty.us/repi/sketch/Sketch.ocx
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 8699 bytes
start list from Hijack this looks like this
StartupList report, 12/27/2007, 12:32:38 PM
StartupList version: 1.52.2
Started from : C:\Program Files\Trend Micro\HijackThis\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v7.00 (7.00.6000.16574)
* Using default options
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM .exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol .exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask .exe
C:\Program Files\Dell\Media Experience\DMXLauncher .exe
C:\WINDOWS\system32\igfxpers .exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1 .EXE
C:\WINDOWS\system32\hkcmd .exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe
C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip .exe
C:\WINDOWS\system32\dla\tfswctrl .exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp .exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ .exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient .exe
C:\Program Files\DellSupport\DSAgnt .exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer .exe
C:\WINDOWS\DvzCommon\DvzMsgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\WiFiConnector\NintendoWFCReg.exe
C:\Program Files\Outlook Express\msimn.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

————————————————–

Listing of startup folders:

Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
Dataviz Messenger.lnk = C:\WINDOWS\DvzCommon\DvzMsgr.exe
Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
Run Nintendo Wi-Fi USB Connector Registration Tool.lnk = C:\Program Files\WiFiConnector\NintendoWFCReg.exe

————————————————–

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

SunJavaUpdateSched = "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
IntelMeM = C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
CTSysVol = C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r
P17Helper = Rundll32 P17.dll,P17Helper
UpdReg = C:\WINDOWS\UpdReg.EXE
MMTray = C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
mmtask = C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
RealTray = C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
QuickTime Task = "C:\Program Files\QuickTime\qttask .exe" -atboottime
ISUSPM Startup = C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
ISUSScheduler = "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
DMXLauncher = C:\Program Files\Dell\Media Experience\DMXLauncher.exe
EPSON Stylus CX5400 = C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE /P19 "EPSON Stylus CX5400" /O6 "USB001" /M "Stylus CX5400"
(Default) =
igfxtray = C:\WINDOWS\system32\igfxtray.exe
igfxhkcmd = C:\WINDOWS\system32\hkcmd.exe
igfxpers = C:\WINDOWS\system32\igfxpers.exe
PinnacleDriverCheck = C:\WINDOWS\system32\\PSDrvCheck.exe
PCLEUSBTip = C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
USB2Check = RUNDLL32.EXE "C:\WINDOWS\system32\PCLECoInst.dll",CheckUSBController
USBToolTip = "C:\Program Files\Pinnacle\Shared Files\\Programs\USBTip\USBTip.exe"
RemoteControl = "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
dla = C:\WINDOWS\system32\dla\tfswctrl.exe
ZoneAlarm Client = "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
Adobe Reader Speed Launcher = "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
avast! = C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

MSMSGS = "C:\Program Files\Messenger\msmsgs.exe" /background
ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
ISUSPM = "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe" -scheduler
DellSupport = "C:\Program Files\DellSupport\DSAgnt.exe" /startup
Regscan = C:\WINDOWS\system32\regscan.exe
AdobeUpdater = C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
SpybotSD TeaTimer = C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

[OptionalComponents]
=

————————————————–

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\system32\ssmypics.scr
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*

————————————————–


Enumerating Task Scheduler jobs:

AppleSoftwareUpdate.job
User_Feed_Synchronization-{50D0D4BC-426E-44B2-9BFA-DEE6413827B3}.job
User_Feed_Synchronization-{92AE00CF-95FA-45D4-8547-820AEBE39993}.job

————————————————–

Enumerating Download Program Files:

[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\system32\macromed\Director\SwDir.dll
CODEBASE = http://fpdownload.macromedia.com/get/shock…director/sw.cab

[{9522B3FB-7A2B-4646-8AF6-36E7F593073C}]
CODEBASE = http://a19.g.akamai.net/7/19/7125/4058/ftp…ver/Coupons.cab

[SketchCtl.Pic1]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\Sketch.ocx
CODEBASE = http://auditor.cuyahogacounty.us/repi/sketch/Sketch.ocx

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx
CODEBASE = http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab

————————————————–

Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*

Windows NT checkdisk command:
BootExecute = autocheck autochk *

Windows NT 'Wininit.ini':
PendingFileRenameOperations: C:\PROGRA~1\ALWILS~1\Avast4\Setup\reboot.txt||C:\PROGRA~1\ALWILS~1\Avast4\ash1.tmp => C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe|||

————————————————–

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\system32\stobject.dll
WPDShServiceObj: C:\WINDOWS\system32\WPDShServiceObj.dll

————————————————–
End of report, 8,633 bytes
Report generated in 0.063 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only

PLEASE HELP identify processes I should disable

THANKS :wacko:
Hello and Welcome to the forum.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.

Open the HijackThis Folder. Find the file HijackThis.exe, Right Click on the file and Select Rename. Rename Hijackthis.exe to Spyware.exe.

After the above:

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.

Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:

Download ComboFix from Here to your Desktop.

**Note: In the event you already have Combofix, please delete it from your desktop and download this new version . It is important that it is saved directly to your desktop**
——————————————————————–
  • Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
  • Please do not re-connect your machine back to the Internet until Combofix has completely finished.
——————————————————————–

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
LDTate THANKS for the reply!

I need to mention I read some similiar posts and downloaded Spyware Doctor before implenting your steps. It's fix to approximately 400 infections created approximately 30 Registry errors on startup(s) , looking for dlls


I disabled Spyware Dr. before proceeding.


Here is the Hijack this log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:22:57 AM, on 12/29/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Spyware Doctor\SDTrayApp .exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM .exe
C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol .exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask .exe
C:\Program Files\Real\RealPlayer\RealPlay .exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray .exe
C:\WINDOWS\system32\igfxpers .exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1 .EXE
C:\WINDOWS\system32\hkcmd .exe
C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip .exe
C:\Program Files\Dell\Media Experience\DMXLauncher .exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient .exe
C:\WINDOWS\system32\dla\tfswctrl .exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ .exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp .exe
C:\Program Files\DellSupport\DSAgnt .exe
C:\WINDOWS\DvzCommon\DvzMsgr.exe
C:\Program Files\WiFiConnector\NintendoWFCReg.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer .exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\Spyware.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotwheelscollectors.com/default.aspx
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
F3 - REG:win.ini: load=C:\WINDOWS\system32\mllmn.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {CEE4AF87-77B6-4FA8-84D4-4D1FBB895037} - C:\WINDOWS\system32\mllmn.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [EPSON Stylus CX5400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE /P19 "EPSON Stylus CX5400" /O6 "USB001" /M "Stylus CX5400"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\\PSDrvCheck.exe
O4 - HKLM\..\Run: [PCLEUSBTip] C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "C:\WINDOWS\system32\PCLECoInst.dll",CheckUSBController
O4 - HKLM\..\Run: [USBToolTip] "C:\Program Files\Pinnacle\Shared Files\\Programs\USBTip\USBTip.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe" -scheduler
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Dataviz Messenger.lnk = C:\WINDOWS\DvzCommon\DvzMsgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Run Nintendo Wi-Fi USB Connector Registration Tool.lnk = C:\Program Files\WiFiConnector\NintendoWFCReg.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} - http://a19.g.akamai.net/7/19/7125/4058/ftp…ver/Coupons.cab
O16 - DPF: {D2349304-8F9E-4A54-ACF6-0F6104B44209} (SketchCtl.Pic1) - http://auditor.cuyahogacounty.us/repi/sketch/Sketch.ocx
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 10172 bytes


Here is the combofix log

ComboFix 07-12-21.4 - Mark 2007-12-28 23:38:30.1 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Nick\Start Menu\Programs\Internet Speed Monitor
C:\Documents and Settings\Nick\Start Menu\Programs\Internet Speed Monitor\Check Now.lnk
C:\Documents and Settings\Nick\Start Menu\Programs\Internet Speed Monitor\Uninstall.lnk
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\gebbccb.dll
C:\WINDOWS\system32\mllmn.dll
C:\WINDOWS\system32\nmllm.ini
C:\WINDOWS\system32\nmllm.ini2
C:\WINDOWS\system32\mllmn.dll . . . . failed to delete

.
((((((((((((((((((((((((( Files Created from 2007-11-28 to 2007-12-29 )))))))))))))))))))))))))))))))
.

2007-12-28 19:42 . 2007-12-29 00:04 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-28 17:12 . 2007-12-29 00:05 d——– C:\Program Files\Spyware Doctor
2007-12-28 17:12 . 2007-12-28 17:12 d——– C:\Documents and Settings\Mark\Application Data\PC Tools
2007-12-28 11:31 . 2007-12-28 11:31 d——– C:\Documents and Settings\Mark\Application Data\Apple Computer
2007-12-28 11:09 . 2007-12-28 11:09 d——– C:\Program Files\Apple Software Update
2007-12-28 11:06 . 2007-12-28 11:06 d——– C:\Documents and Settings\All Users\Application Data\Apple
2007-12-27 11:08 . 2005-08-26 12:11 d——– C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
2007-12-27 11:08 . 2005-08-26 12:24 d——– C:\Documents and Settings\Administrator\Application Data\Creative
2007-12-26 23:13 . 2007-12-26 23:31 d——– C:\Documents and Settings\Mark\.housecall6.6
2007-12-26 22:49 . 2007-12-26 22:49 d——– C:\Program Files\Trend Micro
2007-12-25 09:58 . 2007-12-26 20:14 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-24 10:40 . 2007-12-28 11:29 d——– C:\Program Files\iTunes
2007-12-24 10:40 . 2007-12-24 10:40 d——– C:\Program Files\iPod
2007-12-24 10:30 . 2007-12-26 12:35 d——– C:\Program Files\Apple Software Update(2)
2007-12-24 10:27 . 2007-12-24 10:27 d——– C:\Program Files\Common Files\Apple
2007-12-18 20:48 . 2007-12-18 20:48 d——– C:\Program Files\Logitech
2007-12-18 20:48 . 2007-12-18 20:48 d——– C:\Program Files\Common Files\Logitech
2007-12-15 22:27 . 2007-12-23 23:02 d——– C:\Program Files\Project64 1.6
2007-12-09 20:59 . 2007-12-10 22:01 d——– C:\Program Files\Azureus
2007-12-09 20:59 . 2007-12-13 16:48 d——– C:\Documents and Settings\Nick\Application Data\Azureus
2007-11-30 17:19 . 2007-11-30 17:19 d——– C:\Program Files\IZArc

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-29 05:05 757,760 —-a-w C:\WINDOWS\system32\PSDrvCheck.exe
2007-12-29 05:05 457,728 —-a-w C:\WINDOWS\system32\igfxpers.exe
2007-12-29 05:05 437,248 —-a-w C:\WINDOWS\system32\igfxtray.exe
2007-12-29 05:05 420,864 —-a-w C:\WINDOWS\system32\hkcmd.exe
2007-12-29 05:05 342,016 —-a-w C:\WINDOWS\system32\mllmn.exe
2007-12-29 05:05 ——— d—–w C:\Program Files\QuickTime
2007-12-29 05:04 434,688 —-a-w C:\WINDOWS\UpdReg.EXE
2007-12-29 05:04 ——— d—–w C:\Program Files\DellSupport
2007-12-29 05:03 338,432 ——w C:\WINDOWS\system32\mllmn.dll
2007-12-29 04:07 77,824 —-a-w C:\WINDOWS\system32\hkcmd .exe
2007-12-29 04:07 406,016 —-a-w C:\WINDOWS\system32\PSDrvCheck .exe
2007-12-29 04:07 114,688 —-a-w C:\WINDOWS\system32\igfxpers .exe
2007-12-29 04:06 94,208 —-a-w C:\WINDOWS\system32\igfxtray .exe
2007-12-29 04:06 90,112 —-a-w C:\WINDOWS\UpdReg .EXE
2007-12-29 01:37 15,360 —-a-w C:\WINDOWS\system32\ctfmon .exe
2007-12-29 00:48 350,720 —-a-w C:\WINDOWS\system32\regscan .exe
2007-12-28 22:22 74,240 —-a-w C:\WINDOWS\system32\drivers\iksyssec.sys
2007-12-28 22:22 56,832 —-a-w C:\WINDOWS\system32\drivers\iksysflt.sys
2007-12-28 16:18 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-12-27 19:06 ——— d—–w C:\Program Files\Quicken
2007-12-27 04:13 102,664 —-a-w C:\WINDOWS\system32\drivers\tmcomm.sys
2007-12-24 15:42 ——— d—–w C:\Documents and Settings\Nick\Application Data\Apple Computer
2007-12-21 23:58 11,031,348 —-a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2007-12-21 23:08 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-10 02:45 ——— d—–w C:\Program Files\BitComet
2007-12-04 14:56 93,264 —-a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-04 14:55 94,544 —-a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-04 14:53 23,152 —-a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-04 14:51 42,912 —-a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-04 14:49 26,624 —-a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-04 13:04 837,496 —-a-w C:\WINDOWS\system32\aswBoot.exe
2007-12-04 12:54 95,608 —-a-w C:\WINDOWS\system32\AvastSS.scr
2007-11-29 00:55 ——— d—–w C:\Documents and Settings\All Users\Application Data\Smilebox
2007-11-18 14:05 ——— d—–w C:\Program Files\Java
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-11 22:05 73,216 —-a-w C:\WINDOWS\ST6UNST.EXE
2007-11-11 22:04 19,659,826 —-a-w C:\WINDOWS\system32\lebronjames0607.scr
2007-11-03 20:13 ——— d—–w C:\Program Files\Fire International
2007-11-03 13:52 49,827 —-a-w C:\Uninstal.exe
2007-10-30 23:42 3,590,656 —-a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 ——w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-27 22:40 222,720 —-a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 22:40 222,720 —-a-w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-10 23:56 824,832 —-a-w C:\WINDOWS\system32\dllcache\wininet.dll
2007-10-10 23:56 232,960 ——w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-10-10 23:56 1,159,680 —-a-w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-10-10 23:55 671,232 —-a-w C:\WINDOWS\system32\dllcache\mstime.dll
2007-10-10 23:55 63,488 ——w C:\WINDOWS\system32\dllcache\icardie.dll
2007-10-10 23:55 6,065,664 ——w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-10-10 23:55 52,224 ——w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-10-10 23:55 478,208 —-a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-10-10 23:55 459,264 ——w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-10-10 23:55 44,544 ——w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-10-10 23:55 384,512 ——w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-10-10 23:55 383,488 ——w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-10-10 23:55 27,648 —-a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-10-10 23:55 267,776 ——w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-10-10 23:55 230,400 ——w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-10-10 23:55 214,528 —-a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-10-10 23:55 193,024 —-a-w C:\WINDOWS\system32\dllcache\msrating.dll
2007-10-10 23:55 153,088 ——w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-10-10 23:55 132,608 —-a-w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-10-10 23:55 124,928 ——w C:\WINDOWS\system32\dllcache\advpack.dll
2007-10-10 23:55 105,984 ——w C:\WINDOWS\system32\dllcache\url.dll
2007-10-10 23:55 102,400 ——w C:\WINDOWS\system32\dllcache\occache.dll
2007-10-10 10:59 70,656 ——w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-10-10 10:59 625,152 ——w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-10-10 10:59 13,824 ——w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-10-10 05:46 161,792 ——w C:\WINDOWS\system32\dllcache\ieakui.dll
2002-07-26 21:02 153,088 —-a-w C:\Program Files\UNWISE.EXE
2007-09-27 02:35 56 –sh–r C:\WINDOWS\system32\4D8E059C41.sys
2007-09-27 02:35 1,682 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6EA84A96-138F-4BA8-9FD2-F8E430728F39}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CA4F0D8D-5F2B-4F16-838A-8D52249EAB21}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CEE4AF87-77B6-4FA8-84D4-4D1FBB895037}]
2007-12-29 00:03 338432 ——— C:\WINDOWS\system32\mllmn.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe" [2007-12-29 00:09]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-12-29 00:04]
"AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-12-29 00:04]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-12-29 00:04]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-12-29 00:04]
"IntelMeM"="C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" [2007-12-29 00:04]
"CTSysVol"="C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe" [2007-12-29 00:04]
"P17Helper"="Rundll32 P17.dll" []
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2007-12-29 00:04]
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2007-12-29 00:04]
"mmtask"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe" [2007-12-29 00:04]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2007-12-29 00:05]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2007-12-29 00:05]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2007-12-29 00:05]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2007-12-29 00:05]
"EPSON Stylus CX5400"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.exe" [2007-12-29 00:05]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2007-12-29 00:05]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2007-12-29 00:05]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2007-12-29 00:05]
"PinnacleDriverCheck"="C:\WINDOWS\system32\\PSDrvCheck.exe" [2007-12-29 00:05]
"PCLEUSBTip"="C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe" [2007-12-29 00:05]
"USB2Check"="RUNDLL32.exe" [2004-08-04 05:00 C:\WINDOWS\system32\rundll32.exe]
"USBToolTip"="C:\Program Files\Pinnacle\Shared Files\\Programs\USBTip\USBTip.exe" [2007-12-29 00:05]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2007-12-29 00:05]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2007-12-29 00:05]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-12-28 19:42]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-12-29 00:05]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-29 00:05]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-29 00:05]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-12-29 00:05]

C:\Documents and Settings\Nick\Start Menu\Programs\Startup\
HotSync Manager.lnk - C:\Program Files\Palm\HOTSYNC.EXE [2003-09-25 09:47:12]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Dataviz Messenger.lnk - C:\WINDOWS\DvzCommon\DvzMsgr.exe [2003-07-01 20:16:46]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 15:05:56]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 11:59:36]
Run Nintendo Wi-Fi USB Connector Registration Tool.lnk - C:\Program Files\WiFiConnector\NintendoWFCReg.exe [2006-12-25 22:11:14]

[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows]
"load"=C:\WINDOWS\system32\mllmn.exe

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\mllmn

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

R3 P17;Sound Blaster Live! 24-bit;C:\WINDOWS\system32\drivers\P17.sys [2004-06-09 17:16]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver;C:\WINDOWS\system32\drivers\WmBEnum.sys [2005-04-12 19:21]
R3 WmXlCore;Logitech WingMan Translation Layer Driver;C:\WINDOWS\system32\drivers\WmXlCore.sys [2005-04-12 19:21]
S3 gsplittm;gsplittm;C:\DOCUME~1\Nick\LOCALS~1\Temp\gsplittm.sys []
S3 WmFilter;Logitech Gaming HID Filter Driver;C:\WINDOWS\system32\drivers\WmFilter.sys [2005-04-12 19:21]
S3 WmVirHid;Logitech Virtual Hid Device Driver;C:\WINDOWS\system32\drivers\WmVirHid.sys [2005-04-12 19:21]

.
Contents of the 'Scheduled Tasks' folder
"2007-12-24 15:30:54 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-12-28 23:50:05 C:\WINDOWS\Tasks\User_Feed_Synchronization-{50D0D4BC-426E-44B2-9BFA-DEE6413827B3}.job"
- C:\WINDOWS\system32\msfeedssync.exe
"2007-12-28 20:11:35 C:\WINDOWS\Tasks\User_Feed_Synchronization-{92AE00CF-95FA-45D4-8547-820AEBE39993}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-29 00:08:09
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwClose

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

C:\WINDOWS\system32\nmllm.ini 441 bytes
C:\WINDOWS\system32\nmllm.ini2 441 bytes

scan completed successfully
hidden files: 2

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\WINDOWS\system32\mllmn.dll
.
Completion time: 2007-12-29 0:15:08 - machine was rebooted
.
2007-12-27 12:33:26 — E O F —

PC seems better already……. ……… :thumbup:

Attachments:

Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\mllmn.exe
C:\WINDOWS\system32\mllmn.dll
C:\DOCUME~1\Nick\LOCALS~1\Temp\gsplittm.sys

Folder::
C:\Documents and Settings\All Users\Application Data\TEMP

Driver::
gsplittm

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6EA84A96-138F-4BA8-9FD2-F8E430728F39}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CA4F0D8D-5F2B-4F16-838A-8D52249EAB21}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CEE4AF87-77B6-4FA8-84D4-4D1FBB895037}]
[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows]
"load"=-


Save this as Save this as "CFScript"


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
Here is the HiJ log from today

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:40:45 AM, on 12/29/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Spyware Doctor\SDTrayApp .exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM .exe
C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol .exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray .exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask .exe
C:\Program Files\Dell\Media Experience\DMXLauncher .exe
C:\Program Files\Real\RealPlayer\RealPlay .exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1 .EXE
C:\WINDOWS\system32\igfxpers .exe
C:\WINDOWS\system32\hkcmd .exe
C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip .exe
C:\WINDOWS\system32\dla\tfswctrl .exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ .exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient .exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp .exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\DvzCommon\DvzMsgr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer .exe
C:\WINDOWS\system32\ctfmon .exe
C:\Program Files\DellSupport\DSAgnt .exe
C:\Program Files\WiFiConnector\NintendoWFCReg.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\Spyware.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotwheelscollectors.com/default.aspx
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
F3 - REG:win.ini: load=C:\WINDOWS\system32\mllmn.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll
O2 - BHO: (no name) - {49C99FB8-0B7D-4847-891C-E2ED683AD2EC} - C:\WINDOWS\system32\mllmn.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [EPSON Stylus CX5400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE /P19 "EPSON Stylus CX5400" /O6 "USB001" /M "Stylus CX5400"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\\PSDrvCheck.exe
O4 - HKLM\..\Run: [PCLEUSBTip] C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "C:\WINDOWS\system32\PCLECoInst.dll",CheckUSBController
O4 - HKLM\..\Run: [USBToolTip] "C:\Program Files\Pinnacle\Shared Files\\Programs\USBTip\USBTip.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask .exe" -atboottime
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe" -scheduler
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Dataviz Messenger.lnk = C:\WINDOWS\DvzCommon\DvzMsgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Run Nintendo Wi-Fi USB Connector Registration Tool.lnk = C:\Program Files\WiFiConnector\NintendoWFCReg.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} - http://a19.g.akamai.net/7/19/7125/4058/ftp…ver/Coupons.cab
O16 - DPF: {D2349304-8F9E-4A54-ACF6-0F6104B44209} (SketchCtl.Pic1) - http://auditor.cuyahogacounty.us/repi/sketch/Sketch.ocx
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 10091 bytes

Here is the combofix log

ComboFix 07-12-21.4 - Mark 2007-12-29 8:11:50.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.154 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\CFScript.txt
* Created a new restore point

FILE
C:\DOCUME~1\Nick\LOCALS~1\Temp\gsplittm.sys
C:\WINDOWS\system32\mllmn.dll
C:\WINDOWS\system32\mllmn.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\TEMP
C:\WINDOWS\system32\mllmn.dll
C:\WINDOWS\system32\mllmn.exe
C:\WINDOWS\system32\nmllm.ini
C:\WINDOWS\system32\nmllm.ini2

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_GSPLITTM
——-\gsplittm


((((((((((((((((((((((((( Files Created from 2007-11-28 to 2007-12-29 )))))))))))))))))))))))))))))))
.

2007-12-29 08:34 . 2007-12-29 08:34 390 –ahs—- C:\WINDOWS\system32\nmllm.ini2
2007-12-29 08:34 . 2007-12-29 08:34 390 –ahs—- C:\WINDOWS\system32\nmllm.ini
2007-12-29 08:27 . 2007-12-29 08:27 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-29 08:27 . 2007-12-29 08:27 338,432 ——— C:\WINDOWS\system32\mllmn.dll
2007-12-28 20:36 . 2007-12-28 20:36 342,016 –a—— C:\WINDOWS\system32\RCX105.tmp
2007-12-28 19:48 . 2007-12-28 19:48 350,720 –a—— C:\WINDOWS\system32\regscan .exe
2007-12-28 19:47 . 2007-12-28 19:47 342,016 –a—— C:\WINDOWS\system32\RCXED.tmp
2007-12-28 17:13 . 2007-12-28 17:22 74,240 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2007-12-28 17:13 . 2007-12-28 17:22 56,832 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2007-12-28 17:13 . 2007-10-18 00:14 41,288 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-12-28 17:13 . 2007-10-18 00:16 29,000 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2007-12-28 17:12 . 2007-12-29 08:30 d——– C:\Program Files\Spyware Doctor
2007-12-28 17:12 . 2007-12-28 17:12 d——– C:\Documents and Settings\Mark\Application Data\PC Tools
2007-12-28 17:11 . 2005-09-23 08:29 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-12-28 11:44 . 2007-12-28 11:44 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2007-12-28 11:44 . 2007-12-28 11:44 1,409 –a—— C:\WINDOWS\QTFont.for
2007-12-28 11:31 . 2007-12-28 11:31 d——– C:\Documents and Settings\Mark\Application Data\Apple Computer
2007-12-28 11:09 . 2007-12-28 11:09 d——– C:\Program Files\Apple Software Update
2007-12-28 11:07 . 2007-12-28 11:07 d—-c— C:\WINDOWS\system32\DRVSTORE
2007-12-28 11:06 . 2007-12-28 11:06 d——– C:\Documents and Settings\All Users\Application Data\Apple
2007-12-27 11:08 . 2005-08-26 12:11 d——– C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
2007-12-27 11:08 . 2005-08-26 12:24 d——– C:\Documents and Settings\Administrator\Application Data\Creative
2007-12-26 23:14 . 2007-12-26 23:13 102,664 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2007-12-26 23:13 . 2007-12-26 23:31 d——– C:\Documents and Settings\Mark\.housecall6.6
2007-12-26 22:49 . 2007-12-26 22:49 d——– C:\Program Files\Trend Micro
2007-12-26 13:10 . 2007-12-04 07:54 95,608 –a—— C:\WINDOWS\system32\AvastSS.scr
2007-12-26 13:10 . 2007-12-04 09:55 94,544 –a—— C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-26 13:10 . 2007-12-04 09:56 93,264 –a—— C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-26 13:10 . 2007-12-04 09:51 42,912 –a—— C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-26 13:10 . 2007-12-04 09:49 26,624 –a—— C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-26 13:10 . 2007-12-04 09:53 23,152 –a—— C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-26 13:09 . 2007-12-04 08:04 837,496 –a—— C:\WINDOWS\system32\aswBoot.exe
2007-12-26 13:09 . 2004-01-09 04:13 380,928 –a—— C:\WINDOWS\system32\actskin4.ocx
2007-12-26 12:50 . 2007-12-29 08:29 406,016 –a—— C:\WINDOWS\system32\PSDrvCheck .exe
2007-12-26 12:50 . 2007-12-29 08:29 114,688 –a—— C:\WINDOWS\system32\igfxpers .exe
2007-12-26 12:50 . 2007-12-29 08:29 94,208 –a—— C:\WINDOWS\system32\igfxtray .exe
2007-12-26 12:50 . 2007-12-29 08:29 77,824 –a—— C:\WINDOWS\system32\hkcmd .exe
2007-12-26 12:49 . 2007-12-29 08:28 90,112 –a—— C:\WINDOWS\UpdReg .EXE
2007-12-26 12:46 . 2007-12-29 08:31 15,360 –a—— C:\WINDOWS\system32\ctfmon .exe
2007-12-25 09:58 . 2007-12-26 20:14 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-24 14:55 . 2007-12-24 14:55 342,016 –a—— C:\WINDOWS\system32\RCX5C.tmp
2007-12-24 10:40 . 2007-12-28 11:29 d——– C:\Program Files\iTunes
2007-12-24 10:40 . 2007-12-24 10:40 d——– C:\Program Files\iPod
2007-12-24 10:30 . 2007-12-26 12:35 d——– C:\Program Files\Apple Software Update(2)
2007-12-24 10:27 . 2007-12-24 10:27 d——– C:\Program Files\Common Files\Apple
2007-12-18 20:48 . 2007-12-18 20:48 d——– C:\Program Files\Logitech
2007-12-18 20:48 . 2007-12-18 20:48 d——– C:\Program Files\Common Files\Logitech
2007-12-18 20:48 . 2005-04-12 19:21 45,504 –a—— C:\WINDOWS\system32\drivers\WmXlCore.sys
2007-12-18 20:48 . 2005-04-12 19:21 22,240 –a—— C:\WINDOWS\system32\drivers\WmFilter.sys
2007-12-18 20:48 . 2005-04-12 19:21 10,144 –a—— C:\WINDOWS\system32\drivers\WmBEnum.sys
2007-12-18 20:48 . 2005-04-12 19:21 5,600 –a—— C:\WINDOWS\system32\drivers\WmVirHid.sys
2007-12-15 22:27 . 2007-12-23 23:02 d——– C:\Program Files\Project64 1.6
2007-12-11 10:57 . 2007-12-11 10:57 65,536 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2007-12-11 10:57 . 2007-12-11 10:57 49,152 –a—— C:\WINDOWS\system32\QuickTime.qts
2007-12-09 20:59 . 2007-12-10 22:01 d——– C:\Program Files\Azureus
2007-12-09 20:59 . 2007-12-13 16:48 d——– C:\Documents and Settings\Nick\Application Data\Azureus
2007-12-09 20:53 . 2007-12-09 20:53 d——– C:\Downloads
2007-11-30 17:19 . 2007-11-30 17:19 d——– C:\Program Files\IZArc

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-29 13:30 342,016 —-a-w C:\WINDOWS\system32\mllmn.exe
2007-12-29 13:30 ——— d—–w C:\Program Files\QuickTime
2007-12-29 13:27 358,912 —-a-w C:\WINDOWS\system32\ctfmon.exe
2007-12-29 13:27 ——— d—–w C:\Program Files\DellSupport
2007-12-29 13:14 757,760 —-a-w C:\WINDOWS\system32\PSDrvCheck.exe
2007-12-29 13:14 457,728 —-a-w C:\WINDOWS\system32\igfxpers.exe
2007-12-29 13:14 437,248 —-a-w C:\WINDOWS\system32\igfxtray.exe
2007-12-29 13:14 420,864 —-a-w C:\WINDOWS\system32\hkcmd.exe
2007-12-29 13:13 434,688 —-a-w C:\WINDOWS\UpdReg.EXE
2007-12-28 16:18 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-12-27 19:06 ——— d—–w C:\Program Files\Quicken
2007-12-24 15:42 ——— d—–w C:\Documents and Settings\Nick\Application Data\Apple Computer
2007-12-21 23:58 11,031,348 —-a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2007-12-21 23:08 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-10 02:45 ——— d—–w C:\Program Files\BitComet
2007-11-29 00:55 ——— d—–w C:\Documents and Settings\All Users\Application Data\Smilebox
2007-11-18 14:05 ——— d—–w C:\Program Files\Java
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-11 22:05 73,216 —-a-w C:\WINDOWS\ST6UNST.EXE
2007-11-11 22:04 19,659,826 —-a-w C:\WINDOWS\system32\lebronjames0607.scr
2007-11-03 20:13 ——— d—–w C:\Program Files\Fire International
2007-11-03 13:52 49,827 —-a-w C:\Uninstal.exe
2007-10-30 23:42 3,590,656 —-a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 ——w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-27 22:40 222,720 —-a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 22:40 222,720 —-a-w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-10 23:56 824,832 —-a-w C:\WINDOWS\system32\dllcache\wininet.dll
2007-10-10 23:56 232,960 ——w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-10-10 23:56 1,159,680 —-a-w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-10-10 23:55 671,232 —-a-w C:\WINDOWS\system32\dllcache\mstime.dll
2007-10-10 23:55 63,488 ——w C:\WINDOWS\system32\dllcache\icardie.dll
2007-10-10 23:55 6,065,664 ——w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-10-10 23:55 52,224 ——w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-10-10 23:55 478,208 —-a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-10-10 23:55 459,264 ——w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-10-10 23:55 44,544 ——w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-10-10 23:55 384,512 ——w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-10-10 23:55 383,488 ——w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-10-10 23:55 27,648 —-a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-10-10 23:55 267,776 ——w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-10-10 23:55 230,400 ——w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-10-10 23:55 214,528 —-a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-10-10 23:55 193,024 —-a-w C:\WINDOWS\system32\dllcache\msrating.dll
2007-10-10 23:55 153,088 ——w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-10-10 23:55 132,608 —-a-w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-10-10 23:55 124,928 ——w C:\WINDOWS\system32\dllcache\advpack.dll
2007-10-10 23:55 105,984 ——w C:\WINDOWS\system32\dllcache\url.dll
2007-10-10 23:55 102,400 ——w C:\WINDOWS\system32\dllcache\occache.dll
2007-10-10 10:59 70,656 ——w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-10-10 10:59 625,152 ——w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-10-10 10:59 13,824 ——w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-10-10 05:46 161,792 ——w C:\WINDOWS\system32\dllcache\ieakui.dll
2002-07-26 21:02 153,088 —-a-w C:\Program Files\UNWISE.EXE
2007-09-27 02:35 56 –sh–r C:\WINDOWS\system32\4D8E059C41.sys
2007-09-27 02:35 1,682 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((( snapshot@2007-12-29_ 0.13.39.59 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-12-29 04:07:32 122,941 —-a-w C:\WINDOWS\system32\dla\tfswctrl .exe
+ 2007-12-29 13:30:10 122,941 —-a-w C:\WINDOWS\system32\dla\tfswctrl .exe
- 2007-12-29 05:05:24 491,520 —-a-w C:\WINDOWS\system32\dla\tfswctrl.exe
+ 2007-12-29 13:14:37 491,520 —-a-w C:\WINDOWS\system32\dla\tfswctrl.exe
- 2007-12-29 04:06:48 99,840 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S4I2G1 .EXE
+ 2007-12-29 13:29:08 99,840 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S4I2G1 .EXE
- 2007-12-29 05:05:13 448,000 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S4I2G1.EXE
+ 2007-12-29 13:14:08 448,000 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S4I2G1.EXE
- 2007-12-29 05:07:07 16,384 –sha-w C:\WINDOWS\Temp\Cookies\index.dat
+ 2007-12-29 13:28:33 16,384 –sha-w C:\WINDOWS\Temp\Cookies\index.dat
- 2007-12-29 05:07:07 16,384 –sha-w C:\WINDOWS\Temp\History\History.IE5\index.dat
+ 2007-12-29 13:28:33 16,384 –sha-w C:\WINDOWS\Temp\History\History.IE5\index.dat
+ 2007-12-29 13:26:36 16,384 —-atw C:\WINDOWS\Temp\Perflib_Perfdata_698.dat
- 2007-12-29 05:07:07 32,768 –sha-w C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\index.dat
+ 2007-12-29 13:28:33 32,768 –sha-w C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{49C99FB8-0B7D-4847-891C-E2ED683AD2EC}]
2007-12-29 08:27 338432 ——— C:\WINDOWS\system32\mllmn.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CEE4AF87-77B6-4FA8-84D4-4D1FBB895037}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe" [2007-12-29 08:28]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-12-29 08:27]
"AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-12-29 08:28]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-12-29 08:28]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-12-29 08:13]
"IntelMeM"="C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" [2007-12-29 08:13]
"CTSysVol"="C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe" [2007-12-29 08:13]
"P17Helper"="Rundll32 P17.dll" []
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2007-12-29 08:13]
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2007-12-29 08:13]
"mmtask"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe" [2007-12-29 08:13]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2007-12-29 08:13]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2007-12-29 08:13]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2007-12-29 08:14]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2007-12-29 08:14]
"EPSON Stylus CX5400"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.exe" [2007-12-29 08:14]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2007-12-29 08:14]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2007-12-29 08:14]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2007-12-29 08:14]
"PinnacleDriverCheck"="C:\WINDOWS\system32\\PSDrvCheck.exe" [2007-12-29 08:14]
"PCLEUSBTip"="C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe" [2007-12-29 08:14]
"USB2Check"="RUNDLL32.exe" [2004-08-04 05:00 C:\WINDOWS\system32\rundll32.exe]
"USBToolTip"="C:\Program Files\Pinnacle\Shared Files\\Programs\USBTip\USBTip.exe" [2007-12-29 08:14]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2007-12-29 08:14]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2007-12-29 08:14]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-12-28 19:42]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-12-29 08:30]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-29 08:30]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask .exe" [2007-12-29 08:30]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-12-29 08:30]

C:\Documents and Settings\Nick\Start Menu\Programs\Startup\
HotSync Manager.lnk - C:\Program Files\Palm\HOTSYNC.EXE [2003-09-25 09:47:12]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Dataviz Messenger.lnk - C:\WINDOWS\DvzCommon\DvzMsgr.exe [2003-07-01 20:16:46]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 15:05:56]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 11:59:36]
Run Nintendo Wi-Fi USB Connector Registration Tool.lnk - C:\Program Files\WiFiConnector\NintendoWFCReg.exe [2006-12-25 22:11:14]

[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows]
"load"=C:\WINDOWS\system32\mllmn.exe

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\mllmn

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

R3 P17;Sound Blaster Live! 24-bit;C:\WINDOWS\system32\drivers\P17.sys [2004-06-09 17:16]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver;C:\WINDOWS\system32\drivers\WmBEnum.sys [2005-04-12 19:21]
R3 WmXlCore;Logitech WingMan Translation Layer Driver;C:\WINDOWS\system32\drivers\WmXlCore.sys [2005-04-12 19:21]
S3 WmFilter;Logitech Gaming HID Filter Driver;C:\WINDOWS\system32\drivers\WmFilter.sys [2005-04-12 19:21]
S3 WmVirHid;Logitech Virtual Hid Device Driver;C:\WINDOWS\system32\drivers\WmVirHid.sys [2005-04-12 19:21]

.
Contents of the 'Scheduled Tasks' folder
"2007-12-24 15:30:54 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-12-28 23:50:05 C:\WINDOWS\Tasks\User_Feed_Synchronization-{50D0D4BC-426E-44B2-9BFA-DEE6413827B3}.job"
- C:\WINDOWS\system32\msfeedssync.exe
"2007-12-28 20:11:35 C:\WINDOWS\Tasks\User_Feed_Synchronization-{92AE00CF-95FA-45D4-8547-820AEBE39993}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-29 08:34:48
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwClose

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\WINDOWS\system32\mllmn.dll
-> C:\Program Files\ArcSoft\Software Suite\PhotoImpression 5\share\pihook.dll
.
Completion time: 2007-12-29 8:38:54 - machine was rebooted
C:\ComboFix2.txt … 2007-12-29 00:15

PC is booting faster than it had been, overall performance is better! No registry errors on start up!
Spyware Doctor was run and still found 5 Infections including Vitumonde. It tried to delete mllmn.dll in the C:\windows\system32 directory but could not, because some background process was using it. I tried to delete it in SAFE mode and could not.

see the attached word doc w/ screen shots of spyware :o
1. Download RenV.exe by sUBs to your desktop
2. Double click on it to run it
It will search your system drive looking for any modified .exe file and will produce a log for you.
3. Please attach this report to your reply (Do not copy and paste)
All of those files got renamed by the infection. It added an extra space into the filename.

Example:

Original Name: "Reader_sl.exe"
Name modified by the infection: "Reader_sl .exe"



[external image: Posted Image]

Refering to the picture above, drag Log.txt into RenV.exe

When finished, it shall produce a new log for you. Post that log in your next reply.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you, combofix.txt. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick while its running. That may cause it to stall
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:01:08 PM, on 12/31/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient .exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\DvzCommon\DvzMsgr.exe
C:\Program Files\WiFiConnector\NintendoWFCReg.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\Spyware.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotwheelscollectors.com/default.aspx
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [EPSON Stylus CX5400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE /P19 "EPSON Stylus CX5400" /O6 "USB001" /M "Stylus CX5400"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\\PSDrvCheck.exe
O4 - HKLM\..\Run: [PCLEUSBTip] C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "C:\WINDOWS\system32\PCLECoInst.dll",CheckUSBController
O4 - HKLM\..\Run: [USBToolTip] "C:\Program Files\Pinnacle\Shared Files\\Programs\USBTip\USBTip.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask .exe" -atboottime
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Dataviz Messenger.lnk = C:\WINDOWS\DvzCommon\DvzMsgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Run Nintendo Wi-Fi USB Connector Registration Tool.lnk = C:\Program Files\WiFiConnector\NintendoWFCReg.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} - http://a19.g.akamai.net/7/19/7125/4058/ftp…ver/Coupons.cab
O16 - DPF: {D2349304-8F9E-4A54-ACF6-0F6104B44209} (SketchCtl.Pic1) - http://auditor.cuyahogacounty.us/repi/sketch/Sketch.ocx
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 9917 bytes
ComboFix 07-12-21.4 - Mark 2007-12-31 13:11:20.3 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\mllmn.dll
C:\WINDOWS\system32\nmllm.ini
C:\WINDOWS\system32\nmllm.ini2
C:\WINDOWS\system32\regscan.exe

.
((((((((((((((((((((((((( Files Created from 2007-11-28 to 2007-12-31 )))))))))))))))))))))))))))))))
.

2007-12-31 11:30 . 2007-12-30 17:50 406,016 –a—— C:\WINDOWS\system32\PSDrvCheck.exe
2007-12-30 16:42 . 2007-12-30 16:42 342,016 –a—— C:\WINDOWS\system32\RCX58.tmp
2007-12-30 13:06 . 2007-12-30 13:06 342,016 –a—— C:\WINDOWS\system32\RCX57.tmp
2007-12-29 08:45 . 2007-12-30 13:29 342,016 –a—— C:\WINDOWS\system32\mllmn.exe
2007-12-29 08:27 . 2007-12-31 13:52 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-28 20:36 . 2007-12-28 20:36 342,016 –a—— C:\WINDOWS\system32\RCX105.tmp
2007-12-28 19:47 . 2007-12-28 19:47 342,016 –a—— C:\WINDOWS\system32\RCXED.tmp
2007-12-28 17:13 . 2007-12-28 17:22 74,240 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2007-12-28 17:13 . 2007-12-28 17:22 56,832 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2007-12-28 17:13 . 2007-10-18 00:14 41,288 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-12-28 17:13 . 2007-10-18 00:16 29,000 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2007-12-28 17:12 . 2007-12-31 11:30 d——– C:\Program Files\Spyware Doctor
2007-12-28 17:12 . 2007-12-28 17:12 d——– C:\Documents and Settings\Mark\Application Data\PC Tools
2007-12-28 17:11 . 2005-09-23 08:29 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-12-28 11:31 . 2007-12-28 11:31 d——– C:\Documents and Settings\Mark\Application Data\Apple Computer
2007-12-28 11:09 . 2007-12-28 11:09 d——– C:\Program Files\Apple Software Update
2007-12-28 11:07 . 2007-12-28 11:07 d—-c— C:\WINDOWS\system32\DRVSTORE
2007-12-28 11:07 . 2007-10-31 14:09 30,464 –a—— C:\WINDOWS\system32\drivers\usbaapl.sys
2007-12-28 11:06 . 2007-12-28 11:06 d——– C:\Documents and Settings\All Users\Application Data\Apple
2007-12-27 11:08 . 2005-08-26 12:11 d——– C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
2007-12-27 11:08 . 2005-08-26 12:24 d——– C:\Documents and Settings\Administrator\Application Data\Creative
2007-12-26 23:14 . 2007-12-26 23:13 102,664 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2007-12-26 23:13 . 2007-12-26 23:31 d——– C:\Documents and Settings\Mark\.housecall6.6
2007-12-26 22:49 . 2007-12-26 22:49 d——– C:\Program Files\Trend Micro
2007-12-26 13:10 . 2007-12-04 07:54 95,608 –a—— C:\WINDOWS\system32\AvastSS.scr
2007-12-26 13:10 . 2007-12-04 09:55 94,544 –a—— C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-26 13:10 . 2007-12-04 09:56 93,264 –a—— C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-26 13:10 . 2007-12-04 09:51 42,912 –a—— C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-26 13:10 . 2007-12-04 09:49 26,624 –a—— C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-26 13:10 . 2007-12-04 09:53 23,152 –a—— C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-26 13:09 . 2007-12-04 08:04 837,496 –a—— C:\WINDOWS\system32\aswBoot.exe
2007-12-26 13:09 . 2004-01-09 04:13 380,928 –a—— C:\WINDOWS\system32\actskin4.ocx
2007-12-25 09:58 . 2007-12-26 20:14 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-24 14:55 . 2007-12-24 14:55 342,016 –a—— C:\WINDOWS\system32\RCX5C.tmp
2007-12-24 10:40 . 2007-12-28 11:29 d——– C:\Program Files\iTunes
2007-12-24 10:40 . 2007-12-24 10:40 d——– C:\Program Files\iPod
2007-12-24 10:30 . 2007-12-26 12:35 d——– C:\Program Files\Apple Software Update(2)
2007-12-24 10:27 . 2007-12-24 10:27 d——– C:\Program Files\Common Files\Apple
2007-12-18 20:48 . 2007-12-18 20:48 d——– C:\Program Files\Logitech
2007-12-18 20:48 . 2007-12-18 20:48 d——– C:\Program Files\Common Files\Logitech
2007-12-18 20:48 . 2005-04-12 19:21 45,504 –a—— C:\WINDOWS\system32\drivers\WmXlCore.sys
2007-12-18 20:48 . 2005-04-12 19:21 22,240 –a—— C:\WINDOWS\system32\drivers\WmFilter.sys
2007-12-18 20:48 . 2005-04-12 19:21 10,144 –a—— C:\WINDOWS\system32\drivers\WmBEnum.sys
2007-12-18 20:48 . 2005-04-12 19:21 5,600 –a—— C:\WINDOWS\system32\drivers\WmVirHid.sys
2007-12-15 22:27 . 2007-12-29 11:34 d——– C:\Program Files\Project64 1.6
2007-12-11 10:57 . 2007-12-11 10:57 65,536 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2007-12-11 10:57 . 2007-12-11 10:57 49,152 –a—— C:\WINDOWS\system32\QuickTime.qts
2007-12-09 20:59 . 2007-12-10 22:01 d——– C:\Program Files\Azureus
2007-12-09 20:59 . 2007-12-13 16:48 d——– C:\Documents and Settings\Nick\Application Data\Azureus
2007-12-09 20:53 . 2007-12-09 20:53 d——– C:\Downloads
2007-11-30 17:19 . 2007-11-30 17:19 d——– C:\Program Files\IZArc
2007-11-18 09:05 . 2007-09-24 23:31 69,632 –a—— C:\WINDOWS\system32\javacpl.cpl
2007-11-11 17:05 . 2007-11-11 17:05 1,966 –a—— C:\WINDOWS\system32\ST6UNST.001
2007-11-11 17:04 . 2007-11-11 17:04 19,659,826 –a—— C:\WINDOWS\system32\lebronjames0607.scr
2007-11-11 17:04 . 2007-11-11 17:05 1,948 –a—— C:\WINDOWS\system32\ST6UNST.000
2007-11-11 17:03 . 2007-11-11 17:05 364,544 ——— C:\WINDOWS\support.cn
2007-11-11 17:03 . 2007-11-11 17:05 73,216 –a—— C:\WINDOWS\ST6UNST.EXE
2007-11-03 15:15 . 2007-11-24 09:57 d——– C:\WINDOWS\Firesoft
2007-11-03 13:47 . 2007-11-03 15:13 d——– C:\Program Files\Fire International
2007-11-03 08:52 . 2007-11-03 08:52 49,827 –a—— C:\Uninstal.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-31 16:30 ——— d—–w C:\Program Files\QuickTime
2007-12-31 16:30 ——— d—–w C:\Program Files\DellSupport
2007-12-30 22:49 90,112 —-a-w C:\WINDOWS\UpdReg.EXE
2007-12-30 21:07 ——— d—–w C:\Program Files\Quicken
2007-12-28 16:18 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-12-24 15:42 ——— d—–w C:\Documents and Settings\Nick\Application Data\Apple Computer
2007-12-21 23:08 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-10 02:45 ——— d—–w C:\Program Files\BitComet
2007-11-29 00:55 ——— d—–w C:\Documents and Settings\All Users\Application Data\Smilebox
2007-11-18 14:05 ——— d—–w C:\Program Files\Java
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2002-07-26 21:02 153,088 —-a-w C:\Program Files\UNWISE.EXE
2007-09-27 02:35 56 –sh–r C:\WINDOWS\system32\4D8E059C41.sys
2007-09-27 02:35 1,682 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((( snapshot@2007-12-29_ 0.13.39.59 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-12-28 16:32:20 102,400 —-a-r C:\WINDOWS\Installer\{18388EF8-E0A3-442B-8BFE-E2F1B3D05C91}\iTunesIco.exe
+ 2007-12-29 16:36:21 102,400 —-a-r C:\WINDOWS\Installer\{18388EF8-E0A3-442B-8BFE-E2F1B3D05C91}\iTunesIco.exe
- 2004-08-04 10:00:00 15,360 —-a-w C:\WINDOWS\system32\ctfmon.exe
+ 2007-12-30 21:43:26 15,360 —-a-w C:\WINDOWS\system32\ctfmon.exe
- 2007-12-29 04:07:32 122,941 —-a-w C:\WINDOWS\system32\dla\tfswctrl .exe
+ 2007-12-30 21:42:48 122,941 —-a-w C:\WINDOWS\system32\dla\tfswctrl .exe
- 2007-12-29 05:05:24 491,520 —-a-w C:\WINDOWS\system32\dla\tfswctrl.exe
+ 2007-12-30 21:42:48 122,941 —-a-w C:\WINDOWS\system32\dla\tfswctrl.exe
- 2004-08-04 10:00:00 15,360 —-a-w C:\WINDOWS\system32\dllcache\ctfmon.exe
+ 2007-12-30 21:43:26 15,360 —-a-w C:\WINDOWS\system32\dllcache\ctfmon.exe
- 2007-12-29 05:05:18 420,864 —-a-w C:\WINDOWS\system32\hkcmd.exe
+ 2007-12-30 21:42:34 77,824 —-a-w C:\WINDOWS\system32\hkcmd.exe
- 2007-12-29 05:05:20 457,728 —-a-w C:\WINDOWS\system32\igfxpers.exe
+ 2007-12-30 21:42:35 114,688 —-a-w C:\WINDOWS\system32\igfxpers.exe
- 2007-12-29 05:05:15 437,248 —-a-w C:\WINDOWS\system32\igfxtray.exe
+ 2007-12-30 22:50:47 94,208 —-a-w C:\WINDOWS\system32\igfxtray.exe
- 2007-12-29 05:05:13 448,000 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S4I2G1.EXE
+ 2007-12-30 21:42:29 99,840 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S4I2G1.EXE
+ 2007-12-31 18:52:05 16,384 —-atw C:\WINDOWS\Temp\Perflib_Perfdata_69c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{891B4C5A-13AD-4875-A895-8ECF535DBFEE}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CEE4AF87-77B6-4FA8-84D4-4D1FBB895037}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2007-12-26 13:07]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2007-12-30 16:43]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2007-12-30 16:42]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-12-30 16:43]
"AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-12-30 16:43]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-12-30 16:43]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-12-30 16:42]
"IntelMeM"="C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" [2007-12-30 16:42]
"CTSysVol"="C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe" [2007-12-30 16:42]
"P17Helper"="Rundll32 P17.dll" []
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2007-12-30 17:49]
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2007-12-30 16:42]
"mmtask"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe" [2007-12-30 16:42]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2007-12-30 16:42]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2007-12-30 16:42]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2007-12-30 17:50]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2007-12-30 16:42]
"EPSON Stylus CX5400"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.exe" [2007-12-30 16:42]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2007-12-30 17:50]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2007-12-30 16:42]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2007-12-30 16:42]
"PinnacleDriverCheck"="C:\WINDOWS\system32\\PSDrvCheck.exe" [2007-12-30 17:50]
"PCLEUSBTip"="C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe" [2007-12-30 16:42]
"USB2Check"="RUNDLL32.exe" [2004-08-04 05:00 C:\WINDOWS\system32\rundll32.exe]
"USBToolTip"="C:\Program Files\Pinnacle\Shared Files\\Programs\USBTip\USBTip.exe" [2007-12-30 16:42]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2007-12-30 16:42]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2007-12-30 16:42]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-12-29 17:23]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-12-30 17:51]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 08:00]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask .exe" []
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-12-31 11:27]

C:\Documents and Settings\Nick\Start Menu\Programs\Startup\
HotSync Manager.lnk - C:\Program Files\Palm\HOTSYNC.EXE [2003-09-25 09:47:12]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Dataviz Messenger.lnk - C:\WINDOWS\DvzCommon\DvzMsgr.exe [2003-07-01 20:16:46]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 15:05:56]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 11:59:36]
Run Nintendo Wi-Fi USB Connector Registration Tool.lnk - C:\Program Files\WiFiConnector\NintendoWFCReg.exe [2006-12-25 22:11:14]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

R3 P17;Sound Blaster Live! 24-bit;C:\WINDOWS\system32\drivers\P17.sys [2004-06-09 17:16]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver;C:\WINDOWS\system32\drivers\WmBEnum.sys [2005-04-12 19:21]
R3 WmXlCore;Logitech WingMan Translation Layer Driver;C:\WINDOWS\system32\drivers\WmXlCore.sys [2005-04-12 19:21]
S3 USBAAPL;Apple Mobile USB Driver;C:\WINDOWS\system32\Drivers\usbaapl.sys [2007-10-31 14:09]
S3 WmFilter;Logitech Gaming HID Filter Driver;C:\WINDOWS\system32\drivers\WmFilter.sys [2005-04-12 19:21]
S3 WmVirHid;Logitech Virtual Hid Device Driver;C:\WINDOWS\system32\drivers\WmVirHid.sys [2005-04-12 19:21]

.
Contents of the 'Scheduled Tasks' folder
"2007-12-29 17:23:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-12-31 06:08:23 C:\WINDOWS\Tasks\User_Feed_Synchronization-{50D0D4BC-426E-44B2-9BFA-DEE6413827B3}.job"
- C:\WINDOWS\system32\msfeedssync.exe
"2007-12-31 18:55:42 C:\WINDOWS\Tasks\User_Feed_Synchronization-{92AE00CF-95FA-45D4-8547-820AEBE39993}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-31 13:54:59
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwClose

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-31 13:59:56 - machine was rebooted
C:\ComboFix2.txt … 2007-12-29 08:38
C:\ComboFix3.txt … 2007-12-29 00:15
.
2007-12-27 12:33:26 — E O F —
ZoneAlarm was running in the background when ComboFix was running, kept getting "nrcmd.cfexe" was trying to access the trusted zone. I allowed this because it appeared CFix needed this to complete and move on to the next stage.

After CFix startup Spybot detected a deletion of mllmn.exe which I allowed.

thanks again
Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\RCX58.tmp
C:\WINDOWS\system32\RCX57.tmp
C:\WINDOWS\system32\mllmn.exe
C:\WINDOWS\system32\RCX105.tmp
C:\WINDOWS\system32\RCXED.tmp
C:\WINDOWS\system32\RCX5C.tmp
C:\WINDOWS\system32\4D8E059C41.sys

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{891B4C5A-13AD-4875-A895-8ECF535DBFEE}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CEE4AF87-77B6-4FA8-84D4-4D1FBB895037}]


Save this as Save this as "CFScript"


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:12:37 PM, on 12/31/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Spyware Doctor\SDTrayApp .exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM .exe
C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol .exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray .exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask .exe
C:\Program Files\Real\RealPlayer\RealPlay .exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Dell\Media Experience\DMXLauncher .exe
C:\WINDOWS\system32\igfxpers .exe
C:\WINDOWS\system32\hkcmd .exe
C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip .exe
C:\WINDOWS\system32\dla\tfswctrl .exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ .exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp .exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe
C:\WINDOWS\DvzCommon\DvzMsgr.exe
C:\Program Files\DellSupport\DSAgnt .exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer .exe
C:\Program Files\WiFiConnector\NintendoWFCReg.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\Spyware.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotwheelscollectors.com/default.aspx
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
F3 - REG:win.ini: load=C:\WINDOWS\system32\mllmn.exe
O2 - BHO: (no name) - {034E9743-8FC4-4F89-8D1B-D11E302CB0FF} - C:\WINDOWS\system32\mllmn.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [EPSON Stylus CX5400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE /P19 "EPSON Stylus CX5400" /O6 "USB001" /M "Stylus CX5400"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\\PSDrvCheck.exe
O4 - HKLM\..\Run: [PCLEUSBTip] C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "C:\WINDOWS\system32\PCLECoInst.dll",CheckUSBController
O4 - HKLM\..\Run: [USBToolTip] "C:\Program Files\Pinnacle\Shared Files\\Programs\USBTip\USBTip.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask .exe" -atboottime
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe" -scheduler
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Dataviz Messenger.lnk = C:\WINDOWS\DvzCommon\DvzMsgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Run Nintendo Wi-Fi USB Connector Registration Tool.lnk = C:\Program Files\WiFiConnector\NintendoWFCReg.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.1.11.30.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} - http://a19.g.akamai.net/7/19/7125/4058/ftp…ver/Coupons.cab
O16 - DPF: {D2349304-8F9E-4A54-ACF6-0F6104B44209} (SketchCtl.Pic1) - http://auditor.cuyahogacounty.us/repi/sketch/Sketch.ocx
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 10052 bytes

ComboFix 07-12-21.4 - Mark 2007-12-31 16:28:54.4 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Mark\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\WINDOWS\system32\4D8E059C41.sys
C:\WINDOWS\system32\mllmn.exe
C:\WINDOWS\system32\RCX105.tmp
C:\WINDOWS\system32\RCX57.tmp
C:\WINDOWS\system32\RCX58.tmp
C:\WINDOWS\system32\RCX5C.tmp
C:\WINDOWS\system32\RCXED.tmp
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\4D8E059C41.sys
C:\WINDOWS\system32\mllmn.dll
C:\WINDOWS\system32\mllmn.exe
C:\WINDOWS\system32\nmllm.ini
C:\WINDOWS\system32\nmllm.ini2
C:\WINDOWS\system32\RCX105.tmp
C:\WINDOWS\system32\RCX57.tmp
C:\WINDOWS\system32\RCX58.tmp
C:\WINDOWS\system32\RCX5C.tmp
C:\WINDOWS\system32\RCXED.tmp

.
((((((((((((((((((((((((( Files Created from 2007-11-28 to 2007-12-31 )))))))))))))))))))))))))))))))
.

2007-12-31 16:53 . 2007-12-31 16:53 338,432 ——— C:\WINDOWS\system32\mllmn.dll
2007-12-31 16:02 . 2007-12-31 16:57 229,408 –ahs—- C:\WINDOWS\system32\drivers\fidbox.dat
2007-12-31 16:02 . 2007-12-31 16:51 3,668 –ahs—- C:\WINDOWS\system32\drivers\fidbox.idx
2007-12-31 15:57 . 2007-12-31 15:57 d——– C:\Documents and Settings\All Users\Application Data\MailFrontier
2007-12-31 15:28 . 2007-12-31 16:57 406,016 –a—— C:\WINDOWS\system32\PSDrvCheck .exe
2007-12-31 15:28 . 2007-12-31 16:57 114,688 –a—— C:\WINDOWS\system32\igfxpers .exe
2007-12-31 15:28 . 2007-12-31 16:57 94,208 –a—— C:\WINDOWS\system32\igfxtray .exe
2007-12-31 15:28 . 2007-12-31 16:56 90,112 –a—— C:\WINDOWS\UpdReg .EXE
2007-12-31 15:28 . 2007-12-31 16:57 77,824 –a—— C:\WINDOWS\system32\hkcmd .exe
2007-12-31 14:23 . 2007-12-31 14:23 15,360 –a—— C:\WINDOWS\system32\ctfmon .exe
2007-12-31 11:30 . 2007-12-31 16:54 757,760 –a—— C:\WINDOWS\system32\PSDrvCheck.exe
2007-12-29 08:27 . 2007-12-31 16:53 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-28 17:13 . 2007-12-28 17:22 74,240 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2007-12-28 17:13 . 2007-12-28 17:22 56,832 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2007-12-28 17:13 . 2007-10-18 00:14 41,288 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-12-28 17:13 . 2007-10-18 00:16 29,000 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2007-12-28 17:12 . 2007-12-31 16:55 d——– C:\Program Files\Spyware Doctor
2007-12-28 17:12 . 2007-12-28 17:12 d——– C:\Documents and Settings\Mark\Application Data\PC Tools
2007-12-28 17:11 . 2005-09-23 08:29 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-12-28 11:31 . 2007-12-28 11:31 d——– C:\Documents and Settings\Mark\Application Data\Apple Computer
2007-12-28 11:09 . 2007-12-28 11:09 d——– C:\Program Files\Apple Software Update
2007-12-28 11:07 . 2007-12-28 11:07 d—-c— C:\WINDOWS\system32\DRVSTORE
2007-12-28 11:07 . 2007-10-31 14:09 30,464 –a—— C:\WINDOWS\system32\drivers\usbaapl.sys
2007-12-28 11:06 . 2007-12-28 11:06 d——– C:\Documents and Settings\All Users\Application Data\Apple
2007-12-27 11:08 . 2005-08-26 12:11 d——– C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
2007-12-27 11:08 . 2005-08-26 12:24 d——– C:\Documents and Settings\Administrator\Application Data\Creative
2007-12-26 23:14 . 2007-12-26 23:13 102,664 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2007-12-26 23:13 . 2007-12-26 23:31 d——– C:\Documents and Settings\Mark\.housecall6.6
2007-12-26 22:49 . 2007-12-26 22:49 d——– C:\Program Files\Trend Micro
2007-12-26 13:10 . 2007-12-04 07:54 95,608 –a—— C:\WINDOWS\system32\AvastSS.scr
2007-12-26 13:10 . 2007-12-04 09:55 94,544 –a—— C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-26 13:10 . 2007-12-04 09:56 93,264 –a—— C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-26 13:10 . 2007-12-04 09:51 42,912 –a—— C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-26 13:10 . 2007-12-04 09:49 26,624 –a—— C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-26 13:10 . 2007-12-04 09:53 23,152 –a—— C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-26 13:09 . 2007-12-04 08:04 837,496 –a—— C:\WINDOWS\system32\aswBoot.exe
2007-12-26 13:09 . 2004-01-09 04:13 380,928 –a—— C:\WINDOWS\system32\actskin4.ocx
2007-12-25 09:58 . 2007-12-26 20:14 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-24 10:40 . 2007-12-28 11:29 d——– C:\Program Files\iTunes
2007-12-24 10:40 . 2007-12-24 10:40 d——– C:\Program Files\iPod
2007-12-24 10:30 . 2007-12-26 12:35 d——– C:\Program Files\Apple Software Update(2)
2007-12-24 10:27 . 2007-12-24 10:27 d——– C:\Program Files\Common Files\Apple
2007-12-18 20:48 . 2007-12-18 20:48 d——– C:\Program Files\Logitech
2007-12-18 20:48 . 2007-12-18 20:48 d——– C:\Program Files\Common Files\Logitech
2007-12-18 20:48 . 2005-04-12 19:21 45,504 –a—— C:\WINDOWS\system32\drivers\WmXlCore.sys
2007-12-18 20:48 . 2005-04-12 19:21 22,240 –a—— C:\WINDOWS\system32\drivers\WmFilter.sys
2007-12-18 20:48 . 2005-04-12 19:21 10,144 –a—— C:\WINDOWS\system32\drivers\WmBEnum.sys
2007-12-18 20:48 . 2005-04-12 19:21 5,600 –a—— C:\WINDOWS\system32\drivers\WmVirHid.sys
2007-12-15 22:27 . 2007-12-29 11:34 d——– C:\Program Files\Project64 1.6
2007-12-11 10:57 . 2007-12-11 10:57 65,536 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2007-12-11 10:57 . 2007-12-11 10:57 49,152 –a—— C:\WINDOWS\system32\QuickTime.qts
2007-12-09 20:59 . 2007-12-10 22:01 d——– C:\Program Files\Azureus
2007-12-09 20:59 . 2007-12-13 16:48 d——– C:\Documents and Settings\Nick\Application Data\Azureus
2007-12-09 20:53 . 2007-12-09 20:53 d——– C:\Downloads
2007-11-30 17:19 . 2007-11-30 17:19 d——– C:\Program Files\IZArc
2007-11-18 09:05 . 2007-09-24 23:31 69,632 –a—— C:\WINDOWS\system32\javacpl.cpl
2007-11-11 17:05 . 2007-11-11 17:05 1,966 –a—— C:\WINDOWS\system32\ST6UNST.001
2007-11-11 17:04 . 2007-11-11 17:04 19,659,826 –a—— C:\WINDOWS\system32\lebronjames0607.scr
2007-11-11 17:04 . 2007-11-11 17:05 1,948 –a—— C:\WINDOWS\system32\ST6UNST.000
2007-11-11 17:03 . 2007-11-11 17:05 364,544 ——— C:\WINDOWS\support.cn
2007-11-11 17:03 . 2007-11-11 17:05 73,216 –a—— C:\WINDOWS\ST6UNST.EXE
2007-11-03 15:15 . 2007-11-24 09:57 d——– C:\WINDOWS\Firesoft
2007-11-03 13:47 . 2007-11-03 15:13 d——– C:\Program Files\Fire International
2007-11-03 08:52 . 2007-11-03 08:52 49,827 –a—— C:\Uninstal.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-31 21:55 342,016 —-a-w C:\WINDOWS\system32\mllmn.exe
2007-12-31 21:54 457,728 —-a-w C:\WINDOWS\system32\igfxpers.exe
2007-12-31 21:54 437,248 —-a-w C:\WINDOWS\system32\igfxtray.exe
2007-12-31 21:54 420,864 —-a-w C:\WINDOWS\system32\hkcmd.exe
2007-12-31 21:53 434,688 —-a-w C:\WINDOWS\UpdReg.EXE
2007-12-31 21:53 ——— d—–w C:\Program Files\DellSupport
2007-12-31 16:30 ——— d—–w C:\Program Files\QuickTime
2007-12-30 21:43 15,360 —-a-w C:\WINDOWS\system32\dllcache\ctfmon.exe
2007-12-30 21:43 15,360 —-a-w C:\WINDOWS\system32\ctfmon.exe
2007-12-30 21:07 ——— d—–w C:\Program Files\Quicken
2007-12-28 16:18 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-12-24 15:42 ——— d—–w C:\Documents and Settings\Nick\Application Data\Apple Computer
2007-12-21 23:58 11,031,348 —-a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2007-12-21 23:08 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-10 02:45 ——— d—–w C:\Program Files\BitComet
2007-11-29 00:55 ——— d—–w C:\Documents and Settings\All Users\Application Data\Smilebox
2007-11-18 14:05 ——— d—–w C:\Program Files\Java
2007-11-14 21:05 75,248 —-a-w C:\WINDOWS\zllsputility.exe
2007-11-14 21:05 1,086,952 —-a-w C:\WINDOWS\system32\zpeng24.dll
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-30 23:42 3,590,656 —-a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 ——w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-27 22:40 222,720 —-a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 22:40 222,720 —-a-w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-10 23:56 824,832 —-a-w C:\WINDOWS\system32\dllcache\wininet.dll
2007-10-10 23:56 232,960 ——w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-10-10 23:56 1,159,680 —-a-w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-10-10 23:55 671,232 —-a-w C:\WINDOWS\system32\dllcache\mstime.dll
2007-10-10 23:55 63,488 ——w C:\WINDOWS\system32\dllcache\icardie.dll
2007-10-10 23:55 6,065,664 ——w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-10-10 23:55 52,224 ——w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-10-10 23:55 478,208 —-a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-10-10 23:55 459,264 ——w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-10-10 23:55 44,544 ——w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-10-10 23:55 384,512 ——w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-10-10 23:55 383,488 ——w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-10-10 23:55 27,648 —-a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-10-10 23:55 267,776 ——w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-10-10 23:55 230,400 ——w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-10-10 23:55 214,528 —-a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-10-10 23:55 193,024 —-a-w C:\WINDOWS\system32\dllcache\msrating.dll
2007-10-10 23:55 153,088 ——w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-10-10 23:55 132,608 —-a-w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-10-10 23:55 124,928 ——w C:\WINDOWS\system32\dllcache\advpack.dll
2007-10-10 23:55 105,984 ——w C:\WINDOWS\system32\dllcache\url.dll
2007-10-10 23:55 102,400 ——w C:\WINDOWS\system32\dllcache\occache.dll
2007-10-10 10:59 70,656 ——w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-10-10 10:59 625,152 ——w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-10-10 10:59 13,824 ——w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-10-10 05:46 161,792 ——w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-09-08 13:35 203,264 —-a-w C:\WINDOWS\system32\Pokemon Diamond and Pearl.scr
2002-07-26 21:02 153,088 —-a-w C:\Program Files\UNWISE.EXE
2007-09-27 02:35 1,682 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((( snapshot@2007-12-29_ 0.13.39.59 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-12-28 16:32:20 102,400 —-a-r C:\WINDOWS\Installer\{18388EF8-E0A3-442B-8BFE-E2F1B3D05C91}\iTunesIco.exe
+ 2007-12-29 16:36:21 102,400 —-a-r C:\WINDOWS\Installer\{18388EF8-E0A3-442B-8BFE-E2F1B3D05C91}\iTunesIco.exe
- 2007-12-29 04:07:32 122,941 —-a-w C:\WINDOWS\system32\dla\tfswctrl .exe
+ 2007-12-31 21:58:01 122,941 —-a-w C:\WINDOWS\system32\dla\tfswctrl .exe
- 2007-12-29 05:05:24 491,520 —-a-w C:\WINDOWS\system32\dla\tfswctrl.exe
+ 2007-12-31 21:55:28 491,520 —-a-w C:\WINDOWS\system32\dla\tfswctrl.exe
+ 2007-07-19 20:10:28 127,768 —-a-w C:\WINDOWS\system32\drivers\klif.sys
- 2007-12-29 04:06:48 99,840 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S4I2G1 .EXE
+ 2007-12-31 21:56:53 99,840 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S4I2G1 .EXE
- 2007-12-29 05:05:13 448,000 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S4I2G1.EXE
+ 2007-12-31 21:54:38 448,000 —-a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\E_S4I2G1.EXE
- 2007-03-09 05:01:24 83,696 —-a-w C:\WINDOWS\system32\vsdata.dll
+ 2007-11-14 21:04:52 83,432 —-a-w C:\WINDOWS\system32\vsdata.dll
- 2007-03-09 05:02:10 394,192 —-a-w C:\WINDOWS\system32\vsdatant.sys
+ 2007-11-14 21:05:16 394,952 —-a-w C:\WINDOWS\system32\vsdatant.sys
- 2007-03-09 05:01:24 157,424 —-a-w C:\WINDOWS\system32\vsinit.dll
+ 2007-11-14 21:04:52 157,160 —-a-w C:\WINDOWS\system32\vsinit.dll
- 2007-03-09 05:01:26 104,176 —-a-w C:\WINDOWS\system32\vsmonapi.dll
+ 2007-11-14 21:04:52 103,912 —-a-w C:\WINDOWS\system32\vsmonapi.dll
- 2007-03-09 05:01:26 276,208 —-a-w C:\WINDOWS\system32\vspubapi.dll
+ 2007-11-14 21:04:52 275,944 —-a-w C:\WINDOWS\system32\vspubapi.dll
- 2007-03-09 05:01:26 71,408 —-a-w C:\WINDOWS\system32\vsregexp.dll
+ 2007-11-14 21:04:52 71,144 —-a-w C:\WINDOWS\system32\vsregexp.dll
- 2007-03-09 05:01:28 472,816 —-a-w C:\WINDOWS\system32\vsutil.dll
+ 2007-11-14 21:04:54 472,552 —-a-w C:\WINDOWS\system32\vsutil.dll
- 2007-03-09 05:01:30 46,832 —-a-w C:\WINDOWS\system32\vswmi.dll
+ 2007-11-14 21:04:54 46,568 —-a-w C:\WINDOWS\system32\vswmi.dll
- 2007-03-09 05:01:30 100,080 —-a-w C:\WINDOWS\system32\vsxml.dll
+ 2007-11-14 21:04:54 99,816 —-a-w C:\WINDOWS\system32\vsxml.dll
- 2007-03-09 05:01:30 83,696 —-a-w C:\WINDOWS\system32\zlcomm.dll
+ 2007-11-14 21:04:56 83,432 —-a-w C:\WINDOWS\system32\zlcomm.dll
- 2007-03-09 05:01:32 71,408 —-a-w C:\WINDOWS\system32\zlcommdb.dll
+ 2007-11-14 21:04:56 71,144 —-a-w C:\WINDOWS\system32\zlcommdb.dll
- 2007-04-13 17:08:28 4,212 —ha-w C:\WINDOWS\system32\zllictbl.dat
+ 2007-12-31 20:59:39 4,212 —ha-w C:\WINDOWS\system32\zllictbl.dat
- 2007-03-09 05:01:10 362,280 —-a-w C:\WINDOWS\system32\ZoneLabs\av.dll
+ 2007-11-14 21:04:44 370,208 —-a-w C:\WINDOWS\system32\ZoneLabs\av.dll
+ 2007-05-31 05:03:30 65,248 —-a-w C:\WINDOWS\system32\ZoneLabs\avsys\bases\aphish.dat
- 2006-12-19 23:13:50 61,565 —-a-w C:\WINDOWS\system32\ZoneLabs\avsys\CKAHComm.dll
+ 2007-05-31 05:03:16 77,824 —-a-w C:\WINDOWS\system32\ZoneLabs\avsys\CKAHComm.dll
- 2006-12-19 23:13:50 114,813 —-a-w C:\WINDOWS\system32\ZoneLabs\avsys\CKAHrule.dll
+ 2007-05-31 05:03:16 110,592 —-a-w C:\WINDOWS\system32\ZoneLabs\avsys\CKAHrule.dll
- 2006-12-19 23:13:50 307,323 —-a-w C:\WINDOWS\system32\ZoneLabs\avsys\CKAHUM.dll
+ 2007-05-31 05:03:16 331,776 —-a-w C:\WINDOWS\system32\ZoneLabs\avsys\CKAHUM.dll
- 2006-11-30 03:02:26 36,923 —-a-w C:\WINDOWS\system32\ZoneLabs\avsys\FSSync.dll
+ 2007-05-31 05:03:16 38,400 —-a-w C:\WINDOWS\system32\ZoneLabs\avsys\FSSync.dll
+ 2007-07-19 20:10:32 110,360 —-a-w C:\WINDOWS\system32\ZoneLabs\avsys\instdrivers\w2kxp32\kl1.sys
+ 2007-07-19 20:10:32 186,128 —-a-w C:\WINDOWS\system32\ZoneLabs\avsys\instdrivers\w2kxp32\klif.sys
+ 2007-05-31 05:03:48 110,360 —-a-w C:\WINDOWS\system32\ZoneLabs\avsys\instdrivers\x32\kl1.sys
+ 2007-07-19 20:10:28 127,768 —-a-w C:\WINDOWS\system32\ZoneLabs\avsys\instdrivers\x32\klif.sys
+ 2007-05-31 05:03:50 45,056 —-a-w C:\WINDOWS\system32\ZoneLabs\avsys\instdrivers\x32\regcat.exe
- 2007-01-11 22:31:04 274,514 —-a-w C:\WINDOWS\system32\ZoneLabs\avsys\kave.dll
+ 2007-09-12 02:09:16 274,432 —-a-w C:\WINDOWS\system32\ZoneLabs\avsys\kave.dll
+ 2007-05-31 05:03:20 548,864 —-a-w C:\WINDOWS\system32\ZoneLabs\avsys\msvcp80.dll
+ 2007-05-31 05:03:20 626,688 —-a-w C:\WINDOWS\system32\ZoneLabs\avsys\msvcr80.dll
- 2006-11-30 03:02:26 184,445 —-a-w C:\WINDOWS\system32\ZoneLabs\avsys\prloader.dll
+ 2007-05-31 05:03:18 184,320 —-a-w C:\WINDOWS\system32\ZoneLabs\avsys\prloader.dll
+ 2007-05-31 05:03:22 90,112 —-a-w C:\WINDOWS\system32\ZoneLabs\avsys\prremote.dll
- 2006-12-19 23:13:52 94,313 —-a-w C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe
+ 2007-09-12 02:09:16 135,168 —-a-w C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe
- 2007-03-09 05:01:10 100,080 —-a-w C:\WINDOWS\system32\ZoneLabs\camupd.dll
+ 2007-11-14 21:04:44 99,816 —-a-w C:\WINDOWS\system32\ZoneLabs\camupd.dll
- 2007-03-09 05:01:14 128,744 —-a-w C:\WINDOWS\system32\ZoneLabs\fbl.dll
+ 2007-11-14 21:04:46 128,480 —-a-w C:\WINDOWS\system32\ZoneLabs\fbl.dll
- 2007-03-09 05:01:14 38,640 —-a-w C:\WINDOWS\system32\ZoneLabs\featuremap.dll
+ 2007-11-14 21:04:46 38,376 —-a-w C:\WINDOWS\system32\ZoneLabs\featuremap.dll
- 2007-03-09 05:01:14 321,280 —-a-w C:\WINDOWS\system32\ZoneLabs\imsecure.dll
+ 2007-11-14 21:04:46 321,016 —-a-w C:\WINDOWS\system32\ZoneLabs\imsecure.dll
- 2007-03-09 05:02:12 288,408 —-a-w C:\WINDOWS\system32\ZoneLabs\lib\ConfigWizard.zip.dll
+ 2007-11-14 21:05:18 288,144 —-a-w C:\WINDOWS\system32\ZoneLabs\lib\ConfigWizard.zip.dll
- 2007-03-09 05:02:12 153,240 —-a-w C:\WINDOWS\system32\ZoneLabs\lib\licenseui.zip.dll
+ 2007-11-14 21:05:18 152,976 —-a-w C:\WINDOWS\system32\ZoneLabs\lib\licenseui.zip.dll
- 2007-03-09 05:02:14 26,264 —-a-w C:\WINDOWS\system32\ZoneLabs\lib\zlsvc.zip.dll
+ 2007-11-14 21:05:18 26,000 —-a-w C:\WINDOWS\system32\ZoneLabs\lib\zlsvc.zip.dll
- 2007-03-09 05:02:14 1,361,560 —-a-w C:\WINDOWS\system32\ZoneLabs\lib\zpy.zip.dll
+ 2007-11-14 21:05:18 1,361,296 —-a-w C:\WINDOWS\system32\ZoneLabs\lib\zpy.zip.dll
- 2007-03-09 05:02:14 71,320 —-a-w C:\WINDOWS\system32\ZoneLabs\lib\zui.zip.dll
+ 2007-11-14 21:05:20 71,056 —-a-w C:\WINDOWS\system32\ZoneLabs\lib\zui.zip.dll
- 2007-03-09 05:04:42 30,448 —-a-w C:\WINDOWS\system32\ZoneLabs\plugins\rpc_server\rpc_server.dll
+ 2007-11-14 21:06:34 30,184 —-a-w C:\WINDOWS\system32\ZoneLabs\plugins\rpc_server\rpc_server.dll
- 2007-03-09 05:04:44 30,480 —-a-w C:\WINDOWS\system32\ZoneLabs\plugins\vsmon_plugin\vsmon_plugin.dll
+ 2007-11-14 21:06:36 30,216 —-a-w C:\WINDOWS\system32\ZoneLabs\plugins\vsmon_plugin\vsmon_plugin.dll
- 2007-01-18 10:39:16 714,472 —-a-w C:\WINDOWS\system32\ZoneLabs\qrbase.dll
+ 2007-10-19 01:18:38 714,208 —-a-w C:\WINDOWS\system32\ZoneLabs\qrbase.dll
- 2007-01-18 10:39:16 677,608 —-a-w C:\WINDOWS\system32\ZoneLabs\qrsrecl.dll
+ 2007-10-19 01:18:38 787,936 —-a-w C:\WINDOWS\system32\ZoneLabs\qrsrecl.dll
- 2007-03-09 05:01:20 173,808 —-a-w C:\WINDOWS\system32\ZoneLabs\scheduler.dll
+ 2007-11-14 21:04:48 173,544 —-a-w C:\WINDOWS\system32\ZoneLabs\scheduler.dll
- 2007-01-18 10:39:18 1,369,832 —-a-w C:\WINDOWS\system32\ZoneLabs\srescan.dll
+ 2007-10-19 01:18:40 1,500,640 —-a-w C:\WINDOWS\system32\ZoneLabs\srescan.dll
- 2007-01-18 10:39:20 50,416 —-a-w C:\WINDOWS\system32\ZoneLabs\srescan.sys
+ 2007-10-19 01:18:44 51,176 —-a-w C:\WINDOWS\system32\ZoneLabs\srescan.sys
- 2007-03-09 05:01:20 456,432 —-a-w C:\WINDOWS\system32\ZoneLabs\ssleay32.dll
+ 2007-11-14 21:04:50 456,168 —-a-w C:\WINDOWS\system32\ZoneLabs\ssleay32.dll
- 2007-03-09 05:04:44 210,696 —-a-w C:\WINDOWS\system32\ZoneLabs\streamapi\httpblocker\httpblocker.dll
+ 2007-11-14 21:06:36 214,528 —-a-w C:\WINDOWS\system32\ZoneLabs\streamapi\httpblocker\httpblocker.dll
- 2007-03-09 05:04:46 3,229,440 —-a-w C:\WINDOWS\system32\ZoneLabs\streamapi\imslsp\imslsp.dll
+ 2007-11-14 21:06:36 3,266,040 —-a-w C:\WINDOWS\system32\ZoneLabs\streamapi\imslsp\imslsp.dll
- 2007-06-26 12:25:38 833,248 —-a-w C:\WINDOWS\system32\ZoneLabs\updating.dll
+ 2007-10-11 21:50:32 832,984 —-a-w C:\WINDOWS\system32\ZoneLabs\updating.dll
- 2007-03-09 05:01:58 141,104 —-a-w C:\WINDOWS\system32\ZoneLabs\updclient.exe
+ 2007-11-14 21:05:06 144,936 —-a-w C:\WINDOWS\system32\ZoneLabs\updclient.exe
- 2007-03-09 05:01:24 108,272 —-a-w C:\WINDOWS\system32\ZoneLabs\vsavpro.dll
+ 2007-11-14 21:04:52 108,008 —-a-w C:\WINDOWS\system32\ZoneLabs\vsavpro.dll
- 2007-03-09 05:01:24 79,600 —-a-w C:\WINDOWS\system32\ZoneLabs\vsdb.dll
+ 2007-11-14 21:04:52 83,432 —-a-w C:\WINDOWS\system32\ZoneLabs\vsdb.dll
- 2007-03-09 05:01:58 75,568 —-a-w C:\WINDOWS\system32\ZoneLabs\vsmon.exe
+ 2007-11-14 21:05:06 75,304 —-a-w C:\WINDOWS\system32\ZoneLabs\vsmon.exe
- 2007-03-09 05:01:26 2,025,200 —-a-w C:\WINDOWS\system32\ZoneLabs\vsmondll.dll
+ 2007-11-14 21:04:52 2,029,032 —-a-w C:\WINDOWS\system32\ZoneLabs\vsmondll.dll
- 2007-03-09 05:01:28 1,345,264 —-a-w C:\WINDOWS\system32\ZoneLabs\vsruledb.dll
+ 2007-11-14 21:04:54 1,361,384 —-a-w C:\WINDOWS\system32\ZoneLabs\vsruledb.dll
- 2007-03-09 05:01:28 243,440 —-a-w C:\WINDOWS\system32\ZoneLabs\vsvault.dll
+ 2007-11-14 21:04:54 239,080 —-a-w C:\WINDOWS\system32\ZoneLabs\vsvault.dll
- 2007-03-09 05:01:32 177,904 —-a-w C:\WINDOWS\system32\ZoneLabs\zlparser.dll
+ 2007-11-14 21:04:56 177,640 —-a-w C:\WINDOWS\system32\ZoneLabs\zlparser.dll
- 2007-03-09 05:01:32 79,608 —-a-w C:\WINDOWS\system32\ZoneLabs\zlquarantine.dll
+ 2007-11-14 21:04:56 79,344 —-a-w C:\WINDOWS\system32\ZoneLabs\zlquarantine.dll
- 2007-03-09 05:01:34 378,608 —-a-w C:\WINDOWS\system32\ZoneLabs\zlsre.dll
+ 2007-11-14 21:04:58 382,440 —-a-w C:\WINDOWS\system32\ZoneLabs\zlsre.dll
- 2007-03-09 05:01:34 120,560 —-a-w C:\WINDOWS\system32\ZoneLabs\zlupdate.dll
+ 2007-11-14 21:04:58 120,296 —-a-w C:\WINDOWS\system32\ZoneLabs\zlupdate.dll
- 2007-12-29 05:07:07 16,384 –sha-w C:\WINDOWS\Temp\Cookies\index.dat
+ 2007-12-31 21:57:01 16,384 –sha-w C:\WINDOWS\Temp\Cookies\index.dat
- 2007-12-29 05:07:07 16,384 –sha-w C:\WINDOWS\Temp\History\History.IE5\index.dat
+ 2007-12-31 21:57:01 16,384 –sha-w C:\WINDOWS\Temp\History\History.IE5\index.dat
+ 2007-12-31 21:53:01 16,384 —-atw C:\WINDOWS\Temp\Perflib_Perfdata_6a4.dat
+ 2007-12-31 21:58:44 16,384 —-atw C:\WINDOWS\Temp\Perflib_Perfdata_d18.dat
- 2007-12-29 05:07:07 32,768 –sha-w C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\index.dat
+ 2007-12-31 21:57:01 32,768 –sha-w C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\index.dat
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{034E9743-8FC4-4F89-8D1B-D11E302CB0FF}]
2007-12-31 16:53 338432 ——— C:\WINDOWS\system32\mllmn.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2007-12-31 16:53]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2007-12-30 16:43]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe" [2007-12-31 16:56]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-12-31 16:53]
"AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-12-31 16:53]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-12-31 16:53]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-12-31 16:53]
"IntelMeM"="C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" [2007-12-31 16:53]
"CTSysVol"="C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe" [2007-12-31 16:53]
"P17Helper"="Rundll32 P17.dll" []
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2007-12-31 16:53]
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2007-12-31 16:53]
"mmtask"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe" [2007-12-31 16:53]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2007-12-31 16:53]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2007-12-31 16:53]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2007-12-31 16:54]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2007-12-31 16:54]
"EPSON Stylus CX5400"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.exe" [2007-12-31 16:54]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2007-12-31 16:54]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2007-12-31 16:54]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2007-12-31 16:54]
"PinnacleDriverCheck"="C:\WINDOWS\system32\\PSDrvCheck.exe" [2007-12-31 16:54]
"PCLEUSBTip"="C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe" [2007-12-31 16:55]
"USB2Check"="RUNDLL32.exe" [2004-08-04 05:00 C:\WINDOWS\system32\rundll32.exe]
"USBToolTip"="C:\Program Files\Pinnacle\Shared Files\\Programs\USBTip\USBTip.exe" [2007-12-31 16:55]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2007-12-31 16:55]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2007-12-31 16:55]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-12-31 16:55]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-31 16:55]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask .exe" []
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-12-31 16:55]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-11-14 16:05]

C:\Documents and Settings\Nick\Start Menu\Programs\Startup\
HotSync Manager.lnk - C:\Program Files\Palm\HOTSYNC.EXE [2003-09-25 09:47:12]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Dataviz Messenger.lnk - C:\WINDOWS\DvzCommon\DvzMsgr.exe [2003-07-01 20:16:46]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 15:05:56]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 11:59:36]
Run Nintendo Wi-Fi USB Connector Registration Tool.lnk - C:\Program Files\WiFiConnector\NintendoWFCReg.exe [2006-12-25 22:11:14]

[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows]
"load"=C:\WINDOWS\system32\mllmn.exe

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\mllmn

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

R3 P17;Sound Blaster Live! 24-bit;C:\WINDOWS\system32\drivers\P17.sys [2004-06-09 17:16]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver;C:\WINDOWS\system32\drivers\WmBEnum.sys [2005-04-12 19:21]
R3 WmXlCore;Logitech WingMan Translation Layer Driver;C:\WINDOWS\system32\drivers\WmXlCore.sys [2005-04-12 19:21]
S3 USBAAPL;Apple Mobile USB Driver;C:\WINDOWS\system32\Drivers\usbaapl.sys [2007-10-31 14:09]
S3 WmFilter;Logitech Gaming HID Filter Driver;C:\WINDOWS\system32\drivers\WmFilter.sys [2005-04-12 19:21]
S3 WmVirHid;Logitech Virtual Hid Device Driver;C:\WINDOWS\system32\drivers\WmVirHid.sys [2005-04-12 19:21]

.
Contents of the 'Scheduled Tasks' folder
"2007-12-29 17:23:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-12-31 06:08:23 C:\WINDOWS\Tasks\User_Feed_Synchronization-{50D0D4BC-426E-44B2-9BFA-DEE6413827B3}.job"
- C:\WINDOWS\system32\msfeedssync.exe
"2007-12-31 18:55:42 C:\WINDOWS\Tasks\User_Feed_Synchronization-{92AE00CF-95FA-45D4-8547-820AEBE39993}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-31 17:01:50
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwClose

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\WINDOWS\system32\mllmn.dll
.
Completion time: 2007-12-31 17:08:02 - machine was rebooted
C:\ComboFix2.txt … 2007-12-31 13:59
C:\ComboFix3.txt … 2007-12-29 08:38
.
2007-12-27 12:33:26 — E O F —

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI